Language

A Chinese Data Privacy Law with Strong Influences from the EU


A Chinese Data Privacy Law with Strong Influences from the EU-China Releases the Draft on Its First Uniform Personal Information Protection Law


Authored by Yingying Zhu


The world has witnessed a torrent of lawmaking, regulatory design and enforcement activities regarding data privacy following the enactment of the General Data Protection Regulation (“GDPR”) [1] of the European Union in May 2018. At present, 132 out of 194 countries had put in place legislation to secure the protection of data and privacy. [2]

 

The inadequacy of personal information protection in China has raised widespread public concerns in this big data land with 904 million netizens,[3] vulnerable to data breaches and cyber frauds. In 2016, a professor at the prestigious Tsinghua University wired more than CNY17 million to a fraud, after she received a scam call from the fraud who knew every detail about the deal of a recent sale of her real property.[4] Incidents like this have led to nationwide discussions and provoked reflection among thinkers, legal experts and law makers. 

 

At present, data protection laws, regulations and specifications in China were scattered in sectional laws, regulations and non-binding guidelines, such as the Criminal Law and its Amendment VII, the Consumer Protection Law, the Cybersecurity Law, the Personal Information Security Specification, the Civil Code, etc.

 

On October 13, 2020, after years of brewing, China releases the long-awaited and much-welcomed draft on its first dedicated personal information protection law. The draft has been submitted to the standing committee of the China's top legislature-the National People’s Congress (“NPC”) for the first review and then posted for public comments on NPC’s official website. The comment period lasts until November 19, 2020.

 

Being the first comprehensive law that emulates the GDPR, the draft Personal Information Protection Law (“draft PIPL”) has shown strong GDPR influences as well as its unique Chinese characteristics.

Definition of “Personal Information” and “Sensitive Personal Information”

The types of information considered personal under the draft PIPL include various information recorded electronically or in other forms that is relating to an identified or identifiable natural person (“data subject”), excluding the anonymized information. The processing of personal information includes activities such as the collection, storage, use, handling, transmission, provision, and disclosure of personal information.

Here, “personal information” under the draft PIPL is similar in terms of definition to “personal data” used in the GDPR as well as in its predecessor, the EU Data Protection Directive,[5] because it includes data that relate both to an “identified” or “identifiable” individual. “Identifiable” means that an individual might not currently be identified but could be identified by combining various pieces of data.[6] For example, the name of a person (in particular, a none-celebrity), is often not identified to an individual, but sometimes can easily be linked to an individual with bits of other information, such as an address, a telephone number or a place of work.

 

On a risk-based approach, the draft PIPL defines sensitive personal information (“SPI”) as personal information that once leaked or illegally used may lead to discriminatory treatment or could seriously endanger the safety of persons or property, including information such as one’s race, ethnicity, religious beliefs, personal biological characteristics, medical health, financial accounts, personal whereabouts and so forth.[7] Only personal information processors with a specific purpose and sufficient necessity may process SPI. The draft also requires that the individuals' “independent consent” shall be obtained where processing SPI is to be based on individuals' consent and individuals shall also be informed of the necessity of processing SPI and the impact on them.

 

The draft PIPL, for the first time in China’s privacy protection legislation, specifically defines SPI. As improper disclosures of SPI can cause greater harm and damage to the image, reputation or security of an individual, it is of significant importance to ensure that SPI could be specifically defined and appropriately protected.

 

One problem with the draft PIPL’s definition of SPI, however, is that it seems to ignore a certain type of SPI -a person’s private or secret life that in many defamation cases has been the subject of public online shaming. If an individual’s personal private life (usually unpleasant, eccentric or immoral) was posted on some popular online platforms due to mishandling of that individual’s personal information, and the news goes viral, the victim in many cases would suffer spiritually from attacks of cyber-mobs and internet violence. The suffering can be nothing financial but only emotional. Here, the risk-based definition of SPI in the draft PIPL only covers risks in the form of “discriminatory treatment” or “endangering safety of persons or property”, but leaving out the harm caused to personal reputation and psychological health, which, in many cases, could be the only resulted harm in violation of SPI. The draft PIPL obviously did not give enough consideration to such type of possible harm in its current definition of SPI.

 

Under the GDPR, processing of personal data of a sensitive nature shall be prohibited, unless some stricter preconditions could be met. Such data are classified under the label of SPI[8] and sensitive data are clearly listed by its definition.

