{"id":1121,"date":"2019-06-12T10:08:24","date_gmt":"2019-06-12T10:08:24","guid":{"rendered":"https:\/\/www.leaf-legal.com\/?p=1121"},"modified":"2020-11-19T07:57:50","modified_gmt":"2020-11-19T07:57:50","slug":"childrens-data-protection-where-does-the-new-prc-regulation-go","status":"publish","type":"post","link":"https:\/\/www.leaf-legal.com\/zh-hans\/childrens-data-protection-where-does-the-new-prc-regulation-go\/","title":{"rendered":"Children\u2019s Data Protection: where does the new PRC regulation go?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Children merit a particular attention with regard to their personal data, as it has been clearly stated in prominent jurisdictions by the EU regulator (EU GDPR, namely Recital 38), the US regulator (with a dedicated regulation: Children\u2019s Online Privacy Protection Act, or \u201cCOPPA\u201d) and now the PRC regulator in the authority of the Cyberspace Administration of China (\u201cCAC\u201d) with the publication of the&nbsp;<strong>Children\u2019s Personal Information Network Protection Regulation<\/strong>&nbsp;in its draft stage.(the \u201cDraft\u201d) issued on the 31<sup>st<\/sup>&nbsp;of May 2019 for 1-month public consultation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First and foremost, a child is defined by his\/her age, varying here according for each legal framework:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013 13 for the COPPA,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013 14 for the PRC Draft,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013 16 for the EU GDPR, or lower where a State Member has stricter regulation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The underlying principles and key measures in the EU GDPR and the US COPPA can be found in the PRC Draft, namely:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u2013 Personal information:<\/strong>&nbsp;data protection measures apply to Personal Information understood as all kinds of information recorded in an electronic or other forms, which can be used, independently or in combination with other information, to identify a natural person\u2019s personal identity, including device information (I.P., MAC address, device serial number).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u2013 Information:&nbsp;<\/strong>the data controller shall communicate with the children in clear and understandable language, and clearly state the scope of data collected and the processing goals;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u2013 Parental consent:&nbsp;<\/strong>the data controller shall expressly seek the consent of legal guardians and renew such consent collection if the scope of data collected and processed changes;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u2013 Data minimisation:&nbsp;<\/strong>the array of personal information shall be strictly necessary for the provision of a services to the data subject;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u2013 Prize incentives:&nbsp;<\/strong>data controller shall refrain from requesting children to input personal information in order to win a prize or enter a lottery, if this information is not directly necessary for the execution of the game, on the same principle as data minimisation;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u2013 Data retention:<\/strong>&nbsp;in alignment with the data minimisation principle, personal information shall be retained during the strict period necessary to fulfil the purpose of its collection and use;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u2013 Data access, modification and erasure:&nbsp;<\/strong>the data controller shall comply with any request from the legal guardian regarding the children\u2019s personal information;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u2013 Third party assessment:<\/strong>&nbsp;when entrusting a third party to process children\u2019s personal information, network operators shall conduct a security assessment on the third party. Furthermore, the processing of children\u2019s personal information by a third party shall be covered by an agreement to include the following obligations for the third party to:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(1) process in accordance with the data controller\u2019s requirements,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(2) assist the data controller,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(3) ensure information security,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(4) delete children\u2019s personal information in a timely manner when the relationship is dissolved,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(5) prohibit the subcontract of the processing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although those fundamental principles are shared among the different regulations, it is worth noting a specific emphasis from the PRC regulator on&nbsp;<strong>security assessment<\/strong>. As commonly observed in previous regulations, the regulator follows the trend of stating an obligation whose technical implementations remain to be defined.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, a data controller may disclose children\u2019s personal information to safeguard national security or public interest, leaving the authorities a broad range of interpretation and thus creating a permanent data leak risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As PRC regulation drafts represent usually a close version to the final text, it appears critical for foreign data controller operating in the PRC to stay ahead of the curve by implementing information protection processes in compliance with the PRC regulations, while assessing the inherent risks of such compliance and potential conflicts with other jurisdictions, namely on data storage and data transfer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To know more, please contact Gregory Louvel&nbsp;<a href=\"https:\/\/www.leaf-legal.com\/children-data-protection-in-prc\/g.louvel@leaf-legal.com\">g.louvel@leaf-legal.com<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The TL Group is a team providing tech and legal services.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><strong>The alliance between Leaf, a law firm, and TekID, a Data intelligence firm, is providing a comprehensive cyber security and data management&nbsp;offering which will help you enhance your security with a holistic approach. This team of cyber \/&nbsp;data experts and lawyers can offer services to companies and managers such as&nbsp;compliance audits and programs in cybersecurity, structuring deals involving data assets, understanding and managing the life cycle of data and the associated risks, forensic investigations, among others.<\/strong><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Children merit a particular attention with regard to their personal data, as it has been clearly stated in prominent jurisdictions by the EU regulator (EU GDPR, namely Recital 38), the US regulator (with a dedicated regulation: Children\u2019s Online Privacy Protection Act, or \u201cCOPPA\u201d) and now the PRC regulator in the authority of the Cyberspace Administration [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":1351,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_FSMCFIC_featured_image_caption":"","_FSMCFIC_featured_image_nocaption":"","_FSMCFIC_featured_image_hide":"","footnotes":""},"categories":[31],"tags":[46],"pub_type":[23],"class_list":["post-1121","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","tag-data-protection","pub_type-article"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.leaf-legal.com\/zh-hans\/wp-json\/wp\/v2\/posts\/1121","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.leaf-legal.com\/zh-hans\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.leaf-legal.com\/zh-hans\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.leaf-legal.com\/zh-hans\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.leaf-legal.com\/zh-hans\/wp-json\/wp\/v2\/comments?post=1121"}],"version-history":[{"count":0,"href":"https:\/\/www.leaf-legal.com\/zh-hans\/wp-json\/wp\/v2\/posts\/1121\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.leaf-legal.com\/zh-hans\/wp-json\/wp\/v2\/media\/1351"}],"wp:attachment":[{"href":"https:\/\/www.leaf-legal.com\/zh-hans\/wp-json\/wp\/v2\/media?parent=1121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.leaf-legal.com\/zh-hans\/wp-json\/wp\/v2\/categories?post=1121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.leaf-legal.com\/zh-hans\/wp-json\/wp\/v2\/tags?post=1121"},{"taxonomy":"pub_type","embeddable":true,"href":"https:\/\/www.leaf-legal.com\/zh-hans\/wp-json\/wp\/v2\/pub_type?post=1121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}