Accelerate Literature Icon
Want to do a literature review? Try our new Literature Review workflow

Transferring data to foreign authorities under Chinese data protection law

  • Abstract
  • Literature Map
  • Similar Papers
Abstract
Translate article icon Translate Article Star icon

Transferring data to foreign authorities under Chinese data protection law

Similar Papers
  • Research Article
  • Cite Count Icon 18
  • 10.1515/ijld-2021-2059
Legislative discourse of digital governance: a corpus-driven comparative study of laws in the European Union and China
  • Nov 25, 2021
  • International Journal of Legal Discourse
  • Siyue Li + 1 more

Based on the self-compiled corpora of the European Union and Chinese laws on data governance, this study adopts a corpus-driven approach to comparatively study the legislative design of the EU and China on digital governance, especially on key issues such as data protection, data processing and utilization, and cross-border data transfer. It is found through corpus analysis that the EU has developed a relatively comprehensive data protection system, which internally focuses on the protection of individual data rights and externally sets high standards on the cross-border transfer of data. Despite the data protection paradigm as it manifests, the EU is facing new challenges on data exportation, data jurisdiction in the competitive digital marketplace. Shared the same concern on the data protection legislation, Chinese data law has made significant progress in personal data protection with the nascent enactment of Data Security Law and Personal Data Protection Law. Notably, Chinese legislation features the hierarchal taxonomy of data under the principle of the national security exception, while it requires more legislative skills, flexible response mechanisms, and more subordinate laws to prevent future data security threats. Moreover, the corpus-driven method conducted in this study provides evidential insights for the comparative legal textual studies across jurisdictions.

  • Research Article
  • Cite Count Icon 14
  • 10.1093/grurint/ikaa136
How Comprehensive Is Chinese Data Protection Law? A Systematisation of Chinese Data Protection Law from a European Perspective
  • Sep 20, 2020
  • GRUR International
  • Anja Geller

In China, there is no unified data protection law similar to the EU’s General Data Protection Regulation (GDPR). As a result, there are many different relevant regulations. Among other things, this makes enforcement and comprehension more difficult. To alleviate this problem and assess the comprehensiveness of Chinese data protection, this article uses the GDPR as a frame to organise and systematise the most important Chinese regulations. Binding and non-binding as well as enacted and draft provisions are included to show the dynamic progress and the general direction of Chinese law. While from a European data protection perspective there still are numerous deficiencies, the general development is positive.

  • Research Article
  • Cite Count Icon 2
  • 10.5817/mujlt2024-2-1
People’s Republic of China and the adequacy – Why Chinese data protection law is not adequate within the meaning of the GDPR
  • Sep 30, 2024
  • Masaryk University Journal of Law and Technology
  • Wojciech Panek

Chinese data protection seems to be problematic. On the one hand, it does exist, at least formally, especially after the reform initiated by the adoption of the Cybersecurity Law and finished by the Personal Information Protection Law entering into force. However, the mere adoption of personal data protection regulations does not guarantee that they provide personal data protection at an appropriate level. For EU law, the adequacy standard is the reference point for verifying personal data protection in a third country. Therefore, it is necessary to meet specific criteria summarising the term of essential equivalence, as introduced by the Court of Justice of the European Union. This article discusses the three most critical problems that result from comparing the provisions of the Chinese Cybersecurity Law, the Civil Code, the Data Security Law and the Personal Information Protection Law with the EU’s adequacy standard. The article consists of the introduction, four parts and closing remarks. The first part explains the methodology of research on Chinese data protection law and criteria applied to its examination. The second, third and fourth parts discuss the complicated relationships between the laws related to the protection of personal data, the status of state authorities as data controllers and multi-stakeholder supervision over personal data protection.

  • Research Article
  • 10.54648/gplr2023004
Are Joint Controllers Joint Trade Secret Owners? What EU Data Protection and US Information Privacy Law Tell Us About Trade Secret Law
  • Feb 1, 2023
  • Global Privacy Law Review
  • Tristan Radtke

The article focusses on (joint) trade secret ownership as a (neglected) aspect of European Union (EU) and United States (US) Trade Secret Law. The article shows that Information Privacy Law and Data Protection Law, respectively, and Trade Secret Law intersect. This intersection can be used to address not only the issue of unclear trade secret ownership in relation with personal data, but also the issue of power imbalance raised by considering two or more parties with entirely different bargaining positions as jointly responsible under Data Protection Law, in particular under the General Data Protection Regulation (GDPR). In this regard, US Information Privacy and Trade Secret Law as well as EU Data Protection and Trade Secret Law and the underlying ownership and liability concepts are analysed and compared to each other. The article shows that factors for (joint) control as developed by the Court of Justice of the European Union (CJEU) (Cases Wirtschaftsakademie, Jehovah’s Witnesses (JW), and Fashion ID) can be adapted by means of interpretation in essence under EU and US Trade Secret Law. Thus, joint controllers are often considered joint owners of the respective personal data as a trade secret. According to this approach, the parties are reciprocally entitled to prevent disclosures by each other beyond what is explicitly or implicitly agreed. Such right can act as a lever for weaker parties when bargaining with ‘stronger’ parties as necessary under Data Protection Law. At the same time, the essentially unified approach of determining trade secret ownership and data protection controllership provides for more clarity when it comes to the determination of trade secret ownership. Joint Control, Trade Secrets, Ownership, Joint Ownership, UTSA, Fashion ID, Trade Secret Directive, GDPR, FTCA, US

  • Research Article
  • Cite Count Icon 86
  • 10.1093/idpl/ipy013
Fairness and enforcement: bridging competition, data protection, and consumer law
  • Aug 1, 2018
  • International Data Privacy Law
  • Inge Graef + 2 more

Recent years have shown a surge of interest from various enforcement agencies to remedy commercial behaviour exploiting the increasing information and power asymmetries between consumers and firms. What is particularly notable about this rise in attention is that enforcement actions demonstrate clear interactions between different legal fields that are traditionally applied and enforced in isolation. The present article will focus in particular on the growing interaction between competition, data protection, and consumer law.

  • Research Article
  • Cite Count Icon 17
  • 10.2139/ssrn.3290824
Data Protection and Competition Law: The Dawn of ‘Uberprotection’
  • Dec 3, 2018
  • SSRN Electronic Journal
  • Gabriela Zanfir-Fortuna + 1 more

Data Protection and Competition Law: The Dawn of ‘Uberprotection’

  • Research Article
  • Cite Count Icon 3
  • 10.2139/ssrn.3740658
The Making of a Civil Code in China: Promises and Perils of a New Civil Law
  • Jan 1, 2020
  • SSRN Electronic Journal
  • Hao Jiang

The Making of a Civil Code in China: Promises and Perils of a New Civil Law

  • Research Article
  • Cite Count Icon 2
  • 10.69554/fncp3521
Cross-border flow of personal data (digital trade) ought to have data protection
  • Nov 1, 2024
  • Journal of Data Protection & Privacy
  • Vandana Gyanchandani

