I. Introduction
The Cyberspace Administration of China (CAC) issued a notice at 12:00 a.m. on 10 July 2021 to publicly solicit comments on the Cybersecurity Review Measures (Revised Draft for Comment)(the “Draft for Comment”) (for previous interpretations of the Cybersecurity Review Measures, please see the article: Innovations and Changes of Cybersecurity Review Measures). Considering the recent regulatory measures taken by CAC, the Cyber Security Review Office and other regulators on a number of enterprises, this article will address some of the key points of the Draft for Comment for your reference.
II. Interpretation of Key Points
This article focuses on two key aspects of the Draft for Comment - one is the new key issues, and the other is the basic issues. We will interpret from these two aspects respectively.
△ New key issues (please see the table at the end of the article for the comparison between the Draft for Comment and the current version)
1) Who is the Draft for Comment applicable to?
The Draft for Comment applies to critical information infrastructure (CII) operators as well as data processors. Given that data processors are new subjects, we understand that even if an enterprise is not a CII operator or is not sure whether it is a CII operator, it is likely subject to the regulation of the Draft for Comment if it conducts data processing activities and such activities affect or may affect national security.
2) If an enterprise is subject to the Draft for Comment, under what conditions would it be required to apply for cybersecurity review?
If an enterprise is a CII operator or data processor, it is required to apply for or pass cybersecurity review if any of the following conditions is met:
Application for security review
Where CII operators procure a network product or service which affect or may affect national security;
Operators (CII operators and data processors) with the personal information of more than one (1) million users who intend to go public abroad.
Voluntary filing
Where any member of the cybersecurity review working mechanism is of the opinion that the network product or service, data processing activities or listing in a foreign country affects or is likely to affect national security.
3) Do enterprises intending to list in Hong Kong need to apply for cybersecurity review? Do they also need to meet compliance requirements such as the requirements for cross-border data transfer?
As the expression used in the Draft for Comment is “listing in a foreign country” rather than “offshore listing” [typically understood to mean a jurisdiction outside of the Chinese Mainland], we understand that there may be some differences between the two.
Referring to the interpretations of “embarkation” and “disembarkation” under the Law of the People's Republic of China on Administration of Embarkation and Disembarkation, we understand that “offshore” regions include Hong Kong SAR, Macao SAR and Taiwan region.
As for the distinction between “domestic” and “foreign”, we understand that “domestic” should generally include Hong Kong SAR, Macao SAR and Taiwan region, while “foreign” refers to “countries and regions other than the People’s Republic of China (PRC)”.
Based on the above understanding, we believe that it is relatively unlikely that a Hong Kong listing will be considered as “listing abroad”. However, given that our interpretation of “offshore” and “foreign” is based on research and reference to the laws of other fields, and that the terms are not clearly defined in the Draft for Comment, we cannot rule out the possibility that such concepts may have other meanings. It is recommended that enterprises follow closely the relevant legal developments.
As defined in the Information Security Technology - Guidelines for Data Cross-Border Transfer Security Assessment, “cross-border data transfer” mainly refers to “one-off or continuous activities in which network operators provide overseas institutions, organizations or individuals with the personal information and important data collected and produced during operations within the territory of the PRC through the Internet or other means, such as direct provision, conducting business, provision of services or products”. Therefore, considering the distinction of “domestic” and “offshore”, and the above interpretation, we believe that, for Hong Kong listings, post-listing data transfer to Hong Kong should still be considered as cross-border data transfer, and therefore enterprises need to comply with the provisions on cross-border data transfer in the Cybersecurity Law, Data Security Law and supporting measures.
4) Does “one million user personal information” mean one million pieces of personal information or the personal information of one million users?
The Guidance for Operations of National Cybersecurity Inspection contains similar requirements in the section “Identification of CII”. The factors to be examined in identifying CII include “the number of registered users exceeds ten million”, “the average number of daily visits exceeds one million”, and “causing the leakage of personal information of more than one million individuals”. All these provisions are made from the perspective of the number of personal information subjects rather than the quantity of personal information.
Since the legislative purpose of the Guidance for Operations of National Cybersecurity Inspection is similar to that of the Draft for Comment, i.e., to strictly regulate the entities or activities (including but not limited to listings abroad) that may affect a large number of individuals in order to protect economic and livelihood interests, we believe that the “one million user personal information” in the Draft for Comment is more likely to refer to the personal information of one million individuals.
