Demystifying Data Localization Report
Demystifying Data Localization Report
February 2022
Introduction
With the adoption of the Personal Information what type of data is being processed. With
Protection Law (PIPL) and the Data Security respect to the first pillar, certain special
Law (DSL) in 2021, China has taken important categories of controllers must store their
steps to solidify its regulatory framework for
data in China due to their importance to
cross-border data flows. While this framework
China’s national security and economy, and
is still in flux and incomplete, it contains
may only transfer data with the approval of
notable features that help clarify questions
regulatory authorities. For the second,
around when organizations subject to
controllers must store “important data” in
Chinese data protection laws (“data
controllers”) must store data locally in China China, and receive approval before
and when they can transfer data abroad. transferring such data abroad.
Step 7 - Choose the transfer mechanism All these steps are detailed below and
accompanied by relevant definitions and
explanations. However, it is important to note
Step 8 - Check whether an international
that this Report does not constitute legal
treaty or agreement is applicable
advice. Finally, a flowchart summarizing the
proposed steps is annexed to the Report.
As a preliminary step, data controllers must China may nonetheless be subject to Chinese
determine whether Chinese data protection privacy law. Under the DSL, this
laws apply to them and, if so, whether their extraterritorial effect kicks in if data handling
processing activities constitute a “transfer” activities outside of the territory of the PRC
that would trigger further compliance harm the national security or the public
requirements. interest of China, or the lawful rights and
interests of individuals and organizations in
Both the PIPL and the DSL apply to “data China (Art. 2). By contrast, the PIPL will apply
handling activities'' (数据处理活动) within the to data controllers that process data of
individuals within China to:
territory of the PRC, with the former covering
“personal information handling” defined as • Provide products or services to
“information that identifies or can identify individuals in China
natural persons'' and the latter applying to
• Analyze and assess the conduct of
data handling generally. The definition of
natural persons in China, or
“data handling activities'' is found in many
Chinese legal instruments and mirrors the • In other situations provided by laws or
definition of “processing” under the GDPR. In regulations (Art. 3)
contrast to the GDPR, these laws apply
Under Article 2 of the draft Online Data
regardless of whether a data controller has an
Security Management Regulations, data
establishment in China.
controllers that handle domestic important
Chinese data protection laws also carry an data will also be subject to Chinese data
extraterritorial effect, which in practice means protection laws. As discussed below,
data controllers who do not process data in important data generally refers to data that if
damaged or leaked could harm China’s
3
Future of Privacy Forum
national security, public order, or the rights • When the data is stored in China but
and interests of individuals in China. can be accessed and viewed by
institutions, organizations, and
Once applicability has been determined, the individuals outside of the country.
next question is what constitutes a transfer.
Numerous Chinese data laws and regulations While these guidelines remain in draft form,
refer to “providing information abroad” (向境 Chinese policymakers may formalize a similar
外提供), but none explicitly specify the approach in the future through either a
technical standard or a regulatory measure.
activities that are subject to this provision.
Until this happens, it is currently unclear if
The 2017 Information Security Technology -
data localization in China follows a strict
Guidelines for Data Cross-Border Transfer
paradigm, as the definition of transfer has not
Security Assessment (信息安全技术数据出境 been solidified. Entities that simultaneously
store a copy in China and abroad may be
安全评估指南 (征求意⻅稿)) defines a transfer
considered non-compliant if a data
in three scenarios: localization rule applies. Additionally, this
loose definition carries important implications
• When data generated in China is for data controllers that access data in China
stored outside of China through subsidiaries or other affiliated
• When a copy of the data is provided entities. Notably, when third parties outside of
to individuals or organizations that are China that process data on behalf of data
not under the jurisdiction of or not handlers as “entrusted parties” obtain data
registered in China, or from a data handler, Chinese regulators will
likely deem that a transfer has occurred.
