Impact of the Draft Measures on Outbound Data Assessment
The Cyberspace Administration of China (the "CAC") issued the Measures for Security Assessment of Cross-border Data Transfer (Draft) (in Chinese “数据出境安全评估办法(征求意见稿)”) (the "Draft Measures") on October 29, 2021.1 This article aims at providing a background to the Draft Measures, its key provisions, and the potential impact it may have on enterprises.
Author:Shihui Partners | Raymond Wang | Jeanette Wang
Background
The Draft Measures are the CAC’s third attempt at building a comprehensive mechanism for cross-border data transfer. The previous attempts were in 2017 through the Measures for Evaluating the Security of Transferring Personal Information and Important Data Overseas (Draft) (in Chinese “个人信息和重要数据出境安全评估办法(征求意见稿)”) and later the Measures for Security Assessment for Cross-border Transfer of Personal Information (Draft) (in Chinese “个人信息出境安全评估办法(征求意见稿)”). 2 The Draft Measures will harmonize the requirements under the CSL and DSL and offers much desired clarification on the security reviews, the governmental department responsible for overseeing security assessments, and what procedures companies must complete to get clearance for the offshore transfer of both important data and personal information.
Scope of Cross-Border
Triggers for Security Assessments
Self-Assessments
the legality, propriety and necessity of the cross-border transfer/processing conducted by the data recipient outside the PRC; the volume, scope, type and sensitivity of the data to be transferred, and the potential risks to national security, public interests and the legitimate interests of individual and corporations; whether the data protection laws and regulations of the data recipient’s jurisdiction, the capability of the security of the data recipient, and whether the protections provided by the data recipient satisfy PRC laws and standards and whether the recipient has sufficient means and capabilities to fulfil such duties; the risk of data leakage, damage, corruption, loss, or misuse; and whether the data transfer agreement adequately allocates relevant responsibilities for data protection.
Security Assessment Procedure
the legality, propriety and necessity of the transfer; the data protection laws of the data recipient’s jurisdiction, and whether the protections and security provided by the data recipient are adequate to satisfy those under PRC laws and regulations; the volume, scope, type and sensitivity of the data being transferred and the risk of leakage, damage, corruption, loss and misuse; whether the data transfer agreement adequately allocates responsibilities for data protection; compliance with Chinese laws, administrative regulations, and departmental regulations by the data processor; and other matters that are deemed necessary by the CAC.
changes in fundamental aspects of the cross-border data transfer: any change to the purpose, method, range and variety regarding the data to be provided overseas, or the purpose and method regarding the data processing by the overseas receiving party, or the extension of the period for overseas storage of personal information and important data; changes in data protection environment (law, control or contract): any change to the legal environment of the country or region where the overseas receiving party is located, or the actual control of the data processor or overseas receiving party, or the contract between the data processor and the overseas receiving party, which may affect the security of the data provided overseas; or other circumstances that may affect the security of the data provided overseas.
Data Transfer Agreement
the purpose, method and scope of the cross-border transfer; the location where the data will be stored outside of the PRC and how long the transferred data will be retained and how the data will be dealt with after the expiration of the retention period, termination of the data transfer agreement, or when the purpose of processing has been met; provisions restricting disclosure and transfer of the data to third parties; the security measures to be taken in the event of a material change to the data recipient’s business or if the data recipient does not have the means or capabilities to satisfy its duties; liability for breach of contractual security responsibilities; a binding and enforceable dispute resolution provision; and data recipient to respond and safeguard the rights and interests of the data subjects (if personal information is involved) in the event of a data leak or other breach.
Conclusion
Companies should take into consideration the timeline to prepare and complete a security assessment for any project planning since there are no existing exemptions. We anticipate that in the near future, other detailed rules and regulations on the cross-border data transfer security management will continue to be released intermittently to create a more comprehensive security management regime for cross-border data transfer. In the meantime, companies are advised to gear up and align their policies with those under the Draft Measures. In this regard, we would be pleased to share with you our experience and understanding on this topic on an ongoing basis.
参考资料:1.The deadline for public comments is set at November 28, 2021.2.It should be noted that the Measures supersedes and replaces these two drafts.3.Application should be made through the provincial cyberspace administration.4.According to the DSL, local governments and industry departments should determine the specific catalog of important data in their regions or industries. We also understand that local governments and industry departments have been working on drafting important data catalogs.5.It is not clear what qualifies as “cumulative.” We understand that since the declaration assessment has a validity period of two years, data processors should nonetheless proceed with a declaration assessment if they expect their cumulative transferred data over the course of two years to meet the threshold based on their internal historical operational data.
6.See Article 8 of the Draft Measures.
Raymond Wang | Partnerwangxr@shihuilaw.com
Raymond focuses on cybersecurity and data protection and frequently advises leading multinational and domestic technology companies and ministries and local governments with respect to legislative and regulatory programs.
Raymond sits on the expert panel for the ICC’s Data Governance Working Group and the B20 Organization Compliance Working Group. He is one of the key authors of the monograph “International Comparative Study on Personal Information Protection" and “Data Service Framework". He has published many articles, reports and translation works in the field of personal information protection, and also has taught courses related to data protection and cyber law in Peking University and Tsinghua University.
He was listed as one of the 2021 ALB China Top 15 Lawyers in TMT area by Asian Legal Business and as "Leading lawyer in data protection area" by The Legal 500 ranking institution. The awards he has gained also include Lawyers of the Year in Cybersecurity areas by 2021 China Law & Practice and China Top 15 Lawyers– Cybersecurity and Data Protection (Tier one) by LEGALBAND in 2019, 2020 and 2021.
Jeanette Wang | Partnerwangjy@shihuilaw.com
Jeanette’s main areas of practices are in M&A, PE/VC, foreign direct investment cybersecurity and data compliance.
Jeanette has assisted across the broad spectrum corporate work including domestic and cross-border mergers and acquisitions, and advised investors and conglomerates such as KKR, Blackstone, Tencent, JD, Haier, Office Depot and Swiss Post in such transactions. She also assisted many venture capital funds and start-ups in several rounds of private equity/venture capital investment and financing transactions. Her track record spans a vast range of sectors, including pharmaceutical & healthcare, TMT, manufacturing, automobile and new energy, chemical engineering, real estate, commercial retails, banking and finance.
Jeanette has also assisted multinational corporations in their various cybersecurity and data protection issues, including data security inspection and assessment, establishment of data compliance system and dealing with government inspection and security incidents. She also provides advice to clients in general corporate matters. Her list of clients includes GE, Richemont, Thermo Fisher, Burberry, Chanel, Danaher, Volvo, PEPSI and Abbott.
