China could soon have stronger privacy laws than the U.S.

Really — at least, when it comes to corporations collecting data. A major draft law could end the free-for-all in the world's largest market.

China could soon have stronger privacy laws than the U.S.

Back to work and back to surveillance in China.

Photo: Getty Images

International observers often think of China as a place where privacy protections are thin or nonexistent. But a forthcoming law could arm Chinese consumers with offensive and defensive tools that web users in places like the United States could only dream of.

In late April, China unveiled the second draft of the country's privacy law, the Personal Information Protection Law, for public comment. The law is expected to pass by the end of the year, and would shield Chinese internet users from excessive data collection and misuse of personal data by tech companies — and even, to some extent, by the government.

The new law, similar to the European Union's General Data Protection Regulation, will give individuals the power to know how their personal data is being used and to consent to it.

"It's a good law," Jeremy Daum, a senior fellow of the Yale Law School Paul Tsai China Center, told Protocol. "We tend to think of China as not being overly concerned with privacy, and that's just wrong … There's a growing expectation of privacy in the Chinese public, and the government is responding to it by passing high-level authority to try and ensure some protections."

Several of the provisions in the draft could change the experience of Chinese web users nationwide.

Privacy committees come to China

One new provision requires big internet platforms — including WeChat, Douyin and Taobao — to each form a committee, staffed predominantly by non-company employees, that supervises the handling of personal information. Tech companies will have to stop providing services that misuse personal information. The big platforms are also required to publish periodic reports about information protection.

This is not a model new to the rest of the world. Facebook, for example, was required to form an independent privacy committee by the Federal Trade Commission in 2019. But Chinese tech companies will be required for the first time to establish an outside board to review the handling of consumer data, especially sensitive biometric data.

"It gives consumers an added level of protection," Daum said. "You're going to have somebody besides the government and besides the company itself looking at how the company is using personal information, making sure they're doing it as they said in their user agreements for the purposes that they state."

Personal information as inheritance

The law also adds novel protections for "post-mortem privacy." When a person passes, that person's family will inherit the rights to handling the decedent's personal information, which could include the power to delete their account.

Alexa Lee, senior manager for global cyber and privacy policy with the Information Technology Industry Council and an associate editor of DigiChina, told Protocol that privacy laws globally rarely address the rights to personal information of the deceased. "This is a very unique addition because if you look at all the global privacy laws, only France has one on this," Lee said. "No other privacy laws have something like this, not even GDPR."

Bye-bye, personalized recommendations

Under the new Personal Information Protection Law, users can elect to block algorithmically-curated information or personalized ads. This means that if Taobao or Douyin recommends merchants or video clips to users, by default the platforms must provide options that aren't tailored for the user based on past and present engagement. If companies want to serve ads based on personal information "with a major influence on the rights and interests of the individual," the app or the site must get affirmative user consent first.

Consent. Consent. Consent.

Other than the new changes, one big theme throughout the draft law is ensuring the consumer's right to consent and the right to know how their information is being used. They also have the right to withdraw that consent at any time, and service providers are required to make a streamlined withdrawal process by law.

The draft law stipulates the concrete applications of minimum necessary standards, meaning tech companies can only collect personal information when it's necessary for the services being provided.

But getting consent is tricky. Users don't always understand the terms and privacy notices to which they're agreeing. "It will be a really long process for consumers to get used to that, and it will also be work for the company themselves to figure out how they can streamline and make this notice easier for the consumer to read," Lee said. Otherwise, Lee said, the process will generate consent fatigue.

Limits on the state

The new law contains a whole chapter regulating the use of personal information by state organs, even though it has less teeth compared to protections against corporate abuse.

The draft law stipulates that when handling personal information, the state "may not exceed the scope or extent necessary to fulfill their statutory duties and responsibilities." And state organs, like corporations and individuals, have to inform individuals and get consent from them when handling their personal information. But there are broad exceptions. The government doesn't have to inform individuals about data collection when doing so would undermine the purpose of the collection — for example, in a criminal investigation.

"Of course, that can get abused," Daum said, "because how do you know to question their use if you don't even know that they're using it? But the fact that there is even a section on state organ use of personal information shows they're really considering who should be allowed to use this and when."


Judge Zia Faruqui is trying to teach you crypto, one ‘SNL’ reference at a time

His decisions on major cryptocurrency cases have quoted "The Big Lebowski," "SNL," and "Dr. Strangelove." That’s because he wants you — yes, you — to read them.

The ways Zia Faruqui (right) has weighed on cases that have come before him can give lawyers clues as to what legal frameworks will pass muster.

Photo: Carolyn Van Houten/The Washington Post via Getty Images

“Cryptocurrency and related software analytics tools are ‘The wave of the future, Dude. One hundred percent electronic.’”