Data controllers that fall under the scope of It is important to note that Chinese law does
the law and transfer data overseas must then not use the term “general” data controller, but
ask whether they are “general” data rather establishes a transfer regime that
controllers or whether they fall within a applies in default settings. This report has
special category of operator, such as, for created the concept of “general” data
example, a “critical information infrastructure controller to refer to the baseline option for
operator” (CIIO), an “automobile data data transfers under the transfer regime. As
processor” under the Several Provisions on discussed below, the architecture of the
the Management of Automobile Data Security Chinese data protection framework builds
Regulationsi (汽⻋数据安全管理若干规定 (试 from this baseline and adds stricter
requirements depending on the type of
行)), or a credit reporting service under the controller and the type and level of sensitivity
Administrative Measures for Credit of the data. For a discussion of entrusted
parties (i.e., “processors” under the GDPR)
Investigation Services (征信业务管理办法).
obligations) see step nine.
4
Future of Privacy Forum
As a default rule, these special data will formulate additional rules in other
controllers usually must localize data in China, industries. In the likely scenario, such
subject to guidance from additional sectoral regulations will be issued first as national
regulations. This report does not cover every standards and then incorporated into
distinct type of controller under Chinese law regulatory measures formulated by key
but rather focuses on one type of important ministries. The test for identifying CIIOs not
controller - CIIOs. While Chinese regulators on the enumerated list has three factors:
will continue to define more narrow
categories of data controllers through • The importance of the business to
subsequent regulations and guidelines, other critical entities, such as the
recent measures have clarified the degree to which the business
compliance path for CIIOs with respect to provides support.
transfers. • The extent of the harm to national
security, the economy and people’s
Definition - Under the Critical Information livelihoods, and the public interest if
Infrastructure Security Protection Regulations the business is damaged.
(关键信息基础设施安全保护条例), CIIOs • The degree to which the business
operate “important” network infrastructure operates in a field that is essential for
and information systems in “important” the functioning of basic economic and
industries and sectors (Art. 2). Two factors governmental services and the impact
must be considered to determine this: of the business on those industries.
Whether the data controller processes Determining the status of a CIIO remains
information in an industry explicitly listed by challenging in China and usually involves
the Regulation. These include receiving clarification from regulators.
telecommunications, information services, Anecdotal evidence suggests that Chinese
energy, transportation, hydraulic engineering authorities have notified individual
and water utilities, finance, public services, e- businesses that they deem them to be CIIOs.
government services, national defense Engaging with the appropriate regulator
science and technology; and through trusted intermediaries or through
social media and other e-government
Whether the data controller, once damaged services may be needed and useful.
or suffers a data leakage, could severely
harm national security, the economy and Transfer Requirements - Under the CSL, CIIOs
people’s livelihood, or the public interest. must store the personal information and other
important data they collect or generate in
Identification - For business models that do China (Art. 36). If transferring data outside the
not clearly fall within an enumerated industry, country is necessary for business purposes,
such as cloud providers, ride-hailing services, CIIOs must undergo a security assessment in
large internet platforms, or businesses that accordance with CAC requirements. Indeed,
provide analytic services to critical this is incorporated under Article 36 of the
businesses, determination of CII remains CSL, Article 40 of the PIPL, and Article 4 of
challenging. Currently, the Ministry of Public the draft Measures for Data Export Security
Security (MPS) oversees the administration of Assessment (Outbound Transfer Guidelines).
CII, but authorities operating in other sectors Note, in theory these provisions only apply to
5
Future of Privacy Forum
the processing of personal data and is so broad that in practice, all of the data a
“important” data, and do not cover other CIIO generates in China could be deemed
generic types of data. However, as discussed “important” simply due to its CIIO status.
below, the current definition of important data
Data controllers that are not CIIOs or do not (ii) cumulatively provide personal information
fall under sectoral regulations that mandate of more than 100,000 people or sensitive
additional compliance obligations (i.e., personal information of more than 10,000
“general” data controllers) must then people abroad, must undergo a security
determine the type of data they are assessment by the CAC before sending data
transferring. As mentioned above, CIIOs must abroad. From these draft Guidelines, it is
always store data in China unless they expected that 1 million is also the threshold
undergo a security assessment with the CAC number under Article 40 of the PIPL.
and receive approval for the transfer.
