The travel card has been removed, where did the personal information go?

📅 2022-12-13 📂 Zhiming Hot Comments Zhiming Hot Comments 🏷️ #PersonalInformationProtectionLaw #Privacy #COVID19 #HealthCode #TravelCard

[4] Compiled from: Red Star News
 
The itinerary card originated from the national demand for resuming work and production in early 2020. After nearly three years, the itinerary card finally retired at 0:00 on December 13. But how should the personal information that was collected be handled?

 
 

Case review
When the travel code was first introduced in early 2020, Han Xia, director of the Information and Communication Administration Bureau of the Ministry of Industry and Information Technology, stated at a press conference regarding the personal information security issues related to the travel card that the travel card does not collect users' ID card numbers, home addresses, or other such information, and strictly implements privacy protection requirements.


 

Recently, with the introduction of policies such as the “Twenty Measures for Optimizing Epidemic Prevention and Control” and the “Ten New Measures for Epidemic Prevention and Control,” epidemic prevention and control has gradually been relaxed, and the existence of the travel card is no longer necessary. On the evening of the 12th, after the travel card was “officially announced” to be taken offline, the three major telecom providers involved with the travel card—China Unicom, China Telecom, and China Mobile—all stated that they would simultaneously delete users’ travel-related data and protect personal information security in accordance with the law.
 
So, what laws and regulations lie behind this seemingly simple operation? And what rights and obligations do we, as the individuals whose information is collected, have?
 
 
The [1] The People's Republic of China Personal Information Protection Law
Article 44
An individual has the right to know and decide about the processing of their personal information, and has the right to restrict or refuse others from processing their personal information, except as otherwise provided by laws or administrative regulations.
 
Article 47
In any of the following circumstances, a personal information processor shall proactively delete personal information; if the processor fails to delete it, the individual has the right to request deletion:
(1) The purpose of processing has been achieved, cannot be achieved, or is no longer necessary for achieving the purpose;
(2) The personal information processor ceases to provide products or services, or the retention period has expired;
(3) The individual withdraws consent;
(4) The personal information processor violates laws, administrative regulations, or agreements in processing personal information;
(5) Other circumstances stipulated by laws or administrative regulations.
If the retention period stipulated by laws or administrative regulations has not expired, or if deleting personal information is technically difficult, the personal information processor shall cease processing other than storage and necessary security protection measures.

 
 

 
[1] The author's perspective
From the above Article 44, it can be seen that we have the right to know and the right to decide regarding our personal information. In other words, whether it is the collection of information at the time or the deletion of it now, the three major telecommunications companies should respect our rights. In fact, every time we opened the travel code in the past, a window would pop up requiring us to tick a box before proceeding to the next interface. Although most people ticked the box without carefully reading the terms, this was in fact our consent to the operators' collection of personal information and an exercise of our rights. Now, the operators say they will delete personal information, but it is worth noting that in this process, citizens' rights such as the right to know must still be respected, rather than being dismissed with a simple “it's deleted.”
 
Furthermore, it is not hard to see that in the regulatory process, government agencies are increasingly using big data and information technology. Since data is to be uniformly used and destroyed at the national level, detailed and unified implementation standards should be established. Clearly, existing standards are not specific enough, and many administrative agencies still collect information unconditionally through technical means without public consent, citing convenience for management—such as facial recognition data, nucleic acid test information, and vaccination records. If these actions are to be taken, they must have corresponding legal basis, rather than making people appear to hold real power while actually being forced to relinquish it.

⚖️ Start your journey to professional legal services today

📍 Address: Room 1802, Block A, Xintian Century Business Center, Shixia North 2nd Street, Futian District, Shenzhen

  • @ Email: zhiminglawfirm@126.com
  • WeChat ID: zhiminglawyer01
  • 💬 WeChat Official Account: gd_zhiming

Administrative Disputes · Marriage and Family Matters · Civil and Commercial Litigation · Criminal Defense - Free Online Consultation

Consultation QR Code

Scan to add consultation QR code

Law Firm Official Account

Scan to follow us

"WeChat Help"
微信二维码
"Press and hold on QR code"
"Add WeChat Inquiry"
×
微信二维码
"Press and hold on QR code"
"Add WeChat Inquiry"