Cybersecurity Law of the People's Republic of China

Cybersecurity Law of the People's Republic of China
National People’s Congress
  • Cybersecurity Law of the People's Republic of China
CitationCybersecurity Law (English)
Territorial extentMainland China
Enacted byStanding Committee of the National People's Congress
EnactedNov 7, 2016
CommencedJun 1, 2017
Related legislation
Data Security Law, National Intelligence Law, National Security Law (China)
Summary
A law formulated in order to: ensure cybersecurity; safeguard cyberspace sovereignty and national security, social and public interests; the lawful rights and interests of citizens, legal persons, other organizations; and promote the healthy development of the informatization of the economy and society.
Keywords
Cybersecurity, National Security, Cyber sovereignty
Status: In force

The Cybersecurity Law of the People's Republic of China (Chinese: 中华人民共和国网络安全法), commonly referred to as the Chinese Cybersecurity Law, was enacted by the National People’s Congress with the aim of increasing data protection, data localization, and cybersecurity ostensibly in the interest of national security.[1] The law is part of a wider series of laws passed by the Chinese government in an effort to strengthen national security legislation. Examples of which since 2014 have included the data security law, the national intelligence law, the national security law, laws on counter-terrorism[2] and foreign NGO management,[3] all passed within successive short timeframes of each other.

History

Chinese policymakers became increasingly concerned about the risk of cyberattacks following the 2010s global surveillance disclosures by Edward Snowden, which demonstrated extensive United States intelligence activities in China.[4]: 129  The Cybersecurity Law was part of China's response following policymakers' heightened concerns of foreign surveillance and data collection after these disclosures.[4]: 250 

This law was enacted by the Standing Committee of the National People's Congress on November 7, 2016, and was implemented on June 1, 2017.[5] It requires network operators to store select data within China and allows Chinese authorities to conduct spot-checks on a company's network operations.[1]

Cybersecurity is recognized as a basic law. This puts the law on the top of the pyramid-structured legislation on cybersecurity. The law is an evolution of the previously existent cybersecurity rules and regulations from various levels and fields, assimilating them to create a structured law at the macro-level. The law also offers principal norms on certain issues that are not immediately urgent but are of long-term importance. These norms will serve as a legal reference when new issues arise.[6]

Provisions

The law is a significant pillar of the Chinese data regulatory environment.[4]: 131  It:

  • Created the principle of cyberspace sovereignty[7]
  • Defined the security obligations of internet products and services providers
  • Detailed the security obligations of internet service providers.
  • Further refined rules surrounding personal information protection[8]
  • Established a security system for key information infrastructure[9]
  • Instituted rules for the transnational transmission of data from critical information infrastructures.[10]

The cybersecurity law is applicable to network operators and businesses in critical sectors.[1] By critical sectors, China roughly divides the domestic businesses into networking businesses that are involved in telecommunications, information services, energy transport, water, financial services, public services, and electronic government services.[11] Some of the most controversial sections of the law include articles 28, 35, and 37.

Article 28 compels vaguely defined "network operators", (interpreted to include: social media platforms, application creators and other technology companies), to cooperate with public security organs such as the Ministry of Public Security and hand over information when requested.

Article 28: Network operators shall provide technical support and assistance to public security organs and national security organs that are safeguarding national security and investigating criminal activities in accordance with the law.

— Section 1: 'Ordinary Provisions'

Article 35 is targeted at purchases of foreign software or hardware by government agencies or other "critical information infrastructure operators", requiring any hardware of software purchased to undergo review by agencies such as China's SCA or State Cryptography Administration, potentially involving the provision source codes and other sensitive proprietary information to government agencies paving the way state theft of intellectual property or transmission to domestic competitors.[12] Above all, the article creates further regulatory burdens for foreign technology companies operating in China, indirectly creating a more favourable playing field for domestic competitors which would naturally be more prepared to comply with the regulations.

Article 35: Critical information infrastructure operators purchasing network products and services that might impact national security shall undergo a national security review organized by the State cybersecurity and informatization departments and relevant departments of the State Council.