Similarly, under Article 40 of the PIPL and Important Data (重要数据)
Article 4 of the draft Outbound Transfer
Guidelines, controllers that process personal The identification of important data remains
information above a certain threshold or unclear. However, a national standard already
handle important data must also undergo an exists to provide some clarification. The
assessment. Sector-specific regulations may Appendix of the 2017 draft Data Outbound
also obligate certain industry participants to Transfer Security Assessment Guideline lays
receive certification from the CAC before out 27 categories of important data, largely
engaging in a transfer. structured around specific sectoral and
industrial uses, but has received much
In each of these scenarios, controllers must criticism in China as being unwieldy and
store data locally and seek approval prior to inefficient. In response, Chinese regulators
sharing data overseas. A transfer also likely are currently formulating the Identification
includes accessing data that is stored in
Guide of Important Data (信息安全技术 重要
China from abroad or sharing data with
subsidiaries or affiliated offices that operate 数据识别指南), which will help businesses
outside of China. This means that as a default
rule, if an entity determines they need to better determine the important data they
receive a security assessment, they must process.
strictly store data in China.
Definition - Currently, the most
Personal Information (个人信息) comprehensive definition of important data
comes from the draft Online Data Security
If the data in question is personal information, Management Regulations (网络数据安全管理
the draft Outbound Guidelines provide that
controllers who (i) process personal 条例 (征求意⻅稿)). Under Article 73(3)
information of at least 1 million individuals or
6
Future of Privacy Forum
important data refers to “data that can biology, space, arctic regions, and
endanger national security or the public deep seas.
interest once tampered with, destroyed,
leaked, or illegally obtained or used.” The Identification Process: The definition of
Regulations provide an illustrative list that important data remains broad and
includes: ambiguous, posing challenges for
organizations that must determine and
• Government affairs, work secrets, classify their own processing activities. The
intelligence data and law Identification Guide of Important Data clarifies
enforcement. that personal information is not important
• Export control data and other data data for the purposes of classification, but
involved in export control items such statistical data and derivative data based on
as core technologies, design massive personal information datasets may
schematics, production processes, qualify. The Identification Guide proposes
etc. three steps for identifying important data:
• Data stipulated by laws or regulations Organizations should first determine when it’s
that needs protection such as national necessary to classify important data by
economic operations, important examining existing regulations and
industrial data, and statistical data. management policies of the industry. For
• Data related to the safe production instance, the Automobile Data Security
and operation of “important” Regulations proposes its own definition of
industries including those listed as important data in the context of automobile
being “critical information data.
infrastructure” in addition to customs,
taxation, and key systems The next step is to identify and describe the
components and equipment supply organization’s important data. This involves
chains. inventorying, determining the purpose of the
• Basic national data on population, data and the main security threats they face
health, national resources, and as well as the risks posed by leakage or
environment that is required by harmful use of the data on national security,
national departments to meet scale public order, and/or the rights and interests of
and precision. individuals in China, and reviewing the
• Data relevant to the security of process after cataloging.
construction and operation of national
Finally, organizations must clarify the source
infrastructure including CII, national
and protection measures of the data and any
defense facilities, military
sharing agreements with third-party
administration areas, and national
processors. After completing this process,
defense science and technology
organizations should share their catalogs with
units.
relevant authorities.
• Other data that may affect the security
of national politics, territory, military, Categories of Important Data: The
economy, culture, society, science Identification Guidelines divide important data
and technology, ecology, resources, into eight broad categories. These categories
nuclear facilities, foreign interests, do not classify data but rather help firms and
7
Future of Privacy Forum
Under Chinese law, certain controllers legitimacy, and necessity of the purpose,
processing certain data in China must scope and method of transfer. This means
undergo a security assessment by the CAC that the transfer is not explicitly prohibited by
before transferring data abroad. While laws or regulations and the controller has
provisions in many Chinese data protection received consent from the data subject if
measures seem to require data to be stored transferring personal information.
locally, they usually also contain a mechanism
that allows transfer when there is a business Additionally, the CAC will focus on the
need. security risks involved in the transfer,
including possible cyber incidents, the scope
In these circumstances, approval from the of minimization and de-identification, the
CAC or other relevant authority will authorize sufficiency of the transfer mechanism and
the transfer. For instance, under the People agreement, the data protection measures
Bank of China’s (PBOC) Notice Regarding taken by the recipient, and the legal
Effective Protection of Personal Financial environment of the country where the
Information by Banking Institutions (中国人民 recipient sits. In particular, the CAC will
evaluate whether the conditions of the
银行关于银行业金融机构做好个人金融信息保 transfer meet the level of data protection
standards required in the PRC under Article
护工作的通知 (现行有效)), financial
38 of the PIPL, which involves considering the
information must be processed in China power of law enforcement agencies in the
unless the data controller obtains express recipient country to acquire the data.
