China’s New DPO Registration Requirement: What You Need to Know
Please see our article about the role and obligations of China DPOs and key distinctions between China DPOs and DPOs under the EU General Data Protection Regulation 2016/679.
Searching…
Please see our article about the role and obligations of China DPOs and key distinctions between China DPOs and DPOs under the EU General Data Protection Regulation 2016/679.
Article 53 PIPL requires offshore personal information processors that are subject to PIPL to appoint a PRC-based representative or establish an agency in the PRC for personal information protection purposes.
Under the PIPL, organisations which meet certain data processing volume thresholds (as yet unspecified by the CAC) are required to appoint a Data Protection Officer (DPO), and to register the name (s) and contact deta...
Please see our article about the role and obligations of China DPOs and key distinctions between China DPOs and DPOs under the EU General Data Protection Regulation 2016/679.
Under the Audit Measures, large-scale data processing entities (defined as those processing personal information of more than 10 million individuals) must conduct audits at least once every two years.
After much anticipation, the Cyberspace Administration of China (“CAC”) has finally issued the much-needed guidance (available here) for Data Protection Officers (“DPO”) (个人信息保护负责人) to register with the CAC. Who needs...
PIPL Article 53 requires overseas handlers to appoint a representative or establish an agency in the PRC for personal information protection purposes and to report the representative or agency’s name and contact infor...
There are no mandatory qualification requirements for DPOs under the PIPL, the Audit Measures or the DPO Filing Notice. DPOs may be either Chinese or foreign citizens. However, they are...
Today (18 July), the Cyberspace Administration of China (CAC) issued a notice requiring certain personal information processors to report details of their designated personal information protection officer (DPO).
Article 6 of the Measures provides the requirements data processors should fulfill before applying for PIP Certification. First, data processors should inform and obtain separate consent from the individuals whose dat...