2. You must give users a way to opt-out of having their personal information used in algorithmic decision-making / marketing. 4/
-
Show this thread
-
3. If you process the personal info of a minor under 14, parental / guardian consent is required, and the processor has to formulate special processing rules for the personal info of minors. 5/
1 reply 3 retweets 17 likesShow this thread -
4. Cue the geopolitical bickering: "Personal information processors shall take necessary measures to ensure that the processing of personal information by overseas recipients meets the personal information protection standards stipulated in this law." 6/
1 reply 4 retweets 16 likesShow this thread -
What that means: if sending personal information to locations outside of China, the information has to be protected to the same standards the PIPL provides. 7/
1 reply 3 retweets 15 likesShow this thread -
That might be done several ways: 1) China could whitelist transfer to certain countries with strong personal privacy laws, 2) Companies could sign data privacy contracts with data recipients 3) International treaties could be signed. 8/
1 reply 3 retweets 16 likesShow this thread -
5. Data portability: if individuals want to move their data from one info processor to another, info processors have to provide means for them to do that, providing no other data laws or regulations are being broken in the process. 9/
1 reply 3 retweets 15 likesShow this thread -
What's interesting to me about that in the Chinese context: Regulators have been trying to lower big tech's "walled gardens" - allowing users to move data more fluidly from one ecosystem to another might serve China's anti-monopoly aims to some extent. 10/
1 reply 2 retweets 16 likesShow this thread -
6. "Close relatives [of the deceased] may, for their own lawful and legitimate interests, exercise the rights of access, copy, correction, deletion, etc., to the relevant personal information of the deceased unless otherwise arranged by the deceased during his lifetime." 11/
2 replies 2 retweets 16 likesShow this thread -
7. Mega-platforms that process lots of personal info must "Follow the principles of openness, fairness, and justice, formulate platform rules, and clarify the standards for the processing of personal information by product or service providers on the platform." 12/
1 reply 2 retweets 14 likesShow this thread -
8. When investigating personal info violations, gov depts may: ask questions, consult related contracts, records, and accounting, conduct on-site inspections, inspect equipment. If evidence of illegal activity, equipment and related materials may be seized. 13/
2 replies 3 retweets 15 likesShow this thread
9. "If the staff of the gov department performing the personal information protection duties neglects their duties, abuses their powers, engages in malpractice for personal gain, but did not commit a crime, they shall be penalized." 14/
-
-
Let the enforcement fun begin.
4 replies 2 retweets 24 likesShow this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.