论文部分内容阅读
Writer Wang Xiaoshan had enough. Never again would he set down his chopsticks during supper to answer an unsolicited phone call from a real estate agent.
On December 26, 2012, Wang microblogged a simulated wanted poster offering a 1,000-yuan ($161) reward for the phone number of Zuo Hui, President of Homelink, one of the largest real estate brokers in the country.
China’s human flesh search engine delivered Zuo’s phone number, which Wang posted the next day to the applause of many for whom aggressive telemarketing is a familiar yet unwanted intrusion into personal privacy.
Ironically, legal experts warned that Wang’s tit-for-tat response might have violated Zuo’s personal privacy. Nevertheless, Wang demanded Homelink reveal how it obtained his personal information. The company refused to do so while offering its apology for the intrusive calls.
A real estate broker in Anhui told China Radio Network that the sale and purchase of client data is standard operating procedure in the industry. Information clients do not voluntarily offer is bought from property management firms or online information vendors.
Wang’s determination to protect his personal information came two days before the Standing Committee of the National People’s Congress (NPC), China’s top legislature, passed a decision on strengthening online information protection on December 28.
The decision, as legally binding as a law, is intended to better protect Internet user privacy and provide a legal basis for safeguarding online information security, so as to ensure the healthy and orderly development of the Web, said a spokesman for the NPC Standing Committee.
“The law represents progress in China’s legal system and maturity in social management,” said Li Yuxiao, Director of Internet Governance and Legal Research Center at Beijing University of Posts and Telecommunications.

Main points
The decision provides legal protection for information that can be used to identify a citizen, or that which involves privacy, and bans illegal acquisition, sale and purchase of data. Personal information can only be obtained with prior consent.
It requires Internet service providers and public institutions to clearly state the purposes, means and scope of all data collection efforts. Information collected must be relevant to business operations.
Organizations are further required to maintain confidentiality, and are forbidden to leak, tamper with, damage, sell or provide information to others illegally. These organizations are also required to take necessary measures to ensure information security. The law addresses data management, and requires Internet service providers to manage user posts and report illegal content to authorities. All providers must verify user identities upon giving them access to services.
“Verified identification is used for backstage management, while users can choose pseudonyms when publishing information online,”said Li Fei, Deputy Director of the Legislative Affairs Commission of the NPC Standing Committee.
“The identity management policy enables people to protect their lawful rights by providing real names while building an environment of free exchange under anonymity,” said Li Yuxiao.
Public resentment against the deluge of spam and telemarketing calls is answered by an opt-in policy. The decision forbids organizations and individuals from commercial solicitation by telephone or digital networks without prior consent.
Companies infringing upon citizen rights or violating privacy with commercial harassment must comply with cease-and-desist demands or face lawsuits.
The decision also empowers regulators to supervise Internet activities and requires network service providers to offer technical support.
Much-needed law
Although the Internet undoubtedly makes shopping, banking and socializing easier for China’s roughly half a billion netizens, the trail of data left by such activities makes them vulnerable to fraud and identity theft.
“Mobile Internet, the Internet of Things and cloud computing have posed severe challenges to information security,” Li Yuxiao said.
Recently, China Youth Daily conducted an online survey on 11,163 people across the country. Of all respondents, 93.8 percent said they believed their personal information had been leaked, and 86 percent were looking forward to a law to protect such data.
“Legal loopholes, ineffective regulation, weak technology, online service provider neglect of information security and low awareness of personal data protection are important factors leading to leakage,” Li Yuxiao said.
Some result from cyber attacks. For instance, in December 2011 the account names and passwords of more than 6 million users of IT programmer community CSDN were made public by hackers. Social networking sites such as Tianya.cn were also reportedly breached.
“Some online service providers, not attaching enough importance to protecting user data, once stored unencrypted passwords, which are vulnerable to information theft,” said Shi Xiaohong, Vice President of Qihoo 360, a leading Internet security provider. A report released by Qihoo 360 last February said that more than half of Chinese websites have gaps in their security and as many as 36 percent carry “high-risk vulnerabilities.”

Identity theft is a profitable enterprise for otherwise legitimate Internet businesses and some unscrupulous employees. Approximately 70 to 80 percent of personal information thefts in China are committed by insiders, according to the China Software Testing Center, an institution affiliated with the Ministry of Industry and Information Technology.
Many Internet users have not realized the importance of protecting their personal data, according to Shi. For example, some netizens set very simple passwords for their online accounts, such as using repetitive numbers or their own birthdays, and they seldom change these.
The number of phishing websites, fake sites aimed at acquiring personal information, is on the rise in China. Data from the China Internet Network Information Center show nearly 14,000 phishing websites were detected in the first half of 2012, 80 percent of which masqueraded as sites of financial institutions and media.
Leaked personal information has been used in telemarketing and even in criminal activities such as fraud, blackmail and kidnapping.
On May 15, 2012, police authorities in Nanjing, capital city of east China’s Jiangsu Province, busted an Internet fraud ring and apprehended five suspects. The latter purchased personal identification numbers and bank account information from online sources and intercepted newly issued credit cards mailed to victims. They used the purchased data to activate the cards and withdraw cash in victims’names.
In February 2012, Beijing police waged a special campaign against cyber crime. Within half a year, it cracked nearly 4,000 cases, captured more than 5,000 suspects and punished over 7,500 rule-violating Internet businesses.
Stolen data contributed to some of the crimes. In one case, identity thieves exploited a Beijing resident’s love of a television talent show to bilk him of 2,500 yuan ($402) in early 2012.
A man surnamed Li queried search engine Baidu.com for the producer’s contact information, and called a number that appeared in the search results. The voice who answered promised Li a place on the show if he remitted 2,500 yuan to a certain bank account. The contact stopped returning calls after payment, and Li reported to the police. After investigation, Beijing police found that from January to March last year, the account in- formation of 660 clients of Baidu Tuiguang, an advertising service offered by Baidu.com, had been stolen. These accounts had been broken into, and clients’ advertisements had been altered to commit fraud.
In Li’s case, the phone number of the program’s producer was changed so that when Li called, another party answered. On June 19, 2012, 13 suspects were arrested in southern Hainan Province. They confessed to cheating netizens out of more than 500,000 yuan($80,333).
Legal process
Since the emergence of the technology in the 1990s, China has promulgated multiple laws and regulations to govern cyberspace.
In 2000, the NPC Standing Committee passed a decision on maintaining Internet security, which included a few provisions on data protection, yet it emphasized the safeguarding of state secrets. It stipulated that intrusion into computer systems in the field of state affairs, national defense, and cuttingedge science and technology, and tampering with data in computer systems should be punished according to the Criminal Law or the Law on Penalties for Administration of Public Security. The decision forbade illegal interception, alteration or deletion of other people’s e-mails or other data, and prohibits infringement on citizen communication freedom and privacy.
The Tort Liability Law that took effect in July 2010 and the amended Criminal Law that went into force in May 2011 respectively specifies civil liabilities for infringement on others’ rights through the Internet and criminal punishment for illegal acquisition and trading of personal information.
The State Council, China’s cabinet, and industry regulators have also made some regulations and rules on protecting digital information.
“Overall, these laws and regulations on protecting online data are still relatively weak,” said Li Fei at a press conference on December 28, 2012. According to him, the NPC Standing Committee and relevant government departments began to draft the decision on strengthening online information protection in 2011.
“Citizens have the basic right to keep their personal digital information confidential, and it is very important to make a law to protect such information,” said Wang Liming, Vice President of the Renmin University of China and civil law expert.

Nonetheless, provisions in the NPC Standing Committee’s decision are not detailed enough, according to Zhou Hanhua, a law research fellow at the Chinese Academy of Social Sciences.
“It has not specified function or power division among network supervisory departments. These need to be further specified in the future,” Zhou told Xinhua News Agency.
“The State Council is making detailed rules to implement the NPC Standing Committee’s decision on strengthening the protection of online personal information,” said Yuan Shuhong, Deputy Director of the State Council’s Legal Affairs Office. “The State Council is also checking its regulations to identify any discrepancies with the decision.”
