Affiliated enterprises bear joint liability for sharing use data without valid consent
When users register only one application but find that "clone" accounts appear on other applications (apps), and their data is automatically synchronized across platforms, does this constitute legitimate cross-platform service or an infringement of user's lawful rights and interests?
The Beijing Internet Court (BIC) recently concluded a case involving the infringement of personality rights arising from data sharing among affiliated apps. The BIC held that the app operators constituted infringement and should bear corresponding liability.
Case summary:
The case involves two defendants: an information company that operates apps A and B, and a technology company that operates app C. The two companies are affiliated enterprises. Apps B and C were derived from fixed functional modules of App A and the three apps were closely connected.
The plaintiff, surnamed Chai, discovered that during the registration and use of App B that accounts on apps A and C were automatically created in their name.
After using all three apps, a series of user data were generated, including nicknames, avatars, personal profiles, posts, followers and following lists, real-name verification information, and private messages.
Cai further found that any data generated through one app would synchronized across to the other two apps. Operations such as publishing, modifying or deleting a post would be also synchronized, and information originally displayed publicly any of them would be shown to users on the rest two.
The plaintiff claimed that, as a user, they had personal information right and privacy right over the user data in dispute. Citing Article 23 of the Personal Information Protection Law, which stipulates that a personal information processor shall obtain the individual's separate consent when providing personal information to any other processor, the plaintiff argued that the two defendants had infringed upon the plaintiff's lawful rights and interests. The plaintiff therefore filed a lawsuit with the BIC to request an apology and compensation.
In their defense, the two defendants argued that, in order to provide consistent services across different products, they jointly decided to operate the three apps under a "unified service platform system". They used the mobile phone number registered on App B to create a unified digital identity for the plaintiff on apps A and C, enabling cross-platform login and data sharing. This, they contended, constituted joint processing of personal information under Article 20 of the Personal Information Protection Law, for which separate consent was not required. They also claimed that the plaintiff had given informed consent through user agreements and privacy policies.
The court found that the two defendants had signed a contract specifying the purposes, methods, scope of data sharing, allocation of responsibilities, and data security measures under the unified service platform system. The three apps had notified users of certain aspects of data sharing through user agreements and privacy policies, and such notifications were generally consistent.
However, the notifications did not fully disclose all processors, nor clearly explain the types of personal information involved and the processing methods. In particular, the sharing of private messages among the three apps and the sharing of real-name verification information between apps A and C were neither effectively notified nor subject to the plaintiff's separate consent. Although a pop-up notice appeared to remind during the sharing of real-name verification information between apps A and B, users were not given the option to refuse.
In the process of collecting evidence, the plaintiff also incurred reasonable expenses.
Focus of dispute:
The key issues of in this case were: first, whether the plaintiff has rights to personal information and privacy regarding user data; second, the legal nature of the defendants' data-sharing conduct; third, whether such conduct infringed upon the plaintiff's rights to personal information and privacy; and fourth, what liability should be borne if infringement established.
First, the plaintiff has right to personal information regarding nicknames, avatars, personal profiles, posts, followers and following lists, real-name verification information, private messages, and other information capable of identifying the individual.
The plaintiff also has privacy rights to the data involving sensitive personal information, such as real-name verification information and private messages. However, no privacy rights applied to the data that had been voluntarily disclosed or left publicly visible, such as nicknames and interest list.
Second, since apps A and B were operated by the same entity, the sharing of user data between them raised no issue requiring determination of the nature of the act. In contrast, the data sharing between App C and the other two apps involved two distinct legal subjects, making it necessary to determine the legal nature of this conduct.
In this case, the two defendants formed a contract governing the sharing of the user data among the three apps, specifying the purposes, methods, scope of data sharing, and allocation of responsibilities. They also notified users with these provisions via user agreements and privacy policies within the apps. The contractual arrangements, user notifications, and the actual data processing activities were consistent with one another. Additionally, the two defendants were affiliated enterprises, and the three apps they operated were closely related in terms of content, demonstrating that the sharing of the user data among the three apps constituted an integrated processing activity. The defendants also expressly agreed on data security measures and adopted corresponding measures for data storage and management, which did not objectively and significantly increase the risk of infringement of users' personal information rights and interests.
