NEW TRANSLATION: Draft "Outbound Data Transfer Security Assessment Measures"
Cross-border data rules have been a big question for five years. This new draft could clarify required govt security assessments.
digichina.stanford.edu/work/… @China_Digital @SammSacks @gwbstr @lorandlaskai
1
19
27
Analysis is likely to follow in longer form, but some relevant cites:
(1) Article 37 of the Cybersecurity Law
digichina.stanford.edu/work/…
1
1
(2) Article 31 of the Data Security Law, effective Sept. 1, refers this issue to the 2017 Cybersecurity Law.
digichina.stanford.edu/work/…
1
1
(3) The Personal Information Protection Law, effective on Monday (Nov. 1), has several references to these security assessments.
(a) Article 40 does the broad strokes.
Oct 29, 2021 · 7:26 PM UTC
1
1
(b) Article 36 of the PIPL specifies that state organs providing personal info abroad shall undertake security assessment.
(c) Article 38 of the PIPL provides some conditions for transfer abroad WITHOUT this assessment.
digichina.stanford.edu/work/…
1
2
China Law Translate has an alternative translation of today's draft Measures. chinalawtranslate.com/en/dat…
2




