[{"content":"AI 生成内容的标识义务：《生成式人工智能服务管理暂行办法》与《人工智能生成合成内容标识办法》的合规要点 一、问题的提出 生成式人工智能的合规风险，常常不是从\u0026quot;模型能不能用\u0026quot;开始，而是从\u0026quot;生成的东西有没有被认出来\u0026quot;开始。未经标识的 AI 生成内容一旦进入传播链条，就可能成为虚假信息与侵权内容的载体。正因如此，内容标识成为中国生成式人工智能监管中最先落地、也最易触碰的义务。\n2025 年 9 月 1 日，《人工智能生成合成内容标识办法》（以下简称《标识办法》）施行，与《生成式人工智能服务管理暂行办法》（以下简称《生成式 AI 办法》）、《互联网信息服务深度合成管理规定》（以下简称《深度合成规定》）形成衔接。本文梳理标识义务的规范依据、义务结构与落地要点。\n二、规范依据与适用范围 2.1 三部规范的阶梯关系 《深度合成规定》（国家互联网信息办公室、工业和信息化部、公安部令第 12 号，2022 年 11 月 25 日公布，2023 年 1 月 10 日起施行）确立底线：第十六条要求对生成或者编辑的信息内容\u0026quot;采取技术措施添加不影响用户使用的标识\u0026quot;；第十七条对可能导致公众混淆或者误认的情形（智能对话、智能写作等模拟自然人进行文本生成或者编辑的服务，人脸生成、替换、操控，合成人声、仿声等）要求显著标识；第十八条禁止以技术手段删除、篡改、隐匿上述标识。 《生成式 AI 办法》（国家互联网信息办公室、国家发展和改革委员会、教育部、科学技术部、工业和信息化部、公安部、国家广播电视总局令第 15 号，2023 年 7 月 10 日公布，2023 年 8 月 15 日起施行）第十二条作衔接性规定：\u0026ldquo;提供者应当按照《互联网信息服务深度合成管理规定》对图片、视频等生成内容进行标识。\u0026rdquo; 《标识办法》（国家互联网信息办公室、工业和信息化部、公安部、国家广播电视总局，国信办通字〔2025〕2 号，2025 年 3 月 7 日发布，2025 年 9 月 1 日起施行）把标识从原则要求细化为技术与流程规则，并区分显式标识与隐式标识。 2.2 四类主体，义务各不同 依《标识办法》第二条，适用主体是\u0026quot;符合《互联网信息服务算法推荐管理规定》《互联网信息服务深度合成管理规定》《生成式人工智能服务管理暂行办法》规定情形的网络信息服务提供者\u0026quot;。结合条文，实践涉及四类角色：\n角色 核心义务 依据 生成合成服务提供者 添加显式与隐式标识、协议告知、日志留存 《标识办法》第四、五、八、九条 网络信息内容传播服务提供者 核验元数据、对无标识或疑似内容加提示、提供标识功能 《标识办法》第六条 应用程序分发平台 上架或上线审核时核验标识材料 《标识办法》第七条 用户 主动声明并标识、不得恶意删除篡改标识 《标识办法》第十条 提示：义务主体不限于大模型厂商——只要落入上述规章的适用情形，或提供内容传播、应用分发服务，即各自落到相应义务上。\n三、标识义务的三层结构 3.1 显式标识：让用户明显感知 《标识办法》第四条针对属于《深度合成规定》第十七条第一款情形的服务，按媒介分别要求：文本在起始、末尾或者中间适当位置添加文字提示或者通用符号提示，或在交互场景界面、文字周边添加显著提示标识；音频添加语音提示或者音频节奏提示；图片在适当位置添加显著提示标识；视频在起始画面和播放周边适当位置添加（可在末尾和中间适当位置补充）；虚拟场景在起始画面适当位置添加；其他场景按自身应用特点添加显著提示标识。\n易被忽略的一处：该条第二款规定，提供生成合成内容下载、复制、导出等功能时，\u0026ldquo;应当确保文件中含有满足要求的显式标识\u0026rdquo;。很多产品只在界面内提示，用户一键导出的文件却干干净净——导出环节正是显式标识的检查点。\n3.2 隐式标识：写入文件元数据 《标识办法》第五条要求按《深度合成规定》第十六条，在文件元数据中添加隐式标识，包含生成合成内容属性信息、服务提供者名称或者编码、内容编号等制作要素信息，并鼓励添加数字水印。同条第三款界定\u0026quot;文件元数据\u0026quot;为按特定编码格式嵌入文件头部的描述性信息。其合规含义有两层。一是内容脱离原界面、被转发到其他平台后，仍可通过元数据回溯生成者。二是转码、压缩环节把元数据清掉，效果等同于未履行义务。\n3.3 传播端核验：平台的四种情形 《标识办法》第六条把传播服务提供者的义务拆为四种情形：\n元数据中含有隐式标识的，在发布内容周边添加显著提示标识，明确提醒公众该内容属于生成合成内容； 元数据中未核验到隐式标识、但用户声明为生成合成内容的，添加提示标识，提醒公众该内容可能为生成合成内容； 元数据中未核验到隐式标识、用户也未声明，但平台检测到显式标识或者其他生成合成痕迹的，识别为疑似生成合成内容并添加提示标识； 提供必要的标识功能，并提醒用户主动声明发布内容中是否包含生成合成内容。 属于前三项情形的，还应当在文件元数据中添加生成合成内容属性信息、传播平台名称或者编码、内容编号等传播要素信息。\n四、三项容易被忽视的规则 其一，无显式标识内容的提供与日志留存。《标识办法》第九条允许用户申请提供不含显式标识的生成合成内容，但设定了两个前提：通过用户协议明确用户的标识义务和使用责任；依法留存提供对象信息等相关日志不少于六个月。这不是豁免条款，而是把风险部分转移给用户。\n其二，用户声明义务与\u0026quot;去标识\u0026quot;禁令。《标识办法》第十条规定，用户发布生成合成内容的，应当主动声明并使用服务提供者提供的标识功能进行标识；并明确任何组织和个人不得恶意删除、篡改、伪造、隐匿标识，不得为他人实施上述恶意行为提供工具或者服务——后半句直接指向\u0026quot;去标识工具\u0026quot;类产品。\n其三，协议条款与强制性国家标准。《标识办法》第八条要求服务提供者在用户服务协议中明确说明标识的方法、样式等规范内容并提示用户理解；第十一条要求标识活动还应当符合相关法律、行政法规、部门规章和强制性国家标准的要求。第九条的合规效果，直接取决于协议是否把用户义务写清楚。\n五、与算法备案、安全评估的衔接 《生成式 AI 办法》第十七条规定，提供具有舆论属性或者社会动员能力的生成式人工智能服务的，应当开展安全评估，并按照《互联网信息服务算法推荐管理规定》履行算法备案手续；《深度合成规定》第十九条要求完成备案者在网站、应用程序显著位置标明备案编号并提供公示信息链接。\n《标识办法》第十二条把两条线拧在一起：服务提供者在履行算法备案、安全评估等手续时，应当按照本办法提供标识相关材料。实务提示：标识的技术细节（水印算法、元数据格式、服务商编码等）会进入备案与评估材料，法务与技术对接应前置到产品设计阶段。\n六、法律责任 《标识办法》第十三条规定，违反本办法的，由网信、电信、公安和广播电视等有关主管部门依据职责，按有关法律、行政法规、部门规章的规定予以处理。《生成式 AI 办法》第二十一条规定，提供者违反本办法的，依照《网络安全法》《数据安全法》《个人信息保护法》《科学技术进步法》等予以处罚；法律、行政法规没有规定的，予以警告、通报批评，责令限期改正；拒不改正或者情节严重的，责令暂停提供相关服务；构成犯罪的，依法追究刑事责任。\n把上述两条放在一起看，逻辑是一致的：标识义务以\u0026quot;衔接条款＋兜底责任\u0026quot;落地，实际处罚依据回到《网络安全法》《数据安全法》《个人信息保护法》等上位法。标识不是行业自律事项，而是有明确法律后果的义务。\n七、企业落地清单 角色定位：判断自己属于生成合成服务提供者、传播服务提供者还是分发平台，义务清单不同； 显式标识落到文件：界面提示之外，导出、下载、复制的文件里也要有； 隐式标识落到元数据：确定字段结构，防止转码、压缩环节清除； 传播端核验：按第六条四种情形设计检测与提示逻辑，并写入传播要素信息； 协议改造：在用户服务协议中加入标识方法与用户义务条款，覆盖第九条情形； 日志留存：无显式标识内容的提供记录留存不少于六个月； 备案材料同步：把标识技术细节纳入算法备案与安全评估材料； 内部红线：禁止开发或提供\u0026quot;去标识\u0026quot;工具，将恶意删除、篡改、伪造、隐匿标识纳入风控。 结语 标识义务的制度逻辑，是让 AI 生成内容在传播链的每个环节都可识别、可追溯。企业真正需要警惕的是义务被拆散到各业务环节后没有人对总账：产品做界面提示、技术做元数据、法务写协议、平台做核验——任何一环缺失，整条合规链就断了。\n规范依据（供核对）\n《互联网信息服务深度合成管理规定》，国家互联网信息办公室、工业和信息化部、公安部令第 12 号，2022 年 11 月 25 日公布，2023 年 1 月 10 日起施行。 《生成式人工智能服务管理暂行办法》，国家互联网信息办公室、国家发展和改革委员会、教育部、科学技术部、工业和信息化部、公安部、国家广播电视总局令第 15 号，2023 年 7 月 10 日公布，2023 年 8 月 15 日起施行。 《人工智能生成合成内容标识办法》，国信办通字〔2025〕2 号，2025 年 3 月 7 日发布，2025 年 9 月 1 日起施行。 ","permalink":"https://intlaws.com/forum/ai%E7%94%9F%E6%88%90%E5%86%85%E5%AE%B9%E7%9A%84%E6%A0%87%E8%AF%86%E4%B9%89%E5%8A%A1-%E5%90%88%E8%A7%84%E8%A6%81%E7%82%B9/","summary":"梳理AI生成内容标识义务的完整链条：显式标识须落到导出文件、隐式标识须写入元数据且防转码清除、传播平台按四种情形核验提示，并明确「去标识工具」提供行为被明文禁止。","title":"AI 生成内容的标识义务：《生成式人工智能服务管理暂行办法》与《人工智能生成合成内容标识办法》的合规要点"},{"content":"Data Security Law of the People\u0026rsquo;s Republic of China Version and sources (verifiable)\nItem Content Adopted 29th Meeting of the Standing Committee of the 13th NPC, June 10, 2021 In force September 1, 2021 Chinese original source Cyberspace Administration of China: https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm English translation source NPC official English site (Translation for Reference Only): http://en.npc.gov.cn.cdurl.cn/2021-06/10/c_689311.htm Verification Retrieved 2026-09-22; 7 chapters / 55 articles; 1:1 correspondence, no gaps Chapter I General Provisions Article 1 This Law is enacted for the purpose of regulating data processing, ensuring data security, promoting development and utilization of data, protecting the lawful rights and interests of individuals and organizations, and safeguarding the sovereignty, security, and development interests of the state.\nArticle 2 This Law shall apply to data processing activities and security supervision and regulation of such activities within the territory of the People\u0026rsquo;s Republic of China. Where data processing outside the territory of People\u0026rsquo;s Republic of China harms the national security, public interests, or the lawful rights and interests of individuals or organizations of the People\u0026rsquo;s Republic of China, legal liability shall be investigated in accordance with the law.\nArticle 3 For the purpose of this Law, the term \u0026ldquo;data\u0026rdquo; refers to any record of information in electronic or any other form. \u0026ldquo;Data processing\u0026rdquo; includes the collection, storage, use, processing, transmission, provision, and disclosure of data, among others. \u0026ldquo;Data security\u0026rdquo; refers to ensuring that data is effectively protected and lawfully used through adopting necessary measures, and to possessing the capacity to guarantee the continuous security of data.\nArticle 4 In preserving data security, the holistic approach to national security shall be adopted, sound data security governance systems shall be established, and data security and protection capabilities shall be improved.\nArticle 5 The central leading authority for national security shall be responsible for the decision-making, deliberation and coordination of the national data security work; researching, formulating, and guiding the implementation of the national data security strategy and related major guidelines and policies; coordinating major matters and important work in respect of national data security; and establishing a coordination mechanism for national data security.\nArticle 6 All localities and departments shall bear responsibility for the management of the data collected or generated in their work as well as for the data security thereof. The competent departments of industry, telecommunications, transport, finance, natural resources, health, education, technology and other relevant competent departments shall assume the responsibilities of supervising and regulating data security in their respective trades and sectors. Public security organs and national security organs, etc. shall assume the responsibilities of supervising and regulating data security within the scopes of their respective duties in accordance with the provisions of this Law and other relevant laws and administrative regulations. The national cyberspace affairs department shall be in charge of the overall planning and coordination of network data security and the related supervision and regulation in accordance with the provisions of this Law and other relevant laws and administrative regulations.\nArticle 7 The state shall protect the data-related rights and interests of individuals and organizations, encourage the lawful, reasonable, and effective use of data, ensure free flow of data in an orderly manner and in accordance with the law, and promote the development of a digital economy with data as the key factor.\nArticle 8 Whoever processes data shall observe laws and regulations, respect social morality and ethics, observe business and professional ethics, uphold honesty and trustworthiness, fulfill data security protection obligations, and undertake social responsibilities; and shall not endanger national security and public interests, nor harm the lawful rights and interests of individuals and organizations.\nArticle 9 The state supports the dissemination and popularization of knowledge of data security to raise public awareness in this regard and ability to protect data security, and promotes the joint participation by relevant departments, industry organizations, research institutions, enterprises, and individuals in data security protection, so as to create a good environment for members of the whole society to jointly protect data, ensure data security and promote development of relevant industries.\nArticle 10 Relevant industry associations shall, in accordance with their articles of association, formulate the code of conduct and standards to ensure data security according to the law, strengthen self-regulation in their respective industries, guide members to strengthen data security protection, improve their protection level and promote the healthy development of the industries.\nArticle 11 The state shall actively carry out international exchanges and cooperation in fields such as data security governance and data development and utilization, participate in the formulation of relevant international rules and standards for data security, and promote the safe and free flow of data across borders.\nArticle 12 Any individual or organization shall have the right to file complaints about or report violations of this Law to the competent departments. The departments receiving such complaints or reports shall deal with them in a timely manner in accordance with the law. The competent departments shall keep confidential the relevant information of those making such complaints or reports, and protect their lawful rights and interests. Data Security and Development\nChapter II Data Security and Development Article 13 The state shall make an overall plan to coordinate development and security, to promote data security through data development and utilization and through industrial development on one hand, and on the other hand, to ensure that data security facilitates data development and utilization as well as industrial development.\nArticle 14 The state shall implement the big data strategy, advance the construction of data infrastructure, and encourage and support the innovative application of data in all industries and fields. People\u0026rsquo;s governments at or above the provincial level shall incorporate the development of digital economy into their national economic and social development plans, and formulate development plans for the digital economy as needed.\nArticle 15 The state supports development and utilization of data to render public services smarter. In providing smarter public services, the needs of the elderly and the disabled shall be taken into full account to avoid posing obstacles to their daily lives.\nArticle 16 The state supports research on development and utilization of data and on data security related technologies, encourages popularization and commercial innovation of technologies in the foregoing fields, and fosters and develops products and industrial systems for development and utilization of data and for data security.\nArticle 17 The state shall advance the forming of the standards for data development and the standards for data utilization technologies and data security. The department in charge of standardization under the State Council and other relevant departments under the State Council shall, within the scopes of their respective duties and functions, organize the establishment of, and make revisions in due time to the standards for technologies and products for data development and data utilization and the standards for data security. The state shall support enterprises, social groups, and education or research institutions, etc. in their participation in the establishment of such standards.\nArticle 18 The state encourages the development of services such as data security testing, evaluation, and accreditation, and supports agencies specialized in data security testing, evaluation, accreditation, etc. to provide services according to the law. The state supports collaboration among relevant departments, industry associations, enterprises, education and research institutions, relevant specialized agencies, etc. in the fields such as data security related risk assessment, prevention, and disposal .\nArticle 19 The state shall establish sound systems for data trading management, standardize data trading activities, and foster a data trading market.\nArticle 20 The state supports education and research institutions, enterprises, and other entities in carrying out education and training on technologies for data development and utilization and on data security, cultivates professionals in data development and utilization technologies and in data security by a variety of means, and promotes talent exchanges. Data Security Systems\nChapter III Data Security Systems Article 21 The state shall establish a categorized and classified system and carry out data protection based on the importance of the data in economic and social development, as well as the extent of harm to national security, public interests, or the lawful rights and interests of individuals or organizations that will be caused once the data are altered, destroyed, leaked, or illegally obtained or used. The coordination mechanism for national data security shall coordinate the relevant departments to formulate a catalog of important data and strengthen protection of important data. Data concerning national security, lifelines of the national economy, important aspects of people\u0026rsquo;s lives, major public interests, ect., are core data of the state, for which a stricter management system shall be implemented. All localities and departments shall, in accordance with the categorized and classified data protection system, prepare specific catalogs of important data for their respective regions, departments, and relevant industries and sectors, and give priority to the data listed in the catalogs in terms of data protection.\nArticle 22 The state shall establish a centralized, unified, highly effective, and authoritative mechanism for assessing, reporting, information sharing, monitoring, and early alert of data security risks. The coordinating mechanism for national data security shall make an overall plan on and coordinate relevant departments in strengthening the work about acquiring, analyzing, researching and evaluating information of data security risks and the work about early alert of such risks.\nArticle 23 The state shall establish a data security emergency response mechanism. Where a data security incident occurs, the relevant competent departments shall initiate emergency response in accordance with the plan and the law, take corresponding measures to prevent further harm and eliminate security hazards, and send out warnings to the public by publishing information relevant thereto in a timely manner.\nArticle 24 The state shall establish a review system for data security, conducting national security reviews of data processing that affects or may affect national security. Security review decisions made in accordance with the law are final decisions.\nArticle 25 The state shall apply export control in accordance with the law on data that are controlled items and concern national security and interests and the performance of international obligations.\nArticle 26 Where any country or region adopts discriminatory prohibitions, restrictions, or other similar measures against the People\u0026rsquo;s Republic of China in respect of investment, trade or any other field related to data and data development and utilization technologies, the People\u0026rsquo;s Republic of China may take countermeasures against that country or region in light of the actual circumstances. 1 2 \u0026gt;\nChapter IV Data Security Protection Obligations Article 27 In data processing, the laws and regulations shall be complied with, a sound data security management system throughout the whole process shall be established, data security education and training shall be organized and conducted, and corresponding technical measures and other necessary measures shall be adopted to ensure data security. In data processing by making use of the internet or any other information networks, the abovementioned data security obligations shall be fulfilled on the basis of the classified protection system for cyber security. Processors of important data shall be clear about their persons responsible for data security and the data security management bodies, and fulfill the responsibilities for data security.\nArticle 28 Data processing as well as research and development of new data technologies shall be conducive to furthering economic and social development, and improving the well-being of people, and shall conform to social morals and ethics.\nArticle 29 Closer risk monitoring shall be applied in data processing. Where data security defects, bugs, or other risks are discovered, remedial measures shall be taken immediately. Where a data security incident occurs, measures shall be taken immediately to address it, and users shall be notified and reports made to relevant competent departments in a timely manner in accordance with relevant provisions.\nArticle 30 Processors of important data shall, in accordance with the relevant provisions, conduct risk assessments of their data processing on a regular basis and submit risk assessment reports to relevant competent departments. Risk assessment reports shall include the types and amounts of important data processed, information on data processing, data security risks and the response measures for them.\nArticle 31 The provisions of the Cyber Security Law of the People\u0026rsquo;s Republic of China shall apply to the outbound security management of the important data collected or produced by critical information infrastructure operators during their operation within the territory of the People\u0026rsquo;s Republic of China, and the measures for the outbound security management of the important data collected or produced by others data processors during their operation within the territory of the People\u0026rsquo;s Republic of China shall be formulated by the national cyberspace authority in conjunction with the relevant departments under the State Council.\nArticle 32 An organization or individual shall collect data by lawful and proper means, and shall not acquire data by theft or in other illegal manners. Where laws or administrative regulations have provisions on the purposes or scopes of data collection and use, data shall be collected and used for the purposes and within the scopes provided for by those laws and administrative regulations.\nArticle 33 When providing services, data transaction intermediaries shall require data providers to specify the sources of the data, verify the identities of both parties to the transactions, and retain the verification and transaction records.\nArticle 34 Where laws or administrative regulations require that administrative permissions be acquired for providing services related to data processing, service providers shall obtain such administrative permissions in accordance with these provisions.\nArticle 35 Where a public security organ or national security organ needs to obtain data for the sake of national security or for investigating crimes in accordance with the law, strict approval formalities shall be completed in accordance with the relevant provisions of the state and data be obtained in accordance with the law, and the relevant organizations and individuals shall cooperate.\nArticle 36 The competent authorities of the People\u0026rsquo;s Republic of China shall handle requests for data made by foreign judicial or law enforcement authorities, in accordance with the relevant laws and international treaties or agreements concluded or acceded to by the People\u0026rsquo;s Republic of China, or in accordance with the principles of equality and reciprocity. Without the approval of the competent authorities of the People\u0026rsquo;s Republic of China, organizations or individuals in the People\u0026rsquo;s Republic of China shall not provide data stored within the territory of the People\u0026rsquo;s Republic of China to any overseas judicial or law enforcement body. Security and Openness of Government Data\nChapter V Security and Openness of Government Data Article 37 The state shall make great efforts to promote the development of e-government, make government database more scientific, accurate, and time-efficient, and improve the ability of using data to serve economic and social development.\nArticle 38 Where state organs need to collect or use data to perform their statutory duties, they shall collect or use data within the scope as needed for performance of their statutory duties and under the conditions and procedures provided by laws and administrative regulations. They shall, in accordance with the law, preserve the confidentiality of the data accessed in the course of performing their duties, such as personal privacy, personal information, trade secrets, and confidential business information, and shall not divulge such data or illegally provide them to others.\nArticle 39 State organs shall, in accordance with the provisions of laws and administrative regulations, establish sound data security management systems, fulfill data security protection responsibilities, and ensure the security of government data.\nArticle 40 Where a state organ entrusts others to construct or maintain e-government systems, or to store or process government data, the state organ shall go through strict approval procedures, and shall supervise the entrusted party in the performance of data security protection obligations. The entrusted party shall perform its data security protection obligations in accordance with the provisions of laws, regulations, and contracts signed, and shall not retain, use, divulge, or provide others with government data without authorization.\nArticle 41 State organs shall, under the principles of fairness, equality and convenience for the people, disclose government data in a timely and accurate manner in accordance with the provisions, except those which shall not be disclosed in accordance with the law.\nArticle 42 The state shall formulate the catalog of open government data, build an open, uniform, standardized, interconnected, safe and controllable government data platform, and promote the release and utilization of government data.\nArticle 43 The provisions of this Chapter shall apply to the data processing carried out by the organizations with the functions of administering public affairs as authorized by laws and regulations for the purpose of performing their statutory duties. Legal Liability\nChapter VI Legal Liability Article 44 Where competent departments discover the existence of major security risks in data processing when they perform their regulatory duties as regards data security, they may, in accordance with the prescribed limits of authority and procedures, conduct regulatory talks with the relevant organizations and/or individuals, and require the relevant organizations and/or individuals to adopt measures to make rectifications and eliminate potential hazards.\nArticle 45 Where an organization or individual that processes data fails to perform the data security protection obligations provided in Articles 27, 29 and 30 of this Law, the organization or individual shall be ordered to make rectifications and be given a warning, and may be concurrently fined not less than RMB 50,000 yuan but not more than RMB 500,000 yuan by the competent department, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. Where the organization or individual refuses to make rectifications or has caused serious consequences such as a massive data breach, the organization or individual shall be fined not less than RMB 500,000 yuan but not more than RMB 2 million yuan, and may be ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked, and the directly liable persons in charge and other directly liable persons shall be fined not less than RMB 50,000 yuan but not more than RMB 200,000 yuan. Where the organization or individual violates the national core data management rules and endangers national sovereignty, security, or development interests of the state, the competent department shall impose upon the organization or individual a fine of not less than RMB 2 million yuan but not more than RMB 10 million yuan, and may, based on the circumstances, order a suspension of relevant business or a suspension of operations for rectification, or revoke relevant business permits or the business license. Where a crime is constituted, criminal responsibilities shall be investigated in accordance with the law.\nArticle 46 Whoever, in violation of the provisions of Article 31 of this Law, provides important data abroad, shall be ordered to make rectifications and be given a warning by the competent department, and may be concurrently fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. Where the circumstances are serious, the violator shall be fined not less than RMB 1 million but not more than RMB 10 million yuan, and may also be ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked, and the directly liable persons in charge and other directly liable persons shall be fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan.\nArticle 47 Where a data transaction intermediary fails to perform the obligations prescribed in Article 33 of this Law, it shall be ordered by the competent department to make rectifications, its illegal gains, if any, shall be confiscated, and it shall also be fined not less than the amount of but not more than ten times the amount of the illegal gains; if there are no illegal gains or the illegal gains are less than RMB 100,000 yuan, it shall be fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan. It may be concurrently ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked. The directly liable persons in charge and other directly liable persons shall be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan.\nArticle 48 Whoever in violation of Article 35 of this Law, refuses to cooperate when a public organ or national security organ needs to access the data, shall be ordered by the competent department to make rectifications and be given a warning, and shall be concurrently fined not less than RMB 50,000 yuan but nor more than RMB 500,000 yuan, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. Whoever, in violation of Article 36 of this Law, provides data to an overseas judicial or law enforcement body without the approval of the competent authorities, shall be given a warning by the competent department, and may be concurrently fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. If serious consequences are caused, the violator shall be fined not less than RMB 1 million yuan but not more than RMB 5 million yuan, and may be ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked. The directly liable persons in charge and other directly liable persons shall be fined not less than RMB 50,000 yuan but not more than RMB 500,000 yuan.\nArticle 49 Where a state organ fails to perform data security obligations as provided for in this Law, the directly liable persons in charge and other directly liable persons shall be given a sanction in accordance with the law.\nArticle 50 Any state functionary performing data security related regulation regulation neglects his duty, abuses power, or engages in malpractice for personal gain, shall be given a sanction in accordance with the law.\nArticle 51 Whoever obtains data through theft or by any other illegal means, or eliminates or restricts competition in data processing, or harms the lawful rights and interests of individuals or organizations, shall be punished in accordance with the provisions of relevant laws and administrative regulations.\nArticle 52 Whoever, in violation of this Law, causes damages to others shall bear civil liability in accordance with the law. Where a violation of the provisions of this Law constitutes a violation of public security administration, a public security administrative penalty shall be given in accordance with the law. Where a crime is constituted, criminal responsibility shall be investigated in accordance with the law. Supplementary Provisions\nChapter VII Supplementary Provisions Article 53 The provisions of the Law of the People\u0026rsquo;s Republic of China on Guarding State Secrets and other relevant laws and administrative regulations shall apply to data processing that involves state secrets. The provisions of relevant laws and administrative regulations shall also be observed when data are processed in statistical or archival work and in data processing involving personal information.\nArticle 54 Measures for the military data security and protection shall be separately formulated by the Central Military Commission in accordance with this Law.\nArticle 55 This Law shall come into force as of September 1, 2021. 1 2\n","permalink":"https://intlaws.com/en/compliance/china/dsl/","summary":"Official full text of the Data Security Law of the PRC: 7 chapters, 55 articles, adopted 2021-06-10, in force 2021-09-01. English text from the NPC official English site (marked \u0026ldquo;Translation for Reference Only\u0026rdquo;); Chinese original from the Cyberspace Administration of China.","title":"Data Security Law of the PRC (Full Text)"},{"content":"Personal Information Protection Law of the People\u0026rsquo;s Republic of China Version and sources (verifiable)\nItem Content Adopted 30th Meeting of the Standing Committee of the 13th NPC, August 20, 2021 In force November 1, 2021 Currently effective Yes (no amendment as of 2026-09-22) Chinese original source Cyberspace Administration of China: https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm English translation source NPC official English site, \u0026ldquo;Laws (Translation for Reference Only)\u0026rdquo;: http://en.npc.gov.cn.cdurl.cn/2021-12/29/c_694559.htm (3 pages) Nature of translation Published on the official NPC English site and marked \u0026ldquo;Translation for Reference Only\u0026rdquo; Verification Retrieved 2026-09-22; 8 chapters / 74 articles; article numbers match the Chinese original one-for-one, with no gaps Chapter I General Provisions Article 1 This Law is enacted in accordance with the Constitution for the purposes of protecting the rights and interests on personal information, regulating personal information processing activities, and promoting reasonable use of personal information.\nArticle 2 The personal information of natural persons shall be protected by law. No organization or individual may infringe upon natural persons\u0026rsquo; rights and interests on their personal information.\nArticle 3 This Law shall apply to the processing of personal information of natural persons within the territory of the People\u0026rsquo;s Republic of China. This Law shall also apply to the processing outside the territory of the People\u0026rsquo;s Republic of China of the personal information of natural persons within the territory of the People\u0026rsquo;s Republic of China, under any of the following circumstances: (1) for the purpose of providing products or services for natural persons inside the People\u0026rsquo;s Republic of China; (2) analyzing or evaluating the behaviors of natural persons within the territory of the People\u0026rsquo;s Republic of China; and (3) any other circumstance as provided by any law or administrative regulation.\nArticle 4 \u0026ldquo;Personal information\u0026rdquo; refers to various information related to an identified or identifiable natural person recorded electronically or by other means, but does not include anonymized information. Personal information processing includes personal information collection, storage, use, processing, transmission, provision, disclosure and deletion, among others.\nArticle 5 Personal information shall be processed according to law when it is necessary, with justified reason, and in good faith, and the processing may not involve misguidance, fraud, coercion, and the like.\nArticle 6 Personal information processing shall be based on explicit and reasonable purposes and directly related to those purposes, and shall exert the minimum impacts on the rights and interests of individuals. The collection of personal information shall be limited to the minimum scope required by the purpose of processing, and personal information may not be collected excessively.\nArticle 7 The principles of openness and transparency shall be observed in the processing of personal information, the rules for processing personal information shall be disclosed, and the purposes, means, and scope of processing shall be explicitly indicated.\nArticle 8 The quality of personal information shall be guaranteed in personal information processing, to avoid adverse impacts on the rights and interests of individuals caused by inaccurate and incomplete personal information.\nArticle 9 Personal information processors shall be responsible for their personal information processing activities and take necessary measures to ensure the security of the personal information they process.\nArticle 10 No organization or individual shall illegally collect, use, process, or transmit the personal information of other persons, or illegally trade, provide or disclose the personal information of other persons, or engage in personal information processing activities that endanger national security or harm public interests.\nArticle 11 The state shall establish and improve the personal information protection system to prevent and punish infringements upon the rights and interests on personal information, strengthen publicity and education on personal information protection, and promote a favorable environment for the government, enterprises, relevant industry organizations, and the public to jointly participate in personal information protection.