On September 28, 2023, the Cyberspace Administration of China (“CAC”) published the draft Provisions on Regulating and Promoting Cross-Border Data Flows (“Draft Provisions”) for public consultation.
The Draft Provisions significantly ease the triggering conditions for security assessments, standard contractual clauses (“SCCs”) and certifications by proposing a series of exemptions for companies which would otherwise be subject to China’s data transfer restrictions.
Cross-Border Data Transfer Mechanisms under China’s Existing Regime
Under existing PRC law, a company is required to implement one of the following three cross-border data transfer mechanisms (“CBDT Mechanisms”) if any personal information or important data are transferred out of China:
(1) Passing a security assessment by the CAC;
(2) Entering into a standard contract with a foreign data recipient in accordance with SCCs published by the CAC; or
(3) Conduct a security certification by a third-party certification institution designated by the CAC.
Generally, a CAC security assessment will be triggered in the following circumstances:
(1) The data exporter is a critical information infrastructure operator (“CIIO”), which is broadly defined as an operator of critical network facilities or information systems in important industries (such as finance, energy, or transportation), where destruction, loss of function, or data leakage may seriously endanger China’s national security, peoples' livelihood, or the public interest;
(2) The data exporter has processed personal information of more than 1 million individuals (“Mass Processor”); OR
(3) Since January 1 of the previous year, the data exporter has made aggregated transfers of personal information of more than 100,000 individuals or sensitive personal information of more than 10,000 individuals.
A company may choose to use SCCs or certification to qualify its data transfer if the CAC security assessment is not triggered.
Exemptions from Implementing a CBDT Mechanisms
Under the Draft Provisions, a company is exempted from adopting ANY of the CBDT Mechanisms in the following circumstances:
(1) No transfer of personal information or important data: If no personal information or important data will be transferred during the course of international trade, academic cooperation, cross-border manufacturing and production or marketing activities, none of the CBDT Mechanisms would be triggered. Notably, the Draft Regulations further clarify that if a company has not been informed by any sectoral or local regulators that their data to be transferred out of China are important data or their data fall within any of the important data lists published by the Chinese regulators, then the company is not subject to the CAC security assessment for transfer of important data. This addresses a key concern for multinational companies due to the lack of clarity on the scope of important data.
(2) Transfer of personal information collected or generated out of China: If the data transferred out of China are not collected or generated in China, their transfer will not be subject to any of the CBDT Mechanisms.
(3) Necessary for entering into or performing a contract: Companies are exempted from the CBDT Mechanisms if the proposed transfer of personal inforamtion is necessary for entering into and performing a contract to which they are a party, such as cross-border e-commerce, cross-border payments, flight and hotel bookings or visa applications. This carve-out will be welcomed by companies such as e-commence retailers, online travel agencies or booking service providers and financial institutions.
(4) Necessary for human resource management: Transfer of employee personal inforamtion necessary for the implementation of HR management in accordance with the employment policies of the companies or collective employment contract with their employees are exempted from the CBDT Mechanisms. However, the scope of this exemption still depend on how broadly the CAC would interpret “necessary.” It appears that transfer of senstive personal information of employees may not be qualified for this exemption according to Article 8 of the Draft Provisions.
(5) Necessary for protecting vital interests: Transfer of personal information necessary for protecting the health and property safety of a natural person in an emergency is exempted from any of the CBDT Mechanisms.
New CAC Security Assessment Threshold
According to the Draft Provisions, if a company transfers personal inforamtion of more than 1 million individuals, a CAC security assessment will be triggered. The company is not required to complete any of the CBDT mechanisms if it expects to transfer personal inforamtion of less than 10,000 individuals within a year. However, the company needs to enter into SCCs or conduct a certification if the volume of data it expects to transfer out of China within a year is between 10,000 and one million individuals within a year.
The Draft Provisions significantly increased the threshold for the CAC security assessment from 100,000 to 1 million individuals. In the meantime, the Draft Provisions also changed the previous approach of focusing on “cumulative” volume of personal information that have been transferred out of China since January 1 of the previous year to “expected” volume of personal information that will be transferred out of China within a year. However, the Draft Provisions remain silent on what will happen if a company exceeds the expected amount in a given year.
“Negative List” for Companies in Free Trade Zones
The Draft Provisions authorize free trade zones (“FTZs”) to develop a “negative list.” A CBDT Mechanism must be adopted if any data on the “negative list” are transferred out of China from relevant FTZs. Transfer of data not on the “negative list” are generally not subject to any of the CBDT Mechanisms. This echoes the recent Opinions of the State Council on Further Optimizing Foreign Investment Environment and Further Optimizing the Foreign Investment Environment and Increasing the Efforts to Attract Foreign Investment which call for issuance of a “list of general data” that could be freely transferred out of China without adopting any of the CBDT Mechanisms.
Observations
The Draft Provisions demonstrate that China is trying to strike a balance between enhancing data security and promoting data-driven economic growth by eliminating restrictions on cross-border data transfers. If adopted in the current form, the Draft Provisions would significantly reduce the burden for companies that would otherwise be subject to a CBDT Mechanism.
However, the Draft Provisions do not exempt companies from other obligations under existing PRC data protection law, such as obtaining separate consent from relevant data subjects if the legal ground of the processing is consent.
The timing for the CAC to finalize the Draft Provisions is not clear. We anticipate that the Draft Provisions would be finalized quickly, given that the CAC only provides a 15-day comment period for the public which usually would be 1 month. We would recommend companies considering taking the security assessment, SCCs or certification revisit their previous analysis based on the changes introduced in the Draft Provisions.
Author: Zhiwei Chen , Crowell Moring LLP
Email: zchen@crowellmoring.asia
COPYRITH BELONGS TO THE AUTHORS.