Conditions and Procedures of Cross-border Transfer of Data

来源:宁人研究院

文章摘要
I.
I.The concept of cross-border transfer of data
Cross-border transfer of data is referred to in the Personal Information Protection Law ("PIPL") as "providing personal information outside of the People's Republic of China" and in the Cross-border transfer of data Security Assessment Administrative Measures (Draft for Comments) ("Assessment Measures") as "providing data outside the border". To clarify the exact meaning of cross-border transfer of data, two key concepts need to be defined: one is "outside the border", and the other is "provide".
According to Embarkation and Disembarkation Administration Law, the term "outside the border" includes foreign countries and Taiwan, Hong Kong and Macao of PRC.
As for "provide", there is currently no legal document in force that clearly defines it. The Information Security Technology - Security Assessment Guideline for Cross-border Transfer of Data (Draft for Comments)" ("the Guideline") issued in 2017 defines "cross-border transfer of data" as follows:
A one-time or continuous provision of personal information and important data collected and generated in the data processor’s operations in PRC through networks or other means to institutions, organizations or individuals outside the border, either directly or conducted in the form of business, including services or products.
In addition, Article 3.7 of the Guideline lists three typical ways of cross-border transfer of data:
(a) Provide personal information and important data to subjects in the PRC territory, yet not under its jurisdiction or not registered therein; or
(b) The data is not transferred or stored outside the border, but is accessed and viewed by institutions, organizations or individuals outside the border (except for public information or web page access);
(c) Provide personal information and important data collected and generated in the domestic operation within the group of network operators.
Since Article 2 of the Data Security Law(“DSL”) provides that all data processing activities carried out within the borders are governed by it, subparagraph (a) of the Guideline has no room for application. As can be seen from subparagraphs (b) and (c), either the data itself is copied or transferred and stored outside the border by means of network transmission or physical carriage, or the data is open to remote access by subjects outside the border through the network, both constitutes "provision". Article 3.7 of the Guideline also clarifies that data not generated and collected within the borders, whether or not processed within the borders, is not "cross-border transfer of data" as long as it does not involve personal information and important data collected and generated domestically. In other words, data transit does not constitute cross-border transfer of data.
II. Legislation framework for cross-border transfer of data
(i) Relevant provisions
1. Cyber Security Law
The Cybersecurity Law ("the CL") came into force on 1 June 2017. Article 37 of the Cybersecurity Law requires that personal information and important data collected and generated by "critical information infrastructure operators" (CIIOs) in the course of their domestic operations shall be stored within the borders. If it is necessary to provide them outside the border for business purposes, security assessments shall be conducted in accordance with the measures formulated by the Cyberspace Administration of China (CAC) in conjunction with relevant departments of the State Council.
2. Data Security Law
The Data Security Law ("the DSL") came into force on 1 September 2021. Article 31 of the DSL provides that the security management of cross-border transfer of important data collected and generated by CIIOs in their domestic operations shall refer to the provisions of the CL.
Article 36 of the DSL also stipulates that "organizations and individuals within the borders shall not provide data stored in the PRC to foreign judicial or law enforcement agencies without the approval of the competent authorities of the PRC." Some scholars have interpreted this article as provision on cross-border transfer of data in international judicial assistance. However, the author believes that this perspective is not correct. In the context of the globalization, MNEs set up subsidiaries or offices in various countries or regions, and are therefore under jurisdiction of local law enforcement authorities and judicial organs. International judicial assistance refers to a process in which foreign judicial or law enforcement agencies request certain assistance from China through diplomatic channels following legal procedures. Without the involvement of Chinese government, there would be no international judicial assistance. However, in many occasions, data transfer only happen between foreign judicial or law enforcement agencies and Chinese data processors. Therefore, we believe that Article 36 of the DSL shall also contain these two scenarios: one is voluntary provision as proof in a law enforcement or dispute resolution procedure; the other is provision by order of a foreign law enforcement agency or judicial authority.
3. The Personal Information Protection Law
Chapter III of the PIPL is a special chapter on the rules for the cross-border provision of personal information. First of all, Article 38, paragraph 1 of the PIPL stipulated a premise for such provision, read as “there is a genuine necessity to provide for business purpose”. In the author's opinion, the "necessity" here is similar to the "direct connection" in paragraph 5.2 of the Information Security Technology-Regulations on Personal Information Security. “Direct connection” means that the function of the product or service may not realize without the involvement of relevant personal information. By "necessity", PIPL also requires the provision of personal information to be indispensable.
