<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PIPL Archives - Zasio</title>
	<atom:link href="https://zasio.com/tag/pipl/feed/" rel="self" type="application/rss+xml" />
	<link>https://zasio.com/tag/pipl/</link>
	<description>Digital Records Management Software</description>
	<lastBuildDate>Wed, 18 Oct 2023 20:23:14 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://zasio.com/wp-content/uploads/2023/05/cropped-zasiopurplefavicon-32x32.png</url>
	<title>PIPL Archives - Zasio</title>
	<link>https://zasio.com/tag/pipl/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Power to the PIPL? A Rundown of China’s New Personal Information Protection Law</title>
		<link>https://zasio.com/power-to-pipl-rundown-chinas-new-personal-information-protection-law/</link>
					<comments>https://zasio.com/power-to-pipl-rundown-chinas-new-personal-information-protection-law/#respond</comments>
		
		<dc:creator><![CDATA[Zasio]]></dc:creator>
		<pubDate>Thu, 30 Sep 2021 20:20:08 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[By Jared Walker]]></category>
		<category><![CDATA[China’s privacy laws]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Information Governance software]]></category>
		<category><![CDATA[Jared Walker]]></category>
		<category><![CDATA[Personal Information Protection Law of the People’s Republic of China]]></category>
		<category><![CDATA[personal information rights]]></category>
		<category><![CDATA[PIPL]]></category>
		<category><![CDATA[privacy laws]]></category>
		<category><![CDATA[record retention consulting]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=495</guid>

					<description><![CDATA[<p>The post <a href="https://zasio.com/power-to-pipl-rundown-chinas-new-personal-information-protection-law/" data-wpel-link="internal">Power to the PIPL? A Rundown of China’s New Personal Information Protection Law</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_0  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">On August 20, 2021, China adopted the <a href="http://www.npc.gov.cn/npc/c30834/202108/a8c4e3672c74491a80b53a172bb753fe.shtml" target="_blank" rel="noopener external noreferrer" data-wpel-link="external">Personal Information Protection Law of the People’s Republic of China</a> (“PIPL”), its first comprehensive national data privacy law and one of the most sweeping and restrictive national privacy laws to date. Modeled largely off the GDPR and set to go into effect on November 1, the PIPL regulates personal information collected or transferred both inside and outside of China. It also comes with harsh penalties for non-compliance and gives broad powers to China’s state authorities to enforce the law.</p>
<p>The PIPL is expected to significantly impact how companies (especially tech companies) do business in China. Aimed at protecting the online user data of Chinese citizens, the law will directly affect companies located in China that handle personal data. But even companies operating outside of China may be subject to the law if they provide products or services to people in China, analyze or evaluate activities of people in China, or fall under circumstances described in certain other laws or administrative regulations.</p>
<p>Without further ado, let’s quickly dive into some of the law’s major provisions:</p>
<p><strong>In General</strong></p>
<p>The PIPL defines personal information to include, similar to the GDPR, “all kinds of information related to an identified or identifiable natural person, recorded electronically or by other means, excluding anonymized information.”</p>
<p>The handling of personal information includes “collection, storage, use, processing, transmission, provision, disclosure, or deletion of personal information.”</p>
<p>Under the PIPL, personal information should only be processed for a clear and reasonable purpose, to the smallest scope possible related to that purpose, and in a method with the least impact on personal rights. Personal information processing must also follow principles of openness and transparency, as well as rules of disclosure. These general principles largely mirror <a href="https://gdpr-info.eu/art-5-gdpr/" target="_blank" rel="noopener external noreferrer" data-wpel-link="external">GDPR principles</a> of fairness, transparency, and limitations on processing of personal data.</p>
<p><strong>Personal Consent</strong></p>
<p>Personal information handlers (the PIPL equivalent of data processors under the GDPR) must obtain personal consent from the data subject to process personal information, unless the data is processed under a specific listed exception. Those exceptions include contract performance, statutory duties or obligations, public health emergencies, news reports or public interest, legally disclosed information, or other circumstances stipulated by laws and regulations.</p>
<p>Personal consent must also be obtained for any cross-border transfer of personal information (for more on this, see the section below that discusses notification requirements).</p>
