The Cyberspace Administration of China has released the Measures for the Administration of Compliance Audits on Personal Information Protection.
Release Date:
2025-02-15
BEIJING, Feb. 14 (Xinhua) — A reporter learned on the 14th from the Cyberspace Administration of China that the agency has recently issued the Measures for the Administration of Compliance Audits on Personal Information Protection. The measures aim to provide systematic, targeted, and practical guidelines for personal information processors conducting compliance audits, thereby enhancing the legality and compliance of personal information processing activities and safeguarding individuals’ rights and interests in their personal information.
An official from the Cyberspace Administration of China stated that, at present, personal information is being extensively collected and used by enterprises, institutions, and even individuals, leading to increasingly acute tensions between the protection of personal information and its utilization. To ensure that personal information processors assume their primary responsibility for safeguarding personal data and to strengthen risk management and oversight of personal information processing activities, the Personal Information Protection Law and the Regulations on the Security Management of Network Data both stipulate requirements for conducting compliance audits of personal information processing. To effectively implement these legal and regulatory provisions, the Cyberspace Administration of China has formulated and promulgated measures that provide detailed rules on the conduct of personal information protection compliance audits, the selection of auditing bodies, the frequency of such audits, and the obligations of personal information processors and specialized agencies in the audit process.
The Measures specify two scenarios under which personal information processors are required to conduct compliance audits. First, when a personal information processor conducts a compliance audit on its own, it shall have its internal department or a designated professional institution carry out regular audits to ensure that its processing of personal information complies with laws and administrative regulations. Personal information processors that handle the personal information of more than 10 million individuals must conduct a personal information protection compliance audit at least once every two years. Second, if the authorities responsible for overseeing personal information protection identify significant risks in personal information processing activities, potential infringements upon the rights and interests of a large number of individuals, or occurrences of personal information security incidents, they may require the personal information processor to engage a professional institution to conduct a compliance audit of its personal information processing activities.
The Measures shall come into force on May 1, 2025.
[Editor-in-charge: Wang Xue]
Source: Xinhua Net
Tags:
More information
Contact Us
Address:
No. 1, No. 1, New District Road No. 1, Gaocheng District, Shijiazhuang City, Hebei Province
WeChat/WhatsApp:
Phone:
Email: