38092
post-template-default,single,single-post,postid-38092,single-format-standard,stockholm-core-2.4,qodef-qi--no-touch,qi-addons-for-elementor-1.6.7,select-theme-ver-9.5,ajax_fade,page_not_loaded,,qode_menu_,wpb-js-composer js-comp-ver-7.9,vc_responsive,elementor-default,elementor-kit-38031
Title Image

China’s New Data Security Law

China’s New Data Security Law

On June 10, 2021, China’s top legislature, the Standing Committee of the National People’s Congress (NPC), promulgated the new Data Security Law (DSL) of the People’s Republic of China.[1] This legislative development took place two months after the NPC released the second draft of the proposed law in April 2021.[2] The DSL became effective on September 1, 2021.[3]

Article 2 of the legislation states its broad scope – the law applies to all data processing activities within the mainland territory of China.[4] Outside of the mainland territory, this new law governs any aspect of data processing detrimental to national security, the public interest, or legal rights and interests of Chinese citizens and organizations.[5] This expands on the previous Network Security Law (NSL), which applied only to outside-China processing deemed an attack, infringement, interference or damage to Chinese information infrastructure.[6] Data, as defined by the DSL, covers any record of information in electronic or other forms, such as hard copy written records of information.[7] Data processing activities regulated by DSL include, though are not limited to, the collection, storage, use, processing, transmission, provision, and disclosure of data.[8]

The DSL classifies data based on its importance to the state’s economic development, national security, public interest, and the legitimate rights and interests of individuals and entities.[9] Following the directive of the Network Security Law to adopt data classification measures,[10] the DSL classifies all data into three categories. The DSL uses the concept of “core national data” to implement a strengthened management system regulating core data involving national security, lifelines of the national economy, people’s livelihoods, and major public interests.[11] Violations of the core state data management system or any activities that may endanger China’s sovereignty, security, and development interests will be subject to fines up to 10 million yuan.[12] suspension of business, revocation of business licenses, and possible criminal liability.[13]

The concept of “important data” was first raised in the NSL, under which network operators in China are required to categorize data and formulate backup and encryption measures for the protection of important data. [14] The DSL further requires, however, that business operators who process important data must appoint a responsible person and establish a specific internal department for important data protection, carry out risk assessments on a regular basis, and report the risk assessment results.[15]

Neither the NSL nor the DSL provides details on the definition and scope of important data or the detailed protection mechanism. The DSL authorizes the national data security coordination mechanism to coordinate with the relevant departments to formulate an important data catalogue at the national level.[16] The DSL also authorizes different provincial regions and industrial sectors to formulate their own specific important data catalogues with protection requirements.[17] The extent of the regulatory duties owed by regional and industrial sectors, however, are yet to be spelled out.

Regarding the cross-border transfer of important data, the DSL introduces separate frameworks for the regulations of operators of critical information infrastructure (CII) and non-CII data processing operators.[18] For CIIs, the export of important data collected and generated in China is governed by the NSL and requires passing a security assessment by pertinent regulatory authorities.[19] Under the NSL, CII operators are required to locally store important data that is collected or generated in China.[20] For non-CIIs, the DSL specifies that the rules regulating the export of important data collected and generated in China will be developed by the Chinese Cyberspace Administration along with the relevant departments of the State Council.[21]

The passage of the DSL reflects China’s growing concern over the security of data amassed by private firms, the risks of data breach, and an upward trend toward more intensified regulatory scrutiny. In July, the Cyberspace Administration of China launched an investigation into Chinese ride-hailing company DiDi days after it began trading on the New York Stock Exchange.[22] The DSL was promulgated days after the launch of the DiDi investigation. While the full extent of the legislation’s regulatory impact is yet to be assessed, careful monitoring of data security issues is more important than ever—for businesses and investors alike.

.

 

Footnotes[+]

Shengkai Xu

Shengkai Xu is a second year J.D. candidate at Fordham University School of Law and a staff member of the Intellectual Property, Media & Entertainment Law Journal. He holds a B.A. from Minzu University of China, a M.A. from University at Buffalo, and is a Ph.D. candidate at University at Buffalo, State University of New York.