• news-banner

    Expert Insights

China’s Personal Information Protection Law – keeping up with the Joneses or increased cyber-security?

Up until recently, China’s data protection rules could be found through a number of laws and guidelines, found at both a national and local level. As of 20 August 2021, it would appear that the National People’s Congress of China took note of their global neighbours’ activity over the garden fence and implemented a comprehensive piece of data protection legislation, akin to Europe’s GDPR – the Personal Information Protection Law (PIPL).

It is currently unclear whether the driving force for PIPL was indeed to achieve parity with legislation such as the GDPR or whether the move was a result of the Chinese government’s increased focus on “cyber-security”. The parity argument can be made due to the obvious similarities drawn between GDPR and PIPL when looking at the rules surrounding the definitions and legal basis for the handling of personal data.

The cyber-security argument gains significant traction when the strict rules surrounding data localisation and the cross-border transfer of data are considered. An interesting case study that reflects China’s heightened cyber-security focus has been the Cyberspace Administration of China’s (CAC) treatment of Didi. The Chinese company Didi (akin to Uber) recently went public on the New York Stock Exchange, however, in a move that many have hailed as being to protect Chinese data sharing internationally, the CAC ordered app stores to stop offering the app on their platforms.

PIPL is due to become effective on 1 November 2021, leaving organisations with no time to waste in terms of understanding the obligations and effecting policies that ensure compliance with the new law. The recent treatment of Didi would suggest that data protection (and breaches thereof) will be treated severely. In stark contrast with the consequences for non-compliance under the old rules, companies in breach of the PIPL could face fines of up to 5% of the previous years’ revenue.

Below is a very brief overview of some of the key changes implemented by the new legislation.

Data Localisation

PIPL has widened the scope of “Critical Information Infrastructure Operators” (CIIOs) – organisations required to store information in China. Any organisation that reaches a certain threshold of processing personal information will be treated as a CIIO and required to localise data. Unfortunately, this threshold is still unknown. Given the proximity of the implementation date of PIPL, organisations that process large amounts of data should begin to prepare their ability to store data onshore. They should also consider the possibility that a dedicated body need be established or representative appointed in mainland China to meet the new administering requirements and reporting to the CAC.

Cross-Border Transfers

There are several ways in which organisations can transfer data outside of China. One of these methods has been taken straight from the GDPR playbook – standard contracts. As with the Standard Contractual Clauses (SCC) of GDPR, PIPL will require the company in question to enter into a standard contract, drafted by the CAC, with the foreign recipient of the personal information. The drafting has not yet been published, but companies must ensure that any existing contracts for the transferring of personal information are brought in line with these when released. It is important to note that separate consent will still be required from any data subjects whose personal information is to be transferred out of China.

GDPR v PIPL

Under the old legislation in China, express consent is the only legal requirement for processing personal information – PIPL introduces a further six legal bases. These are similar to GDPR (i.e. performance of a contract), however, organisations should take note that the PIPL does not contain a “legitimate interests” legal basis. In general, however, given the similarities, where an organisation is already compliant under GDPR, there should not be a significant requirement for the amendment of privacy policies to ensure compliance with PIPL. The problems will more likely arise where organisations are based solely in China and have not already implemented a GDPR compliant privacy policy.

Consent

Despite the additions of the further legal bases, consent will remain the cornerstone of Chinese data processing. For example, as mentioned above, specific consent will be required for any cross-border transfers that occur and consent may still be needed where separate sectoral laws apply – sector specific laws may even outweigh one of the new legal bases in certain circumstances.

Despite uncertainty surrounding several elements of PIPL, the reality is that there is not a lot of time left to ensure compliance. It will be a useful exercise, for all organisations processing Chinese data, to consider how the minor differences with the GDPR need to be reflected within their existing privacy policies.

Our thinking

  • Women in Leadership: Planning for the future

    Sarah Wigington

    Events

  • Retail Week quotes Ilona Bateson on the CMA’s investigation into environmental claims in the fashion retail sector

    Ilona Bateson

    In the Press

  • Fashion and the Green Claims Code brought into focus by open letter from the CMA.

