Py学习  »  Git

Digital Economy and Data Protection Newsletter(25.24)

TMT法律论坛 • 8 月前 • 433 次点击  

Click above|Follow us


Domestically, revisions to the Trademark Law and other regulations are ongoing. Market supervision, cyberspace administration, industry and information technology and other departments are focusing on key issues such as platform economy, data security and AI. Particularly in AI, CAC has issued a draft measure targeting AI anthropomorphic interaction services, actively responding to emerging business formats such as AI companions and virtual idols. Regarding data outbound transfers, the personal information outbound transfer certification standards have been updated, the cross-border personal information processing and protection requirements between the mainland and Macao have been publicly solicited for comments, and the Fujian Pilot Free Trade Zone has released a negative list for data outbound transfers.  Internationally, the EU has made new progress in data adequacy determination, AIGC transparency, and the implementation of the Data Act; the United States has taken frequent actions on drone imports, app store rules (especially age verification), and AI chatbot risks; many other countries have also continuously strengthened cyberspace security, platform competition, AI supervision, and data law enforcement.


HOTSPOT

HOTSPOT



CAC Issues the "Interim Measures for the Administration of Artificial Intelligence Anthropomorphic Interaction Services (Draft for Comment)"


On December 27, 2025, the Cyberspace Administration of China (CAC) issued the "Interim Measures for the Administration of Artificial Intelligence Anthropomorphic Interaction Services (Draft for Comment)" (hereinafter referred to as the "Measures"). The Measures apply to products or services that use artificial intelligence technology to provide the domestic public with emotional interaction with humans through text, pictures, audio, video and other means by simulating human personality traits, thinking modes, and communication styles (i.e., anthropomorphic interaction services), actively responding to emerging business formats such as AI companions and virtual idols. On the basis of the service security, data security, and complaint and reporting mechanism requirements specified in the "Interim Measures for the Administration of Generative Artificial Intelligence Services", the Measures propose more stringent security requirements from multiple dimensions, including special information content security and induced addiction risks, emotional dependence and social alienation risks, cognitive manipulation and values guidance risks, and protection of minors and the elderly that may be caused by anthropomorphic services. It emphasizes that providers shall have security capabilities such as mental health protection, emotional boundary guidance, and dependence risk early warning, and shall not take replacing social interaction, controlling user psychology, or inducing addiction and dependence as design goals. Among them, regarding the Measures’ requirements such as identifying users’ minor identities, adopting an "Opt-in" approach for using user interaction data in model training, and conducting security assessments on the implementation of relevant provisions, service providers should closely focus on how to effectively identify risk factors and take corresponding measures while protecting user privacy.


Source: CAC 






SAMR and CAC Issue the "Announcement on Changing the Certification Basis Standards for Personal Information Outbound Transfers"


On December 25, 2025, the State Administration for Market Regulation (SAMR) and the Cyberspace Administration of China (CAC) issued the "Announcement on Changing the Certification Basis Standards for Personal Information Outbound Transfers". It changes the "Specification for Security Certification of Cross-Border Personal Information Processing Activities" (TC260-PG-20222A), which is the basis for personal information protection certification involving cross-border processing activities in the "Implementation Rules for Personal Information Protection Certification" attached to Announcement No. 37 of 2022 "Announcement on Implementing Personal Information Protection Certification", to GB/T 46068 "Data Security Technology - Requirements for Security Certification of Cross-Border Personal Information Processing Activities". Since then, the basis for personal information protection certification has been GB/T 35273 and GB/T 46068.


Source: CNCA   






TC260 Publicly Solicits Comments on the "Network Security Standard Practice Guide - Cross-Border Personal Information Processing and Protection Requirements for the Guangdong-Hong Kong-Macao Greater Bay Area (Mainland and Macao)"


On December 22, 2025, the Secretariat of the National Information Security Standardization Technical Committee (TC260) issued the "Network Security Standard Practice Guide - Cross-Border Personal Information Processing and Protection Requirements for the Guangdong-Hong Kong-Macao Greater Bay Area (Mainland and Macao) (Draft for Comment)" (hereinafter referred to as the "Cross-Border Protection Requirements"), publicly soliciting comments from the public, with the deadline on January 5, 2026.

