Valid

GB/T 37932-2025Data security technology - Security requirements for data transaction services (English PDF)

数据安全技术 数据交易服务安全要求

Open the GB/T 37932-2025 preview as PDF

Preview — first pages of GB/T 37932-2025 (full document: 31 pages)

This is a limited preview

Buy now to download the full PDF (31 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

December 2, 2025

Implementation date

July 1, 2026

Scope

GB/T 37932-2025 is the English-translated version of 数据安全技术 数据交易服务安全要求.

GB/T 37932-2025 is the Chinese national standard covering the security of a data exchange - the verification that the seller had the right to sell, the classification of what is being traded, the de-identification where personal data is involved, the delivery and the audit trail of who received what. China has established regional data exchanges, and this is the standard they operate under. It replaces GB/T 37932-2019. It was issued on 2 December 2025 and has been in force since 1 July 2026, replacing GB/T 37932-2019. The document is under the responsibility of the Standardization Administration of China. This page is published from the official record of the 2025 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

Document preview — GB/T 37932-2025

National Standard of the People's Republic of China

ICS
35.030
Classification
L 80
Replacing
GB/T 37932-2019

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • Foreword...3
  • 1 Scope...6
  • 2 Normative references...6
  • 3 Terms and definitions...6
  • 4 General rules...9
  • 4.1 Reference model for data transaction services...9
  • 4.2 Data transaction process...9
  • 4.3 Data transaction object...11
  • 5 Security principles for data transactions...11
  • 6 Security requirements for data transaction service participants...13
  • 6.1 Basic requirements...13
  • 6.2 Data supplier...14
  • 6.3 Data demander...15
  • 6.4 Data provider and data third-party professional service agency...15
  • 6.5 Data transaction agency...17
  • 7 Security requirements for data transaction platforms...19
  • 7.1 Basic requirements...19
  • 7.2 Protection of transaction data security...20
  • 7.3 Security controls for the transaction process...21
  • 7.4 Transaction security audit...22
  • 8 Security requirements for data transaction objects...22
  • 8.1 Prohibited transaction data...22
  • 8.2 Data quality compliance...23
  • 8.3 Classification and grading protection of transaction data...24
  • 9 Security requirements for data transaction process...25
  • 9.1 Entity onboarding, registration and listing...25
  • 9.2 Transaction negotiation, order execution...26
  • 9.3 Product delivery, transaction settlement...27

1 Scope

GB/T 37932-2025 is the Chinese national standard covering the security of a data exchange - the verification that the seller had the right to sell, the classification of what is being traded, the de-identification where personal data is involved, the delivery and the audit trail of who received what. China has established regional data exchanges, and this is the standard they operate under. It replaces GB/T 37932-2019. It was issued on 2 December 2025 and has been in force since 1 July 2026, replacing GB/T 37932-2019. The document is under the responsibility of the Standardization Administration of China. This page is published from the official record of the 2025 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

This document specifies security requirements for data transaction services, including security requirements for data transaction participants, transaction platforms, transaction objects, and the transaction process. This document applies to data suppliers, data demanders, data transaction agencies, data providers, and data third-party professional service agencies for the purpose of standardizing their data transaction activities. It also applies to regulatory authorities and assessment bodies for the supervision, management, and assessment of data transaction service security.

2 Normative references

The following referenced documents are indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies.

GB/T 22239-2019, Information security technology -- Baseline for classified protection of cybersecurity

GB/T 25069, Information security techniques -- Terminology

GB/T 36343, Information technology -- Data transaction service platform -- Transaction data description

GB/T 37988, Information security technology -- Data security capability maturity model

GB/T 43697, Data security technology -- Rules for data classification and grading

3 Terms and definitions

For the purposes of this document, the terms and definitions defined in GB/T 25069 as well as the followings apply.

3.1 data resources NOTE. "Access" refers to a delivery method in which the provider grants the recipient use of an environment or interface that permits the computation or viewing of data, but does not allow the downloading, copying, or modification of the raw data, nor the downloading of the raw data to a local system.

4 General rules

4.1 Reference model for data transaction services Data transaction services are categorized into two models. data in-site transaction and data off-site transaction. Data in-site transaction involves suppliers and demanders transacting through a data transaction agency, whereas data off-site transaction takes place outside of such agencies. In actual practice, transactions may take place directly between data suppliers and demanders or through data transaction institutions. Data providers may also participate in the process, providing services such as the development, release, and underwriting of data products and services. Additionally, specialized data third-party professional service agencies may offer legal support, data assetization, security and quality assessments, and training and consulting to facilitate the orderly conduct of data transaction activities. A reference model for data transaction services is shown in Figure 1. Figure 1 -- Reference model for data transaction services

4.2 Data transaction process The end-to-end process of data in-site transaction typically encompasses stages such as entity onboarding, registration and listing, transaction negotiation, order execution, product delivery, settlement, transaction conclusion, and supervision and maintenance. Among these, entity onboarding and registration/listing constitute the pre-transaction preparation phase; transaction negotiation, order execution, product delivery, and settlement constitute the execution phase; and transaction conclusion and supervision/maintenance constitute the post-transaction phase. The process of data off- site transaction typically includes stages such as transaction negotiation, order execution, product delivery, settlement, and transaction conclusion. Apart from data transaction agencies, other participants in data transaction must comply with the relevant security requirements set forth in Chapter