5) How to understand “the operators “with” personal information”? If an operator only provides storage or transfer services, or entrusts other third parties such as cloud service providers to process personal information, is it subject to regulation?
We understand that the expression of operators “with” personal information is similar to the concept of “controller”, therefore we can refer to the definition of controller for its interpretation. However, there is no clear legal distinction between controllers and processors in China. Due to increasingly stringent regulations, we recommend that enterprises include both physical data control and data processing in a legal context in this category and apply for cybersecurity review.
6) What materials are required to be submitted for cybersecurity review? What IPO materials need to be provided?
The application materials should include:
A declaration;
An analysis report concerning the impact or possible impact on national security;
The procurement document, agreement, contract to be concluded or IPO documents to be submitted, among others; and
Other materials required for the cybersecurity review.
Specifically, with reference to data security laws and other related legislation, we believe that an analysis report may contain a number of elements such as supply chain security, data security and compliance, cross-border data transfer, and jurisdictional conflict resolution mechanisms. For the purpose of the review, we believe that IPO documents may include prospectuses, but whether they include working papers remains to be clarified.
7) How long will the cybersecurity review take and will it affect the listing process?
In accordance with the Draft for Comment, the Cybersecurity Review Office shall, within ten (10) working days of receiving the declaration materials for review, determine whether the review is required and notify the operators in writing. Where the Cybersecurity Review Office deems it necessary to conduct a cybersecurity review, it shall complete the preliminary review within thirty (30) working days from the date of issuing a written notice to the operators; if the case is complicated, the said time limit may be extended by fifteen (15) working days. Members of the cybersecurity review working mechanism and relevant CII protection departments shall give a written reply to the operator within fifteen (15) working days of receiving the suggested finding. If the members of the cybersecurity review working mechanism have not reached a unanimous agreement on the suggested finding, the case shall enter the special review process. The special review process shall generally be completed within three (3) months, and may be extended if the case is complicated.
In conclusion, the general procedure takes a maximum of 70 (10+30+15+15=70) working days as of the date of application. However, the maximum duration of the special review process is 70 working days + 3 months + n working days ≈ 135 + n working days, that is, the actual calendar days needed to complete such a process may reach 180 days (6 months) or more.
8) Effective date of the Draft for Comment
Considering the recent cybersecurity review enforcement developments and the focus of the Draft for Comment on the regulation of activities such as listings aboard, we do not rule out the possibility that the Draft for Comment will take effect soon. However, even if it has not come into effect or it will come into effect at a later date, considering that some enterprises have already been investigated and punished, it’s understood that enterprises can reduce their risk to a certain extent by preparing countermeasures in advance, rather than defend on the ground that the Draft for Comment has not come into effect.
△ Basic questions
1) What are critical information infrastructure operators?
Critical Information Infrastructure includes the information infrastructure in such important industries and fields as public communications and information services, energy, transportation, water conservancy, finance, public services and e-government and CII that may result in serious damage to state security, the national economy and the people’s livelihood and public interest if it is destroyed, loses functions or encounters data leakage. However, the specific scope and security protection measures of CII have not been officially promulgated yet.
In accordance with the Guiding Opinions on Implementing the Graded Protection System for Cybersecurity and the Security Protection System for Critical Information Infrastructure promulgated by the Ministry of Public Security in 2020, competent and regulatory authorities in charge of such important industries and fields as public communications and information services, energy, transportation, water conservancy, finance, public services, e-government and science and technology industry for national defense shall develop the rules for the identification of CII in such industries and fields and file the same with the Ministry of Public Security for record. In addition, they shall include eligible basic networks, large private networks, core business systems, cloud platforms, big data platforms, Internet of things, industrial control systems, intelligent manufacturing systems, new Internet, emerging communication facilities and other key objects under protection into CII.
2) What are competent authorities for cybersecurity review?
Competent authorities for cybersecurity review mainly include the cybersecurity review working mechanism of the PRC and the Cybersecurity Review Office.
Among them, the cybersecurity review working mechanism is established by the CAC in concert with the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security, the Ministry of State Security, the Ministry of Finance, the Ministry of Commerce, the People’s Bank of China, the State Administration for Market Regulation, the National Radio and Television Administration, China Securities Regulatory Commission, the National Administration of State Secrets Protection and the State Cryptography Administration.