The Cross-Border Protection Requirements apply to personal information processors and recipients in the nine mainland cities of the Greater Bay Area and Macao. Cross-border flows are carried out through voluntary application for security certification (mainland) or recognition (Macao), excluding important data and information processing activities related to Macao's critical infrastructure public operators. It covers cross-border personal information processing scenarios such as data cross-border transfer, remote access, and extraterritorial application, aiming to provide principles and requirement guidelines for cross-border personal information processing in the Greater Bay Area (mainland and Macao) and serve as the basis for certification and recognition of cross-border security mutual recognition. During the formulation of this document, opinions were solicited from the Office for Personal Data Protection of Macao. However, according to the Cross-Border Protection Requirements, Macao entities can only use it as a reference for meeting the security measure requirements of the local "Personal Data Protection Law" and cannot directly regard it as fulfilling legal obligations.


For more information, please click here.

Source: TC260





Fujian Pilot Free Trade Zone Administrative Committee Issues the "Data Outbound Transfer Management List (Negative List) (2025 Version)"


On December 25, 2025, the Fujian Provincial Cyberspace Administration of China, Department of Commerce (Free Trade Zone Office), Data Management Bureau and other departments jointly issued the "Measures for the Administration of the Data Outbound Transfer Negative List of China (Fujian) Pilot Free Trade Zone (Trial)" (hereinafter referred to as the "Administrative Measures ") and the "Data Outbound Transfer Management List (Negative List) of China (Fujian) Pilot Free Trade Zone (2025 Version)" (hereinafter referred to as the "Negative List"). They apply to organizations registered in the Fujian Pilot Free Trade Zone (Fuzhou, Xiamen, Pingtan Areas) and engaged in data cross-border flow and other related activities. The first batch of the Negative List focuses on four industries: pharmaceuticals, internet of vehicles, retail, and aviation maintenance. Subsequent supporting implementation guidelines will be issued by each area to refine operations.

According to the Administrative Measures, data processors applying the Negative List shall submit materials to the implementation agency of the respective area in accordance with the "application-filing-compliant outbound transfer" process, and carry out data outbound transfer activities after obtaining the applicability opinion. At the same time, the Administrative Measures clarify that the negative list implements dynamic updates and cross-regional mutual recognition. Negative lists issued by other free trade zones and free trade ports can be referred to and implemented in the Fujian Pilot Free Trade Zone; data classification and grading standards issued by industry competent authorities have priority applicability. It is recommended that relevant enterprises comprehensively assess the compliant paths for data outbound transfer in combination with industry norms and area guidelines.


For more information, please click here

Source: Fujian Pilot Free Trade Zone Administrative Committee 





NEWSLETTER

NEWSLETTER


(Click on the source or copy the corresponding link to view the details)




LEGISLATION

  1. Standing Committee of the National People's Congress Publicly Solicits Comments on the "Draft Amendment to the Trademark Law"

    Source: Standing Committee of the National People's Congress


  2. Legislative Affairs Commission of the Standing Committee of the National People's Congress Responds to Issues Such as "Sealing of Drug Abuse Records"

    Source: Xinhua News Agency

    https://www.news.cn/legal/20251224/fce428e819484d47a3fd8febd3cc1004/c.html


  3. CAC Publicly Solicits Comments on the "Interim Measures for the Administration of Artificial Intelligence Anthropomorphic Interaction Services (Draft for Comment)"

    Source: CAC


  4. SAMR and CAC Issue the "Announcement on Changing the Certification Basis Standards for Personal Information Outbound Transfers"

    Source: CNCA


  5. CAC and Other Departments Issue the "Rules for Price Behaviors of Internet Platforms"

    Source: CAC


  6. Supreme People's Court Issues the Revised "Provisions on the Causes of Civil Cases"

    Source: Supreme People's Court


  7. Supreme People's Court Publicly Solicits Comments on the "Interpretation of Several Issues Concerning the Application of Law in the Trial of Cases of Disputes over Infringement of Patent Rights (III)"

    Source: Supreme People's Court


  8. Ministry of Justice and National Intellectual Property Administration Jointly Issue the "Guiding Opinions on Strengthening Arbitration of Intellectual Property Disputes"

    Source: Ministry of Justice


  9. People's Bank of China Issues the "Policy Q&A on the 'Notice of the People's Bank of China on the Relevant Arrangements for the Implementation of the One-Time Credit Restoration Policy'"

    Source: People's Bank of China


  10. Ministry of Finance and Three Other Departments Issue a Document: Data Assets Shall Not Be Recorded in Accounts at Valuation

    Source: Ministry of Finance


  11. Responsible Persons of Relevant Departments of the National Financial Regulatory Administration Answer Reporters' Questions on the "Implementation Plan for the High-Quality Development of Digital Finance in the Banking and Insurance Industry"

