Data Protection and Privacy 2025

CHINA Law and Practice Contributed by: Jihong Chen, Zhong Lun Law Firm

are complex and typically involve multiple par - ties, such as AIGC developers, service providers and service users, which poses significant chal - lenges for privacy and data protection. In key data protection regulations in China, spe - cific provisions have been formulated to address AI development while simultaneously ensuring a balance between innovation and data protection, and safeguarding privacy associated with AIGC technologies. For instance, the RANDS provide that, insofar as the training data and process - ing activities thereof are concerned, the network data handlers providing AIGC services shall fulfil relevant security management obligations (Arti - cle 19 of the RANDS). Moreover, the increasingly rapid development of AI technology also drives competent authorities to further incorporate AI regulation into the legal framework of data pro - tection. Action Plan for the Construction of Infor - mation Standards (2024–2027) ( 信息化标准建设行动 计划 (2024–2027 年 )) was released on 24 May 2024 and has expressly made AIGC related technical standards a key focus for future legislation. Interplay Between AI-Related Laws and Data Protection-Related Laws On one hand, the essential data protection laws (including the Three Fundamental Laws and the Three Key Regulations) are applicable to all data processing activities under AI-related scenarios. AIGC developers and service providers should also comply with such essential data protection laws when carrying out data processing activi - ties. For instance, both the PIPL and the DSL require data minimisation and purpose limitation (in Article 6 of the PIPL and Article 32 of the DSL, respectively), which directly affects how AI models are trained. AI systems that process PI must ensure that users can exercise their rights as set out under the PIPL, such as the right to withdraw consent or request data deletion (Arti -

cles 15 and 47 of the PIPL). AI systems must incorporate robust security measures to prevent breaches of PI as set out in Article 27 of the DSL and Article 51 of the PIPL; as a result, AIGC ser - vice providers shall build these features into their platforms to comply with such data protection requirements. If AIGC services involve cross- border data transmission, the legal requirements on cross-border data transfer (CBDT) shall also be followed. On the other hand, in some cases, the AI-relat - ed laws specify and complement the data pro - tection requirements in the context of AI. For instance, Article 7 of the AIGC Measures pro - vides that AIGC service providers shall ensure the lawfulness of the training model and data sources when processing training data, and data subjects’ consent shall be obtained if any PI is involved. In addition, echoing the relevant requirements in the PIPL, Article 11 of the AIGC Measures also specifies that users’ PI shall be collected based on the minimum necessary prin - ciple, and any illegal use, storage or provision is not allowed. Moreover, AIGC service provid - ers shall timely address and respond to users’ requests to exercise their PI-related rights to access, copy, correct, supplement, delete, etc. In China, AI regulation and data protection laws, including the PIPL and the AIGC Meas - ures, are designed to complement each other, thereby fostering innovation of AI systems and maintaining respect for individuals’ rights. The PIPL focuses on PI protection, whereas AI- related laws such as the AIGC Measures aim to regulate AI systems in a manner that ensures safety, accountability and ethical considerations. Together, they create a comprehensive regulato - ry structure that guides the responsible develop - ment and deployment of AI while safeguarding privacy and data protection rights.

78

CHAMBERS.COM

Powered by