GB/T 46071-2025Data security technology — Guidance on social responsibility of data security and personal information protection (English PDF)
数据安全技术 数据安全和个人信息保护社会责任指南
Open the GB/T 46071-2025 preview as PDF
This is a limited preview
Buy now to download the full PDF (33 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
August 29, 2025
Implementation date
March 1, 2026
Scope
GB/T 46071-2025 is the English-translated version of 数据安全技术 数据安全和个人信息保护社会责任指南.
GB/T 46071-2025 is the Chinese national standard covering what an organisation owes beyond compliance — the governance and the accountability, the transparency towards the people whose data it holds, the treatment of vulnerable groups and minors, the supply chain, the incident disclosure, and the reporting through which any of it can be judged from outside. At 20,000 words. First edition, in force from 1 March 2026. Issued on 29 August 2025, it has been in force since 1 March 2026.
Document preview — GB/T 46071-2025
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- PrefaceIII
- 1 Scope1
- 2 Normative references1
- 3 Terms and Definitions1
- 4 Abbreviations2
- 5 General Provisions2
- 6 Organizational Governance2
- 7 Compliance, Innovation and Value5
- 8 Fair Operations, Competition and Cooperation7
- 9 User Rights Protection10
- 10 Public Welfare Participation and Social Development1216
- 11 Disclosure of social responsibility performance1416
- Appendix A (Informative) Data Security and Personal Information Protection Social Responsibility Performance Evaluation Method16
- Appendix B (Informative) Data Security and Personal Information Protection Social Responsibility Practice Cases29
- Appendix C (Informative) Data Security and Personal Information Protection Social Responsibility Report Template34
- Reference36
Foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.
Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.
This document is proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260).
This document was drafted by: Beijing CESI Technology Development Co., Ltd., Institute of Information Engineering, Chinese Academy of Sciences, China Electronics Technology Standards China Cybersecurity Review and Certification and Market Supervision Big Data Center, Beijing Baidu Netcom Technology Co., Ltd., Beijing Kuaishou Technology Co., Ltd.
Technology Co., Ltd., Ant Technology Group Co., Ltd., National Information Technology Security Research Center, the Third Research Institute of the Ministry of Public Security, Shenzhen Saixixin Information Technology Co., Ltd., Beike Real Estate (Beijing) Technology Co., Ltd., Shanghai Hehe Information Technology Co., Ltd., and China Southern Power Grid Digital Grid Group Information and Communication Technology Co., Ltd., Tianyi Cloud Technology Co., Ltd., Honor Terminal Co., Ltd., Beijing Zero One Everything Technology Co., Ltd.
Company, Qitian Technology Group Co., Ltd., Beijing Douyin Information Service Co., Ltd., Alibaba (Beijing) Software Service Co., Ltd., Guangzhou Jingyuan Security Technology Co., Ltd., Beijing Tengyun Tianxia Technology Co., Ltd., Shanghai Shanyong Law Firm, Northwestern Polytechnical University, Shenzhen Wangan Computer Security Testing Technology Co., Ltd., Shenzhen National Financial Technology Evaluation Center Co., Ltd., Guangzhou Huya Technology Co., Ltd., Shanghai Feishu Shenno Digital Technology Group Co., Ltd., Tsinghua University, Beijing Qibao Industry and Economics Online Culture Media Co., Ltd., Guangzhou CESI Standard Testing and Research Institute Co., Ltd., Grandall Law Firm (Beijing), Beijing Topsec Network Security Technology Co., Ltd., Huaneng Information Technology Ltd.
The main drafters of this document are: He Yanzhe, Gao Neng, Li Min, Fan Hua, Zhu Xuefeng, Fan Kefeng, Luo Hongwei, Xu Yuna, Li Lin, Yang Tao, Meng Yaping, Bai Xiaoyuan, Guo Jianling, Zhang Chao, Li Shuilin, Zhao Ranran, Xuan Qi, Wang Haitang, Wang Fubiao, Song Hongyu, Li Weijing, He Gang, Chen Bin, Wu Yuesheng, Lu Bing, Peng Jin, Wang Xin, Xue Ying, Zou Qiuyang, Liu Aijing, Xu Huan, Xie Mi, Wang Ping, Long Jun, Cheng Yanhao, Wu Jiamei, Chen Shenzi, Wang Chuanyin, Zhang Youyi, Liao Chaohao, Ge Mengying, Wang Zhen, Huang Rong, Luo Feng, Xu Jing, Huang Liuyong, Du Haowen, Gao Chao, Sheng Xia, Zhang Dingshuang, Wang Mingyan, Zhang Mingying, Zhao Xiaona, Chen Xinyi, Liang Zhechen, Huang Shenghua, Li Zhengwei, Zhang Hui, Jing Gang, Su Yini, Han Shuo, Hu Jing, Qiu Jianzhong, and Su Li.
Data Security Technology Data Security and Personal Information Guidelines for Protecting Social Responsibility
1 Scope
This document provides organizational governance, compliance, innovation, and value system for organizations to implement their social responsibilities for data security and personal information protection.
Guidelines for the disclosure of social responsibility performance, fair operation, competition and cooperation, protection of user rights and interests, public welfare participation and social development, and social responsibility fulfillment.
This document is applicable to organizations carrying out activities related to data security and personal information protection social responsibility, and is also applicable to third-party evaluation groups.
The organization's fulfillment of its social responsibilities for data security and personal information protection.
2 Normative references
This document has no normative references.
3 Terms and Definitions
The following terms and definitions apply to this document.
3.1 social responsibility
An organization takes responsibility for the impact of its decisions and activities on society and the environment through transparent and ethical behavior. These behaviors.
— Committed to sustainable development, including the health of members of society and the well-being of society;
— Taking into account the expectations of stakeholders;
— Comply with applicable laws and be consistent with international norms of conduct;
— Be integrated into the entire organization and implemented in organizational relationships.
Note 1 to entry. Activities include products, services and processes.
Note 2 to entry. Organizational relationships refer to the activities of an organization within its sphere of influence.
[Source. GB/T 36000-2015, 3.16]
3.2 stakeholders
Individuals or groups whose interests may be affected by the decisions or activities of an organization.
[Source. GB/T 36000-2015, 3.13]
3.3 consumer
An individual who purchases or uses property, products, or services for personal use.
[Source. GB/T 36000-2015, 3.19]
3.4 employee
An individual who has established a labor relationship with an organization through a labor contract or has a de facto labor relationship with the organization.
[Source. GB/T 36000-2015, 3.20]
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 33 pages — is available in the English PDF.
Editions of GB/T 46071
| Edition | Title | Revision | Status |
|---|---|---|---|
| GB/T 46071-2025 | Data security technology - Guidance on social responsibility of data security and personal information protection | current edition | Current |
This page sells the current edition, GB/T 46071-2025. Earlier editions are listed for reference only.
How to Buy GB/T 46071-2025
- 1Add to cart. Click the "Buy GB/T 46071-2025" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 46071-2025
$590.00