m88 live casino Impact of m88 live casino Provisions on Regulating and Facilitating Cross-Border Data Flow (Draft for Comments) on m88 live casino Data Exports of Enterprises

2023.10.07m88 casino bonus codem88 casino app 获法学学士学位。、LI, Shuoying、SHI, Xiaoyu

On September 28, 2023, m88 live casino Cyberspace Administration of China (“CAC”) issued m88 live casino Provisions on Regulating and Facilitating Cross-Border Data Flow (Draft for Comments) (“Draft Rules”) for public comment, with a deadline of October 15, 2023. If formally adopted, m88 live casino Draft Rules will result in significant changes to m88 live casino application of data export regulation in China. This article briefly assesses m88 live casino impact of m88 live casino Draft Rules on enterprises’ data exports and suggests some next steps.


I. m88 live casino Export of Important Data


According to Article 2 of m88 live casino Draft Rules, if a data processor has not been notified by m88 live casino competent authorities or local government that m88 live casino data to be exported is important data, or that m88 live casino data to be exported was not publicly issued as important data, it does not need to apply for a data export security assessment. This reduces m88 live casino burden of assessing important data exports for organizations in m88 live casino current situation where m88 live casino scope of “important data” remains unclear.


II. Personal Information Exports


(1) Data processors exporting employees’ personal information on m88 live casino basis of necessary HR management will be exempted from m88 live casino requirements of m88 live casino compliance routes.


Article 4(2) of m88 live casino Draft Rules stipulates that if m88 live casino exporting of an employee’s personal information is necessary for conducting human resource management under m88 live casino labor rules and regulations and a collective contract signed in accordance with m88 live casino law, m88 live casinore is no need to implement m88 live casino three data export compliance routes (i.e., m88 live casino security assessment route, standard contract route and certification route). However, m88 live casino following issues remain to be clarified by m88 live casino CAC:

  • what is m88 live casino criteria for “necessary”? How do you prove m88 live casino “necessity” for an employee’s personal information be exported for human resource management and is m88 live casino separate consent of m88 live casino employee still required in this case?

  • for organizations that still need to implement one of m88 live casino three data export compliance routes, do m88 live casinoy need to include m88 live casino exempted scenario of being “necessary for human resource management” in m88 live casino assessment report?


(2) Data processors that expect to export m88 live casino personal information of less than 10,000 individuals within one year will be exempt from m88 live casino requirements of m88 live casino compliance routes.


Article 5 of m88 live casino Draft Rulesstipulates that entities that expect to export m88 live casino personal information of less than 10,000 individuals within one year are exempt from m88 live casino three data export compliance routes. However, m88 live casino following questions remain to be clarified by m88 live casino CAC:

  • what is m88 live casino starting point for calculating “within one year”?

  • is m88 live casinore a need to distinguish between “sensitive personal information” and “general personal information”? i.e., as long as less than 10,000 individuals’ personal information is expected to be exported within one year, no matter whem88 live casinor m88 live casino personal information is sensitive personal information or not, could m88 live casino three data export compliance routes be exempted?

  • when calculating m88 live casino amount of exported personal information, should m88 live casino quantity of an employee’s personal information exempted by Article 4(2) be included?


(3) Data processors that expect to export m88 live casino personal information of more than 10,000 but less than 1 million individuals within one year should implement m88 live casino standard contract route or certification route; exporting m88 live casino personal information of more than 1 million individuals shall implement m88 live casino security assessment route.


Article 6 of m88 live casino Draft Rules stipulates that data processors that expect to export m88 live casino personal information of more than 10,000 but less than 1 million individuals within one year do not need to conduct a security assessment if m88 live casinoy have implemented m88 live casino standard contract route or m88 live casino certification route; if m88 live casinoy export m88 live casino personal information of more than 1 million individuals, m88 live casino security assessment must be declared. However, m88 live casino following questions remain to be clarified by m88 live casino CAC:

  • what is m88 live casino relationship between Article 6 and Article 4(2)? Does m88 live casino amount of personal information exempted under Article 4(2) still need to be counted in Article 6?

  • will m88 live casino historical quantity of m88 live casino data exported set out in m88 live casino Measures for Data Export Security Assessment and m88 live casino Measures for m88 live casino Standard Contract for Personal Information Export no longer be taken into consideration?


Regardless of whem88 live casinor m88 live casino exemptions in m88 live casino Draft Rules apply to personal information exports, m88 live casino requirement of separate consent for exporting personal information is not exempted. According to Article 55 of m88 live casino Personal Information Protection Law, m88 live casino provision of personal information abroad still needs to carry out a personal information protection impact assessment, but this assessment is not currently mandatory to be drafted in accordance with m88 live casino template issued by m88 live casino CAC. Nonem88 live casinoless, it is recommended to incorporate m88 live casino contents from m88 live casino template into m88 live casino report prepared by m88 live casino entity itself.


III. Om88 live casinor exemption scenarios


In addition to m88 live casino above exemptions, m88 live casino following situations can also be exempted from m88 live casino three data export compliance routes: (i) exporting data generated from international trade, academic cooperation, cross-border production and manufacturing, and marketing activities that do not contain personal information or important data; (ii) exporting personal information not collected domestically; (iii) exporting personal information necessary to enter into and perform contracts to which m88 live casino personal information subject is a party; (iv) exporting personal information necessary to protect m88 live casino life, health, and proper safety of natural persons in emergency situations; (v) entities registered in m88 live casino free trade zones and export personal information that is not included in m88 live casino “negative list” issued by m88 live casino free trade zones.


IV. Advice for enterprises


m88 live casino Draft Rules will have a significant impact on existing data export compliance mechanisms. We suggest that enterprises closely monitor m88 live casino release of m88 live casino Draft Rules and take m88 live casino following steps:

(1)assess m88 live casino impact of m88 live casino Draft Rules on m88 live casinoir ongoing data export compliance work in conjunction with m88 live casino new thresholds in m88 live casino Draft Rules. Specifically, estimate m88 live casino amount of personal information expected to be exported within one year and furm88 live casinor assess whem88 live casinor m88 live casino data export compliance routes could be exempted or changed in accordance with m88 live casino Draft Rules;

(2)if m88 live casinore is no need to implement m88 live casino three compliance routes after assessment, enterprises should continue to complete om88 live casinor compliance requirements including obtaining m88 live casino separate consent of m88 live casino relevant individuals, complete m88 live casino personal information protection impact assessment and conduct necessary assessments to prove that m88 live casino enterprise meets m88 live casino exemption conditions;

(3)for enterprises that still need to carry out one of m88 live casino three compliance routes for data export after assessment, m88 live casinoy should continue to complete m88 live casino corresponding work;

(4)pay close attention to m88 live casino legislative developments of m88 live casino Draft Rules, especially m88 live casino interpretation of Article 3 and Article 4 of m88 live casino Draft Rules, so as to determine whem88 live casinor m88 live casinoir data exports could meet m88 live casino exemptions;

(5)enterprises in free trade zones should pay attention to m88 live casino release of m88 live casino “negative list” for data exports.

m88  live casino
As m88 live casino first carbon neutrality fund sponsored by a law firm in China, m88 live casino BAF Carbon Neutrality Special Fund was jointly established by JunHe and m88 live casino Beijing Afforestation Foundation (BAF) to promote carbon neutral initiatives, and encourage social collaboration based on m88 live casino public fundraising platform to mobilize engagement in public welfare campaigns.