    Source: National Financial Regulatory Administration


  12. SAMR Issues the "Measures for the Supervision and Administration of the Quality and Safety of Key Industrial Products Sold Online"

    Source: SAMR


  13. SAMR Issues the "Guidelines for the Review of Non-Horizontal Mergers and Acquisitions of Undertakings"

    Source: SAMR


  14. SAMR Revises the "Regulations on Prohibiting Monopoly Agreements"

    Source: SAMR


  15. China's First Industry Standard Regulating E-Commerce Platforms' Implementation of Qualification Verification for Online Sold Products Is Implemented

    Source: SAMR


  16. SAMR Will Issue the "Measures for the Supervision and Administration of E-Commerce Live Streaming Platforms' Fulfillment of Main Responsibilities for Food Safety"

    Source: SAMR


  17. National Medical Products Administration Issues the "Measures for the Recordation Administration of Internet Drug and Medical Device Information Services"

    Source: National Medical Products Administration 

    https://www.nmpa.gov.cn/xxgk/ggtg/ylqxggtg/ylqxqtggtg/20251222182516159.html?sessionid=1408615460


  18. Six Public Security Industry Standards for the National Network Identity Authentication Public Service Are Approved and Released

    Source: Cyberspace Security Bureau of the Ministry of Public Security


  19. MIIT Publicly Solicits Comments on the Mandatory Standards "Technical Requirements for Automobile Vehicle Information Security" and "General Technical Requirements for Automobile Software Upgrades" (Draft for Approval)

    Source: MIIT

    https://www.miit.gov.cn/zwgk/wjgs/art/2025/art_b6f3ad1fe8a04edebe5a84150c4ee4df.html


  20. MIIT Publicly Solicits Comments on 279 Industry Standards Including the "General Security Capability Requirements for Digital Human Systems in Artificial Intelligence Security Governance"

    Source: MIIT

    https://www.miit.gov.cn/gzcy/yjzj/art/2025/art_f62a70f1bd204af2a5da6b17b32715fc.html


  21. TC260 Publicly Solicits Comments on the "Network Security Standard Practice Guide - Cross-Border Personal Information Processing and Protection Requirements for the Guangdong-Hong Kong-Macao Greater Bay Area (Mainland and Macao)"

    Source: TC260


  22. TC260 Issues the "Network Security Standard Practice Guide - Requirements for Database Network Connection Security"

    Source: TC260


  23. TC260 Publicly Solicits Comments on the "Network Security Standard Practice Guide - Technical Specifications for Network Data Labeling and Identification (Draft for Comment)"

    Source: TC260


  24. Fujian Pilot Free Trade Zone Administrative Committee Issues the "Data Outbound Transfer Management List (Negative List) (2025 Version)"

    Source: Fujian Pilot Free Trade Zone Administrative Committee


  25. Yunnan Provincial Department of Industry and Information Technology Issues the "Measures for the Administration of Road Testing and Demonstration Application of Intelligent Connected Vehicles in Yunnan Province (Trial)"

    Source: Yunnan Provincial Department of Industry and Information Technology

    https://gxt.yn.gov.cn/zwgk/zc/zfwj2ynsgxw/content_32750?sessionid=1485527185


  26. Shandong Provincial Department of Industry and Information Technology and Other Departments Issue the "Measures for the Administration of Road Testing and Demonstration Application of Intelligent Connected Vehicles in Shandong Province (Trial)"

    Source: Shandong Provincial Department of Industry and Information Technology, etc.

    http://gxt.shandong.gov.cn/art/2025/12/17/art_103862_10354333.html?sessionid=1485527185


  27. Shenzhen Qianhai Authority Issues the "China-Singapore Joint Data Compliance Guidelines: Practical Manual"

    Source: Shenzhen Qianhai Authority

    https://qh.sz.gov.cn/sygnan/qhzx/dtzx/content/post_12549577.html


INDUSTRY TRENDS

  1. National Data Administration Issues Expert Interpretation of the "Typical Cases of the Application of Automobile Data Circulation Security Technology Based on the Closed-Loop Application Scenarios of Intelligent Driving Data"

    Source: NDA


  2. CAC and China Securities Regulatory Commission Jointly Carry Out In-depth Rectification of False and Inaccurate Information Related to the Capital Market Online

    Source: CAC


  3. MIIT Approves Two L3-Level Autonomous Driving Vehicle Products

    Source: MIIT


  4. SAMR Announces Five Typical Cases of False Propaganda in Private Domain Live Broadcasts in People's Livelihood Fields

    Source: SAMR


  5. Ministry of State Security Reminds That It Is Unnecessary to Grant Location Permissions to Apps

    Source: Ministry of State Security


  6. Announcement on the Testing of Five Safety Requirements for Automobile Data Processing (Fourth Batch) Is Released

    Source: CNCERT


  7. Shanghai Communications Administration Issues an Announcement on Removing 38 Apps (SDKs) That Infringe on Users' Rights and Interests

