{"id":8168,"date":"2021-11-03T09:56:43","date_gmt":"2021-11-02T20:56:43","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=8168"},"modified":"2021-11-03T09:56:43","modified_gmt":"2021-11-02T20:56:43","slug":"does-the-new-chinese-pipl-law-apply-to-you","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=8168","title":{"rendered":"Does the new Chinese PIPL law apply to you?"},"content":{"rendered":"\n\n[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<h2>If you do business in China, you need to know about the \u201cPIPL\u201d<\/h2>\n<p>It\u2019s the Chinese equivalent of the GDPR from the EU \u2013 and your responsibility to protect the data privacy of the Chinese.<\/p>\n<p>The law came into being relatively quickly and has already taken effect as at November 1st 2021. However, as this stage it appears to be mainly a framework and there will be further regulations emerging across specific sectors that relate back to these requirements.<\/p>\n<p>If you are already working in Europe and complying with the GDPR, then you probably just need to apply those regimes to data that relates to Chinese citizens as well. (\u201call information related to identified or identifiable natural persons\u201d)<\/p>\n<p>We\u2019ve taken the following table from an excellent analysis at the<a href=\"https:\/\/iapp.org\/news\/a\/analyzing-chinas-pipl-and-how-it-compares-to-the-eus-gdpr\/\"> International Association of Privacy Professionals (IAPP) <\/a><\/p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; column_structure=&#8221;3_5,2_5&#8243;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<table width=\"595\" style=\"border-style: solid; width: 595px;\">\n<tbody>\n<tr>\n<td width=\"359\"><strong>Rights under the GDPR<\/strong><\/td>\n<td width=\"236\"><strong>Rights under the PIPL<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"359\">Right to information<\/td>\n<td width=\"236\"><strong>\u221a<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"359\">Right to access<\/td>\n<td width=\"236\"><strong>\u221a<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"359\">Right to correction\/rectification<\/td>\n<td width=\"236\"><strong>\u221a<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"359\">Right to erasure<\/td>\n<td width=\"236\"><strong>\u221a<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"359\">Right to object to and restrict the processing of an individual\u2019s data<\/td>\n<td width=\"236\"><strong>\u221a<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"359\">Right to data portability<\/td>\n<td width=\"236\"><strong>\u221a\u00a0<\/strong>(but needs to satisfy conditions stipulated by the Cyberspace Administration of China)<\/td>\n<\/tr>\n<tr>\n<td width=\"359\">Right not to be subject to automated decision-making<\/td>\n<td width=\"236\"><strong>\u221a<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"359\">Right to withdraw consent<\/td>\n<td width=\"236\"><strong>\u221a<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"359\">Right to lodge a complaint with the regulator<\/td>\n<td width=\"236\"><strong>\u221a<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_5&#8243; _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;http:\/\/kinetics.co.nz\/wp-content\/uploads\/2021\/11\/PIPL.jpg&#8221; _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; title_text=&#8221;PIPL&#8221; hover_enabled=&#8221;0&#8243; sticky_enabled=&#8221;0&#8243;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.11.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<h4>As with other data privacy regimes, it is important to consider the information you hold, and the obligations on it.<\/h4>\n<p>Do you know :<\/p>\n<ul>\n<li>What data you hold?<\/li>\n<li>Why you hold it? (Is there data you hold that is \u2018nice to have\u2019 rather than necessary)<\/li>\n<li>Where it is held?<\/li>\n<li>Who should have access to it, and who does have access to it?<\/li>\n<li>Do the people with access understand their obligations?<\/li>\n<\/ul>\n<p><strong>These considerations, and others, are part of the data governance considerations of a <a href=\"http:\/\/kinetics.co.nz\/flightplan\/\">FlightPlan<\/a> \u2013 contact your account manager for more information.<\/strong><\/p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]\n\n","protected":false},"excerpt":{"rendered":"<p>If you do business in China, you need to know about the \u201cPIPL\u201d It\u2019s the Chinese equivalent of the GDPR from the EU \u2013 and your responsibility to protect the data privacy of the Chinese. The law came into being relatively quickly and has already taken effect as at November 1st 2021. However, as this [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":8169,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-8168","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/8168","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8168"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/8168\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8168"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8168"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8168"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}