On June 3, the Flanders-China Chamber of Commerce (FCCC) held a webinar on “Cross-Border data Transfers between the EU and China: What You Need to Know”. Ms. Gwenn Sonck, Executive Director, Flanders-China Chamber of Commerce (FCCC)/EU-China Business Association (EUCBA) introduced the subject of the webinar. The speakers navigated the intricate landscape of data localization and cross-border transfer regulations stipulated in the Cyber Security Law (CSL), Data Security Law (DSL), and Personal Information Protection Law (PIPL). Mr. Guohua Zhang from Osborne Clarke China introduced the relevant rules and cross-border transfer requirements, and shared compliance recommendations from a Chinese law perspective. The European angle was tackled by other guest speakers, Mr. Valentin de le Court and Ms. Margo Cornette from Osborne Clarke Belgium, who focused on the GDPR requirements. They presented the European Data Protection Board's stand on data transfers to China with practical suggestions to help companies meeting the requirements for transferring data to China, and the potential impact of the new PIPL on earlier guidance from the European Data Protection Board or on data transfer impact assessments previously conducted by companies. Mr. Moti Khan, Senior Solutions Specialist at China Telecom Global, talked about the business benefits and typical solutions that will help European companies collaborate easily with their counterparts in China. China Telecom Europe has become a platinum structural partner of the Flanders-China Chamber of Commerce. They are committed to establishing a digital silk road that connects Europe to China, leveraging its state-of-the-art Europe-Asia network which consists of seven cables from Asia to Europe. They provide world-class integrated telecommunications solutions and services to meet the growing communications demand.
Mr. Valentin de le Court, Partner in the Brussels office of Osborne Clarke Belgium, introduced his two collaborators. Mr. Guohua Zhang is a Partner of Osborne Clarke China based in Shanghai. He focussed on the cross-border transfer of personal information. There are four categories of laws related to data protection: basic laws; sectoral laws; cross-border rules; and multiple industrial standards and guidelines. As far as implementation is concerned, the fourth category is the most important. Just like the GDPR, China's personal information protection law also has extra-territorial reach and applies to data activities out of China that are conducted for the purpose of providing goods or services to natural persons in China and for the purpose of analyzing or assessing behaviors of natural persons in China, or fall within what is otherwise stipulated by laws and regulations. If you are a foreign data controller you need to appoint a local department/representative. In order to collect and process personal information you need legal grounds similar to those in the GDPR, such as consent. Unlike in the GDPR, there is no legal ground of “legitimate interest for business” in the Chinese law.
The specific rights of data subjects are similar to the GDPR, such as the right to information, to object, the right of access etc. You need to make sure these rights are offered to the data subjects and are enforced in a proper way. Also required is a convenient mechanism for exercising rights, only providing an international telephone number for example is not “convenient”. The penalties for breaking the law could be quite severe compared to the previous rules. Penalties include a warning; an order to rectify; and/or confiscation of unlawful proceeds. The fine can go up to CNY 50 million or 5% of the turnover. You cannot really ignore the consequences. In addition to the administrative penalties you could also be subject to civil liabilities, such as claims for compensation or class action. The burden of proof will be on the part of the data controller so the data subjects will be in a more favorable position to establish their case. In a few scenarios you could also be subject to criminal liabilities, for example if you illegally sell or dispose of personal data for profit.
A cross-border transfer is legal if a separate consent is obtained from the data subject and if one of the CBDT options is satisfied: having passed the mandatory security assessment of the China Administration of Cyberspace (CAC); having obtained a personal information protection certification (PIP certification) by a professional firm or agency; having entered into standard contractual terms (SCCs) with the foreign recipient and filed with CAC; or as otherwise permitted by PRC law. There are also industry-specific localization requirements, e.g. if transferring automobile data, the number is up to 100,000 data subjects; and transferring population health information is not permitted. Unlike in the GDPR, there is no “adequacy decision”. If the government determines that there are discriminatory restrictions or prohibitions upon China, it may require reciprocal measures, but this has so far never happened. If you transfer data to a foreign law enforcement entity, special approval from the regulator is required.
