One-sentence summary
GB/T 44588-2024 is China's first recommended national standard specifically addressing privacy policies of internet platforms, systematically specifying basic requirements, drafting procedures, content requirements, publication formats, and dispute resolution mechanisms for personal information processing rules. Issued September 29, 2024; effective April 1, 2025.
Standard Overview
| Item | Content |
|---|---|
| Standard No. | GB/T 44588-2024 |
| Standard Name | Data security technology—Personal information processing rules of internet platforms, products and services |
| Standard Status | Current (Issued September 29, 2024; Effective April 1, 2025) |
| Issuing Authority | State Administration for Market Regulation (SAMR), Standardization Administration of China (SAC) |
| Responsible Committee | National Technical Committee for Cybersecurity Standardization (SAC/TC 260) |
| Proposing Department | National Technical Committee for Cybersecurity Standardization (SAC/TC 260) |
| ICS | 35.030 |
| CCS | L80 |
Scope of Application
This document specifies requirements for basic requirements, drafting procedures, content, publication formats, and dispute resolution for personal information processing rules of internet platforms and product services.
This document applies to the process of operators of internet platforms and product services formulating and publishing personal information processing rules, and also applies to the supervision, management, and evaluation of such rules.
Applicable to: Internet platform operators, product/service providers, regulatory authorities, third-party assessment bodies.
Key Clause Highlights
| Clause/Chapter | Content | Affected Parties |
|---|---|---|
| Chapter 5 (Overview) | Overall framework and basic principles of personal information processing rules | All operators |
| Chapter 6 (Basic Requirements) | Fundamental compliance requirements: legality, legitimacy, necessity, transparency | Legal & compliance departments |
| Chapter 7 (Drafting Procedures) | Full-process requirements: drafting, review, publication, revision | Product, legal, compliance teams |
| Chapter 8 (Content) | Mandatory content elements (types of information collected, purposes of use, sharing scope, user rights, etc.) | Privacy policy drafters |
| Chapter 9 (Publication Formats) | Display methods, accessibility, language requirements | Product design, front-end development |
| Chapter 10 (Revision) | Notification obligations upon changes, version management, user notification | Operations, legal |
| Chapter 11 (Dispute Resolution) | User complaints, dispute handling, remedy channels | Customer service, legal |
Note: Chapter structure based on the standard's table of contents; refer to the official text for exact wording.
Compliance Recommendations
- Comprehensive Privacy Policy Review: Internet platform operators should conduct a full review of existing privacy policies against Chapter 8 requirements before April 1, 2025.
- Establish Drafting & Revision Procedures: Implement processes for drafting, review, publication, revision, and version management per Chapters 7 and 10.
- Optimize Publication Formats: Ensure privacy policy display meets Chapter 9 accessibility and readability requirements across App, web, and other channels.
- Establish Dispute Resolution Mechanisms: Build robust user complaint and dispute resolution channels per Chapter 11.
- Ongoing Monitoring: Track supporting guidelines and interpretations issued by SAC/TC 260.
Official Sources
- National Standard Information Public Service Platform (openstd): GB/T 44588-2024
- China Standard Service Network (spc): GB/T 44588-2024
- National Technical Committee for Cybersecurity Standardization (SAC/TC 260): www.tc260.org.cn
