SecProbe.io

Filing text and metadata
Intelligence Terminal Search Topics Monthly Activity About

Correspondence 0001104659-23-111032 from iHuman Inc. (IH)

iHuman Inc.
Date: Oct. 24, 2023 · CIK: 0001814423 · Accession: 0001104659-23-111032

AI Filing Summary & Sentiment

File numbers found in text: 001-39591

Referenced dates: August 3, 2023, August 31, 2023, August 31, 2023, September 26, 2023

Date
October 24, 2023
Author
Not clearly detected
Form
CORRESP
Company
iHuman Inc.

Letter

VIA EDGAR Division of Corporation Finance Office of Trade & Services Securities and Exchange Commission RE: iHuman Inc. (the “Company”) Form 20-F for Fiscal Year Ended December 31, Response dated August 31, 2023 File No. 001-39591

Dear Mr. King and Mr. Fetterolf:

This letter sets forth the Company’s response to the comments contained in the letter dated September 26, 2023 from the staff (the “Staff”) of the Securities and Exchange Commission (the “Commission”) regarding the Company’s annual report on Form 20-F for the fiscal year ended December 31, 2022 (the “2022 Form 20-F”) and the Company’s response dated August 31, 2023. The Staff’s comments are repeated below in bold and followed by the Company’s responses thereto. All capitalized terms used but not defined in this letter shall have the meaning ascribed to such terms in the 2022 Form 20-F.

Response Letter dated August 31, 2023

“Our business generates and processes data in the ordinary course, and we are required to comply with PRC and . . . ”, page 23

1. We note your response to comment 9, as well as your proposed disclosure that “[a]s advised by our PRC counsel, as of the date of this annual report, we are in compliance with the existing PRC laws and regulations on cybersecurity, data security and personal data protection issued by the CAC in material aspects.” The disclosure here should not be qualified by materiality. Please make appropriate revisions and tell us what your disclosure will look like.

Division of Corporation Finance

Office of Trade & Services

Securities and Exchange Commission

October 24, 2023

Page 2

In response to the Staff’s comment herein and the Staff’s Comment #9 dated August 3, 2023, the Company respectfully advises the Staff that, although the Company believes it is customary to include a materiality qualifier in light of the complexity of all existing laws and regulations of mainland China issued by the CAC, the Company is able to remove the materiality qualifier with respect to CAC’s all permissions and approvals requirements. As such, the Company proposes to revise the referenced disclosure as follows (page reference is made to the 2022 Form 20-F to illustrate the approximate location of the disclosure) in its future Form 20-F filings (with deletions shown as strike-through and additions underlined, and incremental changes in response to the Staff’s follow-up comment shown in strike-through for deletions or double underlines for additions), subject to updates and adjustments to be made in connection with any material development of the subject matter being disclosed:

Page 24

Data Security and Cybersecurity

· […]

· In June 2021, the Standing Committee of the National People’s Congress promulgated the Data Security Law, which took effect in September 2021. The Data Security Law, among other things, provides for security review procedure for data-related activities that may affect national security. In July 2021, the State Council promulgated the Regulations on Protection of Critical Information Infrastructure, which became effective on September 1, 2021. Pursuant to this regulation, critical information infrastructure means key network facilities or information systems of critical industries or sectors, such as public communication and information service, energy, transportation, water conservation, finance, public services, e-government affairs and national defense science, the damage, malfunction or data leakage of which may endanger national security, people’s livelihoods and the public interest. In December 2021, the CAC, together with other authorities, jointly promulgated the Revised Cybersecurity Review Measures, which became effective on February 15, 2022 and replaces its predecessor regulation. Pursuant to the Revised Cybersecurity Review Measures, critical information infrastructure operators that procure internet products and services or online platform operators that are engaged in data processing activities must be subject to the cybersecurity review if their activities affect or may affect national security. The Revised Cybersecurity Review Measures further stipulates that network platform operators that hold personal information of over one million users shall apply with the Cybersecurity Review Office for a cybersecurity review before any initial public offering at a foreign stock exchange. As of the date of this annual report, we have not been informed that we are a critical information infrastructure operator by any government authorities., . Moreover, our PRC counsel has consulted the relevant government authority, which confirmed that, under the currently effective laws and regulations of mainland China, a company already listed in a foreign stock exchange before promulgation of the Revised Cybersecurity Review Measures is not required to apply with the Cybersecurity Review Office for a cybersecurity review. As of the date of this annual report,and we have not been involved in any investigations on cyber security review made by the CAC, nor have we received any inquiries, notices, warnings, or sanctions from any competent mainland China regulatory authorities related to cybersecurity, data security and personal data protection. As advised by our PRC counsel, as of the date of this annual report, we are not required to apply with the Cybersecurity Review Office for a cybersecurity review. HoweverFurthermore, the exact scope of “critical information infrastructure operators” under the current regulatory regime remains unclear are subject to more detailed interpretations by competent government authorities, and the mainland ChinaPRC government authorities may have wide a certain degree of discretion within their scope of authority in the interpretation and enforcement of the applicable laws. Therefore, it is uncertain whether we would be deemed to be a critical information infrastructure operator or be subject to cybersecurity review under the laws and regulations of mainland China in the future. If we are deemed to be a critical information infrastructure operator under the cybersecurity laws and regulations in mainland China, we may be subject to obligations in addition to what we have fulfilled under the cybersecurity laws and regulations in mainland China.

