CHINA Law and Practice Contributed by: Jihong Chen, Zhong Lun Law Firm
Transfer of Personal Information ( 个人信息出境标准 合同办法 ) came into effect on 1 June 2023. Regarding derogations, Article 38 of the PIPL allows the provision of PI according to inter - national treaties or agreements concluded or acceded to by China. Furthermore, the CBDT Provisions that came into effective on 22 March 2024 provide for the following scenarios that are exempt from the CBDT application procedures: • CBDT that does not contain PI or important data; • where data handlers transfer PI collected and generated overseas after being processed domestically without involving domestic PI or important data in the process; • for the establishment or performance of con - tracts to which individuals are parties; • in implementing cross-border HR manage - ment based on legally formulated labour rules and collective contracts; • in emergency situations to protect the life, health and property safety of natural persons; and • where a non-CIIO data handler provides PI of fewer than 100,000 individuals (excluding sensitive PI) to an overseas recipient since January 1 of the same year. With the goal of stabilising the economy and promoting development, the CBDT Provisions responded to companies’ expectations and have substantially facilitated CBDT and allevi - ated companies’ compliance burden. 5.2 Government Notifications and Approvals The cross-border transfer of PI and important data is regulated under the Three Fundamental Laws. CIIOs are required by the CSL to conduct a security assessment prior to the cross-border
transfer of PI and important data. With respect to important data, data handlers are required by the DSL to abide by the regulations or meas - ures issued by a certain authority, which refers to the Outbound Measures. In addition, the CBDT of certain specially regulated data (eg, human genetic resources information) is subject to spe - cific regulatory rules provided in certain fields and may require government approval, accord - ing to applicable regulatory rules for the CBDT of such data. For non-CIIOs transferring PI, refer to 5.1 Restrictions on International Data Transfers . 5.3 Data Localisation Requirements In China, the first and foremost data localisa - tion requirement is that national secrets are not allowed to be transferred overseas. Secondly, PI and important data collected by CIIOs in the course of their operations in China are required to be stored domestically, and a security assess - ment is required for CBDT. Data handlers who are not CIIOs but process PI reaching a certain volume threshold or who collect important data are required to undergo a security assessment. There are also localisation requirements for spe - cially regulated business data, including relating to the following: • credit information; • personal financial information; • map data; • essential tech equipment required for online publication services; • data and information related to car hailing services; • health information of the population; and • insurance data and fiscal data. In principle, such data must be stored within the Chinese territory (excluding the Hong Kong,
86
CHAMBERS.COM
Powered by FlippingBook