Valid

GB/T 45404-2025Data security technology — Requirements for large Internet companies internal personal information protection supervision agency (English PDF)

数据安全技术 大型互联网企业内设个人信息保护监督机构要求

Open the GB/T 45404-2025 preview as PDF

Preview — first pages of GB/T 45404-2025 (full document: 17 pages)

This is a limited preview

Buy now to download the full PDF (17 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

March 28, 2025

Implementation date

October 1, 2025

Scope

GB/T 45404-2025 is the English-translated version of 数据安全技术 大型互联网企业内设个人信息保护监督机构要求.

GB/T 45404-2025 is the Chinese national standard covering the body a large Internet platform sets up to supervise its own handling of personal information — the composition and the duties of the director, deputy director and secretary, the external members and their nomination and appointment, the internal members and their term, the general and special supervision, the meetings and the deferral of a vote, and the guarantees of independence without which an internal body only reviews its own employer. First edition, in force from 1 October 2025. Issued on 28 March 2025, it has been in force since 1 October 2025.

Document preview — GB/T 45404-2025

National Standard of the People's Republic of China

ICS
35.030
Classification
L 80

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • Preface... III 1 Scope1
  • 2 Normative references1
  • 3 Terms and Definitions1
  • 4 Composition of the Personal Information Protection Supervisory Body1
  • 4.1 Personnel Composition1
  • 4.2 Director, Deputy Director and Responsibilities2
  • 4.3 Secretary and Responsibilities2
  • 5 Members of the Personal Information Protection Supervisory Body2
  • 5.1 Requirements for external members2
  • 5.2 Nomination and appointment of external members3
  • 5.3 Performance of duties by external members4
  • 5.4 Selection and term of office of internal members4
  • 5.5 Performance of duties by internal members5
  • 6 Responsibilities of the Personal Information Protection Supervisory Agency5
  • 6.1 General Supervision5
  • 6.2 Supervision of special matters6
  • 6.3 Suggestions and comments7
  • 7 Working Mechanism of Personal Information Protection Supervisory Institutions7
  • 7.1 General requirements7
  • 7.2 Extraordinary Meeting8
  • 7.3 Postponement of meeting and deliberation9
  • 7.4 Postponement of voting9
  • 7.5 Guaranteeing independence in performance of duties9
  • 7.6 Guarantee of conditions for performance of duties9
  • 7.7 Formulation of work rules9
  • References10

Foreword

This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting is required.

Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.

This document was proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC 260).

This document was drafted by: Renmin University of China, China Academy of Information and Communications Technology, Beijing Institute of Technology, China Electronics Technology Standardization Research Institute Institute of Cyberspace Affairs, China Institute of Cyberspace Affairs, National Information Technology Security Research Center, Ant Group Co., Ltd., Alibaba (Beijing) Software Service Co., Ltd., Beike Real Estate (Beijing) Technology Co., Ltd., Beijing Xiaoju Technology Co., Ltd., Beijing Douyin Information Services Co., Ltd., Shanghai Dewu Information Group Co., Ltd., Beijing Jingdong Shangke Information Technology Co., Ltd., Beijing Baidu Netcom Technology Co., Ltd.

Company, Huawei Terminal Co., Ltd., Beijing Xiaomi Mobile Software Co., Ltd., Beijing Weimeng Chuangke Network Technology Co., Ltd., Yuncong Technology Group Group Co., Ltd., Zhejiang University, Shanghai SenseTime Intelligent Technology Co., Ltd., Honor Terminal Co., Ltd., National Computer Network Emergency Response Technology Co., Ltd.

Zhejiang Branch of the Technical Processing Coordination Center, Shenzhen Wangan Computer Security Testing Technology Co., Ltd., Beijing Qihoo Technology Co., Ltd., Qiming Xingchen Information Technology Group Co., Ltd.

The main drafters of this document are: Zhang Xinbao, Ge Xin, Chen Qi, Hong Yanqing, Chen Te, Chen Tian, Yao Xiangzhen, Lu Lei, Jiang Wei, Yan Hui, He Yanzhe, He Bo, Wang Hui, Tian Shen, Nie Zhengjun, Bai Xiaoyuan, Sun Tie, Xu Rui, Wang Haitang, Guo Jianling, Gu Wei, Liu Aijing, Shi Yuzhen, Zhu Xuefeng, Liu Xiaocen, Li Weijing, Zhang Chao, Peng Jin, Liu Ke, Xu Yan, Shi Jingnan, Zhang Na, Chen Yifu, Huang Tianning, Zhang Xiangtuo, Gu Haiyan, Wang Lei, Fan Ye, Cui Lisha, Qin Xiaoxiao, Yi Qiang, Zhao Xiaona, Ren Kui, Liu Nan, Ma Junye, Pan Jie, Li Jun, Bai Yaxi, Zhao Gaohua, Yao Yinan, Wang Pu, Liu Jinfei, Wenlong, Xu Hao, Liang Rongrong, Li Ran, Li Li, Yang Tianshi, Zhang Yao.

Data security technology is installed in large Internet companies Requirements from the Personal Information Protection Supervisory Agency

1 Scope

This document specifies the requirements for large Internet companies to establish and operate personal information protection supervisory agencies, including The requirements include the establishment, responsibilities, working rules, and members of the personal information protection supervisory body.

This document applies to large Internet companies that establish and operate personal information protection supervisory bodies and conduct supervision, inspection, and assessment activities.

2 Normative references

GB/T 25069-2022

GB/T 35273-2020

3 Terms and definitions

The terms and definitions defined in GB/T 25069-2022 and GB/T 35273-2020 and the following apply to this document.

3.1 Large Internet company

Internet companies that provide important Internet platform services, have a huge number of users, and have complex business types.

3.2 Personal information protection supervision agency

The Internet companies established by large enterprises are mainly composed of external members, and they are responsible for their own legal and compliance with personal information protection and fulfillment of personal information protection obligations.

An institution that independently supervises the protection of personal information and its social responsibilities, and provides suggestions and opinions on improving the level of personal information protection.

3.3 external member of personal information protection supervision

agency Possess professional knowledge and skills in personal information protection, and have no ties with large Internet companies or their major shareholders that may hinder their independent Independent and objective judgment relationship, supervise the personal information protection of large Internet companies, and issue independent and objective suggestions and opinions.

External experts who hold any other position in a small Internet company.

4 Composition of the Personal Information Protection Supervisory Body

4.1 Personnel Composition

The personal information protection supervision body of a large Internet company should be composed of seven to fifteen internal and external members, of which external members should account for The ratio shall not be less than two-thirds, and internal members shall not exceed one-third.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 17 pages — is available in the English PDF.

Referenced standards

Editions of GB/T 45404

EditionTitleRevisionStatus
GB/T 45404-2025Data security technology - Requirements for large Internet companies internal personal information protection supervision agencycurrent editionCurrent

This page sells the current edition, GB/T 45404-2025. Earlier editions are listed for reference only.

How to Buy GB/T 45404-2025

  1. 1Add to cart. Click the "Buy GB/T 45404-2025" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
17 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 45404-2025

$305.00

$260.00for partners