社区所有版块导航
Python
python开源   Django   Python   DjangoApp   pycharm  
DATA
docker   Elasticsearch  
aigc
aigc   chatgpt  
WEB开发
linux   MongoDB   Redis   DATABASE   NGINX   其他Web框架   web工具   zookeeper   tornado   NoSql   Bootstrap   js   peewee   Git   bottle   IE   MQ   Jquery  
机器学习
机器学习算法  
Python88.com
反馈   公告   社区推广  
产品
短视频  
印度
印度  
Py学习  »  Git

Digital Economy and Data Protection Newsletter(25.13)

TMT法律论坛 • 2 月前 • 140 次点击  

Click above|Follow us


Recently, in legislation, the CAC has solicited public comments on the mandatory national standard "Technical Requirements for Information Erasure in Electronic Products." The TC260 has intensively advanced the formulation and release of multiple national cybersecurity standards. The MIIT and others have released the "Compliance Management Guide for Protecting User Rights and Interests in Mobile Internet Application Services." The National Data Administration and the SAMR have jointly released a model data trading contract. In regulatory developments, the CAC has spearheaded multiple actions including Personal Information Protection Officer reporting, China-EU/China-Germany data cross-border exchanges, a Personal Information Protection Questionnaire Survey, and the summer campaign to rectify the online environment for minors. It has also announced new batches of Deep Synthesis Algorithm filings and Generative AI Service filings. Various departments have also strengthened industry supervision from different dimensions: SAMR focused on issues in live-streaming e-commerce and food delivery platforms; NDA advanced pilot projects for trusted data spaces; MIIT piloted number protection services; the National Energy Administration included data security and critical information infrastructure protection in its administrative inspection list. Overseas, the EU continues to deepen AI governance, data sharing, and minor protection rules; multiple US states have introduced bills addressing algorithmic pricing discrimination and AI employment discrimination; Malaysia released a DPO handbook; Ireland's DPC has launched another investigation into TikTok's data cross-border transfers.


HOTSPOT

HOTSPOT



CAC Releases "Announcement on Launching the Work of Reporting Personal Information Protection Officer Information"


On July 18, 2025, the CAC released the "Announcement on Launching the Work of Reporting Personal Information Protection Officer Information". Personal information handlers processing the personal information of over 1 million individuals shall fulfill the reporting procedures for their Personal Information Protection Officer information to the municipal-level (division-level) cyberspace administration department at their location. The reporting deadline is within 30 working days from the date the processing volume threshold is reached. For personal information handlers that have already reached the threshold, information reporting must be completed by August 29, 2025. Reporting shall be conducted online via the "Personal Information Protection Business System". This system has also provided the "Filling Instructions for the Personal Information Protection Officer Information Reporting System (First Edition)", clarifying the content to be included in the report, such as the basic information of the personal information handler, the information of the Personal Information Protection Officer, and the details of personal information processing.


Source: CAC






CAC Releases Draft Mandatory National Standard "Data Security Technology - Technical Requirements for Information Erasure in Electronic Products" (Soliciting Comments)


On July 14, 2025, the CAC solicited public comments on the draft mandatory national standard "Data Security Technology - Technical Requirements for Information Erasure in Electronic Products" (hereinafter referred to as "Technical Requirements for Information Erasure"). The comment period ends on September 13, 2025. The Technical Requirements for Information Erasure stipulate that both electronic product manufacturers during the product design and development phase and recycling operators during the second-hand transaction phase must strictly implement information erasure specifications. This involves operations such as deleting address mappings and erasing encryption keys to cut off data recovery paths and ensure data is rendered completely unreadable. The scope of information erasure covers user-addressable applications, media files, system caches, account configuration information, and encryption keys, among others. According to the plan, this standard may set a one-year transition period after formal release before official implementation.


Source: CAC








NEWSLETTER

NEWSLETTER


(Click on the source or copy the corresponding link to view the details)




LEGISLATION

  1. CAC Releases Draft Mandatory National Standard "Data Security Technology - Technical Requirements for Information Erasure in Electronic Products" (Soliciting Comments)

    Source: CAC


  2. TC260 Issues Notice Soliciting Comments on 9 National Standards including "Cybersecurity Technology - Cybersecurity Product Interoperability - Part 5: Behavior Information Format" (Draft)

    Source: TC260


  3. TC260 Notifies Issuance of 9 Cybersecurity Recommended National Standard Plans

    Source: TC260


  4. Three National Cybersecurity Standards including GB/T 22080-2025 "Cybersecurity Technology - Information Security Management Systems - Requirements" Approved and Released

