2022-09-30-普华永道-China_s_cybersecurity_and_data_legal_developments_and_implications_for_businesses_4页_212kb
报告摘要
China's cybersecurity and data legal developments, as outlined in the October 2022 news flash, emphasize strict enforcement of laws like the Cybersecurity Law, Data Security Law, and Personal Information Protection Law since their implementation in 2017 and 2021. The proposed amendments to the Cybersecurity Law aim to increase penalties for individuals and companies, with potential fines up to RMB 50 million for firms and RMB 1 million for individuals, plus possible blacklisting.
Key obligations for companies include data security measures, such as implementing internal systems, conducting security assessments under the Multi-Level Protection Scheme (MLPS), and backup procedures. Critical information infrastructure (CII) operators face additional requirements, like security background checks and annual inspections. Data localization is crucial; outbound data transfers require security assessments under specific circumstances, or through approved mechanisms like certification or standard contracts.
Recent penalties highlight compliance risks, with non-compliance leading to fines, operational suspensions, and asset freezing. Regulations grant authorities broad powers for investigations and oversight. Businesses must review their data policies and ensure adherence to personal information handling principles, including obtaining consent and protecting individual rights, to avoid repercussions. The proposed amendments are expected to intensify regulatory scrutiny, urging multinational corporations to prioritize compliance in sectors like energy, finance, and critical infrastructure.
试读结束,高清完整版pdf/doc/ppt,请点下载