The travel card has been removed, where did the personal information go?
[4] Compiled from: Red Star News
The travel card originated from the nationwide need to resume work and production in early 2020. After nearly three years, it finally retired at 0:00 on December 13. But how should the collected personal information be handled?
Case review
When the travel card was first launched in early 2020, regarding the personal information security issues involved, Han Xia, director of the Information and Communication Administration Bureau of the Ministry of Industry and Information Technology, stated at a press conference that the travel card does not collect users' ID numbers, home addresses, and other information, strictly adhering to privacy protection requirements.
Now, with the introduction of policies such as the "20 Measures for Optimizing Epidemic Prevention and Control" and the "10 New Measures for Epidemic Prevention and Control," epidemic prevention and control has gradually relaxed, making the travel card no longer necessary. On the evening of the 12th, after the travel card officially announced its shutdown, the three major telecom providers involved—China Unicom, China Telecom, and China Mobile—all stated that they would simultaneously delete user travel-related data to ensure the security of personal information in accordance with the law.
So, what laws and regulations lie behind this seemingly simple operation? And what rights and obligations do we, as the individuals whose information is collected, have?
《
[1] The People's Republic of China
Personal Information Protection Law
Article 44
An individual has the right to know and decide about the processing of their personal information, and has the right to restrict or refuse others from processing their personal information, except as otherwise provided by laws or administrative regulations.
Article 47
In any of the following circumstances, a personal information processor shall proactively delete personal information; if the processor fails to delete it, the individual has the right to request deletion:
(1) The purpose of processing has been achieved, cannot be achieved, or is no longer necessary for achieving the purpose;
(2) The personal information processor ceases to provide products or services, or the retention period has expired;
(3) The individual withdraws consent;
(4) The personal information processor violates laws, administrative regulations, or agreements in processing personal information;
(5) Other circumstances stipulated by laws or administrative regulations.
If the retention period stipulated by laws or administrative regulations has not expired, or if deleting personal information is technically difficult, the personal information processor shall cease processing other than storage and necessary security protection measures.
[1] The author's perspective
From Article 44 above, we know that we have the right to know and decide about our personal information. That is, whether it was collection in the past or deletion now, the three major telecom companies should respect our rights. In fact, every time we opened the travel code, a window would pop up requiring us to check a box to proceed. Although most people did not read the terms carefully before checking, this was essentially our approval for operators to collect personal information—an exercise of rights. Now, operators say they will delete personal information, but it is worth noting that in this process, citizens' rights such as the right to know must still be respected, rather than being glossed over with a simple "deleted."
Furthermore, it is not hard to see that in the regulatory process, government agencies are increasingly using big data and information technology. Since data is to be uniformly used and destroyed at the national level, detailed and unified implementation standards should be established. Clearly, existing standards are not specific enough, and many administrative agencies still collect information unconditionally through technical means without public consent, citing convenience for management—such as facial recognition data, nucleic acid test information, and vaccination records. If these actions are to be taken, they must have corresponding legal basis, rather than making people appear to hold real power while actually being forced to relinquish it.