Valid

GB/T 47532-2026Application software distribution platforms - Specification for service and management (English PDF)

移动应用分发平台 服务和管理规范

Open the GB/T 47532-2026 preview as PDF

Preview — first pages of GB/T 47532-2026 (full document: 51 pages)

This is a limited preview

Buy now to download the full PDF (51 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

April 30, 2026

Implementation date

August 1, 2026

Scope

GB/T 47532-2026 is the English-translated version of 移动应用分发平台 服务和管理规范.

GB/T 47532-2026 is the Chinese national standard covering the app store as a regulated service - the review of applications before listing, the identification of the developer, the permissions and the disclosure of what an app collects, the handling of complaints and the removal of an application. First edition, in force since 1 August 2026. It was issued on 30 April 2026 and has been in force since 1 August 2026, as a first edition. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

Document preview — GB/T 47532-2026

National Standard of the People's Republic of China

ICS
35.030
Classification
L 70

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 1 Scope
  • 2 Normative references
  • 5 Mobile application distribution platform service requirements
  • 6 Management Requirements
  • 6.4 Remedial Measures
  • 7 Personal Information Protection Requirements
  • 8 Evaluation Methods
  • 8.3 Evaluation Method
  • 8.4 Evaluation Process

2 Normative references

This document has no normative references.

4.Service and Management Processes Mobile application distribution platforms, as a key component of the mobile application ecosystem, assume the role and responsibility of application distributors, and their services... The business and management processes should conform to Figure 1. Figure

5 Mobile application distribution platform service requirements

5.1 Overview This chapter primarily clarifies the requirements for mobile application distribution platforms in providing services to users and developers/operators. Through full public... Specific requirements such as notification, complaint handling, and training empowerment are implemented to promote the platform to provide a transparent, secure, and reliable application access environment, thereby enhancing the platform's credibility. Confidence and satisfaction.

5.2 Full announcement Mobile application distribution platforms should meet the following full disclosure requirements.

a) Mobile application distribution platforms should publicly disclose all apps or mini-programs;

b) Mobile application distribution platforms should clearly display the accurate name of the app or mini-program, a brief description of its functions, and the developer and operator on the distribution page. Version number, permission list, personal information processing rules, and other related information; Note

1.If the APP or mini-program does not involve the above information, it may not be displayed. Note

2.The display format of personal information processing rules includes, but is not limited to, text, links, etc.

c) Mobile application distribution platforms should ensure consistency in display style and should not differentiate based on factors such as the developer's/operator's identity or market position. treat;

d) Mobile application distribution platforms should classify apps or mini-programs by age and provide age classification labels.

5.3 Complaints and Appeals Mobile application distribution platforms should establish appeal and complaint channels, with the following specific requirements.

a) Mobile application distribution platforms should provide user feedback channels, establish processes for handling user complaints, reports, and comments, and address user feedback issues. Verify the problematic app or mini-program;

b) Mobile application distribution platforms should explain to developers and operators the reasons why their apps or mini-programs failed the review process, and provide them with relevant information. An appeal channel should be established to promptly address any objections raised by developers and operators regarding the review results.

c) Mobile application distribution platforms should, upon receiving complaints or grievances regarding their own personal information protection and user rights protection, promptly... We will accept and follow up on these cases promptly.

5.4 Training and Empowerment Mobile application distribution platforms should guide and supervise apps or mini-programs by issuing guidance documents, launching training courses, and opening up testing capabilities. App developers and operators should enhance their awareness and ability to protect personal information.

6 Management Requirements

6.1 Overview This chapter primarily clarifies the responsibilities and requirements of mobile application distribution platforms in managing the application distribution process, including their responsibilities to developers and operators. The app or mini-program must fulfill its responsibilities regarding strict registration, review, monitoring, and handling. This includes specific measures such as information registration, review and testing, and handling procedures. The requirement is to ensure that apps and mini-programs distributed by the platform comply with laws, regulations, and platform rules, maintain a healthy order in the app distribution market, and safeguard [the rights and interests of users]. The platform operates healthily and stably.