Secondly, cross-border provision of personal information must meet at least one of the following three conditions: The first is to pass the security assessment organized by the CAC, i.e. the cross-border transfer of data security assessment stipulated in the Assessment Measures. The second is acquisition of certification by a professional institution for personal information protection in accordance with the provisions of the CAC, which is to be formulated. The third is to enter into a contract with the overseas recipient in accordance with the standard contract formulated by the CAC, agreeing one the respective rights and obligations of parties, which is also not yet available.
To better safeguard personal information, paragraph 3 of this article requires personal information processors to take necessary measures to ensure that the processing of personal information by overseas recipients meets the protection standards of the PIPL. This provision made reference to the GDPR, but there is also difference. Instead of requiring the protection level of legislation of the foreign country as a whole, the PIPL only requires the processing activities of the foreign recipient, which is more achievable and operable than the GDPR.
Similar to other personal information processing activities, cross-border transfer of personal information is subject to the "notification-consent" rule in personal information protection. Article 39 stipulates personal information processors shall inform the individuals the foreign recipient’s name, contact information, the purpose and method of processing, the types of personal information and the procedure of exercising personal information rights. A separate consent shall be obtained after full notification.
Finally, Article 40 made similar provisions as Article 31 of the CL. Besides CIIOs, it also requires personal information processors who handle personal information up to the standard of the CAC (one million people according to the Assessment Measures) to store personal information within the borders and conduct a security assessment organized by the CAC if cross-border transfer is necessary. Article 41 is identical to Article 36 of the Data Security Law, except that the object of the provision is personal information instead of data, which needs no repetition here.
4. Information Security Technology - Security Assessment Guideline for Cross-border Transfer of Data (Draft for Comments)
The Guideline, a recommended national standard, divides security assessment on cross-border transfer of data into two parts: self-assessment and assessment by competent authorities, and provides for the respective assessment processes and commonly applicable assessment key points. In addition, the Guideline also stipulates the "Guideline on Identifying Important Data" and "Methodology for Security Risk Assessment of Personal Information and Important Data" in the form of appendices. However, the ISC publicized the "Guidance on Identification of Important Data (Draft for Comments)" in September, 2021. It is expected that the Guideline on Identifying Important Data will no longer be formulated as it differs significantly from the newly publicized provisions. Although there are some differences between the Guideline and the Assessment Measures, the Guideline can still be of great reference significance for security assessment on cross-border transfer of data as a more detailed and operational provision.
5. Cybersecurity Review Measures (Draft for Comments)
In recent years, a large number of Internet enterprises in China have gone public abroad and provided a large amount of data to foreign countries during the listing approval process, which seriously endangers China's national security and the rights and interests of individual citizens. Against this background, on July 10, 2021, the CAC issued a draft revision of the Cybersecurity Review Measures (hereinafter referred to as the Review Measures), which had been in effect for only one year, for comments.
Compared with the version currently in effect, the main difference of the Review Measures is that the scope of application of the cybersecurity review has been extended to "operators with personal information of more than one million users going public outside of the country", while corresponding review conditions have been added. In terms of the scope of application, the wording of the Review Measures is "country" rather than "border", so companies are not required to conduct cybersecurity reviews for listing in Hong Kong for the time being. The review of foreign listing focuses on assessing data processing activities and the national security risks that may be brought by foreign listing, mainly from two perspectives: firstly, the risk of core data, important data or a large amount of personal information being stolen, leaked, destroyed, illegally used or cross-border transferred; secondly, the risk of critical information infrastructure, core data, important data or a large amount of personal information being influenced, controlled or maliciously used by foreign governments after the listing, taking into account other factors that may endanger the security of critical information infrastructure and national data security.
6. Cross-border transfer of data Security Assessment Administrative Measures (Draft for Comments)
The CAC issued the Assessment Measures on 29 October 2021, which divides the assessment into a risk self-assessment of cross-border transfer of data conducted by data processors on their own (self-assessment) and a security assessment on cross-border transfer of data organized by the CAC (security assessment), and sets out the respective applicable conditions, assessment key points and procedures, which will be discussed in detail later.
Previously, the CAC has publicly solicited comments on the Measures for Security Assessment on Cross-border Transfer of Personal Information and Important Data (Draft for Comments) and the Measures for Security Assessment on Cross-border Transfer of Personal Information (Draft for Comments) respectively in 2017 and 2019. However, both the drafts and the Assessment Measures set out the assessment key points and the applicable conditions for the security assessment organized by the CAC, which are provisions on the same matter. Since the Assessment Measures apply to all types of data, including personal information and important data, its scope of application includes the two previous drafts. With this consultation on the Assessment Measures, it is foreseeable that both previous documents will be discarded.
7. Regulations on Cyber Data Security Management (Draft for Comments)
On November 14, 2021, the CAC released the Regulations on Regulations on Cyber Data Security Management (Draft for Comments) (hereinafter referred to as “the Regulations”). The Regulations, if adopted, would be an administrative regulation, whose effect hierarchy is only under law in China. The Regulations consists of 9 chapters and 75 Articles, which refines many of the provisions of the DSL and the PIPL, while also establishing some new systems that were not previously formulated in laws and regulations. Chapter 5, entitled "Management of Data Cross-Border Security," mainly regulates cross-border transfer of data by six out of eight articles. Among them, the following provisions need extra attention:
A. By changing the subject from personal information processor to data processor, Article 35, paragraph 1 of the Regulations extended the application of Article 38 of the PIPL to all data processors. You may find more detailed content of Article 38 of the PIPL at item II.3, paragraph 2.
B. On conditions for application of the security assessment, the Regulations made different provision from the previous Assessment measures. The major difference is the deduction of the condition “personal information processors that cumulatively provide personal information up to more than 100,000 people or more than 10,000 people with sensitive personal information outside the border”. However, as this condition is designed to protect personal information of a big amount, the author believes that it would still apply, either by being added to new versions of the relevant regulations, or by application as “other provisions by the CAC”.
C. Article 39, paragraph 1 of the Regulations imposed the following obligations on data processors involved in cross-border transfer of data:
(a) shall not exceed the purpose, scope, method, data type and amount of personal information provided outside the country as specified in the impact assessment report on personal information protection submitted to the CAC; and
(b) shall not provide personal information and important data outside the country beyond the purpose, scope, method, data type and amount of the transfer as specified in the security assessment of the CAC; and
(c) shall take effective measures such as contracts to supervise the data recipient in accordance with the purpose, scope and method of use of data agreed by both parties, to fulfill data security protection obligations and ensure data security; and
(d) shall accept and handle complaints from users involved in the cross-border transfer of data; and
(e) shall be held responsible according to the laws if the cross-border transfer of data damages the legitimate rights and interests of individuals, organizations or public interest; and
(f) shall retain the relevant log records and approval on cross-border transfer of data records for more than three years; and
(g) shall display the type and scope of personal information and important data transferred in a plain text and readable manner when verified by the CAC and relevant departments of the State Council; and
(h) shall stop the transfer and take effective measures to remedy the security of the data that has left the border if the CAC disapproves the cross-border transfer; and
(i) shall agree in advance with the individuals on conditions of re-transfer and clarify the obligations which the data recipient assumes if the transferred personal information needs to be transferred again.
D. Article 40 provided that all data processors involved in cross-border transfer of data shall hand an annual security report to the CAC.
(ii) Overall commentary
Since 2016, China has introduced three separate laws for cybersecurity, data security and personal information protection. The legislation of the three major laws has been completed and the legal framework has been initially established. Among them, cybersecurity and data security mainly focus on public law functions, and the legislative objectives are integrated within the framework of the overall national security concept, both of which are important components of national security and cyberspace sovereignty; personal information protection, on the other hand, mainly focuses on private law functions, emphasizing the protection of personal information of natural persons. Although each of the three areas has its own focus, there is also crossover and overlap between them, for example, the CL and the DSL both include the protection of personal information, and the PIPL also requires personal information processors to take cybersecurity and data security measures to ensure the safety of personal information.
The three laws contain general provisions on what and how data may be transferred across the border. However, there are no corresponding administrative regulations, department regulations or other regulative documents in force that provide an enforceable refinement of the provisions of the laws. From the provisions of the law and the various consultation drafts, we can summarize as follows: three procedures are currently necessarily required for cross-border transfer of data, namely signation of the contract with the recipient, the self-assessment, and the annual security report on cross-border transfer of data. There are three procedures that may be required, namely the approval by the competent authority when providing data to foreign judicial or law enforcement agencies, the security assessment, cybersecurity review organized by the Cybersecurity Review Office established in the CAC.
Among them, there are certain similarities between cybersecurity review and security assessment, which makes the condition of their application worth discussing. Given that the conditions for application, methods of review and subjects of the two procedures are different, they should be separately applied and independent systems. In case of crossover and overlap, considering that an operator with personal information of more than one million users going public abroad will definitely involve cross-border transfer of data and meets the condition of the security assessment, cybersecurity review and cross-border transfer of data security assessment shall both be conducted under such circumstances. As for the order in which they are conducted and whether the relevant procedures can be combined, further explanation from the CAC is needed.
