GB/T 45396-2025Data security technology — Security requirements for government data processing (English PDF)
数据安全技术 政务数据处理安全要求
Open the GB/T 45396-2025 preview as PDF
This is a limited preview
Buy now to download the full PDF (28 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
March 28, 2025
Implementation date
October 1, 2025
Scope
GB/T 45396-2025 is the English-translated version of 数据安全技术 政务数据处理安全要求.
GB/T 45396-2025 is the Chinese national standard covering data held by government departments and by the support bodies that process it for them — the organisational and institutional arrangements, the control of entrusted work, which is where government data most often leaves the government, the protection applied at each stage from collection and storage through transmission, provision and public disclosure to destruction, the risk assessment and monitoring, the incident reporting, and the compliance evaluation indicators. First edition, with the automated decision making standard GB/T 45392-2025. In force from 1 October 2025. Issued on 28 March 2025, it has been in force since 1 October 2025.
Document preview — GB/T 45396-2025
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- PrefaceIII
- 1 Scope1
- 2 Normative references1
- 3 Terms and Definitions1
- 4 Government Data Processing Security Framework1
- 5 Safety system requirements2
- 5.1 Organizational guarantee2
- 5.2 Institutional System4
- 5.3 Entrusted Management4
- 5.4 Personal Information Protection5
- 6 Safety technical protection requirements5
- 6.1 Data Collection5
- 6.2 Data Storage6
- 6.3 Data Usage6
- 6.4 Data Processing6
- 6.5 Data Transmission6
- 6.6 Data provision7
- 6.7 Data Disclosure7
- 6.8 Data Destruction7
- 7 Safety operation management requirements8
- 7.1 Basic Environment8
- 7.2 Data Processing8
- 7.3 Compliance Assessment8
- 7.4 Risk Assessment8
- 7.5 Risk Monitoring8
- 7.6 Situational Awareness9
- 7.7 Early warning notification9
- 7.8 Emergency Response9
- 7.9 Incident Reporting9
- 7.10 Origin Analysis9
- 7.11 Security Audit9
- 7.12 Social Supervision9
- Appendix A (Informative) Government Data Security Compliance Assessment Methods and Evaluation Indicators10
- A.1 Government Data Security Compliance Assessment Methods10 A.2 Government Data Security Compliance Evaluation Indicators12 Reference23
Foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.
Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.
This document was proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260).
This document was drafted by: National Information Center, Jiangxi Big Data Center, Sangfor Technologies Co., Ltd., Guizhou Information Center, Institute of Information Engineering, Chinese Academy of Sciences, Guangdong Provincial Government Services and Data Management Bureau, Zhejiang Provincial Data Bureau, Zhejiang Provincial Big Data Development Center, Anhui Big Data Center, Wuxi Data Bureau, Beijing Big Data Center, Zhejiang Development Information Security Evaluation Technology Co., Ltd., China Telecom Electronic Technology Standardization Institute, Qi'anxin Wangshen Information Technology (Beijing) Co., Ltd.
The main drafters of this document are: Xu Chunxue, Ren Fei, Luo Haining, Cheng Zidong, Luan Guochun, Song Botao, Tian Zhipan, Wang Pengbiao, Yu Xiaolei, Ma Zaiying, He Liming, Luo Huayang, Yu Jing, Luo Qiwei, Zhu Dian, Wang Hu, Zhao Chengyao, Zhao Zhangjie, Jiang Zihai, Wang Jun, Xu Xia, Li Ting, Xu Yujia, Bai Yuqiang.
Data security technology Government data processing security requirements
1 Scope
This document proposes a security framework for government data processing, specifies security system requirements, security technology protection requirements and security operation management requirements. Management requirements.
This document is applicable to regulating the government data processing activities of government departments and technical support institutions, as well as competent (supervisory) departments, third-party institutions, supervision and evaluation by the relevant agencies.
2 Normative references
GB/T 22239
GB/T 35273
GB/T 39477
GB/T 39786
3 Terms and definitions
The following terms and definitions apply to this document.
3.1 Government data government data
Data generated, collected and managed by government departments at all levels in the process of performing their duties in accordance with the law.
3.2
Organizations and individuals who independently decide on the purpose and method of processing government data in government data processing activities.
[Source. GB/T 43697-2024, 3.11, modified]
4 Security Framework for Government Data Processing
Based on the network security level protection of government data infrastructure, a government data processing security framework is proposed for government data processors.
The framework consists of three parts. security system specifications for government data processing, security technology protection, and security operation management, as shown in Figure 1.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 28 pages — is available in the English PDF.
Referenced standards
Normative references
- GB/T 22239Information security technology - Baseline for classified protection of cybersecurity
- GB/T 35273Information security technology—Personal information security specification
- GB/T 39477Information security technology—Government information sharing—Data security technology requirements
- GB/T 39786Information security technology—Baseline for information system cryptography application
Editions of GB/T 45396
| Edition | Title | Revision | Status |
|---|---|---|---|
| GB/T 45396-2025 | Data security technology - Security requirements for government data processing | current edition | Current |
This page sells the current edition, GB/T 45396-2025. Earlier editions are listed for reference only.
How to Buy GB/T 45396-2025
- 1Add to cart. Click the "Buy GB/T 45396-2025" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 22239-2019 — Information security technology - Baseline for classified protection of cybersecurity
GB/T 35273-2020 — Information security technology—Personal information security specification
GB/T 39477-2020 — Information security technology—Government information sharing—Data security technology requirements
Secure payment via Stripe
Payments accepted
GB/T 45396-2025
$500.00