Division of Corporation Finance

Office of Trade & Services

Securities and Exchange Commission

October 24, 2023

Page 3

· As advised by our PRC counsel, as of the date of this annual report, we are in compliance with the permissions and approvals requirements under the existing PRC laws and regulations and policies on cybersecurity, data security and personal data protection issued by the CAC in material aspects.

General

2. We note the additional changes, beyond those sought by our August 3, 2023 comment letter, that you have made to your proposed revised disclosure to appear in future annual report filings, especially changes in the “Item 3. Key Information” and “Risk Factors” sections relating to legal and operational risks associated with operating in China and PRC regulations. It is unclear to us that there have been changes in the regulatory environment in the PRC since your annual report on Form 20-F was filed on April 25, 2023, warranting revised disclosure to mitigate the challenges you face and related disclosures. The Sample Letters to China-Based Companies sought specific disclosure relating to the risk that the PRC government may intervene in or influence your operations at any time, or may exert control over operations of your business, which could result in a material change in your operations and/or the value of your ADSs. We remind you that, pursuant to federal securities rules, the term “control” (including the terms “controlling,” “controlled by,” and “under common control with”) as defined in Securities Act Rule 405 means “the possession, direct or indirect, of the power to direct or cause the direction of the management and policies of a person, whether through the ownership of voting securities, by contract, or otherwise.” The Sample Letters also sought specific disclosures relating to uncertainties regarding the enforcement of laws and that the rules and regulations in China can change quickly with little advance notice, as well as the risks if the PRC government determines that the contractual arrangements constituting part of the VIE structure do not comply with PRC regulations, or if these regulations change or are interpreted differently in the future. We do not believe that your proposed disclosure that removes detailed references to the PRC legal system and the nature of the PRC government’s regulatory oversight conveys the same risks. In future annual reports, please restore your disclosures in these areas to the disclosures as they existed in the annual report on Form 20-F filed April 25, 2023, as modified by your responses to our August 3, 2023 comment letter, and otherwise updated, as necessary, to reflect then existing facts and circumstances. Please show us what your disclosure will look like, assuming you were to file an annual report on the date of your response to this comment.

Division of Corporation Finance

Office of Trade & Services

Securities and Exchange Commission

October 24, 2023

Page 4

The Staff’s comment is duly noted. The Company respectfully submits that, it had provided in the Form 6-K furnished with the Commission on April 25, 2023 (the “Form 6-K”), that “the Company is not aware of any governmental entity of mainland China that is in possession of, directly or indirectly, the power to direct or cause the direction of the management and policies of the Company, whether through the ownership of voting securities, by contract, or otherwise.” As provided in the Form 6-K and further supplemented in the Company’s response to Comment #15 in the response letter dated August 31, 2023, the Company had relied on the examination of the Company’s register of members and public filings made by its shareholders to establish that it is not owned or controlled by a governmental entity of mainland China. The oversight of the mainland China government is carried out through the issuance of laws, regulations or policies, as well as the implementation of regulatory actions, which are of general applicability and are not specifically targeted at the C

Show Raw Text
CORRESP
1
filename1.htm

IHUMAN INC.

Floor 8, Building B

No. 1 Wangjing East Road

Chaoyang District, Beijing 100102

People’s Republic of China

October 24, 2023

VIA EDGAR

Mr. Dieter King

Mr. Brian Fetterolf

Division of Corporation Finance

Office of Trade & Services

Securities and Exchange Commission

100 F Street, N.E.

Washington, D.C. 20549

 RE: iHuman Inc. (the “Company”)

Form 20-F for Fiscal Year Ended December 31,
2022

Response dated August 31, 2023

File No. 001-39591

Dear Mr. King and Mr. Fetterolf:

This letter sets forth the Company’s response
to the comments contained in the letter dated September 26, 2023 from the staff (the “Staff”) of the Securities
and Exchange Commission (the “Commission”) regarding the Company’s annual report on Form 20-F for the fiscal
year ended December 31, 2022 (the “2022 Form 20-F”) and the Company’s response dated August 31,
2023. The Staff’s comments are repeated below in bold and followed by the Company’s responses thereto. All capitalized terms
used but not defined in this letter shall have the meaning ascribed to such terms in the 2022 Form 20-F.

Response Letter dated August 31, 2023

“Our business generates and processes
data in the ordinary course, and we are required to comply with PRC and . . . ”, page 23

 1. We
                                            note your response to comment 9, as well as your proposed disclosure that “[a]s advised
                                            by our PRC counsel, as of the date of this annual report, we are in compliance with the existing
                                            PRC laws and regulations on cybersecurity, data security and personal data protection issued
                                            by the CAC in material aspects.” The disclosure here should not be qualified by materiality.
                                            Please make appropriate revisions and tell us what your disclosure will look like.

Division of Corporation Finance

Office of Trade & Services

Securities
and Exchange Commission

October 24, 2023

Page 2

In
response to the Staff’s comment herein and the Staff’s Comment #9 dated August 3, 2023, the Company respectfully advises
the Staff that, although the Company believes it is customary to include a materiality qualifier in light of the complexity of all existing
laws and regulations of mainland China issued by the CAC, the Company is able to remove the materiality qualifier with respect to CAC’s
all permissions and approvals requirements. As such, the Company proposes to revise the referenced disclosure as follows (page reference
is made to the 2022 Form 20-F to illustrate the approximate location of the disclosure) in its future Form 20-F filings (with
deletions shown as strike-through and additions underlined, and incremental changes in response to the Staff’s follow-up comment
shown in strike-through for deletions or double underlines for additions), subject to updates and adjustments to be made in connection
with any material development of the subject matter being disclosed:

Page 24

Data Security and Cybersecurity

 · […]

 · In June 2021, the Standing Committee of the National People’s Congress promulgated the
                                                                                                             Data Security Law, which took effect in September 2021. The Data Security Law, among other things, provides for security review
                                                                                                             procedure for data-related activities that may affect national security. In July 2021, the State Council promulgated the
                                                                                                             Regulations on Protection of Critical Information Infrastructure, which became effective on September 1, 2021. Pursuant to this
                                                                                                             regulation, critical information infrastructure means key network facilities or information systems of critical industries or
                                                                                                             sectors, such as public communication and information service, energy, transportation, water conservation, finance, public services,
                                                                                                             e-government affairs and national defense science, the damage, malfunction or data leakage of which may endanger national security,
                                                                                                             people’s livelihoods and the public interest. In December 2021, the CAC, together with other authorities, jointly
                                                                                                             promulgated the Revised Cybersecurity Review Measures, which became effective on February 15, 2022 and replaces its predecessor
                                                                                                             regulation. Pursuant to the Revised Cybersecurity Review Measures, critical information infrastructure operators that procure
                                                                                                             internet products and services or online platform operators that are engaged in data processing activities must be subject to the
                                                                                                             cybersecurity review if their activities affect or may affect national security. The Revised Cybersecurity Review Measures further
                                                                                                             stipulates that network platform operators that hold personal information of over one million users shall apply with the
                                                                                                             Cybersecurity Review Office for a cybersecurity review before any initial public offering at a foreign stock exchange. As of the
                                                                                                             date of this annual report, we have not been informed that we are a critical information infrastructure operator by any government
                                                                                                             authorities., .
                                                                                                             Moreover, our PRC counsel has consulted the relevant government authority, which confirmed that, under the currently effective laws
                                                                                                             and regulations of mainland China, a company already listed in a foreign stock exchange before promulgation of the Revised
                                                                                                             Cybersecurity Review Measures is not required to apply with the Cybersecurity Review Office for a cybersecurity review. As of the
                                                                                                             date of this annual report,and we have not been involved in any investigations on cyber
                                                                                                             security review made by the CAC, nor have we received any inquiries, notices, warnings, or sanctions from any competent mainland
                                                                                                             China regulatory authorities related to cybersecurity, data security and personal data protection. As
                                                                                                             advised by our PRC counsel, as of the date of this annual report, we are not required to apply with the Cybersecurity Review Office
                                                                                                             for a cybersecurity review. HoweverFurthermore, the exact scope of “critical information
                                                                                                             infrastructure operators” under the current regulatory regime remains unclear are subject to more detailed
                                                                                                             interpretations by competent government authorities, and the mainland ChinaPRC government authorities
                                                                                                             may have wide a certain degree of discretion within their scope of authority in the
                                                                                                             interpretation and enforcement of the applicable laws. Therefore, it is uncertain whether we would be deemed to be a critical
                                                                                                             information infrastructure operator or
                                                                                                             be subject to cybersecurity review under the laws
                                                                                                             and regulations of mainland China
                                                                                                             in the future. If we are deemed to be a critical information infrastructure operator under the cybersecurity laws and
                                                                                                             regulations in mainland China, we may be subject to obligations in addition to what we have fulfilled under the cybersecurity laws
                                                                                                             and regulations in mainland China.

