Data dump: China sees surge in personal information up for sale

    SHANGHAI (Reuters) – When William Zhang’s automotive insurance coverage was about to run out in March, he didn’t have to look far for renewal choices. Within the two months earlier than the coverage was up Zhang acquired calls nearly every day from insurers attempting to promote him a brand new one.

    FILE PHOTO: A person appears to be like at a telephone in the course of the third annual World Web Convention in Wuzhen city of Jiaxing, Zhejiang province, China November 17, 2016. REUTERS/Aly Tune/File Picture

    Since his preliminary coverage was from Ping An Insurance coverage Group (601318.SS), it was pure the corporate had been in contact.

    “What confuses me is how different insurance coverage firms knew about it,” stated Zhang, a 26-year-old authorities worker from Shandong. Three different automotive homeowners advised Reuters that they’d skilled the identical drawback.

    Private knowledge has turn out to be broadly accessible in China and could be scooped up for pennies by insurance coverage firms, banks, mortgage sharks, and scammers alike, in response to sellers and financiers interviewed by Reuters.

    In Could, China launched its most complete knowledge safety legal guidelines to this point, tightening restrictions on the sharing of personal knowledge held by monetary establishments and different corporations.

    “Private info leaks are dangerous,” stated Susan Ning, a associate on the legislation agency King & Wooden Mallesons in Beijing. “Such info can facilitate different crimes,” she added.


    Insurers typically purchase numbers from shadowy on-line knowledge sellers, who themselves have acquired the data illegally, in response to folks within the business.

    Some firms illegally purchase info from the division of motor autos, automotive licensing authorities, automotive sellers, or from police stations, stated Michelle Hu, a associate at Boston Consulting Group who has been a advisor on insurance coverage offers.

    By getting into key phrases like “private knowledge” or “cellphone knowledge”, in Chinese language, Reuters discovered greater than 30 teams created for the aim of promoting and shopping for private info on Tencent’s (0700.HK) instantaneous messaging service QQ and Baidu Inc’s (BIDU.O) discussion board website Tieba.

    Baidu declined to remark. In a press release emailed to Reuters, Tencent stated it was “dedicated to the safety of consumer privateness and sustaining knowledge safety”.

    Info sellers publish advertisements within the on-line teams and negotiate with patrons by means of non-public messages on QQ or WeChat.

    5 sellers supplied to promote Reuters lists from monetary establishments of “individuals who want loans”, “individuals who want insurance coverage”, and “Shanghainese males aged between 30 to 50”.

    The worth of such info assorted amongst sellers, starting from 300 yuan ($43.64) to 2,800 yuan for 100,000 folks.

    A pattern listing included people’ beginning dates, automotive and residential possession standing, and mortgage info, along with names and phone numbers.

    Reuters was unable to confirm the authenticity of the data.

    Three mortgage brokers who promote mortgages for 3 main Chinese language lenders stated buyer info was typically offered by financial institution workers.

    Some web firms additionally present entry to delicate private info for a price, in response to Reuters’ communications with two such platforms.

    Duoku Know-how, a Wuhan-based agency, for instance, operates a private info search platform.

    For five yuan, Duoku returns the ID image of any Chinese language citizen whose identify and ID quantity are offered. For three yuan, the positioning returns knowledge about an individual’s cellphone utilization.

    Reuters verified that each companies labored. The particular person whose ID image was requested didn’t understand how the companies obtained his photograph or phone payments.

    When requested the place Duoku collected or bought the data, a spokeswoman at Duoku Know-how who recognized herself as Ms. Li, stated a lot of the information was purchased from on-line retailers and offered to banks and insurance coverage firms.

    “Monetary establishments use our service for threat administration functions solely,” she stated.

    Hours after Reuters first printed the story Duoku Know-how emailed to say their web site has eliminated the merchandise set out above and in future is not going to be promoting to people.


    Knowledge privateness has additionally turn out to be a serious concern all over the world, with firms like Fb criticized for harvesting and promoting customers’ private knowledge with out their specific consent. On-line scammers are additionally frequent in different international locations.

    In China, a proliferation of on-line monetary platforms and customers has led to a surge within the sharing of private knowledge, regardless of legislative efforts to guard customers lately, consultants say.

    Beneath present legal guidelines, private info sellers can withstand seven years in jail and a nice, whereas shopping for private knowledge could be punished by fines and as much as three years in jail. Companies are topic to related authorized punishments.

    Regardless of such censure, round 90 p.c of telephone scams stem from private info breaches, in response to a Union Pay report in Could.

    “Central to this drawback is the excessive financial advantages related to private info commerce and the low prices of violating related legal guidelines,” stated Ning.

    “For some people with authorization, others’ private info is only a few clicks away.”

    Different causes behind private knowledge breaches embody a scarcity of safety measures on some web sites, and ambiguous phrases in sure contracts relating to the usage of private info, stated Ning.

    “China has a big inhabitants and knowledge privateness instances cowl a broad vary, so it may be fairly tough to analyze,” Ning stated.

    New tips for firms on dealing with private knowledge have been issued by regulators in Could that included the hiring of compliance officers and getting specific consent from customers when amassing private info.

    The European Union’s new guidelines on privateness safety – the Normal Knowledge Safety Regulation – took impact the identical month.

    The EU laws – which can impression Chinese language corporations whose services or products are offered within the European Union – seems to be extra restrictive than the Chinese language ones. The Chinese language tips permits for silent or implied consent, for instance, whereas the European guidelines don’t.

    Reporting by Engen Tham and Shanghai newsroom; Further reporting by Shu Zhang in Beijing; Modifying by Philip McClellan

    Recent Articles

    Q&A: Workplace exec on employee productivity, app plans for 2021

    Facebook hopes to make it simpler to get work finished inside Workplace by way of new productiveness options — some natively constructed, others from...

    CES 2021 wrap up: How enterprise tech makes all those smart toilets and robots possible

    From sensible bathrooms and disinfecting robots to clear OLED shows and sleep tech, CES 2021 was...

    Galaxy reality check: 4 big reasons to avoid Samsung’s Android phones

    The greatest story within the Android universe this week is the pending arrival of Samsung's newest and biggest Galaxy flagships — the Galaxy S21...

    Related Stories

    Stay on op - Ge the daily news in your inbox