Correspondence 0001104659-23-111032 from iHuman Inc. (IH)
iHuman Inc.
Date: Oct. 24, 2023 · CIK: 0001814423 · Accession: 0001104659-23-111032
AI Filing Summary & Sentiment
File numbers found in text: 001-39591
Referenced dates: August 3, 2023, August 31, 2023, August 31, 2023, September 26, 2023
Show Raw Text
CORRESP
1
filename1.htm
IHUMAN INC.
Floor 8, Building B
No. 1 Wangjing East Road
Chaoyang District, Beijing 100102
People’s Republic of China
October 24, 2023
VIA EDGAR
Mr. Dieter King
Mr. Brian Fetterolf
Division of Corporation Finance
Office of Trade & Services
Securities and Exchange Commission
100 F Street, N.E.
Washington, D.C. 20549
RE: iHuman Inc. (the “Company”)
Form 20-F for Fiscal Year Ended December 31,
2022
Response dated August 31, 2023
File No. 001-39591
Dear Mr. King and Mr. Fetterolf:
This letter sets forth the Company’s response
to the comments contained in the letter dated September 26, 2023 from the staff (the “Staff”) of the Securities
and Exchange Commission (the “Commission”) regarding the Company’s annual report on Form 20-F for the fiscal
year ended December 31, 2022 (the “2022 Form 20-F”) and the Company’s response dated August 31,
2023. The Staff’s comments are repeated below in bold and followed by the Company’s responses thereto. All capitalized terms
used but not defined in this letter shall have the meaning ascribed to such terms in the 2022 Form 20-F.
Response Letter dated August 31, 2023
“Our business generates and processes
data in the ordinary course, and we are required to comply with PRC and . . . ”, page 23
1. We
note your response to comment 9, as well as your proposed disclosure that “[a]s advised
by our PRC counsel, as of the date of this annual report, we are in compliance with the existing
PRC laws and regulations on cybersecurity, data security and personal data protection issued
by the CAC in material aspects.” The disclosure here should not be qualified by materiality.
Please make appropriate revisions and tell us what your disclosure will look like.
Division of Corporation Finance
Office of Trade & Services
Securities
and Exchange Commission
October 24, 2023
Page 2
In
response to the Staff’s comment herein and the Staff’s Comment #9 dated August 3, 2023, the Company respectfully advises
the Staff that, although the Company believes it is customary to include a materiality qualifier in light of the complexity of all existing
laws and regulations of mainland China issued by the CAC, the Company is able to remove the materiality qualifier with respect to CAC’s
all permissions and approvals requirements. As such, the Company proposes to revise the referenced disclosure as follows (page reference
is made to the 2022 Form 20-F to illustrate the approximate location of the disclosure) in its future Form 20-F filings (with
deletions shown as strike-through and additions underlined, and incremental changes in response to the Staff’s follow-up comment
shown in strike-through for deletions or double underlines for additions), subject to updates and adjustments to be made in connection
with any material development of the subject matter being disclosed:
Page 24
Data Security and Cybersecurity
· […]
· In June 2021, the Standing Committee of the National People’s Congress promulgated the
Data Security Law, which took effect in September 2021. The Data Security Law, among other things, provides for security review
procedure for data-related activities that may affect national security. In July 2021, the State Council promulgated the
Regulations on Protection of Critical Information Infrastructure, which became effective on September 1, 2021. Pursuant to this
regulation, critical information infrastructure means key network facilities or information systems of critical industries or
sectors, such as public communication and information service, energy, transportation, water conservation, finance, public services,
e-government affairs and national defense science, the damage, malfunction or data leakage of which may endanger national security,
people’s livelihoods and the public interest. In December 2021, the CAC, together with other authorities, jointly
promulgated the Revised Cybersecurity Review Measures, which became effective on February 15, 2022 and replaces its predecessor
regulation. Pursuant to the Revised Cybersecurity Review Measures, critical information infrastructure operators that procure
internet products and services or online platform operators that are engaged in data processing activities must be subject to the
cybersecurity review if their activities affect or may affect national security. The Revised Cybersecurity Review Measures further
stipulates that network platform operators that hold personal information of over one million users shall apply with the
Cybersecurity Review Office for a cybersecurity review before any initial public offering at a foreign stock exchange. As of the
date of this annual report, we have not been informed that we are a critical information infrastructure operator by any government
authorities., .
