Py学习  »  Git

Digital Economy and Data Protection Newsletter(26.07)

TMT法律论坛 • 2 月前 • 231 次点击  

Click above|Follow us


Recently, on cross‑border data transfers, China’s Regulations on Counteracting Unjustified Extra‑territorial Application of Foreign Laws introduced penalties for data‑transfer activities that facilitate foreign discriminatory measures, while Shanghai expanded the scope of its negative list for data exports and Suzhou issued operational guidelines for data transfers. On AI, TC260 released AI ethics guidelines, the SPC will issue opinions on AI‑related disputes, a Beijing court ruled that certain AI parameter‑related conduct constitutes unfair competition, and the NDB is soliciting comments on token (prompt) trading. On platform governance and enforcement, eight authorities led by the PBOC regulated online marketing of financial products, SAMR penalized seven e‑commerce platforms for “ghost kitchens”, the CAC together with the National Railway Administration summoned seven ticketing platforms, and the CAC simultaneously tightened rules on live‑stream tipping. On IP, the SPC published an interpretation on punitive damages, and the SPP issued a white paper focusing on data‑related crimes. Internationally, the European Commission is exploring age verification, while the EDPB released a DPIA template, guidelines on scientific research, and approved Europrivacy as a GDPR transfer tool; the White House is guarding against “industrial‑scale distillation” of frontier AI models, the U.S. House advanced financial data security bills and export controls, and Alabama enacted a consumer data privacy law; the Netherlands passed a cybersecurity act; South Korea penalized 373 location information service providers; and Anthropic launched identity verification on Claude while OpenAI released a child safety blueprint.


HOTSPOT

HOTSPOT



State Council Promulgates Regulations on Countering Unjustified Extraterritorial Jurisdiction of Foreign Countries, Adding Penalties for Restricting Cross-Border Data Transfers


On April 13, 2026, the State Council promulgated the Regulations of the People's Republic of China on Counteracting Foreign Undue Extraterritorial Jurisdiction (State Council Order No. 835, hereinafter referred to as the “Regulations”), which took effect on the date of promulgation. Together with the State Council Provisions on the Security of Industrial and Supply Chains (State Council Order No. 834, hereinafter referred to as the “Provisions”), promulgated and effective on April 7, 2026, these two instruments establish China’s legal tools for countering foreign undue extraterritorial jurisdiction and safeguarding supply chain security. Both the Provisions and the Regulations include “prohibiting or restricting the receipt or provision of data or personal information from or to outside China” as one of the countermeasures or penalties, highlighting the critical role of cross-border data transfer in the field of foreign-related security.


Source: State Council





Shanghai CAC and Shanghai Data Bureau Issue Administrative Measures and Negative List for Data Export from the Free Trade Zone and National Comprehensive Pilot Area for Expanding Opening-up in the Service Sector (Shanghai)


On April 24, 2026, the Cyberspace Administration of Shanghai and the Shanghai Data Bureau jointly issued the Measures for the Administration of the Negative List for Cross-Border Data Transfer in the China (Shanghai) Pilot Free Trade Zone, the Lin-gang Special Area, and the National Comprehensive Pilot Area for Further Opening up the Services Sector (Shanghai) (for Trial Implementation) and the *Negative List for Cross-Border Data Transfer (2025 Edition)* . They took effect on the date of issuance, simultaneously repealing the 2024 Edition.

The key adjustments include: expanding the scope of application from the original FTZ and Lin‑gang Special Area to the entire territory of Shanghai, applying to all data processors registered in Shanghai that engage in cross-border data transfer activities (excluding critical information infrastructure operators); clarifying a city‑unified reference rule for data classification and grading  — specifically, personal data (excluding sensitive personal data) of 10 million or more individuals, sensitive personal data of 1 million or more individuals, or sensitive personal data of 100,000 or more individuals that includes bank account, insurance account, registered account, or personal medical diagnosis data held by Shanghai‑based enterprises falls within the reference scope for identifying important data; and adding the meteorological sector to the 2025 Negative List, which now covers four sectors: reinsurance, international shipping (water freight transport, port operations, and seafarer management), commerce (retail & catering, accommodation), and meteorology, while raising relevant quantitative thresholds in certain sectors.

Regarding the filing procedure, data processors must submit required materials to their district authorities, which will issue a preliminary review opinion within 10 business days and report it to the municipal level for confirmation. If cross-border data transfer circumstances change, processors shall apply for a filing amendment within 15 business days. All enterprises using the Negative List must report their annual cross-border data transfer status to their district authorities by the end of each year.


Source: Shanghai Cyberspace Administration






NEWSLETTER

NEWSLETTER


(Click on the source or copy the corresponding link to view the details)




LEGISLATION

  1. State Council Promulgates Regulations on Countering Unjustified Extraterritorial Jurisdiction of Foreign Countries, Adding Penalties for Restricting Cross-Border Data Transfers

    Source: State Council


  2. PBoC, MIIT and Six Other Departments Jointly Issue Measures for the Administration of Online Marketing of Financial Products

    Source: Ministry of Industry and Information Technology (MIIT)

    https://wap.miit.gov.cn/jgsj/xgj/wjfb/art/2026/art_5d2d34e50a5f42bcabc8e861d181d723.html


  3. CAC and Nine Other Departments Jointly Publish Provisions on Promoting and Regulating the Application of Electronic Documents

    Source: Cyberspace Administration of China (CAC)


  4. Secretariat of the Central Cyberspace Affairs Commission Issues Notice on Strengthening the Regulation of Online Live-streaming Tipping

    Source: Cyberspace Administration of China (CAC)


  5. State Council Issues Opinions on Promoting the Expansion and Quality Improvement of the Service Industry

    Source: State Council


  6. SPC Issues Interpretation on Applying Punitive Damages in Civil Disputes Involving IP Infringement

    Source: Supreme People's Court (SPC)


  7. SPP Releases White Paper on IP Prosecution (2025)

    Source: Supreme People's Procuratorate (SPP)


  8. NDA Releases Implementation Plan for Promoting the Construction of High-Quality Industry Datasets (Draft for Comment), Including Token Trading

    Source: National Data Administration (NDA)


  9. TC260: Guidelines on AI Application Ethics and Safety v1.0 (Draft for Comment) Open for Public Consultation

    Source: National Information Security Standardization Technical Committee (TC260)


  10. Shanghai CAC and Shanghai Data Bureau Issue Administrative Measures and Negative List for Data Export from the Free Trade Zone and National Comprehensive Pilot Area for Expanding Opening-up in the Service Sector (Shanghai)

    Source: Shanghai Cyberspace Administration



INDUSTRY TRENDS

  1. CAC Signs MOU on Innovation and Technology Development with HKSAR Innovation, Technology and Industry Bureau

    Source: Cyberspace Administration of China (CAC)


  2. Central Cyberspace Affairs Commission and National Railway Administration Jointly Interview 7 Third-Party Train Ticket Platforms Under the Cybersecurity Law and CII Regulations

    Source: Cyberspace Administration of China (CAC)


  3. SPC: Releases Summary of IP Court Adjudication Key Points (2025)

    Source: Supreme People's Court (SPC)


  4. SPC Holds 2026 IP Awareness Week Press Conference, Currently Drafting Opinions on Properly Adjudicating AI-Related Disputes in Accordance with Law

    Source:  Supreme People's Court (SPC)


  5. State Administration for Market Regulation (SAMR) Imposes Administrative Penalties on 7 E-commerce Platforms Including Pinduoduo, Meituan, JD.com, Ele.me, Douyin, Taobao, and Tmall for Ghost Kitchen Food Delivery Cases

    Source: State Administration for Market Regulation (SAMR)

    https://www.samr.gov.cn/xw/zj/art/2026/art_9714ee2bef9244819134ef4ffdd14017.html


  6. NDA Issues Notice on the First Batch of National Standard Requirements in the Data Field for 2026

    Source: National Data Administration (NDA)


  7. CCTV News / National Bureau of Statistics: China's Daily Average Token Invocations Exceed 140 Trillion, Up Over 40% from End of Previous Year

    Source: National Data Administration (NDA)


  8. MPS Cybersecurity Bureau Publishes Technical Logic and Protection Strategies for Privacy Leaks in Smart Home Devices

    Source: Cybersecurity Bureau of the Ministry of Public Security


  9. CNIPA Issues Announcement on Including 91 Marks Notified by WIPO International Bureau Under Official Mark Protection

    Source: China National Intellectual Property Administration (CNIPA)

    https://www.cnipa.gov.cn/art/2026/4/10/art_2089_205668.html?sessionid=


  10. CNIPA Issues Letter of Opinions on Jurisdiction of Administrative Adjudication of Patent Infringement Disputes

    Source: China National Intellectual Property Administration (CNIPA)

    https://www.cnipa.gov.cn/art/2026/4/10/art_3611_205691.html?xxgkhide=1


  11. CPCC Issues Notice on Trial Online Processing of Software Copyright Pledge Registration

    Source: Copyright Protection Center of China (CPCC)

    https://www.ccopyright.com/mobile/index.php?optionid=1330&method=view&optionid=1330&auto_id=1533


