Back to list

Compliance with Cross-Border Provision of Personal Information under the Personal Information Protection Law

2023-01-20 · Admin

Currently, with economic globalization, the proportion of multinational corporations in the global market is gradually increasing. For operational and management purposes, multinational corporations frequently need to transfer data such as employee information and customer data generated by entities established in various countries across borders to their headquarters, thereby giving rise to the need for compliance in the cross-border provision of personal information. At the same time, with the enactment of domestic regulations such as the Personal Information Protection Law, increasingly stringent requirements have been imposed on the compliance of data processing activities, including the aforementioned cross-border provision of personal information. Therefore, this article compiles the relevant provisions concerning the cross-border provision of personal information by multinational corporations. The table below lists some of the regulations involved in the cross-border provision of personal information, as well as officially published exposure drafts:

Scope of Application

Title

Effective/Amendment/Publication Date

Abbreviation in This Article

Personal Information Protection

Personal Information Protection Law of the People's Republic of China

2021.11.01

PIPL

Personal Information Protection

Regulations on the Administration of Network Data Security (Draft for Comments)

2021.11.14

The Regulations

Security Assessment for Cross-Border Data Transfer by Special Entities

Measures for Security Assessment of Cross-Border Data Transfer

2022.09.01

The Assessment Measures

Prerequisites for Cross-Border Data Transfer by Ordinary Entities

Provisions on Standard Contracts for Cross-Border Transfer of Personal Information (Draft for Comments)

2022.06.30

The Standard Contract

Prerequisites for the Outbound Transfer of Ordinary Subject Data

"Cybersecurity Standards Practice Guide — Security Certification Specification for Cross-Border Processing of Personal InformationV2.0"

2022.12.16

"Certification Specification"

Personal Information Security Impact Assessment

"Information Security Technology — Guide for Personal Information Security Impact Assessment (Draft for Comments)"

2018.06.11

"Assessment Guide"

I. Scope of Application of Laws and Regulations such as the Personal Information Protection Law

Article 3 of the Personal Information Protection Law

This Law shall apply to the processing of the personal information of natural persons within the territory of the People's Republic of China.

This Law shall also apply to the processing of the personal information of natural persons within the territory of the People's Republic of China outside the territory of the People's Republic of China, under any of the following circumstances:

(1) for the purpose of providing products or services to natural persons within the territory;

(2) analyzing or evaluating the behavior of natural persons within the territory; or

(3) other circumstances provided by laws or administrative regulations.

With respect to the compliance of cross-border provision of personal information by multinational corporations, the first issue to be discussed is whether such conduct is subject to the relevant domestic regulations. China's legislation adopts a legislative model of territorial jurisdiction + protective jurisdiction. In terms of territorial jurisdiction, as long as the processing of personal information of natural persons occurs within the territory of the People's Republic of China, regardless of whether the processing entity is a Chinese citizen or a Chinese enterprise, it shall be subject to the Personal Information Protection Law and other regulations. Therefore, when a multinational corporation within the territory provides data to an overseas company, it is subject to the Personal Information Protection Law and other regulations under territorial jurisdiction.

Secondly, with regard to protective jurisdiction, the provisions of Article 3, Paragraph 2 of the Personal Information Protection Law take the purpose and object of the information processing conduct as the criteria for determining protective jurisdiction, which essentially covers all information processing conduct directed at individuals or organizations within the territory of China, encompassing a broad scope. At the same time, the Regulations supplement the circumstance of "involving the processing of important data within the territory," resulting in a trend of further expansion of the scope of application of the Personal Information Protection Law and other regulations. Therefore, if information transmitted or processed within a multinational corporation group includes information of organizations or individuals within the territory of China or other important data involving the territory, it is highly likely to be subject to the regulation of the Personal Information Protection Law and other provisions.

II. Compliance Requirements for Cross-Border Provision of Personal Information

(1) Prerequisites for Cross-Border Provision of Personal Information

1. Obligation of Special Subjects to Declare Security Assessments

Article 40 of the Personal Information Protection Law

Operators of critical information infrastructure and personal information processors that process personal information reaching the volume prescribed by the national cyberspace administration shall store within the territory of the People's Republic of China the personal information collected and generated within the territory of the People's Republic of China. Where it is truly necessary to provide such information abroad, a security assessment organized by the national cyberspace administration shall be passed; where laws, administrative regulations, or provisions of the national cyberspace administration stipulate that a security assessment is not required, such provisions shall prevail.

Pursuant to Article 40 of the Personal Information Protection Law, personal information processing subjects that meet specific conditions and need to provide information abroad shall declare a security assessment to the national cyberspace administration. Meanwhile, the Assessment Measures and other regulations further elaborate on the relevant content of security assessments.

(1) Operators of Critical Information Infrastructure

Article 2 of the Regulations on the Security Protection of Critical Information Infrastructure continues the provisions of the Cybersecurity Law of the People's Republic of China, defining critical information infrastructure as important network facilities and information systems in key industries and sectors such as public communication and information services, energy, transportation, water conservancy, finance, public services, e-government, and national defense science, technology, and industry, as well as other network facilities and information systems that, once damaged, lose functionality, or suffer data leakage, may seriously endanger national security, the national economy and people's livelihoods, or the public interest.

