CHINA Trends and Developments Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Patrick Guo, Fangda Partners
Risk assessment and audit In addition to the core notice-and-report obligations, Chinese regulators are also calling on organizations to fulfil certain procedural compliance requirements, including data inventory/data mapping, scenario- based record of processing activities (RoPA), data risk assessments and personal information compli - ance audit (PI Audit). On 6 December 2025, CAC issued the Measures for Network Data Security Risk Assessment (Draft for Public Consultation) (the “Draft Measures”), establish - ing a unified, cross-sectoral framework for assessing risks arising from network data processing. Extend - ing requirements previously imposed on banking and insurance institutions stipulated in the Measures for the Data Security Management of Banking and Insurance Institutions, the Draft Measures apply to all network data processing activities within China and define risk assessment as a “structured process of identifying, analysing, and evaluating data security risks”. Under the proposed regulatory architecture, CAC co-ordinates nationwide assessment work, while sectoral regulators organise and implement assess - ments based on the principle that business operators are responsible for their own data and data security. The Draft Measures distinguish between important data handlers and general data handlers, echoing Article 30 of the DSL and Article 33 of the Regulation on Network Data Security Management. Important data handlers must conduct annual risk assessments, while general handlers are encouraged to conduct them at least once every three years. Assessments may be performed internally by designated personnel or externally by certified third-party institutions. When engaging third-party institutions, handlers must clearly define responsibilities and confidentiality obligations. Assessment institutions must maintain independ - ence, objectivity and professional judgement, and are accountable for the authenticity and complete - ness of their reports. The same institution may not conduct more than three consecutive assessments for the same handler. Reports must be retained for at least three years, and important data handlers must file the reports with competent regulators within ten working days.
The Draft Measures further introduce a trigger-based mechanism. If CAC identifies significant risks, major data security incidents, or activities that may endan - ger national security or public interests, it may require the engagement of certified third-party institutions. Regulators may order rectification, restrict the impor - tant data processing, or pursue liability for non-com - pliance. Assessment institutions themselves may be subject to corrective measures or prohibitions in case of serious misconduct. As a matter of best practice, organisations are expect - ed to test the effectiveness of their cybersecurity and data protection control measures, and China is no exception. Under the current regulatory framework, there is a mandatory PI audit programme requirement where large companies need to complete an audit once every two years. In parallel to the periodic audits, the regime also con - templates special audits targeting specific processing activities, for example, the processing of minors’ per - sonal information. In particular, CAC has been actively requiring organisations that process minors’ personal information to submit the results of their annual PI audits, with recent practice indicating a submission deadline of the end of January each year. AI regulation In parallel, the CAC is continuing to draft and roll out a new generation of rules to regulate AI. Recap of regulatory framework In China, AI regulations distinguish between two cat - egories of AI: traditional AI and Generative AI (“Gen AI”). Traditional AI refers to algorithms that have auto - mated decision-making functions for non-generative tasks, such as search, ranking or recommendation. By contrast, Gen AI refers to models that perform a generative function such as text-to-text, text-to-graph or text-to-video generation function. Chinese regulations impose different filing require - ments for traditional AI algorithms and public-facing Gen AI services. Under the Provisions on the Administration of Algo - rithm-generated Recommendations for Internet
93 CHAMBERS.COM
Powered by FlippingBook