[{"content":"摘要（期刊要目页所载原文摘要）\n基于互联网提供的生成式人工智能服务属于网络服务，生成式人工智能服务提供者既不同于网络技术服务提供者，也有别于网络内容服务提供者，其生成了新的信息和内容。基于人工智能的自主性，生成式人工智能服务提供者对于生成内容的控制力要弱于网络内容服务提供者。生成式人工智能服务是立法者在确立网络侵权规则时未能预见的新型网络服务，网络侵权规则也不是以其为目标原型的。我国民法典第1195—1197条规定的网络侵权规则由通知规则与知道规则所组成，规范的核心对象是网络服务提供者，为网络服务提供者确定了及时采取必要措施以预防和制止侵权行为的作为义务。网络侵权规则适用于本身没有直接实施作为的侵权行为的网络服务提供者即网络技术服务提供者，不适用于直接实施了作为的侵权行为的网络服务提供者。生成式人工智能服务提供者输出内容的行为属于作为，因此，不符合网络侵权规则所调整的侵权关系。生成式人工智能侵权可能源于数据训练中的侵权行为、系统内置的侵权危险或者其他系统原因（如模型幻觉等），也可能来自用户故意输入侵权提示的操控行为。对于生成式人工智能侵权适用通知规则与知道规则，既无助于预防和制止同一侵权行为的发生，也不利于鼓励生成式人工智能技术的创新与发展。因此，不能将网络侵权规则适用或类推适用于生成式人工智能侵权责任。\n出处：论生成式人工智能服务侵权不应适用网络侵权规则，《比较法研究》2026 年第 1 期。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：人工智能侵权与归责\n","permalink":"https://ai.intlaws.com/scholarship/%E7%A8%8B%E5%95%B8-%E7%94%9F%E6%88%90%E5%BC%8Fai%E6%9C%8D%E5%8A%A1%E4%BE%B5%E6%9D%83%E4%B8%8D%E5%BA%94%E9%80%82%E7%94%A8%E7%BD%91%E7%BB%9C%E4%BE%B5%E6%9D%83%E8%A7%84%E5%88%99/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e基于互联网提供的生成式人工智能服务属于网络服务，生成式人工智能服务提供者既不同于网络技术服务提供者，也有别于网络内容服务提供者，其生成了新的信息和内容。基于人工智能的自主性，生成式人工智能服务提供者对于生成内容的控制力要弱于网络内容服务提供者。生成式人工智能服务是立法者在确立网络侵权规则时未能预见的新型网络服务，网络侵权规则也不是以其为目标原型的。我国民法典第1195—1197条规定的网络侵权规则由通知规则与知道规则所组成，规范的核心对象是网络服务提供者，为网络服务提供者确定了及时采取必要措施以预防和制止侵权行为的作为义务。网络侵权规则适用于本身没有直接实施作为的侵权行为的网络服务提供者即网络技术服务提供者，不适用于直接实施了作为的侵权行为的网络服务提供者。生成式人工智能服务提供者输出内容的行为属于作为，因此，不符合网络侵权规则所调整的侵权关系。生成式人工智能侵权可能源于数据训练中的侵权行为、系统内置的侵权危险或者其他系统原因（如模型幻觉等），也可能来自用户故意输入侵权提示的操控行为。对于生成式人工智能侵权适用通知规则与知道规则，既无助于预防和制止同一侵权行为的发生，也不利于鼓励生成式人工智能技术的创新与发展。因此，不能将网络侵权规则适用或类推适用于生成式人工智能侵权责任。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：论生成式人工智能服务侵权不应适用网络侵权规则，《比较法研究》2026 年第 1 期。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/fxyjdt/202603/t20260302_5974668.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：人工智能侵权与归责\u003c/p\u003e","title":"程啸：论生成式人工智能服务侵权不应适用网络侵权规则"},{"content":"摘要（期刊要目页所载原文摘要）\n现代刑法需要回应与控制“人工智能+犯罪”的新型风险。生成式人工智能参与的新型犯罪风险可分为两类，一是自主生成的技术风险所导致的危险，二是滥用生成式人工智能技术实施犯罪而导致的危险，这两类风险均包含服务提供者应当答责与无需答责的风险两种情况。服务提供者的行为可能存在侵害结果发生前阶段的风险，以及指向多种发散性危害后果的不确定风险。刑法规范应当以对法益安全状态的保护为目的，针对前阶段服务提供行为的危害性构建归责基础。在犯罪风险中，应当针对服务提供者前阶段行为导致的超越允许范围的不当升高技术风险，以及具备后继犯罪危害性的促成他人后续滥用生成式人工智能技术实施犯罪的行为风险进行刑事归责。应当先依据具体注意义务规范通过归责理论构建刑事责任，未来在此基础上新构建一套完整的生成式人工智能服务提供者的答责规则体系并直接修正构成要件层面的答责原则。\n出处：现代刑法框架下生成式人工智能服务提供者的归责基础，《环球法律评论》2026 年第 2 期（「理论前沿」栏目）。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：人工智能侵权与归责\n","permalink":"https://ai.intlaws.com/scholarship/%E6%9D%8E%E6%BA%90%E7%B2%92-%E7%94%9F%E6%88%90%E5%BC%8Fai%E6%9C%8D%E5%8A%A1%E6%8F%90%E4%BE%9B%E8%80%85%E7%9A%84%E5%BD%92%E8%B4%A3%E5%9F%BA%E7%A1%80/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e现代刑法需要回应与控制“人工智能+犯罪”的新型风险。生成式人工智能参与的新型犯罪风险可分为两类，一是自主生成的技术风险所导致的危险，二是滥用生成式人工智能技术实施犯罪而导致的危险，这两类风险均包含服务提供者应当答责与无需答责的风险两种情况。服务提供者的行为可能存在侵害结果发生前阶段的风险，以及指向多种发散性危害后果的不确定风险。刑法规范应当以对法益安全状态的保护为目的，针对前阶段服务提供行为的危害性构建归责基础。在犯罪风险中，应当针对服务提供者前阶段行为导致的超越允许范围的不当升高技术风险，以及具备后继犯罪危害性的促成他人后续滥用生成式人工智能技术实施犯罪的行为风险进行刑事归责。应当先依据具体注意义务规范通过归责理论构建刑事责任，未来在此基础上新构建一套完整的生成式人工智能服务提供者的答责规则体系并直接修正构成要件层面的答责原则。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：现代刑法框架下生成式人工智能服务提供者的归责基础，《环球法律评论》2026 年第 2 期（「理论前沿」栏目）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/journal/huanqiu/202603/t20260324_5977834.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：人工智能侵权与归责\u003c/p\u003e","title":"李源粒：现代刑法框架下生成式人工智能服务提供者的归责基础"},{"content":"摘要（期刊要目页所载原文摘要）\n在自动驾驶语境中，人工智能软件产品缺陷是指预测模型和决策函数在事故基础率、预测误差率、假阴性率上没有达到合理的安全标准。但晚近的计算机科学研究已经表明，低事故基础率、低预测误差率以及低假阴性率的“三低”状态不具有理论上的可能性，处理其中两项“缺陷”的过程，必然伴随着放大剩下一项“缺陷”。为了保证人工智能的安全性，有理由放弃假阴性率这一指标，如此便会导致“缺陷”这一概念在人工智能致损责任分配问题上式微。而一旦告别“缺陷”，纯粹因自动化决策而产生的损害赔偿责任就应当采纳二层次判断方案。第一层次是“无过错责任”，即只要能够证明损害发生时处于自动化决策状态，就由人工智能软件提供者承担损害赔偿责任；第二层次是“安全性证明+风险基金补偿”，即被告通过统计型证据举证证明软件的事故基础率和预测误差率符合市场准入门槛时，由行业组织设立的风险基金承担替代责任。\n出处：告别「缺陷」：人工智能致损无过错责任的法理根据，《政治与法律》2026 年第 2 期（「实务研究」栏目）。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：人工智能侵权与归责\n","permalink":"https://ai.intlaws.com/scholarship/%E5%BE%90%E8%88%92%E6%B5%A9-%E5%91%8A%E5%88%AB%E7%BC%BA%E9%99%B7-%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E8%87%B4%E6%8D%9F%E6%97%A0%E8%BF%87%E9%94%99%E8%B4%A3%E4%BB%BB%E7%9A%84%E6%B3%95%E7%90%86%E6%A0%B9%E6%8D%AE/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e在自动驾驶语境中，人工智能软件产品缺陷是指预测模型和决策函数在事故基础率、预测误差率、假阴性率上没有达到合理的安全标准。但晚近的计算机科学研究已经表明，低事故基础率、低预测误差率以及低假阴性率的“三低”状态不具有理论上的可能性，处理其中两项“缺陷”的过程，必然伴随着放大剩下一项“缺陷”。为了保证人工智能的安全性，有理由放弃假阴性率这一指标，如此便会导致“缺陷”这一概念在人工智能致损责任分配问题上式微。而一旦告别“缺陷”，纯粹因自动化决策而产生的损害赔偿责任就应当采纳二层次判断方案。第一层次是“无过错责任”，即只要能够证明损害发生时处于自动化决策状态，就由人工智能软件提供者承担损害赔偿责任；第二层次是“安全性证明+风险基金补偿”，即被告通过统计型证据举证证明软件的事故基础率和预测误差率符合市场准入门槛时，由行业组织设立的风险基金承担替代责任。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：告别「缺陷」：人工智能致损无过错责任的法理根据，《政治与法律》2026 年第 2 期（「实务研究」栏目）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/fxyjdt/202602/t20260203_5971908.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：人工智能侵权与归责\u003c/p\u003e","title":"徐舒浩：告别「缺陷」：人工智能致损无过错责任的法理根据"},{"content":"摘要（期刊要目页所载原文摘要）\n实践中，法律规范相对滞后和粗疏，个人信息调取的授权规范不明确、调取程序失范、程序性保障缺失等多重问题亟待化解。侦查规范体系改革的功利化和被动化、技术治理下个人信息共享的政策推动、个人信息权益侵犯的隐蔽性和无形性等因素叠加，进一步加剧了个人信息调取的法律控制难题。个人信息调取的规范体系以基本权干预之判定为起点，由调取之法律授权、调取之令状程序、调取之程序保障等构成正当程序三元框架。我国个人信息调取正当程序的三元结构应包括：以隐私权为中心的比例控制；以检察机关为中心的准司法令状制度；以个人信息权益为中心的程序保障。据此，应在比例原则之下运用“五要素衡量法”和“五要素干预法”完善授权规范，明确令状审批主体、申请主体和具体内容，构建四元保障程序。\n出处：个人信息调取的正当程序，《法学研究》2026 年第 3 期（「数智法治」专题）。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：个人信息保护与人格权益\n","permalink":"https://ai.intlaws.com/scholarship/%E5%BC%A0%E8%BF%AA-%E4%B8%AA%E4%BA%BA%E4%BF%A1%E6%81%AF%E8%B0%83%E5%8F%96%E7%9A%84%E6%AD%A3%E5%BD%93%E7%A8%8B%E5%BA%8F/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e实践中，法律规范相对滞后和粗疏，个人信息调取的授权规范不明确、调取程序失范、程序性保障缺失等多重问题亟待化解。侦查规范体系改革的功利化和被动化、技术治理下个人信息共享的政策推动、个人信息权益侵犯的隐蔽性和无形性等因素叠加，进一步加剧了个人信息调取的法律控制难题。个人信息调取的规范体系以基本权干预之判定为起点，由调取之法律授权、调取之令状程序、调取之程序保障等构成正当程序三元框架。我国个人信息调取正当程序的三元结构应包括：以隐私权为中心的比例控制；以检察机关为中心的准司法令状制度；以个人信息权益为中心的程序保障。据此，应在比例原则之下运用“五要素衡量法”和“五要素干预法”完善授权规范，明确令状审批主体、申请主体和具体内容，构建四元保障程序。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：个人信息调取的正当程序，《法学研究》2026 年第 3 期（「数智法治」专题）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/journal/fxyj/202605/t20260522_5992792.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：个人信息保护与人格权益\u003c/p\u003e","title":"张迪：个人信息调取的正当程序"},{"content":"摘要（期刊要目页所载原文摘要）\n我国首例AI声音权益侵权案一审判决虽权宜性地定分止争，但就AI声音权益的法律性质与保护路径未做全面回应，引发广泛讨论。AI声音以自然人声纹为中介进而体现其人格特征，既受《民法典》人格权编调整产生一般人格权益，亦与《反不正当竞争法》《著作权法》《个人信息保护法》结合产生特别人格权益。前者欠缺可支配性，性质为未具名的人格利益，侵权行为的归责要件应统合为未经自然人许可处分AI声音，而损害结果则依据物质性人格权益与精神性人格权益而区分为造成经济损失与贬损人格形象。后者可类型化为竞争法权益、表演者权与个人信息权益，依据特别法各自的归责要件与责任承担方式予以保护。为协调责任竞合，既需明确适用具体人格权规则保护AI声音权益的情形，亦需厘清包括《民法典》人格权编与各特别法在内的不同法律之间的适用关系。\n出处：AI 声音权益的法律性质与保护路径，《政治与法律》2026 年第 2 期（「争鸣园地」栏目）。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：个人信息保护与人格权益\n","permalink":"https://ai.intlaws.com/scholarship/%E6%B1%AA%E5%80%AA%E6%9D%B0-ai%E5%A3%B0%E9%9F%B3%E6%9D%83%E7%9B%8A%E7%9A%84%E6%B3%95%E5%BE%8B%E6%80%A7%E8%B4%A8%E4%B8%8E%E4%BF%9D%E6%8A%A4%E8%B7%AF%E5%BE%84/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e我国首例AI声音权益侵权案一审判决虽权宜性地定分止争，但就AI声音权益的法律性质与保护路径未做全面回应，引发广泛讨论。AI声音以自然人声纹为中介进而体现其人格特征，既受《民法典》人格权编调整产生一般人格权益，亦与《反不正当竞争法》《著作权法》《个人信息保护法》结合产生特别人格权益。前者欠缺可支配性，性质为未具名的人格利益，侵权行为的归责要件应统合为未经自然人许可处分AI声音，而损害结果则依据物质性人格权益与精神性人格权益而区分为造成经济损失与贬损人格形象。后者可类型化为竞争法权益、表演者权与个人信息权益，依据特别法各自的归责要件与责任承担方式予以保护。为协调责任竞合，既需明确适用具体人格权规则保护AI声音权益的情形，亦需厘清包括《民法典》人格权编与各特别法在内的不同法律之间的适用关系。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：AI 声音权益的法律性质与保护路径，《政治与法律》2026 年第 2 期（「争鸣园地」栏目）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/fxyjdt/202602/t20260203_5971908.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：个人信息保护与人格权益\u003c/p\u003e","title":"汪倪杰：AI 声音权益的法律性质与保护路径"},{"content":"摘要（期刊要目页所载原文摘要）\n围绕公共数据的权属界定，当前地方立法实践中存在数据汇集型、数据维护型、数据经营型三种确权逻辑。相关立法多笼统借用经济学产权概念与政策性表述，欠缺严格的法学维度的正当性证成与上位法依据支撑。公共数据深度嵌入行政过程、数字基础设施运转架构和社会协同创新网络，其运行遵循信息媒介逻辑，与自然资源属性迥异。公共数据利用秩序的建构，不宜直接套用宪法上关于自然资源国家所有的法理，而应在宪法第12条所确立的社会主义公共财产规范框架下展开。公共数据归国家所有，应理解为由国家承担防止侵占、保障合理利用、促进公平利用之义务的规范要求。未来应通过中央立法明确公共数据治理的基本原则、数据汇集的合法性要件、授权运营的目的与基本程序、私法规则的适用边界等，并配套财政监督、程序保障与数据流通的统筹机制，推动形成体系完整、逻辑融贯、普惠包容的公共数据利用生态。\n出处：「公共数据归国家所有」的宪法检视，《法学研究》2026 年第 3 期（「部门法域」栏目）。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：数据要素与数据产权\n","permalink":"https://ai.intlaws.com/scholarship/%E8%83%A1%E8%90%A7%E5%8A%9B-%E5%85%AC%E5%85%B1%E6%95%B0%E6%8D%AE%E5%BD%92%E5%9B%BD%E5%AE%B6%E6%89%80%E6%9C%89%E7%9A%84%E5%AE%AA%E6%B3%95%E6%A3%80%E8%A7%86/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e围绕公共数据的权属界定，当前地方立法实践中存在数据汇集型、数据维护型、数据经营型三种确权逻辑。相关立法多笼统借用经济学产权概念与政策性表述，欠缺严格的法学维度的正当性证成与上位法依据支撑。公共数据深度嵌入行政过程、数字基础设施运转架构和社会协同创新网络，其运行遵循信息媒介逻辑，与自然资源属性迥异。公共数据利用秩序的建构，不宜直接套用宪法上关于自然资源国家所有的法理，而应在宪法第12条所确立的社会主义公共财产规范框架下展开。公共数据归国家所有，应理解为由国家承担防止侵占、保障合理利用、促进公平利用之义务的规范要求。未来应通过中央立法明确公共数据治理的基本原则、数据汇集的合法性要件、授权运营的目的与基本程序、私法规则的适用边界等，并配套财政监督、程序保障与数据流通的统筹机制，推动形成体系完整、逻辑融贯、普惠包容的公共数据利用生态。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：「公共数据归国家所有」的宪法检视，《法学研究》2026 年第 3 期（「部门法域」栏目）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/journal/fxyj/202605/t20260522_5992792.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：数据要素与数据产权\u003c/p\u003e","title":"胡萧力：「公共数据归国家所有」的宪法检视"},{"content":"摘要（期刊要目页所载原文摘要）\n数据持有事实及其变动乃数据产权制度构建的客观土壤，有必要回应因此产生的规范难题。数据持有事实本身将产生三个规范难题，即不受持有行为控制之数据是否受到法律保护，是否有必要为所有持有事实提供一般性保护，持有事实的法律效力如何设置。对此，应确立数据持有保护的一般性规则，明确持有事实仅具有财产特定化功能，无推定效力和公信力。数据持有的变动将引发自主持有与他主持有并存、有权持有与无权持有并存等复杂数据持有关系，并产生新的数据产权分配难题。对此，可尝试确立间接持有保护规则，明确持有者无权处分数据或进行非合意数据生产时的数据产权分配规则。\n出处：论数据持有事实及其变动的规范意义，《法学评论》2026 年第 3 期。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：数据要素与数据产权\n","permalink":"https://ai.intlaws.com/scholarship/%E5%AE%81%E5%9B%AD-%E8%AE%BA%E6%95%B0%E6%8D%AE%E6%8C%81%E6%9C%89%E4%BA%8B%E5%AE%9E%E5%8F%8A%E5%85%B6%E5%8F%98%E5%8A%A8%E7%9A%84%E8%A7%84%E8%8C%83%E6%84%8F%E4%B9%89/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e数据持有事实及其变动乃数据产权制度构建的客观土壤，有必要回应因此产生的规范难题。数据持有事实本身将产生三个规范难题，即不受持有行为控制之数据是否受到法律保护，是否有必要为所有持有事实提供一般性保护，持有事实的法律效力如何设置。对此，应确立数据持有保护的一般性规则，明确持有事实仅具有财产特定化功能，无推定效力和公信力。数据持有的变动将引发自主持有与他主持有并存、有权持有与无权持有并存等复杂数据持有关系，并产生新的数据产权分配难题。对此，可尝试确立间接持有保护规则，明确持有者无权处分数据或进行非合意数据生产时的数据产权分配规则。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：论数据持有事实及其变动的规范意义，《法学评论》2026 年第 3 期。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/fxyjdt/202605/t20260511_5988560.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：数据要素与数据产权\u003c/p\u003e","title":"宁园：论数据持有事实及其变动的规范意义"},{"content":"摘要（期刊要目页所载原文摘要）\n智能平权是我国人工智能发展与治理的新要求。开源人工智能具有技术民主化、规模定律脱钩性、监督开放化等宏观价值，应以数字开源的人工智能立法实现智能平权，并设置相应的微观法律保障措施以维护开源方的合法权益。在开源架构下，人工智能立法需要参考客观语境与技术现状，以数据分类分级保护机制预防开源人工智能潜在的数据安全风险，具体需对人工智能系统中的公共数据、商业数据以及个人数据提供不同保护模式，并根据数据内涵差异设置不同级别的保护强度。数字开源时代需要实现从部门性立法向领域性立法的转型，以领域性立法框架实现智能平权的人工智能立法，即在横向上优化自身与其他法规的衔接流程，在纵向上吸收人工智能专业知识以提升立法科学性。\n出处：智能平权：通过数字开源的人工智能立法实现，《中外法学》2026 年第 1 期（「专题：数字法治」）。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：人工智能治理与立法路径\n","permalink":"https://ai.intlaws.com/scholarship/%E5%88%98%E8%89%B3%E7%BA%A2-%E6%99%BA%E8%83%BD%E5%B9%B3%E6%9D%83-%E9%80%9A%E8%BF%87%E6%95%B0%E5%AD%97%E5%BC%80%E6%BA%90%E7%9A%84%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E7%AB%8B%E6%B3%95%E5%AE%9E%E7%8E%B0/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e智能平权是我国人工智能发展与治理的新要求。开源人工智能具有技术民主化、规模定律脱钩性、监督开放化等宏观价值，应以数字开源的人工智能立法实现智能平权，并设置相应的微观法律保障措施以维护开源方的合法权益。在开源架构下，人工智能立法需要参考客观语境与技术现状，以数据分类分级保护机制预防开源人工智能潜在的数据安全风险，具体需对人工智能系统中的公共数据、商业数据以及个人数据提供不同保护模式，并根据数据内涵差异设置不同级别的保护强度。数字开源时代需要实现从部门性立法向领域性立法的转型，以领域性立法框架实现智能平权的人工智能立法，即在横向上优化自身与其他法规的衔接流程，在纵向上吸收人工智能专业知识以提升立法科学性。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：智能平权：通过数字开源的人工智能立法实现，《中外法学》2026 年第 1 期（「专题：数字法治」）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/fxyjdt/202601/t20260123_5970638.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：人工智能治理与立法路径\u003c/p\u003e","title":"刘艳红：智能平权：通过数字开源的人工智能立法实现"},{"content":"摘要（期刊要目页所载原文摘要）\n人工智能技术狂飙背后潜藏着多重结构性挑战，它使人类现有的法律、伦理等规范跟进速度迟缓，难以穿透人工智能设计、生产和应用的全链条进行监管，由此产生调整滞后的规范治理时间差，甚或治理真空，此即所谓“规范延迟”现象。这需要我们审视有关“人工智能作为对象的治理”和“借助人工智能的治理”这两种治理类型，考察它们在人类现实生活中展现的相互交错关系，设计既尊重人类基本价值、又能发挥人工智能治理潜在效能的“人主机辅”“人—机规范协同”的秩序与规范世界图景。如果未来强人工智能（通用人工智能及超人工智能）在模拟人类的“意识”上真正实现了实质性的技术突破，则如何让人工智能变得更加安全便应当成为人类社会在发展和使用人工智能技术时的首要考量因素。我们应建立一种“安全防御”的新型治理范式，有必要将“人类主导权原则”和人类“不可让渡领域”以代码形式直接强制写入所有强人工智能系统的底层架构，确保最终撤销权与解释权属于人类本体。\n出处：人工智能时代的规范延迟：问题与应对——基于法哲学视角的考察，《中外法学》2026 年第 4 期（「专题：数字法治」）。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：人工智能治理与立法路径\n","permalink":"https://ai.intlaws.com/scholarship/%E8%88%92%E5%9B%BD%E6%BB%A2-%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E6%97%B6%E4%BB%A3%E7%9A%84%E8%A7%84%E8%8C%83%E5%BB%B6%E8%BF%9F/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e人工智能技术狂飙背后潜藏着多重结构性挑战，它使人类现有的法律、伦理等规范跟进速度迟缓，难以穿透人工智能设计、生产和应用的全链条进行监管，由此产生调整滞后的规范治理时间差，甚或治理真空，此即所谓“规范延迟”现象。这需要我们审视有关“人工智能作为对象的治理”和“借助人工智能的治理”这两种治理类型，考察它们在人类现实生活中展现的相互交错关系，设计既尊重人类基本价值、又能发挥人工智能治理潜在效能的“人主机辅”“人—机规范协同”的秩序与规范世界图景。如果未来强人工智能（通用人工智能及超人工智能）在模拟人类的“意识”上真正实现了实质性的技术突破，则如何让人工智能变得更加安全便应当成为人类社会在发展和使用人工智能技术时的首要考量因素。我们应建立一种“安全防御”的新型治理范式，有必要将“人类主导权原则”和人类“不可让渡领域”以代码形式直接强制写入所有强人工智能系统的底层架构，确保最终撤销权与解释权属于人类本体。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：人工智能时代的规范延迟：问题与应对——基于法哲学视角的考察，《中外法学》2026 年第 4 期（「专题：数字法治」）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/fxyjdt/202607/t20260721_6060226.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：人工智能治理与立法路径\u003c/p\u003e","title":"舒国滢：人工智能时代的规范延迟：问题与应对——基于法哲学视角的考察"},{"content":"摘要（期刊要目页所载原文摘要）\n版权法是维系多方利益平衡的法律框架，“先授权再使用”规则一直支撑着内容产业的健康发展。信息技术的快速更迭改变了传统的内容产业生态链，互联网发展初期对仅提供技术服务、不介入版权内容经营的平台中立性之假定，已不适用于数智时代越来越多以技术控制内容生产和传播、以流量分成作为营收的多功能综合平台。基于“避风港”规则适用在我国遭遇多重困境和平台“注意义务”标准设定无法形成共识的现实，结合数智技术掌控者已深度介入和实质性控制内容产业运行的实际，应更新平台版权侵权责任判定的理念，依权责匹配逻辑按“技术—市场”控制力高低，分层判定不同类型平台的侵权责任，尤其是基于用户协议直接控制用户内容传播并以此获利的平台之替代责任。\n出处：数智时代版权侵权平台责任判定的权责匹配逻辑，《中外法学》2026 年第 4 期（「专题：数字法治」）。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：人工智能治理与立法路径\n","permalink":"https://ai.intlaws.com/scholarship/%E7%AE%A1%E8%82%B2%E9%B9%B0-%E6%95%B0%E6%99%BA%E6%97%B6%E4%BB%A3%E7%89%88%E6%9D%83%E4%BE%B5%E6%9D%83%E5%B9%B3%E5%8F%B0%E8%B4%A3%E4%BB%BB%E5%88%A4%E5%AE%9A%E7%9A%84%E6%9D%83%E8%B4%A3%E5%8C%B9%E9%85%8D%E9%80%BB%E8%BE%91/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e版权法是维系多方利益平衡的法律框架，“先授权再使用”规则一直支撑着内容产业的健康发展。信息技术的快速更迭改变了传统的内容产业生态链，互联网发展初期对仅提供技术服务、不介入版权内容经营的平台中立性之假定，已不适用于数智时代越来越多以技术控制内容生产和传播、以流量分成作为营收的多功能综合平台。基于“避风港”规则适用在我国遭遇多重困境和平台“注意义务”标准设定无法形成共识的现实，结合数智技术掌控者已深度介入和实质性控制内容产业运行的实际，应更新平台版权侵权责任判定的理念，依权责匹配逻辑按“技术—市场”控制力高低，分层判定不同类型平台的侵权责任，尤其是基于用户协议直接控制用户内容传播并以此获利的平台之替代责任。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：数智时代版权侵权平台责任判定的权责匹配逻辑，《中外法学》2026 年第 4 期（「专题：数字法治」）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/fxyjdt/202607/t20260721_6060226.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：人工智能治理与立法路径\u003c/p\u003e","title":"管育鹰：数智时代版权侵权平台责任判定的权责匹配逻辑"},{"content":"摘要（期刊要目页所载原文摘要）\n新技术给社会不同人群带来的影响往往是不均质的，这种差异化影响为认知、分析数字法治领域相关议题提示了一种可能视角。作为知识线索和分析框架的“数字拉齐”，将技术应用的出现和扩展视为导致本限于精英群体的受惠与困扰向普通民众扩散的社会过程。“数字拉齐”提供了一种有关诸多数字法治议题生成逻辑的解释。在身份认证、智能法律服务、智能个人助理等典型场景中，“数字拉齐”可能以不同形式呈现，并对应相互区别的治理思路。当新技术应用被认为未给民众带来充分受惠、却使其面临更多新的困扰，即导致“非对称拉齐”时，严格监管的社会呼声更容易出现，也有更强的正当性与合理性。而若新技术应用给民众带来的受惠与困扰基本相当，或受惠明显超出困扰时，治理者更宜选取审慎监管策略，乃至采取以鼓励创新、推动发展为主旨的举措。\n出处：「数字拉齐」：数字法治议题的知识线索与分析框架，《中外法学》2026 年第 1 期（「专题：数字法治」）。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：数字法治框架与域外治理\n","permalink":"https://ai.intlaws.com/scholarship/%E6%88%B4%E6%98%95-%E6%95%B0%E5%AD%97%E6%8B%89%E9%BD%90-%E6%95%B0%E5%AD%97%E6%B3%95%E6%B2%BB%E8%AE%AE%E9%A2%98%E7%9A%84%E7%9F%A5%E8%AF%86%E7%BA%BF%E7%B4%A2%E4%B8%8E%E5%88%86%E6%9E%90%E6%A1%86%E6%9E%B6/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e新技术给社会不同人群带来的影响往往是不均质的，这种差异化影响为认知、分析数字法治领域相关议题提示了一种可能视角。作为知识线索和分析框架的“数字拉齐”，将技术应用的出现和扩展视为导致本限于精英群体的受惠与困扰向普通民众扩散的社会过程。“数字拉齐”提供了一种有关诸多数字法治议题生成逻辑的解释。在身份认证、智能法律服务、智能个人助理等典型场景中，“数字拉齐”可能以不同形式呈现，并对应相互区别的治理思路。当新技术应用被认为未给民众带来充分受惠、却使其面临更多新的困扰，即导致“非对称拉齐”时，严格监管的社会呼声更容易出现，也有更强的正当性与合理性。而若新技术应用给民众带来的受惠与困扰基本相当，或受惠明显超出困扰时，治理者更宜选取审慎监管策略，乃至采取以鼓励创新、推动发展为主旨的举措。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：「数字拉齐」：数字法治议题的知识线索与分析框架，《中外法学》2026 年第 1 期（「专题：数字法治」）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/fxyjdt/202601/t20260123_5970638.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：数字法治框架与域外治理\u003c/p\u003e","title":"戴昕：「数字拉齐」：数字法治议题的知识线索与分析框架"},{"content":"摘要（期刊要目页所载原文摘要）\n欧盟人工智能治理正在边境场景中形成区别于传统“布鲁塞尔效应”的外溢路径。欧盟《人工智能法》将边境应用界定为高风险领域，设定更为严格的合规义务；《边境与签证互操作性条例》《警务司法合作、庇护与移民互操作性条例》通过数据库整合与数据接口统一，在制度与技术运行层面嵌入合规要求。法律与技术的耦合效应，使欧盟规制影响不再局限于市场准入，而是在系统接入条件下，通过技术与制度安排，使合作国适用欧盟规则和标准，形成嵌入式外溢。在欧盟外部政策支持、合作国家现实权衡与欧盟法持续合规框架的共同作用下，这种外溢呈现制度化发展趋势。其对合作国的影响主要体现为规则依赖加深、技术路径锁定与产业结构压制的三重效应，并可能通过合作链条传导至中国企业，导致合规成本上升、制度壁垒增强与竞争空间收缩等间接压力。在“一带一路”倡议与“数字丝绸之路”持续推进的背景下，中国应由被动回应转向主动塑造，通过建立前置性法律影响评估、探索最低共同标准、制度升级“数字丝绸之路”与主动塑造多边议程，将潜在外部压力转化为制度创新空间。\n出处：欧盟人工智能治理的嵌入式外溢与中国因应，《环球法律评论》2026 年第 2 期（「涉外法治」栏目）。\n等级：CSSCI 来源期刊（2025—2026 年版，法学类）。\n直链：中国法学网要目页 （中国社会科学院法学研究所主办，链接现场可打开）\n主题：数字法治框架与域外治理\n","permalink":"https://ai.intlaws.com/scholarship/%E9%AD%8F%E6%80%A1%E7%84%B6-%E6%AC%A7%E7%9B%9F%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E6%B2%BB%E7%90%86%E7%9A%84%E5%B5%8C%E5%85%A5%E5%BC%8F%E5%A4%96%E6%BA%A2%E4%B8%8E%E4%B8%AD%E5%9B%BD%E5%9B%A0%E5%BA%94/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（期刊要目页所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e欧盟人工智能治理正在边境场景中形成区别于传统“布鲁塞尔效应”的外溢路径。欧盟《人工智能法》将边境应用界定为高风险领域，设定更为严格的合规义务；《边境与签证互操作性条例》《警务司法合作、庇护与移民互操作性条例》通过数据库整合与数据接口统一，在制度与技术运行层面嵌入合规要求。法律与技术的耦合效应，使欧盟规制影响不再局限于市场准入，而是在系统接入条件下，通过技术与制度安排，使合作国适用欧盟规则和标准，形成嵌入式外溢。在欧盟外部政策支持、合作国家现实权衡与欧盟法持续合规框架的共同作用下，这种外溢呈现制度化发展趋势。其对合作国的影响主要体现为规则依赖加深、技术路径锁定与产业结构压制的三重效应，并可能通过合作链条传导至中国企业，导致合规成本上升、制度壁垒增强与竞争空间收缩等间接压力。在“一带一路”倡议与“数字丝绸之路”持续推进的背景下，中国应由被动回应转向主动塑造，通过建立前置性法律影响评估、探索最低共同标准、制度升级“数字丝绸之路”与主动塑造多边议程，将潜在外部压力转化为制度创新空间。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：欧盟人工智能治理的嵌入式外溢与中国因应，《环球法律评论》2026 年第 2 期（「涉外法治」栏目）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e等级\u003c/strong\u003e：CSSCI 来源期刊（2025—2026 年版，法学类）。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"http://iolaw.cssn.cn/journal/huanqiu/202603/t20260324_5977834.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国法学网要目页\u003c/a\u003e\n（中国社会科学院法学研究所主办，链接现场可打开）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：数字法治框架与域外治理\u003c/p\u003e","title":"魏怡然：欧盟人工智能治理的嵌入式外溢与中国因应"},{"content":"2026 年 6—9 月的中文期刊文献呈现三个明确转向：其一，从\u0026quot;立规\u0026quot;转向\u0026quot;归责\u0026quot;——学界重心由规则创制移向责任配置；其二，从\u0026quot;通用治理\u0026quot;转向\u0026quot;场景与要素治理\u0026quot;——智能体、模型开源、政务智能体、数据跨境流动成为新的落点；其三，从\u0026quot;软法宣示\u0026quot;转向\u0026quot;硬法化与规则负担的再平衡\u0026quot;。法哲学层面的\u0026quot;规范延迟\u0026quot;与伦理层面的\u0026quot;价值对齐幻象\u0026quot;构成两条并行的理论省思主线；2026 年 9 月 7 日最高人民法院《关于依法审理涉人工智能纠纷案件的意见》（法发〔2026〕10号）的发布，使该季度研究获得了鲜明的司法回应背景。\n一、检索口径与选文范围 时间窗：采用\u0026quot;滚动窗＋刊期\u0026quot;双标注口径——收录窗口为 2026-06-25 至 2026-09-25，同时标注文献所属刊期或网络首发日；凡出版时间逼近窗口边界的，均在文献清单中显式标注。\n来源范围：以中文核心期刊（CSSCI／北大核心）为主，并纳入《数字法治》等人工智能法治领域权威专业期刊（后者的期刊等级以刊物自身定位为准）；非法学期刊中涉及人工智能治理议题的，仅在必要时纳入并标注刊物性质。本综述以法学及相邻学科为主，非穷尽性检索。\n纳入标准：以人工智能治理为直接研究对象；具备明确的问题意识与规范论证；同一议题优先择取刊期最新的文献。\n边界说明：窗口外但属同一研究脉络的重要文献（如《中国法学》2026年第2期、《现代法学》2026年第3期相关的责任主体研究）不再纳入，仅在必要处提示脉络。窗口边缘文献（《中国社会科学》2026年第6期，2026年6月中旬出版）予以保留并标注，理由是其构成全球治理议题的框架性研究。\n二、总体图景：三个转向 其一，从\u0026quot;立规\u0026quot;到\u0026quot;归责\u0026quot;。 2023—2025 年研究的主轴是\u0026quot;要不要立、立什么\u0026quot;，本季度的重心明显下移至\u0026quot;谁来担、担多少、如何证明\u0026quot;。程啸围绕生成式人工智能服务提供者的注意义务、法定义务与过错展开体系化辨析；张文睿等以行为分析为前提提出分阶段的归责方案；周光权、姚万勤分别从过失犯论与代理理论切入刑事归责。这一转向与最高人民法院 9 月 7 日发布的《关于依法审理涉人工智能纠纷案件的意见》以过错责任为一般归责原则、审慎认定生成式人工智能服务提供者侵权责任的立场同频。\n其二，从\u0026quot;通用治理\u0026quot;到\u0026quot;场景与要素治理\u0026quot;。 本季度出现的明显增量集中在具体落点：AI 智能体的知识幻觉、模型开源许可、政务智能体、自动化行政、裁判文书生成、数据跨境流动、平台版权责任。这表明研究已越过\u0026quot;人工智能治理\u0026quot;的整体性口号，进入按技术形态与业务场景分层的阶段。\n其三，从\u0026quot;软法宣示\u0026quot;到\u0026quot;硬法化与负担再平衡\u0026quot;。 一方面，沈伟等主张治理规则硬法化以克服科林格里奇困境、安全困境与集体行动困境；另一方面，苏宇提出\u0026quot;规则负担的合理配置\u0026quot;，郑戈则对\u0026quot;技术立宪\u0026quot;的法治限度提出警示——同一方向上的两种张力，构成本季度最具理论含量的争论点。\n三、专题综述 （一）治理范式与基础理论：规范延迟、技术立宪与价值对齐 舒国滢（《中外法学》2026年第4期）提出\u0026quot;规范延迟\u0026quot;概念：人工智能技术的高速迭代使既有法律与伦理规范跟进迟缓，难以穿透设计、生产、应用全链条，形成调整滞后的时间差乃至治理真空。其分析框架区分了\u0026quot;以人工智能为对象的治理\u0026quot;与\u0026quot;借助人工智能的治理\u0026quot;，主张构建\u0026quot;人主机辅\u0026quot;\u0026ldquo;人—机规范协同\u0026quot;的秩序图景，并将\u0026quot;人类主导权原则\u0026quot;与\u0026quot;不可让渡领域\u0026quot;作为强人工智能底层架构的强制要求。\n郑戈（《政法论丛》2026年第4期，第3页起）从宪法维度提出\u0026quot;技术立宪\u0026quot;的法治限度问题。苏宇（《政法论丛》2026年第4期，第48页起）关注\u0026quot;人工智能规则负担的合理配置\u0026rdquo;，指向规则密度与守法成本之间的比例问题，与郑戈的警示构成同一问题域的两面。两文的展开论证涉及原文注释与摘要细节，本综述仅作篇名级与提要级转述，细部观点以原刊为准。\n张云龙、滕洋洋（《自然辩证法研究》2026年第7期）对\u0026quot;价值对齐\u0026quot;范式本身提出本体论质疑：大语言模型仅具统计相关性而无意向性，其显现的价值是人类主观投射的幻象；人类价值本身不可通约、依赖语境且内嵌权力关系，使对齐目标预设模糊。文章主张舍弃依附工具理性的外在超越路径，经由主体自我反思的\u0026quot;内在超越\u0026quot;构建负责任的人机共生秩序。王海英（《伦理学研究》2026年第4期）则以马克思主义实践论重构人工智能道德主体性，认为主体性并非源于内在属性，而生成于可评价、可归责、可追溯的实践结构之中——两文共同体现出伦理学内部对\u0026quot;对齐\u0026quot;范式从技术路径向规范路径的回摆。\n（二）侵权归责与责任配置：从注意义务到分层构造 本专题是本季度文献最密集处。程啸（《政法论丛》2026年第4期，第35页起）系统辨析生成式人工智能服务提供者的注意义务、法定义务与过错三者关系，重申其侵权责任属过错责任的基础判断。张文睿、刘颖泽（《河北法学》2026年第7期，第178-194页）主张不宜设置一刀切的统一归责原则，而应以行为分析为前提，结合生成式人工智能不同运行阶段的差异化侵权行为进行归责原则的分层建构——输入阶段适用过错责任原则，输出阶段适用无过错责任原则。余茂玉、王雪岚（《数字法治》2026年第4期）则从司法应用端梳理风险类型与规制路径。\n刑事方向有两条进路。周光权（《法学家》2026年第4期，第46-61页）主张人工智能时代的过失犯论应以结果回避可能性为评价重心，由此在鼓励创新与避免重大事故之间取得平衡，并重构注意义务结构。姚万勤（《政法论坛》2026年第4期，第111页起）提出，人工智能代理的刑事责任归属应从能力分配逻辑转向权力分配逻辑，人工智能体不能成为刑事责任主体，归属对象应是被代理人。\n司法背景：最高人民法院《关于依法审理涉人工智能纠纷案件的意见》（法发〔2026〕10号，2026-09-07 发布）明确：\u0026ldquo;法律没有明确规定适用无过错责任或者过错推定责任的，应当依照民法典第一千一百六十五条第一款规定的过错责任原则认定行为人是否承担侵权责任\u0026rdquo;；应审慎认定生成式人工智能服务提供者的侵权责任，对经权利人通知后未采取必要措施者依法追究责任，对以侵权提示词恶意诱导的用户依法追究责任，权利人可以依照民法典第一千一百九十五条的规定请求保护。答记者问并说明，生成式人工智能服务提供者参照适用\u0026quot;避风港规则\u0026quot;具有正当性、合理性基础。上述裁判立场与本季度学理讨论形成明显的相互印证，也构成综述阅读时的必要语境。\n（三）著作权、训练数据与开源生态 管育鹰（《中外法学》2026年第4期）指出，数智时代以技术控制内容生产与传播、以流量分成为营收的综合平台，已使\u0026quot;避风港\u0026quot;规则所依赖的平台中立性假定失效，主张依\u0026quot;技术—市场\u0026quot;控制力高低分层判定平台侵权责任，尤其强调替代责任。罗祥（《法学杂志》2026年第4期）以\u0026quot;商业学习\u0026quot;重新定性人工智能训练中的复制行为，认为复制权不应控制该类事实性复制，并主张配套补偿金制度、区分高低收入实体设定费率。辜凌云（《清华法学》2026年第4期）研究模型开源的双层治理结构，提出\u0026quot;版权许可＋平台规则\u0026quot;的复合结构，并以收益反哺机制回应贡献激励减弱的现实。吴亚曦（《数字法治》2026年第4期）则聚焦生成式人工智能平台版权责任的适应性建构。四文合观，训练端、许可端与平台端的责任图景已初步成形。\n（四）数据、个人信息与智能体治理 宗绍昊（《东方法学》2026年第4期）将 AI 智能体的新型知识幻觉（记忆、推理、工具、感知四类）纳入法律治理视野，提出\u0026quot;技法互嵌\u0026quot;模型与以合规整改为原则、以处罚为例外的责任承担模式。赵精武、冯文轩（《数字法治》2026年第4期）以智能体场景为中心重构个人信息处理中的\u0026quot;同意\u0026quot;制度。于晓洋（《行政法学研究》2026年第5期）提出个人信息处理同意规则的类型化构造：静态层面确立择入同意为基本模式、择出同意为法定补充、豁免同意为特殊情形的三元结构；动态层面提炼\u0026quot;对个人权益有重大影响\u0026quot;\u0026ldquo;合理范围\u0026quot;\u0026ldquo;为…所必需\u0026quot;等规范变量，作为同意模式转换与同意强度调节的判断依据。易雨竹（《数字法治》2026年第4期）分析生成式人工智能数据跨境流动的风险与法治进路。\n（五）公法与司法场景：自动化行政与人机协同裁判 彭涛（《法商研究》2026年第4期）指出人工智能在相关关系运行、认知化约与\u0026quot;暗知识\u0026quot;三个层面冲击传统正当程序，主张在涉及社会事实的决策中排除自动化决策，并设置强制性的算法解释义务。李蕊佚（《法商研究》2026年第5期）指出，针对技术黑箱、自动化偏见及民事权利冲突导致的信息披露障碍，可从说理内容、说理程度与说理方式三个维度调适自动化行政行为的说理义务：合法性依据应覆盖从法律条文到算法规则的完整链条，合理性理由须披露关键参数并结合比例原则作实质性证成；说理程度构建与行政行为影响程度相匹配的分层标准；说理方式以算法解释为工具，采用易理解、可验证的语言。张翅翔（《法商研究》2026年第5期）揭示人工智能辅助裁判文书生成中的三类说理失衡——修辞压制理性、论证膨胀削弱裁判权威、法律正确性标准偏移，并相应提出程序层面的人工审定机制、内容层面的必要性审查机制与评价层面的差异化标准。陈天昊（《数字法治》2026年第4期）研究政务智能体的规范体系构建。该专题的共同关切是：技术效率与人类判断主体性之间的平衡。\n（六）全球治理与比较监管 王净宇、梁正（《中国社会科学》2026年第6期）构建基于风险类型的国际公共产品供给分析框架，认为风险治理需求与公共产品供给之间的失衡错配构成当前全球人工智能安全治理的主要矛盾，主张构建动态、敏捷的多层次治理架构。沈伟、吴柄萱（《上海交通大学学报（哲学社会科学版）》2026年第4期）论证人工智能倡议作为软法形式的局限，提出规则硬法化是国内（区域）立法与国际条约双重制度条件下的可行路径。孙心茹等（《中国科技论坛》2026年第7期）以 TF-IDF 与 LDA 文本挖掘量化比较中欧生成式人工智能监管体系，发现横向差异化路径与相互借鉴、纵向标准输出与本土创新的双向互动。任志峰（《华中科技大学学报（社会科学版）》，期次未载明，据作者单位通报为 2026 年 7 月前后）以杭州互联网法院生成式 AI 幻觉侵权首案为切入，提出涵盖前端提示、中端审查、技术减幻与后端追溯的闭环治理框架，是\u0026quot;敏捷治理\u0026quot;理念在司法场景的落地尝试。\n四、共识、分歧与研究缺口 已形成的共识：其一，过错责任为一般归责基础，仅在法律另有规定时例外；其二，治理应分层分类，反对\u0026quot;一刀切\u0026rdquo;；其三，人类主体性与可问责性是不可退让的底线。\n尚存的分歧：一是伦理范式之争——\u0026ldquo;价值对齐\u0026quot;是否成立（张云龙等持否定／重构立场，与既有的对齐研究形成对峙）；二是合规路径之争——独立第三方评估（郑戈）与规则负担精简（苏宇）代表两种改革方向；三是软硬法之争——倡议与硬法化的功能边界仍无定论；四是训练数据的定性之争——\u0026ldquo;商业学习说\u0026quot;与复制权控制路径的取舍直接影响补偿金制度的正当性根基。\n研究缺口：① 责任配置研究多停留于规范推演，缺乏对中国司法数据的实证检验；② 智能体、数据跨境流动等新客体与传统法律概念的衔接研究仍不充分，专门规范供给尚待跟进；③ 全球治理研究与国内制度研究之间对话不足，硬法化方案缺少具体的条约设计；④ 关于治理成本与中小主体负担的研究缺乏量化与实证分析。\n五、文献清单 检索日期 2026-09-25。「来源性质」一栏标注该条目的发布方与转载载体，并注明转载页是否省略原文注释；部分来源站点设有访问限制，未逐条取得全文。\n# 文献 出处 来源与直链 来源性质 1 舒国滢《人工智能时代的规范延迟：问题与应对——基于法哲学视角的考察》 《中外法学》2026年第4期（2026-07-21 要目） http://iolaw.cssn.cn/fxyjdt/202607/t20260721_6060226.shtml 期刊主办单位官网（中国法学网） 2 管育鹰《数智时代版权侵权平台责任判定的权责匹配逻辑》 《中外法学》2026年第4期 同上 期刊主办单位官网 3 郑戈《人工智能的宪法与宪法的人工智能——人工智能治理中技术立宪的法治限度及其规范重构》 《政法论丛》2026年第4期，第3页起 https://xbbjb.sdupsl.edu.cn/info/1012/1821.htm 期刊官网目录（2026-07-23）；摘要未载，转述及于篇名与提要层面 4 程啸《论生成式人工智能服务提供者的注意义务、法定义务与过错》 《政法论丛》2026年第4期，第35页起 同上 期刊官网目录 5 苏宇《人工智能规则负担的合理配置》 《政法论丛》2026年第4期，第48页起 同上 期刊官网目录 6 周光权《人工智能时代的过失犯论》 《法学家》2026年第4期，第46-61页 https://faxuejia.ruc.edu.cn/CN/Y2026/V0/I4 期刊官网定刊期页；摘要未载，转述及于篇名与提要层面 7 姚万勤《人工智能代理的权力分配逻辑与刑事责任归属》 《政法论坛》2026年第4期，第111页起 https://m.163.com/news/article/L6500N290530W1MT.html 北大法律信息网官方网易号转载（源自北大法宝法学期刊库，文末附本期目录），已略去原文注释；载内容提要 8 罗祥《人工智能训练作品的商业学习属性与补偿金制度构建》 《法学杂志》2026年第4期 https://www.163.com/dy/article/L4I8RPVG0530W1MT.html 北大法律信息网官方网易号转载（源自北大法宝法学期刊库，含摘要与目次），已略去原文注释 9 辜凌云《论人工智能模型开源的双层治理结构——以版权许可与平台规则为建构》 《清华法学》2026年第4期 http://www.qikanvip.com/qkml/164756.html 商业期刊数据库转载（含摘要、作者单位与基金信息） 10 张文睿、刘颖泽《生成式人工智能服务提供者归责原则的分层建构》 《河北法学》2026年第7期，第178-194页（网络首发 2026-05-28；DOI 10.16494/j.cnki.1002-3933.2026.07.010） https://coaa.istic.ac.cn/openjournal/periodicalArticle/0120260701111501 中国科学技术信息研究所开放学术期刊平台（含摘要、关键词、DOI） 11 彭涛《数字政府中正当程序的底层逻辑与重塑路径》 《法商研究》2026年第4期 http://www.fxcxw.org.cn/dyna/contentM.php?id=29387 中国法学创新网门户转载《法商研究》第4期目录与内容提要（原刊编辑部首发；直链经该门户跳转至微信公众平台原文页） 12 李蕊佚《论自动化行政行为的说理义务》 《法商研究》2026年第5期（2026-09-18） http://www.fxcxw.org.cn/dyna/contentM.php?id=29487 中国法学创新网门户转载《法商研究》2026年第5期目录与内容摘要（编辑部首发，载作者单位与摘要原文；直链经该门户跳转至微信公众平台原文页） 13 张翅翔《人工智能辅助裁判文书生成中的说理失衡及其制度调适》 《法商研究》2026年第5期（2026-09-18） 同上 同上（同第 12 条；直链经该门户跳转至微信公众平台原文页） 14 宗绍昊《AI智能体新型知识幻觉风险的激励型法律治理》 《东方法学》2026年第4期 http://www.fxcxw.org.cn/dyna/contentM.php?id=29478 上海市法学会·《东方法学》官方账号发布，经中国法学创新网门户转载（直链经该门户跳转至微信公众平台原文页） 15 余茂玉、王雪岚《人工智能司法应用的风险与规制》 《数字法治》2026年第4期（总第22期） https://www.courtbook.com.cn/court-web/szfz 主办单位官网（人民法院出版社） 16 陈天昊《数字政府建设视域下政务智能体规范体系构建》 《数字法治》2026年第4期 同上 主办单位官网 17 赵精武、冯文轩《智能经济中个人信息处理\u0026quot;同意\u0026quot;的重构——以智能体场景为中心》 《数字法治》2026年第4期 同上 主办单位官网 18 易雨竹《生成式人工智能数据跨境流动的风险解析与法治进路》 《数字法治》2026年第4期 同上 主办单位官网 19 吴亚曦《生成式人工智能平台版权责任的适应性建构》 《数字法治》2026年第4期 同上 主办单位官网 20 王净宇、梁正《风险类型与国际公共产品供给模式——全球人工智能安全治理的分析框架》 《中国社会科学》2026年第6期，第94-113页（窗口边缘文献：2026年6月中旬出版） https://news.qq.com/rain/a/20260727A0BS0L00 清华大学人工智能国际治理研究院官方账号发布（2026-07-27）经腾讯新闻转载，载原刊题名、作者与页码 21 沈伟、吴柄萱《人工智能治理规则硬法化——以人工智能倡议为对象》 《上海交通大学学报（哲学社会科学版）》2026年第4期 http://www.qikanvip.com/qkml/163659.html 商业期刊数据库转载（含摘要与基金信息） 22 孙心茹、孙刚、赵小渝、黄燕芬《中欧生成式人工智能监管动态特征及比较研究——基于制度互动视角》 《中国科技论坛》2026年第7期，第178-188页 http://www.zgkjlt.org.cn/CN/Y2026/V7/I7/178 期刊官网（含中英文摘要） 23 张云龙、滕洋洋《人工智能价值对齐的幻象困境及其超越》 《自然辩证法研究》2026年第42卷第7期，第37-45页；DOI 10.19484/j.cnki.1000-8934.2026.07.004 https://zrbz.cbpt.cnki.net/portal/journal/portal/client/paper/cd860f1a15a45254dc266a88d885e956 期刊官网（含作者、单位、DOI、引文格式） 24 王海英《人工智能道德主体性的实践论重构》 《伦理学研究》2026年第4期，第37-45页（2026-08-31 出版） https://llx.hunnu.edu.cn/EN/abstract/abstract3512.shtml 期刊官网（含作者简介与出版信息） 25 于晓洋《个人信息处理同意规则的类型化构造及其动态调适》 《行政法学研究》2026年第5期 https://m.toutiao.com/article/7670355894885974564 上海市法学会官方账号汇编转载（《智慧法治学术动态》2026年第29期总第201期，2026-08-05，载原刊摘要） 26 任志峰《AI幻觉的传播风险、司法归责与敏捷治理》 《华中科技大学学报（社会科学版）》（期次未载明，据作者单位通报为 2026 年 7 月前后） https://gench.edu.cn/2026/0701/c3150a185025/page.htm 作者单位官网通报（含论文摘要要点） 背景性司法文件（非期刊文献）：最高人民法院《关于依法审理涉人工智能纠纷案件的意见》（法发〔2026〕10号，2026-09-07 发布），发布稿 https://www.court.gov.cn/zixun/xiangqing/511101.html 、答记者问 https://www.court.gov.cn/zixun/xiangqing/511111.html （检索于 2026-09-25）。\n六、来源说明 来源性质：文献清单「来源性质」一栏标注该条目的发布方与转载载体，并注明转载页是否省略原文注释。其中第 9、21 条取自商业期刊数据库，第 25 条系上海市法学会官方账号汇编转载，第 7、8 条系北大法律信息网官方网易号转载（均略去原文注释），第 26 条系作者单位官网通报；上述来源所载著录与摘要均转自原刊，正式引用建议以原刊纸本或数据库版本为准。 表述原则：正文转述以期刊公开信息（摘要、目录、关键词）为据。其中第 3、6 条两文的原刊摘要未公开，相关转述仅及篇名级与提要级，细部以原刊为准；未使用无法溯源的\u0026quot;通说\u0026quot;\u0026ldquo;一般认为\u0026quot;式表述。 口径说明：时间窗为 2026-06-25 至 2026-09-25 滚动窗，兼标刊期；窗口边缘文献已在清单中显式标注。 范围局限：本综述以法学及相邻学科为主，非穷尽性检索，未系统覆盖图书情报、计算机、公共管理等学科对同一议题的研究；《法学研究》《法学》等刊本期相关文献未纳入本次检索范围，后续可补充。 直链落点：转载型门户页若发生跳转，直链一律标注最终落点平台。本清单第 11–14 条的直链为中国法学创新网门户页，该页系跳转页（站内无正文），点击后落在微信公众平台原文页（承载账号「法学创新网」，中国法学会主管；第 11、12、13 条原文由《法商研究》编辑部首发，第 14 条原文来源为上海市法学会「东方法学」官方账号）。该等平台链接可能被发布方删除或改动，正式引用仍以原刊纸本或数据库版本为准。 链接与访问日期：链接可达性以检索当日（2026-09-25）为准；部分来源站点设有访问限制，个别页面可能随时间变化；\u0026ldquo;当期／滚动\u0026quot;型页面一律以定刊期归档页替代链接。 ","permalink":"https://ai.intlaws.com/scholarship/%E6%B3%95%E5%AD%A6%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E5%AE%9E%E9%AA%8C%E5%AE%A4-%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E6%B2%BB%E7%90%86%E7%A0%94%E7%A9%B6%E7%BB%BC%E8%BF%B0-2026%E5%B9%B46-9%E6%9C%88/","summary":"\u003cp\u003e2026 年 6—9 月的中文期刊文献呈现三个明确转向：\u003cstrong\u003e其一，从\u0026quot;立规\u0026quot;转向\u0026quot;归责\u0026quot;\u003c/strong\u003e——学界重心由规则创制移向责任配置；\u003cstrong\u003e其二，从\u0026quot;通用治理\u0026quot;转向\u0026quot;场景与要素治理\u0026quot;\u003c/strong\u003e——智能体、模型开源、政务智能体、数据跨境流动成为新的落点；\u003cstrong\u003e其三，从\u0026quot;软法宣示\u0026quot;转向\u0026quot;硬法化与规则负担的再平衡\u0026quot;\u003c/strong\u003e。法哲学层面的\u0026quot;规范延迟\u0026quot;与伦理层面的\u0026quot;价值对齐幻象\u0026quot;构成两条并行的理论省思主线；2026 年 9 月 7 日最高人民法院《关于依法审理涉人工智能纠纷案件的意见》（法发〔2026〕10号）的发布，使该季度研究获得了鲜明的司法回应背景。\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"一检索口径与选文范围\"\u003e一、检索口径与选文范围\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e时间窗\u003c/strong\u003e：采用\u0026quot;滚动窗＋刊期\u0026quot;双标注口径——收录窗口为 \u003cstrong\u003e2026-06-25 至 2026-09-25\u003c/strong\u003e，同时标注文献所属刊期或网络首发日；凡出版时间逼近窗口边界的，均在文献清单中显式标注。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e来源范围\u003c/strong\u003e：以中文核心期刊（CSSCI／北大核心）为主，并纳入《数字法治》等人工智能法治领域权威专业期刊（后者的期刊等级以刊物自身定位为准）；非法学期刊中涉及人工智能治理议题的，仅在必要时纳入并标注刊物性质。本综述以法学及相邻学科为主，非穷尽性检索。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e纳入标准\u003c/strong\u003e：以人工智能治理为直接研究对象；具备明确的问题意识与规范论证；同一议题优先择取刊期最新的文献。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e边界说明\u003c/strong\u003e：窗口外但属同一研究脉络的重要文献（如《中国法学》2026年第2期、《现代法学》2026年第3期相关的责任主体研究）不再纳入，仅在必要处提示脉络。窗口边缘文献（《中国社会科学》2026年第6期，2026年6月中旬出版）予以保留并标注，理由是其构成全球治理议题的框架性研究。\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"二总体图景三个转向\"\u003e二、总体图景：三个转向\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e其一，从\u0026quot;立规\u0026quot;到\u0026quot;归责\u0026quot;。\u003c/strong\u003e 2023—2025 年研究的主轴是\u0026quot;要不要立、立什么\u0026quot;，本季度的重心明显下移至\u0026quot;谁来担、担多少、如何证明\u0026quot;。程啸围绕生成式人工智能服务提供者的注意义务、法定义务与过错展开体系化辨析；张文睿等以行为分析为前提提出分阶段的归责方案；周光权、姚万勤分别从过失犯论与代理理论切入刑事归责。这一转向与最高人民法院 9 月 7 日发布的《关于依法审理涉人工智能纠纷案件的意见》以过错责任为一般归责原则、审慎认定生成式人工智能服务提供者侵权责任的立场同频。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e其二，从\u0026quot;通用治理\u0026quot;到\u0026quot;场景与要素治理\u0026quot;。\u003c/strong\u003e 本季度出现的明显增量集中在具体落点：AI 智能体的知识幻觉、模型开源许可、政务智能体、自动化行政、裁判文书生成、数据跨境流动、平台版权责任。这表明研究已越过\u0026quot;人工智能治理\u0026quot;的整体性口号，进入按技术形态与业务场景分层的阶段。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e其三，从\u0026quot;软法宣示\u0026quot;到\u0026quot;硬法化与负担再平衡\u0026quot;。\u003c/strong\u003e 一方面，沈伟等主张治理规则硬法化以克服科林格里奇困境、安全困境与集体行动困境；另一方面，苏宇提出\u0026quot;规则负担的合理配置\u0026quot;，郑戈则对\u0026quot;技术立宪\u0026quot;的法治限度提出警示——同一方向上的两种张力，构成本季度最具理论含量的争论点。\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"三专题综述\"\u003e三、专题综述\u003c/h2\u003e\n\u003ch3 id=\"一治理范式与基础理论规范延迟技术立宪与价值对齐\"\u003e（一）治理范式与基础理论：规范延迟、技术立宪与价值对齐\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e舒国滢\u003c/strong\u003e（《中外法学》2026年第4期）提出\u0026quot;规范延迟\u0026quot;概念：人工智能技术的高速迭代使既有法律与伦理规范跟进迟缓，难以穿透设计、生产、应用全链条，形成调整滞后的时间差乃至治理真空。其分析框架区分了\u0026quot;以人工智能为对象的治理\u0026quot;与\u0026quot;借助人工智能的治理\u0026quot;，主张构建\u0026quot;人主机辅\u0026quot;\u0026ldquo;人—机规范协同\u0026quot;的秩序图景，并将\u0026quot;人类主导权原则\u0026quot;与\u0026quot;不可让渡领域\u0026quot;作为强人工智能底层架构的强制要求。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e郑戈\u003c/strong\u003e（《政法论丛》2026年第4期，第3页起）从宪法维度提出\u0026quot;技术立宪\u0026quot;的法治限度问题。\u003cstrong\u003e苏宇\u003c/strong\u003e（《政法论丛》2026年第4期，第48页起）关注\u0026quot;人工智能规则负担的合理配置\u0026rdquo;，指向规则密度与守法成本之间的比例问题，与郑戈的警示构成同一问题域的两面。两文的展开论证涉及原文注释与摘要细节，本综述仅作篇名级与提要级转述，细部观点以原刊为准。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e张云龙、滕洋洋\u003c/strong\u003e（《自然辩证法研究》2026年第7期）对\u0026quot;价值对齐\u0026quot;范式本身提出本体论质疑：大语言模型仅具统计相关性而无意向性，其显现的价值是人类主观投射的幻象；人类价值本身不可通约、依赖语境且内嵌权力关系，使对齐目标预设模糊。文章主张舍弃依附工具理性的外在超越路径，经由主体自我反思的\u0026quot;内在超越\u0026quot;构建负责任的人机共生秩序。\u003cstrong\u003e王海英\u003c/strong\u003e（《伦理学研究》2026年第4期）则以马克思主义实践论重构人工智能道德主体性，认为主体性并非源于内在属性，而生成于可评价、可归责、可追溯的实践结构之中——两文共同体现出伦理学内部对\u0026quot;对齐\u0026quot;范式从技术路径向规范路径的回摆。\u003c/p\u003e\n\u003ch3 id=\"二侵权归责与责任配置从注意义务到分层构造\"\u003e（二）侵权归责与责任配置：从注意义务到分层构造\u003c/h3\u003e\n\u003cp\u003e本专题是本季度文献最密集处。\u003cstrong\u003e程啸\u003c/strong\u003e（《政法论丛》2026年第4期，第35页起）系统辨析生成式人工智能服务提供者的注意义务、法定义务与过错三者关系，重申其侵权责任属过错责任的基础判断。\u003cstrong\u003e张文睿、刘颖泽\u003c/strong\u003e（《河北法学》2026年第7期，第178-194页）主张不宜设置一刀切的统一归责原则，而应以行为分析为前提，结合生成式人工智能不同运行阶段的差异化侵权行为进行归责原则的分层建构——输入阶段适用过错责任原则，输出阶段适用无过错责任原则。\u003cstrong\u003e余茂玉、王雪岚\u003c/strong\u003e（《数字法治》2026年第4期）则从司法应用端梳理风险类型与规制路径。\u003c/p\u003e\n\u003cp\u003e刑事方向有两条进路。\u003cstrong\u003e周光权\u003c/strong\u003e（《法学家》2026年第4期，第46-61页）主张人工智能时代的过失犯论应以结果回避可能性为评价重心，由此在鼓励创新与避免重大事故之间取得平衡，并重构注意义务结构。\u003cstrong\u003e姚万勤\u003c/strong\u003e（《政法论坛》2026年第4期，第111页起）提出，人工智能代理的刑事责任归属应从能力分配逻辑转向权力分配逻辑，人工智能体不能成为刑事责任主体，归属对象应是被代理人。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e司法背景\u003c/strong\u003e：最高人民法院《关于依法审理涉人工智能纠纷案件的意见》（法发〔2026〕10号，2026-09-07 发布）明确：\u0026ldquo;法律没有明确规定适用无过错责任或者过错推定责任的，应当依照民法典第一千一百六十五条第一款规定的过错责任原则认定行为人是否承担侵权责任\u0026rdquo;；应审慎认定生成式人工智能服务提供者的侵权责任，对经权利人通知后未采取必要措施者依法追究责任，对以侵权提示词恶意诱导的用户依法追究责任，权利人可以依照民法典第一千一百九十五条的规定请求保护。答记者问并说明，生成式人工智能服务提供者参照适用\u0026quot;避风港规则\u0026quot;具有正当性、合理性基础。上述裁判立场与本季度学理讨论形成明显的相互印证，也构成综述阅读时的必要语境。\u003c/p\u003e\n\u003ch3 id=\"三著作权训练数据与开源生态\"\u003e（三）著作权、训练数据与开源生态\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e管育鹰\u003c/strong\u003e（《中外法学》2026年第4期）指出，数智时代以技术控制内容生产与传播、以流量分成为营收的综合平台，已使\u0026quot;避风港\u0026quot;规则所依赖的平台中立性假定失效，主张依\u0026quot;技术—市场\u0026quot;控制力高低分层判定平台侵权责任，尤其强调替代责任。\u003cstrong\u003e罗祥\u003c/strong\u003e（《法学杂志》2026年第4期）以\u0026quot;商业学习\u0026quot;重新定性人工智能训练中的复制行为，认为复制权不应控制该类事实性复制，并主张配套补偿金制度、区分高低收入实体设定费率。\u003cstrong\u003e辜凌云\u003c/strong\u003e（《清华法学》2026年第4期）研究模型开源的双层治理结构，提出\u0026quot;版权许可＋平台规则\u0026quot;的复合结构，并以收益反哺机制回应贡献激励减弱的现实。\u003cstrong\u003e吴亚曦\u003c/strong\u003e（《数字法治》2026年第4期）则聚焦生成式人工智能平台版权责任的适应性建构。四文合观，训练端、许可端与平台端的责任图景已初步成形。\u003c/p\u003e\n\u003ch3 id=\"四数据个人信息与智能体治理\"\u003e（四）数据、个人信息与智能体治理\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e宗绍昊\u003c/strong\u003e（《东方法学》2026年第4期）将 AI 智能体的新型知识幻觉（记忆、推理、工具、感知四类）纳入法律治理视野，提出\u0026quot;技法互嵌\u0026quot;模型与以合规整改为原则、以处罚为例外的责任承担模式。\u003cstrong\u003e赵精武、冯文轩\u003c/strong\u003e（《数字法治》2026年第4期）以智能体场景为中心重构个人信息处理中的\u0026quot;同意\u0026quot;制度。\u003cstrong\u003e于晓洋\u003c/strong\u003e（《行政法学研究》2026年第5期）提出个人信息处理同意规则的类型化构造：静态层面确立择入同意为基本模式、择出同意为法定补充、豁免同意为特殊情形的三元结构；动态层面提炼\u0026quot;对个人权益有重大影响\u0026quot;\u0026ldquo;合理范围\u0026quot;\u0026ldquo;为…所必需\u0026quot;等规范变量，作为同意模式转换与同意强度调节的判断依据。\u003cstrong\u003e易雨竹\u003c/strong\u003e（《数字法治》2026年第4期）分析生成式人工智能数据跨境流动的风险与法治进路。\u003c/p\u003e\n\u003ch3 id=\"五公法与司法场景自动化行政与人机协同裁判\"\u003e（五）公法与司法场景：自动化行政与人机协同裁判\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e彭涛\u003c/strong\u003e（《法商研究》2026年第4期）指出人工智能在相关关系运行、认知化约与\u0026quot;暗知识\u0026quot;三个层面冲击传统正当程序，主张在涉及社会事实的决策中排除自动化决策，并设置强制性的算法解释义务。\u003cstrong\u003e李蕊佚\u003c/strong\u003e（《法商研究》2026年第5期）指出，针对技术黑箱、自动化偏见及民事权利冲突导致的信息披露障碍，可从说理内容、说理程度与说理方式三个维度调适自动化行政行为的说理义务：合法性依据应覆盖从法律条文到算法规则的完整链条，合理性理由须披露关键参数并结合比例原则作实质性证成；说理程度构建与行政行为影响程度相匹配的分层标准；说理方式以算法解释为工具，采用易理解、可验证的语言。\u003cstrong\u003e张翅翔\u003c/strong\u003e（《法商研究》2026年第5期）揭示人工智能辅助裁判文书生成中的三类说理失衡——修辞压制理性、论证膨胀削弱裁判权威、法律正确性标准偏移，并相应提出程序层面的人工审定机制、内容层面的必要性审查机制与评价层面的差异化标准。\u003cstrong\u003e陈天昊\u003c/strong\u003e（《数字法治》2026年第4期）研究政务智能体的规范体系构建。该专题的共同关切是：\u003cstrong\u003e技术效率与人类判断主体性之间的平衡\u003c/strong\u003e。\u003c/p\u003e\n\u003ch3 id=\"六全球治理与比较监管\"\u003e（六）全球治理与比较监管\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e王净宇、梁正\u003c/strong\u003e（《中国社会科学》2026年第6期）构建基于风险类型的国际公共产品供给分析框架，认为风险治理需求与公共产品供给之间的失衡错配构成当前全球人工智能安全治理的主要矛盾，主张构建动态、敏捷的多层次治理架构。\u003cstrong\u003e沈伟、吴柄萱\u003c/strong\u003e（《上海交通大学学报（哲学社会科学版）》2026年第4期）论证人工智能倡议作为软法形式的局限，提出规则硬法化是国内（区域）立法与国际条约双重制度条件下的可行路径。\u003cstrong\u003e孙心茹等\u003c/strong\u003e（《中国科技论坛》2026年第7期）以 TF-IDF 与 LDA 文本挖掘量化比较中欧生成式人工智能监管体系，发现横向差异化路径与相互借鉴、纵向标准输出与本土创新的双向互动。\u003cstrong\u003e任志峰\u003c/strong\u003e（《华中科技大学学报（社会科学版）》，期次未载明，据作者单位通报为 2026 年 7 月前后）以杭州互联网法院生成式 AI 幻觉侵权首案为切入，提出涵盖前端提示、中端审查、技术减幻与后端追溯的闭环治理框架，是\u0026quot;敏捷治理\u0026quot;理念在司法场景的落地尝试。\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"四共识分歧与研究缺口\"\u003e四、共识、分歧与研究缺口\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e已形成的共识\u003c/strong\u003e：其一，过错责任为一般归责基础，仅在法律另有规定时例外；其二，治理应分层分类，反对\u0026quot;一刀切\u0026rdquo;；其三，人类主体性与可问责性是不可退让的底线。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e尚存的分歧\u003c/strong\u003e：一是\u003cstrong\u003e伦理范式之争\u003c/strong\u003e——\u0026ldquo;价值对齐\u0026quot;是否成立（张云龙等持否定／重构立场，与既有的对齐研究形成对峙）；二是\u003cstrong\u003e合规路径之争\u003c/strong\u003e——独立第三方评估（郑戈）与规则负担精简（苏宇）代表两种改革方向；三是\u003cstrong\u003e软硬法之争\u003c/strong\u003e——倡议与硬法化的功能边界仍无定论；四是\u003cstrong\u003e训练数据的定性之争\u003c/strong\u003e——\u0026ldquo;商业学习说\u0026quot;与复制权控制路径的取舍直接影响补偿金制度的正当性根基。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e研究缺口\u003c/strong\u003e：① 责任配置研究多停留于规范推演，缺乏对中国司法数据的实证检验；② 智能体、数据跨境流动等新客体与传统法律概念的衔接研究仍不充分，专门规范供给尚待跟进；③ 全球治理研究与国内制度研究之间对话不足，硬法化方案缺少具体的条约设计；④ 关于\u003cstrong\u003e治理成本与中小主体负担\u003c/strong\u003e的研究缺乏量化与实证分析。\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"五文献清单\"\u003e五、文献清单\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e检索日期 \u003cstrong\u003e2026-09-25\u003c/strong\u003e。「来源性质」一栏标注该条目的发布方与转载载体，并注明转载页是否省略原文注释；部分来源站点设有访问限制，未逐条取得全文。\u003c/p\u003e","title":"人工智能治理研究综述（2026 年 6—9 月）"},{"content":"摘要（出版方所载原文摘要）\nIn June 2024, the EU AI Act came into force. The AI Act includes obligations for the provider of an AI system. Article 10 of the AI Act includes a new obligation for providers to evaluate whether their training, validation and testing datasets meet certain quality criteria, including an appropriate examination of biases in the datasets and correction measures. With the obligation comes a new provision in Article 10(5) AI Act, allowing providers to collect sensitive data to fulfil the obligation. Article 10(5) AI Act aims to prevent discrimination. In this paper, I investigate the scope and implications of Article 10(5) AI Act. The paper primarily concerns European Union law, but may be relevant in other parts of the world, as policymakers aim to regulate biases in AI systems.\n出处：Using sensitive data to de-bias AI systems: Article 10(5) of the EU AI Act，Computer Law \u0026amp; Security Review, Vol. 56 (2025), Art. 106115。\n作者：Marvin van Bekkum（荷兰拉德堡德大学 Radboud University）\n收录：SSCI 收录（Law 类）；据 WoS Journal Info 聚合页核验（ISSN 2212-473X）。\n直链：10.1016/j.clsr.2025.106115 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：欧盟人工智能法与敏感数据治理\n","permalink":"https://ai.intlaws.com/scholarship/van-bekkum-using-sensitive-data-to-debias-ai-systems-article-10-5-ai-act/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（出版方所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eIn June 2024, the EU AI Act came into force. The AI Act includes obligations for the provider of an AI system. Article 10 of the AI Act includes a new obligation for providers to evaluate whether their training, validation and testing datasets meet certain quality criteria, including an appropriate examination of biases in the datasets and correction measures. With the obligation comes a new provision in Article 10(5) AI Act, allowing providers to collect sensitive data to fulfil the obligation. Article 10(5) AI Act aims to prevent discrimination. In this paper, I investigate the scope and implications of Article 10(5) AI Act. The paper primarily concerns European Union law, but may be relevant in other parts of the world, as policymakers aim to regulate biases in AI systems.\u003c/p\u003e","title":"Using sensitive data to de-bias AI systems: Article 10(5) of the EU AI Act"},{"content":"摘要（出版方所载原文摘要）\nThe risk-based approach of the AI Act (AIA) results in a complex normative structure, in which the applicable subset of rules for a specific AI system is determined by the general scope of application and the classification of the system into particular risk levels. A pyramid of risks, a widely accepted explanation of the risk-based approach proposed by the European Commission, fails to provide a comprehensive classification process and does not accurately reflect the risk levels (either directly or indirectly) recognized in the AIA or the relation between classification criteria. This paper proposes a corrective solution to rebuild the pyramid of risks. Given that each AI system must be classified into one risk level and the AIA assigns a specific subset of rules to each risk level, an adaptation of the Commission ’ s risk levels was necessary. Two types of exceptions are included in the list of prohibited AI practices, which significantly impact the classification process. The exception stricto sensu (in a strict sense) is the result of a balancing of interests, whereas the exception lato sensu (in a broader sense) is due to the absence of excessive regulatory risks. The transparency requirements, identified by the pyramid as a “ limited-risk level, ” operate in parallel with the risk-based approach and do not constitute an independent risk level. Furthermore, as the AIA assigns a specific subset of rules to AI systems used in critical areas that do not pose significant risks, it is necessary to recognize a separate risk level (non-high risk). By analyzing the pyramid of risks, this study suggests representing the classification process as a binary decision diagram. This ensures that the risk-based approach is clearly defined and can help regulators and regulatees classify AI systems in accordance with the AIA.\n出处：Rebuilding the pyramid: The AI Act\u0026rsquo;s risk-based approach using a binary decision diagram，Computer Law \u0026amp; Security Review, Vol. 58 (2025), Art. 106189。\n作者：Gustavo Gil Gasiola（德国卡尔斯鲁厄理工学院 KIT）\n收录：SSCI 收录（Law 类）；据 WoS Journal Info 聚合页核验。\n直链：10.1016/j.clsr.2025.106189 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：欧盟人工智能法与敏感数据治理\n","permalink":"https://ai.intlaws.com/scholarship/gasiola-rebuilding-the-pyramid-ai-act-risk-based-approach/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（出版方所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThe risk-based approach of the AI Act (AIA) results in a complex normative structure, in which the applicable subset of rules for a specific AI system is determined by the general scope of application and the classification of the system into particular risk levels. A pyramid of risks, a widely accepted explanation of the risk-based approach proposed by the European Commission, fails to provide a comprehensive classification process and does not accurately reflect the risk levels (either directly or indirectly) recognized in the AIA or the relation between classification criteria. This paper proposes a corrective solution to rebuild the pyramid of risks. Given that each AI system must be classified into one risk level and the AIA assigns a specific subset of rules to each risk level, an adaptation of the Commission ’ s risk levels was necessary. Two types of exceptions are included in the list of prohibited AI practices, which significantly impact the classification process. The exception stricto sensu (in a strict sense) is the result of a balancing of interests, whereas the exception lato sensu (in a broader sense) is due to the absence of excessive regulatory risks. The transparency requirements, identified by the pyramid as a “ limited-risk level, ” operate in parallel with the risk-based approach and do not constitute an independent risk level. Furthermore, as the AIA assigns a specific subset of rules to AI systems used in critical areas that do not pose significant risks, it is necessary to recognize a separate risk level (non-high risk). By analyzing the pyramid of risks, this study suggests representing the classification process as a binary decision diagram. This ensures that the risk-based approach is clearly defined and can help regulators and regulatees classify AI systems in accordance with the AIA.\u003c/p\u003e","title":"Rebuilding the pyramid: The AI Act's risk-based approach using a binary decision diagram"},{"content":"摘要：该文官方摘要暂未公开，本页暂不载摘要原文；取得后补录。\n出处：Permitted by design? Article 10(5) AIA, sensitive data, and the legal illusion of bias correction，International Data Privacy Law, Vol. 16, Issue 1 (2026)。\n作者：Arnoud Engelfriet（荷兰阿姆斯特丹自由大学 VU Amsterdam）\n收录：SSCI 收录（Law 类）；据 WoS Journal Info 聚合页核验。\n直链：10.1093/idpl/ipaf035 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：欧盟人工智能法与敏感数据治理\n","permalink":"https://ai.intlaws.com/scholarship/engelfriet-permitted-by-design-article-10-5-aia/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e：该文官方摘要暂未公开，本页暂不载摘要原文；取得后补录。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：Permitted by design? Article 10(5) AIA, sensitive data, and the legal illusion of bias correction，International Data Privacy Law, Vol. 16, Issue 1 (2026)。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e作者\u003c/strong\u003e：Arnoud Engelfriet（荷兰阿姆斯特丹自由大学 VU Amsterdam）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e收录\u003c/strong\u003e：SSCI 收录（Law 类）；据 WoS Journal Info 聚合页核验。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"https://doi.org/10.1093/idpl/ipaf035\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e10.1093/idpl/ipaf035\u003c/a\u003e\n（DOI 解析；题录经 Crossref API 逐条比对一致）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：欧盟人工智能法与敏感数据治理\u003c/p\u003e","title":"Permitted by design? Article 10(5) AIA, sensitive data, and the legal illusion of bias correction"},{"content":"摘要：该文官方摘要暂未公开，本页暂不载摘要原文；取得后补录。\n出处：Assessing the implementation of China\u0026rsquo;s personal information protection law: a two-year review，International Data Privacy Law, Vol. 15, Issue 1 (2025), pp. 18 起。\n作者：Guosong Shao、Qi Huang、Qin Xiang、Chengxin Peng\n收录：SSCI 收录（Law 类）；据 WoS Journal Info 聚合页核验。\n直链：10.1093/idpl/ipae022 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：中国数据保护与 AI 训练数据的法律基础\n","permalink":"https://ai.intlaws.com/scholarship/shao-assessing-implementation-of-china-pipl-two-year-review/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e：该文官方摘要暂未公开，本页暂不载摘要原文；取得后补录。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：Assessing the implementation of China\u0026rsquo;s personal information protection law: a two-year review，International Data Privacy Law, Vol. 15, Issue 1 (2025), pp. 18 起。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e作者\u003c/strong\u003e：Guosong Shao、Qi Huang、Qin Xiang、Chengxin Peng\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e收录\u003c/strong\u003e：SSCI 收录（Law 类）；据 WoS Journal Info 聚合页核验。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"https://doi.org/10.1093/idpl/ipae022\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e10.1093/idpl/ipae022\u003c/a\u003e\n（DOI 解析；题录经 Crossref API 逐条比对一致）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：中国数据保护与 AI 训练数据的法律基础\u003c/p\u003e","title":"Assessing the implementation of China's personal information protection law: a two-year review"},{"content":"摘要：该文官方摘要已随文上线（见下「直链」Oxford Academic 文章页），本页待取件后补录原文。\n出处：How the Legal Basis for AI Training Is Framed in Data Protection Guidelines and Interventions: Comparative Perspectives and the Prospect of Global Convergence，International Data Privacy Law, Vol. 16, Issue 2 (2026)。\n作者：Wenlong Li（浙江大学光华法学院）、Yueming Zhang（比利时根特大学）、Qingqing Zheng、Aolan Li\n收录：SSCI 收录（Law 类）；据 WoS Journal Info 聚合页核验。\n直链：10.1093/idpl/ipaf032 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：中国数据保护与 AI 训练数据的法律基础\n","permalink":"https://ai.intlaws.com/scholarship/li-how-the-legal-basis-for-ai-training-is-framed/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e：该文官方摘要已随文上线（见下「直链」Oxford Academic 文章页），本页待取件后补录原文。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e出处\u003c/strong\u003e：How the Legal Basis for AI Training Is Framed in Data Protection Guidelines and Interventions: Comparative Perspectives and the Prospect of Global Convergence，International Data Privacy Law, Vol. 16, Issue 2 (2026)。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e作者\u003c/strong\u003e：Wenlong Li（浙江大学光华法学院）、Yueming Zhang（比利时根特大学）、Qingqing Zheng、Aolan Li\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e收录\u003c/strong\u003e：SSCI 收录（Law 类）；据 WoS Journal Info 聚合页核验。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e直链\u003c/strong\u003e：\u003ca href=\"https://doi.org/10.1093/idpl/ipaf032\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e10.1093/idpl/ipaf032\u003c/a\u003e\n（DOI 解析；题录经 Crossref API 逐条比对一致）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e主题\u003c/strong\u003e：中国数据保护与 AI 训练数据的法律基础\u003c/p\u003e","title":"How the Legal Basis for AI Training Is Framed in Data Protection Guidelines and Interventions: Comparative Perspectives and the Prospect of Global Convergence"},{"content":"摘要（出版方所载原文摘要）\nThis article analyzes the divergence between China’s Personal Information Protection Law (PIPL) and the EU’s General Data Protection Regulation (GDPR), despite their textual similarities. It argues that China’s approach to data protection is shaped by distinct domestic understandings of “risk,” rooted in past legislation, judicial practices, and social concerns. Using focal point theory, the authors identify three key dimensions of risk in China: large-scale participation, economic loss, and threats from third parties. These focal points explain why China’s risk-based approach prioritizes different enforcement goals than the GDPR. The article also shows how these differences manifest in several areas, including the definition of personal information, the regulation of automated decision-making, and the design of enforcement authorities. Ultimately, the article challenges the assumption that legal diffusion through the “Brussels Effect” leads to uniform global standards. Instead, it highlights how domestic cultural and institutional factors reshape transplanted laws, creating seemingly performative enforcement that reflects localized regulatory logics.\n出处：Same text, different meaning: China\u0026rsquo;s risk-based approach to data protection，Humanities and Social Sciences Communications (2025), 文章号 s41599-025-06100-3。\n作者：Xiaodong Ding（中国人民大学）、Hao Huang（美国加州大学伯克利分校）、Zhengyu Shi、Yeliang Wang\n收录：SSCI 收录（Multidisciplinary 类）；Nature 系开放获取期刊，页面直读。\n直链：10.1057/s41599-025-06100-3 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：中国数据保护与 AI 训练数据的法律基础\n","permalink":"https://ai.intlaws.com/scholarship/ding-same-text-different-meaning-china-risk-based-approach/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（出版方所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThis article analyzes the divergence between China’s Personal Information Protection Law (PIPL) and the EU’s General Data Protection Regulation (GDPR), despite their textual similarities. It argues that China’s approach to data protection is shaped by distinct domestic understandings of “risk,” rooted in past legislation, judicial practices, and social concerns. Using focal point theory, the authors identify three key dimensions of risk in China: large-scale participation, economic loss, and threats from third parties. These focal points explain why China’s risk-based approach prioritizes different enforcement goals than the GDPR. The article also shows how these differences manifest in several areas, including the definition of personal information, the regulation of automated decision-making, and the design of enforcement authorities. Ultimately, the article challenges the assumption that legal diffusion through the “Brussels Effect” leads to uniform global standards. Instead, it highlights how domestic cultural and institutional factors reshape transplanted laws, creating seemingly performative enforcement that reflects localized regulatory logics.\u003c/p\u003e","title":"Same text, different meaning: China's risk-based approach to data protection"},{"content":"摘要（出版方所载原文摘要）\nImplementing artificial intelligence (AI) in public settings requires a fundamental transformation of various social and technical aspects within public administration. However, the transformative efforts required for AI integration and use in government remain underexplored. This study introduces the concept of \u0026lsquo;AI-augmented government transformation,\u0026rsquo; building on sociomateriality and sociotechnical theory, and develops a theoretical framework to explore this phenomenon. By applying this framework and drawing insights from expert interviews, we identify the strategic shifts and socio-technical adaptations essential for integrating AI into public administrations. Our analysis highlights the importance of opening the \u0026lsquo;black box\u0026rsquo; of AI to gain a deep understanding of its underlying technologies and their materialities. The findings reveal complex interdependencies between AI materiality and the social and technical systems that public administrations must navigate. Specifically, AI, as a novel materiality, introduces new organizational dynamics, enhances employee capabilities, and alters operational routines and practices. These changes complement technical ones, such as upgrades and advancements in data collection and processing. By investigating the complexities of AI-augmented government transformation, this research offers novel and practical insights for policymakers and practitioners navigating the challenges and opportunities of AI integration.\n出处：AI-augmented government transformation: Organisational transformation and the sociotechnical implications of artificial intelligence in public administrations，Government Information Quarterly, Vol. 42, Issue 3 (2025), Art. 102055。\n作者：Luca Tangi、A. Paula Rodriguez Müller（欧盟委员会联合研究中心 JRC）、Marijn Janssen\n收录：SSCI 收录（Information Science \u0026amp; Library Science 类）；据 WoS Journal Info 聚合页核验。\n直链：10.1016/j.giq.2025.102055 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：人工智能的公共治理\n","permalink":"https://ai.intlaws.com/scholarship/tangi-ai-augmented-government-transformation/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（出版方所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eImplementing artificial intelligence (AI) in public settings requires a fundamental transformation of various social and technical aspects within public administration. However, the transformative efforts required for AI integration and use in government remain underexplored. This study introduces the concept of \u0026lsquo;AI-augmented government transformation,\u0026rsquo; building on sociomateriality and sociotechnical theory, and develops a theoretical framework to explore this phenomenon. By applying this framework and drawing insights from expert interviews, we identify the strategic shifts and socio-technical adaptations essential for integrating AI into public administrations. Our analysis highlights the importance of opening the \u0026lsquo;black box\u0026rsquo; of AI to gain a deep understanding of its underlying technologies and their materialities. The findings reveal complex interdependencies between AI materiality and the social and technical systems that public administrations must navigate. Specifically, AI, as a novel materiality, introduces new organizational dynamics, enhances employee capabilities, and alters operational routines and practices. These changes complement technical ones, such as upgrades and advancements in data collection and processing. By investigating the complexities of AI-augmented government transformation, this research offers novel and practical insights for policymakers and practitioners navigating the challenges and opportunities of AI integration.\u003c/p\u003e","title":"AI-augmented government transformation: Organisational transformation and the sociotechnical implications of artificial intelligence in public administrations"},{"content":"摘要（出版方所载原文摘要）\nPolitical scientists have had remarkably little to say about artificial intelligence (AI), perhaps because they are dissuaded by its technical complexity and by current debates about whether AI might emulate, outstrip, or replace individual human intelligence. They ought to consider AI in terms of its relationship with governance. Existing large-scale systems of governance such as markets, bureaucracy, and democracy make complex human relations tractable, albeit with some loss of information. AI\u0026rsquo;s major political consequences can be considered under two headings. First, we may treat AI as a technology of governance, asking how AI\u0026rsquo;s capacities to classify information at scale affect markets, bureaucracy, and democracy. Second, we might treat AI as an emerging form of governance in its own right, with its own particular mechanisms of representation and coordination. These two perspectives reveal new questions for political scientists, encouraging them to reconsider the boundaries of their discipline.\n出处：AI as Governance，Annual Review of Political Science, Vol. 28 (2025), pp. 375–392。\n作者：Henry Farrell（美国约翰斯·霍普金斯大学 SAIS）\n收录：SSCI 收录（Political Science 类）；据 WoS Journal Info 聚合页核验。\n直链：10.1146/annurev-polisci-040723-013245 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：人工智能的公共治理\n","permalink":"https://ai.intlaws.com/scholarship/farrell-ai-as-governance/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（出版方所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003ePolitical scientists have had remarkably little to say about artificial intelligence (AI), perhaps because they are dissuaded by its technical complexity and by current debates about whether AI might emulate, outstrip, or replace individual human intelligence. They ought to consider AI in terms of its relationship with governance. Existing large-scale systems of governance such as markets, bureaucracy, and democracy make complex human relations tractable, albeit with some loss of information. AI\u0026rsquo;s major political consequences can be considered under two headings. First, we may treat AI as a technology of governance, asking how AI\u0026rsquo;s capacities to classify information at scale affect markets, bureaucracy, and democracy. Second, we might treat AI as an emerging form of governance in its own right, with its own particular mechanisms of representation and coordination. These two perspectives reveal new questions for political scientists, encouraging them to reconsider the boundaries of their discipline.\u003c/p\u003e","title":"AI as Governance"},{"content":"摘要（出版方所载原文摘要）\nThe rapid and widespread diffusion of generative artificial intelligence (AI) has unlocked new capabilities and changed how content and services are created, shared, and consumed. This special issue builds on the 2021 Policy and Society special issue on the governance of AI by focusing on the legal, organizational, political, regulatory, and social challenges of governing generative AI. This introductory article lays the foundation for understanding generative AI and underscores its key risks, including hallucination, jailbreaking, data training and validation issues, sensitive information leakage, opacity, control challenges, and design and implementation risks. It then examines the governance challenges of generative AI, such as data governance, intellectual property concerns, bias amplification, privacy violations, misinformation, fraud, societal impacts, power imbalances, limited public engagement, public sector challenges, and the need for international cooperation. The article then highlights a comprehensive framework to govern generative AI, emphasizing the need for adaptive, participatory, and proactive approaches. The articles in this special issue stress the urgency of developing innovative and inclusive approaches to ensure that generative AI development is aligned with societal values. They explore the need for adaptation of data governance and intellectual property laws, propose a complexity-based approach for responsible governance, analyze how the dominance of Big Tech is exacerbated by generative AI developments and how this affects policy processes, highlight the shortcomings of technocratic governance and the need for broader stakeholder participation, propose new regulatory frameworks informed by AI safety research and learning from other industries, and highlight the societal impacts of generative AI.\n出处：Governance of Generative AI，Policy and Society, Vol. 44, Issue 1 (2025), pp. 1–22。\n作者：Araz Taeihagh（新加坡国立大学李光耀公共政策学院 LKYSPP）\n收录：SSCI 收录（Public Administration 类）；据 WoS Journal Info 聚合页核验。\n直链：10.1093/polsoc/puaf001 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：人工智能的公共治理\n","permalink":"https://ai.intlaws.com/scholarship/taeihagh-governance-of-generative-ai/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（出版方所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe rapid and widespread diffusion of generative artificial intelligence (AI) has unlocked new capabilities and changed how content and services are created, shared, and consumed. This special issue builds on the 2021 Policy and Society special issue on the governance of AI by focusing on the legal, organizational, political, regulatory, and social challenges of governing generative AI. This introductory article lays the foundation for understanding generative AI and underscores its key risks, including hallucination, jailbreaking, data training and validation issues, sensitive information leakage, opacity, control challenges, and design and implementation risks. It then examines the governance challenges of generative AI, such as data governance, intellectual property concerns, bias amplification, privacy violations, misinformation, fraud, societal impacts, power imbalances, limited public engagement, public sector challenges, and the need for international cooperation. The article then highlights a comprehensive framework to govern generative AI, emphasizing the need for adaptive, participatory, and proactive approaches. The articles in this special issue stress the urgency of developing innovative and inclusive approaches to ensure that generative AI development is aligned with societal values. They explore the need for adaptation of data governance and intellectual property laws, propose a complexity-based approach for responsible governance, analyze how the dominance of Big Tech is exacerbated by generative AI developments and how this affects policy processes, highlight the shortcomings of technocratic governance and the need for broader stakeholder participation, propose new regulatory frameworks informed by AI safety research and learning from other industries, and highlight the societal impacts of generative AI.\u003c/p\u003e","title":"Governance of Generative AI"},{"content":"摘要（出版方所载原文摘要）\nIt seemed well established that producing a smart device could not, by itself, render someone a personal data controller in the absence of subsequent influence over the processing operations (the influence thesis). In contrast, legal scholars have introduced a new interpretation of European data protection law that seeks to apply the General Data Protection Regulation (GDPR) to the processing operations of smart devices even if no entity influences the processing remotely after the release of the product. This approach classifies producers as personal data controllers for device-based processing (producer-controller thesis). The proponents of the producer-controller thesis highlight the increasing importance of smart devices that store data locally and the need for protecting consumers’ rights in that context. However, as this paper claims, the GDPR is not the proper legal instrument for addressing the safety standards of smart products that process data locally. These considerations relate to legislative texts that prescribe product requirements, such as the AI Act and the Cyber Resilience Act. On those grounds, the present work criticises the producer-controller thesis. As this paper concludes, expanding the concept of ‘controller’ to encompass producers of smart devices does not enhance the protection of the data subjects and does not fit within the current data protection framework of the European Union.\n出处：Personal data controllers and device producers: Mind the gap，Computer Law \u0026amp; Security Review, Vol. 58 (2025), Art. 106172（开放获取）。\n作者：Efstratios Koulierakis（希腊雅典大学法学院 NKUA 法律·信息学与人工智能实验室）\n收录：SSCI 收录（Law 类）；据 WoS Journal Info 聚合页核验。\n直链：10.1016/j.clsr.2025.106172 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：数据生态与比较监管路径\n","permalink":"https://ai.intlaws.com/scholarship/koulierakis-personal-data-controllers-and-device-producers/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（出版方所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eIt seemed well established that producing a smart device could not, by itself, render someone a personal data controller in the absence of subsequent influence over the processing operations (the influence thesis). In contrast, legal scholars have introduced a new interpretation of European data protection law that seeks to apply the General Data Protection Regulation (GDPR) to the processing operations of smart devices even if no entity influences the processing remotely after the release of the product. This approach classifies producers as personal data controllers for device-based processing (producer-controller thesis). The proponents of the producer-controller thesis highlight the increasing importance of smart devices that store data locally and the need for protecting consumers’ rights in that context. However, as this paper claims, the GDPR is not the proper legal instrument for addressing the safety standards of smart products that process data locally. These considerations relate to legislative texts that prescribe product requirements, such as the AI Act and the Cyber Resilience Act. On those grounds, the present work criticises the producer-controller thesis. As this paper concludes, expanding the concept of ‘controller’ to encompass producers of smart devices does not enhance the protection of the data subjects and does not fit within the current data protection framework of the European Union.\u003c/p\u003e","title":"Personal data controllers and device producers: Mind the gap"},{"content":"摘要（出版方所载原文摘要）\nSynthetic data – algorithmically generated data – has been considered a novel solution to the data scarcity issue, and a ‘technical fix’ able to fill the gap in areas where real data is sensitive or biased. Different narratives about the nature of synthetic data as either mirroring or replacing real data, alongside diverse evaluation metrics for measuring the fidelity and utility of such data, have proliferated across the machine learning fairness community, in public policy research, privacy and data protection studies, and critical data scholarship. Yet, there is still no consensus on what constitutes ‘high-quality’ synthetic data. Against this background, I demonstrate how the concept of synthetic data introduces an analogical perspective on data. This perspective is relational and regulative, extending the discussion on data quality to encompass questions of data justice and responsible innovation. It invites critical reflections on the purpose and trade-offs involved in synthetic data generation and use, the social practices and power dynamics that underpin and configure it, and how its direction can be shaped in response to changing real-world circumstances and emerging human values. Building on this analysis, I argue that the generation and use of meaningful synthetic data require promoting responsibility in complex AI and data innovation ecosystems, and facilitating forms of algorithmic reparation and responsiveness.\n出处：Synthetic data as meaningful data: On responsibility in data ecosystems，Big Data \u0026amp; Society, Vol. 12, Issue 4 (2025)（开放获取）。\n作者：Marianna Capasso（荷兰乌得勒支大学 Utrecht University）\n收录：SSCI 收录（Social Sciences, Interdisciplinary 类）；据 WoS Journal Info 聚合页核验。\n直链：10.1177/20539517251386053 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：数据生态与比较监管路径\n","permalink":"https://ai.intlaws.com/scholarship/capasso-synthetic-data-as-meaningful-data/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（出版方所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eSynthetic data – algorithmically generated data – has been considered a novel solution to the data scarcity issue, and a ‘technical fix’ able to fill the gap in areas where real data is sensitive or biased. Different narratives about the nature of synthetic data as either mirroring or replacing real data, alongside diverse evaluation metrics for measuring the fidelity and utility of such data, have proliferated across the machine learning fairness community, in public policy research, privacy and data protection studies, and critical data scholarship. Yet, there is still no consensus on what constitutes ‘high-quality’ synthetic data. Against this background, I demonstrate how the concept of synthetic data introduces an analogical perspective on data. This perspective is relational and regulative, extending the discussion on data quality to encompass questions of data justice and responsible innovation. It invites critical reflections on the purpose and trade-offs involved in synthetic data generation and use, the social practices and power dynamics that underpin and configure it, and how its direction can be shaped in response to changing real-world circumstances and emerging human values. Building on this analysis, I argue that the generation and use of meaningful synthetic data require promoting responsibility in complex AI and data innovation ecosystems, and facilitating forms of algorithmic reparation and responsiveness.\u003c/p\u003e","title":"Synthetic data as meaningful data: On responsibility in data ecosystems"},{"content":"摘要（出版方所载原文摘要）\nThis paper is a comparative analysis of how two leading developing nations, China and India, are proposing to regulate artificial intelligence (AI) systems. Despite similarity in circumstances as large developing economies aiming to upgrade their technology sectors and create jobs, the two countries have taken significantly different approaches to AI regulation. Based on interest group theory, we argue that contrasting problem definitions—predominantly in terms of economic competitiveness and national security in China and as applications in India—resulted in the recruitment of very different decision-making groups in the two countries; homogeneous groups of technocrats and security specialists in China and a broader group including consumer advocates in India. This in turn resulted in ambitious and deep policy changes in China and relatively incremental and consensus-based moves in India.\n出处：Same goal, different paths: Contrasting approaches to AI regulation in China and India，Telecommunications Policy, Vol. 49, Issue 8 (2025), Art. 103019。\n作者：Puxin Zhang、Krishna Jayakar、Richard D. Taylor、Chun Liu（美国宾夕法尼亚州立大学等）\n收录：SSCI 收录（Communication / Economics 类）；据 WoS Journal Info 聚合页核验。\n直链：10.1016/j.telpol.2025.103019 （DOI 解析；题录经 Crossref API 逐条比对一致）\n主题：数据生态与比较监管路径\n","permalink":"https://ai.intlaws.com/scholarship/zhang-same-goal-different-paths-ai-regulation-china-india/","summary":"\u003cp\u003e\u003cstrong\u003e摘要\u003c/strong\u003e（出版方所载原文摘要）\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThis paper is a comparative analysis of how two leading developing nations, China and India, are proposing to regulate artificial intelligence (AI) systems. Despite similarity in circumstances as large developing economies aiming to upgrade their technology sectors and create jobs, the two countries have taken significantly different approaches to AI regulation. Based on interest group theory, we argue that contrasting problem definitions—predominantly in terms of economic competitiveness and national security in China and as applications in India—resulted in the recruitment of very different decision-making groups in the two countries; homogeneous groups of technocrats and security specialists in China and a broader group including consumer advocates in India. This in turn resulted in ambitious and deep policy changes in China and relatively incremental and consensus-based moves in India.\u003c/p\u003e","title":"Same goal, different paths: Contrasting approaches to AI regulation in China and India"},{"content":" 来源：Federal Register（官方 API + 官方全文文本）\n官方直链：https://www.federalregister.gov/documents/2026/10/08/2026-20672/certain-mobile-electronic-devices-and-components-thereof-institution-of-investigation\n注：调查终裁时点以 ITC 后续程序为准（立案通告不含裁决日程）。\n一、基本信息 项 内容 类型 通告（337 条款调查立案） 发布机关 美国国际贸易委员会（U.S. International Trade Commission, ITC） 公布 91 FR 64398，2026-10-08 FR Doc 号 2026-20672 调查编号 Investigation No. 337-TA-1525 法律依据 《1930 年关税法》第 337 条（Tariff Act of 1930, section 337） 申诉提交 2026-09-03（2026-09-17 提交补充） 申诉方 trinamiX Sensing LLC（美国得克萨斯州奥斯汀）；trinamiX GmbH（德国） 被诉方 Apple Inc.（One Apple Park Way, Cupertino, CA 95014） 状态 已立案 二、涉案专利与被诉产品 涉案专利（6 件，均在官方通告中列明）：\n专利号 通告内标注 U.S. Patent No. 12,530,925 the \u0026lsquo;925 patent U.S. Patent No. 12,288,421 the \u0026lsquo;421 patent U.S. Patent No. 12,456,334 the \u0026lsquo;334 patent U.S. Patent No. 12,361,760 the \u0026lsquo;760 patent U.S. Patent No. 12,298,394 the \u0026lsquo;394 patent U.S. Patent No. 12,332,352 the \u0026lsquo;352 patent 被诉产品范围（照录通告 plain language description）：iPhone 与 iPad 及其组件，如处理器与 TrueDepth 摄像头——搭载垂直腔面发射激光器（VCSEL）、泛光照明 VCSEL 与近红外摄像头模组，具面部认证（face authentication）、3D 传感和/或材料检测能力。\n请求救济：申诉方请求委员会调查终结后发布有限排除令（limited exclusion order）与禁止令（cease and desist orders）。\n三、数据治理与合规影响 生物识别前端硬件：涉案技术为人脸识别的前端传感模组（面部认证/3D 传感）。如申诉成立并发布排除令，相关组件对美进口与含该组件设备在美销售将受限制；设备制造商的面部识别硬件供应链安排需关注调查进展。 义务边界：337 调查系贸易救济程序，不直接设定数据处理义务；其排除令/禁止令（如最终发布）仅约束被诉的进口与销售行为，与州级生物识别法（如伊利诺伊 BIPA）的数据处理义务分属不同法律轨道，不得混同。 时点口径：2026-09-03 为申诉提交日、2026-10-08 为立案公布日，两者均非义务生效节点；调查终裁与任何救济令发布时点以 ITC 后续程序为准 。 四、核验方式 调查编号（337-TA-1525）、FR Doc 2026-20672、申诉日（September 3, 2026）、被诉产品描述关键词（face authentication、3D-sensing、VCSEL、TrueDepth）、救济请求（limited exclusion order、cease and desist）、6 件涉案专利号均在官方全文文本中做字符级命中复核，全部命中。官方全文快照随本稿放入 sources/ 目录。\n备注：本通告全文未出现「facial recognition」字样（技术描述使用 face authentication / 3D-sensing），相关概括表述以通告原文用语为准。\n","permalink":"https://ai.intlaws.com/legislation/us/legislation-us-itc-337-ta-1525-trinamix-apple-2026/","summary":"美国国际贸易委员会 2026-10-08 在《联邦公报》（91 FR 64398）发布通告，就 trinamiX 诉苹果公司的 337 条款调查正式立案（Inv. No. 337-TA-1525）：被诉产品为 iPhone/iPad 搭载面部认证、3D 传感功能 TrueDepth 摄像头组件，涉案专利 6 件， 申诉方请求有限排除令与禁止令。","title":"美国国际贸易委员会 337 调查立案：trinamiX 诉苹果——移动设备面部识别与 3D 传感专利（337-TA-1525）"},{"content":" 来源：Federal Register（官方 API + 官方全文文本）\n官方直链：https://www.federalregister.gov/documents/2026/10/08/2026-20650/low-value-shipments\n注：法规文本生效日与合规义务适用日以官方后续公告为准（拟议规则阶段尚无生效日）。\n一、基本信息 项 内容 类型 拟议规则（Notice of proposed rulemaking） 发布机关 美国国土安全部海关与边境保护局（U.S. Customs and Border Protection, CBP） 公布 91 FR 64532，2026-10-08 FR Doc 号 2026-20650 Docket 号 USCBP-2026-0298 拟修订对象 CBP 非正式申报（informal entries）相关条例 评论截止 2026-12-07 状态 征求意见中；法规文本生效日 （拟议规则阶段尚无生效日）；合规义务适用日以官方后续公告为准 二、内容要旨 （照录《联邦公报》官方摘要）本拟议规则拟修改 CBP 条例中价值 2,500 美元及以下货物非正式申报的申报要求，并设立经邮件环境进境商品的新电子非正式申报类型。此外拟作相关配套修改：要求承运人就邮件包裹提交附加数据元，并对特定非正式申报施加担保（bonding）要求。\n三、数据治理与合规影响 申报数据扩展：邮件环境电子申报类型一旦确立，承运人、寄递企业须就邮件包裹向海关传输新增数据元，属跨境物流数据申报义务的实质扩展；现行对低值包裹的申报豁免空间相应收窄。 跨境电商影响：≤2,500 美元非正式申报门槛内的直邮与包裹业务为电商主要通道，新规将提高其数据申报与担保合规成本。 时点口径：本文件为拟议规则，评论截止 2026-12-07；最终规则公布前不产生合规义务。义务落地时点取决于最终规则的生效条款（如自公布日起或指定日期生效），本页不作推算。 四、核验方式 编号（FR Doc 2026-20650、Docket USCBP-2026-0298）、评论截止日（Comments on the rule must be received on or before December 7, 2026）、拟案内容关键词（low-value shipments、informal entries、$2,500）均在官方全文文本中做字符级命中复核，全部命中（low-value shipments 命中 13 处、informal entries 43 处、$2,500 48 处）。官方全文快照（Federal Register 官方 text 通道原始格式）随本稿放入 sources/ 目录。\n","permalink":"https://ai.intlaws.com/legislation/us/legislation-us-cbp-low-value-shipments-2026/","summary":"美国海关与边境保护局 2026-10-08 在《联邦公报》（91 FR 64532）发布拟议规则，拟修改 价值 2,500 美元及以下货物非正式申报要求、为邮件环境设立新的电子非正式申报类型， 并拟要求承运人就邮件包裹提交附加数据元，评论截止 2026-12-07。","title":"美国海关与边境保护局拟议规则：低值包裹申报要求修改（91 FR 64532）"},{"content":" 本期速览（可核验）\n法域 条目 类型 编号 状态 美国 CBP 低值包裹申报规则修改 拟议规则 91 FR 64532 / FR Doc 2026-20650 / USCBP-2026-0298 征求意见中，截止 2026-12-07 美国 ICE F-1 实习许可（OPT）新费用 拟议规则 91 FR 64566 / FR Doc 2026-20660 / DHS Docket ICEB-2026-0100 征求意见中，截止 2026-11-09 美国 ITC 337 调查：trinamiX 诉苹果（面部识别/3D 传感） 调查立案通告 91 FR 64398 / FR Doc 2026-20672 / Inv. No. 337-TA-1525 已立案 美国 CMS CLIA 虚拟访问与数字图像能力测试 拟议规则 91 FR 64480 / FR Doc 2026-20613 / CMS-3478-P 征求意见中，截止 2026-12-07 采集窗口：2026-10-08（当日刊期；2026-10-09 期截至发稿尚未开刊）。编号、卷页号、日期均以 Federal Register 官方 API 与官方全文文本为准；关键词检索命中 41 条去重后人工筛出 4 条。\n一、本周要点 本窗口内美国联邦层面无新的 AI 专门立法或最终规则。数据治理方向增量集中在三处：一是海关入境数据申报（CBP 低值包裹新规拟案，涉及邮件环境新增电子申报类型与承运人附加数据元）；二是移民系统数字化收费（ICE 拟对 OPT 设立高额费用，属身份与数据密集型行政程序）；三是面部识别技术的贸易救济（ITC 337 条款调查立案，被诉产品直接涉及 iPhone/iPad TrueDepth 摄像头的面部认证与 3D 传感组件）。另有一条卫生领域拟案（CMS CLIA）涉及数字图像用于能力测试，与自动化审查相关，列为次要条目。\n对合规实务的时点口径提示：上述拟议规则在最终规则公布前不产生对外合规义务；ITC 337 调查系贸易救济程序，其排除令/禁止令（如最终发布）仅约束被诉进口与销售行为，不构成一般性数据处理义务。各评论截止日与调查节点已分列，不得混同。\n二、美国（联邦） 2.1 海关与边境保护局（CBP）：低值包裹（Low-Value Shipments）申报规则修改拟案 项 内容 类型 拟议规则（Notice of proposed rulemaking） 发布机关 美国国土安全部海关与边境保护局（U.S. Customs and Border Protection） 公布 91 FR 64532，2026-10-08 FR Doc 号 2026-20650 Docket 号 USCBP-2026-0298 状态 征求意见中；评论截止 2026-12-07；法规文本生效日 （拟议规则阶段尚无生效日）；合规义务适用日 官方直链 https://www.federalregister.gov/documents/2026/10/08/2026-20650/low-value-shipments 内容（照录官方摘要）：拟修改 CBP 条例中价值 2,500 美元及以下货物非正式申报（informal entries）的申报要求，并为经邮件环境进境的商品设立新的电子非正式申报类型；另拟规定承运人就邮件包裹提交附加数据元，并对特定非正式申报施加担保（bonding）要求。\n数据治理关联点：邮件环境电子申报类型一旦确立，承运人与寄递企业须向海关传输新增数据元，属跨境物流数据申报义务的实质扩展；义务落地时点以最终规则公布及其生效条款为准（本页不作推算）。\n2.2 移民与海关执法局（ICE）：F-1 学生实习许可（OPT）新费用拟案 项 内容 类型 拟议规则（Notice of proposed rulemaking） 发布机关 美国国土安全部移民与海关执法局（U.S. Immigration and Customs Enforcement） 公布 91 FR 64566，2026-10-08 FR Doc 号 2026-20660 Docket 号 DHS Docket No. ICEB-2026-0100 状态 征求意见中；评论截止 2026-11-09（另：纸面减负法信息收集评论截止 2026-12-07）；法规文本生效日 ；合规义务适用日 官方直链 https://www.federalregister.gov/documents/2026/10/08/2026-20660/optional-practical-training-fees 内容（照录官方摘要）：拟为 F-1 非移民学生经学生与交流访问者计划（SEVP）认证机构参加实习许可（Optional Practical Training, OPT）设立新费用，以打击欺诈、强化移民系统完整性并保护美国工人：首次 OPT 每人次 70,000 美元；后续 OPT 每人次 30,000 美元。\n数据治理关联点：OPT 申请与监管依赖 SEVP 学生信息系统（SEVIS）的身份与就读数据流转；高额费用将实质改变申请行为，进而影响该系统数据规模与更新频率。此为间接关联，实体义务仍以最终规则为准。\n2.3 美国国际贸易委员会（ITC）：trinamiX 诉苹果——移动电子设备面部识别/3D 传感专利 337 调查立案 项 内容 类型 通告（337 条款调查立案） 发布机关 美国国际贸易委员会（U.S. International Trade Commission） 公布 91 FR 64398，2026-10-08 FR Doc 号 2026-20672 调查编号 Investigation No. 337-TA-1525 申诉方 trinamiX Sensing LLC（美国得克萨斯州奥斯汀）与 trinamiX GmbH（德国） 被诉方 Apple Inc.（加州库比蒂诺） 申诉提交 2026-09-03（2026-09-17 提交补充） 涉案专利 U.S. Patent No. 12,530,925；12,288,421；12,456,334；12,361,760；12,298,394；12,332,352（共 6 件） 被诉产品范围 iPhone 与 iPad 及其组件，含搭载垂直腔面发射激光器（VCSEL）、泛光照明 VCSEL 与近红外摄像头模组、具面部认证（face authentication）、3D 传感和/或材料检测功能的处理器与 TrueDepth 摄像头 请求救济 有限排除令（limited exclusion order）与禁止令（cease and desist orders） 状态 已立案；主审行政法官与 100 天任期程序等按委员会程序推进 官方直链 https://www.federalregister.gov/documents/2026/10/08/2026-20672/certain-mobile-electronic-devices-and-components-thereof-institution-of-investigation 数据治理关联点：涉案技术为消费电子设备上的人脸识别前端硬件（面部认证/3D 传感模组）。如申诉成立并发布排除令，将影响相关传感组件对美进口；该调查本身不直接设定数据处理义务，但生物识别前端硬件的供应链安排（设备制造商视角）受其结果影响。委员会另就公共利益征集书面意见（证据性表述以通告原文为准）。\n2.4 医疗保险与医疗补助服务中心（CMS）：CLIA 虚拟访问与数字图像能力测试拟案（次要条目） 项 内容 类型 拟议规则 发布机关 美国卫生与公众服务部医疗保险与医疗补助服务中心（CMS） 公布 91 FR 64480，2026-10-08 FR Doc 号 2026-20613 Docket 号 CMS-3478-P 状态 征求意见中；评论截止 2026-12-07；法规文本生效日 ；合规义务适用日 官方直链 https://www.federalregister.gov/documents/2026/10/08/2026-20613/clinical-laboratory-improvement-amendments-of-1988-clia-virtual-access-gynecologic-cytology 内容（照录官方摘要）：拟修订 1988 年《临床实验室改进修正案》（CLIA）条例，允许在出具数据的初级检测实验室的 CLIA 证书下进行虚拟访问（细胞学亚专业除外），并允许使用数字图像进行妇科细胞学能力测试（proficiency testing）；同时拟调整人员资格要求及其他与 SARS-CoV-2 报告相关的修改。\n数据治理关联点：数字图像替代实体切片送检、远程虚拟访问监管，均属医疗检测数据的远程调取与图像化审查场景，与实验室信息系统访问控制相关。\n三、状态与日期口径说明 四条目中 2.1、2.2、2.4 为拟议规则：仅评论截止日确定；法规文本生效日与合规义务适用日均 （拟议阶段尚无生效日，不作推算）。 2.3 为调查立案通告：2026-09-03 为申诉提交日、2026-10-08 为立案公布日，两者均非义务生效节点；调查结果（排除令/禁止令是否发布）以 ITC 后续裁决定为准。 ","permalink":"https://ai.intlaws.com/legislation/us/legislation-digest-2026-10-09/","summary":"2026-10-08 期《联邦公报》数据治理相关增量三条主线：CBP 拟修改低值包裹（≤2,500 美元） 非正式申报规则并新增邮件环境电子申报类型（评论截止 2026-12-07）；ICE 拟对 F-1 学生 实习许可（OPT）设立每人次 70,000/30,000 美元新费用（评论截止 2026-11-09）； 美国国际贸易委员会就 trinamiX 诉苹果公司移动设备面部识别/3D 传感专利侵权 正式立案 337 调查（337-TA-1525）。另有 CMS CLIA 虚拟访问拟案一条。","title":"立法动态周报（2026-10-08）：联邦公报数据治理窗口增量——CBP 低值包裹新规、ICE OPT 高额费用拟案与 ITC 337 面部识别调查"},{"content":" 来源：Federal Register（官方 API + 官方全文文本）\n官方直链：https://www.federalregister.gov/documents/2026/10/07/2026-20532/privacy-act-of-1974-implementation\n注：法规文本生效日与合规义务适用日以官方后续公告为准（拟议规则阶段尚无生效日）。\n一、基本信息 项 内容 类型 拟议规则（Notice of proposed rulemaking） 发布机关 美国司法部（Department of Justice），Office of the Pardon Attorney 公布 91 FR 64125，2026-10-07（《联邦公报》第 91 卷第 193 期，页 64125–64128） FR Doc 号 2026-20532 令号 CPCLO Order No. 009-2026 拟修订法规 28 CFR Part 16（司法部《隐私权法》实施条例） 评论截止 2026-11-06 状态 征求意见中；法规文本生效日 [未取得原文]（拟议规则阶段尚无生效日）；合规义务适用日 [未取得原文] 二、内容要旨 （照录《联邦公报》官方摘要）司法部赦免检察官办公室（PARDON）已在同日《联邦公报》通告栏发布一项新记录系统——枪支权利恢复电子记录数据库（Firearms Rights Restoration Electronic Records Database, FRRERD），系统编号 JUSTICE/OPA-002。本拟议规则拟将该系统豁免于《隐私权法》的若干条款，理由是：该系统所存信息系在刑事执法程序各阶段编制的机密信息，以及为保障枪支权利恢复程序完整性而编制的信息；豁免旨在防止披露对执法程序构成干扰或危害。\n设立通告另见同日 Notice 栏（FR Doc 号待查）。\n三、时点口径 该文件为拟议规则，评论截止 2026-11-06； 最终规则公布前不产生合规义务； 其所豁免的记录系统本身属政府内部记录系统（对象为个人但限于刑事执法语境），对外部企业无直接合规义务；对涉该程序的个人，其查阅/更正等《隐私权法》权利将因豁免而受限——此为实体影响点。 四、核验方式 编号（FR Doc 2026-20532、91 FR 64125、CPCLO Order No. 009-2026、JUSTICE/OPA-002、FRRERD）、评论截止日（November 6, 2026）均在官方全文文本中做字符级命中复核，全部命中。官方全文快照（GPO 原始格式）随本稿放入 sources/ 目录。\n","permalink":"https://ai.intlaws.com/legislation/us/legislation-us-doj-privacy-act-frrerd-2026/","summary":"美国司法部赦免检察官办公室 2026-10-07 在《联邦公报》（91 FR 64125）发布拟议规则， 拟就新设的枪支权利恢复电子记录数据库（FRRERD，JUSTICE/OPA-002）豁免《隐私权法》若干条款， 评论截止 2026-11-06。","title":"美国司法部《隐私权法》实施拟议规则：FRRERD 记录系统豁免（28 CFR Part 16）"},{"content":" 本期速览（可核验）\n法域 条目 类型 编号 状态 美国 司法部《隐私权法》实施：FRRERD 系统豁免 拟议规则 91 FR 64125 / FR Doc 2026-20532 / CPCLO Order No. 009-2026 征求意见中，截止 2026-11-06 美国 NRC 13 项《隐私权法》记录系统通告重发布 通告 91 FR 63587 / FR Doc 2026-20438 征求意见中，截止 2026-11-05 美国 NHTSA 情景式驾驶员监测系统（DMS）信息收集 通告（信息收集） 91 FR 63642 / FR Doc 2026-20394 / Docket NHTSA-2025-0060 征求意见中，截止 2026-11-05 美国 NHTSA 2026 秋季安全研究公开会议暨 ADS 研讨会 通告（会议） 91 FR 64222 / FR Doc 2026-20516 / Docket NHTSA-2026-1618 会议定于 2026-12-01 至 12-02；评论期至 2027-03-02 美国 版权局音乐流媒体欺诈征询 通告（征询） 91 FR 64188 / FR Doc 2026-20537 / Docket No. 2026-6 首轮评论截止 2026-11-23；回复评论截止 2026-12-21 采集窗口：2026-10-05 至 2026-10-07（2026-10-08 期《联邦公报》截至发稿尚未开刊）。编号、卷页号、日期均以 Federal Register 官方 API 与官方全文文本为准；本窗口为缩短窗口（3 天），系周报节奏错峰所致。\n一、本周要点 本窗口内美国联邦层面无新的 AI 专门立法或最终规则；数据治理方向的增量集中在两类：一是政府记录系统的《隐私权法》合规动作（司法部新系统豁免拟议、NRC 记录系统重发布），二是监管机构围绕自动化技术的信息收集与征询（NHTSA 驾驶员监测系统、版权局音乐流媒体欺诈）。\n对合规实务的时点口径提示：上述文件均为拟议规则或通告，在最终规则出台或系统正式设立前不产生对外合规义务；各评论截止日与会议日期已分列，不得混同。\n二、美国（联邦） 2.1 司法部《隐私权法》实施：拟为 FRRERD 系统设立豁免（28 CFR Part 16） 项 内容 类型 拟议规则（Notice of proposed rulemaking） 发布机关 美国司法部（Office of the Pardon Attorney） 公布 91 FR 64125，2026-10-07 FR Doc 号 2026-20532 令号 CPCLO Order No. 009-2026 拟设系统 Firearms Rights Restoration Electronic Records Database（FRRERD），JUSTICE/OPA-002 状态 征求意见中；评论截止 2026-11-06；法规文本生效日 [未取得原文]（拟议规则阶段尚无生效日）；合规义务适用日 [未取得原文] 官方直链 https://www.federalregister.gov/documents/2026/10/07/2026-20532/privacy-act-of-1974-implementation 内容（照录官方摘要）：司法部赦免检察官办公室（PARDON）已另行发布新记录系统 FRRERD（JUSTICE/OPA-002）的设立通告；本拟议规则拟将该系统豁免于《隐私权法》的若干条款，以保护在刑事执法程序各阶段编制的机密信息，以及为保障枪支权利恢复程序完整性而编制的信息。该规则如经最终化，将修改 28 CFR Part 16。\n2.2 核管理委员会（NRC）：13 项《隐私权法》记录系统通告重发布 项 内容 类型 通告（记录系统修订；征求意见） 发布机关 美国核管理委员会（NRC） 公布 91 FR 63587，2026-10-06 FR Doc 号 2026-20438 状态 征求意见中；评论截止 2026-11-05 官方直链 https://www.federalregister.gov/documents/2026/10/06/2026-20438/privacy-act-of-1974-systems-of-records 内容（照录官方摘要）：依据《隐私权法》与 OMB Circular A-108，NRC 经全面审查后重发布 13 项记录系统通告（SORN）：8 项仅作轻微行政更新，1 项无变化，4 项（NRC 27、NRC 36、NRC 39、NRC 40）含实体修订，需 30 天公开评论。更新内容包括现代化系统描述、澄清权限与系统位置、更新记录类别与安全保障措施。\n2.3 NHTSA：情景式驾驶员监测系统（DMS）信息收集征求意见 项 内容 类型 通告（信息收集，PRA 审批程序） 发布机关 交通部国家公路交通安全管理局（NHTSA） 公布 91 FR 63642，2026-10-06 FR Doc 号 2026-20394 Docket 号 NHTSA-2025-0060 状态 征求意见中；评论截止 2026-11-05；不产生合规义务 官方直链 https://www.federalregister.gov/documents/2026/10/06/2026-20394/agency-information-collection-activities-submission-to-the-office-of-management-and-budget 内容（照录官方摘要）：依据 1995 年《文书削减法》（PRA），NHTSA 拟就「情景式驾驶员监测系统（contextual driver monitoring systems, DMS）评估」的信息收集请求（ICR）提交管理与预算办公室（OMB）审查批准。此前已就该信息收集发布 60 天评论期通告，本文件为提交 OMB 审批前的再次征求意见。\n2.4 NHTSA：2026 秋季安全研究公开会议暨自动驾驶系统（ADS）研讨会 项 内容 类型 通告（公开会议） 发布机关 交通部国家公路交通安全管理局（NHTSA） 公布 91 FR 64222，2026-10-07 FR Doc 号 2026-20516 Docket 号 NHTSA-2026-1618 会议日期 2026-12-01 至 2026-12-02（ADS 研讨会为 12 月 1 日下午） 注册截止 2026-11-24 评论期 公开会议 docket 自会议之日起开放 90 天，至 2027-03-02（注：FR 原文「90 days」并照录「March 2, 2026」，系官方笔误，按 90 天历日推算实为 2027-03-02） 状态 会议已公告、尚未召开；评论期尚未开始 官方直链 https://www.federalregister.gov/documents/2026/10/07/2026-20516/nhtsa-safety-research-portfolio-public-meeting-fall-2026-and-automated-driving-systems-workshop 内容（照录官方摘要）：NHTSA 将于 2026 年 12 月 1 日至 2 日举行安全研究组合公开会议，介绍车辆安全研究办公室与行为安全研究办公室各项研究计划的进展，线下举行，含专题小组报告与研究海报，每场报告后设技术问答环节。会议后一天下午举行自动驾驶系统（ADS）研讨会。\n2.5 美国版权局：音乐流媒体欺诈征询（Music Streaming Fraud） 项 内容 类型 通告（征询，Notice of inquiry） 发布机关 美国版权局（Library of Congress, Copyright Office） 公布 91 FR 64188，2026-10-07 FR Doc 号 2026-20537 Docket 号 2026-6 状态 征询中；首轮评论截止 2026-11-23（美东 23:59）；回复评论截止 2026-12-21（美东 23:59） 官方直链 https://www.federalregister.gov/documents/2026/10/07/2026-20537/music-streaming-fraud 内容（照录官方摘要）：应国会要求，美国版权局就音乐流媒体欺诈相关问题向公众征询信息。该事项涉及流媒体平台上的欺诈性播放与收益分配问题；评论分首轮与回复两轮，两轮截止日分列如上。\n三、欧盟与国际组织 本窗口内欧盟官方公报与国际组织（OECD、欧洲理事会）未检索到新的数据/AI 方向条例或指令。\n四、来源与核验方式 来源 用途 Federal Register API（federalregister.gov/api/v1） 8 组关键词检索（artificial intelligence / privacy / biometric / data broker / automated decision / digital identity / consumer data / algorithm），窗口 2026-10-05 至 2026-10-07，去重后 63 条中筛选 Federal Register 官方全文文本（/full_text/text/ 通道） 5 份候选文件全文快照，关键字段（Docket 号、日期、系统编号）逐条字符级检索复核 关键日期（评论截止、会议日、注册截止）均经官方全文文本逐项复核；未载明事项以官方文本为准，未做估算。\n","permalink":"https://ai.intlaws.com/legislation/us/legislation-digest-2026-10-08/","summary":"2026-10-05 至 2026-10-07 窗口内，美国联邦公报数据治理相关增量以政府记录系统与信息收集类文件为主： 司法部拟为枪支权利恢复电子记录数据库（FRRERD，JUSTICE/OPA-002）设立《隐私权法》豁免（评论截止 2026-11-06）； NRC 重发布 13 项隐私记录系统通告（4 项实体修订，评论截止 2026-11-05）；NHTSA 就情景式驾驶员监测系统（DMS） 信息收集征求意见（截止 2026-11-05），并定于 2026-12-01 至 12-02 召开安全研究公开会议暨自动驾驶系统研讨会； 美国版权局就音乐流媒体欺诈发出征询通告（首轮评论 2026-11-23 截止，回复评论 2026-12-21 截止）。","title":"立法动态周报（2026-10-05 至 2026-10-07）：美国联邦数据治理窗口增量与政府记录系统新规"},{"content":" 来源与核验（可核验）\n项目 内容 文书名称 《「人工智能+软件」专项行动实施方案》及印发通知 文号 工信部信发〔2026〕209 号 发文机关 工业和信息化部 成文日期 2026 年 9 月 2 日（通知落款） 公开发布日期 2026 年 9 月 11 日（中国政府网政策文件库上网日期） 公文种类 通知（对各省、自治区、直辖市及新疆生产建设兵团工业和信息化主管部门的工作部署文件） 现行状态 已印发施行（政策实施方案，非设定合规义务的规章） 官方来源 通知正文页：中国政府网·国务院部门文件 ；方案全文（官方附件 PDF）：P020260911688449695690.pdf 校对记录 通知页元数据「发文字号：工信部信发〔2026〕209号」「成文日期：2026年09月02日」字符级核验命中；方案 PDF 共 8 页，章节「一、总体要求」至「八、加强组织保障」连续无缺 一、这是一件什么规格的文件 《「人工智能+软件」专项行动实施方案》（以下称《实施方案》）系工业和信息化部为贯彻落实《国务院关于深入实施「人工智能+」行动的意见》制定的产业政策实施方案，2026 年 9 月 2 日以工信部信发〔2026〕209 号通知印发各省级工业和信息化主管部门执行。方案体例为八个部分：一、总体要求；二、推进软件生产变革，加速迈向「智能驱动」；三、加快软件产品智能化升级，大力推广「智能伙伴」；四、培育智能体软件新业态，加速推动「持续进化」；五、拓展智能软件服务，积极变革「服务模式」；六、夯实软件智能化发展基础；七、优化软件产业发展环境；八、加强组织保障——除总体要求与组织保障外，共十九项任务（（一）至（十九））。\n二、目标节点 时点 目标 到 2028 年 培育一批高水平智能编程工具和智能开发平台，推广应用覆盖 2 万家规模以上软件企业；累计组织实施 100 项软件企业智能化技改项目；重点行业打造 100 个智能体软件标杆应用；孵化 5 个以上优质开源项目；建设 15 家以上软硬协同适配中心（第（四）项） 到 2030 年 关键软件全面实现智能化升级，智能编程、智能体软件及智能服务等新业态成为产业新增长极，建成若干具有国际影响力的开源社区和产业集群 三、任务主线（数据/AI 视角） 软件生产变革（第（一）至（三）项）：发展智能体驱动的智能编程工具，提升项目级、全流程自主开发能力；推进软件企业智能化技改；运用大模型对存量软件实施漏洞挖掘、缺陷自动识别和风险分级评估。 产品升级与新业态（第（四）至（九）项）：基础软件、工业软件智能化升级；培育通用与垂直领域智能体软件；建设智能体软件应用商店和技能包（Skills）资源库，规范平台上架审核与运营管理。 服务模式与基础支撑（第（十）至（十五）项）：智能软件服务主体培育；开源协同；算力服务支撑（算力券等普惠政策）；建设软件行业高质量数据集，完善数据标注、清洗与合成工具链，提升软件工程数据治理能力。 标准与人才（第（十六）至（十八）项）：制定智能编程能力成熟度分级评估标准，研制智能体接口标准，研究制定「模型即服务」「智能体即服务」等智能服务标准；人才培养与就业友好发展（加强人工智能对软件领域就业影响评估）。 安全保障（第（十九）项）：加强人工智能生成代码安全审查，防范智能编程工具恶意指令注入等新型攻击；研究智能体身份标识、可信互联、数据安全、行为管控等安全技术，推动建立覆盖开发、部署、应用等环节的智能体安全管理规范；加强人工智能生成代码的知识产权合规治理。 四、适用说明（日期口径分写） 生效/执行起点：本件为产业政策实施方案，成文日 2026 年 9 月 2 日即印发执行，无施行缓冲期条款。 合规义务适用日：本件属推进性政策文件，尚未直接创设对企业的强制合规义务；其中涉及安全管理规范、标准研制者均为「研究制定／推动建立」性质的表述，相关国家标准出台后，相应义务的适用日以标准发布实施日为准。 五、局限与引用提示 工信部官网（miit.gov.cn）原发布页因列表页 JS 动态加载，机器抓取两次未取得清单数据，本页以中国政府网政策文件库（官方一手镜像，含完整文号与附件原文）为准；如需 miit 原发布页直链，后续可补。 方案 PDF 未载「施行日期」条款（政策实施方案体例所限），引用生效时点以成文日为准。 资料来源：中国政府网国务院政策文件库通知正文页与方案全文 PDF。整理时间：2026-10-06。本页为采集整理稿，供研究参考，不构成法律意见。\n","permalink":"https://ai.intlaws.com/legislation/miit-ai-plus-software-action-plan/","summary":"工业和信息化部 2026 年 9 月 2 日以工信部信发〔2026〕209 号印发《「人工智能+软件」专项行动实施方案》，提出到 2028 年智能编程工具推广应用覆盖 2 万家规模以上软件企业、累计实施 100 项软件企业智能化技改项目、重点行业打造 100 个智能体软件标杆应用、孵化 5 个以上优质开源项目，到 2030 年关键软件全面实现智能化升级；方案以智能编程、智能体软件、智能服务为主线部署八大板块任务，并就人工智能生成代码安全审查、智能体安全管理规范、软件行业高质量数据集等安全与数据事项作出推进性安排。","title":"工信部印发「人工智能+软件」专项行动实施方案（工信部信发〔2026〕209号）"},{"content":" 来源与核验（可核验）\n项目 内容 文书名称 《国务院关于修改〈住房公积金管理条例〉的决定》（附：依决定修订后重新公布的《住房公积金管理条例》全文） 文号 国务院令第 844 号（发布页元数据「国令第844号」） 通过时间 2026 年 7 月 31 日国务院第 93 次常务会议通过 公布（成文）日 2026 年 8 月 10 日（令署总理李强） 施行日 2026 年 9 月 20 日 网站发布日 中国政府网政策文件库 2026 年 8 月 18 日 条例沿革 1999 年 4 月 3 日国务院令第 262 号发布；2002 年 3 月 24 日第一次修订；2019 年 3 月 24 日第二次修订；2026 年 8 月 10 日第三次修订 体例 修改决定共 二十 条（一至二十，连续无缺号）；修订后条例共 七章 五十条（第一章至第七章、第一条至第五十条，连续无缺号） 官方来源 中国政府网·国务院政策文件库（修改决定及修订后条例全文） 校对记录 抓取发布页文本；「第844号」3 处、「2026年8月10日」2 处、「2026年9月20日」4 处字符级命中；决定条目号一至二十连续、条例条号第一条至第五十条连续、章号一至七连续，无缺号、无重号、无空条 一、这是一件什么规格的文件 《国务院关于修改〈住房公积金管理条例〉的决定》属行政法规修订决定，以国务院令第 844 号公布，自 2026 年 9 月 20 日起施行；决定同时重新公布依其修改并调整条文序号后的《住房公积金管理条例》全文。本次为该条例的第三次修订，修改决定共二十条，修订后条例为七章五十条。\n二、修改决定要点（按修订后文本） 立法目的扩容（决定第一条，修订第一条）：立法目的增加「更好满足多样化住房消费需求」。 缴存比例（决定第五条，修订第十八条）：职工和单位缴存比例均不得低于职工上一年度月平均工资的 5%，不得高于国家规定的最高缴存比例；具体比例由住房公积金管理委员会拟订，经本级人民政府审核后报省级人民政府批准。 提取情形扩容（决定第七条，修订第二十四条第一、二款）：提取情形九项——（一）支付房租；（二）购买、建造、翻建、大修自住住房；（三）偿还购房贷款本息；（四）装修自住住房；（五）支付自住住房物业费；（六）离休、退休；（七）完全丧失劳动能力并与单位终止劳动关系；（八）出境定居；（九）国务院批准的其他住房消费情形。依第六、七、八项提取的，可以同时注销账户。 办理时限（决定第八、九条，修订第二十五条、第二十六条第二款）：提取决定3 日内、贷款决定10 日内作出并通知申请人。 资金运用扩围（决定第十条，修订第二十八条第一款）：公积金可用于购买国债和政策性金融债。 增值收益用途（决定第十一条，修订第二十九条）：主要用于贷款风险准备金、管理中心管理费用，以及建设、筹集、运维公共租赁住房与房屋全生命周期安全管理等住房领域相关公共支出的补充资金。 数字化全国互认（决定第十三条，新增第三十一条）：实现住房公积金缴存记录等全国范围内互信互认，推动转移接续、异地贷款等业务便捷高效办理。 信用管理（决定第十五条，新增第三十八条）：确定公积金领域公共信用信息，建立信用记录，纳入全国信用信息共享平台。 违法惩戒（决定第十六条，新增第四十一条）：以欺诈、伪造证明材料等手段违法提取的，责令限期退回，3 年内不得提取或使用公积金贷款；违法获得贷款的，责令限期返还，5 年内不得提取或使用公积金贷款。 单位违规罚款上调（决定第二十条第（二）项，原第三十七条改为第三十九条）：不办理缴存登记或不为职工办理账户设立手续、逾期不办理的，罚款由「1 万元以上 5 万元以下」上调为「5 万元以上 30 万元以下」；管理中心责任情形并新增第八项「未督促单位按时履行住房公积金的缴存登记等义务的」。 灵活就业人员自愿缴存（决定第十八条，新增第四十九条）：个体工商户、非全日制从业人员以及其他灵活就业人员可以自愿缴存，按照规定享受相应的政策支持；具体办法由设区的市级以上地方人民政府制定，国务院住房城乡建设主管部门等加强指导。 其他：第九条增列呆账核销审批职权（决定第四条）；删去第四十六条（决定第十九条）；「建设行政主管部门」统一改为「住房城乡建设主管部门」，并在相关条款增列银行业监督管理机构（决定第十七、二十条）。 三、与劳动用工直接相关的义务条款（修订后文本） 第十四条：新设立单位应自设立之日起 30 日内办理缴存登记，并自登记之日起 20 日内为职工办理账户设立手续；单位合并、分立、撤销、解散或破产的，30 日内办理变更或注销登记。 第十五条：单位录用职工的，应当自录用之日起 30 日内办理缴存登记并办理职工账户设立或转移手续；终止劳动关系的，自劳动关系终止之日起 30 日内办理变更登记及账户转移或封存手续。 第三十五条：住房公积金管理中心应当督促单位按时履行缴存登记、账户设立转移封存、足额缴存等义务；职工有权督促单位按时履行前款义务（第二款）。 第三十九条：单位不办理缴存登记或不为职工办理账户设立手续的，责令限期办理，逾期不办理的处 5 万元以上 30 万元以下罚款。 第四十条：单位逾期不缴或者少缴住房公积金的，责令限期缴存；逾期仍不缴存的，可以申请人民法院强制执行。 四、生效日与合规义务适用日分写 法律生效日：修改决定自 2026 年 9 月 20 日起施行（决定末条）。 合规义务适用日：修订后条例的缴存、提取、贷款、监管义务自 2026 年 9 月 20 日起按修订后文本适用；第十四条、第十五条各项期限义务自施行日起对存续与新增劳动关系一并适用，施行日前发生的期间不溯及。修订后第五十条「本条例自发布之日起施行」系原条例施行条款的历史沿革表述，现行文本整体适用时点以决定施行日为准。 提示：引用罚则时须按修订后条号（如罚款条款为第三十九条，原为第三十七条），避免沿用旧条号；第四十九条属授权条款，各设区的市级以上地方制定具体办法后，灵活就业人员才有可操作的缴存渠道与政策支持口径，不宜表述为灵活就业人员已普遍可缴存。 五、局限与引用提示 全国人大常委会国家法律法规数据库（flk.npc.gov.cn）检索接口返回前端页面壳，未能取得条例在本库的独立收录页直链（2026-10-02 实测）；本页以政府网发布页为唯一全文来源。 未见与中文文本对应的官方外文译本，引用英文表述时不应转引第三方译文。 配套落地：第三十一条（数字化互认）、第四十九条（灵活就业人员缴存）均需地方及部门配套办法，发布后另件采集。 资料来源：中国政府网国务院政策文件库发布页（修改决定及修订后条例全文）。整理时间：2026-10-06。本页为采集整理稿，供研究参考，不构成法律意见。\n","permalink":"https://ai.intlaws.com/legislation/housing-fund-regulations-2026-third-amendment/","summary":"《国务院关于修改〈住房公积金管理条例〉的决定》（国务院令第 844 号）经 2026 年 7 月 31 日国务院第 93 次常务会议通过，2026 年 8 月 10 日公布，自 2026 年 9 月 20 日起施行，系该条例 1999 年发布以来的第三次修订；修改决定共二十条，修订后条例为七章五十条，主要内容：扩容住房消费提取情形（新增支付房租居首、装修、物业费）、提取决定 3 日内与贷款决定 10 日内办结、单位违法缴存义务罚款上限升至 30 万元、缴存记录全国互信互认、违法提取 3 年与违法贷款 5 年限制、个体工商户等灵活就业人员可自愿缴存。","title":"国务院令第844号修改《住房公积金管理条例》：第三次修订，自2026年9月20日起施行"},{"content":"案件名称与案号 某甲科技（北京）有限公司等与北京某乙科技有限公司等侵害信息网络传播权纠纷案\n——通过提级管辖明确相关领域平台侵权责任承担规则\n一审 海南自由贸易港知识产权法院 ｜ 二审 海南省高级人民法院驳回上诉、维持原判 ｜ 发布：最高人民法院《人民法院司法改革案例选编（十六）》暨提级管辖典型案例（2026-09-28 发布）改革案例第 210 号\n官方发布文本未载明案号与一、二审判决具体日期（最高法选编体例匿名化处理），本页如实注明。\n关键词 民事 / 著作权 / 信息网络传播权 / 通知—删除 / 过滤拦截 / 必要措施 / 帮助侵权 / 提级管辖\n基本案情 案涉作品为国产 3D 玄幻动画，位居动漫热搜榜前列。深圳市某某科技有限公司（深圳公司）享有案涉作品独占信息网络传播权，并将非独占信息网络传播权及维权权利授予某甲科技（北京）有限公司、海南某天娱乐有限公司。北京某乙科技有限公司运营的某平台（App、网页等）存在大量侵害案涉作品信息网络传播权的侵权视频。\n案涉作品开播前，权利人向某平台发送预警函；作品开播后，多次发出侵权通知函要求下线、删除侵权视频。某平台对部分视频履行了「通知—删除」义务，但在其有技术能力通过审核机制识别侵权视频的前提下，并未采取过滤、拦截等技术措施有效遏制侵权视频传播。权利人诉请停止侵权并赔偿经济损失及合理开支。\n管辖：案件最初由海南省琼海市人民法院受理。海南自由贸易港知识产权法院认为，该案涉及视频平台信息网络传播权侵权责任承担问题，提级审理更有利于发挥示范诉讼作用、统一裁判尺度，且与本院已受理的另案当事人相同、侵权行为性质相似，故决定提级管辖。\n法院审理与说理 海南自由贸易港知识产权法院经审理认为：某平台具备采取必要措施过滤、拦截侵权视频的技术能力和审核识别机制；接到预警函和侵权通知函后，虽对部分侵权视频采取删除措施，但至本案证据交换时该平台仍存在大量侵权视频——在此情形下，仅履行「通知—删除」义务已难以有效保护权利人合法权益；认定北京某乙公司在明知平台用户实施侵害信息网络传播权行为的情况下，未采取必要措施过滤、拦截，未有效预防、制止用户侵权行为，亦构成侵权。\n裁判结果 北京某乙公司立即停止侵害信息网络传播权的行为，即立即采取有效措施，包括但不限于删除、过滤、拦截未经授权在某平台传播案涉作品的视频内容； 赔偿原告深圳公司等经济损失 100 万元及为维权支出的合理开支 6.168 万元； 驳回其他诉讼请求。 一审宣判后双方均上诉；海南省高级人民法院判决驳回上诉，维持原判。\n数据法 / 平台治理要点 「通知—删除」只是底线而非免责牌：视频平台作为网络服务提供者，在收到权利人侵权通知、且有技术能力通过审核机制识别侵权视频的前提下，不能仅履行「通知—删除」义务，而应采取过滤、拦截等必要措施，及时有效预防、制止侵权视频传播，否则构成侵权。 技术能力本身构成注意义务的认定基础：「有技术能力而不用」是本案过错认定的关键事实；预警函（开播前发送）与后续侵权通知函共同构成「明知」的事实基础。 停止侵权的方式是动态的：判项一要求「包括但不限于删除、过滤、拦截」的持续有效措施，而非一次性删除被点名链接——对具备内容识别能力的平台，事后删除义务是过程性义务。 提级管辖的示范功能：本案系涉视频平台信息网络传播权侵权责任的标杆案件，提级管辖有利于统一辖区同类平台侵权纠纷裁判尺度，具有「审理一案、指导一类、规范一片」的示范价值。 相关法条 官方发布文本未单列裁判依据法条，上文说理部分所引义务表述以发布文本原文为准（《民法典》第一千一百九十七条、《信息网络传播权保护条例》及《最高人民法院关于审理侵害信息网络传播权民事纠纷案件适用法律若干问题的规定》项下「明知或者应知」与「必要措施」的认定框架可作理解参照，非本案裁判依据的官方明示罗列）。\n权威来源 最高人民法院官网 ·《人民法院司法改革案例选编（十六）》暨提级管辖典型案例（2026-09-28 发布，改革案例第 210 号全文） （页面载「发布时间：2026-09-28 11:08:03」「来源：最高人民法院新闻局」） 判赔金额（100 万元、6.168 万元）、二审结果与「案例210」序号均已按发布页文本逐字核对。 站内关联 AI搜索引擎检索增强生成（RAG）侵权责任案 ——同为信息网络传播权场景下的平台注意义务认定，该案认定「通知后及时有效处理＋无主动上传」不构成侵权，与本案「有技术能力而不采取必要措施」构成侵权形成义务梯度的两端对照。 ","permalink":"https://ai.intlaws.com/cases/china/hnftip-notice-takedown-insufficient-video-platform/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e某甲科技（北京）有限公司等与北京某乙科技有限公司等侵害信息网络传播权纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——通过提级管辖明确相关领域平台侵权责任承担规则\u003c/p\u003e\n\u003cp\u003e一审 海南自由贸易港知识产权法院 ｜ 二审 海南省高级人民法院驳回上诉、维持原判 ｜ \u003cstrong\u003e发布\u003c/strong\u003e：最高人民法院《人民法院司法改革案例选编（十六）》暨提级管辖典型案例（2026-09-28 发布）改革案例第 210 号\u003c/p\u003e\n\u003cp\u003e官方发布文本未载明案号与一、二审判决具体日期（最高法选编体例匿名化处理），本页如实注明。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 著作权 / 信息网络传播权 / 通知—删除 / 过滤拦截 / 必要措施 / 帮助侵权 / 提级管辖\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e案涉作品为国产 3D 玄幻动画，位居动漫热搜榜前列。深圳市某某科技有限公司（深圳公司）享有案涉作品\u003cstrong\u003e独占信息网络传播权\u003c/strong\u003e，并将非独占信息网络传播权及维权权利授予某甲科技（北京）有限公司、海南某天娱乐有限公司。北京某乙科技有限公司运营的某平台（App、网页等）存在大量侵害案涉作品信息网络传播权的侵权视频。\u003c/p\u003e\n\u003cp\u003e案涉作品\u003cstrong\u003e开播前\u003c/strong\u003e，权利人向某平台发送\u003cstrong\u003e预警函\u003c/strong\u003e；作品开播后，多次发出侵权通知函要求下线、删除侵权视频。某平台对部分视频履行了「通知—删除」义务，但在其\u003cstrong\u003e有技术能力通过审核机制识别侵权视频\u003c/strong\u003e的前提下，并未采取过滤、拦截等技术措施有效遏制侵权视频传播。权利人诉请停止侵权并赔偿经济损失及合理开支。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e管辖\u003c/strong\u003e：案件最初由海南省琼海市人民法院受理。海南自由贸易港知识产权法院认为，该案涉及视频平台信息网络传播权侵权责任承担问题，提级审理更有利于发挥示范诉讼作用、统一裁判尺度，且与本院已受理的另案当事人相同、侵权行为性质相似，故决定\u003cstrong\u003e提级管辖\u003c/strong\u003e。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e海南自由贸易港知识产权法院经审理认为：某平台\u003cstrong\u003e具备采取必要措施过滤、拦截侵权视频的技术能力和审核识别机制\u003c/strong\u003e；接到预警函和侵权通知函后，虽对部分侵权视频采取删除措施，但至本案证据交换时该平台仍存在大量侵权视频——在此情形下，仅履行「通知—删除」义务\u003cstrong\u003e已难以有效保护权利人合法权益\u003c/strong\u003e；认定北京某乙公司在\u003cstrong\u003e明知\u003c/strong\u003e平台用户实施侵害信息网络传播权行为的情况下，未采取必要措施过滤、拦截，未有效预防、制止用户侵权行为，\u003cstrong\u003e亦构成侵权\u003c/strong\u003e。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e北京某乙公司立即停止侵害信息网络传播权的行为，即立即采取有效措施，\u003cstrong\u003e包括但不限于删除、过滤、拦截\u003c/strong\u003e未经授权在某平台传播案涉作品的视频内容；\u003c/li\u003e\n\u003cli\u003e赔偿原告深圳公司等经济损失 \u003cstrong\u003e100 万元\u003c/strong\u003e及为维权支出的合理开支 \u003cstrong\u003e6.168 万元\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e驳回其他诉讼请求。\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003e一审宣判后\u003cstrong\u003e双方均上诉\u003c/strong\u003e；海南省高级人民法院判决\u003cstrong\u003e驳回上诉，维持原判\u003c/strong\u003e。\u003c/p\u003e\n\u003ch2 id=\"数据法--平台治理要点\"\u003e数据法 / 平台治理要点\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e「通知—删除」只是底线而非免责牌\u003c/strong\u003e：视频平台作为网络服务提供者，在收到权利人侵权通知、且\u003cstrong\u003e有技术能力通过审核机制识别侵权视频\u003c/strong\u003e的前提下，不能仅履行「通知—删除」义务，而应采取\u003cstrong\u003e过滤、拦截等必要措施\u003c/strong\u003e，及时有效预防、制止侵权视频传播，否则构成侵权。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e技术能力本身构成注意义务的认定基础\u003c/strong\u003e：「有技术能力而不用」是本案过错认定的关键事实；预警函（开播前发送）与后续侵权通知函共同构成「明知」的事实基础。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e停止侵权的方式是动态的\u003c/strong\u003e：判项一要求「包括但不限于删除、过滤、拦截」的持续有效措施，而非一次性删除被点名链接——对具备内容识别能力的平台，事后删除义务是过程性义务。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e提级管辖的示范功能\u003c/strong\u003e：本案系涉视频平台信息网络传播权侵权责任的标杆案件，提级管辖有利于统一辖区同类平台侵权纠纷裁判尺度，具有「审理一案、指导一类、规范一片」的示范价值。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据法条，上文说理部分所引义务表述以发布文本原文为准（《民法典》第一千一百九十七条、《信息网络传播权保护条例》及《最高人民法院关于审理侵害信息网络传播权民事纠纷案件适用法律若干问题的规定》项下「明知或者应知」与「必要措施」的认定框架可作理解参照，非本案裁判依据的官方明示罗列）。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/513181.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院官网 ·《人民法院司法改革案例选编（十六）》暨提级管辖典型案例（2026-09-28 发布，改革案例第 210 号全文）\u003c/a\u003e\n（页面载「发布时间：2026-09-28 11:08:03」「来源：最高人民法院新闻局」）\u003c/li\u003e\n\u003cli\u003e判赔金额（100 万元、6.168 万元）、二审结果与「案例210」序号均已按发布页文本逐字核对。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"站内关联\"\u003e站内关联\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"/cases/china/shxh-ai-rag-search-liability/\" target=\"_blank\" rel=\"noopener noreferrer\"\u003eAI搜索引擎检索增强生成（RAG）侵权责任案\u003c/a\u003e\n——同为信息网络传播权场景下的平台注意义务认定，该案认定「通知后及时有效处理＋无主动上传」不构成侵权，与本案「有技术能力而不采取必要措施」构成侵权形成义务梯度的两端对照。\u003c/li\u003e\n\u003c/ul\u003e","title":"最高法提级管辖典型案例210：视频平台仅履行通知删除义务不足以免责，构成侵权（海南自贸港知产法院）"},{"content":" 来源与核验（可核验）\n项目 内容 文件名称 《关于加强涉企侵权信息管理 持续推动营商网络环境优化的通知》 文件性质 规范性文件（通知），非法律、非行政法规、非部门规章；官方发布页未载文号 发布主体 中央网络安全和信息化委员会办公室（国家互联网信息办公室） 发布日期 2026 年 9 月 18 日（中国网信网「网信发布」栏目刊发，页面载「2026年09月18日」） 受文对象 各省、自治区、直辖市党委网信办，新疆生产建设兵团党委网信办 落款 中央网信办秘书局，2026 年 9 月 15 日（发布页刊发日期 2026-09-18） 现行状态 已公开发布（2026-09-18 起官方直链可获取） 官方来源 中国网信网发布页 ；栏目佐证：「网信发布」列表页 校对记录 2026-10-03 抓取中国网信网发布页（快照留存）；「各省、自治区、直辖市党委网信办」1 处、「涉企侵权信息」3 处命中；发布日期「2026年09月18日」字符级命中；HTTP 200 一、这是一件什么规格的文件 2026 年 9 月 18 日，中央网络安全和信息化委员会办公室（国家互联网信息办公室）发布《关于加强涉企侵权信息管理 持续推动营商网络环境优化的通知》（以下称《通知》），主送各省、自治区、直辖市党委网信办和新疆生产建设兵团党委网信办。《通知》为规范性文件，官方发布页未载发文字号，本页如实注明。\n《通知》指出网上涉企侵权行为成本低、传播快、影响大，企业维权存在「举证难、周期长、成本高」难题，要求压实网站平台主体责任、加大涉企侵权信息处置力度。\n二、平台全链条管理义务 《通知》要求坚持关口前移、源头管理，健全涉企信息事前审核、事中巡查、事后处置全链条管理机制，主动清理显性涉企侵权信息，从严从快处置涉事账号、MCN 机构；健全信息内容管理制度，完善平台社区规则，将涉企信息纳入日常内容审核处置范围，强化账号、MCN 机构管理。\n三、应主动清理处置的五类涉企侵权信息 《通知》列明平台应主动清理处置的五类信息：\n# 类别 要点 一 个人信息类 泄露企业家身份证、护照、户籍档案、家庭住址、电话号码等个人身份及联系信息，以及生物识别、医疗健康、金融账户、行踪轨迹等敏感个人信息 二 侮辱贬损类 侮辱谩骂企业、企业家，恶搞丑化企业标识、产品和企业家肖像，将企业、企业家与色情低俗话题恶意关联，使用污名化词汇诋毁企业、企业家或特定品牌用户 三 假冒仿冒类 假冒仿冒新闻单位制作发布的涉企监督信息，假借企业或企业家名义发布的信息，在公众账号名称、头像、简介中擅自使用与企业相同或相似的名称标识或企业家姓名肖像 四 虚假误导类 断章取义、歪曲解读企业家过往言论，呈现与事实不符的搜索关键词联想、搜索落地页结果，已经权威辟谣、澄清的不实信息，与企业、企业家在超大平台上的官方账号发布的公开声明不符信息 五 其他类 涉企拉踩引战信息，集纳翻炒的企业旧闻旧事、负面信息，已被本平台处置过的涉企侵权信息，机器人账号、网络水军账号发布的涉企评论信息，明显违背公序良俗抹黑诋毁企业、企业家信息 其中第一类直接对接个人信息保护制度：企业家个人身份与联系信息属个人信息，生物识别、医疗健康、金融账户、行踪轨迹属《个人信息保护法》第二十八条项下的敏感个人信息，平台内容审核与处置义务与个保处理合法性义务在此叠加。\n四、监管责任与合规提示 监管责任：网信部门落实属地管理责任，对重视不足、落实不力特别是网民反映问题集中的平台依法依规从严处理。 性质与定位：本件为规范性文件，不直接创设新的法律责任；对平台涉企信息（含企业家个人信息、敏感个人信息）内容审核与处置义务作出更明确的操作口径。平台侧的强制义务仍以《网络安全法》《个人信息保护法》《网络信息内容生态治理规定》等法律法规和规章为基础，《通知》是监管执行层面的细化指引。 五、法律生效日与合规义务适用日分写 本件为规范性文件发布，不存在法律生效日；发布日 2026-09-18 即公开可获取日，平台涉企侵权信息处置的执行口径自发布日起在监管实践中适用，但不新设法律责任。\n相关权威来源 中国网信网 ·《关于加强涉企侵权信息管理 持续推动营商网络环境优化的通知》（2026-09-18） 中国网信网「网信发布」栏目列表页（发布日期佐证） 站内关联法规 个人信息保护法 ｜ 网络安全法 ｜ 网络数据安全管理条例 ","permalink":"https://ai.intlaws.com/legislation/cac-enterprise-infringing-info-management-notice/","summary":"中央网络安全和信息化委员会办公室（国家互联网信息办公室）2026 年 9 月 18 日发布《关于加强涉企侵权信息管理 持续推动营商网络环境优化的通知》，主送各省级党委网信办和新疆生产建设兵团党委网信办。通知要求压实网站平台主体责任，健全涉企信息事前审核、事中巡查、事后处置全链条管理机制，并列明应主动清理处置的五类涉企侵权信息（含泄露企业家个人信息与敏感个人信息）；本件为规范性文件，不新设法律责任，平台强制义务仍以《网络安全法》《个人信息保护法》等为基础。","title":"网信办《关于加强涉企侵权信息管理 持续推动营商网络环境优化的通知》（2026-09-18）：平台涉企侵权信息处置的五类清单与全链条义务"},{"content":" 来源与核验（可核验）\n项目 内容 文件名称 《人工智能安全治理框架3.0》 文件性质 标准性/框架性技术文件（非法律、非行政法规、非部门规章；官方发布页未载文号） 发布主体 全国网络安全标准化技术委员会（网安标委，TC260）；在国家互联网信息办公室指导下，组织中国网络空间研究院、国家互联网信息办公室数据与技术保障中心等专业机构、科研院所、行业企业研究编制 发布日期 2026 年 9 月 14 日，在 2026 年国家网络安全宣传周开幕式上发布（中国网信网发布页刊发日期 2026年09月14日，页面系统时间戳 2026/09/15 17:31:39） 沿革 网安标委 2024 年发布框架 1.0、2025 年发布框架 2.0；3.0 为其更新版 现行状态 已公开发布（2026-09-14 起全文 PDF 可官方直链下载） 官方来源 发布页：中国网信网 ；全文 PDF：官方直链 校对记录 2026-10-03 抓取中国网信网发布页（快照留存）；「框架3.0」字样 3 处命中、发布日期「2026年09月14日」字符级命中；全文 PDF（约 3.3MB）下载留档，HTTP 200 一、这是一件什么规格的文件 《人工智能安全治理框架3.0》（以下称《框架3.0》）由全国网络安全标准化技术委员会在国家互联网信息办公室指导下，组织中国网络空间研究院、国家互联网信息办公室数据与技术保障中心等专业机构、科研院所、行业企业研究编制，2026 年 9 月 14 日在 2026 年国家网络安全宣传周开幕式上发布。\n《框架3.0》是人工智能安全治理领域的框架性技术文件：不是法律、行政法规，也不是部门规章，不直接设定法律责任。官方发布页未载文号，本页如实注明。\n二、沿革与定位 网安标委 2024 年发布框架 1.0，2025 年发布框架 2.0；《框架3.0》为其更新版，配套《全球人工智能治理倡议》的落地文件。发布口径载明其秉持以人为本、向上向善理念，坚持强化风险意识、确保安全可控。\n三、方法论与增量 《框架3.0》延续框架系列「风险分类、技术应对、综合治理」的核心逻辑：按风险类别组织应对措施，并配套综合治理安排。3.0 的增量在于与时俱进更新风险分类、优化调整技术应对和综合治理措施。全文 PDF 已官方直链留档；具体风险条目编号本页未逐条摘录，引用具体条目前应先按 PDF 原文核对。\n四、合规提示 强制义务与推荐参照分立：对人工智能服务提供者，《框架3.0》与《生成式人工智能服务管理暂行办法》《人工智能生成合成内容标识办法》《互联网信息服务深度合成管理规定》等现行规章配合使用——框架提供风险识别与应对的技术坐标系，规章设定强制义务。中国境内主体的强制义务以规章为准，框架本身为推荐性参照。 企业用法：可作为人工智能安全风险管理、对齐监管预期的技术参照；风险管理框架与规章项下的算法备案、内容标识等义务并行不悖。 五、法律生效日与合规义务适用日分写 本件为标准性文件发布，不存在法律生效日；其发布日 2026-09-14 即公开可获取日，对使用者的参照价值自发布日起产生，但不产生新的强制合规义务。《生成式人工智能服务管理暂行办法》等规章的强制义务自其各自施行日起普遍适用，不因本框架发布而变动。\n相关权威来源 中国网信网 ·《人工智能安全治理框架3.0》发布页（2026-09-14） 《人工智能安全治理框架3.0》全文 PDF（官方直链） 延伸阅读 allen 解读版《人工智能安全治理框架3.0》解读（2026-10-03）——单独排期上站，链接待其发布后补挂。 站内关联法规：生成式人工智能服务管理暂行办法 ｜ 人工智能生成合成内容标识办法 ｜ 网络安全法 ","permalink":"https://ai.intlaws.com/legislation/tc260-ai-safety-governance-framework-3-0/","summary":"全国网络安全标准化技术委员会于 2026 年 9 月 14 日在 2026 年国家网络安全宣传周开幕式上发布《人工智能安全治理框架3.0》。该文件为国家互联网信息办公室指导下组织编制的标准性技术文件，系 2024 年框架 1.0、2025 年框架 2.0 的更新版，延续「风险分类、技术应对、综合治理」核心逻辑，更新风险分类并优化技术应对与综合治理措施。框架不设定法律责任，中国境内主体的强制义务仍以《生成式人工智能服务管理暂行办法》《人工智能生成合成内容标识办法》等现行规章为准。","title":"全国网安标委发布《人工智能安全治理框架3.0》（2026-09-14）：风险分类、技术应对与综合治理的更新版"},{"content":" 来源与核验（可核验）\n项目 内容 文书名称 《大型个人信息处理者个人信息保护规定（征求意见稿）》 文书性质 部门规章草案（国家网信部门制定；现处于公开征求意见期届满、尚未正式公布） 文号 [无文号]（草案阶段不编令号） 发布主体 国家互联网信息办公室（经中国网信网发布） 公开征求意见通告日 2026 年 8 月 7 日（页面载「2026年08月07日 16:00」） 意见反馈截止日 2026 年 9 月 7 日（原文：「意见反馈截止时间为2026年9月7日。」） 现行状态 公开征求意见期已届满（截至 2026-09-27 未见正式公布文本），不产生规范效力 体例 正文 六章、五十条；附件监督委员会工作规则要点以中文序号「一」至「十八」分列 施行日期 第五十条作「本规定自 年 月 日起施行」——留空未定 上位法依据 《中华人民共和国个人信息保护法》《网络数据安全管理条例》 官方来源 中国网信网 · 公开征求意见通知页（含草案全文） ；栏目归属：「网信政务·政策法规」 版本提示 草案引用的《网络安全法》第二十三条（网络日志留存不少于六个月）系按 2025 年修正版条号核对无误；2016 年版条号引用一律以 2025 年修正版为准 文本校读 抓取国家网信办页面文本；章号「第一章」至「第六章」连续无缺，条号「第一条」至「第五十条」1—50 连续、无缺号、无重号、无空条；附件中文序号「一」至「十八」连续；通告日与反馈截止日逐字符比对 一、这是一件什么规格的文件 《大型个人信息处理者个人信息保护规定（征求意见稿）》（以下称《规定（征求意见稿）》）由国家互联网信息办公室起草，2026 年 8 月 7 日公开征求意见，反馈截止 2026 年 9 月 7 日。依据草案第一条，其上位法为《中华人民共和国个人信息保护法》《网络数据安全管理条例》。\n按通知正文所述，该草案系将前期已公开征求意见的《大型网络平台设立个人信息保护监督委员会规定（征求意见稿）》与《大型网络平台个人信息保护规定（征求意见稿）》作整合完善后形成，规范对象的表述由「大型网络平台」调整为「大型个人信息处理者」。\n草案体例为六章、五十条：第一章总则；第二章个人信息处理规则；第三章大型个人信息处理者的义务；第四章个人信息保护监督委员会；第五章监督管理和法律责任；第六章附则。另附监督委员会工作规则要点，以中文序号「一」至「十八」分列。施行日期留空（第五十条作「本规定自 年 月 日起施行」），与该件仍处草案阶段相印证。\n二、规范对象：大型个人信息处理者的认定与程序 草案第二条以三项并列条件界定大型个人信息处理者，认定时综合考虑：\n序号 条件 （一） 处理 1000 万人以上自然人个人信息 （二） 提供涉及个人信息处理的重要网络服务，或者经营范围涵盖多种业务且涉及个人信息处理 （三） 个人信息处理活动对国家安全、经济运行、社会稳定、公共健康和安全等具有重要影响 第三条设定申报—查验—公告链条：达到条件的处理者，应当通过所在地省级网信部门向国家网信部门申报认定；省级网信部门自收到申报材料之日起 15 个工作日内完成完备性查验，材料齐全的连同初步认定意见报送国家网信部门，材料不齐全的一次性告知需要补充的材料；符合条件但未主动申报的，由省级以上网信部门、电信主管部门、公安机关等督促申报；国家网信部门会同国务院电信主管部门、公安部门等研究确定大型个人信息处理者清单，并向社会公告。被认定者认为已连续 6 个月不再符合条件时，可以申请变更认定。\n三、与数据、人工智能直接相关的处理规则 主题 要点 条文 安全措施 应当采取加密、去标识化、访问控制、匿名化等措施保障所处理个人信息安全；可以应用国家网络身份认证公共服务，鼓励使用数据标签标识技术、通过个人信息保护认证 第五条 境外对象清单 对境外组织、个人侵害中国公民个人信息权益或危害中国国家安全、公共利益的个人信息处理活动，国家网信部门可将其列入限制或者禁止个人信息提供清单并公告，采取限制或禁止向其提供个人信息等措施 第七条 最小必要 收集个人信息应坚持最小必要原则，限于提供产品或服务所必需，不得过度收集 第九条 处理规则公开 应以结构化清单逐项列明每项功能服务收集使用个人信息的目的、方式、种类、权限名称与频度、收集敏感个人信息的必要性及对个人权益的影响；嵌入 SDK 的，须以结构化清单列明 SDK 名称（包名）、版本、主要功能、运营者、收集种类及完整规则访问途径；向其他个人信息处理者提供个人信息的，列明接收方名称、联系方式、处理目的、处理方式和个人信息种类 第十条 单独同意与重新同意 列举应当取得个人单独同意的情形，并要求以对个人权益影响最小的方式处理；处理目的、处理方式、处理的个人信息种类发生变更的，应当重新取得个人同意 第十一、十二条 境内存储 应当将在中国境内运营中收集和产生的个人信息存储在境内；并规定数据中心应当符合的条件、数据中心管理机构的管理与协助义务、委托第三方数据中心管理机构的书面合同要求 第十三至十六条 自动化决策 通过自动化决策方式向个人推送信息、商业营销的，应当采取相应措施保护个人权益 第十七条 汇聚融合 对个人信息进行汇聚或融合等处理，处理后符合《个人信息保护法》第二十八条规定的，应当按照敏感个人信息识别与保护 第十八条 转移权 对符合《网络数据安全管理条例》第二十五条条件的转移请求，应自完成个人身份验证和请求验证后 30 个工作日内以通用或机器可读格式转移并告知处理结果；可因请求数量、操作复杂等在合理必要范围内延长 30 个工作日 第十九条 数据出境 确需向境外提供个人信息的，应当按照国家有关规定申报数据出境安全评估、订立个人信息出境标准合同或者通过个人信息保护认证，健全相关技术与管理措施 第二十条 对外提供 向其他个人信息处理者提供个人信息应当优先采取去标识化、聚合统计等措施；按《网络安全法》第二十三条要求采取监测、记录对外传输情况的技术措施，留存相关日志不少于六个月 第二十一条 公开个人信息 原则上不得公开其处理的个人信息，取得个人单独同意的除外；公开应限于实现处理目的最小范围，并采取去标识化等技术措施；公开前应当开展个人信息保护影响评估 第二十二条 保存与删除 保存期限限于提供产品或服务所必需的最短时限；列举应当主动删除个人信息的情形 第二十三条 四、组织与程序性义务 内部管理制度：围绕个人信息处理活动、个人行使权利响应、安全义务履行等环节建立健全制度与操作规程，加强安全监测预警（第二十四条）。 个人信息保护负责人：指定一名管理层成员担任并公开联系方式，草案列举其职责（第二十五、二十六条）。 业务部门合规人员：明确具备个人信息保护合规审计能力的人员负责本部门工作，人员数量与业务规模、履行的义务相适应（第二十七条）。 权限与记录：以实现业务功能所需的最小授权为原则配置操作权限；个人信息处理操作记录、权限审批记录等至少保存六个月；涉及个人信息保护影响评估报告和处理情况记录的至少保存三年（第二十八条）。 平台内治理：提供网络平台服务的，应明确平台内产品或者服务提供者处理个人信息的规范、权限和保护义务（第二十九条）。 年度社会责任报告：每年编制并于上半年发布上一年度个人信息保护社会责任报告（第三十条）。 影响评估备案：上线涉及自动化决策、敏感个人信息处理等可能对个人权益有重大影响的产品、服务或者功能，应当事前开展个人信息保护影响评估，并在评估完成后 15 个工作日内通过所在地省级网信部门报国家网信部门备案（第三十一条）。 未成年人：严格保护未成年人个人信息，通过国家网络身份认证公共服务等方式识别未成年人，并依照《未成年人网络保护条例》每年开展未成年人个人信息保护合规审计（第三十二条）。 审计与风险评估：至少每两年开展一次个人信息保护合规审计，每年对其个人信息处理活动开展风险评估并整改；鼓励在显著位置公开展示审计、风险评估结果（第三十三条）。 投诉举报：在个人信息处理规则中提供有效、易于访问的投诉举报渠道，受理处置的承诺时限不得超过 15 个工作日（第三十五条）。 信息报送：自被认定之日起 30 个工作日内向所在地设区的市级网信部门报送规定信息（第三十六条）。 五、个人信息保护监督委员会 第三十七条要求大型个人信息处理者自被认定之日起 6 个月内成立主要由外部成员组成的个人信息保护监督委员会，按附件要求制定工作规则，并通过所在地省级网信部门向国家网信部门报送成立情况、工作规则、成员名单等基本信息。第三十八条至第四十一条规定外部成员的任职条件、独立性要求（含最近一年内的禁止情形）、津贴机制与重点监督事项；第四十二条明确监管部门的监督管理权限。第四十三条要求于每年第一季度报送监督委员会上一年度履职情况，并至少每两年报送个人信息保护合规审计报告。\n六、监督管理与法律责任 第四十四条列举现场检查、约谈、要求整改、督促解散监督委员会等处置措施；第四十五条确立任何组织和个人的投诉举报权；第四十六条规定履职人员对个人隐私、个人信息、商业秘密、保密商务信息的保密义务；第四十七条规定违法处理个人信息或者处理个人信息未履行个人信息保护义务的，由网信部门、电信主管部门、公安机关等依照《个人信息保护法》《治安管理处罚法》《网络数据安全管理条例》等处理，构成犯罪的依法追究刑事责任。\n七、与既有制度的衔接（对照阅读） 《中华人民共和国个人信息保护法》第五十八条对提供重要互联网平台服务、用户数量巨大、业务类型复杂的个人信息处理者设定了特别义务。本草案将特别义务的适用对象改造为按个人信息处理规模（1000 万人以上）、服务重要性、影响程度三重标准认定的「大型个人信息处理者」，并配套申报认定与清单公告机制。 草案将第五十八条项下的外部独立机构监督细化为可操作的「个人信息保护监督委员会」制度（外部成员为主、独立性禁止情形、津贴、年度履职报告与报送）。 个人信息出境方面，草案重申既有路径（安全评估／标准合同／认证）与《促进和规范数据跨境流动规定》的框架，未新设出境通道。 未成年人个人信息方面，与《未成年人网络保护条例》衔接，另设按年开展合规审计的要求。 站内关联法规与文件 中华人民共和国个人信息保护法 网络数据安全管理条例 促进和规范数据跨境流动规定 数据出境安全评估办法 个人信息出境标准合同办法 个人信息保护合规审计管理办法 官方文本未载明事项 是否已正式公布：截至 2026-09-27，未检索到该规定的正式公布文本与令号；本文以征求意见阶段文本为准，正式公布后须以公布文本更新。 附件的正式标题：页面以「附件：大型个人信息处理者个人信息保护规定（征求意见稿）」列示，附件正文以中文序号呈现，其单独标题在公开文本中未单列。 草案整理过程中被整合的两份前身征求意见稿的原始通告，本文未逐一取回；如需追溯沿革，应另作对照件。 ","permalink":"https://ai.intlaws.com/legislation/large-pi-processor-rules-draft/","summary":"国家互联网信息办公室于 2026 年 8 月 7 日就《大型个人信息处理者个人信息保护规定（征求意见稿）》公开征求意见，意见反馈截止 2026 年 9 月 7 日。该草案由《大型网络平台设立个人信息保护监督委员会规定（征求意见稿）》《大型网络平台个人信息保护规定（征求意见稿）》整合完善而成，共六章五十条，另附监督委员会工作规则要点十八项；以「处理 1000 万人以上自然人个人信息」等三项条件认定大型个人信息处理者，配套申报认定与清单公告机制，并规定单独同意、境内存储、出境申报、合规审计、影响评估备案、个人信息保护监督委员会等义务；施行日期条款留空未定。","title":"《大型个人信息处理者个人信息保护规定（征求意见稿）》公开征求意见（意见反馈截止 2026 年 9 月 7 日）"},{"content":" 案情、裁判结果与典型意义取自最高人民法院 2026 年 5 月 8 日《人民法院依法惩治侵犯公民个人信息犯罪及关联犯罪典型案例》发布文本（该批共 5 件，本案为案例一），以直接引述或紧贴原文的归纳为限，不作超出原文的推论。\n案件名称与案号 博某软件有限公司、何某某等侵犯公民个人信息案\n——依法惩治外包公司窃取患者隐私行为，筑牢医疗数据安全防线\n一审 江苏省无锡市锡山区人民法院 ｜ 发布：最高人民法院《人民法院依法惩治侵犯公民个人信息犯罪及关联犯罪典型案例》（2026-05-08 发布）案例一\n案号与裁判日期：官方发布文本未附案号、未载裁判日期，本页不作推测补写。\n关键词 刑事 / 侵犯公民个人信息罪 / 医疗服务外包 / 网上挂号系统 / 提供服务过程中收集 / 数据去重 / 单位犯罪\n基本案情 2015 年至 2020 年间，被告单位博某软件有限公司负责为某医院开发、维护网上挂号系统，被告人何某某系公司法定代表人。在提供服务过程中，何某某暗中收集从后台非法获取的该医院挂号用户相关个人信息，并安排公司员工被告人熊某、罗某某将所获取的信息数据导入公司自建数据库。2021 年初，熊某又安排人员在为该医院开发的软件上安装接口，自动将挂号用户个人信息导入公司自建数据库。\n案发后，在公司服务器、自建数据库及何某某家中设备内均提取到包含有挂号用户的个人信息，数据去重后合计 2 878 070 条。\n法院审理与说理 一审（江苏省无锡市锡山区人民法院） 认定：\n被告单位博某软件有限公司在提供服务过程中非法获取公民个人信息，情节特别严重，已构成侵犯公民个人信息罪，应依法惩处； 被告人何某某等人为被告单位直接负责的主管人员和其他直接责任人员，均已构成侵犯公民个人信息罪； 综合本案事实、情节、后果等作出量刑（见下栏）。 法律定性路径（官方发布文本「典型意义」栏所载）：互联网企业在为医疗卫生领域提供服务过程中，应当严格依照法律法规、企业经营范围、合同约定及隐私协议等，在服务和授权范围内合理合法地处理公民个人信息。互联网企业利用为医疗机构提供服务的便利，非法获取患者信息、医疗数据的行为，属于《最高人民法院、最高人民检察院关于办理侵犯公民个人信息刑事案件适用法律若干问题的解释》第四条规定的在「提供服务过程中收集公民个人信息」的情形，情节严重，应依法惩处。人民法院追究被告单位和直接负责的主管人员、其他直接责任人员的刑事责任，同时适用财产刑。\n裁判结果 对被告单位博某软件有限公司以侵犯公民个人信息罪判处罚金人民币三十万元； 对被告人何某某等人以侵犯公民个人信息罪判处有期徒刑五年六个月至一年六个月不等，并处罚金人民币十万元至一万元不等。 数据法 / AI 法要点 受托处理方的义务边界：为医疗机构开发、维护信息系统的承包方，对其在提供服务过程中接触的个人信息负有法定处理边界；超出合同约定与授权范围获取数据，属于非法获取，不因「具备系统访问权限」而正当化。 「提供服务过程中收集」的定性：官方文本明确援引《办理侵犯公民个人信息刑事案件适用法律若干问题的解释》第四条，将在履行职责或者提供服务过程中收集公民个人信息作为情节要素适用，本案是该条款在医疗信息系统外包场景下的适用例证。 单位犯罪与双向追责：既对被告单位判处罚金，又对直接负责的主管人员（法定代表人）与其他直接责任人员追究刑事责任，体现对数据处理组织中决策层与执行层的双向追责。 数据规模作为核心事实：去重后 2 878 070 条挂号用户个人信息，是「情节特别严重」认定的基础事实之一。 接口化的持续性外流：除人工导出外，法院查明行为人在为医院开发的软件上安装接口自动导入数据，把一次性窃取转化为持续性、工程化的数据外流通道，是医疗信息化外包场景下的典型风险形态。 医疗数据的敏感属性：挂号用户信息关联就诊事实，官方文本将其表述为「患者隐私」「医疗数据」，并据此强调医疗机构数据安全体系建设，以及对泄露、非法获取患者医疗信息犯罪的严厉打击。 相关法条 《中华人民共和国刑法》第二百五十三条之一（侵犯公民个人信息罪）。 《最高人民法院、最高人民检察院关于办理侵犯公民个人信息刑事案件适用法律若干问题的解释》第四条——官方发布文本「典型意义」栏明确援引，即「在履行职责或者提供服务过程中收集公民个人信息」的情形。 裁判文书中具体援引的其他条款，官方发布文本未载明，本页不代官方补写。 权威来源 最高人民法院 · 《人民法院依法惩治侵犯公民个人信息犯罪及关联犯罪典型案例》发布文本（2026-05-08） 组级发布口径：最高人民法院官网「典型案例发布」栏目 材料来源：最高人民法院 2026 年 5 月 8 日《人民法院依法惩治侵犯公民个人信息犯罪及关联犯罪典型案例》发布文本（案例一），该批共 5 件（案例一至案例五，序号连续）。\n官方文本未载明事项 案号：官方发布文本未附案号；最高人民法院官网发布页全文未列案号，中国裁判文书网本次未检索到本案裁判文书。本页不作推测补写。 裁判日期：官方发布文本未载明一审裁判日期（仅载犯罪行为期间为 2015 年至 2020 年间、2021 年初有接口安装行为）。 审级与生效状态：官方发布文本仅载一审审理与判决，未载上诉、抗诉或生效说明。 被告人明细：官方以「何某某」「熊某」「罗某某」等化名表述，未公开完整被告人名单及各人具体刑期对应关系（仅给出区间）。 数据条数口径：官方表述为「数据去重后合计 2 878 070 条」，去重口径与统计边界未细化。 同批其余 4 件（案例二至案例五）本批次暂未收录；其中案例四（搭建「社工库」并提供有偿查询、组织「开盒」）涉个人信息非法交易，如需另出件。 收录口径说明：本站案例栏目以涉数据、个人信息与人工智能为收录口径；本案为刑事案件，争点为提供服务过程中非法获取个人信息，未涉及数据权属、数据出境等议题，援引时不宜作扩张解释。 站内关联法规 中华人民共和国个人信息保护法 中华人民共和国数据安全法 中华人民共和国网络安全法 网络数据安全管理条例 ","permalink":"https://ai.intlaws.com/cases/china/xishan-hospital-registration-data-crime/","summary":"\u003cblockquote\u003e\n\u003cp\u003e案情、裁判结果与典型意义取自最高人民法院 2026 年 5 月 8 日《人民法院依法惩治侵犯公民个人信息犯罪及关联犯罪典型案例》发布文本（该批共 5 件，本案为案例一），以直接引述或紧贴原文的归纳为限，不作超出原文的推论。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e博某软件有限公司、何某某等侵犯公民个人信息案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——依法惩治外包公司窃取患者隐私行为，筑牢医疗数据安全防线\u003c/p\u003e\n\u003cp\u003e一审 江苏省无锡市锡山区人民法院 ｜ \u003cstrong\u003e发布\u003c/strong\u003e：最高人民法院《人民法院依法惩治侵犯公民个人信息犯罪及关联犯罪典型案例》（2026-05-08 发布）案例一\u003c/p\u003e\n\u003cp\u003e案号与裁判日期：\u003cstrong\u003e官方发布文本未附案号、未载裁判日期\u003c/strong\u003e，本页不作推测补写。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e刑事 / 侵犯公民个人信息罪 / 医疗服务外包 / 网上挂号系统 / 提供服务过程中收集 / 数据去重 / 单位犯罪\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e2015 年至 2020 年间，被告单位\u003cstrong\u003e博某软件有限公司\u003c/strong\u003e负责为\u003cstrong\u003e某医院开发、维护网上挂号系统\u003c/strong\u003e，被告人\u003cstrong\u003e何某某\u003c/strong\u003e系公司法定代表人。在提供服务过程中，何某某\u003cstrong\u003e暗中收集从后台非法获取的该医院挂号用户相关个人信息\u003c/strong\u003e，并安排公司员工被告人\u003cstrong\u003e熊某、罗某某\u003c/strong\u003e将所获取的信息数据\u003cstrong\u003e导入公司自建数据库\u003c/strong\u003e。2021 年初，熊某又安排人员在为\u003cstrong\u003e该医院开发的软件上安装接口\u003c/strong\u003e，\u003cstrong\u003e自动将挂号用户个人信息导入公司自建数据库\u003c/strong\u003e。\u003c/p\u003e\n\u003cp\u003e案发后，在公司服务器、自建数据库及何某某家中设备内均提取到包含有挂号用户的个人信息，\u003cstrong\u003e数据去重后合计 2 878 070 条\u003c/strong\u003e。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e一审（江苏省无锡市锡山区人民法院）\u003c/strong\u003e 认定：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e被告单位\u003cstrong\u003e博某软件有限公司在提供服务过程中非法获取公民个人信息，情节特别严重\u003c/strong\u003e，已构成侵犯公民个人信息罪，应依法惩处；\u003c/li\u003e\n\u003cli\u003e被告人何某某等人\u003cstrong\u003e为被告单位直接负责的主管人员和其他直接责任人员\u003c/strong\u003e，均已构成侵犯公民个人信息罪；\u003c/li\u003e\n\u003cli\u003e综合本案事实、情节、后果等作出量刑（见下栏）。\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e法律定性路径\u003c/strong\u003e（官方发布文本「典型意义」栏所载）：互联网企业在为医疗卫生领域提供服务过程中，应当严格依照法律法规、企业经营范围、合同约定及隐私协议等，\u003cstrong\u003e在服务和授权范围内\u003c/strong\u003e合理合法地处理公民个人信息。互联网企业\u003cstrong\u003e利用为医疗机构提供服务的便利，非法获取患者信息、医疗数据\u003c/strong\u003e的行为，属于《最高人民法院、最高人民检察院关于办理侵犯公民个人信息刑事案件适用法律若干问题的解释》\u003cstrong\u003e第四条\u003c/strong\u003e规定的在「\u003cstrong\u003e提供服务过程中收集公民个人信息\u003c/strong\u003e」的情形，情节严重，应依法惩处。人民法院追究被告单位和\u003cstrong\u003e直接负责的主管人员、其他直接责任人员\u003c/strong\u003e的刑事责任，同时适用\u003cstrong\u003e财产刑\u003c/strong\u003e。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e对被告单位\u003cstrong\u003e博某软件有限公司\u003c/strong\u003e以\u003cstrong\u003e侵犯公民个人信息罪判处罚金人民币三十万元\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e对被告人\u003cstrong\u003e何某某等人\u003c/strong\u003e以侵犯公民个人信息罪判处\u003cstrong\u003e有期徒刑五年六个月至一年六个月不等\u003c/strong\u003e，并\u003cstrong\u003e处罚金人民币十万元至一万元不等\u003c/strong\u003e。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003e受托处理方的义务边界\u003c/strong\u003e：为医疗机构开发、维护信息系统的承包方，对其在提供服务过程中接触的个人信息负有法定处理边界；超出合同约定与授权范围获取数据，属于非法获取，\u003cstrong\u003e不因「具备系统访问权限」而正当化\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e「提供服务过程中收集」的定性\u003c/strong\u003e：官方文本明确援引《办理侵犯公民个人信息刑事案件适用法律若干问题的解释》\u003cstrong\u003e第四条\u003c/strong\u003e，将在履行职责或者提供服务过程中收集公民个人信息作为情节要素适用，本案是该条款在\u003cstrong\u003e医疗信息系统外包\u003c/strong\u003e场景下的适用例证。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e单位犯罪与双向追责\u003c/strong\u003e：既对\u003cstrong\u003e被告单位\u003c/strong\u003e判处罚金，又对\u003cstrong\u003e直接负责的主管人员\u003c/strong\u003e（法定代表人）与\u003cstrong\u003e其他直接责任人员\u003c/strong\u003e追究刑事责任，体现对数据处理组织中决策层与执行层的双向追责。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e数据规模作为核心事实\u003c/strong\u003e：去重后 \u003cstrong\u003e2 878 070 条\u003c/strong\u003e挂号用户个人信息，是「情节特别严重」认定的基础事实之一。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e接口化的持续性外流\u003c/strong\u003e：除人工导出外，法院查明行为人在为医院开发的软件上\u003cstrong\u003e安装接口自动导入\u003c/strong\u003e数据，把一次性窃取转化为\u003cstrong\u003e持续性、工程化\u003c/strong\u003e的数据外流通道，是医疗信息化外包场景下的典型风险形态。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e医疗数据的敏感属性\u003c/strong\u003e：挂号用户信息关联就诊事实，官方文本将其表述为「患者隐私」「医疗数据」，并据此强调医疗机构数据安全体系建设，以及对泄露、非法获取患者医疗信息犯罪的严厉打击。\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e《中华人民共和国刑法》\u003cstrong\u003e第二百五十三条之一\u003c/strong\u003e（侵犯公民个人信息罪）。\u003c/li\u003e\n\u003cli\u003e《最高人民法院、最高人民检察院关于办理侵犯公民个人信息刑事案件适用法律若干问题的解释》\u003cstrong\u003e第四条\u003c/strong\u003e——官方发布文本「典型意义」栏明确援引，即「在履行职责或者提供服务过程中收集公民个人信息」的情形。\u003c/li\u003e\n\u003cli\u003e裁判文书中具体援引的其他条款，官方发布文本未载明，本页不代官方补写。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/499271.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院 · 《人民法院依法惩治侵犯公民个人信息犯罪及关联犯罪典型案例》发布文本（2026-05-08）\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e组级发布口径：\u003ca href=\"https://www.court.gov.cn/zixun/gengduo/104.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院官网「典型案例发布」栏目\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：最高人民法院 2026 年 5 月 8 日《人民法院依法惩治侵犯公民个人信息犯罪及关联犯罪典型案例》发布文本（案例一），该批共 5 件（案例一至案例五，序号连续）。\u003c/p\u003e","title":"最高法侵犯公民个人信息犯罪典型案例：医疗挂号系统外包商窃取患者个人信息，判处罚金并追究主管人员刑责（博某软件有限公司、何某某等）"},{"content":" 状态提示（务必先读）\n本件为征求意见稿：国家互联网信息办公室于 2026 年 9 月 18 日发布并公开征求意见，意见反馈截止 2026 年 10 月 17 日。该草案尚未经国务院审议通过、尚未公布、尚未施行，不产生规范效力，不得作为执法依据或合规义务依据。正式公布时以国务院令形式发布，本页届时按正式文本校订。\n版本与来源（可核验）\n项目 内容 文书名称 《国务院关于保障未成年人健康安全使用网络的规定（征求意见稿）》 文书性质 行政法规草案（由国务院制定；现处公开征求意见阶段） 文号 [无文号]（草案阶段不编令号；正式公布时以国务院令形式发布） 起草主体 国家互联网信息办公室组织起草 征求意见通告日 2026 年 9 月 18 日 17:00（中国网信网发布） 意见反馈截止 2026 年 10 月 17 日 现行状态 征求意见中（尚未通过、尚未生效），截至 2026-09-26 体例 草案正文 二十五条，不分章；随通知附《起草说明》（官方附件二） 施行日期 第二十五条作「本规定自 2026 年 月 日起施行」——留空未定 官方原文 征求意见通知页（含草案全文与起草说明）：https://www.cac.gov.cn/2026-09/18/c_1791482017777471.htm 校对记录 2026-09-26 抓取国家网信办官方页面存档比对；条号 1—25 连续、无缺号、无重号、无空条；全文逐段与官方页面比对，未作删改（仅条号加粗、条款分行） 草案全文（二十五条） 第一条 为了加强未成年人网络保护，营造有利于未成年人身心健康的网络环境，保障未成年人合法权益，根据《中华人民共和国未成年人保护法》、《中华人民共和国网络安全法》、《中华人民共和国个人信息保护法》等法律，制定本规定。\n第二条 在中华人民共和国境内向未成年人提供网络服务，研发、制造智能终端产品，通过应用程序分发平台为智能终端用户提供应用程序的，适用本规定和有关法律、行政法规的规定。\n第三条 网络服务提供者、智能终端产品制造者、应用程序分发平台服务提供者应当坚持最有利于未成年人的原则，充分考虑未成年人身心健康发展特点，科学评估对未成年人的潜在影响，合理设定服务对象和服务方式，按照本规定、国家有关规定和标准提供未成年人模式。\n鼓励智能终端产品产业链供应链加强合作联动，研发、制造以未成年人为服务对象、适应未成年人身心健康发展规律和特点的专用智能终端产品，推进未成年人专用智能终端产品产业化；支持研发、提供有利于未成年人健康成长的网络技术和服务，保障未成年人用网需求，促进未成年人科学、文明、安全、合理使用网络。\n第四条 网络服务提供者不得向未成年人提供下列网络服务：\n（一）陌生人网络社交服务，向十六周岁以上并以自己的劳动收入为主要生活来源的未成年人提供服务的除外；\n（二）虚拟亲属、虚拟伴侣等虚拟亲密关系服务；\n（三）诱导未成年人沉迷等危害或者可能严重影响未成年人身心健康的网络服务；\n（四）向未满十六周岁的未成年人提供网络直播发布服务；\n（五）法律、行政法规和国家有关规定明确的其他不得向未成年人提供的网络服务。\n第五条 网络服务提供者向未满十六周岁的未成年人提供下列网络服务的，应当通过未成年人模式提供：\n（一）网络音视频服务、网络直播发布服务以外的其他网络直播服务、网络游戏服务；\n（二）网络社交服务，包括但不限于微博客、论坛社区、群组、朋友圈、私信、跟帖评论等类型的服务；\n（三）可能影响未成年人认知的人工智能服务；\n（四）其他可能对未成年人具有重要影响的网络服务。\n第六条 网络服务提供者应当具备未成年人用户识别能力，依法综合运用法定身份证件、国家网络身份认证公共服务、分布式数字身份认证公共服务、非存储式一次性人脸核验、行为特征识别等方式，提升未成年人用户识别精准度，并采取必要措施保障未成年人个人信息安全。\n无民事行为能力、限制民事行为能力的未成年人办理电话卡的，由其法定代理人代为其办理，电信业务经营者应当依法登记未成年人用户的真实身份信息。\n第七条 国家鼓励和支持制作、复制、发布、传播有利于未成年人健康成长的网络信息，营造有利于未成年人健康成长的清朗网络空间和良好网络生态。\n网络服务提供者应当加强对用户发布信息的管理，发现制作、复制、发布、传播危害或者可能影响未成年人身心健康的网络信息的，应当依法采取相应处置措施。\n网络服务提供者在未成年人模式下不得呈现危害或者可能影响未成年人身心健康的网络信息；发现未成年人用户存在自残自杀等威胁其生命健康的极端情境的，应当采取必要措施予以干预，并及时联络用户监护人或者紧急联系人。\n第八条 网络服务提供者应当依法履行未成年人网络保护义务，建立健全算法机制机理审核、科技伦理审查、信息内容管理、网络和数据安全管理等制度；配备与服务类型、规模和未成年人用户特点相适应的内容管理技术措施和人员；不得设置诱导未成年人用户情感依赖、沉迷以及过度消费等的算法模型。\n第九条 对经实名认证或者识别为未成年人用户的，网络服务提供者不得向其提供本规定第四条规定的网络服务；提供本规定第五条规定的网络服务的，应当按照规定将相关服务切换至未成年人模式。\n网络服务提供者应当提供相应申诉渠道，及时受理用户申诉并予以核验，对经核验符合本规定要求情形的用户，应当及时解除有关措施。\n第十条 智能终端产品制造者应当为智能终端产品设置未成年人模式联动、一键切换、退出核验、防绕过以及使用时段、时长、功能和内容管理等功能。应用程序分发平台服务提供者应当落实上架审核、日常管理、应急处置等安全管理责任，综合未成年人模式建设和备案等因素，科学评估应用程序适龄范围，从严审核在未成年人模式下申请上架和更新的应用程序；对于不符合应用程序适用年龄的，应当限制下载、安装该应用程序。\n智能终端产品制造者、应用程序分发平台服务提供者应当遵守本规定第四条、第五条对网络服务提供者作出的规定，依照前款规定、国家有关规定和标准的要求，设置未成年人模式，履行相应未成年人网络保护义务。\n第十一条 未成年人模式应当符合国家有关规定和标准，具备有效识别危害或者可能影响未成年人身心健康的网络信息、保护未成年人个人信息权益、预防未成年人沉迷网络、便于监护人履行监护职责等功能。\n鼓励创新未成年人模式功能，加强专属内容池建设，丰富积极健康、向上向善的优质内容，满足未成年人精神文化需求。\n国家网信部门会同国务院有关部门根据未成年人网络保护工作需要，建立健全未成年人模式相关技术标准和规范。\n第十二条 国家网信部门建立未成年人模式备案机制。\n提供未成年人模式的智能终端产品制造者和网络服务提供者应当将未成年人模式设置及功能情况向省级网信部门备案；未成年人用户数量巨大和对未成年人群体具有显著影响的网络平台服务提供者应当通过省级网信部门向国家网信部门备案，并提交未成年人模式建设和服务使用情况报告。网信部门对备案材料实施年度核验。\n国务院电信主管部门将移动智能终端未成年人模式纳入电信设备进网许可检测，会同国家网信部门制定移动智能终端未成年人模式电信设备进网许可检测项目。\n国家新闻出版部门牵头组织开展未成年人沉迷网络游戏防治工作。向未成年人提供网络游戏服务的，应当遵守《未成年人网络保护条例》和国家新闻出版部门关于网络游戏管理的有关规定。\n第十三条 教育部门应当指导、支持学校培育未成年人网络安全意识、文明素养、行为习惯和防护技能，依法规范管理未成年学生带入学校的智能终端产品，通过多种形式开展应用未成年人模式等未成年人网络保护宣传教育。\n第十四条 公安机关应当制止侵害未成年人的犯罪行为，依法打击涉及未成年人的网络暴力、传播淫秽物品、侵犯公民个人信息等犯罪活动。\n第十五条 共产主义青年团、妇女联合会、工会、残疾人联合会、关心下一代工作委员会、青年联合会、学生联合会、少年先锋队以及其他人民团体、有关社会组织、基层群众性自治组织等协同做好未成年人合理使用网络教育引导、未成年人模式推广、未成年人合法权益维护等工作。\n第十六条 学校应当加强对教师的指导和培训，提高教师对未成年学生沉迷网络的早期识别和干预能力，依法规范管理未成年学生带入学校的智能终端产品，指导其使用未成年人模式；对于有沉迷网络倾向的未成年学生，学校应当及时告知其监护人，共同对未成年学生合理使用网络进行教育和引导。\n第十七条 未成年人的监护人应当加强家庭家教家风建设，提高自身网络素养，规范自身使用网络的行为，加强对未成年人使用网络行为的教育、示范、引导和监督，协助开启并引导未成年人使用未成年人模式。\n第十八条 违反本规定第四条、第五条、第六条第一款、第七条第三款、第九条第一款、第十一条第一款规定的，由网信、新闻出版、电信、公安、文化和旅游、市场监督管理、广播电视等部门依据各自职责责令改正，给予警告，没收违法所得，违法所得100万元以上的，并处违法所得1倍以上10倍以下罚款，没有违法所得或者违法所得不足100万元的，并处10万元以上100万元以下罚款，对直接负责的主管人员和其他直接责任人员处1万元以上10万元以下罚款；拒不改正或者情节严重的，并可以责令暂停相关业务、停业整顿、关闭网站或者应用程序、吊销相关业务许可证或者吊销营业执照。\n第十九条 违反本规定第九条第二款规定的，由网信、新闻出版、电信、公安、文化和旅游、市场监督管理、广播电视等部门依据各自职责责令改正；拒不改正或者情节严重的，处5万元以上50万元以下罚款，对直接负责的主管人员和其他直接责任人员处1万元以上10万元以下罚款。\n第二十条 违反本规定第十条、第十二条第二款规定的，由网信部门责令改正，给予警告，可以并处10万元以上100万元以下罚款，对直接负责的主管人员和其他直接责任人员处1万元以上10万元以下罚款；拒不改正或者情节严重的，并可以责令暂停相关业务、停业整顿、关闭网站或者应用程序、吊销相关业务许可证或者吊销营业执照。\n第二十一条 违反本规定其他有关规定的，由有关主管部门依照《中华人民共和国未成年人保护法》、《中华人民共和国网络安全法》、《中华人民共和国个人信息保护法》、《未成年人网络保护条例》、《中华人民共和国电信条例》等法律、行政法规的规定处理、处罚。\n违反本规定，侵犯未成年人合法权益，造成人身、财产或者其他损害的，依法承担民事责任；构成违反治安管理行为的，依法给予治安管理处罚；构成犯罪的，依法追究刑事责任。\n第二十二条 学校违反本规定，不履行相应未成年人保护职责的，由教育部门按照职责责令改正；拒不改正或者情节严重的，对直接负责的主管人员和其他直接责任人员依法给予处分。\n第二十三条 未成年人的监护人不履行本规定的监护职责或者侵犯未成年人合法权益的，由未成年人居住地的居民委员会、村民委员会、妇女联合会，监护人所在单位，以及中小学校、幼儿园等有关密切接触未成年人的单位依法予以批评教育、劝诫制止、督促其接受家庭教育指导等。\n第二十四条 国家网信部门可以会同国务院有关部门根据保障未成年人健康安全使用网络的需要，对本规定第四条、第五条所列网络服务类型适时予以调整。\n鼓励通过未成年人模式向十六周岁以上的未成年人提供网络服务。\n第二十五条 本规定自2026年 月 日起施行。\n附：起草说明（官方附件二） 未成年人网络保护关系国家未来和民族希望，关系亿万家庭幸福安宁。为了加强未成年人网络保护，营造有利于未成年人身心健康的网络环境，保障未成年人合法权益，国家互联网信息办公室在深入开展立法调研、认真总结实践经验、广泛听取各方意见基础上，组织起草了《国务院关于保障未成年人健康安全使用网络的规定（征求意见稿）》（以下简称《规定（征求意见稿）》），并向社会公开征求意见。现将有关情况说明如下：\n一、制定的必要性\n一是 落实党中央决策部署的重要举措。党的十八大以来，以习近平同志为核心的党中央高度重视未成年人健康成长。习近平总书记强调，“为广大网民特别是青少年营造一个风清气正的网络空间”。“十五五”规划纲要提出，“加强未成年人网络保护，拓展网络育人空间和阵地”。制定《规定》是通过法规制度深化落实党中央决策部署、进一步保障未成年人健康安全使用网络的重要举措。\n二是 加强未成年人网络保护的迫切需求。近年来，我国修订制定《中华人民共和国未成年人保护法》、《未成年人网络保护条例》、《儿童个人信息网络保护规定》等，基本形成未成年人网络保护制度体系。随着互联网与人工智能、大数据等新技术加快融合，不断融入未成年人学习生活，网络沉迷、违法和不良信息传播等问题仍需持续治理。制定《规定》是进一步加强与未成年人有关网络服务管理，明确制度规则、严密保护体系的迫切需求。\n三是 顺应全球互联网治理趋势的必然要求。近年来特别是去年以来，国际社会普遍关注保障未成年人健康安全使用网络问题，开展系列相关立法，反映了全球互联网治理和加强未成年人网络保护的共性趋势。推出具有中国特色的未成年人网络保护“小快灵”立法，是契合当前全球互联网治理趋势、贡献中国智慧和中国方案的必然要求。\n二、制定思路\n制定《规定》遵循以下思路：\n一是 坚持党的领导。以习近平新时代中国特色社会主义思想为指导，贯彻落实党的二十大和二十届历次全会精神，深入落实习近平总书记关于未成年人网络保护的重要论述和党中央决策部署。\n二是 坚持问题导向。立足我国未成年人网络保护治理实践，针对未成年人使用网络过程中出现的新情况新问题，创新制度设计，衔接有关法律法规，增强制度系统性、针对性和实效性。\n三是 坚持协同共治。明确有关部门、网络服务提供者、智能终端产品制造者、应用程序分发平台服务提供者、群团组织、学校、监护人等各方主体在未成年人健康安全使用网络中的协同治理要求。\n四是 坚持守正创新。对现行未成年人网络保护法律法规规定中的成熟制度巩固深化，对当前未成年人使用网络产品和服务面临的突出问题设置精细化治理制度。\n三、起草过程\n起草过程中，国家互联网信息办公室会同有关部门主要开展了以下工作：\n一是 调研论证。调研了解平台未成年人网络保护实践、我国未成年人网络保护法律法规实施情况、智能终端产品和未成年人常用应用程序的未成年人模式建设等情况，对主要国家和地区未成年人网络保护相关立法动态进行深入研究论证。与相关单位充分会商，研提法规框架和制度建设重点。\n二是 组织起草。立足我国实际情况并结合全球未成年人网络保护趋势，提出了统筹发展和安全、分类施策的未成年人网络保护制度方案，明确规范向未成年人提供网络服务的范围、未成年人模式建设等主要制度，研究起草《规定（初稿）》。\n三是 充分征求意见。征求了中央和地方有关单位、平台企业和专家学者等的意见，结合各方面意见进一步修改完善并依法开展有关立法评估后，形成《规定（征求意见稿）》。\n四、主要内容\n《规定（征求意见稿）》共二十五条，主要规定了以下内容：\n（一）明确目的依据和基本原则。 提出加强未成年人网络保护、营造有利于未成年人身心健康的网络环境、保障未成年人合法权益等立法目的。明确网络服务提供者、智能终端产品制造者、应用程序分发平台服务提供者应当坚持最有利于未成年人的原则，充分考虑未成年人身心健康发展特点，按照本规定、国家有关规定和标准提供未成年人模式。\n（二）规范向未成年人提供网络服务。 明确网络服务提供者不得向未成年人提供陌生人网络社交服务、虚拟亲属和虚拟伴侣等虚拟亲密关系服务等，并规定了相关例外情形。提出网络服务提供者向未满十六周岁的未成年人提供网络音视频服务、网络直播发布服务以外的其他网络直播服务、网络游戏服务和网络社交服务等，应当通过未成年人模式提供。\n（三）规定未成年人用户识别和信息内容规范制度。 要求网络服务提供者具备未成年人用户识别能力，并采取必要措施保障未成年人个人信息安全；对经实名认证或者识别为未成年人用户的，网络服务提供者应当采取相应的措施。明确国家鼓励和支持制作、复制、发布、传播有利于未成年人健康成长的网络信息，要求网络服务提供者加强对用户发布信息的管理，规定网络服务提供者在未成年人模式下不得呈现危害或者可能影响未成年人身心健康的网络信息。明确网络服务提供者应当建立健全算法机制机理审核、信息内容管理等制度，不得设置诱导未成年人用户情感依赖、沉迷及过度消费等的算法模型。\n（四）明确未成年人模式建设要求。 要求智能终端产品制造者为智能终端产品设置未成年人模式联动、一键切换、退出核验、防绕过等功能，明确应用程序分发平台服务提供者应当落实安全管理责任。规定未成年人模式应当符合国家有关规定和标准，具备有效识别危害或者可能影响未成年人身心健康的网络信息、预防未成年人沉迷网络等功能。鼓励创新未成年人模式功能，加强专属内容池建设，丰富积极健康、向上向善的优质内容。明确提供未成年人模式的智能终端产品制造者和网络服务提供者应当将未成年人模式设置及功能情况向省级网信部门备案等。\n（五）明确协同共治要求和法律责任制度。 规定国家网信部门和国务院电信主管部门、国家新闻出版部门、教育部门、公安机关等的职责，明确共产主义青年团、妇女联合会、工会、残疾人联合会、关心下一代工作委员会、青年联合会、学生联合会、少年先锋队以及其他人民团体、有关社会组织、基层群众性自治组织等协同做好未成年人网络保护工作。规定了学校和未成年人监护人的义务。明确了法律责任、施行时间等。\n资料来源：国家互联网信息办公室（中国网信网）征求意见通知页（含草案全文与起草说明）。整理时间：2026-09-26。本页为官方草案文本的采集整理件，供研究参考，不构成法律意见；引用请以官方发布为准。相关的立法进程梳理与要点分析见立法动态条目 。\n","permalink":"https://ai.intlaws.com/compliance/china/minor-online-safety-regulation-draft-text/","summary":"《国务院关于保障未成年人健康安全使用网络的规定（征求意见稿）》官方全文：国家互联网信息办公室组织起草，2026 年 9 月 18 日发布并公开征求意见（反馈截止 2026 年 10 月 17 日）。草案共二十五条，不分章，施行日期留空；随通知附《起草说明》。本件尚未通过、尚未施行，不产生规范效力。","title":"国务院关于保障未成年人健康安全使用网络的规定（征求意见稿）"},{"content":" 版本与来源（可核验）\n项目 内容 通过与公布 《个人信息保护合规审计管理办法》经 2024 年 5 月 20 日国家互联网信息办公室 2024 年第 15 次室务会会议审议通过，国家互联网信息办公室令第 18 号公布 签署与发布日期 2025 年 2 月 12 日签署（国家互联网信息办公室主任庄荣文）；中国网信网 2025 年 2 月 14 日发布 施行日期 2025 年 5 月 1 日（第二十条） 现行有效 是（截至 2026-09-26） 体例 全文 20 条，不分章；附件《个人信息保护合规审计指引》共 27 项 中文原文来源 https://www.cac.gov.cn/2025-02/14/c_1741233507681519.htm 关联官方发布 《个人信息保护合规审计管理办法》答记者问 ；《个人信息保护合规审计管理办法》实施有关事项答记者问 （2025-05-27，见「数据治理—政策法规」栏目） 校对记录 2026-09-26 抓取官方页面；条标题自「第一条」起 1—20 连续、无缺号、无空条；文号、通过日期、签署日期、施行日期与官方文本逐字符复核 第一条 为了规范个人信息保护合规审计活动，保护个人信息权益，根据《中华人民共和国个人信息保护法》、《网络数据安全管理条例》等法律、行政法规，制定本办法。\n第二条 在中华人民共和国境内开展个人信息保护合规审计，适用本办法。\n本办法所称个人信息保护合规审计，是指对个人信息处理者的个人信息处理活动是否遵守法律、行政法规的情况进行审查和评价的监督活动。\n第三条 个人信息处理者自行开展个人信息保护合规审计的，应当由个人信息处理者内部机构或者委托专业机构定期对其处理个人信息遵守法律、行政法规的情况进行合规审计。\n第四条 处理超过1000万人个人信息的个人信息处理者，应当每两年至少开展一次个人信息保护合规审计。\n第五条 个人信息处理者有以下情形之一的，国家网信部门和其他履行个人信息保护职责的部门（以下统称为保护部门），可以要求个人信息处理者委托专业机构对个人信息处理活动进行合规审计：\n（一）发现个人信息处理活动存在严重影响个人权益或者严重缺乏安全措施等较大风险的；\n（二）个人信息处理活动可能侵害众多个人的权益的；\n（三）发生个人信息安全事件，导致100万人以上个人信息或者10万人以上敏感个人信息泄露、篡改、丢失、毁损的。\n对同一个人信息安全事件或者风险，不得重复要求个人信息处理者委托专业机构开展个人信息保护合规审计。\n第六条 个人信息处理者自行开展或者按照保护部门要求委托专业机构开展个人信息保护合规审计的，应当参照本办法附件《个人信息保护合规审计指引》。\n第七条 专业机构应当具备开展个人信息保护合规审计的能力，有与服务相适应的审计人员、场所、设施和资金等。\n鼓励相关专业机构通过认证。专业机构的认证按照《中华人民共和国认证认可条例》的有关规定执行。\n第八条 个人信息处理者按照保护部门要求开展个人信息保护合规审计的，应当为专业机构正常开展个人信息保护合规审计工作提供必要支持，并承担审计费用。\n第九条 个人信息处理者按照保护部门要求开展个人信息保护合规审计的，应当按照保护部门要求选定专业机构，在限定时间内完成个人信息保护合规审计；情况复杂的，报保护部门批准后，可以适当延长。\n第十条 个人信息处理者按照保护部门要求开展个人信息保护合规审计的，在完成合规审计后，应当将专业机构出具的个人信息保护合规审计报告报送保护部门。\n个人信息保护合规审计报告应当由专业机构主要负责人、合规审计负责人签字并加盖专业机构公章。\n第十一条 个人信息处理者按照保护部门要求开展个人信息保护合规审计的，应当按照保护部门要求对合规审计中发现的问题进行整改。在整改完成后15个工作日内，向保护部门报送整改情况报告。\n第十二条 处理100万人以上个人信息的个人信息处理者应当指定个人信息保护负责人，负责个人信息处理者的个人信息保护合规审计工作。\n提供重要互联网平台服务、用户数量巨大、业务类型复杂的个人信息处理者，应当成立主要由外部成员组成的独立机构对个人信息保护合规审计情况进行监督。\n第十三条 专业机构在从事个人信息保护合规审计活动时，应当遵守法律法规，诚信正直，公正客观地作出合规审计职业判断，对在履行个人信息保护合规审计职责中获得的个人信息、商业秘密、保密商务信息等应当依法予以保密，不得泄露或者非法向他人提供，在合规审计工作结束后及时删除相关信息。\n第十四条 专业机构不得转委托其他机构开展个人信息保护合规审计。\n第十五条 同一专业机构及其关联机构、同一合规审计负责人不得连续三次以上对同一审计对象开展个人信息保护合规审计。\n第十六条 保护部门对个人信息处理者开展个人信息保护合规审计情况进行监督检查。\n第十七条 任何组织、个人有权对个人信息保护合规审计中的违法活动向保护部门进行投诉、举报。收到投诉、举报的部门应当依法及时处理，并将处理结果告知投诉、举报人。\n第十八条 个人信息处理者、专业机构违反本办法规定的，依照《中华人民共和国个人信息保护法》、《网络数据安全管理条例》等法律法规的规定处理；构成犯罪的，依法追究刑事责任。\n第十九条 对国家机关和法律、法规授权的具有管理公共事务职能的组织的个人信息保护合规审计，不适用本办法。\n第二十条 本办法自2025年5月1日起施行。\n附件：个人信息保护合规审计指引 一、本指引根据《中华人民共和国个人信息保护法》、《网络数据安全管理条例》等法律、行政法规制定。\n二、对个人信息处理活动的合法性基础进行合规审计的，应当重点审查下列事项：\n（一）基于个人同意处理个人信息的，是否取得个人同意，该同意是否由个人在充分知情的前提下自愿、明确作出；\n（二）基于个人同意处理个人信息的，个人信息的处理目的、处理方式、处理的个人信息种类发生变更的，是否重新取得个人同意；\n（三）基于个人同意处理个人信息的，是否依照法律、行政法规取得个人单独同意或者书面同意；\n（四）处理个人信息未取得个人同意的，是否属于法律、行政法规规定不需要取得个人同意的情形。\n三、对个人信息处理规则进行合规审计的，应当重点审查下列事项：\n（一）是否真实、准确、完整地告知个人信息处理者的名称或者姓名和联系方式；\n（二）是否以清单等便于查看的形式列明所收集的个人信息及其处理方式和种类；\n（三）是否与处理目的直接相关，采取对个人权益影响最小的方式；\n（四）是否明确个人信息保存期限或者保存期限的确定方法、到期后的处理方式，以及确定保存期限为实现处理目的所必要的最短时间；\n（五）是否明确个人查阅、复制、转移、更正、补充、删除、限制处理个人信息以及注销账号、撤回同意的途径和方法。\n四、对个人信息处理者履行告知个人信息处理规则义务进行合规审计的，应当重点审查下列事项：\n（一）个人信息处理者在处理个人信息前，是否以显著方式、清晰易懂的语言真实、准确、完整地向个人告知个人信息处理规则；\n（二）告知文本的大小、字体和颜色是否便于个人完整阅读告知事项；\n（三）线下告知是否通过标注、说明等多种方式向个人履行告知义务；\n（四）在线告知是否提供文本信息或者通过适当方式向个人履行告知义务；\n（五）个人信息处理规则发生变更的，是否将变更内容及时告知个人；\n（六）处理个人信息不需要告知的，是否属于法律、行政法规规定应当保密或者不需要告知的情形。\n五、对个人信息处理者与其他个人信息处理者共同处理个人信息进行合规审计的，应当重点审查下列事项：\n（一）是否约定各自的权利义务；\n（二）个人信息权益保护机制；\n（三）个人信息安全事件报告机制；\n（四）其他法律、行政法规规定需要约定的权利和义务。\n六、对个人信息处理者委托处理个人信息进行合规审计的，应当重点审查下列事项：\n（一）个人信息处理者在委托处理个人信息前，是否开展个人信息保护影响评估；\n（二）个人信息处理者与受托人签订的合同，是否与受托人约定了委托处理的目的、期限、方式、个人信息的种类、保护措施以及双方的权利义务等；\n（三）个人信息处理者是否采取定期检查等方式，对受托人的个人信息处理活动进行监督。\n七、个人信息处理者存在因合并、重组、分立、解散、被宣告破产等原因需要转移个人信息情形的，应当重点审查个人信息处理者是否向个人告知接收方的名称或者姓名和联系方式。\n八、对个人信息处理者向其他个人信息处理者提供其处理的个人信息进行合规审计的，应当重点审查下列事项：\n（一）基于个人同意处理个人信息的，是否取得个人的单独同意；\n（二）是否向个人告知接收方的名称或者姓名、联系方式、处理目的、处理方式和个人信息的种类，法律、行政法规规定应当保密或者不需要告知的除外；\n（三）是否事前进行个人信息保护影响评估。\n九、对个人信息处理者利用自动化决策处理个人信息进行合规审计的，应当重点审查下列事项：\n（一）自动化决策的透明度，以及自动化决策的结果是否公平、公正；\n（二）是否事前告知个人自动化决策处理个人信息的种类及可能带来的影响；\n（三）是否事前进行个人信息保护影响评估；\n（四）是否向用户提供保障机制，以便个人通过便捷方式拒绝通过自动化决策方式作出对个人权益有重大影响的决定，并要求个人信息处理者就通过自动化决策方式作出对用户个人权益有重大影响的决定予以说明；\n（五）向个人进行信息推送、商业营销的，是否同时提供不针对个人特征的选项，或者提供便捷的拒绝自动化决策服务的方式；\n（六）是否采取了有效措施，防止自动化决策根据消费者的偏好、交易习惯等对个人在交易条件上实行不合理的差别待遇；\n（七）其他可能影响自动化决策的透明度和结果公平、公正的事项。\n十、对个人信息处理者基于个人同意公开个人信息进行合规审计的，应当重点审查下列事项：\n（一）个人信息处理者公开其处理的个人信息前是否取得个人单独同意，该授权是否真实、有效，是否存在违背个人意愿将个人信息予以公开的情况；\n（二）个人信息处理者公开个人信息前，是否进行个人信息保护影响评估。\n十一、个人信息处理者在公共场所安装图像收集、个人身份识别设备的，应当重点对其安装图像收集、个人信息身份识别设备的合法性及所收集个人信息的用途进行审查。审查内容包括但不限于：\n（一）是否为维护公共安全所必需，是否为商业目的处理所收集的个人信息；\n（二）是否设置了显著的提示标识；\n（三）个人信息处理者所收集的个人图像、身份识别信息用于维护公共安全以外用途的，是否取得个人单独同意。\n十二、对个人信息处理者处理已公开的个人信息进行合规审计的，应当重点审查个人信息处理者是否存在下列违法违规行为：\n（一）向已公开个人信息中的电子邮箱、手机号等发送与其公开目的无关的商业信息；\n（二）利用已公开的个人信息从事网络暴力、传播网络谣言和虚假信息等活动；\n（三）处理个人明确拒绝处理的已公开个人信息；\n（四）对个人权益有重大影响，未取得个人同意；\n（五）收集、留存或处理已公开个人信息的规模、时间或使用目的超出合理范围。\n十三、对个人信息处理者处理敏感个人信息进行合规审计的，应当重点审查下列事项：\n（一）基于个人同意处理个人信息的，处理生物识别、宗教信仰、特定身份、医疗健康、金融账户、行踪轨迹等敏感个人信息，是否事前取得个人的单独同意；\n（二）基于个人同意处理个人信息的，处理不满十四周岁未成年人的个人信息，是否事前取得未成年人的父母或者其他监护人的同意；\n（三）处理敏感个人信息的目的、方式、范围是否合法、正当、必要；\n（四）是否在事前进行个人信息保护影响评估；\n（五）是否向个人告知处理敏感个人信息的必要性以及对个人权益的影响，法律、行政法规规定应当保密或者不需要告知的除外；\n（六）法律、行政法规规定应当取得书面同意的，是否取得书面同意；\n（七）是否遵守法律、行政法规对处理敏感个人信息的限制性规定。\n十四、对个人信息处理者处理不满十四周岁未成年人个人信息进行合规审计的，应当重点审查下列事项：\n（一）是否制定专门的个人信息处理规则；\n（二）是否向未成年人及其监护人告知未成年人个人信息的处理目的、处理方式、处理必要性，以及处理个人信息的种类、所采取的保护措施等，法律、行政法规规定不需要告知的除外；\n（三）基于个人同意处理个人信息，是否存在强制要求未成年人或者其监护人同意处理非必要个人信息的行为。\n十五、对个人信息处理者向境外提供个人信息进行合规审计的，应当重点审查下列事项：\n（一）关键信息基础设施运营者向境外提供个人信息是否经过国家网信部门组织的安全评估，法律、行政法规、国家网信部门另有规定的，从其规定；\n（二）关键信息基础设施运营者以外的数据处理者自当年1月1日起累计向境外提供100万人以上个人信息（不含敏感个人信息）或者1万人以上敏感个人信息是否经过国家网信部门组织的安全评估，法律、行政法规、国家网信部门另有规定的，从其规定；\n（三）关键信息基础设施运营者以外的数据处理者自当年1月1日起累计向境外提供10万人以上、不满100万人个人信息（不含敏感个人信息）或者不满1万人敏感个人信息的，是否按照国家网信部门的规定，经个人信息保护认证或者按照国家网信部门制定的标准合同与境外接收方签订合同并向所在地省级网信部门备案，或者符合法律、行政法规、国家网信部门规定的其他条件；\n（四）存在向外国司法或者执法机构提供存储于中华人民共和国境内个人信息情形的，是否经过中华人民共和国主管机关批准；\n（五）是否向被列入限制或者禁止个人信息提供清单的组织和个人提供个人信息。\n十六、对个人信息删除权保障情况进行合规审计的，应当重点审查下列事项：\n（一）个人信息处理目的是否已实现、无法实现或者为实现处理目的不再必要；\n（二）个人信息处理者是否停止提供产品或者服务，或者个人是否已注销账号；\n（三）保存期限是否已届满；\n（四）个人是否撤回同意；\n（五）个人信息处理者是否违反法律、行政法规或者违反约定处理个人信息；\n（六）应当删除个人信息，但法律、行政法规规定的保存期限未届满，或者删除个人信息从技术上难以实现的，个人信息处理者是否停止除存储和采取必要的安全措施之外的处理。\n十七、对个人信息处理者保障个人在个人信息处理活动中的权利情况进行合规审计的，应当重点审查下列事项：\n（一）是否建立便捷的个人行使权利的申请受理机制和处理机制；\n（二）是否及时响应个人行使权利的申请，是否及时、完整、准确告知处理意见或者执行结果；\n（三）拒绝个人行使权利请求的，是否向个人说明理由。\n十八、个人信息处理者应当响应个人申请，对其个人信息处理规则进行解释说明，合规审计时应当重点对下列内容进行评价：\n（一）个人信息处理者是否提供便捷的方式和途径，接受、处理个人关于个人信息处理规则解释说明的要求；\n（二）接到个人的要求后，个人信息处理者是否在合理的时间内，使用通俗易懂的语言对其个人信息处理规则作出解释说明。\n十九、个人信息处理者应当依照法律、行政法规的规定制定内部管理制度和操作规程，明确组织架构、岗位职责，建立工作流程、完善内控制度，保障个人信息处理合规与安全。合规审计时，应当重点对个人信息处理者个人信息保护内部管理制度和操作规程进行审查，包括但不限于：\n（一）个人信息保护工作的方针、目标、原则是否符合法律、行政法规规定；\n（二）个人信息保护组织架构、人员配备、行为规范、管理责任是否与应当履行的个人信息保护责任相适应；\n（三）是否根据个人信息的种类、来源、敏感程度、用途等，对个人信息进行分类；\n（四）是否建立个人信息安全事件应急响应机制；\n（五）是否建立个人信息保护影响评估制度、合规审计制度；\n（六）是否建立畅通的个人信息保护投诉举报受理流程；\n（七）是否合理制定个人信息处理操作权限；\n（八）是否制定实施个人信息保护安全教育和培训计划；\n（九）是否建立个人信息保护负责人及相关人员履职评价制度；\n（十）是否建立个人信息违法处理责任制度；\n（十一）法律、行政法规规定的其他事项。\n二十、个人信息处理者应当采取与所处理个人信息规模、类型相适应的安全技术措施，并对个人信息处理者采取的技术措施的有效性进行评价，评价内容包括但不限于：\n（一）是否采取相应安全技术措施实现个人信息的保密性、完整性、可用性；\n（二）是否采取加密、去标识化等安全技术措施，确保在不借助额外信息的情况下，消除或者降低个人信息的可识别性；\n（三）采取的安全技术措施能否合理确定有关人员查阅、复制、传输个人信息等的操作权限，减少个人信息在处理过程中未经授权的访问和滥用风险。\n二十一、对个人信息处理者教育培训计划的制定和实施情况进行合规审计时，应当重点对下列事项进行评价：\n（一）是否按计划对管理人员、技术人员、操作人员、全员开展相应的安全教育和培训，是否对相应人员的个人信息保护意识和技能进行考核；\n（二）培训内容、方式、对象、频率等能否满足个人信息保护需要。\n二十二、对个人信息处理者指定的个人信息保护负责人履职情况进行合规审计的，应当重点审查下列事项：\n（一）个人信息保护负责人是否具有相关的工作经历和专业知识，熟悉个人信息保护相关法律、行政法规；\n（二）个人信息保护负责人是否具有明确清晰的职责，是否被赋予充分的权限协调个人信息处理者内部相关部门与人员；\n（三）个人信息保护负责人在个人信息处理重大事项决策前是否有权提出相关意见和建议；\n（四）个人信息保护负责人是否有权对个人信息处理者内部个人信息处理的不合规操作进行制止和采取必要的纠正措施；\n（五）个人信息处理者是否公开个人信息保护负责人的联系方式，并将个人信息保护负责人的姓名、联系方式等报送保护部门。\n二十三、对个人信息处理者开展个人信息保护影响评估情况进行合规审计时，应当重点对影响评估开展情况和评估内容进行审查：\n（一）是否依照法律、行政法规的规定，在进行对个人权益具有重大影响的个人信息处理活动前进行个人信息保护影响评估；\n（二）是否对个人信息的处理目的、处理方式等进行合法、正当、必要评估；\n（三）是否对个人权益的影响及安全风险进行评估；\n（四）是否对所采取的保护措施的合法性、有效性，以及与风险程度的适应性进行评估。\n二十四、个人信息处理者应当制定个人信息安全事件应急预案。合规审计时，应当对应急预案的全面性、有效性、可执行性作出评价，包括但不限于下列内容：\n（一）是否结合业务实际，对面临的个人信息安全风险作出系统评估和预测；\n（二）总体要求、基本策略，组织机构、人员，技术、物资保障，指挥处置程序，应急和支持措施等是否足以应对预测的风险；\n（三）是否对相关人员进行应急预案培训，定期对应急预案进行演练。\n二十五、对个人信息处理者个人信息安全事件应急响应处置情况进行合规审计的，应当重点审查下列事项：\n（一）是否按照应急预案、操作规程及时查明个人信息安全事件的影响、范围和可能造成的危害，分析、确定事件发生的原因，提出防止危害扩大的措施方案；\n（二）是否建立通报渠道，在安全事件发生后按照相关规定及时通知保护部门和个人；\n（三）是否采取相应措施将个人信息安全事件可能造成的损失和可能产生的危害风险降低到最小。\n二十六、对提供重要互联网平台服务、用户数量巨大、业务类型复杂的个人信息处理者制定的平台规则进行合规审计的，应当重点审查下列事项：\n（一）平台规则是否与法律、行政法规相抵触；\n（二）平台规则个人信息保护条款的有效性，是否合理界定了平台、平台内产品或者服务提供者的个人信息保护权利和义务；\n（三）平台规则的执行情况，是否通过抽样等方式验证平台规则被有效执行。\n二十七、对提供重要互联网平台服务、用户数量巨大、业务类型复杂的个人信息处理者发布的个人信息保护社会责任报告进行合规审计的，应当重点审查社会责任报告披露下列内容的情况：\n（一）个人信息保护组织架构和内部管理情况；\n（二）个人信息保护能力建设情况；\n（三）个人信息保护措施和成效；\n（四）个人行使权利的申请受理情况；\n（五）独立监督机构履职情况；\n（六）重大个人信息安全事件处理情况；\n（七）促进个人信息保护社会共治的科普宣传、公益活动情况；\n（八）法律、行政法规规定的其他事项。\n材料来源：国家互联网信息办公室（中国网信网）官方全文页（2025-02-14 发布）。生效日：2025 年 5 月 1 日（第二十条）。本页为法规全文档案，供研究参考，不构成法律意见。\n站内关联 中华人民共和国个人信息保护法 网络数据安全管理条例 数据出境安全评估办法 个人信息保护认证实施规则 ","permalink":"https://ai.intlaws.com/compliance/china/personal-information-compliance-audit-measures/","summary":"《个人信息保护合规审计管理办法》官方文本：国家互联网信息办公室令第 18 号，2024 年 5 月 20 日国家互联网信息办公室 2024 年第 15 次室务会会议审议通过，2025 年 2 月 12 日签署公布，自 2025 年 5 月 1 日起施行；全文 20 条，附件《个人信息保护合规审计指引》27 项，规定自行审计与保护部门要求审计两种情形、处理超过 1000 万人个人信息的处理者每两年至少审计一次、专业机构回避与不得转委托等规则。","title":"个人信息保护合规审计管理办法"},{"content":" 来源与核验（可核验）\n项目 内容 文书名称 《国务院关于保障未成年人健康安全使用网络的规定（征求意见稿）》 文书性质 行政法规草案（由国务院制定；现处于公开征求意见阶段，尚未审议通过、尚未公布） 文号 [无文号]（草案阶段不编令号；正式公布时以国务院令形式发布） 起草主体 国家互联网信息办公室组织起草 征求意见通告日 2026 年 9 月 18 日（中国网信网 2026-09-18 17:00 发布） 意见反馈截止 2026 年 10 月 17 日 现行状态 征求意见中（截至 2026-09-26），不产生规范效力 体例 草案正文 二十五条，不分章；随通知附《起草说明》 施行日期 第二十五条作「本规定自 2026 年 月 日起施行」——留空未定 官方来源 通知、草案全文、起草说明：https://www.cac.gov.cn/2026-09/18/c_1791482017777471.htm ；栏目归属确认：「网信发布」列表页 校对记录 2026-09-26 抓取国家网信办页面；条号自「第一条」起 1—25 连续、无缺号、无重号、无空条；无章级标题；通告日期、反馈截止日期逐字符复核 一、这是一件什么规格的文件 《国务院关于保障未成年人健康安全使用网络的规定（征求意见稿）》（以下称《规定（征求意见稿）》）拟以行政法规形式，在《中华人民共和国未成年人保护法》《未成年人网络保护条例》以及《儿童个人信息网络保护规定》等既有制度之上，就未成年人「健康安全使用网络」作统一规范。依据草案第一条，其上位法为《未成年人保护法》《中华人民共和国网络安全法》《中华人民共和国个人信息保护法》。\n草案共 二十五条，不分章，覆盖总则性条款、服务禁限与未成年人模式、用户识别与信息内容规范、智能终端与应用程序分发平台、协同共治与法律责任五个板块。施行日期留空（第二十五条作「本规定自 2026 年 月 日起施行」），表明该件尚处意见征集阶段。\n适用范围（第二条）：在中国境内向未成年人提供网络服务、研发制造智能终端产品、通过应用程序分发平台为智能终端用户提供应用程序的活动。\n二、与数据、人工智能直接相关的条款要点 主题 要点 条文 未成年人模式的一般要求 网络服务提供者、智能终端产品制造者、应用程序分发平台服务提供者应坚持最有利于未成年人原则，充分考虑未成年人身心健康发展特点，按照本规定、国家有关规定和标准提供未成年人模式 第三条 禁向未成年人提供的服务 陌生人网络社交服务、虚拟亲属与虚拟伴侣等虚拟亲密关系服务、诱导沉迷等危害或可能严重影响身心健康的服务；未满十六周岁不提供网络直播发布服务等 第四条 应以未成年人模式提供的服务 面向未满十六周岁未成年人的网络音视频、网络游戏、网络社交等服务，以及可能影响未成年人认知的人工智能服务 第五条第一款第三项等 用户识别与个人信息安全 应具备未成年人用户识别能力，可综合运用法定身份证件、国家网络身份认证公共服务、分布式数字身份认证公共服务、非存储式一次性人脸核验、行为特征识别等方式提升识别精准度，并采取必要措施保障未成年人个人信息安全；未成年人办理电话卡由法定代理人代办，电信业务经营者依法登记真实身份信息 第六条 算法与内部制度 应建立健全算法机制机理审核、科技伦理审查、信息内容管理、网络和数据安全管理等制度，配备与规模相适应的内容管理技术措施和人员；不得设置诱导未成年人情感依赖、沉迷以及过度消费的算法模型 第八条 未成年人模式功能 应具备有效识别危害或可能影响身心健康的网络信息、保护未成年人个人信息权益、预防沉迷、便于监护人履职等功能；鼓励加强专属内容池建设 第十一条 备案机制 国家网信部门建立未成年人模式备案机制：智能终端产品制造者与网络服务提供者向省级网信部门备案；未成年人用户数量巨大、对未成年人群体具有显著影响的平台服务提供者通过省级网信部门向国家网信部门备案，并提交建设与服务使用情况报告；网信部门实施年度核验 第十二条 涉个人信息犯罪打击 公安机关依法打击涉及未成年人的网络暴力、传播淫秽物品、侵犯公民个人信息等犯罪活动 第十四条 法律责任 违反第四条、第五条、第六条第一款、第七条第三款、第九条第一款、第十一条第一款的：责令改正、警告、没收违法所得并处罚款（违法所得 100 万元以上按 1—10 倍，无违法所得或不足 100 万元处 10 万—100 万元，直接负责的主管人员与其他直接责任人员处 1 万—10 万元）等 第十八条至第二十条 三、生效日与合规义务适用日分写 文件生效日：未定。草案第二十五条将施行日期留空，现阶段该件不产生规范效力，不得作为执法依据或合规义务依据。 合规义务适用日：自正式公布并施行之日起，相关主体才产生未成年人模式提供、用户识别、备案、算法模型限制等义务。本次意见征集期（2026-09-18 至 2026-10-17）不属于合规义务期。 易混点：草案第六条列举的识别方式中包含「非存储式一次性人脸核验」，属身份识别技术路径的列举，并非授权无限制采集人脸信息；该条同时要求「采取必要措施保障未成年人个人信息安全」。不满十四周岁未成年人的个人信息依《个人信息保护法》属敏感个人信息，处理需取得监护人同意等规则继续适用，不得以本条作为豁免依据。 四、尚未确定的事项 文号、通过日期、施行日期：草案阶段无令号，施行日期留空；待正式公布后补录（正式公布时以国务院令形式发布）。 附件版本：官方以网页内嵌方式提供草案文本与起草说明，本页未另抓独立附件文件；如官方后续发布附件版本，需补存留档。 与现行条例的衔接：草案与《未成年人网络保护条例》《儿童个人信息网络保护规定》在未成年人模式备案、专门个人信息处理规则方面的衔接关系未见明文，本页不作结论。 全文已另页收录：草案全文（二十五条）与官方附件二《起草说明》见《国务院关于保障未成年人健康安全使用网络的规定（征求意见稿）》全文页 ；正式公布后按正式文本校订。本页保留为立法进程与要点分析。 资料来源：国家互联网信息办公室（中国网信网）征求意见通知页（含草案全文与起草说明）。整理时间：2026-09-26。本页供研究参考，不构成法律意见。\n","permalink":"https://ai.intlaws.com/legislation/minor-online-safety-regulation-draft/","summary":"国家互联网信息办公室于 2026 年 9 月 18 日就《国务院关于保障未成年人健康安全使用网络的规定（征求意见稿）》公开征求意见，意见反馈截止 2026 年 10 月 17 日。草案共二十五条，不分章，施行日期留空未定；与数据、人工智能直接相关的条款包括：应将可能影响未成年人认知的人工智能服务纳入未成年人模式、未成年人用户识别能力与个人信息安全保障、不得设置诱导情感依赖与沉迷的算法模型、未成年人模式备案机制等。","title":"《国务院关于保障未成年人健康安全使用网络的规定（征求意见稿）》公开征求意见（意见反馈截止 2026 年 10 月 17 日）"},{"content":" 案情、说理与裁判结果取自最高人民法院 2026 年 9 月 9 日《2026年人民法院反不正当竞争典型案例》发布文本（该批共 9 件，本案为案例六），以直接引述或紧贴原文的归纳为限，不作超出原文的推论。\n案件名称与案号 某科技公司与某软件公司等侵害商标权及不正当竞争纠纷案\n——利用AI虚构他人产品测评文章搭车引流构成不正当竞争\n一审 江苏省无锡市新吴区人民法院 ｜ 案号 （2024）苏0214民初9489号 ｜ 发布：最高人民法院《2026年人民法院反不正当竞争典型案例》（2026-09-09 发布）案例六\n关键词 民事 / 不正当竞争 / 人工智能生成内容 / 搜索引擎自然检索 / 数据污染 / 反不正当竞争法一般条款 / 诚实信用原则\n基本案情 某科技公司主营销售进销存软件产品等业务；某软件公司为同业经营者。\n某软件公司以「进销存」为词根，利用 AI 批量生成文章标题，再交由 AI 自动生成相应文章，文章内容均为对某科技公司进销存软件的介绍和点评。某软件公司在自有网站发布上述文章，并在文章前后位置设置了指向其自有进销存软件产品的链接。\n某科技公司认为某软件公司的上述行为构成不正当竞争，遂诉至法院。\n法院审理与说理 一审（江苏省无锡市新吴区人民法院） 经审理认为：\n某软件公司利用人工智能等工具批量生成大量针对他人「进销存」软件的介绍、点评文章，并将其中含有「某进销存软件」字样的多篇文章发布至其官网，目的是利用搜索引擎的自然检索规则，使其官网发布的多篇涉案文章可以被检索并呈现至相关公众的检索结果中，以吸引相关公众点击文章中设置的其自有产品链接，实现引流目的。\n该行为产生三重后果：\n降低了某科技公司的用户流量和交易机会； 在网络中制造了大量垃圾信息，造成数据污染； 扰乱了竞争秩序。 据此，一审法院认定该行为构成不正当竞争，遂判令某软件公司赔偿某科技公司相应经济损失，该一审判决已生效。\n裁判结果 一审：江苏省无锡市新吴区人民法院（案号 （2024）苏0214民初9489号）判令某软件公司赔偿某科技公司相应经济损失；官方发布文本载「该一审判决已生效」。 裁判日期与赔偿数额：官方发布文本未载明。 数据法 / AI 法要点 生成式工具批量生产内容的竞争法后果：以 AI 批量生成针对他人产品的介绍、点评文章，并搭载自身产品链接引流，被认定为不当截取他人交易机会的不正当竞争行为，适用反不正当竞争法一般条款规制——「利用 AI 技术批量生成、发布虚构测评文章，搭载自身产品或服务进行引流」有违诚实信用原则和商业道德。 「数据污染」进入裁判说理：判决将「在网络中制造大量垃圾信息，造成数据污染，扰乱了竞争秩序」作为认定违法的理由之一。这是从搜索引擎生态与信息质量角度对劣质合成内容外部性的否定性评价，可作为 AIGC 内容治理、SEO 滥用类合规风险的裁判样本。 对检索排序的「投喂」被认定为引流手段：判决直指行为目的在于「利用搜索引擎的自然检索规则」，使批量生成的页面进入检索结果以获取曝光，提示以合成内容影响检索呈现的行为可能同时承受竞争法与内容治理层面的评价。 本件不涉及个人信息处理：争点为竞争秩序，未涉及个人信息保护、数据要素权属、数据出境等议题；援引时不宜作扩张解释。 相关法条 《中华人民共和国反不正当竞争法》一般条款（诚实信用原则与商业道德）——官方发布文本表述为「适用反不正当竞争法一般条款」认定构成不正当竞争，未列具体条文序号。 具体所引条文序号官方文本未逐条列举，本页不代官方补写。 权威来源 最高人民法院《2026年人民法院反不正当竞争典型案例》发布文本（2026-09-09） 组级发布口径：最高人民法院官网「典型案例发布」栏目 材料来源：最高人民法院 2026 年 9 月 9 日《2026年人民法院反不正当竞争典型案例》发布文本（案例六），该批共 9 件（案例一至案例九，序号连续）。\n官方文本未载明事项 裁判日期：官方发布文本未载明一审裁判日期；最高人民法院官网发布页所载全文为本案唯一官方文本，中国裁判文书网未检索到本案判决书全文。本页不推测补写。 赔偿数额与生效方式：官方表述为「赔偿某科技公司相应经济损失」，未列具体金额；官方文本仅载一审并「已生效」，未述上诉情况。 当事人名称以官方发布文本表述为准（「某科技公司」「某软件公司」），不作还原。 同批其余 8 件（案例一至案例五、案例七至案例九）本批次暂未收录；其中案例三（恶意「转码重构」妨碍网络产品正常运行）、案例五（抢单「物理外挂」）、案例七（篡改同行直播带货视频构成虚假宣传）涉网络技术，如需另出件。 收录口径：本站案例栏目以涉数据、个人信息与人工智能为收录口径；本案属涉人工智能与数据竞争秩序类，非个人信息处理纠纷，特此说明。 站内关联法规 个人信息保护法 人工智能生成合成内容标识办法 ","permalink":"https://ai.intlaws.com/cases/china/wxai-ai-generated-reviews-unfair-competition/","summary":"\u003cblockquote\u003e\n\u003cp\u003e案情、说理与裁判结果取自最高人民法院 2026 年 9 月 9 日《2026年人民法院反不正当竞争典型案例》发布文本（该批共 9 件，本案为案例六），以直接引述或紧贴原文的归纳为限，不作超出原文的推论。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e某科技公司与某软件公司等侵害商标权及不正当竞争纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——利用AI虚构他人产品测评文章搭车引流构成不正当竞争\u003c/p\u003e\n\u003cp\u003e一审 江苏省无锡市新吴区人民法院 ｜ 案号 \u003cstrong\u003e（2024）苏0214民初9489号\u003c/strong\u003e ｜ \u003cstrong\u003e发布\u003c/strong\u003e：最高人民法院《2026年人民法院反不正当竞争典型案例》（2026-09-09 发布）案例六\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 不正当竞争 / 人工智能生成内容 / 搜索引擎自然检索 / 数据污染 / 反不正当竞争法一般条款 / 诚实信用原则\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e某科技公司主营销售\u003cstrong\u003e进销存软件产品\u003c/strong\u003e等业务；某软件公司为\u003cstrong\u003e同业经营者\u003c/strong\u003e。\u003c/p\u003e\n\u003cp\u003e某软件公司以「进销存」为词根，\u003cstrong\u003e利用 AI 批量生成文章标题，再交由 AI 自动生成相应文章\u003c/strong\u003e，文章内容均为对某科技公司进销存软件的介绍和点评。某软件公司在\u003cstrong\u003e自有网站\u003c/strong\u003e发布上述文章，并在文章前后位置\u003cstrong\u003e设置了指向其自有进销存软件产品的链接\u003c/strong\u003e。\u003c/p\u003e\n\u003cp\u003e某科技公司认为某软件公司的上述行为构成不正当竞争，遂诉至法院。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e一审（江苏省无锡市新吴区人民法院）\u003c/strong\u003e 经审理认为：\u003c/p\u003e\n\u003cp\u003e某软件公司利用人工智能等工具批量生成大量针对他人「进销存」软件的介绍、点评文章，并将其中含有「某进销存软件」字样的多篇文章发布至其官网，\u003cstrong\u003e目的是利用搜索引擎的自然检索规则\u003c/strong\u003e，使其官网发布的多篇涉案文章可以被检索并呈现至相关公众的检索结果中，以吸引相关公众点击文章中设置的其自有产品链接，\u003cstrong\u003e实现引流目的\u003c/strong\u003e。\u003c/p\u003e\n\u003cp\u003e该行为产生三重后果：\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003e降低了某科技公司的用户流量和交易机会\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e在网络中制造了大量垃圾信息，造成数据污染\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e扰乱了竞争秩序\u003c/strong\u003e。\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003e据此，一审法院认定该行为\u003cstrong\u003e构成不正当竞争\u003c/strong\u003e，遂判令某软件公司赔偿某科技公司相应经济损失，\u003cstrong\u003e该一审判决已生效\u003c/strong\u003e。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e一审：江苏省无锡市新吴区人民法院（案号 \u003cstrong\u003e（2024）苏0214民初9489号\u003c/strong\u003e）判令某软件公司赔偿某科技公司\u003cstrong\u003e相应经济损失\u003c/strong\u003e；官方发布文本载「该一审判决已生效」。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e裁判日期与赔偿数额\u003c/strong\u003e：官方发布文本未载明。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003e生成式工具批量生产内容的竞争法后果\u003c/strong\u003e：以 AI 批量生成针对他人产品的介绍、点评文章，并搭载自身产品链接引流，被认定为\u003cstrong\u003e不当截取他人交易机会\u003c/strong\u003e的不正当竞争行为，适用反不正当竞争法\u003cstrong\u003e一般条款\u003c/strong\u003e规制——「利用 AI 技术批量生成、发布虚构测评文章，搭载自身产品或服务进行引流」有违诚实信用原则和商业道德。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e「数据污染」进入裁判说理\u003c/strong\u003e：判决将「在网络中制造大量垃圾信息，\u003cstrong\u003e造成数据污染\u003c/strong\u003e，扰乱了竞争秩序」作为认定违法的理由之一。这是从搜索引擎生态与信息质量角度对劣质合成内容外部性的否定性评价，可作为 AIGC 内容治理、SEO 滥用类合规风险的裁判样本。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e对检索排序的「投喂」被认定为引流手段\u003c/strong\u003e：判决直指行为目的在于「利用搜索引擎的自然检索规则」，使批量生成的页面进入检索结果以获取曝光，提示以合成内容影响检索呈现的行为可能同时承受竞争法与内容治理层面的评价。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e本件不涉及个人信息处理\u003c/strong\u003e：争点为竞争秩序，\u003cstrong\u003e未涉及个人信息保护、数据要素权属、数据出境\u003c/strong\u003e等议题；援引时不宜作扩张解释。\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e《中华人民共和国反不正当竞争法》\u003cstrong\u003e一般条款\u003c/strong\u003e（诚实信用原则与商业道德）——官方发布文本表述为「适用反不正当竞争法一般条款」认定构成不正当竞争，未列具体条文序号。\u003c/li\u003e\n\u003cli\u003e具体所引条文序号官方文本未逐条列举，本页不代官方补写。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/511301.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院《2026年人民法院反不正当竞争典型案例》发布文本（2026-09-09）\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e组级发布口径：\u003ca href=\"https://www.court.gov.cn/zixun/gengduo/104.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院官网「典型案例发布」栏目\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：最高人民法院 2026 年 9 月 9 日《2026年人民法院反不正当竞争典型案例》发布文本（案例六），该批共 9 件（案例一至案例九，序号连续）。\u003c/p\u003e","title":"最高法反不正当竞争典型案例：利用AI批量生成他人产品测评文章搭车引流构成不正当竞争（某科技公司与某软件公司等）"},{"content":"案件名称与案号 淘宝（中国）软件有限公司诉安徽美景信息科技有限公司不正当竞争纠纷案（业内通称「生意参谋」数据产品案）\n一审 杭州铁路运输法院，（2017）浙8601民初4034号：2017-12-06 立案，2018-06-15 依淘宝公司申请作出禁止被诉侵权行为的行为保全裁定，2018-08-16 判决\n二审 浙江省杭州市中级人民法院，（2018）浙01民终7312号：2018-12-18 判决，驳回上诉，维持原判，为终审判决\n专题归属：在先经典（2021 年前）。该案裁判时数据领域专门立法（《数据安全法》《个人信息保护法》）尚未施行。\n入选：据法院发布文本，本案被《人民法院报》评为 2018 年度人民法院十大民事行政案件，并入选「2018 年中国法院 50 件典型知识产权案例」；为《杭州法院司法保障数字经济十大案例》案例一，被称为首例涉数据资源开发应用与权属判定的新类型案件。\n程序事实（据一审判决书）：一审审理中，美景公司提出管辖权异议，2018-03-29 被裁定驳回，其上诉后经杭州市中级人民法院 2018-05-29 裁定驳回上诉、维持原裁定；2018-01-10 淘宝公司申请追加谢松林为共同被告并获准许，2018-08-07 申请撤回对其起诉并获准许；2018-07-20 公开开庭审理。\n关键词 民事 / 不正当竞争 / 数据产品 / 衍生数据 / 竞争性财产权益 / 三重授权 / 行为保全 / 技术中立\n基本案情 原告主张：淘宝（中国）软件有限公司（下称淘宝公司）系阿里巴巴卖家端「生意参谋」零售电商数据产品的开发者和运营者。「生意参谋」数据产品是在用户浏览、搜索、收藏、加购、交易等行为痕迹所产生的原始数据基础上，经过深度分析处理、整合加工而形成的预测型、指数型、统计型衍生数据，呈现形式为行业大盘趋势图、商品店铺榜、搜索词分析、买卖家人群画像等板块的排行数据与指数。淘宝公司认为，涉案数据产品中的原始数据与衍生数据均系其无形资产，其享有财产所有权及竞争性财产权益；美景公司的被诉行为已实质性替代涉案数据产品，构成不正当竞争，诉请判令美景公司立即停止侵权，并赔偿经济损失及合理费用 500 万元。\n被诉行为：安徽美景信息科技有限公司（下称美景公司）以提供远程登录「生意参谋」数据产品淘宝用户电脑的技术服务为招揽，通过组织、帮助他人利用已订购「生意参谋」服务的淘宝用户所提供的子账户获取「生意参谋」数据产品中的数据内容，从中牟取商业利益（据一审判决书所载被诉行为）。另据《法制日报》（中国新闻网转载，2019-01-22）报道，美景公司开发和运营「咕咕互助平台」软件及「咕咕生意参谋众筹」网站，教唆、引诱已订购「生意参谋」产品的用户下载该软件、共享子账户并从中牟利。\n查明事实要点（据一审判决书）：经公证保全，涉案网站「生意参谋租用」栏目的租用客户数升至 13226 户、类目 58 个、子账户 245 个；2018-06-15 一审法院作出禁止被诉侵权行为裁定后，涉案网站与「咕咕互助平台」已暂停运营；淘宝公司为本案维权支出公证费 6900 元。\n法院审理与说理 一、一审说理（杭州铁路运输法院，据一审判决书全文） 一审确定的争议焦点为四项：①淘宝公司收集并使用网络用户信息的行为是否正当；②淘宝公司对「生意参谋」数据产品是否享有法定权益；③被诉行为是否构成不正当竞争；④本案民事责任的确定。\n关于争议焦点①（信息收集使用的正当性）：信息是数据的内容，数据是信息的形式；涉案数据产品的数据内容虽来源于原始数据，但原始数据只是网络用户行为痕迹信息外化为数字、符号、文字、图像等方式的表现形式。一审从规则公开（淘宝公司已向用户公开涉及个人信息、非个人信息收集规定的法律声明及隐私权政策）、取得同意（用户注册账号时通过服务协议、法律声明及隐私权政策的形式取得授权许可）、合法正当性（经授权后收集使用的原始数据均来自用户主动提供或平台自动获取的活动痕迹，不存在非法渠道获取信息）、行为必要性（目的在于通过大数据分析为用户经营活动提供参谋服务，使用目的、方式和范围符合法律规定）四个方面认定淘宝公司收集、使用网络用户信息以及数据产品公开使用网络用户信息的行为符合法律规定，具有正当性。 关于天猫网用户信息的「三重授权」规则：作为第三方的淘宝公司使用天猫网用户信息，受「用户授权网络运营者＋网络运营者授权第三方＋用户授权第三方」的三重授权许可使用规则限制；经审查天猫网《隐私权政策》已明确用户个人信息可能与其关联公司共享，且天猫网商户及会员统一使用淘宝网账户并在注册时同意相关协议与政策，故可认定淘宝公司已获得用户信息提供者的同意。 关于争议焦点②（数据产品的法定权益）：涉案数据产品所提供的数据内容不再是原始网络数据，而是在巨量原始网络数据基础上通过一定算法，经过深度分析过滤、提炼整合以及匿名化脱敏处理后形成的预测型、指数型、统计型的衍生数据，其呈现方式为趋势图、排行榜、占比图等图形，已成为网络大数据产品。一审认为，该数据产品是淘宝公司的劳动成果，其数据内容中所包含的原始数据与衍生数据均系淘宝公司的无形资产，淘宝公司对此依法享有竞争性财产权益。 关于是否享有「财产所有权」：是否赋予网络运营者享有网络大数据产品财产所有权，事关民事法律制度的确定；限于当时的法律对数据产品的权利保护尚未作出具体规定，基于「物权法定」原则，对淘宝公司的该项诉讼主张，一审法院不予确认。（即：确认竞争性财产权益，不确认财产所有权——据一审判决书。） 关于争议焦点③（不正当竞争判定）：反不正当竞争法规制的对象不仅局限于同业间的竞争行为，也包括跨行业间的竞争行为。美景公司以提供远程登录技术服务为招揽，组织、帮助他人利用他人子账户获取数据内容并牟利，构成不正当竞争。 关于争议焦点④（民事责任的确定）：一审综合考量淘宝公司产品开发和维护成本、市场价值和市场收益，以及侵权情节、侵权恶意（美景公司在诉讼过程中仍未停止侵权行为）等因素，依法行使自由裁量权，确定法定赔偿数额及合理费用开支共计 200 万元。 二、二审说理（杭州市中级人民法院，据二审判决书全文） 二审争议焦点为两项：①不正当竞争行为的判定；②判赔金额。\n法律适用的兜底路径：反不正当竞争法第二条第二款是对不正当竞争行为的总则性规定；在经营者的相关行为未落入该法第六条至第十二条的特别规定调整范畴时，应适用该款规定对被控行为予以评价。美景公司以「特别规定未提及本案行为」为由主张一审适用法律不当，缺乏法律依据。 竞争关系与技术中立抗辩：美景公司辩称其系技术中立的平台服务商、与淘宝公司不存在竞争关系。二审认为，「咕咕互助平台」以淘宝公司的「生意参谋」产品为对象，其分享账号的行为直接导致淘宝公司数据产品销售的减少，两者存在此消彼长的替代性，具有竞争关系；《生意参谋零售电商大数据软件服务协议》明确禁止出售、转售、出租、出借或以其他方式提供给第三方使用账户，美景公司作为分享账户的平台方理应知道该约定并明知其行为会导致销售数量减少，其恶意组织分享账户、借由损害淘宝公司利益而从中牟利的行为，属于直接实施侵权行为——技术中立抗辩不能成立。 数据产品与个人信息的界限：数据产品是淘宝公司在原始痕迹数据基础上经综合、计算、整理而得到的趋势、占比、排行等分析意见，其对信息的使用结果与原始痕迹信息本身已不具有直接关联，已远远脱出个人信息范畴，不属于对用户信息的公开使用。 判赔金额：美景公司主张其侵权收入仅约 16 万元。二审认为该主张缺乏证据支持和计算的合理推导；在淘宝公司被侵权损失和美景公司侵权获利均无法查明的情况下，一审综合考虑数据内容开发与维护成本较高、市场价值和收益较高、涉案平台用户数量及收费标准、淘宝公司不同版本用户占比、美景公司在诉讼后仍未停止不正当竞争行为、侵权主观恶意明显、淘宝公司为本案支付的合理维权费用等情节，酌情判赔 200 万元并无不当；结合美景公司注册资金 500 万元且无证据显示其从事其他经营行为，判令赔偿 200 万元合理恰当。 裁判结果 一审判决（2018-08-16，据一审判决书全文）：\n被告安徽美景信息科技有限公司于本判决生效之日起立即停止涉案不正当竞争行为，即立即停止以不正当的方式获取、使用（包括提供他人使用）、泄露市场行情标准版和市场行情专业版「生意参谋」数据产品中的数据内容以及涉案网站上的相关宣传行为等； 被告赔偿原告淘宝（中国）软件有限公司经济损失及为制止不正当竞争行为所支付的合理费用共计 200 万元，于本判决生效之日起十日内履行完毕； 驳回原告的其他诉讼请求。 一审诉讼费用：案件受理费 46800 元，由淘宝公司负担 14040 元、美景公司负担 32760 元；财产保全费 5000 元由美景公司负担。\n二审判决（2018-12-18）：驳回上诉，维持原判；二审案件受理费人民币 22800 元由上诉人安徽美景信息科技有限公司负担；本判决为终审判决。（审判长潘才敏，审判员徐雁、黄斯蓓）\n数据法 / AI 法要点 数据权益的「分层确认」：法院确认网络运营者对大数据产品享有竞争性财产权益，但基于物权法定原则不确认财产所有权——这是「数据权益」在专门立法缺位时期的典型裁判路径，也是该案被称「首例涉数据资源开发应用与权属判定新类型案件」的原因。 用户信息与数据产品的界分：经匿名化脱敏与算法加工形成的衍生数据，已与原始痕迹信息不具有直接关联、超出个人信息范畴；本案据此认定数据产品的使用不属于对用户信息的公开使用。 个人信息收集正当性的四项审查要素：规则公开、取得同意、合法渠道、目的必要（一审的裁判方法），并对天猫网用户信息适用三重授权规则。 竞争关系的扩张理解：不正当竞争规制不限于同业；只要存在此消彼长的替代性即具备竞争关系。技术中立不构成免责抗辩：以技术为工具组织他人违约分享账户牟利的，属直接实施侵权行为。 举证与赔偿：在权利人损失与侵权获利均无法查明时，可依司法解释酌定赔偿；被告主张的较低获利数额因缺乏证据支持不被采纳，诉讼中持续侵权、侵权主观恶意明显是加重赔偿的重要情节。 时际法提示：本案适用裁判时的《反不正当竞争法》（2017 年修订）第二条、第十七条与《网络安全法》，以及当时的司法解释；不得直接以现行个人信息保护法、数据安全法的规则评价本案裁判。 相关法条 裁判时实际适用（据一审判决书判决依据段）：《中华人民共和国反不正当竞争法》第二条、第十七条；《中华人民共和国网络安全法》第二十二条第三款、第四十一条、第四十二条、第七十六条；《最高人民法院关于审理不正当竞争民事案件应用法律若干问题的解释》第十七条；《中华人民共和国民事诉讼法》第六十四条第一款。\n二审适用：《中华人民共和国反不正当竞争法》第二条第二款（二审说理即以此款为总则性依据）；《中华人民共和国民事诉讼法》第一百七十条第一款第（一）项（判决依据）。\n注意：《反不正当竞争法》及上述不正当竞争司法解释均于本案裁判后经修订或替代，援引时须核对现行有效文本的版本与条文序号。\n对照规则（发布在后，非本案裁判依据）\n现行法对照：《中华人民共和国民法典》第 127 条（法律对数据、网络虚拟财产的保护有规定的，依照其规定）；《中华人民共和国反不正当竞争法》关于商业秘密与数据、算法相关行为的规定（版本与序号见上「注意」项）。 在后的规则文件：最高人民法院关于依法审理涉人工智能纠纷案件的意见（法发〔2026〕10号） 中（十六）「依法规范涉人工智能数据使用行为」明确：人工智能开发者通过采集生成、衍生创造、受让取得、授权许可等方式合法获取数据并享有相应数据权益的，人民法院应当予以保护；对于构成汇编作品或者其他作品的数据、数据集合，依照著作权法予以保护；构成商业秘密的依照反不正当竞争法予以保护；不构成商业秘密的数据、数据集合，被诉侵权行为违反反不正当竞争法有关规定的，依法承担责任。该文件 2026-09-07 发布，本案裁判时尚未发布，仅作对照。（引用体例：该文件各项以（一）至（二十四）编号，官方概括为「5 个部分、共 24 条」，正文单元不称「第X条」，本站按原文以「（X）」形式引用。） 权威来源 杭州市临安区人民法院《杭州法院司法保障数字经济十大案例》案例一：淘宝（中国）软件有限公司诉安徽美景信息科技有限公司不正当竞争纠纷案（载案例索引、典型意义、基本案情、裁判结果） 中国新闻网转载《法制日报》：《评淘宝诉美景公司大数据产品不正当竞争案》（2019-01-22，载二审判决日期、判赔数额与两审法院认定） 判决书全文转载文本（非官方平台转载，非判决书原件）：一审判决书全文（杭州铁路运输法院，（2017）浙8601民初4034号，载当事人、审理经过、四项争议焦点与全部判项、判决依据条文）见 https://www.ciplawyer.cn/articles/139946.html；二审判决书全文（杭州市中级人民法院，（2018）浙01民终7312号，载两争议焦点、技术中立与竞争关系认定、判赔考量、全部判项与审判人员）见 http://www.zscqwh.com/case-bzdjz/1052.html。两份文本经本站与本栏官方发布文本互核一致（一审案号、200 万元判赔、维持原判均相符），但仍属非官方来源，官方渠道的裁判文书链接暂缺。 来源说明：前两项一为法院发布文本（经地方媒体平台「临安新闻网·临安区人民法院」页面承载），一为官媒报道；末项为非官方平台转载的判决书全文，仅作核对线索。三者均非官方渠道发布的判决书原件。\n站内关联法规 /compliance/china/spc-opinions-ai-disputes-2026/ ","permalink":"https://ai.intlaws.com/cases/china/legacy-taobao-shengyicanmou-data/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e淘宝（中国）软件有限公司诉安徽美景信息科技有限公司不正当竞争纠纷案\u003c/strong\u003e（业内通称「生意参谋」数据产品案）\u003c/p\u003e\n\u003cp\u003e一审 杭州铁路运输法院，（2017）浙8601民初4034号：2017-12-06 立案，2018-06-15 依淘宝公司申请作出\u003cstrong\u003e禁止被诉侵权行为的行为保全裁定\u003c/strong\u003e，2018-08-16 判决\u003c/p\u003e\n\u003cp\u003e二审 浙江省杭州市中级人民法院，（2018）浙01民终7312号：2018-12-18 判决，\u003cstrong\u003e驳回上诉，维持原判\u003c/strong\u003e，为终审判决\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e专题归属\u003c/strong\u003e：在先经典（2021 年前）。该案裁判时数据领域专门立法（《数据安全法》《个人信息保护法》）尚未施行。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e入选\u003c/strong\u003e：据法院发布文本，本案被《人民法院报》评为 2018 年度人民法院十大民事行政案件，并入选「2018 年中国法院 50 件典型知识产权案例」；为《杭州法院司法保障数字经济十大案例》案例一，被称为\u003cstrong\u003e首例涉数据资源开发应用与权属判定的新类型案件\u003c/strong\u003e。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e程序事实（据一审判决书）\u003c/strong\u003e：一审审理中，美景公司提出管辖权异议，2018-03-29 被裁定驳回，其上诉后经杭州市中级人民法院 2018-05-29 裁定驳回上诉、维持原裁定；2018-01-10 淘宝公司申请追加谢松林为共同被告并获准许，2018-08-07 申请撤回对其起诉并获准许；2018-07-20 公开开庭审理。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 不正当竞争 / 数据产品 / 衍生数据 / 竞争性财产权益 / 三重授权 / 行为保全 / 技术中立\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e原告主张\u003c/strong\u003e：淘宝（中国）软件有限公司（下称淘宝公司）系阿里巴巴卖家端「生意参谋」零售电商数据产品的开发者和运营者。「生意参谋」数据产品是在用户浏览、搜索、收藏、加购、交易等行为痕迹所产生的原始数据基础上，经过深度分析处理、整合加工而形成的预测型、指数型、统计型\u003cstrong\u003e衍生数据\u003c/strong\u003e，呈现形式为行业大盘趋势图、商品店铺榜、搜索词分析、买卖家人群画像等板块的排行数据与指数。淘宝公司认为，涉案数据产品中的原始数据与衍生数据均系其无形资产，其享有财产所有权及竞争性财产权益；美景公司的被诉行为已实质性替代涉案数据产品，构成不正当竞争，\u003cstrong\u003e诉请判令美景公司立即停止侵权，并赔偿经济损失及合理费用 500 万元\u003c/strong\u003e。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e被诉行为\u003c/strong\u003e：安徽美景信息科技有限公司（下称美景公司）以提供远程登录「生意参谋」数据产品淘宝用户电脑的技术服务为招揽，通过组织、帮助他人利用已订购「生意参谋」服务的淘宝用户所提供的\u003cstrong\u003e子账户\u003c/strong\u003e获取「生意参谋」数据产品中的数据内容，从中牟取商业利益（据一审判决书所载被诉行为）。另据《法制日报》（中国新闻网转载，2019-01-22）报道，美景公司开发和运营「咕咕互助平台」软件及「咕咕生意参谋众筹」网站，教唆、引诱已订购「生意参谋」产品的用户下载该软件、共享子账户并从中牟利。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e查明事实要点（据一审判决书）\u003c/strong\u003e：经公证保全，涉案网站「生意参谋租用」栏目的租用客户数升至 13226 户、类目 58 个、子账户 245 个；2018-06-15 一审法院作出禁止被诉侵权行为裁定后，涉案网站与「咕咕互助平台」已暂停运营；淘宝公司为本案维权支出公证费 6900 元。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003ch3 id=\"一一审说理杭州铁路运输法院据一审判决书全文\"\u003e一、一审说理（杭州铁路运输法院，据一审判决书全文）\u003c/h3\u003e\n\u003cp\u003e一审确定的争议焦点为四项：\u003cstrong\u003e①淘宝公司收集并使用网络用户信息的行为是否正当；②淘宝公司对「生意参谋」数据产品是否享有法定权益；③被诉行为是否构成不正当竞争；④本案民事责任的确定\u003c/strong\u003e。\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e关于争议焦点①（信息收集使用的正当性）\u003c/strong\u003e：信息是数据的内容，数据是信息的形式；涉案数据产品的数据内容虽来源于原始数据，但原始数据只是网络用户行为痕迹信息外化为数字、符号、文字、图像等方式的表现形式。一审从\u003cstrong\u003e规则公开\u003c/strong\u003e（淘宝公司已向用户公开涉及个人信息、非个人信息收集规定的法律声明及隐私权政策）、\u003cstrong\u003e取得同意\u003c/strong\u003e（用户注册账号时通过服务协议、法律声明及隐私权政策的形式取得授权许可）、\u003cstrong\u003e合法正当性\u003c/strong\u003e（经授权后收集使用的原始数据均来自用户主动提供或平台自动获取的活动痕迹，不存在非法渠道获取信息）、\u003cstrong\u003e行为必要性\u003c/strong\u003e（目的在于通过大数据分析为用户经营活动提供参谋服务，使用目的、方式和范围符合法律规定）四个方面认定淘宝公司收集、使用网络用户信息以及数据产品公开使用网络用户信息的行为\u003cstrong\u003e符合法律规定，具有正当性\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e关于天猫网用户信息的「三重授权」规则\u003c/strong\u003e：作为第三方的淘宝公司使用天猫网用户信息，受「\u003cstrong\u003e用户授权网络运营者＋网络运营者授权第三方＋用户授权第三方\u003c/strong\u003e」的三重授权许可使用规则限制；经审查天猫网《隐私权政策》已明确用户个人信息可能与其关联公司共享，且天猫网商户及会员统一使用淘宝网账户并在注册时同意相关协议与政策，故可认定淘宝公司已获得用户信息提供者的同意。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e关于争议焦点②（数据产品的法定权益）\u003c/strong\u003e：涉案数据产品所提供的数据内容不再是原始网络数据，而是在巨量原始网络数据基础上通过一定算法，经过深度分析过滤、提炼整合以及匿名化脱敏处理后形成的\u003cstrong\u003e预测型、指数型、统计型的衍生数据\u003c/strong\u003e，其呈现方式为趋势图、排行榜、占比图等图形，已成为\u003cstrong\u003e网络大数据产品\u003c/strong\u003e。一审认为，该数据产品是淘宝公司的劳动成果，其数据内容中所包含的原始数据与衍生数据均系淘宝公司的无形资产，淘宝公司对此依法享有\u003cstrong\u003e竞争性财产权益\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e关于是否享有「财产所有权」\u003c/strong\u003e：是否赋予网络运营者享有网络大数据产品财产所有权，事关民事法律制度的确定；限于当时的法律对数据产品的权利保护尚未作出具体规定，\u003cstrong\u003e基于「物权法定」原则，对淘宝公司的该项诉讼主张，一审法院不予确认\u003c/strong\u003e。（即：确认竞争性财产权益，不确认财产所有权——据一审判决书。）\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e关于争议焦点③（不正当竞争判定）\u003c/strong\u003e：反不正当竞争法规制的对象不仅局限于同业间的竞争行为，也包括跨行业间的竞争行为。美景公司以提供远程登录技术服务为招揽，组织、帮助他人利用他人子账户获取数据内容并牟利，构成不正当竞争。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e关于争议焦点④（民事责任的确定）\u003c/strong\u003e：一审综合考量淘宝公司产品开发和维护成本、市场价值和市场收益，以及侵权情节、侵权恶意（美景公司在诉讼过程中仍未停止侵权行为）等因素，依法行使自由裁量权，确定法定赔偿数额及合理费用开支共计 200 万元。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"二二审说理杭州市中级人民法院据二审判决书全文\"\u003e二、二审说理（杭州市中级人民法院，据二审判决书全文）\u003c/h3\u003e\n\u003cp\u003e二审争议焦点为两项：\u003cstrong\u003e①不正当竞争行为的判定；②判赔金额\u003c/strong\u003e。\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e法律适用的兜底路径\u003c/strong\u003e：反不正当竞争法第二条第二款是对不正当竞争行为的总则性规定；在经营者的相关行为\u003cstrong\u003e未落入该法第六条至第十二条的特别规定调整范畴\u003c/strong\u003e时，应适用该款规定对被控行为予以评价。美景公司以「特别规定未提及本案行为」为由主张一审适用法律不当，缺乏法律依据。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e竞争关系与技术中立抗辩\u003c/strong\u003e：美景公司辩称其系\u003cstrong\u003e技术中立\u003c/strong\u003e的平台服务商、与淘宝公司不存在竞争关系。二审认为，「咕咕互助平台」以淘宝公司的「生意参谋」产品为对象，其分享账号的行为直接导致淘宝公司数据产品销售的减少，\u003cstrong\u003e两者存在此消彼长的替代性，具有竞争关系\u003c/strong\u003e；《生意参谋零售电商大数据软件服务协议》明确禁止出售、转售、出租、出借或以其他方式提供给第三方使用账户，美景公司作为分享账户的平台方理应知道该约定并明知其行为会导致销售数量减少，其\u003cstrong\u003e恶意组织分享账户、借由损害淘宝公司利益而从中牟利的行为，属于直接实施侵权行为\u003c/strong\u003e——技术中立抗辩不能成立。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e数据产品与个人信息的界限\u003c/strong\u003e：数据产品是淘宝公司在原始痕迹数据基础上经综合、计算、整理而得到的趋势、占比、排行等分析意见，其对信息的使用结果\u003cstrong\u003e与原始痕迹信息本身已不具有直接关联，已远远脱出个人信息范畴，不属于对用户信息的公开使用\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e判赔金额\u003c/strong\u003e：美景公司主张其侵权收入仅约 16 万元。二审认为该主张缺乏证据支持和计算的合理推导；在淘宝公司被侵权损失和美景公司侵权获利均无法查明的情况下，一审综合考虑数据内容开发与维护成本较高、市场价值和收益较高、涉案平台用户数量及收费标准、淘宝公司不同版本用户占比、\u003cstrong\u003e美景公司在诉讼后仍未停止不正当竞争行为、侵权主观恶意明显\u003c/strong\u003e、淘宝公司为本案支付的合理维权费用等情节，酌情判赔 200 万元并无不当；结合美景公司注册资金 500 万元且无证据显示其从事其他经营行为，\u003cstrong\u003e判令赔偿 200 万元合理恰当\u003c/strong\u003e。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e一审判决（2018-08-16，据一审判决书全文）\u003c/strong\u003e：\u003c/p\u003e","title":"【在先经典】淘宝（中国）软件有限公司诉安徽美景信息科技有限公司不正当竞争纠纷案（「生意参谋」数据产品案）"},{"content":"案件名称与案号 郭兵与杭州野生动物世界有限公司服务合同纠纷案（业内通称「人脸识别第一案」）\n一审 杭州市富阳区人民法院，（2019）浙0111民初6971号，2020-11-20 公开宣判 ｜ 二审 杭州市中级人民法院，（2020）浙01民终10940号，2021-04-09 公开宣判\n专题归属：在先经典（2021 年前）。该案裁判时《个人信息保护法》尚未施行。\n一审法院是杭州市富阳区人民法院（案号「浙0111」即富阳区），部分媒体表述为「杭州互联网法院」，与案号及官媒报道不符。\n最高人民法院官网发布文本已收录本案：该院《人民法院服务和保障长三角一体化发展典型案例》（2021-11-02 发布，案例八）载有本案基本案情、两审判项与二审裁判理由（见页末「权威来源」栏），本页案情与判项据该官方发布文本写实。\n一审程序（据非法院渠道的一审判决书全文转载文本）：该院于 2019 年 10 月 28 日收到立案材料后引入诉前调解程序，因调解未果，于 2019 年 11 月 1 日正式立案，依法适用普通程序审理；因新冠肺炎疫情影响于 2020 年 1 月 23 日中止诉讼，恢复后于 2020 年 6 月 15 日公开开庭审理；本案经批准延长审限，并经该院审判委员会讨论决定后于 2020 年 11 月 20 日作出判决。审判人员：审判长喻青霞，审判员唐承飞、马嶙侃，书记员周锋。判决载明如不服可于送达之日起十五日内上诉于浙江省杭州市中级人民法院。\n关键词 民事 / 服务合同 / 生物识别信息 / 敏感个人信息 / 必要原则 / 违约责任 / 人脸识别\n基本案情 据最高人民法院官网所载《人民法院服务和保障长三角一体化发展典型案例》案例八（2021-11-02）：\n2019 年 4 月 27 日，郭兵向杭州野生动物世界有限公司（以下简称野生动物世界）购买以指纹识别方式入园的双人年卡并支付卡费 1360 元。野生动物世界以店堂告示形式公示指纹识别年卡的办理和使用说明，郭兵与其妻子留存了姓名、身份证号码、电话号码等个人信息，并录入指纹和拍摄照片。在双方服务合同履行过程中，野生动物世界将入园方式从指纹识别调整为人脸识别，并于 2019 年 10 月 7 日停用指纹识别闸机；先后于 2019 年 7 月 12 日和 10 月 17 日向包括郭兵在内的年卡消费者发送两条短信，告知年卡系统已升级，若不激活人脸识别系统将无法正常入园。2019 年 10 月 26 日，郭兵至野生动物世界交涉，园方表示原指纹识别方式已无法入园、未注册人脸识别系统将无法入园。郭兵不同意接受人脸识别，要求退卡，协商未果，遂提起诉讼，请求判令：一、确认野生动物世界店堂告示和短信通知中涉及指纹识别和人脸识别的内容无效；二、赔偿年卡卡费及为解决纠纷支出的交通费等费用；三、删除郭兵提交的全部个人信息等。\n法院审理与说理 （一）一审说理（杭州市富阳区人民法院，据杭州网 2020-11-22 报道所载法院认定）\n野生动物世界基于年卡用户可在有效期内无限次入园畅游的实际情况，使用指纹识别、人脸识别等生物识别技术，以达到甄别年卡用户身份、提高年卡用户入园效率的目的，该行为本身符合法律规定的「合法、正当、必要」的原则要求。 客户在办理年卡时，野生动物世界以店堂告示的形式告知购卡人需提供部分个人信息，未对消费者作出不公平、不合理的其他规定，客户的消费知情权和对个人信息的自主决定权未受到侵害；郭兵系自行决定提供指纹等个人信息而成为年卡客户。 审理中未发现有证据表明野生动物世界对郭兵实施了欺诈行为，驳回原告主张的欺诈问题。 （二）二审说理（杭州市中级人民法院，据最高人民法院官网《人民法院服务和保障长三角一体化发展典型案例》案例八所载裁判理由）\n生物识别信息作为敏感的个人信息，深度体现自然人的生理和行为特征，具备较强的人格属性，一旦被泄露或者非法使用，可能导致个人受到歧视或者人身、财产安全受到不测危害，更应谨慎处理和严格保护。 经营者只有在消费者知情同意的前提下方能收集和使用生物识别信息，且须遵循合法、正当、必要原则。 经营者违反双方约定处理信息或者因违约而停止提供某项产品或服务，消费者有权要求经营者删除与其违约情形相对应的个人信息。 郭兵在知悉指纹识别店堂告示内容的情况下，权衡后自主作出办理年卡的决定并提供相关个人信息，指纹识别店堂告示对双方具有约束力，而人脸识别店堂告示并非双方之间的合同条款，对郭兵不发生效力。 郭兵办理指纹识别年卡时选择权并未受到限制或侵害，野生动物世界的行为亦不构成欺诈，但野生动物世界单方变更入园方式构成违约。 野生动物世界欲利用收集的照片扩大信息处理范围，超出事前收集目的，表明其存在侵害郭兵面部特征信息之人格利益的可能与危险，应当删除郭兵办卡时提交的包括照片在内的面部特征信息。 鉴于野生动物世界停止使用指纹识别闸机，致使原约定的入园服务方式无法实现，故二审在原判决的基础上增判删除郭兵办理指纹年卡时提交的指纹识别信息。 裁判结果 一审（浙江省杭州市富阳区人民法院，据最高人民法院官网发布文本）：\n一、野生动物世界赔偿郭兵合同利益损失及交通费共计 1038 元；\n二、野生动物世界删除郭兵办理指纹年卡时提交的包括照片在内的面部特征信息；\n三、驳回郭兵的其他诉讼请求。\n一审宣判后，郭兵与野生动物世界均提起上诉。\n二审（浙江省杭州市中级人民法院，据最高人民法院官网发布文本）：\n一、维持一审判决第一项、第二项；\n二、撤销一审判决第三项；\n三、野生动物世界删除郭兵办理指纹年卡时提交的指纹识别信息；\n四、驳回郭兵的其他诉讼请求。\n官方发布文本另载典型意义：本案系数字经济背景下人脸识别纠纷第一案，依法保护了消费者对人脸等身份识别信息享有的合法权益，对生物识别信息收集加以规范；裁判结果兼顾鼓励数字产业发展与个人信息保护两大需求。\n来源说明：上述两审判项与二审裁判理由据最高人民法院官网发布文本整理（该文本为案例汇编发布稿，非判决书原件）；一审裁判理由据杭州网报道所载法院认定整理。判项的具体文字表述以判决书原件为准。\n数据法 / AI 法要点 生物识别信息（人脸、指纹）属敏感个人信息，应谨慎处理和严格保护——该认定作于《个人信息保护法》施行前，其后的现行法以专节（敏感个人信息）予以规范。 合同条款的识别：指纹识别店堂告示构成合同内容且有约束力；经营者单方以短信变更入园方式（人脸识别）的店堂告示并非合同条款，对消费者不发生效力。 单方变更服务方式构成违约：经营者在合同履行中单方改变约定的服务方式，即使其技术手段本身符合「合法、正当、必要」原则，仍构成违约。 超出事前收集目的的处理行为应停止并删除：以已收集照片扩大信息处理范围，存在侵害人格利益的可能与危险，应删除相关信息。 时际法提示：本案是服务合同纠纷（违约路径），不是侵权之诉；裁判时适用《合同法》与《消费者权益保护法》的收集必要原则，二审作出于 2021-01-01《民法典》施行之后，因时间效力规定仍适用当时的合同法。不得直接以现行《个人信息保护法》评价本案裁判。 相关法条 裁判时实际适用（据二审说理所述裁判路径）：《中华人民共和国合同法》关于违约责任的规定；《中华人民共和国消费者权益保护法》关于经营者收集、使用消费者个人信息应遵循合法、正当、必要原则的规定。\n裁判所引具体条文号（据非法院渠道的一审判决书全文转载文本）：判决载明「本案经本院审判委员会讨论决定，依据……判决如下」——《中华人民共和国民法总则》第一百一十一条、第一百四十二条；《中华人民共和国合同法》第十三条、第十六条第一款、第二十条第一项、第一百零八条；《中华人民共和国消费者权益保护法》第二十六条、第二十九条、第四十条；《中华人民共和国民事诉讼法》第六十四条第一款。\n来源说明：上述条文号取自非官方平台转载的一审判决书全文（见「权威来源」栏），未经法院官方渠道文本复核，援引时请以法院文书原件为准。\n对照规则（发布在后，非本案裁判依据）\n现行法对照：《个人信息保护法》第 26 条（公共场所安装图像采集、个人身份识别设备应遵守的规定）、第 28 条（敏感个人信息的定义与处理要件）、第 29 条（处理敏感个人信息的单独同意）；《中华人民共和国民法典》第 1034—1039 条（隐私权与个人信息保护）。 在后的规则文件：最高人民法院关于依法审理涉人工智能纠纷案件的意见（法发〔2026〕10号） 中（三）要求「准确适用民法典、个人信息保护法、产品质量法、道路交通安全法等相关法律规定」认定相关责任，与本类案件转入现行法路径后的审查方向一致。该文件 2026-09-07 发布，本案裁判时尚未发布，仅作对照。（引用体例：该文件各项以（一）至（二十四）编号，正文单元不称「第X条」，本站按原文以「（X）」形式引用。） 权威来源 最高人民法院官网：《人民法院服务和保障长三角一体化发展典型案例》（2021-11-02 发布，案例八为本案；载基本案情、一审判项、二审裁判理由与二审四项判项） 中国新闻网：「人脸识别第一案」二审宣判：删除原告指纹识别信息（2021-04-09，中新社稿，载二审宣判时间与增判内容） 杭州网：杭州「人脸识别第一案」在富阳宣判（2020-11-22，载一审判项与法院认定） China Justice Observer（第三方研究项目站点）：杭州市富阳区人民法院（2019）浙0111民初6971号民事判决书全文转载文本 —— 非法院渠道（判决书全文转载文本，非判决书原件）。\n中国新闻网：「人脸识别第一案」二审宣判：删除原告指纹识别信息 来源说明：首项为最高人民法院官网发布的案例汇编文本（官方渠道，但非判决书原件）；其余为官媒报道（中国新闻社）与地方党报新媒体平台报道（杭州日报报业集团杭州网）；末项为非官方平台转载的判决书全文，（非判决书原件）。\n站内关联法规 /compliance/china/pipl/ /compliance/china/spc-opinions-ai-disputes-2026/ ","permalink":"https://ai.intlaws.com/cases/china/legacy-face-recognition-guobing/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e郭兵与杭州野生动物世界有限公司服务合同纠纷案\u003c/strong\u003e（业内通称「人脸识别第一案」）\u003c/p\u003e\n\u003cp\u003e一审 杭州市富阳区人民法院，（2019）浙0111民初6971号，2020-11-20 公开宣判 ｜ 二审 杭州市中级人民法院，（2020）浙01民终10940号，2021-04-09 公开宣判\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e专题归属\u003c/strong\u003e：在先经典（2021 年前）。该案裁判时《个人信息保护法》尚未施行。\u003c/p\u003e\n\u003cp\u003e一审法院是\u003cstrong\u003e杭州市富阳区人民法院\u003c/strong\u003e（案号「浙0111」即富阳区），部分媒体表述为「杭州互联网法院」，与案号及官媒报道不符。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e最高人民法院官网发布文本\u003c/strong\u003e已收录本案：该院《人民法院服务和保障长三角一体化发展典型案例》（2021-11-02 发布，案例八）载有本案基本案情、两审判项与二审裁判理由（见页末「权威来源」栏），本页案情与判项据该官方发布文本写实。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e一审程序（据非法院渠道的一审判决书全文转载文本）\u003c/strong\u003e：该院于 2019 年 10 月 28 日收到立案材料后引入诉前调解程序，因调解未果，于 \u003cstrong\u003e2019 年 11 月 1 日正式立案\u003c/strong\u003e，依法适用普通程序审理；因新冠肺炎疫情影响于 \u003cstrong\u003e2020 年 1 月 23 日中止诉讼\u003c/strong\u003e，恢复后于 \u003cstrong\u003e2020 年 6 月 15 日公开开庭\u003c/strong\u003e审理；本案经批准延长审限，并\u003cstrong\u003e经该院审判委员会讨论决定\u003c/strong\u003e后于 2020 年 11 月 20 日作出判决。审判人员：\u003cstrong\u003e审判长喻青霞，审判员唐承飞、马嶙侃，书记员周锋\u003c/strong\u003e。判决载明如不服可于送达之日起十五日内上诉于\u003cstrong\u003e浙江省杭州市中级人民法院\u003c/strong\u003e。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 服务合同 / 生物识别信息 / 敏感个人信息 / 必要原则 / 违约责任 / 人脸识别\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e据\u003cstrong\u003e最高人民法院官网\u003c/strong\u003e所载《人民法院服务和保障长三角一体化发展典型案例》案例八（2021-11-02）：\u003c/p\u003e\n\u003cp\u003e2019 年 4 月 27 日，郭兵向杭州野生动物世界有限公司（以下简称野生动物世界）购买以指纹识别方式入园的双人年卡并支付卡费 \u003cstrong\u003e1360 元\u003c/strong\u003e。野生动物世界以店堂告示形式公示指纹识别年卡的办理和使用说明，郭兵与其妻子留存了姓名、身份证号码、电话号码等个人信息，并录入指纹和拍摄照片。在双方服务合同履行过程中，野生动物世界将入园方式从指纹识别调整为人脸识别，并于 \u003cstrong\u003e2019 年 10 月 7 日停用指纹识别闸机\u003c/strong\u003e；先后于 \u003cstrong\u003e2019 年 7 月 12 日和 10 月 17 日\u003c/strong\u003e向包括郭兵在内的年卡消费者发送两条短信，告知年卡系统已升级，\u003cstrong\u003e若不激活人脸识别系统将无法正常入园\u003c/strong\u003e。2019 年 10 月 26 日，郭兵至野生动物世界交涉，园方表示原指纹识别方式已无法入园、未注册人脸识别系统将无法入园。郭兵不同意接受人脸识别，要求退卡，协商未果，遂提起诉讼，请求判令：一、确认野生动物世界店堂告示和短信通知中涉及指纹识别和人脸识别的内容无效；二、赔偿年卡卡费及为解决纠纷支出的交通费等费用；三、删除郭兵提交的全部个人信息等。\u003c/p\u003e","title":"【在先经典】「人脸识别第一案」：郭兵诉杭州野生动物世界服务合同纠纷案"},{"content":"案件名称与案号 黄某与腾讯科技（深圳）有限公司、腾讯科技（北京）有限公司、深圳市腾讯计算机系统有限公司个人信息权益网络侵权责任纠纷案（业内通称「微信读书案」）\n一审 北京互联网法院，（2019）京0491民初16142号，2020-07-30 判决（审判长孙铭溪，审判员颜君，人民陪审员郝作成）\n本案一审判决书全文已由最高人民法院审判管理办公室「百篇优秀裁判文书」平台公开（官方渠道，见页末「权威来源」栏），本页判项、判决依据与诉讼费用据该全文写实。\n专题归属：在先经典（2021 年前）。该案裁判时《个人信息保护法》尚未施行。\n关键词 民事 / 个人信息权益 / 隐私权 / 知情同意 / 好友关系 / 人格画像 / 必要原则\n基本案情 黄某认为微信读书在未经其有效同意的情况下获取其微信好友关系，为其自动关注微信好友，并向共同使用微信读书的微信好友默认开放其读书信息，构成侵权，于 2019 年将微信读书软件、微信软件的开发者、运营者腾讯科技（深圳）有限公司、腾讯科技（北京）有限公司、深圳市腾讯计算机系统有限公司诉至北京互联网法院。（据人民网·法治频道 2020-07-31 报道）\n2020-07-30，北京互联网法院作出一审判决，认定腾讯公司侵害原告黄某个人信息权益，但未侵害其隐私权。（同上）\n法院审理与说理 以下据人民网·法治频道 2020-07-31 报道所载北京互联网法院认定，逐段引述：\n行为定性：微信读书为用户自动添加好友、微信好友之间的读书信息默认开放的行为，构成对原告个人信息权益的侵害。 知情同意的实质标准：微信读书、微信在应用软件中为两款独立的应用，显示的开发者并不相同，两个软件共同好友的关系并不符合一般用户的合理预期；读书信息可能构成对用户的「人格画像」，在互联网时代，用户应享有自主建立或拒绝建立信息化「人设」的自由，而这种自由行使的前提是用户清晰、明确地知晓此种自由；但微信读书在用户协议中并没有就应对好友列表、读书信息的处理方式等重要事项进行充分告知，易让用户对微信和微信读书两个软件中的「好友」产生混淆，因此不能视为获得用户有效的知情同意，构成对原告个人信息权益的侵害。 隐私权不成立的理由：互联网时代需要合理考量隐私、个人信息的关系，进而平衡个人信息保护及信息合理利用的关系。隐私主要是防御性权利，注重精神利益；个人信息权益注重预防侵害，同时有财产利益，有积极利用的可能。判断是否构成隐私，需要符合社会一般理性标准，强调其「不愿为他人知晓」的「私密性」。对于读书信息，用户可能存在不愿为他人知晓的期待，也可能存在知识共享、文化交流甚至商业回报等积极利用的期待，不同用户对于读书信息的隐私期待有所不同；因此判断是否侵害隐私权需要结合具体场景。就本案来看，原告的读书信息呈现方式尚不至构成一般理性标准下的「私密性」标准，对原告主张腾讯公司侵害其隐私权，不予支持。 裁判结果 据最高人民法院审判管理办公室「百篇优秀裁判文书」平台所载本案一审判决书全文（官方渠道），判项共八项：\n一、被告深圳市腾讯计算机系统有限公司于本判决生效之日停止微信读书收集、使用原告黄某微信好友列表信息的行为，并删除微信读书中留存的原告黄某的微信好友列表信息；\n二、被告深圳市腾讯计算机系统有限公司于本判决生效之日解除原告黄某在微信读书中对其微信好友的关注；\n三、被告深圳市腾讯计算机系统有限公司于本判决生效之日解除原告黄某的微信好友在微信读书中对原告黄某的关注；\n四、被告深圳市腾讯计算机系统有限公司于本判决生效之日停止将原告黄某使用微信读书软件生成的信息（包括读书时长、书架、正在阅读的读物）向原告黄某共同使用微信读书的微信好友展示的行为；\n五、被告腾讯科技（深圳）有限公司于本判决生效之日起 7 日内以书面形式向原告黄某赔礼道歉（致歉内容须经法院审核；逾期不履行的，法院将选择一家全国公开发行的报纸刊登本判决主要内容，费用由该公司负担）；\n六、被告深圳市腾讯计算机系统有限公司于本判决生效之日起 7 日内以书面形式向原告黄某赔礼道歉（审核与替代执行方式同上）；\n七、被告腾讯科技（深圳）有限公司、腾讯科技（北京）有限公司、深圳市腾讯计算机系统有限公司于本判决生效之日起 7 日内连带赔偿原告黄某公证费 6660 元；\n八、驳回原告黄某的其他诉讼请求。\n案件受理费 300 元，由三被告负担。判决书载明：如不服本判决，可在判决书送达之日起十五日内向北京市第四中级人民法院提出上诉。\n生效状态：据案例库体例文本（该文本经新闻平台承载，非官方渠道）载「宣判后，原、被告均未提起上诉，该判决已生效」；官方渠道的生效证明未取得。\n数据法 / AI 法要点 知情同意是实质标准而非形式条款：即便用户协议有约定，若对好友列表、读书信息等重要事项未充分告知，致使一般用户对两款应用中的「好友」产生混淆，不能视为获得有效知情同意。 「人格画像」与信息化「人设」自主权：读书信息可用于刻画用户的「人格画像」，用户应享有自主建立或拒绝建立信息化「人设」的自由，其前提是清晰、明确地知晓。 隐私与个人信息权益的分野：隐私为防御性权利、注重精神利益；个人信息权益注重预防侵害并具有财产利益与积极利用可能。信息呈现方式未达一般理性标准下的「私密性」的，不构成隐私权侵害，但处理行为仍可能侵害个人信息权益。 平台的角色影响义务范围：两款独立应用共用好友关系，超出用户合理预期，是该案认定同意无效的关键场景因素。 相关法条 裁判时实际适用（据一审判决书全文「判决依据」段）：《中华人民共和国民法总则》第一百一十一条；《中华人民共和国侵权责任法》第八条、第十五条；《中华人民共和国网络安全法》第四十三条、第七十六条第（五）项；《最高人民法院关于审理利用信息网络侵害人身权益民事纠纷案件适用法律若干问题的规定》第十二条、第十六条、第十八条。\n时际法说明：《民法总则》《侵权责任法》已随《中华人民共和国民法典》施行而废止；《网络安全法》与上述司法解释此后亦经修改或替代。援引时应核对现行有效文本，不得直接以现行法评价本案裁判。\n对照规则（发布在后，非本案裁判依据）\n现行法对照：《个人信息保护法》第 6 条（目的明确合理、最小范围）、第 13 条（合法性基础）、第 14 条（同意的要件：自愿、明确作出）、第 17 条（告知义务）、第 24 条（自动化决策的告知与拒绝）；《中华人民共和国民法典》第 1035 条（处理个人信息的原则与条件）。 在后的规则文件：最高人民法院关于依法审理涉人工智能纠纷案件的意见（法发〔2026〕10号） 中（三）关于「准确适用民法典、个人信息保护法」与过错责任原则的表述，可作为现行审查路径的对照；本案裁判时该文件尚未发布，仅作对照。（引用体例：该文件各项以（一）至（二十四）编号，正文单元不称「第X条」，本站按原文以「（X）」形式引用。） 权威来源 最高人民法院审判管理办公室「百篇优秀裁判文书」平台：北京互联网法院（2019）京0491民初16142号民事判决书全文（官方渠道；载八项判项、判决依据、案件受理费与审判人员） 人民网·法治频道：北京互联网法院：微信读书、抖音侵犯个人信息权（2020-07-31） 来源说明：首项为最高人民法院审判管理办公室主办平台的官方判决书全文（官方渠道）；次项为人民网所载法院信息报道。引证校正：人民网报道将公证费写作「6600 元」，与判决原文「6660 元」不符，本站以判决原文为准。\n站内关联法规 /compliance/china/pipl/ /compliance/china/spc-opinions-ai-disputes-2026/ ","permalink":"https://ai.intlaws.com/cases/china/legacy-weread-reading-info/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e黄某与腾讯科技（深圳）有限公司、腾讯科技（北京）有限公司、深圳市腾讯计算机系统有限公司个人信息权益网络侵权责任纠纷案\u003c/strong\u003e（业内通称「微信读书案」）\u003c/p\u003e\n\u003cp\u003e一审 北京互联网法院，（2019）京0491民初16142号，2020-07-30 判决（审判长孙铭溪，审判员颜君，人民陪审员郝作成）\u003c/p\u003e\n\u003cp\u003e本案一审判决书全文已由\u003cstrong\u003e最高人民法院审判管理办公室「百篇优秀裁判文书」平台\u003c/strong\u003e公开（官方渠道，见页末「权威来源」栏），本页判项、判决依据与诉讼费用据该全文写实。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e专题归属\u003c/strong\u003e：在先经典（2021 年前）。该案裁判时《个人信息保护法》尚未施行。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 个人信息权益 / 隐私权 / 知情同意 / 好友关系 / 人格画像 / 必要原则\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e黄某认为微信读书在未经其有效同意的情况下获取其微信好友关系，为其自动关注微信好友，并向共同使用微信读书的微信好友默认开放其读书信息，构成侵权，于 2019 年将微信读书软件、微信软件的开发者、运营者腾讯科技（深圳）有限公司、腾讯科技（北京）有限公司、深圳市腾讯计算机系统有限公司诉至北京互联网法院。（据人民网·法治频道 2020-07-31 报道）\u003c/p\u003e\n\u003cp\u003e2020-07-30，北京互联网法院作出一审判决，认定腾讯公司侵害原告黄某个人信息权益，\u003cstrong\u003e但未侵害其隐私权\u003c/strong\u003e。（同上）\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e以下据人民网·法治频道 2020-07-31 报道所载北京互联网法院认定，逐段引述：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e行为定性\u003c/strong\u003e：微信读书为用户自动添加好友、微信好友之间的读书信息默认开放的行为，构成对原告个人信息权益的侵害。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e知情同意的实质标准\u003c/strong\u003e：微信读书、微信在应用软件中为两款独立的应用，显示的开发者并不相同，\u003cstrong\u003e两个软件共同好友的关系并不符合一般用户的合理预期\u003c/strong\u003e；读书信息可能构成对用户的「\u003cstrong\u003e人格画像\u003c/strong\u003e」，在互联网时代，用户应享有自主建立或拒绝建立信息化「人设」的自由，而这种自由行使的前提是\u003cstrong\u003e用户清晰、明确地知晓\u003c/strong\u003e此种自由；但微信读书在用户协议中并没有就应对好友列表、读书信息的处理方式等重要事项进行充分告知，易让用户对微信和微信读书两个软件中的「好友」产生混淆，因此\u003cstrong\u003e不能视为获得用户有效的知情同意\u003c/strong\u003e，构成对原告个人信息权益的侵害。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e隐私权不成立的理由\u003c/strong\u003e：互联网时代需要合理考量隐私、个人信息的关系，进而平衡个人信息保护及信息合理利用的关系。隐私主要是\u003cstrong\u003e防御性权利\u003c/strong\u003e，注重精神利益；个人信息权益注重\u003cstrong\u003e预防侵害\u003c/strong\u003e，同时有财产利益，有积极利用的可能。判断是否构成隐私，需要符合社会一般理性标准，强调其「不愿为他人知晓」的「私密性」。对于读书信息，用户可能存在不愿为他人知晓的期待，也可能存在知识共享、文化交流甚至商业回报等积极利用的期待，\u003cstrong\u003e不同用户对于读书信息的隐私期待有所不同\u003c/strong\u003e；因此判断是否侵害隐私权需要结合具体场景。就本案来看，原告的读书信息呈现方式尚不至构成一般理性标准下的「私密性」标准，对原告主张腾讯公司侵害其隐私权，不予支持。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e据\u003cstrong\u003e最高人民法院审判管理办公室「百篇优秀裁判文书」平台\u003c/strong\u003e所载本案一审判决书全文（\u003cstrong\u003e官方渠道\u003c/strong\u003e），判项共八项：\u003c/p\u003e\n\u003cp\u003e一、被告深圳市腾讯计算机系统有限公司于本判决生效之日停止微信读书收集、使用原告黄某微信好友列表信息的行为，并删除微信读书中留存的原告黄某的微信好友列表信息；\u003cbr\u003e\n二、被告深圳市腾讯计算机系统有限公司于本判决生效之日解除原告黄某在微信读书中对其微信好友的关注；\u003cbr\u003e\n三、被告深圳市腾讯计算机系统有限公司于本判决生效之日解除原告黄某的微信好友在微信读书中对原告黄某的关注；\u003cbr\u003e\n四、被告深圳市腾讯计算机系统有限公司于本判决生效之日停止将原告黄某使用微信读书软件生成的信息（包括读书时长、书架、正在阅读的读物）向原告黄某共同使用微信读书的微信好友展示的行为；\u003cbr\u003e\n五、被告腾讯科技（深圳）有限公司于本判决生效之日起 7 日内以书面形式向原告黄某赔礼道歉（致歉内容须经法院审核；逾期不履行的，法院将选择一家全国公开发行的报纸刊登本判决主要内容，费用由该公司负担）；\u003cbr\u003e\n六、被告深圳市腾讯计算机系统有限公司于本判决生效之日起 7 日内以书面形式向原告黄某赔礼道歉（审核与替代执行方式同上）；\u003cbr\u003e\n七、被告腾讯科技（深圳）有限公司、腾讯科技（北京）有限公司、深圳市腾讯计算机系统有限公司于本判决生效之日起 7 日内\u003cstrong\u003e连带赔偿原告黄某公证费 6660 元\u003c/strong\u003e；\u003cbr\u003e\n八、驳回原告黄某的其他诉讼请求。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e案件受理费 300 元\u003c/strong\u003e，由三被告负担。判决书载明：如不服本判决，可在判决书送达之日起十五日内向\u003cstrong\u003e北京市第四中级人民法院\u003c/strong\u003e提出上诉。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e生效状态\u003c/strong\u003e：据案例库体例文本（该文本经新闻平台承载，\u003cstrong\u003e非官方渠道\u003c/strong\u003e）载「宣判后，原、被告均未提起上诉，该判决已生效」；官方渠道的生效证明未取得。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e知情同意是实质标准而非形式条款\u003c/strong\u003e：即便用户协议有约定，若对好友列表、读书信息等重要事项\u003cstrong\u003e未充分告知\u003c/strong\u003e，致使一般用户对两款应用中的「好友」产生混淆，\u003cstrong\u003e不能视为获得有效知情同意\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e「人格画像」与信息化「人设」自主权\u003c/strong\u003e：读书信息可用于刻画用户的「人格画像」，用户应享有自主建立或拒绝建立信息化「人设」的自由，其前提是\u003cstrong\u003e清晰、明确地知晓\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e隐私与个人信息权益的分野\u003c/strong\u003e：隐私为防御性权利、注重精神利益；个人信息权益注重预防侵害并具有财产利益与积极利用可能。信息呈现方式未达一般理性标准下的「私密性」的，\u003cstrong\u003e不构成隐私权侵害\u003c/strong\u003e，但处理行为仍可能侵害个人信息权益。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e平台的角色影响义务范围\u003c/strong\u003e：两款独立应用共用好友关系，超出用户合理预期，是该案认定同意无效的关键场景因素。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e裁判时实际适用（据一审判决书全文「判决依据」段）\u003c/strong\u003e：《中华人民共和国民法总则》第一百一十一条；《中华人民共和国侵权责任法》第八条、第十五条；《中华人民共和国网络安全法》第四十三条、第七十六条第（五）项；《最高人民法院关于审理利用信息网络侵害人身权益民事纠纷案件适用法律若干问题的规定》第十二条、第十六条、第十八条。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e时际法说明\u003c/strong\u003e：《民法总则》《侵权责任法》已随《中华人民共和国民法典》施行而废止；《网络安全法》与上述司法解释此后亦经修改或替代。援引时应核对现行有效文本，\u003cstrong\u003e不得直接以现行法评价本案裁判\u003c/strong\u003e。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e对照规则（发布在后，非本案裁判依据）\u003c/strong\u003e\u003c/p\u003e","title":"【在先经典】黄某诉腾讯科技（深圳）有限公司等个人信息权益网络侵权责任纠纷案（微信读书案）"},{"content":"案件名称与案号 凌某某与北京微播视界科技有限公司隐私权、个人信息权益网络侵权责任纠纷案（业内通称「抖音通讯录推荐案」）\n一审 北京互联网法院，2020-07-30 一审宣判；案号 (2019)京0491民初6694号 系非官方来源载录，未见于任何官方发布页，故标 ``，不因转载普遍而视为已核。\n专题归属：在先经典（2021 年前）。该案裁判时《个人信息保护法》尚未施行。\n关键词 民事 / 个人信息权益 / 隐私权 / 通讯录信息 / 社交关系 / 地理位置信息 / 必要原则\n基本案情 凌某某在手机通讯录除本人外没有其他联系人的情况下，使用该手机号码注册登录抖音 APP 后，被推荐大量「可能认识的人」。凌某某认为抖音 APP 非法获取其个人信息，侵害其个人信息权益和隐私权，将抖音 APP 的运营者北京微播视界科技有限公司诉至北京互联网法院。（据人民网·法治频道 2020-07-31 报道）\n法院审理与说理 以下据人民网·法治频道 2020-07-31 报道所载北京互联网法院认定，逐段引述：\n关于姓名和手机号码：凌某某的姓名和手机号码属于个人信息，微播视界公司构成侵权。在处理手机通讯录中联系人的姓名和手机号码时，一般情况下应征得手机用户及联系人的双重同意；但如果要求在任何使用场景下都必须严格征得双重同意，有可能会导致具体场景下利益的失衡，因此需要在具体应用场景中考察是否存在构成个人信息合理使用的情形。 合理使用应符合必要原则：微播视界公司读取及匹配通讯录的行为不会对凌某某产生打扰，通常亦不会不合理地损害其利益，且可满足其他有社交需求用户的利益和行业发展的需要，属于对该信息的合理使用；但该合理使用应符合必要原则——在凌某某未注册时，其没有在抖音 APP 中建立社交关系的可能，微播视界公司从其他用户手机通讯录收集到凌某某的姓名和手机号码后，通过匹配可以知道软件内没有使用该手机号码作为账户的用户，应当及时删除该信息；但直至凌某某起诉时，该信息仍然存储于抖音 APP 的后台系统中，超出必要限度，不属于合理使用，构成侵权。 关于社交关系：凌某某的社交关系属于个人信息，微播视界公司构成侵权。社交关系表现为在其他用户手机通讯录中存储了凌某某的姓名和手机号码，此信息分布记录于其他用户的手机通讯录中，虽然并未以列表形式体现，却能够体现出凌某某的社交关系，属于凌某某的个人信息，构成侵权。 关于地理位置：「地理位置」属于个人信息，微播视界公司构成侵权。位置信息能够起到识别个人特征的作用，属于个人信息，与该位置的精确程度并无直接关系；IP 地址并不必然等同于地理位置，即使通过 IP 地址分析用户所在地理位置，亦属于对信息的进一步处理和使用，需征得同意。微播视界公司在未征得凌某某同意的情况下，收集凌某某地理位置信息，构成侵权。 关于隐私权：凌某某的上述信息不具有私密性，微播视界公司推荐有限的「可能认识的人」，不构成对凌某某生活安宁的侵扰，不存在侵害凌某某隐私权的行为。 裁判结果 据人民网·法治频道 2020-07-31 报道列明的判项：\n微播视界公司于判决生效之日删除 2019 年 2 月 9 日前收集并存储的凌某某姓名和涉案手机号码的个人信息； 微播视界公司于判决生效之日删除未经凌某某同意通过抖音软件收集并存储的其地理位置信息； 微播视界公司于判决生效之日起 7 日内以书面形式向凌某某道歉； 微播视界公司于判决生效之日起 7 日内赔偿凌某某经济损失 1000 元及维权合理费用 4231 元； 驳回凌某某的其他诉讼请求。 判项的文字表述以判决书为准，\n数据法 / AI 法要点 通讯录联系人信息的「双重同意」与其例外：原则上应征得手机用户及联系人的双重同意，但须在具体应用场景中考察是否构成合理使用，以避免场景下利益失衡。 合理使用的边界是必要原则：当信息对实现处理目的已无必要（如未注册用户不可能据此建立社交关系），应当及时删除；继续存储即超出必要限度而构成侵权。 「社交关系」可构成个人信息，即便未以好友列表形式呈现，只要能够体现特定自然人的社交关系即属之（本案作于《个人信息保护法》施行前，现行法下对应「个人信息」的可识别性判断）。 位置信息与 IP 地址：位置信息属于个人信息，与精确程度无关；IP 地址并不必然等同于地理位置，由 IP 地址分析地理位置属于进一步的处理和使用，需另行取得同意。 隐私与个人信息的分野：个人信息处理行为未侵害私密性、未侵扰生活安宁的，不构成隐私权侵害，但仍可能侵害个人信息权益。 相关法条 裁判时实际适用：官媒报道未列明裁判所引条文号。\n对照规则（发布在后，非本案裁判依据）\n现行法对照：《个人信息保护法》第 6 条（处理个人信息应具有明确、合理的目的，限于实现处理目的的最小范围）、第 13 条（处理个人信息的合法性基础）、第 17 条（处理前的告知义务）；《中华人民共和国民法典》第 1035 条（处理个人信息的原则与条件）。 在后的规则文件：最高人民法院关于依法审理涉人工智能纠纷案件的意见（法发〔2026〕10号） 中（三）要求「准确适用民法典、个人信息保护法」等法律认定利用人工智能侵害民事权益的法律责任，并明确以过错责任为原则；本案裁判时该文件尚未发布，仅作对照。（引用体例：该文件各项以（一）至（二十四）编号，正文单元不称「第X条」，本站按原文以「（X）」形式引用。） 权威来源 人民网·法治频道：北京互联网法院：微信读书、抖音侵犯个人信息权（2020-07-31，载两案案号外的判项与法院认定全文） 来源说明：该报道为人民网（中央重点新闻网站）所载法院信息，非判决书全文；该报道非判决书全文。\n站内关联法规 /compliance/china/pipl/ /compliance/china/spc-opinions-ai-disputes-2026/ ","permalink":"https://ai.intlaws.com/cases/china/legacy-douyin-contact-matching/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e凌某某与北京微播视界科技有限公司隐私权、个人信息权益网络侵权责任纠纷案\u003c/strong\u003e（业内通称「抖音通讯录推荐案」）\u003c/p\u003e\n\u003cp\u003e一审 北京互联网法院，2020-07-30 一审宣判；案号 \u003cstrong\u003e(2019)京0491民初6694号\u003c/strong\u003e 系非官方来源载录，\u003cstrong\u003e未见于任何官方发布页\u003c/strong\u003e，故标 ``，\u003cstrong\u003e不因转载普遍而视为已核\u003c/strong\u003e。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e专题归属\u003c/strong\u003e：在先经典（2021 年前）。该案裁判时《个人信息保护法》尚未施行。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 个人信息权益 / 隐私权 / 通讯录信息 / 社交关系 / 地理位置信息 / 必要原则\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e凌某某在手机通讯录除本人外没有其他联系人的情况下，使用该手机号码注册登录抖音 APP 后，被推荐大量「可能认识的人」。凌某某认为抖音 APP 非法获取其个人信息，侵害其个人信息权益和隐私权，将抖音 APP 的运营者北京微播视界科技有限公司诉至北京互联网法院。（据人民网·法治频道 2020-07-31 报道）\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e以下据人民网·法治频道 2020-07-31 报道所载北京互联网法院认定，逐段引述：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e关于姓名和手机号码\u003c/strong\u003e：凌某某的姓名和手机号码属于个人信息，微播视界公司构成侵权。在处理手机通讯录中联系人的姓名和手机号码时，一般情况下应征得手机用户及联系人的\u003cstrong\u003e双重同意\u003c/strong\u003e；但如果要求在任何使用场景下都必须严格征得双重同意，有可能会导致具体场景下利益的失衡，因此需要在具体应用场景中考察是否存在构成\u003cstrong\u003e个人信息合理使用\u003c/strong\u003e的情形。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e合理使用应符合必要原则\u003c/strong\u003e：微播视界公司读取及匹配通讯录的行为不会对凌某某产生打扰，通常亦不会不合理地损害其利益，且可满足其他有社交需求用户的利益和行业发展的需要，属于对该信息的合理使用；但该合理使用应符合必要原则——在凌某某未注册时，其没有在抖音 APP 中建立社交关系的可能，微播视界公司从其他用户手机通讯录收集到凌某某的姓名和手机号码后，通过匹配可以知道软件内没有使用该手机号码作为账户的用户，\u003cstrong\u003e应当及时删除该信息\u003c/strong\u003e；但直至凌某某起诉时，该信息仍然存储于抖音 APP 的后台系统中，\u003cstrong\u003e超出必要限度，不属于合理使用，构成侵权\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e关于社交关系\u003c/strong\u003e：凌某某的社交关系属于个人信息，微播视界公司构成侵权。社交关系表现为在其他用户手机通讯录中存储了凌某某的姓名和手机号码，此信息分布记录于其他用户的手机通讯录中，虽然并未以列表形式体现，却能够体现出凌某某的社交关系，属于凌某某的个人信息，构成侵权。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e关于地理位置\u003c/strong\u003e：「地理位置」属于个人信息，微播视界公司构成侵权。位置信息能够起到识别个人特征的作用，属于个人信息，\u003cstrong\u003e与该位置的精确程度并无直接关系\u003c/strong\u003e；\u003cstrong\u003eIP 地址并不必然等同于地理位置\u003c/strong\u003e，即使通过 IP 地址分析用户所在地理位置，亦属于对信息的进一步处理和使用，需征得同意。微播视界公司在未征得凌某某同意的情况下，收集凌某某地理位置信息，构成侵权。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e关于隐私权\u003c/strong\u003e：凌某某的上述信息不具有私密性，微播视界公司推荐有限的「可能认识的人」，不构成对凌某某生活安宁的侵扰，\u003cstrong\u003e不存在侵害凌某某隐私权的行为\u003c/strong\u003e。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e据人民网·法治频道 2020-07-31 报道列明的判项：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e微播视界公司于判决生效之日删除 2019 年 2 月 9 日前收集并存储的凌某某姓名和涉案手机号码的个人信息；\u003c/li\u003e\n\u003cli\u003e微播视界公司于判决生效之日删除未经凌某某同意通过抖音软件收集并存储的其地理位置信息；\u003c/li\u003e\n\u003cli\u003e微播视界公司于判决生效之日起 7 日内以书面形式向凌某某道歉；\u003c/li\u003e\n\u003cli\u003e微播视界公司于判决生效之日起 7 日内赔偿凌某某经济损失 \u003cstrong\u003e1000 元\u003c/strong\u003e及维权合理费用 \u003cstrong\u003e4231 元\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e驳回凌某某的其他诉讼请求。\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e判项的文字表述以判决书为准，\u003c/p\u003e","title":"【在先经典】凌某某诉北京微播视界科技有限公司隐私权、个人信息权益网络侵权责任纠纷案（抖音通讯录推荐案）"},{"content":"案件名称与案号 深圳市腾讯计算机系统有限公司诉上海盈讯科技有限公司著作权权属、侵权纠纷案（业内通称「Dreamwriter 案」、「人工智能写作第一案」）\n一审 广东省深圳市南山区人民法院，(2019)粤0305民初14010号（该案号未见于官方发布页，仅见于非官方转载，标 ``）\n专题归属：在先经典（2021 年前）。该案裁判时《个人信息保护法》尚未施行，人工智能生成内容的著作权规则亦无专门立法。\n关键词 民事 / 著作权 / 人工智能生成内容 / 文字作品 / 独创性 / 信息网络传播权\n基本案情 据国家版权局官网所载报道（2020-01-08）：\nDreamwriter 是腾讯公司自主研发的一套基于数据和算法的智能写作辅助系统。2018 年 8 月 20 日，由 Dreamwriter 智能写作助手创作完成的《午评：沪指小幅上涨0.11%报2671.93点 通信运营、石油开采等板块领涨》的财经报道文章，在腾讯证券网站上首次发表，并在文章末尾注明「本文由腾讯机器人 Dreamwriter 自动撰写」。\n被告上海盈讯科技有限公司未经腾讯公司许可，在该文章发表当日擅自复制涉案文章，通过其经营的「网贷之家」网站向公众传播，且发布的内容和涉案文章内容完全相同。腾讯公司认为被告的行为侵犯其享有的著作权，遂将其诉至法院。上海盈讯公司在庭审中认可腾讯公司主张的事实。\n法院审理与说理 据国家版权局官网所载报道（2020-01-08）转述的南山区人民法院认定：\n从外在表现形式看：Dreamwriter 创作的财经报道文章，符合文字作品的形式要求，内容体现出对当日上午相关股市信息、数据的选择、分析、判断，文章结构合理、表达逻辑清晰，具有一定的独创性。 从生成过程看：该文章的表现形式是由腾讯公司主创团队相关人员个性化的安排与选择所决定的，其表现形式并非唯一，具有一定的独创性。 结论：Dreamwriter 软件在技术上「生成」的创作过程均满足著作权法对文字作品的保护条件，属于我国著作权法所保护的文字作品。 据最高人民法院官网英文版所载报道（2020-01-09，原载 China Daily Global）：深圳市南山区人民法院认定被告上海盈讯科技有限公司侵害了腾讯公司的著作权，应当承担民事责任。\n裁判结果 据国家版权局官网所载报道（2020-01-08）：南山法院一审判决上海盈讯公司侵犯了腾讯公司所享有的信息网络传播权，应承担相应的民事责任；鉴于被告已经删除侵权作品，法院判定被告赔偿原告经济损失及合理的维权费用人民币 1500 元。该报道同时载明：截至发稿，该案判决正在上诉期内。\n判项的文字表述以判决书为准，\n数据法 / AI 法要点 人工智能生成内容可构成著作权法上的「文字作品」：其判断包含两个维度——外在表现形式（内容体现对数据与信息的选择、分析、判断，结构合理、表达逻辑清晰）与生成过程（由人的「个性化的安排与选择」所决定，表现形式并非唯一）。 保护对象的落点在人：该案把独创性归于主创团队相关人员的个性化安排与选择，而非机器本身（本案裁判时《个人信息保护法》与生成式人工智能专门规范均未出台）。 侵权类型：未经许可复制并在网站向公众传播，侵害信息网络传播权；被告删除侵权作品的情节影响了赔偿责任的具体承担方式。 时际法提示：人工智能生成内容的著作权认定规则在此后有新的发展（参见站内收录的「AI 文生图」等在后案例），不得以本案结论直接推断在后案件的结果。 相关法条 裁判时实际适用：据官方渠道报道，该案认定涉案文章构成文字作品并认定侵害信息网络传播权，适用《中华人民共和国著作权法》关于文字作品与信息网络传播权的规定；具体条文号官方报道未列明。\n对照规则（发布在后，非本案裁判依据）\n现行法对照：《中华人民共和国著作权法》第 3 条（作品类型，含文字作品）、第 10 条（著作权的内容，含信息网络传播权）。 在后的规则文件：最高人民法院关于依法审理涉人工智能纠纷案件的意见（法发〔2026〕10号） 中（十二）「依法规制涉人工智能侵害知识产权的行为」规定：人工智能生成内容侵害他人著作权的，人民法院应当综合考量人工智能服务类型、行业特点、训练数据来源、各方参与度、采取的必要措施以及获利情况等因素，依法合理认定人工智能开发者、提供者、使用者的责任；人工智能开发者提出不侵权抗辩的，应当责令其提供训练数据来源、训练过程记录、模型运行模式以及科学理论依据等予以佐证。该文件 2026-09-07 发布，本案裁判时尚未发布，仅作对照。（引用体例：该文件各项以（一）至（二十四）编号，官方概括为「5 个部分、共 24 条」，正文单元不称「第X条」，本站按原文以「（X）」形式引用。） 权威来源 国家版权局官网：法院认定AI生成内容为作品，享有著作权（2020-01-08，转载自《中国知识产权资讯网》，作者姜旭；载基本案情、南山法院认定与判赔 1500 元、上诉期状态） 最高人民法院官网英文版：Court rules AI-written article has copyright（2020-01-09，原载 China Daily Global） 来源说明：前者为国家版权局官网页面，其内容转载自《中国知识产权资讯网》（页面已注明来源与作者），系官方站点承载的转载报道；后者为最高人民法院官网英文版所载报道。两者均非判决书全文。\n站内关联法规 /compliance/china/spc-opinions-ai-disputes-2026/ ","permalink":"https://ai.intlaws.com/cases/china/legacy-dreamwriter-tencent/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e深圳市腾讯计算机系统有限公司诉上海盈讯科技有限公司著作权权属、侵权纠纷案\u003c/strong\u003e（业内通称「Dreamwriter 案」、「人工智能写作第一案」）\u003c/p\u003e\n\u003cp\u003e一审 广东省深圳市南山区人民法院，\u003cstrong\u003e(2019)粤0305民初14010号\u003c/strong\u003e（该案号\u003cstrong\u003e未见于官方发布页\u003c/strong\u003e，仅见于非官方转载，标 ``）\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e专题归属\u003c/strong\u003e：在先经典（2021 年前）。该案裁判时《个人信息保护法》尚未施行，人工智能生成内容的著作权规则亦无专门立法。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 著作权 / 人工智能生成内容 / 文字作品 / 独创性 / 信息网络传播权\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e据国家版权局官网所载报道（2020-01-08）：\u003c/p\u003e\n\u003cp\u003eDreamwriter 是腾讯公司自主研发的一套基于数据和算法的智能写作辅助系统。2018 年 8 月 20 日，由 Dreamwriter 智能写作助手创作完成的《午评：沪指小幅上涨0.11%报2671.93点 通信运营、石油开采等板块领涨》的财经报道文章，在腾讯证券网站上首次发表，并在文章末尾注明「本文由腾讯机器人 Dreamwriter 自动撰写」。\u003c/p\u003e\n\u003cp\u003e被告上海盈讯科技有限公司未经腾讯公司许可，在该文章发表当日擅自复制涉案文章，通过其经营的「网贷之家」网站向公众传播，且发布的内容和涉案文章内容完全相同。腾讯公司认为被告的行为侵犯其享有的著作权，遂将其诉至法院。上海盈讯公司在庭审中认可腾讯公司主张的事实。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e据国家版权局官网所载报道（2020-01-08）转述的南山区人民法院认定：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e从外在表现形式看\u003c/strong\u003e：Dreamwriter 创作的财经报道文章，符合\u003cstrong\u003e文字作品的形式要求\u003c/strong\u003e，内容体现出对当日上午相关股市信息、数据的选择、分析、判断，文章结构合理、表达逻辑清晰，\u003cstrong\u003e具有一定的独创性\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e从生成过程看\u003c/strong\u003e：该文章的表现形式是由腾讯公司\u003cstrong\u003e主创团队相关人员个性化的安排与选择\u003c/strong\u003e所决定的，其表现形式并非唯一，\u003cstrong\u003e具有一定的独创性\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e结论\u003c/strong\u003e：Dreamwriter 软件在技术上「生成」的创作过程均满足著作权法对文字作品的保护条件，\u003cstrong\u003e属于我国著作权法所保护的文字作品\u003c/strong\u003e。\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e据最高人民法院官网英文版所载报道（2020-01-09，原载 China Daily Global）：深圳市南山区人民法院认定被告上海盈讯科技有限公司侵害了腾讯公司的著作权，应当承担民事责任。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e据国家版权局官网所载报道（2020-01-08）：南山法院一审判决上海盈讯公司\u003cstrong\u003e侵犯了腾讯公司所享有的信息网络传播权\u003c/strong\u003e，应承担相应的民事责任；\u003cstrong\u003e鉴于被告已经删除侵权作品\u003c/strong\u003e，法院判定被告赔偿原告经济损失及合理的维权费用人民币 \u003cstrong\u003e1500 元\u003c/strong\u003e。该报道同时载明：截至发稿，该案\u003cstrong\u003e判决正在上诉期内\u003c/strong\u003e。\u003c/p\u003e\n\u003cp\u003e判项的文字表述以判决书为准，\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e人工智能生成内容可构成著作权法上的「文字作品」\u003c/strong\u003e：其判断包含两个维度——外在表现形式（内容体现对数据与信息的选择、分析、判断，结构合理、表达逻辑清晰）与\u003cstrong\u003e生成过程\u003c/strong\u003e（由人的「个性化的安排与选择」所决定，表现形式并非唯一）。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e保护对象的落点在人\u003c/strong\u003e：该案把独创性归于\u003cstrong\u003e主创团队相关人员\u003c/strong\u003e的个性化安排与选择，而非机器本身（本案裁判时《个人信息保护法》与生成式人工智能专门规范均未出台）。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e侵权类型\u003c/strong\u003e：未经许可复制并在网站向公众传播，侵害\u003cstrong\u003e信息网络传播权\u003c/strong\u003e；被告删除侵权作品的情节影响了赔偿责任的具体承担方式。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e时际法提示\u003c/strong\u003e：人工智能生成内容的著作权认定规则在\u003cstrong\u003e此后有新的发展\u003c/strong\u003e（参见站内收录的「AI 文生图」等在后案例），\u003cstrong\u003e不得以本案结论直接推断在后案件的结果\u003c/strong\u003e。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e裁判时实际适用\u003c/strong\u003e：据官方渠道报道，该案认定涉案文章构成\u003cstrong\u003e文字作品\u003c/strong\u003e并认定侵害\u003cstrong\u003e信息网络传播权\u003c/strong\u003e，适用《中华人民共和国著作权法》关于文字作品与信息网络传播权的规定；\u003cstrong\u003e具体条文号\u003c/strong\u003e官方报道未列明。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e对照规则（发布在后，非本案裁判依据）\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e现行法对照\u003c/strong\u003e：《中华人民共和国著作权法》第 3 条（作品类型，含文字作品）、第 10 条（著作权的内容，含信息网络传播权）。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e在后的规则文件\u003c/strong\u003e：\u003ca href=\"/compliance/china/spc-opinions-ai-disputes-2026/\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院关于依法审理涉人工智能纠纷案件的意见（法发〔2026〕10号）\u003c/a\u003e\n 中（十二）「依法规制涉人工智能侵害知识产权的行为」规定：人工智能生成内容侵害他人著作权的，人民法院应当\u003cstrong\u003e综合考量人工智能服务类型、行业特点、训练数据来源、各方参与度、采取的必要措施以及获利情况\u003c/strong\u003e等因素，依法合理认定人工智能开发者、提供者、使用者的责任；人工智能开发者提出不侵权抗辩的，应当责令其提供训练数据来源、训练过程记录、模型运行模式以及科学理论依据等予以佐证。该文件 2026-09-07 发布，\u003cstrong\u003e本案裁判时尚未发布，仅作对照\u003c/strong\u003e。（引用体例：该文件各项以（一）至（二十四）编号，官方概括为「5 个部分、共 24 条」，正文单元\u003cstrong\u003e不称「第X条」\u003c/strong\u003e，本站按原文以「（X）」形式引用。）\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.ncac.gov.cn/xxfb/yjdt/202001/t20200108_49729.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e国家版权局官网：法院认定AI生成内容为作品，享有著作权（2020-01-08，转载自《中国知识产权资讯网》，作者姜旭；载基本案情、南山法院认定与判赔 1500 元、上诉期状态）\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://english.court.gov.cn/2020-01/09/c_761820.htm\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院官网英文版：Court rules AI-written article has copyright（2020-01-09，原载 China Daily Global）\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e来源说明\u003c/strong\u003e：前者为国家版权局官网页面，其内容\u003cstrong\u003e转载自《中国知识产权资讯网》\u003c/strong\u003e（页面已注明来源与作者），系官方站点承载的转载报道；后者为最高人民法院官网英文版所载报道。两者均\u003cstrong\u003e非判决书全文\u003c/strong\u003e。\u003c/p\u003e","title":"【在先经典】深圳市腾讯计算机系统有限公司诉上海盈讯科技有限公司著作权权属、侵权纠纷案（Dreamwriter 生成文章案）"},{"content":" 来源与核验（可核验）\n项目 内容 文书名称 《小型个人信息处理者个人信息保护简化措施规定》 文号 国家互联网信息办公室、中华人民共和国公安部令第 25 号 审议通过 2026 年 6 月 26 日国家互联网信息办公室 2026 年第 14 次室务会会议审议通过，并经公安部同意 签署公布 2026 年 7 月 22 日签署（国家互联网信息办公室主任庄荣文、公安部部长王小洪）；中国网信网 2026 年 7 月 24 日发布 施行日期 2026 年 9 月 1 日（第二十二条） 现行状态 已生效施行、现行有效（截至 2026-09-25） 体例 全文 22 条，不分章；另附《小型个人信息处理者个人信息保护合规审计自查表》《小型个人信息处理者个人信息保护影响评估表》两项附件（官方 PDF） 官方来源 全文：https://www.cac.gov.cn/2026-07/24/c_1786638889704872.htm ；公布消息：https://www.cac.gov.cn/2026-07/24/c_1786638889443160.htm ；中国政府网转发新华社稿：https://www.gov.cn/lianbo/202607/content_7076526.htm 校对记录 2026-09-25 抓取国家网信办全文页；条号 1—22 自「第一条」起连续、无缺号、无空条；文号、通过日期、签署日期、施行日期逐字符复核 一、这是一件什么规格的文件 《小型个人信息处理者个人信息保护简化措施规定》（以下称《规定》）是部门联合规章（国家互联网信息办公室、公安部联合公布），不是法律、也不是行政法规。其上位依据为《中华人民共和国个人信息保护法》《网络数据安全管理条例》（第一条）。\n落地的法律规定是《个人信息保护法》第六十二条关于「国家网信部门统筹协调有关部门针对小型个人信息处理者，制定专门的个人信息保护规则、标准」的要求：本次以专门规章的形式，把针对小规模处理者的义务「减负」条款集中在一件文书中。\n二、适用对象的关键界定 要素 规定内容 条文 适用范围 在中华人民共和国境内的小型个人信息处理者实施个人信息保护 第二条第一款 「小型」的量线 处理不满 10 万人个人信息的个人信息处理者 第二条第二款 处理未成年人信息 处理不满十四周岁未成年人个人信息的，应当制定专门的个人信息处理规则 第四条第三款 需要提示的实务含义：10 万人是处理者规模的界定线，不是出境规模的免报线；两者口径不同，不可互相代入（详见第四节）。\n三、简化措施要点 3.1 处理规则与告知 处理规则的最低内容：处理者名称或姓名、个人行使权利的受理部门或人员及联系方式、处理目的与方式、处理的个人信息种类、保存期限（第四条第一款）。 公开方式的简化：线下收集的，可通过在经营场所醒目位置张贴公告等简便方式公开；线上收集的，可通过服务协议、产品服务客户端弹窗、网站公告等方式公开（第四条第二款）。 园区统一规则：园区、产业基地、商业物业等服务管理单位可统一制定并在显著位置公开规则；同意遵守统一个人信息处理规则且在该规则中被列明的处理者，可以不再制定个人信息处理规则（第五条）。 仅公开规则即视为履行告知义务：需同时满足处理个人信息（不含敏感个人信息）为提供产品或服务所必需、不向其他处理者提供且不对外公开个人信息并在规则中明示两项条件，且规则应以加粗字体、放大字号、标记不同颜色等显著方式提示（第六条）。处理敏感个人信息另有规定的从其规定。 依托网络平台的处理者：同时满足仅通过网络平台开展处理活动且不向平台外提供、平台已制定规则并约定权利义务、处理者声明遵守平台规则且未超出其载明范围三项条件的，可以不再制定处理规则、履行告知义务（第八条第一款）。 3.2 合规审计与影响评估 合规审计：可按《小型个人信息处理者个人信息保护合规审计自查表》的简便方式，至少每五年开展一次，并保存自查表至少五年；法律、行政法规对处理未成年人个人信息的合规审计另有规定的，从其规定（第十三条）。 影响评估：可按《小型个人信息处理者个人信息保护影响评估表》的简便方式开展，并保存影响评估表至少三年（第十四条）。 依托平台的免除重复：平台已开展的合规审计、影响评估覆盖该处理者依托平台开展的处理活动的，可以不再重复开展（第八条第二款）。 认证替代审计：通过个人信息保护认证的小型个人信息处理者，在认证有效期内可以免予开展个人信息保护合规审计（第十七条第二款）。 3.3 个人信息出境 符合下列情形之一的，免予申报数据出境安全评估、订立个人信息出境标准合同、通过个人信息保护认证（第十条第一款）：\n为订立、履行个人作为一方当事人的合同（跨境购物、跨境寄递、跨境汇款、跨境支付、跨境开户、机票酒店预订、签证办理、考试服务等）确需向境外提供的； 按照依法制定的劳动规章制度和依法签订的集体合同实施跨境人力资源管理，确需向境外提供员工个人信息的； 紧急情况下为保护自然人的生命健康和财产安全确需向境外提供的； 为履行法定职责或者法定义务确需向境外提供的； 关键信息基础设施运营者以外的处理者自当年 1 月 1 日起累计向境外提供不满 10 万人个人信息（不含敏感个人信息）的； 法律、行政法规或者国家网信部门规定的其他条件。 两点限制：向境外提供的个人信息不包括重要数据；即便免予出境程序，仍应当按照法律、行政法规的规定履行告知、取得个人单独同意等义务（第十条第二款、第三款）。另经核实，依规申请数据出境安全评估的，可由所在地省级网信部门形成评估结论建议并报国家网信部门核准（第十条第四款）。\n3.4 安全事件与内部制度 可通过在组织管理文件中明确内部管理要求、安全事件应急处置要求等简便方式，建立个人信息保护管理制度与安全事件应急预案（第十五条）。 发生或可能发生个人信息泄露、篡改、丢失的，应当立即采取补救措施并依法通知个人；确因客观条件限制无法通过其他方式通知个人的，可以仅通过在经营场所醒目位置张贴公告、产品服务客户端弹窗和网站公告等简便方式通知，并按规定通知履行个人信息保护职责的部门；涉嫌犯罪的，及时向公安机关报案（第十六条）。 因合并、分立、解散、被宣告破产等需转移个人信息的，可通过经营场所张贴公告、短信提醒、经营者页面公告、小程序公告等简便方式告知接收方信息；且应至少提前 30 个工作日公开发布，公开时长不少于 30 个工作日（第九条）。 3.5 不予处罚与从轻、减轻处罚 应当不予处罚：违法行为轻微并及时改正、没有造成危害后果的；有证据足以证明没有主观过错的（法律、行政法规另有规定的从其规定）；其他依法不予处罚的情形。初次违法且危害后果轻微并及时改正的，可以不予处罚；依法不予处罚的，监管部门应当视情采取约谈、发送提示函等监管措施（第十八条）。 应当从轻或者减轻处罚：主动消除或减轻危害后果；主动供述监管部门尚未掌握的违法行为；发生安全事件时及时通知个人、采取补救措施并主动通知有关部门；配合查处有立功表现；其他法定情形（第十九条）。 监督检查：网信部门、公安机关和其他履行个人信息保护职责的部门可以采取抽查评估、审计报告等方式开展监督检查；发现违法处理个人信息、多次发生个人信息安全事件的，依法处理，并依有关规定记入信用档案、予以公示（第二十一条）。 四、生效日与合规义务适用日分写 文件生效日：本规定自 2026 年 9 月 1 日起施行（第二十二条）。在该日之前，本规定不产生规范效力，此前监管部门不得据以作出处理。 合规义务适用日：本规定的简化措施（如每五年一次的合规审计、附件自查表与评估表、认证免审计、出境豁免清单）自 2026 年 9 月 1 日起适用于小型个人信息处理者开展的相应活动。经检索，全文 22 条未设过渡条款或新旧衔接条款，故不存在「施行前已开展活动如何衔接」的明文安排；同时，本规定属于减负性的专门规则，不构成对《个人信息保护法》《网络数据安全管理条例》既有义务的一般性豁免——未落入简化条件的小型处理者，仍适用上位法的一般规则。 提示：「处理不满 10 万人个人信息」既是本规定的适用门槛（第二条第二款），也在第十条第一款第五项中作为出境免报条件出现；但两者的判定对象不同（前者为处理者处理个人信息的总体规模，后者为自当年 1 月 1 日起累计向境外提供的个人信息规模），实务中不可混用。 五、引用提示 两项附件的具体表格字段以官方 PDF 为准，本页未逐字段抄录； 「小型个人信息处理者」与《促进和规范数据跨境流动规定》项下出境免报情形的组合适用（如处理规模接近 10 万人、同时涉及敏感个人信息出境），需结合个案判断，本页不作结论。 资料来源：国家互联网信息办公室（中国网信网）官方全文页与公布消息页；中国政府网转发新华社稿。整理时间：2026-09-25。本页为采集整理稿，供研究参考，不构成法律意见。\n","permalink":"https://ai.intlaws.com/legislation/small-personal-information-processor-simplification-measures/","summary":"国家互联网信息办公室、公安部令第25号《小型个人信息处理者个人信息保护简化措施规定》于2026年6月26日经国家互联网信息办公室2026年第14次室务会会议审议通过，2026年7月22日签署公布，自2026年9月1日起施行；全文22条，将“小型个人信息处理者”界定为处理不满10万人个人信息的个人信息处理者，并就处理规则、告知同意、合规审计与影响评估、个人信息出境、不予处罚与从轻情形作出简化安排。","title":"小型个人信息处理者个人信息保护简化措施规定（国家网信办、公安部令第25号）自2026年9月1日起施行"},{"content":" 版本与来源（可核验）\n项目 内容 发布机关 最高人民法院 文号 法发〔2026〕10 号 发布日期 2026 年 9 月 7 日 施行日期 文件未载明施行日期（文本无施行条款） 文件性质 司法规范性文件（文号为「法发」而非「法释」，非司法解释） 现行有效 是（截至 2026-09-25） 中文原文来源 https://www.court.gov.cn/zixun/xiangqing/511101.html （最高人民法院官网发布页所载全文） 官方解读 答记者问 https://www.court.gov.cn/zixun/xiangqing/511111.html ；理解与适用 https://ipc.court.gov.cn/zh-cn/news/view-6039.html 英文译本 无官方英译本。本网译本待建（已列入本站英文缺译队列），建成前请勿以第三方英文译本替代引用 校对记录 2026-09-25 抓取官方页面；共 5 部分 24 条（官方答记者问表述），正文各项以 （一）—（二十四） 编号、连续无缺号；与官网页面逐字一致 引用体例 该文件属下发的司法规范性文件（文号「法发」），不是司法解释，正文单元以（一）至（二十四）编号、不称「第X条」；引用时应写作「（十六）」「第（十六）项」，不得写作「第（十六）条」 站内关联案例 /cases/china/ （本站涉数据法与人工智能典型案例栏目） 一、总体要求 （一）指导思想\n坚持以习近平新时代中国特色社会主义思想为指导，深入贯彻习近平法治思想，认真贯彻习近平总书记关于网络强国的重要思想，深刻认识人工智能是新一轮科技革命和产业变革的重要驱动力量，坚持发展和安全并重、促进创新和依法治理相结合，依法公正审理涉人工智能纠纷案件，促进提升人工智能技术应用的安全性、可靠性、可控性、公平性，为以中国式现代化全面推进强国建设、民族复兴伟业提供有力司法服务和保障。\n（二）基本原则\n坚持以人为本。发挥司法裁判引领作用，积极引导人工智能增进人民福祉，切实加强数字时代民生权益司法保障。积极稳妥探索、完善涉算法伦理、算法规则等人工智能领域的司法裁判规则和机制建设，用足用好现有法律规定，妥善应对人工智能技术发展带来的规则冲突、社会风险和伦理挑战，促进完善人工智能企业社会责任体系，注重防范和消除算法歧视，依法保障个人在自动化决策中的知情权和选择权，预防和规制滥用人工智能技术侵害人民群众合法权益的行为，促推人工智能为民、向善。\n支持创新发展。尊重科技创新规律和人工智能行业发展实践，以符合法律政策精神、符合技术发展规律的司法裁判支持科技创新和产业创新。探索新型权益司法保护路径，不断加大对人工智能创新成果、创新主体、创新行为、创新环境的保护力度。以包容审慎的态度平衡权益保护与技术产业发展，营造鼓励探索、宽容失败的良好环境。依法规制利用人工智能技术实施的垄断或者不正当竞争，依法保障相关主体开发和利用人工智能技术的权利平等、机会平等、规则平等，加强对中小企业等经营主体权益的平等保护。通过依法公正高效审理涉人工智能纠纷案件，积极引导、推动互联网、大数据、人工智能和实体经济深度融合，助力培育壮大人工智能产业，最大限度释放人工智能赋能经济社会高质量发展的巨大潜力。\n筑牢安全底线。根据人工智能在不同应用场景下对民事主体合法权益可能造成的具体损害以及风险的性质和大小，依法准确认定法律责任。区分通用与专用、开源与闭源等不同类型大模型在技术原理、风险外溢与控制能力上的差异，对开发者、提供者、使用者等主体的法律责任作出合理划分。全面准确贯彻宽严相济刑事政策，对于故意利用人工智能实施的危害国家安全、侵犯公民权益、扰乱社会秩序等犯罪行为，坚决依法严惩；对于在人工智能研发、应用中的创新性行为，依法审慎处理，恪守罪刑法定、罪责刑相适应原则。\n二、依法妥善审理涉人工智能侵权案件，切实维护民事主体合法权益 （三） 准确把握涉人工智能侵权责任的归责原则。准确适用民法典、个人信息保护法、产品质量法、道路交通安全法等相关法律规定，依法认定利用人工智能侵害民事权益产生的法律责任。法律没有明确规定适用无过错责任或者过错推定责任的，应当依照民法典第一千一百六十五条第一款规定的过错责任原则认定行为人是否承担侵权责任。在判断行为人有无过错以及过错程度时，应当综合考量人工智能应用的具体场景、自主化程度、技术与信息透明度、潜在风险及影响范围，人工智能开发者、提供者等相关主体为预防和减少人工智能侵权所采取的措施及技术上的可能性，人工智能使用者对利用人工智能技术实施的侵权行为可能造成损害的预见能力与控制能力等因素。\n（四） 依法规制“AI换脸拟声”“AI复活逝者”等利用生成式人工智能侵害人格权益的行为。利用生成式人工智能处理特定自然人或者死者的姓名、肖像等，不得违反法律、法规，不得违背公序良俗。除法律另有规定的外，未经自然人同意，利用人工智能处理自然人的姓名、肖像等，生成可识别该自然人的虚拟数字形象并使用、公开，该自然人主张行为人侵害其姓名权、肖像权等人格权益的，人民法院依法予以支持。除法律另有规定的外，未经自然人同意，使用自然人的声音作为训练语料，模仿该自然人的音色、语调和发音风格等生成能够识别该自然人的合成人声，该自然人主张行为人侵害其声音权益的，人民法院依法予以支持。操控生成合成的能够识别特定自然人的虚拟数字形象、声音实施不当行为或者发表不实言论，降低该自然人或者他人社会评价的，人民法院应当依法认定构成对名誉权的侵害。利用人工智能技术擅自制作、使用死者的虚拟数字形象致使死者的姓名、肖像、名誉等受到侵害，死者近亲属依据民法典第九百九十四条的规定请求行为人承担民事责任的，人民法院依法予以支持。\n（五） 依法规制利用人工智能实施“网络开盒”“人肉搜索”等侵害自然人隐私权的行为。以刺探隐私为目的，利用人工智能对特定自然人的电话号码、网络账号及社交媒体等公开信息进行追踪、分析，获取私密信息，或者将所获取的私密信息泄露、公开，或者利用所获取信息侵扰私人生活安宁的，应当认定构成对隐私权的侵害。利用人工智能对特定自然人的私密空间、私密活动等实施拍摄、窥视、窃听等行为的，应当认定构成对隐私权的侵害，但是法律另有规定或者该自然人明确同意的除外。\n（六） 依法认定人工智能训练过程中侵害个人信息权益的民事责任。为人工智能模型训练，在合理范围内处理个人自行公开的或者其他已经合法公开的个人信息，且个人未明确拒绝的，一般不认定为侵害个人信息权益的行为。对个人权益有重大影响的，应当依照法律规定取得个人同意。在认定合理范围时，应当综合考量处理个人信息的目的与模型功能的必要性和适当性，所涉个人信息的类型、敏感程度及对个人权益的潜在影响，个人公开信息时的场景及可合理预期的使用范围等因素。\n（七） 审慎认定生成式人工智能服务提供者的侵权责任。生成式人工智能自动生成的内容侵害他人名誉权、隐私权等人格权益，经权利人通知，生成式人工智能服务提供者未及时采取停止生成侵权内容等必要措施的，应当对造成的损害依法承担侵权责任。通知应当包括构成侵权的初步证据及权利人的真实身份信息。网络用户通过输入侵权提示词等方式恶意诱导生成式人工智能生成侵权内容并造成他人损害的，该网络用户应当依法承担侵权责任；经权利人通知，生成式人工智能服务提供者未及时采取停止生成侵权内容、屏蔽相关生成指令等必要措施，权利人依据民法典第一千一百九十五条的规定请求该网络用户、生成式人工智能服务提供者承担民事责任的，人民法院依法予以支持。\n（八） 依法适用人格权侵害禁令制度。自然人、法人或者非法人组织有证据证明行为人利用人工智能正在实施或者即将实施侵害其人格权益的违法行为，不及时制止将使其合法权益受到难以弥补的损害，向人民法院申请采取责令行为人停止有关行为或者责令有关网络服务提供者、生成式人工智能服务提供者停止提供有关服务的措施的，人民法院可以依法作出人格权侵害禁令。在作出人格权侵害禁令时，人民法院应当结合被侵害的人格权类型、违法行为的方式以及可能造成损害的范围、程度等因素，采取相应的禁令措施，不得超出必要限度。\n（九） 准确认定人工智能产品责任。人民法院应当依据产品质量法关于“产品”的定义，依法准确认定以实物为载体的人工智能产品并适用相应的法律规则。人工智能产品存在缺陷造成损害的，生产者、销售者应当依法承担产品责任。在认定人工智能产品是否存在危及人身、财产安全的不合理危险时，应当综合考量人工智能产品的性质与用途、自主学习能力、升级更新情况、用户对系统的控制程度，以及是否符合相关国家标准、行业标准等因素，并重点审查生产者、销售者是否就人工智能产品的适用场景、固有局限及可预见的风险等进行了真实的说明和明确的警示。\n（十） 依法规制“大数据杀熟”“仿冒名人带货”等侵害消费者合法权益的行为。针对同一商品或者服务，经营者利用算法在交易价格等交易条件上实行不合理的差别待遇，侵害他人合法权益造成损害的，人民法院应当依法认定其承担相应的侵权责任。在认定是否构成不合理的差别待遇时，应当根据差别待遇是否对消费者的知情权、自主选择权、公平交易权等造成实质性限制或者损害，是否基于消费者的消费偏好、支付意愿、支付能力、浏览记录等信息形成针对其个人的交易条件，是否违背诚信原则及商业伦理等，综合考量实行差别待遇的理由是否正当、充分、非歧视。经营者提供商品或者服务时，利用人工智能实施“仿冒名人带货”且构成欺诈，消费者依据消费者权益保护法第五十五条的规定主张惩罚性赔偿的，人民法院依法予以支持。\n（十一） 依法认定涉自动驾驶汽车、具备辅助驾驶功能汽车交通事故的赔偿责任。自动驾驶汽车、具备辅助驾驶功能汽车上道路行驶，发生交通事故造成损害的，依据民法典和道路交通安全法有关规定承担赔偿责任。因车辆存在产品缺陷导致交通事故造成损害，当事人请求生产者或者销售者依照民法典第七编第四章的规定承担赔偿责任的，人民法院应予支持。具备辅助驾驶功能的汽车因车辆缺陷与驾驶人的过错行为结合导致同一损害，当事人依据民法典第一千一百七十二条等规定同时请求驾驶人和车辆生产者或者销售者承担赔偿责任的，人民法院依法予以支持。车辆生产者、销售者对自动驾驶汽车、具备辅助驾驶功能汽车的自动化等级、智能程度、性能、用途等进行虚假或者引人误解的宣传，损害消费者合法权益，消费者依据民法典、消费者权益保护法等法律规定请求车辆生产者、销售者承担民事责任的，人民法院依法予以支持。为查明道路交通事故发生原因，人民法院可以要求车辆生产者、销售者或者运营者等数据控制方，在必要范围内提供真实、完整的自动驾驶、辅助驾驶事件记录等查明案件事实所需要的数据。\n三、依法妥善审理涉人工智能知识产权纠纷案件，保障人工智能高质量发展和高水平安全 （十二） 依法规制涉人工智能侵害知识产权的行为。人工智能生成内容侵害他人著作权的，人民法院应当综合考量人工智能服务类型、行业特点、训练数据来源、各方参与度、采取的必要措施以及获利情况等因素，依法合理认定人工智能开发者、提供者、使用者的责任。人工智能开发者提出不侵权抗辩的，应当责令其提供训练数据来源、训练过程记录、模型运行模式以及科学理论依据等予以佐证。权利人主张人工智能提供者利用算法技术侵害其著作权的，应当提供相关证据。人工智能使用者知道或者应当知道在先作品存在，利用人工智能生成与在先作品实质相似的作品且无合理抗辩理由，在先作品权利人请求其承担侵权责任的，人民法院应予支持。利用人工智能实施侵权假冒、虚假宣传、刷量刷单等行为，侵害他人权利或者构成不正当竞争的，依法承担相应责任。\n（十三） 依法合理认定涉人工智能开源软件相关方的法律责任。审理涉开源软件案件，认定开源软件开发者、提供者以及后续开发者、提供者的侵权责任，应当综合考量开源许可协议类型、权利限制的具体内容、安全合规举措和信息披露程度等因素，依法给予开源软件开发者、提供者适当的责任豁免。开源软件开发者、提供者以免费开源的方式提供涉人工智能软件研发所需要的部分代码模块，并公开说明其功能和安全风险，他人使用该代码模块导致侵权的，人民法院可以认定开源软件开发者、提供者不承担侵权责任。\n（十四） 依法规范涉人工智能发明创造的专利授权确权行为。涉人工智能发明创造采用遵循自然规律的技术手段，解决了技术问题，实现了符合自然规律的技术效果的，人民法院应当依法认定其为专利法所保护的客体，但是违反法律、社会公德、损害社会公共利益或者自然人没有实质贡献的除外。自然人使用人工智能完成的发明创造，该自然人对发明创造的实质性特点作出了创造性贡献的，应当认定该自然人为发明人。涉人工智能专利说明书对技术方案的表述，达到本领域普通技术人员能够实现该发明的程度的，应当认定符合公开充分的授权条件。\n（十五） 依法审慎认定涉人工智能技术合同履行的违约责任。人民法院审理涉人工智能技术开发、转让、许可、咨询、服务合同纠纷案件，应当根据合同约定，充分考量人工智能技术研发特点、技术开发方是否尽到合理努力等情形依法认定违约责任。\n（十六） 依法规范涉人工智能数据使用行为。人工智能开发者通过采集生成、衍生创造、受让取得、授权许可等方式合法获取数据并享有相应数据权益的，人民法院应当予以保护。对于构成汇编作品或者符合其他作品构成要件的数据、数据集合，应当依照著作权法予以保护。对于构成商业秘密的数据、数据集合，应当依照反不正当竞争法予以保护。对于不构成商业秘密的数据、数据集合，被诉侵权行为违反反不正当竞争法第十三条规定的，应当依法承担责任。经营者利用数据、算法等技术手段达成垄断协议或者实施滥用市场支配地位等行为的，依法承担相应责任。采取虚构干扰数据、恶意标注数据、对抗样本攻击等技术手段，损害人工智能运行安全的，依法承担相应责任。\n四、完善涉人工智能纠纷案件审理程序规则，依法惩治利用生成式人工智能实施妨害司法秩序等违法犯罪行为 （十七） 依法准确查明涉人工智能纠纷案件事实。基于涉人工智能纠纷案件技术性、专业性强等特点，人民法院应当依法加强诉讼引导和释明，引导当事人围绕争议事实及时全面地完成举证。当事人因客观原因不能自行收集的证据，可申请人民法院调查收集；必要时，人民法院可以依职权调查收集证据。当事人为固定关键技术申请证据保全的，人民法院应当及时依法审查。控制书证、电子数据等证据的当事人无正当理由拒不提交，对方当事人主张该证据的内容不利于控制人的，人民法院可以认定该主张成立。对于涉及人工智能技术原理、运行机制等专业问题的，人民法院应当依法充分发挥人民陪审员、鉴定人、专家辅助人以及技术调查官的作用，辅助查明案件事实。\n（十八） 探索完善涉人工智能纠纷案件证据审查规则。人民法院应当充分考量人工智能技术的复杂性、系统运行的不透明性以及证据收集的特殊性，不断完善适应新技术发展的证据审查规则。对电子数据生成、收集、存储、传输过程的真实性、完整性进行重点审查。对大数据、区块链等不同信息技术产生的证据明确差异化证据审查重点。对大数据分析报告类证据，应当重点审查其原始数据的来源、清洗规则及分析方法的科学性等；对区块链存证类证据，应当重点审查其上链前数据的真实性及技术平台的可靠性等。当事人将人工智能生成内容作为侵权证据的，人民法院应当综合考量提示词的设计及其对生成结果的影响、生成内容与主张权利作品的相似程度、重复测试的一致性，以及模型训练、算法设计、生成内容过滤机制等因素予以认定。\n（十九） 依法规制利用人工智能不当取证等妨害司法秩序的行为。当事人利用人工智能自主学习、自主决策的特性，通过删除或者篡改生成合成内容标识、特定指令输入、选择性结果呈现、对抗性干扰等人为干预或者误导的方式取得虚假证据，捏造民事案件基本事实，进行虚假诉讼，企图侵害国家利益、社会公共利益或者他人合法权益的，人民法院应当依法驳回其诉讼请求，并根据情节轻重予以罚款、拘留；构成犯罪的，依法追究刑事责任。诉讼参与人或者其他人利用人工智能伪造证据，妨碍人民法院审理案件的，依据民事诉讼法第一百一十四条规定处理。诉讼参与人提交诉讼文书、案例检索报告等材料如系使用人工智能生成，在提交法庭前应当认真核实相关法律、司法解释、案例等内容的真实性、准确性，在提交法庭时对使用人工智能辅助情况作出说明，并对有关内容的真实性、准确性依法承担责任。\n（二十） 依法惩治利用人工智能实施的犯罪活动。利用人工智能实施诈骗、侮辱、诽谤、损害商业信誉、商品声誉、侵犯公民个人信息、非法获取计算机信息系统数据、制作、贩卖、传播淫秽物品等行为，构成犯罪的，依法追究刑事责任。行为人激活辅助驾驶功能后利用私自安装的配件逃避辅助驾驶系统监测导致道路交通事故，构成犯罪的，依法追究刑事责任。\n五、加大对涉人工智能纠纷案件审判指导力度，不断健全完善工作机制 （二十一） 充分发挥多元解纷机制作用。人民法院应当积极运用多元解纷机制妥善化解涉人工智能纠纷，推动与人工智能行业主管部门、行业性专业性调解组织、人工智能专家学者等建立联动协同机制，共同开展纠纷化解工作，做实先行调解。立足司法审判职能，推动提升涉人工智能纠纷预防化解的法治化水平，积极通过庭审公开、以案释法等方式明确权利义务、划定行为边界，发挥司法裁判示范引领作用，促进涉人工智能纠纷源头预防、及时化解。\n（二十二） 加强审判监督指导。积极规范适用提级管辖，强化示范引领作用，做实审判监督指导。对涉及重大利益、疑难复杂新类型、具有规则确立意义、需要统一法律适用标准等涉人工智能纠纷案件，由上级人民法院提级审理。充分运用人民法院案例库，加强案例指导工作，促推法律适用统一和人工智能治理规则的完善。\n（二十三） 加强部门协作协同。通过制发司法建议、建立合作机制等多种方式，充分发挥司法职能，服务国家和社会治理。加强与网信、公安、检察以及市场监管等部门衔接协作，建立并落实长效综合治理机制。引导相关企业、平台、行业协会等规范自治，推动形成人工智能行业自律、行政监管、司法保障的全链条保护合力。\n（二十四） 加强国际司法交流合作。妥善审理涉人工智能及数据跨境纠纷案件，在坚持相互尊重、平等互利原则基础上，推进人工智能领域涉外审判交流合作，加强规则对接与互鉴，推动构建更加公平合理、包容开放的人工智能治理体系，促进、保护人工智能生态系统和人类文明的多样性。\n","permalink":"https://ai.intlaws.com/compliance/china/spc-opinions-ai-disputes-2026/","summary":"《最高人民法院关于依法审理涉人工智能纠纷案件的意见》官方文本：2026 年 9 月 7 日发布（法发〔2026〕10 号），首部由国家最高审判机构发布的涉人工智能司法裁判规则文件，共 5 部分 24 条，就归责原则、AI 换脸拟声、AI「幻觉」侵权、网络开盒、模型训练个人信息处理、生成式人工智能服务提供者责任、产品责任、大数据杀熟、自动驾驶权责、涉 AI 知识产权、开源软件、专利授权确权、证据审查与惩治利用 AI 犯罪等作出规定。","title":"最高人民法院关于依法审理涉人工智能纠纷案件的意见"},{"content":"案件名称与案号 某文化公司诉某网络科技公司侵害作品信息网络传播权纠纷案\n——使用检索增强生成技术的 AI 搜索引擎服务提供者的侵权责任边界\n一审 上海市徐汇区人民法院 ｜ 二审 上海知识产权法院 ｜ 发布：最高人民法院《人民法院网络法治典型案例》（2026-09-16 发布）案例三\n关键词 民事 / 著作权 / 信息网络传播权 / AI 搜索引擎 / 检索增强生成（RAG） / 算法备案 / 注意义务\n基本案情 某网络科技公司基于某大语言模型（已通过国家网信办的生成合成类算法备案），使用检索增强生成技术（使用外部知识源对搜索结果进行补充完善，以提供精准搜索服务）开发并运营某 AI 搜索引擎平台。\n某文化公司享有《某兵》《某花》两部电视剧的信息网络传播权。2024 年 11 月 28 日，某文化公司在案涉搜索引擎平台分别搜索上述两部电视剧，首位搜索结果是第三方网盘分享链接，链接提供的视频内容与两部电视剧内容一致。2024 年 12 月 5 日，某文化公司向某网络科技公司提出下架搜索结果等要求，某网络科技公司当日即删除了案涉搜索结果。某文化公司向法院起诉，请求判令某网络科技公司赔偿经济损失。\n法院审理与说理 一审（上海市徐汇区人民法院） 经审理认为：\n案涉网盘分享链接侵害了某文化公司对《某兵》《某花》两部电视剧的信息网络传播权，但某网络科技公司作为某 AI 搜索引擎平台的网络服务提供者，未主动上传案涉侵权视频的网盘分享链接，不构成直接侵权； 由于某 AI 搜索引擎平台展示的是源自公共互联网网页的内容，在现阶段现有技术无法自动识别侵权信息，且某网络科技公司已履行模型算法的备案义务，在获悉侵权信息后及时作出有效处理，尽到了注意义务，亦不构成帮助侵权。 二审（上海知识产权法院）：某文化公司不服一审判决提起上诉，2025 年 12 月 25 日二审判决驳回上诉、维持原判。\n说理中的义务梯度：官方发布文本在典型意义部分明确，与一般搜索引擎的网络服务不同，使用检索增强生成技术的搜索引擎服务的检索结果精准性、个性化更强，人民法院在适用民法典第一千一百九十七条等规定认定网络服务提供者侵权责任时，应当考虑技术特点、服务模式、检索结果生成过程等因素。\n裁判结果 一审：2025 年 7 月 1 日，上海市徐汇区人民法院判决驳回某文化公司全部诉讼请求。 二审：某文化公司提起上诉，2025 年 12 月 25 日，上海知识产权法院作出二审判决，驳回上诉，维持原判。 数据法 / AI 法要点 注意义务与「算法、数据优势」相匹配：本案确立的规则是，搜索引擎服务提供者应当依法承担与其算法、数据优势程度相匹配的注意义务，对检索增强生成技术的算法合规负有更重的证明责任。 「明知或者应知」的认定重内容来源与控制能力：检索信息来源于互联网，服务提供者未主动上传、编辑、推荐该信息，不符合明知或者应知的主观状态；在知悉侵权信息后及时作出有效处理的，不具有侵权过错，不构成侵权。 算法备案与合规动作在司法上被计入评价：本案将「已履行模型算法的备案义务」「收到通知当日下架」作为认定其已尽注意义务的因素。这为生成式 AI 服务提供者的行政合规动作在民事侵权责任认定中产生正向作用，提供了可援引的裁判样本。 利益平衡的取向：本案的处理被官方表述为有利于实现著作权人、技术创新者、社会公共利益三者之间的利益平衡，推动形成支持和规范网络领域科技创新的法治环境。 相关法条 《中华人民共和国民法典》第一千一百九十七条（网络服务提供者知道或者应当知道网络用户利用其网络服务侵害他人民事权益，未采取必要措施的，与该网络用户承担连带责任）——官方发布文本直接引述该条。 《最高人民法院关于审理侵害信息网络传播权民事纠纷案件适用法律若干问题的规定》——官方发布文本称该规定细化了「明知或者应知」的考量因素。 《生成式人工智能服务管理暂行办法》项下的算法备案义务（官方文本表述为「生成合成类算法备案」，未点明具体文件名称）。 权威来源 最高人民法院《人民法院网络法治典型案例》发布文本（2026-09-16） 组级发布口径：最高人民法院官网「典型案例发布」栏目 材料来源：最高人民法院 2026 年 9 月 16 日《人民法院网络法治典型案例》发布文本（案例三）\n站内关联法规 最高人民法院关于依法审理涉人工智能纠纷案件的意见 人工智能生成合成内容标识办法 ","permalink":"https://ai.intlaws.com/cases/china/shxh-ai-rag-search-liability/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e某文化公司诉某网络科技公司侵害作品信息网络传播权纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——使用检索增强生成技术的 AI 搜索引擎服务提供者的侵权责任边界\u003c/p\u003e\n\u003cp\u003e一审 上海市徐汇区人民法院 ｜ 二审 上海知识产权法院 ｜ \u003cstrong\u003e发布\u003c/strong\u003e：最高人民法院《人民法院网络法治典型案例》（2026-09-16 发布）案例三\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 著作权 / 信息网络传播权 / AI 搜索引擎 / 检索增强生成（RAG） / 算法备案 / 注意义务\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e某网络科技公司基于某大语言模型（已通过国家网信办的生成合成类算法备案），使用\u003cstrong\u003e检索增强生成技术\u003c/strong\u003e（使用外部知识源对搜索结果进行补充完善，以提供精准搜索服务）开发并运营某 AI 搜索引擎平台。\u003c/p\u003e\n\u003cp\u003e某文化公司享有《某兵》《某花》两部电视剧的信息网络传播权。2024 年 11 月 28 日，某文化公司在案涉搜索引擎平台分别搜索上述两部电视剧，\u003cstrong\u003e首位搜索结果是第三方网盘分享链接\u003c/strong\u003e，链接提供的视频内容与两部电视剧内容一致。2024 年 12 月 5 日，某文化公司向某网络科技公司提出下架搜索结果等要求，\u003cstrong\u003e某网络科技公司当日即删除了案涉搜索结果\u003c/strong\u003e。某文化公司向法院起诉，请求判令某网络科技公司赔偿经济损失。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e一审（上海市徐汇区人民法院）\u003c/strong\u003e 经审理认为：\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003e案涉网盘分享链接侵害了某文化公司对《某兵》《某花》两部电视剧的信息网络传播权，但某网络科技公司作为某 AI 搜索引擎平台的\u003cstrong\u003e网络服务提供者，未主动上传案涉侵权视频的网盘分享链接，不构成直接侵权\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e由于某 AI 搜索引擎平台展示的是\u003cstrong\u003e源自公共互联网网页的内容\u003c/strong\u003e，在现阶段现有技术无法自动识别侵权信息，且某网络科技公司\u003cstrong\u003e已履行模型算法的备案义务\u003c/strong\u003e，在获悉侵权信息后\u003cstrong\u003e及时作出有效处理\u003c/strong\u003e，尽到了注意义务，\u003cstrong\u003e亦不构成帮助侵权\u003c/strong\u003e。\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003e\u003cstrong\u003e二审（上海知识产权法院）\u003c/strong\u003e：某文化公司不服一审判决提起上诉，2025 年 12 月 25 日二审判决驳回上诉、维持原判。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e说理中的义务梯度\u003c/strong\u003e：官方发布文本在典型意义部分明确，与一般搜索引擎的网络服务不同，使用检索增强生成技术的搜索引擎服务的\u003cstrong\u003e检索结果精准性、个性化更强\u003c/strong\u003e，人民法院在适用民法典第一千一百九十七条等规定认定网络服务提供者侵权责任时，应当考虑\u003cstrong\u003e技术特点、服务模式、检索结果生成过程\u003c/strong\u003e等因素。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e一审：\u003cstrong\u003e2025 年 7 月 1 日\u003c/strong\u003e，上海市徐汇区人民法院判决\u003cstrong\u003e驳回某文化公司全部诉讼请求\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e二审：某文化公司提起上诉，\u003cstrong\u003e2025 年 12 月 25 日\u003c/strong\u003e，上海知识产权法院作出二审判决，\u003cstrong\u003e驳回上诉，维持原判\u003c/strong\u003e。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003e注意义务与「算法、数据优势」相匹配\u003c/strong\u003e：本案确立的规则是，搜索引擎服务提供者应当依法承担\u003cstrong\u003e与其算法、数据优势程度相匹配的注意义务\u003c/strong\u003e，对检索增强生成技术的\u003cstrong\u003e算法合规负有更重的证明责任\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e「明知或者应知」的认定重内容来源与控制能力\u003c/strong\u003e：检索信息来源于互联网，服务提供者\u003cstrong\u003e未主动上传、编辑、推荐\u003c/strong\u003e该信息，不符合明知或者应知的主观状态；在知悉侵权信息后\u003cstrong\u003e及时作出有效处理\u003c/strong\u003e的，不具有侵权过错，不构成侵权。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e算法备案与合规动作在司法上被计入评价\u003c/strong\u003e：本案将「已履行模型算法的备案义务」「收到通知当日下架」作为认定其已尽注意义务的因素。这为生成式 AI 服务提供者的行政合规动作在民事侵权责任认定中产生正向作用，提供了可援引的裁判样本。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e利益平衡的取向\u003c/strong\u003e：本案的处理被官方表述为有利于实现著作权人、技术创新者、社会公共利益三者之间的利益平衡，推动形成支持和规范网络领域科技创新的法治环境。\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e《中华人民共和国民法典》\u003cstrong\u003e第一千一百九十七条\u003c/strong\u003e（网络服务提供者知道或者应当知道网络用户利用其网络服务侵害他人民事权益，未采取必要措施的，与该网络用户承担连带责任）——官方发布文本直接引述该条。\u003c/li\u003e\n\u003cli\u003e《最高人民法院关于审理侵害信息网络传播权民事纠纷案件适用法律若干问题的规定》——官方发布文本称该规定细化了「明知或者应知」的考量因素。\u003c/li\u003e\n\u003cli\u003e《生成式人工智能服务管理暂行办法》项下的\u003cstrong\u003e算法备案\u003c/strong\u003e义务（官方文本表述为「生成合成类算法备案」，未点明具体文件名称）。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/512041.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院《人民法院网络法治典型案例》发布文本（2026-09-16）\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e组级发布口径：\u003ca href=\"https://www.court.gov.cn/zixun/gengduo/104.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院官网「典型案例发布」栏目\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：最高人民法院 2026 年 9 月 16 日《人民法院网络法治典型案例》发布文本（案例三）\u003c/p\u003e","title":"最高人民法院网络法治典型案例：AI搜索引擎检索增强生成（RAG）侵权责任案（某文化公司诉某网络科技公司）"},{"content":"本栏目每一条目对应一篇论文的独立页面，页内所载文字为期刊要目页或出版方所载的摘要原文，不加自撰概括；官方摘要未公开的条目，页面相应注明，不以自撰文字替代。\n一、收录标准：SSCI、CSSCI（含扩展版）、北大核心期刊文章，或同等级别期刊文章；普通期刊文章仅当作者在上述期刊发表过三篇以上方可入选。本批中文文献 12 篇均为 CSSCI 来源期刊（2025—2026 年版，法学类）论文，英文文献 12 篇均为 SSCI 收录期刊论文。\n二、摘要来源：中文文献 12 篇摘要取自中国法学网（中国社会科学院法学研究所主办）各期要目页所载「内容提要」原文；英文文献各篇摘要取自出版方页面所载摘要字段。两篇官方摘要暂未公开的条目，以及一篇官方摘要已随文上线、本页尚待取件补录的条目，均已在该页注明。\n四、著录体例：题名、作者、栏目名均以期刊要目页或原刊题名原文为准，不作改写；三处与官方页面「不同形」的处理特此说明：① 原刊把副标题另起一行、行内不用连接符者（如《中外法学》2026 年第 4 期舒国滢文，原刊两行居中、无标点），站内单行著录以「——」连接主副标题，属单行化排版，非改动原刊标点；② 题名中的外文缩略语（如 AI）与汉字之间按站内排版体例加半角空格，官方要目页无空格者不作改动；③ 题名内引号按站内体例统一为「」，官方要目页作弯引号或书名号者不另改。中文条目「出处」栏的栏目名从官方要目页原文（如「专题：数字法治」「部门法域」）；官方要目页未标栏目者不添。\n三、条目构成：中文文献 12 篇（左栏），外文文献 12 篇（右栏），论文条目一篇一页。左栏另收录阶段性研究综述《人工智能治理研究综述（2026 年 6—9 月）》1 篇，正文分专题梳理该时段文献，并附所据文献清单与来源。\n","permalink":"https://ai.intlaws.com/scholarship/%E5%AD%A6%E7%95%8C%E8%A7%82%E7%82%B9-%E6%A0%B8%E9%AA%8C%E8%AF%B4%E6%98%8E/","summary":"\u003cp\u003e本栏目每一条目对应一篇论文的独立页面，页内所载文字为\u003cstrong\u003e期刊要目页或出版方所载的摘要原文\u003c/strong\u003e，不加自撰概括；官方摘要未公开的条目，页面相应注明，不以自撰文字替代。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e一、收录标准\u003c/strong\u003e：SSCI、CSSCI（含扩展版）、北大核心期刊文章，或同等级别期刊文章；普通期刊文章仅当作者在上述期刊发表过三篇以上方可入选。本批中文文献 12 篇均为 CSSCI 来源期刊（2025—2026 年版，法学类）论文，英文文献 12 篇均为 SSCI 收录期刊论文。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e二、摘要来源\u003c/strong\u003e：中文文献 12 篇摘要取自中国法学网（中国社会科学院法学研究所主办）各期要目页所载「内容提要」原文；英文文献各篇摘要取自出版方页面所载摘要字段。两篇官方摘要暂未公开的条目，以及一篇官方摘要已随文上线、本页尚待取件补录的条目，均已在该页注明。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e四、著录体例\u003c/strong\u003e：题名、作者、栏目名均以期刊要目页或原刊题名原文为准，不作改写；三处与官方页面「不同形」的处理特此说明：① 原刊把副标题另起一行、行内不用连接符者（如《中外法学》2026 年第 4 期舒国滢文，原刊两行居中、无标点），站内单行著录以「——」连接主副标题，属单行化排版，非改动原刊标点；② 题名中的外文缩略语（如 AI）与汉字之间按站内排版体例加半角空格，官方要目页无空格者不作改动；③ 题名内引号按站内体例统一为「」，官方要目页作弯引号或书名号者不另改。中文条目「出处」栏的栏目名从官方要目页原文（如「专题：数字法治」「部门法域」）；官方要目页未标栏目者不添。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e三、条目构成\u003c/strong\u003e：中文文献 12 篇（左栏），外文文献 12 篇（右栏），论文条目一篇一页。左栏另收录阶段性研究综述《人工智能治理研究综述（2026 年 6—9 月）》1 篇，正文分专题梳理该时段文献，并附所据文献清单与来源。\u003c/p\u003e","title":"学界观点·核验说明"},{"content":" Source: California Privacy Protection Agency (CPPA / CalPrivacy) official website\nCollected: 2026-09-24\nOfficial links:\nAnnouncement (2026-01-08): https://cppa.ca.gov/announcements/2026/20260108.html Decision (PDF): https://cppa.ca.gov/pdf/datamasters_order_signed.pdf Case Case/Matter number: Case No. ENF25-172-D-DA (body of the decision; verified 2026-09-24 against the archived original) Authority: California Privacy Protection Agency (CPPA / CalPrivacy) Board Date: announcement 2026-01-08; decision signed 2025-12-30 (signature page: template \u0026ldquo;IT IS SO ORDERED this ____ day of ____, 2025\u0026rdquo; + handwritten \u0026ldquo;30th December\u0026rdquo;; corroborated by the same-batch S\u0026amp;P Global digital signature of 2025-12-30; verified 2026-09-24) Applicable law: California Delete Act — annual data broker registration duty Holding (official text quoted): \u0026ldquo;The first decision requires Rickenbacher Data LLC, d/b/a Datamasters, a Texas-based reseller of personal information for targeted advertising, to pay a $45,000 fine for failing to register as a data broker in violation of California\u0026rsquo;s Delete Act. The decision also orders the company to stop selling all Californians\u0026rsquo; personal information.\u0026rdquo;\n\u0026ldquo;According to the decision, Datamasters bought and resold the names, addresses, phone numbers, and email addresses of millions of people with Alzheimer\u0026rsquo;s disease, drug addiction, bladder incontinence, and other health conditions for targeted advertising. In addition, Datamasters bought and resold lists of people based on age and perceived race, offering \u0026quot;Senior Lists\u0026quot; and \u0026quot;Hispanic Lists,\u0026quot; as well as lists based on political views, grocery store purchases, banking activity, and health-related purchases. The company engaged in these activities in 2024 without registering with the California Data Broker Registry.\u0026rdquo;\n\u0026ldquo;As a result of the Board\u0026rsquo;s decision, Datamasters will stop selling all forms of personal information about Californians, effectively removing it from the marketplace in California.\u0026rdquo;\nJurisdiction: United States (California) ","permalink":"https://ai.intlaws.com/en/cases/%E7%BE%8E%E5%9B%BD-calprivacy%E6%95%B0%E6%8D%AE%E7%BB%8F%E7%BA%AA%E6%89%A7%E6%B3%95-datamasters%E6%A1%88/","summary":"The California Privacy Protection Agency (CPPA / CalPrivacy) Board decided that Rickenbacher Data LLC (d/b/a Datamasters) violated the California Delete Act by failing to register as a data broker: a USD 45,000 fine and a ban on selling Californians\u0026rsquo; personal information. Case number and signature date verified against the archived original (2026-09-24).","title":"Case Collection — US CalPrivacy Data Broker Enforcement: Datamasters (Unregistered Data Broker)"},{"content":" Source: California Privacy Protection Agency (CPPA / CalPrivacy) official website\nCollected: 2026-09-24\nOfficial links:\nAnnouncement (2026-01-08): https://cppa.ca.gov/announcements/2026/20260108.html Decision (PDF): https://cppa.ca.gov/pdf/sp_global_inc_fo_signed.pdf Case Case/Matter number: Case No. ENF25-220-D-SP (body of the decision; verified 2026-09-24 against the archived original) Authority: California Privacy Protection Agency (CPPA / CalPrivacy) Board Date: decision signed 2025-12-30 — extracted verbatim from the PDF digital-signature text layer: Signed by: jill hamer / Date: 2025-12-30 18:45:17 (Jill Hamer, Board Member); announcement 2026-01-08 Applicable law: California Delete Act — annual data broker registration duty Holding (official text quoted): \u0026ldquo;The second decision requires S\u0026amp;P Global, Inc., a New York-based provider of data and technology, to pay a $62,600 fine for failing to register as a data broker due to an administrative error. In addition to the fine, the decision requires S\u0026amp;P Global to adopt procedures for registration and compliance auditing to prevent similar errors in the future.\u0026rdquo;\nJurisdiction: United States (California) ","permalink":"https://ai.intlaws.com/en/cases/%E7%BE%8E%E5%9B%BD-calprivacy%E6%95%B0%E6%8D%AE%E7%BB%8F%E7%BA%AA%E6%89%A7%E6%B3%95-spglobal%E6%A1%88/","summary":"The California Privacy Protection Agency (CPPA / CalPrivacy) Board decided that S\u0026amp;P Global, Inc. failed to register as a data broker due to an administrative error: a USD 62,600 fine plus registration and compliance-audit procedures. Digital signature date 2025-12-30 extracted from the decision\u0026rsquo;s signature panel; case number verified (2026-09-24).","title":"Case Collection — US CalPrivacy Data Broker Enforcement: S\u0026P Global (Unregistered Data Broker)"},{"content":" Source: Colorado General Assembly, official session law (Ch. 131, 2026)\nOfficial link: https://leg.colorado.gov/laws/session-laws/SB26-189/131/download Note: English original text. 本页为官方英文原文;中文译本整理中,发布后将在此链接。\nKey dates: Approved May 14, 2026; applies to consequential decisions made on or after January 1, 2027(义务适用日;生效日与义务适用日分列)\nCHAPTER 131\nCONSUMER AND COMMERCIAL TRANSACTIONS SENATE BILL 26-189\nBY SENATOR(S) Rodriguez and Coleman, Baisley, Amabile, Ball, Benavidez, Bridges, Cutter, Exum, Frizell, Kirkmeyer, Kolker, Lindstedt, Marchman, Pelton B., Pelton R., Rich, Simpson, Snyder; also REPRESENTATIVE(S) Duran and Bacon, Titone, Boesenecker, Brown, Caldwell, Carter, Clifford, English, Flanell, Goldstein, Gonzalez R., Hamrick, Jackson, Lieder, Lindsay, McCormick, Nguyen, Paschal, Rutinel, Slaugh, Smith, Story, Velasco, Winter T., McCluskie.\nAN ACT CONCERNING THE USE OF AUTOMATED DECISION-MAKING TECHNOLOGY IN CONSEQUENTIAL DECISIONS , AND , IN CONNECTION THEREWITH , MAKING AN APPROPRIATION .\nBe it enacted by the General Assembly of the State of Colorado:\nSECTION 1. In Colorado Revised Statutes, repeal and reenact, with amendments, part 17 of article 1 of title 6 as follows: PART 17 AUTOMATED DECISION-MAKING TECHNOLOGY IN CONSEQUENTIAL DECISIONS 6-1-1701. Definitions. AS USED IN THIS PART 17, UNLESS THE CONTEXT OTHERWISE REQUIRES : (1) \u0026ldquo;A DVERSE OUTCOME \u0026quot; MEANS :\n(a) A DECISION THAT DENIES , TERMINATES , REVOKES , OR MATERIALLY REDUCES OR RESTRICTS A CONSUMER \u0026lsquo;S ACCESS TO , ELIGIBILITY FOR , SELECTION FOR ,\nCOMPENSATION FOR , OR THE PROVISION OF AN OPPORTUNITY OR SERVICE ; OR\n(b) A DECISION THAT RESULTS IN MATERIALLY LESS FAVORABLE DIFFERENTIATED PRICE , COST , COMPENSATION , OR OTHER MATERIAL TERMS THAT ARE REASONABLY LIKELY TO MATERIALLY LIMIT , DELAY , OR EFFECTIVELY DENY , OR OTHERWISE FUNDAMENTALLY ALTER , A CONSUMER \u0026lsquo;S ACCESS TO , ELIGIBILITY FOR , SELECTION\n))))) Capital letters or bold \u0026amp; italic numbers indicate new material added to existing law; dashes through words or numbers indicate deletions from existing law and such material is not part of the act. FOR , COMPENSATION FOR , OR THE PROVISION OF AN OPPORTUNITY OR SERVICE COMPARED TO TERMS OFFERED TO SIMILARLY SITUATED CONSUMERS . IF A DECISION OUTCOME IMPOSES MATERIALLY LESS FAVORABLE DIFFERENTIATED PRICING OR TERMS , THE DECISION OUTCOME MATERIALLY INFLUENCES PRICE , COST SHARING ,\nCOMPENSATION , OR MATERIAL TERMS .\n(2)\n(a) \u0026ldquo;A UTOMATED DECISION-MAKING TECHNOLOGY \u0026quot; OR \u0026ldquo;ADMT\u0026rdquo; MEANS A TECHNOLOGY THAT PROCESSES PERSONAL DATA AND USES COMPUTATION TO GE N E R A TE O U T P U T , IN C L U D IN G P R E D IC T IO N S , R E C O M M E N D A TIO N S ,\nCLASSIFICATIONS , RANKINGS , SCORES , OR OTHER INFORMATION THAT IS USED TO MAKE , GUIDE , OR ASSIST A DECISION , JUDGMENT , OR DETERMINATION CONCERNING AN INDIVIDUAL .\n(b) \u0026ldquo;A UTOMATED DECISION-MAKING TECHNOLOGY \u0026quot; OR \u0026ldquo;ADMT\u0026rdquo; DOES NOT INCLUDE :(I) T HE FOLLOWING TECHNOLOGIES :(A) A NTI-MALWARE ;(B) A NTI-VIRUS ;(C) C ALCULATORS ;(D) D ATABASES ;(E) D ATA STORAGE ;(F) F IREWALLS ;(G) I NTERNET DOMAIN REGISTRATION ;(H) I NTERNET WEBSITE LOADING ;(I) N ETWORKING ;(J) S PAM - AND ROBOCALL-FILTERING ;(K) S PELL-CHECKING ;(L) S PREADSHEETS THAT REQUIRE HUMAN ANALYSIS AND DO NOT USE MACHINE LEARNING , FOUNDATION MODELS , OR LARGE LANGUAGE MODELS ;(M) W EB CACHING ; OR\n(N) W EB HOSTING ;(II) A TOOL USED BY AN INDIVIDUAL SOLELY TO SUMMARIZE , ORGANIZE ,\nTRANSLATE , DRAFT , ROUTE , OR PRESENT INFORMATION FOR HUMAN REVIEW OF ADMINISTRATIVE PROCESSING ; OR (III) TECHNOLOGY THAT COMMUNICATES WITH CONSUMERS IN NATURAL LANGUAGE OR OTHER MEANS READILY UNDERSTOOD BY AN AVERAGE CONSUMER FOR THE PURPOSE OF PROVIDING CONSUMERS WITH INFORMATION , MAKING REFERRALS OR RECOMMENDATIONS , ANSWERING QUESTIONS , OR GENERATING OTHER CONTENT , IF :(A) THE TECHNOLOGY IS NOT CONTRACTED , ADVERTISED , MARKETED ,\nCONFIGURED , OR INTENDED BY A PERSON TO BE USED IN A CONSEQUENTIAL DECISION ; AND\n(B) THE TECHNOLOGY IS SUBJECT TO AN ACCEPTABLE USE POLICY THAT PROHIBITS GENERATED CONTENT TO BE USED IN A CONSEQUENTIAL DECISION .\n(3)\n(a) \u0026ldquo;C ONSEQUENTIAL DECISION \u0026quot; MEANS :(I) A DECISION , DETERMINATION , OR ACTION MADE ABOUT A CONSUMER THAT RELATES TO THE PROVISION OF OR A CONSUMER \u0026lsquo;S ACCESS TO , ELIGIBILITY FOR ,\nSELECTION FOR , OR COMPENSATION FOR A COVERED DOMAIN ; OR\n(II) A DECISION , DETERMINATION , OR ACTION ABOUT A CONSUMER THAT RELATES TO A DIFFERENTIATED PRICE , COST SHARING , COMPENSATION , OR OTHER MATERIAL TERMS IN A MANNER THAT IS REASONABLY LIKELY TO MATERIALLY LIMIT , DELAY ,\nEFFECTIVELY DENY , OR OTHERWISE FUNDAMENTALLY ALTER THE CONSUMER \u0026lsquo;SACCESS , ELIGIBILITY , OR OPPORTUNITY FOR A COVERED DOMAIN .\n(b) \u0026ldquo;C ONSEQUENTIAL DECISION \u0026quot; DOES NOT INCLUDE :(I) LOW-STAKES OR ROUTINE DECISIONS , ACTIONS , AND BUSINESS PROCESSES THAT DO NOT MATERIALLY INFLUENCE ELIGIBILITY FOR , SELECTION FOR , DENIAL OF ,\nCOMPENSATION FOR , PRICING OF , OR ACCESS TO AN OPPORTUNITY OR SERVICE FOR A COVERED DOMAIN , INCLUDING ROUTINE SCHEDULING , CLASSROOM PERSONALIZATION , ADMINISTRATIVE ROUTING , CUSTOMER SERVICE TRIAGE ,\nCOMMUNICATION OF DECISIONS , OR WORKFLOW MANAGEMENT ;(II) A DVERTISING , MARKETING , DIFFERENTIATED PRODUCT RECOMMENDATIONS ,\nSEARCH , OR CONTENT MODERATION ;(III) S PREADSHEETS THAT REQUIRE MANUAL HUMAN ANALYSIS AND DO NOT USE MACHINE LEARNING , FOUNDATION MODELS , OR LARGE LANGUAGE MODELS ;(IV) ACTIONS IN WHICH AN ADMT IS USED TO SUMMARIZE , ORGANIZE , OR PRESENT INFORMATION FOR HUMAN REVIEW AND THE SYSTEM DOES NOT PRODUCE A SCORE , RANKING , RECOMMENDATION , CLASSIFICATION , PREDICTION , OR OTHER INFERENCE THAT MATERIALLY INFLUENCES AN OUTCOME OR A DECISION ;(V) N ARROW PROCEDURAL TASKS OR DATA-PROCESSING FUNCTIONS THAT DO NOT GENERATE A PREDICTION OR INFERENCE ABOUT A CONSUMER OR MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION OR CONSEQUENTIAL DECISION PROCESS ;(VI) A CTIVITIES RELATING TO TECHNOLOGIES USED FOR CYBERSECURITY , SPAM- AND ROBO-CALL FILTERING , SYSTEM RELIABILITY , AND ANTI-MONEY LAUNDERING AND COUNTER-TERRORIST FINANCING CONTROLS ;(VII) A CTIVITIES RELATING TO TECHNOLOGIES USED FOR ECONOMIC SANCTIONS COMPLIANCE , INCLUDING UNDER THE FEDERAL \u0026ldquo;B ANK SECRECY ACT \u0026ldquo;, 12 U.S.C.\nSEC . 1951 ET SEQ .; THE FEDERAL \u0026ldquo;USA PATRIOT ACT \u0026ldquo;, PUB .L. 107-56; THE FEDERAL TRADE COMMISSION \u0026lsquo;S RED FLAGS RULE , 16 CFR 681, AS AMENDED ; AND SANCTIONS PROGRAMS ADMINISTERED BY THE UNITED STATES DEPARTMENT OF THE TREASURY , EXCLUDING FACIAL RECOGNITION UNLESS THE SOLE PURPOSE OF WHICH IS TO CONFIRM AN INDIVIDUAL \u0026lsquo;S IDENTITY ;(VIII) A CTIVITIES RELATING TO TECHNOLOGIES USED FOR FRAUD PREVENTION ,\nINCLUDING IDENTITY VERIFICATION , CONSUMER IDENTIFICATION , MONITORING , AND REPORTING CONTROLS REQUIRED UNDER STATE OR FEDERAL LAW ; OR\n(IX) R OUTINE ACADEMIC ADMINISTRATION AND STUDENT SUPPORT PROCESSES THAT DO NOT MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION .\n(4)\n(a) \u0026ldquo;C ONSUMER \u0026quot; HAS THE MEANING SET FORTH IN SECTION 6-1-1303 (6)(a).\n(b) \u0026ldquo;C ONSUMER \u0026quot; INCLUDES AN EMPLOYEE , A JOB APPLICANT WHO IS A COLORADO RESIDENT , AND ANY INDIVIDUAL WHOSE ACCESS TO , ELIGIBILITY FOR , OR OPPORTUNITY IN COLORADO IS EVALUATED IN A CONSEQUENTIAL DECISION BY A PERSON DOING BUSINESS IN COLORADO .\n(5) \u0026ldquo;C OVERED ADMT\u0026rdquo; MEANS AUTOMATED DECISION-MAKING TECHNOLOGY THAT IS USED TO MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION .\n(6) \u0026ldquo;C OVERED DOMAIN \u0026quot; MEANS :\n(a) A N EDUCATION ENROLLMENT OR AN EDUCATION OPPORTUNITY ;\n(b) E MPLOYMENT OR AN EMPLOYMENT OPPORTUNITY THAT CREATES OR MAY CREATE AN EMPLOYER-EMPLOYEE RELATIONSHIP ;\n(c) T HE LEASE OR PURCHASE OF RESIDENTIAL REAL ESTATE IN COLORADO ;\n(d) A FINANCIAL OR LENDING SERVICE ;\n(e) INSURANCE , INCLUDING UNDERWRITING , PRICING , COVERAGE , CLAIMS ADJUDICATION , OR OTHER DETERMINATIONS THAT MATERIALLY AFFECT ACCESS TO BENEFITS ;\n(f) H EALTH-CARE SERVICES ; OR\n(g) ESSENTIAL GOVERNMENT SERVICES AND PUBLIC BENEFITS , INCLUDING ELIGIBILITY AND RENEWAL DETERMINATIONS .\n(7) \u0026ldquo;D EPLOYER \u0026quot; MEANS A PERSON DOING BUSINESS IN COLORADO THAT DEPLOYS A COVERED ADMT. (8)\n(a) \u0026ldquo;D EVELOPER \u0026quot; MEANS A PERSON DOING BUSINESS IN COLORADO THAT :(I) DEVELOPS , OFFERS , SELLS , LEASES , LICENSES , OR OTHERWISE MAKES COMMERCIALLY AVAILABLE A COVERED ADMT; (II) DEVELOPS A COMPONENT THAT IS DESIGNED , MARKETED , INTENDED ,\nDOCUMENTED , ADVERTISED , CONFIGURED , OR CONTRACTED TO BE USED AS PART OF A COVERED ADMT; OR\n(III) I NTENTIONALLY AND SUBSTANTIALLY MODIFIES AN ADMT SUCH THAT IT BECOMES A COVERED ADMT.\n(b) \u0026ldquo;D EVELOPER \u0026quot; DOES NOT INCLUDE A PERSON THAT :(I) D EVELOPS AND USES AN ADMT: (A) SOLELY FOR RESEARCH PURPOSES AND THE ADMT IS NOT USED IN A CONSEQUENTIAL DECISION IN THE RESEARCH ; OR\n(B) F OR INTERNAL PURPOSES , SUCH AS USE AND DEVELOPMENT ACTIVITIES BY AFFILIATES AND COMMERCIAL SUPPORT FUNCTIONS , AND THAT DOES NOT MAKE THE SYSTEM AVAILABLE TO ANOTHER PERSON FOR USE IN A CONSEQUENTIAL DECISION ;(II) IS A PRECEDING DEVELOPER THAT MAKES AN ADMT COMMERCIALLY AVAILABLE AND AN UNAFFILIATED PERSON MODIFIES THE COVERED ADMT IN A MANNER THAT CHANGES THE SYSTEM \u0026lsquo;S INTENDED , DOCUMENTED , MARKETED ,\nADVERTISED , CONFIGURED , OR CONTRACTED USE ; OR\n(III) HAS DESIGNED , MARKETED , INTENDED , DOCUMENTED , ADVERTISED ,\nCONFIGURED , OR CONTRACTED A COMPONENT THAT IS USED AS PART OF AN ADMT,\nBUT THE COMPONENT IS INTEGRATED INTO A COVERED ADMT WITHOUT THE ACTUAL KNOWLEDGE OF THE PERSON .\n(9) \u0026ldquo;E MPLOYEE \u0026quot; HAS THE MEANING SET FORTH IN SECTION 8-4-101 (5).\n(10) \u0026ldquo;E MPLOYER \u0026quot; HAS THE MEANING SET FORTH IN SECTION 8-4-101 (6).\n(11) \u0026ldquo;FERPA\u0026rdquo; MEANS THE FEDERAL \u0026ldquo;F AMILY EDUCATIONAL RIGHTS AND\nPRIVACY ACT OF 1974\u0026rdquo;, 20 U.S.C. SEC . 1232g ET SEQ ., AND ITS IMPLEMENTING REGULATIONS . (12) \u0026ldquo;I NTENTIONAL AND SUBSTANTIAL MODIFICATION \u0026quot; MEANS A DELIBERATE CHANGE MADE TO AN ADMT THAT RESULTS IN A MATERIAL CHANGE TO THE SYSTEM \u0026lsquo;S INTENDED , DOCUMENTED , ADVERTISED , CONFIGURED , OR CONTRACTED USE .\n(13)\n(a) \u0026ldquo;M ATERIALLY INFLUENCE \u0026quot; MEANS :(I) A N ADMT OUTPUT IS A NON-DE MINIMIS FACTOR THAT IS USED IN MAKING A CONSEQUENTIAL DECISION ; AND (II) A N ADMT OUTPUT AFFECTS THE OUTCOME OF A CONSEQUENTIAL DECISION ,\nINCLUDING BY CONSTRAINING , RANKING , SCORING , RECOMMENDING , CLASSIFYING ,\nOR OTHERWISE MEANINGFULLY ALTERING HOW A CONSEQUENTIAL DECISION IS MADE .\n(b) \u0026ldquo;M ATERIALLY INFLUENCE \u0026quot; DOES NOT INCLUDE INCIDENTAL , TRIVIAL , OR CLERICAL USES .\n(14)\n(a) \u0026ldquo;M ATERIAL UPDATE \u0026quot; MEANS AN UPDATE , PATCH , RELEASE , REVISION , OR NEW VERSION OF A COVERED ADMT, INCLUDING ASSOCIATED SOFTWARE , MODEL PARAMETERS , DEFAULT SETTINGS , OR DOCUMENTATION , THAT A DEVELOPER KNOWS OR REASONABLY SHOULD KNOW IS LIKELY TO MATERIALLY AFFECT :(I) T HE COVERED ADMT\u0026rsquo; S OUTPUTS OR PERFORMANCE IN A MANNER RELEVANT TO ITS INTENDED USE ; OR\n(II) T HE DEVELOPER \u0026lsquo;S STATED INTENDED USE FOR THE COVERED ADMT.\n(b) \u0026ldquo;M ATERIAL UPDATE \u0026quot; DOES NOT INCLUDE ROUTINE MAINTENANCE , COSMETIC CHANGES , OR BUG FIXES THAT DO NOT MATERIALLY INFLUENCE :(I) A COVERED ADMT\u0026rsquo; S OUTPUTS OR PERFORMANCE IN A MANNER RELEVANT TO ITS INTENDED USE ; OR\n(II) A DEVELOPER \u0026lsquo;S STATED INTENDED USE FOR THE COVERED ADMT.\n(15) \u0026ldquo;M EANINGFUL HUMAN REVIEW \u0026quot; MEANS REVIEW BY A INDIVIDUAL DESIGNATED BY THE DEPLOYER WHO HAS AUTHORITY TO APPROVE , MODIFY , OR OVERRIDE A CONSEQUENTIAL DECISION AND WHO :\n(a) C ONSIDERS RELEVANT , AVAILABLE PRIMARY EVIDENCE ;\n(b) I S TRAINED TO CONDUCT THE REVIEW ;\n(c) D OES NOT DEFAULT TO THE SYSTEM OUTPUT ; AND\n(d) H AS ACCESS TO SUFFICIENT INFORMATION TO UNDERSTAND :(I) T HE OUTPUT \u0026lsquo;S:(A) I NTENDED USE ;(B) M ATERIAL LIMITATIONS ; AND\n(C) C ATEGORIES OF INPUTS ; AND\n(II) THE PRINCIPAL FACTORS USED TO GENERATE THE OUTPUT , WITHOUT REQUIRING DISCLOSURE OF PROPRIETARY SOURCE CODE , MODEL WEIGHTS , OR OTHER TRADE SECRETS .\n(16) \u0026ldquo;P ERSONAL DATA \u0026quot; HAS THE MEANING SET FORTH IN SECTION 6-1-1303 (17). (17) \u0026ldquo;T RADE SECRET \u0026quot; HAS THE MEANING SET FORTH IN SECTION 7-74-102 (4).\n6-1-1702. Developer responsibilities - documentation. (1) O N AND AFTER JANUARY 1, 2027, A DEVELOPER SHALL MAKE AVAILABLE TO EACH DEPLOYER OF A COVERED ADMT DEVELOPED BY THE DEVELOPER , IN A FORM AND MANNER THAT IS REASONABLY UNDERSTANDABLE TO A DEPLOYER AND THAT PROTECTS TRADE SECRETS OR INFORMATION PROTECTED FROM DISCLOSURE BY STATE OR FEDERAL LAW :\n(a) A GENERAL STATEMENT DESCRIBING THE INTENDED USES AND KNOWN HARMFUL OR INAPPROPRIATE USES OF THE COVERED ADMT;\n(b) A DESCRIPTION OF THE CATEGORIES OF DATA , INCLUDING PERSONAL DATA ,\nUSED TO TRAIN THE COVERED ADMT, TO THE EXTENT KNOWN ;\n(c) K NOWN LIMITATIONS OF THE COVERED ADMT, INCLUDING KNOWN RISKS AND CIRCUMSTANCES IN WHICH THE COVERED ADMT SHOULD NOT BE USED ;\n(d) INSTRUCTIONS FOR THE DEPLOYER \u0026lsquo;S APPROPRIATE USE , MONITORING , AND MEANINGFUL HUMAN REVIEW , WHERE APPLICABLE ;\n(e) I NFORMATION REASONABLY NECESSARY FOR THE DEPLOYER TO COMPLY WITH SECTION 6-1-1704. IF INFORMATION IS WITHHELD , THE DEVELOPER SHALL NOTIFY THE DEPLOYER .\n(2)\n(a) A DEVELOPER SHALL PROVIDE TO EACH DEPLOYER OF A COVERED ADMT\nDEVELOPED BY THE DEVELOPER A NOTICE OF MATERIAL UPDATES , INTENTIONAL AND SUBSTANTIAL MODIFICATIONS , AND CHANGES TO THE INTENDED USE OF , LIMITATIONS FOR , OR RISK MITIGATION FOR THE COVERED ADMT WITHIN A REASONABLE TIME .\n(b) A DEVELOPER MAY USE PUBLIC RELEASE NOTES CONTAINING THE INFORMATION REQUIRED BY SUBSECTION (2)\n(a) OF THIS SECTION TO COMPLY WITH THIS SUBSECTION\n(2) IF THE DEVELOPER PROVIDES DIRECT NOTICE OF THE PUBLIC RELEASE TO EACH DEPLOYER OF THE COVERED ADMT.\n(3) A DEVELOPER IS SUBJECT TO THE DISCLOSURE REQUIREMENTS DESCRIBED IN SUBSECTIONS\n(1) AND\n(2) OF THIS SECTION ONLY FOR A DEPLOYER \u0026lsquo;S USE OF A COVERED ADMT WHERE THE ADMT WAS MARKETED , ADVERTISED , CONFIGURED ,\nCONTRACTED , SOLD , OR LICENSED TO BE USED TO MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION .\n(4) A DEVELOPER SHALL RETAIN , FOR NOT LESS THAN THREE YEARS AFTER THE CREATION OF A RECORD REQUIRED OR CREATED UNDER THIS SECTION OR FOR A LONGER PERIOD IF REQUIRED BY APPLICABLE STATE OR FEDERAL LAW , RECORDS REASONABLY NECESSARY TO DEMONSTRATE COMPLIANCE WITH THIS SECTION .RECORDS INCLUDE SYSTEM VERSION IDENTIFIERS , CHANGELOGS , AND DOCUMENTATION AND NOTICES OF MATERIAL UPDATES PROVIDED TO DEPLOYERS PURSUANT TO SUBSECTION\n(2) OF THIS SECTION .\n(5) T HIS SECTION APPLIES WHEN A DEVELOPER CREATES A COVERED ADMT THAT IS INTENDED , DOCUMENTED , MARKETED , ADVERTISED , CONFIGURED , OR CONTRACTED TO BE USED TO MAKE CONSEQUENTIAL DECISIONS OR WHEN THE DEVELOPER BECOMES AWARE THAT THE COVERED ADMT IS BEING USED TO MAKE CONSEQUENTIAL DECISIONS IN A MANNER CONSISTENT WITH THE INTENDED AND CONTRACTED USES .\n6-1-1703. Deployer record keeping. A DEPLOYER SHALL RETAIN , FOR NOT LESS THAN THREE YEARS AFTER THE DATE OF A CONSEQUENTIAL DECISION OR FOR A LONGER PERIOD IF REQUIRED BY APPLICABLE STATE OR FEDERAL LAW , RECORDS REASONABLY NECESSARY TO DEMONSTRATE COMPLIANCE WITH THIS PART 17. RECORDS MAY INCLUDE , AS APPLICABLE , COVERED ADMT VERSION IDENTIFIERS , CHANGELOGS , AND DOCUMENTATION OF MATERIAL MITIGATION CHANGES . 6-1-1704. Deployer disclosures - point-of-interaction notice - public posting option - post-adverse outcome disclosures - legislative declaration - trade secrets - compliance with other law - accessibility - rules. (1) P RIOR TO A DEPLOYER USING A COVERED ADMT TO MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION , THE DEPLOYER SHALL PROVIDE A CLEAR AND CONSPICUOUS NOTICE TO A CONSUMER THAT THE DEPLOYER USED OR WILL USE A COVERED ADMT IN A CONSEQUENTIAL DECISION AFFECTING THE CONSUMER AND INSTRUCTIONS REGARDING HOW THE CONSUMER MAY OBTAIN THE ADDITIONAL INFORMATION DESCRIBED IN THIS SECTION .\n(2) A DEPLOYER COMPLIES WITH SUBSECTION\n(1) OF THIS SECTION BY MAINTAINING A PROMINENT PUBLIC NOTICE THAT IS REASONABLY ACCESSIBLE AT POINTS OF CONSUMER INTERACTION , INCLUDING THROUGH A LINK OR POSTING THAT IS REASONABLY PROXIMATE TO THE INTERACTION OR TRANSACTION IN WHICH A CONSEQUENTIAL DECISION MAY OCCUR .\n(3) IF A DEPLOYER USES A COVERED ADMT TO MATERIALLY INFLUENCE A CONSEQUENTIAL DECISION THAT RESULTS IN AN ADVERSE OUTCOME FOR ACONSUMER , THE DEPLOYER SHALL PROVIDE WITHIN THIRTY DAYS AFTER MAKING THE DECISION :\n(a) A PLAIN LANGUAGE DESCRIPTION OF THE CONSEQUENTIAL DECISION AND THE ROLE THE COVERED ADMT PLAYED IN THE CONSEQUENTIAL DECISION ;\n(b) I NSTRUCTIONS AND A SIMPLE-TO-FOLLOW PROCESS TO REQUEST ADDITIONAL INFORMATION ABOUT THE COVERED ADMT AND THE INPUTS , INCLUDING THE NAME OF THE COVERED ADMT, THE COVERED ADMT VERSION NUMBER , IF APPLICABLE ,\nTHE COVERED ADMT DEVELOPER , AND THE TYPES , CATEGORIES , AND SOURCES OF PERSONAL DATA USED , TO THE EXTENT THE DEPLOYER RECEIVES THE NECESSARY INFORMATION FROM THE DEVELOPER IN COMPLIANCE WITH SECTION 6-1-1702; AND\n(c) A N EXPLANATION OF THE CONSUMER RIGHTS DESCRIBED IN SECTION 6-1-1705\nAND HOW TO EXERCISE THEM .\n(4)\n(a) T HE GENERAL ASSEMBLY FINDS THAT THE SPECIFIC CONTENT AND FORMAT OF POST-ADVERSE OUTCOME DISCLOSURES MAY VARY ACROSS CONSEQUENTIAL DECISION DOMAINS . THE GENERAL ASSEMBLY INTENDS THAT THE SPECIFIC ELEMENTS OF POST-ADVERSE OUTCOME DISCLOSURES BE FURTHER CLARIFIED THROUGH RULE-MAKING THAT ACCOUNTS FOR SECTOR-SPECIFIC PRACTICES WHILE ENSURING THAT CONSUMERS RECEIVE MEANINGFUL AND UNDERSTANDABLE INFORMATION ABOUT CONSEQUENTIAL DECISIONS .\n(b) O N OR BEFORE JANUARY 1, 2027, THE ATTORNEY GENERAL SHALL ADOPT RULES TO CLARIFY AND IMPLEMENT THE POST-ADVERSE OUTCOME DISCLOSURE REQUIREMENTS SET FORTH IN SUBSECTION\n(3) OF THIS SECTION . RULES ADOPTED PURSUANT TO THIS SUBSECTION\n(4) MAY INCLUDE , AS APPROPRIATE :(I) R ULES CLARIFYING THE CONTENT OF REQUIRED DISCLOSURES RELATED TO THE TYPES , SOURCES , OR CATEGORIES OF PERSONAL DATA THAT A DEPLOYER MUST PROVIDE TO A CONSUMER FOLLOWING AN ADVERSE OUTCOME INVOLVING ACOVERED ADMT PURSUANT TO SUBSECTION\n(3) OF THIS SECTION ;(II) SECTOR-SPECIFIC GUIDANCE OR ILLUSTRATIVE EXAMPLES TAILORED TO DIFFERENT COVERED DOMAINS ;(III) STANDARDS FOR DESCRIBING THE ROLE OF THE COVERED ADMT IN A CONSEQUENTIAL DECISION IN A MANNER THAT IS REASONABLY UNDERSTANDABLE TO A CONSUMER ; AND\n(IV) G UIDANCE ADDRESSING HOW THE DISCLOSURE REQUIREMENTS DESCRIBED IN THIS SECTION INTERACT WITH FEDERAL OR STATE LAWS THAT REQUIRE OR GOVERN NOTICES , EXPLANATIONS , OR ADVERSE OUTCOME DISCLOSURES .\n(5) NOTHING IN THIS SECTION REQUIRES A DEPLOYER TO DISCLOSE A TRADE SECRET OR INFORMATION PROTECTED FROM DISCLOSURE BY STATE OR FEDERAL LAW .IF A DEPLOYER WITHHOLDS INFORMATION PURSUANT TO THIS SUBSECTION (5), THE DEPLOYER SHALL NOTIFY THE CONSUMER .\n(6)\n(a) A CREDITOR , WITH RESPECT TO A CONSEQUENTIAL DECISION INVOLVING THE OFFERING , THE DENIAL , THE PRICING , THE SERVICING , OR OTHER MATERIAL TERMS OF CREDIT , THAT IS REQUIRED TO PROVIDE AND THAT PROVIDES A NOTICE TO A CONSUMER PURSUANT TO THE FEDERAL \u0026ldquo;E QUAL CREDIT OPPORTUNITY ACT \u0026ldquo;, 15 U.S.C. SEC . 1691 ET SEQ ., AND ITS IMPLEMENTING REGULATIONS , INCLUDING\nREGULATION B, 12 CFR 1002, AND , WHEN APPLICABLE , THE FEDERAL \u0026ldquo;F AIR CREDIT REPORTING ACT \u0026ldquo;, 15 U.S.C. SEC . 1681 ET SEQ ., COMPLIES WITH THE NOTICE OR DISCLOSURE REQUIREMENTS OF THIS SECTION THAT RELATE TO THE SAME DECISION OR ADVERSE OUTCOME IF THE NOTICE PROVIDED TO THE CONSUMER PURSUANT TO THE FEDERAL LAWS AND REGULATIONS DESCRIBED IN THIS SUBSECTION (6) (a) ALSO SATISFIES THE NOTICE OR DISCLOSURE REQUIREMENTS OF THIS SECTION .\n(b) IF A CREDITOR COMPLIES WITH THE FEDERAL LAWS AND REGULATIONS DESCRIBED IN SUBSECTION (6)\n(a) OF THIS SECTION AND COMPLIES WITH SUBSECTION\n(6)\n(a) OF THIS SECTION , THE CREDITOR IS NOT REQUIRED TO PROVIDE A SEPARATE OR DUPLICATIVE NOTICE PURSUANT TO THIS SECTION .\n(c) NOTHING IN THIS SUBSECTION\n(6) SHALL BE CONSTRUED TO REQUIRE A CREDITOR TO PROVIDE ANY NOTICE OR DISCLOSURE IN A MANNER THAT IS PROHIBITED BY FEDERAL LAW .\n(d) F OR PURPOSES OF THIS SUBSECTION (6), A NOTICE THAT COMPLIES WITH THE FEDERAL LAWS AND REGULATIONS DESCRIBED IN SUBSECTION (6)\n(a) OF THIS SECTION AND COMPLIES WITH SUBSECTION (6)\n(a) OF THIS SECTION MAY INCLUDE A BRIEF STATEMENT INDICATING THAT A COVERED ADMT WAS USED TO MATERIALLY INFLUENCE THE CONSEQUENTIAL DECISION AND INSTRUCTIONS FOR HOW THE CONSUMER MAY OBTAIN ANY ADDITIONAL INFORMATION OR EXERCISE ANY RIGHTS PROVIDED UNDER THIS PART 17.\n(7) T HIS PART 17 SHALL NOT BE CONSTRUED TO REQUIRE A PERSON TO MAKE A DISCLOSURE , PROVIDE AN EXPLANATION , OR FURNISH INFORMATION TO A CONSUMER TO THE EXTENT DOING SO WOULD BE PROHIBITED BY FEDERAL LAW OR WOULD COMPROMISE THE CONFIDENTIALITY OR INTEGRITY OF CYBERSECURITY , FRAUD PREVENTION , ANTI-MONEY LAUNDERING , COUNTER-TERRORIST FINANCING , OR ECONOMIC SANCTIONS COMPLIANCE PROGRAMS REQUIRED BY LAW .\n(8) A DEPLOYER OR DEVELOPER SHALL PROVIDE THE NOTICES AND DISCLOSURES REQUIRED BY THIS PART 17 IN A MANNER THAT IS REASONABLY ACCESSIBLE TO CONSUMERS WITH DISABILITIES AND CONSUMERS WITH LIMITED ENGLISH PROFICIENCY , CONSISTENT WITH APPLICABLE STATE AND FEDERAL LAW .\n(9)\n(a) F OR A CONSEQUENTIAL DECISION RELATING TO EDUCATION , A DEPLOYER THAT IS SUBJECT TO FERPA SATISFIES THE NOTICE AND DISCLOSURE REQUIREMENTS OF THIS SECTION BY PROVIDING NOTICE AND DISCLOSURES THROUGH PROCESSES AND CHANNELS THAT ARE CONSISTENT WITH FERPA AND THE DEPLOYER \u0026lsquo;S FERPA\nNOTICES AND STUDENT RECORD ACCESS PROCEDURES , INCLUDING , WHERE APPLICABLE , NOTICE TO A PARENT OR GUARDIAN OR AN ELIGIBLE STUDENT .\n(b) A DEPLOYER THAT IS SUBJECT TO FERPA IS NOT REQUIRED TO ESTABLISH A SEPARATE OR DUPLICATIVE NOTICE OR DISCLOSURE PROCESS IF THE DEPLOYER HAS ESTABLISHED A NOTICE OR DISCLOSURE PROCESS TO COMPLY WITH FERPA.\n6-1-1705. Consumer rights - correction - human review and reconsideration - rules. (1)\n(a) WHEN A CONSUMER EXPERIENCES AN ADVERSE OUTCOME RESULTING FROM A CONSEQUENTIAL DECISION IN WHICH A COVERED ADMT MATERIALLY INFLUENCES THE CONSEQUENTIAL DECISION , THE CONSUMER MAY REQUEST AND THE DEPLOYER SHALL PROVIDE IN RESPONSE TO THE REQUEST :(I) INSTRUCTIONS FOR REQUESTING PERSONAL DATA AND CORRECTING FACTUALLY INCORRECT OR MATERIALLY INACCURATE PERSONAL DATA USED IN A CONSEQUENTIAL DECISION THAT USED A COVERED ADMT CONSISTENT WITH SECTION 6-1-1306; AND\n(II) A N OPPORTUNITY FOR MEANINGFUL HUMAN REVIEW AND RECONSIDERATION OF THE CONSEQUENTIAL DECISION , TO THE EXTENT COMMERCIALLY REASONABLE .\n(b) FOR THE PURPOSES OF THIS SUBSECTION (1), THE EXCEPTIONS TO THE DEFINITION OF \u0026ldquo;CONSUMER \u0026quot; IN SECTION 6-1-1303 (6)\n(b) AND THE EXCEPTIONS IN SECTION 6-1-1304 (2)(k), (2)(n), AND (2)\n(o) DO NOT APPLY TO THE RIGHT TO REQUEST CORRECTION OF FACTUALLY INCORRECT OR MATERIALLY INACCURATE PERSONAL DATA PURSUANT TO THIS SUBSECTION (1).\n(c) SUBSECTION (1)\n(a) OF THIS SECTION DOES NOT REQUIRE CORRECTION OF OPINIONS , PREDICTIONS , SCORES , OR PROTECTED EVALUATIONS .\n(2)\n(a) F OR A CONSEQUENTIAL DECISION RELATING TO EDUCATION , A DEPLOYER THAT IS SUBJECT TO FERPA COMPLIES WITH THE REQUIREMENTS OF SUBSECTION\n(1) OF THIS SECTION THROUGH THE DEPLOYER \u0026lsquo;S EXISTING STUDENT RECORD INSPECTION ,\nREVIEW , AND AMENDMENT PROCEDURES AND ANY APPLICABLE DISTRICT COMPLAINT OR APPEAL PROCESS , IF THE DEPLOYER OFFERS A REASONABLE MECHANISM FOR A PARENT , GUARDIAN , OR ELIGIBLE STUDENT TO REQUEST CORRECTION OF MATERIALLY INACCURATE PERSONAL DATA AND RECONSIDERATION WHERE APPLICABLE UNDER THIS PART 17.\n(b) A DEPLOYER THAT IS SUBJECT TO FERPA IS NOT REQUIRED TO ESTABLISH A SEPARATE OR DUPLICATIVE CORRECTION OR HUMAN REVIEW AND RECONSIDERATION PROCESS IF THE DEPLOYER HAS ESTABLISHED A CORRECTION OR HUMAN REVIEW AND RECONSIDERATION PROCESS TO COMPLY WITH FERPA.\n(3) O N OR BEFORE JANUARY 1, 2027, THE ATTORNEY GENERAL SHALL ADOPT RULES TO CLARIFY AND IMPLEMENT THE REQUIREMENTS OF THIS SECTION .\n6-1-1706. Enforcement by the attorney general - deceptive trade practice-right to cure - no private right of action - joinder rules - reporting - repeal. (1)\n(a) T HE ATTORNEY GENERAL SHALL ENFORCE THIS PART 17 THROUGH THE\n\u0026ldquo;C OLORADO CONSUMER PROTECTION ACT \u0026ldquo;, THIS ARTICLE 1. (b) VIOLATIONS OF THE DISCLOSURE REQUIREMENTS AND CONSUMER RIGHTS DESCRIBED IN SECTIONS 6-1-1702, 6-1-1703, 6-1-1704, AND 6-1-1705 ARE ENFORCEABLE EXCLUSIVELY BY THE ATTORNEY GENERAL WITHOUT REGARD TO ANY OTHER PROVISION IN THIS TITLE 6.\n(2)\n(a) A VIOLATION OF THIS PART 17 IS A DECEPTIVE TRADE PRACTICE AND IS SUBJECT TO THE PROVISIONS OF THE \u0026ldquo;C OLORADO CONSUMER PROTECTION ACT \u0026ldquo;,\nTHIS ARTICLE 1.\n(b) ANY PROVISION OF THE \u0026ldquo;C OLORADO CONSUMER PROTECTION ACT \u0026ldquo;, THIS ARTICLE 1, THAT IS INCONSISTENT WITH THE EXCLUSIVE ENFORCEMENT AUTHORITY GRANTED TO THE ATTORNEY GENERAL IN THIS SECTION FOR A VIOLATION OF THIS PART 17 DOES NOT APPLY TO ANY SUCH VIOLATION .\n(3)\n(a) P RIOR TO ANY ENFORCEMENT ACTION FOR A VIOLATION OF THIS PART 17,\nTHE ATTORNEY GENERAL SHALL ISSUE A NOTICE OF VIOLATION TO A DEVELOPER OR DEPLOYER IF A CURE IS DEEMED POSSIBLE BY THE ATTORNEY GENERAL .\n(b) I F THE DEVELOPER OR DEPLOYER FAILS TO CURE A VIOLATION WITHIN SIXTY DAYS AFTER RECEIPT OF A NOTICE OF VIOLATION , THE ATTORNEY GENERAL MAY BRING AN ACTION PURSUANT TO THIS SECTION .\n(c) IF THE ATTORNEY GENERAL FINDS AND CAN DEMONSTRATE THAT ADEVELOPER OR DEPLOYER KNOWINGLY VIOLATED THIS PART 17 OR A DEVELOPER OR DEPLOYER REPEATEDLY VIOLATED THIS PART 17, THE ATTORNEY GENERAL IS NOT REQUIRED TO PROVIDE A CURE PERIOD BEFORE SEEKING PENALTIES OR OTHER RELIEF .\n(d) I F A VIOLATION IS DISCOVERED IN THE COURSE OF AN ENFORCEMENT ACTION ,\nA COURT MAY CONSIDER THAT A DEVELOPER OR DEPLOYER CURED THE VIOLATION WITHIN SIXTY DAYS AFTER RECEIPT OF WRITTEN NOTICE AS A MITIGATING FACTOR IN DETERMINING CIVIL PENALTIES OR OTHER MONETARY RELIEF , IF ANY .\n(e) B EGINNING IN JANUARY 2028, AND IN JANUARY EVERY YEAR THEREAFTER ,\nTHE ATTORNEY GENERAL SHALL INCLUDE , AS PART OF THE DEPARTMENT OF LAW \u0026lsquo;SPRESENTATION DURING ITS \u0026ldquo;SMART ACT \u0026quot; HEARING REQUIRED BY SECTION 2-7-203,\nA REPORT CONCERNING ENFORCEMENT ACTIONS BROUGHT AND CURE PERIODS OFFERED BY THE ATTORNEY GENERAL RELATED TO VIOLATIONS OF THIS PART 17,\nINCLUDING :(I) THE NUMBER OF ACTIONS FILED BY THE ATTORNEY GENERAL AGAINST DEVELOPERS AND DEPLOYERS , RESPECTIVELY ;(II) THE NUMBER OF ACTIONS FILED BY THE ATTORNEY GENERAL AGAINST DEVELOPERS AND DEPLOYERS , RESPECTIVELY , THAT WERE COMPLETED ;(III) T HE NUMBER OF CURE PERIODS OFFERED BY THE ATTORNEY GENERAL TO DEVELOPERS AND DEPLOYERS , RESPECTIVELY ;(IV) T HE NUMBER OF CURE PERIODS OFFERED BY THE ATTORNEY GENERAL THAT WERE NOT MET BY DEVELOPERS AND DEPLOYERS , RESPECTIVELY ; AND\n(V) T HE NUMBER OF VIOLATIONS FILED BY THE ATTORNEY GENERAL AGAINST DEVELOPERS AND DEPLOYERS , RESPECTIVELY , WHERE A CURE PERIOD WAS NOT DEEMED POSSIBLE .\n(f) T HIS SUBSECTION\n(3) IS REPEALED , EFFECTIVE JANUARY 1, 2030.\n(4) NOTHING IN THIS PART 17 CREATES A NEW PRIVATE RIGHT OF ACTION .NOTHING IN THIS PART 17 LIMITS OR REDUCES ANY EXISTING RIGHTS OR REMEDIES AVAILABLE UNDER STATE OR FEDERAL LAW , INCLUDING THE \u0026ldquo;C OLORADO\nANTI-DISCRIMINATION ACT \u0026ldquo;, PARTS 3 TO 8 OF ARTICLE 34 OF TITLE 24; THE \u0026ldquo;C OLORADO CONSUMER PROTECTION ACT \u0026ldquo;, THIS ARTICLE 1; PRODUCT LIABILITY LAW ; OR OTHER APPLICABLE LAW . (5)\n(a) THE ATTORNEY GENERAL MAY ADOPT RULES AS NECESSARY TO IMPLEMENT AND CLARIFY THIS PART 17.\n(b) T HE ATTORNEY GENERAL MAY ADOPT RULES TO CLARIFY THE APPLICATION OF THE DEFINITION OF \u0026ldquo;MATERIALLY INFLUENCE \u0026ldquo;, AS DEFINED IN SECTION 6-1-1701 (13), INCLUDING PRESUMPTIONS , ILLUSTRATIVE EXAMPLES , AND OBJECTIVE INDICATORS .\n(c) I N ADOPTING RULES PURSUANT TO THIS PART 17, THE ATTORNEY GENERAL SHALL UTILIZE A PROCESS THAT MEANINGFULLY ENGAGES STAKEHOLDERS ,\nINCLUDING CONSUMER ADVOCATES , DEPLOYERS , DEVELOPERS , AND SECTOR REGULATORS , THROUGH PUBLIC NOTICE , OPPORTUNITY FOR WRITTEN COMMENT , AND AT LEAST ONE PUBLIC HEARING AND SHALL ADOPT RULES IN ACCORDANCE WITH SECTION 24-4-103.\n(6) N OTHING IN THIS PART 17 LIMITS THE ABILITY OF A PARTY TO JOIN NECESSARY OR PERMISSIVE PARTIES UNDER THE COLORADO RULES OF CIVIL PROCEDURE ,\nINCLUDING RULES 19 AND 20 OF THE COLORADO RULES OF CIVIL PROCEDURE , IN ANY ACTION ARISING UNDER EXISTING LAW .\n6-1-1707. Liability - fault - allocation - no joint and several liability-indemnification prohibited - effect on existing law. (1) A DEVELOPER OR DEPLOYER MAY BE HELD LIABLE IN AN ACTION ALLEGING UNLAWFUL DISCRIMINATION UNDER STATE ANTI-DISCRIMINATION LAWS , INCLUDING THE \u0026ldquo;C OLORADO ANTI-DISCRIMINATION ACT \u0026ldquo;, PARTS 3 TO 8 OF ARTICLE 34 OF TITLE\n24, ARISING FROM A CONSEQUENTIAL DECISION MATERIALLY INFLUENCED BY A COVERED ADMT. (2) I N AN ACTION DESCRIBED IN SUBSECTION\n(1) OF THIS SECTION , FAULT SHALL BE ALLOCATED AMONG DEPLOYERS AND DEVELOPERS BASED ON THEIR RELATIVE FAULT FOR THE VIOLATION .\n(3) N OTHING IN THIS SECTION SHALL BE CONSTRUED TO APPORTION LIABILITY TO A CLAIMANT WHERE SUCH APPORTIONMENT IS NOT PROVIDED FOR UNDER EXISTING LAW .\n(4) NOTHING IN THIS SECTION SHALL BE CONSTRUED TO CREATE JOINT AND SEVERAL LIABILITY , EXCEPT TO THE EXTENT PERMITTED UNDER EXISTING LAW .\n(5)\n(a) A DEVELOPER IS LIABLE IN AN ACTION DESCRIBED IN SUBSECTION\n(1) OF THIS SECTION ONLY TO THE EXTENT THAT :(I) T HE DEVELOPER \u0026lsquo;S COVERED ADMT WAS USED BY A DEPLOYER IN A MANNER THAT WAS INTENDED , DOCUMENTED , MARKETED , ADVERTISED , CONFIGURED , OR CONTRACTED FOR BY THE DEVELOPER ; AND\n(II) THE DEVELOPER \u0026lsquo;S COVERED ADMT MATERIALLY INFLUENCED ACONSEQUENTIAL DECISION THAT GAVE RISE TO THE VIOLATION OF EXISTING LAW .\n(b) A DEVELOPER IS NOT LIABLE UNDER THIS SECTION FOR VIOLATIONS OF EXISTING LAW ARISING FROM A DEPLOYER \u0026lsquo;S USE OF A COVERED ADMT IN A MANNER THAT WAS NOT INTENDED , DOCUMENTED , MARKETED , ADVERTISED , CONFIGURED ,\nOR CONTRACTED FOR BY THE DEVELOPER .\n(6) N OTHING IN THIS SECTION SHALL BE CONSTRUED TO LIMIT THE LIABILITY OF A DEPLOYER FOR THE DEPLOYER \u0026lsquo;S INDEPENDENT ACTS OR OMISSIONS IN ACONSEQUENTIAL DECISION MATERIALLY INFLUENCED BY A COVERED ADMT,\nINCLUDING USING AN ADMT IN A MANNER THAT WAS NOT INTENDED , DOCUMENTED ,\nMARKETED , ADVERTISED , CONFIGURED , OR CONTRACTED FOR BY THE DEVELOPER IF THE DEVELOPER OF THE COVERED ADMT COMPLIED WITH SECTION 6-1-1702.\n(7)\n(a) N OTWITHSTANDING ANY OTHER PROVISION OF LAW , IF A PROVISION OF A CONTRACT FOR THE USE OF AUTOMATED DECISION-MAKING TECHNOLOGY IN MAKING A CONSEQUENTIAL DECISION OR ANY OTHER CONTRACT BETWEEN A DEVELOPER AND DEPLOYER PURPORTS TO INDEMNIFY , DEFEND , OR HOLD HARMLESS OR HAS THE EFFECT OF INDEMNIFYING , DEFENDING , OR HOLDING HARMLESS THE INDEMNITEE FROM OR AGAINST ANY LIABILITY FOR DAMAGES PURSUANT TO THIS SECTION RESULTING FROM THE DEVELOPER \u0026lsquo;S OR DEPLOYER \u0026lsquo;S OWN ACTS OR OMISSIONS RELATED TO THE USE OF AUTOMATED DECISION-MAKING TECHNOLOGY IN MAKING C O N S E Q U E N T IA L D E C IS IO N S I N V I O L A T I O N O F T H E \u0026ldquo;C O L O R A D O\nANTI-DISCRIMINATION ACT \u0026ldquo;, PARTS 3 TO 8 OF ARTICLE 34 OF TITLE 24, OR OTHER COLORADO ANTI-DISCRIMINATION LAW , THE PROVISION IS CONTRARY TO PUBLIC POLICY AND VOID . (b) T HE LIMITATIONS OF SUBSECTION (7)\n(a) OF THIS SECTION DO NOT APPLY TO A DEVELOPER WHERE THE USE OF THE COVERED ADMT IN MAKING A CONSEQUENTIAL DECISION WAS NOT INTENDED , DOCUMENTED , MARKETED , ADVERTISED ,\nCONFIGURED , OR CONTRACTED FOR BY THE DEVELOPER IF THE DEVELOPER OF THE COVERED ADMT COMPLIED WITH SECTION 6-1-1702.\n(c) T HIS SUBSECTION\n(7) DOES NOT OTHERWISE LIMIT THE ENFORCEABILITY OF CONTRACT TERMS BETWEEN PARTIES ACTING IN A COMMERCIAL OR BUSINESS CAPACITY , EXCEPT TO THE EXTENT OTHERWISE PROVIDED BY APPLICABLE LAW .\n(d) THIS SUBSECTION\n(7) DOES NOT PROHIBIT OR LIMIT ANY PERSON FROM OBTAINING OR MAKING A CLAIM ON APPLICABLE INSURANCE FOR ANY APPLICABLE ALLEGED LIABILITIES OR RELATED LOSSES .\n(8) NOTHING IN THIS SECTION SHALL BE CONSTRUED TO LIMIT , DISPLACE , OR OTHERWISE AFFECT ANY LIABILITY THAT A DEVELOPER OR A DEPLOYER MAY HAVE ,\nSEPARATE AND APART FROM LIABILITY UNDER THIS SECTION , FOR A VIOLATION OF STATE LAW . COMPLIANCE WITH THE REQUIREMENTS OF THIS PART 17 IS NOT A DEFENSE TO AND DOES NOT OTHERWISE EXCUSE NONCOMPLIANCE WITH ANY APPLICABLE LAW .\n(9) T HE USE OF AN ADMT IN A CONSEQUENTIAL DECISION DOES NOT EXCUSE ,\nJUSTIFY , OR PROVIDE A DEFENSE TO ANY OBLIGATION OR LIABILITY UNDER STATE OR FEDERAL LAW , INCLUDING OBLIGATIONS AND LIABILITY RELATED TO DISCRIMINATION OR CONSUMER PROTECTION .\n6-1-1708. Compliance with other legal obligations - insurers - covered entities - disclosures. (1)\n(a) AN INSURER , AS DEFINED IN SECTION 10-1-102 (13), AND AFFILIATED ENTITIES THAT ARE SUBJECT TO THE REQUIREMENTS OF SECTION 10-3-1104.9 ARE IN COMPLIANCE WITH THIS PART 17 IN THE PRACTICE OF INSURANCE . (b) I F AN INSURER IS NOT DEEMED IN COMPLIANCE PURSUANT TO SUBSECTION\n(1)\n(a) OF THIS SECTION , THE INSURER SHALL PROVIDE NOTICE AND DISCLOSURE OF ITS USE OF A COVERED ADMT IN MATERIALLY INFLUENCING A CONSEQUENTIAL DECISION REGARDING THE PRACTICE OF INSURANCE PURSUANT TO THE DISCLOSURE REQUIREMENTS OF SECTION 6-1-1704 (3), TO THE EXTENT APPLICABLE .\n(2) T HIS SECTION DOES NOT LIMIT THE APPLICABILITY OF THIS PART 17 TO USES OF COVERED ADMT RELATED TO INSURER EMPLOYMENT OR INSURER EMPLOYMENT OPPORTUNITIES BY INSURERS AND AFFILIATED ENTITIES THAT ARE SUBJECT TO THE REQUIREMENTS OF SECTION 10-3-1104.9.\n(3)\n(a) SECTIONS 6-1-1701, 6-1-1702, 6-1-1703, 6-1-1704, 6-1-1705, AND\n6-1-1706 DO NOT APPLY TO A COVERED ENTITY WITHIN THE MEANING OF THE FEDERAL \u0026ldquo;H EALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996\u0026rdquo;, 42 U.S.C. SECS . 1320d TO 1320d-9, AND THE REGULATIONS PROMULGATED UNDER THE FEDERAL ACT , OR A COVERED ENTITY \u0026lsquo;S BUSINESS ASSOCIATES FOR ANY SERVICES RENDERED TO A COVERED ENTITY , TO THE EXTENT THE COVERED ENTITY IS DOING BUSINESS IN COLORADO , EXCEPT FOR A CONSEQUENTIAL DECISION RELATED TO EMPLOYMENT OR AN EMPLOYMENT OPPORTUNITY . (b) NOTWITHSTANDING SUBSECTION (3)\n(a) OF THIS SECTION , FOR A COVERED ENTITY THAT IS A HEALTH-CARE PROVIDER , AS DEFINED IN 45 CFR 160.103, THIS SUBSECTION\n(3) APPLIES ONLY IF THE HEALTH-CARE PROVIDER IS OPERATING FROM A LOCATION WITHIN COLORADO .\n(c) A COVERED ENTITY SHALL PROVIDE PATIENTS WITH A GENERAL NOTICE OF USE OF ADVANCED TECHNOLOGIES , INCLUDING A COVERED ADMT. THE NOTICE MAY BE INCORPORATED WITH OTHER NOTICES DESCRIBING PATIENT RIGHTS AND HOW THE COVERED ENTITY PROVIDES CARE .\n(d) N OTWITHSTANDING SUBSECTION (3)\n(a) OF THIS SECTION , A COVERED ENTITY THAT USES A COVERED ADMT TO DETERMINE A PATIENT \u0026lsquo;S ELIGIBILITY FOR FINANCIAL ASSISTANCE , INCLUDING DISCOUNTED CARE AS DESCRIBED IN SECTION\n25.5-3-502, SHALL PROVIDE A PATIENT THE FOLLOWING DISCLOSURES :(I) A PLAIN LANGUAGE DESCRIPTION OF THE CONSEQUENTIAL DECISION AND THE ROLE OF THE COVERED ADMT IN THE CONSEQUENTIAL DECISION ;(II) T HE TYPES OF INFORMATION ABOUT THE INDIVIDUAL THE COVERED ENTITY RELIED UPON IN MAKING ITS DETERMINATION OF ELIGIBILITY , EXCEPT FOR TRADE SECRETS AND OTHER CONFIDENTIAL OR LEGALLY PROTECTED INFORMATION ;(III) INFORMATION ON HOW TO REQUEST CORRECTION OF MATERIALLY INACCURATE PERSONAL DATA HELD BY THE COVERED ENTITY CONSISTENT WITH THE FEDERAL \u0026ldquo;H EALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996\u0026rdquo;, 42 U.S.C. SECS . 1320d TO 1320d-9 AND SECTION 25.5-3-502; AND (IV) INFORMATION ON HOW TO REQUEST MEANINGFUL HUMAN REVIEW OR RECONSIDERATION , WHERE APPLICABLE .\n(e) A COVERED ENTITY MAY COMPLY WITH SUBSECTION (3)\n(d) OF THIS SECTION THROUGH EITHER AN ADVANCE GENERAL DISCLOSURE OF THE INFORMATION REQUIRED BY SUBSECTION (3)\n(d) OF THIS SECTION OR THROUGH A NOTICE PROVIDED WITHIN THIRTY CALENDAR DAYS AFTER AN ADVERSE OUTCOME . THIS SECTION DOES NOT CREATE A SEPARATE AND DUPLICATIVE DISCLOSURE PROCESS OR APPEAL PROCESS IF THE REVIEW OPPORTUNITIES AND INFORMATION DESCRIBED IN SUBSECTION (3)\n(d) OF THIS SECTION ARE PROVIDED .\n(4) S ECTIONS 6-1-1701, 6-1-1702, 6-1-1703, 6-1-1704, 6-1-1705, AND 6-1-1706\nDO NOT APPLY TO A MEDICAL DEVICE SUBJECT TO OVERSIGHT BY THE UNITED\nSTATES FOOD AND DRUG ADMINISTRATION OR A PHARMACEUTICAL OR MEDICAL DEVICE MANUFACTURER \u0026lsquo;S RESEARCH AND DEVELOPMENT ACTIVITIES THAT ARE SUBJECT TO OVERSIGHT BY THE UNITED STATES FOOD AND DRUG ADMINISTRATION , INCLUDING CLINICAL INVESTIGATIONS CONDUCTED UNDER 21 CFR 312.\n(5) NOTHING IN THIS PART 17 REQUIRES A COVERED ENTITY OR BUSINESS ASSOCIATE , AS THOSE TERMS ARE DEFINED UNDER THE FEDERAL \u0026ldquo;H EALTH\nINSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996\u0026rdquo;, 42 U.S.C. SECS .1320d TO 1320d-9, TO DISCLOSE PROTECTED HEALTH INFORMATION OR OTHER INFORMATION IN A MANNER THAT WOULD VIOLATE FEDERAL LAW . TO THE EXTENT COMPLIANCE WITH SECTION 6-1-1704 OR 6-1-1705 WOULD CONFLICT WITH FEDERAL HEALTH PRIVACY REQUIREMENTS , THE DEPLOYER SHALL COMPLY WITH APPLICABLE FEDERAL LAW AND PROVIDE DISCLOSURES AND ACCESS CONSISTENT WITH THAT LAW . (6) THIS PART 17 DOES NOT REQUIRE A PERSON TO DISCLOSE NONPUBLIC PERSONAL INFORMATION IN A MANNER THAT WOULD VIOLATE THE FEDERAL\n\u0026ldquo;G RAMM-L EACH-B LILEY ACT \u0026ldquo;, 15 U.S.C. SEC . 6801 ET SEQ ., OR ITS IMPLEMENTING REGULATIONS . 6-1-1709. No new private right of action - application of other law. (1) N OTHING IN THIS PART 17 CREATES A NEW PRIVATE RIGHT OF ACTION .\n(2) C OMPLIANCE WITH THIS PART 17 DOES NOT CONSTITUTE A DEFENSE TO AND DOES NOT EXCUSE NONCOMPLIANCE WITH ANY APPLICABLE LAW .\nSECTION 2. In Colorado Revised Statutes, 6-1-105, add (1)(uuuu) as follows: 6-1-105. Unfair or deceptive trade practices. (1) A person engages in a deceptive trade practice when, in the course of the person\u0026rsquo;s business, vocation, or occupation, the person: (uuuu) V IOLATES PART 17 OF THIS ARTICLE 1.\nSECTION 3. In Colorado Revised Statutes, 10-3-1104.9, add (3) (e) as follows:\n10-3-1104.9. Insurers\u0026rsquo; use of external consumer data and information sources, algorithms, and predictive models - unfair discrimination prohibited - rules - stakeholder process required - investigations - definitions. (3) (e) T HE COMMISSIONER MAY ADOPT NEW RULES OR UPDATE EXISTING RULES REGARDING NOTICE AND DISCLOSURES FROM INSURERS TO CONSUMERS .\nSECTION 4. Appropriation. For the 2026-27 state fiscal year, $46,190 is appropriated to the department of law. This appropriation is from the general fund and is based on an assumption that the department will require an additional 0.4 FTE. To implement this act, the department may use this appropriation for consumer protection, antitrust, and civil rights. SECTION 5. Effective date - applicability. (1) Except as otherwise provided in subsection\n(2) of this section, this act takes effect January 1, 2027.\n(2) Sections 6-1-1704 (4), 6-1-1705 (3), and 6-1-1706 (6), Colorado Revised Statutes, as amended in section 1 of this act, section 10-3-1104.9 (3)(e), Colorado Revised Statutes, as enacted in section 3 of this act, section 4 of this act, this section, and section 6 of this act take effect upon passage.\n(3) This act applies to consequential decisions made on or after January 1, 2027.\nSECTION 6. Safety clause. The general assembly finds, determines, and declares that this act is necessary for the immediate preservation of the public peace, health, or safety or for appropriations for the support and maintenance of the departments of the state and state institutions. Approved: May 14, 2026 ","permalink":"https://ai.intlaws.com/en/compliance/us/%E7%A7%91%E7%BD%97%E6%8B%89%E5%A4%9Asb26-189/","summary":"Official session-law text of Colorado SB 26-189 (Chapter 131, Laws of 2026), approved May 14, 2026: an amendment to the Colorado Privacy Act governing the use of artificial intelligence in consequential decisions. Obligations apply to consequential decisions made on or after January 1, 2027. English original; Chinese translation available.","title":"Colorado SB 26-189 (Artificial Intelligence Amendment to the Colorado Privacy Act)"},{"content":" Source: EUR-Lex, Official Journal L 119, 4.5.2016, p. 1–88 — CELEX 32016R0679\nOfficial links:\nEUR-Lex (EN HTML): https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 EUR-Lex (CELEX resource): https://publications.europa.eu/resource/celex/32016R0679 Structure: Recitals (1)–(173); Chapters I–XI; Articles 1–99; in force since 24 May 2016, applicable from 25 May 2018\nNote: 本页为《欧盟官方公报》刊登的英文原文;欧盟法仅以欧盟官方语言作准,无官方中文文本。中文导读见 中文页 。 REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL\nof 27 April 2016\non the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)\n(Text with EEA relevance)\nTHE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,\nHaving regard to the Treaty on the Functioning of the European Union, and in particular Article 16 thereof,\nHaving regard to the proposal from the European Commission,\nAfter transmission of the draft legislative act to the national parliaments,\nHaving regard to the opinion of the European Economic and Social Committee(1),\nHaving regard to the opinion of the Committee of the Regions(2),\nActing in accordance with the ordinary legislative procedure(3),\nWhereas:\n(1)The protection of natural persons in relation to the processing of personal data is a fundamental right. Article 8(1) of the Charter of Fundamental Rights of the European Union (the ‘Charter’) and Article 16(1) of the Treaty on the Functioning of the European Union (TFEU) provide that everyone has the right to the protection of personal data concerning him or her.\n(2)The principles of, and rules on the protection of natural persons with regard to the processing of their personal data should, whatever their nationality or residence, respect their fundamental rights and freedoms, in particular their right to the protection of personal data. This Regulation is intended to contribute to the accomplishment of an area of freedom, security and justice and of an economic union, to economic and social progress, to the strengthening and the convergence of the economies within the internal market, and to the well-being of natural persons.\n(3)Directive 95/46/EC of the European Parliament and of the Council(4) seeks to harmonise the protection of fundamental rights and freedoms of natural persons in respect of processing activities and to ensure the free flow of personal data between Member States.\n(4)The processing of personal data should be designed to serve mankind. The right to the protection of personal data is not an absolute right; it must be considered in relation to its function in society and be balanced against other fundamental rights, in accordance with the principle of proportionality. This Regulation respects all fundamental rights and observes the freedoms and principles recognised in the Charter as enshrined in the Treaties, in particular the respect for private and family life, home and communications, the protection of personal data, freedom of thought, conscience and religion, freedom of expression and information, freedom to conduct a business, the right to an effective remedy and to a fair trial, and cultural, religious and linguistic diversity.\n(5)The economic and social integration resulting from the functioning of the internal market has led to a substantial increase in cross-border flows of personal data. The exchange of personal data between public and private actors, including natural persons, associations and undertakings across the Union has increased. National authorities in the Member States are being called upon by Union law to cooperate and exchange personal data so as to be able to perform their duties or carry out tasks on behalf of an authority in another Member State.\n(6)Rapid technological developments and globalisation have brought new challenges for the protection of personal data. The scale of the collection and sharing of personal data has increased significantly. Technology allows both private companies and public authorities to make use of personal data on an unprecedented scale in order to pursue their activities. Natural persons increasingly make personal information available publicly and globally. Technology has transformed both the economy and social life, and should further facilitate the free flow of personal data within the Union and the transfer to third countries and international organisations, while ensuring a high level of the protection of personal data.\n(7)Those developments require a strong and more coherent data protection framework in the Union, backed by strong enforcement, given the importance of creating the trust that will allow the digital economy to develop across the internal market. Natural persons should have control of their own personal data. Legal and practical certainty for natural persons, economic operators and public authorities should be enhanced.\n(8)Where this Regulation provides for specifications or restrictions of its rules by Member State law, Member States may, as far as necessary for coherence and for making the national provisions comprehensible to the persons to whom they apply, incorporate elements of this Regulation into their national law.\n(9)The objectives and principles of Directive 95/46/EC remain sound, but it has not prevented fragmentation in the implementation of data protection across the Union, legal uncertainty or a widespread public perception that there are significant risks to the protection of natural persons, in particular with regard to online activity. Differences in the level of protection of the rights and freedoms of natural persons, in particular the right to the protection of personal data, with regard to the processing of personal data in the Member States may prevent the free flow of personal data throughout the Union. Those differences may therefore constitute an obstacle to the pursuit of economic activities at the level of the Union, distort competition and impede authorities in the discharge of their responsibilities under Union law. Such a difference in levels of protection is due to the existence of differences in the implementation and application of Directive 95/46/EC.\n(10)In order to ensure a consistent and high level of protection of natural persons and to remove the obstacles to flows of personal data within the Union, the level of protection of the rights and freedoms of natural persons with regard to the processing of such data should be equivalent in all Member States. Consistent and homogenous application of the rules for the protection of the fundamental rights and freedoms of natural persons with regard to the processing of personal data should be ensured throughout the Union. Regarding the processing of personal data for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Member States should be allowed to maintain or introduce national provisions to further specify the application of the rules of this Regulation. In conjunction with the general and horizontal law on data protection implementing Directive 95/46/EC, Member States have several sector-specific laws in areas that need more specific provisions. This Regulation also provides a margin of manoeuvre for Member States to specify its rules, including for the processing of special categories of personal data (‘sensitive data’). To that extent, this Regulation does not exclude Member State law that sets out the circumstances for specific processing situations, including determining more precisely the conditions under which the processing of personal data is lawful.\n(11)Effective protection of personal data throughout the Union requires the strengthening and setting out in detail of the rights of data subjects and the obligations of those who process and determine the processing of personal data, as well as equivalent powers for monitoring and ensuring compliance with the rules for the protection of personal data and equivalent sanctions for infringements in the Member States.\n(12)Article 16(2) TFEU mandates the European Parliament and the Council to lay down the rules relating to the protection of natural persons with regard to the processing of personal data and the rules relating to the free movement of personal data.\n(13)In order to ensure a consistent level of protection for natural persons throughout the Union and to prevent divergences hampering the free movement of personal data within the internal market, a Regulation is necessary to provide legal certainty and transparency for economic operators, including micro, small and medium-sized enterprises, and to provide natural persons in all Member States with the same level of legally enforceable rights and obligations and responsibilities for controllers and processors, to ensure consistent monitoring of the processing of personal data, and equivalent sanctions in all Member States as well as effective cooperation between the supervisory authorities of different Member States. The proper functioning of the internal market requires that the free movement of personal data within the Union is not restricted or prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data. To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping. In addition, the Union institutions and bodies, and Member States and their supervisory authorities, are encouraged to take account of the specific needs of micro, small and medium-sized enterprises in the application of this Regulation. The notion of micro, small and medium-sized enterprises should draw from Article 2 of the Annex to Commission Recommendation 2003/361/EC(5).\n(14)The protection afforded by this Regulation should apply to natural persons, whatever their nationality or place of residence, in relation to the processing of their personal data. This Regulation does not cover the processing of personal data which concerns legal persons and in particular undertakings established as legal persons, including the name and the form of the legal person and the contact details of the legal person.\n(15)In order to prevent creating a serious risk of circumvention, the protection of natural persons should be technologically neutral and should not depend on the techniques used. The protection of natural persons should apply to the processing of personal data by automated means, as well as to manual processing, if the personal data are contained or are intended to be contained in a filing system. Files or sets of files, as well as their cover pages, which are not structured according to specific criteria should not fall within the scope of this Regulation.\n(16)This Regulation does not apply to issues of protection of fundamental rights and freedoms or the free flow of personal data related to activities which fall outside the scope of Union law, such as activities concerning national security. This Regulation does not apply to the processing of personal data by the Member States when carrying out activities in relation to the common foreign and security policy of the Union.\n(17)Regulation (EC) No 45/2001 of the European Parliament and of the Council(6) applies to the processing of personal data by the Union institutions, bodies, offices and agencies. Regulation (EC) No 45/2001 and other Union legal acts applicable to such processing of personal data should be adapted to the principles and rules established in this Regulation and applied in the light of this Regulation. In order to provide a strong and coherent data protection framework in the Union, the necessary adaptations of Regulation (EC) No 45/2001 should follow after the adoption of this Regulation, in order to allow application at the same time as this Regulation.\n(18)This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.\n(19)The protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security and the free movement of such data, is the subject of a specific Union legal act. This Regulation should not, therefore, apply to processing activities for those purposes. However, personal data processed by public authorities under this Regulation should, when used for those purposes, be governed by a more specific Union legal act, namely Directive (EU) 2016/680 of the European Parliament and of the Council(7). Member States may entrust competent authorities within the meaning of Directive (EU) 2016/680 with tasks which are not necessarily carried out for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and prevention of threats to public security, so that the processing of personal data for those other purposes, in so far as it is within the scope of Union law, falls within the scope of this Regulation.\nWith regard to the processing of personal data by those competent authorities for purposes falling within scope of this Regulation, Member States should be able to maintain or introduce more specific provisions to adapt the application of the rules of this Regulation. Such provisions may determine more precisely specific requirements for the processing of personal data by those competent authorities for those other purposes, taking into account the constitutional, organisational and administrative structure of the respective Member State. When the processing of personal data by private bodies falls within the scope of this Regulation, this Regulation should provide for the possibility for Member States under specific conditions to restrict by law certain obligations and rights when such a restriction constitutes a necessary and proportionate measure in a democratic society to safeguard specific important interests including public security and the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security. This is relevant for instance in the framework of anti-money laundering or the activities of forensic laboratories.\n(20)While this Regulation applies, inter alia, to the activities of courts and other judicial authorities, Union or Member State law could specify the processing operations and processing procedures in relation to the processing of personal data by courts and other judicial authorities. The competence of the supervisory authorities should not cover the processing of personal data when courts are acting in their judicial capacity, in order to safeguard the independence of the judiciary in the performance of its judicial tasks, including decision-making. It should be possible to entrust supervision of such data processing operations to specific bodies within the judicial system of the Member State, which should, in particular ensure compliance with the rules of this Regulation, enhance awareness among members of the judiciary of their obligations under this Regulation and handle complaints in relation to such data processing operations.\n(21)This Regulation is without prejudice to the application of Directive 2000/31/EC of the European Parliament and of the Council(8), in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive. That Directive seeks to contribute to the proper functioning of the internal market by ensuring the free movement of information society services between Member States.\n(22)Any processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union should be carried out in accordance with this Regulation, regardless of whether the processing itself takes place within the Union. Establishment implies the effective and real exercise of activity through stable arrangements. The legal form of such arrangements, whether through a branch or a subsidiary with a legal personality, is not the determining factor in that respect.\n(23)In order to ensure that natural persons are not deprived of the protection to which they are entitled under this Regulation, the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union should be subject to this Regulation where the processing activities are related to offering goods or services to such data subjects irrespective of whether connected to a payment. In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. Whereas the mere accessibility of the controller\u0026rsquo;s, processor\u0026rsquo;s or an intermediary\u0026rsquo;s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.\n(24)The processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union should also be subject to this Regulation when it is related to the monitoring of the behaviour of such data subjects in so far as their behaviour takes place within the Union. In order to determine whether a processing activity can be considered to monitor the behaviour of data subjects, it should be ascertained whether natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analysing or predicting her or his personal preferences, behaviours and attitudes.\n(25)Where Member State law applies by virtue of public international law, this Regulation should also apply to a controller not established in the Union, such as in a Member State\u0026rsquo;s diplomatic mission or consular post.\n(26)The principles of data protection should apply to any information concerning an identified or identifiable natural person. Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person. To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly. To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments. The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes.\n(27)This Regulation does not apply to the personal data of deceased persons. Member States may provide for rules regarding the processing of personal data of deceased persons.\n(28)The application of pseudonymisation to personal data can reduce the risks to the data subjects concerned and help controllers and processors to meet their data-protection obligations. The explicit introduction of ‘pseudonymisation’ in this Regulation is not intended to preclude any other measures of data protection.\n(29)In order to create incentives to apply pseudonymisation when processing personal data, measures of pseudonymisation should, whilst allowing general analysis, be possible within the same controller when that controller has taken technical and organisational measures necessary to ensure, for the processing concerned, that this Regulation is implemented, and that additional information for attributing the personal data to a specific data subject is kept separately. The controller processing the personal data should indicate the authorised persons within the same controller.\n(30)Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.\n(31)Public authorities to which personal data are disclosed in accordance with a legal obligation for the exercise of their official mission, such as tax and customs authorities, financial investigation units, independent administrative authorities, or financial market authorities responsible for the regulation and supervision of securities markets should not be regarded as recipients if they receive personal data which are necessary to carry out a particular inquiry in the general interest, in accordance with Union or Member State law. The requests for disclosure sent by the public authorities should always be in writing, reasoned and occasional and should not concern the entirety of a filing system or lead to the interconnection of filing systems. The processing of personal data by those public authorities should comply with the applicable data-protection rules according to the purposes of the processing.\n(32)Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject\u0026rsquo;s agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject\u0026rsquo;s acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject\u0026rsquo;s consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.\n(33)It is often not possible to fully identify the purpose of personal data processing for scientific research purposes at the time of data collection. Therefore, data subjects should be allowed to give their consent to certain areas of scientific research when in keeping with recognised ethical standards for scientific research. Data subjects should have the opportunity to give their consent only to certain areas of research or parts of research projects to the extent allowed by the intended purpose.\n(34)Genetic data should be defined as personal data relating to the inherited or acquired genetic characteristics of a natural person which result from the analysis of a biological sample from the natural person in question, in particular chromosomal, deoxyribonucleic acid (DNA) or ribonucleic acid (RNA) analysis, or from the analysis of another element enabling equivalent information to be obtained.\n(35)Personal data concerning health should include all data pertaining to the health status of a data subject which reveal information relating to the past, current or future physical or mental health status of the data subject. This includes information about the natural person collected in the course of the registration for, or the provision of, health care services as referred to in Directive 2011/24/EU of the European Parliament and of the Council(9) to that natural person; a number, symbol or particular assigned to a natural person to uniquely identify the natural person for health purposes; information derived from the testing or examination of a body part or bodily substance, including from genetic data and biological samples; and any information on, for example, a disease, disability, disease risk, medical history, clinical treatment or the physiological or biomedical state of the data subject independent of its source, for example from a physician or other health professional, a hospital, a medical device or an in vitro diagnostic test.\n(36)The main establishment of a controller in the Union should be the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union, in which case that other establishment should be considered to be the main establishment. The main establishment of a controller in the Union should be determined according to objective criteria and should imply the effective and real exercise of management activities determining the main decisions as to the purposes and means of processing through stable arrangements. That criterion should not depend on whether the processing of personal data is carried out at that location. The presence and use of technical means and technologies for processing personal data or processing activities do not, in themselves, constitute a main establishment and are therefore not determining criteria for a main establishment. The main establishment of the processor should be the place of its central administration in the Union or, if it has no central administration in the Union, the place where the main processing activities take place in the Union. In cases involving both the controller and the processor, the competent lead supervisory authority should remain the supervisory authority of the Member State where the controller has its main establishment, but the supervisory authority of the processor should be considered to be a supervisory authority concerned and that supervisory authority should participate in the cooperation procedure provided for by this Regulation. In any case, the supervisory authorities of the Member State or Member States where the processor has one or more establishments should not be considered to be supervisory authorities concerned where the draft decision concerns only the controller. Where the processing is carried out by a group of undertakings, the main establishment of the controlling undertaking should be considered to be the main establishment of the group of undertakings, except where the purposes and means of processing are determined by another undertaking.\n(37)A group of undertakings should cover a controlling undertaking and its controlled undertakings, whereby the controlling undertaking should be the undertaking which can exert a dominant influence over the other undertakings by virtue, for example, of ownership, financial participation or the rules which govern it or the power to have personal data protection rules implemented. An undertaking which controls the processing of personal data in undertakings affiliated to it should be regarded, together with those undertakings, as a group of undertakings.\n(38)Children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data. Such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles and the collection of personal data with regard to children when using services offered directly to a child. The consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child.\n(39)Any processing of personal data should be lawful and fair. It should be transparent to natural persons that personal data concerning them are collected, used, consulted or otherwise processed and to what extent the personal data are or will be processed. The principle of transparency requires that any information and communication relating to the processing of those personal data be easily accessible and easy to understand, and that clear and plain language be used. That principle concerns, in particular, information to the data subjects on the identity of the controller and the purposes of the processing and further information to ensure fair and transparent processing in respect of the natural persons concerned and their right to obtain confirmation and communication of personal data concerning them which are being processed. Natural persons should be made aware of risks, rules, safeguards and rights in relation to the processing of personal data and how to exercise their rights in relation to such processing. In particular, the specific purposes for which personal data are processed should be explicit and legitimate and determined at the time of the collection of the personal data. The personal data should be adequate, relevant and limited to what is necessary for the purposes for which they are processed. This requires, in particular, ensuring that the period for which the personal data are stored is limited to a strict minimum. Personal data should be processed only if the purpose of the processing could not reasonably be fulfilled by other means. In order to ensure that the personal data are not kept longer than necessary, time limits should be established by the controller for erasure or for a periodic review. Every reasonable step should be taken to ensure that personal data which are inaccurate are rectified or deleted. Personal data should be processed in a manner that ensures appropriate security and confidentiality of the personal data, including for preventing unauthorised access to or use of personal data and the equipment used for the processing.\n(40)In order for processing to be lawful, personal data should be processed on the basis of the consent of the data subject concerned or some other legitimate basis, laid down by law, either in this Regulation or in other Union or Member State law as referred to in this Regulation, including the necessity for compliance with the legal obligation to which the controller is subject or the necessity for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.\n(41)Where this Regulation refers to a legal basis or a legislative measure, this does not necessarily require a legislative act adopted by a parliament, without prejudice to requirements pursuant to the constitutional order of the Member State concerned. However, such a legal basis or legislative measure should be clear and precise and its application should be foreseeable to persons subject to it, in accordance with the case-law of the Court of Justice of the European Union (the ‘Court of Justice’) and the European Court of Human Rights.\n(42)Where processing is based on the data subject\u0026rsquo;s consent, the controller should be able to demonstrate that the data subject has given consent to the processing operation. In particular in the context of a written declaration on another matter, safeguards should ensure that the data subject is aware of the fact that and the extent to which consent is given. In accordance with Council Directive 93/13/EEC(10) a declaration of consent pre-formulated by the controller should be provided in an intelligible and easily accessible form, using clear and plain language and it should not contain unfair terms. For consent to be informed, the data subject should be aware at least of the identity of the controller and the purposes of the processing for which the personal data are intended. Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.\n(43)In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation. Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance.\n(44)Processing should be lawful where it is necessary in the context of a contract or the intention to enter into a contract.\n(45)Where processing is carried out in accordance with a legal obligation to which the controller is subject or where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, the processing should have a basis in Union or Member State law. This Regulation does not require a specific law for each individual processing. A law as a basis for several processing operations based on a legal obligation to which the controller is subject or where processing is necessary for the performance of a task carried out in the public interest or in the exercise of an official authority may be sufficient. It should also be for Union or Member State law to determine the purpose of processing. Furthermore, that law could specify the general conditions of this Regulation governing the lawfulness of personal data processing, establish specifications for determining the controller, the type of personal data which are subject to the processing, the data subjects concerned, the entities to which the personal data may be disclosed, the purpose limitations, the storage period and other measures to ensure lawful and fair processing. It should also be for Union or Member State law to determine whether the controller performing a task carried out in the public interest or in the exercise of official authority should be a public authority or another natural or legal person governed by public law, or, where it is in the public interest to do so, including for health purposes such as public health and social protection and the management of health care services, by private law, such as a professional association.\n(46)The processing of personal data should also be regarded to be lawful where it is necessary to protect an interest which is essential for the life of the data subject or that of another natural person. Processing of personal data based on the vital interest of another natural person should in principle take place only where the processing cannot be manifestly based on another legal basis. Some types of processing may serve both important grounds of public interest and the vital interests of the data subject as for instance when processing is necessary for humanitarian purposes, including for monitoring epidemics and their spread or in situations of humanitarian emergencies, in particular in situations of natural and man-made disasters.\n(47)The legitimate interests of a controller, including those of a controller to which the personal data may be disclosed, or of a third party, may provide a legal basis for processing, provided that the interests or the fundamental rights and freedoms of the data subject are not overriding, taking into consideration the reasonable expectations of data subjects based on their relationship with the controller. Such legitimate interest could exist for example where there is a relevant and appropriate relationship between the data subject and the controller in situations such as where the data subject is a client or in the service of the controller. At any rate the existence of a legitimate interest would need careful assessment including whether a data subject can reasonably expect at the time and in the context of the collection of the personal data that processing for that purpose may take place. The interests and fundamental rights of the data subject could in particular override the interest of the data controller where personal data are processed in circumstances where data subjects do not reasonably expect further processing. Given that it is for the legislator to provide by law for the legal basis for public authorities to process personal data, that legal basis should not apply to the processing by public authorities in the performance of their tasks. The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned. The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.\n(48)Controllers that are part of a group of undertakings or institutions affiliated to a central body may have a legitimate interest in transmitting personal data within the group of undertakings for internal administrative purposes, including the processing of clients\u0026rsquo; or employees\u0026rsquo; personal data. The general principles for the transfer of personal data, within a group of undertakings, to an undertaking located in a third country remain unaffected.\n(49)The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, by public authorities, by computer emergency response teams (CERTs), computer security incident response teams (CSIRTs), by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems.\n(50)The processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which the personal data were initially collected. In such a case, no legal basis separate from that which allowed the collection of the personal data is required. If the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Union or Member State law may determine and specify the tasks and purposes for which the further processing should be regarded as compatible and lawful. Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be considered to be compatible lawful processing operations. The legal basis provided by Union or Member State law for the processing of personal data may also provide a legal basis for further processing. In order to ascertain whether a purpose of further processing is compatible with the purpose for which the personal data are initially collected, the controller, after having met all the requirements for the lawfulness of the original processing, should take into account, inter alia: any link between those purposes and the purposes of the intended further processing; the context in which the personal data have been collected, in particular the reasonable expectations of data subjects based on their relationship with the controller as to their further use; the nature of the personal data; the consequences of the intended further processing for data subjects; and the existence of appropriate safeguards in both the original and intended further processing operations.\nWhere the data subject has given consent or the processing is based on Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard, in particular, important objectives of general public interest, the controller should be allowed to further process the personal data irrespective of the compatibility of the purposes. In any case, the application of the principles set out in this Regulation and in particular the information of the data subject on those other purposes and on his or her rights including the right to object, should be ensured. Indicating possible criminal acts or threats to public security by the controller and transmitting the relevant personal data in individual cases or in several cases relating to the same criminal act or threats to public security to a competent authority should be regarded as being in the legitimate interest pursued by the controller. However, such transmission in the legitimate interest of the controller or further processing of personal data should be prohibited if the processing is not compatible with a legal, professional or other binding obligation of secrecy.\n(51)Personal data which are, by their nature, particularly sensitive in relation to fundamental rights and freedoms merit specific protection as the context of their processing could create significant risks to the fundamental rights and freedoms. Those personal data should include personal data revealing racial or ethnic origin, whereby the use of the term ‘racial origin’ in this Regulation does not imply an acceptance by the Union of theories which attempt to determine the existence of separate human races. The processing of photographs should not systematically be considered to be processing of special categories of personal data as they are covered by the definition of biometric data only when processed through a specific technical means allowing the unique identification or authentication of a natural person. Such personal data should not be processed, unless processing is allowed in specific cases set out in this Regulation, taking into account that Member States law may lay down specific provisions on data protection in order to adapt the application of the rules of this Regulation for compliance with a legal obligation or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. In addition to the specific requirements for such processing, the general principles and other rules of this Regulation should apply, in particular as regards the conditions for lawful processing. Derogations from the general prohibition for processing such special categories of personal data should be explicitly provided, inter alia, where the data subject gives his or her explicit consent or in respect of specific needs in particular where the processing is carried out in the course of legitimate activities by certain associations or foundations the purpose of which is to permit the exercise of fundamental freedoms.\n(52)Derogating from the prohibition on processing special categories of personal data should also be allowed when provided for in Union or Member State law and subject to suitable safeguards, so as to protect personal data and other fundamental rights, where it is in the public interest to do so, in particular processing personal data in the field of employment law, social protection law including pensions and for health security, monitoring and alert purposes, the prevention or control of communicable diseases and other serious threats to health. Such a derogation may be made for health purposes, including public health and the management of health-care services, especially in order to ensure the quality and cost-effectiveness of the procedures used for settling claims for benefits and services in the health insurance system, or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. A derogation should also allow the processing of such personal data where necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.\n(53)Special categories of personal data which merit higher protection should be processed for health-related purposes only where necessary to achieve those purposes for the benefit of natural persons and society as a whole, in particular in the context of the management of health or social care services and systems, including processing by the management and central national health authorities of such data for the purpose of quality control, management information and the general national and local supervision of the health or social care system, and ensuring continuity of health or social care and cross-border healthcare or health security, monitoring and alert purposes, or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, based on Union or Member State law which has to meet an objective of public interest, as well as for studies conducted in the public interest in the area of public health. Therefore, this Regulation should provide for harmonised conditions for the processing of special categories of personal data concerning health, in respect of specific needs, in particular where the processing of such data is carried out for certain health-related purposes by persons subject to a legal obligation of professional secrecy. Union or Member State law should provide for specific and suitable measures so as to protect the fundamental rights and the personal data of natural persons. Member States should be allowed to maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health. However, this should not hamper the free flow of personal data within the Union when those conditions apply to cross-border processing of such data.\n(54)The processing of special categories of personal data may be necessary for reasons of public interest in the areas of public health without consent of the data subject. Such processing should be subject to suitable and specific measures so as to protect the rights and freedoms of natural persons. In that context, ‘public health’ should be interpreted as defined in Regulation (EC) No 1338/2008 of the European Parliament and of the Council(11), namely all elements related to health, namely health status, including morbidity and disability, the determinants having an effect on that health status, health care needs, resources allocated to health care, the provision of, and universal access to, health care as well as health care expenditure and financing, and the causes of mortality. Such processing of data concerning health for reasons of public interest should not result in personal data being processed for other purposes by third parties such as employers or insurance and banking companies.\n(55)Moreover, the processing of personal data by official authorities for the purpose of achieving the aims, laid down by constitutional law or by international public law, of officially recognised religious associations, is carried out on grounds of public interest.\n(56)Where in the course of electoral activities, the operation of the democratic system in a Member State requires that political parties compile personal data on people\u0026rsquo;s political opinions, the processing of such data may be permitted for reasons of public interest, provided that appropriate safeguards are established.\n(57)If the personal data processed by a controller do not permit the controller to identify a natural person, the data controller should not be obliged to acquire additional information in order to identify the data subject for the sole purpose of complying with any provision of this Regulation. However, the controller should not refuse to take additional information provided by the data subject in order to support the exercise of his or her rights. Identification should include the digital identification of a data subject, for example through authentication mechanism such as the same credentials, used by the data subject to log-in to the on-line service offered by the data controller.\n(58)The principle of transparency requires that any information addressed to the public or to the data subject be concise, easily accessible and easy to understand, and that clear and plain language and, additionally, where appropriate, visualisation be used. Such information could be provided in electronic form, for example, when addressed to the public, through a website. This is of particular relevance in situations where the proliferation of actors and the technological complexity of practice make it difficult for the data subject to know and understand whether, by whom and for what purpose personal data relating to him or her are being collected, such as in the case of online advertising. Given that children merit specific protection, any information and communication, where processing is addressed to a child, should be in such a clear and plain language that the child can easily understand.\n(59)Modalities should be provided for facilitating the exercise of the data subject\u0026rsquo;s rights under this Regulation, including mechanisms to request and, if applicable, obtain, free of charge, in particular, access to and rectification or erasure of personal data and the exercise of the right to object. The controller should also provide means for requests to be made electronically, especially where personal data are processed by electronic means. The controller should be obliged to respond to requests from the data subject without undue delay and at the latest within one month and to give reasons where the controller does not intend to comply with any such requests.\n(60)The principles of fair and transparent processing require that the data subject be informed of the existence of the processing operation and its purposes. The controller should provide the data subject with any further information necessary to ensure fair and transparent processing taking into account the specific circumstances and context in which the personal data are processed. Furthermore, the data subject should be informed of the existence of profiling and the consequences of such profiling. Where the personal data are collected from the data subject, the data subject should also be informed whether he or she is obliged to provide the personal data and of the consequences, where he or she does not provide such data. That information may be provided in combination with standardised icons in order to give in an easily visible, intelligible and clearly legible manner, a meaningful overview of the intended processing. Where the icons are presented electronically, they should be machine-readable.\n(61)The information in relation to the processing of personal data relating to the data subject should be given to him or her at the time of collection from the data subject, or, where the personal data are obtained from another source, within a reasonable period, depending on the circumstances of the case. Where personal data can be legitimately disclosed to another recipient, the data subject should be informed when the personal data are first disclosed to the recipient. Where the controller intends to process the personal data for a purpose other than that for which they were collected, the controller should provide the data subject prior to that further processing with information on that other purpose and other necessary information. Where the origin of the personal data cannot be provided to the data subject because various sources have been used, general information should be provided.\n(62)However, it is not necessary to impose the obligation to provide information where the data subject already possesses the information, where the recording or disclosure of the personal data is expressly laid down by law or where the provision of information to the data subject proves to be impossible or would involve a disproportionate effort. The latter could in particular be the case where processing is carried out for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. In that regard, the number of data subjects, the age of the data and any appropriate safeguards adopted should be taken into consideration.\n(63)A data subject should have the right of access to personal data which have been collected concerning him or her, and to exercise that right easily and at reasonable intervals, in order to be aware of, and verify, the lawfulness of the processing. This includes the right for data subjects to have access to data concerning their health, for example the data in their medical records containing information such as diagnoses, examination results, assessments by treating physicians and any treatment or interventions provided. Every data subject should therefore have the right to know and obtain communication in particular with regard to the purposes for which the personal data are processed, where possible the period for which the personal data are processed, the recipients of the personal data, the logic involved in any automatic personal data processing and, at least when based on profiling, the consequences of such processing. Where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data. That right should not adversely affect the rights or freedoms of others, including trade secrets or intellectual property and in particular the copyright protecting the software. However, the result of those considerations should not be a refusal to provide all information to the data subject. Where the controller processes a large quantity of information concerning the data subject, the controller should be able to request that, before the information is delivered, the data subject specify the information or processing activities to which the request relates.\n(64)The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers. A controller should not retain personal data for the sole purpose of being able to react to potential requests.\n(65)A data subject should have the right to have personal data concerning him or her rectified and a ‘right to be forgotten’ where the retention of such data infringes this Regulation or Union or Member State law to which the controller is subject. In particular, a data subject should have the right to have his or her personal data erased and no longer processed where the personal data are no longer necessary in relation to the purposes for which they are collected or otherwise processed, where a data subject has withdrawn his or her consent or objects to the processing of personal data concerning him or her, or where the processing of his or her personal data does not otherwise comply with this Regulation. That right is relevant in particular where the data subject has given his or her consent as a child and is not fully aware of the risks involved by the processing, and later wants to remove such personal data, especially on the internet. The data subject should be able to exercise that right notwithstanding the fact that he or she is no longer a child. However, the further retention of the personal data should be lawful where it is necessary, for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, on the grounds of public interest in the area of public health, for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, or for the establishment, exercise or defence of legal claims.\n(66)To strengthen the right to be forgotten in the online environment, the right to erasure should also be extended in such a way that a controller who has made the personal data public should be obliged to inform the controllers which are processing such personal data to erase any links to, or copies or replications of those personal data. In doing so, that controller should take reasonable steps, taking into account available technology and the means available to the controller, including technical measures, to inform the controllers which are processing the personal data of the data subject\u0026rsquo;s request.\n(67)Methods by which to restrict the processing of personal data could include, inter alia, temporarily moving the selected data to another processing system, making the selected personal data unavailable to users, or temporarily removing published data from a website. In automated filing systems, the restriction of processing should in principle be ensured by technical means in such a manner that the personal data are not subject to further processing operations and cannot be changed. The fact that the processing of personal data is restricted should be clearly indicated in the system.\n(68)To further strengthen the control over his or her own data, where the processing of personal data is carried out by automated means, the data subject should also be allowed to receive personal data concerning him or her which he or she has provided to a controller in a structured, commonly used, machine-readable and interoperable format, and to transmit it to another controller. Data controllers should be encouraged to develop interoperable formats that enable data portability. That right should apply where the data subject provided the personal data on the basis of his or her consent or the processing is necessary for the performance of a contract. It should not apply where processing is based on a legal ground other than consent or contract. By its very nature, that right should not be exercised against controllers processing personal data in the exercise of their public duties. It should therefore not apply where the processing of the personal data is necessary for compliance with a legal obligation to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of an official authority vested in the controller. The data subject\u0026rsquo;s right to transmit or receive personal data concerning him or her should not create an obligation for the controllers to adopt or maintain processing systems which are technically compatible. Where, in a certain set of personal data, more than one data subject is concerned, the right to receive the personal data should be without prejudice to the rights and freedoms of other data subjects in accordance with this Regulation. Furthermore, that right should not prejudice the right of the data subject to obtain the erasure of personal data and the limitations of that right as set out in this Regulation and should, in particular, not imply the erasure of personal data concerning the data subject which have been provided by him or her for the performance of a contract to the extent that and for as long as the personal data are necessary for the performance of that contract. Where technically feasible, the data subject should have the right to have the personal data transmitted directly from one controller to another.\n(69)Where personal data might lawfully be processed because processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or on grounds of the legitimate interests of a controller or a third party, a data subject should, nevertheless, be entitled to object to the processing of any personal data relating to his or her particular situation. It should be for the controller to demonstrate that its compelling legitimate interest overrides the interests or the fundamental rights and freedoms of the data subject.\n(70)Where personal data are processed for the purposes of direct marketing, the data subject should have the right to object to such processing, including profiling to the extent that it is related to such direct marketing, whether with regard to initial or further processing, at any time and free of charge. That right should be explicitly brought to the attention of the data subject and presented clearly and separately from any other information.\n(71)The data subject should have the right not to be subject to a decision, which may include a measure, evaluating personal aspects relating to him or her which is based solely on automated processing and which produces legal effects concerning him or her or similarly significantly affects him or her, such as automatic refusal of an online credit application or e-recruiting practices without any human intervention. Such processing includes ‘profiling’ that consists of any form of automated processing of personal data evaluating the personal aspects relating to a natural person, in particular to analyse or predict aspects concerning the data subject\u0026rsquo;s performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, where it produces legal effects concerning him or her or similarly significantly affects him or her. However, decision-making based on such processing, including profiling, should be allowed where expressly authorised by Union or Member State law to which the controller is subject, including for fraud and tax-evasion monitoring and prevention purposes conducted in accordance with the regulations, standards and recommendations of Union institutions or national oversight bodies and to ensure the security and reliability of a service provided by the controller, or necessary for the entering or performance of a contract between the data subject and a controller, or when the data subject has given his or her explicit consent. In any case, such processing should be subject to suitable safeguards, which should include specific information to the data subject and the right to obtain human intervention, to express his or her point of view, to obtain an explanation of the decision reached after such assessment and to challenge the decision. Such measure should not concern a child.\nIn order to ensure fair and transparent processing in respect of the data subject, taking into account the specific circumstances and context in which the personal data are processed, the controller should use appropriate mathematical or statistical procedures for the profiling, implement technical and organisational measures appropriate to ensure, in particular, that factors which result in inaccuracies in personal data are corrected and the risk of errors is minimised, secure personal data in a manner that takes account of the potential risks involved for the interests and rights of the data subject and that prevents, inter alia, discriminatory effects on natural persons on the basis of racial or ethnic origin, political opinion, religion or beliefs, trade union membership, genetic or health status or sexual orientation, or that result in measures having such an effect. Automated decision-making and profiling based on special categories of personal data should be allowed only under specific conditions.\n(72)Profiling is subject to the rules of this Regulation governing the processing of personal data, such as the legal grounds for processing or data protection principles. The European Data Protection Board established by this Regulation (the ‘Board’) should be able to issue guidance in that context.\n(73)Restrictions concerning specific principles and the rights of information, access to and rectification or erasure of personal data, the right to data portability, the right to object, decisions based on profiling, as well as the communication of a personal data breach to a data subject and certain related obligations of the controllers may be imposed by Union or Member State law, as far as necessary and proportionate in a democratic society to safeguard public security, including the protection of human life especially in response to natural or manmade disasters, the prevention, investigation and prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, or of breaches of ethics for regulated professions, other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, the keeping of public registers kept for reasons of general public interest, further processing of archived personal data to provide specific information related to the political behaviour under former totalitarian state regimes or the protection of the data subject or the rights and freedoms of others, including social protection, public health and humanitarian purposes. Those restrictions should be in accordance with the requirements set out in the Charter and in the European Convention for the Protection of Human Rights and Fundamental Freedoms.\n(74)The responsibility and liability of the controller for any processing of personal data carried out by the controller or on the controller\u0026rsquo;s behalf should be established. In particular, the controller should be obliged to implement appropriate and effective measures and be able to demonstrate the compliance of processing activities with this Regulation, including the effectiveness of the measures. Those measures should take into account the nature, scope, context and purposes of the processing and the risk to the rights and freedoms of natural persons.\n(75)The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, and the processing of genetic data, data concerning health or data concerning sex life or criminal convictions and offences or related security measures; where personal aspects are evaluated, in particular analysing or predicting aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, in order to create or use personal profiles; where personal data of vulnerable natural persons, in particular of children, are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.\n(76)The likelihood and severity of the risk to the rights and freedoms of the data subject should be determined by reference to the nature, scope, context and purposes of the processing. Risk should be evaluated on the basis of an objective assessment, by which it is established whether data processing operations involve a risk or a high risk.\n(77)Guidance on the implementation of appropriate measures and on the demonstration of compliance by the controller or the processor, especially as regards the identification of the risk related to the processing, their assessment in terms of origin, nature, likelihood and severity, and the identification of best practices to mitigate the risk, could be provided in particular by means of approved codes of conduct, approved certifications, guidelines provided by the Board or indications provided by a data protection officer. The Board may also issue guidelines on processing operations that are considered to be unlikely to result in a high risk to the rights and freedoms of natural persons and indicate what measures may be sufficient in such cases to address such risk.\n(78)The protection of the rights and freedoms of natural persons with regard to the processing of personal data require that appropriate technical and organisational measures be taken to ensure that the requirements of this Regulation are met. In order to be able to demonstrate compliance with this Regulation, the controller should adopt internal policies and implement measures which meet in particular the principles of data protection by design and data protection by default. Such measures could consist, inter alia, of minimising the processing of personal data, pseudonymising personal data as soon as possible, transparency with regard to the functions and processing of personal data, enabling the data subject to monitor the data processing, enabling the controller to create and improve security features. When developing, designing, selecting and using applications, services and products that are based on the processing of personal data or process personal data to fulfil their task, producers of the products, services and applications should be encouraged to take into account the right to data protection when developing and designing such products, services and applications and, with due regard to the state of the art, to make sure that controllers and processors are able to fulfil their data protection obligations. The principles of data protection by design and by default should also be taken into consideration in the context of public tenders.\n(79)The protection of the rights and freedoms of data subjects as well as the responsibility and liability of controllers and processors, also in relation to the monitoring by and measures of supervisory authorities, requires a clear allocation of the responsibilities under this Regulation, including where a controller determines the purposes and means of the processing jointly with other controllers or where a processing operation is carried out on behalf of a controller.\n(80)Where a controller or a processor not established in the Union is processing personal data of data subjects who are in the Union whose processing activities are related to the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union, or to the monitoring of their behaviour as far as their behaviour takes place within the Union, the controller or the processor should designate a representative, unless the processing is occasional, does not include processing, on a large scale, of special categories of personal data or the processing of personal data relating to criminal convictions and offences, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing or if the controller is a public authority or body. The representative should act on behalf of the controller or the processor and may be addressed by any supervisory authority. The representative should be explicitly designated by a written mandate of the controller or of the processor to act on its behalf with regard to its obligations under this Regulation. The designation of such a representative does not affect the responsibility or liability of the controller or of the processor under this Regulation. Such a representative should perform its tasks according to the mandate received from the controller or processor, including cooperating with the competent supervisory authorities with regard to any action taken to ensure compliance with this Regulation. The designated representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor.\n(81)To ensure compliance with the requirements of this Regulation in respect of the processing to be carried out by the processor on behalf of the controller, when entrusting a processor with processing activities, the controller should use only processors providing sufficient guarantees, in particular in terms of expert knowledge, reliability and resources, to implement technical and organisational measures which will meet the requirements of this Regulation, including for the security of processing. The adherence of the processor to an approved code of conduct or an approved certification mechanism may be used as an element to demonstrate compliance with the obligations of the controller. The carrying-out of processing by a processor should be governed by a contract or other legal act under Union or Member State law, binding the processor to the controller, setting out the subject-matter and duration of the processing, the nature and purposes of the processing, the type of personal data and categories of data subjects, taking into account the specific tasks and responsibilities of the processor in the context of the processing to be carried out and the risk to the rights and freedoms of the data subject. The controller and processor may choose to use an individual contract or standard contractual clauses which are adopted either directly by the Commission or by a supervisory authority in accordance with the consistency mechanism and then adopted by the Commission. After the completion of the processing on behalf of the controller, the processor should, at the choice of the controller, return or delete the personal data, unless there is a requirement to store the personal data under Union or Member State law to which the processor is subject.\n(82)In order to demonstrate compliance with this Regulation, the controller or processor should maintain records of processing activities under its responsibility. Each controller and processor should be obliged to cooperate with the supervisory authority and make those records, on request, available to it, so that it might serve for monitoring those processing operations.\n(83)In order to maintain security and to prevent processing in infringement of this Regulation, the controller or processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks, such as encryption. Those measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the costs of implementation in relation to the risks and the nature of the personal data to be protected. In assessing data security risk, consideration should be given to the risks that are presented by personal data processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed which may in particular lead to physical, material or non-material damage.\n(84)In order to enhance compliance with this Regulation where processing operations are likely to result in a high risk to the rights and freedoms of natural persons, the controller should be responsible for the carrying-out of a data protection impact assessment to evaluate, in particular, the origin, nature, particularity and severity of that risk. The outcome of the assessment should be taken into account when determining the appropriate measures to be taken in order to demonstrate that the processing of personal data complies with this Regulation. Where a data-protection impact assessment indicates that processing operations involve a high risk which the controller cannot mitigate by appropriate measures in terms of available technology and costs of implementation, a consultation of the supervisory authority should take place prior to the processing.\n(85)A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal data or limitation of their rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of personal data protected by professional secrecy or any other significant economic or social disadvantage to the natural person concerned. Therefore, as soon as the controller becomes aware that a personal data breach has occurred, the controller should notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the controller is able to demonstrate, in accordance with the accountability principle, that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where such notification cannot be achieved within 72 hours, the reasons for the delay should accompany the notification and information may be provided in phases without undue further delay.\n(86)The controller should communicate to the data subject a personal data breach, without undue delay, where that personal data breach is likely to result in a high risk to the rights and freedoms of the natural person in order to allow him or her to take the necessary precautions. The communication should describe the nature of the personal data breach as well as recommendations for the natural person concerned to mitigate potential adverse effects. Such communications to data subjects should be made as soon as reasonably feasible and in close cooperation with the supervisory authority, respecting guidance provided by it or by other relevant authorities such as law-enforcement authorities. For example, the need to mitigate an immediate risk of damage would call for prompt communication with data subjects whereas the need to implement appropriate measures against continuing or similar personal data breaches may justify more time for communication.\n(87)It should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place and to inform promptly the supervisory authority and the data subject. The fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject. Such notification may result in an intervention of the supervisory authority in accordance with its tasks and powers laid down in this Regulation.\n(88)In setting detailed rules concerning the format and procedures applicable to the notification of personal data breaches, due consideration should be given to the circumstances of that breach, including whether or not personal data had been protected by appropriate technical protection measures, effectively limiting the likelihood of identity fraud or other forms of misuse. Moreover, such rules and procedures should take into account the legitimate interests of law-enforcement authorities where early disclosure could unnecessarily hamper the investigation of the circumstances of a personal data breach.\n(89)Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation produces administrative and financial burdens, it did not in all cases contribute to improving the protection of personal data. Such indiscriminate general notification obligations should therefore be abolished, and replaced by effective procedures and mechanisms which focus instead on those types of processing operations which are likely to result in a high risk to the rights and freedoms of natural persons by virtue of their nature, scope, context and purposes. Such types of processing operations may be those which in, particular, involve using new technologies, or are of a new kind and where no data protection impact assessment has been carried out before by the controller, or where they become necessary in the light of the time that has elapsed since the initial processing.\n(90)In such cases, a data protection impact assessment should be carried out by the controller prior to the processing in order to assess the particular likelihood and severity of the high risk, taking into account the nature, scope, context and purposes of the processing and the sources of the risk. That impact assessment should include, in particular, the measures, safeguards and mechanisms envisaged for mitigating that risk, ensuring the protection of personal data and demonstrating compliance with this Regulation.\n(91)This should in particular apply to large-scale processing operations which aim to process a considerable amount of personal data at regional, national or supranational level and which could affect a large number of data subjects and which are likely to result in a high risk, for example, on account of their sensitivity, where in accordance with the achieved state of technological knowledge a new technology is used on a large scale as well as to other processing operations which result in a high risk to the rights and freedoms of data subjects, in particular where those operations render it more difficult for data subjects to exercise their rights. A data protection impact assessment should also be made where personal data are processed for taking decisions regarding specific natural persons following any systematic and extensive evaluation of personal aspects relating to natural persons based on profiling those data or following the processing of special categories of personal data, biometric data, or data on criminal convictions and offences or related security measures. A data protection impact assessment is equally required for monitoring publicly accessible areas on a large scale, especially when using optic-electronic devices or for any other operations where the competent supervisory authority considers that the processing is likely to result in a high risk to the rights and freedoms of data subjects, in particular because they prevent data subjects from exercising a right or using a service or a contract, or because they are carried out systematically on a large scale. The processing of personal data should not be considered to be on a large scale if the processing concerns personal data from patients or clients by an individual physician, other health care professional or lawyer. In such cases, a data protection impact assessment should not be mandatory.\n(92)There are circumstances under which it may be reasonable and economical for the subject of a data protection impact assessment to be broader than a single project, for example where public authorities or bodies intend to establish a common application or processing platform or where several controllers plan to introduce a common application or processing environment across an industry sector or segment or for a widely used horizontal activity.\n(93)In the context of the adoption of the Member State law on which the performance of the tasks of the public authority or public body is based and which regulates the specific processing operation or set of operations in question, Member States may deem it necessary to carry out such assessment prior to the processing activities.\n(94)Where a data protection impact assessment indicates that the processing would, in the absence of safeguards, security measures and mechanisms to mitigate the risk, result in a high risk to the rights and freedoms of natural persons and the controller is of the opinion that the risk cannot be mitigated by reasonable means in terms of available technologies and costs of implementation, the supervisory authority should be consulted prior to the start of processing activities. Such high risk is likely to result from certain types of processing and the extent and frequency of processing, which may result also in a realisation of damage or interference with the rights and freedoms of the natural person. The supervisory authority should respond to the request for consultation within a specified period. However, the absence of a reaction of the supervisory authority within that period should be without prejudice to any intervention of the supervisory authority in accordance with its tasks and powers laid down in this Regulation, including the power to prohibit processing operations. As part of that consultation process, the outcome of a data protection impact assessment carried out with regard to the processing at issue may be submitted to the supervisory authority, in particular the measures envisaged to mitigate the risk to the rights and freedoms of natural persons.\n(95)The processor should assist the controller, where necessary and upon request, in ensuring compliance with the obligations deriving from the carrying out of data protection impact assessments and from prior consultation of the supervisory authority.\n(96)A consultation of the supervisory authority should also take place in the course of the preparation of a legislative or regulatory measure which provides for the processing of personal data, in order to ensure compliance of the intended processing with this Regulation and in particular to mitigate the risk involved for the data subject.\n(97)Where the processing is carried out by a public authority, except for courts or independent judicial authorities when acting in their judicial capacity, where, in the private sector, processing is carried out by a controller whose core activities consist of processing operations that require regular and systematic monitoring of the data subjects on a large scale, or where the core activities of the controller or the processor consist of processing on a large scale of special categories of personal data and data relating to criminal convictions and offences, a person with expert knowledge of data protection law and practices should assist the controller or processor to monitor internal compliance with this Regulation. In the private sector, the core activities of a controller relate to its primary activities and do not relate to the processing of personal data as ancillary activities. The necessary level of expert knowledge should be determined in particular according to the data processing operations carried out and the protection required for the personal data processed by the controller or the processor. Such data protection officers, whether or not they are an employee of the controller, should be in a position to perform their duties and tasks in an independent manner.\n(98)Associations or other bodies representing categories of controllers or processors should be encouraged to draw up codes of conduct, within the limits of this Regulation, so as to facilitate the effective application of this Regulation, taking account of the specific characteristics of the processing carried out in certain sectors and the specific needs of micro, small and medium enterprises. In particular, such codes of conduct could calibrate the obligations of controllers and processors, taking into account the risk likely to result from the processing for the rights and freedoms of natural persons.\n(99)When drawing up a code of conduct, or when amending or extending such a code, associations and other bodies representing categories of controllers or processors should consult relevant stakeholders, including data subjects where feasible, and have regard to submissions received and views expressed in response to such consultations.\n(100)In order to enhance transparency and compliance with this Regulation, the establishment of certification mechanisms and data protection seals and marks should be encouraged, allowing data subjects to quickly assess the level of data protection of relevant products and services.\n(101)Flows of personal data to and from countries outside the Union and international organisations are necessary for the expansion of international trade and international cooperation. The increase in such flows has raised new challenges and concerns with regard to the protection of personal data. However, when personal data are transferred from the Union to controllers, processors or other recipients in third countries or to international organisations, the level of protection of natural persons ensured in the Union by this Regulation should not be undermined, including in cases of onward transfers of personal data from the third country or international organisation to controllers, processors in the same or another third country or international organisation. In any event, transfers to third countries and international organisations may only be carried out in full compliance with this Regulation. A transfer could take place only if, subject to the other provisions of this Regulation, the conditions laid down in the provisions of this Regulation relating to the transfer of personal data to third countries or international organisations are complied with by the controller or processor.\n(102)This Regulation is without prejudice to international agreements concluded between the Union and third countries regulating the transfer of personal data including appropriate safeguards for the data subjects. Member States may conclude international agreements which involve the transfer of personal data to third countries or international organisations, as far as such agreements do not affect this Regulation or any other provisions of Union law and include an appropriate level of protection for the fundamental rights of the data subjects.\n(103)The Commission may decide with effect for the entire Union that a third country, a territory or specified sector within a third country, or an international organisation, offers an adequate level of data protection, thus providing legal certainty and uniformity throughout the Union as regards the third country or international organisation which is considered to provide such level of protection. In such cases, transfers of personal data to that third country or international organisation may take place without the need to obtain any further authorisation. The Commission may also decide, having given notice and a full statement setting out the reasons to the third country or international organisation, to revoke such a decision.\n(104)In line with the fundamental values on which the Union is founded, in particular the protection of human rights, the Commission should, in its assessment of the third country, or of a territory or specified sector within a third country, take into account how a particular third country respects the rule of law, access to justice as well as international human rights norms and standards and its general and sectoral law, including legislation concerning public security, defence and national security as well as public order and criminal law. The adoption of an adequacy decision with regard to a territory or a specified sector in a third country should take into account clear and objective criteria, such as specific processing activities and the scope of applicable legal standards and legislation in force in the third country. The third country should offer guarantees ensuring an adequate level of protection essentially equivalent to that ensured within the Union, in particular where personal data are processed in one or several specific sectors. In particular, the third country should ensure effective independent data protection supervision and should provide for cooperation mechanisms with the Member States\u0026rsquo; data protection authorities, and the data subjects should be provided with effective and enforceable rights and effective administrative and judicial redress.\n(105)Apart from the international commitments the third country or international organisation has entered into, the Commission should take account of obligations arising from the third country\u0026rsquo;s or international organisation\u0026rsquo;s participation in multilateral or regional systems in particular in relation to the protection of personal data, as well as the implementation of such obligations. In particular, the third country\u0026rsquo;s accession to the Council of Europe Convention of 28 January 1981 for the Protection of Individuals with regard to the Automatic Processing of Personal Data and its Additional Protocol should be taken into account. The Commission should consult the Board when assessing the level of protection in third countries or international organisations.\n(106)The Commission should monitor the functioning of decisions on the level of protection in a third country, a territory or specified sector within a third country, or an international organisation, and monitor the functioning of decisions adopted on the basis of Article 25(6) or Article 26(4) of Directive 95/46/EC. In its adequacy decisions, the Commission should provide for a periodic review mechanism of their functioning. That periodic review should be conducted in consultation with the third country or international organisation in question and take into account all relevant developments in the third country or international organisation. For the purposes of monitoring and of carrying out the periodic reviews, the Commission should take into consideration the views and findings of the European Parliament and of the Council as well as of other relevant bodies and sources. The Commission should evaluate, within a reasonable time, the functioning of the latter decisions and report any relevant findings to the Committee within the meaning of Regulation (EU) No 182/2011 of the European Parliament and of the Council(12) as established under this Regulation, to the European Parliament and to the Council.\n(107)The Commission may recognise that a third country, a territory or a specified sector within a third country, or an international organisation no longer ensures an adequate level of data protection. Consequently the transfer of personal data to that third country or international organisation should be prohibited, unless the requirements in this Regulation relating to transfers subject to appropriate safeguards, including binding corporate rules, and derogations for specific situations are fulfilled. In that case, provision should be made for consultations between the Commission and such third countries or international organisations. The Commission should, in a timely manner, inform the third country or international organisation of the reasons and enter into consultations with it in order to remedy the situation.\n(108)In the absence of an adequacy decision, the controller or processor should take measures to compensate for the lack of data protection in a third country by way of appropriate safeguards for the data subject. Such appropriate safeguards may consist of making use of binding corporate rules, standard data protection clauses adopted by the Commission, standard data protection clauses adopted by a supervisory authority or contractual clauses authorised by a supervisory authority. Those safeguards should ensure compliance with data protection requirements and the rights of the data subjects appropriate to processing within the Union, including the availability of enforceable data subject rights and of effective legal remedies, including to obtain effective administrative or judicial redress and to claim compensation, in the Union or in a third country. They should relate in particular to compliance with the general principles relating to personal data processing, the principles of data protection by design and by default. Transfers may also be carried out by public authorities or bodies with public authorities or bodies in third countries or with international organisations with corresponding duties or functions, including on the basis of provisions to be inserted into administrative arrangements, such as a memorandum of understanding, providing for enforceable and effective rights for data subjects. Authorisation by the competent supervisory authority should be obtained when the safeguards are provided for in administrative arrangements that are not legally binding.\n(109)The possibility for the controller or processor to use standard data-protection clauses adopted by the Commission or by a supervisory authority should prevent controllers or processors neither from including the standard data-protection clauses in a wider contract, such as a contract between the processor and another processor, nor from adding other clauses or additional safeguards provided that they do not contradict, directly or indirectly, the standard contractual clauses adopted by the Commission or by a supervisory authority or prejudice the fundamental rights or freedoms of the data subjects. Controllers and processors should be encouraged to provide additional safeguards via contractual commitments that supplement standard protection clauses.\n(110)A group of undertakings, or a group of enterprises engaged in a joint economic activity, should be able to make use of approved binding corporate rules for its international transfers from the Union to organisations within the same group of undertakings, or group of enterprises engaged in a joint economic activity, provided that such corporate rules include all essential principles and enforceable rights to ensure appropriate safeguards for transfers or categories of transfers of personal data.\n(111)Provisions should be made for the possibility for transfers in certain circumstances where the data subject has given his or her explicit consent, where the transfer is occasional and necessary in relation to a contract or a legal claim, regardless of whether in a judicial procedure or whether in an administrative or any out-of-court procedure, including procedures before regulatory bodies. Provision should also be made for the possibility for transfers where important grounds of public interest laid down by Union or Member State law so require or where the transfer is made from a register established by law and intended for consultation by the public or persons having a legitimate interest. In the latter case, such a transfer should not involve the entirety of the personal data or entire categories of the data contained in the register and, when the register is intended for consultation by persons having a legitimate interest, the transfer should be made only at the request of those persons or, if they are to be the recipients, taking into full account the interests and fundamental rights of the data subject.\n(112)Those derogations should in particular apply to data transfers required and necessary for important reasons of public interest, for example in cases of international data exchange between competition authorities, tax or customs administrations, between financial supervisory authorities, between services competent for social security matters, or for public health, for example in the case of contact tracing for contagious diseases or in order to reduce and/or eliminate doping in sport. A transfer of personal data should also be regarded as lawful where it is necessary to protect an interest which is essential for the data subject\u0026rsquo;s or another person\u0026rsquo;s vital interests, including physical integrity or life, if the data subject is incapable of giving consent. In the absence of an adequacy decision, Union or Member State law may, for important reasons of public interest, expressly set limits to the transfer of specific categories of data to a third country or an international organisation. Member States should notify such provisions to the Commission. Any transfer to an international humanitarian organisation of personal data of a data subject who is physically or legally incapable of giving consent, with a view to accomplishing a task incumbent under the Geneva Conventions or to complying with international humanitarian law applicable in armed conflicts, could be considered to be necessary for an important reason of public interest or because it is in the vital interest of the data subject.\n(113)Transfers which can be qualified as not repetitive and that only concern a limited number of data subjects, could also be possible for the purposes of the compelling legitimate interests pursued by the controller, when those interests are not overridden by the interests or rights and freedoms of the data subject and when the controller has assessed all the circumstances surrounding the data transfer. The controller should give particular consideration to the nature of the personal data, the purpose and duration of the proposed processing operation or operations, as well as the situation in the country of origin, the third country and the country of final destination, and should provide suitable safeguards to protect fundamental rights and freedoms of natural persons with regard to the processing of their personal data. Such transfers should be possible only in residual cases where none of the other grounds for transfer are applicable. For scientific or historical research purposes or statistical purposes, the legitimate expectations of society for an increase of knowledge should be taken into consideration. The controller should inform the supervisory authority and the data subject about the transfer.\n(114)In any case, where the Commission has taken no decision on the adequate level of data protection in a third country, the controller or processor should make use of solutions that provide data subjects with enforceable and effective rights as regards the processing of their data in the Union once those data have been transferred so that that they will continue to benefit from fundamental rights and safeguards.\n(115)Some third countries adopt laws, regulations and other legal acts which purport to directly regulate the processing activities of natural and legal persons under the jurisdiction of the Member States. This may include judgments of courts or tribunals or decisions of administrative authorities in third countries requiring a controller or processor to transfer or disclose personal data, and which are not based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State. The extraterritorial application of those laws, regulations and other legal acts may be in breach of international law and may impede the attainment of the protection of natural persons ensured in the Union by this Regulation. Transfers should only be allowed where the conditions of this Regulation for a transfer to third countries are met. This may be the case, inter alia, where disclosure is necessary for an important ground of public interest recognised in Union or Member State law to which the controller is subject.\n(116)When personal data moves across borders outside the Union it may put at increased risk the ability of natural persons to exercise data protection rights in particular to protect themselves from the unlawful use or disclosure of that information. At the same time, supervisory authorities may find that they are unable to pursue complaints or conduct investigations relating to the activities outside their borders. Their efforts to work together in the cross-border context may also be hampered by insufficient preventative or remedial powers, inconsistent legal regimes, and practical obstacles like resource constraints. Therefore, there is a need to promote closer cooperation among data protection supervisory authorities to help them exchange information and carry out investigations with their international counterparts. For the purposes of developing international cooperation mechanisms to facilitate and provide international mutual assistance for the enforcement of legislation for the protection of personal data, the Commission and the supervisory authorities should exchange information and cooperate in activities related to the exercise of their powers with competent authorities in third countries, based on reciprocity and in accordance with this Regulation.\n(117)The establishment of supervisory authorities in Member States, empowered to perform their tasks and exercise their powers with complete independence, is an essential component of the protection of natural persons with regard to the processing of their personal data. Member States should be able to establish more than one supervisory authority, to reflect their constitutional, organisational and administrative structure.\n(118)The independence of supervisory authorities should not mean that the supervisory authorities cannot be subject to control or monitoring mechanisms regarding their financial expenditure or to judicial review.\n(119)Where a Member State establishes several supervisory authorities, it should establish by law mechanisms for ensuring the effective participation of those supervisory authorities in the consistency mechanism. That Member State should in particular designate the supervisory authority which functions as a single contact point for the effective participation of those authorities in the mechanism, to ensure swift and smooth cooperation with other supervisory authorities, the Board and the Commission.\n(120)Each supervisory authority should be provided with the financial and human resources, premises and infrastructure necessary for the effective performance of their tasks, including those related to mutual assistance and cooperation with other supervisory authorities throughout the Union. Each supervisory authority should have a separate, public annual budget, which may be part of the overall state or national budget.\n(121)The general conditions for the member or members of the supervisory authority should be laid down by law in each Member State and should in particular provide that those members are to be appointed, by means of a transparent procedure, either by the parliament, government or the head of State of the Member State on the basis of a proposal from the government, a member of the government, the parliament or a chamber of the parliament, or by an independent body entrusted under Member State law. In order to ensure the independence of the supervisory authority, the member or members should act with integrity, refrain from any action that is incompatible with their duties and should not, during their term of office, engage in any incompatible occupation, whether gainful or not. The supervisory authority should have its own staff, chosen by the supervisory authority or an independent body established by Member State law, which should be subject to the exclusive direction of the member or members of the supervisory authority.\n(122)Each supervisory authority should be competent on the territory of its own Member State to exercise the powers and to perform the tasks conferred on it in accordance with this Regulation. This should cover in particular the processing in the context of the activities of an establishment of the controller or processor on the territory of its own Member State, the processing of personal data carried out by public authorities or private bodies acting in the public interest, processing affecting data subjects on its territory or processing carried out by a controller or processor not established in the Union when targeting data subjects residing on its territory. This should include handling complaints lodged by a data subject, conducting investigations on the application of this Regulation and promoting public awareness of the risks, rules, safeguards and rights in relation to the processing of personal data.\n(123)The supervisory authorities should monitor the application of the provisions pursuant to this Regulation and contribute to its consistent application throughout the Union, in order to protect natural persons in relation to the processing of their personal data and to facilitate the free flow of personal data within the internal market. For that purpose, the supervisory authorities should cooperate with each other and with the Commission, without the need for any agreement between Member States on the provision of mutual assistance or on such cooperation.\n(124)Where the processing of personal data takes place in the context of the activities of an establishment of a controller or a processor in the Union and the controller or processor is established in more than one Member State, or where processing taking place in the context of the activities of a single establishment of a controller or processor in the Union substantially affects or is likely to substantially affect data subjects in more than one Member State, the supervisory authority for the main establishment of the controller or processor or for the single establishment of the controller or processor should act as lead authority. It should cooperate with the other authorities concerned, because the controller or processor has an establishment on the territory of their Member State, because data subjects residing on their territory are substantially affected, or because a complaint has been lodged with them. Also where a data subject not residing in that Member State has lodged a complaint, the supervisory authority with which such complaint has been lodged should also be a supervisory authority concerned. Within its tasks to issue guidelines on any question covering the application of this Regulation, the Board should be able to issue guidelines in particular on the criteria to be taken into account in order to ascertain whether the processing in question substantially affects data subjects in more than one Member State and on what constitutes a relevant and reasoned objection.\n(125)The lead authority should be competent to adopt binding decisions regarding measures applying the powers conferred on it in accordance with this Regulation. In its capacity as lead authority, the supervisory authority should closely involve and coordinate the supervisory authorities concerned in the decision-making process. Where the decision is to reject the complaint by the data subject in whole or in part, that decision should be adopted by the supervisory authority with which the complaint has been lodged.\n(126)The decision should be agreed jointly by the lead supervisory authority and the supervisory authorities concerned and should be directed towards the main or single establishment of the controller or processor and be binding on the controller and processor. The controller or processor should take the necessary measures to ensure compliance with this Regulation and the implementation of the decision notified by the lead supervisory authority to the main establishment of the controller or processor as regards the processing activities in the Union.\n(127)Each supervisory authority not acting as the lead supervisory authority should be competent to handle local cases where the controller or processor is established in more than one Member State, but the subject matter of the specific processing concerns only processing carried out in a single Member State and involves only data subjects in that single Member State, for example, where the subject matter concerns the processing of employees\u0026rsquo; personal data in the specific employment context of a Member State. In such cases, the supervisory authority should inform the lead supervisory authority without delay about the matter. After being informed, the lead supervisory authority should decide, whether it will handle the case pursuant to the provision on cooperation between the lead supervisory authority and other supervisory authorities concerned (‘one-stop-shop mechanism’), or whether the supervisory authority which informed it should handle the case at local level. When deciding whether it will handle the case, the lead supervisory authority should take into account whether there is an establishment of the controller or processor in the Member State of the supervisory authority which informed it in order to ensure effective enforcement of a decision vis-à-vis the controller or processor. Where the lead supervisory authority decides to handle the case, the supervisory authority which informed it should have the possibility to submit a draft for a decision, of which the lead supervisory authority should take utmost account when preparing its draft decision in that one-stop-shop mechanism.\n(128)The rules on the lead supervisory authority and the one-stop-shop mechanism should not apply where the processing is carried out by public authorities or private bodies in the public interest. In such cases the only supervisory authority competent to exercise the powers conferred to it in accordance with this Regulation should be the supervisory authority of the Member State where the public authority or private body is established.\n(129)In order to ensure consistent monitoring and enforcement of this Regulation throughout the Union, the supervisory authorities should have in each Member State the same tasks and effective powers, including powers of investigation, corrective powers and sanctions, and authorisation and advisory powers, in particular in cases of complaints from natural persons, and without prejudice to the powers of prosecutorial authorities under Member State law, to bring infringements of this Regulation to the attention of the judicial authorities and engage in legal proceedings. Such powers should also include the power to impose a temporary or definitive limitation, including a ban, on processing. Member States may specify other tasks related to the protection of personal data under this Regulation. The powers of supervisory authorities should be exercised in accordance with appropriate procedural safeguards set out in Union and Member State law, impartially, fairly and within a reasonable time. In particular each measure should be appropriate, necessary and proportionate in view of ensuring compliance with this Regulation, taking into account the circumstances of each individual case, respect the right of every person to be heard before any individual measure which would affect him or her adversely is taken and avoid superfluous costs and excessive inconveniences for the persons concerned. Investigatory powers as regards access to premises should be exercised in accordance with specific requirements in Member State procedural law, such as the requirement to obtain a prior judicial authorisation. Each legally binding measure of the supervisory authority should be in writing, be clear and unambiguous, indicate the supervisory authority which has issued the measure, the date of issue of the measure, bear the signature of the head, or a member of the supervisory authority authorised by him or her, give the reasons for the measure, and refer to the right of an effective remedy. This should not preclude additional requirements pursuant to Member State procedural law. The adoption of a legally binding decision implies that it may give rise to judicial review in the Member State of the supervisory authority that adopted the decision.\n(130)Where the supervisory authority with which the complaint has been lodged is not the lead supervisory authority, the lead supervisory authority should closely cooperate with the supervisory authority with which the complaint has been lodged in accordance with the provisions on cooperation and consistency laid down in this Regulation. In such cases, the lead supervisory authority should, when taking measures intended to produce legal effects, including the imposition of administrative fines, take utmost account of the view of the supervisory authority with which the complaint has been lodged and which should remain competent to carry out any investigation on the territory of its own Member State in liaison with the competent supervisory authority.\n(131)Where another supervisory authority should act as a lead supervisory authority for the processing activities of the controller or processor but the concrete subject matter of a complaint or the possible infringement concerns only processing activities of the controller or processor in the Member State where the complaint has been lodged or the possible infringement detected and the matter does not substantially affect or is not likely to substantially affect data subjects in other Member States, the supervisory authority receiving a complaint or detecting or being informed otherwise of situations that entail possible infringements of this Regulation should seek an amicable settlement with the controller and, if this proves unsuccessful, exercise its full range of powers. This should include: specific processing carried out in the territory of the Member State of the supervisory authority or with regard to data subjects on the territory of that Member State; processing that is carried out in the context of an offer of goods or services specifically aimed at data subjects in the territory of the Member State of the supervisory authority; or processing that has to be assessed taking into account relevant legal obligations under Member State law.\n(132)Awareness-raising activities by supervisory authorities addressed to the public should include specific measures directed at controllers and processors, including micro, small and medium-sized enterprises, as well as natural persons in particular in the educational context.\n(133)The supervisory authorities should assist each other in performing their tasks and provide mutual assistance, so as to ensure the consistent application and enforcement of this Regulation in the internal market. A supervisory authority requesting mutual assistance may adopt a provisional measure if it receives no response to a request for mutual assistance within one month of the receipt of that request by the other supervisory authority.\n(134)Each supervisory authority should, where appropriate, participate in joint operations with other supervisory authorities. The requested supervisory authority should be obliged to respond to the request within a specified time period.\n(135)In order to ensure the consistent application of this Regulation throughout the Union, a consistency mechanism for cooperation between the supervisory authorities should be established. That mechanism should in particular apply where a supervisory authority intends to adopt a measure intended to produce legal effects as regards processing operations which substantially affect a significant number of data subjects in several Member States. It should also apply where any supervisory authority concerned or the Commission requests that such matter should be handled in the consistency mechanism. That mechanism should be without prejudice to any measures that the Commission may take in the exercise of its powers under the Treaties.\n(136)In applying the consistency mechanism, the Board should, within a determined period of time, issue an opinion, if a majority of its members so decides or if so requested by any supervisory authority concerned or the Commission. The Board should also be empowered to adopt legally binding decisions where there are disputes between supervisory authorities. For that purpose, it should issue, in principle by a two-thirds majority of its members, legally binding decisions in clearly specified cases where there are conflicting views among supervisory authorities, in particular in the cooperation mechanism between the lead supervisory authority and supervisory authorities concerned on the merits of the case, in particular whether there is an infringement of this Regulation.\n(137)There may be an urgent need to act in order to protect the rights and freedoms of data subjects, in particular when the danger exists that the enforcement of a right of a data subject could be considerably impeded. A supervisory authority should therefore be able to adopt duly justified provisional measures on its territory with a specified period of validity which should not exceed three months.\n(138)The application of such mechanism should be a condition for the lawfulness of a measure intended to produce legal effects by a supervisory authority in those cases where its application is mandatory. In other cases of cross-border relevance, the cooperation mechanism between the lead supervisory authority and supervisory authorities concerned should be applied and mutual assistance and joint operations might be carried out between the supervisory authorities concerned on a bilateral or multilateral basis without triggering the consistency mechanism.\n(139)In order to promote the consistent application of this Regulation, the Board should be set up as an independent body of the Union. To fulfil its objectives, the Board should have legal personality. The Board should be represented by its Chair. It should replace the Working Party on the Protection of Individuals with Regard to the Processing of Personal Data established by Directive 95/46/EC. It should consist of the head of a supervisory authority of each Member State and the European Data Protection Supervisor or their respective representatives. The Commission should participate in the Board\u0026rsquo;s activities without voting rights and the European Data Protection Supervisor should have specific voting rights. The Board should contribute to the consistent application of this Regulation throughout the Union, including by advising the Commission, in particular on the level of protection in third countries or international organisations, and promoting cooperation of the supervisory authorities throughout the Union. The Board should act independently when performing its tasks.\n(140)The Board should be assisted by a secretariat provided by the European Data Protection Supervisor. The staff of the European Data Protection Supervisor involved in carrying out the tasks conferred on the Board by this Regulation should perform its tasks exclusively under the instructions of, and report to, the Chair of the Board.\n(141)Every data subject should have the right to lodge a complaint with a single supervisory authority, in particular in the Member State of his or her habitual residence, and the right to an effective judicial remedy in accordance with Article 47 of the Charter if the data subject considers that his or her rights under this Regulation are infringed or where the supervisory authority does not act on a complaint, partially or wholly rejects or dismisses a complaint or does not act where such action is necessary to protect the rights of the data subject. The investigation following a complaint should be carried out, subject to judicial review, to the extent that is appropriate in the specific case. The supervisory authority should inform the data subject of the progress and the outcome of the complaint within a reasonable period. If the case requires further investigation or coordination with another supervisory authority, intermediate information should be given to the data subject. In order to facilitate the submission of complaints, each supervisory authority should take measures such as providing a complaint submission form which can also be completed electronically, without excluding other means of communication.\n(142)Where a data subject considers that his or her rights under this Regulation are infringed, he or she should have the right to mandate a not-for-profit body, organisation or association which is constituted in accordance with the law of a Member State, has statutory objectives which are in the public interest and is active in the field of the protection of personal data to lodge a complaint on his or her behalf with a supervisory authority, exercise the right to a judicial remedy on behalf of data subjects or, if provided for in Member State law, exercise the right to receive compensation on behalf of data subjects. A Member State may provide for such a body, organisation or association to have the right to lodge a complaint in that Member State, independently of a data subject\u0026rsquo;s mandate, and the right to an effective judicial remedy where it has reasons to consider that the rights of a data subject have been infringed as a result of the processing of personal data which infringes this Regulation. That body, organisation or association may not be allowed to claim compensation on a data subject\u0026rsquo;s behalf independently of the data subject\u0026rsquo;s mandate.\n(143)Any natural or legal person has the right to bring an action for annulment of decisions of the Board before the Court of Justice under the conditions provided for in Article 263 TFEU. As addressees of such decisions, the supervisory authorities concerned which wish to challenge them have to bring action within two months of being notified of them, in accordance with Article 263 TFEU. Where decisions of the Board are of direct and individual concern to a controller, processor or complainant, the latter may bring an action for annulment against those decisions within two months of their publication on the website of the Board, in accordance with Article 263 TFEU. Without prejudice to this right under Article 263 TFEU, each natural or legal person should have an effective judicial remedy before the competent national court against a decision of a supervisory authority which produces legal effects concerning that person. Such a decision concerns in particular the exercise of investigative, corrective and authorisation powers by the supervisory authority or the dismissal or rejection of complaints. However, the right to an effective judicial remedy does not encompass measures taken by supervisory authorities which are not legally binding, such as opinions issued by or advice provided by the supervisory authority. Proceedings against a supervisory authority should be brought before the courts of the Member State where the supervisory authority is established and should be conducted in accordance with that Member State\u0026rsquo;s procedural law. Those courts should exercise full jurisdiction, which should include jurisdiction to examine all questions of fact and law relevant to the dispute before them.\nWhere a complaint has been rejected or dismissed by a supervisory authority, the complainant may bring proceedings before the courts in the same Member State. In the context of judicial remedies relating to the application of this Regulation, national courts which consider a decision on the question necessary to enable them to give judgment, may, or in the case provided for in Article 267 TFEU, must, request the Court of Justice to give a preliminary ruling on the interpretation of Union law, including this Regulation. Furthermore, where a decision of a supervisory authority implementing a decision of the Board is challenged before a national court and the validity of the decision of the Board is at issue, that national court does not have the power to declare the Board\u0026rsquo;s decision invalid but must refer the question of validity to the Court of Justice in accordance with Article 267 TFEU as interpreted by the Court of Justice, where it considers the decision invalid. However, a national court may not refer a question on the validity of the decision of the Board at the request of a natural or legal person which had the opportunity to bring an action for annulment of that decision, in particular if it was directly and individually concerned by that decision, but had not done so within the period laid down in Article 263 TFEU.\n(144)Where a court seized of proceedings against a decision by a supervisory authority has reason to believe that proceedings concerning the same processing, such as the same subject matter as regards processing by the same controller or processor, or the same cause of action, are brought before a competent court in another Member State, it should contact that court in order to confirm the existence of such related proceedings. If related proceedings are pending before a court in another Member State, any court other than the court first seized may stay its proceedings or may, on request of one of the parties, decline jurisdiction in favour of the court first seized if that court has jurisdiction over the proceedings in question and its law permits the consolidation of such related proceedings. Proceedings are deemed to be related where they are so closely connected that it is expedient to hear and determine them together in order to avoid the risk of irreconcilable judgments resulting from separate proceedings.\n(145)For proceedings against a controller or processor, the plaintiff should have the choice to bring the action before the courts of the Member States where the controller or processor has an establishment or where the data subject resides, unless the controller is a public authority of a Member State acting in the exercise of its public powers.\n(146)The controller or processor should compensate any damage which a person may suffer as a result of processing that infringes this Regulation. The controller or processor should be exempt from liability if it proves that it is not in any way responsible for the damage. The concept of damage should be broadly interpreted in the light of the case-law of the Court of Justice in a manner which fully reflects the objectives of this Regulation. This is without prejudice to any claims for damage deriving from the violation of other rules in Union or Member State law. Processing that infringes this Regulation also includes processing that infringes delegated and implementing acts adopted in accordance with this Regulation and Member State law specifying rules of this Regulation. Data subjects should receive full and effective compensation for the damage they have suffered. Where controllers or processors are involved in the same processing, each controller or processor should be held liable for the entire damage. However, where they are joined to the same judicial proceedings, in accordance with Member State law, compensation may be apportioned according to the responsibility of each controller or processor for the damage caused by the processing, provided that full and effective compensation of the data subject who suffered the damage is ensured. Any controller or processor which has paid full compensation may subsequently institute recourse proceedings against other controllers or processors involved in the same processing.\n(147)Where specific rules on jurisdiction are contained in this Regulation, in particular as regards proceedings seeking a judicial remedy including compensation, against a controller or processor, general jurisdiction rules such as those of Regulation (EU) No 1215/2012 of the European Parliament and of the Council(13) should not prejudice the application of such specific rules.\n(148)In order to strengthen the enforcement of the rules of this Regulation, penalties including administrative fines should be imposed for any infringement of this Regulation, in addition to, or instead of appropriate measures imposed by the supervisory authority pursuant to this Regulation. In a case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden to a natural person, a reprimand may be issued instead of a fine. Due regard should however be given to the nature, gravity and duration of the infringement, the intentional character of the infringement, actions taken to mitigate the damage suffered, degree of responsibility or any relevant previous infringements, the manner in which the infringement became known to the supervisory authority, compliance with measures ordered against the controller or processor, adherence to a code of conduct and any other aggravating or mitigating factor. The imposition of penalties including administrative fines should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter, including effective judicial protection and due process.\n(149)Member States should be able to lay down the rules on criminal penalties for infringements of this Regulation, including for infringements of national rules adopted pursuant to and within the limits of this Regulation. Those criminal penalties may also allow for the deprivation of the profits obtained through infringements of this Regulation. However, the imposition of criminal penalties for infringements of such national rules and of administrative penalties should not lead to a breach of the principle of ne bis in idem, as interpreted by the Court of Justice.\n(150)In order to strengthen and harmonise administrative penalties for infringements of this Regulation, each supervisory authority should have the power to impose administrative fines. This Regulation should indicate infringements and the upper limit and criteria for setting the related administrative fines, which should be determined by the competent supervisory authority in each individual case, taking into account all relevant circumstances of the specific situation, with due regard in particular to the nature, gravity and duration of the infringement and of its consequences and the measures taken to ensure compliance with the obligations under this Regulation and to prevent or mitigate the consequences of the infringement. Where administrative fines are imposed on an undertaking, an undertaking should be understood to be an undertaking in accordance with Articles 101 and 102 TFEU for those purposes. Where administrative fines are imposed on persons that are not an undertaking, the supervisory authority should take account of the general level of income in the Member State as well as the economic situation of the person in considering the appropriate amount of the fine. The consistency mechanism may also be used to promote a consistent application of administrative fines. It should be for the Member States to determine whether and to which extent public authorities should be subject to administrative fines. Imposing an administrative fine or giving a warning does not affect the application of other powers of the supervisory authorities or of other penalties under this Regulation.\n(151)The legal systems of Denmark and Estonia do not allow for administrative fines as set out in this Regulation. The rules on administrative fines may be applied in such a manner that in Denmark the fine is imposed by competent national courts as a criminal penalty and in Estonia the fine is imposed by the supervisory authority in the framework of a misdemeanour procedure, provided that such an application of the rules in those Member States has an equivalent effect to administrative fines imposed by supervisory authorities. Therefore the competent national courts should take into account the recommendation by the supervisory authority initiating the fine. In any event, the fines imposed should be effective, proportionate and dissuasive.\n(152)Where this Regulation does not harmonise administrative penalties or where necessary in other cases, for example in cases of serious infringements of this Regulation, Member States should implement a system which provides for effective, proportionate and dissuasive penalties. The nature of such penalties, criminal or administrative, should be determined by Member State law.\n(153)Member States law should reconcile the rules governing freedom of expression and information, including journalistic, academic, artistic and or literary expression with the right to the protection of personal data pursuant to this Regulation. The processing of personal data solely for journalistic purposes, or for the purposes of academic, artistic or literary expression should be subject to derogations or exemptions from certain provisions of this Regulation if necessary to reconcile the right to the protection of personal data with the right to freedom of expression and information, as enshrined in Article 11 of the Charter. This should apply in particular to the processing of personal data in the audiovisual field and in news archives and press libraries. Therefore, Member States should adopt legislative measures which lay down the exemptions and derogations necessary for the purpose of balancing those fundamental rights. Member States should adopt such exemptions and derogations on general principles, the rights of the data subject, the controller and the processor, the transfer of personal data to third countries or international organisations, the independent supervisory authorities, cooperation and consistency, and specific data-processing situations. Where such exemptions or derogations differ from one Member State to another, the law of the Member State to which the controller is subject should apply. In order to take account of the importance of the right to freedom of expression in every democratic society, it is necessary to interpret notions relating to that freedom, such as journalism, broadly.\n(154)This Regulation allows the principle of public access to official documents to be taken into account when applying this Regulation. Public access to official documents may be considered to be in the public interest. Personal data in documents held by a public authority or a public body should be able to be publicly disclosed by that authority or body if the disclosure is provided for by Union or Member State law to which the public authority or public body is subject. Such laws should reconcile public access to official documents and the reuse of public sector information with the right to the protection of personal data and may therefore provide for the necessary reconciliation with the right to the protection of personal data pursuant to this Regulation. The reference to public authorities and bodies should in that context include all authorities or other bodies covered by Member State law on public access to documents. Directive 2003/98/EC of the European Parliament and of the Council(14) leaves intact and in no way affects the level of protection of natural persons with regard to the processing of personal data under the provisions of Union and Member State law, and in particular does not alter the obligations and rights set out in this Regulation. In particular, that Directive should not apply to documents to which access is excluded or restricted by virtue of the access regimes on the grounds of protection of personal data, and parts of documents accessible by virtue of those regimes which contain personal data the re-use of which has been provided for by law as being incompatible with the law concerning the protection of natural persons with regard to the processing of personal data.\n(155)Member State law or collective agreements, including ‘works agreements’, may provide for specific rules on the processing of employees\u0026rsquo; personal data in the employment context, in particular for the conditions under which personal data in the employment context may be processed on the basis of the consent of the employee, the purposes of the recruitment, the performance of the contract of employment, including discharge of obligations laid down by law or by collective agreements, management, planning and organisation of work, equality and diversity in the workplace, health and safety at work, and for the purposes of the exercise and enjoyment, on an individual or collective basis, of rights and benefits related to employment, and for the purpose of the termination of the employment relationship.\n(156)The processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be subject to appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation. Those safeguards should ensure that technical and organisational measures are in place in order to ensure, in particular, the principle of data minimisation. The further processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is to be carried out when the controller has assessed the feasibility to fulfil those purposes by processing data which do not permit or no longer permit the identification of data subjects, provided that appropriate safeguards exist (such as, for instance, pseudonymisation of the data). Member States should provide for appropriate safeguards for the processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. Member States should be authorised to provide, under specific conditions and subject to appropriate safeguards for data subjects, specifications and derogations with regard to the information requirements and rights to rectification, to erasure, to be forgotten, to restriction of processing, to data portability, and to object when processing personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. The conditions and safeguards in question may entail specific procedures for data subjects to exercise those rights if this is appropriate in the light of the purposes sought by the specific processing along with technical and organisational measures aimed at minimising the processing of personal data in pursuance of the proportionality and necessity principles. The processing of personal data for scientific purposes should also comply with other relevant legislation such as on clinical trials.\n(157)By coupling information from registries, researchers can obtain new knowledge of great value with regard to widespread medical conditions such as cardiovascular disease, cancer and depression. On the basis of registries, research results can be enhanced, as they draw on a larger population. Within social science, research on the basis of registries enables researchers to obtain essential knowledge about the long-term correlation of a number of social conditions such as unemployment and education with other life conditions. Research results obtained through registries provide solid, high-quality knowledge which can provide the basis for the formulation and implementation of knowledge-based policy, improve the quality of life for a number of people and improve the efficiency of social services. In order to facilitate scientific research, personal data can be processed for scientific research purposes, subject to appropriate conditions and safeguards set out in Union or Member State law.\n(158)Where personal data are processed for archiving purposes, this Regulation should also apply to that processing, bearing in mind that this Regulation should not apply to deceased persons. Public authorities or public or private bodies that hold records of public interest should be services which, pursuant to Union or Member State law, have a legal obligation to acquire, preserve, appraise, arrange, describe, communicate, promote, disseminate and provide access to records of enduring value for general public interest. Member States should also be authorised to provide for the further processing of personal data for archiving purposes, for example with a view to providing specific information related to the political behaviour under former totalitarian state regimes, genocide, crimes against humanity, in particular the Holocaust, or war crimes.\n(159)Where personal data are processed for scientific research purposes, this Regulation should also apply to that processing. For the purposes of this Regulation, the processing of personal data for scientific research purposes should be interpreted in a broad manner including for example technological development and demonstration, fundamental research, applied research and privately funded research. In addition, it should take into account the Union\u0026rsquo;s objective under Article 179(1) TFEU of achieving a European Research Area. Scientific research purposes should also include studies conducted in the public interest in the area of public health. To meet the specificities of processing personal data for scientific research purposes, specific conditions should apply in particular as regards the publication or otherwise disclosure of personal data in the context of scientific research purposes. If the result of scientific research in particular in the health context gives reason for further measures in the interest of the data subject, the general rules of this Regulation should apply in view of those measures.\n(160)Where personal data are processed for historical research purposes, this Regulation should also apply to that processing. This should also include historical research and research for genealogical purposes, bearing in mind that this Regulation should not apply to deceased persons.\n(161)For the purpose of consenting to the participation in scientific research activities in clinical trials, the relevant provisions of Regulation (EU) No 536/2014 of the European Parliament and of the Council(15) should apply.\n(162)Where personal data are processed for statistical purposes, this Regulation should apply to that processing. Union or Member State law should, within the limits of this Regulation, determine statistical content, control of access, specifications for the processing of personal data for statistical purposes and appropriate measures to safeguard the rights and freedoms of the data subject and for ensuring statistical confidentiality. Statistical purposes mean any operation of collection and the processing of personal data necessary for statistical surveys or for the production of statistical results. Those statistical results may further be used for different purposes, including a scientific research purpose. The statistical purpose implies that the result of processing for statistical purposes is not personal data, but aggregate data, and that this result or the personal data are not used in support of measures or decisions regarding any particular natural person.\n(163)The confidential information which the Union and national statistical authorities collect for the production of official European and official national statistics should be protected. European statistics should be developed, produced and disseminated in accordance with the statistical principles as set out in Article 338(2) TFEU, while national statistics should also comply with Member State law. Regulation (EC) No 223/2009 of the European Parliament and of the Council(16) provides further specifications on statistical confidentiality for European statistics.\n(164)As regards the powers of the supervisory authorities to obtain from the controller or processor access to personal data and access to their premises, Member States may adopt by law, within the limits of this Regulation, specific rules in order to safeguard the professional or other equivalent secrecy obligations, in so far as necessary to reconcile the right to the protection of personal data with an obligation of professional secrecy. This is without prejudice to existing Member State obligations to adopt rules on professional secrecy where required by Union law.\n(165)This Regulation respects and does not prejudice the status under existing constitutional law of churches and religious associations or communities in the Member States, as recognised in Article 17 TFEU.\n(166)In order to fulfil the objectives of this Regulation, namely to protect the fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data and to ensure the free movement of personal data within the Union, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission. In particular, delegated acts should be adopted in respect of criteria and requirements for certification mechanisms, information to be presented by standardised icons and procedures for providing such icons. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level. The Commission, when preparing and drawing-up delegated acts, should ensure a simultaneous, timely and appropriate transmission of relevant documents to the European Parliament and to the Council.\n(167)In order to ensure uniform conditions for the implementation of this Regulation, implementing powers should be conferred on the Commission when provided for by this Regulation. Those powers should be exercised in accordance with Regulation (EU) No 182/2011. In that context, the Commission should consider specific measures for micro, small and medium-sized enterprises.\n(168)The examination procedure should be used for the adoption of implementing acts on standard contractual clauses between controllers and processors and between processors; codes of conduct; technical standards and mechanisms for certification; the adequate level of protection afforded by a third country, a territory or a specified sector within that third country, or an international organisation; standard protection clauses; formats and procedures for the exchange of information by electronic means between controllers, processors and supervisory authorities for binding corporate rules; mutual assistance; and arrangements for the exchange of information by electronic means between supervisory authorities, and between supervisory authorities and the Board.\n(169)The Commission should adopt immediately applicable implementing acts where available evidence reveals that a third country, a territory or a specified sector within that third country, or an international organisation does not ensure an adequate level of protection, and imperative grounds of urgency so require.\n(170)Since the objective of this Regulation, namely to ensure an equivalent level of protection of natural persons and the free flow of personal data throughout the Union, cannot be sufficiently achieved by the Member States and can rather, by reason of the scale or effects of the action, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union (TEU). In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective.\n(171)Directive 95/46/EC should be repealed by this Regulation. Processing already under way on the date of application of this Regulation should be brought into conformity with this Regulation within the period of two years after which this Regulation enters into force. Where processing is based on consent pursuant to Directive 95/46/EC, it is not necessary for the data subject to give his or her consent again if the manner in which the consent has been given is in line with the conditions of this Regulation, so as to allow the controller to continue such processing after the date of application of this Regulation. Commission decisions adopted and authorisations by supervisory authorities based on Directive 95/46/EC remain in force until amended, replaced or repealed.\n(172)The European Data Protection Supervisor was consulted in accordance with Article 28(2) of Regulation (EC) No 45/2001 and delivered an opinion on 7 March 2012(17).\n(173)This Regulation should apply to all matters concerning the protection of fundamental rights and freedoms vis-à-vis the processing of personal data which are not subject to specific obligations with the same objective set out in Directive 2002/58/EC of the European Parliament and of the Council(18), including the obligations on the controller and the rights of natural persons. In order to clarify the relationship between this Regulation and Directive 2002/58/EC, that Directive should be amended accordingly. Once this Regulation is adopted, Directive 2002/58/EC should be reviewed in particular in order to ensure consistency with this Regulation,\nHAVE ADOPTED THIS REGULATION:\nCHAPTER I General provisions\nArticle 1 Subject-matter and objectives\n1.This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data.\n2.This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.\n3.The free movement of personal data within the Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data.\nArticle 2 Material scope\n1.This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.\n2.This Regulation does not apply to the processing of personal data:\n(a)in the course of an activity which falls outside the scope of Union law;\n(b)by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU;\n(c)by a natural person in the course of a purely personal or household activity;\n(d)by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.\n3.For the processing of personal data by the Union institutions, bodies, offices and agencies, Regulation (EC) No 45/2001 applies. Regulation (EC) No 45/2001 and other Union legal acts applicable to such processing of personal data shall be adapted to the principles and rules of this Regulation in accordance with Article 98.\n4.This Regulation shall be without prejudice to the application of Directive 2000/31/EC, in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive.\nArticle 3 Territorial scope\n1.This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.\n2.This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:\n(a)the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or\n(b)the monitoring of their behaviour as far as their behaviour takes place within the Union.\n3.This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.\nArticle 4 Definitions\nFor the purposes of this Regulation:\n(1)‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;\n(2)‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;\n(3)‘restriction of processing’ means the marking of stored personal data with the aim of limiting their processing in the future;\n(4)‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person\u0026rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;\n(5)‘pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;\n(6)‘filing system’ means any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis;\n(7)‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;\n(8)‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;\n(9)‘recipient’ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;\n(10)‘third party’ means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;\n(11)‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject\u0026rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;\n(12)‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;\n(13)‘genetic data’ means personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question;\n(14)‘biometric data’ means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data;\n(15)‘data concerning health’ means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status;\n(16)‘main establishment’ means: (a)as regards a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment having taken such decisions is to be considered to be the main establishment; (b)as regards a processor with establishments in more than one Member State, the place of its central administration in the Union, or, if the processor has no central administration in the Union, the establishment of the processor in the Union where the main processing activities in the context of the activities of an establishment of the processor take place to the extent that the processor is subject to specific obligations under this Regulation;\n(17)‘representative’ means a natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27, represents the controller or processor with regard to their respective obligations under this Regulation;\n(18)‘enterprise’ means a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity;\n(19)‘group of undertakings’ means a controlling undertaking and its controlled undertakings;\n(20)‘binding corporate rules’ means personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity;\n(21)‘supervisory authority’ means an independent public authority which is established by a Member State pursuant to Article 51;\n(22)‘supervisory authority concerned’ means a supervisory authority which is concerned by the processing of personal data because: (a)the controller or processor is established on the territory of the Member State of that supervisory authority; (b)data subjects residing in the Member State of that supervisory authority are substantially affected or likely to be substantially affected by the processing; or (c)a complaint has been lodged with that supervisory authority;\n(23)‘cross-border processing’ means either: (a)processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State; or (b)processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.\n(24)‘relevant and reasoned objection’ means an objection to a draft decision as to whether there is an infringement of this Regulation, or whether envisaged action in relation to the controller or processor complies with this Regulation, which clearly demonstrates the significance of the risks posed by the draft decision as regards the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union;\n(25)‘information society service’ means a service as defined in point(b) of Article 1(1) of Directive (EU) 2015/1535 of the European Parliament and of the Council(19);\n(26)‘international organisation’ means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries.\nCHAPTER II Principles\nArticle 5 Principles relating to processing of personal data\n1.Personal data shall be:\n(a)processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);\n(b)collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);\n(c)adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);\n(d)accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);\n(e)kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);\n(f)processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).\n2.The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).\nArticle 6 Lawfulness of processing\n1.Processing shall be lawful only if and to the extent that at least one of the following applies:\n(a)the data subject has given consent to the processing of his or her personal data for one or more specific purposes;\n(b)processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;\n(c)processing is necessary for compliance with a legal obligation to which the controller is subject;\n(d)processing is necessary in order to protect the vital interests of the data subject or of another natural person;\n(e)processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;\n(f)processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.\nPoint (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks.\n2.Member States may maintain or introduce more specific provisions to adapt the application of the rules of this Regulation with regard to processing for compliance with points(c) and(e) of paragraph 1 by determining more precisely specific requirements for the processing and other measures to ensure lawful and fair processing including for other specific processing situations as provided for in Chapter IX.\n3.The basis for the processing referred to in point (c) and (e) of paragraph 1 shall be laid down by:\n(a)Union law; or\n(b)Member State law to which the controller is subject.\nThe purpose of the processing shall be determined in that legal basis or, as regards the processing referred to in point (e) of paragraph 1, shall be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. That legal basis may contain specific provisions to adapt the application of rules of this Regulation, inter alia: the general conditions governing the lawfulness of processing by the controller; the types of data which are subject to the processing; the data subjects concerned; the entities to, and the purposes for which, the personal data may be disclosed; the purpose limitation; storage periods; and processing operations and processing procedures, including measures to ensure lawful and fair processing such as those for other specific processing situations as provided for in Chapter IX. The Union or the Member State law shall meet an objective of public interest and be proportionate to the legitimate aim pursued.\n4.Where the processing for a purpose other than that for which the personal data have been collected is not based on the data subject\u0026rsquo;s consent or on a Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23(1), the controller shall, in order to ascertain whether processing for another purpose is compatible with the purpose for which the personal data are initially collected, take into account, inter alia:\n(a)any link between the purposes for which the personal data have been collected and the purposes of the intended further processing;\n(b)the context in which the personal data have been collected, in particular regarding the relationship between data subjects and the controller;\n(c)the nature of the personal data, in particular whether special categories of personal data are processed, pursuant to Article 9, or whether personal data related to criminal convictions and offences are processed, pursuant to Article 10;\n(d)the possible consequences of the intended further processing for data subjects;\n(e)the existence of appropriate safeguards, which may include encryption or pseudonymisation.\nArticle 7 Conditions for consent\n1.Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.\n2.If the data subject\u0026rsquo;s consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding.\n3.The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.\n4.When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.\nArticle 8 Conditions applicable to child\u0026rsquo;s consent in relation to information society services\n1.Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child.\nMember States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years.\n2.The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology.\n3.Paragraph 1 shall not affect the general contract law of Member States such as the rules on the validity, formation or effect of a contract in relation to a child.\nArticle 9 Processing of special categories of personal data\n1.Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person\u0026rsquo;s sex life or sexual orientation shall be prohibited.\n2.Paragraph 1 shall not apply if one of the following applies:\n(a)the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject;\n(b)processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law in so far as it is authorised by Union or Member State law or a collective agreement pursuant to Member State law providing for appropriate safeguards for the fundamental rights and the interests of the data subject;\n(c)processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent;\n(d)processing is carried out in the course of its legitimate activities with appropriate safeguards by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim and on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data are not disclosed outside that body without the consent of the data subjects;\n(e)processing relates to personal data which are manifestly made public by the data subject;\n(f)processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity;\n(g)processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject;\n(h)processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3;\n(i)processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy;\n(j)processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) based on Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.\n3.Personal data referred to in paragraph 1 may be processed for the purposes referred to in point(h) of paragraph 2 when those data are processed by or under the responsibility of a professional subject to the obligation of professional secrecy under Union or Member State law or rules established by national competent bodies or by another person also subject to an obligation of secrecy under Union or Member State law or rules established by national competent bodies.\n4.Member States may maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health.\nArticle 10 Processing of personal data relating to criminal convictions and offences\nProcessing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.\nArticle 11 Processing which does not require identification\n1.If the purposes for which a controller processes personal data do not or do no longer require the identification of a data subject by the controller, the controller shall not be obliged to maintain, acquire or process additional information in order to identify the data subject for the sole purpose of complying with this Regulation.\n2.Where, in cases referred to in paragraph 1 of this Article, the controller is able to demonstrate that it is not in a position to identify the data subject, the controller shall inform the data subject accordingly, if possible. In such cases, Articles 15 to 20 shall not apply except where the data subject, for the purpose of exercising his or her rights under those articles, provides additional information enabling his or her identification.\nCHAPTER III Rights of the data subject\nSection 1\nTransparency and modalities\nArticle 12 Transparent information, communication and modalities for the exercise of the rights of the data subject\n1.The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication under Articles 15 to 22 and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means. When requested by the data subject, the information may be provided orally, provided that the identity of the data subject is proven by other means.\n2.The controller shall facilitate the exercise of data subject rights under Articles 15 to 22. In the cases referred to in Article 11(2), the controller shall not refuse to act on the request of the data subject for exercising his or her rights under Articles 15 to 22, unless the controller demonstrates that it is not in a position to identify the data subject.\n3.The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay. Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.\n4.If the controller does not take action on the request of the data subject, the controller shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.\n5.Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either:\n(a)charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or\n(b)refuse to act on the request.\nThe controller shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.\n6.Without prejudice to Article 11, where the controller has reasonable doubts concerning the identity of the natural person making the request referred to in Articles 15 to 21, the controller may request the provision of additional information necessary to confirm the identity of the data subject.\n7.The information to be provided to data subjects pursuant to Articles 13 and 14 may be provided in combination with standardised icons in order to give in an easily visible, intelligible and clearly legible manner a meaningful overview of the intended processing. Where the icons are presented electronically they shall be machine-readable.\n8.The Commission shall be empowered to adopt delegated acts in accordance with Article 92 for the purpose of determining the information to be presented by the icons and the procedures for providing standardised icons.\nSection 2\nInformation and access to personal data\nArticle 13 Information to be provided where personal data are collected from the data subject\n1.Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information:\n(a)the identity and the contact details of the controller and, where applicable, of the controller\u0026rsquo;s representative;\n(b)the contact details of the data protection officer, where applicable;\n(c)the purposes of the processing for which the personal data are intended as well as the legal basis for the processing;\n(d)where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party;\n(e)the recipients or categories of recipients of the personal data, if any;\n(f)where applicable, the fact that the controller intends to transfer personal data to a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means by which to obtain a copy of them or where they have been made available.\n2.In addition to the information referred to in paragraph 1, the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing:\n(a)the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;\n(b)the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;\n(c)where the processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;\n(d)the right to lodge a complaint with a supervisory authority;\n(e)whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and of the possible consequences of failure to provide such data;\n(f)the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.\n3.Where the controller intends to further process the personal data for a purpose other than that for which the personal data were collected, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2.\n4.Paragraphs 1, 2 and 3 shall not apply where and insofar as the data subject already has the information.\nArticle 14 Information to be provided where personal data have not been obtained from the data subject\n1.Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information:\n(a)the identity and the contact details of the controller and, where applicable, of the controller\u0026rsquo;s representative;\n(b)the contact details of the data protection officer, where applicable;\n(c)the purposes of the processing for which the personal data are intended as well as the legal basis for the processing;\n(d)the categories of personal data concerned;\n(e)the recipients or categories of recipients of the personal data, if any;\n(f)where applicable, that the controller intends to transfer personal data to a recipient in a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means to obtain a copy of them or where they have been made available.\n2.In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing in respect of the data subject:\n(a)the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;\n(b)where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party;\n(c)the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject and to object to processing as well as the right to data portability;\n(d)where processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;\n(e)the right to lodge a complaint with a supervisory authority;\n(f)from which source the personal data originate, and if applicable, whether it came from publicly accessible sources;\n(g)the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.\n3.The controller shall provide the information referred to in paragraphs 1 and 2:\n(a)within a reasonable period after obtaining the personal data, but at the latest within one month, having regard to the specific circumstances in which the personal data are processed;\n(b)if the personal data are to be used for communication with the data subject, at the latest at the time of the first communication to that data subject; or\n(c)if a disclosure to another recipient is envisaged, at the latest when the personal data are first disclosed.\n4.Where the controller intends to further process the personal data for a purpose other than that for which the personal data were obtained, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2.\n5.Paragraphs 1 to 4 shall not apply where and insofar as:\n(a)the data subject already has the information;\n(b)the provision of such information proves impossible or would involve a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing. In such cases the controller shall take appropriate measures to protect the data subject\u0026rsquo;s rights and freedoms and legitimate interests, including making the information publicly available;\n(c)obtaining or disclosure is expressly laid down by Union or Member State law to which the controller is subject and which provides appropriate measures to protect the data subject\u0026rsquo;s legitimate interests; or\n(d)where the personal data must remain confidential subject to an obligation of professional secrecy regulated by Union or Member State law, including a statutory obligation of secrecy.\nArticle 15 Right of access by the data subject\n1.The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:\n(a)the purposes of the processing;\n(b)the categories of personal data concerned;\n(c)the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;\n(d)where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;\n(e)the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;\n(f)the right to lodge a complaint with a supervisory authority;\n(g)where the personal data are not collected from the data subject, any available information as to their source;\n(h)the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.\n2.Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards pursuant to Article 46 relating to the transfer.\n3.The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form.\n4.The right to obtain a copy referred to in paragraph 3 shall not adversely affect the rights and freedoms of others.\nSection 3\nRectification and erasure\nArticle 16 Right to rectification\nThe data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.\nArticle 17 Right to erasure (‘right to be forgotten’)\n1.The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:\n(a)the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;\n(b)the data subject withdraws consent on which the processing is based according to point(a) of Article 6(1), or point(a) of Article 9(2), and where there is no other legal ground for the processing;\n(c)the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);\n(d)the personal data have been unlawfully processed;\n(e)the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;\n(f)the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).\n2.Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.\n3.Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:\n(a)for exercising the right of freedom of expression and information;\n(b)for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;\n(c)for reasons of public interest in the area of public health in accordance with points(h) and (i) of Article 9(2) as well as Article 9(3);\n(d)for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or\n(e)for the establishment, exercise or defence of legal claims.\nArticle 18 Right to restriction of processing\n1.The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:\n(a)the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;\n(b)the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;\n(c)the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;\n(d)the data subject has objected to processing pursuant to Article 21(1) pending the verification whether the legitimate grounds of the controller override those of the data subject.\n2.Where processing has been restricted under paragraph 1, such personal data shall, with the exception of storage, only be processed with the data subject\u0026rsquo;s consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.\n3.A data subject who has obtained restriction of processing pursuant to paragraph 1 shall be informed by the controller before the restriction of processing is lifted.\nArticle 19 Notification obligation regarding rectification or erasure of personal data or restriction of processing\nThe controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.\nArticle 20 Right to data portability\n1.The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:\n(a)the processing is based on consent pursuant to point (a) of Article 6(1) or point(a) of Article 9(2) or on a contract pursuant to point (b) of Article 6(1); and\n(b)the processing is carried out by automated means.\n2.In exercising his or her right to data portability pursuant to paragraph 1, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible.\n3.The exercise of the right referred to in paragraph 1 of this Article shall be without prejudice to Article 17. That right shall not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.\n4.The right referred to in paragraph 1 shall not adversely affect the rights and freedoms of others.\nSection 4\nRight to object and automated individual decision-making\nArticle 21 Right to object\n1.The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.\n2.Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.\n3.Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.\n4.At the latest at the time of the first communication with the data subject, the right referred to in paragraphs 1 and 2 shall be explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information.\n5.In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, the data subject may exercise his or her right to object by automated means using technical specifications.\n6.Where personal data are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1), the data subject, on grounds relating to his or her particular situation, shall have the right to object to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.\nArticle 22 Automated individual decision-making, including profiling\n1.The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.\n2.Paragraph 1 shall not apply if the decision:\n(a)is necessary for entering into, or performance of, a contract between the data subject and a data controller;\n(b)is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject\u0026rsquo;s rights and freedoms and legitimate interests; or\n(c)is based on the data subject\u0026rsquo;s explicit consent.\n3.In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall implement suitable measures to safeguard the data subject\u0026rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.\n4.Decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless point (a) or (g) of Article 9(2) applies and suitable measures to safeguard the data subject\u0026rsquo;s rights and freedoms and legitimate interests are in place.\nSection 5\nRestrictions\nArticle 23 Restrictions\n1.Union or Member State law to which the data controller or processor is subject may restrict by way of a legislative measure the scope of the obligations and rights provided for in Articles 12 to 22 and Article 34, as well as Article 5 in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22, when such a restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard:\n(a)national security;\n(b)defence;\n(c)public security;\n(d)the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;\n(e)other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, including monetary, budgetary and taxation a matters, public health and social security;\n(f)the protection of judicial independence and judicial proceedings;\n(g)the prevention, investigation, detection and prosecution of breaches of ethics for regulated professions;\n(h)a monitoring, inspection or regulatory function connected, even occasionally, to the exercise of official authority in the cases referred to in points (a) to (e) and(g);\n(i)the protection of the data subject or the rights and freedoms of others;\n(j)the enforcement of civil law claims.\n2.In particular, any legislative measure referred to in paragraph 1 shall contain specific provisions at least, where relevant, as to:\n(a)the purposes of the processing or categories of processing;\n(b)the categories of personal data;\n(c)the scope of the restrictions introduced;\n(d)the safeguards to prevent abuse or unlawful access or transfer;\n(e)the specification of the controller or categories of controllers;\n(f)the storage periods and the applicable safeguards taking into account the nature, scope and purposes of the processing or categories of processing;\n(g)the risks to the rights and freedoms of data subjects; and\n(h)the right of data subjects to be informed about the restriction, unless that may be prejudicial to the purpose of the restriction.\nCHAPTER IV Controller and processor\nSection 1\nGeneral obligations\nArticle 24 Responsibility of the controller\n1.Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.\n2.Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.\n3.Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller.\nArticle 25 Data protection by design and by default\n1.Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.\n2.The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual\u0026rsquo;s intervention to an indefinite number of natural persons.\n3.An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.\nArticle 26 Joint controllers\n1.Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers. They shall in a transparent manner determine their respective responsibilities for compliance with the obligations under this Regulation, in particular as regards the exercising of the rights of the data subject and their respective duties to provide the information referred to in Articles 13 and 14, by means of an arrangement between them unless, and in so far as, the respective responsibilities of the controllers are determined by Union or Member State law to which the controllers are subject. The arrangement may designate a contact point for data subjects.\n2.The arrangement referred to in paragraph 1 shall duly reflect the respective roles and relationships of the joint controllers vis-à-vis the data subjects. The essence of the arrangement shall be made available to the data subject.\n3.Irrespective of the terms of the arrangement referred to in paragraph 1, the data subject may exercise his or her rights under this Regulation in respect of and against each of the controllers.\nArticle 27 Representatives of controllers or processors not established in the Union\n1.Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.\n2.The obligation laid down in paragraph 1 of this Article shall not apply to:\n(a)processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or\n(b)a public authority or body.\n3.The representative shall be established in one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are.\n4.The representative shall be mandated by the controller or processor to be addressed in addition to or instead of the controller or the processor by, in particular, supervisory authorities and data subjects, on all issues related to processing, for the purposes of ensuring compliance with this Regulation.\n5.The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves.\nArticle 28 Processor\n1.Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.\n2.The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.\n3.Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor:\n(a)processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;\n(b)ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;\n(c)takes all measures required pursuant to Article 32;\n(d)respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;\n(e)taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller\u0026rsquo;s obligation to respond to requests for exercising the data subject\u0026rsquo;s rights laid down in Chapter III;\n(f)assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor;\n(g)at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;\n(h)makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.\nWith regard to point(h) of the first subparagraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions.\n4.Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor as referred to in paragraph 3 shall be imposed on that other processor by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of this Regulation. Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor\u0026rsquo;s obligations.\n5.Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.\n6.Without prejudice to an individual contract between the controller and the processor, the contract or the other legal act referred to in paragraphs 3 and 4 of this Article may be based, in whole or in part, on standard contractual clauses referred to in paragraphs 7 and 8 of this Article, including when they are part of a certification granted to the controller or processor pursuant to Articles 42 and 43.\n7.The Commission may lay down standard contractual clauses for the matters referred to in paragraph 3 and 4 of this Article and in accordance with the examination procedure referred to in Article 93(2).\n8.A supervisory authority may adopt standard contractual clauses for the matters referred to in paragraph 3 and 4 of this Article and in accordance with the consistency mechanism referred to in Article 63.\n9.The contract or the other legal act referred to in paragraphs 3 and 4 shall be in writing, including in electronic form.\n10.Without prejudice to Articles 82, 83 and 84, if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing.\nArticle 29 Processing under the authority of the controller or processor\nThe processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law.\nArticle 30 Records of processing activities\n1.Each controller and, where applicable, the controller\u0026rsquo;s representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information:\n(a)the name and contact details of the controller and, where applicable, the joint controller, the controller\u0026rsquo;s representative and the data protection officer;\n(b)the purposes of the processing;\n(c)a description of the categories of data subjects and of the categories of personal data;\n(d)the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations;\n(e)where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;\n(f)where possible, the envisaged time limits for erasure of the different categories of data;\n(g)where possible, a general description of the technical and organisational security measures referred to in Article 32(1).\n2.Each processor and, where applicable, the processor\u0026rsquo;s representative shall maintain a record of all categories of processing activities carried out on behalf of a controller, containing:\n(a)the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller\u0026rsquo;s or the processor\u0026rsquo;s representative, and the data protection officer;\n(b)the categories of processing carried out on behalf of each controller;\n(c)where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards;\n(d)where possible, a general description of the technical and organisational security measures referred to in Article 32(1).\n3.The records referred to in paragraphs 1 and 2 shall be in writing, including in electronic form.\n4.The controller or the processor and, where applicable, the controller\u0026rsquo;s or the processor\u0026rsquo;s representative, shall make the record available to the supervisory authority on request.\n5.The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.\nArticle 31 Cooperation with the supervisory authority\nThe controller and the processor and, where applicable, their representatives, shall cooperate, on request, with the supervisory authority in the performance of its tasks.\nSection 2\nSecurity of personal data\nArticle 32 Security of processing\n1.Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:\n(a)the pseudonymisation and encryption of personal data;\n(b)the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;\n(c)the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;\n(d)a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.\n2.In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.\n3.Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance with the requirements set out in paragraph 1 of this Article.\n4.The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or she is required to do so by Union or Member State law.\nArticle 33 Notification of a personal data breach to the supervisory authority\n1.In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.\n2.The processor shall notify the controller without undue delay after becoming aware of a personal data breach.\n3.The notification referred to in paragraph 1 shall at least:\n(a)describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;\n(b)communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;\n(c)describe the likely consequences of the personal data breach;\n(d)describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.\n4.Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.\n5.The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.\nArticle 34 Communication of a personal data breach to the data subject\n1.When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.\n2.The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points(b), (c) and (d) of Article 33(3).\n3.The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met:\n(a)the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;\n(b)the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 is no longer likely to materialise;\n(c)it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.\n4.If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so or may decide that any of the conditions referred to in paragraph 3 are met.\nSection 3\nData protection impact assessment and prior consultation\nArticle 35 Data protection impact assessment\n1.Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.\n2.The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.\n3.A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:\n(a)a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;\n(b)processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or\n(c)a systematic monitoring of a publicly accessible area on a large scale.\n4.The supervisory authority shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68.\n5.The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board.\n6.Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union.\n7.The assessment shall contain at least:\n(a)a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;\n(b)an assessment of the necessity and proportionality of the processing operations in relation to the purposes;\n(c)an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and\n(d)the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.\n8.Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.\n9.Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.\n10.Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.\n11.Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.\nArticle 36 Prior consultation\n1.The controller shall consult the supervisory authority prior to processing where a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk.\n2.Where the supervisory authority is of the opinion that the intended processing referred to in paragraph 1 would infringe this Regulation, in particular where the controller has insufficiently identified or mitigated the risk, the supervisory authority shall, within period of up to eight weeks of receipt of the request for consultation, provide written advice to the controller and, where applicable to the processor, and may use any of its powers referred to in Article 58. That period may be extended by six weeks, taking into account the complexity of the intended processing. The supervisory authority shall inform the controller and, where applicable, the processor, of any such extension within one month of receipt of the request for consultation together with the reasons for the delay. Those periods may be suspended until the supervisory authority has obtained information it has requested for the purposes of the consultation.\n3.When consulting the supervisory authority pursuant to paragraph 1, the controller shall provide the supervisory authority with:\n(a)where applicable, the respective responsibilities of the controller, joint controllers and processors involved in the processing, in particular for processing within a group of undertakings;\n(b)the purposes and means of the intended processing;\n(c)the measures and safeguards provided to protect the rights and freedoms of data subjects pursuant to this Regulation;\n(d)where applicable, the contact details of the data protection officer;\n(e)the data protection impact assessment provided for in Article 35; and\n(f)any other information requested by the supervisory authority.\n4.Member States shall consult the supervisory authority during the preparation of a proposal for a legislative measure to be adopted by a national parliament, or of a regulatory measure based on such a legislative measure, which relates to processing.\n5.Notwithstanding paragraph 1, Member State law may require controllers to consult with, and obtain prior authorisation from, the supervisory authority in relation to processing by a controller for the performance of a task carried out by the controller in the public interest, including processing in relation to social protection and public health.\nSection 4\nData protection officer\nArticle 37 Designation of the data protection officer\n1.The controller and the processor shall designate a data protection officer in any case where:\n(a)the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;\n(b)the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or\n(c)the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10.\n2.A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.\n3.Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.\n4.In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.\n5.The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.\n6.The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.\n7.The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.\nArticle 38 Position of the data protection officer\n1.The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.\n2.The controller and processor shall support the data protection officer in performing the tasks referred to in Article 39 by providing resources necessary to carry out those tasks and access to personal data and processing operations, and to maintain his or her expert knowledge.\n3.The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks. The data protection officer shall directly report to the highest management level of the controller or the processor.\n4.Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data and to the exercise of their rights under this Regulation.\n5.The data protection officer shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law.\n6.The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.\nArticle 39 Tasks of the data protection officer\n1.The data protection officer shall have at least the following tasks:\n(a)to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions;\n(b)to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;\n(c)to provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35;\n(d)to cooperate with the supervisory authority;\n(e)to act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter.\n2.The data protection officer shall in the performance of his or her tasks have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing.\nSection 5\nCodes of conduct and certification\nArticle 40 Codes of conduct\n1.The Member States, the supervisory authorities, the Board and the Commission shall encourage the drawing up of codes of conduct intended to contribute to the proper application of this Regulation, taking account of the specific features of the various processing sectors and the specific needs of micro, small and medium-sized enterprises.\n2.Associations and other bodies representing categories of controllers or processors may prepare codes of conduct, or amend or extend such codes, for the purpose of specifying the application of this Regulation, such as with regard to:\n(a)fair and transparent processing;\n(b)the legitimate interests pursued by controllers in specific contexts;\n(c)the collection of personal data;\n(d)the pseudonymisation of personal data;\n(e)the information provided to the public and to data subjects;\n(f)the exercise of the rights of data subjects;\n(g)the information provided to, and the protection of, children, and the manner in which the consent of the holders of parental responsibility over children is to be obtained;\n(h)the measures and procedures referred to in Articles 24 and 25 and the measures to ensure security of processing referred to in Article 32;\n(i)the notification of personal data breaches to supervisory authorities and the communication of such personal data breaches to data subjects;\n(j)the transfer of personal data to third countries or international organisations; or\n(k)out-of-court proceedings and other dispute resolution procedures for resolving disputes between controllers and data subjects with regard to processing, without prejudice to the rights of data subjects pursuant to Articles 77 and 79.\n3.In addition to adherence by controllers or processors subject to this Regulation, codes of conduct approved pursuant to paragraph 5 of this Article and having general validity pursuant to paragraph 9 of this Article may also be adhered to by controllers or processors that are not subject to this Regulation pursuant to Article 3 in order to provide appropriate safeguards within the framework of personal data transfers to third countries or international organisations under the terms referred to in point (e) of Article 46(2). Such controllers or processors shall make binding and enforceable commitments, via contractual or other legally binding instruments, to apply those appropriate safeguards including with regard to the rights of data subjects.\n4.A code of conduct referred to in paragraph 2 of this Article shall contain mechanisms which enable the body referred to in Article 41(1) to carry out the mandatory monitoring of compliance with its provisions by the controllers or processors which undertake to apply it, without prejudice to the tasks and powers of supervisory authorities competent pursuant to Article 55 or 56.\n5.Associations and other bodies referred to in paragraph 2 of this Article which intend to prepare a code of conduct or to amend or extend an existing code shall submit the draft code, amendment or extension to the supervisory authority which is competent pursuant to Article 55. The supervisory authority shall provide an opinion on whether the draft code, amendment or extension complies with this Regulation and shall approve that draft code, amendment or extension if it finds that it provides sufficient appropriate safeguards.\n6.Where the draft code, or amendment or extension is approved in accordance with paragraph 5, and where the code of conduct concerned does not relate to processing activities in several Member States, the supervisory authority shall register and publish the code.\n7.Where a draft code of conduct relates to processing activities in several Member States, the supervisory authority which is competent pursuant to Article 55 shall, before approving the draft code, amendment or extension, submit it in the procedure referred to in Article 63 to the Board which shall provide an opinion on whether the draft code, amendment or extension complies with this Regulation or, in the situation referred to in paragraph 3 of this Article, provides appropriate safeguards.\n8.Where the opinion referred to in paragraph 7 confirms that the draft code, amendment or extension complies with this Regulation, or, in the situation referred to in paragraph 3, provides appropriate safeguards, the Board shall submit its opinion to the Commission.\n9.The Commission may, by way of implementing acts, decide that the approved code of conduct, amendment or extension submitted to it pursuant to paragraph 8 of this Article have general validity within the Union. Those implementing acts shall be adopted in accordance with the examination procedure set out in Article 93(2).\n10.The Commission shall ensure appropriate publicity for the approved codes which have been decided as having general validity in accordance with paragraph 9.\n11.The Board shall collate all approved codes of conduct, amendments and extensions in a register and shall make them publicly available by way of appropriate means.\nArticle 41 Monitoring of approved codes of conduct\n1.Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, the monitoring of compliance with a code of conduct pursuant to Article 40 may be carried out by a body which has an appropriate level of expertise in relation to the subject-matter of the code and is accredited for that purpose by the competent supervisory authority.\n2.A body as referred to in paragraph 1 may be accredited to monitor compliance with a code of conduct where that body has:\n(a)demonstrated its independence and expertise in relation to the subject-matter of the code to the satisfaction of the competent supervisory authority;\n(b)established procedures which allow it to assess the eligibility of controllers and processors concerned to apply the code, to monitor their compliance with its provisions and to periodically review its operation;\n(c)established procedures and structures to handle complaints about infringements of the code or the manner in which the code has been, or is being, implemented by a controller or processor, and to make those procedures and structures transparent to data subjects and the public; and\n(d)demonstrated to the satisfaction of the competent supervisory authority that its tasks and duties do not result in a conflict of interests.\n3.The competent supervisory authority shall submit the draft criteria for accreditation of a body as referred to in paragraph 1 of this Article to the Board pursuant to the consistency mechanism referred to in Article 63.\n4.Without prejudice to the tasks and powers of the competent supervisory authority and the provisions of Chapter VIII, a body as referred to in paragraph 1 of this Article shall, subject to appropriate safeguards, take appropriate action in cases of infringement of the code by a controller or processor, including suspension or exclusion of the controller or processor concerned from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them.\n5.The competent supervisory authority shall revoke the accreditation of a body as referred to in paragraph 1 if the conditions for accreditation are not, or are no longer, met or where actions taken by the body infringe this Regulation.\n6.This Article shall not apply to processing carried out by public authorities and bodies.\nArticle 42 Certification\n1.The Member States, the supervisory authorities, the Board and the Commission shall encourage, in particular at Union level, the establishment of data protection certification mechanisms and of data protection seals and marks, for the purpose of demonstrating compliance with this Regulation of processing operations by controllers and processors. The specific needs of micro, small and medium-sized enterprises shall be taken into account.\n2.In addition to adherence by controllers or processors subject to this Regulation, data protection certification mechanisms, seals or marks approved pursuant to paragraph 5 of this Article may be established for the purpose of demonstrating the existence of appropriate safeguards provided by controllers or processors that are not subject to this Regulation pursuant to Article 3 within the framework of personal data transfers to third countries or international organisations under the terms referred to in point(f) of Article 46(2). Such controllers or processors shall make binding and enforceable commitments, via contractual or other legally binding instruments, to apply those appropriate safeguards, including with regard to the rights of data subjects.\n3.The certification shall be voluntary and available via a process that is transparent.\n4.A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation and is without prejudice to the tasks and powers of the supervisory authorities which are competent pursuant to Article 55 or 56.\n5.A certification pursuant to this Article shall be issued by the certification bodies referred to in Article 43 or by the competent supervisory authority, on the basis of criteria approved by that competent supervisory authority pursuant to Article 58(3) or by the Board pursuant to Article 63. Where the criteria are approved by the Board, this may result in a common certification, the European Data Protection Seal.\n6.The controller or processor which submits its processing to the certification mechanism shall provide the certification body referred to in Article 43, or where applicable, the competent supervisory authority, with all information and access to its processing activities which are necessary to conduct the certification procedure.\n7.Certification shall be issued to a controller or processor for a maximum period of three years and may be renewed, under the same conditions, provided that the relevant requirements continue to be met. Certification shall be withdrawn, as applicable, by the certification bodies referred to in Article 43 or by the competent supervisory authority where the requirements for the certification are not or are no longer met.\n8.The Board shall collate all certification mechanisms and data protection seals and marks in a register and shall make them publicly available by any appropriate means.\nArticle 43 Certification bodies\n1.Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, certification bodies which have an appropriate level of expertise in relation to data protection shall, after informing the supervisory authority in order to allow it to exercise its powers pursuant to point (h) of Article 58(2) where necessary, issue and renew certification. Member States shall ensure that those certification bodies are accredited by one or both of the following:\n(a)the supervisory authority which is competent pursuant to Article 55 or 56;\n(b)the national accreditation body named in accordance with Regulation (EC) No 765/2008 of the European Parliament and of the Council(20) in accordance with EN-ISO/IEC 17065/2012 and with the additional requirements established by the supervisory authority which is competent pursuant to Article 55 or 56.\n2.Certification bodies referred to in paragraph 1 shall be accredited in accordance with that paragraph only where they have:\n(a)demonstrated their independence and expertise in relation to the subject-matter of the certification to the satisfaction of the competent supervisory authority;\n(b)undertaken to respect the criteria referred to in Article 42(5) and approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63;\n(c)established procedures for the issuing, periodic review and withdrawal of data protection certification, seals and marks;\n(d)established procedures and structures to handle complaints about infringements of the certification or the manner in which the certification has been, or is being, implemented by the controller or processor, and to make those procedures and structures transparent to data subjects and the public; and\n(e)demonstrated, to the satisfaction of the competent supervisory authority, that their tasks and duties do not result in a conflict of interests.\n3.The accreditation of certification bodies as referred to in paragraphs 1 and 2 of this Article shall take place on the basis of criteria approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63. In the case of accreditation pursuant to point(b) of paragraph 1 of this Article, those requirements shall complement those envisaged in Regulation (EC) No 765/2008 and the technical rules that describe the methods and procedures of the certification bodies.\n4.The certification bodies referred to in paragraph 1 shall be responsible for the proper assessment leading to the certification or the withdrawal of such certification without prejudice to the responsibility of the controller or processor for compliance with this Regulation. The accreditation shall be issued for a maximum period of five years and may be renewed on the same conditions provided that the certification body meets the requirements set out in this Article.\n5.The certification bodies referred to in paragraph 1 shall provide the competent supervisory authorities with the reasons for granting or withdrawing the requested certification.\n6.The requirements referred to in paragraph 3 of this Article and the criteria referred to in Article 42(5) shall be made public by the supervisory authority in an easily accessible form. The supervisory authorities shall also transmit those requirements and criteria to the Board. The Board shall collate all certification mechanisms and data protection seals in a register and shall make them publicly available by any appropriate means.\n7.Without prejudice to Chapter VIII, the competent supervisory authority or the national accreditation body shall revoke an accreditation of a certification body pursuant to paragraph 1 of this Article where the conditions for the accreditation are not, or are no longer, met or where actions taken by a certification body infringe this Regulation.\n8.The Commission shall be empowered to adopt delegated acts in accordance with Article 92 for the purpose of specifying the requirements to be taken into account for the data protection certification mechanisms referred to in Article 42(1).\n9.The Commission may adopt implementing acts laying down technical standards for certification mechanisms and data protection seals and marks, and mechanisms to promote and recognise those certification mechanisms, seals and marks. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).\nCHAPTER V Transfers of personal data to third countries or international organisations\nArticle 44 General principle for transfers\nAny transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.\nArticle 45 Transfers on the basis of an adequacy decision\n1.A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation.\n2.When assessing the adequacy of the level of protection, the Commission shall, in particular, take account of the following elements:\n(a)the rule of law, respect for human rights and fundamental freedoms, relevant legislation, both general and sectoral, including concerning public security, defence, national security and criminal law and the access of public authorities to personal data, as well as the implementation of such legislation, data protection rules, professional rules and security measures, including rules for the onward transfer of personal data to another third country or international organisation which are complied with in that country or international organisation, case-law, as well as effective and enforceable data subject rights and effective administrative and judicial redress for the data subjects whose personal data are being transferred;\n(b)the existence and effective functioning of one or more independent supervisory authorities in the third country or to which an international organisation is subject, with responsibility for ensuring and enforcing compliance with the data protection rules, including adequate enforcement powers, for assisting and advising the data subjects in exercising their rights and for cooperation with the supervisory authorities of the Member States; and\n(c)the international commitments the third country or international organisation concerned has entered into, or other obligations arising from legally binding conventions or instruments as well as from its participation in multilateral or regional systems, in particular in relation to the protection of personal data.\n3.The Commission, after assessing the adequacy of the level of protection, may decide, by means of implementing act, that a third country, a territory or one or more specified sectors within a third country, or an international organisation ensures an adequate level of protection within the meaning of paragraph 2 of this Article. The implementing act shall provide for a mechanism for a periodic review, at least every four years, which shall take into account all relevant developments in the third country or international organisation. The implementing act shall specify its territorial and sectoral application and, where applicable, identify the supervisory authority or authorities referred to in point (b) of paragraph 2 of this Article. The implementing act shall be adopted in accordance with the examination procedure referred to in Article 93(2).\n4.The Commission shall, on an ongoing basis, monitor developments in third countries and international organisations that could affect the functioning of decisions adopted pursuant to paragraph 3 of this Article and decisions adopted on the basis of Article 25(6) of Directive 95/46/EC.\n5.The Commission shall, where available information reveals, in particular following the review referred to in paragraph 3 of this Article, that a third country, a territory or one or more specified sectors within a third country, or an international organisation no longer ensures an adequate level of protection within the meaning of paragraph 2 of this Article, to the extent necessary, repeal, amend or suspend the decision referred to in paragraph 3 of this Article by means of implementing acts without retro-active effect. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).\nOn duly justified imperative grounds of urgency, the Commission shall adopt immediately applicable implementing acts in accordance with the procedure referred to in Article 93(3).\n6.The Commission shall enter into consultations with the third country or international organisation with a view to remedying the situation giving rise to the decision made pursuant to paragraph 5.\n7.A decision pursuant to paragraph 5 of this Article is without prejudice to transfers of personal data to the third country, a territory or one or more specified sectors within that third country, or the international organisation in question pursuant to Articles 46 to 49.\n8.The Commission shall publish in the Official Journal of the European Union and on its website a list of the third countries, territories and specified sectors within a third country and international organisations for which it has decided that an adequate level of protection is or is no longer ensured.\n9.Decisions adopted by the Commission on the basis of Article 25(6) of Directive 95/46/EC shall remain in force until amended, replaced or repealed by a Commission Decision adopted in accordance with paragraph 3 or 5 of this Article.\nArticle 46 Transfers subject to appropriate safeguards\n1.In the absence of a decision pursuant to Article 45(3), a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available.\n2.The appropriate safeguards referred to in paragraph 1 may be provided for, without requiring any specific authorisation from a supervisory authority, by:\n(a)a legally binding and enforceable instrument between public authorities or bodies;\n(b)binding corporate rules in accordance with Article 47;\n(c)standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93(2);\n(d)standard data protection clauses adopted by a supervisory authority and approved by the Commission pursuant to the examination procedure referred to in Article 93(2);\n(e)an approved code of conduct pursuant to Article 40 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects\u0026rsquo; rights; or\n(f)an approved certification mechanism pursuant to Article 42 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects\u0026rsquo; rights.\n3.Subject to the authorisation from the competent supervisory authority, the appropriate safeguards referred to in paragraph 1 may also be provided for, in particular, by:\n(a)contractual clauses between the controller or processor and the controller, processor or the recipient of the personal data in the third country or international organisation; or\n(b)provisions to be inserted into administrative arrangements between public authorities or bodies which include enforceable and effective data subject rights.\n4.The supervisory authority shall apply the consistency mechanism referred to in Article 63 in the cases referred to in paragraph 3 of this Article.\n5.Authorisations by a Member State or supervisory authority on the basis of Article 26(2) of Directive 95/46/EC shall remain valid until amended, replaced or repealed, if necessary, by that supervisory authority. Decisions adopted by the Commission on the basis of Article 26(4) of Directive 95/46/EC shall remain in force until amended, replaced or repealed, if necessary, by a Commission Decision adopted in accordance with paragraph 2 of this Article.\nArticle 47 Binding corporate rules\n1.The competent supervisory authority shall approve binding corporate rules in accordance with the consistency mechanism set out in Article 63, provided that they:\n(a)are legally binding and apply to and are enforced by every member concerned of the group of undertakings, or group of enterprises engaged in a joint economic activity, including their employees;\n(b)expressly confer enforceable rights on data subjects with regard to the processing of their personal data; and\n(c)fulfil the requirements laid down in paragraph 2.\n2.The binding corporate rules referred to in paragraph 1 shall specify at least:\n(a)the structure and contact details of the group of undertakings, or group of enterprises engaged in a joint economic activity and of each of its members;\n(b)the data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected and the identification of the third country or countries in question;\n(c)their legally binding nature, both internally and externally;\n(d)the application of the general data protection principles, in particular purpose limitation, data minimisation, limited storage periods, data quality, data protection by design and by default, legal basis for processing, processing of special categories of personal data, measures to ensure data security, and the requirements in respect of onward transfers to bodies not bound by the binding corporate rules;\n(e)the rights of data subjects in regard to processing and the means to exercise those rights, including the right not to be subject to decisions based solely on automated processing, including profiling in accordance with Article 22, the right to lodge a complaint with the competent supervisory authority and before the competent courts of the Member States in accordance with Article 79, and to obtain redress and, where appropriate, compensation for a breach of the binding corporate rules;\n(f)the acceptance by the controller or processor established on the territory of a Member State of liability for any breaches of the binding corporate rules by any member concerned not established in the Union; the controller or the processor shall be exempt from that liability, in whole or in part, only if it proves that that member is not responsible for the event giving rise to the damage;\n(g)how the information on the binding corporate rules, in particular on the provisions referred to in points (d), (e) and(f) of this paragraph is provided to the data subjects in addition to Articles 13 and 14;\n(h)the tasks of any data protection officer designated in accordance with Article 37 or any other person or entity in charge of the monitoring compliance with the binding corporate rules within the group of undertakings, or group of enterprises engaged in a joint economic activity, as well as monitoring training and complaint-handling;\n(i)the complaint procedures;\n(j)the mechanisms within the group of undertakings, or group of enterprises engaged in a joint economic activity for ensuring the verification of compliance with the binding corporate rules. Such mechanisms shall include data protection audits and methods for ensuring corrective actions to protect the rights of the data subject. Results of such verification should be communicated to the person or entity referred to in point(h) and to the board of the controlling undertaking of a group of undertakings, or of the group of enterprises engaged in a joint economic activity, and should be available upon request to the competent supervisory authority;\n(k)the mechanisms for reporting and recording changes to the rules and reporting those changes to the supervisory authority;\n(l)the cooperation mechanism with the supervisory authority to ensure compliance by any member of the group of undertakings, or group of enterprises engaged in a joint economic activity, in particular by making available to the supervisory authority the results of verifications of the measures referred to in point (j);\n(m)the mechanisms for reporting to the competent supervisory authority any legal requirements to which a member of the group of undertakings, or group of enterprises engaged in a joint economic activity is subject in a third country which are likely to have a substantial adverse effect on the guarantees provided by the binding corporate rules; and\n(n)the appropriate data protection training to personnel having permanent or regular access to personal data.\n3.The Commission may specify the format and procedures for the exchange of information between controllers, processors and supervisory authorities for binding corporate rules within the meaning of this Article. Those implementing acts shall be adopted in accordance with the examination procedure set out in Article 93(2).\nArticle 48 Transfers or disclosures not authorised by Union law\nAny judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable in any manner if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer pursuant to this Chapter.\nArticle 49 Derogations for specific situations\n1.In the absence of an adequacy decision pursuant to Article 45(3), or of appropriate safeguards pursuant to Article 46, including binding corporate rules, a transfer or a set of transfers of personal data to a third country or an international organisation shall take place only on one of the following conditions:\n(a)the data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers for the data subject due to the absence of an adequacy decision and appropriate safeguards;\n(b)the transfer is necessary for the performance of a contract between the data subject and the controller or the implementation of pre-contractual measures taken at the data subject\u0026rsquo;s request;\n(c)the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject between the controller and another natural or legal person;\n(d)the transfer is necessary for important reasons of public interest;\n(e)the transfer is necessary for the establishment, exercise or defence of legal claims;\n(f)the transfer is necessary in order to protect the vital interests of the data subject or of other persons, where the data subject is physically or legally incapable of giving consent;\n(g)the transfer is made from a register which according to Union or Member State law is intended to provide information to the public and which is open to consultation either by the public in general or by any person who can demonstrate a legitimate interest, but only to the extent that the conditions laid down by Union or Member State law for consultation are fulfilled in the particular case.\nWhere a transfer could not be based on a provision in Article 45 or 46, including the provisions on binding corporate rules, and none of the derogations for a specific situation referred to in the first subparagraph of this paragraph is applicable, a transfer to a third country or an international organisation may take place only if the transfer is not repetitive, concerns only a limited number of data subjects, is necessary for the purposes of compelling legitimate interests pursued by the controller which are not overridden by the interests or rights and freedoms of the data subject, and the controller has assessed all the circumstances surrounding the data transfer and has on the basis of that assessment provided suitable safeguards with regard to the protection of personal data. The controller shall inform the supervisory authority of the transfer. The controller shall, in addition to providing the information referred to in Articles 13 and 14, inform the data subject of the transfer and on the compelling legitimate interests pursued.\n2.A transfer pursuant to point (g) of the first subparagraph of paragraph 1 shall not involve the entirety of the personal data or entire categories of the personal data contained in the register. Where the register is intended for consultation by persons having a legitimate interest, the transfer shall be made only at the request of those persons or if they are to be the recipients.\n3.Points (a), (b) and (c) of the first subparagraph of paragraph 1 and the second subparagraph thereof shall not apply to activities carried out by public authorities in the exercise of their public powers.\n4.The public interest referred to in point (d) of the first subparagraph of paragraph 1 shall be recognised in Union law or in the law of the Member State to which the controller is subject.\n5.In the absence of an adequacy decision, Union or Member State law may, for important reasons of public interest, expressly set limits to the transfer of specific categories of personal data to a third country or an international organisation. Member States shall notify such provisions to the Commission.\n6.The controller or processor shall document the assessment as well as the suitable safeguards referred to in the second subparagraph of paragraph 1 of this Article in the records referred to in Article 30.\nArticle 50 International cooperation for the protection of personal data\nIn relation to third countries and international organisations, the Commission and supervisory authorities shall take appropriate steps to:\n(a)develop international cooperation mechanisms to facilitate the effective enforcement of legislation for the protection of personal data;\n(b)provide international mutual assistance in the enforcement of legislation for the protection of personal data, including through notification, complaint referral, investigative assistance and information exchange, subject to appropriate safeguards for the protection of personal data and other fundamental rights and freedoms;\n(c)engage relevant stakeholders in discussion and activities aimed at furthering international cooperation in the enforcement of legislation for the protection of personal data;\n(d)promote the exchange and documentation of personal data protection legislation and practice, including on jurisdictional conflicts with third countries.\nCHAPTER VI Independent supervisory authorities\nSection 1\nIndependent status\nArticle 51 Supervisory authority\n1.Each Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation, in order to protect the fundamental rights and freedoms of natural persons in relation to processing and to facilitate the free flow of personal data within the Union (‘supervisory authority’).\n2.Each supervisory authority shall contribute to the consistent application of this Regulation throughout the Union. For that purpose, the supervisory authorities shall cooperate with each other and the Commission in accordance with Chapter VII.\n3.Where more than one supervisory authority is established in a Member State, that Member State shall designate the supervisory authority which is to represent those authorities in the Board and shall set out the mechanism to ensure compliance by the other authorities with the rules relating to the consistency mechanism referred to in Article 63.\n4.Each Member State shall notify to the Commission the provisions of its law which it adopts pursuant to this Chapter, by 25 May 2018 and, without delay, any subsequent amendment affecting them.\nArticle 52 Independence\n1.Each supervisory authority shall act with complete independence in performing its tasks and exercising its powers in accordance with this Regulation.\n2.The member or members of each supervisory authority shall, in the performance of their tasks and exercise of their powers in accordance with this Regulation, remain free from external influence, whether direct or indirect, and shall neither seek nor take instructions from anybody.\n3.Member or members of each supervisory authority shall refrain from any action incompatible with their duties and shall not, during their term of office, engage in any incompatible occupation, whether gainful or not.\n4.Each Member State shall ensure that each supervisory authority is provided with the human, technical and financial resources, premises and infrastructure necessary for the effective performance of its tasks and exercise of its powers, including those to be carried out in the context of mutual assistance, cooperation and participation in the Board.\n5.Each Member State shall ensure that each supervisory authority chooses and has its own staff which shall be subject to the exclusive direction of the member or members of the supervisory authority concerned.\n6.Each Member State shall ensure that each supervisory authority is subject to financial control which does not affect its independence and that it has separate, public annual budgets, which may be part of the overall state or national budget.\nArticle 53 General conditions for the members of the supervisory authority\n1.Member States shall provide for each member of their supervisory authorities to be appointed by means of a transparent procedure by:\n—their parliament;\n—their government;\n—their head of State; or\n—an independent body entrusted with the appointment under Member State law.\n2.Each member shall have the qualifications, experience and skills, in particular in the area of the protection of personal data, required to perform its duties and exercise its powers.\n3.The duties of a member shall end in the event of the expiry of the term of office, resignation or compulsory retirement, in accordance with the law of the Member State concerned.\n4.A member shall be dismissed only in cases of serious misconduct or if the member no longer fulfils the conditions required for the performance of the duties.\nArticle 54 Rules on the establishment of the supervisory authority\n1.Each Member State shall provide by law for all of the following:\n(a)the establishment of each supervisory authority;\n(b)the qualifications and eligibility conditions required to be appointed as member of each supervisory authority;\n(c)the rules and procedures for the appointment of the member or members of each supervisory authority;\n(d)the duration of the term of the member or members of each supervisory authority of no less than four years, except for the first appointment after 24 May 2016, part of which may take place for a shorter period where that is necessary to protect the independence of the supervisory authority by means of a staggered appointment procedure;\n(e)whether and, if so, for how many terms the member or members of each supervisory authority is eligible for reappointment;\n(f)the conditions governing the obligations of the member or members and staff of each supervisory authority, prohibitions on actions, occupations and benefits incompatible therewith during and after the term of office and rules governing the cessation of employment.\n2.The member or members and the staff of each supervisory authority shall, in accordance with Union or Member State law, be subject to a duty of professional secrecy both during and after their term of office, with regard to any confidential information which has come to their knowledge in the course of the performance of their tasks or exercise of their powers. During their term of office, that duty of professional secrecy shall in particular apply to reporting by natural persons of infringements of this Regulation.\nSection 2\nCompetence, tasks and powers\nArticle 55 Competence\n1.Each supervisory authority shall be competent for the performance of the tasks assigned to and the exercise of the powers conferred on it in accordance with this Regulation on the territory of its own Member State.\n2.Where processing is carried out by public authorities or private bodies acting on the basis of point(c) or (e) of Article 6(1), the supervisory authority of the Member State concerned shall be competent. In such cases Article 56 does not apply.\n3.Supervisory authorities shall not be competent to supervise processing operations of courts acting in their judicial capacity.\nArticle 56 Competence of the lead supervisory authority\n1.Without prejudice to Article 55, the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor in accordance with the procedure provided in Article 60.\n2.By derogation from paragraph 1, each supervisory authority shall be competent to handle a complaint lodged with it or a possible infringement of this Regulation, if the subject matter relates only to an establishment in its Member State or substantially affects data subjects only in its Member State.\n3.In the cases referred to in paragraph 2 of this Article, the supervisory authority shall inform the lead supervisory authority without delay on that matter. Within a period of three weeks after being informed the lead supervisory authority shall decide whether or not it will handle the case in accordance with the procedure provided in Article 60, taking into account whether or not there is an establishment of the controller or processor in the Member State of which the supervisory authority informed it.\n4.Where the lead supervisory authority decides to handle the case, the procedure provided in Article 60 shall apply. The supervisory authority which informed the lead supervisory authority may submit to the lead supervisory authority a draft for a decision. The lead supervisory authority shall take utmost account of that draft when preparing the draft decision referred to in Article 60(3).\n5.Where the lead supervisory authority decides not to handle the case, the supervisory authority which informed the lead supervisory authority shall handle it according to Articles 61 and 62.\n6.The lead supervisory authority shall be the sole interlocutor of the controller or processor for the cross-border processing carried out by that controller or processor.\nArticle 57 Tasks\n1.Without prejudice to other tasks set out under this Regulation, each supervisory authority shall on its territory:\n(a)monitor and enforce the application of this Regulation;\n(b)promote public awareness and understanding of the risks, rules, safeguards and rights in relation to processing. Activities addressed specifically to children shall receive specific attention;\n(c)advise, in accordance with Member State law, the national parliament, the government, and other institutions and bodies on legislative and administrative measures relating to the protection of natural persons\u0026rsquo; rights and freedoms with regard to processing;\n(d)promote the awareness of controllers and processors of their obligations under this Regulation;\n(e)upon request, provide information to any data subject concerning the exercise of their rights under this Regulation and, if appropriate, cooperate with the supervisory authorities in other Member States to that end;\n(f)handle complaints lodged by a data subject, or by a body, organisation or association in accordance with Article 80, and investigate, to the extent appropriate, the subject matter of the complaint and inform the complainant of the progress and the outcome of the investigation within a reasonable period, in particular if further investigation or coordination with another supervisory authority is necessary;\n(g)cooperate with, including sharing information and provide mutual assistance to, other supervisory authorities with a view to ensuring the consistency of application and enforcement of this Regulation;\n(h)conduct investigations on the application of this Regulation, including on the basis of information received from another supervisory authority or other public authority;\n(i)monitor relevant developments, insofar as they have an impact on the protection of personal data, in particular the development of information and communication technologies and commercial practices;\n(j)adopt standard contractual clauses referred to in Article 28(8) and in point(d) of Article 46(2);\n(k)establish and maintain a list in relation to the requirement for data protection impact assessment pursuant to Article 35(4);\n(l)give advice on the processing operations referred to in Article 36(2);\n(m)encourage the drawing up of codes of conduct pursuant to Article 40(1) and provide an opinion and approve such codes of conduct which provide sufficient safeguards, pursuant to Article 40(5);\n(n)encourage the establishment of data protection certification mechanisms and of data protection seals and marks pursuant to Article 42(1), and approve the criteria of certification pursuant to Article 42(5);\n(o)where applicable, carry out a periodic review of certifications issued in accordance with Article 42(7);\n(p)draft and publish the criteria for accreditation of a body for monitoring codes of conduct pursuant to Article 41 and of a certification body pursuant to Article 43;\n(q)conduct the accreditation of a body for monitoring codes of conduct pursuant to Article 41 and of a certification body pursuant to Article 43;\n(r)authorise contractual clauses and provisions referred to in Article 46(3);\n(s)approve binding corporate rules pursuant to Article 47;\n(t)contribute to the activities of the Board;\n(u)keep internal records of infringements of this Regulation and of measures taken in accordance with Article 58(2); and\n(v)fulfil any other tasks related to the protection of personal data.\n2.Each supervisory authority shall facilitate the submission of complaints referred to in point(f) of paragraph 1 by measures such as a complaint submission form which can also be completed electronically, without excluding other means of communication.\n3.The performance of the tasks of each supervisory authority shall be free of charge for the data subject and, where applicable, for the data protection officer.\n4.Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the supervisory authority may charge a reasonable fee based on administrative costs, or refuse to act on the request. The supervisory authority shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.\nArticle 58 Powers\n1.Each supervisory authority shall have all of the following investigative powers:\n(a)to order the controller and the processor, and, where applicable, the controller\u0026rsquo;s or the processor\u0026rsquo;s representative to provide any information it requires for the performance of its tasks;\n(b)to carry out investigations in the form of data protection audits;\n(c)to carry out a review on certifications issued pursuant to Article 42(7);\n(d)to notify the controller or the processor of an alleged infringement of this Regulation;\n(e)to obtain, from the controller and the processor, access to all personal data and to all information necessary for the performance of its tasks;\n(f)to obtain access to any premises of the controller and the processor, including to any data processing equipment and means, in accordance with Union or Member State procedural law.\n2.Each supervisory authority shall have all of the following corrective powers:\n(a)to issue warnings to a controller or processor that intended processing operations are likely to infringe provisions of this Regulation;\n(b)to issue reprimands to a controller or a processor where processing operations have infringed provisions of this Regulation;\n(c)to order the controller or the processor to comply with the data subject\u0026rsquo;s requests to exercise his or her rights pursuant to this Regulation;\n(d)to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period;\n(e)to order the controller to communicate a personal data breach to the data subject;\n(f)to impose a temporary or definitive limitation including a ban on processing;\n(g)to order the rectification or erasure of personal data or restriction of processing pursuant to Articles 16, 17 and 18 and the notification of such actions to recipients to whom the personal data have been disclosed pursuant to Article 17(2) and Article 19;\n(h)to withdraw a certification or to order the certification body to withdraw a certification issued pursuant to Articles 42 and 43, or to order the certification body not to issue certification if the requirements for the certification are not or are no longer met;\n(i)to impose an administrative fine pursuant to Article 83, in addition to, or instead of measures referred to in this paragraph, depending on the circumstances of each individual case;\n(j)to order the suspension of data flows to a recipient in a third country or to an international organisation.\n3.Each supervisory authority shall have all of the following authorisation and advisory powers:\n(a)to advise the controller in accordance with the prior consultation procedure referred to in Article 36;\n(b)to issue, on its own initiative or on request, opinions to the national parliament, the Member State government or, in accordance with Member State law, to other institutions and bodies as well as to the public on any issue related to the protection of personal data;\n(c)to authorise processing referred to in Article 36(5), if the law of the Member State requires such prior authorisation;\n(d)to issue an opinion and approve draft codes of conduct pursuant to Article 40(5);\n(e)to accredit certification bodies pursuant to Article 43;\n(f)to issue certifications and approve criteria of certification in accordance with Article 42(5);\n(g)to adopt standard data protection clauses referred to in Article 28(8) and in point(d) of Article 46(2);\n(h)to authorise contractual clauses referred to in point (a) of Article 46(3);\n(i)to authorise administrative arrangements referred to in point (b) of Article 46(3);\n(j)to approve binding corporate rules pursuant to Article 47.\n4.The exercise of the powers conferred on the supervisory authority pursuant to this Article shall be subject to appropriate safeguards, including effective judicial remedy and due process, set out in Union and Member State law in accordance with the Charter.\n5.Each Member State shall provide by law that its supervisory authority shall have the power to bring infringements of this Regulation to the attention of the judicial authorities and where appropriate, to commence or engage otherwise in legal proceedings, in order to enforce the provisions of this Regulation.\n6.Each Member State may provide by law that its supervisory authority shall have additional powers to those referred to in paragraphs 1, 2 and 3. The exercise of those powers shall not impair the effective operation of Chapter VII.\nArticle 59 Activity reports\nEach supervisory authority shall draw up an annual report on its activities, which may include a list of types of infringement notified and types of measures taken in accordance with Article 58(2). Those reports shall be transmitted to the national parliament, the government and other authorities as designated by Member State law. They shall be made available to the public, to the Commission and to the Board.\nCHAPTER VII Cooperation and consistency\nSection 1\nCooperation\nArticle 60 Cooperation between the lead supervisory authority and the other supervisory authorities concerned\n1.The lead supervisory authority shall cooperate with the other supervisory authorities concerned in accordance with this Article in an endeavour to reach consensus. The lead supervisory authority and the supervisory authorities concerned shall exchange all relevant information with each other.\n2.The lead supervisory authority may request at any time other supervisory authorities concerned to provide mutual assistance pursuant to Article 61 and may conduct joint operations pursuant to Article 62, in particular for carrying out investigations or for monitoring the implementation of a measure concerning a controller or processor established in another Member State.\n3.The lead supervisory authority shall, without delay, communicate the relevant information on the matter to the other supervisory authorities concerned. It shall without delay submit a draft decision to the other supervisory authorities concerned for their opinion and take due account of their views.\n4.Where any of the other supervisory authorities concerned within a period of four weeks after having been consulted in accordance with paragraph 3 of this Article, expresses a relevant and reasoned objection to the draft decision, the lead supervisory authority shall, if it does not follow the relevant and reasoned objection or is of the opinion that the objection is not relevant or reasoned, submit the matter to the consistency mechanism referred to in Article 63.\n5.Where the lead supervisory authority intends to follow the relevant and reasoned objection made, it shall submit to the other supervisory authorities concerned a revised draft decision for their opinion. That revised draft decision shall be subject to the procedure referred to in paragraph 4 within a period of two weeks.\n6.Where none of the other supervisory authorities concerned has objected to the draft decision submitted by the lead supervisory authority within the period referred to in paragraphs 4 and 5, the lead supervisory authority and the supervisory authorities concerned shall be deemed to be in agreement with that draft decision and shall be bound by it.\n7.The lead supervisory authority shall adopt and notify the decision to the main establishment or single establishment of the controller or processor, as the case may be and inform the other supervisory authorities concerned and the Board of the decision in question, including a summary of the relevant facts and grounds. The supervisory authority with which a complaint has been lodged shall inform the complainant on the decision.\n8.By derogation from paragraph 7, where a complaint is dismissed or rejected, the supervisory authority with which the complaint was lodged shall adopt the decision and notify it to the complainant and shall inform the controller thereof.\n9.Where the lead supervisory authority and the supervisory authorities concerned agree to dismiss or reject parts of a complaint and to act on other parts of that complaint, a separate decision shall be adopted for each of those parts of the matter. The lead supervisory authority shall adopt the decision for the part concerning actions in relation to the controller, shall notify it to the main establishment or single establishment of the controller or processor on the territory of its Member State and shall inform the complainant thereof, while the supervisory authority of the complainant shall adopt the decision for the part concerning dismissal or rejection of that complaint, and shall notify it to that complainant and shall inform the controller or processor thereof.\n10.After being notified of the decision of the lead supervisory authority pursuant to paragraphs 7 and 9, the controller or processor shall take the necessary measures to ensure compliance with the decision as regards processing activities in the context of all its establishments in the Union. The controller or processor shall notify the measures taken for complying with the decision to the lead supervisory authority, which shall inform the other supervisory authorities concerned.\n11.Where, in exceptional circumstances, a supervisory authority concerned has reasons to consider that there is an urgent need to act in order to protect the interests of data subjects, the urgency procedure referred to in Article 66 shall apply.\n12.The lead supervisory authority and the other supervisory authorities concerned shall supply the information required under this Article to each other by electronic means, using a standardised format.\nArticle 61 Mutual assistance\n1.Supervisory authorities shall provide each other with relevant information and mutual assistance in order to implement and apply this Regulation in a consistent manner, and shall put in place measures for effective cooperation with one another. Mutual assistance shall cover, in particular, information requests and supervisory measures, such as requests to carry out prior authorisations and consultations, inspections and investigations.\n2.Each supervisory authority shall take all appropriate measures required to reply to a request of another supervisory authority without undue delay and no later than one month after receiving the request. Such measures may include, in particular, the transmission of relevant information on the conduct of an investigation.\n3.Requests for assistance shall contain all the necessary information, including the purpose of and reasons for the request. Information exchanged shall be used only for the purpose for which it was requested.\n4.The requested supervisory authority shall not refuse to comply with the request unless:\n(a)it is not competent for the subject-matter of the request or for the measures it is requested to execute; or\n(b)compliance with the request would infringe this Regulation or Union or Member State law to which the supervisory authority receiving the request is subject.\n5.The requested supervisory authority shall inform the requesting supervisory authority of the results or, as the case may be, of the progress of the measures taken in order to respond to the request. The requested supervisory authority shall provide reasons for any refusal to comply with a request pursuant to paragraph 4.\n6.Requested supervisory authorities shall, as a rule, supply the information requested by other supervisory authorities by electronic means, using a standardised format.\n7.Requested supervisory authorities shall not charge a fee for any action taken by them pursuant to a request for mutual assistance. Supervisory authorities may agree on rules to indemnify each other for specific expenditure arising from the provision of mutual assistance in exceptional circumstances.\n8.Where a supervisory authority does not provide the information referred to in paragraph 5 of this Article within one month of receiving the request of another supervisory authority, the requesting supervisory authority may adopt a provisional measure on the territory of its Member State in accordance with Article 55(1). In that case, the urgent need to act under Article 66(1) shall be presumed to be met and require an urgent binding decision from the Board pursuant to Article 66(2).\n9.The Commission may, by means of implementing acts, specify the format and procedures for mutual assistance referred to in this Article and the arrangements for the exchange of information by electronic means between supervisory authorities, and between supervisory authorities and the Board, in particular the standardised format referred to in paragraph 6 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).\nArticle 62 Joint operations of supervisory authorities\n1.The supervisory authorities shall, where appropriate, conduct joint operations including joint investigations and joint enforcement measures in which members or staff of the supervisory authorities of other Member States are involved.\n2.Where the controller or processor has establishments in several Member States or where a significant number of data subjects in more than one Member State are likely to be substantially affected by processing operations, a supervisory authority of each of those Member States shall have the right to participate in joint operations. The supervisory authority which is competent pursuant to Article 56(1) or (4) shall invite the supervisory authority of each of those Member States to take part in the joint operations and shall respond without delay to the request of a supervisory authority to participate.\n3.A supervisory authority may, in accordance with Member State law, and with the seconding supervisory authority\u0026rsquo;s authorisation, confer powers, including investigative powers on the seconding supervisory authority\u0026rsquo;s members or staff involved in joint operations or, in so far as the law of the Member State of the host supervisory authority permits, allow the seconding supervisory authority\u0026rsquo;s members or staff to exercise their investigative powers in accordance with the law of the Member State of the seconding supervisory authority. Such investigative powers may be exercised only under the guidance and in the presence of members or staff of the host supervisory authority. The seconding supervisory authority\u0026rsquo;s members or staff shall be subject to the Member State law of the host supervisory authority.\n4.Where, in accordance with paragraph 1, staff of a seconding supervisory authority operate in another Member State, the Member State of the host supervisory authority shall assume responsibility for their actions, including liability, for any damage caused by them during their operations, in accordance with the law of the Member State in whose territory they are operating.\n5.The Member State in whose territory the damage was caused shall make good such damage under the conditions applicable to damage caused by its own staff. The Member State of the seconding supervisory authority whose staff has caused damage to any person in the territory of another Member State shall reimburse that other Member State in full any sums it has paid to the persons entitled on their behalf.\n6.Without prejudice to the exercise of its rights vis-à-vis third parties and with the exception of paragraph 5, each Member State shall refrain, in the case provided for in paragraph 1, from requesting reimbursement from another Member State in relation to damage referred to in paragraph 4.\n7.Where a joint operation is intended and a supervisory authority does not, within one month, comply with the obligation laid down in the second sentence of paragraph 2 of this Article, the other supervisory authorities may adopt a provisional measure on the territory of its Member State in accordance with Article 55. In that case, the urgent need to act under Article 66(1) shall be presumed to be met and require an opinion or an urgent binding decision from the Board pursuant to Article 66(2).\nSection 2\nConsistency\nArticle 63 Consistency mechanism\nIn order to contribute to the consistent application of this Regulation throughout the Union, the supervisory authorities shall cooperate with each other and, where relevant, with the Commission, through the consistency mechanism as set out in this Section.\nArticle 64 Opinion of the Board\n1.The Board shall issue an opinion where a competent supervisory authority intends to adopt any of the measures below. To that end, the competent supervisory authority shall communicate the draft decision to the Board, when it:\n(a)aims to adopt a list of the processing operations subject to the requirement for a data protection impact assessment pursuant to Article 35(4);\n(b)concerns a matter pursuant to Article 40(7) whether a draft code of conduct or an amendment or extension to a code of conduct complies with this Regulation;\n(c)aims to approve the criteria for accreditation of a body pursuant to Article 41(3) or a certification body pursuant to Article 43(3);\n(d)aims to determine standard data protection clauses referred to in point(d) of Article 46(2) and in Article 28(8);\n(e)aims to authorise contractual clauses referred to in point (a) of Article 46(3); or\n(f)aims to approve binding corporate rules within the meaning of Article 47.\n2.Any supervisory authority, the Chair of the Board or the Commission may request that any matter of general application or producing effects in more than one Member State be examined by the Board with a view to obtaining an opinion, in particular where a competent supervisory authority does not comply with the obligations for mutual assistance in accordance with Article 61 or for joint operations in accordance with Article 62.\n3.In the cases referred to in paragraphs 1 and 2, the Board shall issue an opinion on the matter submitted to it provided that it has not already issued an opinion on the same matter. That opinion shall be adopted within eight weeks by simple majority of the members of the Board. That period may be extended by a further six weeks, taking into account the complexity of the subject matter. Regarding the draft decision referred to in paragraph 1 circulated to the members of the Board in accordance with paragraph 5, a member which has not objected within a reasonable period indicated by the Chair, shall be deemed to be in agreement with the draft decision.\n4.Supervisory authorities and the Commission shall, without undue delay, communicate by electronic means to the Board, using a standardised format any relevant information, including as the case may be a summary of the facts, the draft decision, the grounds which make the enactment of such measure necessary, and the views of other supervisory authorities concerned.\n5.The Chair of the Board shall, without undue, delay inform by electronic means:\n(a)the members of the Board and the Commission of any relevant information which has been communicated to it using a standardised format. The secretariat of the Board shall, where necessary, provide translations of relevant information; and\n(b)the supervisory authority referred to, as the case may be, in paragraphs 1 and 2, and the Commission of the opinion and make it public.\n6.The competent supervisory authority shall not adopt its draft decision referred to in paragraph 1 within the period referred to in paragraph 3.\n7.The supervisory authority referred to in paragraph 1 shall take utmost account of the opinion of the Board and shall, within two weeks after receiving the opinion, communicate to the Chair of the Board by electronic means whether it will maintain or amend its draft decision and, if any, the amended draft decision, using a standardised format.\n8.Where the supervisory authority concerned informs the Chair of the Board within the period referred to in paragraph 7 of this Article that it does not intend to follow the opinion of the Board, in whole or in part, providing the relevant grounds, Article 65(1) shall apply.\nArticle 65 Dispute resolution by the Board\n1.In order to ensure the correct and consistent application of this Regulation in individual cases, the Board shall adopt a binding decision in the following cases:\n(a)where, in a case referred to in Article 60(4), a supervisory authority concerned has raised a relevant and reasoned objection to a draft decision of the lead authority or the lead authority has rejected such an objection as being not relevant or reasoned. The binding decision shall concern all the matters which are the subject of the relevant and reasoned objection, in particular whether there is an infringement of this Regulation;\n(b)where there are conflicting views on which of the supervisory authorities concerned is competent for the main establishment;\n(c)where a competent supervisory authority does not request the opinion of the Board in the cases referred to in Article 64(1), or does not follow the opinion of the Board issued under Article 64. In that case, any supervisory authority concerned or the Commission may communicate the matter to the Board.\n2.The decision referred to in paragraph 1 shall be adopted within one month from the referral of the subject-matter by a two-thirds majority of the members of the Board. That period may be extended by a further month on account of the complexity of the subject-matter. The decision referred to in paragraph 1 shall be reasoned and addressed to the lead supervisory authority and all the supervisory authorities concerned and binding on them.\n3.Where the Board has been unable to adopt a decision within the periods referred to in paragraph 2, it shall adopt its decision within two weeks following the expiration of the second month referred to in paragraph 2 by a simple majority of the members of the Board. Where the members of the Board are split, the decision shall by adopted by the vote of its Chair.\n4.The supervisory authorities concerned shall not adopt a decision on the subject matter submitted to the Board under paragraph 1 during the periods referred to in paragraphs 2 and 3.\n5.The Chair of the Board shall notify, without undue delay, the decision referred to in paragraph 1 to the supervisory authorities concerned. It shall inform the Commission thereof. The decision shall be published on the website of the Board without delay after the supervisory authority has notified the final decision referred to in paragraph 6.\n6.The lead supervisory authority or, as the case may be, the supervisory authority with which the complaint has been lodged shall adopt its final decision on the basis of the decision referred to in paragraph 1 of this Article, without undue delay and at the latest by one month after the Board has notified its decision. The lead supervisory authority or, as the case may be, the supervisory authority with which the complaint has been lodged, shall inform the Board of the date when its final decision is notified respectively to the controller or the processor and to the data subject. The final decision of the supervisory authorities concerned shall be adopted under the terms of Article 60(7), (8) and(9). The final decision shall refer to the decision referred to in paragraph 1 of this Article and shall specify that the decision referred to in that paragraph will be published on the website of the Board in accordance with paragraph 5 of this Article. The final decision shall attach the decision referred to in paragraph 1 of this Article.\nArticle 66 Urgency procedure\n1.In exceptional circumstances, where a supervisory authority concerned considers that there is an urgent need to act in order to protect the rights and freedoms of data subjects, it may, by way of derogation from the consistency mechanism referred to in Articles 63, 64 and 65 or the procedure referred to in Article 60, immediately adopt provisional measures intended to produce legal effects on its own territory with a specified period of validity which shall not exceed three months. The supervisory authority shall, without delay, communicate those measures and the reasons for adopting them to the other supervisory authorities concerned, to the Board and to the Commission.\n2.Where a supervisory authority has taken a measure pursuant to paragraph 1 and considers that final measures need urgently be adopted, it may request an urgent opinion or an urgent binding decision from the Board, giving reasons for requesting such opinion or decision.\n3.Any supervisory authority may request an urgent opinion or an urgent binding decision, as the case may be, from the Board where a competent supervisory authority has not taken an appropriate measure in a situation where there is an urgent need to act, in order to protect the rights and freedoms of data subjects, giving reasons for requesting such opinion or decision, including for the urgent need to act.\n4.By derogation from Article 64(3) and Article 65(2), an urgent opinion or an urgent binding decision referred to in paragraphs 2 and 3 of this Article shall be adopted within two weeks by simple majority of the members of the Board.\nArticle 67 Exchange of information\nThe Commission may adopt implementing acts of general scope in order to specify the arrangements for the exchange of information by electronic means between supervisory authorities, and between supervisory authorities and the Board, in particular the standardised format referred to in Article 64.\nThose implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).\nSection 3\nEuropean data protection board\nArticle 68 European Data Protection Board\n1.The European Data Protection Board (the ‘Board’) is hereby established as a body of the Union and shall have legal personality.\n2.The Board shall be represented by its Chair.\n3.The Board shall be composed of the head of one supervisory authority of each Member State and of the European Data Protection Supervisor, or their respective representatives.\n4.Where in a Member State more than one supervisory authority is responsible for monitoring the application of the provisions pursuant to this Regulation, a joint representative shall be appointed in accordance with that Member State\u0026rsquo;s law.\n5.The Commission shall have the right to participate in the activities and meetings of the Board without voting right. The Commission shall designate a representative. The Chair of the Board shall communicate to the Commission the activities of the Board.\n6.In the cases referred to in Article 65, the European Data Protection Supervisor shall have voting rights only on decisions which concern principles and rules applicable to the Union institutions, bodies, offices and agencies which correspond in substance to those of this Regulation.\nArticle 69 Independence\n1.The Board shall act independently when performing its tasks or exercising its powers pursuant to Articles 70 and 71.\n2.Without prejudice to requests by the Commission referred to in point (b) of Article 70(1) and in Article 70(2), the Board shall, in the performance of its tasks or the exercise of its powers, neither seek nor take instructions from anybody.\nArticle 70 Tasks of the Board\n1.The Board shall ensure the consistent application of this Regulation. To that end, the Board shall, on its own initiative or, where relevant, at the request of the Commission, in particular:\n(a)monitor and ensure the correct application of this Regulation in the cases provided for in Articles 64 and 65 without prejudice to the tasks of national supervisory authorities;\n(b)advise the Commission on any issue related to the protection of personal data in the Union, including on any proposed amendment of this Regulation;\n(c)advise the Commission on the format and procedures for the exchange of information between controllers, processors and supervisory authorities for binding corporate rules;\n(d)issue guidelines, recommendations, and best practices on procedures for erasing links, copies or replications of personal data from publicly available communication services as referred to in Article 17(2);\n(e)examine, on its own initiative, on request of one of its members or on request of the Commission, any question covering the application of this Regulation and issue guidelines, recommendations and best practices in order to encourage consistent application of this Regulation;\n(f)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph for further specifying the criteria and conditions for decisions based on profiling pursuant to Article 22(2);\n(g)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph for establishing the personal data breaches and determining the undue delay referred to in Article 33(1) and (2) and for the particular circumstances in which a controller or a processor is required to notify the personal data breach;\n(h)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph as to the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of the natural persons referred to in Article 34(1).\n(i)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph for the purpose of further specifying the criteria and requirements for personal data transfers based on binding corporate rules adhered to by controllers and binding corporate rules adhered to by processors and on further necessary requirements to ensure the protection of personal data of the data subjects concerned referred to in Article 47;\n(j)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph for the purpose of further specifying the criteria and requirements for the personal data transfers on the basis of Article 49(1);\n(k)draw up guidelines for supervisory authorities concerning the application of measures referred to in Article 58(1), (2) and (3) and the setting of administrative fines pursuant to Article 83;\n(l)review the practical application of the guidelines, recommendations and best practices referred to in points (e) and(f);\n(m)issue guidelines, recommendations and best practices in accordance with point(e) of this paragraph for establishing common procedures for reporting by natural persons of infringements of this Regulation pursuant to Article 54(2);\n(n)encourage the drawing-up of codes of conduct and the establishment of data protection certification mechanisms and data protection seals and marks pursuant to Articles 40 and 42;\n(o)carry out the accreditation of certification bodies and its periodic review pursuant to Article 43 and maintain a public register of accredited bodies pursuant to Article 43(6) and of the accredited controllers or processors established in third countries pursuant to Article 42(7);\n(p)specify the requirements referred to in Article 43(3) with a view to the accreditation of certification bodies under Article 42;\n(q)provide the Commission with an opinion on the certification requirements referred to in Article 43(8);\n(r)provide the Commission with an opinion on the icons referred to in Article 12(7);\n(s)provide the Commission with an opinion for the assessment of the adequacy of the level of protection in a third country or international organisation, including for the assessment whether a third country, a territory or one or more specified sectors within that third country, or an international organisation no longer ensures an adequate level of protection. To that end, the Commission shall provide the Board with all necessary documentation, including correspondence with the government of the third country, with regard to that third country, territory or specified sector, or with the international organisation.\n(t)issue opinions on draft decisions of supervisory authorities pursuant to the consistency mechanism referred to in Article 64(1), on matters submitted pursuant to Article 64(2) and to issue binding decisions pursuant to Article 65, including in cases referred to in Article 66;\n(u)promote the cooperation and the effective bilateral and multilateral exchange of information and best practices between the supervisory authorities;\n(v)promote common training programmes and facilitate personnel exchanges between the supervisory authorities and, where appropriate, with the supervisory authorities of third countries or with international organisations;\n(w)promote the exchange of knowledge and documentation on data protection legislation and practice with data protection supervisory authorities worldwide.\n(x)issue opinions on codes of conduct drawn up at Union level pursuant to Article 40(9); and\n(y)maintain a publicly accessible electronic register of decisions taken by supervisory authorities and courts on issues handled in the consistency mechanism.\n2.Where the Commission requests advice from the Board, it may indicate a time limit, taking into account the urgency of the matter.\n3.The Board shall forward its opinions, guidelines, recommendations, and best practices to the Commission and to the committee referred to in Article 93 and make them public.\n4.The Board shall, where appropriate, consult interested parties and give them the opportunity to comment within a reasonable period. The Board shall, without prejudice to Article 76, make the results of the consultation procedure publicly available.\nArticle 71 Reports\n1.The Board shall draw up an annual report regarding the protection of natural persons with regard to processing in the Union and, where relevant, in third countries and international organisations. The report shall be made public and be transmitted to the European Parliament, to the Council and to the Commission.\n2.The annual report shall include a review of the practical application of the guidelines, recommendations and best practices referred to in point (l) of Article 70(1) as well as of the binding decisions referred to in Article 65.\nArticle 72 Procedure\n1.The Board shall take decisions by a simple majority of its members, unless otherwise provided for in this Regulation.\n2.The Board shall adopt its own rules of procedure by a two-thirds majority of its members and organise its own operational arrangements.\nArticle 73 Chair\n1.The Board shall elect a chair and two deputy chairs from amongst its members by simple majority.\n2.The term of office of the Chair and of the deputy chairs shall be five years and be renewable once.\nArticle 74 Tasks of the Chair\n1.The Chair shall have the following tasks:\n(a)to convene the meetings of the Board and prepare its agenda;\n(b)to notify decisions adopted by the Board pursuant to Article 65 to the lead supervisory authority and the supervisory authorities concerned;\n(c)to ensure the timely performance of the tasks of the Board, in particular in relation to the consistency mechanism referred to in Article 63.\n2.The Board shall lay down the allocation of tasks between the Chair and the deputy chairs in its rules of procedure.\nArticle 75 Secretariat\n1.The Board shall have a secretariat, which shall be provided by the European Data Protection Supervisor.\n2.The secretariat shall perform its tasks exclusively under the instructions of the Chair of the Board.\n3.The staff of the European Data Protection Supervisor involved in carrying out the tasks conferred on the Board by this Regulation shall be subject to separate reporting lines from the staff involved in carrying out tasks conferred on the European Data Protection Supervisor.\n4.Where appropriate, the Board and the European Data Protection Supervisor shall establish and publish a Memorandum of Understanding implementing this Article, determining the terms of their cooperation, and applicable to the staff of the European Data Protection Supervisor involved in carrying out the tasks conferred on the Board by this Regulation.\n5.The secretariat shall provide analytical, administrative and logistical support to the Board.\n6.The secretariat shall be responsible in particular for:\n(a)the day-to-day business of the Board;\n(b)communication between the members of the Board, its Chair and the Commission;\n(c)communication with other institutions and the public;\n(d)the use of electronic means for the internal and external communication;\n(e)the translation of relevant information;\n(f)the preparation and follow-up of the meetings of the Board;\n(g)the preparation, drafting and publication of opinions, decisions on the settlement of disputes between supervisory authorities and other texts adopted by the Board.\nArticle 76 Confidentiality\n1.The discussions of the Board shall be confidential where the Board deems it necessary, as provided for in its rules of procedure.\n2.Access to documents submitted to members of the Board, experts and representatives of third parties shall be governed by Regulation (EC) No 1049/2001 of the European Parliament and of the Council(21).\nCHAPTER VIII Remedies, liability and penalties\nArticle 77 Right to lodge a complaint with a supervisory authority\n1.Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.\n2.The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.\nArticle 78 Right to an effective judicial remedy against a supervisory authority\n1.Without prejudice to any other administrative or non-judicial remedy, each natural or legal person shall have the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning them.\n2.Without prejudice to any other administrative or non-judicial remedy, each data subject shall have the right to a an effective judicial remedy where the supervisory authority which is competent pursuant to Articles 55 and 56 does not handle a complaint or does not inform the data subject within three months on the progress or outcome of the complaint lodged pursuant to Article 77.\n3.Proceedings against a supervisory authority shall be brought before the courts of the Member State where the supervisory authority is established.\n4.Where proceedings are brought against a decision of a supervisory authority which was preceded by an opinion or a decision of the Board in the consistency mechanism, the supervisory authority shall forward that opinion or decision to the court.\nArticle 79 Right to an effective judicial remedy against a controller or processor\n1.Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.\n2.Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. Alternatively, such proceedings may be brought before the courts of the Member State where the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.\nArticle 80 Representation of data subjects\n1.The data subject shall have the right to mandate a not-for-profit body, organisation or association which has been properly constituted in accordance with the law of a Member State, has statutory objectives which are in the public interest, and is active in the field of the protection of data subjects\u0026rsquo; rights and freedoms with regard to the protection of their personal data to lodge the complaint on his or her behalf, to exercise the rights referred to in Articles 77, 78 and 79 on his or her behalf, and to exercise the right to receive compensation referred to in Article 82 on his or her behalf where provided for by Member State law.\n2.Member States may provide that any body, organisation or association referred to in paragraph 1 of this Article, independently of a data subject\u0026rsquo;s mandate, has the right to lodge, in that Member State, a complaint with the supervisory authority which is competent pursuant to Article 77 and to exercise the rights referred to in Articles 78 and 79 if it considers that the rights of a data subject under this Regulation have been infringed as a result of the processing.\nArticle 81 Suspension of proceedings\n1.Where a competent court of a Member State has information on proceedings, concerning the same subject matter as regards processing by the same controller or processor, that are pending in a court in another Member State, it shall contact that court in the other Member State to confirm the existence of such proceedings.\n2.Where proceedings concerning the same subject matter as regards processing of the same controller or processor are pending in a court in another Member State, any competent court other than the court first seized may suspend its proceedings.\n3.Where those proceedings are pending at first instance, any court other than the court first seized may also, on the application of one of the parties, decline jurisdiction if the court first seized has jurisdiction over the actions in question and its law permits the consolidation thereof.\nArticle 82 Right to compensation and liability\n1.Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.\n2.Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation. A processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller.\n3.A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage.\n4.Where more than one controller or processor, or both a controller and a processor, are involved in the same processing and where they are, under paragraphs 2 and 3, responsible for any damage caused by processing, each controller or processor shall be held liable for the entire damage in order to ensure effective compensation of the data subject.\n5.Where a controller or processor has, in accordance with paragraph 4, paid full compensation for the damage suffered, that controller or processor shall be entitled to claim back from the other controllers or processors involved in the same processing that part of the compensation corresponding to their part of responsibility for the damage, in accordance with the conditions set out in paragraph 2.\n6.Court proceedings for exercising the right to receive compensation shall be brought before the courts competent under the law of the Member State referred to in Article 79(2).\nArticle 83 General conditions for imposing administrative fines\n1.Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.\n2.Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:\n(a)the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;\n(b)the intentional or negligent character of the infringement;\n(c)any action taken by the controller or processor to mitigate the damage suffered by data subjects;\n(d)the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;\n(e)any relevant previous infringements by the controller or processor;\n(f)the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;\n(g)the categories of personal data affected by the infringement;\n(h)the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;\n(i)where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;\n(j)adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and\n(k)any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.\n3.If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement.\n4.Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:\n(a)the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43;\n(b)the obligations of the certification body pursuant to Articles 42 and 43;\n(c)the obligations of the monitoring body pursuant to Article 41(4).\n5.Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:\n(a)the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9;\n(b)the data subjects\u0026rsquo; rights pursuant to Articles 12 to 22;\n(c)the transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44 to 49;\n(d)any obligations pursuant to Member State law adopted under Chapter IX;\n(e)non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 58(2) or failure to provide access in violation of Article 58(1).\n6.Non-compliance with an order by the supervisory authority as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.\n7.Without prejudice to the corrective powers of supervisory authorities pursuant to Article 58(2), each Member State may lay down the rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.\n8.The exercise by the supervisory authority of its powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and Member State law, including effective judicial remedy and due process.\n9.Where the legal system of the Member State does not provide for administrative fines, this Article may be applied in such a manner that the fine is initiated by the competent supervisory authority and imposed by competent national courts, while ensuring that those legal remedies are effective and have an equivalent effect to the administrative fines imposed by supervisory authorities. In any event, the fines imposed shall be effective, proportionate and dissuasive. Those Member States shall notify to the Commission the provisions of their laws which they adopt pursuant to this paragraph by 25 May 2018 and, without delay, any subsequent amendment law or amendment affecting them.\nArticle 84 Penalties\n1.Member States shall lay down the rules on other penalties applicable to infringements of this Regulation in particular for infringements which are not subject to administrative fines pursuant to Article 83, and shall take all measures necessary to ensure that they are implemented. Such penalties shall be effective, proportionate and dissuasive.\n2.Each Member State shall notify to the Commission the provisions of its law which it adopts pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them.\nCHAPTER IX Provisions relating to specific processing situations\nArticle 85 Processing and freedom of expression and information\n1.Member States shall by law reconcile the right to the protection of personal data pursuant to this Regulation with the right to freedom of expression and information, including processing for journalistic purposes and the purposes of academic, artistic or literary expression.\n2.For processing carried out for journalistic purposes or the purpose of academic artistic or literary expression, Member States shall provide for exemptions or derogations from Chapter II (principles), Chapter III (rights of the data subject), Chapter IV (controller and processor), Chapter V (transfer of personal data to third countries or international organisations), Chapter VI (independent supervisory authorities), Chapter VII (cooperation and consistency) and Chapter IX (specific data processing situations) if they are necessary to reconcile the right to the protection of personal data with the freedom of expression and information.\n3.Each Member State shall notify to the Commission the provisions of its law which it has adopted pursuant to paragraph 2 and, without delay, any subsequent amendment law or amendment affecting them.\nArticle 86 Processing and public access to official documents\nPersonal data in official documents held by a public authority or a public body or a private body for the performance of a task carried out in the public interest may be disclosed by the authority or body in accordance with Union or Member State law to which the public authority or body is subject in order to reconcile public access to official documents with the right to the protection of personal data pursuant to this Regulation.\nArticle 87 Processing of the national identification number\nMember States may further determine the specific conditions for the processing of a national identification number or any other identifier of general application. In that case the national identification number or any other identifier of general application shall be used only under appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation.\nArticle 88 Processing in the context of employment\n1.Member States may, by law or by collective agreements, provide for more specific rules to ensure the protection of the rights and freedoms in respect of the processing of employees\u0026rsquo; personal data in the employment context, in particular for the purposes of the recruitment, the performance of the contract of employment, including discharge of obligations laid down by law or by collective agreements, management, planning and organisation of work, equality and diversity in the workplace, health and safety at work, protection of employer\u0026rsquo;s or customer\u0026rsquo;s property and for the purposes of the exercise and enjoyment, on an individual or collective basis, of rights and benefits related to employment, and for the purpose of the termination of the employment relationship.\n2.Those rules shall include suitable and specific measures to safeguard the data subject\u0026rsquo;s human dignity, legitimate interests and fundamental rights, with particular regard to the transparency of processing, the transfer of personal data within a group of undertakings, or a group of enterprises engaged in a joint economic activity and monitoring systems at the work place.\n3.Each Member State shall notify to the Commission those provisions of its law which it adopts pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them.\nArticle 89 Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes\n1.Processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, shall be subject to appropriate safeguards, in accordance with this Regulation, for the rights and freedoms of the data subject. Those safeguards shall ensure that technical and organisational measures are in place in particular in order to ensure respect for the principle of data minimisation. Those measures may include pseudonymisation provided that those purposes can be fulfilled in that manner. Where those purposes can be fulfilled by further processing which does not permit or no longer permits the identification of data subjects, those purposes shall be fulfilled in that manner.\n2.Where personal data are processed for scientific or historical research purposes or statistical purposes, Union or Member State law may provide for derogations from the rights referred to in Articles 15, 16, 18 and 21 subject to the conditions and safeguards referred to in paragraph 1 of this Article in so far as such rights are likely to render impossible or seriously impair the achievement of the specific purposes, and such derogations are necessary for the fulfilment of those purposes.\n3.Where personal data are processed for archiving purposes in the public interest, Union or Member State law may provide for derogations from the rights referred to in Articles 15, 16, 18, 19, 20 and 21 subject to the conditions and safeguards referred to in paragraph 1 of this Article in so far as such rights are likely to render impossible or seriously impair the achievement of the specific purposes, and such derogations are necessary for the fulfilment of those purposes.\n4.Where processing referred to in paragraphs 2 and 3 serves at the same time another purpose, the derogations shall apply only to processing for the purposes referred to in those paragraphs.\nArticle 90 Obligations of secrecy\n1.Member States may adopt specific rules to set out the powers of the supervisory authorities laid down in points (e) and (f) of Article 58(1) in relation to controllers or processors that are subject, under Union or Member State law or rules established by national competent bodies, to an obligation of professional secrecy or other equivalent obligations of secrecy where this is necessary and proportionate to reconcile the right of the protection of personal data with the obligation of secrecy. Those rules shall apply only with regard to personal data which the controller or processor has received as a result of or has obtained in an activity covered by that obligation of secrecy.\n2.Each Member State shall notify to the Commission the rules adopted pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them.\nArticle 91 Existing data protection rules of churches and religious associations\n1.Where in a Member State, churches and religious associations or communities apply, at the time of entry into force of this Regulation, comprehensive rules relating to the protection of natural persons with regard to processing, such rules may continue to apply, provided that they are brought into line with this Regulation.\n2.Churches and religious associations which apply comprehensive rules in accordance with paragraph 1 of this Article shall be subject to the supervision of an independent supervisory authority, which may be specific, provided that it fulfils the conditions laid down in Chapter VI of this Regulation.\nCHAPTER X Delegated acts and implementing acts\nArticle 92 Exercise of the delegation\n1.The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.\n2.The delegation of power referred to in Article 12(8) and Article 43(8) shall be conferred on the Commission for an indeterminate period of time from 24 May 2016.\n3.The delegation of power referred to in Article 12(8) and Article 43(8) may be revoked at any time by the European Parliament or by the Council. A decision of revocation shall put an end to the delegation of power specified in that decision. It shall take effect the day following that of its publication in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.\n4.As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.\n5.A delegated act adopted pursuant to Article 12(8) and Article 43(8) shall enter into force only if no objection has been expressed by either the European Parliament or the Council within a period of three months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by three months at the initiative of the European Parliament or of the Council.\nArticle 93 Committee procedure\n1.The Commission shall be assisted by a committee. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.\n2.Where reference is made to this paragraph, Article 5 of Regulation (EU) No 182/2011 shall apply.\n3.Where reference is made to this paragraph, Article 8 of Regulation (EU) No 182/2011, in conjunction with Article 5 thereof, shall apply.\nCHAPTER XI Final provisions\nArticle 94 Repeal of Directive 95/46/EC\n1.Directive 95/46/EC is repealed with effect from 25 May 2018.\n2.References to the repealed Directive shall be construed as references to this Regulation. References to the Working Party on the Protection of Individuals with regard to the Processing of Personal Data established by Article 29 of Directive 95/46/EC shall be construed as references to the European Data Protection Board established by this Regulation.\nArticle 95 Relationship with Directive 2002/58/EC\nThis Regulation shall not impose additional obligations on natural or legal persons in relation to processing in connection with the provision of publicly available electronic communications services in public communication networks in the Union in relation to matters for which they are subject to specific obligations with the same objective set out in Directive 2002/58/EC.\nArticle 96 Relationship with previously concluded Agreements\nInternational agreements involving the transfer of personal data to third countries or international organisations which were concluded by Member States prior to 24 May 2016, and which comply with Union law as applicable prior to that date, shall remain in force until amended, replaced or revoked.\nArticle 97 Commission reports\n1.By 25 May 2020 and every four years thereafter, the Commission shall submit a report on the evaluation and review of this Regulation to the European Parliament and to the Council. The reports shall be made public.\n2.In the context of the evaluations and reviews referred to in paragraph 1, the Commission shall examine, in particular, the application and functioning of:\n(a)Chapter V on the transfer of personal data to third countries or international organisations with particular regard to decisions adopted pursuant to Article 45(3) of this Regulation and decisions adopted on the basis of Article 25(6) of Directive 95/46/EC;\n(b)Chapter VII on cooperation and consistency.\n3.For the purpose of paragraph 1, the Commission may request information from Member States and supervisory authorities.\n4.In carrying out the evaluations and reviews referred to in paragraphs 1 and 2, the Commission shall take into account the positions and findings of the European Parliament, of the Council, and of other relevant bodies or sources.\n5.The Commission shall, if necessary, submit appropriate proposals to amend this Regulation, in particular taking into account of developments in information technology and in the light of the state of progress in the information society.\nArticle 98 Review of other Union legal acts on data protection\nThe Commission shall, if appropriate, submit legislative proposals with a view to amending other Union legal acts on the protection of personal data, in order to ensure uniform and consistent protection of natural persons with regard to processing. This shall in particular concern the rules relating to the protection of natural persons with regard to processing by Union institutions, bodies, offices and agencies and on the free movement of such data.\nArticle 99 Entry into force and application\n1.This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.\n2.It shall apply from 25 May 2018.\nThis Regulation shall be binding in its entirety and directly applicable in all Member States.\nDone at Brussels, 27 April 2016.\nFor the European Parliament\nThe President\nM. SCHULZ\nFor the Council\nThe President\nJ.A. HENNIS-PLASSCHAERT\n(1)OJ C 229, 31.7.2012, p. 90.\n(2)OJ C 391, 18.12.2012, p. 127.\n(3)Position of the European Parliament of 12 March 2014 (not yet published in the Official Journal) and position of the Council at first reading of 8 April 2016 (not yet published in the Official Journal). Position of the European Parliament of 14 April 2016.\n(4)Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ L 281, 23.11.1995, p. 31).\n(5)Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (C(2003) 1422) (OJ L 124, 20.5.2003, p. 36).\n(6)Regulation (EC) No 45/2001 of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data (OJ L 8, 12.1.2001, p. 1).\n(7)Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and the free movement of such data and repealing Council Framework Decision 2008/977/JHA (see page 89 of this Official Journal).\n(8)Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market (‘Directive on electronic commerce’) (OJ L 178, 17.7.2000, p. 1).\n(9)Directive 2011/24/EU of the European Parliament and of the Council of 9 March 2011 on the application of patients\u0026rsquo; rights in cross-border healthcare (OJ L 88, 4.4.2011, p. 45).\n(10)Council Directive 93/13/EEC of 5 April 1993 on unfair terms in consumer contracts (OJ L 95, 21.4.1993, p. 29).\n(11)Regulation (EC) No 1338/2008 of the European Parliament and of the Council of 16 December 2008 on Community statistics on public health and health and safety at work (OJ L 354, 31.12.2008, p. 70).\n(12)Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by Member States of the Commission\u0026rsquo;s exercise of implementing powers (OJ L 55, 28.2.2011, p.13).\n(13)Regulation (EU) No 1215/2012 of the European Parliament and of the Council of 12 December 2012 on jurisdiction and the recognition and enforcement of judgments in civil and commercial matters (OJ L 351, 20.12.2012, p. 1).\n(14)Directive 2003/98/EC of the European Parliament and of the Council of 17 November 2003 on the re-use of public sector information (OJ L 345, 31.12.2003, p. 90).\n(15)Regulation (EU) No 536/2014 of the European Parliament and of the Council of 16 April 2014 on clinical trials on medicinal products for human use, and repealing Directive 2001/20/EC (OJ L 158, 27.5.2014, p. 1).\n(16)Regulation (EC) No 223/2009 of the European Parliament and of the Council of 11 March 2009 on European statistics and repealing Regulation (EC, Euratom) No 1101/2008 of the European Parliament and of the Council on the transmission of data subject to statistical confidentiality to the Statistical Office of the European Communities, Council Regulation (EC) No 322/97 on Community Statistics, and Council Decision 89/382/EEC, Euratom establishing a Committee on the Statistical Programmes of the European Communities (OJ L 87, 31.3.2009, p. 164).\n(17)OJ C 192, 30.6.2012, p. 7.\n(18)Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ L 201, 31.7.2002, p. 37).\n(19)Directive (EU) 2015/1535 of the European Parliament and of the Council of 9 September 2015 laying down a procedure for the provision of information in the field of technical regulations and of rules on Information Society services (OJ L 241, 17.9.2015, p.1).\n(20)Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 setting out the requirements for accreditation and market surveillance relating to the marketing of products and repealing Regulation (EEC) No 339/93 (OJ L 218, 13.8.2008, p.30).\n(21)Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).\n","permalink":"https://ai.intlaws.com/en/compliance/eu/gdpr/","summary":"Official English text of Regulation (EU) 2016/679 (General Data Protection Regulation), as published in the Official Journal: 11 chapters, 99 articles and 173 recitals. The authentic languages of EU law are the official EU languages; there is no official Chinese text.","title":"General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679"},{"content":" Source: legislation.gov.uk (The National Archives), Data (Use and Access) Act 2025, Part 5\nOfficial link: https://www.legislation.gov.uk/ukpga/2025/18/part/5 Note: English original text. 本页为官方英文原文;中文译本整理中,发布后将在此链接。\nStructure: Chapter 1 — Data protection(第 66–108 条);Chapter 2 — PEC Regulations(第 109–116 条)\nPart 5 U.K.Data protection and privacy\nChapter 1 U.K.Data protection Terms used in this Chapter U.K. 66 The 2018 Act and the UK GDPR U.K. In this Chapter—\n“the 2018 Act” means the Data Protection Act 2018;\n“” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.\nCommencement Information\nDefinitions in the UK GDPR and the 2018 Act U.K. 67 Meaning of research and statistical purposes U.K. (1)In Article 4 of the UK GDPR (definitions)—\n(a)the existing text becomes paragraph 1, and\n(b)after that paragraph insert—\n“2.References in this Regulation to the processing of personal data for the purposes of scientific research (including references to processing for “scientific research purposes”) are references to processing for the purposes of any research that can reasonably be described as scientific, whether publicly or privately funded and whether carried out as a commercial or non-commercial activity.\n3.Such references—\n(a)include processing for the purposes of technological development or demonstration, fundamental research or applied research, so far as those activities can reasonably be described as scientific, but\n(b)only include processing for the purposes of a study in the area of public health that can reasonably be described as scientific where the study is conducted in the public interest.\n4.References in this Regulation to the processing of personal data for the purposes of historical research (including references to processing for “historical research purposes”) include processing for the purposes of genealogical research.\n5.References in this Regulation to the processing of personal data for statistical purposes are references to processing for statistical surveys or for the production of statistical results where—\n(a)the information that results from the processing is aggregate data that is not personal data, and\n(b)the controller does not use the personal data processed, or the information that results from the processing, in support of measures or decisions with respect to a particular data subject to whom the personal data relates.”\n(2)In consequence of the amendment made by subsection (1)(a), in section 6 of the 2018 Act (meaning of “controller”), for “4(7)” substitute “4(1)(7)”.\nCommencement Information\n68 Consent to processing for the purposes of scientific research U.K. (1)Article 4 of the UK GDPR (definitions) is amended as follows.\n(2)In point (11) of paragraph 1 (definition of “consent”), at the end insert “(and see paragraphs 6 and 7 of this Article)”.\n(3)After paragraph 5 (inserted by section 67 of this Act) insert—\n“6.A data subject’s consent is to be treated as falling within the definition of “consent” in point (11) of paragraph 1 if—\n(a)it does not fall within that definition because (and only because) the consent is given to the processing of personal data for the purposes of an area of scientific research,\n(b)at the time the consent is sought, it is not possible to identify fully the purposes for which personal data is to be processed,\n(c)seeking consent in relation to the area of scientific research is consistent with generally recognised ethical standards relevant to the area of research, and\n(d)so far as the intended purposes of the processing allow, the data subject is given the opportunity to consent only to processing for part of the research.\n7.References in this Regulation to consent given for a specific purpose (however expressed) include consent described in paragraph 6.”\nCommencement Information\n69 Consent to law enforcement processing U.K. (1)The 2018 Act is amended as follows.\n(2)In section 33 (definitions), after subsection (1) insert—\n“(1A)“Consent” of the data subject to the processing of personal data means a freely given, specific, informed and unambiguous indication of the data subject’s wishes by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of the personal data (and see section 40A).”\n(3)In section 34(2) (overview of Chapter 2 of Part 3), after paragraph (a) (but before the “and” at the end of that paragraph) insert—\n“(aa)section 40A makes provision about processing carried out in reliance on the consent of the data subject,”.\n(4)After section 40 insert—\n“40A Conditions for consent (1)This section is about processing of personal data that is carried out in reliance on the consent of the data subject.\n(2)The controller must be able to demonstrate that the data subject consented to the processing.\n(3)If the data subject’s consent is given in writing as part of a document which also concerns other matters, the request for consent must be made—\n(a)in a manner which clearly distinguishes the request from the other matters,\n(b)in an intelligible and easily accessible form, and\n(c)in clear and plain language.\n(4)Any part of a document described in subsection (3) which constitutes an infringement of this Part is not binding.\n(5)The data subject may withdraw the consent at any time (but the withdrawal of consent does not affect the lawfulness of processing in reliance on the consent before its withdrawal).\n(6)Processing may only be carried out in reliance on consent if—\n(a)before the consent is given, the controller or processor informs the data subject of the right to withdraw it, and\n(b)it is as easy for the data subject to withdraw the consent as to give it.\n(7)When assessing whether consent is freely given, account must be taken of, among other things, whether the provision of a service is conditional on consent to the processing of personal data that is not necessary for the provision of that service.”\n(5)In section 206 (index of defined expressions), in the Table, in the entry for “consent”—\n(a)after “consent” insert “(to processing of personal data)”,\n(b)for “Part” substitute “Parts 3 and”, and\n(c)for “section” substitute “sections 33, 40A and”.\nCommencement Information\nData protection principles U.K. 70 Lawfulness of processing U.K. (1)The UK GDPR is amended in accordance with subsections (2) to (5).\n(2)In Article 6(1) (lawful processing)—\n(a)in point (e)—\n(i)after “task” insert “of the controller”, and\n(ii)after “or” insert “a task carried out”,\n(b)after that point insert—\n“(ea)processing is necessary for the purposes of a recognised legitimate interest;”, and\n(c)in the words after point (f), for “Point (f)” substitute “Points (ea) and (f)”.\n(3)In Article 6(3) (basis for processing etc), in the last subparagraph, in the first sentence—\n(a)after “task” insert “of the controller”, and\n(b)after “interest or” insert “a task carried out”.\n(4)In Article 6, at the end insert—\n“5.For the purposes of paragraph 1(ea), processing is necessary for the purposes of a recognised legitimate interest only if it meets a condition in Annex 1.\n6.The Secretary of State may by regulations amend Annex 1 by—\n(a)adding or varying provisions, or\n(b)omitting provisions added by regulations made under this paragraph.\n7.The Secretary of State may only make regulations under paragraph 6 where—\n(a)the requirement in paragraph 8 is satisfied, and\n(b)if the regulations add a case to Annex 1, the requirement in paragraph 9 is also satisfied.\n8.The requirement in this paragraph is that the Secretary of State considers it appropriate to make the regulations having regard to, among other things—\n(a)the interests and fundamental rights and freedoms of data subjects which require protection of personal data, and\n(b)where relevant, the fact that children merit specific protection with regard to their personal data because they may be less aware of the risks and consequences associated with processing of personal data and of their rights in relation to such processing.\n9.The requirement in this paragraph is that the Secretary of State considers that processing in the case to be added to Annex 1 is necessary to safeguard an objective listed in Article 23(1)(c) to (j).\n10.Regulations under paragraph 6 are subject to the affirmative resolution procedure.\n11.For the purposes of paragraph 1(f), examples of types of processing that may be processing that is necessary for the purposes of a legitimate interest include—\n(a)processing that is necessary for the purposes of direct marketing,\n(b)intra-group transmission of personal data (whether relating to clients, employees or other individuals) where that is necessary for internal administrative purposes, and\n(c)processing that is necessary for the purposes of ensuring the security of network and information systems.\n12.In paragraph 11—\n“intra-group transmission” means transmission between members of a group of undertakings or between members of a group of institutions affiliated to a central body;\n“security of network and information systems” has the same meaning as in the Network and Information Systems Regulations 2018 (S.I. 2018/506 ) (see regulation 1(3)(g)).”\n(5)In Article 21(1) (right to object), after “point (e)” insert “, (ea)”.\n(6)Schedule 4 to this Act inserts Annex 1 to the UK GDPR.\n(7)In section 8 of the 2018 Act (lawfulness of processing: public interest etc), omit “the controller’s”.\n(8)In the provisions listed in subsection (9)—\n(a)for “gateway” substitute “gateways”, and\n(b)for “were omitted” substitute “disapplied only the gateway in point (ea) (recognised legitimate interests)”.\n(9)The provisions are—\n(a)section 40(8) of the Freedom of Information Act 2000 (personal data which is exempt information);\n(b)section 38(5A) of the Freedom of Information (Scotland) Act 2002 (asp 13) (personal data which is exempt information);\n(c)regulation 13(6) of the Environmental Information Regulations 2004 (S.I. 2004/3391 ) (restriction on disclosure of personal data);\n(d)regulation 11(7) of the Environmental Information (Scotland) Regulations 2004 (S.S.I. 2004/520 ) (restriction on disclosure of personal data);\n(e)regulation 45(1E) of the Civil Contingencies Act 2004 (Contingency Planning) Regulations 2005 (S.I. 2005/2042 ) (personal data which is sensitive information);\n(f)regulation 39(1E) of the Civil Contingencies Act 2004 (Contingency Planning) (Scotland) Regulations 2005 (S.S.I. 2005/494 ) (personal data which is sensitive information);\n(g)regulation 9(9) of the INSPIRE Regulations 2009 (S.I. 2009/3157 ) (limitation of public access to personal data included in a spatial data set);\n(h)regulation 10(8) of the INSPIRE (Scotland) Regulations 2009 (S.S.I. 2009/440 ) (limitation of public access to personal data included in a spatial data set).\nCommencement Information\n71 The purpose limitation U.K. (1)The UK GDPR is amended in accordance with subsections (2) to (5).\n(2)In Article 5(1)(b) (purpose limitation)—\n(a)after “collected” insert “(whether from the data subject or otherwise)”,\n(b)after “further processed” insert “by or on behalf of a controller”, and\n(c)for the words from “those purposes;” to “initial purposes” substitute “the purposes for which the controller collected the data”.\n(3)In Article 5, at the end insert—\n“3.For the avoidance of doubt, processing is not lawful by virtue only of being processing in a manner that is compatible with the purposes for which the personal data was collected.”\n(4)In Article 6 (lawfulness of processing), omit paragraph 4.\n(5)After Article 8 insert—\n“Article 8A Purpose limitation: further processing 1.This Article is about the determination, for the purposes of Article 5(1)(b) (purpose limitation), of whether processing of personal data by or on behalf of a controller for a purpose (a “new purpose”) other than the purpose for which the controller collected the data (“the original purpose”) is processing in a manner compatible with the original purpose.\n2.In making the determination, a person must take into account, among other things—\n(a)any link between the original purpose and the new purpose;\n(b)the context in which the personal data was collected, including the relationship between the data subject and the controller;\n(c)the nature of the processing, including whether it is processing described in Article 9(1) (processing of special categories of personal data) or Article 10(1) (processing of personal data relating to criminal convictions etc);\n(d)the possible consequences of the intended processing for data subjects;\n(e)the existence of appropriate safeguards (for example, encryption or pseudonymisation).\n3.Processing of personal data for a new purpose is to be treated as processing in a manner compatible with the original purpose where—\n(a)the data subject consents to the processing of personal data for the new purpose and the new purpose is specified, explicit and legitimate,\n(b)the processing is carried out in accordance with Article 84B—\n(i)for the purposes of scientific research or historical research,\n(ii)for the purposes of archiving in the public interest, or\n(iii)for statistical purposes,\n(c)the processing is carried out for the purposes of ensuring that processing of personal data complies with Article 5(1) or demonstrating that it does so,\n(d)the processing meets a condition in Annex 2, or\n(e)the processing is necessary to safeguard an objective listed in Article 23(1)(c) to (j) and is authorised by an enactment or rule of law.\n4.Where the controller collected the personal data based on Article 6(1)(a) (data subject’s consent), processing for a new purpose is only processing in a manner compatible with the original purpose if—\n(a)it falls within paragraph 3(a) or (c), or\n(b)it falls within paragraph 3(d) or (e) and the controller cannot reasonably be expected to obtain the data subject’s consent.\n5.The Secretary of State may by regulations amend Annex 2 by—\n(a)adding or varying provisions, or\n(b)omitting provisions added by regulations made under this paragraph.\n6.The Secretary of State may only make regulations under paragraph 5 adding a case to Annex 2 where the Secretary of State considers that processing in that case is necessary to safeguard an objective listed in Article 23(1)(c) to (j).\n7.Regulations under paragraph 5 may make provision identifying processing by any means, including by reference to the controller, the data subject, the personal data or the provision of Article 6(1) relied on for the purposes of the processing.\n8.Regulations under paragraph 5 are subject to the affirmative resolution procedure.”\n(6)Schedule 5 to this Act inserts Annex 2 to the UK GDPR.\n(7)The 2018 Act is amended in accordance with subsections (8) to (10).\n(8)In section 36(1) (the second data protection principle)—\n(a)in paragraph (a), for “on any occasion” substitute “(whether from the data subject or otherwise)”, and\n(b)in paragraph (b)—\n(i)after “processed” insert “by or on behalf of a controller”, and\n(ii)for “it was collected” substitute “the controller collected it”.\n(9)In section 87(1) (the second data protection principle)—\n(a)in paragraph (a), for “on any occasion” substitute “(whether from the data subject or otherwise)”, and\n(b)in paragraph (b)—\n(i)after “processed” insert “by or on behalf of a controller”, and\n(ii)for “it was collected” substitute “the controller collected it”.\n(10)In paragraph 1 of Schedule 2 (exemptions etc from the UK GDPR: provisions to be adapted or restricted), omit sub-paragraph (b)(ii).\nCommencement Information\n72 Processing in reliance on relevant international law U.K. (1)The UK GDPR is amended in accordance with subsections (2) to (5).\n(2)In Article 6(3) (lawfulness of processing: basis in domestic law)—\n(a)in the first subparagraph, omit “and (e)”,\n(b)after that subparagraph insert—\n“The basis for the processing referred to in point (e) of paragraph 1 must be laid down by domestic law or relevant international law (see section 9A of the 2018 Act).”, and\n(c)in the last subparagraph, in the last sentence, after “domestic law” insert “or relevant international law”.\n(3)In Article 8A(3)(e) (purpose limitation: further processing necessary to safeguard an objective listed in Article 23(1)) (inserted by section 71 of this Act), at the end insert “or by relevant international law (see section 9A of the 2018 Act)”.