    Ilona Bateson

    Quick Reads

  • Charles Russell Speechlys grows its rankings in The Legal 500 EMEA directory

    Frédéric Jeannin

    News

  • Landmark European AI Act Passed By The European Parliament

    Louise Zafer

    Insights

  • Expert Evidence - Avoiding fatal failure

    Claudine Morgan

    Insights

  • Charles Russell Speechlys hosts international arbitration event in Dubai

    Peter Smith

    Quick Reads

  • Property Patter – Filming Agreements Part 2

    Naomi Nettleton

    Podcasts

  • Charles Russell Speechlys Paris significantly strengthens litigation practice with notable team hire led by Frédéric Dereux

    Frédéric Dereux

    News

  • Trade Credit Insurance – Protection, Economic Instability and Increased Demand

    Mary Barrett

    Insights

  • Consumer Duty - FCA warns that some firms are “lagging behind”

    Richard Ellis

    Insights

  • UK Government AI Regulation Response & Roadmap – Is the Government behind the wheel?

    Mark Bailey

    Insights

  • Remote Hearings – factors to consider

    Richard Kiddell

    Insights

  • Richard Davies writes for City AM on the lessons that the Premier League can learn from the Super Bowl and NFL

    Richard Davies

    In the Press

  • The ongoing fight against fakes

    Charlotte Duly

    Quick Reads

  • Abu Dhabi’s New Arbitral Centre Unveils its Rules

    Dalal Alhouti

    Quick Reads

  • Fortune quotes Richard Davies on sponsorship deals and the strength of brand/supporter loyalty in football

    Richard Davies

    In the Press

  • Legal tips and trends for Creative Design Agencies in 2024

    Rebecca Steer

    Insights

  • Charles Russell Speechlys advises Downing LLP on the successful refinancing of its loan facility with Kao Data

    News

  • New Regulations for the UAE’s Media Sector in 2024

    Mark Hill

    Quick Reads

  • Megan Paul writes for The Grocer on why green energy can be a 'money saver' for retailers rather than a 'money spender'

    Megan Paul

    In the Press

  • Greenwashing: The Story So Far

    Caroline Greenwell

    Insights

  • Under the Influence: Legal Considerations for Social Media Influencer Partnerships in the UAE

    Mark Hill

    Quick Reads

  • Reuters quotes Megan Paul on supply chain considerations coming out of tensions in the Red Sea

    Megan Paul

    In the Press

  • EU AI Act – Will it become a law for all the world?

    Nick White

    Quick Reads

  • Indemnity Costs in Derivative Claims – Briefing Note

    John Sykes

    Insights

  • Trading insolvently or trading out of difficulty? Are we being naughty or did we have the best intentions? Part 3

    Claudine Morgan

    Insights

  • Ctrl + GCC: The Rise of e-Sports in the Gulf

    Mark Hill

    Quick Reads

  • Digital Markets, Competition and Consumers Bill: Will new consumer protection rules restrict access to Gift Aid?

    Verity Heath

    Quick Reads

  • The End of the SAG-AFTRA Strike & What it Means for the Middle East

    Mark Hill

    Quick Reads

  • UAE Strengthens its Position as Leading Destination for A.I.

    Mark Hill

    Quick Reads

  • Dubai Court of Cassation Extends Arbitration Agreement Across Subsequent Contracts

    Peter Smith

    Quick Reads

  • UAE Polishes Federal Arbitration Law

    Peter Smith

    Quick Reads

  • Drone deliveries: Be Prepared

    Emma Humphreys

    Quick Reads

  • Product compliance and Brexit - UK Government concedes to CE markings indefinite recognition

    Jamie Cartwright

    Quick Reads

  • Has the Orpéa plan impaired shareholder's consent? - Le plan de sauvegarde d'Orpéa n'a-t-il pas vicié le consentement des actionnaires historiques ?

    Dimitri-André Sonier

    Quick Reads

  • Will the downturn in the Paris region property market lead property companies to turn to ad hoc proceedings, as they did in the 1990s?

    Dimitri-André Sonier

    Quick Reads

  • Les défaillances en France proches de leur niveau de 2019 - French insolvencies close to 2019 levels

    Dimitri-André Sonier

    Quick Reads

  • Casino Group: An agreement with investors and debt holders is expected at the end of July

    Dimitri-André Sonier

    Quick Reads

  • DIAC Issues First Annual Report

    Georgia Fullarton

    Quick Reads

Back to top