Data Security Law of the People's Republic of China 09/08/2022, 06:44 with, a sound data security management system throughout the whole process shall be established, data security education and training shall be organized and conducted, and corresponding technical measures and other necessary measures shall be adopted to ensure data security. In data processing by making use of the internet or any other information networks, the abovementioned data security obligations shall be fulfilled on the basis of the classified protection system for cyber security. Processors of important data shall be clear about their persons responsible for data security and the data security management bodies, and fulfill the responsibilities for data security. Article 28 Data processing as well as research and development of new data technologies shall be conducive to furthering economic and social development, and improving the well-being of people, and shall conform to social morals and ethics. Article 29 Closer risk monitoring shall be applied in data processing. Where data security defects, bugs, or other risks are discovered, remedial measures shall be taken immediately. Where a data security incident occurs, measures shall be taken immediately to address it, and users shall be notified and reports made to relevant competent departments in a timely manner in accordance with relevant provisions. Article 30 Processors of important data shall, in accordance with the relevant provisions, conduct risk assessments of their data processing on a regular basis and submit risk assessment reports to relevant competent departments. Risk assessment reports shall include the types and amounts of important data processed, information on data processing, data security risks and the response measures for them. Article 31 The provisions of the Cyber Security Law of the People’s Republic of China shall apply to the outbound security management of the important data collected or produced by critical information infrastructure operators during their operation within the territory of the People’s Republic of China, and the measures for the outbound security management of the important data collected or produced by others data processors during their operation within the territory of the People’s Republic of China shall be formulated by the national cyberspace authority in conjunction with the relevant departments under the State Council. http://www.npc.gov.cn/englishnpc/c23934/202112/1abd8829788946ecab270e469b13c39c.shtml Page 7 of 13

Select target paragraph3