On the afternoon of August 28, 2026, Llinks Law Offices co-hosted a special event titled "Practical Personal Information Protection Audit: How Does a Platform with Tens of Millions of Users Pass the Audit? A Comprehensive Analysis of Legal and Technical Testing" with a professional personal information protection audit and testing institution. Using a comprehensive Internet platform with approximately 30 million registered users as a virtual case, this event fully restored the entire process of personal information protection compliance audits, from preparation and implementation to report issuance and rectification follow-up. It attracted numerous guests, including corporate legal directors, compliance heads, data security heads and Data Protection Officers (DPOs) from industries such as Internet, finance, telecommunications, e-commerce and healthcare.
Llinks partner Dr. David Pan, Mr. Nigel Zhu and Llinks contractual partner Ms. Susan Deng served as keynote speakers. Together with the co-hosting personal information protection audit and testing institution, they conducted systematic sharing centered on the legal logic and technical implementation of compliance audits.
Llinks partner Dr. David Pan first delivered a speech titled "Personal Information Protection Compliance Audit Practice and Breakthrough Strategies." Combining the regulatory posture following the implementation of the Administrative Measures for Personal Information Protection Compliance Audits, he pointed out that enterprises have entered an era of mandatory audits at the policy level, and the value of enterprise algorithm and data compliance audits has risen to a strategic level. Furthermore, focusing on specific project types, law enforcement situations in key industries and common difficulties in personal information protection audit practices, he outlined a breakthrough path of collaborative audits driven by the dual wheels of "law and technology."
Using the virtual case of the "Xingqiao Platform" (30 million registered users and three business lines) as a clue, Llinks contractual partner Ms. Susan Deng systematically broke down the four major stages of personal information protection audits: preparation, implementation, reporting and rectification tracking. Her analysis ranged from project initiation decisions, team building and preliminary sorting of data assets, to dual-track evidence collection via legal review and technical testing, grading of audit findings and report writing standards, and finally to the formulation of rectification ledgers and the closed-loop verification of effectiveness. She also provided manpower and cycle calculations for direct benchmarking—the full cycle of an initial audit takes about 12 to 16 weeks, with a core human resource input of approximately 280 to 300 person-days—giving attendees a clear understanding of "how to do it, how many people to invest and how long it takes" for personal information protection audits.
In the second half of the event, the co-hosting personal information protection audit and testing institution demonstrated the entire audit process on-site using its self-developed personal information protection audit software, showcasing a secure mode characterized by standalone operation and off-grid audit data.
Subsequently, Llinks partner Mr. Nigel Zhu provided a specialized explanation of common difficulties in audit practice. He engaged in in-depth exchanges with attending guests on topics such as how enterprises with limited resources can initiate initial audits with the minimum viable configuration, the rectification priority and implementation strategies for audit findings, the usage scenarios and disclosure risk prevention of audit reports, as well as the role positioning and value of lawyers in compliance audit projects.
Llinks has always been committed to providing practical and implementable compliance audit solutions for various enterprises. Through professional practice synergizing the dual dimensions of law and technology, Llinks assists enterprises in penetrating paper-based compliance in the era of mandatory audits, building a solid moat for data security and business operations.