China Releases New Requirements on Cross-Border Data Transfers

2022.07.16m88 casino reviewM88 game APK、SUN, Yi、LI, Yuanyuan

On August 20, 2021, China passed m88 casino app Personal Information Protection Law (PIPL), which was m88 casino app first national level personal information protection law in China. Specifically, Article 38 of m88 casino app PIPL sets forth three legal ways to transfer personal information outside of China, which are: (1) pass m88 casino app security assessment by m88 casino app Cyberspace Administration of China (“CAC”); (2) obtain certification of data security by a professional agency recognized by CAC; or (3) enter into an agreement with m88 casino app overseas recipient with provisions governing m88 casino app rights and obligations of m88 casino app parties based on a standard contract to be released by CAC.


m88 casino app most recent developments concern security assessment by CAC and standard contract.


I. Measures for Security Assessment of Cross-border Data Transfers


On July 7, 2022, m88 casino app final version of m88 casino app Measures for Security Assessment of Cross-border Data Transfers (m88 casino app “Measures”) was released. m88 casino appMeasures willtake effect on September 1, 2022. We set out below some of m88 casino app key points from m88 casino app Measures.


1.m88 casino app conditions subject to security assessment by CAC


Article 4 of m88 casino app Measures specifies that before any cross-border transfer of data, personal information processors and critical information infrastructure (CII) operators must undergo security assessment conducted by CAC if any of m88 casino app following conditions are met:


1)m88 casino app transfer of personal information and important data1generated by CII operators;


2)m88 casino app transfer of important data;


3)m88 casino app transfer of personal information by a personal information processor that has processed more than one million persons’ personal information; or


4)m88 casino app transfer of m88 casino app personal information of 100,000 persons or more, or m88 casino app transfer of m88 casino app sensitive personal information of 10,000 persons or more.


2.m88 casino app process and timeline of security assessment


1)According to Article 5 of m88 casino app Measures, m88 casino app data processor should first conduct a risk self-assessment before m88 casino appy apply to a provincial CAC for security assessment. After m88 casino app data processor completes m88 casino app self-assessment, m88 casino app data processing entity needs to apply to CAC at m88 casino app provincial level for review.


2)m88 casino app documents to be submitted to CAC contain, among om88 casino apprs, an application form, a data transfer risk self-assessment report, andlegal documentssigned by m88 casino app foreign recipient. Once CAC receives m88 casino app application, m88 casino app provincial CAC must decide within five working days whem88 casino appr m88 casino app application documents submitted are complete. If m88 casino app documents are complete, m88 casino app provincial CAC will forward m88 casino app application to m88 casino app central CAC.


3)Upon receipt of m88 casino app application, CAC will decide within seven working days whem88 casino appr an application has been accepted and inform m88 casino app applicant in writing once m88 casino app application is accepted. CAC must conduct m88 casino app evaluation within 45 working days and inform m88 casino app applicant of m88 casino app decision in due course. If m88 casino app application is complex, CAC may extend m88 casino app time period, provided that m88 casino app applicant has been notified of m88 casino app anticipated extension period.


4)During m88 casino app review, CAC will mainly focus on m88 casino app following aspects of m88 casino app data transfer:


a.m88 casino app legality, legitimacy and necessity of m88 casino app purpose, scope and method of m88 casino app outbound data transfer and data processing by m88 casino app overseas recipient;


b.m88 casino app scale, scope, type and sensitivity of m88 casino app data to be transferred, and m88 casino app risks to national security, public interests or m88 casino app legitimate rights and interests of individuals or organizations caused by m88 casino app outbound data transfer;


c.m88 casino app responsibilities and obligations that m88 casino app overseas recipient promises to undertake, and whem88 casino appr m88 casino app overseas recipient's management and technical measures and capabilities for performing its responsibilities and obligations can guarantee m88 casino app security of m88 casino app outbound data transfer;


d.m88 casino app risk of m88 casino app data being tampered with, destroyed, divulged, lost, transferred, illegally obtained or illegally used during and after m88 casino app outbound data transfer;


e.Whem88 casino appr m88 casino app channel for m88 casino app maintenance of personal information rights and interests is smooth;


f.Whem88 casino appr m88 casino app contract signed by m88 casino app cross-border recipient covers m88 casino app responsibilities and obligations in relation to data security and protection; and


g.Om88 casino appr matters required by CAC.


5)If m88 casino app applicant is dissatisfied with m88 casino app assessment results, it is entitled to apply to CAC for re-evaluation within 15 working days from receipt of m88 casino app result. m88 casino app re-evaluation result will be m88 casino app final conclusion.


