Language

A Chinese Data Privacy Law with Strong Influences from the EU


A Chinese Data Privacy Law with Strong Influences from the EU-China Releases the Draft on Its First Uniform Personal Information Protection Law


Authored by Yingying Zhu


The world has witnessed a torrent of lawmaking, regulatory design and enforcement activities regarding data privacy following the enactment of the General Data Protection Regulation (“GDPR”) [1] of the European Union in May 2018. At present, 132 out of 194 countries had put in place legislation to secure the protection of data and privacy. [2]

 

The inadequacy of personal information protection in China has raised widespread public concerns in this big data land with 904 million netizens,[3] vulnerable to data breaches and cyber frauds. In 2016, a professor at the prestigious Tsinghua University wired more than CNY17 million to a fraud, after she received a scam call from the fraud who knew every detail about the deal of a recent sale of her real property.[4] Incidents like this have led to nationwide discussions and provoked reflection among thinkers, legal experts and law makers. 

 

At present, data protection laws, regulations and specifications in China were scattered in sectional laws, regulations and non-binding guidelines, such as the Criminal Law and its Amendment VII, the Consumer Protection Law, the Cybersecurity Law, the Personal Information Security Specification, the Civil Code, etc.

 

On October 13, 2020, after years of brewing, China releases the long-awaited and much-welcomed draft on its first dedicated personal information protection law. The draft has been submitted to the standing committee of the China's top legislature-the National People’s Congress (“NPC”) for the first review and then posted for public comments on NPC’s official website. The comment period lasts until November 19, 2020.

 

Being the first comprehensive law that emulates the GDPR, the draft Personal Information Protection Law (“draft PIPL”) has shown strong GDPR influences as well as its unique Chinese characteristics.

Definition of “Personal Information” and “Sensitive Personal Information”

The types of information considered personal under the draft PIPL include various information recorded electronically or in other forms that is relating to an identified or identifiable natural person (“data subject”), excluding the anonymized information. The processing of personal information includes activities such as the collection, storage, use, handling, transmission, provision, and disclosure of personal information.

Here, “personal information” under the draft PIPL is similar in terms of definition to “personal data” used in the GDPR as well as in its predecessor, the EU Data Protection Directive,[5] because it includes data that relate both to an “identified” or “identifiable” individual. “Identifiable” means that an individual might not currently be identified but could be identified by combining various pieces of data.[6] For example, the name of a person (in particular, a none-celebrity), is often not identified to an individual, but sometimes can easily be linked to an individual with bits of other information, such as an address, a telephone number or a place of work.

 

On a risk-based approach, the draft PIPL defines sensitive personal information (“SPI”) as personal information that once leaked or illegally used may lead to discriminatory treatment or could seriously endanger the safety of persons or property, including information such as one’s race, ethnicity, religious beliefs, personal biological characteristics, medical health, financial accounts, personal whereabouts and so forth.[7] Only personal information processors with a specific purpose and sufficient necessity may process SPI. The draft also requires that the individuals' “independent consent” shall be obtained where processing SPI is to be based on individuals' consent and individuals shall also be informed of the necessity of processing SPI and the impact on them.

 

The draft PIPL, for the first time in China’s privacy protection legislation, specifically defines SPI. As improper disclosures of SPI can cause greater harm and damage to the image, reputation or security of an individual, it is of significant importance to ensure that SPI could be specifically defined and appropriately protected.

 

One problem with the draft PIPL’s definition of SPI, however, is that it seems to ignore a certain type of SPI -a person’s private or secret life that in many defamation cases has been the subject of public online shaming. If an individual’s personal private life (usually unpleasant, eccentric or immoral) was posted on some popular online platforms due to mishandling of that individual’s personal information, and the news goes viral, the victim in many cases would suffer spiritually from attacks of cyber-mobs and internet violence. The suffering can be nothing financial but only emotional. Here, the risk-based definition of SPI in the draft PIPL only covers risks in the form of “discriminatory treatment” or “endangering safety of persons or property”, but leaving out the harm caused to personal reputation and psychological health, which, in many cases, could be the only resulted harm in violation of SPI. The draft PIPL obviously did not give enough consideration to such type of possible harm in its current definition of SPI.

 

Under the GDPR, processing of personal data of a sensitive nature shall be prohibited, unless some stricter preconditions could be met. Such data are classified under the label of SPI[8] and sensitive data are clearly listed by its definition.

