Our business involves collecting and retaining certain internal and customer data. We also maintain information about various aspects of our operations as well as regarding our employees. The integrity and protection of our customer, employee and company data is critical to our business. Our customers and employees expect that we will adequately protect their personal information. We are required by applicable laws to keep strictly confidential the personal information that we collect, and to take adequate security measures to safeguard such information.
The PRC Criminal Law, as amended by its Amendment 7 (effective on February 28, 2009) and Amendment 9 (effective on November 1, 2015), prohibits institutions, companies and their employees from selling or otherwise illegally disclosing a citizen's personal information obtained in performing duties or providing services or obtaining such information through theft or other illegal ways. On November 7, 2016, the SCNPC issued the Cyber Security Law of the PRC (the "Cyber Security Law"), which became effective on June 1, 2017. Pursuant to the Cyber Security Law, network operators must not, without users' consent, collect their personal information, and may only collect users' personal information necessary to provide their services. Providers are also obliged to provide security maintenance for their products and services and shall comply with provisions regarding the protection of personal information as stipulated under the relevant laws and regulations.
The Civil Code of the PRC (issued by the PRC National People's Congress on May 28, 2020 and effective from January 1, 2021) provides legal basis for privacy and personal information infringement claims under the Chinese civil laws. PRC regulators, including the CAC, MIIT and the Ministry of Public Security, have been increasingly focused on regulation in data security and data protection.
The PRC regulatory requirements regarding cybersecurity are evolving. For instance, various regulatory bodies in China, including the CAC, the Ministry of Public Security and the State Administration for Market Regulation (the "SAMR," formerly the State Administration for Industry and Commerce of the People's Republic of China, the "SAIC"), have enforced data privacy and protection laws and regulations with varying and evolving standards and interpretations. In April 2020, the Chinese government promulgated Cybersecurity Review Measures, which came into effect on June 1, 2020. According to the Cybersecurity Review Measures, operators of critical information infrastructure must pass a cybersecurity review when purchasing network products and services which do or may affect national security.
In July 2021, the CAC and other related authorities released the draft amendment to the Cybersecurity Review Measures for public comments through July 25, 2021, which became effective on February 15, 2022. The Cybersecurity Review Measures propose the following key changes:
- companies who are engaged in data processing are also subject to the regulatory scope;- the CSRC is included as one of the regulatory authorities for purposes of jointly establishing the state cybersecurity review working mechanism;- the online platform operators holding more than one million users individual information and seeking a listing outside China shall file for cybersecurity review with the Cybersecurity Review Office; and - the risks of core data, material data or large amounts of personal information being stolen, leaked, destroyed, damaged, illegally used or transmitted to overseas parties and the risks of critical information infrastructure, core data, material data or large amounts of personal information being influenced, controlled or used maliciously shall be collectively taken into consideration during the cybersecurity review process.
We may become subject to enhanced cybersecurity review. Certain internet platforms in China have been reportedly subject to heightened regulatory scrutiny in relation to cybersecurity matters. As of the date of this annual report, we have not been informed by any PRC governmental authority of any requirement that we file for a cybersecurity review. However, if we are deemed to be a critical information infrastructure operator or a company that is engaged in data processing and holds personal information of more than one million users, we could be subject to PRC cybersecurity review.
As there remains significant uncertainty in the interpretation and enforcement of relevant PRC cybersecurity laws and regulations, we could be subject to cybersecurity review, and if so, we may not be able to pass such review in relation to our securities offerings. In addition, we could become subject to enhanced cybersecurity review or investigations launched by PRC regulators in the future. Any failure or delay in the completion of the cybersecurity review procedures or any other non-compliance with the related laws and regulations may result in fines or other penalties, including suspension of business, website closure, removal of our app from the relevant app stores, and revocation of prerequisite licenses, as well as reputational damage or legal proceedings or actions against us, which may have material adverse effect on our business, financial condition or results of operations.
On June 10, 2021, the SCNPC promulgated the PRC Data Security Law, which became effective in September 2021. The PRC Data Security Law imposes data security and privacy obligations on entities and individuals carrying out data activities, and introduces a data classification and hierarchical protection system based on the importance of data in economic and social development, and the degree of harm it will cause to national security, public interests, or legitimate rights and interests of individuals or organizations when such data is tampered with, destroyed, leaked, illegally acquired or used. The PRC Data Security Law also provides for a national security review procedure for data activities that may affect national security and imposes export restrictions on certain data an information.
As uncertainties remain regarding the interpretation and implementation of these laws and regulations, we cannot assure you that we will comply with such regulations in all respects and we may be ordered to rectify or terminate any actions that are deemed illegal by regulatory authorities. We may also become subject to fines and/or other sanctions which may have material adverse effect on our business, operations and financial condition.
While we take various measures to comply with all applicable data privacy and protection laws and regulations, our current security measures and those of our third-party service providers may not always be adequate for the protection of our customer, employee or company data. We may be a target for computer hackers, foreign governments or cyber terrorists in the future.
Unauthorized access to our proprietary internal and customer data may be obtained through break-ins, sabotage, breach of our secure network by an unauthorized party, computer viruses, computer denial-of-service attacks, employee theft or misuse, breach of the security of the networks of our third-party service providers, or other misconduct. Because the techniques used by computer programmers who may attempt to penetrate and sabotage our proprietary internal and customer data change frequently and may not be recognized until launched against a target, we may be unable to anticipate these techniques.
Unauthorized access to our proprietary internal and customer data may also be obtained through inadequate use of security controls. Any of such incidents may harm our reputation and adversely affect our business and results of operations. In addition, we may be subject to negative publicity about our security and privacy policies, systems, or measurements. Any failure to prevent or mitigate security breaches, cyber-attacks or other unauthorized access to our systems or disclosure of our customers' data, including their personal information, could result in loss or misuse of such data, interruptions to our service system, diminished customer experience, loss of customer confidence and trust, impairment of our technology infrastructure, and harm our reputation and business, resulting in significant legal and financial exposure and potential lawsuits.