Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ LAW · GB/T 46903

Data Security Technology — Requirements for Personal Information Protection Compliance Audits (GB/T 46903-2025).

数据安全技术 个人信息保护合规审计要求 (GB/T 46903-2025)

DCC summary, not a translation. GB/T 46903-2025 is a copyrighted national standard. The structured summary below is DCC’s own paraphrase grounded in the published text; specific clauses should be checked against the standard.

Published by: State Administration for Market Regulation and Standardization Administration of China; proposed and administered by the National Information Security Standardization Technical Committee (SAC/TC260). Drafters include CESI, the CAC Data and Technology Support Center, CAICT, CNCERT, the MPS Third Research Institute, Tsinghua and Nanjing Audit University, and the compliance teams of Kuaishou, Ant, Douyin, Tencent, Lenovo, Taobao, Didi, Huawei and Volcano Engine.
Published December 31, 2025. Implemented July 1, 2026. Recommended national standard.

Scope

GB/T 46903-2025 states the principles of personal information protection compliance audits and specifies their general requirements, implementation process, content and methods. It applies to personal information handlers conducting self-audits and to professional institutions conducting entrusted audits. It normatively references GB/T 25069, GB/T 35273 and GB/T 45574. A compliance audit is the supervisory activity of examining and evaluating whether a handler’s processing complies with laws and administrative regulations; the standard also defines the professional institution, auditor, audit findings, evidence, plan, working papers, conclusion and report.

Key contents

Principles and general requirements (clause 4)

Six principles govern every audit: legality, independence (institutions and auditors independent of the audited activity; internal auditors independent of the specific processing they audit), objectivity of evidence, impartiality of judgment, professionalism, and confidentiality.

Management requirements (4.2.1) restate and sharpen the Compliance Audit Measures: a professional institution must have suitable staff, premises, facilities and funds; it may not subcontract the audit; the same institution or affiliated institutions and the same audit lead may not audit the same client more than three consecutive times; and it must delete the information obtained once the audit ends. A handler auditing itself must, if it processes the personal information of more than 1 million individuals, designate its personal information protection officer to lead the audit; a large platform (more than 50 million registered or 10 million monthly active users, complex business, significant national-security or economic impact) must establish an independent body mainly composed of external members to supervise the audit; and every self-auditing handler must adopt an audit management system, provide budget, staff, premises and tools, keep auditors out of management and decision-making for the audited activity, preferably report directly to the board or a security-and-compliance committee, and maintain an evidence base of policies, technical measures, processing records, operation logs, inspection records and test reports.

Evidence (4.2.2). Evidence must be genuine, complete and valid: management documents properly drafted and approved; agreements effectively consented to and performed; work files reflecting reality; access, storage, transfer and deletion logs untampered originals; certifications within validity; and test reports stamped by the testing body. Annex A classifies evidence types and validity.

Staffing (4.2.3). Auditors are graded junior, intermediate and senior. A handler processing more than 10 million individuals’ data must have at least ten auditors including at least one senior and three intermediate; one processing between 1 and 10 million must have at least five including at least two intermediate or above.

Frequency (4.2.4). At least once every two years above 10 million individuals; once every three or four years between 1 and 10 million, calibrated to risk and scale; preferably once every five years below 1 million; and annually for handlers processing minors’ personal information, with the results reported to the cyberspace administration.

Documentation (4.2.5). An audit plan (scope, basis, content and methods, organization and staff, schedule and requirements); working papers explaining steps, methods, findings, recommendations, evidence and basis for every audit item (template in Annex B); and an audit report with overview, basis, conclusions, findings, opinions and recommendations (template in Annex C). Internal reports are signed by the audit lead and, above 1 million individuals, by the PIPO; institutional reports are signed by the institution’s principal and the audit lead and stamped.

Auditor conduct and competence (4.3). Independence (recusal from own business, no family, financial or legal ties with the client, no gifts, voluntary and client-requested recusal), objectivity, impartiality and confidentiality (NDA before the audit, no use beyond the audit purpose, no third-party disclosure). Junior auditors need at least two years in personal information protection and work under supervision; intermediate auditors need at least three years and, in the last three years, five projects as a core member for handlers above 10 million or five as lead for handlers between 1 and 10 million; senior auditors need at least four years, five projects as lead for handlers above 10 million in the last three years, the ability to design audit programs, lead teams, resolve disputes with the client and sign off the final report.

Implementation process (clause 5)

Five stages. Preparation: define scope and basis; form the audit team (from a dedicated team, from internal audit, security and legal teams in reasonable proportions with the lead approving the roster, or from the professional institution with internal support), appoint the lead and train; conduct a pre-audit survey of organization, PIPO and department, processing scenarios (categories, volume, sensitivity, purposes, methods, key business flows), supporting systems, rules and procedures, technical measures and past incidents; choose on-site and off-site methods, preferably electronic and automated; prepare and review the plan (eleven required elements, re-drafted when objectives, object or basis change). Fieldwork: notify the client of participants, objectives, methods, risk management, channels, resources, confidentiality, safety and feedback; collect evidence widely and archive it; accept only qualifying evidence, including current-year or still-valid results of official inspections, tests, assessments and certifications; where necessary test and analyze to form admissible evidence; write working papers with thirteen listed elements; and confirm findings with management at a meeting, recording unresolved disagreements and ranking problems by impact and remediation cost. Reporting: a dispute-resolution mechanism before drafting; a report covering overview (auditor, client profile, background, objectives and scope, focus, procedures and methods), basis, process, conclusions, findings (facts, characterization, causes, consequences), opinions, recommendations and supporting material; delivery within the agreed period. Rectification: track non-compliance, press for correction within the deadline and, where necessary, follow-up audit. Archiving: retain working papers and reports.

