---
title_en: "Data Security Technology — Requirements for Personal Information Protection Compliance Audits (GB/T 46903-2025)"
title_zh: "数据安全技术 个人信息保护合规审计要求 (GB/T 46903-2025)"
abbreviation: "GB/T 46903"
hierarchy: "standard"
issuing_body: "State Administration for Market Regulation; Standardization Administration of China (drafted by TC260)"
adopted_date: 2025-12-31
effective_date: 2026-07-01
status: "effective"
related_laws: ["personal-info-audit-measures", "tc260-pi-audit-practice-guide", "pipl", "network-data-security-regulations", "gbt-35273-pi-security-specification", "gbt-45574-sensitive-pi-processing-security", "minors-pi-compliance-audit-reporting-announcement", "small-pi-handlers-simplified-measures", "pi-protection-officer-reporting-announcement", "cross-border-data-flows-provisions", "gbt-46071-data-protection-social-responsibility"]
domains: ["personal-information", "enforcement"]
url: https://datacompliancechina.com/laws/gbt-46903-pi-compliance-audit-requirements/
summary: "GB/T 46903-2025, published December 31, 2025 and implemented July 1, 2026, is the national standard that gives operational content to the CAC's 2025 Personal Information Protection Compliance Audit Measures, replacing the 2024 TC260 practice guide as the reference text for auditors and audited handlers. It applies to personal information handlers and professional audit institutions. Its general requirements track the Measures — handlers of more than 1 million individuals' data must designate a PIPO to lead audits, large platforms must set up an outside-member supervisory body, professional institutions may not subcontract or audit the same client more than three consecutive times, and audit frequency is at least every two years above 10 million individuals, every three to four years between 1 and 10 million, preferably every five years below, and annually for minors' data — and add staffing floors: at least ten auditors (one senior, three intermediate) above 10 million and five (two intermediate or above) between 1 and 10 million, with junior, intermediate and senior competence profiles defined by years of experience and project counts. Chapter 5 sets a five-stage process — preparation, fieldwork, reporting, rectification and archiving — with required contents for the audit plan, working papers and report, signature rules, and a dispute-resolution mechanism. Chapter 6 is the substance: 26 audit areas, each with audit content, reference evidence and method, covering lawful basis and consent, processing rules and notice, joint and entrusted processing, transfers on merger, provision to third parties, automated decision-making, public disclosure, public-place image capture, publicly available data, sensitive data, children under 14, cross-border transfers, deletion and individual rights, internal rules, technical measures, training, the PIPO, impact assessments, incident plans and response, large-platform rules and social-responsibility reports. Annexes give an evidence typology and templates for working papers and the report."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/gbt-46903-pi-compliance-audit-requirements/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Data Security Technology — Requirements for Personal Information Protection Compliance Audits (GB/T 46903-2025)", https://datacompliancechina.com/laws/gbt-46903-pi-compliance-audit-requirements/
> *DCC summary, not a translation.* GB/T 46903-2025 is a copyrighted
> national standard. The structured summary below is DCC's own paraphrase
> grounded in the published text; specific clauses should be checked
> against the standard.

**Published by:** State Administration for Market Regulation and Standardization Administration of China; proposed and administered by the National Information Security Standardization Technical Committee (SAC/TC260). Drafters include CESI, the CAC Data and Technology Support Center, CAICT, CNCERT, the MPS Third Research Institute, Tsinghua and Nanjing Audit University, and the compliance teams of Kuaishou, Ant, Douyin, Tencent, Lenovo, Taobao, Didi, Huawei and Volcano Engine.  
**Published December 31, 2025. Implemented July 1, 2026. Recommended national standard.**

## Scope

GB/T 46903-2025 states the principles of personal information protection compliance audits and specifies their general requirements, implementation process, content and methods. It applies to personal information handlers conducting self-audits and to professional institutions conducting entrusted audits. It normatively references GB/T 25069, GB/T 35273 and GB/T 45574. A *compliance audit* is the supervisory activity of examining and evaluating whether a handler's processing complies with laws and administrative regulations; the standard also defines the professional institution, auditor, audit findings, evidence, plan, working papers, conclusion and report.

## Key contents

### Principles and general requirements (clause 4)

Six principles govern every audit: legality, independence (institutions and auditors independent of the audited activity; internal auditors independent of the specific processing they audit), objectivity of evidence, impartiality of judgment, professionalism, and confidentiality.

**Management requirements (4.2.1)** restate and sharpen the [Compliance Audit Measures](/laws/personal-info-audit-measures/): a professional institution must have suitable staff, premises, facilities and funds; it may not subcontract the audit; the same institution or affiliated institutions and the same audit lead may not audit the same client more than three consecutive times; and it must delete the information obtained once the audit ends. A handler auditing itself must, if it processes the personal information of more than 1 million individuals, designate its personal information protection officer to lead the audit; a large platform (more than 50 million registered or 10 million monthly active users, complex business, significant national-security or economic impact) must establish an independent body mainly composed of external members to supervise the audit; and every self-auditing handler must adopt an audit management system, provide budget, staff, premises and tools, keep auditors out of management and decision-making for the audited activity, preferably report directly to the board or a security-and-compliance committee, and maintain an evidence base of policies, technical measures, processing records, operation logs, inspection records and test reports.

**Evidence (4.2.2).** Evidence must be genuine, complete and valid: management documents properly drafted and approved; agreements effectively consented to and performed; work files reflecting reality; access, storage, transfer and deletion logs untampered originals; certifications within validity; and test reports stamped by the testing body. Annex A classifies evidence types and validity.