\nArticle 12 The state will actively engage in the development of international rules on personal information protection, promote the international exchanges and cooperation in personal information protection, and encourage the mutual recognition of personal information protection rules and standards, among others, with other countries, regions, and international organizations. Personal Information Processing Rules General Rules\nChapter II Personal Information Processing Rules Section 1 General Rules Article 13 A personal information processor can process personal information of an individual only if one of the following circumstances exists: (1) the individual\u0026rsquo;s consent has been obtained; (2) the processing is necessary for the conclusion or performance of a contract in which the individual is a party, or necessary for human resources management in accordance with the labor rules and regulations established in accordance with the law and the collective contracts signed in accordance with the law; (3) the processing is necessary for the performance of statutory duties or obligations; (4) the processing is necessary for the response to public health emergencies, or for the protection of life, health, and property safety of natural persons in emergencies; (5) the personal information is reasonably processed for news reporting, media supervision, and other activities conducted in the public interest; (6) the personal information disclosed by the individual himself or other legally disclosed personal information of the individual is reasonably processed in accordance with this Law; and (7) other circumstances as provided by laws or administrative regulations. Individual consent shall be obtained for processing personal information if any other relevant provisions of this Law so provide, except under the circumstances specified in Subparagraphs (2) to (7) of the preceding paragraph.\nArticle 14 Where personal information processing is based on individual consent, the individual consent shall be voluntary, explicit, and fully informed. Where any other law or administrative regulation provides that an individual\u0026rsquo;s separate consent or written consent must be obtained for processing personal information, such provisions shall apply. In the case of any change of the purposes or means of personal information processing, or the category of processed personal information, a new consent shall be obtained from the individual.\nArticle 15 Where personal information processing is based on individual consent, an individual shall have the right to withdraw his consent. Personal information processors shall provide convenient ways for individuals to withdraw their consents. The withdrawal of consent shall not affect the validity of the processing activities conducted based on consent before it is withdrawn.\nArticle 16 A personal information processor shall not refuse to provide products or services for an individual on the grounds that the individual withholds his consent for the processing of his personal information or has withdrawn his consent for the processing of personal information, except where the processing of personal information is necessary for the provision of products or services.\nArticle 17 A personal information processor shall, before processing personal information, truthfully, accurately and fully inform an individual of the following matters in a easy-to-notice manner and in clear and easy-to-understand language: (1) the name and contact information of the personal information processor; (2) the purposes and means of personal information processing, and the categories and storage periods of the personal information to be processed; (3) the methods and procedures for the individual to exercise his rights as provided in this Law; and (4) other matters that the individual should be notified of as provided by laws and administrative regulations. Where any matter as set forth in the preceding paragraph changes, the individual shall be informed of the change. Where the personal information processor informs an individual of the matters specified in the first paragraph by formulating personal information processing rules, the processing rules shall be made public and be easy to consult and save.\nArticle 18 When processing personal information, personal information processors are permitted not to inform individuals of the matters specified in the first paragraph of the preceding article where laws or administrative regulations require confidentiality or provide no requirement for such notification. Where it is impossible to notify individuals in a timely manner in a bid to protect natural persons\u0026rsquo; life, health and property safety in case of emergency, the personal information processors shall notify them without delay after the emergency is removed.\nArticle 19 Except as otherwise provided by laws and administrative regulations, the storage period of personal information shall be the minimum time necessary to achieve the purpose of processing.\nArticle 20 Where two or more personal information processors jointly determine the purposes and means of processing certain personal information, they shall reach an agreement on their respective rights and obligations in processing the personal information. However, this agreement shall not affect an individual\u0026rsquo;s request to any one of them to exercise his rights as provided in this Law. Where, in jointly processing certain personal information, a processor infringes the rights and interests on personal information and causes damages, other personal information processors shall bear joint and several liability in accordance with law.\nArticle 21 A personal information processor entrusting the processing of certain personal information to a party shall reach an agreement with the entrusted party on the purposes, period and means of processing, the categories of personal information to be processed and the protection measures, as well as the rights and obligations of both parties, among others, and shall supervise the personal information processing activities of the entrusted party. The entrusted party shall process personal information in accordance with the agreement and may not process personal information beyond the purposes, means and other conditions as agreed upon. Where the entrustment contract has not taken effect, or is invalid, or is revoked or terminated, the entrusted party shall return the personal information in question to the personal information processor or delete it and shall not retain the personal information. Without the consent of the personal information processor, the entrusted party may not sub-contract the processing of personal information to any other party.\nArticle 22 Where a personal information processor needs to transfer personal information due to a merger, division, dissolution, or bankruptcy or for other reasons, the processor shall inform the individuals of the name and contact information of the recipient of the transferred personal information. The recipient shall continue to perform the obligations of the said personal information processor. Any change of the original purposes or means of processing by the recipient shall be subject to individual consent in accordance with this Law.\nArticle 23 To provide personal information for any other processor, a personal information processor shall inform the individuals of the recipient\u0026rsquo;s name and contact information, the purposes and means of processing and the categories of personal information to be processed, and shall obtain the individuals\u0026rsquo; separate consent. The recipient shall process personal information within the scope of the purposes, means, and categories of personal information mentioned above. Any change of the purposes or means of processing by the recipient shall be subject to individual consent in accordance with this Law.\nArticle 24 Personal information processors using personal information for automated decision making shall ensure the transparency of the decision making and the fairness and impartiality of the results, and may not apply unreasonable differential treatment to individuals in terms of transaction prices and other transaction conditions. Information push and commercial marketing to individuals based on automated decision making shall be simultaneously accompanied by options not specific to their personal characteristics or with convenient means for individuals to refuse. Where a decision that may have a significant impact on an individual\u0026rsquo;s rights and interests is made through automated decision making, the individual shall have the right to request clarification from the personal information processor and the right to refuse the processor for making the decision only through automated decision making.\nArticle 25 Personal information processors shall not disclose the personal information they process, except where separate consents has been obtained from the individuals. 1 2 3 \u0026gt;\nArticle 26 Image collection and personal identification equipment in public places shall be installed only when it is necessary for the purpose of maintaining public security, and shall be installed in compliance with the relevant provisions of the state and with prominent reminders. The personal images and identification information collected can only be used for the purpose of maintaining public security and, unless the individuals\u0026rsquo; separate consents are obtained, shall not be used for any other purpose.\nArticle 27 A personal information processor may reasonably process the personal information disclosed by an individual himself or other legally disclosed personal information, except where the individual expressly refuses. Where the processing of disclosed personal information may have a significant impact on an individual\u0026rsquo;s rights and interests, the personal information processors shall first obtain the individual\u0026rsquo;s consent in accordance with the provisions of this Law. Rules on Processing Sensitive Personal Information\nSection 2 Rules on Processing Sensitive Personal Information Article 28 \u0026ldquo;Sensitive personal information\u0026rdquo; is personal information that once leaked or illegally used, may easily lead to the infringement of the personal dignity of a natural person or may endanger his personal safety or property, including information such as biometrics, religious belief, specific identity, medical health status, financial accounts, and the person\u0026rsquo;s whereabouts, as well as the personal information of a minor under the age of 14 years. Personal information processors can process sensitive personal information only when there is a specific purpose and when it is of necessity, under the circumstance where strict protective measures are taken.\nArticle 29 For the processing of sensitive personal information, individual\u0026rsquo;s separate consent shall be obtained. Where other laws or administrative regulations provide that written consent shall be obtained for the processing of sensitive personal information, such provisions shall prevail.\nArticle 30 In addition to the matters specified in the first paragraph of Article 17 of this Law, a processor processing sensitive personal information shall notify an individual of the necessity of processing his sensitive personal information and the impact it has on his rights and interests, except where such notification is not required in accordance with the provisions of this Law.\nArticle 31 To process the personal information of minors under the age of 14, personal information processors shall obtain the consent of the parents or other guardians of the minors. Personal information processors processing the personal information of minors under the age of 14 shall develop special rules for processing such personal information.\nArticle 32 Where other laws or administrative regulations provide that relevant administrative permit shall be obtained for the processing of sensitive personal information or impose other restrictions, such provisions shall prevail. Special Provisions on the Processing of Personal Information by State Organs\nSection 3 Special Provisions on the Processing of Personal Information by State Organs Article 33 This Law shall apply to the processing of personal information by state organs; where there are special provisions in this Section, the provisions of this Section shall prevail.\nArticle 34 When state organs process personal information in order to perform their statutory duties, they shall act in accordance with the authority and procedures prescribed by laws and administrative regulations, and shall not exceed the scope and limits necessary to perform their statutory duties.\nArticle 35 When state organs process personal information in order to perform their statutory duties, they shall fulfill the obligation of notification in accordance with the provisions of this Law, except under the circumstances specified in the first paragraph of Article 18 of this Law or where notification will hinder the state organs from performing their statutory duties.\nArticle 36 Personal information processed by state organs shall be stored within the territory of the People\u0026rsquo;s Republic of China. A security assessment shall be conducted where it is truly necessary to provide such information for any party outside of the territory of the People\u0026rsquo;s Republic of China. In the security assessment the relevant departments shall provide support and assistance if so requested.\nArticle 37 Where organizations authorized by laws or regulations with the function of administering public affairs process personal information in order to fulfill their statutory duties, the provisions herein on the processing of personal information by state organs shall apply. Rules on Provision of Personal Information Across Border\nChapter III Rules on Provision of Personal Information Across Border Article 38 A personal information processor that truly needs to provide personal information for a party outside the territory of the People\u0026rsquo;s Republic of China for business sake or other reasons, shall meet one of the following requirements: (1) passing the security assessment organized by the national cyberspace department in accordance with Article 40 of this Law; (2) obtaining personal information protection certification from the relevant specialized institution according to the provisions issued by the national cyberspace department; (3) concluding a contract stipulating both parties\u0026rsquo; rights and obligations with the overseas recipient in accordance with the standard contract formulated by the national cyberspace department; and (4) meeting other conditions set forth by laws and administrative regulations and by the national cyberspace department. Where an international treaty or agreement that the People\u0026rsquo;s Republic of China has concluded or acceded to stipulates conditions for providing personal information for a party outside the territory of the People\u0026rsquo;s Republic of China, such stipulations may be followed. The personal information processor shall take necessary measures to ensure that the personal information processing activities of the overseas recipient meet the personal information protection standards set forth in this Law.\nArticle 39 Where a personal information processor provides personal information for any party outside the territory of the People\u0026rsquo;s Republic of China, the processor shall inform the individuals of the overseas recipient\u0026rsquo;s name and contact information, the purposes and means of processing, the categories of personal information to be processed, as well as the methods and procedures for the individuals to exercise their rights as provided in this Law over the overseas recipient, etc., and shall obtain individual\u0026rsquo;s separate consent.\nArticle 40 Critical information infrastructure operators and the personal information processors that process personal information up to the amount prescribed by the national cyberspace department shall store domestically the personal information collected and generated within the territory of the People\u0026rsquo;s Republic of China. Where it is truly necessary to provide the information for a party outside the territory of the People\u0026rsquo;s Republic of China, the matter shall be subjected to security assessment organized by the national cyberspace department. Where laws, administrative regulations, or the provisions issued by the national cyberspace department provide that security assessment is not necessary, such provisions shall prevail.\nArticle 41 The competent authorities of the People\u0026rsquo;s Republic of China shall handle foreign judicial or law enforcement authorities\u0026rsquo; requests for personal information stored within China in accordance with relevant laws and the international treaties and agreements concluded or acceded to by the People\u0026rsquo;s Republic of China, or under the principle of equality and reciprocity. Without the approval of the competent authorities of the People\u0026rsquo;s Republic of China, no organization or individual shall provide data stored in the territory of the People\u0026rsquo;s Republic of China for any foreign judicial or law enforcement authority.\nArticle 42 Where overseas organizations or individuals engage in personal information processing activities, which infringe upon the rights and interests of citizens of the People\u0026rsquo;s Republic of China on personal information or endanger the national security or public interests of the People\u0026rsquo;s Republic of China, the national cyberspace department may include them in a list of restricted or prohibited recipients of personal information, publicize the list, and take measures such as restricting or prohibiting the provision of personal information for such organizations and individuals.\nArticle 43 Where any country or region adopts any prohibitive, restrictive or other similar discriminatory measures against the People\u0026rsquo;s Republic of China in terms of personal information protection, the People\u0026rsquo;s Republic of China may take countermeasures against the aforesaid country or region based on actual situations. Individuals\u0026rsquo; Rights in Personal Information Processing Activities\nChapter IV Individuals\u0026rsquo; Rights in Personal Information Processing Activities Article 44 Individuals shall have the right to be informed, the right to make decisions on the processing of their personal information, and the right to restrict or refuse the processing of their personal information by others, except as otherwise provided by laws or administrative regulations.\nArticle 45 Individuals shall have the right to consult and duplicate their personal information from personal information processors, except under circumstances as set out in the first paragraph of Article 18 and Article 35 of this Law. Where an individual requests the consultation or duplication of his personal information, the requested personal information processor shall provide such information in a timely manner. Where an individual requests the transfer of his personal information to a designated personal information processor, which meets the requirements of national cyberspace department for transferring personal information , the requested personal information processor shall provide means for the transfer.\nArticle 46 Where an individual discovers that his personal information is incorrect or incomplete, he shall have the right to request the personal information processors to rectify or supplement relevant information. Where an individual requests the rectification or supplementation of his personal information, the personal information processors shall verify the information in question, and make rectification or supplementation in a timely manner.\nArticle 47 In any of the following circumstances, a personal information processor shall take the initiative to erase personal information, and an individual has the right to request the deletion of his personal information if the personal information processor fails to erase the information: (1) the purposes of processing have been achieved or cannot be achieved, or such information is no longer necessary for achieving the purposes of processing; (2) the personal information processor ceases to provide products or services, or the storage period has expired; (3) the individual withdraws his consent; (4) the personal information processor processes personal information in violation of laws, administrative regulations, or agreements; or (5) other circumstances as provided by laws and administrative regulations. Where the storage period provided by any law or administrative regulation has not expired, or it is difficult to erase personal information technically, the personal information processor shall cease the processing of personal information other than storing and taking necessary security protection measures for such information.\nArticle 48 An individuals has the right to request a personal information processor to interpret the personal information processing rules developed by the latter.\nArticle 49 The close relatives of a deceased natural person may, for their own legal and legitimate interests, exercise the rights to handle the personal information of the deceased, such as consultation, duplication, rectification, and deletion, as provided in this Chapter, except as otherwise arranged by the deceased before death.\nArticle 50 A personal information processor shall establish the mechanism for receiving and handling individuals\u0026rsquo; requests for exercising their rights. Where an individual\u0026rsquo;s request is rejected, the reasons therefor shall be given. Where an individual\u0026rsquo;s request to exercise his rights is rejected by a personal information processor, the individual may file a lawsuit with the people\u0026rsquo;s court in accordance with the law. Obligations of Personal Information Processors\nChapter V Obligations of Personal Information Processors Article 51 Personal information processors shall take the following measures to ensure that their personal information processing activities are in compliance with laws and administrative regulations based on the purpose and means of processing, the categories of personal information to be processed, the impact on personal rights and interests, and the potential security risks, among others, and shall prevent unauthorized access to, as well as breach, tampering or loss of any personal information: (1) formulating internal management system and operational procedures; (2) implementing classified management of personal information; (3) adopting corresponding security technical measures such as encryption and de-identification; (4) reasonably determining the operational authority of personal information processing, and regularly conducting safety education and training for practitioners; (5) formulating contingent plans for personal information security emergencies and organizing the implementation of such plans; and (6) other measures as provided by laws and administrative regulations. 1 2 3 \u0026gt;\nArticle 52 A personal information processor that processes personal information up to the amount prescribed by the national cyberspace department shall designate a person in charge of personal information protection, who shall supervise the personal information processing activities of the processor as well as the protective measures taken thereby, among others. The personal information processor shall disclose the contact information of the person in charge of personal information protection, and submit the said person\u0026rsquo;s name, contact information, and other information to the departments with personal information protection duties.\nArticle 53 Personal information processors outside the territory of the People\u0026rsquo;s Republic of China as specified in the second paragraph of Article 3 of this Law shall set up specialized agencies or designate representatives within the territory of the People\u0026rsquo;s Republic of China to be responsible for handling personal information protection related matters, and shall submit the names, contact information, and other information of the agencies and representatives to the departments with personal information protection duties.\nArticle 54 Personal information processors shall regularly conduct compliance audits of their personal information processing activities with laws and administrative regulations.\nArticle 55 In any of the following circumstances, a personal information processor shall assess in advance the impact on personal information protection and keep a record of the course of the processing: (1) processing sensitive personal information; (2) using personal information to conduct automated decision making; (3) entrusting personal information processing to another party, providing personal information for another party, or publicizing personal information; (4) providing personal information for any party outside the territory of the People\u0026rsquo;s Republic of China; or (5) conducting other personal information processing activities which may have significant impacts on individuals.\nArticle 56 The assessment of impact on personal information protection shall include the following contents: (1) whether the purposes and means of personal information processing, are legitimate, justified and necessary; (2) the impact on individuals\u0026rsquo; rights and interests, and security risks; and (3) whether the protection measures taken are legitimate, effective, and compatible with the degree of risks. The report of the impact assessment on personal information protection and the processing record shall be retained for at least three years.\nArticle 57 Where the breach, tampering, or loss of personal information occurs or may occur, a personal information processor shall immediately take remedial measures and notify the departments with personal information protection duties and the relevant individuals. The notice shall include the following items: (1) the categories of personal information that has been or may be breached, tampered with or lost, and the reasons and possible harm of the breach, tampering and loss; (2) the remedial measures adopted by the personal information processor and the measures the individuals may take to mitigate the harm; and (3) the contact information of the personal information processor. Where the measures taken by the personal information processor can effectively avoid the harm caused by breach, tampering, or loss of personal information, the personal information processor is not required to notify individuals; where the departments with personal information protection duties consider that harm may be caused, they have the authority to request the personal information processor to notify individuals.\nArticle 58 A personal information processor that provides important internet platform services involving a huge number of users and complicated business types shall perform the following obligations: (1) establishing and improving the personal information protection compliance system in accordance with the provisions of the state and establishing an independent organization mainly composed of external members to supervise the protection of personal information; (2) following the principles of openness, fairness, and justice, formulating platform rules, and clarifying the norms and obligations that product or service providers within the platform should meet when processing personal information; (3) stopping providing services for product or service providers within the platforms that process personal information in serious violation of laws and administrative regulations; and (4) regularly publishing social responsibility reports on personal information protection for public supervision.\nArticle 59 The party entrusted with the processing of personal information shall, in accordance with this Law and relevant laws and administrative regulations, take the necessary measures to ensure the security of the personal information entrusted for processing, and assist the entrusting personal information processor in fulfilling the obligations provided by this Law. Departments with Personal Information Protection Duties\nChapter VI Departments with Personal Information Protection Duties Article 60 The national cyberspace department shall be responsible for the overall planning and coordination of personal information protection and related supervision and administration. The relevant departments of the State Council shall, in accordance with this Law and other relevant laws and administrative regulations, be responsible for personal information protection and related supervision and administration within the scope of their respective duties. The duties of personal information protection and related supervision and administration of the relevant departments of the local people\u0026rsquo;s governments at or above the county level shall be determined in accordance with the relevant provisions of the state. The departments provided in the preceding two paragraphs are collectively referred to as the departments with personal information protection duties.\nArticle 61 Departments with personal information protection duties shall perform the following personal information protection duties: (1) conducting publicity and education on personal information protection, and guiding and supervising personal information processors in their protection of personal information; (2) receiving and handling complaints and reports related to personal information protection; (3) organizing evaluations on applications, etc. in terms of personal information protection and publish the results of such evaluations; (4) investigating and handling illegal personal information processing activities; and (5) other duties as provided by laws and administrative regulations.\nArticle 62 The national cyberspace department shall coordinate relevant departments to promote personal information protection through the following efforts in accordance with this Law: (1) formulating specific rules and standards for personal information protection; (2) developing special personal information protection rules and standards for small personal information processors, the processing of sensitive personal information, and new technologies and applications such as face recognition and artificial intelligence; (3) supporting the research and development, and promoting the application of secure and convenient electronic identity authentication technology, and advancing the public services for network identity authentication; (4) promoting the development of a personal information protection service system with the participation of various social sectors, and supporting relevant institutions in providing personal information protection assessment and certification services; and (5) improving the complaint and reporting mechanism related to personal information protection .\nArticle 63 A department with personal information protection duties when fulfilling related duties may take the following measures: (1) questioning relevant parties, and investigating circumstances related to personal information processing activities; (2) consulting and duplicating the parties\u0026rsquo; contracts, records, account books and other relevant materials related to personal information processing activities; (3) conducting on-site inspections, and investigating suspected illegal personal information processing activities; and (4) inspecting equipment and articles related to personal information processing activities; and sealing up or seizing equipment and articles related to illegal personal information processing activities as proved by evidence after submitting written reports to and obtaining approval from the principal person in charge of the departments with personal information protection duties. When departments with personal information protection duties carry out their duties in accordance with the law, the parties concerned shall cooperate and provide assistance, and shall not reject or obstruct them.\nArticle 64 Where a department with personal information protection duties finds, when performing its duties, relatively high risks in personal information processing activities or the occurrence of personal information security incidents, the department may hold an interview with the legal representative or the principal person in charge of the personal information processor according to the provided authority and procedures, or request the processor to entrust a professional institution to conduct compliance audits of the personal information processing activities. The personal information processor shall adopt measures to make rectification and eliminate potential risks as required. Where a department with personal information protection duties, in performing its duties, finds an illegal personal information processing activity that may involve a crime, the department shall transfer the case to the public security organ in a timely manner in accordance with the law.\nArticle 65 Any organization or individual has the right to complain and report to a department with personal information protection duties about illegal personal information processing. The department that receives such a complaint or report shall handle it in a timely manner in accordance with the law, and notify the complainant or informant of the results. Departments with personal information protection duties shall publish their contact information for receiving complaints and reports. Legal Liability\nChapter VII Legal Liability Article 66 Where personal information is processed in violation of the provisions of this Law or without fulfilling the personal information protection obligations provided in this Law, the departments with personal information protection duties shall order the violator to make corrections, give a warning, confiscate the illegal gains, and order the suspension or termination of provision of services by the applications that illegally process personal information; where the violator refuses to make corrections, a fine of not more than RMB one million yuan shall be imposed thereupon; and the directly liable persons in charge and other directly liable persons shall each be fined not less than RMB 10,000 yuan nor more than RMB 100,000 yuan. In case of an illegal act as prescribed in the preceding paragraph and the circumstances are serious, the departments with personal information protection duties at or above the provincial level shall order the violator to make corrections, confiscate the illegal gains, impose a fine of not more than RMB 50 million yuan or not more than five percent of the previous year\u0026rsquo;s turnover; may also order the suspension of relevant businesses, or order the suspension of all the business operations for an overhaul, and notify the competent authorities to revoke relevant business permits or license; shall impose a fine of not less than RMB 100,000 yuan but not more than RMB 1 million yuan upon each of the directly liable persons in charge and other directly liable persons, and may decide to prohibit the abovementioned persons from serving as directors, supervisors, senior managers, or the persons in charge of relevant companies within a specific period of time.