China: Data Security and Personal Information
Chapter Seventy-Three
Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."
Pages 444 to 454 of 948
In one line
China finished its regime in 2021 with two statutes: one grading data by how much its loss would hurt the State, and one that reads like the European data protection regulation.
In the wording a student can write in an exam: the Data Security Law of the People's Republic of China, in force from 1 September 2021, establishes a categorical and hierarchical system of data protection under article 21 with a stricter regime for core state data, provides for national security review of data handling activities under article 24 and export controls under article 25, and by article 36 forbids domestic organisations and individuals from providing data stored in China to foreign judicial or law enforcement bodies without the approval of the competent authorities; and the Personal Information Protection Law, in force from 1 November 2021, sets out lawful bases in article 13, individual rights in articles 44 to 50, cross-border transfer requirements in articles 38 to 40 and penalties of up to fifty million yuan or five per cent of the previous year's turnover in article 66.
Why there are three statutes and not one
Because they answer three different questions and China chose to keep them apart.
The Cybersecurity Law asks whether the network is secure. Its unit is the network operator and its concern is the integrity of infrastructure. Chapter 720.
The Data Security Law asks whether data is secure, whoever holds it and whether or not it is personal. Its unit is the data handler and its concern is national security and the public interest.
The Personal Information Protection Law asks whether the individual is protected. Its unit is the personal information handler and its concern is the rights of the person.
India has nothing corresponding to the middle one. There is no Indian statute about non-personal data, and the several committee reports proposing one have not produced legislation. That gap is worth naming in an answer.
The Data Security Law: the grading system
Articles 1 and 2 first, because they set the reach. Article 1 states the purposes: to regulate the handling of data, ensure data security, promote the development and exploitation of data, protect the lawful rights and interests of citizens and organisations, and preserve state sovereignty, security and development interests. Article 2 applies the Law to data handling and security regulation within the mainland territory, and then adds the second paragraph that matters: data handling carried out outside the territory that harms the national security of China, the public interest, or the lawful rights and interests of citizens and organisations is to be pursued for legal responsibility.
Read those two beside the Cybersecurity Law and the change is deliberate. Article 2 of the 2016 Law was purely territorial. Article 2 of this Law claims jurisdiction over conduct abroad by its effects, which is the same technique as section 75 of the Indian Act although the connecting factor differs: India's is a computer resource located in India, China's is harm to Chinese interests. Chapters 720 and 850.
The rest of this chapter
Module one is free. The rest of this chapter comes with the LL.M. Intellectual Property and Information Technology Semester 3 notes.
You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.
Notes + Solved papers: ₹798 Already bought it? Sign in
Or notes only: ₹499
Or solved papers only: ₹499
Free either way: question papers, the syllabus, and module one of every subject.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.