网易首页 > 网易号 > 正文 申请入驻

Q&A on the Standard Contract for Transferring PI Abroad

0
分享至

The Measures for the Standard Contract for Cross-border Transfer of Personal Information (hereinafter the "Standard Contract Measures") has been officially promulgated on February 24, 2023, and will come into force on June 1, 2023[1]. In light of this, we have prepared the following ten Q&As for enterprises to learn how they could transfer personal information across borders legally through entering into a standard contract.

Q1How should data be transferred legally across borders?

According to the currently applicable laws and regulations, there are three main approaches:

(1)Passing a security assessment organized by the Cyberspace Administration of China ("CAC”).

(2)Acquiring a personal information protection certification at a specialized institution in accordance with the provisions issued by the CAC.

(3)Entering into a contract with the overseas recipient in accordance with the standard contract formulated by the CAC, agreeing on both parties' rights and obligations.

Q2In which scenarios can a standard contract be concluded for the Cross-border transfer of data?

According to the Standard Contract Measures, the scope of information processor permitted to enter into the standard contract to transfer data across borders is narrow, since they must fulfill all following conditions simultaneously:

(1)it is not a critical information infrastructure operator;

(2)it processes the personal information of less than 1 million individuals;

(3)it has cumulatively transferred abroad the personal information of less than 100,000 individuals since January 1 of the previous year; and

(4)it has cumulatively transferred abroad the sensitive personal information of less than 10,000 individuals since January 1 of the previous year.

In addition, the Standard Contract Measures also explicitly stipulated that a personal information processor shall not use methods such as quantity splitting of the personal information that is required by law to undergo the cross-border security assessment.

Q3What is the procedure needed for entering into a standard contract?

Prior to entering into the standard contract, enterprises shall conduct a personal information protection impact assessment. The contents of such assessment shall mainly include: the legality, legitimacy, and necessity of cross-border data transfer; the volume, scope, category, and sensitivity of personal information to be transferred abroad and the risks that may be caused; whether the foreign recipient can ensure the security of the personal information to be transferred abroad, etc.

While the personal information processor may initiate cross-border transfer once a standard contract is executed and becomes effective, it shall fill the standard contract and the personal information protection impact assessment report with the cyberspace administration at the provincial level within 10 working days. It is worth noting that the Standard Contract Measures did not provide for a substantive review of the filed materials by cyberspace administrations, nor does it make the filing of contracts a precondition for cross-border data transfer.

Q4What are the requirements on the contract itself?

(1)According to Article 6 of the Standard Contract Measures, the standard contract shall be concluded in strict accordance with the annexed Standard Contract for Cross-border Transfer of Personal Information (the “Standard Contract Template”, and the CAC may adjust the annex based on actual circumstances. Therefore, we understand that enterprises shall enter into standard contracts in strict accordance with the Standard Contract Template which shall not be amended at their will. However, the parties may agree upon other terms not in conflict with the text of the Standard Contract Template.

(2)Impact of local policies and regulations on personal information protection in foreign countries: the Standard Contract Template takes a more liberal approach, only requiring the personal information processor and the foreign recipient to warrant that they have exercised reasonable care when entering into the contract and is not aware of personal information protection policies and regulations in the foreign recipient’s country or region that would have an impact on the foreign recipient’s performance of its obligations under the contract.

(3)Dispute Resolution: If any dispute arises during the performance of the standard contract, the parties to the contract may choose to bring a lawsuit in a Chinese court or choose an arbitration institution of one of the member states of the New York Convention to settle the dispute. There are no requirements on the seat of arbitration. Such an arbitration option provided in the standard contract may potentially lead to overseas data recipients more willing to enter into the standard contract.

Q5What is the third-party beneficiary under the standard contract?

The Standard Contract enhances the protection of personal information subjects by endowing them with the status of "third-party beneficiary". The specific process is as follows:

(1)The data processor grants the personal information subject the right to become a "third party beneficiary" by informing the subject of the same in accordance with Section 2 (iv) of the Standard Contract Template.

(2)The Standard Contract Template stipulates several obligations (such as its Section 3) that the personal information processor and/or the foreign recipient shall bear to the personal information subject as well as providing for the rights of the subject of personal information (Section 5).

(3)Section 6, item 3 of the Standard Contract Template specifies the approaches that the subject of personal information can realize his rights as a "third-party beneficiary" through either litigation or filing a complaint to the regulatory authority.

(4)Either party shall bear civil liabilities if it infringes upon the rights of the personal information subject due to a violation of the standard contract. Should both parties bear joint and several liabilities in accordance with law, the personal information subject shall have the right to request either party or both parties to bear the liabilities.

Q6In what aspects might the cyberspace administrations supervise a standard contract and the parties thereto?

Section 3, item 13 of the Standard Contract Template provides the obligation of the foreign recipient, in which the foreign recipient shall agree to be subject to supervision by the PRC regulatory authorities during an enforcement procedure related to supervising the implementation of the contract, including but not limited to responding to inquiries, following the actions taken or decisions made by the Regulatory Authority, and providing written confirmation that necessary measures have been taken, etc.

In addition, the Standard Contract Template also prescribes that the personal information processor shall cooperate with regulatory measures. On the one hand, the Personal Information Protection Law applies to personal information processors that process personal information domestically and shall be subject to the supervision of regulatory authorities in accordance with the law. On the other hand, according to Section 2 (vii) of the Standard Contract Template, the personal information processor shall reply to inquiries from the Regulatory Authority about the foreign recipient’s processing activities.

Q7Under what circumstances can cross-border data transfer be suspended or a standard contract be rescinded?

According to Section 7, item 1 of the Standard Contract Template, if the foreign recipient breaches the obligations specified in the contract or the foreign recipient is unable to perform the contract due to a change in the policies and regulations on personal information protection in the foreign recipient’s country or region (including an amendment to the laws or adoption of compulsory measures in the foreign recipient’s country or region), the personal information processor may suspend the provision of personal information to the foreign recipient until the breach is corrected or the contract is terminated.

In addition, the Standard Contract Template provides some circumstances in which the personal information processor or both parties are entitled to terminate the contract:

(1)Where the personal information processor has suspended the provision of personal information to the foreign recipient for more than one month in accordance with Section 7, Item 1 - both parties may terminate the contract.

(2)By following the standard contract, the foreign recipient will violate the laws and regulations of its own country or region- both parties may terminate the contract.

(3)The foreign recipient seriously or persistently breaches the obligations under the contract - only the personal information processor may terminate the contract.

(4)The foreign recipient or the personal information processor has breached this contract pursuant to a final decision of a competent court or the regulatory body supervising the foreign recipient - both parties may terminate the contract.

Q8Does the standard contract have a validity period? Under what circumstances should the contract be re-entered into?

Since there is no provision on the term of validity in the Standard Contract Measures or the Standard Contract Template, we understand that both parties are free to stipulate the term of validity. However, if any of the following circumstances occur during the validity period, the personal information processor shall conduct the following formalities again: a) conduct a personal information protection impact assessment, b) supplement or re-sign the contract, and c) conduct relevant record-filing formalities:

(1)the purpose, scope, category, sensitivity, method, and storage location of personal information transferred abroad, or the purpose and method of personal information processing by the foreign recipient has changed, or the retention period of personal information located abroad has been extended;

(2)the personal information rights and interests may be affected by the changes in the policies and regulations on personal information protection in the country or region where the foreign recipient is located; or

(3)other circumstances that may affect personal information rights and interests.

Q9Does the Standard Contract Measures provide for a “grace period” similar to the Measures for the Security Assessment of Cross-border Data Transfer?

Yes. The Standard Contract Measures will enter into force on June 1, 2023. For noncompliant cross-border transfers that has already occurred before it takes effect, rectification shall be completed within 6 months upon the effective date of the Measures (i.e., before December 31, 2023). As there is only a post-process filing requirement under the Standard Contract Measures, the time available for companies under such grace period is greater than the security assessment approach.

Q10Besides entering into a standard contract, what are the other ways to comply with the Cross-border data transfer?

As mentioned in Q1, there are two additional approaches available: acquiring a personal information protection certification at a specialized institution in accordance with the provisions issued by the CAC, and entering into a contract with the overseas recipient in accordance with the standard contract formulated by the CAC, agreeing on both parties' rights and obligations. These two paths will be explained in our next article.

● 注释:

[1]Please refer to Standard Contract Measures published on the CAC’s official WeChat account:

https://mp.weixin.qq.com/s/5T7pCReDif6tzCd56m3zKA

特别声明:

大成律师事务所严格遵守对客户的信息保护义务,本篇所涉客户项目内容均取自公开信息或取得客户同意。全文内容、观点仅供参考,不代表大成律师事务所任何立场,亦不应当被视为出具任何形式的法律意见或建议。如需转载或引用该文章的任何内容,请私信沟通授权事宜,并于转载时在文章开头处注明来源。未经授权,不得转载或使用该等文章中的任何内容。

特别声明:以上内容(如有图片或视频亦包括在内)为自媒体平台“网易号”用户上传并发布,本平台仅提供信息存储服务。

Notice: The content above (including the pictures and videos if any) is uploaded and posted by a user of NetEase Hao, which is a social media platform and only provides information storage services.

相关推荐
热点推荐
国家卫健委: 家长应关注孩子“远视储备量”,避免过早耗尽

国家卫健委: 家长应关注孩子“远视储备量”,避免过早耗尽

南方都市报
2024-05-31 22:06:15
活下去,像牲口一样的活下去

活下去,像牲口一样的活下去

黑噪音
2024-05-30 23:01:23
不堪入目!儿童节文艺汇演,幼师领舞成热点,短裙跳舞引热议!

