News: 1623694513

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Law prof: New Chinese data regulations make it 'very hard for foreign firms to comply'

(2021/06/14)


China's Standing Committee of the National People's Congress has passed a new data security law requiring companies to seek approval before transferring what it refers to as "core" data overseas.

Rule-breakers can end up paying up to ¥10m ($1.56m, £1.1m) in fines or possibly face closure.

Data under a lesser qualification of "important" that is handed to overseas law enforcement agencies without Beijing's approval will receive up to ¥5m ($781,000) and a possible business suspension, up from a previous ¥1m ($156,000) that was stated in the draft of the law.

[1]

The new [2]law also punishes companies that suffer large data leaks with a fine of up to ¥2m ($312,000).

[3]

[4]

The law is scheduled to come into effect on 1 September, leaving 2.5 months for companies and governments to plan accordingly. Major data security decisions will be made by a central national security agency.

[5]China arrests over 1000 for using cryptocurrency to help launder proceeds of phone scams

[6]Hong Kong to explore its own digital currency and keep testing China’s Digital Yuan

[7]Biden cancels Trump's bans on TikTok, WeChat, other Chinese apps

[8]Supreme Court narrows Computer Fraud and Abuse Act: Misusing access not quite the same as breaking in

Qualifications for "core" and "important" data were left undefined, but the law did call for the development of a classification system.

Singapore Management University law professor Henry Gao, who specialises in China, trade and the WTO, [9]tweeted that there seems to be a lot of overlap between "core" and "important", but settled on this definition for core:

Now Data Security Law creates yet another type called “core data”, which is more important than important data & subject to the most stringent restrictions. “Core data” includes those on national security, lifeline of national economy, key people's livelihood, public interests. [10]pic.twitter.com/30yLyX2050 — Henry Gao (@henrysgao) [11]June 11, 2021

Gao told The Register via email that there are two possible reasons the law left the key terms unclear: a rushed timeline where the drafters had not yet settled on definitions and/or to give the government wide discretion over their use. He reckons it's a combination of both. Vague wording has long been a tradition in Chinese law.

Gao added:

It would be very hard for foreign firms to comply, as now they have to tread in a field filled with potential landmines. To be cautious, they might want to segment their Chinese operations from the rest of the world or transact with Chinese entities through third parties rather than directly.

One interesting thing to watch will be how China's new data law interacts with the United States' 2018 [12]CLOUD Act (Clarifying Lawful Overseas Use of Data Act), which allows law enforcement agencies to access stored data from US-based technology companies no matter where that data resides in the world. ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YMfRgT3jrpBObp1s-z69vQAAAFY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] http://www.xinhuanet.com/politics/2021-06/11/c_1127552204.htm

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMfRgT3jrpBObp1s-z69vQAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMfRgT3jrpBObp1s-z69vQAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2021/06/11/china_crypto_crackdown_continues/

[6] https://www.theregister.com/2021/06/10/hong_kong_fintech_cdbc_strategy/

[7] https://www.theregister.com/2021/06/10/biden_china_apps/

[8] https://www.theregister.com/2021/06/03/supreme_court_cfaa/

[9] https://twitter.com/henrysgao/status/1403305752744189957

[10] https://t.co/30yLyX2050

[11] https://twitter.com/henrysgao/status/1403305211855212548?ref_src=twsrc%5Etfw

[12] https://www.theregister.com/2018/02/07/big_tech_biz_back_us_proposals_to_ease_overseas_data_transfers/

[13] https://whitepapers.theregister.com/

'Core and important data'

Eclectic Man

I guess that non-Chinese owned companies operating in the PRC will be concerned that their internal operational data, needed for international operations could be considered core or important data. The definition seems to include some economic data, so will Western banks and other financial institutions find their normal trading practices be covered by this?

Blackjack

Maybe it would be good to just stop doing business in China and so you aren't at the mercy of a dictatorship that changes the rules all the time and does whatever it wants.

But hey companies will do anything for money...

Data under multiple jurisdictions.

BOFH in Training

I wonder how the CLOUD act from the US holds up with other countries having their own versions of privacy laws such as the GDPR, etc.

Now China has it's own version of data control law. I wonder "who wins" when a piece of data is under multiple jurisdictions.

Might end up with a case of die if you do, die if you don't.

Sysadmin and editors. The holy wars of UNIX.

- Linus Torvalds on linux-kernel