0% found this document useful (0 votes)
5 views20 pages

Demystifying Data Localization Report

The document provides a practical guide on data localization and cross-border data transfers in China, particularly in light of the Personal Information Protection Law (PIPL) and the Data Security Law (DSL). It outlines the circumstances under which data controllers must store data locally and the steps they can take to comply with Chinese regulations, including determining the type of data and whether a security assessment is required. The report also emphasizes the importance of understanding the definitions of 'important data' and the implications for data handling activities in relation to national security and public interest.

Uploaded by

musunga02
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views20 pages

Demystifying Data Localization Report

The document provides a practical guide on data localization and cross-border data transfers in China, particularly in light of the Personal Information Protection Law (PIPL) and the Data Security Law (DSL). It outlines the circumstances under which data controllers must store data locally and the steps they can take to comply with Chinese regulations, including determining the type of data and whether a security assessment is required. The report also emphasizes the importance of understanding the definitions of 'important data' and the implications for data handling activities in relation to national security and public interest.

Uploaded by

musunga02
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

DEMYSTIFYING DATA LOCALIZATION

IN CHINA: A PRACTICAL GUIDE

Author: Hunter Dorwart


Policy Counsel, Future of Privacy Forum

February 2022
Introduction
With the adoption of the Personal Information what type of data is being processed. With
Protection Law (PIPL) and the Data Security respect to the first pillar, certain special
Law (DSL) in 2021, China has taken important categories of controllers must store their
steps to solidify its regulatory framework for
data in China due to their importance to
cross-border data flows. While this framework
China’s national security and economy, and
is still in flux and incomplete, it contains
may only transfer data with the approval of
notable features that help clarify questions
regulatory authorities. For the second,
around when organizations subject to
controllers must store “important data” in
Chinese data protection laws (“data
controllers”) must store data locally in China China, and receive approval before
and when they can transfer data abroad. transferring such data abroad.

This report provides an overview of data In other circumstances, controllers do not


localization and cross-border transfers under need to store data locally in China but must
the current Chinese data protection regime. It comply with other transfer requirements.
attempts to give data controllers a better Article 38 of the PIPL sets forth these
understanding of how the transfers conditions for lawfully transferring data. Once
framework operates, the expectations of a controller chooses a transfer mechanism, it
Chinese regulatory authorities with respect to must comply with additional transparency
such transfers, and the specific steps obligations. However, it is important to take
controllers can take for better compliance both the PIPL and DSL requirements into
mapping. It examines provisions of laws account when deciding whether to localize
formally adopted by the National People’s data or to transfer it.
Congress (NPC) and regulatory measures
In order to untangle this complex legal
promulgated by ministerial departments.
landscape, this Report proposes 10 steps that
As this report will show, while the new data data controllers can take before deciding to
protection and data security legal framework localize or transfer data, with practical advice
solidified and added to pre-existing data on how to carry them out:
localization requirements, it also clarified that
Step 1 - Determine scope and when data is
data can be transferred or made accessible
outside of China if specific conditions are “transferred” overseas
met. Although these localization obligations in
China are cumbersome and constitute a Step 2 - Evaluate the type of data controller
barrier to the free flow of data across borders, and whether it is a critical information
several pathways remain open for transfers infrastructure operator (CIIO) or a special
that once understood become easier to controller
implement.
Step 3 - Determine the type of data to be
Under Chinese law, data localization is only transferred including whether it is important
required in certain circumstances framed data
around two distinct conceptual pillars: (1)
which entity is processing the data; and 2)
Future of Privacy Forum

Step 4 - Evaluate whether a security Step 9 - Obligations for Entrusted Processors


assessment by the CAC is required (委托处理)

Step 5 - Determine whether a cybersecurity


review is mandatory Step 10 (bonus) - Determine whether the
transfer is compelled by a foreign judicial or
Step 6 - Determine if an exception applies law enforcement body

Step 7 - Choose the transfer mechanism All these steps are detailed below and
accompanied by relevant definitions and
explanations. However, it is important to note
Step 8 - Check whether an international
that this Report does not constitute legal
treaty or agreement is applicable
advice. Finally, a flowchart summarizing the
proposed steps is annexed to the Report.

