GB/T 47469-2026Data security technology - Management guidance for smart mobile terminals on the personal information processing activities of mobile internet applications (English PDF)
数据安全技术 移动智能终端的移动互联网应用程序(App)个人信息处理活动管理指南
Open the GB/T 47469-2026 preview as PDF
This is a limited preview
Buy now to download the full PDF (24 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
April 30, 2026
Implementation date
November 1, 2026
Scope
GB/T 47469-2026 is the English-translated version of 数据安全技术 移动智能终端的移动互联网应用程序(App)个人信息处理活动管理指南.
GB/T 47469-2026 is the Chinese national standard covering what the phone itself should do about the apps on it - the permission model and its granularity, the visibility given to the user of what an app is collecting, the limits the operating system enforces and the records it keeps. It puts the obligation on the terminal rather than only on the app, which is where it can actually be enforced. First edition, in force since 1 November 2026. It was issued on 30 April 2026 and takes effect on 1 November 2026, as a first edition. The document is under the responsibility of the Standardization Administration of China. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.
Document preview — GB/T 47469-2026
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- 5 General Principles
- 7.2 Transparent Display
- 7.3 Management of Personal Information Processing Behavior
- 7.4 App Lifecycle Management
Foreword
This document complies with the provisions of GB/T 1.1-2020 "Standardization Work Guidelines Part
1.Structure and Drafting Rules of Standardization Documents". Drafting. Please note that some content in this document may involve patents. The issuing organization of this document assumes no responsibility for identifying patents. This document was proposed and is under the jurisdiction of the National Cybersecurity Standardization Technical Committee (SAC/TC260). This document was drafted by: Huawei Technologies Co., Ltd., China Electronics Technology Standardization Institute, and National Computer Network Emergency Response Technical Team/Coordination Center. Coordination Center, China Cybersecurity Review, Certification and Market Supervision Big Data Center, Bodin Shihua (Beijing) Technology Co., Ltd., OPPO Guangdong Mobile Communications Corporation Limited, Vivo Mobile Communications Co., Ltd., Ant Group Co., Ltd., Beijing Baidu Netcom Technology Co., Ltd. Tongdun Technology Co., Ltd., Zhengzhou Xinda Jiean Information Technology Co., Ltd., Beijing Qihoo Technology Co., Ltd., Beijing Kuaishou Technology Co., Ltd. The company, Daily Interactive Co., Ltd., Beijing Momo Technology Co., Ltd., Beijing Shuanxing Technology Co., Ltd., and Wuhan Antiy Information Technology Co., Ltd. Limited Liability Company, Venustech Information Technology Group Co., Ltd., Beijing Wodong Tianjun Information Technology Co., Ltd., Guangdong Midea Refrigeration Equipment Equipment Co., Ltd., Alibaba (Beijing) Software Service Co., Ltd. The main drafters of this document are. Yi Qiang, Hu Ying, Fan Hua, Ren Yan, He Yanzhe, Xue Chen, Liu Xing, Zhou Chenwei, Zhu Xuefeng, Dou Yu, and Zhang Bowen. Yang Minghui, Dong Ji, Li Teng, Jia Ke, Zhang Wei, Liu Xianlun, Yao Yinan, Lin Guanchen, Shi Yuzhen, Guo Jianling, Deng Ting, Tan Cheng, Zhao Feng, Ren Haifeng Luo Hongwei, Wang Xin, Dong Lin, Ye Xinjiang, Ji Shuai, Liu Yuhong, Chen Jialin, Yu Lina, Shi Jing, Zhai Shijun, Li Ran, Qi Jinye, Huang Tianning, Liu Aijing.
With the rapid development of the mobile internet, while mobile internet applications have brought convenience to people's lives, they have also posed challenges such as the collection of personal information. The problem lies in the collection and improper use of mobile smart terminals. As the carrier of mobile internet applications, mobile smart terminals provide processing capabilities for these applications. A management mechanism for personal information on mobile smart terminals can effectively promote the reasonable collection and use of personal information by mobile internet applications. Personal information. To protect the legitimate rights and interests of mobile smart terminal users, this document, based on the fundamental principles of user awareness and control, proposes personal protection guidelines for mobile smart terminals. Information protection management measures to enhance the level of personal information protection in mobile internet applications. Data security technology for mobile smart terminals Internet application (App) personal information processing Event Management Guide
1.Scope This document provides recommendations for personal information protection management measures for mobile smart terminals. This document is intended to guide mobile smart terminal providers in designing and developing personal information protection features.
4.Abbreviations The following abbreviations apply to this document. App. Application IMEI. International Mobile Equipment Identity MAC. Media Access Control WLAN. Wireless Local Area Network
5 General Principles
5.1 Scope of Personal Information on Mobile Smart Terminals Mobile smart terminal personal information refers to the personal information that an app can obtain through a mobile smart terminal, including information stored on the mobile smart terminal device. Personal information stored or collected through mobile smart terminal devices, such as contacts, call logs, text messages, and media information (such as pictures, audio, and video). (Frequency), device identifier, local number, application list, location, network access information, etc.
