As advised by our PRC Legal Advisor, we are not required to file a data export security assessment, enter into a standard personal information export contract, or obtain personal information protection certification for our existing data export scenarios.
Business · 第 174 页
As advised by our PRC Legal Advisor, we are not obligated to proactively file for a cybersecurity review.
As our business primarily serves enterprise customers, we also do not collect any personal data.
Business · 第 170 页
In our business operations, we may collect and retain limited contact information for business purposes after obtaining the prior consent of customers, suppliers and other business partners, and such collection and retention are in compliance with applicable data privacy and cybersecurity laws and regulations.
The Alaya NeW AI computing operations management platform, has successfully obtained certification under the national Multi-Level Protection Scheme (MLPS) Level 3 (國家《信息系統安全等級保護3級》) for information system security.
Over the same period, we are of the view that we have complied in all material respects with applicable data protection and privacy, cybersecurity and cross-border data transfer laws and regulations in regions and countries where we operate.
Our PRC Legal Advisor is of the view that, the cybersecurity-related laws and regulations have no material impact on our business operation, and we had been in compliance with the relevant laws and regulations in the PRC in respect of cybersecurity, data privacy and protection in all material respects.
We do not believe these requirements apply to us, as we are not a critical information infrastructure operator and our proposed [REDACTED] in Hong Kong does not constitute a ‘‘listing abroad’’ within the meaning of the Measures.
Risk Factors · 第 48 页
Such personal information is necessary for the normal conduct of our business operations, and the total volume of personal information transferred out of the PRC is relatively small (not exceeding 10,000 individuals) and does not involve any sensitive personal information.
Our PRC Legal Advisor is of the view that, during the Track Record Period and up to the Latest Practicable Date, we had complied with the data privacy and security-related and cyber security-related laws and regulations in the PRC, based on (i) to the best of our knowledge, we have not been subject to any complaint, legal proceeding or administrative penalty or investigation relating to relevant laws and regulations, (ii) we have implemented internal measures with the purpose of ensuring data and cyber security and ensuring compliance with relevant laws and regulations, and (iii) during the Track Record Period and up to the Latest Practicable Date, we did not experience any material data leakage or data loss.
Business · 第 172 页
We do not transfer any personal information or important data (if any) collected or generated during the ordinary course of our business in China to locations outside mainland China, and therefore do not trigger any prior approval requirements for cross-border data transfer under relevant PRC laws and regulations.
Our PRC Legal Advisor is of the view that, during the Track Record Period, we had complied with the applicable laws and regulations in effect in material respects, based on: (i) we have not received any complaint relating to data privacy or security measures; (ii) we have implemented internal policies, with the purpose of ensuring data and information security and ensuring compliance with applicable laws and regulations; (iii) during the Track Record Period, there had been no material incident of data or personal information leakage; (iv) during the Track Record Period, there had been no litigation, claims or administrative penalty relating to the violation of relevant network security, data security and personal information protection laws or regulations, to our best knowledge, pending or threatened against us initiated by competent government authorities or third parties; and (v) we will continue to pay close attention to the regulatory developments in data security and comply with the latest regulatory requirements.
Business · 第 171 页
Our Directors are of the view that we are able to comply with the relevant cybersecurity laws and regulations in all material aspects.
According to our PRC Legal Advisor, during the Track Record Period and up to the Latest Practicable Date, in the course of our business development and operations, we do not involve in engaging in business activities or data processing activities that affect or may affect national security, nor do we involve in providing personal information to overseas; therefore, we are not involved in the circumstances where cybersecurity and data security reviews and assessments are required under the cybersecurity and data security related laws and regulations such as the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Measures for Cybersecurity Review, the Measures for Data Export Security Assessment, and the Provisions on Promoting and Regulating the Cross-border Flow of Data.
Business · 第 150 页
During the Track Record Period and up to the Latest Practicable Date, according to our PRC Legal Advisor, Singapore Legal Advisor, Bangladesh Legal Advisor, UAE Legal Advisor, Ethiopia Legal Advisor, India Legal Advisor, and our Local Legal Advisor as to Hong Kong Law, we had complied with relevant data security and privacy, cybersecurity, cross-border data transfer and personal information protection laws and regulations in all material aspects.
Up to the Latest Practicable Date, our PRC Data Compliance Counsel is of the view that we are in compliance with all material respects with applicable laws and regulations relating to data, privacy protection, cross-border data transfer and cybersecurity.
Business · 第 160 页
Our PRC Data Compliance Counsel is of the view that, during the Track Record Period and up to the Latest Practicable Date, we have not been subject to cybersecurity reviews by relevant regulatory authorities, nor have we received any inquiries, notices, warnings or sanctions related to cybersecurity reviews.
our PRC Legal Advisors as to data compliance is of the view, and our Directors concur, that we have complied with the relevant laws and regulations on cybersecurity and data security and privacy in all jurisdictions where we operated during the Track Record Period and up to the Latest Practicable Date.
With respect to outbound transfers of personal information from Chinese Mainland, pursuant to the Provisions on Promoting and Regulating Cross-Border Data Flows, such transfers satisfied the applicable exemption conditions and were therefore not required to undergo (1) a security assessment for outbound data transfers, (2) the filing of standard contracts for the outbound transfer of personal information, or (3) certification for the outbound transfer of personal information.
Business · 第 148 页
We are subject to, and have implemented measures to comply with, evolving laws and regulations relating to data security and privacy, including the Cybersecurity Law of China, the Data Security Law of China and the Personal Information Protection Law of China.
Our PRC Legal Advisor is of the view that we have been in compliance with the relevant PRC laws and regulations relating to cybersecurity and data protection in all material aspects during the Track Record Period and up to the Latest Practicable Date.
All data generated and collected in PRC is retained locally at the originating entity in PRC, which maintains ownership and control over the data, and there was no cross-border transfer or transmission of such data.
Business · 第 178 页
Accordingly, our PRC Data Compliance Advisor, Hankun Data, is of the view that our Group is in compliance with the applicable laws and regulations in respect of data security and privacy in China in all material aspects.
In addition, our PRC Legal Adviser is of the view that (i) our Company was not subject to any material risk in relation to cybersecurity and data compliance, including any material non-compliance with applicable laws and regulatory requirements relating to cybersecurity, data security or personal information protection that would render its business operations unsustainable and incapable of rectification; (ii) our business operations did not rely on any serious violation of applicable laws involving the unlawful collection, use, provision to third parties or cross-border transfer of data; and (iii) we were, in all material respects, in compliance with applicable PRC laws and regulations relating to cybersecurity, data security and personal information protection.
彤程新材料集团股份有限公司Red Avenue New Materials Group Co., Ltd.09607.HK
网络安全及数据保护合规确认
We do not otherwise process, disclose or transfer such personal information to any third parties or involve in any cross-border transfer of personal or material business data.
Business · 第 155 页
Based on the above, as advised by our PRC Legal Adviser, we had been in compliance with relevant PRC laws and regulations concerning cybersecurity, data privacy and data protection during the Track Record Period and Latest Practicable Date.
As advised by our Data Privacy Legal Advisor, after conducting verification under applicable PRC laws and regulations relating to cybersecurity, data security and personal information protection, including the PRC Cybersecurity Law, the PRC Data Security Law and the PRC Personal Information Protection Law, we had, in all material respects, complied with the relevant data privacy and security laws and regulations during the Track Record Period and up to the Latest Practicable Date.
深圳四方精创资讯股份有限公司Shenzhen Forms Syntron Information Co., Ltd.06700.HK
网络安全审查不适用及数据合规确认
Moreover, we have not been designated as a Critical Information Infrastructure Operator, and we have not received notice from relevant regulatory authorities indicating that: (i) the services we provide, as well as our data processing activities, affect or may affect national security; (ii) we are required to undergo a cybersecurity review; or (iii) we process core data or important data.
Business · 第 152 页
Based on the above, our PRC Legal Advisors are of the view that, during the Track Record Period and up to the Latest Practicable Date, we have established internal control management systems for network security, data security and personal information protection, and have taken corresponding compliance measures, and we have satisfied the requirements of the PRC Cybersecurity Law, Data Security Law, and Personal Information Protection Law in all material respects.
As advised by our PRC Legal Advisor and local counsel in Thailand, U.S. and Hong Kong, based on their due diligence, we had been in compliance with such laws and regulations of these respective jurisdictions in all material aspects during the Track Record Period and up to the Latest Practicable Date.
As advised by our PRC Legal Advisor, based on the foregoing and the relevant regulatory framework, during the Track Record Period and up to the Latest Practicable Date, we have complied with applicable PRC laws and regulations in all material respects in relation to cybersecurity, data security and personal information protection, and no material non-compliance has been identified.
Business · 第 179 页
We are not involved in cross-border transmission of important data or sensitive personal information, and the volume of general personal information transmitted overseas does not exceed the regulatory thresholds under PRC laws and regulations for completing outbound administrative regulatory procedures.