On October 29, 2021, the Cyberspace Administration of China (“CAC”) issued the Draft Measures on Security Assessment of Cross-Border Data Transfers (“Measures”) for public comments. The draft Measures is a key implementing rule of China’s Cybersecurity Law (“CSL”), Data Security Law (“DSL”) and Personal Information Protection Law (“PIPL”). The draft Measures provide clarifications on a variety of significant issues related to transfers of important data and personal information outside of China. The public comment period will expire on November 28, 2021.
Data Transfer Restrictions under Existing PRC Laws
The CSL, which was passed five years ago, for the first time introduced China’s data localization and security assessment requirement. The requirement is not a complete ban. CIIOs could still transfer important data or personal information outside of China there is a “genuine business need” and pass the security assessment by the CAC. The data localization and security assessment requirement under the CSL applies only to critical information infrastructure operators (“CIIOs”).
The DSL does not explicitly impose any additional restrictions on cross-border data transfers, but instead provides that the transfers of important data by CIIOs shall be subject to the CSL while the transfers of important data by non-CIIOs shall be subject to the regulations to be issued by the CAC and other relevant responsible authorities.
Under the PIPL, which will come into effect on November 1, 2021, CIIOs and personal information processors (“PIP”) (similar to the comcept of "data controller" under the GDPR) who process personal information in volumes reaching the threshold to be specified by the CAC are required to store the personal information collected or generated in China within China and any transfers of such personal information outside of China would be subject to the security assessment by the CAC. PIPs who process personal information in volumes below the threshold would be subject to more flexible data transfer mechanisms, including (1) security assessment by the CAC; (2) certification by an institution designated by the CAC; or (3) standard contract with the overseas data recipient. However, no further guidance is provided under the PIPL about the above threshold.
Clarification on the “Threshold” Affecting the Applicable Data Transfer Mechanism under the PIPL
After the issuance of the PIPL, most multinational companies are waiting for further clarification on the “threshold” to implement corresponding data transfer mechanisms within their organizations. According to the draft Measures, PIPs processing personal information of 1,000,000 individuals or more would be subject to the security assessment by the CAC.
In addition, the following cross-border transfers would also be subject to the security assessment by the CAC:
(1) cross-border transfers of important data and personal information collected or generated by CIIOs;
(2) cross-border transfers of important data;
(3) cross-border transfers of personal information of more than 100,000 individuals accumulatively or cross-border transfers of sensitive personal information of more than 10,000 individuals accumulatively; or
(4) other circumstances to be determined by the CAC.
Process of the Security Assessment
Factors Considered by the CAC
The CAC would consider the following factors in its determination of whether or not to approve a proposed data transfer:
(1) The legality, reasonableness and necessity of the purpose, scope and means of the proposed data transfer;
(2) The impact of the regulatory and security environment of the country or region where the data recipient is located on the security of the data to be transferred, and whether the data protection level of the data recipient meets the requirements under applicable PRC laws, administrative regulations and mandatory national standards;
(3) The quantity, scope, type, and sensitivity of the data to be transferred, and the risks of leakage, modification, loss, destruction, transfer or illegal acquisition or use during and after the proposed transfer;
(4) Whether the security of the data and the privacy rights of the data subjects could be fully and effectively protected;
(5) Whether the data transfer agreement between the PIP and data recipient specifies the responsibilities and obligations of the parties with respect to the data security protection;
(6) Compliance with applicable PRC laws, regulations and rules; and
(7) Other factors deemed necessary by the CAC.
Document Required for the Security Assessment
The data exporter needs to submit the following document for the security assessment by the CAC:
(1) Security assessment application;
(2) Self-assessment report;
(3) Data transfer contract; and
(4) Other documents required by the CAC.