On November 14, 2021, the CAC published the Regulations of Internet Data Security Management (Draft for Comments), which further regulate the internet data processing activities and emphasize the supervision and management of network data security, and further stipulate the obligations of internet platform operators, such as to establish a system for disclosure of platform rules, privacy policies and algorithmic strategies related to data. Specifically, the draft regulations require data processors to, among others, (1) adopt immediate remediation measures when finding that network products and services they use or provide have security defects and vulnerabilities, or threaten national security or endanger public interest, and (2) follow a series of detailed requirements with respect to processing of personal information, management of important data and proposed overseas transfer of data. In addition, such draft regulations require data processors handling important data or the data processors to be listed overseas to complete an annual data security assessment and file a data security assessment report to applicable regulators. Such annual assessment, as required by the draft regulations, would encompass areas including but not limited to the status of important data processing, data security risks identified and the measures adopted, the effectiveness of data protection measures, the implementation of national data security laws and regulations, data security incidents that occurred and their handling, and a security assessment with respect to sharing and provision of important data overseas. As of the date of this offering memorandum, the draft regulations have been released for public comment only and have not been formally adopted. The final provisions and the timeline for its adoption are subject to changes and uncertainties.
The interpretation, application and enforcement of these newly enacted and drafted laws and regulations are subject to substantial uncertainties. See “Risk Factors—Risks Related to Our Business and Industry—Our business is subject to complex and evolving Chinese and international laws and regulations, including those regarding data privacy and cybersecurity. Many of these laws and regulations are subject to change and uncertain interpretation, and could result in claims, penalties, changes to our business practices, increased cost of operations, damages to our reputation and brand, or declines in user growth or engagement, or otherwise harm our business” and “The PRC government has taken steps to limit online game playing time for all minors and to otherwise control the content and operation of online games. Such restrictions on online games may materially and adversely impact our business and results of operations.”
Our business is subject to complex and evolving Chinese and international laws and regulations, including those regarding data privacy and cybersecurity. Many of these laws and regulations are subject to change and uncertain interpretation, and could result in claims, penalties, changes to our business practices, increased cost of operations, damages to our reputation and brand, or declines in user growth or engagement, or otherwise harm our business.
We collect personal data from our users in order to better understand our users and their needs for the purpose of our content feeds recommendation and to help our advertisement customers target specific demographic groups. Concerns about the collection, use, disclosure or security of personal information or other privacy-related matters, even if unfounded, could damage our reputation, cause us to lose users and other customers and adversely affect our results of operations.
Many jurisdictions, including China and the U.S., continue to consider the need for greater regulation or reform to the existing regulatory framework. In the U.S., all 50 states have now passed laws to regulate the actions that a business must take in the event of a data breach, such as prompt disclosure and notification to affected users and regulatory authorities. In addition to the data breach notification laws, some states have also enacted statutes and rules requiring businesses to reasonably protect certain types of personal information they hold or to otherwise comply with certain specified data security requirements for personal information. The U.S. federal and state governments will likely continue to consider the need for greater regulation aimed at restricting certain uses of personal data for targeted advertising. California enacted the California Consumer Privacy Act, or CCPA, which creates new individual privacy rights for consumers (as that word is broadly defined in the law) and places increased privacy and security obligations on entities handling personal data of consumers or households. The CCPA, which went into effect on January 1, 2020, requires covered companies to provide new disclosures to California consumers, and provides such consumers new ways to opt-out of certain sales of personal information. The CCPA provides for civil penalties for violations, as well as a private right of action for data breaches that is expected to increase data breach litigation. The CCPA may increase our compliance costs and potential liability. Some observers have noted that the CCPA could mark the beginning of a trend toward more stringent privacy legislation in the U.S., which could increase our potential liability and adversely affect our business.
4