\nArticle 67 Any violation of the provisions of this Law shall be entered in the relevant credit record and be published in accordance with the provisions of the relevant laws and administrative regulations.\nArticle 68 Where any state organ fails to fulfill the personal information protection obligations as provided in this Law, the organ at the higher level or the departments with personal information protection duties shall order it to make corrections, and discipline the directly liable person in charge and other directly liable persons in accordance with the law. Where a staff member of a department with personal information protection duties neglects duties, abuses power, or practices favoritism, which does not constitute a crime, the staff member shall be subject to sanction in accordance with the law.\nArticle 69 Where a personal information processor infringes the rights or interests on personal information due to any personal information processing activity and cannot prove that the processor is not at fault, the processor shall assume the liability for damages and other tort liability. The liability for damages prescribed in the preceding paragraph shall be determined based on the losses of individuals incurred thereby and the benefits acquired by the infringing personal information processor; and where it is difficult to determine the aforementioned losses or the benefits, the amount of damages shall be determined based on the actual circumstances.\nArticle 70 Where a personal information processor processes personal information in violation of the provisions of this Law and infringes the rights and interests of many individuals, the people\u0026rsquo;s procuratorate, the consumer organizations specified by law, and the organization designated by the national cyberspace department may file a lawsuit with the people\u0026rsquo;s court in accordance with the law.\nArticle 71 Any violation of this Law which constitutes a violation of public security administration shall be subject to public security administration penalty in accordance with the law. If the violation constitutes a crime, the violator shall be held criminally liable in accordance with the law. Supplementary Provisions\nChapter VIII Supplementary Provisions Article 72 This Law is not applicable where a natural person processes personal information for personal or household affairs. Where other laws provide personal information processing in statistical or archives management activities organized and conducted by the people\u0026rsquo;s governments at all levels and their relevant departments, the provisions of such laws shall prevail.\nArticle 73 For purposes of this Law, the following terms shall have the following meanings: (1) \u0026ldquo;A personal information processor\u0026rdquo; refers to an organization or individual that autonomously determines the purposes and means of personal information processing. (2) \u0026ldquo;automated decision making\u0026rdquo; refers to the activities of automatically analyzing and evaluating personal behaviors, hobbies, or economic, health, and credit status, among others, through computer programs, and making decisions. (3) \u0026ldquo;de-identification\u0026rdquo; refers to processing personal information to make it impossible to identify specific natural persons in the absence of the support of additional information. (4) \u0026ldquo;anonymization\u0026rdquo; refers to the process of processing personal information to make it impossible to identify specific natural persons and impossible to restore.\nArticle 74 This Law shall come into force as of November 1st , 2021.\n","permalink":"https://intlaws.com/en/compliance/china/pipl/","summary":"Official full text of the Personal Information Protection Law of the PRC: 8 chapters, 74 articles, adopted 2021-08-20, in force 2021-11-01. English text as published on the NPC official English site (marked \u0026ldquo;Translation for Reference Only\u0026rdquo;).","title":"Personal Information Protection Law of the PRC (Full Text)"},{"content":"United Nations Convention against Cybercrime; Strengthening International Cooperation for Combating Certain Crimes Committed by Means of Information and Communications Technology Systems and for the Sharing of Evidence in Electronic Form of Serious Crimes Version and sources (verifiable)\nItem Content Adopted 24 December 2024 by UNGA resolution 79/243; contained in the annex Structure Preamble + 9 chapters, 68 articles Entry into force Article 65: ninetieth day after deposit of the fortieth instrument of ratification, acceptance, approval or accession (verified from the official text) Status Not yet in force (as of 2026-09-22; see UN Treaty Collection https://treaties.un.org ) English source UNODC full text: https://www.unodc.org/unodc/en/cybercrime/convention/text/convention-full-text.html ; official document A/RES/79/243 (English): https://documents.un.org/api/symbol/access?s=A%2FRES%2F79%2F243\u0026l=en\u0026t=pdf Verification Retrieved 2026-09-22; 68 articles correspond one-for-one with the Chinese official text; the Article 47 heading (missing from the UN PDF text layer) was restored from the official UNODC HTML text and cross-checked against the Chinese official text Article 1 Statement of purpose\nThe purposes of this Convention are to: (a) Promote and strengthen measures to prevent and combat cybercrime more efficiently and effectively; (b) Promote, facilitate and strengthen international cooperation in preventing and combating cybercrime; and (c) Promote, facilitate and support technical assistance and capacity-building to prevent and combat cybercrime, in particular for the benefit of developing countries.\nArticle 2 Use of terms\nFor the purposes of this Convention: (a) “Information and communications technology system” shall mean any device or group of interconnected or related devices, one or more of which, pursuant to a program, gathers, stores and performs automatic processing of electronic data; (b) “Electronic data” shall mean any representation of facts, information or concepts in a form suitable for processing in an information and communications technology system, including a program suitable to cause an information and communications technology system to perform a function; (c) “Traffic data” shall mean any electronic data relating to a communication by means of an information and communications technology system, generated by an information and communications technology system that formed a part in the chain of communication, indicating the communication’s origin, destination, route, time, date, size, duration or type of underlying service; (d) “Content data” shall mean any electronic data, other than subscriber information or traffic data, relating to the substance of the data transferred by an information and communications technology system, including, but not limited to, images, text messages, voice messages, audio recordings and video recordings; (e) “Service provider” shall mean any public or private entity that: (f) “Subscriber information” shall mean any information that is held by a service provider, relating to subscribers of its services other than traffic or content data and by which can be established: (g) “Personal data” shall mean any information relating to an identified or identifiable natural person; (h) “Serious crime” shall mean conduct constituting an offence punishable by a maximum deprivation of liberty of at least four years or a more serious penalty; (i) “Property” shall mean assets of every kind, whether corporeal or incorporeal, movable or immovable, tangible or intangible, including virtual assets, and legal documents or instruments evidencing title to, or interest in, such assets; (j) “Proceeds of crime” shall mean any property derived from or obtained, directly or indirectly, through the commission of an offence; (k) “Freezing” or “seizure” shall mean temporarily prohibiting the transfer, conversion, disposition or movement of property or temporarily assuming custody or control of property on the basis of an order issued by a court or other competent authority; (l) “Confiscation”, which includes forfeiture where applicable, shall mean the permanent deprivation of property by order of a court or other competent authority; (m) “Predicate offence” shall mean any offence as a result of which proceeds have been generated that may become the subject of an offence as defined in article 17 of this Convention; (n) “Regional economic integration organization” shall mean an organization constituted by sovereign States of a given region to which its member States have transferred competence in respect of matters governed by this Convention and which has been duly authorized, in accordance with its internal procedures, to sign, ratify, accept, approve or accede to it; references to “States Parties” under this Convention shall apply to such organizations within the limits of their competence; (o) “Emergency” shall mean a situation in which there is a significant and imminent risk to the life or safety of any natural person.\nArticle 3 Scope of application\nThis Convention shall apply, except as otherwise stated herein, to: (a) The prevention, investigation and prosecution of the criminal offences established in accordance with this Convention, including the freezing, seizure, confiscation and return of the proceeds from such offences; (b) The collecting, obtaining, preserving and sharing of evidence in electronic form for the purpose of criminal investigations or proceedings, as provided for in articles 23 and 35 of this Convention.\nArticle 4 Offences established in accordance with other United Nations conventions and protocols\nIn giving effect to other applicable United Nations conventions and protocols to which they are Parties, States Parties shall ensure that criminal offences established in accordance with such conventions and protocols are also considered criminal offences under domestic law when committed through the use of information and communications technology systems. Nothing in this article shall be interpreted as establishing criminal offences in accordance with this Convention. Article 5 Protection of sovereignty\nStates Parties shall carry out their obligations under this Convention in a manner consistent with the principles of sovereign equality and territorial integrity of States and that of non-intervention in the domestic affairs of other States. Nothing in this Convention shall entitle a State Party to undertake in the territory of another State the exercise of jurisdiction and performance of functions that are reserved exclusively for the authorities of that other State by its domestic law. Article 6 Respect for human rights\nStates Parties shall ensure that the implementation of their obligations under this Convention is consistent with their obligations under international human rights law. Nothing in this Convention shall be interpreted as permitting suppression of human rights or fundamental freedoms, including the rights related to the freedoms of expression, conscience, opinion, religion or belief, peaceful assembly and association, in accordance and in a manner consistent with applicable international human rights law. Chapter II: Criminalization Article 7 Illegal access\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as a criminal offence under its domestic law, when committed intentionally, the access to the whole or any part of an information and communications technology system without right. A State Party may require that the offence be committed by infringing security measures, with the intent of obtaining electronic data or other dishonest or criminal intent or in relation to an information and communications technology system that is connected to another information and communications technology system. Article 8 Illegal interception\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the interception, made by technical means, of non‑public transmissions of electronic data to, from or within an information and communications technology system, including electromagnetic emissions from an information and communications technology system carrying such electronic data. A State Party may require that the offence be committed with dishonest or criminal intent, or in relation to an information and communications technology system that is connected to another information and communications technology system. Article 9 Interference with electronic data\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the damaging, deletion, deterioration, alteration or suppression of electronic data. A State Party may require that the conduct described in paragraph 1 of this article result in serious harm. Article 10 Interference with an information and communications technology system\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the serious hindering of the functioning of an information and communications technology system by inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing electronic data.\nArticle 11 Misuse of devices\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right: (a) The obtaining, production, sale, procurement for use, import, distribution or otherwise making available of: with the intent that the device, including a program, or the password, access credentials, electronic signature or similar data be used for the purpose of committing any of the offences established in accordance with articles 7 to 10 of this Convention; and (b) The possession of an item referred to in paragraph 1 (a) (i) or (ii) of this article, with intent that it be used for the purpose of committing any of the offences established in accordance with articles 7 to 10 of this Convention. This article shall not be interpreted as imposing criminal liability where the obtaining, production, sale, procurement for use, import, distribution or otherwise making available, or the possession referred to in paragraph 1 of this article is not for the purpose of committing an offence established in accordance with articles 7 to 10 of this Convention, such as for the authorized testing or protection of an information and communications technology system. Each State Party may reserve the right not to apply paragraph 1 of this article, provided that the reservation does not concern the sale, distribution or otherwise making available of the items referred to in paragraph 1 (a) (ii) of this article. Article 12 Information and communications technology system-related forgery\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the input, alteration, deletion or suppression of electronic data resulting in inauthentic data with the intent that they be considered or acted upon for legal purposes as if they were authentic, regardless of whether or not the data are directly readable and intelligible. A State Party may require an intent to defraud, or a similar dishonest or criminal intent, before criminal liability attaches. Article 13 Information and communications technology system-related theft or fraud\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as a criminal offence under its domestic law, when committed intentionally and without right, the causing of a loss of property to another person by means of: (a) Any input, alteration, deletion or suppression of electronic data; (b) Any interference with the functioning of an information and communications technology system; (c) Any deception as to factual circumstances made through an information and communications technology system that causes a person to do or omit to do anything which that person would not otherwise do or omit to do; with the fraudulent or dishonest intent of procuring for oneself or for another person, without right, a gain in money or other property.\nArticle 14 Offences related to online child sexual abuse or child sexual exploitation material\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the following conduct: (a) Producing, offering, selling, distributing, transmitting, broadcasting, displaying, publishing or otherwise making available child sexual abuse or child sexual exploitation material through an information and communications technology system; (b) Soliciting, procuring or accessing child sexual abuse or child sexual exploitation material through an information and communications technology system; (c) Possessing or controlling child sexual abuse or child sexual exploitation material stored in an information and communications technology system or another storage medium; (d) Financing the offences established in accordance with subparagraphs (a) to (c) of this paragraph, which States Parties may establish as a separate offence. For the purposes of this article, the term “child sexual abuse or child sexual exploitation material” shall include visual material, and may include written or audio content, that depicts, describes or represents any person under 18 years of age: (a) Engaging in real or simulated sexual activity; (b) In the presence of a person engaging in any sexual activity; (c) Whose sexual parts are displayed for primarily sexual purposes; or (d) Subjected to torture or cruel, inhumane or degrading treatment or punishment and such material is sexual in nature. A State Party may require that the material identified in paragraph 2 of this article be limited to material that: (a) Depicts, describes or represents an existing person; or (b) Visually depicts child sexual abuse or child sexual exploitation. In accordance with their domestic law and consistent with applicable international obligations, States Parties may take steps to exclude the criminalization of: (a) Conduct by children for self-generated material depicting them; or (b) The consensual production, transmission, or possession of material described in paragraph 2 (a) to (c) of this article, where the underlying conduct depicted is legal as determined by domestic law, and where such material is maintained exclusively for the private and consensual use of the persons involved. Nothing in this Convention shall affect any international obligations which are more conducive to the realization of the rights of the child. Article 15 Solicitation or grooming for the purpose of committing a sexual offence against a child\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law the act of intentionally communicating, soliciting, grooming, or making any arrangement through an information and communications technology system for the purpose of committing a sexual offence against a child, as defined in domestic law, including for the commission of any of the offences established in accordance with article 14 of this Convention. A State Party may require an act in furtherance of the conduct described in paragraph 1 of this article. A State Party may consider extending criminalization in accordance with paragraph 1 of this article in relation to a person believed to be a child. States Parties may take steps to exclude the criminalization of conduct as described in paragraph 1 of this article when committed by children. Article 16 Non-consensual dissemination of intimate images\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the selling, distributing, transmitting, publishing or otherwise making available of an intimate image of a person by means of an information and communications technology system, without the consent of the person depicted in the image. For the purpose of paragraph 1 of this article, “intimate image” shall mean a visual recording of a person over the age of 18 years made by any means, including a photograph or video recording, that is sexual in nature, in which the person’s sexual parts are exposed or the person is engaged in sexual activity, which was private at the time of the recording, and in respect of which the person or persons depicted maintained a reasonable expectation of privacy at the time of the offence. A State Party may extend the definition of intimate images, as appropriate, to depictions of persons who are under the age of 18 years if they are of legal age to engage in sexual activity under domestic law and the image does not depict child abuse or exploitation. For the purposes of this article, a person who is under the age of 18 years and depicted in an intimate image cannot consent to the dissemination of an intimate image that constitutes child sexual abuse or child sexual exploitation material under article 14 of this Convention. A State Party may require the intent to cause harm before criminal liability attaches. States Parties may take other measures concerning matters related to this article, in accordance with their domestic law and consistent with applicable international obligations. Article 17 Laundering of proceeds of crime\nEach State Party shall adopt, in accordance with fundamental principles of its domestic law, such legislative and other measures as may be necessary to establish as criminal offences, when committed intentionally: (a) (b) Subject to the basic concepts of its legal system: For purposes of implementing or applying paragraph 1 of this article: (a) Each State Party shall establish as predicate offences relevant offences established in accordance with articles 7 to 16 of this Convention; (b) In the case of States Parties whose legislation sets out a list of specific predicate offences, they shall, at a minimum, include in that list a comprehensive range of offences established in accordance with articles 7 to 16 of this Convention; (c) For the purposes of subparagraph (b) of this paragraph, predicate offences shall include offences committed both within and outside the jurisdiction of the State Party in question. However, offences committed outside the jurisdiction of a State Party shall constitute predicate offences only when the relevant conduct is a criminal offence under the domestic law of the State where it is committed and would be a criminal offence under the domestic law of the State Party implementing or applying this article, had it been committed there; (d) Each State Party shall furnish copies of its laws that give effect to this article and of any subsequent changes to such laws or a description thereof to the Secretary-General of the United Nations; (e) If required by fundamental principles of the domestic law of a State Party, it may be provided that the offences set forth in paragraph 1 of this article do not apply to the persons who committed the predicate offence; (f) Knowledge, intent or purpose required as an element of an offence set forth in paragraph 1 of this article may be inferred from objective factual circumstances. Article 18 Liability of legal persons\nEach State Party shall adopt such measures as may be necessary, consistent with its legal principles, to establish the liability of legal persons for participation in the offences established in accordance with this Convention. Subject to the legal principles of the State Party, the liability of legal persons may be criminal, civil or administrative. Such liability shall be without prejudice to the criminal liability of the natural persons who have committed the offences. Each State Party shall, in particular, ensure that legal persons held liable in accordance with this article are subject to effective, proportionate and dissuasive criminal or non-criminal sanctions, including monetary sanctions. Article 19 Participation and attempt\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as a criminal offence, in accordance with its domestic law, when committed intentionally, the participation in any capacity, such as that of an accomplice, assistant or instigator, in an offence established in accordance with this Convention. Each State Party may adopt the necessary legislative and other measures to establish as a criminal offence, in accordance with its domestic law, when committed intentionally, any attempt to commit an offence established in accordance with this Convention. Each State Party may adopt the necessary legislative and other measures to establish as a criminal offence, in accordance with its domestic law, when committed intentionally, the preparation for an offence established in accordance with this Convention. Article 20 Statute of limitations\nEach State Party shall, where appropriate, considering the gravity of the crime, establish under its domestic law a long statute of limitations period in which to commence proceedings for any offence established in accordance with this Convention and establish a longer statute of limitations period or provide for the suspension of the statute of limitations where the alleged offender has evaded the administration of justice.\nArticle 21 Prosecution, adjudication and sanctions\nEach State Party shall make the commission of an offence established in accordance with this Convention liable to effective, proportionate and dissuasive sanctions that take into account the gravity of the offence. Each State Party may adopt, in accordance with its domestic law, such legislative and other measures as may be necessary to establish aggravating circumstances in relation to the offences established in accordance with this Convention, including circumstances that affect critical information infrastructures. Each State Party shall endeavour to ensure that any discretionary legal powers under its domestic law relating to the prosecution of persons for offences established in accordance with this Convention are exercised in order to maximize the effectiveness of law enforcement measures in respect of those offences and with due regard to the need to deter the commission of such offences. Each State Party shall ensure that any person prosecuted for offences established in accordance with this Convention enjoys all rights and guarantees in conformity with domestic law and consistent with the applicable international obligations of the State Party, including the right to a fair trial and the rights of the defence. In the case of offences established in accordance with this Convention, each State Party shall take appropriate measures, in accordance with its domestic law and with due regard to the rights of the defence, to seek to ensure that conditions imposed in connection with decisions on release pending trial or appeal take into consideration the need to ensure the presence of the defendant at subsequent criminal proceedings. Each State Party shall take into account the gravity of the offences concerned when considering the eventuality of early release or parole of persons convicted of such offences. States Parties shall ensure that appropriate measures are in place under domestic law to protect children who are accused of offences established in accordance with this Convention, consistent with the obligations under the Convention on the Rights of the Child and the applicable Protocols thereto, as well as other applicable international or regional instruments. Nothing contained in this Convention shall affect the principle that the description of the offences established in accordance with this Convention and of the applicable legal defences or other legal principles controlling the lawfulness of conduct is reserved to the domestic law of a State Party and that such offences shall be prosecuted and punished in accordance with that law. Chapter III: Jurisdiction Article 22 Jurisdiction\nEach State Party shall adopt such measures as may be necessary to establish its jurisdiction over the offences established in accordance with this Convention when: (a) The offence is committed in the territory of that State Party; or (b) The offence is committed on board a vessel that is flying the flag of that State Party or an aircraft that is registered under the laws of that State Party at the time when the offence is committed. Subject to article 5of this Convention, a State Party may also establish its jurisdiction over any such offence when: (a) The offence is committed against a national of that State Party; or (b) The offence is committed by a national of that State Party or a stateless person with habitual residence in its territory; or (c) The offence is one of those established in accordance with article 17, paragraph 1 (b) (ii), of this Convention and is committed outside its territory with a view to the commission of an offence established in accordance with article 17, paragraph 1 (a) (i) or (ii) or (b) (i), of this Convention within its territory; or (d) The offence is committed against the State Party. For the purposes of article 37, paragraph 11,of this Convention, each State Party shall take such measures as may be necessary to establish its jurisdiction over the offences established in accordance with this Convention when the alleged offender is present in its territory and it does not extradite such person solely on the ground that the person is one of its nationals. Each State Party may also adopt such measures as may be necessary to establish its jurisdiction over the offences established in accordance with this Convention when the alleged offender is present in its territory and it does not extradite the person. If a State Party exercising its jurisdiction under paragraph 1 or 2 of this article has been notified, or has otherwise learned, that any other States Parties are conducting an investigation, prosecution or judicial proceeding in respect of the same conduct, the competent authorities of those States Parties shall, as appropriate, consult one another with a view to coordinating their actions. Without prejudice to norms of general international law, this Convention shall not exclude the exercise of any criminal jurisdiction established by a State Party in accordance with its domestic law. Chapter IV: Procedural measures and law enforcement Article 23 Scope of procedural measures\nEach State Party shall adopt such legislative and other measures as may be necessary to establish the powers and procedures provided for in this chapter for the purpose of specific criminal investigations or proceedings. Except as provided otherwise in this Convention, each State Party shall apply the powers and procedures referred to in paragraph 1 of this article to: (a) The criminal offences established in accordance with this Convention; (b) Other criminal offences committed by means of an information and communications technology system; and (c) The collection of evidence in electronic form of any criminal offence. (a) Each State Party may reserve the right to apply the measures referred to in article 29 of this Convention only to offences or categories of offences specified in the reservation, provided that the range of such offences or categories of offences is not more restricted than the range of offences to which it applies the measures referred to in article 30 of this Convention. Each State Party shall consider restricting such a reservation to enable the broadest application of the measures referred to in article 29; (b) Where a State Party, owing to limitations in its legislation in force at the time of the adoption of this Convention, is not able to apply the measures referred to in articles 29 and 30 of this Convention to communications being transmitted within an information and communications technology system of a service provider which: that State Party may reserve the right not to apply these measures to such communications. Each State Party shall consider restricting such a reservation to enable the broadest application of the measures referred to in articles 29 and 30 of this Convention. Article 24 Conditions and safeguards\nEach State Party shall ensure that the establishment, implementation and application of the powers and procedures provided for in this chapter are subject to conditions and safeguards provided for under its domestic law, which shall provide for the protection of human rights, in accordance with its obligations under international human rights law, and which shall incorporate the principle of proportionality. In accordance with and pursuant to the domestic law of each State Party, such conditions and safeguards shall, as appropriate in view of the nature of the procedure or power concerned, include, inter alia, judicial or other independent review, the right to an effective remedy, grounds justifying application, and limitation of the scope and the duration of such power or procedure. To the extent that it is consistent with the public interest, in particular the proper administration of justice, each State Party shall consider the impact of the powers and procedures in this chapter upon the rights, responsibilities and legitimate interests of third parties. The conditions and safeguards established in accordance with this article shall apply at the domestic level to the powers and procedures set forth in this chapter, both for the purpose of domestic criminal investigations and proceedings and for the purpose of rendering international cooperation by the requested State Party. References to judicial or other independent review in paragraph 2 of this article are references to such review at the domestic level. Article 25 Expedited preservation of stored electronic data\nEach State Party shall adopt such legislative and other measures as may be necessary to enable its competent authorities to order or similarly obtain the expeditious preservation of specified electronic data, including traffic data, content data and subscriber information, that have been stored by means of an information and communications technology system, in particular where there are grounds to believe that the electronic data are particularly vulnerable to loss or modification. Where a State Party gives effect to paragraph 1 of this article by means of an order to a person to preserve specified stored electronic data in the person’s possession or control, the State Party shall adopt such legislative and other measures as may be necessary to oblige that person to preserve and maintain the integrity of those electronic data for a period of time as long as necessary, up to a maximum of 90 days, to enable the competent authorities to seek their disclosure. A State Party may provide for such an order to be subsequently renewed. Each State Party shall adopt such legislative and other measures as may be necessary to oblige the custodian or other person who is to preserve the electronic data to keep confidential the undertaking of such procedures for the period of time provided for in its domestic legislation. Article 26 Expedited preservation and partial disclosure of traffic data\nEach State Party shall adopt, in respect of traffic data that are to be preserved under the provisions of article 25 of this Convention, such legislative and other measures as may be necessary to: (a) Ensure that such expeditious preservation of traffic data is available regardless of whether one or more service providers were involved in the transmission of a communication; and (b) Ensure the expeditious disclosure to the State Party’s competent authority, or a person designated by that authority, of a sufficient amount of traffic data to enable the State Party to identify the service providers and the path through which the communication or indicated information was transmitted.