Valid

GB/T 43739-2024Data security technology - Audit and management guide for personal information processing normativeness of mobile internet applications in App stores (English PDF)

数据安全技术 应用商店的移动互联网应用程序(App)个人信息处理规范性审核与管理指南

Open the GB/T 43739-2024 preview as PDF

Preview — first pages of GB/T 43739-2024 (full document: 23 pages)

This is a limited preview

Buy now to download the full PDF (23 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

April 25, 2024

Implementation date

November 1, 2024

Scope

GB/T 43739-2024 is the English-translated version of 数据安全技术 应用商店的移动互联网应用程序(App)个人信息处理规范性审核与管理指南.

GB/T 43739-2024 is the Chinese guide for app stores to audit and manage how the applications they distribute handle personal information. It places the obligation where enforcement actually works: China has hundreds of thousands of apps and a regulator that cannot review them individually, so the store becomes the gatekeeper, and this standard tells it what to check and how. It sets the app review and management process within the store, then the review content, the privacy policy and its completeness and accessibility, the consent mechanisms and whether they are genuinely optional, the permissions requested against the declared function, the actual collection behaviour including the SDKs embedded in the app, the handling of minors, the account deletion and data export, and the cross-border transfer; then the methods of review, combining document examination with technical detection, the handling of apps that fail, the re-review on update, the record keeping and the cooperation with the regulator. It takes effect on 1 November 2024.

Document preview — GB/T 43739-2024

National Standard of the People's Republic of China

ICS
35.030
Classification
L80

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 1 Scope1
  • 2 Normative references1
  • 3 Terms and Definitions1
  • 4 Abbreviations2
  • 5 App review and management process in the app store2
  • 5 Review of existing apps and version updates5
  • 18 References19

Foreword

This document is in accordance with the provisions of GB/T 1:1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting: Please note that some of the contents of this document may involve patents: The issuing organization of this document does not assume the responsibility for identifying patents: This document was proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260): This document was drafted by: China Mobile Communications Group Co:, Ltd:, China Electronics Technology Standardization Institute, National Computer Network Emergency Response Team Technical Processing Coordination Center, Beijing University of Posts and Telecommunications, China Cyberspace Research Institute, Huawei Technologies Co:, Ltd:, OPPO Guangdong Mobile Communications Co:, Ltd: Ltd:, Beijing Xiaomi Mobile Software Co:, Ltd:, Beijing Baidu Netcom Technology Co:, Ltd:, Beijing Douyin Information Service Co:, Ltd:, Beijing Kuaishou Technology Co:, Ltd:, Beijing Sankuai Online Technology Co:, Ltd:, Vivo Mobile Communications Co:, Ltd:, the Third Research Institute of the Ministry of Public Security, China Network Security Full Review Technology and Certification Center, China Electronics Technology Group Corporation No:

15 Research Institute, Ant Technology Group Co:, Ltd:, Changyang Technology (Beijing) Co:, Ltd:, Beijing Times Xinwei Information Technology Co:, Ltd:, Zhengzhou Xindajiean Information Technology Co:, Ltd:, Wuhan An Tian Information Technology Co:, Ltd: and Beijing Zhizhangyi Technology Co:, Ltd: The main drafters of this document are: Zhang Bin, Qiu Qin, He Yanzhe, Liao Jianxin, Yuan Jie, Zhang Feng, Xu Sijia, Du Xuetao, Liu Shenglan, Zhao Bei, Zhang Chen, Jin Tao, Hu Ying, Ren Yan, Jiang Weiqiang, Yu Le, Zhou Ying, Liu Chang, Li Wenqi, Bai Xue, Jiang Wei, Xue Chen, Zhou Chenwei, Hao Chunliang, Shao Bing, Liu Haoxin, Dou Yu, Wang Wenlei, Yi Qiang, Li Shi, Lu Xiaoming, Zhu Xuefeng, Fu Yanyan, Yang Minghui, Wang Ding, Li Ruiqing, Du Wenbo, Guo Jianling, Deng Ting, Wang Haitang, Yang Xiaohan, Zhao Naixuan, Dai Zhuoheng, Huang Hourui, Zhang Huan, Wang Pu, Wang Xin, Luo Hongwei, Li Chaoran, Zu Yanyan, Liu Jin, Zhao Yingjie, Jia Ke, Zhang Yan, Shen Yongbo, Lu Qing, Fan Hua, Zhang Lei, Wu Yuesheng, Xu Tianni, Yi Li, Liu Jian, Dong Jingjing, Peng Jin, Lin Guanchen, Bai Xiaoyuan, Zhao Hua, Wang Lianqiang, Yang Yuzhong, Yu Zhengchen, Yu Haiyang, Liu Xianlun, Peng Jing, Yu Lina, Liu Yang, Liu Dong, Wang Guangtao, Peng Gen, Cai Xu, Zhao Feng, Ma Dan, Wang Yali, Wang Pu, Gui Yanfeng, Wang Fuhai and Zhang Zhiyuan: Mobile Internet of Things App Store for Cybersecurity Technology Application (App) personal information processing standard Audit and Management Guidelines

1 Scope

GB/T 43739-2024 is the Chinese guide for app stores to audit and manage how the applications they distribute handle personal information. It places the obligation where enforcement actually works: China has hundreds of thousands of apps and a regulator that cannot review them individually, so the store becomes the gatekeeper, and this standard tells it what to check and how. It sets the app review and management process within the store, then the review content, the privacy policy and its completeness and accessibility, the consent mechanisms and whether they are genuinely optional, the permissions requested against the declared function, the actual collection behaviour including the SDKs embedded in the app, the handling of minors, the account deletion and data export, and the cross-border transfer; then the methods of review, combining document examination with technical detection, the handling of apps that fail, the re-review on update, the record keeping and the cooperation with the regulator. It takes effect on 1 November 2024.

This document provides normative review and management of the processing of personal information by mobile Internet applications (Apps) by application store operators: guide: This document is intended to guide app store operators in conducting App personal information security review and management, and is also intended for regulatory authorities and third-party organizations: The organization provides a reference for evaluating the ability of app store operators to review and manage App personal information processing activities:

2 Normative references

The contents of the following documents constitute the essential clauses of this document through normative references in this document: For referenced documents without a date, only the version corresponding to that date applies to this document; for referenced documents without a date, the latest version (including all amendments) applies to This document:

GB/T 19011-2021 Management System Audit Guide

GB/T 25069-2022 Information Security Technical Terminology

GB/T 35273-2020 Information security technology Personal information security specification

GB/T 41391-2022 Information security technology Basic requirements for mobile Internet applications (Apps) to collect personal information

3 Terms and definitions

GB/T 19011-2021, GB/T 25069-2022, GB/T 35273-2020 and GB/T 41391-2022 and The following terms and definitions apply to this document: 3:

1 An application that runs on a mobile smart terminal and provides information services to users:

Note: This includes applications and applets pre-installed, downloaded and installed on mobile smart terminals: [Source: GB/T 41391-2022, 3:1, modified] 3:

2 The owner, manager or provider of a mobile Internet application:

Note: Referred to as App operator: [Source: GB/T 41391-2022, 3:2] 3:

3 Appstore Various platforms that provide distribution services such as downloading, installation, and upgrading of mobile Internet applications:

Note: Includes application markets, distribution websites, mobile Internet applications with distribution capabilities, etc:

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 23 pages — is available in the English PDF.

Referenced standards

Similar standards

How to Buy GB/T 43739-2024

  1. 1Add to cart. Click the "Buy GB/T 43739-2024" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
23 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 43739-2024

$305.00

$260.00for partners