(2) Processing Personal Information Reaching the Prescribed Volume

After the Personal Information Protection Law (PIPL) introduced the requirement for security assessment, the Assessment Measures set forth specific provisions regarding such assessment. Pursuant to Article 4 of the Assessment Measures, a data processor that processes the personal information of more than one million individuals, or that has, since January 1 of the preceding year, cumulatively provided the personal information of 100,000 individuals or the sensitive personal information of 10,000 individuals to overseas recipients, shall, when providing data abroad, submit an application for a data cross-border transfer security assessment to the national cyberspace administration through the provincial-level cyberspace administration of its locality.

(3) Self-Assessment of Data Cross-Border Transfer Risks

According to Article 5 of the Assessment Measures, a data processor shall, within 30 days prior to submitting an application for a data cross-border transfer security assessment, complete a self-assessment of data cross-border transfer risks, and shall submit the self-assessment report together with the application for the security assessment. The self-assessment of data cross-border transfer risks shall include the following:

Principle of Purpose Specification and Minimization

The legality, legitimacy, and necessity of the purpose, scope, and methods of the data cross-border transfer and the processing of data by the overseas recipient.

Risks and Protective Measures for Data Cross-Border Transfer

The scale, scope, categories, and sensitivity of the data to be transferred, and the risks that such data transfer may pose to national security, public interests, or the lawful rights and interests of individuals or organizations.

Whether the responsibilities and obligations undertaken by the overseas recipient, as well as the management and technical measures and capabilities for fulfilling such responsibilities and obligations, can ensure the security of the data during cross-border transfer.

The risks of data being tampered with, destroyed, leaked, lost, transferred, or illegally accessed or used during and after the cross-border transfer, and whether the channels for safeguarding personal information rights are unobstructed.

Contractual Stipulations for Data Cross-Border Transfer

Whether the contract or other legally binding documents (hereinafter collectively referred to as "legal documents") to be entered into with the overseas recipient regarding the data cross-border transfer sufficiently stipulate the responsibilities and obligations for data security protection.

Other Content

Other matters that may affect the security of data cross-border transfer.

(4) Matters Assessed in the Data Cross-Border Transfer Security Assessment

Pursuant to Article 8 of the Assessment Measures, the specific content of the data cross-border transfer security assessment bears similarities to the content of the data cross-border transfer self-assessment, as detailed below:

Principle of Purpose Specification and Data Minimization

Legality, justifiability, and necessity of the purpose, scope, and methods of data export

Risks and Protective Measures for Data Export

The impact of the data security protection policies, laws, and regulations, as well as the cybersecurity environment, of the country or region where the overseas recipient is located on the security of the exported data; whether the data protection level of the overseas recipient meets the requirements of the laws, administrative regulations, and mandatory national standards of the People's Republic of China

The scale, scope, type, and sensitivity of the exported data, and the risks of tampering, destruction, leakage, loss, transfer, or illegal acquisition or misuse during and after the export

Whether data security and personal information rights and interests can be fully and effectively safeguarded

Contractual Stipulations for Data Export

Whether the legal documents to be entered into between the data processor and the overseas recipient adequately stipulate the responsibilities and obligations for data security protection

Other Matters

Compliance with the laws, administrative regulations, and departmental rules of the People's Republic of China

Other matters that the national cyberspace administration deems necessary for assessment

2. Prerequisites for Cross-Border Provision of Personal Information by Non-Special Entities

Article 38 of the Personal Information Protection Law stipulates:

Where a personal information processor truly needs to provide personal information to a party outside the territory of the People's Republic of China due to business or other needs, it shall satisfy one of the following conditions:

(1) Passing the security assessment organized by the national cyberspace administration in accordance with Article 40 of this Law;

(2) Obtaining personal information protection certification from a professional institution in accordance with the provisions of the national cyberspace administration;

(3) Entering into a contract with the overseas recipient in accordance with the standard contract formulated by the national cyberspace administration, stipulating the rights and obligations of both parties; or

(4) Other conditions provided by laws, administrative regulations, or the national cyberspace administration.

Where international treaties or agreements concluded or acceded to by the People's Republic of China stipulate conditions for providing personal information to a party outside the territory of the People's Republic of China, such provisions may be followed.

The personal information processor shall take necessary measures to ensure that the overseas recipient's processing of personal information meets the personal information protection standards set forth in this Law.

For the cross-border transfer of personal information by non-special entities, the Personal Information Protection Law adopts a pre-transaction regulatory model. Unlike special entities, which are required to undergo a security assessment, non-special entities may choose to obtain certification from a professional institution in accordance with the provisions of the national cyberspace administration, or enter into a contract with the overseas recipient in accordance with the standard contract formulated by the national cyberspace administration.

(1) Personal Information Protection Certification

The Certification Specification took effect on December 16, 2022, further elaborating on the relevant content of personal information protection certification. Notably, the Certification Specification explicitly states that an overseas personal information processor may apply for certification through a specialized agency or designated representative established within China, and shall bear legal liability accordingly. This implies that for multinational enterprises with cross-border data transfer needs, personal information protection certification may serve as a significant means to ensure compliance in information processing.

