China’s New Data Laws Come With Many Unanswered Questions

Share post:

China’s upcoming data protection law, which will enter into force on September 1, requires all companies in China to categorize the data they process into a series of classifications and governs how the data is stored and shared with other parties.

Important categories are “national core data” and “important data,” for which mishandling could result in a fine of up to 10 million yuan or even a lawsuit. However, the government has not yet given definitions for this or other details about what type of data falls into which category.

For example, the law states that only companies wishing to transfer “important data” abroad must carry out a security assessment each time.

“There is no list, there is no annex, there are no examples so we’re a little bit in the dark here,” says Nicolas Bahmanyar, a senior consultant at the Beijing law firm LEAF.

China will also introduce new provisions on September 1 to protect “critical information infrastructure,” but experts say definitions of such infrastructure remain vague and unclear.

Industry-specific regulators, who are also expected to provide a more detailed framework, have not yet done so.

The new rules mark Beijing’s growing concern about the amount of data that private companies have received and whether such information could be exposed to attack and abuse, particularly by other countries.

China’s 2017 cybersecurity law mandates firms to store data in China and agree to security checks, and will be supplemented by new rules on the handling of personal data on November 1.

One landmark case is that of Didi Global, China’s powerful cyberspace regulator, which launched an investigation into data security risks in July, just two days after the company’s New York debut.

The Cyberspace Administration of China is also investigating online recruitment platform Boss Zhipin, owned by Kanzhun, and two commercial freight platforms of the Full Truck Alliance for alleged national data security risks.

For more information, read the original story in Reuters.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday, April 26, 2024

This episode features a discussion on the latest in the Change Healthcare ransomware attack, a vulnerability in an abandoned Apache open source project, the next step in Canada's proposed critical infrastructure cybersecurity law and the future

Cyber Security Today, April 26, 2024 – Patch warnings for Cisco ASA gateways and a WordPress plugin

This episode reports on the malicious plugin worm that refuses to die

Cyber Security Today, April 24, 2024 – Good news/bad news in Mandiant report, UnitedHealth admits paying a ransomware gang, and more

This episode reports on the danger of using expired open-source packages, a tool used by a Russian hacking group and passw

Google Play introduces new biometric verification with a user warning

Google has recently announced updates to the biometric verification process for Google Play purchases, aiming to bolster security...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways