For years, China’s cross-border data transfer regime was long on rules but short on consequences. Companies—both foreign and domestic—were given a relatively extended period to understand the requirements, formulate suitable strategies, and implement compliance measures. Recent enforcement actions led by the Cyberspace Administration of China (CAC), the country’s data regulator, suggest that the education phase

Continue Reading CHINA: China’s Data Regulator Means Business – The Education Phase Is Over

The Cyberspace Administration of China (“CAC“) has recently published the Administrative Measures for Network Security Incident Reporting (“Measures“), which provide further guidance on when and how to report network security incidents under existing laws such as the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law. The Measures

Continue Reading CHINA: new stricter and 4-hour data breach reporting requirements for certain incidents