 

Though differ in defining, the draft PIPL converges with the GDPR in that both recognize SPI is belonging to a specific category of information that must be treated with extra safeguarding.

Rights of Individuals

Under the draft PIPL, individuals enjoy the right to know and make decisions about the processing of their personal information, and have the right to limit or refuse the processing of their personal information by others, except otherwise provided by laws and administrative regulations

Specifically, individuals enjoy the following rights:

1)    Right to access:[9] the data subject may consult or reproduce his personal information from the information processor;

2)    Right to rectification: upon discovery of any error in the information, the data subject has the right to raise an objection and to request to have a timely correction;

3)    Right to be forgotten: if the handling of personal information is in violation of law, or any prior agreement, or the purposes of processing have been realized, or an individual has withdrawn the consent, the data subject has the right to request a timely erasure. If, however, the retention period prescribed by law has not been completed, or deletion of personal information is technically difficult to achieve, the personal information processor shall stop the processing;

4)    Right to be informed: individuals have the right to be informed about rules concerning the processing of their personal information;

5)    Right to refuse automated decision-making: where an individual believes that automated decision-making has a significant impact on one’s rights and interests, one has the right to request an explanation from the personal information processor and has the right to refuse automated individual decision-making.

Under the draft PIPL, individuals have a broader scope of rights than previous laws in the same sector and it brings China’s protection on privacy even closer to the GDPR standards.[10] It is however interesting to note the “right to data portability”[11] under the GDPR has not been transplanted to its Chinese counterpart. As the right to data portability does not apply to genuinely anonymous data but only to pseudonymous data that can clearly be linked back to a data subject, maybe the notions of cyber- sovereignty and network security with a distinguishable Chinese feature could account for the missing of such right in the Chinese context..

Principles and Conditions for Data Processing

Under the draft PIPL, the general principles for data collection are: data shall be collected lawfully and justifiably, openly and transparently, accurately and kept up-to-date and data collection shall have clear and reasonable purposes and be limited to the minimum scope to achieve such purposes of processing. The data processing activities shall meet the following conditions:

(1) With the consent of the individual;

 

(2) It is necessary for entering into or performing a contract to which the individual is a party;

 

(3) It is necessary for performing of legally-binding duties or obligations;

 

(4) It is necessary to respond to public health incidents or to protect natural persons' security in their lives, health, and property under an emergency;

 

(5) It is within a reasonable range in order to carry out acts such as news reporting and public opinion overseeing in the public interest; or

 

Other circumstances warranted by laws or administrative regulations.

 

The GDPR provides six legal bases for processing personal data, namely: consent; contract; legal obligation; vital interests; public task; or legitimate interests pursued by the controller or by a third party.[12] The draft PIPL sets out the above five specific legal bases for processing personal data, which are comparable to the first five legal bases of the GDPR while chipping away the last one concerning “legitimate interests pursued by the controller or by a third party”, on the possible account that it would have the potential of giving too much discretion to the information processor and therefore dilute the value of all the other legal bases.

 

Under the draft PIPL, consent, albeit the most well-known one, is just one of the legal bases a business can rely on to justify the proceeding of individuals’ personal data. Furthermore, for consent to be valid, it must be freely-given, unambiguous and explicit, informed and withdrawable. Consent is not freely-given if individuals have no other meaningful options but to give out their consent. This means businesses shall not create an opt-in-or-leave-it situation when seeking people’s consent. Individuals need to maintain the ability to decline and shall be free from discrimination when they opt out. The draft PIPL also specifies that if there are changes to the purposes or methods for processing information, or to the type of personal information to be processed, the individual's consent shall be re-obtained.

 

Extraterritorial Applicability

 

The GDPR has an extraterritorial scope, because it may apply to businesses established outside the European Union when they offer goods or services to data subjects in the European Union or monitor their behavior when it takes place in the European Union.[13]

 

Modeling on the GDPR’s approach towards extraterritorial application, Article 3 of the draft PIPL expands the law’s territorial scope to data processing activities outside China. Any data processing activities that process personal data within P.R. China, if meeting any of the following conditions, will fall under the territorial scope of the Chinese data protection law:

 

(1) for the purpose of providing products or services to natural persons within the territory;

 

(2) to analyze and evaluate the conduct of natural persons in the territory; or

 

(3) other circumstances provided for by laws and administrative regulations.

 

If this clause remains intact in the final legal text, it means that the Chinese privacy rules now can also apply to data processing activities outside China. The consequence of this expansion is that non-Chinese data controllers and processors must comply with the Chinese data protection obligations when processing data on individuals in China for the above-listed purposes.

Obligations of Personal Information Processor

Under the draft PIPL, the personal information processor, the one who collects, stores, uses, handles, transmits, provides, and discloses personal information, shall have the following obligations:

(1) take necessary measures to ensure the legal compliance of personal information processing activities and prevent unauthorized access, disclosure or theft, tampering, and deletion of personal information;

(2) while processing personal information at certain volume, shall designate a person in charge to be responsible for overseeing personal information processing activities and any protection measures taken;

(3) if processing Chinese individuals’ personal information outside China as provided in Article 3 of the Law shall establish a point of contact within China;

(4) shall conduct periodic audits and risk assessments in advance for certain categories of personal information processing activities;

(5) where there is incident of personal information leakage, shall immediately take remedial measures and notify the supervisory authorities.

Once a data breach occurs, the GDPR requires data controllers to notify supervisory authorities of a security breach within 72 hours after it has been aware of it.[14] Furthermore, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.[15]

In comparison, the draft PIPL is not specific about the timeframe for notification to the supervisory authorities and where personal information processors take measures that can effectively avoid the harm caused by the information leakage, the personal information processors are allowed to not notify the individuals.

Liabilities and Penalties

Violations of the draft PIPL may be subject to a fine of up to CNY1 million (about EUR 0.128 million); the directly responsible management and other directly responsible person may be subject to a fine of between CNY10,000 (about EUR1,283) to CNY100,000 (about EUR12,831). Serious violations of the draft PIPL can be fined up to CNY 50 million (about EUR 6.4 million) or up to 5% of the preceding year's turnover. Where there is an illegal act of data processing activities, it is to be recorded in the business’ credit files with a public announcement posted.

In comparison, under GDPR, the less severe infringements could result in a fine of up to EUR10 million, or 2% of the business’ global annual revenue in the preceding financial year, whichever is higher. For more severe infringements, GDPR sets a maximum fine of EUR 20 million or 4% of annual turnover, whichever is higher.[16]

In an age of constant, complex and sometimes intrusive technological innovation, the high penalties on noncompliance aim to have a deterrent effect on rule-breakers who are mishandling people’s data or using people’s data without adequate measures in place to safeguard them.

Conclusion

The draft PIPL, being the first dedicated law to data privacy protection in China, thus forming a unified force of enforcement, marks a milestone in the country data privacy legislation. The law shows a broader scope of application than the previous sectional laws and regulations and levels up the country’s protection on data privacy closer to the GDPR standards, a.k.a., the global standards, given the large number of countries around the world that have adopted the GDPR model. While highly converging with the EU rules, the draft PIPL demonstrates a unique Chinese characteristics thus showing a strong Chinese voice with a subtle EU accent.

The laws and regulations on data privacy are constantly evolving in China with changes still in the pipeline. We are here to help if you have any problems, issues, concerns regarding data privacy protection inside or outside China.

 



[1] The General Data Protection Regulation (EU) 2016/679.

[2] See https://unctad.org/page/data-protection-and-privacy-legislation-worldwide.

[3]See https://www.thehindu.com/news/international/chinas-netizen-population-hits-record-904-million-report/article31451143.ece.

[4] See http://www.techweb.com.cn/tele/2017-02-20/2489197.shtml.

[5] The Data Protection Directive, officially Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data.

[6] Paul M. Schwartz & Daniel J. Solove, Reconciling Personal Information in the U.S. and EU, 102 Cal. L. Rev. 886 (2014).

[7] While an official translation is not yet available, the author has referenced the source at https://www.chinalawtranslate.com/en/personal-information-protection-draft for the translation of the texts of the draft PIPL.

[8] Definition of “sensitive personal information” under the GDPR: data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation.

[9] The subtitles are used in this article for convenience only; they are not part of the draft PIPL.

[10] Rights for individuals under the GDPR, see https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights.

[11] The right to data portability allows individuals to obtain and reuse their personal data for their own purposes across different services. It allows them to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without affecting its usability. See https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-data-portability/.

[12] GDPR, Article 6(1).

[13] GDPR, Article 3(2).

[14] GDPR, Article 33(1).

[15] GDPR, Article 34(1).

[16] See https://www.itgovernance.co.uk/dpa-and-gdpr-penalties.

