Graham Webster
Research Scholar, Program on Geopolitics, Technology, and Governance, Stanford University
New actors are collecting and handling sensitive personal information, and the Cyberspace Administration of China is reiterating data rules
In its fight against the outbreak of a novel coronavirus (recently designated COVID-19 by the World Health Organization), China’s government has mobilized efforts at all levels. Successful infectious disease surveillance, however, requires collecting and handling large amounts of sensitive personal information about patients, potential cases, and the people and circumstances around them.
The Cyberspace Administration of China (CAC) on February 9 published a notice (translated in full below) reiterating responsibilities for personal information protection and emphasizing existing rules and regulations, including China’s Cybersecurity Law, which includes rules on personal information protection, and the Personal Information Security Specification, which provides details on how best to handle specific practices around personal information. These references are part of a growing data governance regime led by CAC. The document also calls for concerted efforts to use big data analysis to monitor the outbreak.
This document largely reiterates existing rules, but as Yan Luo writes for the law firm Covington, disease response is distributing new responsibilities for information collection and reporting throughout society. Moreover, China's data protection regulations often include broad exemptions for national emergencies, and this notice could provide some limiting guidance around those exemptions. As such, the notice flags relevant principles around purpose limitation, minimum necessary scope for data collection, and data protection for these new actors. And it reminds data handlers from the private sector and, especially, security authorities (see item 6) that there are legal consequences for mishandling personal information.
The translation below is by Rui Zhong and Rogier Creemers, with editing and introduction by Graham Webster.
Published Feb. 9, 2020
All provincial, autonomous region, and municipal cybersecurity and informatization committees, all relevant ministries and commissions of Central Committee and State bodies:
In order to protect personal information during the joint prevention and joint control of the novel coronavirus infectious pneumonia epidemic, and to vigorously use big data including personal information to support joint prevention and joint control work, with the approval of the Central Commission for Cybersecurity and Informatization, the following relevant matters are hereby notified as follows:
Cyberspace Administration of China
Feb. 4, 2020