The paper provides three specific arguments in support of the two key claims to promote an interface between data protection and digital trade law. It engages in the current academic debate among scholars to understand the role of digital trade law in coordinating the regulatory thicket of national data protection regulations (NDPRs) among states. In pursuance, it proposes a rebuttal to the critique that digital trade law is fundamentally ill-suited to engage in data protection policy debates. The paper argues that data protection and digital trade law cannot remain in separate silos as they both are fundamentally intertwined with the governance of cross-border flow of personal data. Data protection issues should form an indispensable consideration in the context of digital trade liberalisation and vice versa. The paper concludes that the standards regime in international trade law can be considered as a blueprint for the necessary regulatory interface between data protection and digital trade. The paper consists of five main sections. This introduction is the first section. The second section titled ‘Interconnected structural blocks of a data protection regulation in general’ provides the general structural elements of a data protection regulation and how the data protection principles and practices combine to actualise the mechanisms which govern the cross-border flow of personal data in a jurisdiction. It highlights that the structural elements of a data protection regulation are interconnected, which necessitates policy coherence between data protection and digital trade law. The third section titled ‘Three arguments against and in favour of an interface between data protection and digital trade law’ provides an outline of the critiques by Irion, Kaminski and Yakovleva to the proposals by Chander and Schwartz to promote a legal interface between data protection and digital trade law. Notably, it provides a rebuttal to the critiques by supporting the proposals by Chander and Schwartz. It supports the proposal for an international agreement on data privacy among states in the future which can bring coherence in the governance of cross-border flow of personal data. The fourth section titled ‘Future interface between data protection and digital trade law’ underscores the need for a self-standing agreement on data privacy in the context of international trade law. This is due to the fact that traditional trade law approaches need readjustment to cohesively tackle the realities of digital economy, especially data protection issues. In pursuance, it proposes that the trade standards regime, ie the Technical Barriers to Trade (TBT) and Sanitary and Phytosanitary (SPS) Agreement in the World Trade Organization’s (WTO) provide a unique blueprint to envision a self-standing legal agreement and forum on data protection concerns as it relates to cross-border flow of personal data in international trade law. The section briefly highlights the relevance of the WTO trade standards regime as a blueprint for the future international data privacy agreement in international trade law. The fifth section concludes the paper by raising two key challenges for a policy coherence between data protection and digital trade law — (a) progressive coordination and (b) a reasonable legal interface between the two regimes in both theory and practice.

  • Single Book
  • Cite Count Icon 1
  • 10.1007/978-981-15-6803-9
Legal Aspects of Privately Financed Infrastructure Projects (PFIPs) in China
  • Jan 1, 2020
  • White Rose eTheses Online (University of Leeds, The University of Sheffield, University of York)
  • Shuang Liang

This thesis discusses the reform and improvement of Chinese legislation on Privately Financed Infrastructure Projects (PFIPs), to develop the PFIP model in China, under the protection of Chinese laws, so that its implementation in China may reach international standards. Existing Chinese laws are found to be insufficient in reducing risks to PFIPs because of certain shortcomings. Therefore, it is necessary to reform and improve Chinese legislation on PFIPs, to prevent their failure. The Legislative Guide and Model Provisions drafted by UNCITRAL are treated as the international standards to guide Chinese legislation reform on PFIPs. Other countries’ laws on PFIPs provide supplementary reference. This thesis addresses its aim in four steps: First, the current Chinese legislative and institutional framework on PFIPs is reviewed, with discussion on establishing a more appropriate legislative and institutional framework, to facilitate the development of PFIPs in China through the principles of transparency, fairness, long-term sustainability and the elimination of undesirable restrictions. Second, Chinese laws on the concessioner selection procedure in PFIPs are reviewed, with discussion on possible improvements to the laws to achieve international standards of fairness and transparency. Third, current Chinese laws and policies which affect the various contracts involved in PFIPs are reviewed, with discussion on these may be improved to achieve international standards. Fourth, the PFIP dispute settlements that may be used in China are reviewed, with discussion on the necessity to remove certain undesirable restrictions in relevant Chinese laws. Following the rapid rise in the practical use of PFIPs in China, this thesis offers a strong theoretical basis for suggesting a reform of Chinese legislation on PFIPs. It also provides a general basis for any national reform of laws on PFIPs in any other countries.