Step 1 - Determine scope and whether data is “transferred”


overseas

As a preliminary step, data controllers must China may nonetheless be subject to Chinese
determine whether Chinese data protection privacy law. Under the DSL, this
laws apply to them and, if so, whether their extraterritorial effect kicks in if data handling
processing activities constitute a “transfer” activities outside of the territory of the PRC
that would trigger further compliance harm the national security or the public
requirements. interest of China, or the lawful rights and
interests of individuals and organizations in
Both the PIPL and the DSL apply to “data China (Art. 2). By contrast, the PIPL will apply
handling activities'' (数据处理活动) within the to data controllers that process data of
individuals within China to:
territory of the PRC, with the former covering
“personal information handling” defined as • Provide products or services to
“information that identifies or can identify individuals in China
natural persons'' and the latter applying to
• Analyze and assess the conduct of
data handling generally. The definition of
natural persons in China, or
“data handling activities'' is found in many
Chinese legal instruments and mirrors the • In other situations provided by laws or
definition of “processing” under the GDPR. In regulations (Art. 3)
contrast to the GDPR, these laws apply
Under Article 2 of the draft Online Data
regardless of whether a data controller has an
Security Management Regulations, data
establishment in China.
controllers that handle domestic important
Chinese data protection laws also carry an data will also be subject to Chinese data
extraterritorial effect, which in practice means protection laws. As discussed below,
data controllers who do not process data in important data generally refers to data that if
damaged or leaked could harm China’s
3
Future of Privacy Forum

national security, public order, or the rights • When the data is stored in China but
and interests of individuals in China. can be accessed and viewed by
institutions, organizations, and
Once applicability has been determined, the individuals outside of the country.
next question is what constitutes a transfer.
Numerous Chinese data laws and regulations While these guidelines remain in draft form,
refer to “providing information abroad” (向境 Chinese policymakers may formalize a similar
外提供), but none explicitly specify the approach in the future through either a
technical standard or a regulatory measure.
activities that are subject to this provision.
Until this happens, it is currently unclear if
The 2017 Information Security Technology -
data localization in China follows a strict
Guidelines for Data Cross-Border Transfer
paradigm, as the definition of transfer has not
Security Assessment (信息安全技术数据出境 been solidified. Entities that simultaneously
store a copy in China and abroad may be
安全评估指南 (征求意⻅稿)) defines a transfer
considered non-compliant if a data
in three scenarios: localization rule applies. Additionally, this
loose definition carries important implications
• When data generated in China is for data controllers that access data in China
stored outside of China through subsidiaries or other affiliated
• When a copy of the data is provided entities. Notably, when third parties outside of
to individuals or organizations that are China that process data on behalf of data
not under the jurisdiction of or not handlers as “entrusted parties” obtain data
registered in China, or from a data handler, Chinese regulators will
likely deem that a transfer has occurred.

Step 2 - Determine the type of data controller and whether it


is a critical information infrastructure operator (CIIO)

Data controllers that fall under the scope of It is important to note that Chinese law does
the law and transfer data overseas must then not use the term “general” data controller, but
ask whether they are “general” data rather establishes a transfer regime that
controllers or whether they fall within a applies in default settings. This report has
special category of operator, such as, for created the concept of “general” data
example, a “critical information infrastructure controller to refer to the baseline option for
operator” (CIIO), an “automobile data data transfers under the transfer regime. As
processor” under the Several Provisions on discussed below, the architecture of the
the Management of Automobile Data Security Chinese data protection framework builds
Regulationsi (汽⻋数据安全管理若干规定 (试 from this baseline and adds stricter
requirements depending on the type of
行)), or a credit reporting service under the controller and the type and level of sensitivity
Administrative Measures for Credit of the data. For a discussion of entrusted
parties (i.e., “processors” under the GDPR)
Investigation Services (征信业务管理办法).
obligations) see step nine.

4
Future of Privacy Forum

As a default rule, these special data will formulate additional rules in other
controllers usually must localize data in China, industries. In the likely scenario, such
subject to guidance from additional sectoral regulations will be issued first as national
regulations. This report does not cover every standards and then incorporated into
distinct type of controller under Chinese law regulatory measures formulated by key
but rather focuses on one type of important ministries. The test for identifying CIIOs not
controller - CIIOs. While Chinese regulators on the enumerated list has three factors:
will continue to define more narrow
categories of data controllers through • The importance of the business to
subsequent regulations and guidelines, other critical entities, such as the
recent measures have clarified the degree to which the business
compliance path for CIIOs with respect to provides support.
transfers. • The extent of the harm to national
security, the economy and people’s
Definition - Under the Critical Information livelihoods, and the public interest if
Infrastructure Security Protection Regulations the business is damaged.
(关键信息基础设施安全保护条例), CIIOs • The degree to which the business
operate “important” network infrastructure operates in a field that is essential for
and information systems in “important” the functioning of basic economic and
industries and sectors (Art. 2). Two factors governmental services and the impact
must be considered to determine this: of the business on those industries.