 

Though differ in defining, the draft PIPL converges with the GDPR in that both recognize SPI is belonging to a specific category of information that must be treated with extra safeguarding.

Rights of Individuals

Under the draft PIPL, individuals enjoy the right to know and make decisions about the processing of their personal information, and have the right to limit or refuse the processing of their personal information by others, except otherwise provided by laws and administrative regulations

Specifically, individuals enjoy the following rights:

1)    Right to access:[9] the data subject may consult or reproduce his personal information from the information processor;

2)    Right to rectification: upon discovery of any error in the information, the data subject has the right to raise an objection and to request to have a timely correction;

3)    Right to be forgotten: if the handling of personal information is in violation of law, or any prior agreement, or the purposes of processing have been realized, or an individual has withdrawn the consent, the data subject has the right to request a timely erasure. If, however, the retention period prescribed by law has not been completed, or deletion of personal information is technically difficult to achieve, the personal information processor shall stop the processing;

4)    Right to be informed: individuals have the right to be informed about rules concerning the processing of their personal information;

5)    Right to refuse automated decision-making: where an individual believes that automated decision-making has a significant impact on one’s rights and interests, one has the right to request an explanation from the personal information processor and has the right to refuse automated individual decision-making.

Under the draft PIPL, individuals have a broader scope of rights than previous laws in the same sector and it brings China’s protection on privacy even closer to the GDPR standards.[10] It is however interesting to note the “right to data portability”[11] under the GDPR has not been transplanted to its Chinese counterpart. As the right to data portability does not apply to genuinely anonymous data but only to pseudonymous data that can clearly be linked back to a data subject, maybe the notions of cyber- sovereignty and network security with a distinguishable Chinese feature could account for the missing of such right in the Chinese context..

Principles and Conditions for Data Processing

Under the draft PIPL, the general principles for data collection are: data shall be collected lawfully and justifiably, openly and transparently, accurately and kept up-to-date and data collection shall have clear and reasonable purposes and be limited to the minimum scope to achieve such purposes of processing. The data processing activities shall meet the following conditions:

(1) With the consent of the individual;

 

(2) It is necessary for entering into or performing a contract to which the individual is a party;

 

(3) It is necessary for performing of legally-binding duties or obligations;

 

(4) It is necessary to respond to public health incidents or to protect natural persons' security in their lives, health, and property under an emergency;

 

(5) It is within a reasonable range in order to carry out acts such as news reporting and public opinion overseeing in the public interest; or

 

Other circumstances warranted by laws or administrative regulations.

 

The GDPR provides six legal bases for processing personal data, namely: consent; contract; legal obligation; vital interests; public task; or legitimate interests pursued by the controller or by a third party.[12] The draft PIPL sets out the above five specific legal bases for processing personal data, which are comparable to the first five legal bases of the GDPR while chipping away the last one concerning “legitimate interests pursued by the controller or by a third party”, on the possible account that it would have the potential of giving too much discretion to the information processor and therefore dilute the value of all the other legal bases.

 

Under the draft PIPL, consent, albeit the most well-known one, is just one of the legal bases a business can rely on to justify the proceeding of individuals’ personal data. Furthermore, for consent to be valid, it must be freely-given, unambiguous and explicit, informed and withdrawable. Consent is not freely-given if individuals have no other meaningful options but to give out their consent. This means businesses shall not create an opt-in-or-leave-it situation when seeking people’s consent. Individuals need to maintain the ability to decline and shall be free from discrimination when they opt out. The draft PIPL also specifies that if there are changes to the purposes or methods for processing information, or to the type of personal information to be processed, the individual's consent shall be re-obtained.

 

Extraterritorial Applicability

 

The GDPR has an extraterritorial scope, because it may apply to businesses established outside the European Union when they offer goods or services to data subjects in the European Union or monitor their behavior when it takes place in the European Union.[13]

 

Modeling on the GDPR’s approach towards extraterritorial application, Article 3 of the draft PIPL expands the law’s territorial scope to data processing activities outside China. Any data processing activities that process personal data within P.R. China, if meeting any of the following conditions, will fall under the territorial scope of the Chinese data protection law:

 

(1) for the purpose of providing products or services to natural persons within the territory;

 

(2) to analyze and evaluate the conduct of natural persons in the territory; or

 

(3) other circumstances provided for by laws and administrative regulations.

