Standard

GB/T 44588-2024 Data security technology — Personal information processing rules of internet platforms, products and services

GB/T 44588-2024 specifies requirements for personal information processing rules (privacy policies) of internet platforms and product services, including basic requirements, drafting procedures, content, publication formats, and dispute resolution. Issued September 29, 2024; effective April 1, 2025.

One-sentence summary

GB/T 44588-2024 is China's first recommended national standard specifically addressing privacy policies of internet platforms, systematically specifying basic requirements, drafting procedures, content requirements, publication formats, and dispute resolution mechanisms for personal information processing rules. Issued September 29, 2024; effective April 1, 2025.

Standard Overview

ItemContent
Standard No.GB/T 44588-2024
Standard NameData security technology—Personal information processing rules of internet platforms, products and services
Standard StatusCurrent (Issued September 29, 2024; Effective April 1, 2025)
Issuing AuthorityState Administration for Market Regulation (SAMR), Standardization Administration of China (SAC)
Responsible CommitteeNational Technical Committee for Cybersecurity Standardization (SAC/TC 260)
Proposing DepartmentNational Technical Committee for Cybersecurity Standardization (SAC/TC 260)
ICS35.030
CCSL80

Scope of Application

This document specifies requirements for basic requirements, drafting procedures, content, publication formats, and dispute resolution for personal information processing rules of internet platforms and product services.

This document applies to the process of operators of internet platforms and product services formulating and publishing personal information processing rules, and also applies to the supervision, management, and evaluation of such rules.

Applicable to: Internet platform operators, product/service providers, regulatory authorities, third-party assessment bodies.

Key Clause Highlights

Clause/ChapterContentAffected Parties
Chapter 5 (Overview)Overall framework and basic principles of personal information processing rulesAll operators
Chapter 6 (Basic Requirements)Fundamental compliance requirements: legality, legitimacy, necessity, transparencyLegal & compliance departments
Chapter 7 (Drafting Procedures)Full-process requirements: drafting, review, publication, revisionProduct, legal, compliance teams
Chapter 8 (Content)Mandatory content elements (types of information collected, purposes of use, sharing scope, user rights, etc.)Privacy policy drafters
Chapter 9 (Publication Formats)Display methods, accessibility, language requirementsProduct design, front-end development
Chapter 10 (Revision)Notification obligations upon changes, version management, user notificationOperations, legal
Chapter 11 (Dispute Resolution)User complaints, dispute handling, remedy channelsCustomer service, legal

Note: Chapter structure based on the standard's table of contents; refer to the official text for exact wording.

Compliance Recommendations

  1. Comprehensive Privacy Policy Review: Internet platform operators should conduct a full review of existing privacy policies against Chapter 8 requirements before April 1, 2025.
  2. Establish Drafting & Revision Procedures: Implement processes for drafting, review, publication, revision, and version management per Chapters 7 and 10.
  3. Optimize Publication Formats: Ensure privacy policy display meets Chapter 9 accessibility and readability requirements across App, web, and other channels.
  4. Establish Dispute Resolution Mechanisms: Build robust user complaint and dispute resolution channels per Chapter 11.
  5. Ongoing Monitoring: Track supporting guidelines and interpretations issued by SAC/TC 260.

Official Sources