SecProbe.io

Filing text and metadata
Intelligence Terminal Search Topics Monthly Activity About

Correspondence 0001104659-23-104648 from Qfin Holdings, Inc. (QFIN)

Qfin Holdings, Inc.
Date: Sept. 28, 2023 · CIK: 0001741530 · Accession: 0001104659-23-104648

AI Filing Summary & Sentiment

Sentiment
Urgency
Document Type
Confidence
SEC Posture
Company Posture

Summary

Reasoning

File numbers found in text: 001-38752

Referenced dates: September 18, 2023

Date
September 28, 2023
Author
Not clearly detected
Form
CORRESP
Company
Qfin Holdings, Inc.

Letter

VIA EDGAR Division of Corporation Finance Office of Finance Securities and Exchange Commission Re: Qifu Technology, Inc. (the “Company”) Form 20-F for the Year Ended 2022 Filed April 27, 2023 File No. 001-38752

Dear Ms. Empie, Mr. Henderson, Mr. Mew, Mr. McNamara, Ms. Block and Mr. Stickel:

This letter sets forth the Company’s response to the comment contained in the letter dated September 18, 2023 from the staff (the “Staff”) of the Securities and Exchange Commission (the “Commission”) regarding the Company’s Form 20-F for the fiscal year ended December 31, 2022 filed with the Commission on April 27, 2023 (the “2022 Form 20-F”). The Staff’s comment is repeated below in bold and is followed by the Company’s response thereto. All capitalized terms used but not defined in this letter shall have the meaning ascribed to such terms in the 2022 Form 20-F.

Qifu Technology, Inc.

September 28,

Page 2

Form 20-F for the Year Ended 2022

Introduction, page 1

1. In future filings, please revise your definition of “China” or “PRC” to remove the exclusion of Hong Kong and Macau from this definition. The definition may clarify that the only time that “China” or the “PRC” does not include Hong Kong or Macau is when you are referencing specific laws and regulations adopted by the PRC. If it does, please revise your disclosure to discuss any commensurate laws or regulations in Hong Kong, if applicable, and any risks and consequences to the company associated with those regulations. Please also disclose in the definition section that the same legal and operational risks associated with operations in China may also apply to operations in Hong Kong. Please confirm your understanding and include your proposed disclosure in your response letter.

In response to the Staff’s comment, the Company respectfully proposes to revise the referenced disclosure as follows (page reference is made to the 2022 Form 20-F to illustrate the approximate location of the disclosure) in its future Form 20-F filings (with deletions shown as strike-through and additions underlined), subject to updates and adjustments to be made in connection with any material development of the subject matter being disclosed:

Page 1

● “China” or “the PRC” is to the People’s Republic of China. Unless otherwise indicated, the policies, laws, regulations and interpretations adopted by the government of mainland China, which are specifically referenced in this annual report, are not applicable to Hong Kong, Macau or Taiwan, excluding, for the purposes of this annual report only, Taiwan and the special administrative regions of Hong Kong and Macau, except where the context otherwise requires;

In response to the Staff’s comment on legal and operational risks associated with operations in China and whether those risks also apply to any operations in Hong Kong, the Company respectfully advises the Staff that as of the date of the 2022 Form 20-F, its operations in Hong Kong were immaterial to the Company’s overall business operation pursuant to U.S. federal securities laws. The Company’s subsidiary in Hong Kong, namely HK Qirui, primarily serves the interim holding function for holding shares in the Company’s consolidated operating entities in mainland China, and, to a lesser extent, provides certain IT and consulting services. Therefore, the Company believes it is not required to disclose the relevant laws, regulations, or associated risks in Hong Kong in the 2022 Form 20-F. The Staff’s comment is duly noted. To the extent that the Company’s operations in Hong Kong becomes material in the future, the Company undertakes to include the relevant disclosure in its future Form 20-F filings.

Qifu Technology, Inc.

September 28,

Page 3

Risk Factors

Our business is subject to complex and evolving PRC laws regarding data privacy and cybersecurity, page 25

2. In light of recent events indicating greater oversight by the Cyberspace Administration of China (CAC) over data security, particularly for companies seeking to list on a foreign exchange, in future filings, please revise your disclosure to explain how this oversight impacts your business and to what extent you believe that you are compliant with the regulations or policies that have been issued by the CAC to date. Please provide us your proposed disclosure in your response letter.

