Valid

GB/T 46068-2025Data security technology — Security certification requirements for cross-border processing activity of personal information (English PDF)

数据安全技术 个人信息跨境处理活动安全认证要求

Open the GB/T 46068-2025 preview as PDF

Preview — first pages of GB/T 46068-2025 (full document: 16 pages)

This is a limited preview

Buy now to download the full PDF (16 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

August 29, 2025

Implementation date

March 1, 2026

Scope

GB/T 46068-2025 is the English-translated version of 数据安全技术 个人信息跨境处理活动安全认证要求.

GB/T 46068-2025 is the Chinese national standard covering the certification route for sending personal information out of China — the binding agreement between the parties and the responsibilities it must allocate, the organisational and technical measures required of the overseas recipient, the impact assessment, the data subject's rights and how they are exercised abroad, and what the certification body checks. Certification is one of the three lawful routes for a cross-border transfer, and this is the standard the certifier works to. First edition, in force from 1 March 2026. Issued on 29 August 2025, it has been in force since 1 March 2026.

Document preview — GB/T 46068-2025

National Standard of the People's Republic of China

ICS
35.030
Classification
L 80

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • PrefaceIII
  • 1 Scope1
  • 2 Normative references1
  • 3 Terms and Definitions1
  • 4 Basic Principles2
  • 5 Basic Requirements2
  • 6 Requirements for protecting the rights and interests of personal information subjects5
  • Appendix A (Informative) Typical Cross-border Processing Scenarios of Personal Information7
  • Appendix B (Informative) Personal Information Protection Impact Assessment Report Template10
  • Reference17

Foreword

This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.

Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.

This document is proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260).

This document was drafted by: China Certification and Certification (Beijing) Technology Service Co., Ltd., China Cybersecurity Review and Certification and Market Supervision Big Data Center Center, Central University of Finance and Economics, China Electronics Standardization Institute, National Computer Network Emergency Response Technical Processing Coordination Center, National Information Technology Security Research Center, Beijing Branch of National Computer Network and Information Security Management Center, China Software Evaluation Center, China Electronics Technology Group Corporation Network Security Technology Co., Ltd., Tsinghua University, University of Science and Technology of China, Cybersecurity Management Center of Beijing Municipal Bureau of Economy and Information Technology, Beijing Kuaishou Technology Co., Ltd., Beijing UnionPay Gold Card Technology Co., Ltd., Huawei Technologies Co., Ltd., Ant Technology Group Co., Ltd., Sangfor Technologies Technology Co., Ltd., Alibaba (Beijing) Software Services Co., Ltd., Beijing Baidu Netcom Technology Co., Ltd., Qi'anxin Technology Group Co., Ltd. Co., Ltd.

The main drafters of this document are: Bunin, Chen Shixiang, Wang Fengjiao, Zhang Jinping, Hu Ying, Wang Hui, Sun Xiaoli, Chen Qi, Shi Dawei, Chen Te, Chen Liang, Yang Ting, Yan Hui, Wang Yalu, Lu Lei, Li Haidong, Jin Tao, Zuo Xiaodong, Huo Ran, Li Yuan, Li Anlun, Luo Hongwei, Cheng Yuqi, Duan Jinghui, Fan Hua, Wang Huili, Zheng Zheng, Zheng Yunwen, Bai Xiaoyuan, Ye Runguo, Li Zihan, Liu Bin, Yu Yuanyuan, Dong Hualing, Guo Jianling, Liu Qianwei, and Wu Mengting. Data security technology Security certification requirements for cross-border processing of personal information

1 Scope

This document stipulates the basic principles and requirements that relevant parties must comply with when processing personal information across borders, as well as the protection of the rights and interests of personal information subjects. Require.

This document is applicable to parties involved in cross-border processing of personal information to regulate their cross-border processing of personal information, and is also applicable to competent authorities, Third-party organizations and other organizations supervise, manage, certify and evaluate the cross-border processing of personal information by personal information processors.

2 Normative references

GB/T 35273-2020

3 Terms and Definitions

The following terms and definitions apply to this document.

3.1 Personal information

Any information relating to an identified or identifiable natural person recorded electronically or otherwise.

Note. Anonymized information is not included.

3.2 information

Once leaked or used illegally, it is easy to cause the personal dignity of natural persons to be violated or the personal and property safety to be endangered.

Note. This includes biometrics, religious beliefs, specific identities, medical health, financial accounts, whereabouts, and personal information of minors under the age of fourteen.

3.3 [Source. GB/T 35273-2020, 3.3]

The natural person identified or associated with the personal information.

3.4

An organization that independently determines the purpose and method of processing personal information.

3.5 overseas recipient

Organizations or individuals located outside the People's Republic of China that receive and process personal information from personal information processors.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 16 pages — is available in the English PDF.

Referenced standards

Editions of GB/T 46068

EditionTitleRevisionStatus
GB/T 46068-2025Data security technology - Security certification requirements for cross-border processing activity of personal informationcurrent editionCurrent

This page sells the current edition, GB/T 46068-2025. Earlier editions are listed for reference only.

How to Buy GB/T 46068-2025

  1. 1Add to cart. Click the "Buy GB/T 46068-2025" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
16 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 46068-2025

$290.00

$245.00for partners