On December 26, 2012, Wang microblogged a simulated wanted poster offering a 1,000-yuan ($161) reward for the phone number of Zuo Hui, President of Homelink, one of the largest real estate brokers in the country.
China’s human flesh search engine delivered Zuo’s phone number, which Wang posted the next day to the applause of many for whom aggressive telemarketing is a familiar yet unwanted intrusion into personal privacy.
Ironically, legal experts warned that Wang’s tit-for-tat response might have violated Zuo’s personal privacy. Nevertheless, Wang demanded Homelink reveal how it obtained his personal information. The company refused to do so while offering its apology for the intrusive calls.
A real estate broker in Anhui told China Radio Network that the sale and purchase of client data is standard operating procedure in the industry. Information clients do not voluntarily offer is bought from property management firms or online information vendors.
Wang’s determination to protect his personal information came two days before the Standing Committee of the National People’s Congress (NPC), China’s top legislature, passed a decision on strengthening online information protection on December 28.
The decision, as legally binding as a law, is intended to better protect Internet user privacy and provide a legal basis for safeguarding online information security, so as to ensure the healthy and orderly development of the Web, said a spokesman for the NPC Standing Committee.
“The law represents progress in China’s legal system and maturity in social management,” said Li Yuxiao, Director of Internet Governance and Legal Research Center at Beijing University of Posts and Telecommunications.

Main points
The decision provides legal protection for information that can be used to identify a citizen, or that which involves privacy, and bans illegal acquisition, sale and purchase of data. Personal information can only be obtained with prior consent.
It requires Internet service providers and public institutions to clearly state the purposes, means and scope of all data collection efforts. Information collected must be relevant to business operations.
Organizations are further required to maintain confidentiality, and are forbidden to leak, tamper with, damage, sell or provide information to others illegally. These organizations are also required to take necessary measures to ensure information security. The law addresses data management, and requires Internet service providers to manage user posts and report illegal content to authorities. All providers must verify user identities upon giving them access to services.
“Verified identification is used for backstage management, while users can choose pseudonyms when publishing information online,”said Li Fei, Deputy Director of the Legislative Affairs Commission of the NPC Standing Committee.
“The identity management policy enables people to protect their lawful rights by providing real names while building an environment of free exchange under anonymity,” said Li Yuxiao.
Public resentment against the deluge of spam and telemarketing calls is answered by an opt-in policy. The decision forbids organizations and individuals from commercial solicitation by telephone or digital networks without prior consent.
Companies infringing upon citizen rights or violating privacy with commercial harassment must comply with cease-and-desist demands or face lawsuits.
The decision also empowers regulators to supervise Internet activities and requires network service providers to offer technical support.
Much-needed law
Although the Internet undoubtedly makes shopping, banking and socializing easier for China’s roughly half a billion netizens, the trail of data left by such activities makes them vulnerable to fraud and identity theft.
“Mobile Internet, the Internet of Things and cloud computing have posed severe challenges to information security,” Li Yuxiao said.
Recently, China Youth Daily conducted an online survey on 11,163 people across the country. Of all respondents, 93.8 percent said they believed their personal information had been leaked, and 86 percent were looking forward to a law to protect such data.
“Legal loopholes, ineffective regulation, weak technology, online service provider neglect of information security and low awareness of personal data protection are important factors leading to leakage,” Li Yuxiao said.
Some result from cyber attacks. For instance, in December 2011 the account names and passwords of more than 6 million users of IT programmer community CSDN were made public by hackers. Social networking sites such as Tianya.cn were also reportedly breached.
“Some online service providers, not attaching enough importance to protecting user data, once stored unencrypted passwords, which are vulnerable to information theft,” said Shi Xiaohong, Vice President of Qihoo 360, a leading Internet security provider. A report released by Qihoo 360 last February said that more than half of Chinese websites have gaps in their security and as many as 36 percent carry “high-risk vulnerabilities.”