— Section 2: 'Operations Security for Critical Information Infrastructure'

The law establishes stringent data localization requirements.[4]: 131 

The law is applicable to all businesses in China that manage their own servers or other data networks. Network operators are expected, among other things, to clarify cybersecurity responsibilities within their organization, take technical measures to safeguard network operations, prevent data leaks and theft, and report any cybersecurity incidents to both users of the network and the relevant implementing department for that sector.[13]

The law is composed of supportive subdivisions of regulations that specify the purpose of it. For instance, the Core Infrastructure Initiative (CII) Security Protection Regulations and Measures for Security Assessment of Cross-border Transfer of Personal Information and Important Data. However, the law is yet to be set in stone since China's government authorities are occupied with defining more contingent laws to better correspond with the cybersecurity law. By incorporating preexisting laws on VPN and data security into the cybersecurity law, the Chinese government reinforces its control in addition to emphasize has the need for foreign companies to comply with domestic regulations.[14]

The cybersecurity law also provides regulations and definitions on legal liability. For different types of illegal conduct, the law sets a variety of punishments, such as fines, suspension for rectification, revocation of permits and business licenses, and others. The Law accordingly grant cybersecurity and administration authorities with rights and guidelines to carry out law enforcement on illegal acts.[15]

In July 2021, the Cyberspace Administration of China issued "Regulations on the Management of Security Vulnerabilities in Network Products" requiring that all vulnerabilities be reported to the Ministry of Industry and Information Technology (MIIT) and prohibits the public disclosure of vulnerabilities, including to overseas organizations.[16]

Reactions

Along with the Great Firewall, restrictions stipulated in the law have raised concerns, especially from foreign technology companies operating in China.[17] Regarding the requirements for spot-checks and certifications, international law firms have warned that companies could be asked to provide source code, encryption, or other crucial information for review by the authorities, increasing the risk of intellectual property theft, information being lost, passed on to local competitors, or being used by the authorities themselves.[1] The Federal Bureau of Investigation warned that the law could force companies transmitting data through servers in China to submit to data surveillance and espionage.[18]

Some analysts from Western backgrounds consider this law to be comparable to the EU's GDPR. They have suggested that the law could improve the Chinese government’s ability to monitor the public, as well as giving Chinese companies an advantage over foreign companies.[19]

The law sparked concerns both domestically and internationally due to its phrasing and specific requirements.[20] Foreign companies and businesses in China expressed concerns that this law might impede future investments in China, since the law requires them to "store their data on Chinese-law regulated local servers, and cooperate with Chinese national security agencies".[21]

Since its inception many foreign technology companies have already complied with the law. Apple for example, announced in 2017 that it would invest $1 billion in partnership with local cloud computing company Guizhou Cloud Big Data or GCBD to construct a new data center located in China's Guizhou province for the purposes of compliance.[22] Simultaneously, the company also announced that it would transfer the operation and storage of iCloud data to mainland China.[23] Microsoft also announced an expansion of its Azure services in partnership cloud computing company 21Vianet through investment in more servers.[24] Meanwhile, online services, such as Skype and WhatsApp which refused to store their data locally and were either delisted from domestic app stores or restricted from further expansion.[25]

The law forces foreign technology and other companies operating within China to either invest in new server infrastructure in order to comply with the law or partner with service providers such as Huawei, Tencent, or Alibaba, which have already have server infrastructure on the ground, saving capital expenditure costs for companies. The law is widely seen to be in line with 12th Five-Year Plan (2011–2015) which aims to create domestic champions in industries such as cloud computing and big data processing. The law is seen as a boon to domestic companies and has been criticized as creating an unfair playing ground against international technology companies such as Microsoft and Google.[citation needed]

Supporters of the law have stated that the intention of the law is not to prohibit foreign businesses from operating in China, or boost domestic Chinese competitiveness. A study by Matthias Bauer and Hosuk Lee-Makiyama in 2015, states that data localization causes minor damage to economic growth due to inefficiencies that arise from data transfer processes and the duplication of data between several jurisdictions. The requirement for data localization is also seen as a move by Beijing to bring data under Chinese jurisdiction and make it easier to prosecute entities seen as violating China's internet laws.[1]

