Privacy law will help China flex muscles on digital trade


China’s new privacy law outlines Beijing’s mandate to shape global discussions about data protections, giving the government greater power to scrutinize how companies transfer information abroad.

The Personal Information Protection Law, or PIPL, unveiled Friday imposes rules on how companies can use Chinese citizens’ data and the conditions firms must meet to share information with computer servers or business partners outside the country. That could have a significant impact on international data flows as more countries erect digital trade barriers to protect citizens’ privacy or national security, privacy and legal experts say.

“[Chinese lawmakers] make it no secret that they intend to be a player in this space,” said Omer Tene, chief knowledge officer at the International Association of Privacy Professionals.


The PIPL’s framework is generally similar to that of the European Union’s General Data Protection Regulation, privacy experts say. Both require firms to justify their data collection and provide consumers the right to access or delete their information.

But the Chinese law’s approach to how companies transfer data internationally is more restrictive than the GDPR in certain ways, said David Hale, a shareholder at law firm Brownstein Hyatt Farber Schreck LLP.

“I would be looking at what types of export approval I need to get if I am processing information outside of China,” said Mr. Hale, the former chief privacy officer of brokerage TD Ameritrade.


Tech firms such as Microsoft Corp. and Apple Inc. in recent years increasingly have stored customer data inside China as the Chinese market expanded and the government began unveiling a web of data-security rules. The new privacy statute could push more firms to follow suit after it comes into force on Nov. 1, Mr. Hale said.

Companies that wish to transfer information internationally will have to use state-approved contracts, receive certification of data practices by a state-approved body or undergo a security review by Chinese cyber regulators, said Barbara Li, head of corporate at the Rui Bai Law Firm in Beijing.

Firms deemed to be “critical information infrastructure operators,” along with businesses that handle large amounts of user data, generally are required to store data inside China, Ms. Li said. The GDPR has no such explicit data-localization requirements, which privacy experts say aim to prevent foreign surveillance and allow local authorities greater access to data.


Beijing this month released separate rules giving the state power to define businesses as critical in sectors such as technology, telecommunications and finance based on company networks’ importance to the overall sector or potential damage of a hack. Still, it is unclear what the precise criteria are for getting that designation and, in turn, facing greater potential penalties under the law, said Gabriela Zanfir-Fortuna, director of global privacy at the Future of Privacy Forum, a think tank.

The cybersecurity review of ride-hailing giant Didi Global Inc., during which the state forced app stores to remove Didi products, suggests Beijing may interpret the category broadly, Dr. Zanfir-Fortuna said. Beijing last month sent regulators including security officials and police to the company’s offices to conduct the investigation.

“We don’t tend to look at ride-hailing companies as being such a critical information company,” she said. “This shows us either that it’s arbitrary how this category is thought of, or that, indeed, the Chinese government thinks Didi has some extraordinarily sensitive data.”


Didi didn’t respond to a request for comment.

The Chinese law opens the door for Beijing to strike international deals that enable some data flows, according to a translation by the DigiChina Project, a tech policy center at Stanford University. But unlike the GDPR, which gives power to the European Commission to evaluate other countries’ privacy protections, the Chinese statute doesn’t detail a similar process for establishing that other foreign safeguards meet local standards.

That approach gives the Chinese state more latitude in the long term to negotiate agreements with other governments, said Paul McKenzie, managing partner of the law firm Morrison Foerster’s Shanghai and Beijing offices.


As for countries that curb data flows into China in the name of privacy, the law says, Beijing could reciprocate with digital trade restrictions of its own.

Subscribe to Mint Newsletters


* Enter a valid email

* Thank you for subscribing to our newsletter.


Never miss a story! Stay connected and informed with Mint.
our App Now!!

Stay connected with us on social media platform for instant update click here to join our  Twitter, & Facebook

We are now on Telegram. Click here to join our channel (@TechiUpdate) and stay updated with the latest Technology headlines.


For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TechAzi is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More