Identity theft is a profitable enterprise for otherwise legitimate Internet businesses and some unscrupulous employees. Approximately 70 to 80 percent of personal information thefts in China are committed by insiders, according to the China Software Testing Center, an institution affiliated with the Ministry of Industry and Information Technology.
Many Internet users have not realized the importance of protecting their personal data, according to Shi. For example, some netizens set very simple passwords for their online accounts, such as using repetitive numbers or their own birthdays, and they seldom change these.
The number of phishing websites, fake sites aimed at acquiring personal information, is on the rise in China. Data from the China Internet Network Information Center show nearly 14,000 phishing websites were detected in the first half of 2012, 80 percent of which masqueraded as sites of financial institutions and media.
Leaked personal information has been used in telemarketing and even in criminal activities such as fraud, blackmail and kidnapping.
On May 15, 2012, police authorities in Nanjing, capital city of east China’s Jiangsu Province, busted an Internet fraud ring and apprehended five suspects. The latter purchased personal identification numbers and bank account information from online sources and intercepted newly issued credit cards mailed to victims. They used the purchased data to activate the cards and withdraw cash in victims’names.
In February 2012, Beijing police waged a special campaign against cyber crime. Within half a year, it cracked nearly 4,000 cases, captured more than 5,000 suspects and punished over 7,500 rule-violating Internet businesses.
Stolen data contributed to some of the crimes. In one case, identity thieves exploited a Beijing resident’s love of a television talent show to bilk him of 2,500 yuan ($402) in early 2012.
A man surnamed Li queried search engine Baidu.com for the producer’s contact information, and called a number that appeared in the search results. The voice who answered promised Li a place on the show if he remitted 2,500 yuan to a certain bank account. The contact stopped returning calls after payment, and Li reported to the police. After investigation, Beijing police found that from January to March last year, the account in- formation of 660 clients of Baidu Tuiguang, an advertising service offered by Baidu.com, had been stolen. These accounts had been broken into, and clients’ advertisements had been altered to commit fraud.
In Li’s case, the phone number of the program’s producer was changed so that when Li called, another party answered. On June 19, 2012, 13 suspects were arrested in southern Hainan Province. They confessed to cheating netizens out of more than 500,000 yuan($80,333).
Legal process
Since the emergence of the technology in the 1990s, China has promulgated multiple laws and regulations to govern cyberspace.
In 2000, the NPC Standing Committee passed a decision on maintaining Internet security, which included a few provisions on data protection, yet it emphasized the safeguarding of state secrets. It stipulated that intrusion into computer systems in the field of state affairs, national defense, and cuttingedge science and technology, and tampering with data in computer systems should be punished according to the Criminal Law or the Law on Penalties for Administration of Public Security. The decision forbade illegal interception, alteration or deletion of other people’s e-mails or other data, and prohibits infringement on citizen communication freedom and privacy.
The Tort Liability Law that took effect in July 2010 and the amended Criminal Law that went into force in May 2011 respectively specifies civil liabilities for infringement on others’ rights through the Internet and criminal punishment for illegal acquisition and trading of personal information.
The State Council, China’s cabinet, and industry regulators have also made some regulations and rules on protecting digital information.
“Overall, these laws and regulations on protecting online data are still relatively weak,” said Li Fei at a press conference on December 28, 2012. According to him, the NPC Standing Committee and relevant government departments began to draft the decision on strengthening online information protection in 2011.
“Citizens have the basic right to keep their personal digital information confidential, and it is very important to make a law to protect such information,” said Wang Liming, Vice President of the Renmin University of China and civil law expert.

Nonetheless, provisions in the NPC Standing Committee’s decision are not detailed enough, according to Zhou Hanhua, a law research fellow at the Chinese Academy of Social Sciences.
“It has not specified function or power division among network supervisory departments. These need to be further specified in the future,” Zhou told Xinhua News Agency.
“The State Council is making detailed rules to implement the NPC Standing Committee’s decision on strengthening the protection of online personal information,” said Yuan Shuhong, Deputy Director of the State Council’s Legal Affairs Office. “The State Council is also checking its regulations to identify any discrepancies with the decision.”