The first batch involves 16000 stores, and Shanghai has launched legal education training on personal information protection in the catering industry
In response to the illegal and irregular behavior of excessive collection, frequent inducement, and even forced solicitation of unnecessary personal information by catering establishments discovered in the "Bright Sword Pujiang · Consumer Personal Information Rights Protection Special Law Enforcement Action", the Shanghai Cyberspace Administration, in conjunction with the Municipal Market Supervision Bureau, Municipal Commission of Commerce and other departments, has recently launched a legal education training on personal information protection in the catering industry.
It is reported that this legal education training will be carried out in batches, focusing on promoting catering enterprises to continuously enhance their awareness of personal information protection and actively fulfill their personal information protection obligations through legal education, supervision and rectification, and compliance guidance.
On July 4th, the first personal information protection legal education training class was held, attended by more than 80 responsible persons of chain catering enterprises under the Shanghai Catering and Culinary Association, including Haidilao, Guimanlong, Damile, Dian Dude, and Xicha, involving more than 16000 catering stores.
In the training class, the Shanghai Cyberspace Administration analyzed the common illegal and irregular behaviors of catering enterprises in the personal information collection process through case interpretation based on the problem clues and typical cases found in the previous investigation, and provided guidance for enterprises to carry out self inspection and rectification. The Municipal Market Supervision Bureau, Municipal Commission of Commerce and other departments are required to conscientiously implement laws and regulations such as the Personal Information Protection Law and the Consumer Rights and Interests Protection Law, and require catering enterprises to follow the principles of legality, legitimacy, necessity, and integrity. The collection of personal information must be limited to the minimum scope of catering business and excessive collection is not allowed.
The Shanghai Cyberspace Administration emphasizes that all catering enterprises should conduct self-examination and rectification in the personal information collection process based on the "Self inspection Checklist for Common Personal Information Protection Issues in the Catering Industry's Scan Code Ordering", comparing the following 8 types of problems, and effectively fulfill their personal information protection obligations:
1. When consumers first use the QR code ordering service, they scan the QR code and then jump to the mini program page to order, but the mini program does not inform consumers of their privacy policy through prominent means such as pop ups.
2. Although the mini program informs consumers of privacy policies through pop ups and other means, it only has the option to agree and no options to reject or disagree; Alternatively, privacy policies can be selected by default on ordering, logging in, and other pages, allowing consumers to provide personal information to catering enterprises by default.
3. During the process of ordering at the store or on the checkout page, the mini program requires or induces consumers to fill in personal information unrelated to catering services, and no obvious prompts are non mandatory items.
4. After the consumer scans the code to place an order, the mini program will display pop-up prompts such as "One click login on WeChat" to obtain a nickname and profile picture, "One click login on WeChat phone number" to obtain a phone number, or request the consumer to provide a phone number when making an order. If the consumer refuses the above authorization, they will not be able to place an order.
5. After the consumer scans the code and places an order, the mini program applies for location permission to obtain accurate location information on the grounds of facilitating the consumer's selection of nearby stores. If the consumer refuses, they will not be able to select a store to complete the order.
6. After the consumer scans the code and places an order, the mini program applies for accurate location information. However, after the consumer refuses, they still frequently pop up windows to apply for location information, and the consumer cannot use the store search function normally.
7. After the consumer scanned the code and ordered the order, the applet induced the consumer to authorize personal information such as accurate location information or mobile phone number in the name of optimizing the service experience, providing member discounts, or induced the consumer to pay attention to the enterprise official account. After the consumer refused, pop-up applications still appeared repeatedly on the page, affecting the normal use of consumers.
8. Without consumer consent or anonymization, businesses provide consumer personal information to third parties for use, and consumers frequently receive targeted advertising and marketing messages; Or qualitatively push advertising and marketing information to consumers, but do not provide options for unsubscribing or rejecting.
It is reported that the Shanghai Cyberspace Administration will also work with relevant departments to develop and issue compliance guidelines for personal information protection in the catering industry, guiding catering enterprises to establish and improve long-term mechanisms for personal information protection. At the same time, the organization will conduct a "look back" inspection of the rectification situation of key catering enterprises. For individual catering enterprises that repeatedly refuse to improve, fail to rectify, and have serious problems, they will be registered in accordance with the law, strictly investigated and dealt with, and typical cases will be exposed to the media.
It is understood that in order to curb the chaos related to personal information protection and respond to the concerns of netizens, on June 16th, the Shanghai Cyberspace Administration and the Municipal Market Supervision Bureau jointly launched the "Bright Sword Pujiang · Special Law Enforcement Action for Personal Information Rights and Interests Protection in the Consumer Field". This action lasts for six months and adopts various means to punish illegal behaviors that infringe on consumer personal information rights and interests, promote enterprises to actively fulfill their personal information protection obligations, enhance the awareness of personal information protection in the whole society, and strive to significantly improve the current situation of personal information protection in the consumer field.