consent from the data subject, passes a
security assessment by the PBOC, and Security assessments are valid for two years
ensures that the recipient follows the unless a material change to the (i) purpose,
processing agreement. scope, type or duration of transferred data, (ii)
the data protection standards of either the
The draft Outbound Transfer Guidelines sender or recipient of data, or (iii) the legal
provide that the CAC will assess the legality, environment of the recipient countries occurs.
8
Future of Privacy Forum
Both the PIPL and the DSL propose the • “General” data controllers processing
creation of a “whitelist” for data transfers, that personal information of over 1 million
would operate as a quasi-adequacy individuals or that provide personal
agreement for bilateral transfers in and out of information of 100,000 individuals or
China. The draft Outbound Transfer sensitive personal information of
Guidelines indicate that the CAC security 10,000 individuals → must obtain an
assessment procedure will primarily assessment for their personal
operationalize this process, especially for information.
transactions involving well-known recipients • “General” data controllers processing
or destinations such as Hong Kong. important data → must obtain a
security assessment for their
After determining applicability, the type of
important data.
controller, and the type of data being
processed, it is relatively easy to decide • Entities operating in specific industries
whether a security assessment by the CAC is with sectoral regulations and
required. administrative measures → must check
those regulations for tailored
• CIIOs and other “non-general” data guidance.
controllers → must obtain an
assessment for all their data.
The Cybersecurity Review Measures (CRM) 网 cybersecurity review, the CRM only specifies
that CIIOs and “platform network operators”
络安全审查办法 (修订草案征求意⻅稿)) that process personal information of more
impose an additional review for certain than 1 million users and list on a foreign stock
entities and may prohibit the transfer of data exchange must undergo the review.
abroad. Notably, Chinese regulators used this
review process on Didi Chuxing in July. For a It is unclear how Chinese regulators will use
more detailed overview, see our analysis, this mechanism going forward. Unlike the
“Spotlight on the emerging Chinese Data security assessment, which focuses
Protection framework: Lessons learned from exclusively on the risks of the transfer, the
the unprecedent investigation of Didi CRM is much broader and potentially
Chunxing”.ii encompasses a range of activities. This raises
questions as to how authorities in China
Under this review process, regulatory envision the applicability of the security
authorities will conduct an audit when the assessment. It is unclear whether the security
processing activities of the data handler, assessment will primarily target transfers that
including cross-border transfers, carry affect the rights and interests of individuals in
potential harm to national security. Of the China or whether it will also include a strong
type of activities that will always mandate a national security dimension.
9
Future of Privacy Forum
If the former, the CRM may be used more apply to every data transfer. Regardless, it is
readily, especially in cases that involve state unlikely the CRM will be a major concern for
secrets or sensitive information directly tied foreign data controllers and in most cases a
to national security. If the latter, the CRM may cybersecurity review will likely not be
become an exceptional regulatory tool used required on top of a security assessment.
only in extreme circumstances and will not
At this point, controllers that pass the CIIOs, special controllers, and general
inquiries mentioned above do not have to controllers transferring important data or
store data locally in China. However, certain personal information above the specified 1
transfer restrictions under the PIPL may still million threshold must still undergo a security
apply. For this reason, general controllers assessment by the CAC. In other words, this
should determine whether their processing derogation does not override the draft
activities fall within an exception to these Outbound Transfer Guidelines but rather
restrictions. Article 35 of the draft Online Data modifies the general transfer requirements
Security Management Regulations specifies stipulated under the PIPL.
that data handlers who transfer personal
information abroad as required for concluding Notably, Article 38(4) of the PIPL specifies
or fulfilling a contract where the data subject that other laws or administrative regulations
is a concerned party do not need to comply may add further transfer mechanisms. The
with the transfer requirements of Article 38 of draft Online Data Security Management
the PIPL. Additionally, Article 35 also Regulations represents one such measure.
stipulates a derogation to the transfer However, these regulations are currently in
requirements in situations when providing draft form and the specifics of these
personal information abroad is necessary to provisions remain unclear. Consequently,
protect individuals’ lives or health or the policymakers in China may modify this
security or their property. provision in the near future and will likely
need to add more clarity around how these
Note these derogations only apply to exceptions will be implemented.
