Our PRC subsidiaries' business involves collecting and retaining certain internal and customer data. Our PRC subsidiaries also maintain information about various aspects of their operations. The integrity and protection of customer and company data is critical to our business. Our subsidiaries' customers expect that our subsidiaries will adequately protect their personal information. Our PRC subsidiaries are required by applicable laws to keep strictly confidential the personal information that they collect, and to take adequate security measures to safeguard such information.
The PRC Criminal Law, as amended by its Amendment 7 (effective on February 28, 2009) and Amendment 9 (effective on November 1, 2015), prohibits institutions, companies and their employees from selling or otherwise illegally disclosing a citizen's personal information obtained in performing duties or providing services or obtaining such information through theft or other illegal ways. On November 7, 2016, the Standing Committee of the PRC National People's Congress issued the Cyber Security Law of the PRC, or Cyber Security Law, which became effective on June 1, 2017. Pursuant to the Cyber Security Law, network operators must not, without users' consent, collect their personal information, and may only collect users' personal information necessary to provide their services. Providers are also obliged to provide security maintenance for their products and services and shall comply with provisions regarding the protection of personal information as stipulated under the relevant laws and regulations.
The Civil Code of the PRC (issued by the PRC National People's Congress on May 28, 2020 and effective from January 1, 2021) provides the legal basis for privacy and personal information infringement claims under the Chinese civil laws. PRC regulators, including the CAC, the Ministry of Industry and Information Technology, and the Ministry of Public Security, have been increasingly focused on regulation in data security and data protection.
The PRC regulatory requirements regarding cybersecurity are evolving. For instance, various regulatory bodies in China, including the CAC, the Ministry of Public Security and the State Administration for Market Regulation, have enforced data privacy and protection laws and regulations with varying and evolving standards and interpretations. In April 2020, the Chinese government promulgated Cybersecurity Review Measures, which came into effect on June 1, 2020. According to the Cybersecurity Review Measures, operators of critical information infrastructure must pass a cybersecurity review when purchasing network products and services which do or may affect national security.
In December 2021, the CAC and other related authorities promulgated the revised Cybersecurity Review Measures, which came into effect on February 15, 2022. The revised Cybersecurity Review Measures propose the following key changes:
- online platform operators who are engaged in data processing are also subject to the regulatory scope;- the CSRC is included as one of the regulatory authorities for purposes of jointly establishing the state cybersecurity review working mechanism;- the online platform operators holding more than one million users' individual information and seeking a listing outside China shall file for cybersecurity review with the Cybersecurity Review Office; and - the risks of core data, material data or large amounts of personal information being stolen, leaked, destroyed, damaged, illegally used or transmitted to overseas parties and the risks of critical information infrastructure, core data, material data or large amounts of personal information being influenced, controlled or used maliciously shall be collectively taken into consideration during the cybersecurity review process.
Certain internet platforms in China have reportedly become subject to heightened regulatory scrutiny in relation to cybersecurity matters. As of the date of this Report, we have not been included within the definition of "operator of critical information infrastructure" by a competent authority, nor have we been informed by any PRC governmental authority of any requirement that we file for a cybersecurity review. However, if we are deemed to be a critical information infrastructure operator or an online platform operator that is engaged in data processing and holds personal information of more than one million users, we could be subject to PRC cybersecurity review in the future.
As there remains significant uncertainty in the interpretation and enforcement of relevant PRC cybersecurity laws and regulations, we could be subject to cybersecurity review. In addition, we could become subject to enhanced cybersecurity review or investigations launched by PRC regulators in the future. Any failure or delay in the completion of the cybersecurity review procedures or any other non-compliance with the related laws and regulations may result in fines or other penalties, including suspension of business, website closure and revocation of prerequisite licenses, as well as reputational damage or legal proceedings or actions against us and/or our PRC subsidiaries, which may have material adverse effect on our business, financial condition or results of operations. As of the date of this Report, we and our PRC subsidiaries have not been involved in any investigations on cybersecurity review initiated by the CAC or related governmental regulatory authorities, and we and our PRC subsidiaries have not received any inquiry, notice, warning, or sanction in such respect.
On June 10, 2021, the Standing Committee of the National People's Congress of China, or the SCNPC, promulgated the PRC Data Security Law, which took effect in September 2021. The PRC Data Security Law imposes data security and privacy obligations on entities and individuals carrying out data activities, and introduces a data classification and hierarchical protection system based on the importance of data in economic and social development, and the degree of harm it will cause to national security, public interests, or legitimate rights and interests of individuals or organizations when such data is tampered with, destroyed, leaked, illegally acquired or used. The PRC Data Security Law also provides for a national security review procedure for data activities that may affect national security and imposes export restrictions on certain data an information.
As of the date of this Report, we do not expect that the current PRC laws on cybersecurity or data security would have a material adverse impact on our business operations. However, as the scope of the PRC Data Security Law is broad and includes the collection, storage, use, processing, transmission, availability and disclosure of data, among others, and uncertainties remain regarding the interpretation and implementation of these laws and regulations, we cannot assure you that we and our PRC subsidiaries will comply with such regulations in all respects and we and/or our PRC subsidiaries may be ordered to rectify or terminate any actions that are deemed illegal by regulatory authorities. Any directly liable person within our Company for violations or alleged violations of the PRC Data Security Law may become subject to fines. We and/or our PRC subsidiaries may also become subject to fines and/or other sanctions that may have material adverse effect on our business, operations and financial condition.
On September 24, 2024, the CAC released the Administrative Regulations on the Network Data Security, or the Data Security Regulations, which will become effective on January 1, 2025. The Data Security Regulations may apply to the use of networks to carry out data processing activities and the supervision and administration of network data security in mainland China and apply to activities outside mainland China to process personal information of any natural persons in mainland China under any of the following circumstances: (i) for the purpose of providing products or services to natural persons in mainland China; (ii) analyze and evaluate the behavior of natural persons in mainland China; and (iii) other circumstances stipulated by laws and administrative regulations. The Data Security Regulations further stipulate that where it is indeed necessary to transfer "important data" collected and generated by a network data processor during its operation within the territory of mainland China to overseas parties, it shall pass the security assessment for cross-border data transfer organized by the CAC. Network data processors should identify and declare "important data" in accordance with the relevant provisions, but they are not required to conduct security assessment for outbound data transfer for data that has not been notified or published as "important data" by relevant departments or regions. In addition, the Data Security Regulations provides that data processors that process "important data" must conduct an annual data security assessment with regard to the data process activities, and submit the assessment report to relevant competent authorities at or above the provincial level. Since the Data Security Regulations is newly promulgated, there remains uncertainty as to how it will be implemented and interpreted by the competent authorities and whether the PRC regulatory agencies, including the CAC, will adopt new laws, regulations, rules, or detailed implementation and interpretation related to security assessment. We cannot predict the impact of the Data Security Regulations on us, if any, at this stage, and we will closely monitor and assess any development in the implementation and interpretation of the Data Security Regulations. Even though we do not believe our business activities fall under the scope of Data Security Regulations, in the event that a competent PRC governmental authority concludes otherwise, we face uncertainties as to whether such clearance can be timely obtained, or at all.