blogAugust 03, 2023

Standard Contract Measures for Personal Information Export Come into Force June

Share:
Standard Contract Measures for Personal Information Export Come into Force June

China’s cybersecurity authority has officially adopted a set of measures that clarify the “standard contract” procedures for companies to transfer personal information overseas as required under the Personal Information Protection Law. These measures will greatly facilitate cross-border data transfer for foreign companies and multinationals handling small amounts of data. We explain the contract requirements for China data transfer.  

Measures stipulating the requirements for using the “standard contract” procedures to conduct cross-border transfer of personal information (PI) came into effect on June 1, 2023. 

The Standard Contract Measures for the Export of Personal Information (“Standard Contract Measures”), which were initially released on February 22 by the Cyberspace Administration of China (CAC)clarify how companies can transfer PI outside of China by signing a “Standard Contract” with the overseas recipient of the data – a much simpler procedure than the other options as it does not require an external audit.  

At the end of May 2023, the CAC released the Guidelines for the Filing of Standard Contracts for Exporting Personal Information Abroad (First Edition) (the “Standard Contract Guidelines”), a supplementary document that acts as a comprehensive guide for companies adopting the Standard Contract mechanism. These guidelines provide additional information for the implementation of the Standard Contract mechanism, including more clarity on legal definitions and further information on how to file materials with the local authorities. 

Under China’s Personal Information Protection Law (PIPL), which came into effect on November 1, 2021, companies are required to undergo certain procedures in order to transfer certain types of data and certain volumes of PI outside of China. The Standard Contract is one of a few different PIPL-compliant mechanisms for CBDT.   

The Standard Contract Measures and Standard Contract Guidelines are the final pieces in the puzzle, explaining in detail which companies are eligible for this mechanism, the requirements for additional procedures – such as self-assessments, and the requisite contents of the contract itself.  

This article is part of our series on the different methods for legally exporting data out of China. Reference our ongoing coverage via the below articles:  

  • The Measures for Data Export Security Assessment, which cover requirements for companies to undergo a security assessment by the CAC, a requisite for companies to export large volumes of data or data that is highly sensitive or important.  
  • The Guidelines for Data Exit Security Assessment and Declaration, which cover how to apply for the CAC security assessment.  
  • The Technical Specifications for Certification of Cross-Border Processing of Personal Information, which provide guidance for multinationals and other entities with a presence in multiple countries to comply with China’s requirements for cross-border personal information processing.
  • The Security Certification Specifications for Cross-Border Processing of Personal Information, which outline the basic principles and PI protection standards for companies and overseas recipients of PI in the cross-border processing of PI and provide a basis for certification agencies to carry out certification of PI processors’ cross-border processing activities.  

Recap: What are the CBDT requirements in Article 38 of the PIPL? 

The three sets of data export security measures released in late 2021 and 2022 concern themselves with clarifying Article 38 of the PIPL, which stipulates that companies must undergo a series of requirements in order to transfer data overseas.  

Specifically, companies must meet one of the following criteria in order to transfer PI over a certain scale overseas:  

  1. Undergo a security review organized by the CAC, except where exempted by relevant laws and regulations.
  2. Undergo PI protection certification by a professional institution in accordance with the regulations of the CAC. 
  3. Sign a contract with a foreign party stipulating the rights and obligations of each party in accordance with standards set by the CAC. 
  4. Meet other conditions set by the CAC or relevant laws and regulations.

Article 38 also states that companies must adopt necessary measures to guarantee that the overseas recipient of the PI also complies with the requirements and regulations for processing and protecting PI stipulated in the PIPL.

“PI” is defined very broadly in the PIPL and is described as “various kinds of information related to identified or identifiable natural persons recorded by electronic or other means, excluding the information processed anonymously”. 

This means PI can include any data points or information that can be used to identify an individual, such as names, phone numbers, and IP addresses. Separately, the PIPL also defines “sensitive” PI, which is subject to stricter protection requirements. Sensitive PI includes (but is not limited to):  

  • Biometric data (such as fingerprints, iris and facial recognition information, and DNA)  
  • Data pertaining to religious beliefs or “specific identities” 
  • Medical history
  • Financial accounts
  • Location and whereabouts
  • Any PI of minors under the age of 14  

FIND BUSINESS SUPPORT

However, it does not include data that has been anonymized or abstract data that doesn’t contain any specific PI on individuals, such as aggregated information. Meanwhile, the “processing” of PI is defined as “the collection, storage, use, processing, transmission, provision, publication, and erasure of PI”.

