From September 1, 2022, the rule of Cross-Border Data Transfer will be implemented with specific requirements and descriptions of procedures. It was announced as a draft in 2021. The rule defines that Data Processors should request an assessment from the Cyberspace Administration of China (CAC). Two bodies are responsible for this: the police with MLPS and the CAC with Cross-Border Data Transfer. This is a subordinate rule under the Data Security Law (DSL), with relevant laws such as the Personal Information Protection Law (PIPL). The DSL is different from the GDPR, as it only defines Data Processors, but the goal is similar: to protect personal and important/sensitive information.