In response to the Staff’s comment, the Company respectfully proposes to revise the referenced disclosure as follows (page reference is made to the 2022 Form 20-F to illustrate the approximate location of the disclosure) in its future Form 20-F filings (with deletions shown as strike-through and additions underlined), subject to updates and adjustments to be made in connection with any material development of the subject matter being disclosed:

Pages 25-29

Our business is subject to complex and evolving PRC laws and regulations regarding data privacy and cybersecurity, as such regulations and laws as newly promulgated, many of which are subject to furtherchange and uncertain interpretation. Any changes in these laws and regulations have caused and could continue to cause changes to our business practices and increase costs of operations, and any security breaches or our actual or perceived failure to comply with such laws and regulations could result in claims, penalties, damages to our reputation and brand, declines in user growth or engagement, or otherwise harm our business, results of operations and financial condition.

Our platform collects, stores and processes certain personal information and other sensitive data from users for the purpose of providing our services, such as name, identity number and phone number. We have obtained the explicit consents from users to use their personal information within the scope of authorization and we have taken technical measures to protect the security of such personal information and prevent personal information from being divulged, damaged or lost. However, we face risks inherent in handling and protecting personal informationdata. In particular, we face a number of challenges relating to data generated from transactions and other activities on our platform, including:

· protecting the data in and hosted on our system, including against attacks on our system by outside parties or fraudulent behavior or improper use by our employees;

· addressing concerns related to privacy and sharing, safety, security and other factors; and

· complying with applicable laws, rules and regulations relating to the collection, use, storage, transfer, disclosure and security of personal information, which are subject to change and new interpretations, including any requests from regulatory and government authorities relating to such data.

In general, we expect that data security and data protection compliance will receive greater attention and focus from regulators, both domestically and globally, as well as continued or greater public scrutiny and attention going forward, which could increase our compliance costs and subject us to heightened risks and challenges associated with data security and protection. If we are unable to manage these risks, or if we are accused of failing to comply with such laws and regulations, we could become subject to corrective orders, penalties, including fines, suspension of business, websites, or applications, and revocation of required licenses, and our reputation and results of operations could be materially and adversely affected.

Qifu Technology, Inc.

September 28,

Page 4

Recently, regulatory authorities in China have enhanced data protection and cybersecurity regulatory requirements, as such regulations and laws as newly promulgated, many of which are subject to furtherchange and uncertain interpretation. These laws continue to develop, and the PRC government may adopt further rules, restrictions and clarifications in the future. Moreover, different PRC regulatory bodies, including the Standing Committee of the National People’s Congress, or the SCNPC, the MIIT, the CAC, the Ministry of Public Security, or the MPS and the State Administration for Market Regulation, or the SAMR, have enforced data privacy and protections laws and regulations with varying standards and applications. See “Item 4. Information on the Company—B. Business Overview—Regulation—Regulations on Information Security and Privacy Protection.” The following are non-exhaustive examples of certain recent PRC regulatory activities in this area:

Cybersecurity

· [Omitted.]