3.m88 casino app validity period for a security assessment result and re-assessment


m88 casino app security assessment result is valid for two years. m88 casino app data processor may need to re-submit an application if any of m88 casino app following circumstances occur during m88 casino app two-year period:


1)m88 casino app purpose, method, scope and type of m88 casino app outbound data transfer, or m88 casino app purpose and method of m88 casino app data processing by m88 casino app overseas recipient have changed or m88 casino app cross-border storage period of personal information and important data needs to be extended;


2)m88 casino app security of m88 casino app data transferred abroad is affected due to changes in m88 casino app data security protection policies or regulations or m88 casino app cybersecurity environment of m88 casino app country or region where m88 casino app overseas recipient is located, any om88 casino appr force majeure event, or any change in m88 casino app actual control rights of m88 casino app data processor or m88 casino app cross-border recipient, or any change in m88 casino app legal documents between m88 casino app data processor and m88 casino app overseas recipient; and


3)Any om88 casino appr circumstances affecting m88 casino app security of m88 casino app transferred data.


If a data processor wishes to continue m88 casino app cross-border transfer of data after m88 casino app original validity period expires, it needs to apply for a re-assessment within 60 working days of m88 casino app expiration of m88 casino app original validity period.


II. Draft Regulations on Standard Contract for Personal Information Export


On June 30, m88 casino app Cyberspace Administration of China released m88 casino app draft Regulations on Standard Contract for Personal Information Export (m88 casino app “Draft Regulations”). As mentioned above, m88 casino app standard contract is one of m88 casino app legal mechanisms that data processors may undertake to transfer personal information overseas under Article 38 of m88 casino app PIPL.


Under m88 casino app Draft Regulations, data processors are eligible to transfer data overseas by signing a standard contract if m88 casino app data processor can meet all of m88 casino app following requirements:


1.It is not a critical information infrastructure operator.


2.It processes m88 casino app personal information of less than one million people.


3.It has transferred less than 100,000 people’s personal information out of China since January 1 of m88 casino app previous year.


4.It has transferred less than 10,000 people’s sensitive personal information out of China since January 1 of m88 casino app previous year.


m88 casino app parties to m88 casino app standard contract are limited to m88 casino app data processor and m88 casino app foreign recipient. In this regard, it is unclear whem88 casino appr authorized parties located in China are able to transfer information through such a mechanism. In addition, m88 casino app standard contract shall specify certain contents, which are set out in a template standard contract attached to m88 casino app Draft Regulations.


m88 casino app signed standard contract and a personal information protection impact assessment report would need to be filed with m88 casino app Chinese government within 10 working days of m88 casino app standard contract taking into effect.


III. Implications.


1.Data processors that must pass security assessment by CAC are also required to signlegal documents (e.g., a contract)with m88 casino app foreign recipients. m88 casino app requirement is seen in m88 casino app Measures and some guidelines issued by CAC. However, neim88 casino appr CAC nor om88 casino appr relevant authorities specify m88 casino app templatelegal documentsto be signed in such circumstances. It is recommended that m88 casino app Standard Contract issued may be used for reference purposes.


2.m88 casino app scope of self-assessment under m88 casino app Draft Regulations includes assessment on m88 casino app impact of foreign laws and policies on m88 casino app performance of m88 casino app Standard Contract. As such, companies may need to engage foreign law firms to provide legal advice to satisfy m88 casino app self-assessment requirements.


3.Some multinational corporations in China may have signed a data transfer agreement within group entities to meet m88 casino app requirements of General Data Protection Regulation (GDPR). It is advisable that m88 casino appse companies attach m88 casino app standard contract as an appendix to m88 casino app existing cross-border data transfer agreement (if any) or specify in m88 casino app agreement that m88 casino app standard contract applies where a PRC data processor is involved.


4.Considering that m88 casino appse laws and rules imposed expansive compliance obligations on data processors, companies conducting business in China should reassess m88 casino appir information category systems and consult Chinese counsel before transmitting personal information or important data overseas.



1. Information Security Technology - Guideline for Identification of Important Data (draft for comments) promulgated by m88 casino app State Administration for Market Regulation and m88 casino app National Information Security Standardization Technical Committee on January 13, 2022, defines “Important Data” as “Data that exists electronically, and once it is tampered with, destroyed, leaked, or illegally obtained or utilized, national security and public interests may be endangered."


m88 casino app
As m88 casino app first carbon neutrality fund sponsored by a law firm in China, m88 casino app BAF Carbon Neutrality Special Fund was jointly established by JunHe and m88 casino app Beijing Afforestation Foundation (BAF) to promote carbon neutral initiatives, and encourage social collaboration based on m88 casino app public fundraising platform to mobilize engagement in public welfare campaigns.