CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners
dictions from mainland China where Chinese cyber - security laws do not apply. For the purpose of this article only, China refers to mainland China), and sets out stringent requirements for the protection of net - work information and the security of network opera - tions. The recent amendment to the CSL significantly increases the severity of penalties for network opera - tors and CII operators (CIIOs) that breach cybersecu - rity obligations, reflecting a strengthened enforcement framework. The revised CSL explicitly supports the research on artificial intelligence and R&D of key tech - nologies such as algorithms, advances construction of infrastructure such as training data resources and computing power, improves ethical norms for artificial intelligence, and strengthens risk monitoring, assess - ment and security supervision. The DSL applies to any individual or organisation engaged in data processing activities in China. These activities include collecting, storing, processing, using, providing, trading, and publicly disclosing data, whether conducted online or offline. The DSL also has extraterritorial application effect – ie, if any data pro - cessing activities carried out outside of the territory of China harms the national security, public interests, or legitimate rights and interests of citizens or organisa - tions of China, legal liability shall be investigated in accordance with the DSL. At a general level, the DSL imposes comprehensive data safeguarding obligations on data handlers (which are, conceptually, similar to data controllers under GDPR) encompassing organisational governance and technical safeguards, including the establishment of internal data security management mechanisms, the provision of security awareness training, the imple - mentation of data classification and grading, and the conduct of periodic data security risk assessments. The PIPL applies to any activity of processing of per - sonal information of a natural person that is carried out within China. The PIPL also has clear extraterritorial application effect – ie, it applies to any data process - ing activities carried on outside of China if it covers the personal information of a natural person in China and the purpose is to provide a product or service to that natural person, or to analyse or assess the behaviour of that natural person. The PIPL establishes principles
for personal information processing such as transpar - ency, fairness, purpose limitation, data minimisation, limited retention, accuracy and accountability. While many provisions echo the EU’s GDPR, including fines of up to 5% of prior-year revenue for serious breach - es, the PIPL differs in the sense that consent is the default lawful basis for data processing activities, and it does not recognise the “legitimate interest” lawful The Regulation on Network Data Security Manage - ment (“Network Data Management Regulation”, in Chinese 网络数据安全管理条例 ), promulgated by China’s State Council on 30 September 2024 and effective from 1 January 2025, sets out detailed obligations for data handlers in China, with a particular focus on the protection of important data, for instance, regularly conducting network data security risk monitoring, risk assessments and emergency drills. The regulation also restates requirements for security assessments of cross-border data transfer (CBDTs) that were set out in previous rules and clarifies the responsibilities of internet platform service providers, specifying the obligations of third-party service and product provid - ers. As an implementing regulation of the CSL, DSL and PIPL, the Network Data Management Regulation has a substantially unified scope of application, apply - ing to network data processing activities and related security supervision conducted within the territory of China, and, where applicable, extending extraterritori - ally to overseas activities that process personal infor - mation of individuals located within China or that harm China’s national security, public interests or the lawful rights and interests of its citizens or organisations. The other regulation is known as the Regulation on Protecting the Security of Critical Information Infra - structure (“CIIO Regulation”, in Chinese 关键信息基础设 施安全保护条例 ). Compared to the Network Data Man - agement Regulation which applies to all data handlers, the scope of application for the CIIO is much nar - rower, as it applies only to CIIOs. It sets out detailed obligations for any CIIO, including risk assessment, security management, incident response and report - ing requirements. basis widely used in EU. The “Two Regulations”
76 CHAMBERS.COM
Powered by FlippingBook