  • 相关资讯 More
  • 点击次数: 1000001
    2025 - 12 - 12
    作者:杨秀芸近日,一个名为“人民咖啡馆”的品牌引发市场关注,其在营造亲切感的同时,也埋下了重大的法律隐患。该案例恰好成为我们剖析《商标法》第十条的典型样本。实践中,许多企业像“人民咖啡馆”一样,对商标注册的合法性认识不足,尤其在商标本身可能触犯禁用条款时仍坚持使用,这种行为隐藏着巨大风险。本文将以“人民咖啡馆”为切入点,分析违反《商标法》第十条的法律风险,为企业品牌建设提供合规参考。 一、商标法第十条的法律性质:不可逾越的“禁用”红线 在深入分析案例前,必须首先理解《商标法》第十条的根本性质。该条款明确列举了不得作为商标使用的标志,通常被称为商标的“禁用条款”。这与仅禁止注册但允许在先使用的第十一条“禁注条款”有着本质区别。  “禁用条款”的立法目的,在于禁止使用可能损害国家尊严、社会公共利益、社会公共秩序、民族团结、宗教信仰等的标志或者违反社会善良风俗、具有其他不良影响的标志。关键在于,它所禁止的标志不仅无法获得注册,其商业使用行为本身就是违法的。这意味着,无论是否提交注册申请,只要一个标志落入第十条的规制范围,其在市场上的任何商业使用均处于违法状态,随时面临监管部门的查处。 二、“人民咖啡馆”触及的具体风险条款 “人民咖啡馆”是一家名为要潮(上海)文化传播有限公司的市场化企业在运营。其名称看似巧妙,实则精准地触及了《商标法》第十条的红线。以下将逐一剖析其与具体款项的关联风险。 (一)主要风险:易被认定为具有“其他不良影响”(第十条第一款第(八)项)《商标法》第十条第一款第八项是一个兜底条款,即“有害于社会主义道德风尚或者有其他不良影响的”标志,不得作为商标使用。“人民”一词在我国语境中具有崇高的政治与公共属性,将其用于咖啡馆等纯商业服务,极易被认定为构成“其他不良影响”,具体表现为: 1、贬损与商业化...
  • 点击次数: 1000011
    2025 - 11 - 07
    作者:张琳一、引言合同是当事人之间的法律,与企业经营成败息息相关,因此加强合同管理对于企业来说至关重要。2015年12月4日最高人民法院发布了19起合同纠纷典型案例,其中有一个案例虽已时隔数年,但仍具有重要的现实指导意义。本文拟结合该案例探讨当今企业如何加强合同管理。 二、案情简介案号:临沂市兰山区人民法院(2013)临兰商初字第3091号民事判决书、山东省临沂市中级人民法院(2014)临商终字第99号 王XX从事贩卖板皮业务,孙YY为个体工商户AA板材厂的经营者,孙ZZ为孙YY之兄。王XX多次与AA板材厂发生买卖夹心皮的业务关系。2012年4月1日,王XX给AA板材厂送夹心皮,孙ZZ当时给王XX出具了出货单,载明:夹心皮,货款236000元。孙YY分别于2012年4月14日和10月17日向王XX名下银行账户存款54000元和10000元。2023年9月17日,王XX给孙YY打电话催要226000元货款,孙YY表示十月一过后安排点。 后王XX以买卖合同纠纷为由将孙YY、孙ZZ诉至一审法院,请求判令孙YY、孙ZZ支付所欠货款226000元及利息。一审法院经审理认为:1、孙ZZ收到王XX价值236000元夹心皮的事实有当事人陈述及王XX提交的出库单一份等证据予以证实。王XX向孙ZZ索要货款,孙ZZ理应支付。但是,王XX提交的证据不足以证明孙ZZ、孙YY系合伙经营或共同经营,故王XX要求孙YY共同偿付欠款的诉讼请求,证据不足,不予支持。2、王XX对孙YY于2012年10月17日金额为10000元的转账凭证无异议。孙ZZ主张已偿付欠款64000元,有其提交的合计金额为64000元的银行个人业务凭证予以证实,王XX虽主张2012年4月14日金额为54000元的转款并非偿付该案所诉欠款,但未提交相关证据予以证实。因此,合计金额为64000元的转款应当在王X...
  • 点击次数: 1000016
    2025 - 10 - 31
