Personal information refers to information that identifies a person either by itself or in combination with other information. Personal information includes a person’s:
- name
- address
- telephone number
- date of birth
- identity card number
- biometrics
Network operators cannot collect personal information that is not relevant to the services they offer. Prior to collecting personal information from individuals (the data subjects), the operators must notify the individuals via clear and easily accessible language, and obtain consents from the individuals. No operators may collect personal information of children under 14 years old without the consent of their parents or custodians.
Network operators must keep users’ personal information in strict confidence. This includes an obligation to implement technical measures to monitor and record the operational status of their networks and any cybersecurity incidents. Operators must designate responsible persons who have data protection knowledge and experience to lead the security of personal information collected by operators.
If network operators collect sensitive personal information for operational purposes, they must file their data collection practices with the local CAC. Sensitive personal information refers to personal information that, if leaked or abused, might:
- endanger personal and property security
- damage personal reputation and physical and psychological health
- lead to discriminatory treatment
Examples of sensitive personal information are:
- ID card numbers
- biometrics
- bank accounts
- personal communications
- credit records
- geolocation data
- health data
- personal information of children under 14 years old
The filing materials should include the following information on the sensitive personal information being collected:
- purpose
- volume
- method
- scope
- type
- retention period
In most of the circumstances, prior to sharing personal information with third parties (whether in or outside China), network operators must assess the security risks associated with such data sharing and obtain consents from the data subjects.
In some circumstances of transferring personal information outside China (including remote access from overseas), the operators are required to either pass a mandatory security assessment by CAC, sign a CAC standard contract with their overseas recipients, or obtain the security certification from a designated institution.