Whether the data controller processes Determining the status of a CIIO remains
information in an industry explicitly listed by challenging in China and usually involves
the Regulation. These include receiving clarification from regulators.
telecommunications, information services, Anecdotal evidence suggests that Chinese
energy, transportation, hydraulic engineering authorities have notified individual
and water utilities, finance, public services, e- businesses that they deem them to be CIIOs.
government services, national defense Engaging with the appropriate regulator
science and technology; and through trusted intermediaries or through
social media and other e-government
Whether the data controller, once damaged services may be needed and useful.
or suffers a data leakage, could severely
harm national security, the economy and Transfer Requirements - Under the CSL, CIIOs
people’s livelihood, or the public interest. must store the personal information and other
important data they collect or generate in
Identification - For business models that do China (Art. 36). If transferring data outside the
not clearly fall within an enumerated industry, country is necessary for business purposes,
such as cloud providers, ride-hailing services, CIIOs must undergo a security assessment in
large internet platforms, or businesses that accordance with CAC requirements. Indeed,
provide analytic services to critical this is incorporated under Article 36 of the
businesses, determination of CII remains CSL, Article 40 of the PIPL, and Article 4 of
challenging. Currently, the Ministry of Public the draft Measures for Data Export Security
Security (MPS) oversees the administration of Assessment (Outbound Transfer Guidelines).
CII, but authorities operating in other sectors Note, in theory these provisions only apply to
5
Future of Privacy Forum

the processing of personal data and is so broad that in practice, all of the data a
“important” data, and do not cover other CIIO generates in China could be deemed
generic types of data. However, as discussed “important” simply due to its CIIO status.
below, the current definition of important data

Step 3 - Determine the type of data to be transferred


including whether it is important data

Data controllers that are not CIIOs or do not (ii) cumulatively provide personal information
fall under sectoral regulations that mandate of more than 100,000 people or sensitive
additional compliance obligations (i.e., personal information of more than 10,000
“general” data controllers) must then people abroad, must undergo a security
determine the type of data they are assessment by the CAC before sending data
transferring. As mentioned above, CIIOs must abroad. From these draft Guidelines, it is
always store data in China unless they expected that 1 million is also the threshold
undergo a security assessment with the CAC number under Article 40 of the PIPL.
and receive approval for the transfer.
Similarly, under Article 40 of the PIPL and Important Data (重要数据)
Article 4 of the draft Outbound Transfer
Guidelines, controllers that process personal The identification of important data remains
information above a certain threshold or unclear. However, a national standard already
handle important data must also undergo an exists to provide some clarification. The
assessment. Sector-specific regulations may Appendix of the 2017 draft Data Outbound
also obligate certain industry participants to Transfer Security Assessment Guideline lays
receive certification from the CAC before out 27 categories of important data, largely
engaging in a transfer. structured around specific sectoral and
industrial uses, but has received much
In each of these scenarios, controllers must criticism in China as being unwieldy and
store data locally and seek approval prior to inefficient. In response, Chinese regulators
sharing data overseas. A transfer also likely are currently formulating the Identification
includes accessing data that is stored in
Guide of Important Data (信息安全技术 重要
China from abroad or sharing data with
subsidiaries or affiliated offices that operate 数据识别指南), which will help businesses
outside of China. This means that as a default
rule, if an entity determines they need to better determine the important data they
receive a security assessment, they must process.
strictly store data in China.
Definition - Currently, the most
Personal Information (个人信息) comprehensive definition of important data
comes from the draft Online Data Security
If the data in question is personal information, Management Regulations (网络数据安全管理
the draft Outbound Guidelines provide that
controllers who (i) process personal 条例 (征求意⻅稿)). Under Article 73(3)
information of at least 1 million individuals or
6
Future of Privacy Forum

important data refers to “data that can biology, space, arctic regions, and
endanger national security or the public deep seas.
interest once tampered with, destroyed,
leaked, or illegally obtained or used.” The Identification Process: The definition of
Regulations provide an illustrative list that important data remains broad and
includes: ambiguous, posing challenges for
organizations that must determine and
• Government affairs, work secrets, classify their own processing activities. The
intelligence data and law Identification Guide of Important Data clarifies
enforcement. that personal information is not important
• Export control data and other data data for the purposes of classification, but
involved in export control items such statistical data and derivative data based on
as core technologies, design massive personal information datasets may
schematics, production processes, qualify. The Identification Guide proposes
etc. three steps for identifying important data:
• Data stipulated by laws or regulations Organizations should first determine when it’s
that needs protection such as national necessary to classify important data by
economic operations, important examining existing regulations and
industrial data, and statistical data. management policies of the industry. For
• Data related to the safe production instance, the Automobile Data Security
and operation of “important” Regulations proposes its own definition of
industries including those listed as important data in the context of automobile
being “critical information data.
infrastructure” in addition to customs,
taxation, and key systems The next step is to identify and describe the
components and equipment supply organization’s important data. This involves
chains. inventorying, determining the purpose of the
• Basic national data on population, data and the main security threats they face
health, national resources, and as well as the risks posed by leakage or
environment that is required by harmful use of the data on national security,
national departments to meet scale public order, and/or the rights and interests of
and precision. individuals in China, and reviewing the
• Data relevant to the security of process after cataloging.
construction and operation of national
Finally, organizations must clarify the source
infrastructure including CII, national
and protection measures of the data and any
defense facilities, military
sharing agreements with third-party
administration areas, and national
processors. After completing this process,
defense science and technology
organizations should share their catalogs with
units.
relevant authorities.
• Other data that may affect the security
of national politics, territory, military, Categories of Important Data: The
economy, culture, society, science Identification Guidelines divide important data
and technology, ecology, resources, into eight broad categories. These categories
nuclear facilities, foreign interests, do not classify data but rather help firms and
7
Future of Privacy Forum

regulators describe the characteristics of • Natural resources and environment (


important data. Organizations should keep
自然资源及环境)
these categories in mind when they identify
their important data. These categories • Science and technology (科学技术)
include:·
• Security protection (安全保护)
• Economic operation (经济运行)
• Application services (应用服务)
• Population and health (人口和健康)
• Government affairs (政务活动)

Step 4 - Evaluate whether a security assessment by the CAC


is required

Under Chinese law, certain controllers legitimacy, and necessity of the purpose,
processing certain data in China must scope and method of transfer. This means
undergo a security assessment by the CAC that the transfer is not explicitly prohibited by
before transferring data abroad. While laws or regulations and the controller has
provisions in many Chinese data protection received consent from the data subject if
measures seem to require data to be stored transferring personal information.
locally, they usually also contain a mechanism
that allows transfer when there is a business Additionally, the CAC will focus on the
need. security risks involved in the transfer,
including possible cyber incidents, the scope
In these circumstances, approval from the of minimization and de-identification, the
CAC or other relevant authority will authorize sufficiency of the transfer mechanism and
the transfer. For instance, under the People agreement, the data protection measures
Bank of China’s (PBOC) Notice Regarding taken by the recipient, and the legal
Effective Protection of Personal Financial environment of the country where the
Information by Banking Institutions (中国人民 recipient sits. In particular, the CAC will
evaluate whether the conditions of the
银行关于银行业金融机构做好个人金融信息保 transfer meet the level of data protection
standards required in the PRC under Article
护工作的通知 (现行有效)), financial
38 of the PIPL, which involves considering the
information must be processed in China power of law enforcement agencies in the
unless the data controller obtains express recipient country to acquire the data.
consent from the data subject, passes a
security assessment by the PBOC, and Security assessments are valid for two years
ensures that the recipient follows the unless a material change to the (i) purpose,
processing agreement. scope, type or duration of transferred data, (ii)
the data protection standards of either the
The draft Outbound Transfer Guidelines sender or recipient of data, or (iii) the legal
provide that the CAC will assess the legality, environment of the recipient countries occurs.

8
Future of Privacy Forum

Both the PIPL and the DSL propose the • “General” data controllers processing
creation of a “whitelist” for data transfers, that personal information of over 1 million
would operate as a quasi-adequacy individuals or that provide personal
agreement for bilateral transfers in and out of information of 100,000 individuals or
China. The draft Outbound Transfer sensitive personal information of
Guidelines indicate that the CAC security 10,000 individuals → must obtain an
assessment procedure will primarily assessment for their personal
operationalize this process, especially for information.
transactions involving well-known recipients • “General” data controllers processing
or destinations such as Hong Kong. important data → must obtain a
security assessment for their
After determining applicability, the type of
important data.
controller, and the type of data being
processed, it is relatively easy to decide • Entities operating in specific industries
whether a security assessment by the CAC is with sectoral regulations and
required. administrative measures → must check
those regulations for tailored
• CIIOs and other “non-general” data guidance.
controllers → must obtain an
assessment for all their data.

