• Login
    • Advanced search
    • Title
    • Channel
    • Module
  • Home
  • Industry
    •  

      • Aerospace, Defense, and Government Services
      • Automotive
      • Consumer
      • Diversified Industrials
      • Education
      • Energy and Natural Resources
      • Financial Institutions
    •  

      • Insurance
      • Life Sciences and Health Care
      • Private Capital
      • Real Estate
      • Sports, Media & Entertainment
      • Technology and Telecoms
      • Transport and Logistics
  • Practice
    • Corporate & Finance

      • Banking and Loan Finance
      • Blockchain
      • Business Restructuring and Insolvency
      • Capital Markets
      • Corporate Governance and Public Company Representation
      • Infrastructure, Energy, Resources, and Projects
      • Leveraged and Acquisition Finance
      • Mergers and Acquisitions
      • Pensions
      • Private Equity, Venture Capital and Investment Funds
      • Real Estate
      • Real Estate Investment Trusts (REITs)
      • Tax
      • Transfer Pricing
    • Global Regulatory

      • Administrative and Public Law
      • Antitrust and Competition
      • Communications, Internet, and Media
      • Education
      • Energy Regulatory
      • Environment and Natural Resources
      • Financial Services
      • Food Law
      • Gaming Law
      • Government Contracts and Public Procurement
      • Government Relations and Public Affairs
      • Health
      • Immigration
      • International Trade and Investment
      • Medical Device and Technology Regulatory
      • Pharmaceuticals and Biotechnology Regulatory
      • Privacy and Cybersecurity
      • Space and Satellite
      • Strategic Operations, Agreements and Regulation
      • Transportation Regulatory
    • Intellectual Property

      • Copyright
      • Designs
      • Domain Names
      • IP and Technology Transactions
      • IP Enforcement
      • Patents
      • Trade Secrets and Confidential Know-how
      • Trademarks and Brands
      • Unfair Competition
    • Litigation, Arbitration, and Employment

      • Business and Human Rights
      • Construction and Engineering
      • Corporate and Securities Litigation
      • Employment
      • International Arbitration
      • Investigations, White Collar, and Fraud
      • Products Law
      • Risks, Disputes, and Litigation
  • Comparative guides
  • Engage Premium
  • Login
  • Register
Hogan Lovells Engage 5.6.12
      • Title
      • Channel
      • Module
    • Hit ENTER to search in content
    • Advanced search
    • Login
  • Home
  • Industry
    •  

      • Aerospace, Defense, and Government Services
      • Automotive
      • Consumer
      • Diversified Industrials
      • Education
      • Energy and Natural Resources
      • Financial Institutions
    •  

      • Insurance
      • Life Sciences and Health Care
      • Private Capital
      • Real Estate
      • Sports, Media & Entertainment
      • Technology and Telecoms
      • Transport and Logistics
  • Practice
    • Corporate & Finance

      • Banking and Loan Finance
      • Blockchain
      • Business Restructuring and Insolvency
      • Capital Markets
      • Corporate Governance and Public Company Representation
      • Infrastructure, Energy, Resources, and Projects
      • Leveraged and Acquisition Finance
      • Mergers and Acquisitions
      • Pensions
      • Private Equity, Venture Capital and Investment Funds
      • Real Estate
      • Real Estate Investment Trusts (REITs)
      • Tax
      • Transfer Pricing
    • Global Regulatory

      • Administrative and Public Law
      • Antitrust and Competition
      • Communications, Internet, and Media
      • Education
      • Energy Regulatory
      • Environment and Natural Resources
      • Financial Services
      • Food Law
      • Gaming Law
      • Government Contracts and Public Procurement
      • Government Relations and Public Affairs
      • Health
      • Immigration
      • International Trade and Investment
      • Medical Device and Technology Regulatory
      • Pharmaceuticals and Biotechnology Regulatory
      • Privacy and Cybersecurity
      • Space and Satellite
      • Strategic Operations, Agreements and Regulation
      • Transportation Regulatory
    • Intellectual Property

      • Copyright
      • Designs
      • Domain Names
      • IP and Technology Transactions
      • IP Enforcement
      • Patents
      • Trade Secrets and Confidential Know-how
      • Trademarks and Brands
      • Unfair Competition
    • Litigation, Arbitration, and Employment

      • Business and Human Rights
      • Construction and Engineering
      • Corporate and Securities Litigation
      • Employment
      • International Arbitration
      • Investigations, White Collar, and Fraud
      • Products Law
      • Risks, Disputes, and Litigation
  • Comparative guides
  • Engage Premium
  • Login
  • Register
  1. News
  2. Data protection enforcement progresses in China

Data protection enforcement progresses in China

09 May 2022
    • Share by email
    • Share on
    • Twitter
    • LinkedIn
    • Get link
    • Get QR Code
    • Download
    • Print

Six months have now passed since China's Personal Information Protection Law (PIPL) became effective on November 1, 2021. As noted below, Chinese authorities have recently stepped up enforcement actions relative to PIPL.

China’s PIPL resembles the EU General Data Protection Regulation (GDPR) in many ways. For example, the PIPL tracks GDPR's extraterritorial application in cases where data processing activities outside China are (i) for the purpose of providing services or products to individuals in China, or (ii) analyzing or evaluating the activities of individuals in China. But the PIPL also endorses a unique Chinese perspective on such issues as separate consent requirements, data localization, and cross-border transfer of personal data. Our previous summary of PIPL is available here: The journey has just begun: China passes its Personal Information Protection Law.

Many institutions outside China have been working to evaluate PIPL's impact on their operations related to China. For organizations that have a subsidiary or representative office in China, the compliance efforts often include (but are not limited to) conducting a data mapping exercise and gap analysis, and developing privacy notices and consent forms directed at employees, visiting scholars, students, and website users. For organizations that have no presence in China, the PIPL’s extraterritorial effect may still mandate action, such as appropriate consent mechanisms embedded in websites and mobile applications (including WeChat mini programs) targeting China, and appropriate data protection and cybersecurity clauses in agreements with Chinese parties. All organizations are closely monitoring prospective regulatory developments in China which are expected to shed more light on the specific requirements for data localization and cross-border transfer of personal data.   

Over the past six months, Chinese authorities have stepped up their enforcement actions. Thus far, the enforcement has centered on unlawful data collection and data leakage. Neither PIPL’s data exportation restrictions nor its extraterritorial reach has been publicly enforced at this time.     

  • Emerging civil cases with regards to illegal data collection. Beginning in 2021, several individual users sued prominent Internet platforms in China for mishandling their personal information. In one case, the Hangzhou Internet Court ruled that a vague statement in an organization’s privacy policy did not meet the requirement of separate consent for processing of sensitive personal information.1 In January 2022, the Shenzhen Intermediate Court ruled that Tencent’s short video app, Weishi App, illegally obtained personal information from the WeChat App without effective consent of the plaintiff data subject in order to provide the “Add WeChat friends to Weishi App” function, although the plaintiff ultimately failed to prove damages.2    
  • Strengthened governance over data protection in mobile applications.  Since 2020, the Cyberspace Administration of China (CAC), Ministry of Industry and Information Technology (MIIT), and Public Security Bureau (PSB) have exercised strong supervision over data protection within mobile apps, focusing on over-collection of personal information; the unlawful usage of targeted push function; and ineffective channels for data subjects to exercise rights. In 2021, Chinese authorities required numerous mobile apps to rectify their procedures –  several English training apps and pre-education apps have been issued violations, including Offcn, a famous Chinese vocational education and training company.3

These enforcement actions demonstrate that authorities are focused on Chinese websites and apps, including consent and separate consent mechanisms, over-collection of personal information, and protection of data subject rights. In the education industry, especially online education, the Ministry of Education has recently emphasized data protection via several circulars issued in 2021.4 As online education programs surge with both Chinese and non-Chinese providers entering the market, the education industry is poised for data protection enforcement in China. 

The PIPL features many vague provisions. Accordingly, organizations continue to await China’s issuance of rules and regulations that clarify PIPL’s scope and practical effect on operations that touch China. Meanwhile, preparation is key. The recent enforcement actions suggest that organizations should give priority to developing tailored consent mechanisms and mitigating risk through effective data protection and cybersecurity clauses in agreements with Chinese parties. 

Next steps

Our team is guiding many organizations as they develop and implement PIPL compliance strategies. Please contact us at any point.

 

Authored by Sherry Gong, Tong Zhu, and William Ferreira.

 

References
1 https://mp.weixin.qq.com/s/MArtUWlTnEM8PAL_Ji0ceg.
2 https://mp.weixin.qq.com/s/z_Q_4HJ2t5unreH-28DG7A.
3 Examples can be found in a Notice of the List of Apps Infringing Users’ Rights and Interests (miit.gov.cn)
4 For example, the Circular of the Ministry of Education on Strengthening Information Technology in Education Management in the New Era, and the Notice on the Change of Requirement for Online Training Institution from Record-Filing to Approval
Contacts
William Ferreira
Partner
Washington, D.C.
Sherry Gong
Partner
Beijing
Tong Zhu
Associate
Beijing
Related Materials
Sanctions Navigator

Launching our new Sanctions Navigator: Russia Sanctions

China-flag

The journey has just begun: China passes its Personal Information Protection Law

China-flag

China’s first personal information protection law in the home stretch

China-flag

China's draft Personal Information Protection Law released for public comment

Keywords PIPL, Personal Information Protection Law, The Personal Information Protection Law, China, china data protection, Data Security, Data Security Law, Data Security Law of the People's Republic of China, Cybersecurity Law, China's National People's Congress, National People's Congress, National People's Congress of China
Languages English
Topics Accreditation and State Licensure, Distance Education, Education Regulatory Compliance and Investigations, Elementary and Secondary Education, Federal Student Financial Aid, International Education Programs
Countries People's Republic of China
Delete Comment ?

Are you sure want to delete comment ?

Get link
Embed
Share by email
Get QR Code

Scan this QR Code to share this content