(2) Standard Contract Formulated by the National Cyberspace Administration

The Cyberspace Administration of China published the Standard Contract on June 30, 2022. The Standard Contract stipulates matters such as the purpose and scope of the cross-border transfer of personal information, and the requirement to obtain prior separate consent. The contents of the contract are summarized as follows:

Principle of Purpose Specification and Data Minimization

Article 2(1): The basic information of both parties, the purpose and scope of the cross-border transfer of personal information, obtaining prior separate consent, the responsibilities and obligations of both parties regarding the protection of personal information, etc., as well as clarifying the impact of the laws and regulations of the recipient's country on the protection of personal information with respect to the Standard Contract.

Separate Consent

Article 2(2): The personal information subject has been informed of the name or title and contact information of the overseas recipient, the relevant details in Appendix I "Description of Cross-border Transfer of Personal Information," as well as the methods and procedures for exercising the rights of the personal information subject, and separate consent has been obtained from the personal information subject...

Risk Protection Measures for Cross-border Data Transfer

Article 2(4): Reasonable efforts have been made to ensure that the overseas recipient can fulfill the obligations stipulated in this Contract and has adopted the following technical and administrative measures...

Personal Information Protection Impact Assessment

Article 2(7): A Personal Information Protection Impact Assessment has been conducted in accordance with applicable laws and regulations regarding the proposed activity of providing personal information to the overseas recipient...

Remedial Measures for Data Breach

Article 3(6): In the event of a data breach involving the processed personal information, the following actions shall be taken: ...

It should be noted that the agreement between the data processor and the data subject regarding the data processing contract is crucial for compliance with cross-border personal information transfer requirements. A well-drafted data processing contract can assist enterprises in mitigating most legal risks arising during the process of cross-border personal information transfer. Therefore, in addition to satisfying the provisions of Article 38 of the Personal Information Protection Law, multinational enterprises may also refer to the content of the Standard Contract when entering into contracts in other contexts involving information processing.

(2) Personal Information Security Impact Assessment

Article 55 of the Personal Information Protection Law stipulates:

Under any of the following circumstances, a personal information processor shall, prior to the processing, conduct a personal information protection impact assessment and keep records of the processing: ... (4) providing personal information to a party outside the territory of the People's Republic of China ...

A personal information security impact assessment refers to the process of examining the legality and compliance of personal information processing activities, identifying various risks that may cause harm to the legitimate rights and interests of the data subjects, and evaluating the effectiveness of measures implemented to protect the data subjects. The personal information protection impact assessment report shall be retained for at least three (3) years. Pursuant to Article 55 of the Personal Information Protection Law, if a personal information processor needs to transfer information across borders, in addition to satisfying the prerequisites mentioned above, it shall separately conduct a personal information security impact assessment. Currently, the National Information Security Standardization Technical Committee issued the "Assessment Guidelines" on June 11, 2018, providing reference texts on the implementation and content of such assessments.

(3) Separate Consent

Article 39 of the Personal Information Protection Law

Where a personal information processor provides personal information to a party outside the territory of the People's Republic of China, it shall inform the data subject of the name or title and contact information of the overseas recipient, the purpose and method of processing, the categories of personal information involved, and the methods and procedures for the data subject to exercise the rights provided under this Law against the overseas recipient, and shall obtain the data subject's separate consent.

Separate consent, as defined in Article 73 of the Regulations, means that when carrying out specific personal information processing activities, a data processor shall obtain separate consent for each item of personal information, and may not request consent for multiple items of personal information or multiple processing activities in a single request. Therefore, the previous practice of enterprises using a single separate request page to seek authorization for the processing of all personal information at once no longer meets the requirements of the current Personal Information Protection Law (PIPL).

It is worth noting that Article 13 of the PIPL stipulates exceptions to obtaining personal consent: where the processing of personal information is necessary for the conclusion or performance of a contract to which the individual is a party, or is necessary for the implementation of human resources management in accordance with labor rules and regulations formulated pursuant to law and a collective contract concluded pursuant to law, the personal information processor is not required to obtain the individual's consent. When multinational enterprises transfer employee personal information across borders within the enterprise for purposes such as corporate management, such processing may, to a certain extent, satisfy the requirement of being "necessary for the implementation of human resources management in accordance with labor rules and regulations and a collective contract concluded pursuant to law." Consequently, the question arises as to whether separate consent must be obtained from the individual under such circumstances. Currently, there are no legally binding provisions or interpretations addressing this issue. This article posits that, on the one hand, the "separate consent" requirement under Article 39 of the PIPL imposes a higher standard than the "consent" requirement under Article 13 of the PIPL, and the two are not in a relationship of inclusion and subordination. Therefore, the exemption conditions for "consent" cannot automatically apply to "separate consent." On the other hand, in the context of cross-border information transfer, the protection of personal information should be prioritized. Accordingly, as a matter of prudence, this article recommends that enterprises, under the aforementioned circumstances, mitigate potential legal risks by executing authorization documents such as separate "Consent and Authorization Letters" with employees.