Taking these factors into account, the court held that the two defendants, as the personal information processors, jointly determined the purposes and methods of processing the user data in dispute and agreed upon their, each other's rights and obligations. Their acts, therefore, constituted joint processing of personal information by multiple personal informatioin processors under Article 20 of the Personal Information Protection Law, rather the provision of personal information by one personal information processor to another under Article 23 of the law.
Third, the defendants shared the user data under accounts belonging to the plaintiff across the three apps. Because the accounts and the data-sharing activities directly corresponded to the plaintiff, such conduct did not constitute the collection or use of publicly disclosed personal information in the ordinary sense, nor did it fall within the circumstances of the reasonable processing of personal information that has been voluntarily disclosed by an individual. Accordingly, the defendants were not exempt from their statutory obligation to obtain the plaintiff's valid consents.
In this case, the user data involved different categories of personal information, meaning that different legal bases applied to the processing of different types of the personal information. The legality of the defendants' processing activities should be assessed based on the type of personal information involved. With respect to the processing of general personal information, like the nicknames, avatars, personal profiles, posts, followers and following lists, the defendants' joint processing did not require the plaintiff's separate consent, but it was still subject to the general requirements of informed consent.
Since the defendants' failure to offer a complete and comprehensive notification made the plaintiff's consent invalid, thereby infringing upon the plaintiff's personal information rights and interests Furthermore, according to the Personal Information Protection Law, the sensitive personal information, such as real-name verification information and private massages, should be processed with the plaintiff's separate consent, even in case of joint processing. As the defendants failed to obtain the plaintiff's separate consent, their conduct infringed upon the plaintiff's privacy right.
In conclusion, the plaintiff's claims requesting the two defendants to jointly issue an apology and compensate for losses were well-founded in law and should therefore be upheld.
Result of judgement
The court ordered the defendants to issue an apology and compensate the plaintiff for economic losses, and denied the plaintiff's other Claims.
Both the defendants and plaintiff appealed. The court of second instance dismissed both appeals and upheld the original judgement.
The ruling has now taken effect.
Opinion of judge
With the rapid development of digital economy, it has become increasingly common for internet enterprises to establish mechanisms such as the "unified service platform system" in this case to collect and utilize user data across different online products, such as websites, apps and mini-programs. Such data utilization models have improved service efficiency and enhanced the experience of users with strong content-sharing needs, but they may also cause user data to circulate across different product ecosystems without users' knowledge, expectation or explicit consent, thereby infringing upon users' legitimate rights and interests.
To regulate such data utilization, this court explored the issue in the case from three aspects.
First, it confirms that individuals enjoy lawful rights and interests, including privacy rights and personal information rights and interests, with respect to user data.
Second, with regard to personal information processing involving multiple entities, the court proposes that whether such processing constitutes joint processing of personal information under Article 20 of the Personal Information Protection Law should be comprehensively determined based on the comprehensively determined based on the contractual arrangements, user notifications, actual processing activities, and their impact on individuals' rights and interests. This provides a basis for examining the legality of specific processing activities and clarifying the allocation of liabilities among multiple processors.
Third, the case distinguishes different categories of personal information according to their different sensitivity, so as to determine the legality of the corresponding personal information processing.
Through these explorations, the court seeks to strike a balance between data circulation and the protection of personal information rights and interests, and offering internet enterprises with a guidance to legally utilize user data across different online platforms.
This case also reminds personal information processors that, under innovative forms of data utilization, such as the "unified service platform system", they should avoid the failure of the informed consent rules. The processors should carve into their minds that the adequate notifications and valid consent are the legal grounds for personal information processing, and establish a tiered consent mechanism, including general consent, explicit consent and separate consent, for processing personal information of different sensitivity levels.
The court also encourages personal information processors to improve the content and presentation of privacy policies and related notices, enhance users' control over sensitive personal information, and provide features such as a "one-click refusal to share" option, so as to maximize the value of data while minimizing risks to personal information and privacy.

Beijing Internet Court Lawsuit Service WeChat Account
Beijing Internet Court WeChat Account