  • Research Article
  • Cite Count Icon 15
  • 10.54648/bula2021001
Insolvency and Data Protection
  • Jan 1, 2021
  • Business Law Review
  • Robert Walters

This article examines the interrelationship between crossborder insolvency, insolvency in general and data protection. Prior to the outbreak of the coronavirus, the world had already been facing significant geopolitical and economic challenges. It examines Australia, the European Union, the United Kingdom (BREXIT), and the United States data protection and privacy laws. What has emerged from the recent adoption of data protection and privacy law, is a highly fragmented approach. States and in the case of the European Union have largely gone it alone. This poses significant challenges to entities that are experiencing financial stress and either going through insolvency (including cross border insolvency), restructuring or a merger or acquisition. Insolvency and legal practitioners will need to be aware of the varied approach taken by jurisdictions in defining personal data, the concept of consent and regulatory requirement(s) to appoint a controller or processor. This article argues that increasingly administrators and liquidators will need to consider the various data protection laws, when proceeding with cross-border insolvency. Cross-border insolvency, insolvency in general and data protection, Australia, the European Union, the United Kingdom (BREXIT), and the United States data protection and privacy laws

  • Research Article
  • Cite Count Icon 22
  • 10.1016/j.clsr.2024.105994
From brussels effect to gravity assists: Understanding the evolution of the GDPR-inspired personal information protection law in China
  • Jun 8, 2024
  • Computer Law & Security Review: The International Journal of Technology Law and Practice
  • Wenlong Li + 1 more

This paper explores the evolution of China's Personal Information Protection Law (PIPL) and situates it within the context of global data protection development. It draws inspiration from the theory of ‘Brussels Effect’ and provides a critical account of its application in non-Western jurisdictions, taking China as a prime example. Our objective is not to provide a comparative commentary on China's legal development but to illuminate the intricate dynamics between the Chinese law and the EU's GDPR. We argue that the trajectory of China's Personal Information Protection Law calls into question the applicability of the Brussels Effect: while the GDPR's imprint on the PIPL is evident, a deeper analysis unveils China's nuanced, non-linear adoption that diverges from many assumptions of the Brussels Effect and similar theories. The evolution of the GDPR-inspired PIPL is not as a straightforward outcome of the Brussels Effect but as a nuanced, intricate interplay of external influence and domestic dynamics. We introduce a complementary theory of ‘gravity assist’, which portrays China's strategic instrumentalisation of the GDPR as a template to shape its unique data protection landscape. Our theoretical framework highlights how China navigates through a patchwork of internal considerations, international standards, and strategic choices, ultimately sculpting a data protection regime that has a similar appearance to the GDPR but aligns with its distinct political, cultural and legal landscape. With a detailed historical and policy analysis of the PIPL, coupled with reasonable speculations on its future avenues, our analysis presents a pragmatic, culturally congruent approach to legal development in China. It signals a trajectory that, while potentially converging at a principled level, is likely to diverge significantly in practice, driven by China's broader socio-political and economic agendas rather than the foundational premises of EU data protection law and its global aspirations. It thus indicates the inherent limitations of applying Brussels Effect and other theoretical frameworks to non-Western jurisdictions, highlighting the imperative for integrating complementary theories to more accurately navigate complex legal landscapes.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 32
  • 10.1017/err.2020.92
Towards Smarter Regulation in the Areas of Competition, Data Protection and Consumer Law: Why Greater Power Should Come with Greater Responsibility
  • Nov 12, 2020
  • European Journal of Risk Regulation
  • Inge Graef + 1 more

Based on a mix of conceptual insights and findings from cases, this paper discusses three ways in which the effectiveness of regulation in the areas of competition, data and consumer protection can be improved by tailoring substantive protections and enforcement mechanisms to the extent of market power held by firms. First, it is analysed how market power can be integrated into the substantive scope of protection of data protection and consumer law, drawing inspiration from competition law’s special responsibility for dominant firms. Second, it is illustrated how more asymmetric and smarter enforcement of existing data protection rules against firms possessing market power can strengthen the protection of data subjects and stimulate competition based on lessons from priority-setting and cooperation by consumer authorities. Third, it is explored how competition law’s special responsibility for dominant firms can be further strengthened in analogy with the principle of accountability in data protection law. Similarly, it is discussed how positive duties to ensure fair outcomes for consumers are developed in consumer law. The analysis offers lessons for improving the ability of the three regimes to protect consumers by imposing greater responsibility on firms with greater market power and thus posing greater risks for consumer harm.