  12. TC260: Notice on Soliciting Participating Units for the Standard on Information Technology — Security Techniques — Anonymous Entity Authentication — Part 4: Mechanisms Based on Weak Secrets

    Source: National Information Security Standardization Technical Committee (TC260)


  13. CSAC: Announcement on Publishing the List of Apps that Have Completed Optimization of Personal Information Collection and Use (1st Batch, 2026)

    Source: Cyber Security Association of China (CSAC)


  14. Beijing: Public Announcement of Filed Generative AI Services (April 21, 2026)

    Source: Beijing Cyberspace Administration


  15. Beijing: Public Announcement of Filed Generative AI Services (April 17, 2026)

    Source: Beijing Cyberspace Administration


  16. Beijing CAC Launches Clear and Bright Jinghua — Guarding Minors Special Campaign for Online Protection of Minors

    Source: Beijing Cyberspace Administration


  17. Beijing Internet Court Releases Typical Cases on Platform Copyright Liability

    Source: Beijing Internet Court


  18. Beijing Chaoyang Court Releases White Paper on IP Adjudication Safeguarding Regional High-Quality Development — Cases Show Copying AI Parameters and Architectures Constitutes Unfair Competition

    Source: Beijing Chaoyang District People's Court


  19. Beijing No. 3 Intermediate Court Publishes Article: Accountability for Unauthorized Use of AI to Process Classified Documents

    Source: Beijing No. 3 Intermediate People's Court


  20. Shanghai: Public Announcement of Filed Generative AI Services (April 21)

    Source: Shanghai Cyberspace Administration


  21. Shanghai CAC Notification on Issues with Personal Information Collection and Use by Local Apps (1st Batch, 2026)

    Source: Shanghai Cyberspace Administration


  22. Shanghai Communications Administration Issues Notification on Apps (SDKs) Infringing User Rights (2nd Batch, 2026)

    Source: Shanghai Communications Administration


  23. Shanghai: Jinshan District Explores Cybersecurity and Data Security Risk Assessment for Smart Villages

    Source: Jinshan District, Shanghai


  24. Suzhou: Suzhou Issues Operational Guidelines for Data Export Negative List

    Source: Suzhou Data Bureau


  25. Zhejiang CAC Publishes March Enforcement Report — Enterprise Fined RMB 50,000 for Data Stolen by Overseas Actors

    Source: Zhejiang Cyberspace Administration

    https://www.zjwx.gov.cn/col/col1694583/art/2026/art_525f2e44cd849977d51bb824eff8e304.html


  26. Zhejiang Higher People's Court Releases Typical Cases of IP Protection by Zhejiang Courts in 2025, Including Two Data-Related Unfair Competition Cases

    Source: Zhejiang Higher People's Court


  27. Shandong Higher Court Publishes Case: Platform's Unilateral Change of Jurisdiction Clause in User Service Agreement Held Invalid

    Source: Shandong Higher People's Court


  28. Beijing Institute of Automation Leads ISO International Standard Project for Humanoid Robot Datasets

    Source: Global Robotics News


  29. iQIYI's AI Celebrity Database Sparks Controversy Over Unauthorized Use

    Source: The Paper (Pengpai News)



OVERSEAS

  1. EU:

    1. MOFCOM Spokesperson Answers Questions on the EU Cybersecurity Act Amendment Draft

      Source: Ministry of Commerce (MOFCOM)


    2. EDPB Releases Draft DPIA Template for Public Consultation

      Source: EDPB

      https://www.edpb.europa.eu/news/news/2026/enhancing-compliance-and-consistency-edpb-adopts-dpia-template_en


    3. EDPB Issues Guidelines on Scientific Research

      Source: EDPB

      https://www.edpb.europa.eu/system/files/2026-04/edpb_guidelines_202601_scientificresearch_en.pdf


    4. EDPB Approves Updated Europrivacy Standard and Recognizes Europrivacy as a GDPR Data Transfer Tool

      Source: EDPB

      https://www.edpb.europa.eu/system/files/2026-04/edpb_opinion_202615_europrivacy_en.pdf


