China Publishes Regulations Regarding Cloud Services for Public Comment
Time 2 Minute Read

Recently, the Ministry of Industry and Information Technology of the People’s Republic of China published a draft of the new Notice on Regulating Business Behaviors in the Cloud Service Market (Draft for Public Comments) (the “Draft”) for public comment. The Draft is open for comment until December 24, 2016.

Under the Draft, foreign investors investing in and operating cloud services within China must establish a foreign-invested telecommunications enterprise and obtain a value-added telecommunications business license. In addition, the Draft provides that when establishing technical cooperation with other entities, a cloud service operator must not lease out or transfer its telecommunication business license by any method to its partners, or provide resources, premises or facilities to its partners to facilitate illegal operations. The Draft also prohibits cloud service operators from using dedicated lines or VPNs to connect to an international network.

In addition, the Draft applies certain requirements to cloud service providers which were already applicable to Internet service providers, including that cloud service providers must establish and publish rules regarding their collection and use of personal information, and adopt security safeguards for network data and users’ personal information. In addition, upon a user’s termination of services, cloud service operators are required to cease their collection and use of the user’s personal information. Also, when establishing technical cooperation with other entities, a cloud service operator may not provide users’ personal information or network data to its partners in violation of law.

The Draft also provides that when providing services to residents of China, cloud service operators must host their service facilities and retain network data within the territory of China, and cross-border data transfers must proceed in compliance with relevant regulations. In the event of an information leakage, cloud service operators must promptly inform the users of the leakage, adopt effective remedial measures and report the incident to the administrative authority for the telecommunications sector.

The Draft is not yet in final form and there remains a possibility that the final version may differ substantially from the Draft. No time frame has been announced for the adoption of a final version.

 

You May Also Be Interested In

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 2 Minute Read

On February 24, 2026, the UK ICO announced that it had fined Reddit, Inc. £14.47 million following an investigation into the company’s handling of children’s personal information.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page