GB/T 43506-2023Telecom and internet service—User personal information protection requirements (English PDF)
电信和互联网服务 用户个人信息保护技术要求
Open the GB/T 43506-2023 preview as PDF
This is a limited preview
Buy now to download the full PDF (15 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
December 28, 2023
Implementation date
April 1, 2024
Scope
GB/T 43506-2023 is the English-translated version of 电信和互联网服务 用户个人信息保护技术要求.
GB/T 43506-2023 is the Chinese national standard covering telecom and internet service, User personal information protection requirements. Issued on 28 December 2023, it has been in force since 1 April 2024.
Document preview — GB/T 43506-2023
National Standard of the People's Republic of China
- ICS
- 33.030
- Classification
- M 42
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- PrefaceI IntroductionII
- 1 Scope1
- 2 Normative references1
- 3 Terms and Definitions1
- 4 Abbreviations1
- 5 Scope of user personal information protection1
- 6 User personal information classification2
- 6:1 Classification Overview2
- 6:2 User identity and authentication information2
- 6:3 User data and service content information2
- 6:4 User service related information3
- 7 User personal information protection classification and protection requirements3
- 7:1 Grading overview3
- 7:2 Grading method4
- 7:2:1 Classification method for Level 5 services4
- 7:2:2 Classification method for Level 4 services4
- 7:2:3 Classification method for Level 3 services4
- 7:2:4 Grading approach to Level 2 services5
- 7:2:5 Grading approach to Level 1 services5
- 7:3 Protection requirements5
- 7:3:1 Basic protection requirements5
- 7:3:2 Level 5 service protection requirements6
- 7:3:3 Level 4 service protection requirements6
- 7:3:4 Level 3 service protection requirements6
- 7:3:5 Level 2 service protection requirements6
- 7:3:6 Level 1 service protection requirements6
- Reference7
Foreword
This document complies with the provisions of GB/T 1:1-2020 "Standardization Work Guidelines Part 1: Structure and Drafting Rules of Standardization Documents" Drafting:
Please note that some content in this document may be subject to patents: The publisher of this document assumes no responsibility for identifying patents:
This document is proposed by the Ministry of Industry and Information Technology:
This document is under the jurisdiction of the National Communications Services Standardization Technical Committee (SAC/TC543):
This document was drafted by: China Academy of Information and Communications Technology, Shenzhen Tencent Computer Systems Co:, Ltd:, Beijing Qihoo Technology Co:, Ltd:, Alibaba Cloud Computing (Beijing) Co:, Ltd:, China Mobile Internet Co:, Ltd:, China United Network Communications Group Co:, Ltd:, China Telecom Group Group Co:, Ltd:, Beijing Jiexing Xinyuan Information Technology Co:, Ltd:, Beijing Zhuoyixunchang Technology Co:, Ltd:, Beijing Baidu Netcom Technology Co:, Ltd:
Company, Zhejiang Pengxin Information Technology Co:, Ltd:, Zhongfa Data Security Technology (Beijing) Co:, Ltd:, Beijing JD Sanbailu Shidu E-commerce Co:, Ltd:
Co:, Ltd:, Vivo Mobile Communications Co:, Ltd:, and Shanghai Xunmeng Information Technology Co:, Ltd:
The main drafters of this document: Tang Libo, Chang Haolun, Zang Lei, Li Cheng, Yu Rundong, Guo Wenshuang, Li Xin, Li Zongxiang, Gu Wei, Huang Xiaolin, Ge Yuming, Zhang Xueli, Ma Feng, Li Weijian, Hu Liqiong, Gao Feng, Wang Lanfang, Yang Chengyu, Liu Miao, Zhang Yi, Zhou Qun, Chen Xuebao, Jia Ke, Zhang Hang, Zhu Zheng, Chen Xin, Zhang Yanan:
Introduction
In recent years, with the rapid development of new generation information and communication technologies such as big data and cloud computing, data assets have become a key factor in telecommunications and the Internet:
An important and indispensable asset for enterprises, user personal information has become the top priority of data assets: However, corporate personal information protection awareness The situation is uneven: Violations of personal information protection in telecommunications and Internet services continue to occur, and users' personal information and rights are infringed: telecommunications and The protection of personal information of Internet service users has been listed as an important regulatory task by industry authorities, and relevant standards for the protection of personal information and rights and interests It is an important basis for industry management and enterprise self-discipline:
This document is based on the Personal Information Protection Law of the People's Republic of China, the Cybersecurity Law of the People's Republic of China, and the National People's Congress The Standing Committee’s Decision on Strengthening Network Information Protection, the Regulations on the Protection of Personal Information of Telecommunications and Internet Users, and other laws and regulations require that line writing:
The existing series of industry standards "Protection of Personal Information of Telecommunications and Internet Service Users" are widely used in the telecommunications and Internet service industries:
It has effectively promoted the healthy development of the telecommunications and Internet service industries in terms of personal information and rights protection: To further ensure telecommunications and The standardization and security of Internet services to prevent users’ personal information and rights from being infringed upon are improved and formed in accordance with existing industry standards:
software to further strengthen the broad applicability of user personal information and rights protection:
Protection of personal information of telecommunications and Internet service users skills requirement
1 Scope
This document defines the terms and definitions for the protection of personal information and rights of telecommunications and Internet service users, and stipulates the scope of protection, information classification Classes, classification objects, classification methods and protection requirements:
This document applies to users’ personal information and rights and interests in the process of providing services by telecommunications business operators and Internet information service providers: Protect:
2 Normative reference documents
This document has no normative references:
3 Terms and definitions
The following terms and definitions apply to this document: 3:1 Telecommunications business operators and Internet information service providers record electronically or otherwise identified information in the process of providing services:
Or various information related to identifiable natural persons, excluding anonymized information:
Note: Hereinafter referred to as user personal information: 3:2 cessing Telecommunications business operators and Internet information service providers collect, store, use, process, transmit, provide, and disclose personal information:
Open, delete and other activities:
4 Abbreviations
The following abbreviations apply to this document:
MAC: Media Access Control (MediaAccessControl)
5 Scope of protection of user personal information
The scope of user personal information protection includes telecommunications and Internet service operating entities and the services they provide during business preparation, processing, registration, Electronic or other means collected, stored, used, processed, transmitted, provided, disclosed, and deleted during the entire life cycle including development and termination:
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 15 pages — is available in the English PDF.
Referenced standards
Editions of GB/T 43506
| Edition | Title | Revision | Status |
|---|---|---|---|
| GB/T 43506-2023 | Telecom and internet service - User personal information protection requirements | current edition | Current |
This page sells the current edition, GB/T 43506-2023. Earlier editions are listed for reference only.
How to Buy GB/T 43506-2023
- 1Add to cart. Click the "Buy GB/T 43506-2023" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 43506-2023
$155.00