    作者:金涟伊《中华人民共和国民法典》第一百二十三条将“地理标志”与商标、著作权等并列为可产生专有权利的知识产权客体。简言之,地理标志是一种可确权、可受益的资产,谁能证明“原产地身份”,谁就能合法获得商业红利。 一、地理标志的渊源 根据国家知识产权局商标局发布的《地理标志的概念和特征》一文,地理标志(Geographical Indications)是现代知识产权制度的重要组成部分,是TRIPs协定所确定的七大类知识产权之一。与商标、专利侧重“个体智慧成果”不同,地理标志保护的是“传统集体智慧”,即因特定自然与人文条件而成就的产品品质与声誉。其概念历经“货源标记—原产地名称—地理标志”的演进,各国保护模式亦呈多样化。 我国对地理标志的系统保护始于 1999 年《原产地域产品保护规定》,后逐步过渡到 2005 年《地理标志产品保护规定》及 2023 年《地理标志产品保护办法》。。 二、核心概念拆解 地理标志是一个法定概念。要深入了解地理标志,首先要分清几个相关概念:地理标志产品、地理标志产品保护、地理标志产品名称、地理标志专用标志。后文将以五常大米为例辅助理解。 1、地理标志产品 地理标志产品是指产自特定地域,所具有的质量、声誉或其他特性本质上取决于该产地的自然因素和人文因素,经审核批准以地理名称进行命名的产品。如产自五常地区、经原国家质量监督检验检疫总局审核公告核准实施原产地域产品保护(即地理标志产品保护)的五常大米产品。根据百度百科记载,五常大米历史可追溯到唐初渤海国时期,受产区独特的地理、气候等因素影响,干物质积累多,直链淀粉含量适中,支链淀粉含量较高,颗粒饱满,质地坚硬,色泽清白透明;饭粒油亮,香味浓郁。 2、地理标志产品保护 地理标志产品保护目前主要由《地理标志产品保护规定》(2...
  • 点击次数: 1000010
    2025 - 10 - 24
    作者:张嘉畅您是否正在经营自主品牌?您是否在网购平台发现类似商品?您是否在投诉、警告过程中,被对方以商品描述为“同款”而抗辩?我相信很多权利人都曾遇到过这种问题,对方明明销售了类似的商品,明明在网店当中使用了您的商标,但因为标注了“XX同款”而被网购平台判定为不是商标性使用,仅为商品描述,进而认定未侵权。针对这种情况,江苏省南京市中级人民法院做出判决,认定在商品描述中使用他人的商标,也可被认定为商标侵权。一、 案件概况原告上海亚朵商业管理(集团)有限公司是国内知名酒店管理公司,经营酒店及相关产品供应链。2021年,原告在24类“织物;纺织品毛巾;浴巾;被子;毛毯;床单;家庭日用纺织品;餐桌用布;毡”等商品上获准注册其主营商标“亚朵”,注册号为49867247号。被告一某某易购集团股份有限公司主营国内中型网购平台,被告二某某易购集团有限公司某某采购中心是被告一的分公司,在被告一的网购平台上注册并经营“某某易购官方旗舰店”。原告发现,被告二在其经营的网店当中,未经原告许可,大量销售侵害原告涉案注册商标专用权的商品,在网店介绍、商品图片中大量使用并突出展示侵权标识。被告在网店当中使用“记忆棉枕头芯沉睡慢回弹护颈椎助睡眠儿童亚朵酒店同款旗舰店1847”“全棉可水洗羽丝绒枕芯柔软枕头亚朵酒店同款家用护颈枕25”及“旗舰店亚朵同款星球枕枕头枕芯沉睡枕护颈枕助睡眠枕头旗”等商品标题。在公证购买后,原告取证到被告二邮寄的商品包裹内有枕头一个,无制造商信息,且快递面单上写有“亚朵双拼枕”字样。综上,原告认为被告的行为构成商标侵权和不正当竞争。被告一、二辩称:1. 被诉侵权商品是枕头,与原告享有商标权的49867247号商标指定商品具有明显差异,不应认定为相同或类似商品,不构成商标侵权。2. 被诉侵权商品的详情页中明确标明自有品牌,“亚朵同款”的描述是指同种款式、平价替代,并非商标性...
× 扫一扫,关注微信公众号
铭盾MiNGDUN   www.mdlaw.cn                                               犀牛云提供企业云服务 
Copyright© 2008 - 2025 铭盾京ICP备14029762号-1                                                                                                                                隐私政策   免责声明       
X
1

QQ设置

3

SKYPE 设置

4

阿里旺旺设置

5

电话号码管理

6

二维码管理

展开