Llinks recently had several of its lawyers successfully pass the first national certification for Personal Information Protection Compliance Auditors, administered by the Cyberspace Security Association of China. The firm now has one Advanced Compliance Auditor and ten Intermediate Compliance Auditors, who are qualified to conduct personal information protection compliance audits for companies that handle the personal information of over 10 million people, in accordance with the Practical Guidelines for Cybersecurity Standards—Personal Information Protection Compliance Audit Requirements.
Name
Qualification
David Pan
Advanced Compliance Auditor
Jane Chen
Intermediate Compliance Auditor
Tracy Chen
Intermediate Compliance Auditor
Susan Deng
Intermediate Compliance Auditor
Daisy Ding
Intermediate Compliance Auditor
Nancy Gao
Intermediate Compliance Auditor
Raymond Li
Intermediate Compliance Auditor
Yiran Li
Intermediate Compliance Auditor
Shana Sha
Intermediate Compliance Auditor
Lily Yuan
Intermediate Compliance Auditor
Eric Zuo
Intermediate Compliance Auditor
This achievement highlights Llinks' professional expertise and talent in data compliance, demonstrating the team's comprehensive strength in meeting increasingly complex compliance requirements.
For many years, Llinks has focused on data compliance and cybersecurity legal practice, actively participating in industry standard discussions and system development to provide clients with forward-looking, end-to-end compliance solutions. Having multiple lawyers certified at the intermediate and advanced levels simultaneously is not only a testament to their individual expertise but also showcases Llinks' systematic and well-structured approach to talent cultivation in this field.
Llinks' Specialized Personal Information Compliance Audit Service
The Personal Information Protection Law and the Regulations on the Management of Network Data Security both require personal information handlers to conduct regular compliance audits. Starting May 1, 2025, the Personal Information Protection Compliance Audit Management Measures officially came into effect. According to these measures, there are two types of audits:
Regular Audits: Handlers of personal information for over 10 million people must conduct an audit at least once every two years, while other handlers can schedule their audits more flexibly. Audits can be conducted in-house or by a third-party professional firm.
Mandatory Audits: If regulatory authorities find significant risks, potential infringement of numerous individuals' rights, or a security incident has occurred, they can require the handler to commission a professional firm to complete an audit within a specified period.
By law, all personal information handlers must conduct a personal information audit. Regular audits not only satisfy compliance requirements but also help companies identify risks, improve management practices, and raise internal awareness of personal information protection.
Llinks' specialized personal information protection compliance audit service aims to establish and improve a company's personal information security management system, covering the entire process from data collection to storage, processing, and destruction. Our service helps companies systematically identify and manage personal information security risks, ensuring that all data processing activities are compliant.
Project Goals:
Risk Management: Prevent data leaks, litigation risks, and reputational damage, and provide proof of a sound system in the event of a security incident or data infringement.
Gap Analysis: Identify compliance vulnerabilities through an audit and improve the data governance system.
Build Trust: Enhance trust with business partners and consumers.
Our Strengths:
Comprehensive Coverage: Full-spectrum experience in personal information compliance across various industries (consumer goods, manufacturing, automotive, pharmaceuticals, healthcare, finance) and scenarios.
Extensive Experience: Over 15 years of experience in full-scenario data compliance audit projects, with a team that meets standard requirements.
Certified Professionals: Multiple team members hold professional certifications such as CIPP, CISSP, and PIPCA.
Recognized Leader: A leading team in the field, as recognized by major legal ranking directories like Chambers and Partners, The Legal 500, ALB, and LEGALBAND.
Industry Leadership: Recently joined the National Technical Committee for Information Standardization as a member of the Data Governance Standards Working Group.