Those handling important data shall clearly specify responsible personnel and management bodies for data security and fully implement data security protection responsibilities. Article 28 Any data handling activity as well as the research and development of new data technologies shall benefit the advancement of economic and social development, enhance the people's welfare, and conform to social morals and ethics. Article 29 Those conducting data handling activities shall strengthen risk monitoring, and where they discover risks such as data security flaws and vulnerabilities, immediately adopt remedial measures; when data security incidents occur, they shall immediately take disposal measures, notify the users as required and report the matter to the relevant competent department. Article 30 Those handling important data shall, in accordance with relevant provisions, periodically conduct risk assessments for their data handling activities, and submit a risk assessment report to the relevant competent department. The risk assessment report shall include the categories and quantities of important data handled by the said organization, how data are handled, the data security risks faced and their countermeasures. Article 31 The security administration of the cross-border transfer of important data collected and generated by operators of critical information infrastructure during their operation in China shall be subject to the provisions of the Cybersecurity Law of the People's Republic of China; the administrative measures for the cross-border transfer of important data collected and generated by other data handlers during their operation in the People's Republic of China shall be formulated by the national cyberspace administration authority in collaboration with relevant departments of the State Council. Article 32 Any organization or individual collecting data shall adopt lawful and proper methods and shall not steal data or obtain them by other illegal means. Where any law and administrative regulation contains provisions on the purpose or scope of data collection or use, data shall be collected and used for the purpose and within the scope prescribed by such law and administrative regulation. Article 33 Institutions engaging in data transaction intermediary services shall, when providing their services, require the data providers to explain the source of data, examine and verify the identity of both parties to the transaction, and retain examination, verification, and transaction records. Article 34 Where any law and administrative regulation stipulates that administrative license shall be obtained before providing any service related to data handling, the service providers shall obtain such license in accordance with the law. Article 35 Where public security organs and national security organs need to consult any data in order to safeguard national security or investigate a crime in accordance with the law, they shall, in accordance with the relevant provisions of the State, undergo strict approval procedures and proceed with the matter in accordance with the law; and the relevant organizations and individuals shall render cooperation. Article 36 The competent authority of the People's Republic of China shall handle the request for providing any data from a foreign judicial body and law enforcement body in accordance with relevant laws and the international treaty or agreement which the People's Republic of China has concluded or acceded to, or under the principle of equality and mutual benefit. Any organization or individual within the territory of the People's Republic of China shall not provide any foreign judicial body and law enforcement body with any data stored within the territory of the People's Republic of China without the approval of the competent authority of the People's Republic of China. 5

Seleccionar párrafo de destino3