CHINA Law and Practice Contributed by: Jihong Chen, Zhong Lun Law Firm
3.2 Interaction of Data Regulation and Data Protection The interplay between data regulation and data protection requirements in China is complex but complementary. On one hand, data protec - tion laws such as the Three Fundamental Laws govern the legality, legitimacy and necessity of data processing, as well as the protection of the rights and interests of data subjects involved in IoT services. On the other hand, broader data regulation framework – including the industry- specific regulations and guidelines – aims to oversee specific industries and types of data usage, ensuring that data protection principles are applied in various contexts, particularly in critical sectors such as IoT. Together, they provide a comprehensive approach to ensure cybersecurity and promote data and privacy protection. The above legal frameworks collectively address different aspects of data handling in China. However, they share unified objectives of safe - guarding data privacy, enhancing security and ensuring accountability in the digital age. The Three Fundamental Laws serve as the primary regulation governing data protection, while other industry-specific laws built on the foundation of the Three Fundamental Laws ensure that data is handled responsibly, transparently and in com - pliance with privacy rights in IoT scenarios. Data holders (which may include IoT service provid - ers and data processors) and data processing service providers in China must navigate the aforementioned multiple frameworks to ensure the protection of user privacy and compliance with stringent data security requirements. 3.3 Rights and Obligations Under Applicable Data Regulation IoT service providers and data processing ser - vice providers in China must navigate a complex
• The PIPL focuses on how the data handlers collect, store, use and process the PI gener - ated by IoT devices, and applies to data hold - ers and data processing service providers who collect and process PI in China. • The DSL is another key law addressing data security, which covers not only PI but also general data in the course of IoT services pro - vision, especially for “important data” gener - ated or processed by IoT services. • Other industrial measures and/or standards (the Measures on Safety Evaluation for Cloud Computing Services, Information Security Technology – Security Technical Require - ments of Data Transmission for IoT, etc) collectively depict the roadmaps for the pre- assessment and stringent supervision of the technologies, infrastructures and other key aspects of cloud computing service platforms involved in IoT services. • In terms of facilitating data use, the Opinions unveil orientations and guidelines to promote efficient data circulation. A data ownership affirmation mechanism shall be established, in which the legal rights enjoyed by all par - ticipants in the process of data production, circulation and use, including data holders and data processing service providers, shall be defined. As far as corporate data that does not involve PI and public interests is concerned, the relevant parties may legally enjoy the rights and interests to hold, use and obtain profits from such data. Regarding PI, a corresponding authorisation mechanism shall be established to collect, hold, host and use PI according to the scope of individual authorisation, so as to promote the rational use of PI. Data holders, data processing ser - vice providers and other relevant stakehold - ers may legally carry out business co-opera - tion and circulate data, sharing the dividends of the digital economy.
81
CHAMBERS.COM
Powered by FlippingBook