Data Security

· In June 2021, the SCNPC promulgated the PRC Data Security Law, which took effect in September 2021. The PRC Data Security Law, among other things, provides for security review procedure for data-related activities that may affect national security. It also introduces a data classification and hierarchical protection system based on the importance of data in terms of economic and social development, as well as the degree of harm it will cause to national security, public interests, or legitimate rights and interests of individuals or organizations when such data is tampered with, destroyed, leaked, or illegally acquired or used. Appropriate level of protection measures are required to be taken for each respective category of data. In addition, the PRC Data Security Law also provides that any organization or individual within the territory of the PRC shall not provide any foreign judicial body or law enforcement body with any data stored within the territory of the PRC without the approval of the competent PRC government authorities. A series of regulations, guidelines and other measures have been and are expected to be adopted to implement the requirements created by the PRC Data Security Law. For example, in July 2021, the State Council promulgated the Regulations on Protection of Critical Information Infrastructure (the “CIIO Regulations”), which became effective on September 1, 2021. Pursuant to this regulation, a “critical information infrastructure” is defined as key network facilities or information systems of critical industries or sectors, such as public communication and information service, energy, transportation, water conservation, finance, public services, e-government affairs and national defense science, the damage, malfunction or data leakage of which may endanger national security, people’s livelihoods and the public interest. In December 2021, the CAC, together with other authorities, jointly promulgated the Measures for Cybersecurity Review (2021 Revision), which became effective on February 15, 2022 and replaces its predecessor regulation. Pursuant to the Cybersecurity Review Measures, critical information infrastructure operators that procure internet products and services or network platform operators that carry out data processing activities must be subject to a cybersecurity review if their activities affect or may affect national security. The Cybersecurity Review Measures further stipulate that network platform operators that hold personal information of over one million users shall apply with the Cybersecurity Review Office for a cybersecurity review before any public offering at a foreign stock exchange. As of the date of this annual report, no detailed rules or implementation rules have been issued by any authority and we have not been informed that we are a “critical information infrastructure operator” by any government authority. The CIIO Regulations stipulate that the respective supervision and administration departments of the important industries and sectors as mentioned above (“Protection Departments”) shall be responsible for the security protection of critical information infrastructures, and the Protection Departments shall be responsible for organizing the recognition of the “critical information infrastructure” within the industries and sectors according to the recognition rules, and shall inform the recognized “critical information infrastructure operator” accordingly. However, as of the date of this annual report, to our best knowledge, we are not aware of any published regulations for recognition for “critical information infrastructure”the exact scope of “critical information infrastructure operators” under the current regulatory regime remains unclear, and the PRC government authorities may have wide discretion in the interpretation and enforcement of the applicable laws. Therefore, it is uncertain whether we would be deemed to be a “critical information infrastructure operator” under PRC law. If we are deemed a “critical

Show Raw Text
CORRESP
1
filename1.htm

Qifu Technology, Inc.

7/F Lujiazui Finance Plaza

No. 1217 Dongfang Road

Pudong New Area, Shanghai 200122

People’s
Republic of China

September 28, 2023

VIA EDGAR

Ms. Lory Empie

Mr. Michael Henderson

Mr. Andrew Mew

Mr. Jimmy McNamara

Ms. Susan Block

Mr. John Stickel

Division of Corporation Finance

Office of Finance

Securities and Exchange Commission

100 F Street, N.E.

Washington, D.C. 20549

 Re: Qifu Technology, Inc. (the “Company”)

    Form 20-F for the Year Ended 2022

    Filed April 27, 2023

    File
                                            No. 001-38752

Dear Ms. Empie, Mr. Henderson, Mr. Mew, Mr. McNamara,
Ms. Block and Mr. Stickel:

This letter sets forth the
Company’s response to the comment contained in the letter dated September 18, 2023 from the staff (the “Staff”)
of the Securities and Exchange Commission (the “Commission”) regarding the Company’s Form 20-F for the
fiscal year ended December 31, 2022 filed with the Commission on April 27, 2023 (the “2022 Form 20-F”).
The Staff’s comment is repeated below in bold and is followed by the Company’s response thereto. All capitalized terms used
but not defined in this letter shall have the meaning ascribed to such terms in the 2022 Form 20-F.

Qifu Technology, Inc.

September 28,
2023

Page 2

Form 20-F for the Year Ended 2022

Introduction, page 1

 1. In
                                            future filings, please revise your definition of “China” or “PRC”
                                            to remove the exclusion of Hong Kong and Macau from this definition. The definition may clarify
                                            that the only time that “China” or the “PRC” does not include Hong
                                            Kong or Macau is when you are referencing specific laws and regulations adopted by the PRC.
                                            If it does, please revise your disclosure to discuss any commensurate laws or regulations
                                            in Hong Kong, if applicable, and any risks and consequences to the company associated with
                                            those regulations. Please also disclose in the definition section that the same legal and
                                            operational risks associated with operations in China may also apply to operations in Hong
                                            Kong. Please confirm your understanding and include your proposed disclosure in your response
                                            letter.