Step 5 - Determine whether a cybersecurity review is


mandatory

The Cybersecurity Review Measures (CRM) 网 cybersecurity review, the CRM only specifies
that CIIOs and “platform network operators”
络安全审查办法 (修订草案征求意⻅稿)) that process personal information of more
impose an additional review for certain than 1 million users and list on a foreign stock
entities and may prohibit the transfer of data exchange must undergo the review.
abroad. Notably, Chinese regulators used this
review process on Didi Chuxing in July. For a It is unclear how Chinese regulators will use
more detailed overview, see our analysis, this mechanism going forward. Unlike the
“Spotlight on the emerging Chinese Data security assessment, which focuses
Protection framework: Lessons learned from exclusively on the risks of the transfer, the
the unprecedent investigation of Didi CRM is much broader and potentially
Chunxing”.ii encompasses a range of activities. This raises
questions as to how authorities in China
Under this review process, regulatory envision the applicability of the security
authorities will conduct an audit when the assessment. It is unclear whether the security
processing activities of the data handler, assessment will primarily target transfers that
including cross-border transfers, carry affect the rights and interests of individuals in
potential harm to national security. Of the China or whether it will also include a strong
type of activities that will always mandate a national security dimension.

9
Future of Privacy Forum

If the former, the CRM may be used more apply to every data transfer. Regardless, it is
readily, especially in cases that involve state unlikely the CRM will be a major concern for
secrets or sensitive information directly tied foreign data controllers and in most cases a
to national security. If the latter, the CRM may cybersecurity review will likely not be
become an exceptional regulatory tool used required on top of a security assessment.
only in extreme circumstances and will not

Step 6 - Determine if an exception applies

At this point, controllers that pass the CIIOs, special controllers, and general
inquiries mentioned above do not have to controllers transferring important data or
store data locally in China. However, certain personal information above the specified 1
transfer restrictions under the PIPL may still million threshold must still undergo a security
apply. For this reason, general controllers assessment by the CAC. In other words, this
should determine whether their processing derogation does not override the draft
activities fall within an exception to these Outbound Transfer Guidelines but rather
restrictions. Article 35 of the draft Online Data modifies the general transfer requirements
Security Management Regulations specifies stipulated under the PIPL.
that data handlers who transfer personal
information abroad as required for concluding Notably, Article 38(4) of the PIPL specifies
or fulfilling a contract where the data subject that other laws or administrative regulations
is a concerned party do not need to comply may add further transfer mechanisms. The
with the transfer requirements of Article 38 of draft Online Data Security Management
the PIPL. Additionally, Article 35 also Regulations represents one such measure.
stipulates a derogation to the transfer However, these regulations are currently in
requirements in situations when providing draft form and the specifics of these
personal information abroad is necessary to provisions remain unclear. Consequently,
protect individuals’ lives or health or the policymakers in China may modify this
security or their property. provision in the near future and will likely
need to add more clarity around how these
Note these derogations only apply to exceptions will be implemented.
“general” controllers in limited circumstances.

Step 7 - Choose the transfer mechanism

Data controllers that do not need to undergo stipulates the following conditions for a
a CAC security assessment or a cybersecurity transfer pursuant to business needs:
review (i.e., “general” controllers) and do not
meet the conditions for a derogation must • Undergoing a security assessment
then choose a relevant transfer mechanism conducted by the CAC. The draft
under Chinese law. Article 38 of the PIPL Outbound Transfer Guidelines provide
the most up to date details on this
10
Future of Privacy Forum

process (Art. 38(1)). Indeed, this is the takes place according to the matters related
same assessment outlined in Step 4. to the original consent.
The primary difference here is that
“general” controllers may opt for this For each transfer of personal information, the
pathway but are not required to data handler must notify the data subject of
choose it. the name and contact method of the foreign
• Obtaining third-party certification recipient, the purpose and method of
through a competent government processing, and methods for the data subject
authority according to guidelines to exercise their personal information rights.
issued by the CAC (Art. 38(2)).
The CAC has yet to formulate SCCs or clarify
• Adopting a standard contractual the certification process, although a
clause (SCC) developed by the CAC standardized security assessment may
(Art. 38(3)). operate as one basis through which the
certification process works. Another
The PIPL imposes two additional obligations
certification option could involve export
regardless of the mechanism chosen.
control licensing administered by relevant
First, data controllers must take measures to Chinese authorities as stipulated by the DSL.
ensure that the overseas recipients of the Both options, however, have yet to be
data transfer meet the protection finalized. This means that as of writing,
requirements under Chinese law (Art. 38). “general” data controllers that do not have to
Note that this provision does not mention the undergo a security assessment by the CAC
legal environment in which the data controller may nonetheless choose to do so depending
sits (although a security assessment by the on the level of risk and the potential cost of
CAC will take this into account). noncompliance.