“general” controllers in limited circumstances.
Data controllers that do not need to undergo stipulates the following conditions for a
a CAC security assessment or a cybersecurity transfer pursuant to business needs:
review (i.e., “general” controllers) and do not
meet the conditions for a derogation must • Undergoing a security assessment
then choose a relevant transfer mechanism conducted by the CAC. The draft
under Chinese law. Article 38 of the PIPL Outbound Transfer Guidelines provide
the most up to date details on this
10
Future of Privacy Forum
process (Art. 38(1)). Indeed, this is the takes place according to the matters related
same assessment outlined in Step 4. to the original consent.
The primary difference here is that
“general” controllers may opt for this For each transfer of personal information, the
pathway but are not required to data handler must notify the data subject of
choose it. the name and contact method of the foreign
• Obtaining third-party certification recipient, the purpose and method of
through a competent government processing, and methods for the data subject
authority according to guidelines to exercise their personal information rights.
issued by the CAC (Art. 38(2)).
The CAC has yet to formulate SCCs or clarify
• Adopting a standard contractual the certification process, although a
clause (SCC) developed by the CAC standardized security assessment may
(Art. 38(3)). operate as one basis through which the
certification process works. Another
The PIPL imposes two additional obligations
certification option could involve export
regardless of the mechanism chosen.
control licensing administered by relevant
First, data controllers must take measures to Chinese authorities as stipulated by the DSL.
ensure that the overseas recipients of the Both options, however, have yet to be
data transfer meet the protection finalized. This means that as of writing,
requirements under Chinese law (Art. 38). “general” data controllers that do not have to
Note that this provision does not mention the undergo a security assessment by the CAC
legal environment in which the data controller may nonetheless choose to do so depending
sits (although a security assessment by the on the level of risk and the potential cost of
CAC will take this into account). noncompliance.
Second, controllers must obtain separate The draft Online Data Security Management
Regulations stipulate that all data controllers
consent (单独同意) from each of the data providing personal information and important
subjects. Under the draft Online Data Security data abroad shall compile an outbound
Management Regulations, separate consent transfer security report annually, to be
requires the data handler to obtain personal submitted to a district-level CAC before
consent for each item of personal information January 31 of each year. The report must
when carrying out data handling activities and include:
not bundle such consent for multiple items of
personal information and multiple processing • The complete name and contact
activities (Art. 73(8)). method of the data recipient and the
categories and quantities of the
Note that Article 36 of the draft Online Data exported data.
Security Management Regulations specifies • The storage location and retention
that controllers who obtain individual consent period of the transfer.
separately for transfers of PI at the time of PI • Any user complaints involving the
collection do not need to obtain additional transfer and subsequent processing
separate consent as long as the transfer of their data.
11
Future of Privacy Forum
• Data security incidents and their compliance process, such as those indicated
response situation. in a DPIA, a security assessment, and/or
• Onward transfers after the initial processing or transfer contracts with
export of data. recipients. Additionally, data controllers must
also provide a means of handling transfer-
Finally, controllers must also comply with related user complaints, retain daily records
additional transparency requirements when of outbound transfer examinations and
transferring data abroad. Under Article 39 of approval records for three years, and ensure
the draft Online Data Security Management that the details of the transfer, including
Regulations, these requirements involve contemplated onward transfers, are explicitly
ensuring that the transfer falls within the provided for in the processing agreement and
purpose, scope, and method of handling in the notification to the original data subject.
identified in key documents along the
The PIPL provides that “general” controllers Note that under Chinese data protection law,
who do not need to undergo a security the Chinese government may take unilateral
assessment may also rely on an international action to restrict data transfers to certain
treaty or agreement that China has signed as recipients. This occurs in two primary
the basis for the data transfer (Art. 38). These circumstances. First, when a data controller
treaties will likely take the form of infringes upon the data protection rights and
agreements specific to data flows or data interests of individuals in China or threatens
security. Currently, China has yet to enter into China’s national security by processing
such an agreement. Nevertheless, Article 12 certain data, Chinese authorities may prohibit
of the PIPL plus China’s application to join transfers of information to that entity. Second,
notable regional trade agreements like the if a foreign country discriminates or employs
Comprehensive and Progressive Agreement prohibitive measures against China with
of Trans-Pacific Partnership (CPTPP) and the respect to data, China can take equal
Digital Economy Partnership Agreement measures against that country based on
(DEPA), suggest that the Chinese government actual conditions.
is open to exploring this option. Such a treaty
would bypass the foregoing steps.
