Chinese Internet Watchdog Proposes New Rules on Personal Data Compliance Audits

Chinese Internet Watchdog Proposes New Rules on Personal Data Compliance Audits

by  
Seneca ESG  
- August 9, 2023

The Cyberspace Administration of China (CAC) has introduced a draft regulation, mandating the implementation of regular compliance audits for all companies involved in handling personal data, as reported by South China Morning Post on August 3. According to these rules, companies offering infrastructure information or services that possess data from more than 1 million users will be required to conduct at least one compliance audit annually. Conversely, companies with less than 1 million users will need to undergo audits every two years. Additionally, for services engaged in the cross-border transfer of their data, the audit will encompass verifying whether personal information is shared with foreign judicial or law enforcement bodies and whether such transfer are endorsed by Chinese authorities.

Over the past few years, China has progressively tightened its control over data and information, particular concerning data that crosses international borders. These newly proposed rules expand upon the existing legal frameworks, including the Personal Information Protection Law and Data Security Law that became effective in November 2021, along with the Measures for Security Assessment of Cross-border Data Transfer that were implemented last September. The CAC clarified that these forthcoming rules aim to “provide guidance and regulate compliance audits” to safeguard personal data. According to Caixin, it is anticipated that there will be hundreds of thousands of companies possessing personal data from over 1 million users, making compliance audits a significant undertaking. Under the new guideline, these companies will have the option to enlist auditing agencies designated by the CAC to perform their audits.

Sources:

https://www.scmp.com/news/china/politics/article/3229902/companies-china-conduct-regular-personal-data-compliance-audits-under-new-rules?module=perpetual_scroll_0&pgtype=article&campaign=3229902

https://www.reuters.com/world/china/china-make-holders-more-than-1-mln-users-data-get-annual-audits-2023-08-03/

http://politics.people.com.cn/n1/2023/0803/c1001-40049918.html

https://asia.nikkei.com/Spotlight/Caixin/China-tightens-controls-on-cross-border-data-transfers

Start Using The Seneca ESG Toolkit Today

Monitor ESG performance in portfolios, create your own ESG frameworks, and make better informed business decisions.

Toolkit

Seneca ESG

Interested? Contact us now

In order to contact us please fill the form on the right or directly email us at the address below

sales@senecaesg.com

Singapore Office

7 Straits View, Marina One East Tower, #05-01, Singapore 018936

+65 6223 8888

Amsterdam Office

Gustav Mahlerplein 2 Amsterdam, Netherlands 1082 MA

(+31) 6 4817 3634

Taipei Office

77 Dunhua South Road, 7F Section 2, Da'an District Taipei City, Taiwan 106414

(+886) 02 2706 2108

Hanoi Office

Viet Tower 1, Thai Ha, Dong Da Hanoi, Vietnam 100000

(+84) 936 075 490

Lima Office

Av. Santo Toribio 143,

San Isidro, Lima, Peru, 15073

(+51) 951 722 377

Tokyo Office

1-4-20 Nishikicho, Tachikawa City, Tokyo 190-0022