CYBERSECURITY REVIEW 9 AUGUST - 2023As you know, China Personal Information Protection Law (PIPL) took into effect on 1st Nov 2021, which is equivalent to Europe's GDPR, even more, strict in some areas. But the biggest difference is still due to China's unique digital ecosystems, which leads to the unique approach to privacy protection regulation's enforcement and execution in China. After PIPL, all the major Chinese E-Commerce platforms have performed privacy revamp per the latest privacy requirements; after that, the interface between E-Commerce CRM, Order Management System and Logistic System changed, and it became more and more difficult for a merchant to acquire the personal information from customers, unless we successfully convince the customer to join our own membership program, legally speaking, this is the right thing to protect the lawful rights and interests of citizens and organizations, also serve the economic and social development of the whole digital ecology.To protect all our loyalty members' privacy information in China with compliance with the China local cybersecurity and privacy regulations, we must build a comprehensive privacy protection program or system, which includes:· Privacy and Security by Design· Supply Chain security management· Personnel security governance· Privacy regulation compliance· China digital application compliance check· China-specific target marketing rule · Chinese Data Subject Rights protection and appeal management· Content managementOne thing I need to highlight here is the last bullet item: content management, which is also a very special requirement in China's cybersecurity framework, this requires continuous checking and making sure all the content generated either by your company or your users are legally and politically right, this is not a small effort.In a global company, there are always some debates between a global security solution and a local security solution; a global solution enables centralized management and operation and keeps global consistent configuration and rules, enabling global visibility. While the local solution is fitter to local consumer habits and experience, sometimes with high performance and even low cost. Again, China is a unique market; for some consumer-facing solutions, we definitely can consider local solutions with a global standardized risk assessment to be performed. Of course, we will prefer to choose a globally certified solution for the more backend solution; then, we can have a global view of the full picture. Again, there is no one-fit-all answer, we still need to dive deep into it case by case, but the risk assessment methodology and process should be consistent without any bias. One of the good examples is the NFT platform, which is also a very hot topic in China, to issue NFT in China, there are many potential legal risks, compliance requirements and industry practices in China, so we must choose a platform or key market player with all the license in China and contractual commitment to cooperate. However, we will still mitigate all the cybersecurity risks with global solutions based on the underneath blockchain technology. To protect all our loyalty members' privacy information inChina with compliance with the China local cybersecurity andprivacy regulations, we must build a comprehensive privacy protection program or system
<
Page 8 |
Page 10 >