CSL CSL International Cybersecurity Law 2 — Questions and Answers
Question 1: China's Cybersecurity Law (CSL) of 2017 requires operators of 'critical information infrastructure' to store data locally within China. This type of requirement is known as:
- Data sovereignty mandate
- Data localization requirement (Correct answer)
- Cross-border transfer prohibition
- Cybersecurity certification standard
Correct answer: Data localization requirement
Data localization requirements mandate that certain categories of data be stored and processed within national borders, affecting multinational companies' cloud strategies.
Question 2: The EU's NIS2 Directive (2022) replaced the original NIS Directive and expanded its scope. Which of the following is a key addition in NIS2?
- It only applies to critical infrastructure operators
- It imposes supply chain security requirements on essential and important entities (Correct answer)
- It eliminates member state discretion in implementation
- It only applies to companies with over 500 employees
Correct answer: It imposes supply chain security requirements on essential and important entities
NIS2 significantly expanded the original directive by adding supply chain security obligations, requiring entities to assess cybersecurity risks in their supplier relationships.
Question 3: What is the significance of the 'cyber equivalent of an armed attack' threshold under the UN Charter Article 51?
- All cyberattacks trigger Article 51 self-defense rights
- Only cyberattacks causing effects comparable to armed attacks may trigger self-defense rights (Correct answer)
- Article 51 does not apply to cyber operations
- The threshold is defined by the Budapest Convention
Correct answer: Only cyberattacks causing effects comparable to armed attacks may trigger self-defense rights
Most legal scholars agree that a cyber operation must produce effects comparable to a traditional armed attack (death, injury, or significant destruction) to trigger the right of self-defense under Article 51.
Question 4: Under the EU's GDPR, what obligation does the 'one-stop-shop' mechanism create for multinationals operating across EU member states?
- They must comply with every member state's data protection authority separately
- They deal primarily with the DPA of their EU main establishment (Correct answer)
- They can choose any member state's DPA as their sole supervisor
- The ECJ serves as the single supervisory authority
Correct answer: They deal primarily with the DPA of their EU main establishment
The one-stop-shop mechanism designates the DPA of the controller's main establishment as the lead supervisory authority for cross-border processing activities.
Question 5: Which international framework, updated in 2023, provides guidance on responsible state behavior in cyberspace as a non-binding norm?
- UN GGE (Group of Governmental Experts) framework (Correct answer)
- Budapest Convention protocols
- NATO cyber defense commitments
- WTO digital trade rules
Correct answer: UN GGE (Group of Governmental Experts) framework
The UN GGE process has produced consensus reports establishing non-binding norms for responsible state behavior in cyberspace, including the applicability of international law.
Question 6: A U.S. company's GDPR-compliant data processing agreement with a European vendor is voided by a change in EU law. Which legal principle describes this risk?
- Force majeure
- Regulatory risk / change in law risk (Correct answer)
- Breach of contract
- Frustration of purpose
Correct answer: Regulatory risk / change in law risk
Regulatory risk refers to the possibility that changes in applicable laws or regulations will render existing contractual arrangements non-compliant or void.
China's Cybersecurity Law (CSL) of 2017 requires operators of 'critical information infrastructure' to store data locally within China.
This type of requirement is known as: