Valid

GB/T 44588-2024Data security technology—Personal information processing rules of internet platforms, products and services (English PDF)

数据安全技术 互联网平台及产品服务个人信息处理规则

Open the GB/T 44588-2024 preview as PDF

Preview — first pages of GB/T 44588-2024 (full document: 15 pages)

This is a limited preview

Buy now to download the full PDF (15 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

September 29, 2024

Implementation date

April 1, 2025

Scope

GB/T 44588-2024 is the English-translated version of 数据安全技术 互联网平台及产品服务个人信息处理规则.

GB/T 44588-2024 is the Chinese national standard covering the privacy notice an internet platform, product or app publishes — the basic requirements the rules must meet, the procedure by which an operator drafts them, the content they have to carry, the way they are published, how a revision is made and announced, and the handling of disputes, together with the sensitive information whose leak can put a person's dignity or safety at risk. The scope reaches the supervisor as well as the operator: the same rules are what an assessment is measured against. First edition. In force from 1 April 2025. Issued on 29 September 2024, it has been in force since 1 April 2025.

Document preview — GB/T 44588-2024

National Standard of the People's Republic of China

ICS
35.030
Classification
L 80

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • PrefaceIII
  • 1 Scope1
  • 2 Normative references1
  • 3 Terms and Definitions1
  • 4 Abbreviations2
  • 5 Overview2
  • 6 Basic requirements for personal information processing rules3
  • 7 Procedures for the preparation of personal information handling rules3
  • 8 Contents of personal information processing rules3
  • 9 Publication of personal information processing rules6
  • 10 Revision of personal information processing rules7
  • 11 Dispute resolution regarding personal information handling rules7
  • References8

Foreword

This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.

Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.

This document was proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260).

This document was drafted by: Beijing Institute of Technology, National Computer Network Emergency Response Technical Processing Coordination Center, China Electronics Technology Standardization Research Institute China Academy of Information and Communications Technology, China Cyberspace Research Institute, Perfect World (Beijing) Software Technology Development Co., Ltd., Shanghai Ctrip Business Beijing Douyin Information Service Co., Ltd., Beike Real Estate (Beijing) Technology Co., Ltd., Beijing Weibo Vision Technology Co., Ltd.

Company, Great Wall Motor Co., Ltd., Beijing Baidu Netcom Technology Co., Ltd., Beijing Sankuai Technology Co., Ltd., OPPO Guangdong Mobile Communications Co., Ltd., Vivo Mobile Communications Co., Ltd., Beijing Tengyun Tianxia Technology Co., Ltd., iReader Technology Co., Ltd., Shanghai SenseTime Intelligent Technology Co., Ltd., Beijing Shangyin Technology Co., Ltd., Beijing Zhuanzhuan Spirit Technology Co., Ltd., Beijing Jingtian & Gongcheng Law Firm Shanghai Branch of the Firm, Qi'anxin Technology Group Co., Ltd., Huawei Technologies Co., Ltd., Honor Terminal Co., Ltd., Beijing Samsung Communications Technology Co., Ltd.

Technology Research Co., Ltd., Beijing Xiaoju Technology Co., Ltd., China Telecom Co., Ltd. Jiangxi Branch, Beijing Tongyuan Legal Consulting Co., Ltd.

Company, China National Petroleum Corporation Changqing Oilfield Branch, Guangzhou Shiyuan Electronic Technology Co., Ltd., Hangzhou Xiaoying Innovation Technology Co., Ltd.

The main drafters of this document are: Hong Yanqing, Ren Yan, Zhu Xuefeng, Xue Ying, Xue Chen, Wu Mengyi, Ge Mengying, He Yanzhe, Yang Qin, Ge Xin, Hu Ying, Tian Shen, Dou Yu, Chen Tian, He Yunyun, Li Yanjie, Gao Chao, Liu Xiaocen, Li Weijing, Lin Xingchen, Zhang Chao, Wu Di, Xue Jing, Xu Quanquan, Li Hangmin, Yu Fang, Yuan Lizhi, Yang Dan, Wang Yiyu, Yi Li, Wang Jingzhou, Li Yangchun, Song Ziyi, Wang Haitang, Huang Rong, Liu Rong, Cheng Yan, Gao Siping, Tian Linchuan, Mao Xinyi, Fu Yanyan, Zhao Pengyang, Yi Qiang, Zhao Xiaona, Sun Shuxian, Chen Shu, Cheng Jin, Lu Meng, Wu Geng, Wang Xing, Song Xiaoai, Li Shihong, Zhou Yang, Zhu Lei, Wang Danhui, Xie Boyan, Zhang Cheng, Ma Ke, Zhang Bowen, Yang Xinyu, Jia Ke, Zhang Wei, An Jincheng, Lian Xiyu, Wu Yue, Zhang Na, Tian Mingren, Guo Li, Su Ying, Song Yangqi, Jiao Qionghui, Liao Hanxing.

Data security technology Internet platform and product services Personal Information Processing Rules

1 Scope

This document specifies the basic requirements, compilation procedures, content, and publication format of the rules for the processing of personal information on Internet platforms and product services.

The requirements include the format, rules for handling personal information, and dispute resolution.

This document is applicable to the process of regulating the formulation and publication of personal information processing rules by operators of Internet platforms and product services.

Supervise, manage and evaluate personal information processing rules.

2 Normative references

GB/T 25069-2022

GB/T 35273-2020

3 Terms and definitions

The terms and definitions defined in GB/T 25069-2022 and GB/T 35273-2020 and the following apply to this document.

3.1 Internet platforms, products and services

A platform, product or service that directly provides the required business functions to the subject of personal information through the Internet.

3.2 [Source. GB/T 41391-2022, 3.1, modified]

An application running on a mobile smart terminal.

Note. This includes application software pre-installed on smart terminals, downloaded and installed, and software developed based on the application software development platform interface that users can use without installation.

Mini programs, quick applications, etc., referred to as App.

3.3 Personal information

Any information related to an identified or identifiable natural person recorded electronically or otherwise, excluding any information that has been anonymized. information.

[Source. GB/T 35273-2020, 3.1, modified]

3.4 information

Once leaked or illegally used, it is likely to cause the personal dignity of natural persons to be infringed or the personal and property safety to be endangered.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 15 pages — is available in the English PDF.

Referenced standards

Editions of GB/T 44588

EditionTitleRevisionStatus
GB/T 44588-2024Data security technology - Personal information processing rules of internet platforms, products and servicescurrent editionCurrent

This page sells the current edition, GB/T 44588-2024. Earlier editions are listed for reference only.

How to Buy GB/T 44588-2024

  1. 1Add to cart. Click the "Buy GB/T 44588-2024" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
15 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 44588-2024

$200.00

$170.00for partners