|
US$339.00 ยท In stock Delivery: <= 4 days. True-PDF full-copy in English will be manually translated and delivered via email. GB/T 42012-2022: Information security technology - Data security requirements for instant messaging services Status: Valid
| Standard ID | Contents [version] | USD | STEP2 | [PDF] delivered in | Standard Title (Description) | Status | PDF |
| GB/T 42012-2022 | English | 339 |
Add to Cart
|
4 days [Need to translate]
|
Information security technology - Data security requirements for instant messaging services
| Valid |
GB/T 42012-2022
|
PDF similar to GB/T 42012-2022
Basic data | Standard ID | GB/T 42012-2022 (GB/T42012-2022) | | Description (Translated English) | Information security technology - Data security requirements for instant messaging services | | Sector / Industry | National Standard (Recommended) | | Classification of Chinese Standard | L80 | | Classification of International Standard | 35.030 | | Word Count Estimation | 18,160 | | Date of Issue | 2022-10-14 | | Date of Implementation | 2023-05-01 | | Issuing agency(ies) | State Administration for Market Regulation, China National Standardization Administration |
GB/T 42012-2022: Information security technology - Data security requirements for instant messaging services ---This is a DRAFT version for illustration, not a final translation. Full copy of true-PDF in English version (including equations, symbols, images, flow-chart, tables, and figures etc.) will be manually/carefully translated upon your order.
Information security technology -- Data security requirements for instant messaging services
ICS 35.030
CCSL80
National Standards of People's Republic of China
Information Security Technology Instant Messaging Service Data Security Requirements
2023-05-01 Implementation
State Administration for Market Regulation
Released by the National Standardization Administration
directory
Preface III
1 Scope 1
2 Normative references 1
3 Terms and Definitions 1
4 Abbreviations 2
5 Overview 2
5.1 Instant Messaging Service Business Composition 2
5.2 IM Service Data Scope 3
6 Basic requirements 3
7 Data collection 3
7.1 Collection of User Information 3
7.2 Applying for system permissions 4
7.3 Informed consent4
8 Data Storage and Transmission 4
8.1 Data Storage 4
8.2 Data transfer 4
9 Data use and processing5
9.1 Data Display 5
9.2 Data Processing 5
10 Data provision and disclosure5
11 Data deletion 6
12 Data Exit 6
13 Rights of Personal Information Subjects 6
13.1 Access and Correction of Personal Information 6
13.2 Deletion of personal and organizational information6
13.3 Individual withdrawal of consent6
14 Special Scenarios for Instant Messaging Services 7
14.1 Protection of minors 7
14.2 Protective measures against online fraud 7
Appendix A (Informative) Instant Messaging Service Data Processing Activities and Security Risks8
Appendix B (Informative) Reference Rules for Identification of Important Data of Instant Messaging Service and Example of Data Classification 9
Appendix C (Informative) Common Extended Business Functions of Personal Instant Messaging Services Scope of Collection of Personal Information 10
Appendix D (Informative) Application Scope and Usage Requirements for App-related System Permissions of Instant Messaging Service 11
Reference 13
foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for Standardization Work Part 1.Structure and Drafting Rules of Standardization Documents"
drafted.
Please note that some content of this document may be patented. The issuing agency of this document assumes no responsibility for identifying patents.
This document is proposed and managed by the National Information Security Standardization Technical Committee (SAC/TC260).
This document is drafted by. Shenzhen Tencent Computer System Co., Ltd., China Electronics Standardization Institute, National Information Technology Security
Quan Research Center, Zhejiang Yixin Technology Co., Ltd., Lanxin Mobile (Beijing) Technology Co., Ltd., China Academy of Information and Communications Technology, National Computer
Network Emergency Technology Handling Coordination Center, China Mobile Communications Group Co., Ltd., Alibaba Cloud Computing Co., Ltd., Beijing Qihoo Technology Co., Ltd.
Company, Huawei Technologies Co., Ltd., Zhengzhou Xinda Jiian Information Technology Co., Ltd., Beijing Tianrongxin Network Security Technology Co., Ltd.,
OPPO Guangdong Mobile Communications Co., Ltd., Shanghai Guanan Information Technology Co., Ltd., Beijing Momo Technology Co., Ltd., Chengdu Westone
Information Industry Co., Ltd., National Industrial Information Security Development Research Center, Geer Software Co., Ltd.