5.2 Basic Principles for Personal Information Security Management of Mobile Smart Terminals The principles for managing personal information on mobile smart terminals include.
a) User awareness. The App records and notifies the User of the processing of personal information on the mobile smart terminal in a reasonable manner, so that the User has a clear understanding of the App's processing methods. The behavior of processing personal information on mobile smart terminals can be used to determine this;
b) User controllability. Provides a mechanism for users to manage their personal information on mobile smart terminals, allowing users to either allow or refuse access to their personal information. deal with;
c) Security Measures. Provide security mechanisms such as secure storage for personal information processed by the App on mobile smart terminals to prevent attackers from accessing the app. Attacking mobile smart terminals by means of tampering or theft;
d) Meticulous Management. Implementing fine-grained management measures for sensitive personal information on mobile smart terminals;
e) Appropriate Management. Mobile smart terminals shall manage personal information on mobile smart terminals using reasonable means to avoid interfering with users and negatively impacting their lives. To ensure the normal operation of the app;
f) Clear rules. The rules for managing personal information on mobile smart terminals must be clear and explicit.
6.Personal Information Security Risks of Mobile Smart Terminals The main risks to personal information security on mobile smart terminals include the following.
a) Risk of misuse of personal information due to collection without user knowledge. Apps running on mobile smart terminals may collect personal information in an unreasonable manner. Collecting personal information from mobile smart terminals without the user's knowledge or consent in business scenarios, and without the mobile smart terminal providing the user with [certain information/resources]. Effective prompts or behavior display mechanisms.
b) Risk of harm to user rights due to users' weak control over their personal information. Mobile smart terminals do not protect users' personal information. The lack of effective control measures prevents apps from collecting users' personal information beyond their scope or frequency, or from engaging in coercion, inducement, or fraud. The risk of users consenting to the collection of personal information from mobile smart terminals is increasing, which infringes on users' personal information rights.
c) Personal information security risks arising from key stages of the App lifecycle. Apps running on mobile smart terminals, their installation, launch... The processes of updating, uninstalling, and other operations on mobile smart terminals may pose security risks to personal information, including but not limited to. 1) During the installation phase, an app that poses a risk of stealing user personal information was installed without the user's authorization; 2) During the startup phase, the app may automatically start or be launched by an associated entity without the user's knowledge, potentially resulting in the app not being used after startup. Risks associated with users consenting to the processing of their personal information; 3) During the update phase, the app may introduce vulnerabilities or viruses, leading to the risk of unauthorized collection and use of personal information; 4) If personal information is not deleted in time during the uninstallation process, there is a risk that the personal information may be maliciously used by other apps.
7.Measures for the Management of Personal Information Processing on Mobile Smart Terminals
7.1 Classification of Management Measures for Personal Information Processing on Mobile Smart Terminals Based on the different levels of personal information protection for mobile smart terminals, the management measures for processing personal information on mobile smart terminals are divided into two categories. There are two levels. Basic and Enhanced. Enhanced management measures are indicated in bold.
7.2 Transparent Display
7.2.1 Notice Regarding the Collection and Use of Personal Information During periods when an app continuously or frequently requests permissions that allow the collection of personal information (such as microphone, camera, and location permissions), the mobile smart terminal... Prompt users through methods such as displaying icons. When displaying icons, the following elements should be considered.
a) Display method. Displayed in a prominent position on the screen, including but not limited to the status bar at the top of the screen, a colored icon in the corner, or a drop-down menu. Column display, etc.;
b) Timing of notification display. When the app is running in the foreground and background, the user is notified that the app is using permissions that allow the collection of personal information;
c) Brief Explanation of Logo Meaning. Provide users with a brief explanation of the logo's meaning;
d) Permission Query and Adjustment. Allows users to query the names of apps that are currently using permissions to collect personal information, and to grant permissions accordingly. The status needs to be adjusted.
Note. Frequent calls refer to calls made at short intervals, resulting in a continuous call effect.
