2023年2月24日,国家互联网信息办公室(“国家网信办”)正式发布《个人信息出境标准合同办法》(以下简称“《标准合同办法》”),并随附个人信息出境标准合同(以下简称“标准合同”)的范本,至此《个人信息保护法》(以下简称“《个保法》”)第38条所规定的个人信息出境三大路径已基本明晰:(1)通过国家网信办组织的数据出境安全评估;(2)经专业机构进行个人信息保护认证;(2)与境外接收方签署标准合同并备案。
跨国公司在全球范围内会布局分支机构,基于公司统一管理员工信息的需求,不可避免地会触及员工个人信息合规出境的问题,结合我们的实务经验,很大一部分跨国公司在境内设立的实体承担的主要是市场开拓、营销推广的职责,通常涉及出境的员工数量在1000人以内,一般不会超过1万人。本文将对跨国公司员工个人信息出境的场景与合规痛点进行梳理,提出选择标准合同路径进行跨境传输的理由并总结该路径下公司需开展的主要合规工作。
一、跨国公司员工个人信息出境的场景与合规痛点
1.员工个人信息跨境传输的常见场景有哪些?
员工个人信息的跨境传输关乎跨国公司的命脉,母公司正是通过全球一体化的HR系统管理着其全球员工。否则员工的薪资福利、网络访问权限、员工管理体系、接班人计划以及其他核心功能将无法实现。
境内公司将员工个人信息跨境传输至境外公司的主要形式有两种:其一,境内公司直接向境外公司提供员工个人信息(例如公司邮箱、OA系统);其二,境内公司使用服务器位于境外的HR管理系统(例如Workday、SAP)。
2.员工个人信息出境所面临的合规难点?
(1)告知并获得同意的形式
员工个人信息的跨境传输不仅涉及境内外的不同法人主体,且通常包含敏感个人信息,因此依照个保法的要求,应当告知员工境外接收方的名称、处理目的、处理方式、个人信息的种类等,并取得员工的同意。
《标准合同办法》的最终版本放宽了对雇员个人信息跨境转移的单独同意要求。具体而言,《标准合同办法》规定,只有在处理个人信息的法律依据是基于个人信息主体的同意时,才需要单独同意。如果跨境数据转移是基于其他法律依据,例如为了履行法定职责或义务,则根据《标准合同办法》,个人信息处理者没有义务获得个人信息主体的单独同意。
实务中,由于跨国公司间组织架构、员工规模、管理逻辑的差异,员工单独同意的形式也存在不同,需结合公司的实际情况,定制差异化的员工隐私通知,并对劳动合同、员工个人信息保护政策等公司制度进行升级,以满足合规的要求。
(2)出境个人信息的正当、必要性
实务中,跨国公司对于出境员工个人信息必要性的常见误区之一是,以为只要征得员工同意即可将其个人信息全部出境,从而忽视了对出境个人信息最小必要原则的遵循。例如,总部为实现员工薪酬全球管理的目的,将其姓名、职级、银行账户信息等个人信息传输出境符合薪酬管理目的的最小必要,但该场景下向境外提供员工的性别、家庭信息则与薪酬管理目的无直接关联。
二、为什么选择以标准合同出境?
由于触发数据出境安全评估的门槛较高,适用主体和场景有限,而相较于个人信息保护认证,标准合同具备如下优势:
(1)高效便捷,合规成本较低。生效的标准合同仅需履行备案手续,完成周期显著短于数据安全评估路径的申报审批周期(5+7+45+15个工作日),对于有迫切需求的跨国公司内部的员工个人信息的传输场景而言,落地性更强、效率更高。
(2)标准合同是国际上运用最为广泛的个人信息出境路径。我国的标准合同借鉴了欧盟《统一数据保护条例(GDPR)》的成熟做法,便于跨国公司内部合规制度的衔接。例如,跨国公司基于搭建全球的合规隐私体系的需求,在已有GDPR或本国个人信息保护立法的合规框架下,为了将中国法下的个人信息保护合规要求融入全球合规框架中,会倾向于选取在衔接上更为顺畅的标准合同路径。
(3)开放灵活的争议解决方式,不仅允许缔约双方在诉讼和仲裁之间自由选择,且未禁止双方对选国际仲裁机构的选择。通常,境外公司更倾向于选择具备国际知名度和普通法背景的仲裁机构,该条款的设计不仅解决了国内法院判决在境外承认和执行难的痛点,也更符合境外公司对争议解决方式的选择。
综上,对于数据体量较小、风险较低的跨国公司内部员工数据出境的场景而言,选用标准合同路径更为适宜。
三、跨国公司以标准合同形式出境的,需开展哪些工作?
(一)事前:前期准备工作
1.数据盘点
由于标准合同路径使用条件的限制,在跨国公司员工个人信息出境的场景下,境内公司首先需要对自身的基本情况进行梳理,以判定是否达到安全评估的门槛,包括:是否构成关键信息基础设施运营者(CIIO);是否处理100万人以上个人信息;是否在最近两个自然年度内累计出境10万人以上个人信息或1万人以上敏感个人信息。落入以上任一种情形,将直接触发安全评估,无法使用标准合同路径。
2.完成个人信息保护影响评估(PIA)
(1)成立PIA工作小组;
(2)自行开展或聘请第三方机构(如律师事务所)协助开展;
(3)PIA评估涉及的重点事项:
a.处理目的、范围、方式等是否合法、正当、必要;
b.出境信息的规模、范围、种类、敏感程度对员工个人权益的影响及风险等级;
c.境外接收方能否保障出境个人信息的安全,例如境外收受方的数据安全管理能力、技术保护措施是否与出境风险等级相匹配;
d.是否向员工提供了畅通的个人信息权益维权渠道等。
(4)制作个人信息保护影响评估报告(至少保存三年)。
(二)事中:签署标准合同
鉴于标准合同正文部分不得随意修改,且双方签署的其他合作协议不得与标准合同相冲突,因此跨国公司内部在签署标准合同之前应特别注意协议间的冲突与兼容,例如:校验不同协议之间的兼容性,尤其是各方权利义务是否冲突、法律适用、监管应对责任等。
(三)事后:后期管理监督
1.标准合同的备案
(1)备案材料:生效的标准合同及PIA报告;
(2)备案流程:自标准合同生效之日起10个工作日内向所在地省级网信办备案;
(3)重新备案:在标准合同有效期内出现下列情形之一的,需重新开展PIA,补充或者重新订立标准合同,并履行相应备案手续:
a.向境外提供个人信息的目的、范围、种类、敏感程度、方式、保存地点或者境外接收方处理个人信息的用途、方式发生变化,或者延长个人信息境外保存期限的;
b.境外接收方所在国家或者地区的个人信息保护政策和法规发生变化等可能影响个人信息权益的;
c.可能影响个人信息权益的其他情形。
(4)备案周期:根据我们的实务经验,完成备案全流程预计需要3-4个月。
2.持续监督义务
(1)持续监督境外接收方的处理活动,留存审计记录;
(2)建立并维持适当渠道,及时响应个人信息主体的个人行权、提供合同副本等请求;
(3)接受监管机构的询问,提供相关信息,配合监督检查等。
总的来说,针对前述数据体量较小、风险较低的跨国公司而言,触发数据出境安全评估的可能性较低,订立标准合同或开展个人信息保护认证是更为适宜的两条出境路径。但综合考量个人信息保护认证路径现阶段的落地性、合规成本、境外主体的接受程度等,我们认为,签署标准合同是现阶段更适合跨国公司跨境传输员工个人信息的合规路径。
英 文 版
Chinese SCCs: Guiding the Cross-Border Transfer of Employee PI
This article provides practical guidance for the outbound transfer of employee personal information for multinational corporations.
1. Legal Background
On 24 February 2023, the Cyberspace Administration of China ("CAC") officially released the final version of the Measures for Standard Contract for the Outbound Transfer of Personal Information (the "Standard Contract Measures"), which includes a template Standard Contract, so that the three major routes for the cross-border transfer of personal information as stipulated in Article 38 of the Personal Information Protection Law ("PIPL") are clear:
(1)passing the mandatory security assessment organized by the CAC ("Security Assessment");
(2)obtaining a personal information protection certificate issued by a qualified institution ("Certification"); and
(3)concluding and filing the Standard Contract formulated by the CAC with the overseas recipient ("Standard Contract")
Multinational Corporations ("MNCs") always lay out branches around the world, based on the company's unified management of employee personal information needs, which will inevitably involve with the issue of the cross-border transfer of employee personal information. Based on our practical experience, a large proportion of MNCs set up entities in China mainly for marketing, and the number of employees involved in the personal information cross-border transfer is usually less than 1,000 and not more than 10,000.
In this article, we will review the scenarios and compliance sore points for MNCs exporting employee personal information, present the reasons for choosing the Standard Contract route and summarise the compliance work that MNCs need to carry out under this route.
2. Scenarios and Compliance sore points of export of employee personal information by MNCS
1.What are the typical scenarios for the cross-border transfer of employee personal information?
The cross-border transfer of employee personal information is the lifeblood of a multinational company, whose parent company manages its global workforce through an integrated global HR system. Without these transfers, the payment benefits, network access, staff management system, succession planning and other core functions would not be possible.
There are two main forms of providing employee personal information abroad: (1) where a domestic company provides employee personal information directly to the foreign company (e.g. via company email, OA system); (2) where a domestic company uses an HR management system with servers located outside the country (e.g. Workday, SAP).
2.What are the compliance difficulties for the cross-border transfer of employee personal information?
(1)Forms of notification and obtaining consent
The cross-border transfer of employees' personal information not only involves with different legal entities within and outside of China, but also usually contains sensitive personal information. Therefore, in accordance with the requirements of PIPL, employees should be informed of the name of the overseas recipient, the purpose of processing, the method of processing, the type of personal information, etc., obtaining consent from employees is necessary as well.
The final version of the Standard Contract Measures eases the separate consent requirement for the cross-border transfer of employee personal information. Specifically, the Standard Contract Measures states that separate consent is only required where the legal basis for processing personal information is based on the consent of the individual. Where the cross-border data transfer is based on other legal bases, such as for the performance of statutory duties or obligations, there would be no obligation under the Standard Contract Measures for the personal information processor to obtain separate consent from the individual.
In practice, due to the differences in organizational structure, employee size, and management logic among MNCs, the form of consent obtained varies. It is necessary to customize a differentiated employee privacy notice by the actual situation of the company, and to upgrade the company system such as the employment contract and employee data protection policy to meet the requirements of compliance.
(2) The legitimacy and necessity of the cross-border transfer of employee personal information
In practice, MNCs often mistakenly believe that they can export all personal information of their employees as long as they have their consent, thus neglecting to follow the principle of necessity. For instance, it is minimally necessary for a head office to require the domestic company to transfer personal information such as names, grades and bank accounts abroad for global payment management, whereas gender and family information is not directly related to the above purposes.
3. Why choose the Standard Contract route?
Due to the high threshold for triggering Security Assessment, the applicable subjects and scenarios are limited as well, Standard Contract has the following advantages compared to Certification:
1. Efficient and convenient, with lower compliance costs. An executed standard contract basically only requires filing, whose cycle is significantly shorter than the reporting and approval cycle of the Security Assessment (5+7+45+15 working days), making it easier to implement for the MNCs;
- The standard contract is the most widely used international route for the cross-border transfer of personal information. Standard Contract draws on the proven practices of the GDPR and facilitates the convergence of compliance systems within MNCs. For instance, based on the need to build a global compliance privacy system, MNCs prefer standard contract route to integrate the personal information protection compliance requirement under PRC law into the global regulatory framework under the GDPR or the compliance framework of their own personal information protection legislation.
