China: The Top 10 Trends and Issues in Data Protection in 2023

来源:君合法律评论

文章摘要
Contents Introduction 1. Basic data regime is built up gradually 2.

Contents
Introduction



  1. Basic data regime is built up gradually

  2. Rules governing algorithms become increasingly thorough and specific

  3. Rules on data export implement in practice with self-assessment becoming a focus of internal compliance work

  4. Regulators strengthen cybersecurity review efforts

  5. More specific rules and standards will provide guidance in the field of data governance

  6. Law enforcement efforts will continue and law enforcement processes become more specific

  7. Security certification for data security is encouraged

  8. Local data legislation will continue while their implementation remains to be seen

  9. Civil actions and public interest litigation related to personal information will increase

  10. Data security remains a focus in compliance work and establishing data protection systems become critical
    Conclusion
    Introduction
    2022 was the first year after the entry into force of the Personal Information Protection Law (PIPL) and the Data Security Law (DSL). Legislation and law enforcement in the field of data protection have rapidly developed and been promoted. The CPC Central Committee and the State Council issued 20 policy initiatives related to building basic systems for data element.1 Regulators began to implement data protection and data export rules in practice. Institutions and enterprises in various sectors adjusted and reinforced their data compliance efforts accordingly. Some enterprises were punished by regulatory authorities for violating the new regulations. In this article, we have reviewed the important developments in 2022 and summarize the top 10 noteworthy trends and issues related to data protection, cybersecurity legislation and supervision in 2023.
    1.Basic data regime is built up gradually
    On December 19, 2022, the CPC Central Committee and the State Council issued the Opinions on Building Basic Data Regimes to Make Better Use of Data (the “Opinions”), setting forth 20 policies on the initial building of basic data regimes in terms of property rights, circulation and transaction, proceeds distribution and security management. According to the Opinions, basic data regimes consist of data property rights, data circulation and transactions, data proceeds distribution and data security management. In terms of security management, the Opinions engaged qualified sectors to take the lead in system building, technical capabilities, development and other aspects. This was to innovate internal data compliance rules and policies, and to explore and improve basic data regimes.
    The exploration of basic data regimes will continue in the future, and the relevant legislation will also be carried out as set out by the Opinions. The establishment and improvement of basic data regimes will help to promote data compliance and efficient data circulation, so as to fully realize the value of data.
    2.Rules governing algorithms become increasingly thorough and specific
    In 2022, the regulation of algorithm technology and services became increasingly thorough. The Cyberspace Administration of China (CAC) and other authorities issued the Regulations on Algorithm-Based Recommendations in Internet Information Services and the Regulations on Deep Synthesis in Internet Information Services, which impose obligations upon algorithm-based recommendation service providers, including those providing deep synthesis service. To protect algorithm-related security on Internet platforms, nine authorities including the State Administration of Market Regulation (SAMR), the CAC, and the Ministry of Industry and Information Technology (MIIT) jointly issued opinions requiring platform operators to build algorithm security systems for Internet information services. The CAC released the first batch of registered algorithm services and launched a special action title the "2022 Qinglang Algorithm Integrated Management". In response to these regulatory requirements, some well-known apps launched opt-out buttons in March, allowing users to disable personalized recommendations.
    We expect that legislation and enforcement in the field of algorithm will continue in 2023. More specific regulatory requirements may be imposed upon app services for different types of algorithm technologies, to provide specific compliance guidance for enterprises using algorithm technologies and providing algorithm services. With topics such as ChatGPT continuing to be hotly debated in early 2023, it can be expected that further exploration of the regulation of related algorithms will also continue and deepen.
    3.Rules on data export implement in practice with self-assessment becoming a focus of internal compliance work
    “Data export” was one of the hot issues in the field of data law in 2022. The CAC issued the Measures for Security Assessment of Data Export and the Guidelines for the Application of Data Export Security Assessment (Version 1), specifying the application thresholds, procedures, and the templates for application materials, for the security assessment of data exports. The CAC also issued the Provisions on Standard Contract for the Export of Personal Information (Draft for Comments), but the standard contract is still being finalized and has not yet come into force. The National Information Security Standardization Technical Committee (TC260) issued the Guidelines for Cybersecurity Standards in Practice - Specification for the Security Certification of Cross-Border Processing of Personal Information (the “Specifications”), and then revised and issued the second version of these Specifications.2 The Specifications set forth the basic principles to be followed in the cross-border processing of personal information, and the rules for personal information protection and safeguarding of personal information subject rights by data transferors and overseas recipients in the cross-border transfer activities.
    The above regulations (drafts) clarify the implementation rules to a certain extent of the “three paths for cross-border transfer of personal information” under the PIPL, and guide data processors to carry out cross-border personal information processing activities in a regulated manner. We expect that more detailed, specific and clear data export rules will be issued in 2023 to support the implementation of the "three paths" for data export. Enterprises will also carry out data export compliance work internally and gradually develop internal procedural control systems in this regard.