Second, controllers must obtain separate The draft Online Data Security Management
Regulations stipulate that all data controllers
consent (单独同意) from each of the data providing personal information and important
subjects. Under the draft Online Data Security data abroad shall compile an outbound
Management Regulations, separate consent transfer security report annually, to be
requires the data handler to obtain personal submitted to a district-level CAC before
consent for each item of personal information January 31 of each year. The report must
when carrying out data handling activities and include:
not bundle such consent for multiple items of
personal information and multiple processing • The complete name and contact
activities (Art. 73(8)). method of the data recipient and the
categories and quantities of the
Note that Article 36 of the draft Online Data exported data.
Security Management Regulations specifies • The storage location and retention
that controllers who obtain individual consent period of the transfer.
separately for transfers of PI at the time of PI • Any user complaints involving the
collection do not need to obtain additional transfer and subsequent processing
separate consent as long as the transfer of their data.

11
Future of Privacy Forum

• Data security incidents and their compliance process, such as those indicated
response situation. in a DPIA, a security assessment, and/or
• Onward transfers after the initial processing or transfer contracts with
export of data. recipients. Additionally, data controllers must
also provide a means of handling transfer-
Finally, controllers must also comply with related user complaints, retain daily records
additional transparency requirements when of outbound transfer examinations and
transferring data abroad. Under Article 39 of approval records for three years, and ensure
the draft Online Data Security Management that the details of the transfer, including
Regulations, these requirements involve contemplated onward transfers, are explicitly
ensuring that the transfer falls within the provided for in the processing agreement and
purpose, scope, and method of handling in the notification to the original data subject.
identified in key documents along the

Step 8 - Check whether an international treaty or agreement


is applicable

The PIPL provides that “general” controllers Note that under Chinese data protection law,
who do not need to undergo a security the Chinese government may take unilateral
assessment may also rely on an international action to restrict data transfers to certain
treaty or agreement that China has signed as recipients. This occurs in two primary
the basis for the data transfer (Art. 38). These circumstances. First, when a data controller
treaties will likely take the form of infringes upon the data protection rights and
agreements specific to data flows or data interests of individuals in China or threatens
security. Currently, China has yet to enter into China’s national security by processing
such an agreement. Nevertheless, Article 12 certain data, Chinese authorities may prohibit
of the PIPL plus China’s application to join transfers of information to that entity. Second,
notable regional trade agreements like the if a foreign country discriminates or employs
Comprehensive and Progressive Agreement prohibitive measures against China with
of Trans-Pacific Partnership (CPTPP) and the respect to data, China can take equal
Digital Economy Partnership Agreement measures against that country based on
(DEPA), suggest that the Chinese government actual conditions.
is open to exploring this option. Such a treaty
would bypass the foregoing steps.

Step 9 - Obligations for Entrusted Processors (委托处理)

Article 21 of the PIPL stipulates that data the GDPR). The core document outlining the
handlers can entrust certain processing responsibilities of the data handler and the
activities to trusted third parties (this mirrors entrusted party is the processing agreement,
the controller/processor relationship found in which must specify the purpose and methods
12
Future of Privacy Forum

of processing, the types of personal transfer complies with relevant requirements,


information handled, the rights and including data localization obligations and, if
obligations of both parties, and any necessary, obtaining a security assessment.
subsequent processing agreements between Such obligations also include supervision and
the entrusted party and another entity (Art. oversight.
21).
The draft Outbound Transfer Guidelines and
The interaction between entrusted handling the draft Online Data Security Management
and China’s regime for cross-border transfers Regulations both require the data controller
occurs largely through the processing to conduct an internal risk assessment for
agreement, with key compliance obligations entrusted processing to identify the potential
revolving around the terms and scope of that risks of processing, including those related to
agreement. Note, controllers must conduct a cross-border transfers.
risk-assessment for all cross-border transfers
to an entrusted party and will have to submit Entrusted processors have the responsibility
this information to the CAC if a security to follow and carry out the processing
assessment is required. agreement according to the terms of that
agreement and must not exceed the purpose
Entrusted Processors Obligations - Generally, or methods of processing in the agreement.
the entrusted processor has the duty to (PIPL Art. 21). In other words, any condition of
strictly follow the terms and conditions of the onward transfers or sub-processing should be
processing agreement. If the agreement itself contemplated prior to entering into a
violates Chinese data protection law, the data processing agreement.
controller, not the processor, bears liability.
Additionally, the 2020 PI Security The entrusted processor does not bear
Specification stipulates additional liability for violations to cross-border
requirements. Under these provisions, restriction provisions (including those that
entrusted processors must: harm data subjects) unless the data collection
exception applies (see below) or the
• Notify the controller if it fails to comply processor violates the terms of the
with the agreement due to a special processing agreement. The entrusted
reason. processor must obtain prior authorization
• Obtain prior authorization for any sub- from the controller before entrusting to sub-
processing or onward transfers. processors.
• Assist the controller to respond to Notification Requirements - Under the draft
data subject requests. Online Data Security Management
• Notify the controller if it cannot Regulations, data controllers must notify the
provide adequate security or if a data subject of the name of the foreign
security incident occurs, and, recipient, their contact method, the handling
• Not store personal information purpose, method, and information categories,
beyond the terms indicated in the as well as means for data subjects to exercise
contract, including upon termination. their data subject rights (Art. 36). Note, the
2020 PI Security Specification (信息安全技术
Processing Agreement - The data controller
carries the responsibility to ensure that the
13
Future of Privacy Forum

