CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners
protection impact assessment and keep the assess - ment report and records of processing for at least three years. Such processing activities mainly include processing sensitive personal information, using per - sonal information to conduct automated decision- making, entrusting personal information processing to a third party, providing personal information to another handler, publicly disclosing personal information and transferring personal information overseas. Regarding incident response, under Article 57 of the PIPL, where the breach, tampering or loss of person - al information occurs or may occur, a handler shall immediately take remedial measures and notify the cyberspace administration department and relevant individuals. The notice shall include the types of per - sonal information involved, the reason and possible harm, the remedial measures adopted and the contact information of the handler. While the handler is not required to notify individuals if the measures taken can effectively avoid harm, the cyberspace administration department has the authority to request the handler to notify individuals if they consider that harm may have materialised. For specific breach-notification obliga - tions, including notification thresholds, timelines and required content, see 2.3 Incident Response and Notification Obligations . For a handler that provides important internet plat - form services involving a huge number of users and complicated business types, Article 58 of the PIPL establishes heightened obligations. These handlers shall establish and maintain a compliance system, set up an independent organisation mainly composed of external members to supervise protection efforts, for - mulate platform rules following the principles of open - ness, fairness and justice to clarify norms for providers within the platform, stop providing services to provid - ers that seriously violate laws, and regularly publish social responsibility reports for public supervision. 6.2 Cybersecurity and AI The cybersecurity landscape for AI in China operates under a layered framework where specific AI legisla - tion functions as a specialised extension of the CSL, DSL and PIPL. A pivotal development is the 2025 Amendment to the CSL, which added a new Article 20. This article explicitly mandates that the state shall
improve AI ethical norms and strengthen risk monitor - ing, assessment and security supervision, providing the statutory bedrock for the entire AI governance regime. Under this framework, AI service providers face strict “security-by-design” and supply chain obli - gations. Providers shall ensure the legality of founda - tion models and training data used in pre-training and optimisation, strictly utilising data from lawful sources that do not infringe on intellectual property rights. Fur - thermore, where data annotation is involved, provid - ers should establish clear labelling rules and conduct accuracy verification to ensure the authenticity and objectivity of the data. Chinese regulations impose different filing require - ments on traditional AI algorithms and generative AI (“Gen AI”) services. Under the Provisions on the Administration of Algorithm-Generated Recommen - dations for Internet Information Services, traditional AI algorithms, such as search and deep synthesis algo - rithms, are subject to the algorithm filing with the CAC (the “Algorithm Filing”). Separately, pursuant to the Interim Measures for the Administration of Genera - tive Artificial Intelligence Services, providers of Gen AI services are subject to a filing requirement with the competent local CAC (the “Gen AI Filing”). Accordingly, for Gen AI products, the filing require - ment follows a “dual filing” process. Specifically, tradi - tional AI components are subject to the Algorithm Fil - ing, while the Gen AI component is subject to the Gen AI Filing. By contrast, traditional AI products that do not involve generative functionalities are only required to complete the Algorithm Filing. Beyond the above filing obligations, providers are also obligated to establish comprehensive management systems, including algorithmic mechanism reviews and technological ethics reviews, to regularly verify the security of models and data to prevent the genera - tion of illegal content. Regarding incident reporting, the statutory obligations are rigorous and quantifiable. Providers shall imme - diately suspend the generation of illegal content and take corrective measures such as model retraining. In practice, the Guidelines for Security Incident Emer - gency Response of Generative Artificial Intelligence
87 CHAMBERS.COM
Powered by FlippingBook