CHINA Trends and Developments Contributed by: Vincent Wang, Xinyao Zhao and Amy Cao, Global Law Office
Data Practice in China in 2024: A Year-End Review 2024 saw noteworthy developments in cross- border data transfer, data security measures, personal information compliance audit and AI- related litigation, including flexibility in the regu - lation of cross-border data transfers from China, the practical implementation of rules for personal information protection, and rapid developments in data assets. All these efforts highlight China’s desire to establish a secure and dynamic digi - tal economy that addresses domestic growth needs while keeping an eye on global digital trade, embracing international standards and tackling practical challenges. Meanwhile, the pervasive application of new technologies like generative artificial intelli - gence (AI) spurred an increase in litigation on intellectual property right claims and personal information protection, sending cautionary notes to businesses about things they need to prepare for in an ever-changing legal environment. Cross-border data transfers Provisions on Facilitating and Regulating Cross-border Data Flows The Provisions on Facilitating and Regulating Cross-border Data Flows (the “Provisions”) were released by the Cyberspace Adminis - tration of China (CAC) on 22 March 2024 and introduced critical updates to China’s regulatory mechanisms for cross-border data transfers (the “Regulatory Mechanisms”). Although the Provi - sions do not change the local processing pref - erence established by the three channels that make up the Regulatory Mechanisms – ie, the Security Assessment, the China standard con - tractual clauses (CN SCC) and the cross-border privacy certification – it does put the regulation on cross-border data transfer at ease by increas -
ing the triggering thresholds for the Regulatory Mechanisms. Highlights of the Provisions include the follow - ing. • The following processing scenarios are exempted from going through any Regulatory Mechanisms: (a) transfers of employee data necessary for cross-border human resource manage - ment; (b) transfers involving the performance of a contract, such as cross-border shop - ping, shipping, remittance of payments, payments, account opening, hotel/flight bookings, visa applications, and examina - tion services; and (c) transfers of fewer than 100,000 individu - als’ personal data (excluding important data or sensitive personal data) within a year. • Increased threshold for the Security Assess - ment: data processors other than critical information infrastructure operators (CIIOs) anticipating the transfer of personal data of more than 100,000 but fewer than one mil - lion individuals in a year are exempt from the Security Assessment. • Clarification on important data determina - tion: important data can only be determined through the notice from the competent regulators or the local authorities, or from the important data catalogue published by such entities. • Negative lists within Pilot Free-Trade Zones (FTZs): the FTZs in China will publish negative lists of data for cross-border transfer purpos - es (the “Negative List”), and data processors located within the FTZs can freely perform the cross-border transfer of data that is not on the Negative List out of China without the
90
CHAMBERS.COM
Powered by FlippingBook