Application of the above procedures is shown in the following flow chart:

III. Risk Self-assessment on cross-border transfer of data
(i) Conditions for application
Article 5, paragraph 1 of the Assessment Measures provides that "a data processor shall carry out a prior risk self-assessment on cross-border transfer of data before cross-border transfer of data". According to this article, self-assessment is required before any subject conducts any cross-border transfer activities as previously defined. If security assessment on cross-border transfer of data by the CAC is conducted, the self-assessment report will also be provided as part of the handed materials.
(ii) Assessment key points
The assessment key points of the self-assessment includes:
1. The legality, legitimacy and necessity of the cross-border transfer of data and the purpose, scope and method of data processing by the recipient outside the border.
2. The quantity, scope, type and sensitivity of the data to be transferred, and the risk it may pose to national security, public interests, and the legitimate rights and interests of individuals or organizations.
3. Whether the management and technical measures and capabilities of data processors in the data transfer process can neutralize risks such as data leakage or destruction.
4. The responsibility and obligations that the offshore recipient undertakes to assume, and whether the management and technical measures and capacity can guarantee the security of the data.
5. The risk of leakage, destruction, falsification, misuse, etc. of data after transfer and re-transfer, and whether the channels for individuals to defend the rights and interests of personal information are open, etc.
6. Whether the data security protection responsibility obligations are adequately agreed in the related contract with the offshore recipient.
Among them, item 1 focuses on the legality, legitimacy and necessity of data processing; item 2 focuses on the protection of national security, public interests, and the legitimate rights and interests of individuals or organizations; items 3-5 focus on the security of the outbound data itself and the protection of the rights of personal information; and items 4 and 6 focus on the responsibilities and obligations of the overseas recipient in terms of data protection.
It is noteworthy that if the data to be exported is personal information, a standard contract formulated by the CAC should be signed with the data recipient; for data other than personal information to be exported, although a standard contract is not required, Article 9 of the Assessment Measures sets out specific and detailed requirements for the content of the contract.
IV. Security Assessment on Cross-border Transfer of Data by the CAC
(i) Conditions for application
Article 4 of the Assessment Measures stipulates five circumstances under which security assessment should be conducted when providing data outside the border, which can be divided into three categories: the first category is special subjects, including personal information processors that handle personal information up to one million people, and personal information processors that cumulatively provide personal information up to more than 100,000 people or more than 10,000 people with sensitive personal information outside the border; the second category is special objects, including personal information collected or generated by CIIOs and important data; the third category is the miscellaneous clause, i.e. other situations stipulated by the CAC. In addition, Article 12 of the Assessment Scheme provides that the results of the cross-border transfer of data assessment are valid for two years and are subject to reassessment sixty days prior to the expiry date; and are also subject to reassessment in the following conditions:
1. Changes in the purpose, method, scope and type of data provided outside the border, the use and method of data processing by the recipient outside the border, or extension of the period of keeping personal information and important data outside the border.
2. Changes in the legal environment of the country or region where the foreign recipient is located, changes in the actual control of the data processor or the foreign recipient, changes in the contract between the data processor and the foreign recipient, and other changes that may affect the security of outbound data.
3. Other circumstances arise that affect the security of the transferred data.
(ii) Assessment procedures
Data processors that are required to conduct the security assessments should apply for security assessments to the CAC through the provincial cyberspace administration department where they are located. Article 6 of the Assessment Measures sets out the needed materials, Article 7 sets out the time limit for acceptance, Article 10 sets out the assessment process, and Article 11 sets out the length of the assessment. To facilitate readers' understanding, we have drawn a flow chart for the procedure.

(iii) Assessment key points
Section 8 of the Assessment Measures sets out seven assessment key points for the security assessment, which are as follows:
(a) the legality, legitimacy, and necessity of the purpose, scope and method of the cross-border transfer; and
(b) the impact of data security protection policies and regulations of the country or region where the overseas recipient is located and the cybersecurity environment on the security of the transferred data; whether the level of data protection of the overseas recipient meets the requirements of the laws, administrative regulations and mandatory national standards of the People's Republic of China; and
(c) the number, scope, type and sensitivity of the transferred data, the risk of leakage, tampering, loss, destruction, transfer or illegal access, illegal use, etc. in the transfer and after the transfer; and
(d) whether data security, the rights and interests of personal information can be fully and effectively protected; and
(e) whether the contract between the data processor and the overseas recipient adequately agrees on the responsibility and obligation of data security protection; and
(f) compliance with Chinese laws, administrative regulations and departmental rules; and
(g) other matters that the CAC considers necessary to assess.
技术驱动法律,专业成就未来