GB/T 46903-2025Data security technology - Personal information protection compliance audit requirements (English PDF)
数据安全技术 个人信息保护合规审计要求
Open the GB/T 46903-2025 preview as PDF
This is a limited preview
Buy now to download the full PDF (52 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
December 31, 2025
Implementation date
July 1, 2026
Scope
GB/T 46903-2025 is the English-translated version of 数据安全技术 个人信息保护合规审计要求.
GB/T 46903-2025 is the Chinese national standard covering auditing an organisation's handling of personal information - the lawful basis and consent, the minimisation and retention, the sharing and cross-border transfer, the rights of the individual and the security measures, with the evidence an auditor collects for each. China's personal information law requires these audits, and this is what the auditor works from. First edition, 25,000 words. It was issued on 31 December 2025 and has been in force since 1 July 2026, as a first edition. The document is under the responsibility of the Standardization Administration of China. This page is published from the official record of the 2025 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.
Document preview — GB/T 46903-2025
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- 1.Scope1
- 2 Normative References1
- 3.Terms and Definitions1
- 4.Principles and General Requirements for Personal Information Protection Compliance Audits2
- 4.1 Compliance Audit Principles2
- 4.2 Requirements for Conducting Compliance Audits2
- 5.1 Overview7
- 5.2 Audit Preparation Phase8
- 5.3 Audit Implementation Phase10
- 5.4 Audit Report Stage11
- 5.5 Problem Rectification Phase12
- 5.6 Archiving Management Phase12
- 6.Content and Methods of Personal Information Protection Compliance Audit12
- 6.1 Legality of Personal Information Processing Activities12
- 6.2 Normative Standards for Personal Information Processing Rules14
- 6.4 Processing personal information jointly with other personal information processors17
- 6.5 Entrusted processing of personal information17
- 6.7 Providing personal information processed by other personal information processors19
- 6.8 Utilizing automated decision processing for personal information19
- 6.9 Disclosure of Personal Information Based on Individual Consent21
- 6.10 Install image collection and personal identification devices in public places.22
- 6.11 Processing publicly disclosed personal information23
- 6.12 Processing Sensitive Personal Information24
- 6.15 Status of Protection of the Right to Deletion of Personal Information28
- 6.16 Protecting Individuals' Rights in Personal Information Processing Activities30
- 6.17 Respond to individuals and explain their personal information processing rules31
- 6.18 Internal Management System and Operating Procedures for Personal Information Protection31
- 6.19 Safety Technical Measures34
- 6.20 Development and Implementation of Education and Training Plans35
- 6.21 Personal Information Protection Officer35
- 6.22 Impact Assessment on Personal Information Protection37
- 6.23 Emergency Response Plan for Personal Information Security Incidents38
- 6.24 Emergency Response and Handling of Personal Information Security Incidents38
- 6.25 Large Internet Platform Rule39
- 45 References48
Foreword
This document complies with the provisions of GB/T 1.1-2020 "Standardization Work Guidelines Part
1.Structure and Drafting Rules of Standardization Documents". Drafting. Please note that some content in this document may involve patents. The issuing organization of this document assumes no responsibility for identifying patents. This document was proposed and is under the jurisdiction of the National Cybersecurity Standardization Technical Committee (SAC/TC260). This document was drafted by: China Electronics Technology Standardization Institute, and the Data and Technology Support Center of the Cyberspace Administration of China (CAC). China Electronics and Information Industry Development Research Institute, China Academy of Information and Communications Technology, National Computer Network Emergency Response Technical Team/Coordination Center, National Information Center Information Technology Security Research Center, Third Research Institute of the Ministry of Public Security, Tsinghua University, Nanjing Audit University, Beijing Kuaishou Technology Co., Ltd., Ant Technology Group Co., Ltd., Beijing Douyin Information Service Co., Ltd., Shenzhen Tencent Computer Systems Co., Ltd., Lenovo (Beijing) Co., Ltd. Company, Taotian Co., Ltd., Beijing Xiaoju Technology Co., Ltd., Beijing Shidai Xinwei