Lenovo refutes claims of data transfer to China in class action lawsuit

Lenovo is facing allegations in a class action lawsuit filed by the U.S.-based Almeida Law Group, accusing the company of transferring large amounts of data to China. This lawsuit claims that Lenovo’s actions violate the U.S. Department of Justice’s Data Security Program, which aims to prevent the transfer of sensitive personal data to countries considered “countries of concern.” The lawsuit argues that Lenovo’s automated advertising infrastructure is transmitting American consumers’ data to China, in direct violation of the DOJ Rule.

The lawsuit, brought by Spencer Christy of San Francisco, California, and others, alleges that Lenovo and its Chinese parent company are linking browsing activity to individual identities, tracking behaviors, and building detailed profiles without consent. These actions not only invade privacy but also pose a potential threat to national security by increasing the risk of coercion, reputational harm, or blackmail.

While Lenovo is not the only company engaging in data collection, its parent company, Lenovo Group Limited, is incorporated in Hong Kong with headquarters in Beijing, China. Moreover, its largest shareholder, Legend Holdings Corporation, is based in Beijing and has ties to the Chinese government. According to the lawsuit, Lenovo falls under the covered persons provision of the DOJ regulation due to its connections to countries of concern and entities controlled by such countries.

Lenovo Group is subject to Chinese regulations such as the National Intelligence Law, Cybersecurity Law, and Data Security Law, which require cooperation with local authorities when requested for data. In response to these allegations, Lenovo has denied any improper sharing of customer data and emphasized its compliance with data protection laws and regulations globally, including stringent U.S. requirements.

This lawsuit raises concerns about the data practices of technology companies operating globally and the potential risks associated with transferring sensitive information to countries with different data protection standards. It underscores the importance of transparency, privacy, and security in handling consumer data to prevent unauthorized access or misuse by foreign entities.

As the legal battle unfolds, the outcome of this case could have significant implications for how companies collect, store, and transfer data across international borders. It highlights the challenges of balancing data privacy and national security concerns in an increasingly interconnected digital world. Consumers, lawmakers, and tech companies alike will be closely watching the developments in this case to understand the broader implications for data privacy and protection in the tech industry.