GB/T 34978-2017 in English
VALIDInformation security technology-Technology requirements for personal information protection of smart mobile terminal
- Issued on:2017-11-01
- Implemented on:2018-05-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$156.00
《GB/T 34978-2017信息安全技术 移动智能终端个人信息保护技术要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
GB/T 34978—2017: Interpretation of Technical Requirements for Personal Information Protection in Mobile Smart Terminals
Background and Significance of Standard Formulation
With the widespread application of mobile smart terminals, personal information plays an increasingly important role in social and economic activities. However, the abuse of personal information has also increased, bringing potential risks to individuals and society. The formulation of GB/T 34978—2017 aims to regulate the behavior of mobile smart terminals in handling personal information and ensure the reasonable use and safe protection of personal information.
Comparative Analysis of Standard Frameworks
| Dimensions | GB/T 34978—2017 | Other relevant standards |
|---|---|---|
| Scope | Applicable to guiding the processing of personal information by mobile smart terminals for public and commercial purposes | Mainly for internal information management systems of enterprises |
| Classification principles | Based on the principles of minimum sufficiency and explicit consent | Highly flexible, without clear principle constraints |
| Technical requirements | Covering the four links of collection, processing, transfer and deletion | Mainly focusing on data storage and transmission security |
Interpretation of Personal Information Protection Principles and Technical Requirements
1. Collection Stage
- Users must be informed of the purpose and scope of information before collection
- Only collect the minimum information necessary to achieve the purpose
- Users are supported to configure or disable the collection function
- Sensitive information must be authorized using explicit consent
2. Processing Stage
- Users must be informed of the purpose and method before processing
- Ensure data security and integrity
- Users are supported to adjust or disable the processing function
- Prohibit covert means of mining identity feature data
3. Transfer Stage
- Users must be informed of the purpose and recipient before transfer
- The scope of transfer is controlled based on the principle of minimum sufficiency
- User authorization is required for sensitive information transfer
- Ensure data transmission security and integrity
4. Deletion phase
- Provide a convenient deletion function
- Ensure data is completely deleted and cannot be recovered
- Support remote destruction of data in lost devices
Actual application case analysis
For example, in a mobile smart terminal application, the user authorizes the use of location information for map navigation services. According to the standard requirements, the application must:
- Explicitly inform users that location information will be used for navigation services
- Only collect the minimum location data required to implement navigation functions
- Provide the function of turning off location information services
- Ensure encryption protection of location data during transmission
Implementation recommendations
- Enterprise level:Establish a personal information protection system that meets the standards and conduct security audits and risk assessments on a regular basis.
- Developer level: Strictly follow the standard requirements during application development to ensure that each link complies with the specifications.
- User level: Improve awareness of personal information protection and reasonably authorize application permissions.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06 -

GB/T 40018-2021 in English
Information security technology—Certificate request and application protocol based on multiple channels
2021-04-30 -

GB/T 37931-2019 in English
Information security technology—Security technology requirements and testing and evaluation approaches for Web application security detection system
2019-08-30 -

GB/T 29241-2012 in English
Information security technology—Public key infrastructure—PKI interoperability evaluation criteria
2012-12-31 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 36618-2018 in English
Information security technology—Specification for financial information service security
2018-09-17 -

GB/T 39276-2020 in English
Information security technology—General security requirements of network products and services
2020-11-19 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 20979-2019 in English
Information security technology—Technical requirements for iris recognition system
2019-08-30