- Open and flexible dispute resolution, which not only allows the parties to choose between litigation and arbitration, but also open the choose of international arbitration institution. The design of this clause not only solves the problem of the recognition and enforcement of domestic court decisions abroad, but also meet the preferred choice of the dispute resolution method by overseas companies.
In summary, the Standard Contract route is more suitable for the scenario of cross-border transfer of personal information of employees within MNCs with small data volume and low risk..
4. What are the processes to complete the Standard Contract route?
(i)Preliminary work
1. Data sorting
Due to the restrictions on the conditions of using the standard contract route, in the case of cross-border transfers of employee personal information, the domestic company needs to sort out its basic situation to determine whether it meets the threshold for security assessment, including whether the company is a critical information infrastructure operator (“CIIO”); whether the company has handled personal information of more than 1 million people, whether the company has transferred personal information of a total of more than 100,000 or sensitive personal information of a total of more than 100,00 abroad in the last two natural years. Otherwise, the security assessment would be triggered and the standard contract route cannot be used.
2. Completion of Personal Information Protection Impact Assessment ("PIA")
(1) Establishing a PIA working group;
(2) Carrying out the PIA on its own or hiring a third-party agency (such as a law firm);
(3) Key matters involved in the PIA:
a. Whether the purposes and methods of processing are lawful, legitimate and necessary;
b. The impact of the size, scope, type and sensitivity of the outbound information on individuals' rights and interests and security risks;
c. Whether the protection measures taken are lawful, effective, and commensurate with the degrees of risks, such as whether the data security management capability and technical protection measures of the overseas recipient match the degrees of risks;
d. Whether there are smooth channels for individuals to protect their rights and interests of their in personal information, etc.
(4) Produce a PIA report (PIA reports and records on processing shall be preserved for at least three years)
(ii) Concluding a standard contract
Given that the terms of a standard contract cannot be modified and that other cooperation agreements signed by the parties cannot conflict with the standard contract, special attention should be paid to conflicts and compatibility between agreements within MNCs before concluding a standard contract, e.g. to check the compatibility of different agreements, in particular the conflict of rights and obligations of the parties, the application of the law and the responsibility for regulatory response, etc.
(iii)Supervision and management
1. Post filing
(1) Materials: the executed standard contract and the PIA report;
(2) Process: within 10 working days from the effective date of the standard contract, undergo recordation formalities with the cyberspace administration of the province or equivalent where it is located;
(3) Re-filing: under any of the following circumstances during the validity of the standard contract, MNCs shall conduct a new PIA, retroactively conclude a standard contract or conclude a new one, and perform the corresponding recordation procedures:
a. There is any change to the purpose, scope, type, sensitivity, manner, or storage location of personal information transferred aboard, or any change in the purpose and method of processing personal information by the overseas recipient, or an extension of the overseas retention period of personal information;
b.There is any change to personal information protection policies and regulations in the country or region where the overseas recipient is located, which may affect the rights and interests in personal information;
c. Other circumstances that may affect the rights and interests in personal information.
(4) Filing cycle: According to our practical experience, it is expected to take 3-4 months to complete the above procedures.
2. Continuous monitoring
(1) Continuously monitoring the processing activities of the overseas recipient and keeping audit records;
(2) Establishing and maintaining appropriate channels to respond promptly to requests from personal information subjects for individual exercise of rights, provision of copies of contracts, etc;
(3) Accepting enquiries from regulators, providing relevant information, cooperating with supervision and inspection, etc.
In general, for the aforementioned MNCs with smaller data volumes and lower risks, it is less likely to trigger a security assessment, and concluding a standard contract or carrying out certification are two more appropriate routes. However, taking into account the feasibility of the Certification, the cost of compliance and the acceptance of overseas entities, we believe that the Standard Contract route is more suitable for MNCs providing employee personal information abroad at this stage.