 

If this clause remains intact in the final legal text, it means that the Chinese privacy rules now can also apply to data processing activities outside China. The consequence of this expansion is that non-Chinese data controllers and processors must comply with the Chinese data protection obligations when processing data on individuals in China for the above-listed purposes.

Obligations of Personal Information Processor

Under the draft PIPL, the personal information processor, the one who collects, stores, uses, handles, transmits, provides, and discloses personal information, shall have the following obligations:

(1) take necessary measures to ensure the legal compliance of personal information processing activities and prevent unauthorized access, disclosure or theft, tampering, and deletion of personal information;

(2) while processing personal information at certain volume, shall designate a person in charge to be responsible for overseeing personal information processing activities and any protection measures taken;

(3) if processing Chinese individuals’ personal information outside China as provided in Article 3 of the Law shall establish a point of contact within China;

(4) shall conduct periodic audits and risk assessments in advance for certain categories of personal information processing activities;

(5) where there is incident of personal information leakage, shall immediately take remedial measures and notify the supervisory authorities.

Once a data breach occurs, the GDPR requires data controllers to notify supervisory authorities of a security breach within 72 hours after it has been aware of it.[14] Furthermore, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.[15]

In comparison, the draft PIPL is not specific about the timeframe for notification to the supervisory authorities and where personal information processors take measures that can effectively avoid the harm caused by the information leakage, the personal information processors are allowed to not notify the individuals.

Liabilities and Penalties

Violations of the draft PIPL may be subject to a fine of up to CNY1 million (about EUR 0.128 million); the directly responsible management and other directly responsible person may be subject to a fine of between CNY10,000 (about EUR1,283) to CNY100,000 (about EUR12,831). Serious violations of the draft PIPL can be fined up to CNY 50 million (about EUR 6.4 million) or up to 5% of the preceding year's turnover. Where there is an illegal act of data processing activities, it is to be recorded in the business’ credit files with a public announcement posted.

In comparison, under GDPR, the less severe infringements could result in a fine of up to EUR10 million, or 2% of the business’ global annual revenue in the preceding financial year, whichever is higher. For more severe infringements, GDPR sets a maximum fine of EUR 20 million or 4% of annual turnover, whichever is higher.[16]

In an age of constant, complex and sometimes intrusive technological innovation, the high penalties on noncompliance aim to have a deterrent effect on rule-breakers who are mishandling people’s data or using people’s data without adequate measures in place to safeguard them.

Conclusion

The draft PIPL, being the first dedicated law to data privacy protection in China, thus forming a unified force of enforcement, marks a milestone in the country data privacy legislation. The law shows a broader scope of application than the previous sectional laws and regulations and levels up the country’s protection on data privacy closer to the GDPR standards, a.k.a., the global standards, given the large number of countries around the world that have adopted the GDPR model. While highly converging with the EU rules, the draft PIPL demonstrates a unique Chinese characteristics thus showing a strong Chinese voice with a subtle EU accent.

The laws and regulations on data privacy are constantly evolving in China with changes still in the pipeline. We are here to help if you have any problems, issues, concerns regarding data privacy protection inside or outside China.

 



[1] The General Data Protection Regulation (EU) 2016/679.

[2] See https://unctad.org/page/data-protection-and-privacy-legislation-worldwide.

[3]See https://www.thehindu.com/news/international/chinas-netizen-population-hits-record-904-million-report/article31451143.ece.

[4] See http://www.techweb.com.cn/tele/2017-02-20/2489197.shtml.

[5] The Data Protection Directive, officially Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data.

[6] Paul M. Schwartz & Daniel J. Solove, Reconciling Personal Information in the U.S. and EU, 102 Cal. L. Rev. 886 (2014).

[7] While an official translation is not yet available, the author has referenced the source at https://www.chinalawtranslate.com/en/personal-information-protection-draft for the translation of the texts of the draft PIPL.

[8] Definition of “sensitive personal information” under the GDPR: data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation.

[9] The subtitles are used in this article for convenience only; they are not part of the draft PIPL.

[10] Rights for individuals under the GDPR, see https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights.

[11] The right to data portability allows individuals to obtain and reuse their personal data for their own purposes across different services. It allows them to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without affecting its usability. See https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-data-portability/.

[12] GDPR, Article 6(1).

[13] GDPR, Article 3(2).

[14] GDPR, Article 33(1).

[15] GDPR, Article 34(1).

[16] See https://www.itgovernance.co.uk/dpa-and-gdpr-penalties.

