- Banking and Finance Laws
- Cybersecurity
- Insurance Law
- Law Digest
- Legislation
- Technology Media and Telecom
National Financial Regulatory Administration, Measures for Administration of the Security of the Data of Banking and Insurance Institutions (Draft for Comments)
国家金融监督管理总局银行保险机构数据安全管理办法 (征求意见稿)
April 12, 2024 | BY
Susan MokMeasures are laid out for handling of sensitive data by banking and insurance institutions
Issued: March 22, 2023
Main contents: A banking or insurance institution shall divide data into core data, key data and general data based on their importance and sensitivity. General data is further divided into sensitive data and miscellaneous general data (Article 18).
In business activities involving the processing of data of sensitive or higher grade or conducting activities that have a relatively large impact on data subjects, such as commissioned processing, joint processing, transfer, disclosure or sharing of data, a banking or insurance institution shall conduct a data security assessment beforehand. A data security assessment shall, in light of the objective, nature and scope of the processing of the data, and in accordance with the requirements of laws, regulations, and ethical and moral norms, analyze the risks to data security and the impact on the rights and interests of the data subjects, assess the necessity and compliance of the data processing, and assess the risks to data security and the effectiveness of the preventive and control measures (Article 22).
This premium content is reserved for
China Law & Practice Subscribers.
A Premium Subscription Provides:
- A database of over 3,000 essential documents including key PRC legislation translated into English
- A choice of newsletters to alert you to changes affecting your business including sector specific updates
- Premium access to the mobile optimized site for timely analysis that guides you through China's ever-changing business environment
Already a subscriber? Log In Now