\n(4)In Article 9 (processing of special categories of personal data)—\n(a)in paragraph 2(g) (substantial public interest), after “domestic law” insert “, or relevant international law,”, and\n(b)in paragraph 5, before point (a) insert—\n“(za)section 9A makes provision about when the requirement in paragraph 2(g) of this Article for a basis in relevant international law is met;”.\n(5)In Article 10 (processing of personal data relating to criminal convictions and offences)—\n(a)in paragraph 1, after “domestic law” insert “, or relevant international law,”, and\n(b)in paragraph 2, before point (a) insert—\n“(za)section 9A makes provision about when the requirement in paragraph 1 of this Article for authorisation by relevant international law is met;”.\n(6)The 2018 Act is amended in accordance with subsections (7) and (8).\n(7)Before section 10 (and the italic heading before that section) insert—\n“Relevant international law U.K. 9A Processing in reliance on relevant international law (1)Processing of personal data meets the requirement in Article 6(3), 8A(3)(e), 9(2)(g) or 10(1) of the UK GDPR for a basis in, or authorisation by, relevant international law only if it meets a condition in Schedule A1.\n(2)A condition in Schedule A1 may be relied on for the purposes of any of those provisions, unless that Schedule provides otherwise.\n(3)The Secretary of State may by regulations amend Schedule A1 by adding, varying or omitting—\n(a)conditions,\n(b)provision about the purposes for which a condition may be relied on, and\n(c)safeguards in connection with processing carried out in reliance on a condition in the Schedule.\n(4)Regulations under this section may only add a condition relating entirely or partly to a treaty ratified by the United Kingdom.\n(5)Regulations under this section are subject to the affirmative resolution procedure.\n(6)In this section, “treaty” and “ratified” have the same meaning as in Part 2 of the Constitutional Reform and Governance Act 2010 (see section 25 of that Act).”\n(8)Before Schedule 1 insert—\nSection 9A\n“Schedule A1 U.K.Processing in reliance on relevant international law This condition is met where the processing is necessary for the purposes of responding to a request made in accordance with the Agreement between the Government of the United Kingdom of Great Britain and Northern Ireland and the Government of the United States of America on Access to Electronic Data for the Purpose of Countering Serious Crime, signed on 3 October 2019.”\nCommencement Information\nProcessing of special categories of personal data U.K. 73 Elected representatives responding to requests U.K. In paragraph 23 of Schedule 1 to the 2018 Act (processing of special categories of personal data: elected representatives responding to requests), in sub-paragraph (4), for “fourth day after” substitute “period of 30 days beginning with the day after”.\nCommencement Information\n74 Processing of special categories of personal data U.K. (1)In Chapter 2 of the UK GDPR, after Article 11 insert—\n“Article 11A Further provision about processing of special categories of personal data 1.The Secretary of State may by regulations—\n(a)make provision so that an additional description of processing of personal data is subject to the prohibition in Article 9(1),\n(b)make provision so that added processing is not subject to that prohibition,\n(c)make provision so that an exception in Article 9(2) may or may not be relied on in connection with added processing, and\n(d)make provision varying such an exception as it applies in connection with added processing.\n2.In paragraph 1, “added processing” means a description of processing which is subject to the prohibition in Article 9(1) by virtue of provision made under paragraph 1(a).\n3.Regulations made under this Article (in reliance on Article 91A(4)(b)) may amend section 5, 205 or 206 of the 2018 Act (interpretation).\n4.Regulations under this Article are subject to the affirmative resolution procedure.”\n(2)The 2018 Act is amended in accordance with subsections (3) to (9).\n(3)In section 33 (definitions of expressions used in Part 3), after subsection (6) insert—\n“(6A)“Sensitive processing” has the meaning given in section 35(8).”\n(4)In section 35 (the first data protection principle)—\n(a)in subsection (6)(b) (power to omit conditions added to Schedule 8 by regulations), after “by”, in the first place it occurs, insert “varying or”, and\n(b)in subsection (8) (definition of “sensitive processing”), for “section” substitute “Part”.\n(5)After section 42 insert—\n“42A Further provision about sensitive processing (1)The Secretary of State may by regulations—\n(a)make provision so that an additional description of processing of personal data is sensitive processing for the purposes of this Part,\n(b)make provision so that added processing is not sensitive processing for the purposes of this Part,\n(c)make provision so that a protected condition in Schedule 8 may or may not be relied on in connection with added processing, and\n(d)make provision varying such a condition as it relates to added processing.\n(2)In subsection (1)—\n“added processing” means a description of processing which is sensitive processing by virtue of provision made under subsection (1)(a);\n“protected condition in Schedule 8” means a condition in that Schedule other than one that was added to the Schedule by regulations under section 35(6).\n(3)Regulations under this section may amend this Part and sections 205 and 206.\n(4)Regulations under this section are subject to the affirmative resolution procedure.”\n(6)In section 84 (definitions of expressions used in Part 4), after subsection (6) insert—\n“(6A)“Sensitive processing” has the meaning given in section 86(7).”\n(7)In section 86 (the first data protection principle)—\n(a)in subsection (3)(b) (power to omit conditions added to Schedule 10 by regulations), after “by”, in the first place it occurs, insert “varying or”, and\n(b)in subsection (7) (definition of “sensitive processing”), for “section” substitute “Part”.\n(8)After section 91 insert—\n“91A Further provision about sensitive processing (1)The Secretary of State may by regulations—\n(a)make provision so that an additional description of processing of personal data is sensitive processing for the purposes of this Part,\n(b)make provision so that added processing is not sensitive processing for the purposes of this Part,\n(c)make provision so that a protected condition in Schedule 10 may or may not be relied on in connection with added processing, and\n(d)make provision varying such a condition as it relates to added processing.\n(2)In subsection (1)—\n“added processing” means a description of processing which is sensitive processing by virtue of provision made under subsection (1)(a);\n“protected condition in Schedule 10” means a condition in that Schedule other than one that was added to the Schedule by regulations under section 86(3).\n(3)Regulations under this section may amend this Part and sections 205 and 206.\n(4)Regulations under this section are subject to the affirmative resolution procedure.”\n(9)In section 206 (index of defined expressions), in the Table, at the appropriate place insert—\n“sensitive processing (in Parts 3 and 4)sections 35 and 86”.\n(10)The Investigatory Powers Act 2016 is amended in accordance with subsections (11) to (13).\n(11)In section 202(4) (restrictions on use of class BPD warrants: definitions), omit the definition of “sensitive personal data” and insert—\n““sensitive personal data” means personal data whose retention, or (as appropriate) retention and examination, would be sensitive processing;\n“sensitive processing” means—\n(a)\nprocessing of personal data relating to a living individual that is processing of a kind described in section 86(7)(a) to (e) of the Data Protection Act 2018, or (b)\nprocessing of personal data relating to a deceased individual that would be that kind of processing if the personal data related to a living individual.”\n(12)After that section insert—\n“202A Further provision about sensitive processing (1)The Secretary of State may by regulations—\n(a)make provision so that a description of Part 4 sensitive processing, or of processing that would be such processing if the information processed related to a living individual, is sensitive processing for the purposes of section 202, and\n(b)make provision so that added processing is not sensitive processing for the purposes of that section.\n(2)In this section—\n“added processing” means a description of processing that is sensitive processing for the purposes of section 202 by virtue of provision made under subsection (1)(a);\n“Part 4 sensitive processing” means processing of personal data that, at the time the regulations are made, is sensitive processing for the purposes of Part 4 of the Data Protection Act 2018 by virtue of regulations made under section 91A of that Act.\n(3)Regulations under this section may amend section 202.”\n(13)In section 267(3) (regulations subject to the affirmative procedure), after paragraph (e) insert—\n“(ea)section 202A,”.\nCommencement Information\nData subject’s rights U.K. 75 Fees and reasons for responses to data subjects’ requests about law enforcement processing U.K. (1)The 2018 Act is amended as follows.\n(2)In section 53 (manifestly unfounded or excessive requests by the data subject under Part 3)—\n(a)after subsection (4) insert—\n“(4A)The Secretary of State may by regulations—\n(a)require controllers of a description specified in the regulations to produce and publish guidance about the fees that they charge in accordance with subsection (1)(a), and\n(b)specify what the guidance must include.”,\n(b)in subsection (5), for “subsection (4)” substitute “this section”, and\n(c)after subsection (5) insert—\n“(6)If, in reliance on subsection (1)(b), the controller does not take action on the request, the controller must inform the data subject of—\n(a)the reasons for not doing so, and\n(b)the data subject’s right to lodge a complaint with the Commissioner.\n(7)The controller must comply with subsection (6)—\n(a)without undue delay, and\n(b)in any event, before the end of the applicable time period (as to which see section 54).”\n(3)In section 54(1) (meaning of “applicable time period”), for “and 48(2)(b)” substitute “, 48(2)(b) and 53(7)”.\nCommencement Information\n76 Time limits for responding to data subjects’ requests U.K. (1)The UK GDPR is amended in accordance with subsections (2) and (3).\n(2)In Article 12 (transparent information, communication and modalities for the exercise of rights of the data subject)—\n(a)in paragraph 3—\n(i)for “within one month of receipt of the request” substitute “before the end of the applicable time period (see Article 12A)”, and\n(ii)omit the second and third sentences,\n(b)in paragraph 4, for “without delay and at the latest within one month of receipt of the request” substitute “without undue delay, and in any event before the end of the applicable time period (see Article 12A),”, and\n(c)in paragraph 6—\n(i)after “may” insert “—\n(a)”, and\n(ii)at the end insert “, and\n(b)delay dealing with the request until the identity is confirmed.”\n(3)After Article 12 insert—\n“Article 12A Meaning of “applicable time period” 1.In Article 12, “the applicable time period” means the period of one month beginning with the relevant time, subject to paragraph 3.\n2.“The relevant time” means the latest of the following—\n(a)when the controller receives the request in question;\n(b)when the controller receives the information (if any) requested in connection with a request under Article 12(6);\n(c)when the fee (if any) charged in connection with the request under Article 12(5) is paid.\n3.The controller may, by giving notice to the data subject, extend the applicable time period by two further months where that is necessary by reason of—\n(a)the complexity of requests made by the data subject, or\n(b)the number of such requests.\n4.A notice under paragraph 3 must—\n(a)be given before the end of the period of one month beginning with the relevant time, and\n(b)state the reasons for the delay.\n5.Where the controller reasonably requires further information in order to identify the information or processing activities to which a request under Article 15 relates—\n(a)the controller may ask the data subject to provide the further information, and\n(b)the period beginning with the day on which the controller makes the request and ending with the day on which the controller receives the information does not count towards—\n(i)the applicable time period, or\n(ii)the period described in paragraph 4(a).\n6.An example of a case in which a controller may reasonably require further information is where the controller processes a large amount of information concerning the data subject.”\n(4)The 2018 Act is amended in accordance with subsections (5) to (7).\n(5)In section 45(5) (right of access by the data subject), after “delay” insert “and in any event before the end of the applicable time period (as to which see section 54)”.\n(6)In section 54 (meaning of “applicable time period” for responding to data subjects’ requests)—\n(a)in subsection (1), after “45(3)(b)” insert “and (5)”,\n(b)in subsection (2)—\n(i)for “1 month, or such longer period as may be specified in regulations,” substitute “one month”, and\n(ii)at the end insert “, subject to subsection (3A)”,\n(c)after subsection (3) insert—\n“(3A)The controller may, by giving notice to the data subject, extend the applicable time period by two further months where that is necessary by reason of—\n(a)the complexity of requests made by the data subject, or\n(b)the number of such requests.\n(3B)A notice under subsection (3A) must—\n(a)be given before the end of the period of one month beginning with the relevant time, and\n(b)state the reasons for the delay.\n(3C)Where the controller reasonably requires further information in order to identify the information or processing activities to which a request under section 45(1) relates—\n(a)the controller may ask the data subject to provide the further information, and\n(b)the period beginning with the day on which the controller makes the request and ending with the day on which the controller receives the information does not count towards—\n(i)the applicable time period, or\n(ii)the period described in subsection (3B)(a).\n(3D)An example of a case in which a controller may reasonably require further information is where the controller processes a large amount of information concerning the data subject.”, and\n(d)omit subsections (4) to (6).\n(7)In section 94 (right of access under Part 4)—\n(a)in subsection (14), for the definition of “the applicable time period” substitute—\n““the applicable time period” means the period of one month beginning with the relevant time, subject to subsection (14A);”, and (b)after subsection (14) insert—\n“(14A)The controller may, by giving notice to the data subject, extend the applicable time period by two further months where that is necessary by reason of—\n(a)the complexity of requests made by the data subject, or\n(b)the number of such requests.\n(14B)A notice under subsection (14A) must—\n(a)be given before the end of the period of one month beginning with the relevant time, and\n(b)state the reasons for the delay.”\nCommencement Information\n77 Information to be provided to data subjects U.K. (1)In Article 13 of the UK GDPR (information to be provided where personal data is collected from the data subject)—\n(a)in paragraph 4, for “shall not apply where and insofar as” substitute “do not apply to the extent that”, and\n(b)at the end insert—\n“5.Paragraph 3 does not apply to the extent that—\n(a)the controller intends to further process the personal data—\n(i)for (and only for) the purposes of scientific or historical research, the purposes of archiving in the public interest or statistical purposes, and\n(ii)in accordance with Article 84B, and\n(b)providing the information is impossible or would involve a disproportionate effort.\n6.For the purposes of paragraph 5(b), whether providing the information would involve a disproportionate effort depends on, among other things, the number of data subjects, the age of the personal data and any appropriate safeguards applied to the processing.\n7.A controller relying on paragraph 5 must take appropriate measures to protect the data subject’s rights, freedoms and legitimate interests, including by making the information available publicly.”\n(2)In Article 14 of the UK GDPR (information to be provided where personal data is not obtained from the data subject)—\n(a)in paragraph 5—\n(i)for “shall not apply where and insofar as” substitute “do not apply to the extent that”,\n(ii)omit point (b),\n(iii)omit the “or” at the end of point (c),\n(iv)in point (d), omit “where”, and\n(v)after that point insert—\n“(e)providing the information is impossible or would involve a disproportionate effort, or\n(f)the obligation referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of the processing for which the personal data are intended.”, and\n(b)at the end insert—\n“6.For the purposes of paragraph 5(e), whether providing the information would involve a disproportionate effort depends on, among other things, the number of data subjects, the age of the personal data and any appropriate safeguards applied to the processing.\n7.A controller relying on paragraph 5(e) or (f) must take appropriate measures to protect the data subject’s rights, freedoms and legitimate interests, including by making the information available publicly.”\nCommencement Information\n78 Searches in response to data subjects’ requests U.K. (1)In Article 15 of the UK GDPR (right of access by the data subject)—\n(a)after paragraph 1 insert—\n“1A.Under paragraph 1, the data subject is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search for the personal data and other information described in that paragraph.”, and\n(b)in paragraph 3, after “processing” insert “to which the data subject is entitled under paragraph 1”.\n(2)The 2018 Act is amended in accordance with subsections (3) and (4).\n(3)In section 45 (law enforcement processing: right of access by the data subject), after subsection (2) insert—\n“(2A)Under subsection (1), the data subject is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search for the personal data and other information described in that subsection.”\n(4)In section 94 (intelligence services processing: right of access by the data subject), after subsection (2) insert—\n“(2A)Under subsection (1), the data subject is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search for the personal data and other information described in that subsection.”\n(5)The amendments made by this section are to be treated as having come into force on 1 January 2024.\nCommencement Information\n79 Data subjects’ rights to information: legal professional privilege exemption U.K. (1)The 2018 Act is amended as follows.\n(2)In section 43 (overview and scope of Chapter 3 of Part 3: rights of the data subject in connection with law enforcement processing)—\n(a)in subsection (1)(a), for “section 44” substitute “sections 44 and 45A”, and\n(b)in subsection (1)(b), for “section 45” substitute “sections 45 and 45A”.\n(3)For the italic heading before section 44 substitute—\n“Data subject’s rights to information”. (4)In the heading of section 44, omit “Information:”.\n(5)Omit the italic heading before section 45.\n(6)After that section insert—\n“45A Exemption from sections 44 and 45: legal professional privilege (1)Sections 44(2) and 45(1) do not require the controller to give the data subject—\n(a)information in respect of which a claim to legal professional privilege or, in Scotland, confidentiality of communications could be maintained in legal proceedings, or\n(b)information in respect of which a duty of confidentiality is owed by a professional legal adviser to a client of the adviser.\n(2)A controller relying on the exemption in subsection (1) must inform the data subject in writing without undue delay of—\n(a)the decision to rely on the exemption,\n(b)the reason for the decision,\n(c)the data subject’s right to make a request to the Commissioner under section 51,\n(d)the data subject’s right to lodge a complaint with the Commissioner under section 165, and\n(e)the data subject’s right to apply to a court under section 167.\n(3)Subsection (2)(a) and (b) do not apply to the extent that complying with them would—\n(a)undermine a claim described in subsection (1)(a), or\n(b)conflict with a duty described in subsection (1)(b).\n(4)The controller must—\n(a)record the reason for a decision to rely on the exemption in subsection (1), and\n(b)if requested to do so by the Commissioner, make the record available to the Commissioner.\n(5)The reference in subsection (1) to sections 44(2) and 45(1) includes sections 35 to 40 so far as their provisions correspond to the rights and obligations provided for in sections 44(2) and 45(1).”\n(7)In section 51 (exercise of rights through the Commissioner)—\n(a)in subsection (1), after paragraph (b) (but before the “or” at the end of that paragraph) insert—\n“(ba)relies on the exemption from sections 44(2) and 45(1) in section 45A (legal professional privilege),”,\n(b)in subsection (2), after paragraph (a) insert—\n“(aa)where subsection (1)(ba) applies, request the Commissioner to check that the controller was entitled to rely on the exemption;”,\n(c)in subsection (4), after paragraph (a) insert—\n“(aa)where subsection (1)(ba) applies, whether the Commissioner is satisfied that the controller was entitled to rely on the exemption;”, and\n(d)in subsection (6), after “(a)” insert “, (aa)”.\nCommencement Information\nAutomated decision-making U.K. 80 Automated decision-making U.K. (1)For Article 22 of the UK GDPR (automated individual decision-making, including profiling) substitute—\n“Section 4A U.K.Automated individual decision-making Article 22A Automated processing and significant decisions 1.For the purposes of Articles 22B and 22C—\n(a)a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision, and\n(b)a decision is a significant decision, in relation to a data subject, if—\n(i)it produces a legal effect for the data subject, or\n(ii)it has a similarly significant effect for the data subject.\n2.When considering whether there is meaningful human involvement in the taking of a decision, a person must consider, among other things, the extent to which the decision is reached by means of profiling.\nArticle 22B Restrictions on automated decision-making 1.A significant decision based entirely or partly on processing described in Article 9(1) (processing of special categories of personal data) may not be taken based solely on automated processing, unless one of the following conditions is met.\n2.The first condition is that the decision is based entirely on processing of personal data to which the data subject has given explicit consent.\n3.The second condition is that—\n(a)the decision is—\n(i)necessary for entering into, or performing, a contract between the data subject and a controller, or\n(ii)required or authorised by law, and\n(b)point (g) of Article 9(2) applies.\n4.A significant decision may not be taken based solely on automated processing if the processing of personal data carried out by, or on behalf of, the decision-maker for the purposes of the decision is carried out entirely or partly in reliance on Article 6(1)(ea).\nArticle 22C Safeguards for automated decision-making 1.Where a significant decision taken by or on behalf of a controller in relation to a data subject is—\n(a)based entirely or partly on personal data, and\n(b)based solely on automated processing,\nthe controller must ensure that safeguards for the data subject’s rights, freedoms and legitimate interests are in place which comply with paragraph 2 and any regulations under Article 22D(3).\n2.The safeguards must consist of or include measures which—\n(a)provide the data subject with information about decisions described in paragraph 1 taken in relation to the data subject;\n(b)enable the data subject to make representations about such decisions;\n(c)enable the data subject to obtain human intervention on the part of the controller in relation to such decisions;\n(d)enable the data subject to contest such decisions.\nArticle 22D Further provision about automated decision-making 1.The Secretary of State may by regulations provide that, for the purposes of Article 22A(1)(a), there is, or is not, to be taken to be meaningful human involvement in the taking of a decision in cases described in the regulations.\n2.The Secretary of State may by regulations provide that, for the purposes of Article 22A(1)(b)(ii), a description of decision is, or is not, to be taken to have a similarly significant effect for the data subject.\n3.The Secretary of State may by regulations make the following types of provision about the safeguards required under Article 22C(1)—\n(a)provision requiring the safeguards to include measures in addition to those described in Article 22C(2),\n(b)provision imposing requirements which supplement what Article 22C(2) requires the safeguards to consist of or include (including, for example, provision about how and when things described in Article 22C(2) must be done or be capable of being done), and\n(c)provision about measures which are not to be taken to satisfy one or more of points (a) to (d) of Article 22C(2).\n4.Regulations under paragraph 3 may not amend Article 22C.\n5.Regulations under this Article are subject to the affirmative resolution procedure.”\n(2)The 2018 Act is amended in accordance with subsections (3) to (5).\n(3)For sections 49 and 50 (law enforcement processing: automated individual decision-making) substitute—\n“50A Automated processing and significant decisions (1)For the purposes of sections 50B and 50C—\n(a)a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision, and\n(b)a decision is a significant decision, in relation to a data subject, if—\n(i)it produces an adverse legal effect for the data subject, or\n(ii)it has a similarly significant adverse effect for the data subject.\n(2)When considering whether there is meaningful human involvement in the taking of a decision, a person must consider, among other things, the extent to which the decision is reached by means of profiling.\n50B Restrictions on automated decision-making based on sensitive processing (1)A significant decision based entirely or partly on sensitive processing may not be taken based solely on automated processing, unless one of the following conditions is met.\n(2)The first condition is that the decision is based entirely on processing of personal data to which the data subject has given explicit consent.\n(3)The second condition is that the decision is required or authorised by law.\n50C Safeguards for automated decision-making (1)Subject to subsection (3), where a significant decision taken by or on behalf of a controller in relation to a data subject is—\n(a)based entirely or partly on personal data, and\n(b)based solely on automated processing,\nthe controller must ensure that safeguards for the data subject’s rights, freedoms and legitimate interests are in place which comply with subsection (2) and any regulations under section 50D(4).\n(2)The safeguards must consist of or include measures which—\n(a)provide the data subject with information about decisions described in subsection (1) taken in relation to the data subject;\n(b)enable the data subject to make representations about such decisions;\n(c)enable the data subject to obtain human intervention on the part of the controller in relation to such decisions;\n(d)enable the data subject to contest such decisions.\n(3)Subsections (1) and (2) do not apply in relation to a significant decision if—\n(a)exemption from those provisions is required for a reason listed in subsection (4),\n(b)the controller reconsiders the decision as soon as reasonably practicable, and\n(c)there is meaningful human involvement in the reconsideration of the decision.\n(4)Those reasons are—\n(a)to avoid obstructing an official or legal inquiry, investigation or procedure;\n(b)to avoid prejudicing the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties;\n(c)to protect public security;\n(d)to safeguard national security;\n(e)to protect the rights and freedoms of others.\n(5)When considering whether there is meaningful human involvement in the reconsideration of a decision, a person must consider, among other things, the extent to which the conclusion reached on reconsideration is reached by means of profiling.\n50D Further provision about automated decision-making (1)The Secretary of State may by regulations provide that, for the purposes of sections 50A(1)(a) and 50C(3)(c), there is, or is not, to be taken to be meaningful human involvement in the taking or reconsideration of a decision in cases described in the regulations.\n(2)The Secretary of State may by regulations provide that, for the purposes of section 50A(1)(b)(ii), a description of decision is, or is not, to be taken to have a similarly significant adverse effect for the data subject.\n(3)Regulations under subsection (1) or (2) may amend section 50A.\n(4)The Secretary of State may by regulations make the following types of provision about the safeguards required under section 50C(1)—\n(a)provision requiring the safeguards to include measures in addition to those described in section 50C(2),\n(b)provision imposing requirements which supplement what section 50C(2) requires the safeguards to consist of or include (including, for example, provision about how and when things described in section 50C(2) must be done or be capable of being done), and\n(c)provision about measures which are not to be taken to satisfy one or more of paragraphs (a) to (d) of section 50C(2).\n(5)Regulations under this section are subject to the affirmative resolution procedure.”\n(4)In section 96 (intelligence services processing: right not to be subject to automated decision-making)—\n(a)in subsection (1), for “solely on” substitute “on entirely”,\n(b)in subsection (3), after “section” insert “and section 97”, and\n(c)at the end insert—\n“(4)For the purposes of this section and section 97, a decision is based on entirely automated processing if the decision-making process does not include an opportunity for a human being to accept, reject or influence the decision.”\n(5)In section 97 (intelligence services processing: right to intervene in automated decision-making)—\n(a)in subsection (1)(a), for “solely on” substitute “on entirely”,\n(b)in subsection (4)(b), for “solely on” substitute “on entirely”, and\n(c)omit subsection (6).\n(6)Schedule 6 to this Act contains minor and consequential amendments.\nCommencement Information\nObligations of controllers U.K. 81 Data protection by design: children’s higher protection matters U.K. (1)Article 25 of the UK GDPR (data protection by design and by default) is amended as follows.\n(2)After paragraph 1 insert—\n“1A.In the case of processing carried out in the course of providing information society services which are likely to be accessed by children, when assessing what are appropriate technical and organisational measures in accordance with paragraph 1, the controller must take into account the children’s higher protection matters.\n1B.The children’s higher protection matters are—\n(a)how children can best be protected and supported when using the services, and\n(b)the fact that children—\n(i)merit specific protection with regard to their personal data because they may be less aware of the risks and consequences associated with processing of personal data and of their rights in relation to such processing, and\n(ii)have different needs at different ages and at different stages of development.”\n(3)In paragraph 3, for “1 and 2” substitute “1 to 2”.\n(4)At the end insert—\n“4.Paragraphs 1A and 1B are not to be read as implying anything about the matters that may be relevant to the assessment of what are appropriate technical and organisational measures for the purposes of paragraph 1 in cases other than those described in paragraph 1A.\n5.In this Article, “information society services” does not include preventive or counselling services.”\nCommencement Information\nLogging of law enforcement processing U.K. 82 Logging of law enforcement processing U.K. In section 62 of the 2018 Act (logging of law enforcement processing)—\n(a)in subsection (2)(a), omit “justification for, and”, and\n(b)in subsection (3)(a), omit “justification for, and”.\nCommencement Information\nCodes of conduct U.K. 83 General processing and codes of conduct U.K. In Article 41 of the UK GDPR (monitoring of approved codes of conduct)—\n(a)in paragraph 4, omit the words from “, including suspension” to the end, and\n(b)after that paragraph insert—\n“4A.If the action taken by a body under paragraph 4 consists of suspending or excluding a controller or processor from the code, the body must inform the Commissioner, giving reasons for taking that action.”\nCommencement Information\n84 Law enforcement processing and codes of conduct U.K. (1)The 2018 Act is amended as follows.\n(2)In section 55(1) (overview and scope of provisions about controllers and processors), at the end insert—\n“(e)makes provision about codes of conduct (see section 71A).”\n(3)In section 56 (general obligations of the controller), at the end insert—\n“(4)Adherence to a code of conduct approved under section 71A may be used by a controller as a means of demonstrating compliance with the requirements of this Part.”\n(4)In section 59 (processors), after subsection (7) insert—\n“(7A)Adherence to a code of conduct approved under section 71A may be used by a processor as a means of demonstrating sufficient guarantees as described in subsection (2).”\n(5)In section 66 (security of processing), at the end insert—\n“(3)Adherence to a code of conduct approved under section 71A may be used by a controller or processor as a means of demonstrating compliance with subsection (1).”\n(6)After section 71 insert—\n“Codes of conduct U.K. 71A Codes of conduct (1)The Commissioner must encourage expert public bodies to produce codes of conduct intended to contribute to compliance with this Part.\n(2)Under subsection (1), the Commissioner must, among other things, encourage the production of codes which take account of the specific features of the various processing sectors.\n(3)For the purposes of this section—\n(a)“public body” means a body or other person whose functions are, or include, functions of a public nature, and\n(b)a public body is “expert” if, in the Commissioner’s opinion, the body has the knowledge and experience needed to produce a code of conduct described in subsection (1).\n(4)A code of conduct described in subsection (1) may, for example, make provision with regard to—\n(a)lawful and fair processing;\n(b)the collection of personal data;\n(c)the information provided to the public and to data subjects;\n(d)the exercise of the rights of data subjects;\n(e)the measures and procedures referred to in sections 56, 57 and 62;\n(f)the notification of personal data breaches to the Commissioner and the communication of personal data breaches to data subjects;\n(g)the transfer of personal data to third countries or international organisations;\n(h)out-of-court proceedings and other dispute resolution procedures for resolving disputes between controllers and data subjects with regard to processing.\n(5)The Commissioner must encourage expert public bodies to submit codes of conduct described in subsection (1) to the Commissioner in draft.\n(6)Where an expert public body does so, the Commissioner must—\n(a)provide the body with an opinion on whether the code correctly reflects the requirements of this Part,\n(b)decide whether to approve the code, and\n(c)if the code is approved, register and publish the code.\n(7)Subsections (5) and (6) apply in relation to amendments of a code of conduct that is for the time being approved under this section as they apply in relation to a code.”\nCommencement Information\nInternational transfers of personal data U.K. 85 Transfers of personal data to third countries and international organisations U.K. (1)Schedule 7 amends Chapter 5 of the UK GDPR (general processing and transfers of personal data to third countries and international organisations).\n(2)Schedule 8 amends Chapter 5 of Part 3 of the 2018 Act (law enforcement processing and transfers of personal data to third countries and international organisations).\n(3)In Schedule 9—\n(a)Part 1 contains minor and consequential amendments, and\n(b)Part 2 contains transitional provision.\nCommencement Information\nSafeguards for processing for research etc purposes U.K. 86 Safeguards for processing for research etc purposes U.K. (1)The UK GDPR is amended in accordance with subsections (2) to (4).\n(2)After Chapter 8 insert—\n“CHAPTER 8A U.K.Safeguards for processing for research, archiving or statistical purposes Article 84A Research, archives and statistics 1.This Chapter makes provision about the processing of personal data—\n(a)for the purposes of scientific research or historical research,\n(b)for the purposes of archiving in the public interest, or\n(c)for statistical purposes.\n2.Those purposes are referred to in this Chapter as “RAS purposes”.\nArticle 84B Additional requirements when processing for RAS purposes 1.Personal data may only be processed for RAS purposes if—\n(a)the processing consists of the collection of the personal data (whether from the data subject or otherwise),\n(b)the processing is carried out in order to convert the personal data into information which can be processed in a manner which does not permit the identification of a data subject, or\n(c)without the processing, the RAS purposes cannot be fulfilled.\n2.Processing of personal data for RAS purposes must be carried out subject to appropriate safeguards for the rights and freedoms of the data subject.\nArticle 84C Appropriate safeguards 1.This Article makes provision about when the requirement under Article 84B(2) for processing of personal data to be carried out subject to appropriate safeguards is satisfied.\n2.The requirement is not satisfied if the processing is likely to cause substantial damage or substantial distress to a data subject to whom the personal data relates.\n3.The requirement is not satisfied if the processing is carried out for the purposes of measures or decisions with respect to a particular data subject to whom the personal data relates, except where the purposes for which the processing is carried out include the purposes of approved medical research.\n4.The requirement is only satisfied if the safeguards include technical and organisational measures for the purpose of ensuring respect for the principle of data minimisation (see Article 5(1)(c)), such as, for example, pseudonymisation.\n5.In this Article—\n“approved medical research” means medical research carried out by a person who has approval to carry out that research from— (a)\na research ethics committee recognised or established by the Health Research Authority under Chapter 2 of Part 3 of the Care Act 2014, or (b)\na body appointed by any of the following for the purpose of assessing the ethics of research involving individuals—\n(i)\nthe Secretary of State, the Scottish Ministers, the Welsh Ministers or a Northern Ireland department; (ii)\na relevant NHS body; (iii)\nUnited Kingdom Research and Innovation or a body that is a Research Council for the purposes of the Science and Technology Act 1965; (iv)\nan institution that is a research institution for the purposes of Chapter 4A of Part 7 of the Income Tax (Earnings and Pensions) Act 2003 (see section 457 of that Act);\n“relevant NHS body” means— (a)\nan NHS trust or NHS foundation trust in England, (b)\nan NHS trust or Local Health Board in Wales, (c)\na Health Board or Special Health Board constituted under section 2 of the National Health Service (Scotland) Act 1978, (d)\nthe Common Services Agency for the Scottish Health Service, or (e)\nany of the health and social care bodies in Northern Ireland falling within paragraphs (b) to (e) of section 1(5) of the Health and Social Care (Reform) Act (Northern Ireland) 2009 (c. 1 (N.I.)) .\nArticle 84D Appropriate safeguards: further provision 1.The Secretary of State may by regulations make further provision about when the requirement for appropriate safeguards under Article 84B(2) is, or is not, satisfied.\n2.Regulations under this Article may not amend or revoke Article 84C(2), (3) or (4) (but may change the meaning of “approved medical research” for the purposes of Article 84C).\n3.Regulations under this Article are subject to the affirmative resolution procedure.”\n(3)In the heading of Chapter 9, after “relating to” insert “other”.\n(4)Omit Article 89 (safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes).\n(5)The 2018 Act is amended in accordance with subsections (6) and (7).\n(6)Omit section 19 (processing for archiving, research and statistical purposes: safeguards) and the italic heading before it.\n(7)In section 41(1) (safeguards: archiving), for “necessary” substitute “carried out”.\nCommencement Information\n87 Section 86: consequential provision U.K. (1)In the UK GDPR—\n(a)in Article 5(1)(e) (storage limitation), for “Article 89(1)” to “data subject” substitute “Article 84B”,\n(b)in Article 9(2)(j) (processing of special categories of personal data), for “in accordance with Article 89(1) (as supplemented by section 19 of the 2018 Act)” substitute “, is carried out in accordance with Article 84B and is”,\n(c)in Article 17(3)(d) (right to erasure), for “Article 89(1)” substitute “Article 84B”, and\n(d)in Article 21(6) (right to object), omit “pursuant to Article 89(1)”.\n(2)In the 2018 Act—\n(a)in section 24(4) (manual unstructured data held by FOI public authorities), after paragraph (b) insert—\n“(ba)Chapter 8A (safeguards for processing for research, archiving or statistical purposes);”,\n(b)in paragraph 4(b) of Schedule 1 (special categories of personal data and criminal convictions etc data: research etc), for “Article 89(1) of the UK GDPR (as supplemented by section 19)” substitute “Article 84B of the UK GDPR”, and\n(c)in Schedule 2 (exemptions etc from the UK GDPR)—\n(i)in paragraph 27(3)(a) (research and statistics), for “Article 89(1) of the UK GDPR (as supplemented by section 19)” substitute “Article 84B of the UK GDPR”, and\n(ii)in paragraph 28(3) (archiving), for “Article 89(1) of the UK GDPR (as supplemented by section 19)” substitute “Article 84B of the UK GDPR”.\n(3)In section 279(2) of the Mental Health (Care and Treatment) (Scotland) Act 2003 (asp 13) (information for research), for “Article 89(1) of the UK GDPR (archiving in the public interest, scientific or historical research and statistics)” substitute “Article 84A of the UK GDPR (research, archives and statistics)”.\nCommencement Information\nNational security U.K. 88 National security exemption U.K. (1)The 2018 Act is amended in accordance with subsections (2) to (10).\n(2)In section 26(2)(f) (national security and defence exemption), before sub-paragraph (i) insert—\n“(ai)Article 77 (right to lodge a complaint with the Commissioner);”.\n(3)In section 44 (controller’s general duties to provide information to data subject)—\n(a)in subsection (4), omit paragraph (d) (grounds for restricting information provided: national security),\n(b)in subsection (5), after “restricted” insert “under subsection (4)”, and\n(c)in subsection (7)(a), after “subsection (2)” insert “in reliance on subsection (4)”.\n(4)In section 45 (right of access by the data subject)—\n(a)in subsection (4), omit paragraph (d) (grounds for restricting information provided: national security),\n(b)in subsection (5), after “restricted” insert “under subsection (4)”, and\n(c)in subsection (7)(a), after “subsection (1)” insert “in reliance on subsection (4)”.\n(5)In section 48 (requests by data subject for rectification or erasure of personal data)—\n(a)in subsection (3), omit paragraph (d) (grounds for restricting information provided: national security),\n(b)in subsection (4)—\n(i)for “(1)” substitute “(1)(b)(i)”, and\n(ii)after “restricted” insert “under subsection (3)”, and\n(c)in subsection (6)(a), after “subsection (1)(b)(i)” insert “in reliance on subsection (3)”.\n(6)In section 68(7) (communication of a personal data breach to the data subject: grounds for restricting information provided), omit paragraph (d) (national security).\n(7)In Chapter 6 of Part 3 (law enforcement processing: supplementary), before section 79 insert—\n“78A National security exemption (1)A provision mentioned in subsection (2) does not apply to personal data processed for law enforcement purposes if exemption from the provision is required for the purposes of safeguarding national security.\n(2)The provisions are—\n(a)Chapter 2 of this Part (principles), except for the provisions listed in subsection (3);\n(b)Chapter 3 of this Part (rights of the data subject);\n(c)in Chapter 4 of this Part—\n(i)section 67 (notification of personal data breach to the Commissioner);\n(ii)section 68 (communication of personal data breach to the data subject);\n(d)Chapter 5 of this Part (transfers of personal data to third countries etc), except for the provisions listed in subsection (4);\n(e)in Part 5—\n(i)section 119 (inspection in accordance with international obligations);\n(ii)in Schedule 13 (other general functions of the Commissioner), paragraphs 1(1)(a) and (g) and 2;\n(f)in Part 6—\n(i)sections 142 to 154 and Schedule 15 (Commissioner’s notices and powers of entry and inspection);\n(ii)sections 170 to 173 (offences relating to personal data);\n(g)in Part 7, section 187 (representation of data subjects).\n(3)The provisions of Chapter 2 of this Part (principles) which are excepted from the list in subsection (2) are—\n(a)section 35(1) (the first data protection principle) so far as it requires processing of personal data to be lawful;\n(b)section 35(2) to (5) (lawfulness of processing and restrictions on sensitive processing);\n(c)section 42 (safeguards: sensitive processing);\n(d)Schedule 8 (conditions for sensitive processing).\n(4)The provisions of Chapter 5 of this Part (transfers of personal data to third countries etc) which are excepted from the list in subsection (2) are—\n(a)the following provisions of section 73—\n(i)subsection (1)(a) (conditions for transfer), so far as it relates to the condition in subsection (2) of that section, and subsection (2) (transfer must be necessary for a law enforcement purpose);\n(ii)subsections (1)(b), (5) and (6) (conditions for transfer of personal data originally made available by a member State);\n(b)section 78 (subsequent transfers).”\n(8)In section 79 (national security: certificate)—\n(a)omit subsections (1) to (3),\n(b)after subsection (3) insert—\n“(3A)Subject to subsection (5), a certificate signed by a Minister of the Crown certifying that exemption from all or any of the provisions listed in section 78A(2) is, or at any time was, required in relation to any personal data for the purposes of safeguarding national security is conclusive evidence of that fact.”,\n(c)in subsection (4), for “subsection (1)” substitute “subsection (3A)—\n“(a)may identify the personal data to which it applies by means of a general description, and\n(b)”,\n(d)in subsection (5), for “subsection (1)” substitute “subsection (3A)”,\n(e)in subsection (7)—\n(i)for “a restriction falls within a general description in a certificate issued under subsection (1)” substitute “a certificate under subsection (3A) which identifies the personal data to which it applies by means of a general description applies to any personal data”, and\n(ii)for “the restriction does not fall within that description” substitute “the certificate does not apply to the personal data in question”,\n(f)in subsection (8)—\n(i)for “the restriction” substitute “the certificate”, and\n(ii)for “to fall within the general description” substitute “so to apply”,\n(g)in subsection (10), for “subsection (1)” substitute “subsection (3A)”,\n(h)in subsection (11), for “subsection (1)” substitute “subsection (3A)”,\n(i)in subsection (12), for “subsection (1)” substitute “subsection (3A)”, and\n(j)omit subsection (13).\n(9)In section 110(2) (intelligence services processing: national security)—\n(a)in paragraph (a), after “Chapter 2” insert “of this Part”,\n(b)in paragraph (b), after “Chapter 3” insert “of this Part”, and\n(c)in paragraph (c), after “Chapter 4” insert “of this Part”.\n(10)In section 186(3) (data subject’s rights etc: exceptions), after paragraph (c) insert—\n“(ca)in Part 3 of this Act, section 78A, and”.\n(11)In the provisions listed in subsection (12), for “subsection (4) of that section” substitute “section 45(4) or 78A of that Act”.\n(12)The provisions are—\n(a)section 40(4A)(b) and (5B)(d) of the Freedom of Information Act 2000 (personal data which is exempt information);\n(b)section 38(3A)(b) of the Freedom of Information (Scotland) Act 2002 (asp 13) (personal data which is exempt information);\n(c)regulation 13(3A)(b) and (5B)(d) of the Environmental Information Regulations 2004 (S.I. 2004/3391 ) (restriction on disclosure of personal data);\n(d)regulation 11(4A)(b) of the Environmental Information (Scotland) Regulations 2004 (S.S.I. 2004/520 ) (restriction on disclosure of personal data);\n(e)regulation 45(1C)(b) of the Civil Contingencies Act 2004 (Contingency Planning) Regulations 2005 (S.I. 2005/2042 ) (personal data which is sensitive information);\n(f)regulation 39(1C)(b) of the Civil Contingencies Act 2004 (Contingency Planning) (Scotland) Regulations 2005 (S.S.I. 2005/494 ) (personal data which is sensitive information).\nCommencement Information\nIntelligence services U.K. 89 Joint processing by intelligence services and competent authorities U.K. (1)Part 4 of the 2018 Act (intelligence services processing) is amended as follows.\n(2)In section 82 (processing to which Part 4 applies)—\n(a)before subsection (1) insert—\n“(A1)This Part—\n(a)applies to processing of personal data by an intelligence service, and\n(b)applies to processing of personal data by a qualifying competent authority where the processing is the subject of a designation notice that is for the time being in force (see sections 82A to 82E).”,\n(b)in subsection (1)—\n(i)after “applies” insert “only”,\n(ii)in paragraph (a), for “the processing by an intelligence service” substitute “processing”, and\n(iii)in paragraph (b), for “the processing by an intelligence service” substitute “processing”,\n(c)after subsection (2) insert—\n“(2A)In this Part—\n“competent authority” has the same meaning as in Part 3;\n“qualifying competent authority” means a competent authority specified or described in regulations made by the Secretary of State.”, and\n(d)after subsection (3) insert—\n“(4)Regulations under this section are subject to the affirmative resolution procedure.”\n(3)After section 82 insert—\n“82A Designation of processing by a qualifying competent authority (1)For the purposes of this Part, the Secretary of State may give a notice designating processing of personal data by a qualifying competent authority (a “designation notice”) where—\n(a)an application for designation of the processing is made in accordance with this section, and\n(b)the Secretary of State considers that designation of the processing is required for the purposes of safeguarding national security.\n(2)The Secretary of State may only designate processing by a qualifying competent authority that is carried out by the authority as a joint controller with at least one intelligence service.\n(3)The Secretary of State may not designate processing by a qualifying competent authority that consists of the transfer of personal data to—\n(a)a country or territory outside the United Kingdom, or\n(b)an international organisation.\n(4)A designation notice must—\n(a)specify or describe the processing and qualifying competent authority that are designated, and\n(b)be given to the applicants for the designation (and see also section 82D).\n(5)An application for designation of processing of personal data by a qualifying competent authority must be made jointly by—\n(a)the qualifying competent authority, and\n(b)the intelligence service with which the processing is to be carried out.\n(6)An application may be made in respect of more than one qualifying competent authority and in respect of processing with more than one intelligence service.\n(7)The application must—\n(a)describe the processing, including the intended purposes and means of processing, and\n(b)explain why the applicants consider that designation is required for the purposes of safeguarding national security.\n(8)Before giving a designation notice, the Secretary of State must consult the Commissioner.\n(9)In this section, “joint controller”, in relation to processing of personal data, means a controller whose responsibilities for compliance with this Part in relation to the processing are determined in an arrangement under section 104.\n82B Duration of designation notice (1)A designation notice must state when it comes into force.\n(2)A designation notice ceases to be in force at the earliest of the following times—\n(a)at the end of the period of 5 years beginning when the notice comes into force;\n(b)(if relevant) at the end of a shorter period specified in the notice;\n(c)when the notice is withdrawn under section 82C.\n(3)The Secretary of State may give a further designation notice in respect of processing that is, or has been, the subject of a previous designation notice.\n82C Review and withdrawal of designation notice (1)Subsections (2) to (4) apply where processing is the subject of a designation notice for the time being in force.\n(2)A person who applied for the designation of the processing must notify the Secretary of State without undue delay if the person considers that the designation is no longer required for the purposes of safeguarding national security.\n(3)A person who applied for the designation of the processing must, on a request from the Secretary of State, provide—\n(a)a description of the processing that is being, or is intended to be, carried out in reliance on the notice, and\n(b)an explanation of why the person considers that designation of the processing continues to be required for the purposes of safeguarding national security.\n(4)The Secretary of State must at least annually—\n(a)review each designation notice that is for the time being in force, and\n(b)consider whether designation of the processing which is the subject of the notice continues to be required for the purposes of safeguarding national security.\n(5)The Secretary of State—\n(a)may withdraw a designation notice by giving a further notice (a “withdrawal notice”) to the persons who applied for the designation, and\n(b)must give a withdrawal notice if the Secretary of State considers that designation of some or all of the processing to which the notice applies is no longer required for the purposes of safeguarding national security (whether as a result of a review required under subsection (4) or otherwise).\n(6)A withdrawal notice must—\n(a)withdraw the designation notice completely, and\n(b)state when it comes into force.\n(7)In determining when a withdrawal notice required under subsection (5)(b) comes into force, the Secretary of State must consider—\n(a)the desirability of the processing ceasing to be designated as soon as possible, and\n(b)where relevant, the time needed to effect an orderly transition to new arrangements for the processing of personal data.\n82D Records of designation notices (1)Where the Secretary of State gives a designation notice—\n(a)the Secretary of State must send a copy of the notice to the Commissioner, and\n(b)the Commissioner must publish a record of the notice.\n(2)The record must contain—\n(a)the Secretary of State’s name,\n(b)the date on which the notice was given,\n(c)the date on which the notice ceases to have effect (if not previously withdrawn), and\n(d)subject to subsection (3), the rest of the text of the notice.\n(3)The Commissioner must not publish the text, or a part of the text, of the notice if—\n(a)the Secretary of State has determined that publishing the text or that part of the text—\n(i)would be against the interests of national security,\n(ii)would be contrary to the public interest, or\n(iii)might jeopardise the safety of any person, and\n(b)the Secretary of State has notified the Commissioner of that determination.\n(4)The Commissioner must keep the record of the notice available to the public while the notice is in force.\n(5)Where the Secretary of State gives a withdrawal notice, the Secretary of State must send a copy of the notice to the Commissioner.\n82E Appeal against designation notice (1)A person directly affected by a designation notice may appeal to the Tribunal against the notice.\n(2)If, on an appeal under this section, the Tribunal finds that, applying the principles applied by a court on an application for judicial review, the Secretary of State did not have reasonable grounds for giving the notice, the Tribunal may—\n(a)allow the appeal, and\n(b)quash the notice.”\nCommencement Information\n90 Joint processing: consequential amendments U.K. (1)The 2018 Act is amended in accordance with subsections (2) to (9).\n(2)In section 1(5) (overview: Part 4), at the end insert “(and certain processing carried out by competent authorities jointly with the intelligence services)”.\n(3)In section 29 (processing to which Part 3 applies), after subsection (1) insert—\n“(1A)This Part does not apply to processing to which Part 4 applies by virtue of a designation notice (see section 82A).”\n(4)In section 83 (meaning of “controller” and “processor” in Part 4)—\n(a)before subsection (1) insert—\n“(A1)For the purposes of this Part—\n(a)an intelligence service is the “controller” in relation to the processing of personal data if it satisfies subsection (1) alone or jointly with others, and\n(b)a qualifying competent authority is the “controller” in relation to the processing of personal data that is the subject of a designation notice that is for the time being in force if the authority satisfies subsection (1) jointly with others.”,\n(b)in subsection (1), for the words before paragraph (a) substitute “This subsection is satisfied by a person who—”, and\n(c)in subsection (2), for “intelligence service on which” substitute “person on whom”.\n(5)In section 84 (other definitions)—\n(a)after subsection (2) insert—\n“(2A)“Designation notice” has the meaning given in section 82A.”, and\n(b)before subsection (7) insert—\n“(6B)“Withdrawal notice” has the meaning given in section 82C.”\n(6)In section 104(1) (joint controllers), for “intelligence services” substitute “controllers”.\n(7)In section 202(1)(a)(i) (proceedings in the First-tier Tribunal: contempt) after “79,” insert “82E,”.\n(8)In section 203(1) (Tribunal Procedure Rules), after “79,” insert “82E,”.\n(9)In section 206 (index of defined expressions), in the Table—\n(a)in the entry for “competent authority”—\n(i)for “Part 3” substitute “Parts 3 and 4”, and\n(ii)for “section 30” substitute “sections 30 and 82”, and\n(b)at the appropriate places insert—\n“designation notice (in Part 4)section 84”;\n“qualifying competent authority (in Part 4)section 82”;\n“withdrawal notice (in Part 4)section 84”.\n(10)In section 199(2)(a) of the Investigatory Powers Act 2016 (bulk personal datasets: meaning of “personal data”), after “section 82(1) of that Act” insert “by an intelligence service”.\nCommencement Information\nInformation Commissioner’s role U.K. 91 Duties of the Commissioner in carrying out functions U.K. (1)The 2018 Act is amended in accordance with subsections (2) to (4).\n(2)Omit section 2(2) (duty of Commissioner when carrying out functions).\n(3)After section 120 insert—\n“Duties in carrying out functions U.K. 120A Principal objective It is the principal objective of the Commissioner, in carrying out functions under the data protection legislation—\n(a)to secure an appropriate level of protection for personal data, having regard to the interests of data subjects, controllers and others and matters of general public interest, and\n(b)to promote public trust and confidence in the processing of personal data.\n120B Duties in relation to functions under the data protection legislation In carrying out functions under the data protection legislation, the Commissioner must have regard to such of the following as appear to the Commissioner to be relevant in the circumstances—\n(a)the desirability of promoting innovation;\n(b)the desirability of promoting competition;\n(c)the importance of the prevention, investigation, detection and prosecution of criminal offences;\n(d)the need to safeguard public security and national security;\n(e)the fact that children merit specific protection with regard to their personal data because they may be less aware of the risks and consequences associated with processing of personal data and of their rights in relation to such processing.\n120C Strategy (1)The Commissioner must prepare a strategy for carrying out the Commissioner’s functions under the data protection legislation in accordance with the Commissioner’s duties under—\n(a)sections 120A and 120B,\n(b)section 108 of the Deregulation Act 2015 (exercise of regulatory functions: economic growth), and\n(c)section 21 of the Legislative and Regulatory Reform Act 2006 (exercise of regulatory functions: principles).\n(2)The Commissioner must—\n(a)review the strategy from time to time, and\n(b)revise the strategy as appropriate.\n(3)The Commissioner must publish the strategy and any revised strategy.\n120D Duty to consult other regulators (1)The Commissioner must, at such times as the Commissioner considers appropriate, consult the persons mentioned in subsection (2) about how the manner in which the Commissioner exercises functions under the data protection legislation may affect economic growth, innovation and competition.\n(2)The persons are—\n(a)such persons exercising regulatory functions as the Commissioner considers appropriate;\n(b)such other persons as the Commissioner considers appropriate.\n(3)In this section, “regulatory function” has the meaning given by section 111 of the Deregulation Act 2015.”\n(4)In section 139 (reporting to Parliament), after subsection (1) insert—\n“(1A)In connection with the Commissioner’s functions under the data protection legislation, the report must contain (among other things)—\n(a)a review of what the Commissioner has done during the reporting period to comply with the duties under—\n(i)sections 120A and 120B,\n(ii)section 108 of the Deregulation Act 2015, and\n(iii)section 21 of the Legislative and Regulatory Reform Act 2006,\nincluding a review of the operation of the strategy prepared and published under section 120C;\n(b)a review of what the Commissioner has done during the reporting period to comply with the duty under section 120D.\n(1B)In subsection (1A), “the reporting period” means the period to which the report relates.”\n(5)The Information Commissioner must prepare and publish a strategy in accordance with section 120C of the 2018 Act before the end of the period of 18 months beginning with the day on which this section comes into force.\nCommencement Information\n92 Codes of practice for the processing of personal data U.K. (1)The 2018 Act is amended in accordance with subsections (2) to (6).\n(2)After section 124 insert—\n“124A Other codes of practice (1)The Commissioner must prepare appropriate codes of practice giving guidance as to good practice in the processing of personal data if required to do so by regulations made by the Secretary of State.\n(2)Regulations under this section—\n(a)must describe the personal data or processing to which the code of practice is to relate, and\n(b)may describe the persons or classes of person to whom it is to relate.\n(3)Where a code under this section is in force, the Commissioner may prepare amendments of the code or a replacement code.\n(4)Before preparing a code or amendments under this section, the Commissioner must consult the Secretary of State and such of the following as the Commissioner considers appropriate—\n(a)trade associations;\n(b)data subjects;\n(c)persons who appear to the Commissioner to represent the interests of data subjects.\n(5)A code under this section may include transitional provision or savings.\n(6)Regulations under this section are subject to the negative resolution procedure.\n(7)In this section—\n“good practice in the processing of personal data” means such practice in the processing of personal data as appears to the Commissioner to be desirable having regard to the interests of data subjects and others, including compliance with the requirements of the data protection legislation;\n“trade association” includes a body representing controllers or processors.”\n(3)In section 125 (approval of codes prepared under sections 121 to 124)—\n(a)in the heading, for “124” substitute “124A”,\n(b)in subsection (1), for “or 124” substitute “, 124 or 124A”,\n(c)in subsection (3), for “or 124” substitute “, 124 or 124A”,\n(d)for subsection (5) substitute—\n“(5)If the Commissioner is prevented by subsection (3) from issuing a code that is not a replacement code, the Commissioner must prepare another version of the code.”, and\n(e)in subsection (9), for “or 124” substitute “, 124 or 124A”.\n(4)In section 126 (publication and review of codes issued under section 125(4)), in subsection (4), for “or 124(2)” substitute “, 124(2) or 124A(3)”.\n(5)Omit section 128 (other codes of practice).\n(6)In section 129 (consensual audits), in subsection (3), for “128” substitute “124A”.\n(7)In section 19AC of the Registration Service Act 1953 (code of practice), in subsection (11), for “128” substitute “124A”.\n(8)In the Statistics and Registration Service Act 2007—\n(a)in section 45 (information held by HMRC), in subsection (4A), for “128” substitute “124A”,\n(b)in section 45A (information held by other public authorities), in subsection (8), for “128” substitute “124A”,\n(c)in section 45E (further provisions about powers in sections 45B, 45C and 45D), in subsection (16), for “128” substitute “124A”, and\n(d)in section 53A (disclosure by the Board to devolved administrations), in subsection (9), for “128” substitute “124A”.\n(9)In the Digital Economy Act 2017—\n(a)in section 43 (code of practice), in subsection (13), for “128” substitute “124A”,\n(b)in section 52 (code of practice), in subsection (13), for “128” substitute “124A”,\n(c)in section 60 (code of practice), in subsection (13), for “128” substitute “124A”, and\n(d)in section 70 (code of practice), in subsection (15), for “128” substitute “124A”.\nCommencement Information\n93 Codes of practice: panels and impact assessments U.K. In the 2018 Act, after section 124A (inserted by section 92 of this Act) insert—\n“124B Panels to consider codes of practice (1)This section applies where a code is prepared under section 121, 122, 123, 124 or 124A, subject to subsection (11).\n(2)The Commissioner must establish a panel of individuals to consider the code.\n(3)The panel must consist of—\n(a)individuals the Commissioner considers have expertise in the subject matter of the code, and\n(b)individuals the Commissioner considers—\n(i)are likely to be affected by the code, or\n(ii)represent persons likely to be affected by the code.\n(4)Before the panel begins to consider the code, the Commissioner must—\n(a)publish the code in draft, and\n(b)publish a statement that—\n(i)states that a panel has been established to consider the code,\n(ii)identifies the members of the panel,\n(iii)explains the process by which they were selected, and\n(iv)explains the reasons for their selection.\n(5)Where at any time it appears to the Commissioner that a member of the panel is not willing or able to serve as a member of the panel, the Commissioner may select another individual to be a member of the panel.\n(6)Where the Commissioner selects an individual to be a member of the panel under subsection (5), the Commissioner must publish a statement that—\n(a)identifies the member of the panel,\n(b)explains the process by which the member was selected, and\n(c)explains the reasons for the member’s selection.\n(7)The Commissioner must make arrangements—\n(a)for the members of the panel to consider the code with one another (whether in person or otherwise), and\n(b)for the panel to prepare and submit to the Commissioner a report on the code within such reasonable period as is determined by the Commissioner.\n(8)If the panel submits to the Commissioner a report on the code within the period determined by the Commissioner, the Commissioner must as soon as reasonably practicable—\n(a)make any alterations to the code that the Commissioner considers appropriate in the light of the report, and\n(b)publish—\n(i)the code in draft,\n(ii)the report or a summary of it, and\n(iii)in a case where a recommendation in the report to alter the code has not been accepted by the Commissioner, an explanation of why it has not been accepted.\n(9)The Commissioner may pay remuneration and expenses to the members of the panel.\n(10)This section applies in relation to amendments prepared under section 121, 122, 123, 124 or 124A as it applies in relation to codes prepared under those sections, subject to subsection (11).\n(11)The Secretary of State may by regulations provide that this section does not apply, or applies with modifications, in the case of—\n(a)a code prepared under section 124A, or\n(b)an amendment of such a code,\nthat is specified or described in the regulations.\n(12)Regulations under this section are subject to the negative resolution procedure.\n124C Impact assessments for codes of practice (1)Where a code is prepared under section 121, 122, 123, 124 or 124A, the Commissioner must carry out and publish an assessment of—\n(a)who would be likely to be affected by the code, and\n(b)the effect the code would be likely to have on them.\n(2)This section applies in relation to amendments prepared under section 121, 122, 123, 124 or 124A as it applies in relation to codes prepared under those sections.”\nCommencement Information\n94 Manifestly unfounded or excessive requests to the Commissioner U.K. (1)The 2018 Act is amended in accordance with subsections (2) and (3).\n(2)In section 135 (manifestly unfounded or excessive requests made to the Commissioner)—\n(a)before subsection (1) insert—\n“(A1)This section makes provision about cases in which a request made to the Commissioner, to which the Commissioner is required or authorised to respond under the data protection legislation, is manifestly unfounded or excessive.”,\n(b)in subsection (1) omit the words from the beginning to “excessive,”,\n(c)after subsection (1) insert—\n“(1A)In subsection (1)—\n(a)the reference in paragraph (a) to charging a reasonable fee is, in a case in which section 134 is relevant, a reference to doing so under that section, and\n(b)paragraph (b) is not to be read as implying anything about whether the Commissioner may refuse to act on requests that are neither manifestly unfounded nor excessive.”,\n(d)in subsection (3), for “(1)” substitute “(A1)”,\n(e)omit subsection (4), and\n(f)after that subsection insert—\n“(5)Article 57(3) of the UK GDPR (performance of Commissioner’s tasks generally to be free of charge for data subject) has effect subject to this section.”\n(3)In section 136(1) (guidance about fees), omit paragraph (b) and the “or” before it.\n(4)In Article 57 of the UK GDPR (Commissioner’s tasks), omit paragraph 4.\nCommencement Information\n95 Analysis of performance U.K. In the 2018 Act, after section 139 insert—\n“139A Analysis of performance (1)The Commissioner must prepare and publish an analysis of the Commissioner’s performance using key performance indicators.\n(2)The analysis must be prepared and published at least annually.\n(3)In this section, “key performance indicators” means factors by reference to which the Commissioner’s performance can be measured most effectively.\nDocuments and notices”. Commencement Information\n96 Notices from the Commissioner U.K. (1)The 2018 Act is amended in accordance with subsections (2) and (3).\n(2)Omit section 141 (notices from the Commissioner).\n(3)After that section insert—\n“141A Notices from the Commissioner (1)This section applies in relation to a notice authorised or required by this Act to be given to a person by the Commissioner.\n(2)The notice may be given to the person by—\n(a)delivering it by hand to a relevant individual,\n(b)leaving it at the person’s proper address,\n(c)sending it by post to the person at that address, or\n(d)sending it by email to the person’s email address.\n(3)A “relevant individual” means—\n(a)in the case of a notice to an individual, that individual;\n(b)in the case of a notice to a body corporate (other than a partnership), an officer of that body;\n(c)in the case of a notice to a partnership, a partner in the partnership or a person who has the control or management of the partnership business;\n(d)in the case of a notice to an unincorporated body (other than a partnership), a member of its governing body.\n(4)For the purposes of subsection (2)(b) and (c), and section 7 of the Interpretation Act 1978 (services of documents by post) in its application to those provisions, a person’s proper address is—\n(a)in a case where the person has specified an address as one at which the person, or someone acting on the person’s behalf, will accept service of notices or other documents, that address;\n(b)in any other case, the address determined in accordance with subsection (5).\n(5)The address is—\n(a)in a case where the person is a body corporate with a registered office in the United Kingdom, that office;\n(b)in a case where paragraph (a) does not apply and the person is a body corporate, partnership or unincorporated body with a principal office in the United Kingdom, that office;\n(c)in any other case, an address in the United Kingdom at which the Commissioner believes, on reasonable grounds, that the notice will come to the attention of the person.\n(6)A person’s email address is—\n(a)an email address published for the time being by that person as an address for contacting that person, or\n(b)if there is no such published address, an email address by means of which the Commissioner believes, on reasonable grounds, that the notice will come to the attention of that person.\n(7)A notice sent by email is treated as given 48 hours after it was sent, unless the contrary is proved.\n(8)In this section, “officer”, in relation to a body corporate, means a director, manager, secretary or other similar officer of the body.\n(9)This section does not limit other lawful means of giving a notice.”\n(4)In Schedule 2 to the Electronic Identification and Trust Services for Electronic Transactions Regulations 2016 (S.I. 2016/696 ) (Commissioner’s enforcement powers), in paragraph 1(b), for “141” substitute “141A”.\nCommencement Information\nEnforcement U.K. 97 Power of the Commissioner to require documents U.K. (1)The 2018 Act is amended as follows.\n(2)In section 142 (information notices)—\n(a)in subsection (1)—\n(i)in paragraph (a), after “information” insert “or documents”, and\n(ii)in paragraph (b), after “information” insert “or documents”,\n(b)in subsection (2)(b), after “information” insert “or documents”,\n(c)in subsection (3)—\n(i)in paragraph (a), after “information”, in both places it occurs, insert “or documents”,\n(ii)in paragraph (b), after “information” insert “or documents”,\n(iii)in paragraph (c), after “information” insert “or documents”, and\n(iv)in paragraph (d), after “information” insert “or documents”,\n(d)in subsection (5), after “information”, in the second place it occurs, insert “or documents”,\n(e)in subsection (6), after “information”, in the second place it occurs, insert “or documents”, and\n(f)in subsection (7)—\n(i)in paragraph (a), for “is” substitute “or documents are”, and\n(ii)in the words after paragraph (b), after “information” insert “or documents”.\n(3)In section 143 (information notices: restrictions)—\n(a)in subsection (1)(b)(ii), for “is” substitute “or documents are”,\n(b)in subsection (2), after “information”, in the second place it occurs, insert “or documents”,\n(c)in subsection (3), for “in respect” substitute “or documents to the extent that requiring the person to do so would result in the disclosure”,\n(d)in subsection (4), for “in respect” substitute “or documents to the extent that requiring the person to do so would result in the disclosure”, and\n(e)in subsection (6), after “information”, in the second place it occurs, insert “or documents”.\n(4)In section 145 (information orders)—\n(a)in subsection (2)—\n(i)in paragraph (a), after “information”, in the first place it occurs, insert “or documents”, and\n(ii)in paragraph (b), after “information” insert “or documents”, and\n(b)in subsection (3)—\n(i)in paragraph (a), after “information” insert “or documents”,\n(ii)in paragraph (b), after “information” insert “or documents”, and\n(iii)in paragraph (c), after “information” insert “or documents”.\n(5)In section 148(1) (destroying or falsifying information and documents etc), in paragraph (a), after “information”, in the second place it occurs, insert “or a document”.\n(6)In section 160 (guidance about regulatory action), in subsection (3)(a), for “is” substitute “or documents are”.\n(7)In Schedule 17 (review of processing of personal data for the purposes of journalism), in paragraph 2(2) (information notices)—\n(a)in paragraph (a), for “is” substitute “or documents are”, and\n(b)in the words after paragraph (b), after “information” insert “or documents”.\nCommencement Information\n98 Power of the Commissioner to require a report U.K. (1)The 2018 Act is amended as follows.\n(2)In section 146 (assessment notices)—\n(a)in subsection (2), after paragraph (i), insert—\n“(j)make arrangements for an approved person to prepare a report on a specified matter;\n(k)provide to the Commissioner a report prepared in pursuance of such arrangements.”,\n(b)after subsection (3) insert—\n“(3A)An assessment notice that requires a controller or processor to make arrangements for an approved person to prepare a report may require the arrangements to include specified terms as to—\n(a)the preparation of the report;\n(b)the contents of the report;\n(c)the form in which the report is to be provided;\n(d)the date by which the report is to be completed.”,\n(c)after subsection (11) insert—\n“(11A)Where the Commissioner gives an assessment notice that requires the controller or processor to make arrangements for an approved person to prepare a report, the controller or processor is liable for the payment of the approved person’s remuneration and expenses under the arrangements.”, and\n(d)in subsection (12), before the definition of “domestic premises” insert—\n““approved person”, in relation to a report, means a person approved to prepare the report in accordance with section 146A;”. (3)After section 146 insert—\n“146A Assessment notices: approval of person to prepare report etc (1)This section applies where an assessment notice requires a controller or processor to make arrangements for an approved person to prepare a report.\n(2)The controller or processor must, within such period as is specified in the assessment notice, nominate to the Commissioner a person to prepare the report.\n(3)If the Commissioner is satisfied that the nominated person is a suitable person to prepare the report, the Commissioner must by written notice to the controller or processor approve the nominated person to prepare the report.\n(4)If the Commissioner is not satisfied that the nominated person is a suitable person to prepare the report, the Commissioner must by written notice to the controller or processor—\n(a)inform the controller or processor that the Commissioner has decided not to approve the nominated person to prepare the report,\n(b)inform the controller or processor of the reasons for that decision, and\n(c)approve a person who the Commissioner is satisfied is a suitable person to prepare the report to do so.\n(5)If the controller or processor does not nominate a person within the period specified in the assessment notice, the Commissioner must by written notice to the controller or processor approve a person who the Commissioner is satisfied is a suitable person to prepare the report to do so.\n(6)It is the duty of the controller or processor to give the person approved to prepare the report all such assistance as the person may reasonably require to prepare the report.”\n(4)In section 155 (penalty notices), in subsection (1)—\n(a)omit the “or” at the end of paragraph (a), and\n(b)at the end of paragraph (b) insert “, or\n(c)has failed to comply with a duty imposed on the person by section 146A(6).”\n(5)In section 160 (guidance about regulatory action), in subsection (4), after paragraph (a) insert—\n“(aa)provision specifying factors to be considered in determining whether to give an assessment notice to a person that imposes a requirement of a sort mentioned in section 146(2)(j);\n(ab)provision about the factors the Commissioner may take into account when determining the suitability of a person to prepare a report of a sort mentioned in section 146(2)(j);”.\nCommencement Information\n99 Assessment notices: removal of OFSTED restriction U.K. In section 147 of the 2018 Act (assessment notices: restrictions), in subsection (6), omit paragraph (b) and the “or” before it.\nCommencement Information\n100 Interview notices U.K. (1)The 2018 Act is amended as follows.\n(2)After section 148 insert—\n“Interview notices U.K. 148A Interview notices (1)This section applies where the Commissioner suspects that a controller or processor—\n(a)has failed or is failing as described in section 149(2), or\n(b)has committed or is committing an offence under this Act.\n(2)For the purpose of investigating the suspected failure or offence, the Commissioner may, by written notice (an “interview notice”), require an individual within subsection (3) to—\n(a)attend at a place specified in the notice, and\n(b)answer questions with respect to any matter relevant to the investigation.\n(3)An individual is within this subsection if the individual—\n(a)is the controller or processor,\n(b)is or was at any time employed by, or otherwise working for, the controller or processor, or\n(c)is or was at any time concerned in the management or control of the controller or processor.\n(4)An interview notice must specify the time at which the individual must attend at the specified place and answer questions (but see the restrictions in subsections (6) and (7)).\n(5)An interview notice must—\n(a)indicate the nature of the suspected failure or offence that is the subject of the investigation,\n(b)provide information about the consequences of failure to comply with the notice, and\n(c)provide information about the rights under sections 162 and 164 (appeals etc).\n(6)An interview notice may not require an individual to attend at the specified place and answer questions before the end of the period within which an appeal can be brought against the notice.\n(7)If an appeal is brought against an interview notice, the individual to whom the notice is given need not attend at the specified place and answer questions pending the determination or withdrawal of the appeal.\n(8)If an interview notice—\n(a)states that, in the Commissioner’s opinion, it is necessary for the individual to attend at the specified place and answer questions urgently, and\n(b)gives the Commissioner’s reasons for reaching that opinion,\nsubsections (6) and (7) do not apply but the notice must not require the individual to attend at the specified place and answer questions before the end of the period of 24 hours beginning when the notice is given.\n(9)The Commissioner may cancel or vary an interview notice by written notice to the individual to whom it was given.\n148B Interview notices: restrictions (1)An interview notice does not require an individual to answer questions to the extent that requiring the person to do so would involve an infringement of the privileges of either House of Parliament.\n(2)An interview notice does not require an individual to answer questions in respect of a communication which is made—\n(a)between a professional legal adviser and the adviser’s client, and\n(b)in connection with the giving of legal advice to the client with respect to obligations, liabilities or rights under the data protection legislation.\n(3)An interview notice does not require an individual to answer questions in respect of a communication which is made—\n(a)between a professional legal adviser and the adviser’s client or between such an adviser or client and another person,\n(b)in connection with or in contemplation of proceedings under or arising out of the data protection legislation, and\n(c)for the purposes of such proceedings.\n(4)In subsections (2) and (3), references to the client of a professional legal adviser include references to a person acting on behalf of the client.\n(5)An interview notice does not require an individual to answer questions if doing so would, by revealing evidence of the commission of an offence, expose the individual to proceedings for that offence.\n(6)The reference to an offence in subsection (5) does not include an offence under—\n(a)this Act;\n(b)section 5 of the Perjury Act 1911 (false statements made otherwise than on oath);\n(c)section 44(2) of the Criminal Law (Consolidation) (Scotland) Act 1995 (false statements made otherwise than on oath);\n(d)Article 10 of the Perjury (Northern Ireland) Order 1979 (S.I. 1979/1714 (N.I. 19)) (false statutory declarations and other false unsworn statements).\n(7)A statement made by an individual in response to an interview notice may not be used in evidence against that individual on a prosecution for an offence under this Act (other than an offence under section 148C) unless in the proceedings—\n(a)in giving evidence the individual provides information inconsistent with the statement, and\n(b)evidence relating to the statement is adduced, or a question relating to it is asked, by that individual or on that individual’s behalf.\n(8)The Commissioner may not give an interview notice with respect to the processing of personal data for the special purposes.\n(9)The Commissioner may not give an interview notice to an individual for the purpose of investigating a suspected failure or offence if the controller or processor suspected of the failure or offence is a body specified in section 23(3) of the Freedom of Information Act 2000 (bodies dealing with security matters).\n148C False statements made in response to interview notices It is an offence for an individual, in response to an interview notice—\n(a)to make a statement which the individual knows to be false in a material respect, or\n(b)recklessly to make a statement which is false in a material respect.”\n(3)In section 149 (enforcement notices), in subsection (9)(b)—\n(a)after “an assessment notice” insert “, an interview notice”, and\n(b)after “147” insert “, 148A, 148B”.\n(4)In section 155 (penalty notices), in subsection (1)(b), after “assessment notice” insert “, an interview notice”.\n(5)In section 157 (maximum amount of penalty), in subsection (4), after “assessment notice” insert “, an interview notice”.\n(6)In section 160 (guidance about regulatory action)—\n(a)in subsection (1), after paragraph (b) insert—\n“(ba)interview notices,”, and\n(b)after subsection (5) insert—\n“(5A)In relation to interview notices, the guidance must include—\n(a)provision specifying factors to be considered in determining whether to give an interview notice to an individual;\n(b)provision about the circumstances in which the Commissioner would consider it appropriate to give an interview notice to an individual in reliance on section 148A(8) (urgent cases);\n(c)provision about the circumstances in which the Commissioner would consider it appropriate to vary the place or time specified in an interview notice at the request of the individual to whom the notice is given;\n(d)provision about the nature of interviews carried out in accordance with an interview notice;\n(e)provision about how the Commissioner will determine how to proceed if an individual does not comply with an interview notice.”\n(7)In section 162 (rights of appeal), in subsection (1), after paragraph (b) insert—\n“(ba)an interview notice;”.\n(8)In section 164 (applications in respect of urgent notices)—\n(a)in subsection (1), after “assessment notice” insert “, an interview notice”, and\n(b)in subsection (5), after paragraph (b) (but before the “and” at the end of that paragraph) insert—\n“(ba)in relation to an interview notice, a statement under section 148A(8)(a),”.\n(9)In section 181 (interpretation of Part 6), at the appropriate place, insert—\n““interview notice” has the meaning given in section 148A;”. (10)In section 196 (penalties for offences), in subsection (2), after “148,” insert “148C,”.\n(11)In section 206 (index of defined expressions), at the appropriate place, insert—\n“interview notice (in Part 6)section 181”.\n(12)In Schedule 17 (review of processing of personal data for the purposes of journalism)—\n(a)after paragraph 3 insert—\nInterview notices 3A(1)Sub-paragraph (2) applies where the Commissioner gives an interview notice to an individual during a relevant period.\n(2)If the interview notice—\n(a)states that, in the Commissioner’s opinion, it is necessary for the individual to comply with a requirement in the notice for the purposes of the relevant review, and\n(b)gives the Commissioner’s reasons for reaching that opinion,\nsubsections (6) and (7) of section 148A do not apply but the notice must not require the individual to comply with the requirement before the end of the period of 24 hours beginning when the notice is given.\n(3)During a relevant period, section 148B has effect as if for subsection (8) there were substituted—\n“(8)The Commissioner may not give an individual an interview notice with respect to the processing of personal data for the special purposes unless a determination under section 174 with respect to the data or the processing has taken effect.””, and\n(b)in paragraph 4 (applications in respect of urgent notices)—\n(i)for “or assessment notice” substitute “, assessment notice or interview notice”,\n(ii)for “or 3(2)(a)” substitute “, 3(2)(a) or 3A(2)(a)”, and\n(iii)for “or 146(8)(a)” substitute “, 146(8)(a) or 148A(8)(a)”.\nCommencement Information\n101 Penalty notices U.K. (1)The 2018 Act is amended as follows.\n(2)In paragraph 2 of Schedule 16 (notice of intent to impose penalty), omit sub-paragraphs (2) and (3).\n(3)In paragraph 4 of that Schedule (giving a penalty notice)—\n(a)before sub-paragraph (1) insert—\n“(A1)This paragraph applies where the Commissioner gives a notice of intent to a person.\n(A2)Within the period of 6 months beginning when the notice is given, or as soon as reasonably practicable thereafter, the Commission must give to the person—\n(a)a penalty notice, or\n(b)written notice that the Commissioner has decided not to give a penalty notice to the person.”,\n(b)in sub-paragraph (1)—\n(i)at the beginning, insert “But”, and\n(ii)after “penalty notice” insert “to the person”, and\n(c)in sub-paragraph (2), for “a person” substitute “the person”.\n(4)In section 160 (guidance about regulatory action), in subsection (7), after paragraph (d) insert—\n“(e)provision about the circumstances in which the Commissioner would consider it necessary to comply with the duty in paragraph 4(A2) of Schedule 16 after the period of 6 months mentioned in that paragraph.”\nCommencement Information\n102 Annual report on regulatory action U.K. (1)The 2018 Act is amended as follows.\n(2)In section 139 (reporting to Parliament), before subsection (3) insert—\n“(2A)The report under this section may include the annual report under section 161A.”\n(3)In the italic heading before section 160, at the end insert “and report”.\n(4)After section 161 insert—\n“161A Annual report on regulatory action (1)The Commissioner must produce and publish an annual report containing the information described in subsections (2) to (5).\n(2)The report must include the following information about UK GDPR investigations—\n(a)the number of investigations begun, continued or completed by the Commissioner during the reporting period,\n(b)the different types of act and omission that were the subject matter of the investigations,\n(c)the enforcement powers exercised by the Commissioner in the reporting period in connection with the investigations,\n(d)the duration of investigations that ended in the reporting period, and\n(e)the different types of outcome in investigations that ended in that period.\n(3)The report must include information about the enforcement powers exercised by the Commissioner in the reporting period in connection with—\n(a)processing of personal data by a competent authority for any of the law enforcement purposes, and\n(b)processing of personal data to which Part 4 applies.\n(4)The information included in the report in accordance with subsections (2) and (3) must include information about—\n(a)the number of penalty notices given in the reporting period that were given more than 6 months after the notice of intent was given under paragraph 2 of Schedule 16, and\n(b)the reasons why that happened.\n(5)The report must include a review of how the Commissioner had regard to the guidance published under section 160 when exercising the Commissioner’s enforcement powers as described in subsections (2)(c) and (3).\n(6)In this section—\n“enforcement powers” means the powers under— (a)\nArticle 58(1)(c) and (d) and (2)(a) and (b) of the UK GDPR, (b)\nsections 142 to 159 of this Act, (c)\nparagraph 2(a), (b) and (c) of Schedule 13 to this Act, and (d)\nSchedules 15 and 16 to this Act;\n“the law enforcement purposes” has the meaning given in section 31 of this Act;\n“the reporting period” means the period to which the report relates;\n“UK GDPR investigation” means an investigation required under Article 57(1)(h) of the UK GDPR (investigations on the application of the UK GDPR).”\nCommencement Information\n103 Complaints by data subjects U.K. (1)The 2018 Act is amended in accordance with subsections (2) and (3).\n(2)Before section 165 (but after the italic heading before it) insert—\n“164A Complaints by data subjects to controllers (1)A data subject may make a complaint to the controller if the data subject considers that, in connection with personal data relating to the data subject, there is an infringement of the UK GDPR or Part 3 of this Act.\n(2)A controller must facilitate the making of complaints under this section by taking steps such as providing a complaint form which can be completed electronically and by other means.\n(3)If a controller receives a complaint under this section, the controller must acknowledge receipt of the complaint within the period of 30 days beginning when the complaint is received.\n(4)If a controller receives a complaint under this section, the controller must without undue delay—\n(a)take appropriate steps to respond to the complaint, and\n(b)inform the complainant of the outcome of the complaint.\n(5)The reference in subsection (4)(a) to taking appropriate steps to respond to the complaint includes—\n(a)making enquiries into the subject matter of the complaint, to the extent appropriate, and\n(b)informing the complainant about progress on the complaint.\n164B Controllers to notify the Commissioner of the number of complaints (1)The Secretary of State may by regulations require a controller to notify the Commissioner of the number of complaints made to the controller under section 164A in periods specified or described in the regulations.\n(2)Regulations under this section may provide that a controller is required to make a notification to the Commissioner in respect of a period only in circumstances specified in the regulations.\n(3)Regulations under this section may include—\n(a)provision about a matter listed in subsection (4), or\n(b)provision conferring power on the Commissioner to determine those matters.\n(4)The matters are—\n(a)the form and manner in which a notification must be made,\n(b)the time at which, or period within which, a notification must be made, and\n(c)how the number of complaints made to a controller during a period is to be calculated.\n(5)Regulations under this section are subject to the negative resolution procedure.”\n(3)In section 165 (complaints by data subjects to the Commissioner)—\n(a)omit subsection (1), and\n(b)in subsection (2), after “infringement of” insert “the UK GDPR or”.\n(4)The UK GDPR is amended in accordance with subsections (5) and (6).\n(5)In Article 57 (Commissioner’s tasks)—\n(a)in paragraph 1, omit point (f), and\n(b)omit paragraph 2.\n(6)Omit Article 77 (right to lodge a complaint with the Commissioner).\n(7)Schedule 10 to this Act contains minor and consequential amendments.\nCommencement Information\n104 Court procedure in connection with subject access requests U.K. (1)The 2018 Act is amended as follows.\n(2)For the italic heading before section 180 substitute—\n“Jurisdiction and court procedure”. (3)After section 180 insert—\n“180A Procedure in connection with subject access requests (1)This section applies where a court is required to determine whether a data subject is entitled to information by virtue of a right under—\n(a)Article 15 of the UK GDPR (right of access by the data subject);\n(b)Article 20 of the UK GDPR (right to data portability);\n(c)section 45 of this Act (law enforcement processing: right of access by the data subject);\n(d)section 94 of this Act (intelligence services processing: right of access by the data subject).\n(2)The court may require the controller to make available for inspection by the court so much of the information as is available to the controller.\n(3)But, unless and until the question in subsection (1) has been determined in the data subject’s favour, the court may not require the information to be disclosed to the data subject or the data subject’s representatives, whether by discovery (or, in Scotland, recovery) or otherwise.\n(4)Where the question in subsection (1) relates to a right under a provision listed in subsection (1)(a), (c) or (d), this section does not confer power on the court to require the controller to carry out a search for information that is more extensive than the reasonable and proportionate search required by that provision.”\nCommencement Information\n105 Consequential amendments to the EITSET Regulations U.K. (1)Schedule 2 to the Electronic Identification and Trust Services for Electronic Transactions Regulations 2016 (S.I. 2016/696 ) (Commissioner’s enforcement powers) is amended as follows.\n(2)In paragraph 1 (provisions of the 2018 Act applied for enforcement purposes)—\n(a)after paragraph (g) insert—\n“(ga)section 146A (assessment notices: approval of person to prepare report etc);”, and\n(b)after paragraph (i) insert—\n“(ia)section 148A (interview notices);\n(ib)section 148B (interview notices: restrictions);\n(ic)section 148C (false statements made in response to interview notices);”.\n(3)In paragraph 4(2) (modification of section 143 (information notices: restrictions))—\n(a)in paragraph (b), for “or 148” substitute “, 148 or 148C”, and\n(b)in paragraph (c), after “148” insert “or 148C”.\n(4)In paragraph 6 (modification of section 146 (assessment notices)), in sub-paragraph (2)—\n(a)for paragraph (b) substitute—\n“(b)subsection (2) has effect as if—\n(i)for “controller or processor” there were substituted “trust service provider”;\n(ii)paragraphs (h) and (i) were omitted;”,\n(b)in paragraph (c), for “subsections (7), (8), (9) and (10)” substitute “subsections (3A), (7), (8), (9), (10) and (11A)”, and\n(c)in paragraph (d), for “or 148” substitute “, 148 or 148C”.\n(5)After paragraph 6 insert—\nModification of section 146A (assessment notices: approval of person to prepare report etc) 6A Section 146A has effect as if for “controller or processor” (in each place) there were substituted “trust service provider”.”\n(6)After paragraph 7 insert—\nModification of section 148A (interview notices) 7A Section 148A has effect as if—\n(a)in subsection (1)—\n(i)for “controller or processor” there were substituted “trust service provider”;\n(ii)in paragraph (a), for “as described in section 149(2)” there were substituted “to comply with the eIDAS requirements”;\n(iii)in paragraph (b), for “this Act” there were substituted “section 144, 148 or 148C or paragraph 15 of Schedule 15”;\n(b)in subsection (3), for “controller or processor” (in each place) there were substituted “trust service provider”.\nModification of section 148B (interview notices: restrictions) 7B(1)Section 148B has effect as if subsections (8) and (9) were omitted.\n(2)In that section—\n(a)subsections (2)(b) and (3)(b) have effect as if for “the data protection legislation” there were substituted “the eIDAS Regulation or the EITSET Regulations”;\n(b)subsection (6)(a) has effect as if for “this Act” there were substituted “section 144, 148 or 148C or paragraph 15 of Schedule 15”;\n(c)subsection (7) has effect as if for “this Act (other than an offence under section 148C)” there were substituted “section 144 or 148 or paragraph 15 of Schedule 15”.”\n(7)In paragraph 12 (modification of Schedule 15 (powers of entry and inspection)), in sub-paragraph (2), in the substituted paragraph (a), for “or 148” substitute “, 148 or 148C”.\n(8)In paragraph 13 (modification of section 155 (penalty notices)), in sub-paragraph (3)(c), for “for “data subjects”” there were substituted “for the words from “data subjects” to the end”.\n(9)Omit paragraph 21 (modification of section 182 (regulations and consultation)) and the heading before it.\n(10)In paragraph 22 (modification of section 196 (penalties for offences)), in sub-paragraph (2)(b)—\n(a)after “148”, in the first place it occurs, insert “, 148C”, and\n(b)for “or 148” substitute “, 148 or 148C”.\nCommencement Information\nProtection of prohibitions, restrictions and data subject’s rights U.K. 106 Protection of prohibitions, restrictions and data subject’s rights U.K. (1)The 2018 Act is amended in accordance with subsections (2) to (5).\n(2)After section 183 insert—\n“Prohibitions and restrictions etc on processing U.K. 183A Protection of prohibitions and restrictions etc on processing: relevant enactments (1)A relevant enactment or rule of law which imposes a duty, or confers a power, to process personal data does not override a requirement under the main data protection legislation relating to the processing of personal data.\n(2)Subsection (1) does not apply—\n(a)to a relevant enactment forming part of the main data protection legislation, or\n(b)to the extent that an enactment makes express provision to the contrary referring to this section or to the main data protection legislation (or a provision of that legislation).\n(3)Subsection (1) does not prevent a duty or power to process personal data from being taken into account for the purpose of determining whether it is possible to rely on an exception to a requirement under the main data protection legislation that is available where there is such a duty or power.\n(4)In this section—\n“the main data protection legislation” means the data protection legislation other than provision of or made under— (a)\nChapter 6 or 8 of the UK GDPR, or (b)\nParts 5 to 7 of this Act;\n“relevant enactment” means an enactment so far as passed or made on or after the day on which section 106(2) of the Data (Use and Access) Act 2025 comes into force;\n“requirement” includes a prohibition or restriction.\n(5)The reference in subsection (1) to an enactment or rule of law which imposes a duty, or confers a power, to process personal data is a reference to an enactment or rule of law which, directly or indirectly, requires or authorises the processing of personal data, including (for example)—\n(a)by authorising one person to require another person to process personal data, or\n(b)by removing restrictions on processing personal data,\nand the references in subsection (3) to a duty or power are to be read accordingly.”\n(3)Before section 184 (and the italic heading before it) insert—\n“183B Protection of prohibitions and restrictions etc on processing: other enactments (1)This section is about the relationship between—\n(a)a pre-commencement enactment which imposes a duty, or confers a power, to process personal data, and\n(b)a provision of the main data protection legislation containing a requirement relating to the processing of personal data.\n(2)The relationship is not changed by section 5(A1) of the European Union (Withdrawal) Act 2018 (removal of the principle of supremacy of EU law) (or the repeal of section 5(1) to (3) of that Act).\n(3)Where the provision described in subsection (1)(b) is a provision of, or made under, the UK GDPR, section 5(A2) of the European Union (Withdrawal) Act 2018 (assimilated direct legislation subject to domestic enactments) does not apply to the relationship.\n(4)Nothing is to be implied about a relationship described in subsection (1) merely due to the fact that express provision with similar effect to section 183A(1) (or applying that provision) is made in connection with one such relationship but not another.\n(5)In this section—\n(a)“the main data protection legislation” and “requirement” have the same meaning as in section 183A, and\n(b)“pre-commencement enactment” means an enactment so far as passed or made before the day on which section 106(2) of the Data (Use and Access) Act 2025 comes into force.\n(6)Section 183A(5) applies for the purposes of subsection (1)(a) of this section as it applies for the purposes of section 183A(1).”\n(4)In section 186 (data subject’s rights and other prohibitions and restrictions)—\n(a)for the heading substitute “Protection of data subject’s rights”,\n(b)in subsection (1) omit “, except as provided by or under the provisions listed in subsection (3)”,\n(c)after subsection (2) insert—\n“(2A)Subsection (1) does not apply—\n(a)to an enactment contained in, or made under, a provision listed in subsection (2),\n(b)to an enactment contained in, or made under, a provision listed in subsection (3),\n(c)to the extent that an enactment makes express provision to the contrary referring to this section or to a provision listed in subsection (2), or\n(d)to the extent that subsection (1) is disapplied by section 186A(3).”, and\n(d)in subsection (3)—\n(i)for “provisions providing exceptions” substitute “provisions referred to in subsection (2A)(b)”, and\n(ii)omit paragraph (c) (and the “and” after it).\n(5)After section 186 insert—\n“186A Protection of data subject’s rights: further provision (1)This section is about the relationship between—\n(a)a pre-commencement enactment which prohibits or restricts the disclosure of information or authorises the withholding of information, and\n(b)a provision of the UK GDPR or this Act listed in section 186(2).\n(2)The relationship is not changed by section 5(A1) of the European Union (Withdrawal) Act 2018 (removal of the principle of supremacy of EU law) (or the repeal of section 5(1) to (3) of that Act).\n(3)Subsection (1) of section 186 does not apply to the relationship so far as there is a contrary intention, whether express or implied (taking account of, among other things, subsection (2) of this section).\n(4)Nothing is to be implied about a relationship described in subsection (1) merely due to the fact that express provision stating that section 186(1) applies (or with similar effect) is made in connection with one such relationship but not another.\n(5)In this section, “pre-commencement enactment” means an enactment so far as passed or made before the day on which section 106(4) of the Data (Use and Access) Act 2025 comes into force, other than an enactment contained in, or made under, a provision listed in section 186(2) or (3).”\n(6)In section 5 of the European Union (Withdrawal) Act 2018 (exceptions to savings and incorporation), in subsection (A3)(a)—\n(a)for “section” substitute “sections 183A and”,\n(b)for “(data subject’s rights and other prohibitions and restrictions)” substitute “(protection of prohibitions, restrictions and data subject’s rights)”, and\n(c)at the end insert “(and see also section 183B(3) of that Act)”.\n(7)Subsections (3), (5) and (6)(c) are to be treated as having come into force on 1 January 2024.\nCommencement Information\nMiscellaneous U.K. 107 Regulations under the UK GDPR U.K. (1)In the UK GDPR, after Chapter 9 insert—\n“CHAPTER 9A U.K.Regulations Article 91A Regulations made by Secretary of State 1.This Article makes provision about regulations made by the Secretary of State under this Regulation (“UK GDPR regulations”).\n2.Before making UK GDPR regulations, the Secretary of State must consult—\n(a)the Commissioner, and\n(b)such other persons as the Secretary of State considers appropriate.\n3.Paragraph 2 does not apply to regulations made under Article 49 or 49A where the Secretary of State has made an urgency statement in respect of them.\n4.UK GDPR regulations may—\n(a)make different provision for different purposes;\n(b)include consequential, supplementary, incidental, transitional, transitory or saving provision.\n5.UK GDPR regulations are to be made by statutory instrument.\n6.For the purposes of this Regulation, where regulations are subject to “the negative resolution procedure”, the statutory instrument containing the regulations is subject to annulment in pursuance of a resolution of either House of Parliament.\n7.For the purposes of this Regulation, where regulations are subject to “the affirmative resolution procedure”, the regulations may not be made unless a draft of the statutory instrument containing them has been laid before Parliament and approved by a resolution of each House of Parliament.\n8.For the purposes of this Regulation, where regulations are subject to “the made affirmative resolution procedure”—\n(a)the statutory instrument containing the regulations must be laid before Parliament after being made, together with the urgency statement in respect of them, and\n(b)the regulations cease to have effect at the end of the period of 120 days beginning with the day on which the instrument is made, unless within that period the instrument is approved by a resolution of each House of Parliament.\n9.In calculating the period of 120 days, no account is to be taken of any whole days that fall within a period during which—\n(a)Parliament is dissolved or prorogued, or\n(b)both Houses of Parliament are adjourned for more than 4 days.\n10.Where regulations cease to have effect as a result of paragraph 8, that does not—\n(a)affect anything previously done under the regulations, or\n(b)prevent the making of new regulations.\n11.Any provision that may be included in UK GDPR regulations subject to the negative resolution procedure may be made by regulations made under this Regulation or another enactment that are subject to the affirmative resolution procedure or the made affirmative resolution procedure.\n12.A requirement under this Article to consult may be satisfied by consultation before, as well as by consultation after, the provision conferring the power to make regulations comes into force.\n13.In this Article, “urgency statement”, in relation to regulations, means a reasoned statement that the Secretary of State considers it desirable for the regulations to come into force without delay.”\n(2)In section 3(9) of the 2018 Act (definition of “data protection legislation”), in paragraph (d), after “Act” insert “or the UK GDPR”.\nCommencement Information\n108 Further minor provision about data protection U.K. Schedule 11 contains further minor provision about data protection.\nCommencement Information\nChapter 2 U.K.Privacy and electronic communications 109 The PEC Regulations U.K. In this Chapter, “the PEC Regulations” means the Privacy and Electronic Communications (EC Directive) Regulations 2003 (S.I. 2003/2426 ).\nCommencement Information\n110 Interpretation of the PEC Regulations U.K. (1)Regulation 2 of the PEC Regulations (interpretation) is amended as follows.\n(2)In paragraph (1)—\n(a)in the definition of “call”, at the end insert “, and a reference to making a call includes a reference to attempting to establish such a connection”,\n(b)in the definition of “communication”—\n(i)for “exchanged or conveyed between” substitute “transmitted to”, and\n(ii)for “conveyed”, in the second place it occurs, substitute “transmitted”, and\n(c)at the appropriate place insert—\n““direct marketing” means the communication (by whatever means) of advertising or marketing material which is directed to particular individuals;”. (3)After paragraph (1) insert—\n“(1A)In the application of these Regulations in relation to—\n(a)information that is sent but not received,\n(b)a communication that is transmitted but not received,\n(c)an electronic mail that is sent but not received, or\n(d)an unsuccessful attempt to make a call,\na reference to the recipient of the information, communication, electronic mail or call is to be read as a reference to the intended recipient.”\n(4)In paragraph (4) omit “, without prejudice to paragraph (3),”.\n(5)After that paragraph insert—\n“(5)References in these Regulations to a period expressed in hours, days, weeks, months or years are to be interpreted in accordance with Article 3 of the Periods of Time Regulation, except that Article 3(4) of that Regulation does not apply to the interpretation of a reference to a period in regulation 16A.\n(6)In paragraph (5), “the Periods of Time Regulation” means Regulation (EEC, Euratom) No. 1182/71 of the Council of 3 June 1971 determining the rules applicable to periods, dates and time limits.”\nCommencement Information\n111 Duty to notify the Commissioner of personal data breach: time periods U.K. (1)In regulation 5A of the PEC Regulations (personal data breach)—\n(a)in paragraph (2), after “delay” insert “and, where feasible, not later than 72 hours after having become aware of it”, and\n(b)after paragraph (3) insert—\n“(3A)Where notification under paragraph (2) is not made within 72 hours, it must be accompanied by reasons for the delay.”\n(2)In regulation 5C of the PEC Regulations (personal data breach: fixed monetary penalty)—\n(a)in paragraph (4)(f), for “from the service of the notice of intent” substitute “beginning when the notice of intent is served”, and\n(b)in paragraph (5), for “21 days of receipt of the notice of intent” substitute “the period of 21 days beginning when the notice of intent is received”.\n(3)In Article 2 of Commission Regulation (EU) No 611/2013 of 24 June 2013 on the measures applicable to the notification of personal data breaches under Directive 2002/58/EC of the European Parliament and of the Council on privacy and electronic communications (notification to the Commissioner)—\n(a)in paragraph 2—\n(i)in the first subparagraph, for the words from “no” to “feasible” substitute “without undue delay and, where feasible, not later than 72 hours after having become aware of it”,\n(ii)in the second subparagraph, after “shall” insert “, subject to paragraph 3,”, and\n(iii)after the third subparagraph insert—\n“This paragraph is to be interpreted in accordance with Article 3 of Regulation (EEC, Euratom) No. 1182/71 of the Council of 3 June 1971 determining the rules applicable to periods, dates and time limits.”, and\n(b)for paragraph 3 substitute—\n“3.To the extent that the information set out in Annex 1 is not available to be included in the notification, it may be provided in phases without undue further delay.”\nCommencement Information\n112 Storing information in the terminal equipment of a subscriber or user U.K. (1)The PEC Regulations are amended in accordance with subsections (2) and (3).\n(2)For regulation 6 (storing information, or gaining access to information stored, in the terminal equipment of a subscriber or user) substitute—\n“6.Storing information in the terminal equipment of a subscriber or user (1)Subject to Schedule A1, a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user.\n(2)In paragraph (1) and Schedule A1—\n(a)a reference (however expressed) to storing information, or gaining access to information stored, in the terminal equipment of a subscriber or user includes a reference to instigating the storage or access, and\n(b)except as otherwise provided, a reference (however expressed) to gaining access to information stored in the terminal equipment of a subscriber or user includes a reference to collecting or monitoring information automatically emitted by the terminal equipment.”\n(3)After regulation 6 insert—\n“6A.Power to provide exceptions to regulation 6(1) (1)The Secretary of State may by regulations made by statutory instrument—\n(a)amend these Regulations—\n(i)by adding an exception to the prohibition in regulation 6(1), or\n(ii)by omitting or varying an exception to that prohibition, and\n(b)make consequential, supplementary, incidental, transitional, transitory or saving provision, including provision amending these Regulations.\n(2)Regulations under paragraph (1) may make different provision for different purposes.\n(3)Before making regulations under paragraph (1), the Secretary of State must consult—\n(a)the Information Commissioner, and\n(b)such other persons as the Secretary of State considers appropriate.\n(4)A statutory instrument containing regulations under paragraph (1) may not be made unless a draft of the instrument has been laid before, and approved by a resolution of, each House of Parliament.”\n(4)Schedule 12 to this Act inserts Schedule A1 to the PEC Regulations.\n(5)A requirement to consult under regulation 6A of the PEC Regulations (inserted by subsection (3) of this section) may be satisfied by consultation undertaken before the day on which this Act is passed.\nCommencement Information\n113 Emergency alerts: interpretation of time periods U.K. In regulation 16A of the PEC Regulations (emergency alerts), in paragraph (6), for the words from “7 days” to “paragraph (3)(b)” substitute “the period of 7 days beginning with the day on which the time period specified by the relevant public authority pursuant to paragraph (3)(b) expires”.\nCommencement Information\n114 Use of electronic mail for direct marketing by charities U.K. (1)Regulation 22 of the PEC Regulations (use of electronic mail for direct marketing purposes) is amended as follows.\n(2)In paragraph (2), after “paragraph (3)” insert “or (3A)”.\n(3)After paragraph (3) insert—\n“(3A)A charity may send or instigate the sending of electronic mail for the purposes of direct marketing where—\n(a)the sole purpose of the direct marketing is to further one or more of the charity’s charitable purposes;\n(b)the charity obtained the contact details of the recipient of the electronic mail in the course of the recipient—\n(i)expressing an interest in one or more of the purposes that were the charity’s charitable purposes at that time; or\n(ii)offering or providing support to further one or more of those purposes; and\n(c)the recipient has been given a simple means of refusing (free of charge except for the costs of the transmission of the refusal) the use of their contact details for the purposes of direct marketing by the charity, at the time that the details were initially collected, and, where the recipient did not initially refuse the use of the details, at the time of each subsequent communication.”\n(4)After paragraph (4) insert—\n“(5)In this regulation, “charity” means—\n(a)a charity as defined in section 1(1) of the Charities Act 2011,\n(b)a charity as defined in section 1(1) of the Charities Act (Northern Ireland) 2008 (c.12 (N.I.)) , including an institution treated as such a charity for the purposes of that Act by virtue of the Charities Act 2008 (Transitional Provision) Order (Northern Ireland) 2013 (S.R. (N.I.) 2013 No. 211 ), and\n(c)a body entered in the Scottish Charity Register, other than a body which no longer meets the charity test in section 7 of the Charities and Trustee Investment (Scotland) Act 2005 (asp 10) ,\nand, in relation to such a charity, institution or body, “charitable purpose” has the meaning given in the relevant Act.”\nCommencement Information\n115 Commissioner’s enforcement powers U.K. (1)The PEC Regulations are amended in accordance with subsections (2) to (8).\n(2)In regulation 5 (security of public electronic communications services), omit paragraph (6).\n(3)Omit regulation 5B (personal data breach: audit).\n(4)In regulation 5C (personal data breach: fixed monetary penalty)—\n(a)in paragraph (10)—\n(i)omit “and Northern Ireland”, and\n(ii)in paragraph (a), for “a county court” substitute “the county court”, and\n(b)after paragraph (11) insert—\n“(12)In Northern Ireland, the penalty is recoverable—\n(a)if a county court so orders, as if it were payable under an order of that court;\n(b)if the High Court so orders, as if it were payable under an order of that court.\n(13)The Secretary of State may by regulations made by statutory instrument amend this regulation so as to substitute a different amount for the amount for the time being specified in paragraph (2) or (5).\n(14)Regulations under paragraph (13) may make transitional provision.\n(15)Before making regulations under paragraph (13), the Secretary of State must consult—\n(a)the Information Commissioner, and\n(b)such other persons as the Secretary of State considers appropriate.\n(16)A statutory instrument containing regulations under this regulation may not be made unless a draft of the instrument has been laid before, and approved by a resolution of, each House of Parliament.”\n(5)For regulation 31 substitute—\n“31.Information Commissioner’s enforcement powers (1)Schedule 1 provides for certain provisions of Parts 5 to 7 of the Data Protection Act 2018 to apply with modifications for the purposes of enforcing these Regulations.\n(2)In regulations 32 and 33, “enforcement functions” means the functions of the Information Commissioner under those provisions, as applied by that Schedule.”\n(6)Omit regulation 31A (third party information notices).\n(7)Omit regulation 31B (appeals against third party information notices).\n(8)For Schedule 1 substitute the Schedule set out in Schedule 13 to this Act.\n(9)In paragraph 58(1) of Schedule 20 to the Data Protection Act 2018 (transitional provision relating to the PEC Regulations) for “regulations 2, 31 and 31B of, and Schedule 1 to,” substitute “regulation 2 of”.\n(10)A requirement to consult under regulation 5C(15) of the PEC Regulations (inserted by subsection (4)(b) of this section) may be satisfied by consultation undertaken before the day on which this Act is passed.\nCommencement Information\n116 Codes of conduct U.K. (1)The PEC Regulations are amended as follows.\n(2)After regulation 32 insert—\n“32A.Codes of conduct (1)The Commissioner must encourage representative bodies to produce codes of conduct intended to contribute to compliance with these Regulations.\n(2)Under paragraph (1), the Commissioner must encourage representative bodies to produce codes which take account of, among other things, the specific features of different sectors.\n(3)A code of conduct described in paragraph (1) may, for example, make provision with regard to—\n(a)rights and obligations under these Regulations;\n(b)out-of-court proceedings and other dispute resolution procedures for resolving disputes arising in connection with these Regulations.\n(4)The Commissioner must encourage representative bodies to submit codes of conduct described in paragraph (1) to the Commissioner in draft.\n(5)Where a representative body does so, the Commissioner must—\n(a)provide the representative body with an opinion on whether the code correctly reflects the requirements of these Regulations,\n(b)decide whether to approve the code, and\n(c)if the code is approved, register and publish the code.\n(6)The Commissioner may only approve a code if, among other things—\n(a)the code contains a mechanism for monitoring whether persons who undertake to apply the code comply with its provisions, and\n(b)in relation to persons other than public bodies, the mechanism involves monitoring by a body which is accredited for that purpose by the Commissioner under regulation 32B.\n(7)In relation to amendments of a code of conduct that is for the time being approved under this regulation—\n(a)paragraphs (4) and (5) apply as they apply in relation to a code, and\n(b)the requirements in paragraph (6) must be satisfied by the code as amended.\n(8)A code of conduct described in paragraph (1) may be contained in the same document as a code of conduct described in Article 40 of the UK GDPR (and a provision contained in such a document may be a provision of both codes).\n(9)In this regulation—\n“public body” has the meaning given in section 7 of the Data Protection Act 2018 (for the purposes of the UK GDPR);\n“representative body” means an association or other body representing categories of—\n(a)\ncommunications providers, or (b)\nother persons engaged in activities regulated by these Regulations;\n“the UK GDPR” has the meaning given in section 3(10) of the Data Protection Act 2018. 32B.Accreditation of bodies monitoring compliance with codes of conduct (1)The Commissioner may, in accordance with this regulation, accredit a body for the purpose of monitoring whether persons other than public bodies comply with a code of conduct described in regulation 32A(1).\n(2)The Commissioner may accredit a body only where the Commissioner is satisfied that the body has—\n(a)demonstrated its independence,\n(b)demonstrated that it has an appropriate level of expertise in relation to the subject matter of the code,\n(c)established procedures which allow it—\n(i)to assess a person’s eligibility to apply the code,\n(ii)to monitor compliance with the code, and\n(iii)to review the operation of the code periodically,\n(d)established procedures and structures to handle complaints about infringements of the code or about the manner in which the code has been, or is being, implemented by a person,\n(e)made arrangements to publish information about the procedures and structures described in sub-paragraph (d), and\n(f)demonstrated that it does not have a conflict of interest.\n(3)The Commissioner must prepare and publish guidance about how the Commissioner proposes to take decisions about accreditation under this regulation.\n(4)A body accredited under this regulation in relation to a code must take appropriate action where a person infringes the code.\n(5)If the action taken by a body under paragraph (4) consists of suspending or excluding a person from the code, the body must inform the Commissioner, giving reasons for taking that action.\n(6)The Commissioner must revoke the accreditation of a body under this regulation if the Commissioner considers that the body—\n(a)no longer meets the requirements for accreditation, or\n(b)has failed, or is failing, to comply with paragraph (4) or (5).\n(7)In this regulation, “public body” has the same meaning as in regulation 32A.\n32C.Effect of codes of conduct Adherence to a code of conduct approved under regulation 32A may be used by a person as a means of demonstrating compliance with these Regulations.”\n(3)In regulation 33 (technical advice to the Commissioner)—\n(a)omit “, in connection with his enforcement functions,” and\n(b)at the end insert “where the request is made in connection with—\n(a)the Commissioner’s enforcement functions, or\n(b)the Commissioner’s functions under regulation 32A or 32B (codes of conduct).”\n(4)In Schedule 1 (Commissioner’s enforcement powers) (inserted by Schedule 13 to this Act), in paragraph 18(b)(ii) (maximum amount of penalty), for “or 24” substitute “, 24 or 32B(4) or (5)”.\nCommencement Information\n","permalink":"https://ai.intlaws.com/en/compliance/other/%E8%8B%B1%E5%9B%BD-duaa2025-part5/","summary":"Official text of Part 5 (Data Protection and Privacy) of the UK Data (Use and Access) Act 2025, comprising Chapter 1 (Data protection, sections 66–108) and Chapter 2 (PECR reform, sections 109–116): 51 sections in total. English original from legislation.gov.uk; Chinese translation in progress.","title":"UK Data (Use and Access) Act 2025 — Part 5 (Data Protection and Privacy)"},{"content":" 来源：加州隐私保护局（California Privacy Protection Agency, CPPA / CalPrivacy）官网\n案例正文 案号/文号：Case No. ENF25-172-D-DA 机关：加州隐私保护局（CPPA / CalPrivacy）董事会（Board） 日期：公告日 2026-01-08；决定书签署日 2025-12-30 所涉法律：加州《删除法》（California Delete Act）——数据经纪商年度登记义务；另涉及 CCPA 项下数据经纪制度背景 要旨（官方原文照录，2026-01-08 公告）： \u0026ldquo;The first decision requires Rickenbacher Data LLC, d/b/a Datamasters, a Texas-based reseller of personal information for targeted advertising, to pay a $45,000 fine for failing to register as a data broker in violation of California\u0026rsquo;s Delete Act. The decision also orders the company to stop selling all Californians\u0026rsquo; personal information.\u0026rdquo;\n\u0026ldquo;According to the decision, Datamasters bought and resold the names, addresses, phone numbers, and email addresses of millions of people with Alzheimer\u0026rsquo;s disease, drug addiction, bladder incontinence, and other health conditions for targeted advertising. In addition, Datamasters bought and resold lists of people based on age and perceived race, offering \u0026ldquo;Senior Lists\u0026rdquo; and \u0026ldquo;Hispanic Lists,\u0026rdquo; as well as lists based on political views, grocery store purchases, banking activity, and health-related purchases. The company engaged in these activities in 2024 without registering with the California Data Broker Registry.\u0026rdquo;\n\u0026ldquo;As a result of the Board\u0026rsquo;s decision, Datamasters will stop selling all forms of personal information about Californians, effectively removing it from the marketplace in California.\u0026rdquo;\n（本网译，非官方译本，仅供参考）：董事会第一项决定要求 Rickenbacher Data LLC（d/b/a Datamasters，得克萨斯州定向广告个人信息转售商）就违反加州《删除法》未登记为数据经纪商缴纳 45,000 美元罚款，并命令其停止出售全部加州居民个人信息。据决定书，Datamasters 于 2024 年在未向加州数据经纪商登记处登记的情况下，购买并转售数百万阿尔茨海默病、药物成瘾、膀胱失禁等健康状况人士及基于年龄、感知种族（「长者名单」「西裔名单」）、政治观点、杂货消费、银行活动、健康类消费等类别的姓名、住址、电话与电子邮箱名单。\n官方直链： 公告页：https://cppa.ca.gov/announcements/2026/20260108.html 决定书 PDF：https://cppa.ca.gov/pdf/datamasters_order_signed.pdf 法域：美国（加州） ","permalink":"https://ai.intlaws.com/cases/%E7%BE%8E%E5%9B%BD-calprivacy%E6%95%B0%E6%8D%AE%E7%BB%8F%E7%BA%AA%E6%89%A7%E6%B3%95-datamasters%E6%A1%88/","summary":"加州隐私保护局（CPPA / CalPrivacy）董事会就 Rickenbacher Data LLC（d/b/a Datamasters） 违反加州《删除法》未登记为数据经纪商一案作出决定：罚款 45,000 美元并禁止其继续出售 加州居民个人信息。四要素、官方直链与原文快照齐备；决定书签署日待核。","title":"案例荟萃｜美国 CalPrivacy 数据经纪执法：Datamasters 未登记数据经纪商案"},{"content":" 来源：加州隐私保护局（California Privacy Protection Agency, CPPA / CalPrivacy）官网\n案例正文 案号/文号：Case No. ENF25-220-D-SP 机关：加州隐私保护局（CPPA / CalPrivacy）董事会（Board） 日期： 决定书签署日：2025-12-30——自决定书 PDF 签署页数字签章文本层逐字提取：Signed by: jill hamer / Date: 2025-12-30 18:45:17（Jill Hamer 系 CPPA 董事会成员，签章为 PDF 数字签章属性文本，非推测） 公告日 2026-01-08 所涉法律：加州《删除法》（California Delete Act）——数据经纪商年度登记义务 要旨（官方原文照录，2026-01-08 公告）： \u0026ldquo;The second decision requires S\u0026amp;P Global, Inc., a New York-based provider of data and technology, to pay a $62,600 fine for failing to register as a data broker due to an administrative error. In addition to the fine, the decision requires S\u0026amp;P Global to adopt procedures for registration and compliance auditing to prevent similar errors in the future.\u0026rdquo;\n（本网译，非官方译本，仅供参考）：董事会第二项决定要求总部位于纽约的数据与技术提供商 S\u0026amp;P Global, Inc.，就因行政性差错未登记为数据经纪商缴纳 62,600 美元罚款；除罚款外，决定还要求 S\u0026amp;P Global 建立登记与合规审计程序，以防同类差错再发。\n官方直链： 公告页：https://cppa.ca.gov/announcements/2026/20260108.html 决定书 PDF：https://cppa.ca.gov/pdf/sp_global_inc_fo_signed.pdf 法域：美国（加州） ","permalink":"https://ai.intlaws.com/cases/%E7%BE%8E%E5%9B%BD-calprivacy%E6%95%B0%E6%8D%AE%E7%BB%8F%E7%BA%AA%E6%89%A7%E6%B3%95-spglobal%E6%A1%88/","summary":"加州隐私保护局（CPPA / CalPrivacy）董事会就 S\u0026amp;P Global, Inc. 违反加州《删除法》 未登记为数据经纪商（行政性差错）一案作出决定：罚款 62,600 美元并要求建立登记与 合规审计程序。决定书数字签章日期 2025-12-30（自 PDF 签章文本层提取）。","title":"案例荟萃｜美国 CalPrivacy 数据经纪执法：S\u0026P Global 未登记数据经纪商案"},{"content":" 来源:科罗拉多州议会,官方法案(第 131 章,2026 年法律)\n官方链接: https://leg.colorado.gov/laws/session-laws/SB26-189/131/download 声明:本页为非官方翻译(unofficial translation),仅供参考;如有歧义,以英文原文为准。\n关键日期:批准于 2026 年 5 月 14 日;适用于 2027 年 1 月 1 日及之后作出的重大影响决定(义务适用日;生效日与义务适用日分列)。依第 5 节(生效日—适用),本法于 2027 年 1 月 1 日生效,并适用于该日及之后作出的重大影响决定;原《科罗拉多州人工智能法》(SB 24-205,2024 年制定)经本法第 1 节废止并重新制定,未及施行即废止。\n译注:\n原官方法案以大写字母或粗体、斜体标示对现行法律新增的内容,以删除线标示对现行法律的删除;该等排版标记不属于本法实体内容,本译文未逐一保留。 本译文条款序号按中文层级转换:(1)→一、;(a)→(一);(I)→1.;(A)→(1)。条文内部互引按此转换(如\u0026quot;本条第二款第(一)项\u0026quot;);对《科罗拉多州修订法典》其他条文及其他成文法的引用,保留原法典编号(如\u0026quot;第 6-1-1303 (6)(a) 条\u0026quot;)。 术语:consequential decision 译作\u0026quot;重大影响决定\u0026quot;;covered ADMT 译作\u0026quot;受规制的 ADMT\u0026quot;;covered domain 译作\u0026quot;受规制领域\u0026quot;;deployer 译作\u0026quot;部署者\u0026quot;;developer 译作\u0026quot;开发者\u0026quot;;materially influence 译作\u0026quot;实质性影响\u0026quot;。 第 131 章 消费者与商业交易 参议院法案 26-189\n提案参议员:Rodriguez 与 Coleman、Baisley、Amabile、Ball、Benavidez、Bridges、Cutter、Exum、Frizell、Kirkmeyer、Kolker、Lindstedt、Marchman、Pelton B.、Pelton R.、Rich、Simpson、Snyder;以及众议员:Duran 与 Bacon、Titone、Boesenecker、Brown、Caldwell、Carter、Clifford、English、Flanell、Goldstein、Gonzalez R.、Hamrick、Jackson、Lieder、Lindsay、McCormick、Nguyen、Paschal、Rutinel、Slaugh、Smith、Story、Velasco、Winter T.、McCluskie。\n本法 关于在重大影响决定中使用自动化决策技术,以及与此相关作出拨款。\n兹由科罗拉多州议会制定如下:\n第 1 节 兹废止并重新制定《科罗拉多州修订法典》(Colorado Revised Statutes)第 6 编第 1 章第 17 部分,并作修正,内容如下:第 17 部分 重大影响决定中的自动化决策技术 6-1-1701. 定义。 在本第 17 部分中,除上下文另有要求外:\n一、\u0026ldquo;不利结果\u0026rdquo;(adverse outcome)指:\n(一)一项决定,其拒绝、终止、撤销,或实质性地减少或限制消费者对下列事项的获取、资格、入选、获得报酬,或获得某项机会或服务的提供;或\n(二)一项决定,其导致实质性更为不利的差异化价格、成本、报酬或其他重要条款,而这些条款合理可能实质性限制、延迟或实质上阻止,或以其他方式根本改变消费者对下列事项的获取、资格、入选、获得报酬,或获得某项机会或服务的提供——与提供给处境相似的消费者的条款相比。若某项决定结果施加了实质性更为不利的差异化定价或条款,则该决定结果实质性影响价格、成本分摊、报酬或重要条款。\n二、\u0026ldquo;自动化决策技术\u0026rdquo;(automated decision-making technology)或\u0026quot;ADMT\u0026quot;指:\n(一)一种处理个人数据并运用计算生成输出的技术,输出包括预测、推荐、分类、排名、评分或其他信息,该等信息被用于作出、指导或协助关于个人的决定、判断或认定;\n(二)\u0026ldquo;自动化决策技术\u0026quot;或\u0026quot;ADMT\u0026quot;不包括:\n下列技术:(1) 反恶意软件;(2) 反病毒;(3) 计算器;(4) 数据库;(5) 数据存储;(6) 防火墙;(7) 互联网域名注册;(8) 互联网网页加载;(9) 网络连接;(10) 垃圾邮件与自动语音电话过滤;(11) 拼写检查;(12) 需要人工分析且不使用机器学习、基础模型或大型语言模型的电子表格;(13) 网页缓存;或 (14) 网页托管;\n由个人仅为总结、整理、翻译、起草、路由或呈现信息以供对行政处理进行人工复核之目的而使用的工具;或\n以自然语言或普通消费者易于理解的其他方式与消费者沟通的技术,其目的在于向消费者提供信息、作出转介或推荐、回答问题或生成其他内容,前提是:(1) 该技术未被任何人约定、宣传、营销、配置或意图用于重大影响决定;且 (2) 该技术受一项可接受使用政策约束,该政策禁止将所生成的内容用于重大影响决定。\n三、\u0026ldquo;重大影响决定\u0026rdquo;(consequential decision)指:\n(一)1. 就消费者作出的决定、认定或行动,其涉及某一受规制领域的提供,或消费者对某一受规制领域的获取、资格、入选或获得报酬;或 2. 关于消费者的决定、认定或行动,其以合理可能实质性限制、延迟、实质上阻止,或以其他方式根本改变消费者对某一受规制领域的获取、资格或机会的方式,涉及差异化价格、成本分摊、报酬或其他重要条款。\n(二)\u0026ldquo;重大影响决定\u0026quot;不包括:\n不会实质性影响某一受规制领域内对某项机会或服务的资格、入选、拒绝、报酬、定价或获取的低风险或常规决定、行动及业务流程,包括常规排程、课堂个性化、行政路由、客户服务分流、决定的传达或工作流管理;\n广告、营销、差异化产品推荐、搜索或内容审核;\n需要人工手动分析且不使用机器学习、基础模型或大型语言模型的电子表格;\n使用 ADMT 总结、整理或呈现信息以供人工复核,且该系统不产生实质性影响某项结果或决定的评分、排名、推荐、分类、预测或其他推断的行动;\n不生成关于消费者的预测或推断、亦不实质性影响某项重大影响决定或重大影响决定流程的狭窄程序性任务或数据处理功能;\n与用于网络安全、垃圾邮件与自动语音电话过滤、系统可靠性,以及反洗钱与反恐怖主义融资管控的技术有关的活动;\n与用于经济制裁合规的技术有关的活动,包括依据联邦《银行保密法》(Bank Secrecy Act),12 U.S.C. 第 1951 条及以下各条;联邦《美国爱国者法》(USA PATRIOT Act),Pub. L. 107-56;联邦贸易委员会《红旗规则》(Red Flags Rule),16 CFR 681(经修正);以及美国财政部管理的制裁项目,但面部识别除外,除非其唯一目的是确认个人身份;\n与用于欺诈预防的技术有关的活动,包括身份核验、消费者身份识别、监测,以及州法或联邦法律要求的报告管控;或\n不实质性影响重大影响决定的常规学术管理与学生支持流程。\n四、\u0026ldquo;消费者\u0026rdquo;(consumer):\n(一)\u0026ldquo;消费者\u0026quot;具有第 6-1-1303 (6)(a) 条规定的含义。\n(二)\u0026ldquo;消费者\u0026quot;包括雇员、身为科罗拉多州居民的求职者,以及任何个人:其在科罗拉多州的获取、资格或机会由在科罗拉多州经营业务的人在重大影响决定中予以评估。\n五、\u0026ldquo;受规制的 ADMT\u0026rdquo;(covered ADMT)指用于实质性影响重大影响决定的自动化决策技术。\n六、\u0026ldquo;受规制领域\u0026rdquo;(covered domain)指:\n(一)教育入学或教育机会;\n(二)建立或可能建立雇主—雇员关系的雇佣或雇佣机会;\n(三)在科罗拉多州租赁或购买住宅不动产;\n(四)金融或借贷服务;\n(五)保险,包括承保、定价、保障范围、理赔裁决,或实质性影响福利获取的其他认定;\n(六)医疗保健服务;或\n(七)基本政府服务与公共福利,包括资格认定与续期认定。\n七、\u0026ldquo;部署者\u0026rdquo;(deployer)指在科罗拉多州经营业务且部署受规制 ADMT 的人。\n八、\u0026ldquo;开发者\u0026rdquo;(developer)指:\n(一)在科罗拉多州经营业务并符合下列情形的人:\n开发、提供、销售、出租、许可或以其他方式将受规制 ADMT 投入商业供应;\n开发某项组件,该组件被设计、营销、意图、记载、宣传、配置或约定用作受规制 ADMT 的组成部分;或\n故意且实质性修改某项 ADMT,使其成为受规制的 ADMT。\n(二)\u0026ldquo;开发者\u0026quot;不包括符合下列情形的人:\n开发并使用某项 ADMT: (1) 仅为研究目的,且该 ADMT 在该研究中未被用于重大影响决定;或\n(2) 为内部目的,例如关联方及商业支持职能的使用与开发活动,且不将该系统提供给他人用于重大影响决定;\n系前置开发者,其将某项 ADMT 投入商业供应,而非关联方以改变该系统预期、记载、营销、宣传、配置或约定用途的方式修改该受规制的 ADMT;或\n已设计、营销、意图、记载、宣传、配置或约定某项用作 ADMT 组成部分的组件,但该组件在该人并不实际知悉的情况下被整合进受规制的 ADMT。\n九、\u0026ldquo;雇员\u0026rdquo;(employee)具有第 8-4-101 (5) 条规定的含义。\n十、\u0026ldquo;雇主\u0026rdquo;(employer)具有第 8-4-101 (6) 条规定的含义。\n十一、\u0026ldquo;FERPA\u0026quot;指联邦《家庭教育权利与隐私法》(Family Educational Rights and Privacy Act of 1974),20 U.S.C. 第 1232g 条及以下各条,及其实施条例。\n十二、\u0026ldquo;故意且实质性修改\u0026rdquo;(intentional and substantial modification)指对某项 ADMT 作出的故意变更,该变更导致该系统的预期、记载、宣传、配置或约定用途发生实质性变化。\n十三、\u0026ldquo;实质性影响\u0026rdquo;(materially influence)指:\n(一)1. ADMT 输出是作出重大影响决定时所使用的非轻微因素;且 2. ADMT 输出影响重大影响决定的结果,包括通过限制、排名、评分、推荐、分类,或以其他方式实质性改变重大影响决定的作出方式。\n(二)\u0026ldquo;实质性影响\u0026quot;不包括附带的、琐碎的或文书性的使用。\n十四、\u0026ldquo;实质性更新\u0026rdquo;(material update)指受规制 ADMT 的更新、补丁、发行版、修订或新版本,包括相关软件、模型参数、默认设置或文档。\n(一)指开发者知道或合理应当知道其可能实质性影响下列事项的上述更新:1. 该受规制 ADMT 在与其预期用途相关方面的输出或性能;或 2. 开发者就该受规制 ADMT 所述明的预期用途。\n(二)不包括不会实质性影响下列事项的常规维护、外观变更或缺陷修复:1. 受规制 ADMT 在与其预期用途相关方面的输出或性能;或 2. 开发者就该受规制 ADMT 所述明的预期用途。\n十五、\u0026ldquo;有意义的人工复核\u0026rdquo;(meaningful human review)指由部署者指定的、有权批准、修改或推翻某项重大影响决定且符合下列条件的个人所作的复核,该个人:\n(一)考虑相关的、可获得的主要证据;\n(二)经培训以进行该复核;\n(三)不以系统输出作为默认结论;且\n(四)可获取充分信息以理解:\n该输出的:(1) 预期用途;(2) 重要限制;以及 (3) 输入类别;以及\n用于生成该输出的主要因素,且不要求披露专有源代码、模型权重或其他商业秘密。\n十六、\u0026ldquo;个人数据\u0026rdquo;(personal data)具有第 6-1-1303 (17) 条规定的含义。\n十七、\u0026ldquo;商业秘密\u0026rdquo;(trade secret)具有第 7-74-102 (4) 条规定的含义。\n6-1-1702. 开发者责任——文档。 一、自 2027 年 1 月 1 日起,开发者应以部署者合理可理解、且能保护商业秘密或受州法或联邦法律保护而不得披露的信息的形式和方式,向该开发者所开发的受规制 ADMT 的每一部署者提供:\n(一)说明该受规制 ADMT 的预期用途及已知有害或不适当用途的一般性声明;\n(二)对用于训练该受规制 ADMT 的数据类别(包括个人数据)的说明,以已知范围为限;\n(三)该受规制 ADMT 的已知限制,包括已知风险以及不应使用该受规制 ADMT 的情形;\n(四)关于部署者适当使用、监测及在适用时进行有意义的人工复核的说明;\n(五)部署者为遵守第 6-1-1704 条合理必要的信息。若信息被保留不予披露,开发者应通知部署者。\n二、(一)开发者应向该开发者所开发的受规制 ADMT 的每一部署者,在合理时间内提供关于该 ADMT 的实质性更新、故意且实质性修改,以及该受规制 ADMT 的预期用途、限制或风险缓解措施变更的通知;\n(二)开发者可使用包含本款第(一)项所要求信息的公开发行说明来遵守本款规定,前提是开发者向该受规制 ADMT 的每一部署者提供该公开发行的直接通知。\n三、开发者仅在某部署者将受规制 ADMT 用于实质性影响重大影响决定,且该 ADMT 被营销、宣传、配置、约定、销售或许可用于该用途时,才受本条第一款和第二款所述披露要求的约束。\n四、开发者应自依本条要求或产生的记录产生之日起不少于三年内(若适用的州法或联邦法律要求更长期限,则按更长期限)保存为证明遵守本条所合理必要的记录。记录包括系统版本标识、变更日志,以及依本条第二款向部署者提供的实质性更新的文档和通知。\n五、当开发者创建的受规制 ADMT 被意图、记载、营销、宣传、配置或约定用于作出重大影响决定时,或当开发者知悉该受规制 ADMT 正以符合预期及约定用途的方式被用于作出重大影响决定时,本条适用。\n6-1-1703. 部署者记录保存。 部署者应自重大影响决定作出之日起不少于三年内(若适用的州法或联邦法律要求更长期限,则按更长期限)保存为证明遵守本第 17 部分所合理必要的记录。记录可酌情包括受规制 ADMT 版本标识、变更日志,以及实质性缓释变更的文档。\n6-1-1704. 部署者披露——交互时点通知——公开张贴选项——不利结果后的披露——立法声明——商业秘密——遵守其他法律——无障碍——规则。 一、在部署者使用受规制 ADMT 实质性影响重大影响决定之前,部署者应向消费者提供清晰且显著的通知,说明部署者在影响该消费者的重大影响决定中使用了或将要使用受规制的 ADMT,并提供关于消费者可如何获取本条所述额外信息的说明。\n二、部署者通过维持一项显著的公开通知来遵守本条第一款的规定,该通知在消费者交互时点可合理获取,包括通过与该可能发生重大影响决定的交互或交易合理邻近的链接或张贴。\n三、若部署者使用受规制 ADMT 实质性影响某项导致消费者遭受不利结果的重大影响决定,部署者应在作出该决定后三十日内提供:\n(一)对重大影响决定的通俗语言描述,以及受规制 ADMT 在该重大影响决定中所起的作用;\n(二)关于请求获取受规制 ADMT 及其输入的额外信息的说明与简便易行的流程,该等信息包括该受规制 ADMT 的名称、该受规制 ADMT 的版本号(如适用)、该受规制 ADMT 的开发者,以及所使用个人数据的类型、类别和来源——以部署者依第 6-1-1702 条从开发者处收到必要信息为限;以及\n(三)对第 6-1-1705 条所述消费者权利的说明,以及如何行使这些权利。\n四、议会认定,不利结果后披露的具体内容与格式可能因重大影响决定领域不同而有所差异。议会意图通过制定规则进一步明确不利结果后披露的具体要素,该规则应顾及行业特定做法,同时确保消费者获得关于重大影响决定的有意义且可理解的信息。总检察长应在 2027 年 1 月 1 日或之前制定规则,以明确并实施本条第三款所规定的不利结果后披露要求。依本款制定的规则可酌情包括:\n(一)明确下列内容的规则:在涉及受规制 ADMT 的不利结果发生后,部署者依本条第三款必须向消费者提供的、与个人数据的类型、来源或类别相关的必要披露的内容;\n(二)针对不同受规制领域量身定制的行业特定指引或示例;\n(三)以消费者合理可理解的方式描述受规制 ADMT 在重大影响决定中所起作用的标准;以及\n(四)关于本条所述披露要求与要求或规范通知、说明或不利结果披露的联邦或州法律之间如何相互作用的指引。\n五、本条不要求部署者披露商业秘密或受州法或联邦法律保护而不得披露的信息。若部署者依本款保留信息不予披露,部署者应通知消费者。\n六、就涉及信贷的提供、拒绝、定价、服务或其他重要条款的重大影响决定而言:\n(一)凡依联邦《平等信贷机会法》(Equal Credit Opportunity Act),15 U.S.C. 第 1691 条及以下各条,及其实施条例(包括《B 条例》(Regulation B),12 CFR 1002,以及在适用时的联邦《公平信用报告法》(Fair Credit Reporting Act),15 U.S.C. 第 1681 条及以下各条)被要求且实际向消费者提供通知的债权人,若其依本项所述联邦法律和条例向消费者提供的通知同时满足本条的通知或披露要求,则该债权人遵守了本条中与同一决定或不利结果相关的通知或披露要求。\n(二)若债权人遵守本项所述的联邦法律和条例,并遵守本款第(一)项的规定,则不要求该债权人依本条提供单独或重复的通知。\n(三)本款中的任何内容均不得解释为要求债权人以联邦法律所禁止的方式提供任何通知或披露。\n(四)就本款而言,符合本项所述联邦法律和条例且符合本款第(一)项规定的通知,可以包含一份简要说明,表明某项受规制 ADMT 被用于实质性影响该重大影响决定,并包含关于消费者如何获取任何附加信息或行使本第 17 部分所规定的任何权利的指引。\n七、本第 17 部分不得被解释为要求某人在以下范围内向消费者作出披露、提供解释或提供信息:这样做将为联邦法律所禁止,或会损害法律所要求的网络安全、欺诈预防、反洗钱、反恐怖主义融资或经济制裁合规计划的保密性或完整性。\n八、部署者或开发者应以对残障消费者和英语能力有限的消费者合理可及的方式,提供本第 17 部分所要求的通知和披露,并符合适用的州法律和联邦法律。\n九、对于与教育有关的重大影响决定:\n(一)受 FERPA 约束的部署者,通过符合 FERPA 以及该部署者的 FERPA 通知及学生记录查阅程序的方式和渠道提供通知和披露,包括在适用情况下向父母或监护人,或向符合资格的学生发出通知,即视为满足本条的要求。\n(二)受 FERPA 约束的部署者,如果已建立为遵守 FERPA 的通知或披露程序,则无须另行建立单独或重复的通知或披露程序。\n6-1-1705. 消费者权利——更正——人工复核与重新考虑——规则。 一、当消费者因某项重大影响决定而遭遇不利结果,且在该重大影响决定中某项受规制 ADMT 实质性影响该决定时:\n(一)消费者可以请求,部署者应当响应请求提供:\n关于请求个人数据以及更正依第 6-1-1306 条在使用了受规制 ADMT 的重大影响决定中所使用的、事实不正确或实质不准确的个人数据的指引(与第 6-1-1306 条一致);以及\n在商业上合理的范围内,对重大影响决定进行有意义的人工复核和重新考虑的机会。\n(二)就本款而言,第 6-1-1303 (6)(b) 条中\u0026quot;消费者\u0026quot;定义的例外,以及第 6-1-1304 (2)(k)、(2)(n) 和 (2)(o) 条中的例外,不适用于依本款请求更正事实不正确或实质不准确的个人数据的权利。\n(三)本条第一款第(一)项不要求更正意见、预测、评分或受保护的评估。\n二、对于与教育有关的重大影响决定:\n(一)受 FERPA 约束的部署者,通过该部署者现有的学生记录查阅、复核和修正程序,以及任何适用的学区投诉或申诉程序,满足本条第一款的要求,前提是该部署者提供合理机制,使父母、监护人或符合资格的学生能够请求更正实质不准确的个人数据,并在本第 17 部分适用的情况下请求重新考虑。\n(二)受 FERPA 约束的部署者,如果已建立为遵守 FERPA 的更正程序或人工复核与重新考虑程序,则无须另行建立单独或重复的更正程序或人工复核与重新考虑程序。\n三、总检察长应在 2027 年 1 月 1 日或之前制定规则,以明确并实施本条的要求。\n6-1-1706. 总检察长执法——欺骗性交易行为——补救权——无私人诉讼权——合并当事人规则——报告——废止。 一、总检察长应通过《科罗拉多州消费者保护法》(Colorado Consumer Protection Act),即本第 1 编,执行本第 17 部分。违反第 6-1-1702、6-1-1703、6-1-1704 和 6-1-1705 条所述披露要求和消费者权利的行为,仅可由总检察长执行,而不适用本第 6 编中的任何其他规定。\n二、违反本第 17 部分的行为属于欺骗性交易行为,并适用《科罗拉多州消费者保护法》,即本第 1 编的规定。《科罗拉多州消费者保护法》(本第 1 编)中,与本条就违反本第 17 部分的行为授予总检察长的专属执法权不一致的任何规定,不适用于任何此类违法行为。\n三、在就违反本第 17 部分的行为采取任何执法行动之前,如果总检察长认为可以补救,总检察长应向开发者或部署者发出违法通知。如果开发者或部署者未能在收到违法通知后六十日内补救该违法行为,总检察长可以依本条提起诉讼。如果总检察长认定并能够证明某开发者或部署者明知而违反本第 17 部分,或某开发者或部署者反复违反本第 17 部分,则总检察长在寻求处罚或其他救济之前无须提供补救期。如果在执法行动过程中发现违法行为,法院可以将开发者或部署者在收到书面通知后六十日内已补救该违法行为,作为确定民事处罚或其他金钱救济(如有)时的减轻情节予以考虑。\n自 2028 年 1 月起,以及此后每年的 1 月,总检察长应在依第 2-7-203 条要求的\u0026quot;SMART ACT\u0026quot;听证会中,作为法律部陈述的一部分,列入一份关于总检察长就违反本第 17 部分的行为所提起的执法行动和所提供的补救期的报告,包括:\n(一)总检察长分别针对开发者和部署者提起的诉讼数量;\n(二)总检察长分别针对开发者和部署者提起的、已完结的诉讼数量;\n(三)总检察长分别向开发者和部署者提供的补救期数量;\n(四)总检察长所提供、而开发者和部署者分别未予遵守的补救期数量;以及\n(五)总检察长分别针对开发者和部署者提起的、未认定可以补救的违法行为数量。\n本款自 2030 年 1 月 1 日起废止。\n四、本第 17 部分中的任何内容均不创设新的私人诉讼权。本第 17 部分中的任何内容均不限制或减少州法律或联邦法律下可获得的任何现有权利或救济,包括《科罗拉多州反歧视法》(Colorado Anti-Discrimination Act,第 24 编第 34 章第 3 至第 8 部分);《科罗拉多州消费者保护法》(本第 1 编);产品责任法;或其他适用法律。\n五、总检察长可依本第 17 部分视需要制定规则,以实施和澄清本第 17 部分。总检察长可以制定规则,以澄清第 6-1-1701 (13) 条所定义的\u0026quot;实质性影响\u0026quot;定义的适用,包括推定、示例和客观指标。在依本第 17 部分制定规则时,总检察长应采用能够切实吸纳利益相关方(包括消费者权益倡导者、部署者、开发者和行业监管机构)参与的流程,通过公告、书面意见机会以及至少一次公开听证会予以参与,并应依照第 24-4-103 条制定规则。\n六、本第 17 部分中的任何内容均不限制当事方依《科罗拉多州民事诉讼规则》(包括该规则第 19 条和第 20 条)合并必要当事方或任意当事方的能力,该能力适用于依现有法律提起的任何诉讼。\n6-1-1707. 责任——过错——分摊——不承担连带责任——禁止补偿——对现有法律的影响。 一、在依州反歧视法律(包括《科罗拉多州反歧视法》,第 24 编第 34 章第 3 至第 8 部分)指控非法歧视的诉讼中,开发者或部署者可能因某项受规制 ADMT 实质性影响的重大影响决定而被认定承担责任。\n二、在第一款所述诉讼中,应根据部署者和开发者对该违法行为的相对过错,在他们之间分摊过错。\n三、本条中的任何内容均不得被解释为在现有法律未作规定的情况下,将责任分摊给请求人。\n四、本条中的任何内容均不得被解释为创设连带责任,但现有法律允许的范围除外。\n五、在第一款所述诉讼中,开发者仅在以下范围内承担责任:\n(一)1. 该开发者的受规制 ADMT 被部署者以该开发者所意图、记载、营销、宣传、配置或合同约定的方式使用;且 2. 该开发者的受规制 ADMT 实质性影响了导致违反现有法律的重大影响决定;\n(二)对于因部署者以非该开发者所意图、记载、营销、宣传、配置或合同约定的方式使用受规制 ADMT 而产生的违反现有法律的情形,开发者不依本条承担责任。\n六、本条中的任何内容均不得被解释为限制部署者因其在受规制 ADMT 实质性影响的重大影响决定中自身独立作为或不作为而承担的责任,包括以非该开发者所意图、记载、营销、宣传、配置或合同约定的方式使用 ADMT(前提是该受规制 ADMT 的开发者已遵守第 6-1-1702 条)。\n七、尽管有任何其他法律规定,如果关于在作出重大影响决定时使用自动化决策技术的合同条款,或开发者与部署者之间的任何其他合同,意图就受补偿方依本条承担的损害赔偿责任(该责任系因开发者或部署者自身与在作出重大影响决定时违反《科罗拉多州反歧视法》(第 24 编第 34 章第 3 至第 8 部分)或其他科罗拉多州反歧视法律而使用自动化决策技术有关的作为或不作为所引起)予以补偿、抗辩或使其免受损害,或具有该等效果,则该条款违反公共政策并无效。\n(一)本款第(一)项的限制,在受规制 ADMT 用于作出重大影响决定并非该开发者所意图、记载、营销、宣传、配置或合同约定的情况下,不适用于该开发者,前提是该受规制 ADMT 的开发者已遵守第 6-1-1702 条。\n(二)本款在其他方面不限制以商业或营业身份行事的当事人之间合同条款的可执行性,但适用法律另有规定的范围除外。\n(三)本款不禁止或限制任何人就任何适用的被主张责任或相关损失取得适用保险或提出保险索赔。\n八、本条中的任何内容均不得被解释为限制、取代或以其他方式影响开发者或部署者可能承担的任何责任,即独立于本条规定的责任之外、因违反州法律而承担的责任。遵守本第 17 部分的要求不构成对不遵守任何适用法律的抗辩,也不以其他方式免除不遵守任何适用法律的责任。\n九、在重大影响决定中使用 ADMT,并不免除、不使之正当化,也不构成对州法律或联邦法律下任何义务或责任的抗辩,包括与歧视或消费者保护有关的义务和责任。\n6-1-1708. 遵守其他法律义务——保险人——受规制实体——披露。 一、第 10-1-102 (13) 条所定义的保险人,以及受第 10-3-1104.9 条要求约束的关联实体,在从事保险业务时符合本第 17 部分的规定。如果保险人依本款第(一)项未被认定合规,则保险人应在其适用范围内,依照第 6-1-1704 (3) 条的披露要求,就其使用受规制 ADMT 实质性影响与保险业务有关的重大影响决定,提供通知和披露。\n二、本条不限制本第 17 部分对以下情形的适用:受第 10-3-1104.9 条要求约束的保险人和关联实体对与保险人雇佣或保险人雇佣机会有关的受规制 ADMT 的使用。\n三、第 6-1-1701、6-1-1702、6-1-1703、6-1-1704、6-1-1705 和 6-1-1706 条不适用于联邦《1996 年健康保险流通与责任法》(Health Insurance Portability and Accountability Act of 1996,42 U.S.C. 第 1320d 条至第 1320d-9 条)及依该联邦法律颁布的法规意义上的受规制实体(covered entity),也不适用于受规制实体为向其提供服务而聘用的业务关联方,前提是该受规制实体在科罗拉多州开展业务,但与雇佣或雇佣机会有关的重大影响决定除外。尽管有本项的前述规定,对于 45 CFR 160.103 所定义的作为医疗服务提供者的受规制实体,本项仅在医疗服务提供者从科罗拉多州境内的场所运营时适用。受规制实体应向患者提供关于使用先进技术(包括受规制 ADMT)的一般性通知,该通知可并入描述患者权利以及该受规制实体如何提供医疗服务的其他通知中。尽管有本项的前述规定,受规制实体使用受规制 ADMT 判定患者获得财务援助(包括第 25.5-3-502 条所述折扣医疗服务)的资格时,应向患者提供以下披露:\n(一)对重大影响决定以及受规制 ADMT 在该重大影响决定中的作用的通俗语言描述;\n(二)该受规制实体在作出资格判定时所依据的关于该个人的信息类型,但商业秘密及其他保密或受法律保护的信息除外;\n(三)关于如何请求更正该受规制实体持有的、符合联邦《1996 年健康保险流通与责任法》(42 U.S.C. 第 1320d 条至第 1320d-9 条)及第 25.5-3-502 条的实质不准确的个人数据的信息;以及\n(四)关于在适用情况下如何请求有意义的人工复核或重新考虑的信息。\n受规制实体可以通过以下任一方式遵守本项前述规定:或是事先一般性披露本项所要求的信息,或是在出现不利结果后的三十个日历日内提供通知。如果本项所述的复核机会和信息已予提供,则本条不创设单独或重复的披露程序或申诉程序。\n四、第 6-1-1701、6-1-1702、6-1-1703、6-1-1704、6-1-1705 和 6-1-1706 条不适用于受美国食品药品监督管理局(FDA)监管的医疗器械,或制药或医疗器械制造商受 FDA 监管的研究与开发活动,包括依据 21 CFR 312 开展的临床研究。\n五、本第 17 部分中的任何内容均不要求联邦《1996 年健康保险流通与责任法》(42 U.S.C. 第 1320d 条至第 1320d-9 条)所定义的受规制实体或业务关联方,以会违反联邦法律的方式披露受保护健康信息或其他信息。在遵守第 6-1-1704 条或第 6-1-1705 条会与联邦健康隐私要求相冲突的范围内,部署者应遵守适用的联邦法律,并提供与该法律一致的披露和查阅。\n六、本第 17 部分不要求任何人以会违反联邦《格雷姆-里奇-比利雷法》(Gramm-Leach-Bliley Act,15 U.S.C. 第 6801 条及以下各条)或其实施条例的方式披露非公开个人信息。\n6-1-1709. 不创设新的私人诉讼权——其他法律的适用。 一、本第 17 部分中的任何内容均不创设新的私人诉讼权。\n二、遵守本第 17 部分不构成对不遵守任何适用法律的抗辩,也不免除不遵守任何适用法律的责任。\n第 2 节 在《科罗拉多州修订法典》第 6-1-105 条中,增加 (1)(uuuu) 项如下: 6-1-105. 不公平或欺骗性交易行为。 一、当某人在其业务、职业或营业过程中实施下列行为时,该人即从事欺骗性交易行为:第(uuuu)项所述行为:\n(uuuu)违反本第 1 编第 17 部分。\n第 3 节 在《科罗拉多州修订法典》第 10-3-1104.9 条中,增加 (3)(e) 项如下: 10-3-1104.9. 保险人对外部消费者数据和信息来源、算法及预测模型的使用——禁止不公平歧视——规则——要求利益相关方程序——调查——定义。 (3)(e) 保险监管专员可以就保险人向消费者发出的通知和披露制定新规则或更新现有规则。\n第 4 节 拨款。就 2026-27 州财政年度,向法律部拨款 46,190 美元。该拨款来自普通基金,并基于该部将需要增加 0.4 个全职等效人员(FTE)的假设。为实施本法,该部可将该拨款用于消费者保护、反垄断和公民权利事务。 第 5 节 生效日——适用性。 一、除本条第二款另有规定外,本法自 2027 年 1 月 1 日起生效。\n二、《科罗拉多州修订法典》第 6-1-1704 (4) 条、第 6-1-1705 (3) 条和第 6-1-1706 (6) 条(经本法第 1 节修正)、经本法第 3 节制定的《科罗拉多州修订法典》第 10-3-1104.9 (3)(e) 条、本法第 4 节、本节以及本法第 6 节,自通过时生效。\n三、本法适用于 2027 年 1 月 1 日及之后作出的重大影响决定。\n第 6 节 安全条款。州议会认定、确定并宣布,本法对于立即维护公共和平、健康或安全,或对于为维持和供养州各部门及州属机构所需的拨款而言,是必要的。 批准日期:2026 年 5 月 14 日\n本译文由本网译整理,系非官方翻译(unofficial translation),仅供参考;如有歧义,以科罗拉多州官方法案文本为准。\n","permalink":"https://ai.intlaws.com/compliance/us/colorado-sb-26-189/","summary":"科罗拉多州参议院法案 26-189(2026 年法律第 131 章,2026 年 5 月 14 日批准)官方文本中文译校版: 对《科罗拉多隐私法》的人工智能修正,规制在重大影响决定中使用自动化决策技术(ADMT), 义务适用于 2027 年 1 月 1 日及之后作出的重大影响决定。本页为据官方英文文本译校的中文译本(非官方)。","title":"科罗拉多州参议院法案 26-189"},{"content":" 官方原文全文(英文) → General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 说明:欧盟法 24 种官方语言不含中文,故无官方中文文本。本页为导读与体例说明;逐条中文译校整理中,完成后在此提供入口。\n一、基本信息 项目 内容 正式名称 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 通称 General Data Protection Regulation(GDPR);中文通称「通用数据保护条例」 公布 《欧盟官方公报》L 119,2016 年 5 月 4 日,第 1–88 页(CELEX 32016R0679) 生效 2016 年 5 月 24 日(第 99 条第 1 款) 适用 2018 年 5 月 25 日起(第 99 条第 2 款) 取代 废止 1995 年《数据保护指令》(Directive 95/46/EC) 结构 序言(Whereas)(1)–(173);正文 11 章、99 条 官方来源 EUR-Lex 英文 HTML · CELEX 资源 二、章节结构(官方英文原文全文见上方入口) 章 标题 条 第一章 General provisions 第 1–4 条 第二章 Principles 第 5–11 条 第三章 Rights of the data subject 第 12–23 条 第四章 Controller and processor 第 24–43 条 第五章 Transfers of personal data to third countries or international organisations 第 44–50 条 第六章 Independent supervisory authorities 第 51–59 条 第七章 Cooperation and consistency 第 60–76 条 第八章 Remedies, liability and penalties 第 77–84 条 第九章 Provisions relating to specific processing situations 第 85–91 条 第十章 Delegated acts and implementing acts 第 92–93 条 第十一章 Final provisions 第 94–99 条 三、与本站其他欧盟法文件的关联 《人工智能法》(Regulation (EU) 2024/1689)中文导读 → 欧盟人工智能法 《人工智能法》官方英文原文全文(13 章 113 条 13 附件) → AI Act (full text) 跨境传输机制对照(GDPR 第五章 ↔ 中国个人信息出境路径)→ 见本站专题文章 ","permalink":"https://ai.intlaws.com/compliance/eu/gdpr/","summary":"欧盟《通用数据保护条例》(Regulation (EU) 2016/679)概况:11 章、99 条、173 段序言,2016 年 5 月 24 日生效, 2018 年 5 月 25 日起适用。\u003cstrong\u003e欧盟法仅以欧盟官方语言作准,无官方中文文本\u003c/strong\u003e;本站收录《官方公报》英文原文全文。","title":"通用数据保护条例（GDPR）"},{"content":"欧盟《人工智能法》（Regulation (EU) 2024/1689，下称 AI Act）的\u0026quot;全面生效\u0026quot;，大概是 2026 年被误读最多的一次生效。2026 年 8 月 2 日零点起，媒体标题多写作\u0026quot;欧盟 AI 法正式实施\u0026quot;，但打开 8 月 2 日真正切换的开关清单，会发现它比公众想象窄得多：真正咬人的是透明度义务与通用人工智能（GPAI）模型的执行机制；企业最害怕的高风险系统义务，已被 7 月 27 日生效的《数字综合修法》（Regulation (EU) 2026/1744，AI Omnibus）推迟到 2027 年 12 月。对打算把 AI 产品送进欧盟市场的企业——包括大量经由 API 接入模型的中国出海企业——此刻最重要的不是记住\u0026quot;AI Act 生效了\u0026quot;，而是分清这部法律五条适用轨道上，此刻各自走到了哪一站。\n一、五条轨道：此刻的适用格局 AI Act 第 113 条本来就设计了分档适用，《数字综合修法》又动了其中两档。截至本文写作日（2026-09-24），格局如下：\n轨道 适用（生效）时点 执行力时点 现状 第 5 条禁止行为（社会评分、操纵、利用弱点等） 2025-02-02 2026-08-02（市场监督框架到位） 已可被执法 GPAI 模型义务（第 53–55 条：透明度、版权、系统性风险） 2025-08-02 2026-08-02（AI Office 执行权启动） 已可被执法 第 50 条透明度义务（对话告知、合成内容标记、深度伪造标签） 2026-08-02 2026-08-02（同步） 已生效 附件 III 独立高风险系统义务 原定 2026-08-02，修法后 2027-12-02 同左 已推迟 附件 I 受监管产品内嵌高风险系统义务 原定 2027-08-02，修法后 2028-08-02 同左 已推迟 另有三个容易被漏掉的节点：其一，修法新增的 AI Act 第 111(4) 条给了\u0026quot;2026 年 8 月 2 日前已投放市场\u0026quot;的生成式系统一个过渡期——到 2026 年 12 月 2 日前，只须补齐第 50(2) 条的机器可读标记，告知类义务没有宽限；其二，非自愿亲密影像与儿童性虐待材料的生成/操纵禁令自 2026-12-02 起适用；其三，成员国国家监管沙盒的建设期限被顺延至 2027 年 8 月。\n罚则结构没有变化，且值得整个表格抄进合规手册：违反第 5 条禁止行为，最高 3500 万欧元或全球年营业额 7%；违反包括第 50 条透明度、GPAI 义务在内的其余多数义务，最高 1500 万欧元或 3%；向监管机构提供错误、不完整或误导性信息，最高 750 万欧元或 1%（AI Act 第 99 条）。\n二、8 月 2 日真正\u0026quot;上线\u0026quot;的是什么 第一块：第 50 条透明度义务。 四项义务同日生效：部署者必须让用户知道自己在与 AI 系统而非人互动（对话场景，除非从语境中显而易见）；合成音频、图像、视频、文本的提供者必须保证输出以机器可读格式标记、可被检测为人工生成或操纵；对暴露于情绪识别或生物特征分类系统的人负有告知义务；深度伪造内容与就公共利益事项发布的 AI 生成文本须予标注。委员会 2026 年 7 月 20 日发布的最终指南确认了几个实务要点：意图欺骗与否不影响深度伪造标注义务；艺术、讽刺、虚构作品只须\u0026quot;以不妨碍作品呈现的方式\u0026quot;披露存在生成或操纵；广播类场景的披露须持续、可被中途收看的观众捕捉。\n第二块：GPAI 执行机制。 GPAI 模型义务自 2025 年 8 月 2 日就已约束模型提供者，但整整一年里\u0026quot;规则约束着企业、却无人能执行\u0026quot;。2026 年 8 月 2 日起，委员会 AI Office 正式取得调查权（信息请求、模型评估、要求采取纠正措施直至限制模型公开可得性）与处罚权——对 GPAI 提供者最高可处 1500 万欧元或全球年营业额 3% 的罚款。同步开通了三条投诉入口：任何人的通用投诉工具（第 85 条）、举报人通道、以及面向下游提供者的专用通道。执法不再等待监管者主动出击——一条投诉、一个网页表单即可启动。\n第三块（常被忽略）：AI Office 管辖边界。《数字综合修法》把 AI Office 的专属管辖从 GPAI 模型扩展到两类系统：模型与系统出自同一企业集团的，以及集成于《数字服务法》下超大平台/搜索引擎的 AI。这条边界务必要画清楚：自己训练模型又自营产品的（OpenAI、Google 类），监管者是布鲁塞尔；经 API 使用别人模型的，监管者是各成员国市场监督机关。\n三、《数字综合修法》：推迟的是非 委员会给推迟的理由是成套的：协调标准尚未就绪（首个 AI 领域协调标准 EN 18286:2026 于 2026 年 7 月 12 日才经 CEN-CENELEC 登记册确认批准，十余项支撑高风险符合性评估的标准仍在制定）、多数成员国尚未按期限指定主管机关。批评者的理由同样成套：立法文本确定的期限经不起行业游说即告松动，向市场传递了\u0026quot;观望有利\u0026quot;的信号，且高风险义务本就是这部法律风险规制结构的核心。\n这是一个没有定论的争议，本文不下判语。 支持方可以援引委员会的立场：义务的可行性以标准与机构的存在为前提，强行按期适用只会制造普遍违法；反对方可以援引立法程序的事实：2024 年文本中的期限是经完整民主程序确定的，2026 年的修法是在行业两年施压后实现的。务实的企业只需注意一点：推迟不是豁免，2027 年 12 月 2 日与 2028 年 8 月 2 日已是修法后的固定日期，符合性评估、技术文档、人工监督等义务的内容一条未删。\n四、行为准则的双轨实验：两部准则，一个说\u0026quot;不\u0026quot;的 Meta 2026 年最具标本意义的，是同一家公司对两部自愿准则的相反选择。\nGPAI 行为准则（2025 年 7 月 10 日定稿，用以具体化 GPAI 义务）：官方名单所列 21 家签署（含 Amazon、Anthropic、Black Forest Labs、Cohere、Google、IBM、Microsoft、Mistral AI、OpenAI、ServiceNow 等）；Meta 公开拒绝签署——其首席全球事务官 Joel Kaplan 2025 年 7 月 18 日声明，该准则\u0026quot;给模型开发者带来大量法律不确定性，多项措施远超 AI Act 的范围\u0026quot;（据媒体转述的公开声明）；xAI 则只签署安全与保障章节，透明度与版权两项义务须\u0026quot;以其他充分方式\u0026quot;另行证明合规。在 AI Act 第 56 条的机制下，签署产生可反驳的合规推定；不签署者必须\u0026quot;向委员会演示其他充分的合规手段\u0026quot;——这意味着更多的信息请求、更高的执法优先级，且罚款裁量时无从轻情节。执行权一旦到位，这套差异立刻有了价格。\nAI 生成内容透明度行为准则（2026 年 7 月定稿）：委员会 7 月 31 日公布的首批签署方名单（当日新闻稿称逾 180 家组织，准则政策页则写约 190 家——两个官方口径略有出入，本文并存注明），分红提供者适用的第 1 部分与部署者适用的第 2 部分；官方点名第 1 部分签署方包括 Google、Meta、Microsoft、OpenAI、Mistral、Anthropic、Synthesia 等。名单上出现了 Meta——2025 年拒签 GPAI 准则的公司，2026 年签了内容标记准则。这个对比本身是一份无需注释的判读材料：内容标记已成为\u0026quot;桌面筹码\u0026quot;，连最高调的抵制者也认为公开抗辩不划算；而 GPAI 准则之争争的是别的东西——训练数据、版权、系统性风险评估的实质义务。\n这里埋着 AI Act 治理结构中最值得学界跟踪的争议：第 56 条的合规推定，使\u0026quot;自愿\u0026quot;准则实际成为了事实上的准入许可。支持者认为这保持了规制弹性，避免把快速演进的技术细节写死在条约文本里；批评者认为软法由此获得了硬法之实，却绕开了硬法的程序保障。两边都有道理，目前也无权威裁决——企业在策略上只需理解：不签署不是违法，但签署与不签署，在 2026 年 8 月 2 日之后是两种完全不同的监管处境。\n五、成员国短板：执法版图不均匀 委员会 7 月 31 日的新闻稿里有一句克制的话：有效执法\u0026quot;还取决于成员国适当指定并充分资源化其主管机关\u0026quot;。译成直白语言：成员国掉链子了。第 70 条要求各成员国在 2025 年 8 月 2 日前指定市场监督机关与通知机关；据第三方执法周报（2026 年 8 月，非官方统计），27 个成员国中仅 9 个同时指定了市场监督机关与通知机关；该报同时指出 8 月 2 日的沙盒期限在多数国家\u0026quot;覆盖不全\u0026quot;。德国《人工智能市场监督法》（KI-MIG）已于 2026 年 7 月 29 日生效，联邦网络局（BNetzA）即日起担任市场监督机关、单一联络点与投诉受理点——但即便算上德国，27 个成员国中完成双机关指定的仍只有 9 国，执法版图的不均匀由此可见。\n对企业的实际含义：同样的系统，在爱尔兰面对的是有名字、有联系方式的监管者，在六个空白成员国面对的是不确定性本身——案件会落在哪张桌子上无人能预先告知。但义务不因成员国迟延而中止：空白国积压的投诉，会在机关到位后苏醒。\n六、企业行动清单（中国出海企业视角） AI Act 第 2 条的域外效力使\u0026quot;在欧盟境内投放系统或其输出在欧盟境内被使用\u0026quot;的提供者与部署者落入管辖。据此，一份最低限度的行动清单：\n画出自己在执法版图上的位置：是否自研模型？（是 → AI Office；否 → 各成员国市场监督机关）在每个目标成员国查清主管机关是否已指定、名字是什么，留痕备查。 对上游模型提供者做尽职调查：签署 GPAI 准则没有？签了哪些章节？这已是实质性的供应商风险评估项，而非脚注。 逐项对照第 50 条：交互告知、合成内容机器可读标记（修法后须至少两层机器可读技术，如签名元数据＋不可感知水印——委员会明确单一技术不达标）、情绪识别告知、深度伪造标注。2026 年 8 月 2 日前已上线的存量系统，12 月 2 日前补齐标记一档；此后新上线者无任何宽限。 把投诉当作用例设计输入：三条投诉通道已开，一个不满的用户即可触发调查。透明度义务的可验证性（标签是否显著、告知是否清楚）比内部合规声明更接近风险源。 为 2027 年 12 月 2 日现在开始排期：高风险义务未删一项，符合性评估机构排队与协调标准落地之间存在时间差，观望到 2027 年再动手的企业大概率排不上队。 七、比较法一瞥：与 GDPR 及中国《生成式人工智能服务管理暂行办法》 两点对照，供国内读者定位。与 GDPR 的关系：AI Act 不是数据保护法的替代，而是叠加——第 50 条的透明度义务与 GDPR 第 13/14 条的告知义务并行不悖，前者管\u0026quot;这是 AI/这是合成内容\u0026quot;，后者管\u0026quot;你的数据被如何处理\u0026quot;；情绪识别在职场与教育场景本已为 GDPR/劳动法所限，AI Act 第 5 条再添禁令，两层义务取其严者；对既有 DPO 体系的企业，AI Act 第 50 条可直接挂接现有告知流程，边际成本不高。对中国出海企业，这意味着 DPO 与 AI 合规团队不能各管一段，须合并做一次映射。\n与中国规范的对照：中国《生成式人工智能服务管理暂行办法》（2023）与后续算法/深度合成规定，同样采用\u0026quot;生成内容标识＋显著提示\u0026quot;思路，2025 年 9 月生效的《人工智能生成合成内容标识办法》更把标识义务细化到显式与隐式两层——与 AI Act 第 50 条\u0026quot;显著标注＋机器可读标记\u0026quot;的双层结构惊人地趋同。差异在于执法结构：中国是垂直的备案与网信执法，欧盟是分权的市场监督＋统一投诉入口。趋同的是义务文本，分岔的是执行生态——这或许才是全球化企业真正要建两套台账的原因。\n结语 AI Act 的 2026 年，示范了超国家立法进入执行期后的真实形态：不是开关的\u0026quot;咔哒\u0026quot;一声，而是五条轨道各自的漫长爬坡——有的轨道已能开罚单，有的还在等标准和机构。对法律人，值得跟踪的问题至少有三个：合规推定机制下软法与硬法的边界、修法推迟对立法可信度的长期影响、以及一个只有九分之二七完备的成员国执法网络能否支撑一部号称全球标杆的法律。对实务人，问题只有一个：五条轨道上，你的产品在哪一条，下一站是哪天。\n参考来源（访问日期均为 2026-09-24；标注\u0026quot;官方\u0026quot;者为欧盟机构页面，标注\u0026quot;第三方\u0026quot;者请自行复核） 官方｜AI Act 条例文本：EUR-Lex，Regulation (EU) 2024/1689，https://eur-lex.europa.eu/eli/reg/2024/1689/oj 官方｜《数字综合修法》文本：EUR-Lex，Regulation (EU) 2026/1744（2026-07-08 签署、OJ 2026-07-24 刊布、07-27 生效），https://eur-lex.europa.eu/eli/reg/2026/1744/oj 官方｜委员会\u0026quot;AI Omnibus enters into force\u0026quot;（原文：\u0026ldquo;High-risk AI systems in Annex III: Rules apply starting 2 December 2027\u0026rdquo;；\u0026ldquo;Annex I: 2 August 2028\u0026rdquo;）：https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force 官方｜委员会 AI Act 执法框架页（AI Office 调查权/处罚权、管辖分工、2026-12-02 禁令节点）：https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act 官方｜委员会新闻稿\u0026quot;Commission starts enforcing AI Act rules…\u0026quot;（2026-07-31，IP/26/1714）：https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714 官方｜第 50 条透明度义务指南（最终版 2026-07-20）：https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations 官方｜AI 生成内容透明度行为准则及签署方名单（2026-07-31 公布，原文\u0026quot;About 190 organisations signed\u0026quot;；第 1 部分官方点名含 Meta、Google、Microsoft、OpenAI）：https://digital-strategy.ec.europa.eu/en/news/strong-backing-code-practice-transparency-ai-generated-content 官方｜GPAI 行为准则页（签署方名单 21 家；xAI 单列注明仅签安全与保障章）：https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai 官方｜AI Act Service Desk 第 99 条罚则、第 111 条过渡条款：https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99 、https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-111 第三方｜Meta 拒签 GPAI 准则的 Kaplan 声明（2025-07-18，媒体转述）：https://euperspectives.eu/2025/07/meta-ai-code 第三方｜AI in Europe 执法周报（2026-08，原文：\u0026ldquo;Only nine member states have designated both a market surveillance and a notifying authority\u0026rdquo;）：https://aiineurope.co/news/europe-act-tracker-2026-08-10 第三方｜EN 18286:2026 批准日（CEN-CENELEC 登记册 DOR=2026-07-12；本站已按登记册字段口径核验）：https://www.cencenelec.eu/ ","permalink":"https://ai.intlaws.com/forum/%E6%AC%A7%E7%9B%9F%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E6%B3%95%E5%88%86%E6%A1%A3%E7%94%9F%E6%95%88%E8%BF%9B%E8%A1%8C%E6%97%B6-%E5%BD%93%E4%B8%8B%E9%80%82%E7%94%A8%E6%A0%BC%E5%B1%80%E4%B8%8E%E4%BC%81%E4%B8%9A%E5%90%88%E8%A7%84%E8%A6%81%E7%82%B9/","summary":"拆解 AI Act 2026 年 8 月 2 日进入执行期后的真实适用格局：五条轨道各自走到哪一站，哪些义务真正\u0026quot;咬人\u0026quot;，AI Omnibus（Regulation (EU) 2026/1744）推迟了什么、没推迟什么，两部行为准则的双轨实验意味着什么，以及中国出海企业此刻该做的五件事。","title":"分档生效进行时：欧盟人工智能法的当下适用格局与企业合规要点"},{"content":" Sources: U.S. Federal Trade Commission (FTC) official website; California Privacy Protection Agency (CalPrivacy / CPPA) official website\nDate collected: 2026-09-23\nOfficial links: listed under each entry; all are directly accessible official pages (not home pages, not search-result pages)\nVerification: every holding below is quoted verbatim from the official English text; the quotations were checked sentence by sentence against the official pages\nJurisdiction: United States (federal / California)\nCase 1: Workado, LLC (f/k/a Content at Scale AI) — accuracy claims for an AI content-detection product Case/Matter number: FTC Matter/File No. 2323092 (from the \u0026ldquo;FTC Matter/File Number\u0026rdquo; field on the official case page) Authority: U.S. Federal Trade Commission (FTC) Date: final order approved and made final on 2025-08-28 (date of the official press release; the complaint was issued in April 2025) Applicable law: Section 5 of the FTC Act (unfair or deceptive acts or practices) [to verify] — the official press release does not cite the section; the official case page is tagged \u0026ldquo;deceptive/misleading conduct\u0026rdquo; Holding (official text): \u0026ldquo;The Federal Trade Commission has given final approval to an order against Workado, LLC, requiring the company to stop advertising the accuracy or efficacy of its artificial intelligence (AI) content detection products unless it has competent and reliable evidence showing those products are as accurate as claimed.\u0026rdquo;\n\u0026ldquo;Workado markets its AI Content Detector to consumers seeking to determine whether written content was developed using generative AI technology or if it was written by a human being. The company claimed that its AI Content Detector was developed using a wide range of material, including blog posts and Wikipedia entries, to make it more accurate for average users. The FTC\u0026rsquo;s April 2025 complaint alleges, however, that the AI model powering the AI Content Detector was trained or fine-tuned to effect…\u0026rdquo;\n\u0026ldquo;The final order is designed to ensure Workado does not engage in similar false, misleading, or unsupported advertising. Under the order, Workado: Is prohibited from making any representations about the effectiveness of any AI content detection product unless it is not misleading, and the company has competent and reliable evidence to support the claim at the time it is made; …\u0026rdquo;\nOfficial links: Case page (matter number, status): https://www.ftc.gov/legal-library/browse/cases-proceedings/2323092-content-scale-ai Press release (final order approved, 2025-08-28): https://www.ftc.gov/news-events/news/press-releases/2025/08/ftc-approves-final-order-against-workado-llc-which-misrepresented-accuracy-its-artificial Press release (April 2025 order requiring substantiation): https://www.ftc.gov/news-events/news/press-releases/2025/04/ftc-order-requires-workado-back-artificial-intelligence-detection-claims Jurisdiction: United States (federal) To verify: ① the exact signing/effective date of the final order (this entry uses the press-release date 2025-08-28 as the \u0026ldquo;final approval\u0026rdquo; milestone); ② the official case page shows \u0026ldquo;Case Status: Pending\u0026rdquo; alongside the fact that the final order was approved — the status field needs confirmation against the source; ③ the statutory provision (FTC Act §5) is not stated in the press release; ④ the last sentence of the second quotation is truncated on the official page. Case 2: GGL Projects, Inc. (d/b/a Sitejabber) — misleading ratings and reviews on an AI-enabled review platform Case/Matter number: [to verify] — the official case page does not list an \u0026ldquo;FTC Matter/File Number\u0026rdquo; field; case name: In the Matter of GGL Projects, Inc., a Corporation, also d/b/a Sitejabber. Authority: U.S. Federal Trade Commission (FTC) Date: complaint issued in November 2024 (official case page: \u0026ldquo;In a complaint issued in November 2024\u0026rdquo;); the date the final order was approved is [to verify] (the \u0026ldquo;Last Updated\u0026rdquo; field showing 2025-01-03 is a page-update date, not the order date) Applicable law: Section 5 of the FTC Act (deceptive acts or practices) [to verify] — to be confirmed against the order text Holding (official text): \u0026ldquo;In a complaint issued in November 2024, the FTC charged that Sitejabber deceived consumers by misrepresenting that ratings and reviews it published came from customers who experienced the reviewed product or service, artificially inflating average ratings and review counts. Under a proposed order settling the agency\u0026rsquo;s complaint, Sitejabber will be prohibited from making such misrepresentations and from making other misrepresentations about consumer ratings or reviews. The Commission approved the…\u0026rdquo;\nOfficial link: Case page (full description and press-release links): https://www.ftc.gov/legal-library/browse/cases-proceedings/sitejabber Jurisdiction: United States (federal) To verify: ① the FTC Matter/File Number (not listed on the case page); ② the date the final order was approved; ③ the \u0026ldquo;Case Status\u0026rdquo; field; ④ the final sentence is truncated on the official page. Case 3: FTC v. Evolv Technologies Holdings, Inc. — unsupported claims about an AI security-screening system Case/Matter number: Federal Trade Commission, Plaintiff, v. Evolv Technologies Holdings, Inc., a Corporation, Defendant.; docket number [to verify] (not listed on the case page) Authority: U.S. Federal Trade Commission (FTC, as plaintiff) Date: 2024-11-26 (date of the official press release) Applicable law: Section 5 of the FTC Act (deceptive acts or practices) [to verify] — to be confirmed against the order/complaint text Holding (official text): \u0026ldquo;The Federal Trade Commission is taking action against Evolv Technologies over allegations that the company made false claims about the extent to which its AI-powered security screening system can detect weapons and ignore harmless personal items, including in school settings.\u0026rdquo;\n\u0026ldquo;In the proposed FTC settlement order, Evolv would be banned from making unsupported claims about its products\u0026rsquo; ability…\u0026rdquo;\n(press-release subheading) \u0026ldquo;Proposed settlement would prohibit misrepresentations and allow affected schools to opt out of current contracts for security screening systems\u0026rdquo;\nOfficial links: Case page: https://www.ftc.gov/legal-library/browse/cases-proceedings/evolv-technologies Press release (2024-11-26): https://www.ftc.gov/news-events/news/press-releases/2024/11/ftc-takes-action-against-evolv-technologies-deceiving-users-about-its-ai-powered-security-screening Jurisdiction: United States (federal) To verify: ① docket/case number; ② final approval status and date of the proposed order; ③ the \u0026ldquo;Case Status\u0026rdquo; field; ④ the second quotation is truncated on the official page. Case 4: Tractor Supply Company — CCPA privacy-notice and job-applicant notice violations (largest fine in the agency\u0026rsquo;s history) Case/Matter number: Case No. ENF24-M-TR-04 (body of the decision; verified 2026-09-24 against the archived original) Authority: California Privacy Protection Agency (CPPA / CalPrivacy) Board Date: announcement date 2025-09-30; decision signed 2025-09-26 (\u0026ldquo;this 26th day of September, 2025\u0026rdquo; on the signature page; verified 2026-09-24) Applicable law: California Consumer Privacy Act (CCPA) — privacy-notice obligations and the obligation to inform consumers and job applicants of their rights Holding (official text): \u0026ldquo;SACRAMENTO – The California Privacy Protection Agency (CPPA) Board has issued a decision requiring Tractor Supply Company, the nation\u0026rsquo;s largest rural lifestyle retailer with more than 2,500 stores in 49 states, to change its business practices and pay a $1,350,000 fine to resolve claims that the company violated the California Consumer Privacy Act (CCPA). The fine is the largest in the CPPA\u0026rsquo;s history, and the decision is the first to address the importance of CCPA privacy notices and privacy rig…\u0026rdquo;\n\u0026ldquo;According to the Board\u0026rsquo;s decision, Tractor Supply violated Californians\u0026rsquo; privacy rights by: Failing to maintain a privacy policy that notified consumers of their rights; Failing to notify California job applicants of their privacy rights and how to exercise them; …\u0026rdquo;\n\u0026ldquo;To resolve the allegations, Tractor Supply agreed to pay $1,350,000, implement broad remedial measures, such as scanning its digital properties to inventory tracking technologies, and require a corporate officer or director to certify compliance annually for the next four years.\u0026rdquo;\nOfficial links: Announcement: https://cppa.ca.gov/announcements/2025/20250930.html Decision (linked from the announcement): https://cppa.ca.gov/pdf/20250930_tractor_supply_bd_sfo.pdf Jurisdiction: United States (California) To verify: ① the signature date and case number on the decision (the PDF is a scanned document; the text layer could not be extracted); ② the first quotation and the list of violations are truncated on the official page; ③ \u0026ldquo;largest fine in the CPPA\u0026rsquo;s history\u0026rdquo; is the agency\u0026rsquo;s own statement, not a comparison across decisions. Case 5: ROR Partners LLC — failure to register as a data broker under California\u0026rsquo;s Delete Act Case/Matter number: Case No. ENF25-245-D-RO (body of the decision; verified 2026-09-24 against the archived original) Authority: California Privacy Protection Agency (CPPA / CalPrivacy) Board Date: announcement date 2025-12-03; decision signed 2025-11-26 (template year 2025 + handwritten \u0026ldquo;26th November\u0026rdquo; on the signature page; verified 2026-09-24. The page\u0026rsquo;s \u0026lt;time\u0026gt; attribute 2025-11-20 is page metadata, a different node — conflict resolved). the date of signature on the decision governs) Applicable law: California Delete Act — annual registration obligation for data brokers Holding (official text): \u0026ldquo;SACRAMENTO, CA – The California Privacy Protection Agency Board has issued a decision requiring ROR Partners LLC, a Nevada-based marketing firm catering to fitness and wellness brands, to pay $56,600 in fines and past-due fees for failing to register as a data broker in violation of California\u0026rsquo;s Delete Act. The Enforcement Division brought the case as part of its …\u0026rdquo;\nOfficial links: Announcement: https://cppa.ca.gov/announcements/2025/20251203.html Decision (linked from the announcement): https://cppa.ca.gov/pdf/ror_partners_ood.pdf Jurisdiction: United States (California) To verify: ① the conflict between the announcement body date (2025-12-03) and the page\u0026rsquo;s \u0026lt;time datetime\u0026gt; value (2025-11-20) — the decision\u0026rsquo;s signature date governs; ② the decision PDF is a scanned document (no text layer); ③ case number. Appendix 1: two further verified entries that can be added Both entries below belong to the same CalPrivacy enforcement announcement of 2026-01-08 on data brokers. Because they share the same source and date as Case 5, and to avoid splitting a single enforcement announcement into multiple entries, they are listed here in tabular form pending separate entries per respondent.\n# Respondent Penalty Grounds Applicable law Announcement date Official link A Rickenbacher Data LLC (d/b/a Datamasters, Texas) $45,000 Failure to register as a data broker; resale of names, addresses, phone numbers and emails of individuals with health conditions including Alzheimer\u0026rsquo;s disease, drug addiction and bladder incontinence California Delete Act 2026-01-08 https://cppa.ca.gov/announcements/2026/20260108.html ; decision https://cppa.ca.gov/pdf/datamasters_order_signed.pdf B S\u0026amp;P Global, Inc. (New York) $62,600 Failure to register as a data broker owing to an administrative error; required to establish registration and compliance-audit procedures California Delete Act 2026-01-08 https://cppa.ca.gov/announcements/2026/20260108.html ; decision https://cppa.ca.gov/pdf/sp_global_inc_fo_signed.pdf The decisions for these two entries were not downloaded in this round; [to verify]: decision date and case number.\nAppendix 2: scope and limitations of this batch Change of authority name: the California Privacy Protection Agency (CPPA) moved all announcements to privacy.ca.gov as of 2026-01-26 and now uses the name CalPrivacy. Announcements from 2025 and earlier remain at cppa.ca.gov/announcements/ and those links remain valid. Date conventions: this batch consists of enforcement/penalty cases and therefore does not involve the \u0026ldquo;entry into force vs. date of application of compliance obligations\u0026rdquo; distinction. Note, however, that the annual data-broker registration obligation under the Delete Act falls due each January, a different kind of milestone from the announcement dates of each penalty; the two are labelled separately where listed together in this section. Sources used: all fields are taken solely from first-hand pages on the FTC and CalPrivacy/CPPA official websites and from official PDFs — no third-party republication and no law-firm commentary is used in the body text. ","permalink":"https://ai.intlaws.com/en/cases/us-enforcement-first-batch/","summary":"First batch of five enforcement/penalty cases from U.S. federal and California regulators in the fields of artificial intelligence, data privacy and data brokerage: three from the Federal Trade Commission (FTC) — accuracy claims for AI content detection, an AI-enabled review platform, and an AI security-screening system — and two from the California Privacy Protection Agency (CalPrivacy, formerly CPPA) — CCPA privacy-notice violations and data-broker registration violations. Each entry carries the four required elements, with holdings quoted verbatim from official documents and direct official links.","title":"Case Collection | AI and Data Protection Enforcement in the United States (First Batch: FTC and CalPrivacy)"},{"content":" Version \u0026amp; sources (verifiable)\nItem Content Adoption \u0026amp; promulgation 24 February 2023 (CAC Order No. 13) Effective date 1 June 2023 Currently in force Yes (as of 2026-09-23) Chinese original Official website of the Cyberspace Administration of China English translation No official English version. Translated by this journal from the official Chinese text and cross-checked article by article — unofficial translation, for reference only → 中文全文 Order of the Cyberspace Administration of China No. 13: The Measures for Standard Contract for Outbound Transfer of Personal Information, as adopted at the 2nd executive meeting of the Cyberspace Administration of China on 3 February 2023, are hereby promulgated and shall come into force on 1 June 2023.\nArticle 1 These Measures are formulated in accordance with the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and regulations for the purpose of protecting the rights and interests of personal information and regulating the outbound transfer of personal information.\nArticle 2 Where a personal information handler provides personal information abroad by entering into a standard contract with the overseas recipient in accordance with Article 38, paragraph 1, item 3 of the Personal Information Protection Law of the People\u0026rsquo;s Republic of China, these Measures shall apply.\nArticle 3 Outbound transfer of personal information by way of concluding a standard contract shall adhere to the combination of independent contracting and record-filing administration, and the combination of protecting rights and interests with preventing risks, so as to ensure the secure and free cross-border flow of personal information.\nArticle 4 Where a personal information handler provides personal information abroad by way of concluding a standard contract, it shall meet all of the following circumstances:\n(1) it is not a critical information infrastructure operator;\n(2) it processes the personal information of fewer than 1,000,000 individuals;\n(3) it has cumulatively provided abroad, since 1 January of the previous year, the personal information of fewer than 100,000 individuals; and\n(4) it has cumulatively provided abroad, since 1 January of the previous year, the sensitive personal information of fewer than 10,000 individuals.\nWhere laws, administrative regulations or the national cyberspace administration provide otherwise, those provisions shall prevail.\nA personal information handler shall not resort to means such as splitting quantities to provide abroad, by way of concluding a standard contract, personal information for which a security assessment of data export is required by law.\nArticle 5 Before providing personal information abroad, a personal information handler shall conduct a personal information protection impact assessment, focusing on the following matters:\n(1) the lawfulness, legitimacy and necessity of the purposes, scope and methods of the processing of personal information by the personal information handler and the overseas recipient;\n(2) the scale, scope, categories and sensitivity of the personal information to be exported, and the risks that the outbound transfer of personal information may pose to the rights and interests of individuals;\n(3) the obligations undertaken by the overseas recipient, and whether its management and technical measures, capabilities and the like for performing those obligations can guarantee the security of the personal information to be exported;\n(4) the risks of the personal information, after export, being tampered with, destroyed, leaked, lost, or illegally used, and whether the channels for safeguarding the rights and interests of individuals are unobstructed;\n(5) the impact of the personal information protection policies, laws and regulations of the country or region where the overseas recipient is located on the performance of the standard contract; and\n(6) other matters that may affect the security of the outbound transfer of personal information.\nArticle 6 The standard contract shall be concluded in strict accordance with the annex to these Measures. The national cyberspace administration may adjust the annex in light of actual circumstances.\nA personal information handler may agree with the overseas recipient on other terms, provided that such terms do not conflict with the standard contract.\nOutbound transfer of personal information may be carried out only after the standard contract takes effect.\nArticle 7 A personal information handler shall, within 10 working days from the date on which the standard contract takes effect, file the standard contract with the cyberspace administration of the province where it is located. The filing shall be accompanied by the following materials:\n(1) the standard contract; and\n(2) the personal information protection impact assessment report.\nA personal information handler shall be responsible for the authenticity of the materials filed.\nArticle 8 During the validity period of the standard contract, where any of the following circumstances occurs, the personal information handler shall conduct a personal information protection impact assessment anew, supplement or re-conclude the standard contract, and perform the corresponding filing procedures:\n(1) the purpose, scope, type, sensitivity, method, place of storage or retention period of the personal information provided abroad changes, or the purpose or method of processing by the overseas recipient changes, in a manner that may increase the risk to the rights and interests of individuals;\n(2) the laws, regulations or cybersecurity environment of the country or region where the overseas recipient is located changes in a manner that may increase the risk to the rights and interests of individuals; or\n(3) any other circumstance arises that may affect the rights and interests of individuals.\nArticle 9 Cyberspace administrations and their staff shall keep confidential the personal privacy, personal information, trade secrets and confidential business information obtained in the performance of their duties, and shall not disclose such information or provide it to others illegally, nor use it illegally.\nArticle 10 Any organisation or individual that discovers a personal information handler providing personal information abroad in violation of these Measures may report it to a cyberspace administration at or above the provincial level.\nArticle 11 Where a cyberspace administration at or above the provincial level discovers that an outbound personal information activity involves relatively large risks or that a personal information security incident has occurred, it may conduct regulatory talks with the personal information handler in accordance with the law. The personal information handler shall rectify as required and eliminate the risks.\nArticle 12 Where these Measures are violated, the case shall be handled in accordance with the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and regulations; where a crime is constituted, criminal responsibility shall be pursued according to law.\nArticle 13 These Measures shall come into force on 1 June 2023. Outbound personal information activities that have already been carried out before these Measures come into force and do not comply with the provisions of these Measures shall be rectified within 6 months from the date on which these Measures come into force.\n","permalink":"https://ai.intlaws.com/en/compliance/china/personal-information-exit-standard-contract/","summary":"English translation of China\u0026rsquo;s Measures for Standard Contract for Outbound Transfer of Personal Information (CAC Order No. 13, adopted 3 February 2023, effective 1 June 2023). Unofficial translation, for reference only.","title":"Measures for Standard Contract for Outbound Transfer of Personal Information"},{"content":" Version \u0026amp; sources (verifiable)\nItem Content Regulation Regulation (EU) 2024/1689 (Artificial Intelligence Act) Adopted 13 June 2024; OJ L series, 12.7.2024 Entry into force 1 August 2024 (staged application) Official text EUR-Lex OJ HTML · ELI Structure 13 chapters · 113 articles · 13 annexes (reproduced in full) Note Official EU languages only — no official Chinese version; 中文译本将据本官方文本另行译校并单独发布 Verification 2026-09-23 reproduced verbatim from EUR-Lex; article numbers 1–113 complete, no gaps REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL\nof 13 June 2024\nlaying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)\n(Text with EEA relevance)\nTHE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,\nHaving regard to the Treaty on the Functioning of the European Union, and in particular Articles 16 and 114 thereof,\nHaving regard to the proposal from the European Commission,\nAfter transmission of the draft legislative act to the national parliaments,\nHaving regard to the opinion of the European Economic and Social Committee (1),\nHaving regard to the opinion of the European Central Bank (2),\nHaving regard to the opinion of the Committee of the Regions (3),\nActing in accordance with the ordinary legislative procedure (4),\nWhereas:\n(1)\nThe purpose of this Regulation is to improve the functioning of the internal market by laying down a uniform legal framework in particular for the development, the placing on the market, the putting into service and the use of artificial intelligence systems (AI systems) in the Union, in accordance with Union values, to promote the uptake of human centric and trustworthy artificial intelligence (AI) while ensuring a high level of protection of health, safety, fundamental rights as enshrined in the Charter of Fundamental Rights of the European Union (the ‘Charter’), including democracy, the rule of law and environmental protection, to protect against the harmful effects of AI systems in the Union, and to support innovation. This Regulation ensures the free movement, cross-border, of AI-based goods and services, thus preventing Member States from imposing restrictions on the development, marketing and use of AI systems, unless explicitly authorised by this Regulation.\n(2)\nThis Regulation should be applied in accordance with the values of the Union enshrined as in the Charter, facilitating the protection of natural persons, undertakings, democracy, the rule of law and environmental protection, while boosting innovation and employment and making the Union a leader in the uptake of trustworthy AI.\n(3)\nAI systems can be easily deployed in a large variety of sectors of the economy and many parts of society, including across borders, and can easily circulate throughout the Union. Certain Member States have already explored the adoption of national rules to ensure that AI is trustworthy and safe and is developed and used in accordance with fundamental rights obligations. Diverging national rules may lead to the fragmentation of the internal market and may decrease legal certainty for operators that develop, import or use AI systems. A consistent and high level of protection throughout the Union should therefore be ensured in order to achieve trustworthy AI, while divergences hampering the free circulation, innovation, deployment and the uptake of AI systems and related products and services within the internal market should be prevented by laying down uniform obligations for operators and guaranteeing the uniform protection of overriding reasons of public interest and of rights of persons throughout the internal market on the basis of Article 114 of the Treaty on the Functioning of the European Union (TFEU). To the extent that this Regulation contains specific rules on the protection of individuals with regard to the processing of personal data concerning restrictions of the use of AI systems for remote biometric identification for the purpose of law enforcement, of the use of AI systems for risk assessments of natural persons for the purpose of law enforcement and of the use of AI systems of biometric categorisation for the purpose of law enforcement, it is appropriate to base this Regulation, in so far as those specific rules are concerned, on Article 16 TFEU. In light of those specific rules and the recourse to Article 16 TFEU, it is appropriate to consult the European Data Protection Board.\n(4)\nAI is a fast evolving family of technologies that contributes to a wide array of economic, environmental and societal benefits across the entire spectrum of industries and social activities. By improving prediction, optimising operations and resource allocation, and personalising digital solutions available for individuals and organisations, the use of AI can provide key competitive advantages to undertakings and support socially and environmentally beneficial outcomes, for example in healthcare, agriculture, food safety, education and training, media, sports, culture, infrastructure management, energy, transport and logistics, public services, security, justice, resource and energy efficiency, environmental monitoring, the conservation and restoration of biodiversity and ecosystems and climate change mitigation and adaptation.\n(5)\nAt the same time, depending on the circumstances regarding its specific application, use, and level of technological development, AI may generate risks and cause harm to public interests and fundamental rights that are protected by Union law. Such harm might be material or immaterial, including physical, psychological, societal or economic harm.\n(6)\nGiven the major impact that AI can have on society and the need to build trust, it is vital for AI and its regulatory framework to be developed in accordance with Union values as enshrined in Article 2 of the Treaty on European Union (TEU), the fundamental rights and freedoms enshrined in the Treaties and, pursuant to Article 6 TEU, the Charter. As a prerequisite, AI should be a human-centric technology. It should serve as a tool for people, with the ultimate aim of increasing human well-being.\n(7)\nIn order to ensure a consistent and high level of protection of public interests as regards health, safety and fundamental rights, common rules for high-risk AI systems should be established. Those rules should be consistent with the Charter, non-discriminatory and in line with the Union’s international trade commitments. They should also take into account the European Declaration on Digital Rights and Principles for the Digital Decade and the Ethics guidelines for trustworthy AI of the High-Level Expert Group on Artificial Intelligence (AI HLEG).\n(8)\nA Union legal framework laying down harmonised rules on AI is therefore needed to foster the development, use and uptake of AI in the internal market that at the same time meets a high level of protection of public interests, such as health and safety and the protection of fundamental rights, including democracy, the rule of law and environmental protection as recognised and protected by Union law. To achieve that objective, rules regulating the placing on the market, the putting into service and the use of certain AI systems should be laid down, thus ensuring the smooth functioning of the internal market and allowing those systems to benefit from the principle of free movement of goods and services. Those rules should be clear and robust in protecting fundamental rights, supportive of new innovative solutions, enabling a European ecosystem of public and private actors creating AI systems in line with Union values and unlocking the potential of the digital transformation across all regions of the Union. By laying down those rules as well as measures in support of innovation with a particular focus on small and medium enterprises (SMEs), including startups, this Regulation supports the objective of promoting the European human-centric approach to AI and being a global leader in the development of secure, trustworthy and ethical AI as stated by the European Council (5), and it ensures the protection of ethical principles, as specifically requested by the European Parliament (6).\n(9)\nHarmonised rules applicable to the placing on the market, the putting into service and the use of high-risk AI systems should be laid down consistently with Regulation (EC) No 765/2008 of the European Parliament and of the Council (7), Decision No 768/2008/EC of the European Parliament and of the Council (8) and Regulation (EU) 2019/1020 of the European Parliament and of the Council (9) (New Legislative Framework). The harmonised rules laid down in this Regulation should apply across sectors and, in line with the New Legislative Framework, should be without prejudice to existing Union law, in particular on data protection, consumer protection, fundamental rights, employment, and protection of workers, and product safety, to which this Regulation is complementary. As a consequence, all rights and remedies provided for by such Union law to consumers, and other persons on whom AI systems may have a negative impact, including as regards the compensation of possible damages pursuant to Council Directive 85/374/EEC (10) remain unaffected and fully applicable. Furthermore, in the context of employment and protection of workers, this Regulation should therefore not affect Union law on social policy and national labour law, in compliance with Union law, concerning employment and working conditions, including health and safety at work and the relationship between employers and workers. This Regulation should also not affect the exercise of fundamental rights as recognised in the Member States and at Union level, including the right or freedom to strike or to take other action covered by the specific industrial relations systems in Member States as well as the right to negotiate, to conclude and enforce collective agreements or to take collective action in accordance with national law. This Regulation should not affect the provisions aiming to improve working conditions in platform work laid down in a Directive of the European Parliament and of the Council on improving working conditions in platform work. Moreover, this Regulation aims to strengthen the effectiveness of such existing rights and remedies by establishing specific requirements and obligations, including in respect of the transparency, technical documentation and record-keeping of AI systems. Furthermore, the obligations placed on various operators involved in the AI value chain under this Regulation should apply without prejudice to national law, in compliance with Union law, having the effect of limiting the use of certain AI systems where such law falls outside the scope of this Regulation or pursues legitimate public interest objectives other than those pursued by this Regulation. For example, national labour law and law on the protection of minors, namely persons below the age of 18, taking into account the UNCRC General Comment No 25 (2021) on children’s rights in relation to the digital environment, insofar as they are not specific to AI systems and pursue other legitimate public interest objectives, should not be affected by this Regulation.\n(10)\nThe fundamental right to the protection of personal data is safeguarded in particular by Regulations (EU) 2016/679 (11) and (EU) 2018/1725 (12) of the European Parliament and of the Council and Directive (EU) 2016/680 of the European Parliament and of the Council (13). Directive 2002/58/EC of the European Parliament and of the Council (14) additionally protects private life and the confidentiality of communications, including by way of providing conditions for any storing of personal and non-personal data in, and access from, terminal equipment. Those Union legal acts provide the basis for sustainable and responsible data processing, including where data sets include a mix of personal and non-personal data. This Regulation does not seek to affect the application of existing Union law governing the processing of personal data, including the tasks and powers of the independent supervisory authorities competent to monitor compliance with those instruments. It also does not affect the obligations of providers and deployers of AI systems in their role as data controllers or processors stemming from Union or national law on the protection of personal data in so far as the design, the development or the use of AI systems involves the processing of personal data. It is also appropriate to clarify that data subjects continue to enjoy all the rights and guarantees awarded to them by such Union law, including the rights related to solely automated individual decision-making, including profiling. Harmonised rules for the placing on the market, the putting into service and the use of AI systems established under this Regulation should facilitate the effective implementation and enable the exercise of the data subjects’ rights and other remedies guaranteed under Union law on the protection of personal data and of other fundamental rights.\n(11)\nThis Regulation should be without prejudice to the provisions regarding the liability of providers of intermediary services as set out in Regulation (EU) 2022/2065 of the European Parliament and of the Council (15).\n(12)\nThe notion of ‘AI system’ in this Regulation should be clearly defined and should be closely aligned with the work of international organisations working on AI to ensure legal certainty, facilitate international convergence and wide acceptance, while providing the flexibility to accommodate the rapid technological developments in this field. Moreover, the definition should be based on key characteristics of AI systems that distinguish it from simpler traditional software systems or programming approaches and should not cover systems that are based on the rules defined solely by natural persons to automatically execute operations. A key characteristic of AI systems is their capability to infer. This capability to infer refers to the process of obtaining the outputs, such as predictions, content, recommendations, or decisions, which can influence physical and virtual environments, and to a capability of AI systems to derive models or algorithms, or both, from inputs or data. The techniques that enable inference while building an AI system include machine learning approaches that learn from data how to achieve certain objectives, and logic- and knowledge-based approaches that infer from encoded knowledge or symbolic representation of the task to be solved. The capacity of an AI system to infer transcends basic data processing by enabling learning, reasoning or modelling. The term ‘machine-based’ refers to the fact that AI systems run on machines. The reference to explicit or implicit objectives underscores that AI systems can operate according to explicit defined objectives or to implicit objectives. The objectives of the AI system may be different from the intended purpose of the AI system in a specific context. For the purposes of this Regulation, environments should be understood to be the contexts in which the AI systems operate, whereas outputs generated by the AI system reflect different functions performed by AI systems and include predictions, content, recommendations or decisions. AI systems are designed to operate with varying levels of autonomy, meaning that they have some degree of independence of actions from human involvement and of capabilities to operate without human intervention. The adaptiveness that an AI system could exhibit after deployment, refers to self-learning capabilities, allowing the system to change while in use. AI systems can be used on a stand-alone basis or as a component of a product, irrespective of whether the system is physically integrated into the product (embedded) or serves the functionality of the product without being integrated therein (non-embedded).\n(13)\nThe notion of ‘deployer’ referred to in this Regulation should be interpreted as any natural or legal person, including a public authority, agency or other body, using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity. Depending on the type of AI system, the use of the system may affect persons other than the deployer.\n(14)\nThe notion of ‘biometric data’ used in this Regulation should be interpreted in light of the notion of biometric data as defined in Article 4, point (14) of Regulation (EU) 2016/679, Article 3, point (18) of Regulation (EU) 2018/1725 and Article 3, point (13) of Directive (EU) 2016/680. Biometric data can allow for the authentication, identification or categorisation of natural persons and for the recognition of emotions of natural persons.\n(15)\nThe notion of ‘biometric identification’ referred to in this Regulation should be defined as the automated recognition of physical, physiological and behavioural human features such as the face, eye movement, body shape, voice, prosody, gait, posture, heart rate, blood pressure, odour, keystrokes characteristics, for the purpose of establishing an individual’s identity by comparing biometric data of that individual to stored biometric data of individuals in a reference database, irrespective of whether the individual has given its consent or not. This excludes AI systems intended to be used for biometric verification, which includes authentication, whose sole purpose is to confirm that a specific natural person is the person he or she claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having security access to premises.\n(16)\nThe notion of ‘biometric categorisation’ referred to in this Regulation should be defined as assigning natural persons to specific categories on the basis of their biometric data. Such specific categories can relate to aspects such as sex, age, hair colour, eye colour, tattoos, behavioural or personality traits, language, religion, membership of a national minority, sexual or political orientation. This does not include biometric categorisation systems that are a purely ancillary feature intrinsically linked to another commercial service, meaning that the feature cannot, for objective technical reasons, be used without the principal service, and the integration of that feature or functionality is not a means to circumvent the applicability of the rules of this Regulation. For example, filters categorising facial or body features used on online marketplaces could constitute such an ancillary feature as they can be used only in relation to the principal service which consists in selling a product by allowing the consumer to preview the display of the product on him or herself and help the consumer to make a purchase decision. Filters used on online social network services which categorise facial or body features to allow users to add or modify pictures or videos could also be considered to be ancillary feature as such filter cannot be used without the principal service of the social network services consisting in the sharing of content online.\n(17)\nThe notion of ‘remote biometric identification system’ referred to in this Regulation should be defined functionally, as an AI system intended for the identification of natural persons without their active involvement, typically at a distance, through the comparison of a person’s biometric data with the biometric data contained in a reference database, irrespectively of the particular technology, processes or types of biometric data used. Such remote biometric identification systems are typically used to perceive multiple persons or their behaviour simultaneously in order to facilitate significantly the identification of natural persons without their active involvement. This excludes AI systems intended to be used for biometric verification, which includes authentication, the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having security access to premises. That exclusion is justified by the fact that such systems are likely to have a minor impact on fundamental rights of natural persons compared to the remote biometric identification systems which may be used for the processing of the biometric data of a large number of persons without their active involvement. In the case of ‘real-time’ systems, the capturing of the biometric data, the comparison and the identification occur all instantaneously, near-instantaneously or in any event without a significant delay. In this regard, there should be no scope for circumventing the rules of this Regulation on the ‘real-time’ use of the AI systems concerned by providing for minor delays. ‘Real-time’ systems involve the use of ‘live’ or ‘near-live’ material, such as video footage, generated by a camera or other device with similar functionality. In the case of ‘post’ systems, in contrast, the biometric data has already been captured and the comparison and identification occur only after a significant delay. This involves material, such as pictures or video footage generated by closed circuit television cameras or private devices, which has been generated before the use of the system in respect of the natural persons concerned.\n(18)\nThe notion of ‘emotion recognition system’ referred to in this Regulation should be defined as an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data. The notion refers to emotions or intentions such as happiness, sadness, anger, surprise, disgust, embarrassment, excitement, shame, contempt, satisfaction and amusement. It does not include physical states, such as pain or fatigue, including, for example, systems used in detecting the state of fatigue of professional pilots or drivers for the purpose of preventing accidents. This does also not include the mere detection of readily apparent expressions, gestures or movements, unless they are used for identifying or inferring emotions. Those expressions can be basic facial expressions, such as a frown or a smile, or gestures such as the movement of hands, arms or head, or characteristics of a person’s voice, such as a raised voice or whispering.\n(19)\nFor the purposes of this Regulation the notion of ‘publicly accessible space’ should be understood as referring to any physical space that is accessible to an undetermined number of natural persons, and irrespective of whether the space in question is privately or publicly owned, irrespective of the activity for which the space may be used, such as for commerce, for example, shops, restaurants, cafés; for services, for example, banks, professional activities, hospitality; for sport, for example, swimming pools, gyms, stadiums; for transport, for example, bus, metro and railway stations, airports, means of transport; for entertainment, for example, cinemas, theatres, museums, concert and conference halls; or for leisure or otherwise, for example, public roads and squares, parks, forests, playgrounds. A space should also be classified as being publicly accessible if, regardless of potential capacity or security restrictions, access is subject to certain predetermined conditions which can be fulfilled by an undetermined number of persons, such as the purchase of a ticket or title of transport, prior registration or having a certain age. In contrast, a space should not be considered to be publicly accessible if access is limited to specific and defined natural persons through either Union or national law directly related to public safety or security or through the clear manifestation of will by the person having the relevant authority over the space. The factual possibility of access alone, such as an unlocked door or an open gate in a fence, does not imply that the space is publicly accessible in the presence of indications or circumstances suggesting the contrary, such as. signs prohibiting or restricting access. Company and factory premises, as well as offices and workplaces that are intended to be accessed only by relevant employees and service providers, are spaces that are not publicly accessible. Publicly accessible spaces should not include prisons or border control. Some other spaces may comprise both publicly accessible and non-publicly accessible spaces, such as the hallway of a private residential building necessary to access a doctor’s office or an airport. Online spaces are not covered, as they are not physical spaces. Whether a given space is accessible to the public should however be determined on a case-by-case basis, having regard to the specificities of the individual situation at hand.\n(20)\nIn order to obtain the greatest benefits from AI systems while protecting fundamental rights, health and safety and to enable democratic control, AI literacy should equip providers, deployers and affected persons with the necessary notions to make informed decisions regarding AI systems. Those notions may vary with regard to the relevant context and can include understanding the correct application of technical elements during the AI system’s development phase, the measures to be applied during its use, the suitable ways in which to interpret the AI system’s output, and, in the case of affected persons, the knowledge necessary to understand how decisions taken with the assistance of AI will have an impact on them. In the context of the application this Regulation, AI literacy should provide all relevant actors in the AI value chain with the insights required to ensure the appropriate compliance and its correct enforcement. Furthermore, the wide implementation of AI literacy measures and the introduction of appropriate follow-up actions could contribute to improving working conditions and ultimately sustain the consolidation, and innovation path of trustworthy AI in the Union. The European Artificial Intelligence Board (the ‘Board’) should support the Commission, to promote AI literacy tools, public awareness and understanding of the benefits, risks, safeguards, rights and obligations in relation to the use of AI systems. In cooperation with the relevant stakeholders, the Commission and the Member States should facilitate the drawing up of voluntary codes of conduct to advance AI literacy among persons dealing with the development, operation and use of AI.\n(21)\nIn order to ensure a level playing field and an effective protection of rights and freedoms of individuals across the Union, the rules established by this Regulation should apply to providers of AI systems in a non-discriminatory manner, irrespective of whether they are established within the Union or in a third country, and to deployers of AI systems established within the Union.\n(22)\nIn light of their digital nature, certain AI systems should fall within the scope of this Regulation even when they are not placed on the market, put into service, or used in the Union. This is the case, for example, where an operator established in the Union contracts certain services to an operator established in a third country in relation to an activity to be performed by an AI system that would qualify as high-risk. In those circumstances, the AI system used in a third country by the operator could process data lawfully collected in and transferred from the Union, and provide to the contracting operator in the Union the output of that AI system resulting from that processing, without that AI system being placed on the market, put into service or used in the Union. To prevent the circumvention of this Regulation and to ensure an effective protection of natural persons located in the Union, this Regulation should also apply to providers and deployers of AI systems that are established in a third country, to the extent the output produced by those systems is intended to be used in the Union. Nonetheless, to take into account existing arrangements and special needs for future cooperation with foreign partners with whom information and evidence is exchanged, this Regulation should not apply to public authorities of a third country and international organisations when acting in the framework of cooperation or international agreements concluded at Union or national level for law enforcement and judicial cooperation with the Union or the Member States, provided that the relevant third country or international organisation provides adequate safeguards with respect to the protection of fundamental rights and freedoms of individuals. Where relevant, this may cover activities of entities entrusted by the third countries to carry out specific tasks in support of such law enforcement and judicial cooperation. Such framework for cooperation or agreements have been established bilaterally between Member States and third countries or between the European Union, Europol and other Union agencies and third countries and international organisations. The authorities competent for supervision of the law enforcement and judicial authorities under this Regulation should assess whether those frameworks for cooperation or international agreements include adequate safeguards with respect to the protection of fundamental rights and freedoms of individuals. Recipient national authorities and Union institutions, bodies, offices and agencies making use of such outputs in the Union remain accountable to ensure their use complies with Union law. When those international agreements are revised or new ones are concluded in the future, the contracting parties should make utmost efforts to align those agreements with the requirements of this Regulation.\n(23)\nThis Regulation should also apply to Union institutions, bodies, offices and agencies when acting as a provider or deployer of an AI system.\n(24)\nIf, and insofar as, AI systems are placed on the market, put into service, or used with or without modification of such systems for military, defence or national security purposes, those should be excluded from the scope of this Regulation regardless of which type of entity is carrying out those activities, such as whether it is a public or private entity. As regards military and defence purposes, such exclusion is justified both by Article 4(2) TEU and by the specificities of the Member States’ and the common Union defence policy covered by Chapter 2 of Title V TEU that are subject to public international law, which is therefore the more appropriate legal framework for the regulation of AI systems in the context of the use of lethal force and other AI systems in the context of military and defence activities. As regards national security purposes, the exclusion is justified both by the fact that national security remains the sole responsibility of Member States in accordance with Article 4(2) TEU and by the specific nature and operational needs of national security activities and specific national rules applicable to those activities. Nonetheless, if an AI system developed, placed on the market, put into service or used for military, defence or national security purposes is used outside those temporarily or permanently for other purposes, for example, civilian or humanitarian purposes, law enforcement or public security purposes, such a system would fall within the scope of this Regulation. In that case, the entity using the AI system for other than military, defence or national security purposes should ensure the compliance of the AI system with this Regulation, unless the system is already compliant with this Regulation. AI systems placed on the market or put into service for an excluded purpose, namely military, defence or national security, and one or more non-excluded purposes, such as civilian purposes or law enforcement, fall within the scope of this Regulation and providers of those systems should ensure compliance with this Regulation. In those cases, the fact that an AI system may fall within the scope of this Regulation should not affect the possibility of entities carrying out national security, defence and military activities, regardless of the type of entity carrying out those activities, to use AI systems for national security, military and defence purposes, the use of which is excluded from the scope of this Regulation. An AI system placed on the market for civilian or law enforcement purposes which is used with or without modification for military, defence or national security purposes should not fall within the scope of this Regulation, regardless of the type of entity carrying out those activities.\n(25)\nThis Regulation should support innovation, should respect freedom of science, and should not undermine research and development activity. It is therefore necessary to exclude from its scope AI systems and models specifically developed and put into service for the sole purpose of scientific research and development. Moreover, it is necessary to ensure that this Regulation does not otherwise affect scientific research and development activity on AI systems or models prior to being placed on the market or put into service. As regards product-oriented research, testing and development activity regarding AI systems or models, the provisions of this Regulation should also not apply prior to those systems and models being put into service or placed on the market. That exclusion is without prejudice to the obligation to comply with this Regulation where an AI system falling into the scope of this Regulation is placed on the market or put into service as a result of such research and development activity and to the application of provisions on AI regulatory sandboxes and testing in real world conditions. Furthermore, without prejudice to the exclusion of AI systems specifically developed and put into service for the sole purpose of scientific research and development, any other AI system that may be used for the conduct of any research and development activity should remain subject to the provisions of this Regulation. In any event, any research and development activity should be carried out in accordance with recognised ethical and professional standards for scientific research and should be conducted in accordance with applicable Union law.\n(26)\nIn order to introduce a proportionate and effective set of binding rules for AI systems, a clearly defined risk-based approach should be followed. That approach should tailor the type and content of such rules to the intensity and scope of the risks that AI systems can generate. It is therefore necessary to prohibit certain unacceptable AI practices, to lay down requirements for high-risk AI systems and obligations for the relevant operators, and to lay down transparency obligations for certain AI systems.\n(27)\nWhile the risk-based approach is the basis for a proportionate and effective set of binding rules, it is important to recall the 2019 Ethics guidelines for trustworthy AI developed by the independent AI HLEG appointed by the Commission. In those guidelines, the AI HLEG developed seven non-binding ethical principles for AI which are intended to help ensure that AI is trustworthy and ethically sound. The seven principles include human agency and oversight; technical robustness and safety; privacy and data governance; transparency; diversity, non-discrimination and fairness; societal and environmental well-being and accountability. Without prejudice to the legally binding requirements of this Regulation and any other applicable Union law, those guidelines contribute to the design of coherent, trustworthy and human-centric AI, in line with the Charter and with the values on which the Union is founded. According to the guidelines of the AI HLEG, human agency and oversight means that AI systems are developed and used as a tool that serves people, respects human dignity and personal autonomy, and that is functioning in a way that can be appropriately controlled and overseen by humans. Technical robustness and safety means that AI systems are developed and used in a way that allows robustness in the case of problems and resilience against attempts to alter the use or performance of the AI system so as to allow unlawful use by third parties, and minimise unintended harm. Privacy and data governance means that AI systems are developed and used in accordance with privacy and data protection rules, while processing data that meets high standards in terms of quality and integrity. Transparency means that AI systems are developed and used in a way that allows appropriate traceability and explainability, while making humans aware that they communicate or interact with an AI system, as well as duly informing deployers of the capabilities and limitations of that AI system and affected persons about their rights. Diversity, non-discrimination and fairness means that AI systems are developed and used in a way that includes diverse actors and promotes equal access, gender equality and cultural diversity, while avoiding discriminatory impacts and unfair biases that are prohibited by Union or national law. Social and environmental well-being means that AI systems are developed and used in a sustainable and environmentally friendly manner as well as in a way to benefit all human beings, while monitoring and assessing the long-term impacts on the individual, society and democracy. The application of those principles should be translated, when possible, in the design and use of AI models. They should in any case serve as a basis for the drafting of codes of conduct under this Regulation. All stakeholders, including industry, academia, civil society and standardisation organisations, are encouraged to take into account, as appropriate, the ethical principles for the development of voluntary best practices and standards.\n(28)\nAside from the many beneficial uses of AI, it can also be misused and provide novel and powerful tools for manipulative, exploitative and social control practices. Such practices are particularly harmful and abusive and should be prohibited because they contradict Union values of respect for human dignity, freedom, equality, democracy and the rule of law and fundamental rights enshrined in the Charter, including the right to non-discrimination, to data protection and to privacy and the rights of the child.\n(29)\nAI-enabled manipulative techniques can be used to persuade persons to engage in unwanted behaviours, or to deceive them by nudging them into decisions in a way that subverts and impairs their autonomy, decision-making and free choices. The placing on the market, the putting into service or the use of certain AI systems with the objective to or the effect of materially distorting human behaviour, whereby significant harms, in particular having sufficiently important adverse impacts on physical, psychological health or financial interests are likely to occur, are particularly dangerous and should therefore be prohibited. Such AI systems deploy subliminal components such as audio, image, video stimuli that persons cannot perceive, as those stimuli are beyond human perception, or other manipulative or deceptive techniques that subvert or impair person’s autonomy, decision-making or free choice in ways that people are not consciously aware of those techniques or, where they are aware of them, can still be deceived or are not able to control or resist them. This could be facilitated, for example, by machine-brain interfaces or virtual reality as they allow for a higher degree of control of what stimuli are presented to persons, insofar as they may materially distort their behaviour in a significantly harmful manner. In addition, AI systems may also otherwise exploit the vulnerabilities of a person or a specific group of persons due to their age, disability within the meaning of Directive (EU) 2019/882 of the European Parliament and of the Council (16), or a specific social or economic situation that is likely to make those persons more vulnerable to exploitation such as persons living in extreme poverty, ethnic or religious minorities. Such AI systems can be placed on the market, put into service or used with the objective to or the effect of materially distorting the behaviour of a person and in a manner that causes or is reasonably likely to cause significant harm to that or another person or groups of persons, including harms that may be accumulated over time and should therefore be prohibited. It may not be possible to assume that there is an intention to distort behaviour where the distortion results from factors external to the AI system which are outside the control of the provider or the deployer, namely factors that may not be reasonably foreseeable and therefore not possible for the provider or the deployer of the AI system to mitigate. In any case, it is not necessary for the provider or the deployer to have the intention to cause significant harm, provided that such harm results from the manipulative or exploitative AI-enabled practices. The prohibitions for such AI practices are complementary to the provisions contained in Directive 2005/29/EC of the European Parliament and of the Council (17), in particular unfair commercial practices leading to economic or financial harms to consumers are prohibited under all circumstances, irrespective of whether they are put in place through AI systems or otherwise. The prohibitions of manipulative and exploitative practices in this Regulation should not affect lawful practices in the context of medical treatment such as psychological treatment of a mental disease or physical rehabilitation, when those practices are carried out in accordance with the applicable law and medical standards, for example explicit consent of the individuals or their legal representatives. In addition, common and legitimate commercial practices, for example in the field of advertising, that comply with the applicable law should not, in themselves, be regarded as constituting harmful manipulative AI-enabled practices.\n(30)\nBiometric categorisation systems that are based on natural persons’ biometric data, such as an individual person’s face or fingerprint, to deduce or infer an individuals’ political opinions, trade union membership, religious or philosophical beliefs, race, sex life or sexual orientation should be prohibited. That prohibition should not cover the lawful labelling, filtering or categorisation of biometric data sets acquired in line with Union or national law according to biometric data, such as the sorting of images according to hair colour or eye colour, which can for example be used in the area of law enforcement.\n(31)\nAI systems providing social scoring of natural persons by public or private actors may lead to discriminatory outcomes and the exclusion of certain groups. They may violate the right to dignity and non-discrimination and the values of equality and justice. Such AI systems evaluate or classify natural persons or groups thereof on the basis of multiple data points related to their social behaviour in multiple contexts or known, inferred or predicted personal or personality characteristics over certain periods of time. The social score obtained from such AI systems may lead to the detrimental or unfavourable treatment of natural persons or whole groups thereof in social contexts, which are unrelated to the context in which the data was originally generated or collected or to a detrimental treatment that is disproportionate or unjustified to the gravity of their social behaviour. AI systems entailing such unacceptable scoring practices and leading to such detrimental or unfavourable outcomes should therefore be prohibited. That prohibition should not affect lawful evaluation practices of natural persons that are carried out for a specific purpose in accordance with Union and national law.\n(32)\nThe use of AI systems for ‘real-time’ remote biometric identification of natural persons in publicly accessible spaces for the purpose of law enforcement is particularly intrusive to the rights and freedoms of the concerned persons, to the extent that it may affect the private life of a large part of the population, evoke a feeling of constant surveillance and indirectly dissuade the exercise of the freedom of assembly and other fundamental rights. Technical inaccuracies of AI systems intended for the remote biometric identification of natural persons can lead to biased results and entail discriminatory effects. Such possible biased results and discriminatory effects are particularly relevant with regard to age, ethnicity, race, sex or disabilities. In addition, the immediacy of the impact and the limited opportunities for further checks or corrections in relation to the use of such systems operating in real-time carry heightened risks for the rights and freedoms of the persons concerned in the context of, or impacted by, law enforcement activities.\n(33)\nThe use of those systems for the purpose of law enforcement should therefore be prohibited, except in exhaustively listed and narrowly defined situations, where the use is strictly necessary to achieve a substantial public interest, the importance of which outweighs the risks. Those situations involve the search for certain victims of crime including missing persons; certain threats to the life or to the physical safety of natural persons or of a terrorist attack; and the localisation or identification of perpetrators or suspects of the criminal offences listed in an annex to this Regulation, where those criminal offences are punishable in the Member State concerned by a custodial sentence or a detention order for a maximum period of at least four years and as they are defined in the law of that Member State. Such a threshold for the custodial sentence or detention order in accordance with national law contributes to ensuring that the offence should be serious enough to potentially justify the use of ‘real-time’ remote biometric identification systems. Moreover, the list of criminal offences provided in an annex to this Regulation is based on the 32 criminal offences listed in the Council Framework Decision 2002/584/JHA (18), taking into account that some of those offences are, in practice, likely to be more relevant than others, in that the recourse to ‘real-time’ remote biometric identification could, foreseeably, be necessary and proportionate to highly varying degrees for the practical pursuit of the localisation or identification of a perpetrator or suspect of the different criminal offences listed and having regard to the likely differences in the seriousness, probability and scale of the harm or possible negative consequences. An imminent threat to life or the physical safety of natural persons could also result from a serious disruption of critical infrastructure, as defined in Article 2, point (4) of Directive (EU) 2022/2557 of the European Parliament and of the Council (19), where the disruption or destruction of such critical infrastructure would result in an imminent threat to life or the physical safety of a person, including through serious harm to the provision of basic supplies to the population or to the exercise of the core function of the State. In addition, this Regulation should preserve the ability for law enforcement, border control, immigration or asylum authorities to carry out identity checks in the presence of the person concerned in accordance with the conditions set out in Union and national law for such checks. In particular, law enforcement, border control, immigration or asylum authorities should be able to use information systems, in accordance with Union or national law, to identify persons who, during an identity check, either refuse to be identified or are unable to state or prove their identity, without being required by this Regulation to obtain prior authorisation. This could be, for example, a person involved in a crime, being unwilling, or unable due to an accident or a medical condition, to disclose their identity to law enforcement authorities.\n(34)\nIn order to ensure that those systems are used in a responsible and proportionate manner, it is also important to establish that, in each of those exhaustively listed and narrowly defined situations, certain elements should be taken into account, in particular as regards the nature of the situation giving rise to the request and the consequences of the use for the rights and freedoms of all persons concerned and the safeguards and conditions provided for with the use. In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement should be deployed only to confirm the specifically targeted individual’s identity and should be limited to what is strictly necessary concerning the period of time, as well as the geographic and personal scope, having regard in particular to the evidence or indications regarding the threats, the victims or perpetrator. The use of the real-time remote biometric identification system in publicly accessible spaces should be authorised only if the relevant law enforcement authority has completed a fundamental rights impact assessment and, unless provided otherwise in this Regulation, has registered the system in the database as set out in this Regulation. The reference database of persons should be appropriate for each use case in each of the situations mentioned above.\n(35)\nEach use of a ‘real-time’ remote biometric identification system in publicly accessible spaces for the purpose of law enforcement should be subject to an express and specific authorisation by a judicial authority or by an independent administrative authority of a Member State whose decision is binding. Such authorisation should, in principle, be obtained prior to the use of the AI system with a view to identifying a person or persons. Exceptions to that rule should be allowed in duly justified situations on grounds of urgency, namely in situations where the need to use the systems concerned is such as to make it effectively and objectively impossible to obtain an authorisation before commencing the use of the AI system. In such situations of urgency, the use of the AI system should be restricted to the absolute minimum necessary and should be subject to appropriate safeguards and conditions, as determined in national law and specified in the context of each individual urgent use case by the law enforcement authority itself. In addition, the law enforcement authority should in such situations request such authorisation while providing the reasons for not having been able to request it earlier, without undue delay and at the latest within 24 hours. If such an authorisation is rejected, the use of real-time biometric identification systems linked to that authorisation should cease with immediate effect and all the data related to such use should be discarded and deleted. Such data includes input data directly acquired by an AI system in the course of the use of such system as well as the results and outputs of the use linked to that authorisation. It should not include input that is legally acquired in accordance with another Union or national law. In any case, no decision producing an adverse legal effect on a person should be taken based solely on the output of the remote biometric identification system.\n(36)\nIn order to carry out their tasks in accordance with the requirements set out in this Regulation as well as in national rules, the relevant market surveillance authority and the national data protection authority should be notified of each use of the real-time biometric identification system. Market surveillance authorities and the national data protection authorities that have been notified should submit to the Commission an annual report on the use of real-time biometric identification systems.\n(37)\nFurthermore, it is appropriate to provide, within the exhaustive framework set by this Regulation that such use in the territory of a Member State in accordance with this Regulation should only be possible where and in as far as the Member State concerned has decided to expressly provide for the possibility to authorise such use in its detailed rules of national law. Consequently, Member States remain free under this Regulation not to provide for such a possibility at all or to only provide for such a possibility in respect of some of the objectives capable of justifying authorised use identified in this Regulation. Such national rules should be notified to the Commission within 30 days of their adoption.\n(38)\nThe use of AI systems for real-time remote biometric identification of natural persons in publicly accessible spaces for the purpose of law enforcement necessarily involves the processing of biometric data. The rules of this Regulation that prohibit, subject to certain exceptions, such use, which are based on Article 16 TFEU, should apply as lex specialis in respect of the rules on the processing of biometric data contained in Article 10 of Directive (EU) 2016/680, thus regulating such use and the processing of biometric data involved in an exhaustive manner. Therefore, such use and processing should be possible only in as far as it is compatible with the framework set by this Regulation, without there being scope, outside that framework, for the competent authorities, where they act for purpose of law enforcement, to use such systems and process such data in connection thereto on the grounds listed in Article 10 of Directive (EU) 2016/680. In that context, this Regulation is not intended to provide the legal basis for the processing of personal data under Article 8 of Directive (EU) 2016/680. However, the use of real-time remote biometric identification systems in publicly accessible spaces for purposes other than law enforcement, including by competent authorities, should not be covered by the specific framework regarding such use for the purpose of law enforcement set by this Regulation. Such use for purposes other than law enforcement should therefore not be subject to the requirement of an authorisation under this Regulation and the applicable detailed rules of national law that may give effect to that authorisation.\n(39)\nAny processing of biometric data and other personal data involved in the use of AI systems for biometric identification, other than in connection to the use of real-time remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement as regulated by this Regulation, should continue to comply with all requirements resulting from Article 10 of Directive (EU) 2016/680. For purposes other than law enforcement, Article 9(1) of Regulation (EU) 2016/679 and Article 10(1) of Regulation (EU) 2018/1725 prohibit the processing of biometric data subject to limited exceptions as provided in those Articles. In the application of Article 9(1) of Regulation (EU) 2016/679, the use of remote biometric identification for purposes other than law enforcement has already been subject to prohibition decisions by national data protection authorities.\n(40)\nIn accordance with Article 6a of Protocol No 21 on the position of the United Kingdom and Ireland in respect of the area of freedom, security and justice, as annexed to the TEU and to the TFEU, Ireland is not bound by the rules laid down in Article 5(1), first subparagraph, point (g), to the extent it applies to the use of biometric categorisation systems for activities in the field of police cooperation and judicial cooperation in criminal matters, Article 5(1), first subparagraph, point (d), to the extent it applies to the use of AI systems covered by that provision, Article 5(1), first subparagraph, point (h), Article 5(2) to (6) and Article 26(10) of this Regulation adopted on the basis of Article 16 TFEU which relate to the processing of personal data by the Member States when carrying out activities falling within the scope of Chapter 4 or Chapter 5 of Title V of Part Three of the TFEU, where Ireland is not bound by the rules governing the forms of judicial cooperation in criminal matters or police cooperation which require compliance with the provisions laid down on the basis of Article 16 TFEU.\n(41)\nIn accordance with Articles 2 and 2a of Protocol No 22 on the position of Denmark, annexed to the TEU and to the TFEU, Denmark is not bound by rules laid down in Article 5(1), first subparagraph, point (g), to the extent it applies to the use of biometric categorisation systems for activities in the field of police cooperation and judicial cooperation in criminal matters, Article 5(1), first subparagraph, point (d), to the extent it applies to the use of AI systems covered by that provision, Article 5(1), first subparagraph, point (h), (2) to (6) and Article 26(10) of this Regulation adopted on the basis of Article 16 TFEU, or subject to their application, which relate to the processing of personal data by the Member States when carrying out activities falling within the scope of Chapter 4 or Chapter 5 of Title V of Part Three of the TFEU.\n(42)\nIn line with the presumption of innocence, natural persons in the Union should always be judged on their actual behaviour. Natural persons should never be judged on AI-predicted behaviour based solely on their profiling, personality traits or characteristics, such as nationality, place of birth, place of residence, number of children, level of debt or type of car, without a reasonable suspicion of that person being involved in a criminal activity based on objective verifiable facts and without human assessment thereof. Therefore, risk assessments carried out with regard to natural persons in order to assess the likelihood of their offending or to predict the occurrence of an actual or potential criminal offence based solely on profiling them or on assessing their personality traits and characteristics should be prohibited. In any case, that prohibition does not refer to or touch upon risk analytics that are not based on the profiling of individuals or on the personality traits and characteristics of individuals, such as AI systems using risk analytics to assess the likelihood of financial fraud by undertakings on the basis of suspicious transactions or risk analytic tools to predict the likelihood of the localisation of narcotics or illicit goods by customs authorities, for example on the basis of known trafficking routes.\n(43)\nThe placing on the market, the putting into service for that specific purpose, or the use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage, should be prohibited because that practice adds to the feeling of mass surveillance and can lead to gross violations of fundamental rights, including the right to privacy.\n(44)\nThere are serious concerns about the scientific basis of AI systems aiming to identify or infer emotions, particularly as expression of emotions vary considerably across cultures and situations, and even within a single individual. Among the key shortcomings of such systems are the limited reliability, the lack of specificity and the limited generalisability. Therefore, AI systems identifying or inferring emotions or intentions of natural persons on the basis of their biometric data may lead to discriminatory outcomes and can be intrusive to the rights and freedoms of the concerned persons. Considering the imbalance of power in the context of work or education, combined with the intrusive nature of these systems, such systems could lead to detrimental or unfavourable treatment of certain natural persons or whole groups thereof. Therefore, the placing on the market, the putting into service, or the use of AI systems intended to be used to detect the emotional state of individuals in situations related to the workplace and education should be prohibited. That prohibition should not cover AI systems placed on the market strictly for medical or safety reasons, such as systems intended for therapeutical use.\n(45)\nPractices that are prohibited by Union law, including data protection law, non-discrimination law, consumer protection law, and competition law, should not be affected by this Regulation.\n(46)\nHigh-risk AI systems should only be placed on the Union market, put into service or used if they comply with certain mandatory requirements. Those requirements should ensure that high-risk AI systems available in the Union or whose output is otherwise used in the Union do not pose unacceptable risks to important Union public interests as recognised and protected by Union law. On the basis of the New Legislative Framework, as clarified in the Commission notice ‘The “Blue Guide” on the implementation of EU product rules 2022’ (20), the general rule is that more than one legal act of Union harmonisation legislation, such as Regulations (EU) 2017/745 (21) and (EU) 2017/746 (22) of the European Parliament and of the Council or Directive 2006/42/EC of the European Parliament and of the Council (23), may be applicable to one product, since the making available or putting into service can take place only when the product complies with all applicable Union harmonisation legislation. To ensure consistency and avoid unnecessary administrative burdens or costs, providers of a product that contains one or more high-risk AI systems, to which the requirements of this Regulation and of the Union harmonisation legislation listed in an annex to this Regulation apply, should have flexibility with regard to operational decisions on how to ensure compliance of a product that contains one or more AI systems with all applicable requirements of the Union harmonisation legislation in an optimal manner. AI systems identified as high-risk should be limited to those that have a significant harmful impact on the health, safety and fundamental rights of persons in the Union and such limitation should minimise any potential restriction to international trade.\n(47)\nAI systems could have an adverse impact on the health and safety of persons, in particular when such systems operate as safety components of products. Consistent with the objectives of Union harmonisation legislation to facilitate the free movement of products in the internal market and to ensure that only safe and otherwise compliant products find their way into the market, it is important that the safety risks that may be generated by a product as a whole due to its digital components, including AI systems, are duly prevented and mitigated. For instance, increasingly autonomous robots, whether in the context of manufacturing or personal assistance and care should be able to safely operate and performs their functions in complex environments. Similarly, in the health sector where the stakes for life and health are particularly high, increasingly sophisticated diagnostics systems and systems supporting human decisions should be reliable and accurate.\n(48)\nThe extent of the adverse impact caused by the AI system on the fundamental rights protected by the Charter is of particular relevance when classifying an AI system as high risk. Those rights include the right to human dignity, respect for private and family life, protection of personal data, freedom of expression and information, freedom of assembly and of association, the right to non-discrimination, the right to education, consumer protection, workers’ rights, the rights of persons with disabilities, gender equality, intellectual property rights, the right to an effective remedy and to a fair trial, the right of defence and the presumption of innocence, and the right to good administration. In addition to those rights, it is important to highlight the fact that children have specific rights as enshrined in Article 24 of the Charter and in the United Nations Convention on the Rights of the Child, further developed in the UNCRC General Comment No 25 as regards the digital environment, both of which require consideration of the children’s vulnerabilities and provision of such protection and care as necessary for their well-being. The fundamental right to a high level of environmental protection enshrined in the Charter and implemented in Union policies should also be considered when assessing the severity of the harm that an AI system can cause, including in relation to the health and safety of persons.\n(49)\nAs regards high-risk AI systems that are safety components of products or systems, or which are themselves products or systems falling within the scope of Regulation (EC) No 300/2008 of the European Parliament and of the Council (24), Regulation (EU) No 167/2013 of the European Parliament and of the Council (25), Regulation (EU) No 168/2013 of the European Parliament and of the Council (26), Directive 2014/90/EU of the European Parliament and of the Council (27), Directive (EU) 2016/797 of the European Parliament and of the Council (28), Regulation (EU) 2018/858 of the European Parliament and of the Council (29), Regulation (EU) 2018/1139 of the European Parliament and of the Council (30), and Regulation (EU) 2019/2144 of the European Parliament and of the Council (31), it is appropriate to amend those acts to ensure that the Commission takes into account, on the basis of the technical and regulatory specificities of each sector, and without interfering with existing governance, conformity assessment and enforcement mechanisms and authorities established therein, the mandatory requirements for high-risk AI systems laid down in this Regulation when adopting any relevant delegated or implementing acts on the basis of those acts.\n(50)\nAs regards AI systems that are safety components of products, or which are themselves products, falling within the scope of certain Union harmonisation legislation listed in an annex to this Regulation, it is appropriate to classify them as high-risk under this Regulation if the product concerned undergoes the conformity assessment procedure with a third-party conformity assessment body pursuant to that relevant Union harmonisation legislation. In particular, such products are machinery, toys, lifts, equipment and protective systems intended for use in potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft equipment, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, automotive and aviation.\n(51)\nThe classification of an AI system as high-risk pursuant to this Regulation should not necessarily mean that the product whose safety component is the AI system, or the AI system itself as a product, is considered to be high-risk under the criteria established in the relevant Union harmonisation legislation that applies to the product. This is, in particular, the case for Regulations (EU) 2017/745 and (EU) 2017/746, where a third-party conformity assessment is provided for medium-risk and high-risk products.\n(52)\nAs regards stand-alone AI systems, namely high-risk AI systems other than those that are safety components of products, or that are themselves products, it is appropriate to classify them as high-risk if, in light of their intended purpose, they pose a high risk of harm to the health and safety or the fundamental rights of persons, taking into account both the severity of the possible harm and its probability of occurrence and they are used in a number of specifically pre-defined areas specified in this Regulation. The identification of those systems is based on the same methodology and criteria envisaged also for any future amendments of the list of high-risk AI systems that the Commission should be empowered to adopt, via delegated acts, to take into account the rapid pace of technological development, as well as the potential changes in the use of AI systems.\n(53)\nIt is also important to clarify that there may be specific cases in which AI systems referred to in pre-defined areas specified in this Regulation do not lead to a significant risk of harm to the legal interests protected under those areas because they do not materially influence the decision-making or do not harm those interests substantially. For the purposes of this Regulation, an AI system that does not materially influence the outcome of decision-making should be understood to be an AI system that does not have an impact on the substance, and thereby the outcome, of decision-making, whether human or automated. An AI system that does not materially influence the outcome of decision-making could include situations in which one or more of the following conditions are fulfilled. The first such condition should be that the AI system is intended to perform a narrow procedural task, such as an AI system that transforms unstructured data into structured data, an AI system that classifies incoming documents into categories or an AI system that is used to detect duplicates among a large number of applications. Those tasks are of such narrow and limited nature that they pose only limited risks which are not increased through the use of an AI system in a context that is listed as a high-risk use in an annex to this Regulation. The second condition should be that the task performed by the AI system is intended to improve the result of a previously completed human activity that may be relevant for the purposes of the high-risk uses listed in an annex to this Regulation. Considering those characteristics, the AI system provides only an additional layer to a human activity with consequently lowered risk. That condition would, for example, apply to AI systems that are intended to improve the language used in previously drafted documents, for example in relation to professional tone, academic style of language or by aligning text to a certain brand messaging. The third condition should be that the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns. The risk would be lowered because the use of the AI system follows a previously completed human assessment which it is not meant to replace or influence, without proper human review. Such AI systems include for instance those that, given a certain grading pattern of a teacher, can be used to check ex post whether the teacher may have deviated from the grading pattern so as to flag potential inconsistencies or anomalies. The fourth condition should be that the AI system is intended to perform a task that is only preparatory to an assessment relevant for the purposes of the AI systems listed in an annex to this Regulation, thus making the possible impact of the output of the system very low in terms of representing a risk for the assessment to follow. That condition covers, inter alia, smart solutions for file handling, which include various functions from indexing, searching, text and speech processing or linking data to other data sources, or AI systems used for translation of initial documents. In any case, AI systems used in high-risk use-cases listed in an annex to this Regulation should be considered to pose significant risks of harm to the health, safety or fundamental rights if the AI system implies profiling within the meaning of Article 4, point (4) of Regulation (EU) 2016/679 or Article 3, point (4) of Directive (EU) 2016/680 or Article 3, point (5) of Regulation (EU) 2018/1725. To ensure traceability and transparency, a provider who considers that an AI system is not high-risk on the basis of the conditions referred to above should draw up documentation of the assessment before that system is placed on the market or put into service and should provide that documentation to national competent authorities upon request. Such a provider should be obliged to register the AI system in the EU database established under this Regulation. With a view to providing further guidance for the practical implementation of the conditions under which the AI systems listed in an annex to this Regulation are, on an exceptional basis, non-high-risk, the Commission should, after consulting the Board, provide guidelines specifying that practical implementation, completed by a comprehensive list of practical examples of use cases of AI systems that are high-risk and use cases that are not.\n(54)\nAs biometric data constitutes a special category of personal data, it is appropriate to classify as high-risk several critical-use cases of biometric systems, insofar as their use is permitted under relevant Union and national law. Technical inaccuracies of AI systems intended for the remote biometric identification of natural persons can lead to biased results and entail discriminatory effects. The risk of such biased results and discriminatory effects is particularly relevant with regard to age, ethnicity, race, sex or disabilities. Remote biometric identification systems should therefore be classified as high-risk in view of the risks that they pose. Such a classification excludes AI systems intended to be used for biometric verification, including authentication, the sole purpose of which is to confirm that a specific natural person is who that person claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having secure access to premises. In addition, AI systems intended to be used for biometric categorisation according to sensitive attributes or characteristics protected under Article 9(1) of Regulation (EU) 2016/679 on the basis of biometric data, in so far as these are not prohibited under this Regulation, and emotion recognition systems that are not prohibited under this Regulation, should be classified as high-risk. Biometric systems which are intended to be used solely for the purpose of enabling cybersecurity and personal data protection measures should not be considered to be high-risk AI systems.\n(55)\nAs regards the management and operation of critical infrastructure, it is appropriate to classify as high-risk the AI systems intended to be used as safety components in the management and operation of critical digital infrastructure as listed in point (8) of the Annex to Directive (EU) 2022/2557, road traffic and the supply of water, gas, heating and electricity, since their failure or malfunctioning may put at risk the life and health of persons at large scale and lead to appreciable disruptions in the ordinary conduct of social and economic activities. Safety components of critical infrastructure, including critical digital infrastructure, are systems used to directly protect the physical integrity of critical infrastructure or the health and safety of persons and property but which are not necessary in order for the system to function. The failure or malfunctioning of such components might directly lead to risks to the physical integrity of critical infrastructure and thus to risks to health and safety of persons and property. Components intended to be used solely for cybersecurity purposes should not qualify as safety components. Examples of safety components of such critical infrastructure may include systems for monitoring water pressure or fire alarm controlling systems in cloud computing centres.\n(56)\nThe deployment of AI systems in education is important to promote high-quality digital education and training and to allow all learners and teachers to acquire and share the necessary digital skills and competences, including media literacy, and critical thinking, to take an active part in the economy, society, and in democratic processes. However, AI systems used in education or vocational training, in particular for determining access or admission, for assigning persons to educational and vocational training institutions or programmes at all levels, for evaluating learning outcomes of persons, for assessing the appropriate level of education for an individual and materially influencing the level of education and training that individuals will receive or will be able to access or for monitoring and detecting prohibited behaviour of students during tests should be classified as high-risk AI systems, since they may determine the educational and professional course of a person’s life and therefore may affect that person’s ability to secure a livelihood. When improperly designed and used, such systems may be particularly intrusive and may violate the right to education and training as well as the right not to be discriminated against and perpetuate historical patterns of discrimination, for example against women, certain age groups, persons with disabilities, or persons of certain racial or ethnic origins or sexual orientation.\n(57)\nAI systems used in employment, workers management and access to self-employment, in particular for the recruitment and selection of persons, for making decisions affecting terms of the work-related relationship, promotion and termination of work-related contractual relationships, for allocating tasks on the basis of individual behaviour, personal traits or characteristics and for monitoring or evaluation of persons in work-related contractual relationships, should also be classified as high-risk, since those systems may have an appreciable impact on future career prospects, livelihoods of those persons and workers’ rights. Relevant work-related contractual relationships should, in a meaningful manner, involve employees and persons providing services through platforms as referred to in the Commission Work Programme 2021. Throughout the recruitment process and in the evaluation, promotion, or retention of persons in work-related contractual relationships, such systems may perpetuate historical patterns of discrimination, for example against women, certain age groups, persons with disabilities, or persons of certain racial or ethnic origins or sexual orientation. AI systems used to monitor the performance and behaviour of such persons may also undermine their fundamental rights to data protection and privacy.\n(58)\nAnother area in which the use of AI systems deserves special consideration is the access to and enjoyment of certain essential private and public services and benefits necessary for people to fully participate in society or to improve one’s standard of living. In particular, natural persons applying for or receiving essential public assistance benefits and services from public authorities namely healthcare services, social security benefits, social services providing protection in cases such as maternity, illness, industrial accidents, dependency or old age and loss of employment and social and housing assistance, are typically dependent on those benefits and services and in a vulnerable position in relation to the responsible authorities. If AI systems are used for determining whether such benefits and services should be granted, denied, reduced, revoked or reclaimed by authorities, including whether beneficiaries are legitimately entitled to such benefits or services, those systems may have a significant impact on persons’ livelihood and may infringe their fundamental rights, such as the right to social protection, non-discrimination, human dignity or an effective remedy and should therefore be classified as high-risk. Nonetheless, this Regulation should not hamper the development and use of innovative approaches in the public administration, which would stand to benefit from a wider use of compliant and safe AI systems, provided that those systems do not entail a high risk to legal and natural persons. In addition, AI systems used to evaluate the credit score or creditworthiness of natural persons should be classified as high-risk AI systems, since they determine those persons’ access to financial resources or essential services such as housing, electricity, and telecommunication services. AI systems used for those purposes may lead to discrimination between persons or groups and may perpetuate historical patterns of discrimination, such as that based on racial or ethnic origins, gender, disabilities, age or sexual orientation, or may create new forms of discriminatory impacts. However, AI systems provided for by Union law for the purpose of detecting fraud in the offering of financial services and for prudential purposes to calculate credit institutions’ and insurance undertakings’ capital requirements should not be considered to be high-risk under this Regulation. Moreover, AI systems intended to be used for risk assessment and pricing in relation to natural persons for health and life insurance can also have a significant impact on persons’ livelihood and if not duly designed, developed and used, can infringe their fundamental rights and can lead to serious consequences for people’s life and health, including financial exclusion and discrimination. Finally, AI systems used to evaluate and classify emergency calls by natural persons or to dispatch or establish priority in the dispatching of emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems, should also be classified as high-risk since they make decisions in very critical situations for the life and health of persons and their property.\n(59)\nGiven their role and responsibility, actions by law enforcement authorities involving certain uses of AI systems are characterised by a significant degree of power imbalance and may lead to surveillance, arrest or deprivation of a natural person’s liberty as well as other adverse impacts on fundamental rights guaranteed in the Charter. In particular, if the AI system is not trained with high-quality data, does not meet adequate requirements in terms of its performance, its accuracy or robustness, or is not properly designed and tested before being put on the market or otherwise put into service, it may single out people in a discriminatory or otherwise incorrect or unjust manner. Furthermore, the exercise of important procedural fundamental rights, such as the right to an effective remedy and to a fair trial as well as the right of defence and the presumption of innocence, could be hampered, in particular, where such AI systems are not sufficiently transparent, explainable and documented. It is therefore appropriate to classify as high-risk, insofar as their use is permitted under relevant Union and national law, a number of AI systems intended to be used in the law enforcement context where accuracy, reliability and transparency is particularly important to avoid adverse impacts, retain public trust and ensure accountability and effective redress. In view of the nature of the activities and the risks relating thereto, those high-risk AI systems should include in particular AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices, or agencies in support of law enforcement authorities for assessing the risk of a natural person to become a victim of criminal offences, as polygraphs and similar tools, for the evaluation of the reliability of evidence in in the course of investigation or prosecution of criminal offences, and, insofar as not prohibited under this Regulation, for assessing the risk of a natural person offending or reoffending not solely on the basis of the profiling of natural persons or the assessment of personality traits and characteristics or the past criminal behaviour of natural persons or groups, for profiling in the course of detection, investigation or prosecution of criminal offences. AI systems specifically intended to be used for administrative proceedings by tax and customs authorities as well as by financial intelligence units carrying out administrative tasks analysing information pursuant to Union anti-money laundering law should not be classified as high-risk AI systems used by law enforcement authorities for the purpose of prevention, detection, investigation and prosecution of criminal offences. The use of AI tools by law enforcement and other relevant authorities should not become a factor of inequality, or exclusion. The impact of the use of AI tools on the defence rights of suspects should not be ignored, in particular the difficulty in obtaining meaningful information on the functioning of those systems and the resulting difficulty in challenging their results in court, in particular by natural persons under investigation.\n(60)\nAI systems used in migration, asylum and border control management affect persons who are often in particularly vulnerable position and who are dependent on the outcome of the actions of the competent public authorities. The accuracy, non-discriminatory nature and transparency of the AI systems used in those contexts are therefore particularly important to guarantee respect for the fundamental rights of the affected persons, in particular their rights to free movement, non-discrimination, protection of private life and personal data, international protection and good administration. It is therefore appropriate to classify as high-risk, insofar as their use is permitted under relevant Union and national law, AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies charged with tasks in the fields of migration, asylum and border control management as polygraphs and similar tools, for assessing certain risks posed by natural persons entering the territory of a Member State or applying for visa or asylum, for assisting competent public authorities for the examination, including related assessment of the reliability of evidence, of applications for asylum, visa and residence permits and associated complaints with regard to the objective to establish the eligibility of the natural persons applying for a status, for the purpose of detecting, recognising or identifying natural persons in the context of migration, asylum and border control management, with the exception of verification of travel documents. AI systems in the area of migration, asylum and border control management covered by this Regulation should comply with the relevant procedural requirements set by the Regulation (EC) No 810/2009 of the European Parliament and of the Council (32), the Directive 2013/32/EU of the European Parliament and of the Council (33), and other relevant Union law. The use of AI systems in migration, asylum and border control management should, in no circumstances, be used by Member States or Union institutions, bodies, offices or agencies as a means to circumvent their international obligations under the UN Convention relating to the Status of Refugees done at Geneva on 28 July 1951 as amended by the Protocol of 31 January 1967. Nor should they be used to in any way infringe on the principle of non-refoulement, or to deny safe and effective legal avenues into the territory of the Union, including the right to international protection.\n(61)\nCertain AI systems intended for the administration of justice and democratic processes should be classified as high-risk, considering their potentially significant impact on democracy, the rule of law, individual freedoms as well as the right to an effective remedy and to a fair trial. In particular, to address the risks of potential biases, errors and opacity, it is appropriate to qualify as high-risk AI systems intended to be used by a judicial authority or on its behalf to assist judicial authorities in researching and interpreting facts and the law and in applying the law to a concrete set of facts. AI systems intended to be used by alternative dispute resolution bodies for those purposes should also be considered to be high-risk when the outcomes of the alternative dispute resolution proceedings produce legal effects for the parties. The use of AI tools can support the decision-making power of judges or judicial independence, but should not replace it: the final decision-making must remain a human-driven activity. The classification of AI systems as high-risk should not, however, extend to AI systems intended for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases, such as anonymisation or pseudonymisation of judicial decisions, documents or data, communication between personnel, administrative tasks.\n(62)\nWithout prejudice to the rules provided for in Regulation (EU) 2024/900 of the European Parliament and of the Council (34), and in order to address the risks of undue external interference with the right to vote enshrined in Article 39 of the Charter, and of adverse effects on democracy and the rule of law, AI systems intended to be used to influence the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda should be classified as high-risk AI systems with the exception of AI systems whose output natural persons are not directly exposed to, such as tools used to organise, optimise and structure political campaigns from an administrative and logistical point of view.\n(63)\nThe fact that an AI system is classified as a high-risk AI system under this Regulation should not be interpreted as indicating that the use of the system is lawful under other acts of Union law or under national law compatible with Union law, such as on the protection of personal data, on the use of polygraphs and similar tools or other systems to detect the emotional state of natural persons. Any such use should continue to occur solely in accordance with the applicable requirements resulting from the Charter and from the applicable acts of secondary Union law and national law. This Regulation should not be understood as providing for the legal ground for processing of personal data, including special categories of personal data, where relevant, unless it is specifically otherwise provided for in this Regulation.\n(64)\nTo mitigate the risks from high-risk AI systems placed on the market or put into service and to ensure a high level of trustworthiness, certain mandatory requirements should apply to high-risk AI systems, taking into account the intended purpose and the context of use of the AI system and according to the risk-management system to be established by the provider. The measures adopted by the providers to comply with the mandatory requirements of this Regulation should take into account the generally acknowledged state of the art on AI, be proportionate and effective to meet the objectives of this Regulation. Based on the New Legislative Framework, as clarified in Commission notice ‘The “Blue Guide” on the implementation of EU product rules 2022’, the general rule is that more than one legal act of Union harmonisation legislation may be applicable to one product, since the making available or putting into service can take place only when the product complies with all applicable Union harmonisation legislation. The hazards of AI systems covered by the requirements of this Regulation concern different aspects than the existing Union harmonisation legislation and therefore the requirements of this Regulation would complement the existing body of the Union harmonisation legislation. For example, machinery or medical devices products incorporating an AI system might present risks not addressed by the essential health and safety requirements set out in the relevant Union harmonised legislation, as that sectoral law does not deal with risks specific to AI systems. This calls for a simultaneous and complementary application of the various legislative acts. To ensure consistency and to avoid an unnecessary administrative burden and unnecessary costs, providers of a product that contains one or more high-risk AI system, to which the requirements of this Regulation and of the Union harmonisation legislation based on the New Legislative Framework and listed in an annex to this Regulation apply, should have flexibility with regard to operational decisions on how to ensure compliance of a product that contains one or more AI systems with all the applicable requirements of that Union harmonised legislation in an optimal manner. That flexibility could mean, for example a decision by the provider to integrate a part of the necessary testing and reporting processes, information and documentation required under this Regulation into already existing documentation and procedures required under existing Union harmonisation legislation based on the New Legislative Framework and listed in an annex to this Regulation. This should not, in any way, undermine the obligation of the provider to comply with all the applicable requirements.\n(65)\nThe risk-management system should consist of a continuous, iterative process that is planned and run throughout the entire lifecycle of a high-risk AI system. That process should be aimed at identifying and mitigating the relevant risks of AI systems on health, safety and fundamental rights. The risk-management system should be regularly reviewed and updated to ensure its continuing effectiveness, as well as justification and documentation of any significant decisions and actions taken subject to this Regulation. This process should ensure that the provider identifies risks or adverse impacts and implements mitigation measures for the known and reasonably foreseeable risks of AI systems to the health, safety and fundamental rights in light of their intended purpose and reasonably foreseeable misuse, including the possible risks arising from the interaction between the AI system and the environment within which it operates. The risk-management system should adopt the most appropriate risk-management measures in light of the state of the art in AI. When identifying the most appropriate risk-management measures, the provider should document and explain the choices made and, when relevant, involve experts and external stakeholders. In identifying the reasonably foreseeable misuse of high-risk AI systems, the provider should cover uses of AI systems which, while not directly covered by the intended purpose and provided for in the instruction for use may nevertheless be reasonably expected to result from readily predictable human behaviour in the context of the specific characteristics and use of a particular AI system. Any known or foreseeable circumstances related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights should be included in the instructions for use that are provided by the provider. This is to ensure that the deployer is aware and takes them into account when using the high-risk AI system. Identifying and implementing risk mitigation measures for foreseeable misuse under this Regulation should not require specific additional training for the high-risk AI system by the provider to address foreseeable misuse. The providers however are encouraged to consider such additional training measures to mitigate reasonable foreseeable misuses as necessary and appropriate.\n(66)\nRequirements should apply to high-risk AI systems as regards risk management, the quality and relevance of data sets used, technical documentation and record-keeping, transparency and the provision of information to deployers, human oversight, and robustness, accuracy and cybersecurity. Those requirements are necessary to effectively mitigate the risks for health, safety and fundamental rights. As no other less trade restrictive measures are reasonably available those requirements are not unjustified restrictions to trade.\n(67)\nHigh-quality data and access to high-quality data plays a vital role in providing structure and in ensuring the performance of many AI systems, especially when techniques involving the training of models are used, with a view to ensure that the high-risk AI system performs as intended and safely and it does not become a source of discrimination prohibited by Union law. High-quality data sets for training, validation and testing require the implementation of appropriate data governance and management practices. Data sets for training, validation and testing, including the labels, should be relevant, sufficiently representative, and to the best extent possible free of errors and complete in view of the intended purpose of the system. In order to facilitate compliance with Union data protection law, such as Regulation (EU) 2016/679, data governance and management practices should include, in the case of personal data, transparency about the original purpose of the data collection. The data sets should also have the appropriate statistical properties, including as regards the persons or groups of persons in relation to whom the high-risk AI system is intended to be used, with specific attention to the mitigation of possible biases in the data sets, that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations (feedback loops). Biases can for example be inherent in underlying data sets, especially when historical data is being used, or generated when the systems are implemented in real world settings. Results provided by AI systems could be influenced by such inherent biases that are inclined to gradually increase and thereby perpetuate and amplify existing discrimination, in particular for persons belonging to certain vulnerable groups, including racial or ethnic groups. The requirement for the data sets to be to the best extent possible complete and free of errors should not affect the use of privacy-preserving techniques in the context of the development and testing of AI systems. In particular, data sets should take into account, to the extent required by their intended purpose, the features, characteristics or elements that are particular to the specific geographical, contextual, behavioural or functional setting which the AI system is intended to be used. The requirements related to data governance can be complied with by having recourse to third parties that offer certified compliance services including verification of data governance, data set integrity, and data training, validation and testing practices, as far as compliance with the data requirements of this Regulation are ensured.\n(68)\nFor the development and assessment of high-risk AI systems, certain actors, such as providers, notified bodies and other relevant entities, such as European Digital Innovation Hubs, testing experimentation facilities and researchers, should be able to access and use high-quality data sets within the fields of activities of those actors which are related to this Regulation. European common data spaces established by the Commission and the facilitation of data sharing between businesses and with government in the public interest will be instrumental to provide trustful, accountable and non-discriminatory access to high-quality data for the training, validation and testing of AI systems. For example, in health, the European health data space will facilitate non-discriminatory access to health data and the training of AI algorithms on those data sets, in a privacy-preserving, secure, timely, transparent and trustworthy manner, and with an appropriate institutional governance. Relevant competent authorities, including sectoral ones, providing or supporting the access to data may also support the provision of high-quality data for the training, validation and testing of AI systems.\n(69)\nThe right to privacy and to protection of personal data must be guaranteed throughout the entire lifecycle of the AI system. In this regard, the principles of data minimisation and data protection by design and by default, as set out in Union data protection law, are applicable when personal data are processed. Measures taken by providers to ensure compliance with those principles may include not only anonymisation and encryption, but also the use of technology that permits algorithms to be brought to the data and allows training of AI systems without the transmission between parties or copying of the raw or structured data themselves, without prejudice to the requirements on data governance provided for in this Regulation.\n(70)\nIn order to protect the right of others from the discrimination that might result from the bias in AI systems, the providers should, exceptionally, to the extent that it is strictly necessary for the purpose of ensuring bias detection and correction in relation to the high-risk AI systems, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons and following the application of all applicable conditions laid down under this Regulation in addition to the conditions laid down in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, be able to process also special categories of personal data, as a matter of substantial public interest within the meaning of Article 9(2), point (g) of Regulation (EU) 2016/679 and Article 10(2), point (g) of Regulation (EU) 2018/1725.\n(71)\nHaving comprehensible information on how high-risk AI systems have been developed and how they perform throughout their lifetime is essential to enable traceability of those systems, verify compliance with the requirements under this Regulation, as well as monitoring of their operations and post market monitoring. This requires keeping records and the availability of technical documentation, containing information which is necessary to assess the compliance of the AI system with the relevant requirements and facilitate post market monitoring. Such information should include the general characteristics, capabilities and limitations of the system, algorithms, data, training, testing and validation processes used as well as documentation on the relevant risk-management system and drawn in a clear and comprehensive form. The technical documentation should be kept up to date, appropriately throughout the lifetime of the AI system. Furthermore, high-risk AI systems should technically allow for the automatic recording of events, by means of logs, over the duration of the lifetime of the system.\n(72)\nTo address concerns related to opacity and complexity of certain AI systems and help deployers to fulfil their obligations under this Regulation, transparency should be required for high-risk AI systems before they are placed on the market or put it into service. High-risk AI systems should be designed in a manner to enable deployers to understand how the AI system works, evaluate its functionality, and comprehend its strengths and limitations. High-risk AI systems should be accompanied by appropriate information in the form of instructions of use. Such information should include the characteristics, capabilities and limitations of performance of the AI system. Those would cover information on possible known and foreseeable circumstances related to the use of the high-risk AI system, including deployer action that may influence system behaviour and performance, under which the AI system can lead to risks to health, safety, and fundamental rights, on the changes that have been pre-determined and assessed for conformity by the provider and on the relevant human oversight measures, including the measures to facilitate the interpretation of the outputs of the AI system by the deployers. Transparency, including the accompanying instructions for use, should assist deployers in the use of the system and support informed decision making by them. Deployers should, inter alia, be in a better position to make the correct choice of the system that they intend to use in light of the obligations applicable to them, be educated about the intended and precluded uses, and use the AI system correctly and as appropriate. In order to enhance legibility and accessibility of the information included in the instructions of use, where appropriate, illustrative examples, for instance on the limitations and on the intended and precluded uses of the AI system, should be included. Providers should ensure that all documentation, including the instructions for use, contains meaningful, comprehensive, accessible and understandable information, taking into account the needs and foreseeable knowledge of the target deployers. Instructions for use should be made available in a language which can be easily understood by target deployers, as determined by the Member State concerned.\n(73)\nHigh-risk AI systems should be designed and developed in such a way that natural persons can oversee their functioning, ensure that they are used as intended and that their impacts are addressed over the system’s lifecycle. To that end, appropriate human oversight measures should be identified by the provider of the system before its placing on the market or putting into service. In particular, where appropriate, such measures should guarantee that the system is subject to in-built operational constraints that cannot be overridden by the system itself and is responsive to the human operator, and that the natural persons to whom human oversight has been assigned have the necessary competence, training and authority to carry out that role. It is also essential, as appropriate, to ensure that high-risk AI systems include mechanisms to guide and inform a natural person to whom human oversight has been assigned to make informed decisions if, when and how to intervene in order to avoid negative consequences or risks, or stop the system if it does not perform as intended. Considering the significant consequences for persons in the case of an incorrect match by certain biometric identification systems, it is appropriate to provide for an enhanced human oversight requirement for those systems so that no action or decision may be taken by the deployer on the basis of the identification resulting from the system unless this has been separately verified and confirmed by at least two natural persons. Those persons could be from one or more entities and include the person operating or using the system. This requirement should not pose unnecessary burden or delays and it could be sufficient that the separate verifications by the different persons are automatically recorded in the logs generated by the system. Given the specificities of the areas of law enforcement, migration, border control and asylum, this requirement should not apply where Union or national law considers the application of that requirement to be disproportionate.\n(74)\nHigh-risk AI systems should perform consistently throughout their lifecycle and meet an appropriate level of accuracy, robustness and cybersecurity, in light of their intended purpose and in accordance with the generally acknowledged state of the art. The Commission and relevant organisations and stakeholders are encouraged to take due consideration of the mitigation of risks and the negative impacts of the AI system. The expected level of performance metrics should be declared in the accompanying instructions of use. Providers are urged to communicate that information to deployers in a clear and easily understandable way, free of misunderstandings or misleading statements. Union law on legal metrology, including Directives 2014/31/EU (35) and 2014/32/EU (36) of the European Parliament and of the Council, aims to ensure the accuracy of measurements and to help the transparency and fairness of commercial transactions. In that context, in cooperation with relevant stakeholders and organisation, such as metrology and benchmarking authorities, the Commission should encourage, as appropriate, the development of benchmarks and measurement methodologies for AI systems. In doing so, the Commission should take note and collaborate with international partners working on metrology and relevant measurement indicators relating to AI.\n(75)\nTechnical robustness is a key requirement for high-risk AI systems. They should be resilient in relation to harmful or otherwise undesirable behaviour that may result from limitations within the systems or the environment in which the systems operate (e.g. errors, faults, inconsistencies, unexpected situations). Therefore, technical and organisational measures should be taken to ensure robustness of high-risk AI systems, for example by designing and developing appropriate technical solutions to prevent or minimise harmful or otherwise undesirable behaviour. Those technical solution may include for instance mechanisms enabling the system to safely interrupt its operation (fail-safe plans) in the presence of certain anomalies or when operation takes place outside certain predetermined boundaries. Failure to protect against these risks could lead to safety impacts or negatively affect the fundamental rights, for example due to erroneous decisions or wrong or biased outputs generated by the AI system.\n(76)\nCybersecurity plays a crucial role in ensuring that AI systems are resilient against attempts to alter their use, behaviour, performance or compromise their security properties by malicious third parties exploiting the system’s vulnerabilities. Cyberattacks against AI systems can leverage AI specific assets, such as training data sets (e.g. data poisoning) or trained models (e.g. adversarial attacks or membership inference), or exploit vulnerabilities in the AI system’s digital assets or the underlying ICT infrastructure. To ensure a level of cybersecurity appropriate to the risks, suitable measures, such as security controls, should therefore be taken by the providers of high-risk AI systems, also taking into account as appropriate the underlying ICT infrastructure.\n(77)\nWithout prejudice to the requirements related to robustness and accuracy set out in this Regulation, high-risk AI systems which fall within the scope of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, in accordance with that regulation may demonstrate compliance with the cybersecurity requirements of this Regulation by fulfilling the essential cybersecurity requirements set out in that regulation. When high-risk AI systems fulfil the essential requirements of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, they should be deemed compliant with the cybersecurity requirements set out in this Regulation in so far as the achievement of those requirements is demonstrated in the EU declaration of conformity or parts thereof issued under that regulation. To that end, the assessment of the cybersecurity risks, associated to a product with digital elements classified as high-risk AI system according to this Regulation, carried out under a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, should consider risks to the cyber resilience of an AI system as regards attempts by unauthorised third parties to alter its use, behaviour or performance, including AI specific vulnerabilities such as data poisoning or adversarial attacks, as well as, as relevant, risks to fundamental rights as required by this Regulation.\n(78)\nThe conformity assessment procedure provided by this Regulation should apply in relation to the essential cybersecurity requirements of a product with digital elements covered by a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and classified as a high-risk AI system under this Regulation. However, this rule should not result in reducing the necessary level of assurance for critical products with digital elements covered by a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements. Therefore, by way of derogation from this rule, high-risk AI systems that fall within the scope of this Regulation and are also qualified as important and critical products with digital elements pursuant to a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and to which the conformity assessment procedure based on internal control set out in an annex to this Regulation applies, are subject to the conformity assessment provisions of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements insofar as the essential cybersecurity requirements of that regulation are concerned. In this case, for all the other aspects covered by this Regulation the respective provisions on conformity assessment based on internal control set out in an annex to this Regulation should apply. Building on the knowledge and expertise of ENISA on the cybersecurity policy and tasks assigned to ENISA under the Regulation (EU) 2019/881 of the European Parliament and of the Council (37), the Commission should cooperate with ENISA on issues related to cybersecurity of AI systems.\n(79)\nIt is appropriate that a specific natural or legal person, defined as the provider, takes responsibility for the placing on the market or the putting into service of a high-risk AI system, regardless of whether that natural or legal person is the person who designed or developed the system.\n(80)\nAs signatories to the United Nations Convention on the Rights of Persons with Disabilities, the Union and the Member States are legally obliged to protect persons with disabilities from discrimination and promote their equality, to ensure that persons with disabilities have access, on an equal basis with others, to information and communications technologies and systems, and to ensure respect for privacy for persons with disabilities. Given the growing importance and use of AI systems, the application of universal design principles to all new technologies and services should ensure full and equal access for everyone potentially affected by or using AI technologies, including persons with disabilities, in a way that takes full account of their inherent dignity and diversity. It is therefore essential that providers ensure full compliance with accessibility requirements, including Directive (EU) 2016/2102 of the European Parliament and of the Council (38) and Directive (EU) 2019/882. Providers should ensure compliance with these requirements by design. Therefore, the necessary measures should be integrated as much as possible into the design of the high-risk AI system.\n(81)\nThe provider should establish a sound quality management system, ensure the accomplishment of the required conformity assessment procedure, draw up the relevant documentation and establish a robust post-market monitoring system. Providers of high-risk AI systems that are subject to obligations regarding quality management systems under relevant sectoral Union law should have the possibility to include the elements of the quality management system provided for in this Regulation as part of the existing quality management system provided for in that other sectoral Union law. The complementarity between this Regulation and existing sectoral Union law should also be taken into account in future standardisation activities or guidance adopted by the Commission. Public authorities which put into service high-risk AI systems for their own use may adopt and implement the rules for the quality management system as part of the quality management system adopted at a national or regional level, as appropriate, taking into account the specificities of the sector and the competences and organisation of the public authority concerned.\n(82)\nTo enable enforcement of this Regulation and create a level playing field for operators, and, taking into account the different forms of making available of digital products, it is important to ensure that, under all circumstances, a person established in the Union can provide authorities with all the necessary information on the compliance of an AI system. Therefore, prior to making their AI systems available in the Union, providers established in third countries should, by written mandate, appoint an authorised representative established in the Union. This authorised representative plays a pivotal role in ensuring the compliance of the high-risk AI systems placed on the market or put into service in the Union by those providers who are not established in the Union and in serving as their contact person established in the Union.\n(83)\nIn light of the nature and complexity of the value chain for AI systems and in line with the New Legislative Framework, it is essential to ensure legal certainty and facilitate the compliance with this Regulation. Therefore, it is necessary to clarify the role and the specific obligations of relevant operators along that value chain, such as importers and distributors who may contribute to the development of AI systems. In certain situations those operators could act in more than one role at the same time and should therefore fulfil cumulatively all relevant obligations associated with those roles. For example, an operator could act as a distributor and an importer at the same time.\n(84)\nTo ensure legal certainty, it is necessary to clarify that, under certain specific conditions, any distributor, importer, deployer or other third-party should be considered to be a provider of a high-risk AI system and therefore assume all the relevant obligations. This would be the case if that party puts its name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are allocated otherwise. This would also be the case if that party makes a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in a way that it remains a high-risk AI system in accordance with this Regulation, or if it modifies the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service, in a way that the AI system becomes a high-risk AI system in accordance with this Regulation. Those provisions should apply without prejudice to more specific provisions established in certain Union harmonisation legislation based on the New Legislative Framework, together with which this Regulation should apply. For example, Article 16(2) of Regulation (EU) 2017/745, establishing that certain changes should not be considered to be modifications of a device that could affect its compliance with the applicable requirements, should continue to apply to high-risk AI systems that are medical devices within the meaning of that Regulation.\n(85)\nGeneral-purpose AI systems may be used as high-risk AI systems by themselves or be components of other high-risk AI systems. Therefore, due to their particular nature and in order to ensure a fair sharing of responsibilities along the AI value chain, the providers of such systems should, irrespective of whether they may be used as high-risk AI systems as such by other providers or as components of high-risk AI systems and unless provided otherwise under this Regulation, closely cooperate with the providers of the relevant high-risk AI systems to enable their compliance with the relevant obligations under this Regulation and with the competent authorities established under this Regulation.\n(86)\nWhere, under the conditions laid down in this Regulation, the provider that initially placed the AI system on the market or put it into service should no longer be considered to be the provider for the purposes of this Regulation, and when that provider has not expressly excluded the change of the AI system into a high-risk AI system, the former provider should nonetheless closely cooperate and make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular regarding the compliance with the conformity assessment of high-risk AI systems.\n(87)\nIn addition, where a high-risk AI system that is a safety component of a product which falls within the scope of Union harmonisation legislation based on the New Legislative Framework is not placed on the market or put into service independently from the product, the product manufacturer defined in that legislation should comply with the obligations of the provider established in this Regulation and should, in particular, ensure that the AI system embedded in the final product complies with the requirements of this Regulation.\n(88)\nAlong the AI value chain multiple parties often supply AI systems, tools and services but also components or processes that are incorporated by the provider into the AI system with various objectives, including the model training, model retraining, model testing and evaluation, integration into software, or other aspects of model development. Those parties have an important role to play in the value chain towards the provider of the high-risk AI system into which their AI systems, tools, services, components or processes are integrated, and should provide by written agreement this provider with the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider to fully comply with the obligations set out in this Regulation, without compromising their own intellectual property rights or trade secrets.\n(89)\nThird parties making accessible to the public tools, services, processes, or AI components other than general-purpose AI models, should not be mandated to comply with requirements targeting the responsibilities along the AI value chain, in particular towards the provider that has used or integrated them, when those tools, services, processes, or AI components are made accessible under a free and open-source licence. Developers of free and open-source tools, services, processes, or AI components other than general-purpose AI models should be encouraged to implement widely adopted documentation practices, such as model cards and data sheets, as a way to accelerate information sharing along the AI value chain, allowing the promotion of trustworthy AI systems in the Union.\n(90)\nThe Commission could develop and recommend voluntary model contractual terms between providers of high-risk AI systems and third parties that supply tools, services, components or processes that are used or integrated in high-risk AI systems, to facilitate the cooperation along the value chain. When developing voluntary model contractual terms, the Commission should also take into account possible contractual requirements applicable in specific sectors or business cases.\n(91)\nGiven the nature of AI systems and the risks to safety and fundamental rights possibly associated with their use, including as regards the need to ensure proper monitoring of the performance of an AI system in a real-life setting, it is appropriate to set specific responsibilities for deployers. Deployers should in particular take appropriate technical and organisational measures to ensure they use high-risk AI systems in accordance with the instructions of use and certain other obligations should be provided for with regard to monitoring of the functioning of the AI systems and with regard to record-keeping, as appropriate. Furthermore, deployers should ensure that the persons assigned to implement the instructions for use and human oversight as set out in this Regulation have the necessary competence, in particular an adequate level of AI literacy, training and authority to properly fulfil those tasks. Those obligations should be without prejudice to other deployer obligations in relation to high-risk AI systems under Union or national law.\n(92)\nThis Regulation is without prejudice to obligations for employers to inform or to inform and consult workers or their representatives under Union or national law and practice, including Directive 2002/14/EC of the European Parliament and of the Council (39), on decisions to put into service or use AI systems. It remains necessary to ensure information of workers and their representatives on the planned deployment of high-risk AI systems at the workplace where the conditions for those information or information and consultation obligations in other legal instruments are not fulfilled. Moreover, such information right is ancillary and necessary to the objective of protecting fundamental rights that underlies this Regulation. Therefore, an information requirement to that effect should be laid down in this Regulation, without affecting any existing rights of workers.\n(93)\nWhilst risks related to AI systems can result from the way such systems are designed, risks can as well stem from how such AI systems are used. Deployers of high-risk AI system therefore play a critical role in ensuring that fundamental rights are protected, complementing the obligations of the provider when developing the AI system. Deployers are best placed to understand how the high-risk AI system will be used concretely and can therefore identify potential significant risks that were not foreseen in the development phase, due to a more precise knowledge of the context of use, the persons or groups of persons likely to be affected, including vulnerable groups. Deployers of high-risk AI systems listed in an annex to this Regulation also play a critical role in informing natural persons and should, when they make decisions or assist in making decisions related to natural persons, where applicable, inform the natural persons that they are subject to the use of the high-risk AI system. This information should include the intended purpose and the type of decisions it makes. The deployer should also inform the natural persons about their right to an explanation provided under this Regulation. With regard to high-risk AI systems used for law enforcement purposes, that obligation should be implemented in accordance with Article 13 of Directive (EU) 2016/680.\n(94)\nAny processing of biometric data involved in the use of AI systems for biometric identification for the purpose of law enforcement needs to comply with Article 10 of Directive (EU) 2016/680, that allows such processing only where strictly necessary, subject to appropriate safeguards for the rights and freedoms of the data subject, and where authorised by Union or Member State law. Such use, when authorised, also needs to respect the principles laid down in Article 4 (1) of Directive (EU) 2016/680 including lawfulness, fairness and transparency, purpose limitation, accuracy and storage limitation.\n(95)\nWithout prejudice to applicable Union law, in particular Regulation (EU) 2016/679 and Directive (EU) 2016/680, considering the intrusive nature of post-remote biometric identification systems, the use of post-remote biometric identification systems should be subject to safeguards. Post-remote biometric identification systems should always be used in a way that is proportionate, legitimate and strictly necessary, and thus targeted, in terms of the individuals to be identified, the location, temporal scope and based on a closed data set of legally acquired video footage. In any case, post-remote biometric identification systems should not be used in the framework of law enforcement to lead to indiscriminate surveillance. The conditions for post-remote biometric identification should in any case not provide a basis to circumvent the conditions of the prohibition and strict exceptions for real time remote biometric identification.\n(96)\nIn order to efficiently ensure that fundamental rights are protected, deployers of high-risk AI systems that are bodies governed by public law, or private entities providing public services and deployers of certain high-risk AI systems listed in an annex to this Regulation, such as banking or insurance entities, should carry out a fundamental rights impact assessment prior to putting it into use. Services important for individuals that are of public nature may also be provided by private entities. Private entities providing such public services are linked to tasks in the public interest such as in the areas of education, healthcare, social services, housing, administration of justice. The aim of the fundamental rights impact assessment is for the deployer to identify the specific risks to the rights of individuals or groups of individuals likely to be affected, identify measures to be taken in the case of a materialisation of those risks. The impact assessment should be performed prior to deploying the high-risk AI system, and should be updated when the deployer considers that any of the relevant factors have changed. The impact assessment should identify the deployer’s relevant processes in which the high-risk AI system will be used in line with its intended purpose, and should include a description of the period of time and frequency in which the system is intended to be used as well as of specific categories of natural persons and groups who are likely to be affected in the specific context of use. The assessment should also include the identification of specific risks of harm likely to have an impact on the fundamental rights of those persons or groups. While performing this assessment, the deployer should take into account information relevant to a proper assessment of the impact, including but not limited to the information given by the provider of the high-risk AI system in the instructions for use. In light of the risks identified, deployers should determine measures to be taken in the case of a materialisation of those risks, including for example governance arrangements in that specific context of use, such as arrangements for human oversight according to the instructions of use or, complaint handling and redress procedures, as they could be instrumental in mitigating risks to fundamental rights in concrete use-cases. After performing that impact assessment, the deployer should notify the relevant market surveillance authority. Where appropriate, to collect relevant information necessary to perform the impact assessment, deployers of high-risk AI system, in particular when AI systems are used in the public sector, could involve relevant stakeholders, including the representatives of groups of persons likely to be affected by the AI system, independent experts, and civil society organisations in conducting such impact assessments and designing measures to be taken in the case of materialisation of the risks. The European Artificial Intelligence Office (AI Office) should develop a template for a questionnaire in order to facilitate compliance and reduce the administrative burden for deployers.\n(97)\nThe notion of general-purpose AI models should be clearly defined and set apart from the notion of AI systems to enable legal certainty. The definition should be based on the key functional characteristics of a general-purpose AI model, in particular the generality and the capability to competently perform a wide range of distinct tasks. These models are typically trained on large amounts of data, through various methods, such as self-supervised, unsupervised or reinforcement learning. General-purpose AI models may be placed on the market in various ways, including through libraries, application programming interfaces (APIs), as direct download, or as physical copy. These models may be further modified or fine-tuned into new models. Although AI models are essential components of AI systems, they do not constitute AI systems on their own. AI models require the addition of further components, such as for example a user interface, to become AI systems. AI models are typically integrated into and form part of AI systems. This Regulation provides specific rules for general-purpose AI models and for general-purpose AI models that pose systemic risks, which should apply also when these models are integrated or form part of an AI system. It should be understood that the obligations for the providers of general-purpose AI models should apply once the general-purpose AI models are placed on the market. When the provider of a general-purpose AI model integrates an own model into its own AI system that is made available on the market or put into service, that model should be considered to be placed on the market and, therefore, the obligations in this Regulation for models should continue to apply in addition to those for AI systems. The obligations laid down for models should in any case not apply when an own model is used for purely internal processes that are not essential for providing a product or a service to third parties and the rights of natural persons are not affected. Considering their potential significantly negative effects, the general-purpose AI models with systemic risk should always be subject to the relevant obligations under this Regulation. The definition should not cover AI models used before their placing on the market for the sole purpose of research, development and prototyping activities. This is without prejudice to the obligation to comply with this Regulation when, following such activities, a model is placed on the market.\n(98)\nWhereas the generality of a model could, inter alia, also be determined by a number of parameters, models with at least a billion of parameters and trained with a large amount of data using self-supervision at scale should be considered to display significant generality and to competently perform a wide range of distinctive tasks.\n(99)\nLarge generative AI models are a typical example for a general-purpose AI model, given that they allow for flexible generation of content, such as in the form of text, audio, images or video, that can readily accommodate a wide range of distinctive tasks.\n(100)\nWhen a general-purpose AI model is integrated into or forms part of an AI system, this system should be considered to be general-purpose AI system when, due to this integration, this system has the capability to serve a variety of purposes. A general-purpose AI system can be used directly, or it may be integrated into other AI systems.\n(101)\nProviders of general-purpose AI models have a particular role and responsibility along the AI value chain, as the models they provide may form the basis for a range of downstream systems, often provided by downstream providers that necessitate a good understanding of the models and their capabilities, both to enable the integration of such models into their products, and to fulfil their obligations under this or other regulations. Therefore, proportionate transparency measures should be laid down, including the drawing up and keeping up to date of documentation, and the provision of information on the general-purpose AI model for its usage by the downstream providers. Technical documentation should be prepared and kept up to date by the general-purpose AI model provider for the purpose of making it available, upon request, to the AI Office and the national competent authorities. The minimal set of elements to be included in such documentation should be set out in specific annexes to this Regulation. The Commission should be empowered to amend those annexes by means of delegated acts in light of evolving technological developments.\n(102)\nSoftware and data, including models, released under a free and open-source licence that allows them to be openly shared and where users can freely access, use, modify and redistribute them or modified versions thereof, can contribute to research and innovation in the market and can provide significant growth opportunities for the Union economy. General-purpose AI models released under free and open-source licences should be considered to ensure high levels of transparency and openness if their parameters, including the weights, the information on the model architecture, and the information on model usage are made publicly available. The licence should be considered to be free and open-source also when it allows users to run, copy, distribute, study, change and improve software and data, including models under the condition that the original provider of the model is credited, the identical or comparable terms of distribution are respected.\n(103)\nFree and open-source AI components covers the software and data, including models and general-purpose AI models, tools, services or processes of an AI system. Free and open-source AI components can be provided through different channels, including their development on open repositories. For the purposes of this Regulation, AI components that are provided against a price or otherwise monetised, including through the provision of technical support or other services, including through a software platform, related to the AI component, or the use of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software, with the exception of transactions between microenterprises, should not benefit from the exceptions provided to free and open-source AI components. The fact of making AI components available through open repositories should not, in itself, constitute a monetisation.\n(104)\nThe providers of general-purpose AI models that are released under a free and open-source licence, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available should be subject to exceptions as regards the transparency-related requirements imposed on general-purpose AI models, unless they can be considered to present a systemic risk, in which case the circumstance that the model is transparent and accompanied by an open-source license should not be considered to be a sufficient reason to exclude compliance with the obligations under this Regulation. In any case, given that the release of general-purpose AI models under free and open-source licence does not necessarily reveal substantial information on the data set used for the training or fine-tuning of the model and on how compliance of copyright law was thereby ensured, the exception provided for general-purpose AI models from compliance with the transparency-related requirements should not concern the obligation to produce a summary about the content used for model training and the obligation to put in place a policy to comply with Union copyright law, in particular to identify and comply with the reservation of rights pursuant to Article 4(3) of Directive (EU) 2019/790 of the European Parliament and of the Council (40).\n(105)\nGeneral-purpose AI models, in particular large generative AI models, capable of generating text, images, and other content, present unique innovation opportunities but also challenges to artists, authors, and other creators and the way their creative content is created, distributed, used and consumed. The development and training of such models require access to vast amounts of text, images, videos and other data. Text and data mining techniques may be used extensively in this context for the retrieval and analysis of such content, which may be protected by copyright and related rights. Any use of copyright protected content requires the authorisation of the rightsholder concerned unless relevant copyright exceptions and limitations apply. Directive (EU) 2019/790 introduced exceptions and limitations allowing reproductions and extractions of works or other subject matter, for the purpose of text and data mining, under certain conditions. Under these rules, rightsholders may choose to reserve their rights over their works or other subject matter to prevent text and data mining, unless this is done for the purposes of scientific research. Where the rights to opt out has been expressly reserved in an appropriate manner, providers of general-purpose AI models need to obtain an authorisation from rightsholders if they want to carry out text and data mining over such works.\n(106)\nProviders that place general-purpose AI models on the Union market should ensure compliance with the relevant obligations in this Regulation. To that end, providers of general-purpose AI models should put in place a policy to comply with Union law on copyright and related rights, in particular to identify and comply with the reservation of rights expressed by rightsholders pursuant to Article 4(3) of Directive (EU) 2019/790. Any provider placing a general-purpose AI model on the Union market should comply with this obligation, regardless of the jurisdiction in which the copyright-relevant acts underpinning the training of those general-purpose AI models take place. This is necessary to ensure a level playing field among providers of general-purpose AI models where no provider should be able to gain a competitive advantage in the Union market by applying lower copyright standards than those provided in the Union.\n(107)\nIn order to increase transparency on the data that is used in the pre-training and training of general-purpose AI models, including text and data protected by copyright law, it is adequate that providers of such models draw up and make publicly available a sufficiently detailed summary of the content used for training the general-purpose AI model. While taking into due account the need to protect trade secrets and confidential business information, this summary should be generally comprehensive in its scope instead of technically detailed to facilitate parties with legitimate interests, including copyright holders, to exercise and enforce their rights under Union law, for example by listing the main data collections or sets that went into training the model, such as large private or public databases or data archives, and by providing a narrative explanation about other data sources used. It is appropriate for the AI Office to provide a template for the summary, which should be simple, effective, and allow the provider to provide the required summary in narrative form.\n(108)\nWith regard to the obligations imposed on providers of general-purpose AI models to put in place a policy to comply with Union copyright law and make publicly available a summary of the content used for the training, the AI Office should monitor whether the provider has fulfilled those obligations without verifying or proceeding to a work-by-work assessment of the training data in terms of copyright compliance. This Regulation does not affect the enforcement of copyright rules as provided for under Union law.\n(109)\nCompliance with the obligations applicable to the providers of general-purpose AI models should be commensurate and proportionate to the type of model provider, excluding the need for compliance for persons who develop or use models for non-professional or scientific research purposes, who should nevertheless be encouraged to voluntarily comply with these requirements. Without prejudice to Union copyright law, compliance with those obligations should take due account of the size of the provider and allow simplified ways of compliance for SMEs, including start-ups, that should not represent an excessive cost and not discourage the use of such models. In the case of a modification or fine-tuning of a model, the obligations for providers of general-purpose AI models should be limited to that modification or fine-tuning, for example by complementing the already existing technical documentation with information on the modifications, including new training data sources, as a means to comply with the value chain obligations provided in this Regulation.\n(110)\nGeneral-purpose AI models could pose systemic risks which include, but are not limited to, any actual or reasonably foreseeable negative effects in relation to major accidents, disruptions of critical sectors and serious consequences to public health and safety; any actual or reasonably foreseeable negative effects on democratic processes, public and economic security; the dissemination of illegal, false, or discriminatory content. Systemic risks should be understood to increase with model capabilities and model reach, can arise along the entire lifecycle of the model, and are influenced by conditions of misuse, model reliability, model fairness and model security, the level of autonomy of the model, its access to tools, novel or combined modalities, release and distribution strategies, the potential to remove guardrails and other factors. In particular, international approaches have so far identified the need to pay attention to risks from potential intentional misuse or unintended issues of control relating to alignment with human intent; chemical, biological, radiological, and nuclear risks, such as the ways in which barriers to entry can be lowered, including for weapons development, design acquisition, or use; offensive cyber capabilities, such as the ways in vulnerability discovery, exploitation, or operational use can be enabled; the effects of interaction and tool use, including for example the capacity to control physical systems and interfere with critical infrastructure; risks from models of making copies of themselves or ‘self-replicating’ or training other models; the ways in which models can give rise to harmful bias and discrimination with risks to individuals, communities or societies; the facilitation of disinformation or harming privacy with threats to democratic values and human rights; risk that a particular event could lead to a chain reaction with considerable negative effects that could affect up to an entire city, an entire domain activity or an entire community.\n(111)\nIt is appropriate to establish a methodology for the classification of general-purpose AI models as general-purpose AI model with systemic risks. Since systemic risks result from particularly high capabilities, a general-purpose AI model should be considered to present systemic risks if it has high-impact capabilities, evaluated on the basis of appropriate technical tools and methodologies, or significant impact on the internal market due to its reach. High-impact capabilities in general-purpose AI models means capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models. The full range of capabilities in a model could be better understood after its placing on the market or when deployers interact with the model. According to the state of the art at the time of entry into force of this Regulation, the cumulative amount of computation used for the training of the general-purpose AI model measured in floating point operations is one of the relevant approximations for model capabilities. The cumulative amount of computation used for training includes the computation used across the activities and methods that are intended to enhance the capabilities of the model prior to deployment, such as pre-training, synthetic data generation and fine-tuning. Therefore, an initial threshold of floating point operations should be set, which, if met by a general-purpose AI model, leads to a presumption that the model is a general-purpose AI model with systemic risks. This threshold should be adjusted over time to reflect technological and industrial changes, such as algorithmic improvements or increased hardware efficiency, and should be supplemented with benchmarks and indicators for model capability. To inform this, the AI Office should engage with the scientific community, industry, civil society and other experts. Thresholds, as well as tools and benchmarks for the assessment of high-impact capabilities, should be strong predictors of generality, its capabilities and associated systemic risk of general-purpose AI models, and could take into account the way the model will be placed on the market or the number of users it may affect. To complement this system, there should be a possibility for the Commission to take individual decisions designating a general-purpose AI model as a general-purpose AI model with systemic risk if it is found that such model has capabilities or an impact equivalent to those captured by the set threshold. That decision should be taken on the basis of an overall assessment of the criteria for the designation of a general-purpose AI model with systemic risk set out in an annex to this Regulation, such as quality or size of the training data set, number of business and end users, its input and output modalities, its level of autonomy and scalability, or the tools it has access to. Upon a reasoned request of a provider whose model has been designated as a general-purpose AI model with systemic risk, the Commission should take the request into account and may decide to reassess whether the general-purpose AI model can still be considered to present systemic risks.\n(112)\nIt is also necessary to clarify a procedure for the classification of a general-purpose AI model with systemic risks. A general-purpose AI model that meets the applicable threshold for high-impact capabilities should be presumed to be a general-purpose AI models with systemic risk. The provider should notify the AI Office at the latest two weeks after the requirements are met or it becomes known that a general-purpose AI model will meet the requirements that lead to the presumption. This is especially relevant in relation to the threshold of floating point operations because training of general-purpose AI models takes considerable planning which includes the upfront allocation of compute resources and, therefore, providers of general-purpose AI models are able to know if their model would meet the threshold before the training is completed. In the context of that notification, the provider should be able to demonstrate that, because of its specific characteristics, a general-purpose AI model exceptionally does not present systemic risks, and that it thus should not be classified as a general-purpose AI model with systemic risks. That information is valuable for the AI Office to anticipate the placing on the market of general-purpose AI models with systemic risks and the providers can start to engage with the AI Office early on. That information is especially important with regard to general-purpose AI models that are planned to be released as open-source, given that, after the open-source model release, necessary measures to ensure compliance with the obligations under this Regulation may be more difficult to implement.\n(113)\nIf the Commission becomes aware of the fact that a general-purpose AI model meets the requirements to classify as a general-purpose AI model with systemic risk, which previously had either not been known or of which the relevant provider has failed to notify the Commission, the Commission should be empowered to designate it so. A system of qualified alerts should ensure that the AI Office is made aware by the scientific panel of general-purpose AI models that should possibly be classified as general-purpose AI models with systemic risk, in addition to the monitoring activities of the AI Office.\n(114)\nThe providers of general-purpose AI models presenting systemic risks should be subject, in addition to the obligations provided for providers of general-purpose AI models, to obligations aimed at identifying and mitigating those risks and ensuring an adequate level of cybersecurity protection, regardless of whether it is provided as a standalone model or embedded in an AI system or a product. To achieve those objectives, this Regulation should require providers to perform the necessary model evaluations, in particular prior to its first placing on the market, including conducting and documenting adversarial testing of models, also, as appropriate, through internal or independent external testing. In addition, providers of general-purpose AI models with systemic risks should continuously assess and mitigate systemic risks, including for example by putting in place risk-management policies, such as accountability and governance processes, implementing post-market monitoring, taking appropriate measures along the entire model’s lifecycle and cooperating with relevant actors along the AI value chain.\n(115)\nProviders of general-purpose AI models with systemic risks should assess and mitigate possible systemic risks. If, despite efforts to identify and prevent risks related to a general-purpose AI model that may present systemic risks, the development or use of the model causes a serious incident, the general-purpose AI model provider should without undue delay keep track of the incident and report any relevant information and possible corrective measures to the Commission and national competent authorities. Furthermore, providers should ensure an adequate level of cybersecurity protection for the model and its physical infrastructure, if appropriate, along the entire model lifecycle. Cybersecurity protection related to systemic risks associated with malicious use or attacks should duly consider accidental model leakage, unauthorised releases, circumvention of safety measures, and defence against cyberattacks, unauthorised access or model theft. That protection could be facilitated by securing model weights, algorithms, servers, and data sets, such as through operational security measures for information security, specific cybersecurity policies, adequate technical and established solutions, and cyber and physical access controls, appropriate to the relevant circumstances and the risks involved.\n(116)\nThe AI Office should encourage and facilitate the drawing up, review and adaptation of codes of practice, taking into account international approaches. All providers of general-purpose AI models could be invited to participate. To ensure that the codes of practice reflect the state of the art and duly take into account a diverse set of perspectives, the AI Office should collaborate with relevant national competent authorities, and could, where appropriate, consult with civil society organisations and other relevant stakeholders and experts, including the Scientific Panel, for the drawing up of such codes. Codes of practice should cover obligations for providers of general-purpose AI models and of general-purpose AI models presenting systemic risks. In addition, as regards systemic risks, codes of practice should help to establish a risk taxonomy of the type and nature of the systemic risks at Union level, including their sources. Codes of practice should also be focused on specific risk assessment and mitigation measures.\n(117)\nThe codes of practice should represent a central tool for the proper compliance with the obligations provided for under this Regulation for providers of general-purpose AI models. Providers should be able to rely on codes of practice to demonstrate compliance with the obligations. By means of implementing acts, the Commission may decide to approve a code of practice and give it a general validity within the Union, or, alternatively, to provide common rules for the implementation of the relevant obligations, if, by the time this Regulation becomes applicable, a code of practice cannot be finalised or is not deemed adequate by the AI Office. Once a harmonised standard is published and assessed as suitable to cover the relevant obligations by the AI Office, compliance with a European harmonised standard should grant providers the presumption of conformity. Providers of general-purpose AI models should furthermore be able to demonstrate compliance using alternative adequate means, if codes of practice or harmonised standards are not available, or they choose not to rely on those.\n(118)\nThis Regulation regulates AI systems and AI models by imposing certain requirements and obligations for relevant market actors that are placing them on the market, putting into service or use in the Union, thereby complementing obligations for providers of intermediary services that embed such systems or models into their services regulated by Regulation (EU) 2022/2065. To the extent that such systems or models are embedded into designated very large online platforms or very large online search engines, they are subject to the risk-management framework provided for in Regulation (EU) 2022/2065. Consequently, the corresponding obligations of this Regulation should be presumed to be fulfilled, unless significant systemic risks not covered by Regulation (EU) 2022/2065 emerge and are identified in such models. Within this framework, providers of very large online platforms and very large online search engines are obliged to assess potential systemic risks stemming from the design, functioning and use of their services, including how the design of algorithmic systems used in the service may contribute to such risks, as well as systemic risks stemming from potential misuses. Those providers are also obliged to take appropriate mitigating measures in observance of fundamental rights.\n(119)\nConsidering the quick pace of innovation and the technological evolution of digital services in scope of different instruments of Union law in particular having in mind the usage and the perception of their recipients, the AI systems subject to this Regulation may be provided as intermediary services or parts thereof within the meaning of Regulation (EU) 2022/2065, which should be interpreted in a technology-neutral manner. For example, AI systems may be used to provide online search engines, in particular, to the extent that an AI system such as an online chatbot performs searches of, in principle, all websites, then incorporates the results into its existing knowledge and uses the updated knowledge to generate a single output that combines different sources of information.\n(120)\nFurthermore, obligations placed on providers and deployers of certain AI systems in this Regulation to enable the detection and disclosure that the outputs of those systems are artificially generated or manipulated are particularly relevant to facilitate the effective implementation of Regulation (EU) 2022/2065. This applies in particular as regards the obligations of providers of very large online platforms or very large online search engines to identify and mitigate systemic risks that may arise from the dissemination of content that has been artificially generated or manipulated, in particular risk of the actual or foreseeable negative effects on democratic processes, civic discourse and electoral processes, including through disinformation.\n(121)\nStandardisation should play a key role to provide technical solutions to providers to ensure compliance with this Regulation, in line with the state of the art, to promote innovation as well as competitiveness and growth in the single market. Compliance with harmonised standards as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012 of the European Parliament and of the Council (41), which are normally expected to reflect the state of the art, should be a means for providers to demonstrate conformity with the requirements of this Regulation. A balanced representation of interests involving all relevant stakeholders in the development of standards, in particular SMEs, consumer organisations and environmental and social stakeholders in accordance with Articles 5 and 6 of Regulation (EU) No 1025/2012 should therefore be encouraged. In order to facilitate compliance, the standardisation requests should be issued by the Commission without undue delay. When preparing the standardisation request, the Commission should consult the advisory forum and the Board in order to collect relevant expertise. However, in the absence of relevant references to harmonised standards, the Commission should be able to establish, via implementing acts, and after consultation of the advisory forum, common specifications for certain requirements under this Regulation. The common specification should be an exceptional fall back solution to facilitate the provider’s obligation to comply with the requirements of this Regulation, when the standardisation request has not been accepted by any of the European standardisation organisations, or when the relevant harmonised standards insufficiently address fundamental rights concerns, or when the harmonised standards do not comply with the request, or when there are delays in the adoption of an appropriate harmonised standard. Where such a delay in the adoption of a harmonised standard is due to the technical complexity of that standard, this should be considered by the Commission before contemplating the establishment of common specifications. When developing common specifications, the Commission is encouraged to cooperate with international partners and international standardisation bodies.\n(122)\nIt is appropriate that, without prejudice to the use of harmonised standards and common specifications, providers of a high-risk AI system that has been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which the AI system is intended to be used, should be presumed to comply with the relevant measure provided for under the requirement on data governance set out in this Regulation. Without prejudice to the requirements related to robustness and accuracy set out in this Regulation, in accordance with Article 54(3) of Regulation (EU) 2019/881, high-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to that Regulation and the references of which have been published in the Official Journal of the European Union should be presumed to comply with the cybersecurity requirement of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover the cybersecurity requirement of this Regulation. This remains without prejudice to the voluntary nature of that cybersecurity scheme.\n(123)\nIn order to ensure a high level of trustworthiness of high-risk AI systems, those systems should be subject to a conformity assessment prior to their placing on the market or putting into service.\n(124)\nIt is appropriate that, in order to minimise the burden on operators and avoid any possible duplication, for high-risk AI systems related to products which are covered by existing Union harmonisation legislation based on the New Legislative Framework, the compliance of those AI systems with the requirements of this Regulation should be assessed as part of the conformity assessment already provided for in that law. The applicability of the requirements of this Regulation should thus not affect the specific logic, methodology or general structure of conformity assessment under the relevant Union harmonisation legislation.\n(125)\nGiven the complexity of high-risk AI systems and the risks that are associated with them, it is important to develop an adequate conformity assessment procedure for high-risk AI systems involving notified bodies, so-called third party conformity assessment. However, given the current experience of professional pre-market certifiers in the field of product safety and the different nature of risks involved, it is appropriate to limit, at least in an initial phase of application of this Regulation, the scope of application of third-party conformity assessment for high-risk AI systems other than those related to products. Therefore, the conformity assessment of such systems should be carried out as a general rule by the provider under its own responsibility, with the only exception of AI systems intended to be used for biometrics.\n(126)\nIn order to carry out third-party conformity assessments when so required, notified bodies should be notified under this Regulation by the national competent authorities, provided that they comply with a set of requirements, in particular on independence, competence, absence of conflicts of interests and suitable cybersecurity requirements. Notification of those bodies should be sent by national competent authorities to the Commission and the other Member States by means of the electronic notification tool developed and managed by the Commission pursuant to Article R23 of Annex I to Decision No 768/2008/EC.\n(127)\nIn line with Union commitments under the World Trade Organization Agreement on Technical Barriers to Trade, it is adequate to facilitate the mutual recognition of conformity assessment results produced by competent conformity assessment bodies, independent of the territory in which they are established, provided that those conformity assessment bodies established under the law of a third country meet the applicable requirements of this Regulation and the Union has concluded an agreement to that extent. In this context, the Commission should actively explore possible international instruments for that purpose and in particular pursue the conclusion of mutual recognition agreements with third countries.\n(128)\nIn line with the commonly established notion of substantial modification for products regulated by Union harmonisation legislation, it is appropriate that whenever a change occurs which may affect the compliance of a high-risk AI system with this Regulation (e.g. change of operating system or software architecture), or when the intended purpose of the system changes, that AI system should be considered to be a new AI system which should undergo a new conformity assessment. However, changes occurring to the algorithm and the performance of AI systems which continue to ‘learn’ after being placed on the market or put into service, namely automatically adapting how functions are carried out, should not constitute a substantial modification, provided that those changes have been pre-determined by the provider and assessed at the moment of the conformity assessment.\n(129)\nHigh-risk AI systems should bear the CE marking to indicate their conformity with this Regulation so that they can move freely within the internal market. For high-risk AI systems embedded in a product, a physical CE marking should be affixed, and may be complemented by a digital CE marking. For high-risk AI systems only provided digitally, a digital CE marking should be used. Member States should not create unjustified obstacles to the placing on the market or the putting into service of high-risk AI systems that comply with the requirements laid down in this Regulation and bear the CE marking.\n(130)\nUnder certain conditions, rapid availability of innovative technologies may be crucial for health and safety of persons, the protection of the environment and climate change and for society as a whole. It is thus appropriate that under exceptional reasons of public security or protection of life and health of natural persons, environmental protection and the protection of key industrial and infrastructural assets, market surveillance authorities could authorise the placing on the market or the putting into service of AI systems which have not undergone a conformity assessment. In duly justified situations, as provided for in this Regulation, law enforcement authorities or civil protection authorities may put a specific high-risk AI system into service without the authorisation of the market surveillance authority, provided that such authorisation is requested during or after the use without undue delay.\n(131)\nIn order to facilitate the work of the Commission and the Member States in the AI field as well as to increase the transparency towards the public, providers of high-risk AI systems other than those related to products falling within the scope of relevant existing Union harmonisation legislation, as well as providers who consider that an AI system listed in the high-risk use cases in an annex to this Regulation is not high-risk on the basis of a derogation, should be required to register themselves and information about their AI system in an EU database, to be established and managed by the Commission. Before using an AI system listed in the high-risk use cases in an annex to this Regulation, deployers of high-risk AI systems that are public authorities, agencies or bodies, should register themselves in such database and select the system that they envisage to use. Other deployers should be entitled to do so voluntarily. This section of the EU database should be publicly accessible, free of charge, the information should be easily navigable, understandable and machine-readable. The EU database should also be user-friendly, for example by providing search functionalities, including through keywords, allowing the general public to find relevant information to be submitted upon the registration of high-risk AI systems and on the use case of high-risk AI systems, set out in an annex to this Regulation, to which the high-risk AI systems correspond. Any substantial modification of high-risk AI systems should also be registered in the EU database. For high-risk AI systems in the area of law enforcement, migration, asylum and border control management, the registration obligations should be fulfilled in a secure non-public section of the EU database. Access to the secure non-public section should be strictly limited to the Commission as well as to market surveillance authorities with regard to their national section of that database. High-risk AI systems in the area of critical infrastructure should only be registered at national level. The Commission should be the controller of the EU database, in accordance with Regulation (EU) 2018/1725. In order to ensure the full functionality of the EU database, when deployed, the procedure for setting the database should include the development of functional specifications by the Commission and an independent audit report. The Commission should take into account cybersecurity risks when carrying out its tasks as data controller on the EU database. In order to maximise the availability and use of the EU database by the public, the EU database, including the information made available through it, should comply with requirements under the Directive (EU) 2019/882.\n(132)\nCertain AI systems intended to interact with natural persons or to generate content may pose specific risks of impersonation or deception irrespective of whether they qualify as high-risk or not. In certain circumstances, the use of these systems should therefore be subject to specific transparency obligations without prejudice to the requirements and obligations for high-risk AI systems and subject to targeted exceptions to take into account the special need of law enforcement. In particular, natural persons should be notified that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect taking into account the circumstances and the context of use. When implementing that obligation, the characteristics of natural persons belonging to vulnerable groups due to their age or disability should be taken into account to the extent the AI system is intended to interact with those groups as well. Moreover, natural persons should be notified when they are exposed to AI systems that, by processing their biometric data, can identify or infer the emotions or intentions of those persons or assign them to specific categories. Such specific categories can relate to aspects such as sex, age, hair colour, eye colour, tattoos, personal traits, ethnic origin, personal preferences and interests. Such information and notifications should be provided in accessible formats for persons with disabilities.\n(133)\nA variety of AI systems can generate large quantities of synthetic content that becomes increasingly hard for humans to distinguish from human-generated and authentic content. The wide availability and increasing capabilities of those systems have a significant impact on the integrity and trust in the information ecosystem, raising new risks of misinformation and manipulation at scale, fraud, impersonation and consumer deception. In light of those impacts, the fast technological pace and the need for new methods and techniques to trace origin of information, it is appropriate to require providers of those systems to embed technical solutions that enable marking in a machine readable format and detection that the output has been generated or manipulated by an AI system and not a human. Such techniques and methods should be sufficiently reliable, interoperable, effective and robust as far as this is technically feasible, taking into account available techniques or a combination of such techniques, such as watermarks, metadata identifications, cryptographic methods for proving provenance and authenticity of content, logging methods, fingerprints or other techniques, as may be appropriate. When implementing this obligation, providers should also take into account the specificities and the limitations of the different types of content and the relevant technological and market developments in the field, as reflected in the generally acknowledged state of the art. Such techniques and methods can be implemented at the level of the AI system or at the level of the AI model, including general-purpose AI models generating content, thereby facilitating fulfilment of this obligation by the downstream provider of the AI system. To remain proportionate, it is appropriate to envisage that this marking obligation should not cover AI systems performing primarily an assistive function for standard editing or AI systems not substantially altering the input data provided by the deployer or the semantics thereof.\n(134)\nFurther to the technical solutions employed by the providers of the AI system, deployers who use an AI system to generate or manipulate image, audio or video content that appreciably resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful (deep fakes), should also clearly and distinguishably disclose that the content has been artificially created or manipulated by labelling the AI output accordingly and disclosing its artificial origin. Compliance with this transparency obligation should not be interpreted as indicating that the use of the AI system or its output impedes the right to freedom of expression and the right to freedom of the arts and sciences guaranteed in the Charter, in particular where the content is part of an evidently creative, satirical, artistic, fictional or analogous work or programme, subject to appropriate safeguards for the rights and freedoms of third parties. In those cases, the transparency obligation for deep fakes set out in this Regulation is limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work, including its normal exploitation and use, while maintaining the utility and quality of the work. In addition, it is also appropriate to envisage a similar disclosure obligation in relation to AI-generated or manipulated text to the extent it is published with the purpose of informing the public on matters of public interest unless the AI-generated content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication of the content.\n(135)\nWithout prejudice to the mandatory nature and full applicability of the transparency obligations, the Commission may also encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection and labelling of artificially generated or manipulated content, including to support practical arrangements for making, as appropriate, the detection mechanisms accessible and facilitating cooperation with other actors along the value chain, disseminating content or checking its authenticity and provenance to enable the public to effectively distinguish AI-generated content.\n(136)\nThe obligations placed on providers and deployers of certain AI systems in this Regulation to enable the detection and disclosure that the outputs of those systems are artificially generated or manipulated are particularly relevant to facilitate the effective implementation of Regulation (EU) 2022/2065. This applies in particular as regards the obligations of providers of very large online platforms or very large online search engines to identify and mitigate systemic risks that may arise from the dissemination of content that has been artificially generated or manipulated, in particular the risk of the actual or foreseeable negative effects on democratic processes, civic discourse and electoral processes, including through disinformation. The requirement to label content generated by AI systems under this Regulation is without prejudice to the obligation in Article 16(6) of Regulation (EU) 2022/2065 for providers of hosting services to process notices on illegal content received pursuant to Article 16(1) of that Regulation and should not influence the assessment and the decision on the illegality of the specific content. That assessment should be performed solely with reference to the rules governing the legality of the content.\n(137)\nCompliance with the transparency obligations for the AI systems covered by this Regulation should not be interpreted as indicating that the use of the AI system or its output is lawful under this Regulation or other Union and Member State law and should be without prejudice to other transparency obligations for deployers of AI systems laid down in Union or national law.\n(138)\nAI is a rapidly developing family of technologies that requires regulatory oversight and a safe and controlled space for experimentation, while ensuring responsible innovation and integration of appropriate safeguards and risk mitigation measures. To ensure a legal framework that promotes innovation, is future-proof and resilient to disruption, Member States should ensure that their national competent authorities establish at least one AI regulatory sandbox at national level to facilitate the development and testing of innovative AI systems under strict regulatory oversight before these systems are placed on the market or otherwise put into service. Member States could also fulfil this obligation through participating in already existing regulatory sandboxes or establishing jointly a sandbox with one or more Member States’ competent authorities, insofar as this participation provides equivalent level of national coverage for the participating Member States. AI regulatory sandboxes could be established in physical, digital or hybrid form and may accommodate physical as well as digital products. Establishing authorities should also ensure that the AI regulatory sandboxes have the adequate resources for their functioning, including financial and human resources.\n(139)\nThe objectives of the AI regulatory sandboxes should be to foster AI innovation by establishing a controlled experimentation and testing environment in the development and pre-marketing phase with a view to ensuring compliance of the innovative AI systems with this Regulation and other relevant Union and national law. Moreover, the AI regulatory sandboxes should aim to enhance legal certainty for innovators and the competent authorities’ oversight and understanding of the opportunities, emerging risks and the impacts of AI use, to facilitate regulatory learning for authorities and undertakings, including with a view to future adaptions of the legal framework, to support cooperation and the sharing of best practices with the authorities involved in the AI regulatory sandbox, and to accelerate access to markets, including by removing barriers for SMEs, including start-ups. AI regulatory sandboxes should be widely available throughout the Union, and particular attention should be given to their accessibility for SMEs, including start-ups. The participation in the AI regulatory sandbox should focus on issues that raise legal uncertainty for providers and prospective providers to innovate, experiment with AI in the Union and contribute to evidence-based regulatory learning. The supervision of the AI systems in the AI regulatory sandbox should therefore cover their development, training, testing and validation before the systems are placed on the market or put into service, as well as the notion and occurrence of substantial modification that may require a new conformity assessment procedure. Any significant risks identified during the development and testing of such AI systems should result in adequate mitigation and, failing that, in the suspension of the development and testing process. Where appropriate, national competent authorities establishing AI regulatory sandboxes should cooperate with other relevant authorities, including those supervising the protection of fundamental rights, and could allow for the involvement of other actors within the AI ecosystem such as national or European standardisation organisations, notified bodies, testing and experimentation facilities, research and experimentation labs, European Digital Innovation Hubs and relevant stakeholder and civil society organisations. To ensure uniform implementation across the Union and economies of scale, it is appropriate to establish common rules for the AI regulatory sandboxes’ implementation and a framework for cooperation between the relevant authorities involved in the supervision of the sandboxes. AI regulatory sandboxes established under this Regulation should be without prejudice to other law allowing for the establishment of other sandboxes aiming to ensure compliance with law other than this Regulation. Where appropriate, relevant competent authorities in charge of those other regulatory sandboxes should consider the benefits of using those sandboxes also for the purpose of ensuring compliance of AI systems with this Regulation. Upon agreement between the national competent authorities and the participants in the AI regulatory sandbox, testing in real world conditions may also be operated and supervised in the framework of the AI regulatory sandbox.\n(140)\nThis Regulation should provide the legal basis for the providers and prospective providers in the AI regulatory sandbox to use personal data collected for other purposes for developing certain AI systems in the public interest within the AI regulatory sandbox, only under specified conditions, in accordance with Article 6(4) and Article 9(2), point (g), of Regulation (EU) 2016/679, and Articles 5, 6 and 10 of Regulation (EU) 2018/1725, and without prejudice to Article 4(2) and Article 10 of Directive (EU) 2016/680. All other obligations of data controllers and rights of data subjects under Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 remain applicable. In particular, this Regulation should not provide a legal basis in the meaning of Article 22(2), point (b) of Regulation (EU) 2016/679 and Article 24(2), point (b) of Regulation (EU) 2018/1725. Providers and prospective providers in the AI regulatory sandbox should ensure appropriate safeguards and cooperate with the competent authorities, including by following their guidance and acting expeditiously and in good faith to adequately mitigate any identified significant risks to safety, health, and fundamental rights that may arise during the development, testing and experimentation in that sandbox.\n(141)\nIn order to accelerate the process of development and the placing on the market of the high-risk AI systems listed in an annex to this Regulation, it is important that providers or prospective providers of such systems may also benefit from a specific regime for testing those systems in real world conditions, without participating in an AI regulatory sandbox. However, in such cases, taking into account the possible consequences of such testing on individuals, it should be ensured that appropriate and sufficient guarantees and conditions are introduced by this Regulation for providers or prospective providers. Such guarantees should include, inter alia, requesting informed consent of natural persons to participate in testing in real world conditions, with the exception of law enforcement where the seeking of informed consent would prevent the AI system from being tested. Consent of subjects to participate in such testing under this Regulation is distinct from, and without prejudice to, consent of data subjects for the processing of their personal data under the relevant data protection law. It is also important to minimise the risks and enable oversight by competent authorities and therefore require prospective providers to have a real-world testing plan submitted to competent market surveillance authority, register the testing in dedicated sections in the EU database subject to some limited exceptions, set limitations on the period for which the testing can be done and require additional safeguards for persons belonging to certain vulnerable groups, as well as a written agreement defining the roles and responsibilities of prospective providers and deployers and effective oversight by competent personnel involved in the real world testing. Furthermore, it is appropriate to envisage additional safeguards to ensure that the predictions, recommendations or decisions of the AI system can be effectively reversed and disregarded and that personal data is protected and is deleted when the subjects have withdrawn their consent to participate in the testing without prejudice to their rights as data subjects under the Union data protection law. As regards transfer of data, it is also appropriate to envisage that data collected and processed for the purpose of testing in real-world conditions should be transferred to third countries only where appropriate and applicable safeguards under Union law are implemented, in particular in accordance with bases for transfer of personal data under Union law on data protection, while for non-personal data appropriate safeguards are put in place in accordance with Union law, such as Regulations (EU) 2022/868 (42) and (EU) 2023/2854 (43) of the European Parliament and of the Council.\n(142)\nTo ensure that AI leads to socially and environmentally beneficial outcomes, Member States are encouraged to support and promote research and development of AI solutions in support of socially and environmentally beneficial outcomes, such as AI-based solutions to increase accessibility for persons with disabilities, tackle socio-economic inequalities, or meet environmental targets, by allocating sufficient resources, including public and Union funding, and, where appropriate and provided that the eligibility and selection criteria are fulfilled, considering in particular projects which pursue such objectives. Such projects should be based on the principle of interdisciplinary cooperation between AI developers, experts on inequality and non-discrimination, accessibility, consumer, environmental, and digital rights, as well as academics.\n(143)\nIn order to promote and protect innovation, it is important that the interests of SMEs, including start-ups, that are providers or deployers of AI systems are taken into particular account. To that end, Member States should develop initiatives, which are targeted at those operators, including on awareness raising and information communication. Member States should provide SMEs, including start-ups, that have a registered office or a branch in the Union, with priority access to the AI regulatory sandboxes provided that they fulfil the eligibility conditions and selection criteria and without precluding other providers and prospective providers to access the sandboxes provided the same conditions and criteria are fulfilled. Member States should utilise existing channels and where appropriate, establish new dedicated channels for communication with SMEs, including start-ups, deployers, other innovators and, as appropriate, local public authorities, to support SMEs throughout their development path by providing guidance and responding to queries about the implementation of this Regulation. Where appropriate, these channels should work together to create synergies and ensure homogeneity in their guidance to SMEs, including start-ups, and deployers. Additionally, Member States should facilitate the participation of SMEs and other relevant stakeholders in the standardisation development processes. Moreover, the specific interests and needs of providers that are SMEs, including start-ups, should be taken into account when notified bodies set conformity assessment fees. The Commission should regularly assess the certification and compliance costs for SMEs, including start-ups, through transparent consultations and should work with Member States to lower such costs. For example, translation costs related to mandatory documentation and communication with authorities may constitute a significant cost for providers and other operators, in particular those of a smaller scale. Member States should possibly ensure that one of the languages determined and accepted by them for relevant providers’ documentation and for communication with operators is one which is broadly understood by the largest possible number of cross-border deployers. In order to address the specific needs of SMEs, including start-ups, the Commission should provide standardised templates for the areas covered by this Regulation, upon request of the Board. Additionally, the Commission should complement Member States’ efforts by providing a single information platform with easy-to-use information with regards to this Regulation for all providers and deployers, by organising appropriate communication campaigns to raise awareness about the obligations arising from this Regulation, and by evaluating and promoting the convergence of best practices in public procurement procedures in relation to AI systems. Medium-sized enterprises which until recently qualified as small enterprises within the meaning of the Annex to Commission Recommendation 2003/361/EC (44) should have access to those support measures, as those new medium-sized enterprises may sometimes lack the legal resources and training necessary to ensure proper understanding of, and compliance with, this Regulation.\n(144)\nIn order to promote and protect innovation, the AI-on-demand platform, all relevant Union funding programmes and projects, such as Digital Europe Programme, Horizon Europe, implemented by the Commission and the Member States at Union or national level should, as appropriate, contribute to the achievement of the objectives of this Regulation.\n(145)\nIn order to minimise the risks to implementation resulting from lack of knowledge and expertise in the market as well as to facilitate compliance of providers, in particular SMEs, including start-ups, and notified bodies with their obligations under this Regulation, the AI-on-demand platform, the European Digital Innovation Hubs and the testing and experimentation facilities established by the Commission and the Member States at Union or national level should contribute to the implementation of this Regulation. Within their respective mission and fields of competence, the AI-on-demand platform, the European Digital Innovation Hubs and the testing and experimentation Facilities are able to provide in particular technical and scientific support to providers and notified bodies.\n(146)\nMoreover, in light of the very small size of some operators and in order to ensure proportionality regarding costs of innovation, it is appropriate to allow microenterprises to fulfil one of the most costly obligations, namely to establish a quality management system, in a simplified manner which would reduce the administrative burden and the costs for those enterprises without affecting the level of protection and the need for compliance with the requirements for high-risk AI systems. The Commission should develop guidelines to specify the elements of the quality management system to be fulfilled in this simplified manner by microenterprises.\n(147)\nIt is appropriate that the Commission facilitates, to the extent possible, access to testing and experimentation facilities to bodies, groups or laboratories established or accredited pursuant to any relevant Union harmonisation legislation and which fulfil tasks in the context of conformity assessment of products or devices covered by that Union harmonisation legislation. This is, in particular, the case as regards expert panels, expert laboratories and reference laboratories in the field of medical devices pursuant to Regulations (EU) 2017/745 and (EU) 2017/746.\n(148)\nThis Regulation should establish a governance framework that both allows to coordinate and support the application of this Regulation at national level, as well as build capabilities at Union level and integrate stakeholders in the field of AI. The effective implementation and enforcement of this Regulation require a governance framework that allows to coordinate and build up central expertise at Union level. The AI Office was established by Commission Decision (45) and has as its mission to develop Union expertise and capabilities in the field of AI and to contribute to the implementation of Union law on AI. Member States should facilitate the tasks of the AI Office with a view to support the development of Union expertise and capabilities at Union level and to strengthen the functioning of the digital single market. Furthermore, a Board composed of representatives of the Member States, a scientific panel to integrate the scientific community and an advisory forum to contribute stakeholder input to the implementation of this Regulation, at Union and national level, should be established. The development of Union expertise and capabilities should also include making use of existing resources and expertise, in particular through synergies with structures built up in the context of the Union level enforcement of other law and synergies with related initiatives at Union level, such as the EuroHPC Joint Undertaking and the AI testing and experimentation facilities under the Digital Europe Programme.\n(149)\nIn order to facilitate a smooth, effective and harmonised implementation of this Regulation a Board should be established. The Board should reflect the various interests of the AI eco-system and be composed of representatives of the Member States. The Board should be responsible for a number of advisory tasks, including issuing opinions, recommendations, advice or contributing to guidance on matters related to the implementation of this Regulation, including on enforcement matters, technical specifications or existing standards regarding the requirements established in this Regulation and providing advice to the Commission and the Member States and their national competent authorities on specific questions related to AI. In order to give some flexibility to Member States in the designation of their representatives in the Board, such representatives may be any persons belonging to public entities who should have the relevant competences and powers to facilitate coordination at national level and contribute to the achievement of the Board’s tasks. The Board should establish two standing sub-groups to provide a platform for cooperation and exchange among market surveillance authorities and notifying authorities on issues related, respectively, to market surveillance and notified bodies. The standing subgroup for market surveillance should act as the administrative cooperation group (ADCO) for this Regulation within the meaning of Article 30 of Regulation (EU) 2019/1020. In accordance with Article 33 of that Regulation, the Commission should support the activities of the standing subgroup for market surveillance by undertaking market evaluations or studies, in particular with a view to identifying aspects of this Regulation requiring specific and urgent coordination among market surveillance authorities. The Board may establish other standing or temporary sub-groups as appropriate for the purpose of examining specific issues. The Board should also cooperate, as appropriate, with relevant Union bodies, experts groups and networks active in the context of relevant Union law, including in particular those active under relevant Union law on data, digital products and services.\n(150)\nWith a view to ensuring the involvement of stakeholders in the implementation and application of this Regulation, an advisory forum should be established to advise and provide technical expertise to the Board and the Commission. To ensure a varied and balanced stakeholder representation between commercial and non-commercial interest and, within the category of commercial interests, with regards to SMEs and other undertakings, the advisory forum should comprise inter alia industry, start-ups, SMEs, academia, civil society, including the social partners, as well as the Fundamental Rights Agency, ENISA, the European Committee for Standardization (CEN), the European Committee for Electrotechnical Standardization (CENELEC) and the European Telecommunications Standards Institute (ETSI).\n(151)\nTo support the implementation and enforcement of this Regulation, in particular the monitoring activities of the AI Office as regards general-purpose AI models, a scientific panel of independent experts should be established. The independent experts constituting the scientific panel should be selected on the basis of up-to-date scientific or technical expertise in the field of AI and should perform their tasks with impartiality, objectivity and ensure the confidentiality of information and data obtained in carrying out their tasks and activities. To allow the reinforcement of national capacities necessary for the effective enforcement of this Regulation, Member States should be able to request support from the pool of experts constituting the scientific panel for their enforcement activities.\n(152)\nIn order to support adequate enforcement as regards AI systems and reinforce the capacities of the Member States, Union AI testing support structures should be established and made available to the Member States.\n(153)\nMember States hold a key role in the application and enforcement of this Regulation. In that respect, each Member State should designate at least one notifying authority and at least one market surveillance authority as national competent authorities for the purpose of supervising the application and implementation of this Regulation. Member States may decide to appoint any kind of public entity to perform the tasks of the national competent authorities within the meaning of this Regulation, in accordance with their specific national organisational characteristics and needs. In order to increase organisation efficiency on the side of Member States and to set a single point of contact vis-à-vis the public and other counterparts at Member State and Union levels, each Member State should designate a market surveillance authority to act as a single point of contact.\n(154)\nThe national competent authorities should exercise their powers independently, impartially and without bias, so as to safeguard the principles of objectivity of their activities and tasks and to ensure the application and implementation of this Regulation. The members of these authorities should refrain from any action incompatible with their duties and should be subject to confidentiality rules under this Regulation.\n(155)\nIn order to ensure that providers of high-risk AI systems can take into account the experience on the use of high-risk AI systems for improving their systems and the design and development process or can take any possible corrective action in a timely manner, all providers should have a post-market monitoring system in place. Where relevant, post-market monitoring should include an analysis of the interaction with other AI systems including other devices and software. Post-market monitoring should not cover sensitive operational data of deployers which are law enforcement authorities. This system is also key to ensure that the possible risks emerging from AI systems which continue to ‘learn’ after being placed on the market or put into service can be more efficiently and timely addressed. In this context, providers should also be required to have a system in place to report to the relevant authorities any serious incidents resulting from the use of their AI systems, meaning incident or malfunctioning leading to death or serious damage to health, serious and irreversible disruption of the management and operation of critical infrastructure, infringements of obligations under Union law intended to protect fundamental rights or serious damage to property or the environment.\n(156)\nIn order to ensure an appropriate and effective enforcement of the requirements and obligations set out by this Regulation, which is Union harmonisation legislation, the system of market surveillance and compliance of products established by Regulation (EU) 2019/1020 should apply in its entirety. Market surveillance authorities designated pursuant to this Regulation should have all enforcement powers laid down in this Regulation and in Regulation (EU) 2019/1020 and should exercise their powers and carry out their duties independently, impartially and without bias. Although the majority of AI systems are not subject to specific requirements and obligations under this Regulation, market surveillance authorities may take measures in relation to all AI systems when they present a risk in accordance with this Regulation. Due to the specific nature of Union institutions, agencies and bodies falling within the scope of this Regulation, it is appropriate to designate the European Data Protection Supervisor as a competent market surveillance authority for them. This should be without prejudice to the designation of national competent authorities by the Member States. Market surveillance activities should not affect the ability of the supervised entities to carry out their tasks independently, when such independence is required by Union law.\n(157)\nThis Regulation is without prejudice to the competences, tasks, powers and independence of relevant national public authorities or bodies which supervise the application of Union law protecting fundamental rights, including equality bodies and data protection authorities. Where necessary for their mandate, those national public authorities or bodies should also have access to any documentation created under this Regulation. A specific safeguard procedure should be set for ensuring adequate and timely enforcement against AI systems presenting a risk to health, safety and fundamental rights. The procedure for such AI systems presenting a risk should be applied to high-risk AI systems presenting a risk, prohibited systems which have been placed on the market, put into service or used in violation of the prohibited practices laid down in this Regulation and AI systems which have been made available in violation of the transparency requirements laid down in this Regulation and present a risk.\n(158)\nUnion financial services law includes internal governance and risk-management rules and requirements which are applicable to regulated financial institutions in the course of provision of those services, including when they make use of AI systems. In order to ensure coherent application and enforcement of the obligations under this Regulation and relevant rules and requirements of the Union financial services legal acts, the competent authorities for the supervision and enforcement of those legal acts, in particular competent authorities as defined in Regulation (EU) No 575/2013 of the European Parliament and of the Council (46) and Directives 2008/48/EC (47), 2009/138/EC (48), 2013/36/EU (49), 2014/17/EU (50) and (EU) 2016/97 (51) of the European Parliament and of the Council, should be designated, within their respective competences, as competent authorities for the purpose of supervising the implementation of this Regulation, including for market surveillance activities, as regards AI systems provided or used by regulated and supervised financial institutions unless Member States decide to designate another authority to fulfil these market surveillance tasks. Those competent authorities should have all powers under this Regulation and Regulation (EU) 2019/1020 to enforce the requirements and obligations of this Regulation, including powers to carry our ex post market surveillance activities that can be integrated, as appropriate, into their existing supervisory mechanisms and procedures under the relevant Union financial services law. It is appropriate to envisage that, when acting as market surveillance authorities under this Regulation, the national authorities responsible for the supervision of credit institutions regulated under Directive 2013/36/EU, which are participating in the Single Supervisory Mechanism established by Council Regulation (EU) No 1024/2013 (52), should report, without delay, to the European Central Bank any information identified in the course of their market surveillance activities that may be of potential interest for the European Central Bank’s prudential supervisory tasks as specified in that Regulation. To further enhance the consistency between this Regulation and the rules applicable to credit institutions regulated under Directive 2013/36/EU, it is also appropriate to integrate some of the providers’ procedural obligations in relation to risk management, post marketing monitoring and documentation into the existing obligations and procedures under Directive 2013/36/EU. In order to avoid overlaps, limited derogations should also be envisaged in relation to the quality management system of providers and the monitoring obligation placed on deployers of high-risk AI systems to the extent that these apply to credit institutions regulated by Directive 2013/36/EU. The same regime should apply to insurance and re-insurance undertakings and insurance holding companies under Directive 2009/138/EC and the insurance intermediaries under Directive (EU) 2016/97 and other types of financial institutions subject to requirements regarding internal governance, arrangements or processes established pursuant to the relevant Union financial services law to ensure consistency and equal treatment in the financial sector.\n(159)\nEach market surveillance authority for high-risk AI systems in the area of biometrics, as listed in an annex to this Regulation insofar as those systems are used for the purposes of law enforcement, migration, asylum and border control management, or the administration of justice and democratic processes, should have effective investigative and corrective powers, including at least the power to obtain access to all personal data that are being processed and to all information necessary for the performance of its tasks. The market surveillance authorities should be able to exercise their powers by acting with complete independence. Any limitations of their access to sensitive operational data under this Regulation should be without prejudice to the powers conferred to them by Directive (EU) 2016/680. No exclusion on disclosing data to national data protection authorities under this Regulation should affect the current or future powers of those authorities beyond the scope of this Regulation.\n(160)\nThe market surveillance authorities and the Commission should be able to propose joint activities, including joint investigations, to be conducted by market surveillance authorities or market surveillance authorities jointly with the Commission, that have the aim of promoting compliance, identifying non-compliance, raising awareness and providing guidance in relation to this Regulation with respect to specific categories of high-risk AI systems that are found to present a serious risk across two or more Member States. Joint activities to promote compliance should be carried out in accordance with Article 9 of Regulation (EU) 2019/1020. The AI Office should provide coordination support for joint investigations.\n(161)\nIt is necessary to clarify the responsibilities and competences at Union and national level as regards AI systems that are built on general-purpose AI models. To avoid overlapping competences, where an AI system is based on a general-purpose AI model and the model and system are provided by the same provider, the supervision should take place at Union level through the AI Office, which should have the powers of a market surveillance authority within the meaning of Regulation (EU) 2019/1020 for this purpose. In all other cases, national market surveillance authorities remain responsible for the supervision of AI systems. However, for general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk, market surveillance authorities should cooperate with the AI Office to carry out evaluations of compliance and inform the Board and other market surveillance authorities accordingly. Furthermore, market surveillance authorities should be able to request assistance from the AI Office where the market surveillance authority is unable to conclude an investigation on a high-risk AI system because of its inability to access certain information related to the general-purpose AI model on which the high-risk AI system is built. In such cases, the procedure regarding mutual assistance in cross-border cases in Chapter VI of Regulation (EU) 2019/1020 should apply mutatis mutandis.\n(162)\nTo make best use of the centralised Union expertise and synergies at Union level, the powers of supervision and enforcement of the obligations on providers of general-purpose AI models should be a competence of the Commission. The AI Office should be able to carry out all necessary actions to monitor the effective implementation of this Regulation as regards general-purpose AI models. It should be able to investigate possible infringements of the rules on providers of general-purpose AI models both on its own initiative, following the results of its monitoring activities, or upon request from market surveillance authorities in line with the conditions set out in this Regulation. To support effective monitoring of the AI Office, it should provide for the possibility that downstream providers lodge complaints about possible infringements of the rules on providers of general-purpose AI models and systems.\n(163)\nWith a view to complementing the governance systems for general-purpose AI models, the scientific panel should support the monitoring activities of the AI Office and may, in certain cases, provide qualified alerts to the AI Office which trigger follow-ups, such as investigations. This should be the case where the scientific panel has reason to suspect that a general-purpose AI model poses a concrete and identifiable risk at Union level. Furthermore, this should be the case where the scientific panel has reason to suspect that a general-purpose AI model meets the criteria that would lead to a classification as general-purpose AI model with systemic risk. To equip the scientific panel with the information necessary for the performance of those tasks, there should be a mechanism whereby the scientific panel can request the Commission to require documentation or information from a provider.\n(164)\nThe AI Office should be able to take the necessary actions to monitor the effective implementation of and compliance with the obligations for providers of general-purpose AI models laid down in this Regulation. The AI Office should be able to investigate possible infringements in accordance with the powers provided for in this Regulation, including by requesting documentation and information, by conducting evaluations, as well as by requesting measures from providers of general-purpose AI models. When conducting evaluations, in order to make use of independent expertise, the AI Office should be able to involve independent experts to carry out the evaluations on its behalf. Compliance with the obligations should be enforceable, inter alia, through requests to take appropriate measures, including risk mitigation measures in the case of identified systemic risks as well as restricting the making available on the market, withdrawing or recalling the model. As a safeguard, where needed beyond the procedural rights provided for in this Regulation, providers of general-purpose AI models should have the procedural rights provided for in Article 18 of Regulation (EU) 2019/1020, which should apply mutatis mutandis, without prejudice to more specific procedural rights provided for by this Regulation.\n(165)\nThe development of AI systems other than high-risk AI systems in accordance with the requirements of this Regulation may lead to a larger uptake of ethical and trustworthy AI in the Union. Providers of AI systems that are not high-risk should be encouraged to create codes of conduct, including related governance mechanisms, intended to foster the voluntary application of some or all of the mandatory requirements applicable to high-risk AI systems, adapted in light of the intended purpose of the systems and the lower risk involved and taking into account the available technical solutions and industry best practices such as model and data cards. Providers and, as appropriate, deployers of all AI systems, high-risk or not, and AI models should also be encouraged to apply on a voluntary basis additional requirements related, for example, to the elements of the Union’s Ethics Guidelines for Trustworthy AI, environmental sustainability, AI literacy measures, inclusive and diverse design and development of AI systems, including attention to vulnerable persons and accessibility to persons with disability, stakeholders’ participation with the involvement, as appropriate, of relevant stakeholders such as business and civil society organisations, academia, research organisations, trade unions and consumer protection organisations in the design and development of AI systems, and diversity of the development teams, including gender balance. To ensure that the voluntary codes of conduct are effective, they should be based on clear objectives and key performance indicators to measure the achievement of those objectives. They should also be developed in an inclusive way, as appropriate, with the involvement of relevant stakeholders such as business and civil society organisations, academia, research organisations, trade unions and consumer protection organisation. The Commission may develop initiatives, including of a sectoral nature, to facilitate the lowering of technical barriers hindering cross-border exchange of data for AI development, including on data access infrastructure, semantic and technical interoperability of different types of data.\n(166)\nIt is important that AI systems related to products that are not high-risk in accordance with this Regulation and thus are not required to comply with the requirements set out for high-risk AI systems are nevertheless safe when placed on the market or put into service. To contribute to this objective, Regulation (EU) 2023/988 of the European Parliament and of the Council (53) would apply as a safety net.\n(167)\nIn order to ensure trustful and constructive cooperation of competent authorities on Union and national level, all parties involved in the application of this Regulation should respect the confidentiality of information and data obtained in carrying out their tasks, in accordance with Union or national law. They should carry out their tasks and activities in such a manner as to protect, in particular, intellectual property rights, confidential business information and trade secrets, the effective implementation of this Regulation, public and national security interests, the integrity of criminal and administrative proceedings, and the integrity of classified information.\n(168)\nCompliance with this Regulation should be enforceable by means of the imposition of penalties and other enforcement measures. Member States should take all necessary measures to ensure that the provisions of this Regulation are implemented, including by laying down effective, proportionate and dissuasive penalties for their infringement, and to respect the ne bis in idem principle. In order to strengthen and harmonise administrative penalties for infringement of this Regulation, the upper limits for setting the administrative fines for certain specific infringements should be laid down. When assessing the amount of the fines, Member States should, in each individual case, take into account all relevant circumstances of the specific situation, with due regard in particular to the nature, gravity and duration of the infringement and of its consequences and to the size of the provider, in particular if the provider is an SME, including a start-up. The European Data Protection Supervisor should have the power to impose fines on Union institutions, agencies and bodies falling within the scope of this Regulation.\n(169)\nCompliance with the obligations on providers of general-purpose AI models imposed under this Regulation should be enforceable, inter alia, by means of fines. To that end, appropriate levels of fines should also be laid down for infringement of those obligations, including the failure to comply with measures requested by the Commission in accordance with this Regulation, subject to appropriate limitation periods in accordance with the principle of proportionality. All decisions taken by the Commission under this Regulation are subject to review by the Court of Justice of the European Union in accordance with the TFEU, including the unlimited jurisdiction of the Court of Justice with regard to penalties pursuant to Article 261 TFEU.\n(170)\nUnion and national law already provide effective remedies to natural and legal persons whose rights and freedoms are adversely affected by the use of AI systems. Without prejudice to those remedies, any natural or legal person that has grounds to consider that there has been an infringement of this Regulation should be entitled to lodge a complaint to the relevant market surveillance authority.\n(171)\nAffected persons should have the right to obtain an explanation where a deployer’s decision is based mainly upon the output from certain high-risk AI systems that fall within the scope of this Regulation and where that decision produces legal effects or similarly significantly affects those persons in a way that they consider to have an adverse impact on their health, safety or fundamental rights. That explanation should be clear and meaningful and should provide a basis on which the affected persons are able to exercise their rights. The right to obtain an explanation should not apply to the use of AI systems for which exceptions or restrictions follow from Union or national law and should apply only to the extent this right is not already provided for under Union law.\n(172)\nPersons acting as whistleblowers on the infringements of this Regulation should be protected under the Union law. Directive (EU) 2019/1937 of the European Parliament and of the Council (54) should therefore apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.\n(173)\nIn order to ensure that the regulatory framework can be adapted where necessary, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission to amend the conditions under which an AI system is not to be considered to be high-risk, the list of high-risk AI systems, the provisions regarding technical documentation, the content of the EU declaration of conformity the provisions regarding the conformity assessment procedures, the provisions establishing the high-risk AI systems to which the conformity assessment procedure based on assessment of the quality management system and assessment of the technical documentation should apply, the threshold, benchmarks and indicators, including by supplementing those benchmarks and indicators, in the rules for the classification of general-purpose AI models with systemic risk, the criteria for the designation of general-purpose AI models with systemic risk, the technical documentation for providers of general-purpose AI models and the transparency information for providers of general-purpose AI models. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (55). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.\n(174)\nGiven the rapid technological developments and the technical expertise required to effectively apply this Regulation, the Commission should evaluate and review this Regulation by 2 August 2029 and every four years thereafter and report to the European Parliament and the Council. In addition, taking into account the implications for the scope of this Regulation, the Commission should carry out an assessment of the need to amend the list of high-risk AI systems and the list of prohibited practices once a year. Moreover, by 2 August 2028 and every four years thereafter, the Commission should evaluate and report to the European Parliament and to the Council on the need to amend the list of high-risk areas headings in the annex to this Regulation, the AI systems within the scope of the transparency obligations, the effectiveness of the supervision and governance system and the progress on the development of standardisation deliverables on energy efficient development of general-purpose AI models, including the need for further measures or actions. Finally, by 2 August 2028 and every three years thereafter, the Commission should evaluate the impact and effectiveness of voluntary codes of conduct to foster the application of the requirements provided for high-risk AI systems in the case of AI systems other than high-risk AI systems and possibly other additional requirements for such AI systems.\n(175)\nIn order to ensure uniform conditions for the implementation of this Regulation, implementing powers should be conferred on the Commission. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council (56).\n(176)\nSince the objective of this Regulation, namely to improve the functioning of the internal market and to promote the uptake of human centric and trustworthy AI, while ensuring a high level of protection of health, safety, fundamental rights enshrined in the Charter, including democracy, the rule of law and environmental protection against harmful effects of AI systems in the Union and supporting innovation, cannot be sufficiently achieved by the Member States and can rather, by reason of the scale or effects of the action, be better achieved at Union level, the Union may adopt measures in accordance with the principle of subsidiarity as set out in Article 5 TEU. In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective.\n(177)\nIn order to ensure legal certainty, ensure an appropriate adaptation period for operators and avoid disruption to the market, including by ensuring continuity of the use of AI systems, it is appropriate that this Regulation applies to the high-risk AI systems that have been placed on the market or put into service before the general date of application thereof, only if, from that date, those systems are subject to significant changes in their design or intended purpose. It is appropriate to clarify that, in this respect, the concept of significant change should be understood as equivalent in substance to the notion of substantial modification, which is used with regard only to high-risk AI systems pursuant to this Regulation. On an exceptional basis and in light of public accountability, operators of AI systems which are components of the large-scale IT systems established by the legal acts listed in an annex to this Regulation and operators of high-risk AI systems that are intended to be used by public authorities should, respectively, take the necessary steps to comply with the requirements of this Regulation by end of 2030 and by 2 August 2030.\n(178)\nProviders of high-risk AI systems are encouraged to start to comply, on a voluntary basis, with the relevant obligations of this Regulation already during the transitional period.\n(179)\nThis Regulation should apply from 2 August 2026. However, taking into account the unacceptable risk associated with the use of AI in certain ways, the prohibitions as well as the general provisions of this Regulation should already apply from 2 February 2025. While the full effect of those prohibitions follows with the establishment of the governance and enforcement of this Regulation, anticipating the application of the prohibitions is important to take account of unacceptable risks and to have an effect on other procedures, such as in civil law. Moreover, the infrastructure related to the governance and the conformity assessment system should be operational before 2 August 2026, therefore the provisions on notified bodies and governance structure should apply from 2 August 2025. Given the rapid pace of technological advancements and adoption of general-purpose AI models, obligations for providers of general-purpose AI models should apply from 2 August 2025. Codes of practice should be ready by 2 May 2025 in view of enabling providers to demonstrate compliance on time. The AI Office should ensure that classification rules and procedures are up to date in light of technological developments. In addition, Member States should lay down and notify to the Commission the rules on penalties, including administrative fines, and ensure that they are properly and effectively implemented by the date of application of this Regulation. Therefore the provisions on penalties should apply from 2 August 2025.\n(180)\nThe European Data Protection Supervisor and the European Data Protection Board were consulted in accordance with Article 42(1) and (2) of Regulation (EU) 2018/1725 and delivered their joint opinion on 18 June 2021,\nHAVE ADOPTED THIS REGULATION:\nCHAPTER I GENERAL PROVISIONS\nArticle 1 Subject matter The purpose of this Regulation is to improve the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence (AI), while ensuring a high level of protection of health, safety, fundamental rights enshrined in the Charter, including democracy, the rule of law and environmental protection, against the harmful effects of AI systems in the Union and supporting innovation.\nThis Regulation lays down:\n(a)\nharmonised rules for the placing on the market, the putting into service, and the use of AI systems in the Union;\n(b)\nprohibitions of certain AI practices;\n(c)\nspecific requirements for high-risk AI systems and obligations for operators of such systems;\n(d)\nharmonised transparency rules for certain AI systems;\n(e)\nharmonised rules for the placing on the market of general-purpose AI models;\n(f)\nrules on market monitoring, market surveillance, governance and enforcement;\n(g)\nmeasures to support innovation, with a particular focus on SMEs, including start-ups.\nArticle 2 Scope This Regulation applies to: (a)\nproviders placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country;\n(b)\ndeployers of AI systems that have their place of establishment or are located within the Union;\n(c)\nproviders and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union;\n(d)\nimporters and distributors of AI systems;\n(e)\nproduct manufacturers placing on the market or putting into service an AI system together with their product and under their own name or trademark;\n(f)\nauthorised representatives of providers, which are not established in the Union;\n(g)\naffected persons that are located in the Union.\nFor AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 apply. Article 57 applies only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation.\nThis Regulation does not apply to areas outside the scope of Union law, and shall not, in any event, affect the competences of the Member States concerning national security, regardless of the type of entity entrusted by the Member States with carrying out tasks in relation to those competences.\nThis Regulation does not apply to AI systems where and in so far they are placed on the market, put into service, or used with or without modification exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities.\nThis Regulation does not apply to AI systems which are not placed on the market or put into service in the Union, where the output is used in the Union exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities.\nThis Regulation applies neither to public authorities in a third country nor to international organisations falling within the scope of this Regulation pursuant to paragraph 1, where those authorities or organisations use AI systems in the framework of international cooperation or agreements for law enforcement and judicial cooperation with the Union or with one or more Member States, provided that such a third country or international organisation provides adequate safeguards with respect to the protection of fundamental rights and freedoms of individuals.\nThis Regulation shall not affect the application of the provisions on the liability of providers of intermediary services as set out in Chapter II of Regulation (EU) 2022/2065.\nThis Regulation does not apply to AI systems or AI models, including their output, specifically developed and put into service for the sole purpose of scientific research and development.\nUnion law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. This Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680, without prejudice to Article 10(5) and Article 59 of this Regulation.\nThis Regulation does not apply to any research, testing or development activity regarding AI systems or AI models prior to their being placed on the market or put into service. Such activities shall be conducted in accordance with applicable Union law. Testing in real world conditions shall not be covered by that exclusion.\nThis Regulation is without prejudice to the rules laid down by other Union legal acts related to consumer protection and product safety.\nThis Regulation does not apply to obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity.\nThis Regulation does not preclude the Union or Member States from maintaining or introducing laws, regulations or administrative provisions which are more favourable to workers in terms of protecting their rights in respect of the use of AI systems by employers, or from encouraging or allowing the application of collective agreements which are more favourable to workers.\nThis Regulation does not apply to AI systems released under free and open-source licences, unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50.\nArticle 3 Definitions For the purposes of this Regulation, the following definitions apply:\n(1)\n‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments;\n(2)\n‘risk’ means the combination of the probability of an occurrence of harm and the severity of that harm;\n(3)\n‘provider’ means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge;\n(4)\n‘deployer’ means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity;\n(5)\n‘authorised representative’ means a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation;\n(6)\n‘importer’ means a natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country;\n(7)\n‘distributor’ means a natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market;\n(8)\n‘operator’ means a provider, product manufacturer, deployer, authorised representative, importer or distributor;\n(9)\n‘placing on the market’ means the first making available of an AI system or a general-purpose AI model on the Union market;\n(10)\n‘making available on the market’ means the supply of an AI system or a general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;\n(11)\n‘putting into service’ means the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose;\n(12)\n‘intended purpose’ means the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation;\n(13)\n‘reasonably foreseeable misuse’ means the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems;\n(14)\n‘safety component’ means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property;\n(15)\n‘instructions for use’ means the information provided by the provider to inform the deployer of, in particular, an AI system’s intended purpose and proper use;\n(16)\n‘recall of an AI system’ means any measure aiming to achieve the return to the provider or taking out of service or disabling the use of an AI system made available to deployers;\n(17)\n‘withdrawal of an AI system’ means any measure aiming to prevent an AI system in the supply chain being made available on the market;\n(18)\n‘performance of an AI system’ means the ability of an AI system to achieve its intended purpose;\n(19)\n‘notifying authority’ means the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring;\n(20)\n‘conformity assessment’ means the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled;\n(21)\n‘conformity assessment body’ means a body that performs third-party conformity assessment activities, including testing, certification and inspection;\n(22)\n‘notified body’ means a conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation;\n(23)\n‘substantial modification’ means a change to an AI system after its placing on the market or putting into service which is not foreseen or planned in the initial conformity assessment carried out by the provider and as a result of which the compliance of the AI system with the requirements set out in Chapter III, Section 2 is affected or results in a modification to the intended purpose for which the AI system has been assessed;\n(24)\n‘CE marking’ means a marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing;\n(25)\n‘post-market monitoring system’ means all activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service for the purpose of identifying any need to immediately apply any necessary corrective or preventive actions;\n(26)\n‘market surveillance authority’ means the national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020;\n(27)\n‘harmonised standard’ means a harmonised standard as defined in Article 2(1), point (c), of Regulation (EU) No 1025/2012;\n(28)\n‘common specification’ means a set of technical specifications as defined in Article 2, point (4) of Regulation (EU) No 1025/2012, providing means to comply with certain requirements established under this Regulation;\n(29)\n‘training data’ means data used for training an AI system through fitting its learnable parameters;\n(30)\n‘validation data’ means data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process in order, inter alia, to prevent underfitting or overfitting;\n(31)\n‘validation data set’ means a separate data set or part of the training data set, either as a fixed or variable split;\n(32)\n‘testing data’ means data used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service;\n(33)\n‘input data’ means data provided to or directly acquired by an AI system on the basis of which the system produces an output;\n(34)\n‘biometric data’ means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data;\n(35)\n‘biometric identification’ means the automated recognition of physical, physiological, behavioural, or psychological human features for the purpose of establishing the identity of a natural person by comparing biometric data of that individual to biometric data of individuals stored in a database;\n(36)\n‘biometric verification’ means the automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data;\n(37)\n‘special categories of personal data’ means the categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725;\n(38)\n‘sensitive operational data’ means operational data related to activities of prevention, detection, investigation or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedings;\n(39)\n‘emotion recognition system’ means an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data;\n(40)\n‘biometric categorisation system’ means an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons;\n(41)\n‘remote biometric identification system’ means an AI system for the purpose of identifying natural persons, without their active involvement, typically at a distance through the comparison of a person’s biometric data with the biometric data contained in a reference database;\n(42)\n‘real-time remote biometric identification system’ means a remote biometric identification system, whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay, comprising not only instant identification, but also limited short delays in order to avoid circumvention;\n(43)\n‘post-remote biometric identification system’ means a remote biometric identification system other than a real-time remote biometric identification system;\n(44)\n‘publicly accessible space’ means any publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of whether certain conditions for access may apply, and regardless of the potential capacity restrictions;\n(45)\n‘law enforcement authority’ means:\n(a)\nany public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; or\n(b)\nany other body or entity entrusted by Member State law to exercise public authority and public powers for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;\n(46)\n‘law enforcement’ means activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security;\n(47)\n‘AI Office’ means the Commission’s function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI models, and AI governance, provided for in Commission Decision of 24 January 2024; references in this Regulation to the AI Office shall be construed as references to the Commission;\n(48)\n‘national competent authority’ means a notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities in this Regulation shall be construed as references to the European Data Protection Supervisor;\n(49)\n‘serious incident’ means an incident or malfunctioning of an AI system that directly or indirectly leads to any of the following:\n(a)\nthe death of a person, or serious harm to a person’s health;\n(b)\na serious and irreversible disruption of the management or operation of critical infrastructure;\n(c)\nthe infringement of obligations under Union law intended to protect fundamental rights;\n(d)\nserious harm to property or the environment;\n(50)\n‘personal data’ means personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679;\n(51)\n‘non-personal data’ means data other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679;\n(52)\n‘profiling’ means profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679;\n(53)\n‘real-world testing plan’ means a document that describes the objectives, methodology, geographical, population and temporal scope, monitoring, organisation and conduct of testing in real-world conditions;\n(54)\n‘sandbox plan’ means a document agreed between the participating provider and the competent authority describing the objectives, conditions, timeframe, methodology and requirements for the activities carried out within the sandbox;\n(55)\n‘AI regulatory sandbox’ means a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision;\n(56)\n‘AI literacy’ means skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause;\n(57)\n‘testing in real-world conditions’ means the temporary testing of an AI system for its intended purpose in real-world conditions outside a laboratory or otherwise simulated environment, with a view to gathering reliable and robust data and to assessing and verifying the conformity of the AI system with the requirements of this Regulation and it does not qualify as placing the AI system on the market or putting it into service within the meaning of this Regulation, provided that all the conditions laid down in Article 57 or 60 are fulfilled;\n(58)\n‘subject’, for the purpose of real-world testing, means a natural person who participates in testing in real-world conditions;\n(59)\n‘informed consent’ means a subject’s freely given, specific, unambiguous and voluntary expression of his or her willingness to participate in a particular testing in real-world conditions, after having been informed of all aspects of the testing that are relevant to the subject’s decision to participate;\n(60)\n‘deep fake’ means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful;\n(61)\n‘widespread infringement’ means any act or omission contrary to Union law protecting the interest of individuals, which:\n(a)\nhas harmed or is likely to harm the collective interests of individuals residing in at least two Member States other than the Member State in which:\n(i)\nthe act or omission originated or took place;\n(ii)\nthe provider concerned, or, where applicable, its authorised representative is located or established; or\n(iii)\nthe deployer is established, when the infringement is committed by the deployer;\n(b)\nhas caused, causes or is likely to cause harm to the collective interests of individuals and has common features, including the same unlawful practice or the same interest being infringed, and is occurring concurrently, committed by the same operator, in at least three Member States;\n(62)\n‘critical infrastructure’ means critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557;\n(63)\n‘general-purpose AI model’ means an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market;\n(64)\n‘high-impact capabilities’ means capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models;\n(65)\n‘systemic risk’ means a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain;\n(66)\n‘general-purpose AI system’ means an AI system which is based on a general-purpose AI model and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems;\n(67)\n‘floating-point operation’ means any mathematical operation or assignment involving floating-point numbers, which are a subset of the real numbers typically represented on computers by an integer of fixed precision scaled by an integer exponent of a fixed base;\n(68)\n‘downstream provider’ means a provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations.\nArticle 4 AI literacy Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.\nCHAPTER II PROHIBITED AI PRACTICES\nArticle 5 Prohibited AI practices The following AI practices shall be prohibited: (a)\nthe placing on the market, the putting into service or the use of an AI system that deploys subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing them to take a decision that they would not have otherwise taken in a manner that causes or is reasonably likely to cause that person, another person or group of persons significant harm;\n(b)\nthe placing on the market, the putting into service or the use of an AI system that exploits any of the vulnerabilities of a natural person or a specific group of persons due to their age, disability or a specific social or economic situation, with the objective, or the effect, of materially distorting the behaviour of that person or a person belonging to that group in a manner that causes or is reasonably likely to cause that person or another person significant harm;\n(c)\nthe placing on the market, the putting into service or the use of AI systems for the evaluation or classification of natural persons or groups of persons over a certain period of time based on their social behaviour or known, inferred or predicted personal or personality characteristics, with the social score leading to either or both of the following:\n(i)\ndetrimental or unfavourable treatment of certain natural persons or groups of persons in social contexts that are unrelated to the contexts in which the data was originally generated or collected;\n(ii)\ndetrimental or unfavourable treatment of certain natural persons or groups of persons that is unjustified or disproportionate to their social behaviour or its gravity;\n(d)\nthe placing on the market, the putting into service for this specific purpose, or the use of an AI system for making risk assessments of natural persons in order to assess or predict the risk of a natural person committing a criminal offence, based solely on the profiling of a natural person or on assessing their personality traits and characteristics; this prohibition shall not apply to AI systems used to support the human assessment of the involvement of a person in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity;\n(e)\nthe placing on the market, the putting into service for this specific purpose, or the use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage;\n(f)\nthe placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons;\n(g)\nthe placing on the market, the putting into service for this specific purpose, or the use of biometric categorisation systems that categorise individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation; this prohibition does not cover any labelling or filtering of lawfully acquired biometric datasets, such as images, based on biometric data or categorizing of biometric data in the area of law enforcement;\n(h)\nthe use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement, unless and in so far as such use is strictly necessary for one of the following objectives:\n(i)\nthe targeted search for specific victims of abduction, trafficking in human beings or sexual exploitation of human beings, as well as the search for missing persons;\n(ii)\nthe prevention of a specific, substantial and imminent threat to the life or physical safety of natural persons or a genuine and present or genuine and foreseeable threat of a terrorist attack;\n(iii)\nthe localisation or identification of a person suspected of having committed a criminal offence, for the purpose of conducting a criminal investigation or prosecution or executing a criminal penalty for offences referred to in Annex II and punishable in the Member State concerned by a custodial sentence or a detention order for a maximum period of at least four years.\nPoint (h) of the first subparagraph is without prejudice to Article 9 of Regulation (EU) 2016/679 for the processing of biometric data for purposes other than law enforcement.\nThe use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement for any of the objectives referred to in paragraph 1, first subparagraph, point (h), shall be deployed for the purposes set out in that point only to confirm the identity of the specifically targeted individual, and it shall take into account the following elements: (a)\nthe nature of the situation giving rise to the possible use, in particular the seriousness, probability and scale of the harm that would be caused if the system were not used;\n(b)\nthe consequences of the use of the system for the rights and freedoms of all persons concerned, in particular the seriousness, probability and scale of those consequences.\nIn addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement for any of the objectives referred to in paragraph 1, first subparagraph, point (h), of this Article shall comply with necessary and proportionate safeguards and conditions in relation to the use in accordance with the national law authorising the use thereof, in particular as regards the temporal, geographic and personal limitations. The use of the ‘real-time’ remote biometric identification system in publicly accessible spaces shall be authorised only if the law enforcement authority has completed a fundamental rights impact assessment as provided for in Article 27 and has registered the system in the EU database according to Article 49. However, in duly justified cases of urgency, the use of such systems may be commenced without the registration in the EU database, provided that such registration is completed without undue delay.\nFor the purposes of paragraph 1, first subparagraph, point (h) and paragraph 2, each use for the purposes of law enforcement of a ‘real-time’ remote biometric identification system in publicly accessible spaces shall be subject to a prior authorisation granted by a judicial authority or an independent administrative authority whose decision is binding of the Member State in which the use is to take place, issued upon a reasoned request and in accordance with the detailed rules of national law referred to in paragraph 5. However, in a duly justified situation of urgency, the use of such system may be commenced without an authorisation provided that such authorisation is requested without undue delay, at the latest within 24 hours. If such authorisation is rejected, the use shall be stopped with immediate effect and all the data, as well as the results and outputs of that use shall be immediately discarded and deleted. The competent judicial authority or an independent administrative authority whose decision is binding shall grant the authorisation only where it is satisfied, on the basis of objective evidence or clear indications presented to it, that the use of the ‘real-time’ remote biometric identification system concerned is necessary for, and proportionate to, achieving one of the objectives specified in paragraph 1, first subparagraph, point (h), as identified in the request and, in particular, remains limited to what is strictly necessary concerning the period of time as well as the geographic and personal scope. In deciding on the request, that authority shall take into account the elements referred to in paragraph 2. No decision that produces an adverse legal effect on a person may be taken based solely on the output of the ‘real-time’ remote biometric identification system.\nWithout prejudice to paragraph 3, each use of a ‘real-time’ remote biometric identification system in publicly accessible spaces for law enforcement purposes shall be notified to the relevant market surveillance authority and the national data protection authority in accordance with the national rules referred to in paragraph 5. The notification shall, as a minimum, contain the information specified under paragraph 6 and shall not include sensitive operational data.\nA Member State may decide to provide for the possibility to fully or partially authorise the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement within the limits and under the conditions listed in paragraph 1, first subparagraph, point (h), and paragraphs 2 and 3. Member States concerned shall lay down in their national law the necessary detailed rules for the request, issuance and exercise of, as well as supervision and reporting relating to, the authorisations referred to in paragraph 3. Those rules shall also specify in respect of which of the objectives listed in paragraph 1, first subparagraph, point (h), including which of the criminal offences referred to in point (h)(iii) thereof, the competent authorities may be authorised to use those systems for the purposes of law enforcement. Member States shall notify those rules to the Commission at the latest 30 days following the adoption thereof. Member States may introduce, in accordance with Union law, more restrictive laws on the use of remote biometric identification systems.\nNational market surveillance authorities and the national data protection authorities of Member States that have been notified of the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for law enforcement purposes pursuant to paragraph 4 shall submit to the Commission annual reports on such use. For that purpose, the Commission shall provide Member States and national market surveillance and data protection authorities with a template, including information on the number of the decisions taken by competent judicial authorities or an independent administrative authority whose decision is binding upon requests for authorisations in accordance with paragraph 3 and their result.\nThe Commission shall publish annual reports on the use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes, based on aggregated data in Member States on the basis of the annual reports referred to in paragraph 6. Those annual reports shall not include sensitive operational data of the related law enforcement activities.\nThis Article shall not affect the prohibitions that apply where an AI practice infringes other Union law.\nCHAPTER III HIGH-RISK AI SYSTEMS\nSECTION 1\nClassification of AI systems as high-risk\nArticle 6 Classification rules for high-risk AI systems Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: (a)\nthe AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;\n(b)\nthe product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.\nIn addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.\nBy derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.\nThe first subparagraph shall apply where any of the following conditions is fulfilled:\n(a)\nthe AI system is intended to perform a narrow procedural task;\n(b)\nthe AI system is intended to improve the result of a previously completed human activity;\n(c)\nthe AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review; or\n(d)\nthe AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III.\nNotwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.\nA provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment before that system is placed on the market or put into service. Such provider shall be subject to the registration obligation set out in Article 49(2). Upon request of national competent authorities, the provider shall provide the documentation of the assessment.\nThe Commission shall, after consulting the European Artificial Intelligence Board (the ‘Board’), and no later than 2 February 2026, provide guidelines specifying the practical implementation of this Article in line with Article 96 together with a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by adding new conditions to those laid down therein, or by modifying them, where there is concrete and reliable evidence of the existence of AI systems that fall under the scope of Annex III, but do not pose a significant risk of harm to the health, safety or fundamental rights of natural persons.\nThe Commission shall adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by deleting any of the conditions laid down therein, where there is concrete and reliable evidence that this is necessary to maintain the level of protection of health, safety and fundamental rights provided for by this Regulation.\nAny amendment to the conditions laid down in paragraph 3, second subparagraph, adopted in accordance with paragraphs 6 and 7 of this Article shall not decrease the overall level of protection of health, safety and fundamental rights provided for by this Regulation and shall ensure consistency with the delegated acts adopted pursuant to Article 7(1), and take account of market and technological developments.\nArticle 7 Amendments to Annex III The Commission is empowered to adopt delegated acts in accordance with Article 97 to amend Annex III by adding or modifying use-cases of high-risk AI systems where both of the following conditions are fulfilled: (a)\nthe AI systems are intended to be used in any of the areas listed in Annex III;\n(b)\nthe AI systems pose a risk of harm to health and safety, or an adverse impact on fundamental rights, and that risk is equivalent to, or greater than, the risk of harm or of adverse impact posed by the high-risk AI systems already referred to in Annex III.\nWhen assessing the condition under paragraph 1, point (b), the Commission shall take into account the following criteria: (a)\nthe intended purpose of the AI system;\n(b)\nthe extent to which an AI system has been used or is likely to be used;\n(c)\nthe nature and amount of the data processed and used by the AI system, in particular whether special categories of personal data are processed;\n(d)\nthe extent to which the AI system acts autonomously and the possibility for a human to override a decision or recommendations that may lead to potential harm;\n(e)\nthe extent to which the use of an AI system has already caused harm to health and safety, has had an adverse impact on fundamental rights or has given rise to significant concerns in relation to the likelihood of such harm or adverse impact, as demonstrated, for example, by reports or documented allegations submitted to national competent authorities or by other reports, as appropriate;\n(f)\nthe potential extent of such harm or such adverse impact, in particular in terms of its intensity and its ability to affect multiple persons or to disproportionately affect a particular group of persons;\n(g)\nthe extent to which persons who are potentially harmed or suffer an adverse impact are dependent on the outcome produced with an AI system, in particular because for practical or legal reasons it is not reasonably possible to opt-out from that outcome;\n(h)\nthe extent to which there is an imbalance of power, or the persons who are potentially harmed or suffer an adverse impact are in a vulnerable position in relation to the deployer of an AI system, in particular due to status, authority, knowledge, economic or social circumstances, or age;\n(i)\nthe extent to which the outcome produced involving an AI system is easily corrigible or reversible, taking into account the technical solutions available to correct or reverse it, whereby outcomes having an adverse impact on health, safety or fundamental rights, shall not be considered to be easily corrigible or reversible;\n(j)\nthe magnitude and likelihood of benefit of the deployment of the AI system for individuals, groups, or society at large, including possible improvements in product safety;\n(k)\nthe extent to which existing Union law provides for:\n(i)\neffective measures of redress in relation to the risks posed by an AI system, with the exclusion of claims for damages;\n(ii)\neffective measures to prevent or substantially minimise those risks.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 to amend the list in Annex III by removing high-risk AI systems where both of the following conditions are fulfilled: (a)\nthe high-risk AI system concerned no longer poses any significant risks to fundamental rights, health or safety, taking into account the criteria listed in paragraph 2;\n(b)\nthe deletion does not decrease the overall level of protection of health, safety and fundamental rights under Union law.\nSECTION 2\nRequirements for high-risk AI systems\nArticle 8 Compliance with the requirements High-risk AI systems shall comply with the requirements laid down in this Section, taking into account their intended purpose as well as the generally acknowledged state of the art on AI and AI-related technologies. The risk management system referred to in Article 9 shall be taken into account when ensuring compliance with those requirements.\nWhere a product contains an AI system, to which the requirements of this Regulation as well as requirements of the Union harmonisation legislation listed in Section A of Annex I apply, providers shall be responsible for ensuring that their product is fully compliant with all applicable requirements under applicable Union harmonisation legislation. In ensuring the compliance of high-risk AI systems referred to in paragraph 1 with the requirements set out in this Section, and in order to ensure consistency, avoid duplication and minimise additional burdens, providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist and are required under the Union harmonisation legislation listed in Section A of Annex I.\nArticle 9 Risk management system A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.\nThe risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating. It shall comprise the following steps:\n(a)\nthe identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpose;\n(b)\nthe estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse;\n(c)\nthe evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 72;\n(d)\nthe adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to point (a).\nThe risks referred to in this Article shall concern only those which may be reasonably mitigated or eliminated through the development or design of the high-risk AI system, or the provision of adequate technical information.\nThe risk management measures referred to in paragraph 2, point (d), shall give due consideration to the effects and possible interaction resulting from the combined application of the requirements set out in this Section, with a view to minimising risks more effectively while achieving an appropriate balance in implementing the measures to fulfil those requirements.\nThe risk management measures referred to in paragraph 2, point (d), shall be such that the relevant residual risk associated with each hazard, as well as the overall residual risk of the high-risk AI systems is judged to be acceptable.\nIn identifying the most appropriate risk management measures, the following shall be ensured:\n(a)\nelimination or reduction of risks identified and evaluated pursuant to paragraph 2 in as far as technically feasible through adequate design and development of the high-risk AI system;\n(b)\nwhere appropriate, implementation of adequate mitigation and control measures addressing risks that cannot be eliminated;\n(c)\nprovision of information required pursuant to Article 13 and, where appropriate, training to deployers.\nWith a view to eliminating or reducing risks related to the use of the high-risk AI system, due consideration shall be given to the technical knowledge, experience, education, the training to be expected by the deployer, and the presumable context in which the system is intended to be used.\nHigh-risk AI systems shall be tested for the purpose of identifying the most appropriate and targeted risk management measures. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and that they are in compliance with the requirements set out in this Section.\nTesting procedures may include testing in real-world conditions in accordance with Article 60.\nThe testing of high-risk AI systems shall be performed, as appropriate, at any time throughout the development process, and, in any event, prior to their being placed on the market or put into service. Testing shall be carried out against prior defined metrics and probabilistic thresholds that are appropriate to the intended purpose of the high-risk AI system.\nWhen implementing the risk management system as provided for in paragraphs 1 to 7, providers shall give consideration to whether in view of its intended purpose the high-risk AI system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups.\nFor providers of high-risk AI systems that are subject to requirements regarding internal risk management processes under other relevant provisions of Union law, the aspects provided in paragraphs 1 to 9 may be part of, or combined with, the risk management procedures established pursuant to that law.\nArticle 10 Data and data governance High-risk AI systems which make use of techniques involving the training of AI models with data shall be developed on the basis of training, validation and testing data sets that meet the quality criteria referred to in paragraphs 2 to 5 whenever such data sets are used.\nTraining, validation and testing data sets shall be subject to data governance and management practices appropriate for the intended purpose of the high-risk AI system. Those practices shall concern in particular:\n(a)\nthe relevant design choices;\n(b)\ndata collection processes and the origin of data, and in the case of personal data, the original purpose of the data collection;\n(c)\nrelevant data-preparation processing operations, such as annotation, labelling, cleaning, updating, enrichment and aggregation;\n(d)\nthe formulation of assumptions, in particular with respect to the information that the data are supposed to measure and represent;\n(e)\nan assessment of the availability, quantity and suitability of the data sets that are needed;\n(f)\nexamination in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations;\n(g)\nappropriate measures to detect, prevent and mitigate possible biases identified according to point (f);\n(h)\nthe identification of relevant data gaps or shortcomings that prevent compliance with this Regulation, and how those gaps and shortcomings can be addressed.\nTraining, validation and testing data sets shall be relevant, sufficiently representative, and to the best extent possible, free of errors and complete in view of the intended purpose. They shall have the appropriate statistical properties, including, where applicable, as regards the persons or groups of persons in relation to whom the high-risk AI system is intended to be used. Those characteristics of the data sets may be met at the level of individual data sets or at the level of a combination thereof.\nData sets shall take into account, to the extent required by the intended purpose, the characteristics or elements that are particular to the specific geographical, contextual, behavioural or functional setting within which the high-risk AI system is intended to be used.\nTo the extent that it is strictly necessary for the purpose of ensuring bias detection and correction in relation to the high-risk AI systems in accordance with paragraph (2), points (f) and (g) of this Article, the providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, all the following conditions must be met in order for such processing to occur:\n(a)\nthe bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data;\n(b)\nthe special categories of personal data are subject to technical limitations on the re-use of the personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation;\n(c)\nthe special categories of personal data are subject to measures to ensure that the personal data processed are secured, protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations;\n(d)\nthe special categories of personal data are not to be transmitted, transferred or otherwise accessed by other parties;\n(e)\nthe special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first;\n(f)\nthe records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.\nFor the development of high-risk AI systems not using techniques involving the training of AI models, paragraphs 2 to 5 apply only to the testing data sets. Article 11 Technical documentation The technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date. The technical documentation shall be drawn up in such a way as to demonstrate that the high-risk AI system complies with the requirements set out in this Section and to provide national competent authorities and notified bodies with the necessary information in a clear and comprehensive form to assess the compliance of the AI system with those requirements. It shall contain, at a minimum, the elements set out in Annex IV. SMEs, including start-ups, may provide the elements of the technical documentation specified in Annex IV in a simplified manner. To that end, the Commission shall establish a simplified technical documentation form targeted at the needs of small and microenterprises. Where an SME, including a start-up, opts to provide the information required in Annex IV in a simplified manner, it shall use the form referred to in this paragraph. Notified bodies shall accept the form for the purposes of the conformity assessment.\nWhere a high-risk AI system related to a product covered by the Union harmonisation legislation listed in Section A of Annex I is placed on the market or put into service, a single set of technical documentation shall be drawn up containing all the information set out in paragraph 1, as well as the information required under those legal acts.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annex IV, where necessary, to ensure that, in light of technical progress, the technical documentation provides all the information necessary to assess the compliance of the system with the requirements set out in this Section.\nArticle 12 Record-keeping High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.\nIn order to ensure a level of traceability of the functioning of a high-risk AI system that is appropriate to the intended purpose of the system, logging capabilities shall enable the recording of events relevant for:\n(a)\nidentifying situations that may result in the high-risk AI system presenting a risk within the meaning of Article 79(1) or in a substantial modification;\n(b)\nfacilitating the post-market monitoring referred to in Article 72; and\n(c)\nmonitoring the operation of high-risk AI systems referred to in Article 26(5).\nFor high-risk AI systems referred to in point 1 (a), of Annex III, the logging capabilities shall provide, at a minimum: (a)\nrecording of the period of each use of the system (start date and time and end date and time of each use);\n(b)\nthe reference database against which input data has been checked by the system;\n(c)\nthe input data for which the search has led to a match;\n(d)\nthe identification of the natural persons involved in the verification of the results, as referred to in Article 14(5).\nArticle 13 Transparency and provision of information to deployers High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system’s output and use it appropriately. An appropriate type and degree of transparency shall be ensured with a view to achieving compliance with the relevant obligations of the provider and deployer set out in Section 3.\nHigh-risk AI systems shall be accompanied by instructions for use in an appropriate digital format or otherwise that include concise, complete, correct and clear information that is relevant, accessible and comprehensible to deployers.\nThe instructions for use shall contain at least the following information:\n(a)\nthe identity and the contact details of the provider and, where applicable, of its authorised representative;\n(b)\nthe characteristics, capabilities and limitations of performance of the high-risk AI system, including:\n(i)\nits intended purpose;\n(ii)\nthe level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity;\n(iii)\nany known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2);\n(iv)\nwhere applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output;\n(v)\nwhen appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used;\n(vi)\nwhen appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system;\n(vii)\nwhere applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;\n(c)\nthe changes to the high-risk AI system and its performance which have been pre-determined by the provider at the moment of the initial conformity assessment, if any;\n(d)\nthe human oversight measures referred to in Article 14, including the technical measures put in place to facilitate the interpretation of the outputs of the high-risk AI systems by the deployers;\n(e)\nthe computational and hardware resources needed, the expected lifetime of the high-risk AI system and any necessary maintenance and care measures, including their frequency, to ensure the proper functioning of that AI system, including as regards software updates;\n(f)\nwhere relevant, a description of the mechanisms included within the high-risk AI system that allows deployers to properly collect, store and interpret the logs in accordance with Article 12.\nArticle 14 Human oversight High-risk AI systems shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use.\nHuman oversight shall aim to prevent or minimise the risks to health, safety or fundamental rights that may emerge when a high-risk AI system is used in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, in particular where such risks persist despite the application of other requirements set out in this Section.\nThe oversight measures shall be commensurate with the risks, level of autonomy and context of use of the high-risk AI system, and shall be ensured through either one or both of the following types of measures:\n(a)\nmeasures identified and built, when technically feasible, into the high-risk AI system by the provider before it is placed on the market or put into service;\n(b)\nmeasures identified by the provider before placing the high-risk AI system on the market or putting it into service and that are appropriate to be implemented by the deployer.\nFor the purpose of implementing paragraphs 1, 2 and 3, the high-risk AI system shall be provided to the deployer in such a way that natural persons to whom human oversight is assigned are enabled, as appropriate and proportionate: (a)\nto properly understand the relevant capacities and limitations of the high-risk AI system and be able to duly monitor its operation, including in view of detecting and addressing anomalies, dysfunctions and unexpected performance;\n(b)\nto remain aware of the possible tendency of automatically relying or over-relying on the output produced by a high-risk AI system (automation bias), in particular for high-risk AI systems used to provide information or recommendations for decisions to be taken by natural persons;\n(c)\nto correctly interpret the high-risk AI system’s output, taking into account, for example, the interpretation tools and methods available;\n(d)\nto decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output of the high-risk AI system;\n(e)\nto intervene in the operation of the high-risk AI system or interrupt the system through a ‘stop’ button or a similar procedure that allows the system to come to a halt in a safe state.\nFor high-risk AI systems referred to in point 1(a) of Annex III, the measures referred to in paragraph 3 of this Article shall be such as to ensure that, in addition, no action or decision is taken by the deployer on the basis of the identification resulting from the system unless that identification has been separately verified and confirmed by at least two natural persons with the necessary competence, training and authority. The requirement for a separate verification by at least two natural persons shall not apply to high-risk AI systems used for the purposes of law enforcement, migration, border control or asylum, where Union or national law considers the application of this requirement to be disproportionate.\nArticle 15 Accuracy, robustness and cybersecurity High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle.\nTo address the technical aspects of how to measure the appropriate levels of accuracy and robustness set out in paragraph 1 and any other relevant performance metrics, the Commission shall, in cooperation with relevant stakeholders and organisations such as metrology and benchmarking authorities, encourage, as appropriate, the development of benchmarks and measurement methodologies.\nThe levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions of use.\nHigh-risk AI systems shall be as resilient as possible regarding errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems. Technical and organisational measures shall be taken in this regard.\nThe robustness of high-risk AI systems may be achieved through technical redundancy solutions, which may include backup or fail-safe plans.\nHigh-risk AI systems that continue to learn after being placed on the market or put into service shall be developed in such a way as to eliminate or reduce as far as possible the risk of possibly biased outputs influencing input for future operations (feedback loops), and as to ensure that any such feedback loops are duly addressed with appropriate mitigation measures.\nHigh-risk AI systems shall be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities. The technical solutions aiming to ensure the cybersecurity of high-risk AI systems shall be appropriate to the relevant circumstances and the risks.\nThe technical solutions to address AI specific vulnerabilities shall include, where appropriate, measures to prevent, detect, respond to, resolve and control for attacks trying to manipulate the training data set (data poisoning), or pre-trained components used in training (model poisoning), inputs designed to cause the AI model to make a mistake (adversarial examples or model evasion), confidentiality attacks or model flaws.\nSECTION 3\nObligations of providers and deployers of high-risk AI systems and other parties\nArticle 16 Obligations of providers of high-risk AI systems Providers of high-risk AI systems shall:\n(a)\nensure that their high-risk AI systems are compliant with the requirements set out in Section 2;\n(b)\nindicate on the high-risk AI system or, where that is not possible, on its packaging or its accompanying documentation, as applicable, their name, registered trade name or registered trade mark, the address at which they can be contacted;\n(c)\nhave a quality management system in place which complies with Article 17;\n(d)\nkeep the documentation referred to in Article 18;\n(e)\nwhen under their control, keep the logs automatically generated by their high-risk AI systems as referred to in Article 19;\n(f)\nensure that the high-risk AI system undergoes the relevant conformity assessment procedure as referred to in Article 43, prior to its being placed on the market or put into service;\n(g)\ndraw up an EU declaration of conformity in accordance with Article 47;\n(h)\naffix the CE marking to the high-risk AI system or, where that is not possible, on its packaging or its accompanying documentation, to indicate conformity with this Regulation, in accordance with Article 48;\n(i)\ncomply with the registration obligations referred to in Article 49(1);\n(j)\ntake the necessary corrective actions and provide information as required in Article 20;\n(k)\nupon a reasoned request of a national competent authority, demonstrate the conformity of the high-risk AI system with the requirements set out in Section 2;\n(l)\nensure that the high-risk AI system complies with accessibility requirements in accordance with Directives (EU) 2016/2102 and (EU) 2019/882.\nArticle 17 Quality management system Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. That system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions, and shall include at least the following aspects: (a)\na strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for the management of modifications to the high-risk AI system;\n(b)\ntechniques, procedures and systematic actions to be used for the design, design control and design verification of the high-risk AI system;\n(c)\ntechniques, procedures and systematic actions to be used for the development, quality control and quality assurance of the high-risk AI system;\n(d)\nexamination, test and validation procedures to be carried out before, during and after the development of the high-risk AI system, and the frequency with which they have to be carried out;\n(e)\ntechnical specifications, including standards, to be applied and, where the relevant harmonised standards are not applied in full or do not cover all of the relevant requirements set out in Section 2, the means to be used to ensure that the high-risk AI system complies with those requirements;\n(f)\nsystems and procedures for data management, including data acquisition, data collection, data analysis, data labelling, data storage, data filtration, data mining, data aggregation, data retention and any other operation regarding the data that is performed before and for the purpose of the placing on the market or the putting into service of high-risk AI systems;\n(g)\nthe risk management system referred to in Article 9;\n(h)\nthe setting-up, implementation and maintenance of a post-market monitoring system, in accordance with Article 72;\n(i)\nprocedures related to the reporting of a serious incident in accordance with Article 73;\n(j)\nthe handling of communication with national competent authorities, other relevant authorities, including those providing or supporting the access to data, notified bodies, other operators, customers or other interested parties;\n(k)\nsystems and procedures for record-keeping of all relevant documentation and information;\n(l)\nresource management, including security-of-supply related measures;\n(m)\nan accountability framework setting out the responsibilities of the management and other staff with regard to all the aspects listed in this paragraph.\nThe implementation of the aspects referred to in paragraph 1 shall be proportionate to the size of the provider’s organisation. Providers shall, in any event, respect the degree of rigour and the level of protection required to ensure the compliance of their high-risk AI systems with this Regulation.\nProviders of high-risk AI systems that are subject to obligations regarding quality management systems or an equivalent function under relevant sectoral Union law may include the aspects listed in paragraph 1 as part of the quality management systems pursuant to that law.\nFor providers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the obligation to put in place a quality management system, with the exception of paragraph 1, points (g), (h) and (i) of this Article, shall be deemed to be fulfilled by complying with the rules on internal governance arrangements or processes pursuant to the relevant Union financial services law. To that end, any harmonised standards referred to in Article 40 shall be taken into account.\nArticle 18 Documentation keeping The provider shall, for a period ending 10 years after the high-risk AI system has been placed on the market or put into service, keep at the disposal of the national competent authorities: (a)\nthe technical documentation referred to in Article 11;\n(b)\nthe documentation concerning the quality management system referred to in Article 17;\n(c)\nthe documentation concerning the changes approved by notified bodies, where applicable;\n(d)\nthe decisions and other documents issued by the notified bodies, where applicable;\n(e)\nthe EU declaration of conformity referred to in Article 47.\nEach Member State shall determine conditions under which the documentation referred to in paragraph 1 remains at the disposal of the national competent authorities for the period indicated in that paragraph for the cases when a provider or its authorised representative established on its territory goes bankrupt or ceases its activity prior to the end of that period.\nProviders that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the technical documentation as part of the documentation kept under the relevant Union financial services law.\nArticle 19 Automatically generated logs Providers of high-risk AI systems shall keep the logs referred to in Article 12(1), automatically generated by their high-risk AI systems, to the extent such logs are under their control. Without prejudice to applicable Union or national law, the logs shall be kept for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in the applicable Union or national law, in particular in Union law on the protection of personal data.\nProviders that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the logs automatically generated by their high-risk AI systems as part of the documentation kept under the relevant financial services law.\nArticle 20 Corrective actions and duty of information Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system that they have placed on the market or put into service is not in conformity with this Regulation shall immediately take the necessary corrective actions to bring that system into conformity, to withdraw it, to disable it, or to recall it, as appropriate. They shall inform the distributors of the high-risk AI system concerned and, where applicable, the deployers, the authorised representative and importers accordingly.\nWhere the high-risk AI system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk, it shall immediately investigate the causes, in collaboration with the reporting deployer, where applicable, and inform the market surveillance authorities competent for the high-risk AI system concerned and, where applicable, the notified body that issued a certificate for that high-risk AI system in accordance with Article 44, in particular, of the nature of the non-compliance and of any relevant corrective action taken.\nArticle 21 Cooperation with competent authorities Providers of high-risk AI systems shall, upon a reasoned request by a competent authority, provide that authority all the information and documentation necessary to demonstrate the conformity of the high-risk AI system with the requirements set out in Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned.\nUpon a reasoned request by a competent authority, providers shall also give the requesting competent authority, as applicable, access to the automatically generated logs of the high-risk AI system referred to in Article 12(1), to the extent such logs are under their control.\nAny information obtained by a competent authority pursuant to this Article shall be treated in accordance with the confidentiality obligations set out in Article 78.\nArticle 22 Authorised representatives of providers of high-risk AI systems Prior to making their high-risk AI systems available on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union.\nThe provider shall enable its authorised representative to perform the tasks specified in the mandate received from the provider.\nThe authorised representative shall perform the tasks specified in the mandate received from the provider. It shall provide a copy of the mandate to the market surveillance authorities upon request, in one of the official languages of the institutions of the Union, as indicated by the competent authority. For the purposes of this Regulation, the mandate shall empower the authorised representative to carry out the following tasks:\n(a)\nverify that the EU declaration of conformity referred to in Article 47 and the technical documentation referred to in Article 11 have been drawn up and that an appropriate conformity assessment procedure has been carried out by the provider;\n(b)\nkeep at the disposal of the competent authorities and national authorities or bodies referred to in Article 74(10), for a period of 10 years after the high-risk AI system has been placed on the market or put into service, the contact details of the provider that appointed the authorised representative, a copy of the EU declaration of conformity referred to in Article 47, the technical documentation and, if applicable, the certificate issued by the notified body;\n(c)\nprovide a competent authority, upon a reasoned request, with all the information and documentation, including that referred to in point (b) of this subparagraph, necessary to demonstrate the conformity of a high-risk AI system with the requirements set out in Section 2, including access to the logs, as referred to in Article 12(1), automatically generated by the high-risk AI system, to the extent such logs are under the control of the provider;\n(d)\ncooperate with competent authorities, upon a reasoned request, in any action the latter take in relation to the high-risk AI system, in particular to reduce and mitigate the risks posed by the high-risk AI system;\n(e)\nwhere applicable, comply with the registration obligations referred to in Article 49(1), or, if the registration is carried out by the provider itself, ensure that the information referred to in point 3 of Section A of Annex VIII is correct.\nThe mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the competent authorities, on all issues related to ensuring compliance with this Regulation.\nThe authorised representative shall terminate the mandate if it considers or has reason to consider the provider to be acting contrary to its obligations pursuant to this Regulation. In such a case, it shall immediately inform the relevant market surveillance authority, as well as, where applicable, the relevant notified body, about the termination of the mandate and the reasons therefor. Article 23 Obligations of importers Before placing a high-risk AI system on the market, importers shall ensure that the system is in conformity with this Regulation by verifying that: (a)\nthe relevant conformity assessment procedure referred to in Article 43 has been carried out by the provider of the high-risk AI system;\n(b)\nthe provider has drawn up the technical documentation in accordance with Article 11 and Annex IV;\n(c)\nthe system bears the required CE marking and is accompanied by the EU declaration of conformity referred to in Article 47 and instructions for use;\n(d)\nthe provider has appointed an authorised representative in accordance with Article 22(1).\nWhere an importer has sufficient reason to consider that a high-risk AI system is not in conformity with this Regulation, or is falsified, or accompanied by falsified documentation, it shall not place the system on the market until it has been brought into conformity. Where the high-risk AI system presents a risk within the meaning of Article 79(1), the importer shall inform the provider of the system, the authorised representative and the market surveillance authorities to that effect.\nImporters shall indicate their name, registered trade name or registered trade mark, and the address at which they can be contacted on the high-risk AI system and on its packaging or its accompanying documentation, where applicable.\nImporters shall ensure that, while a high-risk AI system is under their responsibility, storage or transport conditions, where applicable, do not jeopardise its compliance with the requirements set out in Section 2.\nImporters shall keep, for a period of 10 years after the high-risk AI system has been placed on the market or put into service, a copy of the certificate issued by the notified body, where applicable, of the instructions for use, and of the EU declaration of conformity referred to in Article 47.\nImporters shall provide the relevant competent authorities, upon a reasoned request, with all the necessary information and documentation, including that referred to in paragraph 5, to demonstrate the conformity of a high-risk AI system with the requirements set out in Section 2 in a language which can be easily understood by them. For this purpose, they shall also ensure that the technical documentation can be made available to those authorities.\nImporters shall cooperate with the relevant competent authorities in any action those authorities take in relation to a high-risk AI system placed on the market by the importers, in particular to reduce and mitigate the risks posed by it.\nArticle 24 Obligations of distributors Before making a high-risk AI system available on the market, distributors shall verify that it bears the required CE marking, that it is accompanied by a copy of the EU declaration of conformity referred to in Article 47 and instructions for use, and that the provider and the importer of that system, as applicable, have complied with their respective obligations as laid down in Article 16, points (b) and (c) and Article 23(3).\nWhere a distributor considers or has reason to consider, on the basis of the information in its possession, that a high-risk AI system is not in conformity with the requirements set out in Section 2, it shall not make the high-risk AI system available on the market until the system has been brought into conformity with those requirements. Furthermore, where the high-risk AI system presents a risk within the meaning of Article 79(1), the distributor shall inform the provider or the importer of the system, as applicable, to that effect.\nDistributors shall ensure that, while a high-risk AI system is under their responsibility, storage or transport conditions, where applicable, do not jeopardise the compliance of the system with the requirements set out in Section 2.\nA distributor that considers or has reason to consider, on the basis of the information in its possession, a high-risk AI system which it has made available on the market not to be in conformity with the requirements set out in Section 2, shall take the corrective actions necessary to bring that system into conformity with those requirements, to withdraw it or recall it, or shall ensure that the provider, the importer or any relevant operator, as appropriate, takes those corrective actions. Where the high-risk AI system presents a risk within the meaning of Article 79(1), the distributor shall immediately inform the provider or importer of the system and the authorities competent for the high-risk AI system concerned, giving details, in particular, of the non-compliance and of any corrective actions taken.\nUpon a reasoned request from a relevant competent authority, distributors of a high-risk AI system shall provide that authority with all the information and documentation regarding their actions pursuant to paragraphs 1 to 4 necessary to demonstrate the conformity of that system with the requirements set out in Section 2.\nDistributors shall cooperate with the relevant competent authorities in any action those authorities take in relation to a high-risk AI system made available on the market by the distributors, in particular to reduce or mitigate the risk posed by it.\nArticle 25 Responsibilities along the AI value chain Any distributor, importer, deployer or other third-party shall be considered to be a provider of a high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circumstances: (a)\nthey put their name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated;\n(b)\nthey make a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in such a way that it remains a high-risk AI system pursuant to Article 6;\n(c)\nthey modify the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system concerned becomes a high-risk AI system in accordance with Article 6.\nWhere the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation. That initial provider shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular regarding the compliance with the conformity assessment of high-risk AI systems. This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to hand over the documentation.\nIn the case of high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be considered to be the provider of the high-risk AI system, and shall be subject to the obligations under Article 16 under either of the following circumstances:\n(a)\nthe high-risk AI system is placed on the market together with the product under the name or trademark of the product manufacturer;\n(b)\nthe high-risk AI system is put into service under the name or trademark of the product manufacturer after the product has been placed on the market.\nThe provider of a high-risk AI system and the third party that supplies an AI system, tools, services, components, or processes that are used or integrated in a high-risk AI system shall, by written agreement, specify the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider of the high-risk AI system to fully comply with the obligations set out in this Regulation. This paragraph shall not apply to third parties making accessible to the public tools, services, processes, or components, other than general-purpose AI models, under a free and open-source licence. The AI Office may develop and recommend voluntary model terms for contracts between providers of high-risk AI systems and third parties that supply tools, services, components or processes that are used for or integrated into high-risk AI systems. When developing those voluntary model terms, the AI Office shall take into account possible contractual requirements applicable in specific sectors or business cases. The voluntary model terms shall be published and be available free of charge in an easily usable electronic format.\nParagraphs 2 and 3 are without prejudice to the need to observe and protect intellectual property rights, confidential business information and trade secrets in accordance with Union and national law. Article 26 Obligations of deployers of high-risk AI systems Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems, pursuant to paragraphs 3 and 6.\nDeployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.\nThe obligations set out in paragraphs 1 and 2, are without prejudice to other deployer obligations under Union or national law and to the deployer’s freedom to organise its own resources and activities for the purpose of implementing the human oversight measures indicated by the provider.\nWithout prejudice to paragraphs 1 and 2, to the extent the deployer exercises control over the input data, that deployer shall ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system.\nDeployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities.\nFor deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the rules on internal governance arrangements, processes and mechanisms pursuant to the relevant financial service law.\nDeployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data. Deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the logs as part of the documentation kept pursuant to the relevant Union financial service law.\nBefore putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers’ representatives and the affected workers that they will be subject to the use of the high-risk AI system. This information shall be provided, where applicable, in accordance with the rules and procedures laid down in Union and national law and practice on information of workers and their representatives.\nDeployers of high-risk AI systems that are public authorities, or Union institutions, bodies, offices or agencies shall comply with the registration obligations referred to in Article 49. When such deployers find that the high-risk AI system that they envisage using has not been registered in the EU database referred to in Article 71, they shall not use that system and shall inform the provider or the distributor.\nWhere applicable, deployers of high-risk AI systems shall use the information provided under Article 13 of this Regulation to comply with their obligation to carry out a data protection impact assessment under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680.\nWithout prejudice to Directive (EU) 2016/680, in the framework of an investigation for the targeted search of a person suspected or convicted of having committed a criminal offence, the deployer of a high-risk AI system for post-remote biometric identification shall request an authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or an administrative authority whose decision is binding and subject to judicial review, for the use of that system, except when it is used for the initial identification of a potential suspect based on objective and verifiable facts directly linked to the offence. Each use shall be limited to what is strictly necessary for the investigation of a specific criminal offence.\nIf the authorisation requested pursuant to the first subparagraph is rejected, the use of the post-remote biometric identification system linked to that requested authorisation shall be stopped with immediate effect and the personal data linked to the use of the high-risk AI system for which the authorisation was requested shall be deleted.\nIn no case shall such high-risk AI system for post-remote biometric identification be used for law enforcement purposes in an untargeted way, without any link to a criminal offence, a criminal proceeding, a genuine and present or genuine and foreseeable threat of a criminal offence, or the search for a specific missing person. It shall be ensured that no decision that produces an adverse legal effect on a person may be taken by the law enforcement authorities based solely on the output of such post-remote biometric identification systems.\nThis paragraph is without prejudice to Article 9 of Regulation (EU) 2016/679 and Article 10 of Directive (EU) 2016/680 for the processing of biometric data.\nRegardless of the purpose or deployer, each use of such high-risk AI systems shall be documented in the relevant police file and shall be made available to the relevant market surveillance authority and the national data protection authority upon request, excluding the disclosure of sensitive operational data related to law enforcement. This subparagraph shall be without prejudice to the powers conferred by Directive (EU) 2016/680 on supervisory authorities.\nDeployers shall submit annual reports to the relevant market surveillance and national data protection authorities on their use of post-remote biometric identification systems, excluding the disclosure of sensitive operational data related to law enforcement. The reports may be aggregated to cover more than one deployment.\nMember States may introduce, in accordance with Union law, more restrictive laws on the use of post-remote biometric identification systems.\nWithout prejudice to Article 50 of this Regulation, deployers of high-risk AI systems referred to in Annex III that make decisions or assist in making decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system. For high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 shall apply.\nDeployers shall cooperate with the relevant competent authorities in any action those authorities take in relation to the high-risk AI system in order to implement this Regulation.\nArticle 27 Fundamental rights impact assessment for high-risk AI systems Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of: (a)\na description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose;\n(b)\na description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used;\n(c)\nthe categories of natural persons and groups likely to be affected by its use in the specific context;\n(d)\nthe specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13;\n(e)\na description of the implementation of human oversight measures, according to the instructions for use;\n(f)\nthe measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms.\nThe obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, the deployer shall take the necessary steps to update the information.\nOnce the assessment referred to in paragraph 1 of this Article has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification. In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify.\nIf any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the fundamental rights impact assessment referred to in paragraph 1 of this Article shall complement that data protection impact assessment.\nThe AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner.\nSECTION 4\nNotifying authorities and notified bodies\nArticle 28 Notifying authorities Each Member State shall designate or establish at least one notifying authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring. Those procedures shall be developed in cooperation between the notifying authorities of all Member States.\nMember States may decide that the assessment and monitoring referred to in paragraph 1 is to be carried out by a national accreditation body within the meaning of, and in accordance with, Regulation (EC) No 765/2008.\nNotifying authorities shall be established, organised and operated in such a way that no conflict of interest arises with conformity assessment bodies, and that the objectivity and impartiality of their activities are safeguarded.\nNotifying authorities shall be organised in such a way that decisions relating to the notification of conformity assessment bodies are taken by competent persons different from those who carried out the assessment of those bodies.\nNotifying authorities shall offer or provide neither any activities that conformity assessment bodies perform, nor any consultancy services on a commercial or competitive basis.\nNotifying authorities shall safeguard the confidentiality of the information that they obtain, in accordance with Article 78.\nNotifying authorities shall have an adequate number of competent personnel at their disposal for the proper performance of their tasks. Competent personnel shall have the necessary expertise, where applicable, for their function, in fields such as information technologies, AI and law, including the supervision of fundamental rights.\nArticle 29 Application of a conformity assessment body for notification Conformity assessment bodies shall submit an application for notification to the notifying authority of the Member State in which they are established.\nThe application for notification shall be accompanied by a description of the conformity assessment activities, the conformity assessment module or modules and the types of AI systems for which the conformity assessment body claims to be competent, as well as by an accreditation certificate, where one exists, issued by a national accreditation body attesting that the conformity assessment body fulfils the requirements laid down in Article 31.\nAny valid document related to existing designations of the applicant notified body under any other Union harmonisation legislation shall be added.\nWhere the conformity assessment body concerned cannot provide an accreditation certificate, it shall provide the notifying authority with all the documentary evidence necessary for the verification, recognition and regular monitoring of its compliance with the requirements laid down in Article 31.\nFor notified bodies which are designated under any other Union harmonisation legislation, all documents and certificates linked to those designations may be used to support their designation procedure under this Regulation, as appropriate. The notified body shall update the documentation referred to in paragraphs 2 and 3 of this Article whenever relevant changes occur, in order to enable the authority responsible for notified bodies to monitor and verify continuous compliance with all the requirements laid down in Article 31.\nArticle 30 Notification procedure Notifying authorities may notify only conformity assessment bodies which have satisfied the requirements laid down in Article 31.\nNotifying authorities shall notify the Commission and the other Member States, using the electronic notification tool developed and managed by the Commission, of each conformity assessment body referred to in paragraph 1.\nThe notification referred to in paragraph 2 of this Article shall include full details of the conformity assessment activities, the conformity assessment module or modules, the types of AI systems concerned, and the relevant attestation of competence. Where a notification is not based on an accreditation certificate as referred to in Article 29(2), the notifying authority shall provide the Commission and the other Member States with documentary evidence which attests to the competence of the conformity assessment body and to the arrangements in place to ensure that that body will be monitored regularly and will continue to satisfy the requirements laid down in Article 31.\nThe conformity assessment body concerned may perform the activities of a notified body only where no objections are raised by the Commission or the other Member States within two weeks of a notification by a notifying authority where it includes an accreditation certificate referred to in Article 29(2), or within two months of a notification by the notifying authority where it includes documentary evidence referred to in Article 29(3).\nWhere objections are raised, the Commission shall, without delay, enter into consultations with the relevant Member States and the conformity assessment body. In view thereof, the Commission shall decide whether the authorisation is justified. The Commission shall address its decision to the Member State concerned and to the relevant conformity assessment body.\nArticle 31 Requirements relating to notified bodies A notified body shall be established under the national law of a Member State and shall have legal personality.\nNotified bodies shall satisfy the organisational, quality management, resources and process requirements that are necessary to fulfil their tasks, as well as suitable cybersecurity requirements.\nThe organisational structure, allocation of responsibilities, reporting lines and operation of notified bodies shall ensure confidence in their performance, and in the results of the conformity assessment activities that the notified bodies conduct.\nNotified bodies shall be independent of the provider of a high-risk AI system in relation to which they perform conformity assessment activities. Notified bodies shall also be independent of any other operator having an economic interest in high-risk AI systems assessed, as well as of any competitors of the provider. This shall not preclude the use of assessed high-risk AI systems that are necessary for the operations of the conformity assessment body, or the use of such high-risk AI systems for personal purposes.\nNeither a conformity assessment body, its top-level management nor the personnel responsible for carrying out its conformity assessment tasks shall be directly involved in the design, development, marketing or use of high-risk AI systems, nor shall they represent the parties engaged in those activities. They shall not engage in any activity that might conflict with their independence of judgement or integrity in relation to conformity assessment activities for which they are notified. This shall, in particular, apply to consultancy services.\nNotified bodies shall be organised and operated so as to safeguard the independence, objectivity and impartiality of their activities. Notified bodies shall document and implement a structure and procedures to safeguard impartiality and to promote and apply the principles of impartiality throughout their organisation, personnel and assessment activities.\nNotified bodies shall have documented procedures in place ensuring that their personnel, committees, subsidiaries, subcontractors and any associated body or personnel of external bodies maintain, in accordance with Article 78, the confidentiality of the information which comes into their possession during the performance of conformity assessment activities, except when its disclosure is required by law. The staff of notified bodies shall be bound to observe professional secrecy with regard to all information obtained in carrying out their tasks under this Regulation, except in relation to the notifying authorities of the Member State in which their activities are carried out.\nNotified bodies shall have procedures for the performance of activities which take due account of the size of a provider, the sector in which it operates, its structure, and the degree of complexity of the AI system concerned.\nNotified bodies shall take out appropriate liability insurance for their conformity assessment activities, unless liability is assumed by the Member State in which they are established in accordance with national law or that Member State is itself directly responsible for the conformity assessment.\nNotified bodies shall be capable of carrying out all their tasks under this Regulation with the highest degree of professional integrity and the requisite competence in the specific field, whether those tasks are carried out by notified bodies themselves or on their behalf and under their responsibility.\nNotified bodies shall have sufficient internal competences to be able effectively to evaluate the tasks conducted by external parties on their behalf. The notified body shall have permanent availability of sufficient administrative, technical, legal and scientific personnel who possess experience and knowledge relating to the relevant types of AI systems, data and data computing, and relating to the requirements set out in Section 2.\nNotified bodies shall participate in coordination activities as referred to in Article 38. They shall also take part directly, or be represented in, European standardisation organisations, or ensure that they are aware and up to date in respect of relevant standards.\nArticle 32 Presumption of conformity with requirements relating to notified bodies Where a conformity assessment body demonstrates its conformity with the criteria laid down in the relevant harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, it shall be presumed to comply with the requirements set out in Article 31 in so far as the applicable harmonised standards cover those requirements.\nArticle 33 Subsidiaries of notified bodies and subcontracting Where a notified body subcontracts specific tasks connected with the conformity assessment or has recourse to a subsidiary, it shall ensure that the subcontractor or the subsidiary meets the requirements laid down in Article 31, and shall inform the notifying authority accordingly.\nNotified bodies shall take full responsibility for the tasks performed by any subcontractors or subsidiaries.\nActivities may be subcontracted or carried out by a subsidiary only with the agreement of the provider. Notified bodies shall make a list of their subsidiaries publicly available.\nThe relevant documents concerning the assessment of the qualifications of the subcontractor or the subsidiary and the work carried out by them under this Regulation shall be kept at the disposal of the notifying authority for a period of five years from the termination date of the subcontracting.\nArticle 34 Operational obligations of notified bodies Notified bodies shall verify the conformity of high-risk AI systems in accordance with the conformity assessment procedures set out in Article 43.\nNotified bodies shall avoid unnecessary burdens for providers when performing their activities, and take due account of the size of the provider, the sector in which it operates, its structure and the degree of complexity of the high-risk AI system concerned, in particular in view of minimising administrative burdens and compliance costs for micro- and small enterprises within the meaning of Recommendation 2003/361/EC. The notified body shall, nevertheless, respect the degree of rigour and the level of protection required for the compliance of the high-risk AI system with the requirements of this Regulation.\nNotified bodies shall make available and submit upon request all relevant documentation, including the providers’ documentation, to the notifying authority referred to in Article 28 to allow that authority to conduct its assessment, designation, notification and monitoring activities, and to facilitate the assessment outlined in this Section.\nArticle 35 Identification numbers and lists of notified bodies The Commission shall assign a single identification number to each notified body, even where a body is notified under more than one Union act.\nThe Commission shall make publicly available the list of the bodies notified under this Regulation, including their identification numbers and the activities for which they have been notified. The Commission shall ensure that the list is kept up to date.\nArticle 36 Changes to notifications The notifying authority shall notify the Commission and the other Member States of any relevant changes to the notification of a notified body via the electronic notification tool referred to in Article 30(2).\nThe procedures laid down in Articles 29 and 30 shall apply to extensions of the scope of the notification.\nFor changes to the notification other than extensions of its scope, the procedures laid down in paragraphs (3) to (9) shall apply.\nWhere a notified body decides to cease its conformity assessment activities, it shall inform the notifying authority and the providers concerned as soon as possible and, in the case of a planned cessation, at least one year before ceasing its activities. The certificates of the notified body may remain valid for a period of nine months after cessation of the notified body’s activities, on condition that another notified body has confirmed in writing that it will assume responsibilities for the high-risk AI systems covered by those certificates. The latter notified body shall complete a full assessment of the high-risk AI systems affected by the end of that nine-month-period before issuing new certificates for those systems. Where the notified body has ceased its activity, the notifying authority shall withdraw the designation.\nWhere a notifying authority has sufficient reason to consider that a notified body no longer meets the requirements laid down in Article 31, or that it is failing to fulfil its obligations, the notifying authority shall without delay investigate the matter with the utmost diligence. In that context, it shall inform the notified body concerned about the objections raised and give it the possibility to make its views known. If the notifying authority comes to the conclusion that the notified body no longer meets the requirements laid down in Article 31 or that it is failing to fulfil its obligations, it shall restrict, suspend or withdraw the designation as appropriate, depending on the seriousness of the failure to meet those requirements or fulfil those obligations. It shall immediately inform the Commission and the other Member States accordingly.\nWhere its designation has been suspended, restricted, or fully or partially withdrawn, the notified body shall inform the providers concerned within 10 days.\nIn the event of the restriction, suspension or withdrawal of a designation, the notifying authority shall take appropriate steps to ensure that the files of the notified body concerned are kept, and to make them available to notifying authorities in other Member States and to market surveillance authorities at their request.\nIn the event of the restriction, suspension or withdrawal of a designation, the notifying authority shall:\n(a)\nassess the impact on the certificates issued by the notified body;\n(b)\nsubmit a report on its findings to the Commission and the other Member States within three months of having notified the changes to the designation;\n(c)\nrequire the notified body to suspend or withdraw, within a reasonable period of time determined by the authority, any certificates which were unduly issued, in order to ensure the continuing conformity of high-risk AI systems on the market;\n(d)\ninform the Commission and the Member States about certificates the suspension or withdrawal of which it has required;\n(e)\nprovide the national competent authorities of the Member State in which the provider has its registered place of business with all relevant information about the certificates of which it has required the suspension or withdrawal; that authority shall take the appropriate measures, where necessary, to avoid a potential risk to health, safety or fundamental rights.\nWith the exception of certificates unduly issued, and where a designation has been suspended or restricted, the certificates shall remain valid in one of the following circumstances: (a)\nthe notifying authority has confirmed, within one month of the suspension or restriction, that there is no risk to health, safety or fundamental rights in relation to certificates affected by the suspension or restriction, and the notifying authority has outlined a timeline for actions to remedy the suspension or restriction; or\n(b)\nthe notifying authority has confirmed that no certificates relevant to the suspension will be issued, amended or re-issued during the course of the suspension or restriction, and states whether the notified body has the capability of continuing to monitor and remain responsible for existing certificates issued for the period of the suspension or restriction; in the event that the notifying authority determines that the notified body does not have the capability to support existing certificates issued, the provider of the system covered by the certificate shall confirm in writing to the national competent authorities of the Member State in which it has its registered place of business, within three months of the suspension or restriction, that another qualified notified body is temporarily assuming the functions of the notified body to monitor and remain responsible for the certificates during the period of suspension or restriction.\nWith the exception of certificates unduly issued, and where a designation has been withdrawn, the certificates shall remain valid for a period of nine months under the following circumstances: (a)\nthe national competent authority of the Member State in which the provider of the high-risk AI system covered by the certificate has its registered place of business has confirmed that there is no risk to health, safety or fundamental rights associated with the high-risk AI systems concerned; and\n(b)\nanother notified body has confirmed in writing that it will assume immediate responsibility for those AI systems and completes its assessment within 12 months of the withdrawal of the designation.\nIn the circumstances referred to in the first subparagraph, the national competent authority of the Member State in which the provider of the system covered by the certificate has its place of business may extend the provisional validity of the certificates for additional periods of three months, which shall not exceed 12 months in total.\nThe national competent authority or the notified body assuming the functions of the notified body affected by the change of designation shall immediately inform the Commission, the other Member States and the other notified bodies thereof.\nArticle 37 Challenge to the competence of notified bodies The Commission shall, where necessary, investigate all cases where there are reasons to doubt the competence of a notified body or the continued fulfilment by a notified body of the requirements laid down in Article 31 and of its applicable responsibilities.\nThe notifying authority shall provide the Commission, on request, with all relevant information relating to the notification or the maintenance of the competence of the notified body concerned.\nThe Commission shall ensure that all sensitive information obtained in the course of its investigations pursuant to this Article is treated confidentially in accordance with Article 78.\nWhere the Commission ascertains that a notified body does not meet or no longer meets the requirements for its notification, it shall inform the notifying Member State accordingly and request it to take the necessary corrective measures, including the suspension or withdrawal of the notification if necessary. Where the Member State fails to take the necessary corrective measures, the Commission may, by means of an implementing act, suspend, restrict or withdraw the designation. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nArticle 38 Coordination of notified bodies The Commission shall ensure that, with regard to high-risk AI systems, appropriate coordination and cooperation between notified bodies active in the conformity assessment procedures pursuant to this Regulation are put in place and properly operated in the form of a sectoral group of notified bodies.\nEach notifying authority shall ensure that the bodies notified by it participate in the work of a group referred to in paragraph 1, directly or through designated representatives.\nThe Commission shall provide for the exchange of knowledge and best practices between notifying authorities.\nArticle 39 Conformity assessment bodies of third countries Conformity assessment bodies established under the law of a third country with which the Union has concluded an agreement may be authorised to carry out the activities of notified bodies under this Regulation, provided that they meet the requirements laid down in Article 31 or they ensure an equivalent level of compliance.\nSECTION 5\nStandards, conformity assessment, certificates, registration\nArticle 40 Harmonised standards and standardisation deliverables High-risk AI systems or general-purpose AI models which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, with the obligations set out in of Chapter V, Sections 2 and 3, of this Regulation, to the extent that those standards cover those requirements or obligations.\nIn accordance with Article 10 of Regulation (EU) No 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, as applicable, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3, of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum.\nWhen issuing a standardisation request to European standardisation organisations, the Commission shall specify that standards have to be clear, consistent, including with the standards developed in the various sectors for products covered by the existing Union harmonisation legislation listed in Annex I, and aiming to ensure that high-risk AI systems or general-purpose AI models placed on the market or put into service in the Union meet the relevant requirements or obligations laid down in this Regulation.\nThe Commission shall request the European standardisation organisations to provide evidence of their best efforts to fulfil the objectives referred to in the first and the second subparagraph of this paragraph in accordance with Article 24 of Regulation (EU) No 1025/2012.\nThe participants in the standardisation process shall seek to promote investment and innovation in AI, including through increasing legal certainty, as well as the competitiveness and growth of the Union market, to contribute to strengthening global cooperation on standardisation and taking into account existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests, and to enhance multi-stakeholder governance ensuring a balanced representation of interests and the effective participation of all relevant stakeholders in accordance with Articles 5, 6, and 7 of Regulation (EU) No 1025/2012. Article 41 Common specifications The Commission may adopt, implementing acts establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled: (a)\nthe Commission has requested, pursuant to Article 10(1) of Regulation (EU) No 1025/2012, one or more European standardisation organisations to draft a harmonised standard for the requirements set out in Section 2 of this Chapter, or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V, and:\n(i)\nthe request has not been accepted by any of the European standardisation organisations; or\n(ii)\nthe harmonised standards addressing that request are not delivered within the deadline set in accordance with Article 10(1) of Regulation (EU) No 1025/2012; or\n(iii)\nthe relevant harmonised standards insufficiently address fundamental rights concerns; or\n(iv)\nthe harmonised standards do not comply with the request; and\n(b)\nno reference to harmonised standards covering the requirements referred to in Section 2 of this Chapter or, as applicable, the obligations referred to in Sections 2 and 3 of Chapter V has been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and no such reference is expected to be published within a reasonable period.\nWhen drafting the common specifications, the Commission shall consult the advisory forum referred to in Article 67.\nThe implementing acts referred to in the first subparagraph of this paragraph shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nBefore preparing a draft implementing act, the Commission shall inform the committee referred to in Article 22 of Regulation (EU) No 1025/2012 that it considers the conditions laid down in paragraph 1 of this Article to be fulfilled.\nHigh-risk AI systems or general-purpose AI models which are in conformity with the common specifications referred to in paragraph 1, or parts of those specifications, shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, to comply with the obligations referred to in Sections 2 and 3 of Chapter V, to the extent those common specifications cover those requirements or those obligations.\nWhere a harmonised standard is adopted by a European standardisation organisation and proposed to the Commission for the publication of its reference in the Official Journal of the European Union, the Commission shall assess the harmonised standard in accordance with Regulation (EU) No 1025/2012. When reference to a harmonised standard is published in the Official Journal of the European Union, the Commission shall repeal the implementing acts referred to in paragraph 1, or parts thereof which cover the same requirements set out in Section 2 of this Chapter or, as applicable, the same obligations set out in Sections 2 and 3 of Chapter V.\nWhere providers of high-risk AI systems or general-purpose AI models do not comply with the common specifications referred to in paragraph 1, they shall duly justify that they have adopted technical solutions that meet the requirements referred to in Section 2 of this Chapter or, as applicable, comply with the obligations set out in Sections 2 and 3 of Chapter V to a level at least equivalent thereto.\nWhere a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.\nArticle 42 Presumption of conformity with certain requirements High-risk AI systems that have been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used shall be presumed to comply with the relevant requirements laid down in Article 10(4).\nHigh-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements.\nArticle 43 Conformity assessment For high-risk AI systems listed in point 1 of Annex III, where, in demonstrating the compliance of a high-risk AI system with the requirements set out in Section 2, the provider has applied harmonised standards referred to in Article 40, or, where applicable, common specifications referred to in Article 41, the provider shall opt for one of the following conformity assessment procedures based on: (a)\nthe internal control referred to in Annex VI; or\n(b)\nthe assessment of the quality management system and the assessment of the technical documentation, with the involvement of a notified body, referred to in Annex VII.\nIn demonstrating the compliance of a high-risk AI system with the requirements set out in Section 2, the provider shall follow the conformity assessment procedure set out in Annex VII where:\n(a)\nharmonised standards referred to in Article 40 do not exist, and common specifications referred to in Article 41 are not available;\n(b)\nthe provider has not applied, or has applied only part of, the harmonised standard;\n(c)\nthe common specifications referred to in point (a) exist, but the provider has not applied them;\n(d)\none or more of the harmonised standards referred to in point (a) has been published with a restriction, and only on the part of the standard that was restricted.\nFor the purposes of the conformity assessment procedure referred to in Annex VII, the provider may choose any of the notified bodies. However, where the high-risk AI system is intended to be put into service by law enforcement, immigration or asylum authorities or by Union institutions, bodies, offices or agencies, the market surveillance authority referred to in Article 74(8) or (9), as applicable, shall act as a notified body.\nFor high-risk AI systems referred to in points 2 to 8 of Annex III, providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body.\nFor high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, the provider shall follow the relevant conformity assessment procedure as required under those legal acts. The requirements set out in Section 2 of this Chapter shall apply to those high-risk AI systems and shall be part of that assessment. Points 4.3., 4.4., 4.5. and the fifth paragraph of point 4.6 of Annex VII shall also apply.\nFor the purposes of that assessment, notified bodies which have been notified under those legal acts shall be entitled to control the conformity of the high-risk AI systems with the requirements set out in Section 2, provided that the compliance of those notified bodies with requirements laid down in Article 31(4), (5), (10) and (11) has been assessed in the context of the notification procedure under those legal acts.\nWhere a legal act listed in Section A of Annex I enables the product manufacturer to opt out from a third-party conformity assessment, provided that that manufacturer has applied all harmonised standards covering all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter.\nHigh-risk AI systems that have already been subject to a conformity assessment procedure shall undergo a new conformity assessment procedure in the event of a substantial modification, regardless of whether the modified system is intended to be further distributed or continues to be used by the current deployer. For high-risk AI systems that continue to learn after being placed on the market or put into service, changes to the high-risk AI system and its performance that have been pre-determined by the provider at the moment of the initial conformity assessment and are part of the information contained in the technical documentation referred to in point 2(f) of Annex IV, shall not constitute a substantial modification.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annexes VI and VII by updating them in light of technical progress.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend paragraphs 1 and 2 of this Article in order to subject high-risk AI systems referred to in points 2 to 8 of Annex III to the conformity assessment procedure referred to in Annex VII or parts thereof. The Commission shall adopt such delegated acts taking into account the effectiveness of the conformity assessment procedure based on internal control referred to in Annex VI in preventing or minimising the risks to health and safety and protection of fundamental rights posed by such systems, as well as the availability of adequate capacities and resources among notified bodies.\nArticle 44 Certificates Certificates issued by notified bodies in accordance with Annex VII shall be drawn-up in a language which can be easily understood by the relevant authorities in the Member State in which the notified body is established.\nCertificates shall be valid for the period they indicate, which shall not exceed five years for AI systems covered by Annex I, and four years for AI systems covered by Annex III. At the request of the provider, the validity of a certificate may be extended for further periods, each not exceeding five years for AI systems covered by Annex I, and four years for AI systems covered by Annex III, based on a re-assessment in accordance with the applicable conformity assessment procedures. Any supplement to a certificate shall remain valid, provided that the certificate which it supplements is valid.\nWhere a notified body finds that an AI system no longer meets the requirements set out in Section 2, it shall, taking account of the principle of proportionality, suspend or withdraw the certificate issued or impose restrictions on it, unless compliance with those requirements is ensured by appropriate corrective action taken by the provider of the system within an appropriate deadline set by the notified body. The notified body shall give reasons for its decision.\nAn appeal procedure against decisions of the notified bodies, including on conformity certificates issued, shall be available.\nArticle 45 Information obligations of notified bodies Notified bodies shall inform the notifying authority of the following: (a)\nany Union technical documentation assessment certificates, any supplements to those certificates, and any quality management system approvals issued in accordance with the requirements of Annex VII;\n(b)\nany refusal, restriction, suspension or withdrawal of a Union technical documentation assessment certificate or a quality management system approval issued in accordance with the requirements of Annex VII;\n(c)\nany circumstances affecting the scope of or conditions for notification;\n(d)\nany request for information which they have received from market surveillance authorities regarding conformity assessment activities;\n(e)\non request, conformity assessment activities performed within the scope of their notification and any other activity performed, including cross-border activities and subcontracting.\nEach notified body shall inform the other notified bodies of: (a)\nquality management system approvals which it has refused, suspended or withdrawn, and, upon request, of quality system approvals which it has issued;\n(b)\nUnion technical documentation assessment certificates or any supplements thereto which it has refused, withdrawn, suspended or otherwise restricted, and, upon request, of the certificates and/or supplements thereto which it has issued.\nEach notified body shall provide the other notified bodies carrying out similar conformity assessment activities covering the same types of AI systems with relevant information on issues relating to negative and, on request, positive conformity assessment results.\nNotified bodies shall safeguard the confidentiality of the information that they obtain, in accordance with Article 78.\nArticle 46 Derogation from conformity assessment procedure By way of derogation from Article 43 and upon a duly justified request, any market surveillance authority may authorise the placing on the market or the putting into service of specific high-risk AI systems within the territory of the Member State concerned, for exceptional reasons of public security or the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. That authorisation shall be for a limited period while the necessary conformity assessment procedures are being carried out, taking into account the exceptional reasons justifying the derogation. The completion of those procedures shall be undertaken without undue delay.\nIn a duly justified situation of urgency for exceptional reasons of public security or in the case of specific, substantial and imminent threat to the life or physical safety of natural persons, law-enforcement authorities or civil protection authorities may put a specific high-risk AI system into service without the authorisation referred to in paragraph 1, provided that such authorisation is requested during or after the use without undue delay. If the authorisation referred to in paragraph 1 is refused, the use of the high-risk AI system shall be stopped with immediate effect and all the results and outputs of such use shall be immediately discarded.\nThe authorisation referred to in paragraph 1 shall be issued only if the market surveillance authority concludes that the high-risk AI system complies with the requirements of Section 2. The market surveillance authority shall inform the Commission and the other Member States of any authorisation issued pursuant to paragraphs 1 and 2. This obligation shall not cover sensitive operational data in relation to the activities of law-enforcement authorities.\nWhere, within 15 calendar days of receipt of the information referred to in paragraph 3, no objection has been raised by either a Member State or the Commission in respect of an authorisation issued by a market surveillance authority of a Member State in accordance with paragraph 1, that authorisation shall be deemed justified.\nWhere, within 15 calendar days of receipt of the notification referred to in paragraph 3, objections are raised by a Member State against an authorisation issued by a market surveillance authority of another Member State, or where the Commission considers the authorisation to be contrary to Union law, or the conclusion of the Member States regarding the compliance of the system as referred to in paragraph 3 to be unfounded, the Commission shall, without delay, enter into consultations with the relevant Member State. The operators concerned shall be consulted and have the possibility to present their views. Having regard thereto, the Commission shall decide whether the authorisation is justified. The Commission shall address its decision to the Member State concerned and to the relevant operators.\nWhere the Commission considers the authorisation unjustified, it shall be withdrawn by the market surveillance authority of the Member State concerned.\nFor high-risk AI systems related to products covered by Union harmonisation legislation listed in Section A of Annex I, only the derogations from the conformity assessment established in that Union harmonisation legislation shall apply.\nArticle 47 EU declaration of conformity The provider shall draw up a written machine readable, physical or electronically signed EU declaration of conformity for each high-risk AI system, and keep it at the disposal of the national competent authorities for 10 years after the high-risk AI system has been placed on the market or put into service. The EU declaration of conformity shall identify the high-risk AI system for which it has been drawn up. A copy of the EU declaration of conformity shall be submitted to the relevant national competent authorities upon request.\nThe EU declaration of conformity shall state that the high-risk AI system concerned meets the requirements set out in Section 2. The EU declaration of conformity shall contain the information set out in Annex V, and shall be translated into a language that can be easily understood by the national competent authorities of the Member States in which the high-risk AI system is placed on the market or made available.\nWhere high-risk AI systems are subject to other Union harmonisation legislation which also requires an EU declaration of conformity, a single EU declaration of conformity shall be drawn up in respect of all Union law applicable to the high-risk AI system. The declaration shall contain all the information required to identify the Union harmonisation legislation to which the declaration relates.\nBy drawing up the EU declaration of conformity, the provider shall assume responsibility for compliance with the requirements set out in Section 2. The provider shall keep the EU declaration of conformity up-to-date as appropriate.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annex V by updating the content of the EU declaration of conformity set out in that Annex, in order to introduce elements that become necessary in light of technical progress.\nArticle 48 CE marking The CE marking shall be subject to the general principles set out in Article 30 of Regulation (EC) No 765/2008.\nFor high-risk AI systems provided digitally, a digital CE marking shall be used, only if it can easily be accessed via the interface from which that system is accessed or via an easily accessible machine-readable code or other electronic means.\nThe CE marking shall be affixed visibly, legibly and indelibly for high-risk AI systems. Where that is not possible or not warranted on account of the nature of the high-risk AI system, it shall be affixed to the packaging or to the accompanying documentation, as appropriate.\nWhere applicable, the CE marking shall be followed by the identification number of the notified body responsible for the conformity assessment procedures set out in Article 43. The identification number of the notified body shall be affixed by the body itself or, under its instructions, by the provider or by the provider’s authorised representative. The identification number shall also be indicated in any promotional material which mentions that the high-risk AI system fulfils the requirements for CE marking.\nWhere high-risk AI systems are subject to other Union law which also provides for the affixing of the CE marking, the CE marking shall indicate that the high-risk AI system also fulfil the requirements of that other law.\nArticle 49 Registration Before placing on the market or putting into service a high-risk AI system listed in Annex III, with the exception of high-risk AI systems referred to in point 2 of Annex III, the provider or, where applicable, the authorised representative shall register themselves and their system in the EU database referred to in Article 71.\nBefore placing on the market or putting into service an AI system for which the provider has concluded that it is not high-risk according to Article 6(3), that provider or, where applicable, the authorised representative shall register themselves and that system in the EU database referred to in Article 71.\nBefore putting into service or using a high-risk AI system listed in Annex III, with the exception of high-risk AI systems listed in point 2 of Annex III, deployers that are public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf shall register themselves, select the system and register its use in the EU database referred to in Article 71.\nFor high-risk AI systems referred to in points 1, 6 and 7 of Annex III, in the areas of law enforcement, migration, asylum and border control management, the registration referred to in paragraphs 1, 2 and 3 of this Article shall be in a secure non-public section of the EU database referred to in Article 71 and shall include only the following information, as applicable, referred to in:\n(a)\nSection A, points 1 to 10, of Annex VIII, with the exception of points 6, 8 and 9;\n(b)\nSection B, points 1 to 5, and points 8 and 9 of Annex VIII;\n(c)\nSection C, points 1 to 3, of Annex VIII;\n(d)\npoints 1, 2, 3 and 5, of Annex IX.\nOnly the Commission and national authorities referred to in Article 74(8) shall have access to the respective restricted sections of the EU database listed in the first subparagraph of this paragraph.\nHigh-risk AI systems referred to in point 2 of Annex III shall be registered at national level. CHAPTER IV TRANSPARENCY OBLIGATIONS FOR PROVIDERS AND DEPLOYERS OF CERTAIN AI SYSTEMS\nArticle 50 Transparency obligations for providers and deployers of certain AI systems Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. This obligation shall not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, unless those systems are available for the public to report a criminal offence.\nProviders of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards. This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences.\nDeployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. This obligation shall not apply to AI systems used for biometric categorisation and emotion recognition, which are permitted by law to detect, prevent or investigate criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, and in accordance with Union law.\nDeployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.\nDeployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.\nThe information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.\nParagraphs 1 to 4 shall not affect the requirements and obligations set out in Chapter III, and shall be without prejudice to other transparency obligations laid down in Union or national law for deployers of AI systems.\nThe AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection and labelling of artificially generated or manipulated content. The Commission may adopt implementing acts to approve those codes of practice in accordance with the procedure laid down in Article 56 (6). If it deems the code is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).\nCHAPTER V GENERAL-PURPOSE AI MODELS\nSECTION 1\nClassification rules\nArticle 51 Classification of general-purpose AI models as general-purpose AI models with systemic risk A general-purpose AI model shall be classified as a general-purpose AI model with systemic risk if it meets any of the following conditions: (a)\nit has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks;\n(b)\nbased on a decision of the Commission, ex officio or following a qualified alert from the scientific panel, it has capabilities or an impact equivalent to those set out in point (a) having regard to the criteria set out in Annex XIII.\nA general-purpose AI model shall be presumed to have high impact capabilities pursuant to paragraph 1, point (a), when the cumulative amount of computation used for its training measured in floating point operations is greater than 1025.\nThe Commission shall adopt delegated acts in accordance with Article 97 to amend the thresholds listed in paragraphs 1 and 2 of this Article, as well as to supplement benchmarks and indicators in light of evolving technological developments, such as algorithmic improvements or increased hardware efficiency, when necessary, for these thresholds to reflect the state of the art.\nArticle 52 Procedure Where a general-purpose AI model meets the condition referred to in Article 51(1), point (a), the relevant provider shall notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met. That notification shall include the information necessary to demonstrate that the relevant requirement has been met. If the Commission becomes aware of a general-purpose AI model presenting systemic risks of which it has not been notified, it may decide to designate it as a model with systemic risk.\nThe provider of a general-purpose AI model that meets the condition referred to in Article 51(1), point (a), may present, with its notification, sufficiently substantiated arguments to demonstrate that, exceptionally, although it meets that requirement, the general-purpose AI model does not present, due to its specific characteristics, systemic risks and therefore should not be classified as a general-purpose AI model with systemic risk.\nWhere the Commission concludes that the arguments submitted pursuant to paragraph 2 are not sufficiently substantiated and the relevant provider was not able to demonstrate that the general-purpose AI model does not present, due to its specific characteristics, systemic risks, it shall reject those arguments, and the general-purpose AI model shall be considered to be a general-purpose AI model with systemic risk.\nThe Commission may designate a general-purpose AI model as presenting systemic risks, ex officio or following a qualified alert from the scientific panel pursuant to Article 90(1), point (a), on the basis of criteria set out in Annex XIII.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annex XIII by specifying and updating the criteria set out in that Annex.\nUpon a reasoned request of a provider whose model has been designated as a general-purpose AI model with systemic risk pursuant to paragraph 4, the Commission shall take the request into account and may decide to reassess whether the general-purpose AI model can still be considered to present systemic risks on the basis of the criteria set out in Annex XIII. Such a request shall contain objective, detailed and new reasons that have arisen since the designation decision. Providers may request reassessment at the earliest six months after the designation decision. Where the Commission, following its reassessment, decides to maintain the designation as a general-purpose AI model with systemic risk, providers may request reassessment at the earliest six months after that decision.\nThe Commission shall ensure that a list of general-purpose AI models with systemic risk is published and shall keep that list up to date, without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law.\nSECTION 2\nObligations for providers of general-purpose AI models\nArticle 53 Obligations for providers of general-purpose AI models Providers of general-purpose AI models shall: (a)\ndraw up and keep up-to-date the technical documentation of the model, including its training and testing process and the results of its evaluation, which shall contain, at a minimum, the information set out in Annex XI for the purpose of providing it, upon request, to the AI Office and the national competent authorities;\n(b)\ndraw up, keep up-to-date and make available information and documentation to providers of AI systems who intend to integrate the general-purpose AI model into their AI systems. Without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law, the information and documentation shall:\n(i)\nenable providers of AI systems to have a good understanding of the capabilities and limitations of the general-purpose AI model and to comply with their obligations pursuant to this Regulation; and\n(ii)\ncontain, at a minimum, the elements set out in Annex XII;\n(c)\nput in place a policy to comply with Union law on copyright and related rights, and in particular to identify and comply with, including through state-of-the-art technologies, a reservation of rights expressed pursuant to Article 4(3) of Directive (EU) 2019/790;\n(d)\ndraw up and make publicly available a sufficiently detailed summary about the content used for training of the general-purpose AI model, according to a template provided by the AI Office.\nThe obligations set out in paragraph 1, points (a) and (b), shall not apply to providers of AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available. This exception shall not apply to general-purpose AI models with systemic risks.\nProviders of general-purpose AI models shall cooperate as necessary with the Commission and the national competent authorities in the exercise of their competences and powers pursuant to this Regulation.\nProviders of general-purpose AI models may rely on codes of practice within the meaning of Article 56 to demonstrate compliance with the obligations set out in paragraph 1 of this Article, until a harmonised standard is published. Compliance with European harmonised standards grants providers the presumption of conformity to the extent that those standards cover those obligations. Providers of general-purpose AI models who do not adhere to an approved code of practice or do not comply with a European harmonised standard shall demonstrate alternative adequate means of compliance for assessment by the Commission.\nFor the purpose of facilitating compliance with Annex XI, in particular points 2 (d) and (e) thereof, the Commission is empowered to adopt delegated acts in accordance with Article 97 to detail measurement and calculation methodologies with a view to allowing for comparable and verifiable documentation.\nThe Commission is empowered to adopt delegated acts in accordance with Article 97(2) to amend Annexes XI and XII in light of evolving technological developments.\nAny information or documentation obtained pursuant to this Article, including trade secrets, shall be treated in accordance with the confidentiality obligations set out in Article 78.\nArticle 54 Authorised representatives of providers of general-purpose AI models Prior to placing a general-purpose AI model on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union.\nThe provider shall enable its authorised representative to perform the tasks specified in the mandate received from the provider.\nThe authorised representative shall perform the tasks specified in the mandate received from the provider. It shall provide a copy of the mandate to the AI Office upon request, in one of the official languages of the institutions of the Union. For the purposes of this Regulation, the mandate shall empower the authorised representative to carry out the following tasks:\n(a)\nverify that the technical documentation specified in Annex XI has been drawn up and all obligations referred to in Article 53 and, where applicable, Article 55 have been fulfilled by the provider;\n(b)\nkeep a copy of the technical documentation specified in Annex XI at the disposal of the AI Office and national competent authorities, for a period of 10 years after the general-purpose AI model has been placed on the market, and the contact details of the provider that appointed the authorised representative;\n(c)\nprovide the AI Office, upon a reasoned request, with all the information and documentation, including that referred to in point (b), necessary to demonstrate compliance with the obligations in this Chapter;\n(d)\ncooperate with the AI Office and competent authorities, upon a reasoned request, in any action they take in relation to the general-purpose AI model, including when the model is integrated into AI systems placed on the market or put into service in the Union.\nThe mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the AI Office or the competent authorities, on all issues related to ensuring compliance with this Regulation.\nThe authorised representative shall terminate the mandate if it considers or has reason to consider the provider to be acting contrary to its obligations pursuant to this Regulation. In such a case, it shall also immediately inform the AI Office about the termination of the mandate and the reasons therefor.\nThe obligation set out in this Article shall not apply to providers of general-purpose AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available, unless the general-purpose AI models present systemic risks.\nSECTION 3\nObligations of providers of general-purpose AI models with systemic risk\nArticle 55 Obligations of providers of general-purpose AI models with systemic risk In addition to the obligations listed in Articles 53 and 54, providers of general-purpose AI models with systemic risk shall: (a)\nperform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks;\n(b)\nassess and mitigate possible systemic risks at Union level, including their sources, that may stem from the development, the placing on the market, or the use of general-purpose AI models with systemic risk;\n(c)\nkeep track of, document, and report, without undue delay, to the AI Office and, as appropriate, to national competent authorities, relevant information about serious incidents and possible corrective measures to address them;\n(d)\nensure an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model.\nProviders of general-purpose AI models with systemic risk may rely on codes of practice within the meaning of Article 56 to demonstrate compliance with the obligations set out in paragraph 1 of this Article, until a harmonised standard is published. Compliance with European harmonised standards grants providers the presumption of conformity to the extent that those standards cover those obligations. Providers of general-purpose AI models with systemic risks who do not adhere to an approved code of practice or do not comply with a European harmonised standard shall demonstrate alternative adequate means of compliance for assessment by the Commission.\nAny information or documentation obtained pursuant to this Article, including trade secrets, shall be treated in accordance with the confidentiality obligations set out in Article 78.\nSECTION 4\nCodes of practice\nArticle 56 Codes of practice The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level in order to contribute to the proper application of this Regulation, taking into account international approaches.\nThe AI Office and the Board shall aim to ensure that the codes of practice cover at least the obligations provided for in Articles 53 and 55, including the following issues:\n(a)\nthe means to ensure that the information referred to in Article 53(1), points (a) and (b), is kept up to date in light of market and technological developments;\n(b)\nthe adequate level of detail for the summary about the content used for training;\n(c)\nthe identification of the type and nature of the systemic risks at Union level, including their sources, where appropriate;\n(d)\nthe measures, procedures and modalities for the assessment and management of the systemic risks at Union level, including the documentation thereof, which shall be proportionate to the risks, take into consideration their severity and probability and take into account the specific challenges of tackling those risks in light of the possible ways in which such risks may emerge and materialise along the AI value chain.\nThe AI Office may invite all providers of general-purpose AI models, as well as relevant national competent authorities, to participate in the drawing-up of codes of practice. Civil society organisations, industry, academia and other relevant stakeholders, such as downstream providers and independent experts, may support the process.\nThe AI Office and the Board shall aim to ensure that the codes of practice clearly set out their specific objectives and contain commitments or measures, including key performance indicators as appropriate, to ensure the achievement of those objectives, and that they take due account of the needs and interests of all interested parties, including affected persons, at Union level.\nThe AI Office shall aim to ensure that participants to the codes of practice report regularly to the AI Office on the implementation of the commitments and the measures taken and their outcomes, including as measured against the key performance indicators as appropriate. Key performance indicators and reporting commitments shall reflect differences in size and capacity between various participants.\nThe AI Office and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The AI Office and the Board shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. They shall publish their assessment of the adequacy of the codes of practice.\nThe Commission may, by way of an implementing act, approve a code of practice and give it a general validity within the Union. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nThe AI Office may invite all providers of general-purpose AI models to adhere to the codes of practice. For providers of general-purpose AI models not presenting systemic risks this adherence may be limited to the obligations provided for in Article 53, unless they declare explicitly their interest to join the full code.\nThe AI Office shall, as appropriate, also encourage and facilitate the review and adaptation of the codes of practice, in particular in light of emerging standards. The AI Office shall assist in the assessment of available standards.\nCodes of practice shall be ready at the latest by 2 May 2025. The AI Office shall take the necessary steps, including inviting providers pursuant to paragraph 7.\nIf, by 2 August 2025, a code of practice cannot be finalised, or if the AI Office deems it is not adequate following its assessment under paragraph 6 of this Article, the Commission may provide, by means of implementing acts, common rules for the implementation of the obligations provided for in Articles 53 and 55, including the issues set out in paragraph 2 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nCHAPTER VI MEASURES IN SUPPORT OF INNOVATION\nArticle 57 AI regulatory sandboxes Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2026. That sandbox may also be established jointly with the competent authorities of other Member States. The Commission may provide technical support, advice and tools for the establishment and operation of AI regulatory sandboxes. The obligation under the first subparagraph may also be fulfilled by participating in an existing sandbox in so far as that participation provides an equivalent level of national coverage for the participating Member States.\nAdditional AI regulatory sandboxes at regional or local level, or established jointly with the competent authorities of other Member States may also be established.\nThe European Data Protection Supervisor may also establish an AI regulatory sandbox for Union institutions, bodies, offices and agencies, and may exercise the roles and the tasks of national competent authorities in accordance with this Chapter.\nMember States shall ensure that the competent authorities referred to in paragraphs 1 and 2 allocate sufficient resources to comply with this Article effectively and in a timely manner. Where appropriate, national competent authorities shall cooperate with other relevant authorities, and may allow for the involvement of other actors within the AI ecosystem. This Article shall not affect other regulatory sandboxes established under Union or national law. Member States shall ensure an appropriate level of cooperation between the authorities supervising those other sandboxes and the national competent authorities.\nAI regulatory sandboxes established under paragraph 1 shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authority. Such sandboxes may include testing in real world conditions supervised therein.\nCompetent authorities shall provide, as appropriate, guidance, supervision and support within the AI regulatory sandbox with a view to identifying risks, in particular to fundamental rights, health and safety, testing, mitigation measures, and their effectiveness in relation to the obligations and requirements of this Regulation and, where relevant, other Union and national law supervised within the sandbox.\nCompetent authorities shall provide providers and prospective providers participating in the AI regulatory sandbox with guidance on regulatory expectations and how to fulfil the requirements and obligations set out in this Regulation.\nUpon request of the provider or prospective provider of the AI system, the competent authority shall provide a written proof of the activities successfully carried out in the sandbox. The competent authority shall also provide an exit report detailing the activities carried out in the sandbox and the related results and learning outcomes. Providers may use such documentation to demonstrate their compliance with this Regulation through the conformity assessment process or relevant market surveillance activities. In this regard, the exit reports and the written proof provided by the national competent authority shall be taken positively into account by market surveillance authorities and notified bodies, with a view to accelerating conformity assessment procedures to a reasonable extent.\nSubject to the confidentiality provisions in Article 78, and with the agreement of the provider or prospective provider, the Commission and the Board shall be authorised to access the exit reports and shall take them into account, as appropriate, when exercising their tasks under this Regulation. If both the provider or prospective provider and the national competent authority explicitly agree, the exit report may be made publicly available through the single information platform referred to in this Article.\nThe establishment of AI regulatory sandboxes shall aim to contribute to the following objectives:\n(a)\nimproving legal certainty to achieve regulatory compliance with this Regulation or, where relevant, other applicable Union and national law;\n(b)\nsupporting the sharing of best practices through cooperation with the authorities involved in the AI regulatory sandbox;\n(c)\nfostering innovation and competitiveness and facilitating the development of an AI ecosystem;\n(d)\ncontributing to evidence-based regulatory learning;\n(e)\nfacilitating and accelerating access to the Union market for AI systems, in particular when provided by SMEs, including start-ups.\nNational competent authorities shall ensure that, to the extent the innovative AI systems involve the processing of personal data or otherwise fall under the supervisory remit of other national authorities or competent authorities providing or supporting access to data, the national data protection authorities and those other national or competent authorities are associated with the operation of the AI regulatory sandbox and involved in the supervision of those aspects to the extent of their respective tasks and powers.\nThe AI regulatory sandboxes shall not affect the supervisory or corrective powers of the competent authorities supervising the sandboxes, including at regional or local level. Any significant risks to health and safety and fundamental rights identified during the development and testing of such AI systems shall result in an adequate mitigation. National competent authorities shall have the power to temporarily or permanently suspend the testing process, or the participation in the sandbox if no effective mitigation is possible, and shall inform the AI Office of such decision. National competent authorities shall exercise their supervisory powers within the limits of the relevant law, using their discretionary powers when implementing legal provisions in respect of a specific AI regulatory sandbox project, with the objective of supporting innovation in AI in the Union.\nProviders and prospective providers participating in the AI regulatory sandbox shall remain liable under applicable Union and national liability law for any damage inflicted on third parties as a result of the experimentation taking place in the sandbox. However, provided that the prospective providers observe the specific plan and the terms and conditions for their participation and follow in good faith the guidance given by the national competent authority, no administrative fines shall be imposed by the authorities for infringements of this Regulation. Where other competent authorities responsible for other Union and national law were actively involved in the supervision of the AI system in the sandbox and provided guidance for compliance, no administrative fines shall be imposed regarding that law.\nThe AI regulatory sandboxes shall be designed and implemented in such a way that, where relevant, they facilitate cross-border cooperation between national competent authorities.\nNational competent authorities shall coordinate their activities and cooperate within the framework of the Board.\nNational competent authorities shall inform the AI Office and the Board of the establishment of a sandbox, and may ask them for support and guidance. The AI Office shall make publicly available a list of planned and existing sandboxes and keep it up to date in order to encourage more interaction in the AI regulatory sandboxes and cross-border cooperation.\nNational competent authorities shall submit annual reports to the AI Office and to the Board, from one year after the establishment of the AI regulatory sandbox and every year thereafter until its termination, and a final report. Those reports shall provide information on the progress and results of the implementation of those sandboxes, including best practices, incidents, lessons learnt and recommendations on their setup and, where relevant, on the application and possible revision of this Regulation, including its delegated and implementing acts, and on the application of other Union law supervised by the competent authorities within the sandbox. The national competent authorities shall make those annual reports or abstracts thereof available to the public, online. The Commission shall, where appropriate, take the annual reports into account when exercising its tasks under this Regulation.\nThe Commission shall develop a single and dedicated interface containing all relevant information related to AI regulatory sandboxes to allow stakeholders to interact with AI regulatory sandboxes and to raise enquiries with competent authorities, and to seek non-binding guidance on the conformity of innovative products, services, business models embedding AI technologies, in accordance with Article 62(1), point (c). The Commission shall proactively coordinate with national competent authorities, where relevant.\nArticle 58 Detailed arrangements for, and functioning of, AI regulatory sandboxes In order to avoid fragmentation across the Union, the Commission shall adopt implementing acts specifying the detailed arrangements for the establishment, development, implementation, operation and supervision of the AI regulatory sandboxes. The implementing acts shall include common principles on the following issues: (a)\neligibility and selection criteria for participation in the AI regulatory sandbox;\n(b)\nprocedures for the application, participation, monitoring, exiting from and termination of the AI regulatory sandbox, including the sandbox plan and the exit report;\n(c)\nthe terms and conditions applicable to the participants.\nThose implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nThe implementing acts referred to in paragraph 1 shall ensure: (a)\nthat AI regulatory sandboxes are open to any applying provider or prospective provider of an AI system who fulfils eligibility and selection criteria, which shall be transparent and fair, and that national competent authorities inform applicants of their decision within three months of the application;\n(b)\nthat AI regulatory sandboxes allow broad and equal access and keep up with demand for participation; providers and prospective providers may also submit applications in partnerships with deployers and other relevant third parties;\n(c)\nthat the detailed arrangements for, and conditions concerning AI regulatory sandboxes support, to the best extent possible, flexibility for national competent authorities to establish and operate their AI regulatory sandboxes;\n(d)\nthat access to the AI regulatory sandboxes is free of charge for SMEs, including start-ups, without prejudice to exceptional costs that national competent authorities may recover in a fair and proportionate manner;\n(e)\nthat they facilitate providers and prospective providers, by means of the learning outcomes of the AI regulatory sandboxes, in complying with conformity assessment obligations under this Regulation and the voluntary application of the codes of conduct referred to in Article 95;\n(f)\nthat AI regulatory sandboxes facilitate the involvement of other relevant actors within the AI ecosystem, such as notified bodies and standardisation organisations, SMEs, including start-ups, enterprises, innovators, testing and experimentation facilities, research and experimentation labs and European Digital Innovation Hubs, centres of excellence, individual researchers, in order to allow and facilitate cooperation with the public and private sectors;\n(g)\nthat procedures, processes and administrative requirements for application, selection, participation and exiting the AI regulatory sandbox are simple, easily intelligible, and clearly communicated in order to facilitate the participation of SMEs, including start-ups, with limited legal and administrative capacities and are streamlined across the Union, in order to avoid fragmentation and that participation in an AI regulatory sandbox established by a Member State, or by the European Data Protection Supervisor is mutually and uniformly recognised and carries the same legal effects across the Union;\n(h)\nthat participation in the AI regulatory sandbox is limited to a period that is appropriate to the complexity and scale of the project and that may be extended by the national competent authority;\n(i)\nthat AI regulatory sandboxes facilitate the development of tools and infrastructure for testing, benchmarking, assessing and explaining dimensions of AI systems relevant for regulatory learning, such as accuracy, robustness and cybersecurity, as well as measures to mitigate risks to fundamental rights and society at large.\nProspective providers in the AI regulatory sandboxes, in particular SMEs and start-ups, shall be directed, where relevant, to pre-deployment services such as guidance on the implementation of this Regulation, to other value-adding services such as help with standardisation documents and certification, testing and experimentation facilities, European Digital Innovation Hubs and centres of excellence.\nWhere national competent authorities consider authorising testing in real world conditions supervised within the framework of an AI regulatory sandbox to be established under this Article, they shall specifically agree the terms and conditions of such testing and, in particular, the appropriate safeguards with the participants, with a view to protecting fundamental rights, health and safety. Where appropriate, they shall cooperate with other national competent authorities with a view to ensuring consistent practices across the Union.\nArticle 59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox\nIn the AI regulatory sandbox, personal data lawfully collected for other purposes may be processed solely for the purpose of developing, training and testing certain AI systems in the sandbox when all of the following conditions are met: (a)\nAI systems shall be developed for safeguarding substantial public interest by a public authority or another natural or legal person and in one or more of the following areas:\n(i)\npublic safety and public health, including disease detection, diagnosis prevention, control and treatment and improvement of health care systems;\n(ii)\na high level of protection and improvement of the quality of the environment, protection of biodiversity, protection against pollution, green transition measures, climate change mitigation and adaptation measures;\n(iii)\nenergy sustainability;\n(iv)\nsafety and resilience of transport systems and mobility, critical infrastructure and networks;\n(v)\nefficiency and quality of public administration and public services;\n(b)\nthe data processed are necessary for complying with one or more of the requirements referred to in Chapter III, Section 2 where those requirements cannot effectively be fulfilled by processing anonymised, synthetic or other non-personal data;\n(c)\nthere are effective monitoring mechanisms to identify if any high risks to the rights and freedoms of the data subjects, as referred to in Article 35 of Regulation (EU) 2016/679 and in Article 39 of Regulation (EU) 2018/1725, may arise during the sandbox experimentation, as well as response mechanisms to promptly mitigate those risks and, where necessary, stop the processing;\n(d)\nany personal data to be processed in the context of the sandbox are in a functionally separate, isolated and protected data processing environment under the control of the prospective provider and only authorised persons have access to those data;\n(e)\nproviders can further share the originally collected data only in accordance with Union data protection law; any personal data created in the sandbox cannot be shared outside the sandbox;\n(f)\nany processing of personal data in the context of the sandbox neither leads to measures or decisions affecting the data subjects nor does it affect the application of their rights laid down in Union law on the protection of personal data;\n(g)\nany personal data processed in the context of the sandbox are protected by means of appropriate technical and organisational measures and deleted once the participation in the sandbox has terminated or the personal data has reached the end of its retention period;\n(h)\nthe logs of the processing of personal data in the context of the sandbox are kept for the duration of the participation in the sandbox, unless provided otherwise by Union or national law;\n(i)\na complete and detailed description of the process and rationale behind the training, testing and validation of the AI system is kept together with the testing results as part of the technical documentation referred to in Annex IV;\n(j)\na short summary of the AI project developed in the sandbox, its objectives and expected results is published on the website of the competent authorities; this obligation shall not cover sensitive operational data in relation to the activities of law enforcement, border control, immigration or asylum authorities.\nFor the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security, under the control and responsibility of law enforcement authorities, the processing of personal data in AI regulatory sandboxes shall be based on a specific Union or national law and subject to the same cumulative conditions as referred to in paragraph 1.\nParagraph 1 is without prejudice to Union or national law which excludes processing of personal data for other purposes than those explicitly mentioned in that law, as well as to Union or national law laying down the basis for the processing of personal data which is necessary for the purpose of developing, testing or training of innovative AI systems or any other legal basis, in compliance with Union law on the protection of personal data.\nArticle 60 Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes may be conducted by providers or prospective providers of high-risk AI systems listed in Annex III, in accordance with this Article and the real-world testing plan referred to in this Article, without prejudice to the prohibitions under Article 5. The Commission shall, by means of implementing acts, specify the detailed elements of the real-world testing plan. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nThis paragraph shall be without prejudice to Union or national law on the testing in real world conditions of high-risk AI systems related to products covered by Union harmonisation legislation listed in Annex I.\nProviders or prospective providers may conduct testing of high-risk AI systems referred to in Annex III in real world conditions at any time before the placing on the market or the putting into service of the AI system on their own or in partnership with one or more deployers or prospective deployers.\nThe testing of high-risk AI systems in real world conditions under this Article shall be without prejudice to any ethical review that is required by Union or national law.\nProviders or prospective providers may conduct the testing in real world conditions only where all of the following conditions are met:\n(a)\nthe provider or prospective provider has drawn up a real-world testing plan and submitted it to the market surveillance authority in the Member State where the testing in real world conditions is to be conducted;\n(b)\nthe market surveillance authority in the Member State where the testing in real world conditions is to be conducted has approved the testing in real world conditions and the real-world testing plan; where the market surveillance authority has not provided an answer within 30 days, the testing in real world conditions and the real-world testing plan shall be understood to have been approved; where national law does not provide for a tacit approval, the testing in real world conditions shall remain subject to an authorisation;\n(c)\nthe provider or prospective provider, with the exception of providers or prospective providers of high-risk AI systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, and high-risk AI systems referred to in point 2 of Annex III has registered the testing in real world conditions in accordance with Article 71(4) with a Union-wide unique single identification number and with the information specified in Annex IX; the provider or prospective provider of high-risk AI systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, has registered the testing in real-world conditions in the secure non-public section of the EU database according to Article 49(4), point (d), with a Union-wide unique single identification number and with the information specified therein; the provider or prospective provider of high-risk AI systems referred to in point 2 of Annex III has registered the testing in real-world conditions in accordance with Article 49(5);\n(d)\nthe provider or prospective provider conducting the testing in real world conditions is established in the Union or has appointed a legal representative who is established in the Union;\n(e)\ndata collected and processed for the purpose of the testing in real world conditions shall be transferred to third countries only provided that appropriate and applicable safeguards under Union law are implemented;\n(f)\nthe testing in real world conditions does not last longer than necessary to achieve its objectives and in any case not longer than six months, which may be extended for an additional period of six months, subject to prior notification by the provider or prospective provider to the market surveillance authority, accompanied by an explanation of the need for such an extension;\n(g)\nthe subjects of the testing in real world conditions who are persons belonging to vulnerable groups due to their age or disability, are appropriately protected;\n(h)\nwhere a provider or prospective provider organises the testing in real world conditions in cooperation with one or more deployers or prospective deployers, the latter have been informed of all aspects of the testing that are relevant to their decision to participate, and given the relevant instructions for use of the AI system referred to in Article 13; the provider or prospective provider and the deployer or prospective deployer shall conclude an agreement specifying their roles and responsibilities with a view to ensuring compliance with the provisions for testing in real world conditions under this Regulation and under other applicable Union and national law;\n(i)\nthe subjects of the testing in real world conditions have given informed consent in accordance with Article 61, or in the case of law enforcement, where the seeking of informed consent would prevent the AI system from being tested, the testing itself and the outcome of the testing in the real world conditions shall not have any negative effect on the subjects, and their personal data shall be deleted after the test is performed;\n(j)\nthe testing in real world conditions is effectively overseen by the provider or prospective provider, as well as by deployers or prospective deployers through persons who are suitably qualified in the relevant field and have the necessary capacity, training and authority to perform their tasks;\n(k)\nthe predictions, recommendations or decisions of the AI system can be effectively reversed and disregarded.\nAny subjects of the testing in real world conditions, or their legally designated representative, as appropriate, may, without any resulting detriment and without having to provide any justification, withdraw from the testing at any time by revoking their informed consent and may request the immediate and permanent deletion of their personal data. The withdrawal of the informed consent shall not affect the activities already carried out.\nIn accordance with Article 75, Member States shall confer on their market surveillance authorities the powers of requiring providers and prospective providers to provide information, of carrying out unannounced remote or on-site inspections, and of performing checks on the conduct of the testing in real world conditions and the related high-risk AI systems. Market surveillance authorities shall use those powers to ensure the safe development of testing in real world conditions.\nAny serious incident identified in the course of the testing in real world conditions shall be reported to the national market surveillance authority in accordance with Article 73. The provider or prospective provider shall adopt immediate mitigation measures or, failing that, shall suspend the testing in real world conditions until such mitigation takes place, or otherwise terminate it. The provider or prospective provider shall establish a procedure for the prompt recall of the AI system upon such termination of the testing in real world conditions.\nProviders or prospective providers shall notify the national market surveillance authority in the Member State where the testing in real world conditions is to be conducted of the suspension or termination of the testing in real world conditions and of the final outcomes.\nThe provider or prospective provider shall be liable under applicable Union and national liability law for any damage caused in the course of their testing in real world conditions.\nArticle 61 Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes\nFor the purpose of testing in real world conditions under Article 60, freely-given informed consent shall be obtained from the subjects of testing prior to their participation in such testing and after their having been duly informed with concise, clear, relevant, and understandable information regarding: (a)\nthe nature and objectives of the testing in real world conditions and the possible inconvenience that may be linked to their participation;\n(b)\nthe conditions under which the testing in real world conditions is to be conducted, including the expected duration of the subject or subjects’ participation;\n(c)\ntheir rights, and the guarantees regarding their participation, in particular their right to refuse to participate in, and the right to withdraw from, testing in real world conditions at any time without any resulting detriment and without having to provide any justification;\n(d)\nthe arrangements for requesting the reversal or the disregarding of the predictions, recommendations or decisions of the AI system;\n(e)\nthe Union-wide unique single identification number of the testing in real world conditions in accordance with Article 60(4) point (c), and the contact details of the provider or its legal representative from whom further information can be obtained.\nThe informed consent shall be dated and documented and a copy shall be given to the subjects of testing or their legal representative. Article 62 Measures for providers and deployers, in particular SMEs, including start-ups Member States shall undertake the following actions: (a)\nprovide SMEs, including start-ups, having a registered office or a branch in the Union, with priority access to the AI regulatory sandboxes, to the extent that they fulfil the eligibility conditions and selection criteria; the priority access shall not preclude other SMEs, including start-ups, other than those referred to in this paragraph from access to the AI regulatory sandbox, provided that they also fulfil the eligibility conditions and selection criteria;\n(b)\norganise specific awareness raising and training activities on the application of this Regulation tailored to the needs of SMEs including start-ups, deployers and, as appropriate, local public authorities;\n(c)\nutilise existing dedicated channels and where appropriate, establish new ones for communication with SMEs including start-ups, deployers, other innovators and, as appropriate, local public authorities to provide advice and respond to queries about the implementation of this Regulation, including as regards participation in AI regulatory sandboxes;\n(d)\nfacilitate the participation of SMEs and other relevant stakeholders in the standardisation development process.\nThe specific interests and needs of the SME providers, including start-ups, shall be taken into account when setting the fees for conformity assessment under Article 43, reducing those fees proportionately to their size, market size and other relevant indicators.\nThe AI Office shall undertake the following actions:\n(a)\nprovide standardised templates for areas covered by this Regulation, as specified by the Board in its request;\n(b)\ndevelop and maintain a single information platform providing easy to use information in relation to this Regulation for all operators across the Union;\n(c)\norganise appropriate communication campaigns to raise awareness about the obligations arising from this Regulation;\n(d)\nevaluate and promote the convergence of best practices in public procurement procedures in relation to AI systems.\nArticle 63 Derogations for specific operators Microenterprises within the meaning of Recommendation 2003/361/EC may comply with certain elements of the quality management system required by Article 17 of this Regulation in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of that Recommendation. For that purpose, the Commission shall develop guidelines on the elements of the quality management system which may be complied with in a simplified manner considering the needs of microenterprises, without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems.\nParagraph 1 of this Article shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73.\nCHAPTER VII GOVERNANCE\nSECTION 1\nGovernance at Union level\nArticle 64 AI Office The Commission shall develop Union expertise and capabilities in the field of AI through the AI Office.\nMember States shall facilitate the tasks entrusted to the AI Office, as reflected in this Regulation.\nArticle 65 Establishment and structure of the European Artificial Intelligence Board A European Artificial Intelligence Board (the ‘Board’) is hereby established.\nThe Board shall be composed of one representative per Member State. The European Data Protection Supervisor shall participate as observer. The AI Office shall also attend the Board’s meetings, without taking part in the votes. Other national and Union authorities, bodies or experts may be invited to the meetings by the Board on a case by case basis, where the issues discussed are of relevance for them.\nEach representative shall be designated by their Member State for a period of three years, renewable once.\nMember States shall ensure that their representatives on the Board:\n(a)\nhave the relevant competences and powers in their Member State so as to contribute actively to the achievement of the Board’s tasks referred to in Article 66;\n(b)\nare designated as a single contact point vis-à-vis the Board and, where appropriate, taking into account Member States’ needs, as a single contact point for stakeholders;\n(c)\nare empowered to facilitate consistency and coordination between national competent authorities in their Member State as regards the implementation of this Regulation, including through the collection of relevant data and information for the purpose of fulfilling their tasks on the Board.\nThe designated representatives of the Member States shall adopt the Board’s rules of procedure by a two-thirds majority. The rules of procedure shall, in particular, lay down procedures for the selection process, the duration of the mandate of, and specifications of the tasks of, the Chair, detailed arrangements for voting, and the organisation of the Board’s activities and those of its sub-groups.\nThe Board shall establish two standing sub-groups to provide a platform for cooperation and exchange among market surveillance authorities and notifying authorities about issues related to market surveillance and notified bodies respectively.\nThe standing sub-group for market surveillance should act as the administrative cooperation group (ADCO) for this Regulation within the meaning of Article 30 of Regulation (EU) 2019/1020.\nThe Board may establish other standing or temporary sub-groups as appropriate for the purpose of examining specific issues. Where appropriate, representatives of the advisory forum referred to in Article 67 may be invited to such sub-groups or to specific meetings of those subgroups as observers.\nThe Board shall be organised and operated so as to safeguard the objectivity and impartiality of its activities.\nThe Board shall be chaired by one of the representatives of the Member States. The AI Office shall provide the secretariat for the Board, convene the meetings upon request of the Chair, and prepare the agenda in accordance with the tasks of the Board pursuant to this Regulation and its rules of procedure.\nArticle 66 Tasks of the Board The Board shall advise and assist the Commission and the Member States in order to facilitate the consistent and effective application of this Regulation. To that end, the Board may in particular:\n(a)\ncontribute to the coordination among national competent authorities responsible for the application of this Regulation and, in cooperation with and subject to the agreement of the market surveillance authorities concerned, support joint activities of market surveillance authorities referred to in Article 74(11);\n(b)\ncollect and share technical and regulatory expertise and best practices among Member States;\n(c)\nprovide advice on the implementation of this Regulation, in particular as regards the enforcement of rules on general-purpose AI models;\n(d)\ncontribute to the harmonisation of administrative practices in the Member States, including in relation to the derogation from the conformity assessment procedures referred to in Article 46, the functioning of AI regulatory sandboxes, and testing in real world conditions referred to in Articles 57, 59 and 60;\n(e)\nat the request of the Commission or on its own initiative, issue recommendations and written opinions on any relevant matters related to the implementation of this Regulation and to its consistent and effective application, including:\n(i)\non the development and application of codes of conduct and codes of practice pursuant to this Regulation, as well as of the Commission’s guidelines;\n(ii)\nthe evaluation and review of this Regulation pursuant to Article 112, including as regards the serious incident reports referred to in Article 73, and the functioning of the EU database referred to in Article 71, the preparation of the delegated or implementing acts, and as regards possible alignments of this Regulation with the Union harmonisation legislation listed in Annex I;\n(iii)\non technical specifications or existing standards regarding the requirements set out in Chapter III, Section 2;\n(iv)\non the use of harmonised standards or common specifications referred to in Articles 40 and 41;\n(v)\ntrends, such as European global competitiveness in AI, the uptake of AI in the Union, and the development of digital skills;\n(vi)\ntrends on the evolving typology of AI value chains, in particular on the resulting implications in terms of accountability;\n(vii)\non the potential need for amendment to Annex III in accordance with Article 7, and on the potential need for possible revision of Article 5 pursuant to Article 112, taking into account relevant available evidence and the latest developments in technology;\n(f)\nsupport the Commission in promoting AI literacy, public awareness and understanding of the benefits, risks, safeguards and rights and obligations in relation to the use of AI systems;\n(g)\nfacilitate the development of common criteria and a shared understanding among market operators and competent authorities of the relevant concepts provided for in this Regulation, including by contributing to the development of benchmarks;\n(h)\ncooperate, as appropriate, with other Union institutions, bodies, offices and agencies, as well as relevant Union expert groups and networks, in particular in the fields of product safety, cybersecurity, competition, digital and media services, financial services, consumer protection, data and fundamental rights protection;\n(i)\ncontribute to effective cooperation with the competent authorities of third countries and with international organisations;\n(j)\nassist national competent authorities and the Commission in developing the organisational and technical expertise required for the implementation of this Regulation, including by contributing to the assessment of training needs for staff of Member States involved in implementing this Regulation;\n(k)\nassist the AI Office in supporting national competent authorities in the establishment and development of AI regulatory sandboxes, and facilitate cooperation and information-sharing among AI regulatory sandboxes;\n(l)\ncontribute to, and provide relevant advice on, the development of guidance documents;\n(m)\nadvise the Commission in relation to international matters on AI;\n(n)\nprovide opinions to the Commission on the qualified alerts regarding general-purpose AI models;\n(o)\nreceive opinions by the Member States on qualified alerts regarding general-purpose AI models, and on national experiences and practices on the monitoring and enforcement of AI systems, in particular systems integrating the general-purpose AI models.\nArticle 67 Advisory forum An advisory forum shall be established to provide technical expertise and advise the Board and the Commission, and to contribute to their tasks under this Regulation.\nThe membership of the advisory forum shall represent a balanced selection of stakeholders, including industry, start-ups, SMEs, civil society and academia. The membership of the advisory forum shall be balanced with regard to commercial and non-commercial interests and, within the category of commercial interests, with regard to SMEs and other undertakings.\nThe Commission shall appoint the members of the advisory forum, in accordance with the criteria set out in paragraph 2, from amongst stakeholders with recognised expertise in the field of AI.\nThe term of office of the members of the advisory forum shall be two years, which may be extended by up to no more than four years.\nThe Fundamental Rights Agency, ENISA, the European Committee for Standardization (CEN), the European Committee for Electrotechnical Standardization (CENELEC), and the European Telecommunications Standards Institute (ETSI) shall be permanent members of the advisory forum.\nThe advisory forum shall draw up its rules of procedure. It shall elect two co-chairs from among its members, in accordance with criteria set out in paragraph 2. The term of office of the co-chairs shall be two years, renewable once.\nThe advisory forum shall hold meetings at least twice a year. The advisory forum may invite experts and other stakeholders to its meetings.\nThe advisory forum may prepare opinions, recommendations and written contributions at the request of the Board or the Commission.\nThe advisory forum may establish standing or temporary sub-groups as appropriate for the purpose of examining specific questions related to the objectives of this Regulation.\nThe advisory forum shall prepare an annual report on its activities. That report shall be made publicly available.\nArticle 68 Scientific panel of independent experts The Commission shall, by means of an implementing act, make provisions on the establishment of a scientific panel of independent experts (the ‘scientific panel’) intended to support the enforcement activities under this Regulation. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nThe scientific panel shall consist of experts selected by the Commission on the basis of up-to-date scientific or technical expertise in the field of AI necessary for the tasks set out in paragraph 3, and shall be able to demonstrate meeting all of the following conditions:\n(a)\nhaving particular expertise and competence and scientific or technical expertise in the field of AI;\n(b)\nindependence from any provider of AI systems or general-purpose AI models;\n(c)\nan ability to carry out activities diligently, accurately and objectively.\nThe Commission, in consultation with the Board, shall determine the number of experts on the panel in accordance with the required needs and shall ensure fair gender and geographical representation.\nThe scientific panel shall advise and support the AI Office, in particular with regard to the following tasks: (a)\nsupporting the implementation and enforcement of this Regulation as regards general-purpose AI models and systems, in particular by:\n(i)\nalerting the AI Office of possible systemic risks at Union level of general-purpose AI models, in accordance with Article 90;\n(ii)\ncontributing to the development of tools and methodologies for evaluating capabilities of general-purpose AI models and systems, including through benchmarks;\n(iii)\nproviding advice on the classification of general-purpose AI models with systemic risk;\n(iv)\nproviding advice on the classification of various general-purpose AI models and systems;\n(v)\ncontributing to the development of tools and templates;\n(b)\nsupporting the work of market surveillance authorities, at their request;\n(c)\nsupporting cross-border market surveillance activities as referred to in Article 74(11), without prejudice to the powers of market surveillance authorities;\n(d)\nsupporting the AI Office in carrying out its duties in the context of the Union safeguard procedure pursuant to Article 81.\nThe experts on the scientific panel shall perform their tasks with impartiality and objectivity, and shall ensure the confidentiality of information and data obtained in carrying out their tasks and activities. They shall neither seek nor take instructions from anyone when exercising their tasks under paragraph 3. Each expert shall draw up a declaration of interests, which shall be made publicly available. The AI Office shall establish systems and procedures to actively manage and prevent potential conflicts of interest.\nThe implementing act referred to in paragraph 1 shall include provisions on the conditions, procedures and detailed arrangements for the scientific panel and its members to issue alerts, and to request the assistance of the AI Office for the performance of the tasks of the scientific panel.\nArticle 69 Access to the pool of experts by the Member States Member States may call upon experts of the scientific panel to support their enforcement activities under this Regulation.\nThe Member States may be required to pay fees for the advice and support provided by the experts. The structure and the level of fees as well as the scale and structure of recoverable costs shall be set out in the implementing act referred to in Article 68(1), taking into account the objectives of the adequate implementation of this Regulation, cost-effectiveness and the necessity of ensuring effective access to experts for all Member States.\nThe Commission shall facilitate timely access to the experts by the Member States, as needed, and ensure that the combination of support activities carried out by Union AI testing support pursuant to Article 84 and experts pursuant to this Article is efficiently organised and provides the best possible added value.\nSECTION 2\nNational competent authorities\nArticle 70 Designation of national competent authorities and single points of contact Each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of this Regulation. Those national competent authorities shall exercise their powers independently, impartially and without bias so as to safeguard the objectivity of their activities and tasks, and to ensure the application and implementation of this Regulation. The members of those authorities shall refrain from any action incompatible with their duties. Provided that those principles are observed, such activities and tasks may be performed by one or more designated authorities, in accordance with the organisational needs of the Member State.\nMember States shall communicate to the Commission the identity of the notifying authorities and the market surveillance authorities and the tasks of those authorities, as well as any subsequent changes thereto. Member States shall make publicly available information on how competent authorities and single points of contact can be contacted, through electronic communication means by 2 August 2025. Member States shall designate a market surveillance authority to act as the single point of contact for this Regulation, and shall notify the Commission of the identity of the single point of contact. The Commission shall make a list of the single points of contact publicly available.\nMember States shall ensure that their national competent authorities are provided with adequate technical, financial and human resources, and with infrastructure to fulfil their tasks effectively under this Regulation. In particular, the national competent authorities shall have a sufficient number of personnel permanently available whose competences and expertise shall include an in-depth understanding of AI technologies, data and data computing, personal data protection, cybersecurity, fundamental rights, health and safety risks and knowledge of existing standards and legal requirements. Member States shall assess and, if necessary, update competence and resource requirements referred to in this paragraph on an annual basis.\nNational competent authorities shall take appropriate measures to ensure an adequate level of cybersecurity.\nWhen performing their tasks, the national competent authorities shall act in accordance with the confidentiality obligations set out in Article 78.\nBy 2 August 2025, and once every two years thereafter, Member States shall report to the Commission on the status of the financial and human resources of the national competent authorities, with an assessment of their adequacy. The Commission shall transmit that information to the Board for discussion and possible recommendations.\nThe Commission shall facilitate the exchange of experience between national competent authorities.\nNational competent authorities may provide guidance and advice on the implementation of this Regulation, in particular to SMEs including start-ups, taking into account the guidance and advice of the Board and the Commission, as appropriate. Whenever national competent authorities intend to provide guidance and advice with regard to an AI system in areas covered by other Union law, the national competent authorities under that Union law shall be consulted, as appropriate.\nWhere Union institutions, bodies, offices or agencies fall within the scope of this Regulation, the European Data Protection Supervisor shall act as the competent authority for their supervision.\nCHAPTER VIII EU DATABASE FOR HIGH-RISK AI SYSTEMS\nArticle 71 EU database for high-risk AI systems listed in Annex III The Commission shall, in collaboration with the Member States, set up and maintain an EU database containing information referred to in paragraphs 2 and 3 of this Article concerning high-risk AI systems referred to in Article 6(2) which are registered in accordance with Articles 49 and 60 and AI systems that are not considered as high-risk pursuant to Article 6(3) and which are registered in accordance with Article 6(4) and Article 49. When setting the functional specifications of such database, the Commission shall consult the relevant experts, and when updating the functional specifications of such database, the Commission shall consult the Board.\nThe data listed in Sections A and B of Annex VIII shall be entered into the EU database by the provider or, where applicable, by the authorised representative.\nThe data listed in Section C of Annex VIII shall be entered into the EU database by the deployer who is, or who acts on behalf of, a public authority, agency or body, in accordance with Article 49(3) and (4).\nWith the exception of the section referred to in Article 49(4) and Article 60(4), point (c), the information contained in the EU database registered in accordance with Article 49 shall be accessible and publicly available in a user-friendly manner. The information should be easily navigable and machine-readable. The information registered in accordance with Article 60 shall be accessible only to market surveillance authorities and the Commission, unless the prospective provider or provider has given consent for also making the information accessible the public.\nThe EU database shall contain personal data only in so far as necessary for collecting and processing information in accordance with this Regulation. That information shall include the names and contact details of natural persons who are responsible for registering the system and have the legal authority to represent the provider or the deployer, as applicable.\nThe Commission shall be the controller of the EU database. It shall make available to providers, prospective providers and deployers adequate technical and administrative support. The EU database shall comply with the applicable accessibility requirements.\nCHAPTER IX POST-MARKET MONITORING, INFORMATION SHARING AND MARKET SURVEILLANCE\nSECTION 1\nPost-market monitoring\nArticle 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems\nProviders shall establish and document a post-market monitoring system in a manner that is proportionate to the nature of the AI technologies and the risks of the high-risk AI system.\nThe post-market monitoring system shall actively and systematically collect, document and analyse relevant data which may be provided by deployers or which may be collected through other sources on the performance of high-risk AI systems throughout their lifetime, and which allow the provider to evaluate the continuous compliance of AI systems with the requirements set out in Chapter III, Section 2. Where relevant, post-market monitoring shall include an analysis of the interaction with other AI systems. This obligation shall not cover sensitive operational data of deployers which are law-enforcement authorities.\nThe post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission shall adopt an implementing act laying down detailed provisions establishing a template for the post-market monitoring plan and the list of elements to be included in the plan by 2 February 2026. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nFor high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, where a post-market monitoring system and plan are already established under that legislation, in order to ensure consistency, avoid duplications and minimise additional burdens, providers shall have a choice of integrating, as appropriate, the necessary elements described in paragraphs 1, 2 and 3 using the template referred in paragraph 3 into systems and plans already existing under that legislation, provided that it achieves an equivalent level of protection.\nThe first subparagraph of this paragraph shall also apply to high-risk AI systems referred to in point 5 of Annex III placed on the market or put into service by financial institutions that are subject to requirements under Union financial services law regarding their internal governance, arrangements or processes.\nSECTION 2\nSharing of information on serious incidents\nArticle 73 Reporting of serious incidents Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States where that incident occurred.\nThe report referred to in paragraph 1 shall be made immediately after the provider has established a causal link between the AI system and the serious incident or the reasonable likelihood of such a link, and, in any event, not later than 15 days after the provider or, where applicable, the deployer, becomes aware of the serious incident.\nThe period for the reporting referred to in the first subparagraph shall take account of the severity of the serious incident.\nNotwithstanding paragraph 2 of this Article, in the event of a widespread infringement or a serious incident as defined in Article 3, point (49)(b), the report referred to in paragraph 1 of this Article shall be provided immediately, and not later than two days after the provider or, where applicable, the deployer becomes aware of that incident.\nNotwithstanding paragraph 2, in the event of the death of a person, the report shall be provided immediately after the provider or the deployer has established, or as soon as it suspects, a causal relationship between the high-risk AI system and the serious incident, but not later than 10 days after the date on which the provider or, where applicable, the deployer becomes aware of the serious incident.\nWhere necessary to ensure timely reporting, the provider or, where applicable, the deployer, may submit an initial report that is incomplete, followed by a complete report.\nFollowing the reporting of a serious incident pursuant to paragraph 1, the provider shall, without delay, perform the necessary investigations in relation to the serious incident and the AI system concerned. This shall include a risk assessment of the incident, and corrective action.\nThe provider shall cooperate with the competent authorities, and where relevant with the notified body concerned, during the investigations referred to in the first subparagraph, and shall not perform any investigation which involves altering the AI system concerned in a way which may affect any subsequent evaluation of the causes of the incident, prior to informing the competent authorities of such action.\nUpon receiving a notification related to a serious incident referred to in Article 3, point (49)(c), the relevant market surveillance authority shall inform the national public authorities or bodies referred to in Article 77(1). The Commission shall develop dedicated guidance to facilitate compliance with the obligations set out in paragraph 1 of this Article. That guidance shall be issued by 2 August 2025, and shall be assessed regularly.\nThe market surveillance authority shall take appropriate measures, as provided for in Article 19 of Regulation (EU) 2019/1020, within seven days from the date it received the notification referred to in paragraph 1 of this Article, and shall follow the notification procedures as provided in that Regulation.\nFor high-risk AI systems referred to in Annex III that are placed on the market or put into service by providers that are subject to Union legislative instruments laying down reporting obligations equivalent to those set out in this Regulation, the notification of serious incidents shall be limited to those referred to in Article 3, point (49)(c).\nFor high-risk AI systems which are safety components of devices, or are themselves devices, covered by Regulations (EU) 2017/745 and (EU) 2017/746, the notification of serious incidents shall be limited to those referred to in Article 3, point (49)(c) of this Regulation, and shall be made to the national competent authority chosen for that purpose by the Member States where the incident occurred.\nNational competent authorities shall immediately notify the Commission of any serious incident, whether or not they have taken action on it, in accordance with Article 20 of Regulation (EU) 2019/1020.\nSECTION 3\nEnforcement\nArticle 74 Market surveillance and control of AI systems in the Union market Regulation (EU) 2019/1020 shall apply to AI systems covered by this Regulation. For the purposes of the effective enforcement of this Regulation: (a)\nany reference to an economic operator under Regulation (EU) 2019/1020 shall be understood as including all operators identified in Article 2(1) of this Regulation;\n(b)\nany reference to a product under Regulation (EU) 2019/1020 shall be understood as including all AI systems falling within the scope of this Regulation.\nAs part of their reporting obligations under Article 34(4) of Regulation (EU) 2019/1020, the market surveillance authorities shall report annually to the Commission and relevant national competition authorities any information identified in the course of market surveillance activities that may be of potential interest for the application of Union law on competition rules. They shall also annually report to the Commission about the use of prohibited practices that occurred during that year and about the measures taken.\nFor high-risk AI systems related to products covered by the Union harmonisation legislation listed in Section A of Annex I, the market surveillance authority for the purposes of this Regulation shall be the authority responsible for market surveillance activities designated under those legal acts.\nBy derogation from the first subparagraph, and in appropriate circumstances, Member States may designate another relevant authority to act as a market surveillance authority, provided they ensure coordination with the relevant sectoral market surveillance authorities responsible for the enforcement of the Union harmonisation legislation listed in Annex I.\nThe procedures referred to in Articles 79 to 83 of this Regulation shall not apply to AI systems related to products covered by the Union harmonisation legislation listed in section A of Annex I, where such legal acts already provide for procedures ensuring an equivalent level of protection and having the same objective. In such cases, the relevant sectoral procedures shall apply instead.\nWithout prejudice to the powers of market surveillance authorities under Article 14 of Regulation (EU) 2019/1020, for the purpose of ensuring the effective enforcement of this Regulation, market surveillance authorities may exercise the powers referred to in Article 14(4), points (d) and (j), of that Regulation remotely, as appropriate.\nFor high-risk AI systems placed on the market, put into service, or used by financial institutions regulated by Union financial services law, the market surveillance authority for the purposes of this Regulation shall be the relevant national authority responsible for the financial supervision of those institutions under that legislation in so far as the placing on the market, putting into service, or the use of the AI system is in direct connection with the provision of those financial services.\nBy way of derogation from paragraph 6, in appropriate circumstances, and provided that coordination is ensured, another relevant authority may be identified by the Member State as market surveillance authority for the purposes of this Regulation.\nNational market surveillance authorities supervising regulated credit institutions regulated under Directive 2013/36/EU, which are participating in the Single Supervisory Mechanism established by Regulation (EU) No 1024/2013, should report, without delay, to the European Central Bank any information identified in the course of their market surveillance activities that may be of potential interest for the prudential supervisory tasks of the European Central Bank specified in that Regulation.\nFor high-risk AI systems listed in point 1 of Annex III to this Regulation, in so far as the systems are used for law enforcement purposes, border management and justice and democracy, and for high-risk AI systems listed in points 6, 7 and 8 of Annex III to this Regulation, Member States shall designate as market surveillance authorities for the purposes of this Regulation either the competent data protection supervisory authorities under Regulation (EU) 2016/679 or Directive (EU) 2016/680, or any other authority designated pursuant to the same conditions laid down in Articles 41 to 44 of Directive (EU) 2016/680. Market surveillance activities shall in no way affect the independence of judicial authorities, or otherwise interfere with their activities when acting in their judicial capacity.\nWhere Union institutions, bodies, offices or agencies fall within the scope of this Regulation, the European Data Protection Supervisor shall act as their market surveillance authority, except in relation to the Court of Justice of the European Union acting in its judicial capacity.\nMember States shall facilitate coordination between market surveillance authorities designated under this Regulation and other relevant national authorities or bodies which supervise the application of Union harmonisation legislation listed in Annex I, or in other Union law, that might be relevant for the high-risk AI systems referred to in Annex III.\nMarket surveillance authorities and the Commission shall be able to propose joint activities, including joint investigations, to be conducted by either market surveillance authorities or market surveillance authorities jointly with the Commission, that have the aim of promoting compliance, identifying non-compliance, raising awareness or providing guidance in relation to this Regulation with respect to specific categories of high-risk AI systems that are found to present a serious risk across two or more Member States in accordance with Article 9 of Regulation (EU) 2019/1020. The AI Office shall provide coordination support for joint investigations.\nWithout prejudice to the powers provided for under Regulation (EU) 2019/1020, and where relevant and limited to what is necessary to fulfil their tasks, the market surveillance authorities shall be granted full access by providers to the documentation as well as the training, validation and testing data sets used for the development of high-risk AI systems, including, where appropriate and subject to security safeguards, through application programming interfaces (API) or other relevant technical means and tools enabling remote access.\nMarket surveillance authorities shall be granted access to the source code of the high-risk AI system upon a reasoned request and only when both of the following conditions are fulfilled:\n(a)\naccess to source code is necessary to assess the conformity of a high-risk AI system with the requirements set out in Chapter III, Section 2; and\n(b)\ntesting or auditing procedures and verifications based on the data and documentation provided by the provider have been exhausted or proved insufficient.\nAny information or documentation obtained by market surveillance authorities shall be treated in accordance with the confidentiality obligations set out in Article 78. Article 75 Mutual assistance, market surveillance and control of general-purpose AI systems Where an AI system is based on a general-purpose AI model, and the model and the system are developed by the same provider, the AI Office shall have powers to monitor and supervise compliance of that AI system with obligations under this Regulation. To carry out its monitoring and supervision tasks, the AI Office shall have all the powers of a market surveillance authority provided for in this Section and Regulation (EU) 2019/1020.\nWhere the relevant market surveillance authorities have sufficient reason to consider general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk pursuant to this Regulation to be non-compliant with the requirements laid down in this Regulation, they shall cooperate with the AI Office to carry out compliance evaluations, and shall inform the Board and other market surveillance authorities accordingly.\nWhere a market surveillance authority is unable to conclude its investigation of the high-risk AI system because of its inability to access certain information related to the general-purpose AI model despite having made all appropriate efforts to obtain that information, it may submit a reasoned request to the AI Office, by which access to that information shall be enforced. In that case, the AI Office shall supply to the applicant authority without delay, and in any event within 30 days, any information that the AI Office considers to be relevant in order to establish whether a high-risk AI system is non-compliant. Market surveillance authorities shall safeguard the confidentiality of the information that they obtain in accordance with Article 78 of this Regulation. The procedure provided for in Chapter VI of Regulation (EU) 2019/1020 shall apply mutatis mutandis.\nArticle 76 Supervision of testing in real world conditions by market surveillance authorities Market surveillance authorities shall have competences and powers to ensure that testing in real world conditions is in accordance with this Regulation.\nWhere testing in real world conditions is conducted for AI systems that are supervised within an AI regulatory sandbox under Article 58, the market surveillance authorities shall verify the compliance with Article 60 as part of their supervisory role for the AI regulatory sandbox. Those authorities may, as appropriate, allow the testing in real world conditions to be conducted by the provider or prospective provider, in derogation from the conditions set out in Article 60(4), points (f) and (g).\nWhere a market surveillance authority has been informed by the prospective provider, the provider or any third party of a serious incident or has other grounds for considering that the conditions set out in Articles 60 and 61 are not met, it may take either of the following decisions on its territory, as appropriate:\n(a)\nto suspend or terminate the testing in real world conditions;\n(b)\nto require the provider or prospective provider and the deployer or prospective deployer to modify any aspect of the testing in real world conditions.\nWhere a market surveillance authority has taken a decision referred to in paragraph 3 of this Article, or has issued an objection within the meaning of Article 60(4), point (b), the decision or the objection shall indicate the grounds therefor and how the provider or prospective provider can challenge the decision or objection.\nWhere applicable, where a market surveillance authority has taken a decision referred to in paragraph 3, it shall communicate the grounds therefor to the market surveillance authorities of other Member States in which the AI system has been tested in accordance with the testing plan.\nArticle 77 Powers of authorities protecting fundamental rights National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, in relation to the use of high-risk AI systems referred to in Annex III shall have the power to request and access any documentation created or maintained under this Regulation in accessible language and format when access to that documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction. The relevant public authority or body shall inform the market surveillance authority of the Member State concerned of any such request.\nBy 2 November 2024, each Member State shall identify the public authorities or bodies referred to in paragraph 1 and make a list of them publicly available. Member States shall notify the list to the Commission and to the other Member States, and shall keep the list up to date.\nWhere the documentation referred to in paragraph 1 is insufficient to ascertain whether an infringement of obligations under Union law protecting fundamental rights has occurred, the public authority or body referred to in paragraph 1 may make a reasoned request to the market surveillance authority, to organise testing of the high-risk AI system through technical means. The market surveillance authority shall organise the testing with the close involvement of the requesting public authority or body within a reasonable time following the request.\nAny information or documentation obtained by the national public authorities or bodies referred to in paragraph 1 of this Article pursuant to this Article shall be treated in accordance with the confidentiality obligations set out in Article 78.\nArticle 78 Confidentiality The Commission, market surveillance authorities and notified bodies and any other natural or legal person involved in the application of this Regulation shall, in accordance with Union or national law, respect the confidentiality of information and data obtained in carrying out their tasks and activities in such a manner as to protect, in particular: (a)\nthe intellectual property rights and confidential business information or trade secrets of a natural or legal person, including source code, except in the cases referred to in Article 5 of Directive (EU) 2016/943 of the European Parliament and of the Council (57);\n(b)\nthe effective implementation of this Regulation, in particular for the purposes of inspections, investigations or audits;\n(c)\npublic and national security interests;\n(d)\nthe conduct of criminal or administrative proceedings;\n(e)\ninformation classified pursuant to Union or national law.\nThe authorities involved in the application of this Regulation pursuant to paragraph 1 shall request only data that is strictly necessary for the assessment of the risk posed by AI systems and for the exercise of their powers in accordance with this Regulation and with Regulation (EU) 2019/1020. They shall put in place adequate and effective cybersecurity measures to protect the security and confidentiality of the information and data obtained, and shall delete the data collected as soon as it is no longer needed for the purpose for which it was obtained, in accordance with applicable Union or national law.\nWithout prejudice to paragraphs 1 and 2, information exchanged on a confidential basis between the national competent authorities or between national competent authorities and the Commission shall not be disclosed without prior consultation of the originating national competent authority and the deployer when high-risk AI systems referred to in point 1, 6 or 7 of Annex III are used by law enforcement, border control, immigration or asylum authorities and when such disclosure would jeopardise public and national security interests. This exchange of information shall not cover sensitive operational data in relation to the activities of law enforcement, border control, immigration or asylum authorities.\nWhen the law enforcement, immigration or asylum authorities are providers of high-risk AI systems referred to in point 1, 6 or 7 of Annex III, the technical documentation referred to in Annex IV shall remain within the premises of those authorities. Those authorities shall ensure that the market surveillance authorities referred to in Article 74(8) and (9), as applicable, can, upon request, immediately access the documentation or obtain a copy thereof. Only staff of the market surveillance authority holding the appropriate level of security clearance shall be allowed to access that documentation or any copy thereof.\nParagraphs 1, 2 and 3 shall not affect the rights or obligations of the Commission, Member States and their relevant authorities, as well as those of notified bodies, with regard to the exchange of information and the dissemination of warnings, including in the context of cross-border cooperation, nor shall they affect the obligations of the parties concerned to provide information under criminal law of the Member States.\nThe Commission and Member States may exchange, where necessary and in accordance with relevant provisions of international and trade agreements, confidential information with regulatory authorities of third countries with which they have concluded bilateral or multilateral confidentiality arrangements guaranteeing an adequate level of confidentiality.\nArticle 79 Procedure at national level for dealing with AI systems presenting a risk AI systems presenting a risk shall be understood as a ‘product presenting a risk’ as defined in Article 3, point 19 of Regulation (EU) 2019/1020, in so far as they present risks to the health or safety, or to fundamental rights, of persons.\nWhere the market surveillance authority of a Member State has sufficient reason to consider an AI system to present a risk as referred to in paragraph 1 of this Article, it shall carry out an evaluation of the AI system concerned in respect of its compliance with all the requirements and obligations laid down in this Regulation. Particular attention shall be given to AI systems presenting a risk to vulnerable groups. Where risks to fundamental rights are identified, the market surveillance authority shall also inform and fully cooperate with the relevant national public authorities or bodies referred to in Article 77(1). The relevant operators shall cooperate as necessary with the market surveillance authority and with the other national public authorities or bodies referred to in Article 77(1).\nWhere, in the course of that evaluation, the market surveillance authority or, where applicable the market surveillance authority in cooperation with the national public authority referred to in Article 77(1), finds that the AI system does not comply with the requirements and obligations laid down in this Regulation, it shall without undue delay require the relevant operator to take all appropriate corrective actions to bring the AI system into compliance, to withdraw the AI system from the market, or to recall it within a period the market surveillance authority may prescribe, and in any event within the shorter of 15 working days, or as provided for in the relevant Union harmonisation legislation.\nThe market surveillance authority shall inform the relevant notified body accordingly. Article 18 of Regulation (EU) 2019/1020 shall apply to the measures referred to in the second subparagraph of this paragraph.\nWhere the market surveillance authority considers that the non-compliance is not restricted to its national territory, it shall inform the Commission and the other Member States without undue delay of the results of the evaluation and of the actions which it has required the operator to take.\nThe operator shall ensure that all appropriate corrective action is taken in respect of all the AI systems concerned that it has made available on the Union market.\nWhere the operator of an AI system does not take adequate corrective action within the period referred to in paragraph 2, the market surveillance authority shall take all appropriate provisional measures to prohibit or restrict the AI system’s being made available on its national market or put into service, to withdraw the product or the standalone AI system from that market or to recall it. That authority shall without undue delay notify the Commission and the other Member States of those measures.\nThe notification referred to in paragraph 5 shall include all available details, in particular the information necessary for the identification of the non-compliant AI system, the origin of the AI system and the supply chain, the nature of the non-compliance alleged and the risk involved, the nature and duration of the national measures taken and the arguments put forward by the relevant operator. In particular, the market surveillance authorities shall indicate whether the non-compliance is due to one or more of the following:\n(a)\nnon-compliance with the prohibition of the AI practices referred to in Article 5;\n(b)\na failure of a high-risk AI system to meet requirements set out in Chapter III, Section 2;\n(c)\nshortcomings in the harmonised standards or common specifications referred to in Articles 40 and 41 conferring a presumption of conformity;\n(d)\nnon-compliance with Article 50.\nThe market surveillance authorities other than the market surveillance authority of the Member State initiating the procedure shall, without undue delay, inform the Commission and the other Member States of any measures adopted and of any additional information at their disposal relating to the non-compliance of the AI system concerned, and, in the event of disagreement with the notified national measure, of their objections.\nWhere, within three months of receipt of the notification referred to in paragraph 5 of this Article, no objection has been raised by either a market surveillance authority of a Member State or by the Commission in respect of a provisional measure taken by a market surveillance authority of another Member State, that measure shall be deemed justified. This shall be without prejudice to the procedural rights of the concerned operator in accordance with Article 18 of Regulation (EU) 2019/1020. The three-month period referred to in this paragraph shall be reduced to 30 days in the event of non-compliance with the prohibition of the AI practices referred to in Article 5 of this Regulation.\nThe market surveillance authorities shall ensure that appropriate restrictive measures are taken in respect of the product or the AI system concerned, such as withdrawal of the product or the AI system from their market, without undue delay.\nArticle 80 Procedure for dealing with AI systems classified by the provider as non-high-risk in application of Annex III\nWhere a market surveillance authority has sufficient reason to consider that an AI system classified by the provider as non-high-risk pursuant to Article 6(3) is indeed high-risk, the market surveillance authority shall carry out an evaluation of the AI system concerned in respect of its classification as a high-risk AI system based on the conditions set out in Article 6(3) and the Commission guidelines.\nWhere, in the course of that evaluation, the market surveillance authority finds that the AI system concerned is high-risk, it shall without undue delay require the relevant provider to take all necessary actions to bring the AI system into compliance with the requirements and obligations laid down in this Regulation, as well as take appropriate corrective action within a period the market surveillance authority may prescribe.\nWhere the market surveillance authority considers that the use of the AI system concerned is not restricted to its national territory, it shall inform the Commission and the other Member States without undue delay of the results of the evaluation and of the actions which it has required the provider to take.\nThe provider shall ensure that all necessary action is taken to bring the AI system into compliance with the requirements and obligations laid down in this Regulation. Where the provider of an AI system concerned does not bring the AI system into compliance with those requirements and obligations within the period referred to in paragraph 2 of this Article, the provider shall be subject to fines in accordance with Article 99.\nThe provider shall ensure that all appropriate corrective action is taken in respect of all the AI systems concerned that it has made available on the Union market.\nWhere the provider of the AI system concerned does not take adequate corrective action within the period referred to in paragraph 2 of this Article, Article 79(5) to (9) shall apply.\nWhere, in the course of the evaluation pursuant to paragraph 1 of this Article, the market surveillance authority establishes that the AI system was misclassified by the provider as non-high-risk in order to circumvent the application of requirements in Chapter III, Section 2, the provider shall be subject to fines in accordance with Article 99.\nIn exercising their power to monitor the application of this Article, and in accordance with Article 11 of Regulation (EU) 2019/1020, market surveillance authorities may perform appropriate checks, taking into account in particular information stored in the EU database referred to in Article 71 of this Regulation.\nArticle 81 Union safeguard procedure Where, within three months of receipt of the notification referred to in Article 79(5), or within 30 days in the case of non-compliance with the prohibition of the AI practices referred to in Article 5, objections are raised by the market surveillance authority of a Member State to a measure taken by another market surveillance authority, or where the Commission considers the measure to be contrary to Union law, the Commission shall without undue delay enter into consultation with the market surveillance authority of the relevant Member State and the operator or operators, and shall evaluate the national measure. On the basis of the results of that evaluation, the Commission shall, within six months, or within 60 days in the case of non-compliance with the prohibition of the AI practices referred to in Article 5, starting from the notification referred to in Article 79(5), decide whether the national measure is justified and shall notify its decision to the market surveillance authority of the Member State concerned. The Commission shall also inform all other market surveillance authorities of its decision.\nWhere the Commission considers the measure taken by the relevant Member State to be justified, all Member States shall ensure that they take appropriate restrictive measures in respect of the AI system concerned, such as requiring the withdrawal of the AI system from their market without undue delay, and shall inform the Commission accordingly. Where the Commission considers the national measure to be unjustified, the Member State concerned shall withdraw the measure and shall inform the Commission accordingly.\nWhere the national measure is considered justified and the non-compliance of the AI system is attributed to shortcomings in the harmonised standards or common specifications referred to in Articles 40 and 41 of this Regulation, the Commission shall apply the procedure provided for in Article 11 of Regulation (EU) No 1025/2012.\nArticle 82 Compliant AI systems which present a risk Where, having performed an evaluation under Article 79, after consulting the relevant national public authority referred to in Article 77(1), the market surveillance authority of a Member State finds that although a high-risk AI system complies with this Regulation, it nevertheless presents a risk to the health or safety of persons, to fundamental rights, or to other aspects of public interest protection, it shall require the relevant operator to take all appropriate measures to ensure that the AI system concerned, when placed on the market or put into service, no longer presents that risk without undue delay, within a period it may prescribe.\nThe provider or other relevant operator shall ensure that corrective action is taken in respect of all the AI systems concerned that it has made available on the Union market within the timeline prescribed by the market surveillance authority of the Member State referred to in paragraph 1.\nThe Member States shall immediately inform the Commission and the other Member States of a finding under paragraph 1. That information shall include all available details, in particular the data necessary for the identification of the AI system concerned, the origin and the supply chain of the AI system, the nature of the risk involved and the nature and duration of the national measures taken.\nThe Commission shall without undue delay enter into consultation with the Member States concerned and the relevant operators, and shall evaluate the national measures taken. On the basis of the results of that evaluation, the Commission shall decide whether the measure is justified and, where necessary, propose other appropriate measures.\nThe Commission shall immediately communicate its decision to the Member States concerned and to the relevant operators. It shall also inform the other Member States.\nArticle 83 Formal non-compliance Where the market surveillance authority of a Member State makes one of the following findings, it shall require the relevant provider to put an end to the non-compliance concerned, within a period it may prescribe: (a)\nthe CE marking has been affixed in violation of Article 48;\n(b)\nthe CE marking has not been affixed;\n(c)\nthe EU declaration of conformity referred to in Article 47 has not been drawn up;\n(d)\nthe EU declaration of conformity referred to in Article 47 has not been drawn up correctly;\n(e)\nthe registration in the EU database referred to in Article 71 has not been carried out;\n(f)\nwhere applicable, no authorised representative has been appointed;\n(g)\ntechnical documentation is not available.\nWhere the non-compliance referred to in paragraph 1 persists, the market surveillance authority of the Member State concerned shall take appropriate and proportionate measures to restrict or prohibit the high-risk AI system being made available on the market or to ensure that it is recalled or withdrawn from the market without delay. Article 84 Union AI testing support structures The Commission shall designate one or more Union AI testing support structures to perform the tasks listed under Article 21(6) of Regulation (EU) 2019/1020 in the area of AI.\nWithout prejudice to the tasks referred to in paragraph 1, Union AI testing support structures shall also provide independent technical or scientific advice at the request of the Board, the Commission, or of market surveillance authorities.\nSECTION 4\nRemedies\nArticle 85 Right to lodge a complaint with a market surveillance authority Without prejudice to other administrative or judicial remedies, any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority.\nIn accordance with Regulation (EU) 2019/1020, such complaints shall be taken into account for the purpose of conducting market surveillance activities, and shall be handled in line with the dedicated procedures established therefor by the market surveillance authorities.\nArticle 86 Right to explanation of individual decision-making Any affected person subject to a decision which is taken by the deployer on the basis of the output from a high-risk AI system listed in Annex III, with the exception of systems listed under point 2 thereof, and which produces legal effects or similarly significantly affects that person in a way that they consider to have an adverse impact on their health, safety or fundamental rights shall have the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken.\nParagraph 1 shall not apply to the use of AI systems for which exceptions from, or restrictions to, the obligation under that paragraph follow from Union or national law in compliance with Union law.\nThis Article shall apply only to the extent that the right referred to in paragraph 1 is not otherwise provided for under Union law.\nArticle 87 Reporting of infringements and protection of reporting persons Directive (EU) 2019/1937 shall apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.\nSECTION 5\nSupervision, investigation, enforcement and monitoring in respect of providers of general-purpose AI models\nArticle 88 Enforcement of the obligations of providers of general-purpose AI models The Commission shall have exclusive powers to supervise and enforce Chapter V, taking into account the procedural guarantees under Article 94. The Commission shall entrust the implementation of these tasks to the AI Office, without prejudice to the powers of organisation of the Commission and the division of competences between Member States and the Union based on the Treaties.\nWithout prejudice to Article 75(3), market surveillance authorities may request the Commission to exercise the powers laid down in this Section, where that is necessary and proportionate to assist with the fulfilment of their tasks under this Regulation.\nArticle 89 Monitoring actions For the purpose of carrying out the tasks assigned to it under this Section, the AI Office may take the necessary actions to monitor the effective implementation and compliance with this Regulation by providers of general-purpose AI models, including their adherence to approved codes of practice.\nDownstream providers shall have the right to lodge a complaint alleging an infringement of this Regulation. A complaint shall be duly reasoned and indicate at least:\n(a)\nthe point of contact of the provider of the general-purpose AI model concerned;\n(b)\na description of the relevant facts, the provisions of this Regulation concerned, and the reason why the downstream provider considers that the provider of the general-purpose AI model concerned infringed this Regulation;\n(c)\nany other information that the downstream provider that sent the request considers relevant, including, where appropriate, information gathered on its own initiative.\nArticle 90 Alerts of systemic risks by the scientific panel The scientific panel may provide a qualified alert to the AI Office where it has reason to suspect that: (a)\na general-purpose AI model poses concrete identifiable risk at Union level; or\n(b)\na general-purpose AI model meets the conditions referred to in Article 51.\nUpon such qualified alert, the Commission, through the AI Office and after having informed the Board, may exercise the powers laid down in this Section for the purpose of assessing the matter. The AI Office shall inform the Board of any measure according to Articles 91 to 94.\nA qualified alert shall be duly reasoned and indicate at least:\n(a)\nthe point of contact of the provider of the general-purpose AI model with systemic risk concerned;\n(b)\na description of the relevant facts and the reasons for the alert by the scientific panel;\n(c)\nany other information that the scientific panel considers to be relevant, including, where appropriate, information gathered on its own initiative.\nArticle 91 Power to request documentation and information The Commission may request the provider of the general-purpose AI model concerned to provide the documentation drawn up by the provider in accordance with Articles 53 and 55, or any additional information that is necessary for the purpose of assessing compliance of the provider with this Regulation.\nBefore sending the request for information, the AI Office may initiate a structured dialogue with the provider of the general-purpose AI model.\nUpon a duly substantiated request from the scientific panel, the Commission may issue a request for information to a provider of a general-purpose AI model, where the access to information is necessary and proportionate for the fulfilment of the tasks of the scientific panel under Article 68(2).\nThe request for information shall state the legal basis and the purpose of the request, specify what information is required, set a period within which the information is to be provided, and indicate the fines provided for in Article 101 for supplying incorrect, incomplete or misleading information.\nThe provider of the general-purpose AI model concerned, or its representative shall supply the information requested. In the case of legal persons, companies or firms, or where the provider has no legal personality, the persons authorised to represent them by law or by their statutes, shall supply the information requested on behalf of the provider of the general-purpose AI model concerned. Lawyers duly authorised to act may supply information on behalf of their clients. The clients shall nevertheless remain fully responsible if the information supplied is incomplete, incorrect or misleading.\nArticle 92 Power to conduct evaluations The AI Office, after consulting the Board, may conduct evaluations of the general-purpose AI model concerned: (a)\nto assess compliance of the provider with obligations under this Regulation, where the information gathered pursuant to Article 91 is insufficient; or\n(b)\nto investigate systemic risks at Union level of general-purpose AI models with systemic risk, in particular following a qualified alert from the scientific panel in accordance with Article 90(1), point (a).\nThe Commission may decide to appoint independent experts to carry out evaluations on its behalf, including from the scientific panel established pursuant to Article 68. Independent experts appointed for this task shall meet the criteria outlined in Article 68(2).\nFor the purposes of paragraph 1, the Commission may request access to the general-purpose AI model concerned through APIs or further appropriate technical means and tools, including source code.\nThe request for access shall state the legal basis, the purpose and reasons of the request and set the period within which the access is to be provided, and the fines provided for in Article 101 for failure to provide access.\nThe providers of the general-purpose AI model concerned or its representative shall supply the information requested. In the case of legal persons, companies or firms, or where the provider has no legal personality, the persons authorised to represent them by law or by their statutes, shall provide the access requested on behalf of the provider of the general-purpose AI model concerned.\nThe Commission shall adopt implementing acts setting out the detailed arrangements and the conditions for the evaluations, including the detailed arrangements for involving independent experts, and the procedure for the selection thereof. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nPrior to requesting access to the general-purpose AI model concerned, the AI Office may initiate a structured dialogue with the provider of the general-purpose AI model to gather more information on the internal testing of the model, internal safeguards for preventing systemic risks, and other internal procedures and measures the provider has taken to mitigate such risks.\nArticle 93 Power to request measures Where necessary and appropriate, the Commission may request providers to: (a)\ntake appropriate measures to comply with the obligations set out in Articles 53 and 54;\n(b)\nimplement mitigation measures, where the evaluation carried out in accordance with Article 92 has given rise to serious and substantiated concern of a systemic risk at Union level;\n(c)\nrestrict the making available on the market, withdraw or recall the model.\nBefore a measure is requested, the AI Office may initiate a structured dialogue with the provider of the general-purpose AI model.\nIf, during the structured dialogue referred to in paragraph 2, the provider of the general-purpose AI model with systemic risk offers commitments to implement mitigation measures to address a systemic risk at Union level, the Commission may, by decision, make those commitments binding and declare that there are no further grounds for action.\nArticle 94 Procedural rights of economic operators of the general-purpose AI model Article 18 of Regulation (EU) 2019/1020 shall apply mutatis mutandis to the providers of the general-purpose AI model, without prejudice to more specific procedural rights provided for in this Regulation.\nCHAPTER X CODES OF CONDUCT AND GUIDELINES\nArticle 95 Codes of conduct for voluntary application of specific requirements The AI Office and the Member States shall encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems, other than high-risk AI systems, of some or all of the requirements set out in Chapter III, Section 2 taking into account the available technical solutions and industry best practices allowing for the application of such requirements.\nThe AI Office and the Member States shall facilitate the drawing up of codes of conduct concerning the voluntary application, including by deployers, of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators to measure the achievement of those objectives, including elements such as, but not limited to:\n(a)\napplicable elements provided for in Union ethical guidelines for trustworthy AI;\n(b)\nassessing and minimising the impact of AI systems on environmental sustainability, including as regards energy-efficient programming and techniques for the efficient design, training and use of AI;\n(c)\npromoting AI literacy, in particular that of persons dealing with the development, operation and use of AI;\n(d)\nfacilitating an inclusive and diverse design of AI systems, including through the establishment of inclusive and diverse development teams and the promotion of stakeholders’ participation in that process;\n(e)\nassessing and preventing the negative impact of AI systems on vulnerable persons or groups of vulnerable persons, including as regards accessibility for persons with a disability, as well as on gender equality.\nCodes of conduct may be drawn up by individual providers or deployers of AI systems or by organisations representing them or by both, including with the involvement of any interested stakeholders and their representative organisations, including civil society organisations and academia. Codes of conduct may cover one or more AI systems taking into account the similarity of the intended purpose of the relevant systems.\nThe AI Office and the Member States shall take into account the specific interests and needs of SMEs, including start-ups, when encouraging and facilitating the drawing up of codes of conduct.\nArticle 96 Guidelines from the Commission on the implementation of this Regulation The Commission shall develop guidelines on the practical implementation of this Regulation, and in particular on: (a)\nthe application of the requirements and obligations referred to in Articles 8 to 15 and in Article 25;\n(b)\nthe prohibited practices referred to in Article 5;\n(c)\nthe practical implementation of the provisions related to substantial modification;\n(d)\nthe practical implementation of transparency obligations laid down in Article 50;\n(e)\ndetailed information on the relationship of this Regulation with the Union harmonisation legislation listed in Annex I, as well as with other relevant Union law, including as regards consistency in their enforcement;\n(f)\nthe application of the definition of an AI system as set out in Article 3, point (1).\nWhen issuing such guidelines, the Commission shall pay particular attention to the needs of SMEs including start-ups, of local public authorities and of the sectors most likely to be affected by this Regulation.\nThe guidelines referred to in the first subparagraph of this paragraph shall take due account of the generally acknowledged state of the art on AI, as well as of relevant harmonised standards and common specifications that are referred to in Articles 40 and 41, or of those harmonised standards or technical specifications that are set out pursuant to Union harmonisation law.\nAt the request of the Member States or the AI Office, or on its own initiative, the Commission shall update guidelines previously adopted when deemed necessary. CHAPTER XI DELEGATION OF POWER AND COMMITTEE PROCEDURE\nArticle 97 Exercise of the delegation The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.\nThe power to adopt delegated acts referred to in Article 6(6) and (7), Article 7(1) and (3), Article 11(3), Article 43(5) and (6), Article 47(5), Article 51(3), Article 52(4) and Article 53(5) and (6) shall be conferred on the Commission for a period of five years from 1 August 2024. The Commission shall draw up a report in respect of the delegation of power not later than nine months before the end of the five-year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not later than three months before the end of each period.\nThe delegation of power referred to in Article 6(6) and (7), Article 7(1) and (3), Article 11(3), Article 43(5) and (6), Article 47(5), Article 51(3), Article 52(4) and Article 53(5) and (6) may be revoked at any time by the European Parliament or by the Council. A decision of revocation shall put an end to the delegation of power specified in that decision. It shall take effect the day following that of its publication in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.\nBefore adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making.\nAs soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.\nAny delegated act adopted pursuant to Article 6(6) or (7), Article 7(1) or (3), Article 11(3), Article 43(5) or (6), Article 47(5), Article 51(3), Article 52(4) or Article 53(5) or (6) shall enter into force only if no objection has been expressed by either the European Parliament or the Council within a period of three months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by three months at the initiative of the European Parliament or of the Council.\nArticle 98 Committee procedure The Commission shall be assisted by a committee. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.\nWhere reference is made to this paragraph, Article 5 of Regulation (EU) No 182/2011 shall apply.\nCHAPTER XII PENALTIES\nArticle 99 Penalties In accordance with the terms and conditions laid down in this Regulation, Member States shall lay down the rules on penalties and other enforcement measures, which may also include warnings and non-monetary measures, applicable to infringements of this Regulation by operators, and shall take all measures necessary to ensure that they are properly and effectively implemented, thereby taking into account the guidelines issued by the Commission pursuant to Article 96. The penalties provided for shall be effective, proportionate and dissuasive. They shall take into account the interests of SMEs, including start-ups, and their economic viability.\nThe Member States shall, without delay and at the latest by the date of entry into application, notify the Commission of the rules on penalties and of other enforcement measures referred to in paragraph 1, and shall notify it, without delay, of any subsequent amendment to them.\nNon-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.\nNon-compliance with any of the following provisions related to operators or notified bodies, other than those laid down in Articles 5, shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher:\n(a)\nobligations of providers pursuant to Article 16;\n(b)\nobligations of authorised representatives pursuant to Article 22;\n(c)\nobligations of importers pursuant to Article 23;\n(d)\nobligations of distributors pursuant to Article 24;\n(e)\nobligations of deployers pursuant to Article 26;\n(f)\nrequirements and obligations of notified bodies pursuant to Article 31, Article 33(1), (3) and (4) or Article 34;\n(g)\ntransparency obligations for providers and deployers pursuant to Article 50.\nThe supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request shall be subject to administrative fines of up to EUR 7 500 000 or, if the offender is an undertaking, up to 1 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.\nIn the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.\nWhen deciding whether to impose an administrative fine and when deciding on the amount of the administrative fine in each individual case, all relevant circumstances of the specific situation shall be taken into account and, as appropriate, regard shall be given to the following:\n(a)\nthe nature, gravity and duration of the infringement and of its consequences, taking into account the purpose of the AI system, as well as, where appropriate, the number of affected persons and the level of damage suffered by them;\n(b)\nwhether administrative fines have already been applied by other market surveillance authorities to the same operator for the same infringement;\n(c)\nwhether administrative fines have already been applied by other authorities to the same operator for infringements of other Union or national law, when such infringements result from the same activity or omission constituting a relevant infringement of this Regulation;\n(d)\nthe size, the annual turnover and market share of the operator committing the infringement;\n(e)\nany other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement;\n(f)\nthe degree of cooperation with the national competent authorities, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;\n(g)\nthe degree of responsibility of the operator taking into account the technical and organisational measures implemented by it;\n(h)\nthe manner in which the infringement became known to the national competent authorities, in particular whether, and if so to what extent, the operator notified the infringement;\n(i)\nthe intentional or negligent character of the infringement;\n(j)\nany action taken by the operator to mitigate the harm suffered by the affected persons.\nEach Member State shall lay down rules on to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.\nDepending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fines are imposed by competent national courts or by other bodies, as applicable in those Member States. The application of such rules in those Member States shall have an equivalent effect.\nThe exercise of powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and national law, including effective judicial remedies and due process.\nMember States shall, on an annual basis, report to the Commission about the administrative fines they have issued during that year, in accordance with this Article, and about any related litigation or judicial proceedings.\nArticle 100 Administrative fines on Union institutions, bodies, offices and agencies The European Data Protection Supervisor may impose administrative fines on Union institutions, bodies, offices and agencies falling within the scope of this Regulation. When deciding whether to impose an administrative fine and when deciding on the amount of the administrative fine in each individual case, all relevant circumstances of the specific situation shall be taken into account and due regard shall be given to the following: (a)\nthe nature, gravity and duration of the infringement and of its consequences, taking into account the purpose of the AI system concerned, as well as, where appropriate, the number of affected persons and the level of damage suffered by them;\n(b)\nthe degree of responsibility of the Union institution, body, office or agency, taking into account technical and organisational measures implemented by them;\n(c)\nany action taken by the Union institution, body, office or agency to mitigate the damage suffered by affected persons;\n(d)\nthe degree of cooperation with the European Data Protection Supervisor in order to remedy the infringement and mitigate the possible adverse effects of the infringement, including compliance with any of the measures previously ordered by the European Data Protection Supervisor against the Union institution, body, office or agency concerned with regard to the same subject matter;\n(e)\nany similar previous infringements by the Union institution, body, office or agency;\n(f)\nthe manner in which the infringement became known to the European Data Protection Supervisor, in particular whether, and if so to what extent, the Union institution, body, office or agency notified the infringement;\n(g)\nthe annual budget of the Union institution, body, office or agency.\nNon-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to EUR 1 500 000.\nThe non-compliance of the AI system with any requirements or obligations under this Regulation, other than those laid down in Article 5, shall be subject to administrative fines of up to EUR 750 000.\nBefore taking decisions pursuant to this Article, the European Data Protection Supervisor shall give the Union institution, body, office or agency which is the subject of the proceedings conducted by the European Data Protection Supervisor the opportunity of being heard on the matter regarding the possible infringement. The European Data Protection Supervisor shall base his or her decisions only on elements and circumstances on which the parties concerned have been able to comment. Complainants, if any, shall be associated closely with the proceedings.\nThe rights of defence of the parties concerned shall be fully respected in the proceedings. They shall be entitled to have access to the European Data Protection Supervisor’s file, subject to the legitimate interest of individuals or undertakings in the protection of their personal data or business secrets.\nFunds collected by imposition of fines in this Article shall contribute to the general budget of the Union. The fines shall not affect the effective operation of the Union institution, body, office or agency fined.\nThe European Data Protection Supervisor shall, on an annual basis, notify the Commission of the administrative fines it has imposed pursuant to this Article and of any litigation or judicial proceedings it has initiated.\nArticle 101 Fines for providers of general-purpose AI models The Commission may impose on providers of general-purpose AI models fines not exceeding 3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher., when the Commission finds that the provider intentionally or negligently: (a)\ninfringed the relevant provisions of this Regulation;\n(b)\nfailed to comply with a request for a document or for information pursuant to Article 91, or supplied incorrect, incomplete or misleading information;\n(c)\nfailed to comply with a measure requested under Article 93;\n(d)\nfailed to make available to the Commission access to the general-purpose AI model or general-purpose AI model with systemic risk with a view to conducting an evaluation pursuant to Article 92.\nIn fixing the amount of the fine or periodic penalty payment, regard shall be had to the nature, gravity and duration of the infringement, taking due account of the principles of proportionality and appropriateness. The Commission shall also into account commitments made in accordance with Article 93(3) or made in relevant codes of practice in accordance with Article 56.\nBefore adopting the decision pursuant to paragraph 1, the Commission shall communicate its preliminary findings to the provider of the general-purpose AI model and give it an opportunity to be heard.\nFines imposed in accordance with this Article shall be effective, proportionate and dissuasive.\nInformation on fines imposed under this Article shall also be communicated to the Board as appropriate.\nThe Court of Justice of the European Union shall have unlimited jurisdiction to review decisions of the Commission fixing a fine under this Article. It may cancel, reduce or increase the fine imposed.\nThe Commission shall adopt implementing acts containing detailed arrangements and procedural safeguards for proceedings in view of the possible adoption of decisions pursuant to paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).\nCHAPTER XIII FINAL PROVISIONS\nArticle 102 Amendment to Regulation (EC) No 300/2008 In Article 4(3) of Regulation (EC) No 300/2008, the following subparagraph is added:\n‘When adopting detailed measures related to technical specifications and procedures for approval and use of security equipment concerning Artificial Intelligence systems within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 103 Amendment to Regulation (EU) No 167/2013 In Article 17(5) of Regulation (EU) No 167/2013, the following subparagraph is added:\n‘When adopting delegated acts pursuant to the first subparagraph concerning artificial intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 104 Amendment to Regulation (EU) No 168/2013 In Article 22(5) of Regulation (EU) No 168/2013, the following subparagraph is added:\n‘When adopting delegated acts pursuant to the first subparagraph concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 105 Amendment to Directive 2014/90/EU In Article 8 of Directive 2014/90/EU, the following paragraph is added:\n‘5. For Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), when carrying out its activities pursuant to paragraph 1 and when adopting technical specifications and testing standards in accordance with paragraphs 2 and 3, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation.\nArticle 106 Amendment to Directive (EU) 2016/797 In Article 5 of Directive (EU) 2016/797, the following paragraph is added:\n‘12. When adopting delegated acts pursuant to paragraph 1 and implementing acts pursuant to paragraph 11 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 107 Amendment to Regulation (EU) 2018/858 In Article 5 of Regulation (EU) 2018/858 the following paragraph is added:\n‘4. When adopting delegated acts pursuant to paragraph 3 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 108 Amendments to Regulation (EU) 2018/1139 Regulation (EU) 2018/1139 is amended as follows:\n(1)\nin Article 17, the following paragraph is added:\n‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\n(*) Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (OJ L, 2024/1689, 12.7.2024, ELI: http://data.europa.eu/eli/reg/2024/1689/oj ).’;\u0026quot;\n(2)\nin Article 19, the following paragraph is added:\n‘4. When adopting delegated acts pursuant to paragraphs 1 and 2 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’\n;\n(3)\nin Article 43, the following paragraph is added:\n‘4. When adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’\n;\n(4)\nin Article 47, the following paragraph is added:\n‘3. When adopting delegated acts pursuant to paragraphs 1 and 2 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’\n;\n(5)\nin Article 57, the following subparagraph is added:\n‘When adopting those implementing acts concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’\n;\n(6)\nin Article 58, the following paragraph is added:\n‘3. When adopting delegated acts pursuant to paragraphs 1 and 2 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’.\nArticle 109 Amendment to Regulation (EU) 2019/2144 In Article 11 of Regulation (EU) 2019/2144, the following paragraph is added:\n‘3. When adopting the implementing acts pursuant to paragraph 2, concerning artificial intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.\nArticle 110 Amendment to Directive (EU) 2020/1828 In Annex I to Directive (EU) 2020/1828 of the European Parliament and of the Council (58), the following point is added:\n‘(68)\nRegulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (OJ L, 2024/1689, 12.7.2024, ELI: http://data.europa.eu/eli/reg/2024/1689/oj ).’.\nArticle 111 AI systems already placed on the market or put into service and general-purpose AI models already placed on the marked\nWithout prejudice to the application of Article 5 as referred to in Article 113(3), point (a), AI systems which are components of the large-scale IT systems established by the legal acts listed in Annex X that have been placed on the market or put into service before 2 August 2027 shall be brought into compliance with this Regulation by 31 December 2030. The requirements laid down in this Regulation shall be taken into account in the evaluation of each large-scale IT system established by the legal acts listed in Annex X to be undertaken as provided for in those legal acts and where those legal acts are replaced or amended.\nWithout prejudice to the application of Article 5 as referred to in Article 113(3), point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before 2 August 2026, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations of this Regulation by 2 August 2030.\nProviders of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in this Regulation by 2 August 2027.\nArticle 112 Evaluation and review The Commission shall assess the need for amendment of the list set out in Annex III and of the list of prohibited AI practices laid down in Article 5, once a year following the entry into force of this Regulation, and until the end of the period of the delegation of power laid down in Article 97. The Commission shall submit the findings of that assessment to the European Parliament and the Council.\nBy 2 August 2028 and every four years thereafter, the Commission shall evaluate and report to the European Parliament and to the Council on the following:\n(a)\nthe need for amendments extending existing area headings or adding new area headings in Annex III;\n(b)\namendments to the list of AI systems requiring additional transparency measures in Article 50;\n(c)\namendments enhancing the effectiveness of the supervision and governance system.\nBy 2 August 2029 and every four years thereafter, the Commission shall submit a report on the evaluation and review of this Regulation to the European Parliament and to the Council. The report shall include an assessment with regard to the structure of enforcement and the possible need for a Union agency to resolve any identified shortcomings. On the basis of the findings, that report shall, where appropriate, be accompanied by a proposal for amendment of this Regulation. The reports shall be made public.\nThe reports referred to in paragraph 2 shall pay specific attention to the following:\n(a)\nthe status of the financial, technical and human resources of the national competent authorities in order to effectively perform the tasks assigned to them under this Regulation;\n(b)\nthe state of penalties, in particular administrative fines as referred to in Article 99(1), applied by Member States for infringements of this Regulation;\n(c)\nadopted harmonised standards and common specifications developed to support this Regulation;\n(d)\nthe number of undertakings that enter the market after the entry into application of this Regulation, and how many of them are SMEs.\nBy 2 August 2028, the Commission shall evaluate the functioning of the AI Office, whether the AI Office has been given sufficient powers and competences to fulfil its tasks, and whether it would be relevant and needed for the proper implementation and enforcement of this Regulation to upgrade the AI Office and its enforcement competences and to increase its resources. The Commission shall submit a report on its evaluation to the European Parliament and to the Council.\nBy 2 August 2028 and every four years thereafter, the Commission shall submit a report on the review of the progress on the development of standardisation deliverables on the energy-efficient development of general-purpose AI models, and asses the need for further measures or actions, including binding measures or actions. The report shall be submitted to the European Parliament and to the Council, and it shall be made public.\nBy 2 August 2028 and every three years thereafter, the Commission shall evaluate the impact and effectiveness of voluntary codes of conduct to foster the application of the requirements set out in Chapter III, Section 2 for AI systems other than high-risk AI systems and possibly other additional requirements for AI systems other than high-risk AI systems, including as regards environmental sustainability.\nFor the purposes of paragraphs 1 to 7, the Board, the Member States and national competent authorities shall provide the Commission with information upon its request and without undue delay.\nIn carrying out the evaluations and reviews referred to in paragraphs 1 to 7, the Commission shall take into account the positions and findings of the Board, of the European Parliament, of the Council, and of other relevant bodies or sources.\nThe Commission shall, if necessary, submit appropriate proposals to amend this Regulation, in particular taking into account developments in technology, the effect of AI systems on health and safety, and on fundamental rights, and in light of the state of progress in the information society.\nTo guide the evaluations and reviews referred to in paragraphs 1 to 7 of this Article, the AI Office shall undertake to develop an objective and participative methodology for the evaluation of risk levels based on the criteria outlined in the relevant Articles and the inclusion of new systems in:\n(a)\nthe list set out in Annex III, including the extension of existing area headings or the addition of new area headings in that Annex;\n(b)\nthe list of prohibited practices set out in Article 5; and\n(c)\nthe list of AI systems requiring additional transparency measures pursuant to Article 50.\nAny amendment to this Regulation pursuant to paragraph 10, or relevant delegated or implementing acts, which concerns sectoral Union harmonisation legislation listed in Section B of Annex I shall take into account the regulatory specificities of each sector, and the existing governance, conformity assessment and enforcement mechanisms and authorities established therein.\nBy 2 August 2031, the Commission shall carry out an assessment of the enforcement of this Regulation and shall report on it to the European Parliament, the Council and the European Economic and Social Committee, taking into account the first years of application of this Regulation. On the basis of the findings, that report shall, where appropriate, be accompanied by a proposal for amendment of this Regulation with regard to the structure of enforcement and the need for a Union agency to resolve any identified shortcomings.\nArticle 113 Entry into force and application This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.\nIt shall apply from 2 August 2026.\nHowever:\n(a)\nChapters I and II shall apply from 2 February 2025;\n(b)\nChapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101;\n(c)\nArticle 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027.\nThis Regulation shall be binding in its entirety and directly applicable in all Member States.\nDone at Brussels, 13 June 2024.\nFor the European Parliament\nThe President\nR. METSOLA\nFor the Council\nThe President\nM. MICHEL\n(1) OJ C 517, 22.12.2021, p. 56.\n(2) OJ C 115, 11.3.2022, p. 5.\n(3) OJ C 97, 28.2.2022, p. 60.\n(4) Position of the European Parliament of 13 March 2024 (not yet published in the Official Journal) and decision of the Council of 21 May 2024.\n(5) European Council, Special meeting of the European Council (1 and 2 October 2020) — Conclusions, EUCO 13/20, 2020, p. 6.\n(6) European Parliament resolution of 20 October 2020 with recommendations to the Commission on a framework of ethical aspects of artificial intelligence, robotics and related technologies, 2020/2012(INL).\n(7) Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 setting out the requirements for accreditation and repealing Regulation (EEC) No 339/93 (OJ L 218, 13.8.2008, p. 30).\n(8) Decision No 768/2008/EC of the European Parliament and of the Council of 9 July 2008 on a common framework for the marketing of products, and repealing Council Decision 93/465/EEC (OJ L 218, 13.8.2008, p. 82).\n(9) Regulation (EU) 2019/1020 of the European Parliament and of the Council of 20 June 2019 on market surveillance and compliance of products and amending Directive 2004/42/EC and Regulations (EC) No 765/2008 and (EU) No 305/2011 (OJ L 169, 25.6.2019, p. 1).\n(10) Council Directive 85/374/EEC of 25 July 1985 on the approximation of the laws, regulations and administrative provisions of the Member States concerning liability for defective products (OJ L 210, 7.8.1985, p. 29).\n(11) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1).\n(12) Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39).\n(13) Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, p. 89).\n(14) Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ L 201, 31.7.2002, p. 37).\n(15) Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) (OJ L 277, 27.10.2022, p. 1).\n(16) Directive (EU) 2019/882 of the European Parliament and of the Council of 17 April 2019 on the accessibility requirements for products and services (OJ L 151, 7.6.2019, p. 70).\n(17) Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consumer commercial practices in the internal market and amending Council Directive 84/450/EEC, Directives 97/7/EC, 98/27/EC and 2002/65/EC of the European Parliament and of the Council and Regulation (EC) No 2006/2004 of the European Parliament and of the Council (‘Unfair Commercial Practices Directive’) (OJ L 149, 11.6.2005, p. 22).\n(18) Council Framework Decision 2002/584/JHA of 13 June 2002 on the European arrest warrant and the surrender procedures between Member States (OJ L 190, 18.7.2002, p. 1).\n(19) Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC (OJ L 333, 27.12.2022, p. 164).\n(20) OJ C 247, 29.6.2022, p. 1.\n(21) Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC (OJ L 117, 5.5.2017, p. 1).\n(22) Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU (OJ L 117, 5.5.2017, p. 176).\n(23) Directive 2006/42/EC of the European Parliament and of the Council of 17 May 2006 on machinery, and amending Directive 95/16/EC (OJ L 157, 9.6.2006, p. 24).\n(24) Regulation (EC) No 300/2008 of the European Parliament and of the Council of 11 March 2008 on common rules in the field of civil aviation security and repealing Regulation (EC) No 2320/2002 (OJ L 97, 9.4.2008, p. 72).\n(25) Regulation (EU) No 167/2013 of the European Parliament and of the Council of 5 February 2013 on the approval and market surveillance of agricultural and forestry vehicles (OJ L 60, 2.3.2013, p. 1).\n(26) Regulation (EU) No 168/2013 of the European Parliament and of the Council of 15 January 2013 on the approval and market surveillance of two- or three-wheel vehicles and quadricycles (OJ L 60, 2.3.2013, p. 52).\n(27) Directive 2014/90/EU of the European Parliament and of the Council of 23 July 2014 on marine equipment and repealing Council Directive 96/98/EC (OJ L 257, 28.8.2014, p. 146).\n(28) Directive (EU) 2016/797 of the European Parliament and of the Council of 11 May 2016 on the interoperability of the rail system within the European Union (OJ L 138, 26.5.2016, p. 44).\n(29) Regulation (EU) 2018/858 of the European Parliament and of the Council of 30 May 2018 on the approval and market surveillance of motor vehicles and their trailers, and of systems, components and separate technical units intended for such vehicles, amending Regulations (EC) No 715/2007 and (EC) No 595/2009 and repealing Directive 2007/46/EC (OJ L 151, 14.6.2018, p. 1).\n(30) Regulation (EU) 2018/1139 of the European Parliament and of the Council of 4 July 2018 on common rules in the field of civil aviation and establishing a European Union Aviation Safety Agency, and amending Regulations (EC) No 2111/2005, (EC) No 1008/2008, (EU) No 996/2010, (EU) No 376/2014 and Directives 2014/30/EU and 2014/53/EU of the European Parliament and of the Council, and repealing Regulations (EC) No 552/2004 and (EC) No 216/2008 of the European Parliament and of the Council and Council Regulation (EEC) No 3922/91 (OJ L 212, 22.8.2018, p. 1).\n(31) Regulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users, amending Regulation (EU) 2018/858 of the European Parliament and of the Council and repealing Regulations (EC) No 78/2009, (EC) No 79/2009 and (EC) No 661/2009 of the European Parliament and of the Council and Commission Regulations (EC) No 631/2009, (EU) No 406/2010, (EU) No 672/2010, (EU) No 1003/2010, (EU) No 1005/2010, (EU) No 1008/2010, (EU) No 1009/2010, (EU) No 19/2011, (EU) No 109/2011, (EU) No 458/2011, (EU) No 65/2012, (EU) No 130/2012, (EU) No 347/2012, (EU) No 351/2012, (EU) No 1230/2012 and (EU) 2015/166 (OJ L 325, 16.12.2019, p. 1).\n(32) Regulation (EC) No 810/2009 of the European Parliament and of the Council of 13 July 2009 establishing a Community Code on Visas (Visa Code) (OJ L 243, 15.9.2009, p. 1).\n(33) Directive 2013/32/EU of the European Parliament and of the Council of 26 June 2013 on common procedures for granting and withdrawing international protection (OJ L 180, 29.6.2013, p. 60).\n(34) Regulation (EU) 2024/900 of the European parliament and of the Council of 13 March 2024 on the transparency and targeting of political advertising (OJ L, 2024/900, 20.3.2024, ELI: http://data.europa.eu/eli/reg/2024/900/oj ).\n(35) Directive 2014/31/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of non-automatic weighing instruments (OJ L 96, 29.3.2014, p. 107).\n(36) Directive 2014/32/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of measuring instruments (OJ L 96, 29.3.2014, p. 149).\n(37) Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ L 151, 7.6.2019, p. 15).\n(38) Directive (EU) 2016/2102 of the European Parliament and of the Council of 26 October 2016 on the accessibility of the websites and mobile applications of public sector bodies (OJ L 327, 2.12.2016, p. 1).\n(39) Directive 2002/14/EC of the European Parliament and of the Council of 11 March 2002 establishing a general framework for informing and consulting employees in the European Community (OJ L 80, 23.3.2002, p. 29).\n(40) Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC (OJ L 130, 17.5.2019, p. 92).\n(41) Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (OJ L 316, 14.11.2012, p. 12).\n(42) Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance and amending Regulation (EU) 2018/1724 (Data Governance Act) (OJ L 152, 3.6.2022, p. 1).\n(43) Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act) (OJ L, 2023/2854, 22.12.2023, ELI: http://data.europa.eu/eli/reg/2023/2854/oj ).\n(44) Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (OJ L 124, 20.5.2003, p. 36).\n(45) Commission Decision of 24.1.2024 establishing the European Artificial Intelligence Office C(2024) 390.\n(46) Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requirements for credit institutions and investment firms and amending Regulation (EU) No 648/2012 (OJ L 176, 27.6.2013, p. 1).\n(47) Directive 2008/48/EC of the European Parliament and of the Council of 23 April 2008 on credit agreements for consumers and repealing Council Directive 87/102/EEC (OJ L 133, 22.5.2008, p. 66).\n(48) Directive 2009/138/EC of the European Parliament and of the Council of 25 November 2009 on the taking-up and pursuit of the business of Insurance and Reinsurance (Solvency II) (OJ L 335, 17.12.2009, p. 1).\n(49) Directive 2013/36/EU of the European Parliament and of the Council of 26 June 2013 on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC (OJ L 176, 27.6.2013, p. 338).\n(50) Directive 2014/17/EU of the European Parliament and of the Council of 4 February 2014 on credit agreements for consumers relating to residential immovable property and amending Directives 2008/48/EC and 2013/36/EU and Regulation (EU) No 1093/2010 (OJ L 60, 28.2.2014, p. 34).\n(51) Directive (EU) 2016/97 of the European Parliament and of the Council of 20 January 2016 on insurance distribution (OJ L 26, 2.2.2016, p. 19).\n(52) Council Regulation (EU) No 1024/2013 of 15 October 2013 conferring specific tasks on the European Central Bank concerning policies relating to the prudential supervision of credit institutions (OJ L 287, 29.10.2013, p. 63).\n(53) Regulation (EU) 2023/988 of the European Parliament and of the Council of 10 May 2023 on general product safety, amending Regulation (EU) No 1025/2012 of the European Parliament and of the Council and Directive (EU) 2020/1828 of the European Parliament and the Council, and repealing Directive 2001/95/EC of the European Parliament and of the Council and Council Directive 87/357/EEC (OJ L 135, 23.5.2023, p. 1).\n(54) Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law (OJ L 305, 26.11.2019, p. 17).\n(55) OJ L 123, 12.5.2016, p. 1.\n(56) Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by Member States of the Commission’s exercise of implementing powers (OJ L 55, 28.2.2011, p. 13).\n(57) Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure (OJ L 157, 15.6.2016, p. 1).\n(58) Directive (EU) 2020/1828 of the European Parliament and of the Council of 25 November 2020 on representative actions for the protection of the collective interests of consumers and repealing Directive 2009/22/EC (OJ L 409, 4.12.2020, p. 1).\nANNEX I List of Union harmonisation legislation\nSection A. List of Union harmonisation legislation based on the New Legislative Framework\nDirective 2006/42/EC of the European Parliament and of the Council of 17 May 2006 on machinery, and amending Directive 95/16/EC (OJ L 157, 9.6.2006, p. 24);\nDirective 2009/48/EC of the European Parliament and of the Council of 18 June 2009 on the safety of toys (OJ L 170, 30.6.2009, p. 1);\nDirective 2013/53/EU of the European Parliament and of the Council of 20 November 2013 on recreational craft and personal watercraft and repealing Directive 94/25/EC (OJ L 354, 28.12.2013, p. 90);\nDirective 2014/33/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to lifts and safety components for lifts (OJ L 96, 29.3.2014, p. 251);\nDirective 2014/34/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to equipment and protective systems intended for use in potentially explosive atmospheres (OJ L 96, 29.3.2014, p. 309);\nDirective 2014/53/EU of the European Parliament and of the Council of 16 April 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment and repealing Directive 1999/5/EC (OJ L 153, 22.5.2014, p. 62);\nDirective 2014/68/EU of the European Parliament and of the Council of 15 May 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of pressure equipment (OJ L 189, 27.6.2014, p. 164);\nRegulation (EU) 2016/424 of the European Parliament and of the Council of 9 March 2016 on cableway installations and repealing Directive 2000/9/EC (OJ L 81, 31.3.2016, p. 1);\nRegulation (EU) 2016/425 of the European Parliament and of the Council of 9 March 2016 on personal protective equipment and repealing Council Directive 89/686/EEC (OJ L 81, 31.3.2016, p. 51);\nRegulation (EU) 2016/426 of the European Parliament and of the Council of 9 March 2016 on appliances burning gaseous fuels and repealing Directive 2009/142/EC (OJ L 81, 31.3.2016, p. 99);\nRegulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC (OJ L 117, 5.5.2017, p. 1);\nRegulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU (OJ L 117, 5.5.2017, p. 176).\nSection B. List of other Union harmonisation legislation\nRegulation (EC) No 300/2008 of the European Parliament and of the Council of 11 March 2008 on common rules in the field of civil aviation security and repealing Regulation (EC) No 2320/2002 (OJ L 97, 9.4.2008, p. 72);\nRegulation (EU) No 168/2013 of the European Parliament and of the Council of 15 January 2013 on the approval and market surveillance of two- or three-wheel vehicles and quadricycles (OJ L 60, 2.3.2013, p. 52);\nRegulation (EU) No 167/2013 of the European Parliament and of the Council of 5 February 2013 on the approval and market surveillance of agricultural and forestry vehicles (OJ L 60, 2.3.2013, p. 1);\nDirective 2014/90/EU of the European Parliament and of the Council of 23 July 2014 on marine equipment and repealing Council Directive 96/98/EC (OJ L 257, 28.8.2014, p. 146);\nDirective (EU) 2016/797 of the European Parliament and of the Council of 11 May 2016 on the interoperability of the rail system within the European Union (OJ L 138, 26.5.2016, p. 44);\nRegulation (EU) 2018/858 of the European Parliament and of the Council of 30 May 2018 on the approval and market surveillance of motor vehicles and their trailers, and of systems, components and separate technical units intended for such vehicles, amending Regulations (EC) No 715/2007 and (EC) No 595/2009 and repealing Directive 2007/46/EC (OJ L 151, 14.6.2018, p. 1);\nRegulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users, amending Regulation (EU) 2018/858 of the European Parliament and of the Council and repealing Regulations (EC) No 78/2009, (EC) No 79/2009 and (EC) No 661/2009 of the European Parliament and of the Council and Commission Regulations (EC) No 631/2009, (EU) No 406/2010, (EU) No 672/2010, (EU) No 1003/2010, (EU) No 1005/2010, (EU) No 1008/2010, (EU) No 1009/2010, (EU) No 19/2011, (EU) No 109/2011, (EU) No 458/2011, (EU) No 65/2012, (EU) No 130/2012, (EU) No 347/2012, (EU) No 351/2012, (EU) No 1230/2012 and (EU) 2015/166 (OJ L 325, 16.12.2019, p. 1);\nRegulation (EU) 2018/1139 of the European Parliament and of the Council of 4 July 2018 on common rules in the field of civil aviation and establishing a European Union Aviation Safety Agency, and amending Regulations (EC) No 2111/2005, (EC) No 1008/2008, (EU) No 996/2010, (EU) No 376/2014 and Directives 2014/30/EU and 2014/53/EU of the European Parliament and of the Council, and repealing Regulations (EC) No 552/2004 and (EC) No 216/2008 of the European Parliament and of the Council and Council Regulation (EEC) No 3922/91 (OJ L 212, 22.8.2018, p. 1), in so far as the design, production and placing on the market of aircrafts referred to in Article 2(1), points (a) and (b) thereof, where it concerns unmanned aircraft and their engines, propellers, parts and equipment to control them remotely, are concerned.\nANNEX II List of criminal offences referred to in Article 5(1), first subparagraph, point (h)(iii)\nCriminal offences referred to in Article 5(1), first subparagraph, point (h)(iii):\n—\nterrorism,\n—\ntrafficking in human beings,\n—\nsexual exploitation of children, and child pornography,\n—\nillicit trafficking in narcotic drugs or psychotropic substances,\n—\nillicit trafficking in weapons, munitions or explosives,\n—\nmurder, grievous bodily injury,\n—\nillicit trade in human organs or tissue,\n—\nillicit trafficking in nuclear or radioactive materials,\n—\nkidnapping, illegal restraint or hostage-taking,\n—\ncrimes within the jurisdiction of the International Criminal Court,\n—\nunlawful seizure of aircraft or ships,\n—\nrape,\n—\nenvironmental crime,\n—\norganised or armed robbery,\n—\nsabotage,\n—\nparticipation in a criminal organisation involved in one or more of the offences listed above.\nANNEX III High-risk AI systems referred to in Article 6(2)\nHigh-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas:\nBiometrics, in so far as their use is permitted under relevant Union or national law: (a)\nremote biometric identification systems.\nThis shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be;\n(b)\nAI systems intended to be used for biometric categorisation, according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics;\n(c)\nAI systems intended to be used for emotion recognition.\nCritical infrastructure: AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.\nEducation and vocational training:\n(a)\nAI systems intended to be used to determine access or admission or to assign natural persons to educational and vocational training institutions at all levels;\n(b)\nAI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions at all levels;\n(c)\nAI systems intended to be used for the purpose of assessing the appropriate level of education that an individual will receive or will be able to access, in the context of or within educational and vocational training institutions at all levels;\n(d)\nAI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests in the context of or within educational and vocational training institutions at all levels.\nEmployment, workers’ management and access to self-employment: (a)\nAI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates;\n(b)\nAI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships.\nAccess to and enjoyment of essential private services and essential public services and benefits: (a)\nAI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services;\n(b)\nAI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud;\n(c)\nAI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance;\n(d)\nAI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems.\nLaw enforcement, in so far as their use is permitted under relevant Union or national law: (a)\nAI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies in support of law enforcement authorities or on their behalf to assess the risk of a natural person becoming the victim of criminal offences;\n(b)\nAI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities as polygraphs or similar tools;\n(c)\nAI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies, in support of law enforcement authorities to evaluate the reliability of evidence in the course of the investigation or prosecution of criminal offences;\n(d)\nAI systems intended to be used by law enforcement authorities or on their behalf or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for assessing the risk of a natural person offending or re-offending not solely on the basis of the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680, or to assess personality traits and characteristics or past criminal behaviour of natural persons or groups;\n(e)\nAI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680 in the course of the detection, investigation or prosecution of criminal offences.\nMigration, asylum and border control management, in so far as their use is permitted under relevant Union or national law: (a)\nAI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies as polygraphs or similar tools;\n(b)\nAI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assess a risk, including a security risk, a risk of irregular migration, or a health risk, posed by a natural person who intends to enter or who has entered into the territory of a Member State;\n(c)\nAI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assist competent public authorities for the examination of applications for asylum, visa or residence permits and for associated complaints with regard to the eligibility of the natural persons applying for a status, including related assessments of the reliability of evidence;\n(d)\nAI systems intended to be used by or on behalf of competent public authorities, or by Union institutions, bodies, offices or agencies, in the context of migration, asylum or border control management, for the purpose of detecting, recognising or identifying natural persons, with the exception of the verification of travel documents.\nAdministration of justice and democratic processes: (a)\nAI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution;\n(b)\nAI systems intended to be used for influencing the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda. This does not include AI systems to the output of which natural persons are not directly exposed, such as tools used to organise, optimise or structure political campaigns from an administrative or logistical point of view.\nANNEX IV Technical documentation referred to in Article 11(1)\nThe technical documentation referred to in Article 11(1) shall contain at least the following information, as applicable to the relevant AI system:\nA general description of the AI system including: (a)\nits intended purpose, the name of the provider and the version of the system reflecting its relation to previous versions;\n(b)\nhow the AI system interacts with, or can be used to interact with, hardware or software, including with other AI systems, that are not part of the AI system itself, where applicable;\n(c)\nthe versions of relevant software or firmware, and any requirements related to version updates;\n(d)\nthe description of all the forms in which the AI system is placed on the market or put into service, such as software packages embedded into hardware, downloads, or APIs;\n(e)\nthe description of the hardware on which the AI system is intended to run;\n(f)\nwhere the AI system is a component of products, photographs or illustrations showing external features, the marking and internal layout of those products;\n(g)\na basic description of the user-interface provided to the deployer;\n(h)\ninstructions for use for the deployer, and a basic description of the user-interface provided to the deployer, where applicable;\nA detailed description of the elements of the AI system and of the process for its development, including: (a)\nthe methods and steps performed for the development of the AI system, including, where relevant, recourse to pre-trained systems or tools provided by third parties and how those were used, integrated or modified by the provider;\n(b)\nthe design specifications of the system, namely the general logic of the AI system and of the algorithms; the key design choices including the rationale and assumptions made, including with regard to persons or groups of persons in respect of who, the system is intended to be used; the main classification choices; what the system is designed to optimise for, and the relevance of the different parameters; the description of the expected output and output quality of the system; the decisions about any possible trade-off made regarding the technical solutions adopted to comply with the requirements set out in Chapter III, Section 2;\n(c)\nthe description of the system architecture explaining how software components build on or feed into each other and integrate into the overall processing; the computational resources used to develop, train, test and validate the AI system;\n(d)\nwhere relevant, the data requirements in terms of datasheets describing the training methodologies and techniques and the training data sets used, including a general description of these data sets, information about their provenance, scope and main characteristics; how the data was obtained and selected; labelling procedures (e.g. for supervised learning), data cleaning methodologies (e.g. outliers detection);\n(e)\nassessment of the human oversight measures needed in accordance with Article 14, including an assessment of the technical measures needed to facilitate the interpretation of the outputs of AI systems by the deployers, in accordance with Article 13(3), point (d);\n(f)\nwhere applicable, a detailed description of pre-determined changes to the AI system and its performance, together with all the relevant information related to the technical solutions adopted to ensure continuous compliance of the AI system with the relevant requirements set out in Chapter III, Section 2;\n(g)\nthe validation and testing procedures used, including information about the validation and testing data used and their main characteristics; metrics used to measure accuracy, robustness and compliance with other relevant requirements set out in Chapter III, Section 2, as well as potentially discriminatory impacts; test logs and all test reports dated and signed by the responsible persons, including with regard to pre-determined changes as referred to under point (f);\n(h)\ncybersecurity measures put in place;\nDetailed information about the monitoring, functioning and control of the AI system, in particular with regard to: its capabilities and limitations in performance, including the degrees of accuracy for specific persons or groups of persons on which the system is intended to be used and the overall expected level of accuracy in relation to its intended purpose; the foreseeable unintended outcomes and sources of risks to health and safety, fundamental rights and discrimination in view of the intended purpose of the AI system; the human oversight measures needed in accordance with Article 14, including the technical measures put in place to facilitate the interpretation of the outputs of AI systems by the deployers; specifications on input data, as appropriate;\nA description of the appropriateness of the performance metrics for the specific AI system;\nA detailed description of the risk management system in accordance with Article 9;\nA description of relevant changes made by the provider to the system through its lifecycle;\nA list of the harmonised standards applied in full or in part the references of which have been published in the Official Journal of the European Union; where no such harmonised standards have been applied, a detailed description of the solutions adopted to meet the requirements set out in Chapter III, Section 2, including a list of other relevant standards and technical specifications applied;\nA copy of the EU declaration of conformity referred to in Article 47;\nA detailed description of the system in place to evaluate the AI system performance in the post-market phase in accordance with Article 72, including the post-market monitoring plan referred to in Article 72(3).\nANNEX V EU declaration of conformity\nThe EU declaration of conformity referred to in Article 47, shall contain all of the following information:\nAI system name and type and any additional unambiguous reference allowing the identification and traceability of the AI system;\nThe name and address of the provider or, where applicable, of their authorised representative;\nA statement that the EU declaration of conformity referred to in Article 47 is issued under the sole responsibility of the provider;\nA statement that the AI system is in conformity with this Regulation and, if applicable, with any other relevant Union law that provides for the issuing of the EU declaration of conformity referred to in Article 47;\nWhere an AI system involves the processing of personal data, a statement that that AI system complies with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680;\nReferences to any relevant harmonised standards used or any other common specification in relation to which conformity is declared;\nWhere applicable, the name and identification number of the notified body, a description of the conformity assessment procedure performed, and identification of the certificate issued;\nThe place and date of issue of the declaration, the name and function of the person who signed it, as well as an indication for, or on behalf of whom, that person signed, a signature.\nANNEX VI Conformity assessment procedure based on internal control\nThe conformity assessment procedure based on internal control is the conformity assessment procedure based on points 2, 3 and 4.\nThe provider verifies that the established quality management system is in compliance with the requirements of Article 17.\nThe provider examines the information contained in the technical documentation in order to assess the compliance of the AI system with the relevant essential requirements set out in Chapter III, Section 2.\nThe provider also verifies that the design and development process of the AI system and its post-market monitoring as referred to in Article 72 is consistent with the technical documentation.\nANNEX VII Conformity based on an assessment of the quality management system and an assessment of the technical documentation\nIntroduction Conformity based on an assessment of the quality management system and an assessment of the technical documentation is the conformity assessment procedure based on points 2 to 5.\nOverview The approved quality management system for the design, development and testing of AI systems pursuant to Article 17 shall be examined in accordance with point 3 and shall be subject to surveillance as specified in point 5. The technical documentation of the AI system shall be examined in accordance with point 4.\nQuality management system 3.1.\nThe application of the provider shall include: (a)\nthe name and address of the provider and, if the application is lodged by an authorised representative, also their name and address;\n(b)\nthe list of AI systems covered under the same quality management system;\n(c)\nthe technical documentation for each AI system covered under the same quality management system;\n(d)\nthe documentation concerning the quality management system which shall cover all the aspects listed under Article 17;\n(e)\na description of the procedures in place to ensure that the quality management system remains adequate and effective;\n(f)\na written declaration that the same application has not been lodged with any other notified body.\n3.2.\nThe quality management system shall be assessed by the notified body, which shall determine whether it satisfies the requirements referred to in Article 17. The decision shall be notified to the provider or its authorised representative.\nThe notification shall contain the conclusions of the assessment of the quality management system and the reasoned assessment decision.\n3.3.\nThe quality management system as approved shall continue to be implemented and maintained by the provider so that it remains adequate and efficient. 3.4.\nAny intended change to the approved quality management system or the list of AI systems covered by the latter shall be brought to the attention of the notified body by the provider. The proposed changes shall be examined by the notified body, which shall decide whether the modified quality management system continues to satisfy the requirements referred to in point 3.2 or whether a reassessment is necessary.\nThe notified body shall notify the provider of its decision. The notification shall contain the conclusions of the examination of the changes and the reasoned assessment decision.\nControl of the technical documentation. 4.1.\nIn addition to the application referred to in point 3, an application with a notified body of their choice shall be lodged by the provider for the assessment of the technical documentation relating to the AI system which the provider intends to place on the market or put into service and which is covered by the quality management system referred to under point 3. 4.2.\nThe application shall include: (a)\nthe name and address of the provider;\n(b)\na written declaration that the same application has not been lodged with any other notified body;\n(c)\nthe technical documentation referred to in Annex IV.\n4.3.\nThe technical documentation shall be examined by the notified body. Where relevant, and limited to what is necessary to fulfil its tasks, the notified body shall be granted full access to the training, validation, and testing data sets used, including, where appropriate and subject to security safeguards, through API or other relevant technical means and tools enabling remote access. 4.4.\nIn examining the technical documentation, the notified body may require that the provider supply further evidence or carry out further tests so as to enable a proper assessment of the conformity of the AI system with the requirements set out in Chapter III, Section 2. Where the notified body is not satisfied with the tests carried out by the provider, the notified body shall itself directly carry out adequate tests, as appropriate. 4.5.\nWhere necessary to assess the conformity of the high-risk AI system with the requirements set out in Chapter III, Section 2, after all other reasonable means to verify conformity have been exhausted and have proven to be insufficient, and upon a reasoned request, the notified body shall also be granted access to the training and trained models of the AI system, including its relevant parameters. Such access shall be subject to existing Union law on the protection of intellectual property and trade secrets. 4.6.\nThe decision of the notified body shall be notified to the provider or its authorised representative. The notification shall contain the conclusions of the assessment of the technical documentation and the reasoned assessment decision. Where the AI system is in conformity with the requirements set out in Chapter III, Section 2, the notified body shall issue a Union technical documentation assessment certificate. The certificate shall indicate the name and address of the provider, the conclusions of the examination, the conditions (if any) for its validity and the data necessary for the identification of the AI system.\nThe certificate and its annexes shall contain all relevant information to allow the conformity of the AI system to be evaluated, and to allow for control of the AI system while in use, where applicable.\nWhere the AI system is not in conformity with the requirements set out in Chapter III, Section 2, the notified body shall refuse to issue a Union technical documentation assessment certificate and shall inform the applicant accordingly, giving detailed reasons for its refusal.\nWhere the AI system does not meet the requirement relating to the data used to train it, re-training of the AI system will be needed prior to the application for a new conformity assessment. In this case, the reasoned assessment decision of the notified body refusing to issue the Union technical documentation assessment certificate shall contain specific considerations on the quality data used to train the AI system, in particular on the reasons for non-compliance.\n4.7.\nAny change to the AI system that could affect the compliance of the AI system with the requirements or its intended purpose shall be assessed by the notified body which issued the Union technical documentation assessment certificate. The provider shall inform such notified body of its intention to introduce any of the abovementioned changes, or if it otherwise becomes aware of the occurrence of such changes. The intended changes shall be assessed by the notified body, which shall decide whether those changes require a new conformity assessment in accordance with Article 43(4) or whether they could be addressed by means of a supplement to the Union technical documentation assessment certificate. In the latter case, the notified body shall assess the changes, notify the provider of its decision and, where the changes are approved, issue to the provider a supplement to the Union technical documentation assessment certificate. Surveillance of the approved quality management system. 5.1.\nThe purpose of the surveillance carried out by the notified body referred to in Point 3 is to make sure that the provider duly complies with the terms and conditions of the approved quality management system. 5.2.\nFor assessment purposes, the provider shall allow the notified body to access the premises where the design, development, testing of the AI systems is taking place. The provider shall further share with the notified body all necessary information. 5.3.\nThe notified body shall carry out periodic audits to make sure that the provider maintains and applies the quality management system and shall provide the provider with an audit report. In the context of those audits, the notified body may carry out additional tests of the AI systems for which a Union technical documentation assessment certificate was issued. ANNEX VIII Information to be submitted upon the registration of high-risk AI systems in accordance with Article 49\nSection A — Information to be submitted by providers of high-risk AI systems in accordance with Article 49(1)\nThe following information shall be provided and thereafter kept up to date with regard to high-risk AI systems to be registered in accordance with Article 49(1):\nThe name, address and contact details of the provider;\nWhere submission of information is carried out by another person on behalf of the provider, the name, address and contact details of that person;\nThe name, address and contact details of the authorised representative, where applicable;\nThe AI system trade name and any additional unambiguous reference allowing the identification and traceability of the AI system;\nA description of the intended purpose of the AI system and of the components and functions supported through this AI system;\nA basic and concise description of the information used by the system (data, inputs) and its operating logic;\nThe status of the AI system (on the market, or in service; no longer placed on the market/in service, recalled);\nThe type, number and expiry date of the certificate issued by the notified body and the name or identification number of that notified body, where applicable;\nA scanned copy of the certificate referred to in point 8, where applicable;\nAny Member States in which the AI system has been placed on the market, put into service or made available in the Union;\nA copy of the EU declaration of conformity referred to in Article 47;\nElectronic instructions for use; this information shall not be provided for high-risk AI systems in the areas of law enforcement or migration, asylum and border control management referred to in Annex III, points 1, 6 and 7;\nA URL for additional information (optional).\nSection B — Information to be submitted by providers of high-risk AI systems in accordance with Article 49(2)\nThe following information shall be provided and thereafter kept up to date with regard to AI systems to be registered in accordance with Article 49(2):\nThe name, address and contact details of the provider;\nWhere submission of information is carried out by another person on behalf of the provider, the name, address and contact details of that person;\nThe name, address and contact details of the authorised representative, where applicable;\nThe AI system trade name and any additional unambiguous reference allowing the identification and traceability of the AI system;\nA description of the intended purpose of the AI system;\nThe condition or conditions under Article 6(3)based on which the AI system is considered to be not-high-risk;\nA short summary of the grounds on which the AI system is considered to be not-high-risk in application of the procedure under Article 6(3);\nThe status of the AI system (on the market, or in service; no longer placed on the market/in service, recalled);\nAny Member States in which the AI system has been placed on the market, put into service or made available in the Union.\nSection C — Information to be submitted by deployers of high-risk AI systems in accordance with Article 49(3)\nThe following information shall be provided and thereafter kept up to date with regard to high-risk AI systems to be registered in accordance with Article 49(3):\nThe name, address and contact details of the deployer;\nThe name, address and contact details of the person submitting information on behalf of the deployer;\nThe URL of the entry of the AI system in the EU database by its provider;\nA summary of the findings of the fundamental rights impact assessment conducted in accordance with Article 27;\nA summary of the data protection impact assessment carried out in accordance with Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680 as specified in Article 26(8) of this Regulation, where applicable.\nANNEX IX Information to be submitted upon the registration of high-risk AI systems listed in Annex III in relation to testing in real world conditions in accordance with Article 60\nThe following information shall be provided and thereafter kept up to date with regard to testing in real world conditions to be registered in accordance with Article 60:\nA Union-wide unique single identification number of the testing in real world conditions;\nThe name and contact details of the provider or prospective provider and of the deployers involved in the testing in real world conditions;\nA brief description of the AI system, its intended purpose, and other information necessary for the identification of the system;\nA summary of the main characteristics of the plan for testing in real world conditions;\nInformation on the suspension or termination of the testing in real world conditions.\nANNEX X Union legislative acts on large-scale IT systems in the area of Freedom, Security and Justice\nSchengen Information System (a)\nRegulation (EU) 2018/1860 of the European Parliament and of the Council of 28 November 2018 on the use of the Schengen Information System for the return of illegally staying third-country nationals (OJ L 312, 7.12.2018, p. 1).\n(b)\nRegulation (EU) 2018/1861 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of border checks, and amending the Convention implementing the Schengen Agreement, and amending and repealing Regulation (EC) No 1987/2006 (OJ L 312, 7.12.2018, p. 14).\n(c)\nRegulation (EU) 2018/1862 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of police cooperation and judicial cooperation in criminal matters, amending and repealing Council Decision 2007/533/JHA, and repealing Regulation (EC) No 1986/2006 of the European Parliament and of the Council and Commission Decision 2010/261/EU (OJ L 312, 7.12.2018, p. 56).\nVisa Information System (a)\nRegulation (EU) 2021/1133 of the European Parliament and of the Council of 7 July 2021 amending Regulations (EU) No 603/2013, (EU) 2016/794, (EU) 2018/1862, (EU) 2019/816 and (EU) 2019/818 as regards the establishment of the conditions for accessing other EU information systems for the purposes of the Visa Information System (OJ L 248, 13.7.2021, p. 1).\n(b)\nRegulation (EU) 2021/1134 of the European Parliament and of the Council of 7 July 2021 amending Regulations (EC) No 767/2008, (EC) No 810/2009, (EU) 2016/399, (EU) 2017/2226, (EU) 2018/1240, (EU) 2018/1860, (EU) 2018/1861, (EU) 2019/817 and (EU) 2019/1896 of the European Parliament and of the Council and repealing Council Decisions 2004/512/EC and 2008/633/JHA, for the purpose of reforming the Visa Information System (OJ L 248, 13.7.2021, p. 11).\nEurodac Regulation (EU) 2024/1358 of the European Parliament and of the Council of 14 May 2024 on the establishment of ‘Eurodac’ for the comparison of biometric data in order to effectively apply Regulations (EU) 2024/1315 and (EU) 2024/1350 of the European Parliament and of the Council and Council Directive 2001/55/EC and to identify illegally staying third-country nationals and stateless persons and on requests for the comparison with Eurodac data by Member States’ law enforcement authorities and Europol for law enforcement purposes, amending Regulations (EU) 2018/1240 and (EU) 2019/818 of the European Parliament and of the Council and repealing Regulation (EU) No 603/2013 of the European Parliament and of the Council (OJ L, 2024/1358, 22.5.2024, ELI: http://data.europa.eu/eli/reg/2024/1358/oj ).\nEntry/Exit System Regulation (EU) 2017/2226 of the European Parliament and of the Council of 30 November 2017 establishing an Entry/Exit System (EES) to register entry and exit data and refusal of entry data of third-country nationals crossing the external borders of the Member States and determining the conditions for access to the EES for law enforcement purposes, and amending the Convention implementing the Schengen Agreement and Regulations (EC) No 767/2008 and (EU) No 1077/2011 (OJ L 327, 9.12.2017, p. 20).\nEuropean Travel Information and Authorisation System (a)\nRegulation (EU) 2018/1240 of the European Parliament and of the Council of 12 September 2018 establishing a European Travel Information and Authorisation System (ETIAS) and amending Regulations (EU) No 1077/2011, (EU) No 515/2014, (EU) 2016/399, (EU) 2016/1624 and (EU) 2017/2226 (OJ L 236, 19.9.2018, p. 1).\n(b)\nRegulation (EU) 2018/1241 of the European Parliament and of the Council of 12 September 2018 amending Regulation (EU) 2016/794 for the purpose of establishing a European Travel Information and Authorisation System (ETIAS) (OJ L 236, 19.9.2018, p. 72).\nEuropean Criminal Records Information System on third-country nationals and stateless persons Regulation (EU) 2019/816 of the European Parliament and of the Council of 17 April 2019 establishing a centralised system for the identification of Member States holding conviction information on third-country nationals and stateless persons (ECRIS-TCN) to supplement the European Criminal Records Information System and amending Regulation (EU) 2018/1726 (OJ L 135, 22.5.2019, p. 1).\nInteroperability (a)\nRegulation (EU) 2019/817 of the European Parliament and of the Council of 20 May 2019 on establishing a framework for interoperability between EU information systems in the field of borders and visa and amending Regulations (EC) No 767/2008, (EU) 2016/399, (EU) 2017/2226, (EU) 2018/1240, (EU) 2018/1726 and (EU) 2018/1861 of the European Parliament and of the Council and Council Decisions 2004/512/EC and 2008/633/JHA (OJ L 135, 22.5.2019, p. 27).\n(b)\nRegulation (EU) 2019/818 of the European Parliament and of the Council of 20 May 2019 on establishing a framework for interoperability between EU information systems in the field of police and judicial cooperation, asylum and migration and amending Regulations (EU) 2018/1726, (EU) 2018/1862 and (EU) 2019/816 (OJ L 135, 22.5.2019, p. 85).\nANNEX XI Technical documentation referred to in Article 53(1), point (a) — technical documentation for providers of general-purpose AI models\nSection 1\nInformation to be provided by all providers of general-purpose AI models\nThe technical documentation referred to in Article 53(1), point (a) shall contain at least the following information as appropriate to the size and risk profile of the model:\nA general description of the general-purpose AI model including: (a)\nthe tasks that the model is intended to perform and the type and nature of AI systems in which it can be integrated;\n(b)\nthe acceptable use policies applicable;\n(c)\nthe date of release and methods of distribution;\n(d)\nthe architecture and number of parameters;\n(e)\nthe modality (e.g. text, image) and format of inputs and outputs;\n(f)\nthe licence.\nA detailed description of the elements of the model referred to in point 1, and relevant information of the process for the development, including the following elements: (a)\nthe technical means (e.g. instructions of use, infrastructure, tools) required for the general-purpose AI model to be integrated in AI systems;\n(b)\nthe design specifications of the model and training process, including training methodologies and techniques, the key design choices including the rationale and assumptions made; what the model is designed to optimise for and the relevance of the different parameters, as applicable;\n(c)\ninformation on the data used for training, testing and validation, where applicable, including the type and provenance of data and curation methodologies (e.g. cleaning, filtering, etc.), the number of data points, their scope and main characteristics; how the data was obtained and selected as well as all other measures to detect the unsuitability of data sources and methods to detect identifiable biases, where applicable;\n(d)\nthe computational resources used to train the model (e.g. number of floating point operations), training time, and other relevant details related to the training;\n(e)\nknown or estimated energy consumption of the model.\nWith regard to point (e), where the energy consumption of the model is unknown, the energy consumption may be based on information about computational resources used.\nSection 2\nAdditional information to be provided by providers of general-purpose AI models with systemic risk\nA detailed description of the evaluation strategies, including evaluation results, on the basis of available public evaluation protocols and tools or otherwise of other evaluation methodologies. Evaluation strategies shall include evaluation criteria, metrics and the methodology on the identification of limitations.\nWhere applicable, a detailed description of the measures put in place for the purpose of conducting internal and/or external adversarial testing (e.g. red teaming), model adaptations, including alignment and fine-tuning.\nWhere applicable, a detailed description of the system architecture explaining how software components build or feed into each other and integrate into the overall processing.\nANNEX XII Transparency information referred to in Article 53(1), point (b) — technical documentation for providers of general-purpose AI models to downstream providers that integrate the model into their AI system\nThe information referred to in Article 53(1), point (b) shall contain at least the following:\nA general description of the general-purpose AI model including: (a)\nthe tasks that the model is intended to perform and the type and nature of AI systems into which it can be integrated;\n(b)\nthe acceptable use policies applicable;\n(c)\nthe date of release and methods of distribution;\n(d)\nhow the model interacts, or can be used to interact, with hardware or software that is not part of the model itself, where applicable;\n(e)\nthe versions of relevant software related to the use of the general-purpose AI model, where applicable;\n(f)\nthe architecture and number of parameters;\n(g)\nthe modality (e.g. text, image) and format of inputs and outputs;\n(h)\nthe licence for the model.\nA description of the elements of the model and of the process for its development, including: (a)\nthe technical means (e.g. instructions for use, infrastructure, tools) required for the general-purpose AI model to be integrated into AI systems;\n(b)\nthe modality (e.g. text, image, etc.) and format of the inputs and outputs and their maximum size (e.g. context window length, etc.);\n(c)\ninformation on the data used for training, testing and validation, where applicable, including the type and provenance of data and curation methodologies.\nANNEX XIII Criteria for the designation of general-purpose AI models with systemic risk referred to in Article 51\nFor the purpose of determining that a general-purpose AI model has capabilities or an impact equivalent to those set out in Article 51(1), point (a), the Commission shall take into account the following criteria:\n(a)\nthe number of parameters of the model;\n(b)\nthe quality or size of the data set, for example measured through tokens;\n(c)\nthe amount of computation used for training the model, measured in floating point operations or indicated by a combination of other variables such as estimated cost of training, estimated time required for the training, or estimated energy consumption for the training;\n(d)\nthe input and output modalities of the model, such as text to text (large language models), text to image, multi-modality, and the state of the art thresholds for determining high-impact capabilities for each modality, and the specific type of inputs and outputs (e.g. biological sequences);\n(e)\nthe benchmarks and evaluations of capabilities of the model, including considering the number of tasks without additional training, adaptability to learn new, distinct tasks, its level of autonomy and scalability, the tools it has access to;\n(f)\nwhether it has a high impact on the internal market due to its reach, which shall be presumed when it has been made available to at least 10 000 registered business users established in the Union;\n(g)\nthe number of registered end-users.\n","permalink":"https://ai.intlaws.com/en/compliance/eu/eu-ai-act-full-text/","summary":"Official Englishof Regulation (EU) 2024/1689 (Artificial Intelligence Act) as published in the Official Journal of the European Union (OJ L, 12.7.2024): 13 chapters, 113 articles and 13 annexes, reproduced verbatim from EUR-Lex. Unofficial Chinese translation pending.","title":"Regulation (EU) 2024/1689 — Artificial Intelligence Act"},{"content":"案例 1：Workado, LLC（f/k/a Content at Scale AI）——AI 内容检测产品准确性宣称案 案号/文号：FTC Matter/File No. 2323092（官方案例页「FTC Matter/File Number」字段） 机关：美国联邦贸易委员会（Federal Trade Commission, FTC） 日期：最终命令获终局批准 2025-08-28（官方新闻稿发布日；起诉为 2025 年 4 月） 所涉法律：FTC Act 第 5 条（不公平或欺骗性行为）``——官方新闻稿未直接点明条文号，须回最终命令/起诉书原文坐实；官方案例页标签为「deceptive/misleading conduct」 要旨（官方原文）： \u0026ldquo;The Federal Trade Commission has given final approval to an order against Workado, LLC, requiring the company to stop advertising the accuracy or efficacy of its artificial intelligence (AI) content detection products unless it has competent and reliable evidence showing those products are as accurate as claimed.\u0026rdquo;\n\u0026ldquo;Workado markets its AI Content Detector to consumers seeking to determine whether written content was developed using generative AI technology or if it was written by a human being. The company claimed that its AI Content Detector was developed using a wide range of material, including blog posts and Wikipedia entries, to make it more accurate for average users. The FTC\u0026rsquo;s April 2025 complaint alleges, however, that the AI model powering the AI Content Detector was trained or fine-tuned to effect…\u0026rdquo;\n\u0026ldquo;The final order is designed to ensure Workado does not engage in similar false, misleading, or unsupported advertising. Under the order, Workado: Is prohibited from making any representations about the effectiveness of any AI content detection product unless it is not misleading, and the company has competent and reliable evidence to support the claim at the time it is made; …\u0026rdquo;\n（本网译，非官方译本，仅供参考）：FTC 已对 Workado, LLC 作出终局命令：除有适格且可靠的证据证明其人工智能（AI）内容检测产品确实达到所宣称的准确度外，该公司不得再就该等产品的准确性或效能作广告宣称。Workado 向消费者销售 AI Content Detector，用于判断文字内容系由生成式 AI 生成还是由人撰写；该公司宣称其检测器使用了包括博客文章、维基百科条目在内的大量素材训练以提高准确度。而 FTC 2025 年 4 月的起诉状指称，其底层 AI 模型被训练/微调至特定效果……终局命令要求 Workado 不得作出误导性宣称，且作出宣称时须有适格可靠证据支持。\n官方直链： 案例页（含文号、状态）：https://www.ftc.gov/legal-library/browse/cases-proceedings/2323092-content-scale-ai 新闻稿（最终命令批准，2025-08-28）：https://www.ftc.gov/news-events/news/press-releases/2025/08/ftc-approves-final-order-against-workado-llc-which-misrepresented-accuracy-its-artificial 新闻稿（2025-04 命令要求举证）：https://www.ftc.gov/news-events/news/press-releases/2025/04/ftc-order-requires-workado-back-artificial-intelligence-detection-claims 官方原文存档：FTC-Workado-2323092-案例页.html / .txt；FTC-Workado-2323092-最终命令新闻稿.html / .txt 法域：美国（联邦） 案例 2：GGL Projects, Inc.（d/b/a Sitejabber）——AI 评价平台虚假评分与评论案 案号/文号：``——官方案例页未列「FTC Matter/File Number」字段；案名为 In the Matter of GGL Projects, Inc., a Corporation, also d/b/a Sitejabber. 机关：美国联邦贸易委员会（FTC） 日期：起诉状发出于 2024 年 11 月（官方案例页原文 \u0026ldquo;In a complaint issued in November 2024\u0026rdquo;）；最终命令批准日 `` 所涉法律：FTC Act 第 5 条（欺骗性行为）``——须回命令原文坐实 要旨（官方原文）： \u0026ldquo;In a complaint issued in November 2024, the FTC charged that Sitejabber deceived consumers by misrepresenting that ratings and reviews it published came from customers who experienced the reviewed product or service, artificially inflating average ratings and review counts. Under a proposed order settling the agency\u0026rsquo;s complaint, Sitejabber will be prohibited from making such misrepresentations and from making other misrepresentations about consumer ratings or reviews. The Commission approved the…\u0026rdquo;\n\u0026ldquo;PRESS RELEASE: FTC Order Against AI-Enabled Review Platform Sitejabber Will Ensure Consumers Get Truthful and Accurate Reviews\u0026rdquo;\n\u0026ldquo;PRESS RELEASE: FTC Approves Final Order against Sitejabber, Which Misrepresented Ratings and Reviews by Consumers Who Had Not Yet Received Products or Services\u0026rdquo;\n（本网译，非官方译本，仅供参考）：FTC 于 2024 年 11 月发出起诉状，指控 Sitejabber 欺骗消费者——其发布的评分与评论被虚假表示为来自实际体验过所评商品或服务的消费者，从而人为抬高平均评分与评论数量。依和解拟议命令，Sitejabber 将被禁止作出此类虚假表示，亦不得就消费者评分或评论作出其他虚假表示。委员会已批准……（官方新闻稿标题：FTC 针对人工智能驱动的评价平台 Sitejabber 的命令将确保消费者获得真实准确的评论。）\n官方直链： 案例页（含完整描述与新闻稿内链）：https://www.ftc.gov/legal-library/browse/cases-proceedings/sitejabber 官方原文存档：FTC-GGL-Projects-Sitejabber-案例页.html / .txt 法域：美国（联邦） 案例 3：FTC 诉 Evolv Technologies Holdings, Inc.——AI 安检系统检测能力虚假宣称案 案号/文号：案名 Federal Trade Commission, Plaintiff, v. Evolv Technologies Holdings, Inc., a Corporation, Defendant.；案号/docket 号 ``（官方页面未列） 机关：美国联邦贸易委员会（FTC，作为原告） 日期：2024-11-26（官方新闻稿发布日） 所涉法律：FTC Act 第 5 条（欺骗性行为）``——须回命令/起诉书原文坐实 要旨（官方原文）： \u0026ldquo;The Federal Trade Commission is taking action against Evolv Technologies over allegations that the company made false claims about the extent to which its AI-powered security screening system can detect weapons and ignore harmless personal items, including in school settings.\u0026rdquo;\n\u0026ldquo;In the proposed FTC settlement order, Evolv would be banned from making unsupported claims about its products\u0026rsquo; ability…\u0026rdquo;\n（新闻稿副题） \u0026ldquo;Proposed settlement would prohibit misrepresentations and allow affected schools to opt out of current contracts for security screening systems\u0026rdquo;\n（本网译，非官方译本，仅供参考）：FTC 对 Evolv Technologies 采取执法行动，指称该公司就其人工智能驱动的安检系统在武器检出能力、以及对无害随身物品的忽略能力（含校园场景）方面作出虚假宣称。依拟议和解命令，Evolv 将被禁止就其产品能力作出无依据的宣称；拟议和解还将禁止虚假表示，并允许受影响的学校退出现行的安检系统合同。\n官方直链： 案例页：https://www.ftc.gov/legal-library/browse/cases-proceedings/evolv-technologies 新闻稿（2024-11-26）：https://www.ftc.gov/news-events/news/press-releases/2024/11/ftc-takes-action-against-evolv-technologies-deceiving-users-about-its-ai-powered-security-screening 官方原文存档：FTC-Evolv-Technologies-案例页.html / .txt；FTC-Evolv-Technologies-新闻稿.html / .txt 法域：美国（联邦） 案例 4：Tractor Supply Company——CCPA 隐私告知与求职者权利告知违规案（CPPA 史上最大罚单） 案号/文号：Case No. ENF24-M-TR-04（） 机关：加州隐私保护局（CPPA / CalPrivacy）董事会（Board） 日期：公告日 2025-09-30；决定书签署日 2025-09-26 所涉法律：加州消费者隐私法（California Consumer Privacy Act, CCPA）——隐私告知（privacy notice）与消费者/求职者权利告知义务 要旨（官方原文）： \u0026ldquo;SACRAMENTO – The California Privacy Protection Agency (CPPA) Board has issued a decision requiring Tractor Supply Company, the nation\u0026rsquo;s largest rural lifestyle retailer with more than 2,500 stores in 49 states, to change its business practices and pay a $1,350,000 fine to resolve claims that the company violated the California Consumer Privacy Act (CCPA). The fine is the largest in the CPPA\u0026rsquo;s history, and the decision is the first to address the importance of CCPA privacy notices and privacy rig…\u0026rdquo;\n\u0026ldquo;According to the Board\u0026rsquo;s decision, Tractor Supply violated Californians\u0026rsquo; privacy rights by: Failing to maintain a privacy policy that notified consumers of their rights; Failing to notify California job applicants of their privacy rights and how to exercise them; …\u0026rdquo;\n\u0026ldquo;To resolve the allegations, Tractor Supply agreed to pay $1,350,000, implement broad remedial measures, such as scanning its digital properties to inventory tracking technologies, and require a corporate officer or director to certify compliance annually for the next four years.\u0026rdquo;\n（本网译，非官方译本，仅供参考）：加州隐私保护局董事会作出决定，要求全美最大乡村生活方式零售商 Tractor Supply Company（在 49 州拥有 2,500 余家门店）改变其业务做法并支付 1,350,000 美元罚款，以了结其违反 CCPA 的主张；该罚款为 CPPA 史上最高，该决定亦为首次就 CCPA 隐私告知与隐私权的重要性作出认定。据董事会决定，Tractor Supply 侵害加州居民隐私权的方式包括：未维持告知消费者其权利的隐私政策；未告知加州求职者其隐私权及行使方式……为达成和解，Tractor Supply 同意支付 1,350,000 美元、采取广泛的补救措施（如扫描其数字资产以梳理追踪技术清单），并须由公司高管或董事在未来四年内每年认证合规。\n官方直链： 公告页：https://cppa.ca.gov/announcements/2025/20250930.html 决定书（公告页内链）：https://cppa.ca.gov/pdf/20250930_tractor_supply_bd_sfo.pdf 官方原文存档：CPPA-20250930-Tractor-Supply-决定公告.html / .txt；CPPA-20250930-Tractor-Supply-决定书.pdf（1.0 MB） 法域：美国（加州） 案例 5：ROR Partners LLC——健身健康品牌营销商未依《删除法》登记为数据经纪商案 案号/文号：Case No. ENF25-245-D-RO（） 机关：加州隐私保护局（CPPA / CalPrivacy）董事会 日期：公告日 2025-12-03；决定书签署日 2025-11-26 所涉法律：加州《删除法》（California Delete Act）——数据经纪商年度登记义务 要旨（官方原文）： \u0026ldquo;SACRAMENTO, CA – The California Privacy Protection Agency Board has issued a decision requiring ROR Partners LLC, a Nevada-based marketing firm catering to fitness and wellness brands, to pay $56,600 in fines and past-due fees for failing to register as a data broker in violation of California\u0026rsquo;s Delete Act. The Enforcement Division brought the case as part of its …\u0026rdquo;\n（本网译，非官方译本，仅供参考）：加州隐私保护局董事会作出决定，要求总部位于内华达、服务健身与健康品牌的营销公司 ROR Partners LLC，因违反加州《删除法》未登记为数据经纪商，缴纳 56,600 美元的罚款及欠缴费用。\n官方直链： 公告页：https://cppa.ca.gov/announcements/2025/20251203.html 决定书（公告页内链）：https://cppa.ca.gov/pdf/ror_partners_ood.pdf 官方原文存档：CPPA-20251203-ROR-Partners-决定公告.html / .txt；CPPA-20251203-ROR-Partners-决定书.pdf（0.9 MB） 附一：同批另 2 件（未计入上述 5 件） 以下 2 件同属 CalPrivacy 2026-01-08 数据经纪人执法公告，字段已从官方公告页核实，因与案例 5 同源同日，并列于此：\n# 主体 处罚金额 事由 所涉法律 公告日 官方直链 A Rickenbacher Data LLC（d/b/a Datamasters，得克萨斯州） $45,000 未登记为数据经纪商；并转售含阿尔茨海默病、药物成瘾、膀胱失禁等健康状况人士的姓名/住址/电话/邮箱 加州《删除法》 2026-01-08 https://cppa.ca.gov/announcements/2026/20260108.html ；决定书 https://cppa.ca.gov/pdf/datamasters_order_signed.pdf B S\u0026amp;P Global, Inc.（纽约州） $62,600 因行政性差错未登记为数据经纪商；须建立登记与合规审计程序 加州《删除法》 2026-01-08 https://cppa.ca.gov/announcements/2026/20260108.html ；决定书 https://cppa.ca.gov/pdf/sp_global_inc_fo_signed.pdf 附二：说明 机关名称变更：加州隐私保护局（CPPA）自 2026-01-26 起将全部公告迁至 privacy.ca.gov，对外名称改用 CalPrivacy。2025 年及更早公告仍留存于 cppa.ca.gov/announcements/，链接有效。 日期口径：本批为执法/处罚案例，不涉法规生效节点，故无「法律生效日 vs 合规义务适用日」之分。但《删除法》项下数据经纪商登记义务为每年 1 月履行，与各案处罚公告日属不同性质的节点。 来源范围：全部字段仅取自 FTC 官网与 CalPrivacy/CPPA 官网一手页面与官方 PDF，无第三方转载、无律所解读入正文。 ","permalink":"https://ai.intlaws.com/cases/us-enforcement-first-batch/","summary":"美国联邦与加州两级监管机关在人工智能、数据隐私与数据经纪领域的执法/处罚案例首批 5 件： 联邦贸易委员会（FTC）3 件（AI 内容检测准确性、AI 评价平台、AI 安检系统虚假宣称）， 加州隐私保护局（CalPrivacy，原 CPPA）2 件（CCPA 隐私告知违规、数据经纪注册违规）。 各条四要素齐备，要旨以官方文书原文为准，附官方直链。","title":"案例荟萃｜美国人工智能与数据保护执法案例（首批：FTC 与加州 CalPrivacy）"},{"content":" 版本与来源（可核验）\n项目 内容 发布 2022 年 11 月 18 日（中国网络安全审查认证和市场监管大数据中心） 施行 自发布之日起实施 现行有效 是（截至 2026-09-23） 中文原文来源 国家互联网信息办公室官网 英文译本 无官方英译本。本页英文译本由本网据官方中文文本翻译并交叉校核，标注为非官方译本、仅供参考 → English 校对记录 2026-09-23 抓取官方页面；共 7 节（适用范围/认证依据/认证模式/认证程序/认证证书和标志/获证个人信息处理者义务/认证机构义务·认证责任），结构完整 1. 适用范围 本规则依据《中华人民共和国认证认可条例》制定，规定了对个人信息处理者开展个人信息收集、存储、使用、加工、传输、提供、公开、删除以及跨境等处理活动进行认证的基本原则和要求。\n2. 认证依据 个人信息处理者应当符合GB/T 35273《信息安全技术 个人信息安全规范》的要求。\n对于开展跨境处理活动的个人信息处理者，还应当符合TC260-PG-20222A《个人信息跨境处理活动安全认证规范》的要求。\n上述标准、规范原则上应当执行最新版本。\n3. 认证模式 个人信息保护认证的认证模式为：\n技术验证 + 现场审核 + 获证后监督\n4 认证实施程序\n4.1 认证委托\n认证机构应当明确认证委托资料要求，包括但不限于认证委托人基本材料、认证委托书、相关证明文档等。\n认证委托人应当按认证机构要求提交认证委托资料，认证机构在对认证委托资料审查后及时反馈是否受理。\n认证机构应当根据认证委托资料确定认证方案，包括个人信息类型和数量、涉及的个人信息处理活动范围、技术验证机构信息等，并通知认证委托人。\n4.2 技术验证\n技术验证机构应当按照认证方案实施技术验证，并向认证机构和认证委托人出具技术验证报告。\n4.3 现场审核\n认证机构实施现场审核，并向认证委托人出具现场审核报告。\n4.4 认证结果评价和批准\n认证机构根据认证委托资料、技术验证报告、现场审核报告和其他相关资料信息进行综合评价，作出认证决定。对符合认证要求的，颁发认证证书；对暂不符合认证要求的，可要求认证委托人限期整改，整改后仍不符合的，以书面形式通知认证委托人终止认证。\n如发现认证委托人、个人信息处理者存在欺骗、隐瞒信息、故意违反认证要求等严重影响认证实施的行为时，认证不予通过。\n4.5 获证后监督\n4.5.1 监督的频次\n认证机构应当在认证有效期内，对获得认证的个人信息处理者进行持续监督，并合理确定监督频次。\n4.5.2 监督的内容\n认证机构应当采取适当的方式实施获证后监督，确保获得认证的个人信息处理者持续符合认证要求。\n4.5.3 获证后监督结果的评价\n认证机构对获证后监督结论和其他相关资料信息进行综合评价，评价通过的，可继续保持认证证书；不通过的，认证机构应当根据相应情形作出暂停直至撤销认证证书的处理。\n4.6 认证时限\n认证机构应当对认证各环节的时限作出明确规定，并确保相关工作按时限要求完成。认证委托人应当对认证活动予以积极配合。\n5 认证证书和认证标志\n5.1 认证证书\n5.1.1 认证证书的保持\n认证证书有效期为3年。在有效期内，通过认证机构的获证后监督，保持认证证书的有效性。\n证书到期需延续使用的，认证委托人应当在有效期届满前6个月内提出认证委托。认证机构应当采用获证后监督的方式，对符合认证要求的委托换发新证书。\n5.1.2 认证证书的变更\n认证证书有效期内，若获得认证的个人信息处理者名称、注册地址，或认证要求、认证范围等发生变化时，认证委托人应当向认证机构提出变更委托。认证机构根据变更的内容，对变更委托资料进行评价，确定是否可以批准变更。如需进行技术验证和/或现场审核，还应当在批准变更前进行技术验证和/或现场审核。\n5.1.3 认证证书的注销、暂停和撤销\n当获得认证的个人信息处理者不再符合认证要求时，认证机构应当及时对认证证书予以暂停直至撤销。认证委托人在认证证书有效期内可申请认证证书暂停、注销。\n5.1.4 认证证书的公布\n认证机构应当采用适当方式对外公布认证证书颁发、变更、暂停、注销和撤销等相关信息。\n5.2 认证标志\n不含跨境处理活动的个人信息保护认证标志如下：\n包含跨境处理活动的个人信息保护认证标志如下：\n“ABCD”代表认证机构识别信息。\n5.3 认证证书和认证标志的使用\n在认证证书有效期内，获得认证的个人信息处理者应当按照有关规定在广告等宣传中正确使用认证证书和认证标志，不得对公众产生误导。\n6 认证实施细则\n认证机构应当依据本规则有关要求，细化认证实施程序，制定科学、合理、可操作的认证实施细则，并对外公布实施。\n7. 认证责任 认证机构应当对现场审核结论、认证结论负责。\n技术验证机构应当对技术验证结论负责。\n认证委托人应当对认证委托资料的真实性、合法性负责。\n","permalink":"https://ai.intlaws.com/compliance/china/personal-information-protection-certification-rules/","summary":"《个人信息保护认证实施规则》官方文本：2022 年 11 月 18 日发布（中国网络安全审查技术与认证中心 CCRC 编制）； 规定个人信息保护认证的适用范围、认证依据、认证模式（技术验证+现场审核+获证后监督）、认证证书与标志等。","title":"个人信息保护认证实施规则"},{"content":" 版本与来源（可核验）\n项目 内容 通过与公布 2023 年 2 月 24 日公布（国家互联网信息办公室令第 13 号） 施行日期 2023 年 6 月 1 日 现行有效 是（截至 2026-09-23） 中文原文来源 国家互联网信息办公室官网 英文译本 无官方英译本。本页英文译本由本网据官方中文文本翻译并逐条交叉校核，标注为非官方译本、仅供参考 → English 校对记录 2026-09-23 抓取官方页面；共 13 条，条号连续、无缺号 国家互联网信息办公室令\n第13号\n《个人信息出境标准合同办法》已经202\n3年2月3日国家互联网信息办公室2023年第2次室务会议审议通过，现予公布，自2023年6月1日起施行。\n国家互联网信息办公室主任 庄荣文\n2023年2月22日\n个人信息出境标准合同办法\n第一条 为了保护个人信息权益，规范个人信息出境活动，根据《中华人民共和国个人信息保护法》等法律法规，制定本办法。\n第二条 个人信息处理者通过与境外接收方订立个人信息出境标准合同（以下简称标准合同）的方式向中华人民共和国境外提供个人信息，适用本办法。\n第三条 通过订立标准合同的方式开展个人信息出境活动，应当坚持自主缔约与备案管理相结合、保护权益与防范风险相结合，保障个人信息跨境安全、自由流动。\n第四条 个人信息处理者通过订立标准合同的方式向境外提供个人信息的，应当同时符合下列情形：\n（一）非关键信息基础设施运营者；\n（二）处理个人信息不满100万人的；\n（三）自上年1月1日起累计向境外提供个人信息不满10万人的；\n（四）自上年1月1日起累计向境外提供敏感个人信息不满1万人的。\n法律、行政法规或者国家网信部门另有规定的，从其规定。\n个人信息处理者不得采取数量拆分等手段，将依法应当通过出境安全评估的个人信息通过订立标准合同的方式向境外提供。\n第五条 个人信息处理者向境外提供个人信息前，应当开展个人信息保护影响评估，重点评估以下内容：\n（一）个人信息处理者和境外接收方处理个人信息的目的、范围、方式等的合法性、正当性、必要性；\n（二）出境个人信息的规模、范围、种类、敏感程度，个人信息出境可能对个人信息权益带来的风险；\n（三）境外接收方承诺承担的义务，以及履行义务的管理和技术措施、能力等能否保障出境个人信息的安全；\n（四）个人信息出境后遭到篡改、破坏、泄露、丢失、非法利用等的风险，个人信息权益维护的渠道是否通畅等；\n（五）境外接收方所在国家或者地区的个人信息保护政策和法规对标准合同履行的影响；\n（六）其他可能影响个人信息出境安全的事项。\n第六条 标准合同应当严格按照本办法附件订立。国家网信部门可以根据实际情况对附件进行调整。\n个人信息处理者可以与境外接收方约定其他条款，但不得与标准合同相冲突。\n标准合同生效后方可开展个人信息出境活动。\n第七条 个人信息处理者应当在标准合同生效之日起10个工作日内向所在地省级网信部门备案。备案应当提交以下材料：\n（一）标准合同；\n（二）个人信息保护影响评估报告。\n个人信息处理者应当对所备案材料的真实性负责。\n第八条 在标准合同有效期内出现下列情形之一的，个人信息处理者应当重新开展个人信息保护影响评估，补充或者重新订立标准合同，并履行相应备案手续：\n（一）向境外提供个人信息的目的、范围、种类、敏感程度、方式、保存地点或者境外接收方处理个人信息的用途、方式发生变化，或者延长个人信息境外保存期限的；\n（二）境外接收方所在国家或者地区的个人信息保护政策和法规发生变化等可能影响个人信息权益的；\n（三）可能影响个人信息权益的其他情形。\n第九条 网信部门及其工作人员对在履行职责中知悉的个人隐私、个人信息、商业秘密、保密商务信息等应当依法予以保密，不得泄露或者非法向他人提供、非法使用。\n第十条 任何组织和个人发现个人信息处理者违反本办法向境外提供个人信息的，可以向省级以上网信部门举报。\n第十一条 省级以上网信部门发现个人信息出境活动存在较大风险或者发生个人信息安全事件的，可以依法对个人信息处理者进行约谈。个人信息处理者应当按照要求整改，消除隐患。\n第十二条 违反本办法规定的，依据《中华人民共和国个人信息保护法》等法律法规处理；构成犯罪的，依法追究刑事责任。\n第十三条 本办法自2023年6月1日起施行。本办法施行前已经开展的个人信息出境活动，不符合本办法规定的，应当自本办法施行之日起6个月内完成整改。\n","permalink":"https://ai.intlaws.com/compliance/china/personal-information-exit-standard-contract/","summary":"《个人信息出境标准合同办法》官方文本：2023 年 2 月 24 日公布（国家互联网信息办公室令第 13 号）、2023 年 6 月 1 日起施行； 确立个人信息出境标准合同的订立、备案与个人信息保护影响评估义务。","title":"个人信息出境标准合同办法"},{"content":"一、问题的提出 生成式人工智能的合规风险，常常不是从\u0026quot;模型能不能用\u0026quot;开始，而是从\u0026quot;生成的东西有没有被认出来\u0026quot;开始。未经标识的 AI 生成内容一旦进入传播链条，就可能成为虚假信息与侵权内容的载体。正因如此，内容标识成为中国生成式人工智能监管中最先落地、也最易触碰的义务。\n2025 年 9 月 1 日，《人工智能生成合成内容标识办法》（以下简称《标识办法》）施行，与《生成式人工智能服务管理暂行办法》（以下简称《生成式 AI 办法》）、《互联网信息服务深度合成管理规定》（以下简称《深度合成规定》）形成衔接。本文梳理标识义务的规范依据、义务结构与落地要点。\n二、规范依据与适用范围 2.1 三部规范的阶梯关系 《深度合成规定》（国家互联网信息办公室、工业和信息化部、公安部令第 12 号，2022 年 11 月 25 日公布，2023 年 1 月 10 日起施行）确立底线：第十六条要求对生成或者编辑的信息内容\u0026quot;采取技术措施添加不影响用户使用的标识\u0026quot;；第十七条对可能导致公众混淆或者误认的情形（智能对话、智能写作等模拟自然人进行文本生成或者编辑的服务，人脸生成、替换、操控，合成人声、仿声等）要求显著标识；第十八条禁止以技术手段删除、篡改、隐匿上述标识。 《生成式 AI 办法》（国家互联网信息办公室、国家发展和改革委员会、教育部、科学技术部、工业和信息化部、公安部、国家广播电视总局令第 15 号，2023 年 7 月 10 日公布，2023 年 8 月 15 日起施行）第十二条作衔接性规定：\u0026ldquo;提供者应当按照《互联网信息服务深度合成管理规定》对图片、视频等生成内容进行标识。\u0026rdquo; 《标识办法》（国家互联网信息办公室、工业和信息化部、公安部、国家广播电视总局，国信办通字〔2025〕2 号，2025 年 3 月 7 日签发、3 月 14 日公开发布，2025 年 9 月 1 日起施行）把标识从原则要求细化为技术与流程规则，并区分显式标识与隐式标识。 2.2 四类主体，义务各不同 依《标识办法》第二条，适用主体是\u0026quot;符合《互联网信息服务算法推荐管理规定》《互联网信息服务深度合成管理规定》《生成式人工智能服务管理暂行办法》规定情形的网络信息服务提供者\u0026quot;。结合条文，实践涉及四类角色：\n角色 核心义务 依据 生成合成服务提供者 添加显式与隐式标识、协议告知、日志留存 《标识办法》第四、五、八、九条 网络信息内容传播服务提供者 核验元数据、对无标识或疑似内容加提示、提供标识功能 《标识办法》第六条 应用程序分发平台 上架或上线审核时核验标识材料 《标识办法》第七条 用户 主动声明并标识、不得恶意删除篡改标识 《标识办法》第十条 提示：义务主体不限于大模型厂商——只要落入上述规章的适用情形，或提供内容传播、应用分发服务，即各自落到相应义务上。\n三、标识义务的三层结构 3.1 显式标识：让用户明显感知 《标识办法》第四条针对属于《深度合成规定》第十七条第一款情形的服务，按媒介分别要求：文本在起始、末尾或者中间适当位置添加文字提示或者通用符号提示，或在交互场景界面、文字周边添加显著提示标识；音频添加语音提示或者音频节奏提示；图片在适当位置添加显著提示标识；视频在起始画面和播放周边适当位置添加（可在末尾和中间适当位置补充）；虚拟场景在起始画面适当位置添加；其他场景按自身应用特点添加显著提示标识。\n易被忽略的一处：该条第二款规定，提供生成合成内容下载、复制、导出等功能时，\u0026ldquo;应当确保文件中含有满足要求的显式标识\u0026rdquo;。很多产品只在界面内提示，用户一键导出的文件却干干净净——导出环节正是显式标识的检查点。\n3.2 隐式标识：写入文件元数据 《标识办法》第五条要求按《深度合成规定》第十六条，在文件元数据中添加隐式标识，包含生成合成内容属性信息、服务提供者名称或者编码、内容编号等制作要素信息，并鼓励添加数字水印。同条第三款界定\u0026quot;文件元数据\u0026quot;为按特定编码格式嵌入文件头部的描述性信息。其合规含义有两层。一是内容脱离原界面、被转发到其他平台后，仍可通过元数据回溯生成者。二是转码、压缩环节把元数据清掉，效果等同于未履行义务。\n3.3 传播端核验：平台的四种情形 《标识办法》第六条把传播服务提供者的义务拆为四种情形：\n元数据中含有隐式标识的，在发布内容周边添加显著提示标识，明确提醒公众该内容属于生成合成内容； 元数据中未核验到隐式标识、但用户声明为生成合成内容的，添加提示标识，提醒公众该内容可能为生成合成内容； 元数据中未核验到隐式标识、用户也未声明，但平台检测到显式标识或者其他生成合成痕迹的，识别为疑似生成合成内容并添加提示标识； 提供必要的标识功能，并提醒用户主动声明发布内容中是否包含生成合成内容。 属于前三项情形的，还应当在文件元数据中添加生成合成内容属性信息、传播平台名称或者编码、内容编号等传播要素信息。\n四、三项容易被忽视的规则 其一，无显式标识内容的提供与日志留存。《标识办法》第九条允许用户申请提供不含显式标识的生成合成内容，但设定了两个前提：通过用户协议明确用户的标识义务和使用责任；依法留存提供对象信息等相关日志不少于六个月。这不是豁免条款，而是把风险部分转移给用户。\n其二，用户声明义务与\u0026quot;去标识\u0026quot;禁令。《标识办法》第十条规定，用户发布生成合成内容的，应当主动声明并使用服务提供者提供的标识功能进行标识；并明确任何组织和个人不得恶意删除、篡改、伪造、隐匿标识，不得为他人实施上述恶意行为提供工具或者服务——后半句直接指向\u0026quot;去标识工具\u0026quot;类产品。\n其三，协议条款与强制性国家标准。《标识办法》第八条要求服务提供者在用户服务协议中明确说明标识的方法、样式等规范内容并提示用户理解；第十一条要求标识活动还应当符合相关法律、行政法规、部门规章和强制性国家标准的要求。第九条的合规效果，直接取决于协议是否把用户义务写清楚。\n五、与算法备案、安全评估的衔接 《生成式 AI 办法》第十七条规定，提供具有舆论属性或者社会动员能力的生成式人工智能服务的，应当开展安全评估，并按照《互联网信息服务算法推荐管理规定》履行算法备案手续；《深度合成规定》第十九条要求完成备案者在网站、应用程序显著位置标明备案编号并提供公示信息链接。\n《标识办法》第十二条把两条线拧在一起：服务提供者在履行算法备案、安全评估等手续时，应当按照本办法提供标识相关材料。实务提示：标识的技术细节（水印算法、元数据格式、服务商编码等）会进入备案与评估材料，法务与技术对接应前置到产品设计阶段。\n六、法律责任 《标识办法》第十三条规定，违反本办法的，由网信、电信、公安和广播电视等有关主管部门依据职责，按有关法律、行政法规、部门规章的规定予以处理。《生成式 AI 办法》第二十一条规定，提供者违反本办法的，依照《网络安全法》《数据安全法》《个人信息保护法》《科学技术进步法》等予以处罚；法律、行政法规没有规定的，予以警告、通报批评，责令限期改正；拒不改正或者情节严重的，责令暂停提供相关服务；构成犯罪的，依法追究刑事责任。\n把上述两条放在一起看，逻辑是一致的：标识义务以\u0026quot;衔接条款＋兜底责任\u0026quot;落地，实际处罚依据回到《网络安全法》《数据安全法》《个人信息保护法》等上位法。标识不是行业自律事项，而是有明确法律后果的义务。\n七、企业落地清单 角色定位：判断自己属于生成合成服务提供者、传播服务提供者还是分发平台，义务清单不同； 显式标识落到文件：界面提示之外，导出、下载、复制的文件里也要有； 隐式标识落到元数据：确定字段结构，防止转码、压缩环节清除； 传播端核验：按第六条四种情形设计检测与提示逻辑，并写入传播要素信息； 协议改造：在用户服务协议中加入标识方法与用户义务条款，覆盖第九条情形； 日志留存：无显式标识内容的提供记录留存不少于六个月； 备案材料同步：把标识技术细节纳入算法备案与安全评估材料； 内部红线：禁止开发或提供\u0026quot;去标识\u0026quot;工具，将恶意删除、篡改、伪造、隐匿标识纳入风控。 结语 标识义务的制度逻辑，是让 AI 生成内容在传播链的每个环节都可识别、可追溯。企业真正需要警惕的是义务被拆散到各业务环节后没有人对总账：产品做界面提示、技术做元数据、法务写协议、平台做核验——任何一环缺失，整条合规链就断了。\n规范依据（供核对）\n《互联网信息服务深度合成管理规定》，国家互联网信息办公室、工业和信息化部、公安部令第 12 号，2022 年 11 月 25 日公布，2023 年 1 月 10 日起施行。 《生成式人工智能服务管理暂行办法》，国家互联网信息办公室、国家发展和改革委员会、教育部、科学技术部、工业和信息化部、公安部、国家广播电视总局令第 15 号，2023 年 7 月 10 日公布，2023 年 8 月 15 日起施行。 《人工智能生成合成内容标识办法》，国信办通字〔2025〕2 号，2025 年 3 月 7 日签发、3 月 14 日公开发布，2025 年 9 月 1 日起施行。 注：文中涉及《网络安全法》的处罚衔接条款，条号一律以 2025 年修正版为准（2016 年版条文序号已调整）。\n","permalink":"https://ai.intlaws.com/forum/ai%E7%94%9F%E6%88%90%E5%86%85%E5%AE%B9%E7%9A%84%E6%A0%87%E8%AF%86%E4%B9%89%E5%8A%A1-%E5%90%88%E8%A7%84%E8%A6%81%E7%82%B9/","summary":"梳理AI生成内容标识义务的完整链条：显式标识须落到导出文件、隐式标识须写入元数据且防转码清除、传播平台按四种情形核验提示，并明确「去标识工具」提供行为被明文禁止。","title":"AI 生成内容的标识义务合规要点"},{"content":" Version and sources (verifiable)\nItem Content Instrument Senate Bill 53 (2025–2026 Regular Session), \u0026ldquo;Artificial intelligence models: large developers\u0026rdquo; Status approved by the Governor and filed with the Secretary of State on 29 September 2025 (chaptered) Chapter Chapter 138, Statutes of 2025 Short title Transparency in Frontier Artificial Intelligence Act (TFAIA) — per the Legislative Counsel\u0026rsquo;s Digest and the chapter heading of B\u0026amp;P Code Chapter 25.1 Effect adds Business and Professions Code Chapter 25.1 (commencing with Section 22757.10); amends Government Code Section 11546.8; adds Labor Code Chapter 5.1 (commencing with Section 1107) Official text https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53 Verification 2026-09-23 re-verified against the official Chapter 138 chaptered PDF (leginfo version 20250SB5390CHP, 16 pp.): SECTION/SEC 6/6; code sections 11/11; item markers (a)–(p) counts identical per letter; numeric markers identical per SEC — no omissions against the official text Legislative status page bill status ｜ Governor\u0026rsquo;s signing release (29 Sep 2025) Chinese version No official Chinese text. A Chinese translation by our editorial team, marked non-official, is available → 中文全文 Retrieval \u0026amp; verification Retrieved 2026-09-22 from the official California Legislative Information bill-text page; SECTION numbering and code references checked against the published text. Scope note This page reproduces the bill text as published; it is the enacted instrument, not the codified code sections as later integrated into the codes. SECTION 1. The Legislature finds and declares all of the following:\n(a) California is leading the world in artificial intelligence innovation and research through companies large and small and through the state’s remarkable public and private universities.\n(b) Artificial intelligence, including new advances in foundation models, has the potential to catalyze innovation and the rapid development of a wide range of benefits for Californians and the California economy, including advances in medicine, wildfire forecasting and prevention, and climate science, and to push the bounds of human creativity and capacity.\n(c) The Joint California Policy Working Group on AI Frontier Models has recommended sound principles for policy in artificial intelligence.\n(d) Targeted interventions to support effective artificial intelligence governance should balance the technology’s benefits and the potential for material risks.\n(e) In building a robust and transparent evidence environment, policymakers can align incentives to simultaneously protect consumers, leverage industry expertise, and recognize leading safety practices.\n(f) As industry actors conduct internal research on their technologies’ impacts, public trust in these technologies would significantly benefit from access to information regarding, and increased awareness of, frontier AI capabilities.\n(g) Greater transparency can also advance accountability, competition, and public trust.\n(h) Whistleblower protections and public-facing information sharing are key instruments to increase transparency.\n(i) Incident reporting systems enable monitoring of the post-deployment impacts of artificial intelligence.\n(j) Unless they are developed with careful diligence and reasonable precaution, there is concern that advanced artificial intelligence systems could have capabilities that pose catastrophic risks from both malicious uses and malfunctions, including artificial intelligence-enabled hacking, biological attacks, and loss of control.\n(k) With the frontier of artificial intelligence rapidly evolving, there is a need for legislation to track the frontier of artificial intelligence research and alert policymakers and the public to serious risks and harms from the very most advanced artificial intelligence systems, while avoiding burdening smaller companies behind the frontier.\n(l) While the major artificial intelligence developers have already voluntarily established the creation, use, and publication of frontier AI frameworks as an industry best practice, not all developers are providing reporting that is consistent and sufficient to ensure necessary transparency and protection of the public. Mandatory, standardized, and objective reporting by frontier developers is required to provide the government and the public with timely and accurate information.\n(m) Timely reporting of critical safety incidents to the government is essential to ensure that public authorities are promptly informed of ongoing and emerging risks to public safety. This reporting enables the government to monitor, assess, and respond effectively in the event that advanced capabilities emerge in frontier artificial intelligence models that may pose a threat to the public.\n(n) In the future, foundation models developed by smaller companies or that are behind the frontier may pose significant catastrophic risk, and additional legislation may be needed at that time.\n(o) The recent release of the Governor’s California Report on Frontier AI Policy and testimony from legislative hearings on artificial intelligence before the Legislature reflect the advances in AI model capabilities that could pose potential catastrophic risk in frontier artificial intelligence, which this act aims to address.\n(p) It is the intent of the Legislature to create more transparency, but collective safety will depend in part on frontier developers taking due care in their development and deployment of frontier models proportional to the scale of the foreseeable risks.\nSEC. 2. Chapter 25.1 (commencing with Section 22757.10) is added to Division 8 of the Business and Professions Code, to read:\nCHAPTER 25.1. Transparency in Frontier Artificial Intelligence Act 22757.10. This chapter shall be known as the Transparency in Frontier Artificial Intelligence Act.\n22757.11. For purposes of this chapter:\n(a) “Affiliate” means a person controlling, controlled by, or under common control with a specified person, directly or indirectly, through one or more intermediaries.\n(b) “Artificial intelligence model” means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.\n(c) (1) “Catastrophic risk” means a foreseeable and material risk that a frontier developer’s development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than one billion dollars ($1,000,000,000) in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following:\n(A) Providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon.\n(B) Engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense.\n(C) Evading the control of its frontier developer or user.\n(2) “Catastrophic risk” does not include a foreseeable and material risk from any of the following:\n(A) Information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model.\n(B) Lawful activity of the federal government.\n(C) Harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.\n(d) “Critical safety incident” means any of the following:\n(1) Unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury.\n(2) Harm resulting from the materialization of a catastrophic risk.\n(3) Loss of control of a frontier model causing death or bodily injury.\n(4) A frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.\n(e) (1) “Deploy” means to make a frontier model available to a third party for use, modification, copying, or combination with other software.\n(2) “Deploy” does not include making a frontier model available to a third party for the primary purpose of developing or evaluating the frontier model.\n(f) “Foundation model” means an artificial intelligence model that is all of the following:\n(1) Trained on a broad data set.\n(2) Designed for generality of output.\n(3) Adaptable to a wide range of distinctive tasks.\n(g) “Frontier AI framework” means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.\n(h) “Frontier developer” means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in subdivision (i).\n(i) (1) “Frontier model” means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations.\n(2) The quantity of computing power described in paragraph (1) shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.\n(j) “Large frontier developer” means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of five hundred million dollars ($500,000,000) in the preceding calendar year.\n(k) “Model weight” means a numerical parameter in a frontier model that is adjusted through training and that helps determine how inputs are transformed into outputs.\n(l) “Property” means tangible or intangible property.\n22757.12. (a) A large frontier developer shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models and describes how the large frontier developer approaches all of the following:\n(1) Incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework.\n(2) Defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds.\n(3) Applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to paragraph (2).\n(4) Reviewing assessments and adequacy of mitigations as part of the decision to deploy a frontier model or use it extensively internally.\n(5) Using third parties to assess the potential for catastrophic risks and the effectiveness of mitigations of catastrophic risks.\n(6) Revisiting and updating the frontier AI framework, including any criteria that trigger updates and how the large frontier developer determines when its frontier models are substantially modified enough to require disclosures pursuant to subdivision (c).\n(7) Cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties.\n(8) Identifying and responding to critical safety incidents.\n(9) Instituting internal governance practices to ensure implementation of these processes.\n(10) Assessing and managing catastrophic risk resulting from the internal use of its frontier models, including risks resulting from a frontier model circumventing oversight mechanisms.\n(b) (1) A large frontier developer shall review and, as appropriate, update its frontier AI framework at least once per year.\n(2) If a large frontier developer makes a material modification to its frontier AI framework, the large frontier developer shall clearly and conspicuously publish the modified frontier AI framework and a justification for that modification within 30 days.\n(c) (1) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a frontier developer shall clearly and conspicuously publish on its internet website a transparency report containing all of the following:\n(A) The internet website of the frontier developer.\n(B) A mechanism that enables a natural person to communicate with the frontier developer.\n(C) The release date of the frontier model.\n(D) The languages supported by the frontier model.\n(E) The modalities of output supported by the frontier model.\n(F) The intended uses of the frontier model.\n(G) Any generally applicable restrictions or conditions on uses of the frontier model.\n(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following:\n(A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework.\n(B) The results of those assessments.\n(C) The extent to which third-party evaluators were involved.\n(D) Other steps taken to fulfill the requirements of the frontier AI framework with respect to the frontier model.\n(3) A frontier developer that publishes the information described in paragraph (1) or (2) as part of a larger document, including a system card or model card, shall be deemed in compliance with the applicable paragraph.\n(4) A frontier developer is encouraged, but not required, to make disclosures described in this subdivision that are consistent with, or superior to, industry best practices.\n(d) A large frontier developer shall transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every three months or pursuant to another reasonable schedule specified by the large frontier developer and communicated in writing to the Office of Emergency Services with written updates, as appropriate.\n(e) (1) (A) A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk.\n(B) A large frontier developer shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework.\n(2) This subdivision does not apply to a statement that was made in good faith and was reasonable under the circumstances.\n(f) (1) When a frontier developer publishes documents to comply with this section, the frontier developer may make redactions to those documents that are necessary to protect the frontier developer’s trade secrets, the frontier developer’s cybersecurity, public safety, or the national security of the United States or to comply with any federal or state law.\n(2) If a frontier developer redacts information in a document pursuant to this subdivision, the frontier developer shall describe the character and justification of the redaction in any published version of the document to the extent permitted by the concerns that justify redaction and shall retain the unredacted information for five years.\n22757.13. (a) The Office of Emergency Services shall establish a mechanism to be used by a frontier developer or a member of the public to report a critical safety incident that includes all of the following:\n(1) The date of the critical safety incident.\n(2) The reasons the incident qualifies as a critical safety incident.\n(3) A short and plain statement describing the critical safety incident.\n(4) Whether the incident was associated with internal use of a frontier model.\n(b) (1) The Office of Emergency Services shall establish a mechanism to be used by a large frontier developer to confidentially submit summaries of any assessments of the potential for catastrophic risk resulting from internal use of its frontier models.\n(2) The Office of Emergency Services shall take all necessary precautions to limit access to any reports related to internal use of frontier models to only personnel with a specific need to know the information and to protect the reports from unauthorized access.\n(c) (1) Subject to paragraph (2), a frontier developer shall report any critical safety incident pertaining to one or more of its frontier models to the Office of Emergency Services within 15 days of discovering the critical safety incident.\n(2) If a frontier developer discovers that a critical safety incident poses an imminent risk of death or serious physical injury, the frontier developer shall disclose that incident within 24 hours to an authority, including any law enforcement agency or public safety agency with jurisdiction, that is appropriate based on the nature of that incident and as required by law.\n(3) A frontier developer that discovers information about a critical safety incident after filing the initial report required by this subdivision may file an amended report.\n(4) A frontier developer is encouraged, but not required, to report critical safety incidents pertaining to foundation models that are not frontier models.\n(d) The Office of Emergency Services shall review critical safety incident reports submitted by frontier developers and may review reports submitted by members of the public.\n(e) (1) The Attorney General or the Office of Emergency Services may transmit reports of critical safety incidents and reports from covered employees made pursuant to Chapter 5.1 (commencing with Section 1107) of Part 3 of Division 2 of the Labor Code to the Legislature, the Governor, the federal government, or appropriate state agencies.\n(2) The Attorney General or the Office of Emergency Services shall strongly consider any risks related to trade secrets, public safety, cybersecurity of a frontier developer, or national security when transmitting reports.\n(f) A report of a critical safety incident submitted to the Office of Emergency Services pursuant to this section, a report of assessments of catastrophic risk from internal use pursuant to Section 22757.12, and a covered employee report made pursuant to Chapter 5.1 (commencing with Section 1107) of Part 3 of Division 2 of the Labor Code are exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).\n(g) (1) Beginning January 1, 2027, and annually thereafter, the Office of Emergency Services shall produce a report with anonymized and aggregated information about critical safety incidents that have been reviewed by the Office of Emergency Services since the preceding report.\n(2) The Office of Emergency Services shall not include information in a report pursuant to this subdivision that would compromise the trade secrets or cybersecurity of a frontier developer, public safety, or the national security of the United States or that would be prohibited by any federal or state law.\n(3) The Office of Emergency Services shall transmit a report pursuant to this subdivision to the Legislature, pursuant to Section 9795, and to the Governor.\n(h) The Office of Emergency Services may adopt regulations designating one or more federal laws, regulations, or guidance documents that meet all of the following conditions for the purposes of subdivision (i):\n(1) (A) The law, regulation, or guidance document imposes or states standards or requirements for critical safety incident reporting that are substantially equivalent to, or stricter than, those required by this section.\n(B) The law, regulation, or guidance document described in subparagraph (A) does not need to require critical safety incident reporting to the State of California.\n(2) The law, regulation, or guidance document is intended to assess, detect, or mitigate the catastrophic risk.\n(i) (1) A frontier developer that intends to comply with this section by complying with the requirements of, or meeting the standards stated by, a federal law, regulation, or guidance document designated pursuant to subdivision\n(h) shall declare its intent to do so to the Office of Emergency Services.\n(2) After a frontier developer has declared its intent pursuant to paragraph (1), both of the following apply:\n(A) The frontier developer shall be deemed in compliance with this section to the extent that the frontier developer meets the standards of, or complies with the requirements imposed or stated by, the designated federal law, regulation, or guidance document until the frontier developer declares the revocation of that intent to the Office of Emergency Services or the Office of Emergency Services revokes a relevant regulation pursuant to subdivision (j).\n(B) The failure by a frontier developer to meet the standards of, or comply with the requirements stated by, the federal law, regulation, or guidance document designated pursuant to subdivision\n(h) shall constitute a violation of this chapter.\n(j) The Office of Emergency Services shall revoke a regulation adopted under subdivision\n(h) if the requirements of subdivision\n(h) are no longer met.\n22757.14. (a) On or before January 1, 2027, and annually thereafter, the Department of Technology shall assess recent evidence and developments relevant to the purposes of this chapter and shall make recommendations about whether and how to update any of the following definitions for the purposes of this chapter to ensure that they accurately reflect technological developments, scientific literature, and widely accepted national and international standards:\n(1) “Frontier model” so that it applies to foundation models at the frontier of artificial intelligence development.\n(2) “Frontier developer” so that it applies to developers of frontier models who are themselves at the frontier of artificial intelligence development.\n(3) “Large frontier developer” so that it applies to well-resourced frontier developers.\n(b) In making recommendations pursuant to this section, the Department of Technology shall take into account all of the following:\n(1) Similar thresholds used in international standards or federal law, guidance, or regulations for the management of catastrophic risk and shall align with a definition adopted in a federal law or regulation to the extent that it is consistent with the purposes of this chapter.\n(2) Input from stakeholders, including academics, industry, the open-source community, and governmental entities.\n(3) The extent to which a person will be able to determine, before beginning to train or deploy a foundation model, whether that person will be subject to the definition as a frontier developer or as a large frontier developer with an aim toward allowing earlier determinations if possible.\n(4) The complexity of determining whether a person or foundation model is covered, with an aim toward allowing simpler determinations if possible.\n(5) The external verifiability of determining whether a person or foundation model is covered, with an aim toward definitions that are verifiable by parties other than the frontier developer.\n(c) Upon developing recommendations pursuant to this section, the Department of Technology shall submit a report to the Legislature, pursuant to Section 9795 of the Government Code, with those recommendations.\n(d) (1) Beginning January 1, 2027, and annually thereafter, the Attorney General shall produce a report with anonymized and aggregated information about reports from covered employees made pursuant to Chapter 5.1 (commencing with Section 1107) of Part 3 of Division 2 of the Labor Code that have been reviewed by the Attorney General since the preceding report.\n(2) The Attorney General shall not include information in a report pursuant to this subdivision that would compromise the trade secrets or cybersecurity of a frontier developer, confidentiality of a covered employee, public safety, or the national security of the United States or that would be prohibited by any federal or state law.\n(3) The Attorney General shall transmit a report pursuant to this subdivision to the Legislature, pursuant to Section 9795 of the Government Code, and to the Governor.\n22757.15. (a) A large frontier developer that fails to publish or transmit a compliant document required to be published or transmitted under this chapter, makes a statement in violation of subdivision\n(e) of Section 22757.12, fails to report an incident as required by Section 22757.13, or fails to comply with its own frontier AI framework shall be subject to a civil penalty in an amount dependent upon the severity of the violation that does not exceed one million dollars ($1,000,000) per violation.\n(b) A civil penalty described in this section shall be recovered in a civil action brought only by the Attorney General.\n22757.16. The loss of value of equity does not count as damage to or loss of property for the purposes of this chapter.\nSEC. 3. Section 11546.8 is added to the Government Code, to read:\n11546.8. (a) There is hereby established within the Government Operations Agency a consortium that shall develop, pursuant to this section, a framework for the creation of a public cloud computing cluster to be known as “CalCompute.”\n(b) The consortium shall develop a framework for the creation of CalCompute that advances the development and deployment of artificial intelligence that is safe, ethical, equitable, and sustainable by doing, at a minimum, both of the following:\n(1) Fostering research and innovation that benefits the public.\n(2) Enabling equitable innovation by expanding access to computational resources.\n(c) The consortium shall make reasonable efforts to ensure that CalCompute is established within the University of California to the extent possible.\n(d) CalCompute shall include, but not be limited to, all of the following:\n(1) A fully owned and hosted cloud platform.\n(2) Necessary human expertise to operate and maintain the platform.\n(3) Necessary human expertise to support, train, and facilitate the use of CalCompute.\n(e) The consortium shall operate in accordance with all relevant labor and workforce laws and standards.\n(f) (1) On or before January 1, 2027, the Government Operations Agency shall submit, pursuant to Section 9795, a report from the consortium to the Legislature with the framework developed pursuant to subdivision\n(b) for the creation and operation of CalCompute.\n(2) The report required by this subdivision shall include all of the following elements:\n(A) A landscape analysis of California’s current public, private, and nonprofit cloud computing platform infrastructure.\n(B) An analysis of the cost to the state to build and maintain CalCompute and recommendations for potential funding sources.\n(C) Recommendations for the governance structure and ongoing operation of CalCompute.\n(D) Recommendations for the parameters for use of CalCompute, including, but not limited to, a process for determining which users and projects will be supported by CalCompute.\n(E) An analysis of the state’s technology workforce and recommendations for equitable pathways to strengthen the workforce, including the role of CalCompute.\n(F) A detailed description of any proposed partnerships, contracts, or licensing agreements with nongovernmental entities, including, but not limited to, technology-based companies, that demonstrates compliance with the requirements of subdivisions\n(c) and (d).\n(G) Recommendations regarding how the creation and ongoing management of CalCompute can prioritize the use of the current public sector workforce.\n(g) The consortium shall, consistent with state constitutional law, consist of 14 members as follows:\n(1) Four representatives of the University of California and other public and private academic research institutions and national laboratories appointed by the Secretary of Government Operations.\n(2) Three representatives of impacted workforce labor organizations appointed by the Speaker of the Assembly.\n(3) Three representatives of stakeholder groups with relevant expertise and experience, including, but not limited to, ethicists, consumer rights advocates, and other public interest advocates appointed by the Senate Rules Committee.\n(4) Four experts in technology and artificial intelligence to provide technical assistance appointed by the Secretary of Government Operations.\n(h) The members of the consortium shall serve without compensation, but shall be reimbursed for all necessary expenses actually incurred in the performance of their duties.\n(i) The consortium shall be dissolved upon submission of the report required by paragraph (1) of subdivision\n(f) to the Legislature.\n(j) If CalCompute is established within the University of California, the University of California may receive private donations for the purposes of implementing CalCompute.\n(k) This section shall become operative only upon an appropriation in a budget act, or other measure, for the purposes of this section.\nSEC. 4. Chapter 5.1 (commencing with Section 1107) is added to Part 3 of Division 2 of the Labor Code, to read:\nCHAPTER 5.1. Whistleblower Protections: Catastrophic Risks in AI Foundation Models 1107. For purposes of this chapter:\n(a) (1) “Catastrophic risk” means a foreseeable and material risk that a frontier developer’s development, storage, use, or deployment of a foundation model will materially contribute to the death of, or serious injury to, more than 50 people or more than one billion dollars ($1,000,000,000) in damage to, or loss of, property arising from a single incident involving a foundation model doing any of the following:\n(A) Providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon.\n(B) Engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense.\n(C) Evading the control of its frontier developer or user.\n(2) “Catastrophic risk” does not include a foreseeable and material risk from any of the following:\n(A) Information that a foundation model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model.\n(B) Lawful activity of the federal government.\n(C) Harm caused by a foundation model in combination with other software where the foundation model did not materially contribute to the harm.\n(b) “Covered employee” means an employee responsible for assessing, managing, or addressing risk of critical safety incidents.\n(c) “Critical safety incident” means any of the following:\n(1) Unauthorized access to, modification of, or exfiltration of the model weights of a foundation model that results in death, bodily injury, or damage to, or loss of, property.\n(2) Harm resulting from the materialization of a catastrophic risk.\n(3) Loss of control of a foundation model causing death or bodily injury.\n(4) A foundation model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.\n(d) “Foundation model” has the meaning defined in Section 22757.11 of the Business and Professions Code.\n(e) “Frontier developer” has the meaning defined in Section 22757.11 of the Business and Professions Code.\n(f) “Large frontier developer” has the meaning defined in Section 22757.11 of the Business and Professions Code.\n1107.1. (a) A frontier developer shall not make, adopt, enforce, or enter into a rule, regulation, policy, or contract that prevents a covered employee from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee, or another covered employee who has authority to investigate, discover, or correct the reported issue, if the covered employee has reasonable cause to believe that the information discloses either of the following:\n(1) The frontier developer’s activities pose a specific and substantial danger to the public health or safety resulting from a catastrophic risk.\n(2) The frontier developer has violated Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code.\n(b) A frontier developer shall not enter into a contract that prevents a covered employee from making a disclosure protected under Section 1102.5.\n(c) A covered employee may use the hotline described in Section 1102.7 to make reports described in subdivision (a).\n(d) A frontier developer shall provide a clear notice to all covered employees of their rights and responsibilities under this section, including by doing either of the following:\n(1) At all times posting and displaying within any workplace maintained by the frontier developer a notice to all covered employees of their rights under this section, ensuring that any new covered employee receives equivalent notice, and ensuring that any covered employee who works remotely periodically receives an equivalent notice.\n(2) At least once each year, providing written notice to each covered employee of the covered employee’s rights under this section and ensuring that the notice is received and acknowledged by all of those covered employees.\n(e) (1) A large frontier developer shall provide a reasonable internal process through which a covered employee may anonymously disclose information to the large frontier developer if the covered employee believes in good faith that the information indicates that the large frontier developer’s activities present a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the large frontier developer violated Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code, including a monthly update to the person who made the disclosure regarding the status of the large frontier developer’s investigation of the disclosure and the actions taken by the large frontier developer in response to the disclosure.\n(2) (A) Except as provided in subparagraph (B), the disclosures and responses of the process required by this subdivision shall be shared with officers and directors of the large frontier developer at least once each quarter.\n(B) If a covered employee has alleged wrongdoing by an officer or director of the large frontier developer in a disclosure or response, subparagraph (A) shall not apply with respect to that officer or director.\n(f) The court is authorized to award reasonable attorney’s fees to a plaintiff who brings a successful action for a violation of this section.\n(g) In a civil action brought pursuant to this section, once it has been demonstrated by a preponderance of the evidence that an activity proscribed by this section was a contributing factor in the alleged prohibited action against the covered employee, the frontier developer shall have the burden of proof to demonstrate by clear and convincing evidence that the alleged action would have occurred for legitimate, independent reasons even if the covered employee had not engaged in activities protected by this section.\n(h) (1) In a civil action or administrative proceeding brought pursuant to this section, a covered employee may petition the superior court in any county wherein the violation in question is alleged to have occurred, or wherein the person resides or transacts business, for appropriate temporary or preliminary injunctive relief.\n(2) Upon the filing of the petition for injunctive relief, the petitioner shall cause notice thereof to be served upon the person, and thereupon the court shall have jurisdiction to grant temporary injunctive relief as the court deems just and proper.\n(3) In addition to any harm resulting directly from a violation of this section, the court shall consider the chilling effect on other covered employees asserting their rights under this section in determining whether temporary injunctive relief is just and proper.\n(4) Appropriate injunctive relief shall be issued on a showing that reasonable cause exists to believe a violation has occurred.\n(5) An order authorizing temporary injunctive relief shall remain in effect until an administrative or judicial determination or citation has been issued, or until the completion of a review pursuant to subdivision\n(b) of Section 98.74, whichever is longer, or at a certain time set by the court. Thereafter, a preliminary or permanent injunction may be issued if it is shown to be just and proper. Any temporary injunctive relief shall not prohibit a frontier developer from disciplining or terminating a covered employee for conduct that is unrelated to the claim of the retaliation.\n(i) Notwithstanding Section 916 of the Code of Civil Procedure, injunctive relief granted pursuant to this section shall not be stayed pending appeal.\n(j) (1) This section does not impair or limit the applicability of Section 1102.5, including with respect to the rights of employees who are not covered employees to report violations of this chapter or Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code.\n(2) The remedies provided by this section are cumulative to each other and the remedies or penalties available under all other laws of this state.\n1107.2. The loss of value of equity does not count as damage to or loss of property for the purposes of this chapter.\nSEC. 5. (a) The provisions of this act are severable. If any provision of this act or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.\n(b) This act shall be liberally construed to effectuate its purposes.\n(c) The duties and obligations imposed by this act are cumulative with any other duties or obligations imposed under other law and shall not be construed to relieve any party from any duties or obligations imposed under other law and do not limit any rights or remedies under existing law.\n(d) This act shall not apply to the extent that it strictly conflicts with the terms of a contract between a federal government entity and a frontier developer.\n(e) This act shall not apply to the extent that it is preempted by federal law.\n(f) This act preempts any rule, regulation, code, ordinance, or other law adopted by a city, county, city and county, municipality, or local agency on or after January 1, 2025, specifically related to the regulation of frontier developers with respect to their management of catastrophic risk.\nSEC. 6. The Legislature finds and declares that Section 2 of this act, which adds Chapter 25.1 (commencing with Section 22757.10) to Division 8 of the Business and Professions Code, imposes a limitation on the public’s right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:\nInformation in critical safety incident reports, assessments of risks from internal use, and reports from covered employees may contain information that could threaten public safety or compromise the response to an incident if disclosed to the public.\n","permalink":"https://ai.intlaws.com/en/compliance/us/california-sb-53/","summary":"Official text of California Senate Bill 53 (2025–2026 session), which adds transparency and incident-reporting duties for developers of large frontier artificial intelligence models — amending the Business and Professions Code (new Chapter 25.1, commencing with Section 22757.10), the Government Code (Section 11546.8) and the Labor Code (new Chapter 5.1, commencing with Section 1107). Registered with the Secretary of State on 29 September 2025.","title":"California Transparency in Frontier Artificial Intelligence Act (TFAIA)"},{"content":"Version and sources (verifiable)\nItem Content Instrument Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data Reference ETS No. 108 (European Treaty Series No. 108) Opened for signature Strasbourg, 28 January 1981 Structure 7 chapters, 20 articles Status This page reproduces the original 1981 text. The Convention has since been modernised by Protocol CETS No. 223 (\u0026ldquo;Convention 108+\u0026rdquo;) — see the separate entry in this library. The amending Protocol has NOT yet entered into force: as of 2026-09-22, 34 of the required 38 ratifications have been deposited (or ratification by all ETS 108 Parties is required) — Council of Europe announcement Official text (English) https://rm.coe.int/1680078b37 (Council of Europe document repository) Treaty Office record https://www.coe.int/en/web/conventions/full-list?module=treaty-detail\u0026amp;treatynum=108 Official name Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108, 1981) Chinese version No official Chinese text (official languages: English and French). A Chinese translation by our editorial team is in preparation and will be marked non-official. Retrieval \u0026amp; verification 2026-09-22, retrieved through a rendering proxy (r.jina.ai) because the Council of Europe blocks automated direct access from this network. Text de-hyphenated; the two-column PDF layout merges chapter and article headings on one line, so those lines were split before parsing; article numbers accepted only in strict ascending order (1–20) to exclude cross-references. | 中文译本 | 无官方中文译本（欧洲理事会官方文本为英文、法文两种同等作准文本）。本页中文译文由本网据官方英文文本逐条译校，为非官方译本、仅供参考 → 中文全文 |\nConvention for the Protection of Individuals with regard to Automatic Processing of Personal Data Preamble — The member States of the Council of Europe, signatory hereto, considering that the aim of the Council of Europe is to achieve greater unity between its members, based in particular on respect for the rule of law, as well as human rights and fundamental freedoms; considering that it is desirable to extend the safeguards for everyone\u0026rsquo;s rights and fundamental freedoms, and in particular the right to the respect for privacy, taking account of the increasing flow across frontiers of personal data undergoing automatic processing; reaffirming at the same time their commitment to freedom of information regardless of frontiers; recognising that it is necessary to reconcile the fundamental values of the respect for privacy and the free flow of information between peoples, have agreed as follows:\nPreamble — # Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data The member States of the Council of Europe, signatory hereto, Considering that the aim of the Council of Europe is to achieve greater unity between its members, based in particular on respect for the rule of law, as well as human rights and fundamental freedoms; Considering that it is desirable to extend the safeguards for everyone\u0026rsquo;s rights and fundamental freedoms, and in particular the right to the respect for privacy, taking account of the increasing flow across frontiers of personal data undergoing automatic processing; Reaffirming at the same time their commitment to freedom of information regardless of frontiers; Recognising that it is necessary to reconcile the fundamental values of the respect for privacy and the free flow of information between peoples, Have agreed as follows:\nChapter I – General provisions Article 1 – Object and purpose\nThe purpose of this Convention is to secure in the territory of each Party for every individual, whatever his nationality or residence, respect for his rights and fundamental freedoms, and in particular his right to privacy, with regard to automatic processing of personal data relating to him (\u0026ldquo;data protection\u0026rdquo;).\nArticle 2 – Definitions\nFor the purposes of this Convention:\n(a) \u0026ldquo;personal data\u0026rdquo; means any information relating to an identified or identifiable individual (\u0026ldquo;data subject\u0026rdquo;);\n(b) \u0026ldquo;automated data file\u0026rdquo; means any set of data undergoing automatic processing;\n(c) \u0026ldquo;automatic processing\u0026rdquo; includes the following operations if carried out in whole or in part by automated means: storage of data, carrying out of logical and/or arithmetical operations on those data, their alteration, erasure, retrieval or dissemination;\n(d) \u0026ldquo;controller of the file\u0026rdquo; means the natural or legal person, public authority, agency or any other body who is competent according to the national law to decide what should be the purpose of the automated data file, which categories of personal data should be stored and which operations should be applied to them.\nArticle 3 – Scope\n(1) The Parties undertake to apply this Convention to automated personal data files and automatic processing of personal data in the public and private sectors.\n(2) Any State may, at the time of signature or when depositing its instrument of ratification, acceptance, approval or accession, or at any later time, give notice by a declaration addressed to the Secretary General of the Council of Europe:\n(a) that it will not apply this Convention to certain categories of automated personal data files, a list of which will be deposited. In this list it shall not include, however, categories of automated data files subject under its domestic law to data protection provisions. Consequently, it shall amend this list by a new declaration whenever additional categories of automated personal data files are subjected to data protection provisions under its domestic law;\n(b) that it will also apply this Convention to information relating to groups of persons, associations, foundations, companies, corporations and any other bodies consisting directly or indirectly of individuals, whether or not such bodies possess legal personality;\n(c) that it will also apply this Convention to personal data files which are not processed automatically.\n(3) Any State which has extended the scope of this Convention by any of the declarations provided for in sub-paragraph 2.b or c above may give notice in the said declaration that such extensions shall apply only to certain categories of personal data files, a list of which will be deposited.\n(4) Any Party which has excluded certain categories of automated personal data files by a declaration provided for in sub-paragraph 2.a above may not claim the application of this Convention to such categories by a Party which has not excluded them.\n(5) Likewise, a Party which has not made one or other of the extensions provided for in sub-paragraphs 2.b and c above may not claim the application of this Convention on these points with respect to a Party which has made such extensions.\n(6) The declarations provided for in paragraph 2 above shall take effect from the moment of the entry into force of the Convention with regard to the State which has made them if they have been made at the time of signature or deposit of its instrument of ratification, acceptance, approval or accession, or three months after their receipt by the Secretary General of the Council of Europe if they have been made at any later time. These declarations may be withdrawn, in whole or in part, by a notification addressed to the Secretary General of the Council of Europe. Such withdrawals shall take effect three months after the date of receipt of such notification.\nChapter II – Basic principles for data protection Article 4 – Duties of the Parties\n(1) Each Party shall take the necessary measures in its domestic law to give effect to the basic principles for data protection set out in this chapter.\n(2) These measures shall be taken at the latest at the time of entry into force of this Convention in respect of that Party.\nArticle 5 – Quality of data\nPersonal data undergoing automatic processing shall be:\n(a) obtained and processed fairly and lawfully;\n(b) stored for specified and legitimate purposes and not used in a way incompatible with those purposes;\n(c) adequate, relevant and not excessive in relation to the purposes for which they are stored;\n(d) accurate and, where necessary, kept up to date;\n(e) preserved in a form which permits identification of the data subjects for no longer than is required for the purpose for which those data are stored.\nArticle 6 – Special categories of data\nPersonal data revealing racial origin, political opinions or religious or other beliefs, as well as personal data concerning health or sexual life, may not be processed automatically unless domestic law provides appropriate safeguards. The same shall apply to personal data relating to criminal convictions.\nArticle 7 – Data security\nAppropriate security measures shall be taken for the protection of personal data stored in automated data files against accidental or unauthorised destruction or accidental loss as well as against unauthorised access, alteration or dissemination.\nArticle 8 – Additional safeguards for the data subject\nAny person shall be enabled:\n(a) to establish the existence of an automated personal data file, its main purposes, as well as the identity and habitual residence or principal place of business of the controller of the file;\n(b) to obtain at reasonable intervals and without excessive delay or expense confirmation of whether personal data relating to him are stored in the automated data file as well as communication to him of such data in an intelligible form;\n(c) to obtain, as the case may be, rectification or erasure of such data if these have been processed contrary to the provisions of domestic law giving effect to the basic principles set out in Articles 5 and 6 of this Convention;\n(d) to have a remedy if a request for confirmation or, as the case may be, communication, rectification or erasure as referred to in paragraphs b and c of this article is not complied with.\nArticle 9 – Exceptions and restrictions\n(1) No exception to the provisions of Articles 5, 6 and 8 of this Convention shall be allowed except within the limits defined in this article.\n(2) Derogation from the provisions of Articles 5, 6 and 8 of this Convention shall be allowed when such derogation is provided for by the law of the Party and constitutes a necessary measure in a democratic society in the interests of:\n(a) protecting State security, public safety, the monetary interests of the State or the suppression of criminal offences;\n(b) protecting the data subject or the rights and freedoms of others.\n(3) Restrictions on the exercise of the rights specified in Article 8, paragraphs b, c and d, may be provided by law with respect to automated personal data files used for statistics or for scientific research purposes when there is obviously no risk of an infringement of the privacy of the data subjects.\nArticle 10 – Sanctions and remedies\nEach Party undertakes to establish appropriate sanctions and remedies for violations of provisions of domestic law giving effect to the basic principles for data protection set out in this chapter.\nArticle 11 – Extended protection\nNone of the provisions of this chapter shall be interpreted as limiting or otherwise affecting the possibility for a Party to grant data subjects a wider measure of protection than that stipulated in this Convention.\nChapter III – Transborder data flows Article 12 – Transborder flows of personal data and domestic law\n(1) The following provisions shall apply to the transfer across national borders, by whatever medium, of personal data undergoing automatic processing or collected with a view to their being automatically processed.\n(2) A Party shall not, for the sole purpose of the protection of privacy, prohibit or subject to special authorisation transborder flows of personal data going to the territory of another Party.\n(3) Nevertheless, each Party shall be entitled to derogate from the provisions of paragraph 2:\n(a) insofar as its legislation includes specific regulations for certain categories of personal data or of automated personal data files, because of the nature of those data or those files, except where the regulations of the other Party provide an equivalent protection;\n(b) when the transfer is made from its territory to the territory of a non-Contracting State through the intermediary of the territory of another Party, in order to avoid such transfers resulting in circumvention of the legislation of the Party referred to at the beginning of this paragraph.\nChapter IV – Mutual assistance Article 13 – Co-operation between Parties\n(1) The Parties agree to render each other mutual assistance in order to implement this Convention.\n(2) For that purpose:\n(a) each Party shall designate one or more authorities, the name and address of each of which it shall communicate to the Secretary General of the Council of Europe;\n(b) each Party which has designated more than one authority shall specify in its communication referred to in the previous sub-paragraph the competence of each authority.\n(3) An authority designated by a Party shall at the request of an authority designated by another Party:\n(a) furnish information on its law and administrative practice in the field of data protection;\n(b) take, in conformity with its domestic law and for the sole purpose of protection of privacy, all appropriate measures for furnishing factual information relating to specific automatic processing carried out in its territory, with the exception however of the personal data being processed.\nArticle 14 – Assistance to data subjects resident abroad\n(1) Each Party shall assist any person resident abroad to exercise the rights conferred by its domestic law giving effect to the principles set out in Article 8 of this Convention.\n(2) When such a person resides in the territory of another Party he shall be given the option of submitting his request through the intermediary of the authority designated by that Party.\n(3) The request for assistance shall contain all the necessary particulars, relating inter alia to:\n(a) the name, address and any other relevant particulars identifying the person making the request;\n(b) the automated personal data file to which the request pertains, or its controller; c the purpose of the request.\nArticle 15 – Safeguards concerning assistance rendered by designated authorities\n(1) An authority designated by a Party which has received information from an authority designated by another Party either accompanying a request for assistance or in reply to its own request for assistance shall not use that information for purposes other than those specified in the request for assistance.\n(2) Each Party shall see to it that the persons belonging to or acting on behalf of the designated authority shall be bound by appropriate obligations of secrecy or confidentiality with regard to that information.\n(3) In no case may a designated authority be allowed to make under Article 14, paragraph 2, a request for assistance on behalf of a data subject resident abroad, of its own accord and without the express consent of the person concerned.\nArticle 16 – Refusal of requests for assistance\nA designated authority to which a request for assistance is addressed under Articles 13 or 14 of this Convention may not refuse to comply with it unless:\n(a) the request is not compatible with the powers in the field of data protection of the authorities responsible for replying;\n(b) the request does not comply with the provisions of this Convention;\n(c) compliance with the request would be incompatible with the sovereignty, security or public policy ( ordre public ) of the Party by which it was designated, or with the rights and fundamental freedoms of persons under the jurisdiction of that Party.\nArticle 17 – Costs and procedures of assistance\n(1) Mutual assistance which the Parties render each other under Article 13 and assistance they render to data subjects abroad under Article 14 shall not give rise to the payment of any costs or fees other than those incurred for experts and interpreters. The latter costs or fees shall be borne by the Party which has designated the authority making the request for assistance.\n(2) The data subject may not be charged costs or fees in connection with the steps taken on his behalf in the territory of another Party other than those lawfully payable by residents of that Party.\n(3) Other details concerning the assistance relating in particular to the forms and procedures and the languages to be used, shall be established directly between the Parties concerned.\nChapter V – Consultative Committee Article 18 – Composition of the committee\n(1) A Consultative Committee shall be set up after the entry into force of this Convention.\n(2) Each Party shall appoint a representative to the committee and a deputy representative. Any member State of the Council of Europe which is not a Party to the Convention shall have the right to be represented on the committee by an observer.\n(3) The Consultative Committee may, by unanimous decision, invite any non-member State of the Council of Europe which is not a Party to the Convention to be represented by an observer at a given meeting.\nArticle 19 – Functions of the committee\nThe Consultative Committee:\n(a) may make proposals with a view to facilitating or improving the application of the Convention;\n(b) may make proposals for amendment of this Convention in accordance with Article 21;\n(c) shall formulate its opinion on any proposal for amendment of this Convention which is referred to it in accordance with Article 21, paragraph 3;\n(d) may, at the request of a Party, express an opinion on any question concerning the application of this Convention.\nArticle 20 – Procedure\n(1) The Consultative Committee shall be convened by the Secretary General of the Council of Europe. Its first meeting shall be held within twelve months of the entry into force of this Convention. It shall subsequently meet at least once every two years and in any case when one-third of the representatives of the Parties request its convocation.\n(2) A majority of representatives of the Parties shall constitute a quorum for a meeting of the Consultative Committee.\n(3) After each of its meetings, the Consultative Committee shall submit to the Committee of Ministers of the Council of Europe a report on its work and on the functioning of the Convention.\n(4) Subject to the provisions of this convention, the Consultative Committee shall draw up its own Rules of Procedure.\nChapter VI – Amendments Article 21 – Amendments\n(1) Amendments to this Convention may be proposed by a Party, the Committee of Ministers of the Council of Europe or the Consultative Committee.\n(2) Any proposal for amendment shall be communicated by the Secretary General of the Council of Europe to the member States of the Council of Europe and to every non-member State which has acceded to or has been invited to accede to this Convention in accordance with the provisions of Article 23.\n(3) Moreover, any amendment proposed by a Party or the Committee of Ministers shall be communicated to the Consultative Committee, which shall submit to the Committee of Ministers its opinion on that proposed amendment.\n(4) The Committee of Ministers shall consider the proposed amendment and any opinion submitted by the Consultative Committee and may approve the amendment.\n(5) The text of any amendment approved by the Committee of Ministers in accordance with paragraph 4 of this article shall be forwarded to the Parties for acceptance.\n(6) Any amendment approved in accordance with paragraph 4 of this article shall come into force on the thirtieth day after all Parties have informed the Secretary General of their acceptance thereof.\nChapter VII – Final clauses Article 22 – Entry into force\n(1) This Convention shall be open for signature by the member States of the Council of Europe. It is subject to ratification, acceptance or approval. Instruments of ratification, acceptance or approval shall be deposited with the Secretary General of the Council of Europe.\n(2) This Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date on which five member States of the Council of Europe have expressed their consent to be bound by the Convention in accordance with the provisions of the preceding paragraph.\n(3) In respect of any member State which subsequently expresses its consent to be bound by it, the Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date of deposit of the instrument of ratification, acceptance or approval.\nArticle 23 – Accession by non-member States\n(1) After the entry into force of this Convention, the Committee of Ministers of the Council of Europe may invite any State not a member of the Council of Europe to accede to this Convention by a decision taken by the majority provided for in Article 20.d of the Statute of the Council of Europe and by the unanimous vote of the representatives of the Contracting States entitled to sit on the committee.\n(2) In respect of any acceding State, the Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date of deposit of the instrument of accession with the Secretary General of the Council of Europe.\nArticle 24 – Territorial clause\n(1) Any State may at the time of signature or when depositing its instrument of ratification, acceptance, approval or accession, specify the territory or territories to which this Convention shall apply.\n(2) Any State may at any later date, by a declaration addressed to the Secretary General of the Council of Europe, extend the application of this Convention to any other territory specified in the declaration. In respect of such territory the Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date of receipt of such declaration by the Secretary General.\n(3) Any declaration made under the two preceding paragraphs may, in respect of any territory specified in such declaration, be withdrawn by a notification addressed to the Secretary General. The withdrawal shall become effective on the first day of the month following the expiration of a period of six months after the date of receipt of such notification by the Secretary General.\nArticle 25 – Reservations\nNo reservation may be made in respect of the provisions of this Convention.\nArticle 26 – Denunciation\n(1) Any Party may at any time denounce this Convention by means of a notification addressed to the Secretary General of the Council of Europe.\n(2) Such denunciation shall become effective on the first day of the month following the expiration of a period of six months after the date of receipt of the notification by the Secretary General.\nArticle 27 – Notifications\nThe Secretary General of the Council of Europe shall notify the member States of the Council and any State which has acceded to this Convention of:\n(a) any signature;\n(b) the deposit of any instrument of ratification, acceptance, approval or accession;\n(c) any date of entry into force of this Convention in accordance with Articles 22, 23 and 24;\n(d) any other act, notification or communication relating to this Convention. In witness whereof the undersigned, being duly authorised thereto, have signed this Convention. Done at Strasbourg, the 28th day of January 1981, in English and in French, both texts being equally authoritative, in a single copy which shall remain deposited in the archives of the Council of Europe. The Secretary General of the Council of Europe shall transmit certified copies to each member State of the Council of Europe and to any State invited to accede to this Convention.\n","permalink":"https://ai.intlaws.com/en/compliance/intl/coe-convention-108/","summary":"Official English text of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108), opened for signature in Strasbourg on 28 January 1981 — the first binding international instrument on data protection, comprising 20 articles. The Convention as modernised by Protocol CETS No. 223 (\u0026ldquo;Convention 108+\u0026rdquo;) is published separately in this library.","title":"Convention 108"},{"content":" Version and sources (verifiable)\nItem Content Original law adopted 7 November 2016, effective 1 June 2017 Amendment Decision on Amending the Cybersecurity Law of the People\u0026rsquo;s Republic of China adopted 28 October 2025 Version this page contains the consolidated amended text, effective 1 January 2026 Structure 7 chapters, 81 articles Key amendments new Article 3 (CPC leadership; holistic approach to national security); new Article 20 (artificial intelligence); new Article 63 (penalties for uncertified critical network equipment); penalty caps raised to RMB 10 million in the most serious cases; article numbering re-ordered throughout — always cite the version Chinese original CAC — amended text ; amendment decision English version No official English translation of the 2025 amendment has been published. This English text is a translation by our editorial team cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 81 articles, no gaps; chapter and section structure verified against the official text Chapter I General provisions Article 1 This Law is enacted for the purposes of safeguarding cybersecurity, maintaining cyberspace sovereignty and national security and public interests, protecting the lawful rights and interests of citizens, legal persons and other organisations, and promoting the sound development of the information economy and society.\nArticle 2 This Law applies to the construction, operation, maintenance and use of networks within the territory of the People\u0026rsquo;s Republic of China, and to the supervision and administration of cybersecurity.\nArticle 3 Cybersecurity work upholds the leadership of the Communist Party of China, implements the holistic approach to national security, coordinates development and security, and advances the building of a strong cyber power.\nArticle 4 The State attaches equal importance to cybersecurity and the development of informatisation, follows the principles of active use, scientific development, administration in accordance with law and ensuring security, promotes the construction of cyber infrastructure and interconnection, encourages innovation in and application of cyber technology, supports the training of cybersecurity professionals, and establishes and improves a cybersecurity assurance system so as to enhance cybersecurity protection capacity.\nArticle 5 The State formulates and continuously improves the national cybersecurity strategy, defines the basic requirements and main objectives for safeguarding cybersecurity, and sets out cybersecurity policies, tasks and measures for key areas.\nArticle 6 The State takes measures to monitor, defend against and handle cybersecurity risks and threats originating within and outside the territory of the People\u0026rsquo;s Republic of China, protects critical information infrastructure against attacks, intrusions, interference and destruction, and punishes cybercrime and unlawful activities in accordance with law so as to maintain security and order in cyberspace.\nArticle 7 The State advocates honesty, credibility, healthy and civilised online conduct, promotes the dissemination of the core socialist values, and takes measures to raise the cybersecurity awareness and standards of society as a whole, so as to create a favourable environment in which all of society participates in promoting cybersecurity.\nArticle 8 The State actively carries out international exchanges and cooperation in cyberspace governance, research and development of cyber technology and formulation of standards, and combating cybercrime and unlawful activities, promotes the building of a peaceful, secure, open and cooperative cyberspace, and works to establish a multilateral, democratic and transparent system of cyberspace governance.\nArticle 9 The national cyberspace administration department is responsible for coordinating cybersecurity work and the related supervision and administration. The telecommunications department of the State Council, the public security department and other relevant authorities are responsible, within the scope of their respective duties, for cybersecurity protection and supervision and administration in accordance with this Law and the provisions of relevant laws and administrative regulations.\nThe cybersecurity protection and supervision and administration duties of the relevant departments of local people\u0026rsquo;s governments at or above the county level shall be determined in accordance with the relevant provisions of the State.\nArticle 10 In conducting business and service activities, network operators shall comply with laws and administrative regulations, respect public order and good morals, observe business ethics, act in good faith, perform their cybersecurity protection obligations, accept supervision by the government and society, and bear social responsibility.\nArticle 11 In constructing or operating networks or providing services through networks, technical measures and other necessary measures shall be taken in accordance with laws, administrative regulations and the mandatory requirements of national standards to safeguard cybersecurity and stable operation, effectively respond to cybersecurity incidents, prevent and combat cybercrime and unlawful activities, and maintain the integrity, confidentiality and availability of network data.\nArticle 12 Network-related industry organisations shall, in accordance with their articles of association, strengthen industry self-regulation, formulate norms of cybersecurity conduct, guide their members in strengthening cybersecurity protection, raise the level of cybersecurity protection and promote the sound development of the industry.\nArticle 13 The State protects the right of citizens, legal persons and other organisations to use networks in accordance with law, promotes the spread of network access, improves network service standards, provides society with secure and convenient network services, and safeguards the lawful, orderly and free flow of network information.\nAny individual or organisation using a network shall comply with the Constitution and laws, observe public order, respect public morality, and must not endanger cybersecurity or use networks to engage in activities that endanger national security, honour and interests; incite subversion of State power or overthrow of the socialist system; incite secession or undermine national unity; propagate terrorism or extremism; propagate ethnic hatred or ethnic discrimination; disseminate violent or obscene and pornographic information; fabricate or disseminate false information disrupting economic and social order; or infringe the reputation, privacy, intellectual property rights or other lawful rights and interests of others.\nArticle 14 The State supports the research, development and provision of network products and services conducive to the healthy growth of minors, punishes in accordance with law the use of networks for activities harmful to the physical and mental health of minors, and provides minors with a secure and healthy network environment.\nArticle 15 Any individual or organisation has the right to report conduct endangering cybersecurity to the cyberspace administration, telecommunications and public security departments. Departments receiving such reports shall handle them promptly in accordance with law; where a report falls outside their duties, they shall promptly transfer it to the competent department.\nThe relevant departments shall keep confidential the information of the reporting person and protect the reporting person\u0026rsquo;s lawful rights and interests.\nChapter II Support for and promotion of cybersecurity Article 16 The State establishes and improves the cybersecurity standards system. The administrative department for standardisation of the State Council and other relevant departments of the State Council shall, in accordance with their respective duties, organise the formulation and timely revision of national and industry standards relating to cybersecurity administration and the security of network products, services and operation.\nThe State supports enterprises, research institutions, institutions of higher education and network-related industry organisations in participating in the formulation of national and industry cybersecurity standards.\nArticle 17 The State Council and the people\u0026rsquo;s governments of provinces, autonomous regions and municipalities directly under the Central Government shall, through overall planning, increase investment, support key cybersecurity technology industries and projects, support the research, development and application of cybersecurity technology, promote secure and trustworthy network products and services, protect intellectual property rights in network technology, and support enterprises, research institutions and institutions of higher education in participating in national cybersecurity technology innovation projects.\nArticle 18 The State promotes the building of a socialised cybersecurity service system and encourages relevant enterprises and institutions to carry out security services such as cybersecurity certification, testing and risk assessment.\nArticle 19 The State encourages the development of technologies for the protection and exploitation of network data security, promotes the opening of public data resources, and drives technological innovation and economic and social development.\nArticle 20 The State supports basic theoretical research on artificial intelligence and the research and development of key technologies such as algorithms, advances the construction of infrastructure including training data resources and computing power, improves ethical norms for artificial intelligence, strengthens risk monitoring, assessment and security regulation, and promotes the application and healthy development of artificial intelligence.\nThe State supports innovation in cybersecurity management methods and the use of new technologies such as artificial intelligence to raise the level of cybersecurity protection.\nArticle 21 People\u0026rsquo;s governments at all levels and their relevant departments shall organise and carry out regular cybersecurity publicity and education, and guide and urge relevant entities to perform cybersecurity publicity and education work well.\nThe mass media shall carry out targeted cybersecurity publicity and education for the public.\nArticle 22 The State supports enterprises and institutions of higher education, vocational schools and other education and training institutions in carrying out cybersecurity-related education and training, cultivates cybersecurity professionals in various ways, and promotes the exchange of cybersecurity professionals.\nChapter III Network operation security Section 1 General provisions Article 23 The State applies a system of classified protection for cybersecurity. Network operators shall, in accordance with the requirements of the classified protection system for cybersecurity, perform the following security protection obligations to protect networks against interference, destruction or unauthorised access and to prevent network data from being leaked, stolen or tampered with:\n(1) formulate internal security management systems and operating procedures, designate a person responsible for cybersecurity, and implement cybersecurity protection responsibilities;\n(2) adopt technical measures to prevent computer viruses, cyber attacks, network intrusions and other conduct endangering cybersecurity;\n(3) adopt technical measures to monitor and record network operation status and cybersecurity incidents, and retain the relevant network logs for not less than six months as required;\n(4) adopt measures such as data classification, backup of important data and encryption;\n(5) other obligations provided for by laws and administrative regulations.\nArticle 24 Network products and services shall comply with the mandatory requirements of relevant national standards. Providers of network products and services must not install malicious programs; where they discover risks such as security defects or vulnerabilities in their network products or services, they shall immediately take remedial measures, promptly inform users and report to the competent departments as required.\nProviders of network products and services shall continuously provide security maintenance for their products and services; within the period prescribed or agreed by the parties, they must not terminate the provision of security maintenance.\nWhere network products or services have the function of collecting user information, their providers shall expressly inform users and obtain their consent; where personal information of users is involved, the provisions of this Law and relevant laws and administrative regulations on the protection of personal information shall also be complied with.\nArticle 25 Critical network equipment and specialised cybersecurity products shall be sold or provided only after passing security certification by a qualified institution or meeting the requirements of security testing in accordance with the mandatory requirements of relevant national standards. The national cyberspace administration department, together with the relevant departments of the State Council, formulates and publishes the catalogue of critical network equipment and specialised cybersecurity products, and promotes mutual recognition of security certification and security testing results so as to avoid duplicated certification and testing.\nArticle 26 Where a network operator handles network access or domain name registration services for a user, handles network access formalities such as fixed-line and mobile telephony, or provides a user with services such as information publication or instant messaging, it shall require the user to provide true identity information when concluding an agreement with the user or confirming the provision of services. Where a user does not provide true identity information, the network operator must not provide the relevant services to that user.\nThe State implements a trusted identity strategy for networks, supports the research, development and provision of secure and convenient electronic identity authentication technologies, and promotes mutual recognition among different electronic identity authentication systems.\nArticle 27 Network operators shall formulate emergency response plans for cybersecurity incidents and promptly handle security risks such as system vulnerabilities, computer viruses, cyber attacks and network intrusions; when an incident endangering cybersecurity occurs, they shall immediately activate the emergency response plan, take corresponding remedial measures and report to the competent departments as required.\nArticle 28 Conducting activities such as cybersecurity certification, testing and risk assessment, and releasing to the public cybersecurity information such as system vulnerabilities, computer viruses, cyber attacks and network intrusions, shall comply with the relevant provisions of the State.\nArticle 29 No individual or organisation may engage in activities endangering cybersecurity such as unlawfully intruding into another\u0026rsquo;s network, interfering with the normal functions of another\u0026rsquo;s network, or stealing network data; nor provide programs or tools specifically used for such activities as intruding into networks, interfering with the normal functions of networks and protective measures, or stealing network data; where a person knows that another is engaged in activities endangering cybersecurity, the person must not provide technical support, advertising promotion, payment and settlement or other assistance to that other person.\nArticle 30 Network operators shall provide technical support and assistance to public security organs and State security organs in their activities to safeguard national security and investigate crimes in accordance with law.\nArticle 31 The State supports cooperation among network operators in the collection, analysis, notification and emergency handling of cybersecurity information so as to enhance network operators\u0026rsquo; security assurance capability.\nRelevant industry organisations shall establish and improve cybersecurity protection norms and cooperation mechanisms for their industries, strengthen analysis and assessment of cybersecurity risks, periodically issue risk warnings to their members, and support and assist their members in responding to cybersecurity risks.\nArticle 32 Information obtained by the cyberspace administration departments and relevant departments in the performance of cybersecurity protection duties may only be used for the needs of maintaining cybersecurity and must not be used for other purposes.\nSection 2 Security of the operation of critical information infrastructure Article 33 On the basis of the classified protection system for cybersecurity, the State applies key protection to critical information infrastructure in important industries and fields such as public communications and information services, energy, transport, water conservancy, finance, public services and e-government, and other critical information infrastructure which, once destroyed, losing its function or suffering data leakage, may seriously endanger national security, the national economy and people\u0026rsquo;s livelihood, or the public interest. The specific scope of critical information infrastructure and the measures for its security protection shall be formulated by the State Council.\nThe State encourages network operators other than those of critical information infrastructure to participate voluntarily in the critical information infrastructure protection system.\nArticle 34 In accordance with the division of duties prescribed by the State Council, the departments responsible for the security protection of critical information infrastructure shall respectively prepare and organise the implementation of security plans for critical information infrastructure in their respective industries and fields, and guide and supervise the security protection of the operation of critical information infrastructure.\nArticle 35 The construction of critical information infrastructure shall ensure that it has the performance to support stable and continuous business operation, and shall ensure that security technical measures are planned, built and put into use simultaneously.\nArticle 36 In addition to the provisions of Article 23 of this Law, operators of critical information infrastructure shall also perform the following security protection obligations:\n(1) establish a dedicated security management body and a security management officer, and conduct security background checks on that officer and personnel in key positions;\n(2) periodically conduct cybersecurity education, technical training and skills assessment for employees;\n(3) carry out disaster recovery backup for important systems and databases;\n(4) formulate emergency response plans for cybersecurity incidents and conduct regular drills;\n(5) other obligations provided for by laws and administrative regulations.\nArticle 37 Where the procurement of network products and services by an operator of critical information infrastructure may affect national security, it shall undergo a national security review organised by the national cyberspace administration department together with the relevant departments of the State Council.\nArticle 38 Operators of critical information infrastructure shall, as required, conclude security and confidentiality agreements with providers when procuring network products and services, clarifying security and confidentiality obligations and responsibilities.\nArticle 39 Personal information and important data collected and generated by operators of critical information infrastructure in the course of their operations within the territory of the People\u0026rsquo;s Republic of China shall be stored within the territory. Where it is truly necessary to provide them abroad for business needs, a security assessment shall be conducted in accordance with the measures formulated by the national cyberspace administration department together with the relevant departments of the State Council; where laws and administrative regulations provide otherwise, those provisions shall prevail.\nArticle 40 Operators of critical information infrastructure shall, by themselves or by engaging a cybersecurity service institution, conduct at least one testing and assessment each year of the security of their networks and of possible risks, and submit the testing and assessment results and improvement measures to the department responsible for the security protection of critical information infrastructure.\nArticle 41 The national cyberspace administration department shall coordinate the relevant departments in taking the following measures for the security protection of critical information infrastructure:\n(1) conduct spot checks and testing of the security risks of critical information infrastructure, propose improvement measures, and, where necessary, engage cybersecurity service institutions to test and assess security risks existing in the networks;\n(2) periodically organise operators of critical information infrastructure to conduct cybersecurity emergency drills to improve their capacity to respond to cybersecurity incidents and their coordination capabilities;\n(3) promote the sharing of cybersecurity information among relevant departments, operators of critical information infrastructure, relevant research institutions and cybersecurity service institutions;\n(4) provide technical support and assistance for the emergency handling of cybersecurity incidents and the restoration of network functions.\nChapter IV Network information security Article 42 Network operators shall keep strictly confidential the user information they collect and shall establish and improve user information protection systems.\nIn processing personal information, network operators shall comply with the provisions of this Law, the Civil Code of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and administrative regulations.\nArticle 43 Network operators shall, in collecting and using personal information, follow the principles of lawfulness, legitimacy and necessity, publicly disclose their rules for collection and use, expressly state the purpose, method and scope of collecting and using the information, and obtain the consent of the person whose information is collected.\nNetwork operators must not collect personal information unrelated to the services they provide, must not collect or use personal information in violation of laws and administrative regulations or contrary to the agreement between the parties, and shall handle the personal information they retain in accordance with laws and administrative regulations and their agreement with users.\nArticle 44 Network operators must not divulge, tamper with or destroy the personal information they collect; they must not provide personal information to others without the consent of the person whose information is collected, except where the information cannot identify a specific person and cannot be restored after processing.\nNetwork operators shall adopt technical measures and other necessary measures to ensure the security of the personal information they collect and to prevent leakage, destruction or loss of information. Where personal information is or may be leaked, destroyed or lost, they shall immediately take remedial measures, promptly inform users as required and report to the competent departments.\nArticle 45 Where an individual discovers that a network operator collects or uses his or her personal information in violation of laws and administrative regulations or of the agreement between the parties, the individual has the right to require the network operator to delete the personal information; where the personal information collected or stored by the network operator is erroneous, the individual has the right to require the network operator to correct it. Network operators shall take measures to delete or correct it.\nArticle 46 No individual or organisation may steal or obtain personal information by other unlawful means, or unlawfully sell or unlawfully provide personal information to others.\nArticle 47 Departments with cybersecurity supervision and administration duties in accordance with law and their staff must keep strictly confidential the personal information, privacy and trade secrets learned in the performance of their duties, and must not divulge, sell or unlawfully provide them to others.\nArticle 48 Every individual and organisation shall be responsible for its conduct in using networks, and must not set up websites or communication groups for committing fraud, teaching criminal methods, or producing or selling prohibited or controlled items or other illegal or criminal activities, and must not use networks to publish information involving the commission of fraud, the production or sale of prohibited or controlled items, or other illegal or criminal activities.\nArticle 49 Network operators shall strengthen the administration of information published by their users, and where they discover information whose publication or transmission is prohibited by laws and administrative regulations, they shall immediately stop transmitting that information, take measures such as elimination, prevent the spread of the information, preserve the relevant records and report to the competent departments.\nArticle 50 Electronic information sent and application software provided by any individual or organisation must not contain malicious programs or information whose publication or transmission is prohibited by laws and administrative regulations.\nProviders of electronic information sending services and providers of application software download services shall perform their security management obligations, and where they know that their users have committed the acts specified in the preceding paragraph, they shall stop providing services, take measures such as elimination, preserve the relevant records and report to the competent departments.\nArticle 51 Network operators shall establish complaint and reporting systems for network information security, publish information on how to make complaints and reports, and promptly accept and handle complaints and reports concerning network information security.\nNetwork operators shall cooperate with the supervision and inspection carried out by cyberspace administration departments and relevant departments in accordance with law.\nArticle 52 Where the national cyberspace administration department and relevant departments, in performing their network information security supervision and administration duties in accordance with law, discover information whose publication or transmission is prohibited by laws and administrative regulations, they shall require network operators to stop transmitting it, take measures such as elimination and preserve relevant records; for such information originating outside the territory of the People\u0026rsquo;s Republic of China, they shall notify the relevant institutions to take technical measures and other necessary measures to block its dissemination.\nChapter V Monitoring, early warning and emergency handling Article 53 The State establishes systems for cybersecurity monitoring, early warning and information notification. The national cyberspace administration department shall coordinate the relevant departments in strengthening the collection, analysis and notification of cybersecurity information and shall uniformly release cybersecurity monitoring and early warning information as required.\nArticle 54 Departments responsible for the security protection of critical information infrastructure shall establish and improve cybersecurity monitoring, early warning and information notification systems for their respective industries and fields, and submit cybersecurity monitoring and early warning information as required.\nArticle 55 The national cyberspace administration department shall coordinate the relevant departments in establishing and improving cybersecurity risk assessment and emergency response mechanisms, formulating emergency response plans for cybersecurity incidents, and organising regular drills.\nDepartments responsible for the security protection of critical information infrastructure shall formulate emergency response plans for cybersecurity incidents in their respective industries and fields and organise regular drills.\nEmergency response plans for cybersecurity incidents shall classify cybersecurity incidents according to factors such as the degree of harm and scope of impact after occurrence and shall provide for corresponding emergency handling measures.\nArticle 56 Where the risk of a cybersecurity incident increases, the relevant departments of people\u0026rsquo;s governments at or above the provincial level shall, in accordance with the prescribed powers and procedures, and in light of the characteristics of the cybersecurity risk and the harm it may cause, take the following measures:\n(1) require the relevant departments, institutions and personnel to promptly collect and report information and strengthen monitoring of cybersecurity risks;\n(2) organise relevant departments, institutions and professionals to analyse and assess cybersecurity risk information and predict the likelihood, scope of impact and degree of harm of an incident;\n(3) release cybersecurity risk warnings to the public and publish measures to avoid and mitigate harm.\nArticle 57 Where a cybersecurity incident occurs, the emergency response plan for cybersecurity incidents shall be immediately activated, the incident shall be investigated and assessed, network operators shall be required to take technical measures and other necessary measures to eliminate hidden security dangers and prevent the expansion of harm, and warning information relevant to the public shall be released to the public in a timely manner.\nArticle 58 Where the relevant departments of people\u0026rsquo;s governments at or above the provincial level, in performing their cybersecurity supervision and administration duties, discover that a relatively serious security risk exists in a network or that a security incident has occurred, they may, in accordance with the prescribed powers and procedures, conduct a regulatory interview with the legal representative or principal person in charge of the network operator. The network operator shall take measures as required, carry out rectification and eliminate the hidden danger.\nArticle 59 Where a cybersecurity incident gives rise to an emergency or a work safety accident, it shall be handled in accordance with the provisions of the Emergency Response Law of the People\u0026rsquo;s Republic of China, the Work Safety Law of the People\u0026rsquo;s Republic of China and other relevant laws and administrative regulations.\nArticle 60 Where necessary for safeguarding national security and public order or handling a major sudden social security incident, temporary measures such as restricting network communications in specified areas may be taken upon decision or approval by the State Council.\nChapter VI Legal liability Article 61 Where a network operator fails to perform the cybersecurity protection obligations provided for in Articles 23 and 27 of this Law, the competent departments shall order it to correct, give it a warning and may impose a fine of not less than RMB 10,000 and not more than RMB 50,000; where it refuses to correct or causes consequences such as endangering cybersecurity, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons.\nWhere an operator of critical information infrastructure fails to perform the cybersecurity protection obligations provided for in Articles 35, 36, 38 and 40 of this Law, the competent departments shall order it to correct, give it a warning and may impose a fine of not less than RMB 50,000 and not more than RMB 100,000; where it refuses to correct or causes consequences such as endangering cybersecurity, a fine of not less than RMB 100,000 and not more than RMB 1,000,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons.\nWhere the acts in the preceding two paragraphs cause serious consequences endangering cybersecurity, such as the leakage of a large volume of data or the loss of partial functions of critical information infrastructure, the competent departments shall impose a fine of not less than RMB 500,000 and not more than RMB 2,000,000, and a fine of not less than RMB 50,000 and not more than RMB 200,000 on the directly responsible persons in charge and other directly responsible persons; where the acts cause especially serious consequences endangering cybersecurity, such as the loss of the main functions of critical information infrastructure, a fine of not less than RMB 2,000,000 and not more than RMB 10,000,000 shall be imposed, and a fine of not less than RMB 200,000 and not more than RMB 1,000,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons.\nArticle 62 Where the provisions of the first and second paragraphs of Article 24 and the first paragraph of Article 50 of this Law are violated and any of the following acts is committed, the competent departments shall order correction and give a warning; where the offender refuses to correct or causes consequences such as endangering cybersecurity, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible person in charge:\n(1) installing malicious programs;\n(2) failing to immediately take remedial measures for risks such as security defects or vulnerabilities in its products or services, or failing to promptly inform users and report to the competent departments as required;\n(3) terminating without authorisation the provision of security maintenance for its products or services.\nWhere the acts in items (1) and (2) of the preceding paragraph cause the consequences specified in the third paragraph of Article 61 of this Law, the penalty shall be imposed in accordance with that paragraph.\nArticle 63 Where the provisions of Article 25 of this Law are violated by selling or providing critical network equipment or specialised cybersecurity products that have not passed security certification or security testing, or that fail to pass security certification or do not meet the requirements of security testing, the competent departments shall order the cessation of the sale or provision, give a warning and confiscate the unlawful gains; where there are no unlawful gains or the unlawful gains are less than RMB 100,000, a concurrent fine of not less than RMB 20,000 and not more than RMB 100,000 shall be imposed; where the unlawful gains are RMB 100,000 or more, a concurrent fine of not less than one time and not more than five times the unlawful gains shall be imposed; where the circumstances are serious, the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence. Where laws and administrative regulations provide otherwise, those provisions shall prevail.\nArticle 64 Where a network operator violates the first paragraph of Article 26 of this Law by failing to require a user to provide true identity information, or by providing the relevant services to a user who does not provide true identity information, the competent departments shall order correction; where the operator refuses to correct or the circumstances are serious, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.\nArticle 65 Where the provisions of Article 28 of this Law are violated by conducting activities such as cybersecurity certification, testing or risk assessment, or by releasing to the public cybersecurity information such as system vulnerabilities, computer viruses, cyber attacks or network intrusions, the competent departments shall order correction, give a warning and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000; where the offender refuses to correct or the circumstances are serious, a fine of not less than RMB 100,000 and not more than RMB 1,000,000 shall be imposed, and the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.\nWhere the acts in the preceding paragraph cause the consequences specified in the third paragraph of Article 61 of this Law, the penalty shall be imposed in accordance with that paragraph.\nArticle 66 Where the provisions of Article 29 of this Law are violated by engaging in activities endangering cybersecurity, or providing programs or tools specifically used for such activities, or providing technical support, advertising promotion, payment and settlement or other assistance to another person\u0026rsquo;s activities endangering cybersecurity, and the act does not yet constitute a crime, the public security organ shall confiscate the unlawful gains and impose detention of not more than five days, and may concurrently impose a fine of not less than RMB 50,000 and not more than RMB 500,000; where the circumstances are relatively serious, detention of not less than five days and not more than fifteen days shall be imposed, and a fine of not less than RMB 100,000 and not more than RMB 1,000,000 may concurrently be imposed.\nWhere a unit commits the act in the preceding paragraph, the public security organ shall confiscate its unlawful gains, impose a fine of not less than RMB 100,000 and not more than RMB 1,000,000, and punish the directly responsible persons in charge and other directly responsible persons in accordance with the provisions of the preceding paragraph.\nA person who violates Article 29 of this Law and receives a public security administration penalty must not engage in cybersecurity management or key positions in network operations for five years; a person who receives a criminal penalty must not engage in cybersecurity management or key positions in network operations for life.\nArticle 67 Where an operator of critical information infrastructure violates Article 37 of this Law by using network products or services that have not undergone security review or have failed security review, the competent departments shall order correction within a time limit, order the cessation of use and the elimination of the impact on national security, impose a fine of not less than one time and not more than ten times the procurement amount, and impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.\nArticle 68 Where the provisions of Article 48 of this Law are violated by setting up websites or communication groups for committing illegal or criminal activities, or by using networks to publish information involving the commission of illegal or criminal activities, and the act does not yet constitute a crime, the public security organ shall impose detention of not more than five days, and may concurrently impose a fine of not less than RMB 10,000 and not more than RMB 100,000; where the circumstances are relatively serious, detention of not less than five days and not more than fifteen days shall be imposed, and a fine of not less than RMB 50,000 and not more than RMB 500,000 may concurrently be imposed. The websites or communication groups used for committing the illegal or criminal activities shall be closed.\nWhere a unit commits the act in the preceding paragraph, the public security organ shall impose a fine of not less than RMB 100,000 and not more than RMB 500,000 and shall punish the directly responsible persons in charge and other directly responsible persons in accordance with the provisions of the preceding paragraph.\nArticle 69 Where a network operator violates Article 49 of this Law by failing to stop transmitting information whose publication or transmission is prohibited by laws and administrative regulations, failing to take measures such as elimination, failing to preserve the relevant records or failing to report to the competent departments, or violates Article 52 of this Law by failing to stop transmitting such information, take measures such as elimination and preserve the relevant records at the request of the relevant departments, the competent departments shall order correction, give a warning and circulate a notice of criticism, and may impose a fine of not less than RMB 50,000 and not more than RMB 500,000; where the offender refuses to correct or the circumstances are serious, a fine of not less than RMB 500,000 and not more than RMB 2,000,000 shall be imposed, and the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 50,000 and not more than RMB 200,000 on the directly responsible persons in charge and other directly responsible persons.\nWhere the acts in the preceding paragraph cause an especially serious impact or especially serious consequences, the competent departments shall impose a fine of not less than RMB 2,000,000 and not more than RMB 10,000,000, order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and impose a fine of not less than RMB 200,000 and not more than RMB 1,000,000 on the directly responsible persons in charge and other directly responsible persons.\nWhere a provider of electronic information sending services or a provider of application software download services fails to perform the security management obligations provided for in the second paragraph of Article 50 of this Law, it shall be punished in accordance with the preceding two paragraphs.\nArticle 70 Where a network operator violates the provisions of this Law and commits any of the following acts, the competent departments shall order correction; where the operator refuses to correct or the circumstances are serious, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons:\n(1) refusing or obstructing supervision and inspection carried out by the relevant departments in accordance with law;\n(2) refusing to provide technical support and assistance to public security organs and State security organs.\nArticle 71 Any of the following acts shall be handled and punished in accordance with the provisions of relevant laws and administrative regulations:\n(1) publishing or transmitting information whose publication or transmission is prohibited by the second paragraph of Article 13 of this Law or by other laws and administrative regulations;\n(2) infringing upon the rights and interests of personal information in violation of the third paragraph of Article 24 and Articles 43 to 45 of this Law;\n(3) in violation of Article 39 of this Law, storing personal information and important data outside the territory or providing personal information and important data abroad by an operator of critical information infrastructure.\nA person who violates Article 46 of this Law by stealing or otherwise unlawfully obtaining, unlawfully selling or unlawfully providing personal information to others, where the act does not yet constitute a crime, shall be punished by the public security organ in accordance with the provisions of relevant laws and administrative regulations.\nArticle 72 Where an unlawful act is provided for in this Law, it shall be recorded in credit files and made public in accordance with the provisions of relevant laws and administrative regulations.\nArticle 73 Where this Law is violated but circumstances provided for in the Administrative Penalty Law of the People\u0026rsquo;s Republic of China for a mitigated, reduced or no penalty exist, a mitigated or reduced penalty shall be imposed or no penalty shall be imposed in accordance with those provisions.\nArticle 74 Where an operator of a government network of a State organ fails to perform the cybersecurity protection obligations provided for in this Law, its superior authority or the relevant authority shall order it to correct; the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.\nArticle 75 Where the cyberspace administration departments and relevant departments violate Article 32 of this Law by using information obtained in the performance of cybersecurity protection duties for other purposes, the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.\nWhere staff of the cyberspace administration departments and relevant departments derelict their duties, abuse their powers or engage in malpractices for personal gain, and the act does not yet constitute a crime, they shall be given sanctions in accordance with law.\nArticle 76 Where a violation of this Law causes damage to another person, civil liability shall be borne in accordance with law.\nWhere a violation of this Law constitutes an act violating public security administration, a public security administration penalty shall be imposed in accordance with law; where a crime is constituted, criminal liability shall be pursued in accordance with law.\nArticle 77 Where an institution, organisation or individual outside the territory engages in activities endangering the cybersecurity of the People\u0026rsquo;s Republic of China, legal liability shall be pursued in accordance with law; where serious consequences are caused, the public security department of the State Council and the relevant departments may decide to take measures such as freezing property or other necessary sanctions against that institution, organisation or individual.\nChapter VII Supplementary provisions Article 78 For the purposes of this Law, the following terms have the meanings set out below:\n(1) \u0026ldquo;network\u0026rdquo; means a system composed of computers or other information terminals and related equipment that collects, stores, transmits, exchanges and processes information in accordance with certain rules and procedures;\n(2) \u0026ldquo;cybersecurity\u0026rdquo; means, through the adoption of necessary measures, preventing attacks, intrusions, interference, destruction and unlawful use of, and accidents affecting, networks, keeping networks in a stable and reliable state of operation, and the capacity to safeguard the integrity, confidentiality and availability of network data;\n(3) \u0026ldquo;network operator\u0026rdquo; means the owner or administrator of a network and the provider of network services;\n(4) \u0026ldquo;network data\u0026rdquo; means various electronic data collected, stored, transmitted, processed and generated through networks;\n(5) \u0026ldquo;personal information\u0026rdquo; means various information recorded electronically or otherwise that can, alone or in combination with other information, identify a natural person\u0026rsquo;s personal identity, including but not limited to a natural person\u0026rsquo;s name, date of birth, identity document number, personal biometric information, address and telephone number.\nArticle 79 In addition to complying with this Law, the security protection of the operation of networks that store or process information involving State secrets shall also comply with the provisions of laws and administrative regulations on the protection of secrets.\nArticle 80 The security protection of military networks shall be separately prescribed by the Central Military Commission.\nArticle 81 This Law shall come into force on 1 June 2017.\n","permalink":"https://ai.intlaws.com/en/compliance/china/csl/","summary":"Full text of the Cybersecurity Law of the People\u0026rsquo;s Republic of China as amended on 28 October 2025 (effective 1 January 2026), 81 articles in seven chapters: the new Article 3 (CPC leadership and the holistic approach to national security), the new Article 20 on artificial intelligence, the new Article 63 on penalties for uncertified critical network equipment, and the substantially raised penalty caps (up to RMB 10 million). English translation by our editorial team (non-official).","title":"Cybersecurity Law of the People's Republic of China (2025 Amendment)"},{"content":" Version and sources (verifiable)\nItem Content Adopted 29th Meeting of the Standing Committee of the 13th NPC, June 10, 2021 In force September 1, 2021 Chinese original source Cyberspace Administration of China: https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm English translation source NPC official English site (Translation for Reference Only): http://en.npc.gov.cn.cdurl.cn/2021-06/10/c_689311.htm Verification Retrieved 2026-09-22; 7 chapters / 55 articles; 1:1 correspondence, no gaps Chapter I General Provisions Article 1 This Law is enacted for the purpose of regulating data processing, ensuring data security, promoting development and utilization of data, protecting the lawful rights and interests of individuals and organizations, and safeguarding the sovereignty, security, and development interests of the state.\nArticle 2 This Law shall apply to data processing activities and security supervision and regulation of such activities within the territory of the People\u0026rsquo;s Republic of China. Where data processing outside the territory of People\u0026rsquo;s Republic of China harms the national security, public interests, or the lawful rights and interests of individuals or organizations of the People\u0026rsquo;s Republic of China, legal liability shall be investigated in accordance with the law.\nArticle 3 For the purpose of this Law, the term \u0026ldquo;data\u0026rdquo; refers to any record of information in electronic or any other form. \u0026ldquo;Data processing\u0026rdquo; includes the collection, storage, use, processing, transmission, provision, and disclosure of data, among others.\n\u0026ldquo;Data security\u0026rdquo; refers to ensuring that data is effectively protected and lawfully used through adopting necessary measures, and to possessing the capacity to guarantee the continuous security of data.\nArticle 4 In preserving data security, the holistic approach to national security shall be adopted, sound data security governance systems shall be established, and data security and protection capabilities shall be improved.\nArticle 5 The central leading authority for national security shall be responsible for the decision-making, deliberation and coordination of the national data security work; researching, formulating, and guiding the implementation of the national data security strategy and related major guidelines and policies; coordinating major matters and important work in respect of national data security; and establishing a coordination mechanism for national data security.\nArticle 6 All localities and departments shall bear responsibility for the management of the data collected or generated in their work as well as for the data security thereof. The competent departments of industry, telecommunications, transport, finance, natural resources, health, education, technology and other relevant competent departments shall assume the responsibilities of supervising and regulating data security in their respective trades and sectors.\nPublic security organs and national security organs, etc. shall assume the responsibilities of supervising and regulating data security within the scopes of their respective duties in accordance with the provisions of this Law and other relevant laws and administrative regulations.\nThe national cyberspace affairs department shall be in charge of the overall planning and coordination of network data security and the related supervision and regulation in accordance with the provisions of this Law and other relevant laws and administrative regulations.\nArticle 7 The state shall protect the data-related rights and interests of individuals and organizations, encourage the lawful, reasonable, and effective use of data, ensure free flow of data in an orderly manner and in accordance with the law, and promote the development of a digital economy with data as the key factor.\nArticle 8 Whoever processes data shall observe laws and regulations, respect social morality and ethics, observe business and professional ethics, uphold honesty and trustworthiness, fulfill data security protection obligations, and undertake social responsibilities; and shall not endanger national security and public interests, nor harm the lawful rights and interests of individuals and organizations.\nArticle 9 The state supports the dissemination and popularization of knowledge of data security to raise public awareness in this regard and ability to protect data security, and promotes the joint participation by relevant departments, industry organizations, research institutions, enterprises, and individuals in data security protection, so as to create a good environment for members of the whole society to jointly protect data, ensure data security and promote development of relevant industries.\nArticle 10 Relevant industry associations shall, in accordance with their articles of association, formulate the code of conduct and standards to ensure data security according to the law, strengthen self-regulation in their respective industries, guide members to strengthen data security protection, improve their protection level and promote the healthy development of the industries.\nArticle 11 The state shall actively carry out international exchanges and cooperation in fields such as data security governance and data development and utilization, participate in the formulation of relevant international rules and standards for data security, and promote the safe and free flow of data across borders.\nArticle 12 Any individual or organization shall have the right to file complaints about or report violations of this Law to the competent departments. The departments receiving such complaints or reports shall deal with them in a timely manner in accordance with the law. The competent departments shall keep confidential the relevant information of those making such complaints or reports, and protect their lawful rights and interests.\nData Security and Development\nChapter II Data Security and Development Article 13 The state shall make an overall plan to coordinate development and security, to promote data security through data development and utilization and through industrial development on one hand, and on the other hand, to ensure that data security facilitates data development and utilization as well as industrial development.\nArticle 14 The state shall implement the big data strategy, advance the construction of data infrastructure, and encourage and support the innovative application of data in all industries and fields. People\u0026rsquo;s governments at or above the provincial level shall incorporate the development of digital economy into their national economic and social development plans, and formulate development plans for the digital economy as needed.\nArticle 15 The state supports development and utilization of data to render public services smarter. In providing smarter public services, the needs of the elderly and the disabled shall be taken into full account to avoid posing obstacles to their daily lives.\nArticle 16 The state supports research on development and utilization of data and on data security related technologies, encourages popularization and commercial innovation of technologies in the foregoing fields, and fosters and develops products and industrial systems for development and utilization of data and for data security.\nArticle 17 The state shall advance the forming of the standards for data development and the standards for data utilization technologies and data security. The department in charge of standardization under the State Council and other relevant departments under the State Council shall, within the scopes of their respective duties and functions, organize the establishment of, and make revisions in due time to the standards for technologies and products for data development and data utilization and the standards for data security. The state shall support enterprises, social groups, and education or research institutions, etc. in their participation in the establishment of such standards.\nArticle 18 The state encourages the development of services such as data security testing, evaluation, and accreditation, and supports agencies specialized in data security testing, evaluation, accreditation, etc. to provide services according to the law. The state supports collaboration among relevant departments, industry associations, enterprises, education and research institutions, relevant specialized agencies, etc. in the fields such as data security related risk assessment, prevention, and disposal .\nArticle 19 The state shall establish sound systems for data trading management, standardize data trading activities, and foster a data trading market.\nArticle 20 The state supports education and research institutions, enterprises, and other entities in carrying out education and training on technologies for data development and utilization and on data security, cultivates professionals in data development and utilization technologies and in data security by a variety of means, and promotes talent exchanges. Data Security Systems\nChapter III Data Security Systems Article 21 The state shall establish a categorized and classified system and carry out data protection based on the importance of the data in economic and social development, as well as the extent of harm to national security, public interests, or the lawful rights and interests of individuals or organizations that will be caused once the data are altered, destroyed, leaked, or illegally obtained or used. The coordination mechanism for national data security shall coordinate the relevant departments to formulate a catalog of important data and strengthen protection of important data. Data concerning national security, lifelines of the national economy, important aspects of people\u0026rsquo;s lives, major public interests, ect., are core data of the state, for which a stricter management system shall be implemented.\nAll localities and departments shall, in accordance with the categorized and classified data protection system, prepare specific catalogs of important data for their respective regions, departments, and relevant industries and sectors, and give priority to the data listed in the catalogs in terms of data protection.\nArticle 22 The state shall establish a centralized, unified, highly effective, and authoritative mechanism for assessing, reporting, information sharing, monitoring, and early alert of data security risks. The coordinating mechanism for national data security shall make an overall plan on and coordinate relevant departments in strengthening the work about acquiring, analyzing, researching and evaluating information of data security risks and the work about early alert of such risks.\nArticle 23 The state shall establish a data security emergency response mechanism. Where a data security incident occurs, the relevant competent departments shall initiate emergency response in accordance with the plan and the law, take corresponding measures to prevent further harm and eliminate security hazards, and send out warnings to the public by publishing information relevant thereto in a timely manner.\nArticle 24 The state shall establish a review system for data security, conducting national security reviews of data processing that affects or may affect national security. Security review decisions made in accordance with the law are final decisions.\nArticle 25 The state shall apply export control in accordance with the law on data that are controlled items and concern national security and interests and the performance of international obligations.\nArticle 26 Where any country or region adopts discriminatory prohibitions, restrictions, or other similar measures against the People\u0026rsquo;s Republic of China in respect of investment, trade or any other field related to data and data development and utilization technologies, the People\u0026rsquo;s Republic of China may take countermeasures against that country or region in light of the actual circumstances. 1 2 \u0026gt;\nChapter IV Data Security Protection Obligations Article 27 In data processing, the laws and regulations shall be complied with, a sound data security management system throughout the whole process shall be established, data security education and training shall be organized and conducted, and corresponding technical measures and other necessary measures shall be adopted to ensure data security. In data processing by making use of the internet or any other information networks, the abovementioned data security obligations shall be fulfilled on the basis of the classified protection system for cyber security. Processors of important data shall be clear about their persons responsible for data security and the data security management bodies, and fulfill the responsibilities for data security.\nArticle 28 Data processing as well as research and development of new data technologies shall be conducive to furthering economic and social development, and improving the well-being of people, and shall conform to social morals and ethics.\nArticle 29 Closer risk monitoring shall be applied in data processing. Where data security defects, bugs, or other risks are discovered, remedial measures shall be taken immediately. Where a data security incident occurs, measures shall be taken immediately to address it, and users shall be notified and reports made to relevant competent departments in a timely manner in accordance with relevant provisions.\nArticle 30 Processors of important data shall, in accordance with the relevant provisions, conduct risk assessments of their data processing on a regular basis and submit risk assessment reports to relevant competent departments. Risk assessment reports shall include the types and amounts of important data processed, information on data processing, data security risks and the response measures for them.\nArticle 31 The provisions of the Cyber Security Law of the People\u0026rsquo;s Republic of China shall apply to the outbound security management of the important data collected or produced by critical information infrastructure operators during their operation within the territory of the People\u0026rsquo;s Republic of China, and the measures for the outbound security management of the important data collected or produced by others data processors during their operation within the territory of the People\u0026rsquo;s Republic of China shall be formulated by the national cyberspace authority in conjunction with the relevant departments under the State Council.\nArticle 32 An organization or individual shall collect data by lawful and proper means, and shall not acquire data by theft or in other illegal manners. Where laws or administrative regulations have provisions on the purposes or scopes of data collection and use, data shall be collected and used for the purposes and within the scopes provided for by those laws and administrative regulations.\nArticle 33 When providing services, data transaction intermediaries shall require data providers to specify the sources of the data, verify the identities of both parties to the transactions, and retain the verification and transaction records.\nArticle 34 Where laws or administrative regulations require that administrative permissions be acquired for providing services related to data processing, service providers shall obtain such administrative permissions in accordance with these provisions.\nArticle 35 Where a public security organ or national security organ needs to obtain data for the sake of national security or for investigating crimes in accordance with the law, strict approval formalities shall be completed in accordance with the relevant provisions of the state and data be obtained in accordance with the law, and the relevant organizations and individuals shall cooperate.\nArticle 36 The competent authorities of the People\u0026rsquo;s Republic of China shall handle requests for data made by foreign judicial or law enforcement authorities, in accordance with the relevant laws and international treaties or agreements concluded or acceded to by the People\u0026rsquo;s Republic of China, or in accordance with the principles of equality and reciprocity. Without the approval of the competent authorities of the People\u0026rsquo;s Republic of China, organizations or individuals in the People\u0026rsquo;s Republic of China shall not provide data stored within the territory of the People\u0026rsquo;s Republic of China to any overseas judicial or law enforcement body. Security and Openness of Government Data\nChapter V Security and Openness of Government Data Article 37 The state shall make great efforts to promote the development of e-government, make government database more scientific, accurate, and time-efficient, and improve the ability of using data to serve economic and social development.\nArticle 38 Where state organs need to collect or use data to perform their statutory duties, they shall collect or use data within the scope as needed for performance of their statutory duties and under the conditions and procedures provided by laws and administrative regulations. They shall, in accordance with the law, preserve the confidentiality of the data accessed in the course of performing their duties, such as personal privacy, personal information, trade secrets, and confidential business information, and shall not divulge such data or illegally provide them to others.\nArticle 39 State organs shall, in accordance with the provisions of laws and administrative regulations, establish sound data security management systems, fulfill data security protection responsibilities, and ensure the security of government data.\nArticle 40 Where a state organ entrusts others to construct or maintain e-government systems, or to store or process government data, the state organ shall go through strict approval procedures, and shall supervise the entrusted party in the performance of data security protection obligations. The entrusted party shall perform its data security protection obligations in accordance with the provisions of laws, regulations, and contracts signed, and shall not retain, use, divulge, or provide others with government data without authorization.\nArticle 41 State organs shall, under the principles of fairness, equality and convenience for the people, disclose government data in a timely and accurate manner in accordance with the provisions, except those which shall not be disclosed in accordance with the law.\nArticle 42 The state shall formulate the catalog of open government data, build an open, uniform, standardized, interconnected, safe and controllable government data platform, and promote the release and utilization of government data.\nArticle 43 The provisions of this Chapter shall apply to the data processing carried out by the organizations with the functions of administering public affairs as authorized by laws and regulations for the purpose of performing their statutory duties. Legal Liability\nChapter VI Legal Liability Article 44 Where competent departments discover the existence of major security risks in data processing when they perform their regulatory duties as regards data security, they may, in accordance with the prescribed limits of authority and procedures, conduct regulatory talks with the relevant organizations and/or individuals, and require the relevant organizations and/or individuals to adopt measures to make rectifications and eliminate potential hazards.\nArticle 45 Where an organization or individual that processes data fails to perform the data security protection obligations provided in Articles 27, 29 and 30 of this Law, the organization or individual shall be ordered to make rectifications and be given a warning, and may be concurrently fined not less than RMB 50,000 yuan but not more than RMB 500,000 yuan by the competent department, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. Where the organization or individual refuses to make rectifications or has caused serious consequences such as a massive data breach, the organization or individual shall be fined not less than RMB 500,000 yuan but not more than RMB 2 million yuan, and may be ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked, and the directly liable persons in charge and other directly liable persons shall be fined not less than RMB 50,000 yuan but not more than RMB 200,000 yuan. Where the organization or individual violates the national core data management rules and endangers national sovereignty, security, or development interests of the state, the competent department shall impose upon the organization or individual a fine of not less than RMB 2 million yuan but not more than RMB 10 million yuan, and may, based on the circumstances, order a suspension of relevant business or a suspension of operations for rectification, or revoke relevant business permits or the business license. Where a crime is constituted, criminal responsibilities shall be investigated in accordance with the law.\nArticle 46 Whoever, in violation of the provisions of Article 31 of this Law, provides important data abroad, shall be ordered to make rectifications and be given a warning by the competent department, and may be concurrently fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. Where the circumstances are serious, the violator shall be fined not less than RMB 1 million but not more than RMB 10 million yuan, and may also be ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked, and the directly liable persons in charge and other directly liable persons shall be fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan.\nArticle 47 Where a data transaction intermediary fails to perform the obligations prescribed in Article 33 of this Law, it shall be ordered by the competent department to make rectifications, its illegal gains, if any, shall be confiscated, and it shall also be fined not less than the amount of but not more than ten times the amount of the illegal gains; if there are no illegal gains or the illegal gains are less than RMB 100,000 yuan, it shall be fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan. It may be concurrently ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked. The directly liable persons in charge and other directly liable persons shall be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan.\nArticle 48 Whoever in violation of Article 35 of this Law, refuses to cooperate when a public organ or national security organ needs to access the data, shall be ordered by the competent department to make rectifications and be given a warning, and shall be concurrently fined not less than RMB 50,000 yuan but nor more than RMB 500,000 yuan, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. Whoever, in violation of Article 36 of this Law, provides data to an overseas judicial or law enforcement body without the approval of the competent authorities, shall be given a warning by the competent department, and may be concurrently fined not less than RMB 100,000 yuan but not more than RMB 1 million yuan, and the directly liable persons in charge and other directly liable persons may be fined not less than RMB 10,000 yuan but not more than RMB 100,000 yuan. If serious consequences are caused, the violator shall be fined not less than RMB 1 million yuan but not more than RMB 5 million yuan, and may be ordered to suspend the relevant business or suspend operations for rectification, or have relevant business permits or the business license revoked. The directly liable persons in charge and other directly liable persons shall be fined not less than RMB 50,000 yuan but not more than RMB 500,000 yuan.\nArticle 49 Where a state organ fails to perform data security obligations as provided for in this Law, the directly liable persons in charge and other directly liable persons shall be given a sanction in accordance with the law.\nArticle 50 Any state functionary performing data security related regulation regulation neglects his duty, abuses power, or engages in malpractice for personal gain, shall be given a sanction in accordance with the law.\nArticle 51 Whoever obtains data through theft or by any other illegal means, or eliminates or restricts competition in data processing, or harms the lawful rights and interests of individuals or organizations, shall be punished in accordance with the provisions of relevant laws and administrative regulations.\nArticle 52 Whoever, in violation of this Law, causes damages to others shall bear civil liability in accordance with the law. Where a violation of the provisions of this Law constitutes a violation of public security administration, a public security administrative penalty shall be given in accordance with the law. Where a crime is constituted, criminal responsibility shall be investigated in accordance with the law.\nSupplementary Provisions\nChapter VII Supplementary Provisions Article 53 The provisions of the Law of the People\u0026rsquo;s Republic of China on Guarding State Secrets and other relevant laws and administrative regulations shall apply to data processing that involves state secrets. The provisions of relevant laws and administrative regulations shall also be observed when data are processed in statistical or archival work and in data processing involving personal information.\nArticle 54 Measures for the military data security and protection shall be separately formulated by the Central Military Commission in accordance with this Law.\nArticle 55 This Law shall come into force as of September 1, 2021. 1 2\n","permalink":"https://ai.intlaws.com/en/compliance/china/dsl/","summary":"Officialof the Data Security Law of the PRC: 7 chapters, 55 articles, adopted 2021-06-10, in force 2021-09-01. English text from the NPC official English site (marked \u0026ldquo;Translation for Reference Only\u0026rdquo;); Chinese original from the Cyberspace Administration of China.","title":"Data Security Law of the PRC"},{"content":" Version and sources (verifiable)\nItem Content Instrument Executive Order 14365 of 11 December 2025 Official publication 90 FR 58499, published 16 December 2025 (Federal Register document no. 2025-23092) Structure 9 sections (Purpose; Policy; AI Litigation Task Force; Evaluation of State AI Laws; Restrictions on State Funding; Federal Reporting and Disclosure Standard; Preemption of State Laws Mandating Deceptive Conduct in AI Models; Legislation; General Provisions) Official text https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence Chinese version No official Chinese text. A Chinese translation by our editorial team, marked non-official, is available → 中文全文 Status note This is an executive order, not a statute. The legislative recommendation contemplated by section 8 is a proposal; do not treat it as enacted law. Retrieval \u0026amp; verification Retrieved 2026-09-22 from the Federal Register full-text publication; section numbering and citations (47 U.S.C. 902(b), 47 U.S.C. 1702(e)-(f), 15 U.S.C. 45) checked against the published text. Executive Order 14365 of December 11, 2025\nEnsuring a National Policy Framework for Artificial Intelligence By the authority vested in me as President by the Constitution and the laws of the United States of America, it is hereby ordered:\nSection 1. Purpose. United States leadership in Artificial Intelligence (AI) will promote United States national and economic security and dominance across many domains. Pursuant to Executive Order 14179 of January 23, 2025 (Removing Barriers to American Leadership in Artificial Intelligence), I revoked my predecessor\u0026rsquo;s attempt to paralyze this industry and directed my Administration to remove barriers to United States AI leadership. My Administration has already done tremendous work to advance that objective, including by updating existing Federal regulatory frameworks to remove barriers to and encourage adoption of AI applications across sectors. These efforts have already delivered tremendous benefits to the American people and led to trillions of dollars of investments across the country. But we remain in the earliest days of this technological revolution and are in a race with adversaries for supremacy within it.\nTo win, United States AI companies must be free to innovate without cumbersome regulation. But excessive State regulation thwarts this imperative. First, State-by-State regulation by definition creates a patchwork of 50 different regulatory regimes that makes compliance more challenging, particularly for start-ups. Second, State laws are increasingly responsible for requiring entities to embed ideological bias within models. For example, a new Colorado law banning \u0026ldquo;algorithmic discrimination\u0026rdquo; may even force AI models to produce false results in order to avoid a \u0026ldquo;differential treatment or impact\u0026rdquo; on protected groups. Third, State laws sometimes impermissibly regulate beyond State borders, impinging on interstate commerce.\nMy Administration must act with the Congress to ensure that there is a minimally burdensome national standard—not 50 discordant State ones. The resulting framework must forbid State laws that conflict with the policy set forth in this order. That framework should also ensure that children are protected, censorship is prevented, copyrights are respected, and communities are safeguarded. A carefully crafted national framework can ensure that the United States wins the AI race, as we must. Until such a national standard exists, however, it is imperative that my Administration takes action to check the most onerous and excessive laws emerging from the States that threaten to stymie innovation.\nSec. 2. Policy. It is the policy of the United States to sustain and enhance the United States\u0026rsquo; global AI dominance through a minimally burdensome national policy framework for AI.\nSec. 3. AI Litigation Task Force. Within 30 days of the date of this order, the Attorney General shall establish an AI Litigation Task Force (Task Force) whose sole responsibility shall be to challenge State AI laws inconsistent with the policy set forth in section 2 of this order, including on grounds that such laws unconstitutionally regulate interstate commerce, are preempted by existing Federal regulations, or are otherwise unlawful in the Attorney General\u0026rsquo;s judgment, including, if appropriate, those laws identified pursuant to section 4 of this order. The Task Force shall consult from time to time with the Special Advisor for AI and Crypto, the Assistant to the President for Science and Technology, the Assistant to the President for Economic Policy, and the Assistant to the President and Counsel to the President regarding the emergence of specific State AI laws that warrant challenge.\nSec. 4. Evaluation of State AI Laws. Within 90 days of the date of this order, the Secretary of Commerce, consistent with the Secretary\u0026rsquo;s authorities under 47 U.S.C. 902(b), shall, in consultation with the Special Advisor for AI and Crypto, the Assistant to the President for Economic Policy, the Assistant to the President for Science and Technology, and the Assistant to the President and Counsel to the President, publish an evaluation of existing State AI laws that identifies onerous laws that conflict with the policy set forth in section 2 of this order, as well as laws that should be referred to the Task Force established pursuant to section 3 of this order. That evaluation of State AI laws shall, at a minimum, identify laws that require AI models to alter their truthful outputs, or that may compel AI developers or deployers to disclose or report information in a manner that would violate the First Amendment or any other provision of the Constitution. The evaluation may additionally identify State laws that promote AI innovation consistent with the policy set forth in section 2 of this order.\nSec. 5. Restrictions on State Funding. (a) Within 90 days of the date of this order, the Secretary of Commerce, through the Assistant Secretary of Commerce for Communications and Information, shall issue a Policy Notice specifying the conditions under which States may be eligible for remaining funding under the Broadband Equity Access and Deployment (BEAD) Program that was saved through my Administration\u0026rsquo;s \u0026ldquo;Benefit of the Bargain\u0026rdquo; reforms, consistent with 47 U.S.C. 1702(e)-(f). That Policy Notice must provide that States with onerous AI laws identified pursuant to section 4 of this order are ineligible for non-deployment funds, to the maximum extent allowed by Federal law. The Policy Notice must also describe how a fragmented State regulatory landscape for AI threatens to undermine BEAD-funded deployments, the growth of AI applications reliant on high-speed networks, and BEAD\u0026rsquo;s mission of delivering universal, high-speed connectivity.\n(b) Executive departments and agencies (agencies) shall assess their discretionary grant programs in consultation with the Special Advisor for AI and Crypto and determine whether agencies may condition such grants on States either not enacting an AI law that conflicts with the policy of this order, including any AI law identified pursuant to section 4 or challenged pursuant to section 3 of this order, or, for those States that have enacted such laws, on those States entering into a binding agreement with the relevant agency not to enforce any such laws during the performance period in which it receives the discretionary funding.\nSec. 6. Federal Reporting and Disclosure Standard. Within 90 days of the publication of the identification specified in section 4 of this order, the Chairman of the Federal Communications Commission shall, in consultation with the Special Advisor for AI and Crypto, initiate a proceeding to determine whether to adopt a Federal reporting and disclosure standard for AI models that preempts conflicting State laws.\nSec. 7. Preemption of State Laws Mandating Deceptive Conduct in AI Models. Within 90 days of the date of this order, the Chairman of the Federal Trade Commission shall, in consultation with the Special Advisor for AI and Crypto, issue a policy statement on the application of the Federal Trade Commission Act\u0026rsquo;s prohibition on unfair and deceptive acts or practices under 15 U.S.C. 45 to AI models. That policy statement must explain the circumstances under which State laws that require alterations to the truthful outputs of AI models are preempted by the Federal Trade Commission Act\u0026rsquo;s prohibition on engaging in deceptive acts or practices affecting commerce.\nSec. 8. Legislation. (a) The Special Advisor for AI and Crypto and the Assistant to the President for Science and Technology shall jointly prepare a legislative recommendation establishing a uniform Federal policy framework for AI that preempts State AI laws that conflict with the policy set forth in this order.\n(b) The legislative recommendation called for in subsection (a) of this section shall not propose preempting otherwise lawful State AI laws relating to: (i) child safety protections; (ii) AI compute and data center infrastructure, other than generally applicable permitting reforms; (iii) State government procurement and use of AI; and (iv) other topics as shall be determined.\nSec. 9. General Provisions. (a) Nothing in this order shall be construed to impair or otherwise affect: (i) the authority granted by law to an executive department or agency, or the head thereof; or (ii) the functions of the Director of the Office of Management and Budget relating to budgetary, administrative, or legislative proposals.\n(b) This order shall be implemented consistent with applicable law and subject to the availability of appropriations.\n(c) This order is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.\n(d) The costs for publication of this order shall be borne by the Department of Commerce.\nTHE WHITE HOUSE, December 11, 2025.\n","permalink":"https://ai.intlaws.com/en/compliance/us/executive-order-14365/","summary":"Official text of Executive Order 14365 of 11 December 2025, \u0026ldquo;Ensuring a National Policy Framework for Artificial Intelligence\u0026rdquo;, published at 90 FR 58499 (16 December 2025), nine sections: policy of a minimally burdensome national AI framework, an AI Litigation Task Force, a Commerce Department evaluation of State AI laws, restrictions on State funding (BEAD, discretionary grants), an FCC proceeding on a Federal reporting and disclosure standard, an FTC policy statement on preemption, and a legislative recommendation that does not preempt State laws on child safety, AI compute/data-centre infrastructure, State procurement, and other topics as determined.","title":"Executive Order 14365"},{"content":" Version and sources (verifiable)\nItem Content Adopted deliberated and adopted at the 12th executive meeting of the Cyberspace Administration of China in 2023 (23 May 2023), and agreed by the National Development and Reform Commission, the Ministry of Education, the Ministry of Science and Technology, the Ministry of Industry and Information Technology, the Ministry of Public Security and the National Radio and Television Administration Promulgated 10 July 2023 (Order No. 15 of seven departments) Effective 15 August 2023 Structure 5 chapters, 24 articles Currently effective Yes (as of 2026-09-22) Chinese original https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm English version No official English translation published. This English text is a translation by our editorial team, cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 24 articles, correspondence with the Chinese text verified one-for-one, no gaps Chapter I General provisions Article 1 These Measures are formulated in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China, the Law of the People\u0026rsquo;s Republic of China on Scientific and Technological Progress and other laws and administrative regulations, for the purposes of promoting the sound development and regulated application of generative artificial intelligence, safeguarding national security and the public interest, and protecting the lawful rights and interests of citizens, legal persons and other organisations.\nArticle 2 These Measures apply to services that use generative artificial intelligence technology to provide the public within the territory of the People\u0026rsquo;s Republic of China with content such as text, images, audio and video (hereinafter \u0026ldquo;generative AI services\u0026rdquo;).\nWhere the State has other provisions on the use of generative AI services for activities such as news and publishing, film and television production, and literary and artistic creation, those provisions shall prevail.\nThese Measures do not apply to industry organisations, enterprises, educational and research institutions, public cultural institutions and relevant professional institutions that develop and apply generative AI technology without providing generative AI services to the public within the territory.\nArticle 3 The State adheres to the principle of attaching equal importance to development and security and combining the promotion of innovation with governance according to law, takes effective measures to encourage innovative development of generative artificial intelligence, and exercises inclusive, prudent and classification-based, tiered regulation over generative AI services.\nArticle 4 The provision and use of generative AI services shall comply with laws and administrative regulations, respect public order and good morals and ethics, and comply with the following provisions:\n(1) uphold the core socialist values; not generate content prohibited by laws and administrative regulations, such as content that incites subversion of State power or overthrow of the socialist system, endangers national security and interests or damages the national image, incites secession and undermines national unity and social stability, propagates terrorism or extremism, propagates ethnic hatred or ethnic discrimination, or is violent or obscene, or false and harmful information;\n(2) take effective measures in the course of algorithm design, selection of training data, model generation and optimisation, and service provision to prevent discrimination on grounds such as ethnicity, belief, country, region, gender, age, occupation and health;\n(3) respect intellectual property rights and business ethics, keep trade secrets, and refrain from using advantages in algorithms, data or platforms to engage in monopolistic or unfair competitive practices;\n(4) respect the lawful rights and interests of others; not endanger the physical or mental health of others; not infringe others\u0026rsquo; rights to portrait, reputation, honour, privacy or personal information;\n(5) take effective measures, in light of the characteristics of the type of service, to enhance the transparency of generative AI services and improve the accuracy and reliability of generated content.\nArticle 5 Innovative application of generative artificial intelligence technology in all industries and fields is encouraged, so as to generate positive, healthy and uplifting high-quality content, explore and optimise application scenarios, and build an application ecosystem.\nIndustry organisations, enterprises, educational and research institutions, public cultural institutions and relevant professional institutions are supported in collaborating on technological innovation, construction of data resources, transformation and application, and risk prevention in generative artificial intelligence.\nArticle 6 Independent innovation in basic technologies such as generative artificial intelligence algorithms, frameworks, chips and supporting software platforms is encouraged, as are international exchanges and cooperation on the basis of equality and mutual benefit and participation in the formulation of international rules relating to generative artificial intelligence.\nThe construction of generative artificial intelligence infrastructure and public training-data resource platforms shall be promoted. Collaborative sharing of computing power resources shall be facilitated and the efficiency of their use improved. The classified and tiered, orderly opening of public data shall be promoted to expand high-quality public training-data resources. The use of secure and trustworthy chips, software, tools, computing power and data resources is encouraged.\nChapter II Development and governance of generative AI technology Article 7 Providers of generative AI services (hereinafter \u0026ldquo;providers\u0026rdquo;) shall, in accordance with law, carry out training data processing activities such as pre-training and optimisation training, and shall comply with the following provisions:\n(1) use data and foundation models with lawful sources;\n(2) where intellectual property is involved, not infringe intellectual property rights lawfully enjoyed by others;\n(3) where personal information is involved, obtain the consent of the individual or satisfy other circumstances provided for by laws and administrative regulations;\n(4) take effective measures to improve the quality of training data and enhance its authenticity, accuracy, objectivity and diversity;\n(5) comply with other relevant provisions of the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law and other laws and administrative regulations, and with the relevant regulatory requirements of the competent departments.\nArticle 8 Where data annotation is carried out in the course of research and development of generative artificial intelligence technology, the provider shall formulate clear, specific and operable annotation rules that meet the requirements of these Measures; carry out quality assessment of data annotation and verify by sampling the accuracy of annotated content; and provide necessary training to annotators to raise their awareness of law-abiding conduct and supervise and guide them to carry out annotation work in a standardised manner.\nArticle 9 A provider shall, in accordance with law, bear the responsibility of an online information content producer and perform its online information security obligations. Where personal information is involved, it shall, in accordance with law, bear the responsibility of a personal information processor and perform its personal information protection obligations.\nA provider shall conclude a service agreement with the users of the generative AI service registered with it (hereinafter \u0026ldquo;users\u0026rdquo;) to clarify the rights and obligations of both parties.\nArticle 10 A provider shall clearly define and publicly disclose the applicable groups of people, occasions and purposes of its service, guide users to understand and use generative artificial intelligence technology in a scientific and rational manner and in accordance with law, and take effective measures to prevent minor users from becoming overly dependent on or addicted to generative AI services.\nArticle 11 A provider shall, in accordance with law, perform protection obligations in respect of users\u0026rsquo; input information and usage records, shall not collect unnecessary personal information, shall not unlawfully retain input information and usage records that can identify users, and shall not unlawfully provide users\u0026rsquo; input information and usage records to others.\nA provider shall, in accordance with law and in a timely manner, accept and handle individuals\u0026rsquo; requests to access, copy, correct, supplement and delete their personal information.\nArticle 12 A provider shall label generated content such as images and videos in accordance with the Provisions on the Administration of Deep Synthesis of Internet Information Services.\nArticle 13 A provider shall, in the course of its service, provide safe, stable and continuous service and ensure normal use by users.\nArticle 14 Where a provider discovers illegal content, it shall promptly take measures such as stopping generation, stopping transmission and elimination, take measures such as model optimisation training for rectification, and report to the competent departments.\nWhere a provider discovers that a user is using the generative AI service to engage in illegal activities, it shall, in accordance with law and the agreement, take measures such as warning, restricting functions, suspending or terminating the provision of services to that user, preserve the relevant records, and report to the competent departments.\nArticle 15 A provider shall establish and improve complaint and reporting mechanisms, set up convenient complaint and reporting channels, publish the handling process and the time limit for feedback, and promptly accept and handle public complaints and reports and give feedback on the outcome.\nChapter III Obligations of providers Article 16 The departments for cyberspace administration, development and reform, education, science and technology, industry and information technology, public security, radio and television and news and publishing shall, in accordance with their respective duties and in accordance with law, strengthen the administration of generative AI services.\nThe competent State departments shall, in light of the characteristics of generative artificial intelligence technology and its service applications in the relevant industries and fields, improve scientific regulatory approaches compatible with innovative development, and formulate corresponding classification-based and tiered regulatory rules or guidelines.\nArticle 17 A provider that provides generative AI services with attributes of public opinion or capacity for social mobilisation shall carry out a security assessment in accordance with the relevant State provisions and, in accordance with the Provisions on the Administration of Algorithmic Recommendations in Internet Information Services, complete the procedures for algorithm filing and for modification and cancellation of filing.\nArticle 18 Where a user discovers that a generative AI service does not comply with laws, administrative regulations and these Measures, the user has the right to complain to or report the matter to the competent departments.\nArticle 19 The competent departments shall, in accordance with their duties, carry out supervision and inspection of generative AI services, and providers shall cooperate in accordance with law, explain as required the sources, scale and types of training data, annotation rules, and the mechanisms of the algorithms, and provide the necessary technical and data support and assistance.\nRelevant institutions and personnel participating in the security assessment and supervision and inspection of generative AI services shall, in accordance with law, keep confidential the State secrets, trade secrets, personal privacy and personal information learned in the performance of their duties, and shall not disclose them or unlawfully provide them to others.\nArticle 20 Where a generative AI service provided to the public within the territory from outside the territory of the People\u0026rsquo;s Republic of China does not comply with laws, administrative regulations and these Measures, the national cyberspace administration department shall notify the relevant institutions to take technical measures and other necessary measures to deal with it.\nArticle 21 Where a provider violates these Measures, the competent departments shall impose penalties in accordance with the provisions of the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China, the Law of the People\u0026rsquo;s Republic of China on Scientific and Technological Progress and other laws and administrative regulations; where laws and administrative regulations do not so provide, the competent departments shall, in accordance with their duties, issue a warning or a notice of criticism and order correction within a time limit; where the provider refuses to correct or the circumstances are serious, order it to suspend the provision of the relevant service.\nWhere the act constitutes a violation of public security administration, public security administrative penalties shall be imposed in accordance with law; where a crime is constituted, criminal liability shall be pursued in accordance with law.\nChapter IV Definitions Article 22 For the purposes of these Measures:\n(1) \u0026ldquo;generative artificial intelligence technology\u0026rdquo; means models and related technology with the capacity to generate content such as text, images, audio and video;\n(2) \u0026ldquo;provider of generative AI services\u0026rdquo; means an organisation or individual that uses generative artificial intelligence technology to provide generative AI services (including providing such services through, for example, programmable interfaces);\n(3) \u0026ldquo;user of generative AI services\u0026rdquo; means an organisation or individual that uses generative AI services to generate content.\nChapter V Supplementary provisions Article 23 Where laws and administrative regulations require that a relevant administrative licence be obtained to provide generative AI services, the provider shall obtain the licence in accordance with law.\nForeign-invested generative AI services shall comply with the provisions of laws and administrative regulations on foreign investment.\nArticle 24 These Measures shall come into force on 15 August 2023.\n","permalink":"https://ai.intlaws.com/en/compliance/china/generative-ai-interim-measures/","summary":"Full text of the Interim Measures for the Administration of Generative Artificial Intelligence Services (promulgated 10 July 2023, effective 15 August 2023), 24 articles in five chapters: scope, training-data obligations, provider duties, obligations to users, security assessment and algorithm filing for services with public-opinion or social-mobilisation attributes, and penalties. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).","title":"Interim Measures for the Administration of Generative Artificial Intelligence Services"},{"content":" Version and sources (verifiable)\nItem Content Official title 人工知能関連技術の研究開発及び活用の推進に関する法律 Common name AI Promotion Act (AI 推進法) Act number Act No. 53 of Reiwa 7 (令和七年法律第五十三号) Promulgation 4 June 2025 Structure 28 articles + 2 supplementary provisions; four chapters (Ch. I General Provisions, Ch. II Basic Measures, Ch. III AI Basic Plan, Ch. IV AI Strategy Headquarters) Official text (Japanese) e-Gov Law Search ｜ e-Gov API (machine readable) English translation No official English translation has been issued by the Government of Japan. This English text is translated by this journal from the official Japanese text; it is unofficial and for reference only Chinese translation 中文译本(非官方) Scope note The Japanese text is the authoritative version; in case of any discrepancy, the Japanese text prevails. Verification record 2026-09-22, three hard checks against the official Japanese text: ① article headings 30/30 (Articles 1–28 + 2 supplementary provisions); ② paragraph markers 15/15 and items 5/5 in exact sequence; ③ all 7 statutory instrument numbers mapped and verified (7/7), numerical set complete. Translation notes: 7 terms carry [to verify], incl. 知的基盤 (\u0026ldquo;knowledge base\u0026rdquo;) and 主任の大臣 (\u0026ldquo;competent minister\u0026rdquo;) Full text (official Japanese text) 令和七年法律第五十三号\n人工知能関連技術の研究開発及び活用の推進に関する法律\n目次\n第一章　総則\n（第一条―第十条）\n第二章　基本的施策\n（第十一条―第十七条）\n第三章　人工知能基本計画\n（第十八条）\n第四章　人工知能戦略本部\n（第十九条―第二十八条）\n附則\n第一章　総則\n第一条　（目的）\nこの法律は、人工知能関連技術が我が国の経済社会の発展の基盤となる技術であることに鑑み、人工知能関連技術の研究開発及び活用の推進に関する施策について、基本理念並びに人工知能関連技術の研究開発及び活用の推進に関する基本的な計画の策定その他の施策の基本となる事項を定めるとともに、人工知能戦略本部を設置することにより、科学技術・イノベーション基本法（平成七年法律第百三十号）及びデジタル社会形成基本法（令和三年法律第三十五号）その他の関係法律による施策と相まって、人工知能関連技術の研究開発及び活用の推進に関する施策の総合的かつ計画的な推進を図り、もって国民生活の向上及び国民経済の健全な発展に寄与することを目的とする。\n第二条　（定義）\nこの法律において、「人工知能関連技術」とは、人工的な方法により人間の認知、推論及び判断に係る知的な能力を代替する機能を実現するために必要な技術並びに入力された情報を当該技術を利用して処理し、その結果を出力する機能を実現するための情報処理システムに関する技術をいう。\n第三条　（基本理念）\n人工知能関連技術の研究開発及び活用の推進は、科学技術・イノベーション基本法第三条に定める科学技術・イノベーション創出の振興に関する方針及びデジタル社会形成基本法第二章に定める基本理念のほか、この条に定める基本理念に基づいて行うものとする。\n２　人工知能関連技術の研究開発及び活用の推進は、人工知能関連技術が、その適正かつ効果的な活用によって行政事務及び民間の事業活動の著しい効率化及び高度化並びに新産業の創出をもたらすものとして経済社会の発展の基盤となる技術であるとともに、安全保障の観点からも重要な技術であることに鑑み、我が国において人工知能関連技術の研究開発を行う能力を保持するとともに、人工知能関連技術に関する産業の国際競争力を向上させることを旨として、行うものとする。\n３　人工知能関連技術の研究開発及び活用の推進は、人工知能関連技術の基礎研究から国民生活及び経済活動における活用に至るまでの各段階の関係者による取組が相互に密接な関連を有することに鑑み、これらの取組を総合的かつ計画的に推進することを旨として、行うものとする。\n４　人工知能関連技術の研究開発及び活用は、不正な目的又は不適切な方法で行われた場合には、犯罪への利用、個人情報の漏えい、著作権の侵害その他の国民生活の平穏及び国民の権利利益が害される事態を助長するおそれがあることに鑑み、その適正な実施を図るため、人工知能関連技術の研究開発及び活用の過程の透明性の確保その他の必要な施策が講じられなければならない。\n５　人工知能関連技術の研究開発及び活用は、我が国及び国際社会の平和と発展に寄与するものとなるよう、国際的協調の下に推進することを旨とし、我が国が人工知能関連技術の研究開発及び活用に関する国際協力において主導的な役割を果たすよう努めるものとする。\n第四条　（国の責務）\n国は、前条に定める基本理念（以下「基本理念」という。）にのっとり、人工知能関連技術の研究開発及び活用の推進に関する施策を総合的かつ計画的に策定し、及び実施する責務を有する。\n２　国は、行政事務の効率化及び高度化を図るため、国の行政機関における人工知能関連技術の積極的な活用を進めるものとする。\n第五条　（地方公共団体の責務）\n地方公共団体は、基本理念にのっとり、人工知能関連技術の研究開発及び活用の推進に関し、国との適切な役割分担の下、地方公共団体が実施すべき施策として、その地方公共団体の区域の特性を生かした自主的な施策を策定し、及び実施する責務を有する。\n第六条　（研究開発機関の責務等）\n大学、科学技術・イノベーション創出の活性化に関する法律（平成二十年法律第六十三号）第二条第九項に規定する研究開発法人その他の人工知能関連技術の研究開発を行う機関（以下「研究開発機関」という。）は、基本理念にのっとり、人工知能関連技術の研究開発及びその成果の普及並びに専門的かつ幅広い知識を有する人材の育成に積極的に努めるとともに、第四条の規定に基づき国が実施する施策及び前条の規定に基づき地方公共団体が実施する施策に協力するよう努めるものとする。\n２　国及び地方公共団体は、人工知能関連技術の研究開発及び活用の推進に関する施策で大学に係るものを策定し、及び実施するに当たっては、大学における研究活動の活性化を図るよう努めるとともに、研究者の自主性の尊重その他の大学における研究の特性に配慮しなければならない。\n３　研究開発機関は、人工知能関連技術の研究開発を効果的に進めるに当たっては、人文科学及び自然科学に関する多様な分野の知見を総合的に活用することが必要であることに鑑み、学際的又は総合的な研究開発に努めるものとする。\n第七条　（活用事業者の責務）\n人工知能関連技術を活用した製品又はサービスの開発又は提供をしようとする者その他の人工知能関連技術を事業活動において活用しようとする者（以下「活用事業者」という。）は、基本理念にのっとり、自ら積極的な人工知能関連技術の活用により事業活動の効率化及び高度化並びに新産業の創出に努めるとともに、第四条の規定に基づき国が実施する施策及び第五条の規定に基づき地方公共団体が実施する施策に協力しなければならない。\n第八条　（国民の責務）\n国民は、基本理念にのっとり、人工知能関連技術に対する理解と関心を深めるとともに、第四条の規定に基づき国が実施する施策及び第五条の規定に基づき地方公共団体が実施する施策に協力するよう努めるものとする。\n第九条　（連携の強化）\n国は、国、地方公共団体、研究開発機関及び活用事業者が相互に連携を図りながら協力することにより人工知能関連技術の研究開発及び活用の推進が図られることに鑑み、これらの者の間の連携の強化に必要な施策を講ずるものとする。\n第十条　（法制上の措置等）\n国は、人工知能関連技術の研究開発及び活用の推進に関する施策を実施するため必要な法制上又は財政上の措置その他の措置を講ずるものとする。\n第二章　基本的施策\n第十一条　（研究開発の推進等）\n国は、人工知能関連技術の基礎研究から実用化のための研究開発に至るまでの一貫した研究開発の推進、研究開発機関における研究開発の成果の移転のための体制の整備、研究開発の成果に係る情報の提供その他の施策を講ずるものとする。\n第十二条　（施設及び設備等の整備及び共用の促進）\n国は、人工知能関連技術の研究開発及び活用に当たって必要となる大規模な情報処理、情報通信、電磁的記録（電子的方式、磁気的方式その他人の知覚によっては認識することができない方式で作られる記録であって、電子計算機による情報処理の用に供されるものをいう。）の保管等に係る施設及び設備並びにデータセット（特定の目的をもって収集した情報の集合物をいう。）その他の知的基盤（科学技術・イノベーション創出の活性化に関する法律第二十四条の四に規定する知的基盤をいう。以下この条において同じ。）を研究開発機関及び活用事業者が広く利用できるようにするため、これらの施設及び設備並びに知的基盤の整備及び共用の促進のために必要な施策を講ずるものとする。\n第十三条　（適正性の確保）\n国は、人工知能関連技術の研究開発及び活用の適正な実施を図るため、国際的な規範の趣旨に即した指針の整備その他の必要な施策を講ずるものとする。\n第十四条　（人材の確保等）\n国は、地方公共団体、研究開発機関及び活用事業者と緊密な連携協力を図りながら、人工知能関連技術の基礎研究から国民生活及び経済活動における活用に至るまでの各段階において必要となる専門的かつ幅広い知識を有する多様な分野の人材の確保、養成及び資質の向上に必要な施策を講ずるものとする。\n第十五条　（教育の振興等）\n国は、国民が広く人工知能関連技術に対する理解と関心を深めるよう、人工知能関連技術に関する教育及び学習の振興、広報活動の充実その他の必要な施策を講ずるものとする。\n第十六条　（調査研究等）\n国は、国内外の人工知能関連技術の研究開発及び活用の動向に関する情報の収集、不正な目的又は不適切な方法による人工知能関連技術の研究開発又は活用に伴って国民の権利利益の侵害が生じた事案の分析及びそれに基づく対策の検討その他の人工知能関連技術の研究開発及び活用の推進に資する調査及び研究を行い、その結果に基づいて、研究開発機関、活用事業者その他の者に対する指導、助言、情報の提供その他の必要な措置を講ずるものとする。\n第十七条　（国際協力）\n国は、人工知能関連技術の研究開発及び活用に関する国際協力を推進するとともに、国際的な規範の策定に積極的に参画するものとする。\n第三章　人工知能基本計画\n第十八条\n政府は、基本理念にのっとり、前章に定める基本的施策を踏まえ、人工知能関連技術の研究開発及び活用の推進に関する基本的な計画（以下「人工知能基本計画」という。）を定めるものとする。\n２　人工知能基本計画は、次に掲げる事項について定めるものとする。\n一　人工知能関連技術の研究開発及び活用の推進に関する施策についての基本的な方針\n二　人工知能関連技術の研究開発及び活用の推進に関し、政府が総合的かつ計画的に講ずべき施策\n三　前二号に掲げるもののほか、人工知能関連技術の研究開発及び活用の推進に関する施策を政府が総合的かつ計画的に推進するために必要な事項\n３　内閣総理大臣は、人工知能戦略本部の作成した人工知能基本計画の案について閣議の決定を求めるものとする。\n４　内閣総理大臣は、前項の閣議の決定があったときは、遅滞なく、人工知能基本計画を公表するものとする。\n５　前二項の規定は、人工知能基本計画の変更について準用する。\n第四章　人工知能戦略本部\n第十九条　（設置）\n人工知能関連技術の研究開発及び活用の推進に関する施策を総合的かつ計画的に推進するため、内閣に、人工知能戦略本部（以下「本部」という。）を置く。\n第二十条　（所掌事務）\n本部は、次に掲げる事務をつかさどる。\n一　人工知能基本計画の案の作成及び実施の推進に関すること。\n二　前号に掲げるもののほか、人工知能関連技術の研究開発及び活用の推進に関する施策で重要なものの企画及び立案並びに総合調整に関すること。\n第二十一条　（組織）\n本部は、人工知能戦略本部長、人工知能戦略副本部長及び人工知能戦略本部員をもって組織する。\n第二十二条　（人工知能戦略本部長）\n本部の長は、人工知能戦略本部長（以下「本部長」という。）とし、内閣総理大臣をもって充てる。\n２　本部長は、本部の事務を総括し、所部の職員を指揮監督する。\n第二十三条　（人工知能戦略副本部長）\n本部に、人工知能戦略副本部長（次項及び次条第二項において「副本部長」という。）を置き、内閣官房長官及び人工知能戦略担当大臣（内閣総理大臣の命を受けて、人工知能関連技術の研究開発及び活用の総合的かつ計画的な推進に関し内閣総理大臣を助けることをその職務とする国務大臣をいう。）をもって充てる。\n２　副本部長は、本部長の職務を助ける。\n第二十四条　（人工知能戦略本部員）\n本部に、人工知能戦略本部員（次項において「本部員」という。）を置く。\n２　本部員は、本部長及び副本部長以外の全ての国務大臣をもって充てる。\n第二十五条　（資料の提出その他の協力）\n本部は、その所掌事務を遂行するため必要があると認めるときは、関係行政機関、地方公共団体、独立行政法人（独立行政法人通則法（平成十一年法律第百三号）第二条第一項に規定する独立行政法人をいう。）及び地方独立行政法人（地方独立行政法人法（平成十五年法律第百十八号）第二条第一項に規定する地方独立行政法人をいう。）の長並びに特殊法人（法律により直接に設立された法人又は特別の法律により特別の設立行為をもって設立された法人であって、総務省設置法（平成十一年法律第九十一号）第四条第一項第八号の規定の適用を受けるものをいう。）の代表者に対して、資料の提出、意見の表明、説明その他必要な協力を求めることができる。\n２　本部は、その所掌事務を遂行するために特に必要があると認めるときは、前項に規定する者以外の者に対しても、必要な協力を依頼することができる。\n第二十六条　（事務）\n本部に関する事務は、内閣府において処理する。\n第二十七条　（主任の大臣）\n本部に係る事項については、内閣法（昭和二十二年法律第五号）にいう主任の大臣は、内閣総理大臣とする。\n第二十八条　（政令への委任）\nこの法律に定めるもののほか、本部に関し必要な事項は、政令で定める。\n附　則\n第一条　（施行期日）\nこの法律は、公布の日から施行する。ただし、第三章及び第四章並びに附則第三条及び第四条の規定は、公布の日から起算して三月を超えない範囲内において政令で定める日から施行する。\n第二条　（検討）\n政府は、人工知能関連技術の研究開発及び活用の推進に関する諸施策についての国際的動向その他の社会経済情勢の変化を勘案しつつ、この法律の施行の状況について検討を加え、必要があると認めるときは、その結果に基づいて所要の措置を講ずるものとする。\nEnglish translation (unofficial) Reiwa 7 (2025) Act No. 53\nAct on the Promotion of Research and Development and Utilization of Artificial Intelligence-Related Technology\nTable of Contents\nChapter I General Provisions\n(Articles 1 through 10)\nChapter II Basic Measures\n(Articles 11 through 17)\nChapter III AI Basic Plan\n(Article 18)\nChapter IV AI Strategy Headquarters\n(Articles 19 through 28)\nSupplementary Provisions\nChapter I General Provisions\nArticle 1 (Purpose)\nThis Act, in view of the fact that AI-related technology is a technology that forms the foundation for the development of Japan\u0026rsquo;s economy and society, provides for the basic principles concerning measures for the promotion of the research and development and utilization of AI-related technology, and provides for the formulation of a basic plan concerning the promotion of the research and development and utilization of AI-related technology and other matters that form the basis of measures, and establishes the AI Strategy Headquarters, and thereby, in conjunction with the measures under the Science, Technology and Innovation Basic Act (Act No. 130 of 1995) and the Digital Society Formation Basic Act (Act No. 35 of 2021) and other relevant laws, seeks to achieve the comprehensive and systematic promotion of measures concerning the research and development and utilization of AI-related technology, and thereby to contribute to the improvement of the lives of the people and the sound development of the national economy.\nArticle 2 (Definitions)\nIn this Act, \u0026ldquo;AI-related technology\u0026rdquo; means technology necessary for realizing, by artificial methods, functions that substitute for the intellectual capabilities involved in human cognition, reasoning and judgment, as well as technology concerning information processing systems for realizing functions that process input information by using said technology and output the results thereof.\nArticle 3 (Basic Principles)\nThe promotion of the research and development and utilization of AI-related technology is to be carried out based on the basic principles provided for in this Article, in addition to the policy concerning the promotion of the creation of science, technology and innovation provided for in Article 3 of the Science, Technology and Innovation Basic Act and the basic principles provided for in Chapter II of the Digital Society Formation Basic Act.\n2 The promotion of the research and development and utilization of AI-related technology is to be carried out, in view of the fact that AI-related technology is a technology that forms the foundation for the development of the economy and society by bringing about significant efficiency gains and sophistication in administrative affairs and private business activities and the creation of new industries through its appropriate and effective utilization, and is also an important technology from the perspective of national security, with the aim of maintaining Japan\u0026rsquo;s capacity to conduct the research and development of AI-related technology and enhancing the international competitiveness of industries related to AI-related technology.\n3 The promotion of the research and development and utilization of AI-related technology is to be carried out with the aim of comprehensively and systematically promoting the efforts of the parties concerned at each stage from basic research on AI-related technology to its utilization in the lives of the people and economic activities, in view of the fact that those efforts are closely interrelated with one another.\n4 In view of the fact that, if the research and development and utilization of AI-related technology is carried out for wrongful purposes or by inappropriate methods, there is a risk of encouraging situations in which the tranquility of the lives of the people and the rights and interests of the people are harmed through use in crimes, leakage of personal information, infringement of copyright and other means, necessary measures such as ensuring the transparency of the process of the research and development and utilization of AI-related technology must be taken in order to ensure that such research and development and utilization is carried out properly.\n5 The research and development and utilization of AI-related technology is to be promoted under international coordination so as to contribute to the peace and development of Japan and the international community, and efforts are to be made so that Japan plays a leading role in international cooperation concerning the research and development and utilization of AI-related technology.\nArticle 4 (Responsibilities of the State)\nThe State has the responsibility to comprehensively and systematically formulate and implement measures concerning the promotion of the research and development and utilization of AI-related technology, in accordance with the basic principles provided for in the preceding Article (hereinafter referred to as the \u0026ldquo;basic principles\u0026rdquo;).\n2 The State is to promote the active utilization of AI-related technology in the State\u0026rsquo;s administrative organs in order to achieve efficiency gains and sophistication in administrative affairs.\nArticle 5 (Responsibilities of Local Governments)\nLocal governments have the responsibility to formulate and implement, in accordance with the basic principles, under an appropriate division of roles with the State, and as measures that the local governments should implement concerning the promotion of the research and development and utilization of AI-related technology, independent measures that make use of the characteristics of the areas of the relevant local governments.\nArticle 6 (Responsibilities, etc. of Research and Development Institutions)\nUniversities, research and development corporations provided for in Article 2, paragraph (9) of the Act on the Activation of Science, Technology and Innovation Creation [to verify] (Act No. 63 of 2008) and other institutions that conduct the research and development of AI-related technology (hereinafter referred to as \u0026ldquo;research and development institutions\u0026rdquo;) are to, in accordance with the basic principles, actively endeavor to conduct the research and development of AI-related technology, to disseminate the results thereof, and to foster human resources with specialized and wide-ranging knowledge, and are to endeavor to cooperate with the measures implemented by the State pursuant to the provisions of Article 4 and the measures implemented by local governments pursuant to the provisions of the preceding Article.\n2 When the State and local governments formulate and implement measures concerning the promotion of the research and development and utilization of AI-related technology that relate to universities, they are to endeavor to activate research activities at universities and must give consideration to respect for the autonomy of researchers and other characteristics of research at universities.\n3 Research and development institutions are to endeavor to conduct interdisciplinary or comprehensive research and development, in view of the fact that it is necessary to comprehensively utilize knowledge from diverse fields in the humanities and the natural sciences in order to effectively advance the research and development of AI-related technology.\nArticle 7 (Responsibilities of Utilizing Business Operators)\nPersons who intend to develop or provide products or services utilizing AI-related technology, and other persons who intend to utilize AI-related technology in their business activities (hereinafter referred to as \u0026ldquo;utilizing business operators\u0026rdquo; [to verify]), must, in accordance with the basic principles, endeavor to achieve efficiency gains and sophistication in their business activities and the creation of new industries through their own active utilization of AI-related technology, and must cooperate with the measures implemented by the State pursuant to the provisions of Article 4 and the measures implemented by local governments pursuant to the provisions of Article 5.\nArticle 8 (Responsibilities of the People)\nThe people are to, in accordance with the basic principles, deepen their understanding of and interest in AI-related technology and endeavor to cooperate with the measures implemented by the State pursuant to the provisions of Article 4 and the measures implemented by local governments pursuant to the provisions of Article 5.\nArticle 9 (Strengthening of Coordination)\nThe State is to take the necessary measures for strengthening coordination among the State, local governments, research and development institutions and utilizing business operators, in view of the fact that the promotion of the research and development and utilization of AI-related technology is achieved through cooperation among those parties while they coordinate with one another.\nArticle 10 (Legislative Measures, etc.)\nThe State is to take legislative or financial measures and other measures necessary for implementing measures concerning the promotion of the research and development and utilization of AI-related technology.\nChapter II Basic Measures\nArticle 11 (Promotion of Research and Development, etc.)\nThe State is to take measures for the promotion of consistent research and development from basic research on AI-related technology through research and development for practical application, for the development of systems for transferring the results of research and development at research and development institutions, for the provision of information concerning the results of research and development, and other measures.\nArticle 12 (Development of Facilities and Equipment, etc. and Promotion of Their Shared Use)\nThe State is to take the necessary measures for the development and promotion of the shared use of facilities and equipment and of the knowledge base [to verify], in order to enable research and development institutions and utilizing business operators to make wide use of the facilities and equipment pertaining to large-scale information processing, information and communications, and the storage of electromagnetic records [to verify] (meaning records made in an electronic form, a magnetic form or any other form not perceivable by human senses and used for information processing by computers) that are necessary for the research and development and utilization of AI-related technology, as well as of datasets (meaning collections of information gathered for a specific purpose) and other knowledge bases (meaning the knowledge base provided for in Article 24-4 of the Act on the Activation of Science, Technology and Innovation Creation; hereinafter the same applies in this Article).\nArticle 13 (Ensuring Appropriateness)\nThe State is to take measures for the development of guidelines conforming to the purport of international norms and other necessary measures in order to ensure that the research and development and utilization of AI-related technology is carried out properly.\nArticle 14 (Securing Human Resources, etc.)\nThe State is to take the necessary measures for securing, training and improving the qualities of human resources in diverse fields who have specialized and wide-ranging knowledge required at each stage from basic research on AI-related technology to its utilization in the lives of the people and economic activities, while achieving close coordination and cooperation with local governments, research and development institutions and utilizing business operators.\nArticle 15 (Promotion of Education, etc.)\nThe State is to take measures for the promotion of education and learning concerning AI-related technology, for the enhancement of public relations activities and other necessary measures so that the people may widely deepen their understanding of and interest in AI-related technology.\nArticle 16 (Research and Study, etc.)\nThe State is to conduct research and study contributing to the promotion of the research and development and utilization of AI-related technology, such as the collection of information concerning trends in the research and development and utilization of AI-related technology in Japan and abroad, the analysis of cases in which the rights and interests of the people have been harmed in connection with the research and development or utilization of AI-related technology for wrongful purposes or by inappropriate methods, and the examination of countermeasures based on that analysis, and is to take necessary measures such as guidance, advice and provision of information to research and development institutions, utilizing business operators and other persons based on the results thereof.\nArticle 17 (International Cooperation)\nThe State is to promote international cooperation concerning the research and development and utilization of AI-related technology, and is to actively participate in the formulation of international norms.\nChapter III AI Basic Plan\nArticle 18\nThe Government is to formulate a basic plan concerning the promotion of the research and development and utilization of AI-related technology (hereinafter referred to as the \u0026ldquo;AI Basic Plan\u0026rdquo;), in accordance with the basic principles and based on the basic measures provided for in the preceding Chapter.\n2 The AI Basic Plan is to provide for the following matters:\n(i) the basic policy concerning measures for the promotion of the research and development and utilization of AI-related technology;\n(ii) the measures that the Government should take comprehensively and systematically concerning the promotion of the research and development and utilization of AI-related technology;\n(iii) in addition to the matters set forth in the preceding two items, the matters necessary for the Government to comprehensively and systematically promote measures concerning the promotion of the research and development and utilization of AI-related technology.\n3 The Prime Minister is to seek a Cabinet decision on the draft AI Basic Plan prepared by the AI Strategy Headquarters.\n4 When the Cabinet decision under the preceding paragraph has been made, the Prime Minister is to publish the AI Basic Plan without delay.\n5 The provisions of the preceding two paragraphs apply mutatis mutandis to amendments to the AI Basic Plan.\nChapter IV AI Strategy Headquarters\nArticle 19 (Establishment)\nThe AI Strategy Headquarters (hereinafter referred to as the \u0026ldquo;Headquarters\u0026rdquo;) is established in the Cabinet in order to comprehensively and systematically promote measures concerning the promotion of the research and development and utilization of AI-related technology.\nArticle 20 (Affairs under Its Jurisdiction)\nThe Headquarters is to administer the following affairs:\n(i) matters concerning the preparation of the draft AI Basic Plan and the promotion of its implementation;\n(ii) in addition to the matter set forth in the preceding item, matters concerning the planning and drafting, and the comprehensive coordination, of important measures concerning the promotion of the research and development and utilization of AI-related technology.\nArticle 21 (Organization)\nThe Headquarters is organized with the Director-General of the AI Strategy Headquarters, the Vice-Directors-General of the AI Strategy Headquarters and the Members of the AI Strategy Headquarters.\nArticle 22 (Director-General of the AI Strategy Headquarters)\nThe head of the Headquarters is the Director-General of the AI Strategy Headquarters (hereinafter referred to as the \u0026ldquo;Director-General\u0026rdquo;), and the Prime Minister is appointed to that position.\n2 The Director-General is to supervise the affairs of the Headquarters and direct and supervise the staff of the Headquarters.\nArticle 23 (Vice-Directors-General of the AI Strategy Headquarters)\nVice-Directors-General of the AI Strategy Headquarters (referred to as the \u0026ldquo;Vice-Directors-General\u0026rdquo; in the following paragraph and in paragraph (2) of the following Article) are established in the Headquarters, and the Chief Cabinet Secretary and the Minister in Charge of AI Strategy [to verify] (meaning the Minister of State whose duties are to assist the Prime Minister, under the orders of the Prime Minister, with respect to the comprehensive and systematic promotion of the research and development and utilization of AI-related technology) are appointed to those positions.\n2 The Vice-Directors-General are to assist the Director-General in the performance of the Director-General\u0026rsquo;s duties.\nArticle 24 (Members of the AI Strategy Headquarters)\nMembers of the AI Strategy Headquarters (referred to as the \u0026ldquo;Members\u0026rdquo; in the following paragraph) are established in the Headquarters.\n2 All Ministers of State other than the Director-General and the Vice-Directors-General are appointed as the Members.\nArticle 25 (Submission of Materials and Other Cooperation)\nThe Headquarters may, when it finds it necessary for performing the affairs under its jurisdiction, request the submission of materials, the expression of opinions, explanations and other necessary cooperation from the heads of relevant administrative organs, local governments, incorporated administrative agencies (meaning incorporated administrative agencies provided for in Article 2, paragraph (1) of the Act on General Incorporated Administrative Agencies (Act No. 103 of 1999)) and local incorporated administrative agencies (meaning local incorporated administrative agencies provided for in Article 2, paragraph (1) of the Local Incorporated Administrative Agencies Act (Act No. 118 of 2003)), and from the representatives of special corporations [to verify] (meaning corporations directly established by law, or corporations established by a special act of establishment under a special law, to which the provisions of Article 4, paragraph (1), item (viii) of the Act for Establishment of the Ministry of Internal Affairs and Communications (Act No. 91 of 1999) apply).\n2 The Headquarters may, when it finds it particularly necessary for performing the affairs under its jurisdiction, request necessary cooperation also from persons other than those provided for in the preceding paragraph.\nArticle 26 (Affairs)\nAffairs relating to the Headquarters are handled in the Cabinet Office.\nArticle 27 (Competent Minister)\nWith respect to matters relating to the Headquarters, the competent minister [to verify] referred to in the Cabinet Act (Act No. 5 of 1947) is the Prime Minister.\nArticle 28 (Delegation to Cabinet Orders)\nBeyond what is provided for in this Act, necessary matters relating to the Headquarters are prescribed by Cabinet Order.\nSupplementary Provisions\nArticle 1 (Effective Date)\nThis Act comes into effect as from the day of its promulgation; provided, however, that the provisions of Chapter III and Chapter IV and of Articles 3 and 4 of the Supplementary Provisions come into effect as from the day specified by Cabinet Order within a period not exceeding three months from the day of promulgation.\nArticle 2 (Review)\nThe Government is to review the state of enforcement of this Act while taking into consideration changes in the socioeconomic situation, such as international trends concerning the various measures for the promotion of the research and development and utilization of AI-related technology, and is to take any necessary measures based on the results thereof when it finds it necessary.\n| Scope of the Supplementary Provisions | This page reproduces supplementary provisions Articles 1–2 (effective date; review). The official e-Gov data marks the supplementary provisions as an excerpt (抜粋), and the articles cross-referenced in the proviso to Supplementary Provision Article 1 (\u0026ldquo;Articles 3 and 4 of the Supplementary Provisions\u0026rdquo;) are not included in that data. The text is reproduced faithfully as published, with nothing added. |\n","permalink":"https://ai.intlaws.com/en/compliance/other/japan-ai-promotion-act/","summary":"Official Japanese text of the Act on Promotion of Research, Development and Utilization of AI-Related Technologies (Act No. 53 of 2025, promulgated 4 June 2025), 28 articles in four chapters plus 2 supplementary provisions. The Japanese text below is the authoritative version taken from the official e-Gov database; the English translation is prepared by this journal and is unofficial and for reference only.","title":"Japan's Act on Promotion of Research, Development and Utilization of AI-Related Technologies (Act No. 53 of 2025)"},{"content":" Version and sources (verifiable)\nItem Content Official title 인공지능 발전과 신뢰 기반 조성 등에 관한 기본법 Common name AI Framework Act (AI 기본법) Enactment Act No. 20676, promulgated 21 January 2025 Entry into force 22 January 2026 (one year after promulgation; the part on digital medical devices in Article 2 subparagraph 4(d) from 24 January 2026) Amendments ①Act No. 21065 (1 October 2025, Government Organization Act): in Article 38(1), \u0026ldquo;the Commissioner of the Statistics Korea\u0026rdquo; became \u0026ldquo;the Commissioner of the National Data Administration\u0026rdquo;; ②Act No. 21311 (20 January 2026): certain provisions enter into force 6 months after promulgation Current version In force as of 21 July 2026 (date on which the amending provisions of Act No. 21311 took effect) Structure 6 chapters, 2 sections, 43 articles (plus Article 17-2, 22-2 and 22-3 — 46 article units in total); three sets of addenda Official Korean text National Law Information Center (current version) ｜ Enactment version (Act No. 20676) Official English translation Korea Legislation Research Institute (KLRI) — the English text reproduced on this page is that official KLRI translation Chinese translation 中文译本(本网译校,非官方) Related instrument The Enforcement Decree (Presidential Decree) of this Act is a separate instrument, in force 20 August 2026; not reproduced here Scope Articles 1–43 and the addenda (Act No. 20676; the part of Act No. 21065 affecting this Act; Act No. 21311). Passages that the official page itself marks as omitted (provisions amending other statutes) are reproduced as-is, not completed Verification record 2026-09-22: article sequence 1–43 contiguous (46 article units); chapters and sections match the official text (6 chapters, 2 sections); addenda blocks 3, matching the official source Full text (official Korean text) 제1장 총칙\n제1조(목적) 이 법은 인공지능의 건전한 발전과 신뢰 기반 조성에 필요한 기본적인 사항을 규정함으로써 국민의 권익과 존엄성을 보호하고 국민의 삶의 질 향상과 국가경쟁력을 강화하는 데 이바지함을 목적으로 한다.\n제2조(정의) 이 법에서 사용하는 용어의 뜻은 다음과 같다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n“인공지능”이란 학습, 추론, 지각, 판단, 언어의 이해 등 인간이 가진 지적 능력을 전자적 방법으로 구현한 것을 말한다.\n“인공지능시스템”이란 다양한 수준의 자율성과 적응성을 가지고 주어진 목표를 위하여 실제 및 가상환경에 영향을 미치는 예측, 추천, 결정 등의 결과물을 추론하는 인공지능 기반 시스템을 말한다.\n“인공지능기술”이란 인공지능을 구현하기 위하여 필요한 하드웨어ㆍ소프트웨어 기술 또는 그 활용 기술을 말한다.\n“고영향 인공지능”이란 사람의 생명, 신체의 안전 및 기본권에 중대한 영향을 미치거나 위험을 초래할 우려가 있는 인공지능시스템으로서 다음 각 목의 어느 하나의 영역에서 활용되는 것을 말한다.\n가. 「에너지법」 제2조제1호에 따른 에너지의 공급\n나. 「먹는물관리법」 제3조제1호에 따른 먹는물의 생산 공정\n다. 「보건의료기본법」 제3조제1호에 따른 보건의료의 제공 및 이용체계의 구축ㆍ운영\n라. 「의료기기법」 제2조제1항에 따른 의료기기 및 「디지털의료제품법」 제2조제2호에 따른 디지털의료기기의 개발 및 이용\n마. 「원자력시설 등의 방호 및 방사능 방재 대책법」 제2조제1항제1호에 따른 핵물질과 같은 항 제2호에 따른 원자력시설의 안전한 관리 및 운영\n바. 범죄 수사나 체포 업무를 위한 생체인식정보(얼굴ㆍ지문ㆍ홍채 및 손바닥 정맥 등 개인을 식별할 수 있는 신체적ㆍ생리적ㆍ행동적 특징에 관한 개인정보를 말한다)의 분석ㆍ활용\n사. 채용, 대출 심사 등 개인의 권리ㆍ의무 관계에 중대한 영향을 미치는 판단 또는 평가\n아. 「교통안전법」 제2조제1호부터 제3호까지에 따른 교통수단, 교통시설, 교통체계의 주요한 작동 및 운영\n자. 공공서비스 제공에 필요한 자격 확인 및 결정 또는 비용징수 등 국민에게 영향을 미치는 국가, 지방자치단체, 「공공기관의 운영에 관한 법률」 제4조에 따른 공공기관 등(이하 “국가기관등”이라 한다)의 의사결정\n차. 「교육기본법」 제9조제1항에 따른 유아교육ㆍ초등교육 및 중등교육에서의 학생 평가\n카. 그 밖에 사람의 생명ㆍ신체의 안전 및 기본권 보호에 중대한 영향을 미치는 영역으로서 대통령령으로 정하는 영역\n“생성형 인공지능”이란 입력한 데이터(「데이터 산업진흥 및 이용촉진에 관한 기본법」 제2조제1호에 따른 데이터를 말한다. 이하 같다)의 구조와 특성을 모방하여 글, 소리, 그림, 영상, 그 밖의 다양한 결과물을 생성하는 인공지능시스템을 말한다.\n“인공지능산업”이란 인공지능 또는 인공지능기술을 활용한 제품(이하 “인공지능제품”이라 한다)을 개발ㆍ제조ㆍ생산 또는 유통하거나 이와 관련한 서비스(이하 “인공지능서비스”라 한다)를 제공하는 산업을 말한다.\n“인공지능사업자”란 인공지능산업과 관련된 사업을 하는 자로서 다음 각 목의 어느 하나에 해당하는 법인, 단체, 개인 및 국가기관등을 말한다.\n가. 인공지능개발사업자: 인공지능을 개발하여 제공하는 자\n나. 인공지능이용사업자: 가목의 사업자가 제공한 인공지능을 이용하여 인공지능제품 또는 인공지능서비스를 제공하는 자\n“이용자”란 인공지능제품 또는 인공지능서비스를 제공받는 자를 말한다.\n“영향받는 자”란 인공지능제품 또는 인공지능서비스에 의하여 자신의 생명, 신체의 안전 및 기본권에 중대한 영향을 받는 자를 말한다.\n“인공지능사회”란 인공지능을 통하여 산업ㆍ경제, 사회ㆍ문화, 행정 등 모든 분야에서 가치를 창출하고 발전을 이끌어가는 사회를 말한다.\n“인공지능윤리”란 인간의 존엄성에 대한 존중을 기초로 하여, 국민의 권익과 생명ㆍ재산을 보호할 수 있는 안전하고 신뢰할 수 있는 인공지능사회를 구현하기 위하여 인공지능의 개발, 제공 및 이용 등 모든 영역에서 사회구성원이 지켜야 할 윤리적 기준을 말한다.\n“학습용데이터”란 인공지능의 개발ㆍ활용 등에 사용되는 데이터를 말한다.\n제3조(기본원칙 및 국가 등의 책무) ① 인공지능기술과 인공지능산업은 안전성과 신뢰성을 제고하여 국민의 삶의 질을 향상시키는 방향으로 발전되어야 한다.\n② 영향받는 자는 인공지능의 최종결과 도출에 활용된 주요 기준 및 원리 등에 대하여 기술적ㆍ합리적으로 가능한 범위에서 명확하고 의미 있는 설명을 제공받을 수 있어야 한다.\n③ 국가 및 지방자치단체는 인공지능사업자의 창의정신을 존중하고, 안전한 인공지능 이용환경의 조성을 위하여 노력하여야 한다.\n④ 국가 및 지방자치단체는 인공지능이 가져오는 사회ㆍ경제ㆍ문화와 국민의 일상생활 등 모든 영역에서의 변화에 대응하여 모든 국민이 안정적으로 적응할 수 있도록 시책을 강구하여야 한다.\n⑤ 국가 및 지방자치단체는 인공지능 관련 정책의 개발과 수립 과정에 인공지능제품 또는 인공지능서비스의 이용에 어려움을 겪는 장애인ㆍ고령자 등 대통령령으로 정하는 취약계층(이하 “인공지능취약계층”이라 한다)의 참여를 보장하고 의견이 반영될 수 있도록 노력하여야 한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n제4조(적용범위) ① 이 법은 국외에서 이루어진 행위라도 국내 시장 또는 이용자에게 영향을 미치는 경우에는 적용한다.\n② 이 법은 국방 또는 국가안보 목적으로만 개발ㆍ이용되는 인공지능으로서 대통령령으로 정하는 인공지능에 대하여는 적용하지 아니한다.\n제5조(다른 법률과의 관계) ① 인공지능, 인공지능기술, 인공지능산업 및 인공지능사회(이하 “인공지능등”이라 한다)에 관하여 다른 법률에 특별한 규정이 있는 경우를 제외하고는 이 법에서 정하는 바에 따른다.\n② 인공지능등에 관하여 다른 법률을 제정하거나 개정하는 경우에는 이 법의 목적에 부합하도록 하여야 한다.\n제2장 인공지능의 건전한 발전과 신뢰 기반 조성을 위한 추진체계\n제6조(인공지능 기본계획의 수립) ① 과학기술정보통신부장관은 관계 중앙행정기관의 장 및 지방자치단체의 장의 의견을 들어 3년마다 인공지능기술 및 인공지능산업의 진흥과 국가경쟁력 강화를 위하여 인공지능 기본계획(이하 “기본계획”이라 한다)을 제7조에 따른 국가인공지능전략위원회의 심의ㆍ의결을 거쳐 수립ㆍ변경 및 시행하여야 한다. 다만, 기본계획 중 대통령령으로 정하는 경미한 사항을 변경하는 경우에는 그러하지 아니하다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 기본계획에는 다음 각 호의 사항이 포함되어야 한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n인공지능등에 관한 정책의 기본 방향과 전략에 관한 사항\n인공지능산업의 체계적 육성을 위한 전문인력의 양성 및 인공지능 개발ㆍ활용 촉진 기반 조성 등에 관한 사항\n인공지능윤리의 확산 등 건전한 인공지능사회 구현을 위한 법ㆍ제도 및 문화에 관한 사항\n인공지능기술 개발 및 인공지능산업 진흥을 위한 재원의 확보와 투자의 방향 등에 관한 사항\n4의2. 「공공데이터의 제공 및 이용 활성화에 관한 법률」에 따른 공공데이터를 이용한 학습용데이터 생성, 공공데이터 제공 등의 범위와 기준 및 그 활성화에 관한 사항\n인공지능의 공정성ㆍ투명성ㆍ책임성ㆍ안전성ㆍ접근성 확보 등 신뢰 기반 조성에 관한 사항\n인공지능기술의 발전 방향 및 그에 따른 교육ㆍ노동ㆍ경제ㆍ문화 등 사회 각 영역의 변화와 대응에 관한 사항\n6의2. 인공지능기술의 이해 및 활용을 위한 교육의 지원 및 홍보에 관한 사항\n인공지능제품 또는 인공지능서비스에 대한 인공지능취약계층의 접근ㆍ이용을 보장하기 위한 사항\n그 밖에 인공지능기술 및 인공지능산업의 진흥과 국제협력 등 국가경쟁력 강화를 위하여 과학기술정보통신부장관이 필요하다고 인정하는 사항\n③ 과학기술정보통신부장관은 기본계획을 수립할 때에는 「지능정보화 기본법」 제6조제1항에 따른 종합계획 및 같은 법 제7조제1항에 따른 실행계획을 고려하여야 하며, 제2항제4호의2에 따른 학습용데이터 중 「공공데이터의 제공 및 이용 활성화에 관한 법률」에 따라 공공데이터를 학습용데이터로 제공하기 위한 사항에 대해서는 행정안전부장관과 협의하여 정한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n④ 과학기술정보통신부장관은 관계 중앙행정기관, 지방자치단체 및 공공기관(「지능정보화 기본법」 제2조제16호에 따른 공공기관을 말한다. 이하 같다)의 장에게 기본계획의 수립에 필요한 자료의 제출을 요청할 수 있다. 이 경우 자료의 제출을 요청받은 기관의 장은 특별한 사정이 없으면 이에 따라야 한다.\n⑤ 기본계획은 「지능정보화 기본법」 제13조제1항에 따른 인공지능 및 인공지능산업 분야의 부문별 추진계획으로 본다.\n⑥ 중앙행정기관의 장 및 지방자치단체의 장은 소관 주요 정책을 수립하고 집행할 때 기본계획을 고려하여야 한다.\n⑦ 기본계획의 수립ㆍ변경 및 시행에 필요한 사항은 대통령령으로 정한다.\n제7조(국가인공지능전략위원회) ① 인공지능 발전과 신뢰 기반 조성 등을 위한 주요 정책 등에 관한 사항을 심의ㆍ의결하기 위하여 대통령 소속으로 국가인공지능전략위원회(이하 “위원회”라 한다)를 둔다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 위원회는 위원장 1명과 3명 이내의 부위원장을 포함한 60명 이내의 위원으로 구성한다. 이 경우 제4항제4호에 따른 위원이 전체 위원의 과반수가 되어야 하고, 특정 성(性)으로만 위원회를 구성할 수 없다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n③ 위원회의 위원장은 대통령이 되고, 부위원장은 제4항제1호 또는 제4호에 해당하는 사람 중 대통령이 지명하는 사람이 된다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n④ 위원회의 위원은 다음 각 호의 사람이 된다.\n대통령령으로 정하는 관계 중앙행정기관의 장\n국가안보실의 인공지능에 관한 업무를 담당하는 차장\n대통령비서실의 인공지능에 관한 업무를 보좌하는 수석비서관\n인공지능 관련 전문지식과 경험이 풍부한 사람 중 대통령이 위촉하는 사람\n⑤ 위원회의 위원장은 위원회를 대표하고 위원회의 사무를 총괄한다.\n⑥ 위원회의 위원장은 필요한 경우 부위원장으로 하여금 그 직무를 대행하게 할 수 있다.\n⑦ 제4항제4호에 따른 위원의 임기는 2년으로 하되 한 차례에 한정하여 연임할 수 있다.\n⑧ 위원회에 간사위원 1명을 두며, 간사위원은 제4항제3호의 위원이 된다.\n⑨ 위원회의 위원은 그 직무상 알게 된 비밀을 타인에게 누설하거나 직무상 목적 외의 용도로 사용하여서는 아니 된다. 다만, 다른 법률에 특별한 규정이 있는 경우에는 그러하지 아니하다.\n⑩ 위원회의 위원장은 위원회의 회의를 소집하고 그 의장이 된다.\n⑪ 위원회의 회의는 위원 과반수의 출석으로 개의하고, 출석위원 과반수의 찬성으로 의결한다.\n⑫ 위원회의 업무 및 운영을 지원하기 위하여 위원회에 지원단을 둔다.\n⑬ 위원회는 이 법 시행일부터 5년간 존속한다.\n⑭ 그 밖에 위원회와 제12항에 따른 지원단의 구성 및 운영 등에 필요한 사항은 대통령령으로 정한다.\n[제목개정 2026. 1. 20.]\n제8조(위원회의 기능) ① 위원회는 다음 각 호의 사항을 심의ㆍ의결한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n기본계획의 수립ㆍ변경 및 시행의 점검ㆍ분석에 관한 사항\n인공지능등 관련 국가 비전 및 중장기 전략 수립에 관한 사항\n2의2. 인공지능 관련 정책 및 사업 등의 수립ㆍ조정 및 부처 간 조율에 관한 사항\n2의3. 인공지능 관련 정책 및 사업 등에 대한 이행점검 및 성과관리에 관한 사항\n인공지능등에 관한 연구개발 전략 수립에 관한 사항\n인공지능등에 관한 투자 방향 설정 및 투자 전략 수립에 관한 사항\n인공지능산업 발전과 경쟁력을 저해하는 규제의 발굴 및 개선에 관한 사항\n5의2. 인공지능등 관련 기술ㆍ인력ㆍ입지 등 제도 개선에 관한 사항\n5의3. 인공지능 및 인공지능기술 관련 전문인력의 양성 및 지원에 관한 사항\n인공지능 데이터센터(「지능정보화 기본법」 제40조제1항에 따른 데이터센터를 말한다. 이하 같다) 등 인프라 확충 방안에 관한 사항 6의2. 인공지능 발전을 위한 데이터(학습용데이터를 포함한다) 수집ㆍ관리 및 활용 촉진에 관한 사항\n제조업ㆍ서비스업 등 산업부문 및 공공부문에서의 인공지능 활용 촉진에 관한 사항\n인공지능 국제규범 마련 등 인공지능 관련 국제협력에 관한 사항\n제2항에 따른 권고 또는 의견의 표명에 관한 사항\n고영향 인공지능 규율에 관한 사항\n고영향 인공지능과 관련된 사회적 변화 양상과 정책적 대응에 관한 사항\n이 법 또는 다른 법률에서 위원회의 심의사항으로 정한 사항\n그 밖에 위원회의 위원장이 필요하다고 인정하여 위원회의 회의에 부치는 사항\n② 위원회는 국가기관등의 장 및 인공지능사업자 등에 대하여 인공지능의 올바른 사용과 인공지능윤리의 실천, 인공지능기술의 안전성ㆍ신뢰성에 관한 권고 또는 의견의 표명을 할 수 있다.\n③ 위원회가 국가기관등의 장에게 법령ㆍ제도의 개선 또는 실천방안의 수립 등에 대하여 제2항에 따른 권고 또는 의견의 표명을 한 때에는 해당 국가기관등의 장은 법령ㆍ제도 등의 개선방안과 실천방안 등을 수립하여야 한다.\n제9조(위원의 제척ㆍ기피 및 회피) ① 위원회의 위원은 업무의 공정성 확보를 위하여 다음 각 호의 어느 하나에 해당하는 경우에는 해당 안건의 심의ㆍ의결에서 제척(除斥)된다.\n위원 또는 위원이 속한 법인ㆍ단체 등과 직접적인 이해관계가 있는 경우\n위원의 가족(「민법」 제779조에 따른 가족을 말한다)이 이해관계인인 경우\n② 심의 대상 안건의 당사자(당사자가 법인ㆍ단체 등인 경우에는 그 임원 및 직원을 포함한다)는 위원에게 공정한 직무집행을 기대하기 어려운 사정이 있으면 위원회에 기피 신청을 할 수 있으며, 위원회는 기피 신청이 타당하다고 인정하면 의결로 기피를 결정하여야 한다.\n③ 위원은 제1항 또는 제2항의 사유에 해당하면 스스로 해당 안건의 심의를 회피하여야 한다.\n제10조(분과위원회 등) ① 위원회는 위원회의 업무를 전문 분야별로 수행하기 위하여 필요한 경우 분과위원회를 둘 수 있다.\n② 위원회는 인공지능등 관련 특정 현안을 논의하기 위하여 필요한 경우 특별위원회를 둘 수 있다.\n③ 위원회는 인공지능등 관련 사항을 전문적으로 검토하기 위하여 관계 전문가 등으로 구성된 자문단을 둘 수 있다.\n④ 위원회는 정부 내 인공지능 주요 시책의 수립과 사업의 효율적인 추진을 위하여 대통령령으로 정하는 인공지능책임관으로 구성되는 인공지능책임관협의회를 운영할 수 있다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n⑤ 그 밖에 분과위원회, 특별위원회, 자문단 및 인공지능책임관협의회의 구성ㆍ운영 등에 필요한 사항은 대통령령으로 정한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n제11조(인공지능정책센터) ① 과학기술정보통신부장관은 인공지능 관련 정책의 개발과 국제규범 정립ㆍ확산에 필요한 업무를 종합적으로 수행하기 위하여 인공지능정책센터(이하 “센터”라 한다)를 지정할 수 있다.\n② 센터는 다음 각 호의 사업을 수행한다.\n기본계획의 수립ㆍ시행에 필요한 전문기술의 지원\n인공지능과 관련한 시책의 개발 및 관련 사업의 기획ㆍ시행에 관한 전문기술의 지원\n인공지능의 활용 확산에 따른 사회, 경제, 문화 및 국민의 일상생활 등에 미치는 영향의 조사ㆍ분석\n인공지능 및 인공지능기술 관련 정책 개발을 지원하기 위한 동향 분석，사회ㆍ문화 변화와 미래예측 및 법ㆍ제도의 조사ㆍ연구\n다른 법령에서 센터의 업무로 정하거나 센터에 위탁한 사업\n그 밖에 국가기관등의 장이 위탁하는 사업\n③ 그 밖에 센터의 지정 등에 필요한 사항은 대통령령으로 정한다.\n제12조(인공지능안전연구소) ① 과학기술정보통신부장관은 인공지능과 관련하여 발생할 수 있는 위험으로부터 국민의 생명ㆍ신체ㆍ재산 등을 보호하고 인공지능사회의 신뢰 기반을 유지하기 위한 상태(이하 “인공지능안전”이라 한다)를 확보하기 위한 업무를 전문적이고 효율적으로 수행하기 위하여 인공지능안전연구소(이하 “안전연구소”라 한다)를 운영할 수 있다.\n② 안전연구소는 다음 각 호의 사업을 수행한다.\n인공지능안전 관련 위험 정의 및 분석\n인공지능안전 정책 연구\n인공지능안전 평가 기준ㆍ방법 연구\n인공지능안전 기술 및 표준화 연구\n인공지능안전 관련 국제교류ㆍ국제협력\n제32조에 따른 인공지능시스템의 안전성 확보에 관한 지원\n그 밖에 인공지능안전에 관한 사업으로서 대통령령으로 정하는 사업\n③ 정부는 안전연구소의 운영과 사업 추진 등에 필요한 경비를 예산의 범위에서 출연하거나 지원할 수 있다.\n④ 그 밖에 안전연구소의 운영 등에 필요한 사항은 대통령령으로 정한다.\n제3장 인공지능기술 개발 및 산업 육성\n제1절 인공지능산업 기반 조성\n제13조(인공지능기술 개발 및 안전한 이용 지원) ① 정부는 인공지능기술 개발 활성화를 위하여 다음 각 호의 사업을 지원할 수 있다.\n국내외 인공지능기술 동향ㆍ수준 및 관련 제도의 조사\n인공지능기술의 연구ㆍ개발, 시험 및 평가 또는 개발된 기술의 활용\n인공지능기술 확산, 인공지능기술 협력ㆍ이전 등 기술의 실용화 및 사업화 지원\n인공지능기술의 구현을 위한 정보의 원활한 유통 및 산학협력\n그 밖에 인공지능기술의 개발 및 연구ㆍ조사와 관련하여 대통령령으로 정하는 사업\n② 정부는 인공지능기술의 안전하고 편리한 이용을 위하여 다음 각 호의 사업을 지원할 수 있다.\n「지능정보화 기본법」 제60조제1항 각 호의 사항을 인공지능기술로 구현하는 연구개발 사업\n「지능정보화 기본법」 제60조제3항에 따른 비상정지 기능을 인공지능제품 또는 인공지능서비스에서 구현하기 위한 기술 연구 지원 및 해당 기술의 확산을 위한 사업\n인공지능기술의 개발에 있어서 「지능정보화 기본법」 제61조제2항에 따른 사생활등의 보호에 적합한 설계 기준 및 기술의 연구개발 및 보급 사업\n인공지능기술의 「지능정보화 기본법」 제56조제1항에 따른 사회적 영향평가의 실시와 적용을 위한 연구개발 사업\n인공지능이 인간의 존엄성 및 기본권을 존중하는 방향으로 개발ㆍ이용될 수 있도록 하는 기술 또는 기준 등의 연구개발 및 보급 사업\n인공지능의 안전한 개발과 이용을 위한 인식개선, 올바른 이용방법과 안전 환경 조성을 위한 교육 및 홍보 사업\n그 밖에 인공지능의 개발과 이용에 있어서 국민의 기본권, 신체와 재산을 보호하기 위하여 필요한 사업\n③ 정부는 제2항에 따른 사업의 결과를 누구든지 손쉽게 이용할 수 있도록 공개하고 보급하여야 한다. 이 경우 기술을 개발한 자를 보호하기 위하여 필요한 경우에는 보호기간을 정하여 기술사용료를 받을 수 있게 하거나 그 밖의 방법으로 보호할 수 있다.\n제14조(인공지능기술의 표준화) ① 정부는 인공지능기술, 학습용데이터, 인공지능의 안전성ㆍ신뢰성 등과 관련된 표준화를 위하여 다음 각 호의 사업을 추진할 수 있다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n인공지능기술 관련 표준의 제정ㆍ개정 및 폐지와 그 보급\n인공지능기술 관련 국내외 표준의 조사ㆍ연구개발\n그 밖에 인공지능기술 관련 표준화 사업\n② 정부는 제1항제1호에 따라 제정된 표준을 고시하여 관련 사업자에게 그 준수를 권고할 수 있다.\n③ 정부는 민간 부문에서 추진하는 인공지능기술 관련 표준화 사업에 필요한 지원을 할 수 있다.\n④ 정부는 인공지능기술 표준과 관련된 국제표준기구 또는 국제표준기관과 협력체계를 유지ㆍ강화하여야 한다.\n⑤ 그 밖에 제1항 및 제3항에 따른 표준화 사업의 추진 및 지원 등과 관련하여 필요한 사항은 대통령령으로 정한다.\n제15조(인공지능 학습용데이터 관련 시책의 수립 등) ① 과학기술정보통신부장관은 관계 중앙행정기관의 장과 협의하여 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통ㆍ활용 촉진 및 품질수준 확보 등을 위하여 필요한 시책을 추진하여야 한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 정부는 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통 및 활용 등에 관한 시책을 효율적으로 추진하기 위하여 지원대상사업을 선정하고 예산의 범위에서 지원할 수 있다.\n③ 정부는 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통 및 활용의 활성화 등을 위하여 다양한 학습용데이터를 제작ㆍ생산하여 제공하는 사업(이하 “학습용데이터 구축사업”이라 한다)을 시행할 수 있다.\n④ 과학기술정보통신부장관은 학습용데이터 구축사업의 효율적 수행을 위하여 학습용데이터를 통합적으로 제공ㆍ관리할 수 있는 시스템(이하 “통합제공시스템”이라 한다)을 구축ㆍ관리하고 민간이 자유롭게 이용할 수 있도록 제공하여야 한다.\n⑤ 과학기술정보통신부장관은 통합제공시스템을 이용하는 자에 대하여 비용을 징수할 수 있다.\n⑥ 그 밖에 제2항에 따른 지원대상사업의 선정 및 지원, 학습용데이터 구축사업의 시행, 통합제공시스템의 구축ㆍ관리 및 제5항에 따른 비용의 징수 등에 필요한 사항은 대통령령으로 정한다.\n제2절 인공지능기술 개발 및 인공지능산업 활성화\n제16조(인공지능기술 도입ㆍ활용 시책 등) ① 국가 및 지방자치단체는 기업 및 공공기관의 인공지능기술 도입 촉진 및 활용 확산을 위한 시책을 수립ㆍ시행하여야 한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n② 국가 및 지방자치단체는 기업 및 공공기관의 인공지능기술 도입 촉진 및 활용 확산을 위하여 필요한 경우에는 다음 각 호의 지원을 할 수 있다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n인공지능기술, 인공지능제품 또는 인공지능서비스의 개발 지원 및 연구ㆍ개발 성과의 확산\n인공지능기술을 도입ㆍ활용하고자 하는 기업 및 공공기관에 대한 컨설팅 지원\n2의2. 공공기관이 보유ㆍ관리하고 있는 데이터를 학습용데이터로 생성ㆍ제공하고 적절한 품질수준을 확보하기 위하여 필요한 지원\n「중소기업기본법」 제2조제1항에 따른 중소기업, 「벤처기업육성에 관한 특별법」 제2조제1항에 따른 벤처기업 및 「소상공인기본법」 제2조제1항에 따른 소상공인(이하 “중소기업등”이라 한다)의 임직원에 대한 인공지능기술 도입 및 활용 관련 교육 지원\n중소기업등의 인공지능기술 도입 및 활용에 사용되는 자금의 지원\n그 밖에 기업 및 공공기관의 인공지능기술 도입 및 활용을 촉진하기 위하여 대통령령으로 정하는 사항\n③ 국가기관등은 업무 수행에 필요한 제품 또는 서비스를 구매하거나 용역을 발주하려는 경우 대통령령으로 정하는 인공지능제품 또는 인공지능서비스를 우선적으로 고려하여야 한다. 다만, 업무 특성상 인공지능기술의 활용이 적합하지 아니한 경우에는 그러하지 아니하다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n④ 제3항에 따른 인공지능제품 또는 인공지능서비스의 구매 또는 사용으로 국가기관등에 손해가 발생한 경우에도 그 구매 또는 사용 업무를 담당한 자는 해당 기관의 손해에 대하여 배상할 책임이 없다. 다만, 해당 업무 담당자의 고의 또는 중대한 과실로 손해가 발생한 경우에는 그러하지 아니하다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n⑤ 제2항에 따른 지원에 필요한 사항은 대통령령으로 정한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n[제목개정 2026. 1. 20.]\n제17조(중소기업등을 위한 특별지원) ① 이 법에 따라 인공지능기술 및 인공지능산업과 관련한 각종 지원시책을 시행할 때에는 중소기업등을 우선 고려하여야 한다.\n② 정부는 인공지능산업에 대한 중소기업등의 참여 활성화를 위하여 노력하여야 하며, 이와 관련한 사항을 기본계획에 반영하여야 한다.\n③ 과학기술정보통신부장관은 인공지능의 안전성 및 신뢰성 확보를 위하여 중소기업등의 제34조에 따른 조치 이행 및 제35조에 따른 영향평가를 지원할 수 있다.\n제17조의2(인공지능제품 및 인공지능서비스 이용비용의 지원) ① 국가와 지방자치단체는 경제적 여건으로 인하여 인공지능제품 및 인공지능서비스를 이용하기 어려운 사람에 대하여 예산의 범위에서 그 비용의 전부 또는 일부를 지원할 수 있다.\n② 제1항에 따른 비용 지원의 요건과 대상 등에 필요한 사항은 대통령령으로 정한다.\n[본조신설 2026. 1. 20.]\n제18조(창업의 활성화 등) ① 정부는 인공지능산업 분야의 창업을 활성화하기 위하여 다음 각 호의 사업을 추진할 수 있다.\n인공지능산업 분야의 창업자 발굴 및 육성ㆍ지원 등에 관한 사업\n인공지능산업 분야의 창업 활성화를 위한 교육ㆍ훈련에 관한 사업\n제21조에 따른 전문인력의 우수 인공지능기술에 대한 사업화 지원\n인공지능기술의 가치평가 및 창업자금의 금융지원\n인공지능 관련 연구 및 기술개발 성과의 제공\n인공지능산업 분야의 창업을 지원하는 기관ㆍ단체의 육성\n그 밖에 인공지능산업 분야의 창업 활성화를 위하여 필요한 사업\n② 지방자치단체는 인공지능산업 분야의 창업을 지원하는 공공기관 등 공공단체에 출연하거나 출자할 수 있다.\n③ 중앙행정기관의 장은 인공지능산업 분야의 창업을 활성화하기 위하여 중소벤처기업부장관과 협의하여 「벤처투자 촉진에 관한 법률」 제70조에 따른 벤처투자모태조합을 활용한 지원을 할 수 있다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n④ 제3항에 따른 지원을 위한 자금은 다음 각 호의 재원으로 조성한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n국가, 지방자치단체 또는 공공기관의 출자금\n국가, 지방자치단체 또는 공공기관 외의 자로서 인공지능산업과 관련하여 벤처투자모태조합에 출자를 희망하는 자의 출자금\n그 밖의 부대수입\n⑤ 제3항에 따른 벤처투자모태조합에의 출자에 필요한 사항은 대통령령으로 정한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n[제목개정 2026. 1. 20.]\n제19조(인공지능 융합의 촉진) ① 정부는 인공지능산업과 그 밖의 산업 간 융합을 촉진하고 전 분야에서 인공지능 활용을 활성화하기 위하여 필요한 시책을 수립하여 추진하여야 한다.\n② 정부는 인공지능 융합 제품 및 서비스의 개발을 지원하기 위하여 필요한 경우에는 「국가연구개발혁신법」에 따른 국가연구개발사업에 인공지능 융합 제품 및 서비스에 관한 연구개발과제를 우선적으로 반영하여 추진할 수 있다.\n③ 정부는 제2항에 따라 개발된 인공지능 융합 제품 및 서비스에 대하여는 「정보통신 진흥 및 융합 활성화 등에 관한 특별법」 제37조에 따른 임시허가 및 같은 법 제38조의2에 따른 실증을 위한 규제특례가 원활히 시행될 수 있도록 적극 지원하여야 한다.\n제20조(제도개선 등) ① 정부는 인공지능산업의 발전과 신뢰 기반 조성을 위하여 법령의 정비 등 관련 제도를 개선할 수 있도록 노력하여야 한다.\n② 정부는 제1항에 따른 제도개선을 촉진하기 위하여 관련 법ㆍ제도의 연구 및 사회 각계의 의견수렴 등에 필요한 행정적ㆍ재정적 지원을 할 수 있다.\n제21조(전문인력의 확보) ① 과학기술정보통신부장관은 인공지능기술의 개발 및 인공지능산업의 발전을 위하여 「지능정보화 기본법」 제23조제1항에 따른 시책에 따라 인공지능 및 인공지능기술 관련 전문인력을 양성하고 지원할 수 있도록 다음 각 호의 사업을 추진할 수 있다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n전문인력의 직무역량 강화 및 경력개발을 위한 교육훈련 프로그램 개발ㆍ활용\n전문인력의 취업 지원 및 신규 인력유입 활성화 등 고용 촉진\n전문인력의 공직 진출 기회 확대 등 진출 다변화 촉진\n전문인력의 국내외 연수 지원 및 국제교류 활성화\n전문인력의 근로환경 개선과 처우 증진 등 복지 향상\n그 밖에 인공지능 및 인공지능기술 관련 전문인력의 양성ㆍ지원을 위한 사업\n② 정부는 인공지능 및 인공지능기술 관련 해외 전문인력의 확보를 위하여 다음 각 호의 시책을 추진할 수 있다.\n인공지능 및 인공지능기술 관련 해외 대학ㆍ연구기관ㆍ기업 등의 전문인력에 관한 조사ㆍ분석\n해외 전문인력의 유치를 위한 국제네트워크 구축\n해외 전문인력의 국내 취업 지원\n국내 인공지능 연구기관의 해외진출 및 해외 인공지능 연구기관의 국내 유치 지원\n인공지능 및 인공지능기술 관련 국제기구 및 국제행사의 국내 유치 지원\n그 밖에 해외 전문인력의 확보를 위하여 필요한 사항\n제22조(국제협력 및 해외시장 진출의 지원) ① 정부는 인공지능과 관련한 국제적 동향을 파악하고 국제협력을 추진하여야 한다.\n② 정부는 인공지능산업의 경쟁력 강화와 해외시장 진출을 촉진하기 위하여 인공지능산업에 종사하는 개인ㆍ기업 또는 단체 등에 대하여 다음 각 호의 지원을 할 수 있다.\n인공지능산업 관련 정보ㆍ기술ㆍ인력의 국제교류\n인공지능산업 관련 해외진출에 관한 정보의 수집ㆍ분석 및 제공\n국가 간 인공지능기술, 인공지능제품 또는 인공지능서비스의 공동 연구ㆍ개발 및 국제표준화\n인공지능산업 관련 외국자본의 투자유치\n인공지능등 관련 해외 전문 학회 및 전시회 참가 등 홍보 및 해외 마케팅\n인공지능제품 또는 인공지능서비스의 수출에 필요한 판매체계ㆍ유통체계 및 협력체계 등의 구축\n인공지능윤리에 관한 국제적 동향 파악 및 국제협력\n그 밖에 인공지능산업의 경쟁력 강화와 해외시장 진출 촉진을 위하여 필요한 사항\n③ 정부는 제2항 각 호에 따른 지원을 효율적으로 수행하기 위하여 대통령령으로 정하는 바에 따라 공공기관 또는 그 밖의 단체에 이를 위탁하거나 대행하게 할 수 있으며, 이에 필요한 비용을 보조할 수 있다.\n제22조의2(인공지능연구소의 설립 및 지원 등) ① 대학, 기업 등 대통령령으로 정하는 자는 단독으로 또는 공동으로 인공지능의 개발ㆍ활용에 관한 연구소(이하 “인공지능연구소”라 한다)를 설립ㆍ운영할 수 있다.\n② 제1항에 따라 대학, 기업 등 대통령령으로 정하는 자가 인공지능연구소를 설립하려는 경우에는 다음 각 호의 요건을 갖추고 과학기술정보통신부장관의 허가를 받아야 한다.\n3명 이상의 발기인(發起人)이 있을 것\n제5항의 사업을 수행할 수 있는 인력ㆍ시설 등의 능력을 보유하고 있을 것\n그 밖에 인공지능연구소의 설립ㆍ운영을 위하여 필요한 것으로서 대통령령으로 정하는 요건을 갖출 것\n③ 인공지능연구소에 소장을 둔다. 인공지능연구소의 소장은 인공지능연구소를 대표하고 인공지능연구소의 업무를 총괄한다.\n④ 인공지능연구소의 정관에는 다음 각 호의 사항이 포함되어야 한다.\n목적\n명칭\n사무소의 소재지\n자산에 관한 규정\n소장의 자격과 임면에 관한 규정\n소장의 책임과 권한에 관한 규정\n⑤ 인공지능연구소는 업종별ㆍ기능별로 다음 각 호의 사업을 수행한다.\n인공지능기술 연구개발\n인공지능기술과 다른 기술 및 학제 간 융합에 관한 연구개발\n인공지능기술 연구개발 성과 관리ㆍ이전ㆍ활용 및 사업화\n인공지능기술 연구개발 전문인력 양성\n인공지능기술 연구개발 관련 국제교류ㆍ국제협력\n그 밖에 인공지능기술 연구개발에 필요한 사항\n⑥ 정부와 지방자치단체는 예산의 범위에서 인공지능연구소의 운영과 사업 추진 등에 필요한 경비를 지원할 수 있다.\n⑦ 인공지능연구소는 운영에 필요한 재원을 조성하기 위하여 정부ㆍ지방자치단체 외의 자로부터 보조금 또는 기부금 등을 받거나, 정관으로 정하는 바에 따라 수익사업을 할 수 있다.\n⑧ 인공지능연구소의 소장은 인공지능기술의 연구개발 등을 위하여 필요한 경우 제1항에 따른 대학, 기업 등 대통령령으로 정하는 자와 협의하여 임직원을 파견받거나 겸임근무하게 하여 인공지능연구소의 연구 등을 담당하게 할 수 있으며, 파견받은 임직원의 소속 기관에 필요한 지원을 할 수 있다. 이 경우 필요하면 과학기술정보통신부장관에게 협의를 위한 지원을 요청할 수 있다.\n⑨ 인공지능연구소에 관하여 이 법에서 정한 것을 제외하고는 「민법」 중 재단법인에 관한 규정을 준용한다.\n⑩ 과학기술정보통신부장관은 인공지능연구소가 다음 각 호의 어느 하나에 해당하는 경우 시정을 명하거나 그 설립허가를 취소할 수 있다. 다만, 제1호 또는 제2호에 해당하는 경우 그 허가를 취소하여야 한다.\n거짓이나 그 밖의 부정한 방법으로 설립허가를 받은 경우\n목적 달성이 불가능하게 된 경우\n제2항에 따른 허가 요건을 충족하지 못하게 된 경우\n목적사업 외의 사업을 한 경우\n법령, 정관 또는 이 법에 따른 명령을 위반한 경우\n공익을 해치는 행위를 한 경우\n정당한 사유 없이 설립허가를 받은 날부터 6개월 이내에 목적사업을 시작하지 아니하거나 1년 이상 사업실적이 없는 경우\n⑪ 과학기술정보통신부장관은 제10항에 따라 인공지능연구소의 설립허가를 취소하려는 경우에는 청문을 하여야 한다.\n⑫ 그 밖에 인공지능연구소의 설립 절차, 운영, 지원 등에 필요한 사항은 대통령령으로 정한다.\n[본조신설 2026. 1. 20.]\n제22조의3(인공지능기술 확보를 위한 연구기관의 설립ㆍ운영) 과학기술정보통신부장관은 혁신적인 인공지능기술의 확보를 위하여 필요한 경우 대통령령으로 정하는 바에 따라 인공지능의 개발ㆍ활용 등에 관한 연구를 수행하는 기관을 설립ㆍ운영할 수 있다.\n[본조신설 2026. 1. 20.]\n제23조(인공지능집적단지 지정 등) ① 국가 및 지방자치단체는 인공지능산업의 진흥과 인공지능 개발ㆍ활용의 경쟁력 강화를 위하여 인공지능 및 인공지능기술의 연구ㆍ개발을 수행하는 기업, 기관이나 단체의 기능적ㆍ물리적ㆍ지역적 집적화를 추진할 수 있다.\n② 국가 및 지방자치단체는 제1항에 따른 집적화를 위하여 필요한 경우에는 대통령령으로 정하는 바에 따라 인공지능집적단지(이하 “인공지능집적단지”라 한다)를 지정하여 행정적ㆍ재정적ㆍ기술적 지원을 할 수 있다.\n③ 국가 및 지방자치단체는 다음 각 호의 어느 하나에 해당하는 경우 인공지능집적단지의 지정을 취소할 수 있다. 다만, 제1호에 해당하는 경우에는 그 지정을 취소하여야 한다.\n거짓이나 그 밖의 부정한 방법으로 지정을 받은 경우\n인공지능집적단지 지정의 목적을 달성하기 어렵다고 인공지능집적단지를 지정한 국가 또는 지방자치단체의 장이 인정하는 경우\n④ 정부는 제1항에 따른 집적화를 지역에 효과적으로 정착시키기 위하여 관련 업무를 종합적으로 지원하는 전담기관을 설치하거나 지정할 수 있다.\n⑤ 정부는 제4항에 따른 전담기관의 운영 및 사업 수행에 필요한 비용의 전부 또는 일부를 출연하거나 보조할 수 있다.\n⑥ 그 밖에 인공지능집적단지의 지정 및 지정취소와 제4항에 따른 전담기관의 설치 또는 지정 등에 필요한 사항은 대통령령으로 정한다.\n제24조(인공지능 실증기반 조성 등) ① 국가 및 지방자치단체는 인공지능사업자가 개발하거나 이전받은 기술의 실증, 성능시험, 제30조에 따른 검ㆍ인증등(이하 “실증시험등”이라 한다)을 지원하기 위하여 시험, 평가 등에 필요한 시설ㆍ장비ㆍ설비 등(이하 “실증기반등”이라 한다)을 구축ㆍ운영할 수 있다.\n② 국가 및 지방자치단체는 실증시험등을 촉진하기 위하여 대통령령으로 정하는 기관이 보유하고 있는 실증기반등을 인공지능사업자에게 개방할 수 있다.\n③ 그 밖에 실증기반등의 구축ㆍ운영 및 개방 등에 필요한 사항은 대통령령으로 정한다.\n제25조(인공지능 데이터센터 관련 시책의 추진 등) ① 정부는 인공지능의 개발ㆍ활용 등에 이용되는 데이터센터(이하 “인공지능 데이터센터”라 한다)의 구축 및 운영을 활성화하기 위하여 필요한 시책을 추진하여야 한다.\n② 정부는 제1항에 따른 시책을 추진하기 위하여 다음 각 호의 업무를 수행할 수 있다.\n인공지능 데이터센터의 구축 및 운영에 필요한 행정적ㆍ재정적 지원\n중소기업, 연구기관 등의 인공지능 데이터센터 이용 지원\n인공지능 데이터센터 등 인공지능 관련 인프라 시설의 지역별 균형 발전을 위한 지원\n제26조(한국인공지능진흥협회의 설립) ① 인공지능등과 관련한 연구 및 업무에 종사하는 자는 인공지능의 개발ㆍ이용 촉진, 인공지능산업 및 인공지능기술의 진흥, 인공지능등에 대한 교육ㆍ홍보 등을 위하여 대통령령으로 정하는 바에 따라 과학기술정보통신부장관의 인가를 받아 한국인공지능진흥협회(이하 “협회”라 한다)를 설립하거나 협회로 지정받을 수 있다.\n② 협회는 법인으로 한다.\n③ 협회는 다음 각 호의 업무를 수행한다.\n인공지능기술, 인공지능제품 또는 인공지능서비스의 이용 촉진 및 확산\n인공지능등에 대한 현황 및 관련 통계 조사\n인공지능사업자를 위한 공동이용시설의 설치ㆍ운영 및 전문인력 양성을 위한 교육 등\n인공지능사업자 및 인공지능 관련 전문인력의 해외진출 지원\n안전하고 신뢰할 수 있는 인공지능의 개발ㆍ활용을 위한 교육 및 홍보\n이 법 또는 다른 법률에 따라 협회가 위탁받은 사업\n그 밖에 협회의 설립목적을 달성하는 데 필요한 사업으로서 정관으로 정하는 사업\n④ 국가 및 지방자치단체는 인공지능산업의 발전과 신뢰 기반 조성을 위하여 필요한 경우 예산의 범위에서 협회의 사업수행에 필요한 자금을 지원하거나 운영에 필요한 경비를 보조할 수 있다.\n⑤ 협회 회원의 자격과 임원에 관한 사항, 협회의 업무 등은 정관으로 정하며, 그 밖에 정관에 포함하여야 할 사항은 대통령령으로 정한다.\n⑥ 과학기술정보통신부장관은 제1항에 따른 인가를 한 때에는 그 사실을 공고하여야 한다.\n⑦ 협회에 관하여 이 법에 규정된 것을 제외하고는 「민법」 중 사단법인에 관한 규정을 준용한다.\n제4장 인공지능윤리 및 신뢰성 확보\n제27조(인공지능 윤리원칙 등) ① 정부는 인공지능윤리의 확산을 위하여 다음 각 호의 사항을 포함하는 인공지능 윤리원칙(이하 “윤리원칙”이라 한다)을 대통령령으로 정하는 바에 따라 제정ㆍ공표할 수 있다.\n인공지능의 개발ㆍ활용 등의 과정에서 사람의 생명과 신체, 정신적 건강 등에 해가 되지 아니하도록 하는 안전성과 신뢰성에 관한 사항\n인공지능기술이 적용된 제품ㆍ서비스 등을 모든 사람이 자유롭고 편리하게 이용할 수 있는 접근성에 관한 사항\n사람의 삶과 번영에의 공헌을 위한 인공지능의 개발ㆍ활용 등에 관한 사항\n② 과학기술정보통신부장관은 사회 각계의 의견을 수렴하여 윤리원칙이 인공지능의 개발ㆍ활용 등에 관여하는 모든 사람에 의하여 실현될 수 있도록 실천방안을 수립하고 이를 공개 및 홍보ㆍ교육하여야 한다.\n③ 중앙행정기관 또는 지방자치단체의 장이 인공지능윤리기준(그 명칭 및 형태를 불문하고 인공지능윤리에 관한 법령, 기준, 지침, 가이드라인 등을 말한다)을 제정하거나 개정하는 경우 과학기술정보통신부장관은 윤리원칙 및 제2항에 따른 실천방안과의 연계성ㆍ정합성 등에 관한 권고 또는 의견의 표명을 할 수 있다.\n제28조(민간자율인공지능윤리위원회의 설치 등) ① 다음 각 호의 기관 또는 단체는 윤리원칙을 준수하기 위하여 민간자율인공지능윤리위원회(이하 “민간자율위원회”라 한다)를 둘 수 있다.\n인공지능기술 연구 및 개발을 수행하는 사람이 소속된 교육기관ㆍ연구기관\n인공지능사업자\n그 밖에 대통령령으로 정하는 인공지능기술 관련 기관\n② 민간자율위원회는 다음 각 호의 업무를 자율적으로 수행한다.\n인공지능기술 연구ㆍ개발ㆍ활용에 있어서 윤리원칙의 준수 여부 확인\n인공지능기술 연구ㆍ개발ㆍ활용의 안전 및 인권침해 등에 관한 조사ㆍ연구\n인공지능기술 연구ㆍ개발ㆍ활용의 절차 및 결과에 관한 조사ㆍ감독\n해당 기관 또는 단체의 연구자 및 종사자에 대한 윤리원칙 교육\n인공지능기술 연구ㆍ개발ㆍ활용에 적합한 분야별 인공지능윤리 지침 마련\n그 밖에 윤리원칙 구현에 필요한 업무\n③ 민간자율위원회의 구성ㆍ운영 등에 필요한 사항은 해당 기관 또는 단체 등에서 자율적으로 정한다. 다만, 그 구성을 특정한 성(性)으로만 할 수 없으며, 사회적ㆍ윤리적 타당성을 평가할 수 있는 경험과 지식을 갖춘 사람 및 그 기관 또는 단체에 종사하지 아니하는 사람을 각각 포함하여야 한다.\n④ 과학기술정보통신부장관은 민간자율위원회의 공정하고 중립적인 구성ㆍ운영을 위하여 표준 지침 등을 마련하여 보급할 수 있다.\n제29조(인공지능 신뢰 기반 조성을 위한 시책의 마련) 정부는 인공지능이 국민의 생활에 미치는 잠재적 위험을 최소화하고 안전한 인공지능의 이용을 위한 신뢰 기반을 조성하기 위하여 다음 각 호의 시책을 마련하여야 한다.\n안전하고 신뢰할 수 있는 인공지능 이용환경 조성\n인공지능의 이용이 국민의 일상생활에 미치는 영향 등에 관한 전망과 예측 및 관련 법령ㆍ제도의 정비\n인공지능의 안전성ㆍ신뢰성 확보를 위한 안전기술 및 인증기술의 개발 및 확산 지원\n안전하고 신뢰할 수 있는 인공지능사회 구현 및 인공지능윤리 실천을 위한 교육ㆍ홍보\n인공지능사업자의 안전성ㆍ신뢰성 관련 자율적인 규약의 제정ㆍ시행 지원\n인공지능사업자, 이용자 등으로 구성된 인공지능 관련 단체(이하 “단체등”이라 한다)의 인공지능의 안전성ㆍ신뢰성 증진을 위한 자율적인 협력, 윤리지침 제정 등 민간 활동의 지원 및 확산\n그 밖에 인공지능의 안전성ㆍ신뢰성 확보를 위하여 대통령령으로 정하는 사항\n제30조(인공지능 안전성ㆍ신뢰성 검ㆍ인증등 지원) ① 과학기술정보통신부장관은 단체등이 인공지능의 안전성ㆍ신뢰성 확보를 위하여 자율적으로 추진하는 검증ㆍ인증 활동(이하 “검ㆍ인증등”이라 한다)을 지원하기 위하여 다음 각 호의 사업을 추진할 수 있다.\n인공지능의 개발에 관한 가이드라인 보급\n검ㆍ인증등에 관한 연구의 지원\n검ㆍ인증등에 이용되는 장비 및 시스템의 구축ㆍ운영 지원\n검ㆍ인증등에 필요한 전문인력의 양성 지원\n그 밖에 검ㆍ인증등을 지원하기 위하여 대통령령으로 정하는 사항\n② 과학기술정보통신부장관은 검ㆍ인증등을 받고자 하는 중소기업등에 대하여 대통령령으로 정하는 바에 따라 관련 정보를 제공하거나 행정적ㆍ재정적 지원을 할 수 있다.\n③ 인공지능사업자가 고영향 인공지능을 제공하는 경우 사전에 검ㆍ인증등을 받도록 노력하여야 한다.\n④ 국가기관등이 고영향 인공지능을 이용하려는 경우에는 검ㆍ인증등을 받은 인공지능에 기반한 제품 또는 서비스를 우선적으로 고려하여야 한다.\n제31조(인공지능 투명성 확보 의무) ① 인공지능사업자는 고영향 인공지능이나 생성형 인공지능을 이용한 제품 또는 서비스를 제공하려는 경우 제품 또는 서비스가 해당 인공지능에 기반하여 운용된다는 사실을 이용자에게 사전에 고지하여야 한다.\n② 인공지능사업자는 생성형 인공지능 또는 이를 이용한 제품 또는 서비스를 제공하는 경우 그 결과물이 생성형 인공지능에 의하여 생성되었다는 사실을 표시하여야 한다.\n③ 인공지능사업자는 인공지능시스템을 이용하여 실제와 구분하기 어려운 가상의 음향, 이미지 또는 영상 등의 결과물을 제공하는 경우 해당 결과물이 인공지능시스템에 의하여 생성되었다는 사실을 이용자가 명확하게 인식할 수 있는 방식으로 고지 또는 표시하여야 한다. 이 경우 해당 결과물이 예술적ㆍ창의적 표현물에 해당하거나 그 일부를 구성하는 경우에는 전시 또는 향유 등을 저해하지 아니하는 방식으로 고지 또는 표시할 수 있다.\n④ 그 밖에 제1항에 따른 사전고지, 제2항에 따른 표시, 제3항에 따른 고지 또는 표시의 방법 및 그 예외 등에 관하여 필요한 사항은 대통령령으로 정한다.\n제32조(인공지능 안전성 확보 의무) ① 인공지능사업자는 학습에 사용된 누적 연산량이 대통령령으로 정하는 기준 이상인 인공지능시스템의 안전성을 확보하기 위하여 다음 각 호의 사항을 이행하여야 한다.\n인공지능 수명주기 전반에 걸친 위험의 식별ㆍ평가 및 완화\n인공지능 관련 안전사고를 모니터링하고 대응하는 위험관리체계 구축\n② 인공지능사업자는 제1항 각 호에 따른 사항의 이행 결과를 과학기술정보통신부장관에게 제출하여야 한다.\n③ 과학기술정보통신부장관은 제1항 각 호에 따른 사항의 구체적인 이행 방식 및 제2항에 따른 결과 제출 등에 필요한 사항을 정하여 고시하여야 한다.\n제33조(고영향 인공지능의 확인) ① 인공지능사업자는 인공지능 또는 이를 이용한 제품ㆍ서비스를 제공하는 경우 그 인공지능이 고영향 인공지능에 해당하는지에 대하여 사전에 검토하여야 하며, 필요한 경우 과학기술정보통신부장관에게 고영향 인공지능에 해당하는지 여부의 확인을 요청할 수 있다.\n② 과학기술정보통신부장관은 제1항에 따른 요청이 있는 경우 고영향 인공지능 해당 여부를 확인하여야 하며, 필요한 경우 전문위원회를 설치하여 관련 자문을 받을 수 있다.\n③ 과학기술정보통신부장관은 고영향 인공지능의 기준과 예시 등에 관한 가이드라인을 수립하여 보급할 수 있다.\n④ 그 밖에 제1항에 따른 확인 절차 등에 관하여 필요한 사항은 대통령령으로 정한다.\n제34조(고영향 인공지능과 관련한 사업자의 책무) ① 인공지능사업자는 고영향 인공지능 또는 이를 이용한 제품ㆍ서비스를 제공하는 경우 고영향 인공지능의 안전성ㆍ신뢰성을 확보하기 위하여 다음 각 호의 내용을 포함하는 조치를 대통령령으로 정하는 바에 따라 이행하여야 한다.\n위험관리방안의 수립ㆍ운영\n기술적으로 가능한 범위에서의 인공지능이 도출한 최종결과, 인공지능의 최종결과 도출에 활용된 주요 기준, 인공지능의 개발ㆍ활용에 사용된 학습용데이터의 개요 등에 대한 설명 방안의 수립ㆍ시행\n이용자 보호 방안의 수립ㆍ운영\n고영향 인공지능에 대한 사람의 관리ㆍ감독\n안전성ㆍ신뢰성 확보를 위한 조치의 내용을 확인할 수 있는 문서의 작성과 보관\n그 밖에 고영향 인공지능의 안전성ㆍ신뢰성 확보를 위하여 위원회에서 심의ㆍ의결된 사항\n② 과학기술정보통신부장관은 제1항 각 호에 따른 조치의 구체적인 사항을 정하여 고시하고, 인공지능사업자에게 이를 준수하도록 권고할 수 있다.\n③ 인공지능사업자가 다른 법령에 따라 제1항 각 호에 준하는 조치를 대통령령으로 정하는 바에 따라 이행한 경우에는 제1항에 따른 조치를 이행한 것으로 본다.\n제35조(고영향 인공지능 영향평가) ① 인공지능사업자가 고영향 인공지능을 이용한 제품 또는 서비스를 제공하는 경우 사전에 사람의 기본권에 미치는 영향을 평가(이하 “영향평가”라 한다)하기 위하여 노력하여야 한다. 이 경우 영향평가에는 고영향 인공지능을 이용한 제품 또는 서비스의 성격을 고려하여 인공지능취약계층의 특성이 반영될 수 있도록 하여야 한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 국가기관등이 고영향 인공지능을 이용한 제품 또는 서비스를 이용하려는 경우에는 영향평가를 실시한 제품 또는 서비스를 우선적으로 고려하여야 한다.\n③ 그 밖에 영향평가의 구체적인 내용ㆍ방법 등에 관하여 필요한 사항은 대통령령으로 정한다.\n제36조(국내대리인 지정) ① 국내에 주소 또는 영업소가 없는 인공지능사업자로서 이용자 수, 매출액 등이 대통령령으로 정하는 기준에 해당하는 자는 다음 각 호의 사항을 대리하는 자(이하 “국내대리인”이라 한다)를 서면으로 지정하고, 이를 과학기술정보통신부장관에게 신고하여야 한다.\n제32조제2항에 따른 이행 결과의 제출\n제33조제1항에 따른 고영향 인공지능 해당 여부 확인의 요청\n제34조제1항 각 호에 따른 안전성ㆍ신뢰성 확보 조치의 이행에 필요한 지원(같은 항 제5호에 따른 문서의 최신성ㆍ정확성에 대한 점검을 포함한다)\n② 국내대리인은 국내에 주소 또는 영업소가 있는 자로 한다.\n③ 국내대리인이 제1항 각 호와 관련하여 이 법을 위반한 경우에는 해당 국내대리인을 지정한 인공지능사업자가 그 행위를 한 것으로 본다.\n제5장 보칙\n제37조(인공지능산업의 진흥을 위한 재원의 확충 등) ① 국가는 기본계획 및 이 법에 따른 시책 등을 효과적으로 추진하기 위하여 필요한 재원을 지속적이고 안정적으로 확충할 수 있는 방안을 마련하여야 한다.\n② 과학기술정보통신부장관은 인공지능산업의 진흥을 위하여 필요한 경우에는 공공기관으로 하여금 인공지능산업의 진흥에 관한 사업 등에 필요한 지원을 하도록 권고할 수 있다.\n③ 국가 및 지방자치단체는 기업 등 민간이 적극적으로 인공지능산업의 진흥과 관련된 사업에 투자할 수 있도록 필요한 조치를 마련하여야 한다.\n④ 국가 및 지방자치단체는 인공지능산업의 발전단계 등을 종합적으로 고려하여 투자재원을 효율적으로 집행하도록 노력하여야 한다.\n제38조(실태조사, 통계 및 지표의 작성) ① 과학기술정보통신부장관은 국가데이터처장과 협의하여 기본계획 및 인공지능등 관련 시책과 사업의 기획ㆍ수립ㆍ추진을 위하여 국내외 인공지능등에 관한 실태조사, 통계 및 지표를 「과학기술기본법」 제26조의2에 따른 통계와 연계하여 작성ㆍ관리하고 공표하여야 한다. \u0026lt;개정 2025. 10. 1.\u0026gt;\n② 과학기술정보통신부장관은 제1항에 따른 통계 및 지표의 작성을 위하여 관계 중앙행정기관의 장, 지방자치단체의 장 및 공공기관의 장에게 자료의 제출 등 협조를 요청할 수 있다. 이 경우 협조를 요청받은 기관의 장은 특별한 사정이 없으면 이에 따라야 한다.\n③ 그 밖에 제1항에 따른 실태조사, 통계 및 지표의 작성ㆍ관리 및 공표 등에 필요한 사항은 대통령령으로 정한다.\n제39조(권한의 위임 및 업무의 위탁) ① 과학기술정보통신부장관 또는 관계 중앙행정기관의 장은 이 법에 따른 권한의 일부를 대통령령으로 정하는 바에 따라 소속 기관의 장 또는 특별시장ㆍ광역시장ㆍ특별자치시장ㆍ도지사ㆍ특별자치도지사(이하 이 조에서 “시ㆍ도지사”라 한다)에게 위임할 수 있다. 이 경우 시ㆍ도지사는 위임받은 권한의 일부를 시장(「제주특별자치도 설치 및 국제자유도시 조성을 위한 특별법」 제11조제2항에 따른 행정시장을 포함한다)ㆍ군수ㆍ구청장(자치구의 구청장을 말한다)에게 재위임할 수 있다.\n② 정부는 다음 각 호의 업무를 대통령령으로 정하는 바에 따라 관련 기관 또는 단체에 위탁할 수 있다.\n제13조에 따른 인공지능기술 개발 및 이용 관련 사업에 대한 지원\n제15조제2항 및 제3항에 따른 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통 및 활용 등에 관한 지원대상사업의 선정ㆍ지원과 학습용데이터 구축사업의 추진\n통합제공시스템의 구축ㆍ운영 및 관리\n제18조에 따른 창업 활성화를 위하여 과학기술정보통신부장관이 필요하다고 인정하는 사항\n제30조제2항에 따른 검ㆍ인증등 관련 지원\n제38조에 따른 실태조사, 통계 및 지표의 작성\n그 밖에 인공지능산업의 육성 및 인공지능윤리의 확산을 위하여 대통령령으로 정하는 사무\n제40조(사실조사 등) ① 과학기술정보통신부장관은 다음 각 호의 어느 하나에 해당하는 경우에는 인공지능사업자에 대하여 관련 자료를 제출하게 하거나, 소속 공무원으로 하여금 필요한 조사를 하게 할 수 있다.\n제31조제2항ㆍ제3항, 제32조제1항ㆍ제2항 또는 제34조제1항에 위반되는 사항을 발견하거나 혐의가 있음을 알게 된 경우\n제31조제2항ㆍ제3항, 제32조제1항ㆍ제2항 또는 제34조제1항의 위반에 대한 신고를 받거나 민원이 접수된 경우\n② 과학기술정보통신부장관은 제1항에 따른 조사를 위하여 필요한 경우 소속 공무원으로 하여금 인공지능사업자의 사무소ㆍ사업장에 출입하여 장부ㆍ서류, 그 밖의 자료나 물건을 조사하게 할 수 있다. 이 경우 조사의 내용ㆍ방법 및 절차 등에 관하여 이 법에서 정하는 사항을 제외하고는 「행정조사기본법」에서 정하는 바에 따른다.\n③ 과학기술정보통신부장관은 제1항 및 제2항에 따른 조사 결과 인공지능사업자가 이 법을 위반한 사실이 있다고 인정되면 인공지능사업자에게 해당 위반행위의 중지나 시정을 위하여 필요한 조치를 명할 수 있다.\n제41조(벌칙 적용에서 공무원 의제) ① 위원회의 위원 중 공무원이 아닌 위원은 「형법」 제129조부터 제132조까지에 따른 벌칙을 적용할 때에는 공무원으로 본다.\n② 제39조제2항에 따라 위탁받은 업무에 종사하는 기관 또는 단체의 임직원은 「형법」 제127조 및 제129조부터 제132조까지에 따른 벌칙을 적용할 때에는 공무원으로 본다.\n제6장 벌칙\n제42조(벌칙) 제7조제9항을 위반하여 직무상 알게 된 비밀을 타인에게 누설하거나 직무상 목적 외의 용도로 사용한 자는 3년 이하의 징역 또는 3천만원 이하의 벌금에 처한다.\n제43조(과태료) ① 다음 각 호의 어느 하나에 해당하는 자에게는 3천만원 이하의 과태료를 부과한다.\n제31조제1항을 위반하여 고지를 이행하지 아니한 자\n제36조제1항을 위반하여 국내대리인을 지정하지 아니한 자\n제40조제3항에 따른 중지명령이나 시정명령을 이행하지 아니한 자\n② 제1항에 따른 과태료는 대통령령으로 정하는 바에 따라 과학기술정보통신부장관이 부과ㆍ징수한다.\n부 칙 \u0026lt;법률 제20676호, 2025. 1. 21.\u0026gt;\n제1조(시행일) 이 법은 공포 후 1년이 경과한 날부터 시행한다. 다만, 제2조제4호라목 중 디지털의료기기에 관한 부분은 2026년 1월 24일부터 시행한다.\n제2조(이 법 시행을 위한 준비행위) 이 법을 시행하기 위하여 필요한 위원회 위원의 위촉, 분과위원회, 특별위원회, 자문단 및 지원단의 구성 등은 이 법 시행 전에 할 수 있다.\n제3조(전담기관에 관한 특례) 이 법 시행 당시 제23조제1항에 따른 집적화를 지역에 효과적으로 정착시키기 위하여 정부로부터 관련 예산을 지원받아 운영 중인 기관 중 조직, 인력 등 대통령령으로 정하는 요건을 충족한 기관은 제23조제4항에도 불구하고 이 법에 따라 전담기관으로 지정된 것으로 본다.\n부 칙 \u0026lt;법률 제21065호, 2025. 10. 1.\u0026gt; (정부조직법)\n제1조(시행일) 이 법은 공포한 날부터 시행한다. 다만, 부칙 제7조에 따라 개정되는 법률 중 이 법 시행 전에 공포되었으나 시행일이 도래하지 아니한 법률을 개정한 부분은 각각 해당 법률의 시행일부터ㆍㆍㆍ\u0026lt;생략\u0026gt;ㆍㆍㆍ 시행한다.\n및 2. 생략 제2조부터 제6조까지 생략\n제7조(다른 법률의 개정) ①부터 \u0026lt;95\u0026gt;까지 생략\n\u0026lt;96\u0026gt; 인공지능 발전과 신뢰 기반 조성 등에 관한 기본법 일부를 다음과 같이 개정한다.\n제38조제1항 중 “통계청장”을 “국가데이터처장”으로 한다.\n\u0026lt;97\u0026gt;부터 \u0026lt;626\u0026gt;까지 생략\n제8조 생략\n부 칙 \u0026lt;법률 제21311호, 2026. 1. 20.\u0026gt;\n이 법은 2026년 1월 22일부터 시행한다. 다만, 제3조제5항, 제6조제2항제7호ㆍ제8호, 제16조제3항부터 제5항까지(제2항제2호의2의 개정규정에 관한 부분에 한정한다), 제17조의2, 제18조, 제22조의3 및 제35조제1항 후단의 개정규정은 공포 후 6개월이 경과한 날부터 시행한다.\nOfficial English translation (Korea Legislation Research Institute) Source: KLRI elaw, Statutes of the Republic of Korea — official translation by the Korea Legislation Research Institute (KLRI), reproduced as published, with attribution. © Korea Legislation Research Institute; rights in the translation belong to KLRI.\nFRAMEWORK ACT ON THE DEVELOPMENT OF ARTIFICIAL INTELLIGENCE AND THE CREATION OF A FOUNDATION FOR TRUST\nAct No. 20676, Jan. 21, 2025\nAmended by Act No. 21311, Jan. 20, 2026\nChapter I: General Provisions Article 1 (Purpose)\nThe purpose of this Act is to prescribe the basic matters necessary for the sound development of artificial intelligence and the creation of a foundation for trust in artificial intelligence, thereby contributing to the protection of citizens’ rights, interests, and dignity, the improvement of their quality of life, and the strengthening of national competitiveness.\nArticle 2 (Definitions)\nThe terms used in this Act are defined as follows: \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n\u0026ldquo;Artificial intelligence\u0026rdquo; (AI) means the electronic implementation of human intellectual abilities, including learning, reasoning, perception, judgment, and language comprehension; \u0026ldquo;AI system\u0026rdquo; means an AI-based system that infers outputs such as predictions, recommendations, and decisions that affect real and virtual environments for a given goal with various levels of autonomy and adaptability; \u0026ldquo;AI technology\u0026rdquo; means hardware and software technologies, or their application technologies, necessary to implement AI; \u0026ldquo;High-impact AI\u0026rdquo; means an AI system that is likely to have a significant impact on or pose a risk to human life, physical safety, and fundamental rights, and that is utilized in any of the following areas:\na.\tSupply of energy under subparagraph 1 of Article 2 of the Energy Act;\nb.\tProduction process of drinking water under subparagraph 1 of Article 3 of the Drinking Water Management Act;\nc.\tEstablishment and operation of a system for providing and using health and medical services under subparagraph 1 of Article 3 of the Framework Act on Health and Medical Care;\nd.\tDevelopment and use of medical devices under Article 2(1) of the Medical Devices Act and digital medical devices under subparagraph 2 of Article 2 of the Digital Medical Products Act;\ne.\tSafe management and operation of nuclear materials under Article 2(1)1 of the Act on Physical Protection and Radiological Emergency and nuclear facilities under subparagraph 2 of that paragraph;\nf.\tAnalysis and utilization of biometric information (referring to personal information on physical, physiological, and behavioral characteristics by which an individual can be identified, such as facial, fingerprint, iris, and palm vein patterns) for criminal investigation or arrests;\ng.\tJudgments or evaluations that have a significant impact on the rights and obligations of individuals, such as hiring and loan screening;\nh.\tMajor operation and management of means of transportation, traffic facilities, and traffic systems under subparagraphs 1 through 3 of Article 2 of the Traffic Safety Act;\ni.\tDecision-making by the State, a local government, a public institution under Article 4 of the Act on the Management of Public Institutions, or other such entity (hereinafter referred to as \u0026ldquo;State agency or other public entity\u0026rdquo;) that affects citizens, such as through the verification and determination of qualifications required for the provision of public services or the collection of expenses;\nj.\tEvaluation of students in early childhood education, elementary education, and secondary education under Article 9(1) of the Framework Act on Education;\nk.\tOther areas prescribed by Presidential Decree, which have a significant impact on the protection of human life, physical safety, and fundamental rights; \u0026ldquo;Generative AI\u0026rdquo; means an AI system that generates text, sound, images, videos, and other various outputs by imitating the structure and characteristics of input data (referring to data defined in subparagraph 1 of Article 2 of the Framework Act on Promotion of Data Industry and Data Utilization; hereinafter the same shall apply); \u0026ldquo;AI industry\u0026rdquo; means an industry that develops, manufactures, produces, or distributes products utilizing AI or AI technology (hereinafter referred to as \u0026ldquo;AI products\u0026rdquo;) or provides services related thereto (hereinafter referred to as \u0026ldquo;AI services\u0026rdquo;); \u0026ldquo;AI business operator\u0026rdquo; means any of the following corporations, organizations, individuals, State agencies and other public entities that is engaged in business related to the AI industry:\na.\tAI development business operator: A person that develops and provides AI;\nb.\tAI use business operator: A person that provides AI products or AI services using AI provided by a business operator under item a; \u0026ldquo;User\u0026rdquo; means a person that is provided with an AI product or AI service; \u0026ldquo;Impacted person\u0026rdquo; means a person whose life, physical safety, and fundamental rights are significantly impacted by AI products or AI services; \u0026ldquo;AI society\u0026rdquo; means a society that creates value and drives development in all fields, including industry, the economy, society, culture, and public administration, through AI; \u0026ldquo;AI ethics\u0026rdquo; means the ethical standards that all members of society should observe in all areas, including the development, provision, and use of AI, in order to realize a safe and trustworthy AI society capable of protecting citizens’ rights, interests, lives, and property based on respect for human dignity; \u0026ldquo;Training data\u0026rdquo; means data used for AI development, utilization, and other related purposes.\nArticle 3 (Basic principles and the State\u0026rsquo;s responsibilities)\n(1)\tAI technology and the AI industry shall be developed in a manner that enhances safety and trustworthiness, thereby improving the quality of life of the people.\n(2)\tAn impacted person shall be entitled to be provided with a clear and meaningful explanation of the main criteria, principles, etc. utilized in deriving the final results of AI, to the extent technically and reasonably possible.\n(3)\tThe State and local governments shall respect the creative spirit of AI business operators and endeavor to create a safe environment for the use of AI.\n(4)\tThe State and local governments shall devise policy measures to ensure that all citizens can stably adapt to the changes brought about by AI in all areas, including society, the economy, and culture, as well as in the daily lives of the people.\n(5)\tThe State and local governments shall endeavor to ensure the participation of, and to reflect the opinions of, vulnerable groups prescribed by Presidential Decree who experience difficulties in using AI products or AI services, including persons with disabilities and the senior citizens (hereinafter referred to as \u0026ldquo;AI-vulnerable groups\u0026rdquo;), in the process of developing and establishing AI-related policies. \u0026lt;Add on Jan. 20, 2026\u0026gt;\nArticle 4 (Scope of application)\n(1)\tThis Act shall apply to any conduct outside the Republic of Korea if the conduct impacts the domestic market or users.\n(2)\tThis Act shall not apply to AI prescribed by Presidential Decree that is developed and used solely for the purpose of national defense or national security.\nArticle 5 (Relationship to other statutes)\n(1)\tExcept as otherwise expressly provided in other statutes, this Act shall apply to AI, AI technology, the AI industry, and AI society (hereinafter referred to as \u0026ldquo;AI and related matters\u0026rdquo;).\n(2)\tThe enactment or amendment of other statutes regarding AI and related matters shall be made in conformity with the purpose of this Act. Chapter II: System For Promoting Sound Development Of Ai And Creation Of Foundation For Trust Article 6 (Formulation of AI master plans)\n(1)\tThe Minister of Science and ICT shall formulate, modify, and implement an AI master plan (hereinafter referred to as \u0026ldquo;master plan\u0026rdquo;), subject to deliberation and resolution by the Presidential Council on National Artificial Intelligence Strategy under Article 7, for the promotion of AI technology and the AI industry and the enhancement of national competitiveness every 3 years after hearing the opinions of the heads of relevant central administrative agencies and the heads of local governments; provided, the foregoing shall not apply to modifications concern minor matters prescribed by Presidential Decree in the master plan. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(2)\tThe master plan shall include the following: \u0026lt;Amended on Jan. 20, 2026\u0026gt;\nMatters regarding the basic direction and strategies for policies on AI and related matters; Matters regarding the training of professionals for the systematic fostering of the AI industry, the establishment of a foundation for promoting the development and utilization of AI, and other related matters; Matters regarding statutes, systems, and culture for the realization of a sound AI society, such as the dissemination of AI ethics; Matters regarding the securing of financial resources, the direction of investment, etc. for the development of AI technology and the promotion of the AI industry;\n4-2.\tMatters regarding the scope and standards for the generation of training data using public data, the provision of public data, and other related activities, and the promotion thereof, under the Act on Promotion of the Provision and Use of Public Data; Matters regarding the creation of a foundation for trust, including ensuring fairness, transparency, accountability, safety, and accessibility of AI; Matters regarding the direction of development of AI technology, and changes and responses in various areas of society, such as education, labor, economy, and culture;\n6-2.\tMatters regarding support for education and public awareness campaigns for understanding and utilizing AI technology; Matters to ensure access to and use of AI products or AI services by AI-vulnerable groups; Other matters deemed necessary by the Minister of Science and ICT to strengthen national competitiveness, including promotion of AI technology and the AI industry and international cooperation.\n(3)\tWhen the Minister of Science and ICT formulates a master plan, the Minister shall consider the comprehensive plan under Article 6(1) of the Framework Act on Intelligent Informatization and the action plan under Article 7(1) of that Act, and shall determine, in consultation with the Minister of the Interior and Safety, matters regarding the provision of public data as training data under the Act on Promotion of the Provision and Use of Public Data among training data referred to in paragraph (2)4-2. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(4)\tThe Minister of Science and ICT may request the heads of relevant central administrative agencies, heads of local governments, and heads of public institutions (referring to public institutions under subparagraph 16 of Article 2 of the Framework Act on Intelligent Informatization (hereinafter referred to as \u0026ldquo;public institutions\u0026rdquo;; hereinafter the same shall apply) to submit data necessary for the formulation of a master plan. In this case, the head of the agency, local government, or public institution requested to submit data shall comply with the request unless there is a compelling reason not to do so.\n(5)\tThe master plan shall be deemed a sectoral implementation plan for the fields of AI and the AI industry under Article 13(1) of the Framework Act on Intelligent Informatization.\n(6)\tThe heads of central administrative agencies and the heads of local governments shall take the master plan into consideration when establishing and executing policies under their jurisdictions.\n(7)\tOther matters necessary for the formulation, modification, and implementation of master plans shall be prescribed by Presidential Decree.\nArticle 7 (Presidential Council on National Artificial Intelligence Strategy)\n(1)\tA Presidential Council on National Artificial Intelligence Strategy (hereinafter referred to as the \u0026ldquo;Council\u0026rdquo;) shall be established under the President to deliberate and resolve on matters related to major policies, etc. for the development of AI and the creation of a foundation for trust. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(2)\tThe Council shall consist of up to 60 members, including 1 chair and up to 3 vice chairs. In this case, the members under paragraph (4)4 shall constitute a majority of all the members, and the Council shall not be composed exclusively of members of a single gender. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(3)\tThe President shall be the chair of the Council, and the vice chairs shall be persons designated by the President from among those under paragraph (4)1 or 4. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(4)\tMembers of the Council shall be the following persons: Heads of relevant central administrative agencies prescribed by Presidential Decree; Deputy director of the National Security Office who is responsible for AI affairs; Senior secretary of the Office of President responsible for AI affairs; Persons with extensive expertise and experience in AI who are commissioned by the President.\n(5)\tThe chair of the Council shall represent the Council and have general supervision and control of the affairs of the Council.\n(6)\tThe chair of the Council may have the vice chairs of the Council perform the duties on behalf of the chair, if necessary.\n(7)\tThe term of office for members under paragraph (4)4 shall be 2 years, and members may be appointed consecutively for only 1 further term.\n(8)\tThe Council shall have 1 executive secretary, who shall be a member under paragraph (4)3.\n(9)\tA member of the Council shall not disclose secrets obtained in the course of performing the duties to others or use them for purposes other than those of the duties; provided, this shall not apply if there are special provisions in other statutes.\n(10)\tThe chair of the Council shall convene and preside over meetings of the Council.\n(11)\tA majority of the members of the Council shall constitute a quorum, and any decision thereof shall require the concurring vote of a majority of those present.\n(12)\tA secretariat shall be established within the Council to support the work and operations of the Council.\n(13)\tThe Commission shall remain in existence for 5 years from the date this Act enters into force.\n(14)\tOther matters necessary for the composition and operation of the Council and the secretariat under paragraph (12) shall be prescribed by Presidential Decree.\n[Title Amended on Jan. 20, 2026]\nArticle 8 (Functions of the Council)\n(1)\tThe Council shall deliberate and decide on the following: \u0026lt;Amended on Jan. 20, 2026\u0026gt; Matters regarding inspection and analysis of the formulation, modification, and implementation of the master plan; Matters regarding the establishment of national vision and mid- to long-term strategies for AI and related matters;\n2-2.\tMatters regarding the establishment, coordination, and inter-ministerial coordination of policies, programs, and other matters related to AI; Matters regarding implementation monitoring and performance management for policies and programs related to AI; Matters regarding the establishment of research and development strategies for AI and related matters; Matters regarding the establishment of investment directions and the formulation of strategies for AI and related matters; Matters regarding the identification and improvement of regulations that hinder the development and competitiveness of the AI industry;\n5-2.\tMatters regarding institutional improvements related to technologies, human resources, and locations for AI and related matters;\n5-3.\tOther matters regarding the training and support of professionals in AI and AI technology. Matters regarding plans for expansion of infrastructure such as AI data centers (referring to data centers under Article 40(1) of the Framework Act on Intelligent Informatization; hereinafter the same shall apply);\n6-2.\tMatters regarding the promotion of data (including training data) collection, management, and utilization for the advancement of AI; Matters regarding the promotion of AI utilization in industrial sectors, such as manufacturing and service industries, as well as in the public sector; Matters regarding international cooperation related to AI, including the establishment of international AI norms; Matters regarding the expression of recommendations or opinions under paragraph (2); Matters regarding the regulation of high-impact AI; Matters regarding the patterns of social change associated with high-impact AI and policy responses; Matters specified by this Act or any other statute requiring deliberation by the Council; Other matters deemed necessary by the chair of the Council to be submitted to a meeting of the Council.\n(2)\tThe Council may make recommendations or express opinions to the heads of State agencies and public entities, AI business operators, and other such entities regarding the proper use of AI, the practice of AI ethics, the safety and trustworthiness of AI technology.\n(3)\tWhen the Council makes recommendations or expresses opinions under paragraph (2) to the head of a State agency or other public entity regarding the improvement of statutes, regulations, or systems, or the formulation of action plans, the head of the State agency or entity shall formulate improvement plans for statutes, regulations, or systems, as well as action plans.\nArticle 9 (Exclusion of, challenge to, and recusal by member)\n(1)\tWhere any of the following applies to a member of the Council, the member shall be excluded from deliberation and resolution on the relevant agenda item to ensure the impartial performance of the duties: Where a member or a corporation or organization to which the member belongs has a direct interest in the relevant agenda item; Where a family member of a member (referring to any of the family members as defined in Article 779 of the Civil Act) is an interested party.\n(2)\tA party to an agenda item subject to deliberation (including its executive officers and employees if the party is a corporation or organization) may file a request for challenge to a member with the Council if the circumstances indicate that it would be impractical to expect the member to perform their duties impartially, and the Council shall make a decision to challenge by resolution if it recognizes that the request for challenge is valid.\n(3)\tIf the ground under paragraph (1) or (2) applies to a member, the member shall recuse himself or herself from the deliberation on the relevant agenda item.\nArticle 10 (Expert standing committees)\n(1)\tThe Council may establish expert standing committees, where necessary, in order to perform its affairs in specialized areas.\n(2)\tThe Council may establish special committees, where necessary, in order to discuss specific issues related to AI and related matters.\n(3)\tThe Council may establish an advisory committee consisting of relevant experts and others to professionally review matters regarding AI and related matters.\n(4)\tThe Council may operate a council of chief AI officers, composed of chief AI officers as prescribed by Presidential Decree, for the purpose of establishing major government-wide AI policy measures and promoting the efficient implementation of related programs. \u0026lt;Added on Jan. 20, 2026\u0026gt;\n(5)\tOther matters necessary for the composition, operation, etc. of expert standing committees, special committees, advisory committees, and the council of chief AI officers shall be prescribed by Presidential Decree. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\nArticle 11 (AI Policy Center)\n(1)\tThe Minister of Science and ICT may designate an AI Policy Center (hereinafter referred to as the \u0026ldquo;Center\u0026rdquo;) to comprehensively perform the affairs necessary for the development of AI-related policies and the establishment and dissemination of international norms.\n(2)\tThe Center shall perform the following functions: Provision of specialized technical support required for the formulation and implementation of master plans; Provision of specialized technical support for the development of AI-related policy measures and the planning and implementation of related programs; Investigation and analysis of the impact of the expanded utilization of AI on society, the economy, culture, and the daily lives of the people; Trend analyses, social and cultural changes and future forecasting, and investigation and research on laws and systems to support the development of policies related to AI and AI technology; Functions assigned to the Center as its duties or entrusted to the Center under other statutes and regulations; Other tasks entrusted by the head of a State agency or other public entity.\n(3)\tOther matters necessary for the designation, etc. of the Center shall be prescribed by Presidential Decree.\nArticle 12 (AI Safety Institute)\n(1)\tThe Minister of Science and ICT may operate an AI Safety Institute (hereinafter referred to as \u0026ldquo;AISI\u0026rdquo;) to professionally and efficiently perform its duties to secure the state of protecting citizens\u0026rsquo; lives, physical well-being, and property from risks arising in relation to AI and maintaining of a foundation for trust in an AI society (hereinafter referred to as \u0026ldquo;AI safety\u0026rdquo;).\n(2)\tAISI shall perform the following projects: Definition and analysis of risks related to AI safety; Research on AI safety policies; Research on criteria and methods for AI safety evaluation; Research on AI safety technologies and standardization; Promoting international exchange and cooperation related to AI safety; Support for ensuring the safety of AI systems under Article 32; Other projects prescribed by Presidential Decree that are related to AI safety.\n(3)\tThe Government may contribute to or support the expenses necessary for the operation and project implementation of AISI within the budget.\n(4)\tOther matters necessary for the operation, etc. of AISI shall be prescribed by Presidential Decree. Chapter III: Development Of Ai Technology And Fostering Of Ai Industry SECTION 1 Establishment of Foundation for AI Industry\nArticle 13 (Support for development and safe use of AI technology)\n(1)\tThe Government may support the following programs to promote the development of AI technology:\nInvestigation of domestic and international trends and levels of AI technology and related systems; Research and development, testing, and evaluation of AI technology, or utilization of the developed technology; Support for the practical application and commercialization of AI technology, including the dissemination, cooperation, and transfer of AI technology; Efficient dissemination of information and promotion of industry-academia cooperation for the implementation of AI technology; Other programs prescribed by Presidential Decree related to the development, research, and investigation of AI technology.\n(2)\tThe Government may support the following programs for the safe and convenient use of AI technology: Research and development programs that implement the matters under the subparagraphs of Article 60(1) of the Framework Act on Intelligent Informatization with AI technology; Programs to support research on technologies for implementing emergency stop functions under Article 60(3) of the Framework Act on Intelligent Informatization in AI products or AI services and to promote the dissemination of such technologies; Programs for research and development and dissemination of design criteria and technologies suitable for the protection of privacy and personal information under Article 61 (2) of the Framework Act on Intelligent Informatization in the development of AI technology; Research and development programs for the implementation and application of social impact assessments of AI technology in accordance with Article 56(1) of the Framework Act on Intelligent Informatization; Programs for research and development and dissemination of technologies, criteria, etc. that enable AI to be developed and used in a manner that respects human dignity and fundamental rights; Programs for awareness improvement of the safe development and use of AI, and for providing education and public campaigns to promote proper usage methods and safe environment creation; Other programs necessary for the protection of citizens’ fundamental rights, physical safety, and property in the development and use of AI.\n(3)\tThe Government shall disclose and disseminate the results of the programs referred in paragraph (2) so that anyone can readily access and use them. In such cases, where necessary to protect those who have developed technologies under such programs, a protection period may be established to allow those persons to receive royalties or to be protected through other means.\nArticle 14 (Standardization of AI technology)\n(1)\tThe Government may implement the following programs for standardization related to the AI technology, training data, and the safety and trustworthiness of AI: \u0026lt;Amended on Jan. 20, 2026\u0026gt; Establishment, revision, and abolition of standards related to AI technology, and their dissemination; Investigation and research and development of domestic and international standards related to AI technology; Other standardization programs related to AI technology.\n(2)\tThe Government may publicly notify the standards established under paragraph (1)1 and recommend that relevant business operators comply with them.\n(3)\tThe Government may provide support necessary for standardization programs related to AI technology undertaken by the private sector.\n(4)\tThe Government shall maintain and strengthen the cooperation system with international standards organizations or international standards bodies related to AI technology standards.\n(5)\tOther matters necessary for the promotion and support of standardization programs under paragraphs (1) and (3) shall be prescribed by Presidential Decree.\nArticle 15 (Establishment of policies measures related to AI training data)\n(1)\tThe Minister of Science and ICT shall, in consultation with the heads of relevant central administrative agencies, implement necessary policy measures to facilitate the production, collection, management, distribution, and utilization of training data, and to ensure the quality level thereof. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(2)\tThe Government may select projects eligible for support and provide assistance within the budget to efficiently promote policy measures related to the production, collection, management, distribution, and utilization of training data.\n(3)\tThe Government may implement a project that produces and provides various training data (hereinafter referred to as \u0026ldquo;training data development project\u0026rdquo;) to promote the production, collection, management, distribution, and utilization of training data.\n(4)\tThe Minister of Science and ICT shall establish and manage a system that can integrally provide and manage training data (hereinafter referred to as the \u0026ldquo;integrated provision system\u0026rdquo;) for the efficient implementation of the training data development project and make it freely available to the private sector.\n(5)\tThe Minister of Science and ICT may collect fees from persons using the integrated provision system.\n(6)\tMatters necessary for selecting and supporting target projects under paragraph (2), the implementation of the training data development project, the establishment and management of the integrated provision system, and the collection of fees under paragraph (5) shall be prescribed by Presidential Decree.\nSECTION 2 Development of AI technology and Promotion of the AI industry\nArticle 16 (Policy measures for adoption and utilization of AI technology)\n(1)\tThe State and local governments shall establish and implement policy measures to promote the adoption and widespread utilization of AI technology by enterprises and public institutions: \u0026lt;Added on Jan. 20, 2026\u0026gt;\n(2)\tThe State and local governments may, if necessary, provide the following support to promote the adoption and utilization of AI technology by enterprises and public institutions: \u0026lt;Amended on Jan. 20, 2026\u0026gt; Support for the development of AI technology, AI products, or AI services, and the dissemination of research and development outcomes; Consulting support for enterprises and public institutions seeking to adopt and utilize AI technology;\n2-2.\tSupport necessary for public institutions to generate and provide data they hold and manage as training data, and to ensure an appropriate level of quality; Support for education related to the adoption and utilization of AI technology for executive officers and employees of small and medium enterprises under Article 2(1) of the Framework Act on Small and Medium Enterprises, venture businesses under Article 2(1) of the Special Act on the Promotion of Venture Businesses, and micro enterprises under Article 2(1) of Framework Act on Micro Enterprises (hereinafter referred to as \u0026ldquo;small and medium enterprises, etc.\u0026rdquo;); Funding for the adoption and utilization of AI technology by small and medium enterprises, etc.; Other matters prescribed by Presidential Decree to promote the adoption and utilization of AI technology by enterprises and public institutions.\n(3)\tA State agency or other public entity shall give priority consideration to AI products or AI services prescribed by Presidential Decree where intending to procure products or services or award service contracts necessary for the performance of its duties; provided, this shall not apply where the use of AI technology is not appropriate due to the nature of the duties. \u0026lt;Added on Jan. 20, 2026\u0026gt;\n(4)\tEven where damage occurs to a State agency or other public entity as a result of the purchase or use of AI products or AI services under paragraph (3), the person in charge of the purchase or use shall not be liable for compensation for damages to the agency or entity; provided, this shall not apply if the damages resulted from the intentional conduct or gross negligence of that person. \u0026lt;Added on Jan. 20, 2026\u0026gt;\n(5)\tMatters necessary for support under paragraph (2) shall be prescribed by Presidential Decree. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n[Title Amended on Jan. 20, 2026]\nArticle 17 (Special support for small and medium enterprises, etc.)\n(1)\tWhen implementing various support policy measures related to AI technology and the AI industry under this Act, priority shall be given to small and medium enterprises, etc.\n(2)\tThe Government shall endeavor to promote participation of small and medium enterprises, etc. in the AI industry and shall reflect matters related thereto in the master plan.\n(3)\tThe Minister of Science and ICT may provide support to small and medium enterprises, etc., in implementing the measures under Article 34 and in conducting impact assessments under Article 35 to ensure the safety and trustworthiness of AI.\nArticle 17-2 (Support for expenses of using AI products and AI services)\n(1)\tThe State and local governments may, within the budget, provide financial support to cover all or part of the expenses of using AI products and AI services for individuals who have difficulty accessing the products and services due to economic circumstances.\n(2)\tThe requirements, eligible recipients, and other necessary matters for cost support under paragraph (1) shall be prescribed by Presidential Decree.\n[This Article Added on Jan. 20, 2026]\nArticle 18 (Promotion of business start-up)\n(1)\tThe Government may implement the following programs to promote business start-up in the AI industry: Programs related to the identification, fostering, and support of entrepreneurs in the AI industry sectors; Programs related to education and training for the promotion of business start-up in the AI industry sectors; Support for the commercialization of advanced AI technology developed by professionals under Article 21; Valuation of AI technology and financial support for startup funding; Provision of AI-related research and technology development outcomes; Fostering institutions and organizations that support business start-up in the AI industry sectors; Other programs necessary to promote business start-up in the AI industry sectors.\n(2)\tLocal governments may contribute to or invest in public organizations such as public institutions that support business start-up in the AI industry sectors.\n(3)\tThe head of a central administrative agency may, in consultation with the Minister of SMEs and Startups, provide support through the fund of funds for venture investment established under Article 70 of the Venture Investment Promotion Act in order to encourage business start-up in the AI industry. \u0026lt;Added on Jan. 20, 2026\u0026gt;\n(4)\tThe funds for the support under paragraph (3) shall be created with the following financial resources: \u0026lt;Added on Jan. 20, 2026\u0026gt; Capital contributions made by the State, local governments, or public institutions; Capital contributions made by a person, other than the State, a local government, or a public institution, that wishes to invest in the fund of funds for venture investment in connection with the AI industry; Other incidental income.\n(5)\tMatters necessary for making capital contributions to the fund of funds for venture investment under paragraph (3) shall be prescribed by Presidential Decree. \u0026lt;Added on Jan. 20, 2026\u0026gt;\n[Title Amended on Jan. 20, 2026]\nArticle 19 (Promotion of AI convergence)\n(1)\tThe Government shall establish and implement necessary policy measures to facilitate convergence between the AI industry and other industries and to promote the utilization of AI across all sectors.\n(2)\tThe Government may, if necessary, prioritize and promote research and development programs on AI convergence products and services in national research and development programs under the National Research and Development Innovation Act to support the development of AI convergence products and services.\n(3)\tThe Government shall actively support the smooth implementation of temporary permission under Article 37 of the Special Act on Information and Communications Promotion and Convergence Activation and regulatory exceptions for demonstration under Article 38-2 of that Act for AI convergence products and services developed under paragraph (2).\nArticle 20 (System improvement)\n(1)\tThe Government shall endeavor to improve relevant systems, including the revision of statutes and regulations, to promote the development of the AI industry and the creation of a foundation for trust.\n(2)\tThe Government may provide administrative and financial support necessary for research on related laws and systems and for gathering opinions from various sectors of society in order to facilitate the improvement of systems under paragraph (1).\nArticle 21 (Securing AI professionals)\n(1)\tThe Minister of Science and ICT shall implement the following programs to develop and support professionals in AI and AI technology in accordance with the policy measures under Article 23(1) of the Framework Act on Intelligent Informatization for the development of AI technology and the advancement of the AI industry. \u0026lt;Amended on Jan. 20, 2026\u0026gt; Development and implementation of education and training programs to enhance the job competencies and career development of professionals; Promotion of employment, including by supporting the employment of professionals and facilitating the influx of new talent; Promotion of diversified career paths, including the expansion of opportunities for professionals to enter public service; Support for domestic and international training programs for professionals and promotion of international exchange; Improvement of the welfare of professionals, including the improvement of working conditions and enhancement of benefits; Other programs for the development and support of professionals in AI and AI technology.\n(2)\tThe Government may implement the following policy measures to secure overseas professionals in AI and AI technology: Investigation and analysis on professionals at overseas universities, research institutes, enterprises related to AI and AI technology; Establishment of an international network to attract overseas professionals; Support for overseas professionals seeking employment in the Republic of Korea; Support for overseas expansion of domestic AI research institutes and attraction of overseas AI research institutes to the Republic of Korea; Support for attracting international organizations and international events related to AI and AI technology to the Republic of Korea; Other matters necessary to secure overseas professionals.\nArticle 22 (Support for international cooperation and overseas expansion)\n(1)\tThe Government shall identify international trends related to AI and promote international cooperation.\n(2)\tThe Government may provide the following support to individuals, enterprises, or organizations engaged in the AI industry in order to strengthen the competitiveness of the AI industry and promote expansion into overseas markets: International exchange of information, technology, and personnel related to the AI industry; Collection, analysis, and provision of information on overseas expansion related to the AI industry; Joint research and development and international standardization of AI technology, AI products, or AI services between countries; Attraction of foreign capital investment related to the AI industry; Public awareness activities and overseas marketing, including participation in international professional conferences and exhibitions on AI and related matters; Establishment of sales systems, distribution systems, and cooperative systems necessary for the export of AI products or AI services; Identification of international trends in AI ethics, and international cooperation; Other matters necessary to strengthen the competitiveness of the AI industry and promote entry into overseas markets.\n(3)\tIn order to efficiently perform the support under each subparagraph of paragraph (2), the Government may entrust the support to, or have it carried out by, public institutions or other organizations, and may subsidize the costs necessary for the purpose.\nArticle 22-2 (Establishment and support of AI research institutes)\n(1)\tEntities prescribed by the Presidential Decree, such as universities or enterprises, may establish and operate research institutes for the development and utilization of AI (each hereinafter referred to as \u0026ldquo;AI research institute\u0026rdquo;), independently or jointly.\n(2)\tWhere an entity prescribed by the Presidential Decree, such as a university or an enterprise, intends to establish an AI research institute under paragraph (1), it shall obtain permission from the Minister of Science and ICT after meeting the following requirements: It shall have at least 3 promoters; It shall have the capability, including personnel and facilities, to conduct projects under paragraph (5); It shall meet other requirements prescribed by Presidential Decree necessary for the establishment and operation of the AI research institute.\n(3)\tAn AI research institute shall have a director. The director of the AI research institute shall represent the institute and exercise overall control over its affairs.\n(4)\tThe articles of incorporation of an AI research institute shall include the following matters: Purposes; Name; Location of the principal office; Regulations on assets; Regulations on the qualifications and appointment and dismissal of the director of the Institute; Regulations on the responsibilities and authorities of the director of the Institute.\n(5)\tAn AI research institute shall perform the following projects by industry and by function: AI technology research and development; Research and development on the convergence of AI technology with other technologies and interdisciplinary fields; Management, transfer, utilization, and commercialization of research and development outcomes in AI technology; Training of professionals engaged in AI technology research and development; International exchange and cooperation related to AI technology research and development; Other matters necessary for AI technology research and development.\n(6)\tThe Government and local governments may provide financial support within the budget for the expenses necessary for the operation and project implementation of AI research institutes.\n(7)\tAI research institutes may receive subsidies, donations, or other contributions from persons other than the Government or local governments or may engage in revenue-generating activities as stipulated in their articles of incorporation, in order to generate funds necessary for their operation.\n(8)\tThe director of an AI research institute may, where necessary for the research and development of AI technology and related activities, consult with entities prescribed by Presidential Decree, such as universities and enterprises, under paragraph (1), arrange for executive officers or employees to be seconded to, or to serve concurrently at, the AI research institute to conduct research or related activities, and may provide necessary support to the entities to which the executive officers or employees belong. In such cases, the director of the institute may request support for consultation from the Minister of Science and ICT if necessary.\n(9)\tExcept as provided in this Act, the provisions of the Civil Act governing incorporated foundations shall apply mutatis mutandis to AI research institutes.\n(10)\tThe Minister of Science and ICT may issue a corrective order or revoke the permission for the establishment of an AI research institute if it falls under any of the following cases; provided, if the institute falls under subparagraph 1 or 2, the permission shall be revoked: Where the institute has obtained permission for its establishment by fraud or other improper means; Where the institute becomes impossible to achieve its purposes; Where the institute fails to meet the requirements for permission under paragraph (2); Where the institute conducts any business outside the scope of its intended business; Where the Institute violates any statute or regulation, articles of incorporation, or order issued under this Act; Where the institute commits an act harmful to the public interest; Where the institute fails to commence its intended business within 6 months from the date of permission for its establishment without good cause, or it has no business performance for 1 year or more.\n(11)\tThe Minister of Science and ICT shall hold a hearing if the Minister intends to revoke the permission for the establishment of an AI research institute under paragraph (10).\n(12)\tOther matters necessary for the procedures for establishment of AI research institutes, and the operation and support thereof shall be prescribed by Presidential Decree.\n[This Article Added on Jan. 20, 2026]\nArticle 22-3 (Establishment and operation of research institutions for securing AI technology)\nThe Minister of Science and ICT may establish and operate institutions that conduct research on the development and utilization of AI, as prescribed by Presidential Decree, where necessary to secure innovative AI technology.\n[This Article Added on Jan. 20, 2026]\nArticle 23 (Designation of AI clusters)\n(1)\tThe State and local governments may implement the functional, physical, and regional clustering of enterprises, institutions, or organizations engaged in the research and development of AI and AI technology in order to foster the AI industry and strengthen competitiveness in AI development and utilization.\n(2)\tThe State and local governments may, if necessary for the clustering under paragraph (1), designate an AI cluster (hereinafter referred to as the \u0026ldquo;AI cluster\u0026rdquo;) and provide administrative, financial, and technical support as prescribed by Presidential Decree.\n(3)\tThe Minister of Science and ICT may revoke the designation of an AI cluster in any of the following cases; provided, in the case of subparagraph 1, the designation shall be revoked: Where the designation is obtained by fraud or other improper means; Where the head of the State or head of the local government that designated the AI cluster determines that it is difficult for the AI cluster to achieve the purpose of its designation.\n(4)\tThe Government may establish or designate a dedicated institution to comprehensively support related tasks in order to effectively anchor the clustering implemented under paragraph (1) within a region.\n(5)\tThe Government may contribute or subsidize all or part of the expenses necessary for the operation and project execution of the dedicated institution under paragraph (4).\n(6)\tOther matters necessary for the designation and revocation of designation of an AI cluster and the establishment or designation of a dedicated institution under paragraph (4) shall be prescribed by Presidential Decree.\nArticle 24 (Establishment of AI demonstration infrastructure)\n(1)\tThe State and local governments may establish and operate facilities, equipment, installations, etc. necessary for testing and evaluation (hereinafter referred to as \u0026ldquo;demonstration infrastructure\u0026rdquo;) to support demonstration, performance testing, and verification and certification under Article 30 of technologies developed by or transferred to AI business operators (hereinafter referred to as \u0026ldquo;demonstration testing and related activities\u0026rdquo;).\n(2)\tThe State and local governments may make available to AI business operators any demonstration infrastructure held by institutions designated by Presidential Decree in order to promote demonstration testing and related activities.\n(3)\tOther matters necessary for the establishment, operation, availability, etc. of demonstration infrastructure shall be prescribed by Presidential Decree.\nArticle 25 (Implementation of policy measures related to AI data centers)\n(1)\tThe Government shall implement necessary policy measures to encourage the establishment and operation of data centers used for the development and utilization of AI (hereinafter referred to as \u0026ldquo;AI data centers\u0026rdquo;).\n(2)\tThe Government may perform the following tasks to implement the policy measures under paragraph (1). Administrative and financial support necessary for the establishment and operation of AI data centers Support for the use of AI data centers by small and medium enterprises, research institutes, etc.; Support for balanced regional development of AI-related infrastructure facilities, including AI data centers.\nArticle 26 (Establishment of Korean AI promotion association)\n(1)\tPersons engaged in research and practice in AI and related matters may establish or be designated as a Korean AI promotion association (hereinafter referred to as \u0026ldquo;Association\u0026rdquo;) with the authorization of the Minister of Science and ICT, as prescribed by Presidential Decree, to promote the development and use of AI, to advance the AI industry and AI technology, and to provide education and publicity on AI and related matters.\n(2)\tThe Association shall be a corporation.\n(3)\tThe Association shall perform the following duties: Promotion and dissemination of the use of AI technology, AI products, or AI services; Survey on the current state of AI and related matters and on relevant statistics; Establishment and operation of shared facilities for AI business operators, and provision of education for the development of professionals; Support for the overseas expansion of AI business operators and AI-related professionals; Education and publicity for the development and utilization of safe and trustworthy AI; Projects entrusted to the Association under this Act or other statutes; Other projects necessary for achieving the purposes of the establishment of the Association, as prescribed by its articles of incorporation.\n(4)\tThe State and the local government may support funds necessary for the Association\u0026rsquo;s implementation of its projects or subsidize expenses necessary for its operation within the budget where necessary for the development of the AI industry and the creation of a foundation for trust.\n(5)\tThe qualifications for members of the Association, its executive officers, its duties, etc. shall be prescribed by the articles of incorporation; and other matters to be included in the articles of incorporation shall be prescribed by Presidential Decree.\n(6)\tWhere the Minister of Science and ICT grants authorization under paragraph (1), the Minister shall publicly announce the fact.\n(7)\tExcept as provided in this Act, the provisions of the Civil Act governing incorporated associations shall apply mutatis mutandis to the Association. Chapter IV: Ensuring Ai Ethics And Trustworthiness Article 27 (AI Ethics Principles)\n(1)\tThe Government may establish and promulgate AI ethics principles (hereinafter referred to as the \u0026ldquo;Ethics Principles\u0026rdquo;) that include the following matters, as prescribed by Presidential Decree, to promote the dissemination of AI ethics:\nMatters related to AI safety and trustworthiness to ensure that human life, physical health, or mental well-being are not harmed during the process of developing and utilizing AI; Matters related to accessibility that allow all people to freely and conveniently use products, services, etc. incorporating AI technology; Matters related to the development and utilization of AI that contribute to human well-being and prosperity.\n(2)\tThe Minister of Science and ICT shall establish action plans to ensure that the Ethics Principles can be realized by all persons involved in the development and utilization of AI after gathering opinions from various sectors of society and shall disclose, publicize, and educate them.\n(3)\tWhere the head of a central administrative agency or the head of a local government establishes or revises AI ethics standards (referring to statutes or regulations, standards, guidelines, or other instruments related to AI ethics, regardless of their name or form), the Minister of Science and ICT may make recommendations or express opinions on the connectivity and consistency with the Ethics Principles and the action plans under paragraph (2).\nArticle 28 (Establishment of private-sector self-regulatory AI ethics committees)\n(1)\tThe following institutions or organizations may establish a private-sector self-regulatory AI ethics committee (hereinafter referred to as \u0026ldquo;private-sector self-regulatory committee\u0026rdquo;) in order to comply with the Ethics Principles: Educational institutions and research institutes to which persons who conduct AI technology research and development belong; AI business operators; Other AI technology-related institutions prescribed by Presidential Decree.\n(2)\tPrivate-sector self-regulatory committees shall independently perform the following duties: Checking compliance with the Ethics Principles in AI technology research, development, and utilization; Investigation and research on safety, human rights violations, etc. in AI technology research, development, and utilization; Investigation and supervision of the procedures and results of AI technology research, development, and utilization; Provision of education on the Ethics Principles to researchers and employees of the relevant institution or organization; Preparation of sector-specific AI ethics guidelines suitable for AI technology research, development, and utilization; Other duties necessary for the implementation of the Ethics Principles.\n(3)\tThe matters necessary for the composition and operation of the private-sector self-regulatory committee shall be determined autonomously of the relevant institution or organization; provided, the committee shall not be composed of members of a single gender, and shall include persons who have experience and knowledge to evaluate social and ethical validity and persons who are not employed by the relevant institution or organization, respectively.\n(4)\tThe Minister of Science and ICT may prepare and disseminate standard guidelines, etc. for the fair and neutral composition and operation of private-sector self-regulatory committees.\nArticle 29 (Preparation of policy measures to create foundation for trust in AI)\nThe Government shall prepare the following policy measures to minimize the potential risks that AI poses to the daily lives of the people and to create a foundation of trust for the safe use of AI: Creation of a safe and trustworthy environment for the use of AI; Prospects and forecasts regarding the impact of the use of AI on the daily lives of the people and the reorganization of related statutes and regulations and systems; Support for the development and dissemination of safety technologies and certification technologies to ensure the safety and trustworthiness of AI; Provision of education and publicity for the realization of a safe and trustworthy AI society and the practice of AI ethics; Support for AI business operators in the autonomous establishment and implementation of rules related to safety and trustworthiness; Support and dissemination of private activities, such as autonomous cooperation to enhance the safety and trustworthiness of AI and the establishment of ethical guidelines by AI-related organizations composed of AI business operators, users, etc. (hereinafter referred to as \u0026ldquo;organizations, etc.\u0026rdquo;); Other matters prescribed by Presidential Decree to ensure the safety and trustworthiness of AI.\nArticle 30 (Support for verification and certification of AI safety and trustworthiness)\n(1)\tThe Minister of Science and ICT may implement the following projects to support verification and certification activities (hereinafter referred to as \u0026ldquo;verification and certification\u0026rdquo;) voluntarily performed by organizations, etc. to ensure the safety and trustworthiness of AI: Dissemination of guidelines on AI development; Support for research on verification and certification; Support for the construction and operation of equipment and systems used for verification and certification; Support for the training of professionals needed for verification and certification; Other matters prescribed by Presidential Decree to support verification and certification.\n(2)\tThe Minister of Science and ICT may, as prescribed by Presidential Decree, provide related information or administrative and financial support to small and medium enterprises, etc. that intends to obtain verification and certification.\n(3)\tAn AI business operator shall endeavor to obtain verification and certification in advance where the operator provides high-impact AI.\n(4)\tWhere the State agency or other public entity intends to use high-impact AI, it shall give preferential consideration to products or services based on AI that has obtained verification and certification.\nArticle 31 (Obligation to ensure AI transparency)\n(1)\tAn AI business operator that intends to provide a product or service using high-impact AI or generative AI shall notify the user in advance that the product or service is operated based on that AI.\n(2)\tAn AI business operator that provides generative AI or a product or service using it shall indicate that the output was generated by generative AI.\n(3)\tWhere an AI business operator provides outputs, such as synthetic sound, images, or video, that are difficult to distinguish from the real ones, by using an AI system, the operator shall notify or indicate in a manner that users can readily recognize the fact that such outputs have been generated by the AI system. In this case, if the outputs correspond to an artistic or creative work or constitute a part thereof, the fact may be notified or indicated in a manner that does not hinder the exhibition or enjoyment.\n(4)\tOther matters necessary for the prior notification under paragraph (1), the indication under paragraph (2), the method of notification or indication and its exceptions under paragraph (3) shall be prescribed by Presidential Decree.\nArticle 32 (Obligation to ensure AI safety)\n(1)\tAn AI business operator shall implement the following to ensure the safety of an AI system in which the cumulative amount of compute used for training meets or exceeds the threshold prescribed by Presidential Decree: Identification, assessment, and mitigation of risks throughout the entire AI lifecycle; Establishment of a risk management system capable of monitoring and responding to AI safety incidents.\n(2)\tAn AI business operator shall submit the results of the implementation of the matters in the subparagraphs of paragraph (1) to the Minister of Science and ICT.\n(3)\tThe Minister of Science and ICT shall determine and publicly notify the specific implementation methods for the matters in the subparagraphs of paragraph (1) and the matters necessary for submitting the results under paragraph (2).\nArticle 33 (Confirmation of high-impact AI)\n(1)\tWhere an AI business operator provides AI or products and services using the AI, the operator shall review in advance whether the AI falls under the high-impact AI, and if necessary, may request the Minister of Science and ICT to confirm whether it falls under the high-impact AI.\n(2)\tThe Minister of Science and ICT shall, upon receipt of the request under paragraph (1), confirm whether the AI falls under the high-impact AI, and may establish a specialized committee to obtain related advice if necessary.\n(3)\tThe Minister of Science and ICT may establish and disseminate guidelines on criteria, examples, etc. of high-impact AI.\n(4)\tOther matters necessary for the confirmation procedures under paragraph (1) shall be prescribed by Presidential Decree.\nArticle 34 (Responsibilities of business operators regarding high-impact AI)\n(1)\tWhere an AI business operator provides high-impact AI or a product or service using it, the operator shall implement measures, as prescribed by Presidential Decree, that include the following to ensure the safety and trustworthiness of high-impact AI: Establishing and operating risk management measures; Establishing and implementing explanation measures regarding, to the extent technically feasible, the final results derived by the AI, the main criteria utilized to derive the final results of the AI, and the overview of training data used in the development and utilization of the AI; Establishing and operating user protection measures; Ensuring human management and oversight of high-impact AI; Preparing and retaining documents that can verify the contents of the measures taken to ensure the safety and trustworthiness; Other matters deliberated and resolved by the Council to ensure the safety and trustworthiness of high-impact AI.\n(2)\tThe Minister of Science and ICT may determine and publicly notify the details of the measures in the subparagraphs of paragraph (1) and may recommend that AI business operators comply with them.\n(3)\tWhere an AI business operator has implemented measures equivalent to those in the subparagraphs of paragraph (1) as prescribed by Presidential Decree, they shall be deemed to have implemented the measures under paragraph (1).\nArticle 35 (Impact assessment of high-impact AI)\n(1)\tWhere an AI business operator provides products or services using high-impact AI, the operator shall endeavor to assess the impact on the fundamental rights of people in advance (hereinafter referred to as \u0026ldquo;impact assessment\u0026rdquo;). In such cases, the impact assessment shall be conducted in a manner that reflects the characteristics of AI-vulnerable groups, considering the nature of the products or services using high-impact AI. \u0026lt;Amended on Jan. 20, 2026\u0026gt;\n(2)\tWhere the State agency or other public entity intends to use products or services using high-impact AI, it shall give preferential consideration to products or services that have undergone impact assessments.\n(3)\tOther matters necessary for the specific content and methods of impact assessments shall be prescribed by Presidential Decree.\nArticle 36 (Designation of domestic representative)\n(1)\tAn AI business operator that has no domicile or place of business in the country and meets the criteria for the number of users, sales revenue, etc. as prescribed by Presidential Decree shall designate a person who acts on behalf of the operator in the following matters (hereinafter referred to as a \u0026ldquo;domestic representative\u0026rdquo;) in writing and shall report it to the Minister of Science and ICT: Submission of implementation results under Article 32(2); Request for confirmation of whether it falls under the high-impact AI under Article 33 (1); Support necessary for implementing the measures to ensure safety and trustworthiness under the subparagraphs of Article 34(1) (including the inspection of the up-to-dateness and accuracy of the documents under subparagraph 5 of that paragraph).\n(2)\tThe domestic representative shall be a person that has a domicile or place of business within the Republic of Korea.\n(3)\tWhere a domestic representative has violated this Act in connection with the subparagraphs of paragraph (1), the AI business operator that designated the domestic representative shall be deemed to have committed the violation. Chapter V: Supplementary Provisions Article 37 (Expansion of financial resources for promotion of the AI industry)\n(1)\tThe State shall prepare a plan to continuously and stably expand the necessary financial resources to effectively promote the master plan and the policy measures, etc. under this Act.\n(2)\tThe Minister of Science and ICT may, if necessary for the promotion of the AI industry, recommend that a public institution provide necessary support for programs, etc. related to the promotion of the AI industry.\n(3)\tThe State and local governments shall take necessary measures to enable the private sector, including enterprises, to actively invest in programs related to the promotion of the AI industry.\n(4)\tThe State and local governments shall endeavor to efficiently execute investment resources, comprehensively considering the development stage, etc. of the AI industry.\nArticle 38 (Compilation of fact-finding surveys, statistics, and indicators)\n(1)\tThe Minister of Science and ICT shall, in consultation with the Minister of Data and Statistics, prepare, manage, and publish fact-finding surveys, statistics, and indicators regarding domestic and international AI and related matters, in conjunction with the statistics under Article 26-2 of the Framework Act on Science and Technology in order to plan, establish, and implement master plans and other policy measures and programs regarding AI and related matters. \u0026lt;Amended on Oct. 1, 2025\u0026gt;\n(2)\tThe Minister of Science and ICT may request cooperation, such as data submission, from the heads of relevant central administrative agencies, heads of local governments, and heads of public institutions for the compilation of the statistics and indicators under paragraph (1). In this case, the head of the agency, local government, or public institution requested to cooperate shall comply therewith unless there is a compelling reasons not to do so.\n(3)\tOther matters necessary for compiling, managing, and publishing fact-finding surveys, statistics, and indicators under paragraph (1) shall be prescribed by Presidential Decree.\nArticle 39 (Delegation of authority and entrustment of tasks)\n(1)\tThe Minister of Science and ICT or the head of a relevant central administrative agency may delegate part of the authority under this Act to the head of a subordinate agency or the Special Metropolitan City Mayor, a Metropolitan City Mayor, a Special Self-Governing City Mayor, a Do Governor, or a Special Self-Governing Province Governor (hereinafter referred to as the \u0026ldquo;Mayor/Do Governor\u0026rdquo; in this Article) as prescribed by Presidential Decree. In this case, the Mayor/Do Governor may redelegate a part of the delegated authority to the head of a Si (including the head of an administrative Si under Article 11(2) of the Special Act on the Establishment of Jeju Special Self-Governing Province and the Development of Free International Free City)/Gun/Gu (the head of a Gu refers to the head of an autonomous Gu).\n(2)\tThe Government may entrust the following tasks to a relevant institution or organization as prescribed by Presidential Decree:\nSupport for programs related to the development and utilization of AI technology under Article 13; Selection and support of projects eligible for support regarding the production, collection, management, distribution, and utilization of training data and the implementation of training data development projects under Article 15(2) and (3); Establishment, operation, and management of the integrated provision system; Matters deemed necessary by the Minister of Science and ICT for the promotion of business start-up under Article 18; Support related to verification and certification under Article 30(2); Compilation of fact-finding surveys, statistics, and indicators under Article 38; Other tasks prescribed by Presidential Decree for the fostering of the AI industry and the dissemination of AI ethics.\nArticle 40 (Fact-finding investigations)\n(1)\tThe Minister of Science and ICT may require an AI business operator to submit relevant data or have public officials under his or her control conduct necessary investigations in any of the following cases: Where any violation of Article 31(2) or (3), Article 32(1) or (2), or Article 34(1) is discovered or suspected; Where a report is received or a complaint is filed regarding a violation of Article 31(2) or (3), Article 32(1) or (2), or Article 34(1).\n(2)\tWhere the Minister of Science and ICT deems it necessary for the investigation under paragraph (1), he or she may authorize public officials of the Ministry to enter the office or place of business of an AI business operator to investigate ledgers, documents, and other data or things. In this case, except for matters prescribed in this Act regarding the content, method, and procedures of the investigation, the provisions of the Framework Act on Administrative Investigations shall apply.\n(3)\tWhere the Minister of Science and ICT recognizes, based on the results of investigations under paragraphs (1) and (2), that an AI business operator has violated this Act, the Minister may order the AI business operator to take necessary measures to cease or correct the violation.\nArticle 41 (Legal fiction as public officials for purposes of applying penalty provisions)\nA member of the Council who is not a public official shall be deemed a public official for purposes of applying penalty provisions under Articles 129 through 132 of the Criminal Act.\n(2)\tThe executive officers and employees of an institution or organization engaged in the tasks entrusted under Article 39(2) shall be deemed public officials for purposes of applying penalty provisions under Articles 127 and 129 through 132 of the Criminal Act. Chapter VI: Penalty Provisions Article 42 (Penalty provisions)\nA person who, in violation of Article 7(9), discloses any secret that he or she has learned in the course of his or her duties to another person or uses such secret for purposes other than those related to his or her duties shall be punished by imprisonment with labor for not more than 3 years or by a fine not exceeding 30 million won.\nArticle 43 (Administrative fines)\n(1)\tAny of the following persons shall be subject to an administrative fine not exceeding 30 million won:\nA person who fails to provide the notification, in violation of Article 31(1); A person who fails to designate a domestic representative, in violation of Article 36(1); A person who fails to comply with an order to cease or correct a violation issued under Article 40(3);\n(2)\tAdministrative fines under paragraph (1) shall be imposed and collected by the Minister of Science and ICT as prescribed by Presidential Decree.\nADDENDA \u0026lt;Act No. 20676, Jan. 21, 2025\u0026gt;\nArticle 1 (Enforcement date)\nThis Act shall enter into force 1 year after the date of its promulgation; provided, the portion regarding digital medical devices under subparagraph 4d of Article 2 under shall enter into force on January 24, 2026.\nArticle 2 (Preparatory actions for enforcing this Act)\nThe commissioning of members of the Council and the establishment of expert standing committees, special committees, advisory committees, and a secretariat necessary for enforcing this Act may be conducted before this Act enters into force.\nArticle 3 (Special cases concerning dedicated institutions)\nAn institution that, at the time this Act enters into force, is operating with budgetary support from the Government to effectively anchor the clustering in relevant regions in accordance with Article 23(1), and that meets the requirements prescribed by Presidential Decree, including organization and personnel, shall be deemed designated as a dedicated institution in accordance with this Act, notwithstanding Article 23(4).\nADDENDA \u0026lt;Act No. 21065, Oct. 1, 2025\u0026gt;\nArticle 1 (Enforcement date)\nThis Act shall enter into force on the date of its promulgation; provided, among the statutes to be amended under Article 7 of the Addenda, any amendment made by this Act to the statutes that were promulgated before this Act enters into force but whose enforcement dates have yet to arrive shall enter into force \u0026hellip; \u0026hellip; on the enforcement date of the respective statute: and 2. Omitted.\nArticles 2 through 6 Omitted.\nArticle 7 Omitted.\nArticle 8 Omitted.\nADDENDUM \u0026lt;Act No. 21311, Jan. 20, 2026\u0026gt;\nThis Act shall enter into force on January 22, 2026; provided, the amended provisions of Article 3(5), Article 6(2)7 and 8, Article 16(3) through (5) (limited to the portion regarding the amended provisions of paragraph (2)2-2), Article 17-2, Article 18, Article 22-3, and the latter part of Article 35(1) shall enter into force 6 months after the date of their promulgation. ","permalink":"https://ai.intlaws.com/en/compliance/other/korea-ai-framework-act/","summary":"Official Korean text of the Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (Act No. 20676, promulgated 21 January 2025; in force 22 January 2026; amended by Act No. 21311 of 20 January 2026), six chapters and two sections, 43 articles plus three sub-numbered articles, with three sets of addenda. The English text on this page is the official translation by the Korea Legislation Research Institute (KLRI). The Korean text is authoritative.","title":"Korea's Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (AI Framework Act)"},{"content":" Version and sources (verifiable)\nItem Content Promulgated 14 March 2025 by the Cyberspace Administration of China, the Ministry of Industry and Information Technology, the Ministry of Public Security and the National Radio and Television Administration Effective 1 September 2025 Structure 14 articles Currently effective Yes (as of 2026-09-22) Chinese original https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm English version No official English translation published. This English text is a translation by our editorial team, cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 14 articles, correspondence with the Chinese text verified one-for-one, no gaps Article 1 These Measures are formulated in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Provisions on the Administration of Algorithmic Recommendations in Internet Information Services, the Provisions on the Administration of Deep Synthesis of Internet Information Services, the Interim Measures for the Administration of Generative Artificial Intelligence Services and other laws, administrative regulations and departmental rules, for the purposes of promoting the sound development of artificial intelligence, regulating the labelling of AI-generated synthetic content, protecting the lawful rights and interests of citizens, legal persons and other organisations, and safeguarding the public interest.\nArticle 2 These Measures apply to labelling activities for AI-generated synthetic content carried out by providers of internet information services (hereinafter \u0026ldquo;service providers\u0026rdquo;) that fall within the circumstances provided for in the Provisions on the Administration of Algorithmic Recommendations in Internet Information Services, the Provisions on the Administration of Deep Synthesis of Internet Information Services, and the Interim Measures for the Administration of Generative Artificial Intelligence Services.\nArticle 3 AI-generated synthetic content means information such as text, images, audio, video and virtual scenes generated or synthesised by means of artificial intelligence technology.\nLabelling of AI-generated synthetic content includes explicit labels and implicit labels.\nAn explicit label means a label added to the generated synthetic content or to the interface of an interactive scenario, presented in the form of text, sound, graphics or otherwise, and clearly perceivable by users.\nAn implicit label means a label added to the file data of the generated synthetic content by technical measures, and not readily perceivable by users.\nArticle 4 Where the generative synthetic services provided by a service provider fall within the circumstances provided for in Article 17, paragraph 1 of the Provisions on the Administration of Deep Synthesis of Internet Information Services, the service provider shall add explicit labels to the generated synthetic content in accordance with the following requirements:\n(1) add a text prompt, a generic symbol prompt or a similar label at the beginning, the end or an appropriate position in the middle of the text, or add a conspicuous prompt label in the interactive scenario interface or around the text;\n(2) add a voice prompt, an audio rhythm prompt or a similar label at the beginning, the end or an appropriate position in the middle of the audio, or add a conspicuous prompt label in the interactive scenario interface;\n(3) add a conspicuous prompt label at an appropriate position on the image;\n(4) add a conspicuous prompt label at an appropriate position on the opening frame of the video and around the video playback area, and may add a conspicuous prompt label at appropriate positions at the end and in the middle of the video;\n(5) when presenting a virtual scene, add a conspicuous prompt label at an appropriate position on the opening frame, and may add a conspicuous prompt label at an appropriate position during the continued provision of the virtual scene service;\n(6) in other generative synthetic service scenarios, add a conspicuous prompt label according to the characteristics of the application concerned.\nWhere a service provider provides functions such as downloading, copying and exporting generated synthetic content, it shall ensure that the file contains explicit labels meeting the requirements.\nArticle 5 A service provider shall, in accordance with Article 16 of the Provisions on the Administration of Deep Synthesis of Internet Information Services, add implicit labels in the file metadata of the generated synthetic content; implicit labels shall include the attribute information of the generated synthetic content, the name or code of the service provider, the content number and other information on the elements of production.\nService providers are encouraged to add implicit labels in the form of digital watermarks and the like to generated synthetic content.\nFile metadata means descriptive information embedded in the file header in a specific encoding format, used to record information such as the source, attributes and purpose of the file.\nArticle 6 Service providers that provide online information content dissemination services shall take the following measures to regulate the dissemination of generated synthetic content:\n(1) verify whether the file metadata contains an implicit label; where the file metadata clearly indicates that the content is generated synthetic content, add, in an appropriate manner, a conspicuous prompt label around the published content to clearly remind the public that the content is generated synthetic content;\n(2) where no implicit label is verified in the file metadata but the user declares the content to be generated synthetic content, add, in an appropriate manner, a conspicuous prompt label around the published content to remind the public that the content may be generated synthetic content;\n(3) where no implicit label is verified in the file metadata and the user has not declared the content to be generated synthetic content, but the service provider providing online information content dissemination services detects an explicit label or other traces of generation or synthesis, identify the content as suspected generated synthetic content and add, in an appropriate manner, a conspicuous prompt label around the published content to remind the public that the content is suspected to be generated synthetic content;\n(4) provide the necessary labelling functions and remind users to voluntarily declare whether the content they publish contains generated synthetic content.\nWhere any of the circumstances in items (1) to (3) of the preceding paragraph applies, the attribute information of the generated synthetic content, the name or code of the dissemination platform, the content number and other information on dissemination elements shall be added to the file metadata.\nArticle 7 When reviewing an internet application for listing or going online, an internet application distribution platform shall require the provider of the internet application service to state whether it provides AI-generated synthetic services. Where the provider of the internet application service provides AI-generated synthetic services, the internet application distribution platform shall verify the materials relating to the labelling of its generated synthetic content.\nArticle 8 A service provider shall clearly explain in its user service agreement the normative content of the labelling of generated synthetic content, such as the method and style of labelling, and shall prompt users to carefully read and understand the relevant labelling management requirements.\nArticle 9 Where a user applies to a service provider for generated synthetic content that does not carry explicit labels, the service provider may, after making clear the user\u0026rsquo;s labelling obligations and responsibilities for use through the user agreement, provide generated synthetic content without explicit labels, and shall retain the relevant logs, including information on the recipient of the provision, for not less than six months in accordance with law.\nArticle 10 Where a user publishes generated synthetic content using an online information content dissemination service, the user shall voluntarily declare it and use the labelling functions provided by the service provider to label it.\nNo organisation or individual may maliciously delete, tamper with, forge or conceal the labels of generated synthetic content provided for in these Measures, may provide tools or services for others to carry out the aforesaid malicious acts, or may harm the lawful rights and interests of others through improper labelling means.\nArticle 11 Where a service provider carries out labelling activities, it shall also comply with the requirements of relevant laws, administrative regulations, departmental rules and mandatory national standards.\nArticle 12 When completing formalities such as algorithm filing and security assessment, a service provider shall, in accordance with these Measures, provide materials relating to the labelling of generated synthetic content, strengthen the sharing of labelling information, and provide support and assistance for the prevention and combating of relevant illegal and criminal activities.\nArticle 13 Where these Measures are violated, the relevant competent departments for cyberspace administration, telecommunications, public security and radio and television shall, in accordance with their duties, deal with the matter in accordance with the provisions of relevant laws, administrative regulations and departmental rules.\nArticle 14 These Measures shall come into force on 1 September 2025.\n","permalink":"https://ai.intlaws.com/en/compliance/china/ai-generated-content-labelling-measures/","summary":"Full text of the Measures for the Labelling of AI-Generated Synthetic Content (promulgated 14 March 2025, effective 1 September 2025), 14 articles: definitions of explicit and implicit labels, labelling duties across six content scenarios, verification duties of dissemination platforms, and the prohibition on providing tools that remove labels. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).","title":"Measures for the Labelling of AI-Generated Synthetic Content"},{"content":" Version and sources (verifiable)\nItem Content Promulgated 7 July 2022 by the Cyberspace Administration of China (Order No. 11); deliberated and adopted at the 10th executive meeting of the CAC in 2022 on 19 May 2022; signed by Zhuang Rongwen, Director of the CAC Effective 1 September 2022 Structure 20 articles Currently effective Yes, as amended in operation by the Provisions on Promoting and Regulating Cross-Border Data Flows (2024) — see Article 13 of those Provisions, which prevails in case of inconsistency Chinese original https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm English version No official English translation published. This English text is a translation by our editorial team, cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 20 articles, correspondence with the Chinese text verified one-for-one, no gaps Article 1 These Measures are formulated in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and regulations, for the purposes of regulating data export activities, protecting the rights and interests of personal information, safeguarding national security and the public interest, and promoting the secure and free flow of data across borders.\nArticle 2 These Measures apply to the security assessment of data processors providing overseas important data and personal information collected and generated in the course of operations within the territory of the People\u0026rsquo;s Republic of China. Where laws and administrative regulations provide otherwise, those provisions shall prevail.\nArticle 3 The security assessment of data export adheres to combining prior assessment with continuous supervision, and combining self-assessment of risks with security assessment, so as to prevent data export security risks and ensure the lawful, orderly and free flow of data.\nArticle 4 Where a data processor provides data overseas and any of the following circumstances applies, it shall, through the cyberspace administration department of the province where it is located, report to the national cyberspace administration department for the security assessment of data export:\n(1) the data processor provides important data overseas;\n(2) a critical information infrastructure operator, or a data processor that processes the personal information of more than 1,000,000 individuals, provides personal information overseas;\n(3) a data processor that has cumulatively provided overseas the personal information of 100,000 individuals, or the sensitive personal information of 10,000 individuals, since 1 January of the previous year, provides personal information overseas;\n(4) other circumstances requiring a report for the security assessment of data export as provided by the national cyberspace administration department.\nArticle 5 Before reporting for the security assessment of data export, a data processor shall carry out a self-assessment of the risks of data export, focusing on the following matters:\n(1) the lawfulness, legitimacy and necessity of the purposes, scope and methods of the data export and of the overseas recipient\u0026rsquo;s processing of the data;\n(2) the scale, scope, categories and sensitivity of the exported data, and the risks that the data export may pose to national security, the public interest, and the lawful rights and interests of individuals or organisations;\n(3) the responsibilities and obligations undertaken by the overseas recipient and whether its management and technical measures and capabilities for performing those responsibilities and obligations can guarantee the security of the exported data;\n(4) the risks of the exported data being tampered with, destroyed, leaked, lost, transferred, or illegally obtained or illegally used during and after export, and whether the channels for safeguarding personal information rights and interests are unobstructed;\n(5) whether the contract relating to data export or other documents with legal effect (hereinafter collectively \u0026ldquo;legal documents\u0026rdquo;) to be concluded with the overseas recipient fully stipulate the responsibilities and obligations for data security protection;\n(6) other matters that may affect the security of the data export.\nArticle 6 The following materials shall be submitted when reporting for the security assessment of data export:\n(1) the application form;\n(2) the report on the self-assessment of the risks of data export;\n(3) the legal documents to be concluded between the data processor and the overseas recipient;\n(4) other materials required for the security assessment work.\nArticle 7 The provincial cyberspace administration department shall complete a completeness check within 5 working days from the date of receipt of the application materials. Where the application materials are complete, it shall submit them to the national cyberspace administration department; where the application materials are incomplete, it shall return them to the data processor and inform it, in a single notification, of the materials to be supplemented.\nThe national cyberspace administration department shall, within 7 working days from the date of receipt of the application materials, decide whether to accept the application and notify the data processor in writing.\nArticle 8 The security assessment of data export focuses on assessing the risks that data export activities may pose to national security, the public interest, and the lawful rights and interests of individuals or organisations, mainly including the following matters:\n(1) the lawfulness, legitimacy and necessity of the purposes, scope and methods of the data export;\n(2) the impact of the data security protection policies, laws and regulations and the cybersecurity environment of the country or region where the overseas recipient is located on the security of the exported data, and whether the overseas recipient\u0026rsquo;s level of data protection meets the requirements of the laws, administrative regulations and mandatory national standards of the People\u0026rsquo;s Republic of China;\n(3) the scale, scope, categories and sensitivity of the exported data, and the risks of the data being tampered with, destroyed, leaked, lost, transferred, or illegally obtained or illegally used during and after export;\n(4) whether data security and personal information rights and interests can be fully and effectively safeguarded;\n(5) whether the legal documents to be concluded between the data processor and the overseas recipient fully stipulate the responsibilities and obligations for data security protection;\n(6) compliance with Chinese laws, administrative regulations and departmental rules;\n(7) other matters that the national cyberspace administration department considers necessary to assess.\nArticle 9 A data processor shall clearly stipulate in the legal documents concluded with the overseas recipient the responsibilities and obligations for data security protection, including at least the following:\n(1) the purposes and methods of the data export and the scope of the data, and the purposes and methods of the overseas recipient\u0026rsquo;s processing of the data;\n(2) the place and period of storage of the data overseas, and the measures for handling the exported data upon expiry of the storage period, completion of the agreed purposes, or termination of the legal documents;\n(3) binding requirements on the overseas recipient for the onward transfer of the exported data to other organisations or individuals;\n(4) the security measures to be taken where the overseas recipient undergoes a substantive change in actual control or business scope, or where changes in the data security protection policies, laws and regulations and the cybersecurity environment of the country or region where it is located, or other force majeure circumstances, make it difficult to guarantee data security;\n(5) the remedial measures, liability for breach and methods of dispute resolution for breach of the data security protection obligations agreed in the legal documents;\n(6) the requirements for properly carrying out emergency response where the exported data is at risk of being tampered with, destroyed, leaked, lost, transferred, or illegally obtained or illegally used, and the ways and means of safeguarding individuals\u0026rsquo; ability to protect their personal information rights and interests.\nArticle 10 After accepting a report, the national cyberspace administration department shall organise the relevant departments of the State Council, provincial cyberspace administration departments and specialised agencies to conduct the security assessment according to the circumstances of the report.\nArticle 11 In the course of the security assessment, where it is found that the application materials submitted by the data processor do not meet the requirements, the national cyberspace administration department may require it to supplement or correct them. Where the data processor fails to supplement or correct them without justified reasons, the national cyberspace administration department may terminate the security assessment.\nThe data processor is responsible for the authenticity of the materials it submits; where it deliberately submits false materials, the assessment shall be treated as failed and corresponding legal liability shall be pursued in accordance with law.\nArticle 12 The national cyberspace administration department shall complete the security assessment of data export within 45 working days from the date of issuing the written notice of acceptance to the data processor; where the circumstances are complex or materials need to be supplemented or corrected, the period may be appropriately extended and the data processor shall be informed of the estimated extension.\nThe assessment result shall be notified to the data processor in writing.\nArticle 13 Where a data processor objects to the assessment result, it may, within 15 working days of receipt of the assessment result, apply to the national cyberspace administration department for a re-assessment; the re-assessment result is final.\nArticle 14 The result of a passed security assessment of data export is valid for 2 years, counted from the date on which the assessment result is issued. Where any of the following circumstances occurs within the validity period, the data processor shall re-report for assessment:\n(1) changes in the purposes, methods, scope and categories of the data provided overseas or in the purposes and methods of the overseas recipient\u0026rsquo;s processing of the data affect the security of the exported data, or the period of storage of personal information and important data overseas is extended;\n(2) changes in the data security protection policies, laws and regulations and the cybersecurity environment of the country or region where the overseas recipient is located, other force majeure circumstances, changes in the actual control of the data processor or the overseas recipient, or changes to the legal documents between the data processor and the overseas recipient, affect the security of the exported data;\n(3) other circumstances affecting the security of the exported data occur.\nWhere the validity period expires and the data processor needs to continue the data export activities, it shall re-report for assessment 60 working days before the expiry of the validity period.\nArticle 15 Relevant institutions and personnel participating in the security assessment work shall, in accordance with law, keep confidential the state secrets, personal privacy, personal information, trade secrets, confidential commercial information and other data learned in the performance of their duties, and shall not disclose them or illegally provide them to or illegally use them for others.\nArticle 16 Where any organisation or individual discovers that a data processor provides data overseas in violation of these Measures, it may report the matter to the cyberspace administration department at or above the provincial level.\nArticle 17 Where the national cyberspace administration department discovers that data export activities that have passed the assessment no longer meet the data export security management requirements in actual processing, it shall notify the data processor in writing to terminate the data export activities. Where the data processor needs to continue the data export activities, it shall rectify in accordance with the requirements and re-report for assessment after completion of the rectification.\nArticle 18 Where these Measures are violated, the matter shall be dealt with in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and regulations; where a crime is constituted, criminal liability shall be pursued in accordance with law.\nArticle 19 For the purposes of these Measures, \u0026ldquo;important data\u0026rdquo; means data that, once tampered with, destroyed, leaked, or illegally obtained or illegally used, may endanger national security, economic operation, social stability, public health and safety, and the like.\nArticle 20 These Measures shall come into force on 1 September 2022. Where data export activities already carried out before these Measures come into force do not comply with these Measures, rectification shall be completed within 6 months from the date these Measures come into force.\nRelationship between provisions (editorial note, not part of the legal text)\nArticle 19 of the Measures provides the identification standard for \u0026ldquo;important data\u0026rdquo;; Article 2 of the 2024 Provisions and Article 37 of the Regulations make the reporting obligation conditional on notification or public designation by the regulator. The two operate as definition and procedure and do not conflict: it is the regulator, not the processor, that designates important data.\n","permalink":"https://ai.intlaws.com/en/compliance/china/data-export-security-assessment-measures/","summary":"Full text of the Measures for the Security Assessment of Data Export (Cyberspace Administration of China Order No. 11, promulgated 7 July 2022, effective 1 September 2022), 20 articles: the triggers for filing, the self-assessment of risks, materials required, the assessment factors, mandatory clauses in legal documents, the 45-working-day time limit, and the two-year validity of assessment results. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).","title":"Measures for the Security Assessment of Data Export"},{"content":" Version and sources (verifiable)\nItem Content Adopted 30th Meeting of the Standing Committee of the 13th NPC, August 20, 2021 In force November 1, 2021 Currently effective Yes (no amendment as of 2026-09-22) Chinese original source Cyberspace Administration of China: https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm English translation source NPC official English site, \u0026ldquo;Laws (Translation for Reference Only)\u0026rdquo;: http://en.npc.gov.cn.cdurl.cn/2021-12/29/c_694559.htm (3 pages) Nature of translation Published on the official NPC English site and marked \u0026ldquo;Translation for Reference Only\u0026rdquo; Verification Retrieved 2026-09-22; 8 chapters / 74 articles; article numbers match the Chinese original one-for-one, with no gaps Chapter I General Provisions Article 1 This Law is enacted in accordance with the Constitution for the purposes of protecting the rights and interests on personal information, regulating personal information processing activities, and promoting reasonable use of personal information.\nArticle 2 The personal information of natural persons shall be protected by law. No organization or individual may infringe upon natural persons\u0026rsquo; rights and interests on their personal information.\nArticle 3 This Law shall apply to the processing of personal information of natural persons within the territory of the People\u0026rsquo;s Republic of China. This Law shall also apply to the processing outside the territory of the People\u0026rsquo;s Republic of China of the personal information of natural persons within the territory of the People\u0026rsquo;s Republic of China, under any of the following circumstances:\n(1) for the purpose of providing products or services for natural persons inside the People\u0026rsquo;s Republic of China;\n(2) analyzing or evaluating the behaviors of natural persons within the territory of the People\u0026rsquo;s Republic of China; and\n(3) any other circumstance as provided by any law or administrative regulation.\nArticle 4 \u0026ldquo;Personal information\u0026rdquo; refers to various information related to an identified or identifiable natural person recorded electronically or by other means, but does not include anonymized information. Personal information processing includes personal information collection, storage, use, processing, transmission, provision, disclosure and deletion, among others.\nArticle 5 Personal information shall be processed according to law when it is necessary, with justified reason, and in good faith, and the processing may not involve misguidance, fraud, coercion, and the like.\nArticle 6 Personal information processing shall be based on explicit and reasonable purposes and directly related to those purposes, and shall exert the minimum impacts on the rights and interests of individuals. The collection of personal information shall be limited to the minimum scope required by the purpose of processing, and personal information may not be collected excessively.\nArticle 7 The principles of openness and transparency shall be observed in the processing of personal information, the rules for processing personal information shall be disclosed, and the purposes, means, and scope of processing shall be explicitly indicated.\nArticle 8 The quality of personal information shall be guaranteed in personal information processing, to avoid adverse impacts on the rights and interests of individuals caused by inaccurate and incomplete personal information.\nArticle 9 Personal information processors shall be responsible for their personal information processing activities and take necessary measures to ensure the security of the personal information they process.\nArticle 10 No organization or individual shall illegally collect, use, process, or transmit the personal information of other persons, or illegally trade, provide or disclose the personal information of other persons, or engage in personal information processing activities that endanger national security or harm public interests.\nArticle 11 The state shall establish and improve the personal information protection system to prevent and punish infringements upon the rights and interests on personal information, strengthen publicity and education on personal information protection, and promote a favorable environment for the government, enterprises, relevant industry organizations, and the public to jointly participate in personal information protection.\nArticle 12 The state will actively engage in the development of international rules on personal information protection, promote the international exchanges and cooperation in personal information protection, and encourage the mutual recognition of personal information protection rules and standards, among others, with other countries, regions, and international organizations.\nChapter II Personal Information Processing Rules Section 1 General Rules Article 13 A personal information processor can process personal information of an individual only if one of the following circumstances exists: (1) the individual\u0026rsquo;s consent has been obtained;\n(2) the processing is necessary for the conclusion or performance of a contract in which the individual is a party, or necessary for human resources management in accordance with the labor rules and regulations established in accordance with the law and the collective contracts signed in accordance with the law;\n(3) the processing is necessary for the performance of statutory duties or obligations;\n(4) the processing is necessary for the response to public health emergencies, or for the protection of life, health, and property safety of natural persons in emergencies;\n(5) the personal information is reasonably processed for news reporting, media supervision, and other activities conducted in the public interest;\n(6) the personal information disclosed by the individual himself or other legally disclosed personal information of the individual is reasonably processed in accordance with this Law; and\n(7) other circumstances as provided by laws or administrative regulations.\nIndividual consent shall be obtained for processing personal information if any other relevant provisions of this Law so provide, except under the circumstances specified in Subparagraphs (2) to (7) of the preceding paragraph.\nArticle 14 Where personal information processing is based on individual consent, the individual consent shall be voluntary, explicit, and fully informed. Where any other law or administrative regulation provides that an individual\u0026rsquo;s separate consent or written consent must be obtained for processing personal information, such provisions shall apply. In the case of any change of the purposes or means of personal information processing, or the category of processed personal information, a new consent shall be obtained from the individual.\nArticle 15 Where personal information processing is based on individual consent, an individual shall have the right to withdraw his consent. Personal information processors shall provide convenient ways for individuals to withdraw their consents. The withdrawal of consent shall not affect the validity of the processing activities conducted based on consent before it is withdrawn.\nArticle 16 A personal information processor shall not refuse to provide products or services for an individual on the grounds that the individual withholds his consent for the processing of his personal information or has withdrawn his consent for the processing of personal information, except where the processing of personal information is necessary for the provision of products or services.\nArticle 17 A personal information processor shall, before processing personal information, truthfully, accurately and fully inform an individual of the following matters in a easy-to-notice manner and in clear and easy-to-understand language: (1) the name and contact information of the personal information processor;\n(2) the purposes and means of personal information processing, and the categories and storage periods of the personal information to be processed;\n(3) the methods and procedures for the individual to exercise his rights as provided in this Law; and\n(4) other matters that the individual should be notified of as provided by laws and administrative regulations.\nWhere any matter as set forth in the preceding paragraph changes, the individual shall be informed of the change.\nWhere the personal information processor informs an individual of the matters specified in the first paragraph by formulating personal information processing rules, the processing rules shall be made public and be easy to consult and save.\nArticle 18 When processing personal information, personal information processors are permitted not to inform individuals of the matters specified in the first paragraph of the preceding article where laws or administrative regulations require confidentiality or provide no requirement for such notification. Where it is impossible to notify individuals in a timely manner in a bid to protect natural persons\u0026rsquo; life, health and property safety in case of emergency, the personal information processors shall notify them without delay after the emergency is removed.\nArticle 19 Except as otherwise provided by laws and administrative regulations, the storage period of personal information shall be the minimum time necessary to achieve the purpose of processing.\nArticle 20 Where two or more personal information processors jointly determine the purposes and means of processing certain personal information, they shall reach an agreement on their respective rights and obligations in processing the personal information. However, this agreement shall not affect an individual\u0026rsquo;s request to any one of them to exercise his rights as provided in this Law. Where, in jointly processing certain personal information, a processor infringes the rights and interests on personal information and causes damages, other personal information processors shall bear joint and several liability in accordance with law.\nArticle 21 A personal information processor entrusting the processing of certain personal information to a party shall reach an agreement with the entrusted party on the purposes, period and means of processing, the categories of personal information to be processed and the protection measures, as well as the rights and obligations of both parties, among others, and shall supervise the personal information processing activities of the entrusted party. The entrusted party shall process personal information in accordance with the agreement and may not process personal information beyond the purposes, means and other conditions as agreed upon. Where the entrustment contract has not taken effect, or is invalid, or is revoked or terminated, the entrusted party shall return the personal information in question to the personal information processor or delete it and shall not retain the personal information.\nWithout the consent of the personal information processor, the entrusted party may not sub-contract the processing of personal information to any other party.\nArticle 22 Where a personal information processor needs to transfer personal information due to a merger, division, dissolution, or bankruptcy or for other reasons, the processor shall inform the individuals of the name and contact information of the recipient of the transferred personal information. The recipient shall continue to perform the obligations of the said personal information processor. Any change of the original purposes or means of processing by the recipient shall be subject to individual consent in accordance with this Law.\nArticle 23 To provide personal information for any other processor, a personal information processor shall inform the individuals of the recipient\u0026rsquo;s name and contact information, the purposes and means of processing and the categories of personal information to be processed, and shall obtain the individuals\u0026rsquo; separate consent. The recipient shall process personal information within the scope of the purposes, means, and categories of personal information mentioned above. Any change of the purposes or means of processing by the recipient shall be subject to individual consent in accordance with this Law.\nArticle 24 Personal information processors using personal information for automated decision making shall ensure the transparency of the decision making and the fairness and impartiality of the results, and may not apply unreasonable differential treatment to individuals in terms of transaction prices and other transaction conditions. Information push and commercial marketing to individuals based on automated decision making shall be simultaneously accompanied by options not specific to their personal characteristics or with convenient means for individuals to refuse.\nWhere a decision that may have a significant impact on an individual\u0026rsquo;s rights and interests is made through automated decision making, the individual shall have the right to request clarification from the personal information processor and the right to refuse the processor for making the decision only through automated decision making.\nArticle 25 Personal information processors shall not disclose the personal information they process, except where separate consents has been obtained from the individuals. 1 2 3 \u0026gt;\nArticle 26 Image collection and personal identification equipment in public places shall be installed only when it is necessary for the purpose of maintaining public security, and shall be installed in compliance with the relevant provisions of the state and with prominent reminders. The personal images and identification information collected can only be used for the purpose of maintaining public security and, unless the individuals\u0026rsquo; separate consents are obtained, shall not be used for any other purpose.\nArticle 27 A personal information processor may reasonably process the personal information disclosed by an individual himself or other legally disclosed personal information, except where the individual expressly refuses. Where the processing of disclosed personal information may have a significant impact on an individual\u0026rsquo;s rights and interests, the personal information processors shall first obtain the individual\u0026rsquo;s consent in accordance with the provisions of this Law.\nSection 2 Rules on Processing Sensitive Personal Information Article 28 \u0026ldquo;Sensitive personal information\u0026rdquo; is personal information that once leaked or illegally used, may easily lead to the infringement of the personal dignity of a natural person or may endanger his personal safety or property, including information such as biometrics, religious belief, specific identity, medical health status, financial accounts, and the person\u0026rsquo;s whereabouts, as well as the personal information of a minor under the age of 14 years. Personal information processors can process sensitive personal information only when there is a specific purpose and when it is of necessity, under the circumstance where strict protective measures are taken.\nArticle 29 For the processing of sensitive personal information, individual\u0026rsquo;s separate consent shall be obtained. Where other laws or administrative regulations provide that written consent shall be obtained for the processing of sensitive personal information, such provisions shall prevail.\nArticle 30 In addition to the matters specified in the first paragraph of Article 17 of this Law, a processor processing sensitive personal information shall notify an individual of the necessity of processing his sensitive personal information and the impact it has on his rights and interests, except where such notification is not required in accordance with the provisions of this Law.\nArticle 31 To process the personal information of minors under the age of 14, personal information processors shall obtain the consent of the parents or other guardians of the minors. Personal information processors processing the personal information of minors under the age of 14 shall develop special rules for processing such personal information.\nArticle 32 Where other laws or administrative regulations provide that relevant administrative permit shall be obtained for the processing of sensitive personal information or impose other restrictions, such provisions shall prevail.\nSection 3 Special Provisions on the Processing of Personal Information by State Organs Article 33 This Law shall apply to the processing of personal information by state organs; where there are special provisions in this Section, the provisions of this Section shall prevail.\nArticle 34 When state organs process personal information in order to perform their statutory duties, they shall act in accordance with the authority and procedures prescribed by laws and administrative regulations, and shall not exceed the scope and limits necessary to perform their statutory duties.\nArticle 35 When state organs process personal information in order to perform their statutory duties, they shall fulfill the obligation of notification in accordance with the provisions of this Law, except under the circumstances specified in the first paragraph of Article 18 of this Law or where notification will hinder the state organs from performing their statutory duties.\nArticle 36 Personal information processed by state organs shall be stored within the territory of the People\u0026rsquo;s Republic of China. A security assessment shall be conducted where it is truly necessary to provide such information for any party outside of the territory of the People\u0026rsquo;s Republic of China. In the security assessment the relevant departments shall provide support and assistance if so requested.\nArticle 37 Where organizations authorized by laws or regulations with the function of administering public affairs process personal information in order to fulfill their statutory duties, the provisions herein on the processing of personal information by state organs shall apply.\nChapter III Rules on Provision of Personal Information Across Border Article 38 A personal information processor that truly needs to provide personal information for a party outside the territory of the People\u0026rsquo;s Republic of China for business sake or other reasons, shall meet one of the following requirements: (1) passing the security assessment organized by the national cyberspace department in accordance with Article 40 of this Law;\n(2) obtaining personal information protection certification from the relevant specialized institution according to the provisions issued by the national cyberspace department;\n(3) concluding a contract stipulating both parties\u0026rsquo; rights and obligations with the overseas recipient in accordance with the standard contract formulated by the national cyberspace department; and\n(4) meeting other conditions set forth by laws and administrative regulations and by the national cyberspace department.\nWhere an international treaty or agreement that the People\u0026rsquo;s Republic of China has concluded or acceded to stipulates conditions for providing personal information for a party outside the territory of the People\u0026rsquo;s Republic of China, such stipulations may be followed.\nThe personal information processor shall take necessary measures to ensure that the personal information processing activities of the overseas recipient meet the personal information protection standards set forth in this Law.\nArticle 39 Where a personal information processor provides personal information for any party outside the territory of the People\u0026rsquo;s Republic of China, the processor shall inform the individuals of the overseas recipient\u0026rsquo;s name and contact information, the purposes and means of processing, the categories of personal information to be processed, as well as the methods and procedures for the individuals to exercise their rights as provided in this Law over the overseas recipient, etc., and shall obtain individual\u0026rsquo;s separate consent.\nArticle 40 Critical information infrastructure operators and the personal information processors that process personal information up to the amount prescribed by the national cyberspace department shall store domestically the personal information collected and generated within the territory of the People\u0026rsquo;s Republic of China. Where it is truly necessary to provide the information for a party outside the territory of the People\u0026rsquo;s Republic of China, the matter shall be subjected to security assessment organized by the national cyberspace department. Where laws, administrative regulations, or the provisions issued by the national cyberspace department provide that security assessment is not necessary, such provisions shall prevail.\nArticle 41 The competent authorities of the People\u0026rsquo;s Republic of China shall handle foreign judicial or law enforcement authorities\u0026rsquo; requests for personal information stored within China in accordance with relevant laws and the international treaties and agreements concluded or acceded to by the People\u0026rsquo;s Republic of China, or under the principle of equality and reciprocity. Without the approval of the competent authorities of the People\u0026rsquo;s Republic of China, no organization or individual shall provide data stored in the territory of the People\u0026rsquo;s Republic of China for any foreign judicial or law enforcement authority.\nArticle 42 Where overseas organizations or individuals engage in personal information processing activities, which infringe upon the rights and interests of citizens of the People\u0026rsquo;s Republic of China on personal information or endanger the national security or public interests of the People\u0026rsquo;s Republic of China, the national cyberspace department may include them in a list of restricted or prohibited recipients of personal information, publicize the list, and take measures such as restricting or prohibiting the provision of personal information for such organizations and individuals.\nArticle 43 Where any country or region adopts any prohibitive, restrictive or other similar discriminatory measures against the People\u0026rsquo;s Republic of China in terms of personal information protection, the People\u0026rsquo;s Republic of China may take countermeasures against the aforesaid country or region based on actual situations.\nChapter IV Individuals\u0026rsquo; Rights in Personal Information Processing Activities Article 44 Individuals shall have the right to be informed, the right to make decisions on the processing of their personal information, and the right to restrict or refuse the processing of their personal information by others, except as otherwise provided by laws or administrative regulations.\nArticle 45 Individuals shall have the right to consult and duplicate their personal information from personal information processors, except under circumstances as set out in the first paragraph of Article 18 and Article 35 of this Law. Where an individual requests the consultation or duplication of his personal information, the requested personal information processor shall provide such information in a timely manner.\nWhere an individual requests the transfer of his personal information to a designated personal information processor, which meets the requirements of national cyberspace department for transferring personal information , the requested personal information processor shall provide means for the transfer.\nArticle 46 Where an individual discovers that his personal information is incorrect or incomplete, he shall have the right to request the personal information processors to rectify or supplement relevant information. Where an individual requests the rectification or supplementation of his personal information, the personal information processors shall verify the information in question, and make rectification or supplementation in a timely manner.\nArticle 47 In any of the following circumstances, a personal information processor shall take the initiative to erase personal information, and an individual has the right to request the deletion of his personal information if the personal information processor fails to erase the information: (1) the purposes of processing have been achieved or cannot be achieved, or such information is no longer necessary for achieving the purposes of processing;\n(2) the personal information processor ceases to provide products or services, or the storage period has expired;\n(3) the individual withdraws his consent;\n(4) the personal information processor processes personal information in violation of laws, administrative regulations, or agreements; or\n(5) other circumstances as provided by laws and administrative regulations.\nWhere the storage period provided by any law or administrative regulation has not expired, or it is difficult to erase personal information technically, the personal information processor shall cease the processing of personal information other than storing and taking necessary security protection measures for such information.\nArticle 48 An individuals has the right to request a personal information processor to interpret the personal information processing rules developed by the latter.\nArticle 49 The close relatives of a deceased natural person may, for their own legal and legitimate interests, exercise the rights to handle the personal information of the deceased, such as consultation, duplication, rectification, and deletion, as provided in this Chapter, except as otherwise arranged by the deceased before death.\nArticle 50 A personal information processor shall establish the mechanism for receiving and handling individuals\u0026rsquo; requests for exercising their rights. Where an individual\u0026rsquo;s request is rejected, the reasons therefor shall be given. Where an individual\u0026rsquo;s request to exercise his rights is rejected by a personal information processor, the individual may file a lawsuit with the people\u0026rsquo;s court in accordance with the law.\nChapter V Obligations of Personal Information Processors Article 51 Personal information processors shall take the following measures to ensure that their personal information processing activities are in compliance with laws and administrative regulations based on the purpose and means of processing, the categories of personal information to be processed, the impact on personal rights and interests, and the potential security risks, among others, and shall prevent unauthorized access to, as well as breach, tampering or loss of any personal information: (1) formulating internal management system and operational procedures;\n(2) implementing classified management of personal information;\n(3) adopting corresponding security technical measures such as encryption and de-identification;\n(4) reasonably determining the operational authority of personal information processing, and regularly conducting safety education and training for practitioners;\n(5) formulating contingent plans for personal information security emergencies and organizing the implementation of such plans; and\n(6) other measures as provided by laws and administrative regulations.\n1 2 3 \u0026gt;\nArticle 52 A personal information processor that processes personal information up to the amount prescribed by the national cyberspace department shall designate a person in charge of personal information protection, who shall supervise the personal information processing activities of the processor as well as the protective measures taken thereby, among others. The personal information processor shall disclose the contact information of the person in charge of personal information protection, and submit the said person\u0026rsquo;s name, contact information, and other information to the departments with personal information protection duties.\nArticle 53 Personal information processors outside the territory of the People\u0026rsquo;s Republic of China as specified in the second paragraph of Article 3 of this Law shall set up specialized agencies or designate representatives within the territory of the People\u0026rsquo;s Republic of China to be responsible for handling personal information protection related matters, and shall submit the names, contact information, and other information of the agencies and representatives to the departments with personal information protection duties.\nArticle 54 Personal information processors shall regularly conduct compliance audits of their personal information processing activities with laws and administrative regulations.\nArticle 55 In any of the following circumstances, a personal information processor shall assess in advance the impact on personal information protection and keep a record of the course of the processing: (1) processing sensitive personal information;\n(2) using personal information to conduct automated decision making;\n(3) entrusting personal information processing to another party, providing personal information for another party, or publicizing personal information;\n(4) providing personal information for any party outside the territory of the People\u0026rsquo;s Republic of China; or\n(5) conducting other personal information processing activities which may have significant impacts on individuals.\nArticle 56 The assessment of impact on personal information protection shall include the following contents: (1) whether the purposes and means of personal information processing, are legitimate, justified and necessary;\n(2) the impact on individuals\u0026rsquo; rights and interests, and security risks; and\n(3) whether the protection measures taken are legitimate, effective, and compatible with the degree of risks.\nThe report of the impact assessment on personal information protection and the processing record shall be retained for at least three years.\nArticle 57 Where the breach, tampering, or loss of personal information occurs or may occur, a personal information processor shall immediately take remedial measures and notify the departments with personal information protection duties and the relevant individuals. The notice shall include the following items: (1) the categories of personal information that has been or may be breached, tampered with or lost, and the reasons and possible harm of the breach, tampering and loss;\n(2) the remedial measures adopted by the personal information processor and the measures the individuals may take to mitigate the harm; and\n(3) the contact information of the personal information processor.\nWhere the measures taken by the personal information processor can effectively avoid the harm caused by breach, tampering, or loss of personal information, the personal information processor is not required to notify individuals; where the departments with personal information protection duties consider that harm may be caused, they have the authority to request the personal information processor to notify individuals.\nArticle 58 A personal information processor that provides important internet platform services involving a huge number of users and complicated business types shall perform the following obligations: (1) establishing and improving the personal information protection compliance system in accordance with the provisions of the state and establishing an independent organization mainly composed of external members to supervise the protection of personal information;\n(2) following the principles of openness, fairness, and justice, formulating platform rules, and clarifying the norms and obligations that product or service providers within the platform should meet when processing personal information;\n(3) stopping providing services for product or service providers within the platforms that process personal information in serious violation of laws and administrative regulations; and\n(4) regularly publishing social responsibility reports on personal information protection for public supervision.\nArticle 59 The party entrusted with the processing of personal information shall, in accordance with this Law and relevant laws and administrative regulations, take the necessary measures to ensure the security of the personal information entrusted for processing, and assist the entrusting personal information processor in fulfilling the obligations provided by this Law.\nChapter VI Departments with Personal Information Protection Duties Article 60 The national cyberspace department shall be responsible for the overall planning and coordination of personal information protection and related supervision and administration. The relevant departments of the State Council shall, in accordance with this Law and other relevant laws and administrative regulations, be responsible for personal information protection and related supervision and administration within the scope of their respective duties. The duties of personal information protection and related supervision and administration of the relevant departments of the local people\u0026rsquo;s governments at or above the county level shall be determined in accordance with the relevant provisions of the state.\nThe departments provided in the preceding two paragraphs are collectively referred to as the departments with personal information protection duties.\nArticle 61 Departments with personal information protection duties shall perform the following personal information protection duties: (1) conducting publicity and education on personal information protection, and guiding and supervising personal information processors in their protection of personal information;\n(2) receiving and handling complaints and reports related to personal information protection;\n(3) organizing evaluations on applications, etc. in terms of personal information protection and publish the results of such evaluations;\n(4) investigating and handling illegal personal information processing activities; and\n(5) other duties as provided by laws and administrative regulations.\nArticle 62 The national cyberspace department shall coordinate relevant departments to promote personal information protection through the following efforts in accordance with this Law: (1) formulating specific rules and standards for personal information protection;\n(2) developing special personal information protection rules and standards for small personal information processors, the processing of sensitive personal information, and new technologies and applications such as face recognition and artificial intelligence;\n(3) supporting the research and development, and promoting the application of secure and convenient electronic identity authentication technology, and advancing the public services for network identity authentication;\n(4) promoting the development of a personal information protection service system with the participation of various social sectors, and supporting relevant institutions in providing personal information protection assessment and certification services; and\n(5) improving the complaint and reporting mechanism related to personal information protection .\nArticle 63 A department with personal information protection duties when fulfilling related duties may take the following measures: (1) questioning relevant parties, and investigating circumstances related to personal information processing activities;\n(2) consulting and duplicating the parties\u0026rsquo; contracts, records, account books and other relevant materials related to personal information processing activities;\n(3) conducting on-site inspections, and investigating suspected illegal personal information processing activities; and\n(4) inspecting equipment and articles related to personal information processing activities; and sealing up or seizing equipment and articles related to illegal personal information processing activities as proved by evidence after submitting written reports to and obtaining approval from the principal person in charge of the departments with personal information protection duties.\nWhen departments with personal information protection duties carry out their duties in accordance with the law, the parties concerned shall cooperate and provide assistance, and shall not reject or obstruct them.\nArticle 64 Where a department with personal information protection duties finds, when performing its duties, relatively high risks in personal information processing activities or the occurrence of personal information security incidents, the department may hold an interview with the legal representative or the principal person in charge of the personal information processor according to the provided authority and procedures, or request the processor to entrust a professional institution to conduct compliance audits of the personal information processing activities. The personal information processor shall adopt measures to make rectification and eliminate potential risks as required. Where a department with personal information protection duties, in performing its duties, finds an illegal personal information processing activity that may involve a crime, the department shall transfer the case to the public security organ in a timely manner in accordance with the law.\nArticle 65 Any organization or individual has the right to complain and report to a department with personal information protection duties about illegal personal information processing. The department that receives such a complaint or report shall handle it in a timely manner in accordance with the law, and notify the complainant or informant of the results. Departments with personal information protection duties shall publish their contact information for receiving complaints and reports.\nChapter VII Legal Liability Article 66 Where personal information is processed in violation of the provisions of this Law or without fulfilling the personal information protection obligations provided in this Law, the departments with personal information protection duties shall order the violator to make corrections, give a warning, confiscate the illegal gains, and order the suspension or termination of provision of services by the applications that illegally process personal information; where the violator refuses to make corrections, a fine of not more than RMB one million yuan shall be imposed thereupon; and the directly liable persons in charge and other directly liable persons shall each be fined not less than RMB 10,000 yuan nor more than RMB 100,000 yuan. In case of an illegal act as prescribed in the preceding paragraph and the circumstances are serious, the departments with personal information protection duties at or above the provincial level shall order the violator to make corrections, confiscate the illegal gains, impose a fine of not more than RMB 50 million yuan or not more than five percent of the previous year\u0026rsquo;s turnover; may also order the suspension of relevant businesses, or order the suspension of all the business operations for an overhaul, and notify the competent authorities to revoke relevant business permits or license; shall impose a fine of not less than RMB 100,000 yuan but not more than RMB 1 million yuan upon each of the directly liable persons in charge and other directly liable persons, and may decide to prohibit the abovementioned persons from serving as directors, supervisors, senior managers, or the persons in charge of relevant companies within a specific period of time.\nArticle 67 Any violation of the provisions of this Law shall be entered in the relevant credit record and be published in accordance with the provisions of the relevant laws and administrative regulations.\nArticle 68 Where any state organ fails to fulfill the personal information protection obligations as provided in this Law, the organ at the higher level or the departments with personal information protection duties shall order it to make corrections, and discipline the directly liable person in charge and other directly liable persons in accordance with the law. Where a staff member of a department with personal information protection duties neglects duties, abuses power, or practices favoritism, which does not constitute a crime, the staff member shall be subject to sanction in accordance with the law.\nArticle 69 Where a personal information processor infringes the rights or interests on personal information due to any personal information processing activity and cannot prove that the processor is not at fault, the processor shall assume the liability for damages and other tort liability. The liability for damages prescribed in the preceding paragraph shall be determined based on the losses of individuals incurred thereby and the benefits acquired by the infringing personal information processor; and where it is difficult to determine the aforementioned losses or the benefits, the amount of damages shall be determined based on the actual circumstances.\nArticle 70 Where a personal information processor processes personal information in violation of the provisions of this Law and infringes the rights and interests of many individuals, the people\u0026rsquo;s procuratorate, the consumer organizations specified by law, and the organization designated by the national cyberspace department may file a lawsuit with the people\u0026rsquo;s court in accordance with the law.\nArticle 71 Any violation of this Law which constitutes a violation of public security administration shall be subject to public security administration penalty in accordance with the law. If the violation constitutes a crime, the violator shall be held criminally liable in accordance with the law.\nChapter VIII Supplementary Provisions Article 72 This Law is not applicable where a natural person processes personal information for personal or household affairs. Where other laws provide personal information processing in statistical or archives management activities organized and conducted by the people\u0026rsquo;s governments at all levels and their relevant departments, the provisions of such laws shall prevail.\nArticle 73 For purposes of this Law, the following terms shall have the following meanings: (1) \u0026ldquo;A personal information processor\u0026rdquo; refers to an organization or individual that autonomously determines the purposes and means of personal information processing.\n(2) \u0026ldquo;automated decision making\u0026rdquo; refers to the activities of automatically analyzing and evaluating personal behaviors, hobbies, or economic, health, and credit status, among others, through computer programs, and making decisions.\n(3) \u0026ldquo;de-identification\u0026rdquo; refers to processing personal information to make it impossible to identify specific natural persons in the absence of the support of additional information.\n(4) \u0026ldquo;anonymization\u0026rdquo; refers to the process of processing personal information to make it impossible to identify specific natural persons and impossible to restore.\nArticle 74 This Law shall come into force as of November 1st , 2021. 1 2 3\n","permalink":"https://ai.intlaws.com/en/compliance/china/pipl/","summary":"Officialof the Personal Information Protection Law of the PRC: 8 chapters, 74 articles, adopted 2021-08-20, in force 2021-11-01. English text as published on the NPC official English site (marked \u0026ldquo;Translation for Reference Only\u0026rdquo;).","title":"Personal Information Protection Law of the PRC"},{"content":" Version and sources (verifiable)\nItem Content Instrument Protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data — the \u0026ldquo;Convention 108+\u0026rdquo; Reference CETS No. 223 (Council of Europe Treaty Series No. 223) Opened for signature Strasbourg, 10 October 2018, open for signature by the Contracting States to Treaty ETS 108 Entry into force Two independent paths (Article 37): ① ratification by all Parties to treaty ETS 108; or ② five years after the opening for signature (10 October 2018), i.e. as from 11 October 2023, once 38 Parties to the Convention have ratified the Protocol. Status NOT YET IN FORCE. As of 2026-09-22, 34 Parties have ratified (the 34th being the Republic of Moldova, 15 May 2026 — Council of Europe announcement ); four further ratifications are still needed. Entry into force must not be described as imminent. Structure 40 articles: Articles 1–35 amend Convention 108 article by article; Articles 36–40 are final clauses Official text (English) https://rm.coe.int/16808ac918 (Council of Europe repository, 18 pages) Treaty Office record (signatures / ratifications / status) https://www.coe.int/en/web/conventions/full-list?module=treaty-detail\u0026amp;treatynum=223 Explanatory Report https://rm.coe.int/cets-223-explanatory-report-to-the-protocol-amending-the-convention-fo/16808ac91a Chinese version No official Chinese text (official languages: English and French). A Chinese translation by our editorial team, cross-checked article by article, marked non-official, for reference only → 中文全文 Retrieval \u0026amp; verification 2026-09-22. The Council of Europe blocks automated direct access from this network (Cloudflare), so the official PDF was retrieved through a rendering proxy. Text de-hyphenated; article numbers accepted only in strict ascending order (1–40) to exclude cross-references; article count and headings checked against the Treaty Office record. Preamble — # Protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data The member States of the Council of Europe and the other Parties to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108), opened for signature in Strasbourg on 28 January 1981 (hereinafter referred to as “the Convention”), Having regard to Resolution No. 3 on data protection and privacy in the third millennium adopted at the 30th Council of Europe Conference of Ministers of Justice (Istanbul, Turkey, 24-26 November 2010); Having regard to the Parliamentary Assembly of the Council of Europe’s Resolution 1843 (2011) on the protection of privacy and personal data on the Internet and online media and Resolution 1986 (2014) on improving user protection and security in cyberspace; Having regard to Opinion 296 (2017) on the draft protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108) and its explanatory memorandum, adopted by the Standing Committee on behalf of the Parliamentary Assembly of the Council of Europe on 24 November 2017; Considering that new challenges to the protection of individuals with regard to the processing of personal data have emerged since the Convention was adopted; Considering the need to ensure that the Convention continues to play its pre-eminent role in protecting individuals with regard to the pr\nArticle 1\n(1) The first recital of the preamble of the Convention shall be replaced by the following:\n“The member States of the Council of Europe, and the other signatories hereto,”\n(2) The third recital of the preamble of the Convention shall be replaced by the following:\n“Considering that it is necessary to secure the human dignity and protection of the human rights and fundamental freedoms of every individual and, given the diversification, intensification and globalisation of data processing and personal data flows, personal autonomy based on a person’s right to control his or her personal data and the processing of such data;”\n(3) The fourth recital of the preamble of the Convention shall be replaced by the following:\n“Recalling that the right to protection of personal data is to be considered in respect of its role in society and that it has to be reconciled with other human rights and fundamental freedoms, including freedom of expression;”\n(4) The following recital shall be added after the fourth recital of the preamble of the Convention:\n“Considering that this Convention permits account to be taken, in the implementation of the rules laid down therein, of the principle of the right of access to official documents;”\n(5) The fifth recital of the preamble of the Convention shall be deleted. New fifth and sixth recitals shall be added, which read as follows:\n“Recognising that it is necessary to promote at the global level the fundamental values of respect for privacy and protection of personal data, thereby contributing to the free flow of information between people;”\n“Recognising the interest of a reinforcement of international co-operation between the Parties to the Convention,”\nArticle 2\nThe text of Article 1 of the Convention shall be replaced by the following:\n“The purpose of this Convention is to protect every individual, whatever his or her nationality or residence, with regard to the processing of their personal data, thereby contributing to respect for his or her human rights and fundamental freedoms, and in particular the right to privacy.”\nArticle 3\n(1) Littera b of Article 2 of the Convention shall be replaced by the following:\n“b ‘data processing’ means any operation or set of operations performed on personal data, such as the collection, storage, preservation, alteration, retrieval, disclosure, making available, erasure, or destruction of, or the carrying out of logical and/or arithmetical operations on such data;”\n(2) Littera c of Article 2 of the Convention shall be replaced by the following:\n“c where automated processing is not used, ‘data processing’ means an operation or set of operations performed upon personal data within a structured set of such data which are accessible or retrievable according to specific criteria;”\n(3) Littera d of Article 2 of the Convention shall be replaced by the following:\n“d ‘controller’ means the natural or legal person, public authority, service, agency or any other body which, alone or jointly with others, has decision-making power with respect to data processing;”\n(4) The following new litterae shall be added after littera d of Article 2 of the Convention:\n“e ‘recipient’ means a natural or legal person, public authority, service, agency or any other body to whom data are disclosed or made available;\n(f) ‘processor’ means a natural or legal person, public authority, service, agency or any other body which processes personal data on behalf of the controller.”\nArticle 4\n(1) Paragraph 1 of Article 3 of the Convention shall be replaced by the following:\n“1 Each Party undertakes to apply this Convention to data processing subject to its\njurisdiction in the public and private sectors, thereby securing every individual’s right to protection of his or her personal data .”\n(2) Paragraph 2 of Article 3 of the Convention shall be replaced by the following:\n“2 This Convention shall not apply to data processing carried out by an individual in the course of purely personal or household activities .”\n(3) Paragraphs 3 to 6 of Article 3 of the Convention shall be deleted.\nArticle 5\nThe title of Chapter II of the Convention shall be replaced by the following:\n“Chapter II – Basic principles for the protection of personal data”.\nArticle 6\n(1) Paragraph 1 of Article 4 of the Convention shall be replaced by the following:\n“1 Each Party shall take the necessary measures in its law to give effect to the provisions of this Convention and secure their effective application .”\n(2) Paragraph 2 of Article 4 of the Convention shall be replaced by the following:\n“2 These measures shall be taken by each Party and shall have come into force by the time of ratification or of accession to this Convention .”\n(3) A new paragraph shall be added after paragraph 2 of Article 4 of the Convention:\n“3 Each Party undertakes:\n(a) to allow the Convention Committee provided for in Chapter VI to evaluate the effectiveness of the measures it has taken in its law to give effect to the provisions of this Convention; and\n(b) to contribute actively to this evaluation process.”\nArticle 7\n(1) The title of Article 5 shall be replaced by the following:\n“Article 5 – Legitimacy of data processing and quality of data”.\n(2) The text of Article 5 of the Convention shall be replaced by the following:\n“1 Data processing shall be proportionate in relation to the legitimate purpose pursued and reflect at all stages of the processing a fair balance between all interests concerned, whether public or private, and the rights and freedoms at stake .\n(2) Each Par ty shall provide that data processing can be carried out on the basis of the free, specific, informed and unambiguous consent of the data subject or of some other legitimate basis laid down by law .\n(3) Personal data undergoing processing shall be processed lawfully.\n(4) Personal data undergoing processing shall be:\n(a) processed fairly and in a transparent manner;\n(b) collected for explicit, specified and legitimate purposes and not processed in a way incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is, subject to appropriate safeguards, compatible with those purposes;\n(c) adequate, relevant and not excessive in relation to the purposes for which they are processed;\n(d) accurate and, where necessary, kept up to date;\n(e) preserved in a form which permits identification of the data subjects for no longer than is necessary for the purposes for which those data are processed.”