<p>These express consent requirements break from the GDPR, which technically doesn’t require personal consent to use personal data unless (i) it is relied upon as one of the six legal bases to process personal data under <a href="https://gdpr.eu/article-6-how-to-process-personal-data-legally/" target="_blank" rel="noopener external noreferrer" data-wpel-link="external">Article 6</a> of the GDPR, or (ii) is used as an exemption to transfer personal data abroad (in absence of one of the required transfer mechanisms laid out in <a href="https://gdpr-info.eu/chapter-5/" target="_blank" rel="noopener external noreferrer" data-wpel-link="external">Chapter 5</a> of the GDPR).</p>
<p><strong>Data Retention</strong></p>
<p>Similar to the GDPR, the retention of personal information under the PIPL must be the shortest time necessary to achieve the purpose of processing. This time may vary depending on the data processed and any laws or regulations that specify specific periods.</p>
<p><strong>Notification Requirements</strong></p>
<p>Before processing personal information, personal information handlers must inform the data subject of the information being processed and the data subject’s rights concerning this information. For sensitive information, personal information handlers must also notify the data subject of the processing’s necessity.</p>
<p>For any information processed outside of China, a personal information handler must inform the data subject of the overseas recipient, their contact information, and certain processing information such as processing purpose, processing method, and the types of personal information being processed. The personal information handler must also obtain the individual’s specific consent to process after giving notice.</p>
<p><strong>Cross-border Transfer of Information</strong></p>
<p>Before a handler can transfer personal information outside of China, they must first meet one of the following requirements:</p>
<ul>
<li>pass a security assessment organized by the Cyberspace Administration of China (“CAC”), the country’s central internet control agency;</li>
<li>conduct a personal information protection certification;</li>
<li>form a contract with the overseas recipient that stipulates the rights and obligations of both parties, or</li>
<li>meet other conditions required by law, administrative regulations, or the CAC.</li>
</ul>
<p>Further, personal information handlers must ensure that any personal information processing by overseas recipients meets PIPL standards.</p>
<p>Also, operators of “critical information infrastructure” and personal information handlers processing personal information up to an as-of-yet unspecified threshold (which will be prescribed by the national cybersecurity and informatization department) must store the personal information collected and generated within the territory of the People’s Republic of China. This information may not leave China unless it first passes a security assessment organized by the national cybersecurity and informatization department.</p>
<p>Moreover, personal information handlers may not provide personal data stored in China to foreign judicial or law enforcement agencies without first receiving approval from a competent authority within the Chinese government. This requirement will certainly result in conflicts between Chinese authorities and non-Chinese courts as well as plenty of judicial wrangling among litigants in lawsuits involving Chinese companies.</p>
<p><strong>Individual rights</strong></p>
<p>Just like under the GDPR, data subjects in China have various rights concerning their personal information. These include the right to: know and make decisions about their information’s processing; consult and copy their personal information; request that personal information be corrected or supplemented; request deletion (in certain cases); and request the personal information processing rules of personal information handlers.</p>
<p><strong>Obligations of personal information handlers</strong></p>
<p>Personal information handlers must implement internal management systems and security measures to protect personal data. Processors of personal information up to the threshold must appoint a person in charge of personal information protection. Processors outside of China must establish designated agencies or representatives within Chinese territories to handle intra-territorial personal data processing matters.</p>
<p>Personal information handlers must also regularly conduct compliance audits as well as impact assessments for things like processing sensitive personal data, using personal data in automated decision-making, or providing information to other personal information handlers. These impact assessments must be kept for at least 3 years.</p>
<p><strong>Breach notification</strong></p>
<p>If any personal information has been leaked, tampered with, or lost, the personal information handler must immediately notify the relevant departments (the CAC or relevant departments of the State Council) and individuals performing personal information protection duties. In some cases, personal information subjects might also be notified.</p>
