中国美国商会浏览中国的数据迷宫法规如何影响美国公司2019512页

整理文档很辛苦,赏杯茶钱您下走!

免费阅读已结束,点击下载阅读编辑剩下 ...

阅读已结束,您可以下载文档离线阅读编辑

资源描述

VIEWPOINTTheAmericanChamberofCommerceinShanghai-ViewpointMay20192019:HowRegulationsAffectU.S.Companies’sViewpointseriesprovideinsightsandrecommendationsfromAmChamShanghaimembercompaniesonimportantpolicyissuesimpactingforeigncompaniesinChina.ThesereportsarebasedonextensiveinterviewsandresearchbytheAmChamShanghaiGovernmentRelationsteam.ThereportsareusedinAmChamShanghai’sadvocacyeffortswiththeChineseandU.S.governments.ABOUTUSTheAmericanChamberofCommerceinShanghai(AmChamShanghai),knownasthe“VoiceofAmericanBusiness”inChina,isoneofthelargestAmericanChambersintheAsiaPacificregion.Foundedin1915,AmChamShanghaiwasthethirdAmericanChamberestablishedoutsidetheUnitedStates.Asanon-profit,non-partisanbusinessorganization,AmChamShanghaiiscommittedtotheprinciplesoffreetrade,openmarkets,privateenterprise,andtheunrestrictedflowofinformation.AmChamShanghai’smissionistoenablethesuccessofourmembersandstrengthenU.S.-Chinacommercialtiesthroughourroleasanot-for-profitserviceproviderofhigh-qualitybusinessresourcesandsupport,policyadvocacy,andrelationship-buildingopportunities.Findusonlineat:SnapPrintingAmChamShanghaiwouldliketothankallintervieweesfortheircontributionstothisreport.May2019VIEWPOINT3ExecutiveSummaryInFebruaryandMarch2019weinterviewedcybersecurity,data,andITprofessionalsat17foreigncompaniesabouthowtheymanagethedatatheycollect,howwelltheyunderstandChina’sdataregime,andhowthecountry’sdataregulationsaffecttheirbusinessoperationsinChina.Thesecompaniesexpressedthatwhiletheyrecognizedtheimportanceofstrongerdatagovernanceandprotectionofpersonalinformation,theywereconcernedbytheonerouslocalizationrequirements,ambiguouslanguage,vaguenessinlegalrequirements,inconsistentimplementation,lackofinputindrafting,andoverlyexpensivesecurityassessmentsofChina’sCybersecurityLaw(CSL).KeyIssuesOnerousLocalizationRequirements.Datalocalizationrequirementsrepresentedbyfarthebiggesthurdleformostofourrespondentcompanies.Companiesalreadyincompliancebutcontinuingwithcross-bordertransfersmustalsoexpendsignificantcapitaltoanonymizethedatabeforesendingitabroad.CompaniesthatpurchasedatafromexternalsourcesmustalsospendtimeandmoneytoensurethatitcomplieswiththeCSL.AmbiguousLanguageinLaw.Companiesarestillunsureofwhatcountsas“importantdata”andwhichcompanieswillbeclassifiedas“CriticalInformationInfrastructureOperators.”Wordinginthecross-bordertransferrulesisunclearandtherearealsoindustry-specificambiguities,likeinhealthcare,wheregapsexistinthelawoverhowtoanonymizemedicalpatientdata.VaguenesswithLegalRequirementsandRecommendations.Manycompaniesareunsureofwhatwaslegallymandatedbystandardsandwhatwasjustarecommendation.Thisambiguitycausescompetitivedisadvantagetobusinessesthatinstitutecompany-wideprocessestofullycomplyoverthosethat“riskit”anddon’tcloselyfollowthesestandards.InconsistentImplementationoftheLaw.CompaniescomplainedaboutalackofcollaborationbetweengovernmentagenciesthatleadstoinconsistentimplementationoftheCSL.Insomeinstances,differentministriessuddenlypromulgatelawsthatcontradictearlierregulations.Similarly,companiesalsocomplainedaboutinconsistenciesbetweennationalandlocalimplementation.NoVoiceinDraftingofLaws.Manyofourmembersfeelthattheirvoicesareignoredbythegovernmentinthedraftingandimplementationoftheselaws.Thoughforeigncompaniesareabletosubmitpubliccommentstothedraftregulationsindividuallyorcollectivelyasagroup,theybelievethat“foreigncompaniesareexcludedorforgottensometimes”and“domesticcompaniesgettoknowearlierandmoreabouttheregulationchangesthan[foreigncompanies]do.”However,thisperceptionwasnotuniversalacrossourinterviewees—someofthelargerandmoreestablishedMNCsreportedampleopportunitytoengagewiththeregulatorsandparticipateintheregulationdraftingprocess.OverpricedSecurityAssessments.TheannualsecurityevaluationrequiredbytheGuidelinesforGradingofClassifiedProtectionofCybersecurityistooexpensive.Abusingadministrativepowerasaprofiteeringtoolisagainsttheprinciplesofpublicserviceandaddstothefinancialburdenofcompaniesinanalreadysofteningeconomy.RecommendationsForgovernmentOffermoreavenuesinadditiontopubliccommentperiodsforreceivingfeedbackfromdomesticandforeigncompanieswhendraftingregulations.Improvecoordinationbetweendifferentbodiestoensurelawsandregulationsareefficientlyrolledoutandallowlargemultinationalsampletimetocomply.Standardizetheimplementationofthelawatthelocalleveltoensureconsistencywiththenationallaw.SetclearfeestructuresforanysecurityassessmentsrequiredbytheCSLoritssupportingmeasuresanddon’tabuseadministrativepowerasaprofiteeringtool.ForcompaniesProactivelyimplementsolutionsaheadofthedeadlinetoeaseoperationalcomplianceandstemtheslowingofinnovation.WheretheCSLisunclear,benchmarkcomplianceprocesswithGDPR.Continuetoseekadvicefromregulatoryagenciesandengagewithgovernmentbodies.LawenforcementbodiesarebecomingmoreconfidentininterpretingandenforcingtheCSLsoexpectstrictercompliancestand

1 / 12
下载文档,编辑使用

©2015-2020 m.777doc.com 三七文档.

备案号:鲁ICP备2024069028号-1 客服联系 QQ:2149211541

×
保存成功