  • Research Article
  • Cite Count Icon 3
  • 10.1080/17441048.2019.1599771
Chinese private international law and online data protection
  • Jan 2, 2019
  • Journal of Private International Law
  • Jeanne Huang

This paper explores how Chinese private international law responds to online data protection from two aspects: jurisdiction and applicable law. Compared with foreign laws, Chinese private international law related to online data protection has two distinct features. Chinese law for personal jurisdiction is still highly territorial-based. The “target” factor and the interactive level of a website have no play in Chinese jurisprudence. Regarding applicable law, Chinese legislators focus more on the domestic compliance with data regulations rather than their extra-territorial application. Moreover, like foreign countries, China also resorts to Internet intermediaries to enhance enforcement of domestic law. These features should be understood in the Chinese contexts of high-level data localization and Internet censorship.

  • Research Article
  • Cite Count Icon 15
  • 10.1145/3473673
How Could Equality and Data Protection Law Shape AI Fairness for People with Disabilities?
  • Aug 30, 2021
  • ACM Transactions on Accessible Computing
  • Reuben Binns + 1 more

This article examines the concept of ‘AI fairness’ for people with disabilities from the perspective of data protection and equality law. This examination demonstrates that there is a need for a distinctive approach to AI fairness that is fundamentally different to that used for other protected characteristics, due to the different ways in which discrimination and data protection law applies in respect of Disability. We articulate this new agenda for AI fairness for people with disabilities, explaining how combining data protection and equality law creates new opportunities for disabled people's organisations and assistive technology researchers alike to shape the use of AI, as well as to challenge potential harmful uses.

  • Research Article
  • Cite Count Icon 1
  • 10.1093/joclec/nhae016
Data Protection Considerations in Competition Law Assessments: A Qualitative Document Analysis of EU Decision Texts
  • Oct 11, 2024
  • Journal of Competition Law & Economics
  • Robin Vandendriessche + 1 more

Personal data are both protected by a fundamental right and serves as a source of market power. As such, a complex interplay between data protection and competition law arises, sparking debate among policymakers and scholars on whether to incorporate data protection considerations (DPCs) in competition law assessments. Proponents argue that competition cases involving such an interplay require a normative contribution from data protection law, while opponents emphasize the practical challenges of considering data protection as a non-economic public policy objective. We identify nine ways in which data protection might ultimately surface in competition law assessments, categorized into five areas: (i) competition enforcement actions, (ii) existing legal and regulatory framework, (iii) personal data collection, (iv) exclusionary abuses, and (v) alleviation of competition concerns. Using a multiple-step approach for qualitative document analysis, we explore how these considerations have surfaced in the European Commission’s decisional practice through a dataset of 2.041 EU competition decision texts based on articles 101 TFEU and 102 TFEU and the EU Merger Regulation. We identify 53 decisions where DPCs have surfaced, especially in the information and communication industry, where they are more frequently subjected to commitments. In line with the evolving literature, we observe an increasingly integrationist trend as these considerations surface more frequently, particularly since the adoption of the General Data Protection Regulation in 2016 and the Digital Markets Act proposal in 2020. We also find a pattern where data protection provisions are included in commitments as a ‘tick-the-box’ exercise. Several influential alleviations of competition concerns suggest that the Commission is more comfortable using data protection to approve transactions unconditionally rather than as a substantive argument for commitments. We conclude by making a case for a more collaborative approach based on the European Court of Justice’s recent Meta Platforms (2023) judgment. Data protection should be considered in competition law assessments if its normative contribution is required. Such a stance would simply align with the internal logic of competition law without unlawfully expanding its material scope.

Save Icon
Up Arrow
Open/Close
Notes

Save Important notes in documents

Highlight text to save as a note, or write notes directly

You can also access these Documents in Paperpal, our AI writing tool

Powered by our AI Writing Assistant