On 14 November 2024, ACFE China and Llinks Law Offices jointly hosted the 'Regulations on Network Data Security Management' Seminar at Llinks Beijing office.

The 'Regulations on Network Data Security Management' (the 'Network Data Regulations'), issued by Decree No. 790 of the State Council of the People's Republic of China on 30 September 2024, will take effect on January 1, 2025. This seminar was specially organised as an offline salon event to provide interpretations and share experiences related to the Network Data Regulations, aiming to strengthen network data security management and foster a safer environment for the development of the digital economy.

The event commenced with opening remarks from Ms. Yuhua Hu, President of ACFE Beijing, and Mr. Yi Wang, Managing Partner of Llinks Beijing Office, who officially kicked off the seminar on behalf of the organisers. Subsequently, Llinks Partners Dr. David Pan and Mr. Nigel Zhu, as well as Llinks Senior Associate Ms. Susan Deng from Llinks Law Offices, along with representatives from various enterprises, provided in-depth analysis and practical operation guidance for compliance in the era following the 'Network Data Regulations'. They covered topics including an overview of the regulations, AIGC, critical data, compliance with security incidents, personal information auditing, and personal information compliance, drawing on their extensive experience to help enterprises with network data security management and sustainable development in the digital economy.

Dr. David Pan focused on the theme 'Overview and Key Points of the 'Regulations on Network Data Security Management'', sharing insights on the legislative process and system, scope of application, key obligations, and regulatory burden reduction. Dr. Pan first briefly introduced the journey and considerations behind the finalisation of the Network Data Regulations after three years, noting that they are a refinement, supplement, and improvement based on the 'Cybersecurity Law', 'Data Security Law', and 'Personal Information Protection Law'. He then emphasised the scope, framework, and basic concepts such as 'network data' and 'network data processors' in the Network Data Regulations, providing clear explanations of difficult points to provoke further thought among the attendees.

In particular, addressing the widespread corporate concern over compliance obligations in the post-Network Data Regulations era, Dr. Pan combined his rich practical experience and typical cases to outline key points for enterprises to consider in areas such as web crawling and AI, network platform services, personal information protection, critical data, cross-border data flows, and network data security incidents. He provided a wealth of practical advice for enterprises. Finally, Dr. Pan highlighted the regulatory 'burden reduction principle' established by the Network Data Regulations, expressing anticipation for the effective reduction of corporate compliance burdens following their implementation.

Against the backdrop of the imminent post-Network Data Regulations era, Ms. Susan Deng shared her practical experience on the topic of 'Personal Information Compliance and Auditing in the Post-'Network Data Regulations' Era'. In the first part, facing the issue of how enterprises should deal with personal information compliance, Ms. Deng emphasised new changes and trends in legislation and regulation regarding personal information compliance. She specifically introduced the listing requirements for personal information processing rules, the refinement of individual consent rules, circumstances exempt from separate consent, the regulation of automated data collection tools like web crawlers, the provision, commissioning, and joint processing of personal information, the specific conditions for individuals to exercise 'portability rights', the conditions for personal information going abroad, special obligations related to large network platforms, and a series of key personal information compliance issues that are crucial to the interests and needs of enterprises. Building on the Network Data Regulations' reaffirmation and refinement of the legal obligations for personal information auditing, in the second part, Ms. Deng, drawing on her extensive practical experience, pointed out the value of personal information auditing for enterprises and provided a detailed explanation of the ways to conduct audits, regulatory requirements, main steps, process design, team building, and content highlights, offering suggestions for enterprises' future personal information auditing work based on specific data processing scenarios. Ms. Deng also specifically explained the key points of compliance rectification and the implementation of rectification measures, providing a compliance enhancement approach on how to describe the current situation and evaluate gaps based on audit results and accordingly improve systems.

Mr. Nigel Zhu focused on the theme 'Struggling with AIGC, Critical Data, and Security Event Compliance? – The 'Network Data Regulations' Have the Answers', introducing key points and experiences in compliance management for important data, network security event response, AIGC, and network platform services under the Network Data Regulations. Mr. Zhu first sorted out the definition and evolution of critical data, using the identification of critical data as a starting point, and discussed in detail the identification, reporting process, and data export security assessment obligations of critical data, emphasising the responsibilities of data security officers and management institutions, and specifying special risk assessments, annual risk assessments, and reporting and other critical data compliance obligations. On network security event response, Mr. Zhu sorted out the reporting obligations and time limits of network security events based on related definitions and classifications, and discussed with the guests the grading of network security events and the criteria for judging the degree of harm, proposing suggestions for building a crisis response management system and the implementation of security event response systems. Regarding AIGC compliance governance, Mr. Zhu analysed the compliance issues and key points of AIGC in model training, user input, and model output stages, emphasising in particular the compliance risks of copyright infringement and personal information rights infringement of crawled data, content compliance, and information leaks. Finally, Mr. Zhu reviewed the personal information compliance obligations of large Internet companies, comparing the EU's regulatory requirements for 'gatekeeper' platforms, and systematically introduced the definition of large network platforms and their compliance obligations in the Network Data Regulations.

This event drew a crowd of legal professionals from a diverse range of sectors, including insurance, banking, investment funds, automotive, education, and retail. Together, speakers and attendees engaged in discussions around the seminar's theme, enhancing their understanding of the opportunities and challenges that network data security presents for businesses. The exchange was warm and interactive. Moving forward, Llinks remains committed to upholding the principles of professionalism and pragmatism, staying attuned to the latest industry developments and hot topics, and offering a variety of forums, including seminars, where industry professionals can engage in broad and meaningful dialogues.