\nArticle 27 Production order\nEach State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to order: (a) A person in its territory to submit specified electronic data in that person’s possession or control that are stored in an information and communications technology system or an electronic data storage medium; and (b) A service provider offering its services in the territory of the State Party to submit subscriber information relating to such services in that service provider’s possession or control.\nArticle 28 Search and seizure of stored electronic data\nEach State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to search or similarly access: (a) An information and communications technology system, part of it, and electronic data stored therein; and (b) An electronic data storage medium in which the electronic data sought may be stored; in the territory of that State Party. Each State Party shall adopt such legislative and other measures as may be necessary to ensure that, where its authorities search or similarly access a specific information and communications technology system or part of it, pursuant to paragraph 1 (a) of this article, and have grounds to believe that the electronic data sought are stored in another information and communications technology system or part of it in its territory, and such data are lawfully accessible from or available to the initial system, such authorities shall be able to expeditiously conduct the search to obtain access to that other information and communications technology system. Each State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to seize or similarly secure electronic data in its territory accessed in accordance with paragraph 1 or 2 of this article. These measures shall include the power to: (a) Seize or similarly secure an information and communications technology system or part of it, or an electronic data storage medium; (b) Make and retain copies of those electronic data in electronic form; (c) Maintain the integrity of the relevant stored electronic data; (d) Render inaccessible or remove those electronic data in the accessed information and communications technology system. Each State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to order any person who has knowledge about the functioning of the information and communications technology system in question, the information and telecommunications network, or their component parts, or measures applied to protect the electronic data therein, to provide, as is reasonable, the necessary information to enable the undertaking of the measures referred to in paragraphs 1 to 3 of this article. Article 29 Real-time collection of traffic data\nEach State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to: (a) Collect or record, through the application of technical means in the territory of that State Party; and (b) Compel a service provider, within its existing technical capability: Where a State Party, owing to the principles of its domestic legal system, cannot adopt the measures referred to in paragraph 1 (a) of this article, it may instead adopt such legislative and other measures as may be necessary to ensure the real-time collection or recording of traffic data associated with specified communications transmitted in its territory, through the application of technical means in that territory. Each State Party shall adopt such legislative and other measures as may be necessary to oblige a service provider to keep confidential the fact of the execution of any power provided for in this article and any information relating to it. Article 30 Interception of content data\nEach State Party shall adopt such legislative and other measures as may be necessary, in relation to a range of serious criminal offences to be determined by domestic law, to empower its competent authorities to: (a) Collect or record, through the application of technical means in the territory of that State Party; and (b) Compel a service provider, within its existing technical capability: Where a State Party, owing to the principles of its domestic legal system, cannot adopt the measures referred to in paragraph 1 (a) of this article, it may instead adopt such legislative and other measures as may be necessary to ensure the real-time collection or recording of content data on specified communications in its territory, through the application of technical means in that territory. Each State Party shall adopt such legislative and other measures as may be necessary to oblige a service provider to keep confidential the fact of the execution of any power provided for in this article and any information relating to it. Article 31 Freezing, seizure and confiscation of the proceeds of crime\nEach State Party shall adopt, to the greatest extent possible within its domestic legal system, such measures as may be necessary to enable the confiscation of: (a) Proceeds of crime derived from offences established in accordance with this Convention or property the value of which corresponds to that of such proceeds; (b) Property, equipment or other instrumentalities used in or destined for use in offences established in accordance withthis Convention. Each State Party shall adopt such measures as may be necessary to enable the identification, tracing, freezing or seizure of any item referred to in paragraph 1 of this article for the purpose of eventual confiscation. Each State Party shall adopt, in accordance with its domestic law, such legislative and other measures as may be necessary to regulate the administration by the competent authorities of frozen, seized or confiscated property covered in paragraphs 1 and 2 of this article. If proceeds of crime have been transformed or converted, in part or in full, into other property, such property shall be liable to the measures referred to in this article instead of the proceeds. If proceeds of crime have been intermingled with property acquired from legitimate sources, such property shall, without prejudice to any powers relating to freezing or seizure, be liable to confiscation up to the assessed value of the intermingled proceeds. Income or other benefits derived from proceeds of crime, from property into which proceeds of crime have been transformed or converted or from property with which proceeds of crime have been intermingled, shall also be liable to the measures referred to in this article, in the same manner and to the same extent as proceeds of crime. For the purposes of this article and article 50 of this Convention, each State Party shall empower its courts or other competent authorities to order that bank, financial or commercial records be made available or be seized. A State Party shall not decline to act under the provisions of this paragraph on the ground of bank secrecy. Each State Party may consider the possibility of requiring that an offender demonstrate the lawful origin of alleged proceeds of crime or other property liable to confiscation, to the extent that such a requirement is consistent with the principles of their domestic law and with the nature of the judicial and other proceedings. The provisions of this article shall not be construed as prejudicing the rights of bona fide third parties. Nothing contained in this article shall affect the principle that the measures to which it refers shall be defined and implemented in accordance with the provisions of the domestic law of a State Party. Article 32 Establishment of criminal record\nEach State Party may adopt such legislative or other measures as may be necessary to take into consideration, under such terms as, and for the purpose that, it deems appropriate, any previous conviction in another State of an alleged offender for the purpose of using such information in criminal proceedings relating to an offence established in accordance with this Convention.\nArticle 33 Protection of witnesses\nEach State Party shall take appropriate measures, in accordance with its domestic law and within its means, to provide effective protection from potential retaliation or intimidation for witnesses who give testimony or, in good faith and on reasonable grounds, provide information concerning offences established in accordance with this Convention or otherwise cooperate with investigative or judicial authorities and, as appropriate, for their relatives and other persons close to them. The measures envisaged in paragraph 1 of this article may include, inter alia, without prejudice to the rights of the defendant, including the right to due process: (a) Establishing procedures for the physical protection of such persons, such as, to the extent necessary and feasible, relocating them and permitting, where appropriate, non-disclosure or limitations on the disclosure of information concerning the identity and whereabouts of such persons; (b) Providing evidentiary rules to permit witness testimony to be given in a manner that ensures the safety of the witness, such as permitting testimony to be given through the use of communications technology such as video links or other adequate means. States Parties shall consider entering into agreements or arrangements with other States for the relocation of persons referred to in paragraph 1 of this article. The provisions of this article shall also apply to victims insofar as they are witnesses. Article 34 Assistance to and protection of victims\nEach State Party shall take appropriate measures within its means to provide assistance and protection to victims of offences established in accordance with this Convention, in particular in cases of threat of retaliation or intimidation. Each State Party shall, subject to its domestic law, establish appropriate procedures to provide access to compensation and restitution for victims of offences established in accordance with this Convention. Each State Party shall, subject to its domestic law, enable views and concerns of victims to be presented and considered at appropriate stages of criminal proceedings against offenders in a manner not prejudicial to the rights of the defence. With respect to the offences established in accordance with articles 14 to 16 of this Convention, each State Party shall, subject to its domestic law, take measures to provide assistance to victims of such offences, including for their physical and psychological recovery, in cooperation with relevant international organizations, non‑governmental organizations, and other elements of civil society. In applying the provisions of paragraphs 2 to 4 of this article, each State Party shall take into account the age, gender and the particular circumstances and needs of victims, including the particular circumstances and needs of children. Each State Party shall, to the extent consistent with its domestic legal framework, take effective steps to ensure compliance with requests to remove or render inaccessible the content described in articles 14 and 16 of this Convention. Chapter V: International cooperation Article 35 General principles of international cooperation\nStates Parties shall cooperate with each other in accordance with the provisions of this Convention, as well as other applicable international instruments on international cooperation in criminal matters, and domestic laws, for the purpose of: (a) The investigation and prosecution of, and judicial proceedings in relation to, the criminal offences established in accordance with this Convention, including the freezing, seizure, confiscation and return of the proceeds from such offences; (b) The collecting, obtaining, preserving and sharing of evidence in electronic form of criminal offences established in accordance with this Convention; (c) The collecting, obtaining, preserving and sharing of evidence in electronic form of any serious crime, including serious crimes established in accordance with other applicable United Nations conventions and protocols in force at the time of the adoption of this Convention. For the purpose of the collecting, obtaining, preserving and sharing of evidence in electronic form of offences as provided for in paragraph 1 (b) and (c) of this article, the relevant paragraphs of article 40, and articles 41 to 46 of this Convention shall apply. In matters of international cooperation, whenever dual criminality is considered a requirement, it shall be deemed fulfilled irrespective of whether the laws of the requested State Party place the offence within the same category of offence or denominate the offence by the same terminology as the requesting State Party, if the conduct underlying the offence for which assistance is sought is a criminal offence under the laws of both States Parties. Article 36 Protection of personal data\n(a) A State Party transferring personal data pursuant to this Convention shall do so in accordance with its domestic law and any obligations the transferring Party may have under applicable international law. States Parties shall not be required to transfer personal data in accordance with this Convention if the data cannot be provided in compliance with their applicable laws concerning the protection of personal data; (b) Where the transfer of personal data would not be compliant with paragraph 1 (a) of this article, States Parties may seek to impose appropriate conditions, in accordance with such applicable laws, to achieve compliance in order to respond to a request for personal data; (c) States Parties are encouraged to establish bilateral or multilateral arrangements to facilitate the transfer of personal data. For personal data transferred in accordance with this Convention, States Parties shall ensure that the personal data received are subject to effective and appropriate safeguards in the respective legal frameworks of the States Parties. In order to transfer personal data obtained in accordance with this Convention to a third country or an international organization, a State Party shall notify the original transferring State Party of its intention and request its authorization. The State Party shall transfer such personal data only with the authorization of the original transferring State Party, which may require that the authorization be provided in written form. Article 37 Extradition\nThis article shall apply to the criminal offences established in accordance with this Convention where the person who is the subject of the request for extradition is present in the territory of the requested State Party, provided that the offence for which extradition is sought is punishable under the domestic law of both the requesting State Party and the requested State Party. When the extradition is sought for the purpose of serving a final sentence of imprisonment or another form of detention imposed in respect of an extraditable offence, the requested State Party may grant the extradition in accordance with domestic law. Notwithstanding paragraph 1 of this article, a State Party whose law so permits may grant the extradition of a person for any of the criminal offences established in accordance with this Convention that are not punishable under its own domestic law. If the request for extradition includes several separate criminal offences, at least one of which is extraditable under this article and some of which are not extraditable by reason of their period of imprisonment but are related to offences established in accordance with this Convention, the requested State Party may apply this article also in respect of those offences. Each of the offences to which this article applies shall be deemed to be included as an extraditable offence in any extradition treaty existing between States Parties. States Parties undertake to include such offences as extraditable offences in every extradition treaty to be concluded between them. If a State Party that makes extradition conditional on the existence of a treaty receives a request for extradition from another State Party with which it has no extradition treaty, it may consider this Convention the legal basis for extradition in respect of any offence to which this article applies. States Parties that make extradition conditional on the existence of a treaty shall: (a) At the time of deposit of their instruments of ratification, acceptance or approval of or accession to this Convention, inform the Secretary-General of the United Nations whether they will take this Convention as the legal basis for cooperation in extradition with other States Parties to this Convention; and (b) If they do not take this Convention as the legal basis for cooperation in extradition, seek, where appropriate, to conclude treaties on extradition with other States Parties to this Convention in order to implement this article. States Parties that do not make extradition conditional on the existence of a treaty shall recognize offences to which this article applies as extraditable offences between themselves. Extradition shall be subject to the conditions provided for by the domestic law of the requested State Party or by applicable extradition treaties, including, inter alia, conditions in relation to the minimum penalty requirement for extradition and the grounds upon which the requested State Party may refuse extradition. States Parties shall, subject to their domestic law, endeavour to expedite extradition procedures and to simplify evidentiary requirements relating thereto in respect of any offence to which this article applies. Subject to the provisions of its domestic law and its extradition treaties, the requested State Party may, upon being satisfied that the circumstances so warrant and are urgent, and at the request of the requesting State Party, including when the request is transmitted through existing channels of the International Criminal Police Organization, take a person whose extradition is sought and who is present in its territory into custody or take other appropriate measures to ensure the person’s presence at extradition proceedings. A State Party in whose territory an alleged offender is found, if it does not extradite such person in respect of an offence to which this article applies solely on the ground that the person is one of its nationals, shall, at the request of the State Party seeking extradition, be obliged to submit the case without undue delay to its competent authorities for the purpose of prosecution. Those authorities shall take their decisions and conduct their proceedings in the same manner as in the case of any other offence of a comparable nature under the domestic law of that State Party. The States Parties concerned shall cooperate with each other, in particular on procedural and evidentiary aspects, to ensure the efficiency of such prosecution. Whenever a State Party is permitted under its domestic law to extradite or otherwise surrender one of its nationals only upon the condition that the person will be returned to that State Party to serve the sentence imposed as a result of the trial or proceedings for which the extradition or surrender of the person was sought and that State Party and the State Party seeking the extradition of the person agree with this option and other terms that they may deem appropriate, such conditional extradition or surrender shall be sufficient to discharge the obligation set forth in paragraph 11 of this article. If extradition, sought for purposes of enforcing a sentence, is refused because the person sought is a national of the requested State Party, the requested State Party shall, if its domestic law so permits and in conformity with the requirements of such law, upon application of the requesting State Party, consider the enforcement of the sentence imposed under the domestic law of the requesting State Party or the remainder thereof. Any person regarding whom proceedings are being carried out in connection with any of the offences to which this article applies shall be guaranteed fair treatment at all stages of the proceedings, including enjoyment of all the rights and guarantees provided by the domestic law of the State Party in the territory of which that person is present. Nothing in this Convention shall be interpreted as imposing an obligation to extradite if the requested State Party has substantial grounds for believing that the request has been made for the purpose of prosecuting or punishing a person on account of that person’s sex, race, language, religion, nationality, ethnic origin or political opinions, or that compliance with the request would cause prejudice to that person’s position for any one of these reasons. States Parties may not refuse a request for extradition on the sole ground that the offence is also considered to involve fiscal matters. Before refusing extradition, the requested State Party shall, where appropriate, consult with the requesting State Party to provide it with ample opportunity to present its opinions and to provide information relevant to its allegation. The requested State Party shall inform the requesting State Party of its decision with regard to the extradition. The requested State Party shall inform the requesting State Party of any reason for refusal of extradition unless the requested State Party is prevented from doing so by its domestic law or its international legal obligations. Each State Party shall, at the time of signature or when depositing its instrument of ratification, acceptance, approval or accession, communicate to the Secretary-General of the United Nations the name and address of an authority responsible for making or receiving requests for extradition or provisional arrest. The Secretary-General shall set up and keep updated a register of authorities so designated by the States Parties. Each State Party shall ensure that the details held in the register are correct at all times. States Parties shall seek to conclude bilateral and multilateral agreements or arrangements to carry out or to enhance the effectiveness of extradition. Article 38 Transfer of sentenced persons\nStates Parties may, taking into consideration the rights of sentenced persons, consider entering into bilateral or multilateral agreements or arrangements on the transfer to their territory of persons sentenced to imprisonment or other forms of deprivation of liberty for offences established in accordance with this Convention, in order that they may complete their sentences there. States Parties may also take into account issues relating to consent, rehabilitation and reintegration.\nArticle 39 Transfer of criminal proceedings\nStates Parties shall consider the possibility of transferring to one another proceedings for the criminal prosecution of an offence established in accordance with this Convention where such a transfer is deemed to be in the interests of the proper administration of justice, particularly in cases where several jurisdictions are involved, with a view to concentrating the prosecution. If a State Party that makes the transfer of criminal proceedings conditional on the existence of a treaty receives a request for transfer from another State Party with which it has no treaty in this matter, it may consider this Convention as the legal basis for the transfer of criminal proceedings in respect of any offence to which this article applies. Article 40 General principles and procedures relating to mutual legal assistance\nStates Parties shall afford one another the widest measure of mutual legal assistance in investigations, prosecutions and judicial proceedings in relation to the offences established in accordance with this Convention, and for the purposes of the collection of evidence in electronic form of offences established in accordance with this Convention, as well as of serious crimes. Mutual legal assistance shall be afforded to the fullest extent possible under relevant laws, treaties, agreements and arrangements of the requested State Party with respect to investigations, prosecutions and judicial proceedings in relation to the offences for which a legal person may be held liable in accordance with article 18 of this Convention in the requesting State Party. Mutual legal assistance to be afforded in accordance with this article may be requested for any of the following purposes: (a) Taking evidence or statements from persons; (b) Effecting service of judicial documents; (c) Executing searches and seizures, and freezing; (d) Searching or similarly accessing, seizing or similarly securing, and disclosing electronic data stored by means of an information and communications technology system pursuant to article 44 of this Convention; (e) Collecting traffic data in real time pursuant to article 45 of this Convention; (f) Intercepting content data pursuant to article 46 of this Convention; (g) Examining objects and sites; (h) Providing information, evidence and expert evaluations; (i) Providing originals or certified copies of relevant documents and records, including government, bank, financial, corporate or business records; (j) Identifying or tracing proceeds of crime, property, instrumentalities or other things for evidentiary purposes; (k) Facilitating the voluntary appearance of persons in the requesting State Party (l) Recovering proceeds of crime; (m) Any other type of assistance that is not contrary to the domestic law of the requested State Party. Without prejudice to domestic law, the competent authorities of a State Party may, without prior request, transmit information relating to criminal matters to a competent authority in another State Party where they believe that such information could assist the authority in undertaking or successfully concluding inquiries and criminal proceedings or could result in a request formulated by the latter State Party pursuant to this Convention. The transmission of information pursuant to paragraph 4 of this article shall be without prejudice to inquiries and criminal proceedings in the State of the competent authorities providing the information. The competent authorities receiving the information shall comply with a request that said information remain confidential, even temporarily, or with restrictions on its use. However, this shall not prevent the receiving State Party from disclosing in its proceedings information that is exculpatory to an accused person. In such a case, the receiving State Party shall notify the transmitting State Party prior to the disclosure and, if so requested, consult with the transmitting State Party. If, in an exceptional case, advance notice is not possible, the receiving State Party shall inform the transmitting State Party of the disclosure without delay. The provisions of this article shall not affect obligations under any other treaty, bilateral or multilateral, that governs or will govern, in whole or in part, mutual legal assistance. Paragraphs 8 to 31 of this article shall apply to requests made pursuant to this article if the States Parties in question are not bound by a treaty on mutual legal assistance. If those States Parties are bound by such a treaty, the corresponding provisions of that treaty shall apply unless the States Parties agree to apply paragraphs 8 to 31 of this article in lieu thereof. States Parties are strongly encouraged to apply the provisions of those paragraphs if they facilitate cooperation. States Parties may decline to render assistance pursuant to this article on the ground of absence of dual criminality. However, the requested State Party may, when it deems appropriate, provide assistance, to the extent it decides at its discretion, irrespective of whether the conduct would constitute an offence under the domestic law of the requested State Party. Assistance may be refused when requests involve matters of a de minimis nature or matters for which the cooperation or assistance sought is available under other provisions of this Convention. A person who is being detained or is serving a sentence in the territory of one State Party and whose presence in another State Party is requested for purposes of identification, testimony or otherwise providing assistance in obtaining evidence for investigations, prosecutions or judicial proceedings in relation to offences established in accordance with this Convention may be transferred if the following conditions are met: (a) The person freely gives informed consent; (b) The competent authorities of both States Parties agree, subject to such conditions as those States Parties may deem appropriate. For the purposes of paragraph 9 of this article: (a) The State Party to which the person is transferred shall have the authority and obligation to keep the person transferred in custody, unless otherwise requested or authorized by the State Party from which the person was transferred; (b) The State Party to which the person is transferred shall, without delay, implement its obligation to return the person to the custody of the State Party from which the person was transferred as agreed beforehand, or as otherwise agreed, by the competent authorities of both States Parties; (c) The State Party to which the person is transferred shall not require the State Party from which the person was transferred to initiate extradition proceedings for the return of the person; (d) The person transferred shall receive credit for service of the sentence being served in the State from which the person was transferred for time spent in the custody of the State Party to which the person was transferred. Unless the State Party from which a person is to be transferred in accordance with paragraphs 9 and 10 of this article so agrees, that person, regardless of the person’s nationality, shall not be prosecuted, detained, punished or subjected to any other restriction of liberty in the territory of the State to which that person is transferred in respect of acts, omissions or convictions prior to the person’s departure from the territory of the State from which the person was transferred. (a) Each State Party shall designate a central authority or authorities that shall have the responsibility and power to receive requests for mutual legal assistance and either to execute them or to transmit them to the competent authorities for execution. Where a State Party has a special region or territory with a separate system of mutual legal assistance, it may designate a distinct central authority that shall have the same function for that region or territory; (b) Central authorities shall ensure the speedy and proper execution or transmission of the requests received. Where the central authority transmits the request to a competent authority for execution, it shall encourage the speedy and proper execution of the request by the competent authority; (c) The Secretary-General of the United Nations shall be notified of the central authority designated for this purpose at the time each State Party deposits its instrument of ratification, acceptance or approval of or accession to this Convention, and shall set up and keep updated a register of central authorities designated by the States Parties. Each State Party shall ensure that the details held in the register are correct at all times; (d) Requests for mutual legal assistance and any communication related thereto shall be transmitted to the central authorities designated by the States Parties. This requirement shall be without prejudice to the right of a State Party to require that such requests and communications be addressed to it through diplomatic channels and, in urgent circumstances, where the States Parties agree, through the International Criminal Police Organization, if possible. Requests shall be made in writing or, where possible, by any means capable of producing a written record, in a language acceptable to the requested State Party, under conditions allowing that State Party to establish authenticity. The Secretary-General of the United Nations shall be notified of the language or languages acceptable to each State Party at the time it deposits its instrument of ratification, acceptance or approval of or accession to this Convention. In urgent circumstances and where agreed by the States Parties, requests may be made orally, but shall be confirmed in writing forthwith. Where not prohibited by their respective laws, central authorities of States Parties are encouraged to transmit and receive requests for mutual legal assistance, and communications related thereto, as well as evidence, in electronic form under conditions allowing the requested State Party to establish authenticity and ensuring the security of communications. A request for mutual legal assistance shall contain: (a) The identity of the authority making the request; (b) The subject matter and nature of the investigation, prosecution or judicial proceeding to which the request relates and the name and functions of the authority conducting the investigation, prosecution or judicial proceeding; (c) A summary of the relevant facts, except in relation to requests for the purpose of service of judicial documents; (d) A description of the assistance sought and details of any particular procedure that the requesting State Party wishes to be followed; (e) Where possible and appropriate, the identity, location and nationality of any person concerned, as well as the country of origin, description and location of any item or accounts concerned; (f) Where applicable, the time period for which the evidence, information or other assistance is sought; and (g) The purpose for which the evidence, information or other assistance is sought. The requested State Party may request additional information when it appears necessary for the execution of the request in accordance with its domestic law or when it can facilitate such execution. A request shall be executed in accordance with the domestic law of the requested State Party and, to the extent not contrary to the domestic law of the requested State Party and where possible, in accordance with the procedures specified in the request. Wherever possible and consistent with fundamental principles of domestic law, when an individual is in the territory of a State Party and has to be heard as a witness, victim or expert by the judicial authorities of another State Party, the first State Party may, at the request of the other, permit the hearing to take place by videoconference if it is not possible or desirable for the individual in question to appear in person in the territory of the requesting State Party. States Parties may agree that the hearing shall be conducted by a judicial authority of the requesting State Party and attended by a judicial authority of the requested State Party. If the requested State Party does not have access to the technical means necessary for holding a videoconference, such means may be provided by the requesting State Party, upon mutual agreement. The requesting State Party shall not transmit or use information