【环球律师事务所】《云计算(2024版)》之中国篇_21页_708kb
报告摘要
Summary of Cloud Computing 2024 - China: Law & Practice
Core Content
This document provides a comprehensive overview of the legal framework and practical considerations for cloud computing in China, authored by Vincent Wang, Xinyao Zhao, and Lewis Chen from Global Law Office. It outlines the key regulations, obligations, and compliance strategies relevant to data privacy, data security, data ownership, and cross-border data transfers.
Main Sections and Key Points
1. Data Privacy Regulations
-
Relevant Laws:
- Cyber Security Law (CSL)
- Data Security Law (DSL)
- Personal Information Protection Law (PIPL)
-
Legal Basis for Processing:
- Consent is the primary legal basis for processing personal data.
- Separate consent is required for specific activities such as processing sensitive data, cross-border transfers, and third-party sharing.
- Exceptional scenarios allow for processing without consent, such as fulfilling contracts, managing HR, responding to public health incidents, and processing data lawfully disclosed.
-
Obligations of Data Controllers and Processors:
- Data Controllers (cloud tenants/platform users) are responsible for ensuring lawful, transparent, and secure processing of personal data.
- Data Processors (cloud service providers) must comply with instructions, assist in fulfilling legal responsibilities, manage subcontractors, and delete or return data upon contract termination.
2. Data Security Measures
-
Security Measures Required by PRC Law:
- Operators must implement technical and organisational measures to ensure data security, integrity, confidentiality, and availability.
- Measures include:
- Prevention of cyber threats (viruses, attacks, intrusions).
- Monitoring and recording network operations and cybersecurity events, with logs retained for at least six months.
- Data classification, backup, and encryption of important data.
-
Encryption Standards:
- Cloud service providers must implement encryption for data in transit and at rest.
- For services supporting government agencies, CII operators, or party offices, encryption must comply with Administration Measures of Commercial Encryption (2023).
-
Access Control:
- Multi-factor authentication is recommended for privileged account access.
- Anti-replay authentication mechanisms (e.g., dynamic passwords) are advised for sensitive data.
- Access control levels vary depending on data sensitivity and business importance.
-
Incident Response and Reporting:
- Cloud service providers must develop and maintain emergency response plans.
- Regular drills and incident tracking, recording, and reporting are required.
- A summary report must be prepared after incident handling and an annual report submitted to regulatory authorities.
3. Data Ownership and Control
-
Data Ownership:
- In cloud agreements, data is generally owned and controlled by the customer unless otherwise agreed.
- The agreement should clearly define ownership and control of data, including data collected, generated, or stored during cloud operations.
-
Data Portability:
- Data subjects have the right to request data portability, allowing them to transfer their data between service providers.
-
Data Retention and Deletion:
- Data controllers must determine the shortest storage period necessary to fulfill processing purposes.
- Data processors must delete or return all personal data upon contract termination or service conclusion.
4. Vendor Management
-
Due Diligence:
- Data controllers must conduct due diligence on cloud service providers to ensure compliance with data protection requirements.
-
Data Protection in Cloud Service Agreements:
- Agreements should include clear terms on data processing, security measures, and compliance obligations.
-
Data Processing Agreements:
- These agreements are necessary to clarify roles and responsibilities between data controllers and processors.
-
Exit Strategies and Data Migration:
- Cloud service providers must support data migration and deletion upon contract termination to ensure data portability and compliance.
5. Data Breach Notification
- Notification Requirements:
- Data controllers must notify data protection authorities and affected individuals immediately upon a data breach.
- They must take remedial actions to mitigate harm.
6. International Data Transfers
-
Legal Framework:
- CSL, DSL, and PIPL provide a general framework for cross-border data transfers.
- The Provisions on Promoting and Regulating Cross-border Data Flows (2024) offer exemptions to facilitate international data transfers.
-
Compliance Mechanisms:
- Data controllers must choose appropriate compliance mechanisms such as:
- Security assessment
- Standard contractual clauses (SCCs)
- Personal information protection certification
- Other conditions specified by law
- Data controllers must choose appropriate compliance mechanisms such as:
-
Notification and Consent:
- Data controllers must notify data subjects and obtain separate consent before transferring personal data abroad, unless an alternative legal basis applies.
7. Compliance and Audits
- Compliance Obligations:
- Cloud service providers and customers must ensure compliance with data protection laws.
- Regular audits and assessments are necessary to verify adherence to legal and technical standards.
Key Information
-
Data Privacy and Security Laws:
- PRC data privacy laws include CSL, DSL, and PIPL, which apply to cloud computing and data processing activities.
-
Consent and Exceptions:
- Consent is the primary legal basis, but exceptions exist for specific scenarios.
- Separate consent is required for sensitive data and cross-border transfers.
-
Penalties for Non-compliance:
- Data controllers and processors can face administrative, civil, and criminal penalties.
- Fines can be up to RMB50 million or 5% of annual turnover.
- Severe violations may lead to business disruption, confiscation of profits, or criminal charges.
-
Cloud Security Standards:
- National standards like GB/T 31167-2023 and GB/T 31168-2023 provide guidance on cloud security measures.
- These include encryption, access control, and incident response protocols.
-
Cross-Border Data Transfer:
- The Provisions on Promoting and Regulating Cross-border Data Flows (2024) simplifies cross-border data transfers.
- Cloud providers must align their security protocols with Chinese standards and support data controllers in compliance.
Authors and Contact
- Vincent Wang: Partner at Global Law Office, Shanghai, specialises in TMT and data protection.
- Xinyao Zhao: Of counsel at Global Law Office, Shanghai, focuses on cyber and data security.
- Lewis Chen: Associate at Global Law Office, Shanghai, with experience in fintech and TMT.
Global Law Office
36th Floor, Shanghai One ICC
No. 999 Middle Huaihai Road, Xuhui District, Shanghai 200031, China
Tel: (8621) 2310 8288
Fax: (8621) 2310 8299
Email: vincentwang@glo.com.cn
Web: www.glo.com.cn
试读结束,高清完整版pdf/doc/ppt,请点下载