or complete it in a timely manner. Article 47 Under any of the following circumstances, a personal information processor shall delete personal information of an individual on its/his/her own initiative; or the individual has the right to request the deletion if the personal information processor fails to do so: 1. Where the purpose of processing has been achieved or is unable to be achieved, or the personal information is no longer necessary for achieving the purpose of processing; 2. Where the personal information processor ceases the provision of the product or service involved, or the retention period has expired; 3. Where consent is withdrawn by the individual; 4. Where the processing of personal information by the personal information processor is in violation of any law, administrative regulations or agreement; or 5. Any other circumstance as provided by law or administrative regulations. If the retention period prescribed by laws or administrative regulations has not expired, or it is technically difficult to delete the personal information, the personal information processor shall cease the processing of the personal information, except for the storage and any necessary measure taken for security protection. Article 48 Individuals have the right to require personal information processors to explain their rules of processing of personal information. Article 49 In the event of death of a natural person, a close relative of the individual may exercise the rights to access, make copies of, have corrected or deleted and other rights to the relevant personal information of the natural person as provided for by this Chapter, unless the deceased has arranged otherwise before death. Article 50 Personal information processors shall establish an accessible mechanism for receiving requests from individuals to exercise their rights. For any request to exercise his/her rights made by an individual that is denied, an explanation of reasons shall be provided. Individuals may bring a lawsuit in a people's court against a personal information processor for the latter's denial of their request to exercise their rights. Chapter V Obligations of Personal Information Processors Article 51 Personal information processors shall, based on their purpose and method of processing of personal information, the type of personal information processed and the impact on personal rights and interests, any potential security risk, etc., take the following measures to ensure the compliance of their activities of processing of personal information with laws and administrative regulations, and prevent any unauthorized access to, leakage of, tampering with, or loss of personal information: 1. Developing an internal management system and operating procedures; 2. Managing personal information based on classification; 3. Taking appropriate technical security measures such as encryption and de-identification; 4. Reasonably determining the authorizations to operate the processing of personal information, and conducting security education and training for employees on a regular basis; 5. Developing and organizing the implementation of emergency plans for personal information security incidents; and 6. Taking any other measure as required by law or administrative regulations. Article 52 Personal information processors whose processing of personal information reaches the threshold amount prescribed by the national cyberspace authority shall appoint a personal information protection officer to be responsible for supervising their activities of processing of personal information, the protection measures taken, etc. Personal information processors shall disclose the contact information of their personal information 8

Select target paragraph3