Article 21 of the PIPL stipulates that data the GDPR). The core document outlining the
handlers can entrust certain processing responsibilities of the data handler and the
activities to trusted third parties (this mirrors entrusted party is the processing agreement,
the controller/processor relationship found in which must specify the purpose and methods
12
Future of Privacy Forum
14
Future of Privacy Forum
Conclusion
While China’s transfer regime involves myriad should identify whether they are a “special
laws and administrative regulations, a general controller”, such as a CIIO, which would
framework for compliance is discernable and automatically trigger a specific compliance
benefits from detailed regulatory intervention, path. The next step is to evaluate the type of
albeit currently incomplete. In particular, the data being transferred to determine whether
Chinese government has yet to clarify two it is important data or a type of data that
specific transfer mechanisms (the certification would trigger a pre-approval process under a
process under PIPL Article 38(2) and the sectoral regulation or a security assessment
SCCs under Article 38(3)) and has currently by the CAC.
not entered into a treaty or international
agreement relevant for data transfers. The After figuring this out, controllers can
CAC is expected to release SCCs in the near determine whether a security assessment by
term, although specific dates remain the CAC is required (step four) by following
unknown. Experience suggests the regulator the threshold questions. Fifth, controllers
may issue something when it finalizes the should also ask whether their processing
draft Outbound Guidelines, the most recent activities are of the type to trigger a
administrative measure dealing with cross- cybersecurity review under the CRM or
border transfers released in late 2021. whether an exception applies. If not, the next
process involves choosing a transfer
This report untangles some of the complexity mechanism specified under the PIPL. Two of
of the new legal framework by proposing and these transfer mechanisms remain unclarified,
explaining concrete steps organizations can but the CAC should issue guidelines on both
take to lawfully transfer data from China or to in the future. Seventh, controllers should also
ascertain whether they are subject to determine whether an applicable treaty or
localization requirements. international agreement exists between
China and their established jurisdiction, as
First, controllers must determine whether they this may provide another mechanism for
fall within the scope of Chinese data transfer in addition to those specified under
protection law and whether a transfer is the PIPL. Eighth, entrusted processors do not
actually happening. Second, data controllers have the obligation to initiate a security
15
Future of Privacy Forum
assessment for their initial or onward receive approval from a competent Chinese
transfers and must primarily follow the terms authority.
specified in the transfer agreement. Lastly,
compelled transfers of data outside of China
by a foreign law enforcement body must
16
Future of Privacy Forum
“General processors” →
• Personal information of more than 1 million individuals or
a cumulative transfer of personal information of 100,000
individuals or sensitive information of 10,000 individuals →
must undergo a security assessment for transfers of
personal information.
• Important data → must undergo security assessment for
transfers of important data.
18
Future of Privacy Forum
PIPL Article 38 -
1. Undergoing a security assessment by the CAC (voluntary)
2. Obtaining certification through a competent government authority
(unclear)
3. Adopting SCCs issued by CAC (forthcoming)
Additional requirements -
1. Ensure data recipient takes measures to ensure same level of
Chinese data protection standards
2. Obtain separate consent for the transfer. This is not necessary if
the controller notifies the data subject of the transfer at the time
of original collection.
General rule:
• Entrusted processors must follow the terms
and conditions of the processing agreement.
• Entrusted processors do not have
responsibility to undergo a security
assessment.
• Data controllers bear the liability for ensuring
compliance for transfers, including onward
transfers.
ENDNOTES
i
[Link]
october-1-2021/ (last accessed February 18, 2022).
ii
[Link]
lessons-learned-from-the-unprecedented-investigation-of-didi-chuxing/ (last accessed
February 18, 2022).
20