The Personal Information Security Specification, formally known as GB/T 35273, is a recommended national standard issued by China’s National Information Security Standardisation Technical Committee (TC260). Although technically voluntary, it is widely treated as a de facto compliance benchmark because regulators and courts reference it when evaluating whether an organisation’s data practices meet the requirements of the Cybersecurity Law and PIPL.
The specification covers the full lifecycle of personal information, collection, storage, use, sharing, transfer, public disclosure, and deletion, and sets detailed expectations for notice, consent, data minimisation, and security controls.
GB/T 35273 distinguishes between personal information and sensitive personal information, with stricter rules for the latter, including explicit consent, purpose limitation, and enhanced encryption. It mandates that controllers provide clear privacy notices before collection, honour withdrawal-of-consent requests promptly, and conduct personal information security impact assessments when introducing new processing activities or technologies.
The specification also addresses anonymisation standards, requiring that anonymised data be irreversibly de-identified before it can fall outside the scope of personal-data rules.
Seers.ai directly supports many GB/T 35273 requirements. It presents purpose-specific consent prompts that distinguish between essential and non-essential processing, records explicit opt-in for sensitive-data categories, and provides users with a self-service mechanism to withdraw consent at any time.
The platform’s cookie categorisation tool maps each tracker to a declared purpose, enabling the transparency and data-minimisation controls the specification demands. For organisations seeking to demonstrate alignment during a CAC review or certification audit, Seers’ exportable consent logs serve as auditable evidence of good practice.
Build audit-ready consent records for GB/T 35273 with Seers AI
START FREE TODAY