or evidence furnished by the requested State Party for investigations, prosecutions or judicial proceedings other than those stated in the request without the prior consent of the requested State Party. Nothing in this paragraph shall prevent the requesting State Party from disclosing in its proceedings information or evidence that is exculpatory to an accused person. In the latter case, the requesting State Party shall notify the requested State Party prior to the disclosure and, if so requested, consult with the requested State Party. If, in an exceptional case, advance notice is not possible, the requesting State Party shall inform the requested State Party of the disclosure without delay. The requesting State Party may require that the requested State Party keep confidential the fact and substance of the request, except to the extent necessary to execute the request. If the requested State Party cannot comply with the requirement of confidentiality, it shall promptly inform the requesting State Party. Mutual legal assistance may be refused: (a) If the request is not made in conformity with the provisions of this article; (b) If the requested State Party considers that execution of the request is likely to prejudice its sovereignty, security, ordre public or other essential interests; (c) If the authorities of the requested State Party would be prohibited by its domestic law from carrying out the action requested with regard to any similar offence, had it been subject to investigation, prosecution or judicial proceedings under their own jurisdiction; (d) If it would be contrary to the legal system of the requested State Party relating to mutual legal assistance for the request to be granted. Nothing in this Convention shall be interpreted as imposing an obligation to afford mutual legal assistance if the requested State Party has substantial grounds for believing that the request has been made for the purpose of prosecuting or punishing a person on account of that person’s sex, race, language, religion, nationality, ethnic origin or political opinions, or that compliance with the request would cause prejudice to that person’s position for any one of these reasons. States Parties may not refuse a request for mutual legal assistance on the sole ground that the offence is also considered to involve fiscal matters. States Parties shall not decline to render mutual legal assistance pursuant to this article on the ground of bank secrecy. Reasons shall be given for any refusal of mutual legal assistance. The requested State Party shall execute the request for mutual legal assistance as soon as possible and shall take as full account as possible of any deadlines suggested by the requesting State Party and for which reasons are given, preferably in the request. The requested State Party shall respond to reasonable requests by the requesting State Party on the status, and progress in its handling, of the request. The requesting State Party shall promptly inform the requested State Party when the assistance sought is no longer required. Mutual legal assistance may be postponed by the requested State Party on the ground that it interferes with an ongoing investigation, prosecution or judicial proceeding. Before refusing a request pursuant to paragraph 21 of this article or postponing its execution pursuant to paragraph 27 of this article, the requested State Party shall consult with the requesting State Party to consider whether assistance may be granted subject to such terms and conditions as it deems necessary. If the requesting State Party accepts assistance subject to those conditions, it shall comply with the conditions. Without prejudice to the application of paragraph 11 of this article, a witness, expert or other person who, at the request of the requesting State Party, consents to give evidence in a proceeding or to assist in an investigation, prosecution or judicial proceeding in the territory of the requesting State Party shall not be prosecuted, detained, punished or subjected to any other restriction of the person’s liberty in that territory in respect of acts, omissions or convictions prior to the person’s departure from the territory of the requested State Party. Such safe conduct shall cease when the witness, expert or other person having had, for a period of 15 consecutive days or for any period agreed upon by the States Parties from the date on which the person has been officially informed that the presence of the person is no longer required by the judicial authorities, an opportunity of leaving, has nevertheless remained voluntarily in the territory of the requesting State Party or, having left it, has returned of the person’s own free will. The ordinary costs of executing a request shall be borne by the requested State Party, unless otherwise agreed by the States Parties concerned. If expenses of a substantial or extraordinary nature are or will be required to fulfil the request, the States Parties shall consult to determine the terms and conditions under which the request will be executed, as well as the manner in which the costs shall be borne. The requested State Party: (a) Shall provide to the requesting State Party copies of government records, documents or information in its possession that under its domestic law are available to the general public; (b) May, at its discretion, provide to the requesting State Party, in whole, in part or subject to such conditions as it deems appropriate, copies of any government records, documents or information in its possession that under its domestic law are not available to the general public. States Parties shall consider, as may be necessary, the possibility of concluding bilateral or multilateral agreements or arrangements that would serve the purposes of, give practical effect to or enhance the provisions of this article. Article 41 24/7 network\nEach State Party shall designate a point of contact available 24 hours a day, 7 days a week, in order to ensure the provision of immediate assistance for the purpose of specific criminal investigations, prosecutions or judicial proceedings concerning offences established in accordance with this Convention, or for the collection, obtaining and preservation of evidence in electronic form for the purposes of paragraph 3 of this article and in relation to the offences established in accordance with this Convention, as well as to serious crime. The Secretary-General of the United Nations shall be notified of such point of contact and keep an updated register of points of contact designated for the purposes of this article and shall annually circulate to the States Parties the updated list of contact points. Such assistance shall include facilitating or, if permitted by the domestic law and practice of the requested State Party, directly carrying out the following measures: (a) The provision of technical advice; (b) The preservation of stored electronic data pursuant to articles 42 and 43 of this Convention, including, as appropriate, information about the location of the service provider, if known to the requested State Party, to assist the requesting State Party in making a request; (c) The collection of evidence and the provision of legal information; (d) The locating of suspects; or (e) The provision of electronic data to avert an emergency. A State Party’s point of contact shall have the capacity to carry out communications with the point of contact of another State Party on an expedited basis. If the point of contact designated by a State Party is not part of that State Party’s authority or authorities responsible for mutual legal assistance or extradition, the point of contact shall ensure that it is able to coordinate with that authority or those authorities on an expedited basis. Each State Party shall ensure that trained and equipped personnel are available to ensure the operation of the 24/7 network. States Parties may also use and strengthen existing authorized networks of points of contact, where applicable, and within the limits of their domestic laws, including the 24/7 networks for computer-related crime of the International Criminal Police Organization for prompt police-to-police cooperation and other methods of information exchange cooperation. Article 42 International cooperation for the purpose of expedited preservation of stored electronic data\nA State Party may request another State Party to order or otherwise obtain, in accordance with article 25 of this Convention, the expeditious preservation of electronic data stored by means of an information and communications technology system located within the territory of that other State Party, and in respect of which the requesting State Party intends to submit a request for mutual legal assistance in the search or similar access, seizure or similar securing, or disclosure of the electronic data. The requesting State Party may use the 24/7 network provided for in article 41 of this Convention to seek information concerning the location of the electronic data stored by means of an information and communications technology system and, as appropriate, information about the location of the service provider. A request for preservation made under paragraph 1 of this article shall specify: (a) The authority seeking the preservation; (b) The offence that is the subject of a criminal investigation, prosecution or judicial proceeding and a brief summary of the related facts; (c) The stored electronic data to be preserved and their relationship to the offence; (d) Any available information identifying the custodian of the stored electronic data or the location of the information and communications technology system; (e) The necessity of the preservation; (f) That the requesting State Party intends to submit a request for mutual legal assistance in the search or similar access, seizure or similar securing, or disclosure of the stored electronic data; (g) As appropriate, the need to keep the request for preservation confidential and not to notify the user. Upon receiving the request from another State Party, the requested State Party shall take all appropriate measures to preserve expeditiously the specified electronic data in accordance with its domestic law. For the purposes of responding to a request, dual criminality shall not be required as a condition for providing such preservation. A State Party that requires dual criminality as a condition for responding to a request for mutual legal assistance in the search or similar access, seizure or similar securing, or disclosure of stored electronic data may, in respect of offences other than those established in accordance with this Convention, reserve the right to refuse the request for preservation under this article in cases where it has reasons to believe that, at the time of disclosure, the condition of dual criminality could not be fulfilled. In addition, a request for preservation may be refused only on the basis of the grounds contained in article 40, paragraph 21 (b) and (c) and paragraph 22, of this Convention. Where the requested State Party believes that preservation will not ensure the future availability of the data or will threaten the confidentiality of or otherwise prejudice the requesting State Party’s investigation, it shall promptly so inform the requesting State Party, which shall then determine whether the request should nevertheless be executed. Any preservation effected in response to a request made pursuant to paragraph 1 of this article shall be for a period of not less than 60 days, in order to enable the requesting State Party to submit a request for the search or similar access, seizure or similar securing, or disclosure of the data. Following the receipt of such a request, the data shall continue to be preserved pending a decision on that request. Before the expiry of the preservation period in paragraph 8 of this article, the requesting State Party may request an extension of the period of preservation. Article 43 International cooperation for the purpose of expedited disclosure of preserved traffic data\nWhere, in the course of the execution of a request made pursuant to article 42 of this Convention to preserve traffic data concerning a specific communication, the requested State Party discovers that a service provider in another State Party was involved in the transmission of the communication, the requested State Party shall expeditiously disclose to the requesting State Party a sufficient amount of traffic data to identify that service provider and the path through which the communication was transmitted. Disclosure of traffic data under paragraph 1 of this article may be refused only on the basis of the grounds contained in article 40, paragraph 21 (b) and (c) and paragraph 22, of this Convention. Article 44 Mutual legal assistance in accessing stored electronic data\nA State Party may request another State Party to search or similarly access, seize or similarly secure, and disclose electronic data stored by means of an information and communications technology system located within the territory of the requested State Party, including electronic data that have been preserved pursuant to article 42 of this Convention. The requested State Party shall respond to the request through the application of relevant international instruments and laws referred to in article 35 of this Convention, and in accordance with other relevant provisions of this chapter. The request shall be responded to on an expedited basis where: (a) There are grounds to believe that the relevant data are particularly vulnerable to loss or modification; or (b) The instruments and laws referred to in paragraph 2 of this article otherwise provide for expedited cooperation. Article 45 Mutual legal assistance in the real-time collection of traffic data\nStates Parties shall endeavour to provide mutual legal assistance to each other in the real-time collection of traffic data associated with specified communications in their territory transmitted by means of an information and communications technology system. Subject to the provisions of paragraph 2 of this article, such assistance shall be governed by the conditions and procedures provided for under domestic law. Each State Party shall endeavour to provide such assistance at least with respect to criminal offences for which the real-time collection of traffic data would be available in a similar domestic case. A request made in accordance with paragraph 1 of this article shall specify: (a) The name of the requesting authority; (b) A summary of the main facts and the nature of the investigation, prosecution or judicial proceeding to which the request relates; (c) The electronic data in relation to which the collection of the traffic data is required and their relationship to the offence; (d) Any available data that identify the owner or user of the data or the location of the information and communications technology system; (e) Justification for the need to collect the traffic data; (f) The period for which traffic data are to be collected and a corresponding justification of its duration. Article 46 Mutual legal assistance in the interception of content data\nStates Parties shall endeavour to provide mutual legal assistance to each other in the real-time collection or recording of content data of specified communications transmitted by means of an information and communications technology system, to the extent permitted under treaties applicable to them or under their domestic laws.\nArticle 47 Law enforcement cooperation\nStates Parties shall cooperate closely with one another, consistent with their respective domestic legal and administrative systems, to enhance the effectiveness of law enforcement action to combat the offences established in accordance with this Convention. States Parties shall, in particular, take effective measures: (a) To enhance and, where necessary, to establish channels of communication between their competent authorities, agencies and services, taking into account existing channels, including those of the International Criminal Police Organization, in order to facilitate the secure and rapid exchange of information concerning all aspects of the offences established in accordance with this Convention, including, if the States Parties concerned deem it appropriate, links with other criminal activities; (b) To cooperate with other States Parties in conducting inquiries with respect to offences established in accordance with this Convention concerning: (c) To provide, where appropriate, necessary items or data for analytical or investigative purposes; (d) To exchange, where appropriate, information with other States Parties concerning specific means and methods used to commit the offences established in accordance with this Convention, including the use of false identities, forged, altered or false documents and other means of concealing activities, as well as cybercrime tactics, techniques and procedures; (e) To facilitate effective coordination between their competent authorities, agencies and services and to promote the exchange of personnel and other experts, including, subject to bilateral agreements or arrangements between the States Parties concerned, the posting of liaison officers; (f) To exchange information and coordinate administrative and other measures taken, as appropriate, for the purpose of early identification of the offences established in accordance with this Convention. With a view to giving effect to this Convention, States Parties shall consider entering into bilateral or multilateral agreements or arrangements on direct cooperation between their law enforcement agencies and, where such agreements or arrangements already exist, amending them. In the absence of such agreements or arrangements between the States Parties concerned, the States Parties may consider this Convention to be the basis for mutual law enforcement cooperation in respect of the offences established in accordance with this Convention. Whenever appropriate, States Parties shall make full use of agreements or arrangements, including international or regional organizations, to enhance the cooperation between their law enforcement agencies. Article 48 Joint investigations\nStates Parties shall consider concluding bilateral or multilateral agreements or arrangements whereby, in relation to offences established in accordance with this Convention that are the subject of criminal investigations, prosecutions or judicial proceedings in one or more States, the competent authorities concerned may establish joint investigative bodies. In the absence of such agreements or arrangements, joint investigations may be undertaken by agreement on a case-by-case basis. The States Parties involved shall ensure that the sovereignty of the State Party in whose territory such investigations are to take place is fully respected.\nArticle 49 Mechanisms for the recovery of property through international cooperation in confiscation\nEach State Party, in order to provide mutual legal assistance pursuant to article 50 of this Convention with respect to property acquired through or involved in the commission of an offence established in accordance with this Convention, shall, in accordance with its domestic law: (a) Take such measures as may be necessary to permit its competent authorities to give effect to an order of confiscation issued by a court of another State Party; (b) Take such measures as may be necessary to permit its competent authorities, where they have jurisdiction, to order the confiscation of such property of foreign origin by adjudication of an offence of money-laundering or such other offence as may be within its jurisdiction or by other procedures authorized under its domestic law; and (c) Consider taking such measures as may be necessary to allow confiscation of such property without a criminal conviction in cases in which the offender cannot be prosecuted by reason of death, flight or absence or in other appropriate cases. Each State Party, in order to provide mutual legal assistance upon a request made pursuant to article 50, paragraph 2, of this Convention, shall, in accordance with its domestic law: (a) Take such measures as may be necessary to permit its competent authorities to freeze or seize property upon a freezing or seizure order issued by a court or competent authority of a requesting State Party that provides a reasonable basis for the requested State Party to believe that there are sufficient grounds for taking such actions and that the property would eventually be subject to an order of confiscation for the purposes of paragraph 1 (a) of this article; (b) Take such measures as may be necessary to permit its competent authorities to freeze or seize property upon a request that provides a reasonable basis for the requested State Party to believe that there are sufficient grounds for taking such actions and that the property would eventually be subject to an order of confiscation for the purposes of paragraph 1 (a) of this article; and (c) Consider taking additional measures to permit its competent authorities to preserve property for confiscation, such as on the basis of a foreign arrest or criminal charge related to the acquisition of such property. Article 50 International cooperation for the purposes of confiscation\nA State Party that has received a request from another State Party having jurisdiction over an offence established in accordance with this Convention for the confiscation of proceeds of crime, property, equipment or other instrumentalities referred to in article 31, paragraph 1, of this Convention situated in its territory shall, to the greatest extent possible within its domestic legal system: (a) Submit the request to its competent authorities for the purpose of obtaining an order of confiscation and, if such an order is granted, give effect to it; or (b) Submit to its competent authorities, with a view to giving effect to it to the extent requested, an order of confiscation issued by a court in the territory of the requesting State Party in accordance with article 31, paragraph 1, of this Convention insofar as it relates to proceeds of crime, property, equipment or other instrumentalities situated in the territory of the requested State Party. Following a request made by another State Party having jurisdiction over an offence established in accordance with this Convention, the requested State Party shall take measures to identify, trace and freeze or seize proceeds of crime, property, equipment or other instrumentalities referred to in article 31, paragraph 1, of this Convention for the purpose of eventual confiscation to be ordered either by the requesting State Party or, pursuant to a request under paragraph 1 of this article, by the requested State Party. The provisions of article 40 of this Convention are applicable, mutatis mutandis, to this article. In addition to the information specified in article 40, paragraph 15, of this Convention, requests made pursuant to this article shall contain: (a) In the case of a request pertaining to paragraph 1 (a) of this article, a description of the property to be confiscated, including, to the extent possible, the location, and where relevant, the estimated value of the property and a statement of the facts relied upon by the requesting State Party sufficient to enable the requested State Party to seek the order under its domestic law; (b) In the case of a request pertaining to paragraph 1 (b) of this article, a legally admissible copy of an order of confiscation upon which the request is based issued by the requesting State Party, a statement of the facts and information as to the extent to which execution of the order is requested, a statement specifying the measures taken by the requesting State Party to provide adequate notification to bona fide third parties and to ensure due process, and a statement that the confiscation order is final; (c) In the case of a request pertaining to paragraph 2 of this article, a statement of the facts relied upon by the requesting State Party and a description of the actions requested and, where available, a legally admissible copy of an order on which the request is based. The decisions or actions provided for in paragraphs 1 and 2 of this article shall be taken by the requested State Party in accordance with and subject to the provisions of its domestic law and its procedural rules or any bilateral or multilateral treaty, agreement or arrangement to which it may be bound in relation to the requesting State Party. Each State Party shall furnish copies of its laws and regulations that give effect to this article and of any subsequent changes to such laws and regulations or a description thereof to the Secretary-General of the United Nations. If a State Party elects to make the taking of the measures referred to in paragraphs 1 and 2 of this article conditional on the existence of a relevant treaty, that State Party shall consider this Convention the necessary and sufficient treaty basis. Cooperation under this article may also be refused or provisional measures may be lifted if the requested State Party does not receive sufficient and timely evidence or if the property is of a de minimis value. Before lifting any provisional measure taken pursuant to this article, the requested State Party shall, wherever possible, give the requesting State Party an opportunity to present its reasons in favour of continuing the measure. The provisions of this article shall not be construed as prejudicing the rights of bona fide third parties. States Parties shall consider concluding bilateral or multilateral treaties, agreements or arrangements to enhance the effectiveness of international cooperation undertaken pursuant to this article. Article 51 Special cooperation\nWithout prejudice to its domestic law, each State Party shall endeavour to take measures to permit it to forward, without prejudice to its own criminal investigations, prosecutions or judicial proceedings, information on proceeds of offences established in accordance with this Convention to another State Party without prior request, when it considers that the disclosure of such information might assist the receiving State Party in initiating or carrying out criminal investigations, prosecutions or judicial proceedings or might lead to a request by that State Party under article 50 of this Convention.\nArticle 52 Return and disposal of confiscated proceeds of crime or property\nProceeds of crime or property confiscated by a State Party pursuant to article 31 or 50 of this Convention shall be disposed of by that State Party in accordance with its domestic law and administrative procedures. When acting on a request made by another State Party in accordance with article 50 of this Convention, States Parties shall, to the extent permitted by domestic law and if so requested, give priority consideration to returning the confiscated proceeds of crime or property to the requesting State Party so that it can give compensation to the victims of the crime or return such proceeds of crime or property to their prior legitimate owners. When acting on a request made by another State Party in accordance with articles 31 and 50 of this Convention, a State Party may, after due consideration has been given to compensation of victims, give special consideration to concluding agreements or arrangements on: (a) Contributing the value of such proceeds of crime or property or funds derived from the sale of such proceeds of crime or property or a part thereof to the account designated in accordance with article 56, paragraph 2 (c), of this Convention, and to intergovernmental bodies specializing in the fight against cybercrime; (b) Sharing with other States Parties, on a regular or case-by-case basis, such proceeds of crime or property, or funds derived from the sale of such proceeds of crime or property, in accordance with its domestic law or administrative procedures. Where appropriate, unless States Parties decide otherwise, the requested State Party may deduct reasonable expenses incurred in investigations, prosecutions or judicial proceedings leading to the return or disposition of confiscated property pursuant to this article. Chapter VI: Preventive measures Article 53 Preventive measures\nEach State Party shall endeavour, in accordance with fundamental principles of its legal system, to develop and implement or maintain effective and coordinated policies and best practices to reduce existing or future opportunities for cybercrime through appropriate legislative, administrative or other measures. Each State Party shall take appropriate measures, within its means and in accordance with fundamental principles of its domestic law, to promote the active participation of relevant individuals and entities outside the public sector, such as non-governmental organizations, civil society organizations, academic institutions and private sector entities, as well as the general public, in the relevant aspects of prevention of the offences established in accordance with this Convention. Preventive measures may include: (a) Strengthening cooperation between law enforcement agencies or prosecutors and relevant individuals and entities outside the public sector, such as non-governmental organizations, civil society organizations, academic institutions and private sector entities for the purpose of addressing relevant aspects of preventing and combating the offences established in accordance with this Convention; (b) Promoting public awareness regarding the existence, causes and gravity of the threat posed by the offences established in accordance with this Convention through public information activities, public education, media and information literacy programmes and curricula that promote public participation in preventing and combating such offences; (c) Building and making efforts to increase the capacity of domestic criminal justice systems, including training and developing expertise among criminal justice practitioners, as part of national prevention strategies against the offences established in accordance with this Convention; (d) Encouraging service providers to take effective measures, where feasible in the light of national circumstances and to the extent permitted by domestic law, to strengthen the security of the service providers’ products, services and customers; (e) Recognizing the contributions of the legitimate activities of security researchers when intended solely, and to the extent permitted and subject to the conditions prescribed by domestic law, to strengthen and improve the security of service providers’ products, services and customers located within the territory of the State Party; (f) Developing, facilitating and promoting programmes and activities in order to discourage those at risk of engaging in cybercrime from becoming offenders and to develop their skills in a lawful manner; (g) Endeavouring to promote the reintegration into society of persons convicted of offences established in accordance with this Convention; (h) Developing strategies and policies, in accordance with domestic law, to prevent and eradicate gender-based violence that occurs through the use of an information and communications technology system, as well as taking into consideration the special circumstances and needs of persons in vulnerable situations in developing preventive measures; (i) Undertaking specific and tailored efforts to keep children safe online, including through education and training on and raising public awareness of child sexual abuse or child sexual exploitation online and through revising domestic legal frameworks and enhancing international cooperation aimed at its prevention, as well as making efforts to ensure the swift removal of child sexual abuse and child sexual exploitation material; (j) Enhancing the transparency of and promoting the contribution of the public to decision-making processes and ensuring that the public has adequate access to information; (k) Respecting, promoting and protecting the freedom to seek, receive and impart public information concerning cybercrime; (l) Developing or strengthening support programmes for victims of the offences established in accordance with this Convention; (m) Preventing and detecting transfers of proceeds of crime and property related to the offences established in accordance with this Convention. Each State Party shall take appropriate measures to ensure that the relevant competent authority or authorities responsible for preventing and combating cybercrime are known and accessible to the public, where appropriate, for the reporting, including anonymously, of any incident that may be considered a criminal offence established in accordance with this Convention. States Parties shall endeavour to periodically evaluate existing relevant national legal frameworks and administrative practices with a view to identifying gaps and vulnerabilities and ensuring their relevance in the face of changing threats posed by the offences established in accordance with this Convention. States Parties may collaborate with each other and with relevant international and regional organizations in promoting and developing the measures referred to in this article. This includes participation in international projects aimed at the prevention of cybercrime. Each State Party shall inform the Secretary-General of the United Nations of the name and address of the authority or authorities that may assist other States Parties in developing and implementing specific measures to prevent cybercrime. Chapter VII: Technical assistance and information exchange Article 54 Technical assistance and capacity-building\nStates Parties shall, according to their capacity, consider affording one another the widest measure of technical assistance and capacity-building, including training and other forms of assistance, the mutual exchange of relevant experience and specialized knowledge and the transfer of technology on mutually agreed terms, taking into particular consideration the interests and needs of developing States Parties, with a view to facilitating the prevention, detection, investigation and prosecution of the offences covered by this Convention. States Parties shall, to the extent necessary, initiate, develop, implement or improve specific training programmes for their personnel responsible for the prevention, detection, investigation and prosecution of the offences covered by this Convention. Activities referred to in paragraphs 1 and 2 of this article may deal, to the extent permitted by domestic law, with the following: (a) Methods and techniques used in the prevention, detection, investigation and prosecution of the offences covered by this Convention; (b) Building capacity in the development and planning of strategic policies and legislation to prevent and combat cybercrime; (c) Building capacity in the collection, preservation and sharing of evidence, in particular in electronic