  • 相关资讯 More
  • 点击次数: 1000003
    2025 - 09 - 26
    作者:王辉 在员工严重失职给公司造成重大损失时,公司能否依据《劳动合同法》第三十九条解除劳动合同?公司解雇行为属于合法维权还是违法侵权?司法实践中,公司胜诉与败诉的案例皆不鲜见。下文就结合司法案例,从公司合法解除与违法解除两个视角剖析其中关键。一、实务案例◆案例1  合法解除 (参见(2022)京0105民初16489号判决书)原告张某与某顾问公司分别于2007年12月24日、2010年1月1日、2013年1月1日签订劳动合同,2015年3月1日张某与北京某人力资源有限公司签订劳动合同,张某与上述案外公司签订劳动合同后均派遣至被告某公司工作。2021年1月1日原告与被告某公司签订无固定期限劳动合同,从事销售岗位。2021年3月26日,被告某公司以原告张某从事货品职务,因工作失误造成北京某零售部订货损失870件,价值375354元为由解除与张某签署的劳动合同。后张某向北京市朝阳区劳动人事争议仲裁委员会提出仲裁申请,朝阳仲裁委作出京朝劳人仲字[2021]第18715号裁决书,驳回张某的全部仲裁请求。张某不服,诉至法院。被告某公司为证明其解雇行为合法提交了《员工违纪过失单》、邮件截屏、微信聊天记录截屏、损失明细表、《零售员工手册》、征求意见函、通知工会函。《员工违纪过失单》载明:“违纪人姓名:张某;违纪时间:2021年3月25日;违纪经过:工作失误导致某零售公司订货损失870件金额375354元。违反的规定条款:条款原文:丙类(严重)过失行为:由于管理不当、工作失误或玩忽职守或其他个人原因,造成人身伤害或公司财产损失人民币500元以上。”员工签字处显示张某姓名签字,落款日期为2021年3月26日。微信聊天记录截屏显示时间为“星期四12:40”的信息内容:“某某今天有补货,邮件转给你了,销售好款保证店铺两周周转,从开始到导完单告诉我用了多长时间。”张某回复:“好...
  • 点击次数: 1000003
    2025 - 08 - 22
    作者:刘艳玲随着科技的发展,越来越多的发明不再局限于单一技术领域,而是跨越多个技术领域形成创新,这种跨领域的技术创新会产生全新的商业价值和应用场景。先来假设一个场景,假如你或你的团队深耕大健康产业,你们注意到中医理疗市场2019年规模达2920亿元,到了2023年市场规模已经初步统计超过7000亿元,未来增长空间巨大,因此希望在中医理疗市场拓展业务。相比于传统的针灸、推拿、艾灸、拔罐和刮痧等保健方法,你们想结合现代技术提供有市场竞争力的产品和服务。人工智能技术和机器人技术是未来的发展方向,因此看好与电或磁相关的中医理疗产品和服务。上面描述的这类技术创新就涉及多个技术领域,需要了解甚至掌握中医、信息通信技术(ICT)和机械设计等相关知识才能实现创新,很明显这需要团队合作,因为一个人甚至一个团队不可能具备这么多技术领域的知识储备。而且,可能还需要能提供相应技术和/或产品部件的外部供应商支持。通常来说,技术专家大多熟悉的是自己从事的技术领域的最新发展,较少了解其他领域的技术及其发展,希望横跨多个技术领域进行研发创新并商业化落地,那么熟悉专利检索和分析是非常必要的。下面以这个场景为例来介绍专利检索和分析。 第一步,学习和了解业务方向的技术和市场发展情况,确定专利检索主题。随着医学的发展,现代科学已发现生物电和人体细胞、血液、经络和神经都有关系。中医讲究气血循环、经络畅通,气血之“气”为人体之“电气”,即人体生物电。经络是导电的,也即“电气”会循着人体经络流动。因此,将专利检索主题初步确定为利用电技术作用于人体经络实现理疗的发明创新。第二步,进行初步专利检索尝试。这里我们选择国家知识产权局提供的公共专利检索数据库https://pss-system.cponline.cnipa.gov.cn/conventionalSearch为例进行说明,当然你也可以选择其他免费或收费的商业专利数...
  • 点击次数: 1000003
    2025 - 08 - 15
    作者:张琳自我国上世纪80年代开始推行社会保险制度、到90年代各地陆续实施了社会保险制度以来,存在大量用人单位未为劳动者缴纳社会保险的情况。很多劳动者当时并未意识到社会保险的意义和价值,同时每月还可以多到手一些工资,因此并未对此提出质疑。随着人们法律意识的增强,许多劳动者开始认识到了社会保险在养老、看病等方面的价值,开始运用法律武器维护自身的权益。特别是将于2025年9月1日生效的《最高人民法院关于审理劳动争议案件适用法律问题的解释(二)》再一次将社保问题推到了风口浪尖。劳动者社保维权的其中一种方式是向社保部门投诉要求用人单位补缴在职期间的社会保险。但是,如果劳动者无法提供与用人单位的劳动合同,社保部门就无法认定双方之间存在劳动关系,进而无法启动社会保险稽核程序。在这种情况下,劳动者就需要先通过劳动仲裁/诉讼程序确认其与用人单位之间存在劳动关系,之后再带着确认双方劳动关系的裁决书/判决书向社保部门投诉。但是,由于有些劳动者已离职多年,时过境迁,有些用人单位已经注销了,这种情况下劳动者还能否通过劳动仲裁/诉讼主张确认劳动关系?把谁作为被申请人/被告?确认与谁存在劳动关系?这种确认劳动关系之诉是否受仲裁时效或诉讼时效的限制?确认劳动关系后还能否向社保部门投诉要求补缴社保?鉴于我国各地经常就劳动争议和社保等问题出台地方性法规、政府规章、司法文件、规范性文件等,各地劳动仲裁机构和人民法院基于对现有劳动相关法律的理解不一致和地方规定的不一致在同类劳动争议案件中往往作出不一致的裁判结果,本文引用北京的两个案例对上述问题进行分析和讨论,仅供大家参考。 一、案例简介案例一:邢某与某红公司劳动争议案件(参见北京市朝阳区人民法院(2022)京0105民初75494号民事判决书、北京市第三中级人民法院(2024)京03民终9047号民事判决书)邢某于1983年8月1日至1984年3月3...
  • 点击次数: 1000004
    2025 - 08 - 08
    作者:金涟伊《中华人民共和国商标法》(以下简称“商标法”)第三十条规定:“申请注册的商标,凡不符合本法有关规定或者同他人在同一种商品或者类似商品上已经注册的或者初步审定的商标相同或者近似的,由商标局驳回申请,不予公告。” 该法条是商标审查实践中判断商标是否应予核准注册的重要法律依据。 尽管该条款本身并未出现“混淆”二字,但《最高人民法院关于审理商标民事纠纷案件适用法律若干问题的解释》及《北京市高级人民法院商标授权确权行政案件审理指南》等配套规范,已将“容易导致混淆”确立为独立的评判要件。司法实践中,法院援引本条时,除审查标识是否“相同或近似”、商品是否“同一种或类似”外,还需进一步评估是否存在混淆可能。本文拟以某公司诉国家知识产权局商标驳回复审行政纠纷一案为切入点,探析《商标法》第三十条中“混淆可能性”的认定尺度与适用逻辑。 一、《商标法》第30条规定与混淆 现行《商标法》明文提及“混淆”的法条只有3条,即第13条对驰名商标的保护条款、第42条关于转让的条款,以及第57条关于侵犯注册商标专用权的条款。但在商标相关司法解释、部门规章等法规中,“混淆”是商标法第30条认定商标近似的重要判断依据。 2010年《最高人民法院关于审理商标授权确权行政案件若干问题的规定》第16条规定,人民法院认定商标是否近似,既要考虑商标标志构成要素及其整体的近似程度,也要考虑相关商标的显著性和知名度、所使用商品的关联程度等因素,以是否容易导致混淆作为判断标准。 而2019年北京市高级人民法院发布的《商标授权确权行政案件审理指南》第15条进一步明确了,“适用商标法第三十条、第三十一条时,可以综合考虑商标标志的近似程度、商品的类似程度、引证商标的显著性和知名度、相关公众的注意程度以及诉争商标申请人的主观意图等因素,以及前述因素之间的相互影响,以是否容易造...
× 扫一扫,关注微信公众号
铭盾MiNGDUN www.mdlaw.cn
Copyright© 2008 - 2025 铭盾京ICP备09063742号-1犀牛云提供企业云服务
X
1

QQ设置

3

SKYPE 设置

4

阿里旺旺设置

5

电话号码管理

6

二维码管理

展开