The president of AmCham South China, Harley Seyedin, claimed that foreign firms are facing “mass concerns” because the law has greatly increased operating costs and has had a big impact on how business is done in China. More specifically, he stated that the cyber security law continues to create “uncertainties within the investment community, and it’s resulting in, at the minimum, postponement of some R&D investment.”[26]

The law was widely criticized for limiting freedom of speech.[27] For example, the law explicitly requires most online services operating in China to collect and verify the identity of their users, and, when required to, surrender such information to law enforcement without warrant. Activists have argued this policy dissuades people from freely expressing their thoughts online, further stifling dissent by making it easier to target and surveil dissidents.[27]

See also

References

  1. ^ a b c d e Wagner, Jack (2017-06-01). "China's Cybersecurity Law: What You Need to Know". The Diplomat. Archived from the original on 2018-12-12. Retrieved 2018-12-14.
  2. ^ Blanchard, Ben (2015-12-28). "China passes controversial counter-terrorism law". Reuters. Retrieved 2021-07-21.
  3. ^ Wong, Edward (2016-04-28). "Clampdown in China Restricts 7,000 Foreign Organizations". The New York Times. ISSN 0362-4331. Retrieved 2021-07-21.
  4. ^ a b c d Zhang, Angela Huyue (2024). High Wire: How China Regulates Big Tech and Governs Its Economy. Oxford University Press. ISBN 9780197682258.
  5. ^ "网络安全法(草案)全文_中国人大网". www.npc.gov.cn. Archived from the original on 2016-10-29. Retrieved 2018-04-14.
  6. ^ Lulu, Xia, and Zhao Leo (2018-08-21). "China's Cybersecurity Law: An Introduction for Foreign Businesspeople". China Briefing. Archived from the original on 2018-12-13. Retrieved 2018-12-14.{{cite web}}: CS1 maint: multiple names: authors list (link)
  7. ^ 网易. "网络安全法明确了网络空间主权原则_网易新闻". NetEase. Archived from the original on 2019-07-03. Retrieved 2018-04-14.
  8. ^ "《网络安全法》正式施行 为个人信息加把"锁"". China Internet Information Center. Archived from the original on 2018-12-14. Retrieved 2018-04-14.
  9. ^ "网络安全立法中的关键信息基础设施保护问题--理论-人民网". People's Daily. Archived from the original on 2018-04-15. Retrieved 2018-04-14.
  10. ^ "专家解读《网络安全法》 具有六大突出亮点-新华网". www.xinhuanet.com. Archived from the original on 2018-04-15. Retrieved 2018-04-14.
  11. ^ Gierow Johannes, Hauke (2015-04-22). "Cyber Security in China: Internet Security, Protectionism and Competitiveness: New Challenges to Western Businesses" (PDF). China Monitor, Merics: Mercator Institute for China Studies. Archived (PDF) from the original on 2018-12-16. Retrieved 2018-12-14.
  12. ^ "China's cyber regulations: a headache for foreign companies | Merics". merics.org. 22 March 2017. Retrieved 2021-07-22.
  13. ^ "Understanding China's Cybersecurity Law INFORMATION FOR NEW ZEALAND BUSINESSES" (PDF). Ministry of Foreign Affairs and Trade, and New Zealand Trade and Enterprise. Sep 2017. Archived (PDF) from the original on 2019-01-23. Retrieved 2018-12-14.
  14. ^ Beckett, Nick (Nov 2017). "A Guide for Businesses to China's First Cyber Security Law". China Monitor, Merics: Mercator Institute for China Studies. Archived from the original on 2018-12-16. Retrieved 2018-12-14.
  15. ^ Lee, Jyh-An (2017). "Hacking into China's Cybersecurity Law" (PDF). Wake Forest Law Review. 53 (1). SSRN 3174626.
  16. ^ "China lays down new vulnerability disclosure rules". Arjun Ramprasad. Previewtech.net. June 18, 2021.
  17. ^ Uchill, Joe (October 17, 2019). "China's upgraded cybersecurity law could take a toll". Axios. Archived from the original on March 29, 2020. Retrieved April 8, 2020.
  18. ^ "Dangerous Partners: Big Tech and Beijing". Federal Bureau of Investigation. Archived from the original on 2020-04-02. Retrieved 2020-04-09.
  19. ^ Bo, Q. U.; Changxu, H. U. O. (15 September 2020). "Privacy, National Security, and Internet Economy: An Explanation of China's Personal Information Protection Legislation". Frontiers of Law in China. 15 (3): 339–366. doi:10.3868/s050-009-020-0019-4. ProQuest 2450653759.
  20. ^ Lin, Liza; Kubota, Yoko (6 December 2017). "U.S. Tech Firms Spooked by China's Arcane Cybersecurity Law". Wall Street Journal.
  21. ^ "中国施行《网络安全法》 外企为何担忧?". BBC 中文网. 2017-05-31. Archived from the original on 2018-05-11. Retrieved 2018-04-14.
  22. ^ Gartenberg, Chaim (2017-07-13). "Apple is building its first China-based data center per new cybersecurity law". The Verge. Retrieved 2021-07-22.
  23. ^ "Learn more about iCloud in China". Apple Support. Archived from the original on 2018-03-07. Retrieved 2018-04-14.
  24. ^ "New Azure region coming to China in 2022 | Azure blog and updates | Microsoft Azure". azure.microsoft.com. 4 March 2021. Retrieved 2021-07-22.
  25. ^ "多家中国区应用商店下架Skype". 纽约时报中文网 (in Chinese). 2017-11-22. Archived from the original on 2018-04-13. Retrieved 2018-04-14.
  26. ^ Hu, Huifeng (2018-03-01). "Cybersecurity law causing 'mass concerns' among foreign firms in China". South China Post. Archived from the original on 2018-11-07. Retrieved 2018-12-14.
  27. ^ a b "中国《网络安全法》草案出炉 恐加强言论管制". BBC 中文网 (in Simplified Chinese). 9 July 2015. Archived from the original on 2018-05-08. Retrieved 2018-04-14.