    4.Regulators strengthen cybersecurity review efforts
    In June 2022, the Cybersecurity Review Office announced the launch of a cybersecurity review of CNKI. In July, the CAC released the result of the cybersecurity review of Didi. Didi was fined RMB 8.026 billion for violating the Cybersecurity Law, the DSL and the PIPL, and the responsible persons concerned were each fined RMB 1 million. The CAC said that the next step will be to strengthen law enforcement and crack down on illegal acts in the fields of cybersecurity, data security and personal information by imposing fines, ordering the suspension of relevant businesses, closing websites and punishing responsible persons. The CAC further stressed that it would increase the exposure of typical cases of cybersecurity review to serve as a warning and provide guidance.3
    The implementation of the revised Measures for Cybersecurity Review at the beginning of 2022 has lied out thorough requirements on the data processing, the procurement of network products and services and overseas listings triggering the threshold for the review. Article 16 of the Measures for Cybersecurity Review stipulates that, if it is determined by the regulatory authority that network products or services, or data processing activities affect or may affect national security, the Cybersecurity Review Office shall report them to the CAC for approval and conduct a review. The above two major cases also demonstrated the position of the regulatory authorities to strengthen the supervision on important and sensitive data and indicated that cybersecurity reviews will continue with a view to protecting cybersecurity of the nation.
    5.More specific rules and standards will provide guidance in the field of data governance
    In 2022, data protection and cybersecurity laws and regulations related to specific sectors were further promulgated, especially for highly regulated sectors. For example, the Administrative Measures for Cybersecurity of Medical and Healthcare Institutions, the Administrative Measures for Cybersecurity in Power Industry, and the Administrative Measures for Data Security in the Industry and Information Technology Sector (for Trial Implementation). The CAC also promulgated the Regulations on the Protection of Minors in Cyberspace (Draft for Comments) for the sake of minor’s protection. Various standards and guidelines related to information protection and security were also drafted, formulated and released, such as the Guidelines for Identification of Important Data (Draft for Comments) as well as several draft national standards focused on privacy policies, apps installed on mobile devices, and the review and management of apps to be launched by app stores.4
    We expect that in 2023, regulators in different sectors and fields will continue to promulgate data protection rules and guidelines based on the characteristics of their particular sectors and fields. These regulatory rules and guidelines will tend to be more specific and practical and will provide more explicit compliance guidance for market participants.
    6.Law enforcement efforts will continue and law enforcement processes become more specific
    In 2022, regulations and law enforcement in the field of personal information protection was further reinforced. Taking app regulation for example, the law enforcement is carried out primarily by regular and routine notifications of violating apps and supplemented by launching special rectification actions such as "Look Back" and "Security Inspection".5
    Furthermore, the CAC proposed a revised draft of the Cybersecurity Law. The revised draft increases the fines for endangering network operation security or content control and increases the punishment upon the responsible persons. For illegal acts related to personal information, the revised draft suggests applying the legal responsibilities for personal information violation under the PIPL. In addition, the CAC and the MIIT published the revised drafts of their administrative law enforcement procedures respectively for a public consultation. The above developments reflect the efforts to adapt to the development in the field of data and information and the implementation of the Administrative Penalty Law.
    With the future implementation of the above laws and regulations, the authority, scope and procedures for law enforcement by the cyberspace administration and the industry and information technology administration in the fields of cybersecurity, data security and personal information protection will become clearer and more specific. For the supervision and inspection of network law enforcement, regulators will further increase their efforts and improve their work systems.
    7.Security certification for data security is encouraged
    In June and November 2022, the CAC and the SAMR respectively issued announcements on the implementation of data security management certification and the implementation of personal information protection certification and then issued the Implementation Rules for Data Security Management Certification and the Implementation Rules of Personal Information Protection Certification. These certifications are not mandatory, but enterprises are encouraged to obtain these certifications as proof of their data security management compliance and their personal information protection capacity. They can also identify relevant data security management risks and those risks related to personal information processing activities during the certification process, so as to carry out corresponding rectification and improvements. In July, the SAMR issued the Opinions on the Implementation of Cybersecurity Service Certification (Draft for Comments), which is intended to implement uniform cybersecurity service certification launched by the government and encourage network operators to accept the results of such national cybersecurity service certification. The TC260 released the Security Certification Specifications for Cross-border Processing of Personal Information (V2.0) in December, which is only applicable to the export of personal information that does not trigger the threshold for data export security assessment.