<p><strong>Legal Liability and Penalties</strong></p>
<p>The department performing personal information protection duties has the power to order corrections, give warnings, confiscate illegal gains, and issue fines for information processed in violation of the law. Fines can range to up to 1 million yuan for offenders who refuse to make corrections, and between 10,000 and 100,000 yuan for directly responsible persons.</p>
<p>For serious violations, fines can be issued for up to 50 million yuan or up to 5 percent of the processor’s previous year turnover. Furthermore, the department can order the suspension of a business or notify a relevant competent authority to revoke a business permit or license, in addition to issuing additional fines.</p>
<p>Moreover, foreign organizations that violate the personal information rights of Chinese citizens or harm China’s national security or public interests can be blacklisted by the CAC. This also will result in the offending organization being restricted or prohibited from possessing personal information. In addition to everything else, illegal acts will be recorded in the social credit system and publicized.</p>
<p>In some cases, where the rights and interests of many individuals have been infringed, certain entities may file a lawsuit in the people’s court. These entities include the people’s procuratorate, consumer organizations specified in the PIPL, and organizations identified by the CAC.</p>
<p><strong>Exceptions</strong></p>
<p>The law does not apply to natural persons handling personal information for personal or family affairs.</p>
<p><strong>Final Thoughts</strong></p>
<p>We have yet to see exactly how the PIPL will impact the way we conduct business generally, but it is on course to significantly affect companies large and small, both inside and outside of China. If you are doing business in China or with people in China, it may well be worth your while to proactively study up on the law, determine what type of impact it might have on your business, seek legal guidance as necessary, and prepare and implement PIPL-compliant policies and strategies to manage Chinese personal data processed within your organization. A bit of up-front planning can go a long way in giving peace of mind – not to mention helping to avoid costly legal or compliance concerns down the road.</p>
<p><a href="https://www.zasio.com/about-us/contact-us/" data-wpel-link="internal">Contact Zasio</a> to explore the various software and consulting solutions we offer, to address your personal data and privacy needs.</p>
<p><em>Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</em></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row et_pb_row_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_1  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_with_border et_pb_module et_pb_team_member et_pb_team_member_0 clearfix  et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_team_member_image et-waypoint et_pb_animation_off"><img decoding="async" width="96" height="96" src="https://zasio.com/wp-content/uploads/2023/05/Jared-Walker-01-96x96-1.png" alt="Author: Jared Walker, JD" class="wp-image-2021" /></div>
				<div class="et_pb_team_member_description">
					<h4 class="et_pb_module_header">Author: Jared Walker, JD</h4>
					<p class="et_pb_member_position">Senior Research Analyst, Team Lead / Licensed Attorney</p>
					
					
				</div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fpower-to-pipl-rundown-chinas-new-personal-information-protection-law%2F&amp;linkname=Power%20to%20the%20PIPL%3F%20A%20Rundown%20of%20China%E2%80%99s%20New%20Personal%20Information%20Protection%20Law" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fpower-to-pipl-rundown-chinas-new-personal-information-protection-law%2F&amp;linkname=Power%20to%20the%20PIPL%3F%20A%20Rundown%20of%20China%E2%80%99s%20New%20Personal%20Information%20Protection%20Law" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fpower-to-pipl-rundown-chinas-new-personal-information-protection-law%2F&amp;linkname=Power%20to%20the%20PIPL%3F%20A%20Rundown%20of%20China%E2%80%99s%20New%20Personal%20Information%20Protection%20Law" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fpower-to-pipl-rundown-chinas-new-personal-information-protection-law%2F&#038;title=Power%20to%20the%20PIPL%3F%20A%20Rundown%20of%20China%E2%80%99s%20New%20Personal%20Information%20Protection%20Law" data-a2a-url="https://zasio.com/power-to-pipl-rundown-chinas-new-personal-information-protection-law/" data-a2a-title="Power to the PIPL? A Rundown of China’s New Personal Information Protection Law" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/power-to-pipl-rundown-chinas-new-personal-information-protection-law/" data-wpel-link="internal">Power to the PIPL? A Rundown of China’s New Personal Information Protection Law</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/power-to-pipl-rundown-chinas-new-personal-information-protection-law/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
