欧洲安全研究所-中国的数据战略(英)-2021.10-8页_502kb
报告摘要
China's Data Strategy Summary
Core Content
China's data strategy is an evolving framework that reflects a balance between innovation, security, privacy, and surveillance. The government has increasingly recognized data as a "factor of production" and is working to create a state-led data market to boost the digital economy. While China has adopted some privacy protections similar to the EU's GDPR, its approach is more aligned with national security and corporate interests.
Main Objectives
- Innovation: Encourage the use of data to drive economic growth and digital transformation.
- Security: Protect national cyber infrastructure and prevent data leaks and cyberattacks.
- Privacy: Implement legal protections for personal data, though with a different emphasis compared to the EU.
- Surveillance: Monitor and control citizens and companies through data collection.
Key Information
Data Governance Framework
- China's data governance framework is still under development, with local pilot regulations and public debates shaping its direction.
- The framework is designed to allow for non-exclusivity and multistakeholder joint ownership of data.
- Data property rights are being considered to enable data to be traded and monetized, though this is controversial due to data's unique properties.
Data Ownership and Rights
- The Chinese government is promoting data ownership rights for businesses, especially for large databases.
- Individuals have negative rights, such as the ability to delete, access, or correct their personal data.
- Public data is categorized as a "new type of state-owned asset" and is managed by government authorities and public institutions.
Local Pilot Regulations
- The Shenzhen regulation (2020, revised 2021) is the first draft of a local data rights framework.
- It defines three types of data rights for individuals, companies, and the government.
- It includes provisions for data transaction platforms, data evaluation agencies, and international data transfer rules.
Health Data Case Study
- Health data is considered sensitive and is protected under the Personal Information Protection Law.
- It is categorized into standard personal health data and de-identified data, with the latter being more freely usable for public health and research.
- The government collects health data for public health purposes, often without individual consent.
- Human genetic resource data is especially protected and can only be collected with Chinese institutions' involvement.
International Implications
- China's data strategy may challenge the EU's emphasis on individual data rights.
- It raises concerns about data protectionism, where countries may restrict data sharing with foreign entities.
- This could lead to data islands, where companies must operate within national data boundaries, potentially harming digital trade.
- The Data Security Law (2021) outlines export controls for "important data" and strategic measures in data trading.
Challenges for EU Governments and Companies
- Data Collection Risks: EU citizens and companies in China may face abusive data collection and unrestricted use of data by the state.
- Strategic and Ideological Risks: China's approach may influence other countries to adopt similar strategies, putting pressure on the EU's GDPR-centric model.
- Data Protectionism: The risk of restricting cross-border data flows and deepening data protectionism could impact digital trade and economic growth.
- Economic Impact: Potential restrictions on overseas listings and data localization may affect EU companies operating in China.
Policy Recommendations
- EU Engagement: EU governments should engage in bilateral and multilateral negotiations to influence China's data legislation.
- Partnership with Local Governments: European companies and governments can collaborate with local Chinese authorities, such as the Hainan free trade zone, to facilitate smoother data flows.
- Global Norm Setting: The EU can play a key role in setting global data standards, especially regarding anonymization and data auditing.
- Monitoring and Adaptation: European entities should closely monitor China's data governance developments and their implications for EU citizens and businesses.
Conclusion
China's data governance framework is designed to enhance economic growth through state-led data markets and corporate data rights, while also prioritizing national security and surveillance. This strategy may challenge the EU's data rights model and deepen data protectionism, necessitating a proactive and informed response from the EU to safeguard its interests and citizens.
试读结束,高清完整版pdf/doc/ppt,请点下载