On 26th April 2018, the 2nd Data Security and Privacy Protection Summit Forum directed by the China Society of Science and Technology Law, the Networking and Information Law Research Society of the China Law Society, and organized by the Network Security (China) Forum Committee and Shanghai Communications Institute, etc. was held at Hotel Equatorial Shanghai. Llinks Lawyer, YANG Xun. was invited to attend the conference and delivered a keynote speech.
The topic of YANG Xun's speech was "Tightly embracing the new era of information network: minimizing compliance cost, and maximizing potential benefits." Yang esq. pointed out: The cyber security law is not an single piece of law, nor is it a static concept, but a collection of laws and regulations in the past and in the future relating to network and data security. When considering network security legal issues, we must not only consider the "Cyber Security Law", but also consider the administrative rules and regulations related to cyber security matters, and those published industry standards and technical standards as well, including recommended standards.
Yang esq. pointed out that, for lawyers and in-house counsels who provide legal services for enterprises, compliance is certainly a cost, but it should also be regarded as an asset of future income for the company. Referring to the issue of minimizing compliance costs, Yang Xun lawyers stated that, first of all, the to perform compliance work, the first step is to scientifically determine the standards of compliance, which standard should be determined by taking into account the development of business, the development of the law, and the life cycle of business. Secondly, enterprises should consider cyber security compliance issues alongside with business planning. Finally, when a company formulates and implements a sound IT risk management system, the internal management system and policies of the safety assessment system will be conducive to the protection of corporate information security. It will also help the company to comply with regulatory requirements at a lower cost.
In the question and answer section, Yang esq. emphasized that law practice nowadays, especially in the cyber security compliance area, not only requires lawyers to understand laws, but also requires lawyers to have a deep understanding of the business and IT technology. Yang esq. used his experience in the pharmaceutical industry as an example to illustrate the significance of the combination of business knowledge and legal knowledge in assisting clients, and to raise the suggestion that law practice be further subdivided and focused.