GB/T 42574-2023 English PDFUS$1139.00 ยท In stock
Delivery: <= 8 days. True-PDF full-copy in English will be manually translated and delivered via email. GB/T 42574-2023: Information security technology - Implementation guidelines for notices and consent in personal information processing Status: Valid
Basic dataStandard ID: GB/T 42574-2023 (GB/T42574-2023)Description (Translated English): Information security technology - Implementation guidelines for notices and consent in personal information processing Sector / Industry: National Standard (Recommended) Classification of Chinese Standard: L80 Classification of International Standard: 35.030 Word Count Estimation: 60,698 Date of Issue: 2023-05-23 Date of Implementation: 2023-12-01 Issuing agency(ies): State Administration for Market Regulation, China National Standardization Administration GB/T 42574-2023: Information security technology - Implementation guidelines for notices and consent in personal information processing---This is a DRAFT version for illustration, not a final translation. Full copy of true-PDF in English version (including equations, symbols, images, flow-chart, tables, and figures etc.) will be manually/carefully translated upon your order. ICS35:030 CCSL80 National Standards of People's Republic of China Information Security Technology Notify and Agreed Implementation Guidelines Released on 2023-05-23 2023-12-01 implementation State Administration for Market Regulation Released by the National Standardization Management Committee table of contentsPreface III 1 Scope 1 2 Normative references 1 3 Terms and Definitions 1 4 Abbreviations 2 5 Applicable Circumstances of Notification 2 5:1 Collection of personal information 2 5:2 Provision and disclosure of personal information 3 5:3 Changes in processing activities, etc: 3 5:4 Other situations 3 6 Applicable Circumstances of Consent4 6:1 Circumstances requiring consent 4 6:2 Circumstances exempt from obtaining consent4 7 Basic Principles of Information and Consent6 7:1 Basic principles of notification 6 7:2 Basic principles of consent6 7:3 Elements that should be considered for notification and consent6 8 inform 7 8:1 Ways of Notification 7 8:2 Contents of Notification 8 8:3 Implementation of the notification12 9 agreed 14 9:1 Choice of Consent Mechanism 14 9:2 Implementation of Consent 15 9:3 Implementation of individual consent 16 9:4 Implementation of written consent 20 9:5 Implementation of refusal of consent 20 9:6 Withdrawal of consent 21 9:7 Retention of Evidence of Consent 22 Appendix A (informative) Notification and consent of basic business functions and extended business functions of App 24 Appendix B (Informative) Notification and Consent in the Scenario of App Embedding a Third-Party SDK 26 Appendix C (Informative) Notification and Consent of Handling Personal Information of Minors Under 14 Years of Age 28 Appendix D (Informative) Notification and Consent in Smart Life Scenarios 31 APPENDIX E (INFORMATIVE) INFORMATION AND CONSENT IN PUBLIC PLACES 33 Appendix F (Informative) Notification and Consent in Personalized Push Scenario 35 Appendix G (Informative) Notification and Consent in the Cloud Computing Service Scenario 37 Appendix H (Informative) Notification and Consent in the Vehicle Scenario 39 Appendix I (Informative) Notification and Consent in the Internet Finance Scenario 42 Appendix J (Informative) Notice and Consent in Online Shopping Scenario 44 Appendix K (Informative) Notification and Consent in the Express Logistics Scenario 46 Appendix L (Informative) Notification and Consent in the Internet Real Estate Brokerage Service Scenario 48 Appendix M (informative) Notification and consent in the context of personal identification50 Appendix N (informative) Examples of circumstances in which consent may be presumed52 Reference 53forewordThis document is in accordance with the provisions of GB/T 1:1-2020 "Guidelines for Standardization Work Part 1: Structure and Drafting Rules for Standardization Documents" drafting: Please note that some contents of this document may refer to patents: The issuing agency of this document assumes no responsibility for identifying patents: This document is proposed and managed by the National Information Security Standardization Technical Committee (SAC/TC260): This document was drafted by: China Electronics Standardization Institute, Shenzhen Tencent Computer System Co:, Ltd:, China Information and Communication Research Institute Research Institute, Beijing Institute of Technology, Tongdun Technology Co:, Ltd:, Beijing Byte Beat Technology Co:, Ltd:, Perfect World Holdings Group Co:, Ltd:, Beijing Beijing Baidu Netcom Technology Co:, Ltd:, Beijing Xiaomi Mobile Software Co:, Ltd:, Huawei Technologies Co:, Ltd:, Quanzhi Technology (Hangzhou) Co:, Ltd: Company, Keike Fangfang (Beijing) Technology Co:, Ltd:, Alibaba (Beijing) Software Service Co:, Ltd:, Beijing University of Posts and Telecommunications, Beijing Qihoo Technology Ltd:, Glory Terminal Co:, Ltd:, Beijing Jingdong Shangke Information Technology Co:, Ltd:, OPPO Guangdong Mobile Communication Co:, Ltd:, Chongqing University of Posts and Telecommunications, Beijing Xiaoju Technology Co:, Ltd:, First Research Institute of the Ministry of Public Security, China Electronic Information Industry