9.The data transaction process comprises the following aspects.

a) Entity onboarding. data suppliers, data demanders, providers, and data third-party professional service agencies register with the data transaction institution, completing steps such as user registration, real-name authentication, qualification review, and profile completion.

b) Registration and listing. information regarding the data transaction object is registered, and assessments and reviews are conducted concerning the compliance and quality of data products and services. Data products and services that pass this review are then listed on the data transaction agency. NOTE

1.The assessment and review are conducted by data transaction agencies or professional data third-party professional service agencies.

c) Transaction negotiation. once the parties to the transaction have connected, they negotiate terms such as the intended use of the subject matter, transaction amount, delivery method, and security responsibilities. The demander may also request data products and services or sample data for testing. Shall further processing of the data products and services be required, the demander may issue a request for such processing to be performed by the data supplier or data provider.

d) Order execution. the data demander selects data products and services and places an order. After the supplier confirms the order details, both parties sign a data transaction contract, and the data transaction agency reviews and files the contract.

e) Product delivery. data products and services are delivered in accordance with the terms of the data transaction contract - whether via a data transaction platform, through a data provider, or through direct delivery between the parties - and the data demander conducts an acceptance review of the delivered products and services.

f) Settlement. settle fees for transaction participants based on the terms of data transaction contracts and payment bills, and support refunds for fees associated with excess purchases.

g) Transaction conclusion. conclude the data transaction, record and archive transaction-related information, conduct audits, and provide after-sales service for the data transaction.

h) Supervision and maintenance. establish mechanisms for handling complaints, reports, and dispute resolution regarding data transactions. Address issues arising from such transactions. Support the review and traceability of illegal or non- compliant data transaction activities, and safeguard the rights and interests of transaction participants. NOTE

2.Transaction disputes shall primarily be handled by the data transaction agency. If a resolution cannot be reached through coordination, the matter may be referred to expert arbitration or external arbitration bodies.

4.3 Data transaction object The data transaction object typically involves data products and services such as datasets, data interfaces, data reports, data applications, data tools, data services, and other data-related items.

5 Security principles for data transactions

Data transactions adhere to the following security principles.

a) Principle of legality and compliance. the data transaction service participants shall comply with applicable laws and regulations, respect social morals and ethics, adhere to business and professional ethics, and act with honesty and integrity; they shall not endanger national security or the public interest, nor infringe upon the legitimate rights and interests of individuals or organizations.

b) Principle of controllable processes. the data transaction process ensures that data sources are legitimate and verifiable, the scope of use is clearly defined, the transaction process is traceable, and security risks can be prevented.

c) Principles of data classification and grading. the data transaction object must comply with national and industry requirements for classification, grading, and protection. Mechanisms for authorized use and protection - differentiated by data category and grade (such as public data, enterprise data, and personal information) - shall be established, taking into account the scope of data circulation, the extent of potential impact, and associated risks.

d) Principle of ensuring security. the data transaction service participants shall adopt necessary administrative measures and technical means to prevent risks - such as the tampering, destruction, or leakage of transaction subjects, or their unauthorized acquisition, use, or transaction - and to safeguard the rights and interests of personal information subjects.

e) Principle of alignment between rights and responsibilities. participants in data transactions bear security responsibilities for their respective data transaction activities while enjoying the benefits derived from the circulation of data elements. 1) The data supplier is responsible for the quality, security, and compliance of the data transaction object; 2) The data demander is responsible for the security and compliance of the use of the data transaction object; 3) The data transaction agency is responsible for the security of data transaction platforms and the supervision of compliance in the transaction process; 4) The data provider and data third-party professional service agency are responsible for the security, compliance, and professionalism of the data development and utilization process and the products and services provided.

Note 1. 2. **Search (Optional).** Enter the keyword '**GB/T 37932-2025**' in the search bar, if it is not already shown. 3.

Note 2. 9.

Note 3. 10. **Verification (USD

Notes and Explanations

Note 1:**[GB/T 37932-2025](https://

Note 3:** If you are unable to redirect back to our Return Page, do not worry. **Additionally and independently**, our automated system will still deliver your PDF and Invoice via email **(the second mechanism to ensure the delivery)**, typically within 3 minutes. Once your payment is complete, you have two instant ways to access your PDF and invoice: you may stay on the Return Page for download in 3 minutes typically, or simply check your email inbox where a copy is automatically delivered in 3 minutes typically.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 31 pages — is available in the English PDF.

Referenced standards

Editions of GB/T 37932

EditionTitleRevisionStatus
GB/T 37932-2025Data security technology - Security requirements for data transaction servicescurrent editionCurrent
GB/T 37932-2019Data security technology - Security requirements for data transaction servicesprevious editionSuperseded

This page sells the current edition, GB/T 37932-2025. Earlier editions are listed for reference only.

How to Buy GB/T 37932-2025

  1. 1Add to cart. Click the "Buy GB/T 37932-2025" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
31 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 37932-2025

$305.00

$260.00for partners