Cybersecurity Review Measures
(comparison)
In this article, any reference to Hong Kong, Macao and Taiwan shall be construed as a reference to the Hong Kong Special Administrative Region of the PRC, the Macao Special Administrative Region of the PRC and the Taiwan region of the PRC.
Authors
Susan Ning
Partner
Regulatory & Compliance
susan.ning@cn.kwm.com
Areas of Practice:cybersecurity and data compliance, and antitrust and competition law
Susan is one of the first lawyers practicing in Cybersecurity and Data Compliance area, with a professional team of Interdisciplinary background. Her publications include Big Data: Success Comes Down to Solid Compliance, China’s Step Forward to Personal Information Protection, Does Your Data Need a “VISA” to Travel Abroad?, Petya attack makes it a proper time to prepare emergency plan for cybersecurity incidents, No “Data”, No “Internet of Vehicles”, and A Brief Analysis on the Impact of Data on Competition in the Big Data Era in professional journals such as Journal of Cyber Affairs. Susan’s practice areas cover self-audit on network security, responding to network security check initiated by authorities, data compliance training, due diligence of data transaction or exchange, compliance of cross border data transmission, etc. Susan has assisted companies in sectors such as IT, transportation, online payment, consumer goods, finance, Internet of Vehicles in dealing with network security and data compliance issues.
Wu Han
Partner
Regulatory & Compliance
wuhan@cn.kwm.com
Areas of Practice:cybersecurity and data compliance, and antitrust and competition law
In the area of cybersecurity and data compliance, Mr. Wu will provide the services including: assisting clients to establish internal cybersecurity compliance system, helping clients to sort out the compliance system of data circulation, conducting the internal training of cybersecurity and data compliance, executing due diligence of data transaction, assisting clients to design the data trans-border plan and providing advices on responding to investigation on cybersecurity and emergency cybersecurity incidents, including but not limited to reporting bug, network investigation, collecting evidence of remedial actions, and reporting the cybersecurity. Mr. Wu has provided legal services on the cybersecurity and data compliance for several leading enterprises in multi-industries. The projects he participated in cover the industry of financial payment, financial clearing, online platform for vehicle booking, consumer electronics, internet advertising and personal care.
Mr. Wu is the only lawyer from Chinese law firms featured as the 40-under-40 Data Lawyers by Global Data Review in 2018.
Jiang Ke
Partner
Regulatory & Compliance
jiangke@cn.kwm.com
Areas of Practice:on regulatory compliance in the fields of technology, telecommunication, cybersecurity and data protection
With respect to regulatory compliance in technology and telecom industries, Mr. Jiang has advised various technology and internet companies for a wide range of regulatory issues in the past more than ten years, and acted as an in-house counsel to support the operation and product compliance of AWS cloud services in China. Such regulatory issues cover market access, landing, operation and selling of digital contents, cloud and other value-added telecom services, also cover the full life cycle of hardware products from their production, import and export, selling, after sale to recall and destruction, as well as relevant marketing, advertising and consumer protection. Products and services concerned range from mobile phone and other smart devices, wearable devices, commercial encryption and dual-use products, to digital services such as apps, online books, music, movies and games.With respect to cybersecurity and data protection, Mr. Jiang frequently advises multinational companies in China on their cybersecurity and data compliance issues, and was the lead counsel for BMW China’s digitization and cybersecurity projects. Mr. Jiang provides clients with services in this respect including: assisting to draft and review privacy polices and relevant compliance programs; conducting assessment on personal information protection systems and bylaws; sorting out business scenario specific cross-border data transfer and assisting to formulate transfer compliance programs; assisting to formulate and assess compliance programs for transaction and commercial use of data; assisting to conduct self-assessment and internal training for cybersecurity and data compliance; and assisting to cope with cybersecurity inspections and emergencies.
Lucia Liu
Associate
Regulatory & Compliance
Thanks to intern Zhang Ziqian for her input to this article.
