GB/T 45392-2025Data security technology — Security requirements for automated decision making based on personal information (English PDF)
数据安全技术 基于个人信息的自动化决策安全要求
Open the GB/T 45392-2025 preview as PDF
This is a limited preview
Buy now to download the full PDF (17 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
March 28, 2025
Implementation date
October 1, 2025
Scope
GB/T 45392-2025 is the English-translated version of 数据安全技术 基于个人信息的自动化决策安全要求.
GB/T 45392-2025 is the Chinese national standard covering decisions a computer makes about a person from their personal information — the algorithm impact assessment, the training and test data, the human intervention that has to remain available, the feature generation that turns data into a profile, what must be told to the individual before a decision and the rights left afterwards, and the tighter rules for credit, insurance, employment, welfare and targeted marketing. The scenario clauses are where the document bites: a credit score, a welfare eligibility check and a job screening are each treated on their own terms. First edition, with the government data standard GB/T 45396-2025. In force from 1 October 2025. Issued on 28 March 2025, it has been in force since 1 October 2025.
Document preview — GB/T 45392-2025
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- PrefaceIII
- 1 Scope1
- 2 Normative references1
- 3 Terms and Definitions1
- 4 Overview2
- 4.1 Automated decision-making process2
- 4.2 Computer programs and algorithms used for automated decision-making3
- 4.3 Scope of information processed through automated decision making3
- 4.4 Security risks of automated decision making3
- 5 Safety Principles4
- 6 General safety requirements4
- 7 Algorithm security requirements4
- 7.1 Algorithm Impact Assessment4
- 7.2 Algorithm Security Technical Requirements5
- 7.3 Algorithm security and reliability requirements5
- 7.4 Algorithm Security Human Intervention Requirements5
- 7.5 Training and testing data requirements to ensure algorithm security5
- 7.6 Technical documentation requirements for algorithm development6
- 7.7 Algorithm safe operation requirements6
- 7.8 Other requirements7
- 8 Feature Generation Safety Requirements7
- 8.1 Requirements for processing personal information generated by features7
- 8.2 Computational safety requirements for feature generation8
- 9 Decision-making security requirements8
- 9.1 Basic Requirements8
- 9.2 Informative requirements before decision making8
- 9.3 Requirements for protecting individual rights in decision-making9
- 10 Special security requirements for typical scenarios of automated decision-making9
- 10.1 Educational or professional opportunities9
- 10.2 Credit or Insurance Assessment9
- 10.3 Public governance areas such as social welfare qualifications9
- 10.4 Labor relations field1010
- 10.5 Security requirements for automated decision-making for special groups1010
- 10.6 Information push, commercial marketing10
- 10.7 Commercial Transactions11 Reference12
Foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.
Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.
This document was proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260).
This document was drafted by: Beijing Institute of Technology, China Academy of Information and Communications Technology, China Electronics Technology Standardization Institute, China Cyberspace Security Research Institute Review Technology and Certification Center, Beijing Douyin Information Service Co., Ltd., Beijing Baidu Netcom Technology Co., Ltd., Beijing Shangyin Technology Co., Ltd.
Beijing Sankuai Online Technology Co., Ltd., Beike Real Estate (Beijing) Technology Co., Ltd., Shanghai Meishida Business Consulting Co., Ltd., Shanghai Shan Yong Law Firm, Beijing Jingtian & Gongcheng Law Firm, Beijing Xiaoju Technology Co., Ltd., Beijing Hanhua Feitian Xinan Technology Co., Ltd., Ctrip Information Technology (Shanghai) Co., Ltd., Ant Technology Group Co., Ltd., Alibaba (Beijing) Software Services Co., Ltd., Beijing Kuaishou Technology Co., Ltd., Beijing Jingdong Shangke Information Technology Co., Ltd., Beijing Weimeng Chuangke Network Technology Co., Ltd., Beijing Tengyun Tianxia Technology Co., Ltd., Beijing Zhonglun Law Firm, Beijing Foreign Studies University, China University of Political Science and Law, Beijing University of Posts and Telecommunications, Yuncong Technology Group Co., Ltd., Honor Device Co., Ltd., Beijing DeepQuest AI Basic Technology Research Co., Ltd., OPPO Guangdong Mobile Communications Co., Ltd.
The main drafters of this document are: Hong Yanqing, Tian Shen, Ge Xin, Wu Mengyi, Zhu Manli, Wang Jinsong, Zhang Chao, Zhao Ranran, Liu Xiaocen, Xue Jing, Xu Quanquan, Wan Fang, Zhang Linghan, Wang Ding, Peng Gen, Fan Hua, Wang Lei, Chen Tian, He Yanzhe, Liu Ying, Ge Mengying, Wang Jingzhou, Luo Hongwei, Sun Tie, Xu Rui, Zhang Na, Li Weijing, Liu Rong, Gu Wei, Guo Jianling, Zhou Yang, Wu Jiawei, Hu Naying, Ding Xiaoqiang, Hu Liping, Fu Yanyan, Bai Xiaoyuan, Shi Yuzhen, Zhao Xiaona, Li Jun, Peng Juntao, Wu Shaoqing, Huang Rong, Fan Ye, Liang Tianxiang.
Data security technology based on the automation of personal information Decision security requirements
1 Scope
This document proposes basic security principles for automated decision-making based on personal information, and stipulates general security requirements, algorithm security requirements, Feature generation safety requirements, decision-making safety requirements, and special safety requirements for typical scenarios of automated decision-making.
This document applies to personal information processors that conduct automated decision-making to regulate their algorithm development, feature generation and decision-making activities.
Regulatory authorities and third-party assessment agencies supervise, manage and evaluate automated decision-making.
2 Normative references
GB/T 35273
GB/T 41391
GB/T 41479
GB/T 42888-2023
3 Terms and definitions
The terms and definitions defined in GB/T 35273 and the following apply to this document.
3.1
The computer program automatically analyzes and evaluates a person's behavior, hobbies, or economic, health, and credit status, and Decision-making activities.
Note. Automated decision making can be further decomposed into two processes. feature generation and decision making.
3.2
After the personal information is automatically processed by a computer program, it is automatically generated by a computer program about the preferences, occupation, Information about your financial, health, education, and credit status.
Note. Personal characteristic information does not include personal biometric information.
3.3
Personal information is automatically processed through computer programs, and personal features are extracted, selected, calculated and output.
The process of obtaining the input information needed to make individual decisions.
Note. Abbreviated as “feature generation”.
3.4 decision making
The computer program generates personal characteristic information as input, which can affect the individual's own state, the physical environment in which he lives, and the
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 17 pages — is available in the English PDF.
Referenced standards
Normative references
- GB/T 35273Information security technology—Personal information security specification
- GB/T 41391Information security technology—Basic requirements for collecting personal information in mobile internet applications
- GB/T 41479Information security technology—Network data processing security requirements
- GB/T 42888-2023Information security technology - Assessment specification for security of machine learning algorithms
Editions of GB/T 45392
| Edition | Title | Revision | Status |
|---|---|---|---|
| GB/T 45392-2025 | Data security technology - Security requirements for automated decision making based on personal information | current edition | Current |
This page sells the current edition, GB/T 45392-2025. Earlier editions are listed for reference only.
How to Buy GB/T 45392-2025
- 1Add to cart. Click the "Buy GB/T 45392-2025" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 35273-2020 — Information security technology—Personal information security specification
GB/T 41391-2022 — Information security technology—Basic requirements for collecting personal information in mobile internet applications
GB/T 41479-2022 — Information security technology—Network data processing security requirements
Secure payment via Stripe
Payments accepted
GB/T 45392-2025
$305.00