The Security Assessment Measures and Technical Specifications released in October 2021 and April 2022 clarify requirements for the first two clauses of Article 38 (clauses (1) and (2)), respectively. The new Standard Contract Measures, meanwhile, concern the third clause (Clause (3)), thus almost completing the implementation guidelines for CBDT requirements stipulated in the PIPL.

What is considered “PI export activity”? 

In an important development, the Standard Contract Guidelines define “PI export activity”, something which has been absent from previous documents. It is defined as: 

  1. When PI processors transmit and store PI that has been collected and generated during domestic operations overseas;
  2. When PI collected and generated by PI processors is stored within China, but overseas institutions, organizations, or individuals can inquire, retrieve, download, and export the PI;
  3. Other acts of exporting PI abroad as specified by the CAC. 

This definition confirms the assumption that “PI export” does not only include the direct transfer and storage of PI to overseas locations but also remote access to PI stored in China by a person or entity located outside of China. 

Although this definition provides more clarity for companies in assessing what constitutes PI export, it is nonetheless left somewhat open-ended as it includes an “other” clause that can be left up to interpretation by the authorities. 

Which data operators are eligible to sign a “Standard Contract”? 

The Standard Contract is arguably the simplest route to receiving approval to conduct CBDT, as it does not require an audit by either the CAC or an accredited third-party agency. However, companies going this route will be required to carry out a Personal Information Protection Impact Assessment (PIPIA), as we will see below. 

Due to the simplified procedure, the Standard Contract only applies to relatively small data operators and companies that don’t handle data that is deemed to be of concern to national security and interests.  

Companies that meet all of the following criteria are eligible to use the Standard Contract:  

  1. They are not a critical information infrastructure operator (CIIO). 
  2. They process the PI of fewer than one million people.  
  3. Since January 1 of the previous year, they have transferred the PI of less than 100,000 people out of China.  
  4. Since January 1 of the previous year, they have transferred the “sensitive” PI of less than 10,000 people out of China.  

The final version of the measures has also added a clause stating that PI processors cannot use means such as splitting up the PI that ought to undergo a security review into smaller batches in order to be eligible for the Standard Contract procedure. Under the PIPL, PI operators that exceed the above thresholds for data volume or handle sensitive PI are required to submit to a security review by the CAC before they can transfer it overseas. 

What must be evaluated in a PIPIA? 

Before transferring PI overseas using the Standard Contract method, companies must conduct a PIPIA. According to the Standard Contract Measures, the PIPIA must assess the following matters:  

  1. The legality, legitimacy, and necessity of the purpose, scope, and processing method of the data processor [in China] and the overseas recipient. 
  2. The scale, scope, type, and sensitivity level of the outbound PI being, and the potential risks that the export of the PI can pose to the rights and interests of the PI subjects. 
  3. The responsibilities and obligations that are undertaken by the overseas recipient, and whether the management and technical measures and capabilities for fulfilling these responsibilities and obligations can ensure the security of outbound PI. 
  4. The risk of the PI being tampered with, destroyed, leaked, lost, or illegally used after being exported, and whether the channels for safeguarding the rights and interests of the PI subjects are unobstructed. 
  5. The impact that the PI protection policies and regulations in the country or region where the overseas recipient is located may have on the fulfillment of the Standard Contract. 
  6. Other matters that may affect the security of the outbound PI.  

What must be stipulated in the Standard Contract?  

The Standard Contract that is signed with the overseas recipient must strictly adhere to the template that has been provided along with the Standard Contract Measures. However, the CAC may sometimes adjust this template slightly according to the actual situation. The full template can be found along with the Standard Contract Measures on the CAC website.  

The PI processors can agree on other terms with overseas recipients, but these cannot conflict with the requirements of the Standard Contract template. The export of PI can only be carried out after the Standard Contract takes effect.