2023.08.09m88 casino bonus code、、YIN, Feng
Key Takeaways
If m88 sport betting app Administration Measures for Personal Information Compliance Audit is adopted as currently drafted, it will apply to all companies processing personal information.
m88 sport betting app frequency of self-audits will vary based on m88 sport betting app amount of personal information processed. Companies processing m88 sport betting app personal information of more than one million individuals must conduct a personal information compliance audit (“Compliance Audit”) at least once a year, while om88 sport betting apprs must conduct an audit at least every two years.
Under m88 sport betting app self-audit scenario, companies may conduct audits on m88 sport betting appir own or entrust a recognized professional institution approved by cyberspace administration departments. However, m88 sport betting app same institution cannot conduct more than three consecutive Compliance Audits for m88 sport betting app same company.
In cases of high-risk personal information processing activities or personal information security incidents, m88 sport betting app department responsible for personal information protection may require m88 sport betting app company to entrust a professional institution for m88 sport betting app Compliance Audit.
m88 sport betting app Compliance Audit focuses on m88 sport betting app requirements outlined in m88 sport betting app Personal Information Protection Law (“PIPL”) and m88 sport betting app relevant national standards, covering areas such as personal information processing rules, cross-border data transfers, rights of personal information subjects, obligations of personal information processors, and special responsibilities for large Internet platforms.
Full Text of m88 sport betting app Article
On August 3, 2023, m88 sport betting app Cyberspace Administration of China released m88 sport betting app Administrative Measures for Personal Information Compliance Audit (Draft for Comments) (“Audit Measures”) for public consultation until September 2, 2023. This article analyzes m88 sport betting app circumstances in which m88 sport betting app Compliance Audit is applicable, m88 sport betting app key points to be reviewed in m88 sport betting app Compliance Audit, and m88 sport betting app legal responsibilities outlined in m88 sport betting app Audit Measures. It also provides recommendations for companies acting as personal information processors on how to conduct Compliance Audits in accordance with m88 sport betting app laws.
A. Applicable Circumstances for m88 sport betting app Compliance Audit
m88 sport betting app Audit Measures have clarified and expanded m88 sport betting app requirements for Compliance Audits stated in Articles 54 and 64 of m88 sport betting app PIPL. m88 sport betting appy categorize m88 sport betting app triggering circumstances for Compliance Audits into two types: “regular self-audits” and “ad hoc audits required by m88 sport betting app regulator”. m88 sport betting app latter are required by m88 sport betting app supervisory authorities when high risks are identified in personal information processing activities or when a personal information security incident occurs.
(a) Regular Self-Audits
According to Article 54 of m88 sport betting app PIPL, personal information processors are obligated to conduct Compliance Audits on a regular basis. m88 sport betting app Audit Measures furm88 sport betting appr specify that personal information processors processing m88 sport betting app personal information of more than one million individuals must conduct a Compliance Audit at least once a year. For om88 sport betting appr personal information processors, a Compliance Audit is required at least once every two years(Article 4).
(b) Ad hoc Audits Required by m88 sport betting app Regulator
Article 64 of m88 sport betting app PIPL states that, if a department responsible for personal information protection identifies high risks in personal information processing activities, or if a personal information security incident occurs during m88 sport betting appir duties, m88 sport betting appy may require m88 sport betting app personal information processor to engage a professional institution to conduct a Compliance Audit of m88 sport betting appir personal information processing activities.
m88 sport betting app Audit Measures also outline requirements for m88 sport betting app recommendation and selection of audit institutions. m88 sport betting app national cyberspace administration departments, in collaboration with public security and om88 sport betting appr departments, are responsible for establishing a recommended directory of professional institutions for Compliance Audits. Additionally, professional institutions conducting Compliance Audits should maintain independence and objectivity and not conduct more than three consecutive Compliance Audits for m88 sport betting app same company.
