Correspondence 0001104659-23-104648 from Qfin Holdings, Inc. (QFIN)
Qfin Holdings, Inc.
Date: Sept. 28, 2023 · CIK: 0001741530 · Accession: 0001104659-23-104648
AI Filing Summary & Sentiment
File numbers found in text: 001-38752
Referenced dates: September 18, 2023
Show Raw Text
CORRESP
1
filename1.htm
Qifu Technology, Inc.
7/F Lujiazui Finance Plaza
No. 1217 Dongfang Road
Pudong New Area, Shanghai 200122
People’s
Republic of China
September 28, 2023
VIA EDGAR
Ms. Lory Empie
Mr. Michael Henderson
Mr. Andrew Mew
Mr. Jimmy McNamara
Ms. Susan Block
Mr. John Stickel
Division of Corporation Finance
Office of Finance
Securities and Exchange Commission
100 F Street, N.E.
Washington, D.C. 20549
Re: Qifu Technology, Inc. (the “Company”)
Form 20-F for the Year Ended 2022
Filed April 27, 2023
File
No. 001-38752
Dear Ms. Empie, Mr. Henderson, Mr. Mew, Mr. McNamara,
Ms. Block and Mr. Stickel:
This letter sets forth the
Company’s response to the comment contained in the letter dated September 18, 2023 from the staff (the “Staff”)
of the Securities and Exchange Commission (the “Commission”) regarding the Company’s Form 20-F for the
fiscal year ended December 31, 2022 filed with the Commission on April 27, 2023 (the “2022 Form 20-F”).
The Staff’s comment is repeated below in bold and is followed by the Company’s response thereto. All capitalized terms used
but not defined in this letter shall have the meaning ascribed to such terms in the 2022 Form 20-F.
Qifu Technology, Inc.
September 28,
2023
Page 2
Form 20-F for the Year Ended 2022
Introduction, page 1
1. In
future filings, please revise your definition of “China” or “PRC”
to remove the exclusion of Hong Kong and Macau from this definition. The definition may clarify
that the only time that “China” or the “PRC” does not include Hong
Kong or Macau is when you are referencing specific laws and regulations adopted by the PRC.
If it does, please revise your disclosure to discuss any commensurate laws or regulations
in Hong Kong, if applicable, and any risks and consequences to the company associated with
those regulations. Please also disclose in the definition section that the same legal and
operational risks associated with operations in China may also apply to operations in Hong
Kong. Please confirm your understanding and include your proposed disclosure in your response
letter.
In
response to the Staff’s comment, the Company respectfully proposes to revise the referenced disclosure as follows (page reference
is made to the 2022 Form 20-F to illustrate the approximate location of the disclosure) in its future Form 20-F filings (with
deletions shown as strike-through and additions underlined), subject to updates and adjustments to be made in connection with any material
development of the subject matter being disclosed:
Page 1
● “China”
or “the PRC” is to the People’s Republic of China. Unless otherwise indicated, the policies, laws, regulations and
interpretations adopted by the government of mainland China, which are specifically referenced in this annual report, are not applicable
to Hong Kong, Macau or Taiwan, excluding, for the purposes of this annual report only, Taiwan and the special administrative
regions of Hong Kong and Macau, except where the context otherwise requires;
In response to the Staff’s
comment on legal and operational risks associated with operations in China and whether those risks also apply to any operations in
Hong Kong, the Company respectfully advises the Staff that as of the date of the 2022 Form 20-F, its operations in Hong Kong
were immaterial to the Company’s overall business operation pursuant to U.S. federal securities laws. The Company’s subsidiary in Hong Kong, namely HK Qirui,
primarily serves the interim holding function for holding shares in the Company’s consolidated operating entities in mainland
China, and, to a lesser extent, provides certain IT and consulting services. Therefore, the Company believes it is not required to
disclose the relevant laws, regulations, or associated risks in Hong Kong in the 2022 Form 20-F. The Staff’s comment is
duly noted. To the extent that the Company’s operations in Hong Kong becomes material in the future, the Company undertakes to
include the relevant disclosure in its future Form 20-F filings.
Qifu Technology, Inc.
September 28,
2023
Page 3
Risk Factors
Our business is subject to complex and evolving
PRC laws regarding data privacy and cybersecurity, page 25
2. In light of recent events indicating
greater oversight by the Cyberspace Administration of China (CAC) over data security, particularly
for companies seeking to list on a foreign exchange, in future filings, please revise your
disclosure to explain how this oversight impacts your business and to what extent you believe
that you are compliant with the regulations or policies that have been issued by the CAC
to date. Please provide us your proposed disclosure in your response letter.
In
response to the Staff’s comment, the Company respectfully proposes to revise the referenced disclosure as follows (page reference
is made to the 2022 Form 20-F to illustrate the approximate location of the disclosure) in its future Form 20-F filings (with
deletions shown as strike-through and additions underlined), subject to updates and adjustments to be made in connection with any material
development of the subject matter being disclosed:
Pages 25-29
Our business is subject to complex
and evolving PRC laws and regulations regarding data privacy and cybersecurity, as such regulations and laws as newly promulgated,
many of which are subject to furtherchange and uncertain interpretation. Any changes in these laws and regulations
have caused and could continue to cause changes to our business practices and increase costs of operations, and any security breaches
or our actual or perceived failure to comply with such laws and regulations could result in claims, penalties, damages to our reputation
and brand, declines in user growth or engagement, or otherwise harm our business, results of operations and financial condition.