    5. European Commission Issues Statement on Digital Age Verification Application for Privacy-Preserving Age Verification

      Source: European Commission

      https://ec.europa.eu/commission/presscorner/detail/en/statement_26_820?utm_source=chatgpt.com


    6. NOYB Releases Report: Only 16.5% of Access Requests Were Properly Fulfilled

      Source: NOYB

      https://noyb.eu/en/digital-omnibus-reality-check-835-access-requests-not-properly-answered


    7. European Commission has proposed measures to require Google to share search engine data with third parties under the Digital Markets Act (DMA)

      Source: European Commission

      https://digital-markets-act.ec.europa.eu/commission-proposes-measures-google-sharing-search-engine-data-third-parties-under-digital-markets-2026-04-16_en


  2. US:

    1. White House Issues Memorandum to Prevent Industrial-Scale Distillation of Frontier AI Models

      Source: White House

      https://www.whitehouse.gov/wp-content/uploads/2026/04/NSTM-4.pdf


    2. House Committee Advances Protect Financial Data Act and Secure Data Act

      Source: House Financial Services Committee

      https://financialservices.house.gov/news/documentsingle.aspx?DocumentID=411100


    3. House Foreign Affairs Committee Passes 22 Export Control Bills in One Day, Including the MATCH Act

      Source: House Foreign Affairs Committee

      https://foreignaffairs.house.gov/committee-activity/markups/various-measures-35


    4. SEC Seeks Public Comment on Consolidated Audit Trail and Other Audit Trails and Data Sources

      Source: SEC

      https://www.sec.gov/newsroom/press-releases/2026-37-sec-seeks-public-comment-consolidated-audit-trail-other-audit-trails-data-sources


    5. EPIC Files Amicus Brief for South Carolina's Age-Appropriate Design Code (H.3431), Countering Big Tech's Attempt to Overturn Child Online Safety Law

      Source: EPIC

      https://epic.org/epic-files-amicus-brief-countering-big-tech-claim-that-surveillance-based-feeds-are-protected-by-the-first-amendment/


    6. Alabama: Governor Signs Comprehensive Consumer Data Privacy Bill

      Source: Alabama State Legislature

      https://alison.legislature.state.al.us/files/pdf/SearchableInstruments/2026RS/HB351-eng.pdf


    7. Alabama: Attorney General Announces $12.2 Million Settlement with Roblox for Child Safety

      Source: Alabama Attorney General

      https://www.alabamaag.gov/attorney-general-marshall-announces-12-2-million-settlement-with-roblox-to-ensure-child-safety/


    8. California: CalPrivacy Exploring Whether Regulatory Changes Are Needed for Notices, Disclosures, or Employee Data

      Source: CalPrivacy

      https://cppa.ca.gov/regulations/pdf/notices_disclosures_employee_data.pdf


    9. Florida: State Investigates OpenAI Over School Shooting, Alleging AI Provided Suggestions to the Perpetrator

      Source: Public reports


  3. UK:

    1. DSIT and Cabinet Office Issue Open Letter Warning Businesses About Increased Cyber Attack Capabilities from Frontier AI Models

      Source: DSIT / Cabinet Office

      https://www.gov.uk/government/publications/ai-cyber-threats-open-letter-to-business-leaders/ai-cyber-threats-open-letter-to-business-leaders-html


    2. AI Safety Institute (AISI) Evaluates Cybersecurity Capabilities of Anthropic's New Model

      Source: AISI

      https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities


  4. Belgium:

    1. APD Publishes Report on the Impact of AI on Privacy

      Source: APD

      https://www.autoriteprotectiondonnees.be/publications/the-impact-of-artificial-intelligence-on-privacy.pdf


    2. CCB Emphasizes NIS2 Directive Deadlines for Essential Entities

      Source: CCB

      https://atwork.safeonweb.be/frequently-asked-questions-faq-nis2-and-cyberfundamentals


  5. Germany: Bundestag Considers Bill Designating Federal Network Agency as Central Access Point for Short-Term Rental Data

    Source: German Bundestag

    https://www.bundestag.de/dokumente/textarchiv/2026/kw17-de-kurzzeitvermietungen-1165912


  6. France: CNIL Warns That Tracking Pixels in Emails May Collect User Digital Behavior Data

    Source: CNIL

    https://cnil.fr/fr/pixels-de-suivi-dans-les-courriers-electroniques-vous-devez-etre-mieux-informes


  7. Netherlands:

    1. AI Act Open for Public Consultation

      Source: Dutch Ministry of Economic Affairs and Climate Policy

      https://www.rijksoverheid.nl/ministeries/ministerie-van-economische-zaken-en-klimaat/nieuws/2026/04/20/kabinet-zet-stap-met-toezicht-op-europese-ai-regels


    2. House of Representatives Passes Cybersecurity Act

      Source: NCSC

      https://www.ncsc.nl/nieuws/tweede-kamer-stemt-in-met-cyberbeveiligingswet


    3. Dutch DPA (AP) and Consumer and Markets Authority (ACM) Seek Input on Customer Service Chatbots

      Source: ACM

      https://www.acm.nl/en/publications/call-acm-and-ap-please-share-your-opinion-chatbots-customer-service


    4. Dutch DPA (AP) Launches Public Consultation on Enforcement Policy

      Source: AP

      https://autoriteitpersoonsgegevens.nl/actueel/ap-vraagt-input-op-handhavingsbeleid


  8. Italy:

    1. Garante Adopts Guidelines on the Use of Tracking Pixels in Email Communications

      Source: Garante

      https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10241977


    2. Garante Fines Italian Post Office and Postepay Over EUR 12.5 Million for Privacy Violations

      Source: Garante

      https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10241568


    3. Garante Rules on Milan Linate Airport Facial Recognition System — SEA's Processing of Passenger Biometric Data Non-Compliant with GDPR

      Source: Garante

      https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/10238246


    4. Garante Fines Eni EUR 96,000 for Unlawful Disclosure of Personal Data

      Source: Garante

      https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10239073


  9. Latvia: Amendment to Aircraft Passenger Data Processing Law Officially Signed

    Source: Latvian Official Gazette

    https://likumi.lv/ta/id/367718-grozijumi-gaisa-kugu-pasazieru-datu-apstrades-likuma


  10. Slovenia: Information Commissioner (IP) Fines Company EUR 70,000 for Covert Employee Surveillance

    Source: Slovenian Information Commissioner (IP)

    https://www.ip-rs.si/novice/delodajalcu-ki-je-prikrito-nadzoroval-vse-aktivnosti-zaposlenih-na-ra%C4%8Dunalnikih-izre%C4%8Dena-globa-ve%C4%8D-kot-70000-eur-1775713659


  11. Ukraine: Ministry of Digital Transformation Issues Guidelines on Safe Use of AI Assistants and AI Agents

    Source: Ukraine Ministry of Digital Transformation

    https://thedigital.gov.ua/news/shtuchnyy-intelekt/doruchit-rutynu-shtuchnomu-intelektu-iak-bezpechno-pratsiuvaty-z-shi-asystentamy-ta-ahentamy


  12. Morocco: National Commission for Personal Data Protection (CNDP) Signs Agreement to Expand Data-Tika Compliance Program Participation

    Source: CNDP

    https://www.cndp.ma/la-cndp-signe-une-convention-avec-la-cnt-la-fnih-la-fnaavm-la-fnrt-et-la-fntt-pour-leur-adhesion-au-programme-data-tika/?utm_source=chatgpt.com


  13. South Korea: Korea Communications Commission (KCC) Penalizes 373 Location Information Service Providers for Violations of Location Data Management and Technical Protection Obligations

    Source: KCC

    https://www.korea.kr/briefing/pressReleaseView.do?newsId=156753938


  14. Australia: OAIC Demands RentTech Platforms Stop Unfair and Excessive Collection of Personal Information

    Source: OAIC

    https://www.oaic.gov.au/news/media-centre/renttech-platforms-must-stop-unfair-and-excessive-personal-information-collection,-says-privacy-commissioner


  15. Industry / Corporate:

    1. Anthropic: Officially Announces Identity Verification Feature on Claude Platform

      Source: Anthropic

      https://support.claude.com/zh-CN/articles/14328960-claude-%E4%B8%8A%E7%9A%84%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81


    2. OpenAI: Releases New Child Safety Blueprint

      Source: OpenAI

      https://openai.com/index/introducing-child-safety-blueprint/


    3. Apple: Urges Users to Update iOS to Protect iPhones from Cyber Attacks

      Source: Apple

      https://support.apple.com/en-us/126776



Note

本文由Gen AI翻译,仅供参考。

Translated by Gen AI service. For reference only.


本期编辑:吴佳蔚 陈煜烺 林婉琪 陈曦宇 季开 张丽

Python社区是高质量的Python/Django开发社区
本文地址:http://www.python88.com/topic/195550