人工智能:
数据合规:
个人信息保护立法效果、理念及价值平衡 ——欧盟GDPR生效实施三周年比较与前瞻 2021-5
数字征信时代的重要信号——征信业务新规草案解读 2021-1
成年人要看的利弊——互联网数据商业化的模式变局 2020-12
Personal Information Protection Law (Draft): A New Data Regime 2020-11
“道阻且长,行则将至” --从《个人信息保护法(草案)》看中国个人信息保护的思路和数字经济发展策略 2020-10
六个月倒计时!《生物安全法》中的数据合规赛道 2020-10
敢为天下先——特区培育数据要素市场的契机与合规要点 2020-10
“以人为本”——聚焦央行消费者金融信息保护新规 2020-09
变化纵横出新意——民法典中个人信息的定位及影响 2020-06
问答精选-解读《个人金融信息技术保护规范》2020-02
解读《信息安全技术 个人信息告知同意指南(征求意见稿)》2020-02
疫情防控 | 数据资源流转与公开 2020-02
疫情防控|同舟共济——不同场景下健康医疗数据流转的合规路径 2020-02
宜未雨而绸缪——企业上市关注的重点数据合规问题 2020-01
“数”年快乐——万字长文说“数据融合” 2020-01
平安夜里说平安——“数据资产”的误区与合规条件 2019-12
按图索骥——图示移动APP个人信息保护的重点 2019-11
大一统而慎始也——新型信用监管机制问答 2019-10
竹杖芒鞋轻胜马:医疗大数据发展和合规管理并重 2019-09
星光奉献给长夜——儿童个人信息保护的亮点和启示 2019-08
投资出行领域,数据是金矿还是烫手山芋?2019-07
Development Of PrcRegulations On Cross Border Data Transfer 2019-06
数据监管新要求,电子商务法时代跨境电商将走向何方? 2018-11
你的“饼干”安全吗?——Cookie 与个人信息保护 2018-08
“明者因时而变,知者随事而制” ——《个人信息安全规范》实务探讨 2018-02
谨于言而慎于行:互联网信息内容服务管理新规出台 2017-08
No “Data”, No “Internet of Vehicles” 2017-07
布局“自动驾驶”:此时不为,更待何时?2017-07
Putting an “Invisibility Cloak” over Personal Information —— A discussion on “invisible waybills” introduced by express industry 2017-07
图解“车联网” 2017-06
无“数据”,怎“车联”?——“车联网”数据类核心业务法律监管刍议 2017-05
为个人信息披上一件“隐形衣”——从快递行业推行“隐形面单”说开去 2017-05
欲善其事,先利其器——解读《互联网信息内容管理行政执法程序规定》 2017-05
你的数据,能不能走出国门? 2017-04
中国推进个人信息保护 2017-04
2017年,大数据合规离我们有多远? 2017-01
隔耳有“墙”——从美国FCC新规则谈个人信息保护新趋势 2016-12
个人信息保护的百万罚单时代来了? 2016-11
网络安全:
八问八答——《网络安全审查办法(修订草案征求意见稿)》重点解读 2021-07
利刃出鞘:《数据安全法》下中国数据保护路径解读 2021-06
Innovations & New Developments of Cybersecurity Review Measures 2020-05
“柳暗花明又一村”——金融产业链的困局及破局思路 2020-03
“云深不知处”——企业远程办公的网络安全常见问题及建议 2020-02
“管中窥豹”——《生物安全法》前瞻及现行生物安全相关监管体系回顾 2020-02
博观而约取,厚积而薄发:《密码法》要点评析及企业合规路径 2019-11
亡羊补牢未为迟:如何应对网络安全勒索事件 2019-06
“欲穷千里目,更上一层楼”——国际新形势下的等保2.0 2019-05
叶上初生并蒂莲——最新出台的《电子商务法》与《网络安全法》之比较 2018-09
《网安法》生效后不得不知的N件大事 2017-08
“新”电信业务办法:更简、更活、更规范 2017-07
必将婴城固守,皆为金城汤池——看《关键信息基础设施安全保护条例(征求意见稿)》 2017-07
Petya来袭,网络安全事件应急预案正当其时 2017-07
图解安全评估流程——互联网业务安全不可因“新”而废“管” 2017-06
《网络安全法》及其部分配套规定今起实施 2017-06
“一带一路”背景下中国企业境外并购的网络安全和数据合规问题 2017-06
十三五“新常态”下企业营商的合规挑战 2017-05
开启互联网新闻监管新时代——《互联网新闻信息服务管理规定》述评 2017-05
画龙画虎先画骨 ——解读《网络产品和服务安全审查办法(试行)》 2017-05
热点解读:网信办连续颁布三项重磅新规 2017-05

我知道你 在看 哦