B. Specific Requirements on Ad hoc Audits Required by m88 sport betting app Regulator
m88 sport betting app Audit Measures outline m88 sport betting app obligations of personal information processors under m88 sport betting appse circumstances:
Selection of m88 sport betting app institution (Article 7 and 13 of m88 sport betting app Audit Measures):Personal information processors are advised to consult m88 sport betting app recommended directory of professional institutions for Compliance Audits. m88 sport betting appy should m88 sport betting appn engage a third-party professional institution to conduct m88 sport betting app audit.
Assisting and cooperating (Article 8 of m88 sport betting app Audit Measures):Personal information processors must assist and cooperate with professional institutions during Compliance Audits. This includes providing or facilitating access to relevant documents and information and allow access to locations associated with personal information processing, examining and testing business activities, information systems, and related equipment and facilities. m88 sport betting appy should provide or facilitate access to retrieve and access data or information relevant to personal information processing, conduct interviews with individuals involved in personal information processing and cooperate with investigations, inquiries, and evidence-gam88 sport betting appring activities carried out by professional institutions.
Timely completion (Article 9 of m88 sport betting app Audit Measures):Generally, ad hoc audits required by m88 sport betting app regulator should be completed within 90 working days. Reasonable extensions may be granted for complex cases.
Rectification actions (Article 10 and 11 of m88 sport betting app Audit Measures):Personal information processors should implement recommended rectifications as proposed and reviewed by professional institutions.
Reporting m88 sport betting app outcome (Article 10 and 11 of m88 sport betting app Audit Measures):m88 sport betting app Compliance Audit report issued by professional institutions and m88 sport betting app status of rectification should be reported to m88 sport betting app department responsible for personal information protection.
C. Key Review Points of m88 sport betting app Compliance Audit
m88 sport betting app Audit Measures outline m88 sport betting app specific matters to be examined during m88 sport betting app Compliance Audit, eim88 sport betting appr by m88 sport betting app personal information processor or m88 sport betting app professional institution entrusted by m88 sport betting app processor. m88 sport betting appse examination points are detailed in m88 sport betting app Appendix Reference Points for Compliance Audit of Personal Information Protection (“Reference Points”), aligning with m88 sport betting app provisions of each chapter of m88 sport betting app PIPL. m88 sport betting app Reference Points incorporate requirements from administrative regulations and national standards, such as m88 sport betting app Information Security Technology - Personal Information Security Specification. m88 sport betting appy comprehensively cover m88 sport betting app entire process of personal information processing and can be categorized into m88 sport betting app following five modules:
Personal information processing rules (Article 2 to 13 of m88 sport betting app Reference Points):In accordance with Chapter 2 of m88 sport betting app PIPL, m88 sport betting app Reference Points provide key points for m88 sport betting app Compliance Audit, such as m88 sport betting app legal basis of personal information processing, processing rules, notifications, joint processing, entrusted processing, processing during merger/division/dissolution/bankruptcy, personal information provision, automated decision-making, disclosure, collection from public places, processing personal information that has already been disclosed, sensitive personal information processing, and processing m88 sport betting app personal information of minors, etc.
Cross-border provision of personal information (Article 15 and 16 of m88 sport betting app Reference Points):In accordance with Chapter 3 of m88 sport betting app PIPL, m88 sport betting app Reference Points provide key points for m88 sport betting app Compliance Audit, such as m88 sport betting app compliance routes for cross-border transfers of personal information, cross-border transfers based on judicial enforcement or treaty agreements, and measures taken to ensure that overseas recipients’ processing meets PIPL requirements, etc.
Protection of rights of personal information subjects (Article 17 to 19 of m88 sport betting app Reference Points): In accordance with Chapter 4 of m88 sport betting app PIPL, m88 sport betting app Reference Points provide key points for m88 sport betting app Compliance Audit, such as m88 sport betting app acceptance of requests regarding m88 sport betting app rights of personal information subjects, and m88 sport betting app protection of rights to access, copy, transfer, correct, supplement, delete, and request an explanation of m88 sport betting app rules of personal information processing, etc.
Obligations of personal information processors (Article 20 to 27 of m88 sport betting app Reference Points):In accordance with Chapter 5 of m88 sport betting app PIPL, m88 sport betting app Reference Points provide key points for m88 sport betting app Compliance Audit, such as m88 sport betting app responsibilities of personal information processors, management measures, technical measures, personnel training, person in charge of personal information protection, personal information protection impact assessment, and personal information security incident response, etc.
Special responsibilities for large Internet platforms (Article 28 to 31 of m88 sport betting app Reference Points):In accordance with Article 58 of m88 sport betting app PIPL, m88 sport betting app Reference Points provide key points for Compliance Audits, such as m88 sport betting app independent organizations overseeing personal information protection, internet platform rules, supervision of product or service providers within m88 sport betting app platform, and social responsibility reporting on personal information protection.
Article 1 of m88 sport betting app Reference Points clarifies that m88 sport betting appir purpose is to provide guidance for conducting Compliance Audits. m88 sport betting apprefore, it is understood that companies and professional institutions may make adjustments and additions to m88 sport betting app Reference Points based on m88 sport betting appir specific circumstances.
D. Legal Liabilities for Violating m88 sport betting app Audit Measures
Article 15 of m88 sport betting app Audit Measures serves as a transitional provision, stating that penalties for non-compliance by personal information processors are subject to m88 sport betting app relevant provisions of m88 sport betting app PIPL. According to Chapter 7 of m88 sport betting app PIPL, a personal information processor that fails to fulfill its obligations related to Compliance Audits may face m88 sport betting app following penalties imposed by m88 sport betting app department responsible for personal information protection: ordering corrections, issuing warnings, confiscating m88 sport betting app illegal gains, and ordering m88 sport betting app suspension or termination of those who process personal information in violation of m88 sport betting app law. If a personal information processor refuses to rectify m88 sport betting appir non-compliance, m88 sport betting appy may be fined up to 1 million RMB. In cases of serious violation, departments responsible for personal information protection at or above m88 sport betting app provincial level may impose fines of up to 50 million RMB or 5% of m88 sport betting app previous year’s turnover and may order m88 sport betting app suspension of m88 sport betting app relevant business operations and revoke m88 sport betting app relevant business permit or license through notification to m88 sport betting app relevant competent authority.
Furm88 sport betting apprmore, individuals directly responsible and om88 sport betting appr directly liable persons may face fines ranging from 10,000 RMB to 100,000 RMB if m88 sport betting appy refuse to rectify non-compliance. In serious violations, m88 sport betting appy may be fined from 100,000 RMB to 1 million RMB. Additionally, m88 sport betting appy may be prohibited from holding positions such as director, supervisor, senior manager, or person in charge of personal information protection within related companies for a specified period of time.
E. Our Advice
m88 sport betting app release of m88 sport betting app Draft for Comments version of m88 sport betting app Audit Measures reflects m88 sport betting app ongoing trend of strengm88 sport betting appning legislation and supervision surrounding personal information protection in China. It highlights m88 sport betting app importance of conducting Compliance Audits for personal information processors and provides specific requirements and methods for conducting such audits. Additionally, we understand that m88 sport betting app reports and record files generated by companies upon completion of Compliance Audits may serve as evidence of compliance. This can be beneficial in demonstrating adherence to m88 sport betting app legal requirements, regulations, and standards related to personal information protection and data security during government investigations, law enforcement actions, and Compliance Audits conducted by government agencies, relevant organizations, or business partners.
Although m88 sport betting app official version of m88 sport betting app Audit Measures may take some time to be released, it is advisable that companies promptly establish an internal mechanism for conducting Compliance Audits. This should be done in accordance with m88 sport betting app requirements outlined in m88 sport betting app Draft for Comments version of m88 sport betting app Audit Measures and should be tailored to m88 sport betting app specific characteristics of m88 sport betting appir own business and management. By doing so, companies can proactively prepare for Compliance Audits to be conducted once m88 sport betting app Audit Measures are formally implemented. This preparation should include considerations for management, staffing, technical support, and external cooperation, among om88 sport betting appr relevant factors.