Digital New Media Industry Research | Data Outbound How to Complete Security Assessment


Published:

2023-04-14

Overseas listing, bond issuance, international cooperative research and development, cross-border trade, etc. will all involve the issue of data exit. With the process of national industry digitization and digital industrialization, data flow is becoming more and more frequent. How to realize the legal and effective use of data and meet the national data security regulations has become a realistic need, so how can enterprises complete the data exit security assessment? 1. what is data and what is data exit Data means any record of information, electronic or otherwise, and the term "any" covers a wide range of visible data. The essence of data export is that the original data generated in China or the collected summary data are obtained by overseas subjects in different ways, such as direct data transmission or storage, or the open data server can be queried or downloaded by overseas subjects. Whether it is active transmission or passive open data, as long as there is a situation obtained by overseas subjects, it belongs to data exit. 2. what data to leave the country needs to complete a security assessment Data security is an obligation that every subject should bear. The value of a single data may not be large, but a large amount of seemingly worthless data will have new functions and even have extremely high utilization value after being aggregated. This is the inestimable role of big data. However, not all data outbound security assessments need to be carried out. Data security assessment must be performed in the following cases: (I) data processors to provide important data abroad; (II) critical information infrastructure operators and data processors that process personal information of more than 1 million persons to provide personal information abroad; Data processors who have provided personal information of 100000 persons or sensitive personal information of 10000 persons to overseas in total are (III) to provide personal information to overseas since January 1 of the previous year; Is it not necessary to conduct a security assessment in addition to the above-mentioned circumstances, the State Network Information Office has the right to specify other circumstances that require the declaration of data exit security assessment. In addition, the concept of the first important data is not clear. Data directly related to national security, the lifeline of the national economy, important people's livelihood, and major public interests belong to the national core data. These seem to be easy to confirm, but it is difficult to distinguish them in practice. If we specialize in a new "little giant" or a single champion manufacturing enterprise collecting a large number of R & D data, we can analyze and infer the R & D path and national development direction of the enterprise by using the data, and even use it for competitors after leaking secrets, resulting in the loss of competitiveness of domestic enterprises. These enterprises are originally the functions of "supplementing the chain", "strong chain" and "extending the chain" of the national industrial chain. Therefore, although it is the data of a single enterprise, however, it is important to complete a security assessment. If ordinary enterprises gather a large amount of information, it will also have an amplification effect. As big data, it still has an inestimable effect. Whether security assessment is needed depends on the specific situation. The national data security system itself also requires the establishment of a data classification and classification protection system. Enterprises need to establish a data security management system in their operations, and designate data security leaders and management agencies to conduct regular assessments of important data. How to 3. Data Exit Security Assessment Declaration The data processor shall declare the data exit security assessment through the local provincial network information office to declare the data exit security assessment. The declaration method is to serve the written declaration materials and attach the electronic version of the materials. After receiving the application materials, the provincial network information office shall complete the completeness inspection of the application materials within 5 working days. If it passes the completeness inspection, the provincial network information office will report the application materials to the national network information office; the national network information office will determine whether to accept and notify the data processor in writing within 7 working days from the date of receiving the application materials submitted by the provincial network information office. Upon completion of the assessment, the data processor will receive a notification of the results of the assessment. If there is no objection to the evaluation results, the data processor shall regulate the relevant data exit activities in accordance with the relevant laws and regulations on data exit security management and the relevant requirements of the evaluation result notice; if there is any objection to the evaluation results, the data processor may apply to the State Network Information Office for re-evaluation within 15 working days after receiving the evaluation result notice, and the re-evaluation result shall be the final conclusion. Core requirements for 4. data exit security assessment If the data must be exported, it is necessary to prove that the act itself is legitimate and necessary. Whether the data exporter has established a data security management system and whether the specific person in charge and organization has the ability to ensure data security. Whether the data flow is safe during and after the exit of the country, and whether the receiving party can continuously ensure data security. Whether there is an agreement between the data exporter and the receiver on the relevant issues, and how the relevant agreement arrangements can be ensured to be implemented correctly and effectively. Specifically, at least the following aspects should be included in the data exit security self-assessment report: The legality, legitimacy and necessity of the purpose, scope and method of (I) data export; (II) the impact of the data security protection policies and regulations and the network security environment of the country or region where the overseas recipient is located on the security of outbound data; whether the data protection level of the overseas recipient meets the requirements of the People's Republic of China laws, administrative regulations and mandatory national standards; (III) the scale, scope, type and sensitivity of the outbound data, and the risks of tampering, destruction, leakage, loss, transfer, illegal acquisition or illegal use during and after exit; Whether (IV) data security and personal information rights and interests can be fully and effectively guaranteed; (V) whether the data processor and the overseas recipient have fully agreed on the obligations of data security protection in the legal documents; (VI) compliance with Chinese laws, administrative regulations and departmental rules; In short, whether data is used abroad or in China, data processing activities should be carried out in accordance with the provisions of laws and regulations, establish and improve the whole process data security management system, organize and carry out data security education and training, take corresponding technical measures and other necessary measures, strengthen data risk monitoring, regularly complete risk assessment, and ensure the effective use of data security, It is beneficial to the country and the people.

