DCC summary, not a translation. GB 46864-2025 is a copyrighted national standard. The structured summary below is DCC’s own paraphrase grounded in the published text; specific clauses should be checked against the standard.
Published by: State Administration for Market Regulation and Standardization Administration of China; proposed and administered by the Office of the Central Cyberspace Affairs Commission.
Published December 2, 2025. Implemented January 1, 2027. Mandatory national standard.
Scope
GB 46864-2025 specifies the basic requirements, functional requirements and process requirements for the sanitization (信息清除) of information stored on electronic products. It applies to electronic products manufactured or sold within China that have non-volatile storage media; to product manufacturers and third parties developing erasure functions; and to recycling operators (回收经营者) sanitizing used electronic products. It does not apply to products that process State secrets. There are no normative references. The introduction explains the drafting rationale: ordinary deletion only marks data as invalid, and users need deep erasure when devices enter second-hand circulation, are sent for repair or are scrapped, to prevent leakage and malicious recovery — a concern the standard links to the Cybersecurity Law, the Data Security Law, the PIPL and the State Council’s 2024 action plan on large-scale equipment renewal and consumer-goods trade-ins (国发〔2024〕7号).
Key contents
Definitions (clause 3). Storage media are divided into volatile and non-volatile and, by material, into magnetic (HDD, tape, magnetic cards) and semiconductor (RAM, SSD, eMMC, UFS, USB drives). User data is data generated or written by the user in using the product, excluding cloud data, device-status and lifetime data, and factory settings such as the operating system and pre-installed apps. Information sanitization means irreversible technical processing so that data can be neither accessed nor recovered. Data overwrite writes fixed or random meaningless data to every storage unit holding user data; block erase invokes media instructions to erase physical blocks — merely clearing the logical-to-physical address mapping or marking data invalid does not count. Destruction physically or chemically destroys the medium. Used electronic products, recycling and recycling operator are defined to cover offline shops, online platforms, second-hand markets, door-to-door services, refurbishment and resale, and export trade; entities that only provide a trading channel are not recycling operators.
Basic requirements (clause 5). Sanitization must:
- erase all user data, including without limitation user-generated or downloaded files; contacts, call records, SMS/MMS, calendar, notes, location and behavior records; installed apps; app data and cross-app shared data from user-installed and pre-installed apps; identity security data such as accounts, passwords, biometric information and app certificates; information on bound external devices such as bank, transit and access cards; system settings (network, permissions, Bluetooth, desktop and personalization); backups on the device; and caches;
- on products that store user data encrypted, erase or destroy the encryption keys and all copies;
- log out of every pre-installed app account and, after sanitization, prevent automatic login, automatic cloud synchronization of user data, and activation with the original passcode — by unbinding the account, disabling cloud sync and disabling find-my-device;
- use data overwrite for magnetic media, and data overwrite or block erase for semiconductor media;
- for overwrite: on magnetic media, overwrite every physical address holding user data at least three times, including one random-data pass; on semiconductor media, delete the logical-to-physical mapping and overwrite at least once;
- for block erase: delete the mapping and erase all user data on the medium;
- where identity security data or bound-card data cannot be erased by overwrite or block erase, erase by deleting the mapping; a product that stores only system-settings data may likewise erase by deleting the mapping.
Functional requirements (clause 6). Manufacturers must provide a built-in erasure function; where that is impossible they must provide an external tool, information on a usable third-party tool, or a free erasure service. The function must meet clause 5; before execution it must clearly disclose to the user the scope, method and consequences of erasure (on the function’s screen or in the manual) and proceed only with consent; it must verify execution conditions and explain any failure to meet them; on failure it must re-run or offer another method; and products with a management-side app must prompt or automatically unbind the management account.
Process requirements for used products (clause 7). Recycling operators must proactively prompt users to erase before recycling; must not access or retain user data without consent; must use erasure functions or tools meeting clause 6; must physically destroy the medium where damage prevents erasure; must record each erasure (product, method, time, result); must verify erasure before resale; must retain erasure and verification records for at least three years; must not resell or transport abroad devices whose user data has not been erased; and must establish management and technical measures, designate a person responsible, adopt rules and operating procedures, and support queries and tracing of erasure status.
The bibliography cites GB/T 35273-2020, GB/T 43697-2024, GB/T 45070-2024 (recycling of waste electrical and electronic products), GB/T 45656-2025 (grading of used electronic products), ISO/IEC 27040:2024, IEEE 2883-2022 and NIST SP 800-88 Rev. 2.
How it fits the regime
The standard gives operational content to the deletion duties scattered across the general regime — PIPL Article 47 (deletion when the purpose is achieved or the account closed), the Network Data Security Regulations, and the storage-limitation and deletion clauses of GB/T 35273 — at the point where they are most often breached in practice: the resale and disposal of consumer devices. Two features matter for foreign manufacturers and platforms. First, it is mandatory, so a device sold in China after January 1, 2027 must ship an erasure function meeting the three-pass or block-erase floor, and its factory-reset flow must unbind accounts and kill cloud sync. Second, it reaches the second-hand chain — recyclers, refurbishers, trade-in programs and exporters of used devices — with record-keeping and an export ban on un-erased devices, which connects to the Data Security Law rather than only to personal-information rules. It sits alongside the 2026 draft revision of GB/T 35273, which cross-references it for deletion.