Information Technology Co., Ltd., Huawei Technologies Co., Ltd., Beijing Volcano Engine Technology Co., Ltd., Guangxi Power Grid Co., Ltd., Alibaba Cloud Computing Co., Ltd., Honor Terminal Co., Ltd., and Mashangxiao. Fei Financial Co., Ltd., and Guangzhou Nansha Smart City Big Data Co., Ltd. The main drafters of this document are. Yao Xiangzhen, Hu Ying, Liu Xing, Gao Chao, Hao Chunliang, Wang Zhicheng, Guo Zhenhuan, Zhao Li, Yan Xiaoli, Li Anlun, and Gao Yue. Min Dong, Yang Lingling, Chen Yang, Yi Li, Yang Tao, Liu Xize, Li Zhuojun, Wang Jun, Zou Xiang, Chen Bing, Liu Yun, Yu Xiaobing, Luo Hongwei, Wang Xin, Bai Xiaoyuan Shi Yuzhen, Tian Shen, Li Yijing, Zhang Yanan, Mao Anna, Zhang Xin, Jia Yumeng, Gu Wei, Lu Yan, Sun Tie, Xu Rui, Wang Xinjie, Yi Qiang, Ma Shuo, Zhou Yujie Liu Ying, Zhu Shiyang, Liang Zhezhe, Shi Yarong, Zhao Xiaona, Yin Danna, Li Honggang. Data security technology Personal information protection compliance audit requirements
1 Scope
GB/T 46903-2025 is the Chinese national standard covering auditing an organisation's handling of personal information - the lawful basis and consent, the minimisation and retention, the sharing and cross-border transfer, the rights of the individual and the security measures, with the evidence an auditor collects for each. China's personal information law requires these audits, and this is what the auditor works from. First edition, 25,000 words. It was issued on 31 December 2025 and has been in force since 1 July 2026, as a first edition. The document is under the responsibility of the Standardization Administration of China. This page is published from the official record of the 2025 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.
This document outlines the principles for personal information protection compliance auditing, and specifies the overall requirements, implementation procedures, and procedures for such audits. Content and methods. This document applies to personal information processors and professional organizations conducting personal information protection compliance audits.
2 Normative references
The contents of the following documents, through normative references within the text, constitute essential provisions of this document. Dated citations are not included. For references to documents, only the version corresponding to that date applies to this document; for undated references, the latest version (including all amendments) applies. This document.
GB/T 25069 Information Security Technical Terminology
GB/T 35273 Information Security Technology - Personal Information Security Specification
GB/T 45574 Data Security Technology - Security Requirements for the Processing of Sensitive Personal Information
3 Terms and Definitions
The terms and definitions defined in GB/T 25069 and GB/T 35273, as well as the following terms and definitions, apply to this document.
3.1 Supervision that reviews and evaluates whether personal information processors' personal information processing activities comply with laws and administrative regulations. Activity.
Note. This is abbreviated as compliance audit.
3.2 Possesses the capability to conduct personal information protection compliance audits, and has audit personnel, facilities, and funding commensurate with its services, enabling it to provide... Organizations that provide personal information protection compliance audit services.
Note. Abbreviated as professional organization.
3.3 auditor Among personal information processors or professional organizations, those with the capability to conduct compliance audits on personal information protection are responsible for assessing whether personal information processing activities are in compliance with regulations. Personnel who conduct independent reviews and evaluations in accordance with laws and administrative regulations.
3.4 Audit findings The facts, differences, risks, or issues that compliance auditors identify in relation to the auditee after performing audit procedures.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 52 pages — is available in the English PDF.
Referenced standards
How to Buy GB/T 46903-2025
- 1Add to cart. Click the "Buy GB/T 46903-2025" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 25069-2022 — Information security techniques—Terminology
GB/T 35273-2020 — Information security technology—Personal information security specification
GB/T 45574-2025 — Data security technology — Security requirements for processing of sensitive personal information
Secure payment via Stripe
Payments accepted
GB/T 46903-2025
$740.00