As advised by our PRC Legal Advisor, during the Track Record Period and up to the Latest Practicable Date, we had complied with the applicable PRC laws and regulations relating to data privacy and security in all material respects.
Business · 第 155 页
During the Track Record Period and up to the Latest Practicable Date, we did not receive any notice or determination from a competent regulatory authority identifying us as a critical information infrastructure operator, and we were not an operator of critical information infrastructure under the Regulation for Safe Protection of Critical Information Infrastructure.
Business · 第 155 页
In the ordinary course of our business, we generally do not access or collect personal information or data of end users located in any country or region through our products or services.
During the Track Record Period and as of the Latest Practicable Date, we had not experienced any material data or personal information leakage or loss, infringement of data or personal information, or information security incident, we had not been subject to any investigation, inspection or penalty from the PRC authorities or any other relevant regulatory bodies in relation to violation of cybersecurity, data security and personal data protection laws and regulations.
Business · 第 174 页
Based on the foregoing, we and our PRC Legal Advisors are of the view that both the Company’s existing products, services and solutions, and their data privacy features as mentioned above comply with data privacy and cybersecurity laws in the PRC effectively in all material respects.
广东微电新能源股份有限公司Guangdong Mic-Power New Energy Co., Ltd.
网络安全及数据合规确认
As advised by the Company’s PRC Legal Advisor and based on the measures the Company has been taking described above, the Company had complied with applicable laws and regulations relating to cybersecurity, data privacy and protection and cross-border data transmission in all material respects during the Track Record Period and up to the Latest Practicable Date.
We have not been, and are not, subject to any review by the Cyberspace Administration of China, and the [REDACTED] does not fall within the circumstances requiring a mandatory application for cybersecurity review under the Cybersecurity Review Measures
Business · 第 167 页
During the Track Record Period and as of the Latest Practicable Date, our legal advisors of all relevant jurisdictions and our Directors are of the view, and the Sole Sponsor concurs, that we had complied with applicable laws and regulations relating to data security and data protection in all material aspects and have not received any penalty due to breach of data privacy.
According to our PRC Legal Advisor as to data compliance, while our business processes involve cross-border data transfers, our Company is not a processor of personal information, in such cross-border data transfer scenarios but merely a trustee thereof, and is not the subject obligated to perform the aforesaid obligations under the law.
Risk Factors · 第 38 页
According to our PRC Legal Advisor as to data compliance and our telephone consultations with the China Cybersecurity Review, Certification And Market Regulation Big Data Center, enterprises seeking listing in Hong Kong are not required to take the initiative to apply for a cybersecurity review solely by reason of its listing in Hong Kong per se, as Hong Kong is a part of the PRC and does not belong to the “foreign country” as stipulated in the Review Measures.
During the Track Record Period and up to the Latest Practicable Date, the outbound transfer of patient-level data sets from the United States to China only involved personal health data of fewer than 300 U.S. persons—far below the 10,000 U.S. persons threshold for bulk U.S. sensitive personal health data under the NSD Final Rule.
Business · 第 207 页
Based on the above, our PRC Legal Advisor and the legal advisor to Salubris Bio are of the view that we had complied with the applicable laws and regulations in relation to cross-border data transfer between Chinese Mainland and the United States.
The data submitted to the FDA mainly consisted of CSRs, with only a very limited amount of de-identified individual safety data, and the relevant transfer was completed in January 2022, when the relevant PRC laws had only recently come into effect and the detailed implementation rules for cross-border data transfer were not yet clear, and there were no clear and specific enforceable provisions in practice regarding the specific compliance pathways and procedures for cross-border data transfer, as the detailed implementation rules and regulatory guidance had not yet been developed or clarified at the relevant time.
Business · 第 169 页
The Company has ceased such transfer after completion of the FDA submission and will comply with the applicable PRC requirements for any future cross-border data transfer.
Our PRC Legal Advisor is of the view that we have been in compliance with the relevant PRC laws and regulations relating to cybersecurity and data protection in all material aspects during the Track Record Period and up to the Latest Practicable Date.
Business · 第 209 页
Our PRC Counsel is of the view that we are not required to apply for cybersecurity review for the purpose of the Listing.
Risk Factors · 第 77 页
As of the Latest Practicable Date, we had not been notified of being classified as a critical information infrastructure operator (CIIO), we had not received any inquiry, notice, warning from any PRC government authorities, and have not been subject to any investigation, sanctions or penalties made by any PRC government authorities regarding national security risks caused by our business operations or the Listing.
Our PRC Legal Advisor is of the view that the contact information collected by us does not fall under the scope of personal sensitive information based on the basis that such information is limited to the names, positions, and professional contact details (such as mobile numbers and email addresses) of the contact persons of our business partners, which are voluntarily provided by them through emails or contract execution for the sole purpose of business coordination.
Business · 第 194 页
As advised by our PRC Legal Advisor, we are not subject to a mandatory cybersecurity review by the Cyberspace Administration of China (the “CAC”), based on the basis that we are not a critical information infrastructure operator and that our [REDACTED] in Hong Kong does not constitute a “[REDACTED] in a foreign country” as defined under the Measures for Cybersecurity Review.
Given that we only make transactions with enterprises, our business generally does not involve the collection or processing of customers' personal information.
宁波舜宇智行科技股份有限公司Ningbo Sunny Smart Autotech Company Limited
非关键信息基础设施运营者,数据处理合规
Our PRC legal advisor is of the view that we have, in all material respects, complied with the applicable PRC laws and regulations with respect to data privacy and cybersecurity during the Track Record Period and up to the Latest Practicable Date, on the basis that: (i) as confirmed by us and verified by our PRC legal advisor, we are not a critical information infrastructure operator, and all of our business data is stored domestically; (ii) we do not process personal information in the ordinary course of our business operations or important data, nor do we engage in any cross-border data transfer; (iii) in respect of cybersecurity and data security management, we have established a organizational structure, institutional framework, technical safeguards and personnel management measures as set forth above, classified all of our information systems as Level 1, and implemented protection measures; (iv) the algorithms and artificial intelligence technologies used internally by us are not subject to the regulations governing algorithmic recommendations, deep synthesis or generative artificial intelligence services; (v) the [REDACTED] does not require a proactive filing for cybersecurity review; and (vi) we have not been involved in any litigation or penalties relating to data compliance during the Track Record Period and up to the Latest Practicable Date.
Business · 第 164 页
Based on the suite of internal control measures in respect of cyber security and data security as follows, our PRC Legal Advisor is of the view that (i) the users are deemed to have given their consent to the Group to the processing of the submitted personal information for the purpose of product feedback collection, and (ii) our data processing activities during the Track Record Period were in compliance with applicable PRC laws and regulations governing data protection and cybersecurity.
广西玉柴船电动力股份有限公司Guangxi Yuchai Marine and Genset Power Co., Ltd.
数据及个人信息保护符合中国法律
During the Track Record Period and up to the Latest Practicable Date, our data and privacy protection complied with PRC cybersecurity and PIPL regulations.
Our legal advisor as to data compliance law of the PRC, Allbright Law Offices, is of the view that, during the Track Record Period and up to the Latest Practicable Date, we had complied with all applicable laws and regulations concerning data privacy, cybersecurity and data security in the PRC during the Track Record Period and up to the Latest Practicable Date in view that we had not incurred any administrative penalties related to data security, cybersecurity and data privacy.
our PRC Legal Advisor is of the view that, during the Track Record Period and up to the Latest Practicable Date, (i) we have implemented compliance measures concerning cybersecurity, data protection and personal information protection in accordance with the requirements of relevant cybersecurity, data and personal information protection laws and regulations in all material aspects and (ii) has complied with the relevant data protection and privacy, and cybersecurity regulations in all material aspects.
Business · 第 174 页
During the Track Record Period and up to the Latest Practicable Date, (i) we had not received any claim from any third party against us on the ground of infringement of any third party’s right to data and privacy protection as provided by any applicable laws and regulations, (ii) there had been no investigation or other legal proceeding pending or threatened against us initiated by competent government authorities or third parties with respect to cybersecurity, data and personal information protection, and (iii) we had not experienced material leakage of personal information in relation to laws and regulations of cybersecurity, data protection and personal information protection.
During the Track Record Period and up to the Latest Practicable Date, according to our PRC Legal Advisors, German Legal Advisors and Thai Legal Advisors, we are in compliance with applicable data privacy and security laws in the relevant jurisdictions in all material respects, and according to our U.S. Legal Advisors, based on our representations of facts, we were not found to be subject to any penalties or legal proceedings for violation or non-compliance with the applicable data privacy and security laws in the relevant states where we operate.
Business · 第 166 页
We store the data collected and generated in the course of business operations locally and in cloud located in the jurisdictions where the data is generated without transferring data to other jurisdictions from the PRC.
杭州糖吉医疗科技股份有限公司HANGZHOU TANGJI MEDICAL TECHNOLOGY CO., LTD.
数据合规经中国法律顾问确认
Our PRC Legal Advisors have confirmed that, during the Track Record Period and up to the Latest Practicable Date, we had been in compliance with the relevant PRC laws and regulations in all material aspects in this regard.
Business · 第 213 页
These materials do not contain any personal information or important data, and thus do not trigger cross-border data export regulatory procedures.
During the Track Record Period and up to the Latest Practicable Date, we had complied with all applicable laws and regulations on data privacy and security in all material respects, and our PRC Legal Adviser is of the view that during the Track Record Period and up to the Latest Practicable Date, we had complied with applicable PRC laws and regulations in relation to cross border data transfer in all material respects.
Our PRC Legal Adviser is of the view that we have complied in all material respects with applicable PRC data security and personal information protection laws and regulations during the Track Record Period and up to the Latest Practicable Date, and that there has been no unlawful use of personal information.
Business · 第 198 页
As advised by our PRC Legal Adviser, we had not been subject to any claims, lawsuits, penalties or administrative actions relating to cross-border clinical data transfer activities during the Track Record Period and up to the Latest Practicable Date.
Based on the advice of our legal advisors, we had complied with applicable data privacy and cybersecurity laws and regulations in all material respects during the Track Record Period and up to the Latest Practicable Date.
Business · 第 133 页
Regarding cybersecurity, the main information systems used by us have completed Class-3 Filing for Cyber-security Classified Protection.
Business · 第 132 页
During the Track Record Period, we did not experience any material data security incident or material non-compliance in relation to cross-border transfers of personal data.