The Ministry of Industry and Information Technology (MIIT) has issued a directive reinforcing data security safeguards for clients of Internet Data Centers (IDCs). The directive mandates that IDC service providers must clearly outline data security responsibilities in contractual agreements, establish robust data security management systems and customer oversight mechanisms, and devise security policies and procedural frameworks for data handling. Furthermore, they must implement protective measures such as data isolation. Prior to executing high-risk operations or disclosing customer data, clients must be duly informed and grant their consent. The directive also underscores the importance of bolstering business continuity and stability by developing emergency response plans and conducting regular drills. In the event of a data security breach attributed to the IDC service provider, immediate emergency measures must be initiated, customers must be promptly notified, and the relevant telecommunication authority must be informed.