Audit content and methods (clause 6)

For each of 26 areas the standard prescribes audit content, reference evidence and audit method. The areas are: (1) lawfulness of processing — consent obtained voluntarily and explicitly with full knowledge, no default, forced or deceptive consent, re-consent on change of purpose, method or category, separate or written consent where required, and lawful bases for processing without consent; (2) the normativity of processing rules — handler identity and working contact details, a list of collected information with methods and categories, purposes, retention, and rights channels; (3) performance of the notice obligation; (4) joint processing; (5) entrusted processing; (6) transfer on merger, restructuring, division, dissolution or bankruptcy; (7) provision to other handlers; (8) automated decision-making; (9) public disclosure based on consent; (10) image-collection and identification equipment in public places; (11) processing of publicly available information; (12) sensitive personal information; (13) children under 14; (14) cross-border provision; (15) deletion rights; (16) individual rights in processing; (17) responding to individuals and explaining rules; (18) internal management systems and operating procedures; (19) technical security measures; (20) training plans; (21) the personal information protection officer; (22) impact assessments; (23) incident emergency plans; (24) incident response and handling; (25) large-platform rules; and (26) social-responsibility reports. The consent items, for example, direct the auditor to verify whether processing rests on consent, whether the rules are adequate, whether the mechanism secures consent before processing without default or coerced consent, and to sample consent records, including first-consent, re-consent and withdrawal logs.

Annexes

Annex A (evidence types and validity), Annex B (working-paper template) and Annex C (report template) are informative.

How it fits the regime

The standard is the audit rubric for PIPL Article 54 (periodic compliance audits) and Article 64 (audits ordered by regulators), as implemented by the CAC’s Compliance Audit Measures effective May 1, 2025, and it supersedes in practice the TC260 practice guide that auditors used during the Measures’ first year. Where the Measures set the who and when — thresholds, frequencies, independence rules and the reporting duty for minors’ data under the minors’ audit announcement — the standard sets the how: staffing and competence floors, a five-stage process with documented outputs, and a 26-area checklist keyed to PIPL articles with evidence lists and test methods. For multinational handlers, three points matter most: the cross-border audit area (item 14) tests the mechanism chosen under the Cross-border Data Flows Provisions and the records behind it; the staffing floors effectively require a standing audit function, not an annual consultancy engagement, above 10 million individuals; and the acceptance of still-valid official inspection and certification results as evidence rewards handlers that hold personal-information protection certification. The sensitive-information area applies GB/T 45574 as its normative baseline.

§ RELATED LAWS

See also.

§ COMMENTARY

Briefs on this law.

1 brief references this law.

  • § 01 · GBT-35273

    From Consent to Governance: What the 2026 Draft Revision of GB/T 35273 Changes Against the 2020 Standard

    On June 17, 2026 the National Cybersecurity Standardization Technical Committee (TC260), with CESI as drafting lead, released for public comment a systematic revision of GB/T 35273 — China's most-cited personal-information standard, the de-facto 'small PIPL.' The draft retitles the standard from 'Information Security Technology' to 'Data Security Technology' and expands its normative references from one standard to eight. DCC reads the revision as a role change, not a clause count: the standard moves from a consent-and-notice manual into a governance-capability framework. The substantive increments against GB/T 35273-2020: a new Chapter 5 importing PIPL Article 13's seven lawful bases as a standalone chapter with hard boundaries on each (contract-necessity, HR, public-disclosure) plus an evidence-chain duty; a sensitive-PI redefinition aligned to PIPL Article 28 with a new aggregation rule (multiple items that together meet the threshold are treated as sensitive as a whole); a formal 'separate consent' definition (3.7) with a negative list; a new eighth basic principle, 'quality assurance' (Chapter 4(f)); dedicated AI clauses on the collection side (6.7), in minimum-necessity (6.1 d–f), in aggregation/training (8.4), and a new generative-AI use clause (8.5.4) with output review and a 15-working-day deletion SLA; a unified-account-system clause (8.6) aimed at one-account-many-products groups; a terminal/IoT collection clause (6.8); a wholly new Chapter 11 on overseas-jurisdiction determination and conflict handling; and a systematized internal-control chapter (13) covering the person in charge of personal information protection, working body, processing-activity records, impact assessment, and a GB/T 46903-anchored compliance audit. Subject-rights response time tightens from 30 days to 15 working days. Clause numbers are from the comment draft and are not final; formal release is expected after 2027.

    gbt-35273 · personal-information · pipl
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →