← Back to LIANY filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Information regarding risk factors appears in Part I, Item 1A, Risk Factors, in the Company’s Annual Report on Form 10-K for the year ended December 31, 2022. The Company has reviewed the risk factors, and, except as presented below, there have been no material changes in the Company’s risk factors since those reported in its Annual Report on Form 10-K for the year ended December 31, 2022, its Quarterly Report on Form 10-Q for the quarter ended March 31, 2023 and its Quarterly Report on Form 10-Q for the quarter ended June 30, 2023.
We cannot assure you that the strategic review initiated by our Board of Directors will result in any transactions or other strategic changes or outcomes; and there may be negative impacts on our business and the price of our ADSs as a result of this strategic review.
In October 2023, we announced that our Board of Directors has initiated a comprehensive strategic review of the Company. The Board of Directors expects to provide an update on the strategic review in the first half of 2024. There can be no assurance that the strategic review process will result in any transactions or any other strategic changes or outcomes, or as to the timing of any of the foregoing. Whether the process will result in any transactions, and our ability to complete any such transactions, will depend on numerous factors, some of which are beyond our control, including the interest of potential acquirers or strategic partners in a potential transaction, the value potential acquirers or strategic partners attribute to our business, market conditions, interest rates and industry trends. The price of our ADSs may be adversely affected if the strategic review does not result in any transactions or any other strategic changes or outcomes, or if one or more transactions are consummated on terms that investors view as unfavorable to us. Even if one or more transactions are completed, there can be no assurance that any such transactions will be successful or have a positive effect on the value of our ADSs. In addition, our financial results and operations could be adversely affected by the strategic review process and by the uncertainty regarding its outcome. The attention of management and our Board of Directors could be diverted from our core business operations, and we may divert capital and other resources to the process that otherwise could have been used in our business operations. We could incur substantial expenses associated with identifying and evaluating potential strategic alternatives, including those related to equity compensation, severance pay and legal, accounting and financial advisor fees.
In addition, the process could lead us to lose or fail to attract, retain and motivate key employees or to lose or fail to attract business partners. Furthermore, in the past, securities litigation has often followed certain significant business transactions, such as the sale of a company or announcement of any other strategic transaction. We may be exposed to such litigation even if no wrongdoing occurred. Litigation is usually expensive and diverts management’s attention and resources, which could adversely affect our business and cash resources and our ability to consummate a potential transaction or the ultimate value to of a transaction.to our shareholders and holders of our ADSs.
In addition, speculation regarding any developments related to the strategic review and perceived uncertainties related to the future of the Company could cause the price of our ADSs to fluctuate significantly.
Compliance with the Data Security Law of the People’s Republic of China (the “Data Security Law”), Cybersecurity Review Measures, Personal Information Protection Law of the People’s Republic of China (the “PIPL”), the regulations and guidelines relating to the multi-level protection scheme (the “MLPS”) and any other future laws and regulations may entail significant expenses and could materially affect our business. Our failure to comply with such laws and regulations could lead to government enforcement actions and significant penalties against us, materially and adversely impacting our operating results.
34
Table of Contents
China has implemented extensive data protection, privacy and information security rules and is considering a number of additional proposals relating to these subject areas. Based on our understanding of these laws, regulations and policies, some of which were only recently enacted, and the government regulators’ interpretation of those legal requirements as applied to biopharmaceutical companies like us, we believe we are compliant with all of our material legal obligations. Nevertheless, we face significant uncertainties and risks which, as explained below, may materially and adversely affect our operations.
General risks surrounding the types of data we process and types of processing activities in which we engage
We do not maintain, nor do we intend to maintain in the future, personally identifiable health information of patients in China. We do, however, collect and maintain de-identified or anonymized health data for clinical trials in compliance with local regulations. This data could be deemed by government regulators to be “personal information,” “important data,” or “core data.” Under the Cyber Security Law of the People’s Republic of China (the “Cyber Security Law”) and the Data Security Law, data categorized as core data or important data, the latter of which will be determined by governmental authorities in the form of catalogs which have not been published, is to be processed and handled with a higher level of protection, but what data constitutes core data or important data is currently not clearly defined except for certain industry sections. Therefore, in order to comply with the statutory requirements, we will need to determine whether we possess core data or important data, monitor the important data catalogs that are expected to be published by local governments and industry regulators, perform risk assessments and comply with reporting obligations to applicable regulators. We may also be required to disclose to regulators business-sensitive or network security-sensitive details regarding our processing of core data or important data.