不堪入目!儿童节文艺汇演,幼师领舞成热点,短裙跳舞引热议!

三月柳
2024-05-30 15:17:41
连巴铁都不敢想!外媒:歼20技术保密不准外销,但阿联酋不想放弃

连巴铁都不敢想!外媒:歼20技术保密不准外销,但阿联酋不想放弃

影孖看世界
2024-05-31 19:09:38
外国专家:基建如此震撼!西藏让我没想到

外国专家:基建如此震撼!西藏让我没想到

环球网资讯
2024-05-31 18:44:31
霉霉开唱,皇马2天赚910万!佛爷大格局:18亿打造商业帝国

霉霉开唱,皇马2天赚910万!佛爷大格局:18亿打造商业帝国

叶青足球世界
2024-05-31 09:54:16
美国GDP,原来是这么高出来的

美国GDP,原来是这么高出来的

侠客栈
2024-05-31 12:37:22
普京发出警告

普京发出警告

新京报
2024-05-30 12:09:07
我当兵时资助一个女孩上大学,转业才发现,她已是我单位大领导

我当兵时资助一个女孩上大学,转业才发现,她已是我单位大领导

文雅笔墨
2024-05-31 22:09:41
回顾:江苏女子见一学生像前夫,鉴定后竟是她死了17年的儿子

回顾:江苏女子见一学生像前夫,鉴定后竟是她死了17年的儿子

可乐86
2024-05-30 10:11:18
烤肉店老板热情喂流浪犬,结果吸引了更多流浪犬前来蹭饭!

烤肉店老板热情喂流浪犬,结果吸引了更多流浪犬前来蹭饭!

我和宠物的日常
2024-05-29 16:25:16
两军关系、涉台、涉菲等重要议题外,中美防长会谈还涉及哪些“其他”问题?

两军关系、涉台、涉菲等重要议题外,中美防长会谈还涉及哪些“其他”问题?

政知新媒体
2024-05-31 20:40:13
近2亿独生子女的困境,已经来临

近2亿独生子女的困境,已经来临

深度知局
2024-05-29 19:01:27
我们对外部世界的看法是有问题的

我们对外部世界的看法是有问题的

维舟
2024-04-29 21:07:28
“中俄反卫星武器竟然这么多?!”

“中俄反卫星武器竟然这么多?!”

枢密院十号
2024-05-29 23:52:16
曝火箭愿用探花签换大桥!休城媒体人力挺:他与申京格林完美契合

曝火箭愿用探花签换大桥!休城媒体人力挺:他与申京格林完美契合

罗说NBA
2024-06-01 10:12:31
高端会计人的最终宿命:刚从里面出来!哈哈哈笑不活了

高端会计人的最终宿命:刚从里面出来!哈哈哈笑不活了

新动察
2024-05-31 10:22:21
父亲:把空调关掉,让它休息下。连续开机17年的冰箱:那我呢?

父亲:把空调关掉,让它休息下。连续开机17年的冰箱:那我呢?

冥王星与一只碗
2024-06-01 00:57:02
森林北负面消息缠身,疑似与汪峰已分手?很有可能,原因有六个!

森林北负面消息缠身,疑似与汪峰已分手?很有可能,原因有六个!

王子鸣爱游戏
2024-06-01 08:40:45
1946年NBA成立至今,10支球队仍0冠,谁能率先打破无冠魔咒?

1946年NBA成立至今,10支球队仍0冠,谁能率先打破无冠魔咒?

大卫的篮球故事
2024-05-31 16:32:25
2024-06-01 12:30:44
大成律师事务所
大成律师事务所
全球资源 本土智慧
2566文章数 248关注度
往期回顾 全部

教育要闻

高考生报了不喜欢的专业,录取后退学复读,第二年情况如何?

头条要闻

知情者:菲律宾意图在仙宾礁"坐滩" 2艘船已滞留45天

头条要闻

知情者:菲律宾意图在仙宾礁"坐滩" 2艘船已滞留45天

体育要闻

欧文:当老二怎么了?硬就行了!

娱乐要闻

白玉兰提名:胡歌、范伟争视帝

财经要闻

实锤!普华永道,危!

科技要闻

华为上新!余承东:问界6月销量将超4万辆

汽车要闻

吉利银河E5 Flyme Auto智能座舱首发

态度原创

艺术
旅游
亲子
游戏
军事航空

艺术要闻

穿越时空的艺术:《马可·波罗》AI沉浸影片探索人类文明

旅游要闻

美国华盛顿年内将迎来大熊猫“宝力”和“青宝”

亲子要闻

5月是孩子“转骨期”,舍得吃2果,胜过6针生长激素

《寂静岭2RE》将扩展这个世界 抛弃原版的固定镜头

军事要闻

拜登称以色列提出新的三阶段停火方案

无障碍浏览 进入关怀版