个人信息出境重要规则出台——《个人信息出境标准合同备案指南》要点简析(中英)

来源:北京植德律师事务所

文章摘要
背景及前言 Background and Preface 2023年5月30日,国家互联网信息办公室公布正式公布《个人信息出境标准合同备案指南(第一版)》(以下简称“《备案指南》”)。

背景及前言 Background and Preface
2023年5月30日,国家互联网信息办公室公布正式公布《个人信息出境标准合同备案指南(第一版)》(以下简称“《备案指南》”)。《备案指南》明确了标准合同的备案等要求,为6月1日起执行标准合同的备案工作提供了指引。同时,根据此前发布的《个人信息出境标准合同》(“《标准合同办法》”),不符合规定的个人信息出境活动,将给予6个月的整改期。植德律师希望通过对相关问题的分析和解读,为企业在实践中利用标准合同这一合规路径进行个人信息出境提供帮助,供阅览参考。
On May 30, 2023, the Cyberspace Administration of China (the “CAC”) issued the Guidelines for filing the Standard Contract for Cross-border Transfer of Personal Information (First Edition) (the “Guidelines”). The Guidelines provides the detail requirements for filing the record of the standard contract for the execution of the Measures for the Standard Contract for Cross-border Transfer of Personal Information (the “Standard Contract Measures”) which has come into force on June 1, 2023. Meanwhile, a 6-month rectification period has been given for previous activities of cross-border personal information transfer that did not comply with the Standard Contract Measures.
1.《个人信息出境标准合同办法》于2023年6月1日起生效
I. The Standard Contract Measures has come into effect on June 1, 2023
《个人信息出境标准合同办法》于 2023年6月1日起生效实施,同时针对此前不符合规定的个人信息出境活动,给予了6个月的整改期。因此,满足《标准合同办法》要求且希望通过标准合同备案进行个人信息出境的企业,相关整改工作(包括个人信息保护影响评估、标准合同的订立以及备案等),均应于 2023年12月1日前完成,且具体工作开展事项需符合《个人信息出境标准合同备案指南(第一版)》的要求。
同时满足以下四点的个人信息处理者可通过标准合同备案方式向境外提供个人信息:
(一)非关键信息基础设施运营者;
(二)处理个人信息不满100万人的;
(三)自上年1月1日起累计向境外提供个人信息不满10万人的;
(四)自上年1月1日起累计向境外提供敏感个人信息不满1万人的。
The Measures for the Standard Contract for Cross-border Transfer of Personal Information (the "Standard Contract Measures”) has come into force on June 1, 2023, and a 6-month rectification period has been given for previous activities of cross-border personal information transfer that did not comply with the Standard Contract Measures. Therefore, enterprises that meet the requirements of the Standard Contract Measures and wish to use standard contracts to transfer their personal information abroad shall complete the relevant rectification work (including the impact assessment on the protection of personal information, the conclusion and record-filing of standard contracts) before December 1, 2023. The enterprise’s relative work re the record-filing of standard contracts shall follow the requirement of the Guidelines.
Any personal information processor that meets all the following four conditions may provide personal information abroad by signing a standard contract and filing:
It is not a CIIO.
The personal information processed by it is less than 1 million people.
The personal information provided aboard by it is less than 100,000 people cumulatively since January 1 of the previous year.
The sensitive personal information provided aboard by it is less than 10,000 people cumulatively since January 1 of the previous year.
2.利用标准合同进行个人信息出境的基本步骤和流程是怎样的?
II. What are the basic steps for cross-border transfer of personal information by using a standard contract?
满足《标准合同办法》规定的企业,应开展如下4步的合规工作:
(一)事前PIA:个人信息处理者向境外提供个人信息前,应当开展个人信息保护影响评估(PIA)。
(二)合同订立及材料准备:严格按照标准合同模板订立,允许约定其他条款,但不得与标准合同相冲突。同时注意在“双向传输”的情况下(如中欧之间)是否存在与境外国/地区的法律或合同文本内容的冲突。
(三)备案:在标准合同生效之日起10个工作日内向所在地省级网信部门备案,备案时应同时提交标准合同、个人信息保护影响评估报告以及其他程序性文件。
(四)重新评估及缔约、备案:在标准合同有效期内出现需要重新评估的情形时,个人信息处理者应当重新开展个人信息保护影响评估,补充或者重新订立标准合同,并履行相应备案手续。实践中,补充订立可能是更为灵活的方式,但需要注意,即使是补充订立,仍需“重新”开展个人信息保护影响评估。
Enterprises that meet the requirements of the Standard Contract Measures shall carry out the compliance work in the following four steps:
Personal information protection impact assessment (PIA): the personal information processor shall conduct a personal information protection impact assessment before transferring personal information abroad.
Contract conclusion and materials prepare: the personal information processor shall conclude the standard contract in strict accordance with the standard contract template. Though other terms are allowed, they cannot conflict with the standard contract. Meanwhile, we would like to draw your attention on the potential conflicts in laws or regulations between China and other overseas country/district in case of two-way transfer between China and other places (ie. EU).
Filing the record: within 10 working days after the effective date of the standard contract, the personal information processor should submit the standard contract, the PIA report and other procedure materials when filing the record at the provincial cyberspace administration.
Re-evaluation, re-conclusion, and re-filing: the personal information processor shall re-conduct the PIA, supplement or re-conclude the standard contract and go through the relevant filing formalities when re-evaluation is required during the validity period of the standard contract. In practice, supplementary conclusion may be a more flexible approach, but it should be noted that even if the supplementary conclusion is done, a PIA is still required to be conducted "again".
3.《个人信息出境标准合同备案指南(第一版)》于2023年5月30日发布
III. The Guidelines was released on May 30, 2023
2023年5月30日夜间,网信办发布了《备案指南》,列明了更详细的备案材料及流程,包括《个人信息保护影响评估报告(模板)》《经办人授权委托书(模板)》《承诺书(模板)》等,我们梳理了以下《备案指南》所体现的合规要点:
(一)备案结果。企业通过标准合同备案路径进行个人信息跨境传输,并不意味着简单的递交材料即可满足合规要求,备案结果分为通过、不通过,即企业仍有可能面临备案材料不合规而不予通过的风险。另外,对比网信办之前发布的《数据出境安全评估申报指南(第一版)》,本次发布的《备案指南》的要求与前者基本保持一致,这无疑将大大增加企业开展标准合同备案工作的难度和成本。
(二)个人信息出境的场景列举。关于个人信息出境的场景,包括不限于将个人信息传输、存储至境外,境外人员查询、调取、下载、导出境内个人信息等,故即使企基于业务实际情况并未有对应境外的个人信息接收方,但使用了服务器部署在境外的工具,如Workday、SAP系统等,仍有可能构成个人信息出境并需履行备案流程。
(三)关于备案主体确定。备案主体面临穿透要求,需要准确确定备案主体。《备案指南》要求说明备案主体的股权结构、实际控制人以及境内外投资情况,为此备案主体的确定是一大难点,特别是集团公司,下属多个子公司,涉及多个业务目的和范围。同时,《备案指南》再次强调了不得采取数量拆分等手段,故企业在选择备案主体时需谨慎确定。
(四)个人信息出境场景筛查。《备案指南》明确要求对个人信息出境业务和信息系统情况进行描述,因此企业需要按照《备案指南》确定的“业务基本情况——数据资产情况——信息系统情况——数据中心(云服务)情况——数据出境链路情况”的逻辑对其个人信息出境场景进行盘点。
(五)补充/重新备案。建议企业建立个人信息出境情况的监测和预警机制,实时关注向境外提供个人信息的目的、范围、种类、敏感程度、方式、保存地点及期限或者境外接收方处理个人信息的用途、方式等情况,跟踪境外接收方所在国家/地区的个人信息保护政策法规,如上述情况发生变化、可能触发重新评估、补充订立/备案要求的,需及时采取相应的措施。
(六)备案材料。备案材料更为具体且均提供模板,包括个人信息出境标准合同、个人信息保护影响评估报告,以及其他程序性文件如统一社会信用代码证件影印件、法定代表人身份证件影印件、经办人身份证件影印件、经办人授权委托书、承诺书等。此外,经办人授权委托书明确了不可以转委托,为此未来只能特殊情况下撤销委托,重新委托。
(七)关注企业数据安全能力。如存在处罚记录,存在无法通过风险。监管看重过往数据安全能力,为此频繁被曝光、下架、受处罚,将面临无法通过备案的风险,为此“打铁还需自身硬”,需要不断夯实自身数据安全能力。
(八)关注个人信息出境的具体内容、形式,不可“一简了之”。《个人信息保护影响评估报告》(模板)就出境方式、出境链路、出境个人信息情况(规模、种类、敏感程度等)等进行了详细要求,数据出境目的也需具体阐述,不可“一简了之”。这也意味着企业需要整合内部资源,汇总数据出境有关的具体详细信息;
(九)评估情况需详细说明,整改措施和效果是重点。企业需重点说明发现问题、风险隐患,及对应采取的整改措施、整改效果,这一要求需要全部展现在监管面前,消除监管顾虑。这一点值得重视,也是实务中的难点。即对于整改措施,是否可以得到监管认可,监管尺度如何,值得长期跟踪了解。
(十)第三方机构参与评估需盖章,数据出境专家支持企业高效完成数据出境评估工作。这里的第三方机构我们理解包括了律师事务所、数据安全公司或相关咨询公司等。相信企业在数据出境过程中,会越来越多选择专业的数据出境专家,为其提供专业咨询服务,提高审批通过效率,增加说服力。
(十一)答疑渠道公示。有问题可以咨询网信办的电话、邮箱,建议提前做足功课,但实践中该等咨询可能效率不高。
(十二)申报形式目前以线下进行。关于具体申报形式,此前市场上有诸多猜测且预计可能以线上备案的方式进行,但根据《备案指南》,目前大概率将以线下申报纸质材料加电子版材料的形式进行。对此,企业应当注意的是,首先应当确认对应的省级网信办联系方式,其次应当注意线下备案可能导致的潜在排队问题,提前做好规划。
(十三)披露个人信息保护机构。《个人信息保护影响评估报告》其中一条要求披露个人信息保护机构信息,《个人信息保护法》要求处理个人信息达到网信办规定的数量时,应当指定个人信息保护负责人,对于此处何为“网信办规定的数量”,暂未有明确规定,但这一信号也意味着,中国在数据出境监管领域,“DPO”成为了必须设置岗位,各类企业应当尽快建立并完善内部数据治理架构。
In the evening of May 30, 2023, the CAC released the Guidelines, which provides more detailed filing materials and requirements, including the Report of Personal Information Protection Impact Assessment ("PIA Report”) (Template), Power of
Attorney for the Handler (Template), the Commitment Letter (Template) and etc. Meanwhile, the Guidelines have also responded some frequency asked questions in its instruction part. We have sorted out below major notable issues/compliance checkpoints based on the analysis of the Guidelines:
Filing Result. Filing the standard contracts to guarantee the compliance of personal information cross-border transfer does not mean just submitting relevant materials to the provincial CAC is ok. The result includes pass and fail, which means that the enterprises still have the risk of failing to pass the filing after the materials review of provincial CAC. Besides, the requirements specified in the Guidelines are highly similar to that in the Declaration Guidelines for Data Cross-border Transfer Security Assessment (First Edition), which will definitely increase the difficulties to carry out relative work and obtain a pass result.
