China's New Provisions on CBDT: Impacts and Strategies

来源:TMT法律论坛

文章摘要
导读Law ★NEWS★ On March 22, 2024, the Cyberspace Administration of China (“CAC”) officially issued the

导读Law
★NEWS★
On March 22, 2024, the Cyberspace Administration of China (“CAC”) officially issued the "Provisions on Facilitating and Regulating Cross-border Data Flows" ("Provisions") and took effect upon the date of announcement, which is the official version of the "Provisions on Regulating and Facilitating Cross-border Data Flows (Draft for Comments)" issued on September 28 last year. With the goal of stabilizing the economy and promoting development, the Provisions respond to companies’ expectations, facilitate cross-border data transfer, and reduce companies’ compliance burden.
1. Brief Introduction of the Provisions
1.1 Exempted Scenarios
The Provisions provide for the following scenarios that are exempt from the application procedures:
a、Non-regulated data transfer: cross-border data transfer that does not contain personal information or important data.
b、Data transit transmission: Where data handlers transfer personal information collected and generated overseas after being processed domestically without involving domestic personal information or important data in the process.
c、Contract performance: For the establishment or performance of contracts to which individuals are parties, where providing personal information to overseas is necessary.
d、HR management: In implementing cross-border human resource management based on legally formulated labor rules and collective contracts, where it is necessary to provide employee personal information to overseas.
e、Personal interests protection: In emergency situations to protect the life, health, and property safety of natural persons, where it is necessary to provide personal information to overseas.
f、Personal information to be transferred less than 100,000 individuals: Where a Non-Critical Information Infrastructure Operator (CIIO) data handler provides personal information of less than 100,000 individuals (excluding sensitive personal information) to overseas since January 1 of the same year.
1.2 Applicable Scenarios for CAC Security Assessment
a、Where a CIIO provides personal information or important data (regardless of quantity) overseas;
b、Where a non-CIIO data handler provides important data overseas;
c、Where a non-CIIO data handler provides personal information of more than 1 million individuals (excluding sensitive personal information) or sensitive personal information of more than 10,000 individuals to overseas since January 1 of the same year.
However, if it is an exempted scenario according to the Provisions, the exemption shall apply.
1.3 Applicable Scenarios for Standard Contract
a、Providing personal information of more than 100,000 individuals and less than 1 million individuals (excluding sensitive personal information) overseas since January 1 of the same year.
b、Providing sensitive personal information of less than 10,000 individuals overseas since January 1 of the same year.
However, if it is an exempted scenario according to the Provisions, the exemption shall apply.
1.4 Special policies of the Free Trade Zones (FTZs)
The Provisions leave space for the special policies in the FTZs. FTZs can develop their own data list that needs to apply the CAC security assessment, standard contract, or the personal information protection certification ("Negative List"). Cross-border transfers of data not on the Negative List are exempt from the application.
2.Substantive Compliance Obligations of Data Handlers Have Not Been Reduced
Although the Provisions provide for several exempted scenarios, it should be noted that the substantive compliance obligations of data handlers under laws such as the Data Security Law and the Personal Information Protection Law have not been reduced. The key concerns are as follows:
a、Inform and obtain separate consent in the cross-border transfer of personal information, and conduct Personal Information Protection Impact Assessment (PIPIA);
b、Implement the obligations of data security protection, take technical measures and other necessary measures to ensure the safety of outbound data. Where a data security incident occurs or may occur, remedial measures shall be taken and timely reports shall be c、made to the provincial CAC and other relevant competent departments;
d、Regulatory authorities will strengthen the supervision of the whole life-cycle of the data cross-border transfer, and if there is a substantial risk in the data cross-border transfer or a data security incident occurs, the data handler will be required to make rectification and eliminate the risks. Those who refuse to make rectifications or cause serious consequences will be held accountable according to the law.
3.Strategies
We suggest companies seizing this opportunity of the Provisions, adopting the following actions:
a、For companies that have not yet carried out data transfer compliance projects, in view of the elimination of uncertainty in the data transfer regulatory policy, it is recommended that companies seize this opportunity, conduct data mapping on the data outbound scenarios as soon as possible, and adopt the appropriate data outbound transfer mechanism. Even if the company falls into the exempted scenario, it also needs to conduct internal compliance demonstration, implement corresponding legal obligations such as informing, consent obtaining and carrying out the PIPIA.
b、For companies that have applied and passed the CAC security assessment or Standard Contract filing, data outbound activities can be carried out according to the previous CAC security assessment or Standard Contract filing results.
c、For those who have applied the CAC security assessment, but have failed or partially failed, the applicability of the Provisions should be discussed. If the Standard Contract filing or Certification can be adopted in accordance with the Provisions, companies can start a new Standard Contract filing or Certification procedure in accordance with the Provisions to replace the CAC security assessment results.
d、For those who have applied the CAC security assessment, but have failed or partially failed, or those who failed the Standard Contract filing, if it falls into the exempted scenarios in accordance with the Provisions, the exemption can be applied on the basis of eliminating the compliance gaps stipulated in the previous CAC review results.
e、For those who have submitted CAC security assessment or Standard Contract filing, and have not yet received results, if they fall into the exempted scenarios in accordance with the Provisions, companies may take the initiative to withdraw. If companies do not take the initiative to proceed, this can also be deemed as a withdrawal by the CAC.
f、For those who have applied the CAC security assessment, but now can apply the standard contract filing according to the Provisions, companies can withdraw the CAC security assessment and switch to the standard contract filing procedure accordingly.

技术驱动法律,专业成就未来