Read other articles:

Ricostruzione delle fortificazioni dell'esercito di Cesare ad Alesia L'assedio nell'antica Roma fu una delle tecniche utilizzate dall'esercito romano per ottenere la vittoria finale, sebbene le battaglie campali fossero ritenute l'unica vera forma di guerra. Ciò nonostante, non si deve cadere nella tentazione di sottovalutare l'importanza che l'azione d'assedio poteva avere nel quadro bellico di quell'epoca. Annibale non riuscì a debellare la potenza di Roma perché, pur avendo sconfitto g…

Rampo Kitan: Game of Laplace乱歩奇譚 Game of LaplaceGenreMisteri,[1] psikologi[2] Seri animeSutradaraSeiji KishiSkenarioMakoto UezuMusikMasaru YokoyamaStudioLerchePelisensiAUS Madman EntertainmentNA FunimationSaluranasliFuji TV (Noitamina)Saluran bahasa InggrisUK AnimaxUS FunimationTayang 2 Juli 2015 – 17 September 2015Episode11 (Daftar episode)  Portal anime dan manga Rampo Kitan: Game of Laplace (乱歩奇譚 Game of Laplacecode: ja is deprecated , Ranpo Kitan G…

Madrid Metro station Hospital de FuenlabradaMadrid Metro stationGeneral informationLocationFuenlabrada, Community of MadridSpainCoordinates40°17′09″N 3°48′59″W / 40.2857533°N 3.816422°W / 40.2857533; -3.816422Owned byCRTMOperated byCRTMConstructionAccessibleYesOther informationFare zoneB2HistoryOpened11 April 2003; 20 years ago (2003-04-11)Services Preceding station Madrid Metro Following station Lorancaclockwise / outer Line 12 Parque Europa…

2018 South Korean web series Top ManagementOfficial posterHangul탑 매니지먼트 GenreRomanceDramaFantasyBased onTop Managementby Jang Woo-sanWritten byJang Eun-miKim Jung-heeLim Jung-minPark Seul-giYoo Su-jiYoon Yang-woonDirected byYoon Sung-hoStarringSeo Eun-sooAhn Hyo-seopCha Eun-wooJung Yoo-ahnBang Jae-minCountry of originSouth KoreaOriginal languageKoreanNo. of seasons1No. of episodes16 (list of episodes)ProductionExecutive producerYoon Shin-aeProducersGreg LeeSohn Jong-hanYoo Hye-minRun…