Our platform collects, stores and processes
certain personal information and other sensitive data from users for the purpose of providing our services, such as name, identity
number and phone number. We have obtained the explicit consents from users to use their personal information within the scope of authorization
and we have taken technical measures to protect the security of such personal information and prevent personal information from being
divulged, damaged or lost. However, we face risks inherent in handling and protecting personal informationdata.
In particular, we face a number of challenges relating to data generated from transactions and other activities on our platform,
including:
· protecting
the data in and hosted on our system, including against attacks on our system by outside
parties or fraudulent behavior or improper use by our employees;
· addressing
concerns related to privacy and sharing, safety, security and other factors; and
· complying
with applicable laws, rules and regulations relating to the collection, use, storage,
transfer, disclosure and security of personal information, which are subject to change and
new interpretations, including any requests from regulatory and government authorities relating
to such data.
In general, we expect that data security
and data protection compliance will receive greater attention and focus from regulators, both domestically and globally, as well as continued
or greater public scrutiny and attention going forward, which could increase our compliance costs and subject us to heightened risks
and challenges associated with data security and protection. If we are unable to manage these risks, or if we are accused of failing
to comply with such laws and regulations, we could become subject to corrective orders, penalties, including fines, suspension of business,
websites, or applications, and revocation of required licenses, and our reputation and results of operations could be materially and
adversely affected.
Qifu Technology, Inc.
September 28,
2023
Page 4
Recently, regulatory authorities in
China have enhanced data protection and cybersecurity regulatory requirements, as such regulations and laws as newly promulgated,
many of which are subject to furtherchange and uncertain interpretation. These laws continue to develop,
and the PRC government may adopt further rules, restrictions and clarifications in the future. Moreover, different PRC regulatory bodies,
including the Standing Committee of the National People’s Congress, or the SCNPC, the MIIT, the CAC, the Ministry of Public Security,
or the MPS and the State Administration for Market Regulation, or the SAMR, have enforced data privacy and protections laws and regulations
with varying standards and applications. See “Item 4. Information on the Company—B. Business Overview—Regulation—Regulations
on Information Security and Privacy Protection.” The following are non-exhaustive examples of certain recent PRC regulatory activities
in this area:
Cybersecurity
· [Omitted.]
Data Security
· In
June 2021, the SCNPC promulgated the PRC Data Security Law, which took effect in September 2021.
The PRC Data Security Law, among other things, provides for security review procedure for
data-related activities that may affect national security. It also introduces a data classification
and hierarchical protection system based on the importance of data in terms of economic and
social development, as well as the degree of harm it will cause to national security, public
interests, or legitimate rights and interests of individuals or organizations when such data
is tampered with, destroyed, leaked, or illegally acquired or used. Appropriate level of
protection measures are required to be taken for each respective category of data. In addition,
the PRC Data Security Law also provides that any organization or individual within the territory
of the PRC shall not provide any foreign judicial body or law enforcement body with any data
stored within the territory of the PRC without the approval of the competent PRC government
authorities. A series of regulations, guidelines and other measures have been and are expected
to be adopted to implement the requirements created by the PRC Data Security Law. For example,
in July 2021, the State Council promulgated the Regulations on Protection of Critical
Information Infrastructure (the “CIIO Regulations”), which became effective
on September 1, 2021. Pursuant to this regulation, a “critical information infrastructure”
is defined as key network facilities or information systems of critical industries or sectors,
such as public communication and information service, energy, transportation, water conservation,
finance, public services, e-government affairs and national defense science, the damage,
malfunction or data leakage of which may endanger national security, people’s livelihoods
and the public interest. In December 2021, the CAC, together with other authorities,
jointly promulgated the Measures for Cybersecurity Review (2021 Revision), which became effective
on February 15, 2022 and replaces its predecessor regulation. Pursuant to the Cybersecurity
Review Measures, critical information infrastructure operators that procure internet products
and services or network platform operators that carry out data processing activities must
be subject to a cybersecurity review if their activities affect or may affect national security.
The Cybersecurity Review Measures further stipulate that network platform operators that
hold personal information of over one million users shall apply with the Cybersecurity Review
Office for a cybersecurity review before any public offering at a foreign stock exchange.
As of the date of this annual report, no detailed rules or implementation rules have
been issued by any authority and we have not been informed that we are a “critical
information infrastructure operator” by any government authority. The CIIO Regulations
stipulate that the respective supervision and administration departments of the important
industries and sectors as mentioned above (“Protection Departments”) shall be
responsible for the security protection of critical information infrastructures, and the
Protection Departments shall be responsible for organizing the recognition of the “critical
information infrastructure” within the industries and sectors according to the recognition
rules, and shall inform the recognized “critical information infrastructure operator”
accordingly. However, as of the date of this annual report, to our best knowledge,
we are not aware of any published regulations for recognition for “critical information
infrastructure”the exact scope of “critical information infrastructure
operators” under the current regulatory regime remains unclear, and the PRC government
authorities may have wide discretion in the interpretation and enforcement of the applicable
laws. Therefore, it is uncertain whether we would be deemed to be a “critical
information infrastructure operator” under PRC law. If we are deemed a “critical