CHINA Law and Practice Contributed by: Jihong Chen, Zhong Lun Law Firm
regulatory framework to ensure compliance with data protection and cybersecurity requirements. The main obligations arising from the applica - ble laws and regulations regarding the use of IoT services and data processing services are as follows. • The CSL sets out that network operators (which may include IoT service providers as well as data processing service providers, which are often involved in IoT operations as cloud service providers) shall ensure the security of networks, comply with cyberse - curity obligations in relation to multi-level protection schemes (MLPS), take all neces - sary remedies and timely report any cyberse - curity incidents to relevant authorities (Articles 21, 25 and 42). If the network operator is a Critical Information Infrastructure Operator (CIIO), it must comply with stringent security requirements to protect the infrastructure from cyber-attacks (Article 34). • Pursuant to the DSL, while carrying out data processing activities related to IoT services and data processing services, a sound data security management system shall be estab - lished throughout the whole process, includ - ing carrying out data security training and corresponding security measures (Article 27). Moreover, IoT service providers and data pro - cessors shall meet the obligations for the pro - tection of important data collected through IoT devices and generated/processed by IoT services, including designating a responsible person, conducting regular risk assessment and reporting to competent authorities, etc (Articles 27 and 30). • Obligations for IoT service providers as pro - vided by PIPL mainly include complying with the minimum necessary principle (Article 6), satisfying the transparency requirement (Arti - cle 17) and obtaining valid legal basis for col -
lection and processing of PI (Article 13). IoT device users should also be informed of their PI-related rights. In the event of any CBDT, the relevant obligations in relation to CBDT as provided in 5.1 Restrictions on International Data Transfers shall also be fulfilled by IoT service providers. Data processing service providers usually act as the entrusted party under the PIPL and thus shall process PI according to the purposes, methods, etc, as stipulated in the agreement with the PI han - dler. In addition, the entrusted party shall not delegate the PI processing to others without the consent of the PI handler (Article 21). 3.4 Regulators and Enforcement Key regulators of IoT services and data pro - cessing services include the CAC, the MIIT and the MPS. The CAC is in charge of the overall planning of data protection and privacy, and the co-ordination of the competent authorities. The MIIT is the industry authority for IoT services and is responsible for the development of industry regulations and enforcement in the field of IoT. As IoT services involve network operations, the MPS, as the enforcement authority of CSL, is responsible for managing and enforcing the rel - evant requirements under the CSL. In some cases, other departments (eg, the SAMR) may become responsible for enforcing the data regulation under certain circumstances, such as anti-unfair competition in IoT service provision.
4. Sectoral Issues 4.1 Use of Cookies
Under the CSL and PIPL regimes, the use of cookies is usually regarded as the collection of PI, which must comply with PI protection-related
82
CHAMBERS.COM
Powered by FlippingBook