    Source: TC260


  5. Two Important Group Standards on Supply Chain Security Officially Released

    Source: Cybersecurity Law Research Center, Third Research Institute of the Ministry of Public Security


  6. MIIT, Together with the Internet Society of China and CAICT, Releases "Compliance Management Guide for Protecting User Rights and Interests in Mobile Internet Application Services"

    Source: MIIT


  7. NDA and SAMR Issue Model Contract for Data Circulation and Trading

    Source: NDA



INDUSTRY TRENDS

  1. CAC Releases "Announcement on Launching the Work of Reporting Personal Information Protection Officer Information"

    Source: CAC


  2. Second Meeting of China-EU Data Cross-Border Flow Exchange Mechanism Held in Brussels

    Source: CAC


  3. CAC: China and Germany Agree to Deepen Cooperation on Data Cross-Border Flows, Expand Exchanges in AI Governance, and Reach Consensus on Continuing Relevant Institutional Dialogues

    Source: CAC


  4. CAC Launches 2025 Online Questionnaire Survey on Personal Information Protection

    Source: CAC


  5. NEA Releases "List of Administrative Inspection Items for the National Energy Administration and Its Dispatched Agencies", Involving Data Security and Critical Information Infrastructure Protection

    Source: NEA

    https://www.nea.gov.cn/20250630/86c43a44789d417f93e4f3c9f0f932ad/0b8c0ec7a9584187b8517fe959ced9e6.pdf


  6. CAC Announcement on Releasing the Twelfth Batch of Deep Synthesis Service Algorithm Filing Information

    Source: CAC


  7. CAC Deploys "Clear and Bright·2025 Summer Campaign to Rectify the Online Environment for Minors" Special Action

    Source: CAC


  8. CAC Announcement on Releasing Generative Artificial Intelligence Service Filing Information (April to June 2025)

    Source: CAC

    https://www.cac.gov.cn/2024-04/02/c_1713729983803145.htm?sessionid=128914827


  9. National Computer Virus Emergency Response Center Detects and Reports 68 Mobile Apps Violating Laws and Regulations in Collecting and Using Personal Information

    Source: National Cybersecurity Notification Center


  10. SAMR Holds Deployment and Promotion Meeting for Special Campaign to Rectify Prominent Issues in Live-Streaming E-commerce

    Source: SAMR


  11. SAMR Summons Food Delivery Platform Enterprises

    Source: SAMR


  12. NDA Announces Public List of 2025 Trusted Data Space Innovation Development Pilot Projects

    Source: NDA


  13. MIIT Issues Notice on Launching Pilot for Number Protection Service Business, Proposes Planning 700 Number Segment as Dedicated Resource

    Source: MIIT

    https://www.miit.gov.cn/jgsj/xgj/wjfb/art/2025/art_ec866a5d25304fcf8c82382c88dd68c2.html


  14. Cyberspace Administration of China Releases Second Batch of Apps List Completing Personal Information Collection and Usage Optimization Improvements

    Source: Cyberspace Administration of China (CAC)


  15. Cyber Police Announce Typical Cases Applying the "Network Data Security Management Regulations"

    Source: National Cybersecurity Notification Center


  16. Beijing Launches Special Campaign to Rectify "Forced Face-Scanning" in Public Places Starting July

    Source: Beijing Cyberspace Administration


  17. 69 Units in Beijing Have Completed Facial Information Filing Procedures; Special Campaign to Rectify Illegal Collection and Use of Facial Recognition Information in Public Places to be Launched

    Source: Beijing Youth Daily


  18. Beijing Releases Three-Year Action Plan for "AI + Medical Health"

    Source: Beijing Municipal Science & Technology Commission

    https://kw.beijing.gov.cn/zwgk/zcwj/202507/t20250703_4141266.html


  19. Tech Company Penalized for Failing to Fulfill Cybersecurity Obligations Leading to Data Leak in Ticketing System

    Source: Privacy Guardian Team


  20. Shanghai High Court Releases Case: How to Divide Online Virtual Assets After Partnership Operating WeChat Public Account "Breaks Up"?

