Many industries, such as food, pharmaceuticals and medical devices, focus on quality management and have their own management practices, such as GMPs (Good Manufacturing Practices) and GSPs (Good Sales Practices). There is no doubt that the newly released Information Security Technology – Personal Information Security Specification (GB/T 35273-2017) (the “Specification”) is the “GSP” (Good Security Practices) of personal information protection in terms of its structure and content. In the financial industries, financial regulators have their own rules protecting personal financial information. Promulgation of the Specification will help financial institutions to give more protection to their customers.
On December 29, 2017, the General Administration of Quality Supervision, Inspection and Quarantine of the PRC and the Standardization Administration of the PRC jointly released the Specification in the form of a national standard. The full text of the Specification was officially published on the national standards public system on January 24, 2018, and will be effective on May 1, 2018. The Specification establishes a framework for personal information protection in accordance with requirements of the Cybersecurity Law, providing comprehensive and detailed compliance obligations for all aspects of the personal information processing life cycle.