\nArticle 8\nThe text of Article 6 of the Convention shall be replaced by the following:\n“1 The processing of:\n– genetic data;\n– personal data relating to offences, criminal proceedings and convictions, and related security measures;\n– biometric data uniquely identifying a person;\n– personal data for the information they reveal relating to racial or ethnic origin, political opinions, trade-union membership, religious or other beliefs, health or sexual life, shall only be allowed where appropriate safeguards are enshrined in law, complementing\nthose of this Convention.\n(2) Such safeguards shall guard against the risks that the processing of sensitive data may present for the interests, rights and fundamental freedoms of the data subject, notably a risk of discrimination .”\nArticle 9\nThe text of Article 7 of the Convention shall be replaced by the following:\n“1 Each Party shall provide that the controller, and where applicable the processor, takes appropriate security measures against risks such as accidental or unauthorised access to, destruction, loss, use, modification or disclosure of personal data .\n(2) Each Party shall provide that the controller notifies, without delay, at least the competent supervisory authority within the meaning of Article 1 5 of this Convention, of those data breaches which may seriously interfere with the rights and fundamental freedoms of data subjects .”\nArticle 10\nA new Article 8 shall be added after Article 7 of the Convention as follows:\n“Article 8 – Transparency of processing\n(1) Each Party shall provide that the controller informs the data subjects of:\n(a) his or her identity and habitual residence or establishment;\n(b) the legal basis and the purposes of the intended processing;\n(c) the categories of personal data processed;\n(d) the recipients or categories of recipients of the personal data, if any; and\n(e) the means of exercising the rights set out in Article 9,\nas well as any necessary additional information in order to ensure fair and transparent processing of the personal data.\n(2) Paragraph 1 shall not apply where the data subject already has the relevant information.\n(3) Where the personal data are not collected from the data subjects, the controller shall not be required to provide such information where the processing is expressly prescribed by law or this proves to be impossible or involves disproportionate efforts.”\nArticle 11\n(1) The former Article 8 of the Convention shall be renumbered Article 9 and the title shall be replaced by the following:\n“Article 9 – Rights of the data subject”.\n(2) The text of Article 8 of the Convention (new Article 9) shall be replaced by the following:\n“1 Every individual shall have a right:\n(a) not to be subject to a decision significantly affecting him or her based solely on an automated processing of data without having his or her views taken into consideration;\n(b) to obtain, on request, at reasonable intervals and without excessive delay or expense, confirmation of the processing of personal data relating to him or her, the communication in an intelligible form of the data processed, all available information on their origin, on the preservation period as well as any other information that the controller is required to provide in order to ensure the transparency of processing in accordance with Article 8, paragraph 1;\n(c) to obtain, on request, knowledge of the reasoning underlying data processing where the results of such processing are applied to him or her;\n(d) to object at any time, on grounds relating to his or her situation, to the processing of personal data concerning him or her unless the controller demonstrates legitimate grounds for the processing which override his or her interests or rights and fundamental freedoms;\n(e) to obtain, on request, free of charge and without excessive delay, rectification or erasure, as the case may be, of such data if these are being, or have been, processed contrary to the provisions of this Convention;\n(f) to have a remedy under Article 12 where his or her rights under this Convention have been violated;\n(g) to benefit, whatever his or her nationality or residence, from the assistance of a supervisory authority within the meaning of Article 15, in exercising his or her rights under this Convention.\n(2) Paragraph 1.a shall not apply if the decision is authorised by a law to which the controller is subject and which also lays down suitable measures to safeguard the data subject\u0026rsquo;s rights, freedoms and legitimate interests.”\nArticle 12\nA new Article 10 shall be added after the new Article 9 of the Convention as follows:\n“Article 10 – Additional obligations\n(1) Each Party shall provide that controllers and, where applicable, processors, take all appropriate measures to comply with the obligations of this Convention and be able to demonstrate, subject to the domestic legislation adopted in accordance with Article 11, paragraph 3, in particular to the competent supervisory authority provided for in Article 15, that the data processing under their control is in compliance with the provisions of this Convention.\n(2) Each Party shall provide that controllers and, where applicable, processors, examine the likely impact of intended data processing on the rights and fundamental freedoms of data subjects prior to the commencement of such processing, and shall design the data processing in such a manner as to prevent or minimise the risk of interference with those rights and fundamental freedoms.\n(3) Each Party shall provide that controllers, and, where applicable, processors, implement technical and organisational measures which take into account the implications of the right to the protection of personal data at all stages of the data processing.\n(4) Each Party may, having regard to the risks arising for the interests, rights and fundamental freedoms of the data subjects, adapt the application of the provisions of paragraphs 1, 2 and 3 in the law giving effect to the provisions of this Convention, according to the nature and volume of the data, the nature, scope and purpose of the processing and, where appropriate, the size of the controller or processor.”\nArticle 13\nThe former Articles 9 to 12 of the Convention shall become Articles 11 to 14 of the Convention.\nArticle 14\nThe text of Article 9 of the Convention (new Article 11) shall be replaced by the following:\n“1 No exception to the provisions set out in this chapter shall be allowed except to the provisions of Article 5, paragraph 4, Article 7, paragraph 2, Article 8, paragraph 1, and Article 9, when such an exception is provided for by law, respects the essence of the fundamental rights and freedoms and constitutes a necessary and proportionate measure in a democratic society for:\n(a) the protection of national security, defence, public safety, important economic and financial interests of the State, the impartiality and independence of the judiciary or the prevention, investigation and prosecution of criminal offences and the execution of criminal penalties, and other essential objectives of general public interest;\n(b) the protection of the data subject or the rights and fundamental freedoms of others, notably freedom of expression.\n(2) Restrictions on the exercise of the provisions specified in Articles 8 and 9 may be provided for by law with respect to data processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes when there is no recognisable risk of infringement of the rights and fundamental freedoms of data subjects.\n(3) In addition to the exceptions allowed for in paragraph 1 of this article, with reference to processing activities for national security and defence purposes, each Party may provide, by law and only to the extent that it constitutes a necessary and proportionate measure in a democratic society to fulfil such an aim, exceptions to Article 4, paragraph 3, Article 14, paragraphs 5 and 6, and Article 15, paragraph 2, litterae a, b, c and d.\nThis is without prejudice to the requirement that processing activities for national security and defence purposes are subject to independent and effective review and supervision under the domestic legislation of the respective Party.”\nArticle 15\nThe text of Article 10 of the Convention (new Article 12) shall be replaced by the following:\n“Each Party undertakes to establish appropriate judicial and non-judicial sanctions and remedies for violations of the provisions of this Convention.”\nArticle 16\nThe title of Chapter III shall be replaced by the following:\n“Chapter III – Transborder flows of personal data”.\nArticle 17\n(1) The title of Article 12 of the Convention (new Article 14) shall be replaced by the following:\n“Article 14 – Transborder flows of personal data”.\n(2) The text of Article 12 of the Convention (new Article 14) shall be replaced by the following:\n“1 A Party shall not, for the sole purpose of the protection of personal data, prohibit or subject to special authorisation the transfer of such data to a recipient who is subject to the jurisdiction of another Party to the Convention. Such a Party may, however, do so if there is a real and serious risk that the transfer to another Party, or from that other Party to a non-Party, would lead to circumventing the provisions of the Convention. A Party may also do so if bound by harmonised rules of protection shared by States belonging to a regional international organisation.\n(2) When the recipient is subject to the jurisdiction of a State or international organisation which is not Party to this Convention, the transfer of personal data may only take place where an appropriate level of protection based on the provisions of this Convention is secured.\n(3) An appropriate level of protection can be secured by:\n(a) the law of that State or international organisation, including the applicable international treaties or agreements; or\n(b) ad hoc or approved standardised safeguards provided by legally-binding and enforceable instruments adopted and implemented by the persons involved in the transfer and further processing.\n(4) Notwithstanding the provisions of the previous paragraphs, each Party may provide that the transfer of personal data may take place if:\n(a) the data subject has given explicit, specific and free consent, after being informed of risks arising in the absence of appropriate safeguards; or\n(b) the specific interests of the data subject require it in the particular case; or\n(c) prevailing legitimate interests, in particular important public interests, are provided for by law and such transfer constitutes a necessary and proportionate measure in a democratic society; or\n(d) it constitutes a necessary and proportionate measure in a democratic society for freedom of expression.\n(5) Each Party shall provide that the competent supervisory authority, within the meaning of Article 15 of this Convention, is provided with all relevant information concerning the transfers of data referred to in paragraph 3, littera b and, upon request, paragraph 4,\nlitterae b and c.\n(6) Each Party shall also provide that the supervisory authority is entitled to request that the person who transfers data demonstrates the effectiveness of the safeguards or the existence of prevailing legitimate interests and that the supervisory authority may, in order to protect the rights and fundamental freedoms of data subjects, prohibit such transfers, suspend them or subject them to conditions.”\n(3) The text of Article 12 of the Convention (new Article 14) includes the provisions of Article 2 of the Additional Protocol of 2001 regarding supervisory authorities and transborder data flows (ETS No. 181) on transborder flows of personal data to a recipient which is not subject to the jurisdiction of a Party to the Convention.\nArticle 18\nA new Chapter IV shall be added after Chapter III of the Convention, as follows:\n“Chapter IV – Supervisory authorities”.\nArticle 19\nA new Article 15 includes the provisions of Article 1 of the Additional Protocol of 2001 (ETS No.181) and reads as follows:\n“Article 15 – Supervisory authorities\n(1) Each Party shall provide for one or more authorities to be responsible for ensuring compliance with the provisions of this Convention.\n(2) To this end, such authorities:\n(a) shall have powers of investigation and intervention;\n(b) shall perform the functions relating to transfers of data provided for under Article 14, notably the approval of standardised safeguards;\n(c) shall have powers to issue decisions with respect to violations of the provisions of this Convention and may, in particular, impose administrative sanctions;\n(d) shall have the power to engage in legal proceedings or to bring to the attention of the competent judicial authorities violations of the provisions of this Convention;\n(e) shall promote:\n(i) public awareness of their functions and powers, as well as their activities; \u0026gt; ii public awareness of the rights of data subjects and the exercise of such rights; \u0026gt; iii awareness of controllers and processors of their responsibilities under this Convention;\nspecific attention shall be given to the data protection rights of children and other vulnerable individuals.\n(3) The competent supervisory authorities shall be consulted on proposals for any legislative or administrative measures which provide for the processing of personal data.\n(4) Each competent supervisory authority shall deal with requests and complaints lodged by data subjects concerning their data protection rights and shall keep data subjects informed of progress.\n(5) The supervisory authorities shall act with complete independence and impartiality in performing their duties and exercising their powers and in doing so shall neither seek nor accept instructions.\n(6) Each Party shall ensure that the supervisory authorities are provided with the resources necessary for the effective performance of their functions and exercise of their powers.\n(7) Each supervisory authority shall prepare and publish a periodical report outlining its activities.\n(8) Members and staff of the supervisory authorities shall be bound by obligations of confidentiality with regard to confidential information to which they have access, or have had access to, in the performance of their duties and exercise of their powers.\n(9) Decisions of the supervisory authorities may be subject to appeal through the courts.\n(10) The supervisory authorities shall not be competent with respect to processing carried out by bodies when acting in their judicial capacity.”\nArticle 20\n(1) Chapters IV to VII of the Convention shall be renumbered to Chapters V to VIII of the Convention.\n(2) The title of Chapter V shall be replaced by “Chapter V – Co-operation and mutual assistance”.\n(3) A new Article 17 shall be added, and former Articles 13 to 27 of the Convention shall become Articles 16 to 31 of the Convention.\nArticle 21\n(1) The title of Article 13 of the Convention (new Article 16) shall be replaced by the following:\n“Article 16 – Designation of supervisory authorities”.\n(2) Paragraph 1 of Article 13 of the Convention (new Article 16) shall be replaced by the following:\n“1 The Parties agree to co -operate and render each other mutual assistance in order to implement this Convention .”\n(3) Paragraph 2 of Article 13 of the Convention (new Article 16) shall be replaced by the following:\n“2 For that purpose:\n(a) each Party shall designate one or more supervisory authorities within the meaning of Article 15 of this Convention, the name and address of each of which it shall communicate to the Secretary General of the Council of Europe;\n(b) each Party which has designated more than one supervisory authority shall specify the competence of each authority in its communication referred to in the previous littera .”\n(4) Paragraph 3 of Article 13 of the Convention (new Article 16) shall be deleted.\nArticle 22\nA new Article 17 shall be added after the new Article 16 of the Convention as follows:\n“Article 17 – Forms of co-operation\n(1) The supervisory authorities shall co-operate with one another to the extent necessary for the performance of their duties and exercise of their powers, in particular by:\n(a) providing mutual assistance by exchanging relevant and useful information and co-operating with each other under the condition that, as regards the protection of personal data, all the rules and safeguards of this Convention are complied with;\n(b) co-ordinating their investigations or interventions, or conducting joint actions;\n(c) providing information and documentation on their law and administrative practice relating to data protection.\n(2) The information referred to in paragraph 1 shall not include personal data undergoing processing unless such data are essential for co-operation, or where the data subject concerned has given explicit, specific, free and informed consent to its provision.\n(3) In order to organise their co-operation and to perform the duties set out in the preceding paragraphs, the supervisory authorities of the Parties shall form a network.”\nArticle 23\n(1) The title of Article 14 of the Convention (new Article 18) shall be replaced by the following:\n“Article 18 – Assistance to data subjects”.\n(2) The text of Article 14 of the Convention (new Article 18) shall be replaced by the following:\n“1 Each Party shall assist any data subject, whatever his or her nationality or residence, to exercise his or her rights under Article 9 of this Convention.\n(2) Where a data subject resides on the territory of another Party, he or she shall be given the option of submitting the request through the intermediary of the supervisory authority designated by that Party.\n(3) The request for assistance shall contain all the necessary particulars, relating inter alia to:\n(a) the name, address and any other relevant particulars identifying the data subject making the request;\n(b) the processing to which the request pertains, or its controller;\n(c) the purpose of the request.”\nArticle 24\n(1) The title of Article 15 of the Convention (new Article 19) shall be replaced by the following:\n“Article 19 – Safeguards”.\n(2) The text of Article 15 of the Convention (new Article 19) shall be replaced by the following:\n“1 A supervisory authority which has received information from another supervisory authority, either accompanying a request or in reply to its own request, shall not use that information for purposes other than those specified in the request.\n(2) In no case may a supervisory authority be allowed to make a request on behalf of a data subject of its own accord and without the express approval of the data subject concerned.”\nArticle 25\n(1) The title of Article 16 of the Convention (new Article 20) shall be replaced by the following:\n“Article 20 – Refusal of requests”.\n(2) The recital of Article 16 of the Convention (new Article 20) shall be replaced by the following:\n“A supervisory authority to which a request is addressed under Article 17 of this Convention may not refuse to comply with it unless:”\n(3) Littera a of Article 16 of the Convention (new Article 20) shall be replaced by the following:\n“a the request is not compatible with its powers.”\n(4) Littera c of Article 16 of the Convention (new Article 20) shall be replaced by the following:\n“c compliance with the request would be incompatible with the sovereignty, national security or public order of the Party by which it was designated, or with the rights and fundamental freedoms of individuals under the jurisdiction of that Party.”\nArticle 26\n(1) The title of Article 17 of the Convention (new Article 21) shall be replaced by the following:\n“Article 21 – Costs and procedures”.\n(2) Paragraph 1 of Article 17 of the Convention (new Article 21) shall be replaced by the following:\n“1 Co-operation and mutual assistance which the Parties render each other under Article 17 and assistance they render to data subjects under Articles 9 and 18 shall not give rise to the payment of any costs or fees other than those incurred for experts and interpreters. The latter costs or fees shall be borne by the Party making the request.”\n(3) The terms “his or her” shall replace “his” in paragraph 2 of Article 17 of the Convention (new Article 21).\nArticle 27\nThe title of Chapter V of the Convention (new Chapter VI) shall be replaced by the following:\n“Chapter VI – Convention Committee”.\nArticle 28\n(1) The terms “Consultative Committee” in paragraph 1 of Article 18 of the Convention (new Article 22) shall be replaced by “Convention Committee”.\n(2) Paragraph 3 of Article 18 of the Convention (new Article 22) shall be replaced by the following:\n“3 The Convention Committee may, by a decision taken by a majority of two-thirds of the representatives of the Parties, invite an observer to be represented at its meetings.”\n(3) A new paragraph 4 shall be added after paragraph 3 of Article 18 of the Convention (new Article 22):\n“4 Any Party which is not a member of the Council of Europe shall contribute to the funding of the activities of the Convention Committee according to the modalities established by the Committee of Ministers in agreement with that Party.”\nArticle 29\n(1) The terms “Consultative Committee” in the recital of Article 19 of the Convention (new Article 23) shall be replaced by “Convention Committee”.\n(2) The term “proposals” in littera a of Article 19 of the Convention (new Article 23) shall be replaced with the term “recommendations”.\n(3) References to “Article 21” in littera b and “Article 21 paragraph 3” in littera c of Article 19 of the Convention (new Article 23) shall be replaced respectively by references to “Article 25” and “Article 25, paragraph 3”.\n(4) Littera d of Article 19 of the Convention (new Article 23) shall be replaced by the following:\n“d may express an opinion on any question concerning the interpretation or application of this Convention;”.\n(5) The following additional litterae shall be added following littera d of Article 19 of the Convention (new Article 23):\n“e shall prepare, before any new accession to the Convention, an opinion for the Committee of Ministers relating to the level of personal data protection of the candidate for accession and, where necessary, recommend measures to take to reach compliance with the provisions of this Convention;\n(f) may, at the request of a State or an international organisation, evaluate whether the level of personal data protection the former provides is in compliance with the provisions of this Convention and, where necessary, recommend measures to be taken in order to reach such compliance;\n(g) may develop or approve models of standardised safeguards referred to in Article 14;\n(h) shall review the implementation of this Convention by the Parties and recommend measures to be taken in the case where a Party is not in compliance with this Convention;\n(i) shall facilitate, where necessary, the friendly settlement of all difficulties related to the application of this Convention.”\nArticle 30\nThe text of Article 20 of the Convention (new Article 24) shall be replaced by the following:\n“1 The Convention Committee shall be convened by the Secretary General of the Council of Europe. Its first meeting shall be held within twelve months of the entry into force of this Convention. It shall subsequently meet at least once a year, and in any case when one-third of the representatives of the Parties request its convocation.\n(2) After each of its meetings, the Convention Committee shall submit to the Committee of Ministers of the Council of Europe a report on its work and on the functioning of this Convention.\n(3) The voting arrangements in the Convention Committee are laid down in the elements for the rules of procedure appended to Protocol CETS No. 223.\n(4) The Convention Committee shall draw up the other elements of its rules of procedure and establish, in particular, the procedures for evaluation and review referred to in Article 4, paragraph 3, and Article 23, litterae e, f and h on the basis of objective criteria.”\nArticle 31\n(1) Paragraphs 1 to 4 of Article 21 of the Convention (new Article 25) shall be replaced by the following:\n“1 Amendments to this Convention may be proposed by a Party, the Committee of Ministers of the Council of Europe or the Convention Committee.\n(2) Any proposal for amendment shall be communicated by the Secretary General of the Council of Europe to the Parties to this Convention, to the other member States of the Council of Europe, to the European Union and to every non-member State or international organisation which has been invited to accede to this Convention in accordance with the provisions of Article 27.\n(3) Moreover, any amendment proposed by a Party or the Committee of Ministers shall be communicated to the Convention Committee, which shall submit to the Committee of Ministers its opinion on that proposed amendment.\n(4) The Committee of Ministers shall consider the proposed amendment and any opinion submitted by the Convention Committee, and may approve the amendment.”\n(2) An additional paragraph 7 shall be added after paragraph 6 of Article 21 of the Convention (new Article 25) as follows:\n“7 Moreover, the Committee of Ministers may, after consulting the Convention Committee, unanimously decide that a particular amendment shall enter into force at the expiration of a period of three years from the date on which it has been opened to acceptance, unless a Party notifies the Secretary General of the Council of Europe of an objection to its entry into force. If such an objection is notified, the amendment shall enter into force on the first day of the month following the date on which the Party to this Convention which has notified the objection has deposited its instrument of acceptance with the Secretary General of the Council of Europe.”\nArticle 32\n(1) Paragraph 1 of Article 22 of the Convention (new Article 26) shall be replaced by the following:\n“1 This Convention shall be open for signature by the member States of the Council of Europe and by the European Union. It is subject to ratification, acceptance or approval. Instruments of ratification, acceptance or approval shall be deposited with the Secretary General of the Council of Europe.”\n(2) The terms “member State” in paragraph 3 of Article 22 of the Convention (new Article 26) shall be replaced by “Party”.\nArticle 33\nThe title and the text of Article 23 of the Convention (new Article 27) shall be replaced as follows:\n“Article 27 – Accession by non-member States or international organisations\n(1) After the entry into force of this Convention, the Committee of Ministers of the Council of Europe may, after consulting the Parties to this Convention and obtaining their unanimous agreement, and in light of the opinion prepared by the Convention Committee in accordance with Article 23.e, invite any State not a member of the Council of Europe or an international organisation to accede to this Convention by a decision taken by the majority provided for in Article 20.d of the Statute of the Council of Europe and by the unanimous vote of the representatives of the Contracting States entitled to sit on the Committee of Ministers.\n(2) In respect of any State or international organisation acceding to this Convention according to paragraph 1 above, the Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date of deposit of the instrument of accession with the Secretary General of the Council of Europe.”\nArticle 34\nParagraphs 1 and 2 of Article 24 of the Convention (new Article 28) shall be replaced by the following:\n“1 Any State, the European Union or other international organisation may, at the time of signature or when depositing its instrument of ratification, acceptance, approval or accession, specify the territory or territories to which this Convention shall apply.\n(2) Any State, the European Union or other international organisation may, at any later date, by a declaration addressed to the Secretary General of the Council of Europe, extend the application of this Convention to any other territory specified in the declaration. In respect of such territory the Convention shall enter into force on the first day of the month following the expiration of a period of three months after the date of receipt of such declaration by the Secretary General.”\nArticle 35\n(1) The term “State” in the recital of Article 27 of the Convention (new Article 31) shall be replaced by “Party”.\n(2) References to “Articles 22, 23 and 24” in littera c shall be replaced by references to “Articles 26, 27 and 28”.\nArticle 36\n– Signature, ratification and accession\n(1) This Protocol shall be open for signature by Contracting States to the Convention. It shall be subject to ratification, acceptance or approval. Instruments of ratification, acceptance or approval shall be deposited with the Secretary General of the Council of Europe.\n(2) After the opening for signature of this Protocol and before its entry into force, any other State shall express its consent to be bound by this Protocol by accession. It may not become a Party to the Convention without acceding simultaneously to this Protocol.\nArticle 37\n– Entry into force\n(1) This Protocol shall enter into force on the first day of the month following the expiration of a period of three months after the date on which all Parties to the Convention have expressed their consent to be bound by the Protocol, in accordance with the provisions of paragraph 1 of Article 36.\n(2) In the event this Protocol has not entered into force in accordance with paragraph 1, following the expiry of a period of five years after the date on which it has been opened for signature, the Protocol shall enter into force in respect of those States which have expressed their consent to be bound by it in accordance with paragraph 1, provided that the Protocol has at least thirty-eight Parties. As between the Parties to the Protocol, all provisions of the amended Convention shall have effect immediately upon entry into force.\n(3) Pending the entry into force of this Protocol and without prejudice to the provisions regarding the entry into force and the accession by non-member States or international organisations, a Party to the Convention may, at the time of signature of this Protocol or at any later moment, declare that it will apply the provisions of this Protocol on a provisional basis. In such cases, the provisions of this Protocol shall apply only with respect to the other Parties to the Convention which have made a declaration to the same effect. Such a declaration shall take effect on the first day of the third month following the date of its receipt by the Secretary General of the Council of Europe.\n(4) From the date of entry into force of this Protocol, the Additional Protocol to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, regarding supervisory authorities and transborder data flows (ETS No. 181) shall be repealed.\n(5) From the date of the entry into force of this Protocol, the amendments to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, approved by the Committee of Ministers, in Strasbourg, on 15 June 1999, have lost their purpose.\nArticle 38\n– Declarations related to the Convention From the date of entry into force of this Protocol, with respect to a Party having entered one or more declarations in pursuance of Article 3 of the Convention, such declaration(s) will lapse.\nArticle 39\n– Reservations No reservation may be made to the provisions of this Protocol.\nArticle 40\n– Notifications The Secretary General of the Council of Europe shall notify the member States of the Council of Europe and any other Party to the Convention of:\n(a) any signature;\n(b) the deposit of any instrument of ratification, acceptance, approval or accession;\n(c) the date of entry into force of this Protocol in accordance with Article 37;\n(d) any other act, notification or communication relating to this Protocol.\nIn witness whereof the undersigned, being duly authorised thereto, have signed this Protocol.\nDone at Strasbourg, this 10th day of October 2018, in English and in French, both texts being equally authentic, in a single copy which shall be deposited in the archives of the Council of Europe. The Secretary General of the Council of Europe shall transmit certified copies to each member State of the Council of Europe, to other Parties to the Convention and any State invited to accede to the Convention. Appendix to the Protocol: Elements for the rules of procedure of the Convention Committee\n(1) Each Party has a right to vote and shall have one vote.\n(2) A two-thirds majority of representatives of the Parties shall constitute a quorum for the meetings of the Convention Committee. In case the amending Protocol to the Convention enters into force in accordance with its Article 37 (2) before its entry into force in respect of all Contracting States to the Convention, the quorum for the meetings of the Convention Committee shall be no less than 34 Parties to the Protocol.\n(3) The decisions under Article 23 shall be taken by a four-fifths majority. The decisions pursuant to Article 23, littera h, shall be taken by a four-fifths majority, including a majority of the votes of States Parties not members of a regional integration organisation that is a Party to the Convention.\n(4) Where the Convention Committee takes decisions pursuant to Article 23, littera h, the Party concerned by the review shall not vote. Whenever such a decision concerns a matter falling within the competence of a regional integration organisation, neither the organisation nor its member States shall vote.\n(5) Decisions concerning procedural issues shall be taken by a simple majority.\n(6) Regional integration organisations, in matters within their competence, may exercise their right to vote in the Convention Committee, with a number of votes equal to the number of their member States that are Parties to the Convention. Such an organisation shall not exercise its right to vote if any of its member States exercises its right.\n(7) In case of vote, all Parties must be informed of the subject and time for the vote, as well as whether the vote will be exercised by the Parties individually or by a regional integration organisation on behalf of its member States.\n(8) The Convention Committee may further amend its rules of procedure by a two-thirds majority, except for the voting arrangements which may only be amended by unanimous vote of the Parties and to which Article 25 of the Convention applies.\n","permalink":"https://ai.intlaws.com/en/compliance/intl/coe-convention-108-plus/","summary":"Official English text of Protocol CETS No. 223, which modernises Convention 108 (the \u0026ldquo;Convention 108+\u0026rdquo;) — opened for signature in Strasbourg on 10 October 2018, comprising 40 articles: amendments to Convention 108 article by article (Articles 1–35) and final clauses (Articles 36–40). Per the Council of Europe Treaty Office, it enters into force upon ratification by all Parties to Treaty ETS 108, or, as from 11 October 2023, once 38 Parties to the Convention have ratified it.","title":"Protocol amending Convention 108"},{"content":" Version and sources (verifiable)\nItem Content Promulgated 22 March 2024 by the Cyberspace Administration of China (Order No. 16); effective on the date of promulgation Structure 14 articles Currently effective Yes (as of 2026-09-22) Chinese original https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm English version No official English translation published. This English text is a translation by our editorial team, cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Where a term has an established rendering in official translations of the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law, that rendering is used. Verification Retrieved 2026-09-22; 14 articles, correspondence with the Chinese text verified one-for-one, no gaps Article 1 These Provisions are formulated in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws and regulations, for the purposes of safeguarding data security, protecting the rights and interests of personal information, and promoting the lawful, orderly and free flow of data, and in order to govern the implementation of the data export regimes — security assessment of data export, standard contracts for the export of personal information, and personal information protection certification.\nArticle 2 Data processors shall identify and report important data in accordance with relevant provisions. Where no department or region has notified or publicly released data as important data, the data processor is not required to report it as important data for the security assessment of data export.\nArticle 3 Where data collected and generated in activities such as international trade, cross-border transportation, academic cooperation, cross-border manufacturing and marketing are provided overseas and do not contain personal information or important data, the data processor is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification.\nArticle 4 Where personal information collected and generated overseas by a data processor is transmitted into China for processing and is thereafter provided overseas again, and no personal information or important data within China was introduced in the course of processing, the data processor is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification.\nArticle 5 Where a data processor provides personal information overseas and meets any of the following conditions, it is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification:\n(1) where it is genuinely necessary to provide personal information overseas for the conclusion or performance of a contract to which the individual is a party, such as cross-border shopping, cross-border delivery, cross-border remittance, cross-border payment, cross-border account opening, air ticket and hotel booking, visa application, and examination services;\n(2) where it is genuinely necessary to provide employees\u0026rsquo; personal information overseas for the implementation of cross-border human resources management in accordance with labour rules and regulations formulated according to law and collective contracts concluded according to law;\n(3) where it is genuinely necessary to provide personal information overseas in an emergency to protect the life, health and property safety of natural persons;\n(4) where a data processor other than a critical information infrastructure operator has cumulatively provided overseas the personal information of fewer than 100,000 individuals (excluding sensitive personal information) since 1 January of the current year.\nThe personal information provided overseas referred to in the preceding paragraph does not include important data.\nArticle 6 Within the framework of the national data classification and grading protection system, a pilot free trade zone may itself formulate a list of data within the zone that is to be included in the scope of the security assessment of data export, the standard contracts for the export of personal information, and personal information protection certification (hereinafter the \u0026ldquo;negative list\u0026rdquo;), and after approval by the provincial cyberspace and informatisation commission, shall file it with the national cyberspace administration department and the national data administration department. Where a data processor within a pilot free trade zone provides overseas data that is outside the negative list, it is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification.\nArticle 7 Where a data processor provides data overseas and meets any of the following conditions, it shall, through the cyberspace administration department of the province where it is located, report to the national cyberspace administration department for the security assessment of data export:\n(1) a critical information infrastructure operator provides personal information or important data overseas;\n(2) a data processor other than a critical information infrastructure operator provides important data overseas, or has cumulatively provided overseas the personal information of more than 1,000,000 individuals (excluding sensitive personal information), or the sensitive personal information of more than 10,000 individuals, since 1 January of the current year.\nWhere any of the circumstances provided for in Articles 3, 4, 5 and 6 of these Provisions applies, those provisions shall prevail.\nArticle 8 Where a data processor other than a critical information infrastructure operator has cumulatively provided overseas the personal information of 100,000 or more but fewer than 1,000,000 individuals (excluding sensitive personal information), or the sensitive personal information of fewer than 10,000 individuals, since 1 January of the current year, it shall, in accordance with law, conclude with the overseas recipient a standard contract for the export of personal information, or obtain personal information protection certification. Where any of the circumstances provided for in Articles 3, 4, 5 and 6 of these Provisions applies, those provisions shall prevail.\nArticle 9 The result of a security assessment of data export is valid for three years, counted from the date on which the assessment result is issued. Where the validity period expires and the data processor needs to continue the data export activities and no circumstance requiring a fresh report for the security assessment of data export has occurred, the data processor may, within 60 working days before the expiry of the validity period, apply through the cyberspace administration department of the province where it is located to the national cyberspace administration department for an extension of the validity period of the assessment result. Upon approval by the national cyberspace administration department, the validity period of the assessment result may be extended by three years.\nArticle 10 Where a data processor provides personal information overseas, it shall, in accordance with laws and administrative regulations, perform obligations including informing the individual, obtaining the individual\u0026rsquo;s separate consent, and conducting a personal information protection impact assessment.\nArticle 11 Where a data processor provides data overseas, it shall comply with laws and regulations, perform its data security protection obligations, and adopt technical measures and other necessary measures to ensure the security of data export. Where a data security incident occurs or is likely to occur, it shall adopt remedial measures and promptly report to the cyberspace administration department at or above the provincial level and other competent departments.\nArticle 12 Cyberspace administration departments in all localities shall strengthen guidance and supervision over the data export activities of data processors, improve the security assessment system for data export, and optimise the assessment process; strengthen whole-chain, whole-process and all-round supervision before, during and after the event, and where data export activities present relatively high risks or a data security incident occurs, require the data processor to rectify and eliminate the hidden danger; and where the data processor refuses to rectify or causes serious consequences, pursue legal liability in accordance with law.\nArticle 13 Where relevant provisions such as the Measures for the Security Assessment of Data Export (Cyberspace Administration of China Order No. 11), promulgated on 7 July 2022, and the Measures for Standard Contracts for the Export of Personal Information (Cyberspace Administration of China Order No. 13), promulgated on 22 February 2023, are inconsistent with these Provisions, these Provisions shall prevail.\nArticle 14 These Provisions shall come into force on the date of promulgation.\nRelationship between provisions (editorial note, not part of the legal text)\nArticle 19 of the Measures provides the identification standard for \u0026ldquo;important data\u0026rdquo;; Article 2 of the 2024 Provisions and Article 37 of the Regulations make the reporting obligation conditional on notification or public designation by the regulator. The two operate as definition and procedure and do not conflict: it is the regulator, not the processor, that designates important data.\n","permalink":"https://ai.intlaws.com/en/compliance/china/data-cross-border-flow-provisions/","summary":"Full text of the Provisions on Promoting and Regulating Cross-Border Data Flows (CAC Order No. 16, promulgated and effective 22 March 2024), 14 articles: exemption scenarios, the negative-list mechanism in pilot free trade zones, the thresholds for the security assessment and the standard contract, and the three-year validity of assessment results. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).","title":"Provisions on Promoting and Regulating Cross-Border Data Flows"},{"content":" Version and sources (verifiable)\nItem Content Adopted 30 August 2024, at the 40th executive meeting of the State Council Promulgated 24 September 2024 (State Council Order No. 790, signed by Premier Li Qiang) Effective 1 January 2025 Structure 9 chapters, 64 articles Currently effective Yes (as of 2026-09-22) Chinese original State Council Order No. 790 — (the original gov.cn link is no longer reachable; this is theof the Order as republished on a government website) English version No official English translation published. This English text is a translation by our editorial team cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 64 articles, no gaps; chapter structure verified against the official text Chapter I General provisions Article 1 These Regulations are formulated in accordance with the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws, for the purposes of regulating network data processing activities, safeguarding network data security, promoting the lawful, reasonable and effective use of network data, protecting the lawful rights and interests of individuals and organisations, and maintaining national security and the public interest.\nArticle 2 These Regulations apply to network data processing activities carried out within the territory of the People\u0026rsquo;s Republic of China and to the supervision and administration of their security.\nThese Regulations also apply to activities processing, outside the territory of the People\u0026rsquo;s Republic of China, the personal information of natural persons within the territory of the People\u0026rsquo;s Republic of China, where the circumstances provided for in the second paragraph of Article 3 of the Personal Information Protection Law of the People\u0026rsquo;s Republic of China are met.\nWhere network data processing activities carried out outside the territory of the People\u0026rsquo;s Republic of China harm the national security or public interests of the People\u0026rsquo;s Republic of China or the lawful rights and interests of its citizens and organisations, legal liability shall be pursued in accordance with law.\nArticle 3 Network data security management work upholds the leadership of the Communist Party of China, implements the holistic approach to national security, and coordinates the promotion of the development and utilisation of network data with the safeguarding of network data security.\nArticle 4 The State encourages innovative applications of network data in all industries and fields, strengthens capacity-building for network data security protection, supports innovation in technologies, products and services relating to network data, carries out publicity, education and personnel training on network data security, and promotes the development and utilisation of network data and the growth of the industry.\nArticle 5 The State applies classified and graded protection to network data according to its importance in economic and social development and the degree of harm that tampering, destruction, leakage, unlawful acquisition or unlawful use would cause to national security, the public interest or the lawful rights and interests of individuals and organisations.\nArticle 6 The State actively participates in the formulation of international rules and standards relating to network data security and promotes international exchange and cooperation.\nArticle 7 The State supports relevant industry organisations in formulating, in accordance with their articles of association, norms of conduct for network data security, strengthening industry self-regulation, guiding their members in strengthening network data security protection, raising the level of network data security protection and promoting the sound development of the industry.\nChapter II General provisions Article 8 No individual or organisation may use network data to engage in illegal activities, or engage in illegal network data processing activities such as stealing or otherwise unlawfully obtaining network data, or unlawfully selling or unlawfully providing network data to others.\nNo individual or organisation may provide programs or tools specifically used for the illegal activities in the preceding paragraph; where a person knows that another is engaged in the illegal activities in the preceding paragraph, the person must not provide that other person with technical support such as internet access, server hosting, network storage or communication transmission, or assistance such as advertising promotion or payment and settlement.\nArticle 9 Network data processors shall, in accordance with laws and administrative regulations and the mandatory requirements of national standards, and on the basis of the classified protection of cybersecurity, strengthen network data security protection, establish and improve network data security management systems, adopt technical measures such as encryption, backup, access control and security authentication and other necessary measures, protect network data against tampering, destruction, leakage, unlawful acquisition or unlawful use, handle network data security incidents, prevent and combat illegal and criminal activities directed at and using network data, and bear primary responsibility for the security of the network data they process.\nArticle 10 Network products and services provided by network data processors shall comply with the mandatory requirements of relevant national standards; where risks such as security defects or vulnerabilities in network products or services are discovered, remedial measures shall be taken immediately, users shall be promptly informed as required and a report shall be made to the competent departments; where national security or the public interest is endangered, the network data processor shall also report to the competent departments within 24 hours.\nArticle 11 Network data processors shall establish and improve emergency response plans for network data security incidents; when a network data security incident occurs, they shall immediately activate the plan, take measures to prevent the expansion of harm and eliminate hidden security dangers, and report to the competent departments as required.\nWhere a network data security incident harms the lawful rights and interests of individuals or organisations, the network data processor shall promptly notify the interested parties, by telephone, short message, instant messaging tool, email or public announcement, of the incident and the risk situation, the consequences of the harm and the remedial measures already taken; where laws and administrative regulations provide that notification may be dispensed with, those provisions shall prevail. Where a network data processor discovers in the course of handling a network data security incident any leads suggesting illegality or crime, it shall report the case to the public security organ and the State security organ as required and cooperate in investigation, inquiry and handling.\nArticle 12 Where a network data processor provides or entrusts the processing of personal information and important data to another network data processor, it shall, by contract or otherwise, agree with the network data recipient on the processing purpose, method, scope and security protection obligations, and supervise the recipient\u0026rsquo;s performance of those obligations. Records of the provision or entrusted processing of personal information and important data to another network data processor shall be kept for at least three years.\nThe network data recipient shall perform network data security protection obligations and process the personal information and important data in accordance with the agreed purpose, method and scope.\nWhere two or more network data processors jointly determine the processing purpose and method of personal information and important data, they shall agree on their respective rights and obligations.\nArticle 13 Where network data processing activities carried out by a network data processor affect or may affect national security, a national security review shall be conducted in accordance with the relevant provisions of the State.\nArticle 14 Where network data needs to be transferred due to merger, division, dissolution, bankruptcy or other reasons, the network data recipient shall continue to perform the network data security protection obligations.\nArticle 15 Where a State organ entrusts another person with the construction, operation or maintenance of an e-government system or with the storage or processing of government data, it shall, in accordance with the relevant provisions of the State, go through strict approval procedures, clarify the entrusted party\u0026rsquo;s network data processing authority and protection responsibilities, and supervise the entrusted party\u0026rsquo;s performance of network data security protection obligations.\nArticle 16 Where a network data processor provides services to a State organ or an operator of critical information infrastructure, or participates in the construction, operation or maintenance of other public infrastructure or public service systems, it shall perform network data security protection obligations in accordance with laws, regulations and the contract, and provide secure, stable and continuous services.\nA network data processor referred to in the preceding paragraph must not, without the consent of the commissioning party, access, obtain, retain, use or divulge network data or provide it to others, or conduct correlation analysis of network data.\nArticle 17 Information systems providing services for State organs shall strengthen network data security management by reference to the management requirements for e-government systems, so as to safeguard network data security.\nArticle 18 Where a network data processor uses automated tools to access or collect network data, it shall assess the impact on network services, and must not unlawfully intrude into another\u0026rsquo;s network or interfere with the normal operation of network services.\nArticle 19 A network data processor providing generative artificial intelligence services shall strengthen the security management of training data and training data processing activities and take effective measures to prevent and handle network data security risks.\nArticle 20 Network data processors providing products or services to the public shall accept public supervision, establish convenient channels for complaints and reports about network data security, publish information such as the methods for making complaints and reports, and promptly accept and handle complaints and reports about network data security.\nChapter III Personal information protection Article 21 Where a network data processor informs individuals in accordance with law by formulating personal information processing rules before processing their personal information, the personal information processing rules shall be publicly displayed in a centralised manner, easy to access and placed in a prominent position, and shall be clear, specific and easy to understand, including but not limited to the following:\n(1) the name of the network data processor and its contact information;\n(2) the purpose, method and categories of the processing of personal information, the necessity of processing sensitive personal information and the impact on individual rights and interests;\n(3) the retention period of personal information and the method of handling it upon expiry; where the retention period is difficult to determine, the method for determining the retention period shall be specified;\n(4) the methods and channels for individuals to access, copy, transfer, correct, supplement or delete personal information, restrict its processing, cancel accounts and withdraw consent.\nWhere a network data processor informs individuals, in accordance with the preceding paragraph, of the purpose, method and categories of collecting personal information and providing it to other network data processors, and of the information of the network data recipient, it shall set them out in a list or other form. Where a network data processor processes the personal information of minors under the age of fourteen, it shall also formulate dedicated personal information processing rules.\nArticle 22 Where a network data processor processes personal information on the basis of individual consent, it shall comply with the following provisions:\n(1) the collection of personal information shall be necessary for providing products or services; it must not collect personal information beyond the necessary scope, and must not obtain consent by misleading, deceiving or coercing individuals;\n(2) where sensitive personal information such as biometric data, religious belief, specific identity, medical and health information, financial accounts or whereabouts is processed, the individual\u0026rsquo;s separate consent shall be obtained;\n(3) where the personal information of minors under the age of fourteen is processed, the consent of the minors\u0026rsquo; parents or other guardians shall be obtained;\n(4) personal information must not be processed beyond the purpose, method, categories and retention period consented to by the individual;\n(5) where an individual has clearly expressed that he or she does not consent to the processing of his or her personal information, consent must not be sought frequently;\n(6) where the purpose, method or categories of processing of personal information change, the individual\u0026rsquo;s consent shall be obtained anew.\nWhere laws and administrative regulations provide that written consent shall be obtained for the processing of sensitive personal information, those provisions shall prevail.\nArticle 23 Where an individual requests access to, a copy of, correction, supplementation or deletion of, or restriction on the processing of his or her personal information, or cancels an account or withdraws consent, the network data processor shall promptly accept the request and provide convenient methods and channels to support the individual\u0026rsquo;s exercise of rights, and must not impose unreasonable conditions to restrict the individual\u0026rsquo;s reasonable requests.\nArticle 24 Where non-essential personal information or personal information for which individual consent has not been lawfully obtained is inevitably collected through the use of automated collection technology, or where an individual cancels an account, the network data processor shall delete the personal information or anonymise it. Where the retention period provided for by laws and administrative regulations has not expired, or where deletion or anonymisation of personal information is technically difficult to achieve, the network data processor shall stop processing other than storage and the taking of necessary security protection measures.\nArticle 25 For a request to transfer personal information that meets the following conditions, the network data processor shall provide a channel for other network data processors designated by the individual to access and obtain the relevant personal information:\n(1) the true identity of the requesting person can be verified;\n(2) what is requested to be transferred is personal information provided with the individual\u0026rsquo;s consent or collected on the basis of a contract;\n(3) the transfer of the personal information is technically feasible;\n(4) the transfer of the personal information does not harm the lawful rights and interests of others.\nWhere the number of requests to transfer personal information clearly exceeds a reasonable range, the network data processor may charge a necessary fee based on the cost of transferring the personal information.\nArticle 26 Where a network data processor outside the territory of the People\u0026rsquo;s Republic of China processes the personal information of natural persons within the territory and, in accordance with Article 53 of the Personal Information Protection Law of the People\u0026rsquo;s Republic of China, establishes a dedicated institution or designates a representative within the territory, it shall report the name of the institution or the name and contact information of the representative to the cyberspace administration department of the city with districts where it is located; the cyberspace administration department shall promptly notify the relevant competent departments at the same level.\nArticle 27 Network data processors shall, periodically and by themselves or by engaging a professional institution, conduct compliance audits of their processing of personal information for compliance with laws and administrative regulations.\nArticle 28 A network data processor that processes the personal information of 10 million or more individuals shall also comply with the provisions of Articles 30 and 32 of these Regulations applicable to network data processors processing important data (hereinafter \u0026ldquo;processors of important data\u0026rdquo;).\nChapter IV Important data security Article 29 The national data security work coordinating mechanism shall coordinate the relevant departments in formulating a catalogue of important data and shall strengthen the protection of important data. All regions and departments shall, in accordance with the classified and graded protection system for data, determine the specific catalogues of important data for their region, department and relevant industries and fields, and apply key protection to the network data included in the catalogues.\nNetwork data processors shall identify and report important data in accordance with the relevant provisions of the State. Where data is confirmed to be important data, the relevant region or department shall promptly inform the network data processor or make it public. The network data processor shall perform its network data security protection responsibilities.\nThe State encourages network data processors to use technologies and products such as data labelling to improve the level of important data security management.\nArticle 30 A processor of important data shall designate a person responsible for network data security and a network data security management body. The network data security management body shall perform the following network data security protection responsibilities:\n(1) formulate and implement network data security management systems, operating procedures and emergency response plans for network data security incidents;\n(2) periodically organise network data security risk monitoring, risk assessment, emergency drills and publicity, education and training activities, and promptly handle network data security risks and incidents;\n(3) accept and handle complaints and reports about network data security.\nThe person responsible for network data security shall have professional knowledge of network data security and relevant management experience, shall be a member of the management of the network data processor, and shall have the authority to report network data security situations directly to the competent departments.\nA network data processor that controls important data of the specific categories and scale prescribed by the competent departments shall conduct security background checks on the person responsible for network data security and personnel in key positions and strengthen the training of the relevant personnel. In conducting the checks, it may apply to the public security organ and the State security organ for assistance.\nArticle 31 A processor of important data shall, before providing, entrusting the processing of, or jointly processing important data, conduct a risk assessment, except where this is for the performance of statutory duties or legal obligations.\nThe risk assessment shall focus on the following:\n(1) whether providing, entrusting the processing of or jointly processing network data, and the purpose, method and scope of the network data recipient\u0026rsquo;s processing of network data, are lawful, legitimate and necessary;\n(2) the risk of the network data provided, entrusted for processing or jointly processed being tampered with, destroyed, leaked or unlawfully acquired or used, and the risks to national security, the public interest or the lawful rights and interests of individuals and organisations;\n(3) the integrity and law-abiding conduct of the network data recipient;\n(4) whether the network data security requirements in the relevant contracts concluded or to be concluded with the network data recipient can effectively bind the recipient to perform its network data security protection obligations;\n(5) whether the technical and management measures taken or to be taken can effectively prevent risks such as the network data being tampered with, destroyed, leaked or unlawfully acquired or used;\n(6) other assessment contents prescribed by the competent departments.\nArticle 32 Where a processor of important data may affect the security of important data due to merger, division, dissolution, bankruptcy or other reasons, it shall take measures to safeguard network data security and report to the relevant competent departments at or above the provincial level the disposal plan for the important data and the name and contact information of the recipient; where the competent department is unclear, it shall report to the data security work coordinating mechanism at or above the provincial level.\nArticle 33 A processor of important data shall conduct a risk assessment of its network data processing activities each year and submit a risk assessment report to the relevant competent departments at or above the provincial level, and the relevant competent departments shall promptly notify the cyberspace administration departments and public security organs at the same level.\nThe risk assessment report shall include the following:\n(1) basic information on the network data processor, information on the network data security management body, and the name and contact information of the person responsible for network data security;\n(2) the purpose, categories, quantity, method, scope, storage period and storage location of the processing of important data, and the situation of network data processing activities, excluding the content of the network data itself;\n(3) the network data security management system and its implementation, and technical measures such as encryption, backup, labelling, access control and security authentication, other necessary measures and their effectiveness;\n(4) network data security risks discovered, and network data security incidents that occurred and their handling;\n(5) the risk assessment of providing, entrusting the processing of, or jointly processing important data;\n(6) the situation of network data cross-border transfer;\n(7) other report contents prescribed by the competent departments.\nA large online platform service provider processing important data shall, in addition to the contents in the preceding paragraph, fully explain the network data security situation of its key business and supply chain in its risk assessment report.\nWhere the processing activities of important data by a processor of important data may endanger national security, the relevant competent departments at or above the provincial level shall order it to take measures such as rectification or to stop processing important data. The processor of important data shall immediately take measures in accordance with the relevant requirements.\nChapter V Security administration of cross-border network data transfer Article 34 The national cyberspace administration department shall coordinate the relevant departments in establishing a special working mechanism for national data export security administration, studying and formulating national policies for the security administration of network data export, and coordinating the handling of major matters concerning network data export security.\nArticle 35 A network data processor may provide personal information abroad where one of the following conditions is met:\n(1) it has passed a data export security assessment organised by the national cyberspace administration department;\n(2) it has obtained personal information protection certification from a professional institution in accordance with the provisions of the national cyberspace administration department;\n(3) it complies with the provisions on standard contracts for the export of personal information formulated by the national cyberspace administration department;\n(4) it is truly necessary to provide personal information abroad for the conclusion or performance of a contract to which the individual is a party;\n(5) it is truly necessary to provide employees\u0026rsquo; personal information abroad for cross-border human resources management implemented in accordance with lawfully formulated labour rules and lawfully concluded collective contracts;\n(6) it is truly necessary to provide personal information abroad for the performance of statutory duties or legal obligations;\n(7) it is truly necessary to provide personal information abroad in an emergency to protect the life, health and property safety of natural persons;\n(8) other conditions provided for by laws, administrative regulations or the national cyberspace administration department.\nArticle 36 Where international treaties or agreements concluded or acceded to by the People\u0026rsquo;s Republic of China provide for the conditions for providing personal information outside the territory of the People\u0026rsquo;s Republic of China, those provisions may be followed.\nArticle 37 Where important data collected and generated by a network data processor in the course of its operations within the territory of the People\u0026rsquo;s Republic of China is truly necessary to be provided abroad, it shall pass a data export security assessment organised by the national cyberspace administration department. Where a network data processor has identified and reported important data in accordance with the relevant provisions of the State but has not been informed or publicly notified by the relevant region or department that the data is important data, it need not report it as important data for the data export security assessment.\nArticle 38 After passing a data export security assessment, a network data processor providing personal information and important data abroad must not exceed the purpose, method, scope, categories and scale of data export specified in the assessment.\nArticle 39 The State takes measures to prevent and handle network data cross-border security risks and threats. No individual or organisation may provide programs or tools specifically used to destroy or circumvent technical measures; where a person knows that another is engaged in activities such as destroying or circumventing technical measures, the person must not provide technical support or assistance to that other person.\nChapter VI Obligations of online platform service providers Article 40 Online platform service providers shall, through platform rules or contracts, clarify the network data security protection obligations of third-party product and service providers accessing their platforms, and urge third-party product and service providers to strengthen network data security management.\nThe preceding paragraph applies to producers of devices such as smart terminals with pre-installed applications.\nWhere a third-party product or service provider carries out network data processing activities in violation of laws and administrative regulations, platform rules or contractual agreements and causes harm to users, the online platform service provider, the third-party product or service provider and the producer of devices such as smart terminals with pre-installed applications shall bear corresponding liability in accordance with law.\nThe State encourages insurance companies to develop insurance products covering liability for damage caused by network data and encourages online platform service providers and producers of devices such as smart terminals with pre-installed applications to take out such insurance.\nArticle 41 An online platform service provider providing application distribution services shall establish verification rules for applications and carry out verification relating to network data security. Where it discovers that an application to be distributed or already distributed does not comply with laws and administrative regulations or the mandatory requirements of national standards, it shall take measures such as issuing a warning, refusing distribution, suspending distribution or terminating distribution.\nArticle 42 Where an online platform service provider pushes information to individuals through automated decision-making, it shall provide an easy-to-understand, easy-to-access and easy-to-operate option to turn off personalised recommendations, and provide users with functions such as refusing to receive pushed information and deleting user tags targeting their personal characteristics.\nArticle 43 The State promotes the building of a national public service for online identity authentication, which is promoted and applied on the principle of government guidance and user voluntariness.\nOnline platform service providers are encouraged to support users in using the national public service for online identity authentication to register and verify their true identity information.\nArticle 44 Large online platform service providers shall publish an annual social responsibility report on personal information protection, covering, among other things, personal information protection measures and their results, the handling of applications for individuals to exercise their rights, and the performance of duties by the personal information protection supervision body composed mainly of external members.\nArticle 45 Where a large online platform service provider provides network data across borders, it shall comply with the State\u0026rsquo;s requirements for the security administration of cross-border data, improve the relevant technical and management measures, and prevent network data cross-border security risks.\nArticle 46 A large online platform service provider must not use network data, algorithms or platform rules to engage in the following activities:\n(1) processing the network data generated by users on the platform by misleading, deceiving or coercing users;\n(2) restricting users\u0026rsquo; access to or use of the network data generated by them on the platform without justified reasons;\n(3) applying unreasonable differential treatment to users, harming users\u0026rsquo; lawful rights and interests;\n(4) other activities prohibited by laws and administrative regulations.\nChapter VII Supervision and administration Article 47 The national cyberspace administration department is responsible for coordinating network data security and the related supervision and administration.\nPublic security organs and State security organs shall, in accordance with the provisions of relevant laws and administrative regulations and these Regulations, assume network data security supervision and administration duties within the scope of their respective duties, and prevent and combat illegal and criminal activities endangering network data security in accordance with law.\nThe national data management department shall perform the corresponding network data security duties in the specific work of data management.\nAll regions and departments are responsible for the network data collected and generated in the work of their region or department and for the security of that network data.\nArticle 48 The relevant competent departments shall assume network data security supervision and administration duties for their respective industries and fields, designate the bodies responsible for network data security protection in their respective industries and fields, coordinate the formulation and organisation of the implementation of emergency response plans for network data security incidents in their respective industries and fields, periodically organise network data security risk assessments in their respective industries and fields, supervise and inspect the performance by network data processors of their network data security protection obligations, and guide and urge network data processors to promptly rectify existing risks and hidden dangers.\nArticle 49 The national cyberspace administration department shall coordinate the relevant competent departments in promptly compiling, assessing, sharing and publishing information related to network data security risks, and in strengthening the sharing of network data security information, the monitoring and early warning of network data security risks and threats, and the emergency handling of network data security incidents.\nArticle 50 The relevant competent departments may take the following measures to supervise and inspect network data security:\n(1) require network data processors and the relevant personnel to explain matters relating to the supervision and inspection;\n(2) consult and copy documents and records relating to network data security;\n(3) inspect the operation of network data security measures;\n(4) inspect equipment and articles relating to network data processing activities;\n(5) other necessary measures provided for by laws and administrative regulations.\nNetwork data processors shall cooperate with the network data security supervision and inspection carried out by the relevant competent departments in accordance with law.\nArticle 51 In carrying out network data security supervision and inspection, the relevant competent departments shall be objective and impartial and must not charge fees to the entities inspected.\nIn network data security supervision and inspection, the relevant competent departments must not access or collect business information unrelated to network data security, and the information obtained may only be used for the needs of maintaining network data security and must not be used for other purposes.\nWhere the relevant competent departments discover that a network data processor\u0026rsquo;s network data processing activities involve relatively serious security risks, they may, in accordance with the prescribed powers and procedures, require the network data processor to suspend the relevant services, revise platform rules, improve technical measures, etc. so as to eliminate hidden dangers to network data security.\nArticle 52 In carrying out network data security supervision and inspection, the relevant competent departments shall strengthen coordination and information communication, reasonably determine the frequency and methods of inspection, and avoid unnecessary inspections and duplicative overlapping inspections.\nPersonal information protection compliance audits, important data risk assessments, important data export security assessments and the like shall be better connected so as to avoid duplicative assessment and auditing. Where the contents of an important data risk assessment and a cybersecurity classified protection evaluation overlap, the relevant results may be mutually accepted.\nArticle 53 The relevant competent departments and their staff shall, in accordance with law, keep confidential the personal privacy, personal information, trade secrets and confidential business information and other network data learned in the performance of their duties, and must not divulge them or unlawfully provide them to others.\nArticle 54 Where an organisation or individual outside the territory engages in network data processing activities that endanger the national security or public interest of the People\u0026rsquo;s Republic of China, or infringe the personal information rights and interests of citizens of the People\u0026rsquo;s Republic of China, the national cyberspace administration department, together with the relevant competent departments, may take corresponding necessary measures in accordance with law.\nChapter VIII Legal liability Article 55 Where the provisions of Articles 12, 16 to 20, 22, the first and second paragraphs of Article 40, Article 41 and Article 42 of these Regulations are violated, the competent departments for cyberspace administration, telecommunications and public security shall, in accordance with their respective duties, order correction, give a warning and confiscate the unlawful gains; where the offender refuses to correct or the circumstances are serious, a fine of not more than RMB 1,000,000 shall be imposed, and the competent departments may order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence, and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.\nArticle 56 Where Article 13 of these Regulations is violated, the competent departments for cyberspace administration, telecommunications, public security and State security shall, in accordance with their respective duties, order correction, give a warning and may concurrently impose a fine of not less than RMB 100,000 and not more than RMB 1,000,000, and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons; where the offender refuses to correct or the circumstances are serious, a fine of not less than RMB 1,000,000 and not more than RMB 10,000,000 shall be imposed, and the competent departments may order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 100,000 and not more than RMB 1,000,000 on the directly responsible persons in charge and other directly responsible persons.\nArticle 57 Where the second paragraph of Article 29, the second and third paragraphs of Article 30, Article 31 or Article 32 of these Regulations are violated, the competent departments for cyberspace administration, telecommunications and public security shall, in accordance with their respective duties, order correction, give a warning and may concurrently impose a fine of not less than RMB 50,000 and not more than RMB 500,000, and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons; where the offender refuses to correct or causes serious consequences such as the leakage of a large volume of data, a fine of not less than RMB 500,000 and not more than RMB 2,000,000 shall be imposed, and the competent departments may order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 50,000 and not more than RMB 200,000 on the directly responsible persons in charge and other directly responsible persons.\nArticle 58 Where other relevant provisions of these Regulations are violated, the relevant competent departments shall pursue legal liability in accordance with the relevant provisions of the Cybersecurity Law of the People\u0026rsquo;s Republic of China, the Data Security Law of the People\u0026rsquo;s Republic of China, the Personal Information Protection Law of the People\u0026rsquo;s Republic of China and other laws.\nArticle 59 Where a network data processor voluntarily eliminates or mitigates the harmful consequences of an unlawful act, or the unlawful act is minor and promptly corrected without causing harmful consequences, or it is a first violation with minor harmful consequences that is promptly corrected, a mitigated or reduced administrative penalty shall be imposed or no administrative penalty shall be imposed in accordance with the provisions of the Administrative Penalty Law of the People\u0026rsquo;s Republic of China.\nArticle 60 Where a State organ fails to perform the network data security protection obligations provided for in these Regulations, its superior authority or the relevant competent department shall order it to correct; the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.\nArticle 61 Where a violation of these Regulations causes damage to another person, civil liability shall be borne in accordance with law; where the act constitutes a violation of public security administration, a public security administration penalty shall be imposed in accordance with law; where a crime is constituted, criminal liability shall be pursued in accordance with law.\nChapter IX Supplementary provisions Article 62 For the purposes of these Regulations, the following terms have the meanings set out below:\n(1) \u0026ldquo;network data\u0026rdquo; means various electronic data processed and generated through networks;\n(2) \u0026ldquo;network data processing activities\u0026rdquo; means activities such as the collection, storage, use, processing, transmission, provision, disclosure and deletion of network data;\n(3) \u0026ldquo;network data processor\u0026rdquo; means an individual or organisation that independently determines the processing purpose and processing method in network data processing activities;\n(4) \u0026ldquo;important data\u0026rdquo; means data in a specific field, for a specific group or in a specific region, or of a certain precision and scale, which, once tampered with, destroyed, leaked, or unlawfully acquired or used, may directly endanger national security, economic operation, social stability, or public health and safety;\n(5) \u0026ldquo;entrusted processing\u0026rdquo; means network data processing activities carried out by an individual or organisation entrusted by a network data processor in accordance with the agreed purpose and method;\n(6) \u0026ldquo;joint processing\u0026rdquo; means network data processing activities in which two or more network data processors jointly determine the processing purpose and processing method of network data;\n(7) \u0026ldquo;separate consent\u0026rdquo; means a specific and explicit consent specially given by an individual for specific processing of his or her personal information;\n(8) \u0026ldquo;large online platform\u0026rdquo; means an online platform with more than 50 million registered users or more than 10 million monthly active users, with complex business types, whose network data processing activities have an important impact on national security, economic operation, the national economy and people\u0026rsquo;s livelihood.\nArticle 63 Network data processing activities involving core data shall be carried out in accordance with the relevant provisions of the State.\nThese Regulations do not apply to natural persons processing personal information for personal or family affairs.\nNetwork data processing activities involving State secrets or work secrets shall be governed by the provisions of laws and administrative regulations such as the Law of the People\u0026rsquo;s Republic of China on Guarding State Secrets.\nArticle 64 These Regulations shall come into force on 1 January 2025.\n","permalink":"https://ai.intlaws.com/en/compliance/china/network-data-security-regulations/","summary":"Full text of the Regulations on the Administration of Network Data Security (State Council Order No. 790, promulgated 24 September 2024, effective 1 January 2025), 64 articles in nine chapters: classified and graded protection, personal information processing rules, important data (security officer, annual risk assessment), cross-border transfer (assessment, certification, standard contract), obligations of large online platforms, supervision, and penalties of up to RMB 10 million. English translation by our editorial team (non-official).","title":"Regulations on the Administration of Network Data Security"},{"content":" Version and sources (verifiable)\nItem Content Instrument HB 149 (89th Texas Legislature) — the Texas Responsible Artificial Intelligence Governance Act (\u0026quot;TRAIGA\u0026quot;) Enacted text creates Business \u0026amp; Commerce Code Chapters 551–554; this page reproduces Chapter 552 (Artificial Intelligence Protection) in full Effective 1 January 2026 (per the enrolled act\u0026rsquo;s effective-date provision) Structure Chapter 552: 16 sections (552.001–552.003 general; 552.051–552.057 protections; 552.101–552.106 enforcement) Official text Enrolled bill text (HB 149) ｜ codified chapter Scope note This page covers Chapter 552 only. The same act also creates Chapter 551 (general provisions), Chapter 553 (AI regulatory sandbox programme) and Chapter 554 (Texas Artificial Intelligence Council) — those chapters are not reproduced here. Chinese version No official Chinese text. A Chinese translation by our editorial team, marked non-official, is available → 中文全文 Retrieval \u0026amp; verification Retrieved 2026-09-22 from the enrolled bill text published by the Texas Legislature; section numbering (552.001–552.106) and subsection markers checked against the published text. CHAPTER 552. ARTIFICIAL INTELLIGENCE PROTECTION SUBCHAPTER A. GENERAL PROVISIONS\nSec. 552.001. DEFINITIONS. In this chapter:\n(1) \u0026ldquo;Deployer\u0026rdquo; means a person who deploys an\nartificial intelligence system for use in this state.\n(2) \u0026ldquo;Developer\u0026rdquo; means a person who develops an\nartificial intelligence system that is offered, sold, leased,\ngiven, or otherwise provided in this state.\n(3) \u0026ldquo;Governmental entity\u0026rdquo; means any department,\ncommission, board, office, authority, or other administrative unit\nof this state or of any political subdivision of this state, that\nexercises governmental functions under the authority of the laws of\nthis state. The term does not include:\n(A) a hospital district created under the Health\nand Safety Code or Article IX, Texas Constitution; or\n(B) an institution of higher education, as\ndefined by Section 61.003, Education Code, including any university\nsystem or any component institution of the system.\nSec. 552.002. CONSTRUCTION OF CHAPTER. This chapter may\nnot be construed to:\n(1) impose a requirement on a person that adversely\naffects the rights or freedoms of any person, including the right of\nfree speech; or\n(2) authorize any department or agency other than the\nDepartment of Insurance to regulate or oversee the business of\ninsurance.\nSec. 552.003. LOCAL PREEMPTION. This chapter supersedes\nand preempts any ordinance, resolution, rule, or other regulation\nadopted by a political subdivision regarding the use of artificial\nintelligence systems.\nSUBCHAPTER B. DUTIES AND PROHIBITIONS ON USE OF ARTIFICIAL\nINTELLIGENCE\nSec. 552.051. DISCLOSURE TO CONSUMERS.\n(a) In this\nsection, \u0026ldquo;health care services\u0026rdquo; means services related to human\nhealth or to the diagnosis, prevention, or treatment of a human\ndisease or impairment provided by an individual licensed,\nregistered, or certified under applicable state or federal law to\nprovide those services.\n(b) A governmental agency that makes available an\nartificial intelligence system intended to interact with consumers\nshall disclose to each consumer, before or at the time of\ninteraction, that the consumer is interacting with an artificial\nintelligence system.\n(c) A person is required to make the disclosure under\nSubsection\n(b) regardless of whether it would be obvious to a\nreasonable consumer that the consumer is interacting with an\nartificial intelligence system.\n(d) A disclosure under Subsection (b):\n(1) must be clear and conspicuous;\n(2) must be written in plain language; and\n(3) may not use a dark pattern, as that term is defined\nby Section 541.001.\n(e) A disclosure under Subsection\n(b) may be provided by\nusing a hyperlink to direct a consumer to a separate Internet web\npage.\n(f) If an artificial intelligence system is used in relation\nto health care service or treatment, the provider of the service or\ntreatment shall provide the disclosure under Subsection\n(b) to the\nrecipient of the service or treatment or the recipient\u0026rsquo;s personal\nrepresentative not later than the date the service or treatment is\nfirst provided, except in the case of emergency, in which case the\nprovider shall provide the required disclosure as soon as\nreasonably possible.\nSec. 552.052. MANIPULATION OF HUMAN BEHAVIOR. A person may\nnot develop or deploy an artificial intelligence system in a manner\nthat intentionally aims to incite or encourage a person to:\n(1) commit physical self-harm, including suicide;\n(2) harm another person; or\n(3) engage in criminal activity.\nSec. 552.053. SOCIAL SCORING. A governmental entity may\nnot use or deploy an artificial intelligence system that evaluates\nor classifies a natural person or group of natural persons based on\nsocial behavior or personal characteristics, whether known,\ninferred, or predicted, with the intent to calculate or assign a\nsocial score or similar categorical estimation or valuation of the\nperson or group of persons that results or may result in:\n(1) detrimental or unfavorable treatment of a person\nor group of persons in a social context unrelated to the context in\nwhich the behavior or characteristics were observed or noted;\n(2) detrimental or unfavorable treatment of a person\nor group of persons that is unjustified or disproportionate to the\nnature or gravity of the observed or noted behavior or\ncharacteristics; or\n(3) the infringement of any right guaranteed under the\nUnited States Constitution, the Texas Constitution, or state or\nfederal law.\nSec. 552.054. CAPTURE OF BIOMETRIC DATA.\n(a) In this\nsection, \u0026ldquo;biometric data\u0026rdquo; means data generated by automatic\nmeasurements of an individual\u0026rsquo;s biological characteristics. The\nterm includes a fingerprint, voiceprint, eye retina or iris, or\nother unique biological pattern or characteristic that is used to\nidentify a specific individual. The term does not include a\nphysical or digital photograph or data generated from a physical or\ndigital photograph, a video or audio recording or data generated\nfrom a video or audio recording, or information collected, used, or\nstored for health care treatment, payment, or operations under the\nHealth Insurance Portability and Accountability Act of 1996 (42\nU.S.C. Section 1320d et seq.).\n(b) A governmental entity may not develop or deploy an\nartificial intelligence system for the purpose of uniquely\nidentifying a specific individual using biometric data or the\ntargeted or untargeted gathering of images or other media from the\nInternet or any other publicly available source without the\nindividual\u0026rsquo;s consent, if the gathering would infringe on any right\nof the individual under the United States Constitution, the Texas\nConstitution, or state or federal law.\n(c) A violation of Section 503.001 is a violation of this\nsection.\nSec. 552.055. CONSTITUTIONAL PROTECTION.\n(a) A person may\nnot develop or deploy an artificial intelligence system with the\nsole intent for the artificial intelligence system to infringe,\nrestrict, or otherwise impair an individual\u0026rsquo;s rights guaranteed\nunder the United States Constitution.\n(b) This section is remedial in purpose and may not be\nconstrued to create or expand any right guaranteed by the United\nStates Constitution.\nSec. 552.056. UNLAWFUL DISCRIMINATION.\n(a) In this\nsection:\n(1) \u0026ldquo;Financial institution\u0026rdquo; has the meaning assigned\nby Section 201.101, Finance Code.\n(2) \u0026ldquo;Insurance entity\u0026rdquo; means:\n(A) an entity described by Section 82.002(a),\nInsurance Code;\n(B) a fraternal benefit society regulated under\nChapter 885, Insurance Code; or\n(C) the developer of an artificial intelligence\nsystem used by an entity described by Paragraph (A) or (B).\n(3) \u0026ldquo;Protected class\u0026rdquo; means a group or class of\npersons with a characteristic, quality, belief, or status protected\nfrom discrimination by state or federal civil rights laws, and\nincludes race, color, national origin, sex, age, religion, or\ndisability.\n(b) A person may not develop or deploy an artificial\nintelligence system with the intent to unlawfully discriminate\nagainst a protected class in violation of state or federal law.\n(c) For purposes of this section, a disparate impact is not\nsufficient by itself to demonstrate an intent to discriminate.\n(d) This section does not apply to an insurance entity for\npurposes of providing insurance services if the entity is subject\nto applicable statutes regulating unfair discrimination, unfair\nmethods of competition, or unfair or deceptive acts or practices\nrelated to the business of insurance.\n(e) A federally insured financial institution is considered\nto be in compliance with this section if the institution complies\nwith all federal and state banking laws and regulations.\nSec. 552.057. CERTAIN SEXUALLY EXPLICIT CONTENT AND CHILD\nPORNOGRAPHY. A person may not:\n(1) develop or distribute an artificial intelligence\nsystem with the sole intent of producing, assisting or aiding in\nproducing, or distributing:\n(A) visual material in violation of Section\n43.26, Penal Code; or\n(B) deep fake videos or images in violation of\nSection 21.165, Penal Code; or\n(2) intentionally develop or distribute an artificial\nintelligence system that engages in text-based conversations that\nsimulate or describe sexual conduct, as that term is defined by\nSection 43.25, Penal Code, while impersonating or imitating a child\nyounger than 18 years of age.\nSUBCHAPTER C. ENFORCEMENT\nSec. 552.101. ENFORCEMENT AUTHORITY.\n(a) The attorney\ngeneral has exclusive authority to enforce this chapter, except to\nthe extent provided by Section 552.106.\n(b) This chapter does not provide a basis for, and is not\nsubject to, a private right of action for a violation of this\nchapter or any other law.\nSec. 552.102. INFORMATION AND COMPLAINTS. The attorney\ngeneral shall create and maintain an online mechanism on the\nattorney general\u0026rsquo;s Internet website through which a consumer may\nsubmit a complaint under this chapter to the attorney general.\nSec. 552.103. INVESTIGATIVE AUTHORITY.\n(a) If the\nattorney general receives a complaint through the online mechanism\nunder Section 552.102 alleging a violation of this chapter, the\nattorney general may issue a civil investigative demand to\ndetermine if a violation has occurred. The attorney general shall\nissue demands in accordance with and under the procedures\nestablished under Section 15.10.\n(b) The attorney general may request from the person\nreported through the online mechanism, pursuant to a civil\ninvestigative demand issued under Subsection (a):\n(1) a high-level description of the purpose, intended\nuse, deployment context, and associated benefits of the artificial\nintelligence system with which the person is affiliated;\n(2) a description of the type of data used to program\nor train the artificial intelligence system;\n(3) a high-level description of the categories of data\nprocessed as inputs for the artificial intelligence system;\n(4) a high-level description of the outputs produced\nby the artificial intelligence system;\n(5) any metrics the person uses to evaluate the\nperformance of the artificial intelligence system;\n(6) any known limitations of the artificial\nintelligence system;\n(7) a high-level description of the post-deployment\nmonitoring and user safeguards the person uses for the artificial\nintelligence system, including, if the person is a deployer, the\noversight, use, and learning process established by the person to\naddress issues arising from the system\u0026rsquo;s deployment; or\n(8) any other relevant documentation reasonably\nnecessary for the attorney general to conduct an investigation\nunder this section.\nSec. 552.104. NOTICE OF VIOLATION; OPPORTUNITY TO CURE\n(a) If the attorney general determines that a person has violated\nor is violating this chapter, the attorney general shall notify the\nperson in writing of the determination, identifying the specific\nprovisions of this chapter the attorney general alleges have been\nor are being violated.\n(b) The attorney general may not bring an action against the\nperson:\n(1) before the 60th day after the date the attorney\ngeneral provides the notice under Subsection (a); or\n(2) if, before the 60th day after the date the attorney\ngeneral provides the notice under Subsection (a), the person:\n(A) cures the identified violation; and\n(B) provides the attorney general with a written\nstatement that the person has:\n(i) cured the alleged violation;\n(ii) provided supporting documentation to\nshow the manner in which the person cured the violation; and\n(iii) made any necessary changes to\ninternal policies to reasonably prevent further violation of this\nchapter.\nSec. 552.105. CIVIL PENALTY; INJUNCTION.\n(a) A person who\nviolates this chapter and does not cure the violation under Section\n552.104 is liable to this state for a civil penalty in an amount of:\n(1) for each violation the court determines to be\ncurable or a breach of a statement submitted to the attorney general\nunder Section 552.104(b)(2), not less than $10,000 and not more\nthan $12,000;\n(2) for each violation the court determines to be\nuncurable, not less than $80,000 and not more than $200,000; and\n(3) for a continued violation, not less than $2,000\nand not more than $40,000 for each day the violation continues.\n(b) The attorney general may bring an action in the name of\nthis state to:\n(1) collect a civil penalty under this section;\n(2) seek injunctive relief against further violation\nof this chapter; and\n(3) recover attorney\u0026rsquo;s fees and reasonable court costs\nor other investigative expenses.\n(c) There is a rebuttable presumption that a person used\nreasonable care as required under this chapter.\n(d) A defendant in an action under this section may seek an\nexpedited hearing or other process, including a request for\ndeclaratory judgment, if the person believes in good faith that the\nperson has not violated this chapter.\n(e) A defendant in an action under this section may not be\nfound liable if:\n(1) another person uses the artificial intelligence\nsystem affiliated with the defendant in a manner prohibited by this\nchapter; or\n(2) the defendant discovers a violation of this\nchapter through:\n(A) feedback from a developer, deployer, or other\nperson who believes a violation has occurred;\n(B) testing, including adversarial testing or\nred-team testing;\n(C) following guidelines set by applicable state\nagencies; or\n(D) if the defendant substantially complies with\nthe most recent version of the \u0026ldquo;Artificial Intelligence Risk\nManagement Framework: Generative Artificial Intelligence Profile\u0026rdquo;\npublished by the National Institute of Standards and Technology or\nanother nationally or internationally recognized risk management\nframework for artificial intelligence systems, an internal review\nprocess.\n(f) The attorney general may not bring an action to collect\na civil penalty under this section against a person for an\nartificial intelligence system that has not been deployed.\nSec. 552.106. ENFORCEMENT ACTIONS BY STATE AGENCIES.\n(a) A\nstate agency may impose sanctions against a person licensed,\nregistered, or certified by that agency for a violation of\nSubchapter B if:\n(1) the person has been found in violation of this\nchapter under Section 552.105; and\n(2) the attorney general has recommended additional\nenforcement by the applicable agency.\n(b) Sanctions under this section may include:\n(1) suspension, probation, or revocation of a license,\nregistration, certificate, or other authorization to engage in an\nactivity; and\n(2) a monetary penalty not to exceed $100,000.\n","permalink":"https://ai.intlaws.com/en/compliance/us/texas-traiga-chapter-552/","summary":"Official text of Chapter 552 (Artificial Intelligence Protection) of the Texas Business \u0026amp; Commerce Code, enacted by HB 149 — the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), effective 1 January 2026. Sixteen sections: definitions, construction, local preemption, disclosure to consumers, prohibition of manipulation of human behaviour, social scoring (governmental entities only), capture of biometric data, constitutional protection, unlawful discrimination, sexually explicit content and child protection, and enforcement by the attorney general (investigations, notice and cure, civil penalties, injunctions).","title":"Texas Artificial Intelligence Protection Act"},{"content":" Version and sources (verifiable)\nItem Content Adopted 24 December 2024 by UNGA resolution 79/243; contained in the annex Structure Preamble + 9 chapters, 68 articles Entry into force Article 65: ninetieth day after deposit of the fortieth instrument of ratification, acceptance, approval or accession (verified from the official text) Status Not yet in force (as of 2026-09-22; see UN Treaty Collection https://treaties.un.org ) English source UNODC: https://www.unodc.org/unodc/en/cybercrime/convention/text/convention-full-text.html ; official document A/RES/79/243 (English): https://documents.un.org/api/symbol/access?s=A%2FRES%2F79%2F243\u0026amp;l=en\u0026amp;t=pdf Verification Retrieved 2026-09-22; 68 articles correspond one-for-one with the Chinese official text; the Article 47 heading (missing from the UN PDF text layer) was restored from the official UNODC HTML text and cross-checked against the Chinese official text Chapter I: General provisions Article 1 Statement of purpose\nThe purposes of this Convention are to:\n(a) Promote and strengthen measures to prevent and combat cybercrime more efficiently and effectively;\n(b) Promote, facilitate and strengthen international cooperation in preventing and combating cybercrime; and\n(c) Promote, facilitate and support technical assistance and capacity-building to prevent and combat cybercrime, in particular for the benefit of developing countries.\nArticle 2 Use of terms\nFor the purposes of this Convention:\n(a) “Information and communications technology system” shall mean any device or group of interconnected or related devices, one or more of which, pursuant to a program, gathers, stores and performs automatic processing of electronic data;\n(b) “Electronic data” shall mean any representation of facts, information or concepts in a form suitable for processing in an information and communications technology system, including a program suitable to cause an information and communications technology system to perform a function;\n(c) “Traffic data” shall mean any electronic data relating to a communication by means of an information and communications technology system, generated by an information and communications technology system that formed a part in the chain of communication, indicating the communication’s origin, destination, route, time, date, size, duration or type of underlying service;\n(d) “Content data” shall mean any electronic data, other than subscriber information or traffic data, relating to the substance of the data transferred by an information and communications technology system, including, but not limited to, images, text messages, voice messages, audio recordings and video recordings;\n(e) “Service provider” shall mean any public or private entity that:\n(f) “Subscriber information” shall mean any information that is held by a service provider, relating to subscribers of its services other than traffic or content data and by which can be established:\n(g) “Personal data” shall mean any information relating to an identified or identifiable natural person;\n(h) “Serious crime” shall mean conduct constituting an offence punishable by a maximum deprivation of liberty of at least four years or a more serious penalty;\n(i) “Property” shall mean assets of every kind, whether corporeal or incorporeal, movable or immovable, tangible or intangible, including virtual assets, and legal documents or instruments evidencing title to, or interest in, such assets;\n(j) “Proceeds of crime” shall mean any property derived from or obtained, directly or indirectly, through the commission of an offence;\n(k) “Freezing” or “seizure” shall mean temporarily prohibiting the transfer, conversion, disposition or movement of property or temporarily assuming custody or control of property on the basis of an order issued by a court or other competent authority;\n(l) “Confiscation”, which includes forfeiture where applicable, shall mean the permanent deprivation of property by order of a court or other competent authority;\n(m) “Predicate offence” shall mean any offence as a result of which proceeds have been generated that may become the subject of an offence as defined in article 17 of this Convention;\n(n) “Regional economic integration organization” shall mean an organization constituted by sovereign States of a given region to which its member States have transferred competence in respect of matters governed by this Convention and which has been duly authorized, in accordance with its internal procedures, to sign, ratify, accept, approve or accede to it; references to “States Parties” under this Convention shall apply to such organizations within the limits of their competence;\n(o) “Emergency” shall mean a situation in which there is a significant and imminent risk to the life or safety of any natural person.\nArticle 3 Scope of application\nThis Convention shall apply, except as otherwise stated herein, to:\n(a) The prevention, investigation and prosecution of the criminal offences established in accordance with this Convention, including the freezing, seizure, confiscation and return of the proceeds from such offences;\n(b) The collecting, obtaining, preserving and sharing of evidence in electronic form for the purpose of criminal investigations or proceedings, as provided for in articles 23 and 35 of this Convention.\nArticle 4 Offences established in accordance with other United Nations conventions and protocols\nIn giving effect to other applicable United Nations conventions and protocols to which they are Parties, States Parties shall ensure that criminal offences established in accordance with such conventions and protocols are also considered criminal offences under domestic law when committed through the use of information and communications technology systems. Nothing in this article shall be interpreted as establishing criminal offences in accordance with this Convention. Article 5 Protection of sovereignty\nStates Parties shall carry out their obligations under this Convention in a manner consistent with the principles of sovereign equality and territorial integrity of States and that of non-intervention in the domestic affairs of other States. Nothing in this Convention shall entitle a State Party to undertake in the territory of another State the exercise of jurisdiction and performance of functions that are reserved exclusively for the authorities of that other State by its domestic law. Article 6 Respect for human rights\nStates Parties shall ensure that the implementation of their obligations under this Convention is consistent with their obligations under international human rights law. Nothing in this Convention shall be interpreted as permitting suppression of human rights or fundamental freedoms, including the rights related to the freedoms of expression, conscience, opinion, religion or belief, peaceful assembly and association, in accordance and in a manner consistent with applicable international human rights law. Chapter II: Criminalization Article 7 Illegal access\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as a criminal offence under its domestic law, when committed intentionally, the access to the whole or any part of an information and communications technology system without right. A State Party may require that the offence be committed by infringing security measures, with the intent of obtaining electronic data or other dishonest or criminal intent or in relation to an information and communications technology system that is connected to another information and communications technology system. Article 8 Illegal interception\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the interception, made by technical means, of non‑public transmissions of electronic data to, from or within an information and communications technology system, including electromagnetic emissions from an information and communications technology system carrying such electronic data. A State Party may require that the offence be committed with dishonest or criminal intent, or in relation to an information and communications technology system that is connected to another information and communications technology system. Article 9 Interference with electronic data\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the damaging, deletion, deterioration, alteration or suppression of electronic data. A State Party may require that the conduct described in paragraph 1 of this article result in serious harm. Article 10 Interference with an information and communications technology system\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the serious hindering of the functioning of an information and communications technology system by inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing electronic data.\nArticle 11 Misuse of devices\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right:\n(a) The obtaining, production, sale, procurement for use, import, distribution or otherwise making available of:\nwith the intent that the device, including a program, or the password, access credentials, electronic signature or similar data be used for the purpose of committing any of the offences established in accordance with articles 7 to 10 of this Convention; and\n(b) The possession of an item referred to in paragraph 1 (a) (i) or (ii) of this article, with intent that it be used for the purpose of committing any of the offences established in accordance with articles 7 to 10 of this Convention. This article shall not be interpreted as imposing criminal liability where the obtaining, production, sale, procurement for use, import, distribution or otherwise making available, or the possession referred to in paragraph 1 of this article is not for the purpose of committing an offence established in accordance with articles 7 to 10 of this Convention, such as for the authorized testing or protection of an information and communications technology system. Each State Party may reserve the right not to apply paragraph 1 of this article, provided that the reservation does not concern the sale, distribution or otherwise making available of the items referred to in paragraph 1 (a) (ii) of this article. Article 12 Information and communications technology system-related forgery\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the input, alteration, deletion or suppression of electronic data resulting in inauthentic data with the intent that they be considered or acted upon for legal purposes as if they were authentic, regardless of whether or not the data are directly readable and intelligible. A State Party may require an intent to defraud, or a similar dishonest or criminal intent, before criminal liability attaches. Article 13 Information and communications technology system-related theft or fraud\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as a criminal offence under its domestic law, when committed intentionally and without right, the causing of a loss of property to another person by means of:\n(a) Any input, alteration, deletion or suppression of electronic data;\n(b) Any interference with the functioning of an information and communications technology system;\n(c) Any deception as to factual circumstances made through an information and communications technology system that causes a person to do or omit to do anything which that person would not otherwise do or omit to do;\nwith the fraudulent or dishonest intent of procuring for oneself or for another person, without right, a gain in money or other property.\nArticle 14 Offences related to online child sexual abuse or child sexual exploitation material\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the following conduct:\n(a) Producing, offering, selling, distributing, transmitting, broadcasting, displaying, publishing or otherwise making available child sexual abuse or child sexual exploitation material through an information and communications technology system;\n(b) Soliciting, procuring or accessing child sexual abuse or child sexual exploitation material through an information and communications technology system;\n(c) Possessing or controlling child sexual abuse or child sexual exploitation material stored in an information and communications technology system or another storage medium;\n(d) Financing the offences established in accordance with subparagraphs (a) to (c) of this paragraph, which States Parties may establish as a separate offence. For the purposes of this article, the term “child sexual abuse or child sexual exploitation material” shall include visual material, and may include written or audio content, that depicts, describes or represents any person under 18 years of age:\n(a) Engaging in real or simulated sexual activity;\n(b) In the presence of a person engaging in any sexual activity;\n(c) Whose sexual parts are displayed for primarily sexual purposes; or\n(d) Subjected to torture or cruel, inhumane or degrading treatment or punishment and such material is sexual in nature. A State Party may require that the material identified in paragraph 2 of this article be limited to material that:\n(a) Depicts, describes or represents an existing person; or\n(b) Visually depicts child sexual abuse or child sexual exploitation. In accordance with their domestic law and consistent with applicable international obligations, States Parties may take steps to exclude the criminalization of:\n(a) Conduct by children for self-generated material depicting them; or\n(b) The consensual production, transmission, or possession of material described in paragraph 2 (a) to (c) of this article, where the underlying conduct depicted is legal as determined by domestic law, and where such material is maintained exclusively for the private and consensual use of the persons involved. Nothing in this Convention shall affect any international obligations which are more conducive to the realization of the rights of the child. Article 15 Solicitation or grooming for the purpose of committing a sexual offence against a child\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law the act of intentionally communicating, soliciting, grooming, or making any arrangement through an information and communications technology system for the purpose of committing a sexual offence against a child, as defined in domestic law, including for the commission of any of the offences established in accordance with article 14 of this Convention. A State Party may require an act in furtherance of the conduct described in paragraph 1 of this article. A State Party may consider extending criminalization in accordance with paragraph 1 of this article in relation to a person believed to be a child. States Parties may take steps to exclude the criminalization of conduct as described in paragraph 1 of this article when committed by children. Article 16 Non-consensual dissemination of intimate images\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the selling, distributing, transmitting, publishing or otherwise making available of an intimate image of a person by means of an information and communications technology system, without the consent of the person depicted in the image. For the purpose of paragraph 1 of this article, “intimate image” shall mean a visual recording of a person over the age of 18 years made by any means, including a photograph or video recording, that is sexual in nature, in which the person’s sexual parts are exposed or the person is engaged in sexual activity, which was private at the time of the recording, and in respect of which the person or persons depicted maintained a reasonable expectation of privacy at the time of the offence. A State Party may extend the definition of intimate images, as appropriate, to depictions of persons who are under the age of 18 years if they are of legal age to engage in sexual activity under domestic law and the image does not depict child abuse or exploitation. For the purposes of this article, a person who is under the age of 18 years and depicted in an intimate image cannot consent to the dissemination of an intimate image that constitutes child sexual abuse or child sexual exploitation material under article 14 of this Convention. A State Party may require the intent to cause harm before criminal liability attaches. States Parties may take other measures concerning matters related to this article, in accordance with their domestic law and consistent with applicable international obligations. Article 17 Laundering of proceeds of crime\nEach State Party shall adopt, in accordance with fundamental principles of its domestic law, such legislative and other measures as may be necessary to establish as criminal offences, when committed intentionally:\n(a)\n(i) The conversion or transfer of property, knowing that such property is the proceeds of crime, for the purpose of concealing or disguising the illicit origin of the property or of helping any person who is involved in the commission of the predicate offence to evade the legal consequences of that person’s actions;\n(ii) The concealment or disguise of the true nature, source, location, disposition, movement or ownership of or rights with respect to property, knowing that such property is the proceeds of crime;\n(b) Subject to the basic concepts of its legal system:\n(i) The acquisition, possession or use of property, knowing, at the time of receipt, that such property is the proceeds of crime;\n(ii) Participation in, association with or conspiracy to commit, attempts to commit and aiding, abetting, facilitating and counselling the commission of any of the offences established in accordance with this article. For purposes of implementing or applying paragraph 1 of this article:\n(a) Each State Party shall establish as predicate offences relevant offences established in accordance with articles 7 to 16 of this Convention;\n(b) In the case of States Parties whose legislation sets out a list of specific predicate offences, they shall, at a minimum, include in that list a comprehensive range of offences established in accordance with articles 7 to 16 of this Convention;\n(c) For the purposes of subparagraph (b) of this paragraph, predicate offences shall include offences committed both within and outside the jurisdiction of the State Party in question. However, offences committed outside the jurisdiction of a State Party shall constitute predicate offences only when the relevant conduct is a criminal offence under the domestic law of the State where it is committed and would be a criminal offence under the domestic law of the State Party implementing or applying this article, had it been committed there;\n(d) Each State Party shall furnish copies of its laws that give effect to this article and of any subsequent changes to such laws or a description thereof to the Secretary-General of the United Nations;\n(e) If required by fundamental principles of the domestic law of a State Party, it may be provided that the offences set forth in paragraph 1 of this article do not apply to the persons who committed the predicate offence;\n(f) Knowledge, intent or purpose required as an element of an offence set forth in paragraph 1 of this article may be inferred from objective factual circumstances. Article 18 Liability of legal persons\nEach State Party shall adopt such measures as may be necessary, consistent with its legal principles, to establish the liability of legal persons for participation in the offences established in accordance with this Convention. Subject to the legal principles of the State Party, the liability of legal persons may be criminal, civil or administrative. Such liability shall be without prejudice to the criminal liability of the natural persons who have committed the offences. Each State Party shall, in particular, ensure that legal persons held liable in accordance with this article are subject to effective, proportionate and dissuasive criminal or non-criminal sanctions, including monetary sanctions. Article 19 Participation and attempt\nEach State Party shall adopt such legislative and other measures as may be necessary to establish as a criminal offence, in accordance with its domestic law, when committed intentionally, the participation in any capacity, such as that of an accomplice, assistant or instigator, in an offence established in accordance with this Convention. Each State Party may adopt the necessary legislative and other measures to establish as a criminal offence, in accordance with its domestic law, when committed intentionally, any attempt to commit an offence established in accordance with this Convention. Each State Party may adopt the necessary legislative and other measures to establish as a criminal offence, in accordance with its domestic law, when committed intentionally, the preparation for an offence established in accordance with this Convention. Article 20 Statute of limitations\nEach State Party shall, where appropriate, considering the gravity of the crime, establish under its domestic law a long statute of limitations period in which to commence proceedings for any offence established in accordance with this Convention and establish a longer statute of limitations period or provide for the suspension of the statute of limitations where the alleged offender has evaded the administration of justice.\nArticle 21 Prosecution, adjudication and sanctions\nEach State Party shall make the commission of an offence established in accordance with this Convention liable to effective, proportionate and dissuasive sanctions that take into account the gravity of the offence. Each State Party may adopt, in accordance with its domestic law, such legislative and other measures as may be necessary to establish aggravating circumstances in relation to the offences established in accordance with this Convention, including circumstances that affect critical information infrastructures. Each State Party shall endeavour to ensure that any discretionary legal powers under its domestic law relating to the prosecution of persons for offences established in accordance with this Convention are exercised in order to maximize the effectiveness of law enforcement measures in respect of those offences and with due regard to the need to deter the commission of such offences. Each State Party shall ensure that any person prosecuted for offences established in accordance with this Convention enjoys all rights and guarantees in conformity with domestic law and consistent with the applicable international obligations of the State Party, including the right to a fair trial and the rights of the defence. In the case of offences established in accordance with this Convention, each State Party shall take appropriate measures, in accordance with its domestic law and with due regard to the rights of the defence, to seek to ensure that conditions imposed in connection with decisions on release pending trial or appeal take into consideration the need to ensure the presence of the defendant at subsequent criminal proceedings. Each State Party shall take into account the gravity of the offences concerned when considering the eventuality of early release or parole of persons convicted of such offences. States Parties shall ensure that appropriate measures are in place under domestic law to protect children who are accused of offences established in accordance with this Convention, consistent with the obligations under the Convention on the Rights of the Child and the applicable Protocols thereto, as well as other applicable international or regional instruments. Nothing contained in this Convention shall affect the principle that the description of the offences established in accordance with this Convention and of the applicable legal defences or other legal principles controlling the lawfulness of conduct is reserved to the domestic law of a State Party and that such offences shall be prosecuted and punished in accordance with that law. Chapter III: Jurisdiction Article 22 Jurisdiction\nEach State Party shall adopt such measures as may be necessary to establish its jurisdiction over the offences established in accordance with this Convention when:\n(a) The offence is committed in the territory of that State Party; or\n(b) The offence is committed on board a vessel that is flying the flag of that State Party or an aircraft that is registered under the laws of that State Party at the time when the offence is committed. Subject to article 5of this Convention, a State Party may also establish its jurisdiction over any such offence when:\n(a) The offence is committed against a national of that State Party; or\n(b) The offence is committed by a national of that State Party or a stateless person with habitual residence in its territory; or\n(c) The offence is one of those established in accordance with article 17, paragraph 1 (b) (ii), of this Convention and is committed outside its territory with a view to the commission of an offence established in accordance with article 17, paragraph 1 (a) (i) or (ii) or (b) (i), of this Convention within its territory; or\n(d) The offence is committed against the State Party. For the purposes of article 37, paragraph 11,of this Convention, each State Party shall take such measures as may be necessary to establish its jurisdiction over the offences established in accordance with this Convention when the alleged offender is present in its territory and it does not extradite such person solely on the ground that the person is one of its nationals. Each State Party may also adopt such measures as may be necessary to establish its jurisdiction over the offences established in accordance with this Convention when the alleged offender is present in its territory and it does not extradite the person. If a State Party exercising its jurisdiction under paragraph 1 or 2 of this article has been notified, or has otherwise learned, that any other States Parties are conducting an investigation, prosecution or judicial proceeding in respect of the same conduct, the competent authorities of those States Parties shall, as appropriate, consult one another with a view to coordinating their actions. Without prejudice to norms of general international law, this Convention shall not exclude the exercise of any criminal jurisdiction established by a State Party in accordance with its domestic law. Chapter IV: Procedural measures and law enforcement Article 23 Scope of procedural measures\nEach State Party shall adopt such legislative and other measures as may be necessary to establish the powers and procedures provided for in this chapter for the purpose of specific criminal investigations or proceedings. Except as provided otherwise in this Convention, each State Party shall apply the powers and procedures referred to in paragraph 1 of this article to:\n(a) The criminal offences established in accordance with this Convention;\n(b) Other criminal offences committed by means of an information and communications technology system; and\n(c) The collection of evidence in electronic form of any criminal offence. (a) Each State Party may reserve the right to apply the measures referred to in article 29 of this Convention only to offences or categories of offences specified in the reservation, provided that the range of such offences or categories of offences is not more restricted than the range of offences to which it applies the measures referred to in article 30 of this Convention. Each State Party shall consider restricting such a reservation to enable the broadest application of the measures referred to in article 29;\n(b) Where a State Party, owing to limitations in its legislation in force at the time of the adoption of this Convention, is not able to apply the measures referred to in articles 29 and 30 of this Convention to communications being transmitted within an information and communications technology system of a service provider which:\nthat State Party may reserve the right not to apply these measures to such communications. Each State Party shall consider restricting such a reservation to enable the broadest application of the measures referred to in articles 29 and 30 of this Convention. Article 24 Conditions and safeguards\nEach State Party shall ensure that the establishment, implementation and application of the powers and procedures provided for in this chapter are subject to conditions and safeguards provided for under its domestic law, which shall provide for the protection of human rights, in accordance with its obligations under international human rights law, and which shall incorporate the principle of proportionality. In accordance with and pursuant to the domestic law of each State Party, such conditions and safeguards shall, as appropriate in view of the nature of the procedure or power concerned, include, inter alia, judicial or other independent review, the right to an effective remedy, grounds justifying application, and limitation of the scope and the duration of such power or procedure. To the extent that it is consistent with the public interest, in particular the proper administration of justice, each State Party shall consider the impact of the powers and procedures in this chapter upon the rights, responsibilities and legitimate interests of third parties. The conditions and safeguards established in accordance with this article shall apply at the domestic level to the powers and procedures set forth in this chapter, both for the purpose of domestic criminal investigations and proceedings and for the purpose of rendering international cooperation by the requested State Party. References to judicial or other independent review in paragraph 2 of this article are references to such review at the domestic level. Article 25 Expedited preservation of stored electronic data\nEach State Party shall adopt such legislative and other measures as may be necessary to enable its competent authorities to order or similarly obtain the expeditious preservation of specified electronic data, including traffic data, content data and subscriber information, that have been stored by means of an information and communications technology system, in particular where there are grounds to believe that the electronic data are particularly vulnerable to loss or modification. Where a State Party gives effect to paragraph 1 of this article by means of an order to a person to preserve specified stored electronic data in the person’s possession or control, the State Party shall adopt such legislative and other measures as may be necessary to oblige that person to preserve and maintain the integrity of those electronic data for a period of time as long as necessary, up to a maximum of 90 days, to enable the competent authorities to seek their disclosure. A State Party may provide for such an order to be subsequently renewed. Each State Party shall adopt such legislative and other measures as may be necessary to oblige the custodian or other person who is to preserve the electronic data to keep confidential the undertaking of such procedures for the period of time provided for in its domestic legislation. Article 26 Expedited preservation and partial disclosure of traffic data\nEach State Party shall adopt, in respect of traffic data that are to be preserved under the provisions of article 25 of this Convention, such legislative and other measures as may be necessary to:\n(a) Ensure that such expeditious preservation of traffic data is available regardless of whether one or more service providers were involved in the transmission of a communication; and\n(b) Ensure the expeditious disclosure to the State Party’s competent authority, or a person designated by that authority, of a sufficient amount of traffic data to enable the State Party to identify the service providers and the path through which the communication or indicated information was transmitted.\nArticle 27 Production order\nEach State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to order:\n(a) A person in its territory to submit specified electronic data in that person’s possession or control that are stored in an information and communications technology system or an electronic data storage medium; and\n(b) A service provider offering its services in the territory of the State Party to submit subscriber information relating to such services in that service provider’s possession or control.\nArticle 28 Search and seizure of stored electronic data\nEach State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to search or similarly access:\n(a) An information and communications technology system, part of it, and electronic data stored therein; and\n(b) An electronic data storage medium in which the electronic data sought may be stored;\nin the territory of that State Party. Each State Party shall adopt such legislative and other measures as may be necessary to ensure that, where its authorities search or similarly access a specific information and communications technology system or part of it, pursuant to paragraph 1 (a) of this article, and have grounds to believe that the electronic data sought are stored in another information and communications technology system or part of it in its territory, and such data are lawfully accessible from or available to the initial system, such authorities shall be able to expeditiously conduct the search to obtain access to that other information and communications technology system. Each State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to seize or similarly secure electronic data in its territory accessed in accordance with paragraph 1 or 2 of this article. These measures shall include the power to:\n(a) Seize or similarly secure an information and communications technology system or part of it, or an electronic data storage medium;\n(b) Make and retain copies of those electronic data in electronic form;\n(c) Maintain the integrity of the relevant stored electronic data;\n(d) Render inaccessible or remove those electronic data in the accessed information and communications technology system. Each State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to order any person who has knowledge about the functioning of the information and communications technology system in question, the information and telecommunications network, or their component parts, or measures applied to protect the electronic data therein, to provide, as is reasonable, the necessary information to enable the undertaking of the measures referred to in paragraphs 1 to 3 of this article. Article 29 Real-time collection of traffic data\nEach State Party shall adopt such legislative and other measures as may be necessary to empower its competent authorities to:\n(a) Collect or record, through the application of technical means in the territory of that State Party; and\n(b) Compel a service provider, within its existing technical capability: Where a State Party, owing to the principles of its domestic legal system, cannot adopt the measures referred to in paragraph 1 (a) of this article, it may instead adopt such legislative and other measures as may be necessary to ensure the real-time collection or recording of traffic data associated with specified communications transmitted in its territory, through the application of technical means in that territory. Each State Party shall adopt such legislative and other measures as may be necessary to oblige a service provider to keep confidential the fact of the execution of any power provided for in this article and any information relating to it. Article 30 Interception of content data\nEach State Party shall adopt such legislative and other measures as may be necessary, in relation to a range of serious criminal offences to be determined by domestic law, to empower its competent authorities to:\n(a) Collect or record, through the application of technical means in the territory of that State Party; and\n(b) Compel a service provider, within its existing technical capability: Where a State Party, owing to the principles of its domestic legal system, cannot adopt the measures referred to in paragraph 1 (a) of this article, it may instead adopt such legislative and other measures as may be necessary to ensure the real-time collection or recording of content data on specified communications in its territory, through the application of technical means in that territory. Each State Party shall adopt such legislative and other measures as may be necessary to oblige a service provider to keep confidential the fact of the execution of any power provided for in this article and any information relating to it. Article 31 Freezing, seizure and confiscation of the proceeds of crime\nEach State Party shall adopt, to the greatest extent possible within its domestic legal system, such measures as may be necessary to enable the confiscation of:\n(a) Proceeds of crime derived from offences established in accordance with this Convention or property the value of which corresponds to that of such proceeds;\n(b) Property, equipment or other instrumentalities used in or destined for use in offences established in accordance withthis Convention. Each State Party shall adopt such measures as may be necessary to enable the identification, tracing, freezing or seizure of any item referred to in paragraph 1 of this article for the purpose of eventual confiscation. Each State Party shall adopt, in accordance with its domestic law, such legislative and other measures as may be necessary to regulate the administration by the competent authorities of frozen, seized or confiscated property covered in paragraphs 1 and 2 of this article. If proceeds of crime have been transformed or converted, in part or in full, into other property, such property shall be liable to the measures referred to in this article instead of the proceeds. If proceeds of crime have been intermingled with property acquired from legitimate sources, such property shall, without prejudice to any powers relating to freezing or seizure, be liable to confiscation up to the assessed value of the intermingled proceeds. Income or other benefits derived from proceeds of crime, from property into which proceeds of crime have been transformed or converted or from property with which proceeds of crime have been intermingled, shall also be liable to the measures referred to in this article, in the same manner and to the same extent as proceeds of crime. For the purposes of this article and article 50 of this Convention, each State Party shall empower its courts or other competent authorities to order that bank, financial or commercial records be made available or be seized. A State Party shall not decline to act under the provisions of this paragraph on the ground of bank secrecy. Each State Party may consider the possibility of requiring that an offender demonstrate the lawful origin of alleged proceeds of crime or other property liable to confiscation, to the extent that such a requirement is consistent with the principles of their domestic law and with the nature of the judicial and other proceedings. The provisions of this article shall not be construed as prejudicing the rights of bona fide third parties. Nothing contained in this article shall affect the principle that the measures to which it refers shall be defined and implemented in accordance with the provisions of the domestic law of a State Party. Article 32 Establishment of criminal record\nEach State Party may adopt such legislative or other measures as may be necessary to take into consideration, under such terms as, and for the purpose that, it deems appropriate, any previous conviction in another State of an alleged offender for the purpose of using such information in criminal proceedings relating to an offence established in accordance with this Convention.\nArticle 33 Protection of witnesses\nEach State Party shall take appropriate measures, in accordance with its domestic law and within its means, to provide effective protection from potential retaliation or intimidation for witnesses who give testimony or, in good faith and on reasonable grounds, provide information concerning offences established in accordance with this Convention or otherwise cooperate with investigative or judicial authorities and, as appropriate, for their relatives and other persons close to them. The measures envisaged in paragraph 1 of this article may include, inter alia, without prejudice to the rights of the defendant, including the right to due process:\n(a) Establishing procedures for the physical protection of such persons, such as, to the extent necessary and feasible, relocating them and permitting, where appropriate, non-disclosure or limitations on the disclosure of information concerning the identity and whereabouts of such persons;\n(b) Providing evidentiary rules to permit witness testimony to be given in a manner that ensures the safety of the witness, such as permitting testimony to be given through the use of communications technology such as video links or other adequate means. States Parties shall consider entering into agreements or arrangements with other States for the relocation of persons referred to in paragraph 1 of this article. The provisions of this article shall also apply to victims insofar as they are witnesses. Article 34 Assistance to and protection of victims\nEach State Party shall take appropriate measures within its means to provide assistance and protection to victims of offences established in accordance with this Convention, in particular in cases of threat of retaliation or intimidation. Each State Party shall, subject to its domestic law, establish appropriate procedures to provide access to compensation and restitution for victims of offences established in accordance with this Convention. Each State Party shall, subject to its domestic law, enable views and concerns of victims to be presented and considered at appropriate stages of criminal proceedings against offenders in a manner not prejudicial to the rights of the defence. With respect to the offences established in accordance with articles 14 to 16 of this Convention, each State Party shall, subject to its domestic law, take measures to provide assistance to victims of such offences, including for their physical and psychological recovery, in cooperation with relevant international organizations, non‑governmental organizations, and other elements of civil society. In applying the provisions of paragraphs 2 to 4 of this article, each State Party shall take into account the age, gender and the particular circumstances and needs of victims, including the particular circumstances and needs of children. Each State Party shall, to the extent consistent with its domestic legal framework, take effective steps to ensure compliance with requests to remove or render inaccessible the content described in articles 14 and 16 of this Convention. Chapter V: International cooperation Article 35 General principles of international cooperation\nStates Parties shall cooperate with each other in accordance with the provisions of this Convention, as well as other applicable international instruments on international cooperation in criminal matters, and domestic laws, for the purpose of:\n(a) The investigation and prosecution of, and judicial proceedings in relation to, the criminal offences established in accordance with this Convention, including the freezing, seizure, confiscation and return of the proceeds from such offences;\n(b) The collecting, obtaining, preserving and sharing of evidence in electronic form of criminal offences established in accordance with this Convention;\n(c) The collecting, obtaining, preserving and sharing of evidence in electronic form of any serious crime, including serious crimes established in accordance with other applicable United Nations conventions and protocols in force at the time of the adoption of this Convention. For the purpose of the collecting, obtaining, preserving and sharing of evidence in electronic form of offences as provided for in paragraph 1 (b) and (c) of this article, the relevant paragraphs of article 40, and articles 41 to 46 of this Convention shall apply. In matters of international cooperation, whenever dual criminality is considered a requirement, it shall be deemed fulfilled irrespective of whether the laws of the requested State Party place the offence within the same category of offence or denominate the offence by the same terminology as the requesting State Party, if the conduct underlying the offence for which assistance is sought is a criminal offence under the laws of both States Parties. Article 36 Protection of personal data\n(a) A State Party transferring personal data pursuant to this Convention shall do so in accordance with its domestic law and any obligations the transferring Party may have under applicable international law. States Parties shall not be required to transfer personal data in accordance with this Convention if the data cannot be provided in compliance with their applicable laws concerning the protection of personal data;\n(b) Where the transfer of personal data would not be compliant with paragraph 1 (a) of this article, States Parties may seek to impose appropriate conditions, in accordance with such applicable laws, to achieve compliance in order to respond to a request for personal data;\n(c) States Parties are encouraged to establish bilateral or multilateral arrangements to facilitate the transfer of personal data. For personal data transferred in accordance with this Convention, States Parties shall ensure that the personal data received are subject to effective and appropriate safeguards in the respective legal frameworks of the States Parties. In order to transfer personal data obtained in accordance with this Convention to a third country or an international organization, a State Party shall notify the original transferring State Party of its intention and request its authorization. The State Party shall transfer such personal data only with the authorization of the original transferring State Party, which may require that the authorization be provided in written form. Article 37 Extradition\nThis article shall apply to the criminal offences established in accordance with this Convention where the person who is the subject of the request for extradition is present in the territory of the requested State Party, provided that the offence for which extradition is sought is punishable under the domestic law of both the requesting State Party and the requested State Party. When the extradition is sought for the purpose of serving a final sentence of imprisonment or another form of detention imposed in respect of an extraditable offence, the requested State Party may grant the extradition in accordance with domestic law. Notwithstanding paragraph 1 of this article, a State Party whose law so permits may grant the extradition of a person for any of the criminal offences established in accordance with this Convention that are not punishable under its own domestic law. If the request for extradition includes several separate criminal offences, at least one of which is extraditable under this article and some of which are not extraditable by reason of their period of imprisonment but are related to offences established in accordance with this Convention, the requested State Party may apply this article also in respect of those offences. Each of the offences to which this article applies shall be deemed to be included as an extraditable offence in any extradition treaty existing between States Parties. States Parties undertake to include such offences as extraditable offences in every extradition treaty to be concluded between them. If a State Party that makes extradition conditional on the existence of a treaty receives a request for extradition from another State Party with which it has no extradition treaty, it may consider this Convention the legal basis for extradition in respect of any offence to which this article applies. States Parties that make extradition conditional on the existence of a treaty shall:\n(a) At the time of deposit of their instruments of ratification, acceptance or approval of or accession to this Convention, inform the Secretary-General of the United Nations whether they will take this Convention as the legal basis for cooperation in extradition with other States Parties to this Convention; and\n(b) If they do not take this Convention as the legal basis for cooperation in extradition, seek, where appropriate, to conclude treaties on extradition with other States Parties to this Convention in order to implement this article. States Parties that do not make extradition conditional on the existence of a treaty shall recognize offences to which this article applies as extraditable offences between themselves. Extradition shall be subject to the conditions provided for by the domestic law of the requested State Party or by applicable extradition treaties, including, inter alia, conditions in relation to the minimum penalty requirement for extradition and the grounds upon which the requested State Party may refuse extradition. States Parties shall, subject to their domestic law, endeavour to expedite extradition procedures and to simplify evidentiary requirements relating thereto in respect of any offence to which this article applies. Subject to the provisions of its domestic law and its extradition treaties, the requested State Party may, upon being satisfied that the circumstances so warrant and are urgent, and at the request of the requesting State Party, including when the request is transmitted through existing channels of the International Criminal Police Organization, take a person whose extradition is sought and who is present in its territory into custody or take other appropriate measures to ensure the person’s presence at extradition proceedings. A State Party in whose territory an alleged offender is found, if it does not extradite such person in respect of an offence to which this article applies solely on the ground that the person is one of its nationals, shall, at the request of the State Party seeking extradition, be obliged to submit the case without undue delay to its competent authorities for the purpose of prosecution. Those authorities shall take their decisions and conduct their proceedings in the same manner as in the case of any other offence of a comparable nature under the domestic law of that State Party. The States Parties concerned shall cooperate with each other, in particular on procedural and evidentiary aspects, to ensure the efficiency of such prosecution. Whenever a State Party is permitted under its domestic law to extradite or otherwise surrender one of its nationals only upon the condition that the person will be returned to that State Party to serve the sentence imposed as a result of the trial or proceedings for which the extradition or surrender of the person was sought and that State Party and the State Party seeking the extradition of the person agree with this option and other terms that they may deem appropriate, such conditional extradition or surrender shall be sufficient to discharge the obligation set forth in paragraph 11 of this article. If extradition, sought for purposes of enforcing a sentence, is refused because the person sought is a national of the requested State Party, the requested State Party shall, if its domestic law so permits and in conformity with the requirements of such law, upon application of the requesting State Party, consider the enforcement of the sentence imposed under the domestic law of the requesting State Party or the remainder thereof. Any person regarding whom proceedings are being carried out in connection with any of the offences to which this article applies shall be guaranteed fair treatment at all stages of the proceedings, including enjoyment of all the rights and guarantees provided by the domestic law of the State Party in the territory of which that person is present. Nothing in this Convention shall be interpreted as imposing an obligation to extradite if the requested State Party has substantial grounds for believing that the request has been made for the purpose of prosecuting or punishing a person on account of that person’s sex, race, language, religion, nationality, ethnic origin or political opinions, or that compliance with the request would cause prejudice to that person’s position for any one of these reasons. States Parties may not refuse a request for extradition on the sole ground that the offence is also considered to involve fiscal matters. Before refusing extradition, the requested State Party shall, where appropriate, consult with the requesting State Party to provide it with ample opportunity to present its opinions and to provide information relevant to its allegation. The requested State Party shall inform the requesting State Party of its decision with regard to the extradition. The requested State Party shall inform the requesting State Party of any reason for refusal of extradition unless the requested State Party is prevented from doing so by its domestic law or its international legal obligations. Each State Party shall, at the time of signature or when depositing its instrument of ratification, acceptance, approval or accession, communicate to the Secretary-General of the United Nations the name and address of an authority responsible for making or receiving requests for extradition or provisional arrest. The Secretary-General shall set up and keep updated a register of authorities so designated by the States Parties. Each State Party shall ensure that the details held in the register are correct at all times. States Parties shall seek to conclude bilateral and multilateral agreements or arrangements to carry out or to enhance the effectiveness of extradition. Article 38 Transfer of sentenced persons\nStates Parties may, taking into consideration the rights of sentenced persons, consider entering into bilateral or multilateral agreements or arrangements on the transfer to their territory of persons sentenced to imprisonment or other forms of deprivation of liberty for offences established in accordance with this Convention, in order that they may complete their sentences there. States Parties may also take into account issues relating to consent, rehabilitation and reintegration.\nArticle 39 Transfer of criminal proceedings\nStates Parties shall consider the possibility of transferring to one another proceedings for the criminal prosecution of an offence established in accordance with this Convention where such a transfer is deemed to be in the interests of the proper administration of justice, particularly in cases where several jurisdictions are involved, with a view to concentrating the prosecution. If a State Party that makes the transfer of criminal proceedings conditional on the existence of a treaty receives a request for transfer from another State Party with which it has no treaty in this matter, it may consider this Convention as the legal basis for the transfer of criminal proceedings in respect of any offence to which this article applies. Article 40 General principles and procedures relating to mutual legal assistance\nStates Parties shall afford one another the widest measure of mutual legal assistance in investigations, prosecutions and judicial proceedings in relation to the offences established in accordance with this Convention, and for the purposes of the collection of evidence in electronic form of offences established in accordance with this Convention, as well as of serious crimes. Mutual legal assistance shall be afforded to the fullest extent possible under relevant laws, treaties, agreements and arrangements of the requested State Party with respect to investigations, prosecutions and judicial proceedings in relation to the offences for which a legal person may be held liable in accordance with article 18 of this Convention in the requesting State Party. Mutual legal assistance to be afforded in accordance with this article may be requested for any of the following purposes:\n(a) Taking evidence or statements from persons;\n(b) Effecting service of judicial documents;\n(c) Executing searches and seizures, and freezing;\n(d) Searching or similarly accessing, seizing or similarly securing, and disclosing electronic data stored by means of an information and communications technology system pursuant to article 44 of this Convention;\n(e) Collecting traffic data in real time pursuant to article 45 of this Convention;\n(f) Intercepting content data pursuant to article 46 of this Convention;\n(g) Examining objects and sites;\n(h) Providing information, evidence and expert evaluations;\n(i) Providing originals or certified copies of relevant documents and records, including government, bank, financial, corporate or business records;\n(j) Identifying or tracing proceeds of crime, property, instrumentalities or other things for evidentiary purposes;\n(k) Facilitating the voluntary appearance of persons in the requesting State Party\n(l) Recovering proceeds of crime;\n(m) Any other type of assistance that is not contrary to the domestic law of the requested State Party. Without prejudice to domestic law, the competent authorities of a State Party may, without prior request, transmit information relating to criminal matters to a competent authority in another State Party where they believe that such information could assist the authority in undertaking or successfully concluding inquiries and criminal proceedings or could result in a request formulated by the latter State Party pursuant to this Convention. The transmission of information pursuant to paragraph 4 of this article shall be without prejudice to inquiries and criminal proceedings in the State of the competent authorities providing the information. The competent authorities receiving the information shall comply with a request that said information remain confidential, even temporarily, or with restrictions on its use. However, this shall not prevent the receiving State Party from disclosing in its proceedings information that is exculpatory to an accused person. In such a case, the receiving State Party shall notify the transmitting State Party prior to the disclosure and, if so requested, consult with the transmitting State Party. If, in an exceptional case, advance notice is not possible, the receiving State Party shall inform the transmitting State Party of the disclosure without delay. The provisions of this article shall not affect obligations under any other treaty, bilateral or multilateral, that governs or will govern, in whole or in part, mutual legal assistance. Paragraphs 8 to 31 of this article shall apply to requests made pursuant to this article if the States Parties in question are not bound by a treaty on mutual legal assistance. If those States Parties are bound by such a treaty, the corresponding provisions of that treaty shall apply unless the States Parties agree to apply paragraphs 8 to 31 of this article in lieu thereof. States Parties are strongly encouraged to apply the provisions of those paragraphs if they facilitate cooperation. States Parties may decline to render assistance pursuant to this article on the ground of absence of dual criminality. However, the requested State Party may, when it deems appropriate, provide assistance, to the extent it decides at its discretion, irrespective of whether the conduct would constitute an offence under the domestic law of the requested State Party. Assistance may be refused when requests involve matters of a de minimis nature or matters for which the cooperation or assistance sought is available under other provisions of this Convention. A person who is being detained or is serving a sentence in the territory of one State Party and whose presence in another State Party is requested for purposes of identification, testimony or otherwise providing assistance in obtaining evidence for investigations, prosecutions or judicial proceedings in relation to offences established in accordance with this Convention may be transferred if the following conditions are met:\n(a) The person freely gives informed consent;\n(b) The competent authorities of both States Parties agree, subject to such conditions as those States Parties may deem appropriate. For the purposes of paragraph 9 of this article:\n(a) The State Party to which the person is transferred shall have the authority and obligation to keep the person transferred in custody, unless otherwise requested or authorized by the State Party from which the person was transferred;\n(b) The State Party to which the person is transferred shall, without delay, implement its obligation to return the person to the custody of the State Party from which the person was transferred as agreed beforehand, or as otherwise agreed, by the competent authorities of both States Parties;\n(c) The State Party to which the person is transferred shall not require the State Party from which the person was transferred to initiate extradition proceedings for the return of the person;\n(d) The person transferred shall receive credit for service of the sentence being served in the State from which the person was transferred for time spent in the custody of the State Party to which the person was transferred. Unless the State Party from which a person is to be transferred in accordance with paragraphs 9 and 10 of this article so agrees, that person, regardless of the person’s nationality, shall not be prosecuted, detained, punished or subjected to any other restriction of liberty in the territory of the State to which that person is transferred in respect of acts, omissions or convictions prior to the person’s departure from the territory of the State from which the person was transferred. (a) Each State Party shall designate a central authority or authorities that shall have the responsibility and power to receive requests for mutual legal assistance and either to execute them or to transmit them to the competent authorities for execution. Where a State Party has a special region or territory with a separate system of mutual legal assistance, it may designate a distinct central authority that shall have the same function for that region or territory;\n(b) Central authorities shall ensure the speedy and proper execution or transmission of the requests received. Where the central authority transmits the request to a competent authority for execution, it shall encourage the speedy and proper execution of the request by the competent authority;\n(c) The Secretary-General of the United Nations shall be notified of the central authority designated for this purpose at the time each State Party deposits its instrument of ratification, acceptance or approval of or accession to this Convention, and shall set up and keep updated a register of central authorities designated by the States Parties. Each State Party shall ensure that the details held in the register are correct at all times;\n(d) Requests for mutual legal assistance and any communication related thereto shall be transmitted to the central authorities designated by the States Parties. This requirement shall be without prejudice to the right of a State Party to require that such requests and communications be addressed to it through diplomatic channels and, in urgent circumstances, where the States Parties agree, through the International Criminal Police Organization, if possible. Requests shall be made in writing or, where possible, by any means capable of producing a written record, in a language acceptable to the requested State Party, under conditions allowing that State Party to establish authenticity. The Secretary-General of the United Nations shall be notified of the language or languages acceptable to each State Party at the time it deposits its instrument of ratification, acceptance or approval of or accession to this Convention. In urgent circumstances and where agreed by the States Parties, requests may be made orally, but shall be confirmed in writing forthwith. Where not prohibited by their respective laws, central authorities of States Parties are encouraged to transmit and receive requests for mutual legal assistance, and communications related thereto, as well as evidence, in electronic form under conditions allowing the requested State Party to establish authenticity and ensuring the security of communications. A request for mutual legal assistance shall contain:\n(a) The identity of the authority making the request;\n(b) The subject matter and nature of the investigation, prosecution or judicial proceeding to which the request relates and the name and functions of the authority conducting the investigation, prosecution or judicial proceeding;\n(c) A summary of the relevant facts, except in relation to requests for the purpose of service of judicial documents;\n(d) A description of the assistance sought and details of any particular procedure that the requesting State Party wishes to be followed;\n(e) Where possible and appropriate, the identity, location and nationality of any person concerned, as well as the country of origin, description and location of any item or accounts concerned;\n(f) Where applicable, the time period for which the evidence, information or other assistance is sought; and\n(g) The purpose for which the evidence, information or other assistance is sought. The requested State Party may request additional information when it appears necessary for the execution of the request in accordance with its domestic law or when it can facilitate such execution. A request shall be executed in accordance with the domestic law of the requested State Party and, to the extent not contrary to the domestic law of the requested State Party and where possible, in accordance with the procedures specified in the request. Wherever possible and consistent with fundamental principles of domestic law, when an individual is in the territory of a State Party and has to be heard as a witness, victim or expert by the judicial authorities of another State Party, the first State Party may, at the request of the other, permit the hearing to take place by videoconference if it is not possible or desirable for the individual in question to appear in person in the territory of the requesting State Party. States Parties may agree that the hearing shall be conducted by a judicial authority of the requesting State Party and attended by a judicial authority of the requested State Party. If the requested State Party does not have access to the technical means necessary for holding a videoconference, such means may be provided by the requesting State Party, upon mutual agreement. The requesting State Party shall not transmit or use information or evidence furnished by the requested State Party for investigations, prosecutions or judicial proceedings other than those stated in the request without the prior consent of the requested State Party. Nothing in this paragraph shall prevent the requesting State Party from disclosing in its proceedings information or evidence that is exculpatory to an accused person. In the latter case, the requesting State Party shall notify the requested State Party prior to the disclosure and, if so requested, consult with the requested State Party. If, in an exceptional case, advance notice is not possible, the requesting State Party shall inform the requested State Party of the disclosure without delay. The requesting State Party may require that the requested State Party keep confidential the fact and substance of the request, except to the extent necessary to execute the request. If the requested State Party cannot comply with the requirement of confidentiality, it shall promptly inform the requesting State Party. Mutual legal assistance may be refused:\n(a) If the request is not made in conformity with the provisions of this article;\n(b) If the requested State Party considers that execution of the request is likely to prejudice its sovereignty, security, ordre public or other essential interests;\n(c) If the authorities of the requested State Party would be prohibited by its domestic law from carrying out the action requested with regard to any similar offence, had it been subject to investigation, prosecution or judicial proceedings under their own jurisdiction;\n(d) If it would be contrary to the legal system of the requested State Party relating to mutual legal assistance for the request to be granted. Nothing in this Convention shall be interpreted as imposing an obligation to afford mutual legal assistance if the requested State Party has substantial grounds for believing that the request has been made for the purpose of prosecuting or punishing a person on account of that person’s sex, race, language, religion, nationality, ethnic origin or political opinions, or that compliance with the request would cause prejudice to that person’s position for any one of these reasons. States Parties may not refuse a request for mutual legal assistance on the sole ground that the offence is also considered to involve fiscal matters. States Parties shall not decline to render mutual legal assistance pursuant to this article on the ground of bank secrecy. Reasons shall be given for any refusal of mutual legal assistance. The requested State Party shall execute the request for mutual legal assistance as soon as possible and shall take as full account as possible of any deadlines suggested by the requesting State Party and for which reasons are given, preferably in the request. The requested State Party shall respond to reasonable requests by the requesting State Party on the status, and progress in its handling, of the request. The requesting State Party shall promptly inform the requested State Party when the assistance sought is no longer required. Mutual legal assistance may be postponed by the requested State Party on the ground that it interferes with an ongoing investigation, prosecution or judicial proceeding. Before refusing a request pursuant to paragraph 21 of this article or postponing its execution pursuant to paragraph 27 of this article, the requested State Party shall consult with the requesting State Party to consider whether assistance may be granted subject to such terms and conditions as it deems necessary. If the requesting State Party accepts assistance subject to those conditions, it shall comply with the conditions. Without prejudice to the application of paragraph 11 of this article, a witness, expert or other person who, at the request of the requesting State Party, consents to give evidence in a proceeding or to assist in an investigation, prosecution or judicial proceeding in the territory of the requesting State Party shall not be prosecuted, detained, punished or subjected to any other restriction of the person’s liberty in that territory in respect of acts, omissions or convictions prior to the person’s departure from the territory of the requested State Party. Such safe conduct shall cease when the witness, expert or other person having had, for a period of 15 consecutive days or for any period agreed upon by the States Parties from the date on which the person has been officially informed that the presence of the person is no longer required by the judicial authorities, an opportunity of leaving, has nevertheless remained voluntarily in the territory of the requesting State Party or, having left it, has returned of the person’s own free will. The ordinary costs of executing a request shall be borne by the requested State Party, unless otherwise agreed by the States Parties concerned. If expenses of a substantial or extraordinary nature are or will be required to fulfil the request, the States Parties shall consult to determine the terms and conditions under which the request will be executed, as well as the manner in which the costs shall be borne. The requested State Party:\n(a) Shall provide to the requesting State Party copies of government records, documents or information in its possession that under its domestic law are available to the general public;\n(b) May, at its discretion, provide to the requesting State Party, in whole, in part or subject to such conditions as it deems appropriate, copies of any government records, documents or information in its possession that under its domestic law are not available to the general public. States Parties shall consider, as may be necessary, the possibility of concluding bilateral or multilateral agreements or arrangements that would serve the purposes of, give practical effect to or enhance the provisions of this article. Article 41 24/7 network\nEach State Party shall designate a point of contact available 24 hours a day, 7 days a week, in order to ensure the provision of immediate assistance for the purpose of specific criminal investigations, prosecutions or judicial proceedings concerning offences established in accordance with this Convention, or for the collection, obtaining and preservation of evidence in electronic form for the purposes of paragraph 3 of this article and in relation to the offences established in accordance with this Convention, as well as to serious crime. The Secretary-General of the United Nations shall be notified of such point of contact and keep an updated register of points of contact designated for the purposes of this article and shall annually circulate to the States Parties the updated list of contact points. Such assistance shall include facilitating or, if permitted by the domestic law and practice of the requested State Party, directly carrying out the following measures:\n(a) The provision of technical advice;\n(b) The preservation of stored electronic data pursuant to articles 42 and 43 of this Convention, including, as appropriate, information about the location of the service provider, if known to the requested State Party, to assist the requesting State Party in making a request;\n(c) The collection of evidence and the provision of legal information;\n(d) The locating of suspects; or\n(e) The provision of electronic data to avert an emergency. A State Party’s point of contact shall have the capacity to carry out communications with the point of contact of another State Party on an expedited basis. If the point of contact designated by a State Party is not part of that State Party’s authority or authorities responsible for mutual legal assistance or extradition, the point of contact shall ensure that it is able to coordinate with that authority or those authorities on an expedited basis. Each State Party shall ensure that trained and equipped personnel are available to ensure the operation of the 24/7 network. States Parties may also use and strengthen existing authorized networks of points of contact, where applicable, and within the limits of their domestic laws, including the 24/7 networks for computer-related crime of the International Criminal Police Organization for prompt police-to-police cooperation and other methods of information exchange cooperation. Article 42 International cooperation for the purpose of expedited preservation of stored electronic data\nA State Party may request another State Party to order or otherwise obtain, in accordance with article 25 of this Convention, the expeditious preservation of electronic data stored by means of an information and communications technology system located within the territory of that other State Party, and in respect of which the requesting State Party intends to submit a request for mutual legal assistance in the search or similar access, seizure or similar securing, or disclosure of the electronic data. The requesting State Party may use the 24/7 network provided for in article 41 of this Convention to seek information concerning the location of the electronic data stored by means of an information and communications technology system and, as appropriate, information about the location of the service provider. A request for preservation made under paragraph 1 of this article shall specify:\n(a) The authority seeking the preservation;\n(b) The offence that is the subject of a criminal investigation, prosecution or judicial proceeding and a brief summary of the related facts;\n(c) The stored electronic data to be preserved and their relationship to the offence;\n(d) Any available information identifying the custodian of the stored electronic data or the location of the information and communications technology system;\n(e) The necessity of the preservation;\n(f) That the requesting State Party intends to submit a request for mutual legal assistance in the search or similar access, seizure or similar securing, or disclosure of the stored electronic data;\n(g) As appropriate, the need to keep the request for preservation confidential and not to notify the user. Upon receiving the request from another State Party, the requested State Party shall take all appropriate measures to preserve expeditiously the specified electronic data in accordance with its domestic law. For the purposes of responding to a request, dual criminality shall not be required as a condition for providing such preservation. A State Party that requires dual criminality as a condition for responding to a request for mutual legal assistance in the search or similar access, seizure or similar securing, or disclosure of stored electronic data may, in respect of offences other than those established in accordance with this Convention, reserve the right to refuse the request for preservation under this article in cases where it has reasons to believe that, at the time of disclosure, the condition of dual criminality could not be fulfilled. In addition, a request for preservation may be refused only on the basis of the grounds contained in article 40, paragraph 21 (b) and (c) and paragraph 22, of this Convention. Where the requested State Party believes that preservation will not ensure the future availability of the data or will threaten the confidentiality of or otherwise prejudice the requesting State Party’s investigation, it shall promptly so inform the requesting State Party, which shall then determine whether the request should nevertheless be executed. Any preservation effected in response to a request made pursuant to paragraph 1 of this article shall be for a period of not less than 60 days, in order to enable the requesting State Party to submit a request for the search or similar access, seizure or similar securing, or disclosure of the data. Following the receipt of such a request, the data shall continue to be preserved pending a decision on that request. Before the expiry of the preservation period in paragraph 8 of this article, the requesting State Party may request an extension of the period of preservation. Article 43 International cooperation for the purpose of expedited disclosure of preserved traffic data\nWhere, in the course of the execution of a request made pursuant to article 42 of this Convention to preserve traffic data concerning a specific communication, the requested State Party discovers that a service provider in another State Party was involved in the transmission of the communication, the requested State Party shall expeditiously disclose to the requesting State Party a sufficient amount of traffic data to identify that service provider and the path through which the communication was transmitted. Disclosure of traffic data under paragraph 1 of this article may be refused only on the basis of the grounds contained in article 40, paragraph 21 (b) and (c) and paragraph 22, of this Convention. Article 44 Mutual legal assistance in accessing stored electronic data\nA State Party may request another State Party to search or similarly access, seize or similarly secure, and disclose electronic data stored by means of an information and communications technology system located within the territory of the requested State Party, including electronic data that have been preserved pursuant to article 42 of this Convention. The requested State Party shall respond to the request through the application of relevant international instruments and laws referred to in article 35 of this Convention, and in accordance with other relevant provisions of this chapter. The request shall be responded to on an expedited basis where:\n(a) There are grounds to believe that the relevant data are particularly vulnerable to loss or modification; or\n(b) The instruments and laws referred to in paragraph 2 of this article otherwise provide for expedited cooperation. Article 45 Mutual legal assistance in the real-time collection of traffic data\nStates Parties shall endeavour to provide mutual legal assistance to each other in the real-time collection of traffic data associated with specified communications in their territory transmitted by means of an information and communications technology system. Subject to the provisions of paragraph 2 of this article, such assistance shall be governed by the conditions and procedures provided for under domestic law. Each State Party shall endeavour to provide such assistance at least with respect to criminal offences for which the real-time collection of traffic data would be available in a similar domestic case. A request made in accordance with paragraph 1 of this article shall specify:\n(a) The name of the requesting authority;\n(b) A summary of the main facts and the nature of the investigation, prosecution or judicial proceeding to which the request relates;\n(c) The electronic data in relation to which the collection of the traffic data is required and their relationship to the offence;\n(d) Any available data that identify the owner or user of the data or the location of the information and communications technology system;\n(e) Justification for the need to collect the traffic data;\n(f) The period for which traffic data are to be collected and a corresponding justification of its duration. Article 46 Mutual legal assistance in the interception of content data\nStates Parties shall endeavour to provide mutual legal assistance to each other in the real-time collection or recording of content data of specified communications transmitted by means of an information and communications technology system, to the extent permitted under treaties applicable to them or under their domestic laws.\nArticle 47 Law enforcement cooperation\nStates Parties shall cooperate closely with one another, consistent with their respective domestic legal and administrative systems, to enhance the effectiveness of law enforcement action to combat the offences established in accordance with this Convention. States Parties shall, in particular, take effective measures:\n(a) To enhance and, where necessary, to establish channels of communication between their competent authorities, agencies and services, taking into account existing channels, including those of the International Criminal Police Organization, in order to facilitate the secure and rapid exchange of information concerning all aspects of the offences established in accordance with this Convention, including, if the States Parties concerned deem it appropriate, links with other criminal activities;\n(b) To cooperate with other States Parties in conducting inquiries with respect to offences established in accordance with this Convention concerning:\n(c) To provide, where appropriate, necessary items or data for analytical or investigative purposes;\n(d) To exchange, where appropriate, information with other States Parties concerning specific means and methods used to commit the offences established in accordance with this Convention, including the use of false identities, forged, altered or false documents and other means of concealing activities, as well as cybercrime tactics, techniques and procedures;\n(e) To facilitate effective coordination between their competent authorities, agencies and services and to promote the exchange of personnel and other experts, including, subject to bilateral agreements or arrangements between the States Parties concerned, the posting of liaison officers;\n(f) To exchange information and coordinate administrative and other measures taken, as appropriate, for the purpose of early identification of the offences established in accordance with this Convention. With a view to giving effect to this Convention, States Parties shall consider entering into bilateral or multilateral agreements or arrangements on direct cooperation between their law enforcement agencies and, where such agreements or arrangements already exist, amending them. In the absence of such agreements or arrangements between the States Parties concerned, the States Parties may consider this Convention to be the basis for mutual law enforcement cooperation in respect of the offences established in accordance with this Convention. Whenever appropriate, States Parties shall make full use of agreements or arrangements, including international or regional organizations, to enhance the cooperation between their law enforcement agencies. Article 48 Joint investigations\nStates Parties shall consider concluding bilateral or multilateral agreements or arrangements whereby, in relation to offences established in accordance with this Convention that are the subject of criminal investigations, prosecutions or judicial proceedings in one or more States, the competent authorities concerned may establish joint investigative bodies. In the absence of such agreements or arrangements, joint investigations may be undertaken by agreement on a case-by-case basis. The States Parties involved shall ensure that the sovereignty of the State Party in whose territory such investigations are to take place is fully respected.\nArticle 49 Mechanisms for the recovery of property through international cooperation in confiscation\nEach State Party, in order to provide mutual legal assistance pursuant to article 50 of this Convention with respect to property acquired through or involved in the commission of an offence established in accordance with this Convention, shall, in accordance with its domestic law:\n(a) Take such measures as may be necessary to permit its competent authorities to give effect to an order of confiscation issued by a court of another State Party;\n(b) Take such measures as may be necessary to permit its competent authorities, where they have jurisdiction, to order the confiscation of such property of foreign origin by adjudication of an offence of money-laundering or such other offence as may be within its jurisdiction or by other procedures authorized under its domestic law; and\n(c) Consider taking such measures as may be necessary to allow confiscation of such property without a criminal conviction in cases in which the offender cannot be prosecuted by reason of death, flight or absence or in other appropriate cases. Each State Party, in order to provide mutual legal assistance upon a request made pursuant to article 50, paragraph 2, of this Convention, shall, in accordance with its domestic law:\n(a) Take such measures as may be necessary to permit its competent authorities to freeze or seize property upon a freezing or seizure order issued by a court or competent authority of a requesting State Party that provides a reasonable basis for the requested State Party to believe that there are sufficient grounds for taking such actions and that the property would eventually be subject to an order of confiscation for the purposes of paragraph 1 (a) of this article;\n(b) Take such measures as may be necessary to permit its competent authorities to freeze or seize property upon a request that provides a reasonable basis for the requested State Party to believe that there are sufficient grounds for taking such actions and that the property would eventually be subject to an order of confiscation for the purposes of paragraph 1 (a) of this article; and\n(c) Consider taking additional measures to permit its competent authorities to preserve property for confiscation, such as on the basis of a foreign arrest or criminal charge related to the acquisition of such property. Article 50 International cooperation for the purposes of confiscation\nA State Party that has received a request from another State Party having jurisdiction over an offence established in accordance with this Convention for the confiscation of proceeds of crime, property, equipment or other instrumentalities referred to in article 31, paragraph 1, of this Convention situated in its territory shall, to the greatest extent possible within its domestic legal system:\n(a) Submit the request to its competent authorities for the purpose of obtaining an order of confiscation and, if such an order is granted, give effect to it; or\n(b) Submit to its competent authorities, with a view to giving effect to it to the extent requested, an order of confiscation issued by a court in the territory of the requesting State Party in accordance with article 31, paragraph 1, of this Convention insofar as it relates to proceeds of crime, property, equipment or other instrumentalities situated in the territory of the requested State Party. Following a request made by another State Party having jurisdiction over an offence established in accordance with this Convention, the requested State Party shall take measures to identify, trace and freeze or seize proceeds of crime, property, equipment or other instrumentalities referred to in article 31, paragraph 1, of this Convention for the purpose of eventual confiscation to be ordered either by the requesting State Party or, pursuant to a request under paragraph 1 of this article, by the requested State Party. The provisions of article 40 of this Convention are applicable, mutatis mutandis, to this article. In addition to the information specified in article 40, paragraph 15, of this Convention, requests made pursuant to this article shall contain:\n(a) In the case of a request pertaining to paragraph 1 (a) of this article, a description of the property to be confiscated, including, to the extent possible, the location, and where relevant, the estimated value of the property and a statement of the facts relied upon by the requesting State Party sufficient to enable the requested State Party to seek the order under its domestic law;\n(b) In the case of a request pertaining to paragraph 1 (b) of this article, a legally admissible copy of an order of confiscation upon which the request is based issued by the requesting State Party, a statement of the facts and information as to the extent to which execution of the order is requested, a statement specifying the measures taken by the requesting State Party to provide adequate notification to bona fide third parties and to ensure due process, and a statement that the confiscation order is final;\n(c) In the case of a request pertaining to paragraph 2 of this article, a statement of the facts relied upon by the requesting State Party and a description of the actions requested and, where available, a legally admissible copy of an order on which the request is based. The decisions or actions provided for in paragraphs 1 and 2 of this article shall be taken by the requested State Party in accordance with and subject to the provisions of its domestic law and its procedural rules or any bilateral or multilateral treaty, agreement or arrangement to which it may be bound in relation to the requesting State Party. Each State Party shall furnish copies of its laws and regulations that give effect to this article and of any subsequent changes to such laws and regulations or a description thereof to the Secretary-General of the United Nations. If a State Party elects to make the taking of the measures referred to in paragraphs 1 and 2 of this article conditional on the existence of a relevant treaty, that State Party shall consider this Convention the necessary and sufficient treaty basis. Cooperation under this article may also be refused or provisional measures may be lifted if the requested State Party does not receive sufficient and timely evidence or if the property is of a de minimis value. Before lifting any provisional measure taken pursuant to this article, the requested State Party shall, wherever possible, give the requesting State Party an opportunity to present its reasons in favour of continuing the measure. The provisions of this article shall not be construed as prejudicing the rights of bona fide third parties. States Parties shall consider concluding bilateral or multilateral treaties, agreements or arrangements to enhance the effectiveness of international cooperation undertaken pursuant to this article. Article 51 Special cooperation\nWithout prejudice to its domestic law, each State Party shall endeavour to take measures to permit it to forward, without prejudice to its own criminal investigations, prosecutions or judicial proceedings, information on proceeds of offences established in accordance with this Convention to another State Party without prior request, when it considers that the disclosure of such information might assist the receiving State Party in initiating or carrying out criminal investigations, prosecutions or judicial proceedings or might lead to a request by that State Party under article 50 of this Convention.\nArticle 52 Return and disposal of confiscated proceeds of crime or property\nProceeds of crime or property confiscated by a State Party pursuant to article 31 or 50 of this Convention shall be disposed of by that State Party in accordance with its domestic law and administrative procedures. When acting on a request made by another State Party in accordance with article 50 of this Convention, States Parties shall, to the extent permitted by domestic law and if so requested, give priority consideration to returning the confiscated proceeds of crime or property to the requesting State Party so that it can give compensation to the victims of the crime or return such proceeds of crime or property to their prior legitimate owners. When acting on a request made by another State Party in accordance with articles 31 and 50 of this Convention, a State Party may, after due consideration has been given to compensation of victims, give special consideration to concluding agreements or arrangements on:\n(a) Contributing the value of such proceeds of crime or property or funds derived from the sale of such proceeds of crime or property or a part thereof to the account designated in accordance with article 56, paragraph 2 (c), of this Convention, and to intergovernmental bodies specializing in the fight against cybercrime;\n(b) Sharing with other States Parties, on a regular or case-by-case basis, such proceeds of crime or property, or funds derived from the sale of such proceeds of crime or property, in accordance with its domestic law or administrative procedures. Where appropriate, unless States Parties decide otherwise, the requested State Party may deduct reasonable expenses incurred in investigations, prosecutions or judicial proceedings leading to the return or disposition of confiscated property pursuant to this article. Chapter VI: Preventive measures Article 53 Preventive measures\nEach State Party shall endeavour, in accordance with fundamental principles of its legal system, to develop and implement or maintain effective and coordinated policies and best practices to reduce existing or future opportunities for cybercrime through appropriate legislative, administrative or other measures. Each State Party shall take appropriate measures, within its means and in accordance with fundamental principles of its domestic law, to promote the active participation of relevant individuals and entities outside the public sector, such as non-governmental organizations, civil society organizations, academic institutions and private sector entities, as well as the general public, in the relevant aspects of prevention of the offences established in accordance with this Convention. Preventive measures may include:\n(a) Strengthening cooperation between law enforcement agencies or prosecutors and relevant individuals and entities outside the public sector, such as non-governmental organizations, civil society organizations, academic institutions and private sector entities for the purpose of addressing relevant aspects of preventing and combating the offences established in accordance with this Convention;\n(b) Promoting public awareness regarding the existence, causes and gravity of the threat posed by the offences established in accordance with this Convention through public information activities, public education, media and information literacy programmes and curricula that promote public participation in preventing and combating such offences;\n(c) Building and making efforts to increase the capacity of domestic criminal justice systems, including training and developing expertise among criminal justice practitioners, as part of national prevention strategies against the offences established in accordance with this Convention;\n(d) Encouraging service providers to take effective measures, where feasible in the light of national circumstances and to the extent permitted by domestic law, to strengthen the security of the service providers’ products, services and customers;\n(e) Recognizing the contributions of the legitimate activities of security researchers when intended solely, and to the extent permitted and subject to the conditions prescribed by domestic law, to strengthen and improve the security of service providers’ products, services and customers located within the territory of the State Party;\n(f) Developing, facilitating and promoting programmes and activities in order to discourage those at risk of engaging in cybercrime from becoming offenders and to develop their skills in a lawful manner;\n(g) Endeavouring to promote the reintegration into society of persons convicted of offences established in accordance with this Convention;\n(h) Developing strategies and policies, in accordance with domestic law, to prevent and eradicate gender-based violence that occurs through the use of an information and communications technology system, as well as taking into consideration the special circumstances and needs of persons in vulnerable situations in developing preventive measures;\n(i) Undertaking specific and tailored efforts to keep children safe online, including through education and training on and raising public awareness of child sexual abuse or child sexual exploitation online and through revising domestic legal frameworks and enhancing international cooperation aimed at its prevention, as well as making efforts to ensure the swift removal of child sexual abuse and child sexual exploitation material;\n(j) Enhancing the transparency of and promoting the contribution of the public to decision-making processes and ensuring that the public has adequate access to information;\n(k) Respecting, promoting and protecting the freedom to seek, receive and impart public information concerning cybercrime;\n(l) Developing or strengthening support programmes for victims of the offences established in accordance with this Convention;\n(m) Preventing and detecting transfers of proceeds of crime and property related to the offences established in accordance with this Convention. Each State Party shall take appropriate measures to ensure that the relevant competent authority or authorities responsible for preventing and combating cybercrime are known and accessible to the public, where appropriate, for the reporting, including anonymously, of any incident that may be considered a criminal offence established in accordance with this Convention. States Parties shall endeavour to periodically evaluate existing relevant national legal frameworks and administrative practices with a view to identifying gaps and vulnerabilities and ensuring their relevance in the face of changing threats posed by the offences established in accordance with this Convention. States Parties may collaborate with each other and with relevant international and regional organizations in promoting and developing the measures referred to in this article. This includes participation in international projects aimed at the prevention of cybercrime. Each State Party shall inform the Secretary-General of the United Nations of the name and address of the authority or authorities that may assist other States Parties in developing and implementing specific measures to prevent cybercrime. Chapter VII: Technical assistance and information exchange Article 54 Technical assistance and capacity-building\nStates Parties shall, according to their capacity, consider affording one another the widest measure of technical assistance and capacity-building, including training and other forms of assistance, the mutual exchange of relevant experience and specialized knowledge and the transfer of technology on mutually agreed terms, taking into particular consideration the interests and needs of developing States Parties, with a view to facilitating the prevention, detection, investigation and prosecution of the offences covered by this Convention. States Parties shall, to the extent necessary, initiate, develop, implement or improve specific training programmes for their personnel responsible for the prevention, detection, investigation and prosecution of the offences covered by this Convention. Activities referred to in paragraphs 1 and 2 of this article may deal, to the extent permitted by domestic law, with the following:\n(a) Methods and techniques used in the prevention, detection, investigation and prosecution of the offences covered by this Convention;\n(b) Building capacity in the development and planning of strategic policies and legislation to prevent and combat cybercrime;\n(c) Building capacity in the collection, preservation and sharing of evidence, in particular in electronic form, including the maintenance of the chain of custody and forensic analysis;\n(d) Modern law enforcement equipment and the use thereof;\n(e) Training of competent authorities in the preparation of requests for mutual legal assistance and other means of cooperation that meet the requirements of this Convention, especially for the collection, preservation and sharing of evidence in electronic form;\n(f) Prevention, detection and monitoring of the movements of proceeds deriving from the commission of the offences covered by this Convention, property, equipment or other instrumentalities and methods used for the transfer, concealment or disguise of such proceeds, property, equipment or other instrumentalities;\n(g) Appropriate and efficient legal and administrative mechanisms and methods for facilitating the seizure, confiscation and return of proceeds of offences covered by this Convention;\n(h) Methods used in the protection of victims and witnesses who cooperate with judicial authorities;\n(i) Training in relevant substantive and procedural law, and law enforcement investigation powers, as well as in national and international regulations and in languages. States Parties shall, subject to their domestic law, endeavour to leverage the expertise of and cooperate closely with other States Parties and relevant international and regional organizations, non-governmental organizations, civil society organizations, academic institutions and private sector entities, with a view to enhancing the effective implementation of this Convention. States Parties shall assist one another in planning and implementing research and training programmes designed to share expertise in the areas referred to in paragraph 3 of this article, and to that end shall also, when appropriate, use regional and international conferences and seminars to promote cooperation and to stimulate discussion on problems of mutual concern. States Parties shall consider assisting one another, upon request, in conducting evaluations, studies and research relating to the types, causes and effects of offences covered by this Convention committed in their respective territories, with a view to developing, with the participation of the competent authorities and relevant non‑governmental organizations, civil society organizations, academic institutions and private sector entities, strategies and action plans to prevent and combat cybercrime. States Parties shall promote training and technical assistance that facilitates timely extradition and mutual legal assistance. Such training and technical assistance may include language training, assistance with the drafting and handling of mutual legal assistance requests, and secondments and exchanges between personnel in central authorities or agencies with relevant responsibilities. States Parties shall strengthen, to the extent necessary, efforts to maximize the effectiveness of technical assistance and capacity-building in international and regional organizations and in the framework of relevant bilateral and multilateral agreements or arrangements. States Parties shall consider establishing voluntary mechanisms with a view to contributing financially to the efforts of developing countries to implement this Convention through technical assistance programmes and capacity-building projects. Each State Party shall endeavour to make voluntary contributions to the United Nations Office on Drugs and Crime for the purpose of fostering, through the Office, programmes and projects with a view to implementing this Convention through technical assistance and capacity-building. Article 55 Exchange of information\nEach State Party shall consider analysing, as appropriate, in consultation with relevant experts, including from non-governmental organizations, civil society organizations, academic institutions and private sector entities, trends in its territory with respect to offences covered by this Convention, as well as the circumstances in which such offences are committed. States Parties shall consider developing and sharing with each other and through international and regional organizations statistics, analytical expertise and information concerning cybercrime, with a view to developing, insofar as possible, common definitions, standards and methodologies, as well as best practices, to prevent and combat such crime. Each State Party shall consider monitoring its policies and practical measures to prevent and combat offences covered by this Convention and making assessments of their effectiveness and efficiency. States Parties shall consider exchanging information on legal, policy and technological developments related to cybercrime and the collection of evidence in electronic form. Article 56 Implementation of the Convention through economic development and technical assistance\nStates Parties shall take measures conducive to the optimal implementation of this Convention to the extent possible, through international cooperation, taking into account the negative effects of the offences covered by this Convention on society in general and, in particular, on sustainable development. States Parties are strongly encouraged to make concrete efforts, to the extent possible and in coordination with each other, as well as with international and regional organizations:\n(a) To enhance their cooperation at various levels with other States Parties, in particular developing countries, with a view to strengthening their capacity to prevent and combat the offences covered by this Convention;\n(b) To enhance financial and material assistance to support the efforts of other States Parties, in particular developing countries, in effectively preventing and combating the offences covered by this Convention and to help them to implement this Convention;\n(c) To provide technical assistance to other States Parties, in particular developing countries, in support of meeting their needs regarding the implementation of this Convention. To that end, States Parties shall endeavour to make adequate and regular voluntary contributions to an account specifically designated for that purpose in a United Nations funding mechanism;\n(d) To encourage, as appropriate, non-governmental organizations, civil society organizations, academic institutions and private sector entities, as well as financial institutions, to contribute to the efforts of States Parties, including in accordance with this article, in particular by providing more training programmes and modern equipment to developing countries in order to assist them in achieving the objectives of this Convention;\n(e) To exchange best practices and information with regard to activities undertaken, with a view to improving transparency, avoiding duplication of effort and making best use of any lessons learned. States Parties shall also consider using existing subregional, regional and international programmes, including conferences and seminars, to promote cooperation and technical assistance and to stimulate discussion on problems of mutual concern, including the special problems and needs of developing countries. To the extent possible, States Parties shall ensure that resources and efforts are distributed and directed to support the harmonization of standards, skills, capacity, expertise and technical capabilities with the aim of establishing common minimum standards among States Parties to eradicate safe havens for the offences covered by this Convention and strengthen the fight against cybercrime. To the extent possible, the measures taken under this article shall be without prejudice to existing foreign assistance commitments or to other financial cooperation arrangements at the bilateral, regional or international levels. States Parties may conclude bilateral, regional or multilateral agreements or arrangements on material and logistical assistance, taking into consideration the financial arrangements necessary for the means of international cooperation provided for by this Convention to be effective and for the prevention, detection, investigation and prosecution of the offences covered by this Convention. Chapter VIII: Mechanism of implementation Article 57 Conference of the States Parties to the Convention\nA Conference of the States Parties to the Convention is hereby established to improve the capacity of and cooperation between States Parties to achieve the objectives set forth in this Convention and to promote and review its implementation. The Secretary-General of the United Nations shall convene the Conference of the States Parties not later than one year following the entry into force of this Convention. Thereafter, regular meetings of the Conference shall be held in accordance with the rules of procedure adopted by the Conference. The Conference of the States Parties shall adopt rules of procedure and rules governing the activities set forth in this article, including rules concerning the admission and participation of observers, and the payment of expenses incurred in carrying out those activities. Such rules and related activities shall take into account principles such as effectiveness, inclusivity, transparency, efficiency and national ownership. In establishing its regular meetings, the Conference of the States Parties shall take into account the time and location of the meetings of other relevant international and regional organizations and mechanisms in similar matters, including their subsidiary treaty bodies, consistent with the principles identified in paragraph 3 of this article. The Conference of the States Parties shall agree upon activities, procedures and methods of work to achieve the objectives set forth in paragraph 1 of this article, including:\n(a) Facilitating the effective use and implementation of this Convention, the identification of any problems thereof, as well as the activities carried out by States Parties under this Convention, including encouraging the mobilization of voluntary contributions;\n(b) Facilitating the exchange of information on legal, policy and technological developments pertaining to the offences established in accordance with this Convention and the collection of evidence in electronic form among States Parties and relevant international and regional organizations, as well as non-governmental organizations, civil society organizations, academic institutions and private sector entities, in accordance with domestic law, as well as on patterns and trends in cybercrime and on successful practices for preventing and combating such offences;\n(c) Cooperating with relevant international and regional organizations, as well as non-governmental organizations, civil society organizations, academic institutions and private sector entities;\n(d) Making appropriate use of relevant information produced by other international and regional organizations and mechanisms for preventing and combating the offences established in accordance with this Convention, in order to avoid unnecessary duplication of work;\n(e) Reviewing periodically the implementation of this Convention by its States Parties;\n(f) Making recommendations to improve this Convention and its implementation as well as considering possible supplementation or amendment of the Convention;\n(g) Elaborating and adopting supplementary protocols to this Convention on the basis of articles 61 and 62 of this Convention;\n(h) Taking note of the technical assistance and capacity-building requirements of States Parties regarding the implementation of this Convention and recommending any action it may deem necessary in that respect. Each State Party shall provide the Conference of the States Parties with information on legislative, administrative and other measures, as well as on its programmes, plans and practices, to implement this Convention, as required by the Conference. The Conference shall examine the most effective way of receiving and acting upon information, including, inter alia, information received from States Parties and from competent international and regional organizations. Inputs received from representatives of relevant non-governmental organizations, civil society organizations, academic institutions and private sector entities, duly accredited in accordance with procedures to be decided upon by the Conference, may also be considered. For the purpose of paragraph 5 of this article, the Conference of the States Parties may establish and administer such review mechanisms as it considers necessary. Pursuant to paragraphs 5 to 7 of this article, the Conference of the States Parties shall establish, if it deems necessary, any appropriate mechanisms or subsidiary bodies to assist in the effective implementation of the Convention. Article 58 Secretariat\nThe Secretary-General of the United Nations shall provide the necessary secretariat services to the Conference of the States Parties to the Convention. The secretariat shall:\n(a) Assist the Conference of the States Parties in carrying out the activities set forth in this Convention and make arrangements and provide the necessary services for the sessions of the Conference as they pertain to this Convention;\n(b) Upon request, assist States Parties in providing information to the Conference of the States Parties, as envisaged in this Convention; and\n(c) Ensure the necessary coordination with the secretariats of relevant international and regional organizations. Chapter IX: Final provisions Article 59 Implementation of the Convention\nEach State Party shall take the necessary measures, including legislative and administrative measures, in accordance with fundamental principles of its domestic law, to ensure the implementation of its obligations under this Convention. Each State Party may adopt more strict or severe measures than those provided for by this Convention for preventing and combating the offences established in accordance with this Convention. Article 60 Effects of the Convention\nIf two or more States Parties have already concluded an agreement or treaty on the matters dealt with in this Convention or have otherwise established their relations on such matters, or should they in future do so, they shall also be entitled to apply that agreement or treaty or to regulate those relations accordingly. Nothing in this Convention shall affect other rights, restrictions, obligations and responsibilities of a State Party under international law. Article 61 Relation with protocols\nThis Convention may be supplemented by one or more protocols. In order to become a Party to a protocol, a State or a regional economic integration organization must also be a Party to this Convention. A State Party to this Convention is not bound by a protocol unless it becomes a Party to the protocol in accordance with the provisions thereof. Any protocol to this Convention shall be interpreted together with this Convention, taking into account the purpose of that protocol. Article 62 Adoption of supplementary protocols\nAt least 60 States Parties shall be required before any supplementary protocol is considered for adoption by the Conference of the States Parties. The Conference shall make every effort to achieve consensus on any supplementary protocol. If all efforts at consensus have been exhausted and no agreement has been reached, the supplementary protocol shall, as a last resort, require for its adoption at least a two‑thirds majority vote of the States Parties present and voting at the meeting of the Conference. Regional economic integration organizations, in matters within their competence, shall exercise their right to vote under this article with a number of votes equal to the number of their member States that are Parties to this Convention. Such organizations shall not exercise their right to vote if their member States exercise theirs and vice versa. Article 63 Settlement of disputes\nStates Parties shall endeavour to settle disputes concerning the interpretation or application of this Convention through negotiation or any other peaceful means of their own choice. Any dispute between two or more States Parties concerning the interpretation or application of this Convention that cannot be settled through negotiation or other peaceful means within a reasonable time shall, at the request of one of those States Parties, be submitted to arbitration. If, six months after the date of the request for arbitration, those States Parties are unable to agree on the organization of the arbitration, any one of those States Parties may refer the dispute to the International Court of Justice by request in accordance with the Statute of the Court. Each State Party may, at the time of signature, ratification, acceptance or approval of or accession to this Convention, declare that it does not consider itself bound by paragraph 2 of this article. The other States Parties shall not be bound by paragraph 2 of this article with respect to any State Party that has made such a reservation. Any State Party that has made a reservation in accordance with paragraph 3 of this article may at any time withdraw that reservation by notification to the Secretary-General of the United Nations. Article 64 Signature, ratification, acceptance, approval and accession\nThis Convention shall be open to all States for signature in Hanoi in 2025 and thereafter at United Nations Headquarters in New York until 31 December 2026. This Convention shall also be open for signature by regional economic integration organizations, provided that at least one member State of such an organization has signed this Convention in accordance with paragraph 1 of this article. This Convention is subject to ratification, acceptance or approval. Instruments of ratification, acceptance or approval shall be deposited with the Secretary-General of the United Nations. A regional economic integration organization may deposit its instrument of ratification, acceptance or approval if at least one of its member States has done likewise. In that instrument of ratification, acceptance or approval, such organization shall declare the extent of its competence with respect to the matters governed by this Convention. Such organization shall also inform the depositary of any relevant modification in the extent of its competence. This Convention is open for accession by any State or any regional economic integration organization of which at least one member State is a Party to this Convention. Instruments of accession shall be deposited with the Secretary-General of the United Nations. At the time of its accession, a regional economic integration organization shall declare the extent of its competence with respect to matters governed by this Convention. Such organization shall also inform the depositary of any relevant modification in the extent of its competence. Article 65 Entry into force\nThis Convention shall enter into force on the ninetieth day after the date of deposit of the fortieth instrument of ratification, acceptance, approval or accession. For the purpose of this paragraph, any instrument deposited by a regional economic integration organization shall not be counted as additional to those deposited by member States of that organization. For each State or regional economic integration organization ratifying, accepting, approving or acceding to this Convention after the deposit of the fortieth instrument of such action, this Convention shall enter into force on the thirtieth day after the date of deposit by such State or organization of the relevant instrument or on the date on which this Convention enters into force pursuant to paragraph 1 of this article, whichever is later. Article 66 Amendment\nAfter the expiry of five years from the entry into force of this Convention, a State Party may propose an amendment and transmit it to the Secretary-General of the United Nations, who shall thereupon communicate the proposed amendment to the States Parties and to the Conference of the States Parties to the Convention for the purpose of considering and deciding on the proposal. The Conference shall make every effort to achieve consensus on each amendment. If all efforts at consensus have been exhausted and no agreement has been reached, the amendment shall, as a last resort, require for its adoption a two-thirds majority vote of the States Parties present and voting at the meeting of the Conference. Regional economic integration organizations, in matters within their competence, shall exercise their right to vote under this article with a number of votes equal to the number of their member States that are Parties to this Convention. Such organizations shall not exercise their right to vote if their member States exercise theirs and vice versa. An amendment adopted in accordance with paragraph 1 of this article is subject to ratification, acceptance or approval by States Parties. An amendment adopted in accordance with paragraph 1 of this article shall enter into force in respect of a State Party 90 days after the date of the deposit with the Secretary-General of the United Nations of an instrument of ratification, acceptance or approval of such amendment. When an amendment enters into force, it shall be binding on those States Parties that have expressed their consent to be bound by it. Other States Parties shall still be bound by the provisions of this Convention and any earlier amendments that they have ratified, accepted or approved. Article 67 Denunciation\nA State Party may denounce this Convention by written notification to the Secretary-General of the United Nations. Such denunciation shall become effective one year after the date of receipt of the notification by the Secretary-General. A regional economic integration organization shall cease to be a Party to this Convention when all of its member States have denounced it. Denunciation of this Convention in accordance with paragraph 1 of this article shall entail the denunciation of any protocols thereto. Article 68 Depositary and languages\nThe Secretary-General of the United Nations is designated depositary of this Convention. The original of this Convention, of which the Arabic, Chinese, English, French, Russian and Spanish texts are equally authentic, shall be deposited with the Secretary-General of the United Nations.\nIN WITNESS WHEREOF, the undersigned plenipotentiaries, being duly authorized thereto by their respective Governments, have signed this Convention. ","permalink":"https://ai.intlaws.com/en/compliance/intl/un-cybercrime-convention/","summary":"Officialof the UN Convention against Cybercrime (UNGA resolution 79/243, 24 December 2024, annex; 9 chapters, 68 articles). Enters into force on the ninetieth day after deposit of the fortieth instrument of ratification; not yet in force. Text taken from official UN sources.","title":"United Nations Convention against Cybercrime"},{"content":" 版本与来源（可核验）\n项目 内容 通过与公布 2024 年 3 月 22 日国家互联网信息办公室令第 16 号公布 施行日期 2024 年 3 月 22 日（公布之日起施行） 现行有效 是（截至 2026-09-22） 中文原文来源 https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm 英文译本 无官方英译本。本页英文译本已完成：由本网据官方中文文本翻译并逐条交叉校核，标注为非官方译本、仅供参考 → 英文全文 校对记录 2026-09-22 抓取官方页面；共 14 条，条号连续、无缺号 第一条 为了保障数据安全，保护个人信息权益，促进数据依法有序自由流动，根据《中华人民共和国网络安全法》、《中华人民共和国数据安全法》、《中华人民共和国个人信息保护法》等法律法规，对于数据出境安全评估、个人信息出境标准合同、个人信息保护认证等数据出境制度的施行，制定本规定。\n第二条 数据处理者应当按照相关规定识别、申报重要数据。未被相关部门、地区告知或者公开发布为重要数据的，数据处理者不需要作为重要数据申报数据出境安全评估。\n第三条 国际贸易、跨境运输、学术合作、跨国生产制造和市场营销等活动中收集和产生的数据向境外提供，不包含个人信息或者重要数据的，免予申报数据出境安全评估、订立个人信息出境标准合同、通过个人信息保护认证。\n第四条 数据处理者在境外收集和产生的个人信息传输至境内处理后向境外提供，处理过程中没有引入境内个人信息或者重要数据的，免予申报数据出境安全评估、订立个人信息出境标准合同、通过个人信息保护认证。\n第五条 数据处理者向境外提供个人信息，符合下列条件之一的，免予申报数据出境安全评估、订立个人信息出境标准合同、通过个人信息保护认证：\n（一）为订立、履行个人作为一方当事人的合同，如跨境购物、跨境寄递、跨境汇款、跨境支付、跨境开户、机票酒店预订、签证办理、考试服务等，确需向境外提供个人信息的；\n（二）按照依法制定的劳动规章制度和依法签订的集体合同实施跨境人力资源管理，确需向境外提供员工个人信息的；\n（三）紧急情况下为保护自然人的生命健康和财产安全，确需向境外提供个人信息的；\n（四）关键信息基础设施运营者以外的数据处理者自当年1月1日起累计向境外提供不满10万人个人信息（不含敏感个人信息）的。\n前款所称向境外提供的个人信息，不包括重要数据。\n第六条 自由贸易试验区在国家数据分类分级保护制度框架下，可以自行制定区内需要纳入数据出境安全评估、个人信息出境标准合同、个人信息保护认证管理范围的数据清单（以下简称负面清单），经省级网络安全和信息化委员会批准后，报国家网信部门、国家数据管理部门备案。\n自由贸易试验区内数据处理者向境外提供负面清单外的数据，可以免予申报数据出境安全评估、订立个人信息出境标准合同、通过个人信息保护认证。\n第七条 数据处理者向境外提供数据，符合下列条件之一的，应当通过所在地省级网信部门向国家网信部门申报数据出境安全评估：\n（一）关键信息基础设施运营者向境外提供个人信息或者重要数据；\n（二）关键信息基础设施运营者以外的数据处理者向境外提供重要数据，或者自当年1月1日起累计向境外提供100万人以上个人信息（不含敏感个人信息）或者1万人以上敏感个人信息。\n属于本规定第三条、第四条、第五条、第六条规定情形的，从其规定。\n第八条 关键信息基础设施运营者以外的数据处理者自当年1月1日起累计向境外提供10万人以上、不满100万人个人信息（不含敏感个人信息）或者不满1万人敏感个人信息的，应当依法与境外接收方订立个人信息出境标准合同或者通过个人信息保护认证。\n属于本规定第三条、第四条、第五条、第六条规定情形的，从其规定。\n第九条 通过数据出境安全评估的结果有效期为3年，自评估结果出具之日起计算。有效期届满，需要继续开展数据出境活动且未发生需要重新申报数据出境安全评估情形的，数据处理者可以在有效期届满前60个工作日内通过所在地省级网信部门向国家网信部门提出延长评估结果有效期申请。经国家网信部门批准，可以延长评估结果有效期3年。\n第十条 数据处理者向境外提供个人信息的，应当按照法律、行政法规的规定履行告知、取得个人单独同意、进行个人信息保护影响评估等义务。\n第十一条 数据处理者向境外提供数据的，应当遵守法律、法规的规定，履行数据安全保护义务，采取技术措施和其他必要措施，保障数据出境安全。发生或者可能发生数据安全事件的，应当采取补救措施，及时向省级以上网信部门和其他有关主管部门报告。\n第十二条 各地网信部门应当加强对数据处理者数据出境活动的指导监督，健全完善数据出境安全评估制度，优化评估流程；强化事前事中事后全链条全领域监管，发现数据出境活动存在较大风险或者发生数据安全事件的，要求数据处理者进行整改，消除隐患；对拒不改正或者造成严重后果的，依法追究法律责任。\n第十三条 2022年7月7日公布的《数据出境安全评估办法》（国家互联网信息办公室令第11号）、2023年2月22日公布的《个人信息出境标准合同办法》（国家互联网信息办公室令第13号）等相关规定与本规定不一致的，适用本规定。\n第十四条 本规定自公布之日起施行。\n条款关系说明（辅助区块，非条文）\n《数据出境安全评估办法》第十九条为\u0026quot;重要数据\u0026quot;提供识别标准；《促进和规范数据跨境流动规定》第二条及《网络数据安全管理条例》第三十七条明确申报义务以监管部门告知或公开发布为前提。两者是\u0026quot;定义\u0026quot;与\u0026quot;程序\u0026quot;的关系，并非冲突；重要数据的认定权在监管部门，数据处理者不负自认义务。\n","permalink":"https://ai.intlaws.com/compliance/china/data-cross-border-flow-provisions/","summary":"《促进和规范数据跨境流动规定》官方文本：国家互联网信息办公室令第 16 号，2024 年 3 月 22 日公布并施行；调整数据出境安全评估适用门槛（个人信息 100 万人）、明确五类免予申报情形。","title":"促进和规范数据跨境流动规定"},{"content":" 版本与来源(可核验)\n项 内容 法案 HB 149(德州第 89 届议会)——即《德州负责任人工智能治理法》(TRAIGA) 创设条文 该法案创设《商业与商业法典》第 551–554 章;本页收录其中第 552 章“人工智能保护”全文 生效 2026 年 1 月 1 日(经核验:法案第 10 条“本法自 2026 年 1 月 1 日起生效”) 结构 第 552 章共 16 条:第 552.001–552.003 条(分章 A 一般规定)、第 552.051–552.057 条(分章 B 人工智能使用中的义务与禁止)、第 552.101–552.106 条(分章 C 执法) 官方原文 已登记法案文本(HB 149) 收录范围说明 本页仅收录第 552 章;同一法案另创设第 551 章(一般规定)、第 553 章(AI 监管沙盒计划)、第 554 章(德州人工智能委员会),本页未收录 中文译本 无官方中文文本。本页中文译文本网译,据官方英文文本逐条逐款译出,为非官方译本、仅供参考 核对记录 2026-09-24 从德州议会公布的已登记法案文本逐条核对;条号(552.001–552.106)、款项层级与生效日期逐处核验一致 译例说明(本网译)\n原文款项层级与中文层级对应如下:条内第一层级 \u0026ldquo;(a)、(b)、(c)……\u0026rdquo; 译作 \u0026ldquo;一、二、三、……\u0026quot;;第二层级 \u0026ldquo;(1)、(2)、(3)……\u0026rdquo; 译作 \u0026ldquo;(一)、(二)、(三)、……\u0026quot;;第三层级 \u0026ldquo;(A)、(B)、(C)……\u0026rdquo; 译作 \u0026ldquo;1. 2. 3. ……\u0026quot;;第四层级 \u0026ldquo;(i)、(ii)、(iii)……\u0026rdquo; 译作 \u0026ldquo;(1)、(2)、(3)、……\u0026quot;。无款项之条,其项按所处层级顺次对应。 “个人”(person)在德州制定法中包括自然人、法人及其他实体;“政治分区”(political subdivision)指州之下地方行政单位。 文中引用的其他法典条文(如《刑法典》第 43.26 条、《金融法典》第 201.101 条等)保留原条号,未译出其内容。 个别语句如与官方编纂文本表述存在出入,以[未证实]标注;本次核验中未出现该等情形。 第 552 章 人工智能保护 分章 A 一般规定 第 552.001 条 定义\n在本章中:\n一、“部署者”指在本州部署人工智能系统以供使用的人。\n二、“开发者”指开发在本州被提供、出售、出租、赠予或以其他方式供应的人工智能系统的人。\n三、“政府实体”指本州或本州任何政治分区的、依本州法律授权行使政府职能的任何部门、委员会、董事会、办公室、机关或其他行政单位。该术语不包括:\n依《健康与安全法典》或《得克萨斯州宪法》第九条设立的医院区;或\n经《教育法典》第 61.003 条定义的高等教育机构,包括任何大学系统或该系统的任何组成机构。\n第 552.002 条 本章的解释\n本章不得被解释为:\n一、对个人施加对任何人的权利或自由(包括言论自由权)造成不利影响的要求;或\n二、授权除保险局(Department of Insurance)以外的任何部门或机构监管或监督保险业务。\n第 552.003 条 地方先占\n本章取代并优先于政治分区就人工智能系统的使用通过的任何法令、决议、规则或其他法规。\n分章 B 人工智能使用中的义务与禁止 第 552.051 条 向消费者披露\n一、本条中,“医疗服务”指由依适用的州法或联邦法获得许可、登记或认证以提供该等服务的个人所提供的、与人类健康或人类疾病或损伤的诊断、预防或治疗相关的服务。\n二、提供旨在与消费者互动的人工智能系统的政府机构,应当在互动之前或互动之时向每名消费者披露该消费者正在与人工智能系统互动。\n三、无论对于合理消费者而言该消费者正在与人工智能系统互动是否显而易见,个人均须依本条第二款作出披露。\n四、依本条第二款作出的披露:\n(一)必须清晰且醒目;\n(二)必须以平实语言书写;且\n(三)不得使用《商业与商业法典》第 541.001 条所定义的“黑暗模式”(dark pattern)。\n五、依本条第二款作出的披露,可通过使用超链接将消费者引导至单独的互联网网页的方式提供。\n六、如人工智能系统被用于与医疗服务或治疗相关的事项,服务或治疗的提供者应当不迟于首次提供服务或治疗之日,向服务或治疗的接受者或接受者的个人代表提供本条第二款规定的披露;但紧急情况除外,在此情形下,提供者应当在合理可行时尽快提供所要求的披露。\n第 552.052 条 操纵人类行为\n个人不得以故意旨在煽动或鼓励他人实施下列行为的方式开发或部署人工智能系统:\n一、实施身体自伤,包括自杀;\n二、伤害他人;或\n三、从事犯罪活动。\n第 552.053 条 社会评分\n政府实体不得使用或部署对自然人或自然人群体基于社会行为或个人特征(无论已知、推断还是预测)进行评价或分类的人工智能系统,其意图在于计算或赋予该人或该群体社会评分或类似的分级性评估或估值,并导致或可能导致:\n一、在与社会行为或特征被观察或注意到的情境无关的社会情境中,对该人或该群体造成不利或不良待遇;\n二、对该人或该群体造成与所观察或注意到的社会行为或特征的性质或严重程度不相称或无正当理由的不利或不良待遇;或\n三、侵犯依《美国宪法》、《得克萨斯州宪法》或州法或联邦法所保障的任何权利。\n第 552.054 条 生物识别数据的采集\n一、本条中,“生物识别数据”指通过对个人的生物特征进行自动测量而产生的数据。该术语包括指纹、声纹、眼视网膜或虹膜,或用于识别特定个人的其他独特生物模式或特征。该术语不包括实体或数字照片或由实体或数字照片产生的数据、视频或音频记录或由视频或音频记录产生的数据,或依 1996 年《健康保险可携性与责任法》(《美国法典》第 42 编第 1320d 条及以下各条)为医疗保健的治疗、支付或运营而收集、使用或存储的信息。\n二、政府实体不得为下列目的开发或部署人工智能系统:以生物识别数据唯一识别特定个人;或在未经个人同意的情况下,从互联网或任何其他公开可得来源定向或非定向收集图像或其他媒体——前提是该收集会侵犯该个人依《美国宪法》、《得克萨斯州宪法》或州法或联邦法享有的任何权利。\n三、违反《商业与商业法典》第 503.001 条即构成对本条的违反。\n第 552.055 条 宪法保护\n一、个人不得以人工智能系统侵犯、限制或以其他方式损害个人依《美国宪法》所保障的权利为唯一意图,开发或部署该人工智能系统。\n二、本条以补救为目的,不得被解释为创设或扩大《美国宪法》所保障的任何权利。\n第 552.056 条 非法歧视\n一、本条中:\n(一)“金融机构”具有《金融法典》第 201.101 条所赋予的含义。\n(二)“保险实体”指:\n《保险法典》第 82.002(a) 条所描述的实体;\n依《保险法典》第 885 章受监管的兄弟会福利社团;或\n(A)项或(B)项所描述的实体所使用的人工智能系统的开发者。\n(三)“受保护群体”指其某一特征、品质、信仰或身份受州或联邦民权法保护以免受歧视的群体或类别,包括种族、肤色、民族血统、性别、年龄、宗教或残疾。\n二、个人不得以违反州法或联邦法对受保护群体实施非法歧视的意图,开发或部署人工智能系统。\n三、就本条而言,仅存在差别影响(disparate impact)本身不足以证明具有歧视的意图。\n四、就提供保险服务而言,本条不适用于保险实体,前提是该实体受规范与保险业务相关的不公平歧视、不公平竞争方法或不公平或欺骗性行为或做法的可适用制定法约束。\n五、联邦保险的金融机构如遵守所有联邦和州银行法律及法规,即视为符合本条。\n第 552.057 条 特定色情内容与儿童色情物品\n个人不得:\n一、以生产、协助或帮助生产或分发下列内容的唯一意图,开发或分发人工智能系统:\n违反《刑法典》第 43.26 条的视觉材料;或\n违反《刑法典》第 21.165 条的深度伪造(deep fake)视频或图像;或\n二、故意开发或分发在冒充或模仿不满 18 岁儿童的同时,从事模拟或描述《刑法典》第 43.25 条所定义的性行为的基于文本对话的人工智能系统。\n分章 C 执法 第 552.101 条 执法权\n一、除第 552.106 条所规定的范围外,总检察长对本章的执法享有专属权力。\n二、本章不为违反本章或任何其他法律的行为提供私人诉讼权的依据,该等行为亦不受私人诉讼权约束。\n第 552.102 条 信息与投诉\n总检察长应当在其互联网网站上建立并维护一种在线机制,消费者可通过该机制依本章向总检察长提交投诉。\n第 552.103 条 调查权\n一、如总检察长通过第 552.102 条规定的在线机制收到指控违反本章的投诉,总检察长可发出民事调查要求(civil investigative demand),以确定是否已发生违反。总检察长应当依照《商业与商业法典》第 15.10 条所确立的程序并根据该程序发出该等要求。\n二、总检察长可依本条第一款发出的民事调查要求,向通过该在线机制被举报的个人要求提供:\n(一)对该个人所关联的人工智能系统的目的、预期用途、部署情境及相关益处的概要描述;\n(二)对用于编程或训练该人工智能系统的数据类型的描述;\n(三)对作为该人工智能系统输入而被处理的数据类别的概要描述;\n(四)对该人工智能系统所产生的输出的概要描述;\n(五)该个人用于评估该人工智能系统性能的任何指标;\n(六)该人工智能系统的任何已知局限;\n(七)对该个人就该人工智能系统所采用的部署后监测和用户保障措施的概要描述,包括在该个人为部署者的情况下,该个人为处理因系统部署所产生的问题而建立的监督、使用和学习流程;或\n(八)总检察长依本条开展调查所合理必需的任何其他相关文件。\n第 552.104 条 违规通知;补救机会\n一、如总检察长认定个人已违反或正在违反本章,总检察长应当就该认定书面通知该个人,并指明总检察长指称已被违反或正在被违反的本章具体规定。\n二、总检察长不得在下列情形下对该个人提起诉讼:\n(一)在总检察长依本条第一款提供通知之日后第 60 日之前;或\n(二)如在总检察长依本条第一款提供通知之日后第 60 日之前,该个人:\n补救了所认定的违反;且\n向总检察长提供书面声明,载明该个人:\n(1)已补救被指称的违反;\n(2)已提供支持性文件,以表明该个人补救该违反的方式;且\n(3)已对内部政策作出任何必要变更,以合理防止进一步违反本章。\n第 552.105 条 民事罚款;禁令\n一、违反本章且未依第 552.104 条补救该违反的个人,应当就下列金额向本州承担民事罚款责任:\n(一)对法院认定为可补救的每项违反,或对违反依第 552.104 条第二款第(二)项向总检察长提交的声明的行为,不低于 10,000 美元且不超过 12,000 美元;\n(二)对法院认定为不可补救的每项违反,不低于 80,000 美元且不超过 200,000 美元;且\n(三)对持续违反,该违反持续的每一日不低于 2,000 美元且不超过 40,000 美元。\n二、总检察长可以以本州的名义提起诉讼,以:\n(一)收取本条规定的民事罚款;\n(二)就进一步违反本章的行为寻求禁令救济;且\n(三)追回律师费及合理诉讼费用或其他调查支出。\n三、存在可反驳的推定,即个人已尽本章所要求的合理注意。\n四、本条项下诉讼中的被告,如善意相信其未违反本章,可请求加速听证或其他程序,包括请求作出宣告性判决。\n五、本条项下诉讼中的被告,在下列情形下不得被认定承担责任:\n(一)另一人以本章禁止的方式使用与该被告关联的人工智能系统;或\n(二)该被告通过下列方式发现违反本章的行为:\n来自开发者、部署者或认为已发生违反的其他个人的反馈;\n测试,包括对抗性测试或红队测试;\n遵循适用州机构制定的指引;或\n内部审查流程,条件是该被告实质遵守由美国国家标准与技术研究院(NIST)发布的最新版《人工智能风险管理框架:生成式人工智能概况》,或实质遵守另一获国内或国际认可的人工智能系统风险管理框架。\n六、总检察长不得就尚未部署的人工智能系统,依本条对该个人提起诉讼以收取民事罚款。\n第 552.106 条 州机构的执法行动\n一、州机构可对由其许可、登记或认证的个人,就违反分章 B 的行为施加制裁,条件是:\n(一)该个人已依第 552.105 条被认定违反本章;且\n(二)总检察长已建议由适用机构追加执法。\n二、本条项下的制裁可包括:\n(一)中止、察看或撤销从事某项活动的执照、登记、证书或其他授权;且\n(二)不超过 100,000 美元的金钱处罚。\n译校署名:本网译 · 据德州议会已登记法案文本(HB 149,第 89 届议会)逐条译出 · 非官方译本,仅供参考 · 核验日期 2026-09-24\n","permalink":"https://ai.intlaws.com/compliance/us/texas-traiga-chapter-552/","summary":"德克萨斯州《商业与商业法典》第 552 章“人工智能保护”官方条文中文译校版(由 HB 149 即《德州负责任人工智能治理法》TRAIGA 创设,2026 年 1 月 1 日生效),共 16 条:定义、本章解释、地方优先适用、对消费者的披露、禁止操纵人类行为、社会评分(仅限政府实体)、生物识别数据的采集、宪法保护、非法歧视、特定色情内容与儿童保护,以及总检察长的执法(调查权、违法通知与补救、民事罚款、禁令)。本页为据官方英文文本逐条译校的中文译本(非官方)。","title":"德克萨斯州《商业与商业法典》第 552 章(人工智能保护)"},{"content":" 版本与来源(可核验)\n项 内容 正式名称 Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data 条约编号 ETS No. 108(欧洲理事会条约系列第 108 号) 签署 1981 年 1 月 28 日,斯特拉斯堡开放签署 结构 7 章 27 条 作准文本 英文、法文两种文本同等作准(官方声明原文:both texts being equally authoritative) 官方原文 Convention 108 官方文本(英文/法文) ｜ 条约办公室记录(treatynum=108) 中文译本 无官方中文译本。本页中文译文由本网据官方英文文本逐条译校,并核对了条第(款)结构;为非官方译本、仅供参考。法文本同为作准文本,本次校核未据法文本,引用前请以官方英/法文本为准 → English 现代化与衔接 2018 年 10 月 10 日开放签署的修订议定书(Convention 108+ ,CETS No. 223) 对本书逐条修改,详见 Convention 108+ 全文 。该议定书尚未生效:截至 2026-09-22,38 个缔约方的生效门槛已批准 34 个(尚差 4 个),或需 ETS 108 全体缔约国批准——欧洲理事会官方公告 核对记录 2026-09-22 从欧洲理事会官方文件库原文逐条解析;条号 1–27 无缺号;条标题与款(项)结构与官方文本一致;源文档双栏 PDF 中\u0026quot;章标题与条标题同行\u0026quot;处已逐条切开核对 序言 欧洲理事会各成员国,作为本公约签署方:\n考虑到欧洲理事会的目标是实现其成员国之间更紧密的团结,其基础尤其在于对法治以及人权和基本自由的尊重;\n考虑到鉴于个人数据跨越国境进行自动处理的情况日益增多,扩大对每个人权利和基本自由的保障——特别是对隐私的尊重——是可取的;\n同时重申其对不论国界的信息自由的承诺;\n认识到有必要协调尊重隐私与各国人民之间信息自由流动这两项基本价值;\n兹协议如下:\n第一章 一般规定 第一条 目的与宗旨\n本公约的目的是,在每一缔约国领土内,不论个人的国籍或居所如何,确保其在与其有关的个人数据自动处理方面,其权利和基本自由——特别是隐私权——得到尊重(\u0026ldquo;数据保护\u0026rdquo;)。\n第二条 定义\n为本公约之目的:\n(a) \u0026ldquo;个人数据\u0026quot;是指与已识别或可识别的个人(\u0026ldquo;数据主体\u0026rdquo;)有关的任何信息;\n(b) \u0026ldquo;自动化数据档案\u0026quot;是指经过自动处理的任何数据集;\n(c) \u0026ldquo;自动处理\u0026quot;包括以下全部或部分以自动化方式进行的操作:数据的存储、对这些数据进行逻辑和/或算术运算,以及数据的变更、删除、检索或传播;\n(d) \u0026ldquo;档案管理人\u0026quot;是指依国内法有权决定自动化数据档案的目的、应存储哪些类别的个人数据以及应对这些数据适用哪些操作的自然人或法人、公共机关、机构或其他任何组织。\n第三条 适用范围\n(1) 缔约国承诺将本公约适用于公营和私营部门的自动化个人数据档案及个人数据的自动处理。\n(2) 任何国家可在签署时,或在交存其批准书、接受书、核准书或加入书时,或在任何更晚的时间,以致欧洲理事会秘书长的声明作出通知:\n(a) 该国将不对某些类别的自动化个人数据档案适用本公约,此类档案的清单将予交存。但该国不得将依其国内法受数据保护规定约束的自动化数据档案类别列入该清单。因此,当其国内法将更多类别的自动化个人数据档案纳入数据保护规定时,该国应通过新的声明修改该清单;\n(b) 该国还将本公约适用于与由个人直接或间接组成的团体、协会、基金会、公司、企业及任何其他组织有关的信息,不论这些组织是否具有法律人格;\n(c) 该国还将本公约适用于非自动处理的个人数据档案。\n(3) 通过上述第(2)款(b)项或(c)项所作声明扩展本公约适用范围的任何国家,可在该声明中通知该等扩展仅适用于某些类别的个人数据档案,此类档案的清单将予交存。\n(4) 通过上述第(2)款(a)项所作声明排除某些类别自动化个人数据档案的任何缔约国,不得要求未作此类排除的缔约国对这些类别适用本公约。\n(5) 同样,未作出上述第(2)款(b)项和(c)项中任何一项扩展的缔约国,不得就这些事项要求已作出此类扩展的缔约国适用本公约。\n(6) 上述第(2)款规定的声明,如系在签署或交存其批准书、接受书、核准书或加入书时作出,则自本公约对该国生效之时起生效;如系在此后作出,则自欧洲理事会秘书长收到之日起三个月后生效。此类声明可通过致欧洲理事会秘书长的通知全部或部分撤回。撤回自秘书长收到该通知之日起三个月后生效。\n第二章 数据保护基本原则 第四条 缔约国的义务\n(1) 各缔约国应采取必要的国内法措施,使本章规定的数据保护基本原则得以实现。\n(2) 该等措施至迟应在本公约对该缔约国生效时采取。\n第五条 数据质量\n经过自动处理的个人数据应当:\n(a) 以公平、合法的方式获取和处理;\n(b) 为特定、合法的目的而存储,且不得以与这些目的不相容的方式使用;\n(c) 相对于存储目的而言适当、相关且不过量;\n(d) 准确,并在必要时保持更新;\n(e) 保存形式不得允许识别数据主体超过存储目的所需的时间。\n第六条 特殊类别的数据\n揭示种族血统、政治观点或宗教或其他信仰的个人数据,以及涉及健康或性生活的个人数据,除非国内法规定了适当的保障措施,否则不得进行自动处理。与刑事判决有关的个人数据同样适用。\n第七条 数据安全\n应采取适当的安全措施,保护自动化数据档案中存储的个人数据免受意外或未经授权的毁损、意外丢失,以及免受未经授权的访问、变更或传播。\n第八条 对数据主体的额外保障\n任何人应能够:\n(a) 查明是否存在自动化个人数据档案、其主要目的,以及档案管理人的身份和惯常居所或主要营业地;\n(b) 在合理的时间间隔内、不受过度迟延或费用负担地,获得关于与其有关的个人数据是否存储于该自动化数据档案中的确认,并以可理解的形式获得该等数据的告知;\n(c) 在适当情况下,凡该等数据的处理违反使本公约第五条和第六条所定基本原则得以实现的国内法规定者,获得对该等数据的更正或删除;\n(d) 在依本条第(b)项和(c)项提出的确认、告知、更正或删除请求未获遵从时,获得救济。\n第九条 例外与限制\n(1) 除本条所界定的限度外,不得允许对本公约第五条、第六条和第八条的规定作任何例外。\n(2) 当缔约国法律有规定,且该等减损构成民主社会中为下列利益所必需的措施时,允许对本公约第五条、第六条和第八条的规定予以减损:\n(a) 保护国家安全、公共安全、国家的货币利益或打击刑事犯罪;\n(b) 保护数据主体或他人的权利和自由。\n(3) 对于用于统计或科学研究目的的自动化个人数据档案,当明显不存在侵害数据主体隐私的风险时,法律可以规定对行使第八条第(b)、(c)和(d)项所定权利的限制。\n第十条 制裁与救济\n各缔约国承诺,对违反使本章所定数据保护基本原则得以实现的国内法规定的行为,规定适当的制裁和救济。\n第十一条 扩展保护\n本章任何规定均不得解释为限制或以其他方式影响缔约国给予数据主体比本公约规定更广泛保护的可能性。\n第三章 跨境数据流动 第十二条 个人数据的跨境流动与国内法\n(1) 下列规定适用于以任何媒介将经过自动处理的个人数据,或为自动处理而收集的个人数据跨越国境的传输。\n(2) 缔约国不得仅以保护隐私为目的,禁止或要求特别授权将个人数据传输至另一缔约国领土。\n(3) 但各缔约国均有权对第(2)款的规定予以减损:\n(a) 在其立法因某些类别的个人数据或自动化个人数据档案的性质而对其有专门规定时,但另一缔约国的规定提供同等保护者除外;\n(b) 当传输系从其领土经另一缔约国领土的中介而向非缔约国领土进行,以避免此类传输导致规避本款开头所述缔约国的立法时。\n第四章 相互协助 第十三条 缔约国之间的合作\n(1) 各缔约国同意为实施本公约而相互提供协助。\n(2) 为此:\n(a) 各缔约国应指定一个或多个机关,并将其名称和地址通知欧洲理事会秘书长;\n(b) 指定一个以上机关的缔约国,应在前项所述通知中说明各机关的职权范围。\n(3) 缔约国指定的机关,应另一缔约国指定机关的请求:\n(a) 提供关于其数据保护领域法律和行政实践的信息;\n(b) 依其国内法并仅为保护隐私的目的,采取一切适当措施,提供与其领土内特定自动处理有关的事实信息,但正在处理的个人数据除外。\n第十四条 对居住境外的数据主体的协助\n(1) 各缔约国应协助任何居住境外的人行使依其国内法所赋予的、使本公约第八条所定原则得以实现的权利。\n(2) 当该人居住于另一缔约国领土内时,应给予其通过该缔约国指定机关的中介提出请求的选择权。\n(3) 协助请求应包含一切必要的细节,特别是:\n(a) 提出请求者的姓名、地址及其他相关身份信息;\n(b) 请求所涉的自动化个人数据档案或其管理人;\n(c) 请求的目的。\n第十五条 对指定机关提供协助的保障\n(1) 缔约国指定的机关从另一缔约国指定机关收到的信息,无论是随协助请求附送还是对自身协助请求的答复,均不得用于协助请求所指定的目的以外的目的。\n(2) 各缔约国应确保其指定机关的人员或代表该机关行事的人员,对该等信息受适当的保密义务约束。\n(3) 在任何情况下,指定机关均不得依第十四条第(2)款,在未经有关个人明确同意的情况下,自行代表居住境外的数据主体提出协助请求。\n第十六条 拒绝协助请求\n依本公约第十三条或第十四条收到协助请求的指定机关不得拒绝遵从该请求,除非:\n(a) 该请求与负责答复的机关在数据保护领域的职权不相容;\n(b) 该请求不符合本公约的规定;\n(c) 遵从该请求将与该机关所属缔约国的主权、安全或公共政策(公共秩序)不相容,或与该缔约国管辖下的人的权利和基本自由不相容。\n第十七条 协助的费用与程序\n(1) 缔约国依第十三条相互提供的协助,以及依第十四条对境外数据主体提供的协助,不应产生除专家和翻译费用以外的任何费用。后述费用由指定提出协助请求机关的缔约国承担。\n(2) 除另一缔约国居民依法应支付的费用外,不得就为该数据主体在该缔约国领土内采取的措施向其收取费用。\n(3) 有关协助的其他细节,特别是所使用的方式、程序及语文,应由有关缔约国直接商定。\n第五章 协商委员会 第十八条 委员会的组成\n(1) 本公约生效后应设立协商委员会。\n(2) 各缔约国应向委员会指派一名代表和一名副代表。非本公约缔约国的欧洲理事会成员国,有权以观察员身份派代表参加委员会。\n(3) 协商委员会可经一致决定,邀请非本公约缔约国的任何欧洲理事会非成员国,以观察员身份派代表出席某次会议。\n第十九条 委员会的职能\n协商委员会:\n(a) 可提出旨在便利或改进本公约适用的建议;\n(b) 可依第二十一条提出本公约修正建议;\n(c) 应对依第二十一条第(3)款提交其的本公约修正建议提出意见;\n(d) 可应缔约国的请求,就与本公约适用有关的任何问题发表意见。\n第二十条 程序\n(1) 协商委员会由欧洲理事会秘书长召集。其首次会议应在本公约生效后十二个月内举行。此后至少每两年举行一次会议,并在三分之一缔约国代表请求时随时召开。\n(2) 缔约国代表的多数构成协商委员会会议的法定人数。\n(3) 协商委员会每次会议后,应向欧洲理事会部长委员会提交关于其工作及本公约运行情况的报告。\n(4) 在不违反本公约规定的前提下,协商委员会应制定其自身的议事规则。\n第六章 修正 第二十一条 修正\n(1) 本公约的修正,可由缔约国、欧洲理事会部长委员会或协商委员会提出。\n(2) 任何修正建议应由欧洲理事会秘书长转交欧洲理事会各成员国,以及已依第二十三条规定加入或受邀加入本公约的每一非成员国。\n(3) 此外,由缔约国或部长委员会提出的任何修正,应转交协商委员会,由后者向部长委员会提交其对该修正建议的意见。\n(4) 部长委员会应审议该修正建议及协商委员会提交的任何意见,并可核准该修正。\n(5) 部长委员会依本条第(4)款核准的任何修正文本,应转交各缔约国接受。\n(6) 依本条第(4)款核准的任何修正,应在所有缔约国通知秘书长其接受之后第三十天生效。\n第七章 最后条款 第二十二条 生效\n(1) 本公约应对欧洲理事会成员国开放签署。本公约须经批准、接受或核准。批准书、接受书或核准书应交存欧洲理事会秘书长。\n(2) 本公约应在欧洲理事会五个成员国依前款规定表示同意受本公约约束之日后三个月期限届满之次月的第一天生效。\n(3) 对于此后表示同意受本公约约束的任何成员国,本公约应在该国交存批准书、接受书或核准书之日后三个月期限届满之次月的第一天生效。\n第二十三条 非成员国的加入\n(1) 本公约生效后,欧洲理事会部长委员会可依《欧洲理事会规约》第二十条(d)款规定的多数作出决定,并经有权参加委员会的缔约国代表一致投票,邀请非欧洲理事会成员国的任何国家加入本公约。\n(2) 对于任何加入国,本公约应在该国向欧洲理事会秘书长交存加入书之日后三个月期限届满之次月的第一天生效。\n第二十四条 领土条款\n(1) 任何国家可在签署时,或在交存其批准书、接受书、核准书或加入书时,指明本公约适用的一项或多项领土。\n(2) 任何国家可在其后任何时间,以致欧洲理事会秘书长的声明,将本公约的适用扩展至该声明所指明的任何其他领土。对于该等领土,本公约应在秘书长收到该声明之日后三个月期限届满之次月的第一天生效。\n(3) 依前两款所作的任何声明,可就该声明所指明的任何领土,以致秘书长的通知予以撤回。撤回应在秘书长收到该通知之日后六个月期限届满之次月的第一天生效。\n第二十五条 保留\n不得对本公约的规定提出保留。\n第二十六条 退出\n(1) 任何缔约国可随时以致欧洲理事会秘书长的通知退出本公约。\n(2) 该退出应在秘书长收到通知之日后六个月期限届满之次月的第一天生效。\n第二十七条 通知\n欧洲理事会秘书长应将下列事项通知欧洲理事会各成员国及已加入本公约的任何国家:\n(a) 任何签署;\n(b) 任何批准书、接受书、核准书或加入书的交存;\n(c) 依第二十二条、第二十三条和第二十四条本公约生效的任何日期;\n(d) 与本公约有关的任何其他行为、通知或来文。\n下列签署人经正式授权签署本公约,以昭信守。1981 年 1 月 28 日订于斯特拉斯堡,以英文和法文作成,两种文本同等作准,单一副本交存于欧洲理事会档案库。欧洲理事会秘书长应将核证副本分送欧洲理事会各成员国及受邀加入本公约的任何国家。\n","permalink":"https://ai.intlaws.com/compliance/intl/coe-convention-108/","summary":"《个人数据自动处理中的个人保护公约》(ETS No. 108)官方文本中文译校版,共 7 章 27 条:一般规定、数据保护基本原则(数据质量、特殊类别数据、数据安全、数据主体额外保障、例外与限制)、跨境数据流动、相互协助、协商委员会、修正、最后条款。1981 年 1 月 28 日订于斯特拉斯堡,为全球首部有约束力的数据保护国际公约。本页为据官方英文文本逐条译校的中文译本(非官方)。","title":"个人数据保护公约"},{"content":" 版本与来源(可核验)\n项 内容 正式名称 Protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data 通行简称 \u0026ldquo;Convention 108+\u0026rdquo; 条约编号 CETS No. 223(欧洲理事会条约系列第 223 号) 签署 2018 年 10 月 10 日,斯特拉斯堡开放签署 结构 40 条:第 1–35 条逐条修改 1981 年公约;第 36–40 条为最后条款;另附\u0026quot;公约委员会议事规则要素\u0026quot; 生效条件 两条相互独立的路径(第三十七条):①经 ETS 108 公约所有缔约国批准;或 ②自开放签署(2018 年 10 月 10 日)满五年后——即自 2023 年 10 月 11 日起——经 38 个缔约国批准议定书 缔约状态 尚未生效。截至 2026-09-22,已有 34 个缔约方批准(第 34 个为摩尔多瓦,2026 年 5 月 15 日批准——欧洲理事会官方公告 ),距 38 个的生效门槛尚差 4 个;不得表述为“即将生效” 作准文本 英文、法文两种文本同等作准 官方原文 https://rm.coe.int/16808ac918 ｜条约办公室状态页(treatynum=223) 中文译本 无官方中文译本。本页中文译文由本网据官方英文文本逐条译校,并核对了条(款、项)结构与交叉引用编号(修改后条号整体前移);为非官方译本、仅供参考 → English 与公约的关系 本议定书修改基础公约 Convention 108(ETS No. 108)——该公约中文译校版见 Convention 108 中文全文 核对记录 2026-09-22 从欧洲理事会官方文件库原文逐条解析;条号 1–40 严格递增、无缺号;款(项)标记按官方结构分段;交叉引用编号(如\u0026quot;Article 25 paragraph 3\u0026quot;)逐处核对 序言 欧洲理事会各成员国以及《个人数据自动处理中的个人保护公约》(ETS No. 108,1981 年 1 月 28 日在斯特拉斯堡开放签署,下称\u0026quot;公约\u0026quot;)的其他缔约国:\n考虑到司法部长会议(2010 年 11 月 24 日至 26 日,土耳其伊斯坦布尔)通过的关于第三个千年数据保护与隐私的第 3 号决议;\n考虑到欧洲理事会议会大会关于互联网和在线媒体中隐私与个人数据保护的第 1843(2011)号决议,以及关于改善网络空间中用户保护与安全的第 1986(2014)号决议;\n考虑到议会大会常设委员会于 2017 年 11 月 24 日代表议会大会通过的关于《个人数据自动处理中的个人保护公约》(ETS No. 108)修正议定书草案及其解释性备忘录的第 296(2017)号意见;\n考虑到自公约通过以来,个人数据处理中的个人保护面临新的挑战;\n考虑到有必要确保公约在保护个人数据处理方面继续发挥其首要作用;\n兹协议如下:\n对公约的修改 体例说明:本页为议定书中译本。修改条款层用 (1)(2)(3)…;被引条文(引文层)款号照官方原文用裸数字 1、2、3…;引文层内项号已按中文层级惯例转写为（一）（二）（三）…(对应官方原文之 (a)(b)(c))。\n第一条\n(1) 公约序言第一段修改为:\n\u0026ldquo;欧洲理事会各成员国及其他签署方,\u0026rdquo;\n(2) 公约序言第三段修改为:\n\u0026ldquo;考虑到有必要确保每个人的尊严并保护其人权和基本自由,并且鉴于数据处理的多样化和密集化以及个人数据流动的全球化,保障个人基于其控制自身个人数据及该等数据处理的权利而享有的人格自主;\u0026rdquo;\n(3) 公约序言第四段修改为:\n\u0026ldquo;回顾个人数据受保护的权利应结合其在社会中的作用加以考虑,并应与其他各项人权和基本自由——包括表达自由——相协调;\u0026rdquo;\n(4) 在公约序言第四段之后增列一段:\n\u0026ldquo;考虑到本公约允许在执行其所定规则时顾及官方文件查阅权原则;\u0026rdquo;\n(5) 删除公约序言第五段。增列新的第五段和第六段如下:\n\u0026ldquo;认识到有必要在全球层面促进尊重隐私和保护个人数据这两项基本价值,从而推动人民之间的信息自由流动;\u0026rdquo;\n\u0026ldquo;认识到加强本公约各缔约国之间国际合作的必要性,\u0026rdquo;\n第二条\n公约第一条的条文修改为:\n\u0026ldquo;本公约的目的是在个人数据处理方面保护每个人,不论其国籍或居所,从而促进对其人权和基本自由的尊重,特别是对隐私权的尊重。\u0026rdquo;\n第三条\n(1) 公约第二条(b)项修改为:\n\u0026ldquo;b \u0026lsquo;数据处理\u0026rsquo;是指对个人数据进行的任何操作或系列操作,例如个人数据的收集、存储、保存、变更、检索、披露、提供、删除或销毁,或对该等数据进行逻辑和/或算术运算;\u0026rdquo;\n(2) 公约第二条(c)项修改为:\n\u0026ldquo;c 在未使用自动处理的情况下,\u0026lsquo;数据处理\u0026rsquo;是指对按特定标准可访问或可检索的结构化个人数据集合内的个人数据进行的操作或系列操作;\u0026rdquo;\n(3) 公约第二条(d)项修改为:\n\u0026ldquo;d \u0026lsquo;控制者\u0026rsquo;是指单独或与他人共同对数据处理拥有决定权的自然人或法人、公共机关、服务机构、机构或任何其他组织;\u0026rdquo;\n(4) 在公约第二条(d)项之后增列新的各项:\n\u0026ldquo;e \u0026lsquo;接收方\u0026rsquo;是指向其披露或提供个人数据的自然人或法人、公共机关、服务机构、机构或任何其他组织;\nf \u0026lsquo;处理者\u0026rsquo;是指代表控制者处理个人数据的自然人或法人、公共机关、服务机构、机构或任何其他组织。\u0026rdquo;\n第四条\n(1) 公约第三条第 1 款修改为:\n\u0026ldquo;1 缔约国承诺将本公约适用于其管辖范围内的公共和私营部门的数据处理,从而保障每个人对其个人数据的保护权利。\u0026rdquo;\n(2) 公约第三条第 2 款修改为:\n\u0026ldquo;2 本公约不适用于个人在纯粹个人或家庭活动中进行的数据处理。\u0026rdquo;\n(3) 公约第三条第 3 款至第 6 款修改为:\n\u0026ldquo;3 任何缔约国不得在其领土范围内,为行使第 2 款所规定的纯属个人或家庭活动的豁免而保留不适用本公约的权利。\u0026rdquo;\n第五条\n公约第二章标题修改为:\u0026ldquo;第二章 保护个人数据的基本原则\u0026rdquo;。\n第六条\n(1) 公约第四条第 1 款修改为:\n\u0026ldquo;1 各缔约国应在其法律内采取必要措施,赋予本公约各项规定以效力,并确保其有效适用。\u0026rdquo;\n(2) 公约第四条第 2 款修改为:\n\u0026ldquo;2 该等措施应由各缔约国采取,并应在批准或加入本公约之时已经生效。\u0026rdquo;\n(3) 在公约第四条第 2 款之后增列新的第 3 款:\n\u0026ldquo;3 各缔约国承诺:\na 允许本国主管机关为核实本国遵守本公约情况之目的,查阅其领土内受本公约规范的个人数据处理活动;\nb 在核实此类遵守情况所必需的范围内,向欧洲理事会秘书长提供此类数据处理活动的说明;\nc 事实上确保本公约所规定的个人数据保护获得有效遵循;\nd 就本条而言,缔约国应尽可能在其法律内规定主管部门与公约委员会之间开展合作。\u0026rdquo;\n第七条\n(1) 第五条标题修改为:\u0026ldquo;第五条 数据处理的合法性与数据质量\u0026rdquo;。\n(2) 公约第五条的条文修改为:\n\u0026ldquo;1 数据处理应与所追求的合法目的相称,并应在处理的所有阶段体现各项相关利益(无论公或私)与所涉权利和自由之间的公平平衡。\n2 各缔约国应规定,数据处理可以基于数据主体自由作出、具体、知情且明确的同意,或基于法律规定的其他正当依据进行。\n3 正在处理的个人数据应合法处理。\n4 正在处理的个人数据应:\n（一）以公平和透明的方式处理;\n（二）为明确、特定和合法的目的收集,且不得以与这些目的不相容的方式处理;为公共利益存档目的、科学或历史研究目的或统计目的进行的进一步处理,在采取适当保障措施的前提下,与这些目的相容;\n（三）相对于处理目的而言适当、相关且不过量;\n（四）准确,并在必要时保持更新;\n（五）保存形式不得允许识别数据主体超过该等数据处理目的所需的时间。\u0026rdquo;\n第八条\n公约第六条的条文修改为:\n\u0026ldquo;1 对下列数据的处理:基因数据;与犯罪、刑事诉讼和定罪以及相关保安措施有关的个人数据;唯一识别个人的生物识别数据;因其揭示的信息而与种族或民族血统、政治观点、工会成员身份、宗教或其他信仰、健康或性生活有关的个人数据,只有在法律规定了适当保障措施、对本公约的保障予以补充的情况下,才允许进行。\n2 该等保障措施应防范敏感数据处理可能给数据主体的利益、权利和基本自由带来的风险,尤其是歧视风险。\u0026rdquo;\n第九条\n公约第七条的条文修改为:\n\u0026ldquo;1 各缔约国应规定,控制者并在适用情况下处理者,采取适当的安全措施,防范意外或未经授权访问、毁损、丢失、使用、修改或披露个人数据等风险。\n2 各缔约国应规定,控制者应毫不迟延地将可能严重妨碍数据主体权利和基本自由的数据泄露事件,至少通知本公约第十五条意义上的主管监督机关。\u0026rdquo;\n第十条\n在公约第七条之后增列新的第八条如下:\n\u0026ldquo;第八条 处理的透明度\n1 各缔约国应规定,控制者应告知数据主体下列事项:\n（一）其身份和惯常居所或营业地;\n（二）预期处理的法律依据和目的;\n（三）所处理个人数据的类别;\n（四）个人数据的接收方或接收方类别(如有);以及\n（五）行使第九条所定权利的方式,\n以及为确保个人数据得到公平和透明处理所需的任何其他信息。\n2 数据主体已掌握相关信息的,不适用第(1)款。\n3 个人数据并非从数据主体处收集的,如处理系法律明确规定,或证明不可能提供或需要付出不相称的努力,则不应要求控制者提供该等信息。\u0026rdquo;\n第十一条\n(1) 公约原第八条重新编号为第九条,标题修改为:\u0026ldquo;第九条 数据主体的权利\u0026rdquo;。\n(2) 公约第八条(新第九条)的条文修改为:\n\u0026ldquo;1 每个人均有权:\n（一）在未考虑其意见的情况下,不受仅基于数据自动处理而作出的、对其产生重大影响的决定;\n（二）在合理的时间间隔内、不受过度迟延或费用负担地,应请求获得关于与其有关的个人数据正在处理的确认,以可理解的形式获得所处理数据的告知,以及关于其来源、保存期限的一切可用信息和控制者为确保依第八条第(1)款实现处理透明度而须提供的任何其他信息;\n（三）在该等处理结果被适用于其本人时,应请求获知数据处理所依据的理由;\n（四）随时基于与其自身情况有关的理由,反对对其个人数据的处理,除非控制者证明存在优先于其利益或权利和基本自由的正当处理依据;\n（五）在该等数据正在或曾经违反本公约规定被处理时,应请求免费且不受过度迟延地获得对该等数据的更正或删除(视情形而定);\n（六）在其依本公约享有的权利受到侵害时,依第十二条获得救济;\n（七）不论其国籍或居所,在行使本公约所定权利时获得第十五条意义上的监督机关的协助。\n2 如决定系控制者所应遵守的法律所授权,且该法律亦规定了保障数据主体权利、自由和正当利益的适当措施,则不适用第(1)款(a)项。\u0026rdquo;\n第十二条\n在公约新第九条之后增列新的第十条如下:\n\u0026ldquo;第十条 附加义务\n1 各缔约国应规定,控制者并在适用情况下处理者,采取一切适当措施遵守本公约的各项义务,并能够证明——在依第十一条第(3)款通过的国内立法的约束下,特别是向第十五条规定的主管监督机关证明——其控制下的数据处理符合本公约的规定。\n2 各缔约国应规定,控制者并在适用情况下处理者,在预期数据处理开始前审查该处理对数据主体权利和基本自由的潜在影响,并应以防止或尽量减少对该等权利和基本自由干预风险的方式设计数据处理。\n3 各缔约国应规定,控制者并在适用情况下处理者,实施考虑到个人数据受保护权利在数据处理各阶段影响的技术和组织措施。\n4 各缔约国可考虑到数据处理给数据主体利益、权利和基本自由带来的风险,依数据的性质与数量、处理的性质、范围与目的,并酌情依控制者或处理者的规模,在落实本公约各项规定的法律中调整第(1)、(2)、(3)款的适用。\u0026rdquo;\n第十三条\n公约原第九条至第十二条改为公约第十一条至第十四条。\n第十四条\n公约第九条(新第十一条)的条文修改为:\n\u0026ldquo;1 除对本公约第 5 条第 4 款、第 7 条第 2 款、第 8 条第 1 款和第 9 条的例外之外,不得允许对本章规定作任何例外,前提是该等例外系法律规定、尊重基本权利和自由的本质,并构成民主社会中为下列目的所必需且相称的措施:\n（一）保护国家安全、国防、公共安全、国家重大经济和金融利益、司法机关的公正与独立,或者预防、调查和追诉刑事犯罪及执行刑事处罚,以及其他重大公共利益目标;\n（二）保护数据主体或他人的权利和基本自由,尤其是表达自由。\n2 对于为公共利益存档目的、科学或历史研究目的或统计目的进行的数据处理,如不存在可识别的侵害数据主体权利和基本自由的风险,法律可以规定对第八条和第九条所定各项规定行使的限制。\n3 除本条第 1 款允许的例外之外,就国家安全和国防目的的处理活动,各缔约国可以法律规定对第 4 条第 3 款、第 14 条第 5 款和第 6 款以及第 15 条第 2 款(a)、(b)、(c)、(d)项的例外,且仅以该例外构成民主社会中为实现该目的所必需且相称的措施为限。此不影响国家安全和国防目的的处理活动须依各缔约国国内立法接受独立有效的审查和监督这一要求。\u0026rdquo;\n第十五条\n公约第十条(新第十二条)的条文修改为:\n\u0026ldquo;各缔约国承诺,对违反本公约各项规定的行为,规定适当的司法和非司法制裁与救济。\u0026rdquo;\n第十六条\n公约第三章标题修改为:\u0026ldquo;第三章 个人数据的跨境流动\u0026rdquo;。\n第十七条\n(1) 公约第十二条(新第十四条)标题修改为:\u0026ldquo;第十四条 个人数据的跨境流动\u0026rdquo;。\n(2) 公约第十二条(新第十四条)的条文修改为:\n\u0026ldquo;1 缔约国不得仅以保护个人数据为目的,禁止或要求特别授权将此类数据传输给受本公约另一缔约国管辖的接收方。但如存在真实且严重的风险,即向另一缔约国传输、或从该另一缔约国向非缔约国传输将导致规避本公约的规定,则该缔约国可以这样做。缔约国如受属于某一区域国际组织的各国共同保护规则的约束,亦可这样做。\n2 当接收方受非本公约缔约方的国家或国际组织管辖时,个人数据的传输只有在确保基于本公约规定提供适当保护水平的情况下方可进行。\n3 适当保护水平可通过下列方式确保:\n（一）该国或国际组织的法律,包括适用的国际条约或协定;或\n（二）由参与传输和后续处理的各方通过具有法律约束力且可执行的文书所采纳和实施的一次性保障措施,或经批准的标准保障措施。\n4 尽管有前述各款规定,各缔约国仍可规定,在下列情形下可以进行个人数据传输:\n（一）数据主体在被告知在不具备适当保障措施的情况下所生风险后,已作出明确、具体且自由的同意;或\n（二）数据主体的特定利益在个案中要求传输;或\n（三）法律规定了优先的正当利益,尤其是重大公共利益,且该等传输构成民主社会中必要且相称的措施;或\n（四）该传输构成民主社会中为表达自由所必需且相称的措施。\n5 各缔约国应规定,向本公约第十五条意义上的主管监督机关提供与第 3 款(b)项所述数据传输有关的一切相关信息,并应请求提供与第 4 款(b)项和(c)项有关的一切相关信息。\n6 各缔约国还应规定,监督机关有权要求数据传输者证明保障措施的有效性或优先正当利益的存在,并有权为保护数据主体的权利和基本自由而禁止、中止该等传输或对其附加条件。\u0026rdquo;\n(3) 公约第十二条(新第十四条)的条文包含 2001 年附加议定书(ETS No. 181)第 2 条关于监督机关与向非缔约国管辖接收方跨境传输个人数据的规定。\n第十八条\n在公约第三章之后增列新的第四章如下:\u0026ldquo;第四章 监督机关\u0026rdquo;。\n第十九条\n新的第十五条纳入 2001 年附加议定书(ETS No. 181)第 1 条的规定,内容如下:\n\u0026ldquo;第十五条 监督机关\n1 各缔约国应设立一个或多个机关,负责确保本公约各项规定得到遵守。\n2 为此,该等机关:\n（一）应拥有调查和干预的权力;\n（二）应履行与第十四条规定的数据传输有关的职能,特别是批准标准保障措施;\n（三）应有权就违反本公约各项规定的行为作出决定,并尤其可以实施行政处罚;\n（四）应有权参与法律程序,或将违反本公约各项规定的行为提请主管司法机关注意;\n（五）应促进:（九）公众对其职能和权力及其活动的了解;(ii) 公众对数据主体权利及行使该等权利的了解;(iii) 控制者和处理者对其在本公约下责任的了解;并应特别关注儿童及其他弱势个人的数据保护权利。\n3 就规定个人数据处理的任何立法或行政措施提案,应征询主管监督机关的意见。\n4 各主管监督机关应处理数据主体就其数据保护权利提出的请求和投诉,并应使数据主体了解进展情况。\n5 监督机关在履行职责和行使权力时应完全独立和公正,且不得寻求或接受任何指示。\n6 各缔约国应确保监督机关获得有效履行职能和行使权力所必需的资源。\n7 各监督机关应编写并定期公布概述其活动的报告。\n8 监督机关的成员和工作人员,对其在履行职责和行使权力过程中可接触或曾接触的保密信息,应受保密义务约束。\n9 对监督机关的决定,可通过法院提出上诉。\n10 监督机关对以司法身份行事的机关所进行的处理不具有管辖权。\u0026rdquo;\n第二十条\n(1) 公约第四章至第七章重新编号为公约第五章至第八章。\n(2) 第五章标题修改为\u0026quot;第五章 合作与相互协助\u0026quot;。\n(3) 增列新的第十七条,公约原第十三条至第二十七条改为公约第十六条至第三十一条。\n第二十一条\n(1) 公约第十三条(新第十六条)标题修改为:\u0026ldquo;第十六条 监督机关的指定\u0026rdquo;。\n(2) 公约第十三条(新第十六条)第 1 款修改为:\u0026ldquo;1 各缔约国同意为实施本公约而相互合作并提供协助。\u0026rdquo;\n(3) 公约第十三条(新第十六条)第 2 款修改为:\u0026ldquo;2 为此:（一）各缔约国应指定本公约第十五条意义上的一个或多个监督机关,并将其名称和地址通知欧洲理事会秘书长;（二）指定一个以上监督机关的缔约国,应在前项所述通知中说明各机关的职权范围。\u0026rdquo;\n(4) 公约第十三条(新第十六条)第 3 款应予删除。\n第二十二条\n在公约新第十六条之后增列新的第十七条如下:\n\u0026ldquo;第十七条 合作形式\n1 监督机关应在履行职能和行使权力所必需的范围内相互合作,特别是通过下列方式:\n（一）在遵守本公约所有规则和保障的前提下,在个人数据保护方面交换相关且有用的信息并提供相互协助,并相互合作;\n（二）协调其调查或干预,或开展联合行动;\n（三）提供有关其数据保护法律和行政实践的信息和文件。\n2 第 1 款所述信息不应包括正在处理的个人数据,除非该等数据对合作必不可少,或有关数据主体已对该等数据的提供作出明确、具体、自由且知情的同意。\n3 为组织其合作并履行前述各款规定的职能,各缔约国的监督机关应组成一个网络。\u0026rdquo;\n第二十三条\n(1) 公约第十四条(新第十八条)标题修改为:\u0026ldquo;第十八条 对数据主体的协助\u0026rdquo;。\n(2) 公约第十四条(新第十八条)的条文修改为:\n\u0026ldquo;1 各缔约国应协助任何数据主体,不论其国籍或居所,行使本公约第九条规定的权利。\n2 数据主体居住于另一缔约国境内的,应给予其通过该缔约国指定的监督机关的中介提出请求的选择权。\n3 协助请求应包含一切必要的细节,特别是:（一）提出请求的数据主体的姓名、地址及其他相关身份信息;\n（二）请求所涉的处理或其控制者;\n（三）请求的目的。\u0026rdquo;\n第二十四条\n(1) 公约第十五条(新第十九条)标题修改为:\u0026ldquo;第十九条 保障措施\u0026rdquo;。\n(2) 公约第十五条(新第十九条)的条文修改为:\n\u0026ldquo;1 从另一监督机关收到信息的监督机关(无论是随请求附送还是对自身请求的答复),不得将该信息用于请求所指定的目的以外的目的。\n2 在任何情况下,监督机关均不得在未经有关数据主体明确同意的情况下,自行代表该数据主体提出请求。\u0026rdquo;\n第二十五条\n(1) 公约第十六条(新第二十条)标题修改为:\u0026ldquo;第二十条 请求的拒绝\u0026rdquo;。\n(2) 公约第十六条(新第二十条)的引言修改为:\u0026ldquo;依本公约第十七条收到请求的监督机关不得拒绝遵从该请求,除非:\u0026rdquo;\n(3) 公约第十六条(新第二十条)(a)项修改为:\u0026ldquo;a 该请求与其职权不相容。\u0026rdquo;\n(4) 公约第十六条(新第二十条)(c)项修改为:\u0026ldquo;c 遵从该请求将与该机关所属缔约国的主权、国家安全或公共秩序不相容,或与该缔约国管辖下的个人的权利和基本自由不相容。\u0026rdquo;\n第二十六条\n(1) 公约第十七条(新第二十一条)标题修改为:\u0026ldquo;第二十一条 费用与程序\u0026rdquo;。\n(2) 公约第十七条(新第二十一条)第 1 款修改为:\u0026ldquo;1 缔约国依第十七条相互提供的合作与协助,以及依第九条和第十八条对数据主体提供的协助,不应产生除专家和翻译费用以外的任何费用。后述费用由提出请求的缔约国承担。\u0026rdquo;\n(3) 公约第十七条(新第二十一条)第 2 款中的英文用语\u0026quot;his\u0026quot;改为\u0026quot;his or her\u0026quot;(英文本的性别中立化修改;中文本相应按性别中立表述处理)。\n第二十七条\n公约第五章(新第六章)标题修改为:\u0026ldquo;第六章 公约委员会\u0026rdquo;。\n第二十八条\n(1) 公约第十八条(新第二十二条)第 1 款中的\u0026quot;协商委员会\u0026quot;(Consultative Committee)改为\u0026quot;公约委员会\u0026quot;(Convention Committee)。\n(2) 公约第十八条(新第二十二条)第 3 款修改为:\u0026ldquo;3 公约委员会可经缔约国代表三分之二多数作出决定,邀请观察员派代表出席其会议。\u0026rdquo;\n(3) 在公约第十八条(新第二十二条)第 3 款之后增列新的第 4 款:\u0026ldquo;4 非欧洲理事会成员国的任何缔约国,应按照部长委员会与该缔约国商定的方式,为公约委员会活动的经费作出贡献。\u0026rdquo;\n第二十九条\n(1) 公约第十九条(新第二十三条)引言中的\u0026quot;协商委员会\u0026quot;改为\u0026quot;公约委员会\u0026quot;。\n(2) 公约第十九条(新第二十三条)(a)项中的用语由\u0026quot;proposals\u0026quot;改为\u0026quot;recommendations\u0026quot;(中文本均作\u0026quot;建议\u0026quot;)。\n(3) 公约第十九条(新第二十三条)(b)项中提及的\u0026quot;第二十一条\u0026quot;和(c)项中提及的\u0026quot;第二十一条第 3 款\u0026quot;,分别改为\u0026quot;第二十五条\u0026quot;和\u0026quot;第二十五条第 3 款\u0026quot;。\n(4) 公约第十九条(新第二十三条)(d)项修改为:\u0026ldquo;d 可就本公约的解释或适用有关的任何问题发表意见;\u0026rdquo;\n(5) 在公约第十九条(新第二十三条)(d)项之后增列下列各项:\n\u0026ldquo;e 应在任何新的加入之前,就申请加入方的个人数据保护水平为部长委员会编写意见,必要时建议为实现符合本公约规定所需采取的措施;\nf 可应一国或国际组织的请求,评估前者提供的个人数据保护水平是否符合本公约规定,必要时建议为实现该等符合所需采取的措施;\ng 可制定或批准第十四条所述标准保障措施的范本;\nh 应审查各缔约国对本公约的实施情况,并在某一缔约国未遵守本公约时建议应采取的措施;\ni 必要时,应促进与本公约适用有关的一切困难的友好解决。\u0026rdquo;\n第三十条\n公约第二十条(新第二十四条)的条文修改为:\n\u0026ldquo;1 公约委员会由欧洲理事会秘书长召集。其首次会议应在本公约生效后十二个月内举行。此后至少每年举行一次会议,并在三分之一缔约国代表请求时随时召开。\n2 公约委员会每次会议后,应向欧洲理事会部长委员会提交关于其工作及本公约运行情况的报告。\n3 公约委员会的表决安排载于 CETS 第 223 号议定书所附的议事规则要素。\n4 公约委员会应制定其议事规则的其他要素,并特别依据客观标准,确立第 4 条第 3 款和第 23 条(e)、(f)、(h)项所述评估和审查程序。\u0026rdquo;\n第三十一条\n(1) 公约第二十一条(新第二十五条)第 1 款至第 4 款修改为:\n\u0026ldquo;1 本公约的修正,可由缔约国、欧洲理事会部长委员会或公约委员会提出。\n2 任何修正建议应由欧洲理事会秘书长转交本公约各缔约国、欧洲理事会其他成员国、欧盟,以及已依第二十七条规定受邀加入本公约的每一非成员国或国际组织。\n3 此外,由缔约国或部长委员会提出的任何修正,应转交公约委员会,由后者向部长委员会提交其对该修正建议的意见。\n4 部长委员会应审议该修正建议及公约委员会提交的任何意见,并可核准该修正。\u0026rdquo;\n(2) 在公约第二十一条(新第二十五条)第 6 款之后增列新的第 7 款:\n\u0026ldquo;7 此外,部长委员会可在征询公约委员会后,一致决定某一特定修正自其开放接受之日起满三年时生效,除非某一缔约国通知欧洲理事会秘书长反对其生效。如作出该等反对通知,则该修正应在该缔约国向欧洲理事会秘书长交存其接受书之日后次月的第一天生效。\u0026rdquo;\n第三十二条\n(1) 公约第二十二条(新第二十六条)第 1 款修改为:\n\u0026ldquo;1 本公约应对欧洲理事会成员国和欧盟开放签署。本公约须经批准、接受或核准。批准书、接受书或核准书应交存欧洲理事会秘书长。\u0026rdquo;\n(2) 公约第二十二条(新第二十六条)第 3 款中的\u0026quot;成员国\u0026quot;(member State)改为\u0026quot;缔约国\u0026quot;(Party)。\n第三十三条\n公约第二十三条(新第二十七条)的标题和条文修改如下:\n\u0026ldquo;第二十七条 非成员国或国际组织的加入\n1 本公约生效后,欧洲理事会部长委员会可在征询本公约各缔约国并取得其一致同意后,并参照公约委员会依第二十三条(e)项编写的意见,以《欧洲理事会规约》第二十条(d)款规定的多数作出决定,并经有权参加部长委员会的缔约国代表一致投票,邀请非欧洲理事会成员国的任何国家或某一国际组织加入本公约。\n2 对于依上述第 1 款加入本公约的任何国家或国际组织,本公约应在向欧洲理事会秘书长交存加入书之日后三个月期限届满之次月的第一天生效。\u0026rdquo;\n第三十四条\n公约第二十四条(新第二十八条)第 1 款和第 2 款修改为:\n\u0026ldquo;1 任何国家、欧盟或其他国际组织可在签署时,或在交存其批准书、接受书、核准书或加入书时,指明本公约适用的一项或多项领土。\n2 任何国家、欧盟或其他国际组织可在其后任何时间,以致欧洲理事会秘书长的声明,将本公约的适用扩展至该声明所指明的任何其他领土。对于该等领土,本公约应在秘书长收到该声明之日后三个月期限届满之次月的第一天生效。\u0026rdquo;\n第三十五条\n(1) 公约第二十七条(新第三十一条)引言中的\u0026quot;国家\u0026quot;(State)改为\u0026quot;缔约国\u0026quot;(Party)。\n(2) (c)项中提及的\u0026quot;第二十二条、第二十三条和第二十四条\u0026quot;改为\u0026quot;第二十六条、第二十七条和第二十八条\u0026quot;。\n第三十六条 签署、批准与加入\n(1) 本议定书应对本公约各缔约国开放签署。本议定书须经批准、接受或核准。批准书、接受书或核准书应交存欧洲理事会秘书长。\n(2) 在本议定书开放签署之后、其生效之前,任何其他国家应通过加入表示同意受本议定书约束。该国如不同时加入本议定书,不得成为本公约缔约国。\n第三十七条 生效\n(1) 本议定书应在本公约所有缔约国依第三十六条第 1 款规定表示同意受本议定书约束之日后三个月期限届满之次月的第一天生效。\n(2) 如本议定书未依第 1 款生效,则在其开放签署之日起五年期限届满后,在议定书至少已有三十八个缔约国的情形下,本议定书应在此表示同意受其约束的国家之间生效。在议定书各缔约国之间,经修正的公约所有规定自生效时起立即具有效力。\n(3) 在本议定书生效之前,且不影响关于生效及非成员国或国际组织加入的规定,缔约国可在签署本议定书时或其后任何时间,声明将临时适用本议定书的规定。在此情形下,本议定书的规定仅对作出同样声明的本公约其他缔约国适用。该等声明应在欧洲理事会秘书长收到之日后第三个月的第一天生效。\n(4) 自本议定书生效之日起,关于监督机关与跨境数据流动的《个人数据自动处理中的个人保护公约附加议定书》(ETS No. 181)应予废止。\n(5) 自本议定书生效之日起,部长委员会 1999 年 6 月 15 日在斯特拉斯堡核准的对《个人数据自动处理中的个人保护公约》的修正即失去其目的。\n第三十八条 与公约有关的声明\n自本议定书生效之日起,对于已依公约第三条作出一项或多项声明的缔约国,该等声明即失效。\n第三十九条 保留\n不得对本议定书的规定提出保留。\n第四十条 通知\n欧洲理事会秘书长应将下列事项通知欧洲理事会各成员国及本公约任何其他缔约国:\n（一）任何签署;\n（二）任何批准书、接受书、核准书或加入书的交存;\n（三）依第三十七条本议定书生效的日期;\n（四）与本议定书有关的任何其他行为、通知或来文。\n下列签署人经正式授权签署本议定书,以昭信守。2018 年 10 月 10 日订于斯特拉斯堡,以英文和法文作成,两种文本同等作准,单一副本交存于欧洲理事会档案库。欧洲理事会秘书长应将核证副本分送欧洲理事会各成员国、本公约其他缔约国及受邀加入本公约的任何国家。\n议定书附件 —— 公约委员会议事规则要素 (1) 各缔约国均有权投票,且各有一票。\n(2) 缔约国代表的三分之二多数构成公约委员会会议的法定人数。如公约修正议定书在其对公约所有缔约国生效之前依其第三十七条第(2)款生效,则公约委员会会议的法定人数不得少于议定书的 34 个缔约国。\n(3) 第二十三条项下的决定应以五分之四多数作出。依第二十三条(h)项作出的决定应以五分之四多数作出,其中包括属于公约缔约方的区域一体化组织的非成员国缔约国的多数票。\n(4) 公约委员会依第二十三条(h)项作出决定时,受审查影响的缔约国不得投票。该等决定涉及区域一体化组织职权范围内事项时,该组织及其成员国均不得投票。\n(5) 关于程序问题的决定以简单多数作出。\n(6) 区域一体化组织在其职权范围内的事项上,可行使其在公约委员会中的表决权,票数等于其属于公约缔约国的成员国数目。如其任何成员国行使表决权,该组织不得行使表决权。\n(7) 如表决,须将表决事项、表决时间以及表决由各缔约国分别行使还是由区域一体化组织代表其成员国行使,通知所有缔约国。\n(8) 公约委员会可经三分之二多数进一步修改其议事规则,但表决安排除外 —— 表决安排仅可经缔约国一致同意修改,并适用公约第二十五条。\n","permalink":"https://ai.intlaws.com/compliance/intl/coe-convention-108-plus/","summary":"《个人数据自动处理中的个人保护公约修正议定书》(CETS No. 223,即\u0026quot;Convention 108+\u0026quot;)官方文本中文译校版,共 40 条:第 1 至 35 条逐条修改 1981 年公约(序言、定义、合法性基础与数据质量、敏感数据、数据安全、透明度、数据主体权利、附加义务、例外与限制、跨境流动、监督机关、合作与相互协助、公约委员会、修正),第 36 至 40 条为最后条款,并附公约委员会议事规则要素。2018 年 10 月 10 日订于斯特拉斯堡。本页为据官方英文文本逐条译校的中文译本(非官方)。","title":"个人数据保护公约修正议定书"},{"content":"一、义务的规范来源：三层规范叠加 个人信息保护合规审计不是新概念，但直到 2025 年才形成可操作的完整链条。理解这项义务，需要把三层规范叠起来看。\n法律层。《个人信息保护法》第五十四条确立基本义务：\u0026ldquo;个人信息处理者应当定期对其处理个人信息遵守法律、行政法规的情况进行合规审计。\u0026ldquo;第六十四条给出监管侧触发机制：履行个人信息保护职责的部门发现个人信息处理活动存在较大风险或者发生个人信息安全事件的，可以按照规定的权限和程序对该个人信息处理者的法定代表人或者主要负责人进行约谈，或者要求个人信息处理者委托专业机构对其个人信息处理活动进行合规审计。\n行政法规层。《网络数据安全管理条例》（中华人民共和国国务院令第 790 号，2024 年 9 月 24 日公布，2025 年 1 月 1 日起施行）第二十七条把主体扩展为\u0026quot;网络数据处理者\u0026rdquo;，要求\u0026quot;定期自行或者委托专业机构\u0026quot;开展合规审计；第二十八条规定，处理 1000 万人以上个人信息的网络数据处理者，还应当遵守该条例第三十条、第三十二条对重要数据处理者作出的规定（即设置网络数据安全负责人与安全管理机构、数据变动时报告处置方案等）。\n规章层。《个人信息保护合规审计管理办法》（国家互联网信息办公室令第 18 号，2025 年 2 月 12 日公布，2025 年 5 月 1 日起施行，以下简称《办法》）把上述义务程序化：审计如何启动、多久一次、审什么、谁来审、报告怎么报、整改怎么跟，在《办法》及其附件《个人信息保护合规审计指引》中均有对应规则。\n二、\u0026ldquo;谁来审\u0026rdquo;：两种情形与两项主体要求 情形一：自行开展。第三条：由内部机构或者委托专业机构定期开展合规审计。第四条设定频次下限：处理超过 1000 万人个人信息的，应当每两年至少开展一次。\n情形二：保护部门要求委托专业机构。第五条列举三种情形：发现处理活动存在严重影响个人权益或者严重缺乏安全措施等较大风险的；处理活动可能侵害众多个人的权益的；发生个人信息安全事件，导致 100 万人以上个人信息或者 10 万人以上敏感个人信息泄露、篡改、丢失、毁损的。同条第二款明确：对同一个人信息安全事件或者风险，不得重复要求委托专业机构开展审计。\n两项主体要求（第十二条）：处理 100 万人以上个人信息的，应当指定个人信息保护负责人负责本单位合规审计工作；提供重要互联网平台服务、用户数量巨大、业务类型复杂的，应当成立主要由外部成员组成的独立机构对审计情况进行监督。\n三、\u0026ldquo;审什么\u0026rdquo;：附件《审计指引》的四个板块 第六条规定，无论自行开展还是按保护部门要求开展，都应当参照附件《个人信息保护合规审计指引》。该指引以条目形式列明审计重点，可归纳为四个板块。\n其一，合法性基础与处理规则。同意是否真实、明确、可追溯；处理目的变更后是否重新取得同意；应取得单独同意或书面同意的场景是否落实；处理规则是否真实准确完整、是否以清单等形式列明、是否与处理目的直接相关并采取对个人权益影响最小的方式、是否明确保存期限与到期处理方式、是否明确个人行使权利的途径与方法。\n其二，告知与个人权利保障。告知是否以显著方式、清晰易懂的语言作出，文本是否便于完整阅读，规则变更是否及时告知；删除权的触发情形是否落地（目的已实现或不再必要、停止提供产品或服务、账号注销、保存期限届满、撤回同意、违法或违约处理等）；个人权利的申请受理与响应机制、拒绝请求是否说明理由、是否响应对处理规则的解释说明要求。\n其三，高风险场景——审计资源应重点投向这里。自动化决策的透明度与结果公平公正、事前告知与影响评估、拒绝机制与个性化推荐关闭选项；敏感个人信息与不满十四周岁未成年人信息的单独同意、监护人同意与专门处理规则；对外提供、共同处理、委托处理的单独同意与接收方信息告知、事前影响评估、合同约定及定期检查监督；个人信息出境的安全评估或认证、标准合同及备案、向外国司法或执法机构提供是否经主管机关批准、是否向限制或禁止清单中的对象提供；公共场所图像采集与个人身份识别设备的公共安全必要性、显著提示标识与单独同意；已公开个人信息处理的边界（不得发送与公开目的无关的商业信息、不得用于网络暴力或传播谣言、不得处理个人明确拒绝的部分）。\n其四，安全管理制度与技术措施。管理制度与操作规程、操作权限设置、教育与培训计划、个人信息保护负责人的专业能力与履职情况、影响评估开展情况、安全事件应急预案与应急响应处置、平台规则与社会责任报告。\n实务提示：首轮审计不必全面铺开，可先做风险映射——把本单位的自动化决策、敏感信息、对外提供与出境、公共场所采集等场景逐项标注\u0026quot;有无\u0026rdquo;，据此确定首轮范围与资源投入。这比平均用力更符合《办法》\u0026ldquo;参照指引\u0026quot;而非\u0026quot;逐条打分\u0026quot;的定位。\n四、\u0026ldquo;怎么审\u0026rdquo;：程序与时限 按保护部门要求开展审计时，以下节点可直接用于项目排期：\n费用与配合（第八条）：应当为专业机构正常开展工作提供必要支持，并承担审计费用； 期限（第九条）：按保护部门要求选定专业机构，在限定时间内完成；情况复杂的，报保护部门批准后可以适当延长； 报送报告（第十条）：完成后将专业机构出具的合规审计报告报送保护部门，报告须由专业机构主要负责人、合规审计负责人签字并加盖专业机构公章； 整改闭环（第十一条）：按保护部门要求整改，整改完成后 15 个工作日内报送整改情况报告。 五、专业机构侧的四条红线 企业在选定机构时应当逐条核对：能力要求（第七条），应具备与审计服务相适应的审计人员、场所、设施和资金，鼓励通过认证，认证按《认证认可条例》有关规定执行；保密与删除（第十三条），对履职中获得的个人信息、商业秘密等依法保密，不得泄露或非法向他人提供，审计工作结束后及时删除相关信息；禁止转委托（第十四条）；连续审计次数限制（第十五条），同一专业机构及其关联机构、同一合规审计负责人不得连续三次以上对同一审计对象开展审计——这条对长期合作安排有直接影响，应在合同中预先规划轮换。\n六、与既有合规动作的衔接 《网络数据安全管理条例》第五十二条明确：个人信息保护合规审计、重要数据风险评估、重要数据出境安全评估等应当加强衔接，避免重复评估、审计；重要数据风险评估和网络安全等级测评的内容重合的，相关结果可以相互采信。\n这给企业留出了整合空间：把合规审计、影响评估、出境评估与等保测评的证据池与整改台账合并管理，并在监管沟通中说明相互采信关系，可显著降低重复投入。\n七、法律责任与不适用范围 《办法》第十八条：个人信息处理者、专业机构违反本办法的，依照《个人信息保护法》《网络数据安全管理条例》等法律法规的规定处理；构成犯罪的，依法追究刑事责任。\n需要留意一处结构细节：《网络数据安全管理条例》第五十五条列举的罚则条款中并未包含第二十七条的审计义务，该条第五十八条同时规定，违反本条例其他有关规定的，由有关主管部门依照上位法追究法律责任。审计义务的责任落点仍在上位法；「是否建立了可核验的审计记录」往往就是监管沟通中的第一份材料。\n另需注意第十九条：对国家机关和法律、法规授权的具有管理公共事务职能的组织的个人信息保护合规审计，不适用本办法。\n八、企业落地清单 判定自身层级：处理规模达到 1000 万人以上触发\u0026quot;每两年至少一次\u0026rdquo;；达到 100 万人以上触发\u0026quot;指定个人信息保护负责人\u0026quot;； 首轮做风险映射：对照《审计指引》四个板块，标注本单位自动化决策、敏感信息、对外提供与出境、公共场所采集等场景； 确定审计形式：具备内部能力可自行组织；涉及高风险场景或监管关注事项的建议引入专业机构； 核查机构资质与轮换：能力与认证情况、是否转委托、连续审计次数是否触及三次上限； 固化证据与整改台账：审计底稿、影响评估记录、整改通知与完成证明统一归档，整改完成后 15 个工作日内报送整改情况报告； 做实衔接：与重要数据风险评估、出境安全评估、等保测评的结果相互采信，避免重复评估、审计。 结语 合规审计的制度价值不在于每年产出一份报告，而在于让\u0026quot;是否合规\u0026quot;这个问题有可核验的答案。真正的难点通常不是不知道要审计，而是审计发现的问题没有闭环——报告写得完整、整改停在纸面，反而是更明显的风险暴露。把审计、整改与证据归档作为一件事来管理，才是这项义务的正确打开方式。\n规范依据（供核对）\n《中华人民共和国个人信息保护法》第五十四条、第五十五条、第六十四条。 《网络数据安全管理条例》，中华人民共和国国务院令第 790 号，2024 年 9 月 24 日公布，2025 年 1 月 1 日起施行（第二十七条、第二十八条、第五十二条、第五十五条、第五十八条）。 《个人信息保护合规审计管理办法》，国家互联网信息办公室令第 18 号，2025 年 2 月 12 日公布，2025 年 5 月 1 日起施行（第三条至第十五条、第十八条、第十九条，及附件《个人信息保护合规审计指引》）。 ","permalink":"https://ai.intlaws.com/forum/%E4%B8%AA%E4%BA%BA%E4%BF%A1%E6%81%AF%E4%BF%9D%E6%8A%A4%E5%90%88%E8%A7%84%E5%AE%A1%E8%AE%A1-%E4%B9%89%E5%8A%A1%E8%BE%B9%E7%95%8C%E4%B8%8E%E4%BC%81%E4%B8%9A%E8%90%BD%E5%9C%B0/","summary":"以《个人信息保护合规审计管理办法》为中心，拆解合规审计的启动情形、频次要求与《审计指引》27项重点的四大板块，并提示审计机构「不得连续三次」轮换红线与多套评估体系的整合空间。","title":"个人信息保护合规审计：义务边界与企业落地"},{"content":" 版本与来源(可核验)\n项 内容 正式名称 인공지능 발전과 신뢰 기반 조성 등에 관한 기본법 通行英译名 Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust 通称 AI 기본법(AI 基本法 / AI Framework Act) 制定 法律第 20676 号,2025 年 1 月 21 日公布 施行 2026 年 1 月 22 日(公布后满 1 年;第 2 条第 4 号\u0026quot;数字医疗器械\u0026quot;部分自 2026 年 1 月 24 日施行) 修正 ①法律第 21065 号(2025 年 10 月 1 日,《政府组织法》)——其中涉及本法的部分:第 38 条第 1 款\u0026quot;统计厅长(통계청장)\u0026ldquo;改为\u0026quot;国家数据处长(국가데이터처장)\u0026quot;\n②法律第 21311 号(2026 年 1 月 20 日)——部分条款自公布后 6 个月施行 现行版 施行日 2026 年 7 月 21 日(法律第 21311 号部分修正条款生效日) 结构 6 章 2 节,43 条(另有分支条号第 17 条之二、第 22 条之二、第 22 条之三,共 46 个条文单元);附则 3 块 官方原文(韩文) 国家法令信息中心(현행现行版) ｜ 制定版(法律第 20676 号) 官方英文译本 韩国法制研究院(KLRI)官方英译 ——本页英文页面即采用该官方译本 中文译本 无官方中文文本。本页中文译文由本网据韩文官方文本逐条译校,为非官方译本、仅供参考 相关法令 本法的《施行令》(대통령령)另行公布,施行日 2026 年 8 月 20 日;本页仅收录法律本身,不含施行令 收录范围 正文第 1–43 条 + 附则(法律第 20676 号、法律第 21065 号中涉及本法的部分、法律第 21311 号)。附则中官方页面本身以\u0026quot;省略\u0026quot;标示的其他法律修改清单,本页原样保留、不补全 法律全文(韩文官方文本) 제1장 총칙\n제1조(목적) 이 법은 인공지능의 건전한 발전과 신뢰 기반 조성에 필요한 기본적인 사항을 규정함으로써 국민의 권익과 존엄성을 보호하고 국민의 삶의 질 향상과 국가경쟁력을 강화하는 데 이바지함을 목적으로 한다.\n제2조(정의) 이 법에서 사용하는 용어의 뜻은 다음과 같다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n“인공지능”이란 학습, 추론, 지각, 판단, 언어의 이해 등 인간이 가진 지적 능력을 전자적 방법으로 구현한 것을 말한다.\n“인공지능시스템”이란 다양한 수준의 자율성과 적응성을 가지고 주어진 목표를 위하여 실제 및 가상환경에 영향을 미치는 예측, 추천, 결정 등의 결과물을 추론하는 인공지능 기반 시스템을 말한다.\n“인공지능기술”이란 인공지능을 구현하기 위하여 필요한 하드웨어ㆍ소프트웨어 기술 또는 그 활용 기술을 말한다.\n“고영향 인공지능”이란 사람의 생명, 신체의 안전 및 기본권에 중대한 영향을 미치거나 위험을 초래할 우려가 있는 인공지능시스템으로서 다음 각 목의 어느 하나의 영역에서 활용되는 것을 말한다.\n가. 「에너지법」 제2조제1호에 따른 에너지의 공급\n나. 「먹는물관리법」 제3조제1호에 따른 먹는물의 생산 공정\n다. 「보건의료기본법」 제3조제1호에 따른 보건의료의 제공 및 이용체계의 구축ㆍ운영\n라. 「의료기기법」 제2조제1항에 따른 의료기기 및 「디지털의료제품법」 제2조제2호에 따른 디지털의료기기의 개발 및 이용\n마. 「원자력시설 등의 방호 및 방사능 방재 대책법」 제2조제1항제1호에 따른 핵물질과 같은 항 제2호에 따른 원자력시설의 안전한 관리 및 운영\n바. 범죄 수사나 체포 업무를 위한 생체인식정보(얼굴ㆍ지문ㆍ홍채 및 손바닥 정맥 등 개인을 식별할 수 있는 신체적ㆍ생리적ㆍ행동적 특징에 관한 개인정보를 말한다)의 분석ㆍ활용\n사. 채용, 대출 심사 등 개인의 권리ㆍ의무 관계에 중대한 영향을 미치는 판단 또는 평가\n아. 「교통안전법」 제2조제1호부터 제3호까지에 따른 교통수단, 교통시설, 교통체계의 주요한 작동 및 운영\n자. 공공서비스 제공에 필요한 자격 확인 및 결정 또는 비용징수 등 국민에게 영향을 미치는 국가, 지방자치단체, 「공공기관의 운영에 관한 법률」 제4조에 따른 공공기관 등(이하 “국가기관등”이라 한다)의 의사결정\n차. 「교육기본법」 제9조제1항에 따른 유아교육ㆍ초등교육 및 중등교육에서의 학생 평가\n카. 그 밖에 사람의 생명ㆍ신체의 안전 및 기본권 보호에 중대한 영향을 미치는 영역으로서 대통령령으로 정하는 영역\n“생성형 인공지능”이란 입력한 데이터(「데이터 산업진흥 및 이용촉진에 관한 기본법」 제2조제1호에 따른 데이터를 말한다. 이하 같다)의 구조와 특성을 모방하여 글, 소리, 그림, 영상, 그 밖의 다양한 결과물을 생성하는 인공지능시스템을 말한다.\n“인공지능산업”이란 인공지능 또는 인공지능기술을 활용한 제품(이하 “인공지능제품”이라 한다)을 개발ㆍ제조ㆍ생산 또는 유통하거나 이와 관련한 서비스(이하 “인공지능서비스”라 한다)를 제공하는 산업을 말한다.\n“인공지능사업자”란 인공지능산업과 관련된 사업을 하는 자로서 다음 각 목의 어느 하나에 해당하는 법인, 단체, 개인 및 국가기관등을 말한다.\n가. 인공지능개발사업자: 인공지능을 개발하여 제공하는 자\n나. 인공지능이용사업자: 가목의 사업자가 제공한 인공지능을 이용하여 인공지능제품 또는 인공지능서비스를 제공하는 자\n“이용자”란 인공지능제품 또는 인공지능서비스를 제공받는 자를 말한다.\n“영향받는 자”란 인공지능제품 또는 인공지능서비스에 의하여 자신의 생명, 신체의 안전 및 기본권에 중대한 영향을 받는 자를 말한다.\n“인공지능사회”란 인공지능을 통하여 산업ㆍ경제, 사회ㆍ문화, 행정 등 모든 분야에서 가치를 창출하고 발전을 이끌어가는 사회를 말한다.\n“인공지능윤리”란 인간의 존엄성에 대한 존중을 기초로 하여, 국민의 권익과 생명ㆍ재산을 보호할 수 있는 안전하고 신뢰할 수 있는 인공지능사회를 구현하기 위하여 인공지능의 개발, 제공 및 이용 등 모든 영역에서 사회구성원이 지켜야 할 윤리적 기준을 말한다.\n“학습용데이터”란 인공지능의 개발ㆍ활용 등에 사용되는 데이터를 말한다.\n제3조(기본원칙 및 국가 등의 책무) ① 인공지능기술과 인공지능산업은 안전성과 신뢰성을 제고하여 국민의 삶의 질을 향상시키는 방향으로 발전되어야 한다.\n② 영향받는 자는 인공지능의 최종결과 도출에 활용된 주요 기준 및 원리 등에 대하여 기술적ㆍ합리적으로 가능한 범위에서 명확하고 의미 있는 설명을 제공받을 수 있어야 한다.\n③ 국가 및 지방자치단체는 인공지능사업자의 창의정신을 존중하고, 안전한 인공지능 이용환경의 조성을 위하여 노력하여야 한다.\n④ 국가 및 지방자치단체는 인공지능이 가져오는 사회ㆍ경제ㆍ문화와 국민의 일상생활 등 모든 영역에서의 변화에 대응하여 모든 국민이 안정적으로 적응할 수 있도록 시책을 강구하여야 한다.\n⑤ 국가 및 지방자치단체는 인공지능 관련 정책의 개발과 수립 과정에 인공지능제품 또는 인공지능서비스의 이용에 어려움을 겪는 장애인ㆍ고령자 등 대통령령으로 정하는 취약계층(이하 “인공지능취약계층”이라 한다)의 참여를 보장하고 의견이 반영될 수 있도록 노력하여야 한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n제4조(적용범위) ① 이 법은 국외에서 이루어진 행위라도 국내 시장 또는 이용자에게 영향을 미치는 경우에는 적용한다.\n② 이 법은 국방 또는 국가안보 목적으로만 개발ㆍ이용되는 인공지능으로서 대통령령으로 정하는 인공지능에 대하여는 적용하지 아니한다.\n제5조(다른 법률과의 관계) ① 인공지능, 인공지능기술, 인공지능산업 및 인공지능사회(이하 “인공지능등”이라 한다)에 관하여 다른 법률에 특별한 규정이 있는 경우를 제외하고는 이 법에서 정하는 바에 따른다.\n② 인공지능등에 관하여 다른 법률을 제정하거나 개정하는 경우에는 이 법의 목적에 부합하도록 하여야 한다.\n제2장 인공지능의 건전한 발전과 신뢰 기반 조성을 위한 추진체계\n제6조(인공지능 기본계획의 수립) ① 과학기술정보통신부장관은 관계 중앙행정기관의 장 및 지방자치단체의 장의 의견을 들어 3년마다 인공지능기술 및 인공지능산업의 진흥과 국가경쟁력 강화를 위하여 인공지능 기본계획(이하 “기본계획”이라 한다)을 제7조에 따른 국가인공지능전략위원회의 심의ㆍ의결을 거쳐 수립ㆍ변경 및 시행하여야 한다. 다만, 기본계획 중 대통령령으로 정하는 경미한 사항을 변경하는 경우에는 그러하지 아니하다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 기본계획에는 다음 각 호의 사항이 포함되어야 한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n인공지능등에 관한 정책의 기본 방향과 전략에 관한 사항\n인공지능산업의 체계적 육성을 위한 전문인력의 양성 및 인공지능 개발ㆍ활용 촉진 기반 조성 등에 관한 사항\n인공지능윤리의 확산 등 건전한 인공지능사회 구현을 위한 법ㆍ제도 및 문화에 관한 사항\n인공지능기술 개발 및 인공지능산업 진흥을 위한 재원의 확보와 투자의 방향 등에 관한 사항\n4의2. 「공공데이터의 제공 및 이용 활성화에 관한 법률」에 따른 공공데이터를 이용한 학습용데이터 생성, 공공데이터 제공 등의 범위와 기준 및 그 활성화에 관한 사항\n인공지능의 공정성ㆍ투명성ㆍ책임성ㆍ안전성ㆍ접근성 확보 등 신뢰 기반 조성에 관한 사항\n인공지능기술의 발전 방향 및 그에 따른 교육ㆍ노동ㆍ경제ㆍ문화 등 사회 각 영역의 변화와 대응에 관한 사항\n6의2. 인공지능기술의 이해 및 활용을 위한 교육의 지원 및 홍보에 관한 사항\n인공지능제품 또는 인공지능서비스에 대한 인공지능취약계층의 접근ㆍ이용을 보장하기 위한 사항\n그 밖에 인공지능기술 및 인공지능산업의 진흥과 국제협력 등 국가경쟁력 강화를 위하여 과학기술정보통신부장관이 필요하다고 인정하는 사항\n③ 과학기술정보통신부장관은 기본계획을 수립할 때에는 「지능정보화 기본법」 제6조제1항에 따른 종합계획 및 같은 법 제7조제1항에 따른 실행계획을 고려하여야 하며, 제2항제4호의2에 따른 학습용데이터 중 「공공데이터의 제공 및 이용 활성화에 관한 법률」에 따라 공공데이터를 학습용데이터로 제공하기 위한 사항에 대해서는 행정안전부장관과 협의하여 정한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n④ 과학기술정보통신부장관은 관계 중앙행정기관, 지방자치단체 및 공공기관(「지능정보화 기본법」 제2조제16호에 따른 공공기관을 말한다. 이하 같다)의 장에게 기본계획의 수립에 필요한 자료의 제출을 요청할 수 있다. 이 경우 자료의 제출을 요청받은 기관의 장은 특별한 사정이 없으면 이에 따라야 한다.\n⑤ 기본계획은 「지능정보화 기본법」 제13조제1항에 따른 인공지능 및 인공지능산업 분야의 부문별 추진계획으로 본다.\n⑥ 중앙행정기관의 장 및 지방자치단체의 장은 소관 주요 정책을 수립하고 집행할 때 기본계획을 고려하여야 한다.\n⑦ 기본계획의 수립ㆍ변경 및 시행에 필요한 사항은 대통령령으로 정한다.\n제7조(국가인공지능전략위원회) ① 인공지능 발전과 신뢰 기반 조성 등을 위한 주요 정책 등에 관한 사항을 심의ㆍ의결하기 위하여 대통령 소속으로 국가인공지능전략위원회(이하 “위원회”라 한다)를 둔다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 위원회는 위원장 1명과 3명 이내의 부위원장을 포함한 60명 이내의 위원으로 구성한다. 이 경우 제4항제4호에 따른 위원이 전체 위원의 과반수가 되어야 하고, 특정 성(性)으로만 위원회를 구성할 수 없다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n③ 위원회의 위원장은 대통령이 되고, 부위원장은 제4항제1호 또는 제4호에 해당하는 사람 중 대통령이 지명하는 사람이 된다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n④ 위원회의 위원은 다음 각 호의 사람이 된다.\n대통령령으로 정하는 관계 중앙행정기관의 장\n국가안보실의 인공지능에 관한 업무를 담당하는 차장\n대통령비서실의 인공지능에 관한 업무를 보좌하는 수석비서관\n인공지능 관련 전문지식과 경험이 풍부한 사람 중 대통령이 위촉하는 사람\n⑤ 위원회의 위원장은 위원회를 대표하고 위원회의 사무를 총괄한다.\n⑥ 위원회의 위원장은 필요한 경우 부위원장으로 하여금 그 직무를 대행하게 할 수 있다.\n⑦ 제4항제4호에 따른 위원의 임기는 2년으로 하되 한 차례에 한정하여 연임할 수 있다.\n⑧ 위원회에 간사위원 1명을 두며, 간사위원은 제4항제3호의 위원이 된다.\n⑨ 위원회의 위원은 그 직무상 알게 된 비밀을 타인에게 누설하거나 직무상 목적 외의 용도로 사용하여서는 아니 된다. 다만, 다른 법률에 특별한 규정이 있는 경우에는 그러하지 아니하다.\n⑩ 위원회의 위원장은 위원회의 회의를 소집하고 그 의장이 된다.\n⑪ 위원회의 회의는 위원 과반수의 출석으로 개의하고, 출석위원 과반수의 찬성으로 의결한다.\n⑫ 위원회의 업무 및 운영을 지원하기 위하여 위원회에 지원단을 둔다.\n⑬ 위원회는 이 법 시행일부터 5년간 존속한다.\n⑭ 그 밖에 위원회와 제12항에 따른 지원단의 구성 및 운영 등에 필요한 사항은 대통령령으로 정한다.\n[제목개정 2026. 1. 20.]\n제8조(위원회의 기능) ① 위원회는 다음 각 호의 사항을 심의ㆍ의결한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n기본계획의 수립ㆍ변경 및 시행의 점검ㆍ분석에 관한 사항\n인공지능등 관련 국가 비전 및 중장기 전략 수립에 관한 사항\n2의2. 인공지능 관련 정책 및 사업 등의 수립ㆍ조정 및 부처 간 조율에 관한 사항\n2의3. 인공지능 관련 정책 및 사업 등에 대한 이행점검 및 성과관리에 관한 사항\n인공지능등에 관한 연구개발 전략 수립에 관한 사항\n인공지능등에 관한 투자 방향 설정 및 투자 전략 수립에 관한 사항\n인공지능산업 발전과 경쟁력을 저해하는 규제의 발굴 및 개선에 관한 사항\n5의2. 인공지능등 관련 기술ㆍ인력ㆍ입지 등 제도 개선에 관한 사항\n5의3. 인공지능 및 인공지능기술 관련 전문인력의 양성 및 지원에 관한 사항\n인공지능 데이터센터(「지능정보화 기본법」 제40조제1항에 따른 데이터센터를 말한다. 이하 같다) 등 인프라 확충 방안에 관한 사항 6의2. 인공지능 발전을 위한 데이터(학습용데이터를 포함한다) 수집ㆍ관리 및 활용 촉진에 관한 사항\n제조업ㆍ서비스업 등 산업부문 및 공공부문에서의 인공지능 활용 촉진에 관한 사항\n인공지능 국제규범 마련 등 인공지능 관련 국제협력에 관한 사항\n제2항에 따른 권고 또는 의견의 표명에 관한 사항\n고영향 인공지능 규율에 관한 사항\n고영향 인공지능과 관련된 사회적 변화 양상과 정책적 대응에 관한 사항\n이 법 또는 다른 법률에서 위원회의 심의사항으로 정한 사항\n그 밖에 위원회의 위원장이 필요하다고 인정하여 위원회의 회의에 부치는 사항\n② 위원회는 국가기관등의 장 및 인공지능사업자 등에 대하여 인공지능의 올바른 사용과 인공지능윤리의 실천, 인공지능기술의 안전성ㆍ신뢰성에 관한 권고 또는 의견의 표명을 할 수 있다.\n③ 위원회가 국가기관등의 장에게 법령ㆍ제도의 개선 또는 실천방안의 수립 등에 대하여 제2항에 따른 권고 또는 의견의 표명을 한 때에는 해당 국가기관등의 장은 법령ㆍ제도 등의 개선방안과 실천방안 등을 수립하여야 한다.\n제9조(위원의 제척ㆍ기피 및 회피) ① 위원회의 위원은 업무의 공정성 확보를 위하여 다음 각 호의 어느 하나에 해당하는 경우에는 해당 안건의 심의ㆍ의결에서 제척(除斥)된다.\n위원 또는 위원이 속한 법인ㆍ단체 등과 직접적인 이해관계가 있는 경우\n위원의 가족(「민법」 제779조에 따른 가족을 말한다)이 이해관계인인 경우\n② 심의 대상 안건의 당사자(당사자가 법인ㆍ단체 등인 경우에는 그 임원 및 직원을 포함한다)는 위원에게 공정한 직무집행을 기대하기 어려운 사정이 있으면 위원회에 기피 신청을 할 수 있으며, 위원회는 기피 신청이 타당하다고 인정하면 의결로 기피를 결정하여야 한다.\n③ 위원은 제1항 또는 제2항의 사유에 해당하면 스스로 해당 안건의 심의를 회피하여야 한다.\n제10조(분과위원회 등) ① 위원회는 위원회의 업무를 전문 분야별로 수행하기 위하여 필요한 경우 분과위원회를 둘 수 있다.\n② 위원회는 인공지능등 관련 특정 현안을 논의하기 위하여 필요한 경우 특별위원회를 둘 수 있다.\n③ 위원회는 인공지능등 관련 사항을 전문적으로 검토하기 위하여 관계 전문가 등으로 구성된 자문단을 둘 수 있다.\n④ 위원회는 정부 내 인공지능 주요 시책의 수립과 사업의 효율적인 추진을 위하여 대통령령으로 정하는 인공지능책임관으로 구성되는 인공지능책임관협의회를 운영할 수 있다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n⑤ 그 밖에 분과위원회, 특별위원회, 자문단 및 인공지능책임관협의회의 구성ㆍ운영 등에 필요한 사항은 대통령령으로 정한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n제11조(인공지능정책센터) ① 과학기술정보통신부장관은 인공지능 관련 정책의 개발과 국제규범 정립ㆍ확산에 필요한 업무를 종합적으로 수행하기 위하여 인공지능정책센터(이하 “센터”라 한다)를 지정할 수 있다.\n② 센터는 다음 각 호의 사업을 수행한다.\n기본계획의 수립ㆍ시행에 필요한 전문기술의 지원\n인공지능과 관련한 시책의 개발 및 관련 사업의 기획ㆍ시행에 관한 전문기술의 지원\n인공지능의 활용 확산에 따른 사회, 경제, 문화 및 국민의 일상생활 등에 미치는 영향의 조사ㆍ분석\n인공지능 및 인공지능기술 관련 정책 개발을 지원하기 위한 동향 분석，사회ㆍ문화 변화와 미래예측 및 법ㆍ제도의 조사ㆍ연구\n다른 법령에서 센터의 업무로 정하거나 센터에 위탁한 사업\n그 밖에 국가기관등의 장이 위탁하는 사업\n③ 그 밖에 센터의 지정 등에 필요한 사항은 대통령령으로 정한다.\n제12조(인공지능안전연구소) ① 과학기술정보통신부장관은 인공지능과 관련하여 발생할 수 있는 위험으로부터 국민의 생명ㆍ신체ㆍ재산 등을 보호하고 인공지능사회의 신뢰 기반을 유지하기 위한 상태(이하 “인공지능안전”이라 한다)를 확보하기 위한 업무를 전문적이고 효율적으로 수행하기 위하여 인공지능안전연구소(이하 “안전연구소”라 한다)를 운영할 수 있다.\n② 안전연구소는 다음 각 호의 사업을 수행한다.\n인공지능안전 관련 위험 정의 및 분석\n인공지능안전 정책 연구\n인공지능안전 평가 기준ㆍ방법 연구\n인공지능안전 기술 및 표준화 연구\n인공지능안전 관련 국제교류ㆍ국제협력\n제32조에 따른 인공지능시스템의 안전성 확보에 관한 지원\n그 밖에 인공지능안전에 관한 사업으로서 대통령령으로 정하는 사업\n③ 정부는 안전연구소의 운영과 사업 추진 등에 필요한 경비를 예산의 범위에서 출연하거나 지원할 수 있다.\n④ 그 밖에 안전연구소의 운영 등에 필요한 사항은 대통령령으로 정한다.\n제3장 인공지능기술 개발 및 산업 육성\n제1절 인공지능산업 기반 조성\n제13조(인공지능기술 개발 및 안전한 이용 지원) ① 정부는 인공지능기술 개발 활성화를 위하여 다음 각 호의 사업을 지원할 수 있다.\n국내외 인공지능기술 동향ㆍ수준 및 관련 제도의 조사\n인공지능기술의 연구ㆍ개발, 시험 및 평가 또는 개발된 기술의 활용\n인공지능기술 확산, 인공지능기술 협력ㆍ이전 등 기술의 실용화 및 사업화 지원\n인공지능기술의 구현을 위한 정보의 원활한 유통 및 산학협력\n그 밖에 인공지능기술의 개발 및 연구ㆍ조사와 관련하여 대통령령으로 정하는 사업\n② 정부는 인공지능기술의 안전하고 편리한 이용을 위하여 다음 각 호의 사업을 지원할 수 있다.\n「지능정보화 기본법」 제60조제1항 각 호의 사항을 인공지능기술로 구현하는 연구개발 사업\n「지능정보화 기본법」 제60조제3항에 따른 비상정지 기능을 인공지능제품 또는 인공지능서비스에서 구현하기 위한 기술 연구 지원 및 해당 기술의 확산을 위한 사업\n인공지능기술의 개발에 있어서 「지능정보화 기본법」 제61조제2항에 따른 사생활등의 보호에 적합한 설계 기준 및 기술의 연구개발 및 보급 사업\n인공지능기술의 「지능정보화 기본법」 제56조제1항에 따른 사회적 영향평가의 실시와 적용을 위한 연구개발 사업\n인공지능이 인간의 존엄성 및 기본권을 존중하는 방향으로 개발ㆍ이용될 수 있도록 하는 기술 또는 기준 등의 연구개발 및 보급 사업\n인공지능의 안전한 개발과 이용을 위한 인식개선, 올바른 이용방법과 안전 환경 조성을 위한 교육 및 홍보 사업\n그 밖에 인공지능의 개발과 이용에 있어서 국민의 기본권, 신체와 재산을 보호하기 위하여 필요한 사업\n③ 정부는 제2항에 따른 사업의 결과를 누구든지 손쉽게 이용할 수 있도록 공개하고 보급하여야 한다. 