Development Research Institute, Xunlian Zhifu Network Co:, Ltd: Co:, Ltd:, Shanghai Tengqiao Information Technology Co:, Ltd:, National Information Technology Security Research Center, UFIDA Network Technology Co:, Ltd:, Taikang Insurance Insurance Group Co:, Ltd:, S:F: Express Co:, Ltd:, Tianyi E-Commerce Co:, Ltd:, Hunan Caixin Digital Technology Co:, Ltd:, Shenzhen Law Dada Network Technology Co:, Ltd:, Digital Currency Research Institute of the People's Bank of China, Philips (China) Investment Co:, Ltd:, Ant Technology Group Co:, Ltd:, China Power Great Wall Internet System Application Co:, Ltd:, Jingdong Technology Holdings Co:, Ltd:, China Network Security Review Technology and Certification Center, PetroChina Lanzhou Petrochemical Automation Research Institute, Tenpay Payment Technology Co:, Ltd:, PetroChina Daqing Oilfield Information Technology Company Company, China CITIC Bank Co:, Ltd: The main drafters of this document: He Yanzhe, Zhao Ranran, Ge Xin, Hong Yanqing, Xue Ying, Hu Ying, Chen Tian, Zhou Chenwei, Tian Shen, Yi Qiang, Liu Xiaocen, Zhu Lingfeng, Liu Junhe, Tan Lige, Nadia Niaz, Zhang Chao, Deng Ting, Chen Song, Wang Yanhong, Peng Juntao, Zhuang Zijun, Zhao Xiaona, Zhang Lingzi, Liu Xijun, Zhu Tong, Zhang Xiangtuo, Min Jinghua, Xu Caixi, Fu Wei, Zhang Yi, Li Teng, Zhang Na, Wang Cong, Li Yanjing, Chen Shaoliang, Yan Shaomin, Zhang Youke, Kang Qiong, Ma Ke, Fan Hua, Cai Mingyang, Zhou Dunke, Yao Yinan, Wang Wei, Meng Jingzhuo, Fu Wei, Shi Guanglong, Liu Xiaoxia, Wang Lei, Wei Shuyin, Su Yalin, Xu Yuqing, Wang Jinsong, Feng Sha, Wang Xin, Jiao Wei, Li Jing, Wang Fang, Liu Mingyang, Yuan Yangmin, Song Jie, He Yunyun, Wang Chao, Liu Yuanxing, Wang Wei, Wu Tian: Information Security Technology Notify and Agreed Implementation Guidelines1 ScopeThis document provides the implementation methods and steps for informing individuals of the processing rules and obtaining their consent when processing personal information: This document is applicable to the protection of personal rights and interests of personal information processors when carrying out personal information processing activities, and can also be used for supervision, inspection and evaluation: and other activities to provide reference:2 Normative referencesThe contents of the following documents constitute the essential provisions of this document through normative references in the text: Among them, dated references For documents, only the version corresponding to the date is applicable to this document; for undated reference documents, the latest version (including all amendments) is applicable to this document: GB/T 25069-2022 Information Security Technical Terminology GB/T 35273-2020 Personal Information Security Specifications for Information Security Technology GB/T 39335-2020 Information Security Technology Personal Information Security Impact Assessment Guidelines3 Terms and DefinitionsThe following terms and definitions defined in GB/T 25069-2022 and GB/T 35273-2020 apply to this document: 3:1 personal informationpersonalinformation Various information related to identified or identifiable natural persons recorded electronically or otherwise, excluding anonymized Information: [Source: GB/T 35273-2020, 3:1, with modifications] 3:2 Once leaked or illegally used, it is likely to cause the personal dignity of natural persons to be violated or the personal and property safety to be endangered information: Note: Sensitive personal information includes biometrics, religious beliefs, specific identities, medical health, financial accounts, whereabouts, etc:, and minors under the age of 14 person's personal information: 3:3 Organizations or individuals that independently determine the purpose and method of processing personal information: Note: It is consistent with the "personal information controller" in GB/T 35273-2020: 3:4 inform the notice The act of making individuals aware of their personal information processing activities and its related rules: ......Tips & Frequently Asked Questions:Question 1: How long will the true-PDF of GB/T 42574-2023_English be delivered?Answer: Upon your order, we will start to translate GB/T 42574-2023_English as soon as possible, and keep you informed of the progress. The lead time is typically 5 ~ 8 working days. The lengthier the document the longer the lead time.Question 2: Can I share the purchased PDF of GB/T 42574-2023_English with my colleagues?Answer: Yes. The purchased PDF of GB/T 42574-2023_English will be deemed to be sold to your employer/organization who actually pays for it, including your colleagues and your employer's intranet.Question 3: Does the price include tax/VAT?Answer: Yes. Our tax invoice, downloaded/delivered in 9 seconds, includes all tax/VAT and complies with 100+ countries' tax regulations (tax exempted in 100+ countries) -- See Avoidance of Double Taxation Agreements (DTAs): List of DTAs signed between Singapore and 100+ countriesQuestion 4: Do you accept my currency other than USD?Answer: Yes. If you need your currency to be printed on the invoice, please write an email to Sales@ChineseStandard.net. In 2 working-hours, we will create a special link for you to pay in any currencies. Otherwise, follow the normal steps: Add to Cart -- Checkout -- Select your currency to pay. |