With China’s growing emphasis on its sovereignty over data derived from China, the outbound transmission of de-identified or anonymized health data for clinical trials may be subject to the new national security legal regime, including the Cyber Security Law, Data Security Law, the PIPL, the HGR Regulations and various implementing regulations and standards. Due to operational needs, we may from time to time transfer and store personal data and information outside of China in the future. Therefore, we will need to comply with the increasingly strict regulations over cross-border data transfers and monitor any new rules or regulations published by local governments and industry regulators.
Cybersecurity
The Cyber Security Law, which became effective in 2017, requires companies to take certain organizational, technical and administrative measures and other necessary measures to ensure the security of their networks and data stored on their networks. Specifically, the Cyber Security Law provides that companies adopt an MLPS, under which network operators are required to perform obligations of security protection to ensure that their networks are free from interference, disruption or unauthorized access, and prevent network data on their networks from being disclosed, stolen or tampered. Under the MLPS, entities’ operating information systems must have a thorough assessment of the risks and the conditions of their information and network systems to determine the level to which the entity’s information and network systems belong, from the lowest Level 1 to the highest Level 5 pursuant to a series of national standards on the grading and implementation of the classified protection of cyber security. The grading result will determine the set of security protection obligations that entities must comply with. Entities classified as Level 2 or above should report the grade to the relevant government authority for examination and approval.
Under the Cyber Security Law and Data Security Law, we are required to establish and maintain a comprehensive data and network security management system that will enable us to monitor and respond appropriately to data security and network security risks. We will need to classify and take appropriate measures to address risks created by our data processing activities and use of networks. We are obligated to notify affected individuals and appropriate Chinese regulators of and respond to any data security and network security incidents.
Establishing and maintaining such systems and complying with such requirements takes substantial time, effort, and cost, and we may not be able to establish and maintain such systems or comply with such requirements as fully as needed for compliance with our legal obligations. Despite our investment, such systems and compliance efforts may not adequately protect us or enable us to appropriately respond to or mitigate all data compliance risks or data security and network security risks or incidents we face.
Cybersecurity review
35
Table of Contents
Following the Draft Data Security Management Regulations, the Cybersecurity Review Measures, which came into effect on February 15, 2022, confirmed that critical information infrastructure operators procuring network products and services and online platform operators carrying out data processing activities, which affect or may affect national security, are required to conduct a cybersecurity review pursuant to the provisions therein. In addition, online platform operators possessing personal information of more than one million users seeking to be listed on foreign stock markets must apply for a cybersecurity review.
Pursuant to the Draft Data Security Management Regulations, data processors seeking to list on foreign stock markets shall assess their data security themselves or through data security service organizations annually, and submit the assessment reports to relevant competent authorities.
We have not received any notice from any Chinese regulatory authority identifying us as a “critical information infrastructure operator” or “online platform operator” or requiring us to go through cybersecurity review procedures by the CAC pursuant to the Cybersecurity Review Measures. Based on our understanding of the Cybersecurity Review Measures and the Draft Data Security Management Regulations, if enacted as currently proposed, we do not expect ourselves to become subject to cybersecurity review by the CAC for issuing securities to foreign investors because: (i) the clinical and preclinical data we handle in our business operations, either by its nature or in scale, do not normally trigger significant concerns over Mainland China’s national security; and (ii) we have not processed, and do not anticipate to process in the foreseeable future, personal information of more than one million users or individuals. However, there remains uncertainty as to how the Cybersecurity Review Measures and the Draft Data Security Management Regulations, if enacted as currently proposed, will be interpreted or implemented and whether Chinese regulatory authorities may adopt new laws, regulations, rules, or detailed implementation and interpretation in relation, or in addition, to the Cybersecurity Review Measures and the proposed Draft Data Security Management Regulations. While we intend to closely monitor the evolving laws and regulations in this area and take all reasonable measures to mitigate compliance risks, we cannot guarantee that our business and operations will not be adversely affected by the potential impact of the Cybersecurity Review Measures, the Draft Data Security Management Regulations, if enacted, or other laws and regulations related to privacy, data protection and information security.
It is also unclear at the present time how widespread the cybersecurity review requirement and the enforcement action will be and what effect they will have on the life sciences sector generally and the Company in particular. Mainland China’s regulators may impose penalties for non-compliance ranging from fines to suspension of operations, and this could lead to us delisting from the U.S. stock market. Currently, we have not been involved in any investigations on cybersecurity review initiated by the CAC or related governmental regulatory authorities, and we have not received any inquiry, notice, warning, or sanction in such respect.
Cross-border data transfer requirements (security assessment; certification; standard contract)
China continues to strengthen its regulation of cross-border transfers out of Mainland China of data, including important data and personal information.
The requirement for some data processors to store personal information or important data in China, unless certain legally recognized protective measures are undertaken, was first introduced in 2017 under the Cyber Security Law, but is now solidified through the publication of the PIPL and the Security Assessment Measures. The PIPL requires that personal information processors processing certain quantities of personal information in accordance with relevant laws and regulations and need to transfer such information out of Mainland China to pass a security assessment organized by Chinese cyberspace regulators, and all other personal information processors that are not required to pass the security assessment and need to transfer out of Mainland China personal information to either: (i) undergo certification by specialized certification agencies in accordance with relevant regulations, (ii) conclude a standard contract designated by China cyberspace regulators with the overseas recipient of the personal information, or (iii) satisfy other conditions contemplated by laws, administrative regulations or Chinese cyberspace regulators. In addition to the above, personal information processors that need to transfer out of Mainland China personal information shall conduct a privacy impact assessment.
36
Table of Contents
Notably, the PIPL provides for significant fines for serious violations of up to RMB 50 million, or 5% of annual revenues from the prior year and violators may also be ordered to suspend any related activity by competent authorities. We do not maintain, nor do we intend to maintain in the future, personally identifiable health information of patients in China. We do, however, collect and maintain de-identified or pseudonymized health data for clinical trials in compliance with local regulations. This data could be deemed as personal data or important data. We may transfer and store personal data and information that whistleblowers provide through our whistleblower hotline to, in, and using centralized databases and systems located in the United States, Mainland China, and Hong Kong. In addition, we have engaged a third-party data processor to process the personal data and information that such whistleblowers provide, on our behalf. Such personal data and information will be stored in one or more databases located on servers hosted and operated by the third party, in the United States.
To implement the security assessment mechanisms for cross-border transfers out of China of data under the Cyber Security Law, the Data Security Law, and the PIPL, the CAC promulgated the Security Assessment Measures, which took effect on September 1, 2022, and published the Security Assessment Guide on August 31, 2022. Under the Security Assessment Measures, a mandatory security assessment is required for data transfers out of Mainland China under any of the following circumstances: (i) transfer of important data by data processors; (ii) transfer of personal information by critical information infrastructure operators and data processors that process personal information of more than one million individuals; (iii) transfer of personal information by data processors that have transferred either personal information of over 100,000 individuals or sensitive personal information of over 10,000 individuals abroad since January 1 of the preceding year; and (iv) other situations as determined by the CAC. The Security Assessment Measures have retroactive effect for relevant cross-border data transfers out of Mainland China conducted prior to September 1, 2022, and data processors are required to undergo mandatory security assessment for such prior relevant cross-border data transfers by February 28, 2023. We do not believe, based on our understanding of the Security Assessment Measures that our transfers of data out of Mainland China currently or in the past require us to undergo a mandatory security assessment under the Security Assessment Measures, but we may in the foreseeable future conduct cross-border data transfers of data that require us to undergo a mandatory security assessment under the Security Assessment Measures for such transfers.
To implement the standard contract mechanism for cross-border transfers out of China of personal information under the PIPL, on February 24, 2023, the CAC published the PRC Standard Contract, which came into effect on June 1, 2023. After this came into effect, personal information processors may conclude a PRC Standard Contract with overseas recipients of personal information to comply with PIPL requirements for cross-border transfers out of Mainland China of personal information that do not need to undergo a security assessment.
To implement the personal information protection certification mechanism for cross-border transfers out of China of personal information under the PIPL, on November 4, 2022, the CAC and SAMR jointly issued the Notification on the Implementation of Personal Information Protection Certification. In parallel, on December 16, 2022, the National Information Security Standardization Technical Committee released an updated version of the Certification Specification which provides the general principles and detailed requirements for personal information processors engaging in the cross-border transfer out of Mainland China of personal information to meet in order to obtain a personal information protection certification from qualified certification institutions for cross-border transfers out of China of personal information governed by the PIPL.
Transferring data to foreign law enforcement agencies or judicial authorities
The Data Security Law and PIPL prohibit entities in Mainland China from transferring data (including personal information) stored in Mainland China to foreign law enforcement agencies or judicial authorities without prior approval by the Chinese government. We may need to pass a government security review or obtain government approval in order to share data (including personal information) stored in Mainland China with judicial and law enforcement authorities outside of Mainland China. Therefore, if judicial and law enforcement authorities outside Mainland China require us to provide data stored in Mainland China, and we are not able to pass any required government security review or obtain any required government approval to do so, we may not be able to meet the foreign authorities’ requirements. The potential conflicts in legal obligations could have adverse impacts on our operations in and outside of Mainland China. Recently, the CAC has taken action against several Chinese internet companies listed on U.S. securities exchanges for alleged national security risks and improper collection and use of the personal information of Chinese data subjects. According to the official announcement, the action was initiated based on the National Security Law of the People’s Republic of China (the “National Security Law”), the Cyber Security Law and the Cybersecurity Review Measures, which are aimed at “preventing national data security risks, maintaining national security and safeguarding public interests.”