个人信息安全规范), indicates that this does • The trustworthiness and legal


compliance system of the data
not have to be provided if the personal recipient including their cooperation
information is de-identified and the controller with foreign government bodies and
ensures that the data recipient cannot re- whether they can effectively protect
identify the data (Art. 9.2(b)). the data.
Note the data controller does not have to • Whether the terms of the processing
identify sub-processors but must generally agreement can effectively restrain the
notify the data subject that an onward data recipient to fulfill their security
transfer will take place when obtaining protection duties contemplated under
consent. the contract.
• Conditions of re-transfer. Note
When transferring sensitive personal Chinese law does not indicate
information, controllers must inform the data whether the identities of sub-
subject of the types of sensitive personal processors must be disclosed to the
information and obtain explicit consent in authorities, but the data controller
advance. must ensure that data recipients use
the data according to the terms of the
Security Assessments - Data controllers must processing agreement and adopt
include relevant terms regarding the purpose, sufficient data security measures.
method, and scope of the processing
agreement in both their internal risk Data Collection Exception - As stated above,
assessments (usually conducted as part of a entrusted processors do not have to initiate a
DPIA), their annual outbound transfers security assessment or ensure that the
security report, and in the report sent to the transfer is compliant with Chinese law.
CAC when undergoing a security However, Article 9.6(b) of the 2020 PI
assessment. This requirement indicates that Security Specification introduces one notable
the data controller bears responsibility to exception - when the entrusted party collects
ensure that the transfer is compliant with the personal information on behalf of the data
law. Necessary terms include: controller and fails to obtain consent from the
data subject. In this circumstance, regulators
• A certification that the transfer is will treat the entrusted processor as a joint
lawful, proper, and necessary and the controller and therefore impose upon it the
risk to national security and the public responsibilities of the controller.
interest if the recipient leaks or
destroys the data.

14
Future of Privacy Forum

Step 10 (bonus) - Determine whether the transfer is


compelled by a foreign judicial or law enforcement body

Under the PIPL, data controllers cannot enforcement, or other administrative


transfer data stored in China in response to a responsibilities. In these circumstances, data
foreign government request of data without controllers must identify the relevant
approval from competent authorities (Art. 41). regulations and administrative measures that
Competent authorities refer broadly to specify the appropriate regulatory body that
Chinese regulatory bodies, including those must give approval before the transfer.
that carry out public security, law

Conclusion
While China’s transfer regime involves myriad should identify whether they are a “special
laws and administrative regulations, a general controller”, such as a CIIO, which would
framework for compliance is discernable and automatically trigger a specific compliance
benefits from detailed regulatory intervention, path. The next step is to evaluate the type of
albeit currently incomplete. In particular, the data being transferred to determine whether
Chinese government has yet to clarify two it is important data or a type of data that
specific transfer mechanisms (the certification would trigger a pre-approval process under a
process under PIPL Article 38(2) and the sectoral regulation or a security assessment
SCCs under Article 38(3)) and has currently by the CAC.
not entered into a treaty or international
agreement relevant for data transfers. The After figuring this out, controllers can
CAC is expected to release SCCs in the near determine whether a security assessment by
term, although specific dates remain the CAC is required (step four) by following
unknown. Experience suggests the regulator the threshold questions. Fifth, controllers
may issue something when it finalizes the should also ask whether their processing
draft Outbound Guidelines, the most recent activities are of the type to trigger a
administrative measure dealing with cross- cybersecurity review under the CRM or
border transfers released in late 2021. whether an exception applies. If not, the next
process involves choosing a transfer
This report untangles some of the complexity mechanism specified under the PIPL. Two of
of the new legal framework by proposing and these transfer mechanisms remain unclarified,
explaining concrete steps organizations can but the CAC should issue guidelines on both
take to lawfully transfer data from China or to in the future. Seventh, controllers should also
ascertain whether they are subject to determine whether an applicable treaty or
localization requirements. international agreement exists between
China and their established jurisdiction, as
First, controllers must determine whether they this may provide another mechanism for
fall within the scope of Chinese data transfer in addition to those specified under
protection law and whether a transfer is the PIPL. Eighth, entrusted processors do not
actually happening. Second, data controllers have the obligation to initiate a security
15
Future of Privacy Forum

assessment for their initial or onward receive approval from a competent Chinese
transfers and must primarily follow the terms authority.
specified in the transfer agreement. Lastly,
compelled transfers of data outside of China
by a foreign law enforcement body must

