Introduction
On 17 June 2026, a new consultation draft of the Data Security Technology – Personal Information Security Specification was released, which undertakes a systematic restructuring of its 2020 predecessor (GB/T 35273-2020) (the “2026 Draft“). This article examines the eight core areas of change introduced by the 2026 Draft, together with their compliance implications for organisations operating in China.
The changes examined in this first part of our article — the repositioning of the standard within the data security legislative framework, the realignment of core definitions with the PIPL and its companion regulations, and the introduction of a structured, documented lawful basis requirement — collectively lay the conceptual foundations upon which the 2026 Draft’s more detailed operational requirements are built.
In the second part of this article, we will turn to the practical and sector-specific consequences of this reform: the new rules governing AI products and IoT devices, the strengthened data subject rights framework, the new chapter on overseas jurisdiction and cross-border conflict resolution, and the significantly expanded organisational accountability requirements that will affect a broad range of organisations operating in China.
1. Reclassification and Scope: Structural Updates
The standard’s overarching category has been repositioned from “Information Security Technology” to “Data Security Technology” with the corresponding formal title updated accordingly. This repositioning reflects the broader legislative landscape, aligning the standard with both the Personal Information Protection Law (PIPL) and the Data Security Law (DSL). The enumerated categories of personal information processing activities are also expanded to include “processing”, “transmission”, and “provision”, consistent with the PIPL’s definitions.
From a compliance perspective, organisations’ data compliance frameworks must now simultaneously satisfy both the data security and personal information protection dimensions. Existing privacy policies, institutional documents, and standard references will need to be updated once the 2026 Draft comes into formal effect.
2. Definitional Updates — Alignment with the PIPL and Its Companion Regulations
Several definitional changes in the 2026 Draft serve primarily to bring the standard into terminological alignment with the PIPL, the Regulations on Network Data Security Management, and other applicable legislation. These updates include:
- The revision of the definition of “personal information” to information “related to an identified or identifiable natural person”, explicitly excluding anonymised information;
- The renaming of “personal sensitive information” to “sensitive personal information”, with emphasis on the protection of “personal dignity”;
- The replacement of “personal information controller” with “personal information processor”;
- The renaming of “personal information security impact assessment” to “personal information protection impact assessment”, reflecting the PIPL’s rights-centred framing; and
- The consolidation of the 2020 edition’s two separate terms — “explicit consent” and “authorisation consent” — into a single term “consent”, whilst formally incorporating “separate consent” as a defined concept. The definition tracks that already established by the Regulations on Network Data Security Management: consent given by an individual specifically for a particular processing activity, in a specific, clear, and unambiguous manner. The circumstances in which separate consent is required are likewise already addressed under the PIPL.
Whilst these are largely presentational alignments, organisations should not underestimate the administrative effort required to ensure that all internal documents, contracts, and compliance registers are updated consistently.
3. New Definitional Clarifications — Matters Not Previously Clear Under Existing Law
3.1 The Aggregation Rule for Sensitive Personal Information
A new Note 3 to the definition of sensitive personal information establishes that where multiple items of personal information are aggregated and the resulting dataset meets the definitional threshold for sensitive personal information, the aggregated information as a whole must be treated and protected accordingly. This rule is not expressly stated in the PIPL and represents a meaningful elaboration of the existing framework.
For organisations engaged in profiling, big data analytics, or multi-dimensional data modelling, a prior assessment of the risks arising from cross-field aggregation will be required, and existing tiered protection frameworks will need to be upgraded accordingly.
3.2 Stricter Deletion Standard — Irrecoverability Required
The definition of “deletion” has been significantly tightened in a manner that goes beyond the PIPL’s general deletion obligation. The scope has expanded from “systems involved in daily business functions” to “all systems in which the information is stored”, and a new technical requirement has been added that deleted information must be rendered “irrecoverable” — not merely inaccessible. Organisations must ensure that deletion operations extend to backup systems and archives and meet the irrecoverability standard in practice.
3.3 New Definitions for Emerging Concepts
Three entirely new defined terms are introduced to address gaps in the existing legislative framework:
- Device information (Section 3.18): hardware parameters, serial numbers, and unique device identifiers recorded during manufacturing — a concept with particular relevance to connected vehicles and smart devices that has not previously been defined in a national standard.
- Unified account (Section 3.19): account systems shared across multiple entities within the same corporate group, addressing a common platform architecture that has previously operated in a definitional grey area.
- Entrusted processing (Section 3.20): clarifying the legal relationship between the data processor and its entrusted processor, and expressly distinguishing entrusted processing from a “provision” of personal information (Section 3.13) — a distinction that resolves a long-standing ambiguity as to how these two different legal relationships should be characterised and governed.
4. New Chapter on Lawful Bases for Processing
Chapter 5 of the 2026 Draft introduces a new chapter titled “Lawful Bases and Compliance Requirements for Personal Information Processing”, which translates the lawful basis framework already established under Article 13 of the PIPL into the standard and provides further operational detail for each basis. Before processing commences, organisations must identify and document the applicable lawful basis, forming a verifiable, traceable, and auditable chain of evidence. Once established, the lawful basis must not be arbitrarily changed, and must remain consistent with the notification provided to data subjects, processing activity records, Personal Information Protection Impact Assessments (PIPIA), and compliance audit findings.
The six lawful bases set out in Sections 5.2–5.8 correspond to those under the PIPL, with the 2026 Draft adding practical guidance and express limitations for each:
- Consent (Section 5.2): Defaults, passive agreement, and coerced consent are explicitly invalid. Consent evidence must be retained, covering content, timing, method, medium, and withdrawal records.
- Necessity for contract performance (Section 5.3): Strictly limited to achieving the core purpose of the contract. Organisations are expressly prohibited from invoking this basis for purposes such as personalised advertising, behavioural analytics beyond the contract scope, or user profiling unrelated to contractual obligations.
- Necessity for labour contract management (Section 5.4): It is worth noting that the PIPL’s corresponding basis refers specifically to lawfully established labour rules and regulations and collectively signed contracts — both of which require specific procedural steps. Strictly speaking, individual labour contracts would fall under the “necessity for contract performance” basis. The 2026 Draft nonetheless consolidates labour-related processing under this separate heading, limiting it to employment management purposes such as HR management, payroll, performance appraisal, and labour dispute resolution. Commercial marketing, employee profiling, and monitoring unrelated to labour management must not be conducted under this basis.
- Necessity to fulfil statutory duties (Section 5.5): Only applicable where a specific law or administrative regulation imposes a concrete processing obligation. Information collected for compliance purposes must not be used for other commercial ends.
- Emergency situations (Section 5.6): Restricted to genuinely urgent scenarios involving the protection of life, health, or significant property interests.
- News reporting, public interest, and processing publicly available personal information (Sections 5.7–5.8): Both bases carry strict conditions. Publicly available information must not be repurposed for user profiling, commercial marketing, or other unrelated uses.
* With thanks to Ximeng Hong (Intern, Beijing) for her contribution to the article.






