GB/T 41806-2022 in English
VALIDInformation security technology—Security requirements of genetic recognition data
- Issued on:2022-10-12
- Implemented on:2023-05-01
- File Format:PDF
- Delivery:Via email within 5 business days
$359.00
《GB/T 41806-2022信息安全技术 基因识别数据安全要求》由TC260(全国信息安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Analysis of the core content of the standard
| Data processing links | Core requirements | Technical measures |
|---|---|---|
| Data collection | • Minimum necessary principle • Double informed consent • De-identification of biological samples | • Separate storage architecture • Blockchain evidence technology |
| Data transmission | • Domestic storage • Encrypted transmission • Recipient qualification review | • National secret algorithm encryption • Secure transmission protocol |
| Data usage | • Scenario limitation • Temporary association mechanism • Anti-discrimination clause | • Dynamic desensitization technology • Access behavior audit |
Key technical innovations
The standard establishes for the first time a management framework for the full life cycle of genetic data, which is highlighted as follows:
- Three-level protection system: 10,000 data sets require level 3 protection, and 100,000 data sets require a higher level of protection
- Dynamic informed consent: requires separate authorization for different scenarios, and a clear withdrawal mechanism (except for medical research data)
- Special equipment management: formulate special security specifications for special equipment such as sequencers and biological computing servers
Implementation difficulties and countermeasures
Cross-institutional collaboration scenarios
Note on data sharing in research and development scenarios:
- Only provide the minimum necessary related information when entrusting analysis
- Establish a data flow tracking mechanism, see Appendix B of the standard for sample protocols
Compliance storage period
The storage period varies significantly in different scenarios:
- Clinical projects: 2 years (based on the "Medical Institution Clinical Laboratory Management Measures")
- Neonatal screening: 10 years (based on the "Technical Specifications for Neonatal Disease Screening")
- Embryo cryopreservation: 20 years (based on expert consensus)
Industry impact analysis
The implementation of the standard will promote:
- Gene testing institutions need to restructure their data management structure and set up an ethics committee and a data management committee
- Give rise to the genetic data security and compliance audit service market
- Promote the development of special algorithms for de-identification technology in the field of bioinformatics

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 41387-2022 in English
Information security technology—Smart home general security specification
2022-04-15 -

GB/T 20274.1-2023 in English
Information security technology - Evaluation framework for information systems security assurance - Part 1: Introduction and general model
2023-03-17 -

GB/T 24364-2023 in English
Information security technology—Implementation guide for information security risk management
2023-05-23 -

GB/Z 41288-2022 in English
Information security technology—Guidelines of cyber security protection for important industrial control system
2022-03-08 -

GB/T 28451-2023 in English
Information security technology—Technical specification for network intrusion prevention system
2023-05-23 -

GB/T 29246-2023 in English
Information security technology—Information security management systems—Overview and vocabulary
2023-12-28 -

GB/T 17902.1-2023 in English
Information technology―Security techniques―Digital signatures with appendix―Part 1:General
2023-03-17 -

GB/T 25068.3-2022 in English
Information technology—Security techniques—Network security—Part 3: Threats, design techniques and control for network access scenarios
2022-10-12 -

GB/T 32914-2023 in English
Information security technology —Capability requirements of cybersecurity service
2023-09-07 -

GB/T 43269-2023 in English
Information security techniques—Assessment criteria for cybersecurity emergency capability
2023-11-27