CHINA Trends and Developments Contributed by: Vincent Wang, Xinyao Zhao and Amy Cao, Global Law Office
menting appropriate safeguards for important data. • Obligations for network platform service providers: network platform service providers should define the data security management obligations of third parties in the platform rules or contracts. Network platform service providers should be held accountable for any legal liability that results from their failure to fulfil their respective supervisory obligations and the resulting harm to users. Dealing with network security incidents As cyber threats and data breaches continue to increase in China, the Chinese regulators are enhancing the requirements regarding net - work security and the corresponding protection mechanisms, particularly the notification and reporting obligation. Businesses are required to take prompt remedial actions and notify the competent regulatory authorities of any net - work security incidents. The Regulations man - date reporting within 24 hours for incidents that pose a risk to national security or public interest, which is a shorter timeframe than the 48-hour reporting period established under the Regula - tions on Network Product Security Vulnerabilities Management for software vulnerability reporting. In 2024, the rules dealing with network security incidents were made clearer. For example, the Emergency Response Plan for Data Security Incidents in the Industrial and Information Tech - nology Field (Trial), released by the Ministry of Industry and Information Technology (MIIT) and effective in November 2024, provides that data processors are responsible for the prevention, monitoring, emergency response to and report - ing of data security incidents. Upon identifying an incident, data processors must first catego - rise its severity into one of the statutorily defined levels (extremely serious, serious, significant,
or general) and notify the relevant regulatory authority. They must then initiate an emergency response by declaring an emergency status, implementing data recovery or tracing meas - ures, and conducting ongoing monitoring and analysis. Finally, a thorough investigation into the cause of the incident, an assessment of its impact, a summary of lessons learned, and a comprehensive report are required. Determination of important data This was another key development in 2024. Under the current laws, important data is broadly defined as information that pertains to specific fields, groups or regions, or that reaches a cer - tain level of precision and scale; if such data is leaked, tampered with or destroyed, it could directly harm national security, economic stabil - ity, social order, public health or safety. Currently, as clarified under both the Provi - sions and the Regulations, the determination of important data rests with the relevant principal authorities. Businesses are obliged to identify and report such important data to the relevant principal authorities for final and official deter - mination. Nationally, regulators of some specific industries, such as the automotive sector, have established their own data security regulations, providing guidance on the identification of important data. In addition, the recommended national standard, Data Security Technology – Rules for Data Clas - sification and Grading (the “Standard”), came into effect in October 2024 and provided details for important data identification. The Standard suggested that data processors should first refer to the data classification and grading rules, or to the important data catalogues specified by the competent regulatory authorities in their respec -
92
CHAMBERS.COM
Powered by FlippingBook