A foreign trade e-commerce platform operated by Chinese company J obtained approval through the Cyberspace Administration of China’s data export security assessment. In its introduction, J stated that the platform has millions of Chinese suppliers and tens of millions of global buyer members, making it a large-scale and highly representative cross-border e-commerce platform.
(I) Applicable Scenarios for Using the Standard Contract in Cross-Border E-Commerce
According to Article 4 of the Measures on the Standard Contract for the Export of Personal Information, in general, a personal information processor may provide personal information overseas by entering into a standard contract only if all of the following conditions are met at the same time: 1) it is not a critical information infrastructure operator; 2) it processes the personal information of fewer than 1 million individuals; 3) since January 1 of the previous year, it has cumulatively provided the personal information of fewer than 100,000 individuals overseas; and 4) since January 1 of the previous year, it has cumulatively provided sensitive personal information of fewer than 10,000 individuals overseas. In practice, enterprises need to determine whether they may provide personal information overseas by signing a standard contract based on multiple factors, including their entity status, the export scenario, and the volume of personal information involved.
(II) General Steps for Signing the Standard Contract
The general steps for signing the standard contract are as follows:
(1) Conduct a personal information protection impact assessment: Before providing personal information overseas, the personal information processor should assess the scale, scope, type, sensitivity, and other relevant aspects of the personal information to be exported, so as to ensure the legality and security of the cross-border transfer activity.
(2) Negotiate and sign the standard contract: The personal information processor and the overseas recipient should fully communicate and supplement the contractual terms as necessary, and formally sign the standard contract after reaching agreement on its contents. The contract should clearly specify key matters such as the purpose, scope, type, sensitivity, quantity, method, retention period, and storage location of the personal information to be transferred overseas, as well as the rights and obligations of both parties.
(3) Regulatory filing: Within 10 working days from the effective date of the standard contract, the personal information processor should submit a filing application to the provincial-level cyberspace administration authority in its place of domicile, together with the signed standard contract and the personal information protection impact assessment report. Only after the filing is successfully completed may the cross-border transfer activity be formally carried out.
(4) Follow-up and reassessment after implementation: During the course of the cross-border transfer activity, if circumstances arise that may affect data export security — such as changes in the personal information export situation or changes in the personal information protection laws and regulations of the country or region where the overseas recipient is located — the personal information processor must conduct a new personal information protection impact assessment and, where necessary, supplement or re-enter into the standard contract and complete the corresponding filing procedures.
These steps are intended to ensure the legality and security of personal information during cross-border transmission and to protect the rights and interests of personal information subjects. At the same time, as cross-border personal information transfer activities continue, personal information processors must maintain ongoing monitoring and management of such activities to ensure continued compliance with relevant laws and regulations.
Guozun Law Firm believes that the above steps are intended to ensure the legality and security of personal information during cross-border transmission and to protect the rights and interests of personal information subjects. At the same time, as cross-border personal information transfer activities continue, personal information processors must maintain ongoing monitoring and management of such activities to ensure continued compliance with relevant laws and regulations.