e-Commerce Laws in China and Hong Kong:
Integration or Separation?


Internet Security

The Internet security usually concerns two areas including encryption and state security. Both sellers and buyers of a commercial transaction seek security as assurance that both the goods and the payment are real. In addition, both parties demand secure and private transmissions as an assurance that confidential information will not fall into wrong hands. Encryption is considered an important element of the infrastructure for e-Commerce and exchange. However, the emergence of strong encryption products has alerted many governments to public safety and national security risk. China and Hong Kong have adopted different approaches in this area.

China

Encryption Legislation (Kennedy, 2000)
While most countries opt for export controls on encryption only, China has imposed domestic regulation of encryption by bringing the supply and use of encryption products under an authorization scheme. In October 1999, the State Council issued the Commercial Use Cryptography Management Regulations and they were implemented since November 8, 1999. The regulations applied to developers of encryption and require the registration of all individuals and companies selling, buying and using encryption products in China. As written, the regulations require that all encryption products must obtain approval from the State Encryption Management Commission (SEMC) prior to importation. Once sold to a registered user, the transfer of encryption product is prohibited. Foreign entities or individuals also must obtain SEMC approval to use encryption products must be placed on file with SEMC. Violators may be subject to penalties, which range from the confiscation of encryption products to fines of between one and three times the amount of the illegal income derived. Divulging commercial encryption-technology secrets, attempting to break commercial encryption codes, and using encryption to jeopardize state security, among other offenses, are considered criminal acts and thus may be subject to penalties stated in the PRC Criminal Law. Afterwards, SEMC has made some clarifications on the criteria of encryption products. The regulations apply to:
  • Hardware or software for which encryption and decoding operations are core functions.
  • DES (Data Encryption Standard) and RSA (Rivest-Shamir-Adelman) encryption technology, regardless of strength.
The regulations do not apply to:
  • Password-protected devices such as PIN numbers or log-on passwords.
  • Encryption used as an ancillary function for mobile handsets, MS software, browser software and other similar applications.
  • Ordinary office-use software with encryption capability installed into the laptops of business travelers

Next