In
response to the Staff’s comment, the Company respectfully proposes to revise the referenced disclosure as follows (page reference
is made to the 2022 Form 20-F to illustrate the approximate location of the disclosure) in its future Form 20-F filings (with
deletions shown as strike-through and additions underlined), subject to updates and adjustments to be made in connection with any material
development of the subject matter being disclosed:

Page 1

●	     “China”
or “the PRC” is to the People’s Republic of China. Unless otherwise indicated, the policies, laws, regulations and
interpretations adopted by the government of mainland China, which are specifically referenced in this annual report, are not applicable
to Hong Kong, Macau or Taiwan, excluding, for the purposes of this annual report only, Taiwan and the special administrative
regions of Hong Kong and Macau, except where the context otherwise requires;

In response to the Staff’s
comment on legal and operational risks associated with operations in China and whether those risks also apply to any operations in
Hong Kong, the Company respectfully advises the Staff that as of the date of the 2022 Form 20-F, its operations in Hong Kong
were immaterial to the Company’s overall business operation pursuant to U.S. federal securities laws. The Company’s subsidiary in Hong Kong, namely HK Qirui,
primarily serves the interim holding function for holding shares in the Company’s consolidated operating entities in mainland
China, and, to a lesser extent, provides certain IT and consulting services. Therefore, the Company believes it is not required to
disclose the relevant laws, regulations, or associated risks in Hong Kong in the 2022 Form 20-F. The Staff’s comment is
duly noted. To the extent that the Company’s operations in Hong Kong becomes material in the future, the Company undertakes to
include the relevant disclosure in its future Form 20-F filings.

Qifu Technology, Inc.

September 28,
2023

Page 3

Risk Factors

Our business is subject to complex and evolving
PRC laws regarding data privacy and cybersecurity, page 25

 2. In light of recent events indicating
                                            greater oversight by the Cyberspace Administration of China (CAC) over data security, particularly
                                            for companies seeking to list on a foreign exchange, in future filings, please revise your
                                            disclosure to explain how this oversight impacts your business and to what extent you believe
                                            that you are compliant with the regulations or policies that have been issued by the CAC
                                            to date. Please provide us your proposed disclosure in your response letter.

In
response to the Staff’s comment, the Company respectfully proposes to revise the referenced disclosure as follows (page reference
is made to the 2022 Form 20-F to illustrate the approximate location of the disclosure) in its future Form 20-F filings (with
deletions shown as strike-through and additions underlined), subject to updates and adjustments to be made in connection with any material
development of the subject matter being disclosed:

Pages 25-29

Our business is subject to complex
and evolving PRC laws and regulations regarding data privacy and cybersecurity, as such regulations and laws as newly promulgated,
many of which are subject to furtherchange and uncertain interpretation. Any changes in these laws and regulations
have caused and could continue to cause changes to our business practices and increase costs of operations, and any security breaches
or our actual or perceived failure to comply with such laws and regulations could result in claims, penalties, damages to our reputation
and brand, declines in user growth or engagement, or otherwise harm our business, results of operations and financial condition.

Our platform collects, stores and processes
certain personal information and other sensitive data from users for the purpose of providing our services, such as name, identity
number and phone number. We have obtained the explicit consents from users to use their personal information within the scope of authorization
and we have taken technical measures to protect the security of such personal information and prevent personal information from being
divulged, damaged or lost. However, we face risks inherent in handling and protecting personal informationdata.
In particular, we face a number of challenges relating to data generated from transactions and other activities on our platform,
including:

 · protecting
                                            the data in and hosted on our system, including against attacks on our system by outside
                                            parties or fraudulent behavior or improper use by our employees;

 · addressing
                                            concerns related to privacy and sharing, safety, security and other factors; and

 · complying
                                            with applicable laws, rules and regulations relating to the collection, use, storage,
                                            transfer, disclosure and security of personal information, which are subject to change and
                                            new interpretations, including any requests from regulatory and government authorities relating
                                            to such data.

In general, we expect that data security
and data protection compliance will receive greater attention and focus from regulators, both domestically and globally, as well as continued
or greater public scrutiny and attention going forward, which could increase our compliance costs and subject us to heightened risks
and challenges associated with data security and protection. If we are unable to manage these risks, or if we are accused of failing
to comply with such laws and regulations, we could become subject to corrective orders, penalties, including fines, suspension of business,
websites, or applications, and revocation of required licenses, and our reputation and results of operations could be materially and
adversely affected.

