Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
information security technology data transaction service security requirements nist data security framework data transaction participants data transaction process security data transaction participants data suppliers information security technology security requirements laboratory ph meters scopethis procedure applies atmosphere warehouses clearance requirements
GB/T 37932-2019 in English

GB/T 37932-2019 in English

SUPERSEDED

Information security technology—Security requirements for data transaction service

  • Issued on:2019-08-30
  • Implemented on:2020-03-01
  • File Format:PDF
  • Delivery:Via email within 1~3 business days
Price(USD): $160.00
$156.00
Standard No: GB/T 37932-2019
Document status: SUPERSEDED
Superseded by: GB/T 37932-2025 Data security technology—Security requirements for data transaction service
Superseded on: 2026-07-01
Title in English: Information security technology—Security requirements for data transaction service
Title in Chinese: 信息安全技术 数据交易服务安全要求
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 1~3 business days
Issued on: 2019-08-30
Implemented on: 2020-03-01
Chinese Classification: L80-Data encryption
Professional Classification: GB-National Standard
Related Keywords: information security technology data transaction service security requirements
nist data security framework data transaction participants
data transaction process security
data transaction participants data suppliers
information security technology security requirements
Related Topics: trade
Information Security Technology Mobile Internet Application Server Security Technical Requirements
laboratory security data security
Technical Data English
Information technology data transaction service platform transaction data description
Domestic data transaction
Overseas data transaction
GBT37932
Data Security Technical Requirements for Internet of Vehicles Information Service
Safety Technical Requirements for Automobile Data Processing
Information Technology Services Data Asset Management Requirements
Information technology service service security requirements GB/T 39770-2021
GB/T 39770-2021 Information technology service security requirements
Sterile clothing safety
Power data security

《GB/T 37932-2019信息安全技术 数据交易服务安全要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。


Introduction

GB/T 37932—2019: Overview of security requirements for data transaction services

With the continuous increase in the value of data, data transaction has become a key link in promoting economic development. However, the security issues involved in the data transaction process have become increasingly prominent, and standardized security management standards are urgently needed. GB/T 37932—2019 "Information Security Technology Data Transaction Service Security Requirements" came into being, providing comprehensive security specifications for data transaction services.

Background and significance of standard formulation

As an emerging production factor, data plays an important role in global economic and social development. However, the rise of data transactions has also brought many security risks, such as data leakage, privacy infringement and abuse. The formulation of GB/T 37932—2019 aims to:

  • Regulate data transaction behaviors and establish an orderly data market.
  • Guarantee the security responsibility sharing mechanism of data transaction participants.
  • Promote the safe circulation and efficient use of data resources.

Comparative analysis of standard frameworks

Dimensions GB/T 37932—2019 ISO/IEC 27001 NIST Data Security Framework
Data transaction participants Specify the security requirements for data suppliers, demanders and transaction service agencies. Focus on the overall information security management system of the organization. Emphasis on data security risk management.
Transaction object security Regulate the quality of transaction data, the scope of prohibited transaction data and important data protection measures. Does not directly involve requirements related to data transactions. Provide data classification and labeling guidelines.
Transaction process security Covering the full life cycle management of transaction application, negotiation, implementation and termination. Focus on information asset protection measures. Focus on the security of data flow.

Interpretation of core security requirements

1. Security requirements for data transaction participants

Data suppliers:Must ensure their legality, registration review and security commitment.

Data demanders:Must provide proof of security capabilities and use compliance commitment.

Transaction service agencies:Must have security management capabilities, including system construction, organizational structure and technical protection measures.

2. Transaction object security requirements

  • Prohibited transaction data: Data involving personal information, intellectual property rights and data obtained through illegal channels shall not be traded.
  • Data quality requirements: Including legality, clarity of rights and authenticity.
  • Important data protection: Emphasis on risk assessment and security audit.

3. Data transaction process security

Covering the entire life cycle from transaction application to transaction completion, including:

  • Transaction application review and sample data verification.
  • Security compliance review of transaction negotiation.
  • Security monitoring and log recording during transaction implementation.
  • Data cleanup and responsibility tracing after the transaction is completed.

Implementation Suggestions

1. Establish a sound security management system

Data transaction service agencies should formulate data security strategies covering the entire life cycle, including:

  • Organizational structure: clarify security management responsibilities.
  • System construction: formulate security management systems and operating procedures for transaction participants.
  • Personnel management: implement job security review and training plans.

2. Technical measures

The following technical means are recommended:

  • Data encryption and access control: protect the security of transaction data transmission and storage.
  • Log audit and tracing: record each transaction operation and support the tracing of violations.
  • Hosting environment isolation: ensure the security of the data usage environment under the hosting model.

3. Risk Assessment and Emergency Response

Perform regular risk assessment and establish an emergency response mechanism:

  • Develop an emergency plan for data leakage.
  • Set up the manual intervention function of the transaction process to deal with violations in a timely manner.
  • Maintain communication with national regulatory authorities and support audit interface docking.

Analysis of the Future Evolution of Standards

With the rapid development of the data transaction market and technological advancement, GB/T 37932-2019 will face the following challenges and opportunities:

  • Technological Advances:Artificial intelligence and blockchain technology will further enhance the security and transparency of data transactions.
  • Policy Demands:Data governance is becoming stricter around the world, pushing standards to develop towards stricter compliance requirements.
  • Market demand: The growing demand for data security in enterprises has prompted the standard content to be more detailed and practical.

Actual application case: Security practice of a big data trading platform

A large data trading institution has significantly improved the security of its platform by implementing GB/T 37932-2019. Specific measures include:

  • Establish a three-level security protection system.
  • Use data encryption and access control technology.
  • Realize complete recording and auditing of transaction logs.

Sample only — not a preview of GB/T 37932-2019
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend

  • GB/Z 41288-2022 in English

    GB/Z 41288-2022 in English

    Information security technology—Guidelines of cyber security protection for important industrial control system

    2022-03-08
  • GB/T 29246-2023 in English

    GB/T 29246-2023 in English

    Information security technology—Information security management systems—Overview and vocabulary

    2023-12-28
  • GB/T 25068.3-2022 in English

    GB/T 25068.3-2022 in English

    Information technology—Security techniques—Network security—Part 3: Threats, design techniques and control for network access scenarios

    2022-10-12
  • GB/T 17902.1-2023 in English

    GB/T 17902.1-2023 in English

    Information technology―Security techniques―Digital signatures with appendix―Part 1:General

    2023-03-17
  • GB/T 24364-2023 in English

    GB/T 24364-2023 in English

    Information security technology—Implementation guide for information security risk management

    2023-05-23
  • GB/T 43269-2023 in English

    GB/T 43269-2023 in English

    Information security techniques—Assessment criteria for cybersecurity emergency capability

    2023-11-27
  • GB/T 39204-2022 in English

    GB/T 39204-2022 in English

    Information security technology—Cybersecurity requirements for critical information infrastructure protection

    2022-10-12
  • GB/T 40813-2021 in English

    GB/T 40813-2021 in English

    Information security technology—Security protection technical requirements and testing evaluation methods of industrial control systems

    2021-10-11
  • GB/T 35274-2023 in English

    GB/T 35274-2023 in English

    Information security technology—Security capability requirements for big data services

    2023-08-06
  • GB/T 31496-2023 in English

    GB/T 31496-2023 in English

    Information technology—Security techniques—Information security management systems—Guidance

    2023-05-23