form, including the maintenance of the chain of custody and forensic analysis; (d) Modern law enforcement equipment and the use thereof; (e) Training of competent authorities in the preparation of requests for mutual legal assistance and other means of cooperation that meet the requirements of this Convention, especially for the collection, preservation and sharing of evidence in electronic form; (f) Prevention, detection and monitoring of the movements of proceeds deriving from the commission of the offences covered by this Convention, property, equipment or other instrumentalities and methods used for the transfer, concealment or disguise of such proceeds, property, equipment or other instrumentalities; (g) Appropriate and efficient legal and administrative mechanisms and methods for facilitating the seizure, confiscation and return of proceeds of offences covered by this Convention; (h) Methods used in the protection of victims and witnesses who cooperate with judicial authorities; (i) Training in relevant substantive and procedural law, and law enforcement investigation powers, as well as in national and international regulations and in languages. States Parties shall, subject to their domestic law, endeavour to leverage the expertise of and cooperate closely with other States Parties and relevant international and regional organizations, non-governmental organizations, civil society organizations, academic institutions and private sector entities, with a view to enhancing the effective implementation of this Convention. States Parties shall assist one another in planning and implementing research and training programmes designed to share expertise in the areas referred to in paragraph 3 of this article, and to that end shall also, when appropriate, use regional and international conferences and seminars to promote cooperation and to stimulate discussion on problems of mutual concern. States Parties shall consider assisting one another, upon request, in conducting evaluations, studies and research relating to the types, causes and effects of offences covered by this Convention committed in their respective territories, with a view to developing, with the participation of the competent authorities and relevant non‑governmental organizations, civil society organizations, academic institutions and private sector entities, strategies and action plans to prevent and combat cybercrime. States Parties shall promote training and technical assistance that facilitates timely extradition and mutual legal assistance. Such training and technical assistance may include language training, assistance with the drafting and handling of mutual legal assistance requests, and secondments and exchanges between personnel in central authorities or agencies with relevant responsibilities. States Parties shall strengthen, to the extent necessary, efforts to maximize the effectiveness of technical assistance and capacity-building in international and regional organizations and in the framework of relevant bilateral and multilateral agreements or arrangements. States Parties shall consider establishing voluntary mechanisms with a view to contributing financially to the efforts of developing countries to implement this Convention through technical assistance programmes and capacity-building projects. Each State Party shall endeavour to make voluntary contributions to the United Nations Office on Drugs and Crime for the purpose of fostering, through the Office, programmes and projects with a view to implementing this Convention through technical assistance and capacity-building. Article 55 Exchange of information\nEach State Party shall consider analysing, as appropriate, in consultation with relevant experts, including from non-governmental organizations, civil society organizations, academic institutions and private sector entities, trends in its territory with respect to offences covered by this Convention, as well as the circumstances in which such offences are committed. States Parties shall consider developing and sharing with each other and through international and regional organizations statistics, analytical expertise and information concerning cybercrime, with a view to developing, insofar as possible, common definitions, standards and methodologies, as well as best practices, to prevent and combat such crime. Each State Party shall consider monitoring its policies and practical measures to prevent and combat offences covered by this Convention and making assessments of their effectiveness and efficiency. States Parties shall consider exchanging information on legal, policy and technological developments related to cybercrime and the collection of evidence in electronic form. Article 56 Implementation of the Convention through economic development and technical assistance\nStates Parties shall take measures conducive to the optimal implementation of this Convention to the extent possible, through international cooperation, taking into account the negative effects of the offences covered by this Convention on society in general and, in particular, on sustainable development. States Parties are strongly encouraged to make concrete efforts, to the extent possible and in coordination with each other, as well as with international and regional organizations: (a) To enhance their cooperation at various levels with other States Parties, in particular developing countries, with a view to strengthening their capacity to prevent and combat the offences covered by this Convention; (b) To enhance financial and material assistance to support the efforts of other States Parties, in particular developing countries, in effectively preventing and combating the offences covered by this Convention and to help them to implement this Convention; (c) To provide technical assistance to other States Parties, in particular developing countries, in support of meeting their needs regarding the implementation of this Convention. To that end, States Parties shall endeavour to make adequate and regular voluntary contributions to an account specifically designated for that purpose in a United Nations funding mechanism; (d) To encourage, as appropriate, non-governmental organizations, civil society organizations, academic institutions and private sector entities, as well as financial institutions, to contribute to the efforts of States Parties, including in accordance with this article, in particular by providing more training programmes and modern equipment to developing countries in order to assist them in achieving the objectives of this Convention; (e) To exchange best practices and information with regard to activities undertaken, with a view to improving transparency, avoiding duplication of effort and making best use of any lessons learned. States Parties shall also consider using existing subregional, regional and international programmes, including conferences and seminars, to promote cooperation and technical assistance and to stimulate discussion on problems of mutual concern, including the special problems and needs of developing countries. To the extent possible, States Parties shall ensure that resources and efforts are distributed and directed to support the harmonization of standards, skills, capacity, expertise and technical capabilities with the aim of establishing common minimum standards among States Parties to eradicate safe havens for the offences covered by this Convention and strengthen the fight against cybercrime. To the extent possible, the measures taken under this article shall be without prejudice to existing foreign assistance commitments or to other financial cooperation arrangements at the bilateral, regional or international levels. States Parties may conclude bilateral, regional or multilateral agreements or arrangements on material and logistical assistance, taking into consideration the financial arrangements necessary for the means of international cooperation provided for by this Convention to be effective and for the prevention, detection, investigation and prosecution of the offences covered by this Convention. Chapter VIII: Mechanism of implementation Article 57 Conference of the States Parties to the Convention\nA Conference of the States Parties to the Convention is hereby established to improve the capacity of and cooperation between States Parties to achieve the objectives set forth in this Convention and to promote and review its implementation. The Secretary-General of the United Nations shall convene the Conference of the States Parties not later than one year following the entry into force of this Convention. Thereafter, regular meetings of the Conference shall be held in accordance with the rules of procedure adopted by the Conference. The Conference of the States Parties shall adopt rules of procedure and rules governing the activities set forth in this article, including rules concerning the admission and participation of observers, and the payment of expenses incurred in carrying out those activities. Such rules and related activities shall take into account principles such as effectiveness, inclusivity, transparency, efficiency and national ownership. In establishing its regular meetings, the Conference of the States Parties shall take into account the time and location of the meetings of other relevant international and regional organizations and mechanisms in similar matters, including their subsidiary treaty bodies, consistent with the principles identified in paragraph 3 of this article. The Conference of the States Parties shall agree upon activities, procedures and methods of work to achieve the objectives set forth in paragraph 1 of this article, including: (a) Facilitating the effective use and implementation of this Convention, the identification of any problems thereof, as well as the activities carried out by States Parties under this Convention, including encouraging the mobilization of voluntary contributions; (b) Facilitating the exchange of information on legal, policy and technological developments pertaining to the offences established in accordance with this Convention and the collection of evidence in electronic form among States Parties and relevant international and regional organizations, as well as non-governmental organizations, civil society organizations, academic institutions and private sector entities, in accordance with domestic law, as well as on patterns and trends in cybercrime and on successful practices for preventing and combating such offences; (c) Cooperating with relevant international and regional organizations, as well as non-governmental organizations, civil society organizations, academic institutions and private sector entities; (d) Making appropriate use of relevant information produced by other international and regional organizations and mechanisms for preventing and combating the offences established in accordance with this Convention, in order to avoid unnecessary duplication of work; (e) Reviewing periodically the implementation of this Convention by its States Parties; (f) Making recommendations to improve this Convention and its implementation as well as considering possible supplementation or amendment of the Convention; (g) Elaborating and adopting supplementary protocols to this Convention on the basis of articles 61 and 62 of this Convention; (h) Taking note of the technical assistance and capacity-building requirements of States Parties regarding the implementation of this Convention and recommending any action it may deem necessary in that respect. Each State Party shall provide the Conference of the States Parties with information on legislative, administrative and other measures, as well as on its programmes, plans and practices, to implement this Convention, as required by the Conference. The Conference shall examine the most effective way of receiving and acting upon information, including, inter alia, information received from States Parties and from competent international and regional organizations. Inputs received from representatives of relevant non-governmental organizations, civil society organizations, academic institutions and private sector entities, duly accredited in accordance with procedures to be decided upon by the Conference, may also be considered. For the purpose of paragraph 5 of this article, the Conference of the States Parties may establish and administer such review mechanisms as it considers necessary. Pursuant to paragraphs 5 to 7 of this article, the Conference of the States Parties shall establish, if it deems necessary, any appropriate mechanisms or subsidiary bodies to assist in the effective implementation of the Convention. Article 58 Secretariat\nThe Secretary-General of the United Nations shall provide the necessary secretariat services to the Conference of the States Parties to the Convention. The secretariat shall: (a) Assist the Conference of the States Parties in carrying out the activities set forth in this Convention and make arrangements and provide the necessary services for the sessions of the Conference as they pertain to this Convention; (b) Upon request, assist States Parties in providing information to the Conference of the States Parties, as envisaged in this Convention; and (c) Ensure the necessary coordination with the secretariats of relevant international and regional organizations. Chapter IX: Final provisions Article 59 Implementation of the Convention\nEach State Party shall take the necessary measures, including legislative and administrative measures, in accordance with fundamental principles of its domestic law, to ensure the implementation of its obligations under this Convention. Each State Party may adopt more strict or severe measures than those provided for by this Convention for preventing and combating the offences established in accordance with this Convention. Article 60 Effects of the Convention\nIf two or more States Parties have already concluded an agreement or treaty on the matters dealt with in this Convention or have otherwise established their relations on such matters, or should they in future do so, they shall also be entitled to apply that agreement or treaty or to regulate those relations accordingly. Nothing in this Convention shall affect other rights, restrictions, obligations and responsibilities of a State Party under international law. Article 61 Relation with protocols\nThis Convention may be supplemented by one or more protocols. In order to become a Party to a protocol, a State or a regional economic integration organization must also be a Party to this Convention. A State Party to this Convention is not bound by a protocol unless it becomes a Party to the protocol in accordance with the provisions thereof. Any protocol to this Convention shall be interpreted together with this Convention, taking into account the purpose of that protocol. Article 62 Adoption of supplementary protocols\nAt least 60 States Parties shall be required before any supplementary protocol is considered for adoption by the Conference of the States Parties. The Conference shall make every effort to achieve consensus on any supplementary protocol. If all efforts at consensus have been exhausted and no agreement has been reached, the supplementary protocol shall, as a last resort, require for its adoption at least a two‑thirds majority vote of the States Parties present and voting at the meeting of the Conference. Regional economic integration organizations, in matters within their competence, shall exercise their right to vote under this article with a number of votes equal to the number of their member States that are Parties to this Convention. Such organizations shall not exercise their right to vote if their member States exercise theirs and vice versa. Article 63 Settlement of disputes\nStates Parties shall endeavour to settle disputes concerning the interpretation or application of this Convention through negotiation or any other peaceful means of their own choice. Any dispute between two or more States Parties concerning the interpretation or application of this Convention that cannot be settled through negotiation or other peaceful means within a reasonable time shall, at the request of one of those States Parties, be submitted to arbitration. If, six months after the date of the request for arbitration, those States Parties are unable to agree on the organization of the arbitration, any one of those States Parties may refer the dispute to the International Court of Justice by request in accordance with the Statute of the Court. Each State Party may, at the time of signature, ratification, acceptance or approval of or accession to this Convention, declare that it does not consider itself bound by paragraph 2 of this article. The other States Parties shall not be bound by paragraph 2 of this article with respect to any State Party that has made such a reservation. Any State Party that has made a reservation in accordance with paragraph 3 of this article may at any time withdraw that reservation by notification to the Secretary-General of the United Nations. Article 64 Signature, ratification, acceptance, approval and accession\nThis Convention shall be open to all States for signature in Hanoi in 2025 and thereafter at United Nations Headquarters in New York until 31 December 2026. This Convention shall also be open for signature by regional economic integration organizations, provided that at least one member State of such an organization has signed this Convention in accordance with paragraph 1 of this article. This Convention is subject to ratification, acceptance or approval. Instruments of ratification, acceptance or approval shall be deposited with the Secretary-General of the United Nations. A regional economic integration organization may deposit its instrument of ratification, acceptance or approval if at least one of its member States has done likewise. In that instrument of ratification, acceptance or approval, such organization shall declare the extent of its competence with respect to the matters governed by this Convention. Such organization shall also inform the depositary of any relevant modification in the extent of its competence. This Convention is open for accession by any State or any regional economic integration organization of which at least one member State is a Party to this Convention. Instruments of accession shall be deposited with the Secretary-General of the United Nations. At the time of its accession, a regional economic integration organization shall declare the extent of its competence with respect to matters governed by this Convention. Such organization shall also inform the depositary of any relevant modification in the extent of its competence. Article 65 Entry into force\nThis Convention shall enter into force on the ninetieth day after the date of deposit of the fortieth instrument of ratification, acceptance, approval or accession. For the purpose of this paragraph, any instrument deposited by a regional economic integration organization shall not be counted as additional to those deposited by member States of that organization. For each State or regional economic integration organization ratifying, accepting, approving or acceding to this Convention after the deposit of the fortieth instrument of such action, this Convention shall enter into force on the thirtieth day after the date of deposit by such State or organization of the relevant instrument or on the date on which this Convention enters into force pursuant to paragraph 1 of this article, whichever is later. Article 66 Amendment\nAfter the expiry of five years from the entry into force of this Convention, a State Party may propose an amendment and transmit it to the Secretary-General of the United Nations, who shall thereupon communicate the proposed amendment to the States Parties and to the Conference of the States Parties to the Convention for the purpose of considering and deciding on the proposal. The Conference shall make every effort to achieve consensus on each amendment. If all efforts at consensus have been exhausted and no agreement has been reached, the amendment shall, as a last resort, require for its adoption a two-thirds majority vote of the States Parties present and voting at the meeting of the Conference. Regional economic integration organizations, in matters within their competence, shall exercise their right to vote under this article with a number of votes equal to the number of their member States that are Parties to this Convention. Such organizations shall not exercise their right to vote if their member States exercise theirs and vice versa. An amendment adopted in accordance with paragraph 1 of this article is subject to ratification, acceptance or approval by States Parties. An amendment adopted in accordance with paragraph 1 of this article shall enter into force in respect of a State Party 90 days after the date of the deposit with the Secretary-General of the United Nations of an instrument of ratification, acceptance or approval of such amendment. When an amendment enters into force, it shall be binding on those States Parties that have expressed their consent to be bound by it. Other States Parties shall still be bound by the provisions of this Convention and any earlier amendments that they have ratified, accepted or approved. Article 67 Denunciation\nA State Party may denounce this Convention by written notification to the Secretary-General of the United Nations. Such denunciation shall become effective one year after the date of receipt of the notification by the Secretary-General. A regional economic integration organization shall cease to be a Party to this Convention when all of its member States have denounced it. Denunciation of this Convention in accordance with paragraph 1 of this article shall entail the denunciation of any protocols thereto. Article 68 Depositary and languages\nThe Secretary-General of the United Nations is designated depositary of this Convention. The original of this Convention, of which the Arabic, Chinese, English, French, Russian and Spanish texts are equally authentic, shall be deposited with the Secretary-General of the United Nations. IN WITNESS WHEREOF, the undersigned plenipotentiaries, being duly authorized thereto by their respective Governments, have signed this Convention. ","permalink":"https://intlaws.com/en/compliance/intl/un-cybercrime-convention/","summary":"Official full text of the UN Convention against Cybercrime (UNGA resolution 79/243, 24 December 2024, annex; 9 chapters, 68 articles). Enters into force on the ninetieth day after deposit of the fortieth instrument of ratification; not yet in force. Text taken from official UN sources.","title":"United Nations Convention against Cybercrime (Full Text)"},{"content":"个人信息保护合规审计：义务边界与企业落地——以《个人信息保护合规审计管理办法》为中心 一、义务的规范来源：三层规范叠加 个人信息保护合规审计不是新概念，但直到 2025 年才形成可操作的完整链条。理解这项义务，需要把三层规范叠起来看。\n法律层。《个人信息保护法》第五十四条确立基本义务：\u0026ldquo;个人信息处理者应当定期对其处理个人信息遵守法律、行政法规的情况进行合规审计。\u0026ldquo;第六十四条给出监管侧触发机制：履行个人信息保护职责的部门发现个人信息处理活动存在较大风险或者发生个人信息安全事件的，可以按照规定的权限和程序对该个人信息处理者的法定代表人或者主要负责人进行约谈，或者要求个人信息处理者委托专业机构对其个人信息处理活动进行合规审计。\n行政法规层。《网络数据安全管理条例》（中华人民共和国国务院令第 790 号，2024 年 9 月 24 日公布，2025 年 1 月 1 日起施行）第二十七条把主体扩展为\u0026quot;网络数据处理者\u0026rdquo;，要求\u0026quot;定期自行或者委托专业机构\u0026quot;开展合规审计；第二十八条规定，处理 1000 万人以上个人信息的网络数据处理者，还应当遵守该条例第三十条、第三十二条对重要数据处理者作出的规定（即设置网络数据安全负责人与安全管理机构、数据变动时报告处置方案等）。\n规章层。《个人信息保护合规审计管理办法》（国家互联网信息办公室令第 18 号，2025 年 2 月 12 日公布，2025 年 5 月 1 日起施行，以下简称《办法》）把上述义务程序化：审计如何启动、多久一次、审什么、谁来审、报告怎么报、整改怎么跟，在《办法》及其附件《个人信息保护合规审计指引》中均有对应规则。\n二、\u0026ldquo;谁来审\u0026rdquo;：两种情形与两项主体要求 情形一：自行开展。第三条：由内部机构或者委托专业机构定期开展合规审计。第四条设定频次下限：处理超过 1000 万人个人信息的，应当每两年至少开展一次。\n**情形二：保护部门要求委托专业机构。**第五条列举三种情形：发现处理活动存在严重影响个人权益或者严重缺乏安全措施等较大风险的；处理活动可能侵害众多个人的权益的；发生个人信息安全事件，导致 100 万人以上个人信息或者 10 万人以上敏感个人信息泄露、篡改、丢失、毁损的。同条第二款明确：对同一个人信息安全事件或者风险，不得重复要求委托专业机构开展审计。\n两项主体要求（第十二条）：处理 100 万人以上个人信息的，应当指定个人信息保护负责人负责本单位合规审计工作；提供重要互联网平台服务、用户数量巨大、业务类型复杂的，应当成立主要由外部成员组成的独立机构对审计情况进行监督。\n三、\u0026ldquo;审什么\u0026rdquo;：附件《审计指引》的四个板块 第六条规定，无论自行开展还是按保护部门要求开展，都应当参照附件《个人信息保护合规审计指引》。该指引以条目形式列明审计重点，可归纳为四个板块。\n**其一，合法性基础与处理规则。**同意是否真实、明确、可追溯；处理目的变更后是否重新取得同意；应取得单独同意或书面同意的场景是否落实；处理规则是否真实准确完整、是否以清单等形式列明、是否与处理目的直接相关并采取对个人权益影响最小的方式、是否明确保存期限与到期处理方式、是否明确个人行使权利的途径与方法。\n**其二，告知与个人权利保障。**告知是否以显著方式、清晰易懂的语言作出，文本是否便于完整阅读，规则变更是否及时告知；删除权的触发情形是否落地（目的已实现或不再必要、停止提供产品或服务、账号注销、保存期限届满、撤回同意、违法或违约处理等）；个人权利的申请受理与响应机制、拒绝请求是否说明理由、是否响应对处理规则的解释说明要求。\n**其三，高风险场景——审计资源应重点投向这里。**自动化决策的透明度与结果公平公正、事前告知与影响评估、拒绝机制与个性化推荐关闭选项；敏感个人信息与不满十四周岁未成年人信息的单独同意、监护人同意与专门处理规则；对外提供、共同处理、委托处理的单独同意与接收方信息告知、事前影响评估、合同约定及定期检查监督；个人信息出境的安全评估或认证、标准合同及备案、向外国司法或执法机构提供是否经主管机关批准、是否向限制或禁止清单中的对象提供；公共场所图像采集与个人身份识别设备的公共安全必要性、显著提示标识与单独同意；已公开个人信息处理的边界（不得发送与公开目的无关的商业信息、不得用于网络暴力或传播谣言、不得处理个人明确拒绝的部分）。\n**其四，安全管理制度与技术措施。**管理制度与操作规程、操作权限设置、教育与培训计划、个人信息保护负责人的专业能力与履职情况、影响评估开展情况、安全事件应急预案与应急响应处置、平台规则与社会责任报告。\n实务提示：首轮审计不必全面铺开，可先做风险映射——把本单位的自动化决策、敏感信息、对外提供与出境、公共场所采集等场景逐项标注\u0026quot;有无\u0026rdquo;，据此确定首轮范围与资源投入。这比平均用力更符合《办法》\u0026ldquo;参照指引\u0026quot;而非\u0026quot;逐条打分\u0026quot;的定位。\n四、\u0026ldquo;怎么审\u0026rdquo;：程序与时限 按保护部门要求开展审计时，以下节点可直接用于项目排期：\n费用与配合（第八条）：应当为专业机构正常开展工作提供必要支持，并承担审计费用； 期限（第九条）：按保护部门要求选定专业机构，在限定时间内完成；情况复杂的，报保护部门批准后可以适当延长； 报送报告（第十条）：完成后将专业机构出具的合规审计报告报送保护部门，报告须由专业机构主要负责人、合规审计负责人签字并加盖专业机构公章； 整改闭环（第十一条）：按保护部门要求整改，整改完成后 15 个工作日内报送整改情况报告。 五、专业机构侧的四条红线 企业在选定机构时应当逐条核对：能力要求（第七条），应具备与审计服务相适应的审计人员、场所、设施和资金，鼓励通过认证，认证按《认证认可条例》有关规定执行；保密与删除（第十三条），对履职中获得的个人信息、商业秘密等依法保密，不得泄露或非法向他人提供，审计工作结束后及时删除相关信息；禁止转委托（第十四条）；连续审计次数限制（第十五条），同一专业机构及其关联机构、同一合规审计负责人不得连续三次以上对同一审计对象开展审计——这条对长期合作安排有直接影响，应在合同中预先规划轮换。\n六、与既有合规动作的衔接 《网络数据安全管理条例》第五十二条明确：个人信息保护合规审计、重要数据风险评估、重要数据出境安全评估等应当加强衔接，避免重复评估、审计；重要数据风险评估和网络安全等级测评的内容重合的，相关结果可以相互采信。\n这给企业留出了整合空间：把合规审计、影响评估、出境评估与等保测评的证据池与整改台账合并管理，并在监管沟通中说明相互采信关系，可显著降低重复投入。\n七、法律责任与不适用范围 《办法》第十八条：个人信息处理者、专业机构违反本办法的，依照《个人信息保护法》《网络数据安全管理条例》等法律法规的规定处理；构成犯罪的，依法追究刑事责任。\n需要留意一处结构细节：《网络数据安全管理条例》第五十五条列举的罚则条款中并未包含第二十七条的审计义务，该条第五十八条同时规定，违反本条例其他有关规定的，由有关主管部门依照上位法追究法律责任。审计义务的责任落点仍在上位法，而**\u0026ldquo;是否建立了可核验的审计记录\u0026quot;往往就是监管沟通中的第一份材料**。\n另需注意第十九条：对国家机关和法律、法规授权的具有管理公共事务职能的组织的个人信息保护合规审计，不适用本办法。\n八、企业落地清单 判定自身层级：处理规模达到 1000 万人以上触发\u0026quot;每两年至少一次\u0026rdquo;；达到 100 万人以上触发\u0026quot;指定个人信息保护负责人\u0026rdquo;； 首轮做风险映射：对照《审计指引》四个板块，标注本单位自动化决策、敏感信息、对外提供与出境、公共场所采集等场景； 确定审计形式：具备内部能力可自行组织；涉及高风险场景或监管关注事项的建议引入专业机构； 核查机构资质与轮换：能力与认证情况、是否转委托、连续审计次数是否触及三次上限； 固化证据与整改台账：审计底稿、影响评估记录、整改通知与完成证明统一归档，整改完成后 15 个工作日内报送整改情况报告； 做实衔接：与重要数据风险评估、出境安全评估、等保测评的结果相互采信，避免重复评估、审计。 结语 合规审计的制度价值不在于每年产出一份报告，而在于让\u0026quot;是否合规\u0026quot;这个问题有可核验的答案。真正的难点通常不是不知道要审计，而是审计发现的问题没有闭环——报告写得完整、整改停在纸面，反而是更明显的风险暴露。把审计、整改与证据归档作为一件事来管理，才是这项义务的正确打开方式。\n规范依据（供核对）\n《中华人民共和国个人信息保护法》第五十四条、第五十五条、第六十四条。 《网络数据安全管理条例》，中华人民共和国国务院令第 790 号，2024 年 9 月 24 日公布，2025 年 1 月 1 日起施行（第二十七条、第二十八条、第五十二条、第五十五条、第五十八条）。 《个人信息保护合规审计管理办法》，国家互联网信息办公室令第 18 号，2025 年 2 月 12 日公布，2025 年 5 月 1 日起施行（第三条至第十五条、第十八条、第十九条，及附件《个人信息保护合规审计指引》）。 ","permalink":"https://intlaws.com/forum/%E4%B8%AA%E4%BA%BA%E4%BF%A1%E6%81%AF%E4%BF%9D%E6%8A%A4%E5%90%88%E8%A7%84%E5%AE%A1%E8%AE%A1-%E4%B9%89%E5%8A%A1%E8%BE%B9%E7%95%8C%E4%B8%8E%E4%BC%81%E4%B8%9A%E8%90%BD%E5%9C%B0/","summary":"以《个人信息保护合规审计管理办法》为中心，拆解合规审计的启动情形、频次要求与《审计指引》28项重点的四大板块，并提示审计机构「不得连续三次」轮换红线与多套评估体系的整合空间。","title":"个人信息保护合规审计：义务边界与企业落地——以《个人信息保护合规审计管理办法》为中心"},{"content":"联合国打击网络犯罪以及为打击使用信息通信技术系统实施的某些犯罪并共享严重犯罪电子证据而加强国际合作公约 版本与来源（可核验）\n项目 内容 通过 2024 年 12 月 24 日联合国大会第 79/243 号决议通过，公约载于该决议附件 结构 序言 + 9 章 68 条 生效条件 公约第 65 条：自第 40 份批准书、接受书、核准书或加入书交存之日起第 90 天生效（已核官方原文） 现行状态 尚未生效（截至 2026-09-22；签署与批准进展见联合国条约集 https://treaties.un.org ） 中文原文来源 联合国正式文件 A/RES/79/243（中文版）：https://documents.un.org/api/symbol/access?s=A%2FRES%2F79%2F243\u0026amp;l=zh\u0026amp;t=pdf 英文原文来源 UNODC 公约全文页 https://www.unodc.org/unodc/en/cybercrime/convention/text/convention-full-text.html ；联合国正式文件 A/RES/79/243（英文版）：https://documents.un.org/api/symbol/access?s=A%2FRES%2F79%2F243\u0026amp;l=en\u0026amp;t=pdf 校对记录 2026-09-22 抓取官方文本；中英条目 68 条一一对应、无缺号；第 47 条（执法合作 / Law enforcement cooperation）经中英互校确认；英文第 47 条标题在联合国 PDF 文本层缺失，已依 UNODC 官方 HTML 文本与中文官方文本互校补齐 说明 本页为条约原文，中、英文均取自联合国官方文本，不涉及翻译 第一章 总则 第一条 宗旨声明\n本公约的宗旨是： ㈠ 促进和加强各项措施，以更高效和更有效地预防和打击网络犯罪； ㈡ 促进、便利和加强在预防和打击网络犯罪方面开展的国际合作；以及 ㈢ 促进、便利和支持技术援助和能力建设，以预防和打击网络犯罪，特别是使发展中国家从中受益。某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/2435/43 24-24621\n第二条 术语的使用\n为本公约之目的： ㈠ “信息通信技术系统 ”系指任何设备或任何一组相互连接或相关的设备，其中一个或多个设备按照某一程序收集、存储并自动处理电子数据； ㈡ “电子数据”系指任何以适合在信息通信技术系统内处理的形式表现的事实、信息或概念，包括适合使信息通信技术系统 得以 执行某一功能的程序； ㈢ “流量数据”系指与使用信息通信技术系统进行的通信有关的任何电子数据，由构成通信链一部分的信息通信技术系统生成，显示通信的起点、终点、路径、时间、日期、数据量大小、持续时间或基础服务类型； ㈣ “内容数据”系指与使用信息通信技术系统传输的数据的实质内容有关，且不属于订阅用户信息或流量数据的任何电子数据，包括但不限于图像、文本消息、语音消息、录音和录像； ㈤ “服务提供者”系指以下任何公共或私营实体：\n能让使用其服务的用户使用信息通信技术系统进行通信；或 为此类通信服务或此类服务的用户处理或存储电子数据； ㈥ “订阅用户信息 ”系指服务提供者持有的与其服务订阅用户有关的任何信息，但不包括流量数据或内容数据，通过订阅用户信息可以确定： 所使用的通信服务种类、与之相关的技术条款以及服务期限； 根据服务协议或安排提供的订阅用户身份、邮政地址或地理地址、电话或其他接入号码、账单信息或付款信息； 根据服务协议或安排提供的关于通信设备安装地点的任何其他信息； ㈦ “个人数据”系指与已识别或可识别身份的自然人有关的任何信息； ㈧ “严重犯罪”系指构成犯罪且最高可处以至少四年有期徒刑或更重惩处的行为； ㈨ “财产”系指各种资产，不论是物质的或非物质的、动产或不动产、有形的或无形的，包括虚拟资产，以及证明对这些资产拥有所有权或权益的法律文件或文书； ㈩ “犯罪所得 ”系指通过实施犯罪而直接或间接产生或获得的任何财产；(十一) “冻结”或“扣押”系指根据法院或其他主管机关签发的命令暂时禁止财产转移、转换、处置或移动，或对财产实行暂时性扣留或控制；(十二) “没收”，在适用情况下亦包括充公，系指根据法院或其他主管机关的命令对财产实行永久剥夺；(十三) “上游犯罪”系指由其所产生的收益可能成为本公约第十七条所界定的犯罪对象的任何犯罪；(十四) “区域经济一体化组织”系指由某一区域的一些主权国家组成的组织，其成员国已将处理本公约涵盖范围内事务的权限转交该组织，而且该组织已按照其内部程序获得签署、批准、接受、核准或加入本公约的正式授权；本公约中“缔约国”的指称在此类组织的权限范围内适用于这些组织；(十五) “紧急情况”系指任何自然人的生命或安全面临重大和紧迫风险的情况。 第三条 适用范围\n本公约除其中另有规定者外，应适用于： ㈠ 预防、侦查和起诉根据本公约确立的刑事犯罪，包括冻结、扣押、没收和返还此类犯罪的所得； ㈡ 根据本公约第二十三条和第三十五条，为进行刑事侦查或诉讼的目的，收集、获取、保全和共享电子证据。\n第四条 根据联合国其他公约和议定书确立的犯罪\n一、 在履行其作为缔约国的其他适用的联合国公约和议定书时，缔约国应当确保根据此类公约和议定书确立的刑事犯罪，在使用信息通信技术系统实施时，亦视作本国法律规定的刑事犯罪。二、 本条中的任何内容均不得解释为根据本公约确立刑事犯罪。\n第五条 保护主权\n一、 在履行其根据本公约所承担的义务时，缔约国应恪守各国主权平等和领土完整原则和不干涉他国内政原则。二、 本公约的任何规定均未授权一缔约国在另一国领土内行使管辖权和履行该另一国本国法律规定的专属于该国机关的职能。\n第六条 尊重人权\n一、在履行其根据本公约承担的义务时，缔约国应当确保符合其所承担的国际人权法义务。某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/2437/43 24-24621二、根据可适用的国际人权法 且依循与此类人权法相一致的方式，本公约的任何规定均不得解释为允许压制人权或基本自由，包括与言论自由、良心自由、意见自由、宗教或信仰自由、和平集会和结社自由相关的权利。\n第二章 刑事定罪 第七条 非法访问\n一、各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意访问信息通信技术系统的全部或任何部分的行为规定为刑事犯罪 行为。二、缔约国可规定此类犯罪须是以违反安全措施方式实施的，其意图是获取电子数据或有其他不诚实意图或犯罪意图，或者涉及与另一信息通信技术系统相连的信息通信技术系统。\n第八条 非法拦截\n一、各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意实施的以下行为规定为刑事犯罪行为：以技术手段拦截进出信息通信技术系统的或在此类系统内部的电子数据非公开传输，包括拦截携带此类电子数据的信息通信技术系统发出的电磁辐射。二、缔约国可规定此种犯罪须是带有不诚实意图或犯罪意图实施的，或者涉及与另一信息通信技术系统相连的信息通信技术系统。\n第九条 干扰电子数据\n一、各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意破坏、删除、劣化、更改或抑制电子数据的行为规定为刑事犯罪 行为。二、缔约国可规定本条第一款所述行为须是造成了严重损害的行为。\n第十条 干扰信息通信技术系统\n各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意通过输入、传输、破坏、删除、劣化、更改或抑制电子数据而严重妨碍信息通信技术系统运行的行为规定为刑事犯罪行为。\n第十一条 滥用设备\n一、各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意实施的以下行为规定为刑事犯罪行为： ㈠ 获取、制作、销售、采购以供使用、进口、分销或以其他方式提供：\n主要为实施根据本公约第七条至第十条确立的任何犯罪行为而设计或改装的设备（包括程序） ；或 可用以访问信息通信技术系统的全部或任何部分的密码、访问凭证、电子签名或类似数据；意图将该设备（包括程序）或密码、访问凭证、电子签名或类似数据用于实施根据本公约第七条至第十条确立的任何犯罪行为；以及 ㈡ 持有本条第一款第㈠项第 1 或第 2 目所述物项，意图将其用于实施根据本公约第七条至第十条确立的任何犯罪行为。二、如果本条第一款所述的获取、制作、销售、采购以供使用、进口、分销或以其他方式提供或持有等行为并非为了实施根据本公约第七条至第十条确立的犯罪行为，而是为了诸如经授权测试或保护信息通信技术系统等目的，则本条不得解释为对其追究刑事责任。三、各缔约国均可保留不适用本条第一款的权利，但这一保留不得涉及销售、分销或以其他方式提供本条第一款第㈠项第 2 目所述物项。 第十二条 与信息通信技术系统有关的伪造\n一、各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意实施的以下行为规定为刑事犯罪 行为：输入、更改、删除或抑制电子数据，造成不真实的数据，意图使其在合法用途中被当作真实数据来考虑或作为行动依据，而不论该数据是否可直接读取和理解。二、缔约国可规定须存在欺诈意图或类似不诚实意图或犯罪意图才能对之追究刑事责任。\n第十三条 与信息通信技术系统有关的盗窃或欺诈\n各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意使用以下手段造成他人财产损失的行为规定为刑事犯罪行为： ㈠ 以任何方式输入、更改、删除或抑制电子数据； ㈡ 对信息通信技术系统运行的任何干扰；某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/2439/43 24-24621 ㈢ 通过信息通信技术系统做出任何与真实情况不符的欺骗行为，致使某人做出其原本不会做的或未做出其原本会做的任何事情；存有欺诈或不诚实意图，意欲为自己或他人谋取其本无权获取的金钱或其他财产收益。\n第十四条 涉及网上儿童性虐待或儿童性剥削材料的犯罪\n一、各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意实施的以下行为规定为刑事犯罪行为： ㈠ 通过信息通信技术系统制作、主动提供、出售、分销、传送、广播、展示、发布或以其他方式提供儿童性虐待或儿童性剥削材料； ㈡ 通过信息通信技术系统索取、获取或访问儿童性虐待或儿童性剥削材料； ㈢ 持有或控制存储在信息通信技术系统或其他存储介质中的儿童性虐待或儿童性剥削材料； ㈣ 资助根据本款第 ㈠至第㈢项确立的犯罪行为的，缔约国可将之单独规定为一类犯罪。二、就本条而言， “儿童性虐待或儿童性剥削材料 ”一语应当包括视觉材料，亦可包括书面内容或音频内容，其中描绘、描述或呈现任何未满十八岁的人： ㈠ 从事真实或模拟的性活动； ㈡ 所处现场有正在从事任何性活动的人； ㈢ 主要为性目的展示性器官；或 ㈣ 遭受酷刑或残忍、不人道或有辱人格的待遇或惩罚，且此类材料具有性的性质。三、缔约国可要求本条第二款所指材料仅限于以下材料： ㈠ 描绘、描述或呈现某一现实中存在的人；或 ㈡ 以视觉方式描绘儿童性虐待或儿童性剥削。四、缔约国可根据本国法律并依照适用的国际义务采取措施，排除对下列行为的刑事定罪： ㈠ 儿童为自制那些描绘他们的材料而实施的行为；或 ㈡ 在所涉人员同意的情况下制作、传播或持有本条第二款第 ㈠项至第㈡项所述材料的行为，前提是所描绘的行为根据本国法律系属合法行为，且此类材料完全仅供所涉人员私下和同意的情况下使用。五、本公约的任何规定均不得影响更有利于实现儿童权利的任何国际义务。\n第十五条 为对儿童实施性犯罪而进行教唆或诱骗\n一、各缔约国均应采取必要的立法措施和其他措施，在本国法律中将故意实施的以下行为规定为刑事犯罪行为：为实施本国法律所界定的对儿童的性犯罪，包括为实施根据本公约第十四条确立的任何犯罪，通过信息通信技术系统进行通信联络、教唆、诱骗或做出任何安排。二、缔约国可规定须有在本条第一款所述行为基础上的更进一步行动。三、 缔约国可考虑将本条第一款规定的刑事定罪范围扩大到包括被认为是儿童的人。四、缔约国可采取措施，排除对由儿童实施的本条第一款所述行为进行刑事定罪。\n第十六条 未经同意传播私密图像\n一、各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意实施的以下行为规定为刑事犯罪行为：使用信息通信技术系统出售、分销、传送、发布或以其他方式提供某人的私密图像，而未经图像中所描绘的人同意。二、就本条第一款而言， “私密图像”系指以包括照片或录像在内的任何方式对一个年满十八岁的人进行的具有性性质的视觉记录，其中该人的性器官暴露在外，或该人正在进行性活动，这些行为在进行记录时皆属个人隐私，而且在犯罪实施时被描绘者(一人或多人)对其隐私受保护仍保持合理期望。三、缔约国可酌情将私密图像的定义扩至所描绘的对象包含根据本国法律已达到性活动法定年龄但未满十八岁者，且图像中未描绘对儿童的虐待或剥削。四、就本条而言，私密图像中描绘的未满十八岁者不具备同意传播构成本公约\n第十七条 对犯罪所得的洗钱行为\n一、 各缔约国均应根据本国法律的基本原则采取必要的立法措施和其他措施，将故意实施的以下行为规定为刑事犯罪行为： ㈠ 1. 明知财产为犯罪所得，为隐瞒或掩饰此类财产的非法来源，或为协助参与实施上游犯罪的任何人逃避其行为的法律后果而转换或转移该财产； 2. 明知财产为犯罪所得而隐瞒或掩饰此类财产的真实性质、来源、所在地、处置、转移、所有权或与此类财产有关的权利； ㈡ 在符合本国法律制度基本概念的情况下：\n在得到财产时，明知其为犯罪所得而仍获取、占有或使用； 参与、协同或共谋实施，实施未遂，以及协助、教唆、便利和参谋实施根据本条确立的任何犯罪。二、为施行或适用本条第一款： ㈠ 各缔约国均应将根据本公约第七至第十六条确立的相关犯罪列为上游犯罪； ㈡ 缔约国立法中如果列出具体上游犯罪清单，则至少应当在此类清单中列入根据本公约第七至第十六条确立的各种犯罪； ㈢ 就本款第㈡项而言，上游犯罪应当包括在有关缔约国法域之内和之外实施的犯罪。然而，如果犯罪是在一缔约国法域之外实施的，则只有当有关行为根据其发生地所在国的本国法律构成刑事犯罪，且根据施行或适用本条的缔约国的本国法律该行为若发生在该国亦构成刑事犯罪时，才构成上游犯罪； ㈣ 各缔约国均应向联合国秘书长提供本国施行本条的法律副本以及随后对此类法律所作的任何修正的副本或相关说明； ㈤ 如果缔约国本国法律的基本原则有此要求，则可规定本条第一款所列犯罪不适用于实施上游犯罪的人； ㈥ 本条第一款所规定的作为犯罪要件的明知、故意或目的可根据客观实际情况予以推定。 第十八条 法人责任\n一、 各缔约国均应采取符合本国法律原则的必要措施，确定法人参与根据本公约确立的犯罪所应承担的责任。二、 在不违反缔约国法律原则的情况下，法人责任可包括刑事责任、民事责任或行政责任。三、法人责任不得影响实施此类犯罪的自然人的刑事责任。四、 各缔约国均应特别确保依照本条被追究责任的法人受到有效、适度和劝诫性的刑事或非刑事制裁，包括经济制裁。\n第十九条 参与和未遂\n一、各缔约国均应采取必要的立法措施和其他措施，根据本国法律将故意实施的以下行为规定为刑事犯罪行为：以共犯、从犯或教唆犯等任何身份参与根据本公约确立的犯罪。二、各缔约国均可采取必要的立法措施和其他措施，根据本国法律将故意实施根据本公约确立的犯罪的任何未遂行为规定为刑事犯罪行为。三、各缔约国均可采取必要的立法措施和其他措施，根据本国法律将故意为实施根据本公约确立的犯罪做准备的行为规定为刑事犯罪行为。\n第二十条 追诉时效\n各缔约国均应考虑到犯罪的严重性，酌情在 本国法律中规定一个较长的追诉时效期，以便在此期限内针对根据本公约确立的任何犯罪启动诉讼程序，并针对被指控犯罪者逃避司法处置的情况规定更长的追诉时效期或作出中止追诉时效的规定。\n第二十一条 起诉、审判和制裁\n一、各缔约国均应使根据本公约确立的犯罪受到与其严重性相当的有效、适度而具有劝诫性的制裁。二、各缔约国均可根据本国法律采取必要的立法措施和其他措施，针对根据本公约确立的犯罪确定加重情节，包括影响关键信息基础设施的情节。三、各缔约国均应努力确保，为根据本公约确立的犯罪起诉某人时依据本国法律行使的任何法律裁量权，都是为了确保针对此类犯罪的执法措施取得最大成效，并适当考虑到震慑此类犯罪的必要性。四、各缔约国均应确保因根据本公约确立的犯罪而被起诉的任何人都享有既符合本国法律又与适用于本国的国际义务相一致的一切权利和保障，包括得到公平审判的权利和辩护权。五、就根据本公约确立的犯罪而言，各缔约国均应根据本国法律并在适当尊重被告的辩护权的情况下采取适当措施，力求确保针对审前释放裁决或上诉期间释放裁决规定的条件考虑到需要确保被告在后续的刑事诉讼中出庭。六、各缔约国在考虑被判定犯有有关罪行的人员提前释放或假释的可能性时，均应考虑到此类犯罪的严重性。某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24313/43 24-24621七、缔约国应当确保根据本国法律采取适当的措施，依照《儿童权利公约》 及其各项适用的《议定书》以及其他适用的国际或区域文书所规定的义务，保护被控犯有根据本公约确立的罪行的儿童。八、本公约的任何规定均不得影响下述原则，即根据本公约确立的犯罪和可 适用的法律辩护理由或决定行为合法性的其他法律原则，只应由缔约国本国的法律加以阐明，而且应当依照缔约国的本国法律对此类犯罪进行起诉和惩处。\n第三章 管辖权 第二十二条 管辖权\n一、各缔约国均应在下列情况下采取必要措施，对根据本公约确立的犯罪确立管辖权： ㈠ 犯罪发生在该缔约国领土内；或者 ㈡ 犯罪发生在犯罪时悬挂该缔约国国旗的船只上或已根据该缔约国法律注册的航空器内。二、在不违反本公约第五条规定的情况下，缔约国还可在下列情况下对任何此类犯罪确立其管辖权： ㈠ 犯罪系针对该缔约国的国民；或者 ㈡ 犯罪系由该缔约国国民或在该缔约国领土内有惯常居所的无国籍人实施；或者 ㈢ 犯罪系发生在该缔约国领土以外，且属于根据本公约第十七条第一款第㈡项第 2 目所确立的犯罪之一，其目的是在该缔约国领土内实施根据本公约第十七条第一款第㈠项第 1 目或第 2 目或第㈡项第 1 目确立的犯罪；或 ㈣ 犯罪系针对该缔约国。