이 경우 기술을 개발한 자를 보호하기 위하여 필요한 경우에는 보호기간을 정하여 기술사용료를 받을 수 있게 하거나 그 밖의 방법으로 보호할 수 있다.\n제14조(인공지능기술의 표준화) ① 정부는 인공지능기술, 학습용데이터, 인공지능의 안전성ㆍ신뢰성 등과 관련된 표준화를 위하여 다음 각 호의 사업을 추진할 수 있다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n인공지능기술 관련 표준의 제정ㆍ개정 및 폐지와 그 보급\n인공지능기술 관련 국내외 표준의 조사ㆍ연구개발\n그 밖에 인공지능기술 관련 표준화 사업\n② 정부는 제1항제1호에 따라 제정된 표준을 고시하여 관련 사업자에게 그 준수를 권고할 수 있다.\n③ 정부는 민간 부문에서 추진하는 인공지능기술 관련 표준화 사업에 필요한 지원을 할 수 있다.\n④ 정부는 인공지능기술 표준과 관련된 국제표준기구 또는 국제표준기관과 협력체계를 유지ㆍ강화하여야 한다.\n⑤ 그 밖에 제1항 및 제3항에 따른 표준화 사업의 추진 및 지원 등과 관련하여 필요한 사항은 대통령령으로 정한다.\n제15조(인공지능 학습용데이터 관련 시책의 수립 등) ① 과학기술정보통신부장관은 관계 중앙행정기관의 장과 협의하여 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통ㆍ활용 촉진 및 품질수준 확보 등을 위하여 필요한 시책을 추진하여야 한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 정부는 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통 및 활용 등에 관한 시책을 효율적으로 추진하기 위하여 지원대상사업을 선정하고 예산의 범위에서 지원할 수 있다.\n③ 정부는 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통 및 활용의 활성화 등을 위하여 다양한 학습용데이터를 제작ㆍ생산하여 제공하는 사업(이하 “학습용데이터 구축사업”이라 한다)을 시행할 수 있다.\n④ 과학기술정보통신부장관은 학습용데이터 구축사업의 효율적 수행을 위하여 학습용데이터를 통합적으로 제공ㆍ관리할 수 있는 시스템(이하 “통합제공시스템”이라 한다)을 구축ㆍ관리하고 민간이 자유롭게 이용할 수 있도록 제공하여야 한다.\n⑤ 과학기술정보통신부장관은 통합제공시스템을 이용하는 자에 대하여 비용을 징수할 수 있다.\n⑥ 그 밖에 제2항에 따른 지원대상사업의 선정 및 지원, 학습용데이터 구축사업의 시행, 통합제공시스템의 구축ㆍ관리 및 제5항에 따른 비용의 징수 등에 필요한 사항은 대통령령으로 정한다.\n제2절 인공지능기술 개발 및 인공지능산업 활성화\n제16조(인공지능기술 도입ㆍ활용 시책 등) ① 국가 및 지방자치단체는 기업 및 공공기관의 인공지능기술 도입 촉진 및 활용 확산을 위한 시책을 수립ㆍ시행하여야 한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n② 국가 및 지방자치단체는 기업 및 공공기관의 인공지능기술 도입 촉진 및 활용 확산을 위하여 필요한 경우에는 다음 각 호의 지원을 할 수 있다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n인공지능기술, 인공지능제품 또는 인공지능서비스의 개발 지원 및 연구ㆍ개발 성과의 확산\n인공지능기술을 도입ㆍ활용하고자 하는 기업 및 공공기관에 대한 컨설팅 지원\n2의2. 공공기관이 보유ㆍ관리하고 있는 데이터를 학습용데이터로 생성ㆍ제공하고 적절한 품질수준을 확보하기 위하여 필요한 지원\n「중소기업기본법」 제2조제1항에 따른 중소기업, 「벤처기업육성에 관한 특별법」 제2조제1항에 따른 벤처기업 및 「소상공인기본법」 제2조제1항에 따른 소상공인(이하 “중소기업등”이라 한다)의 임직원에 대한 인공지능기술 도입 및 활용 관련 교육 지원\n중소기업등의 인공지능기술 도입 및 활용에 사용되는 자금의 지원\n그 밖에 기업 및 공공기관의 인공지능기술 도입 및 활용을 촉진하기 위하여 대통령령으로 정하는 사항\n③ 국가기관등은 업무 수행에 필요한 제품 또는 서비스를 구매하거나 용역을 발주하려는 경우 대통령령으로 정하는 인공지능제품 또는 인공지능서비스를 우선적으로 고려하여야 한다. 다만, 업무 특성상 인공지능기술의 활용이 적합하지 아니한 경우에는 그러하지 아니하다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n④ 제3항에 따른 인공지능제품 또는 인공지능서비스의 구매 또는 사용으로 국가기관등에 손해가 발생한 경우에도 그 구매 또는 사용 업무를 담당한 자는 해당 기관의 손해에 대하여 배상할 책임이 없다. 다만, 해당 업무 담당자의 고의 또는 중대한 과실로 손해가 발생한 경우에는 그러하지 아니하다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n⑤ 제2항에 따른 지원에 필요한 사항은 대통령령으로 정한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n[제목개정 2026. 1. 20.]\n제17조(중소기업등을 위한 특별지원) ① 이 법에 따라 인공지능기술 및 인공지능산업과 관련한 각종 지원시책을 시행할 때에는 중소기업등을 우선 고려하여야 한다.\n② 정부는 인공지능산업에 대한 중소기업등의 참여 활성화를 위하여 노력하여야 하며, 이와 관련한 사항을 기본계획에 반영하여야 한다.\n③ 과학기술정보통신부장관은 인공지능의 안전성 및 신뢰성 확보를 위하여 중소기업등의 제34조에 따른 조치 이행 및 제35조에 따른 영향평가를 지원할 수 있다.\n제17조의2(인공지능제품 및 인공지능서비스 이용비용의 지원) ① 국가와 지방자치단체는 경제적 여건으로 인하여 인공지능제품 및 인공지능서비스를 이용하기 어려운 사람에 대하여 예산의 범위에서 그 비용의 전부 또는 일부를 지원할 수 있다.\n② 제1항에 따른 비용 지원의 요건과 대상 등에 필요한 사항은 대통령령으로 정한다.\n[본조신설 2026. 1. 20.]\n제18조(창업의 활성화 등) ① 정부는 인공지능산업 분야의 창업을 활성화하기 위하여 다음 각 호의 사업을 추진할 수 있다.\n인공지능산업 분야의 창업자 발굴 및 육성ㆍ지원 등에 관한 사업\n인공지능산업 분야의 창업 활성화를 위한 교육ㆍ훈련에 관한 사업\n제21조에 따른 전문인력의 우수 인공지능기술에 대한 사업화 지원\n인공지능기술의 가치평가 및 창업자금의 금융지원\n인공지능 관련 연구 및 기술개발 성과의 제공\n인공지능산업 분야의 창업을 지원하는 기관ㆍ단체의 육성\n그 밖에 인공지능산업 분야의 창업 활성화를 위하여 필요한 사업\n② 지방자치단체는 인공지능산업 분야의 창업을 지원하는 공공기관 등 공공단체에 출연하거나 출자할 수 있다.\n③ 중앙행정기관의 장은 인공지능산업 분야의 창업을 활성화하기 위하여 중소벤처기업부장관과 협의하여 「벤처투자 촉진에 관한 법률」 제70조에 따른 벤처투자모태조합을 활용한 지원을 할 수 있다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n④ 제3항에 따른 지원을 위한 자금은 다음 각 호의 재원으로 조성한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n국가, 지방자치단체 또는 공공기관의 출자금\n국가, 지방자치단체 또는 공공기관 외의 자로서 인공지능산업과 관련하여 벤처투자모태조합에 출자를 희망하는 자의 출자금\n그 밖의 부대수입\n⑤ 제3항에 따른 벤처투자모태조합에의 출자에 필요한 사항은 대통령령으로 정한다. \u0026lt;신설 2026. 1. 20.\u0026gt;\n[제목개정 2026. 1. 20.]\n제19조(인공지능 융합의 촉진) ① 정부는 인공지능산업과 그 밖의 산업 간 융합을 촉진하고 전 분야에서 인공지능 활용을 활성화하기 위하여 필요한 시책을 수립하여 추진하여야 한다.\n② 정부는 인공지능 융합 제품 및 서비스의 개발을 지원하기 위하여 필요한 경우에는 「국가연구개발혁신법」에 따른 국가연구개발사업에 인공지능 융합 제품 및 서비스에 관한 연구개발과제를 우선적으로 반영하여 추진할 수 있다.\n③ 정부는 제2항에 따라 개발된 인공지능 융합 제품 및 서비스에 대하여는 「정보통신 진흥 및 융합 활성화 등에 관한 특별법」 제37조에 따른 임시허가 및 같은 법 제38조의2에 따른 실증을 위한 규제특례가 원활히 시행될 수 있도록 적극 지원하여야 한다.\n제20조(제도개선 등) ① 정부는 인공지능산업의 발전과 신뢰 기반 조성을 위하여 법령의 정비 등 관련 제도를 개선할 수 있도록 노력하여야 한다.\n② 정부는 제1항에 따른 제도개선을 촉진하기 위하여 관련 법ㆍ제도의 연구 및 사회 각계의 의견수렴 등에 필요한 행정적ㆍ재정적 지원을 할 수 있다.\n제21조(전문인력의 확보) ① 과학기술정보통신부장관은 인공지능기술의 개발 및 인공지능산업의 발전을 위하여 「지능정보화 기본법」 제23조제1항에 따른 시책에 따라 인공지능 및 인공지능기술 관련 전문인력을 양성하고 지원할 수 있도록 다음 각 호의 사업을 추진할 수 있다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n전문인력의 직무역량 강화 및 경력개발을 위한 교육훈련 프로그램 개발ㆍ활용\n전문인력의 취업 지원 및 신규 인력유입 활성화 등 고용 촉진\n전문인력의 공직 진출 기회 확대 등 진출 다변화 촉진\n전문인력의 국내외 연수 지원 및 국제교류 활성화\n전문인력의 근로환경 개선과 처우 증진 등 복지 향상\n그 밖에 인공지능 및 인공지능기술 관련 전문인력의 양성ㆍ지원을 위한 사업\n② 정부는 인공지능 및 인공지능기술 관련 해외 전문인력의 확보를 위하여 다음 각 호의 시책을 추진할 수 있다.\n인공지능 및 인공지능기술 관련 해외 대학ㆍ연구기관ㆍ기업 등의 전문인력에 관한 조사ㆍ분석\n해외 전문인력의 유치를 위한 국제네트워크 구축\n해외 전문인력의 국내 취업 지원\n국내 인공지능 연구기관의 해외진출 및 해외 인공지능 연구기관의 국내 유치 지원\n인공지능 및 인공지능기술 관련 국제기구 및 국제행사의 국내 유치 지원\n그 밖에 해외 전문인력의 확보를 위하여 필요한 사항\n제22조(국제협력 및 해외시장 진출의 지원) ① 정부는 인공지능과 관련한 국제적 동향을 파악하고 국제협력을 추진하여야 한다.\n② 정부는 인공지능산업의 경쟁력 강화와 해외시장 진출을 촉진하기 위하여 인공지능산업에 종사하는 개인ㆍ기업 또는 단체 등에 대하여 다음 각 호의 지원을 할 수 있다.\n인공지능산업 관련 정보ㆍ기술ㆍ인력의 국제교류\n인공지능산업 관련 해외진출에 관한 정보의 수집ㆍ분석 및 제공\n국가 간 인공지능기술, 인공지능제품 또는 인공지능서비스의 공동 연구ㆍ개발 및 국제표준화\n인공지능산업 관련 외국자본의 투자유치\n인공지능등 관련 해외 전문 학회 및 전시회 참가 등 홍보 및 해외 마케팅\n인공지능제품 또는 인공지능서비스의 수출에 필요한 판매체계ㆍ유통체계 및 협력체계 등의 구축\n인공지능윤리에 관한 국제적 동향 파악 및 국제협력\n그 밖에 인공지능산업의 경쟁력 강화와 해외시장 진출 촉진을 위하여 필요한 사항\n③ 정부는 제2항 각 호에 따른 지원을 효율적으로 수행하기 위하여 대통령령으로 정하는 바에 따라 공공기관 또는 그 밖의 단체에 이를 위탁하거나 대행하게 할 수 있으며, 이에 필요한 비용을 보조할 수 있다.\n제22조의2(인공지능연구소의 설립 및 지원 등) ① 대학, 기업 등 대통령령으로 정하는 자는 단독으로 또는 공동으로 인공지능의 개발ㆍ활용에 관한 연구소(이하 “인공지능연구소”라 한다)를 설립ㆍ운영할 수 있다.\n② 제1항에 따라 대학, 기업 등 대통령령으로 정하는 자가 인공지능연구소를 설립하려는 경우에는 다음 각 호의 요건을 갖추고 과학기술정보통신부장관의 허가를 받아야 한다.\n3명 이상의 발기인(發起人)이 있을 것\n제5항의 사업을 수행할 수 있는 인력ㆍ시설 등의 능력을 보유하고 있을 것\n그 밖에 인공지능연구소의 설립ㆍ운영을 위하여 필요한 것으로서 대통령령으로 정하는 요건을 갖출 것\n③ 인공지능연구소에 소장을 둔다. 인공지능연구소의 소장은 인공지능연구소를 대표하고 인공지능연구소의 업무를 총괄한다.\n④ 인공지능연구소의 정관에는 다음 각 호의 사항이 포함되어야 한다.\n목적\n명칭\n사무소의 소재지\n자산에 관한 규정\n소장의 자격과 임면에 관한 규정\n소장의 책임과 권한에 관한 규정\n⑤ 인공지능연구소는 업종별ㆍ기능별로 다음 각 호의 사업을 수행한다.\n인공지능기술 연구개발\n인공지능기술과 다른 기술 및 학제 간 융합에 관한 연구개발\n인공지능기술 연구개발 성과 관리ㆍ이전ㆍ활용 및 사업화\n인공지능기술 연구개발 전문인력 양성\n인공지능기술 연구개발 관련 국제교류ㆍ국제협력\n그 밖에 인공지능기술 연구개발에 필요한 사항\n⑥ 정부와 지방자치단체는 예산의 범위에서 인공지능연구소의 운영과 사업 추진 등에 필요한 경비를 지원할 수 있다.\n⑦ 인공지능연구소는 운영에 필요한 재원을 조성하기 위하여 정부ㆍ지방자치단체 외의 자로부터 보조금 또는 기부금 등을 받거나, 정관으로 정하는 바에 따라 수익사업을 할 수 있다.\n⑧ 인공지능연구소의 소장은 인공지능기술의 연구개발 등을 위하여 필요한 경우 제1항에 따른 대학, 기업 등 대통령령으로 정하는 자와 협의하여 임직원을 파견받거나 겸임근무하게 하여 인공지능연구소의 연구 등을 담당하게 할 수 있으며, 파견받은 임직원의 소속 기관에 필요한 지원을 할 수 있다. 이 경우 필요하면 과학기술정보통신부장관에게 협의를 위한 지원을 요청할 수 있다.\n⑨ 인공지능연구소에 관하여 이 법에서 정한 것을 제외하고는 「민법」 중 재단법인에 관한 규정을 준용한다.\n⑩ 과학기술정보통신부장관은 인공지능연구소가 다음 각 호의 어느 하나에 해당하는 경우 시정을 명하거나 그 설립허가를 취소할 수 있다. 다만, 제1호 또는 제2호에 해당하는 경우 그 허가를 취소하여야 한다.\n거짓이나 그 밖의 부정한 방법으로 설립허가를 받은 경우\n목적 달성이 불가능하게 된 경우\n제2항에 따른 허가 요건을 충족하지 못하게 된 경우\n목적사업 외의 사업을 한 경우\n법령, 정관 또는 이 법에 따른 명령을 위반한 경우\n공익을 해치는 행위를 한 경우\n정당한 사유 없이 설립허가를 받은 날부터 6개월 이내에 목적사업을 시작하지 아니하거나 1년 이상 사업실적이 없는 경우\n⑪ 과학기술정보통신부장관은 제10항에 따라 인공지능연구소의 설립허가를 취소하려는 경우에는 청문을 하여야 한다.\n⑫ 그 밖에 인공지능연구소의 설립 절차, 운영, 지원 등에 필요한 사항은 대통령령으로 정한다.\n[본조신설 2026. 1. 20.]\n제22조의3(인공지능기술 확보를 위한 연구기관의 설립ㆍ운영) 과학기술정보통신부장관은 혁신적인 인공지능기술의 확보를 위하여 필요한 경우 대통령령으로 정하는 바에 따라 인공지능의 개발ㆍ활용 등에 관한 연구를 수행하는 기관을 설립ㆍ운영할 수 있다.\n[본조신설 2026. 1. 20.]\n제23조(인공지능집적단지 지정 등) ① 국가 및 지방자치단체는 인공지능산업의 진흥과 인공지능 개발ㆍ활용의 경쟁력 강화를 위하여 인공지능 및 인공지능기술의 연구ㆍ개발을 수행하는 기업, 기관이나 단체의 기능적ㆍ물리적ㆍ지역적 집적화를 추진할 수 있다.\n② 국가 및 지방자치단체는 제1항에 따른 집적화를 위하여 필요한 경우에는 대통령령으로 정하는 바에 따라 인공지능집적단지(이하 “인공지능집적단지”라 한다)를 지정하여 행정적ㆍ재정적ㆍ기술적 지원을 할 수 있다.\n③ 국가 및 지방자치단체는 다음 각 호의 어느 하나에 해당하는 경우 인공지능집적단지의 지정을 취소할 수 있다. 다만, 제1호에 해당하는 경우에는 그 지정을 취소하여야 한다.\n거짓이나 그 밖의 부정한 방법으로 지정을 받은 경우\n인공지능집적단지 지정의 목적을 달성하기 어렵다고 인공지능집적단지를 지정한 국가 또는 지방자치단체의 장이 인정하는 경우\n④ 정부는 제1항에 따른 집적화를 지역에 효과적으로 정착시키기 위하여 관련 업무를 종합적으로 지원하는 전담기관을 설치하거나 지정할 수 있다.\n⑤ 정부는 제4항에 따른 전담기관의 운영 및 사업 수행에 필요한 비용의 전부 또는 일부를 출연하거나 보조할 수 있다.\n⑥ 그 밖에 인공지능집적단지의 지정 및 지정취소와 제4항에 따른 전담기관의 설치 또는 지정 등에 필요한 사항은 대통령령으로 정한다.\n제24조(인공지능 실증기반 조성 등) ① 국가 및 지방자치단체는 인공지능사업자가 개발하거나 이전받은 기술의 실증, 성능시험, 제30조에 따른 검ㆍ인증등(이하 “실증시험등”이라 한다)을 지원하기 위하여 시험, 평가 등에 필요한 시설ㆍ장비ㆍ설비 등(이하 “실증기반등”이라 한다)을 구축ㆍ운영할 수 있다.\n② 국가 및 지방자치단체는 실증시험등을 촉진하기 위하여 대통령령으로 정하는 기관이 보유하고 있는 실증기반등을 인공지능사업자에게 개방할 수 있다.\n③ 그 밖에 실증기반등의 구축ㆍ운영 및 개방 등에 필요한 사항은 대통령령으로 정한다.\n제25조(인공지능 데이터센터 관련 시책의 추진 등) ① 정부는 인공지능의 개발ㆍ활용 등에 이용되는 데이터센터(이하 “인공지능 데이터센터”라 한다)의 구축 및 운영을 활성화하기 위하여 필요한 시책을 추진하여야 한다.\n② 정부는 제1항에 따른 시책을 추진하기 위하여 다음 각 호의 업무를 수행할 수 있다.\n인공지능 데이터센터의 구축 및 운영에 필요한 행정적ㆍ재정적 지원\n중소기업, 연구기관 등의 인공지능 데이터센터 이용 지원\n인공지능 데이터센터 등 인공지능 관련 인프라 시설의 지역별 균형 발전을 위한 지원\n제26조(한국인공지능진흥협회의 설립) ① 인공지능등과 관련한 연구 및 업무에 종사하는 자는 인공지능의 개발ㆍ이용 촉진, 인공지능산업 및 인공지능기술의 진흥, 인공지능등에 대한 교육ㆍ홍보 등을 위하여 대통령령으로 정하는 바에 따라 과학기술정보통신부장관의 인가를 받아 한국인공지능진흥협회(이하 “협회”라 한다)를 설립하거나 협회로 지정받을 수 있다.\n② 협회는 법인으로 한다.\n③ 협회는 다음 각 호의 업무를 수행한다.\n인공지능기술, 인공지능제품 또는 인공지능서비스의 이용 촉진 및 확산\n인공지능등에 대한 현황 및 관련 통계 조사\n인공지능사업자를 위한 공동이용시설의 설치ㆍ운영 및 전문인력 양성을 위한 교육 등\n인공지능사업자 및 인공지능 관련 전문인력의 해외진출 지원\n안전하고 신뢰할 수 있는 인공지능의 개발ㆍ활용을 위한 교육 및 홍보\n이 법 또는 다른 법률에 따라 협회가 위탁받은 사업\n그 밖에 협회의 설립목적을 달성하는 데 필요한 사업으로서 정관으로 정하는 사업\n④ 국가 및 지방자치단체는 인공지능산업의 발전과 신뢰 기반 조성을 위하여 필요한 경우 예산의 범위에서 협회의 사업수행에 필요한 자금을 지원하거나 운영에 필요한 경비를 보조할 수 있다.\n⑤ 협회 회원의 자격과 임원에 관한 사항, 협회의 업무 등은 정관으로 정하며, 그 밖에 정관에 포함하여야 할 사항은 대통령령으로 정한다.\n⑥ 과학기술정보통신부장관은 제1항에 따른 인가를 한 때에는 그 사실을 공고하여야 한다.\n⑦ 협회에 관하여 이 법에 규정된 것을 제외하고는 「민법」 중 사단법인에 관한 규정을 준용한다.\n제4장 인공지능윤리 및 신뢰성 확보\n제27조(인공지능 윤리원칙 등) ① 정부는 인공지능윤리의 확산을 위하여 다음 각 호의 사항을 포함하는 인공지능 윤리원칙(이하 “윤리원칙”이라 한다)을 대통령령으로 정하는 바에 따라 제정ㆍ공표할 수 있다.\n인공지능의 개발ㆍ활용 등의 과정에서 사람의 생명과 신체, 정신적 건강 등에 해가 되지 아니하도록 하는 안전성과 신뢰성에 관한 사항\n인공지능기술이 적용된 제품ㆍ서비스 등을 모든 사람이 자유롭고 편리하게 이용할 수 있는 접근성에 관한 사항\n사람의 삶과 번영에의 공헌을 위한 인공지능의 개발ㆍ활용 등에 관한 사항\n② 과학기술정보통신부장관은 사회 각계의 의견을 수렴하여 윤리원칙이 인공지능의 개발ㆍ활용 등에 관여하는 모든 사람에 의하여 실현될 수 있도록 실천방안을 수립하고 이를 공개 및 홍보ㆍ교육하여야 한다.\n③ 중앙행정기관 또는 지방자치단체의 장이 인공지능윤리기준(그 명칭 및 형태를 불문하고 인공지능윤리에 관한 법령, 기준, 지침, 가이드라인 등을 말한다)을 제정하거나 개정하는 경우 과학기술정보통신부장관은 윤리원칙 및 제2항에 따른 실천방안과의 연계성ㆍ정합성 등에 관한 권고 또는 의견의 표명을 할 수 있다.\n제28조(민간자율인공지능윤리위원회의 설치 등) ① 다음 각 호의 기관 또는 단체는 윤리원칙을 준수하기 위하여 민간자율인공지능윤리위원회(이하 “민간자율위원회”라 한다)를 둘 수 있다.\n인공지능기술 연구 및 개발을 수행하는 사람이 소속된 교육기관ㆍ연구기관\n인공지능사업자\n그 밖에 대통령령으로 정하는 인공지능기술 관련 기관\n② 민간자율위원회는 다음 각 호의 업무를 자율적으로 수행한다.\n인공지능기술 연구ㆍ개발ㆍ활용에 있어서 윤리원칙의 준수 여부 확인\n인공지능기술 연구ㆍ개발ㆍ활용의 안전 및 인권침해 등에 관한 조사ㆍ연구\n인공지능기술 연구ㆍ개발ㆍ활용의 절차 및 결과에 관한 조사ㆍ감독\n해당 기관 또는 단체의 연구자 및 종사자에 대한 윤리원칙 교육\n인공지능기술 연구ㆍ개발ㆍ활용에 적합한 분야별 인공지능윤리 지침 마련\n그 밖에 윤리원칙 구현에 필요한 업무\n③ 민간자율위원회의 구성ㆍ운영 등에 필요한 사항은 해당 기관 또는 단체 등에서 자율적으로 정한다. 다만, 그 구성을 특정한 성(性)으로만 할 수 없으며, 사회적ㆍ윤리적 타당성을 평가할 수 있는 경험과 지식을 갖춘 사람 및 그 기관 또는 단체에 종사하지 아니하는 사람을 각각 포함하여야 한다.\n④ 과학기술정보통신부장관은 민간자율위원회의 공정하고 중립적인 구성ㆍ운영을 위하여 표준 지침 등을 마련하여 보급할 수 있다.\n제29조(인공지능 신뢰 기반 조성을 위한 시책의 마련) 정부는 인공지능이 국민의 생활에 미치는 잠재적 위험을 최소화하고 안전한 인공지능의 이용을 위한 신뢰 기반을 조성하기 위하여 다음 각 호의 시책을 마련하여야 한다.\n안전하고 신뢰할 수 있는 인공지능 이용환경 조성\n인공지능의 이용이 국민의 일상생활에 미치는 영향 등에 관한 전망과 예측 및 관련 법령ㆍ제도의 정비\n인공지능의 안전성ㆍ신뢰성 확보를 위한 안전기술 및 인증기술의 개발 및 확산 지원\n안전하고 신뢰할 수 있는 인공지능사회 구현 및 인공지능윤리 실천을 위한 교육ㆍ홍보\n인공지능사업자의 안전성ㆍ신뢰성 관련 자율적인 규약의 제정ㆍ시행 지원\n인공지능사업자, 이용자 등으로 구성된 인공지능 관련 단체(이하 “단체등”이라 한다)의 인공지능의 안전성ㆍ신뢰성 증진을 위한 자율적인 협력, 윤리지침 제정 등 민간 활동의 지원 및 확산\n그 밖에 인공지능의 안전성ㆍ신뢰성 확보를 위하여 대통령령으로 정하는 사항\n제30조(인공지능 안전성ㆍ신뢰성 검ㆍ인증등 지원) ① 과학기술정보통신부장관은 단체등이 인공지능의 안전성ㆍ신뢰성 확보를 위하여 자율적으로 추진하는 검증ㆍ인증 활동(이하 “검ㆍ인증등”이라 한다)을 지원하기 위하여 다음 각 호의 사업을 추진할 수 있다.\n인공지능의 개발에 관한 가이드라인 보급\n검ㆍ인증등에 관한 연구의 지원\n검ㆍ인증등에 이용되는 장비 및 시스템의 구축ㆍ운영 지원\n검ㆍ인증등에 필요한 전문인력의 양성 지원\n그 밖에 검ㆍ인증등을 지원하기 위하여 대통령령으로 정하는 사항\n② 과학기술정보통신부장관은 검ㆍ인증등을 받고자 하는 중소기업등에 대하여 대통령령으로 정하는 바에 따라 관련 정보를 제공하거나 행정적ㆍ재정적 지원을 할 수 있다.\n③ 인공지능사업자가 고영향 인공지능을 제공하는 경우 사전에 검ㆍ인증등을 받도록 노력하여야 한다.\n④ 국가기관등이 고영향 인공지능을 이용하려는 경우에는 검ㆍ인증등을 받은 인공지능에 기반한 제품 또는 서비스를 우선적으로 고려하여야 한다.\n제31조(인공지능 투명성 확보 의무) ① 인공지능사업자는 고영향 인공지능이나 생성형 인공지능을 이용한 제품 또는 서비스를 제공하려는 경우 제품 또는 서비스가 해당 인공지능에 기반하여 운용된다는 사실을 이용자에게 사전에 고지하여야 한다.\n② 인공지능사업자는 생성형 인공지능 또는 이를 이용한 제품 또는 서비스를 제공하는 경우 그 결과물이 생성형 인공지능에 의하여 생성되었다는 사실을 표시하여야 한다.\n③ 인공지능사업자는 인공지능시스템을 이용하여 실제와 구분하기 어려운 가상의 음향, 이미지 또는 영상 등의 결과물을 제공하는 경우 해당 결과물이 인공지능시스템에 의하여 생성되었다는 사실을 이용자가 명확하게 인식할 수 있는 방식으로 고지 또는 표시하여야 한다. 이 경우 해당 결과물이 예술적ㆍ창의적 표현물에 해당하거나 그 일부를 구성하는 경우에는 전시 또는 향유 등을 저해하지 아니하는 방식으로 고지 또는 표시할 수 있다.\n④ 그 밖에 제1항에 따른 사전고지, 제2항에 따른 표시, 제3항에 따른 고지 또는 표시의 방법 및 그 예외 등에 관하여 필요한 사항은 대통령령으로 정한다.\n제32조(인공지능 안전성 확보 의무) ① 인공지능사업자는 학습에 사용된 누적 연산량이 대통령령으로 정하는 기준 이상인 인공지능시스템의 안전성을 확보하기 위하여 다음 각 호의 사항을 이행하여야 한다.\n인공지능 수명주기 전반에 걸친 위험의 식별ㆍ평가 및 완화\n인공지능 관련 안전사고를 모니터링하고 대응하는 위험관리체계 구축\n② 인공지능사업자는 제1항 각 호에 따른 사항의 이행 결과를 과학기술정보통신부장관에게 제출하여야 한다.\n③ 과학기술정보통신부장관은 제1항 각 호에 따른 사항의 구체적인 이행 방식 및 제2항에 따른 결과 제출 등에 필요한 사항을 정하여 고시하여야 한다.\n제33조(고영향 인공지능의 확인) ① 인공지능사업자는 인공지능 또는 이를 이용한 제품ㆍ서비스를 제공하는 경우 그 인공지능이 고영향 인공지능에 해당하는지에 대하여 사전에 검토하여야 하며, 필요한 경우 과학기술정보통신부장관에게 고영향 인공지능에 해당하는지 여부의 확인을 요청할 수 있다.\n② 과학기술정보통신부장관은 제1항에 따른 요청이 있는 경우 고영향 인공지능 해당 여부를 확인하여야 하며, 필요한 경우 전문위원회를 설치하여 관련 자문을 받을 수 있다.\n③ 과학기술정보통신부장관은 고영향 인공지능의 기준과 예시 등에 관한 가이드라인을 수립하여 보급할 수 있다.\n④ 그 밖에 제1항에 따른 확인 절차 등에 관하여 필요한 사항은 대통령령으로 정한다.\n제34조(고영향 인공지능과 관련한 사업자의 책무) ① 인공지능사업자는 고영향 인공지능 또는 이를 이용한 제품ㆍ서비스를 제공하는 경우 고영향 인공지능의 안전성ㆍ신뢰성을 확보하기 위하여 다음 각 호의 내용을 포함하는 조치를 대통령령으로 정하는 바에 따라 이행하여야 한다.\n위험관리방안의 수립ㆍ운영\n기술적으로 가능한 범위에서의 인공지능이 도출한 최종결과, 인공지능의 최종결과 도출에 활용된 주요 기준, 인공지능의 개발ㆍ활용에 사용된 학습용데이터의 개요 등에 대한 설명 방안의 수립ㆍ시행\n이용자 보호 방안의 수립ㆍ운영\n고영향 인공지능에 대한 사람의 관리ㆍ감독\n안전성ㆍ신뢰성 확보를 위한 조치의 내용을 확인할 수 있는 문서의 작성과 보관\n그 밖에 고영향 인공지능의 안전성ㆍ신뢰성 확보를 위하여 위원회에서 심의ㆍ의결된 사항\n② 과학기술정보통신부장관은 제1항 각 호에 따른 조치의 구체적인 사항을 정하여 고시하고, 인공지능사업자에게 이를 준수하도록 권고할 수 있다.\n③ 인공지능사업자가 다른 법령에 따라 제1항 각 호에 준하는 조치를 대통령령으로 정하는 바에 따라 이행한 경우에는 제1항에 따른 조치를 이행한 것으로 본다.\n제35조(고영향 인공지능 영향평가) ① 인공지능사업자가 고영향 인공지능을 이용한 제품 또는 서비스를 제공하는 경우 사전에 사람의 기본권에 미치는 영향을 평가(이하 “영향평가”라 한다)하기 위하여 노력하여야 한다. 이 경우 영향평가에는 고영향 인공지능을 이용한 제품 또는 서비스의 성격을 고려하여 인공지능취약계층의 특성이 반영될 수 있도록 하여야 한다. \u0026lt;개정 2026. 1. 20.\u0026gt;\n② 국가기관등이 고영향 인공지능을 이용한 제품 또는 서비스를 이용하려는 경우에는 영향평가를 실시한 제품 또는 서비스를 우선적으로 고려하여야 한다.\n③ 그 밖에 영향평가의 구체적인 내용ㆍ방법 등에 관하여 필요한 사항은 대통령령으로 정한다.\n제36조(국내대리인 지정) ① 국내에 주소 또는 영업소가 없는 인공지능사업자로서 이용자 수, 매출액 등이 대통령령으로 정하는 기준에 해당하는 자는 다음 각 호의 사항을 대리하는 자(이하 “국내대리인”이라 한다)를 서면으로 지정하고, 이를 과학기술정보통신부장관에게 신고하여야 한다.\n제32조제2항에 따른 이행 결과의 제출\n제33조제1항에 따른 고영향 인공지능 해당 여부 확인의 요청\n제34조제1항 각 호에 따른 안전성ㆍ신뢰성 확보 조치의 이행에 필요한 지원(같은 항 제5호에 따른 문서의 최신성ㆍ정확성에 대한 점검을 포함한다)\n② 국내대리인은 국내에 주소 또는 영업소가 있는 자로 한다.\n③ 국내대리인이 제1항 각 호와 관련하여 이 법을 위반한 경우에는 해당 국내대리인을 지정한 인공지능사업자가 그 행위를 한 것으로 본다.\n제5장 보칙\n제37조(인공지능산업의 진흥을 위한 재원의 확충 등) ① 국가는 기본계획 및 이 법에 따른 시책 등을 효과적으로 추진하기 위하여 필요한 재원을 지속적이고 안정적으로 확충할 수 있는 방안을 마련하여야 한다.\n② 과학기술정보통신부장관은 인공지능산업의 진흥을 위하여 필요한 경우에는 공공기관으로 하여금 인공지능산업의 진흥에 관한 사업 등에 필요한 지원을 하도록 권고할 수 있다.\n③ 국가 및 지방자치단체는 기업 등 민간이 적극적으로 인공지능산업의 진흥과 관련된 사업에 투자할 수 있도록 필요한 조치를 마련하여야 한다.\n④ 국가 및 지방자치단체는 인공지능산업의 발전단계 등을 종합적으로 고려하여 투자재원을 효율적으로 집행하도록 노력하여야 한다.\n제38조(실태조사, 통계 및 지표의 작성) ① 과학기술정보통신부장관은 국가데이터처장과 협의하여 기본계획 및 인공지능등 관련 시책과 사업의 기획ㆍ수립ㆍ추진을 위하여 국내외 인공지능등에 관한 실태조사, 통계 및 지표를 「과학기술기본법」 제26조의2에 따른 통계와 연계하여 작성ㆍ관리하고 공표하여야 한다. \u0026lt;개정 2025. 10. 1.\u0026gt;\n② 과학기술정보통신부장관은 제1항에 따른 통계 및 지표의 작성을 위하여 관계 중앙행정기관의 장, 지방자치단체의 장 및 공공기관의 장에게 자료의 제출 등 협조를 요청할 수 있다. 이 경우 협조를 요청받은 기관의 장은 특별한 사정이 없으면 이에 따라야 한다.\n③ 그 밖에 제1항에 따른 실태조사, 통계 및 지표의 작성ㆍ관리 및 공표 등에 필요한 사항은 대통령령으로 정한다.\n제39조(권한의 위임 및 업무의 위탁) ① 과학기술정보통신부장관 또는 관계 중앙행정기관의 장은 이 법에 따른 권한의 일부를 대통령령으로 정하는 바에 따라 소속 기관의 장 또는 특별시장ㆍ광역시장ㆍ특별자치시장ㆍ도지사ㆍ특별자치도지사(이하 이 조에서 “시ㆍ도지사”라 한다)에게 위임할 수 있다. 이 경우 시ㆍ도지사는 위임받은 권한의 일부를 시장(「제주특별자치도 설치 및 국제자유도시 조성을 위한 특별법」 제11조제2항에 따른 행정시장을 포함한다)ㆍ군수ㆍ구청장(자치구의 구청장을 말한다)에게 재위임할 수 있다.\n② 정부는 다음 각 호의 업무를 대통령령으로 정하는 바에 따라 관련 기관 또는 단체에 위탁할 수 있다.\n제13조에 따른 인공지능기술 개발 및 이용 관련 사업에 대한 지원\n제15조제2항 및 제3항에 따른 학습용데이터의 생산ㆍ수집ㆍ관리ㆍ유통 및 활용 등에 관한 지원대상사업의 선정ㆍ지원과 학습용데이터 구축사업의 추진\n통합제공시스템의 구축ㆍ운영 및 관리\n제18조에 따른 창업 활성화를 위하여 과학기술정보통신부장관이 필요하다고 인정하는 사항\n제30조제2항에 따른 검ㆍ인증등 관련 지원\n제38조에 따른 실태조사, 통계 및 지표의 작성\n그 밖에 인공지능산업의 육성 및 인공지능윤리의 확산을 위하여 대통령령으로 정하는 사무\n제40조(사실조사 등) ① 과학기술정보통신부장관은 다음 각 호의 어느 하나에 해당하는 경우에는 인공지능사업자에 대하여 관련 자료를 제출하게 하거나, 소속 공무원으로 하여금 필요한 조사를 하게 할 수 있다.\n제31조제2항ㆍ제3항, 제32조제1항ㆍ제2항 또는 제34조제1항에 위반되는 사항을 발견하거나 혐의가 있음을 알게 된 경우\n제31조제2항ㆍ제3항, 제32조제1항ㆍ제2항 또는 제34조제1항의 위반에 대한 신고를 받거나 민원이 접수된 경우\n② 과학기술정보통신부장관은 제1항에 따른 조사를 위하여 필요한 경우 소속 공무원으로 하여금 인공지능사업자의 사무소ㆍ사업장에 출입하여 장부ㆍ서류, 그 밖의 자료나 물건을 조사하게 할 수 있다. 이 경우 조사의 내용ㆍ방법 및 절차 등에 관하여 이 법에서 정하는 사항을 제외하고는 「행정조사기본법」에서 정하는 바에 따른다.\n③ 과학기술정보통신부장관은 제1항 및 제2항에 따른 조사 결과 인공지능사업자가 이 법을 위반한 사실이 있다고 인정되면 인공지능사업자에게 해당 위반행위의 중지나 시정을 위하여 필요한 조치를 명할 수 있다.\n제41조(벌칙 적용에서 공무원 의제) ① 위원회의 위원 중 공무원이 아닌 위원은 「형법」 제129조부터 제132조까지에 따른 벌칙을 적용할 때에는 공무원으로 본다.\n② 제39조제2항에 따라 위탁받은 업무에 종사하는 기관 또는 단체의 임직원은 「형법」 제127조 및 제129조부터 제132조까지에 따른 벌칙을 적용할 때에는 공무원으로 본다.\n제6장 벌칙\n제42조(벌칙) 제7조제9항을 위반하여 직무상 알게 된 비밀을 타인에게 누설하거나 직무상 목적 외의 용도로 사용한 자는 3년 이하의 징역 또는 3천만원 이하의 벌금에 처한다.\n제43조(과태료) ① 다음 각 호의 어느 하나에 해당하는 자에게는 3천만원 이하의 과태료를 부과한다.\n제31조제1항을 위반하여 고지를 이행하지 아니한 자\n제36조제1항을 위반하여 국내대리인을 지정하지 아니한 자\n제40조제3항에 따른 중지명령이나 시정명령을 이행하지 아니한 자\n② 제1항에 따른 과태료는 대통령령으로 정하는 바에 따라 과학기술정보통신부장관이 부과ㆍ징수한다.\n부 칙 \u0026lt;법률 제20676호, 2025. 1. 21.\u0026gt;\n제1조(시행일) 이 법은 공포 후 1년이 경과한 날부터 시행한다. 다만, 제2조제4호라목 중 디지털의료기기에 관한 부분은 2026년 1월 24일부터 시행한다.\n제2조(이 법 시행을 위한 준비행위) 이 법을 시행하기 위하여 필요한 위원회 위원의 위촉, 분과위원회, 특별위원회, 자문단 및 지원단의 구성 등은 이 법 시행 전에 할 수 있다.\n제3조(전담기관에 관한 특례) 이 법 시행 당시 제23조제1항에 따른 집적화를 지역에 효과적으로 정착시키기 위하여 정부로부터 관련 예산을 지원받아 운영 중인 기관 중 조직, 인력 등 대통령령으로 정하는 요건을 충족한 기관은 제23조제4항에도 불구하고 이 법에 따라 전담기관으로 지정된 것으로 본다.\n부 칙 \u0026lt;법률 제21065호, 2025. 10. 1.\u0026gt; (정부조직법)\n제1조(시행일) 이 법은 공포한 날부터 시행한다. 다만, 부칙 제7조에 따라 개정되는 법률 중 이 법 시행 전에 공포되었으나 시행일이 도래하지 아니한 법률을 개정한 부분은 각각 해당 법률의 시행일부터ㆍㆍㆍ\u0026lt;생략\u0026gt;ㆍㆍㆍ 시행한다.\n및 2. 생략 제2조부터 제6조까지 생략\n제7조(다른 법률의 개정) ①부터 \u0026lt;95\u0026gt;까지 생략\n\u0026lt;96\u0026gt; 인공지능 발전과 신뢰 기반 조성 등에 관한 기본법 일부를 다음과 같이 개정한다.\n제38조제1항 중 “통계청장”을 “국가데이터처장”으로 한다.\n\u0026lt;97\u0026gt;부터 \u0026lt;626\u0026gt;까지 생략\n제8조 생략\n부 칙 \u0026lt;법률 제21311호, 2026. 1. 20.\u0026gt;\n이 법은 2026년 1월 22일부터 시행한다. 다만, 제3조제5항, 제6조제2항제7호ㆍ제8호, 제16조제3항부터 제5항까지(제2항제2호의2의 개정규정에 관한 부분에 한정한다), 제17조의2, 제18조, 제22조의3 및 제35조제1항 후단의 개정규정은 공포 후 6개월이 경과한 날부터 시행한다.\n中文译本(非官方) 非官方译本,仅供参考。\n第一章 总则 第一条(目的)\n本法旨在规定人工智能健康发展与信任基础构建所需的基本事项,从而保护国民的权益与尊严,增进国民生活质量的提高,增强国家竞争力。\n第二条(定义)\n本法所用术语的含义如下。〈2026年1月20日修订〉\n「人工智能」是指以电子方法实现学习、推理、感知、判断、语言理解等人类所具有的智力能力。\n「人工智能系统」是指具备不同程度的自主性和适应性,为达成既定目标而对现实及虚拟环境产生影响,推理出预测、推荐、决定等结果的人工智能基础系统。\n「人工智能技术」是指为实现人工智能所需的硬件、软件技术或其应用技术。\n「高影响人工智能」是指可能对人的生命、身体安全及基本权利产生重大影响或引发危险,并在下列各项领域之一中使用的人工智能系统。\n가. 依《能源法》第2条第1项规定的能源供应\n나. 依《饮用水管理法》第3条第1项规定的饮用水生产工艺\n다. 依《保健医疗基本法》第3条第1项规定的保健医疗服务提供及利用体系的构建、运营\n라. 依《医疗器械法》第2条第1款规定的医疗器械及依《数字医疗产品法》第2条第2项规定的数字医疗产品的开发及利用\n마. 依《核设施等防护及放射性防灾对策法》第2条第1款第1项规定的核物质及同款第2项规定的核设施的安全管理与运营\n바. 为犯罪侦查或逮捕业务而进行生物识别信息(指面部、指纹、虹膜及掌静脉等可用于识别个人的身体、生理、行为特征相关个人信息)的分析与利用\n사. 对雇用、贷款审查等个人的权利义务关系产生重大影响的判断或评价\n아. 依《交通安全法》第2条第1项至第3项规定的交通工具、交通设施、交通系统的主要运行及运营\n자. 提供公共服务所需的资格确认及决定或费用征收等对国民产生影响的国家、地方自治团体、依《关于公共机构运营的法律》第4条规定的公共机构等(以下称「国家机关等」)的决策\n차. 依《教育基本法》第9条第1款规定的幼儿教育、初等教育及中等教育中的学生评价\n카. 其他对人的生命、身体安全及基本权利保护产生重大影响,并由总统令规定的领域\n「生成式人工智能」是指模仿输入数据(指依《数据产业振兴及利用促进基本法》第2条第1项规定的数据。以下同)的结构与特性,生成文字、声音、图画、影像及其他多种输出结果的人工智能系统。\n「人工智能产业」是指将利用人工智能或人工智能技术的产品(以下称「人工智能产品」)予以开发、制造、生产或流通,或提供与此相关服务(以下称「人工智能服务」)的产业。\n「人工智能经营者」是指从事与人工智能产业相关事业,且属于下列各项之一的法人、团体、个人及国家机关等。\n가. 人工智能开发者:开发利用并提供人工智能者\n나. 人工智能利用者:利用가目经营者提供的人工智能,提供人工智能产品或人工智能服务者\n「利用者」是指接受人工智能产品或人工智能服务提供之人。\n「受影响者」是指因人工智能产品或人工智能服务,其生命、身体安全及基本权利受到重大影响之人。\n「人工智能社会」是指通过人工智能在产业、经济、社会、文化、行政等所有领域创造价值并引领发展的社会。\n「人工智能伦理」是指以对人的尊严的尊重为基础,为实现能够保护国民权益及生命、财产的安全可信的人工智能社会,社会成员在人工智能的开发、提供及利用等所有领域应当遵守的伦理标准。\n「训练用数据」是指用于人工智能的开发、利用等的数据。\n第三条(基本原则及国家等的责任)\n① 人工智能技术与人工智能产业应以提高安全性与可信性、增进国民生活质量为方向发展。\n② 受影响者应能在技术与合理可能的范围内,就人工智能最终结果推导中所利用的主要标准及原理等,获得明确且有意义的说明。\n③ 国家及地方自治团体应尊重人工智能经营者的创造精神,并为营造安全的人工智能利用环境而努力。\n④ 国家及地方自治团体应针对人工智能在社会、经济、文化及国民日常生活等所有领域带来的变化采取政策措施,使全体国民能够稳定适应。\n⑤ 国家及地方自治团体应努力保障因使用人工智能产品或人工智能服务存在困难的残疾人、高龄者等总统令规定的弱势群体(以下称「人工智能弱势群体」)参与人工智能相关政策的开发与确立过程,并使其意见得到反映。〈2026年1月20日新增〉\n第四条(适用范围)\n① 本法对在国外实施的行为,若对国内市场或利用者产生影响,亦适用之。\n② 本法不适用于仅为国防或国家安全目的而开发、使用的人工智能中由总统令规定的人工智能。\n第五条(与其他法律的关系)\n① 关于人工智能、人工智能技术、人工智能产业及人工智能社会(以下称「人工智能等」),除其他法律有特别规定者外,依本法规定。\n② 制定或修订关于人工智能等的其他法律时,应符合本法的宗旨。\n第二章 人工智能健康发展与信任基础构建的推进体系 第六条(人工智能基本计划的制定)\n① 科学技术信息通信部部长应听取相关中央行政机关负责人及地方自治团体负责人的意见,为促进人工智能技术及人工智能产业、增强国家竞争力,每3年制定、变更并施行人工智能基本计划(以下称「基本计划」),并须经依第7条规定的国家人工智能战略委员会的审议、决议。但对于变更基本计划中总统令规定的轻微事项,不在此限。〈2026年1月20日修订〉\n② 基本计划应包括下列各项事项。〈2026年1月20日修订〉\n关于人工智能等政策的基本方向与战略的事项\n关于为系统培育人工智能产业而培养专业人才、构建促进人工智能开发利用基础等的事项\n关于为扩散人工智能伦理等实现健康人工智能社会的法律、制度及文化的事项\n关于为开发人工智能技术及振兴人工智能产业而确保财源与投资方向等的事项\n4之2. 关于利用依《公共数据提供及利用活性化法》规定的公共数据生成训练用数据、提供公共数据等的范围与标准及其活性化的事项\n关于确保人工智能的公平性、透明性、责任性、安全性、可及性等构建信任基础的事项\n关于人工智能技术的发展方向及由此带来的教育、劳动、经济、文化等社会各领域变化与应对的事项\n6之2. 关于为理解和利用人工智能技术而提供教育支持及宣传的事项\n关于保障人工智能弱势群体接触、利用人工智能产品或人工智能服务的事项\n其他科学技术信息通信部部长认为为促进人工智能技术及人工智能产业、加强国际合作等增强国家竞争力所必要的事项\n③ 科学技术信息通信部部长在制定基本计划时,应考虑依《智能信息化基本法》第6条第1款规定的综合计划及同法第7条第1款规定的执行计划;对于依第2款第4项之2规定的训练用数据中,依《公共数据提供及利用活性化法》将公共数据作为训练用数据提供的事项,应与行政安全部部长协商确定。〈2026年1月20日修订〉\n④ 科学技术信息通信部部长可要求相关中央行政机关、地方自治团体及公共机构(指依《智能信息化基本法》第2条第16项规定的公共机构。以下同)的负责人提交制定基本计划所需的资料。此时,被要求提交资料的机关负责人除有特别事由外,应予以配合。\n⑤ 基本计划视为依《智能信息化基本法》第13条第1款规定的人工智能及人工智能产业领域的分领域推进计划。\n⑥ 中央行政机关负责人及地方自治团体负责人在制定并执行所管主要政策时,应考虑基本计划。\n⑦ 制定、变更及施行基本计划所需的事项,由总统令规定。\n第七条(国家人工智能战略委员会)\n① 为审议、决议人工智能发展及信任基础构建等的主要政策等事项,在总统属下设立国家人工智能战略委员会(以下称「委员会」)。〈2026年1月20日修订〉\n② 委员会由包括委员长1名和副委员长3名以内的60名以内委员组成。此时,依第4款第4项规定的委员应占全体委员的过半数,且不得仅以特定性别组成委员会。〈2026年1月20日修订〉\n③ 委员会委员长由总统担任,副委员长由总统从属于第4款第1项或第4项的人员中指定。〈2026年1月20日修订〉\n④ 委员会委员为下列各项人员。\n总统令规定的相关中央行政机关负责人\n国家安保室负责人工智能事务的次长\n总统秘书室辅佐人工智能事务的首席秘书官\n在人工智能相关专业知识与经验丰富的人员中由总统委任者\n⑤ 委员会委员长代表委员会,并统管委员会事务。\n⑥ 委员会委员长在必要时可令副委员长代行其职务。\n⑦ 依第4款第4项规定的委员任期为2年,但仅限连任一次。\n⑧ 委员会设干事委员1名,干事委员为第4款第3项的委员。\n⑨ 委员会委员不得向他人泄露因职务而知悉的秘密,或将其用于职务目的以外的用途。但其他法律有特别规定者,不在此限。\n⑩ 委员会委员长召集委员会会议,并担任其议长。\n⑪ 委员会会议以委员过半数出席开议,以出席委员过半数赞成决议。\n⑫ 为支持委员会的工作及运营,在委员会设支援团。\n⑬ 委员会自本法施行日起存续5年。\n⑭ 其他委员会及依第12款规定的支援团的组成与运营等所需事项,由总统令规定。\n[标题修订 2026年1月20日]\n第八条(委员会的职能)\n① 委员会审议、决议下列各项事项。〈2026年1月20日修订〉\n关于基本计划的制定、变更及施行情况的检查、分析的事项\n关于确立人工智能等相关国家愿景及中长期战略的事项\n2之2. 关于人工智能相关政策及事业等的确立、调整及部门间协调的事项\n2之3. 关于人工智能相关政策及事业等的履行检查及绩效管理的事项\n关于确立人工智能等相关研发战略的事项\n关于确定人工智能等相关投资方向及制定投资战略的事项\n关于发掘并改善妨碍人工智能产业发展与竞争力的规制的事项\n5之2. 关于人工智能等相关技术、人才、选址等制度改善的事项\n5之3. 关于人工智能及人工智能技术相关专业人才的培养及支持的事项\n关于扩充人工智能数据中心(指依《智能信息化基本法》第40条第1款规定的数据中心。以下同)等基础设施方案的事项 6之2. 关于为人工智能发展而促进数据(包括训练用数据)收集、管理及利用的事项\n关于促进制造业、服务业等产业部门及公共部门利用人工智能的事项\n关于制定人工智能国际规范等人工智能相关国际合作的事项\n关于依第2款提出建议或表明意见的事项\n关于高影响人工智能规制的事项\n关于与高影响人工智能相关的社会变化形态及政策应对的事项\n本法或其他法律规定为委员会审议事项的事项\n其他委员会委员长认为必要而提交委员会会议的事项\n② 委员会可向国家机关等的负责人及人工智能经营者等,就人工智能的正确使用与人工智能伦理的实践、人工智能技术的安全性与可信性,提出建议或表明意见。\n③ 委员会依第2款向国家机关等的负责人提出关于法令、制度改善或实践方案确立等的建议或表明意见时,该国家机关等的负责人应确立法令、制度等的改善方案与实践方案等。\n第九条(委员的除斥、忌避及回避)\n① 为保障业务公正性,委员会委员属于下列各项之一情形时,在该案件的审议、决议中被除斥。\n委员或委员所属法人、团体等与该案件有直接利害关系的情形\n委员的家属(指依《民法》第779条规定的家属)为利害关系人的情形\n② 审议对象案件的当事人(当事人为法人、团体等时,包括其高管及职员)如有难以期待委员公正执行职务的事由,可向委员会申请忌避;委员会认为忌避申请有理时,应以决议决定忌避。\n③ 委员属于第1款或第2款事由时,应自行回避该案件的审议。\n第十条(分科委员会等)\n① 委员会为按专业领域执行委员会的工作,必要时可设分科委员会。\n② 委员会为讨论人工智能等相关特定议题,必要时可设特别委员会。\n③ 委员会为专业审查人工智能等相关事项,可设由相关专家等组成的咨询团。\n④ 委员会为确立政府内人工智能主要政策并高效推进事业,可运营由总统令规定的人工智能责任官组成的人工智能责任官协议会。〈2026年1月20日新增〉\n⑤ 其他分科委员会、特别委员会、咨询团及人工智能责任官协议会的组成、运营等所需事项,由总统令规定。〈2026年1月20日修订〉\n第十一条(人工智能政策中心)\n① 科学技术信息通信部部长为综合执行人工智能相关政策的开发与国际规范的确立、扩散所需的工作,可指定人工智能政策中心(以下称「中心」)。\n② 中心执行下列各项事业。\n制定、施行基本计划所需的专业技术支持\n人工智能相关政策措施的开发及相关事业的规划、施行所需的专业技术支持\n随人工智能利用的扩散而对社会、经济、文化及国民日常生活等产生的影响的调查、分析\n为支持人工智能及人工智能技术相关政策开发而进行的动向分析,社会、文化变化与未来预测及法律、制度的调查研究\n其他法令规定为中心工作或委托中心的事业\n其他国家机关等的负责人委托的事业\n③ 其他中心的指定等所需事项,由总统令规定。\n第十二条(人工智能安全研究所)\n① 科学技术信息通信部部长为专业且高效地执行保护国民的生命、身体、财产等免受与人工智能相关可能发生的危险、并维持人工智能社会信任基础的状态(以下称「人工智能安全」)所需的工作,可运营人工智能安全研究所(以下称「安全研究所」)。\n② 安全研究所执行下列各项事业。\n人工智能安全相关风险的定义及分析\n人工智能安全政策研究\n人工智能安全评价标准、方法研究\n人工智能安全技术及标准化研究\n人工智能安全相关国际交流、国际合作\n依第32条规定支持确保人工智能系统的安全性\n其他属于人工智能安全相关事业且由总统令规定的事业\n③ 政府可在预算范围内出资或支援安全研究所的运营与事业推进等所需经费。\n④ 其他安全研究所的运营等所需事项,由总统令规定。\n第三章 人工智能技术开发及产业培育 第一节 人工智能产业基础构建 第十三条(人工智能技术开发及安全利用支持)\n① 政府为促进人工智能技术的开发,可支援下列各项事业。\n国内外人工智能技术动向、水平及相关制度的调查\n人工智能技术的研究、开发、试验及评价,或所开发技术的利用\n人工智能技术的扩散、人工智能技术合作与转移等技术的实用化及商业化支持\n为实现人工智能技术的信息顺畅流通及产学研合作\n其他与人工智能技术的开发及研究、调查相关,由总统令规定的事业\n② 政府为安全便利地利用人工智能技术,可支援下列各项事业。\n以人工智能技术实现《智能信息化基本法》第60条第1款各项规定事项的研发事业\n为在人工智能产品或人工智能服务中实现依《智能信息化基本法》第60条第3款规定的紧急停止功能而提供技术研究支持,以及为扩散该技术而开展的事业\n在人工智能技术的开发中,依《智能信息化基本法》第61条第2款规定的适合保护私生活等的设计标准及技术的研究开发与普及事业\n为实施并应用依《智能信息化基本法》第56条第1款规定的人工智能技术社会影响评价而开展的研发事业\n为使人工智能朝着尊重人的尊严及基本权利的方向开发、利用的技术或标准等的研究开发及普及事业\n为人工智能的安全开发与利用而改善认识、营造正确使用方法与安全环境的教育及宣传事业\n其他在人工智能的开发与利用中为保护国民的基本权利、身体与财产所必要的事业\n③ 政府应公开并普及依第2款规定的事业成果,使任何人都能便利地利用。此时,为保护开发技术者,必要时可设定保护期,使其可收取技术使用费,或以其他方法予以保护。\n第十四条(人工智能技术的标准化)\n① 政府为推进与人工智能技术、训练用数据、人工智能的安全性、可信性等相关的标准化,可推进下列各项事业。〈2026年1月20日修订〉\n人工智能技术相关标准的制定、修订与废止及其普及\n人工智能技术相关国内外标准的调查研究开发\n其他人工智能技术相关标准化事业\n② 政府可公告依第1款第1项制定的标准,并建议相关经营者遵守。\n③ 政府可对民间部门推进的人工智能技术相关标准化事业提供必要支持。\n④ 政府应维持并加强与人工智能技术标准相关的国际标准组织或国际标准机构的合作体系。\n⑤ 其他与依第1款及第3款规定的标准化事业的推进及支持等相关所需事项,由总统令规定。\n第十五条(人工智能训练用数据相关政策的制定等)\n① 科学技术信息通信部部长应与相关中央行政机关负责人协商,推进为促进训练用数据的生产、收集、管理、流通、利用及确保质量水平等所需的政策措施。〈2026年1月20日修订〉\n② 政府为高效推进关于训练用数据的生产、收集、管理、流通及利用等的政策措施,可选定受援事业并在预算范围内提供支援。\n③ 政府为促进训练用数据的生产、收集、管理、流通及利用等的活性化,可实施制作、生产并提供多种训练用数据的事业(以下称「训练用数据构建事业」)。\n④ 科学技术信息通信部部长为高效执行训练用数据构建事业,应构建、管理可统一提供、管理训练用数据的系统(以下称「统一提供系统」),并提供给民间自由利用。\n⑤ 科学技术信息通信部部长可向利用统一提供系统者收取费用。\n⑥ 其他依第2款规定的受援事业的选定及支持、训练用数据构建事业的实施、统一提供系统的构建、管理及依第5款规定的费用收取等所需事项,由总统令规定。\n第二节 人工智能技术开发及人工智能产业活性化 第十六条(人工智能技术引进、利用政策措施等)\n① 国家及地方自治团体应制定并施行政策措施,以促进企业与公共机构引进人工智能技术并扩大其利用。〈2026年1月20日新增〉\n② 国家及地方自治团体为促进企业与公共机构引进人工智能技术并扩大其利用,必要时可提供下列各项支持。〈2026年1月20日修订〉\n支持人工智能技术、人工智能产品或人工智能服务的开发及研发成果的扩散\n面向拟引进、利用人工智能技术的企业及公共机构的咨询支持\n2之2. 为公共机构将其持有、管理的数据生成为训练用数据并提供、确保适当质量水平所需的支持\n面向依《中小企业基本法》第2条第1款规定的中小企业、依《关于风险企业培育的特别法》第2条第1款规定的风险企业及依《小微商户基本法》第2条第1款规定的小微商户(以下称「中小企业等」)的高管及职员提供人工智能技术引进及利用相关教育支持\n支持中小企业等引进及利用人工智能技术所使用的资金\n其他为促进企业与公共机构引进及利用人工智能技术而由总统令规定的事项\n③ 国家机关等欲采购履行职责所需的产品或服务,或发包劳务时,应优先考虑总统令规定的人工智能产品或人工智能服务。但因业务特性不宜利用人工智能技术者,不在此限。〈2026年1月20日新增〉\n④ 依第3款采购或使用人工智能产品或人工智能服务致使国家机关等发生损害时,负责该采购或使用业务者对该机关的损害不承担赔偿责任。但损害系因该业务负责人的故意或重大过失而发生者,不在此限。〈2026年1月20日新增〉\n⑤ 依第2款规定的支持所需事项,由总统令规定。〈2026年1月20日修订〉\n[标题修订 2026年1月20日]\n第十七条(面向中小企业等的特别支持)\n① 依本法施行与人工智能技术及人工智能产业相关的各项支持政策措施时,应优先考虑中小企业等。\n② 政府应努力促进中小企业等参与人工智能产业,并将相关事项反映于基本计划。\n③ 科学技术信息通信部部长为保障人工智能的安全性与可信性,可支持中小企业等履行依第34条规定的措施及依第35条规定的影响评价。\n第十七条 之二(人工智能产品及人工智能服务使用费用的支持)\n① 国家与地方自治团体可对因经济条件而难以使用人工智能产品及人工智能服务者,在预算范围内支援其费用的全部或一部分。\n② 依第1款规定的费用支持的要件与对象等所需事项,由总统令规定。\n[本条新增 2026年1月20日]\n第十八条(创业的活性化等)\n① 政府为促进人工智能产业领域的创业,可推进下列各项事业。\n人工智能产业领域创业者的发掘及培育、支持等相关事业\n为促进人工智能产业领域创业而开展的教育、培训相关事业\n对依第21条规定的专业人才的优秀人工智能技术的商业化支持\n人工智能技术的价值评估及创业资金的金融支持\n人工智能相关研究及技术开发成果的提供\n培育支持人工智能产业领域创业的机构、团体\n其他为促进人工智能产业领域创业所需的事业\n② 地方自治团体可向支持人工智能产业领域创业的公共机构等公共团体出资或投资。\n③ 中央行政机关负责人为促进人工智能产业领域的创业,可与中小风险企业部部长协商,提供利用依《风险投资促进法》第70条规定的风险投资母体组合的支持。〈2026年1月20日新增〉\n④ 依第3款规定的支持所需资金由下列各项财源构成。〈2026年1月20日新增〉\n国家、地方自治团体或公共机构的出资款\n国家、地方自治团体或公共机构以外者中,就人工智能产业希望向风险投资母体组合出资者的出资款\n其他附带收入\n⑤ 依第3款规定向风险投资母体组合出资所需事项,由总统令规定。〈2026年1月20日新增〉\n[标题修订 2026年1月20日]\n第十九条(人工智能融合的促进)\n① 政府应制定并推进必要的政策措施,以促进人工智能产业与其他产业之间的融合,并活跃所有领域的人工智能利用。\n② 政府为支持人工智能融合产品与服务的开发,必要时可在依《国家研发创新法》规定的国家研发事业中优先纳入人工智能融合产品及服务相关的研发课题予以推进。\n③ 政府对于依第2款开发的人工智能融合产品及服务,应积极支持依《信息通信振兴及融合活性化等特别法》第37条规定的临时许可及同法第38条之2规定的为实现实证的规制特例得以顺利施行。\n第二十条(制度改善等)\n① 政府为人工智能产业的发展与信任基础的构建,应努力改善法令的整顿等相关制度。\n② 政府为促进依第1款规定的制度改善,可提供相关法律、制度的研究及收集社会各界意见等所需的行政、财政支持。\n第二十一条(专业人才的确保)\n① 科学技术信息通信部部长为人工智能技术的开发及人工智能产业的发展,可依《智能信息化基本法》第23条第1款规定的政策措施,推进下列各项事业,以培养并支持人工智能及人工智能技术相关专业人才。〈2026年1月20日修订〉\n为强化专业人才的职务能力及职业发展而开发、运用教育培训项目\n支持专业人才就业及活跃新人力流入等促进雇用\n扩大专业人才进入公职的机会等促进去向多元化\n支持专业人才的国内外研修及活跃国际交流\n改善专业人才的劳动环境与提高待遇等增进福祉\n其他为培养、支持人工智能及人工智能技术相关专业人才的事业\n② 政府为吸引人工智能及人工智能技术相关的海外专业人才,可推进下列各项政策措施。\n关于人工智能及人工智能技术相关海外大学、研究机构、企业等的专业人才的调查、分析\n为吸引海外专业人才而构建国际网络\n支持海外专业人才在国内就业\n支持国内人工智能研究机构走向海外及海外人工智能研究机构落户国内\n支持人工智能及人工智能技术相关国际组织及国际会议在国内举办\n其他为吸引海外专业人才所需的事项\n第二十二条(国际合作及进军海外市场的支持)\n① 政府应把握人工智能相关的国际动向并推进国际合作。\n② 政府为增强人工智能产业的竞争力并促进进军海外市场,可对从事人工智能产业的个人、企业或团体等提供下列各项支持。\n人工智能产业相关信息、技术、人员的国际交流\n人工智能产业相关进军海外信息的收集、分析及提供\n国家之间人工智能技术、人工智能产品或人工智能服务的共同研发及国际标准化\n人工智能产业相关外资的招商引资\n参加人工智能等相关海外专业学会及展览会等宣传及海外营销\n构建人工智能产品或人工智能服务出口所需的销售体系、流通体系及合作体系等\n把握人工智能伦理相关的国际动向及国际合作\n其他为增强人工智能产业的竞争力并促进进军海外市场所需的事项\n③ 政府为高效执行依第2款各项规定的支持,可依总统令规定将其委托或交由公共机构或其他团体办理,并可补助所需费用。\n第二十二条 之二(人工智能研究所的设立及支持等)\n① 大学、企业等总统令规定者可单独或共同设立、运营从事人工智能开发、利用研究的研究所(以下称「人工智能研究所」)。\n② 依第1款规定,大学、企业等总统令规定者欲设立人工智能研究所时,应具备下列各项要件并取得科学技术信息通信部部长的许可。\n应有3名以上发起人\n应具备可执行第5款事业的人力、设施等能力\n应具备其他为设立、运营人工智能研究所所需且由总统令规定的要件\n③ 人工智能研究所设所长。人工智能研究所所长代表人工智能研究所,并统管人工智能研究所的工作。\n④ 人工智能研究所的章程应包括下列各项事项。\n目的\n名称\n事务所所在地\n关于资产的规定\n关于所长的资格与任免的规定\n关于所长的责任与权限的规定\n⑤ 人工智能研究所按行业、职能执行下列各项事业。\n人工智能技术研发\n人工智能技术与其他技术及学科间融合的研发\n人工智能技术研发成果的管理、转移、利用及商业化\n培养人工智能技术研发专业人才\n人工智能技术研发相关的国际交流、国际合作\n其他人工智能技术研发所需的事项\n⑥ 政府与地方自治团体可在预算范围内支援人工智能研究所的运营与事业推进等所需经费。\n⑦ 人工智能研究所为筹集运营所需财源,可接受政府、地方自治团体以外者的补助金或捐款等,或依章程规定开展收益事业。\n⑧ 人工智能研究所所长为人工智能技术的研发等,必要时可与依第1款规定的大学、企业等总统令规定者协商,接受派遣或兼职工作的高管及职员,使其担任人工智能研究所的研究等工作,并可向被派遣的高管及职员所属机构提供必要支持。此时,必要时可请求科学技术信息通信部部长提供协商所需支持。\n⑨ 关于人工智能研究所,除本法规定者外,准用《民法》中关于财团法人的规定。\n⑩ 科学技术信息通信部部长在人工智能研究所属于下列各项之一情形时,可命令改正或撤销其设立许可。但属于第1项或第2项情形时,应撤销其许可。\n以虚假或其他不正当方法取得设立许可的情形\n已不可能达成目的的情形\n未满足依第2款规定的许可要件的情形\n从事目的事业以外事业的情形\n违反法令、章程或本法规定的命令的情形\n实施损害公益行为的情形\n无正当理由自取得设立许可之日起6个月内未开始目的事业,或1年以上无事业实绩的情形\n⑪ 科学技术信息通信部部长欲依第10款撤销人工智能研究所的设立许可时,应举行听证。\n⑫ 其他人工智能研究所的设立程序、运营、支持等所需事项,由总统令规定。\n[本条新增 2026年1月20日]\n第二十二条 之三(为获取人工智能技术而设立、运营研究机构)\n科学技术信息通信部部长为获取创新性人工智能技术,必要时可依总统令规定,设立、运营开展人工智能的开发、利用等研究的研究机构。\n[本条新增 2026年1月20日]\n第二十三条(人工智能集群园区的指定等)\n① 国家及地方自治团体为振兴人工智能产业并增强人工智能开发、利用的竞争力,可推进开展人工智能及人工智能技术研发的企业、机构或团体的功能性、物理性、区域性集群化。\n② 国家及地方自治团体为实现依第1款规定的集群化,必要时可依总统令规定指定人工智能集群园区(以下称「人工智能集群园区」),提供行政、财政及技术支持。\n③ 国家及地方自治团体在属于下列各项之一情形时,可撤销人工智能集群园区的指定。但属于第1项情形时,应撤销其指定。\n以虚假或其他不正当方法取得指定的情形\n指定人工智能集群园区的国家或地方自治团体的负责人认为难以达成人工智能集群园区指定目的的情形\n④ 政府为将依第1款规定的集群化有效落实于地方,可设立或指定综合支持相关工作的专门机构。\n⑤ 政府可出资或补助依第4款规定的专门机构的运营及事业执行所需费用的全部或一部分。\n⑥ 其他人工智能集群园区的指定及指定撤销与依第4款规定的专门机构的设立或指定等所需事项,由总统令规定。\n第二十四条(人工智能实证基础的构建等)\n① 国家及地方自治团体为支持人工智能经营者开发或受让技术的实证、性能试验及依第30条规定的检验、认证等(以下称「实证试验等」),可构建、运营试验、评价等所需的设施、装备、设备等(以下称「实证基础等」)。\n② 国家及地方自治团体为促进实证试验等,可将总统令规定的机构所持有的实证基础等向人工智能经营者开放。\n③ 其他实证基础等的构建、运营及开放等所需事项,由总统令规定。\n第二十五条(人工智能数据中心相关政策的推进等)\n① 政府应推进为活跃用于人工智能的开发、利用等的数据中心(以下称「人工智能数据中心」)的构建及运营所需的政策措施。\n② 政府为推进依第1款规定的政策措施,可执行下列各项工作。\n人工智能数据中心的构建及运营所需的行政、财政支持\n支持中小企业、研究机构等利用人工智能数据中心\n为人工智能数据中心等人工智能相关基础设施的地区均衡发展提供支持\n第二十六条(韩国人工智能振兴协会的设立)\n① 从事人工智能等相关研究及工作的人员,为促进人工智能的开发、利用,振兴人工智能产业及人工智能技术,开展人工智能等的教育、宣传等,可依总统令规定取得科学技术信息通信部部长的认可,设立韩国人工智能振兴协会(以下称「协会」),或获指定为协会。\n② 协会为法人。\n③ 协会执行下列各项工作。\n促进及扩散人工智能技术、人工智能产品或人工智能服务的利用\n人工智能等的现状及相关统计调查\n为人工智能经营者设置、运营共同利用设施及培养专业人才的教育等\n支持人工智能经营者及人工智能相关专业人才进军海外\n为安全可信的人工智能的开发、利用而开展的教育及宣传\n依本法或其他法律受托由协会办理的事业\n其他为达成协会设立目的所需且由章程规定的事业\n④ 国家及地方自治团体为人工智能产业的发展与信任基础的构建,必要时可在预算范围内支援协会事业执行所需资金或补助其运营所需经费。\n⑤ 协会会员的资格与高管相关事项、协会的工作等由章程规定;其他应载入章程的事项由总统令规定。\n⑥ 科学技术信息通信部部长作出依第1款规定的认可时,应公告该事实。\n⑦ 关于协会,除本法规定者外,准用《民法》中关于社团法人的规定。\n第四章 人工智能伦理及可信性保障 第二十七条(人工智能伦理原则等)\n① 政府为扩散人工智能伦理,可以按照总统令的规定,制定并公布包含下列各项事项的人工智能伦理原则(以下简称“伦理原则”)。\n关于安全性与可信性的事项,即在人工智能的开发、利用等过程中不损害人的生命、身体及精神健康等\n关于可及性的事项,即所有人均能自由、便利地使用适用人工智能技术的产品、服务等\n关于为对人类生活与繁荣作出贡献而开发、利用人工智能等的事项\n② 科学技术信息通信部长官应当汇集社会各界意见,制定实践方案,使伦理原则能够为参与人工智能开发、利用等的所有人所实现,并予以公开及宣传、教育。\n③ 中央行政机关或地方自治团体的首长制定或修改人工智能伦理标准(不论其名称及形式如何,指有关人工智能伦理的法令、标准、指针、指南等)时,科学技术信息通信部长官可以就与伦理原则及第2款规定的实践方案的关联性、一致性等提出建议或发表意见。\n第二十八条(民间自律人工智能伦理委员会的设置等)\n① 下列各机关或团体为遵守伦理原则,可以设置民间自律人工智能伦理委员会(以下简称“民间自律委员会”)。\n从事人工智能技术研究及开发的人员所属的教育机构、研究机构\n人工智能经营者\n其他由总统令规定的人工智能技术相关机构\n② 民间自律委员会自主执行下列各项工作。\n确认人工智能技术研究、开发、利用中是否遵守伦理原则\n对人工智能技术研究、开发、利用的安全性及侵犯人权等问题进行调查、研究\n对人工智能技术研究、开发、利用的程序及结果进行调查、监督\n对所属机关或团体的研究人员及从业人员进行伦理原则教育\n制定适合人工智能技术研究、开发、利用的各领域人工智能伦理指针\n其他实现伦理原则所需的工作\n③ 民间自律委员会的组成、运营等必要事项,由该机关或团体等自主决定。但不得仅以特定性别(性)组成,并且应当分别包含具备能够评价社会、伦理妥当性的经验与知识的人,以及不在该机关或团体任职的人。\n④ 科学技术信息通信部长官可以为民间自律委员会公正、中立的组成与运营,制定并推广标准指针等。\n第二十九条(为营造人工智能信任基础而制定政策措施)\n政府为将人工智能给国民生活造成的潜在风险降至最低,并为安全使用人工智能而营造信任基础,应当制定下列各项政策措施。\n营造安全、可信的人工智能使用环境\n关于人工智能的使用对国民日常生活的影响等的展望与预测,以及相关法令、制度的完善\n为保障人工智能的安全性、可信性,支持安全技术及认证技术的开发与推广\n为实现安全、可信的人工智能社会及践行人工智能伦理而进行教育、宣传\n支持人工智能经营者就安全性、可信性自主制定并施行规约\n支持并推广由人工智能经营者、使用者等组成的人工智能相关团体(以下简称“团体等”)为增进人工智能的安全性、可信性而进行的自主合作、制定伦理指针等民间活动\n其他为保障人工智能的安全性、可信性而由总统令规定的事项\n第三十条(人工智能安全性、可信性验证与认证等的支持)\n① 科学技术信息通信部长官为支持团体等为保障人工智能的安全性、可信性而自主推进的验证、认证活动(以下简称“验证ㆍ认证等”),可以推进下列各项事业。\n推广关于人工智能开发的指南\n支持关于验证ㆍ认证等的研究\n支持验证ㆍ认证等所使用的设备及系统的构建、运营\n支持培养验证ㆍ认证等所需的专业人才\n其他为支持验证ㆍ认证等而由总统令规定的事项\n② 科学技术信息通信部长官可以按照总统令的规定,向拟获得验证ㆍ认证等的中小企业等提供相关信息,或给予行政、财政支持。\n③ 人工智能经营者提供高影响人工智能时,应当努力事先获得验证ㆍ认证等。\n④ 国家机构等拟使用高影响人工智能时,应当优先考虑基于已获得验证ㆍ认证等的人工智能的产品或服务。\n第三十一条(确保人工智能透明性的义务)\n① 人工智能经营者拟提供利用高影响人工智能或生成式人工智能的产品或服务时,应当事先向使用者告知该产品或服务系基于该人工智能运行这一事实。\n② 人工智能经营者提供生成式人工智能或利用其的产品、服务时,应当标示其输出物系由生成式人工智能生成这一事实。\n③ 人工智能经营者利用人工智能系统提供难以与现实相区分的虚拟音响、图像或影像等输出物时,应当以使用者能够明确认知的方式,告知或标示该输出物系由人工智能系统生成这一事实。在此情形下,该输出物属于艺术性、创造性表达物或构成其一部分时,可以以不妨碍展示或欣赏等的方式告知或标示。\n④ 其他关于第1款规定的事前告知、第2款规定的标示、第3款规定的告知或标示的方法及其例外等必要事项,由总统令规定。\n第三十二条(确保人工智能安全性的义务)\n① 人工智能经营者为保障训练所使用的累计计算量在总统令规定的标准以上的人工智能系统的安全性,应当履行下列各项事项。\n在人工智能全生命周期中对风险进行识别、评估及缓解\n构建对人工智能相关安全事故进行监测和应对的风险管理体系\n② 人工智能经营者应当向科学技术信息通信部长官提交第1款各项事项的履行结果。\n③ 科学技术信息通信部长官应当确定并公告第1款各项事项的具体履行方式及第2款规定的结果提交等必要事项。\n第三十三条(高影响人工智能的确认)\n① 人工智能经营者提供人工智能或利用其的产品、服务时,应当事先审查该人工智能是否属于高影响人工智能,必要时可以请求科学技术信息通信部长官确认其是否属于高影响人工智能。\n② 科学技术信息通信部长官在有第1款规定的请求时,应当确认是否属于高影响人工智能,必要时可以设置专门委员会接受相关咨询。\n③ 科学技术信息通信部长官可以制定并推广关于高影响人工智能的标准与示例等的指南。\n④ 其他关于第1款规定的确认程序等必要事项,由总统令规定。\n第三十四条(与高影响人工智能相关的经营者责任)\n① 人工智能经营者提供高影响人工智能或利用其的产品、服务时,为保障高影响人工智能的安全性、可信性,应当按总统令的规定履行包含下列各项内容的措施。\n风险管理方案的制定、运营\n在技术可能的范围内,就人工智能导出的最终结果、用于导出人工智能最终结果的主要标准、人工智能开发、利用中所使用的学习数据的概要等,制定并施行说明方案\n使用者保护方案的制定、运营\n对高影响人工智能的人为管理、监督\n制作并保存能够确认为保障安全性、可信性所采取措施内容的文件\n其他为保障高影响人工智能的安全性、可信性而经委员会审议、表决的事项\n② 科学技术信息通信部长官应当确定并公告第1款各项措施的具体事项,并可以建议人工智能经营者予以遵守。\n③ 人工智能经营者按照总统令的规定,依其他法令履行了相当于第1款各项措施的措施时,视为已履行第1款规定的措施。\n第三十五条(高影响人工智能影响评估)\n① 人工智能经营者提供利用高影响人工智能的产品或服务时,应当努力事先评估其对人的基本权利的影响(以下简称“影响评估”)。在此情形下,影响评估应当考虑利用高影响人工智能的产品或服务的性质,使人工智能弱势群体的特性得以反映。\n② 国家机构等拟使用利用高影响人工智能的产品或服务时,应当优先考虑已实施影响评估的产品或服务。\n③ 其他关于影响评估的具体内容、方法等必要事项,由总统令规定。\n第三十六条(国内代理人的指定)\n① 在国内无住所或营业所的人工智能经营者,其使用者人数、销售额等符合总统令规定标准的,应当以书面指定代理下列各项事项的人(以下简称“国内代理人”),并向科学技术信息通信部长官申报。\n第32条第2款规定的履行结果的提交\n第33条第1款规定的高影响人工智能所属与否确认的请求\n履行第34条第1款各项规定的保障安全性、可信性措施所需的支持(包括对同款第5号规定的文件的最新性、准确性的检查)\n② 国内代理人应当为在国内有住所或营业所的人。\n③ 国内代理人就第1款各项违反本法时,视为指定该国内代理人的人工智能经营者实施了该行为。\n第五章 补则(보칙,相当于补则/杂则) 第三十七条(为振兴人工智能产业扩充财源等)\n① 国家为有效推进基本计划及本法规定的政策措施等,应当制定能够持续、稳定扩充所需财源的方案。\n② 科学技术信息通信部长官为振兴人工智能产业,必要时可以建议公共机构对振兴人工智能产业的相关事业等提供必要支持。\n③ 国家及地方自治团体应当采取必要措施,使企业等民间主体能够积极投资于振兴人工智能产业的相关事业。\n④ 国家及地方自治团体应当综合考虑人工智能产业的发展阶段等,努力高效执行投资财源。\n第三十八条(实态调查、统计及指标的编制)\n① 科学技术信息通信部长官应当与国家数据处长协商,为基本计划及人工智能等相关政策措施与事业的规划、确立、推进,将国内外人工智能等的实态调查、统计及指标与《科学技术基本法》第26条之2规定的统计相联系,予以编制、管理并公布。\n② 科学技术信息通信部长官为编制第1款规定的统计及指标,可以请求相关中央行政机关的首长、地方自治团体的首长及公共机构的首长提交资料等协助。在此情形下,被请求协助的机构首长如无特别事由,应当遵从。\n③ 其他关于第1款规定的实态调查、统计及指标的编制、管理及公布等必要事项,由总统令规定。\n第三十九条(权限的委任及业务的委托)\n① 科学技术信息通信部长官或相关中央行政机关的首长可以按照总统令的规定,将本法规定的部分权限委任给所属机构的首长或特别市长ㆍ广域市长ㆍ特别自治市长ㆍ道知事ㆍ特别自治道知事(本条中以下简称“市ㆍ道知事”)。在此情形下,市ㆍ道知事可以将所受委任的部分权限再委任给市长(包括《关于设置济州特别自治道及建设国际自由城市的特别法》第11条第2款规定的行政市长)ㆍ郡守ㆍ区厅长(指自治区的区厅长)。\n② 政府可以按照总统令的规定,将下列各项业务委托给相关机构或团体。\n对第13条规定的人工智能技术开发及利用相关事业的支持\n第15条第2款及第3款规定的学习数据的生产、收集、管理、流通及利用等相关支持对象事业的选定、支持,以及学习数据构建事业的推进\n综合提供系统的构建、运营及管理\n科学技术信息通信部长官为第18条规定的创业促进而认为必要的事项\n第30条第2款规定的验证ㆍ认证等相关支持\n第38条规定的实态调查、统计及指标的编制\n其他为培育人工智能产业及扩散人工智能伦理而由总统令规定的事务\n第四十条(事实调查等)\n① 科学技术信息通信部长官在符合下列各项任一情形时,可以要求人工智能经营者提交相关资料,或让所属公务员进行必要调查。\n发现或获知有涉嫌违反第31条第2款、第3款,第32条第1款、第2款或第34条第1款的事项时\n收到关于违反第31条第2款、第3款,第32条第1款、第2款或第34条第1款的举报或受理到民愿时\n② 科学技术信息通信部长官为进行第1款规定的调查,必要时可以让所属公务员进入人工智能经营者的事务所、营业场所,调查账簿、文件及其他资料或物品。在此情形下,除本法关于调查内容、方法及程序规定的事项外,依《行政调查基本法》的规定。\n③ 科学技术信息通信部长官根据第1款及第2款调查的结果,认定人工智能经营者有违反本法的事实时,可以命令该人工智能经营者采取停止或纠正该违反行为所需的措施。\n第四十一条(罚则适用中的公务员拟制)\n① 委员会的委员中非公务员的委员,在适用《刑法》第129条至第132条规定的罚则时,视为公务员。\n② 依第39条第2款受委托业务的相关机构或团体的任员及职员,在适用《刑法》第127条及第129条至第132条规定的罚则时,视为公务员。\n第六章 罚则 第四十二条(罚则)\n违反第7条第9款,将因职务知悉的秘密泄露给他人或用于职务目的以外用途的,处3年以下徒刑或3000万韩元以下罚金。\n第四十三条(罚款)\n① 对符合下列各项任一情形者,处3000万韩元以下罚款。\n违反第31条第1款未履行告知义务者\n违反第36条第1款未指定国内代理人者\n未履行第40条第3款规定的停止命令或纠正命令者\n② 第1款规定的罚款,由科学技术信息通信部长官按照总统令的规定课征并收缴。\n附则〈法律第20676号,2025年1月21日〉\n第一条(施行日) 本法自公布之日起经过1年后施行。但第2条第4号라目中关于数字医疗器械的部分,自2026年1月24日起施行。\n第二条(为施行本法的准备行为) 为施行本法所需的委员会成员的委任,以及分科委员会、特别委员会、咨询团及支援团的组成等,可以在本法施行前进行。\n第三条(关于专职机构的特例) 本法施行时,为将第23条第1款规定的集聚化有效落实于地区,接受政府相关预算支持而正在运营的机构中,符合总统令规定的组织、人力等要件的机构,尽管有第23条第4款的规定,视为已依本法被指定为专职机构。\n附则〈法律第21065号,2025年10月1日〉(政府组织法)\n第一条(施行日) 本法自公布之日起施行。但依附则第7条修改的法律中,在本法施行前已公布而施行日尚未到来的法律,对其修改的部分,分别自该法律施行之日ㆍㆍㆍ(省略)ㆍㆍㆍ起施行。\n及 2. (省略) 第二条至第六条 (省略)\n第七条(其他法律的修改) ①至\u0026lt;95\u0026gt; (省略)\n\u0026lt;96\u0026gt; 对《人工智能发展与信任基础构建等基本法》的部分内容作如下修改。\n将第38条第1款中的“统计厅长”改为“国家数据处长”。\n\u0026lt;97\u0026gt;至\u0026lt;626\u0026gt; (省略)\n第八条 (省略)\n附则〈法律第21311号,2026年1月20日〉\n本法自2026年1月22日起施行。但第3条第5款、第6条第2款第7号ㆍ第8号、第16条第3款至第5款(限于与第2款第2号之2的修改规定相关的部分)、第17条之2、第18条、第22条之3及第35条第1款后段的修改规定,自公布后经过6个月之日起施行。\n","permalink":"https://ai.intlaws.com/compliance/other/korea-ai-framework-act/","summary":"韩国《인공지능 발전과 신뢰 기반 조성 등에 관한 기본법》(通称\u0026quot;AI 基本法\u0026quot;)现行版官方文本中文译校版:6 章 2 节,43 条(另有 3 个分支条号),附则 3 块。法律第 20676 号于 2025 年 1 月 21 日公布、2026 年 1 月 22 日施行;经法律第 21311 号(2026 年 1 月 20 日)修正,部分条款自公布后 6 个月即 2026 年 7 月 21 日施行,故现行版施行日为 2026 年 7 月 21 日。本页并附韩文官方原文;中文译本为据韩文官方文本译校的非官方译本,仅供参考。","title":"韩国人工智能基本法"},{"content":" 版本与来源(可核验)\n项 内容 法案 Senate Bill 53(2025–2026 年例会期),主题\u0026quot;Artificial intelligence models: large developers\u0026quot; 状态 州长签署;2025 年 9 月 29 日经州长签署并同日交存州务卿登记(即已成法) 章号 Chapter 138, Statutes of 2025(官方 chaptered 版载明) 法定名称 Transparency in Frontier Artificial Intelligence Act (TFAIA) —— 见法案 digest 及新设《商业与职业法典》第 25.1 章章名 修改内容 新增《商业与职业法典》第 25.1 章(自第 22757.10 条起);修改《政府法典》第 11546.8 条;新增《劳动法典》第 5.1 章(自第 1107 条起) 官方原文 https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53 立法状态页 bill status ｜州长签署新闻稿(2025-09-29) 中文译本 无官方中文文本。本页中文译文由本网据官方英文文本逐条译校,为非官方译本、仅供参考 → English 收录范围 本页收录法案文本本身(SECTION 1 立法认定 + SEC. 2–6 修改条文),不等同于法典整合后的条文 核对记录 2026-09-22 取自加州立法信息网官方文本页;SECTION 编号与法典条款引用逐处核对 复核记录 2026-09-23 取官方 Chapter 138 登记版 PDF(leginfo 版本 20250SB5390CHP,16 页)复核:SECTION/SEC 6/6、法典条号 11/11(22757.10–16、11546.8、1107–1107.2)、字母项 (a)–(p) 16 类逐一计数一致、SEC 分段数字款 (1)(2)(3) 逐段一致 —— 与官方文本零缺漏 法案文本 SECTION 1. 立法机关认定并声明下列全部内容：\n(a) 加州正通过大大小小的企业以及本州卓越的公立和私立大学，在人工智能创新与研究方面引领世界。\n(b) 人工智能，包括基础模型的新进展，具有催生创新并迅速为加州人和加州经济带来广泛惠益的潜力，包括在医学、野火预测与预防以及气候科学方面的进步，并能够拓展人类创造力与能力的边界。\n(c) 加州人工智能前沿模型联合政策工作组已就人工智能政策提出了健全的原则。\n(d) 为支持有效的人工智能治理而采取的针对性干预措施，应当平衡该技术的惠益与重大风险的潜在可能。\n(e) 在构建稳健且透明的证据环境过程中，政策制定者可以协调各类激励，以同时保护消费者、借助行业专业知识并认可领先的安全做法。\n(f) 随着行业主体就其技术的影响开展内部研究，获取有关前沿人工智能能力的信息并提高对此的认识，将显著增进公众对这些技术的信任。\n(g) 更高的透明度还可以促进问责、竞争和公众信任。\n(h) 举报人保护与面向公众的信息共享是提高透明度的关键工具。\n(i) 事件报告制度使得对人工智能部署后影响的监测成为可能。\n(j) 除非以审慎的尽职和合理的预防措施加以开发，人们担心先进的人工智能系统可能具备的能力会因恶意使用和失灵而带来灾难性风险，包括人工智能驱动的黑客攻击、生物攻击和失控。\n(k) 随着人工智能前沿的快速演进，需要立法来跟踪人工智能研究的前沿，并就最为先进的人工智能系统所带来的严重风险和损害向政策制定者和公众发出警示，同时避免给处于前沿之后的小型公司造成负担。\n(l) 尽管主要的人工智能开发者已自愿将前沿人工智能框架的制定、使用和公布确立为行业最佳做法，但并非所有开发者所提供的报告都一致且充分，足以确保必要的透明度和对公众的保护。需要由前沿开发者进行强制、标准化和客观的报告，以便向政府和公众提供及时且准确的信息。\n(m) 及时向政府报告重大安全事件，对于确保公共当局及时获悉对公共安全持续存在和新出现的风险至关重要。此类报告使政府能够在前沿人工智能模型中出现可能对公众构成威胁的先进能力时，进行监测、评估和有效应对。\n(n) 未来，由规模较小的公司开发或处于前沿之后的基础模型可能构成重大灾难性风险，届时可能需要额外的立法。\n(o) 近期发布的州长《加州前沿人工智能政策报告》以及立法机关就人工智能举行的立法听证会上的证词，反映了人工智能模型能力的进步可能在前沿人工智能领域造成潜在灾难性风险，本法案旨在应对该问题。\n(p) 立法机关的意图是创造更多透明度，但集体安全将部分取决于前沿开发者在其前沿模型的开发和部署中，按其可预见风险的规模采取应有的注意。\nSEC. 2. 在《商业与职业法典》第 8 编中新增第 25.1 章（自第 22757.10 条起），内容如下：\n第 25.1 章 前沿人工智能透明度法 第 22757.10 条 本章称为《前沿人工智能透明度法》。\n第 22757.11 条 本章用语定义如下：\n(a) “关联方”指直接或间接通过一个或多个中间主体控制某一特定主体（原文 “specified person”）、受某一特定主体控制或与该特定主体处于共同控制之下的主体。\n(b) “人工智能模型”指一种工程化的或基于机器的系统，其自主程度各不相同，并可为实现明示或默示的目标，从所接收的输入中推断如何生成能够影响物理或虚拟环境的输出。\n(c)\n(1) “灾难性风险”指一项可预见且重大的风险，即前沿开发者对前沿模型的开发、存储、使用或部署，将实质性地促成因单一起涉及前沿模型的事件而导致 50 人以上死亡或重伤，或造成超过十亿美元（$1,000,000,000）的财产损害或损失，而该前沿模型实施了下列任一行为：\n(A) 在为制造或释放化学、生物、放射性或核武器方面提供专家级协助。\n(B) 在没有任何有意义的人类监督、干预或管控的情况下实施行为，该行为属于网络攻击，或者若由人类实施则构成谋杀、伤害、敲诈勒索或盗窃罪，包括以虚假借口实施的盗窃。\n(C) 逃避其前沿开发者或用户的控制。\n(2) “灾难性风险”不包括来自下列任一情形的可预见且重大风险：\n(A) 前沿模型输出的信息，而该信息以实质相似的形式可从基础模型以外的来源公开获取。\n(B) 联邦政府的合法活动。\n(C) 前沿模型与其他软件共同造成的损害，而该前沿模型并未对该损害起实质性促成作用。\n(d) “重大安全事件”指下列任一情形：\n(1) 未经授权访问、修改或窃取前沿模型的模型权重，并导致死亡或身体伤害。\n(2) 灾难性风险实际发生所导致的损害。\n(3) 前沿模型失控并导致死亡或身体伤害。\n(4) 前沿模型针对其前沿开发者使用欺骗性技术，以规避其前沿开发者的控制或监测，且该行为发生在旨在诱发此行为的评估情形之外，并表明灾难性风险实质增加。\n(e)\n(1) “部署”指使前沿模型可供第三方使用、修改、复制或与其他软件组合。\n(2) “部署”不包括为使第三方以开发或评估前沿模型为主要目的而提供前沿模型。\n(f) “基础模型”指符合下列全部情形的人工智能模型：\n(1) 在广泛的数据集上训练。\n(2) 为输出的通用性而设计。\n(3) 可适应范围广泛的各类特定任务。\n(g) “前沿人工智能框架”指用于管理、评估和缓解灾难性风险的成文技术与组织规程。\n(h) “前沿开发者”指已训练或已启动训练某一前沿模型的主体，就该前沿模型而言，该主体已使用或意图使用至少达到 (i) 款所载技术规格的计算量来训练该前沿模型。\n(i)\n(1) “前沿模型”指使用超过 10^26 次整数或浮点运算的计算量训练的基础模型。\n(2) 第 (1) 项所述的计算量应包括原始训练运行的计算量，以及开发者对在先基础模型所作的任何后续微调、强化学习或其他重大修改的计算量。\n(j) “大型前沿开发者”指连同其关联方在前一日历年度的年度总收入合计超过五亿美元（$500,000,000）的前沿开发者。\n(k) “模型权重”指前沿模型中经训练调整的、有助于确定输入如何转换为输出的数值参数。\n(l) “财产”指有形或无形财产。\n第 22757.12 条 (a) 大型前沿开发者应编写、实施、遵守并清晰显著地在其互联网网站上公布适用于该大型前沿开发者的前沿模型的前沿人工智能框架，并说明该大型前沿开发者如何处理下列全部事项：\n(1) 将国家标准、国际标准及行业共识最佳做法纳入其前沿人工智能框架。\n(2) 界定并评估该大型前沿开发者用于识别和评估某一前沿模型是否具备可能构成灾难性风险的能力的阈值，可包括多级阈值。\n(3) 根据依据第 (2) 项开展的评估结果，采取缓解措施以应对灾难性风险的潜在可能。\n(4) 在决定部署某一前沿模型或在内部广泛使用该模型时，审查评估及缓解措施的充分性。\n(5) 使用第三方评估灾难性风险的潜在可能以及灾难性风险缓解措施的有效性。\n(6) 重新审视并更新前沿人工智能框架，包括触发更新的任何标准，以及大型前沿开发者如何判定其前沿模型已被重大修改至须依据 (c) 款进行披露的程度。\n(7) 保护未发布的模型权重免遭内部或外部主体未经授权修改或转移的网络安全做法。\n(8) 识别和应对重大安全事件。\n(9) 建立内部治理做法以确保上述流程得到实施。\n(10) 评估和管理因内部使用其前沿模型而产生的灾难性风险，包括因前沿模型规避监督机制而产生的风险。\n(b)\n(1) 大型前沿开发者应至少每年一次审查并酌情更新其前沿人工智能框架。\n(2) 若大型前沿开发者对其前沿人工智能框架作出重大修改，该大型前沿开发者应在 30 日内清晰显著地公布修改后的前沿人工智能框架及该项修改的理由。\n(c)\n(1) 在部署新的前沿模型或现有前沿模型的重大修改版本之前或与之同时，前沿开发者应清晰显著地在其互联网网站上公布一份包含下列全部内容的透明度报告：\n(A) 前沿开发者的互联网网站。\n(B) 使自然人能够与该前沿开发者进行沟通的机制。\n(C) 前沿模型的发布日期。\n(D) 前沿模型支持的语言。\n(E) 前沿模型支持的输出模态。\n(F) 前沿模型的预期用途。\n(G) 对前沿模型用途的任何普遍适用的限制或条件。\n(2) 在部署新的前沿模型或现有前沿模型的重大修改版本之前或与之同时，大型前沿开发者应在第 (1) 项要求的透明度报告中包含下列全部内容的摘要：\n(A) 依据该大型前沿开发者的前沿人工智能框架就该前沿模型开展的灾难性风险评估。\n(B) 上述评估的结果。\n(C) 第三方评估者的参与程度。\n(D) 为就该前沿模型满足前沿人工智能框架的要求而采取的其他步骤。\n(3) 将第 (1) 项或第 (2) 项所述信息作为更大文件（包括系统卡或模型卡）的一部分予以公布的前沿开发者，应被视为符合相应项的要求。\n(4) 鼓励但不要求前沿开发者作出本款所述与行业最佳做法一致或优于行业最佳做法的披露。\n(d) 大型前沿开发者应每三个月一次，或按其指定的另一合理时间表（该时间表应以书面形式告知紧急服务办公室，并酌情提供书面更新），向紧急服务办公室提交因内部使用其前沿模型而产生的任何灾难性风险评估的摘要。\n(e)\n(1) (A) 前沿开发者不得就其前沿模型所带来的灾难性风险或其对该风险的管理作出重大虚假或误导性陈述。\n(B) 大型前沿开发者不得就其前沿人工智能框架的实施或遵守情况作出重大虚假或误导性陈述。\n(2) 本款不适用于善意作出且在具体情形下属合理的陈述。\n(f)\n(1) 当前沿开发者公布文件以遵守本条时，该前沿开发者可对该等文件进行为保护其商业秘密、其网络安全、公共安全或美国国家安全，或为遵守任何联邦或州法律而有必要的删节。\n(2) 若前沿开发者依据本款对文件中的信息作出删节，该前沿开发者应在该文件任何已公布的版本中，在支持该项删节的关切所允许的范围内说明该删节的性质和理由，并应将未经删节的信息保存五年。\n第 22757.13 条 (a) 紧急服务办公室应设立一种机制，供前沿开发者或公众成员报告重大安全事件，该机制包括下列全部内容：\n(1) 重大安全事件的日期。\n(2) 该事件构成重大安全事件的理由。\n(3) 描述该重大安全事件的简短明了的陈述。\n(4) 该事件是否与前沿模型的内部使用相关。\n(b)\n(1) 紧急服务办公室应设立一种机制，供大型前沿开发者以保密方式提交因内部使用其前沿模型而产生的任何灾难性风险潜在可能的评估摘要。\n(2) 紧急服务办公室应采取一切必要预防措施，将与前沿模型内部使用相关的任何报告仅限具有特定知悉需要的人员查阅，并保护该等报告免遭未经授权的访问。\n(c)\n(1) 在符合第 (2) 项的前提下，前沿开发者应在发现重大安全事件后 15 日内，就其一个或多个前沿模型所涉的任何重大安全事件向紧急服务办公室报告。\n(2) 若前沿开发者发现某一重大安全事件构成死亡或严重身体伤害的紧迫风险，该前沿开发者应在 24 小时内，向根据该事件性质属适当且为法律所要求的机关（包括任何具有管辖权的执法机关或公共安全机关）披露该事件。\n(3) 在提交本款所要求的初次报告后才发现有关某一重大安全事件的信息的前沿开发者，可提交经修订的报告。\n(4) 鼓励但不要求前沿开发者报告与不属于前沿模型的基础模型有关的重大安全事件。\n(d) 紧急服务办公室应审查前沿开发者提交的重大安全事件报告，并可审查公众成员提交的报告。\n(e)\n(1) 总检察长或紧急服务办公室可将依据《劳动法典》第 2 编第 3 部分第 5.1 章（自第 1107 条起）作出的重大安全事件报告和受保护雇员报告转交立法机关、州长、联邦政府或适当的州机关。\n(2) 总检察长或紧急服务办公室在转交报告时，应充分考量与商业秘密、公共安全、前沿开发者的网络安全或国家安全相关的任何风险。\n(f) 依据本条向紧急服务办公室提交的重大安全事件报告、依据第 22757.12 条提交的内部使用灾难性风险评估报告，以及依据《劳动法典》第 2 编第 3 部分第 5.1 章（自第 1107 条起）作出的受保护雇员报告，均豁免适用《加州公共记录法》（《政府法典》第 1 编第 10 编（自第 7920.000 条起））。\n(g)\n(1) 自 2027 年 1 月 1 日起及此后的每一年，紧急服务办公室应编制一份报告，载有关于自上一份报告以来经紧急服务办公室审查的重大安全事件的匿名化和汇总信息。\n(2) 紧急服务办公室不得依据本款在报告中包含会损害前沿开发者的商业秘密或网络安全、公共安全或美国国家安全的信息，或任何联邦或州法律所禁止的信息。\n(3) 紧急服务办公室应依据第 9795 条将本款所述报告转交立法机关，并转交州长。\n(h) 紧急服务办公室可通过规章，为 (i) 款之目的指定符合下列全部条件的一项或多项联邦法律、法规或指导文件：\n(1) (A) 该法律、法规或指导文件对重大安全事件报告规定或载明的标准或要求，与本条所要求者实质等同或更为严格。\n(B) (A) 目所述法律、法规或指导文件无需要求向加利福尼亚州报告重大安全事件。\n(2) 该法律、法规或指导文件旨在评估、检测或缓解灾难性风险。\n(i)\n(1) 意图通过遵守依据 (h) 款指定的联邦法律、法规或指导文件的要求或达到其所载标准来遵守本条的前沿开发者，应向紧急服务办公室声明其上述意图。\n(2) 在前沿开发者依据第 (1) 项声明其意图后，下列两项均适用：\n(A) 在前沿开发者向紧急服务办公室声明撤销该意图，或紧急服务办公室依据 (j) 款撤销相关规章之前，该前沿开发者在其达到指定联邦法律、法规或指导文件所载标准或遵守其规定或所载要求的范围内，应被视为符合本条。\n(B) 前沿开发者未能达到依据 (h) 款指定的联邦法律、法规或指导文件所载标准，或未遵守其所载要求，构成对本章的违反。\n(j) 若 (h) 款的要求不再得到满足，紧急服务办公室应撤销依据 (h) 款通过的规章。\n第 22757.14 条 (a) 在 2027 年 1 月 1 日或之前，以及此后的每一年，技术部应评估与本编目的相关的近期证据和进展，并就是否及如何为本编目的更新下列任何定义提出建议，以确保该等定义准确反映技术发展、科学文献以及广泛接受的国家和国际标准：\n(1) “前沿模型”，使其适用于处于人工智能发展前沿的基础模型。\n(2) “前沿开发者”，使其适用于自身处于人工智能发展前沿的前沿模型开发者。\n(3) “大型前沿开发者”，使其适用于资源雄厚的前沿开发者。\n(b) 在依据本条提出建议时，技术部应考虑下列全部事项：\n(1) 国际标准或联邦法律、指导文件或法规中为管理灾难性风险而使用的类似阈值，并应在其与本编目的一致的范围内与联邦法律或法规所采纳的定义保持一致。\n(2) 来自利益相关方（包括学术界、行业、开源社区和政府实体）的意见。\n(3) 某一主体在开始训练或部署基础模型之前，能够在多大程度上确定其是否将作为前沿开发者或大型前沿开发者而受该定义涵盖，并力求在可能的情况下允许更早作出确定。\n(4) 确定某一主体或基础模型是否被涵盖的复杂性，并力求在可能的情况下允许更简单的确定。\n(5) 确定某一主体或基础模型是否被涵盖的外部可验证性，并力求使定义可由前沿开发者以外的主体验证。\n(c) 在依据本条形成建议后，技术部应依据《政府法典》第 9795 条向立法机关提交载有该等建议的报告。\n(d)\n(1) 自 2027 年 1 月 1 日起及此后的每一年，总检察长应编制一份报告，载有关于自上一份报告以来经总检察长审查的依据《劳动法典》第 2 编第 3 部分第 5.1 章（自第 1107 条起）作出的受保护雇员报告的匿名化和汇总信息。\n(2) 总检察长不得依据本款在报告中包含会损害前沿开发者的商业秘密或网络安全、受保护雇员的保密性、公共安全或美国国家安全的信息，或任何联邦或州法律所禁止的信息。\n(3) 总检察长应依据《政府法典》第 9795 条将本款所述报告转交立法机关，并转交州长。\n第 22757.15 条 (a) 未能公布或转交本章要求公布或转交的合规文件、作出违反第 22757.12 条 (e) 款的陈述、未按第 22757.13 条的要求报告事件，或未遵守其自身前沿人工智能框架的大型前沿开发者，应被处以依违规严重程度确定的民事罚款，每次违规不超过一百万美元（$1,000,000）。\n(b) 本条所述民事罚款应仅在由总检察长提起的民事诉讼中予以追缴。\n第 22757.16 条 就本章而言，股权价值损失不计为财产损害或损失。\nSEC. 3. 在《政府法典》中增加第 11546.8 条，内容如下：\n第 11546.8 条 (a) 特此在政府运作局内设立一个联合体，该联合体应依据本条制定创建名为“CalCompute”的公共云计算集群的框架。\n(b) 该联合体应制定创建 CalCompute 的框架，通过至少实施下列两项，推进安全、合乎伦理、公平且可持续的人工智能的开发与部署：\n(1) 促进有益于公众的研究和创新。\n(2) 通过扩大对计算资源的获取来促进公平创新。\n(c) 该联合体应作出合理努力，确保 CalCompute 在尽可能的范围内设立于加州大学之内。\n(d) CalCompute 应包括但不限于下列全部内容：\n(1) 完全自有并自托管的云平台。\n(2) 运营和维护该平台所必需的人力专业能力。\n(3) 支持、培训并促进使用 CalCompute 所必需的人力专业能力。\n(e) 该联合体应依照所有相关的劳动和劳动力法律及标准运作。\n(f)\n(1) 在 2027 年 1 月 1 日或之前，政府运作局应依据第 9795 条向立法机关提交一份来自该联合体的报告，其中载有依据 (b) 款制定的用于创建和运营 CalCompute 的框架。\n(2) 本款要求的报告应包括下列全部要素：\n(A) 对加州当前公共、私营和非营利云计算平台基础设施的格局分析。\n(B) 对本州建设和维护 CalCompute 的成本的分析以及关于潜在资金来源的建议。\n(C) 关于 CalCompute 的治理结构和持续运营的建议。\n(D) 关于 CalCompute 使用参数的建议，包括但不限于确定哪些用户和项目将获得 CalCompute 支持的程序。\n(E) 对本州技术人才队伍的分析以及关于加强该队伍（包括 CalCompute 的作用）的公平路径的建议。\n(F) 与包括但不限于技术型公司在内的非政府实体拟议的任何合作、合同或许可协议的详细说明，该说明须证明符合 (c) 款和 (d) 款的要求。\n(G) 关于 CalCompute 的创建和持续管理如何能够优先使用当前公共部门人才队伍的建议。\n(g) 该联合体应在符合州宪法的前提下，由下列 14 名成员组成：\n(1) 由政府运作部长任命的加州大学及其他公立和私立学术研究机构以及国家实验室的 4 名代表。\n(2) 由众议院议长任命的受影响劳动力劳工组织的 3 名代表。\n(3) 由参议院规则委员会任命的、具有相关专业知识和经验（包括但不限于伦理学家、消费者权益倡导者和其他公共利益倡导者）的利益相关方团体的 3 名代表。\n(4) 由政府运作部长任命的提供技术协助的 4 名技术和人工智能专家。\n(h) 联合体成员应无偿任职，但其履行职责实际发生的所有必要费用应予报销。\n(i) 联合体应在向立法机关提交 (f) 款第 (1) 项要求的报告后解散。\n(j) 若 CalCompute 设立于加州大学之内，加州大学可为实施 CalCompute 之目的接受私人捐赠。\n(k) 本条仅在为实施本条之目的在预算法案或其他措施中获得拨款时方可生效。\nSEC. 4. 在《劳动法典》第 2 编第 3 部分中新增第 5.1 章（自第 1107 条起），内容如下：\n第 5.1 章 举报人保护：人工智能基础模型中的灾难性风险 第 1107 条 本章用语定义如下：\n(a)\n(1) “灾难性风险”指一项可预见且重大的风险，即前沿开发者对基础模型的开发、存储、使用或部署，将实质性地促成因单一起涉及基础模型的事件而导致 50 人以上死亡或重伤，或造成超过十亿美元（$1,000,000,000）的财产损害或损失，而该基础模型实施了下列任一行为：\n(A) 在为制造或释放化学、生物、放射性或核武器方面提供专家级协助。\n(B) 在没有任何有意义的人类监督、干预或管控的情况下实施行为，该行为属于网络攻击，或者若由人类实施则构成谋杀、伤害、敲诈勒索或盗窃罪，包括以虚假借口实施的盗窃。\n(C) 逃避其前沿开发者或用户的控制。\n(2) “灾难性风险”不包括来自下列任一情形的可预见且重大风险：\n(A) 基础模型输出的信息，而该信息以实质相似的形式可从基础模型以外的来源公开获取。\n(B) 联邦政府的合法活动。\n(C) 基础模型与其他软件共同造成的损害，而该基础模型并未对该损害起实质性促成作用。\n(b) “受保护雇员”指负责评估、管理或应对重大安全事件风险的雇员。\n(c) “重大安全事件”指下列任一情形：\n(1) 未经授权访问、修改或窃取基础模型的模型权重，并导致死亡、身体伤害或财产损害或损失。\n(2) 灾难性风险实际发生所导致的损害。\n(3) 基础模型失控并导致死亡或身体伤害。\n(4) 基础模型针对前沿开发者使用欺骗性技术，以规避其前沿开发者的控制或监测，且该行为发生在旨在诱发此行为的评估情形之外，并表明灾难性风险实质增加。\n(d) “基础模型”具有《商业与职业法典》第 22757.11 条所定义的含义。\n(e) “前沿开发者”具有《商业与职业法典》第 22757.11 条所定义的含义。\n(f) “大型前沿开发者”具有《商业与职业法典》第 22757.11 条所定义的含义。\n第 1107.1 条 (a) 前沿开发者不得制定、采纳、执行或订立任何规则、规章、政策或合同，以阻止受保护雇员向总检察长、联邦机关、对受保护雇员享有权限的个人，或另一名有权限调查、发现或纠正所报告问题的受保护雇员披露信息，或因其作出该等披露而对其进行报复，前提是该受保护雇员有合理理由相信该信息披露了下列任一情形：\n(1) 前沿开发者的活动因灾难性风险而对公共卫生或安全构成具体且重大的危险。\n(2) 前沿开发者违反了《商业与职业法典》第 8 编第 25.1 章（自第 22757.10 条起）。\n(b) 前沿开发者不得订立阻止受保护雇员作出受第 1102.5 条保护的披露的合同。\n(c) 受保护雇员可利用第 1102.7 条所述热线作出 (a) 款所述报告。\n(d) 前沿开发者应向所有受保护雇员提供关于其在本条之下权利和责任的明确通知，包括以下列任一方式为之：\n(1) 始终在前沿开发者维持的任何工作场所内张贴和展示向所有受保护雇员告知其在本条之下权利的通知，确保任何新的受保护雇员收到同等通知，并确保任何远程工作的受保护雇员定期收到同等通知。\n(2) 每年至少一次向每名受保护雇员提供关于该受保护雇员在本条之下权利的书面通知，并确保所有该等受保护雇员收到并确认该通知。\n(e)\n(1) 大型前沿开发者应提供合理的内部程序，使受保护雇员在其善意认为有关信息表明大型前沿开发者的活动因灾难性风险而对公共卫生或安全构成具体且重大的危险，或大型前沿开发者违反了《商业与职业法典》第 8 编第 25.1 章（自第 22757.10 条起）时，可通过该程序匿名向大型前沿开发者披露信息，包括每月向作出披露者提供关于大型前沿开发者对该披露的调查状况以及大型前沿开发者针对该披露所采取行动的最新情况。\n(2) (A) 除 (B) 目另有规定外，本款所要求程序的披露和回应应至少每季度一次与大型前沿开发者的高管和董事共享。\n(B) 若受保护雇员在披露或回应中指控大型前沿开发者的某位高管或董事存在不当行为，(A) 目对该高管或董事不适用。\n(f) 法院有权向就违反本条提起成功诉讼的原告判给合理的律师费。\n(g) 在依据本条提起的民事诉讼中，一旦以优势证据证明本条所禁止的活动是所指控的对受保护雇员的禁止性行为的促成因素，前沿开发者即负有举证责任，须以清楚且令人信服的证据证明：即使该受保护雇员未从事受本条保护的活动，所指控的行为本也会因合法、独立的理由而发生。\n(h)\n(1) 在依据本条提起的民事诉讼或行政程序中，受保护雇员可向所指称违规行为发生地、或其居住地或从事业务所在地的任何县的高等法院申请适当的临时或初步禁令救济。\n(2) 在提出禁令救济申请后，申请人应促成将该申请的通知送达相关主体，此后法院即有权按其认为公正和适当的方式授予临时禁令救济。\n(3) 除因违反本条而直接造成的任何损害外，法院在判定临时禁令救济是否公正和适当时，应考虑对其他受保护雇员主张其在本条之下权利所造成的寒蝉效应。\n(4) 在表明存在合理理由相信已发生违规时，应发出适当的禁令救济。\n(5) 授权临时禁令救济的命令应持续有效，直至作出行政或司法裁定或发出违法通知，或直至依据第 98.74 条 (b) 款完成复审，以其中时间较长者为准，或持续至法院设定的特定时间。此后，如表明属公正和适当，可发出初步或永久禁令。任何临时禁令救济不得禁止前沿开发者就与报复主张无关的行为对受保护雇员进行纪律处分或解雇。\n(i) 尽管有《民事诉讼法典》第 916 条的规定，依据本条授予的禁令救济在上诉期间不予中止。\n(j)\n(1) 本条不损害或限制第 1102.5 条的适用性，包括非受保护雇员举报违反本章或《商业与职业法典》第 8 编第 25.1 章（自第 22757.10 条起）行为的权利。\n(2) 本条规定的救济措施互不排斥，并与本州所有其他法律下可获得的救济或处罚并存。\n第 1107.2 条 就本章而言，股权价值损失不计为财产损害或损失。\nSEC. 5. (a) 本法案各条款可分割。若本法案任何条款或其适用被认定无效，该无效不影响可在没有该无效条款或适用的情况下予以实施的其他条款或适用。\n(b) 本法案应作宽泛解释，以实现其目的。\n(c) 本法案所施加的义务和责任与其他法律所施加的任何其他义务或责任并存，且不得解释为免除任何一方依其他法律所施加的任何义务或责任，也不限制现行法律下的任何权利或救济。\n(d) 在严格抵触联邦政府实体与前沿开发者之间合同条款的范围内，本法案不适用。\n(e) 在联邦法律优先适用的范围内，本法案不适用。\n(f) 本法案优先于任何市、县、市县合一政府、自治市或地方机构在 2025 年 1 月 1 日或之后专门就前沿开发者在灾难性风险管理方面的监管而采纳的任何规则、规章、法典、条例或其他法律。\nSEC. 6. 立法机关认定并声明，本法案第 2 条，即在《商业与职业法典》第 8 编中新增第 25.1 章（自第 22757.10 条起），在《加州宪法》第一条第 3 条的含义内对公众查阅公共机构会议或公职人员及机构文稿的权利施加了限制。依据该宪法条款，立法机关作出下列认定，以证明该限制所保护的利益以及保护该利益的必要性：\n重大安全事件报告、内部使用风险评估以及受保护雇员报告中的信息，若向公众披露，可能包含会威胁公共安全或妨碍对事件之应对的信息。\n","permalink":"https://ai.intlaws.com/compliance/us/california-sb-53/","summary":"加州前沿人工智能透明度法(Transparency in Frontier Artificial Intelligence Act,TFAIA;参议院第 53 号法案)官方文本中文译校版。该法案为大型前沿人工智能模型的开发者设定透明度与事件报告义务,修改《商业与职业法典》(新增第 25.1 章,自第 22757.10 条起)、《政府法典》第 11546.8 条与《劳动法典》(新增第 5.1 章,自第 1107 条起);州务卿登记日为 2025 年 9 月 29 日。本页为据官方英文文本逐条译校的中文译本(非官方)。","title":"加州前沿人工智能透明度法"},{"content":" 版本与来源（可核验）\n项目 内容 通过 2024 年 12 月 24 日联合国大会第 79/243 号决议通过，公约载于该决议附件 结构 序言 + 9 章 68 条 生效条件 公约第 65 条：自第 40 份批准书、接受书、核准书或加入书交存之日起第 90 天生效（已核官方原文） 现行状态 尚未生效（截至 2026-09-22；签署与批准进展见联合国条约集 https://treaties.un.org ） 中文原文来源 联合国正式文件 （中文版）：https://documents.un.org/api/symbol/access?s=A%2FRES%2F79%2F243\u0026amp;l=zh\u0026amp;t=pdf 英文原文来源 UNODC 公约全文页 https://www.unodc.org/unodc/en/cybercrime/convention/text/convention-full-text.html ；联合国正式文件 （英文版）：https://documents.un.org/api/symbol/access?s=A%2FRES%2F79%2F243\u0026amp;l=en\u0026amp;t=pdf 校对记录 2026-09-22 抓取官方文本；中英条目 68 条一一对应、无缺号；第 47 条（执法合作 / Law enforcement cooperation）经中英互校确认；英文第 47 条标题在联合国 PDF 文本层缺失，已依 UNODC 官方 HTML 文本与中文官方文本互校补齐 说明 本页为条约原文，中、英文均取自联合国官方文本，不涉及翻译 第一章 总则 第一条 宗旨声明 本公约的宗旨是：\n㈠ 促进和加强各项措施，以更高效和更有效地预防和打击网络犯罪；\n㈡ 促进、便利和加强在预防和打击网络犯罪方面开展的国际合作；以及\n㈢ 促进、便利和支持技术援助和能力建设，以预防和打击网络犯罪，特别是使发展中国家从中受益。\n第二条 术语的使用 为本公约之目的：\n㈠ “信息通信技术系统 ”系指任何设备或任何一组相互连接或相关的设备，其中一个或多个设备按照某一程序收集、存储并自动处理电子数据；\n㈡ “电子数据”系指任何以适合在信息通信技术系统内处理的形式表现的事实、信息或概念，包括适合使信息通信技术系统 得以 执行某一功能的程序；\n㈢ “流量数据”系指与使用信息通信技术系统进行的通信有关的任何电子数据，由构成通信链一部分的信息通信技术系统生成，显示通信的起点、终点、路径、时间、日期、数据量大小、持续时间或基础服务类型；\n㈣ “内容数据”系指与使用信息通信技术系统传输的数据的实质内容有关，且不属于订阅用户信息或流量数据的任何电子数据，包括但不限于图像、文本消息、语音消息、录音和录像；\n㈤ “服务提供者”系指以下任何公共或私营实体：\n能让使用其服务的用户使用信息通信技术系统进行通信；或 为此类通信服务或此类服务的用户处理或存储电子数据；\n㈥ “订阅用户信息 ”系指服务提供者持有的与其服务订阅用户有关的任何信息，但不包括流量数据或内容数据，通过订阅用户信息可以确定： 所使用的通信服务种类、与之相关的技术条款以及服务期限； 根据服务协议或安排提供的订阅用户身份、邮政地址或地理地址、电话或其他接入号码、账单信息或付款信息； 根据服务协议或安排提供的关于通信设备安装地点的任何其他信息；\n㈦ “个人数据”系指与已识别或可识别身份的自然人有关的任何信息；\n㈧ “严重犯罪”系指构成犯罪且最高可处以至少四年有期徒刑或更重惩处的行为；\n㈨ “财产”系指各种资产，不论是物质的或非物质的、动产或不动产、有形的或无形的，包括虚拟资产，以及证明对这些资产拥有所有权或权益的法律文件或文书；\n㈩ “犯罪所得 ”系指通过实施犯罪而直接或间接产生或获得的任何财产；(十一) “冻结”或“扣押”系指根据法院或其他主管机关签发的命令暂时禁止财产转移、转换、处置或移动，或对财产实行暂时性扣留或控制；(十二) “没收”，在适用情况下亦包括充公，系指根据法院或其他主管机关的命令对财产实行永久剥夺；(十三) “上游犯罪”系指由其所产生的收益可能成为本公约第十七条所界定的犯罪对象的任何犯罪；(十四) “区域经济一体化组织”系指由某一区域的一些主权国家组成的组织，其成员国已将处理本公约涵盖范围内事务的权限转交该组织，而且该组织已按照其内部程序获得签署、批准、接受、核准或加入本公约的正式授权；本公约中“缔约国”的指称在此类组织的权限范围内适用于这些组织；(十五) “紧急情况”系指任何自然人的生命或安全面临重大和紧迫风险的情况。\n第三条 适用范围 本公约除其中另有规定者外，应适用于：\n㈠ 预防、侦查和起诉根据本公约确立的刑事犯罪，包括冻结、扣押、没收和返还此类犯罪的所得；\n㈡ 根据本公约第二十三条和第三十五条，为进行刑事侦查或诉讼的目的，收集、获取、保全和共享电子证据。\n第四条 根据联合国其他公约和议定书确立的犯罪 一、 在履行其作为缔约国的其他适用的联合国公约和议定书时，缔约国应当确保根据此类公约和议定书确立的刑事犯罪，在使用信息通信技术系统实施时，亦视作本国法律规定的刑事犯罪。\n二、 本条中的任何内容均不得解释为根据本公约确立刑事犯罪。\n第五条 保护主权\n一、 在履行其根据本公约所承担的义务时，缔约国应恪守各国主权平等和领土完整原则和不干涉他国内政原则。\n二、 本公约的任何规定均未授权一缔约国在另一国领土内行使管辖权和履行该另一国本国法律规定的专属于该国机关的职能。\n第六条 尊重人权\n一、 在履行其根据本公约承担的义务时，缔约国应当确保符合其所承担的国际人权法义务。\n二、 根据可适用的国际人权法 且依循与此类人权法相一致的方式，本公约的任何规定均不得解释为允许压制人权或基本自由，包括与言论自由、良心自由、意见自由、宗教或信仰自由、和平集会和结社自由相关的权利。\n第二章 刑事定罪 第七条 非法访问\n一、 各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意访问信息通信技术系统的全部或任何部分的行为规定为刑事犯罪 行为。\n二、 缔约国可规定此类犯罪须是以违反安全措施方式实施的，其意图是获取电子数据或有其他不诚实意图或犯罪意图，或者涉及与另一信息通信技术系统相连的信息通信技术系统。\n第八条 非法拦截\n一、 各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意实施的以下行为规定为刑事犯罪行为：以技术手段拦截进出信息通信技术系统的或在此类系统内部的电子数据非公开传输，包括拦截携带此类电子数据的信息通信技术系统发出的电磁辐射。\n二、 缔约国可规定此种犯罪须是带有不诚实意图或犯罪意图实施的，或者涉及与另一信息通信技术系统相连的信息通信技术系统。\n第九条 干扰电子数据\n一、 各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意破坏、删除、劣化、更改或抑制电子数据的行为规定为刑事犯罪 行为。\n二、 缔约国可规定本条第一款所述行为须是造成了严重损害的行为。\n第十条 干扰信息通信技术系统 各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意通过输入、传输、破坏、删除、劣化、更改或抑制电子数据而严重妨碍信息通信技术系统运行的行为规定为刑事犯罪行为。\n第十一条 滥用设备\n一、 各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意实施的以下行为规定为刑事犯罪行为：\n㈠ 获取、制作、销售、采购以供使用、进口、分销或以其他方式提供：\n主要为实施根据本公约第七条至第十条确立的任何犯罪行为而设计或改装的设备（包括程序） ；或 可用以访问信息通信技术系统的全部或任何部分的密码、访问凭证、电子签名或类似数据；意图将该设备（包括程序）或密码、访问凭证、电子签名或类似数据用于实施根据本公约第七条至第十条确立的任何犯罪行为；以及\n㈡ 持有本条第一款第\n㈠项第 1 或第 2 目所述物项，意图将其用于实施根据本公约第七条至第十条确立的任何犯罪行为。 二、 如果本条第一款所述的获取、制作、销售、采购以供使用、进口、分销或以其他方式提供或持有等行为并非为了实施根据本公约第七条至第十条确立的犯罪行为，而是为了诸如经授权测试或保护信息通信技术系统等目的，则本条不得解释为对其追究刑事责任。\n三、 各缔约国均可保留不适用本条第一款的权利，但这一保留不得涉及销售、分销或以其他方式提供本条第一款第\n㈠项第 2 目所述物项。\n第十二条 与信息通信技术系统有关的伪造\n一、 各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意实施的以下行为规定为刑事犯罪 行为：输入、更改、删除或抑制电子数据，造成不真实的数据，意图使其在合法用途中被当作真实数据来考虑或作为行动依据，而不论该数据是否可直接读取和理解。\n二、 缔约国可规定须存在欺诈意图或类似不诚实意图或犯罪意图才能对之追究刑事责任。\n第十三条 与信息通信技术系统有关的盗窃或欺诈 各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意使用以下手段造成他人财产损失的行为规定为刑事犯罪行为：\n㈠ 以任何方式输入、更改、删除或抑制电子数据；\n㈡ 对信息通信技术系统运行的任何干扰；\n㈢ 通过信息通信技术系统做出任何与真实情况不符的欺骗行为，致使某人做出其原本不会做的或未做出其原本会做的任何事情；存有欺诈或不诚实意图，意欲为自己或他人谋取其本无权获取的金钱或其他财产收益。\n第十四条 涉及网上儿童性虐待或儿童性剥削材料的犯罪\n一、 各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意实施的以下行为规定为刑事犯罪行为：\n㈠ 通过信息通信技术系统制作、主动提供、出售、分销、传送、广播、展示、发布或以其他方式提供儿童性虐待或儿童性剥削材料；\n㈡ 通过信息通信技术系统索取、获取或访问儿童性虐待或儿童性剥削材料；\n㈢ 持有或控制存储在信息通信技术系统或其他存储介质中的儿童性虐待或儿童性剥削材料；\n㈣ 资助根据本款第\n㈠至第\n㈢项确立的犯罪行为的，缔约国可将之单独规定为一类犯罪。\n二、 就本条而言， “儿童性虐待或儿童性剥削材料 ”一语应当包括视觉材料，亦可包括书面内容或音频内容，其中描绘、描述或呈现任何未满十八岁的人：\n㈠ 从事真实或模拟的性活动；\n㈡ 所处现场有正在从事任何性活动的人；\n㈢ 主要为性目的展示性器官；或\n㈣ 遭受酷刑或残忍、不人道或有辱人格的待遇或惩罚，且此类材料具有性的性质。\n三、 缔约国可要求本条第二款所指材料仅限于以下材料：\n㈠ 描绘、描述或呈现某一现实中存在的人；或\n㈡ 以视觉方式描绘儿童性虐待或儿童性剥削。\n四、 缔约国可根据本国法律并依照适用的国际义务采取措施，排除对下列行为的刑事定罪：\n㈠ 儿童为自制那些描绘他们的材料而实施的行为；或\n㈡ 在所涉人员同意的情况下制作、传播或持有本条第二款第\n㈠项至第\n㈡项所述材料的行为，前提是所描绘的行为根据本国法律系属合法行为，且此类材料完全仅供所涉人员私下和同意的情况下使用。\n五、 本公约的任何规定均不得影响更有利于实现儿童权利的任何国际义务。\n第十五条 为对儿童实施性犯罪而进行教唆或诱骗\n一、 各缔约国均应采取必要的立法措施和其他措施，在本国法律中将故意实施的以下行为规定为刑事犯罪行为：为实施本国法律所界定的对儿童的性犯罪，包括为实施根据本公约第十四条确立的任何犯罪，通过信息通信技术系统进行通信联络、教唆、诱骗或做出任何安排。\n二、 缔约国可规定须有在本条第一款所述行为基础上的更进一步行动。\n三、 缔约国可考虑将本条第一款规定的刑事定罪范围扩大到包括被认为是儿童的人。\n四、 缔约国可采取措施，排除对由儿童实施的本条第一款所述行为进行刑事定罪。\n第十六条 未经同意传播私密图像\n一、 各缔约国均应采取必要的立法措施和其他措施，在本国法律中将没有相关权限而故意实施的以下行为规定为刑事犯罪行为：使用信息通信技术系统出售、分销、传送、发布或以其他方式提供某人的私密图像，而未经图像中所描绘的人同意。\n二、 就本条第一款而言， “私密图像”系指以包括照片或录像在内的任何方式对一个年满十八岁的人进行的具有性性质的视觉记录，其中该人的性器官暴露在外，或该人正在进行性活动，这些行为在进行记录时皆属个人隐私，而且在犯罪实施时被描绘者(一人或多人)对其隐私受保护仍保持合理期望。\n三、 缔约国可酌情将私密图像的定义扩至所描绘的对象包含根据本国法律已达到性活动法定年龄但未满十八岁者，且图像中未描绘对儿童的虐待或剥削。\n四、 就本条而言，私密图像中描绘的未满十八岁者不具备同意传播构成本公约第十四条所述儿童性虐待或儿童性剥削材料的私密图像的能力。\n五、 缔约国可规定须有造成伤害的意图才能追究刑事责任。\n六、 缔约国可根据本国法律并依照适用的国际义务，就与本条有关的事项采取其他措施。\n第十七条 对犯罪所得的洗钱行为\n一、 各缔约国均应根据本国法律的基本原则采取必要的立法措施和其他措施，将故意实施的以下行为规定为刑事犯罪行为：\n㈠ 1. 明知财产为犯罪所得，为隐瞒或掩饰此类财产的非法来源，或为协助参与实施上游犯罪的任何人逃避其行为的法律后果而转换或转移该财产；\n2. 明知财产为犯罪所得而隐瞒或掩饰此类财产的真实性质、来源、所在地、处置、转移、所有权或与此类财产有关的权利；\n㈡ 在符合本国法律制度基本概念的情况下：\n在得到财产时，明知其为犯罪所得而仍获取、占有或使用； 参与、协同或共谋实施，实施未遂，以及协助、教唆、便利和参谋实施根据本条确立的任何犯罪。 二、 为施行或适用本条第一款：\n㈠ 各缔约国均应将根据本公约第七至第十六条确立的相关犯罪列为上游犯罪；\n㈡ 缔约国立法中如果列出具体上游犯罪清单，则至少应当在此类清单中列入根据本公约第七至第十六条确立的各种犯罪；\n㈢ 就本款第㈡项而言，上游犯罪应当包括在有关缔约国法域之内和之外实施的犯罪。然而，如果犯罪是在一缔约国法域之外实施的，则只有当有关行为根据其发生地所在国的本国法律构成刑事犯罪，且根据施行或适用本条的缔约国的本国法律该行为若发生在该国亦构成刑事犯罪时，才构成上游犯罪；\n㈣ 各缔约国均应向联合国秘书长提供本国施行本条的法律副本以及随后对此类法律所作的任何修正的副本或相关说明；\n㈤ 如果缔约国本国法律的基本原则有此要求，则可规定本条第一款所列犯罪不适用于实施上游犯罪的人；\n㈥ 本条第一款所规定的作为犯罪要件的明知、故意或目的可根据客观实际情况予以推定。\n第十八条 法人责任\n一、 各缔约国均应采取符合本国法律原则的必要措施，确定法人参与根据本公约确立的犯罪所应承担的责任。\n二、 在不违反缔约国法律原则的情况下，法人责任可包括刑事责任、民事责任或行政责任。\n三、 法人责任不得影响实施此类犯罪的自然人的刑事责任。\n四、 各缔约国均应特别确保依照本条被追究责任的法人受到有效、适度和劝诫性的刑事或非刑事制裁，包括经济制裁。\n第十九条 参与和未遂\n一、 各缔约国均应采取必要的立法措施和其他措施，根据本国法律将故意实施的以下行为规定为刑事犯罪行为：以共犯、从犯或教唆犯等任何身份参与根据本公约确立的犯罪。\n二、 各缔约国均可采取必要的立法措施和其他措施，根据本国法律将故意实施根据本公约确立的犯罪的任何未遂行为规定为刑事犯罪行为。\n三、 各缔约国均可采取必要的立法措施和其他措施，根据本国法律将故意为实施根据本公约确立的犯罪做准备的行为规定为刑事犯罪行为。\n第二十条 追诉时效 各缔约国均应考虑到犯罪的严重性，酌情在 本国法律中规定一个较长的追诉时效期，以便在此期限内针对根据本公约确立的任何犯罪启动诉讼程序，并针对被指控犯罪者逃避司法处置的情况规定更长的追诉时效期或作出中止追诉时效的规定。\n第二十一条 起诉、审判和制裁\n一、 各缔约国均应使根据本公约确立的犯罪受到与其严重性相当的有效、适度而具有劝诫性的制裁。\n二、 各缔约国均可根据本国法律采取必要的立法措施和其他措施，针对根据本公约确立的犯罪确定加重情节，包括影响关键信息基础设施的情节。\n三、 各缔约国均应努力确保，为根据本公约确立的犯罪起诉某人时依据本国法律行使的任何法律裁量权，都是为了确保针对此类犯罪的执法措施取得最大成效，并适当考虑到震慑此类犯罪的必要性。\n四、 各缔约国均应确保因根据本公约确立的犯罪而被起诉的任何人都享有既符合本国法律又与适用于本国的国际义务相一致的一切权利和保障，包括得到公平审判的权利和辩护权。\n五、 就根据本公约确立的犯罪而言，各缔约国均应根据本国法律并在适当尊重被告的辩护权的情况下采取适当措施，力求确保针对审前释放裁决或上诉期间释放裁决规定的条件考虑到需要确保被告在后续的刑事诉讼中出庭。\n六、 各缔约国在考虑被判定犯有有关罪行的人员提前释放或假释的可能性时，均应考虑到此类犯罪的严重性。\n七、 缔约国应当确保根据本国法律采取适当的措施，依照《儿童权利公约》 及其各项适用的《议定书》以及其他适用的国际或区域文书所规定的义务，保护被控犯有根据本公约确立的罪行的儿童。\n八、 本公约的任何规定均不得影响下述原则，即根据本公约确立的犯罪和可 适用的法律辩护理由或决定行为合法性的其他法律原则，只应由缔约国本国的法律加以阐明，而且应当依照缔约国的本国法律对此类犯罪进行起诉和惩处。\n第三章 管辖权 第二十二条 管辖权\n一、 各缔约国均应在下列情况下采取必要措施，对根据本公约确立的犯罪确立管辖权：\n㈠ 犯罪发生在该缔约国领土内；或者\n㈡ 犯罪发生在犯罪时悬挂该缔约国国旗的船只上或已根据该缔约国法律注册的航空器内。\n二、 在不违反本公约第五条规定的情况下，缔约国还可在下列情况下对任何此类犯罪确立其管辖权：\n㈠ 犯罪系针对该缔约国的国民；或者\n㈡ 犯罪系由该缔约国国民或在该缔约国领土内有惯常居所的无国籍人实施；或者\n㈢ 犯罪系发生在该缔约国领土以外，且属于根据本公约第十七条第一款第\n㈡项第 2 目所确立的犯罪之一，其目的是在该缔约国领土内实施根据本公约第十七条第一款第\n㈠项第 1 目或第 2 目或第\n㈡项第 1 目确立的犯罪；或\n㈣ 犯罪系针对该缔约国。\n三、 为本公约第三十七条第十一款之目的，各缔约国均应采取必要措施，在被指控犯罪人位于其领土内且仅因该人系本国国民而不予引渡时，对根据本公约确立的犯罪确立本国的管辖权。\n四、 各缔约国还可采取必要措施，在被指控犯罪人位于本国领土内，且不引渡该人时，对根据本公约确立的犯罪确立本国的管辖权。\n五、 如果根据本条第一款或第二款行使管辖权的缔约国被告知或通过其他途径获悉任何其他缔约国正在对同一行为进行侦查、起诉或者司法程序，则这些缔约国的主管机关应当酌情相互磋商，以便协调行动。\n六、 在不影响一般国际法规范的情况下，本公约不排除缔约国行使其根据本国法律确立的任何刑事管辖权。\n第四章 程序措施和执法 第二十三条 程序措施的范围\n一、 各缔约国均应采取必要的立法措施和其他措施，确立本章所规定的权力和程序，以便进行具体的刑事侦查或诉讼。\n二、 除本公约另有规定者外，各缔约国均应将本条第一款所述权力和程序适用于：\n㈠ 根据本公约确立的刑事犯罪；\n㈡ 使用信息通信技术系统实施的其他刑事犯罪；以及\n㈢ 收集任何刑事犯罪的电子证据。\n三、 ㈠ 各缔约国均可保留将本公约第二十九条所述措施仅适用于保留声明中具体指明的犯罪或犯罪类别的权利，条件是这些犯罪或犯罪类别的涵盖范围不得小于缔约国适用本公约第三十条所述措施的犯罪的涵盖范围。各缔约国均应考虑限制此类保留的涵盖范围，以便使第二十九条所述各项措施能够得到最广泛的适用；\n㈡ 若缔约国因本公约通过时有效的本国法律所限，不能对服务提供者的信息通信技术系统内传输的通信适用本公约第二十九条和第三十条所述措施，而该系统：\n正在为一个封闭用户群的利益运行；而且 不使用公共通信网络，也不与另一公共或私人的信息通信技术系统连接；则该缔约国可保留不对此类通信适用上述措施的权利。各缔约国均应考虑限制此类保留的涵盖范围，以使本公约第二十九条和第三十条所述各项措施能够得到最广泛的适用。\n第二十四条 条件和保障措施 一、 各缔约国均应确保本章所规定的权力和程序的确立、实施和适用符合本国法律所规定的条件和保障措施；这些条件和保障措施应当按照本国在国际人权法下承担的义务保护人权，并应纳入比例原则。\n二、 此类条件和保障措施应根据和遵循各缔约国本国法律，视相关程序或权力的性质而定，包括司法审查或其他独立审查、获得有效救济的权利、适用理由以及对此类权力或程序的范围和期限的限制等。\n三、 在符合公共利益，特别是在符合正当司法的范围内，各缔约国均应考虑本章所规定的权力和程序对第三方权利、责任以及合法利益的影响。\n四、 根据本条确立的条件和保障措施应在缔约国国内适用于本章规定的权力和程序，既包括在国内进行刑事侦查和诉讼的权力和程序，也包括作为被请求缔约国提供国际合作的权力和程序。\n五、 本条第二款中提及的司法审查或其他独立审查是指国内一级的此类审查。\n第二十五条 快速保全存储的电子数据\n一、 各缔约国均应采取必要的立法措施和其他措施，使其主管机关得以下令或以类似方式责令快速保全使用信息通信技术系统存储的特定电子数据，包括流量数据、内容数据和订阅用户信息，特别是在有理由认为该电子数据极易丢失或被修改的情况下。\n二、 缔约国为执行本条第一款而下令某人保全其拥有或控制的所存储的特定电子数据时，应当为此采取必要的立法措施和其他措施，责成该人在最长不超过九十天的必要时限内，保全所涉电子数据 并维护其完整性，以便主管机关得以寻求披露这些数据。缔约国可规定此种命令嗣后可予延期。\n三、 各缔约国均应采取必要的立法措施和其他措施，责成保管人或其他负责保全电子数据的人员在本国法律规定的期限内对进行此类程序一事保守秘密。\n第二十六条 快速保全和部分披露流量数据 各缔约国均应针对根据本公约第二十五条的规定应予保全的流量数据采取必要的立法措施和其他措施，以便：\n㈠ 确保无论是一个还是多个服务提供者参与了通信的传输，均能快速保全流量数据；以及\n㈡ 确保向所涉缔约国的主管机关或该机关所指定人员快速披露足够数量的流量数据，以使该缔约国得以识别服务提供者，并识别所涉通信或所指信息的传输路径。\n第二十七条 提交令 各缔约国均应采取必要的立法措施和其他措施，授权本国主管机关下令：\n㈠ 位于本国领土内的某人提交其所拥有或控制的存储在信息通信技术系统或电子数据存储介质中的特定电子数据；以及\n㈡ 在本国领土内提供服务的服务提供者提交其所拥有或控制的与此类服务有关的订阅用户信息。\n第二十八条 搜查和扣押存储的电子数据\n一、 各缔约国均应采取必要的立法措施和其他措施，授权本国主管机关搜查或以类似方式访问位于本国领土内的：\n㈠ 信息通信技术系统、其一部分和存储在其中的电子数据；以及\n㈡ 可能存储所要查找的电子数据的存储介质。\n二、 各缔约国均应采取必要的立法措施和其他措施，以便确保，若其主管机关根据本条第一款第\n㈠项的规定搜查或以类似方式访问某一信息通信技术系统或其一部分时，有理由认为所查找的电子数据存储在位于本国领土内的另一信息通信技术系统或其一部分中，而且该等数据可从初始系统合法访问或可供初始系统合法取用，则应使此类主管机关得以快速进行搜查，以访问该 另一信息通信技术系统。\n三、 各缔约国均应采取必要的立法措施和其他措施，授权其主管机关扣押或以类似方式获取根据本条第一款或第二款访问的位于本国领土内的电子数据。这些措施应当包括以下权力：\n㈠ 扣押或以类似方式获取信息通信技术系统、其一部分或电子数据存储介质；\n㈡ 制作和保留电子数据的电子形式副本；\n㈢ 维护所存储的相关电子数据的完整性；\n㈣ 移除所访问的信息通信技术系统中的这些电子数据或使之无法访问。\n四、 各缔约国均应采取必要的立法措施和其他措施，授权其主管机关下令任何了解相关信息通信技术系统、信息和电信网络或其组成部分的运行、或了解为保护其中的电子数据而适用的措施的人员在合理情况下提供必要信息，以便能够采取本条第一款至第三款所述措施。\n第二十九条 实时收集流量数据\n一、 各缔约国均应采取必要的立法措施和其他措施，授权其主管机关采取下列行动：\n㈠ 在本国领土内应用技术手段实时收集或记录；以及\n㈡ 强令服务提供者在其现有的技术能力范围内：\n在本国领土内应用技术手段实时收集或记录；或者 配合并协助主管机关实时收集或记录；与其领土内使用信息通信技术系统传输的特定通信有关的流量数据。 二、 缔约国因其本国法律制度原则而无法采取本条第一款第\n㈠项所述措施的，可采取其他必要的立法措施和其他措施，确保在其领土内应用技术手段实时收集或记录与在其领土内传输的特定通信有关的流量数据。\n三、 各缔约国均应采取必要的立法措施和其他措施，责成服务提供者对本条规定的任何权力的行使情况以及与之相关的任何信息保守秘密。\n第三十条 拦截内容数据\n一、 各缔约国均应 采取必要的立法措施和其他措施 ，针对拟由本国法律确定的一系列严重刑事犯罪，授权其主管机关采取下列行动：\n㈠ 在本国领土内应用技术手段实时收集或记录；以及\n㈡ 强令服务提供者在其现有的技术能力范围内：\n在本国领土内应用技术手段实时收集或记录；或者 配合并协助主管机关实时收集或记录；在其领土内使用信息通信技术系统传输的特定通信的内容数据。 二、 缔约国因其本国法律制度原则而无法采取本条第一款第\n㈠项所述措施的，可采取必要的立法措施 和其他措施，确保在其领土内应用技术手段实时收集或记录其领土内特定通信的内容数据。\n三、 各缔约国均应采取必要的立法措施和其他措施，责成服务提供者对本条规定的任何权力的行使情况以及与之相关的任何信息保守秘密。\n第三十一条 冻结、扣押和没收犯罪所得\n一、 各缔约国均应在本国法律制度的范围内尽最大可能采取必要措施，以便得以没收：\n㈠ 根据本公约确立的犯罪所产生的犯罪所得或者价值与此类所得相当的财产；\n㈡ 在根据本公约确立的犯罪 中使用或预备使用 的财产、设备或者其他工具。\n二、 各缔约国均应采取必要措施，促成识别、追查、冻结或扣押本条第一款所述任何物项，以便最终予以没收。\n三、 各缔约国均应根据本国法律采取必要的立法措施和其他措施，规范主管机关对本条第一款和第二款涵盖的已冻结、扣押或没收的财产的管理。\n四、 如果犯罪所得已部分或全部转变或转化为其他财产，则应当以此类财产代替犯罪所得，适用本条所述措施。\n五、 如果犯罪所得已与从合法来源获得的财产相混合，则应当在不影响与冻结或扣押有关的任何权力的情况下没收该等财产，没收价值不超过混合于其中的犯罪所得的估定价值。\n六、 对于犯罪所得产生的、犯罪所得转变或者转化而成的财产产生的或者已经混合了犯罪所得的财产产生的收入或者其他收益，亦应适用本条所述措施，处置方式和程度与处置犯罪所得相同。\n七、 为本公约本条和第五十条之目的，各缔约国均应授权其法院或其他主管机关下令提供或扣押银行记录、财务记录或商业记录。缔约国不得以银行保密为由拒绝按照本款规定采取行动。\n八、 各缔约国均可考虑能否要求由犯罪人证明涉嫌犯罪所得或应予没收的其他财产具有合法来源，但此类要求应当符合本国法律原则以及司法程序和其他程序的性质。\n九、 不得对本条的规定作损害善意第三方权利的解释。\n十、 本条的任何规定均不得影响以下原则：即本条所述各项措施应当依照缔约国的本国法律规定予以界定和实施。\n第三十二条 建立犯罪记录 各缔约国均可采取必要的立法措施或其他措施，按其认为适宜的条件并为其认为适宜的目的，考虑别国此前对被指控犯罪人作出的任何有罪判决，以便在涉及根据本公约确立的犯罪的刑事诉讼中利用此类信息。\n第三十三条 保护证人\n一、 各缔约国均应根据本国法律并在力所能及的范围内采取适当措施，有效保护那些针对根据本公约确立的犯罪提供证言或本着善意和基于合理理由提供信息或以其他方式与侦查机关或司法机关配合的证人，并酌情有效保护其亲属和其他与其关系密切的人，以使他们免遭可能的报复或恐吓。\n二、 在无损于被告人包括其正当程序权在内的权利的情况下，本条第一款所述措施可特别包括：\n㈠ 制定向此类人员提供人身保护的程序，例如在必要和可行时将其转移，并在适当情况下允许不披露或限制披露有关其身份和行踪的资料；\n㈡ 制定允许证人以确保其安全的方式作证的取证规则，例如允许借助于视频链接等通信技术或其他适当手段提供证言。\n三、 缔约国应当考虑与其他国家订立有关转移本条第一款所述人员的协议或安排。\n四、 本条的规定亦应适用于作为证人的受害人。\n第三十四条 帮助和保护受害人\n一、 各缔约国均应在其力所能及的范围内采取适当措施，向根据本公约确立的犯罪的受害人提供帮助和保护，尤其是在其受到报复威胁或恐吓的情况下。\n二、 各缔约国均应在符合本国法律的情况下制定适当的程序，使根据本公约确立的犯罪的受害人有机会获得赔偿和补偿。\n三、 各缔约国均应在符合本国法律的情况下，在对犯罪人提起的刑事诉讼的适当阶段，以不损害犯罪人的辩护权的方式使受害人的意见和关切得到表达和考虑。\n四、 对于根据本公约第十四条至第十六条确立的犯罪，各缔约国均应在符合本国法律的情况下采取措施，与相关国际组织、非政府组织和其他民间社会团体合作，向此类犯罪的受害人提供帮助，包括使其身心得到康复。\n五、 各缔约国在适用本条第二款至第四款的规定时，均应考虑到受害人的年龄、性别以及特殊情况和需要，包括儿童的特殊情况和需要。\n六、 各缔约国均应在本国法律框架允许的限度内采取有效步骤，确保遵从关于移除本公约第十四条和第十六条中所指内容或使之无法访问的请求。\n第五章 国际合作 第三十五条 国际合作的一般原则\n一、 缔约国应当依照本公约的规定以及关于刑事事项国际合作的其他适用国际文书以及本国法律，为下列目的开展合作：\n㈠ 对根据本公约确立的刑事犯罪进行的侦查、起诉和与之相关的司法程序，包括对此类犯罪所得的冻结、扣押、没收和返还；\n㈡ 收集、获取、保全和共享根据本公约确立的刑事犯罪的电子证据；\n㈢ 收集、获取、保全和共享任何严重犯罪的电子证据，包括根据本公约通过时有效的其他适用的联合国公约和议定书所确立的严重犯罪。\n二、 按本条第一款第\n㈡项和第\n㈢项的规定收集、获取、保全和共享犯罪电子证据的，应当适用本公约第四十条有关款项以及第四十一至第四十六条。\n三、 在国际合作事项上，凡将双重犯罪视作一项条件的，如果在协助请求中所指的犯罪行为在请求缔约国和被请求缔约国的法律中均属刑事犯罪，则此项条件即应视作已得到满足，而不论这两个缔约国各自的法律是否均将此种犯罪列入相同的犯罪类别或者是否使用相同的术语指称此种犯罪。\n第三十六条 保护个人数据\n一、 ㈠ 缔约国在根据本公约转移个人数据时，应当遵守本国法律以及适用的国际法所规定的任何转移方义务。缔约国依照关于保护个人数据的有关法律不能提供个人数据的，不应要求该缔约国按照本公约转移个人数据；\n㈡ 个人数据转移不符合本条第一款第\n㈠项的，缔约国可根据适用法律寻求施加适当条件以实现合规性，以便对索取个人数据的请求作出回应；\n㈢ 鼓励缔约国订立双边或多边安排，以期便利个人数据的转移。\n二、 对于根据本公约转移的个人数据，缔约国应当确保所收到的个人数据在缔约国各自的法律框架内得到有效而适当的保障。\n三、 为能将根据本公约获得的个人数据转移到第三国或某一国际组织，缔约国应当将其意图通知原转移缔约国并请求其为此授权。缔约国只有在原转移缔约国予以授权的情况下才可转移此类个人数据，原转移缔约国可要求以书面形式提供此种授权。\n第三十七条 引渡\n一、 本条应当适用于根据本公约确立的刑事犯罪，条件是被请求引渡人位于被请求缔约国领土内，且寻求引渡所涉犯罪根据请求缔约国和被请求缔约国的本国法律均为可惩处的犯罪。如果请求引渡的目的是执行对可引渡犯罪判处的最终监禁或其他形式的拘禁，则被请求缔约国可依据本国法律准予引渡。\n二、 虽有本条第一款的规定，缔约国在本国法律允许的情况下，可准予引渡犯有根据本公约确立的任何刑事犯罪、但依照本国法律不予惩处的人员。\n三、 如果引渡请求包括几项独立的刑事犯罪，其中至少有一项犯罪可以依照本条规定予以引渡，而其中几项犯罪由于监禁期的原因不可引渡、但却与根据本公约确立的犯罪有关，则被请求缔约国也可对这些犯罪适用本条的规定。\n四、 本条适用的各项犯罪均应视作已列入缔约国之间现行任何引渡条约的可引渡犯罪。缔约国承诺将此类犯罪作为可引渡犯罪列入在它们之间将要缔结的每一项引渡条约。\n五、 以订有条约为引渡条件的缔约国，如果接到未与之订有引渡条约的另一缔约国的引渡请求，则可将本公约视为对本条所适用的任何犯罪予以引渡的法律依据。\n六、 以订有条约为引渡条件的缔约国应当：\n㈠ 在交存本公约的批准书、接受书、核准书或加入书时通知联合国秘书长，说明其是否将以本公约为法律依据与本公约其他缔约国进行引渡合作；并且\n㈡ 如其不以本公约作为引渡合作的法律依据，则在适当情况下寻求与本公约其他缔约国缔结引渡条约，以实施本条规定。\n七、 不以订有条约为引渡条件的缔约国应当承认本条所适用的犯罪为它们之间可以相互引渡的犯罪。\n八、 引渡应当符合被请求缔约国的本国法律或适用的引渡条约所规定的条件，其中包括与引渡的最低刑罚要求有关的条件以及被请求缔约国可据以拒绝引渡的理由。\n九、 对于本条所适用的任何犯罪，缔约国应当在符合本国法律的情况下，努力加快引渡程序并简化与之相关的证据要求。\n十、 被请求缔约国在不违背本国法律和引渡条约规定的情况下，可以在认定情况必要而且紧迫时，根据请求缔约国的请求，包括通过国际刑事警察组织现有渠道转交的 请求，拘留位于其领土内的被请求引渡人，或者采取其他适当措施，确保该人在进行引渡程序时在场。\n十一、 如果被指控罪犯被发现位于某一缔约国领土内而该国仅以该人系本国国民为理由不就本条所适用的犯罪予以引渡，则该国有义务在寻求引渡的缔约国提出请求时将该案提交本国主管机关以便进行起诉，而不得有任何不当延误。这些机关作出决定和进行诉讼程序的方式应当与根据该缔约国本国法律对性质相当的其他任何犯罪采用的方式相同。有关缔约国应当相互合作，特别是在程序和证据方面相互合作，以确保这些起诉的效率。\n十二、 如果缔约国本国法律允许引渡或移交本国国民的条件是，须将该人送还本国按照引渡或移交请求所涉审判或诉讼作出的判决服刑，且该缔约国和寻求引渡该人的缔约国均同意这一选择以及双方可能认为适宜的其他条件，则此种有条件的引渡或移交即足以解除该缔约国根据本条第十一款所承担的义务。\n十三、 如果为执行判决而提出的引渡请求因被请求引渡人员系被请求缔约国的国民而遭到拒绝，则被请求缔约国应当在本国法律允许且符合该法律的要求的情况下，根据请求缔约国的申请，考虑执行根据请求国本国法律判处的刑期或尚未服满的刑期。\n十四、 在对任何人员就本条所适用的任何犯罪提起诉讼时，应当确保其在诉讼的所有阶段得到公平待遇，包括享有其所在缔约国本国法律所提供的一切权利和保障。\n十五、 如果被请求缔约国有充分理由认为提出引渡请求是为了以某人的性别、种族、语言、宗教、国籍、族裔或政治观点为由对其进行起诉或惩处，或如果执行该请求将会使该人的地位因上述任一原因而受到损害，则本公约的任何 规定均不得解释为强制规定了引渡义务。\n十六、 缔约国不得仅以犯罪亦被视为涉及财税事项为由而拒绝引渡请求。\n十七、 被请求缔约国在拒绝引渡之前应当酌情与请求缔约国磋商，以使其有充分机会陈述自己的意见和提供与其指控有关的资料。\n十八、 被请求缔约国应当将其关于引渡的决定通知请求缔约国。被请求缔约国应告知请求缔约国拒绝引渡的任何理由，除非被请求缔约国的本国法律或其国际法律义务不允许其作出此种告知。\n十九、 各缔约国均应在签署本公约时或在交存其批准书、接受书、核准书或加入书时，告知联合国秘书长负责提出或接收引渡请求或临时逮捕请求的机关的名称和地址。秘书长应当建立并不断更新缔约国所指定的此类机关的登记册。各缔约国均应确保登记册上登记的详细信息始终正确无误。\n二十、 缔约国应当力求缔结双边和多边协定或安排，以执行引渡或加强引渡的成效。\n第三十八条 被判刑人员的移管 缔约国可考虑缔结双边或多边协定或安排，将因实施根据本公约确立的犯罪而被判处监禁或以其他形式被剥夺自由的人员移交其本国服满刑期，同时考虑到被判刑人员的权利。缔约国还可考虑与此类人员的意愿、改造和重返社会有关的问题。\n第三十九条 刑事诉讼的移交\n一、 如果缔约国认为移交诉讼有利于正当司法，特别是在涉及数国管辖权时，为了进行集中起诉，应当考虑相互移交诉讼的可能性，以便对根据本公约确立的犯罪进行刑事诉讼。\n二、 以订有条约为移交刑事诉讼条件的缔约国，如果收到未与之在此事项上订有条约的另一缔约国的移交请求，可以本公约为法律依据移交对本条所适用的任何犯罪的刑事诉讼。\n第四十条 司法协助的一般原则和程序\n一、 缔约国应当在与根据本公约确立的犯罪有关的侦查、起诉和司法程序中，以及在收集根据本公约确立的犯罪和其他严重犯罪的电子证据方面，相互提供最广泛的司法协助。\n二、 对于请求缔约国根据本公约第十八条可能追究法人责任的犯罪进行的侦查、起诉和司法程序，应当根据被请求缔约国的有关法律、条约、协定和安排，尽可能充分地提供司法协助。\n三、 可为下列任何目的请求根据本条提供司法协助：\n㈠ 向个人获取证据或陈词；\n㈡ 送达司法文书；\n㈢ 执行搜查和扣押，以及冻结；\n㈣ 根据本公约第四十四条搜查或以类似方式访问、扣押或以类似方式获取和披露使用信息通信技术系统存储的电子数据；\n㈤ 根据本公约第四十五条实时收集流量数据；\n㈥ 根据本公约第四十六条拦截内容数据；\n㈦ 检查物品和场所；\n㈧ 提供资料、证据以及专家鉴定意见；\n㈨ 提供有关文件和记录的原件或经核证的副本，其中包括政府、银行、财务、公司或业务的记录；\n㈩ 为取证目的而辨认或追查犯罪所得、财产、工具或其他物项；(十一) 为有关人员自愿前往请求缔约国出庭提供方便；(十二) 追回犯罪所得；(十三) 不违反被请求缔约国本国法律的任何其他类型的协助。\n四、 缔约国主管机关如认为与刑事事项有关的资料可能有助于另一缔约国主管机关进行或顺利完成调查和刑事诉讼程序，或可以促成该另一缔约国根据本公约提出请求，则可在不违反本国法律的情况下，无需事先请求而向该缔约国主管机关传送此类资料。\n五、 根据本条第四款传送资料时，不应当影响提供资料的主管机关所属国的侦查和刑事诉讼程序。接收资料的主管机关应当遵守对该资料进行保密的要求，即便是暂时予以保密，或遵守对资料的使用的限制规定。但这不应妨碍接收方缔约国在其诉讼中披露可证明被控告人无罪的资料。在此种情况下，接收方缔约国应当在披露之前通知提供方缔约国，而且，如有要求，还应当就此与提供方缔约国进行协商。如果在特殊情况下无法事先通知，则接收方缔约国应当毫不迟延地将披露一事通报提供方缔约国。\n六、 本条各项规定概不影响规范或将要规范整个或部分司法协助事宜的任何其他双边或多边条约所规定的义务。\n七、 如果有关缔约国无司法协助条约的约束，则本条第八款至第三十一款应当适用于根据本条提出的请求。如果有关缔约国有此类条约的约束，则适用条约的相应条款，除非这些缔约国同意代之以适用本条第八款至第三十一款。大力鼓励缔约国在这几款有助于开展合作时予以适用。\n八、 缔约国可以不构成双重犯罪为由拒绝依照本条提供协助。但被请求缔约国可在其认为适当时在其斟酌决定的范围内提供协助，而不论所涉行为按被请求缔约国本国法律是否构成犯罪。如果请求所涉事项性质极为轻微或所寻求的合作或协助可以依照本公约其他条款获得，则被请求缔约国可拒绝提供协助。\n九、 在一缔约国领土内被羁押或服刑的人员，如果被要求前往另一缔约国进行辨认、作证或者提供其他协助，以便为与根据本公约确立的犯罪有关的侦查、起诉或者司法程序获取证据，则在满足下列条件的情况下，可予以移送：\n㈠ 该人在知情后自由表示同意；\n㈡ 双方缔约国主管机关均同意，但须符合这些缔约国认为适当的条件。\n十、 就本条第九款而言：\n㈠ 该人被移送前往的缔约国应当有权力和义务羁押被移送人，除非移送缔约国另有要求或授权；\n㈡ 该人被移送前往的缔约国应当毫不迟延地履行义务，按照双方缔约国主管机关事先达成的协议或其他协议，将该人交还移送缔约国羁押；\n㈢ 该人被移送前往的缔约国不得要求移送缔约国为该人的交还而启动引渡程序；\n㈣ 被移送人在被移送前往的缔约国的羁押时间应当折抵其在移送国执行的刑期。\n十一、 除非依照本条第九款和第十款移送某人的缔约国同意，否则无论该人国籍为何，均不得因其离开被请求缔约国之前的作为、不作为或被定罪而在请求缔约国领土内被起诉、羁押、处罚，或在其自由方面受到任何其他限制。\n十二、 ㈠ 各缔约国均应指定一个或多个中央机关，由其负责且有权接收司法协助请求并执行请求或将请求转交主管机关执行。如果缔约国有实行单独司法协助制度的特区或者领土，则可为该特区或领土另外指定一个具有同样职能的中央机关；\n㈡ 中央机关应当确保所收到的请求得到迅速而妥善的执行或转交。中央机关在将请求转交某一主管机关执行时，应鼓励该主管机关迅速而妥善地执行请求；\n㈢ 各缔约国均应在交存本公约的批准书、接受书、核准书或加入书时将为此目的指定的中央机关通知联合国秘书长；秘书长应建立并不断更新缔约国所指定的中央机关登记册。各缔约国均应确保登记册上登记的详细信息始终正确无误；\n㈣ 司法协助请求以及与之相关的任何函件均应递交缔约国指定的中央机关。此项规定不得损害缔约国要求通过外交渠道以及在紧急和可能的情况下经有关缔约国同意通过国际刑事警察组织向其传送此种请求和函件的权利。\n十三、 请求应当以被请求缔约国所能接受的语文以书面形式提出，或在可能情况下以能够生成书面记录的任何手段提出，但须能使该缔约国得以鉴定其真实性。各缔约国均应在交存本公约的批准书、接受书、核准书或者加入书时将其所能接受的一种或多种语文通知联合国秘书长。在紧急情况下，如经有关缔约国同意，请求可采用口头方式提出，但应立即加以书面确认。\n十四、 鼓励缔约国中央机关在本国法律未予禁止的情况下，以电子形式传送和接收司法协助请求书、与之相关的函件以及证据，但条件是须允许被请求缔约国确定其真实性并确保通讯安全。\n十五、 司法协助请求书中应当列明如下各项：\n㈠ 提出请求的机关；\n㈡ 请求所涉及的侦查、起诉或司法程序的事由和性质，以及负责进行该项侦查、起诉或司法程序的机关的名称和职能；\n㈢ 有关事实的概述，但为送达司法文书提出的请求除外；\n㈣ 说明所请求的协助以及请求缔约国希望得到遵循的特定程序细节；\n㈤ 在可能且适当的情况下，任何有关人员的身份、所在地和国籍，以及任何有关物项或账户的来源国、说明和所在地；\n㈥ 在适用情况下，请求提供证据、资料或其他协助的时间段；以及\n㈦ 请求提供证据、资料或其他协助的目的。\n十六、 被请求缔约国可要求提供按照其 本国法律执行该请求所必需的或有助于执行该请求的补充资料。\n十七、 请求应根据被请求缔约国本国法律执行，在不违反被请求缔约国本国法律的情况下，如有可能，应当遵循请求书中所列明的程序执行。\n十八、 当位于某一缔约国领土内的某人需作为证人、受害人或鉴定专家接受另一缔约国司法机关询问，且该人不可能或不宜亲身前往请求缔约国领土内时，被请求缔约国可根据该另一缔约国的请求，在可能且符合其本国法律的基本原则的情况下，允许以视频会议方式进行询问。缔约国可商定由请求缔约国司法机关进行询问，且询问时应有被请求缔约国司法机关在场。如果被请求缔约国无法获得举行视频会议所需的技术手段，则可共同商定由请求缔约国提供此种手段。\n十九、 未经被请求缔约国事先同意，请求缔约国不得将被请求缔约国提供的资料或证据转交或用于请求书所述以外的侦查、起诉或司法程序。本款中的任何规定均不妨碍请求缔约国在其诉讼中披露可证明被告人无罪的资料或证据。就后一种情形而言，请求缔约国应当在予以披露之前通知被请求缔约国，并依请求与被请求缔约国磋商。如在特殊情况下无法事先通知，则请求缔约国应当毫不迟延地将披露一事通告被请求缔约国。\n二十、 请求缔约国可要求被请求缔约国对其所提出的请求及其内容予以保密，但为执行请求所必需时除外。如果被请求缔约国不能遵守保密要求，则应当立即就此通知请求缔约国。\n二十一、 在下列情形中可拒绝提供司法协助：\n㈠ 请求未按本条的规定提出；\n㈡ 被请求缔约国认为执行请求可能损害其主权、安全、公共秩序或其他基本利益；\n㈢ 假如被请求缔约国主管机关依其管辖权对任何类似犯罪进行侦查、起诉或司法程序，其本国法律将会禁止该主管机关对此类犯罪采取被请求的行动；\n㈣ 若同意此种请求，将会违反被请求缔约国关于司法协助的法律制度。\n二十二、 如果被请求缔约国有充分理由认为提出请求是为了以某人的性别、种族、语言、宗教、国籍、族裔或政治观点为由对其进行起诉或惩处，或认为满足该请求将使该人的地位因上述任一原因而受到损害，则本公约的任何规定均不得解释为强制规定了提供司法协助的义务。\n二十三、 缔约国不得仅以犯罪亦被视为涉及财税事项为由而拒绝司法协助请求。\n二十四、 缔约国不得以银行保密为由拒绝根据本条提供司法协助。\n二十五、 拒绝司法协助时应当说明理由。\n二十六、 被请求缔约国应当尽快执行司法协助请求，并应尽可能充分考虑到请求缔约国提出的、最好能在请求中说明了理由的任何最后期限。被请求缔约国应当依请求缔约国的合理要求就请求的当前状态及其处理请求的进展情况作出答复。请求缔约国应当在其不再需要被请求国提供所寻求的协助时迅速通知被请求缔约国。\n二十七、 被请求缔约国可以司法协助会妨碍正在进行的侦查、起诉或司法程序为由而暂缓执行。\n二十八、 在根据本条第二十一款拒绝某项请求或根据本条第二十七款暂缓执行请求事项之前，被请求缔约国应当与请求缔约国协商，考虑是否可在其认为必要的条款和条件下给予协助。请求缔约国如果接受附有条件限制的协助，则应遵守这些条件。\n二十九、 在不影响适用本条第十一款的情况下，根据请求缔约国的请求而同意前往请求缔约国领土内就某项诉讼作证或为某项侦查、起诉或司法程序提供协助的证人、鉴定专家或其他人员，不得因其离开被请求缔约国之前的作为、不作为或定罪而在请求缔约国领土内被起诉、羁押、处罚，或在其自由方面受到任何其他限制。如该证人、鉴定专家或其他人员已得到司法机关不再需要其到场的正式通知，在自通知之日起连续十五天内或在所涉缔约国所商定的任何期限内，有机会离开但仍自愿留在请求缔约国领土内，或在离开该领土后又自愿返回，则此项安全通行权即不再有效。\n三十、 除非所涉缔约国另有协议，执行请求的一般费用应当由被请求缔约国承担。如执行请求需要或将需要支付大笔或特殊性质的费用，则应由这些缔约国进行协商，以确定执行相关请求的条款和条件以及费用承担办法。\n三十一、 被请求缔约国：\n㈠ 应当向请求缔约国提供其所拥有的、依其本国法律可向公众公开的政府记录、文件或资料的副本；\n㈡ 可自行斟酌决定全部或部分地或按其认为适当的条件向请求缔约国提供其所拥有的、依其本国法律不可向公众公开的任何政府记录、文件或资料的副本。\n三十二、 缔约国应视需要考虑能否缔结有助于实现本条之目的、具体实施或旨在加强本条各项规定的双边或多边协定或安排。\n第四十一条 7 天 24 小时全天候网络\n一、 各缔约国均应指定一个每周 7 天、每天 24 小时开放的联络点，以确保为就根据本公约确立的犯罪的具体刑事侦查、起诉或司法程序提供即时协助，或为本条第三款之目的以及就根据本公约确立的犯罪和其他严重犯罪即时协助收集、获取、保全电子证据。\n二、 应将此种联络点通知联合国秘书长，秘书长应保存一份为本条目的指定的联络点的最新登记册，并应每年向缔约国分发经过更新的联络点名册。\n三、 此种协助应当包括促进或在被请求缔约国的本国法律和惯例允许的情况下直接采取以下措施：\n㈠ 提供技术咨询；\n㈡ 依照本公约第四十二条和第四十三条保全所存储的电子数据，酌情包括被请求缔约国掌握的服务提供者所在地信息，以协助请求缔约国提出协助请求；\n㈢ 收集证据和提供法律信息；\n㈣ 确定嫌疑人所在地；或\n㈤ 提供电子数据以防发生紧急情况。\n四、 缔约国的联络点应当有能力与另一缔约国的联络点进行快捷通信联络。若缔约国所指定的联络点不隶属于该缔约国负责司法协助或引渡事宜的一个或多个机关，则该联络点应当确保能够快捷地与此类机关进行协调。\n五、 各缔约国均应确保能够提供训练有素且装备齐全的人员，以确保 7 天 24 小时全天候网络的运作。\n六、 缔约国亦可在本国法律的限度内酌情利用和加强现有经授权的联络点网络，包括国际刑事警察组织的用于开展警方之间快捷合作的 7 天 24 小时全天候计算机相关犯罪问题网络以及其他信息交流合作办法。\n第四十二条 快速保全存储的电子数据方面的国际合作\n一、 一缔约国有意提出司法协助请求以搜查或以类似方式访问、扣押或以类似方式获取或披露在另一缔约国领土内使用信息通信技术系统存储的电子数据的，可请该另一缔约国根据本公约第二十五条下令或以其他方式实现快速保全该电子数据。\n二、 请求缔约国可利用本公约第四十一条规定的 7 天 24 小时全天候网络，查找使用信息通信技术系统存储的电子数据所在地信息，并酌情查找服务提供者所在地信息。\n三、 根据本条第一款提出的保全请求应当具体说明：\n㈠ 寻求保全的机关；\n㈡ 作为刑事侦查、起诉或司法程序事由的犯罪以及对相关事实的简要概述；\n㈢ 拟予保全的已存储电子数据及其与犯罪之间的关系；\n㈣ 所掌握的用以识别存储的电子数据保管人身份或信息通信技术系统所在位置的任何信息；\n㈤ 进行保全的必要性；\n㈥ 请求缔约国有意提交司法协助请求，以搜查或以类似方式访问、扣押或以类似方式获取或者披露所存储的电子数据；\n㈦ 酌情说明需要对保全请求保密且不通知所涉用户。\n四、 被请求缔约国收到另一缔约国的请求后，应当根据本国法律采取一切适当措施，快速保全所指定的电子数据。在回应请求时，被请求缔约国不得以构成双重犯罪作为提供此种保全的条件。\n五、 缔约国要求以双重犯罪为条件才能回应关于搜查或以类似方式访问、扣押或以类似方式获取或披露所存储的电子数据的司法协助请求的，对于根据本公约所确立犯罪以外的犯罪，如果有理由认为披露时无法满足双重犯罪的条件，则可保留拒绝根据本条提出的保全请求的权利。\n六、 此外，只能根据本公约第四十条第二十一款第\n㈡和第\n㈢项以及第二十二款所列述的理由拒绝保全请求。\n七、 如果被请求缔约国认为实行保全将无法确保相关数据今后可用，或将威胁到请求缔约国侦查工作的保密性，或将以其他方式妨碍请求缔约国进行的侦查，则该缔约国应当立即将此情况通知请求缔约国，由请求缔约国随后决定是否仍然执行该请求。\n八、 按本条第一款所述请求实行的任何保全应当维持一个不短于六十天的时期，以便使请求缔约国得以提出请求搜查或以类似方式访问、扣押或以类似方式获取或披露相关数据。被请求缔约国在收到此种请求后，应当在就该请求作出决定之前继续保全所涉数据。\n九、 在本条第八款规定的保全期限届满之前，请求缔约国可请求延长保全期限。\n第四十三条 快速披露所保全的流量数据方面的国际合作\n一、 被请求缔约国在执行根据本公约第四十二条提出的保全某一特定通信相关流量数据的请求过程中，若发现另一缔约国的服务提供者参与了该通信的传输，则应迅速向请求缔约国披露足够的流量数据以识别该服务提供者和通信传输路径。\n二、 只能根据本公约第四十条第二十一款第\n㈡项和第\n㈢项以及第二十二款所列述的理由拒绝按本条第一款的规定披露流量数据。\n第四十四条 访问存储的电子数据方面的司法协助\n一、 一缔约国可请求另一缔约国搜查或以类似方式访问、扣押或以类似方式获取并披露使用位于被请求缔约国领土内的信息通信技术系统存储的电子数据 ，包括根据本公约第四十二条保全的电子数据。\n二、 被请求缔约国应当适用本公约第三十五条所述相关国际文书和法律，并根据本章其他相关规定，对此种请求作出回应。\n三、 在下列情况下，应当迅速对请求作出回应：\n㈠ 有理由认为相关数据特别容易丢失或被修改；或\n㈡ 本条第二款中提及的文书和法律对加快合作另有规定。\n第四十五条 实时收集流量数据方面的司法协助\n一、 缔约国应当努力相互提供司法协助，实时收集与本国领土内 使用信息通信技术系统传输的某些指定通信有关的流量数据。在不违反本条第二款规定的情况下，此种协助应受本国法律规定的条件和程序制约。\n二、 各缔约国均应努力至少针对在本国内类似案件中可实时收集流量数据的刑事犯罪提供此种协助。\n三、 根据本条第一款提出的请求应当具体说明：\n㈠ 提出请求的机关名称；\n㈡ 与请求有关的侦查、起诉或司法程序的主要事实和性质概述；\n㈢ 要求收集的流量数据所涉及的电子数据及其与相关犯罪行为之间的关系；\n㈣ 所掌握的用以识别数据所有人或用户身份或信息通信技术系统所在地的任何数据；\n㈤ 要求收集流量数据的理由；\n㈥ 拟收集流量数据的期间及相应的理由。\n第四十六条 拦截内容数据方面的司法协助 缔约国应当在对其适用的条约或本国法律允许的范围内，彼此努力提供司法协助，以实时收集或记录使用信息通信技术系统传输的特定通信的内容数据。\n第四十七条 执法合作\n一、 缔约国应当在符合本国法律制度和行政管理制度的情况下相互密切合作，以期加强打击根据本公约确立的犯罪的执法行动成效。缔约国尤其应当采取有效措施，以便：\n㈠ 加强并于必要时建立其主管机关、机构和部门之间的联络渠道，同时考虑到国际刑事警察组织的渠道等现有渠道，以促进安全而迅速地交换有关根据本公约确立的犯罪的各方面信息，在有关缔约国认为适当时还可包括与其他犯罪活动的关联的信息；\n㈡ 同其他缔约国合作，就与根据本公约确立的犯罪有关的以下事项进行调查：\n参与此类犯罪的嫌疑人的身份、行踪和活动，或其他有关人员的所在地； 源自此类犯罪的犯罪所得或财产的去向； 用于或企图用于实施此类犯罪的财产、设备或其他工具的去向；\n㈢ 酌情提供必要的物项或数据以供分析或侦查之用；\n㈣ 酌情与其他缔约国交流关于为实施根据本公约确立的犯罪而采用的具体手段和方法的信息，包括利用虚假身份、经伪造、变造或者假冒的证件和其他掩饰的手段以及网络犯罪伎俩、技术和程序诸方面的信息；\n㈤ 便利在各缔约国主管机关、机构和部门之间开展有效协调，并促进 交流人员和其他专家，包括在符合有关缔约国之间的双边协定或安排的情况下派驻联络官员；\n㈥ 为尽早查明根据本公约确立的犯罪而酌情交流信息和协调所采取的行政措施及其他措施。 二、 为实施本公约，缔约国应当考虑订立其执法机构间直接合作的双边或多边协定或安排；已有此类协定或安排的，应当考虑加以修订。如果有关缔约国之间没有此类协定或安排，则可考虑以本公约为依据，针对根据本公约确立的犯罪开展执法合作。在适当情况下，缔约国应当充分利用各种协定或安排，包括利用国际组织或区域组织，以加强执法机构之间的合作。\n第四十八条 联合侦查 缔约国应当考虑缔结双边或多边协定或安排，以便有关主管机关可据以就根据本公约确立的，且在一国或多国成为刑事侦查、起诉或司法程序对象的犯罪建立联合侦查机构。如无此类协定或安排，则可在个案基础上商定开展联合侦查。拟在一缔约国领土内开展此类侦查的，相关缔约国应当确保该缔约国的主权得到充分尊重。\n第四十九条 通过没收事宜国际合作追回财产的机制\n一、 为根据本公约第五十条针对通过实施或参与实施 根据本公约确立的犯罪而获得的财产提供司法协助，各缔约国均应根据本国法律：\n㈠ 采取必要措施，准许本国主管机关执行另一缔约国法院签发的没收令；\n㈡ 采取必要措施，准许本国拥有管辖权的主管机关通过对洗钱罪或可能在其管辖范围内的其他犯罪作出判决，或者经由本国法律许可的其他程序，下令没收外国来源的此类财产；以及\n㈢ 考虑采取必要措施，允许在因为犯罪人死亡、潜逃或者缺席而无法对其进行起诉的情形或者其他适当情形下，不经过刑事定罪而没收此类财产。\n二、 为针对依照本公约第五十条第二款提出的请求提供司法协助，各缔约国均应根据本国法律：\n㈠ 采取必要措施，准许本国主管机关根据请求缔约国的法院或主管机关发出的冻结令或扣押令冻结或扣押财产，但条件是该冻结令或扣押令须提供合理的依据，使被请求缔约国相信有充足理由采取此种行动，并且相信有关财产最终将依照本条第一款第\n㈠项所述的没收令予以处理；\n㈡ 采取必要措施，准许本国主管机关根据请求冻结或扣押财产，但条件是该请求须提供合理的依据，使被请求缔约国相信有充足理由采取此种行动，并且相信有关财产最终将依照本条第一款第\n㈠项所述的没收令予以处理；以及\n㈢ 考虑采取额外措施，准许本国主管机关诸如根据外国实行的与财产的获取有关的逮捕或刑事指控等，对此类财产进行保全，以便予以没收。\n第五十条 没收事宜的国际合作\n一、 缔约国在收到对根据本公约确立的一项犯罪拥有管辖权的另一缔约国关于没收本公约第三十一条第一款所述位于其领土内的犯罪所得、财产、设备或其他工具的请求后，应当在本国法律制度的范围内尽最大可能：\n㈠ 将该请求提交本国主管机关，以便获取没收令并在获取没收令后予以执行；或\n㈡ 将请求缔约国的法院根据本公约第三十一条第一款签发的没收令提交本国主管机关，以便按请求的范围予以执行，只要该没收令涉及的犯罪所得、财产、设备或其他工具位于被请求缔约国领土内。\n二、 被请求缔约国应当按照对根据本公约确立的一项犯罪拥有管辖权的另一缔约国提出的请求采取措施，辨认、追查和冻结或扣押本公约第三十一条第一款所述的犯罪所得、财产、设备或其他工具，以便最终由请求缔约国下令或由被请求缔约国根据本条第一款依照请求下令予以没收。\n三、 本公约第四十条的规定经适当变通后可适用于本条。根据本条提出的请求除应包括本公约第四十条第十五款所规定的资料外，还应包括以下内容：\n㈠ 与本条第一款第\n㈠项有关的请求，应当包括对应予没收的财产的说明，尽可能包括财产的所在地，酌情包括对财产的估计价值，以及对请求缔约国所依据的事实的充分陈述，以便被请求缔约国得以根据本国法律申请没收令；\n㈡ 与本条第一款第\n㈡项有关的请求，应当包括请求缔约国签发的据以提出请求的、法律上可以采信的没收令副本、与请求所述没收令执行范围有关的事实和信息陈述、关于请求缔约国为向善意第三方提供充分通知并确保正当程序而采取的措施的具体陈述，以及关于该没收令已不可更改的声明；\n㈢ 与本条第二款有关的请求，应当包括对请求缔约国所依据的事实的陈述和对所请求采取的行动的说明；如有据以提出请求的、法律上可以采信的没收令副本，应当一并附上。\n四、 被请求缔约国依照本条第一款和第二款作出的决定或采取的行动，应当符合且遵循本国法律及程序规则的规定，或符合且遵循可能在与请求缔约国有关的事项上对其具有约束力的任何双边或多边条约、协定或安排的规定。\n五、 各缔约国均应向联合国秘书长提供本国实施本条的法律法规的副本，以及此类法律法规随后的任何修订的副本或相关说明。\n六、 缔约国选择以订有相关条约为条件采取本条第一款和第二款所述措施的，应当将本公约视为必要而充分的条约依据。\n七、 如果被请求缔约国未收到充分和及时的证据，或者如果财产的价值极其轻微，也可拒绝给予本条所规定的合作，或者解除临时措施。\n八、 在解除依照本条采取的任何临时措施之前，如有可能，被请求缔约国应当给予请求缔约国机会说明继续保持该措施的理由。\n九、 不得对本条规定作损害善意第三方权利的解释。\n十、 缔约国应当考虑缔结双边或多边条约、协定或安排，以提高根据本条开展的国际合作的成效。\n第五十一条 特别合作 在不违反本国法律的情况下，各缔约国均应努力采取措施，以便在认为披露根据本公约确立的犯罪所得的资料可有助于接收资料的缔约国启动或进行刑事侦查、起诉或者司法程序时，或在认为可能会使该缔约国根据本公约第五十条提出请求时，得以在不损害本国刑事侦查、起诉或者司法程序的情况下，无须事先请求而向该另一缔约国转发此类资料。\n第五十二条 没收的犯罪所得或财产的返还和处置\n一、 缔约国依照本公约第三十一条或第五十条没收的犯罪所得或财产，应当由该缔约国根据本国法律和行政程序予以处置。\n二、 缔约国根据本公约第五十条的规定依另一缔约国的请求采取行动时，应当在本国法律许可的范围内，根据请求，优先考虑将所没收的犯罪所得或财产返还请求缔约国，以便其对犯罪受害人进行赔偿，或者将此类犯罪所得或财产归还原合法所有人。\n三、 缔约国根据本公约第三十一条和第五十条的规定依另一缔约国的请求采取行动时，可在适当考虑到对受害人进行赔偿后，特别考虑就下述事项缔结协定或安排：\n㈠ 向根据本公约第五十六条第二款第\n㈢项指定的账户以及专门打击网络犯罪的政府间机构捐出与此类犯罪所得或财产等值的款项或变卖此类犯罪所得或财产而得到的资金或其中的一部分；\n㈡ 根据本国法律或行政程序，定期或逐案与其他缔约国分享此类犯罪所得或财产，或变卖此类犯罪所得或财产而获得的资金。\n四、 在适当的情况下，除非缔约国另有决定，被请求缔约国可在依据本条规定返还或者处置没收的财产前，扣除为此进行侦查、起诉或司法程序而发生的合理费用。\n第六章 预防措施 第五十三条 预防措施\n一、 各缔约国均应根据本国法律制度的基本原则，努力制定和实施或维持有效而协调的政策和最佳实践，通过适当的立法措施、行政措施或其他措施，减少现有或未来的网络犯罪机会。\n二、 各缔约国均应根据本国法律的基本原则，在力所能及的范围内采取适当措施，促进相关个人及非政府组织、民间社会组织、学术机构和私营部门实体等公共部门以外的实体以及一般公众在各个相关方面积极参与预防根据本公约确立的犯罪。\n三、 预防措施可包括：\n㈠ 加强执法机构或检察官与相关个人以及非政府组织、民间社会组织、学术机构和私营部门实体等公共部门以外的实体之间的合作，以期在各个相关方面预防和打击根据本公约确立的犯罪；\n㈡ 通过促进公众参与预防和打击此类犯罪的公共宣传活动、公共教育、媒体与信息素养方案和课程，使公众深入了解根据本公约确立的犯罪所构成的威胁的存在、原因和严重性；\n㈢ 建设和努力提高本国刑事司法系统的能力，包括在刑事司法从业人员当中开展培训和培养其专门知识，以此作为针对根据本公约确立的犯罪的国家预防战略的一部分；\n㈣ 鼓励服务提供者在可行情况下根据本国条件并在本国法律允许的限度内采取有效措施，加强服务提供者的产品、服务和客户的安全；\n㈤ 承认安全研究人员在本国法律所允许的范围内和所规定的条件下，专门为加强和改善位于缔约国领土内的服务提供者的产品、服务和客户的安全而开展的合法活动所作的贡献；\n㈥ 制定、促进和推广各种方案和活动，以阻止有可能参与网络犯罪的人员沦为罪犯，并培养其合法技能；\n㈦ 努力促进被判犯有根据本公约确立的犯罪的人员重返社会；\n㈧ 根据本国法律制定战略和政策，以预防和消除通过使用信息通信技术系统发生的性别暴力，并在制定预防措施时考虑到弱势群体的特殊境况和需求；\n㈨ 采取因地制宜的具体努力，保证儿童安全上网，包括为此开展关于网上儿童性虐待或儿童性剥削问题的教育、培训和公众宣传，以及修订旨在预防此类问题的本国法律框架和增进此方面的国际合作，并努力确保快速删除儿童性虐待和性剥削材料；\n㈩ 提高决策进程的透明度，促进公众对决策进程作出贡献，并确保公众有充分的机会获得信息；(十一) 尊重、促进和保护在寻求、接收和传递有关网络犯罪的公共信息方面的自由；(十二) 制定或加强对根据本公约确立的犯罪的受害人的援助方案；(十三) 预防和查明与根据本公约确立的犯罪有关的犯罪所得和财产的转移。\n四、 各缔约国均应采取适当措施，酌情确保公众了解和能够联系到负责预防和打击网络犯罪的一个或多个相关主管机关，以便举报，包括匿名举报，可视作根据本公约确立的刑事犯罪的任何事件。\n五、 缔约国应当努力定期评价现行的相关国家法律框架和行政实践，以便找出差距和不足之处，并确保这些法规和实践在应对根据本公约确立的犯罪所构成的不断变化的威胁时具有现实意义。\n六、 缔约国可相互协作并与有关国际和区域组织协作，推行和制定本条所列述的措施，包括参与旨在预防网络犯罪的国际项目。\n七、 各缔约国均应将可协助其他缔约国制定和实施预防网络犯罪的具体措施的一个或多个机关的名称和地址告知联合国秘书长。\n第七章 技术援助和信息交流 第五十四条 技术援助和能力建设\n一、 缔约国应当根据各自的能力，考虑相互提供最广泛的技术援助和能力建设，包括培训和其他形式的援助，相互交流相关经验和专门知识，以及按照彼此商定的条款转让技术，同时特别考虑到发展中缔约国的利益和需要，以促进预防、监测、侦查和起诉本公约所涵盖的犯罪。\n二、 缔约国应当在必要时为本国负责预防、监测、侦查和起诉本公约所涵盖的犯罪的人员发起、制定、实施或改进具体的培训方案。\n三、 本条第一款和第二款所述活动在本国法律准许的范围内可涉及以下方面：\n㈠ 用于预防、监测、侦查和起诉本公约所涵盖的犯罪的方法和技术；\n㈡ 在制定和规划预防和打击网络犯罪的战略性政策和法规方面开展能力建设；\n㈢ 在收集、保全和共享证据特别是电子证据方面开展能力建设，包括保管链维护和法证分析；\n㈣ 现代执法设备及其使用；\n㈤ 培训主管机关如何撰写符合本公约要求的司法协助以及其他合作手段的请求书，特别是电子证据收集、保全和共享方面的请求；\n㈥ 预防、监测和监控由实施本公约所涵盖的犯罪产生的所得、相关财产、设备或其他工具的 移动，以及转移、藏匿或掩饰此类所得、财产、设备或其他工具所使用的方法；\n㈦ 便利扣押、没收和返还本公约所涵盖的犯罪所得的适当且高效的法律机制和方法以及行政机制和方法；\n㈧ 保护与司法机关合作的受害人和证人的方法；\n㈨ 相关实体法和程序法、执法侦查权、国内和国际有关法规，以及语言等方面的培训。\n四、 缔约国应当在不违反本国法律的情况下，努力利用其他缔约国和相关的国际和区域组织、非政府组织、民间社会组织、学术机构和私营部门实体的专长并与它们开展密切合作，以期加强本公约的有效实施。\n五、 缔约国应当相互协助，规划和实施旨在共享本条第三款所述领域专门知识的研究和培训方案，并应当为此目的酌情利用区域和国际会议及研讨会，促进合作，推动就共同关心的问题开展讨论。\n六、 缔约国应当考虑根据请求相互协助，对在各自领土内实施的本公约所涵盖的犯罪的类型、原因和影响进行评价、考察和研究，以期在主管机关和相关非政府组织、民间社会组织、学术机构和私营部门实体的参与下，制定预防和打击网络犯罪的战略和行动计划。\n七、 缔约国应当促进有助于及时引渡和提供司法协助的培训和技术援助。此类培训和技术援助可包括语言培训、协助起草和处理司法协助请求书，以及在中央机关或负有相关责任的机构的人员之间的借调和交流。\n八、 缔约国应当视需要加强努力，最大限度提高国际和区域组织以及有关双边和多边协定或安排框架内的技术援助和能力建设成效。\n九、 缔约国应当考虑建立自愿捐助机制，以通过技术援助方案和能力建设项目，为发展中国家实施本公约的努力提供资助。\n十、 各缔约国均应努力向联合国毒品和犯罪问题办公室提供自愿捐助，以便经由该办公室推进各种方案和项目，从而通过技术援助和能力建设实施本公约。\n第五十五条 信息交流\n一、 各缔约国均应考虑酌情与有关专家协商，包括与非政府组织、民间社会组织、学术机构和私营部门实体的专家协商，分析本公约涵盖的犯罪在本国领土内的趋势以及实施此类犯罪的环境。\n二、 各缔约国均应考虑开发并彼此共享以及通过国际和区域组织共享有关网络犯罪的统计数据、专业分析技能和信息，以期尽可能制定出预防和打击此类犯罪的共同定义、标准和方法以及最佳实践。\n三、 各缔约国均应考虑监测其预防和打击本公约所涵盖的犯罪的政策和实际措施，并对其成效和效率进行评估。\n四、 缔约国应当考虑相互交流与网络犯罪和收集电子证据有关的法律、政策或技术方面的发展变化情况。\n第五十六条 通过经济发展和技术援助实施本公约\n一、 缔约国应当通过国际合作采取有助于最大限度优化本公约实施工作的措施，同时亦应考虑到本公约涵盖的犯罪对社会总体，尤其是对可持续发展的消极影响。\n二、 大力鼓励缔约国相互协调并与国际和区域组织协调，尽可能作出各种具体努力：\n㈠ 加强与其他缔约国特别是发展中国家在各层级的合作，以增强其预防和打击本公约所涵盖犯罪的能力；\n㈡ 加强资金和物质援助，以支持其他缔约国特别是发展中国家为有效预防和打击本公约所涵盖的犯罪而作出的努力，并帮助它们实施本公约；\n㈢ 向其他缔约国特别是发展中国家提供技术援助，以协助它们满足在实施本公约方面的需要。为此，缔约国应当努力向联合国筹资机制中为此目的专门设定的账户提供充分的经常性自愿捐款；\n㈣ 酌情鼓励非政府组织、民间社会组织、学术机构和私营部门实体以及金融机构，包括根据本条规定，促进缔约国作出各种努力，特别是向发展中国家提供更多的培训方案和现代设备，以协助它们实现本公约的各项目标；\n㈤ 针对所开展的活动交流最佳实践和信息，以期提高透明度，避免重复努力，并充分汲取任何经验教训。\n三、 缔约国还应考虑利用现有的次区域方案、区域方案和国际方案，包括会议和研讨会，促进合作和技术援助，并推动就共同关心的问题，包括发展中国家的特殊问题和需要，展开讨论。\n四、 缔约国应当尽可能确保资源和努力的分配和方向有助于统一标准、技能、能力、专门知识和技术能力，以期在缔约国之间确立共同的最低限度标准，从而铲除本公约涵盖的犯罪的藏身之所，并加强打击网络犯罪的力度。\n五、 根据本条采取的措施应当尽量不影响现有的对外援助承诺或其他双边、区域或国际一级的财政合作安排。\n六、 缔约国可缔结关于物资和后勤援助的双边、区域或多边协定或安排，同时考虑到为使本公约所规定的国际合作手段行之有效和为预防、监测、侦查和起诉本公约所涵盖的犯罪所需要的财政安排。\n第八章 实施机制 第五十七条 公约缔约国会议\n一、 兹此设立公约缔约国会议，以期增强缔约国的能力和增进缔约国之间的合作，从而实现本公约规定的各项目标并促进和审议本公约的实施情况。\n二、 联合国秘书长应当自本公约生效后一年之内召开缔约国会议。其后，缔约国会议常会应当按照缔约国会议所通过的议事规则召开。\n三、 缔约国会议应当通过其议事规则和关于本条所列各项活动的规则，包括关于观察员的接纳和参与以及如何支付这些活动所涉费用的规则。这些规则和相关活动应当考虑到有效性、包容性、透明度、效率和国家自主权等原则。\n四、 缔约国会议在确定其常会时，应当按照本条第三款所述各项原则，考虑到在类似事项上的其他有关国际和区域组织和机制包括其附属条约机构举行会议的时间和地点。\n五、 缔约国会议应当商定实现本条第一款所列目标的活动、程序和工作方法，其中包括：\n㈠ 促进本公约的有效应用和实施、发现其间存在的任何问题，以及 促进缔约国根据本公约开展的活动，包括鼓励调集自愿捐款；\n㈡ 促进缔约国、相关国际和区域组织以及非政府组织、民间社会组织、学术机构和私营部门实体之间根据本国法律交流与根据本公约确立的犯罪有关的法律、政策和技术方面的发展情况以及电子证据收集方面的信息，并交流网络犯罪的模式和趋势以及预防和打击此类犯罪的成功实践方面的信息；\n㈢ 与相关国际和区域组织以及非政府组织、民间社会组织、学术机构和私营部门实体开展合作；\n㈣ 适当利用其他国际和区域组织和机制为预防和打击根据本公约确立的犯罪而提供的相关信息，以避免不必要的重复工作；\n㈤ 定期审议缔约国实施本公约的情况；\n㈥ 提出改进本公约及其实施工作的建议，并审议可能对本公约作出的补充或修正；\n㈦ 依据本公约第六十一条和第六十二条拟订和通过本公约的补充议定书；\n㈧ 注意到缔约国在实施本公约方面的技术援助和能力建设需要，并建议在此方面采取任何其认为必要的行动。\n六、 各缔约国均应按照缔约国会议的要求，向缔约国会议提供信息，说明本国为实施本公约而采取的立法措施、行政措施和其他措施以及本国的方案、计划和实践。缔约国会议应当研究接收信息以及根据这些信息采取行动的最有效方式，这些信息包括从缔约国以及相关国际组织和区域组织收到的信息。根据缔约国会议决定的程序正式获得认可的相关非政府组织、民间社会组织、学术机构和私营部门实体的代表提出的意见亦可予以考虑。\n七、 为了本条第五款之目的，缔约国会议可设立和管理其认为必要的审议机制。\n八、 根据本条第五款至第七款，缔约国会议应当在其认为必要时设立任何适当的机制或附属机构，以协助本公约的有效实施。\n第五十八条 秘书处\n一、 应由联合国秘书长为公约缔约国会议提供必要的秘书处服务。\n二、 秘书处应当：\n㈠ 协助缔约国会议开展本公约所列述的各项活动，并为缔约国会议举行的与本公约有关的届会做出相应的安排和提供必要的服务；\n㈡ 依请求协助缔约国按照本公约的设想向缔约国会议提交资料；以及\n㈢ 确保与有关的国际和区域组织秘书处进行必要的协调。\n第九章 最后条款 第五十九条 本公约的实施\n一、 各缔约国均应根据本国法律的基本原则采取必要措施，包括立法措施和行政措施，确保履行其根据本公约所承担的各项义务。\n二、 为预防和打击根据本公约确立的犯罪，各缔约国均可采取比本公约的规定更为严格或更为严厉的措施。\n第六十条 本公约的效力\n一、 如果两个或两个以上缔约国业已就 本公约所涉事项缔结了协定或条约，或已以其他方式就这些事项建立了关系，或未来将这样做，则这些缔约国亦应有权适用此类协定或条约或相应地规范这些关系。\n二、 本公约的任何规定均不得影响缔约国在国际法下的其他权利、限制、义务和责任。\n第六十一条 同议定书的关系\n一、 本公约可由一项或多项议定书予以补充。\n二、 只有成为本公约缔约方的国家或区域经济一体化组织方可成为议定书缔约方。\n三、 本公约缔约国不受议定书约束，除非其已根据议定书的规定成为议定书的缔约国。\n四、 本公约的任何议定书均应结合本公约解读，并考虑到这些议定书的宗旨。\n第六十二条 通过补充议定书\n一、 至少需要有六十个缔约国，才能在缔约国会议上审议通过任何补充议定书。缔约国会议应尽一切努力就任何补充议定书达成协商一致。如果已为达成协商一致竭尽一切努力而仍未达成一致意见，则作为最后手段，补充议定书须至少获得出席缔约国会议并参加表决的缔约国三分之二多数票方可通过。\n二、 区域经济一体化组织在其职权范围内的事项中依本条行使表决权时，其票数应与其作为本公约缔约国的成员国数目相等。如果这些组织的成员国行使投票权，则这些组织便不得行使投票权；反之亦然。\n第六十三条 争端的解决\n一、 缔约国应当努力通过谈判或自行选择的任何其他和平手段解决与本公约的解释或适用有关的争端。\n二、 两个或两个以上缔约国对于本公约的解释或适用发生任何争端，且未能在合理时间内通过谈判或其他和平手段解决的，应当按其中一缔约国请求交付仲裁。如果自请求交付仲裁之日起六个月后所涉缔约国无法就仲裁安排达成协议，则其中任一缔约国可根据《国际法院规约》请求将争端提交国际法院。\n三、 各缔约国在签署、批准、接受、核准或加入本公约时，均可声明不受本条第二款的约束。其他缔约国对于作出此种保留的任何缔约国，不受本条第二款的约束。\n四、 凡根据本条第三款作出保留的缔约国，均可随时通知联合国秘书长撤销该项保留。\n第六十四条 签署、批准、接受、核准和加入\n一、 本公约应于 2025 年在河内及随后在纽约联合国总部开放供各国签署，直至2026 年 12 月 31 日。\n二、 本公约还应开放供区域 经济一体化组织签署，但条件是此类组织至少有一个成员国已按照本条第一款的规定签署了本公约。\n三、 本公约须经批准、接受或核准。批准书、接受书或核准书应当交存联合国秘书长。如果某一区域经济一体化组织至少有一个成员国已交存批准书、接受书或核准书，则该组织亦可交存其批准书、接受书或核准书。该组织应当在其批准书、接受书或核准书中宣布其在本公约管辖事项方面的权限范围。该组织还应将其权限范围的任何有关变动情况通知保存人。\n四、 任何国家或任何至少已有一个成员国加入本公约的区域经济一体化组织均可加入本公约。加入书应当交存联合国秘书长。区域经济一体化组织加入本公约时应当宣布其在本公约管辖事项方面的权限范围。该组织还应将其权限范围的任何有关变动情况通知保存人。\n第六十五条 生效\n一、 本公约应自第四十份批准书、接受书、核准书或加入书交存之日后第九十天起生效。为本款之目的，区域经济一体化组织交存的任何文书均不得在该组织成员国所交存文书以外另行计算。\n二、 对于在第四十份批准书、接受书、核准书或加入书交存之后批准、接受、核准或加入本公约的国家或区域经济一体化组织，本公约应自该国或该组织交存有关文书之日后第三十天或于本公约根据本条第一款生效之日生效，以其中较晚者为准。\n第六十六条 修正\n一、 缔约国可在本公约生效满五年后提出修正案并将修正案送交联合国秘书长。秘书长应当立即将所提修正案转发缔约国和公约缔约国会议，以便对提案进行审议并作出 决定。缔约国会议应当尽一切努力就每项修正案达成协商一致。如果已为达成协商一致竭尽一切努力而仍未达成一致意见，则作为最后手段，修正案须获得出席缔约国会议并参加表决的缔约国的三分之二多数票方可通过。\n二、 区域经济一体化组织对属于其权限范围内的事项依本条行使表决权时，其票数相当于其作为本公约缔约国的成员国数目。如果这些组织的成员国行使投票权，则这些组织便不得行使投票权，反之亦然。\n三、 根据本条第一款通过的修正案，须经缔约国批准、接受或核准。\n四、 根据本条第一款通过的修正案，应自缔约国向联合国秘书长交存一份批准、接受或核准该修正案的文书之日起九十天后对该缔约国生效。\n五、 修正案一经生效，即对已表示同意受其约束的缔约国具有约束力。其他缔约国则仍受本公约原条款以及此前已批准、接受或核准的任何修正案的约束。\n第六十七条 退约\n一、 缔约国可书面通知联合国秘书长退出本公约。退约应自秘书长收到退约通知之日起一年后生效。\n二、 区域经济一体化组织在其所有成员国均已退出本公约时，即不再是本公约缔约方。\n三、 根据本条第一款的规定退出本公约，即自然退出本公约的任何议定书。\n第六十八条 保存人和语文\n一、 联合国秘书长为本公约的指定保存人。\n二、 本公约原件应交存联合国秘书长，其阿拉伯文、中文、英文、法文、俄文和西班牙文文本同等作准。兹由经各自政府正式授权的下列署名全权代表签署本公约，以昭信守。\n","permalink":"https://ai.intlaws.com/compliance/intl/un-cybercrime-convention/","summary":"联合国打击网络犯罪公约\u003cstrong\u003e官方中文全文\u003c/strong\u003e（英文全文见英文页：\u003ca href=\"/en/compliance/intl/un-cybercrime-convention/\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e/en/compliance/intl/un-cybercrime-convention/\u003c/a\u003e\n）：2024 年 12 月 24 日联合国大会第 79/243 号决议通过，载于决议附件，共 9 章 68 条；须自第 40 份批准书交存后第 90 天生效，目前尚未生效。中文文本取自联合国正式文件 。","title":"联合国打击网络犯罪公约"},{"content":" 译本说明(可核验)\n项 内容 文件 第 14365 号行政令,2025 年 12 月 11 日签署 官方刊登 《联邦公报》90 FR 58499(第 58499–58501 页),2025 年 12 月 16 日刊登(文件号 2025-23092,2025 年 12 月 15 日 11:15 递交) 译本性质 无官方中文文本。本译文由本网译据《联邦公报》官方英文全文逐节译出,为非官方译本、仅供参考,不具法律效力 层级体例 节用\u0026quot;第 N 节\u0026quot;,款用\u0026quot;(a)(b)(c)(d)\u0026ldquo;并另起段,项用\u0026rdquo;(i)(ii)(iii)(iv)\u0026ldquo;各自成段 法条编号 47 U.S.C. 902(b)、47 U.S.C. 1702(e)-(f)、15 U.S.C. 45 等编号逐字保真 官方原文 https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence 性质提示 本件是行政令,不是国会立法;第 8 节所述\u0026quot;立法建议\u0026quot;属提案,不得与已生效法律混同 核对记录 2026-09-24 以《联邦公报》官方纯文本全文(90 FR 58499-58501)与仓库英文底本逐节核对,节号与法条引用逐处一致 第 14365 号行政令 确保人工智能的国家政策框架 依宪法与美利坚合众国法律赋予我作为总统的权力,兹命令:\n第 1 节 目的。 美国在人工智能(AI)领域的领导地位,将在诸多领域促进美国的国家安全与经济安全及其主导地位。依据 2025 年 1 月 23 日第 14179 号行政令(《消除美国人工智能领导地位的障碍》),我撤销了前任使这一产业陷入瘫痪的企图,并指示本届政府消除阻碍美国 AI 领导地位的障碍。本届政府已为推进该目标做了大量工作,包括更新现行联邦监管框架,以消除障碍并鼓励 AI 应用在各行业得到采用。这些努力已为美国人民带来巨大利益,并在全国促成数万亿美元的投资。但我们仍处在这场技术革命的最初期,并且正在其中与对手展开争夺优势地位的竞赛。\n要取胜,美国 AI 企业必须能够自由创新,不受繁琐监管的束缚。但各州过度的监管阻碍了这一要务。第一,逐州监管按其定义必然造成 50 套互不相同的监管制度的拼图,使合规更为困难,对初创企业尤其如此。第二,州法越来越多地要求实体将意识形态偏见嵌入模型。例如,科罗拉多州一项禁止\u0026quot;算法歧视\u0026quot;的新法,甚至可能迫使 AI 模型为避免对受保护群体造成\u0026quot;差别对待或影响\u0026quot;而产出虚假结果。第三,州法有时不被允许地将其规制扩及州界之外,侵犯州际商业。\n本届政府必须与国会共同行动,确保形成一套负担最小的国家标准——而不是 50 套互不协调的州标准。由此形成的框架必须禁止与本行政令所定政策相冲突的州法。该框架还应确保儿童得到保护、审查制度被防止、版权受到尊重、社区得到保障。经审慎设计的国家框架可以确保美国赢得 AI 竞赛——我们必须如此。然而,在该等国家标准出台之前,本届政府必须采取行动,以遏制各州陆续出台的、威胁扼杀创新的最繁重、最过度的法律。\n第 2 节 政策。 美国的政策是:通过一套负担最小的 AI 国家政策框架,维持并增强美国在全球 AI 领域的主导地位。\n第 3 节 AI 诉讼特别工作组。 自本行政令作出之日起 30 日内,司法部长应设立一个 AI 诉讼特别工作组(下称\u0026quot;工作组\u0026rdquo;),其唯一职责是对与本行政令第 2 节所定政策不一致的州 AI 法律提出挑战,所持理由包括:该等法律不被允许地规制州际商业因而违宪、被现行联邦法规优先适用(preempted),或在司法部长判断下属其他违法情形,并酌情包括依本行政令第 4 节所认定的法律。工作组应就不时出现的应予挑战的具体州 AI 法律,与 AI 与加密事务特别顾问、总统科技事务助理、总统经济政策助理以及总统法律顾问兼助理进行磋商。\n第 4 节 对州 AI 法律的评估。 自本行政令作出之日起 90 日内,商务部长应依其在《美国法典》第 47 编第 902(b) 条(47 U.S.C. 902(b))下的职权,与 AI 与加密事务特别顾问、总统经济政策助理、总统科技事务助理以及总统法律顾问兼助理磋商,公布一份对现行州 AI 法律的评估,认定与本行政令第 2 节所定政策相冲突的繁重法律,以及应移交依本行政令第 3 节设立的工作组的法律。该对州 AI 法律的评估至少应认定:要求 AI 模型改变其真实输出的法律,或者可能迫使 AI 开发者或部署者以违反第一修正案或宪法任何其他规定的方式披露或报告信息的法律。该评估还可以另行认定符合本行政令第 2 节所定政策、促进 AI 创新的州法。\n第 5 节 对州资金的限制。\n(a) 自本行政令作出之日起 90 日内,商务部长应通过商务部负责通信与信息的助理部长,发布一份政策通知,规定各州在何种条件下有资格获得\u0026quot;宽带公平接入与部署\u0026quot;(BEAD)计划项下的剩余资金——该资金系经本届政府\u0026quot;交易利益\u0026quot;(Benefit of the Bargain)改革所节省——并符合《美国法典》第 47 编第 1702(e)-(f) 条(47 U.S.C. 1702(e)-(f))。该政策通知必须规定:具有依本行政令第 4 节所认定的繁重 AI 法律的州,在联邦法律允许的最大范围内,没有资格获得非部署类资金。该政策通知还必须说明:碎片化的州 AI 监管格局如何威胁损害 BEAD 资助的部署、依赖高速网络的 AI 应用的增长,以及 BEAD 提供普遍高速连接这一使命。\n(b) 行政各部门与机构(下称\u0026quot;机构\u0026quot;)应与 AI 与加密事务特别顾问磋商,评估其裁量性拨款项目,并确定各机构是否可以将此类拨款附设条件:要求各州或者不制定与本行政令政策相冲突的 AI 法律(包括依本行政令第 4 节认定或依第 3 节被挑战的任何 AI 法律);或者——对已制定此类法律的州而言——要求该等州与相关机构签订具有约束力的协议,承诺在其接受该裁量性资金的项目执行期内不执行任何此类法律。\n第 6 节 联邦报告与披露标准。 自本行政令第 4 节所述认定公布之日起 90 日内,联邦通信委员会主席应与 AI 与加密事务特别顾问磋商,启动一项程序,以决定是否对 AI 模型采用一项可优先适用于相冲突州法的联邦报告与披露标准。\n第 7 节 优先适用于要求 AI 模型从事欺骗性行为的州法。 自本行政令作出之日起 90 日内,联邦贸易委员会主席应与 AI 与加密事务特别顾问磋商,就《联邦贸易委员会法》依《美国法典》第 15 编第 45 条(15 U.S.C. 45)对不公平与欺骗性行为或做法的禁止如何适用于 AI 模型,发布一份政策声明。该政策声明必须说明:在何种情形下,要求改变 AI 模型真实输出的州法,被《联邦贸易委员会法》关于禁止从事影响商业的欺骗性行为或做法的规定所优先适用。\n第 8 节 立法。\n(a) AI 与加密事务特别顾问与总统科技事务助理应共同拟定一项立法建议,建立统一的 AI 联邦政策框架,以优先适用于与本行政令所定政策相冲突的州 AI 法律。\n(b) 本节(a)款所要求的立法建议,不得提议优先适用于与下列事项有关的其他合法州 AI 法律:\n(i) 儿童安全保护;\n(ii) AI 算力与数据中心基础设施(一般适用的许可改革除外);\n(iii) 各州政府的采购与对 AI 的使用;以及\n(iv) 另行确定的其他事项。\n第 9 节 一般规定。\n(a) 本行政令中的任何内容,均不得解释为损害或以其他方式影响:\n(i) 法律授予行政部门或机构或其负责人的职权;或\n(ii) 管理和预算办公室主任与预算、行政或立法建议有关的职能。\n(b) 本行政令的实施应符合适用法律,并取决于拨款的可获得性。\n(c) 本行政令无意且不会创设任何实体上或程序上的权利或利益,使任何一方得以在法律上或衡平法上对美国、其各部门、机构或实体、其官员、雇员或代理人,或任何其他人主张强制执行。\n(d) 本行政令的公布费用由商务部承担。\n白宫,\n2025 年 12 月 11 日。\n译注\n术语对照:State law=州法;preempt/preemption=优先适用;onerous=繁重;discretionary grant=裁量性拨款;non-deployment funds=非部署类资金;Policy Notice=政策通知;performance period=项目执行期;First Amendment=第一修正案;interstate commerce=州际商业。 第 3 节\u0026quot;unconstitutionally regulate interstate commerce\u0026quot;直译为\u0026quot;以违宪的方式规制州际商业\u0026quot;;译文作\u0026quot;不被允许地规制州际商业因而违宪\u0026quot;。 第 5 节\u0026quot;Benefit of the Bargain\u0026quot;为白宫对 BEAD 计划改革的政策名称,保留英文并括注。 官方文本末尾无正文再注;\u0026quot;(Presidential Sig.)\u0026ldquo;为《联邦公报》版式标记,不属正文,未译出。 本译文由本网译,非官方,仅供参考。 ","permalink":"https://ai.intlaws.com/compliance/us/executive-order-14365/","summary":"2025 年 12 月 11 日第 14365 号行政令《确保人工智能的国家政策框架》官方文本中文译校版(《联邦公报》90 FR 58499,2025 年 12 月 16 日刊登),共 9 节:负担最小的 AI 国家政策框架、AI 诉讼特别工作组、商务部对州 AI 法律的评估、对州资金(BEAD 与裁量性拨款)的限制、FCC 联邦报告与披露标准程序、FTC 关于优先适用的政策声明,以及不含儿童安全、AI 算力与数据中心基础设施、州政府采购等事项的立法建议。本页为据官方英文文本译校的中文译本(非官方)。","title":"美国第 14365 号行政令"},{"content":"导语：一份\u0026quot;50 州拼图\u0026quot;式的合规地图 与欧盟一次性通过统一条例的路径不同，美国至今没有联邦层面的综合性人工智能法律。规制由两条线同时推进：联邦层面以行政令与国家立法框架建议牵引，并试图以\u0026quot;先占\u0026quot;（preemption）压制各州立法；州层面则继续各自立法，形成标准不一的拼图。\n2025 年下半年到 2026 年，这两条线正面相撞：一边是德州、加州、科罗拉多等州的实体规则陆续生效或被重置，一边是联邦行政令与立法框架明确主张\u0026quot;统一国家标准\u0026quot;。对在美有业务的中国企业而言，真正的难点不是\u0026quot;美国有没有 AI 法\u0026quot;，而是要同时应对联邦—州两个层面互相矛盾的要求。\n一、结构性事实：先看三个基本判断 没有联邦统一法：联邦层面目前的抓手是行政令、框架性文件与既有部门法（如联邦贸易委员会法第 5 条），而非综合性立法； 州法是当前唯一的实体规制来源：生效的义务几乎全部来自州法； 联邦\u0026quot;先占\u0026quot;主张与州法同时存在，法律确定性处于低谷——这是 2026 年最大的合规风险特征。 二、联邦层面：从\u0026quot;移除障碍\u0026quot;到\u0026quot;统一国家标准\u0026quot; 时间 文件 要点 2025-01-23 第 14179 号行政令（Removing Barriers to American Leadership in Artificial Intelligence） 移除此前的政策障碍（EO 14365 明确援引该令为政策起点） 2025-12-11 第 14365 号行政令（Ensuring a National Policy Framework for Artificial Intelligence），刊登于《联邦公报》2025-12-16 以\u0026quot;确保国家政策框架\u0026quot;为题，主张为人工智能建立统一的国家政策框架 2026-03 白宫发布国家人工智能立法框架（National Policy Framework for AI）建议，官方发布页：whitehouse.gov/releases/2026/03/… 属立法建议而非生效法规；核心是敦促国会以联邦标准取代各州\u0026quot;不当负担\u0026quot;的 AI 法律，同时保留各州在保护儿童、防范欺诈等领域的权限 引用提示：第 14365 号行政令的官方全文见《联邦公报》（90 FR 58499，2025-12-16），务必以该版本为准；白宫 2026 年 3 月的框架文件属建议性质，不具备法律约束力，写作与合规评估时不要与生效法规混同。\n三、州级图景：四个已完成官方核实的节点 3.1 德州：TRAIGA（HB 149），2026 年 1 月 1 日生效 德州第 89 届议会通过 HB 149（Texas Responsible Artificial Intelligence Governance Act）。据德州议会官方\u0026quot;已登记法案摘要\u0026quot;，生效日 2026-01-01；摘要列明的禁止性内容包括：\n禁止使用或部署 AI 系统创建社会评分（social scoring）系统——注意该项禁令的对象限于\u0026quot;政府实体\u0026quot;：HB 149 第 552.053 条规定 \u0026ldquo;A governmental entity may not use or deploy an artificial intelligence system … with the intent to calculate or assign a social score\u0026rdquo;，法案将\u0026quot;governmental entity\u0026quot;定义为州及其政治区划中行使政府职能的部门、委员会、机关等；私主体不在该条禁止对象之列； 禁止开发或分发用于生成、协助生成或传播特定色情内容或儿童色情内容的 AI 系统。 官方链接：德州议会 HB 149 已登记摘要 https://capitol.texas.gov/billlookup/BillSummary.aspx?Bill=HB149\u0026amp;LegSess=89R 3.2 加州：SB 53（前沿模型透明度）+ 2026 年 9 月两项新法 SB 53（Artificial intelligence models: large developers）：据加州立法信息网官方状态页，该法案新增《商业与职业法典》第 25.1 章（自第 22757.10 条起）、《政府法典》第 11546.8 条、《劳动法典》第 5.1 章（自第 1107 条起），州务卿登记日为 2025-09-29（即签署成法）。州长办公室同日发布签署新闻稿。https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill_id=202520260SB53 2026 年 9 月：州长办公室先后发布签署新闻稿——2026-09-09 签署两项 AI 保障法（新闻稿点名的包括 SB 813，McNerney 参议员提出，为独立第三方核查与审计 AI 系统建立全国首创的框架）；2026-09-16 签署 SB 1050（Ashby 参议员提出，要求使用 AI 生成表演者的广告作明确披露，并加强对创意产业劳动者的保护）。另于 2026-09-10 签署儿童安全聊天机器人与社交媒体相关法律。具体条文细节仍以官方文本为准。 加州的特点值得注意：透明度与披露义务先行（模型开发者披露、广告披露、劳动者保护），与欧盟\u0026quot;风险分级+合格评定\u0026quot;的路径明显不同。\n3.3 科罗拉多：一部\u0026quot;被自己取代\u0026quot;的州法 科罗拉多 2024 年的 SB 24-205（《人工智能消费者保护》，Colorado Revised Statutes 第 6 编第 17 部分）是美国第一部综合性州级 AI 法。其命运在 2026 年被改写：\n据科罗拉多州议会官方\u0026quot;法案摘要\u0026quot;：SB 26-189 废止（repeals）并重新制定（reenacts）了 SB 24-205 的规定，改为围绕\u0026quot;自动化决策技术\u0026quot;（automated decision-making technology, ADMT）在\u0026quot;重大决定\u0026quot;（consequential decisions）中的使用设定新要求；该法（第 131 章）的登记生效日为 2026-05-14。\n官方链接：https://leg.colorado.gov/bills/sb26-189 ；原法见 https://leg.colorado.gov/bills/sb24-205 实务含义：按 2024 年版本准备过科罗拉多合规的企业，需要全面重做——监管对象由\u0026quot;人工智能系统\u0026quot;收窄为\u0026quot;自动化决策技术\u0026quot;，义务结构随之改变。\n备注：SB 24-205 的生效日在 2025 年曾经历一次推迟。官方出处已核实：2025 年特别会议 SB 25B-004（《Increase Transparency for Algorithmic Systems》）经州长于 2025-08-28 批准、2025-11-25 生效（第 3 章）；州议会官方\u0026quot;法案摘要\u0026quot;载明其内容为\u0026quot;将 SB 24-205 各项要求的生效日延长至 2026 年 6 月 30 日\u0026quot;。SB 26-189 的\u0026quot;Session Laws\u0026quot;栏亦载明其章号为 131、生效日 2026-05-14。https://leg.colorado.gov/bills/sb25b-004 ｜ https://leg.colorado.gov/bills/sb26-189 3.4 其他州（待核清单，本文不作结论） 康涅狄格等州的 AI 画像/自动化决策条款、犹他州的 AI 政策法、以及各州针对生成式内容与选举的专门立法，均在推进中。本文未对上述州逐一完成官方原文核实，故不列出具体生效日期与条文——数智知库的\u0026quot;立法动态\u0026quot;栏目将按法域逐步补齐。检索时请以各州议会官方网站为准，不要采用第三方汇总表作为引用来源。\n四、对中国企业的合规含义 先判断\u0026quot;有没有美国州际连接点\u0026quot;：州法以\u0026quot;在州内提供、部署或对州内居民产生影响\u0026quot;为常见触发条件，与其是否有美国实体无关； 按义务类型建台账，而不是按\u0026quot;哪部法\u0026quot;记账：目前实际可执行的义务集中在四类——透明度与披露、禁止性用途、歧视与偏见风险评估、高风险场景的人工监督与影响评估； 注意联邦先占诉讼带来的\u0026quot;规则悬置\u0026quot;：州法被挑战不等于自动失效，企业不能以此为由停止合规；应准备\u0026quot;规则可能变化\u0026quot;的预案； 科罗拉多的教训：州法可能在生效前被废止重立——不要把合规投入锁定在某一版本的法条结构上，把体系性内容（数据治理、模型文档、评估流程）做成可复用资产更划算。 五、与中国、欧盟路径的简要对照 维度 美国 欧盟 中国 立法层级 无联邦统一法；州法为主 + 联邦行政令/框架建议 统一条例（AI Act） 法律 + 部门规章（生成式 AI 暂行办法、标识办法等） 规制技术 分州、分场景，透明度与禁止性用途先行 风险分级 + 合格评定 + 协调标准 分类监管 + 备案/安全评估 + 内容标识 当前不确定性 高（联邦先占之争） 中（时间表已修订，规则明确） 低（规则体系已相对成形，细则持续补充） 六、后续观察点 联邦\u0026quot;先占\u0026quot;主张的法律落地方式：国会立法、行政令施压，还是诉讼（州法合宪性/权限之争）； 科罗拉多 SB 26-189 的实施细则与执法口径； 加州 2026 年新法的适用对象与过渡期； 更多州在 2027 年会期前的立法动向。 规范依据（供核对）\n第 14365 号行政令全文（《联邦公报》90 FR 58499，2025-12-16）：https://www.govinfo.gov/content/pkg/FR-2025-12-16/html/2025-23092.htm 德州议会：HB 149 已登记法案摘要 https://capitol.texas.gov/billlookup/BillSummary.aspx?Bill=HB149\u0026amp;LegSess=89R 加州立法信息网：SB 53 状态与章节 https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill_id=202520260SB53 加州州长办公室：SB 53 签署新闻稿（2025-09-29）https://www.gov.ca.gov/2025/09/29/governor-newsom-signs-sb-53-advancing-californias-world-leading-artificial-intelligence-industry/ 加州州长办公室：AI 保障措施签署新闻稿（2026-09-09）https://www.gov.ca.gov/2026/09/09/governor-newsom-signs-first-in-the-nation-ai-safeguards-to-protect-californians-calls-on-the-federal-government-to-do-its-part/ 白宫：President Donald J. Trump Unveils National AI Legislative Framework（2026-03，含框架 PDF 2026-03-20）https://www.whitehouse.gov/releases/2026/03/president-donald-j-trump-unveils-national-ai-legislative-framework 白宫：Ensuring a National Policy Framework for Artificial Intelligence（2025-12 行政令 EO 14365；注：白宫页面 URL slug 沿用早期草案名 \u0026ldquo;eliminating-state-law-obstruction-of-national-artificial-intelligence-policy\u0026rdquo;，与页面正式标题不一致，页面可达且内容为该行政令官方文本）https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/ 德州议会：HB 149 已登记文本（social scoring 见第 552.053 条）https://capitol.texas.gov/tlodocs/89R/billtext/pdf/HB00149F.pdf 加州州长办公室：劳动者保护与 AI 广告披露新法（2026-09-16）https://www.gov.ca.gov/2026/09/16/governor-newsom-signs-new-law-to-protect-workers-require-disclosures-on-ai-generated-advertising/ 科罗拉多州议会：SB 26-189（废止并重立 ADMT 规则）https://leg.colorado.gov/bills/sb26-189 科罗拉多州议会：SB 24-205（2024 年原法）https://leg.colorado.gov/bills/sb24-205 ","permalink":"https://ai.intlaws.com/legislation/%E7%BE%8E%E5%9B%BD%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E7%AB%8B%E6%B3%95%E7%9A%84%E8%81%94%E9%82%A6%E5%B7%9E%E7%BA%A7%E6%8B%89%E9%94%AF-2026%E5%B9%B4%E5%B7%9E%E6%B3%95%E5%9B%BE%E6%99%AF%E4%B8%8E%E5%90%88%E8%A7%84%E8%A6%81%E7%82%B9/","summary":"美国 AI 立法呈「联邦行政令 + 州法拼图」并行格局：以官方源核实第 14365 号行政令、德州 TRAIGA（2026-01-01 生效）、加州 SB 53 及 2026 年 9 月两项新法，并揭示科罗拉多 SB 24-205 已被 2026 年 SB 26-189 废止并重立这一关键变动。","title":"美国人工智能立法的联邦—州级拉锯：2026 年州法图景与合规要点"},{"content":" 项目 内容 法域 欧盟 立法层级 条例(Regulation,直接适用,无需成员国转化) 原文名称 Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) 英文名称 EU Artificial Intelligence Act (AI Act) 中文名称 欧盟《人工智能法》——业内通行译名,欧盟法无官方中文译本 通过与公布 2024-06-13 签署;2024-07-12 刊登于《欧盟官方公报》 生效/施行 2024-08-01 生效;分期适用(见下\u0026quot;生效节点\u0026quot;) 最近修订 Regulation (EU) 2026/1744(AI Omnibus,2026-07-27 生效)——编号已核实:经欧盟出版局 CELEX 官方通道(32026R1744)取得 OJ 记载,并按 EUR-Lex ELI 核验:https://eur-lex.europa.eu/eli/reg/2026/1744/oj 主管机关 成员国国家主管机关 + 欧盟委员会 AI Office(通用模型与部分平台内嵌系统的监督) 适用范围 在欧盟市场投放/投入使用 AI 系统的提供者、部署者、进口商、分销商(部分条款具域外效力) 议题标签 人工智能治理 状态 现行有效,分期适用中 官方原文链接 https://eur-lex.europa.eu/eli/reg/2024/1689/oj ;条款速览:https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113 核验日期 2026-09-22 原文全文（英文）已上线:本页为档案与生效节点速览。《官方公报》刊登的条例英文原文全文(13 章、113 条、13 个附件)已按 EUR-Lex 逐字收录 →\nRegulation (EU) 2024/1689 —(EN) 。\n欧盟法仅以欧盟官方语言作准,无官方中文文本;中文译本正据官方英文原文逐条译校,完成后在本栏目单独发布。\n一、生效节点(经 AI Omnibus 修订后的官方口径) 日期 事项 2024-08-01 生效 2025-02-02 一般条款(定义、AI 素养)与禁止性做法适用 2025-08-02 通用人工智能(GPAI)模型义务适用;成员国须指定主管机关并通过罚则;欧盟治理架构到位 2026-08-02 大部分规则适用;第 50 条透明度义务适用;执法启动 2026-12-02 新增禁令(非自愿性私密内容、儿童性虐待材料)适用;第 50 条第 2 款过渡期 2027-08-02 成员国至少一个监管沙盒运行 2027-12-02 附件三高风险系统规则适用(原 2026-08-02) 2028-08-02 附件一所嵌受监管产品中的高风险系统规则适用(原 2027-08-02) 二、关键机制 风险分级:禁止性做法 / 高风险(第 6 条与附件三场景,及附件一产品)/ 透明度风险(第 50 条)/ 最低风险; 高风险系统义务:风险管理、数据治理、技术文档、日志、透明度、人类监督、准确性稳健性网络安全、质量管理体系、合格评定与 CE 标记; GPAI 义务:技术文档、下游提供者信息、版权政策、训练数据摘要;系统性风险模型另有对抗测试与事件报告义务; 自愿性行为准则:《通用人工智能行为准则》(2025-07-09 定稿),委员会与 AI 委员会确认为\u0026quot;适当的自愿工具\u0026quot;,签署可降低行政负担; 协调标准与符合性推定:2026-07-12 CEN/CENELEC 批准首个标准(《AI:面向 AI Act 监管目的的质量管理体系》,EN 18286:2026;CEN 登记册 date of Ratification 为 2026-07-12,以登记册机器记录为准),委员会预计 2026 年内于 OJ 公布引用。 三、官方指南与配套文件 委员会 GPAI 义务范围指南(2025-07-18,C(2025) 5045 final):https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act 委员会《AI Omnibus enters into force》(2026-07-27):https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force 官方实施时间表:https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline 附件三高风险场景清单:https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3 四、动态观察点 OJ 公布首批协调标准引用(决定\u0026quot;符合性推定\u0026quot;何时可用); 成员国罚则与主管机关落实; AI Office 对 GPAI 的执法(新模型自 2026-08-02 起可执行,既有模型自 2027-08-02); AI Omnibus 实施效果评估及是否引发第二轮调整。 五、相关产出 本站文章:《欧盟《人工智能法》实施进展:AI Omnibus 修订后的义务生效节点与合规要点》(2026-09-22) 归档位置:2026-09-22/欧盟人工智能法实施进展-AI-Omnibus修订后的义务生效节点与合规要点.md 既有素材:归档 2026-09-13/欧盟人工智能法主要内容及其影响分析(内部索引,非对外链接) 六、来源 EUR-Lex:Regulation (EU) 2024/1689 AI Act Service Desk(实施时间表、第 113 条、附件三) 欧盟委员会数字战略网站(AI Omnibus 生效公告、GPAI 行为准则页、GPAI 指南) 欧洲议会立法进程页(Digital Omnibus on AI) CEN-CENELEC(首个协调标准公告) ","permalink":"https://ai.intlaws.com/compliance/eu/%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E6%B3%95-ai-act-2024-1689/","summary":"欧盟《人工智能法》（Regulation (EU) 2024/1689）档案：风险分级框架、通用人工智能义务、治理架构与 AI Omnibus 修订后的义务生效时间表，附官方来源。","title":"欧盟人工智能法"},{"content":"导语：为什么今年必须重看一遍时间表 欧盟《人工智能法》的合规时间表在 2026 年被改写：AI Omnibus（Regulation (EU) 2026/1744）生效后，附件三高风险系统的义务后移至 2027 年 12 月 2 日、附件一所嵌产品的义务后移至 2028 年 8 月 2 日。本文以官方来源逐节点梳理现行生效安排，供企业据此重排合规路线图。\n2024 年 8 月 1 日，欧盟《人工智能法》（Artificial Intelligence Act，Regulation (EU) 2024/1689）生效。此后两年，业界普遍按一套广为流传的时间表安排合规工作：2026 年 8 月 2 日高风险人工智能系统义务适用，2027 年 8 月 2 日附件一产品类高风险系统适用。\n这套时间表已经过时。2026 年 7 月 27 日，欧盟委员会的\u0026quot;人工智能数字综合法案\u0026quot;（AI Omnibus）正式生效，高风险系统的义务节点被整体后移。欧盟官方的 AI Act Service Desk 也据此更新了实施时间表，并明确写道：全面铺开的时间点已调整为 2028 年 8 月 2 日，\u0026ldquo;该时间表已考虑 AI 数字综合法案对《人工智能法》的修订\u0026rdquo;。\n对在欧盟市场投放或使用人工智能系统的中国企业而言，这不是一条程序性新闻：它直接改变了未来两年合规投入的节奏，也改变了\u0026quot;何时必须做完什么\u0026quot;的判断。\n一、修订的由来与生效 节点 日期 依据 欧盟委员会提出 digital omnibus 一揽子方案中的 AI 部分 2025-11-19 欧洲议会立法进程页（Legislative Train） 欧洲议会通过谈判立场 2026-03（当月第二次全会） 同上 刊登于《欧盟官方公报》（OJ） 2026-07-24 已核对官方来源:欧盟出版局资源 OJ L 202601744 AI Omnibus 正式生效 2026-07-27 欧盟委员会官方新闻《AI Omnibus enters into force》 该修订法案的编号为 Regulation (EU) 2026/1744（2026 年 7 月 8 日通过，2026 年 7 月 24 日刊登于《欧盟官方公报》L 系列，OJ L 202601744），同时修订了《人工智能法》（2024/1689）、民航共同规则（2018/1139）与机械条例（2023/1230）。\n编号已核对官方原文：欧盟出版局官方资源 http://publications.europa.eu/resource/celex/32026R1744 载明\u0026quot;REGULATION (EU) 2026/1744 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 8 July 2026 …\u0026quot;，OJ L 系列公布日 2026-07-24；另见欧盟委员会 2026-07-27 生效公告。生效日依据：该条例最后条款明定\u0026quot;This Regulation shall enter into force on the third day following that of its publication in the Official Journal of the European Union\u0026quot;——即自定生效日（刊登后第三日），非二十日通行规则。\n术语说明：欧盟法以欧盟 24 种官方语言公布，不包含中文。本文所附中文名称为业内通行译名，引用时请以英文原文为准。\n二、现行义务生效节点全景 以下为经修订后的官方时间表（来源：AI Act Service Desk 实施时间表）：\n日期 事项 2024-08-01 《人工智能法》生效 2025-02-02 一般条款（定义、AI 素养）与禁止性做法开始适用 2025-08-02 通用人工智能（GPAI）模型义务开始适用；成员国须指定国家主管机关并通过罚则；欧盟层面治理架构（AI 委员会、科学专家组、咨询论坛）须到位 2026-08-02 《人工智能法》大部分规则开始适用，可适用规则的执法启动：第 50 条透明度义务开始适用；支持创新的措施开始适用；针对 GPAI 模型、禁止性做法、透明度义务与 AI 素养的执法在国家与欧盟层面同步启动 2026-12-02 新增禁令开始适用（生成非自愿性私密内容的深度伪造、儿童性虐待材料）；同时为 2026-08-02 前已投放市场的部分合成内容系统的提供者设定第 50 条第 2 款的过渡期 2027-08-02 成员国应至少有一个人工智能监管沙盒投入运行 2027-12-02 附件三所列高风险人工智能系统的规则开始适用（原为 2026-08-02） 2028-08-02 嵌入附件一所列受监管产品（机械、玩具、电梯等）的高风险人工智能系统的规则开始适用（原为 2027-08-02） 三、2026 年最值得注意的两项变动 第一，高风险义务的平移并非单纯延期，而是与\u0026quot;合规工具可用性\u0026quot;挂钩。 欧洲议会立法进程页记录，委员会提出的思路是：高风险系统规则的适用时间与标准或其他支持合规的工具是否到位挂钩。这里需要区分两个层面：其一，提案阶段的机制——委员会提出的思路是把高风险规则的适用时间与标准等合规工具是否到位相绑定；其二，现行法上已确定的固定日期——独立高风险系统 2027 年 12 月 2 日、附件一所嵌系统 2028 年 8 月 2 日（由 AI Omnibus 修订确定的适用日，不再以工具到位为条件）。提案阶段的机制是下一轮调整的政策空间，不要把 2027、2028 两个日期理解为以工具到位为前提的浮动期限。这一设计意味着：标准制定进度将直接影响合规义务的时间表。\n第二，在放宽的同时收紧了部分领域。 委员会公告列出的修订内容包括：\n新增禁令：禁止生成非自愿的色情、私密内容以及儿童性虐待材料的人工智能系统（即俗称的\u0026quot;脱衣类应用\u0026quot;）； 偏误检测：允许为检测与纠正偏见而处理特殊类别的个人数据； 沙盒扩容：扩大监管沙盒的可及范围，并引入欧盟层面的监管沙盒； 减轻行政负担：将原本仅适用于中小企业的简化义务扩展至\u0026quot;小型中型市值公司\u0026quot;（SMCs）；简化人工智能素养要求，改由委员会与成员国承担更多推广职责；简化欧盟中央数据库的登记义务； 治理调整：扩大 AI Office 的监督权限，覆盖部分基于通用模型、且嵌入大型在线平台与搜索引擎的人工智能系统。 四、GPAI：从\u0026quot;规则生效\u0026quot;到\u0026quot;可以执行\u0026quot; 对多数中国企业而言，最直接的接触点是通用人工智能（GPAI）模型义务。\n2025 年 8 月 2 日，GPAI 模型义务开始适用； 依委员会新闻稿，这些规则对新模型在一年后、对既有模型在两年后可由委员会的 AI Office 执行——即新模型自 2026 年 8 月 2 日起、既有模型自 2027 年 8 月 2 日起进入可执行阶段； 2025 年 7 月 9 日，委员会收到《通用人工智能行为准则》（General-Purpose AI Code of Practice）定稿：该准则由 13 名独立专家起草，征求了 1,000 余家利益相关方意见，属自愿性工具；委员会与 AI 委员会已确认其为提供者证明合规的\u0026quot;适当的自愿工具\u0026quot;，签署者可据此降低行政负担； 2025 年 7 月 18 日，委员会发布了关于 GPAI 模型提供者义务范围的指南（文件号 C(2025) 5045 final）。 需注意：行为准则的签署方名单由 AI Office 持续更新（已见 Amazon、Google、Microsoft、Anthropic、IBM、Mistral 等），签署与否不影响法定义务本身，只影响合规证明方式。\n五、标准化：首个协调标准获批，合格推定尚待公报 2026 年 7 月 12 日，CEN 与 CENELEC 批准了 EN 18286:2026《人工智能：面向欧盟《人工智能法》监管目的的质量管理体系》（Artificial Intelligence: Quality Management System for EU AI Act Regulatory Purposes）——《人工智能法》项下首个欧洲标准（批准日以 CEN 登记册为准:登记册载 date of Ratification (DOR) 2026-07-12、date of Availability (DAV) 2026-07-22、DOA 2026-10-31、DOP 2027-01-31;CEN-CENELEC 消息于 2026-07-29 发布,其\u0026rsquo;In June\u0026rsquo;系早期内部节点表述,以登记册机器记录为准），覆盖风险管理、人类监督、数据质量与网络安全等要求。截至本文写作时，委员会尚未在《欧盟官方公报》公布该标准的引用；委员会方面表示预计在 2026 年晚些时候公布。在该引用公布之前，《人工智能法》第 40 条的\u0026quot;符合性推定\u0026quot;尚不生效。\n对企业而言，标准的意义在于：协调标准的引用一经公布，符合该标准即可产生\u0026quot;符合相关要求\u0026quot;的推定效力——这是高风险系统合规路径中成本最低的一条通道，值得提前跟踪。\n六、企业需要做什么：按角色的动作清单 角色 2026 年内 2027—2028 GPAI 模型提供者 完成透明度与版权政策、训练数据摘要；评估是否构成\u0026quot;系统性风险\u0026quot;模型；决定是否签署行为准则 既有模型的义务进入可执行阶段（2027-08-02） 高风险系统提供者（附件三：生物识别、教育、就业、关键基础设施、执法、移民、司法等） 建立质量管理体系与风险管理制度；准备技术文档、日志、人类监督与准确性测试；跟踪协调标准公布 2027-12-02 前完成合规与合格评定 嵌入受监管产品的高风险系统（附件一：机械、玩具、电梯、医疗器械等） 与产品法规下的合格评定流程衔接 2028-08-02 前完成 部署者（企业用户） 按提供者说明使用、保存日志、完成人工监督安排；高风险场景下开展基本权利影响评估 随高风险义务节点同步 合成内容相关系统 第 50 条透明度义务已自 2026-08-02 适用；注意 2026-12-02 的过渡期安排 — 七、与中国规则的简要对照 中国在人工智能治理上的路径与欧盟不同，但部分义务形成事实上的对标：\n议题 欧盟 中国 透明度与内容标识 第 50 条透明度义务（2026-08-02 适用）；2026-12-02 起新增针对非自愿性私密内容与儿童性虐待材料的禁令 《人工智能生成合成内容标识办法》（2025-09-01 施行）区分显式标识与隐式标识；《互联网信息服务深度合成管理规定》（2023-01-10 施行）要求显著标识并禁止删除、篡改标识 通用/生成式模型义务 GPAI 模型义务（2025-08-02 适用）+ 自愿性行为准则 + 委员会指南 《生成式人工智能服务管理暂行办法》（2023-08-15 施行）以服务提供者为规制对象，配套算法备案与安全评估 风险分级 以\u0026quot;禁止—高风险—透明度风险—最低风险\u0026quot;分层，附件三列举高风险场景 以服务类型与内容风险为线索分类监管，未采用统一的四层分级 给中国企业的实务提示：若同一产品同时面向中国与欧盟市场，标识义务是最先需要打通的一环——两套规则在\u0026quot;必须让用户识别内容由 AI 生成\u0026quot;这一目标上趋同，但实现方式（显式/隐式标识 vs 第 50 条的技术性披露）与举证要求不同，需要一套可同时满足两边的工作底稿。\n八、后续观察点 委员会在《欧盟官方公报》公布首批协调标准引用（预计 2026 年内）——直接决定\u0026quot;符合性推定\u0026quot;何时可用； 各成员国依 2025-08-02 要求制定的罚则与主管机关指定落实情况； AI Office 对 GPAI 模型的执法动作（自 2026-08-02 起对新模型可执行）； 附件三高风险义务与标准可用性挂钩机制的后续细化； AI 数字综合法案的实施评估，以及是否会引发第二轮调整。 规范依据（供核对）\n欧盟委员会：《AI Omnibus enters into force》（2026-07-27）https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force AI Act Service Desk：《Timeline for the Implementation of the EU AI Act》 https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline AI Act Service Desk：《Article 113: Entry into force and application》 https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113 AI Act Service Desk：《Annex III》 https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3 欧洲议会立法进程页：《Digital Omnibus on AI》 https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai 欧盟委员会新闻稿：《General-Purpose AI Code of Practice now available》（2025-07-09）https://ec.europa.eu/commission/presscorner/detail/en/ip_25_1787 欧盟委员会：《The General-Purpose AI Code of Practice》 https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai 欧盟委员会：《Guidelines on the scope of obligations for providers of general-purpose AI models under the AI Act》（2025-07-18，C(2025) 5045 final）https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act CEN-CENELEC：《EN 18286 in the Spotlight: Supporting Compliance with the AI Act》（2026-07-30）https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/ CEN-CENELEC：《First Standard Approved under the AI Act》（2026-07-29）https://www.cencenelec.eu/news-events/news/2026/newsletter/ots-75-anec 国家互联网信息办公室：《生成式人工智能服务管理暂行办法》（2023-08-15 施行）https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm ","permalink":"https://ai.intlaws.com/legislation/%E6%AC%A7%E7%9B%9F%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E6%B3%95%E5%AE%9E%E6%96%BD%E8%BF%9B%E5%B1%95-ai-omnibus%E4%BF%AE%E8%AE%A2%E5%90%8E%E7%9A%84%E4%B9%89%E5%8A%A1%E7%94%9F%E6%95%88%E8%8A%82%E7%82%B9%E4%B8%8E%E5%90%88%E8%A7%84%E8%A6%81%E7%82%B9/","summary":"以 2026 年 7 月生效的 AI Omnibus（Regulation (EU) 2026/1744）为基准，重排欧盟《人工智能法》全部义务生效节点：附件三高风险义务后移至 2027-12-02、附件一所嵌产品后移至 2028-08-02，并给出 GPAI 可执行时点、透明度义务与执法启动节点及企业合规要点。","title":"欧盟人工智能法实施进展：AI Omnibus 修订后的义务生效节点与合规要点"},{"content":"修订说明（请先读这一段） 本文基于 2026-09-11 原稿修订，修订范围与理由如下：\n时间表已过时（本次修订的主因）：原稿写\u0026quot;高风险系统大部分义务 2026 年 8 月起\u0026quot;。该时间表已被 2026 年 7 月生效的\u0026quot;人工智能数字综合法案\u0026quot;（AI Omnibus，Regulation (EU) 2026/1744）改写：附件三高风险义务后移至 2027-12-02，附件一所嵌产品的高风险义务后移至 2028-08-02。凡按原稿日期安排合规的读者，请以本文修订后的节点为准。 编号与公报信息已硬核对：Regulation (EU) 2026/1744，法案日 2026-07-08，刊登于《欧盟官方公报》L 系列 2026-07-24（OJ L 202601744），2026-07-27 生效。已通过欧盟出版局（Publications Office）官方资源与欧盟委员会官方公告双向核对。 已逐条核对的项：第 99 条罚则最高档（EUR 35 000 000 或全球营业额 7%，取高者）、第 51 条系统性风险算力阈值（训练算力超过 10^25 浮点运算即推定为高影响能力模型）——均已对照 AI Act 官方条文页原文。 本稿不作确定性表述的项：罚则其余档位（第 99 条第 4、5 款）、日韩立法细节（见第七部分）——未取得官方原文的，以官方文本为准。 一、立法背景与进程 法案全称：《人工智能法》（Artificial Intelligence Act，Regulation (EU) 2024/1689）\n立法动因：欧盟在数字治理领域延续 GDPR（General Data Protection Regulation，通用数据保护条例）的「布鲁塞尔效应」路径，试图通过统一立法确立全球 AI 监管标准，同时应对 AI 带来的基本权利风险、安全风险与市场碎片化问题。 立法进程： 2021 年 4 月：欧盟委员会提出立法提案 2023 年 12 月：欧洲议会、理事会、委员会三方就最终文本达成政治协议 2024 年 3 月：欧洲议会通过；2024 年 5 月：理事会批准 2024-08-01：生效，分阶段适用 2026-07-27：AI Omnibus（Regulation (EU) 2026/1744，2026-07-08 通过，2026-07-24 刊《欧盟官方公报》）生效，对 AI Act 的时间表与部分义务作出修订 法律形式：欧盟条例（Regulation），在全体成员国直接适用，无需转化为国内法。 修订后的义务生效节点（官方口径） 日期 事项 2024-08-01 生效 2025-02-02 一般条款（定义、AI 素养）与禁止性做法适用 2025-08-02 通用人工智能（GPAI）模型义务适用；成员国须指定国家主管机关并通过罚则；欧盟治理架构（AI 委员会、科学专家组、咨询论坛）到位 2026-08-02 大部分规则适用；第 50 条透明度义务适用；对 GPAI、禁止性做法、透明度与 AI 素养的执法启动 2026-12-02 新增禁令适用（生成非自愿性私密内容、儿童性虐待材料的系统）；第 50 条第 2 款过渡期安排 2027-08-02 成员国应至少有一个监管沙盒投入运行 2027-12-02 附件三所列高风险系统规则适用（原为 2026-08-02） 2028-08-02 附件一所列受监管产品中嵌入的高风险系统规则适用（原为 2027-08-02）；官方时间表以此日为全面铺开节点 来源：欧盟 AI Act Service Desk 官方实施时间表（明确载明\u0026quot;已考虑 AI 数字综合法案对 AI Act 的修订\u0026quot;）。\n二、核心框架：基于风险的分级规制 AI Act 的标志性设计是按风险等级分类监管，义务强度随风险递增：\n风险等级 对应系统 监管态度 典型场景 不可接受风险 被禁止的 AI 实践 禁止 社会评分、实时远程生物识别（执法场景严格限定）、操纵潜意识的行为操控、预测犯罪画像、无差别抓取人脸数据库、情绪识别（职场/教育）等；2026-12-02 起新增：生成非自愿性私密内容与儿童性虐待材料的系统 高风险 附件三列举领域 + 产品安全部件（附件一） 严格合规义务 关键基础设施、教育录取/考试评分、招聘与员工管理、执法、移民边境、司法与民主程序、生物识别（许可后）等 有限风险 与人交互的系统、生成合成内容 透明度义务 聊天机器人须告知对方是 AI；深度合成内容（deepfake）须标识 最小风险 一般 AI 应用 自由使用 鼓励自愿行为准则 三、高风险系统的义务体系 被归类为高风险的系统须履行以下义务（构成「事前合规 + 持续监督」全链条）：\n风险管理体系：贯穿生命周期的持续迭代的风险识别、评估与缓解 数据治理：训练/验证/测试数据须具相关性、代表性、无偏性 技术文档：编制并持续更新，供主管机关审查 记录与日志：自动记录事件，保证可追溯 透明度与使用者告知：向部署者提供使用说明 人类监督：设计上确保人类可有效监督（human oversight） 准确性、鲁棒性与网络安全 合格评定：多数高风险系统须完成内部合规评估或第三方符合性评估，加贴 CE 标志后方可上市 上市后监测与事故报告 基本权利影响评估（FRIA）：特定高风险系统的部署者（如公共机构、信用评分场景）在使用前评估对基本权利的影响 上述为框架性归纳；具体条文序号与细节以官方原文为准。\n四、通用目的模型（GPAI）与系统性风险 所有 GPAI 提供者的义务：技术文档、向下游提供者提供信息、版权政策、训练数据摘要等；义务自 2025-08-02 起适用。 可执行的时点：据欧盟委员会 2025 年 7 月 9 日新闻稿，GPAI 规则对新模型在一年后、对既有模型在两年后可由委员会的 AI Office 执行——即新模型 2026-08-02 起、既有模型 2027-08-02 起进入可执行阶段。 系统性风险的判定门槛（已核原文）：第 51 条规定，用于训练的计算量以浮点运算衡量超过 10^25 时，该模型被推定为具有高影响能力；委员会亦可依特定标准主动认定。 自愿性行为准则：委员会于 2025-07-09 收到《通用人工智能行为准则》定稿（13 名独立专家起草、1,000 余家利益相关方参与）；委员会与 AI 委员会确认其为证明合规的\u0026quot;适当的自愿工具\u0026quot;，签署可降低行政负担。签署与否不改变法定义务，只改变合规证明方式。 官方指南：委员会于 2025-07-18 发布关于 GPAI 提供者义务范围的指南（文件号 C(2025) 5045 final）。 五、治理架构与执法 欧盟 AI Office（设于欧盟委员会）：负责 GPAI 监管、协调与标准支持；AI Omnibus 后其监督权限扩展至部分基于通用模型、并嵌入大型在线平台与搜索引擎的系统 各成员国主管机关：指定 notified body 承担第三方合格评定与市场监管；须自 2025-08-02 起指定并制定罚则 咨询机构：欧洲人工智能委员会（成员国代表）、科学顾问小组、利益相关方咨询论坛 处罚（AI Act 第 99 条）： 违反禁止性做法：行政罚款最高 EUR 35 000 000,或（对企业）全球上一年度营业额的 7%,以较高者为准 —— 已核官方条文原文 其余档位（涉其他义务、提供错误信息）：原稿所述 EUR 15 000 000/3% 与 EUR 7 500 000/1.5% 两档，官方原文页面未载完整文本，引用前请核对欧盟《人工智能法》第 99 条第 4、5 款 对中小企业及初创企业设定与营业额挂钩的上限 六、创新配套措施 监管沙盒：成员国须建立；2027-08-02 起各国应至少有一个投入运行；AI Omnibus 后扩大可及范围并引入欧盟层面沙盒 标准与合格推定：协调标准（harmonised standards）经《欧盟官方公报》引用后，符合标准可产生\u0026quot;符合相关要求\u0026quot;的推定效力。2026 年 6 月，CEN 与 CENELEC 批准首个 AI Act 项下欧洲标准——《人工智能：面向欧盟 AI Act 监管目的的质量管理体系》（覆盖风险管理、人类监督、数据质量与网络安全）；委员会预计 2026 年内于官方公报公布其引用 中小企业与\u0026quot;小型中型市值公司\u0026quot;（SMCs）支持：AI Omnibus 将原仅适用中小企业的部分简化义务扩展至 SMCs；简化 AI 素养要求（改由委员会与成员国承担更多推广职责）；简化欧盟中央数据库登记义务 偏误检测：AI Omnibus 允许为检测与纠正偏见而处理特殊类别个人数据 七、影响分析：AI 产业与全球立法格局 （一）对 AI 产业的影响 积极面：明确规则降低法律不确定性；合规能力成为竞争壁垒；高风险场景的合规要求可建立用户信任；沙盒与标准提供合规路径指引。\n消极面：合规成本显著（文档、评估、审计流程）；基础模型层义务可能拖慢开源与学术研究；监管严格度差异可能推动部分开发活动向更宽松法域转移（该判断学界实证尚不充分，本文不作结论）。\n结构性影响：加速\u0026quot;合规即服务\u0026quot;（RegTech）产业兴起；推动 AI 供应链分层（基础模型提供者/系统提供者/部署者）与责任划分清晰化。\n（二）对世界各法域立法的影响 「布鲁塞尔效应」的延续与限度：面向欧盟市场的外国企业被迫合规，进而将欧盟标准内化为全球默认；但 AI 领域竞争激烈，中美等法域有自主议程，地缘科技竞争削弱单极输出，价值观差异（如实时生物识别的容忍度）难以被统一标准覆盖。 各法域路径： 美国：联邦层面无统一立法，呈\u0026quot;行政令 + 州法拼图\u0026quot;格局。2025-12-11 第 14365 号行政令主张建立统一国家政策框架，2026 年 3 月白宫发布国家 AI 立法框架建议（属立法建议，非生效法规）；州层面德州 TRAIGA（HB 149）已于 2026-01-01 生效，加州陆续签署透明度类立法，而科罗拉多 2024 年的 SB 24-205 已被 2026 年的 SB 26-189 废止并重新制定（详见本站《美国人工智能立法的联邦—州级拉锯》一文） 英国：采取\u0026quot;亲创新\u0026quot;的分散式监管（行业监管机构主导），区别于欧盟统一立法，但监管原则与欧盟重叠 中国：坚持\u0026quot;先分后总\u0026quot;的渐进立法路径（算法推荐规定 → 深度合成规定 → 生成式人工智能管理暂行办法 → 内容标识办法 → 综合立法推进中）；以分类监管与备案/安全评估为主要工具，与欧盟风险分级路径存在可对话性 日本、韩国：日本以《人工知能関連技術の研究開発及び活用の推進に関する法律》（令和七年法律第五十三号，2025 年 6 月 4 日公布）建立推进体制，并辅以行业指引；韩国于 2024 年底通过人工智能框架性立法，即《人工智能发展与信赖基础建立等基本法》（法律第 20676 号，2025 年 1 月 21 日公布，2026 年 1 月 22 日施行）。具体法名、通过与生效时间以日本 e-Gov（laws.e-gov.go.jp）与韩国国家法令信息中心（law.go.kr）官方原文为准。 国际组织：G7 广岛进程、OECD AI 原则、联合国相关进程均在风险分级上与欧盟框架形成呼应；ISO/IEC 标准制定受欧盟需求拉动 规则互认与标准博弈：标准跨境衔接（如内容标识、安全评估互认）正在成为数字贸易规则的新条款类型；规则互认谈判能力成为数字治理竞争的关键变量。 八、简要评述（修订后） AI Act 仍是全球首部全面性 AI 统一立法，其风险分级、GPAI 分级、基本权利影响评估等制度工具正在成为各国立法的\u0026quot;参考词汇表\u0026quot;。2026 年的 AI Omnibus 修订则提示了一个更重要的观察点：即便在同一法域内，\u0026ldquo;规则\u0026quot;也不是一次成型的——当合规成本与产业竞争力发生冲突时，立法者会选择性地回撤时间表、简化程序，但不放弃核心监管框架。\n对中国企业的实务含义：不要把合规投入锁死在某一版本的条文结构上。可复用的资产是体系性的：模型与数据文档、评估流程、披露话术、供应链责任划分——这些在任何一版时间表下都不会白做。\n术语说明 欧盟法以欧盟 24 种官方语言公布，不含中文，因此不存在\u0026quot;官方中文译名\u0026rdquo;。本文对关键术语采用\u0026quot;原文 + 业内通行译名\u0026ldquo;的方式标注，例如：Regulation（条例）、GPAI（General-Purpose AI，通用人工智能）、harmonised standards（协调标准）、conformity assessment（合格评定）。引用时请以英文原文为准。\n规范依据（供核对）\nAI Act Service Desk 官方实施时间表（经 AI Omnibus 修订）：https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline AI Act Service Desk 第 99 条（罚则）：https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99 AI Act Service Desk 第 51 条（系统性风险门槛）：https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-51 欧盟委员会：《AI Omnibus enters into force》（2026-07-27）：https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force 欧盟出版局官方资源（OJ L 202601744 = Regulation (EU) 2026/1744，公布日 2026-07-24）：http://publications.europa.eu/resource/celex/32026R1744 欧盟委员会新闻稿：《General-Purpose AI Code of Practice now available》（2025-07-09）：https://ec.europa.eu/commission/presscorner/detail/en/ip_25_1787 欧盟委员会：GPAI 提供者义务范围指南（2025-07-18，C(2025) 5045 final）：https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act CEN-CENELEC：首个 AI Act 协调标准获批（2026-07-29）：https://www.cencenelec.eu/news-events/news/2026/newsletter/ots-75-anec 欧洲议会立法进程页：Digital Omnibus on AI：https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai 本稿为 2026-09-22 修订版；原稿（2026-09-11）中\u0026quot;高风险义务 2026 年 8 月起适用\u0026quot;等表述已按官方口径更正。\n","permalink":"https://ai.intlaws.com/forum/%E6%AC%A7%E7%9B%9F%E4%BA%BA%E5%B7%A5%E6%99%BA%E8%83%BD%E6%B3%95%E4%B8%BB%E8%A6%81%E5%86%85%E5%AE%B9%E5%8F%8A%E5%85%B6%E5%BD%B1%E5%93%8D%E5%88%86%E6%9E%90-%E4%BF%AE%E8%AE%A2%E7%A8%BF/","summary":"按 AI Omnibus 生效后的官方口径全面修订欧盟《人工智能法》梳理稿：更正高风险系统与新增禁令的生效节点，核对第 99 条罚则最高档（EUR 35 000 000 或全球营业额 7%）与第 51 条 10^25 算力阈值，并对罚则档位与日韩立法细节不作确定性表述。","title":"欧盟人工智能法主要内容梳理及其影响分析"},{"content":" 版本与来源（可核验）\n项目 内容 通过与公布 2025 年 3 月 14 日公开发布（中国网信网）；四部门联合印发文件（国信办通字〔2025〕2 号）落款日期为 2025 年 3 月 7 日 施行日期 2025 年 9 月 1 日 现行有效 是（截至 2026-09-22） 中文原文来源 https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm 英文译本 无官方英译本。本页英文译本已完成：由本网据官方中文文本翻译并逐条交叉校核，标注为非官方译本、仅供参考 → 英文全文 校对记录 2026-09-22 抓取官方页面；共 14 条，条号连续、无缺号 第一条 为了促进人工智能健康发展，规范人工智能生成合成内容标识，保护公民、法人和其他组织合法权益，维护社会公共利益，根据《中华人民共和国网络安全法》、《互联网信息服务算法推荐管理规定》、《互联网信息服务深度合成管理规定》、《生成式人工智能服务管理暂行办法》等法律、行政法规和部门规章，制定本办法。\n第二条 符合《互联网信息服务算法推荐管理规定》、《互联网信息服务深度合成管理规定》、《生成式人工智能服务管理暂行办法》规定情形的网络信息服务提供者（以下简称“服务提供者”）开展人工智能生成合成内容标识活动，适用本办法。\n第三条 人工智能生成合成内容是指利用人工智能技术生成、合成的文本、图片、音频、视频、虚拟场景等信息。\n人工智能生成合成内容标识包括显式标识和隐式标识。\n显式标识是指在生成合成内容或者交互场景界面中添加的，以文字、声音、图形等方式呈现并可以被用户明显感知到的标识。\n隐式标识是指采取技术措施在生成合成内容文件数据中添加的，不易被用户明显感知到的标识。\n第四条 服务提供者提供的生成合成服务属于《互联网信息服务深度合成管理规定》第十七条第一款情形的，应当按照下列要求对生成合成内容添加显式标识：\n（一）在文本的起始、末尾或者中间适当位置添加文字提示或者通用符号提示等标识，或者在交互场景界面、文字周边添加显著的提示标识；\n（二）在音频的起始、末尾或者中间适当位置添加语音提示或者音频节奏提示等标识，或者在交互场景界面中添加显著的提示标识；\n（三）在图片的适当位置添加显著的提示标识；\n（四）在视频起始画面和视频播放周边的适当位置添加显著的提示标识，可以在视频末尾和中间适当位置添加显著的提示标识；\n（五）呈现虚拟场景时，在起始画面的适当位置添加显著的提示标识，可以在虚拟场景持续服务过程中的适当位置添加显著的提示标识；\n（六）其他生成合成服务场景根据自身应用特点添加显著的提示标识。\n服务提供者提供生成合成内容下载、复制、导出等功能时，应当确保文件中含有满足要求的显式标识。\n第五条 服务提供者应当按照《互联网信息服务深度合成管理规定》第十六条的规定，在生成合成内容的文件元数据中添加隐式标识，隐式标识包含生成合成内容属性信息、服务提供者名称或者编码、内容编号等制作要素信息。\n鼓励服务提供者在生成合成内容中添加数字水印等形式的隐式标识。\n文件元数据是指按照特定编码格式嵌入到文件头部的描述性信息，用于记录文件来源、属性、用途等信息内容。\n第六条 提供网络信息内容传播服务的服务提供者应当采取下列措施，规范生成合成内容传播活动：\n（一）核验文件元数据中是否含有隐式标识，文件元数据明确标明为生成合成内容的，采取适当方式在发布内容周边添加显著的提示标识，明确提醒公众该内容属于生成合成内容；\n（二）文件元数据中未核验到隐式标识，但用户声明为生成合成内容的，采取适当方式在发布内容周边添加显著的提示标识，提醒公众该内容可能为生成合成内容；\n（三）文件元数据中未核验到隐式标识，用户也未声明为生成合成内容，但提供网络信息内容传播服务的服务提供者检测到显式标识或者其他生成合成痕迹的，识别为疑似生成合成内容，采取适当方式在发布内容周边添加显著的提示标识，提醒公众该内容疑似生成合成内容；\n（四）提供必要的标识功能，并提醒用户主动声明发布内容中是否包含生成合成内容。\n有前款第一项至第三项情形的，应当在文件元数据中添加生成合成内容属性信息、传播平台名称或者编码、内容编号等传播要素信息。\n第七条 互联网应用程序分发平台在应用程序上架或者上线审核时，应当要求互联网应用程序服务提供者说明是否提供人工智能生成合成服务。互联网应用程序服务提供者提供人工智能生成合成服务的，互联网应用程序分发平台应当核验其生成合成内容标识相关材料。\n第八条 服务提供者应当在用户服务协议中明确说明生成合成内容标识的方法、样式等规范内容，并提示用户仔细阅读并理解相关的标识管理要求。\n第九条 用户申请服务提供者提供没有添加显式标识的生成合成内容的，服务提供者可以在通过用户协议明确用户的标识义务和使用责任后，提供不含显式标识的生成合成内容，并依法留存提供对象信息等相关日志不少于六个月。\n第十条 用户使用网络信息内容传播服务发布生成合成内容的，应当主动声明并使用服务提供者提供的标识功能进行标识。\n任何组织和个人不得恶意删除、篡改、伪造、隐匿本办法规定的生成合成内容标识，不得为他人实施上述恶意行为提供工具或者服务，不得通过不正当标识手段损害他人合法权益。\n第十一条 服务提供者开展标识活动的，还应当符合相关法律、行政法规、部门规章和强制性国家标准的要求。\n第十二条 服务提供者在履行算法备案、安全评估等手续时，应当按照本办法提供生成合成内容标识相关材料，并加强标识信息共享，为防范打击相关违法犯罪活动提供支持和帮助。\n第十三条 违反本办法规定的，由网信、电信、公安和广播电视等有关主管部门依据职责，按照有关法律、行政法规、部门规章的规定予以处理。\n第十四条 本办法自2025年9月1日起施行。\n","permalink":"https://ai.intlaws.com/compliance/china/ai-generated-content-labelling-measures/","summary":"《人工智能生成合成内容标识办法》官方文本：2025 年 3 月 14 日公布、2025 年 9 月 1 日起施行；规定显式标识与隐式标识义务、传播平台核验提示义务，并禁止提供去除标识的工具。","title":"人工智能生成合成内容标识办法"},{"content":" 版本与来源(可核验)\n项 内容 正式名称 人工知能関連技術の研究開発及び活用の推進に関する法律 通称 AI 推進法(AI 推进法) 法令编号 令和七年法律第五十三号 公布日 2025 年 6 月 4 日 结构 28 条 + 附则 2 条;四章(第一章 总则、第二章 基本措施、第三章 人工智能基本计划、第四章 人工智能战略本部) 官方原文(日文) e-Gov 法令検索 ｜ e-Gov API(机器可读) 中文译本 无官方中文文本。本页中文译文由本网据日文官方文本逐条譯校,为非官方译本、仅供参考 英文译本 截至 2026-10-06,未见日本政府发布官方英译本(内阁府等机构就部分法令发布的 unofficial translation 亦非作准文本);本页以日文官方文本为作准依据,英文译本不在本页范围 核对记录 2026-09-22 经 e-Gov 官方 API(v2)取得全文数据(法令编号、公布日均取自该数据);条号与章结构逐处核对 法案全文(日文官方文本) 令和七年法律第五十三号\n人工知能関連技術の研究開発及び活用の推進に関する法律\n目次\n第一章　総則\n（第一条―第十条）\n第二章　基本的施策\n（第十一条―第十七条）\n第三章　人工知能基本計画\n（第十八条）\n第四章　人工知能戦略本部\n（第十九条―第二十八条）\n附則\n第一章　総則\n第一条　（目的）\nこの法律は、人工知能関連技術が我が国の経済社会の発展の基盤となる技術であることに鑑み、人工知能関連技術の研究開発及び活用の推進に関する施策について、基本理念並びに人工知能関連技術の研究開発及び活用の推進に関する基本的な計画の策定その他の施策の基本となる事項を定めるとともに、人工知能戦略本部を設置することにより、科学技術・イノベーション基本法（平成七年法律第百三十号）及びデジタル社会形成基本法（令和三年法律第三十五号）その他の関係法律による施策と相まって、人工知能関連技術の研究開発及び活用の推進に関する施策の総合的かつ計画的な推進を図り、もって国民生活の向上及び国民経済の健全な発展に寄与することを目的とする。\n第二条　（定義）\nこの法律において、「人工知能関連技術」とは、人工的な方法により人間の認知、推論及び判断に係る知的な能力を代替する機能を実現するために必要な技術並びに入力された情報を当該技術を利用して処理し、その結果を出力する機能を実現するための情報処理システムに関する技術をいう。\n第三条　（基本理念）\n人工知能関連技術の研究開発及び活用の推進は、科学技術・イノベーション基本法第三条に定める科学技術・イノベーション創出の振興に関する方針及びデジタル社会形成基本法第二章に定める基本理念のほか、この条に定める基本理念に基づいて行うものとする。\n２　人工知能関連技術の研究開発及び活用の推進は、人工知能関連技術が、その適正かつ効果的な活用によって行政事務及び民間の事業活動の著しい効率化及び高度化並びに新産業の創出をもたらすものとして経済社会の発展の基盤となる技術であるとともに、安全保障の観点からも重要な技術であることに鑑み、我が国において人工知能関連技術の研究開発を行う能力を保持するとともに、人工知能関連技術に関する産業の国際競争力を向上させることを旨として、行うものとする。\n３　人工知能関連技術の研究開発及び活用の推進は、人工知能関連技術の基礎研究から国民生活及び経済活動における活用に至るまでの各段階の関係者による取組が相互に密接な関連を有することに鑑み、これらの取組を総合的かつ計画的に推進することを旨として、行うものとする。\n４　人工知能関連技術の研究開発及び活用は、不正な目的又は不適切な方法で行われた場合には、犯罪への利用、個人情報の漏えい、著作権の侵害その他の国民生活の平穏及び国民の権利利益が害される事態を助長するおそれがあることに鑑み、その適正な実施を図るため、人工知能関連技術の研究開発及び活用の過程の透明性の確保その他の必要な施策が講じられなければならない。\n５　人工知能関連技術の研究開発及び活用は、我が国及び国際社会の平和と発展に寄与するものとなるよう、国際的協調の下に推進することを旨とし、我が国が人工知能関連技術の研究開発及び活用に関する国際協力において主導的な役割を果たすよう努めるものとする。\n第四条　（国の責務）\n国は、前条に定める基本理念（以下「基本理念」という。）にのっとり、人工知能関連技術の研究開発及び活用の推進に関する施策を総合的かつ計画的に策定し、及び実施する責務を有する。\n２　国は、行政事務の効率化及び高度化を図るため、国の行政機関における人工知能関連技術の積極的な活用を進めるものとする。\n第五条　（地方公共団体の責務）\n地方公共団体は、基本理念にのっとり、人工知能関連技術の研究開発及び活用の推進に関し、国との適切な役割分担の下、地方公共団体が実施すべき施策として、その地方公共団体の区域の特性を生かした自主的な施策を策定し、及び実施する責務を有する。\n第六条　（研究開発機関の責務等）\n大学、科学技術・イノベーション創出の活性化に関する法律（平成二十年法律第六十三号）第二条第九項に規定する研究開発法人その他の人工知能関連技術の研究開発を行う機関（以下「研究開発機関」という。）は、基本理念にのっとり、人工知能関連技術の研究開発及びその成果の普及並びに専門的かつ幅広い知識を有する人材の育成に積極的に努めるとともに、第四条の規定に基づき国が実施する施策及び前条の規定に基づき地方公共団体が実施する施策に協力するよう努めるものとする。\n２　国及び地方公共団体は、人工知能関連技術の研究開発及び活用の推進に関する施策で大学に係るものを策定し、及び実施するに当たっては、大学における研究活動の活性化を図るよう努めるとともに、研究者の自主性の尊重その他の大学における研究の特性に配慮しなければならない。\n３　研究開発機関は、人工知能関連技術の研究開発を効果的に進めるに当たっては、人文科学及び自然科学に関する多様な分野の知見を総合的に活用することが必要であることに鑑み、学際的又は総合的な研究開発に努めるものとする。\n第七条　（活用事業者の責務）\n人工知能関連技術を活用した製品又はサービスの開発又は提供をしようとする者その他の人工知能関連技術を事業活動において活用しようとする者（以下「活用事業者」という。）は、基本理念にのっとり、自ら積極的な人工知能関連技術の活用により事業活動の効率化及び高度化並びに新産業の創出に努めるとともに、第四条の規定に基づき国が実施する施策及び第五条の規定に基づき地方公共団体が実施する施策に協力しなければならない。\n第八条　（国民の責務）\n国民は、基本理念にのっとり、人工知能関連技術に対する理解と関心を深めるとともに、第四条の規定に基づき国が実施する施策及び第五条の規定に基づき地方公共団体が実施する施策に協力するよう努めるものとする。\n第九条　（連携の強化）\n国は、国、地方公共団体、研究開発機関及び活用事業者が相互に連携を図りながら協力することにより人工知能関連技術の研究開発及び活用の推進が図られることに鑑み、これらの者の間の連携の強化に必要な施策を講ずるものとする。\n第十条　（法制上の措置等）\n国は、人工知能関連技術の研究開発及び活用の推進に関する施策を実施するため必要な法制上又は財政上の措置その他の措置を講ずるものとする。\n第二章　基本的施策\n第十一条　（研究開発の推進等）\n国は、人工知能関連技術の基礎研究から実用化のための研究開発に至るまでの一貫した研究開発の推進、研究開発機関における研究開発の成果の移転のための体制の整備、研究開発の成果に係る情報の提供その他の施策を講ずるものとする。\n第十二条　（施設及び設備等の整備及び共用の促進）\n国は、人工知能関連技術の研究開発及び活用に当たって必要となる大規模な情報処理、情報通信、電磁的記録（電子的方式、磁気的方式その他人の知覚によっては認識することができない方式で作られる記録であって、電子計算機による情報処理の用に供されるものをいう。）の保管等に係る施設及び設備並びにデータセット（特定の目的をもって収集した情報の集合物をいう。）その他の知的基盤（科学技術・イノベーション創出の活性化に関する法律第二十四条の四に規定する知的基盤をいう。以下この条において同じ。）を研究開発機関及び活用事業者が広く利用できるようにするため、これらの施設及び設備並びに知的基盤の整備及び共用の促進のために必要な施策を講ずるものとする。\n第十三条　（適正性の確保）\n国は、人工知能関連技術の研究開発及び活用の適正な実施を図るため、国際的な規範の趣旨に即した指針の整備その他の必要な施策を講ずるものとする。\n第十四条　（人材の確保等）\n国は、地方公共団体、研究開発機関及び活用事業者と緊密な連携協力を図りながら、人工知能関連技術の基礎研究から国民生活及び経済活動における活用に至るまでの各段階において必要となる専門的かつ幅広い知識を有する多様な分野の人材の確保、養成及び資質の向上に必要な施策を講ずるものとする。\n第十五条　（教育の振興等）\n国は、国民が広く人工知能関連技術に対する理解と関心を深めるよう、人工知能関連技術に関する教育及び学習の振興、広報活動の充実その他の必要な施策を講ずるものとする。\n第十六条　（調査研究等）\n国は、国内外の人工知能関連技術の研究開発及び活用の動向に関する情報の収集、不正な目的又は不適切な方法による人工知能関連技術の研究開発又は活用に伴って国民の権利利益の侵害が生じた事案の分析及びそれに基づく対策の検討その他の人工知能関連技術の研究開発及び活用の推進に資する調査及び研究を行い、その結果に基づいて、研究開発機関、活用事業者その他の者に対する指導、助言、情報の提供その他の必要な措置を講ずるものとする。\n第十七条　（国際協力）\n国は、人工知能関連技術の研究開発及び活用に関する国際協力を推進するとともに、国際的な規範の策定に積極的に参画するものとする。\n第三章　人工知能基本計画\n第十八条\n政府は、基本理念にのっとり、前章に定める基本的施策を踏まえ、人工知能関連技術の研究開発及び活用の推進に関する基本的な計画（以下「人工知能基本計画」という。）を定めるものとする。\n２　人工知能基本計画は、次に掲げる事項について定めるものとする。\n一　人工知能関連技術の研究開発及び活用の推進に関する施策についての基本的な方針\n二　人工知能関連技術の研究開発及び活用の推進に関し、政府が総合的かつ計画的に講ずべき施策\n三　前二号に掲げるもののほか、人工知能関連技術の研究開発及び活用の推進に関する施策を政府が総合的かつ計画的に推進するために必要な事項\n３　内閣総理大臣は、人工知能戦略本部の作成した人工知能基本計画の案について閣議の決定を求めるものとする。\n４　内閣総理大臣は、前項の閣議の決定があったときは、遅滞なく、人工知能基本計画を公表するものとする。\n５　前二項の規定は、人工知能基本計画の変更について準用する。\n第四章　人工知能戦略本部\n第十九条　（設置）\n人工知能関連技術の研究開発及び活用の推進に関する施策を総合的かつ計画的に推進するため、内閣に、人工知能戦略本部（以下「本部」という。）を置く。\n第二十条　（所掌事務）\n本部は、次に掲げる事務をつかさどる。\n一　人工知能基本計画の案の作成及び実施の推進に関すること。\n二　前号に掲げるもののほか、人工知能関連技術の研究開発及び活用の推進に関する施策で重要なものの企画及び立案並びに総合調整に関すること。\n第二十一条　（組織）\n本部は、人工知能戦略本部長、人工知能戦略副本部長及び人工知能戦略本部員をもって組織する。\n第二十二条　（人工知能戦略本部長）\n本部の長は、人工知能戦略本部長（以下「本部長」という。）とし、内閣総理大臣をもって充てる。\n２　本部長は、本部の事務を総括し、所部の職員を指揮監督する。\n第二十三条　（人工知能戦略副本部長）\n本部に、人工知能戦略副本部長（次項及び次条第二項において「副本部長」という。）を置き、内閣官房長官及び人工知能戦略担当大臣（内閣総理大臣の命を受けて、人工知能関連技術の研究開発及び活用の総合的かつ計画的な推進に関し内閣総理大臣を助けることをその職務とする国務大臣をいう。）をもって充てる。\n２　副本部長は、本部長の職務を助ける。\n第二十四条　（人工知能戦略本部員）\n本部に、人工知能戦略本部員（次項において「本部員」という。）を置く。\n２　本部員は、本部長及び副本部長以外の全ての国務大臣をもって充てる。\n第二十五条　（資料の提出その他の協力）\n本部は、その所掌事務を遂行するため必要があると認めるときは、関係行政機関、地方公共団体、独立行政法人（独立行政法人通則法（平成十一年法律第百三号）第二条第一項に規定する独立行政法人をいう。）及び地方独立行政法人（地方独立行政法人法（平成十五年法律第百十八号）第二条第一項に規定する地方独立行政法人をいう。）の長並びに特殊法人（法律により直接に設立された法人又は特別の法律により特別の設立行為をもって設立された法人であって、総務省設置法（平成十一年法律第九十一号）第四条第一項第八号の規定の適用を受けるものをいう。）の代表者に対して、資料の提出、意見の表明、説明その他必要な協力を求めることができる。\n２　本部は、その所掌事務を遂行するために特に必要があると認めるときは、前項に規定する者以外の者に対しても、必要な協力を依頼することができる。\n第二十六条　（事務）\n本部に関する事務は、内閣府において処理する。\n第二十七条　（主任の大臣）\n本部に係る事項については、内閣法（昭和二十二年法律第五号）にいう主任の大臣は、内閣総理大臣とする。\n第二十八条　（政令への委任）\nこの法律に定めるもののほか、本部に関し必要な事項は、政令で定める。\n附　則\n第一条　（施行期日）\nこの法律は、公布の日から施行する。ただし、第三章及び第四章並びに附則第三条及び第四条の規定は、公布の日から起算して三月を超えない範囲内において政令で定める日から施行する。\n第二条　（検討）\n政府は、人工知能関連技術の研究開発及び活用の推進に関する諸施策についての国際的動向その他の社会経済情勢の変化を勘案しつつ、この法律の施行の状況について検討を加え、必要があると認めるときは、その結果に基づいて所要の措置を講ずるものとする。\n中文译本(非官方) 关于推进人工智能相关技术的研发及应用的法律\n令和七年法律第五十三号\n目次 第一章 总则\n（第一条—第十条）\n第二章 基本措施\n（第十一条—第十七条）\n第三章 人工智能基本计划\n（第十八条）\n第四章 人工智能战略本部\n（第十九条—第二十八条）\n附则\n第一章 总则 第一条 目的\n鉴于人工智能相关技术是支撑我国经济社会发展的基础性技术，本法就推进人工智能相关技术的研发及应用的措施，规定基本理念以及制定推进人工智能相关技术的研发及应用的基本计划等其他措施的基本事项，同时通过设置人工智能战略本部，与《科学技术与创新基本法》（平成七年法律第一百三十号）及《数字社会形成基本法》（令和三年法律第三十五号）等其他相关法律规定的措施相结合，谋求综合且有计划地推进人工智能相关技术的研发及应用的措施，以期为提高国民生活及国民经济的健康发展作出贡献。\n第二条 定义\n本法中，“人工智能相关技术”是指：为实现以人工方法替代与人的认知、推理及判断有关的智能能力的功能所必需的技术，以及为实现在利用该技术处理所输入的信息并输出其结果的功能所必需的信息处理系统相关技术。\n第三条 基本理念\n推进人工智能相关技术的研发及应用，除依据《科学技术与创新基本法》第三条规定的有关振兴科学技术与创新创造的基本方针及《数字社会形成基本法》第二章规定的基本理念外，应依据本条所规定的基本理念进行。\n２　推进人工智能相关技术的研发及应用，鉴于人工智能相关技术通过其适当且有效的应用，带来行政事务及民间事业活动的显著效率化及高度化以及新产业的创造，是支撑经济社会发展的基础性技术，同时从安全保障角度看也是重要技术，应以在我国保持进行人工智能相关技术研发的能力，并提高人工智能相关技术相关产业的国际竞争力为宗旨进行。\n３　推进人工智能相关技术的研发及应用，鉴于从人工智能相关技术的基础研究到在国民生活及经济活动中的应用为止的各阶段相关方的举措相互具有密切关联，应以综合且有计划地推进这些举措为宗旨进行。\n４　人工智能相关技术的研发及应用，鉴于在以不正当目的或不适当方法进行时，可能有助长被用于犯罪、个人信息泄露、侵犯著作权及其他损害国民生活安宁及国民权益的事态，为谋求其适当实施，必须采取确保人工智能相关技术的研发及应用过程透明性等其他必要措施。\n５　人工智能相关技术的研发及应用，应以有助于我国及国际社会的和平与发展而在国际协调下推进为宗旨，我国应努力在有关人工智能相关技术的研发及应用的国际合作中发挥主导性作用。\n第四条 国家的责任\n国家依据前条规定的基本理念（以下称“基本理念”），负有综合且有计划地制定并实施推进人工智能相关技术的研发及应用的措施的责任。\n２　国家为谋求行政事务的效率化及高度化，应推进国家行政机关积极应用人工智能相关技术。\n第五条 地方公共团体的责任\n地方公共团体依据基本理念，就推进人工智能相关技术的研发及应用，在与国家适当分担职责的前提下，作为地方公共团体应实施之措施，负有制定并实施发挥该地方公共团体区域特性的自主性措施的责任。\n第六条 研发机构的责任等\n大学、《关于促进科学技术与创新创造活性的法律》（平成二十年法律第六十三号）第二条第九项规定的研发法人以及其他进行人工智能相关技术研发的机构（以下称“研发机构”），依据基本理念，应积极致力于人工智能相关技术的研发及其成果的普及以及培养具有专业且广泛知识的人才，同时应努力协助依据第四条规定国家实施的措施及依据前条规定地方公共团体实施的措施。\n２　国家及地方公共团体在制定并实施与大学有关的人工智能相关技术的研发及应用推进措施时，应努力谋求活跃大学的研究活动，同时必须尊重研究人员的自主性并考虑大学研究的其他特性。\n３　研发机构在有效推进人工智能相关技术的研发时，鉴于综合运用人文科学及自然科学多种领域的知识十分必要，应努力进行跨学科或综合性的研发。\n第七条 应用经营者的责任\n拟开发或提供应用人工智能相关技术的产品或服务者以及其他拟在事业活动中应用人工智能相关技术者（以下称“应用经营者”），依据基本理念，应通过自身积极应用人工智能相关技术，努力实现事业活动的效率化及高度化以及新产业的创造，同时必须协助依据第四条规定国家实施的措施及依据第五条规定地方公共团体实施的措施。\n第八条 国民的责任\n国民依据基本理念，应加深对人工智能相关技术的理解与关心，同时应努力协助依据第四条规定国家实施的措施及依据第五条规定地方公共团体实施的措施。\n第九条 强化协作\n国家鉴于国家、地方公共团体、研发机构及应用经营者相互谋求协作并予以配合能够推进人工智能相关技术的研发及应用，应采取强化这些人之间协作所必需的措施。\n第十条 法制上的措施等\n国家应采取为实施推进人工智能相关技术的研发及应用的措施所必需的法制上或财政上的措施及其他措施。\n第二章 基本措施 第十一条 推进研发等\n国家应采取推进从人工智能相关技术的基础研究到以实现实用化为目的的研发的一贯性研发、完善为转移研发机构研发成果的体制、提供研发成果相关信息等其他措施。\n第十二条 促进设施及设备等的完善与共用\n国家为使研发机构及应用经营者能够广泛利用人工智能相关技术的研发及应用中所需要的大规模信息处理、信息通信、电磁记录（指以电子方式、磁力方式及其他人的知觉无法识别的方式制作的、供电子计算机信息处理之用的记录。）的保管等相关的设施及设备、数据集（指为特定目的收集的信息的集合物）及其他知识基础（指《关于促进科学技术与创新创造活性的法律》第二十四条之四规定的知识基础。以下本条中相同。），应采取为促进这些设施及设备及知识基础的完善与共用所必需的措施。\n第十三条 确保适当性\n国家为谋求人工智能相关技术的研发及应用得到适当实施，应完善符合国际规范宗旨的指南及其他必要措施。\n第十四条 确保人才等\n国家应在与地方公共团体、研发机构及应用经营者紧密配合协作的同时，就自人工智能相关技术的基础研究到国民生活及经济活动中的应用为止的各阶段所必需具有专业且广泛知识的多种领域人才，采取确保、培养及提高其素质所必需的措施。\n第十五条 振兴教育等\n国家为使国民广泛加深对人工智能相关技术的理解与关心，应采取振兴有关人工智能相关技术的教育及学习、充实宣传活动等其他必要措施。\n第十六条 调查研究等\n国家应进行收集国内外人工智能相关技术的研发及应用动向相关信息、分析因以不正当目的或不适当方法进行人工智能相关技术的研发或应用而发生侵害国民权益的案件并基于该分析研讨对策以及其他有助于推进人工智能相关技术的研发及应用的调查与研究，并基于其结果，对研发机构、应用经营者及其他人员采取指导、建议、提供信息及其他必要措施。\n第十七条 国际合作\n国家应推进有关人工智能相关技术的研发及应用的国际合作，同时积极参与国际规范的制定。\n第三章 人工智能基本计划 第十八条\n政府依据基本理念，在遵循前章规定的基本措施的基础上，应制定推进人工智能相关技术的研发及应用的基本计划（以下称“人工智能基本计划”）。\n２　人工智能基本计划应就下列事项作出规定。\n一　有关推进人工智能相关技术的研发及应用的措施的基本方针\n二　就推进人工智能相关技术的研发及应用，政府应综合且有计划地采取的措施\n三　除前两项所列事项外，为政府综合且有计划地推进有关人工智能相关技术的研发及应用的措施所必需的事项\n３　内阁总理大臣应就人工智能战略本部作成的人工智能基本计划草案，请求内阁会议作出决定。\n４　内阁总理大臣在前款的内阁会议决定作出时，应毫不迟延地公布人工智能基本计划。\n５　前两款的规定，准用于人工智能基本计划的变更。\n第四章 人工智能战略本部 第十九条 设置\n为综合且有计划地推进有关人工智能相关技术的研发及应用的措施，在内阁设置人工智能战略本部（以下称“本部”）。\n第二十条 所管事务\n本部掌管下列事务。\n一　人工智能基本计划草案的作成及实施的推进相关事项。\n二　除前项所列事项外，有关推进人工智能相关技术的研发及应用的措施中重要事项的规划及立案以及综合调整相关事项。\n第二十一条 组织\n本部由人工智能战略本部长、人工智能战略副本部长及人工智能战略本部员组成。\n第二十二条 人工智能战略本部长\n本部的首长为人工智能战略本部长（以下称“本部长”），由内阁总理大臣充任。\n２　本部长统括本部事务，指挥监督所部职员。\n第二十三条 人工智能战略副本部长\n本部设人工智能战略副本部长（次款及次条第二款中称“副本部长”），由内阁官房长官及人工智能战略担当大臣（指受内阁总理大臣之命、以就综合且有计划地推进人工智能相关技术的研发及应用辅助内阁总理大臣为其职务的国务大臣。）充任。\n２　副本部长辅助本部长的职务。\n第二十四条 人工智能战略本部员\n本部设人工智能战略本部员（次款中称“本部员”）。\n２　本部员由本部长及副本部长以外的全体国务大臣充任。\n第二十五条 资料的提出及其他协助\n本部在认为为执行其所管事务而必要时，可以对相关行政机关、地方公共团体、独立行政法人（指《独立行政法人通则法》（平成十一年法律第一百零三号）第二条第一项规定的独立行政法人）及地方独立行政法人（指《地方独立行政法人法》（平成十五年法律第一百一十八号）第二条第一项规定的地方独立行政法人）的首长以及特殊法人（指依法律直接设立的法人或依特别法律以特别的设立行为设立的法人中，适用《总务省设置法》（平成十一年法律第九十一号）第四条第一项第八号规定者）的代表，要求其提出资料、陈述意见、作出说明及其他必要协助。\n２　本部在认为为执行其所管事务而有特别必要时，也可以对前款规定者以外者请求必要协助。\n第二十六条 事务\n本部相关事务，由内阁府处理。\n第二十七条 主任大臣\n关于本部相关的事项，《内阁法》（昭和二十二年法律第五号）所称主任大臣，为内阁总理大臣。\n第二十八条 对政令的委任\n除本法规定者外，有关本部的必要事项由政令规定。\n附则 第一条 施行日期\n本法自公布之日起施行。但第三章及第四章以及附则第三条及第四条的规定，自公布之日起算不超过三个月的范围内，自政令规定的日期起施行。\n第二条 检讨\n政府应在考量有关推进人工智能相关技术的研发及应用的各项措施的国际动向及其他社会经济形势变化的同时，对本法施行的状况进行检讨，认为有必要时，应基于其结果采取必要的措施。\n| 附则收录范围 | 本页附则含第 1–2 条(施行期日、检讨)。e-Gov 官方数据中附则部分标注为抜粋(摘录),其第一条但书所引「附则第三条及第四条」未包含在该数据中 —— 本页按官方数据如实照录,未补入任何内容;需要完整附则时请核对官报公布文本 |\n","permalink":"https://ai.intlaws.com/compliance/other/japan-ai-promotion-act/","summary":"日本《人工知能関連技術の研究開発及び活用の推進に関する法律》(通称\u0026quot;AI 推进法\u0026quot;,令和七年法律第五十三号,2025 年 6 月 4 日公布)官方文本中文译校版,共 28 条:总则(目的、定义、基本理念)、基本计划、人工智能战略本部、推进施策等。本页并附\u003cstrong\u003e日文官方原文\u003c/strong\u003e,中文译本为据日文官方文本译校的非官方译本,仅供参考。","title":"日本人工智能推进法"},{"content":" 版本与来源（可核验）\n项目 内容 通过与公布 2023 年 7 月 13 日公布（国家互联网信息办公室等七部门令第 15 号） 施行日期 2023 年 8 月 15 日 现行有效 是（截至 2026-09-22） 中文原文来源 https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm 英文译本 无官方英译本。本页英文译本已完成：由本网据官方中文文本翻译并逐条交叉校核，标注为非官方译本、仅供参考 → English 校对记录 2026-09-22 抓取官方页面；共 24 条、5 章，条号连续、无缺号 第一章 总 则 第一条 为了促进生成式人工智能健康发展和规范应用，维护国家安全和社会公共利益，保护公民、法人和其他组织的合法权益，根据《中华人民共和国网络安全法》、《中华人民共和国数据安全法》、《中华人民共和国个人信息保护法》、《中华人民共和国科学技术进步法》等法律、行政法规，制定本办法。\n第二条 利用生成式人工智能技术向中华人民共和国境内公众提供生成文本、图片、音频、视频等内容的服务（以下称生成式人工智能服务），适用本办法。\n国家对利用生成式人工智能服务从事新闻出版、影视制作、文艺创作等活动另有规定的，从其规定。\n行业组织、企业、教育和科研机构、公共文化机构、有关专业机构等研发、应用生成式人工智能技术，未向境内公众提供生成式人工智能服务的，不适用本办法的规定。\n第三条 国家坚持发展和安全并重、促进创新和依法治理相结合的原则，采取有效措施鼓励生成式人工智能创新发展，对生成式人工智能服务实行包容审慎和分类分级监管。\n第四条 提供和使用生成式人工智能服务，应当遵守法律、行政法规，尊重社会公德和伦理道德，遵守以下规定：\n（一）坚持社会主义核心价值观，不得生成煽动颠覆国家政权、推翻社会主义制度，危害国家安全和利益、损害国家形象，煽动分裂国家、破坏国家统一和社会稳定，宣扬恐怖主义、极端主义，宣扬民族仇恨、民族歧视，暴力、淫秽色情，以及虚假有害信息等法律、行政法规禁止的内容；\n（二）在算法设计、训练数据选择、模型生成和优化、提供服务等过程中，采取有效措施防止产生民族、信仰、国别、地域、性别、年龄、职业、健康等歧视；\n（三）尊重知识产权、商业道德，保守商业秘密，不得利用算法、数据、平台等优势，实施垄断和不正当竞争行为；\n（四）尊重他人合法权益，不得危害他人身心健康，不得侵害他人肖像权、名誉权、荣誉权、隐私权和个人信息权益；\n（五）基于服务类型特点，采取有效措施，提升生成式人工智能服务的透明度，提高生成内容的准确性和可靠性。\n第二章 技术发展与治理 第五条 鼓励生成式人工智能技术在各行业、各领域的创新应用，生成积极健康、向上向善的优质内容，探索优化应用场景，构建应用生态体系。\n支持行业组织、企业、教育和科研机构、公共文化机构、有关专业机构等在生成式人工智能技术创新、数据资源建设、转化应用、风险防范等方面开展协作。\n第六条 鼓励生成式人工智能算法、框架、芯片及配套软件平台等基础技术的自主创新，平等互利开展国际交流与合作，参与生成式人工智能相关国际规则制定。\n推动生成式人工智能基础设施和公共训练数据资源平台建设。促进算力资源协同共享，提升算力资源利用效能。推动公共数据分类分级有序开放，扩展高质量的公共训练数据资源。鼓励采用安全可信的芯片、软件、工具、算力和数据资源。\n第七条 生成式人工智能服务提供者（以下称提供者）应当依法开展预训练、优化训练等训练数据处理活动，遵守以下规定：\n（一）使用具有合法来源的数据和基础模型；\n（二）涉及知识产权的，不得侵害他人依法享有的知识产权；\n（三）涉及个人信息的，应当取得个人同意或者符合法律、行政法规规定的其他情形；\n（四）采取有效措施提高训练数据质量，增强训练数据的真实性、准确性、客观性、多样性；\n（五）《中华人民共和国网络安全法》、《中华人民共和国数据安全法》、《中华人民共和国个人信息保护法》等法律、行政法规的其他有关规定和有关主管部门的相关监管要求。\n第八条 在生成式人工智能技术研发过程中进行数据标注的，提供者应当制定符合本办法要求的清晰、具体、可操作的标注规则；开展数据标注质量评估，抽样核验标注内容的准确性；对标注人员进行必要培训，提升尊法守法意识，监督指导标注人员规范开展标注工作。\n第三章 服务规范 第九条 提供者应当依法承担网络信息内容生产者责任，履行网络信息安全义务。涉及个人信息的，依法承担个人信息处理者责任，履行个人信息保护义务。\n提供者应当与注册其服务的生成式人工智能服务使用者（以下称使用者）签订服务协议，明确双方权利义务。\n第十条 提供者应当明确并公开其服务的适用人群、场合、用途，指导使用者科学理性认识和依法使用生成式人工智能技术，采取有效措施防范未成年人用户过度依赖或者沉迷生成式人工智能服务。\n第十一条 提供者对使用者的输入信息和使用记录应当依法履行保护义务，不得收集非必要个人信息，不得非法留存能够识别使用者身份的输入信息和使用记录，不得非法向他人提供使用者的输入信息和使用记录。\n提供者应当依法及时受理和处理个人关于查阅、复制、更正、补充、删除其个人信息等的请求。\n第十二条 提供者应当按照《互联网信息服务深度合成管理规定》对图片、视频等生成内容进行标识。\n第十三条 提供者应当在其服务过程中，提供安全、稳定、持续的服务，保障用户正常使用。\n第十四条 提供者发现违法内容的，应当及时采取停止生成、停止传输、消除等处置措施，采取模型优化训练等措施进行整改，并向有关主管部门报告。\n提供者发现使用者利用生成式人工智能服务从事违法活动的，应当依法依约采取警示、限制功能、暂停或者终止向其提供服务等处置措施，保存有关记录，并向有关主管部门报告。\n第十五条 提供者应当建立健全投诉、举报机制，设置便捷的投诉、举报入口，公布处理流程和反馈时限，及时受理、处理公众投诉举报并反馈处理结果。\n第四章 监督检查和法律责任 第十六条 网信、发展改革、教育、科技、工业和信息化、公安、广播电视、新闻出版等部门，依据各自职责依法加强对生成式人工智能服务的管理。\n国家有关主管部门针对生成式人工智能技术特点及其在有关行业和领域的服务应用，完善与创新发展相适应的科学监管方式，制定相应的分类分级监管规则或者指引。\n第十七条 提供具有舆论属性或者社会动员能力的生成式人工智能服务的，应当按照国家有关规定开展安全评估，并按照《互联网信息服务算法推荐管理规定》履行算法备案和变更、注销备案手续。\n第十八条 使用者发现生成式人工智能服务不符合法律、行政法规和本办法规定的，有权向有关主管部门投诉、举报。\n第十九条 有关主管部门依据职责对生成式人工智能服务开展监督检查，提供者应当依法予以配合，按要求对训练数据来源、规模、类型、标注规则、算法机制机理等予以说明，并提供必要的技术、数据等支持和协助。\n参与生成式人工智能服务安全评估和监督检查的相关机构和人员对在履行职责中知悉的国家秘密、商业秘密、个人隐私和个人信息应当依法予以保密，不得泄露或者非法向他人提供。\n第二十条 对来源于中华人民共和国境外向境内提供生成式人工智能服务不符合法律、行政法规和本办法规定的，国家网信部门应当通知有关机构采取技术措施和其他必要措施予以处置。\n第二十一条 提供者违反本办法规定的，由有关主管部门依照《中华人民共和国网络安全法》、《中华人民共和国数据安全法》、《中华人民共和国个人信息保护法》、《中华人民共和国科学技术进步法》等法律、行政法规的规定予以处罚；法律、行政法规没有规定的，由有关主管部门依据职责予以警告、通报批评，责令限期改正；拒不改正或者情节严重的，责令暂停提供相关服务。\n构成违反治安管理行为的，依法给予治安管理处罚；构成犯罪的，依法追究刑事责任。\n第五章 附 则 第二十二条 本办法下列用语的含义是：\n（一）生成式人工智能技术，是指具有文本、图片、音频、视频等内容生成能力的模型及相关技术。\n（二）生成式人工智能服务提供者，是指利用生成式人工智能技术提供生成式人工智能服务（包括通过提供可编程接口等方式提供生成式人工智能服务）的组织、个人。\n（三）生成式人工智能服务使用者，是指使用生成式人工智能服务生成内容的组织、个人。\n第二十三条 法律、行政法规规定提供生成式人工智能服务应当取得相关行政许可的，提供者应当依法取得许可。\n外商投资生成式人工智能服务，应当符合外商投资相关法律、行政法规的规定。\n第二十四条 本办法自2023年8月15日起施行。\n","permalink":"https://ai.intlaws.com/compliance/china/generative-ai-interim-measures/","summary":"《生成式人工智能服务管理暂行办法》官方文本：2023 年 7 月 13 日公布、2023 年 8 月 15 日起施行；确立生成式人工智能服务的备案、训练数据、内容标识与安全评估义务。","title":"生成式人工智能服务管理暂行办法"},{"content":" 版本与来源（可核验）\n项目 内容 通过与公布 2022 年 7 月 7 日国家互联网信息办公室令第 11 号公布 施行日期 2022 年 9 月 1 日 现行有效 是（截至 2026-09-22） 中文原文来源 https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm 新旧衔接提示 本办法第十四条规定的评估结果有效期（2 年）已被 2024 年《促进和规范数据跨境流动规定》第九条修改为 3 年（有效期届满前 60 个工作日可申请延长，而非重新申报）；本办法第十九条关于\u0026quot;重要数据\u0026quot;的定义仍为现行有效的重要实体定义之一。 英文译本 无官方英译本。本页英文译本已完成：由本网据官方中文文本翻译并逐条交叉校核，标注为非官方译本、仅供参考 → 英文全文 校对记录 2026-09-22 抓取官方页面；共 20 条，条号连续、无缺号 第一条 为了规范数据出境活动，保护个人信息权益，维护国家安全和社会公共利益，促进数据跨境安全、自由流动，根据《中华人民共和国网络安全法》、《中华人民共和国数据安全法》、《中华人民共和国个人信息保护法》等法律法规，制定本办法。\n第二条 数据处理者向境外提供在中华人民共和国境内运营中收集和产生的重要数据和个人信息的安全评估，适用本办法。法律、行政法规另有规定的，依照其规定。\n第三条 数据出境安全评估坚持事前评估和持续监督相结合、风险自评估与安全评估相结合，防范数据出境安全风险，保障数据依法有序自由流动。\n第四条 数据处理者向境外提供数据，有下列情形之一的，应当通过所在地省级网信部门向国家网信部门申报数据出境安全评估：\n（一）数据处理者向境外提供重要数据；\n（二）关键信息基础设施运营者和处理100万人以上个人信息的数据处理者向境外提供个人信息；\n（三）自上年1月1日起累计向境外提供10万人个人信息或者1万人敏感个人信息的数据处理者向境外提供个人信息；\n（四）国家网信部门规定的其他需要申报数据出境安全评估的情形。\n第五条 数据处理者在申报数据出境安全评估前，应当开展数据出境风险自评估，重点评估以下事项：\n（一）数据出境和境外接收方处理数据的目的、范围、方式等的合法性、正当性、必要性；\n（二）出境数据的规模、范围、种类、敏感程度，数据出境可能对国家安全、公共利益、个人或者组织合法权益带来的风险；\n（三）境外接收方承诺承担的责任义务，以及履行责任义务的管理和技术措施、能力等能否保障出境数据的安全；\n（四）数据出境中和出境后遭到篡改、破坏、泄露、丢失、转移或者被非法获取、非法利用等的风险，个人信息权益维护的渠道是否通畅等；\n（五）与境外接收方拟订立的数据出境相关合同或者其他具有法律效力的文件等（以下统称法律文件）是否充分约定了数据安全保护责任义务；\n（六）其他可能影响数据出境安全的事项。\n第六条 申报数据出境安全评估，应当提交以下材料：\n（一）申报书；\n（二）数据出境风险自评估报告；\n（三）数据处理者与境外接收方拟订立的法律文件；\n（四）安全评估工作需要的其他材料。\n第七条 省级网信部门应当自收到申报材料之日起5个工作日内完成完备性查验。申报材料齐全的，将申报材料报送国家网信部门；申报材料不齐全的，应当退回数据处理者并一次性告知需要补充的材料。\n国家网信部门应当自收到申报材料之日起7个工作日内，确定是否受理并书面通知数据处理者。\n第八条 数据出境安全评估重点评估数据出境活动可能对国家安全、公共利益、个人或者组织合法权益带来的风险，主要包括以下事项：\n（一）数据出境的目的、范围、方式等的合法性、正当性、必要性；\n（二）境外接收方所在国家或者地区的数据安全保护政策法规和网络安全环境对出境数据安全的影响；境外接收方的数据保护水平是否达到中华人民共和国法律、行政法规的规定和强制性国家标准的要求；\n（三）出境数据的规模、范围、种类、敏感程度，出境中和出境后遭到篡改、破坏、泄露、丢失、转移或者被非法获取、非法利用等的风险；\n（四）数据安全和个人信息权益是否能够得到充分有效保障；\n（五）数据处理者与境外接收方拟订立的法律文件中是否充分约定了数据安全保护责任义务；\n（六）遵守中国法律、行政法规、部门规章情况；\n（七）国家网信部门认为需要评估的其他事项。\n第九条 数据处理者应当在与境外接收方订立的法律文件中明确约定数据安全保护责任义务，至少包括以下内容：\n（一）数据出境的目的、方式和数据范围，境外接收方处理数据的用途、方式等；\n（二）数据在境外保存地点、期限，以及达到保存期限、完成约定目的或者法律文件终止后出境数据的处理措施；\n（三）对于境外接收方将出境数据再转移给其他组织、个人的约束性要求；\n（四）境外接收方在实际控制权或者经营范围发生实质性变化，或者所在国家、地区数据安全保护政策法规和网络安全环境发生变化以及发生其他不可抗力情形导致难以保障数据安全时，应当采取的安全措施；\n（五）违反法律文件约定的数据安全保护义务的补救措施、违约责任和争议解决方式；\n（六）出境数据遭到篡改、破坏、泄露、丢失、转移或者被非法获取、非法利用等风险时，妥善开展应急处置的要求和保障个人维护其个人信息权益的途径和方式。\n第十条 国家网信部门受理申报后，根据申报情况组织国务院有关部门、省级网信部门、专门机构等进行安全评估。\n第十一条 安全评估过程中，发现数据处理者提交的申报材料不符合要求的，国家网信部门可以要求其补充或者更正。数据处理者无正当理由不补充或者更正的，国家网信部门可以终止安全评估。\n数据处理者对所提交材料的真实性负责，故意提交虚假材料的，按照评估不通过处理，并依法追究相应法律责任。\n第十二条 国家网信部门应当自向数据处理者发出书面受理通知书之日起45个工作日内完成数据出境安全评估；情况复杂或者需要补充、更正材料的，可以适当延长并告知数据处理者预计延长的时间。\n评估结果应当书面通知数据处理者。\n第十三条 数据处理者对评估结果有异议的，可以在收到评估结果15个工作日内向国家网信部门申请复评，复评结果为最终结论。\n第十四条 通过数据出境安全评估的结果有效期为2年，自评估结果出具之日起计算。在有效期内出现以下情形之一的，数据处理者应当重新申报评估：\n（一）向境外提供数据的目的、方式、范围、种类和境外接收方处理数据的用途、方式发生变化影响出境数据安全的，或者延长个人信息和重要数据境外保存期限的；\n（二）境外接收方所在国家或者地区数据安全保护政策法规和网络安全环境发生变化以及发生其他不可抗力情形、数据处理者或者境外接收方实际控制权发生变化、数据处理者与境外接收方法律文件变更等影响出境数据安全的；\n（三）出现影响出境数据安全的其他情形。\n有效期届满，需要继续开展数据出境活动的，数据处理者应当在有效期届满60个工作日前重新申报评估。\n第十五条 参与安全评估工作的相关机构和人员对在履行职责中知悉的国家秘密、个人隐私、个人信息、商业秘密、保密商务信息等数据应当依法予以保密，不得泄露或者非法向他人提供、非法使用。\n第十六条 任何组织和个人发现数据处理者违反本办法向境外提供数据的，可以向省级以上网信部门举报。\n第十七条 国家网信部门发现已经通过评估的数据出境活动在实际处理过程中不再符合数据出境安全管理要求的，应当书面通知数据处理者终止数据出境活动。数据处理者需要继续开展数据出境活动的，应当按照要求整改，整改完成后重新申报评估。\n第十八条 违反本办法规定的，依据《中华人民共和国网络安全法》、《中华人民共和国数据安全法》、《中华人民共和国个人信息保护法》等法律法规处理；构成犯罪的，依法追究刑事责任。\n第十九条 本办法所称重要数据，是指一旦遭到篡改、破坏、泄露或者非法获取、非法利用等，可能危害国家安全、经济运行、社会稳定、公共健康和安全等的数据。\n第二十条 本办法自2022年9月1日起施行。本办法施行前已经开展的数据出境活动，不符合本办法规定的，应当自本办法施行之日起6个月内完成整改。\n条款关系说明（辅助区块，非条文）\n《数据出境安全评估办法》第十九条为\u0026quot;重要数据\u0026quot;提供识别标准；《促进和规范数据跨境流动规定》第二条及《网络数据安全管理条例》第三十七条明确申报义务以监管部门告知或公开发布为前提。两者是\u0026quot;定义\u0026quot;与\u0026quot;程序\u0026quot;的关系，并非冲突；重要数据的认定权在监管部门，数据处理者不负自认义务。\n","permalink":"https://ai.intlaws.com/compliance/china/data-export-security-assessment-measures/","summary":"《数据出境安全评估办法》官方文本：国家互联网信息办公室令第 11 号，2022 年 7 月 7 日公布、2022 年 9 月 1 日起施行；确立数据出境安全评估的申报门槛、评估程序与法律文件要求。","title":"数据出境安全评估办法"},{"content":"一、问题的定位 中国数据出境采用\u0026quot;三条路径并行\u0026quot;的制度设计：数据出境安全评估、个人信息出境标准合同、个人信息保护认证。企业最先要回答的不是\u0026quot;走哪条路径\u0026quot;，而是两个前置问题：有没有重要数据、个人信息规模落在哪个区间。\n判断时必须注意规则的新旧关系。《数据出境安全评估办法》（国家互联网信息办公室令第 11 号，2022 年 7 月 7 日公布，2022 年 9 月 1 日起施行）与《个人信息出境标准合同办法》（国家互联网信息办公室令第 13 号，2023 年 2 月 24 日公布）确立了三路径框架；《促进和规范数据跨境流动规定》（国家互联网信息办公室令第 16 号，2024 年 3 月 22 日公布并施行）调整了适用门槛，其第十三条明确：上述两部办法与本规定不一致的，适用本规定。\n二、\u0026ldquo;要不要申报\u0026rdquo;：三步判断 第一步，是否属于重要数据。《促进和规范数据跨境流动规定》第二条：\u0026ldquo;未被相关部门、地区告知或者公开发布为重要数据的，数据处理者不需要作为重要数据申报数据出境安全评估。\u0026ldquo;重要数据以主管部门告知或公开发布为前提，企业应保存识别与沟通记录，不在申报材料中自行扩大范围。\n第二步，是否为关键信息基础设施运营者。同规定第七条第一项：关键信息基础设施运营者向境外提供个人信息或者重要数据的，应当通过所在地省级网信部门向国家网信部门申报安全评估。此类主体没有数量\u0026quot;安全垫\u0026rdquo;。\n第三步，非关键信息基础设施运营者的数量门槛。同条第二项：向境外提供重要数据，或者自当年 1 月 1 日起累计向境外提供 100 万人以上个人信息（不含敏感个人信息）或者 1 万人以上敏感个人信息的，应当申报安全评估。\n这里有一处容易踩错的新旧差异：《数据出境安全评估办法》第四条规定的是\u0026quot;自上年 1 月 1 日起累计向境外提供 10 万人个人信息或者 1 万人敏感个人信息\u0026rdquo;。新规把个人信息基数由 10 万人提高到 100 万人，起算点改为\u0026quot;当年 1 月 1 日\u0026quot;。数量统计的期间与范围应按新规执行，且\u0026quot;不含敏感个人信息\u0026quot;意味着敏感个人信息单独计算。\n三、\u0026ldquo;可以豁免吗\u0026rdquo;：五类免予情形 情形 条件要点 依据 非个人信息、非重要数据 国际贸易、跨境运输、学术合作、跨国生产制造和市场营销等活动中收集和产生的数据向境外提供，不包含个人信息或者重要数据 第三条 境外收集、境内加工后再出境 处理过程中没有引入境内个人信息或者重要数据 第四条 个人为一方当事人的合同必需 如跨境购物、跨境寄递、跨境汇款、跨境支付、跨境开户、机票酒店预订、签证办理、考试服务等，确需提供 第五条第一项 跨境人力资源管理必需 按依法制定的劳动规章制度和依法签订的集体合同实施，确需提供员工个人信息 第五条第二项 紧急情况与低量豁免 紧急情况下为保护自然人生命健康和财产安全确需提供；以及关键信息基础设施运营者以外的数据处理者自当年 1 月 1 日起累计向境外提供不满 10 万人个人信息（不含敏感个人信息） 第五条第三、四项 第五条第二款还明确：\u0026ldquo;前款所称向境外提供的个人信息，不包括重要数据\u0026quot;——豁免的只是个人信息出境的三项制度，重要数据出境仍回到安全评估。\n另有一条区域性便利安排：第六条规定自由贸易试验区可在国家数据分类分级保护制度框架下制定区内负面清单，经省级网络安全和信息化委员会批准后报国家网信部门、国家数据管理部门备案；区内数据处理者向境外提供负面清单外的数据，可免予申报安全评估、订立标准合同、通过保护认证。\n四、中间区间：标准合同或保护认证 超出低量豁免、又不属于评估范围的，走第二条路径。第八条：关键信息基础设施运营者以外的数据处理者，自当年 1 月 1 日起累计向境外提供 10 万人以上、不满 100 万人个人信息（不含敏感个人信息）或者不满 1 万人敏感个人信息的，应当依法与境外接收方订立个人信息出境标准合同或者通过个人信息保护认证。\n成本排序因此很清楚：能通过调整数据流设计落入低量豁免区间的，成本显著下降；但不得以拆分出境批次等方式人为规避门槛，否则监管核查时难以解释。\n五、申报流程与时限 《数据出境安全评估办法》给出了可直接用于项目排期的节点：\n先行开展风险自评估（第五条），重点评估六项：出境与境外接收方处理的目的、范围、方式的合法性正当性必要性；出境数据的规模、范围、种类、敏感程度及风险；境外接收方的责任义务与其管理、技术措施是否足以保障安全；出境中与出境后的泄露、篡改、丢失、转移等风险及维权渠道；法律文件是否充分约定数据安全保护责任义务；其他可能影响出境安全的事项。 提交材料（第六条）：申报书、数据出境风险自评估报告、与境外接收方拟订立的法律文件，以及安全评估工作需要的其他材料。 时限（第七条）：省级网信部门自收到材料之日起 5 个工作日内完成完备性查验，齐全的报送国家网信部门、不齐全的一次性告知补正；国家网信部门自收到材料之日起 7 个工作日内确定是否受理并书面通知。 评估期限（第十二条）：自发出书面受理通知书之日起 45 个工作日内完成评估，情况复杂或需补正的可适当延长并告知。 复评（第十三条）：对结果有异议的，可在收到结果 15 个工作日内申请复评，复评结果为最终结论。 六、法律文件必备的六项条款 第九条是实务中最易出问题的一环：与境外接收方订立的法律文件中应明确约定数据安全保护责任义务，至少包括——出境目的、方式和数据范围，境外接收方处理数据的用途、方式；数据在境外保存地点、期限及期满或文件终止后的处理措施；对境外接收方再转移给他人的约束性要求；境外接收方实际控制权、经营范围或所在国家（地区）政策法规与网络安全环境变化、不可抗力导致难以保障安全时应采取的措施；违约的补救措施、违约责任和争议解决方式；数据遭篡改、破坏、泄露、丢失、转移或被非法获取、利用时的应急处置要求及个人维权途径。\n提示：这六项是监管审查的直接对照表，建议按项设立独立条款，并与自评估报告表述保持一致，避免\u0026quot;报告写了、合同没写\u0026rdquo;。\n七、有效期与重新申报 新规把有效期由 2 年改为 3 年。第九条：通过安全评估的结果有效期为 3 年，自出具之日起计算；届满需继续开展且未发生重新申报情形的，可在届满前 60 个工作日内通过省级网信部门申请延长，经批准可再延长 3 年。\n有效期内出现下列情形之一的仍需重新申报（《数据出境安全评估办法》第十四条）：出境目的、方式、范围、种类或境外接收方处理数据的用途、方式发生变化影响出境数据安全，或延长境外保存期限的；境外接收方所在国家（地区）政策法规与网络安全环境变化、发生不可抗力、一方实际控制权变化、双方法律文件变更等影响出境数据安全的；其他影响出境数据安全的情形。\n八、容易被忽略的配套义务 评估或标准合同解决的是\u0026quot;出境路径\u0026quot;，出境本身的合法性基础另有一套要求。第十条：向境外提供个人信息的，应当按照法律、行政法规的规定履行告知、取得个人单独同意、进行个人信息保护影响评估等义务。第十一条进一步要求履行数据安全保护义务、采取技术与必要措施，发生或可能发生数据安全事件时采取补救措施并及时向省级以上网信部门和其他有关主管部门报告。\n常见的合规缺口：完成了安全评估申报，却没有同步更新隐私政策中的境外提供告知、没有落实单独同意机制、也没有完成个人信息保护影响评估——这三项与出境路径是并列义务，不能互相替代。\n九、实务清单 先识别重要数据：以主管部门告知或公开发布为准并留存记录，不自行扩大范围； 算清人员规模：按\u0026quot;当年 1 月 1 日起\u0026quot;与\u0026quot;不含敏感个人信息\u0026quot;的口径分别统计； 逐条核对豁免情形（第三至六条），落入豁免的留存业务实质证据； 按第五条六项完成风险自评估，并与法律文件表述一致； 法律文件按第九条六项设置条款，特别是再转移约束与争议解决； 排期与到期管理：预留 5+7 个工作日查验受理与 45 个工作日评估；届满前 60 个工作日判断是否申请延长；同步落实告知、单独同意、影响评估与安全事件报告。 结语 数据出境的合规难点，很少是\u0026quot;制度不知道\u0026quot;，而是\u0026quot;门槛算不准、证据留不住、文书对不上\u0026quot;。2024 年新规之后门槛整体放宽、路径更清晰，但申报与免予申报的边界判断责任仍在企业自己身上：判断错了不会自动获得豁免，判断对了也需要可核验的记录支撑。\n规范依据（供核对）\n《数据出境安全评估办法》，国家互联网信息办公室令第 11 号，2022 年 7 月 7 日公布，2022 年 9 月 1 日起施行。 《个人信息出境标准合同办法》，国家互联网信息办公室令第 13 号，2023 年 2 月 24 日公布。 《促进和规范数据跨境流动规定》，国家互联网信息办公室令第 16 号，2024 年 3 月 22 日公布并施行。 ","permalink":"https://ai.intlaws.com/forum/%E6%95%B0%E6%8D%AE%E5%87%BA%E5%A2%83%E5%AE%89%E5%85%A8%E8%AF%84%E4%BC%B0%E5%AE%9E%E5%8A%A1-%E7%94%B3%E6%8A%A5%E9%97%A8%E6%A7%9B%E4%B8%8E%E5%90%88%E8%A7%84%E8%B7%AF%E5%BE%84/","summary":"数据出境三步判断法与2024年新规三处关键变化：申报门槛由10万人提高至100万人、起算点改为当年1月1日、评估结果有效期由2年延长至3年并可再延长，附五类豁免情形与法律文件六项必备条款。","title":"数据出境安全评估实务：申报门槛、豁免情形与合规路径选择"},{"content":" 版本与来源（可核验）\n项目 内容 通过与公布 2024 年 8 月 30 日国务院第 40 次常务会议通过；2024 年 9 月 24 日国务院令第 790 号公布（总理李强签署） 施行日期 2025 年 1 月 1 日 现行有效 是（截至 2026-09-22） 中文原文来源(权威源) 国务院公报第 790 号:https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html ｜ 中国政府网发布页:https://app.www.gov.cn/govdata/gov/202409/30/520076/article.html 原列来源 生态环境部转载页(已改为上方国务院公报权威源) 英文译本 无官方英译本。本页英文全文已完成：由本网据官方中文文本翻译并逐条交叉校核，标注为非官方译本、仅供参考 → English 校对记录 2026-09-22 抓取官方页面；共 64 条、9 章，条号连续、无缺号。\n2026-09-22 审查整改(Prof. Xu 第二批):经程序化逐条全文比对,发现第四十二条正文缺失(页面仅存条标题),已按国务院公报第 790 号逐字补入;并核对该条与第五十五条(违反第四十二条的处罚情形)的引用关系。 第一章 总 则 第一条 为了规范网络数据处理活动，保障网络数据安全，促进网络数据依法合理有效利用，保护个人、组织的合法权益，维护国家安全和公共利益，根据《中华人民共和国网络安全法》、《中华人民共和国数据安全法》、《中华人民共和国个人信息保护法》等法律，制定本条例。\n第二条 在中华人民共和国境内开展网络数据处理活动及其安全监督管理，适用本条例。\n在中华人民共和国境外处理中华人民共和国境内自然人个人信息的活动，符合《中华人民共和国个人信息保护法》第三条第二款规定情形的，也适用本条例。\n在中华人民共和国境外开展网络数据处理活动，损害中华人民共和国国家安全、公共利益或者公民、组织合法权益的，依法追究法律责任。\n第三条 网络数据安全管理工作坚持中国共产党的领导，贯彻总体国家安全观，统筹促进网络数据开发利用与保障网络数据安全。\n第四条 国家鼓励网络数据在各行业、各领域的创新应用，加强网络数据安全防护能力建设，支持网络数据相关技术、产品、服务创新，开展网络数据安全宣传教育和人才培养，促进网络数据开发利用和产业发展。\n第五条 国家根据网络数据在经济社会发展中的重要程度，以及一旦遭到篡改、破坏、泄露或者非法获取、非法利用，对国家安全、公共利益或者个人、组织合法权益造成的危害程度，对网络数据实行分类分级保护。\n第六条 国家积极参与网络数据安全相关国际规则和标准的制定，促进国际交流与合作。\n第七条 国家支持相关行业组织按照章程，制定网络数据安全行为规范，加强行业自律，指导会员加强网络数据安全保护，提高网络数据安全保护水平，促进行业健康发展。\n第二章 一般规定 第八条 任何个人、组织不得利用网络数据从事非法活动，不得从事窃取或者以其他非法方式获取网络数据、非法出售或者非法向他人提供网络数据等非法网络数据处理活动。\n任何个人、组织不得提供专门用于从事前款非法活动的程序、工具；明知他人从事前款非法活动的，不得为其提供互联网接入、服务器托管、网络存储、通讯传输等技术支持，或者提供广告推广、支付结算等帮助。\n第九条 网络数据处理者应当依照法律、行政法规的规定和国家标准的强制性要求，在网络安全等级保护的基础上，加强网络数据安全防护，建立健全网络数据安全管理制度，采取加密、备份、访问控制、安全认证等技术措施和其他必要措施，保护网络数据免遭篡改、破坏、泄露或者非法获取、非法利用，处置网络数据安全事件，防范针对和利用网络数据实施的违法犯罪活动，并对所处理网络数据的安全承担主体责任。\n第十条 网络数据处理者提供的网络产品、服务应当符合相关国家标准的强制性要求；发现网络产品、服务存在安全缺陷、漏洞等风险时，应当立即采取补救措施，按照规定及时告知用户并向有关主管部门报告；涉及危害国家安全、公共利益的，网络数据处理者还应当在24小时内向有关主管部门报告。\n第十一条 网络数据处理者应当建立健全网络数据安全事件应急预案，发生网络数据安全事件时，应当立即启动预案，采取措施防止危害扩大，消除安全隐患，并按照规定向有关主管部门报告。\n网络数据安全事件对个人、组织合法权益造成危害的，网络数据处理者应当及时将安全事件和风险情况、危害后果、已经采取的补救措施等，以电话、短信、即时通信工具、电子邮件或者公告等方式通知利害关系人；法律、行政法规规定可以不通知的，从其规定。网络数据处理者在处置网络数据安全事件过程中发现涉嫌违法犯罪线索的，应当按照规定向公安机关、国家安全机关报案，并配合开展侦查、调查和处置工作。\n第十二条 网络数据处理者向其他网络数据处理者提供、委托处理个人信息和重要数据的，应当通过合同等与网络数据接收方约定处理目的、方式、范围以及安全保护义务等，并对网络数据接收方履行义务的情况进行监督。向其他网络数据处理者提供、委托处理个人信息和重要数据的处理情况记录，应当至少保存3年。\n网络数据接收方应当履行网络数据安全保护义务，并按照约定的目的、方式、范围等处理个人信息和重要数据。\n两个以上的网络数据处理者共同决定个人信息和重要数据的处理目的和处理方式的，应当约定各自的权利和义务。\n第十三条 网络数据处理者开展网络数据处理活动，影响或者可能影响国家安全的，应当按照国家有关规定进行国家安全审查。\n第十四条 网络数据处理者因合并、分立、解散、破产等原因需要转移网络数据的，网络数据接收方应当继续履行网络数据安全保护义务。\n第十五条 国家机关委托他人建设、运行、维护电子政务系统，存储、加工政务数据，应当按照国家有关规定经过严格的批准程序，明确受托方的网络数据处理权限、保护责任等，监督受托方履行网络数据安全保护义务。\n第十六条 网络数据处理者为国家机关、关键信息基础设施运营者提供服务，或者参与其他公共基础设施、公共服务系统建设、运行、维护的，应当依照法律、法规的规定和合同约定履行网络数据安全保护义务，提供安全、稳定、持续的服务。\n前款规定的网络数据处理者未经委托方同意，不得访问、获取、留存、使用、泄露或者向他人提供网络数据，不得对网络数据进行关联分析。\n第十七条 为国家机关提供服务的信息系统应当参照电子政务系统的管理要求加强网络数据安全管理，保障网络数据安全。\n第十八条 网络数据处理者使用自动化工具访问、收集网络数据，应当评估对网络服务带来的影响，不得非法侵入他人网络，不得干扰网络服务正常运行。\n第十九条 提供生成式人工智能服务的网络数据处理者应当加强对训练数据和训练数据处理活动的安全管理，采取有效措施防范和处置网络数据安全风险。\n第二十条 面向社会提供产品、服务的网络数据处理者应当接受社会监督，建立便捷的网络数据安全投诉、举报渠道，公布投诉、举报方式等信息，及时受理并处理网络数据安全投诉、举报。\n第三章 个人信息保护 第二十一条 网络数据处理者在处理个人信息前，通过制定个人信息处理规则的方式依法向个人告知的，个人信息处理规则应当集中公开展示、易于访问并置于醒目位置，内容明确具体、清晰易懂，包括但不限于下列内容：\n（一）网络数据处理者的名称或者姓名和联系方式；\n（二）处理个人信息的目的、方式、种类，处理敏感个人信息的必要性以及对个人权益的影响；\n（三）个人信息保存期限和到期后的处理方式，保存期限难以确定的，应当明确保存期限的确定方法；\n（四）个人查阅、复制、转移、更正、补充、删除、限制处理个人信息以及注销账号、撤回同意的方法和途径等。\n网络数据处理者按照前款规定向个人告知收集和向其他网络数据处理者提供个人信息的目的、方式、种类以及网络数据接收方信息的，应当以清单等形式予以列明。网络数据处理者处理不满十四周岁未成年人个人信息的，还应当制定专门的个人信息处理规则。\n第二十二条 网络数据处理者基于个人同意处理个人信息的，应当遵守下列规定：\n（一）收集个人信息为提供产品或者服务所必需，不得超范围收集个人信息，不得通过误导、欺诈、胁迫等方式取得个人同意；\n（二）处理生物识别、宗教信仰、特定身份、医疗健康、金融账户、行踪轨迹等敏感个人信息的，应当取得个人的单独同意；\n（三）处理不满十四周岁未成年人个人信息的，应当取得未成年人的父母或者其他监护人的同意；\n（四）不得超出个人同意的个人信息处理目的、方式、种类、保存期限处理个人信息；\n（五）不得在个人明确表示不同意处理其个人信息后，频繁征求同意；\n（六）个人信息的处理目的、方式、种类发生变更的，应当重新取得个人同意。\n法律、行政法规规定处理敏感个人信息应当取得书面同意的，从其规定。\n第二十三条 个人请求查阅、复制、更正、补充、删除、限制处理其个人信息，或者个人注销账号、撤回同意的，网络数据处理者应当及时受理，并提供便捷的支持个人行使权利的方法和途径，不得设置不合理条件限制个人的合理请求。\n第二十四条 因使用自动化采集技术等无法避免采集到非必要个人信息或者未依法取得个人同意的个人信息，以及个人注销账号的，网络数据处理者应当删除个人信息或者进行匿名化处理。法律、行政法规规定的保存期限未届满，或者删除、匿名化处理个人信息从技术上难以实现的，网络数据处理者应当停止除存储和采取必要的安全保护措施之外的处理。\n第二十五条 对符合下列条件的个人信息转移请求，网络数据处理者应当为个人指定的其他网络数据处理者访问、获取有关个人信息提供途径：\n（一）能够验证请求人的真实身份；\n（二）请求转移的是本人同意提供的或者基于合同收集的个人信息；\n（三）转移个人信息具备技术可行性；\n（四）转移个人信息不损害他人合法权益。\n请求转移个人信息次数等明显超出合理范围的，网络数据处理者可以根据转移个人信息的成本收取必要费用。\n第二十六条 中华人民共和国境外网络数据处理者处理境内自然人个人信息，依照《中华人民共和国个人信息保护法》第五十三条规定在境内设立专门机构或者指定代表的，应当将有关机构的名称或者代表的姓名、联系方式等报送所在地设区的市级网信部门；网信部门应当及时通报同级有关主管部门。\n第二十七条 网络数据处理者应当定期自行或者委托专业机构对其处理个人信息遵守法律、行政法规的情况进行合规审计。\n第二十八条 网络数据处理者处理1000万人以上个人信息的，还应当遵守本条例第三十条、第三十二条对处理重要数据的网络数据处理者（以下简称重要数据的处理者）作出的规定。\n第四章 重要数据安全 第二十九条 国家数据安全工作协调机制统筹协调有关部门制定重要数据目录，加强对重要数据的保护。各地区、各部门应当按照数据分类分级保护制度，确定本地区、本部门以及相关行业、领域的重要数据具体目录，对列入目录的网络数据进行重点保护。\n网络数据处理者应当按照国家有关规定识别、申报重要数据。对确认为重要数据的，相关地区、部门应当及时向网络数据处理者告知或者公开发布。网络数据处理者应当履行网络数据安全保护责任。\n国家鼓励网络数据处理者使用数据标签标识等技术和产品，提高重要数据安全管理水平。\n第三十条 重要数据的处理者应当明确网络数据安全负责人和网络数据安全管理机构。网络数据安全管理机构应当履行下列网络数据安全保护责任：\n（一）制定实施网络数据安全管理制度、操作规程和网络数据安全事件应急预案；\n（二）定期组织开展网络数据安全风险监测、风险评估、应急演练、宣传教育培训等活动，及时处置网络数据安全风险和事件；\n（三）受理并处理网络数据安全投诉、举报。\n网络数据安全负责人应当具备网络数据安全专业知识和相关管理工作经历，由网络数据处理者管理层成员担任，有权直接向有关主管部门报告网络数据安全情况。\n掌握有关主管部门规定的特定种类、规模的重要数据的网络数据处理者，应当对网络数据安全负责人和关键岗位的人员进行安全背景审查，加强相关人员培训。审查时，可以申请公安机关、国家安全机关协助。\n第三十一条 重要数据的处理者提供、委托处理、共同处理重要数据前，应当进行风险评估，但是属于履行法定职责或者法定义务的除外。\n风险评估应当重点评估下列内容：\n（一）提供、委托处理、共同处理网络数据，以及网络数据接收方处理网络数据的目的、方式、范围等是否合法、正当、必要；\n（二）提供、委托处理、共同处理的网络数据遭到篡改、破坏、泄露或者非法获取、非法利用的风险，以及对国家安全、公共利益或者个人、组织合法权益带来的风险；\n（三）网络数据接收方的诚信、守法等情况；\n（四）与网络数据接收方订立或者拟订立的相关合同中关于网络数据安全的要求能否有效约束网络数据接收方履行网络数据安全保护义务；\n（五）采取或者拟采取的技术和管理措施等能否有效防范网络数据遭到篡改、破坏、泄露或者非法获取、非法利用等风险；\n（六）有关主管部门规定的其他评估内容。\n第三十二条 重要数据的处理者因合并、分立、解散、破产等可能影响重要数据安全的，应当采取措施保障网络数据安全，并向省级以上有关主管部门报告重要数据处置方案、接收方的名称或者姓名和联系方式等；主管部门不明确的，应当向省级以上数据安全工作协调机制报告。\n第三十三条 重要数据的处理者应当每年度对其网络数据处理活动开展风险评估，并向省级以上有关主管部门报送风险评估报告，有关主管部门应当及时通报同级网信部门、公安机关。\n风险评估报告应当包括下列内容：\n（一）网络数据处理者基本信息、网络数据安全管理机构信息、网络数据安全负责人姓名和联系方式等；\n（二）处理重要数据的目的、种类、数量、方式、范围、存储期限、存储地点等，开展网络数据处理活动的情况，不包括网络数据内容本身；\n（三）网络数据安全管理制度及实施情况，加密、备份、标签标识、访问控制、安全认证等技术措施和其他必要措施及其有效性；\n（四）发现的网络数据安全风险，发生的网络数据安全事件及处置情况；\n（五）提供、委托处理、共同处理重要数据的风险评估情况；\n（六）网络数据出境情况；\n（七）有关主管部门规定的其他报告内容。\n处理重要数据的大型网络平台服务提供者报送的风险评估报告，除包括前款规定的内容外，还应当充分说明关键业务和供应链网络数据安全等情况。\n重要数据的处理者存在可能危害国家安全的重要数据处理活动的，省级以上有关主管部门应当责令其采取整改或者停止处理重要数据等措施。重要数据的处理者应当按照有关要求立即采取措施。\n第五章 网络数据跨境安全管理 第三十四条 国家网信部门统筹协调有关部门建立国家数据出境安全管理专项工作机制，研究制定国家网络数据出境安全管理相关政策，协调处理网络数据出境安全重大事项。\n第三十五条 符合下列条件之一的，网络数据处理者可以向境外提供个人信息：\n（一）通过国家网信部门组织的数据出境安全评估；\n（二）按照国家网信部门的规定经专业机构进行个人信息保护认证；\n（三）符合国家网信部门制定的关于个人信息出境标准合同的规定；\n（四）为订立、履行个人作为一方当事人的合同，确需向境外提供个人信息；\n（五）按照依法制定的劳动规章制度和依法签订的集体合同实施跨境人力资源管理，确需向境外提供员工个人信息；\n（六）为履行法定职责或者法定义务，确需向境外提供个人信息；\n（七）紧急情况下为保护自然人的生命健康和财产安全，确需向境外提供个人信息;\n（八）法律、行政法规或者国家网信部门规定的其他条件。\n第三十六条 中华人民共和国缔结或者参加的国际条约、协定对向中华人民共和国境外提供个人信息的条件等有规定的，可以按照其规定执行。\n第三十七条 网络数据处理者在中华人民共和国境内运营中收集和产生的重要数据确需向境外提供的，应当通过国家网信部门组织的数据出境安全评估。网络数据处理者按照国家有关规定识别、申报重要数据，但未被相关地区、部门告知或者公开发布为重要数据的，不需要将其作为重要数据申报数据出境安全评估。\n第三十八条 通过数据出境安全评估后，网络数据处理者向境外提供个人信息和重要数据的，不得超出评估时明确的数据出境目的、方式、范围和种类、规模等。\n第三十九条 国家采取措施，防范、处置网络数据跨境安全风险和威胁。任何个人、组织不得提供专门用于破坏、避开技术措施的程序、工具等；明知他人从事破坏、避开技术措施等活动的，不得为其提供技术支持或者帮助。\n第六章 网络平台服务提供者义务 第四十条 网络平台服务提供者应当通过平台规则或者合同等明确接入其平台的第三方产品和服务提供者的网络数据安全保护义务，督促第三方产品和服务提供者加强网络数据安全管理。\n预装应用程序的智能终端等设备生产者，适用前款规定。\n第三方产品和服务提供者违反法律、行政法规的规定或者平台规则、合同约定开展网络数据处理活动，对用户造成损害的，网络平台服务提供者、第三方产品和服务提供者、预装应用程序的智能终端等设备生产者应当依法承担相应责任。\n国家鼓励保险公司开发网络数据损害赔偿责任险种，鼓励网络平台服务提供者、预装应用程序的智能终端等设备生产者投保。\n第四十一条 提供应用程序分发服务的网络平台服务提供者，应当建立应用程序核验规则并开展网络数据安全相关核验。发现待分发或者已分发的应用程序不符合法律、行政法规的规定或者国家标准的强制性要求的，应当采取警示、不予分发、暂停分发或者终止分发等措施。\n第四十二条\n网络平台服务提供者通过自动化决策方式向个人进行信息推送的，应当设置易于理解、便于访问和操作的个性化推荐关闭选项，为用户提供拒绝接收推送信息、删除针对其个人特征的用户标签等功能。\n第四十三条 国家推进网络身份认证公共服务建设，按照政府引导、用户自愿原则进行推广应用。\n鼓励网络平台服务提供者支持用户使用国家网络身份认证公共服务登记、核验真实身份信息。\n第四十四条 大型网络平台服务提供者应当每年度发布个人信息保护社会责任报告，报告内容包括但不限于个人信息保护措施和成效、个人行使权利的申请受理情况、主要由外部成员组成的个人信息保护监督机构履行职责情况等。\n第四十五条 大型网络平台服务提供者跨境提供网络数据，应当遵守国家数据跨境安全管理要求，健全相关技术和管理措施，防范网络数据跨境安全风险。\n第四十六条 大型网络平台服务提供者不得利用网络数据、算法以及平台规则等从事下列活动：\n（一）通过误导、欺诈、胁迫等方式处理用户在平台上产生的网络数据；\n（二）无正当理由限制用户访问、使用其在平台上产生的网络数据；\n（三）对用户实施不合理的差别待遇，损害用户合法权益；\n（四）法律、行政法规禁止的其他活动。\n第七章 监督管理 第四十七条 国家网信部门负责统筹协调网络数据安全和相关监督管理工作。\n公安机关、国家安全机关依照有关法律、行政法规和本条例的规定，在各自职责范围内承担网络数据安全监督管理职责，依法防范和打击危害网络数据安全的违法犯罪活动。\n国家数据管理部门在具体承担数据管理工作中履行相应的网络数据安全职责。\n各地区、各部门对本地区、本部门工作中收集和产生的网络数据及网络数据安全负责。\n第四十八条 各有关主管部门承担本行业、本领域网络数据安全监督管理职责，应当明确本行业、本领域网络数据安全保护工作机构，统筹制定并组织实施本行业、本领域网络数据安全事件应急预案，定期组织开展本行业、本领域网络数据安全风险评估，对网络数据处理者履行网络数据安全保护义务情况进行监督检查，指导督促网络数据处理者及时对存在的风险隐患进行整改。\n第四十九条 国家网信部门统筹协调有关主管部门及时汇总、研判、共享、发布网络数据安全风险相关信息，加强网络数据安全信息共享、网络数据安全风险和威胁监测预警以及网络数据安全事件应急处置工作。\n第五十条 有关主管部门可以采取下列措施对网络数据安全进行监督检查：\n（一）要求网络数据处理者及其相关人员就监督检查事项作出说明；\n（二）查阅、复制与网络数据安全有关的文件、记录；\n（三）检查网络数据安全措施运行情况；\n（四）检查与网络数据处理活动有关的设备、物品；\n（五）法律、行政法规规定的其他必要措施。\n网络数据处理者应当对有关主管部门依法开展的网络数据安全监督检查予以配合。\n第五十一条 有关主管部门开展网络数据安全监督检查，应当客观公正，不得向被检查单位收取费用。\n有关主管部门在网络数据安全监督检查中不得访问、收集与网络数据安全无关的业务信息，获取的信息只能用于维护网络数据安全的需要，不得用于其他用途。\n有关主管部门发现网络数据处理者的网络数据处理活动存在较大安全风险的，可以按照规定的权限和程序要求网络数据处理者暂停相关服务、修改平台规则、完善技术措施等，消除网络数据安全隐患。\n第五十二条 有关主管部门在开展网络数据安全监督检查时，应当加强协同配合、信息沟通，合理确定检查频次和检查方式，避免不必要的检查和交叉重复检查。\n个人信息保护合规审计、重要数据风险评估、重要数据出境安全评估等应当加强衔接，避免重复评估、审计。重要数据风险评估和网络安全等级测评的内容重合的，相关结果可以互相采信。\n第五十三条 有关主管部门及其工作人员对在履行职责中知悉的个人隐私、个人信息、商业秘密、保密商务信息等网络数据应当依法予以保密，不得泄露或者非法向他人提供。\n第五十四条 境外的组织、个人从事危害中华人民共和国国家安全、公共利益，或者侵害中华人民共和国公民的个人信息权益的网络数据处理活动的，国家网信部门会同有关主管部门可以依法采取相应的必要措施。\n第八章 法律责任 第五十五条 违反本条例第十二条、第十六条至第二十条、第二十二条、第四十条第一款和第二款、第四十一条、第四十二条规定的，由网信、电信、公安等主管部门依据各自职责责令改正，给予警告，没收违法所得；拒不改正或者情节严重的，处100万元以下罚款，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员可以处1万元以上10万元以下罚款。\n第五十六条 违反本条例第十三条规定的，由网信、电信、公安、国家安全等主管部门依据各自职责责令改正，给予警告，可以并处10万元以上100万元以下罚款，对直接负责的主管人员和其他直接责任人员可以处1万元以上10万元以下罚款；拒不改正或者情节严重的，处100万元以上1000万元以下罚款，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处10万元以上100万元以下罚款。\n第五十七条 违反本条例第二十九条第二款、第三十条第二款和第三款、第三十一条、第三十二条规定的，由网信、电信、公安等主管部门依据各自职责责令改正，给予警告，可以并处5万元以上50万元以下罚款，对直接负责的主管人员和其他直接责任人员可以处1万元以上10万元以下罚款；拒不改正或者造成大量数据泄露等严重后果的，处50万元以上200万元以下罚款，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处5万元以上20万元以下罚款。\n第五十八条 违反本条例其他有关规定的，由有关主管部门依照《中华人民共和国网络安全法》、《中华人民共和国数据安全法》、《中华人民共和国个人信息保护法》等法律的有关规定追究法律责任。\n第五十九条 网络数据处理者存在主动消除或者减轻违法行为危害后果、违法行为轻微并及时改正且没有造成危害后果或者初次违法且危害后果轻微并及时改正等情形的，依照《中华人民共和国行政处罚法》的规定从轻、减轻或者不予行政处罚。\n第六十条 国家机关不履行本条例规定的网络数据安全保护义务的，由其上级机关或者有关主管部门责令改正；对直接负责的主管人员和其他直接责任人员依法给予处分。\n第六十一条 违反本条例规定，给他人造成损害的，依法承担民事责任；构成违反治安管理行为的，依法给予治安管理处罚；构成犯罪的，依法追究刑事责任。\n第九章 附 则 第六十二条 本条例下列用语的含义：\n（一）网络数据，是指通过网络处理和产生的各种电子数据。\n（二）网络数据处理活动，是指网络数据的收集、存储、使用、加工、传输、提供、公开、删除等活动。\n（三）网络数据处理者，是指在网络数据处理活动中自主决定处理目的和处理方式的个人、组织。\n（四）重要数据，是指特定领域、特定群体、特定区域或者达到一定精度和规模，一旦遭到篡改、破坏、泄露或者非法获取、非法利用，可能直接危害国家安全、经济运行、社会稳定、公共健康和安全的数据。\n（五）委托处理，是指网络数据处理者委托个人、组织按照约定的目的和方式开展的网络数据处理活动。\n（六）共同处理，是指两个以上的网络数据处理者共同决定网络数据的处理目的和处理方式的网络数据处理活动。\n（七）单独同意，是指个人针对其个人信息进行特定处理而专门作出具体、明确的同意。\n（八）大型网络平台，是指注册用户5000万以上或者月活跃用户1000万以上，业务类型复杂，网络数据处理活动对国家安全、经济运行、国计民生等具有重要影响的网络平台。\n第六十三条 开展核心数据的网络数据处理活动，按照国家有关规定执行。\n自然人因个人或者家庭事务处理个人信息的，不适用本条例。\n开展涉及国家秘密、工作秘密的网络数据处理活动，适用《中华人民共和国保守国家秘密法》等法律、行政法规的规定。\n第六十四条 本条例自2025年1月1日起施行。\n","permalink":"https://ai.intlaws.com/compliance/china/network-data-security-regulations/","summary":"《网络数据安全管理条例》官方文本：9 章 64 条，2024 年 8 月 30 日国务院第 40 次常务会议通过、2024 年 9 月 24 日国务院令第 790 号公布、2025 年 1 月 1 日起施行。中国数据安全领域首部行政法规。","title":"网络数据安全管理条例"},{"content":" 版本与来源（可核验）\n项目 内容 通过与公布 2021 年 8 月 20 日第十三届全国人民代表大会常务委员会第三十次会议通过 施行日期 2021 年 11 月 1 日 现行有效 是（截至 2026-09-22 未经修订） 中文原文来源 国家互联网信息办公室官方文本：https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm 英文译本来源 全国人民代表大会官网英文版「Laws（Translation for Reference Only）」：http://en.npc.gov.cn.cdurl.cn/2021-12/29/c_694559.htm （正文分 3 页，同名 _2、_3） 译文性质 官网站点发布译本，页面自标「Translation for Reference Only」（仅供参考，不作权威解释） 校对记录 2026-09-22 抓取官方页面；本法 8 章 74 条，中英条目逐一对应、无缺号；章、节标题按官方中文原文节点插入 第一章 总 则 第一条 为了保护个人信息权益，规范个人信息处理活动，促进个人信息合理利用，根据宪法，制定本法。\n第二条 自然人的个人信息受法律保护，任何组织、个人不得侵害自然人的个人信息权益。\n第三条 在中华人民共和国境内处理自然人个人信息的活动，适用本法。\n在中华人民共和国境外处理中华人民共和国境内自然人个人信息的活动，有下列情形之一的，也适用本法：\n（一）以向境内自然人提供产品或者服务为目的；\n（二）分析、评估境内自然人的行为；\n（三）法律、行政法规规定的其他情形。\n第四条 个人信息是以电子或者其他方式记录的与已识别或者可识别的自然人有关的各种信息，不包括匿名化处理后的信息。\n个人信息的处理包括个人信息的收集、存储、使用、加工、传输、提供、公开、删除等。\n第五条 处理个人信息应当遵循合法、正当、必要和诚信原则，不得通过误导、欺诈、胁迫等方式处理个人信息。\n第六条 处理个人信息应当具有明确、合理的目的，并应当与处理目的直接相关，采取对个人权益影响最小的方式。\n收集个人信息，应当限于实现处理目的的最小范围，不得过度收集个人信息。\n第七条 处理个人信息应当遵循公开、透明原则，公开个人信息处理规则，明示处理的目的、方式和范围。\n第八条 处理个人信息应当保证个人信息的质量，避免因个人信息不准确、不完整对个人权益造成不利影响。\n第九条 个人信息处理者应当对其个人信息处理活动负责，并采取必要措施保障所处理的个人信息的安全。\n第十条 任何组织、个人不得非法收集、使用、加工、传输他人个人信息，不得非法买卖、提供或者公开他人个人信息；不得从事危害国家安全、公共利益的个人信息处理活动。\n第十一条 国家建立健全个人信息保护制度，预防和惩治侵害个人信息权益的行为，加强个人信息保护宣传教育，推动形成政府、企业、相关社会组织、公众共同参与个人信息保护的良好环境。\n第十二条 国家积极参与个人信息保护国际规则的制定，促进个人信息保护方面的国际交流与合作，推动与其他国家、地区、国际组织之间的个人信息保护规则、标准等互认。\n第二章 个人信息处理规则 第十三条 符合下列情形之一的，个人信息处理者方可处理个人信息：\n（一）取得个人的同意；\n（二）为订立、履行个人作为一方当事人的合同所必需，或者按照依法制定的劳动规章制度和依法签订的集体合同实施人力资源管理所必需；\n（三）为履行法定职责或者法定义务所必需；\n（四）为应对突发公共卫生事件，或者紧急情况下为保护自然人的生命健康和财产安全所必需；\n（五）为公共利益实施新闻报道、舆论监督等行为，在合理的范围内处理个人信息；\n（六）依照本法规定在合理的范围内处理个人自行公开或者其他已经合法公开的个人信息；\n（七）法律、行政法规规定的其他情形。\n依照本法其他有关规定，处理个人信息应当取得个人同意，但是有前款第二项至第七项规定情形的，不需取得个人同意。\n第十四条 基于个人同意处理个人信息的，该同意应当由个人在充分知情的前提下自愿、明确作出。法律、行政法规规定处理个人信息应当取得个人单独同意或者书面同意的，从其规定。\n个人信息的处理目的、处理方式和处理的个人信息种类发生变更的，应当重新取得个人同意。\n第十五条 基于个人同意处理个人信息的，个人有权撤回其同意。个人信息处理者应当提供便捷的撤回同意的方式。\n个人撤回同意，不影响撤回前基于个人同意已进行的个人信息处理活动的效力。\n第十六条 个人信息处理者不得以个人不同意处理其个人信息或者撤回同意为由，拒绝提供产品或者服务；处理个人信息属于提供产品或者服务所必需的除外。\n第十七条 个人信息处理者在处理个人信息前，应当以显著方式、清晰易懂的语言真实、准确、完整地向个人告知下列事项：\n（一）个人信息处理者的名称或者姓名和联系方式；\n（二）个人信息的处理目的、处理方式，处理的个人信息种类、保存期限；\n（三）个人行使本法规定权利的方式和程序；\n（四）法律、行政法规规定应当告知的其他事项。\n前款规定事项发生变更的，应当将变更部分告知个人。\n个人信息处理者通过制定个人信息处理规则的方式告知第一款规定事项的，处理规则应当公开，并且便于查阅和保存。\n第十八条 个人信息处理者处理个人信息，有法律、行政法规规定应当保密或者不需要告知的情形的，可以不向个人告知前条第一款规定的事项。\n紧急情况下为保护自然人的生命健康和财产安全无法及时向个人告知的，个人信息处理者应当在紧急情况消除后及时告知。\n第十九条 除法律、行政法规另有规定外，个人信息的保存期限应当为实现处理目的所必要的最短时间。\n第二十条 两个以上的个人信息处理者共同决定个人信息的处理目的和处理方式的，应当约定各自的权利和义务。但是，该约定不影响个人向其中任何一个个人信息处理者要求行使本法规定的权利。\n个人信息处理者共同处理个人信息，侵害个人信息权益造成损害的，应当依法承担连带责任。\n第二十一条 个人信息处理者委托处理个人信息的，应当与受托人约定委托处理的目的、期限、处理方式、个人信息的种类、保护措施以及双方的权利和义务等，并对受托人的个人信息处理活动进行监督。\n受托人应当按照约定处理个人信息，不得超出约定的处理目的、处理方式等处理个人信息；委托合同不生效、无效、被撤销或者终止的，受托人应当将个人信息返还个人信息处理者或者予以删除，不得保留。\n未经个人信息处理者同意，受托人不得转委托他人处理个人信息。\n第二十二条 个人信息处理者因合并、分立、解散、被宣告破产等原因需要转移个人信息的，应当向个人告知接收方的名称或者姓名和联系方式。接收方应当继续履行个人信息处理者的义务。接收方变更原先的处理目的、处理方式的，应当依照本法规定重新取得个人同意。\n第二十三条 个人信息处理者向其他个人信息处理者提供其处理的个人信息的，应当向个人告知接收方的名称或者姓名、联系方式、处理目的、处理方式和个人信息的种类，并取得个人的单独同意。接收方应当在上述处理目的、处理方式和个人信息的种类等范围内处理个人信息。接收方变更原先的处理目的、处理方式的，应当依照本法规定重新取得个人同意。\n第二十四条 个人信息处理者利用个人信息进行自动化决策，应当保证决策的透明度和结果公平、公正，不得对个人在交易价格等交易条件上实行不合理的差别待遇。\n通过自动化决策方式向个人进行信息推送、商业营销，应当同时提供不针对其个人特征的选项，或者向个人提供便捷的拒绝方式。\n通过自动化决策方式作出对个人权益有重大影响的决定，个人有权要求个人信息处理者予以说明，并有权拒绝个人信息处理者仅通过自动化决策的方式作出决定。\n第二十五条 个人信息处理者不得公开其处理的个人信息，取得个人单独同意的除外。\n第二十六条 在公共场所安装图像采集、个人身份识别设备，应当为维护公共安全所必需，遵守国家有关规定，并设置显著的提示标识。所收集的个人图像、身份识别信息只能用于维护公共安全的目的，不得用于其他目的；取得个人单独同意的除外。\n第二十七条 个人信息处理者可以在合理的范围内处理个人自行公开或者其他已经合法公开的个人信息；个人明确拒绝的除外。个人信息处理者处理已公开的个人信息，对个人权益有重大影响的，应当依照本法规定取得个人同意。\n第二节 敏感个人信息的处理规则\n第二十八条 敏感个人信息是一旦泄露或者非法使用，容易导致自然人的人格尊严受到侵害或者人身、财产安全受到危害的个人信息，包括生物识别、宗教信仰、特定身份、医疗健康、金融账户、行踪轨迹等信息，以及不满十四周岁未成年人的个人信息。\n只有在具有特定的目的和充分的必要性，并采取严格保护措施的情形下，个人信息处理者方可处理敏感个人信息。\n第二十九条 处理敏感个人信息应当取得个人的单独同意；法律、行政法规规定处理敏感个人信息应当取得书面同意的，从其规定。\n第三十条 个人信息处理者处理敏感个人信息的，除本法第十七条第一款规定的事项外，还应当向个人告知处理敏感个人信息的必要性以及对个人权益的影响；依照本法规定可以不向个人告知的除外。\n第三十一条 个人信息处理者处理不满十四周岁未成年人个人信息的，应当取得未成年人的父母或者其他监护人的同意。\n个人信息处理者处理不满十四周岁未成年人个人信息的，应当制定专门的个人信息处理规则。\n第三十二条 法律、行政法规对处理敏感个人信息规定应当取得相关行政许可或者作出其他限制的，从其规定。\n第三节 国家机关处理个人信息的特别规定\n第三十三条 国家机关处理个人信息的活动，适用本法；本节有特别规定的，适用本节规定。\n第三十四条 国家机关为履行法定职责处理个人信息，应当依照法律、行政法规规定的权限、程序进行，不得超出履行法定职责所必需的范围和限度。\n第三十五条 国家机关为履行法定职责处理个人信息，应当依照本法规定履行告知义务；有本法第十八条第一款规定的情形，或者告知将妨碍国家机关履行法定职责的除外。\n第三十六条 国家机关处理的个人信息应当在中华人民共和国境内存储；确需向境外提供的，应当进行安全评估。安全评估可以要求有关部门提供支持与协助。\n第三十七条 法律、法规授权的具有管理公共事务职能的组织为履行法定职责处理个人信息，适用本法关于国家机关处理个人信息的规定。\n第三章 个人信息跨境提供的规则 第三十八条 个人信息处理者因业务等需要，确需向中华人民共和国境外提供个人信息的，应当具备下列条件之一：\n（一）依照本法第四十条的规定通过国家网信部门组织的安全评估；\n（二）按照国家网信部门的规定经专业机构进行个人信息保护认证；\n（三）按照国家网信部门制定的标准合同与境外接收方订立合同，约定双方的权利和义务；\n（四）法律、行政法规或者国家网信部门规定的其他条件。\n中华人民共和国缔结或者参加的国际条约、协定对向中华人民共和国境外提供个人信息的条件等有规定的，可以按照其规定执行。\n个人信息处理者应当采取必要措施，保障境外接收方处理个人信息的活动达到本法规定的个人信息保护标准。\n第三十九条 个人信息处理者向中华人民共和国境外提供个人信息的，应当向个人告知境外接收方的名称或者姓名、联系方式、处理目的、处理方式、个人信息的种类以及个人向境外接收方行使本法规定权利的方式和程序等事项，并取得个人的单独同意。\n第四十条 关键信息基础设施运营者和处理个人信息达到国家网信部门规定数量的个人信息处理者，应当将在中华人民共和国境内收集和产生的个人信息存储在境内。确需向境外提供的，应当通过国家网信部门组织的安全评估；法律、行政法规和国家网信部门规定可以不进行安全评估的，从其规定。\n第四十一条 中华人民共和国主管机关根据有关法律和中华人民共和国缔结或者参加的国际条约、协定，或者按照平等互惠原则，处理外国司法或者执法机构关于提供存储于境内个人信息的请求。非经中华人民共和国主管机关批准，个人信息处理者不得向外国司法或者执法机构提供存储于中华人民共和国境内的个人信息。\n第四十二条 境外的组织、个人从事侵害中华人民共和国公民的个人信息权益，或者危害中华人民共和国国家安全、公共利益的个人信息处理活动的，国家网信部门可以将其列入限制或者禁止个人信息提供清单，予以公告，并采取限制或者禁止向其提供个人信息等措施。\n第四十三条 任何国家或者地区在个人信息保护方面对中华人民共和国采取歧视性的禁止、限制或者其他类似措施的，中华人民共和国可以根据实际情况对该国家或者地区对等采取措施。\n第四章 个人在个人信息处理活动中的权利 第四十四条 个人对其个人信息的处理享有知情权、决定权，有权限制或者拒绝他人对其个人信息进行处理；法律、行政法规另有规定的除外。\n第四十五条 个人有权向个人信息处理者查阅、复制其个人信息；有本法第十八条第一款、第三十五条规定情形的除外。\n个人请求查阅、复制其个人信息的，个人信息处理者应当及时提供。\n个人请求将个人信息转移至其指定的个人信息处理者，符合国家网信部门规定条件的，个人信息处理者应当提供转移的途径。\n第四十六条 个人发现其个人信息不准确或者不完整的，有权请求个人信息处理者更正、补充。\n个人请求更正、补充其个人信息的，个人信息处理者应当对其个人信息予以核实，并及时更正、补充。\n第四十七条 有下列情形之一的，个人信息处理者应当主动删除个人信息；个人信息处理者未删除的，个人有权请求删除：\n（一）处理目的已实现、无法实现或者为实现处理目的不再必要；\n（二）个人信息处理者停止提供产品或者服务，或者保存期限已届满；\n（三）个人撤回同意；\n（四）个人信息处理者违反法律、行政法规或者违反约定处理个人信息；\n（五）法律、行政法规规定的其他情形。\n法律、行政法规规定的保存期限未届满，或者删除个人信息从技术上难以实现的，个人信息处理者应当停止除存储和采取必要的安全保护措施之外的处理。\n第四十八条 个人有权要求个人信息处理者对其个人信息处理规则进行解释说明。\n第四十九条 自然人死亡的，其近亲属为了自身的合法、正当利益，可以对死者的相关个人信息行使本章规定的查阅、复制、更正、删除等权利；死者生前另有安排的除外。\n第五十条 个人信息处理者应当建立便捷的个人行使权利的申请受理和处理机制。拒绝个人行使权利的请求的，应当说明理由。\n个人信息处理者拒绝个人行使权利的请求的，个人可以依法向人民法院提起诉讼。\n第五章 个人信息处理者的义务 第五十一条 个人信息处理者应当根据个人信息的处理目的、处理方式、个人信息的种类以及对个人权益的影响、可能存在的安全风险等，采取下列措施确保个人信息处理活动符合法律、行政法规的规定，并防止未经授权的访问以及个人信息泄露、篡改、丢失：\n（一）制定内部管理制度和操作规程；\n（二）对个人信息实行分类管理；\n（三）采取相应的加密、去标识化等安全技术措施；\n（四）合理确定个人信息处理的操作权限，并定期对从业人员进行安全教育和培训；\n（五）制定并组织实施个人信息安全事件应急预案；\n（六）法律、行政法规规定的其他措施。\n第五十二条 处理个人信息达到国家网信部门规定数量的个人信息处理者应当指定个人信息保护负责人，负责对个人信息处理活动以及采取的保护措施等进行监督。\n个人信息处理者应当公开个人信息保护负责人的联系方式，并将个人信息保护负责人的姓名、联系方式等报送履行个人信息保护职责的部门。\n第五十三条 本法第三条第二款规定的中华人民共和国境外的个人信息处理者，应当在中华人民共和国境内设立专门机构或者指定代表，负责处理个人信息保护相关事务，并将有关机构的名称或者代表的姓名、联系方式等报送履行个人信息保护职责的部门。\n第五十四条 个人信息处理者应当定期对其处理个人信息遵守法律、行政法规的情况进行合规审计。\n第五十五条 有下列情形之一的，个人信息处理者应当事前进行个人信息保护影响评估，并对处理情况进行记录：\n（一）处理敏感个人信息；\n（二）利用个人信息进行自动化决策；\n（三）委托处理个人信息、向其他个人信息处理者提供个人信息、公开个人信息；\n（四）向境外提供个人信息；\n（五）其他对个人权益有重大影响的个人信息处理活动。\n第五十六条 个人信息保护影响评估应当包括下列内容：\n（一）个人信息的处理目的、处理方式等是否合法、正当、必要；\n（二）对个人权益的影响及安全风险；\n（三）所采取的保护措施是否合法、有效并与风险程度相适应。\n个人信息保护影响评估报告和处理情况记录应当至少保存三年。\n第五十七条 发生或者可能发生个人信息泄露、篡改、丢失的，个人信息处理者应当立即采取补救措施，并通知履行个人信息保护职责的部门和个人。通知应当包括下列事项：\n（一）发生或者可能发生个人信息泄露、篡改、丢失的信息种类、原因和可能造成的危害；\n（二）个人信息处理者采取的补救措施和个人可以采取的减轻危害的措施；\n（三）个人信息处理者的联系方式。\n个人信息处理者采取措施能够有效避免信息泄露、篡改、丢失造成危害的，个人信息处理者可以不通知个人；履行个人信息保护职责的部门认为可能造成危害的，有权要求个人信息处理者通知个人。\n第五十八条 提供重要互联网平台服务、用户数量巨大、业务类型复杂的个人信息处理者，应当履行下列义务：\n（一）按照国家规定建立健全个人信息保护合规制度体系，成立主要由外部成员组成的独立机构对个人信息保护情况进行监督；\n（二）遵循公开、公平、公正的原则，制定平台规则，明确平台内产品或者服务提供者处理个人信息的规范和保护个人信息的义务；\n（三）对严重违反法律、行政法规处理个人信息的平台内的产品或者服务提供者，停止提供服务；\n（四）定期发布个人信息保护社会责任报告，接受社会监督。\n第五十九条 接受委托处理个人信息的受托人，应当依照本法和有关法律、行政法规的规定，采取必要措施保障所处理的个人信息的安全，并协助个人信息处理者履行本法规定的义务。\n第六章 履行个人信息保护职责的部门 第六十条 国家网信部门负责统筹协调个人信息保护工作和相关监督管理工作。国务院有关部门依照本法和有关法律、行政法规的规定，在各自职责范围内负责个人信息保护和监督管理工作。\n县级以上地方人民政府有关部门的个人信息保护和监督管理职责，按照国家有关规定确定。\n前两款规定的部门统称为履行个人信息保护职责的部门。\n第六十一条 履行个人信息保护职责的部门履行下列个人信息保护职责：\n（一）开展个人信息保护宣传教育，指导、监督个人信息处理者开展个人信息保护工作；\n（二）接受、处理与个人信息保护有关的投诉、举报；\n（三）组织对应用程序等个人信息保护情况进行测评，并公布测评结果；\n（四）调查、处理违法个人信息处理活动；\n（五）法律、行政法规规定的其他职责。\n第六十二条 国家网信部门统筹协调有关部门依据本法推进下列个人信息保护工作：\n（一）制定个人信息保护具体规则、标准；\n（二）针对小型个人信息处理者、处理敏感个人信息以及人脸识别、人工智能等新技术、新应用，制定专门的个人信息保护规则、标准；\n（三）支持研究开发和推广应用安全、方便的电子身份认证技术，推进网络身份认证公共服务建设；\n（四）推进个人信息保护社会化服务体系建设，支持有关机构开展个人信息保护评估、认证服务；\n（五）完善个人信息保护投诉、举报工作机制。\n第六十三条 履行个人信息保护职责的部门履行个人信息保护职责，可以采取下列措施：\n（一）询问有关当事人，调查与个人信息处理活动有关的情况；\n（二）查阅、复制当事人与个人信息处理活动有关的合同、记录、账簿以及其他有关资料；\n（三）实施现场检查，对涉嫌违法的个人信息处理活动进行调查；\n（四）检查与个人信息处理活动有关的设备、物品；对有证据证明是用于违法个人信息处理活动的设备、物品，向本部门主要负责人书面报告并经批准，可以查封或者扣押。\n履行个人信息保护职责的部门依法履行职责，当事人应当予以协助、配合，不得拒绝、阻挠。\n第六十四条 履行个人信息保护职责的部门在履行职责中，发现个人信息处理活动存在较大风险或者发生个人信息安全事件的，可以按照规定的权限和程序对该个人信息处理者的法定代表人或者主要负责人进行约谈，或者要求个人信息处理者委托专业机构对其个人信息处理活动进行合规审计。个人信息处理者应当按照要求采取措施，进行整改，消除隐患。\n履行个人信息保护职责的部门在履行职责中，发现违法处理个人信息涉嫌犯罪的，应当及时移送公安机关依法处理。\n第六十五条 任何组织、个人有权对违法个人信息处理活动向履行个人信息保护职责的部门进行投诉、举报。收到投诉、举报的部门应当依法及时处理，并将处理结果告知投诉、举报人。\n履行个人信息保护职责的部门应当公布接受投诉、举报的联系方式。\n第七章 法律责任 第六十六条 违反本法规定处理个人信息，或者处理个人信息未履行本法规定的个人信息保护义务的，由履行个人信息保护职责的部门责令改正，给予警告，没收违法所得，对违法处理个人信息的应用程序，责令暂停或者终止提供服务；拒不改正的，并处一百万元以下罚款；对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。\n有前款规定的违法行为，情节严重的，由省级以上履行个人信息保护职责的部门责令改正，没收违法所得，并处五千万元以下或者上一年度营业额百分之五以下罚款，并可以责令暂停相关业务或者停业整顿、通报有关主管部门吊销相关业务许可或者吊销营业执照；对直接负责的主管人员和其他直接责任人员处十万元以上一百万元以下罚款，并可以决定禁止其在一定期限内担任相关企业的董事、监事、高级管理人员和个人信息保护负责人。\n第六十七条 有本法规定的违法行为的，依照有关法律、行政法规的规定记入信用档案，并予以公示。\n第六十八条 国家机关不履行本法规定的个人信息保护义务的，由其上级机关或者履行个人信息保护职责的部门责令改正；对直接负责的主管人员和其他直接责任人员依法给予处分。\n履行个人信息保护职责的部门的工作人员玩忽职守、滥用职权、徇私舞弊，尚不构成犯罪的，依法给予处分。\n第六十九条 处理个人信息侵害个人信息权益造成损害，个人信息处理者不能证明自己没有过错的，应当承担损害赔偿等侵权责任。\n前款规定的损害赔偿责任按照个人因此受到的损失或者个人信息处理者因此获得的利益确定；个人因此受到的损失和个人信息处理者因此获得的利益难以确定的，根据实际情况确定赔偿数额。\n第七十条 个人信息处理者违反本法规定处理个人信息，侵害众多个人的权益的，人民检察院、法律规定的消费者组织和由国家网信部门确定的组织可以依法向人民法院提起诉讼。\n第七十一条 违反本法规定，构成违反治安管理行为的，依法给予治安管理处罚；构成犯罪的，依法追究刑事责任。\n第八章 附 则 第七十二条 自然人因个人或者家庭事务处理个人信息的，不适用本法。\n法律对各级人民政府及其有关部门组织实施的统计、档案管理活动中的个人信息处理有规定的，适用其规定。\n第七十三条 本法下列用语的含义：\n（一）个人信息处理者，是指在个人信息处理活动中自主决定处理目的、处理方式的组织、个人。\n（二）自动化决策，是指通过计算机程序自动分析、评估个人的行为习惯、兴趣爱好或者经济、健康、信用状况等，并进行决策的活动。\n（三）去标识化，是指个人信息经过处理，使其在不借助额外信息的情况下无法识别特定自然人的过程。\n（四）匿名化，是指个人信息经过处理无法识别特定自然人且不能复原的过程。\n第七十四条 本法自2021年11月1日起施行。\n","permalink":"https://ai.intlaws.com/compliance/china/pipl/","summary":"《中华人民共和国个人信息保护法》官方文本：8 章 74 条，2021 年 8 月 20 日通过、2021 年 11 月 1 日施行。中文原文取自国家互联网信息办公室官方发布；英文译本取自全国人民代表大会官网英文版（页面自标\u0026quot;仅供参考\u0026quot;）。","title":"中华人民共和国个人信息保护法"},{"content":" 版本与来源（可核验）\n项目 内容 通过与公布 2021 年 6 月 10 日第十三届全国人民代表大会常务委员会第二十九次会议通过 施行日期 2021 年 9 月 1 日 现行有效 是（截至 2026-09-22 未经修订） 中文原文来源 国家互联网信息办公室官方文本：https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm 英文译本来源 全国人民代表大会官网英文版「Laws（Translation for Reference Only）」：http://en.npc.gov.cn.cdurl.cn/2021-06/10/c_689311.htm （正文分 2 页） 译文性质 官网站点发布译本，页面自标「Translation for Reference Only」（仅供参考） 校对记录 2026-09-22 抓取官方页面；7 章 55 条，中英条目一一对应、无缺号 第一章 总则 第一条 为了规范数据处理活动，保障数据安全，促进数据开发利用，保护个人、组织的合法权益，维护国家主权、安全和发展利益，制定本法。\n第二条 在中华人民共和国境内开展数据处理活动及其安全监管，适用本法。\n在中华人民共和国境外开展数据处理活动，损害中华人民共和国国家安全、公共利益或者公民、组织合法权益的，依法追究法律责任。\n第三条 本法所称数据，是指任何以电子或者其他方式对信息的记录。\n数据处理，包括数据的收集、存储、使用、加工、传输、提供、公开等。\n数据安全，是指通过采取必要措施，确保数据处于有效保护和合法利用的状态，以及具备保障持续安全状态的能力。\n第四条 维护数据安全，应当坚持总体国家安全观，建立健全数据安全治理体系，提高数据安全保障能力。\n第五条 中央国家安全领导机构负责国家数据安全工作的决策和议事协调，研究制定、指导实施国家数据安全战略和有关重大方针政策，统筹协调国家数据安全的重大事项和重要工作，建立国家数据安全工作协调机制。\n第六条 各地区、各部门对本地区、本部门工作中收集和产生的数据及数据安全负责。\n工业、电信、交通、金融、自然资源、卫生健康、教育、科技等主管部门承担本行业、本领域数据安全监管职责。\n公安机关、国家安全机关等依照本法和有关法律、行政法规的规定，在各自职责范围内承担数据安全监管职责。\n国家网信部门依照本法和有关法律、行政法规的规定，负责统筹协调网络数据安全和相关监管工作。\n第七条 国家保护个人、组织与数据有关的权益，鼓励数据依法合理有效利用，保障数据依法有序自由流动，促进以数据为关键要素的数字经济发展。\n第八条 开展数据处理活动，应当遵守法律、法规，尊重社会公德和伦理，遵守商业道德和职业道德，诚实守信，履行数据安全保护义务，承担社会责任，不得危害国家安全、公共利益，不得损害个人、组织的合法权益。\n第九条 国家支持开展数据安全知识宣传普及，提高全社会的数据安全保护意识和水平，推动有关部门、行业组织、科研机构、企业、个人等共同参与数据安全保护工作，形成全社会共同维护数据安全和促进发展的良好环境。\n第十条 相关行业组织按照章程，依法制定数据安全行为规范和团体标准，加强行业自律，指导会员加强数据安全保护，提高数据安全保护水平，促进行业健康发展。\n第十一条 国家积极开展数据安全治理、数据开发利用等领域的国际交流与合作，参与数据安全相关国际规则和标准的制定，促进数据跨境安全、自由流动。\n第十二条 任何个人、组织都有权对违反本法规定的行为向有关主管部门投诉、举报。收到投诉、举报的部门应当及时依法处理。\n有关主管部门应当对投诉、举报人的相关信息予以保密，保护投诉、举报人的合法权益。\n第二章 数据安全与发展 第十三条 国家统筹发展和安全，坚持以数据开发利用和产业发展促进数据安全，以数据安全保障数据开发利用和产业发展。\n第十四条 国家实施大数据战略，推进数据基础设施建设，鼓励和支持数据在各行业、各领域的创新应用。\n省级以上人民政府应当将数字经济发展纳入本级国民经济和社会发展规划，并根据需要制定数字经济发展规划。\n第十五条 国家支持开发利用数据提升公共服务的智能化水平。提供智能化公共服务，应当充分考虑老年人、残疾人的需求，避免对老年人、残疾人的日常生活造成障碍。\n第十六条 国家支持数据开发利用和数据安全技术研究，鼓励数据开发利用和数据安全等领域的技术推广和商业创新，培育、发展数据开发利用和数据安全产品、产业体系。\n第十七条 国家推进数据开发利用技术和数据安全标准体系建设。国务院标准化行政主管部门和国务院有关部门根据各自的职责，组织制定并适时修订有关数据开发利用技术、产品和数据安全相关标准。国家支持企业、社会团体和教育、科研机构等参与标准制定。\n第十八条 国家促进数据安全检测评估、认证等服务的发展，支持数据安全检测评估、认证等专业机构依法开展服务活动。\n国家支持有关部门、行业组织、企业、教育和科研机构、有关专业机构等在数据安全风险评估、防范、处置等方面开展协作。\n第十九条 国家建立健全数据交易管理制度，规范数据交易行为，培育数据交易市场。\n第二十条 国家支持教育、科研机构和企业等开展数据开发利用技术和数据安全相关教育和培训，采取多种方式培养数据开发利用技术和数据安全专业人才，促进人才交流。\n第三章 数据安全制度 第二十一条 国家建立数据分类分级保护制度，根据数据在经济社会发展中的重要程度，以及一旦遭到篡改、破坏、泄露或者非法获取、非法利用，对国家安全、公共利益或者个人、组织合法权益造成的危害程度，对数据实行分类分级保护。国家数据安全工作协调机制统筹协调有关部门制定重要数据目录，加强对重要数据的保护。\n关系国家安全、国民经济命脉、重要民生、重大公共利益等数据属于国家核心数据，实行更加严格的管理制度。\n各地区、各部门应当按照数据分类分级保护制度，确定本地区、本部门以及相关行业、领域的重要数据具体目录，对列入目录的数据进行重点保护。\n第二十二条 国家建立集中统一、高效权威的数据安全风险评估、报告、信息共享、监测预警机制。国家数据安全工作协调机制统筹协调有关部门加强数据安全风险信息的获取、分析、研判、预警工作。\n第二十三条 国家建立数据安全应急处置机制。发生数据安全事件，有关主管部门应当依法启动应急预案，采取相应的应急处置措施，防止危害扩大，消除安全隐患，并及时向社会发布与公众有关的警示信息。\n第二十四条 国家建立数据安全审查制度，对影响或者可能影响国家安全的数据处理活动进行国家安全审查。\n依法作出的安全审查决定为最终决定。\n第二十五条 国家对与维护国家安全和利益、履行国际义务相关的属于管制物项的数据依法实施出口管制。\n第二十六条 任何国家或者地区在与数据和数据开发利用技术等有关的投资、贸易等方面对中华人民共和国采取歧视性的禁止、限制或者其他类似措施的，中华人民共和国可以根据实际情况对该国家或者地区对等采取措施。\n第四章 数据安全保护义务 第二十七条 开展数据处理活动应当依照法律、法规的规定，建立健全全流程数据安全管理制度，组织开展数据安全教育培训，采取相应的技术措施和其他必要措施，保障数据安全。利用互联网等信息网络开展数据处理活动，应当在网络安全等级保护制度的基础上，履行上述数据安全保护义务。\n重要数据的处理者应当明确数据安全负责人和管理机构，落实数据安全保护责任。\n第二十八条 开展数据处理活动以及研究开发数据新技术，应当有利于促进经济社会发展，增进人民福祉，符合社会公德和伦理。\n第二十九条 开展数据处理活动应当加强风险监测，发现数据安全缺陷、漏洞等风险时，应当立即采取补救措施；发生数据安全事件时，应当立即采取处置措施，按照规定及时告知用户并向有关主管部门报告。\n第三十条 重要数据的处理者应当按照规定对其数据处理活动定期开展风险评估，并向有关主管部门报送风险评估报告。\n风险评估报告应当包括处理的重要数据的种类、数量，开展数据处理活动的情况，面临的数据安全风险及其应对措施等。\n第三十一条 关键信息基础设施的运营者在中华人民共和国境内运营中收集和产生的重要数据的出境安全管理，适用《中华人民共和国网络安全法》的规定；其他数据处理者在中华人民共和国境内运营中收集和产生的重要数据的出境安全管理办法，由国家网信部门会同国务院有关部门制定。\n第三十二条 任何组织、个人收集数据，应当采取合法、正当的方式，不得窃取或者以其他非法方式获取数据。\n法律、行政法规对收集、使用数据的目的、范围有规定的，应当在法律、行政法规规定的目的和范围内收集、使用数据。\n第三十三条 从事数据交易中介服务的机构提供服务，应当要求数据提供方说明数据来源，审核交易双方的身份，并留存审核、交易记录。\n第三十四条 法律、行政法规规定提供数据处理相关服务应当取得行政许可的，服务提供者应当依法取得许可。\n第三十五条 公安机关、国家安全机关因依法维护国家安全或者侦查犯罪的需要调取数据，应当按照国家有关规定，经过严格的批准手续，依法进行，有关组织、个人应当予以配合。\n第三十六条 中华人民共和国主管机关根据有关法律和中华人民共和国缔结或者参加的国际条约、协定，或者按照平等互惠原则，处理外国司法或者执法机构关于提供数据的请求。非经中华人民共和国主管机关批准，境内的组织、个人不得向外国司法或者执法机构提供存储于中华人民共和国境内的数据。\n第五章 政务数据安全与开放 第三十七条 国家大力推进电子政务建设，提高政务数据的科学性、准确性、时效性，提升运用数据服务经济社会发展的能力。\n第三十八条 国家机关为履行法定职责的需要收集、使用数据，应当在其履行法定职责的范围内依照法律、行政法规规定的条件和程序进行；对在履行职责中知悉的个人隐私、个人信息、商业秘密、保密商务信息等数据应当依法予以保密，不得泄露或者非法向他人提供。\n第三十九条 国家机关应当依照法律、行政法规的规定，建立健全数据安全管理制度，落实数据安全保护责任，保障政务数据安全。\n第四十条 国家机关委托他人建设、维护电子政务系统，存储、加工政务数据，应当经过严格的批准程序，并应当监督受托方履行相应的数据安全保护义务。受托方应当依照法律、法规的规定和合同约定履行数据安全保护义务，不得擅自留存、使用、泄露或者向他人提供政务数据。\n第四十一条 国家机关应当遵循公正、公平、便民的原则，按照规定及时、准确地公开政务数据。依法不予公开的除外。\n第四十二条 国家制定政务数据开放目录，构建统一规范、互联互通、安全可控的政务数据开放平台，推动政务数据开放利用。\n第四十三条 法律、法规授权的具有管理公共事务职能的组织为履行法定职责开展数据处理活动，适用本章规定。\n第六章 法律责任 第四十四条 有关主管部门在履行数据安全监管职责中，发现数据处理活动存在较大安全风险的，可以按照规定的权限和程序对有关组织、个人进行约谈，并要求有关组织、个人采取措施进行整改，消除隐患。\n第四十五条 开展数据处理活动的组织、个人不履行本法第二十七条、第二十九条、第三十条规定的数据安全保护义务的，由有关主管部门责令改正，给予警告，可以并处五万元以上五十万元以下罚款，对直接负责的主管人员和其他直接责任人员可以处一万元以上十万元以下罚款；拒不改正或者造成大量数据泄露等严重后果的，处五十万元以上二百万元以下罚款，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处五万元以上二十万元以下罚款。\n违反国家核心数据管理制度，危害国家主权、安全和发展利益的，由有关主管部门处二百万元以上一千万元以下罚款，并根据情况责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照；构成犯罪的，依法追究刑事责任。\n第四十六条 违反本法第三十一条规定，向境外提供重要数据的，由有关主管部门责令改正，给予警告，可以并处十万元以上一百万元以下罚款，对直接负责的主管人员和其他直接责任人员可以处一万元以上十万元以下罚款；情节严重的，处一百万元以上一千万元以下罚款，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处十万元以上一百万元以下罚款。\n第四十七条 从事数据交易中介服务的机构未履行本法第三十三条规定的义务的，由有关主管部门责令改正，没收违法所得，处违法所得一倍以上十倍以下罚款，没有违法所得或者违法所得不足十万元的，处十万元以上一百万元以下罚款，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照；对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。\n第四十八条 违反本法第三十五条规定，拒不配合数据调取的，由有关主管部门责令改正，给予警告，并处五万元以上五十万元以下罚款，对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。\n违反本法第三十六条规定，未经主管机关批准向外国司法或者执法机构提供数据的，由有关主管部门给予警告，可以并处十万元以上一百万元以下罚款，对直接负责的主管人员和其他直接责任人员可以处一万元以上十万元以下罚款；造成严重后果的，处一百万元以上五百万元以下罚款，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处五万元以上五十万元以下罚款。\n第四十九条 国家机关不履行本法规定的数据安全保护义务的，对直接负责的主管人员和其他直接责任人员依法给予处分。\n第五十条 履行数据安全监管职责的国家工作人员玩忽职守、滥用职权、徇私舞弊的，依法给予处分。\n第五十一条 窃取或者以其他非法方式获取数据，开展数据处理活动排除、限制竞争，或者损害个人、组织合法权益的，依照有关法律、行政法规的规定处罚。\n第五十二条 违反本法规定，给他人造成损害的，依法承担民事责任。\n违反本法规定，构成违反治安管理行为的，依法给予治安管理处罚；构成犯罪的，依法追究刑事责任。\n第七章 附则 第五十三条 开展涉及国家秘密的数据处理活动，适用《中华人民共和国保守国家秘密法》等法律、行政法规的规定。\n在统计、档案工作中开展数据处理活动，开展涉及个人信息的数据处理活动，还应当遵守有关法律、行政法规的规定。\n第五十四条 军事数据安全保护的办法，由中央军事委员会依据本法另行制定。\n第五十五条 本法自2021年9月1日起施行。\n","permalink":"https://ai.intlaws.com/compliance/china/dsl/","summary":"《中华人民共和国数据安全法》官方文本：7 章 55 条，2021 年 6 月 10 日通过、2021 年 9 月 1 日施行。中文原文取自国家互联网信息办公室官方发布；英文译本取自全国人民代表大会官网英文版（页面自标\u0026quot;仅供参考\u0026quot;）。","title":"中华人民共和国数据安全法"},{"content":" 立法沿革：2016 年 11 月 7 日第十二届全国人民代表大会常务委员会第二十四次会议通过；根据 2025 年 10 月 28 日第十四届全国人民代表大会常务委员会第十八次会议《关于修改〈中华人民共和国网络安全法〉的决定》修正；自 2026 年 1 月 1 日起施行。\n版本与来源（可核验）\n项目 内容 通过与公布 2016 年 11 月 7 日第十二届全国人大常委会第二十四次会议通过 修正 2025 年 10 月 28 日第十四届全国人大常委会第十八次会议通过《关于修改〈中华人民共和国网络安全法〉的决定》 施行 原法 2017 年 6 月 1 日起施行；修正后自 2026 年 1 月 1 日起施行（修改决定原文：“本决定自 2026 年 1 月 1 日起施行。《中华人民共和国网络安全法》根据本决定作相应修改并对条文顺序作相应调整，重新公布。”） 现行有效 是（2025 年修正版）。引用时须注明版本：2016 年版条文序号已被调整，不再适用 中文原文来源 修正后全文：https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm ；修改决定（含修正要点原文）：https://www.cac.gov.cn/2025-10/29/c_1763461514768457.htm 本次修正要点（据官方决定原文逐条核对） ① 新增第三条（坚持中国共产党的领导、贯彻总体国家安全观、统筹发展和安全、推进网络强国建设）；② 新增第二十条 人工智能专条（支持人工智能基础理论与算法研发、训练数据与算力基础设施、人工智能伦理规范、风险监测评估和安全监管；支持运用人工智能提升网络安全保护水平）；③ 第四十二条增加一款：处理个人信息应当遵守本法、民法典、个人信息保护法等；④ 大幅提高法律责任：拒不改正致危害网络安全——网络运营者 5 万—50 万元、关键信息基础设施运营者 10 万—100 万元；造成大量数据泄露、关键信息基础设施丧失局部功能等严重后果——50 万—200 万元；造成丧失主要功能等特别严重后果——200 万—1000 万元；⑤ 新增第六十三条：销售或提供未经安全认证/检测的网络关键设备和网络安全专用产品的处罚；⑥ 第六十四、六十五条增列“应用程序”并调整处罚；⑦ 因增删条文，条文序号整体调整（如原第五十九条→第六十一条） 英文译本 无官方英译本（全国人大英文站仅发布 2016 年原版译本，条文序号与本修正版不一致，不能直接套用）。本页英文全文已完成：由本网据官方中文文本翻译并逐条交叉校核，标注为非官方译本、仅供参考 → English 校对记录 2026-09-22 抓取国家互联网信息办公室官方页面（修正后全文 + 修改决定）；7 章 81 条，条号连续、无缺号 第一章 总 则 第一条\n为了保障网络安全，维护网络空间主权和国家安全、社会公共利益，保护公民、法人和其他组织的合法权益，促进经济社会信息化健康发展，制定本法。\n第二条\n在中华人民共和国境内建设、运营、维护和使用网络，以及网络安全的监督管理，适用本法。\n第三条\n网络安全工作坚持中国共产党的领导，贯彻总体国家安全观，统筹发展和安全，推进网络强国建设。\n第四条\n国家坚持网络安全与信息化发展并重，遵循积极利用、科学发展、依法管理、确保安全的方针，推进网络基础设施建设和互联互通，鼓励网络技术创新和应用，支持培养网络安全人才，建立健全网络安全保障体系，提高网络安全保护能力。\n第五条\n国家制定并不断完善网络安全战略，明确保障网络安全的基本要求和主要目标，提出重点领域的网络安全政策、工作任务和措施。\n第六条\n国家采取措施，监测、防御、处置来源于中华人民共和国境内外的网络安全风险和威胁，保护关键信息基础设施免受攻击、侵入、干扰和破坏，依法惩治网络违法犯罪活动，维护网络空间安全和秩序。\n第七条\n国家倡导诚实守信、健康文明的网络行为，推动传播社会主义核心价值观，采取措施提高全社会的网络安全意识和水平，形成全社会共同参与促进网络安全的良好环境。\n第八条\n国家积极开展网络空间治理、网络技术研发和标准制定、打击网络违法犯罪等方面的国际交流与合作，推动构建和平、安全、开放、合作的网络空间，建立多边、民主、透明的网络治理体系。\n第九条\n国家网信部门负责统筹协调网络安全工作和相关监督管理工作。国务院电信主管部门、公安部门和其他有关机关依照本法和有关法律、行政法规的规定，在各自职责范围内负责网络安全保护和监督管理工作。\n县级以上地方人民政府有关部门的网络安全保护和监督管理职责，按照国家有关规定确定。\n第十条\n网络运营者开展经营和服务活动，必须遵守法律、行政法规，尊重社会公德，遵守商业道德，诚实信用，履行网络安全保护义务，接受政府和社会的监督，承担社会责任。\n第十一条\n建设、运营网络或者通过网络提供服务，应当依照法律、行政法规的规定和国家标准的强制性要求，采取技术措施和其他必要措施，保障网络安全、稳定运行，有效应对网络安全事件，防范网络违法犯罪活动，维护网络数据的完整性、保密性和可用性。\n第十二条\n网络相关行业组织按照章程，加强行业自律，制定网络安全行为规范，指导会员加强网络安全保护，提高网络安全保护水平，促进行业健康发展。\n第十三条\n国家保护公民、法人和其他组织依法使用网络的权利，促进网络接入普及，提升网络服务水平，为社会提供安全、便利的网络服务，保障网络信息依法有序自由流动。\n任何个人和组织使用网络应当遵守宪法法律，遵守公共秩序，尊重社会公德，不得危害网络安全，不得利用网络从事危害国家安全、荣誉和利益，煽动颠覆国家政权、推翻社会主义制度，煽动分裂国家、破坏国家统一，宣扬恐怖主义、极端主义，宣扬民族仇恨、民族歧视，传播暴力、淫秽色情信息，编造、传播虚假信息扰乱经济秩序和社会秩序，以及侵害他人名誉、隐私、知识产权和其他合法权益等活动。\n第十四条\n国家支持研究开发有利于未成年人健康成长的网络产品和服务，依法惩治利用网络从事危害未成年人身心健康的活动，为未成年人提供安全、健康的网络环境。\n第十五条\n任何个人和组织有权对危害网络安全的行为向网信、电信、公安等部门举报。收到举报的部门应当及时依法作出处理；不属于本部门职责的，应当及时移送有权处理的部门。\n有关部门应当对举报人的相关信息予以保密，保护举报人的合法权益。\n第二章 网络安全支持与促进 第十六条\n国家建立和完善网络安全标准体系。国务院标准化行政主管部门和国务院其他有关部门根据各自的职责，组织制定并适时修订有关网络安全管理以及网络产品、服务和运行安全的国家标准、行业标准。\n国家支持企业、研究机构、高等学校、网络相关行业组织参与网络安全国家标准、行业标准的制定。\n第十七条\n国务院和省、自治区、直辖市人民政府应当统筹规划，加大投入，扶持重点网络安全技术产业和项目，支持网络安全技术的研究开发和应用，推广安全可信的网络产品和服务，保护网络技术知识产权，支持企业、研究机构和高等学校等参与国家网络安全技术创新项目。\n第十八条\n国家推进网络安全社会化服务体系建设，鼓励有关企业、机构开展网络安全认证、检测和风险评估等安全服务。\n第十九条\n国家鼓励开发网络数据安全保护和利用技术，促进公共数据资源开放，推动技术创新和经济社会发展。\n第二十条\n国家支持人工智能基础理论研究和算法等关键技术研发，推进训练数据资源、算力等基础设施建设，完善人工智能伦理规范，加强风险监测评估和安全监管，促进人工智能应用和健康发展。\n国家支持创新网络安全管理方式，运用人工智能等新技术，提升网络安全保护水平。\n第二十一条\n各级人民政府及其有关部门应当组织开展经常性的网络安全宣传教育，并指导、督促有关单位做好网络安全宣传教育工作。\n大众传播媒介应当有针对性地面向社会进行网络安全宣传教育。\n第二十二条\n国家支持企业和高等学校、职业学校等教育培训机构开展网络安全相关教育与培训，采取多种方式培养网络安全人才，促进网络安全人才交流。\n第三章 网络运行安全 第一节 一般规定 第二十三条\n国家实行网络安全等级保护制度。网络运营者应当按照网络安全等级保护制度的要求，履行下列安全保护义务，保障网络免受干扰、破坏或者未经授权的访问，防止网络数据泄露或者被窃取、篡改：\n（一）制定内部安全管理制度和操作规程，确定网络安全负责人，落实网络安全保护责任；\n（二）采取防范计算机病毒和网络攻击、网络侵入等危害网络安全行为的技术措施；\n（三）采取监测、记录网络运行状态、网络安全事件的技术措施，并按照规定留存相关的网络日志不少于六个月；\n（四）采取数据分类、重要数据备份和加密等措施；\n（五）法律、行政法规规定的其他义务。\n第二十四条\n网络产品、服务应当符合相关国家标准的强制性要求。网络产品、服务的提供者不得设置恶意程序；发现其网络产品、服务存在安全缺陷、漏洞等风险时，应当立即采取补救措施，按照规定及时告知用户并向有关主管部门报告。\n网络产品、服务的提供者应当为其产品、服务持续提供安全维护；在规定或者当事人约定的期限内，不得终止提供安全维护。\n网络产品、服务具有收集用户信息功能的，其提供者应当向用户明示并取得同意；涉及用户个人信息的，还应当遵守本法和有关法律、行政法规关于个人信息保护的规定。\n第二十五条\n网络关键设备和网络安全专用产品应当按照相关国家标准的强制性要求，由具备资格的机构安全认证合格或者安全检测符合要求后，方可销售或者提供。国家网信部门会同国务院有关部门制定、公布网络关键设备和网络安全专用产品目录，并推动安全认证和安全检测结果互认，避免重复认证、检测。\n第二十六条\n网络运营者为用户办理网络接入、域名注册服务，办理固定电话、移动电话等入网手续，或者为用户提供信息发布、即时通讯等服务，在与用户签订协议或者确认提供服务时，应当要求用户提供真实身份信息。用户不提供真实身份信息的，网络运营者不得为其提供相关服务。\n国家实施网络可信身份战略，支持研究开发安全、方便的电子身份认证技术，推动不同电子身份认证之间的互认。\n第二十七条\n网络运营者应当制定网络安全事件应急预案，及时处置系统漏洞、计算机病毒、网络攻击、网络侵入等安全风险；在发生危害网络安全的事件时，立即启动应急预案，采取相应的补救措施，并按照规定向有关主管部门报告。\n第二十八条\n开展网络安全认证、检测、风险评估等活动，向社会发布系统漏洞、计算机病毒、网络攻击、网络侵入等网络安全信息，应当遵守国家有关规定。\n第二十九条\n任何个人和组织不得从事非法侵入他人网络、干扰他人网络正常功能、窃取网络数据等危害网络安全的活动；不得提供专门用于从事侵入网络、干扰网络正常功能及防护措施、窃取网络数据等危害网络安全活动的程序、工具；明知他人从事危害网络安全的活动的，不得为其提供技术支持、广告推广、支付结算等帮助。\n第三十条\n网络运营者应当为公安机关、国家安全机关依法维护国家安全和侦查犯罪的活动提供技术支持和协助。\n第三十一条\n国家支持网络运营者之间在网络安全信息收集、分析、通报和应急处置等方面进行合作，提高网络运营者的安全保障能力。\n有关行业组织建立健全本行业的网络安全保护规范和协作机制，加强对网络安全风险的分析评估，定期向会员进行风险警示，支持、协助会员应对网络安全风险。\n第三十二条\n网信部门和有关部门在履行网络安全保护职责中获取的信息，只能用于维护网络安全的需要，不得用于其他用途。\n第二节 关键信息基础设施的运行安全 第三十三条\n国家对公共通信和信息服务、能源、交通、水利、金融、公共服务、电子政务等重要行业和领域，以及其他一旦遭到破坏、丧失功能或者数据泄露，可能严重危害国家安全、国计民生、公共利益的关键信息基础设施，在网络安全等级保护制度的基础上，实行重点保护。关键信息基础设施的具体范围和安全保护办法由国务院制定。\n国家鼓励关键信息基础设施以外的网络运营者自愿参与关键信息基础设施保护体系。\n第三十四条\n按照国务院规定的职责分工，负责关键信息基础设施安全保护工作的部门分别编制并组织实施本行业、本领域的关键信息基础设施安全规划，指导和监督关键信息基础设施运行安全保护工作。\n第三十五条\n建设关键信息基础设施应当确保其具有支持业务稳定、持续运行的性能，并保证安全技术措施同步规划、同步建设、同步使用。\n第三十六条\n除本法第二十三条的规定外，关键信息基础设施的运营者还应当履行下列安全保护义务：\n（一）设置专门安全管理机构和安全管理负责人，并对该负责人和关键岗位的人员进行安全背景审查；\n（二）定期对从业人员进行网络安全教育、技术培训和技能考核；\n（三）对重要系统和数据库进行容灾备份；\n（四）制定网络安全事件应急预案，并定期进行演练；\n（五）法律、行政法规规定的其他义务。\n第三十七条\n关键信息基础设施的运营者采购网络产品和服务，可能影响国家安全的，应当通过国家网信部门会同国务院有关部门组织的国家安全审查。\n第三十八条\n关键信息基础设施的运营者采购网络产品和服务，应当按照规定与提供者签订安全保密协议，明确安全和保密义务与责任。\n第三十九条\n关键信息基础设施的运营者在中华人民共和国境内运营中收集和产生的个人信息和重要数据应当在境内存储。因业务需要，确需向境外提供的，应当按照国家网信部门会同国务院有关部门制定的办法进行安全评估；法律、行政法规另有规定的，依照其规定。\n第四十条\n关键信息基础设施的运营者应当自行或者委托网络安全服务机构对其网络的安全性和可能存在的风险每年至少进行一次检测评估，并将检测评估情况和改进措施报送相关负责关键信息基础设施安全保护工作的部门。\n第四十一条\n国家网信部门应当统筹协调有关部门对关键信息基础设施的安全保护采取下列措施：\n（一）对关键信息基础设施的安全风险进行抽查检测，提出改进措施，必要时可以委托网络安全服务机构对网络存在的安全风险进行检测评估；\n（二）定期组织关键信息基础设施的运营者进行网络安全应急演练，提高应对网络安全事件的水平和协同配合能力；\n（三）促进有关部门、关键信息基础设施的运营者以及有关研究机构、网络安全服务机构等之间的网络安全信息共享；\n（四）对网络安全事件的应急处置与网络功能的恢复等，提供技术支持和协助。\n第四章 网络信息安全 第四十二条\n网络运营者应当对其收集的用户信息严格保密，并建立健全用户信息保护制度。\n网络运营者处理个人信息，应当遵守本法和《中华人民共和国民法典》、《中华人民共和国个人信息保护法》等法律、行政法规的规定。\n第四十三条\n网络运营者收集、使用个人信息，应当遵循合法、正当、必要的原则，公开收集、使用规则，明示收集、使用信息的目的、方式和范围，并经被收集者同意。\n网络运营者不得收集与其提供的服务无关的个人信息，不得违反法律、行政法规的规定和双方的约定收集、使用个人信息，并应当依照法律、行政法规的规定和与用户的约定，处理其保存的个人信息。\n第四十四条\n网络运营者不得泄露、篡改、毁损其收集的个人信息；未经被收集者同意，不得向他人提供个人信息。但是，经过处理无法识别特定个人且不能复原的除外。\n网络运营者应当采取技术措施和其他必要措施，确保其收集的个人信息安全，防止信息泄露、毁损、丢失。在发生或者可能发生个人信息泄露、毁损、丢失的情况时，应当立即采取补救措施，按照规定及时告知用户并向有关主管部门报告。\n第四十五条\n个人发现网络运营者违反法律、行政法规的规定或者双方的约定收集、使用其个人信息的，有权要求网络运营者删除其个人信息；发现网络运营者收集、存储的其个人信息有错误的，有权要求网络运营者予以更正。网络运营者应当采取措施予以删除或者更正。\n第四十六条\n任何个人和组织不得窃取或者以其他非法方式获取个人信息，不得非法出售或者非法向他人提供个人信息。\n第四十七条\n依法负有网络安全监督管理职责的部门及其工作人员，必须对在履行职责中知悉的个人信息、隐私和商业秘密严格保密，不得泄露、出售或者非法向他人提供。\n第四十八条\n任何个人和组织应当对其使用网络的行为负责，不得设立用于实施诈骗，传授犯罪方法，制作或者销售违禁物品、管制物品等违法犯罪活动的网站、通讯群组，不得利用网络发布涉及实施诈骗，制作或者销售违禁物品、管制物品以及其他违法犯罪活动的信息。\n第四十九条\n网络运营者应当加强对其用户发布的信息的管理，发现法律、行政法规禁止发布或者传输的信息的，应当立即停止传输该信息，采取消除等处置措施，防止信息扩散，保存有关记录，并向有关主管部门报告。\n第五十条\n任何个人和组织发送的电子信息、提供的应用软件，不得设置恶意程序，不得含有法律、行政法规禁止发布或者传输的信息。\n电子信息发送服务提供者和应用软件下载服务提供者，应当履行安全管理义务，知道其用户有前款规定行为的，应当停止提供服务，采取消除等处置措施，保存有关记录，并向有关主管部门报告。\n第五十一条\n网络运营者应当建立网络信息安全投诉、举报制度，公布投诉、举报方式等信息，及时受理并处理有关网络信息安全的投诉和举报。\n网络运营者对网信部门和有关部门依法实施的监督检查，应当予以配合。\n第五十二条\n国家网信部门和有关部门依法履行网络信息安全监督管理职责，发现法律、行政法规禁止发布或者传输的信息的，应当要求网络运营者停止传输，采取消除等处置措施，保存有关记录；对来源于中华人民共和国境外的上述信息，应当通知有关机构采取技术措施和其他必要措施阻断传播。\n第五章 监测预警与应急处置 第五十三条\n国家建立网络安全监测预警和信息通报制度。国家网信部门应当统筹协调有关部门加强网络安全信息收集、分析和通报工作，按照规定统一发布网络安全监测预警信息。\n第五十四条\n负责关键信息基础设施安全保护工作的部门，应当建立健全本行业、本领域的网络安全监测预警和信息通报制度，并按照规定报送网络安全监测预警信息。\n第五十五条\n国家网信部门协调有关部门建立健全网络安全风险评估和应急工作机制，制定网络安全事件应急预案，并定期组织演练。\n负责关键信息基础设施安全保护工作的部门应当制定本行业、本领域的网络安全事件应急预案，并定期组织演练。\n网络安全事件应急预案应当按照事件发生后的危害程度、影响范围等因素对网络安全事件进行分级，并规定相应的应急处置措施。\n第五十六条\n网络安全事件发生的风险增大时，省级以上人民政府有关部门应当按照规定的权限和程序，并根据网络安全风险的特点和可能造成的危害，采取下列措施：\n（一）要求有关部门、机构和人员及时收集、报告有关信息，加强对网络安全风险的监测；\n（二）组织有关部门、机构和专业人员，对网络安全风险信息进行分析评估，预测事件发生的可能性、影响范围和危害程度；\n（三）向社会发布网络安全风险预警，发布避免、减轻危害的措施。\n第五十七条\n发生网络安全事件，应当立即启动网络安全事件应急预案，对网络安全事件进行调查和评估，要求网络运营者采取技术措施和其他必要措施，消除安全隐患，防止危害扩大，并及时向社会发布与公众有关的警示信息。\n第五十八条\n省级以上人民政府有关部门在履行网络安全监督管理职责中，发现网络存在较大安全风险或者发生安全事件的，可以按照规定的权限和程序对该网络的运营者的法定代表人或者主要负责人进行约谈。网络运营者应当按照要求采取措施，进行整改，消除隐患。\n第五十九条\n因网络安全事件，发生突发事件或者生产安全事故的，应当依照《中华人民共和国突发事件应对法》、《中华人民共和国安全生产法》等有关法律、行政法规的规定处置。\n第六十条\n因维护国家安全和社会公共秩序，处置重大突发社会安全事件的需要，经国务院决定或者批准，可以在特定区域对网络通信采取限制等临时措施。\n第六章 法 律 责 任 第六十一条\n网络运营者不履行本法第二十三条、第二十七条规定的网络安全保护义务的，由有关主管部门责令改正，给予警告，可以处一万元以上五万元以下罚款；拒不改正或者导致危害网络安全等后果的，处五万元以上五十万元以下罚款，对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。\n关键信息基础设施的运营者不履行本法第三十五条、第三十六条、第三十八条、第四十条规定的网络安全保护义务的，由有关主管部门责令改正，给予警告，可以处五万元以上十万元以下罚款；拒不改正或者导致危害网络安全等后果的，处十万元以上一百万元以下罚款，对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。\n有前两款行为，造成大量数据泄露、关键信息基础设施丧失局部功能等严重危害网络安全后果的，由有关主管部门处五十万元以上二百万元以下罚款，对直接负责的主管人员和其他直接责任人员处五万元以上二十万元以下罚款；造成关键信息基础设施丧失主要功能等特别严重危害网络安全后果的，处二百万元以上一千万元以下罚款，对直接负责的主管人员和其他直接责任人员处二十万元以上一百万元以下罚款。\n第六十二条\n违反本法第二十四条第一款、第二款和第五十条第一款规定，有下列行为之一的，由有关主管部门责令改正，给予警告；拒不改正或者导致危害网络安全等后果的，处五万元以上五十万元以下罚款，对直接负责的主管人员处一万元以上十万元以下罚款：\n（一）设置恶意程序的；\n（二）对其产品、服务存在的安全缺陷、漏洞等风险未立即采取补救措施，或者未按照规定及时告知用户并向有关主管部门报告的；\n（三）擅自终止为其产品、服务提供安全维护的。\n有前款第一项、第二项行为，造成本法第六十一条第三款规定的后果的，依照该款规定处罚。\n第六十三条\n违反本法第二十五条规定，销售或者提供未经安全认证、安全检测或者安全认证不合格、安全检测不符合要求的网络关键设备和网络安全专用产品的，由有关主管部门责令停止销售或者提供，给予警告，没收违法所得；没有违法所得或者违法所得不足十万元的，并处二万元以上十万元以下罚款；违法所得十万元以上的，并处违法所得一倍以上五倍以下罚款；情节严重的，并可以责令暂停相关业务、停业整顿、吊销相关业务许可证或者吊销营业执照。法律、行政法规另有规定的，依照其规定。\n第六十四条\n网络运营者违反本法第二十六条第一款规定，未要求用户提供真实身份信息，或者对不提供真实身份信息的用户提供相关服务的，由有关主管部门责令改正；拒不改正或者情节严重的，处五万元以上五十万元以下罚款，并可以责令暂停相关业务、停业整顿、关闭网站或者应用程序、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。\n第六十五条\n违反本法第二十八条规定，开展网络安全认证、检测、风险评估等活动，或者向社会发布系统漏洞、计算机病毒、网络攻击、网络侵入等网络安全信息的，由有关主管部门责令改正，给予警告，可以处一万元以上十万元以下罚款；拒不改正或者情节严重的，处十万元以上一百万元以下罚款，并可以责令暂停相关业务、停业整顿、关闭网站或者应用程序、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。\n有前款行为，造成本法第六十一条第三款规定的后果的，依照该款规定处罚。\n第六十六条\n违反本法第二十九条规定，从事危害网络安全的活动，或者提供专门用于从事危害网络安全活动的程序、工具，或者为他人从事危害网络安全的活动提供技术支持、广告推广、支付结算等帮助，尚不构成犯罪的，由公安机关没收违法所得，处五日以下拘留，可以并处五万元以上五十万元以下罚款；情节较重的，处五日以上十五日以下拘留，可以并处十万元以上一百万元以下罚款。\n单位有前款行为的，由公安机关没收违法所得，处十万元以上一百万元以下罚款，并对直接负责的主管人员和其他直接责任人员依照前款规定处罚。\n违反本法第二十九条规定，受到治安管理处罚的人员，五年内不得从事网络安全管理和网络运营关键岗位的工作；受到刑事处罚的人员，终身不得从事网络安全管理和网络运营关键岗位的工作。\n第六十七条\n关键信息基础设施的运营者违反本法第三十七条规定，使用未经安全审查或者安全审查未通过的网络产品或者服务的，由有关主管部门责令限期改正、停止使用、消除对国家安全的影响，处采购金额一倍以上十倍以下罚款，对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。\n第六十八条\n违反本法第四十八条规定，设立用于实施违法犯罪活动的网站、通讯群组，或者利用网络发布涉及实施违法犯罪活动的信息，尚不构成犯罪的，由公安机关处五日以下拘留，可以并处一万元以上十万元以下罚款；情节较重的，处五日以上十五日以下拘留，可以并处五万元以上五十万元以下罚款。关闭用于实施违法犯罪活动的网站、通讯群组。\n单位有前款行为的，由公安机关处十万元以上五十万元以下罚款，并对直接负责的主管人员和其他直接责任人员依照前款规定处罚。\n第六十九条\n网络运营者违反本法第四十九条规定，对法律、行政法规禁止发布或者传输的信息未停止传输、采取消除等处置措施、保存有关记录、向有关主管部门报告，或者违反本法第五十二条规定，不按照有关部门的要求对法律、行政法规禁止发布或者传输的信息停止传输、采取消除等处置措施、保存有关记录的，由有关主管部门责令改正，给予警告、予以通报，可以处五万元以上五十万元以下罚款；拒不改正或者情节严重的，处五十万元以上二百万元以下罚款，并可以责令暂停相关业务、停业整顿、关闭网站或者应用程序、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处五万元以上二十万元以下罚款。\n有前款行为，造成特别严重影响、特别严重后果的，由有关主管部门处二百万元以上一千万元以下罚款，责令暂停相关业务、停业整顿、关闭网站或者应用程序、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处二十万元以上一百万元以下罚款。\n电子信息发送服务提供者、应用软件下载服务提供者，不履行本法第五十条第二款规定的安全管理义务的，依照前两款规定处罚。\n第七十条\n网络运营者违反本法规定，有下列行为之一的，由有关主管部门责令改正；拒不改正或者情节严重的，处五万元以上五十万元以下罚款，对直接负责的主管人员和其他直接责任人员，处一万元以上十万元以下罚款：\n（一）拒绝、阻碍有关部门依法实施的监督检查的；\n（二）拒不向公安机关、国家安全机关提供技术支持和协助的。\n第七十一条\n有下列行为之一的，依照有关法律、行政法规的规定处理、处罚：\n（一）发布或者传输本法第十三条第二款和其他法律、行政法规禁止发布或者传输的信息的；\n（二）违反本法第二十四条第三款、第四十三条至第四十五条规定，侵害个人信息权益的；\n（三）违反本法第三十九条规定，关键信息基础设施的运营者在境外存储个人信息和重要数据，或者向境外提供个人信息和重要数据的。\n违反本法第四十六条规定，窃取或者以其他非法方式获取、非法出售或者非法向他人提供个人信息，尚不构成犯罪的，由公安机关依照有关法律、行政法规的规定处罚。\n第七十二条\n有本法规定的违法行为的，依照有关法律、行政法规的规定记入信用档案，并予以公示。\n第七十三条\n违反本法规定，但具有《中华人民共和国行政处罚法》规定的从轻、减轻或者不予处罚情形的，依照其规定从轻、减轻或者不予处罚。\n第七十四条\n国家机关政务网络的运营者不履行本法规定的网络安全保护义务的，由其上级机关或者有关机关责令改正；对直接负责的主管人员和其他直接责任人员依法给予处分。\n第七十五条\n网信部门和有关部门违反本法第三十二条规定，将在履行网络安全保护职责中获取的信息用于其他用途的，对直接负责的主管人员和其他直接责任人员依法给予处分。\n网信部门和有关部门的工作人员玩忽职守、滥用职权、徇私舞弊，尚不构成犯罪的，依法给予处分。\n第七十六条\n违反本法规定，给他人造成损害的，依法承担民事责任。\n违反本法规定，构成违反治安管理行为的，依法给予治安管理处罚；构成犯罪的，依法追究刑事责任。\n第七十七条\n境外的机构、组织、个人从事危害中华人民共和国网络安全的活动的，依法追究法律责任；造成严重后果的，国务院公安部门和有关部门并可以决定对该机构、组织、个人采取冻结财产或者其他必要的制裁措施。\n第七章 附 则 第七十八条\n本法下列用语的含义：\n（一）网络，是指由计算机或者其他信息终端及相关设备组成的按照一定的规则和程序对信息进行收集、存储、传输、交换、处理的系统。\n（二）网络安全，是指通过采取必要措施，防范对网络的攻击、侵入、干扰、破坏和非法使用以及意外事故，使网络处于稳定可靠运行的状态，以及保障网络数据的完整性、保密性、可用性的能力。\n（三）网络运营者，是指网络的所有者、管理者和网络服务提供者。\n（四）网络数据，是指通过网络收集、存储、传输、处理和产生的各种电子数据。\n（五）个人信息，是指以电子或者其他方式记录的能够单独或者与其他信息结合识别自然人个人身份的各种信息，包括但不限于自然人的姓名、出生日期、身份证件号码、个人生物识别信息、住址、电话号码等。\n第七十九条\n存储、处理涉及国家秘密信息的网络的运行安全保护，除应当遵守本法外，还应当遵守保密法律、行政法规的规定。\n第八十条\n军事网络的安全保护，由中央军事委员会另行规定。\n第八十一条\n本法自2017年6月1日起施行。\n※ 编者注：本条系 2016 年原法施行日期条款，2025 年修正后依官方重新公布文本原文保留；修正决定自 2026 年 1 月 1 日起施行，见页首「施行」栏说明。\n","permalink":"https://ai.intlaws.com/compliance/china/csl/","summary":"《中华人民共和国网络安全法》2025 年修正后官方文本：7 章 81 条。2025 年 10 月 28 日通过修改决定、自 2026 年 1 月 1 日起施行；本次修正新增人工智能专条、大幅提高法律责任罚款上限（最高 1000 万元），并重新调整条文序号。中文原文取自国家互联网信息办公室官方发布。","title":"中华人民共和国网络安全法（2025 年修正）"},{"content":" 案情、裁判结果与典型意义取自最高人民法院 2026-09-16 发布《人民法院网络法治典型案例》案例一发布文本，以直接引述或紧贴原文的归纳为限，不作超出原文的推论。\n案件名称与案号 李某申请人格权侵害禁令案\n——明确适用人格权侵害禁令的考量因素，及时有效遏制网络暴力\n一审 吉林省长春新区人民法院 ｜ 发布：最高人民法院《人民法院网络法治典型案例》（2026-09-16 发布）案例一\n案号与禁令裁定具体作出日期：官方发布文本未载，本页如实注明，不作推测补写。\n关键词 民事 / 人格权侵害禁令 / 网络暴力 / 名誉权 / 民法典第九百九十七条 / 群体性网暴\n基本案情 李某与张某、胡某均为短视频平台自媒体博主，张某、胡某网络账号合计粉丝超 2000 万。2023 年 7 月起，张某以李某「插足」其与男友情感为由，在网络平台公开发布侮辱、诽谤言论，并联合胡某炒作话题、煽动粉丝谩骂攻击举报，形成群体性网络暴力；李某部分商业合作方因此解约。\n2023 年 10 月，李某提起名誉权侵权诉讼，诉讼期间侵权行为仍持续。2024 年 3 月，李某申请人格权侵害禁令。\n法院审理与说理 法院认为：张某、胡某实施群体性网暴违法行为且仍在继续，侵权信息传播快、波及广，已造成李某精神损害与经济损失，不及时制止将致其受到难以弥补的损害，符合人格权侵害禁令的适用条件。\n裁判结果 裁定张某、胡某立即停止侵权； 禁令有效期 6 个月；违反禁令的，视情节轻重予以罚款、拘留，构成犯罪的追究刑事责任。 数据法 / AI 法要点 网暴情形下适用人格权侵害禁令（民法典第 997 条）的审查三要素：\n① 紧迫性——综合侵权行为方式、信息传播速度与范围，判断不及时制止是否将使损害难以弥补；\n② 难以弥补性——综合被侵害人格权类型、侵害行为性质、事后赔偿等救济能否充分弥补；\n③ 限度——综合被侵害人格权类型、侵权行为方式、损害范围程度确定禁令措施，不得超出必要限度。 诉讼未决不影响禁令：名誉权侵权诉讼尚在进行中，侵权行为持续的前提下，禁令作为防止损害扩大的独立救济手段及时介入——「先禁令、后判决」的时序对受害人保护具有实益。 与数据合规的关联：网络暴力常伴随个人信息的非法获取与集中传播（「开盒」）。本案例与《最高人民法院关于依法审理涉人工智能纠纷案件的意见》（法发〔2026〕10 号）确立的规则一致——利用 AI 技术追踪、分析特定自然人公开信息以获取或泄露私密信息的，按侵害隐私权处理。平台与企业在处置网暴投诉时，可将「受害人申请禁令」纳入响应预案。 法律适用日分写：民法典第 997 条自 2021-01-01 施行（法律生效日）；本案例的示范效力自官方发布日（2026-09-16）确立，禁令所涉裁判行为发生于 2024 年（裁判时点）。 相关法条 《中华人民共和国民法典》第九百九十七条（人格权侵害禁令）。\n权威来源 最高人民法院官网 ·《人民法院网络法治典型案例》（2026-09-16 发布，案例一全文） （页面载「发布时间：2026-09-16 10:18:39」） 最高人民法院官网 · 典型案例列表页（发布日期佐证） 站内关联法规 /compliance/china/pipl/ /compliance/china/spc-opinions-ai-disputes-2026/ ","permalink":"https://ai.intlaws.com/cases/china/spc-personality-injunction-cyberbullying/","summary":"\u003cblockquote\u003e\n\u003cp\u003e案情、裁判结果与典型意义取自最高人民法院 2026-09-16 发布《人民法院网络法治典型案例》案例一发布文本，以直接引述或紧贴原文的归纳为限，不作超出原文的推论。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e李某申请人格权侵害禁令案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——明确适用人格权侵害禁令的考量因素，及时有效遏制网络暴力\u003c/p\u003e\n\u003cp\u003e一审 吉林省长春新区人民法院 ｜ \u003cstrong\u003e发布\u003c/strong\u003e：最高人民法院《人民法院网络法治典型案例》（2026-09-16 发布）案例一\u003c/p\u003e\n\u003cp\u003e案号与禁令裁定具体作出日期：\u003cstrong\u003e官方发布文本未载\u003c/strong\u003e，本页如实注明，不作推测补写。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 人格权侵害禁令 / 网络暴力 / 名誉权 / 民法典第九百九十七条 / 群体性网暴\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e李某与张某、胡某均为短视频平台自媒体博主，张某、胡某网络账号合计粉丝超 2000 万。2023 年 7 月起，张某以李某「插足」其与男友情感为由，在网络平台公开发布侮辱、诽谤言论，并联合胡某炒作话题、煽动粉丝谩骂攻击举报，形成\u003cstrong\u003e群体性网络暴力\u003c/strong\u003e；李某部分商业合作方因此解约。\u003c/p\u003e\n\u003cp\u003e2023 年 10 月，李某提起名誉权侵权诉讼，诉讼期间侵权行为仍持续。2024 年 3 月，李某申请人格权侵害禁令。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e法院认为：张某、胡某实施群体性网暴违法行为且\u003cstrong\u003e仍在继续\u003c/strong\u003e，侵权信息传播快、波及广，已造成李某精神损害与经济损失，不及时制止将致其受到\u003cstrong\u003e难以弥补的损害\u003c/strong\u003e，符合人格权侵害禁令的适用条件。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e裁定张某、胡某\u003cstrong\u003e立即停止侵权\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e禁令有效期 6 个月\u003c/strong\u003e；违反禁令的，视情节轻重予以罚款、拘留，构成犯罪的追究刑事责任。\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e网暴情形下适用人格权侵害禁令（民法典第 997 条）的审查三要素\u003c/strong\u003e：\u003cbr\u003e\n① \u003cstrong\u003e紧迫性\u003c/strong\u003e——综合侵权行为方式、信息传播速度与范围，判断不及时制止是否将使损害难以弥补；\u003cbr\u003e\n② \u003cstrong\u003e难以弥补性\u003c/strong\u003e——综合被侵害人格权类型、侵害行为性质、事后赔偿等救济能否充分弥补；\u003cbr\u003e\n③ \u003cstrong\u003e限度\u003c/strong\u003e——综合被侵害人格权类型、侵权行为方式、损害范围程度确定禁令措施，\u003cstrong\u003e不得超出必要限度\u003c/strong\u003e。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e诉讼未决不影响禁令\u003c/strong\u003e：名誉权侵权诉讼尚在进行中，侵权行为持续的前提下，禁令作为防止损害扩大的独立救济手段及时介入——「先禁令、后判决」的时序对受害人保护具有实益。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e与数据合规的关联\u003c/strong\u003e：网络暴力常伴随个人信息的非法获取与集中传播（「开盒」）。本案例与《最高人民法院关于依法审理涉人工智能纠纷案件的意见》（法发〔2026〕10 号）确立的规则一致——利用 AI 技术追踪、分析特定自然人公开信息以获取或泄露私密信息的，按侵害隐私权处理。平台与企业在处置网暴投诉时，可将「受害人申请禁令」纳入响应预案。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e法律适用日分写\u003c/strong\u003e：民法典第 997 条自 2021-01-01 施行（法律生效日）；本案例的示范效力自官方发布日（2026-09-16）确立，禁令所涉裁判行为发生于 2024 年（裁判时点）。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e《中华人民共和国民法典》第九百九十七条（人格权侵害禁令）。\u003c/p\u003e","title":"最高法网络法治典型案例：网络暴力情形下适用人格权侵害禁令的三项审查要素（李某申请人格权侵害禁令案，长春新区法院）"},{"content":" 案情、裁判结果与典型意义取自最高人民法院 2026-09-16 发布《人民法院网络法治典型案例》案例四发布文本，以直接引述或紧贴原文的归纳为限，不作超出原文的推论。\n案件名称与案号 黄某等人开设赌场案\n——依法惩处为跨境赌博提供技术支持服务的犯罪，维护网络空间安全\n一审 重庆市綦江区人民法院 ｜ 二审 重庆市第五中级人民法院 2023 年 12 月 6 日裁定驳回上诉、维持原判（部分被告人上诉） ｜ 发布：最高人民法院《人民法院网络法治典型案例》（2026-09-16 发布）案例四\n案号：官方发布文本未载，本页如实注明，不作推测补写（中国裁判文书网检索受限，待补核）。\n关键词 刑事 / 开设赌场罪 / 跨境赌博 / 技术供应链 / 软件开发 / 共同犯罪 / 事先通谋\n基本案情 菲律宾某跨境赌博集团开发、运营了 14 个赌博网站、6 个第四方支付平台，组织、招揽中国公民参与网络赌博。2016 年至 2020 年，被告人黄某等人根据菲律宾某跨境赌博集团安排，在中国成立某软件科技公司，为该赌博集团提供技术支持服务，包括网络赌博软件开发、编写服务器代码、对服务器和域名进行管理、维护赌博平台等。经查，黄某等人违法所得共计 1216 万余元。\n法院审理与说理 重庆市綦江区人民法院经审理认为，被告人黄某等人根据赌博犯罪集团安排，为赌博犯罪活动提供软件开发等技术支持服务，构成开设赌场罪。官方发布文本在典型意义部分进一步载明：黄某等人组建网络赌博技术供应链团队，开发架构复杂、功能齐全的软件，为跨境赌博集团运营的赌博网站、支付平台提供技术支持服务，与跨境赌博集团事先通谋并形成了较为稳定的配合关系。\n裁判结果 判处黄某等人有期徒刑五年六个月至六个月不等，并处罚金。宣判后，部分被告人提出上诉，2023 年 12 月 6 日，重庆市第五中级人民法院作出二审裁定，驳回上诉，维持原判。\n数据法 / AI 法要点 罪名认定：行为人明知是跨境赌博集团，仍根据其安排提供软件开发、技术支持等服务的，构成开设赌场罪的共同犯罪（因存在事先通谋），不以帮助信息网络犯罪活动罪（《刑法》第二百八十七条之二）等轻罪论处，量刑显著加重。发布文本未展开两罪的界分辨析，裁判文书原文未公开可核。 技术供应链入罪：赌博网站开发、服务器与域名管理、支付平台技术支持等「中立技术业务」，在明知用途且与犯罪集团形成稳定配合的情况下被纳入刑事打击范围；官方口径指出技术供应链降低了赌博网站开发和运营成本，跨境赌博犯罪存在网络化趋势，需全方位全链条打击。 企业合规警示：对提供出海支付、软件开发、服务器运维服务的企业，客户尽调（KYC）缺失可能衍生刑事共犯风险；与犯罪集团「事先通谋」是罪责升格的关键。 典型意义（最高法口径）：依法惩处为跨境赌博提供技术支持服务的犯罪，维护网络空间安全，助力营造清朗网络空间。 相关法条 官方发布文本未单列裁判依据条文；按《刑法》第三百零三条第二款（开设赌场罪）与共同犯罪制度的框架理解，条文号待裁判文书原文补核。\n法律生效日与合规义务适用日分写 本案二审裁定 2023 年 12 月 6 日作出并生效，仅约束本案当事人；其作为典型案例于 2026-09-16 发布，属裁判规则的示范性宣示，不改变刑法相关罪名的适用时点，也不新设行政合规义务。\n权威来源 最高人民法院官网 ·《人民法院网络法治典型案例》（2026-09-16 发布，案例四全文） （页面载「发布时间：2026-09-16 10:18:39」） 最高人民法院官网 · 典型案例列表页（发布日期佐证） 站内关联 最高法网络法治典型案例：AI合成声音肖像仿冒名人带货共同侵权案 ｜ 搜索引擎RAG侵权责任案 ｜ 网络暴力人格权侵害禁令案 ——同批发布的网络法治典型案例四件 网络安全法 ——网络技术供应链刑事风险所涉的基础性网络法律制度 ","permalink":"https://ai.intlaws.com/cases/china/spc-cross-border-gambling-tech-support/","summary":"\u003cblockquote\u003e\n\u003cp\u003e案情、裁判结果与典型意义取自最高人民法院 2026-09-16 发布《人民法院网络法治典型案例》案例四发布文本，以直接引述或紧贴原文的归纳为限，不作超出原文的推论。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e黄某等人开设赌场案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——依法惩处为跨境赌博提供技术支持服务的犯罪，维护网络空间安全\u003c/p\u003e\n\u003cp\u003e一审 重庆市綦江区人民法院 ｜ 二审 重庆市第五中级人民法院 2023 年 12 月 6 日裁定驳回上诉、维持原判（部分被告人上诉） ｜ \u003cstrong\u003e发布\u003c/strong\u003e：最高人民法院《人民法院网络法治典型案例》（2026-09-16 发布）案例四\u003c/p\u003e\n\u003cp\u003e案号：\u003cstrong\u003e官方发布文本未载\u003c/strong\u003e，本页如实注明，不作推测补写（中国裁判文书网检索受限，待补核）。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e刑事 / 开设赌场罪 / 跨境赌博 / 技术供应链 / 软件开发 / 共同犯罪 / 事先通谋\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e菲律宾某跨境赌博集团开发、运营了 14 个赌博网站、6 个第四方支付平台，组织、招揽中国公民参与网络赌博。2016 年至 2020 年，被告人黄某等人根据菲律宾某跨境赌博集团安排，在中国成立某软件科技公司，为该赌博集团提供技术支持服务，包括网络赌博软件开发、编写服务器代码、对服务器和域名进行管理、维护赌博平台等。经查，黄某等人违法所得共计 1216 万余元。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e重庆市綦江区人民法院经审理认为，被告人黄某等人根据赌博犯罪集团安排，为赌博犯罪活动提供软件开发等技术支持服务，构成开设赌场罪。官方发布文本在典型意义部分进一步载明：黄某等人组建网络赌博技术供应链团队，开发架构复杂、功能齐全的软件，为跨境赌博集团运营的赌博网站、支付平台提供技术支持服务，与跨境赌博集团\u003cstrong\u003e事先通谋\u003c/strong\u003e并形成了较为稳定的配合关系。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e判处黄某等人\u003cstrong\u003e有期徒刑五年六个月至六个月不等，并处罚金\u003c/strong\u003e。宣判后，部分被告人提出上诉，2023 年 12 月 6 日，重庆市第五中级人民法院作出二审裁定，驳回上诉，维持原判。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003e罪名认定\u003c/strong\u003e：行为人\u003cstrong\u003e明知\u003c/strong\u003e是跨境赌博集团，仍根据其安排提供软件开发、技术支持等服务的，构成开设赌场罪的\u003cstrong\u003e共同犯罪\u003c/strong\u003e（因存在事先通谋），不以帮助信息网络犯罪活动罪（《刑法》第二百八十七条之二）等轻罪论处，量刑显著加重。发布文本未展开两罪的界分辨析，裁判文书原文未公开可核。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e技术供应链入罪\u003c/strong\u003e：赌博网站开发、服务器与域名管理、支付平台技术支持等「中立技术业务」，在明知用途且与犯罪集团形成稳定配合的情况下被纳入刑事打击范围；官方口径指出技术供应链降低了赌博网站开发和运营成本，跨境赌博犯罪存在网络化趋势，需全方位全链条打击。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e企业合规警示\u003c/strong\u003e：对提供出海支付、软件开发、服务器运维服务的企业，客户尽调（KYC）缺失可能衍生刑事共犯风险；与犯罪集团「事先通谋」是罪责升格的关键。\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e典型意义\u003c/strong\u003e（最高法口径）：依法惩处为跨境赌博提供技术支持服务的犯罪，维护网络空间安全，助力营造清朗网络空间。\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据条文；按《刑法》第三百零三条第二款（开设赌场罪）与共同犯罪制度的框架理解，条文号待裁判文书原文补核。\u003c/p\u003e\n\u003ch2 id=\"法律生效日与合规义务适用日分写\"\u003e法律生效日与合规义务适用日分写\u003c/h2\u003e\n\u003cp\u003e本案二审裁定 2023 年 12 月 6 日作出并生效，仅约束本案当事人；其作为典型案例于 2026-09-16 发布，属裁判规则的示范性宣示，不改变刑法相关罪名的适用时点，也不新设行政合规义务。\u003c/p\u003e","title":"最高法网络法治典型案例：为跨境赌博提供技术支持构成开设赌场共同犯罪（黄某等人开设赌场案，重庆綦江一审、五中院二审维持）"},{"content":"案件名称与案号 北京抖某科技有限公司诉亿某某信息技术（北京）有限公司不正当竞争纠纷案\n——模型结构与参数受反不正当竞争法保护的边界\n一审 北京市朝阳区人民法院，（2023）京0105民初71391号；二审 北京知识产权法院，（2023）京73民终3802号 ｜ 入选：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\n官方发布文本未载裁判日期与生效状态。\n关键词 民事 / 不正当竞争 / 人工智能模型结构与参数 / 研发投入 / 搭便车\n基本案情 2020年6月，北京抖某科技有限公司在其“抖某”APP上线人工智能变身漫画特效。该特效通过模型结构及参数，将用户拍摄内容实时转换为真人比例对应的漫画风格，上线后获得较高市场关注。\n同年8月，亿某信息技术（北京）有限公司在其运营的APP上线少女漫画特效。该特效与抖某公司人工智能变身漫画特效在成像视觉效果上高度一致，二者涉及的模型结构和参数存在高度近似。\n法院审理与说理 （一）裁判理由（官方原文）\n二审法院认为，经营者通过数据训练、优化调校等方式形成的人工智能模型结构和参数，凝结研发投入，能够为经营者带来创新优势和经营收益，属于反不正当竞争法保护的合法权益。他人未经许可擅自商业化利用相关模型结构和参数，破坏公平竞争秩序的，构成不正当竞争。\n上引为二审法院裁判理由（官方文本标注为「二审法院认为」，因本案一审、二审意见以二审表述收录）。\n（二）入选理由（官方原文，说明本案的裁判价值）\n本案是关于人工智能模型结构和参数竞争法保护的精品司法案例。人民法院在著作权、商业秘密等法律路径存在保护盲区的情况下，依据反不正当竞争法对擅自利用他人模型成果的行为作出规制，体现了司法对新型技术成果保护方式的审慎拓展。本案有利于保护人工智能模型研发投入，遏制“搭便车”行为，维护人工智能行业公平竞争秩序。\n裁判结果 官方发布文本未载第一审判决主文（判项、赔偿数额、诉讼费用负担等均未公布），本页仅载明官方文本明确认定的责任结论（见上「法院审理与说理」栏）。\n判决主文表述与裁判日期：。\n数据法 / AI 法要点 以下要点系对官方发布文本「入选理由」的逐项原文提炼，不作扩展：\n① 经营者通过数据训练、优化调校等方式形成的人工智能模型结构和参数，凝结研发投入，能够为经营者带来创新优势和经营收益，属于反不正当竞争法保护的合法权益； ② 他人未经许可擅自商业化利用相关模型结构和参数，破坏公平竞争秩序的，构成不正当竞争； ③ 在著作权、商业秘密等法律路径存在保护盲区的情况下，可依反不正当竞争法对擅自利用他人模型成果的行为作出规制； ④ 司法对新型技术成果保护方式的审慎拓展，旨在保护模型研发投入、遏制「搭便车」行为。 相关法条 官方发布文本未单列裁判依据条文；裁判理由中明示适用《中华人民共和国反不正当竞争法》（属该法保护的合法权益）。具体条文号待官方文本补充。\n权威来源 中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网） 选编背景（据官方发布文本）：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\n个案页直链：上述官方发布页载有本案「一审法院 + 案号 + 基本案情 + 裁判理由 + 入选理由」。\n","permalink":"https://ai.intlaws.com/cases/china/bipc-ai-model-params/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e北京抖某科技有限公司诉亿某某信息技术（北京）有限公司不正当竞争纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——模型结构与参数受反不正当竞争法保护的边界\u003c/p\u003e\n\u003cp\u003e一审 北京市朝阳区人民法院，（2023）京0105民初71391号；二审 北京知识产权法院，（2023）京73民终3802号 ｜ \u003cstrong\u003e入选\u003c/strong\u003e：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\u003c/p\u003e\n\u003cp\u003e官方发布文本未载裁判日期与生效状态。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 不正当竞争 / 人工智能模型结构与参数 / 研发投入 / 搭便车\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e2020年6月，北京抖某科技有限公司在其“抖某”APP上线人工智能变身漫画特效。该特效通过模型结构及参数，将用户拍摄内容实时转换为真人比例对应的漫画风格，上线后获得较高市场关注。\u003cbr\u003e\n同年8月，亿某信息技术（北京）有限公司在其运营的APP上线少女漫画特效。该特效与抖某公司人工智能变身漫画特效在成像视觉效果上高度一致，二者涉及的模型结构和参数存在高度近似。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e（一）裁判理由（官方原文）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e二审法院认为，经营者通过数据训练、优化调校等方式形成的人工智能模型结构和参数，凝结研发投入，能够为经营者带来创新优势和经营收益，属于反不正当竞争法保护的合法权益。他人未经许可擅自商业化利用相关模型结构和参数，破坏公平竞争秩序的，构成不正当竞争。\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e上引为二审法院裁判理由（官方文本标注为「二审法院认为」，因本案一审、二审意见以二审表述收录）。\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003e（二）入选理由（官方原文，说明本案的裁判价值）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e本案是关于人工智能模型结构和参数竞争法保护的精品司法案例。人民法院在著作权、商业秘密等法律路径存在保护盲区的情况下，依据反不正当竞争法对擅自利用他人模型成果的行为作出规制，体现了司法对新型技术成果保护方式的审慎拓展。本案有利于保护人工智能模型研发投入，遏制“搭便车”行为，维护人工智能行业公平竞争秩序。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e官方发布文本\u003cstrong\u003e未载第一审判决主文\u003c/strong\u003e（判项、赔偿数额、诉讼费用负担等均未公布），本页仅载明官方文本明确认定的责任结论（见上「法院审理与说理」栏）。\u003c/p\u003e\n\u003cp\u003e判决主文表述与裁判日期：。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e以下要点系对官方发布文本「入选理由」的\u003cstrong\u003e逐项原文提炼\u003c/strong\u003e，不作扩展：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e① 经营者通过\u003cstrong\u003e数据训练、优化调校\u003c/strong\u003e等方式形成的人工智能\u003cstrong\u003e模型结构和参数\u003c/strong\u003e，凝结研发投入，能够为经营者带来创新优势和经营收益，属于\u003cstrong\u003e反不正当竞争法保护的合法权益\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e② 他人未经许可擅自\u003cstrong\u003e商业化利用\u003c/strong\u003e相关模型结构和参数，破坏公平竞争秩序的，构成不正当竞争；\u003c/li\u003e\n\u003cli\u003e③ 在著作权、商业秘密等法律路径存在\u003cstrong\u003e保护盲区\u003c/strong\u003e的情况下，可依反不正当竞争法对擅自利用他人模型成果的行为作出规制；\u003c/li\u003e\n\u003cli\u003e④ 司法对新型技术成果保护方式的\u003cstrong\u003e审慎拓展\u003c/strong\u003e，旨在保护模型研发投入、遏制「搭便车」行为。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据条文；裁判理由中明示适用《中华人民共和国反不正当竞争法》（属该法保护的合法权益）。具体条文号待官方文本补充。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"http://iolaw.cssn.cn/gg/ggqt/202606/t20260603_6009787.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网）\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e选编背景（据官方发布文本）\u003c/strong\u003e：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e个案页直链\u003c/strong\u003e：上述官方发布页载有本案「一审法院 + 案号 + 基本案情 + 裁判理由 + 入选理由」。\u003c/p\u003e","title":"北京知识产权法院：人工智能模型结构和参数不正当竞争案（抖某诉亿某）"},{"content":"案件名称与案号 孙某某诉成都涂某某餐饮管理有限公司、许某肖像权、声音权、姓名权纠纷案\n——合成声音、合成形象与姓名结合用于品牌宣传的侵权认定\n一审 成都铁路运输第一法院，（2025）川7101民初8546号 ｜ 入选：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\n官方发布文本未载裁判日期与生效状态。\n关键词 民事 / 人格权 / 肖像权 / 声音权益 / 姓名权 / AI 合成形象与声音 / 商业营销\n基本案情 2024年2月，被告成都涂某某餐饮管理有限公司通过抖音账号发布视频。视频内容为人工智能合成的孙某某形象及声音，合成形象以孙某某身份向观众拜年，并代表该公司向客户致以新年祝福。\n案涉视频中包含孙某某姓名、肖像特征和声音特征，并涉及对公司品牌的宣传。该视频未经孙某某授权，使用了具有较高识别度的人工智能合成形象和合成声音。\n法院审理与说理 （一）裁判理由（官方原文）\n一审法院认为，经人工智能技术处理后的声音、形象，只要具有足以识别特定自然人的音色、语调、发音风格、外貌特征等要素，仍受人格权益保护。未经许可将合成声音、合成形象与自然人姓名相结合，用于企业品牌宣传或者商业推广，容易使社会公众产生代言、推荐等关联认知，构成对姓名权、肖像权、声音权益的侵害。\n（二）入选理由（官方原文，说明本案的裁判价值）\n本案是关于人工智能合成音视频商业营销的精品司法案例。人民法院将合成声音、合成形象、姓名、肖像和品牌宣传内容结合评价，明确经营者不能以合成技术处理为由规避人格权授权要求。本案为企业利用人工智能合成明星、专家、公众人物形象开展营销活动划定了权利边界，有助于减少冒名宣传、虚假关联和人格利益商业化利用风险。\n裁判结果 官方发布文本未载第一审判决主文（判项、赔偿数额、诉讼费用负担等均未公布），本页仅载明官方文本明确认定的责任结论（见上「法院审理与说理」栏）。\n判决主文表述与裁判日期：。\n数据法 / AI 法要点 以下要点系对官方发布文本「入选理由」的逐项原文提炼，不作扩展：\n① 经人工智能技术处理后的声音、形象，只要具有足以识别特定自然人的音色、语调、发音风格、外貌特征等要素，仍受人格权益保护； ② 未经许可将合成声音、合成形象与自然人姓名相结合，用于企业品牌宣传或者商业推广，容易使公众产生代言、推荐等关联认知的，构成对姓名权、肖像权、声音权益的侵害； ③ 经营者不能以合成技术处理为由规避人格权授权要求；本案为企业利用 AI 合成明星、专家、公众人物形象开展营销划定权利边界。 相关法条 官方发布文本未单列裁判依据条文；说理涉及肖像权、声音权益、姓名权等人格权益保护。具体条文号待官方文本补充。\n权威来源 中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网） 选编背景（据官方发布文本）：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\n个案页直链：上述官方发布页载有本案「一审法院 + 案号 + 基本案情 + 裁判理由 + 入选理由」。\n","permalink":"https://ai.intlaws.com/cases/china/cdt1-ai-synth-celebrity/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e孙某某诉成都涂某某餐饮管理有限公司、许某肖像权、声音权、姓名权纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——合成声音、合成形象与姓名结合用于品牌宣传的侵权认定\u003c/p\u003e\n\u003cp\u003e一审 成都铁路运输第一法院，（2025）川7101民初8546号 ｜ \u003cstrong\u003e入选\u003c/strong\u003e：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\u003c/p\u003e\n\u003cp\u003e官方发布文本未载裁判日期与生效状态。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 人格权 / 肖像权 / 声音权益 / 姓名权 / AI 合成形象与声音 / 商业营销\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e2024年2月，被告成都涂某某餐饮管理有限公司通过抖音账号发布视频。视频内容为人工智能合成的孙某某形象及声音，合成形象以孙某某身份向观众拜年，并代表该公司向客户致以新年祝福。\u003cbr\u003e\n案涉视频中包含孙某某姓名、肖像特征和声音特征，并涉及对公司品牌的宣传。该视频未经孙某某授权，使用了具有较高识别度的人工智能合成形象和合成声音。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e（一）裁判理由（官方原文）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e一审法院认为，经人工智能技术处理后的声音、形象，只要具有足以识别特定自然人的音色、语调、发音风格、外貌特征等要素，仍受人格权益保护。未经许可将合成声音、合成形象与自然人姓名相结合，用于企业品牌宣传或者商业推广，容易使社会公众产生代言、推荐等关联认知，构成对姓名权、肖像权、声音权益的侵害。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e（二）入选理由（官方原文，说明本案的裁判价值）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e本案是关于人工智能合成音视频商业营销的精品司法案例。人民法院将合成声音、合成形象、姓名、肖像和品牌宣传内容结合评价，明确经营者不能以合成技术处理为由规避人格权授权要求。本案为企业利用人工智能合成明星、专家、公众人物形象开展营销活动划定了权利边界，有助于减少冒名宣传、虚假关联和人格利益商业化利用风险。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e官方发布文本\u003cstrong\u003e未载第一审判决主文\u003c/strong\u003e（判项、赔偿数额、诉讼费用负担等均未公布），本页仅载明官方文本明确认定的责任结论（见上「法院审理与说理」栏）。\u003c/p\u003e\n\u003cp\u003e判决主文表述与裁判日期：。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e以下要点系对官方发布文本「入选理由」的\u003cstrong\u003e逐项原文提炼\u003c/strong\u003e，不作扩展：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e① 经人工智能技术处理后的声音、形象，\u003cstrong\u003e只要具有足以识别特定自然人的音色、语调、发音风格、外貌特征等要素，仍受人格权益保护\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e② 未经许可将合成声音、合成形象与自然人姓名\u003cstrong\u003e相结合\u003c/strong\u003e，用于企业品牌宣传或者商业推广，容易使公众产生\u003cstrong\u003e代言、推荐等关联认知\u003c/strong\u003e的，构成对姓名权、肖像权、声音权益的侵害；\u003c/li\u003e\n\u003cli\u003e③ 经营者\u003cstrong\u003e不能以合成技术处理为由规避人格权授权要求\u003c/strong\u003e；本案为企业利用 AI 合成明星、专家、公众人物形象开展营销划定权利边界。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据条文；说理涉及肖像权、声音权益、姓名权等人格权益保护。具体条文号待官方文本补充。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"http://iolaw.cssn.cn/gg/ggqt/202606/t20260603_6009787.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网）\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e选编背景（据官方发布文本）\u003c/strong\u003e：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\u003c/p\u003e","title":"成都铁路运输第一法院：AI 合成明星形象与声音商业营销案（孙某某诉某餐饮公司等）"},{"content":"案件名称与案号 某国际投资公司诉曹某网络侵权责任纠纷案\n——生成式人工智能使用者的核验与标识义务\n一审 广州互联网法院，（2025）粤0192民初23599号 ｜ 入选：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\n官方发布文本未载裁判日期与生效状态。\n关键词 民事 / 网络侵权 / 企业名誉权 / 生成式人工智能使用者责任 / 核验与标识义务\n基本案情 原告某国际投资公司系国内上市企业，该公司某高管因涉嫌职务犯罪被逮捕。2025年8月，曹某在某生成式人工智能应用程序中输入一篇约1700字的文档，内容涉及该高管挪用公款案细节，并包含某国际投资公司存在关联交易等未经公开报道查证属实的信息。\n曹某随后向人工智能发出指令，要求将该文档生成一篇不少于1万字的深度长文。人工智能经过多轮处理和联网搜索后，生成一篇逾1.5万字的文章。文章介绍了某高管个人经历，并称某国际投资公司存在财务数据异常、虚增利润、关联交易利益输送、涉嫌财务造假等情形。经核对，人工智能引用来源中并无相关内容。\n曹某将该文章发布于其运营的财经类公众号，标注“原创”，文章阅读量超过1万次，转发量超过1千次。\n法院审理与说理 （一）裁判理由（官方原文）\n一审法院认为，用户作为生成式人工智能提示词输入、内容生成和外部传播的实际控制者，是侵权风险的开启者和管理者，不能以内容由人工智能生成为由免除责任。用户传播生成式人工智能形成的涉他人名誉内容时，应当对内容真实性、客观性及来源可靠性进行必要核验，并根据内容性质作出适当标识；未尽注意义务导致虚假信息侵害企业名誉的，应依法承担侵权责任。\n（二）入选理由（官方原文，说明本案的裁判价值）\n本案是关于人工智能生成合成内容网络侵权的精品司法案例。人民法院没有将责任简单归结于技术工具，而是围绕输入素材、生成指令、联网搜索、文章发布和传播效果等环节，细化并确认使用者、传播者的义务。本案有利于抑制借助生成式人工智能制造、放大未经核实信息的行为，引导内容生产者对人工智能生成信息保持必要的审慎，维护了企业名誉权益和网络信息秩序。\n裁判结果 官方发布文本未载第一审判决主文（判项、赔偿数额、诉讼费用负担等均未公布），本页仅载明官方文本明确认定的责任结论（见上「法院审理与说理」栏）。\n判决主文表述与裁判日期：。\n数据法 / AI 法要点 以下要点系对官方发布文本「入选理由」的逐项原文提炼，不作扩展：\n① 用户作为提示词输入、内容生成和外部传播的实际控制者，是侵权风险的开启者和管理者，不能以内容由人工智能生成为由免除责任； ② 用户传播生成式人工智能形成的涉他人名誉内容时，应当对内容的真实性、客观性及来源可靠性进行必要核验，并根据内容性质作出适当标识； ③ 责任认定不简单归结于技术工具，而是围绕输入素材、生成指令、联网搜索、文章发布和传播效果等环节，细化确认使用者、传播者的义务。 相关法条 官方发布文本未单列裁判依据条文；说理涉及企业名誉权保护与生成式人工智能使用者的注意义务。具体条文号待官方文本补充。\n权威来源 中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网） 选编背景（据官方发布文本）：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\n个案页直链：上述官方发布页载有本案「一审法院 + 案号 + 基本案情 + 裁判理由 + 入选理由」。\n站内关联法规 /compliance/china/ai-generated-content-labelling-measures/ ","permalink":"https://ai.intlaws.com/cases/china/gic-ai-fake-article-defamation/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e某国际投资公司诉曹某网络侵权责任纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——生成式人工智能使用者的核验与标识义务\u003c/p\u003e\n\u003cp\u003e一审 广州互联网法院，（2025）粤0192民初23599号 ｜ \u003cstrong\u003e入选\u003c/strong\u003e：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\u003c/p\u003e\n\u003cp\u003e官方发布文本未载裁判日期与生效状态。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 网络侵权 / 企业名誉权 / 生成式人工智能使用者责任 / 核验与标识义务\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e原告某国际投资公司系国内上市企业，该公司某高管因涉嫌职务犯罪被逮捕。2025年8月，曹某在某生成式人工智能应用程序中输入一篇约1700字的文档，内容涉及该高管挪用公款案细节，并包含某国际投资公司存在关联交易等未经公开报道查证属实的信息。\u003cbr\u003e\n曹某随后向人工智能发出指令，要求将该文档生成一篇不少于1万字的深度长文。人工智能经过多轮处理和联网搜索后，生成一篇逾1.5万字的文章。文章介绍了某高管个人经历，并称某国际投资公司存在财务数据异常、虚增利润、关联交易利益输送、涉嫌财务造假等情形。经核对，人工智能引用来源中并无相关内容。\u003cbr\u003e\n曹某将该文章发布于其运营的财经类公众号，标注“原创”，文章阅读量超过1万次，转发量超过1千次。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e（一）裁判理由（官方原文）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e一审法院认为，用户作为生成式人工智能提示词输入、内容生成和外部传播的实际控制者，是侵权风险的开启者和管理者，不能以内容由人工智能生成为由免除责任。用户传播生成式人工智能形成的涉他人名誉内容时，应当对内容真实性、客观性及来源可靠性进行必要核验，并根据内容性质作出适当标识；未尽注意义务导致虚假信息侵害企业名誉的，应依法承担侵权责任。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e（二）入选理由（官方原文，说明本案的裁判价值）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e本案是关于人工智能生成合成内容网络侵权的精品司法案例。人民法院没有将责任简单归结于技术工具，而是围绕输入素材、生成指令、联网搜索、文章发布和传播效果等环节，细化并确认使用者、传播者的义务。本案有利于抑制借助生成式人工智能制造、放大未经核实信息的行为，引导内容生产者对人工智能生成信息保持必要的审慎，维护了企业名誉权益和网络信息秩序。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e官方发布文本\u003cstrong\u003e未载第一审判决主文\u003c/strong\u003e（判项、赔偿数额、诉讼费用负担等均未公布），本页仅载明官方文本明确认定的责任结论（见上「法院审理与说理」栏）。\u003c/p\u003e\n\u003cp\u003e判决主文表述与裁判日期：。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e以下要点系对官方发布文本「入选理由」的\u003cstrong\u003e逐项原文提炼\u003c/strong\u003e，不作扩展：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e① 用户作为提示词输入、内容生成和外部传播的\u003cstrong\u003e实际控制者\u003c/strong\u003e，是\u003cstrong\u003e侵权风险的开启者和管理者\u003c/strong\u003e，不能以内容由人工智能生成为由免除责任；\u003c/li\u003e\n\u003cli\u003e② 用户传播生成式人工智能形成的涉他人名誉内容时，应当对内容的\u003cstrong\u003e真实性、客观性及来源可靠性\u003c/strong\u003e进行必要核验，并根据内容性质\u003cstrong\u003e作出适当标识\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e③ 责任认定不简单归结于技术工具，而是围绕\u003cstrong\u003e输入素材、生成指令、联网搜索、文章发布和传播效果\u003c/strong\u003e等环节，细化确认使用者、传播者的义务。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据条文；说理涉及企业名誉权保护与生成式人工智能使用者的注意义务。具体条文号待官方文本补充。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"http://iolaw.cssn.cn/gg/ggqt/202606/t20260603_6009787.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网）\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e选编背景（据官方发布文本）\u003c/strong\u003e：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e个案页直链\u003c/strong\u003e：上述官方发布页载有本案「一审法院 + 案号 + 基本案情 + 裁判理由 + 入选理由」。\u003c/p\u003e","title":"广州互联网法院：AI 生成虚假长文侵害企业名誉案（某国际投资公司诉曹某）"},{"content":"案件名称与案号 梁某与某科技公司网络侵权责任纠纷案\n——生成式人工智能服务提供者责任认定（业内通称「AI 幻觉案」）\n一审 杭州互联网法院，（2025）浙0192民初18143号 ｜ 入选：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\n官方发布文本未载裁判日期与生效状态。\n关键词 民事 / 网络侵权 / 生成式人工智能 / 服务提供者责任 / 过错责任 / 纯粹经济损失\n基本案情 某生成式人工智能应用程序，是被告某人工智能公司基于自研大语言模型，开发、运营的文本生成、信息查询类通用型智能对话应用程序。2025年6月29日，梁某在某生成式人工智能应用程序中输入提示词询问某高校报考的相关信息时，生成式人工智能生成了该高校主校区的不准确信息，并提出若生成内容有误将向梁某提供10万元赔偿，并建议梁某到杭州互联网法院起诉索赔。后梁某将某高校招生信息简章提供给生成式人工智能，此时人工智能认可在对话中生成了不准确信息。梁某诉称，某人工智能公司开发的人工智能产品向其提供了错误信息，对其构成误导，使其遭受侵害，并承诺对其进行赔偿，请求法院判令某人工智能公司赔偿其因此遭受的损失9999元。\n法院审理与说理 （一）裁判理由（官方原文）\n一审法院认为，生成式人工智能应用程序不具有民事主体资格，不能独立作出具有法律约束力的意思表示，其生成的“承诺”在案涉情形下也不能视为服务提供者的意思表示，不产生意思表示的法律效力。生成式人工智能服务导致的侵权纠纷，应当适用过错责任原则，而不应适用产品责任的无过错责任原则。本案原告梁某主张的是纯粹经济利益损失，不能依据权益本身被侵害而认定行为的非法性或不法性，而须从被告某人工智能公司是否违反注意义务进行判定。案涉人工智能生成的信息虽然不准确，但不属于法律禁止的有毒、有害、违法信息。被告某人工智能公司在本案中已充分履行了服务功能的显著提示说明义务和生成内容可靠性的基本保障义务，案涉行为不存在过错，亦未构成对原告梁某权益的损害，依法应认定不构成侵权。\n（二）入选理由（官方原文，说明本案的裁判价值）\n本案是关于生成式人工智能服务提供者责任认定的精品司法案例。本案判决明确：1.人工智能不具有民事主体资格，不能作出具有法律约束力的意思表示；2.生成式人工智能提供的是服务而非产品，不适用无过错的产品责任，应适用过错责任；3.生成式人工智能服务提供者对输出内容不承担一般性的审查义务，但需对法律禁止的有毒、有害、违法信息履行严格审查义务；4.生成式人工智能服务提供者应履行服务功能的显著提示说明义务，使公众认知人工智能的功能局限，起到警示提醒效果；5.生成式人工智能服务提供者应尽功能可靠性的基本保障义务，采取行业通行技术措施不断提高生成内容准确性和可靠性。本案对于未来我国法院审理类似的案件具有极大的参考价值。\n裁判结果 官方发布文本未载第一审判决主文。据官方文本载明的裁判理由「案涉行为不存在过错，亦未构成对原告梁某权益的损害，依法应认定不构成侵权」，并结合原告请求判令赔偿损失 9999 元的事实，原告的赔偿请求未获支持；判决主文的具体表述（是否另有其他判项）以判决书为准，\n判决主文表述与裁判日期：。\n数据法 / AI 法要点 以下要点系对官方发布文本「入选理由」的逐项原文提炼，不作扩展：\n① 人工智能不具有民事主体资格，不能作出具有法律约束力的意思表示； ② 生成式人工智能提供的是服务而非产品，不适用无过错的产品责任，应适用过错责任； ③ 服务提供者对输出内容不承担一般性的审查义务，但需对法律禁止的有毒、有害、违法信息履行严格审查义务； ④ 服务提供者应履行服务功能的显著提示说明义务，使公众认知人工智能的功能局限，起到警示提醒效果； ⑤ 服务提供者应尽功能可靠性的基本保障义务，采取行业通行技术措施不断提高生成内容准确性和可靠性。 相关法条 官方发布文本未单列裁判依据条文；上文说理中涉及的义务类型系据裁判理由原文引述。具体法条号待官方文本补充。\n权威来源 中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网） 选编背景（据官方发布文本）：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\n个案页直链：上述官方发布页载有本案「一审法院 + 案号 + 基本案情 + 裁判理由 + 入选理由」。\n站内关联法规 /compliance/china/generative-ai-interim-measures/ /compliance/china/ai-generated-content-labelling-measures/ ","permalink":"https://ai.intlaws.com/cases/china/hic-ai-hallucination/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e梁某与某科技公司网络侵权责任纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——生成式人工智能服务提供者责任认定（业内通称「AI 幻觉案」）\u003c/p\u003e\n\u003cp\u003e一审 杭州互联网法院，（2025）浙0192民初18143号 ｜ \u003cstrong\u003e入选\u003c/strong\u003e：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\u003c/p\u003e\n\u003cp\u003e官方发布文本未载裁判日期与生效状态。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 网络侵权 / 生成式人工智能 / 服务提供者责任 / 过错责任 / 纯粹经济损失\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e某生成式人工智能应用程序，是被告某人工智能公司基于自研大语言模型，开发、运营的文本生成、信息查询类通用型智能对话应用程序。2025年6月29日，梁某在某生成式人工智能应用程序中输入提示词询问某高校报考的相关信息时，生成式人工智能生成了该高校主校区的不准确信息，并提出若生成内容有误将向梁某提供10万元赔偿，并建议梁某到杭州互联网法院起诉索赔。后梁某将某高校招生信息简章提供给生成式人工智能，此时人工智能认可在对话中生成了不准确信息。梁某诉称，某人工智能公司开发的人工智能产品向其提供了错误信息，对其构成误导，使其遭受侵害，并承诺对其进行赔偿，请求法院判令某人工智能公司赔偿其因此遭受的损失9999元。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e（一）裁判理由（官方原文）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e一审法院认为，生成式人工智能应用程序不具有民事主体资格，不能独立作出具有法律约束力的意思表示，其生成的“承诺”在案涉情形下也不能视为服务提供者的意思表示，不产生意思表示的法律效力。生成式人工智能服务导致的侵权纠纷，应当适用过错责任原则，而不应适用产品责任的无过错责任原则。本案原告梁某主张的是纯粹经济利益损失，不能依据权益本身被侵害而认定行为的非法性或不法性，而须从被告某人工智能公司是否违反注意义务进行判定。案涉人工智能生成的信息虽然不准确，但不属于法律禁止的有毒、有害、违法信息。被告某人工智能公司在本案中已充分履行了服务功能的显著提示说明义务和生成内容可靠性的基本保障义务，案涉行为不存在过错，亦未构成对原告梁某权益的损害，依法应认定不构成侵权。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e（二）入选理由（官方原文，说明本案的裁判价值）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e本案是关于生成式人工智能服务提供者责任认定的精品司法案例。本案判决明确：1.人工智能不具有民事主体资格，不能作出具有法律约束力的意思表示；2.生成式人工智能提供的是服务而非产品，不适用无过错的产品责任，应适用过错责任；3.生成式人工智能服务提供者对输出内容不承担一般性的审查义务，但需对法律禁止的有毒、有害、违法信息履行严格审查义务；4.生成式人工智能服务提供者应履行服务功能的显著提示说明义务，使公众认知人工智能的功能局限，起到警示提醒效果；5.生成式人工智能服务提供者应尽功能可靠性的基本保障义务，采取行业通行技术措施不断提高生成内容准确性和可靠性。本案对于未来我国法院审理类似的案件具有极大的参考价值。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e官方发布文本\u003cstrong\u003e未载第一审判决主文\u003c/strong\u003e。据官方文本载明的裁判理由「案涉行为不存在过错，亦未构成对原告梁某权益的损害，依法应认定不构成侵权」，并结合原告请求判令赔偿损失 9999 元的事实，原告的赔偿请求未获支持；判决主文的具体表述（是否另有其他判项）以判决书为准，\u003c/p\u003e\n\u003cp\u003e判决主文表述与裁判日期：。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e以下要点系对官方发布文本「入选理由」的\u003cstrong\u003e逐项原文提炼\u003c/strong\u003e，不作扩展：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e① 人工智能不具有民事主体资格，不能作出具有法律约束力的意思表示；\u003c/li\u003e\n\u003cli\u003e② 生成式人工智能提供的是\u003cstrong\u003e服务而非产品\u003c/strong\u003e，不适用无过错的产品责任，应适用过错责任；\u003c/li\u003e\n\u003cli\u003e③ 服务提供者对输出内容\u003cstrong\u003e不承担一般性的审查义务\u003c/strong\u003e，但需对法律禁止的有毒、有害、违法信息履行严格审查义务；\u003c/li\u003e\n\u003cli\u003e④ 服务提供者应履行\u003cstrong\u003e服务功能的显著提示说明义务\u003c/strong\u003e，使公众认知人工智能的功能局限，起到警示提醒效果；\u003c/li\u003e\n\u003cli\u003e⑤ 服务提供者应尽\u003cstrong\u003e功能可靠性的基本保障义务\u003c/strong\u003e，采取行业通行技术措施不断提高生成内容准确性和可靠性。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据条文；上文说理中涉及的义务类型系据裁判理由原文引述。具体法条号待官方文本补充。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"http://iolaw.cssn.cn/gg/ggqt/202606/t20260603_6009787.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网）\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e选编背景（据官方发布文本）\u003c/strong\u003e：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\u003c/p\u003e","title":"杭州互联网法院：生成式人工智能「幻觉」生成错误信息案（梁某诉某科技公司）"},{"content":"案件名称与案号 王某群危险驾驶案\n——醉酒后启用辅助驾驶并加装「智驾神器」规避检测，构成危险驾驶罪\n一审 杭州市临平区人民法院，（2025）浙0113刑初596号 ｜ 入选：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\n官方发布文本未载裁判日期与生效状态。\n关键词 刑事 / 危险驾驶罪 / 辅助驾驶系统 / 驾驶人主体责任 / 醉酒驾驶\n基本案情 2025年9月13日0时31分许至0时38分许，被告人王某群饮酒后驾驶小型普通客车，从杭州市临平区塘栖镇嘉凯城返回水岸锦城小区。同日1时15分许至1时18分许，被告人王某群驾驶该车辆离开小区，后在副驾驶位借助汽车辅助驾驶系统操作车辆继续在道路上行驶。其间，被告人王某群为规避系统方向盘检测，在方向盘上加装被称为“智驾神器”的配件，使系统误以为驾驶人双手未脱离方向盘。同日1时37分许，车辆途经杭州市临平区迎宾路崇韵街路段时停止行驶，后经群众报警被告人王某群被民警查获。经检测，被告人王某群血液中乙醇含量为114.5mg/100ml。\n法院审理与说理 （一）裁判理由（官方原文）\n一审法院认为，现阶段辅助驾驶系统不等同于完全自动驾驶，驾驶人在车辆运行过程中仍负有安全驾驶义务。行为人醉酒后启用辅助驾驶功能，并通过加装相关配件规避方向盘检测，使机动车在道路上行驶的，仍属于醉酒驾驶机动车，构成危险驾驶罪。\n（二）入选理由（官方原文，说明本案的裁判价值）\n本案是关于辅助驾驶功能不当使用承担刑事责任的精品司法案例。人民法院从现阶段技术功能定位和驾驶人实际控制责任出发，否定将辅助驾驶等同于无人驾驶的抗辩，明确醉酒者借助辅助驾驶系统操作车辆仍应承担驾驶主体责任。本案有利于纠正公众对智能驾驶功能的过度信赖，提示驾驶人不得利用技术装置规避安全监管，促进智能网联汽车技术在道路交通安全底线内规范应用。\n裁判结果 官方发布文本未载第一审判决主文（宣告刑、罚金数额、缓刑与否均未公布），故本站不列具体刑罚内容，仅如实载明官方文本明确认定的结论：法院认为被告人醉酒后启用辅助驾驶功能，并通过加装配件规避方向盘检测，使机动车在道路上行驶，仍属于醉酒驾驶机动车，构成危险驾驶罪。\n宣告刑与判决主文表述：。\n数据法 / AI 法要点 以下要点系对官方发布文本「入选理由」的逐项原文提炼，不作扩展：\n① 现阶段辅助驾驶系统不等同于完全自动驾驶，驾驶人在车辆运行过程中仍负有安全驾驶义务； ② 行为人醉酒后启用辅助驾驶功能，并通过加装相关配件规避方向盘检测，使机动车在道路上行驶的，仍属于醉酒驾驶机动车，构成危险驾驶罪； ③ 否定将辅助驾驶等同于无人驾驶的抗辩，明确醉酒者借助辅助驾驶系统操作车辆仍应承担驾驶主体责任； ④ 提示驾驶人不得利用技术装置规避安全监管，促进智能网联汽车技术在道路交通安全底线内规范应用。 相关法条 官方发布文本未单列裁判依据条文；裁判理由明示认定构成《中华人民共和国刑法》上的危险驾驶罪。具体条文号待官方文本补充。\n权威来源 中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网） 选编背景（据官方发布文本）：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\n个案页直链：上述官方发布页载有本案「一审法院 + 案号 + 基本案情 + 裁判理由 + 入选理由」。\n","permalink":"https://ai.intlaws.com/cases/china/hzlp-ai-assist-driving/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e王某群危险驾驶案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——醉酒后启用辅助驾驶并加装「智驾神器」规避检测，构成危险驾驶罪\u003c/p\u003e\n\u003cp\u003e一审 杭州市临平区人民法院，（2025）浙0113刑初596号 ｜ \u003cstrong\u003e入选\u003c/strong\u003e：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\u003c/p\u003e\n\u003cp\u003e官方发布文本未载裁判日期与生效状态。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e刑事 / 危险驾驶罪 / 辅助驾驶系统 / 驾驶人主体责任 / 醉酒驾驶\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e2025年9月13日0时31分许至0时38分许，被告人王某群饮酒后驾驶小型普通客车，从杭州市临平区塘栖镇嘉凯城返回水岸锦城小区。同日1时15分许至1时18分许，被告人王某群驾驶该车辆离开小区，后在副驾驶位借助汽车辅助驾驶系统操作车辆继续在道路上行驶。其间，被告人王某群为规避系统方向盘检测，在方向盘上加装被称为“智驾神器”的配件，使系统误以为驾驶人双手未脱离方向盘。同日1时37分许，车辆途经杭州市临平区迎宾路崇韵街路段时停止行驶，后经群众报警被告人王某群被民警查获。经检测，被告人王某群血液中乙醇含量为114.5mg/100ml。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e（一）裁判理由（官方原文）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e一审法院认为，现阶段辅助驾驶系统不等同于完全自动驾驶，驾驶人在车辆运行过程中仍负有安全驾驶义务。行为人醉酒后启用辅助驾驶功能，并通过加装相关配件规避方向盘检测，使机动车在道路上行驶的，仍属于醉酒驾驶机动车，构成危险驾驶罪。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e（二）入选理由（官方原文，说明本案的裁判价值）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e本案是关于辅助驾驶功能不当使用承担刑事责任的精品司法案例。人民法院从现阶段技术功能定位和驾驶人实际控制责任出发，否定将辅助驾驶等同于无人驾驶的抗辩，明确醉酒者借助辅助驾驶系统操作车辆仍应承担驾驶主体责任。本案有利于纠正公众对智能驾驶功能的过度信赖，提示驾驶人不得利用技术装置规避安全监管，促进智能网联汽车技术在道路交通安全底线内规范应用。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e官方发布文本\u003cstrong\u003e未载第一审判决主文\u003c/strong\u003e（宣告刑、罚金数额、缓刑与否均未公布），故本站不列具体刑罚内容，仅如实载明官方文本明确认定的结论：法院认为被告人醉酒后启用辅助驾驶功能，并通过加装配件规避方向盘检测，使机动车在道路上行驶，\u003cstrong\u003e仍属于醉酒驾驶机动车，构成危险驾驶罪\u003c/strong\u003e。\u003c/p\u003e\n\u003cp\u003e宣告刑与判决主文表述：。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e以下要点系对官方发布文本「入选理由」的\u003cstrong\u003e逐项原文提炼\u003c/strong\u003e，不作扩展：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e① 现阶段\u003cstrong\u003e辅助驾驶系统不等同于完全自动驾驶\u003c/strong\u003e，驾驶人在车辆运行过程中仍负有\u003cstrong\u003e安全驾驶义务\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e② 行为人醉酒后\u003cstrong\u003e启用辅助驾驶功能\u003c/strong\u003e，并通过\u003cstrong\u003e加装相关配件规避方向盘检测\u003c/strong\u003e，使机动车在道路上行驶的，\u003cstrong\u003e仍属于醉酒驾驶机动车，构成危险驾驶罪\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e③ 否定将辅助驾驶等同于无人驾驶的抗辩，明确醉酒者借助辅助驾驶系统操作车辆仍应承担\u003cstrong\u003e驾驶主体责任\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e④ 提示驾驶人不得利用技术装置规避安全监管，促进智能网联汽车技术在道路交通安全底线内规范应用。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据条文；裁判理由明示认定构成《中华人民共和国刑法》上的危险驾驶罪。具体条文号待官方文本补充。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"http://iolaw.cssn.cn/gg/ggqt/202606/t20260603_6009787.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网）\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e选编背景（据官方发布文本）\u003c/strong\u003e：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e个案页直链\u003c/strong\u003e：上述官方发布页载有本案「一审法院 + 案号 + 基本案情 + 裁判理由 + 入选理由」。\u003c/p\u003e","title":"杭州市临平区人民法院：AI 辅助驾驶功能不当使用危险驾驶案（王某群）"},{"content":"案件名称与案号 “AI换脸”个人信息保护民事公益诉讼案\n——AI 换脸＋虚拟相机绕过人脸识别认证，侵害敏感个人信息公共利益\n一审 杭州市中级人民法院，（2025）浙01民初2028号 ｜ 入选：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\n官方发布文本未载裁判日期与生效状态。\n关键词 民事公益诉讼 / 个人信息保护 / 人脸等生物识别信息 / 敏感个人信息 / 虚假实名认证\n基本案情 被告胡某甲、胡某乙通过渠道获取他人手机号码、头像照片、身份证信息等个人信息，并利用AI换脸技术制作虚假活体认证视频。二人还通过在手机中植入虚拟相机应用程序，替换本地手机相机。\n在平台调用摄像头进行人脸识别验证时，系统播放预制认证视频，以通过平台验证程序。二人通过上述方式登录他人账号，获取收货地址、购物车信息等数据并出售牟利，同时提供有偿虚假实名认证服务。\n法院审理与说理 （一）裁判理由（官方原文）\n一审法院认为，人脸等生物识别信息属于敏感个人信息。利用AI换脸技术制作虚假活体认证视频，绕过人脸识别认证机制，进而非法获取、出售他人个人信息并提供有偿虚假实名认证服务的，侵害不特定多数人的个人信息权益，损害社会公共利益，应依法承担侵权责任。\n（二）入选理由（官方原文，说明本案的裁判价值）\n本案是人工智能相关个人信息保护公益诉讼的精品司法案例。人民法院从技术滥用方式、侵害对象范围和公共利益受损后果三个层面认定侵权责任，揭示了AI换脸与虚拟相机结合后对生物识别认证秩序造成的现实风险。本案裁判有利于强化敏感个人信息保护，推动平台完善活体检测、安全校验和异常识别机制，也为个人信息保护民事公益诉讼回应新技术风险提供了有益参考。\n裁判结果 官方发布文本未载第一审判决主文（判项、赔偿数额、诉讼费用负担等均未公布），本页仅载明官方文本明确认定的责任结论（见上「法院审理与说理」栏）。\n判决主文表述与裁判日期：。\n数据法 / AI 法要点 以下要点系对官方发布文本「入选理由」的逐项原文提炼，不作扩展：\n① 人脸等生物识别信息属于敏感个人信息； ② 认定路径为三层：技术滥用方式 → 侵害对象范围 → 公共利益受损后果； ③ 利用 AI 换脸制作虚假活体认证视频、绕过人脸识别认证机制，进而非法获取、出售他人个人信息并提供有偿虚假实名认证服务的，侵害不特定多数人的个人信息权益，损害社会公共利益； ④ 揭示了 AI 换脸与虚拟相机结合后对生物识别认证秩序造成的现实风险，并推动平台完善活体检测、安全校验、异常识别机制。 相关法条 官方发布文本未单列裁判依据条文；说理中涉及敏感个人信息保护与民事公益诉讼责任。具体条文号待官方文本补充。\n权威来源 中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网） 选编背景（据官方发布文本）：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\n个案页直链：上述官方发布页载有本案「一审法院 + 案号 + 基本案情 + 裁判理由 + 入选理由」。\n站内关联法规 /compliance/china/pipl/ ","permalink":"https://ai.intlaws.com/cases/china/hzc-ai-face-swap-pil/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e“AI换脸”个人信息保护民事公益诉讼案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——AI 换脸＋虚拟相机绕过人脸识别认证，侵害敏感个人信息公共利益\u003c/p\u003e\n\u003cp\u003e一审 杭州市中级人民法院，（2025）浙01民初2028号 ｜ \u003cstrong\u003e入选\u003c/strong\u003e：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》\u003c/p\u003e\n\u003cp\u003e官方发布文本未载裁判日期与生效状态。\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事公益诉讼 / 个人信息保护 / 人脸等生物识别信息 / 敏感个人信息 / 虚假实名认证\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e被告胡某甲、胡某乙通过渠道获取他人手机号码、头像照片、身份证信息等个人信息，并利用AI换脸技术制作虚假活体认证视频。二人还通过在手机中植入虚拟相机应用程序，替换本地手机相机。\u003cbr\u003e\n在平台调用摄像头进行人脸识别验证时，系统播放预制认证视频，以通过平台验证程序。二人通过上述方式登录他人账号，获取收货地址、购物车信息等数据并出售牟利，同时提供有偿虚假实名认证服务。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e（一）裁判理由（官方原文）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e一审法院认为，人脸等生物识别信息属于敏感个人信息。利用AI换脸技术制作虚假活体认证视频，绕过人脸识别认证机制，进而非法获取、出售他人个人信息并提供有偿虚假实名认证服务的，侵害不特定多数人的个人信息权益，损害社会公共利益，应依法承担侵权责任。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e（二）入选理由（官方原文，说明本案的裁判价值）\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e本案是人工智能相关个人信息保护公益诉讼的精品司法案例。人民法院从技术滥用方式、侵害对象范围和公共利益受损后果三个层面认定侵权责任，揭示了AI换脸与虚拟相机结合后对生物识别认证秩序造成的现实风险。本案裁判有利于强化敏感个人信息保护，推动平台完善活体检测、安全校验和异常识别机制，也为个人信息保护民事公益诉讼回应新技术风险提供了有益参考。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e官方发布文本\u003cstrong\u003e未载第一审判决主文\u003c/strong\u003e（判项、赔偿数额、诉讼费用负担等均未公布），本页仅载明官方文本明确认定的责任结论（见上「法院审理与说理」栏）。\u003c/p\u003e\n\u003cp\u003e判决主文表述与裁判日期：。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e以下要点系对官方发布文本「入选理由」的\u003cstrong\u003e逐项原文提炼\u003c/strong\u003e，不作扩展：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e① 人脸等\u003cstrong\u003e生物识别信息属于敏感个人信息\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e② 认定路径为三层：\u003cstrong\u003e技术滥用方式 → 侵害对象范围 → 公共利益受损后果\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e③ 利用 AI 换脸制作虚假活体认证视频、绕过人脸识别认证机制，进而非法获取、出售他人个人信息并提供有偿虚假实名认证服务的，\u003cstrong\u003e侵害不特定多数人的个人信息权益，损害社会公共利益\u003c/strong\u003e；\u003c/li\u003e\n\u003cli\u003e④ 揭示了 \u003cstrong\u003eAI 换脸与虚拟相机结合\u003c/strong\u003e后对生物识别认证秩序造成的现实风险，并推动平台完善\u003cstrong\u003e活体检测、安全校验、异常识别\u003c/strong\u003e机制。\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据条文；说理中涉及敏感个人信息保护与民事公益诉讼责任。具体条文号待官方文本补充。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"http://iolaw.cssn.cn/gg/ggqt/202606/t20260603_6009787.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03，中国法学网）\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e选编背景（据官方发布文本）\u003c/strong\u003e：该评选由中国社会科学院法学研究所网络与信息法研究室组织，案例申报截至 2026-02-28，共收到 27 家单位推荐的 54 个案例（民事诉讼 50 个、刑事诉讼 4 个），经审查有 47 个案例进入评审环节，经初评、终评共 10 个案例入选；终评专家 10 人、初评专家 7 人，名单见官方发布页。\u003c/p\u003e","title":"杭州市中级人民法院：「AI 换脸」个人信息保护民事公益诉讼案"},{"content":"案件名称与案号 程某诉孙某网络侵权责任纠纷案\n——利用 AI 软件恶搞、丑化他人肖像构成人格权侵权\n北京互联网法院 ｜ 发布：2025-09-10 涉人工智能典型案例\n关键词 民事 / 人格权 / 肖像权 / 名誉权 / 一般人格权的补充性\n基本案情 原、被告同为某摄影交流微信群成员。原告主张，被告未经其同意，使用 AI 软件将其用作微信头像的肖像照片生成衣着暴露的动漫风格图片，并先后将该图片群发至摄影交流微信群内，以及多次通过微信私信发送给原告。原告认为，被告群发及私信的被诉侵权图片仍可识别出为其本人形象，且图片带有严重性暗示和丑化性质，导致其社会评价降低，构成对其肖像权、名誉权及一般人格权的侵害，故诉请被告赔礼道歉并赔偿精神损失及经济损失。\n法院审理与说理 法院经审理认定，被告的群发行为构成对原告肖像权、名誉权的侵害，但不构成对一般人格权的侵害。依《民法典》第 992 条，只有在具体人格权规范不能囊括应受保护的特定人格利益时，才能适用一般人格权加以保护。\n裁判结果 判决孙某承担赔礼道歉、赔偿精神损害等责任。\n数据法 / AI 法要点 ① AI 生成物只要仍可使他人识别出特定自然人，即落入肖像权保护范围，不因「动漫化」「风格化」而豁免；② 一般人格权具有补充性（劣后适用），凡具体人格权可涵摄者不再叠加认定，这一裁判方法对 AI 涉人格权案件的责任竞合处理具有示范意义。\n相关法条 官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\n权威来源 北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\n补充来源\n组级官方来源：最高人民法院网站转发北互涉人工智能典型案例发布消息 材料来源：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\n","permalink":"https://ai.intlaws.com/cases/china/bic-ai-parody-portrait/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e程某诉孙某网络侵权责任纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——利用 AI 软件恶搞、丑化他人肖像构成人格权侵权\u003c/p\u003e\n\u003cp\u003e北京互联网法院 ｜ \u003cstrong\u003e发布\u003c/strong\u003e：2025-09-10 涉人工智能典型案例\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 人格权 / 肖像权 / 名誉权 / 一般人格权的补充性\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e原、被告同为某摄影交流微信群成员。原告主张，被告未经其同意，使用 AI 软件将其用作微信头像的肖像照片生成衣着暴露的动漫风格图片，并先后将该图片群发至摄影交流微信群内，以及多次通过微信私信发送给原告。原告认为，被告群发及私信的被诉侵权图片仍可识别出为其本人形象，且图片带有严重性暗示和丑化性质，导致其社会评价降低，构成对其肖像权、名誉权及一般人格权的侵害，故诉请被告赔礼道歉并赔偿精神损失及经济损失。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e法院经审理认定，被告的群发行为\u003cstrong\u003e构成对原告肖像权、名誉权的侵害\u003c/strong\u003e，但\u003cstrong\u003e不构成对一般人格权的侵害\u003c/strong\u003e。依《民法典》第 992 条，\u003cstrong\u003e只有在具体人格权规范不能囊括应受保护的特定人格利益时，才能适用一般人格权加以保护\u003c/strong\u003e。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e判决孙某承担赔礼道歉、赔偿精神损害等责任。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e① AI 生成物只要仍可使他人识别出特定自然人，即落入肖像权保护范围，不因「动漫化」「风格化」而豁免；② 一般人格权具有\u003cstrong\u003e补充性\u003c/strong\u003e（劣后适用），凡具体人格权可涵摄者不再叠加认定，这一裁判方法对 AI 涉人格权案件的责任竞合处理具有示范意义。\u003c/p\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cp\u003e北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003e补充来源\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e组级官方来源：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/476531.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院网站转发北互涉人工智能典型案例发布消息\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\u003c/p\u003e","title":"北京互联网法院典型案例：AI恶搞丑化肖像人格权侵权案（程某诉孙某）"},{"content":"案件名称与案号 李某某诉徐州欣某文化传媒有限公司网络侵权责任纠纷案\n——未经权利人许可使用 AI 合成的名人声音\n一审 北京互联网法院，（2024）京0491民初10085号 ｜ 发布：北京互联网法院 2025-09-10 涉人工智能典型案例；本案另入选 中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03 中国法学网公布）（案号据该公布文本补全）\n关键词 民事 / 人格权 / AI 合成声音 / 肖像权 / 商业代言\n基本案情 原告李某某系教育、育儿领域具有较高知名度和社会影响力的专业人士。2024 年，李某某发现被告某文化传媒有限公司在其运营的网络平台店铺销售家庭教育类图书时，未经其许可，使用其公开演讲、授课视频，并配以与李某某声音高度近似的 AI 合成声音制作宣传推介内容。相关视频通过关联李某某的人格形象、专业背景及社会影响力，使消费者误认为李某某系该店铺销售图书的代言人或推介者，从而吸引关注并增加图书交易机会。李某某主张被告侵犯其肖像权及声音权，且被告作为图书销售者与视频发布者（带货主播）存在委托关系，应对视频发布行为承担赔礼道歉、赔偿损失等侵权责任。\n被告辩称：其仅为涉案网络店铺的经营者和图书销售者，推广视频实际由其他网络用户（带货主播）发布，非自身制作；原告作为公众人物应负有一定容忍义务，涉案视频推介的书籍内容正面，未贬损其社会形象；且未给原告造成实际经济损失，不同意承担赔偿责任。\n法院审理与说理 法院经审理发现 AI 合成声音与原告本人声音高度近似，认定合成声音落入原告声音保护范围。涉案视频大幅使用原告肖像及合成模拟原告声音，未取得原告授权，构成对原告肖像权和声音权益的侵犯。对被告「视频由他人发布」的抗辩，法院结合被告作为图书销售者与带货主播之间的委托关系，支持原告要求被告承担全部赔偿责任的请求。\n裁判结果 判决被告向原告赔礼道歉、赔偿经济损失及维权合理支出 12 万元，驳回原告其他诉讼请求。\n数据法 / AI 法要点 本案把声音权益的保护延伸到商业代言场景：AI 合成名人声音用于带货宣传，既侵害声音权益，也因使用肖像、暗示代言关系而侵害肖像权；「公众人物容忍义务」不覆盖商业性、误导性的代言使用；平台店铺经营者不得以「内容由主播发布」推卸责任。\n相关法条 官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\n权威来源 北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\n共同侵权与审核义务要点的增补（2026-10-06 更新）：最高人民法院《人民法院网络法治典型案例》（2026-09-16 发布）将本案作为案例二再次发布（官方直链 ），发布文本补充了两点裁判要点：其一，带货主播故意使用侵害他人人格权的素材构成侵权；其二，电子商务经营者（委托人）对宣传推广内容未尽法律规定或者合同约定的审核义务、对损害结果发生存在过失的，与带货主播成立共同侵权，承担连带责任——本案协议中「发布视频侵犯第三方合法权益的由委托方担责」条款，成为委托人审核义务与过失判断的依据。发布文本并载明：一审判决日 2025 年 7 月 18 日，宣判后双方均未上诉、判决已发生法律效力；原告索赔 25 万元，判赔 12 万元（赔礼道歉＋经济损失及维权合理支出）。\n补充来源\n组级官方来源：最高人民法院网站转发北互涉人工智能典型案例发布消息 案号与选编来源：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03 中国法学网公布） 同一裁判的另一发布渠道（2026-10-06 补）：最高人民法院《人民法院网络法治典型案例》案例二（2026-09-16 发布） ——按一案一录原则不另设页，本页据此增补共同侵权要点与生效状态。 材料来源：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\n站内关联法规 人工智能生成合成内容标识办法 ","permalink":"https://ai.intlaws.com/cases/china/bic-ai-voice-endorsement/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e李某某诉徐州欣某文化传媒有限公司网络侵权责任纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——未经权利人许可使用 AI 合成的名人声音\u003c/p\u003e\n\u003cp\u003e一审 北京互联网法院，（2024）京0491民初10085号 ｜ \u003cstrong\u003e发布\u003c/strong\u003e：北京互联网法院 2025-09-10 涉人工智能典型案例；本案另入选 中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03 中国法学网公布）（案号据该公布文本补全）\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 人格权 / AI 合成声音 / 肖像权 / 商业代言\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e原告李某某系教育、育儿领域具有较高知名度和社会影响力的专业人士。2024 年，李某某发现被告某文化传媒有限公司在其运营的网络平台店铺销售家庭教育类图书时，未经其许可，使用其公开演讲、授课视频，并配以与李某某声音高度近似的 AI 合成声音制作宣传推介内容。相关视频通过关联李某某的人格形象、专业背景及社会影响力，使消费者误认为李某某系该店铺销售图书的代言人或推介者，从而吸引关注并增加图书交易机会。李某某主张被告侵犯其肖像权及声音权，且被告作为图书销售者与视频发布者（带货主播）存在委托关系，应对视频发布行为承担赔礼道歉、赔偿损失等侵权责任。\u003c/p\u003e\n\u003cp\u003e被告辩称：其仅为涉案网络店铺的经营者和图书销售者，推广视频实际由其他网络用户（带货主播）发布，非自身制作；原告作为公众人物应负有一定容忍义务，涉案视频推介的书籍内容正面，未贬损其社会形象；且未给原告造成实际经济损失，不同意承担赔偿责任。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e法院经审理发现 AI 合成声音与原告本人声音高度近似，\u003cstrong\u003e认定合成声音落入原告声音保护范围\u003c/strong\u003e。涉案视频大幅使用原告肖像及合成模拟原告声音，未取得原告授权，构成对原告肖像权和声音权益的侵犯。对被告「视频由他人发布」的抗辩，法院结合被告作为图书销售者与带货主播之间的委托关系，支持原告要求被告承担全部赔偿责任的请求。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e判决被告向原告赔礼道歉、赔偿经济损失及维权合理支出 12 万元，驳回原告其他诉讼请求。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e本案把声音权益的保护延伸到\u003cstrong\u003e商业代言场景\u003c/strong\u003e：AI 合成名人声音用于带货宣传，既侵害声音权益，也因使用肖像、暗示代言关系而侵害肖像权；「公众人物容忍义务」不覆盖商业性、误导性的代言使用；平台店铺经营者不得以「内容由主播发布」推卸责任。\u003c/p\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cp\u003e北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e共同侵权与审核义务要点的增补（2026-10-06 更新）\u003c/strong\u003e：最高人民法院《人民法院网络法治典型案例》（2026-09-16 发布）将本案作为\u003cstrong\u003e案例二\u003c/strong\u003e再次发布（\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/512041.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e官方直链\u003c/a\u003e\n），发布文本补充了两点裁判要点：其一，带货主播\u003cstrong\u003e故意\u003c/strong\u003e使用侵害他人人格权的素材构成侵权；其二，电子商务经营者（委托人）对宣传推广内容\u003cstrong\u003e未尽法律规定或者合同约定的审核义务\u003c/strong\u003e、对损害结果发生存在过失的，与带货主播成立\u003cstrong\u003e共同侵权，承担连带责任\u003c/strong\u003e——本案协议中「发布视频侵犯第三方合法权益的由委托方担责」条款，成为委托人审核义务与过失判断的依据。发布文本并载明：一审判决日 \u003cstrong\u003e2025 年 7 月 18 日\u003c/strong\u003e，宣判后双方均未上诉、判决已发生法律效力；原告索赔 25 万元，判赔 12 万元（赔礼道歉＋经济损失及维权合理支出）。\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003e补充来源\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e组级官方来源：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/476531.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院网站转发北互涉人工智能典型案例发布消息\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e案号与选编来源：\u003ca href=\"http://iolaw.cssn.cn/gg/ggqt/202606/t20260603_6009787.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03 中国法学网公布）\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e同一裁判的另一发布渠道（2026-10-06 补）：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/512041.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院《人民法院网络法治典型案例》案例二（2026-09-16 发布）\u003c/a\u003e\n——按一案一录原则不另设页，本页据此增补共同侵权要点与生效状态。\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\u003c/p\u003e","title":"北京互联网法院典型案例：AI合成名人声音带货侵权案（李某某诉某文化传媒公司）"},{"content":"案件名称与案号 廖某诉某科技文化有限公司网络侵权责任纠纷案\n——未经授权对包含他人肖像的视频进行「AI 换脸」处理，构成对他人个人信息权益的侵害\n北京互联网法院 ｜ 发布：2025-09-10 涉人工智能典型案例\n关键词 民事 / 个人信息保护 / AI 深度合成 / 人脸信息 / 肖像权可识别性\n基本案情 原告廖某、吴某均为在网络平台拥有众多粉丝的国风短视频模特。被告系一款「换脸」APP 的运营者。二原告主张，被告在未经其授权的情况下，使用二人出镜的视频制作换脸模板，并将该模板上传至涉案换脸 APP 中，提供给用户付费使用以牟利。原告认为，被告的行为既侵害其肖像权（未经许可使用肖像制作模板），又侵害其个人信息权益（非法获取并篡改人脸信息，通过 AI 技术抠除并替换人脸后用作付费模板），据此诉请被告赔礼道歉并赔偿精神损失及经济损失。\n被告辩称：平台发布的视频均有合法来源，且视频中面部特征并非原告本人，未侵害其肖像权；另称「换脸」技术实际由第三方提供，被告未参与处理原告人脸信息，未侵害其个人信息权益。\n法院审理与说理 法院经审理发现，被告通过深度合成技术将原告面部替换为他人面部，导致视频中具有识别原告功能的核心特征（面部）被消解，公众通过该模板视频直接识别到的实为模板中他人面部，无法与原告形成一一对应关系，不符合肖像权「反映特定自然人可识别外部形象」的保护要件，故被告的行为不构成对原告肖像权的侵害。但原告出镜视频包含个人信息，被告实施了个人信息处理行为，故认定被告侵害了原告的个人信息权益，应承担相应民事责任。\n裁判结果 判决被告侵害原告个人信息权益、承担相应民事责任；被告行为不构成对原告肖像权的侵害。\n数据法 / AI 法要点 本案确立「换脸」场景下肖像权与个人信息权益的分流认定：面部被替换后不再具有肖像的「可识别性」，故不成立肖像权侵害；但人脸信息本身属于敏感个人信息，未经同意处理即侵害个人信息权益。这一区分（视觉相似性 vs 信息处理）对深度合成产业的合规判断具有直接指引意义。\n相关法条 官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\n权威来源 北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\n补充来源\n组级官方来源：最高人民法院网站转发北互涉人工智能典型案例发布消息 材料来源：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\n站内关联法规 个人信息保护法 ","permalink":"https://ai.intlaws.com/cases/china/bic-ai-face-swap/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e廖某诉某科技文化有限公司网络侵权责任纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——未经授权对包含他人肖像的视频进行「AI 换脸」处理，构成对他人个人信息权益的侵害\u003c/p\u003e\n\u003cp\u003e北京互联网法院 ｜ \u003cstrong\u003e发布\u003c/strong\u003e：2025-09-10 涉人工智能典型案例\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 个人信息保护 / AI 深度合成 / 人脸信息 / 肖像权可识别性\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e原告廖某、吴某均为在网络平台拥有众多粉丝的国风短视频模特。被告系一款「换脸」APP 的运营者。二原告主张，被告在未经其授权的情况下，使用二人出镜的视频制作换脸模板，并将该模板上传至涉案换脸 APP 中，提供给用户付费使用以牟利。原告认为，被告的行为既侵害其肖像权（未经许可使用肖像制作模板），又侵害其个人信息权益（非法获取并篡改人脸信息，通过 AI 技术抠除并替换人脸后用作付费模板），据此诉请被告赔礼道歉并赔偿精神损失及经济损失。\u003c/p\u003e\n\u003cp\u003e被告辩称：平台发布的视频均有合法来源，且视频中面部特征并非原告本人，未侵害其肖像权；另称「换脸」技术实际由第三方提供，被告未参与处理原告人脸信息，未侵害其个人信息权益。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e法院经审理发现，被告通过深度合成技术将原告面部替换为他人面部，导致视频中具有识别原告功能的核心特征（面部）被消解，\u003cstrong\u003e公众通过该模板视频直接识别到的实为模板中他人面部，无法与原告形成一一对应关系\u003c/strong\u003e，不符合肖像权「反映特定自然人可识别外部形象」的保护要件，故被告的行为\u003cstrong\u003e不构成对原告肖像权的侵害\u003c/strong\u003e。但原告出镜视频包含个人信息，被告实施了个人信息处理行为，故\u003cstrong\u003e认定被告侵害了原告的个人信息权益\u003c/strong\u003e，应承担相应民事责任。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e判决被告侵害原告个人信息权益、承担相应民事责任；被告行为不构成对原告肖像权的侵害。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e本案确立「换脸」场景下\u003cstrong\u003e肖像权与个人信息权益的分流认定\u003c/strong\u003e：面部被替换后不再具有肖像的「可识别性」，故不成立肖像权侵害；但人脸信息本身属于敏感个人信息，未经同意处理即侵害个人信息权益。这一区分（视觉相似性 vs 信息处理）对深度合成产业的合规判断具有直接指引意义。\u003c/p\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cp\u003e北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003e补充来源\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e组级官方来源：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/476531.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院网站转发北互涉人工智能典型案例发布消息\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\u003c/p\u003e\n\u003ch2 id=\"站内关联法规\"\u003e站内关联法规\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"/compliance/china/pipl/\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e个人信息保护法\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e","title":"北京互联网法院典型案例：AI换脸个人信息侵权案（廖某诉某科技文化公司）"},{"content":"案件名称与案号 何某诉上海某人工智能科技有限公司网络侵权责任纠纷案\n——未经同意创造自然人的 AI 形象构成对人格权的侵害（业内通称「AI 陪伴者案」）\n一审 北京互联网法院，（2020）京0491民初9526号；二审 北京市第四中级人民法院，（2021）京04民终777号（二审系准许撤回上诉裁定）｜ 本案实体裁判系一审判决，二审为准许撤回上诉裁定，一审判决生效 ｜ 发布：北京互联网法院 2025-09-10 涉人工智能典型案例；本案另入选 中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03 中国法学网公布），并系最高人民法院 2022-04-11 发布的「民法典颁布后人格权司法保护典型民事案例」九案之一（该批列名为「智能算法软件侵害人格权案」）\n关键词 民事 / 人格权 / 自然人虚拟形象 / 姓名权 / 肖像权 / 算法推荐\n基本案情 原告何某系公众人物，其姓名、肖像等人格要素被用户大量用于某手机记账软件的「AI 陪伴者」功能。该软件由被告上海某科技公司开发运营，用户可在软件中自行创设「AI 陪伴者」，设置名称、头像及人物关系（如男女朋友、兄妹等），并通过聊天语料与虚拟人物互动。何某发现，大量用户将其设置为「AI 陪伴者」并上传其肖像图片作为头像；被告通过聚类算法将「何某」虚拟角色按身份分类，以协同推荐算法向其他用户推介；更有用户参与「调教」算法机制，上传符合该虚拟角色人设的文字、肖像图片、动态表情等互动语料，经被告 AI 筛选分类后形成专属语料，用于「何某」与用户的对话，营造出与原告真实互动的体验。何某认为被告未经其许可擅自创设、使用其虚拟形象，侵害其姓名权、肖像权及一般人格权，诉请公开赔礼道歉并赔偿经济损失及精神损害。\n法院审理与说理 法院指出，自然人「虚拟形象」包含姓名、肖像、人格特点等具体人格要素，属于人格权客体；未经许可擅自创设、使用自然人虚拟形象的，构成对人格权的侵害。法院认定被告上海某科技公司的行为侵害了何某的姓名权、肖像权及一般人格权。\n裁判结果 判决被告向原告公开赔礼道歉，并赔偿经济损失、合理支出及精神损害抚慰金共计 203 000 元。一审宣判后，被告上诉后撤回，一审判决生效。\n数据法 / AI 法要点 ① 首次正面界定「自然人虚拟形象」的人格权客体地位，涵盖姓名、肖像、人格特点等要素；② 平台以聚类＋协同推荐算法放大虚拟角色可见度、并以用户语料「喂养」角色，构成平台的实质参与，而非单纯中立工具；③ 赔偿包含精神损害抚慰金，体现对沉浸式 AI 互动侵害人格尊严的加重评价。\n相关法条 官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\n权威来源 北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\n补充来源\n组级官方来源：最高人民法院网站转发北互涉人工智能典型案例发布消息 官方佐证：北京市人大常委会网站刊载北互五年工作综述（含本案庭审介绍） 案号与选编来源：中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03 中国法学网公布） 组级发布佐证：最高人民法院发布民法典颁布后人格权司法保护典型民事案例（2022-04-11，载明该批九案均为「已判决生效」案件） 材料来源：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\n站内关联法规 个人信息保护法 ","permalink":"https://ai.intlaws.com/cases/china/bic-ai-companion/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e何某诉上海某人工智能科技有限公司网络侵权责任纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——未经同意创造自然人的 AI 形象构成对人格权的侵害（业内通称「AI 陪伴者案」）\u003c/p\u003e\n\u003cp\u003e一审 北京互联网法院，（2020）京0491民初9526号；二审 北京市第四中级人民法院，（2021）京04民终777号（二审系\u003cstrong\u003e准许撤回上诉\u003c/strong\u003e裁定）｜ \u003cstrong\u003e本案实体裁判系一审判决，二审为准许撤回上诉裁定，一审判决生效\u003c/strong\u003e ｜ \u003cstrong\u003e发布\u003c/strong\u003e：北京互联网法院 2025-09-10 涉人工智能典型案例；本案另入选 中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03 中国法学网公布），并系最高人民法院 2022-04-11 发布的「民法典颁布后人格权司法保护典型民事案例」九案之一（该批列名为「智能算法软件侵害人格权案」）\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 人格权 / 自然人虚拟形象 / 姓名权 / 肖像权 / 算法推荐\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e原告何某系公众人物，其姓名、肖像等人格要素被用户大量用于某手机记账软件的「AI 陪伴者」功能。该软件由被告上海某科技公司开发运营，用户可在软件中自行创设「AI 陪伴者」，设置名称、头像及人物关系（如男女朋友、兄妹等），并通过聊天语料与虚拟人物互动。何某发现，大量用户将其设置为「AI 陪伴者」并上传其肖像图片作为头像；\u003cstrong\u003e被告通过聚类算法将「何某」虚拟角色按身份分类，以协同推荐算法向其他用户推介\u003c/strong\u003e；更有用户参与「调教」算法机制，上传符合该虚拟角色人设的文字、肖像图片、动态表情等互动语料，经被告 AI 筛选分类后形成专属语料，用于「何某」与用户的对话，\u003cstrong\u003e营造出与原告真实互动的体验\u003c/strong\u003e。何某认为被告未经其许可擅自创设、使用其虚拟形象，侵害其姓名权、肖像权及一般人格权，诉请公开赔礼道歉并赔偿经济损失及精神损害。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e法院指出，自然人「虚拟形象」\u003cstrong\u003e包含姓名、肖像、人格特点等具体人格要素，属于人格权客体\u003c/strong\u003e；未经许可擅自创设、使用自然人虚拟形象的，构成对人格权的侵害。法院认定被告上海某科技公司的行为侵害了何某的姓名权、肖像权及一般人格权。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e判决被告向原告公开赔礼道歉，并赔偿经济损失、合理支出及精神损害抚慰金共计 203 000 元。一审宣判后，被告上诉后撤回，一审判决生效。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e① 首次正面界定「自然人虚拟形象」的人格权客体地位，涵盖姓名、肖像、人格特点等要素；② 平台以\u003cstrong\u003e聚类＋协同推荐算法\u003c/strong\u003e放大虚拟角色可见度、并以用户语料「喂养」角色，构成平台的实质参与，而非单纯中立工具；③ 赔偿包含精神损害抚慰金，体现对沉浸式 AI 互动侵害人格尊严的加重评价。\u003c/p\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cp\u003e北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003e补充来源\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e组级官方来源：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/476531.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院网站转发北互涉人工智能典型案例发布消息\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e官方佐证：\u003ca href=\"https://www.bjrd.gov.cn/xwzx/yfly/202311/t20231106_3295819.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e北京市人大常委会网站刊载北互五年工作综述（含本案庭审介绍）\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e案号与选编来源：\u003ca href=\"http://iolaw.cssn.cn/gg/ggqt/202606/t20260603_6009787.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e中国社会科学院法学研究所网络与信息法研究室《首批涉人工智能精品司法案例》（2026-06-03 中国法学网公布）\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e组级发布佐证：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/354271.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院发布民法典颁布后人格权司法保护典型民事案例（2022-04-11，载明该批九案均为「已判决生效」案件）\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\u003c/p\u003e","title":"北京互联网法院典型案例：AI陪伴软件侵害人格权案（何某诉某人工智能科技有限公司）"},{"content":"案件名称与案号 殷某某诉某智能科技公司等人格权侵权纠纷案\n——自然人声音权益可及于 AI 生成声音\n(2023)京0491民初12142号 ｜ 审理法院：北京互联网法院 ｜ 宣判：2024-04-23（双方未上诉，已生效）｜ 通称：全国首例 AI 生成声音人格权侵权案\n关键词 民事 / 人格权 / AI 声音 / 声音权益的可识别性 / 授权范围\n基本案情 原告殷某某系配音演员，以配音、播音为职业。2023 年 5 月，殷某某发现抖音用户「小禾侃剧」等发布的 119 部配音作品中，其声音被用于 AI 配音软件「魔音工坊」的「魔小璇」声音产品，且该产品页面显示播放量高达 3 256 728 530 次，严重侵害其人格权益。殷某某遂以某智能科技公司（「魔音工坊」运营方）、某文化传媒公司（录音制品提供方）、某软件公司（文本转语音产品开发者）、某网络科技公司（微软云平台经销商）、某科技发展公司（软件产品经销商）为共同被告提起诉讼，请求判令下架侵权声音产品、赔礼道歉并赔偿经济损失 50 万元、精神损失 10 万元。\n法院审理与说理 本案争议焦点有三，法院逐层展开：\n其一，原告声音权益是否及于案涉 AI 声音。 依《民法典》第 1023 条第 2 款，对自然人声音的保护参照适用肖像权保护规则。法院指出，声音与肖像均以可识别性为保护前提，但声音具无形性、不可视特征，识别性相对较弱，一般建立在反复多次或长期聆听的基础上。「对于人工智能技术处理后的声音，只要一般社会公众或者一定范围内的公众根据音色、语调和发音风格，能够识别出特定自然人，则该自然人声音权益可及于该 AI 声音。」 本案某软件公司仅使用原告一人声音开发案涉文本转语音产品，且经庭审现场进行文本转语音操作，生成的 AI 声音与原告的音色、语调、发音风格具有高度一致性，可认定一定范围内的听众能将案涉 AI 声音与原告本人建立一一对应联系。\n其二，被告对原告声音的使用是否有合法授权。 依《民法典》第 1018 条第 1 款比照，自然人享有依法录制、使用、公开或许可他人使用其声音的权利。经查：(1) 根据《兼职配音师聘用协议》，某文化传媒公司仅享有《穿越之凰谋天下》录音制品的使用及许可第三方使用原告姓名、肖像的权利，不包括许可第三方进行人工智能处理、生成 AI 声音；(2) 《数据授权书》并非原告本人签署，原告对签署不知情亦不认可；(3) 滑县声耀公司不构成表见代理——代理关系在《协议》履行完毕后即终止，某软件公司未提交充分证据证明其存在代理原告签约的权利外观，且声音 AI 化处理可能对人格及财产利益产生重大影响，某软件公司未就授权进行合理审查，无合理理由相信其有权代理；(4) 某文化传媒公司与某软件公司签订的《数据使用协议》允许以商业或非商业用途使用、复制、修改数据用于微软产品及服务，同样不包括对声音进行人工智能处理并生成 AI 声音。\n其三，侵权成立与责任承担。 五被告均未经原告许可使用了原告声音，实施侵害声音权益的行为。责任分担上：某文化传媒公司未经授权许可某软件公司使用原告声音、某软件公司未获授权开发产品并授权他人使用，具有过错，应承担损害赔偿责任；某智能科技公司对「晓萱」产品未获授权不知情、通过合理价格购买、未作技术加工直接调用，对产品存在合法授权有合理信赖，不存在主观过错；某科技发展公司系经销商、某网络科技公司系云服务平台，销售有合法来源、主观无过错，均不承担损害赔偿责任。赔偿数额方面，法院认为案涉 AI 声音仍可体现原告声音特征，一定程度上可产生替代原告声音的效果，导致原告丧失交易机会；且文本转语音产品的 AI 声音影响用户审美体验，是产品市场价值的重要决定因素，加之「魔小璇」播放量反映原告声音受市场欢迎程度，综合酌定财产损失。精神损害赔偿因原告未举证证明严重精神损害，不予支持。另，2023-09-25 当事人自行达成的《和解协议》，除实体要件外还需以撤诉方式消灭诉讼系属，本案原告未撤诉且双方均有推翻意思表示，该协议尚不能产生拘束法院裁判的效力。\n裁判结果 被告某智能科技公司、某软件公司于判决生效后七日内向原告殷某某书面赔礼道歉（内容经法院核准，拒不履行则由法院在人民法院公告网公布，费用由二被告负担）；被告某文化传媒公司、某软件公司连带赔偿原告殷某某经济损失 25 万元；驳回其他诉讼请求。\n数据法 / AI 法要点 ① 声音 AI 化的合法性闸门在「授权范围」——录制录音制品的授权不等于授权声音 AI 化；② 层层转授权的链条中，下游使用者对授权真实性负有合理审查义务，否则不能以「善意」免责；③ 播放量等平台公开数据可作为损失酌定的市场参考；④ 人格权益侵权中，精神损害须有严重性举证。\n相关法条 官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\n权威来源 北京互联网法院 2025-09-10 涉人工智能典型案例发布文本；(2023)京0491民初12142号判决书（公开转载）。同一生效裁判另入选最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例（案例 2），系同一案件的不同发布渠道。\n补充来源\n组级官方来源：最高人民法院网站转发北互涉人工智能典型案例发布消息 判决书全文（非官方转载，知产力·中国知识产权律师网收录）：全国首例AI生成声音侵权案一审判决书 官方佐证（人民法院报·北京日报客户端）：北京互联网法院入库案例（六）：殷某某诉北京某智能科技公司等人格权纠纷案（入库编号2025-07-2-474-001） 材料来源：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本；另据 (2023)京0491民初12142号判决书公开转载文本\n站内关联法规 个人信息保护法 ","permalink":"https://ai.intlaws.com/cases/china/bic-ai-voice-yin/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e殷某某诉某智能科技公司等人格权侵权纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——自然人声音权益可及于 AI 生成声音\u003c/p\u003e\n\u003cp\u003e(2023)京0491民初12142号 ｜ \u003cstrong\u003e审理法院\u003c/strong\u003e：北京互联网法院 ｜ \u003cstrong\u003e宣判\u003c/strong\u003e：2024-04-23（双方未上诉，已生效）｜ \u003cstrong\u003e通称\u003c/strong\u003e：全国首例 AI 生成声音人格权侵权案\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 人格权 / AI 声音 / 声音权益的可识别性 / 授权范围\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e原告殷某某系配音演员，以配音、播音为职业。2023 年 5 月，殷某某发现抖音用户「小禾侃剧」等发布的 119 部配音作品中，其声音被用于 AI 配音软件「魔音工坊」的「魔小璇」声音产品，且该产品页面显示播放量高达 3 256 728 530 次，严重侵害其人格权益。殷某某遂以某智能科技公司（「魔音工坊」运营方）、某文化传媒公司（录音制品提供方）、某软件公司（文本转语音产品开发者）、某网络科技公司（微软云平台经销商）、某科技发展公司（软件产品经销商）为共同被告提起诉讼，请求判令下架侵权声音产品、赔礼道歉并赔偿经济损失 50 万元、精神损失 10 万元。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e本案争议焦点有三，法院逐层展开：\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e其一，原告声音权益是否及于案涉 AI 声音。\u003c/strong\u003e 依《民法典》第 1023 条第 2 款，对自然人声音的保护参照适用肖像权保护规则。法院指出，声音与肖像均以可识别性为保护前提，但声音具无形性、不可视特征，识别性相对较弱，一般建立在反复多次或长期聆听的基础上。\u003cstrong\u003e「对于人工智能技术处理后的声音，只要一般社会公众或者一定范围内的公众根据音色、语调和发音风格，能够识别出特定自然人，则该自然人声音权益可及于该 AI 声音。」\u003c/strong\u003e 本案某软件公司仅使用原告一人声音开发案涉文本转语音产品，且经庭审现场进行文本转语音操作，生成的 AI 声音与原告的音色、语调、发音风格具有高度一致性，可认定一定范围内的听众能将案涉 AI 声音与原告本人建立一一对应联系。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e其二，被告对原告声音的使用是否有合法授权。\u003c/strong\u003e 依《民法典》第 1018 条第 1 款比照，自然人享有依法录制、使用、公开或许可他人使用其声音的权利。经查：(1) 根据《兼职配音师聘用协议》，某文化传媒公司仅享有《穿越之凰谋天下》录音制品的使用及许可第三方使用原告姓名、肖像的权利，\u003cstrong\u003e不包括许可第三方进行人工智能处理、生成 AI 声音\u003c/strong\u003e；(2) 《数据授权书》并非原告本人签署，原告对签署不知情亦不认可；(3) 滑县声耀公司\u003cstrong\u003e不构成表见代理\u003c/strong\u003e——代理关系在《协议》履行完毕后即终止，某软件公司未提交充分证据证明其存在代理原告签约的权利外观，且声音 AI 化处理可能对人格及财产利益产生重大影响，某软件公司未就授权进行合理审查，无合理理由相信其有权代理；(4) 某文化传媒公司与某软件公司签订的《数据使用协议》允许以商业或非商业用途使用、复制、修改数据用于微软产品及服务，\u003cstrong\u003e同样不包括对声音进行人工智能处理并生成 AI 声音\u003c/strong\u003e。\u003c/p\u003e","title":"北京互联网法院典型案例：AI生成声音人格权侵权第一案（殷某某诉某智能科技公司等）"},{"content":"案件名称与案号 李某某诉刘某某侵害作品署名权和信息网络传播权纠纷案\n——AI 文生图的法律属性及权利归属的认定\n(2023)京0491民初11279号 ｜ 审理法院：北京互联网法院 ｜ 程序：一审判决已生效（双方均未上诉）\n关键词 民事 / 著作权 / AI 文生图 / 作品独创性 / 权利归属\n基本案情 原告李某使用开源软件 Stable Diffusion，通过发出提示词指令的方式生成涉案图片，并发布在小红书平台，发布时标注「AI 插画」。被告刘某在百家号上发布文章，文章的配图未经原告许可使用了涉案图片，并截去小红书平台标注的「小红书」及用户编号水印（李某主张该水印为其署名）。李某认为刘某的行为侵害其署名权及信息网络传播权，请求判令刘某在百家号公开赔礼道歉并赔偿经济损失 5000 元。\n法院审理与说理 法院认定涉案图片符合著作权法对作品的定义，认定李某为涉案图片的作者及著作权人；同时认定刘某的行为侵害了李某的署名权及信息网络传播权。法院在本案中明确了 AI 文生图的法律属性及权利归属，指出：AI 生成图片若体现人类作者的独创性选择、编排与干预，应认定为作品；其著作权归属需结合创作过程中人类的智力投入程度综合判定。\n裁判结果 判决被告赔礼道歉并赔偿原告 500 元，双方均未提起上诉，一审判决已生效。\n数据法 / AI 法要点 AI 生成内容的可版权性以「人类独创性智力投入」为判断枢纽；提示词的取舍、参数的调整、生成结果的筛选，均可构成独创性来源。本案与苏州两审「AI 文生图不构成作品」案并置，可清晰看出分野：关键不在「是否用了 AI」，而在「人的智力投入是否足以体现个性化表达」。\n相关法条 官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\n权威来源 北京互联网法院 2025-09-10 涉人工智能典型案例发布文本；(2023)京0491民初11279号判决书（公开转载）。\n补充来源\n组级官方来源：最高人民法院网站转发北互涉人工智能典型案例发布消息 判决书全文（非官方转载，维基文库收录）：北京互联网法院（2023）京0491民初11279号民事判决书 政府网站转载要旨：汕头市人民政府网站「以案释法」转载判决要旨 材料来源：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本；另据 (2023)京0491民初11279号判决书公开转载文本\n站内关联法规 生成式人工智能服务管理暂行办法 人工智能生成合成内容标识办法 ","permalink":"https://ai.intlaws.com/cases/china/bic-ai-t2i-liu/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e李某某诉刘某某侵害作品署名权和信息网络传播权纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——AI 文生图的法律属性及权利归属的认定\u003c/p\u003e\n\u003cp\u003e(2023)京0491民初11279号 ｜ \u003cstrong\u003e审理法院\u003c/strong\u003e：北京互联网法院 ｜ \u003cstrong\u003e程序\u003c/strong\u003e：一审判决已生效（双方均未上诉）\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 著作权 / AI 文生图 / 作品独创性 / 权利归属\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e原告李某使用开源软件 Stable Diffusion，通过发出提示词指令的方式生成涉案图片，并发布在小红书平台，发布时标注「AI 插画」。被告刘某在百家号上发布文章，文章的配图未经原告许可使用了涉案图片，并截去小红书平台标注的「小红书」及用户编号水印（李某主张该水印为其署名）。李某认为刘某的行为侵害其署名权及信息网络传播权，请求判令刘某在百家号公开赔礼道歉并赔偿经济损失 5000 元。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e法院认定涉案图片符合著作权法对作品的定义，认定李某为涉案图片的作者及著作权人；同时认定刘某的行为侵害了李某的署名权及信息网络传播权。法院在本案中明确了 AI 文生图的法律属性及权利归属，指出：\u003cstrong\u003eAI 生成图片若体现人类作者的独创性选择、编排与干预，应认定为作品；其著作权归属需结合创作过程中人类的智力投入程度综合判定。\u003c/strong\u003e\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e判决被告赔礼道歉并赔偿原告 500 元，双方均未提起上诉，一审判决已生效。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003eAI 生成内容的可版权性以「人类独创性智力投入」为判断枢纽；提示词的取舍、参数的调整、生成结果的筛选，均可构成独创性来源。本案与苏州两审「AI 文生图不构成作品」案并置，可清晰看出分野：关键不在「是否用了 AI」，而在「人的智力投入是否足以体现个性化表达」。\u003c/p\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cp\u003e北京互联网法院 2025-09-10 涉人工智能典型案例发布文本；(2023)京0491民初11279号判决书（公开转载）。\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003e补充来源\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e组级官方来源：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/476531.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院网站转发北互涉人工智能典型案例发布消息\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e判决书全文（非官方转载，维基文库收录）：\u003ca href=\"https://zh.wikisource.org/wiki/%E5%8C%97%E4%BA%AC%E4%BA%92%E8%81%94%E7%BD%91%E6%B3%95%E9%99%A2%EF%BC%882023%EF%BC%89%E4%BA%AC0491%E6%B0%91%E5%88%9D11279%E5%8F%B7%E6%B0%91%E4%BA%8B%E5%88%A4%E5%86%B3%E4%B9%A6\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e北京互联网法院（2023）京0491民初11279号民事判决书\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e政府网站转载要旨：\u003ca href=\"https://www.shantou.gov.cn/stszcwyh/zcal/content/post_2290248.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e汕头市人民政府网站「以案释法」转载判决要旨\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本；另据 (2023)京0491民初11279号判决书公开转载文本\u003c/p\u003e\n\u003ch2 id=\"站内关联法规\"\u003e站内关联法规\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"/compliance/china/generative-ai-interim-measures/\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e生成式人工智能服务管理暂行办法\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"/compliance/china/ai-generated-content-labelling-measures/\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e人工智能生成合成内容标识办法\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e","title":"北京互联网法院典型案例：AI文生图第一案（李某某诉刘某某）"},{"content":"案件名称与案号 唐某某诉某科技有限公司网络服务合同纠纷案\n——网络平台利用算法工具检测 AI 生成内容但未尽到合理适度说明义务的应承担违约责任\n北京互联网法院 ｜ 发布：2025-09-10 涉人工智能典型案例 ｜ 案由：网络服务合同纠纷\n关键词 民事 / 网络服务合同 / AIGC 内容标识 / 算法说明义务\n基本案情 原告系某网络平台用户，其在平台上发布了题为「打工并不能让你真的赚到多少钱，但可以开启你的新视角……」的内容，主要涉及鼓励用户利用假期学车。涉案平台经检测认定该内容「包含 AI 生成内容但未标识」，遂作出隐藏该内容并对原告账号禁言一天的违规处理，原告申诉未获支持。原告主张其未使用 AI 创作，被告的行为构成违约，请求法院判令被告撤销隐藏内容及禁言处理，并删除后台违规记录。\n法院审理与说理 法院认为，平台有权依据合同约定对涉案内容是否属于 AI 生成合成内容进行审查和处理，但平台的审查及处理结果应有合理依据。经审理发现，被告未对算法决策依据和结果进行适度的解释和说明，应对其没有事实依据的情况下对涉案账户的处理行为承担违约责任。被告系统后台仅存在「折叠回答」这一条处理记录，现因该处理已在本案中被判定为不合规，被告应对该处理记录予以删除。\n裁判结果 被告承担违约责任；删除后台相应处理记录。\n数据法 / AI 法要点 这是 AI 内容标识制度落地后「算法结论须可说明」的第一批司法样本：平台有权自动化检测与处置 AI 生成内容，但算法判断本身必须给出合理依据与适度说明，否则构成违约。与《人工智能生成合成内容标识办法》的实施相衔接，提示平台建立可追溯、可复核、可申诉的处置记录机制。\n相关法条 官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\n权威来源 北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\n补充来源\n组级官方来源：最高人民法院网站转发北互涉人工智能典型案例发布消息 材料来源：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\n站内关联法规 人工智能生成合成内容标识办法 ","permalink":"https://ai.intlaws.com/cases/china/bic-ai-detection-breach/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e唐某某诉某科技有限公司网络服务合同纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——网络平台利用算法工具检测 AI 生成内容但未尽到合理适度说明义务的应承担违约责任\u003c/p\u003e\n\u003cp\u003e北京互联网法院 ｜ \u003cstrong\u003e发布\u003c/strong\u003e：2025-09-10 涉人工智能典型案例 ｜ \u003cstrong\u003e案由\u003c/strong\u003e：网络服务合同纠纷\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 网络服务合同 / AIGC 内容标识 / 算法说明义务\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e原告系某网络平台用户，其在平台上发布了题为「打工并不能让你真的赚到多少钱，但可以开启你的新视角……」的内容，主要涉及鼓励用户利用假期学车。涉案平台经检测认定该内容「包含 AI 生成内容但未标识」，遂作出隐藏该内容并对原告账号禁言一天的违规处理，原告申诉未获支持。原告主张其未使用 AI 创作，被告的行为构成违约，请求法院判令被告撤销隐藏内容及禁言处理，并删除后台违规记录。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e法院认为，平台\u003cstrong\u003e有权\u003c/strong\u003e依据合同约定对涉案内容是否属于 AI 生成合成内容进行审查和处理，\u003cstrong\u003e但平台的审查及处理结果应有合理依据\u003c/strong\u003e。经审理发现，被告未对算法决策依据和结果进行适度的解释和说明，\u003cstrong\u003e应对其没有事实依据的情况下对涉案账户的处理行为承担违约责任\u003c/strong\u003e。被告系统后台仅存在「折叠回答」这一条处理记录，现因该处理已在本案中被判定为不合规，被告应对该处理记录予以删除。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e被告承担违约责任；删除后台相应处理记录。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e这是 AI 内容标识制度落地后「\u003cstrong\u003e算法结论须可说明\u003c/strong\u003e」的第一批司法样本：平台有权自动化检测与处置 AI 生成内容，但算法判断本身必须给出合理依据与适度说明，否则构成违约。与《人工智能生成合成内容标识办法》的实施相衔接，提示平台建立可追溯、可复核、可申诉的处置记录机制。\u003c/p\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cp\u003e北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003e补充来源\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e组级官方来源：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/476531.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院网站转发北互涉人工智能典型案例发布消息\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\u003c/p\u003e\n\u003ch2 id=\"站内关联法规\"\u003e站内关联法规\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"/compliance/china/ai-generated-content-labelling-measures/\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e人工智能生成合成内容标识办法\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e","title":"北京互联网法院典型案例：平台算法检测AI生成内容违约案（唐某某诉某科技公司）"},{"content":"案件名称与案号 某甲科技有限公司、某乙科技有限公司诉孙某某、某网络科技有限公司著作权权属、侵权纠纷案\n——具有独创性的虚拟数字人形象构成美术作品\n北京互联网法院 ｜ 发布：2025-09-10 涉人工智能典型案例\n关键词 民事 / 著作权 / 虚拟数字人 / 美术作品 / 平台注意义务\n基本案情 原告聚某公司、元某公司等四家单位联合制作虚拟数字人甲、乙（聚某公司为著作权人，元某公司负责运营），其中虚拟数字人甲在各平台拥有超 440 万粉丝并获 2022 年文化产业和旅游业年度八大热点事件，虚拟数字人乙首次发表于某微博账号。被告孙某某（原联合创作单位员工，离职后运营某公司 CG 模型网）擅自售卖甲、乙模型，原告主张其行为侵害复制权及信息网络传播权；被告某网络科技有限公司作为平台方被指未尽监管责任，应与孙某某承担连带责任。\n法院审理与说理 其一，客体属性与权属。 法院指出，虚拟数字人甲的全身形象与乙的头部形象并非直接来源于真人，而是由制作团队通过艺术加工完成，体现了对线条、色彩、形象设计的独特美学选择，符合《著作权法》对美术作品「独创性」的要求。权属上，法院认定聚某公司作为实际制作方，通过委托创作合同约定取得著作权；元某公司经授权获得除发表权、署名权外的独占许可权，二者均有权提起诉讼。\n其二，侵权认定。 法院比对发现，孙某某上传的模型在五官、发型、服装设计及整体风格上，与甲、乙形象的独创性元素高度相似，构成实质性相似，侵害了二原告的复制权与信息网络传播权。\n其三，平台责任。 对于某网络科技有限公司，法院认为其作为网络服务提供者，已履行上传审核、定期排查、用户协议提醒等合理义务，且在收到投诉后及时处理；涉案虚拟数字人知名度较低、特征不显著，平台难以主动识别侵权，故不构成共同侵权。法院综合考量权利类型（美术作品）、市场价值、侵权人主观过错（孙某某明知侵权仍售卖）、侵权规模及损害后果，最终判令孙某某赔偿二原告经济损失 1.5 万元（甲 1 万元、乙 5000 元）。\n裁判结果 孙某某赔偿二原告经济损失共 1.5 万元；平台方不构成共同侵权。\n数据法 / AI 法要点 ① 虚拟数字人形象可独立构成美术作品，著作权的落脚点是美术造型的独创性表达，而非「数字人」「AI」技术标签；② 委托创作合同是权属认定的关键证据；③ 平台注意义务的高低与权利客体的知名度、识别显著性直接相关——不知名形象不苛求平台主动识别。\n相关法条 官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\n权威来源 北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\n补充来源\n组级官方来源：最高人民法院网站转发北互涉人工智能典型案例发布消息 材料来源：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\n","permalink":"https://ai.intlaws.com/cases/china/bic-virtual-digital-human/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e某甲科技有限公司、某乙科技有限公司诉孙某某、某网络科技有限公司著作权权属、侵权纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——具有独创性的虚拟数字人形象构成美术作品\u003c/p\u003e\n\u003cp\u003e北京互联网法院 ｜ \u003cstrong\u003e发布\u003c/strong\u003e：2025-09-10 涉人工智能典型案例\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 著作权 / 虚拟数字人 / 美术作品 / 平台注意义务\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e原告聚某公司、元某公司等四家单位联合制作虚拟数字人甲、乙（聚某公司为著作权人，元某公司负责运营），其中虚拟数字人甲在各平台拥有超 440 万粉丝并获 2022 年文化产业和旅游业年度八大热点事件，虚拟数字人乙首次发表于某微博账号。被告孙某某（原联合创作单位员工，离职后运营某公司 CG 模型网）擅自售卖甲、乙模型，原告主张其行为侵害复制权及信息网络传播权；被告某网络科技有限公司作为平台方被指未尽监管责任，应与孙某某承担连带责任。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e其一，客体属性与权属。\u003c/strong\u003e 法院指出，虚拟数字人甲的全身形象与乙的头部形象\u003cstrong\u003e并非直接来源于真人，而是由制作团队通过艺术加工完成，体现了对线条、色彩、形象设计的独特美学选择\u003c/strong\u003e，符合《著作权法》对美术作品「独创性」的要求。权属上，法院认定聚某公司作为实际制作方，通过委托创作合同约定取得著作权；元某公司经授权获得除发表权、署名权外的独占许可权，二者均有权提起诉讼。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e其二，侵权认定。\u003c/strong\u003e 法院比对发现，孙某某上传的模型在五官、发型、服装设计及整体风格上，与甲、乙形象的独创性元素\u003cstrong\u003e高度相似，构成实质性相似\u003c/strong\u003e，侵害了二原告的复制权与信息网络传播权。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e其三，平台责任。\u003c/strong\u003e 对于某网络科技有限公司，法院认为其作为网络服务提供者，已履行上传审核、定期排查、用户协议提醒等合理义务，且在收到投诉后及时处理；涉案虚拟数字人\u003cstrong\u003e知名度较低、特征不显著，平台难以主动识别侵权\u003c/strong\u003e，故不构成共同侵权。法院综合考量权利类型（美术作品）、市场价值、侵权人主观过错（孙某某明知侵权仍售卖）、侵权规模及损害后果，最终判令孙某某赔偿二原告经济损失 1.5 万元（甲 1 万元、乙 5000 元）。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e孙某某赔偿二原告经济损失共 1.5 万元；平台方不构成共同侵权。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e① 虚拟数字人形象可独立构成美术作品，著作权的落脚点是\u003cstrong\u003e美术造型的独创性表达\u003c/strong\u003e，而非「数字人」「AI」技术标签；② 委托创作合同是权属认定的关键证据；③ 平台注意义务的高低与\u003cstrong\u003e权利客体的知名度、识别显著性\u003c/strong\u003e直接相关——不知名形象不苛求平台主动识别。\u003c/p\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e官方发布文本未单列裁判依据法条，上文说理部分所引法律依据以原文引述为准。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cp\u003e北京互联网法院 2025-09-10 涉人工智能典型案例发布文本。\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003e补充来源\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e组级官方来源：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/476531.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院网站转发北互涉人工智能典型案例发布消息\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：北京互联网法院 2025 年 9 月 10 日涉人工智能典型案例发布文本\u003c/p\u003e","title":"北京互联网法院典型案例：虚拟数字人形象著作权案（某甲科技有限公司、某乙科技有限公司诉孙某某等）"},{"content":"案件名称与案号 指导性案例 262 号：某科技有限公司诉某文化传媒有限公司不正当竞争纠纷案\n一审（2019）京 0108 民初 35902 号 · 北京市海淀区人民法院 · 2020 年 12 月 31 日\n二审（2021）京 73 民终 1011 号 · 北京知识产权法院 · 2023 年 3 月 16 日\n关键词 民事 / 不正当竞争 / 数据集合 / 数据搬运 / 经营性利益\n基本案情 某科技有限公司（下称某科技公司）运营甲 APP，某文化传媒有限公司（下称某文化公司）运营乙 APP。2018 年 11 月至 2019 年 5 月期间，乙 APP 上有 50392 个短视频与甲 APP 的短视频一致，且短视频中含有甲 APP 专有的代码。案涉短视频中包含 19079 个注册用户昵称、用户头像，其中 15924 个与甲 APP 相同；另有 127 处评论内容、顺序、标点符号与甲 APP 相同。经查，约 40% 的短视频具有独创性、构成作品，其余短视频有一定价值但不具有独创性，属于录像制品。\n某科技公司以不正当竞争纠纷起诉，请求判令消除影响、赔偿经济损失 4000 万元。某文化公司抗辩：案涉短视频属于著作权法保护范畴，甲 APP 中用户自行上传的短视频某科技公司不享有权益；乙 APP 系为用户提供短视频上传的平台，商业模式正当。\n法院审理与说理 争议焦点：其一，某科技公司对汇聚短视频、用户评论、用户信息形成的数据集合享有何种权益；其二，某文化公司获取、使用案涉数据的行为是否构成不正当竞争行为。\n第一，关于数据集合的经营性利益。数据集合中具有独创性的短视频构成作品，其余构成录像制品，二者均受著作权法保护；但某科技公司并非短视频制作者，其对短视频的汇聚\u0026quot;仅按照网络平台常见的\u0026rsquo;视频、直播、音乐\u0026rsquo;等类别进行分类，选择和编排并未体现独创性，亦不构成汇编作品\u0026quot;，故不能依据著作权法主张权益。然而，\u0026ldquo;案涉数据集合系某科技公司采集、汇聚而成\u0026rdquo;，除短视频外还包括用户依用户协议发布的注册信息、用户评论等，\u0026ldquo;系用户遵循平台规则、借助平台提供的技术支持，经由与平台之间的交互关系形成，规模体量大、商业价值高\u0026rdquo;，某科技公司\u0026quot;对数据集合的形成和积累实质性投入了人力、物力、财力\u0026quot;，使数据集合\u0026quot;额外产生独立于单一短视频的经济价值\u0026quot;。据此认定某科技公司对短视频数据集合享有受法律保护的经营性利益，同时明确\u0026quot;这并不影响短视频制作者主张著作权法上的权利\u0026quot;。\n第二，关于行为定性。某文化公司未经许可抓取搬运大量用户信息、短视频和用户评论在乙 APP 使用，\u0026ldquo;导致乙 APP 与甲 APP 内容高度同质化，网络用户不使用甲 APP，通过乙 APP 也可观看相同内容，实质性替代了某科技公司经营的甲 APP 产品和服务\u0026rdquo;。案涉行为不属于反不正当竞争法第二章规定的不正当竞争行为，某科技公司的经营性利益亦无法依著作权法寻求保护，故人民法院依法适用反不正当竞争法第二条（一般条款）认定构成不正当竞争行为。\n第三，法律适用的向前指引。法院专门说明：2025 年 6 月 27 日反不正当竞争法第二次修订，在第十三条第三款对侵害数据权益的不正当竞争行为作出专门规定；自 2025 年 10 月 15 日修订后的反不正当竞争法施行后，对相关行为应当适用第十三条第三款及相关规定认定。\n裁判结果 一审判决某文化公司在《中国知识产权报》非中缝位置刊登声明消除影响、赔偿经济损失 500 万元；二审驳回上诉，维持原判。\n数据法 / AI 法要点 （1）数据集合的\u0026quot;经营性利益\u0026quot;可独立于著作权获得反不正当竞争法保护，请求权基础是反法第二条兜底条款；（2）\u0026ldquo;实质性替代\u0026quot;是认定数据搬运构成不正当竞争的核心标准，\u0026ldquo;内容高度同质化 + 用户无需使用原平台即可获得相同内容\u0026quot;是其实质判断要素；（3）2025 年 10 月 15 日后同类案件应转向反法第十三条第三款——本案例因此具有新旧法适用的分界线意义。\n相关法条 《中华人民共和国反不正当竞争法》第 2 条；《中华人民共和国著作权法》第 3 条、第 15 条、第 44 条（本案适用的是 2010 年修正的著作权法第 3 条、第 14 条、第 42 条）；《最高人民法院关于适用〈中华人民共和国反不正当竞争法〉若干问题的解释》（法释〔2022〕9 号）第 1 条。\n权威来源 官方专页 材料来源：最高人民法院官网「审判业务—指导性案例」栏目发布的第 47 批指导性案例（法〔2025〕150 号，2025 年 8 月 28 日发布）文本\n站内关联法规 数据安全法 ","permalink":"https://ai.intlaws.com/cases/china/gca-262/","summary":"最高人民法院第47批指导性案例（法〔2025〕150号，2025年8月28日发布）之一：某科技有限公司诉某文化传媒有限公司不正当竞争纠纷案。裁判要点以最高人民法院官方发布文本为准。","title":"指导性案例262号：某科技有限公司诉某文化传媒有限公司不正当竞争纠纷案"},{"content":"案件名称与案号 指导性案例 263 号：某网络信息技术有限公司诉某信息科技有限公司不正当竞争纠纷案\n一审（2017）沪 0110 民初 25167 号 · 上海市杨浦区人民法院 · 2019 年 5 月 17 日\n二审（2019）沪 73 民终 263 号 · 上海知识产权法院 · 2020 年 10 月 13 日\n关键词 民事 / 不正当竞争 / 数据 / 关联账号服务 / 用户授权\n基本案情 某网络信息技术有限公司（下称某网络公司）运营甲网站，为求职者提供工作和职业发展机会。个人会员填写简历时可设置控制权限，既可允许招聘企业用户搜索简历，也可禁止包括招聘企业用户在内的任何人搜索；招聘企业用户发布职位后，求职者可主动投递简历；甲网站另向招聘企业用户提供有偿简历搜索服务，购买后可进入数据库搜索求职者允许搜索的简历，获取的简历可在会员账号内查看、下载或发送到指定邮箱；用户登录甲网站需输入图片字符验证码。\n某信息科技有限公司（下称某信息公司）运营乙网站，主要提供简历管理、招聘管理、大数据服务，设有\u0026quot;关联外网账号\u0026quot;功能，便于招聘企业用户集中处理在甲网站和其他网站获取的简历。使用该功能需专门授权，用户设置并输入其在甲网站等其他网站的账号、密码后即可自动登录关联网站，并可自行选择是否同步获取简历到乙网站招聘管理流程或简历库。\n某网络公司发现，招聘企业用户在甲网站经接收投递和主动搜索下载两种方式获取的个人简历，在使用\u0026quot;关联外网账号\u0026quot;功能后可在乙网站中搜索到。某信息公司则称，招聘企业用户使用该功能后仅能将简历同步到自己账号内，其他用户不能在乙网站汇聚简历库中搜索到。双方分别以公证方式固定证据。2017 年 11 月 23 日，某网络公司以不正当竞争纠纷起诉，请求判令停止行为、消除影响、赔偿 500 万元。\n法院审理与说理 争议焦点：某信息公司提供关联账号服务并获取、保存、使用案涉简历数据的行为是否构成不正当竞争行为。\n第一，关于关联账号服务的性质。关联账号服务\u0026quot;系通过绑定用户在不同网络平台上的多个账号，达到共享数据、权限或者功能的目的，以提供更为便捷的使用体验\u0026quot;，在网络空间中是较为常见的服务模式（如招聘市场、电子邮箱领域）。法院明确一般规则：\u0026ldquo;在不侵害数据安全、个人信息和社会公共利益的前提下，网络用户使用关联账号功能，将其持有的数据在不同网络平台间转移，系合法正当行为。\u0026rdquo;\n第二，关于行为正当性。某网络公司对甲网站采集生成的数据\u0026quot;有实质性投入和贡献，享有受法律保护的权益，但不得阻碍招聘企业用户对所收集的数据进行转移等合理处理\u0026quot;；招聘企业用户对通过有偿支付对价、接受求职者投递等方式收集的简历数据可以进行转移，包括使用关联账号转移；且关联账号未超出求职者对个人信息处理范围的预期——同步后简历\u0026quot;只能在招聘企业用户的账号中搜索浏览，他人无法在乙网站获取\u0026quot;，不存在侵害求职者合法权益的情形。\n第三，关于是否构成不正当竞争，法院分三点论证：（1）关联账号功能由招聘企业用户\u0026quot;自行选择是否关联、是否自动同步或者保存简历，并自行输入其在甲网站等其他网站的账号、密码\u0026quot;，服务实现\u0026quot;均为用户自己的意愿\u0026quot;；（2）经技术调查官查证，某信息公司设置程序读取验证码，\u0026ldquo;系实现关联账号功能所使用的一种技术手段\u0026rdquo;，不构成反不正当竞争法规定的\u0026quot;妨碍、破坏其他经营者合法提供的网络产品或者服务正常运行的行为\u0026quot;；（3）简历下载至乙网站服务器\u0026quot;是关联账号功能实现的必然结果\u0026quot;，而同步的简历只能在招聘企业用户账号中搜索浏览，他人无法获取。综上，案涉行为没有扰乱市场竞争秩序，亦未损害其他经营者、消费者的合法权益。\n裁判结果 一审判决驳回某网络公司的诉讼请求；二审驳回上诉，维持原判。\n数据法 / AI 法要点 （1）确立\u0026quot;用户授权 + 数据转移\u0026quot;的合法性边界：在用户同意且不侵害数据安全、个人信息与公共利益的前提下，平台不得以数据权益为由阻碍用户将其持有的数据跨平台转移；（2）\u0026ldquo;绕开验证码\u0026quot;不等于破坏计算机信息系统或妨碍网络服务运行——技术手段的定性应回到其功能目的；（3）平台数据权益与用户数据权益发生冲突时，本案给出了明确的优先序：用户对自身数据的合理处理优先。\n相关法条 《中华人民共和国反不正当竞争法》第 2 条。\n权威来源 官方专页 材料来源：最高人民法院官网「审判业务—指导性案例」栏目发布的第 47 批指导性案例（法〔2025〕150 号，2025 年 8 月 28 日发布）文本\n站内关联法规 数据安全法 ","permalink":"https://ai.intlaws.com/cases/china/gca-263/","summary":"最高人民法院第47批指导性案例（法〔2025〕150号，2025年8月28日发布）之一：某网络信息技术有限公司诉某信息科技有限公司不正当竞争纠纷案。裁判要点以最高人民法院官方发布文本为准。","title":"指导性案例263号：某网络信息技术有限公司诉某信息科技有限公司不正当竞争纠纷案"},{"content":"案件名称与案号 指导性案例 264 号：某钢铁有限公司诉某电子商务股份有限公司侵权责任纠纷案\n一审（2023）沪 0113 民初 23152 号 · 上海市宝山区人民法院 · 2023 年 8 月 24 日\n二审（2023）沪 02 民终 11028 号 · 上海市第二中级人民法院 · 2024 年 6 月 19 日\n关键词 民事 / 侵权责任 / 企业数据 / 数据产品 / 数据处理者\n基本案情 某钢铁有限公司（下称某钢铁公司）生产、经销特种钢材，每天主要通过两种方式发布出厂价格：一是在微信群发布（有的群无入群资格审核和身份限制、以客户为主、人数达上百人，有的群由公司与一级代理商组成）；二是直接电话告知特定客户。\n某电子商务股份有限公司（下称某电子公司）系某网站及 APP 运营商，每日发布各类钢材价格指数，经营范围包括互联网数据服务、大数据服务、数据处理服务，系\u0026quot;商贸流通业典型统计调查企业\u0026quot;。其为采集钢铁价格信息组建信息采集团队，通过公众号和微信群采集、电话询问、销售合同披露三种方式，向钢铁生产企业、贸易商等采集出厂价格、代理商价格、合同交易价格等，并在询问价格过程中同时提供市场行情、市场分析服务；对采集的各类价格经算法技术加工后编制成价格指数发布。其价格指数编制准则经\u0026quot;上海标准\u0026quot;评价委员会、上海市标准化协会评定，获\u0026quot;上海标准\u0026quot;标识证书。其发布的数据不是原始出厂价格，而是价格指数，即\u0026quot;反映一定地区、一定时期某类商品的综合平均价格指标\u0026quot;；信息服务采用会员制。\n2019 年起，某电子公司即在其网站及 APP 公布某钢铁公司钢材产品的品名、价格、涨跌等信息；2020 年 11 月 18 日双方签订合作协议，约定某电子公司提供数据服务、品牌推广，某钢铁公司支付服务费。2021 年 5 月 24 日起，某钢铁公司多次提出价格指数中涉其产品的价格与同区域、同档次其他公司产品价格差异太大，要求下架；2021 年 11 月 30 日双方解除合作协议，但某电子公司仍继续公布。某钢铁公司遂诉请判令删除其网站及 APP 中所有关于某钢铁公司的信息。\n法院审理与说理 争议焦点：某电子公司采集发布案涉数据的行为，是否侵害某钢铁公司的合法权益。\n第一，权益界分。应当\u0026quot;根据数据来源和生成特征，妥当界分数据参与各方享有的权益\u0026quot;：（1）产品出厂价格是某钢铁公司在经营主营业务过程中产生的数据，其享有持有、使用等权益，\u0026ldquo;但钢材交易市场是竞争较为充分的市场，产品出厂价格已公开，某钢铁公司不能禁止他人合法合理采集使用\u0026rdquo;；（2）代理商价格在某钢铁公司产品出厂后的下游交易链条中产生，\u0026ldquo;并无证据证明某钢铁公司直接参与了该数据的产生、发布，故难以认定某钢铁公司对代理商价格享有限制他人采集使用的权益\u0026rdquo;；（3）根据国家发展改革委关于价格指数行为管理的相关规定，依法成立的企业等组织可以编制发布价格指数，相关价格指数\u0026quot;系某电子公司通过采集原始价格数据后，经技术分析而成，属于数据产品\u0026quot;，某电子公司对其\u0026quot;享有经营性利益\u0026quot;。\n第二，采集加工行为的正当性。法院提出数据流动的一般原则：\u0026ldquo;数据信息具有非排他性。通常而言，对于不属于国家秘密、个人信息和商业秘密的数据信息，应允许自由流动，非因法定事由不应过度管控，以防止形成\u0026rsquo;数据壁垒\u0026rsquo;\u0026lsquo;信息封闭\u0026rsquo;。\u0026ldquo;据此论证三点：其一，商业秘密主张不成立——构成商业秘密应满足不为公众所知悉、具有商业价值、采取保密措施三要件，而某钢铁公司主动在无入群资格审核的数百人微信群中发布出厂价格、也未禁止群成员对外再传播，\u0026ldquo;未采取有效保密措施\u0026rdquo;，不符合\u0026quot;不为公众所知悉\u0026quot;要件；其二，案涉合作协议目的是购买服务，而非授权采集、加工、使用出厂价格，\u0026ldquo;故案涉合同关系并非某电子公司采集出厂价格具备合法性的必要条件\u0026rdquo;（即公开数据的采集并不因合同解除而失去合法性）；其三，某电子公司独立采集，未采取误导、欺诈、胁迫、窃取等方式，信息来源合法。\n第三，损害认定。正当获取和合理使用\u0026quot;实际并未影响或者剥夺某钢铁公司对出厂价格数据的持有、使用等权益，更未对某钢铁公司造成经济损失\u0026rdquo;。法院同时指明救济路径：如有证据证明数据质量存在问题，某钢铁公司可以主张包括损害赔偿在内的相关责任，但本案并无该等证据。\n裁判结果 一审判决驳回某钢铁公司的诉讼请求；二审驳回上诉，维持原判。\n数据法 / AI 法要点 （1）确立\u0026quot;公开企业数据自由流动\u0026quot;原则，并给出例外的三项检验（国家秘密、个人信息、商业秘密）；（2）\u0026ldquo;主动在无审核的微信群发布价格\u0026quot;即丧失商业秘密\u0026quot;保密措施\u0026quot;要件——对企业的数据保密管理具有直接的警示意义；（3）数据产品（价格指数等）形成独立经营权，数据来源方不能因其权益而禁止他人合法采集使用；（4）企业数据权益受损的另一个救济口是\u0026quot;数据质量\u0026rdquo;，而非数据持有本身。\n相关法条 《中华人民共和国民法典》第 1165 条；《中华人民共和国数据安全法》第 7 条。\n权威来源 官方专页 材料来源：最高人民法院官网「审判业务—指导性案例」栏目发布的第 47 批指导性案例（法〔2025〕150 号，2025 年 8 月 28 日发布）文本\n站内关联法规 数据安全法 ","permalink":"https://ai.intlaws.com/cases/china/gca-264/","summary":"最高人民法院第47批指导性案例（法〔2025〕150号，2025年8月28日发布）之一：某钢铁有限公司诉某电子商务股份有限公司侵权责任纠纷案。裁判要点以最高人民法院官方发布文本为准。","title":"指导性案例264号：某钢铁有限公司诉某电子商务股份有限公司侵权责任纠纷案"},{"content":"案件名称与案号 指导性案例 265 号：罗某诉某科技有限公司隐私权、个人信息保护纠纷案\n一审（2021）京 0491 民初 5094 号 · 北京互联网法院 · 2022 年 8 月 1 日\n二审（2022）京 04 民终 494 号 · 北京市第四中级人民法院 · 2022 年 11 月 28 日\n关键词 民事 / 隐私权、个人信息保护 / 收集用户画像信息 / 履行合同所必需 / 自动化决策\n基本案情 某科技有限公司（下称某科技公司）运营某英语学习网站及两款 APP。2021 年 1 月 15 日，某科技公司在未征得罗某同意的情况下，通过线下合作体验店收集罗某两个手机号码，为其创建案涉英语学习网站的账号密码，并向其手机发送多条信息。1 月 20 日，罗某为解账号情况，在网站和 APP 账号登录页面输入手机号、密码并点击登录，随即出现若干问答界面，要求填写\u0026quot;职业\u0026quot;\u0026ldquo;学习目的\u0026quot;\u0026ldquo;学龄阶段\u0026quot;\u0026ldquo;英语水平\u0026quot;等内容，不填写相关信息则无法继续登录过程；填写完成后还需填写个人基本信息界面，输入中英文名等必填内容才能完成注册。上述过程中并无\u0026quot;跳过\u0026quot;\u0026ldquo;拒绝\u0026quot;等选项，亦无授权同意收集个人信息的提示。\n罗某以隐私权、个人信息保护纠纷起诉，主张网站和 APP 未告知个人信息收集政策、强制收集手机号和用户画像等信息并超范围使用，且未经允许发送营销短信侵扰私人生活安宁；其提出查阅、复制请求后，认为公司提供的系统截图不够及时清晰；请求判令提供清晰的个人信息副本、停止侵权、删除个人信息、赔礼道歉并赔偿 2900 元。某科技公司抗辩：案涉信息为合作线下体验店收集，其无违法收集处理的主观故意；网站和 APP 需根据用户需求推荐内容，即通过自动化决策方式向用户推送信息是基本功能服务，收集用户画像信息用于自动化决策系提供服务所必需，无需取得同意。\n法院审理与说理 争议焦点：某科技公司以自动化决策推送信息为由收集用户画像信息的行为，是否属于应当取得个人同意的法定例外情形。\n第一，\u0026ldquo;合同所必需\u0026quot;的认定标准。法院确立两步判断法：可以结合有关法律法规及规章、规范性文件对必要个人信息范围的规定，并考量合同的类型、内容作出认定；\u0026ldquo;如果信息处理的缺位将使合同约定的基本功能服务或者用户自主选择的附加功能服务无法实现的，可以认定为订立、履行合同所必需，反之则不予认定\u0026rdquo;。\n第二，本案的具体认定。参照国家互联网信息办公室、工业和信息化部、公安部、国家市场监督管理总局《常见类型移动互联网应用程序必要个人信息范围规定》（国信办秘字〔2021〕14 号），学习教育类 APP 基本功能服务为\u0026quot;在线辅导、网络课堂等\u0026rdquo;，必要个人信息为注册用户移动电话号码。故案涉 APP 的基本功能服务并不包括通过自动化决策方式向用户推送信息，某科技公司\u0026quot;以其业务模式系通过自动化决策方式向用户进行信息推送为由，主张收集用户画像信息是其提供服务的基础，没有依据\u0026rdquo;；亦无证据表明罗某曾自主选择使用附加功能服务。故收集用户画像信息应当取得罗某同意。\n第三，关于同意效力。依据个人信息保护法第十六条，个人信息处理者不得以个人不同意处理其个人信息或者撤回同意为由，拒绝提供产品或者服务（属提供产品或者服务所必需的除外）。案涉软件在用户首次登录界面要求提交职业类型、学龄阶段、英语水平等用户画像相关信息时，未提供\u0026quot;跳过\u0026quot;或\u0026quot;拒绝\u0026quot;等选项，也未提供不同意提交相关信息情况下的其他替代性登录方式，\u0026ldquo;使得用户提交相关信息成为登录的唯一途径\u0026rdquo;；此种产品设计将导致不同意收集相关信息的用户\u0026quot;出于使用软件的目的，不得不勾选\u0026rsquo;同意\u0026rsquo;提供相关信息，否则只能放弃对案涉软件的使用\u0026rdquo;。法院认定：\u0026ldquo;此种情形下\u0026rsquo;同意\u0026rsquo;提供个人信息，实际是在用户非自愿的情况下作出，不符合个人信息保护法第十四条第一款……\u0026lsquo;该同意应当由个人在充分知情的前提下自愿、明确作出\u0026rsquo;的规定，不产生取得个人同意的效力。\u0026rdquo;\n裁判结果 判令某科技公司向罗某提供清晰的个人信息副本，停止关于罗某名下两部手机号码及其用户画像信息、账号密码信息、订单信息等个人信息的处理行为和删除相关个人信息，以书面形式赔礼道歉，并赔偿律师费、取证费合计 2900 元；二审驳回上诉，维持原判。\n数据法 / AI 法要点 （1）\u0026ldquo;个性化推荐/自动化决策\u0026quot;不构成 APP 提供服务的\u0026quot;必要个人信息\u0026rdquo;——这是对\u0026quot;算法推荐是基本功能\u0026quot;这一常见抗辩的正面否定；（2）\u0026ldquo;不给跳过选项的同意\u0026quot;不产生同意效力，即\u0026quot;捆绑式同意\u0026quot;在司法上被认定为非自愿；（3）确立了\u0026quot;合同所必需\u0026quot;的实质判断标准：缺位将使基本功能或用户自主选择的附加功能无法实现；（4）本案对生成式 AI、个性化推送类产品的登录与授权界面设计具有直接合规指引。\n相关法条 《中华人民共和国民法典》第 1035 条；《中华人民共和国个人信息保护法》第 13 条、第 14 条、第 16 条。\n权威来源 官方专页 材料来源：最高人民法院官网「审判业务—指导性案例」栏目发布的第 47 批指导性案例（法〔2025〕150 号，2025 年 8 月 28 日发布）文本\n站内关联法规 个人信息保护法 ","permalink":"https://ai.intlaws.com/cases/china/gca-265/","summary":"最高人民法院第47批指导性案例（法〔2025〕150号，2025年8月28日发布）之一：罗某诉某科技有限公司隐私权、个人信息保护纠纷案。裁判要点以最高人民法院官方发布文本为准。","title":"指导性案例265号：罗某诉某科技有限公司隐私权、个人信息保护纠纷案"},{"content":"案件名称与案号 指导性案例 266 号：黄某欢诉某信用管理有限公司个人信息保护纠纷案\n一审（2021）浙 0192 民初 8058 号 · 杭州互联网法院 · 2022 年 4 月 6 日（双方当事人均未上诉，判决已生效）\n关键词 民事 / 个人信息保护 / 先享后付 / 信用服务 / 必要原则 / 最小影响\n基本案情 2021 年 3 月 15 日，黄某欢发现在未经其允许的情况下被开通某信用账户，询问客服后得知系其 3 月 7 日开通重庆公共交通乘车码时使用\u0026quot;先享后付\u0026quot;功能所致。通过某应用开通乘车码时需点击\u0026quot;同意协议并开通\u0026quot;，下方以蓝色字体载明授权协议与获取姓名、手机号、身份证信息用于实名领卡；《某应用重庆公共交通付款服务协议》载明公交付款服务由某技术公司提供，用户无法及时支付乘车费时由该公司先行支付并获得追索债权，用户须同意授权查询其信用分作为开通与持续提供的风险评估参考；《某服务协议》载明用户授权某信用公司从合法存有用户个人信息的信息提供者处收集信息并进行处理，范围可能包括个人身份信息、交易信息、履约信息、设备信息及其他能够评估反映用户信用或风险状况的信息。黄某欢随即要求客服关闭账户并删除个人信息，后账户被注销、信息被删除。同年 3 月 25 日，其在某应用开通广东省清远市电子公交卡并查阅相关服务协议，内容与重庆乘车码协议大致相同；4 月 25 日其自行注销某信用账户。2021 年 10 月 13 日，黄某欢以个人信息保护纠纷起诉，主张某信用公司存在误导、强迫、非必要开通某信用服务的行为，请求判令停止侵权并赔偿损害。\n法院审理与说理 争议焦点：某信用公司在向黄某欢提供\u0026quot;先享后付\u0026quot;功能时收集其个人信息的行为是否构成侵权。\n其一，收集案涉个人信息是\u0026quot;先享后付\u0026quot;合同所必需。法院指出\u0026quot;先乘车后付款即\u0026rsquo;先享后付\u0026rsquo;，是商业主体基于用户选择而提供的服务，是对承载个人信息的数据的合理运用，也是诚信机制商业化的应用创新\u0026quot;，并具体分析某信用服务的三项功能（提供信用和风险状况、接收同步的订单与付款状态信息以分析履约能力、推送还款信息）。由于\u0026quot;先享后付\u0026quot;涉及第三方平台先行垫资，\u0026ldquo;第三方平台显然需要在服务前评估用户的信用状况，并据此作出是否提供服务的决定，以确保债权的实现\u0026rdquo;。据此，收集相关信息属为订立、履行合同所必需，个案中\u0026quot;实际本可不经个人同意，但公交公司、某技术公司及某信用公司却采取了事先征得用户同意的方式收集信息，最大限度维护了用户的权益\u0026quot;。\n其二，履行了法定告知义务。根据\u0026quot;告知—同意\u0026quot;规则，个人信息处理者即便不需要取得同意，仍须履行告知义务。案涉电子公交卡由三方联合推出，相关协议\u0026quot;均已在显著位置，通过有别于页面其他黑色字体的方式，提醒用户注意查阅\u0026quot;，个人信息处理条款\u0026quot;采用了足以引起用户注意的加粗字体、放大字号、标蓝颜色等明显标识方式\u0026quot;，故误导开通的主张不能成立。\n其三，不存在误导、强迫情形。黄某欢主张信用服务捆绑于电子乘车码、违反消费者权益保护法第九条关于消费者自主选择权的规定。法院认为其\u0026quot;可以以现金投币方式乘车，也可以选择实体公交卡方式乘车，当然还可以选用案涉电子公交卡方式乘车\u0026quot;，公交公司并未强迫；且协议明确告知可申请退卡或停止使用服务，亦告知可通过\u0026quot;我的-某信用-信用管理-授权管理\u0026quot;关闭授权，\u0026ldquo;均给予了用户相应的自主选择服务的权利，用户亦可采用较为便捷的方式终止对其个人信息的授权使用\u0026rdquo;。\n其四，符合最小必要原则。依个人信息保护法第六条（处理个人信息应与处理目的直接相关、采取对个人权益影响最小的方式、限于实现处理目的的最小范围），某信用服务\u0026quot;通过事先对用户进行信誉评估，向公交公司提供的仅是\u0026rsquo;准入与否\u0026rsquo;的结论性信息，属于实现\u0026rsquo;先享后付\u0026rsquo;功能所必需\u0026quot;。\n裁判结果 驳回黄某欢的诉讼请求；判决已发生法律效力。\n数据法 / AI 法要点 （1）以\u0026quot;合同所必需\u0026quot;为例外处理个人信息，须同时满足\u0026quot;必要性 + 告知 + 无强迫 + 最小必要\u0026quot;四项检验，缺一不可；（2）\u0026ldquo;结论性信息\u0026rdquo;（如准入与否）而非原始信用数据的输出方式，被认定为符合最小必要原则——这是数据最小化在商业场景中的可操作范本；（3）本案与 265 号形成鲜明对照：同以\u0026quot;合同必需/自动化决策\u0026quot;为争点，一驳一支持，区别在于必要性与替代性登录方式的有无，宜对照研读。\n相关法条 《中华人民共和国民法典》第 1035 条；《中华人民共和国个人信息保护法》第 6 条、第 13 条、第 17 条。\n权威来源 官方专页 （编者注：该页为 266 号案例专页；此前清单初稿曾误挂同批发布页，已更正，仍可参见最高人民法院公报同案页 https://gongbao.court.gov.cn/Details/0c4461ef4b6e40e7a1ad4e30428909.html ） 材料来源：最高人民法院官网「审判业务—指导性案例」栏目发布的第 47 批指导性案例（法〔2025〕150 号，2025 年 8 月 28 日发布）文本\n站内关联法规 个人信息保护法 ","permalink":"https://ai.intlaws.com/cases/china/gca-266/","summary":"最高人民法院第47批指导性案例（法〔2025〕150号，2025年8月28日发布）之一：黄某欢诉某信用管理有限公司个人信息保护纠纷案。裁判要点以最高人民法院官方发布文本为准。","title":"指导性案例266号：黄某欢诉某信用管理有限公司个人信息保护纠纷案"},{"content":"案件名称与案号 指导性案例 267 号：某文化传媒有限公司与游某梅执行实施案\n审判阶段 一审（2020）渝 01 民初 1035 号 · 重庆市第一中级人民法院 · 2022 年 6 月 29 日；二审（2022）渝民终 859 号 · 重庆市高级人民法院 · 2022 年 12 月 26 日\n执行阶段 （2023）渝 01 执 164 号 · 重庆市第一中级人民法院 · 2023 年 3 月 24 日裁定、2023 年 4 月 27 日结案\n关键词 执行 / 执行实施 / 网络平台账号 / 账号密码交付 / 实名认证信息变更\n基本案情 某文化传媒有限公司以不正当竞争纠纷起诉，请求确认名为\u0026quot;浪某仙\u0026quot;的某平台账号归其所有，判令游某梅等交付账号及密码、停止不正当竞争行为并赔偿经济损失 618 万元。生效判决（一审、二审）确认账号归属某文化传媒公司，游某梅于判决生效后三日内交付账号及密码，驳回赔偿等其他诉讼请求。\n判决生效后游某梅未履行，某文化传媒公司申请强制执行，请求执行法院向平台运营服务商发出协助执行通知书，协助清空案涉账号原实名认证信息、重新认证为某文化传媒公司身份信息并换绑其指定手机号码。另查明，游某梅因涉刑事案件自 2022 年 9 月 18 日起被羁押，后被以职务侵占罪判处有期徒刑八年。执行法院于 2023 年 3 月 24 日作出裁定，清除\u0026quot;浪某仙\u0026quot;账号中游某梅的实名认证信息，解除原绑定手机号码并换绑为申请执行人指定的手机号码；裁定生效后按执行裁定书和协助执行通知书要求，平台运营公司协助完成对案涉账号登录密码、实名认证信息和注册手机号码的变更。2023 年 4 月 27 日结案。\n法院审理与说理 执行争议焦点：交付网络平台账号及密码的执行，应当如何实现账号权利的完整移转。\n第一，交付的实质是完整移转账号权利。根据生效判决认定的理由，案涉账号系某文化传媒公司决定注册，因企业注册认证须先以手机号注册，故由时任法定代表人游某梅以手机号注册并由其代表公司管理；依判决确认的交付内容，\u0026ldquo;应当是将账号全部的用户权限、权益等完整交付\u0026rdquo;，交付的关键是使申请执行人\u0026quot;实现对案涉账号依法占有、独立控制，进行运营、使用、管理\u0026quot;。\n第二，\u0026ldquo;仅交付账号及密码\u0026quot;不足以实现交付目的。网络平台账号\u0026quot;高度依赖实名制认证和注册手机号码验证\u0026rdquo;；若仅交付账号密码而未清空实名信息、变更手机号码，掌握注册信息的他人\u0026quot;依然可以凭注册的实名信息、手机号码等重置账号及密码\u0026quot;，影响合法权利人的占有、控制、支配等权利；且申请执行人对账号管理、后台运营、数据迁移等事项，也会因没有注册用户身份及手机号码验证而难以实施；\u0026ldquo;一旦他人非法使用该账号从事违法活动，将对核实行为主体身份带来困难，损害社会公共利益\u0026rdquo;。因此，账号交付的核心内容应当是变更为申请执行人的注册用户身份及手机号码。\n第三，变更方式的程序选择。依网络安全法第二十四条第一款（网络运营者提供信息发布、即时通讯等服务时应当要求用户提供真实身份信息），通常变更账号主体信息应经向平台申请、平台认证核验并公示主体变更信息等程序；但被执行人客观上存在履行障碍（被羁押），故执行法院根据申请执行人申请，\u0026ldquo;以通知相关平台协助执行的方式，完成案涉账号实名身份信息等的变更\u0026rdquo;。\n裁判结果 2023 年 4 月 27 日，重庆市第一中级人民法院作出结案通知书，该案执行完毕。\n数据法 / AI 法要点 （1）确立网络平台账号作为可执行财产（数字资产）的\u0026quot;完整交付\u0026quot;标准：账号交付必须连同实名认证信息与绑定手机号的变更，否则权利无法真正移转；（2）明确网络安全法实名制规则与民事强制执行的衔接路径：在当事人履行障碍时，可经由协助执行通知书由平台直接变更实名信息；（3）对暗含身份属性的数字资产（账号、店铺、粉丝号等）的司法处置具有示范意义。\n相关法条 《中华人民共和国网络安全法》第 24 条；《中华人民共和国民事诉讼法》第 263 条（本案适用的是 2021 年修正的民事诉讼法第 259 条）。\n权威来源 官方专页 （首批 6 件完。第二批：北京互联网法院涉人工智能典型案例 8 件；第三批：AIGC 著作权与生成式 AI 平台责任案；第四批：涉 AI 人格权案，另行交付。）\n材料来源：最高人民法院官网「审判业务—指导性案例」栏目发布的第 47 批指导性案例（法〔2025〕150 号，2025 年 8 月 28 日发布）文本\n站内关联法规 网络安全法 ","permalink":"https://ai.intlaws.com/cases/china/gca-267/","summary":"最高人民法院第47批指导性案例（法〔2025〕150号，2025年8月28日发布）之一：某文化传媒有限公司与游某梅执行实施案。明确交付网络平台账号及密码的执行方法，执行实施要点以最高人民法院官方发布文本为准。","title":"指导性案例267号：某文化传媒有限公司与游某梅执行实施案"},{"content":"案件名称与案号 彭某某诉某软件运营公司肖像权纠纷案\n——擅用他人肖像供用户「换脸」，应承担肖像权侵权责任\n发布批次为最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例（案例 3），官方未公布案号\n关键词 民事 / 肖像权 / AI 换脸 / 营利目的使用\n基本案情 某软件运营公司开发运营一款软件，用于供付费会员使用他人的照片进行面部替换（俗称「换脸」），进而生成面部为该他人的作品。该公司未经彭某某同意，自行在软件中上架彭某某的肖像供会员「换脸」并牟利。彭某某认为其肖像权受到侵害，诉请判令该公司赔礼道歉、赔偿损失共计 5 万余元。\n法院审理与说理 法院认为，自然人的肖像权受法律保护，未经自然人同意，他人不得制作、使用、公开自然人的肖像；肖像权受到侵害的，有权要求停止侵害、消除影响、赔礼道歉，并可以要求赔偿损失。某软件运营公司未经彭某某授权同意，以营利为目的使用含有彭某某肖像的照片、视频，侵害了彭某某的肖像权，应承担相应民事责任。\n裁判结果 判决某软件运营公司向彭某某赔礼道歉并赔偿损失 3000 元。\n数据法 / AI 法要点 「换脸」软件以模板形式主动上架他人肖像供付费使用，与用户自行生成有本质区别：前者是平台自身的以营利目的使用行为，构成直接侵害肖像权。开发、运营 AI 换脸类应用者，须确保模板素材本身已获肖像授权。\n相关法条 《中华人民共和国民法典》关于肖像权保护的规定（第 1019 条、第 995 条）与侵权责任的规定（第 1165 条），依官方文本说理归纳。\n权威来源 最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例官方文本（court.gov.cn）。\n补充来源\n官方发布：最高人民法院发布侵害人格权典型案例（court.gov.cn 467631） 材料来源：最高人民法院 2025 年 6 月 12 日利用网络、信息技术侵害人格权典型案例官方文本（该专题案例 3）\n站内关联法规 个人信息保护法 ","permalink":"https://ai.intlaws.com/cases/china/spc-personality-ai-deepfake/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e彭某某诉某软件运营公司肖像权纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——擅用他人肖像供用户「换脸」，应承担肖像权侵权责任\u003c/p\u003e\n\u003cp\u003e发布批次为最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例（案例 3），官方未公布案号\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 肖像权 / AI 换脸 / 营利目的使用\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e某软件运营公司开发运营一款软件，用于供付费会员使用他人的照片进行面部替换（俗称「换脸」），进而生成面部为该他人的作品。该公司未经彭某某同意，自行在软件中上架彭某某的肖像供会员「换脸」并牟利。彭某某认为其肖像权受到侵害，诉请判令该公司赔礼道歉、赔偿损失共计 5 万余元。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e法院认为，自然人的肖像权受法律保护，\u003cstrong\u003e未经自然人同意，他人不得制作、使用、公开自然人的肖像\u003c/strong\u003e；肖像权受到侵害的，有权要求停止侵害、消除影响、赔礼道歉，并可以要求赔偿损失。某软件运营公司未经彭某某授权同意，\u003cstrong\u003e以营利为目的使用\u003c/strong\u003e含有彭某某肖像的照片、视频，侵害了彭某某的肖像权，应承担相应民事责任。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e判决某软件运营公司向彭某某赔礼道歉并赔偿损失 3000 元。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e「换脸」软件以模板形式\u003cstrong\u003e主动上架他人肖像供付费使用\u003c/strong\u003e，与用户自行生成有本质区别：前者是平台自身的以营利目的使用行为，构成直接侵害肖像权。开发、运营 AI 换脸类应用者，须确保模板素材本身已获肖像授权。\u003c/p\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e《中华人民共和国民法典》关于肖像权保护的规定（第 1019 条、第 995 条）与侵权责任的规定（第 1165 条），依官方文本说理归纳。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cp\u003e最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例官方文本（court.gov.cn）。\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003e补充来源\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e官方发布：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/467631.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院发布侵害人格权典型案例（court.gov.cn 467631）\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：最高人民法院 2025 年 6 月 12 日利用网络、信息技术侵害人格权典型案例官方文本（该专题案例 3）\u003c/p\u003e\n\u003ch2 id=\"站内关联法规\"\u003e站内关联法规\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"/compliance/china/pipl/\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e个人信息保护法\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e","title":"侵害人格权典型案例：AI换脸软件擅用他人肖像供会员换脸案（彭某某诉某软件运营公司肖像权纠纷案）"},{"content":"案件名称与案号 韩某非法控制计算机信息系统案\n——非法获取他人家庭监控摄像头控制权，情节严重的，构成非法控制计算机信息系统罪\n发布批次为最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例（案例 6），官方未公布案号\n关键词 刑事 / 非法控制计算机信息系统 / 智能家居设备 / 隐私与个人信息安全\n基本案情 2020 年，韩某通过聊天软件，非法获取他人家中网络监控摄像头账号、密码等信息，添加到自己手机或电脑上，非法获取他人家庭监控摄像头的控制权限，远程观看他人家中画面，并将部分画面截图保存。截至 2022 年 5 月，韩某登录并控制的监控摄像头共 193 个。韩某被检察机关提起公诉。\n法院审理与说理 法院认为，非法控制计算机信息系统罪是指违反国家规定，对计算机信息系统实施非法控制，情节严重的行为。在案证据证实，2020 年至 2022 年 5 月，韩某非法控制监控摄像头设备 193 个，窥探他人隐私，保存了大量其窥探到的他人家中画面影像的截图，属于情节特别严重，其行为构成非法控制计算机信息系统罪。\n裁判结果 判决韩某犯非法控制计算机信息系统罪，判处有期徒刑三年一个月，并处罚金人民币 1.3 万元。\n数据法 / AI 法要点 ① 家庭监控摄像头被依法认定为「计算机信息系统」，为智能家居设备提供了刑法保护路径；② 控制数量 193 个达到「情节特别严重」标准，量化了此类犯罪的入罪尺度；③ 提示公众加强智能家居设备账号密码保护。\n相关法条 《中华人民共和国刑法》第 285 条第 2 款（非法控制计算机信息系统罪）。\n权威来源 最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例官方文本（court.gov.cn）。\n补充来源\n官方发布：最高人民法院发布侵害人格权典型案例（court.gov.cn 467631） 材料来源：最高人民法院 2025 年 6 月 12 日利用网络、信息技术侵害人格权典型案例官方文本（该专题案例 6）\n站内关联法规 个人信息保护法 ","permalink":"https://ai.intlaws.com/cases/china/spc-personality-hidden-camera/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e韩某非法控制计算机信息系统案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——非法获取他人家庭监控摄像头控制权，情节严重的，构成非法控制计算机信息系统罪\u003c/p\u003e\n\u003cp\u003e发布批次为最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例（案例 6），官方未公布案号\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e刑事 / 非法控制计算机信息系统 / 智能家居设备 / 隐私与个人信息安全\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e2020 年，韩某通过聊天软件，非法获取他人家中网络监控摄像头账号、密码等信息，添加到自己手机或电脑上，非法获取他人家庭监控摄像头的控制权限，\u003cstrong\u003e远程观看他人家中画面，并将部分画面截图保存\u003c/strong\u003e。截至 2022 年 5 月，韩某登录并控制的监控摄像头共 \u003cstrong\u003e193 个\u003c/strong\u003e。韩某被检察机关提起公诉。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e法院认为，非法控制计算机信息系统罪是指违反国家规定，对计算机信息系统实施非法控制，情节严重的行为。在案证据证实，2020 年至 2022 年 5 月，韩某非法控制监控摄像头设备 193 个，\u003cstrong\u003e窥探他人隐私，保存了大量其窥探到的他人家中画面影像的截图，属于情节特别严重\u003c/strong\u003e，其行为构成非法控制计算机信息系统罪。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e判决韩某犯非法控制计算机信息系统罪，判处有期徒刑三年一个月，并处罚金人民币 1.3 万元。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e① \u003cstrong\u003e家庭监控摄像头被依法认定为「计算机信息系统」\u003c/strong\u003e，为智能家居设备提供了刑法保护路径；② 控制数量 193 个达到「情节特别严重」标准，量化了此类犯罪的入罪尺度；③ 提示公众加强智能家居设备账号密码保护。\u003c/p\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e《中华人民共和国刑法》第 285 条第 2 款（非法控制计算机信息系统罪）。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cp\u003e最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例官方文本（court.gov.cn）。\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003e补充来源\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e官方发布：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/467631.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院发布侵害人格权典型案例（court.gov.cn 467631）\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：最高人民法院 2025 年 6 月 12 日利用网络、信息技术侵害人格权典型案例官方文本（该专题案例 6）\u003c/p\u003e\n\u003ch2 id=\"站内关联法规\"\u003e站内关联法规\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"/compliance/china/pipl/\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e个人信息保护法\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e","title":"侵害人格权典型案例：非法获取家庭监控摄像头控制权案（韩某非法控制计算机信息系统案）"},{"content":"案件名称与案号 徐某、李某侵犯公民个人信息案\n——非法买卖人脸信息情节严重的，构成侵犯公民个人信息罪\n发布批次为最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例（案例 5），官方未公布案号\n关键词 刑事 / 侵犯公民个人信息 / 人脸信息 / 情节严重\n基本案情 2021 年 6 月起，徐某通过其社交账号自他人处购买约 130 套公民个人身份信息（包括公民的动态人脸图等信息）和 1 套软件。在未经游戏账号所有人同意的情况下，徐某用购买的公民个人信息和该软件解封多人的游戏账号，还对外有偿出租该软件、出售公民个人信息给社会人员，用于解封社交账号、游戏账号。徐某获利约 6 千元。\n2021 年 8 月起，李某通过使用徐某提供的软件，采取人脸识别、完成观看任务视频等方式为他人解封社交账号，还将从多个渠道购进的公民个人信息（包括人脸照片、视频等）转卖，获利约 3 万元。徐某、李某被检察机关提起公诉。\n法院审理与说理 法院认为，徐某、李某违反国家有关规定，非法获取、出售或提供公民个人信息，情节严重，其行为均已构成侵犯公民个人信息罪，应依法惩处。两人归案后如实供述犯罪事实，自愿认罪，积极退缴违法所得，依法可以从轻处罚。\n裁判结果 判处李某犯侵犯公民个人信息罪，有期徒刑九个月，并处罚金人民币 3 万元；徐某犯侵犯公民个人信息罪，有期徒刑六个月，并处罚金人民币 6 千元；违法所得及手机、电脑等作案工具予以没收。\n数据法 / AI 法要点 人脸信息属敏感个人信息，刑法层面的保护与《个人信息保护法》第 28 条（敏感个人信息）形成衔接；AI 换脸、深度合成的产业上游因此负有更严格的素材来源合规审查义务。\n相关法条 《中华人民共和国刑法》第 253 条之一（侵犯公民个人信息罪）；《中华人民共和国个人信息保护法》第 28 条（敏感个人信息）。\n权威来源 最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例官方文本（court.gov.cn）。\n补充来源\n官方发布：最高人民法院发布侵害人格权典型案例（court.gov.cn 467631） 材料来源：最高人民法院 2025 年 6 月 12 日利用网络、信息技术侵害人格权典型案例官方文本（该专题案例 5）\n站内关联法规 个人信息保护法 ","permalink":"https://ai.intlaws.com/cases/china/spc-personality-face-data-trafficking/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e徐某、李某侵犯公民个人信息案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——非法买卖人脸信息情节严重的，构成侵犯公民个人信息罪\u003c/p\u003e\n\u003cp\u003e发布批次为最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例（案例 5），官方未公布案号\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e刑事 / 侵犯公民个人信息 / 人脸信息 / 情节严重\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e2021 年 6 月起，徐某通过其社交账号自他人处购买约 130 套公民个人身份信息（包括公民的动态人脸图等信息）和 1 套软件。在未经游戏账号所有人同意的情况下，徐某用购买的公民个人信息和该软件解封多人的游戏账号，还对外有偿出租该软件、出售公民个人信息给社会人员，用于解封社交账号、游戏账号。徐某获利约 6 千元。\u003c/p\u003e\n\u003cp\u003e2021 年 8 月起，李某通过使用徐某提供的软件，采取人脸识别、完成观看任务视频等方式为他人解封社交账号，还将从多个渠道购进的公民个人信息（包括人脸照片、视频等）转卖，获利约 3 万元。徐某、李某被检察机关提起公诉。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e法院认为，徐某、李某违反国家有关规定，非法获取、出售或提供公民个人信息，情节严重，其行为均已构成侵犯公民个人信息罪，应依法惩处。两人归案后如实供述犯罪事实，自愿认罪，积极退缴违法所得，依法可以从轻处罚。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e判处李某犯侵犯公民个人信息罪，有期徒刑九个月，并处罚金人民币 3 万元；徐某犯侵犯公民个人信息罪，有期徒刑六个月，并处罚金人民币 6 千元；违法所得及手机、电脑等作案工具予以没收。\u003c/p\u003e\n\u003ch2 id=\"数据法--ai-法要点\"\u003e数据法 / AI 法要点\u003c/h2\u003e\n\u003cp\u003e人脸信息属敏感个人信息，刑法层面的保护与《个人信息保护法》第 28 条（敏感个人信息）形成衔接；AI 换脸、深度合成的产业上游因此负有更严格的素材来源合规审查义务。\u003c/p\u003e\n\u003ch2 id=\"相关法条\"\u003e相关法条\u003c/h2\u003e\n\u003cp\u003e《中华人民共和国刑法》第 253 条之一（侵犯公民个人信息罪）；《中华人民共和国个人信息保护法》第 28 条（敏感个人信息）。\u003c/p\u003e\n\u003ch2 id=\"权威来源\"\u003e权威来源\u003c/h2\u003e\n\u003cp\u003e最高人民法院 2025-06-12 利用网络、信息技术侵害人格权典型案例官方文本（court.gov.cn）。\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003e补充来源\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e官方发布：\u003ca href=\"https://www.court.gov.cn/zixun/xiangqing/467631.html\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e最高人民法院发布侵害人格权典型案例（court.gov.cn 467631）\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e材料来源\u003c/strong\u003e：最高人民法院 2025 年 6 月 12 日利用网络、信息技术侵害人格权典型案例官方文本（该专题案例 5）\u003c/p\u003e","title":"侵害人格权典型案例：非法买卖人脸信息刑事案（徐某、李某侵犯公民个人信息案）"},{"content":"案件名称与案号 上海新创华文化发展有限公司诉杭州某智能科技有限公司侵害作品信息网络传播权及不正当竞争纠纷案\n——AIGC 平台 LoRA 模型训练著作权侵权案（业内通称「杭互 LoRA 案」）\n一审 (2024)浙0192民初1587号（杭州互联网法院，2024-09-25 判决）；二审 (2024)浙01民终10332号（杭州市中级人民法院，2024-12-30 判决，驳回上诉、维持原判）｜ 入选：浙江法院 2024 年知识产权保护典型案例\n关键词 民事 / 著作权 / 信息网络传播权 / LoRA 模型 / 帮助侵权 / 平台注意义务\n基本案情 原告经授权获得涉案奥特曼动漫形象的知识产权及相关维权权利。被告杭州某智能科技有限公司是某 AI 平台的运营主体，通过该平台提供 Checkpoint 基础模型和 LoRA 模型（一种针对大规模预训练模型的高效微调技术），支持图生图、模型在线训练等诸多功能。在该平台首页及「推荐」「IP 作品」项下，存在包括奥特曼在内的各类 AI 生成图片以及 LoRA 模型，可应用、下载、发布或分享链接。被诉的多个奥特曼 LoRA 模型系由用户上传奥特曼相关训练图片、选择平台基础模型、调整参数进行训练后形成；用户分享奥特曼 LoRA 模型时会将 AI 生成的奥特曼图片作为封面图和示例图，其他用户可通过输入提示词、选择基础模型、叠加奥特曼 LoRA 模型，生成与奥特曼形象实质性相似的图片。\n原告诉请判令被告：停止侵权行为（包括停止提供奥特曼有关模型的训练和发布服务，删除已有奥特曼训练模型、图片等跟奥特曼有关的全部物料和相关数据，对奥特曼及相关关键词在全平台的未授权使用行为进行屏蔽）；赔偿经济损失及合理费用 30 万元。\n法院审理与说理 （一）是否侵害信息网络传播权。 被告系生成式人工智能服务提供者，而非网络传播内容的提供者，并未直接实施受信息网络传播权控制的行为，不构成直接侵权。但鉴于：奥特曼动漫形象在全球范围内具有相当高的知名度和影响力；被诉侵权图片由用户上传后，置于平台中能够被明显感知的位置，被告应当知道相关内容具有较大侵权可能性；用户通过叠加奥特曼 LoRA 模型可以稳定输出图片角色形象的特征，此时生成式人工智能对于用户使用行为的结果增强了可识别性、可干预性；被告从涉案 AI 创作服务中直接获得经济利益，且有能力采取却怠于采取符合侵权行为发生时技术水平的必要措施——综上，被告未尽到合理注意义务，存在主观过错，构成帮助侵害涉案奥特曼作品信息网络传播权的行为。\n（二）是否构成不正当竞争。 从被告的商业模式和经营方式本身看，涉案服务方便了用户的作品创作活动，有利于文学、艺术创作的繁荣，并未违反诚信原则和商业道德；从对著作权人、消费者、社会公众利益的影响看，基础模型和 LoRA 模型训练、参考生图的技术本身具有中立性，用户按照平台服务协议在尊重他人知识产权的前提下进行生成式人工智能创作，一般不会侵害著作权人合法权益，且新旧作品间影响力的此消彼长是竞争的常态化结果，并非对在先作品著作权人合法权益的实质性损害。故对不正当竞争的诉请不予支持。\n裁判结果 一审判决被告停止侵害涉案奥特曼作品信息网络传播权的行为（包括但不限于立即删除已生成并发布的涉案奥特曼图片、奥特曼 LoRA 模型，停止提供相关奥特曼 LoRA 模型的发布和应用服务，并采取必要措施有效制止侵权行为等），赔偿原告经济损失及合理开支 3 万元。二审驳回上诉、维持原判。2025 年初该案入选 2024 年度中国十大传媒法事例；判决生效后，杭州互联网法院向被告发出全国首份涉生成式人工智能司法建议书，从完善「通知＋必要措施」机制、加强对 LoRA 模型的平台监管、强化平台知识产权日常管理、推进人工智能合规建设和行业自律四个层面提出改进建议。\n数据法 / AI 法要点 ① 平台提供模型训练工具（LoRA）并设专区、榜单、激励引导用户上传侵权素材的，其对侵权素材的注意义务相应提高，责任按「服务类型＋干预程度＋获益情况」综合认定；② 「直接侵权／帮助侵权」的区分与技术中立抗辩的射程：技术中立否定不正当竞争，但不免帮助侵权的注意义务；③ 平台「明知或应知」的判断要素：权利作品知名度、内容展示位置、生成结果的可识别性与可干预性、直接获益、措施采取的可行性。\n相关法条 《中华人民共和国著作权法》相关条款（详见上文说理）；《生成式人工智能服务管理暂行办法》相关条款（详见上文说理）。\n权威来源 浙江法院 2024 年知识产权保护典型案例发布文本（一审、二审案号及裁判内容）；杭州互联网法院涉生成式人工智能司法建议书报道。\n补充来源\n杭州中院二审维持原判（公开报道） 材料来源：浙江法院 2024 年知识产权保护典型案例发布文本；公开转载的判决与司法建议报道（判决书全文官方未公开）\n站内关联法规 生成式人工智能服务管理暂行办法 ","permalink":"https://ai.intlaws.com/cases/china/hic-ai-lora/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e上海新创华文化发展有限公司诉杭州某智能科技有限公司侵害作品信息网络传播权及不正当竞争纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——AIGC 平台 LoRA 模型训练著作权侵权案（业内通称「杭互 LoRA 案」）\u003c/p\u003e\n\u003cp\u003e一审 (2024)浙0192民初1587号（杭州互联网法院，2024-09-25 判决）；二审 (2024)浙01民终10332号（杭州市中级人民法院，2024-12-30 判决，驳回上诉、维持原判）｜ \u003cstrong\u003e入选\u003c/strong\u003e：浙江法院 2024 年知识产权保护典型案例\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 著作权 / 信息网络传播权 / LoRA 模型 / 帮助侵权 / 平台注意义务\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e原告经授权获得涉案奥特曼动漫形象的知识产权及相关维权权利。被告杭州某智能科技有限公司是某 AI 平台的运营主体，通过该平台提供 \u003cstrong\u003eCheckpoint 基础模型和 LoRA 模型\u003c/strong\u003e（一种针对大规模预训练模型的高效微调技术），支持图生图、模型在线训练等诸多功能。在该平台首页及「推荐」「IP 作品」项下，存在包括奥特曼在内的各类 AI 生成图片以及 LoRA 模型，可应用、下载、发布或分享链接。被诉的多个奥特曼 LoRA 模型系由用户上传奥特曼相关训练图片、选择平台基础模型、调整参数进行训练后形成；用户分享奥特曼 LoRA 模型时会将 AI 生成的奥特曼图片作为封面图和示例图，其他用户可通过输入提示词、选择基础模型、叠加奥特曼 LoRA 模型，生成与奥特曼形象实质性相似的图片。\u003c/p\u003e\n\u003cp\u003e原告诉请判令被告：停止侵权行为（包括停止提供奥特曼有关模型的训练和发布服务，删除已有奥特曼训练模型、图片等跟奥特曼有关的全部物料和相关数据，对奥特曼及相关关键词在全平台的未授权使用行为进行屏蔽）；赔偿经济损失及合理费用 30 万元。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e（一）是否侵害信息网络传播权。\u003c/strong\u003e 被告系生成式人工智能服务提供者，而非网络传播内容的提供者，并未直接实施受信息网络传播权控制的行为，\u003cstrong\u003e不构成直接侵权\u003c/strong\u003e。但鉴于：奥特曼动漫形象在全球范围内具有相当高的知名度和影响力；被诉侵权图片由用户上传后，\u003cstrong\u003e置于平台中能够被明显感知的位置\u003c/strong\u003e，被告应当知道相关内容具有较大侵权可能性；用户通过叠加奥特曼 LoRA 模型可以\u003cstrong\u003e稳定输出图片角色形象的特征\u003c/strong\u003e，此时生成式人工智能对于用户使用行为的结果增强了\u003cstrong\u003e可识别性、可干预性\u003c/strong\u003e；被告从涉案 AI 创作服务中\u003cstrong\u003e直接获得经济利益\u003c/strong\u003e，且有能力采取却怠于采取符合侵权行为发生时技术水平的必要措施——综上，被告未尽到合理注意义务，存在主观过错，\u003cstrong\u003e构成帮助侵害涉案奥特曼作品信息网络传播权的行为\u003c/strong\u003e。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e（二）是否构成不正当竞争。\u003c/strong\u003e 从被告的商业模式和经营方式本身看，涉案服务方便了用户的作品创作活动，有利于文学、艺术创作的繁荣，并未违反诚信原则和商业道德；从对著作权人、消费者、社会公众利益的影响看，\u003cstrong\u003e基础模型和 LoRA 模型训练、参考生图的技术本身具有中立性\u003c/strong\u003e，用户按照平台服务协议在尊重他人知识产权的前提下进行生成式人工智能创作，一般不会侵害著作权人合法权益，且新旧作品间影响力的此消彼长是\u003cstrong\u003e竞争的常态化结果\u003c/strong\u003e，并非对在先作品著作权人合法权益的实质性损害。故对不正当竞争的诉请\u003cstrong\u003e不予支持\u003c/strong\u003e。\u003c/p\u003e\n\u003ch2 id=\"裁判结果\"\u003e裁判结果\u003c/h2\u003e\n\u003cp\u003e一审判决被告停止侵害涉案奥特曼作品信息网络传播权的行为（包括但不限于立即删除已生成并发布的涉案奥特曼图片、奥特曼 LoRA 模型，停止提供相关奥特曼 LoRA 模型的发布和应用服务，并采取必要措施有效制止侵权行为等），赔偿原告经济损失及合理开支 3 万元。二审驳回上诉、维持原判。2025 年初该案入选 2024 年度中国十大传媒法事例；判决生效后，杭州互联网法院向被告发出\u003cstrong\u003e全国首份涉生成式人工智能司法建议书\u003c/strong\u003e，从完善「通知＋必要措施」机制、加强对 LoRA 模型的平台监管、强化平台知识产权日常管理、推进人工智能合规建设和行业自律四个层面提出改进建议。\u003c/p\u003e","title":"杭州互联网法院：AIGC平台LoRA模型训练著作权侵权案"},{"content":"案件名称与案号 上海新创华文化发展有限公司诉某 AI 公司侵害著作权纠纷案\n——生成式 AI 服务提供者著作权侵权第一案（业内通称「广互奥特曼案」）\n(2024)粤0192民初113号 ｜ 审理法院：广州互联网法院 ｜ 立案：2024-01-05 ｜ 开庭：2024-02-04 ｜ 判决：2024-02-08（简易程序；双方均未上诉，已生效）\n关键词 民事 / 著作权 / 生成式人工智能 / 复制权与改编权 / 服务提供者注意义务\n基本案情 圆谷制作株式会社系奥特曼系列作品著作权人，就奥特曼各系列形象均进行了著作权登记（赛罗、迪迦、捷德、戴拿、银河、欧布、罗布、梦比优斯、奈克赛斯、泰迦、盖亚、高斯、泽塔、特利迦等，登记号如「国作登字-2019-F-00700316」等）。2019 年 4 月 1 日起，圆谷制作株式会社与原告上海新创华文化发展有限公司签订《授权证明》及六份《补充授权证明》（签名、印章经日本公证员公证并由中国驻日使馆领事确认），将授权作品及其作品名称、角色名称、角色形象、标志符号、道具、场景等艺术形象和元素的复制权、信息网络传播权、改编权等，在中华人民共和国境内（不含港澳台）独占性授予原告，并授予独立维权权利。\n被告经营「Tab」网站，具有 AI 对话及 AI 生成绘画功能。AI 绘画系会员专属功能，每次生成图片消耗 3「算力」；会员充值后可获赠一定额度「算力」，用尽需另行充值。 2023 年 12 月下旬，原告发现：在 Tab 的 AI 绘画对话框输入「生成奥特曼」，即显示与涉案奥特曼形象一致的图片；输入「奥特曼拼接长发」，生成保留奥特曼形象特征且头部留有长发的图片；输入「生成插画风格的奥特曼」，生成保留奥特曼形象特征的插画风格图片，均可供用户查看和下载。原告认为被告未经授权利用其作品训练大模型并生成实质性相似图片，通过会员充值及「算力」购买攫取非法收益，起诉请求：停止生成侵权图片并从训练数据集中删除涉案奥特曼物料、赔偿经济损失及合理费用 30 万元。\n被告抗辩：(1) 收到送达材料时已停止原告主张的侵权行为；(2) 案涉网站的 AI 绘画功能通过第三方服务商实现，与被告无关，被告未训练大模型，被诉图片系原告主动生成；(3) AI 绘画为会员限免功能，「算力」系赠送，被告未实际收取费用；(4) 原告无证据证明 30 万元损失。\n法院审理与说理 庭审中法院向双方释明，本案案由变更为著作权侵权纠纷，原告明确主张复制权、改编权及信息网络传播权。\n（一）作品保护与权属。 涉案奥特曼形象作为具有独创性的美术作品依法受著作权保护（《著作权法》第 2 条第 2 款）；依据著作权登记证书及《授权证明》《补充授权证明》，原告在授权期限与范围内独占性享有涉案奥特曼形象系列美术作品的复制权、信息网络传播权、改编权等，并拥有独立维权权利。\n（二）被告是否属于「服务提供者」。 依《生成式人工智能服务管理暂行办法》第 22 条第 2 款，「生成式人工智能服务提供者」包括通过提供可编程接口等方式提供服务者。被告自陈通过可编程接口接入第三方服务商系统进而向用户提供服务，法院认定其属于生成式人工智能服务提供者，对其「服务由第三方提供、不应承担责任」的抗辩不予采纳。\n（三）侵权认定。 涉案奥特曼作品知名度高、可经各大视频网站访问查阅下载，在被告无相反证据的情况下，被告存在接触涉案作品的可能性。经比对：「图 1」至「图 3」保留了奥特曼美术形象的独创性表达（一条中线自水晶向下延伸至嘴部、椭圆蛋型对称双眼、上胸与中胸凸起底座并镶嵌指示灯、U 型护胸甲等），构成实质性相似，被告未经许可复制涉案作品，侵害复制权；「图 4」至「图 10」部分保留「迪迦奥特曼复合型」形象的独创性表达并在该基础上形成新特征，具有插画风格或与他人形象拼接，侵害改编权。关于信息网络传播权，法院认为复制权、改编权与信息网络传播权之争仅涉及具体著作权权利的认定，不影响侵权成立与否，在同一被诉行为已纳入复制权、改编权控制范畴的情况下，不再重复评价。\n（四）停止侵害。 依《暂行办法》第 14 条第 1 款，提供者发现违法内容应及时采取停止生成等处置措施。据生成式人工智能技术原理，不采取技术防范措施，Tab 仍能继续生成实质性相似的图片，故支持停止生成的诉请，被告应采取技术性措施。被告虽已采取关键词过滤并收到一定效果，但庭审中双方见证下输入「迪迦」等关键词仍可生成高度相似图片，故过滤防范程度应达到：用户正常使用与奥特曼相关的提示词，不能生成与案涉奥特曼作品实质性相似的图片。关于「将涉案奥特曼物料从训练数据集中删除」的诉请，因被告并未实际进行模型训练行为，不予支持。\n（五）赔偿与注意义务。 服务提供者应尽合理注意义务（《暂行办法》第 4 条），本案被告未尽，具体表现为三方面欠缺：其一，投诉举报机制欠缺（《暂行办法》第 15 条——截至开庭之日 Tab 网站未建立投诉举报机制，权利人难以通过该机制保护著作权）；其二，潜在风险提示欠缺（未以服务协议等方式提示用户不得侵害他人著作权，而生成式 AI 用户对潜在侵权风险缺乏明确认知，服务提供者有提示义务）；其三，显著标识欠缺（《暂行办法》第 12 条、《互联网信息服务深度合成管理规定》第 17 条——未对生成物作显著标识，标识义务既是对公众知情权的尊重，也是对权利人的保护性义务）。\n裁判结果 判令被告停止生成与案涉奥特曼作品实质性相似的图片（以关键词过滤等技术措施实现，防范程度如上），并赔偿原告经济损失及为制止侵权支出的合理费用共计 10 000 元（金额以公开转载判决文本与报道为准）。本案被业界公认为「全球 AIGC 平台侵权第一案」。\n数据法 / AI 法要点 ① 通过 API 接入第三方大模型的渠道方同样构成「生成式人工智能服务提供者」，不能以「技术由第三方提供」脱责；② 生成式 AI 场景下平台义务的三项清单化落地：投诉举报机制、风险提示、生成内容显著标识；③ 「不作为」的边界：未实际进行模型训练者，不承担「删除训练数据」责任，但须承担「停止生成」责任；④ 关键词过滤的达标标准被具体化为「正常提示词不能生成实质性相似内容」。\n相关法条 《生成式人工智能服务管理暂行办法》第 4 条、第 12 条、第 14 条、第 15 条、第 22 条第 2 款；《中华人民共和国著作权法》相关条款（详见上文说理）。\n权威来源 广州互联网法院 (2024)粤0192民初113号民事判决书（中英对照公开文本）；广州互联网法院官方通报；上海市第三中级人民法院官网「以案释法」引述。\n补充来源\n官方佐证（上海市第三中级人民法院官网「以案释法」引述本案案号、判决主文与三项注意义务）：上海三中院网站评述页 材料来源：广州互联网法院公开转载的 (2024)粤0192民初113号判决书全文（中英对照）；广州互联网法院官方通报；上海市第三中级人民法院官网「以案释法」\n站内关联法规 生成式人工智能服务管理暂行办法 ","permalink":"https://ai.intlaws.com/cases/china/gic-ai-ultraman/","summary":"\u003ch2 id=\"案件名称与案号\"\u003e案件名称与案号\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e上海新创华文化发展有限公司诉某 AI 公司侵害著作权纠纷案\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e——生成式 AI 服务提供者著作权侵权第一案（业内通称「广互奥特曼案」）\u003c/p\u003e\n\u003cp\u003e(2024)粤0192民初113号 ｜ \u003cstrong\u003e审理法院\u003c/strong\u003e：广州互联网法院 ｜ \u003cstrong\u003e立案\u003c/strong\u003e：2024-01-05 ｜ \u003cstrong\u003e开庭\u003c/strong\u003e：2024-02-04 ｜ \u003cstrong\u003e判决\u003c/strong\u003e：2024-02-08（简易程序；双方均未上诉，已生效）\u003c/p\u003e\n\u003ch2 id=\"关键词\"\u003e关键词\u003c/h2\u003e\n\u003cp\u003e民事 / 著作权 / 生成式人工智能 / 复制权与改编权 / 服务提供者注意义务\u003c/p\u003e\n\u003ch2 id=\"基本案情\"\u003e基本案情\u003c/h2\u003e\n\u003cp\u003e圆谷制作株式会社系奥特曼系列作品著作权人，就奥特曼各系列形象均进行了著作权登记（赛罗、迪迦、捷德、戴拿、银河、欧布、罗布、梦比优斯、奈克赛斯、泰迦、盖亚、高斯、泽塔、特利迦等，登记号如「国作登字-2019-F-00700316」等）。2019 年 4 月 1 日起，圆谷制作株式会社与原告上海新创华文化发展有限公司签订《授权证明》及六份《补充授权证明》（签名、印章经日本公证员公证并由中国驻日使馆领事确认），将授权作品及其作品名称、角色名称、角色形象、标志符号、道具、场景等艺术形象和元素的复制权、信息网络传播权、改编权等，在中华人民共和国境内（不含港澳台）\u003cstrong\u003e独占性\u003c/strong\u003e授予原告，并授予独立维权权利。\u003c/p\u003e\n\u003cp\u003e被告经营「Tab」网站，具有 AI 对话及 AI 生成绘画功能。\u003cstrong\u003eAI 绘画系会员专属功能，每次生成图片消耗 3「算力」；会员充值后可获赠一定额度「算力」，用尽需另行充值。\u003c/strong\u003e 2023 年 12 月下旬，原告发现：在 Tab 的 AI 绘画对话框输入「生成奥特曼」，即显示与涉案奥特曼形象一致的图片；输入「奥特曼拼接长发」，生成保留奥特曼形象特征且头部留有长发的图片；输入「生成插画风格的奥特曼」，生成保留奥特曼形象特征的插画风格图片，均可供用户查看和下载。原告认为被告未经授权利用其作品训练大模型并生成实质性相似图片，通过会员充值及「算力」购买攫取非法收益，起诉请求：停止生成侵权图片并从训练数据集中删除涉案奥特曼物料、赔偿经济损失及合理费用 30 万元。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e被告抗辩\u003c/strong\u003e：(1) 收到送达材料时已停止原告主张的侵权行为；(2) 案涉网站的 AI 绘画功能\u003cstrong\u003e通过第三方服务商实现\u003c/strong\u003e，与被告无关，被告未训练大模型，被诉图片系原告主动生成；(3) AI 绘画为会员限免功能，「算力」系赠送，被告未实际收取费用；(4) 原告无证据证明 30 万元损失。\u003c/p\u003e\n\u003ch2 id=\"法院审理与说理\"\u003e法院审理与说理\u003c/h2\u003e\n\u003cp\u003e庭审中法院向双方释明，本案案由变更为著作权侵权纠纷，原告明确主张复制权、改编权及信息网络传播权。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e（一）作品保护与权属。\u003c/strong\u003e 涉案奥特曼形象作为具有独创性的美术作品依法受著作权保护（《著作权法》第 2 条第 2 款）；依据著作权登记证书及《授权证明》《补充授权证明》，原告在授权期限与范围内独占性享有涉案奥特曼形象系列美术作品的复制权、信息网络传播权、改编权等，并拥有独立维权权利。\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e（二）被告是否属于「服务提供者」。\u003c/strong\u003e 依《生成式人工智能服务管理暂行办法》第 22 条第 2 款，「生成式人工智能服务提供者」包括通过提供可编程接口等方式提供服务者。被告自陈通过可编程接口接入第三方服务商系统进而向用户提供服务，\u003cstrong\u003e法院认定其属于生成式人工智能服务提供者\u003c/strong\u003e，对其「服务由第三方提供、不应承担责任」的抗辩\u003cstrong\u003e不予采纳\u003c/strong\u003e。\u003c/p\u003e","title":"广州互联网法院：生成式AI服务著作权侵权第一案（奥特曼案）"}]