That’s not a quote from "The Big Lebowski" — at least, not directly. It’s a quote from a Washington, D.C., district court memorandum opinion on the role cryptocurrency analytics tools can play in government investigations. The author is Magistrate Judge Zia Faruqui.

Keep ReadingShow less
Veronica Irwin

Veronica Irwin (@vronirwin) is a San Francisco-based reporter at Protocol covering fintech. Previously she was at the San Francisco Examiner, covering tech from a hyper-local angle. Before that, her byline was featured in SF Weekly, The Nation, Techworker, Ms. Magazine and The Frisc.

The financial technology transformation is driving competition, creating consumer choice, and shaping the future of finance. Hear from seven fintech leaders who are reshaping the future of finance, and join the inaugural Financial Technology Association Fintech Summit to learn more.

Keep ReadingShow less
The Financial Technology Association (FTA) represents industry leaders shaping the future of finance. We champion the power of technology-centered financial services and advocate for the modernization of financial regulation to support inclusion and responsible innovation.

AWS CEO: The cloud isn’t just about technology

As AWS preps for its annual re:Invent conference, Adam Selipsky talks product strategy, support for hybrid environments, and the value of the cloud in uncertain economic times.

Photo: Noah Berger/Getty Images for Amazon Web Services

AWS is gearing up for re:Invent, its annual cloud computing conference where announcements this year are expected to focus on its end-to-end data strategy and delivering new industry-specific services.

It will be the second re:Invent with CEO Adam Selipsky as leader of the industry’s largest cloud provider after his return last year to AWS from data visualization company Tableau Software.

Keep ReadingShow less
Donna Goodison

Donna Goodison (@dgoodison) is Protocol's senior reporter focusing on enterprise infrastructure technology, from the 'Big 3' cloud computing providers to data centers. She previously covered the public cloud at CRN after 15 years as a business reporter for the Boston Herald. Based in Massachusetts, she also has worked as a Boston Globe freelancer, business reporter at the Boston Business Journal and real estate reporter at Banker & Tradesman after toiling at weekly newspapers.

Image: Protocol

We launched Protocol in February 2020 to cover the evolving power center of tech. It is with deep sadness that just under three years later, we are winding down the publication.

As of today, we will not publish any more stories. All of our newsletters, apart from our flagship, Source Code, will no longer be sent. Source Code will be published and sent for the next few weeks, but it will also close down in December.

Keep ReadingShow less
Bennett Richardson

Bennett Richardson ( @bennettrich) is the president of Protocol. Prior to joining Protocol in 2019, Bennett was executive director of global strategic partnerships at POLITICO, where he led strategic growth efforts including POLITICO's European expansion in Brussels and POLITICO's creative agency POLITICO Focus during his six years with the company. Prior to POLITICO, Bennett was co-founder and CMO of Hinge, the mobile dating company recently acquired by Match Group. Bennett began his career in digital and social brand marketing working with major brands across tech, energy, and health care at leading marketing and communications agencies including Edelman and GMMB. Bennett is originally from Portland, Maine, and received his bachelor's degree from Colgate University.


Why large enterprises struggle to find suitable platforms for MLops

As companies expand their use of AI beyond running just a few machine learning models, and as larger enterprises go from deploying hundreds of models to thousands and even millions of models, ML practitioners say that they have yet to find what they need from prepackaged MLops systems.

As companies expand their use of AI beyond running just a few machine learning models, ML practitioners say that they have yet to find what they need from prepackaged MLops systems.

Photo: artpartner-images via Getty Images

On any given day, Lily AI runs hundreds of machine learning models using computer vision and natural language processing that are customized for its retail and ecommerce clients to make website product recommendations, forecast demand, and plan merchandising. But this spring when the company was in the market for a machine learning operations platform to manage its expanding model roster, it wasn’t easy to find a suitable off-the-shelf system that could handle such a large number of models in deployment while also meeting other criteria.

Some MLops platforms are not well-suited for maintaining even more than 10 machine learning models when it comes to keeping track of data, navigating their user interfaces, or reporting capabilities, Matthew Nokleby, machine learning manager for Lily AI’s product intelligence team, told Protocol earlier this year. “The duct tape starts to show,” he said.

Keep ReadingShow less
Kate Kaye

Kate Kaye is an award-winning multimedia reporter digging deep and telling print, digital and audio stories. She covers AI and data for Protocol. Her reporting on AI and tech ethics issues has been published in OneZero, Fast Company, MIT Technology Review, CityLab, Ad Age and Digiday and heard on NPR. Kate is the creator of and is the author of "Campaign '08: A Turning Point for Digital Media," a book about how the 2008 presidential campaigns used digital media and data.

Latest Stories