三、为本公约第三十七条第十一款之目的，各缔约国均应采取必要措施，在被指控犯罪人位于其领土内且仅因该人系本国国民而不予引渡时，对根据本公约确立的犯罪确立本国的管辖权。四、各缔约国还可采取必要措施，在被指控犯罪人位于本国领土内，且不引渡该人时，对根据本公约确立的犯罪确立本国的管辖权。五、如果根据本条第一款或第二款行使管辖权的缔约国被告知或通过其他途径获悉任何其他缔约国正在对同一行为进行侦查、起诉或者司法程序，则这些缔约国的主管机关应当酌情相互磋商，以便协调行动。六、在不影响一般国际法规范的情况下，本公约不排除缔约国行使其根据本国法律确立的任何刑事管辖权。\n第四章 程序措施和执法 第二十三条 程序措施的范围\n一、各缔约国均应采取必要的立法措施和其他措施，确立本章所规定的权力和程序，以便进行具体的刑事侦查或诉讼。二、 除本公约另有规定者外，各缔约国均应将本条第一款所述权力和程序适用于： ㈠ 根据本公约确立的刑事犯罪； ㈡ 使用信息通信技术系统实施的其他刑事犯罪；以及 ㈢ 收集任何刑事犯罪的电子证据。三、 ㈠ 各缔约国均可保留将本公约第二十九条所述措施仅适用于保留声明中具体指明的犯罪或犯罪类别的权利，条件是这些犯罪或犯罪类别的涵盖范围不得小于缔约国适用本公约第三十条所述措施的犯罪的涵盖范围。各缔约国均应考虑限制此类保留的涵盖范围，以便使第二十九条所述各项措施能够得到最广泛的适用； ㈡ 若缔约国因本公约通过时有效的本国法律所限，不能对服务提供者的信息通信技术系统内传输的通信适用本公约第二十九条和第三十条所述措施，而该系统：\n正在为一个封闭用户群的利益运行；而且 不使用公共通信网络，也不与另一公共或私人的信息通信技术系统连接；则该缔约国可保留不对此类通信适用上述措施的权利。各缔约国均应考虑限制此类保留的涵盖范围，以使本公约第二十九条和第三十条所述各项措施能够得到最广泛的适用。 第二十四条 条件和保障措施\n一、各缔约国均应确保本章所规定的权力和程序的确立、实施和适用符合本国法律所规定的条件和保障措施；这些条件和保障措施应当按照本国在国际人权法下承担的义务保护人权，并应纳入比例原则。二、此类条件和保障措施应根据和遵循各缔约国本国法律，视相关程序或权力的性质而定，包括司法审查或其他独立审查、获得有效救济的权利、适用理由以及对此类权力或程序的范围和期限的限制等。某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24315/43 24-24621三、在符合公共利益，特别是在符合正当司法的范围内，各缔约国均应考虑本章所规定的权力和程序对第三方权利、责任以及合法利益的影响。四、根据本条确立的条件和保障措施应在缔约国国内适用于本章规定的权力和程序，既包括在国内进行刑事侦查和诉讼的权力和程序，也包括作为被请求缔约国提供国际合作的权力和程序。五、本条第二款中提及的司法审查或其他独立审查是指国内一级的此类审查。\n第二十五条 快速保全存储的电子数据\n一、各缔约国均应采取必要的立法措施和其他措施，使其主管机关得以下令或以类似方式责令快速保全使用信息通信技术系统存储的特定电子数据，包括流量数据、内容数据和订阅用户信息，特别是在有理由认为该电子数据极易丢失或被修改的情况下。二、 缔约国为执行本条第一款而下令某人保全其拥有或控制的所存储的特定电子数据时，应当为此采取必要的立法措施和其他措施，责成该人在最长不超过九十天的必要时限内，保全所涉电子数据 并维护其完整性，以便主管机关得以寻求披露这些数据。缔约国可规定此种命令嗣后可予延期。三、各缔约国均应采取必要的立法措施和其他措施，责成保管人或其他负责保全电子数据的人员在本国法律规定的期限内对进行此类程序一事保守秘密。\n第二十六条 快速保全和部分披露流量数据\n各缔约国均应针对根据本公约第二十五条的规定应予保全的流量数据采取必要的立法措施和其他措施，以便： ㈠ 确保无论是一个还是多个服务提供者参与了通信的传输，均能快速保全流量数据；以及 ㈡ 确保向所涉缔约国的主管机关或该机关所指定人员快速披露足够数量的流量数据，以使该缔约国得以识别服务提供者，并识别所涉通信或所指信息的传输路径。\n第二十七条 提交令\n各缔约国均应采取必要的立法措施和其他措施，授权本国主管机关下令： ㈠ 位于本国领土内的某人提交其所拥有或控制的存储在信息通信技术系统或电子数据存储介质中的特定电子数据；以及 ㈡ 在本国领土内提供服务的服务提供者提交其所拥有或控制的与此类服务有关的订阅用户信息。\n第二十八条 搜查和扣押存储的电子数据\n一、各缔约国均应采取必要的立法措施和其他措施，授权本国主管机关搜查或以类似方式访问位于本国领土内的： ㈠ 信息通信技术系统、其一部分和存储在其中的电子数据；以及 ㈡ 可能存储所要查找的电子数据的存储介质。二、各缔约国均应采取必要的立法措施和其他措施，以便确保，若其主管机关根据本条第一款第 ㈠项的规定搜查或以类似方式访问某一信息通信技术系统或其一部分时，有理由认为所查找的电子数据存储在位于本国领土内的另一信息通信技术系统或其一部分中，而且该等数据可从初始系统合法访问或可供初始系统合法取用，则应使此类主管机关得以快速进行搜查，以访问该 另一信息通信技术系统。三、各缔约国均应采取必要的立法措施和其他措施，授权其主管机关扣押或以类似方式获取根据本条第一款或第二款访问的位于本国领土内的电子数据。这些措施应当包括以下权力： ㈠ 扣押或以类似方式获取信息通信技术系统、其一部分或电子数据存储介质； ㈡ 制作和保留电子数据的电子形式副本； ㈢ 维护所存储的相关电子数据的完整性； ㈣ 移除所访问的信息通信技术系统中的这些电子数据或使之无法访问。四、各缔约国均应采取必要的立法措施和其他措施，授权其主管机关下令任何了解相关信息通信技术系统、信息和电信网络或其组成部分的运行、或了解为保护其中的电子数据而适用的措施的人员在合理情况下提供必要信息，以便能够采取本条第一款至第三款所述措施。\n第二十九条 实时收集流量数据\n一、各缔约国均应采取必要的立法措施和其他措施，授权其主管机关采取下列行动： ㈠ 在本国领土内应用技术手段实时收集或记录；以及 ㈡ 强令服务提供者在其现有的技术能力范围内：\n在本国领土内应用技术手段实时收集或记录；或者 配合并协助主管机关实时收集或记录；与其领土内使用信息通信技术系统传输的特定通信有关的流量数据。某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24317/43 24-24621二、缔约国因其本国法律制度原则而无法采取本条第一款第 ㈠项所述措施的，可采取其他必要的立法措施和其他措施，确保在其领土内应用技术手段实时收集或记录与在其领土内传输的特定通信有关的流量数据。三、各缔约国均应采取必要的立法措施和其他措施，责成服务提供者对本条规定的任何权力的行使情况以及与之相关的任何信息保守秘密。 第三十条 拦截内容数据\n一、各缔约国均应 采取必要的立法措施和其他措施 ，针对拟由本国法律确定的一系列严重刑事犯罪，授权其主管机关采取下列行动： ㈠ 在本国领土内应用技术手段实时收集或记录；以及 ㈡ 强令服务提供者在其现有的技术能力范围内：\n在本国领土内应用技术手段实时收集或记录；或者 配合并协助主管机关实时收集或记录；在其领土内使用信息通信技术系统传输的特定通信的内容数据。二、 缔约国因其本国法律制度原则而无法采取本条第一款第 ㈠项所述措施的，可采取必要的立法措施 和其他措施，确保在其领土内应用技术手段实时收集或记录其领土内特定通信的内容数据。三、各缔约国均应采取必要的立法措施和其他措施，责成服务提供者对本条规定的任何权力的行使情况以及与之相关的任何信息保守秘密。 第三十一条 冻结、扣押和没收犯罪所得\n一、各缔约国均应在本国法律制度的范围内尽最大可能采取必要措施，以便得以没收： ㈠ 根据本公约确立的犯罪所产生的犯罪所得或者价值与此类所得相当的财产； ㈡ 在根据本公约确立的犯罪 中使用或预备使用 的财产、设备或者其他工具。二、各缔约国均应采取必要措施，促成识别、追查、冻结或扣押本条第一款所述任何物项，以便最终予以没收。三、各缔约国均应根据本国法律采取必要的立法措施和其他措施，规范主管机关对本条第一款和第二款涵盖的已冻结、扣押或没收的财产的管理。四、如果犯罪所得已部分或全部转变或转化为其他财产，则应当以此类财产代替犯罪所得，适用本条所述措施。五、如果犯罪所得已与从合法来源获得的财产相混合，则应当在不影响与冻结或扣押有关的任何权力的情况下没收该等财产，没收价值不超过混合于其中的犯罪所得的估定价值。六、对于犯罪所得产生的、犯罪所得转变或者转化而成的财产产生的或者已经混合了犯罪所得的财产产生的收入或者其他收益，亦应适用本条所述措施，处置方式和程度与处置犯罪所得相同。七、为本公约本条和第五十条之目的，各缔约国均应授权其法院或其他主管机关下令提供或扣押银行记录、财务记录或商业记录。缔约国不得以银行保密为由拒绝按照本款规定采取行动。八、各缔约国均可考虑能否要求由犯罪人证明涉嫌犯罪所得或应予没收的其他财产具有合法来源，但此类要求应当符合本国法律原则以及司法程序和其他程序的性质。九、不得对本条的规定作损害善意第三方权利的解释。十、本条的任何规定均不得影响以下原则：即本条所述各项措施应当依照缔约国的本国法律规定予以界定和实施。\n第三十二条 建立犯罪记录\n各缔约国均可采取必要的立法措施或其他措施，按其认为适宜的条件并为其认为适宜的目的，考虑别国此前对被指控犯罪人作出的任何有罪判决，以便在涉及根据本公约确立的犯罪的刑事诉讼中利用此类信息。\n第三十三条 保护证人\n一、各缔约国均应根据本国法律并在力所能及的范围内采取适当措施，有效保护那些针对根据本公约确立的犯罪提供证言或本着善意和基于合理理由提供信息或以其他方式与侦查机关或司法机关配合的证人，并酌情有效保护其亲属和其他与其关系密切的人，以使他们免遭可能的报复或恐吓。二、在无损于被告人包括其正当程序权在内的权利的情况下，本条第一款所述措施可特别包括： ㈠ 制定向此类人员提供人身保护的程序，例如在必要和可行时将其转移，并在适当情况下允许不披露或限制披露有关其身份和行踪的资料； ㈡ 制定允许证人以确保其安全的方式作证的取证规则，例如允许借助于视频链接等通信技术或其他适当手段提供证言。三、缔约国应当考虑与其他国家订立有关转移本条第一款所述人员的协议或安排。四、本条的规定亦应适用于作为证人的受害人。某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24319/43 24-24621\n第三十四条 帮助和保护受害人\n一、各缔约国均应在其力所能及的范围内采取适当措施，向根据本公约确立的犯罪的受害人提供帮助和保护，尤其是在其受到报复威胁或恐吓的情况下。二、 各缔约国均应在符合本国法律的情况下制定适当的程序，使根据本公约确立的犯罪的受害人有机会获得赔偿和补偿。三、各缔约国均应在符合本国法律的情况下，在对犯罪人提起的刑事诉讼的适当阶段，以不损害犯罪人的辩护权的方式使受害人的意见和关切得到表达和考虑。四、对于根据本公约第十四条至第十六条确立的犯罪，各缔约国均应在符合本国法律的情况下采取措施，与相关国际组织、非政府组织和其他民间社会团体合作，向此类犯罪的受害人提供帮助，包括使其身心得到康复。五、 各缔约国在适用本条第二款至第四款的规定时，均应考虑到受害人的年龄、性别以及特殊情况和需要，包括儿童的特殊情况和需要。六、 各缔约国均应在本国法律框架允许的限度内采取有效步骤，确保遵从关于移除本公约第十四条和第十六条中所指内容或使之无法访问的请求。\n第五章 国际合作 第三十五条 国际合作的一般原则\n一、 缔约国应当依照本公约的规定以及关于刑事事项国际合作的其他适用国际文书以及本国法律，为下列目的开展合作： ㈠ 对根据本公约确立的刑事犯罪进行的侦查、起诉和与之相关的司法程序，包括对此类犯罪所得的冻结、扣押、没收和返还； ㈡ 收集、获取、保全和共享根据本公约确立的刑事犯罪的电子证据； ㈢ 收集、获取、保全和共享任何严重犯罪的电子证据，包括根据本公约通过时有效的其他适用的联合国公约和议定书所确立的严重犯罪。二、 按本条第一款第 ㈡项和第㈢项的规定收集、获取、保全和共享犯罪电子证据的，应当适用本公约第四十条有关款项以及第四十一至第四十六条。三、 在国际合作事项上，凡将双重犯罪视作一项条件的，如果在协助请求中所指的犯罪行为在请求缔约国和被请求缔约国的法律中均属刑事犯罪，则此项条件即应视作已得到满足，而不论这两个缔约国各自的法律是否均将此种犯罪列入相同的犯罪类别或者是否使用相同的术语指称此种犯罪。\n第三十六条 保护个人数据\n一、㈠ 缔约国在根据本公约转移个人数据时，应当遵守本国法律以及适用的国际法所规定的任何转移方义务。缔约国依照关于保护个人数据的有关法律不能提供个人数据的，不应要求该缔约国按照本公约转移个人数据； ㈡ 个人数据转移不符合本条第一款第 ㈠项的，缔约国可根据适用法律寻求施加适当条件以实现合规性，以便对索取个人数据的请求作出回应； ㈢ 鼓励缔约国订立双边或多边安排，以期便利个人数据的转移。二、 对于根据本公约转移的个人数据，缔约国应当确保所收到的个人数据在缔约国各自的法律框架内得到有效而适当的保障。三、 为能将根据本公约获得的个人数据转移到第三国或某一国际组织，缔约国应当将其意图通知原转移缔约国并请求其为此授权。缔约国只有在原转移缔约国予以授权的情况下才可转移此类个人数据，原转移缔约国可要求以书面形式提供此种授权。\n第三十七条 引渡\n一、本条应当适用于根据本公约确立的刑事犯罪，条件是被请求引渡人位于被请求缔约国领土内，且寻求引渡所涉犯罪根据请求缔约国和被请求缔约国的本国法律均为可惩处的犯罪。如果请求引渡的目的是执行对可引渡犯罪判处的最终监禁或其他形式的拘禁，则被请求缔约国可依据本国法律准予引渡。二、虽有本条第一款的规定，缔约国在本国法律允许的情况下，可准予引渡犯有根据本公约确立的任何刑事犯罪、但依照本国法律不予惩处的人员。三、如果引渡请求包括几项独立的刑事犯罪，其中至少有一项犯罪可以依照本条规定予以引渡，而其中几项犯罪由于监禁期的原因不可引渡、但却与根据本公约确立的犯罪有关，则被请求缔约国也可对这些犯罪适用本条的规定。四、本条适用的各项犯罪均应视作已列入缔约国之间现行任何引渡条约的可引渡犯罪。缔约国承诺将此类犯罪作为可引渡犯罪列入在它们之间将要缔结的每一项引渡条约。五、以订有条约为引渡条件的缔约国，如果接到未与之订有引渡条约的另一缔约国的引渡请求，则可将本公约视为对本条所适用的任何犯罪予以引渡的法律依据。六、以订有条约为引渡条件的缔约国应当： ㈠ 在交存本公约的批准书、接受书、核准书或加入书时通知联合国秘书长，说明其是否将以本公约为法律依据与本公约其他缔约国进行引渡合作；并且某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24321/43 24-24621 ㈡ 如其不以本公约作为引渡合作的法律依据，则在适当情况下寻求与本公约其他缔约国缔结引渡条约，以实施本条规定。七、不以订有条约为引渡条件的缔约国应当承认本条所适用的犯罪为它们之间可以相互引渡的犯罪。八、引渡应当符合被请求缔约国的本国法律或适用的引渡条约所规定的条件，其中包括与引渡的最低刑罚要求有关的条件以及被请求缔约国可据以拒绝引渡的理由。九、对于本条所适用的任何犯罪，缔约国应当在符合本国法律的情况下，努力加快引渡程序并简化与之相关的证据要求。十、被请求缔约国在不违背本国法律和引渡条约规定的情况下，可以在认定情况必要而且紧迫时，根据请求缔约国的请求，包括通过国际刑事警察组织现有渠道转交的 请求，拘留位于其领土内的被请求引渡人，或者采取其他适当措施，确保该人在进行引渡程序时在场。十一、如果被指控罪犯被发现位于某一缔约国领土内而该国仅以该人系本国国民为理由不就本条所适用的犯罪予以引渡，则该国有义务在寻求引渡的缔约国提出请求时将该案提交本国主管机关以便进行起诉，而不得有任何不当延误。这些机关作出决定和进行诉讼程序的方式应当与根据该缔约国本国法律对性质相当的其他任何犯罪采用的方式相同。有关缔约国应当相互合作，特别是在程序和证据方面相互合作，以确保这些起诉的效率。十二、如果缔约国本国法律允许引渡或移交本国国民的条件是，须将该人送还本国按照引渡或移交请求所涉审判或诉讼作出的判决服刑，且该缔约国和寻求引渡该人的缔约国均同意这一选择以及双方可能认为适宜的其他条件，则此种有条件的引渡或移交即足以解除该缔约国根据本条第十一款所承担的义务。十三、如果为执行判决而提出的引渡请求因被请求引渡人员系被请求缔约国的国民而遭到拒绝，则被请求缔约国应当在本国法律允许且符合该法律的要求的情况下，根据请求缔约国的申请，考虑执行根据请求国本国法律判处的刑期或尚未服满的刑期。十四、在对任何人员就本条所适用的任何犯罪提起诉讼时，应当确保其在诉讼的所有阶段得到公平待遇，包括享有其所在缔约国本国法律所提供的一切权利和保障。十五、如果被请求缔约国有充分理由认为提出引渡请求是为了以某人的性别、种族、语言、宗教、国籍、族裔或政治观点为由对其进行起诉或惩处，或如果执行该请求将会使该人的地位因上述任一原因而受到损害，则本公约的任何 规定均不得解释为强制规定了引渡义务。十六、缔约国不得仅以犯罪亦被视为涉及财税事项为由而拒绝引渡请求。十七、被请求缔约国在拒绝引渡之前应当酌情与请求缔约国磋商，以使其有充分机会陈述自己的意见和提供与其指控有关的资料。十八、被请求缔约国应当将其关于引渡的决定通知请求缔约国。被请求缔约国应告知请求缔约国拒绝引渡的任何理由，除非被请求缔约国的本国法律或其国际法律义务不允许其作出此种告知。十九、各缔约国均应在签署本公约时或在交存其批准书、接受书、核准书或加入书时，告知联合国秘书长负责提出或接收引渡请求或临时逮捕请求的机关的名称和地址。秘书长应当建立并不断更新缔约国所指定的此类机关的登记册。各缔约国均应确保登记册上登记的详细信息始终正确无误。二十、缔约国应当力求缔结双边和多边协定或安排，以执行引渡或加强引渡的成效。\n第三十八条 被判刑人员的移管\n缔约国可考虑缔结双边或多边协定或安排，将因实施根据本公约确立的犯罪而被判处监禁或以其他形式被剥夺自由的人员移交其本国服满刑期，同时考虑到被判刑人员的权利。缔约国还可考虑与此类人员的意愿、改造和重返社会有关的问题。\n第三十九条 刑事诉讼的移交\n一、如果缔约国认为移交诉讼有利于正当司法，特别是在涉及数国管辖权时，为了进行集中起诉，应当考虑相互移交诉讼的可能性，以便对根据本公约确立的犯罪进行刑事诉讼。二、以订有条约为移交刑事诉讼条件的缔约国，如果收到未与之在此事项上订有条约的另一缔约国的移交请求，可以本公约为法律依据移交对本条所适用的任何犯罪的刑事诉讼。\n第四十条 司法协助的一般原则和程序\n一、缔约国应当在与根据本公约确立的犯罪有关的侦查、起诉和司法程序中，以及在收集根据本公约确立的犯罪和其他严重犯罪的电子证据方面，相互提供最广泛的司法协助。二、对于请求缔约国根据本公约第十八条可能追究法人责任的犯罪进行的侦查、起诉和司法程序，应当根据被请求缔约国的有关法律、条约、协定和安排，尽可能充分地提供司法协助。三、 可为下列任何目的请求根据本条提供司法协助： ㈠ 向个人获取证据或陈词；某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24323/43 24-24621 ㈡ 送达司法文书； ㈢ 执行搜查和扣押，以及冻结； ㈣ 根据本公约第四十四条搜查或以类似方式访问、扣押或以类似方式获取和披露使用信息通信技术系统存储的电子数据； ㈤ 根据本公约第四十五条实时收集流量数据； ㈥ 根据本公约第四十六条拦截内容数据； ㈦ 检查物品和场所； ㈧ 提供资料、证据以及专家鉴定意见； ㈨ 提供有关文件和记录的原件或经核证的副本，其中包括政府、银行、财务、公司或业务的记录； ㈩ 为取证目的而辨认或追查犯罪所得、财产、工具或其他物项；(十一) 为有关人员自愿前往请求缔约国出庭提供方便；(十二) 追回犯罪所得；(十三) 不违反被请求缔约国本国法律的任何其他类型的协助。四、缔约国主管机关如认为与刑事事项有关的资料可能有助于另一缔约国主管机关进行或顺利完成调查和刑事诉讼程序，或可以促成该另一缔约国根据本公约提出请求，则可在不违反本国法律的情况下，无需事先请求而向该缔约国主管机关传送此类资料。五、根据本条第四款传送资料时，不应当影响提供资料的主管机关所属国的侦查和刑事诉讼程序。接收资料的主管机关应当遵守对该资料进行保密的要求，即便是暂时予以保密，或遵守对资料的使用的限制规定。但这不应妨碍接收方缔约国在其诉讼中披露可证明被控告人无罪的资料。在此种情况下，接收方缔约国应当在披露之前通知提供方缔约国，而且，如有要求，还应当就此与提供方缔约国进行协商。如果在特殊情况下无法事先通知，则接收方缔约国应当毫不迟延地将披露一事通报提供方缔约国。六、本条各项规定概不影响规范或将要规范整个或部分司法协助事宜的任何其他双边或多边条约所规定的义务。七、如果有关缔约国无司法协助条约的约束，则本条第八款至第三十一款应当适用于根据本条提出的请求。如果有关缔约国有此类条约的约束，则适用条约的相应条款，除非这些缔约国同意代之以适用本条第八款至第三十一款。大力鼓励缔约国在这几款有助于开展合作时予以适用。八、缔约国可以不构成双重犯罪为由拒绝依照本条提供协助。但被请求缔约国可在其认为适当时在其斟酌决定的范围内提供协助，而不论所涉行为按被请求缔约国本国法律是否构成犯罪。如果请求所涉事项性质极为轻微或所寻求的合作或协助可以依照本公约其他条款获得，则被请求缔约国可拒绝提供协助。九、 在一缔约国领土内被羁押或服刑的人员，如果被要求前往另一缔约国进行辨认、作证或者提供其他协助，以便为与根据本公约确立的犯罪有关的侦查、起诉或者司法程序获取证据，则在满足下列条件的情况下，可予以移送： ㈠ 该人在知情后自由表示同意； ㈡ 双方缔约国主管机关均同意，但须符合这些缔约国认为适当的条件。十、就本条第九款而言： ㈠ 该人被移送前往的缔约国应当有权力和义务羁押被移送人，除非移送缔约国另有要求或授权； ㈡ 该人被移送前往的缔约国应当毫不迟延地履行义务，按照双方缔约国主管机关事先达成的协议或其他协议，将该人交还移送缔约国羁押； ㈢ 该人被移送前往的缔约国不得要求移送缔约国为该人的交还而启动引渡程序； ㈣ 被移送人在被移送前往的缔约国的羁押时间应当折抵其在移送国执行的刑期。十一、除非依照本条第九款和第十款移送某人的缔约国同意，否则无论该人国籍为何，均不得因其离开被请求缔约国之前的作为、不作为或被定罪而在请求缔约国领土内被起诉、羁押、处罚，或在其自由方面受到任何其他限制。十二、㈠ 各缔约国均应指定一个或多个中央机关，由其负责且有权接收司法协助请求并执行请求或将请求转交主管机关执行。如果缔约国有实行单独司法协助制度的特区或者领土，则可为该特区或领土另外指定一个具有同样职能的中央机关； ㈡ 中央机关应当确保所收到的请求得到迅速而妥善的执行或转交。中央机关在将请求转交某一主管机关执行时，应鼓励该主管机关迅速而妥善地执行请求； ㈢ 各缔约国均应在交存本公约的批准书、接受书、核准书或加入书时将为此目的指定的中央机关通知联合国秘书长；秘书长应建立并不断更新缔约国所指定的中央机关登记册。各缔约国均应确保登记册上登记的详细信息始终正确无误； ㈣ 司法协助请求以及与之相关的任何函件均应递交缔约国指定的中央机关。此项规定不得损害缔约国要求通过外交渠道以及在紧急和可能的情况下经有关缔约国同意通过国际刑事警察组织向其传送此种请求和函件的权利。某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24325/43 24-24621十三、请求应当以被请求缔约国所能接受的语文以书面形式提出，或在可能情况下以能够生成书面记录的任何手段提出，但须能使该缔约国得以鉴定其真实性。各缔约国均应在交存本公约的批准书、接受书、核准书或者加入书时将其所能接受的一种或多种语文通知联合国秘书长。在紧急情况下，如经有关缔约国同意，请求可采用口头方式提出，但应立即加以书面确认。十四、鼓励缔约国中央机关在本国法律未予禁止的情况下，以电子形式传送和接收司法协助请求书、与之相关的函件以及证据，但条件是须允许被请求缔约国确定其真实性并确保通讯安全。十五、司法协助请求书中应当列明如下各项： ㈠ 提出请求的机关； ㈡ 请求所涉及的侦查、起诉或司法程序的事由和性质，以及负责进行该项侦查、起诉或司法程序的机关的名称和职能； ㈢ 有关事实的概述，但为送达司法文书提出的请求除外； ㈣ 说明所请求的协助以及请求缔约国希望得到遵循的特定程序细节； ㈤ 在可能且适当的情况下，任何有关人员的身份、所在地和国籍，以及任何有关物项或账户的来源国、说明和所在地； ㈥ 在适用情况下，请求提供证据、资料或其他协助的时间段；以及 ㈦ 请求提供证据、资料或其他协助的目的。十六、被请求缔约国可要求提供按照其 本国法律执行该请求所必需的或有助于执行该请求的补充资料。十七、请求应根据被请求缔约国本国法律执行，在不违反被请求缔约国本国法律的情况下，如有可能，应当遵循请求书中所列明的程序执行。十八、当位于某一缔约国领土内的某人需作为证人、受害人或鉴定专家接受另一缔约国司法机关询问，且该人不可能或不宜亲身前往请求缔约国领土内时，被请求缔约国可根据该另一缔约国的请求，在可能且符合其本国法律的基本原则的情况下，允许以视频会议方式进行询问。缔约国可商定由请求缔约国司法机关进行询问，且询问时应有被请求缔约国司法机关在场。如果被请求缔约国无法获得举行视频会议所需的技术手段，则可共同商定由请求缔约国提供此种手段。十九、未经被请求缔约国事先同意，请求缔约国不得将被请求缔约国提供的资料或证据转交或用于请求书所述以外的侦查、起诉或司法程序。本款中的任何规定均不妨碍请求缔约国在其诉讼中披露可证明被告人无罪的资料或证据。就后一种情形而言，请求缔约国应当在予以披露之前通知被请求缔约国，并依请求与被请求缔约国磋商。如在特殊情况下无法事先通知，则请求缔约国应当毫不迟延地将披露一事通告被请求缔约国。二十、请求缔约国可要求被请求缔约国对其所提出的请求及其内容予以保密，但为执行请求所必需时除外。如果被请求缔约国不能遵守保密要求，则应当立即就此通知请求缔约国。二十一、在下列情形中可拒绝提供司法协助： ㈠ 请求未按本条的规定提出； ㈡ 被请求缔约国认为执行请求可能损害其主权、安全、公共秩序或其他基本利益； ㈢ 假如被请求缔约国主管机关依其管辖权对任何类似犯罪进行侦查、起诉或司法程序，其本国法律将会禁止该主管机关对此类犯罪采取被请求的行动； ㈣ 若同意此种请求，将会违反被请求缔约国关于司法协助的法律制度。二十二、如果被请求缔约国有充分理由认为提出请求是为了以某人的性别、种族、语言、宗教、国籍、族裔或政治观点为由对其进行起诉或惩处，或认为满足该请求将使该人的地位因上述任一原因而受到损害，则本公约的任何规定均不得解释为强制规定了提供司法协助的义务。二十三、缔约国不得仅以犯罪亦被视为涉及财税事项为由而拒绝司法协助请求。二十四、缔约国不得以银行保密为由拒绝根据本条提供司法协助。二十五、拒绝司法协助时应当说明理由。二十六、被请求缔约国应当尽快执行司法协助请求，并应尽可能充分考虑到请求缔约国提出的、最好能在请求中说明了理由的任何最后期限。被请求缔约国应当依请求缔约国的合理要求就请求的当前状态及其处理请求的进展情况作出答复。请求缔约国应当在其不再需要被请求国提供所寻求的协助时迅速通知被请求缔约国。二十七、被请求缔约国可以司法协助会妨碍正在进行的侦查、起诉或司法程序为由而暂缓执行。二十八、在根据本条第二十一款拒绝某项请求或根据本条第二十七款暂缓执行请求事项之前，被请求缔约国应当与请求缔约国协商，考虑是否可在其认为必要的条款和条件下给予协助。请求缔约国如果接受附有条件限制的协助，则应遵守这些条件。二十九、在不影响适用本条第十一款的情况下，根据请求缔约国的请求而同意前往请求缔约国领土内就某项诉讼作证或为某项侦查、起诉或司法程序提供协助的证人、鉴定专家或其他人员，不得因其离开被请求缔约国之前的作为、不作为或定罪而在请求缔约国领土内被起诉、羁押、处罚，或在其自由方面受到任何其他限制。如该证人、鉴定专家或其他人员已得到司法机关不再需要其到某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24327/43 24-24621场的正式通知，在自通知之日起连续十五天内或在所涉缔约国所商定的任何期限内，有机会离开但仍自愿留在请求缔约国领土内，或在离开该领土后又自愿返回，则此项安全通行权即不再有效。三十、除非所涉缔约国另有协议，执行请求的一般费用应当由被请求缔约国承担。如执行请求需要或将需要支付大笔或特殊性质的费用，则应由这些缔约国进行协商，以确定执行相关请求的条款和条件以及费用承担办法。三十一、被请求缔约国： ㈠ 应当向请求缔约国提供其所拥有的、依其本国法律可向公众公开的政府记录、文件或资料的副本； ㈡ 可自行斟酌决定全部或部分地或按其认为适当的条件向请求缔约国提供其所拥有的、依其本国法律不可向公众公开的任何政府记录、文件或资料的副本。三十二、缔约国应视需要考虑能否缔结有助于实现本条之目的、具体实施或旨在加强本条各项规定的双边或多边协定或安排。\n第四十一条 7 天 24 小时全天候网络\n一、各缔约国均应指定一个每周 7 天、每天 24 小时开放的联络点，以确保为就根据本公约确立的犯罪的具体刑事侦查、起诉或司法程序提供即时协助，或为本条第三款之目的以及就根据本公约确立的犯罪和其他严重犯罪即时协助收集、获取、保全电子证据。二、应将此种联络点通知联合国秘书长，秘书长应保存一份为本条目的指定的联络点的最新登记册，并应每年向缔约国分发经过更新的联络点名册。三、 此种协助应当包括促进或在被请求缔约国的本国法律和惯例允许的情况下直接采取以下措施： ㈠ 提供技术咨询； ㈡ 依照本公约第四十二条和第四十三条保全所存储的电子数据，酌情包括被请求缔约国掌握的服务提供者所在地信息，以协助请求缔约国提出协助请求； ㈢ 收集证据和提供法律信息； ㈣ 确定嫌疑人所在地；或 ㈤ 提供电子数据以防发生紧急情况。四、缔约国的联络点应当有能力与另一缔约国的联络点进行快捷通信联络。若缔约国所指定的联络点不隶属于该缔约国负责司法协助或引渡事宜的一个或多个机关，则该联络点应当确保能够快捷地与此类机关进行协调。五、各缔约国均应确保能够提供训练有素且装备齐全的人员，以确保 7 天 24 小时全天候网络的运作。六、缔约国亦可在本国法律的限度内酌情利用和加强现有经授权的联络点网络，包括国际刑事警察组织的用于开展警方之间快捷合作的 7 天 24 小时全天候计算机相关犯罪问题网络以及其他信息交流合作办法。\n第四十二条 快速保全存储的电子数据方面的国际合作\n一、一缔约国有意提出司法协助请求以搜查或以类似方式访问、扣押或以类似方式获取或披露在另一缔约国领土内使用信息通信技术系统存储的电子数据的，可请该另一缔约国根据本公约第二十五条下令或以其他方式实现快速保全该电子数据。二、请求缔约国可利用本公约第四十一条规定的 7 天 24 小时全天候网络，查找使用信息通信技术系统存储的电子数据所在地信息，并酌情查找服务提供者所在地信息。三、根据本条第一款提出的保全请求应当具体说明： ㈠ 寻求保全的机关； ㈡ 作为刑事侦查、起诉或司法程序事由的犯罪以及对相关事实的简要概述； ㈢ 拟予保全的已存储电子数据及其与犯罪之间的关系； ㈣ 所掌握的用以识别存储的电子数据保管人身份或信息通信技术系统所在位置的任何信息； ㈤ 进行保全的必要性； ㈥ 请求缔约国有意提交司法协助请求，以搜查或以类似方式访问、扣押或以类似方式获取或者披露所存储的电子数据； ㈦ 酌情说明需要对保全请求保密且不通知所涉用户。四、被请求缔约国收到另一缔约国的请求后，应当根据本国法律采取一切适当措施，快速保全所指定的电子数据。在回应请求时，被请求缔约国不得以构成双重犯罪作为提供此种保全的条件。五、缔约国要求以双重犯罪为条件才能回应关于搜查或以类似方式访问、扣押或以类似方式获取或披露所存储的电子数据的司法协助请求的，对于根据本公约所确立犯罪以外的犯罪，如果有理由认为披露时无法满足双重犯罪的条件，则可保留拒绝根据本条提出的保全请求的权利。六、此外，只能根据本公约第四十条第二十一款第㈡和第㈢项以及第二十二款所列述的理由拒绝保全请求。某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24329/43 24-24621七、如果被请求缔约国认为实行保全将无法确保相关数据今后可用，或将威胁到请求缔约国侦查工作的保密性，或将以其他方式妨碍请求缔约国进行的侦查，则该缔约国应当立即将此情况通知请求缔约国，由请求缔约国随后决定是否仍然执行该请求。八、按本条第一款所述请求实行的任何保全应当维持一个不短于六十天的时期，以便使请求缔约国得以提出请求搜查或以类似方式访问、扣押或以类似方式获取或披露相关数据。被请求缔约国在收到此种请求后，应当在就该请求作出决定之前继续保全所涉数据。九、在本条第八款规定的保全期限届满之前，请求缔约国可请求延长保全期限。\n第四十三条 快速披露所保全的流量数据方面的国际合作\n一、被请求缔约国在执行根据本公约第四十二条提出的保全某一特定通信相关流量数据的请求过程中，若发现另一缔约国的服务提供者参与了该通信的传输，则应迅速向请求缔约国披露足够的流量数据以识别该服务提供者和通信传输路径。二、只能根据本公约第四十条第二十一款第㈡项和第㈢项以及第二十二款所列述的理由拒绝按本条第一款的规定披露流量数据。\n第四十四条 访问存储的电子数据方面的司法协助\n一、一缔约国可请求另一缔约国搜查或以类似方式访问、扣押或以类似方式获取并披露使用位于被请求缔约国领土内的信息通信技术系统存储的电子数据 ，包括根据本公约第四十二条保全的电子数据。二、被请求缔约国应当适用本公约第三十五条所述相关国际文书和法律，并根据本章其他相关规定，对此种请求作出回应。三、在下列情况下，应当迅速对请求作出回应： ㈠ 有理由认为相关数据特别容易丢失或被修改；或 ㈡ 本条第二款中提及的文书和法律对加快合作另有规定。\n第四十五条 实时收集流量数据方面的司法协助\n一、缔约国应当努力相互提供司法协助，实时收集与本国领土内 使用信息通信技术系统传输的某些指定通信有关的流量数据。在不违反本条第二款规定的情况下，此种协助应受本国法律规定的条件和程序制约。二、 各缔约国均应努力至少针对在本国内类似案件中可实时收集流量数据的刑事犯罪提供此种协助。三、 根据本条第一款提出的请求应当具体说明： ㈠ 提出请求的机关名称； ㈡ 与请求有关的侦查、起诉或司法程序的主要事实和性质概述； ㈢ 要求收集的流量数据所涉及的电子数据及其与相关犯罪行为之间的关系； ㈣ 所掌握的用以识别数据所有人或用户身份或信息通信技术系统所在地的任何数据； ㈤ 要求收集流量数据的理由； ㈥ 拟收集流量数据的期间及相应的理由。\n第四十六条 拦截内容数据方面的司法协助\n缔约国应当在对其适用的条约或本国法律允许的范围内，彼此努力提供司法协助，以实时收集或记录使用信息通信技术系统传输的特定通信的内容数据。\n第四十七条 执法合作\n一、 缔约国应当在符合本国法律制度和行政管理制度的情况下相互密切合作，以期加强打击根据本公约确立的犯罪的执法行动成效。缔约国尤其应当采取有效措施，以便： ㈠ 加强并于必要时建立其主管机关、机构和部门之间的联络渠道，同时考虑到国际刑事警察组织的渠道等现有渠道，以促进安全而迅速地交换有关根据本公约确立的犯罪的各方面信息，在有关缔约国认为适当时还可包括与其他犯罪活动的关联的信息； ㈡ 同其他缔约国合作，就与根据本公约确立的犯罪有关的以下事项进行调查：\n参与此类犯罪的嫌疑人的身份、行踪和活动，或其他有关人员的所在地； 源自此类犯罪的犯罪所得或财产的去向； 用于或企图用于实施此类犯罪的财产、设备或其他工具的去向； ㈢ 酌情提供必要的物项或数据以供分析或侦查之用； ㈣ 酌情与其他缔约国交流关于为实施根据本公约确立的犯罪而采用的具体手段和方法的信息，包括利用虚假身份、经伪造、变造或者假冒的证件和其他掩饰的手段以及网络犯罪伎俩、技术和程序诸方面的信息；某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24331/43 24-24621 ㈤ 便利在各缔约国主管机关、机构和部门之间开展有效协调，并促进 交流人员和其他专家，包括在符合有关缔约国之间的双边协定或安排的情况下派驻联络官员； ㈥ 为尽早查明根据本公约确立的犯罪而酌情交流信息和协调所采取的行政措施及其他措施。二、为实施本公约，缔约国应当考虑订立其执法机构间直接合作的双边或多边协定或安排；已有此类协定或安排的，应当考虑加以修订。如果有关缔约国之间没有此类协定或安排，则可考虑以本公约为依据，针对根据本公约确立的犯罪开展执法合作。在适当情况下，缔约国应当充分利用各种协定或安排，包括利用国际组织或区域组织，以加强执法机构之间的合作。 第四十八条 联合侦查\n缔约国应当考虑缔结双边或多边协定或安排，以便有关主管机关可据以就根据本公约确立的，且在一国或多国成为刑事侦查、起诉或司法程序对象的犯罪建立联合侦查机构。如无此类协定或安排，则可在个案基础上商定开展联合侦查。拟在一缔约国领土内开展此类侦查的，相关缔约国应当确保该缔约国的主权得到充分尊重。\n第四十九条 通过没收事宜国际合作追回财产的机制\n一、为根据本公约第五十条针对通过实施或参与实施 根据本公约确立的犯罪而获得的财产提供司法协助，各缔约国均应根据本国法律： ㈠ 采取必要措施，准许本国主管机关执行另一缔约国法院签发的没收令； ㈡ 采取必要措施，准许本国拥有管辖权的主管机关通过对洗钱罪或可能在其管辖范围内的其他犯罪作出判决，或者经由本国法律许可的其他程序，下令没收外国来源的此类财产；以及 ㈢ 考虑采取必要措施，允许在因为犯罪人死亡、潜逃或者缺席而无法对其进行起诉的情形或者其他适当情形下，不经过刑事定罪而没收此类财产。二、为针对依照本公约第五十条第二款提出的请求提供司法协助，各缔约国均应根据本国法律： ㈠ 采取必要措施，准许本国主管机关根据请求缔约国的法院或主管机关发出的冻结令或扣押令冻结或扣押财产，但条件是该冻结令或扣押令须提供合理的依据，使被请求缔约国相信有充足理由采取此种行动，并且相信有关财产最终将依照本条第一款第㈠项所述的没收令予以处理； ㈡ 采取必要措施，准许本国主管机关根据请求冻结或扣押财产，但条件是该请求须提供合理的依据，使被请求缔约国相信有充足理由采取此种行动，并且相信有关财产最终将依照本条第一款第㈠项所述的没收令予以处理；以及 ㈢ 考虑采取额外措施，准许本国主管机关诸如根据外国实行的与财产的获取有关的逮捕或刑事指控等，对此类财产进行保全，以便予以没收。\n第五十条 没收事宜的国际合作\n一、 缔约国在收到对根据本公约确立的一项犯罪拥有管辖权的另一缔约国关于没收本公约第三十一条第一款所述位于其领土内的犯罪所得、财产、设备或其他工具的请求后，应当在本国法律制度的范围内尽最大可能： ㈠ 将该请求提交本国主管机关，以便获取没收令并在获取没收令后予以执行；或 ㈡ 将请求缔约国的法院根据本公约第三十一条第一款签发的没收令提交本国主管机关，以便按请求的范围予以执行，只要该没收令涉及的犯罪所得、财产、设备或其他工具位于被请求缔约国领土内。二、 被请求缔约国应当按照对根据本公约确立的一项犯罪拥有管辖权的另一缔约国提出的请求采取措施，辨认、追查和冻结或扣押本公约第三十一条第一款所述的犯罪所得、财产、设备或其他工具，以便最终由请求缔约国下令或由被请求缔约国根据本条第一款依照请求下令予以没收。三、 本公约第四十条的规定经适当变通后可适用于本条。根据本条提出的请求除应包括本公约第四十条第十五款所规定的资料外，还应包括以下内容： ㈠ 与本条第一款第㈠项有关的请求，应当包括对应予没收的财产的说明，尽可能包括财产的所在地，酌情包括对财产的估计价值，以及对请求缔约国所依据的事实的充分陈述，以便被请求缔约国得以根据本国法律申请没收令； ㈡ 与本条第一款第㈡项有关的请求，应当包括请求缔约国签发的据以提出请求的、法律上可以采信的没收令副本、与请求所述没收令执行范围有关的事实和信息陈述、关于请求缔约国为向善意第三方提供充分通知并确保正当程序而采取的措施的具体陈述，以及关于该没收令已不可更改的声明； ㈢ 与本条第二款有关的请求，应当包括对请求缔约国所依据的事实的陈述和对所请求采取的行动的说明；如有据以提出请求的、法律上可以采信的没收令副本，应当一并附上。四、被请求缔约国依照本条第一款和第二款作出的决定或采取的行动，应当符合且遵循本国法律及程序规则的规定，或符合且遵循可能在与请求缔约国有关的事项上对其具有约束力的任何双边或多边条约、协定或安排的规定。某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24333/43 24-24621五、各缔约国均应向联合国秘书长提供本国实施本条的法律法规的副本，以及此类法律法规随后的任何修订的副本或相关说明。六、缔约国选择以订有相关条约为条件采取本条第一款和第二款所述措施的，应当将本公约视为必要而充分的条约依据。七、如果被请求缔约国未收到充分和及时的证据，或者如果财产的价值极其轻微，也可拒绝给予本条所规定的合作，或者解除临时措施。八、在解除依照本条采取的任何临时措施之前，如有可能，被请求缔约国应当给予请求缔约国机会说明继续保持该措施的理由。九、不得对本条规定作损害善意第三方权利的解释。十、缔约国应当考虑缔结双边或多边条约、协定或安排，以提高根据本条开展的国际合作的成效。\n第五十一条 特别合作\n在不违反本国法律的情况下，各缔约国均应努力采取措施，以便在认为披露根据本公约确立的犯罪所得的资料可有助于接收资料的缔约国启动或进行刑事侦查、起诉或者司法程序时，或在认为可能会使该缔约国根据本公约第五十条提出请求时，得以在不损害本国刑事侦查、起诉或者司法程序的情况下，无须事先请求而向该另一缔约国转发此类资料。\n第五十二条 没收的犯罪所得或财产的返还和处置\n一、缔约国依照本公约第三十一条或第五十条没收的犯罪所得或财产，应当由该缔约国根据本国法律和行政程序予以处置。二、缔约国根据本公约第五十条的规定依另一缔约国的请求采取行动时，应当在本国法律许可的范围内，根据请求，优先考虑将所没收的犯罪所得或财产返还请求缔约国，以便其对犯罪受害人进行赔偿，或者将此类犯罪所得或财产归还原合法所有人。三、缔约国根据本公约第三十一条和第五十条的规定依另一缔约国的请求采取行动时，可在适当考虑到对受害人进行赔偿后，特别考虑就下述事项缔结协定或安排： ㈠ 向根据本公约第五十六条第二款第㈢项指定的账户以及专门打击网络犯罪的政府间机构捐出与此类犯罪所得或财产等值的款项或变卖此类犯罪所得或财产而得到的资金或其中的一部分； ㈡ 根据本国法律或行政程序，定期或逐案与其他缔约国分享此类犯罪所得或财产，或变卖此类犯罪所得或财产而获得的资金。四、 在适当的情况下，除非缔约国另有决定，被请求缔约国可在依据本条规定返还或者处置没收的财产前，扣除为此进行侦查、起诉或司法程序而发生的合理费用。\n第六章 预防措施 第五十三条 预防措施\n一、各缔约国均应根据本国法律制度的基本原则，努力制定和实施或维持有效而协调的政策和最佳实践，通过适当的立法措施、行政措施或其他措施，减少现有或未来的网络犯罪机会。二、各缔约国均应根据本国法律的基本原则，在力所能及的范围内采取适当措施，促进相关个人及非政府组织、民间社会组织、学术机构和私营部门实体等公共部门以外的实体以及一般公众在各个相关方面积极参与预防根据本公约确立的犯罪。三、预防措施可包括： ㈠ 加强执法机构或检察官与相关个人以及非政府组织、民间社会组织、学术机构和私营部门实体等公共部门以外的实体之间的合作，以期在各个相关方面预防和打击根据本公约确立的犯罪； ㈡ 通过促进公众参与预防和打击此类犯罪的公共宣传活动、公共教育、媒体与信息素养方案和课程，使公众深入了解根据本公约确立的犯罪所构成的威胁的存在、原因和严重性； ㈢ 建设和努力提高本国刑事司法系统的能力，包括在刑事司法从业人员当中开展培训和培养其专门知识，以此作为针对根据本公约确立的犯罪的国家预防战略的一部分； ㈣ 鼓励服务提供者在可行情况下根据本国条件并在本国法律允许的限度内采取有效措施，加强服务提供者的产品、服务和客户的安全； ㈤ 承认安全研究人员在本国法律所允许的范围内和所规定的条件下，专门为加强和改善位于缔约国领土内的服务提供者的产品、服务和客户的安全而开展的合法活动所作的贡献； ㈥ 制定、促进和推广各种方案和活动，以阻止有可能参与网络犯罪的人员沦为罪犯，并培养其合法技能； ㈦ 努力促进被判犯有根据本公约确立的犯罪的人员重返社会； ㈧ 根据本国法律制定战略和政策，以预防和消除通过使用信息通信技术系统发生的性别暴力，并在制定预防措施时考虑到弱势群体的特殊境况和需求；某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24335/43 24-24621 ㈨ 采取因地制宜的具体努力，保证儿童安全上网，包括为此开展关于网上儿童性虐待或儿童性剥削问题的教育、培训和公众宣传，以及修订旨在预防此类问题的本国法律框架和增进此方面的国际合作，并努力确保快速删除儿童性虐待和性剥削材料； ㈩ 提高决策进程的透明度，促进公众对决策进程作出贡献，并确保公众有充分的机会获得信息；(十一) 尊重、促进和保护在寻求、接收和传递有关网络犯罪的公共信息方面的自由；(十二) 制定或加强对根据本公约确立的犯罪的受害人的援助方案；(十三) 预防和查明与根据本公约确立的犯罪有关的犯罪所得和财产的转移。四、各缔约国均应采取适当措施，酌情确保公众了解和能够联系到负责预防和打击网络犯罪的一个或多个相关主管机关，以便举报，包括匿名举报，可视作根据本公约确立的刑事犯罪的任何事件。五、缔约国应当努力定期评价现行的相关国家法律框架和行政实践，以便找出差距和不足之处，并确保这些法规和实践在应对根据本公约确立的犯罪所构成的不断变化的威胁时具有现实意义。六、缔约国可相互协作并与有关国际和区域组织协作，推行和制定本条所列述的措施，包括参与旨在预防网络犯罪的国际项目。七、各缔约国均应将可协助其他缔约国制定和实施预防网络犯罪的具体措施的一个或多个机关的名称和地址告知联合国秘书长。\n第七章 技术援助和信息交流 第五十四条 技术援助和能力建设\n一、缔约国应当根据各自的能力，考虑相互提供最广泛的技术援助和能力建设，包括培训和其他形式的援助，相互交流相关经验和专门知识，以及按照彼此商定的条款转让技术，同时特别考虑到发展中缔约国的利益和需要，以促进预防、监测、侦查和起诉本公约所涵盖的犯罪。二、缔约国应当在必要时为本国负责预防、监测、侦查和起诉本公约所涵盖的犯罪的人员发起、制定、实施或改进具体的培训方案。三、本条第一款和第二款所述活动在本国法律准许的范围内可涉及以下方面： ㈠ 用于预防、监测、侦查和起诉本公约所涵盖的犯罪的方法和技术； ㈡ 在制定和规划预防和打击网络犯罪的战略性政策和法规方面开展能力建设； ㈢ 在收集、保全和共享证据特别是电子证据方面开展能力建设，包括保管链维护和法证分析； ㈣ 现代执法设备及其使用； ㈤ 培训主管机关如何撰写符合本公约要求的司法协助以及其他合作手段的请求书，特别是电子证据收集、保全和共享方面的请求； ㈥ 预防、监测和监控由实施本公约所涵盖的犯罪产生的所得、相关财产、设备或其他工具的 移动，以及转移、藏匿或掩饰此类所得、财产、设备或其他工具所使用的方法； ㈦ 便利扣押、没收和返还本公约所涵盖的犯罪所得的适当且高效的法律机制和方法以及行政机制和方法； ㈧ 保护与司法机关合作的受害人和证人的方法； ㈨ 相关实体法和程序法、执法侦查权、国内和国际有关法规，以及语言等方面的培训。四、缔约国应当在不违反本国法律的情况下，努力利用其他缔约国和相关的国际和区域组织、非政府组织、民间社会组织、学术机构和私营部门实体的专长并与它们开展密切合作，以期加强本公约的有效实施。五、缔约国应当相互协助，规划和实施旨在共享本条第三款所述领域专门知识的研究和培训方案，并应当为此目的酌情利用区域和国际会议及研讨会，促进合作，推动就共同关心的问题开展讨论。六、缔约国应当考虑根据请求相互协助，对在各自领土内实施的本公约所涵盖的犯罪的类型、原因和影响进行评价、考察和研究，以期在主管机关和相关非政府组织、民间社会组织、学术机构和私营部门实体的参与下，制定预防和打击网络犯罪的战略和行动计划。七、 缔约国应当促进有助于及时引渡和提供司法协助的培训和技术援助。此类培训和技术援助可包括语言培训、协助起草和处理司法协助请求书，以及在中央机关或负有相关责任的机构的人员之间的借调和交流。八、 缔约国应当视需要加强努力，最大限度提高国际和区域组织以及有关双边和多边协定或安排框架内的技术援助和能力建设成效。九、缔约国应当考虑建立自愿捐助机制，以通过技术援助方案和能力建设项目，为发展中国家实施本公约的努力提供资助。十、各缔约国均应努力向联合国毒品和犯罪问题办公室提供自愿捐助，以便经由该办公室推进各种方案和项目，从而通过技术援助和能力建设实施本公约。某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24337/43 24-24621\n第五十五条 信息交流\n一、各缔约国均应考虑酌情与有关专家协商，包括与非政府组织、民间社会组织、学术机构和私营部门实体的专家协商，分析本公约涵盖的犯罪在本国领土内的趋势以及实施此类犯罪的环境。二、各缔约国均应考虑开发并彼此共享以及通过国际和区域组织共享有关网络犯罪的统计数据、专业分析技能和信息，以期尽可能制定出预防和打击此类犯罪的共同定义、标准和方法以及最佳实践。三、各缔约国均应考虑监测其预防和打击本公约所涵盖的犯罪的政策和实际措施，并对其成效和效率进行评估。四、缔约国应当考虑相互交流与网络犯罪和收集电子证据有关的法律、政策或技术方面的发展变化情况。\n第五十六条 通过经济发展和技术援助实施本公约\n一、缔约国应当通过国际合作采取有助于最大限度优化本公约实施工作的措施，同时亦应考虑到本公约涵盖的犯罪对社会总体，尤其是对可持续发展的消极影响。二、大力鼓励缔约国相互协调并与国际和区域组织协调，尽可能作出各种具体努力： ㈠ 加强与其他缔约国特别是发展中国家在各层级的合作，以增强其预防和打击本公约所涵盖犯罪的能力； ㈡ 加强资金和物质援助，以支持其他缔约国特别是发展中国家为有效预防和打击本公约所涵盖的犯罪而作出的努力，并帮助它们实施本公约； ㈢ 向其他缔约国特别是发展中国家提供技术援助，以协助它们满足在实施本公约方面的需要。为此，缔约国应当努力向联合国筹资机制中为此目的专门设定的账户提供充分的经常性自愿捐款； ㈣ 酌情鼓励非政府组织、民间社会组织、学术机构和私营部门实体以及金融机构，包括根据本条规定，促进缔约国作出各种努力，特别是向发展中国家提供更多的培训方案和现代设备，以协助它们实现本公约的各项目标； ㈤ 针对所开展的活动交流最佳实践和信息，以期提高透明度，避免重复努力，并充分汲取任何经验教训。三、 缔约国还应考虑利用现有的次区域方案、区域方案和国际方案，包括会议和研讨会，促进合作和技术援助，并推动就共同关心的问题，包括发展中国家的特殊问题和需要，展开讨论。四、 缔约国应当尽可能确保资源和努力的分配和方向有助于统一标准、技能、能力、专门知识和技术能力，以期在缔约国之间确立共同的最低限度标准，从而铲除本公约涵盖的犯罪的藏身之所，并加强打击网络犯罪的力度。五、根据本条采取的措施应当尽量不影响现有的对外援助承诺或其他双边、区域或国际一级的财政合作安排。六、缔约国可缔结关于物资和后勤援助的双边、区域或多边协定或安排，同时考虑到为使本公约所规定的国际合作手段行之有效和为预防、监测、侦查和起诉本公约所涵盖的犯罪所需要的财政安排。\n第八章 实施机制 第五十七条 公约缔约国会议\n一、兹此设立公约缔约国会议，以期增强缔约国的能力和增进缔约国之间的合作，从而实现本公约规定的各项目标并促进和审议本公约的实施情况。二、联合国秘书长应当自本公约生效后一年之内召开缔约国会议。其后，缔约国会议常会应当按照缔约国会议所通过的议事规则召开。三、缔约国会议应当通过其议事规则和关于本条所列各项活动的规则，包括关于观察员的接纳和参与以及如何支付这些活动所涉费用的规则。这些规则和相关活动应当考虑到有效性、包容性、透明度、效率和国家自主权等原则。四、 缔约国会议在确定其常会时，应当按照本条第三款所述各项原则，考虑到在类似事项上的其他有关国际和区域组织和机制包括其附属条约机构举行会议的时间和地点。五、缔约国会议应当商定实现本条第一款所列目标的活动、程序和工作方法，其中包括： ㈠ 促进本公约的有效应用和实施、发现其间存在的任何问题，以及 促进缔约国根据本公约开展的活动，包括鼓励调集自愿捐款； ㈡ 促进缔约国、相关国际和区域组织以及非政府组织、民间社会组织、学术机构和私营部门实体之间根据本国法律交流与根据本公约确立的犯罪有关的法律、政策和技术方面的发展情况以及电子证据收集方面的信息，并交流网络犯罪的模式和趋势以及预防和打击此类犯罪的成功实践方面的信息； ㈢ 与相关国际和区域组织以及非政府组织、民间社会组织、学术机构和私营部门实体开展合作； ㈣ 适当利用其他国际和区域组织和机制为预防和打击根据本公约确立的犯罪而提供的相关信息，以避免不必要的重复工作； ㈤ 定期审议缔约国实施本公约的情况；某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24339/43 24-24621 ㈥ 提出改进本公约及其实施工作的建议，并审议可能对本公约作出的补充或修正； ㈦ 依据本公约第六十一条和第六十二条拟订和通过本公约的补充议定书； ㈧ 注意到缔约国在实施本公约方面的技术援助和能力建设需要，并建议在此方面采取任何其认为必要的行动。六、各缔约国均应按照缔约国会议的要求，向缔约国会议提供信息，说明本国为实施本公约而采取的立法措施、行政措施和其他措施以及本国的方案、计划和实践。缔约国会议应当研究接收信息以及根据这些信息采取行动的最有效方式，这些信息包括从缔约国以及相关国际组织和区域组织收到的信息。根据缔约国会议决定的程序正式获得认可的相关非政府组织、民间社会组织、学术机构和私营部门实体的代表提出的意见亦可予以考虑。七、为了本条第五款之目的，缔约国会议可设立和管理其认为必要的审议机制。八、 根据本条第五款至第七款，缔约国会议应当在其认为必要时设立任何适当的机制或附属机构，以协助本公约的有效实施。\n第五十八条 秘书处\n一、应由联合国秘书长为公约缔约国会议提供必要的秘书处服务。二、 秘书处应当： ㈠ 协助缔约国会议开展本公约所列述的各项活动，并为缔约国会议举行的与本公约有关的届会做出相应的安排和提供必要的服务； ㈡ 依请求协助缔约国按照本公约的设想向缔约国会议提交资料；以及 ㈢ 确保与有关的国际和区域组织秘书处进行必要的协调。\n第九章 最后条款 第五十九条 本公约的实施\n一、各缔约国均应根据本国法律的基本原则采取必要措施，包括立法措施和行政措施，确保履行其根据本公约所承担的各项义务。二、为预防和打击根据本公约确立的犯罪，各缔约国均可采取比本公约的规定更为严格或更为严厉的措施。\n第六十条 本公约的效力\n一、如果两个或两个以上缔约国业已就 本公约所涉事项缔结了协定或条约，或已以其他方式就这些事项建立了关系，或未来将这样做，则这些缔约国亦应有权适用此类协定或条约或相应地规范这些关系。二、本公约的任何规定均不得影响缔约国在国际法下的其他权利、限制、义务和责任。\n第六十一条 同议定书的关系\n一、本公约可由一项或多项议定书予以补充。二、只有成为本公约缔约方的国家或区域经济一体化组织方可成为议定书缔约方。三、本公约缔约国不受议定书约束，除非其已根据议定书的规定成为议定书的缔约国。四、本公约的任何议定书均应结合本公约解读，并考虑到这些议定书的宗旨。\n第六十二条 通过补充议定书\n一、至少需要有六十个缔约国，才能在缔约国会议上审议通过任何补充议定书。缔约国会议应尽一切努力就任何补充议定书达成协商一致。如果已为达成协商一致竭尽一切努力而仍未达成一致意见，则作为最后手段，补充议定书须至少获得出席缔约国会议并参加表决的缔约国三分之二多数票方可通过。二、区域经济一体化组织在其职权范围内的事项中依本条行使表决权时，其票数应与其作为本公约缔约国的成员国数目相等。如果这些组织的成员国行使投票权，则这些组织便不得行使投票权；反之亦然。\n第六十三条 争端的解决\n一、缔约国应当努力通过谈判或自行选择的任何其他和平手段解决与本公约的解释或适用有关的争端。二、两个或两个以上缔约国对于本公约的解释或适用发生任何争端，且未能在合理时间内通过谈判或其他和平手段解决的，应当按其中一缔约国请求交付仲裁。如果自请求交付仲裁之日起六个月后所涉缔约国无法就仲裁安排达成协议，则其中任一缔约国可根据《国际法院规约》请求将争端提交国际法院。三、各缔约国在签署、批准、接受、核准或加入本公约时，均可声明不受本条第二款的约束。其他缔约国对于作出此种保留的任何缔约国，不受本条第二款的约束。某些犯罪并共享严重犯罪电子证据而加强国际合作公约 A/RES/79/24341/43 24-24621四、凡根据本条第三款作出保留的缔约国，均可随时通知联合国秘书长撤销该项保留。\n第六十四条 签署、批准、接受、核准和加入\n一、本公约应于 2025 年在河内及随后在纽约联合国总部开放供各国签署，直至2026 年 12 月 31 日。二、本公约还应开放供区域 经济一体化组织签署，但条件是此类组织至少有一个成员国已按照本条第一款的规定签署了本公约。三、本公约须经批准、接受或核准。批准书、接受书或核准书应当交存联合国秘书长。如果某一区域经济一体化组织至少有一个成员国已交存批准书、接受书或核准书，则该组织亦可交存其批准书、接受书或核准书。该组织应当在其批准书、接受书或核准书中宣布其在本公约管辖事项方面的权限范围。该组织还应将其权限范围的任何有关变动情况通知保存人。四、任何国家或任何至少已有一个成员国加入本公约的区域经济一体化组织均可加入本公约。加入书应当交存联合国秘书长。区域经济一体化组织加入本公约时应当宣布其在本公约管辖事项方面的权限范围。该组织还应将其权限范围的任何有关变动情况通知保存人。\n第六十五条 生效\n一、本公约应自第四十份批准书、接受书、核准书或加入书交存之日后第九十天起生效。为本款之目的，区域经济一体化组织交存的任何文书均不得在该组织成员国所交存文书以外另行计算。二、对于在第四十份批准书、接受书、核准书或加入书交存之后批准、接受、核准或加入本公约的国家或区域经济一体化组织，本公约应自该国或该组织交存有关文书之日后第三十天或于本公约根据本条第一款生效之日生效，以其中较晚者为准。\n第六十六条 修正\n一、缔约国可在本公约生效满五年后提出修正案并将修正案送交联合国秘书长。秘书长应当立即将所提修正案转发缔约国和公约缔约国会议，以便对提案进行审议并作出 决定。缔约国会议应当尽一切努力就每项修正案达成协商一致。如果已为达成协商一致竭尽一切努力而仍未达成一致意见，则作为最后手段，修正案须获得出席缔约国会议并参加表决的缔约国的三分之二多数票方可通过。二、区域经济一体化组织对属于其权限范围内的事项依本条行使表决权时，其票数相当于其作为本公约缔约国的成员国数目。如果这些组织的成员国行使投票权，则这些组织便不得行使投票权，反之亦然。三、根据本条第一款通过的修正案，须经缔约国批准、接受或核准。四、 根据本条第一款通过的修正案，应自缔约国向联合国秘书长交存一份批准、接受或核准该修正案的文书之日起九十天后对该缔约国生效。五、修正案一经生效，即对已表示同意受其约束的缔约国具有约束力。其他缔约国则仍受本公约原条款以及此前已批准、接受或核准的任何修正案的约束。\n第六十七条 退约\n一、缔约国可书面通知联合国秘书长退出本公约。退约应自秘书长收到退约通知之日起一年后生效。二、区域经济一体化组织在其所有成员国均已退出本公约时，即不再是本公约缔约方。三、根据本条第一款的规定退出本公约，即自然退出本公约的任何议定书。\n第六十八条 保存人和语文\n一、联合国秘书长为本公约的指定保存人。二、本公约原件应交存联合国秘书长，其阿拉伯文、中文、英文、法文、俄文和西班牙文文本同等作准。兹由经各自政府正式授权的下列署名全权代表签署本公约，以昭信守。1附件关于《联合国打击网络犯罪以及为打击 使用信息通信技术系统实施的某些犯罪并共享严重犯罪电子证据而加强国际合作公约》中某些具体条款的解释性说明\n","permalink":"https://intlaws.com/compliance/intl/un-cybercrime-convention/","summary":"联合国打击网络犯罪公约官方全文（中英双语）：2024 年 12 月 24 日联合国大会第 79/243 号决议通过，载于决议附件，共 9 章 68 条；须自第 40 份批准书交存后第 90 天生效，目前尚未生效。中文文本取自联合国正式文件 A/RES/79/243。","title":"联合国打击网络犯罪公约（全文）"},{"content":"美国人工智能立法的联邦—州级拉锯：2026 年州法图景与合规要点 导语：一份 50 州拼图式的合规地图 美国至今没有联邦统一的人工智能法，监管呈「联邦行政令 + 州法拼图」格局。本文以官方来源核实四个关键节点：第 14365 号行政令、德州 TRAIGA（2026-01-01 生效）、加州 SB 53 及 2026 年 9 月两项新法，以及科罗拉多 SB 24-205 已被 2026 年 SB 26-189 废止并重立这一关键变动。\n导语：一份\u0026quot;50 州拼图\u0026quot;式的合规地图 与欧盟一次性通过统一条例的路径不同，美国至今没有联邦层面的综合性人工智能法律。规制由两条线同时推进：联邦层面以行政令与国家立法框架建议牵引，并试图以\u0026quot;先占\u0026quot;（preemption）压制各州立法；州层面则继续各自立法，形成标准不一的拼图。\n2025 年下半年到 2026 年，这两条线正面相撞：一边是德州、加州、科罗拉多等州的实体规则陆续生效或被重置，一边是联邦行政令与立法框架明确主张\u0026quot;统一国家标准\u0026quot;。对在美有业务的中国企业而言，真正的难点不是\u0026quot;美国有没有 AI 法\u0026quot;，而是要同时应对联邦—州两个层面互相矛盾的要求。\n一、结构性事实：先看三个基本判断 没有联邦统一法：联邦层面目前的抓手是行政令、框架性文件与既有部门法（如联邦贸易委员会法第 5 条），而非综合性立法； 州法是当前唯一的实体规制来源：生效的义务几乎全部来自州法； 联邦\u0026quot;先占\u0026quot;主张与州法同时存在，法律确定性处于低谷——这是 2026 年最大的合规风险特征。 二、联邦层面：从\u0026quot;移除障碍\u0026quot;到\u0026quot;统一国家标准\u0026quot; 时间 文件 要点 2025-01-23 第 14179 号行政令（Removing Barriers to American Leadership in Artificial Intelligence） 移除此前的政策障碍（EO 14365 明确援引该令为政策起点） 2025-12-11 第 14365 号行政令（Ensuring a National Policy Framework for Artificial Intelligence），刊登于《联邦公报》2025-12-16 以\u0026quot;确保国家政策框架\u0026quot;为题，主张为人工智能建立统一的国家政策框架 2026-03 白宫发布国家人工智能立法框架（National Policy Framework for AI）建议 属立法建议而非生效法规；核心是敦促国会以联邦标准取代各州\u0026quot;不当负担\u0026quot;的 AI 法律，同时保留各州在保护儿童、防范欺诈等领域的权限 引用提示：第 14365 号行政令的官方全文见《联邦公报》（90 FR 58499，2025-12-16），务必以该版本为准；白宫 2026 年 3 月的框架文件属建议性质，不具备法律约束力，写作与合规评估时不要与生效法规混同。\n三、州级图景：四个已完成官方核实的节点 3.1 德州：TRAIGA（HB 149），2026 年 1 月 1 日生效 德州第 89 届议会通过 HB 149（Texas Responsible Artificial Intelligence Governance Act）。据德州议会官方\u0026quot;已登记法案摘要\u0026quot;，生效日 2026-01-01；摘要列明的禁止性内容包括：\n禁止使用或部署 AI 系统创建社会评分（social scoring）系统； 禁止开发或分发用于生成、协助生成或传播特定色情内容或儿童色情内容的 AI 系统。 官方链接：德州议会 HB 149 已登记摘要 https://capitol.texas.gov/billlookup/BillSummary.aspx?Bill=HB149\u0026LegSess=89R\n3.2 加州：SB 53（前沿模型透明度）+ 2026 年 9 月两项新法 SB 53（Artificial intelligence models: large developers）：据加州立法信息网官方状态页，该法案新增《商业与职业法典》第 25.1 章（自第 22757.10 条起）、《政府法典》第 11546.8 条、《劳动法典》第 5.1 章（自第 1107 条起），州务卿登记日为 2025-09-29（即签署成法）。州长办公室同日发布签署新闻稿。https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill_id=202520260SB53 2026 年 9 月：州长办公室在两天内先后发布签署新闻稿——2026-09-09《签署全国首创的 AI 保障措施以保护加州居民，并呼吁联邦政府履行其职责》；2026-09-16《签署新法保护劳动者、要求 AI 生成广告进行披露》。具体条文细节以官方文本为准，本文不代为归纳。 加州的特点值得注意：透明度与披露义务先行（模型开发者披露、广告披露、劳动者保护），与欧盟\u0026quot;风险分级+合格评定\u0026quot;的路径明显不同。\n3.3 科罗拉多：一部\u0026quot;被自己取代\u0026quot;的州法 科罗拉多 2024 年的 SB 24-205（《人工智能消费者保护》，Colorado Revised Statutes 第 6 编第 17 部分）是美国第一部综合性州级 AI 法。其命运在 2026 年被改写：\n据科罗拉多州议会官方\u0026quot;法案摘要\u0026quot;：**SB 26-189 废止（repeals）并重新制定（reenacts）**了 SB 24-205 的规定，改为围绕\u0026quot;自动化决策技术\u0026quot;（automated decision-making technology, ADMT）在\u0026quot;重大决定\u0026quot;（consequential decisions）中的使用设定新要求；该法（第 131 章）的登记生效日为 2026-05-14。\n官方链接：https://leg.colorado.gov/bills/sb26-189 ；原法见 https://leg.colorado.gov/bills/sb24-205\n实务含义：按 2024 年版本准备过科罗拉多合规的企业，需要全面重做——监管对象由\u0026quot;人工智能系统\u0026quot;收窄为\u0026quot;自动化决策技术\u0026quot;，义务结构随之改变。\n备注：SB 24-205 在 2025 年曾经历一次生效日推迟（由 2026-02-01 推后），该中间节点目前仅见专业机构报道，官方公报页码尚未核实，建议引用前核对州议会档案。\n3.4 其他州（待核清单，本文不作结论） 康涅狄格等州的 AI 画像/自动化决策条款、犹他州的 AI 政策法、以及各州针对生成式内容与选举的专门立法，均在推进中。本文未对上述州逐一完成官方原文核实，故不列出具体生效日期与条文——数智知库的\u0026quot;立法动态\u0026quot;栏目将按法域逐步补齐。检索时请以各州议会官方网站为准，不要采用第三方汇总表作为引用来源。\n四、对中国企业的合规含义 先判断\u0026quot;有没有美国州际连接点\u0026quot;：州法以\u0026quot;在州内提供、部署或对州内居民产生影响\u0026quot;为常见触发条件，与其是否有美国实体无关； 按义务类型建台账，而不是按\u0026quot;哪部法\u0026quot;记账：目前实际可执行的义务集中在四类——透明度与披露、禁止性用途、歧视与偏见风险评估、高风险场景的人工监督与影响评估； 注意联邦先占诉讼带来的\u0026quot;规则悬置\u0026quot;：州法被挑战不等于自动失效，企业不能以此为由停止合规；应准备\u0026quot;规则可能变化\u0026quot;的预案； 科罗拉多的教训：州法可能在生效前被废止重立——不要把合规投入锁定在某一版本的法条结构上，把体系性内容（数据治理、模型文档、评估流程）做成可复用资产更划算。 五、与中国、欧盟路径的简要对照 维度 美国 欧盟 中国 立法层级 无联邦统一法；州法为主 + 联邦行政令/框架建议 统一条例（AI Act） 法律 + 部门规章（生成式 AI 暂行办法、标识办法等） 规制技术 分州、分场景，透明度与禁止性用途先行 风险分级 + 合格评定 + 协调标准 分类监管 + 备案/安全评估 + 内容标识 当前不确定性 高（联邦先占之争） 中（时间表已修订，规则明确） 低（规则体系已相对成形，细则持续补充） 六、后续观察点 联邦\u0026quot;先占\u0026quot;主张的法律落地方式：国会立法、行政令施压，还是诉讼（州法合宪性/权限之争）； 科罗拉多 SB 26-189 的实施细则与执法口径； 加州 2026 年新法的适用对象与过渡期； 更多州在 2027 年会期前的立法动向。 规范依据（供核对）\n第 14365 号行政令全文（《联邦公报》90 FR 58499，2025-12-16）：https://www.govinfo.gov/content/pkg/FR-2025-12-16/html/2025-23092.htm 德州议会：HB 149 已登记法案摘要 https://capitol.texas.gov/billlookup/BillSummary.aspx?Bill=HB149\u0026LegSess=89R 加州立法信息网：SB 53 状态与章节 https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill_id=202520260SB53 加州州长办公室：SB 53 签署新闻稿（2025-09-29）https://www.gov.ca.gov/2025/09/29/governor-newsom-signs-sb-53-advancing-californias-world-leading-artificial-intelligence-industry/ 加州州长办公室：AI 保障措施签署新闻稿（2026-09-09）https://www.gov.ca.gov/2026/09/09/governor-newsom-signs-first-in-the-nation-ai-safeguards-to-protect-californians-calls-on-the-federal-government-to-do-its-part/ 加州州长办公室：劳动者保护与 AI 广告披露新法（2026-09-16）https://www.gov.ca.gov/2026/09/16/governor-newsom-signs-new-law-to-protect-workers-require-disclosures-on-ai-generated-advertising/ 科罗拉多州议会：SB 26-189（废止并重立 ADMT 规则）https://leg.colorado.gov/bills/sb26-189 科罗拉多州议会：SB 24-205（2024 年原法）https://leg.colorado.gov/bills/sb24-205 ","permalink":"https://intlaws.com/legislation/%E7%BE%8E%E5%9B%BD%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E7%AB%8B%E6%B3%95%E7%9A%84%E8%81%94%E9%82%A6%E5%B7%9E%E7%BA%A7%E6%8B%89%E9%94%AF-2026%E5%B9%B4%E5%B7%9E%E6%B3%95%E5%9B%BE%E6%99%AF%E4%B8%8E%E5%90%88%E8%A7%84%E8%A6%81%E7%82%B9/","summary":"美国 AI 立法呈「联邦行政令 + 州法拼图」并行格局：以官方源核实第 14365 号行政令、德州 TRAIGA（2026-01-01 生效）、加州 SB 53 及 2026 年 9 月两项新法，并揭示科罗拉多 SB 24-205 已被 2026 年 SB 26-189 废止并重立这一关键变动。","title":"美国人工智能立法的联邦—州级拉锯：2026 年州法图景与合规要点"},{"content":"欧盟《人工智能法》(AI Act) 项目 内容 法域 欧盟 立法层级 条例(Regulation,直接适用,无需成员国转化) 原文名称 Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) 英文名称 EU Artificial Intelligence Act (AI Act) 中文名称 欧盟《人工智能法》——业内通行译名,欧盟法无官方中文译本 通过与公布 2024-06-13 签署;2024-07-12 刊登于《欧盟官方公报》 生效/施行 2024-08-01 生效;分期适用(见下\u0026quot;生效节点\u0026quot;) 最近修订 Regulation (EU) 2026/1744(AI Omnibus,2026-07-27 生效)——编号来源为专业机构整理,[建议以 EUR-Lex 原文核实] 主管机关 成员国国家主管机关 + 欧盟委员会 AI Office(通用模型与部分平台内嵌系统的监督) 适用范围 在欧盟市场投放/投入使用 AI 系统的提供者、部署者、进口商、分销商(部分条款具域外效力) 议题标签 人工智能治理 状态 现行有效,分期适用中 官方原文链接 https://eur-lex.europa.eu/eli/reg/2024/1689/oj ;条款速览:https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113 核验日期 2026-09-22 一、生效节点(经 AI Omnibus 修订后的官方口径) 日期 事项 2024-08-01 生效 2025-02-02 一般条款(定义、AI 素养)与禁止性做法适用 2025-08-02 通用人工智能(GPAI)模型义务适用;成员国须指定主管机关并通过罚则;欧盟治理架构到位 2026-08-02 大部分规则适用;第 50 条透明度义务适用;执法启动 2026-12-02 新增禁令(非自愿性私密内容、儿童性虐待材料)适用;第 50 条第 2 款过渡期 2027-08-02 成员国至少一个监管沙盒运行 2027-12-02 附件三高风险系统规则适用(原 2026-08-02) 2028-08-02 附件一所嵌受监管产品中的高风险系统规则适用(原 2027-08-02) 二、关键机制 风险分级:禁止性做法 / 高风险(第 6 条与附件三场景,及附件一产品)/ 透明度风险(第 50 条)/ 最低风险; 高风险系统义务:风险管理、数据治理、技术文档、日志、透明度、人类监督、准确性稳健性网络安全、质量管理体系、合格评定与 CE 标记; GPAI 义务:技术文档、下游提供者信息、版权政策、训练数据摘要;系统性风险模型另有对抗测试与事件报告义务; 自愿性行为准则:《通用人工智能行为准则》(2025-07-09 定稿),委员会与 AI 委员会确认为\u0026quot;适当的自愿工具\u0026quot;,签署可降低行政负担; 协调标准与符合性推定:2026 年 6 月 CEN/CENELEC 批准首个标准(《AI:面向 AI Act 监管目的的质量管理体系》),委员会预计 2026 年内于 OJ 公布引用。 三、官方指南与配套文件 委员会 GPAI 义务范围指南(2025-07-18,C(2025) 5045 final):https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act 委员会《AI Omnibus enters into force》(2026-07-27):https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force 官方实施时间表:https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline 附件三高风险场景清单:https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3 四、动态观察点 OJ 公布首批协调标准引用(决定\u0026quot;符合性推定\u0026quot;何时可用); 成员国罚则与主管机关落实; AI Office 对 GPAI 的执法(新模型自 2026-08-02 起可执行,既有模型自 2027-08-02); AI Omnibus 实施效果评估及是否引发第二轮调整。 五、相关产出 本站文章:《欧盟《人工智能法》实施进展:AI Omnibus 修订后的义务生效节点与合规要点》(2026-09-22) 归档位置:2026-09-22/欧盟人工智能法实施进展-AI-Omnibus修订后的义务生效节点与合规要点.md 既有素材:[[2026-09-13/欧盟人工智能法主要内容及其影响分析]] 六、来源 EUR-Lex:Regulation (EU) 2024/1689 AI Act Service Desk(实施时间表、第 113 条、附件三) 欧盟委员会数字战略网站(AI Omnibus 生效公告、GPAI 行为准则页、GPAI 指南) 欧洲议会立法进程页(Digital Omnibus on AI) CEN-CENELEC(首个协调标准公告) ","permalink":"https://intlaws.com/compliance/eu/%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E6%B3%95-ai-act-2024-1689/","summary":"欧盟《人工智能法》（Regulation (EU) 2024/1689）档案：风险分级框架、通用人工智能义务、治理架构与 AI Omnibus 修订后的义务生效时间表，附官方来源。","title":"欧盟《人工智能法》(AI Act)"},{"content":"欧盟《人工智能法》（AI Act）主要内容梳理及其影响分析（2026-09 修订） 修订说明（请先读这一段） 本文基于 2026-09-11 原稿修订，修订范围与理由如下：\n时间表已过时（本次修订的主因）：原稿写\u0026quot;高风险系统大部分义务 2026 年 8 月起\u0026quot;。该时间表已被 2026 年 7 月生效的\u0026quot;人工智能数字综合法案\u0026quot;（AI Omnibus，Regulation (EU) 2026/1744）改写：附件三高风险义务后移至 2027-12-02，附件一所嵌产品的高风险义务后移至 2028-08-02。凡按原稿日期安排合规的读者，请以本文修订后的节点为准。 编号与公报信息已硬核对：Regulation (EU) 2026/1744，法案日 2026-07-08，刊登于《欧盟官方公报》L 系列 2026-07-24（OJ L 202601744），2026-07-27 生效。已通过欧盟出版局（Publications Office）官方资源与欧盟委员会官方公告双向核对。 已逐条核对的项：第 99 条罚则最高档（EUR 35 000 000 或全球营业额 7%，取高者）、第 51 条系统性风险算力阈值（训练算力超过 10^25 浮点运算即推定为高影响能力模型）——均已对照 AI Act 官方条文页原文。 仍标注待核的项：罚则其余档位（第 99 条第 4、5 款）、日韩立法细节（见第七部分）——未取得官方原文，本文不作确定性表述。 一、立法背景与进程 法案全称：《人工智能法》（Artificial Intelligence Act，Regulation (EU) 2024/1689）\n立法动因：欧盟在数字治理领域延续 GDPR（General Data Protection Regulation，通用数据保护条例）的「布鲁塞尔效应」路径，试图通过统一立法确立全球 AI 监管标准，同时应对 AI 带来的基本权利风险、安全风险与市场碎片化问题。 立法进程： 2021 年 4 月：欧盟委员会提出立法提案 2023 年 12 月：欧洲议会、理事会、委员会三方就最终文本达成政治协议 2024 年 3 月：欧洲议会通过；2024 年 5 月：理事会批准 2024-08-01：生效，分阶段适用 2026-07-27：AI Omnibus（Regulation (EU) 2026/1744，2026-07-08 通过，2026-07-24 刊《欧盟官方公报》）生效，对 AI Act 的时间表与部分义务作出修订 法律形式：欧盟条例（Regulation），在全体成员国直接适用，无需转化为国内法。 