Chinese governments has warned 222 apps to remove data slurping code
Full article1,020 words · extracted from therecord.media · click to collapse
Three weeks after a data privacy protection law has entered into effect in China, the Beijing government has begun warning mobile app developers to remove intrusive data slurping code that collects unnecessary user information beyond an application's primary scope. The new Personal Information Protection Law was drafted last fall and approved earlier this year in March, entering into effect on May 1, 2021. The law follows a simple principle—namely that an app or website must collect only the user information they strictly need to achieve their primary functions. Any collected data that is not used to deliver an app or website feature is considered unnecessary and opens the door for the Chinese government to impose giant GDPR-like fines of up to 50 million yuan ($7.77 million) or 5% of a company's annual revenue. To help tech companies put their affairs in order, the Cyberspace Administration of China (CAC) published in March a guideline with what type of information apps were allowed to collect, based on 39 categories: But as soon as the law came into effect on May 1, the Chinese government wanted to send a signal to its tech sector that they were intent on enacting its new user privacy restrictions. On the same day, the CAC issued its first warning, naming 33 applications—15 keyboard apps, 17 map navigation apps, and an instant messaging client—that have been observed collecting too much user information. The CAC issued a second warning a week later, on May 10, when it put another 84 applications on notice, this time 36 cybersecurity and 48 online lending apps. Today, the CAC issued its third warning. The bulkiest one yet, this one listed 105 apps, naming 19 short video apps, 34 web browsers, 51 job-searching apps, and a general utility app. While the second warning put Tencent and Baidu on notice, today's Beijing announcement has put TikTok and Microsoft (through its LinkedIn app) on the hot seat as well. The CAC has given all the app makers listed in its alerts 15 days to remove the data slurping code or face its steep fines, which the government seems intent to apply, as an early warning shot that it means business. The recent warnings come as part of a wider government crackdown on the Chinese tech sector. Through unfettered data collection, many Chinese tech companies have become multi-billion dollar behemoths and have slowly started to believe they could assume independence from Beijing's strict control and leadership, a trend the Chinese Communist Party is trying to stamp out. Furthermore, in recent years, much of the data collected by Chinese companies has also often leaked online or has been stolen by hackers, primarily due to overzealous collection and improper data storage practices. These vasts amounts of leaked data are an operational-security (OpSec) gold mine for foreign security intelligence agencies, and is why the Chinese Ministry of Public Security was also involved in the law's drafting process.Tech companies have been warned in March
Beijing starts enacting its new law
Some big names caught in Beijing's cross-hairs
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/chinese-governments-has-warned-222-apps-to-remove-data-slurping-code