Data Protection and Privacy 2025

CHINA Trends and Developments Contributed by: Vincent Wang, Xinyao Zhao and Amy Cao, Global Law Office

to train its AI model for commercial purposes that exceeded fair use under the current framework of copyright protection. This case is still under review. • In another notable case concerning illegal use of data in AI model training, a well-known video streaming platform filed a lawsuit against a domestic AI start-up, accusing the start-up of committing copyright infringement in the AI model training and content genera - tion process, because it uses the platform’s copyrighted materials for AI model training without authorisation, and generates content that violates the platform’s copyright. The case has been accepted by the court and is now under review. First case on cross-border transfer of personal information In September 2024, the Guangzhou Internet Court released a civil case regarding a dispute concerning the cross-border transfer of personal information, which attracted wide attention. A Chinese citizen filed a lawsuit against a famous global hotel group and its Chinese affiliate (“Hotel”), challenging the legality of their cross- border data-sharing practices. In this case, when the plaintiff joined the Hotel’s membership programme and booked a hotel stay through the Hotel’s app, the plaintiff pro - vided personal information, including their name, contact details, nationality and payment infor - mation. Following the reservation, the plaintiff discovered that the personal information had been shared with foreign entities, including marketing partners and affiliates in several coun - tries. The Hotel’s privacy policy, accessible upon registration, included a broad clause allowing cross-border data transfers, but did not specify which entities would receive the information or the purpose for each data transfer.

The Guangzhou Internet Court ultimately ruled in favour of the plaintiff, as follows. • The court determined that the Hotel’s privacy policy, which required a single, blanket con - sent, did not meet the PIPL’s requirements for separate consents for cross-border trans - fer. The PIPL mandates that, if the personal information processor relies on consents from individuals as a legal basis to process per - sonal information, any cross-border transfer of personal information is subject to sepa - rate consents from individuals. It means that individuals should be given a distinct, explicit choice to approve each data transfer outside of China, especially when personal informa - tion is shared for non-essential purposes like marketing. Therefore, the court determined that the plaintiff’s action of agreeing to the Hotel’s privacy policy cannot be deemed a valid separate consent. • The court also found that the Hotel’s privacy policy allowed data sharing with numerous third parties unrelated to the core purpose of the plaintiff’s reservation. Although the Hotel argued that this data-sharing arrangement was consistent with industry practices, the court ruled that sharing personal information with unrelated third parties or for second - ary purposes other than contract perfor - mance (eg, marketing and customer profiling) exceeded the “minimum necessary” scope required to fulfil the plaintiff’s booking. This case serves as an important compliance reminder for multinational companies operat - ing in China or processing Chinese individuals’ personal information, that even privacy policies adhering to international standards such as the GDPR may fall short in meeting PIPL compli - ance.

96

CHAMBERS.COM

Powered by