What is personal information cross-border transfer? The scenarios of personal information cross-border transfer include without limitation the enterprises transferring/storing personal information to overseas entities, the overseas entities visit, recall, download or export the personal information, which means that once deploy the system/platform such as Workday and SAP with servers outsides China, the enterprises may also be required to follow the Guidelines and prepare filing work.
How to choose the filing subject? The Guidelines requires to disclose the shareholding structure, actual controller and the (inbound & outbound) investment situation of the filing subject. As to group companies, since the data transfer may involve multiple entities, BUs, systems, etc. in the group, it is critical to consider whether the group splits the quantity of personal information and to identify the suitable filing party.
Sort out the cross-border personal information transfer scenarios. The logic of cross-border personal information transfer scenario mapping is “business basic status – data assets status – information system status – data center (cloud service) status –outbound data link”. Data exporter should prepare the data outbound facts in its PIA Report in line with such logic to make sure CAC can clearly understand the business and system situation involving cross-border data transfer.
Re-conclusion or re-filing. It is recommended to establish a mechanism for monitoring the cross-border transfer of personal information, pay attention to the purpose, scope, category, sensitivity, method, and storage place/period in respect of cross-border data transfer, and track the personal information protection policies and regulations in the countries/regions where overseas recipients are located. If there are any changes triggering re-evaluation, re-conclusion or re-filing requirements, corresponding measures shall be taken in a timely manner.
Filing Materials. The Guidelines provides the filing template including the PIA Report, standard contract and other procedural materials (including the stamped business license, legal representative’s ID, handler’s ID and POA to handler, Commitment Letter). Please note in the POA, handler does not enjoy sub-delegation rights. Therefore, the data exporter should delegate a capable and trustworthy employee who may need to communicate with the CAC.
Pay attention to the past administrative penalty to the data exporter. The PIA Report contains the record of the data exporter abiding by the laws and regulations. The rectification work should be completed ASAP after the governmental investigation or otherwise it will affect the CAC filing result.
Detailed description on cross-border personal information transfer. The Guidelines requires a detailed description on cross-border personal information transfer, including without limitation the transfer link, the overall picture of such transfer, etc. This requires the data exporter to integrate internal information, including the technical information related to cross-border personal information transfer.
Detailed illustration of the rectification measures and corresponding effects. Whether CAC recognizes and accepts the rectification measures and what is regulatory criteria regarding the rectification work in practice, more study samples are still needed.
Participation of third party in the assessment. The third parties, e.g., law firms or advisory agencies, shall seal on the PIA Report if they support and participant in the enterprises’ PIA work.
The data exporter may consult CAC via the public channel but in practice, it may be in low efficiency.
Provincial CAC adopts offline filing with paper materials and electric materials but in future, it may go online mode.
Disclosure of Personal Information Protection Body in the Enterprises. The Guidelines requires data exporter to disclose its Personal Information Protection Body. The internal data governance system/DPO shall be established/appointed in China as soon as possible since data governance has been increasingly paid attention from the supervisor.

技术驱动法律,专业成就未来