    It can be seen from these announcements and rules issued in 2022 that the government successively promoted the implementation of a series of certifications in network data processing, personal information processing, personal information export and cybersecurity services and encouraged enterprises to comply with relevant regulations through such certifications. "Certification" is expected to become one of the ways for different market participants to carry out compliance work in the future. While certification rules, such as those regarding the determination of certification bodies, conditions and procedures for certification application, need to be further improved and refined.
    8.Local data legislation will continue while their implementation remains to be seen
    After the gradual improvement of data legislation at the national level, some provincial and municipal governments issued local data regulations based on their local situations. According to incomplete statistics, as of January 2023, local regulations relating to data in 24 provinces and cities including Shanghai, Guangdong, Shenzhen, Zhejiang, Shandong, Anhui, Jilin, Shanxi, Hainan, Tianjin, Guizhou and Shenyang had been officially issued or implemented. For example, the Data Regulations of Shenzhen Special Economic Zone, which came into force on January 1, 2022, was the first basic and comprehensive legislation in the field of data in China. The Regulations of Zhejiang Province on Public Data, which came into force on March 1, 2022, was the first local regulation to govern public data in China.
    In 2023, more provincial and municipal governments may promote local data legislation. It has not been long since the implementation of these local data regulations, and the specific implementation and the impact on enterprises in different regions remains to be seen.
    9.Civil actions and public interest litigation related to personal information will increase
    It has been more than two years since the implementation of the Civil Code. Civil litigation cases relating to personal information protection are increasingly common in judicial practice. For example, a dispute case over privacy and personal information protection is included in the recent representative cases (the second batch)6 published by the Supreme Court, in which people's courts apply the Civil Code in the hearing of cases. The public interest litigation cases relating to personal information protection that are handled by procuratorates also tend to increase. According to the information released by the Supreme People's Procuratorate on 10 November 2022, 5,188 cases of public interest litigation in the area of personal information protection have been filed from January to September 2022, more than double the number of cases heard in the whole year of 2021. Local Internet courts, which usually deal with personal information protection disputes, often publish representative cases related to personal information.
    In view of the rapid development of the digital economy and the increase of citizens' awareness of personal information protection, it is expected that there will be more civil litigation cases relating to personal information and privacy protection in the future. Since personal information infringement cases often affect public interest because they involve large-scale violations of personal information, public interest litigation related to personal information may also become more common in the future, which demands the continued attention.
    10.Data security remains a focus in compliance work and establishing data protection systems become critical
    While digitalization brings many conveniences and opportunities to society and the economy, it also brings serious potential risks of network security and information violations. These risks affect not only the safety of personal property and privacy, but may also endanger public interests and national security. In 2022, several data-related security incidents were reported. In view of the network security trends in 2023, the risk of network attacks faced by enterprises still may not be underestimated, and the prevention of data leakage risks will remain a focus of the data compliance work. We suggest that enterprises take reasonable and appropriate measures to establish data security management systems based on their own conditions, to protect the security of data throughout its life cycle.
    Conclusion
    The above is our perspective for 2023 based on the major legislative and law enforcement events in the data field over the past year. In 2023, China will continue to stimulate the vitality of data and develop the digital economy. China's data protection regulatory system will be further improved and developed. We will continue to pay close attention to legislative developments, regulatory changes and progress in the field of data protection and cybersecurity to together with enterprises and provide timely and effective compliance advice to our clients.
    1.http://www.gov.cn/zhengce/2022-12/19/content5732695.htm
    2.Security Certification Specifications for Cross-border Processing of Personal Information (V2.0)
    3.http://www.cac.gov.cn/2022-07/21/c
    1660021534364976.htm
    4.Please refer to the Information Security Technology – Requirements on Privacy Agreements for Internet Platforms and Products and Services (Draft for Comments), the Information Security Technology – Guidelines for Management of Personal Information Processing Activities by Mobile Internet Applications (Apps) of Mobile Intelligent Terminal (Draft for Comments) and the Information Security Technology – Guidelines for Compliance Review and Management of Personal Information Processing Activities by Apps at App Store (Draft for Comments) for details.
    5.According to statistics, the CAC and its local cyberspace administrations investigated and punished 294 apps conducting illegal processing of personal information in 2022 and removed 420 illegal apps from the app stores. In the first half of 2022, the MIIT organized the inspection and detection of 1.18 million apps, ordered 780 apps to be rectified, and publicly notified 255 apps that failed to be rectified as required. In the second half of 2022, the regulators required non-conforming 227 apps (SDKs) to make rectifications and publicly notified 47 apps (SDKs) that failed to be rectified as required. At the local level, local communication administrations and cyberspace administrations have also successively launched regulatory actions on apps for personal information security protection based on local conditions, and publicly notified the relevant apps that were infringing on users’ rights and had security risks.
    6.https://www.court.gov.cn/zixun-xiangqing-386521.html

技术驱动法律,专业成就未来