China has implemented or will implement rules and is considering a number of additional proposals relating to data protection. China's new Data Security Law promulgated by the Standing Committee of the National People's Congress of China in June 2021, or the Data Security Law, took effect in September 2021. The Data Security Law provides that the data processing activities must be conducted based on "data classification and hierarchical protection system" for the purpose of data protection and prohibits entities in China from transferring data stored in China to foreign law enforcement agencies or judicial authorities without prior approval by the Chinese government.
Additionally, China's Cyber Security Law, requires companies to take certain organizational, technical and administrative measures and other necessary measures to ensure the security of their networks and data stored on their networks. Specifically, the Cyber Security Law provides that China adopt a multi-level protection scheme (MLPS), under which network operators are required to perform obligations of security protection to ensure that the network is free from interference, disruption or unauthorized access, and prevent network data from being disclosed, stolen or tampered. Under the MLPS, entities operating information systems must have a thorough assessment of the risks and the conditions of their information and network systems to determine the level to which the entity's information and network systems belong-from the lowest Level 1 to the highest Level 5 pursuant to the Measures for the Graded Protection and the Guidelines for Grading of Classified Protection of Cyber Security. The grading result will determine the set of security protection obligations that entities must comply with. Entities classified as Level 2 or above should report the grade to the relevant government authority for examination and approval.
Recently, the Cyberspace Administration of China (the "CAC") has taken action against several Chinese internet companies in connection with their initial public offerings on U.S. securities exchanges, for alleged national security risks and improper collection and use of the personal information of Chinese data subjects. According to the official announcement, the action was initiated based on the National Security Law, the Cyber Security Law and the Measures on Cybersecurity Review, which are aimed at "preventing national data security risks, maintaining national security and safeguarding public interests." On July 10, 2021, the CAC published a revised draft of the Measures on Cybersecurity Review, expanding the cybersecurity review to data processing operators in possession of personal information of over 1 million users if the operators intend to list their securities in a foreign country.
We do not believe we are among the "operator of critical information infrastructure" or "data processor" as mentioned above. Based on the above and our understanding of the Chinese laws and regulations currently in effect as of the date of this report, we will not be required to submit an application to the CSRC or the CAC for the approval of a future offering and the listing and trading of our securities on the Nasdaq. However, the revised draft of the Measures for Cybersecurity Review is in the process of being formulated and the Opinions remain unclear on how it will be interpreted, amended and implemented by the relevant PRC governmental authorities. Thus, it is still uncertain how PRC governmental authorities will regulate overseas listing in general and whether we are required to obtain any specific regulatory approvals.
Also, on August 20, 2021, the National People's Congress passed the Personal Information Protection Law, started to be implemented on November 1, 2021. The law creates a comprehensive set of data privacy and protection requirements that apply to the processing of personal information and expands data protection compliance obligations to cover the processing of personal information of persons by organizations and individuals in China, and the processing of personal information of persons in China outside of China if such processing is for purposes of providing products and services to, or analyzing and evaluating the behavior of, persons in China. The law also proposes that critical information infrastructure operators and personal information processing entities who process personal information meeting a volume threshold to-be-set by Chinese cyberspace regulators are also required to store in China personal information generated or collected in China, and to pass a security assessment administered by Chinese cyberspace regulators for any export of such personal information. Lastly, the draft contains proposals for significant fines for serious violations of up to RMB 50 million or 5% of annual revenues from the prior year.
Interpretation, application and enforcement of these laws, rules and regulations evolve from time to time and their scope may continually change, through new legislation, amendments to existing legislation and changes in enforcement. Compliance with the Cyber Security Law and the Data Security Law could significantly increase the cost to us of providing our service offerings, require significant changes to our operations or even prevent us from providing certain service offerings in jurisdictions in which we currently operate or in which we may operate in the future. Despite our efforts to comply with applicable laws, regulations and other obligations relating to privacy, data protection and information security, and our belief that we are currently in compliance therewith, it is possible that our practices, offerings or platform could fail to meet all of the requirements imposed on us by the Cyber Security Law, the Data Security Law and/or related implementing regulations. Any failure on our part to comply with such law or regulations or any other obligations relating to privacy, data protection or information security, or any compromise of security that results in unauthorized access, use or release of personally identifiable information or other data, or the perception or allegation that any of the foregoing types of failure or compromise has occurred, could damage our reputation, discourage new and existing counterparties from contracting with us or result in investigations, fines, suspension or other penalties by Chinese government authorities and private claims or litigation, any of which could materially adversely affect our business, financial condition and results of operations. Even if our practices are not subject to legal challenge, the perception of privacy concerns, whether or not valid, may harm our reputation and brand and adversely affect our business, financial condition and results of operations. Moreover, the legal uncertainty created by the Data Security Law and the recent Chinese government actions could materially adversely affect our ability, on favorable terms, to raise capital, including engaging in follow-on offerings of our securities in the U.S. market or the Stock Exchange of Hong Kong. While we believe that our current operations are in compliance with the laws and regulations of the Cyberspace Administration of China, our operations could be adversely affected, directly or indirectly, by existing or future laws and regulations relating to its business or industry.