Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ LAW · GB/T 47469

Data Security Technology — Management Guidance for Smart Mobile Terminals on Personal Information Processing Activities of Mobile Internet Applications (Apps) (GB/T 47469-2026).

数据安全技术 移动智能终端的移动互联网应用程序(App)个人信息处理活动管理指南 (GB/T 47469-2026)

DCC summary, not a translation. GB/T 47469-2026 is a copyrighted national standard. The structured summary below is DCC’s own paraphrase grounded in the published text; specific clauses should be checked against the standard.

Published by: State Administration for Market Regulation and Standardization Administration of China; proposed and administered by the National Information Security Standardization Technical Committee (SAC/TC260). Drafters led by Huawei with CESI, CNCERT, the China Cybersecurity Review, Certification and Market Regulation Big Data Center, OPPO, vivo, Ant, Baidu, Kuaishou and others.
Published April 30, 2026. Implemented November 1, 2026. Recommended national standard.

Scope

GB/T 47469-2026 gives recommendations on personal-information protection management measures for smart mobile terminals (智能移动终端 — smartphones and tablets, with other terminals by reference) and applies to guide terminal providers in designing and developing personal-information protection functions. It normatively references GB/T 25069-2022 and GB/T 35273-2020, and draws its definitions of terminal, operating system, app, “permissions capable of collecting personal information” and app list from GB/T 34976-2017 and GB/T 41391-2022. The introduction frames the standard around the terminal as the carrier of apps: the operating system’s management mechanisms are what make reasonable collection possible, and the standard’s basic principle is that users should be able to know and control what apps do.

Key contents

Scope of terminal personal information and principles (clause 5). Terminal personal information is what an app can obtain through the device — stored or sensed — including contacts, call records, SMS, media (images, audio, video), device identifiers, the phone number, the installed-app list, location and network-access information. Six management principles apply: user knowledge (record and prompt app behavior), user control (allow and refuse), security (secure storage against tampering and theft), fine-grained management for more sensitive items, proportionate management that does not disrupt users or normal app operation, and clear rules.

Risks (clause 6). Three classes: misuse through collection without the user’s knowledge where the terminal offers no effective prompt or display; harm from weak user control, enabling over-scope or over-frequency collection or forced, induced or deceptive consent; and lifecycle risks — silently installed malicious apps, self-start or associated start followed by unconsented processing, updates that introduce vulnerabilities or malware, and residual data after uninstall.

Tiered measures (7.1). Measures are graded basic and enhanced (the latter shown in bold in the standard).

Transparency (7.2). Prompting: while an app continuously or frequently uses a collecting permission such as microphone, camera or location, the terminal displays an indicator in a prominent position (status bar, colored corner icon or pull-down panel), in both foreground and background, with an explanation of its meaning and the ability to see which app is using the permission and adjust the grant. Behavior logging: the terminal records app reads of location, contacts, media, SMS, biometric data, unique device identifiers (IMEI, WLAN MAC), call logs, microphone and camera use and background screenshots or screen recording; self-start and associated start; and reads of the app list and clipboard. Records are shown by total (app, behavior, count) or per event (app, behavior, start time to the minute, app version), with aggregation permitted for high-frequency location or media reads; retention is at least seven days, adjustable to device capacity or by the user. Central management: a single prominent entry in the second level of the settings menu shows behavior records and hosts permission and other personal-information management screens.

Authorization management (7.3.1). One-time grants for location, camera and microphone that must be renewed on next use; “only while in use” grants tied to foreground operation; developer-editable purpose statements shown in the permission dialog; and automatic reset of permissions after long non-use (about three months), with the user able to toggle the feature.

Sensitive-behavior management (7.3.2). App-list access only with user authorization (always allow or refuse); clipboard access with a prompt when not user-triggered or subject to authorization; screenshot calls only with authorization; location only with authorization and an option to grant only coarse, offset location; no background activation of microphone or camera; media access by authorization or, when the user picks specific photos or videos, access to only those items without an album, media or storage permission; an option to strip attached metadata when sharing images from the gallery; contacts access by authorization, picker-based access to selected contacts, and restriction of contacts permissions to apps with contact-related functions (calling and messaging from contacts, backup, spam blocking); picker-based file access without a storage permission; SMS access by authorization and restricted to apps with SMS functions; call-log access by authorization and restricted to apps with calling functions; and public interfaces that launch the system dialer or SMS composer so apps can place calls and send messages through user action without holding the permission. Annex A tabulates, for each data type, whether the terminal prompts, whether it logs, and the grant granularity — for example, location: prompt and log, with always-allow, refuse, ask-each-time, and while-in-use grants; contacts, SMS and call logs: log without prompt, allow or refuse.

Device identifiers (7.3.3). Restrict app access to immutable identifiers (per GB/T 41391-2022 Annex F); randomize the WLAN MAC address when broadcasting; let users reset the resettable identifier used for third-party tracking; let users switch it off, after which apps receive only zero or an off-state value and cannot identify or link the device; and allow per-app configuration of the resettable identifier.

Storage (7.3.4). Private app directories inaccessible to other apps, and storage encryption for app-held personal information.

Lifecycle (7.4). Install only with user consent, preventing silent installs; no one-shot bulk grant of requested permissions at install; the same rules for updates; a user-facing switch to disable self-start and associated start; and complete deletion of personal information in the private directory on uninstall.

How it fits the regime

The app-compliance regime built since 2019 — the Identification Method for Unlawful Collection by Apps, the Necessary Information Scope Provisions, the Mobile App Information Services Provisions and the platform-processing standard GB/T 44588 — regulates what app operators may do. GB/T 47469 closes the loop from the other side by specifying what the operating system must make possible and visible: the indicator, the seven-day behavior log, picker-based access, coarse location, background camera and microphone blocks and identifier controls are the technical means by which the necessity and consent rules become enforceable on the device. It is the national-standard codification of practices the MIIT has pressed on domestic handset makers through its app-rectification campaigns and the 2022 pre-installation notice cited in its bibliography. For overseas device makers selling in China and for app developers, it forecasts the platform behaviors — permission resets, while-in-use grants, per-app advertising identifiers — that Chinese Android skins will converge on, and it gives regulators a benchmark for judging whether a terminal’s privacy features are adequate.

§ RELATED LAWS

See also.

§ COMMENTARY

Briefs on this law.

No briefs filed yet under this law.

§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →