News: 1629702185

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

China puts continuous consent at the center of data protection law

(2021/08/23)


China has passed a law that authorities say "further perfects" existing arrangements for protection of personal data.

The new "Personal Information Protection Law of the People's Republic of China" comes into effect on November 1st, 2021, and comprises eight chapters and 74 articles that outline strict yet vague measures on how and when data is collected and managed, individuals' rights, and who ultimately owns data.

The Cyberspace Administration of China (CAC) [1]said , as translated from Mandarin using automated tools:

On the basis of relevant laws, the law further refines and perfects the principles and personal information processing rules to be followed in the protection of personal information, clarifies the boundaries of rights and obligations in personal information processing activities, and improves the work systems and mechanisms for personal information protection.

The document outlines standardized data-handling processes, defines rules on big data and large-scale operations, regulates those processing data, addresses data that flows across borders, and outlines legal enforcement of its provisions. It also clarifies that state agencies are not immune from these measures.

The CAC asserts that consenting to collection of data is at the core of China's laws and the new legislation requires continual up-to-date fully informed advance consent of the individual. Parties gathering data cannot require excessive information nor refuse products or services if the individual disapproves. The individual whose data is collected can withdraw consent, and death doesn't end the information collector's responsibilities or the individual's rights – it only passes down the right to control the data to the deceased subject's family.

[2]

Information processors must also take "necessary measures to ensure the security of the personal information processed" and are required to set up compliance management systems and internal audits.

[3]

[4]

To collect sensitive data, like biometrics, religious beliefs, and medical, health and financial accounts, information needs to be necessary, for a specific purpose and protected. Prior to collection, there must be an impact assessment, and the individual should be informed of the collected data's necessity and impact on personal rights.

Interestingly, the law seeks to prevent companies from using big data to prey on consumers – for example setting transaction prices – or mislead or defraud consumers based on individual characteristics or habits. Furthermore, large-scale network platforms must establish compliance systems, publicly self-report their efforts, and outsource data-protective measures.

[5]China orders annual security reviews for all critical information infrastructure operators

[6]China sets goal of running single-stack IPv6 network by 2030, orders upgrade blitz

[7]Won't someone think of the kids? China's Cyberspace Admin steps up, orders massive cleanup to make the net safe for minors

And if data flows across borders, the data collectors must establish a specialized agency in China or appoint a representative to be responsible. Organizations are required to offer clarity on how data is protected and its security assessed.

Storing data overseas does not exempt a person or company from compliance to any of the Personal Information Protection Laws.

[8]

In the end, supervision and law enforcement falls to the Cyberspace Administration and relevant departments of the State Council. The penalties for failure were not listed, but one wouldn't want to run afoul – the CAC has cracked down hard on those who are loose with customer data.

For example in July 2021, China's Uber analog, DiDi, [9]was booted from local app stores on grounds it was not compliant with data rules, less than a week after it IPO'd in the US.

In May 2021 the CAC [10]ordered 105 apps , including LinkedIn, Bing, Douyin, TikTok and Baidu, to stop improperly collecting and using people's personal data. ®

Get our [11]Tech Resources



[1] http://www.cac.gov.cn/2021-08/21/c_1631141677655320.htm

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YSNx4nwwlKkJBIhczPZZxAAAAEg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSNx4nwwlKkJBIhczPZZxAAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YSNx4nwwlKkJBIhczPZZxAAAAEg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2021/08/18/china_critical_information_infrastructure_rules/

[6] https://www.theregister.com/2021/07/26/china_single_stack_ipv6_notice/

[7] https://www.theregister.com/2021/07/21/china_internet_cleanup_for_minors/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSNx4nwwlKkJBIhczPZZxAAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2021/07/05/didi_the_ridesharing_platform_that/

[10] https://www.theregister.com/2021/05/24/china_demands_microsoft_apps_rectify_data_use/

[11] https://whitepapers.theregister.com/



"death doesn't end the information collector's responsibilities or the individual's rights"

Pascal Monett

Interesting. I'd've thought that death meant the erasure of said data, but they're not going that way.

The only way the deceased' family can be granted access is if the deceased created a profile under his legal name and address. That means no anonymous logons.

Well, China's government is not big on anonymity . . .

Re: "death doesn't end the information collector's responsibilities or the individual's rights"

Anonymous Coward

Err, if the person used an anonymous login, how is anybody going to know wher he or she is alive or dead? Or indeed whether they ar a dog? :)

So cheap Chinese IoT has better data laws than the EU

tip pc

I’m certainly getting fed up of companies demanding ever more data from me.

I’m going to start lying to them as saying I don’t want to provide illicit’s a response along the lines of I must comply.

That funny feeling

Pete 2

> outline strict yet vague measures on how and when data is collected and managed, individuals' rights, and who ultimately owns data.

It seems odd that supposedly progressive countries have to look to authoritarian governments to set the standard for citizens rights.

Still I suppose when you aren't inconvenienced by having to ask permission, setting such standards is a much easier task.

Anonymous Coward

I see the shadow of the GDPR, there is a lot of overlap here. But the Chinese have turned the screws a little tighter. The think about the fate of the data of the deceased is probably a cultural thing. The dead ancestors have a more continued immediate presence in East Asia than in Europe.

Just a pity that the law in China exempts governmental institutions from any accountability. With the current administration in China, that will not change.

Humor in the Court:
Q. What is your brother-in-law's name?
A. Borofkin.
Q. What's his first name?
A. I can't remember.
Q. He's been your brother-in-law for years, and you can't remember his first
name?
A. No. I tell you I'm too excited. (Rising from the witness chair and
pointing to Mr. Borofkin.) Nathan, for God's sake, tell them your first
name!