Goddess of dawn, mirth and revelry in the Shinto religion of Japan Ame-no-UzumeGoddess of the Dawn, meditation, and the artsThe statue of Ame-no-Uzume at Amanoiwato-jinjaConsortSarutahiko ŌkamiEquivalentsGreek equivalentEos[1]Roman equivalentAurora[1]Hinduism equivalentUshas[1]Nuristani equivalentDisani[1] Part of a series onShinto Beliefs Kami List of deities Polytheism Animism/Animatism Mythology Sacred objects Sects and schools Major kami Amaterasu Sarutahiko …

Si ce bandeau n'est plus pertinent, retirez-le. Cliquez ici pour en savoir plus. Le fond de cet article d'histoire est à vérifier (novembre 2012). Améliorez-le ou discutez des points à vérifier. Si vous venez d’apposer le bandeau, merci d’indiquer ici les points à vérifier. Si ce bandeau n'est plus pertinent, retirez-le. Cliquez ici pour en savoir plus. Cet article doit être recyclé (novembre 2021). Motif : Article sans source et aux affirmations incongrues ou orientées Améli…

Hichem Mechichiهشام المشيشيMechichi pada 2020 Perdana Menteri TunisiaMasa jabatan2 September 2020 – 25 Juli 2021PresidenKais Saied PendahuluElyes FakhfakhPenggantiLowongMenteri Dalam NegeriMasa jabatan27 Februari 2020 – 2 September 2020Perdana MenteriElyes Fakhfakh PendahuluHichem FouratiPenggantiTaoufik Charfeddine Informasi pribadiLahirJanuari 1974 (umur 50)Bou Salem, TunisiaPartai politikIndependenAlma materUniversitas Tunis El ManarÉcole nationale …

Office in Seoul, South KoreaSeocho Garak Tower EastAlternative namesGT Tower EastGeneral informationStatusCompletedTypeOfficeLocationSeoul, South KoreaCoordinates37°29′53″N 127°1′33″E / 37.49806°N 127.02583°E / 37.49806; 127.02583Construction started2008Completed2011OwnerGT ConstructionHeightRoof130.1 m (427 ft)Technical detailsFloor count24Floor area54,530 m2 (587,000 sq ft)Design and constructionArchitect(s)Het Architecten ConsortDev…

الدوري الأيرلندي 1925–26 تفاصيل الموسم الدوري الأيرلندي  النسخة 5  البلد جمهورية أيرلندا  المنظم اتحاد أيرلندا لكرة القدم  البطل نادي شيلبورن  مباريات ملعوبة 90   عدد المشاركين 10   الدوري الأيرلندي 1924–25  الدوري الأيرلندي 1926–27  تعديل مصدري - تعديل   الدو…

West African ethnic group Not to be confused with the larger Mandé peoples or the unrelated Dinka people of Sudan. MandinkaMansa Musa's visit to Mecca in 1324 CE with large amounts of gold attracted Middle Eastern Muslims and Europeans to Mali.[1][2]Total populationc. 11 million[3]Regions with significant populations Guinea3,786,101 (29.4%)[4] Mali1,772,102 (8.8%)[5] Senegal900,617 (5.6%)[6] The Gambia700,568 (34.4%)[7]…

This is a list of notable syrups. In cooking, a syrup is a condiment that is a thick, viscous liquid consisting primarily of a solution of sugar in water, containing a large amount of dissolved sugars but showing little tendency to deposit crystals. Its consistency is similar to that of molasses. The viscosity arises from the hydrogen bonds between the dissolved sugar, which has many hydroxyl (OH) groups, and the water. Syrups Cheong A railroad tank car carrying a load of corn syrup Pekmez (Üz…

Suasana kota Bahia Blanca, Argentina. Halaman artikel ini diterjemahkan, sebagian atau seluruhnya, dari halaman di en.wikipedia yang berjudul « Bahía Blanca ». Lihat pula sejarah suntingan halaman aslinya untuk melihat daftar penulisnya. Artikel ini tidak memiliki referensi atau sumber tepercaya sehingga isinya tidak bisa dipastikan. Tolong bantu perbaiki artikel ini dengan menambahkan referensi yang layak. Tulisan tanpa sumber dapat dipertanyakan dan dihapus sewaktu-waktu.Cari sumb…

