GB/T 44588-2024Data security technology—Personal information processing rules of internet platforms, products and services (English PDF)
数据安全技术 互联网平台及产品服务个人信息处理规则
Open the GB/T 44588-2024 preview as PDF
This is a limited preview
Buy now to download the full PDF (15 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
September 29, 2024
Implementation date
April 1, 2025
Scope
GB/T 44588-2024 is the English-translated version of 数据安全技术 互联网平台及产品服务个人信息处理规则.
GB/T 44588-2024 is the Chinese national standard covering the privacy notice an internet platform, product or app publishes — the basic requirements the rules must meet, the procedure by which an operator drafts them, the content they have to carry, the way they are published, how a revision is made and announced, and the handling of disputes, together with the sensitive information whose leak can put a person's dignity or safety at risk. The scope reaches the supervisor as well as the operator: the same rules are what an assessment is measured against. First edition. In force from 1 April 2025. Issued on 29 September 2024, it has been in force since 1 April 2025.
Document preview — GB/T 44588-2024
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- PrefaceIII
- 1 Scope1
- 2 Normative references1
- 3 Terms and Definitions1
- 4 Abbreviations2
- 5 Overview2
- 6 Basic requirements for personal information processing rules3
- 7 Procedures for the preparation of personal information handling rules3
- 8 Contents of personal information processing rules3
- 9 Publication of personal information processing rules6
- 10 Revision of personal information processing rules7
- 11 Dispute resolution regarding personal information handling rules7
- References8
Foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.
Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.
This document was proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260).
This document was drafted by: Beijing Institute of Technology, National Computer Network Emergency Response Technical Processing Coordination Center, China Electronics Technology Standardization Research Institute China Academy of Information and Communications Technology, China Cyberspace Research Institute, Perfect World (Beijing) Software Technology Development Co., Ltd., Shanghai Ctrip Business Beijing Douyin Information Service Co., Ltd., Beike Real Estate (Beijing) Technology Co., Ltd., Beijing Weibo Vision Technology Co., Ltd.
Company, Great Wall Motor Co., Ltd., Beijing Baidu Netcom Technology Co., Ltd., Beijing Sankuai Technology Co., Ltd., OPPO Guangdong Mobile Communications Co., Ltd., Vivo Mobile Communications Co., Ltd., Beijing Tengyun Tianxia Technology Co., Ltd., iReader Technology Co., Ltd., Shanghai SenseTime Intelligent Technology Co., Ltd., Beijing Shangyin Technology Co., Ltd., Beijing Zhuanzhuan Spirit Technology Co., Ltd., Beijing Jingtian & Gongcheng Law Firm Shanghai Branch of the Firm, Qi'anxin Technology Group Co., Ltd., Huawei Technologies Co., Ltd., Honor Terminal Co., Ltd., Beijing Samsung Communications Technology Co., Ltd.
Technology Research Co., Ltd., Beijing Xiaoju Technology Co., Ltd., China Telecom Co., Ltd. Jiangxi Branch, Beijing Tongyuan Legal Consulting Co., Ltd.
Company, China National Petroleum Corporation Changqing Oilfield Branch, Guangzhou Shiyuan Electronic Technology Co., Ltd., Hangzhou Xiaoying Innovation Technology Co., Ltd.
The main drafters of this document are: Hong Yanqing, Ren Yan, Zhu Xuefeng, Xue Ying, Xue Chen, Wu Mengyi, Ge Mengying, He Yanzhe, Yang Qin, Ge Xin, Hu Ying, Tian Shen, Dou Yu, Chen Tian, He Yunyun, Li Yanjie, Gao Chao, Liu Xiaocen, Li Weijing, Lin Xingchen, Zhang Chao, Wu Di, Xue Jing, Xu Quanquan, Li Hangmin, Yu Fang, Yuan Lizhi, Yang Dan, Wang Yiyu, Yi Li, Wang Jingzhou, Li Yangchun, Song Ziyi, Wang Haitang, Huang Rong, Liu Rong, Cheng Yan, Gao Siping, Tian Linchuan, Mao Xinyi, Fu Yanyan, Zhao Pengyang, Yi Qiang, Zhao Xiaona, Sun Shuxian, Chen Shu, Cheng Jin, Lu Meng, Wu Geng, Wang Xing, Song Xiaoai, Li Shihong, Zhou Yang, Zhu Lei, Wang Danhui, Xie Boyan, Zhang Cheng, Ma Ke, Zhang Bowen, Yang Xinyu, Jia Ke, Zhang Wei, An Jincheng, Lian Xiyu, Wu Yue, Zhang Na, Tian Mingren, Guo Li, Su Ying, Song Yangqi, Jiao Qionghui, Liao Hanxing.
Data security technology Internet platform and product services Personal Information Processing Rules
1 Scope
This document specifies the basic requirements, compilation procedures, content, and publication format of the rules for the processing of personal information on Internet platforms and product services.
The requirements include the format, rules for handling personal information, and dispute resolution.
This document is applicable to the process of regulating the formulation and publication of personal information processing rules by operators of Internet platforms and product services.
Supervise, manage and evaluate personal information processing rules.
2 Normative references
GB/T 25069-2022
GB/T 35273-2020
3 Terms and definitions
The terms and definitions defined in GB/T 25069-2022 and GB/T 35273-2020 and the following apply to this document.
3.1 Internet platforms, products and services
A platform, product or service that directly provides the required business functions to the subject of personal information through the Internet.
3.2 [Source. GB/T 41391-2022, 3.1, modified]
An application running on a mobile smart terminal.
Note. This includes application software pre-installed on smart terminals, downloaded and installed, and software developed based on the application software development platform interface that users can use without installation.
Mini programs, quick applications, etc., referred to as App.
3.3 Personal information
Any information related to an identified or identifiable natural person recorded electronically or otherwise, excluding any information that has been anonymized. information.
[Source. GB/T 35273-2020, 3.1, modified]
3.4 information
Once leaked or illegally used, it is likely to cause the personal dignity of natural persons to be infringed or the personal and property safety to be endangered.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 15 pages — is available in the English PDF.
Referenced standards
Editions of GB/T 44588
| Edition | Title | Revision | Status |
|---|---|---|---|
| GB/T 44588-2024 | Data security technology - Personal information processing rules of internet platforms, products and services | current edition | Current |
This page sells the current edition, GB/T 44588-2024. Earlier editions are listed for reference only.
How to Buy GB/T 44588-2024
- 1Add to cart. Click the "Buy GB/T 44588-2024" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 25069-2022 — Information security techniques—Terminology
GB/T 35273-2020 — Information security technology—Personal information security specification
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
Secure payment via Stripe
Payments accepted
GB/T 44588-2024
$200.00