in an overall way to take the following measures with respect to the security protection of critical
information infrastructure,
1. Conduct random detection on security risks related to critical information infrastructure, and propose
improvement measures; if necessary, it may entrust professional cybersecurity service institutions to carry
out the detection and evaluation of any potential security risks related to the network;
2. Periodically organize critical information infrastructure operators to conduct emergency cybersecurity
drills, and enhance the level and ability of coordination and cooperation to respond to cybersecurity
incidents;
3. Promote cybersecurity information sharing among the relevant departments, critical information
infrastructure operators, relevant research institutions and cybersecurity service institutions; and
4. Provide technical support and assistance for the emergency disposal of cybersecurity incidents and the
recovery of network functions.
Chapter IV Network Information Security
Article 40 Network operators shall strictly keep confidential users' personal information that they have
collected, and establish and improve the users' information protection system.
Article 41 To collect and use personal information, network operators shall follow the principles of legitimacy,
rightfulness and necessity, disclose their rules of data collection and use, clearly express the purposes, means
and scope of collecting and using the information, and obtain the consent of the persons whose data is
gathered.
Network operators shall neither gather personal information unrelated to the services they provide, nor
gather or use personal information in violation of the provisions of laws and administrative regulations or the
agreements arrived at; and shall dispose of personal information they have saved in accordance with the
provisions of laws and administrative regulations and agreements reached with users.
Article 42 Network operators shall not disclose, tamper with or corrupt the personal information collected by
them, and shall not provide any such personal information to any other person without the consent of the
person from whom the information was collected, except where information has been processed to the
extent that it cannot identify a specific individual and cannot be restored.
Network operators shall adopt technical measures and other necessary measures to ensure the security of
the personal information they have collected and prevent such information from being divulged, damaged or
lost. If personal information has been or may be divulged, damaged or lost, it is necessary to take remedial
measures immediately, inform users promptly according to the provisions and report the same to the
relevant competent departments.
Article 43 Where individuals discover that network operators gather or use their personal information in
violation of the provisions of laws and administrative regulations or the agreements arrived at, they have the
right to request the network operators to delete their personal information; where they find that their
personal information gathered or stored by network operators is subject to any mistake, they have the right
to request the network operators to make corrections. Network operators shall take measures to delete or
correct the said information.
Article 44 Any individual or organization may neither acquire personal information by stealing or through
other illegal ways, nor illegally sell or provide personal information to others.
Article 45 The departments and their staff members responsible for the supervision and management of
cybersecurity in accordance with the law shall strictly maintain the confidentiality of personal information,
privacy and trade secrets known thereby in fulfilling their duties, and shall not divulge, sell or illegally provide
the same to others.
7