Historically, our PRC subsidiary, Kuaidian Power Beijing, operated Kuaidian. As part of the Restructuring, the ownership of Kuaidian as well as the rights to access and use certain data generated by or in the possession of Kuaidian have been transferred to a third-party service provider as of the date of this annual report. NaaS entered into a business cooperation agreement with the third-party service provider, pursuant to which NaaS will receive certain services from such operator in relation to the delivery of EV charging solutions.
We and the third-party service provider face challenges with respect to the complex and evolving laws and regulations regarding cybersecurity and data privacy in China, including without limitation, the PRC Criminal Law, PRC Civil Code, PRC Cybersecurity Law, PRC Data Security Law, and PRC Personal Information Protection Law. These laws and regulations mandate the protection of the confidentiality, integrity, availability, and authenticity of the information of end-users. While we believe the third-party service provider has adopted information security policies and deployed measures to implement the policies, there could be compromise or breach of its information system due to increased level of expertise of hackers or otherwise. If the third-party service provider is unable to protect its systems, and hence the information stored in its systems, from unauthorized access, use, disclosure, disruption, modification, or destruction, such problems or security breaches could cause the termination or suspension of the business of the third-party service provider or otherwise result in material adverse impact on its operations and thereby its collaborative arrangement with us. This could in turn have material adverse impact on our business, prospects, financial condition and operating results.
The PRC Criminal Law, as most recently amended on March 1, 2024, prohibits institutions, companies and their employees from selling or otherwise illegally disclosing a PRC citizen's personal information obtained during the course of performing duties or providing services, or obtaining such information through theft or other illegal ways. On November 7, 2016, the Standing Committee of the National People's Congress of the PRC issued the PRC Cyber Security Law, which became effective on June 1, 2017. Pursuant to the Cyber Security Law, network operators must not collect users' personal information without their consent and may only collect users' personal information necessary to the provision of services. Providers are also obligated to provide security maintenance for their products and services and to comply with provisions regarding the protection of personal information as stipulated under the applicable laws and regulations. On September 14, 2022, CAC issued a proposed revision of the Cyber Security Law, purporting to increase fines for serious violations of up to RMB 50 million or 5% of annual revenues from the prior year. The PRC Civil Code (issued by the National People's Congress of the PRC on May 28, 2020, and effective from January 1, 2021) provides the main legal basis for privacy and personal information infringement claims under Chinese civil law.
PRC regulators have been increasingly focused on regulation in areas of data security and data protection. The PRC regulatory requirements regarding cybersecurity are constantly evolving. For instance, various regulatory bodies in China, including CAC, the Ministry of Industry and Information Technology, the Ministry of Public Security and the State Administration for Market Regulation, have enforced data privacy and protection laws and regulations with varying and evolving standards and interpretations. In addition, certain Internet platforms in China have reportedly been subject to heightened regulatory scrutiny in relation to cybersecurity matters.
In April 2020 the Chinese government promulgated the Cybersecurity Review Measures, which came into effect on June 1, 2020. On December 28, 2021, the Chinese government promulgated the 2022 Cybersecurity Review Measures, which came into effect on February 15, 2022. According to the 2022 Cybersecurity Review Measures, (i) critical information infrastructure operators' purchase of network products and services and internet platform operators' data processing activities shall be subject to cybersecurity review in accordance with the 2022 Cybersecurity Review Measures if such activities affect or may affect national security; and (ii) internet platform operators holding personal information of more than one million users and seeking to have their securities listed on a stock exchange in a foreign country are required to file for cybersecurity review with the Cybersecurity Review Office. Under the Regulation on Protecting the Security of Critical Information Infrastructure promulgated by the State Council on July 30, 2021, effective September 1, 2021, "critical information infrastructure" is defined as important network facilities and information systems in important industries and fields, such as public telecommunication and information services, energy, transportation, water conservancy, finance, public services, e-government and national defense, science, technology and industry, as well as other important network facilities and information systems that, in case of destruction, loss of function or leak of data, may severely damage national security, the national economy and the people's livelihood and public interests. As of the date of this annual report, neither we nor the third-party service provider has been informed by any PRC governmental authority that we or it operates any "critical information infrastructure."
The 2022 Cybersecurity Review Measures provides, among others, that: (i) internet platform operators who are engaged in data processing are also subject to the regulatory scope; (ii) CSRC is included as one of the regulatory authorities for purposes of jointly establishing the state cybersecurity review mechanism; (iii) internet platform operators holding personal information of more than one million users and seeking to have their securities list on a stock exchange in a foreign country shall file for cybersecurity review with the Cybersecurity Review Office; (iv) the risks of core data, important data or large amounts of personal information being stolen, leaked, destroyed, damaged, illegally used or illegally transmitted to overseas parties and the risks of critical information infrastructure, core data, important data or large amounts of personal information being influenced, controlled or used maliciously by foreign governments and any cybersecurity risk associated with a company's listing on a stock exchange shall be collectively taken into consideration during the cybersecurity review process; and (v) critical information infrastructure operators and internet platform operators covered by the 2022 Cybersecurity Review Measures shall take measures to prevent and mitigate cybersecurity risks in accordance with the requirements therein. On November 14, 2021, CAC released the draft Administrative Regulation on Network Data Security for public comments through December 13, 2021. Under the daft regulation, (i) data processors, i.e., individuals and organizations who can decide on the purpose and method of their data processing activities at their own discretion, that process personal information of more than one million individuals shall apply for cybersecurity review before listing in a foreign country; (ii) overseas data processors shall carry out annual data security evaluation and submit the evaluation report to the municipal cyberspace administration authority; and (iii) where the data processor undergoes merger, reorganization or subdivision that involves important data and personal information of more than one million individuals, the transaction shall be reported to the authority in-charge at the municipal level (by data processor or data recipient).
