Contents
I. Circumstances that Trigger a Security Assessment
II. Interpretation of Data Exports
III.Application Methods and Procedures
IV. Application Materials and Highlights
V. Highlights of Risk Self-Assessment Report on Data Export (Template)
VI. Our Observations and Suggestions
On August 31, 2022, the Cyberspace Administration of China (“CAC”) officially released the Application Guidelines for Security Assessment of Data Export (Version 1) (the “Application Guidelines”)1 before the Security Assessment Measures for Data Export (the “Assessment Measures”) officially come into effect. The Application Guidelines specifically address the application scope, methods, procedures, materials, and queries with respect to security assessments of data exports, to provide guidance for data processors who intend to apply for security assessments of data exports.
The local equivalents of CAC have also been making preparations for the application for security assessments of data exports. For example, on September 2, 2022, the Cyberspace Administration of Jiangsu Province released the Application Guidelines for Security Assessment of Data Export of Jiangsu Province (Version 1)2 and the Beijing Municipal Cyberspace Administration now provides an inquiry hotline for further information regarding the Application Guidelines3.
We have analyzed the more specific processes and requirements stipulated by the Application Guidelines for your reference.
I. Circumstances that Trigger a Security Assessment
The circumstances that trigger an application for a security assessment of data export under the Application Guidelines are consistent with Article 4 of the Assessment Measures. This includes the export of important data, the export of personal information by critical information infrastructure operators and by data processors processing a large amount of personal information, and the export of a large amount of personal information or sensitive personal information. However, no further explanation is provided for the time being on how to calculate each specific threshold that triggers a security assessment, and it remains to be determined on a case-by-case basis and communicated with regulators.
We note that the Jiangsu Provincial Application Guidelines for Security Assessment of Data Export (Version 1) provides more specific details regarding important data. It requires data processors to determine whether the exported data constitutes important data by referring to industrial standards or, in the absence of industrial standards, the rules set forth in Article 73 of the Network Data Security Regulations (Draft for Comments)4 regarding the determination of important data, in addition to the definition of “important data” stipulated in the Assessment Measures and it also provides examples of important data.
II. Interpretation of Data Exports
The Application Guidelines also provide more specific rules for the determination of data exports. As mentioned by CAC on July 7, 2022 when answering questions from reporters on issues related to the Assessment Measures, data exports referred to in the Assessment Measures include the following situations: (i) a data processor transmits and stores outside the PRC the data that is collected and generated in its operation within the PRC; and (ii) the data collected and generated by a data processor is stored in the PRC and is available to overseas institutions, organizations or individuals to access or download.5 The Application Guidelines have revised “access or download” to “query, access, download and output”, further clarifying the rules for the determination of data export. The Application Guidelines still retain the expression “other data exports described by CAC,” which allows the regulator to interpret more complicated data exports in future regulatory practice. The Application Guidelines do not clarify whether the processing of the personal information of an individual who is located in China by a data processor who is located outside of China pursuant to Paragraph 2 of Article 3 of the Personal Information Protection Law constitutes a “data export” requiring security assessment, which is subject to further interpretation by CAC in subsequent regulatory processes.
III. Application Methods and Procedures
There is a requirement under the Assessment Measures that the provincial cyberspace administration shall complete its review of the completeness of the application materials and, if the application materials are determined complete, the provincial cyberspace administration will forward the application materials to CAC. This is described in the flow chart below.
Compared to the application method and procedures under the Assessment Measures, the Application Guidelines provide more specific rules in the following areas:
- The application shall be filed with the written application materials and accompanied with electronic copies thereof (in the form of a CD-ROM);
- If the application materials are determined incomplete by the provincial cyberspace administration, the data processor will be given a notice of return of the application and will have no further avenue for any addition or correction at this stage;
- The data processor shall complete a self-assessment three months prior to the date of the application, and no material change will have occurred to it as of the date of the application; and
- CAC and the local equivalents of CAC will provide telephone numbers and email addresses for inquiries regarding security assessment of data export.
IV. Application Materials and Highlights
Compared to the Assessment Measures, the most significant change reflected in the Application Guidelines is the imposition and enforcement of more specific requirements on application materials for security assessment of data export and the provision of relevant templates.
1. The more specific application materials include:
(1)A Unified Social Credit Code Certificate;
(2)An identity document of the legal representative;
(3)An identity document of the authorized representative for filing the application;
(4)The power of attorney for the authorized representative for filing the application (template);
(5)The Application Form for Security Assessment of Data Export (template), including the Letter of Undertaking and the Application Form for Security Assessment of Data Export;
(6)The contract or other legally binding document to be executed by the data processor and the overseas recipient with respect to the data export;
(7)The Risk Self-Assessment Report on Data Export (template); and
(8)Any other supporting material.