بلاندوم     الإحداثيات 40°48′27″N 73°42′00″W / 40.8075°N 73.7°W / 40.8075; -73.7  [1] تقسيم إداري  البلد الولايات المتحدة[2]  التقسيم الأعلى مقاطعة ناسو  خصائص جغرافية  المساحة 1.304923 كيلومتر مربع1.304925 كيلومتر مربع (1 أبريل 2010)  ارتفاع 22 متر  عدد السكان  …

Third season of the AMC crime drama television series Season of television series Breaking BadSeason 3Season 3 DVD coverStarring Bryan Cranston Anna Gunn Aaron Paul Dean Norris Betsy Brandt RJ Mitte Giancarlo Esposito Bob Odenkirk Jonathan Banks No. of episodes13ReleaseOriginal networkAMCOriginal releaseMarch 21 (2010-03-21) –June 13, 2010 (2010-06-13)Season chronology← PreviousSeason 2Next →Season 4List of episodes The third season of the American television drama…

Boy WilliamLahirWilliam Hartanto17 Oktober 1991 (umur 32)Jakarta, IndonesiaNama lainBoy WilliamAlmamater Oaklands School New Zealand First Media Design School PekerjaanPemeranVJPresenterYouTuberRapperTahun aktif2009—sekarang William Hartanto (lahir 17 Oktober 1991), lebih dikenal sebagai Boy William, adalah pemeran, VJ, presenter, personalia YouTube, dan rapper Indonesia keturunan Tionghoa. Karier Ia memulai kariernya di dunia hiburan ketika memenangkan kompetisi model bertajuk …

9K115-2 Metis-M adalah sistem rudal anti-tank Rusia. 9K115-2 adalah sebutan rudal Grau. Pelaporan nama NATO adalah AT-13 Saxhorn-2. Sistem ini dirancang untuk menambah kekuatan tempur unit bermotor. Referensi Russia's Arms Catalog 2004 Pranala luar Wikimedia Commons memiliki media mengenai 9K115 Metis. Video luar Video about Metis-M (in Russian) Description of system with photos Diarsipkan 2014-04-26 di Wayback Machine. METIS-M /M1 at Defense Update Diarsipkan 2008-08-28 di Wayback Machine. Arti…

Badesi BadèsiKomuneComune di BadesiLokasi Austis di Provinsi NuoroNegaraItaliaWilayah SardiniaProvinsiSassari (SS)Pemerintahan • Wali kotaGiovanni Maria MamiaLuas • Total31,30 km2 (12,08 sq mi)Ketinggian102 m (335 ft)Populasi (2016) • Total1,849[1]Zona waktuUTC+1 (CET) • Musim panas (DST)UTC+2 (CEST)Kode pos07030Kode area telepon079Situs webhttp://www.comunebadesi.ot.it Badesi (bahasa Sardinia: Badèsi) adalah…

Об экономическом термине см. Первородный грех (экономика). ХристианствоБиблия Ветхий Завет Новый Завет Евангелие Десять заповедей Нагорная проповедь Апокрифы Бог, Троица Бог Отец Иисус Христос Святой Дух История христианства Апостолы Хронология христианства Ранне…

This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: Margaret Long Wisdom High School – news · newspapers · books · scholar · JSTOR (December 2010) (Learn how and when to remove this template message) Public, secondary school in Houston, Texas , United StatesMargaret Long Wisdom High SchoolAddress6529 Beverly Hill L…

Ini adalah nama Batak Toba, marganya adalah Sitorus. Togar SitorusFoto Togar Sitorus Wali Kota Pemantang Siantar (2017) Wakil Wali Kota Pematangsiantar Ke-4Masa jabatan12 Januari 2018 – 22 Februari 2022PresidenJoko WidodoGubernurEdy Rahmayadi PendahuluHefriansyah NoorPenggantiSusanti Dewayani Jabatan Kosong/Lowong Informasi pribadiLahir16 September 1959 (umur 64)Pematangsiantar, Sumatera UtaraKebangsaanIndonesiaPartai politikDemokratSuami/istriBetty Togar SitorusSunting kotak…

Kembali kehalaman sebelumnya