Laws governing identity theft under cyber law in China

gavel-scale-1024x923.png (1024×923)

Identity theft can be defined as the illegal obtaining of a person’s personal information which defines one’s identity for illegal economic benefits and committing acts see this article such as fraud, theft etc. Identity theft can occur either on or off cyberspace. In recent times, due to the rapid growth and evolution of technology, identity thefts in cyberspace such as creating a fake social media account/ email id, for instance, have become one of the most common forms of cybercrimes around the world. Hacking, Phishing, E-mail/SMS spoofing etc. are examples of cyber identity theft, wherein the cybercriminal gains access to one’s personal information which can be used to impersonate the person and steal money or gain other illegal benefits such as tax-related identity theft, medical identity theft, identity cloning for concealment, online purchase scams etc.

China has always grappled with criminal activities related to identity theft and theft of personal information. Recently, in June of 2020, Chinese media revealed that several universities had discovered graduates between 1999 and 2006, who had stolen another person’s identity and score to get admitted to the university. Apart from this, foreigners and citizens alike have faced many situations of identity and credit card information being stolen. In light of this and other incidents of identity theft, the year 2020 has been an active year for developments in China’s cybersecurity and data protection regimes.

History of Chinese data protection law
China did not have a single comprehensive ‘data protection’ law until 2017. Prior to the introduction of the People’s Republic of China Cybersecurity Law (“Cybersecurity Law 2017”), there were various laws and rules which are a part of a complex legal framework pertaining to the protection of personal information and data security.

Under the Criminal Law of China, cyber crimes are mainly classified as “Crimes Disturbing Public Order”. Articles 285, 286 and 287 of the Criminal Law are the main provisions relating to cybercrimes. Articles 285 and 286 are mainly focused on new crimes targeting computers and the internet, such as illegal access, damaging a computer information system etc. while on the other hand, Article 287 deals with the traditional/ conventional crimes facilitated by computers and the internet.

Though these Articles try to cover cybercrimes, they seem inadequate in light of emerging technology and crimes. The Amendment Nine of 2015, introduced various changes further expanding the meaning of the Articles and strengthening them. The Amendment extended the scope of the criminal liabilities under the Chinese Law in an effort to address various emerging issues. In particular, the Amendment clarified issues related to bribery and data privacy. In relation to data privacy, the Amendment added provisions on the illegal sale of a citizen’s personal information and further prescribed punishments for such crimes.

The Cybersecurity Law of 2017 was the first Chinese law to address cybersecurity and data protection. Thereafter, there were various rules and guidelines which were introduced under the Cybersecurity Law such as- National Standard of Information Security Technology – Personal Information Security Specification (PIS Specification), 2020; Guidelines on Internet Personal Information Security Protection, 2019; and National Standard of Information Security Technology – Guidelines on Personal Information Security Impact Assessment, 2021.

In 2020, a draft Personal Information Protection Law (“PIPL”) was published for consultation, which came into effect on 20th August 2021. This law is China’s first all-encompassing legal attempt to define personal information and regulate the processing of personal information.


Comments

Leave a comment

Design a site like this with WordPress.com
Get started