The Chinese Personal Information Protection Law (PIPL) came into effect to protect online user data privacy. This policy was approved on 20 August 2021 and came into effect just 73 days later, on 1 November 2021. The correct implementation of the PIPL relies heavily on organisations and companies following regulations on new data privacy elements. Sanctions can be imposed if your company or organisation does not comply with the rules and regulations set out. A serious effort needs to be made by organisations to comply with the main requirements of PIPL. This needs to be dealt with urgently as the rules and regulations concerning data privacy are already in effect.
To assist companies and organisations in becoming compliant, here I’ll provide a handy and simplified checklist.
PIPL compliance checklist
Companies and organisations that have business operations in China, whether incorporated in China or elsewhere, will need to make sure they are compliant. We have outlined and simplified these key questions to get companies started as soon as they can.
1. Will you need a designated representative or entity within Chinese borders?
China‘s PIPL extends its territorial scope to the processing of personal information conducted outside of China. The purpose of this processing must be:
(i) To provide products or services to individuals in China, or
(ii) To analyse or assess the behavior of individuals in China, or
(iii) For other purposes to be specified by laws and regulations
If you are an offshore organisation processing the personal data of Chinese residents to provide services or products, or for analysing and assessing their behavior, you must establish a dedicated office or appoint a designated representative in China for personal information protection purposes, and file the information of the entity or the representative with the relevant government authorities.
2. Are you collecting and using personal information on a lawful basis?
The processing activities that take place in your organisation must have a clear and reasonable purpose. Legitimate interest is not a recognised lawful basis under the PIPL.
3. Are you giving individuals the option to withdraw consent?
Individuals must have a convenient way to withdraw their consent. You cannot refuse someone’s right to withdraw their consent at any point.
4. Does your company or organisation have a privacy notice?
An explicit privacy notice must be provided to individuals. The privacy notice must be clear, concise, and in easily understandable language. Your privacy notice needs to include the following:
- Name of the data controller
- Contact method of the data controller
- Purpose of the processing of personal information
- The methods and procedures for individuals to exercise the rights provided in the PIPL
If your organisation notifies individuals using the method of formulating personal information processing rules then you should make these processing rules public. The rules should be easy to read and store.
5. Do you have automated mechanisms to fulfil data subjects’ rights?
Processes for individuals to exercise their rights should be convenient to accept and process. Having an automated data subject request mechanism is probably the easiest way to execute this.
6. Do you have a security breach response in place?
If a security breach occurs, organisations need to have an immediate remediation reaction. You will need to notify the relevant agencies and affected individuals. A clear security breach response plan needs to be in place, along with the tools required to ensure compliance with breach notifications.
7. Does your organisation need to conduct a Personal Information Impact Assessment (PIIA)?
A Personal Information Impact Assessment (PIIA) would need to be rendered if you are processing sensitive personal information, or using personal information to produce automated decision-making. It will also need to be conducted if you are entrusting personal information processing or providing personal information to other data controllers.
8. Have you implemented data classifications and management mechanisms?
Internal management structures and data classification will need to be formulated and implemented. This requirement aligns with new data classifications under China’s Personal Information Protection Law.
9. Have you fulfilled your cross-border data transfer obligations?
If you engage in cross-border data transfers with China, you will need to comply with strict requirements and meet one of these four mechanisms for cross-border transfers.
10. Have you concluded data processing agreements with third-party’s processors?
If you are using third parties for your processing activities, you must ensure that you conclude an agreement with them for processing. The agreement needs to include the following:
- The time limit
- The processing method
- Categories of personal information
- Protection measures
- The rights and duties of both sides
- Supervise the processing activities of the third parties.
Benefits of becoming PIPL compliant
Once you have complied with the laws and regulations surrounding China‘s PIPL, remaining compliant is necessary and beneficial. The long-term benefits are far-reaching and will continue to be seen as we embrace these new laws and regulations concerning data privacy. That being said, the following can already be outlined:
Clarity on data collected
Gaining clarification will give organisations a better understanding of how their data processes work will show how that data is utilised. For example, marketing and sales teams can gain insight into the various demographics they can market products and services to. The aim is to identify key target audiences for improved accuracy for marketing initiatives.
Better brand reputation
Establishing trust is key for any modern business, now more than ever before. By sticking to privacy policies, organisations can improve their brand reputation, securing more business relationships built upon ethical-minded optics and trust.
Simplified business automation processes
As in many business practices that evolve, process improvements begin to reveal themselves. Investigating how your company manages customer and client data storage could ultimately lead to streamlining processes and reveal security vulnerabilities, which can then be addressed and corrected.
Increased credibility
Organisations that utilise the best data management principles will gain credibility and infallible trust from their customers. Becoming PIPL compliant and displaying your privacy policy will signify to clients that your company or organisation has achieved a high level of data protection, a characteristic that business partners, clients, and all customers can appreciate.
An even data privacy playing field
Organisations that already had stringent data privacy measures in place faced unfair competition from companies and organisations that paid no heed to personal privacy. This new ethical environment protects customers and clients without placing them vulnerable under enormous pressure to gain a competitive advantage.
Benefits of utilising privacy governance technology
Privacy governance technology provides functionalities that enable your organisation to create and maintain data registers, visualise the flow of data across the business, document transfer mechanisms and automatically generate processing records and other compliance reporting.
How does it do this?
- It allows an organisation to embed rule logic or skip logic into a questionnaire to manage risk in a more organised way
- Reduces the complexity of managing different workflows of varying consent collection points
- Enables an organisation to prioritise vendor inventory with auto-inherent risk and save time with automated vendor onboarding workflows
- Provides a more transparent and tracked workflow of handling data subject requests than a manual approach
- AI technologies can be used to perform auto compliance regulation checking on contract clauses by monitoring engines embedded with data privacy rules
- AI performs full scans on contracts to auto-compare privacy clauses and analyse the level of compliance of the contract
Take action now
Although the process will take some getting used to, organisations need to take the necessary steps to become PIPL compliant. This involves setting up consent mechanisms for personal information processing, reviewing third-party data processing agreements, and formulating a set of comprehensive internal data compliance policies.
These stringent regulations, similar to that of General Data Protection Regulation (GDPR), were established to protect citizens’ personally identifiable information by regulating data transfer outside China. The ordinary person has now become empowered to control their digital paper trails.
Once a company has an efficient and streamlined data protection process in place, the easier it will be to sustain these practices in the long term. Making compliance easier for all individuals in your organisation will ensure that data protection is recognised as a part of everyday ethical business activity, rather than an overhead required to avoid hefty fines.
If an organisation operates outside of China, or if personal information is exported outside of China, it is necessary to assess the extra-territorial application of the PIPL. Reviewing this application will assist in implementing appropriate cross-border data transfer mechanisms.