2022-06-30-普华永道-China_issues_rules_on_government_approval_for_outbound_transfer_of_data_-_TMT_newsflash_4页_658kb
报告摘要
China issued the Measures on Security Assessment of Cross-Border Data Transfer (effective from 1 September 2022 and requiring rectification by 1 March 2023) to regulate outbound data transfers under laws like the Cybersecurity Law and Personal Information Protection Law. The measures define "important data" and outline six scenarios requiring government approval, including actions by critical information infrastructure operators, large-scale data transfers, and transfers involving personal or sensitive information. The approval process involves a self-assessment followed by a national CAC security assessment within 45 business days, with the entire process potentially taking over 50 days. Each assessment is valid for two years, and the rules exempt companies with low personal information transfer volumes from the assessment but still require compliance. Key sectors like TMT are urged to evaluate their data export activities to avoid legal penalties, criminal liability, and administrative fines, as China is strengthening data security oversight. The measures harmonize with other cross-border data transfer mechanisms expected from standard contractual clauses and security certification guidelines.
试读结束,高清完整版pdf/doc/ppt,请点下载