Industry and local regulations
37
Table of Contents
In addition, certain industry-specific laws and regulations affect the collection and transfer of personal data in Mainland China. For example, the HGR Regulation prohibits both onshore and offshore entities established or actually controlled by foreign entities and individuals from collecting or biobanking any China-Sourced HGR in China, as well as providing such China-Sourced HGR outside of China. Chinese parties are required to seek an advance approval for the collection and biobanking of all China-Sourced HGR. Approval for any export or cross-border transfer of China-Sourced HGR in the form of biospecimens is required, and transfer of derived data by Chinese parties to foreign parties or entities established or actually controlled by them also requires the Chinese parties to file, before the transfer, a copy of the data with the Human Genetic Resources Administration of China (the “HGRAC”) for record purposes and to obtain a notification filing number in order to transfer the data. The HGR Regulation also requires that foreign parties or entities established or actually controlled by them ensure the full participation of Chinese parties in international collaborations and share all records and data with the Chinese parties.
To further tighten the control of China-Sourced HGR, the SCNPC issued the Eleventh Amendment to the Criminal Law of the People’s Republic of China on December 26, 2020, which became effective on March 1, 2021, criminalizing the illegal collection of China-Sourced HGR and the illegal transfer of China-sourced biospecimens outside of Mainland China. An individual who is convicted of any of these violations may be subject to public surveillance, criminal detention, a fixed-term imprisonment of up to seven years and/or a criminal fine. In October 2020, the SCNPC adopted the Biosecurity Law, which became effective on April 15, 2021. The Biosecurity Law will establish an integrated system to regulate biosecurity-related activities in Mainland China, including, among others, the security regulation of HGR and biological resources. The Biosecurity Law for the first time expressly declared that Mainland China has sovereignty over its HGR, and further endorsed the HGR Regulation by recognizing the fundamental regulatory principles and systems established by it over the utilization of China-Sourced HGR by foreign parties or entities established or actually controlled by them in Mainland China. Though the Biosecurity Law does not provide any specific new regulatory requirements on HGR, as it is a law adopted by Mainland China’s highest legislative authority, it gives Mainland China’s primary regulator of HGR, the MOST, significantly more power and discretion to regulate HGR and it is expected that the overall regulatory landscape for China-Sourced HGR will evolve and become even more rigorous and sophisticated. In addition, the interpretation and application of data protection laws in Mainland China and elsewhere are often uncertain and in flux. In May 2023, the Ministry of Science and Technology, or MOST, published the Implementing Rules of the HGR Regulation (the “HGR Implementing Rules”) which came into effect in July 2023. The HGR Implementing Rules have, among other things, provided operational details and clarified questions that have emerged in the past few years, such as further clarified the scope of China-Sourced HGR, improved the procedure rules for applicable approval, filing and security review, and refined the provisions with respect to the prohibition on the collection, preservation and export of China-Sourced HGR by foreign organizations, individuals, and the entities established or actually controlled by foreign organizations or individuals. Under the HGR Implementing Rules, clinical studies conducted for the purpose of obtaining marketing authorization for drugs and medical devices in China, if not involving the export of human genetic materials, will be eligible for a notification filing (instead of the advance approval) if the human genetic materials are collected by sites, and processed by sites or an onshore third-party specified in the clinical trial protocol. The HGR Implementing Rules also enumerate situations where a security review is required for external provision of or open access to of human genetic data, such as external provision of or open access to human genetic data about important genetic pedigrees, human genetic data from specific regions, and exome sequencing and genome sequencing information of over 500 individuals.
So far, the HGRAC has disclosed a number of HGR violation cases. In one case, the sanctioned party was the Chinese subsidiary of a multinational pharmaceutical company that was found to have illegally transferred certain biospecimens to CROs for conducting certain unapproved research. In addition to a written warning and confiscation of relevant human genetic materials, the Chinese subsidiary of the multinational pharmaceutical company was requested by the HGRAC to take rectification measures and was also banned by the HGRAC from submitting any clinical trial applications until the HGRAC was satisfied with the rectification results, which rendered it unable to initiate new clinical trials in Mainland China until the ban was lifted. In another case, the CRO engaged by the Chinese subsidiary of a multinational pharmaceutical company was found to have forged an ethics committee approval in order to accelerate the HGRAC approval. Both the Chinese subsidiary of the multi-national pharmaceutical company and the CRO were debarred from initiating new applications for a period of 6 to 12 months, respectively.
Uncertainties about our compliance with the changing legal landscape despite our best efforts
38
Table of Contents
Interpretation, application and enforcement of these laws, rules and regulations evolve from time to time and their scope may continually change, through new legislation, amendments to existing legislation or changes in enforcement. Compliance with the Cyber Security Law, the Data Security Law, the PIPL and other related laws and regulations could significantly increase the cost to us of providing our products, require significant changes to our operations or even prevent us from providing certain products in jurisdictions in which we currently operate or in which we may operate in the future. Despite our efforts to comply with applicable laws, regulations and other obligations relating to privacy, data protection and information security, it is possible that our practices, products or platform could fail to meet all of the requirements imposed on us by the Cyber Security Law, the Data Security Law, the PIPL and/or related laws and regulations. Any failure on our part to comply with such laws or regulations or any other obligations relating to privacy, data protection or information security, or any compromise of security that results in unauthorized access, use or release of personally identifiable information or other data, or the perception or allegation that any of the foregoing types of failure or compromise has occurred, could damage our reputation, discourage new and existing counterparties from contracting with us or result in investigations, fines, suspension or other penalties by Chinese government authorities and private claims or litigation, any of which could materially adversely affect our business, financial condition and results of operations. If the Chinese parties fail to comply with data protection, data privacy and cybersecurity laws, regulations and practice standards, and our research data is obtained by unauthorized persons, used or disclosed inappropriately or destroyed, we may lose our confidential information and be subject to litigation and government enforcement actions. It is possible that these laws and regulations may be interpreted and applied in a manner that is inconsistent with our or our collaborators’ practices, potentially resulting in suspension of relevant ongoing clinical trials or delays in the initiation of new trials, delays in sharing or an inability to share or receive clinical trial data with or from our collaborators, confiscation of China-Sourced HGR, administrative fines, disgorgement of illegal gains, or temporary or permanent debarment of our or our collaborators’ entities and responsible persons from further clinical trials and, consequently, a de-facto ban on the debarred entities from initiating new clinical trials in Mainland China. In addition, a data breach affecting personal information, including health information, or a failure to comply with applicable requirements could result in significant management resources, legal and financial exposure and reputational damage that could potentially have a material adverse effect on our business and results of operations. Even if our practices are not subject to legal challenge, the perception of privacy concerns, whether or not valid, may harm our reputation and brand and adversely affect our business, financial condition and results of operations. Moreover, the legal uncertainty created by the Data Security Law, the PIPL, the Cyber Security Law, the Cybersecurity Review Measures and the recent Chinese government actions could materially adversely affect our ability, on favorable terms, to raise capital in the U.S. market in the future.
The national security legal regime imposes stricter data localization requirements on personal information and human health-related data and requires us to undergo cybersecurity or other security review and assessments, obtain government approval or certification, implement technical and organizational measures for data privacy and protection, conduct privacy impact assessments, or put in place certain contractual protections before transferring personal information and human health-related data out of Mainland China. As a result, personal information, important data and health and medical data that we or our customers, vendors, clinical trial sites, pharmaceutical partners and other third parties collect, generate or process in Mainland China may be subject to such data localization requirements and heightened regulatory oversight and controls. We may need to maintain local data centers in Mainland China, enter into standard contracts with the overseas recipients of any personal information processed by us, conduct privacy impact assessments, undergo security assessments, or obtain the requisite approvals from the Chinese government for the transmission outside of Mainland China of such controlled information and data, which could significantly increase our operating costs or cause delays or disruptions in our business operations in and outside Mainland China. We expect that the evolving regulatory interpretation and enforcement of the national security legal regime will lead to increased operational and compliance costs and will require us to continually monitor and, where necessary, make changes to our operations, policies, and procedures. If our operations, or the operations of our CROs, licensees or partners, are found to be in violation of these requirements, we may suffer loss of use of data, suffer a delay in obtaining regulatory approval for our products, be unable to transfer data out of Mainland China, be unable to comply with our contractual requirements, suffer reputational harm, or be subject to penalties, including administrative, civil and criminal penalties, damages, fines, and the curtailment or restructuring of our operations. If any of these were to occur, it could materially adversely affect our ability to operate our business and our financial results.