The main drafters of this document. Wu Yang, Yang Jianjun, Chen Shu, Shangguan Xiaoli, Ni Ping, Xu Yongtai, Hu Ying, Zhou Chenwei, Pan Huiwei, Yang Tao,
Zhao Yunwei, Li Haidong, Zhao Xinqiang, Wang Bingzheng, Zhu Xuefeng, Wu Huaqiang, Ji Shuai, Pei Lijie, Lou Zhe, Wu Dongyu, Zheng Lei, Zhang Yi, Zhou Peng, Liu Weihua,
Wang Yan, Chen Tian, Jiang Weiqiang, Wang Xiaopu, Xie Jiang, Dai Wei, Moruo, Huang Chao, Liu Yang, Yang Changpu, Sun Yan.
Information Security Technology Instant Messaging Service Data Security Requirements
1 Scope
This document specifies the data processing activities of instant messaging service collection, storage, transmission, use, processing, provision, disclosure, deletion, and exit.
safety requirements.
This document applies to instant messaging service providers to regulate data processing activities, and can also be used by regulatory authorities and third-party evaluation agencies for instant messaging
Provide reference for the supervision, management and evaluation of information service data processing activities.
2 Normative references
The contents of the following documents constitute essential provisions of this document through normative references in the text. Among them, dated citations
documents, only the version corresponding to that date applies to this document; for undated references, the latest edition (including all amendments) applies to
this document.
GB/T 25069 Information Security Technical Terminology
GB/T 35273-2020 Information Security Technology Personal Information Security Specification
GB/T 37964 Information Security Technology Guidelines for De-identification of Personal Information
GB/T 37988 Information Security Technology Data Security Capability Maturity Model
GB/T 39335 Information Security Technology Personal Information Security Impact Assessment Guide
GB/T 41391-2022 Basic requirements for the collection of personal information by mobile Internet applications (Apps) of information security technology
GB/T 41479 Information Security Technology Network Data Processing Security Requirements
3 Terms and Definitions
The terms and definitions defined in GB/T 25069 and GB/T 35273-2020 and the following terms and definitions apply to this document.
3.1
Provide users with sending and receiving information (text, pictures, files, audio
Online real-time interactive services for videos, links, etc.).
Note 1.The instant messaging service referred to in this document is mainly for related business services, and the internal self-built or self-use services of the organization are not included.
Note 2.For the instant messaging service referred to in this document, typical application scenarios include single chat (direct interaction between two users, between users and administrators), group chat (in the
Send and receive instant messages in groups), chat room (a kind of online space for multi-person online real-time chat), instant messaging-based social, community, online customer service,
Organizing communications, etc.
3.2
Instant messaging service for individual users.
3.3
Instant messaging service for office scenarios of organizations (such as enterprises, government agencies, etc.).
Tips & Frequently Asked Questions:Question 1: How long will the true-PDF of GB/T 42012-2022_English be delivered?Answer: Upon your order, we will start to translate GB/T 42012-2022_English as soon as possible, and keep you informed of the progress. The lead time is typically 2 ~ 4 working days. The lengthier the document the longer the lead time. Question 2: Can I share the purchased PDF of GB/T 42012-2022_English with my colleagues?Answer: Yes. The purchased PDF of GB/T 42012-2022_English will be deemed to be sold to your employer/organization who actually pays for it, including your colleagues and your employer's intranet. Question 3: Does the price include tax/VAT?Answer: Yes. Our tax invoice, downloaded/delivered in 9 seconds, includes all tax/VAT and complies with 100+ countries' tax regulations (tax exempted in 100+ countries) -- See Avoidance of Double Taxation Agreements (DTAs): List of DTAs signed between Singapore and 100+ countriesQuestion 4: Do you accept my currency other than USD?Answer: Yes. If you need your currency to be printed on the invoice, please write an email to [email protected]. In 2 working-hours, we will create a special link for you to pay in any currencies. Otherwise, follow the normal steps: Add to Cart -- Checkout -- Select your currency to pay.
|