GB/T 42012-2022 English PDFUS$339.00 ยท In stock
Delivery: <= 4 days. True-PDF full-copy in English will be manually translated and delivered via email. GB/T 42012-2022: Information security technology - Data security requirements for instant messaging services Status: Valid
Basic dataStandard ID: GB/T 42012-2022 (GB/T42012-2022)Description (Translated English): Information security technology - Data security requirements for instant messaging services Sector / Industry: National Standard (Recommended) Classification of Chinese Standard: L80 Classification of International Standard: 35.030 Word Count Estimation: 18,160 Date of Issue: 2022-10-14 Date of Implementation: 2023-05-01 Issuing agency(ies): State Administration for Market Regulation, China National Standardization Administration GB/T 42012-2022: Information security technology - Data security requirements for instant messaging services---This is a DRAFT version for illustration, not a final translation. Full copy of true-PDF in English version (including equations, symbols, images, flow-chart, tables, and figures etc.) will be manually/carefully translated upon your order. Information security technology -- Data security requirements for instant messaging services ICS 35.030 CCSL80 National Standards of People's Republic of China Information Security Technology Instant Messaging Service Data Security Requirements 2023-05-01 Implementation State Administration for Market Regulation Released by the National Standardization Administration directory Preface III 1 Scope 1 2 Normative references 1 3 Terms and Definitions 1 4 Abbreviations 2 5 Overview 2 5.1 Instant Messaging Service Business Composition 2 5.2 IM Service Data Scope 3 6 Basic requirements 3 7 Data collection 3 7.1 Collection of User Information 3 7.2 Applying for system permissions 4 7.3 Informed consent4 8 Data Storage and Transmission 4 8.1 Data Storage 4 8.2 Data transfer 4 9 Data use and processing5 9.1 Data Display 5 9.2 Data Processing 5 10 Data provision and disclosure5 11 Data deletion 6 12 Data Exit 6 13 Rights of Personal Information Subjects 6 13.1 Access and Correction of Personal Information 6 13.2 Deletion of personal and organizational information6 13.3 Individual withdrawal of consent6 14 Special Scenarios for Instant Messaging Services 7 14.1 Protection of minors 7 14.2 Protective measures against online fraud 7 Appendix A (Informative) Instant Messaging Service Data Processing Activities and Security Risks8 Appendix B (Informative) Reference Rules for Identification of Important Data of Instant Messaging Service and Example of Data Classification 9 Appendix C (Informative) Common Extended Business Functions of Personal Instant Messaging Services Scope of Collection of Personal Information 10 Appendix D (Informative) Application Scope and Usage Requirements for App-related System Permissions of Instant Messaging Service 11 Reference 13 forewordThis document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for Standardization Work Part 1.Structure and Drafting Rules of Standardization Documents" drafted. Please note that some content of this document may be patented. The issuing agency of this document assumes no responsibility for identifying patents. This document is proposed and managed by the National Information Security Standardization Technical Committee (SAC/TC260). This document is drafted by. Shenzhen Tencent Computer System Co., Ltd., China Electronics Standardization Institute, National Information Technology Security Quan Research Center, Zhejiang Yixin Technology Co., Ltd., Lanxin Mobile (Beijing) Technology Co., Ltd., China Academy of Information and Communications Technology, National Computer Network Emergency Technology Handling Coordination Center, China Mobile Communications Group Co., Ltd., Alibaba Cloud Computing Co., Ltd., Beijing Qihoo Technology Co., Ltd. Company, Huawei Technologies Co., Ltd., Zhengzhou Xinda Jiian Information Technology Co., Ltd., Beijing Tianrongxin Network Security Technology Co., Ltd., OPPO Guangdong Mobile Communications Co., Ltd., Shanghai Guanan Information Technology Co., Ltd., Beijing Momo Technology Co., Ltd., Chengdu Westone Information Industry Co., Ltd., National Industrial Information Security Development Research Center, Geer Software Co., Ltd. The main drafters of this document. Wu Yang, Yang Jianjun, Chen Shu, Shangguan Xiaoli, Ni Ping, Xu Yongtai, Hu Ying, Zhou Chenwei, Pan Huiwei, Yang Tao, Zhao Yunwei, Li Haidong, Zhao Xinqiang, Wang Bingzheng, Zhu Xuefeng, Wu Huaqiang, Ji Shuai, Pei Lijie, Lou Zhe, Wu Dongyu, Zheng Lei, Zhang Yi, Zhou Peng, Liu Weihua, Wang Yan, Chen Tian, Jiang Weiqiang, Wang Xiaopu, Xie Jiang, Dai Wei, Moruo, Huang Chao, Liu Yang, Yang Changpu, Sun Yan. Information Security Technology Instant Messaging Service Data Security Requirements1 ScopeThis document specifies the data processing activities of instant messaging service collection, storage, transmission, use, processing, provision, disclosure, deletion, and exit. safety requirements. This document applies to instant messaging service providers to regulate data processing activities, and can also be used by regulatory authorities and third-party evaluation agencies for instant messaging Provide reference for the supervision, management and evaluation of information service data processing activities.2 Normative referencesThe contents of the following documents constitute essential provisions of this document through normative references in the text. Among them, dated citations documents, only the version corresponding to that date applies to this document; for undated references, the latest edition (including all amendments) applies to this document. GB/T 25069 Information Security Technical Terminology GB/T 35273-2020 Information Security Technology Personal Information Security Specification GB/T 37964 Information Security Technology Guidelines for De-identification of Personal Information GB/T 37988 Information Security Technology Data Security Capability Maturity Model GB/T 39335 Information Security Technology Personal Information Security Impact Assessment Guide GB/T 41391-2022 Basic requirements for the collection of personal information by mobile Internet applications (Apps) of information security technology GB/T 41479 Information Security Technology Network Data Processing Security Requirements3 Terms and DefinitionsThe terms and definitions defined in GB/T 25069 and GB/T 35273-2020 and the following terms and definitions apply to this document. 3.1 Provide users with sending and receiving information (text, pictures, files, audio Online real-time interactive services for videos, links, etc.). Note 1.The instant messaging service referred to in this document is mainly for related business services, and the internal self-built or self-use services of the organization are not included. Note 2.For the instant messaging service referred to in this document, typical application scenarios include single chat (direct interaction between two users, between users and administrators), group chat (in the Send and receive instant messages in groups), chat room (a kind of online space for multi-person online real-time chat), instant messaging-based social, community, online customer service, Organizing communications, etc. 3.2 Instant messaging service for individual users. 3.3 Instant messaging service for office scenarios of organizations (such as enterprises, government agencies, etc.). ......Tips & Frequently Asked Questions:Question 1: How long will the true-PDF of GB/T 42012-2022_English be delivered?Answer: Upon your order, we will start to translate GB/T 42012-2022_English as soon as possible, and keep you informed of the progress. The lead time is typically 2 ~ 4 working days. The lengthier the document the longer the lead time.Question 2: Can I share the purchased PDF of GB/T 42012-2022_English with my colleagues?Answer: Yes. The purchased PDF of GB/T 42012-2022_English will be deemed to be sold to your employer/organization who actually pays for it, including your colleagues and your employer's intranet.Question 3: Does the price include tax/VAT?Answer: Yes. Our tax invoice, downloaded/delivered in 9 seconds, includes all tax/VAT and complies with 100+ countries' tax regulations (tax exempted in 100+ countries) -- See Avoidance of Double Taxation Agreements (DTAs): List of DTAs signed between Singapore and 100+ countriesQuestion 4: Do you accept my currency other than USD?Answer: Yes. If you need your currency to be printed on the invoice, please write an email to Sales@ChineseStandard.net. In 2 working-hours, we will create a special link for you to pay in any currencies. Otherwise, follow the normal steps: Add to Cart -- Checkout -- Select your currency to pay. |