    Source: Shanghai Communications Administration


  8. Pudong Releases a Digital Going Global Action Plan to Fully Support Enterprises to Go Global

    Source: Shanghai Cyberspace Administration of China


  9. Tianjin Issues the Announcement on Filed Information of Generative AI Services (December 22)

    Source: Tianjin Cyberspace Administration of China


  10. Hainan Carries Out Special Governance on Illegal Collection and Use of Personal Information by Internet Mobile Applications

    Source: Hainan Cyberspace Administration of China


  11. Hainan Cyberspace Administration of China Issues an Announcement on the Illegal Collection and Use of Personal Information by 22 Mobile Applications Including "Toca's Dream Life", "Homeless Simulator 2", and "Toilet Guy Gary's Mod"

    Source: Hainan Cyberspace Administration of China


  12. Zhejiang Communications Administration Issues an Announcement on Apps (Mini Programs) That Infringe on Users' Rights and Interests (10th and 11th Batches of 2025)

    Source: Zhejiang Communications Administration


  13. Zhejiang Communications Administration Issues a Notice on Carrying Out the 2025 Automobile Data Security Management Reporting Work

    Source: Zhejiang Communications Administration


  14. Guizhou Cyberspace Administration of China Issues an Announcement on Typical Cases of Network Violations and Irregularities in Qianxinan Prefecture in 2025

    Source: Guizhou Cyberspace Administration of China


  15. Guangdong Communications Administration Publicly Announces 5 Apps That Failed to Complete Rectification as Required

    Source: Guangdong Communications Administration


  16. Tianshan District People's Court of Urumqi, Xinjiang Issues a Copyright Case Involving AI "One-Click Image Generation"

    Source: Tianshan District People's Court of Urumqi, Xinjiang


  17. A Short Video and Live Streaming Platform Responds to a Large Number of Pornographic Content in Live Broadcast Rooms: Has Reported to the Police

    Source: Red Star News


  18. An Online Ticketing Service Platform Issues a Statement: The Agreement Does Not Involve Any Data Cooperation, and There Is Absolutely No Leakage of User Privacy Information

    Source: Ctrip


  19. A Pharmaceutical Company Has No Systems, Training, Technology, or Protection for Data Security and Is Legally Penalized

    Source: Cyberspace Security Bureau of the Ministry of Public Security



OVERSEAS

  1. EU:

    1. EU Extends UK Data Adequacy Decision to 2031

      Source: European Commission

      https://ec.europa.eu/commission/presscorner/detail/en/ip_25_3059


    2. European Commission Issues the "Draft Code of Practice on Transparency of AIGC"

      Source: European Commission

      https://digital-strategy.ec.europa.eu/en/news/commission-publishes-first-draft-code-practice-marking-and-labelling-ai-generated-content


    3. European Commission Launches Data Act Legal Helpdesk

      Source: European Commission

      https://digital-strategy.ec.europa.eu/en/news/commission-launches-data-act-legal-helpdesk


  2. US:

    1. FCC Issues Comprehensive Ban on Imports of New Foreign Drones

      Source: Global Times


    2. Court Issues Injunction to Block Texas' "App Store Bill" from Taking Effect

      Source: Texas Court

      https://www.courtlistener.com/docket/71664632/65/computer-communications-industry-association-v-paxton/


    3. Texas Attorney General Issues Temporary Order Restricting Hisense from Collecting Personal Data Through Automatic Content Recognition Technology on TVs

      Source: Office of the Texas Attorney General

      https://texaspolitics.com/2025/12/18/ken-paxtons-temporary-restraining-order-blocks-hisense-from-collecting-texans-tv-data/?__cf_chl_rt_tk=mHi.rdlCbrVQ1TnJmQXRL4DGPKAfJGoOqn0FxtEVNJM-1766737732-1.0.1.1-hIiz3mztp.RWO2RCMhfdWV.xUCB7lRmn47pzRn1J_D8


    4. 42 Attorneys General Jointly Send a Letter to Tech Giants Urging Protection of Users from AI Chatbot Risks

      Source: Jointly Issued by 42 US State Attorneys General

      https://www.njoag.gov/ag-platkin-leads-bipartisan-coalition-demanding-that-tech-companies-put-a-stop-to-harmful-ai-chatbots/


