Privacy law will help China flex muscles on digital trade

China’s new privacy law outlines Beijing’s mandate to shape global discussions about data protections, giving the government greater power to scrutinize how companies transfer information abroad.
The Personal Information Protection Law, or PIPL, unveiled Friday imposes rules on how companies can use Chinese citizens’ data and the conditions firms must meet to share information with computer servers or business partners outside the country. That could have a significant impact on international data flows as more countries erect digital trade barriers to protect citizens’ privacy or national security, privacy and legal experts say.
“[Chinese lawmakers] make it no secret that they intend to be a player in this space,” said Omer Tene, chief knowledge officer at the International Association of Privacy Professionals.
The PIPL’s framework is generally similar to that of the European Union’s General Data Protection Regulation, privacy experts say. Both require firms to justify their data collection and provide consumers the right to access or delete their information.
But the Chinese law’s approach to how companies transfer data internationally is more restrictive than the GDPR in certain ways, said David Hale, a shareholder at law firm Brownstein Hyatt Farber Schreck LLP.
“I would be looking at what types of export approval I need to get if I am processing information outside of China,” said Mr. Hale, the former chief privacy officer of brokerage TD Ameritrade.
Tech firms such as Microsoft Corp. and Apple Inc. in recent years increasingly have stored customer data inside China as the Chinese market expanded and the government began unveiling a web of data-security rules. The new privacy statute could push more firms to follow suit after it comes into force on Nov. 1, Mr. Hale said.
Companies that wish to transfer information internationally will have to use state-approved contracts, receive certification of data practices by a state-approved body or undergo a security review by Chinese cyber regulators, said Barbara Li, head of corporate at the Rui Bai Law Firm in Beijing.
Firms deemed to be “critical information infrastructure operators,” along with businesses that handle large amounts of user data, generally are required to store data inside China, Ms. Li said. The GDPR has no such explicit data-localization requirements, which privacy experts say aim to prevent foreign surveillance and allow local authorities greater access to data.