Overseas listing, bond issuance, international cooperative research and development, cross-border trade, etc. will all involve the issue of data exit. With the process of national industry digitization and digital industrialization, data flow is becoming more and more frequent. How to realize the legal and effective use of data and meet the national data security regulations has become a realistic need, so how can enterprises complete the data exit security assessment?

 

1. what is data and what is data exit

 

Data means any record of information, electronic or otherwise, and the term "any" covers a wide range of visible data. The essence of data export is that the original data generated in China or the collected summary data are obtained by overseas subjects in different ways, such as direct data transmission or storage, or the open data server can be queried or downloaded by overseas subjects. Whether it is active transmission or passive open data, as long as there is a situation obtained by overseas subjects, it belongs to data exit.

 

2. what data to leave the country needs to complete a security assessment

 

Data security is an obligation that every subject should bear. The value of a single data may not be large, but a large amount of seemingly worthless data will have new functions and even have extremely high utilization value after being aggregated. This is the inestimable role of big data. However, not all data outbound security assessments need to be carried out. Data security assessment must be performed in the following cases:

 

(I) data processors to provide important data abroad;

(II) critical information infrastructure operators and data processors that process personal information of more than 1 million persons to provide personal information abroad;

Data processors who have provided personal information of 100000 persons or sensitive personal information of 10000 persons to overseas in total are (III) to provide personal information to overseas since January 1 of the previous year;

 

Is it not necessary to conduct a security assessment in addition to the above-mentioned circumstances, the State Network Information Office has the right to specify other circumstances that require the declaration of data exit security assessment. In addition, the concept of the first important data is not clear. Data directly related to national security, the lifeline of the national economy, important people's livelihood, and major public interests belong to the national core data. These seem to be easy to confirm, but it is difficult to distinguish them in practice. If we specialize in a new "little giant" or a single champion manufacturing enterprise collecting a large number of R & D data, we can analyze and infer the R & D path and national development direction of the enterprise by using the data, and even use it for competitors after leaking secrets, resulting in the loss of competitiveness of domestic enterprises. These enterprises are originally the functions of "supplementing the chain", "strong chain" and "extending the chain" of the national industrial chain. Therefore, although it is the data of a single enterprise, however, it is important to complete a security assessment. If ordinary enterprises gather a large amount of information, it will also have an amplification effect. As big data, it still has an inestimable effect. Whether security assessment is needed depends on the specific situation.

 

The national data security system itself also requires the establishment of a data classification and classification protection system. Enterprises need to establish a data security management system in their operations, and designate data security leaders and management agencies to conduct regular assessments of important data.

 

How to 3. Data Exit Security Assessment Declaration

 

The data processor shall declare the data exit security assessment through the local provincial network information office to declare the data exit security assessment. The declaration method is to serve the written declaration materials and attach the electronic version of the materials. After receiving the application materials, the provincial network information office shall complete the completeness inspection of the application materials within 5 working days. If it passes the completeness inspection, the provincial network information office will report the application materials to the national network information office; the national network information office will determine whether to accept and notify the data processor in writing within 7 working days from the date of receiving the application materials submitted by the provincial network information office.

 

Upon completion of the assessment, the data processor will receive a notification of the results of the assessment. If there is no objection to the evaluation results, the data processor shall regulate the relevant data exit activities in accordance with the relevant laws and regulations on data exit security management and the relevant requirements of the evaluation result notice; if there is any objection to the evaluation results, the data processor may apply to the State Network Information Office for re-evaluation within 15 working days after receiving the evaluation result notice, and the re-evaluation result shall be the final conclusion.

 

Core requirements for 4. data exit security assessment

 

If the data must be exported, it is necessary to prove that the act itself is legitimate and necessary. Whether the data exporter has established a data security management system and whether the specific person in charge and organization has the ability to ensure data security. Whether the data flow is safe during and after the exit of the country, and whether the receiving party can continuously ensure data security. Whether there is an agreement between the data exporter and the receiver on the relevant issues, and how the relevant agreement arrangements can be ensured to be implemented correctly and effectively. Specifically, at least the following aspects should be included in the data exit security self-assessment report:

 

The legality, legitimacy and necessity of the purpose, scope and method of (I) data export;

(II) the impact of the data security protection policies and regulations and the network security environment of the country or region where the overseas recipient is located on the security of outbound data; whether the data protection level of the overseas recipient meets the requirements of the People's Republic of China laws, administrative regulations and mandatory national standards;

(III) the scale, scope, type and sensitivity of the outbound data, and the risks of tampering, destruction, leakage, loss, transfer, illegal acquisition or illegal use during and after exit;

Whether (IV) data security and personal information rights and interests can be fully and effectively guaranteed;

(V) whether the data processor and the overseas recipient have fully agreed on the obligations of data security protection in the legal documents;

(VI) compliance with Chinese laws, administrative regulations and departmental rules;

 

In short, whether data is used abroad or in China, data processing activities should be carried out in accordance with the provisions of laws and regulations, establish and improve the whole process data security management system, organize and carry out data security education and training, take corresponding technical measures and other necessary measures, strengthen data risk monitoring, regularly complete risk assessment, and ensure the effective use of data security, It is beneficial to the country and the people.

Key words:


Related News


Address: Floor 55-57, Jinan China Resources Center, 11111 Jingshi Road, Lixia District, Jinan City, Shandong Province