Article 22—Article 22
>Control Description
Network products and services shall comply with the relevant national and mandatory requirements. Providers of network products and services must not install malicious programs; when discovering that their products and services have security flaws or vulnerabilities, they shall immediately adopt remedial measures, and follow provisions to promptly inform users and report to the competent departments.
Providers of network products and services shall provide security maintenance for their products and services, and they must not terminate the provision of security maintenance during the time limits or period agreed on with clients.
If a network product or service has the function of collecting user information, its provider shall clearly indicate this and obtain consent from the user; and if this involves a user’s personal information, the provider shall also comply with the provisions of this law and relevant laws and administrative regulations on the protection of personal information.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.