Moreover, our PRC counsel has consulted the relevant government authority, which confirmed that, under the currently effective laws
and regulations of mainland China, a company already listed in a foreign stock exchange before promulgation of the Revised
Cybersecurity Review Measures is not required to apply with the Cybersecurity Review Office for a cybersecurity review. As of the
date of this annual report,and we have not been involved in any investigations on cyber
security review made by the CAC, nor have we received any inquiries, notices, warnings, or sanctions from any competent mainland
China regulatory authorities related to cybersecurity, data security and personal data protection. As
advised by our PRC counsel, as of the date of this annual report, we are not required to apply with the Cybersecurity Review Office
for a cybersecurity review. HoweverFurthermore, the exact scope of “critical information
infrastructure operators” under the current regulatory regime remains unclear are subject to more detailed
interpretations by competent government authorities, and the mainland ChinaPRC government authorities
may have wide a certain degree of discretion within their scope of authority in the
interpretation and enforcement of the applicable laws. Therefore, it is uncertain whether we would be deemed to be a critical
information infrastructure operator or
be subject to cybersecurity review under the laws
and regulations of mainland China
in the future. If we are deemed to be a critical information infrastructure operator under the cybersecurity laws and
regulations in mainland China, we may be subject to obligations in addition to what we have fulfilled under the cybersecurity laws
and regulations in mainland China.
Division of Corporation Finance
Office of Trade & Services
Securities
and Exchange Commission
October 24, 2023
Page 3
· As advised by our PRC counsel, as of the date of this annual report, we are in compliance with the
permissions and approvals requirements under the existing PRC laws and regulations and
policies on cybersecurity, data security and personal data protection issued by the CAC in material
aspects.
General
2. We
note the additional changes, beyond those sought by our August 3, 2023 comment letter,
that you have made to your proposed revised disclosure to appear in future annual report
filings, especially changes in the “Item 3. Key Information” and “Risk
Factors” sections relating to legal and operational risks associated with operating
in China and PRC regulations. It is unclear to us that there have been changes in the regulatory
environment in the PRC since your annual report on Form 20-F was filed on April 25,
2023, warranting revised disclosure to mitigate the challenges you face and related disclosures.
The Sample Letters to China-Based Companies sought specific disclosure relating to the risk
that the PRC government may intervene in or influence your operations at any time, or may
exert control over operations of your business, which could result in a material change in
your operations and/or the value of your ADSs. We remind you that, pursuant to federal securities
rules, the term “control” (including the terms “controlling,” “controlled
by,” and “under common control with”) as defined in Securities Act Rule 405
means “the possession, direct or indirect, of the power to direct or cause the direction
of the management and policies of a person, whether through the ownership of voting securities,
by contract, or otherwise.” The Sample Letters also sought specific disclosures relating
to uncertainties regarding the enforcement of laws and that the rules and regulations
in China can change quickly with little advance notice, as well as the risks if the PRC government
determines that the contractual arrangements constituting part of the VIE structure do not
comply with PRC regulations, or if these regulations change or are interpreted differently
in the future. We do not believe that your proposed disclosure that removes detailed references
to the PRC legal system and the nature of the PRC government’s regulatory oversight
conveys the same risks. In future annual reports, please restore your disclosures in these
areas to the disclosures as they existed in the annual report on Form 20-F filed April 25,
2023, as modified by your responses to our August 3, 2023 comment letter, and otherwise
updated, as necessary, to reflect then existing facts and circumstances. Please show us what
your disclosure will look like, assuming you were to file an annual report on the date of
your response to this comment.
Division of Corporation Finance
Office of Trade & Services
Securities
and Exchange Commission
October 24, 2023
Page 4
The
Staff’s comment is duly noted. The Company respectfully submits that, it had provided in the Form 6-K furnished with
the Commission on April 25, 2023 (the “Form 6-K”), that “the Company is not aware of any governmental
entity of mainland China that is in possession of, directly or indirectly, the power to direct or cause the direction of the management
and policies of the Company, whether through the ownership of voting securities, by contract, or otherwise.” As provided in
the Form 6-K and further supplemented in the Company’s response to Comment #15 in the response letter dated August 31,
2023, the Company had relied on the examination of the Company’s register of members and public filings made by its shareholders
to establish that it is not owned or controlled by a governmental entity of mainland China. The oversight of the mainland China government
is carried out through the issuance of laws, regulations or policies, as well as the implementation of regulatory actions, which are
of general applicability and are not specifically targeted at the C