As of the date of this annual report, neither we nor the third-party service provider has been directed by any PRC governmental authority to apply for cybersecurity review, or received any inquiry, notice, warning, sanction in such respect or been denied permission from any Chinese authority with respect to the listing on a stock exchange in any foreign country, the Mergers or the Transactions. However, as the PRC government has the authority and discretion to interpret and implement these laws and regulations and there remains uncertainty in the interpretation and enforcement of PRC cybersecurity laws and regulations, there is no assurance that we or the third-party service provider will not be deemed to be subject to PRC cybersecurity review requirements under the 2022 Cybersecurity Review Measures or the Draft Administrative Regulations on Network Data Security (if enacted) as a critical information infrastructure operator or an interact platform operator that is engaged in data processing activities that affect or may affect national security or holds personal information of more than one million users, nor can it be assured that we or the third-party service provider would be able to pass any cybersecurity review if required. In addition, we and the third-party service provider could become subject to enhanced cybersecurity review or investigations launched by PRC regulators in the future pursuant to any new laws, regulations or policies. Any failure or delay in the completion of the cybersecurity review or any other non-compliance with applicable laws and regulations may result in fines, suspension of business, prospects, website closure, revocation of business licenses or other penalties, as well as reputational damage or legal proceedings or actions against us or the third-party service provider, which may have a material adverse effect on our business, financial condition and results of operations.
On June 10, 2021, the Standing Committee of the National People's Congress of the PRC, promulgated the PRC Data Security Law, which became effective in September 2021. The PRC Data Security Law imposes data security and privacy obligations on entities and individuals carrying out data activities, and introduces a data classification and hierarchical protection system based on the importance of data in economic and social development and the degree of harm it will cause to national security, public interests or the rights and interests of individuals or organizations when such data is tampered with, destroyed, leaked or illegally acquired or used. The PRC Data Security Law also provides for a national security review procedure for data activities that may affect national security and imposes export restrictions on certain data and information. On August 20, 2021, the Standing Committee of the National People's Congress promulgated the Personal Information Protection Law, effective November 1, 2021. The Personal Information Protection Law clarifies the required procedures for personal information processing, the obligations of personal information processors, and individuals' personal information rights and interests. The Personal Information Protection Law provides that, among other things, (i) the processing of personal information is only permissible under certain circumstances, such as prior consent from the subject individual, fulfillment of contractual and legal obligations, furtherance of public interests or other circumstances prescribed by laws and regulations; (ii) the processing of personal information should be conducted in a disciplined manner with as little impact on individuals' rights and interests as possible, and (iii) excessive collection of personal information is prohibited. In particular, the Personal Information Protection Law provides that personal information processors should ensure the transparency and fairness of automated decision-making based on personal information, refrain from offering unreasonably differentiated transaction terms to different individuals and, when sending commercial promotions or information updates to individuals selected through automated decision-making, simultaneously offer such individuals an option not based on such individuals' specific characteristics or a more convenient way for such individuals to turn off such promotions.
On July 7, 2022, CAC promulgated the Measures on Security Assessment of Cross-border Data Transfer which became effective on September 1, 2022. Such data export measures requires that any data processor which processes or exports personal information exceeding certain volume threshold under such measures shall apply for security assessment by CAC before transferring any personal information abroad, including the following circumstances: (i) important data will be provided overseas by any data processor; (ii) personal information will be provided overseas by any operator of critical information infrastructure or any data processor who processes the personal information of more than 1,000,000 individuals; (iii) personal information will be provided overseas by any data processor who has provided the personal information of more than 100,000 individuals in aggregate or has provided the sensitive personal information of more than 10,000 individuals in aggregate since January 1 of last year; and (iv) other circumstances where the security assessment is required as prescribed by CAC. The security assessment requirement also applies to any transfer of important data outside of China.
The Ministry of Industry and Information Technology promulgated the Administrative Measures on Data Security in the Field of Industry and Information Technology (for Trial Implementation), effect on January 1, 2023. The Measures applies to the data processing activities in the field of industry and information technology carried out within the territory of China, and sets out a series of data security protection obligations for data processors in such field, such as establishing a full life-cycle data security management system, appointing data security management personnel, and conducting filings for the important data and core data processed by the data processors.
Pursuant to the 2022 Cybersecurity Review Measures, we conducted a self-assessment with respect to the status of our compliance with the Cyber Security Law, the Data Security Law, the Personal Information Protection Law, and the implementing regulations and we implemented various measures to improve the overall compliance level. We are of the view that our existing practices are compliant with applicable requirements imposed under the foregoing laws, rules and regulations, including the regulations or policies that have been issued by CAC to date, in all material respects. However, regulatory requirements on cybersecurity and data privacy are evolving and can be subject to varying interpretations or significant changes. While NaaS transferred the ownership of Kuaidian as well as the rights to access and use certain data generated by or in the possession of Kuaidian to the third-party service provider and despite our efforts to comply with laws and regulations relating to privacy, data protection and information security, there is no guarantee that the current security measures, practices and operations of ours and of the third-party service provider are and will remain compliant with applicable laws. In the event of non-compliance or any compromise of security that results in unauthorized access, use or release of personally identifiable information or other data, or the perception or allegation that any of the foregoing types of failure or compromise has occurred, our reputation could be harmed and we may be subject to investigations and penalties by PRC governmental authorities, including fines, suspension of business, and revocation of required licenses, as well as private claims and litigations, any of which could materially and adversely affect our business, prospects, financial condition and operating results and could result in a material impact on the value of our securities.