    5. New York State Signs Bill Requiring Disclosure of AI-Generated Performers in Advertising

      Source: New York State Government

      https://www.governor.ny.gov/news/governor-hochul-signs-legislation-protect-consumers-and-boost-ai-transparency-film-industry


    6. TikTok Will Establish a Joint Venture in the US, Ministry of Commerce Responds

      Source: CCTV News


    7. TikTok Wins Lawsuit in California Court Involving Platform Community Guidelines

      Source: courthousenews

      https://www.courthousenews.com/wp-content/uploads/2025/12/bogard-v-tiktok-motion-to-dismiss.pdf


    8. TikTok Wins Lawsuit in California Court Involving Platform Community Guidelines

      Source: Complaint

      https://chatgptiseatingtheworld.com/2025/12/23/copyright-ai-epidemic-lawsuits-flood-us-courts-as-number-grows-to-72/


  3. UK:

    1. ICO Issues Statement on the Introduction of the "Cybersecurity and Resilience (Network and Information Systems) Bill" Proposed by the House of Commons

      Source: ICO

      https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/12/statement-on-the-introduction-of-the-cyber-security-and-resilience-bill/


    2. Ofcom Issues Guidelines on AI Chatbots and Online Regulation

      Source: Ofcom

      https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/ai-chatbots-and-online-regulation-what-you-need-to-know


    3. UK Government Releases Progress on Intellectual Property Rights and AI

      Source: UK Government

      https://committees.parliament.uk/publications/50795/documents/278180/default/#:~:text=Today, we are updating Parliament on the government%E2%80%99s,Technical Working Groups that the government has held


  4. Austria: Austrian Supreme Court Rules Meta's Personalized Advertising Model Illegal

    Source: Noyb

    https://noyb.eu/sites/default/files/2025-12/OGH_ruling_Meta_redacted_autotranslation.pdf


  5. Netherlands: Data Protection Authority (AP) Warns Users That TikTok Continues to Transfer Personal Data to China

    Source: AP

    https://www.autoriteitpersoonsgegevens.nl/actueel/ap-waarschuwt-gebruikers-tiktok-blijft-persoonlijke-gegevens-naar-china-sturen


  6. France:

    1. CNIL Issues Interpretation Related to the "Data Act"

      Source: CNIL

      https://www.cnil.fr/fr/reglement-donnees-data-act-nouveau-cadre-europeen-pour-partage-utilisation-donnees


    2. Israeli Processor Fined €1 Million by CNIL for Violating GDPR

      Source: CNIL

      https://www.cnil.fr/en/data-breach-mobius-solutions-ltd-fined-eu1-million


  7. Italy:

    1. AGCM Fines Apple €98.6 Million for Its "App Tracking Transparency" (ATT) Rules

      Source: AGCM

      https://en.agcm.it/en/media/press-releases/2025/12/A561


    2. AGCM Orders Meta to Suspend WhatsApp AI Ban

      Source: AGCM

      https://en.agcm.it/en/media/press-releases/2025/12/A576


  8. Brazil: Apple Will Open Third-Party Stores

    Source: CADE

    https://www.gov.br/cade/pt-br/assuntos/noticias/cade-forma-maioria-pela-homologacao-de-tcc-em-investigacao-sobre-praticas-da-apple-no-ios


  9. Australia: OAIC Will Conduct Its First Privacy Policy Check in January 2026

    Source: OAIC

    https://www.oaic.gov.au/news/media-centre/privacy-compliance-sweep-to-put-privacy-policies-under-the-spotlight


  10. Hong Kong, China: PCPD Releases AI Deepfake Toolkit

    Source: PCPD

    https://www.pcpd.org.hk/english/resources_centre/publications/files/ai_deepfake.pdf


  11. Japan: "Act on Promotion of Competition in Specified Smartphone Software" Enforced, Apple Opens External Links and Other Third-Party Payments in Japan

    Source: JFTC

    https://www.jftc.go.jp/en/pressreleases/yearly-2025/July/250729.html


  12. South Korea:

    1. PIPC Establishes New Department to Prevent Data Leakage

      Source: PIPC

      https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=11707


    2. PIPC Releases 2026 Work Promotion Plan

      Source: PIPC

      https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=11681



Note

本文由Gen AI翻译,仅供参考。

Translated by Gen AI service. For reference only.


本期编辑:吴佳蔚 陈煜烺 林婉琪 陈瑞庭 张丽

Python社区是高质量的Python/Django开发社区
本文地址:http://www.python88.com/topic/191063