2. The above application materials reflect the following updates:
(1)The Letter of Undertaking requires data processors to provide undertakings not only on the lawful collection and use of exported data, but also on the authenticity, accuracy, completeness and validity of the application materials;
(2)The Application Form for Security Assessment of Data Export requires data processors to provide particulars of its own and of the data export, the data to be exported, the overseas recipient, and legal documents for the data export. It is especially noteworthy that
data processors are required to provide particulars of data security officers and management bodies of its own and the overseas recipient;
if the data to be exported includes both personal information and important data, data processors are required to provide particulars of both;
data processors are required to describe the scale (MB/GB/TB) of the data, in addition to the category of the data to be exported;
data processors are required to describe the data export link, such as the link provider, quantity and bandwidth of the links, the name of the data center and the physical location of the server room within and outside of China, and the IP address
with respect to the clauses required to be contained in the export-related legal documents in accordance with Article 9 of the Assessment Measures, data processors are required to specify the name of the document, the relevant clauses, and the pages containing such clauses, in each legal document; and
data processors are also required to describe the administrative penalties, investigations, and rectifications imposed by the competent regulatory authorities on it during its business operations in the last two years, with an emphasis on those related to data security and cybersecurity.
(3)CAC provides a Risk Self-Assessment Report on Data Export (Template) to give specific guidance for data processors in preparing their self-assessment reports. We summarize below the specific highlights of this template.
V. Highlights of Risk Self-Assessment Report on Data Export (Template)
The Application Guidelines also provide a Risk Self-Assessment Report on Data Export (Template) (“Self-Assessment Report Template”), which sets forth the specific matters to be assessed and analyzed in the self-assessment report and provides important guidance and reference for data processors in preparing the self-assessment report. - The self-assessment is required to be completed three months prior to the application for security assessment of data export, and no material change shall occur as of the date of application;
- In the case of any third-party institution participating in the self-assessment, the data processor is required to describe the basic particulars of the third-party institution, and the participation of the third party in its assessment and affix the official seal of the third-party institution to the pages containing the description;
- The self-assessment report shall include four parts: a brief description of the organization and implementation of the self-assessment, an overview of the data export, a risk assessment of the proposed data export, and a conclusion of the risk self-assessment of the data export. It is noteworthy that data processors in the self-assessment report are required to address:
(1)The particulars of the data processor, not only the general registered information and the business and information system involved in the data export, but also the actual controller, general business and data, and investments in or outside of China;
(2)An assessment of the data security protection capability of the data processor. This includes the establishment of a governance structure and management rules, the management plan for the entire process, classification and rating, emergency response, risk assessment, protection of personal information rights and interests, and other rules and policies, and the implementation of the foregoing. It also should include the technical security measures adopted through the entire process of the data collection, storage, use, processing, transmission, provision, disclosure and deletion as well as proof of the effectiveness of the data security protection measures, such as the data security risk assessment, the data security capability certification, and the classified cybersecurity protection assessment (MLPS);
(3)An assessment of the overseas recipient, not only describing the particulars of the overseas recipient, the data security protection capacity of the overseas recipient, and the data security protection rules and regulations and cybersecurity environment in the country or region where the overseas recipient is located, but also describing the entire flow chart of data processing by the overseas recipient;
(4)A risk assessment of each of the significant matters required to be assessed under Article 5 of the Assessment Measures, with an emphasis on the issues and potential risks identified by the assessment, and the corresponding corrective measures taken and their effectiveness; and
(5)The conclusion of the risk self-assessment, with full reasons and arguments to support such a conclusion.
VI. Our Observations and Suggestions
The above is our summary of the specific rules and additional requirements under the Application Guidelines with respect to security assessment of data export. We hereby provide the following preliminary advice for enterprises on how to comply with such rules and requirements: - If you have not yet reviewed your data exports, it is advised to start checking and reviewing them as soon as possible to determine whether they are subject to application for security assessment of data export in accordance with the Assessment Measures. Considering the overall compliance arrangements, it is advised to complete preparation work as soon as possible.
- If you do need to apply for security assessment of data export,
(1) It is difficult to complete applications with both CAC and the provincial equivalent of CAC, and successfully pass their security assessment of data export within the six-month remedy period required under the Assessment Measures, therefore it is advised to engage a third-party professional institution to help you make a project plan using backward scheduling method and specify the responsibilities and obligations of all participants in a security assessment of data export, so as to complete the preparation and submission of the application materials as soon as possible;
(2) It is advised to conduct a self-assessment on data export to assess each matter required to be assessed in the self-assessment report template and make every effort to correct and rectify issues and problems identified in self-assessment; and
(3) It is advised to prepare other application materials concurrently as required by the Application Guidelines. - It is also advised to consider deployment of localization system in advance according to your own specific situation, to avoid any impact on business continuity in the case of your failure to pass the security assessment of data export.
- Please refer to the Application Guidelines for Security Assessment of Data Export (Version 1) released by the CAC at http://www.cac.gov.cn/2022-08/31/c_1663568169996202.htm
- Please refer to the Easy-to-Understand Diagram: Recent Release of Jiangsu Provincial Application Guidelines for Security Assessment of Data Export at http://www.jswx.gov.cn/xinxi/shuzi/202209/t20220902_3068388.shtml
- Please refer to Beijing Municipal Cyberspace Administration Provides an Inquiry Hotline for Security Assessment of Data Export at https://mp.weixin.qq.com/s/qt3X4O35a7fFfKbaHDO6Fw
- The Network Data Security Administration Regulations (Draft for Comments) were released by CAC on December 14, 2021.
- Please refer to Press Conference of Security Assessment Measures for Data Export at https://mp.weixin.qq.com/s/I_8CoXlwvIAv4vdWQLANZw
