CHINA Law and Practice Contributed by: Jihong Chen, Zhong Lun Law Firm
other new technologies must be identified in a noticeable way and shall be reviewed technically or manually to avoid infringements of the rights and interests of data subjects. In 2024, China continued to formulate relevant standards and technical documents for AIGC governance. In September 2024, the National Information Security Standardisation Technical Committee (TC260) issued the Artificial Intelli - gence Security Governance Framework ( 人工智能 安全治理框架 ), which is designed to promote con - sensus and co-ordination among governments, international organisations, enterprises and oth - er stakeholders regarding AI governance. The development of AI governance in China is further demonstrated by: • the Basic Security Requirements for Genera - tive Artificial Intelligence Service (TC260-003 生成式人工智能服务安全基本要求 ), released in February 2024; • the Measures for Labelling Artificial Intel - ligence Generated Synthetic Contents ( 人工智 能生成合成内容标识办法 ), released in March 2025 and effective from 1 September 2025; and • the Guidelines for Emergency Response to Generative Artificial Intelligence Service Secu - rity Incidents (Draft for Comment) ( 生成式人工 智能服务安全应急响应指南 ( 征求意见稿 )), released in December 2024. Safeguards Provided for Data Protection With regard to data protection in the context of the use of AI systems, all phases related to AIGC services need to comply with the corresponding legal requirements for data protection. For instance, regarding the phase of model train - ing, AIGC developers and AIGC service provid - ers are legally required to use data with lawful sources, to formulate clear data annotation rules
and to take effective measures to ensure the authenticity, accuracy, objectivity and diversity of the training data and properly fulfil the data protection obligations (Articles 7 and 8 of AIGC Measures). Regarding the phase of application operating, certain data protection risks concerning the reli - ability and robustness of the services, as well as issues related to transparency, necessity, etc, of data processing, may arise out of content gen - eration, data analysis and processing, and AIGC service provision. Based on that, AIGC service providers shall assume responsibility for protect - ing the collected data and the information input by users, as well as performing their legal obliga - tions as PI handlers. These obligations include: • collecting only necessary PI; • addressing individuals’ requests to exercise their rights; and • preventing the unlawful retention or disclo - sure of users’ input data and usage records to third parties. Relevant technical measures shall also be taken to enhance the safety, stability and sustainability of services and ensure the normal use of users (Articles 9, 11 and 13 of AIGC Measures). 1.6 Interplay Between AI and Data Protection Regulations How AI Regulation Affects Data Protection in China AI regulation and data protection are closely intertwined in China, where both are governed by legal frameworks designed to balance tech - nological innovation with privacy and data pro - tection. The data compliance issues associated with the entire lifecycle of AIGC, including but not limited to key stages such as model train - ing, service provision and model optimisation,
77
CHAMBERS.COM
Powered by FlippingBook