Qifu Technology, Inc.

September 28,
2023

Page 4

Recently, regulatory authorities in
China have enhanced data protection and cybersecurity regulatory requirements, as such regulations and laws as newly promulgated,
many of which are subject to furtherchange and uncertain interpretation. These laws continue to develop,
and the PRC government may adopt further rules, restrictions and clarifications in the future. Moreover, different PRC regulatory bodies,
including the Standing Committee of the National People’s Congress, or the SCNPC, the MIIT, the CAC, the Ministry of Public Security,
or the MPS and the State Administration for Market Regulation, or the SAMR, have enforced data privacy and protections laws and regulations
with varying standards and applications. See “Item 4. Information on the Company—B. Business Overview—Regulation—Regulations
on Information Security and Privacy Protection.” The following are non-exhaustive examples of certain recent PRC regulatory activities
in this area:

Cybersecurity

 · [Omitted.]

Data Security

 · In
                                            June 2021, the SCNPC promulgated the PRC Data Security Law, which took effect in September 2021.
                                            The PRC Data Security Law, among other things, provides for security review procedure for
                                            data-related activities that may affect national security. It also introduces a data classification
                                            and hierarchical protection system based on the importance of data in terms of economic and
                                            social development, as well as the degree of harm it will cause to national security, public
                                            interests, or legitimate rights and interests of individuals or organizations when such data
                                            is tampered with, destroyed, leaked, or illegally acquired or used. Appropriate level of
                                            protection measures are required to be taken for each respective category of data. In addition,
                                            the PRC Data Security Law also provides that any organization or individual within the territory
                                            of the PRC shall not provide any foreign judicial body or law enforcement body with any data
                                            stored within the territory of the PRC without the approval of the competent PRC government
                                            authorities. A series of regulations, guidelines and other measures have been and are expected
                                            to be adopted to implement the requirements created by the PRC Data Security Law. For example,
                                            in July 2021, the State Council promulgated the Regulations on Protection of Critical
                                            Information Infrastructure (the “CIIO Regulations”), which became effective
                                            on September 1, 2021. Pursuant to this regulation, a “critical information infrastructure”
                                            is defined as key network facilities or information systems of critical industries or sectors,
                                            such as public communication and information service, energy, transportation, water conservation,
                                            finance, public services, e-government affairs and national defense science, the damage,
                                            malfunction or data leakage of which may endanger national security, people’s livelihoods
                                            and the public interest. In December 2021, the CAC, together with other authorities,
                                            jointly promulgated the Measures for Cybersecurity Review (2021 Revision), which became effective
                                            on February 15, 2022 and replaces its predecessor regulation. Pursuant to the Cybersecurity
                                            Review Measures, critical information infrastructure operators that procure internet products
                                            and services or network platform operators that carry out data processing activities must
                                            be subject to a cybersecurity review if their activities affect or may affect national security.
                                            The Cybersecurity Review Measures further stipulate that network platform operators that
                                            hold personal information of over one million users shall apply with the Cybersecurity Review
                                            Office for a cybersecurity review before any public offering at a foreign stock exchange.
                                            As of the date of this annual report, no detailed rules or implementation rules have
                                            been issued by any authority and we have not been informed that we are a “critical
                                            information infrastructure operator” by any government authority. The CIIO Regulations
                                            stipulate that the respective supervision and administration departments of the important
                                            industries and sectors as mentioned above (“Protection Departments”) shall be
                                            responsible for the security protection of critical information infrastructures, and the
                                            Protection Departments shall be responsible for organizing the recognition of the “critical
                                            information infrastructure” within the industries and sectors according to the recognition
                                            rules, and shall inform the recognized “critical information infrastructure operator”
                                            accordingly. However, as of the date of this annual report, to our best knowledge,
                                            we are not aware of any published regulations for recognition for “critical information
                                            infrastructure”the exact scope of “critical information infrastructure
                                            operators” under the current regulatory regime remains unclear, and the PRC government
                                            authorities may have wide discretion in the interpretation and enforcement of the applicable
                                            laws. Therefore, it is uncertain whether we would be deemed to be a “critical
                                            information infrastructure operator” under PRC law. If we are deemed a “critical