7.2.2 Records of Personal Information Collection and Use Mobile smart terminals record the personal information collected and used by apps, and provide statistical and query interfaces for users. The system provides a clear overview of how personal information is collected and used, and the behavioral records take into account the following factors.
a) Recorded actions include, but are not limited to. 1) Read location information, read contacts, read media information (such as pictures, audio and video), read text messages, and read biometric information. Data collection, reading unique device identifiers (such as IMEI, WLAN MAC address), reading call logs, accessing the microphone, Camera, background screenshot/screen recording behavior; 2) App auto-start and associated startup behaviors; 3) Record the behavior of reading the application list and reading clipboard information.
b) Display of recorded information, including but not limited to. 1) When statistics are based on total volume, the displayed information includes the App name, the behavior name, and the total volume data; 2) When counting actions by frequency, the displayed information is either the last detail or the details for each individual action. The details include the App name, The action name, action start time (time precision at least in minutes), and the current app version should be displayed in an appropriate location. information; 3) If the app frequently reads location and media information, to avoid displaying a large amount of invalid information to the user, the last... For a single detail or the total amount within a certain period, other behaviors should display details for each instance.
c) The mobile smart terminal shall retain information about the user's collection and use of the mobile smart terminal's personal data for no less than 7 days, depending on the terminal. Different configuration levels require setting reasonable save thresholds, or providing users with threshold adjustment functions.
7.2.3 Centralized display and management of personal information collection and usage behavior To facilitate users' access to and management of their personal information collection and usage, mobile smart terminals provide a centralized display of personal information collection data. A unified portal for collecting usage information and providing users with a platform to manage their personal information, including the following.
a) Mobile smart terminals provide a unified entry point in a prominent position in the second-level directory of the settings interface.
b) Displaying and managing content includes. 1) View the App's records of collecting and using personal information; 2) Provide a management interface related to personal information, such as permissions to collect personal information.
7.3 Management of Personal Information Processing Behavior
7.3.1 Personal Information Authorization Management Mobile smart terminals provide different levels of authorization for personal information management, including the purpose of permission requests for collecting personal information. The surface provides corresponding mechanisms, including.
a) Single-use authorization method. When the app requests location access, camera access, or microphone access, authorization is granted to the user for this single use. The mechanism requires that when a user restarts the app and uses location, camera, or microphone-related functions, the user's location data needs to be retrieved again. Authorization;
b) Authorization methods permitted only during use. When the app requests location access, camera access, or microphone access, provide the user with... An authorization mechanism that allows access only when the app is running in the foreground; Note
1.Foreground running status refers to the application or application process being a task currently known to the user.
c) Editable Permission Request Purpose. Supports editing the purpose description of permission requests to collect personal information during the App development stage. Please display the permission to collect personal information in the pop-up window;
d) Automatic permission reset mechanism. When a user has not used an app for an extended period (e.g., 3 months), the system will automatically reset the permissions of the app. The ability to reset the permission to collect personal information to an unauthorized state; when an app uses the permission to collect personal information again, it must... Regain user authorization. Note
2.Users can manually enable or disable the automatic permission reset function through the interactive interface.
7.3.2 Terminal Sensitive Behavior Management Mobile smart terminals provide management mechanisms such as prompts and access control for sensitive behaviors on the terminal, specifically including the following mechanisms. sensitive behaviors Examples of management measures are shown in Appendix A.
a) Application List Access Control. Mobile smart terminals manage the list of applications accessed by apps on the mobile smart terminal. In principle, an app obtains a list of applications with the user's authorization, and the authorization methods provided to the user include always allow and deny.
b) Clipboard information access control may employ one or more of the following mechanisms. 1) When the App reads clipboard information without being actively triggered by the user, prompt the user. 2) Mobile smart terminals manage clipboard information, and apps access clipboard information with user authorization.
c) Screenshot Control Mechanism. Mobile smart terminals provide a screenshot management mechanism, which can be invoked by the App with user authorization. Screenshot function.
d) Location information access control mechanism. 1) Mobile smart terminals manage the location information obtained by apps on the mobile smart terminal, provided the app has user authorization. Get location information; 2) Mobile smart terminals provide users with the option to grant apps access to precise location information; users may not allow apps to obtain precise location information. When obtaining location information, the app obtains approximate location information with a certain offset.
e) Mobile smart devices restrict the ability of apps to activate the microphone in the background.
f) Mobile smart terminals restrict the ability of apps to launch the camera in the background.
7.4 App Lifecycle Management
7.4.1 App Installation Management The following management measures are implemented for app downloads and installations on mobile smart terminals.
a) Install the app only after obtaining the user's consent to prevent malicious silent installation without the user's knowledge;
b) Do not grant one-time authorization for permissions to collect personal information requested by the App;
c) Apps that require updates should be managed according to
7.4.2 App Auto-Start and Associated Startup Management Mobile smart terminals provide users with the ability to disable app auto-start and associated startup, preventing unauthorized startup without user consent.
Note. Associated startup refers to the behavior of an application being launched and run without the user's knowledge.
7.4.3 App Uninstallation Management When an app is uninstalled, the mobile smart terminal provides a mechanism to completely delete personal information in the app's private storage directory.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 24 pages — is available in the English PDF.
How to Buy GB/T 47469-2026
- 1Add to cart. Click the "Buy GB/T 47469-2026" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 47469-2026
$260.00