China CAC issues the Draft Regulations on Data Breach Reporting
Source: | Author: Asian Compliance Forum | Publish time: 2023-12-08 | 659 Views | 🔊 Click to read aloud ❚❚ | Share:

On Dember 8, 2023, the Chinese Cyberspace Administration of China (CAC) has released a draft of the "Network Security Incident Reporting Management Measures (Consultation Draft)" aimed at standardizing the reporting of network security incidents to reduce losses and harm caused by such incidents. The regulations are open for public feedback until January 7, 2024.

Reporting Obligations: Entities operating networks or providing services via networks within China must report events that endanger network security as per these regulations.

 

Responsibilities and Reporting Channels:

  • The national cyberspace administration coordinates national-level reporting while local administrations oversee their respective regions.

  • Prompt reporting is required based on incident severity. Major incidents demand immediate reporting within one hour.

  • Different levels of incidents require reporting to corresponding authorities within specified timeframes.

 

Content of Reports: Reports should include detailed information about the incident, its impact, measures taken, and further steps for investigation and mitigation. Specific data elements are mandated in the reporting form.

 

Timelines for Reporting: Immediate reporting of basic incident details is required within one hour. Additional details can be provided within 24 hours if a full assessment cannot be made within the initial hour.

 

Post-Incident Reporting and Analysis: A comprehensive analysis and summary of incidents must be submitted within five working days after the incident resolution.

 

Consequences of Non-Compliance:

  • Failure to report or deliberate concealment of incidents could lead to penalties as stipulated by the regulations.

  • Significant penalties are imposed for intentional delay, omission, false reporting, or concealment causing substantial harm.

 

Exemptions and Mitigating Factors: Entities that proactively implement protective measures and report incidents voluntarily may receive leniency in penalties.

 

Review and Feedback: Stakeholders are encouraged to review the draft regulations and provide feedback via specified channels before the deadline of January 7, 2024.

 

Preparation: Entities operating within China's networks or providing services via networks should assess their readiness to comply with these regulations once enacted.

 

Disclaimer: This alert is for informational purposes only and does not constitute legal advice. Entities should consult legal professionals for specific guidance.