**Staffing (4.2.3).** Auditors are graded junior, intermediate and senior. A handler processing more than 10 million individuals' data must have at least ten auditors including at least one senior and three intermediate; one processing between 1 and 10 million must have at least five including at least two intermediate or above.

**Frequency (4.2.4).** At least once every two years above 10 million individuals; once every three or four years between 1 and 10 million, calibrated to risk and scale; preferably once every five years below 1 million; and annually for handlers processing minors' personal information, with the results reported to the cyberspace administration.

**Documentation (4.2.5).** An audit plan (scope, basis, content and methods, organization and staff, schedule and requirements); working papers explaining steps, methods, findings, recommendations, evidence and basis for every audit item (template in Annex B); and an audit report with overview, basis, conclusions, findings, opinions and recommendations (template in Annex C). Internal reports are signed by the audit lead and, above 1 million individuals, by the PIPO; institutional reports are signed by the institution's principal and the audit lead and stamped.

**Auditor conduct and competence (4.3).** Independence (recusal from own business, no family, financial or legal ties with the client, no gifts, voluntary and client-requested recusal), objectivity, impartiality and confidentiality (NDA before the audit, no use beyond the audit purpose, no third-party disclosure). Junior auditors need at least two years in personal information protection and work under supervision; intermediate auditors need at least three years and, in the last three years, five projects as a core member for handlers above 10 million or five as lead for handlers between 1 and 10 million; senior auditors need at least four years, five projects as lead for handlers above 10 million in the last three years, the ability to design audit programs, lead teams, resolve disputes with the client and sign off the final report.

### Implementation process (clause 5)

Five stages. **Preparation:** define scope and basis; form the audit team (from a dedicated team, from internal audit, security and legal teams in reasonable proportions with the lead approving the roster, or from the professional institution with internal support), appoint the lead and train; conduct a pre-audit survey of organization, PIPO and department, processing scenarios (categories, volume, sensitivity, purposes, methods, key business flows), supporting systems, rules and procedures, technical measures and past incidents; choose on-site and off-site methods, preferably electronic and automated; prepare and review the plan (eleven required elements, re-drafted when objectives, object or basis change). **Fieldwork:** notify the client of participants, objectives, methods, risk management, channels, resources, confidentiality, safety and feedback; collect evidence widely and archive it; accept only qualifying evidence, including current-year or still-valid results of official inspections, tests, assessments and certifications; where necessary test and analyze to form admissible evidence; write working papers with thirteen listed elements; and confirm findings with management at a meeting, recording unresolved disagreements and ranking problems by impact and remediation cost. **Reporting:** a dispute-resolution mechanism before drafting; a report covering overview (auditor, client profile, background, objectives and scope, focus, procedures and methods), basis, process, conclusions, findings (facts, characterization, causes, consequences), opinions, recommendations and supporting material; delivery within the agreed period. **Rectification:** track non-compliance, press for correction within the deadline and, where necessary, follow-up audit. **Archiving:** retain working papers and reports.

### Audit content and methods (clause 6)

For each of 26 areas the standard prescribes audit content, reference evidence and audit method. The areas are: (1) lawfulness of processing — consent obtained voluntarily and explicitly with full knowledge, no default, forced or deceptive consent, re-consent on change of purpose, method or category, separate or written consent where required, and lawful bases for processing without consent; (2) the normativity of processing rules — handler identity and working contact details, a list of collected information with methods and categories, purposes, retention, and rights channels; (3) performance of the notice obligation; (4) joint processing; (5) entrusted processing; (6) transfer on merger, restructuring, division, dissolution or bankruptcy; (7) provision to other handlers; (8) automated decision-making; (9) public disclosure based on consent; (10) image-collection and identification equipment in public places; (11) processing of publicly available information; (12) sensitive personal information; (13) children under 14; (14) cross-border provision; (15) deletion rights; (16) individual rights in processing; (17) responding to individuals and explaining rules; (18) internal management systems and operating procedures; (19) technical security measures; (20) training plans; (21) the personal information protection officer; (22) impact assessments; (23) incident emergency plans; (24) incident response and handling; (25) large-platform rules; and (26) social-responsibility reports. The consent items, for example, direct the auditor to verify whether processing rests on consent, whether the rules are adequate, whether the mechanism secures consent before processing without default or coerced consent, and to sample consent records, including first-consent, re-consent and withdrawal logs.

### Annexes

Annex A (evidence types and validity), Annex B (working-paper template) and Annex C (report template) are informative.

## How it fits the regime

The standard is the audit rubric for PIPL Article 54 (periodic compliance audits) and Article 64 (audits ordered by regulators), as implemented by the CAC's [Compliance Audit Measures](/laws/personal-info-audit-measures/) effective May 1, 2025, and it supersedes in practice the [TC260 practice guide](/laws/tc260-pi-audit-practice-guide/) that auditors used during the Measures' first year. Where the Measures set the who and when — thresholds, frequencies, independence rules and the reporting duty for minors' data under the [minors' audit announcement](/laws/minors-pi-compliance-audit-reporting-announcement/) — the standard sets the how: staffing and competence floors, a five-stage process with documented outputs, and a 26-area checklist keyed to PIPL articles with evidence lists and test methods. For multinational handlers, three points matter most: the cross-border audit area (item 14) tests the mechanism chosen under the [Cross-border Data Flows Provisions](/laws/cross-border-data-flows-provisions/) and the records behind it; the staffing floors effectively require a standing audit function, not an annual consultancy engagement, above 10 million individuals; and the acceptance of still-valid official inspection and certification results as evidence rewards handlers that hold personal-information protection certification. The sensitive-information area applies [GB/T 45574](/laws/gbt-45574-sensitive-pi-processing-security/) as its normative baseline.
