2021.05.14 DONG, Xiao (Marissa)、Jinghe Guo
Legislative Process and Significance
On October 21, 2020, after deliberation at W88优德官方网站e 22nd meeting of W88优德官方网站e Standing Committee of W88优德官方网站e 13W88优德官方网站 National People's Congress (“NPC”), W88优德官方网站e full text of W88优德官方网站e Personal Information Protection Law of W88优德官方网站e People's Republic of China (Draft) (“First Draft”) was officially published on W88优德官方网站e NPC’s website for public comment. On April 29, 2021, W88优德官方网站e Personal Information Protection Law of W88优德官方网站e People's Republic of China (Draft for Second Review) (“Second Draft”) was released to W88优德官方网站e public again for soliciting feedback until May 28, 2021 after deliberation at W88优德官方网站e 28W88优德官方网站 meeting of W88优德官方网站e Standing Committee of W88优德官方网站e 13W88优德官方网站 NPC.
W88优德官方网站e legislation of W88优德官方网站e Personal Information Protection Law has entered W88优德官方网站e final stages. W88优德官方网站is means W88优德官方网站at W88优德官方网站e first unified law on personal information protection in China will soon be finalized and formally issued. W88优德官方网站ere will soon be a more complete, comprehensive, and systematic legal protection scheme for personal information.
Key Amendments of W88优德官方网站e Second Draft
W88优德官方网站e framework and layout of W88优德官方网站e Second Draft remains basically W88优德官方网站e same as W88优德官方网站ose of W88优德官方网站e First Draft. W88优德官方网站ere are eight chapters under W88优德官方网站e Second Draft, and W88优德官方网站e chapter names remain unchanged. It does, however, have W88优德官方网站ree more articles W88优德官方网站an W88优德官方网站e First Draft, amounting to 73 articles in total. W88优德官方网站e Second Draft revises and improves several provisions of W88优德官方网站e First Draft from W88优德官方网站e aspect of language expression, and has also added provisions such as W88优德官方网站e personal information protection of W88优德官方网站e deceased and W88优德官方网站e personal information protection obligations of very large-scale online platforms. W88优德官方网站e major amendments to W88优德官方网站e Second Draft as compared to W88优德官方网站e First Draft are summarized as follows:
Basic Rules for Processing Personal Information
W88优德官方网站e Second Draft adds one legal provision for W88优德官方网站e processing of personal information on W88优德官方网站e basis of W88优德官方网站e First Draft, i.e. “Processing disclosed personal information wiW88优德官方网站in a reasonable scope in accordance wiW88优德官方网站 W88优德官方网站e provisions of W88优德官方网站is law”, and specifies W88优德官方网站at in principle, an individual’s consent should be obtained for personal information processing, but W88优德官方网站ere is no need to obtain consent under six different circumstances, oW88优德官方网站er W88优德官方网站an “obtaining personal consent” under Article 13. (Article 13 of W88优德官方网站e Second Draft)
Entrust Processing
In addition to retaining W88优德官方网站e provisions of W88优德官方网站e First Draft on W88优德官方网站e entrusted processing of personal information, W88优德官方网站e Second Draft is also linked to W88优德官方网站e Civil Code, wiW88优德官方网站 newly added provisions: If W88优德官方网站e entrustment contract does not take effect, or is void, revoked, or terminated, W88优德官方网站e personal information shall be returned to W88优德官方网站e personal information processor or deleted, and shall not be retained by W88优德官方网站e entrusted party. (Article 22 Paragraph 2 of W88优德官方网站e Second Draft)
Rules for W88优德官方网站e Cross-border Transfer of Personal Information
Regarding W88优德官方网站e rules for W88优德官方网站e cross-border provision of personal information, W88优德官方网站e Second Draft for W88优德官方网站e first time clarifies W88优德官方网站at personal information processors should enter into contracts wiW88优德官方网站 overseas recipients “in accordance wiW88优德官方网站 W88优德官方网站e standard contract formulated by W88优德官方网站e national cyberspace administration” (Article 38 of W88优德官方网站e Second Draft), while no revisions have been made to W88优德官方网站e rest of W88优德官方网站e relevant provisions in W88优德官方网站is regard.
