Chinese Internet Watchdog Proposes New Rules on Personal Data Compliance Audits

Chinese Internet Watchdog Proposes New Rules on Personal Data Compliance Audits

BY  
Seneca ESG  
- August 9, 2023

The Cyberspace Administration of China (CAC) has introduced a draft regulation, mandating the implementation of regular compliance audits for all companies involved in handling personal data, as reported by South China Morning Post on August 3. According to these rules, companies offering infrastructure information or services that possess data from more than 1 million users will be required to conduct at least one compliance audit annually. Conversely, companies with less than 1 million users will need to undergo audits every two years. Additionally, for services engaged in the cross-border transfer of their data, the audit will encompass verifying whether personal information is shared with foreign judicial or law enforcement bodies and whether such transfer are endorsed by Chinese authorities.

Over the past few years, China has progressively tightened its control over data and information, particular concerning data that crosses international borders. These newly proposed rules expand upon the existing legal frameworks, including the Personal Information Protection Law and Data Security Law that became effective in November 2021, along with the Measures for Security Assessment of Cross-border Data Transfer that were implemented last September. The CAC clarified that these forthcoming rules aim to “provide guidance and regulate compliance audits” to safeguard personal data. According to Caixin, it is anticipated that there will be hundreds of thousands of companies possessing personal data from over 1 million users, making compliance audits a significant undertaking. Under the new guideline, these companies will have the option to enlist auditing agencies designated by the CAC to perform their audits.

Sources:

https://www.scmp.com/news/china/politics/article/3229902/companies-china-conduct-regular-personal-data-compliance-audits-under-new-rules?module=perpetual_scroll_0&pgtype=article&campaign=3229902

https://www.reuters.com/world/china/china-make-holders-more-than-1-mln-users-data-get-annual-audits-2023-08-03/

http://politics.people.com.cn/n1/2023/0803/c1001-40049918.html

https://asia.nikkei.com/Spotlight/Caixin/China-tightens-controls-on-cross-border-data-transfers

立即開始使用 Seneca ESG 工具包

監控投資組合 ESG 表現,自建 ESG 框架,讓商業決策更精準。

Toolkit

Seneca ESG

有興趣?立即聯絡我們

請填寫右側表單,或直接郵件聯絡我們:

sales@senecaesg.com

新加坡辦公室

7 Straits View, Marina One East Tower, #05-01, Singapore 018936

+(65) 6223 8888

巴塞隆拿辦公室

Carrer de la Tapineria, 10

Ciutat Vella, 08002, Barcelona, Spain

+34 612 22 79 06

台北辦公室

台灣台北市大安區敦化南路二段77號7樓,106414

(+886) 02 2706 2108

利馬辦公室

Av. Santo Toribio 143,

San Isidro, Lima, Peru, 15073

(+51) 951 722 377