    Source: Shanghai High People's Court


  21. Yunnan Provincial Cyberspace Administration Releases Announcement on Further Clarifying Filing Work for Facial Recognition Technology Applications

    Source: Yunnan Provincial Cyberspace Administration


  22. Anhui Communications Administration Releases Notice on Removing 3 Apps Infringing User Rights and Interests

    Source: Anhui Communications Administration


  23. In June, Multiple Banks Fined for Data Security Issues

    Source: Bank Technology Research Society



OVERSEAS

  1. European Union:

    1. European Commission Publishes Final Version of GPAI Code of Conduct

      Source: European Commission

      https://ec.europa.eu/commission/presscorner/detail/en/ip_25_1787


    2. European Commission Releases FAQ on Signing the GPAI Code of Conduct

      Source: European Commission

      https://digital-strategy.ec.europa.eu/en/news/learn-more-about-guidelines-providers-general-purpose-ai-models


    3. European Commission Spokesperson States No Suspension Arrangement for AI Act Implementation

      Source: European Commission

      https://audiovisual.ec.europa.eu/en/video/I-274901


    4. European Commission Proposes Council Sign UN Convention Against Cybercrime

      Source: European Commission

      https://home-affairs.ec.europa.eu/news/commission-proposes-sign-and-conclude-un-convention-against-cybercrime-2025-07-16_en


    5. European Commission Announces Launch of Age Verification Tool Prototype Under DSA

      Source: European Commission

      https://digital-strategy.ec.europa.eu/en/news/commission-presents-guidelines-and-age-verification-app-prototype-safer-online-space-children


    6. EDPB Releases Statement No. 4/2025 on Model Contractual Clauses for Data Sharing

      Source: EDPB

      https://www.edpb.europa.eu/our-work-tools/our-documents/statements/statement-42025-european-commissions-recommendation-draft_en


    7. EDPB and EDPS Issue Opinion on GDPR Revision and Burden Reduction for SMEs

      Source: EDPB

      https://www.edpb.europa.eu/news/news/2025/targeted-modifications-gdpr-edpb-edps-welcome-simplification-record-keeping_en#:\~:text=Brussels%2C%209%20July%202025%20-%20The%20European%20Data,a%20Regulation%20amending%20certain%20regulations%2C%20including%20the%20GDPR


    8. European Board for Digital Services Receives Consultation on Guidelines for Minors' Online Privacy and Safety Protection under DSA

      Source: European Commission

      https://digital-strategy.ec.europa.eu/en/news/ad-hoc-meeting-european-board-digital-services-1


    9. European Parliament Releases Report "Generative AI and Copyright: Training, Generation and Regulation"

      Source: European Parliament

      https://www.europarl.europa.eu/RegData/etudes/STUD/2025/774095/IUST_STU(2025)774095_EN.pdf


    10. EPRS Releases Study on CJEU Data Retention Limitations

      Source: EPRS

      https://www.europarl.europa.eu/RegData/etudes/BRIE/2025/775878/EPRS_BRI(2025)775878_EN.pdf


    11. European Central Bank Releases DORA Cloud Service Outsourcing Guidelines

      Source: European Central Bank

      https://www.bancaditalia.it/media/bce-comunicati/documenti/2025/ssm.pr250716.pdf?language_id=1


    12. Court of Justice of the EU Issues Ruling on Access to Binding Decision Documents of EDPB

      Source: CJEU

      https://gdprhub.eu/index.php?title=CJEU_-_T%E2%80%91183/23_-_Ballmann_v_European_Data_Protection_Board


    13. IAB Europe Voices Concerns Over DFA

      Source: IAB Europe

      https://gdprhub.eu/index.php?title=CJEU_-_T%E2%80%91183/23_-_Ballmann_v_European_Data_Protection_Board (Note: Source link seems incorrect in original; IAB Europe statement link would be elsewhere)


    14. NOYB Files Complaint Against TikTok, AliExpress, and WeChat for Failing to Fulfill DSARs

      Source: NOYB

      https://noyb.eu/en/how-tiktok-aliexpress-wechat-ignore-your-gdpr-rights


    15. Belgium's Data Protection Authority (APD) Dismisses NOYB's Batch Cookies Complaint, Rules Associations Cannot Lodge Complaints in Their Own Name

      Source: APD

      https://www.autoriteprotectiondonnees.be/citoyen/actualites/2025/06/26/l-apd-explique-pourquoi-elle-classe-sans-suite-des-plaintes-de-noyb


    16. ESA Publishes Guide on DORA Oversight Activities

      Source: ESA

      https://www.eba.europa.eu/publications-and-media/press-releases/esas-publish-guide-dora-oversight-activities


  2. United States:

    1. New York State: Bill on Algorithmic Pricing Discrimination Takes Effect

      Source: New York State Assembly

      https://www.nysenate.gov/legislation/bills/2025/A3008/amendment/original


    2. California: Bill Opposing AI Employment Discrimination Passed, Effective October 1, 2025

      Source: National Law Review

      https://natlawreview.com/article/californias-ai-employment-discrimination-regs-receive-final-approval


    3. Nebraska Sues General Motors Over Collection of Sensitive Driving Data

      Source: Nebraska Attorney General

      https://ago.nebraska.gov/attorney-general-mike-hilgers-files-lawsuit-against-general-motors-deceptive-collection-and-sale


  3. Ireland: DPC Announces Launch of Inquiry into TikTok Europe's Data Cross-Border Transfers

    Source: Irish DPC

    https://www.dataprotection.ie/en/news-media/press-releases/dpc-announces-inquiry-tiktok-technology-limiteds-transfers-eea-users-personal-data-servers-located#:\~:text=The%20Data%20Protection%20Commission%20%28DPC%29%20has%20today%20announced,users%E2%80%99%20personal%20data%20to%20servers%20located%20in%20China.


  4. UK: First-Tier Tribunal Rules on Preliminary Issues in TikTok's Appeal Against its 2023 Fine, Upholding ICO Win

    Source: UK Caselaw Website

    https://caselaw.nationalarchives.gov.uk/ukftt/grc/2025/798


  5. France:

    1. CNIL Releases Final Version of Guide on Data Transfer Impact Assessments

      Source: CNIL

      https://cnil.fr/sites/default/files/2025-07/guide_tia.pdf


    2. CNIL Publishes Article "Checking for Ongoing Calls While Using a Banking App: What Are Your Rights?"

      Source: CNIL

      https://www.cnil.fr/fr/appel-en-cours-pendant-lutilisation-dune-application-bancaire-vos-droits


    3. CNIL Finds Use of "Enhanced" Cameras to Estimate Age of Tobacco Shop Customers to Control Sales of Prohibited Products to Minors Unnecessary and Disproportionate

      Source: CNIL

      https://www.cnil.fr/fr/cameras-augmentees-pour-estimer-lage-dans-les-bureaux-de-tabac-la-cnil-precise-sa-position


    4. CNIL Releases DPO Guide on Children's Data Protection

      Source: CNIL

      https://www.cnil.fr/fr/parentalite-numerique-la-cnil-et-lafcdp


  6. Germany: German Court Orders Compensation for Non-Material Damage Due to Meta Collecting Personal Data for User Profiling

    Source: heise

    https://www.heise.de/en/news/Wave-of-lawsuits-foreseeable-5-000-euros-in-damages-due-to-Meta-Business-Tools-10479584.html


  7. Netherlands:

    1. AP Releases Report on AI and Algorithms Regarding Emotion Recognition Systems

      Source: AP

      https://www.autoriteitpersoonsgegevens.nl/actueel/ap-emoties-herkennen-met-ai-dubieus-en-risicovol


    2. AP Calls for Mandatory Registration of Algorithms and AI Systems

      Source: AP

      https://www.autoriteitpersoonsgegevens.nl/actueel/algoritmeregistratie-in-nederland-moet-beter


  8. Cyprus: Commissioner Announces Release of DSA Implementing Regulations

    Source: European Office of Cyprus

    https://eoc.org.cy/harmonised-transparency-reporting-rules-under-the-digital-services-act-now-in-effect/


  9. South Korea:

    1. PIPC Releases Draft Guidelines on Processing Pseudonymized Information for Public Comment

      Source: PIPC

      https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS061&mCode=C010010000&nttId=11358


    2. PIPC to Release "Comprehensive Guidelines on Personal Information Processing"

      Source: PIPC

      https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=11349


  10. Malaysia:

    1. PDP Releases DPO Registration Handbook

      Source: PDP Malaysia

      https://www.pdp.gov.my/ppdpv1/en/data-protection-officer-registration-guide/


    2. House of Representatives Passes "Cybersecurity Act 2025"

      Source: Malaysian House of Representatives

      https://lom.agc.gov.my/ilims/upload/portal/akta/outputaktap/2867049_BM/Akta%20866-Akta%20Keselamatan%20Dalam%20Talian%202025.pdf


  11. Hong Kong: LVHK Reports Data Breach Incident to Hong Kong's Privacy Commissioner for Personal Data (PCPD), Commissioner Launches Investigation

    Source: Wen Wei Po

    https://www.wenweipo.com/a/202507/19/AP687b3f2ce4b0c332a000d9d5.html


  12. International: ISO Releases ISO/IEC 42006:2025 "Information technology — Requirements for bodies providing audit and certification of artificial intelligence management systems"

    Source: ISO

    https://www.iso.org/standard/42006#lifecy

    cle


Note

本文由Gen AI翻译,仅供参考。

Translated by Gen AI service. For reference only.


本期编辑:吴佳蔚 陈煜烺 林婉琪 陈瑞庭 张丽

Python社区是高质量的Python/Django开发社区
本文地址:http://www.python88.com/topic/184676
 
140 次点击