6.2 Information Registration Mobile application distribution platforms should meet the following information registration requirements.

a) Mobile application distribution platforms should register and retain relevant information about apps or mini-programs for no less than 60 days; 1) The app should retain the following information. name, version number, package name, developer/operator, permission list, personal information processing rules, launch date, and functions. Information such as brief introduction, purpose, MD5 hash value, and registration number; 2) Mini-programs should retain the following information. name, developer/operator or their authorized entity, list of authorized entities, personal information processing rules, and launch details. Information such as room, function description, and filing number;

b) Mobile application distribution platforms should accurately register and verify the main information of the developers and operators of the APP or mini-program, including the developer and operator information. Information such as name, contact information, relevant industry qualifications and certifications, and types of services provided. The developer/operator is unable to provide entity information. Or the mobile application distribution platform may discover problems with the developer's/operator's information, such as changes in the developer's/operator's information. However, in cases such as failure to update in a timely manner or failure to notify users of the cessation of operations in a timely manner, the mobile application distribution platform may refuse its registration application or freeze its account. Delete the registered account. See the checklist of qualification documents required for mobile application distribution platforms to review APP or mini-program business types. Appendix A.

6.3 Audit and Testing Mobile application distribution platforms should conduct pre-listing review and testing of apps or mini-programs, and post-listing tracking and monitoring or periodic random testing. The content includes, but is not limited to, the following.

a) Conduct security audits, inspections, and monitoring of apps or mini-programs. 1) The app or mini-program should not contain viruses or Trojans, including those that steal information, maliciously deduct fees, or allow unauthorized remote control. Malicious behaviors include malicious propagation, excessive data usage, deception and fraud, system damage, and rogue behavior; these are the characteristics of malicious programs. See Appendix B for classification examples. 2) Apps or mini-programs should not obtain super user (root) privileges or contain root functions. 3) App or mini-program developers and operators should conduct developer authentication and signing for their developed apps or mini-programs to ensure the app or mini-program... The development of mini-programs is traceable and accountable. Apps or mini-programs with specific regulatory requirements should be developed accordingly. User authentication signature.

b) Review, test, and monitor the basic functions of the APP or mini-program. 1) Apps or mini-programs should not engage in malicious updates that bypass app store review processes, such as automatically updating basic application functions. New, requiring users to update immediately after downloading, or forcing users to update, etc. 2) Apps or mini-programs should not contain maliciously hidden or user-undetectable functions, such as hiding the app or mini-program icon. Processes, etc. 3) The basic function description of the APP or mini-program should not contain false advertising or misleading content. Example. Mosquito repellent apps or mini-programs claim to repel mosquitoes using ultrasound, electromagnetic waves, or other "high-tech" methods, but these claims lack scientific basis and are not supported by mobile phones. Without the necessary hardware, effective expulsion is impossible.

c) Review, test, and monitor paid features within the app or mini-program. 1) Apps or mini-programs should comply with relevant regulations such as clearly displaying prices, clearly indicating the charging standards and methods, and the content displayed should be truthful and accurate. The charges should be clear, conspicuous, and standardized, and users should confirm before deducting fees. There should be no malicious fee collection behavior. 2) If the main function of an app or mini-program requires paid activation, the app or mini-program should provide users with a free trial function or free experience. Verification version. 3) The paid usage terms for the app or mini-program should be consistent with the explicitly stated information, and there should be no other undisclosed terms remaining after payment. Usage conditions. 4) The app or mini-program should contain real and valid contact information, including but not limited to online customer service, phone numbers, and email addresses. This ensures that users can contact the administrator if they encounter payment or other issues.

Note. The verification methods include verifying the self-certification documents provided by the developer and operator.

d) To detect and monitor the protection of user rights in the APP or mini-program, including but not limited to acts that infringe upon user rights. The illegal collection of personal information, collection of personal information beyond the scope and frequency, illegal use of personal information, and forced use of targeted push notifications are all violations of regulations. Frequent self-starting and associated startup, deceptive and misleading coercive behavior, deceptive and misleading users to provide personal information, and unauthorized automatic renewal services. Fee-based services, setting up obstacles to account cancellation, etc.

e) Review, inspect, and monitor advertisements within the app or mini-program. 1) In-app or mini-program ads should not interfere with the functionality of other apps, mini-programs, or devices. Ads should only be displayed on the app or mini-program in that app. The advertisement displayed within the app or mini-program should not dominate the screen, including the lock screen and the unlocked desktop. Furthermore, when an app or mini-program is exited or closed, the advertisements within the app or mini-program should also be turned off. 2) Advertisements within the app or mini-program should be identifiable and distinguishable from other non-advertising information, and should not contain false or misleading content. The content that people misunderstand.

6.4 Remedial Measures

6.4.1 Basic Requirements Mobile application distribution platforms should promptly take appropriate measures to address problematic apps or mini-programs, and should retain records of removed apps. Or related information about the mini-program.

a) The app should retain the following information. name, version number, package name, developer/operator, permission list, personal information processing rules, launch date, and a brief description of its functions. Information such as description, purpose, MD5 hash, and registration number;

b) The mini-program should retain the name, developer/operator or its authorized entity, list of authorized entities, personal information processing rules, launch date, and functions. Information such as a brief introduction and registration number.

6.4.2 Self-disposal Mobile application distribution platforms should take timely action if they discover any of the following behaviors in an app or mini-program, including but not limited to.

a) If any app or mini-program does not meet the requirements of

6.3 during the app store review process, its app store application should be rejected;

b) If any app or mini-program is found to be non-compliant with requirement

6.3 after its release, measures such as notification for rectification and removal should be taken. Handling measures include suspending, deleting, disconnecting related application services, and freezing accounts;

c) For apps or mini-programs that have repeatedly violated regulations, such as those that refuse to rectify after multiple notices or that use technical means to circumvent review, they will be transferred to another app. App distribution platforms should take stricter measures as appropriate, such as removing apps from app stores or freezing accounts.

6.4.3 Coordinated handling Mobile application distribution platforms should promptly cooperate with regulatory authorities to take measures to address relevant apps or mini-programs, including but not limited to.

a) For apps or mini-programs that have been ordered to rectify or publicly notified, the relevant requirements should be promptly communicated, and technical guidance and other assistance should be provided to urge rectification. App or mini-program developers and operators must make rectifications;

b) Apps or mini-programs that have been removed from app stores should be removed from the platform promptly.

c) For apps, mini-programs, or developers/operators that have been subject to multiple rectifications, mobile application distribution platforms should, after the rectification period, appropriately... Training sessions and lectures on requirements interpretation and technical guidance will be conducted regularly, and subsequent management and monitoring will be strengthened.

7 Personal Information Protection Requirements

7.1 Organizational Structure Mobile application distribution platforms should meet the following organizational structure requirements.

a) Mobile application distribution platforms that process personal information in accordance with the requirements of the national cyberspace administration should clearly define their responsibilities for personal information protection. The person is responsible for making important decisions regarding personal information processing activities, fulfilling relevant duties, and providing resource support, including but not limited to providing... Provide human, financial, and material resources, and at the same time. 1) Publicly disclose the contact information of the person in charge of personal information protection; 2) Submit the name and contact information of the person in charge of personal information protection to the department responsible for personal information protection;

Note. For the definition and responsibilities of "departments performing personal information protection duties", please refer to Chapter VI of the Personal Information Protection Law of the People's Republic of China.

b) Mobile application distribution platforms that provide important internet platform services, have a large user base, and complex business types should be primarily established by external entities. An independent body composed of departmental members oversees the protection of personal information and regularly publishes a social responsibility report on personal information protection. The announcement will be subject to public scrutiny.

7.2 Management Mechanism Mobile application distribution platforms should establish and improve management mechanisms for the distributed application software, including but not limited to.

a) Mobile application distribution platforms should formulate platform management rules that clearly define how developers and operators of apps or mini-programs within the platform handle personal information. The obligation to regulate and protect personal information;

b) Mobile application distribution platforms should establish mechanisms for pre-approval, in-process monitoring, and timely handling of illegal and irregular activities, including. 1) Respond to complaints and appeals and provide feedback on the processing progress within a reasonable timeframe; 2) Conduct dynamic inspections of the APP or mini-program to ensure the authenticity and accuracy of the publicized information. Any discrepancies with the publicized information, or any instances of misuse, will be investigated and corrected. Unauthorized alterations to main functions, requested permissions, and the scenarios and scope of personal information collection and use through methods such as "hot updates" and "hot switches" Mobile application distribution platforms should cease providing services to apps or mini-programs that violate regulations, such as those found to be illegal.

c) Mobile application distribution platforms should establish mechanisms for developer/operator credit evaluation and risk warnings, and developer/operator credit evaluation indicators should be provided. See Appendix C for examples;

d) Mobile application distribution platforms should establish mechanisms to cooperate in implementing supervision and inspection, including. 1) Employees should not resist or fail to cooperate with supervision and inspection work; 2) Do not impersonate regulatory authorities to issue rectification requests or take other illegal actions; 3) Illegal or non-compliant apps or mini-programs should be removed from app stores promptly as required; 4) Developers or operators should not be prevented from actively rectifying the issues, such as by prohibiting updates or removing apps from app stores without justifiable reasons. 5) Cooperate with regulatory authorities in data reporting, monitoring and tracing, information sharing, and response and handling. 6) It is advisable to verify the APP developer's authentication signature and to clearly mark APPs with third-party authentication signatures; 7) It is advisable to authenticate and sign the distributed APP to ensure that the distribution behavior of the APP is traceable.

8 Evaluation Methods

8.1 Assessment Format The assessment methods include two categories. inspection and self-assessment. Inspection and assessment are conducted by regulatory authorities to evaluate the compliance of mobile application distribution platforms. Self-assessment involves mobile application distribution platforms evaluating their own services and management.

8.2 Assess relevant parties The stakeholders in the assessment are divided into the assessors and the assessed. The assessors refer to the entities conducting the assessment, including regulatory authorities and mobile application distribution platforms. In Taiwan, the assessor during inspection and evaluation is the regulatory authority; during self-assessment, the assessor is the mobile application distribution platform. The assessed party is the mobile application. Distribution platform.

8.3 Evaluation Method

8.3.1 Technical Testing The mobile application distribution platform is tested using various professional equipment and instruments to obtain accurate data and information.

8.3.2 On-site inspection The mobile application distribution platform was examined through on-site inspections and document review to obtain the actual situation.

8.4 Evaluation Process

8.4.1 Overview The evaluation process for mobile application distribution platform services and management should conform to Figure 2, including defining evaluation objectives, selecting evaluation indicators, and developing evaluation criteria. The process involves five activities. planning, implementation evaluation, and drawing evaluation conclusions.

8.4.2 Define the assessment objectives The determination of assessment objectives should be based on the assessment method and the implementing entity, and should be carried out in accordance with the following requirements.

a) In the case of self-assessment and its implementation by the assessed party, the assessed party should conduct the assessment based on business needs, compliance requirements, and risk management. It is necessary to independently determine the evaluation objectives; (b) In cases where the assessment is self-assessed and carried out by a third party commissioned by the assessed party, the assessed party should consult with the commissioned third-party organization. The evaluation objectives are defined, with the opinions of the evaluated party playing a primary role, while the professional advice provided by the third-party organization commissioned by the evaluated party can be offered.

c) In the case of inspection and assessment, the regulatory authority should take the lead in determining the assessment objectives, and the assessed party should cooperate and provide the necessary assistance. support.

8.4.3 Selection of Evaluation Indicators The evaluator should scientifically select evaluation indicators based on the evaluation objectives. The following requirements should be met when selecting evaluation indicators.

a) The evaluation indicators should be directly related to the evaluation objectives and be able to objectively reflect the actual situation of the evaluated party.

b) The evaluation indicators should be operable, including clearly defined indicators, available data, and quantifiable results.

c) The evaluation indicators should mainly refer to the specific requirements outlined in Chapters 5 through 7, including but not limited to. 1) Service requirements indicators, and the completeness and accuracy of full disclosure (such as APP name, function description, developer and operator information). (etc.), the effectiveness and timeliness of complaint and appeal channels, the breadth and practical effect of training and empowerment content; 2) Management requirements indicators, including the completeness and authenticity of information registration (such as the main information of the developer and operator, the basic information of the APP or mini-program). This information), the comprehensiveness and rigor of the audit and testing (such as security testing, functional testing, paid function testing, etc.), and the handling measures. The timeliness and effectiveness of the measures (such as taking down, deleting, or freezing accounts); 3) Personal information protection requirements and indicators, compliance of organizational structure (e.g., whether a person responsible for personal information protection has been appointed), management The soundness of the mechanism (e.g., whether platform rules have been formulated, and whether a credit rating mechanism has been established); 4) Dynamic monitoring indicators, including the proportion and frequency of regular spot checks on listed apps or mini-programs, and the detection and handling of violations. Efficiency.

8.4.4 Develop an evaluation plan The assessor should reasonably estimate the complexity and workload of the assessment work and develop a reasonable assessment plan. The assessment plan should include the following.

a) Assessment objects and scope, assessment indicators, assessment environment, and assessment tools;

b) Assess team member roles and responsibilities;

c) Evaluate the work plan, including work content and output results;

d) Time schedule.

8.4.5 Implementation Assessment The following requirements should be met when conducting the assessment.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 51 pages — is available in the English PDF.

How to Buy GB/T 47532-2026

  1. 1Add to cart. Click the "Buy GB/T 47532-2026" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
51 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 47532-2026

$500.00

$425.00for partners