CHINA Trends and Developments Contributed by: Vincent Wang, Xinyao Zhao and Amy Cao, Global Law Office
need to go through the current Regulatory Mechanisms. Following the Provisions, the CAC further updat - ed the implementation guidance for Security Assessments and CN SCC filings. These updates include simplified templates for personal infor - mation protection impact assessment reports, which further reduce the compliance burdens. The Provisions and the implementation guidance substantially reduce the need to go through the Regulatory Mechanisms for cross-border data transfers and the compliance burden in prepar - ing the application package for the Regulatory Mechanisms. FTZs’ Negative Lists and Whitelists Local governments and FTZs have been active in facilitating cross-border data flows. In recent years, Tianjin and Beijing FTZs published their respective Negative Lists for cross-border data transfers, the Fujian Pingtan FTZs released Whitelists, and the Lingang Special Area of the Shanghai FTZs released both negative lists and whitelists, identifying data that is exempt from the Regulatory Mechanisms. Although the Nega - tive Lists make more sense in the western style of legal governance, the Whitelists may be easier in implementation given the administrative law enforcement style in China. Global co-operation China alerted the global community to its Global Cross-Border Data Flow Co-operation Initiative in November 2024, outlining construc - tive strategies for cross-border data flows and demonstrating its commitment to balancing development and security. The execution of the Memorandum of Understanding with Germany concerning cross-border data transfers, along with continuous efforts to join regional agree -
ments such as the Comprehensive and Progres - sive Agreement for Trans-Pacific Partnership and the Digital Economy Partnership Agreement, highlight the dream of fostering an open and collaborative international framework for cross- border data flow in China’s favour. New implementation rules on data security and protection Network Data Security Management Regulations After the initial release of the original draft for public comments, the Network Data Security Management Regulations (the “Regulations”) were finally released in September 2024, and came into effect on 1 January 2025. The Regu - lations address important aspects of network data governance, enhancing and complement - ing the existing data protection framework under the Cybersecurity Law (CSL), the Data Security Law (DSL) and the PIPL. Key areas in the Regulations that might impact businesses include the following. • Personal data protection: the Regulations set forth more specific requirements for privacy policy formulation based on the PIPL. Busi - nesses must ensure transparency by adher - ing to the content and display requirements of privacy policies (including the adoption of a dual-list to detail processing activities of col - lecting personal information and sharing per - sonal information with third parties), obtaining separate consents when legally required, and responding appropriately to data portability requests. • Security management of important data: businesses processing important data must conduct risk assessments annually and in certain defined scenarios, as well as imple -
91
CHAMBERS.COM
Powered by FlippingBook