Data Collection, Use, and Security: Developments in China
摘要
China’s data protection regime has undergone significant changes in recent years, starting with the introduction of the Cybersecurity Law (CSL) in 2017. This landmark legislation laid the foundation for a comprehensive data protection framework, which was further expanded with the enactment of the Personal Information Protection Law (PIPL) and the Data Security Law (DSL) in 2021. Prior to these developments, the recommended standard Personal Information Security Specification (PI Specification) served as the main guideline for data protection in China, providing recommendations but lacking the force of law. With the new legal framework now in place, recommended standards have evolved to play a complementary role, providing practical guidance to companies as they navigate the complex requirements of the CSL, PIPL, and DSL. The focus of standardization work has shifted toward addressing IT security challenges. International companies have adapted to the new regulations as far as possible but still need to follow new developments in data localization and cross-border data transfers. The emerging data economy may also provide opportunities for foreign companies.