or complete it in a timely manner.
Article 47 Under any of the following circumstances, a personal information processor shall delete personal
information of an individual on its/his/her own initiative; or the individual has the right to request the
deletion if the personal information processor fails to do so:
1. Where the purpose of processing has been achieved or is unable to be achieved, or the personal
information is no longer necessary for achieving the purpose of processing;
2. Where the personal information processor ceases the provision of the product or service involved, or the
retention period has expired;
3. Where consent is withdrawn by the individual;
4. Where the processing of personal information by the personal information processor is in violation of any
law, administrative regulations or agreement; or
5. Any other circumstance as provided by law or administrative regulations.
If the retention period prescribed by laws or administrative regulations has not expired, or it is technically
difficult to delete the personal information, the personal information processor shall cease the processing of
the personal information, except for the storage and any necessary measure taken for security protection.
Article 48 Individuals have the right to require personal information processors to explain their rules of
processing of personal information.
Article 49 In the event of death of a natural person, a close relative of the individual may exercise the rights
to access, make copies of, have corrected or deleted and other rights to the relevant personal information of
the natural person as provided for by this Chapter, unless the deceased has arranged otherwise before death.
Article 50 Personal information processors shall establish an accessible mechanism for receiving requests
from individuals to exercise their rights. For any request to exercise his/her rights made by an individual that
is denied, an explanation of reasons shall be provided.
Individuals may bring a lawsuit in a people's court against a personal information processor for the latter's
denial of their request to exercise their rights.
Chapter V Obligations of Personal Information Processors
Article 51 Personal information processors shall, based on their purpose and method of processing of
personal information, the type of personal information processed and the impact on personal rights and
interests, any potential security risk, etc., take the following measures to ensure the compliance of their
activities of processing of personal information with laws and administrative regulations, and prevent any
unauthorized access to, leakage of, tampering with, or loss of personal information:
1. Developing an internal management system and operating procedures;
2. Managing personal information based on classification;
3. Taking appropriate technical security measures such as encryption and de-identification;
4. Reasonably determining the authorizations to operate the processing of personal information, and
conducting security education and training for employees on a regular basis;
5. Developing and organizing the implementation of emergency plans for personal information security
incidents; and
6. Taking any other measure as required by law or administrative regulations.
Article 52 Personal information processors whose processing of personal information reaches the threshold
amount prescribed by the national cyberspace authority shall appoint a personal information protection
officer to be responsible for supervising their activities of processing of personal information, the protection
measures taken, etc.
Personal information processors shall disclose the contact information of their personal information
8