修订后的义务生效节点（官方口径） 日期 事项 2024-08-01 生效 2025-02-02 一般条款（定义、AI 素养）与禁止性做法适用 2025-08-02 通用人工智能（GPAI）模型义务适用；成员国须指定国家主管机关并通过罚则；欧盟治理架构（AI 委员会、科学专家组、咨询论坛）到位 2026-08-02 大部分规则适用；第 50 条透明度义务适用；对 GPAI、禁止性做法、透明度与 AI 素养的执法启动 2026-12-02 新增禁令适用（生成非自愿性私密内容、儿童性虐待材料的系统）；第 50 条第 2 款过渡期安排 2027-08-02 成员国应至少有一个监管沙盒投入运行 2027-12-02 附件三所列高风险系统规则适用（原为 2026-08-02） 2028-08-02 附件一所列受监管产品中嵌入的高风险系统规则适用（原为 2027-08-02）；官方时间表以此日为全面铺开节点 来源：欧盟 AI Act Service Desk 官方实施时间表（明确载明\u0026quot;已考虑 AI 数字综合法案对 AI Act 的修订\u0026quot;）。\n二、核心框架：基于风险的分级规制 AI Act 的标志性设计是按风险等级分类监管，义务强度随风险递增：\n风险等级 对应系统 监管态度 典型场景 不可接受风险 被禁止的 AI 实践 禁止 社会评分、实时远程生物识别（执法场景严格限定）、操纵潜意识的行为操控、预测犯罪画像、无差别抓取人脸数据库、情绪识别（职场/教育）等；2026-12-02 起新增：生成非自愿性私密内容与儿童性虐待材料的系统 高风险 附件三列举领域 + 产品安全部件（附件一） 严格合规义务 关键基础设施、教育录取/考试评分、招聘与员工管理、执法、移民边境、司法与民主程序、生物识别（许可后）等 有限风险 与人交互的系统、生成合成内容 透明度义务 聊天机器人须告知对方是 AI；深度合成内容（deepfake）须标识 最小风险 一般 AI 应用 自由使用 鼓励自愿行为准则 三、高风险系统的义务体系 被归类为高风险的系统须履行以下义务（构成「事前合规 + 持续监督」全链条）：\n风险管理体系：贯穿生命周期的持续迭代的风险识别、评估与缓解 数据治理：训练/验证/测试数据须具相关性、代表性、无偏性 技术文档：编制并持续更新，供主管机关审查 记录与日志：自动记录事件，保证可追溯 透明度与使用者告知：向部署者提供使用说明 人类监督：设计上确保人类可有效监督（human oversight） 准确性、鲁棒性与网络安全 合格评定：多数高风险系统须完成内部合规评估或第三方符合性评估，加贴 CE 标志后方可上市 上市后监测与事故报告 基本权利影响评估（FRIA）：特定高风险系统的部署者（如公共机构、信用评分场景）在使用前评估对基本权利的影响 上述为框架性归纳；具体条文序号与细节以官方原文为准。\n四、通用目的模型（GPAI）与系统性风险 所有 GPAI 提供者的义务：技术文档、向下游提供者提供信息、版权政策、训练数据摘要等；义务自 2025-08-02 起适用。 可执行的时点：据欧盟委员会 2025 年 7 月 9 日新闻稿，GPAI 规则对新模型在一年后、对既有模型在两年后可由委员会的 AI Office 执行——即新模型 2026-08-02 起、既有模型 2027-08-02 起进入可执行阶段。 系统性风险的判定门槛（已核原文）：第 51 条规定，用于训练的计算量以浮点运算衡量超过 10^25 时，该模型被推定为具有高影响能力；委员会亦可依特定标准主动认定。 自愿性行为准则：委员会于 2025-07-09 收到《通用人工智能行为准则》定稿（13 名独立专家起草、1,000 余家利益相关方参与）；委员会与 AI 委员会确认其为证明合规的\u0026quot;适当的自愿工具\u0026quot;，签署可降低行政负担。签署与否不改变法定义务，只改变合规证明方式。 官方指南：委员会于 2025-07-18 发布关于 GPAI 提供者义务范围的指南（文件号 C(2025) 5045 final）。 五、治理架构与执法 欧盟 AI Office（设于欧盟委员会）：负责 GPAI 监管、协调与标准支持；AI Omnibus 后其监督权限扩展至部分基于通用模型、并嵌入大型在线平台与搜索引擎的系统 各成员国主管机关：指定 notified body 承担第三方合格评定与市场监管；须自 2025-08-02 起指定并制定罚则 咨询机构：欧洲人工智能委员会（成员国代表）、科学顾问小组、利益相关方咨询论坛 处罚（AI Act 第 99 条）： 违反禁止性做法：行政罚款最高 EUR 35 000 000,或（对企业）全球上一年度营业额的 7%,以较高者为准 —— 已核官方条文原文 其余档位（涉其他义务、提供错误信息）：原稿所述 EUR 15 000 000/3% 与 EUR 7 500 000/1.5% 两档，本次未取得官方原文页面完整文本，标注[待核]，引用前请核对第 99 条第 4、5 款 对中小企业及初创企业设定与营业额挂钩的上限 六、创新配套措施 监管沙盒：成员国须建立；2027-08-02 起各国应至少有一个投入运行；AI Omnibus 后扩大可及范围并引入欧盟层面沙盒 标准与合格推定：协调标准（harmonised standards）经《欧盟官方公报》引用后，符合标准可产生\u0026quot;符合相关要求\u0026quot;的推定效力。2026 年 6 月，CEN 与 CENELEC 批准首个 AI Act 项下欧洲标准——《人工智能：面向欧盟 AI Act 监管目的的质量管理体系》（覆盖风险管理、人类监督、数据质量与网络安全）；委员会预计 2026 年内于官方公报公布其引用 中小企业与\u0026quot;小型中型市值公司\u0026quot;（SMCs）支持：AI Omnibus 将原仅适用中小企业的部分简化义务扩展至 SMCs；简化 AI 素养要求（改由委员会与成员国承担更多推广职责）；简化欧盟中央数据库登记义务 偏误检测：AI Omnibus 允许为检测与纠正偏见而处理特殊类别个人数据 七、影响分析：AI 产业与全球立法格局 （一）对 AI 产业的影响 积极面：明确规则降低法律不确定性；合规能力成为竞争壁垒；高风险场景的合规要求可建立用户信任；沙盒与标准提供合规路径指引。\n消极面：合规成本显著（文档、评估、审计流程）；基础模型层义务可能拖慢开源与学术研究；监管严格度差异可能推动部分开发活动向更宽松法域转移（该判断学界实证尚不充分，本文不作结论）。\n结构性影响：加速\u0026quot;合规即服务\u0026quot;（RegTech）产业兴起；推动 AI 供应链分层（基础模型提供者/系统提供者/部署者）与责任划分清晰化。\n（二）对世界各法域立法的影响 「布鲁塞尔效应」的延续与限度：面向欧盟市场的外国企业被迫合规，进而将欧盟标准内化为全球默认；但 AI 领域竞争激烈，中美等法域有自主议程，地缘科技竞争削弱单极输出，价值观差异（如实时生物识别的容忍度）难以被统一标准覆盖。 各法域路径： 美国：联邦层面无统一立法，呈\u0026quot;行政令 + 州法拼图\u0026quot;格局。2025-12-11 第 14365 号行政令主张建立统一国家政策框架，2026 年 3 月白宫发布国家 AI 立法框架建议（属立法建议，非生效法规）；州层面德州 TRAIGA（HB 149）已于 2026-01-01 生效，加州陆续签署透明度类立法，而科罗拉多 2024 年的 SB 24-205 已被 2026 年的 SB 26-189 废止并重新制定（详见本站《美国人工智能立法的联邦—州级拉锯》一文） 英国：采取\u0026quot;亲创新\u0026quot;的分散式监管（行业监管机构主导），区别于欧盟统一立法，但监管原则与欧盟重叠 中国：坚持\u0026quot;先分后总\u0026quot;的渐进立法路径（算法推荐规定 → 深度合成规定 → 生成式人工智能管理暂行办法 → 内容标识办法 → 综合立法推进中）；以分类监管与备案/安全评估为主要工具，与欧盟风险分级路径存在可对话性 日本、韩国：日本偏软法与行业指引；韩国于 2024 年底通过人工智能框架性立法。[待核] 具体法名、通过与生效时间，请以日本 e-Gov 法令检索（laws.e-gov.go.jp）与韩国国家法令信息中心（law.go.kr）官方原文为准，本站将随\u0026quot;日韩\u0026quot;批次建档后统一校正 国际组织：G7 广岛进程、OECD AI 原则、联合国相关进程均在风险分级上与欧盟框架形成呼应；ISO/IEC 标准制定受欧盟需求拉动 规则互认与标准博弈：标准跨境衔接（如内容标识、安全评估互认）正在成为数字贸易规则的新条款类型；规则互认谈判能力成为数字治理竞争的关键变量。 八、简要评述（修订后） AI Act 仍是全球首部全面性 AI 统一立法，其风险分级、GPAI 分级、基本权利影响评估等制度工具正在成为各国立法的\u0026quot;参考词汇表\u0026quot;。2026 年的 AI Omnibus 修订则提示了一个更重要的观察点：即便在同一法域内，\u0026ldquo;规则\u0026quot;也不是一次成型的——当合规成本与产业竞争力发生冲突时，立法者会选择性地回撤时间表、简化程序，但不放弃核心监管框架。\n对中国企业的实务含义：不要把合规投入锁死在某一版本的条文结构上。可复用的资产是体系性的：模型与数据文档、评估流程、披露话术、供应链责任划分——这些在任何一版时间表下都不会白做。\n术语说明 欧盟法以欧盟 24 种官方语言公布，不含中文，因此不存在\u0026quot;官方中文译名\u0026rdquo;。本文对关键术语采用\u0026quot;原文 + 业内通行译名\u0026ldquo;的方式标注，例如：Regulation（条例）、GPAI（General-Purpose AI，通用人工智能）、harmonised standards（协调标准）、conformity assessment（合格评定）。引用时请以英文原文为准。\n规范依据（供核对）\nAI Act Service Desk 官方实施时间表（经 AI Omnibus 修订）：https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline AI Act Service Desk 第 99 条（罚则）：https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99 AI Act Service Desk 第 51 条（系统性风险门槛）：https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-51 欧盟委员会：《AI Omnibus enters into force》（2026-07-27）：https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force 欧盟出版局官方资源（OJ L 202601744 = Regulation (EU) 2026/1744，公布日 2026-07-24）：http://publications.europa.eu/resource/celex/32026R1744 欧盟委员会新闻稿：《General-Purpose AI Code of Practice now available》（2025-07-09）：https://ec.europa.eu/commission/presscorner/detail/en/ip_25_1787 欧盟委员会：GPAI 提供者义务范围指南（2025-07-18，C(2025) 5045 final）：https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act CEN-CENELEC：首个 AI Act 协调标准获批（2026-07-29）：https://www.cencenelec.eu/news-events/news/2026/newsletter/ots-75-anec 欧洲议会立法进程页：Digital Omnibus on AI：https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai 本稿为 2026-09-22 修订版；原稿（2026-09-11）中\u0026quot;高风险义务 2026 年 8 月起适用\u0026quot;等表述已按官方口径更正。\n","permalink":"https://intlaws.com/forum/%E6%AC%A7%E7%9B%9F%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E6%B3%95%E4%B8%BB%E8%A6%81%E5%86%85%E5%AE%B9%E5%8F%8A%E5%85%B6%E5%BD%B1%E5%93%8D%E5%88%86%E6%9E%90-%E4%BF%AE%E8%AE%A2%E7%A8%BF/","summary":"按 AI Omnibus 生效后的官方口径全面修订欧盟《人工智能法》梳理稿：更正高风险系统与新增禁令的生效节点，核对第 99 条罚则最高档（EUR 35 000 000 或全球营业额 7%）与第 51 条 10^25 算力阈值，并标注尚待核实的条文与日韩立法细节。","title":"欧盟《人工智能法》（AI Act）主要内容梳理及其影响分析（2026-09 修订）"},{"content":"欧盟《人工智能法》实施进展：AI Omnibus 修订后的义务生效节点与合规要点 导语：为什么今年必须重看一遍时间表 欧盟《人工智能法》的合规时间表在 2026 年被改写：AI Omnibus（Regulation (EU) 2026/1744）生效后，附件三高风险系统的义务后移至 2027 年 12 月 2 日、附件一所嵌产品的义务后移至 2028 年 8 月 2 日。本文以官方来源逐节点梳理现行生效安排，供企业据此重排合规路线图。\n导语：为什么今年必须重看一遍时间表 2024 年 8 月 1 日，欧盟《人工智能法》（Artificial Intelligence Act，Regulation (EU) 2024/1689）生效。此后两年，业界普遍按一套广为流传的时间表安排合规工作：2026 年 8 月 2 日高风险人工智能系统义务适用，2027 年 8 月 2 日附件一产品类高风险系统适用。\n这套时间表已经过时。2026 年 7 月 27 日，欧盟委员会的\u0026quot;人工智能数字综合法案\u0026quot;（AI Omnibus）正式生效，高风险系统的义务节点被整体后移。欧盟官方的 AI Act Service Desk 也据此更新了实施时间表，并明确写道：全面铺开的时间点已调整为 2028 年 8 月 2 日，\u0026ldquo;该时间表已考虑 AI 数字综合法案对《人工智能法》的修订\u0026rdquo;。\n对在欧盟市场投放或使用人工智能系统的中国企业而言，这不是一条程序性新闻：它直接改变了未来两年合规投入的节奏，也改变了\u0026quot;何时必须做完什么\u0026quot;的判断。\n一、修订的由来与生效 节点 日期 依据 欧盟委员会提出 digital omnibus 一揽子方案中的 AI 部分 2025-11-19 欧洲议会立法进程页（Legislative Train） 欧洲议会通过谈判立场 2026-03（当月第二次全会） 同上 刊登于《欧盟官方公报》（OJ） 2026-07-24 已核对官方来源:欧盟出版局资源 OJ L 202601744 AI Omnibus 正式生效 2026-07-27 欧盟委员会官方新闻《AI Omnibus enters into force》 该修订法案的编号为 Regulation (EU) 2026/1744（2026 年 7 月 8 日通过，2026 年 7 月 24 日刊登于《欧盟官方公报》L 系列，OJ L 202601744），同时修订了《人工智能法》（2024/1689）、民航共同规则（2018/1139）与机械条例（2023/1230）。\n编号已核对官方原文：欧盟出版局官方资源 http://publications.europa.eu/resource/celex/32026R1744 载明\u0026quot;REGULATION (EU) 2026/1744 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 8 July 2026 …\u0026quot;，OJ L 系列公布日 2026-07-24；另见欧盟委员会 2026-07-27 生效公告。\n术语说明：欧盟法以欧盟 24 种官方语言公布，不包含中文。本文所附中文名称为业内通行译名，引用时请以英文原文为准。\n二、现行义务生效节点全景 以下为经修订后的官方时间表（来源：AI Act Service Desk 实施时间表）：\n日期 事项 2024-08-01 《人工智能法》生效 2025-02-02 一般条款（定义、AI 素养）与禁止性做法开始适用 2025-08-02 通用人工智能（GPAI）模型义务开始适用；成员国须指定国家主管机关并通过罚则；欧盟层面治理架构（AI 委员会、科学专家组、咨询论坛）须到位 2026-08-02 《人工智能法》大部分规则开始适用，可适用规则的执法启动：第 50 条透明度义务开始适用；支持创新的措施开始适用；针对 GPAI 模型、禁止性做法、透明度义务与 AI 素养的执法在国家与欧盟层面同步启动 2026-12-02 新增禁令开始适用（生成非自愿性私密内容的深度伪造、儿童性虐待材料）；同时为 2026-08-02 前已投放市场的部分合成内容系统的提供者设定第 50 条第 2 款的过渡期 2027-08-02 成员国应至少有一个人工智能监管沙盒投入运行 2027-12-02 附件三所列高风险人工智能系统的规则开始适用（原为 2026-08-02） 2028-08-02 嵌入附件一所列受监管产品（机械、玩具、电梯等）的高风险人工智能系统的规则开始适用（原为 2027-08-02） 三、2026 年最值得注意的两项变动 第一，高风险义务的平移并非单纯延期，而是与\u0026quot;合规工具可用性\u0026quot;挂钩。 欧洲议会立法进程页记录，委员会提出的思路是：高风险系统规则的适用时间与标准或其他支持合规的工具是否到位挂钩；在委员会确认工具可用后，规则最迟于 2027 年 12 月 2 日（独立高风险系统）、2028 年 8 月 2 日（附件一所嵌系统）适用。这一设计意味着：标准制定进度将直接影响合规义务的时间表。\n第二，在放宽的同时收紧了部分领域。 委员会公告列出的修订内容包括：\n新增禁令：禁止生成非自愿的色情、私密内容以及儿童性虐待材料的人工智能系统（即俗称的\u0026quot;脱衣类应用\u0026quot;）； 偏误检测：允许为检测与纠正偏见而处理特殊类别的个人数据； 沙盒扩容：扩大监管沙盒的可及范围，并引入欧盟层面的监管沙盒； 减轻行政负担：将原本仅适用于中小企业的简化义务扩展至\u0026quot;小型中型市值公司\u0026quot;（SMCs）；简化人工智能素养要求，改由委员会与成员国承担更多推广职责；简化欧盟中央数据库的登记义务； 治理调整：扩大 AI Office 的监督权限，覆盖部分基于通用模型、且嵌入大型在线平台与搜索引擎的人工智能系统。 四、GPAI：从\u0026quot;规则生效\u0026quot;到\u0026quot;可以执行\u0026quot; 对多数中国企业而言，最直接的接触点是通用人工智能（GPAI）模型义务。\n2025 年 8 月 2 日，GPAI 模型义务开始适用； 依委员会新闻稿，这些规则对新模型在一年后、对既有模型在两年后可由委员会的 AI Office 执行——即新模型自 2026 年 8 月 2 日起、既有模型自 2027 年 8 月 2 日起进入可执行阶段； 2025 年 7 月 9 日，委员会收到《通用人工智能行为准则》（General-Purpose AI Code of Practice）定稿：该准则由 13 名独立专家起草，征求了 1,000 余家利益相关方意见，属自愿性工具；委员会与 AI 委员会已确认其为提供者证明合规的\u0026quot;适当的自愿工具\u0026quot;，签署者可据此降低行政负担； 2025 年 7 月 18 日，委员会发布了关于 GPAI 模型提供者义务范围的指南（文件号 C(2025) 5045 final）。 需注意：行为准则的签署方名单由 AI Office 持续更新（已见 Amazon、Google、Microsoft、Anthropic、IBM、Mistral 等），签署与否不影响法定义务本身，只影响合规证明方式。\n五、标准化：首个协调标准获批，合格推定尚待公报 2026 年 6 月，CEN 与 CENELEC 批准了《人工智能：面向欧盟《人工智能法》监管目的的质量管理体系》（Artificial Intelligence: Quality Management System for EU AI Act Regulatory Purposes）——《人工智能法》项下首个欧洲标准，覆盖风险管理、人类监督、数据质量与网络安全等要求。委员会预计在 2026 年晚些时候于《欧盟官方公报》公布该标准的引用。\n对企业而言，标准的意义在于：协调标准的引用一经公布，符合该标准即可产生\u0026quot;符合相关要求\u0026quot;的推定效力——这是高风险系统合规路径中成本最低的一条通道，值得提前跟踪。\n六、企业需要做什么：按角色的动作清单 角色 2026 年内 2027—2028 GPAI 模型提供者 完成透明度与版权政策、训练数据摘要；评估是否构成\u0026quot;系统性风险\u0026quot;模型；决定是否签署行为准则 既有模型的义务进入可执行阶段（2027-08-02） 高风险系统提供者（附件三：生物识别、教育、就业、关键基础设施、执法、移民、司法等） 建立质量管理体系与风险管理制度；准备技术文档、日志、人类监督与准确性测试；跟踪协调标准公布 2027-12-02 前完成合规与合格评定 嵌入受监管产品的高风险系统（附件一：机械、玩具、电梯、医疗器械等） 与产品法规下的合格评定流程衔接 2028-08-02 前完成 部署者（企业用户） 按提供者说明使用、保存日志、完成人工监督安排；高风险场景下开展基本权利影响评估 随高风险义务节点同步 合成内容相关系统 第 50 条透明度义务已自 2026-08-02 适用；注意 2026-12-02 的过渡期安排 — 七、与中国规则的简要对照 中国在人工智能治理上的路径与欧盟不同，但部分义务形成事实上的对标：\n议题 欧盟 中国 透明度与内容标识 第 50 条透明度义务（2026-08-02 适用）；2026-12-02 起新增针对非自愿性私密内容与儿童性虐待材料的禁令 《人工智能生成合成内容标识办法》（2025-09-01 施行）区分显式标识与隐式标识；《互联网信息服务深度合成管理规定》（2023-01-10 施行）要求显著标识并禁止删除、篡改标识 通用/生成式模型义务 GPAI 模型义务（2025-08-02 适用）+ 自愿性行为准则 + 委员会指南 《生成式人工智能服务管理暂行办法》（2023-08-15 施行）以服务提供者为规制对象，配套算法备案与安全评估 风险分级 以\u0026quot;禁止—高风险—透明度风险—最低风险\u0026quot;分层，附件三列举高风险场景 以服务类型与内容风险为线索分类监管，未采用统一的四层分级 给中国企业的实务提示：若同一产品同时面向中国与欧盟市场，标识义务是最先需要打通的一环——两套规则在\u0026quot;必须让用户识别内容由 AI 生成\u0026quot;这一目标上趋同，但实现方式（显式/隐式标识 vs 第 50 条的技术性披露）与举证要求不同，需要一套可同时满足两边的工作底稿。\n八、后续观察点 委员会在《欧盟官方公报》公布首批协调标准引用（预计 2026 年内）——直接决定\u0026quot;符合性推定\u0026quot;何时可用； 各成员国依 2025-08-02 要求制定的罚则与主管机关指定落实情况； AI Office 对 GPAI 模型的执法动作（自 2026-08-02 起对新模型可执行）； 附件三高风险义务与标准可用性挂钩机制的后续细化； AI 数字综合法案的实施评估，以及是否会引发第二轮调整。 规范依据（供核对）\n欧盟委员会：《AI Omnibus enters into force》（2026-07-27）https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force AI Act Service Desk：《Timeline for the Implementation of the EU AI Act》 https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline AI Act Service Desk：《Article 113: Entry into force and application》 https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113 AI Act Service Desk：《Annex III》 https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3 欧洲议会立法进程页：《Digital Omnibus on AI》 https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai 欧盟委员会新闻稿：《General-Purpose AI Code of Practice now available》（2025-07-09）https://ec.europa.eu/commission/presscorner/detail/en/ip_25_1787 欧盟委员会：《The General-Purpose AI Code of Practice》 https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai 欧盟委员会：《Guidelines on the scope of obligations for providers of general-purpose AI models under the AI Act》（2025-07-18，C(2025) 5045 final）https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act CEN-CENELEC：《First Standard Approved under the AI Act》（2026-07-29）https://www.cencenelec.eu/news-events/news/2026/newsletter/ots-75-anec 国家互联网信息办公室：《生成式人工智能服务管理暂行办法》（2023-08-15 施行）https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm ","permalink":"https://intlaws.com/legislation/%E6%AC%A7%E7%9B%9F%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E6%B3%95%E5%AE%9E%E6%96%BD%E8%BF%9B%E5%B1%95-ai-omnibus%E4%BF%AE%E8%AE%A2%E5%90%8E%E7%9A%84%E4%B9%89%E5%8A%A1%E7%94%9F%E6%95%88%E8%8A%82%E7%82%B9%E4%B8%8E%E5%90%88%E8%A7%84%E8%A6%81%E7%82%B9/","summary":"以 2026 年 7 月生效的 AI Omnibus（Regulation (EU) 2026/1744）为基准，重排欧盟《人工智能法》全部义务生效节点：附件三高风险义务后移至 2027-12-02、附件一所嵌产品后移至 2028-08-02，并给出 GPAI 可执行时点、透明度义务与执法启动节点及企业合规要点。","title":"欧盟《人工智能法》实施进展：AI Omnibus 修订后的义务生效节点与合规要点"},{"content":"数据出境安全评估实务：申报门槛、豁免情形与合规路径选择 一、问题的定位 中国数据出境采用\u0026quot;三条路径并行\u0026quot;的制度设计：数据出境安全评估、个人信息出境标准合同、个人信息保护认证。企业最先要回答的不是\u0026quot;走哪条路径\u0026quot;，而是两个前置问题：有没有重要数据、个人信息规模落在哪个区间。\n判断时必须注意规则的新旧关系。《数据出境安全评估办法》（国家互联网信息办公室令第 11 号，2022 年 7 月 7 日公布，2022 年 9 月 1 日起施行）与《个人信息出境标准合同办法》（国家互联网信息办公室令第 13 号，2023 年 2 月 22 日公布）确立了三路径框架；《促进和规范数据跨境流动规定》（国家互联网信息办公室令第 16 号，2024 年 3 月 22 日公布并施行）调整了适用门槛，其第十三条明确：上述两部办法与本规定不一致的，适用本规定。\n二、\u0026ldquo;要不要申报\u0026rdquo;：三步判断 第一步，是否属于重要数据。《促进和规范数据跨境流动规定》第二条：\u0026ldquo;未被相关部门、地区告知或者公开发布为重要数据的，数据处理者不需要作为重要数据申报数据出境安全评估。\u0026ldquo;重要数据以主管部门告知或公开发布为前提，企业应保存识别与沟通记录，不在申报材料中自行扩大范围。\n第二步，是否为关键信息基础设施运营者。同规定第七条第一项：关键信息基础设施运营者向境外提供个人信息或者重要数据的，应当通过所在地省级网信部门向国家网信部门申报安全评估。此类主体没有数量\u0026quot;安全垫\u0026rdquo;。\n第三步，非关键信息基础设施运营者的数量门槛。同条第二项：向境外提供重要数据，或者自当年 1 月 1 日起累计向境外提供 100 万人以上个人信息（不含敏感个人信息）或者 1 万人以上敏感个人信息的，应当申报安全评估。\n这里有一处容易踩错的新旧差异：《数据出境安全评估办法》第四条规定的是\u0026quot;自上年 1 月 1 日起累计向境外提供 10 万人个人信息或者 1 万人敏感个人信息\u0026rdquo;。新规把个人信息基数由 10 万人提高到 100 万人，起算点改为\u0026quot;当年 1 月 1 日\u0026quot;。数量统计的期间与范围应按新规执行，且\u0026quot;不含敏感个人信息\u0026quot;意味着敏感个人信息单独计算。\n三、\u0026ldquo;可以豁免吗\u0026rdquo;：五类免予情形 情形 条件要点 依据 非个人信息、非重要数据 国际贸易、跨境运输、学术合作、跨国生产制造和市场营销等活动中收集和产生的数据向境外提供，不包含个人信息或者重要数据 第三条 境外收集、境内加工后再出境 处理过程中没有引入境内个人信息或者重要数据 第四条 个人为一方当事人的合同必需 如跨境购物、跨境寄递、跨境汇款、跨境支付、跨境开户、机票酒店预订、签证办理、考试服务等，确需提供 第五条第一项 跨境人力资源管理必需 按依法制定的劳动规章制度和依法签订的集体合同实施，确需提供员工个人信息 第五条第二项 紧急情况与低量豁免 紧急情况下为保护自然人生命健康和财产安全确需提供；以及关键信息基础设施运营者以外的数据处理者自当年 1 月 1 日起累计向境外提供不满 10 万人个人信息（不含敏感个人信息） 第五条第三、四项 第五条第二款还明确：\u0026ldquo;前款所称向境外提供的个人信息，不包括重要数据\u0026quot;——豁免的只是个人信息出境的三项制度，重要数据出境仍回到安全评估。\n另有一条区域性便利安排：第六条规定自由贸易试验区可在国家数据分类分级保护制度框架下制定区内负面清单，经省级网络安全和信息化委员会批准后报国家网信部门、国家数据管理部门备案；区内数据处理者向境外提供负面清单外的数据，可免予申报安全评估、订立标准合同、通过保护认证。\n四、中间区间：标准合同或保护认证 超出低量豁免、又不属于评估范围的，走第二条路径。第八条：关键信息基础设施运营者以外的数据处理者，自当年 1 月 1 日起累计向境外提供 10 万人以上、不满 100 万人个人信息（不含敏感个人信息）或者不满 1 万人敏感个人信息的，应当依法与境外接收方订立个人信息出境标准合同或者通过个人信息保护认证。\n成本排序因此很清楚：能通过调整数据流设计落入低量豁免区间的，成本显著下降；但不得以拆分出境批次等方式人为规避门槛，否则监管核查时难以解释。\n五、申报流程与时限 《数据出境安全评估办法》给出了可直接用于项目排期的节点：\n先行开展风险自评估（第五条），重点评估六项：出境与境外接收方处理的目的、范围、方式的合法性正当性必要性；出境数据的规模、范围、种类、敏感程度及风险；境外接收方的责任义务与其管理、技术措施是否足以保障安全；出境中与出境后的泄露、篡改、丢失、转移等风险及维权渠道；法律文件是否充分约定数据安全保护责任义务；其他可能影响出境安全的事项。 提交材料（第六条）：申报书、数据出境风险自评估报告、与境外接收方拟订立的法律文件，以及安全评估工作需要的其他材料。 时限（第七条）：省级网信部门自收到材料之日起 5 个工作日内完成完备性查验，齐全的报送国家网信部门、不齐全的一次性告知补正；国家网信部门自收到材料之日起 7 个工作日内确定是否受理并书面通知。 评估期限（第十二条）：自发出书面受理通知书之日起 45 个工作日内完成评估，情况复杂或需补正的可适当延长并告知。 复评（第十三条）：对结果有异议的，可在收到结果 15 个工作日内申请复评，复评结果为最终结论。 六、法律文件必备的六项条款 第九条是实务中最易出问题的一环：与境外接收方订立的法律文件中应明确约定数据安全保护责任义务，至少包括——出境目的、方式和数据范围，境外接收方处理数据的用途、方式；数据在境外保存地点、期限及期满或文件终止后的处理措施；对境外接收方再转移给他人的约束性要求；境外接收方实际控制权、经营范围或所在国家（地区）政策法规与网络安全环境变化、不可抗力导致难以保障安全时应采取的措施；违约的补救措施、违约责任和争议解决方式；数据遭篡改、破坏、泄露、丢失、转移或被非法获取、利用时的应急处置要求及个人维权途径。\n提示：这六项是监管审查的直接对照表，建议按项设立独立条款，并与自评估报告表述保持一致，避免\u0026quot;报告写了、合同没写\u0026rdquo;。\n七、有效期与重新申报 新规把有效期由 2 年改为 3 年。第九条：通过安全评估的结果有效期为 3 年，自出具之日起计算；届满需继续开展且未发生重新申报情形的，可在届满前 60 个工作日内通过省级网信部门申请延长，经批准可再延长 3 年。\n有效期内出现下列情形之一的仍需重新申报（《数据出境安全评估办法》第十四条）：出境目的、方式、范围、种类或境外接收方处理数据的用途、方式发生变化影响出境数据安全，或延长境外保存期限的；境外接收方所在国家（地区）政策法规与网络安全环境变化、发生不可抗力、一方实际控制权变化、双方法律文件变更等影响出境数据安全的；其他影响出境数据安全的情形。\n八、容易被忽略的配套义务 评估或标准合同解决的是\u0026quot;出境路径\u0026quot;，出境本身的合法性基础另有一套要求。第十条：向境外提供个人信息的，应当按照法律、行政法规的规定履行告知、取得个人单独同意、进行个人信息保护影响评估等义务。第十一条进一步要求履行数据安全保护义务、采取技术与必要措施，发生或可能发生数据安全事件时采取补救措施并及时向省级以上网信部门和其他有关主管部门报告。\n常见的合规缺口：完成了安全评估申报，却没有同步更新隐私政策中的境外提供告知、没有落实单独同意机制、也没有完成个人信息保护影响评估——这三项与出境路径是并列义务，不能互相替代。\n九、实务清单 先识别重要数据：以主管部门告知或公开发布为准并留存记录，不自行扩大范围； 算清人员规模：按\u0026quot;当年 1 月 1 日起\u0026quot;与\u0026quot;不含敏感个人信息\u0026quot;的口径分别统计； 逐条核对豁免情形（第三至六条），落入豁免的留存业务实质证据； 按第五条六项完成风险自评估，并与法律文件表述一致； 法律文件按第九条六项设置条款，特别是再转移约束与争议解决； 排期与到期管理：预留 5+7 个工作日查验受理与 45 个工作日评估；届满前 60 个工作日判断是否申请延长；同步落实告知、单独同意、影响评估与安全事件报告。 结语 数据出境的合规难点，很少是\u0026quot;制度不知道\u0026quot;，而是\u0026quot;门槛算不准、证据留不住、文书对不上\u0026quot;。2024 年新规之后门槛整体放宽、路径更清晰，但申报与免予申报的边界判断责任仍在企业自己身上：判断错了不会自动获得豁免，判断对了也需要可核验的记录支撑。\n规范依据（供核对）\n《数据出境安全评估办法》，国家互联网信息办公室令第 11 号，2022 年 7 月 7 日公布，2022 年 9 月 1 日起施行。 《个人信息出境标准合同办法》，国家互联网信息办公室令第 13 号，2023 年 2 月 22 日公布。 《促进和规范数据跨境流动规定》，国家互联网信息办公室令第 16 号，2024 年 3 月 22 日公布并施行。 ","permalink":"https://intlaws.com/forum/%E6%95%B0%E6%8D%AE%E5%87%BA%E5%A2%83%E5%AE%89%E5%85%A8%E8%AF%84%E4%BC%B0%E5%AE%9E%E5%8A%A1-%E7%94%B3%E6%8A%A5%E9%97%A8%E6%A7%9B%E4%B8%8E%E5%90%88%E8%A7%84%E8%B7%AF%E5%BE%84/","summary":"数据出境三步判断法与2024年新规三处关键变化：申报门槛由10万人提高至100万人、起算点改为当年1月1日、评估结果有效期由2年延长至3年并可再延长，附五类豁免情形与法律文件六项必备条款。","title":"数据出境安全评估实务：申报门槛、豁免情形与合规路径选择"},{"content":"中华人民共和国个人信息保护法 版本与来源（可核验）\n项目 内容 通过与公布 2021 年 8 月 20 日第十三届全国人民代表大会常务委员会第三十次会议通过 施行日期 2021 年 11 月 1 日 现行有效 是（截至 2026-09-22 未经修订） 中文原文来源 国家互联网信息办公室官方全文：https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm 英文译本来源 全国人民代表大会官网英文版「Laws（Translation for Reference Only）」：http://en.npc.gov.cn.cdurl.cn/2021-12/29/c_694559.htm （正文分 3 页，同名 _2、_3） 译文性质 官网站点发布译本，页面自标「Translation for Reference Only」（仅供参考，不作权威解释） 校对记录 2026-09-22 抓取官方页面；本法 8 章 74 条，中英条目逐一对应、无缺号；章、节标题按官方中文原文节点插入 第一章 总 则 第一条 为了保护个人信息权益，规范个人信息处理活动，促进个人信息合理利用，根据宪法，制定本法。\n第二条 自然人的个人信息受法律保护，任何组织、个人不得侵害自然人的个人信息权益。\n第三条 在中华人民共和国境内处理自然人个人信息的活动，适用本法。 在中华人民共和国境外处理中华人民共和国境内自然人个人信息的活动，有下列情形之一的，也适用本法： （一）以向境内自然人提供产品或者服务为目的； （二）分析、评估境内自然人的行为； （三）法律、行政法规规定的其他情形。\n第四条 个人信息是以电子或者其他方式记录的与已识别或者可识别的自然人有关的各种信息，不包括匿名化处理后的信息。 个人信息的处理包括个人信息的收集、存储、使用、加工、传输、提供、公开、删除等。\n第五条 处理个人信息应当遵循合法、正当、必要和诚信原则，不得通过误导、欺诈、胁迫等方式处理个人信息。\n第六条 处理个人信息应当具有明确、合理的目的，并应当与处理目的直接相关，采取对个人权益影响最小的方式。 收集个人信息，应当限于实现处理目的的最小范围，不得过度收集个人信息。\n第七条 处理个人信息应当遵循公开、透明原则，公开个人信息处理规则，明示处理的目的、方式和范围。\n第八条 处理个人信息应当保证个人信息的质量，避免因个人信息不准确、不完整对个人权益造成不利影响。\n第九条 个人信息处理者应当对其个人信息处理活动负责，并采取必要措施保障所处理的个人信息的安全。\n第十条 任何组织、个人不得非法收集、使用、加工、传输他人个人信息，不得非法买卖、提供或者公开他人个人信息；不得从事危害国家安全、公共利益的个人信息处理活动。\n第十一条 国家建立健全个人信息保护制度，预防和惩治侵害个人信息权益的行为，加强个人信息保护宣传教育，推动形成政府、企业、相关社会组织、公众共同参与个人信息保护的良好环境。\n第十二条 国家积极参与个人信息保护国际规则的制定，促进个人信息保护方面的国际交流与合作，推动与其他国家、地区、国际组织之间的个人信息保护规则、标准等互认。\n第二章 个人信息处理规则 第一节 一般规定 第十三条 符合下列情形之一的，个人信息处理者方可处理个人信息： （一）取得个人的同意； （二）为订立、履行个人作为一方当事人的合同所必需，或者按照依法制定的劳动规章制度和依法签订的集体合同实施人力资源管理所必需； （三）为履行法定职责或者法定义务所必需； （四）为应对突发公共卫生事件，或者紧急情况下为保护自然人的生命健康和财产安全所必需； （五）为公共利益实施新闻报道、舆论监督等行为，在合理的范围内处理个人信息； （六）依照本法规定在合理的范围内处理个人自行公开或者其他已经合法公开的个人信息； （七）法律、行政法规规定的其他情形。 依照本法其他有关规定，处理个人信息应当取得个人同意，但是有前款第二项至第七项规定情形的，不需取得个人同意。\n第十四条 基于个人同意处理个人信息的，该同意应当由个人在充分知情的前提下自愿、明确作出。法律、行政法规规定处理个人信息应当取得个人单独同意或者书面同意的，从其规定。 个人信息的处理目的、处理方式和处理的个人信息种类发生变更的，应当重新取得个人同意。\n第十五条 基于个人同意处理个人信息的，个人有权撤回其同意。个人信息处理者应当提供便捷的撤回同意的方式。 个人撤回同意，不影响撤回前基于个人同意已进行的个人信息处理活动的效力。\n第十六条 个人信息处理者不得以个人不同意处理其个人信息或者撤回同意为由，拒绝提供产品或者服务；处理个人信息属于提供产品或者服务所必需的除外。\n第十七条 个人信息处理者在处理个人信息前，应当以显著方式、清晰易懂的语言真实、准确、完整地向个人告知下列事项： （一）个人信息处理者的名称或者姓名和联系方式； （二）个人信息的处理目的、处理方式，处理的个人信息种类、保存期限； （三）个人行使本法规定权利的方式和程序； （四）法律、行政法规规定应当告知的其他事项。 前款规定事项发生变更的，应当将变更部分告知个人。 个人信息处理者通过制定个人信息处理规则的方式告知第一款规定事项的，处理规则应当公开，并且便于查阅和保存。\n第十八条 个人信息处理者处理个人信息，有法律、行政法规规定应当保密或者不需要告知的情形的，可以不向个人告知前条第一款规定的事项。 紧急情况下为保护自然人的生命健康和财产安全无法及时向个人告知的，个人信息处理者应当在紧急情况消除后及时告知。\n第十九条 除法律、行政法规另有规定外，个人信息的保存期限应当为实现处理目的所必要的最短时间。\n第二十条 两个以上的个人信息处理者共同决定个人信息的处理目的和处理方式的，应当约定各自的权利和义务。但是，该约定不影响个人向其中任何一个个人信息处理者要求行使本法规定的权利。 个人信息处理者共同处理个人信息，侵害个人信息权益造成损害的，应当依法承担连带责任。\n第二十一条 个人信息处理者委托处理个人信息的，应当与受托人约定委托处理的目的、期限、处理方式、个人信息的种类、保护措施以及双方的权利和义务等，并对受托人的个人信息处理活动进行监督。 受托人应当按照约定处理个人信息，不得超出约定的处理目的、处理方式等处理个人信息；委托合同不生效、无效、被撤销或者终止的，受托人应当将个人信息返还个人信息处理者或者予以删除，不得保留。 未经个人信息处理者同意，受托人不得转委托他人处理个人信息。\n第二十二条 个人信息处理者因合并、分立、解散、被宣告破产等原因需要转移个人信息的，应当向个人告知接收方的名称或者姓名和联系方式。接收方应当继续履行个人信息处理者的义务。接收方变更原先的处理目的、处理方式的，应当依照本法规定重新取得个人同意。\n第二十三条 个人信息处理者向其他个人信息处理者提供其处理的个人信息的，应当向个人告知接收方的名称或者姓名、联系方式、处理目的、处理方式和个人信息的种类，并取得个人的单独同意。接收方应当在上述处理目的、处理方式和个人信息的种类等范围内处理个人信息。接收方变更原先的处理目的、处理方式的，应当依照本法规定重新取得个人同意。\n第二十四条 个人信息处理者利用个人信息进行自动化决策，应当保证决策的透明度和结果公平、公正，不得对个人在交易价格等交易条件上实行不合理的差别待遇。 通过自动化决策方式向个人进行信息推送、商业营销，应当同时提供不针对其个人特征的选项，或者向个人提供便捷的拒绝方式。 通过自动化决策方式作出对个人权益有重大影响的决定，个人有权要求个人信息处理者予以说明，并有权拒绝个人信息处理者仅通过自动化决策的方式作出决定。\n第二十五条 个人信息处理者不得公开其处理的个人信息，取得个人单独同意的除外。\n第二十六条 在公共场所安装图像采集、个人身份识别设备，应当为维护公共安全所必需，遵守国家有关规定，并设置显著的提示标识。所收集的个人图像、身份识别信息只能用于维护公共安全的目的，不得用于其他目的；取得个人单独同意的除外。\n第二十七条 个人信息处理者可以在合理的范围内处理个人自行公开或者其他已经合法公开的个人信息；个人明确拒绝的除外。个人信息处理者处理已公开的个人信息，对个人权益有重大影响的，应当依照本法规定取得个人同意。 第二节 敏感个人信息的处理规则\n第二节 敏感个人信息的处理规则 第二十八条 敏感个人信息是一旦泄露或者非法使用，容易导致自然人的人格尊严受到侵害或者人身、财产安全受到危害的个人信息，包括生物识别、宗教信仰、特定身份、医疗健康、金融账户、行踪轨迹等信息，以及不满十四周岁未成年人的个人信息。 只有在具有特定的目的和充分的必要性，并采取严格保护措施的情形下，个人信息处理者方可处理敏感个人信息。\n第二十九条 处理敏感个人信息应当取得个人的单独同意；法律、行政法规规定处理敏感个人信息应当取得书面同意的，从其规定。\n第三十条 个人信息处理者处理敏感个人信息的，除本法第十七条第一款规定的事项外，还应当向个人告知处理敏感个人信息的必要性以及对个人权益的影响；依照本法规定可以不向个人告知的除外。\n第三十一条 个人信息处理者处理不满十四周岁未成年人个人信息的，应当取得未成年人的父母或者其他监护人的同意。 个人信息处理者处理不满十四周岁未成年人个人信息的，应当制定专门的个人信息处理规则。\n第三十二条 法律、行政法规对处理敏感个人信息规定应当取得相关行政许可或者作出其他限制的，从其规定。 第三节 国家机关处理个人信息的特别规定\n第三节 国家机关处理个人信息的特别规定 第三十三条 国家机关处理个人信息的活动，适用本法；本节有特别规定的，适用本节规定。\n第三十四条 国家机关为履行法定职责处理个人信息，应当依照法律、行政法规规定的权限、程序进行，不得超出履行法定职责所必需的范围和限度。\n第三十五条 国家机关为履行法定职责处理个人信息，应当依照本法规定履行告知义务；有本法第十八条第一款规定的情形，或者告知将妨碍国家机关履行法定职责的除外。\n第三十六条 国家机关处理的个人信息应当在中华人民共和国境内存储；确需向境外提供的，应当进行安全评估。安全评估可以要求有关部门提供支持与协助。\n第三十七条 法律、法规授权的具有管理公共事务职能的组织为履行法定职责处理个人信息，适用本法关于国家机关处理个人信息的规定。\n第三章 个人信息跨境提供的规则 第三十八条 个人信息处理者因业务等需要，确需向中华人民共和国境外提供个人信息的，应当具备下列条件之一： （一）依照本法第四十条的规定通过国家网信部门组织的安全评估； （二）按照国家网信部门的规定经专业机构进行个人信息保护认证； （三）按照国家网信部门制定的标准合同与境外接收方订立合同，约定双方的权利和义务； （四）法律、行政法规或者国家网信部门规定的其他条件。 中华人民共和国缔结或者参加的国际条约、协定对向中华人民共和国境外提供个人信息的条件等有规定的，可以按照其规定执行。 个人信息处理者应当采取必要措施，保障境外接收方处理个人信息的活动达到本法规定的个人信息保护标准。\n第三十九条 个人信息处理者向中华人民共和国境外提供个人信息的，应当向个人告知境外接收方的名称或者姓名、联系方式、处理目的、处理方式、个人信息的种类以及个人向境外接收方行使本法规定权利的方式和程序等事项，并取得个人的单独同意。\n第四十条 关键信息基础设施运营者和处理个人信息达到国家网信部门规定数量的个人信息处理者，应当将在中华人民共和国境内收集和产生的个人信息存储在境内。确需向境外提供的，应当通过国家网信部门组织的安全评估；法律、行政法规和国家网信部门规定可以不进行安全评估的，从其规定。\n第四十一条 中华人民共和国主管机关根据有关法律和中华人民共和国缔结或者参加的国际条约、协定，或者按照平等互惠原则，处理外国司法或者执法机构关于提供存储于境内个人信息的请求。非经中华人民共和国主管机关批准，个人信息处理者不得向外国司法或者执法机构提供存储于中华人民共和国境内的个人信息。\n第四十二条 境外的组织、个人从事侵害中华人民共和国公民的个人信息权益，或者危害中华人民共和国国家安全、公共利益的个人信息处理活动的，国家网信部门可以将其列入限制或者禁止个人信息提供清单，予以公告，并采取限制或者禁止向其提供个人信息等措施。\n第四十三条 任何国家或者地区在个人信息保护方面对中华人民共和国采取歧视性的禁止、限制或者其他类似措施的，中华人民共和国可以根据实际情况对该国家或者地区对等采取措施。\n第四章 个人在个人信息处理活动中的权利 第四十四条 个人对其个人信息的处理享有知情权、决定权，有权限制或者拒绝他人对其个人信息进行处理；法律、行政法规另有规定的除外。\n第四十五条 个人有权向个人信息处理者查阅、复制其个人信息；有本法第十八条第一款、第三十五条规定情形的除外。 个人请求查阅、复制其个人信息的，个人信息处理者应当及时提供。 个人请求将个人信息转移至其指定的个人信息处理者，符合国家网信部门规定条件的，个人信息处理者应当提供转移的途径。\n第四十六条 个人发现其个人信息不准确或者不完整的，有权请求个人信息处理者更正、补充。 个人请求更正、补充其个人信息的，个人信息处理者应当对其个人信息予以核实，并及时更正、补充。\n第四十七条 有下列情形之一的，个人信息处理者应当主动删除个人信息；个人信息处理者未删除的，个人有权请求删除： （一）处理目的已实现、无法实现或者为实现处理目的不再必要； （二）个人信息处理者停止提供产品或者服务，或者保存期限已届满； （三）个人撤回同意； （四）个人信息处理者违反法律、行政法规或者违反约定处理个人信息； （五）法律、行政法规规定的其他情形。 法律、行政法规规定的保存期限未届满，或者删除个人信息从技术上难以实现的，个人信息处理者应当停止除存储和采取必要的安全保护措施之外的处理。\n第四十八条 个人有权要求个人信息处理者对其个人信息处理规则进行解释说明。\n第四十九条 自然人死亡的，其近亲属为了自身的合法、正当利益，可以对死者的相关个人信息行使本章规定的查阅、复制、更正、删除等权利；死者生前另有安排的除外。\n第五十条 个人信息处理者应当建立便捷的个人行使权利的申请受理和处理机制。拒绝个人行使权利的请求的，应当说明理由。 个人信息处理者拒绝个人行使权利的请求的，个人可以依法向人民法院提起诉讼。\n第五章 个人信息处理者的义务 第五十一条 个人信息处理者应当根据个人信息的处理目的、处理方式、个人信息的种类以及对个人权益的影响、可能存在的安全风险等，采取下列措施确保个人信息处理活动符合法律、行政法规的规定，并防止未经授权的访问以及个人信息泄露、篡改、丢失： （一）制定内部管理制度和操作规程； （二）对个人信息实行分类管理； （三）采取相应的加密、去标识化等安全技术措施； （四）合理确定个人信息处理的操作权限，并定期对从业人员进行安全教育和培训； （五）制定并组织实施个人信息安全事件应急预案； （六）法律、行政法规规定的其他措施。\n第五十二条 处理个人信息达到国家网信部门规定数量的个人信息处理者应当指定个人信息保护负责人，负责对个人信息处理活动以及采取的保护措施等进行监督。 个人信息处理者应当公开个人信息保护负责人的联系方式，并将个人信息保护负责人的姓名、联系方式等报送履行个人信息保护职责的部门。\n第五十三条 本法第三条第二款规定的中华人民共和国境外的个人信息处理者，应当在中华人民共和国境内设立专门机构或者指定代表，负责处理个人信息保护相关事务，并将有关机构的名称或者代表的姓名、联系方式等报送履行个人信息保护职责的部门。\n第五十四条 个人信息处理者应当定期对其处理个人信息遵守法律、行政法规的情况进行合规审计。\n第五十五条 有下列情形之一的，个人信息处理者应当事前进行个人信息保护影响评估，并对处理情况进行记录： （一）处理敏感个人信息； （二）利用个人信息进行自动化决策； （三）委托处理个人信息、向其他个人信息处理者提供个人信息、公开个人信息； （四）向境外提供个人信息； （五）其他对个人权益有重大影响的个人信息处理活动。\n第五十六条 个人信息保护影响评估应当包括下列内容： （一）个人信息的处理目的、处理方式等是否合法、正当、必要； （二）对个人权益的影响及安全风险； （三）所采取的保护措施是否合法、有效并与风险程度相适应。 个人信息保护影响评估报告和处理情况记录应当至少保存三年。\n第五十七条 发生或者可能发生个人信息泄露、篡改、丢失的，个人信息处理者应当立即采取补救措施，并通知履行个人信息保护职责的部门和个人。通知应当包括下列事项： （一）发生或者可能发生个人信息泄露、篡改、丢失的信息种类、原因和可能造成的危害； （二）个人信息处理者采取的补救措施和个人可以采取的减轻危害的措施； （三）个人信息处理者的联系方式。 个人信息处理者采取措施能够有效避免信息泄露、篡改、丢失造成危害的，个人信息处理者可以不通知个人；履行个人信息保护职责的部门认为可能造成危害的，有权要求个人信息处理者通知个人。\n第五十八条 提供重要互联网平台服务、用户数量巨大、业务类型复杂的个人信息处理者，应当履行下列义务： （一）按照国家规定建立健全个人信息保护合规制度体系，成立主要由外部成员组成的独立机构对个人信息保护情况进行监督； （二）遵循公开、公平、公正的原则，制定平台规则，明确平台内产品或者服务提供者处理个人信息的规范和保护个人信息的义务； （三）对严重违反法律、行政法规处理个人信息的平台内的产品或者服务提供者，停止提供服务； （四）定期发布个人信息保护社会责任报告，接受社会监督。\n第五十九条 接受委托处理个人信息的受托人，应当依照本法和有关法律、行政法规的规定，采取必要措施保障所处理的个人信息的安全，并协助个人信息处理者履行本法规定的义务。\n第六章 履行个人信息保护职责的部门 第六十条 国家网信部门负责统筹协调个人信息保护工作和相关监督管理工作。国务院有关部门依照本法和有关法律、行政法规的规定，在各自职责范围内负责个人信息保护和监督管理工作。 县级以上地方人民政府有关部门的个人信息保护和监督管理职责，按照国家有关规定确定。 前两款规定的部门统称为履行个人信息保护职责的部门。\n第六十一条 履行个人信息保护职责的部门履行下列个人信息保护职责： （一）开展个人信息保护宣传教育，指导、监督个人信息处理者开展个人信息保护工作； （二）接受、处理与个人信息保护有关的投诉、举报； （三）组织对应用程序等个人信息保护情况进行测评，并公布测评结果； （四）调查、处理违法个人信息处理活动； （五）法律、行政法规规定的其他职责。\n第六十二条 国家网信部门统筹协调有关部门依据本法推进下列个人信息保护工作： （一）制定个人信息保护具体规则、标准； （二）针对小型个人信息处理者、处理敏感个人信息以及人脸识别、人工智能等新技术、新应用，制定专门的个人信息保护规则、标准； （三）支持研究开发和推广应用安全、方便的电子身份认证技术，推进网络身份认证公共服务建设； （四）推进个人信息保护社会化服务体系建设，支持有关机构开展个人信息保护评估、认证服务； （五）完善个人信息保护投诉、举报工作机制。\n第六十三条 履行个人信息保护职责的部门履行个人信息保护职责，可以采取下列措施： （一）询问有关当事人，调查与个人信息处理活动有关的情况； （二）查阅、复制当事人与个人信息处理活动有关的合同、记录、账簿以及其他有关资料； （三）实施现场检查，对涉嫌违法的个人信息处理活动进行调查； （四）检查与个人信息处理活动有关的设备、物品；对有证据证明是用于违法个人信息处理活动的设备、物品，向本部门主要负责人书面报告并经批准，可以查封或者扣押。 履行个人信息保护职责的部门依法履行职责，当事人应当予以协助、配合，不得拒绝、阻挠。\n第六十四条 履行个人信息保护职责的部门在履行职责中，发现个人信息处理活动存在较大风险或者发生个人信息安全事件的，可以按照规定的权限和程序对该个人信息处理者的法定代表人或者主要负责人进行约谈，或者要求个人信息处理者委托专业机构对其个人信息处理活动进行合规审计。个人信息处理者应当按照要求采取措施，进行整改，消除隐患。 履行个人信息保护职责的部门在履行职责中，发现违法处理个人信息涉嫌犯罪的，应当及时移送公安机关依法处理。\n第六十五条 任何组织、个人有权对违法个人信息处理活动向履行个人信息保护职责的部门进行投诉、举报。收到投诉、举报的部门应当依法及时处理，并将处理结果告知投诉、举报人。 履行个人信息保护职责的部门应当公布接受投诉、举报的联系方式。\n第七章 法律责任 第六十六条 违反本法规定处理个人信息，或者处理个人信息未履行本法规定的个人信息保护义务的，由履行个人信息保护职责的部门责令改正，给予警告，没收违法所得，对违法处理个人信息的应用程序，责令暂停或者终止提供服务；拒不改正的，并处一百万元以下罚款；对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。 有前款规定的违法行为，情节严重的，由省级以上履行个人信息保护职责的部门责令改正，没收违法所得，并处五千万元以下或者上一年度营业额百分之五以下罚款，并可以责令暂停相关业务或者停业整顿、通报有关主管部门吊销相关业务许可或者吊销营业执照；对直接负责的主管人员和其他直接责任人员处十万元以上一百万元以下罚款，并可以决定禁止其在一定期限内担任相关企业的董事、监事、高级管理人员和个人信息保护负责人。\n第六十七条 有本法规定的违法行为的，依照有关法律、行政法规的规定记入信用档案，并予以公示。\n第六十八条 国家机关不履行本法规定的个人信息保护义务的，由其上级机关或者履行个人信息保护职责的部门责令改正；对直接负责的主管人员和其他直接责任人员依法给予处分。 履行个人信息保护职责的部门的工作人员玩忽职守、滥用职权、徇私舞弊，尚不构成犯罪的，依法给予处分。\n第六十九条 处理个人信息侵害个人信息权益造成损害，个人信息处理者不能证明自己没有过错的，应当承担损害赔偿等侵权责任。 前款规定的损害赔偿责任按照个人因此受到的损失或者个人信息处理者因此获得的利益确定；个人因此受到的损失和个人信息处理者因此获得的利益难以确定的，根据实际情况确定赔偿数额。\n第七十条 个人信息处理者违反本法规定处理个人信息，侵害众多个人的权益的，人民检察院、法律规定的消费者组织和由国家网信部门确定的组织可以依法向人民法院提起诉讼。\n第七十一条 违反本法规定，构成违反治安管理行为的，依法给予治安管理处罚；构成犯罪的，依法追究刑事责任。\n第八章 附 则 第七十二条 自然人因个人或者家庭事务处理个人信息的，不适用本法。 法律对各级人民政府及其有关部门组织实施的统计、档案管理活动中的个人信息处理有规定的，适用其规定。\n第七十三条 本法下列用语的含义： （一）个人信息处理者，是指在个人信息处理活动中自主决定处理目的、处理方式的组织、个人。 （二）自动化决策，是指通过计算机程序自动分析、评估个人的行为习惯、兴趣爱好或者经济、健康、信用状况等，并进行决策的活动。 （三）去标识化，是指个人信息经过处理，使其在不借助额外信息的情况下无法识别特定自然人的过程。 （四）匿名化，是指个人信息经过处理无法识别特定自然人且不能复原的过程。\n第七十四条 本法自2021年11月1日起施行。 关闭 中央网络安全和信息化委员会办公室 中华人民共和国国家互联网信息办公室 © 版权所有 联系我们 承办：国家互联网应急中心 技术支持：长安通信科技有限责任公司 京ICP备14042428号 京公网安备11040102700108号 学习强国 ◆ ◆ 微信 ◆ ◆ 返回顶部 中央网络安全和信息化委员会办公室 中华人民共和国国家互联网信息办公室 © 版权所有 承办：国家互联网应急中心 技术支持：长安通信科技有限责任公司 京ICP备14042428号 京公网安备11040102700108号 PC版 Produced By CMS 网站群内容管理系统 publishdate:2025/09/26 13:38:44\n","permalink":"https://intlaws.com/compliance/china/pipl/","summary":"《中华人民共和国个人信息保护法》官方全文：8 章 74 条，2021 年 8 月 20 日通过、2021 年 11 月 1 日施行。中文原文取自国家互联网信息办公室官方发布；英文译本取自全国人民代表大会官网英文版（页面自标\u0026quot;仅供参考\u0026quot;）。","title":"中华人民共和国个人信息保护法（全文）"},{"content":"中华人民共和国数据安全法 版本与来源（可核验）\n项目 内容 通过与公布 2021 年 6 月 10 日第十三届全国人民代表大会常务委员会第二十九次会议通过 施行日期 2021 年 9 月 1 日 现行有效 是（截至 2026-09-22 未经修订） 中文原文来源 国家互联网信息办公室官方全文：https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm 英文译本来源 全国人民代表大会官网英文版「Laws（Translation for Reference Only）」：http://en.npc.gov.cn.cdurl.cn/2021-06/10/c_689311.htm （正文分 2 页） 译文性质 官网站点发布译本，页面自标「Translation for Reference Only」（仅供参考） 校对记录 2026-09-22 抓取官方页面；7 章 55 条，中英条目一一对应、无缺号 第一章 总则 第一条 为了规范数据处理活动，保障数据安全，促进数据开发利用，保护个人、组织的合法权益，维护国家主权、安全和发展利益，制定本法。\n第二条 在中华人民共和国境内开展数据处理活动及其安全监管，适用本法。 在中华人民共和国境外开展数据处理活动，损害中华人民共和国国家安全、公共利益或者公民、组织合法权益的，依法追究法律责任。\n第三条 本法所称数据，是指任何以电子或者其他方式对信息的记录。 数据处理，包括数据的收集、存储、使用、加工、传输、提供、公开等。 数据安全，是指通过采取必要措施，确保数据处于有效保护和合法利用的状态，以及具备保障持续安全状态的能力。\n第四条 维护数据安全，应当坚持总体国家安全观，建立健全数据安全治理体系，提高数据安全保障能力。\n第五条 中央国家安全领导机构负责国家数据安全工作的决策和议事协调，研究制定、指导实施国家数据安全战略和有关重大方针政策，统筹协调国家数据安全的重大事项和重要工作，建立国家数据安全工作协调机制。\n第六条 各地区、各部门对本地区、本部门工作中收集和产生的数据及数据安全负责。 工业、电信、交通、金融、自然资源、卫生健康、教育、科技等主管部门承担本行业、本领域数据安全监管职责。 公安机关、国家安全机关等依照本法和有关法律、行政法规的规定，在各自职责范围内承担数据安全监管职责。 国家网信部门依照本法和有关法律、行政法规的规定，负责统筹协调网络数据安全和相关监管工作。\n第七条 国家保护个人、组织与数据有关的权益，鼓励数据依法合理有效利用，保障数据依法有序自由流动，促进以数据为关键要素的数字经济发展。\n第八条 开展数据处理活动，应当遵守法律、法规，尊重社会公德和伦理，遵守商业道德和职业道德，诚实守信，履行数据安全保护义务，承担社会责任，不得危害国家安全、公共利益，不得损害个人、组织的合法权益。\n第九条 国家支持开展数据安全知识宣传普及，提高全社会的数据安全保护意识和水平，推动有关部门、行业组织、科研机构、企业、个人等共同参与数据安全保护工作，形成全社会共同维护数据安全和促进发展的良好环境。\n第十条 相关行业组织按照章程，依法制定数据安全行为规范和团体标准，加强行业自律，指导会员加强数据安全保护，提高数据安全保护水平，促进行业健康发展。\n第十一条 国家积极开展数据安全治理、数据开发利用等领域的国际交流与合作，参与数据安全相关国际规则和标准的制定，促进数据跨境安全、自由流动。\n第十二条 任何个人、组织都有权对违反本法规定的行为向有关主管部门投诉、举报。收到投诉、举报的部门应当及时依法处理。 有关主管部门应当对投诉、举报人的相关信息予以保密，保护投诉、举报人的合法权益。\n第二章 数据安全与发展 第十三条 国家统筹发展和安全，坚持以数据开发利用和产业发展促进数据安全，以数据安全保障数据开发利用和产业发展。\n第十四条 国家实施大数据战略，推进数据基础设施建设，鼓励和支持数据在各行业、各领域的创新应用。 省级以上人民政府应当将数字经济发展纳入本级国民经济和社会发展规划，并根据需要制定数字经济发展规划。\n第十五条 国家支持开发利用数据提升公共服务的智能化水平。提供智能化公共服务，应当充分考虑老年人、残疾人的需求，避免对老年人、残疾人的日常生活造成障碍。\n第十六条 国家支持数据开发利用和数据安全技术研究，鼓励数据开发利用和数据安全等领域的技术推广和商业创新，培育、发展数据开发利用和数据安全产品、产业体系。\n第十七条 国家推进数据开发利用技术和数据安全标准体系建设。国务院标准化行政主管部门和国务院有关部门根据各自的职责，组织制定并适时修订有关数据开发利用技术、产品和数据安全相关标准。国家支持企业、社会团体和教育、科研机构等参与标准制定。\n第十八条 国家促进数据安全检测评估、认证等服务的发展，支持数据安全检测评估、认证等专业机构依法开展服务活动。 国家支持有关部门、行业组织、企业、教育和科研机构、有关专业机构等在数据安全风险评估、防范、处置等方面开展协作。\n第十九条 国家建立健全数据交易管理制度，规范数据交易行为，培育数据交易市场。\n第二十条 国家支持教育、科研机构和企业等开展数据开发利用技术和数据安全相关教育和培训，采取多种方式培养数据开发利用技术和数据安全专业人才，促进人才交流。\n第三章 数据安全制度 第二十一条 国家建立数据分类分级保护制度，根据数据在经济社会发展中的重要程度，以及一旦遭到篡改、破坏、泄露或者非法获取、非法利用，对国家安全、公共利益或者个人、组织合法权益造成的危害程度，对数据实行分类分级保护。国家数据安全工作协调机制统筹协调有关部门制定重要数据目录，加强对重要数据的保护。 关系国家安全、国民经济命脉、重要民生、重大公共利益等数据属于国家核心数据，实行更加严格的管理制度。 各地区、各部门应当按照数据分类分级保护制度，确定本地区、本部门以及相关行业、领域的重要数据具体目录，对列入目录的数据进行重点保护。\n第二十二条 国家建立集中统一、高效权威的数据安全风险评估、报告、信息共享、监测预警机制。国家数据安全工作协调机制统筹协调有关部门加强数据安全风险信息的获取、分析、研判、预警工作。\n第二十三条 国家建立数据安全应急处置机制。发生数据安全事件，有关主管部门应当依法启动应急预案，采取相应的应急处置措施，防止危害扩大，消除安全隐患，并及时向社会发布与公众有关的警示信息。\n第二十四条 国家建立数据安全审查制度，对影响或者可能影响国家安全的数据处理活动进行国家安全审查。 依法作出的安全审查决定为最终决定。\n第二十五条 国家对与维护国家安全和利益、履行国际义务相关的属于管制物项的数据依法实施出口管制。\n第二十六条 任何国家或者地区在与数据和数据开发利用技术等有关的投资、贸易等方面对中华人民共和国采取歧视性的禁止、限制或者其他类似措施的，中华人民共和国可以根据实际情况对该国家或者地区对等采取措施。\n第四章 数据安全保护义务 第二十七条 开展数据处理活动应当依照法律、法规的规定，建立健全全流程数据安全管理制度，组织开展数据安全教育培训，采取相应的技术措施和其他必要措施，保障数据安全。利用互联网等信息网络开展数据处理活动，应当在网络安全等级保护制度的基础上，履行上述数据安全保护义务。 重要数据的处理者应当明确数据安全负责人和管理机构，落实数据安全保护责任。\n第二十八条 开展数据处理活动以及研究开发数据新技术，应当有利于促进经济社会发展，增进人民福祉，符合社会公德和伦理。\n第二十九条 开展数据处理活动应当加强风险监测，发现数据安全缺陷、漏洞等风险时，应当立即采取补救措施；发生数据安全事件时，应当立即采取处置措施，按照规定及时告知用户并向有关主管部门报告。\n第三十条 重要数据的处理者应当按照规定对其数据处理活动定期开展风险评估，并向有关主管部门报送风险评估报告。 风险评估报告应当包括处理的重要数据的种类、数量，开展数据处理活动的情况，面临的数据安全风险及其应对措施等。\n第三十一条 关键信息基础设施的运营者在中华人民共和国境内运营中收集和产生的重要数据的出境安全管理，适用《中华人民共和国网络安全法》的规定；其他数据处理者在中华人民共和国境内运营中收集和产生的重要数据的出境安全管理办法，由国家网信部门会同国务院有关部门制定。\n第三十二条 任何组织、个人收集数据，应当采取合法、正当的方式，不得窃取或者以其他非法方式获取数据。 法律、行政法规对收集、使用数据的目的、范围有规定的，应当在法律、行政法规规定的目的和范围内收集、使用数据。\n第三十三条 从事数据交易中介服务的机构提供服务，应当要求数据提供方说明数据来源，审核交易双方的身份，并留存审核、交易记录。\n第三十四条 法律、行政法规规定提供数据处理相关服务应当取得行政许可的，服务提供者应当依法取得许可。\n第三十五条 公安机关、国家安全机关因依法维护国家安全或者侦查犯罪的需要调取数据，应当按照国家有关规定，经过严格的批准手续，依法进行，有关组织、个人应当予以配合。\n第三十六条 中华人民共和国主管机关根据有关法律和中华人民共和国缔结或者参加的国际条约、协定，或者按照平等互惠原则，处理外国司法或者执法机构关于提供数据的请求。非经中华人民共和国主管机关批准，境内的组织、个人不得向外国司法或者执法机构提供存储于中华人民共和国境内的数据。\n第五章 政务数据安全与开放 第三十七条 国家大力推进电子政务建设，提高政务数据的科学性、准确性、时效性，提升运用数据服务经济社会发展的能力。\n第三十八条 国家机关为履行法定职责的需要收集、使用数据，应当在其履行法定职责的范围内依照法律、行政法规规定的条件和程序进行；对在履行职责中知悉的个人隐私、个人信息、商业秘密、保密商务信息等数据应当依法予以保密，不得泄露或者非法向他人提供。\n第三十九条 国家机关应当依照法律、行政法规的规定，建立健全数据安全管理制度，落实数据安全保护责任，保障政务数据安全。\n第四十条 国家机关委托他人建设、维护电子政务系统，存储、加工政务数据，应当经过严格的批准程序，并应当监督受托方履行相应的数据安全保护义务。受托方应当依照法律、法规的规定和合同约定履行数据安全保护义务，不得擅自留存、使用、泄露或者向他人提供政务数据。\n第四十一条 国家机关应当遵循公正、公平、便民的原则，按照规定及时、准确地公开政务数据。依法不予公开的除外。\n第四十二条 国家制定政务数据开放目录，构建统一规范、互联互通、安全可控的政务数据开放平台，推动政务数据开放利用。\n第四十三条 法律、法规授权的具有管理公共事务职能的组织为履行法定职责开展数据处理活动，适用本章规定。\n第六章 法律责任 第四十四条 有关主管部门在履行数据安全监管职责中，发现数据处理活动存在较大安全风险的，可以按照规定的权限和程序对有关组织、个人进行约谈，并要求有关组织、个人采取措施进行整改，消除隐患。\n第四十五条 开展数据处理活动的组织、个人不履行本法第二十七条、第二十九条、第三十条规定的数据安全保护义务的，由有关主管部门责令改正，给予警告，可以并处五万元以上五十万元以下罚款，对直接负责的主管人员和其他直接责任人员可以处一万元以上十万元以下罚款；拒不改正或者造成大量数据泄露等严重后果的，处五十万元以上二百万元以下罚款，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处五万元以上二十万元以下罚款。 违反国家核心数据管理制度，危害国家主权、安全和发展利益的，由有关主管部门处二百万元以上一千万元以下罚款，并根据情况责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照；构成犯罪的，依法追究刑事责任。\n第四十六条 违反本法第三十一条规定，向境外提供重要数据的，由有关主管部门责令改正，给予警告，可以并处十万元以上一百万元以下罚款，对直接负责的主管人员和其他直接责任人员可以处一万元以上十万元以下罚款；情节严重的，处一百万元以上一千万元以下罚款，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处十万元以上一百万元以下罚款。\n第四十七条 从事数据交易中介服务的机构未履行本法第三十三条规定的义务的，由有关主管部门责令改正，没收违法所得，处违法所得一倍以上十倍以下罚款，没有违法所得或者违法所得不足十万元的，处十万元以上一百万元以下罚款，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照；对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。\n第四十八条 违反本法第三十五条规定，拒不配合数据调取的，由有关主管部门责令改正，给予警告，并处五万元以上五十万元以下罚款，对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。 违反本法第三十六条规定，未经主管机关批准向外国司法或者执法机构提供数据的，由有关主管部门给予警告，可以并处十万元以上一百万元以下罚款，对直接负责的主管人员和其他直接责任人员可以处一万元以上十万元以下罚款；造成严重后果的，处一百万元以上五百万元以下罚款，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处五万元以上五十万元以下罚款。\n第四十九条 国家机关不履行本法规定的数据安全保护义务的，对直接负责的主管人员和其他直接责任人员依法给予处分。\n第五十条 履行数据安全监管职责的国家工作人员玩忽职守、滥用职权、徇私舞弊的，依法给予处分。\n第五十一条 窃取或者以其他非法方式获取数据，开展数据处理活动排除、限制竞争，或者损害个人、组织合法权益的，依照有关法律、行政法规的规定处罚。\n第五十二条 违反本法规定，给他人造成损害的，依法承担民事责任。 违反本法规定，构成违反治安管理行为的，依法给予治安管理处罚；构成犯罪的，依法追究刑事责任。\n第七章 附则 第五十三条 开展涉及国家秘密的数据处理活动，适用《中华人民共和国保守国家秘密法》等法律、行政法规的规定。 在统计、档案工作中开展数据处理活动，开展涉及个人信息的数据处理活动，还应当遵守有关法律、行政法规的规定。\n第五十四条 军事数据安全保护的办法，由中央军事委员会依据本法另行制定。\n第五十五条 本法自2021年9月1日起施行。 关闭 中央网络安全和信息化委员会办公室 中华人民共和国国家互联网信息办公室 © 版权所有 联系我们 承办：国家互联网应急中心 技术支持：长安通信科技有限责任公司 京ICP备14042428号 京公网安备11040102700108号 学习强国 ◆ ◆ 微信 ◆ ◆ 返回顶部 中央网络安全和信息化委员会办公室 中华人民共和国国家互联网信息办公室 © 版权所有 承办：国家互联网应急中心 技术支持：长安通信科技有限责任公司 京ICP备14042428号 京公网安备11040102700108号 PC版 Produced By CMS 网站群内容管理系统 publishdate:2024/01/05 22:08:29\n","permalink":"https://intlaws.com/compliance/china/dsl/","summary":"《中华人民共和国数据安全法》官方全文：7 章 55 条，2021 年 6 月 10 日通过、2021 年 9 月 1 日施行。中文原文取自国家互联网信息办公室官方发布；英文译本取自全国人民代表大会官网英文版（页面自标\u0026quot;仅供参考\u0026quot;）。","title":"中华人民共和国数据安全法（全文）"},{"content":"中华人民共和国网络安全法(2025 年修正) 项目 内容 法域 中国 立法层级 法律 原文名称 中华人民共和国网络安全法 英文名称 Cybersecurity Law of the People\u0026rsquo;s Republic of China 通过与公布 2016-11-07 第十二届全国人民代表大会常务委员会第二十四次会议通过 最近修订 2025-10-28 第十四届全国人民代表大会常务委员会第十八次会议通过《关于修改〈中华人民共和国网络安全法〉的决定》修正 生效/施行 原法 2017-06-01 施行;修改决定自 2026-01-01 起施行,修正后全文重新公布 主管机关 国家网信部门统筹协调;公安、工信等部门依职责分工负责 适用范围 在中国境内建设、运营、维护和使用网络,以及网络安全的监督管理 议题标签 数据合规 / 人工智能治理(衔接条款) 状态 现行有效(2025 年修正,2026-01-01 起适用) 官方原文链接 修改决定(中国人大网):http://www.npc.gov.cn/c2/c30834/202510/t20251028_449048.html 修正后全文(CAC 转载中国人大网):https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm 修改决定(CAC):https://www.cac.gov.cn/2025-10/29/c_1763461514768457.htm 核验日期 2026-09-22 一、本次修改的官方口径 据新华社权威快报(2025-10-28):十四届全国人大常委会第十八次会议表决通过修改决定,自 2026 年 1 月 1 日起施行;此次修改\u0026quot;适应网络安全新形势新要求,重点强化网络安全法律责任,加强与相关法律的衔接协调\u0026quot;,并\u0026quot;回应人工智能治理和促进\u0026quot;相关要求。\n上述为官方报道的修改要旨;具体条文增删与罚则幅度的逐条比对属下一步工作,未逐条核实前不在本档案给出结论。\n二、制度框架(修正后目录结构) 第一章 总则 / 第二章 网络安全支持与促进 / 第三章 网络运行安全(第一节 一般规定;第二节 关键信息基础设施的运行安全)/ 第四章 网络信息安全 / 第五章 监测预警与应急处置 / 第六章 法律责任 / 第七章 附则。\n来源:修正后全文目录(CAC 转载中国人大网)。\n三、与其他规范的关系 与《数据安全法》《个人信息保护法》共同构成中国数据治理的基础性法律层;本次修改的官方表述即强调\u0026quot;加强与相关法律的衔接协调\u0026quot;; 与《网络数据安全管理条例》(行政法规)形成\u0026quot;法律—行政法规\u0026quot;的层级衔接; 人工智能治理方面的条款属\u0026quot;衔接性回应\u0026quot;,具体内容待与修正后全文逐条核对。 四、动态观察点 修正后全文与旧文本的逐条比对(尤其是法律责任章、关键信息基础设施部分); 配套部门规章、国标(TC260)是否随之修订; 2026-01-01 起适用后的首批执法案例。 五、相关产出 数智知库同批档案:[[中华人民共和国数据安全法]]、[[中华人民共和国个人信息保护法]] 本站/站内既有材料:[2026-09-22/数据出境安全评估实务-申报门槛与合规路径] 六、来源 中国人大网:修改决定全文(2025-10-28) 中央网络安全和信息化委员会办公室:修改决定、修正后法律全文 新华社:权威快报《网络安全法完成修改》(2025-10-28) ","permalink":"https://intlaws.com/compliance/china/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E6%B3%95-2025%E5%B9%B4%E4%BF%AE%E6%AD%A3/","summary":"《网络安全法》2025 年修正档案：2025-10-28 通过修改决定、2026-01-01 起施行。梳理修正重点、法律责任强化与配套义务框架，附官方原文与核验记录。","title":"中华人民共和国网络安全法(2025 年修正)"}]