16
Future of Privacy Forum

Localization vs. Transfers: Flowchart


Step 1: Applicability and Determining Transfer

Processing within China? → Yes

Processing data of individuals within China outside of


China for the purpose of (a) providing services in
China, or (b) analyzing behavior? → Yes

Processing important data? → Yes

Transfer occurs when:


(i) When data generated in China is stored outside of
China
(ii) when data is provided to organizations not in China
(iii) When the data is stored in China but can be
accessed outside of the country.

Step 2: Determine Type of Data Controller

“General” controllers → not CIIOs or “special”


controllers.

CIIOs → Enumerated industry, damage to national


security or people’s livelihoods if business is damaged
or malfunctions.

“Special controllers” → defined in sectoral regulations or


administrative measures (e.g., automobile data
processor)

Step 3: Determine Type of Data

Personal information → identifies or can identify a


natural person.

Important data → damage or leakage risks harm to


national security, the public order, or the rights
and interest of individuals in China.

Other types of data → to be further clarified and


defined by subsequent administrative regulations.
17
Future of Privacy Forum

Step 4: CAC Security Assessment

CIIOs → must undergo security assessment for all transfers.

“Special controllers” → may possibly need a security assessment


pursuant to specific administrative measures.

“General processors” →
• Personal information of more than 1 million individuals or
a cumulative transfer of personal information of 100,000
individuals or sensitive information of 10,000 individuals →
must undergo a security assessment for transfers of
personal information.
• Important data → must undergo security assessment for
transfers of important data.

Step 5: Cybersecurity Assessment

Unlikely in most cases.

CIIOs → must undergo a review.

Domestic controllers processing personal information of at


least 1 million individuals and listing on a foreign stock
exchange → must undergo a review.

Transfers that harm national security → possibly need a


review (need more clarification).

Step 6 - Online Data Security Management Regulations


Exception

“General” controllers who do not need to undergo a security


assessment may rely on the health and contractual necessity
exception.

Controllers do not need to choose a transfer mechanism


when providing personal information abroad is necessary to:
1. Fulfill or conclude a contract where an individual is a
concerned party
2. Protect individuals’ lives or health, or the security of
their property.

18
Future of Privacy Forum

Step 7 - Transfer Mechanism

“General” controllers that do not need to undergo a security assessment


must choose a transfer mechanism.

PIPL Article 38 -
1. Undergoing a security assessment by the CAC (voluntary)
2. Obtaining certification through a competent government authority
(unclear)
3. Adopting SCCs issued by CAC (forthcoming)

Additional requirements -
1. Ensure data recipient takes measures to ensure same level of
Chinese data protection standards
2. Obtain separate consent for the transfer. This is not necessary if
the controller notifies the data subject of the transfer at the time
of original collection.

Step 8 - International Treaties and Agreements

Concluded between China and a foreign jurisdiction.

May offer another mechanism for transfer in addition


to those specified in Article 38 PIPL. Does not
mitigate against a security assessment, if required.

No agreements currently in operation.

Step 9 - Obligations for Entrusted Processors

General rule:
• Entrusted processors must follow the terms
and conditions of the processing agreement.
• Entrusted processors do not have
responsibility to undergo a security
assessment.
• Data controllers bear the liability for ensuring
compliance for transfers, including onward
transfers.

Data Collection Exception: Step 10 (bonus) - Compelled Transfers


An entrusted processor collects data on behalf of a
controller and fails to obtain consent from the data
subject. Compelled by a foreign judicial or law
enforcement body
• Data controllers cannot transfer
without pre-approval from Chinese
authorities.
• Which authority depends on
19 circumstances specified in additional
administrative regulations.
Future of Privacy Forum

ENDNOTES

i
[Link]
october-1-2021/ (last accessed February 18, 2022).
ii
[Link]
lessons-learned-from-the-unprecedented-investigation-of-didi-chuxing/ (last accessed
February 18, 2022).

Future of Privacy Forum


1350 Eye Street NW
Suite 350
Washington, DC 20005
e-mail: info@[Link]
[Link]

20

You might also like