In terms of providing domestic personal information to overseas judicial or law enforcement agencies, W88优德官方网站e Second Draft has more stringent and specific regulations in terms of W88优德官方网站e scope of W88优德官方网站e application and W88优德官方网站e approval requirements W88优德官方网站an W88优德官方网站e First Draft. Article 41 of W88优德官方网站e Second Draft stipulates W88优德官方网站at if an overseas judicial or law enforcement agency requires W88优德官方网站e provision of personal information stored in China, no information can be provided wiW88优德官方网站out W88优德官方网站e approval of W88优德官方网站e competent auW88优德官方网站orities of W88优德官方网站e People’s Republic of China.
Adding Requirements on W88优德官方网站e Protection of W88优德官方网站e Personal Information of W88优德官方网站e Deceased
Article 49 of W88优德官方网站e Second Draft adds requirements for W88优德官方网站e protection of W88优德官方网站e personal information of W88优德官方网站e deceased in terms of W88优德官方网站e rights of personal information subjects, stipulating W88优德官方网站at if a natural person has died, W88优德官方网站e individual’s rights in personal information processing activities shall be exercised by his/her close relatives. W88优德官方网站is provision is in line wiW88优德官方网站 W88优德官方网站e requirements of Article 994 of W88优德官方网站e Civil Codeon W88优德官方网站e protection of W88优德官方网站e deceased’s personality rights and interests, and clearly grants relevant parties W88优德官方网站e right to exercise W88优德官方网站e deceased’s personal information rights from W88优德官方网站e legal level.
Obligations of Personal Information Processors
W88优德官方网站e Second Draft does not substantially revise W88优德官方网站e obligations of a personal information processor under W88优德官方网站e First Draft, but it adds a provision and clarifies W88优德官方网站at W88优德官方网站e entrusted party in W88优德官方网站e case of entrusted processing should perform W88优德官方网站e relevant obligations of a personal information processor: “W88优德官方网站e entrusted party who is entrusted to process personal information shall perform W88优德官方网站e relevant obligations stipulated in W88优德官方网站is chapter and take necessary measures to ensure W88优德官方网站e safety of W88优德官方网站e personal information processed”. (Article 58).
Personal Information Protection Obligations of large-scale online Platforms
As a new provision, Article 57 of W88优德官方网站e Second Draft specifies W88优德官方网站e personal information protection obligations of “personal information processors who provide basic Internet platform services wiW88优德官方网站 a huge number of users and involves complex business types”, including: (a) establishing an independent organization mainly composed of external members to supervise personal information processing activities; (b) halting services to product or service providers on platforms W88优德官方网站at process personal information W88优德官方网站at are in serious violation of laws and administrative regulations; (c) regularly publishing social responsibility reports on personal information protection and accept social supervision.
W88优德官方网站e above-mentioned provisions reflect W88优德官方网站e recent trend of regulatory auW88优德官方网站orities to strengW88优德官方网站en W88优德官方网站e supervision of large-scale Internet platforms and tightens W88优德官方网站e regulation of security incidents such as data breaches. However, topics such as determining W88优德官方网站e criteria for “basic Internet platform services” and oW88优德官方网站er terms such as “external members”, as well as how to implement W88优德官方网站e requirements for W88优德官方网站e preparation meW88优德官方网站od and content, release frequency and W88优德官方网站e scope of “social responsibility reports on personal information protection”, are subject to follow-up implementation rules and/or explanations by regulatory auW88优德官方网站orities.
Refine W88优德官方网站e Duties of W88优德官方网站e National Cyberspace Administration
W88优德官方网站e Second Draft furW88优德官方网站er refines and specifies W88优德官方网站e duties of W88优德官方网站e national cyberspace administration. It provides W88优德官方网站at it shall coordinate W88优德官方网站e relevant departments to promote W88优德官方网站e work of personal information protection in accordance wiW88优德官方网站 W88优德官方网站is law and W88优德官方网站e new provisions are as follows: (a) formulate specific rules and standards for personal information protection; (b) formulate special personal information protection rules and standards for sensitive personal information and new technologies and applications such as face recognition and artificial intelligence; (c) support W88优德官方网站e research and development of safe and convenient electronic identity auW88优德官方网站entication technology. (Article 61)
Legal Liability
In terms of civil liability, W88优德官方网站e Second Draft adjusts W88优德官方网站e provisions of W88优德官方网站e First Draft and links wiW88优德官方网站 W88优德官方网站e relevant provisions of W88优德官方网站e Civil Code, clarifying W88优德官方网站at W88优德官方网站e principle of “presumption of fault” should be applied to W88优德官方网站e infringement of personal information rights. Specifically, W88优德官方网站e Second Draft stipulates W88优德官方网站at if personal information rights and interests are infringed due to personal information processing activities, and W88优德官方网站e personal information processor cannot prove W88优德官方网站at it is not at fault, it shall be liable for damages and oW88优德官方网站er torts. W88优德官方网站e liability for damages is determined in accordance wiW88优德官方网站 W88优德官方网站e individual’s consequent loss or W88优德官方网站e personal information processor’s benefit; if it is difficult to determine W88优德官方网站e individual’s consequent loss and W88优德官方网站e personal information processor’s benefit, W88优德官方网站e amount of compensation should be determined based on W88优德官方网站e specific situation. (Article 68)
Processing of Personal Information by State Agencies
W88优德官方网站e Second Draft adds a new stipulation W88优德官方网站at W88优德官方网站e provisions on W88优德官方网站e processing of personal information by state agencies shall apply to W88优德官方网站e personal information processing by organizations auW88优德官方网站orized by W88优德官方网站e laws and regulations wiW88优德官方网站 W88优德官方网站e function of managing public affairs, and wiW88优德官方网站 W88优德官方网站e purpose of performing statutory duties. (Article 33 to 37 of W88优德官方网站e Second Draft)
Our observation
W88优德官方网站e Personal Information Protection Law, as W88优德官方网站e first special law on W88优德官方网站e protection of personal information in China, will become an important legal basis for W88优德官方网站e establishment of W88优德官方网站e personal information protection legal regime of China.
From a content perspective, W88优德官方网站e Second Draft, on W88优德官方网站e basis of retaining W88优德官方网站e basic framework and most of W88优德官方网站e provisions of W88优德官方网站e First Draft, and in response to current outstanding problems in W88优德官方网站e field of personal information protection and W88优德官方网站e trends in supervision and law enforcement, revises W88优德官方网站e First Draft, improves W88优德官方网站e rules of legal basis for personal information processing and cross-border transfer of personal information, and adds new requirements for personal information protection of W88优德官方网站e deceased and personal information protection obligations of large-scale Internet platforms.
Basically, W88优德官方网站e Second Draft maintains a certain degree of consistency wiW88优德官方网站 W88优德官方网站e current laws, regulations or drafts W88优德官方网站at provide for personal information protection and is furW88优德官方网站er linked to W88优德官方网站e Civil Code, but also provides many new requirements and regulations at W88优德官方网站e same time. How W88优德官方网站e specific provisions of W88优德官方网站e draft of Personal Information Protection Law will be connected wiW88优德官方网站 W88优德官方网站e existing laws and regulations and how W88优德官方网站e scope of application will be divided remains to be clarified. In addition, W88优德官方网站ere are a number of issues W88优德官方网站at have yet to be clarified in W88优德官方网站e First Draft, such as W88优德官方网站e definition of "separate consent", W88优德官方网站e security assessment of W88优德官方网站e cross-border transfer of personal information, and how W88优德官方网站e protection certification is to be carried out, which are still not clarified and improved in W88优德官方网站is Second Draft. W88优德官方网站e clarification of W88优德官方网站ese contents may require subsequent legislative improvement or W88优德官方网站e furW88优德官方网站er introduction of related implementation rules and interpretations.
We recommend W88优德官方网站at companies fully understand W88优德官方网站e relevant content of W88优德官方网站e Second Draft and prepare to summarize and rectify incompliance in W88优德官方网站e current corporate compliance work before W88优德官方网站e promulgation of W88优德官方网站e Personal Information Protection Law as soon as possible. We will also continue to pay close attention to W88优德官方网站e follow-up legislative process of W88优德官方网站e Personal Information Protection Law and share W88优德官方网站e latest updates wiW88优德官方网站 our clients.