数据安全系列
投融资系列
跨境投融资系列 I《外商投资法》下修改合资合同和章程的要点分析 跨境投融资系列 II 外商投资监管变革浪潮来袭——企业如何应对 跨境投融资系列 II 人民币机构投资VIE架构项目的路径探析 – 以近期赴港上市项目为例 被BAT投资的剧本中通常有哪些经典桥段——战略投融资常见条款 “跪”还是“贵”?经济实质法对红筹架构壳公司的影响 跨境投融资系列 II 新《外商投资法》要点简析 跨境投融资系列 II 红筹架构下人民币机构ODI路径解密 – 以近期赴港上市的新经济企业为例 跨境投融资系列 II 推开"ODI"之门
辉说A股 || 新规之下突击入股影响几何?——股东信息披露指引解读 辉说A股 || 审核监管2.0:A股IPO现场检查和现场督导 走近科创板 II 如何在创业板 「2.0时代」乘风破浪? 世辉观点II 又㕛叒叕上市了?—— 一起聊聊港股二次上市 世辉A股 II 战略投资者投资A股锁价定增应了解的九大问题 世辉观点 II 新《证券法》背景下上市地的简要对比 走近科创板:带期权计划科创板上市你准备好了吗? 辉说A股 II 股权投资基金坚持优惠新政策难点解读看这篇就够了 走近科创板:发行上市篇 || 红筹企业境内科创板上市离我们有多远? 扫雷贴 II 2018年度港股上市被否案例全解析 上交所新发权威问答!16个科创板发行上市审核问答要点梳理 走近科创板:发行上市篇 || 九问九答解读科创板上市标准与制度亮点 医疗健康系列 || 医疗机构赴港上市或海外融资模式解密——以赴港上市的境内医疗机构为例
投资基金
辉说基金 || 简析私募基金参与非公开发行的发展近况与基金特殊事项 辉说基金 || 简析《关于加强私募投资基金监管的若干规定》(征求意见稿)》所可能带来的挑战 辉说互金 II 靴子落地,民间借贷利率司法保护上限的新安排 辉说基金 II 从实操视角解读新出台的“便利管理人登记的通知” 辉说基金 II 30秒读懂私募基金募集管理规定 辉说基金 II 分配机制(二) 辉说基金 II 后续募集 辉说互金系列(一)II 基于保险经纪牌照外资准入实务谈谈互联网企业对保险业务的布局 辉说基金 II 分配机制(一) 辉说基金 II 创投企业税收优惠之新解读
辉说期权 || VIE结构下的员工股权激励计划和信托 辉说并购 II 并购价格机制之二:锁箱机制 辉说并购 II 并购价格机制之一:交割账目机制 辉说期权 II 盘他!非上市公司股权激励的个人所得税 辉说期权 II 员工创富记的背后——揭秘小米、美团等公司的员工股权激励计划 辉说期权 II VIE结构中境外ESOP的外汇问题
辉说反垄断 || 平台经济加强监管和科学监管并进 — 简评《关于平台经济领域的反垄断指南》正式稿修订要点 辉说反垄断 || 2020年经营者集中审查和执法回顾 辉说反垄断 || 经营者集中申报容易陷入的误区 辉说反垄断 || 刚柔并济—简评《反垄断法(修正草案)》公开征求意见稿修订要点
Shihui Articles || What does the PIPL mean for an HR manager
世辉观点 || 《汽车数据安全管理若干规定(试行)》重点条文解读 辉说诉讼 || 《个保法》下侵权诉讼:权利人和个人信息处理者应如何应对? 世辉解读 |《数据出境安全评估办法(征求意见稿)》对企业合规工作的影响 世辉观点 || 《汽车数据安全管理若干规定(试行)》重点条文解读 世辉解读 | 如何理解和落地个人信息保护法下的合规审计 世辉观点 || 国资成分基金增资和份额/股权转让中的国资程序问题探讨 世辉观点 || 投融资项目中涉及高校教师持股及任职情况的尽调核查要点 世辉观点 || 股东出资期限加速到期在执行程序中的情形和实践 辉说教育 || 守得云开见月明 ---后民促法时代民办高校投资并购的机遇和挑战 世辉观点 || 光伏发电项目用地合规性的法律判断 世辉观点 II 银行保险业公司治理新规—— 《银行保险机构公司治理准则》要点解读 辉说投资 || 减资前置对股权回购可履行性的障碍 世辉观点 || 无人驾驶车辆产业所需测绘资质辨析 世辉观点 || 后浪去哪浪,上太空挖矿 辉说信托 || 九民纪要后,国内家族信托可行? 辉说合规 II 以案说法之网络爬虫的法律风险 辉说合规 II APP专项整治:您有一份自“救”(纠)宝典待查收 秒懂个人外汇调回、反避税和CRS,体验有钱人的烦恼 世辉观点 || 增值电信千万条,外资准入第一条 世辉观点 || 区块链私募投资有问币答:尽职调查&交易架构 辉说信托 || 境外家族信托基本问题Q&A