Three Chinese Cybersecurity Standards Take Effect on July 1, 2026
China has published three national standards covering personal information transfers, cybersecurity maps and personal information protection compliance audits, effective July 1, 2026.
This article introduces three Chinese national cybersecurity standards concerning personal information transfers at an individual’s request, the representation of cybersecurity map elements, and personal information protection compliance audits. Standard titles below are descriptive translations of the Chinese titles.
Three national standards administered by China’s National Technical Committee on Cybersecurity of Standardization Administration have recently been published: GB/T 46901—2025, Data security technology — Requirements for personal information transfers at an individual’s request; GB/T 46902—2025, Cybersecurity technology — Requirements for representing cybersecurity map elements; and GB/T 46903—2025, Data security technology — Requirements for personal information protection compliance audits. All three will take effect on July 1, 2026.
1. GB/T 46901—2025: Personal information transfers at an individual’s request
This standard specifies the scope, prerequisites, procedural requirements and additional requirements for specific situations when personal information is transferred at the request of the individual concerned. It guides personal information handlers in responding to such requests. It also supports related supervision and management by regulators and third-party assessment bodies.
2. GB/T 46902—2025: Representation of cybersecurity map elements
This standard specifies the classification, codes and graphical symbols used to represent elements of cybersecurity maps. It applies to cybersecurity regulators, industry authorities, network operators and network service providers when constructing and visually representing such maps.
3. GB/T 46903—2025: Personal information protection compliance audits
This standard sets out principles for personal information protection compliance audits and specifies their overall requirements, implementation procedures, content and methods. It applies to personal information handlers and professional organizations carrying out these audits.
Source: China’s National Technical Committee on Cybersecurity of Standardization Administration.