You need to consider whether a mandatory security assessment is triggered, which is the case if you want to transfer important data. If your data is not advised or publicized by the regulator as important data, then we can assume this data is not important data. If you are a critical information infrastructure operator (CIIO), such as utilities or big e-commerce platforms, a mandatory security assessment is required. If you are not transferring “important data” or if you are not a CIIO operator, and you cumulatively transfer personal information for more than one million data subjects or sensitive personal information for more than 10,000 data subjects, since January 1 of the current year, you need a mandatory assessment. If not triggered, you need either obtain PIP certification – which is not common for international businesses – or sign PRC SCCs and file a DPIA report and SCCs with CAC.
There are several exemptions under CBDT promotion rules, which means the process can be simplified. If you transfer non-personal or non-important data, you are exempt, neither if foreign personal information was imported and no domestic information is included. Other exemptions include the necessity for entering into or performing a contract; the necessity for global HR management or safety emergency; small-scale transfers (less than 10,000 data subjects in one year) or data not falling within the negative lists in the pilot free trade zones of Shanghai and Tianjin. If you are exempted you still need to advise data subjects of the relevant details of the transfer, such as the foreign recipient and the purpose of the data transfer, obtain separate consent, DPIA and DPA.
Margo Cornette from Osborne Clarke Belgium focussed on data transfers from the EU to China. The basic rule is that you cannot transfer personal data outside the EU/EEA unless you can ensure that the data is equally protected in the receiving country. It is permitted under certain conditions, including adequacy findings; binding corporate rules; standard contractual clauses; ad hoc clauses; approved codes of conduct; and derogations for specific situations. The similarities between China SCCs and EU SCCs are the fixed form, the hierarchy of effect, and the impact assessment. Dissimilarities are the applicability scope; modules for different scenarios; filing requirement; governing law and dispute resolution; and onward transfers. According to the EU SCCs and transfer impact assessment you need to know your transfer; identify the transfer tools you are relying on; assess the effectiveness of the transfer tool; identify and adopt supplementary measures; and review and update. There are also several contractual and technical/organizational measures you can take into account.
Mr. Moti Khan, Senior Solutions Specialist at China Telecom Global, introduced the regulator, the Ministry of Industry and Information Technology, which grants licenses to telecom providers. China Telecom offers a wide variety of telecom solutions, ranging from traditional connectivity to cloud and internet services, managed services and unified communications, and technology innovations. China Telecom is a major telecom operator in China making full use of the digital policies, leveraging the advantages of cloud-network integration, and accelerating the systematic layout of digital infrastructure construction, including networks, AI and applications. The business benefits of using a software-defined WAN is to enable the customer to embrace global change in terms of moving away from on-premises to hosting applications in the cloud, and providing flexibility. The SD-WAN from China Telecom stands out because it is China-compliant, tailored to your business requirements, and comprehensive. An SD-WAN is a software-defined wide-area network, allowing customers in Europe to effectively communicate with their counterparts in China and everywhere else. Characteristics of the SD-WAN are reduced cost, flexibility, more control, and application performance.
The SD-WAN backbone for global connectivity delivers a total international capacity of more than 70 terabytes through 52 submarine cables. For the financial sector, there is a good low-latency network from Frankfurt to Shanghai. China Telecom can provide businesses with all the necessary equipment, configuring and maintaining it. The company provides private connections between China, APAC and Europe. China Telecom sits down with the customer to design the solution, provide proof of concept, deploy it and operate it. Finally, Mr. Khan mentioned a few case studies. Digitalization is reshaping the future by creating new customer needs, changing supply chains, adding competition models, diversifying business players, etc. Examples are the 5G networked drone application, and the fully cloud-based 5G customized network.
If you wish to receive more information about this topic, please send an e-mail to: info@flanders-china.be
A Q&A session concluded the webinar.