Division of Corporation Finance

Office of Trade & Services

Securities
and Exchange Commission

October 24, 2023

Page 3

 · As advised by our PRC counsel, as of the date of this annual report, we are in compliance with  the
                                                                                                             permissions and approvals requirements under the existing PRC laws and regulations and
                                                                                                             policies on cybersecurity, data security and personal data protection issued by the CAC in material
                                                                                                             aspects.

General

 2. We
                                            note the additional changes, beyond those sought by our August 3, 2023 comment letter,
                                            that you have made to your proposed revised disclosure to appear in future annual report
                                            filings, especially changes in the “Item 3. Key Information” and “Risk
                                            Factors” sections relating to legal and operational risks associated with operating
                                            in China and PRC regulations. It is unclear to us that there have been changes in the regulatory
                                            environment in the PRC since your annual report on Form 20-F was filed on April 25,
                                            2023, warranting revised disclosure to mitigate the challenges you face and related disclosures.
                                            The Sample Letters to China-Based Companies sought specific disclosure relating to the risk
                                            that the PRC government may intervene in or influence your operations at any time, or may
                                            exert control over operations of your business, which could result in a material change in
                                            your operations and/or the value of your ADSs. We remind you that, pursuant to federal securities
                                            rules, the term “control” (including the terms “controlling,” “controlled
                                            by,” and “under common control with”) as defined in Securities Act Rule 405
                                            means “the possession, direct or indirect, of the power to direct or cause the direction
                                            of the management and policies of a person, whether through the ownership of voting securities,
                                            by contract, or otherwise.” The Sample Letters also sought specific disclosures relating
                                            to uncertainties regarding the enforcement of laws and that the rules and regulations
                                            in China can change quickly with little advance notice, as well as the risks if the PRC government
                                            determines that the contractual arrangements constituting part of the VIE structure do not
                                            comply with PRC regulations, or if these regulations change or are interpreted differently
                                            in the future. We do not believe that your proposed disclosure that removes detailed references
                                            to the PRC legal system and the nature of the PRC government’s regulatory oversight
                                            conveys the same risks. In future annual reports, please restore your disclosures in these
                                            areas to the disclosures as they existed in the annual report on Form 20-F filed April 25,
                                            2023, as modified by your responses to our August 3, 2023 comment letter, and otherwise
                                            updated, as necessary, to reflect then existing facts and circumstances. Please show us what
                                            your disclosure will look like, assuming you were to file an annual report on the date of
                                            your response to this comment.

Division of Corporation Finance

Office of Trade & Services

Securities
and Exchange Commission

October 24, 2023

Page 4

The
Staff’s comment is duly noted. The Company respectfully submits that, it had provided in the Form 6-K furnished with
the Commission on April 25, 2023 (the “Form 6-K”), that “the Company is not aware of any governmental
entity of mainland China that is in possession of, directly or indirectly, the power to direct or cause the direction of the management
and policies of the Company, whether through the ownership of voting securities, by contract, or otherwise.” As provided in
the Form 6-K and further supplemented in the Company’s response to Comment #15 in the response letter dated August 31,
2023, the Company had relied on the examination of the Company’s register of members and public filings made by its shareholders
to establish that it is not owned or controlled by a governmental entity of mainland China. The oversight of the mainland China government
is carried out through the issuance of laws, regulations or policies, as well as the implementation of regulatory actions, which are
of general applicability and are not specifically targeted at the C