2025-12-5 10.1.6.65
Code of China Chinese Classification Professional Classification ICS Classification Latest News Value-added Services

Position: Chinese Standard in English/GB/T 40660-2021
GB/T 40660-2021   Information security technology—General requirements for biometric information protection (English Version)
Standard No.: GB/T 40660-2021 Status:valid remind me the status change

Email:

Target Language:English File Format:PDF
Word Count: 6000 words Translation Price(USD):180.0 remind me the price change

Email:

Implemented on:2022-5-1 Delivery: via email in 1 business day

→ → →

,,2022-5-1,4B9AF7558BED94741634817706718
Standard No.: GB/T 40660-2021
English Name: Information security technology—General requirements for biometric information protection
Chinese Name: 信息安全技术 生物特征识别信息保护基本要求
Professional Classification: GB    National Standard
Source Content Issued by: SAMR; SAC
Issued on: 2021-10-11
Implemented on: 2022-5-1
Status: valid
Target Language: English
File Format: PDF
Word Count: 6000 words
Translation Price(USD): 180.0
Delivery: via email in 1 business day
Codeofchina.com is in charge of this English translation. In case of any doubt about the English translation, the Chinese original shall be considered authoritative. This document is developed in accordance with the rules given in GB/T 1.1-2020 Directives for standardization—Part 1: Rules for the structure and drafting of standardizing documents. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. The issuing body of this document shall not be held responsible for identifying any or all such patent rights. This document was proposed by and is under the jurisdiction of National Information Security Standardization Technical Committee (SAC/TC 260). Information security technology— General requirements of biometric information protection 1 Scope This document specifies the basic principles and relevant security requirements which shall be followed during biometric information processing activities like collection, storage, use, entrusted processing, sharing, transfer, public disclosure and deletion carried out by the biometric information controller. This document is applicable to standardizing all kinds of biometric information controllers to carry out biometric information processing activities, and is also applicable to third-party organizations to evaluate biometric information processing activities. 2 Normative references The following referenced documents are indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies. GB/T 25069 Information security technology glossary GB/T 35273-2020 Information security technology—Personal information security specification 3 Terms and definitions For the purposes of this document, the terms and definitions given in GB/T 25069, GB/T 35273-2020 and the following apply. 3.1 biometric original information analog or digital representation of physical, biological or behavioral features of natural persons obtained by means of collecting and preprocessing Note: Like samples, images, etc. 3.2 biometric comparison information information obtained by technical processing of the biometric original information and used for comparison 3.3 biometric information personal information obtained by technical processing of physical, biological or behavioral features of a natural person, which can identify the information of the natural person alone or in combination with other information Note 1: The biometric information includes personal facial recognition features, iris, fingerprint, gene, voiceprint, gait, palmprint, auricle, eyeprint, etc. Note 2: The biometric information covers biometric original information and biometric comparison information. 3.4 biometric information subject natural person identified by or connected to biometric information 3.5 biometric information controller organization or individual that has the power to determine the purpose, manner, etc. of the processing of biometric information 3.6 revoke behavior preventing a specific biometric comparison information and corresponding identity-related information from passing verification. Note: A biometric information subject may be rejected because it has been added to the revoke list. 3.7 irreversibility property impossible to infer the biometric original information from the biometric comparison information 3.8 unlinkability property of two or more pieces of biometric comparison information that cannot be linked to each other Note: With unlinkability, one user can use different programs, resources and services for multiple times, while others cannot associate these uses through biometric comparison information.   4 Basic principles for protection of biometric information The basic principles for protection of biometric information are as follows: a) All requirements for personal information controllers in GB/T 35273-2020 shall be met. b) The basic principles of personal information security in Clause 4 of GB/T 35273-2020 as well as the following principles shall be followed: 1) Independently selecting——ensure that individuals have the right to select whether to use biometric information or not, that individuals provide biometric information through direct means voluntarily, and that individuals have continuous right of control over their biometric information in the scene where activities related to identification are conducted; 2) Diversity and updatability—use biometric comparison information with characteristics of irreversibility, unlinkability, diversity and updatability; 3) Fully informed——ensure that the biometric information subject has the right to be informed for biometric information processing and security incidents. 5 Collection of biometric information The requirements for biometric information controllers are as follows. a) The collection of biometric information shall not be limited as the only way to achieve business objectives, except for the scenarios stipulated by laws and regulations and the scenarios of protecting public interests and important personal interests. b) Before collecting biometric information, the following information shall be informed to the biometric information subject and the explicit consent of the biometric information subject shall be obtained: 1) Purpose, method and scope of collecting and using biometric information, as well as the authorized storage time, etc.; 2) Description of the processing method of the collected biometric information; 3) Contact details of the biometric information controller, including organization information, contact information, etc.; 4) Methods used by the biometric information subject to view, modify and withdraw its consent. c) It shall be avoided to collect biometric information that does not belong to the biometric information subject, including biometric original information. d) It shall be avoided to obtain the information from the non biometric information subject in an indirect way. e) When the biometric information subject is unable to complete the information collection, the subsequent available alternative processing flow shall be informed. f) When biometric information is collected according to relevant national laws and regulations, the biometric information subject shall be informed of relevant requirements and the type of biometric information collected. g) The risk of interference and attack shall be fully considered. The factors to be considered include but are not limited to different attack forms such as physical and virtual forms, different attack materials such as paper and plastic, and different attack environments such as presentation angles and light conditions.
Foreword i 1 Scope 2 Normative references 3 Terms and definitions 4 Basic principles for protection of biometric information 5 Collection of biometric information 6 Storage of biometric information 7 Use of biometric information 8 Rights of biometric information subject 9 Entrusted processing, sharing, transfer and public disclosure of biometric information 10 Processing of biometric information security incidents 11 Requirements for biometric information security management Bibliography
Referred in GB/T 40660-2021:
*GB/T 25069-2022 Information security techniques—Terminology
*GB/T 35273-2020 Information security technology—Personal information security specification
*GB 3565-2005 Safety requirements for bicycles
*TSG 21-2016/XG1-2020 Supervision Regulation on Safety Technology for Stationary Pressure Vessel,includes Amendment 1
*GB 14748-2006 Safety Requirements for Wheeled Child Conveyances
*GB 2763-2021 National Food Safety Standard-Maximum Residue Limits for Pesticides in Food
*GB/T 22849-2014 Knitted T-shirt
*GB 4943.1-2011 Information technology equipment -Safety - Part 1: General requirements
*GB/T 95-2002 Plain washers - Product grade C
*GB/T 35590-2017 Information technology―General specification for portable digital equipments used power bank
*GB/T 2662-2008 Cotton wadded clothes
*GB/T 2662-2017 Clothes with fillings
*GB/T 14048.5-2017 Low-voltage switchgear and controlgear-Part 5-1:Control circuit devices and switching element-Electromechanical control circuit devices
*GB/T 18455-2022 Packaging recycling marking
*GB/T 2664-2009 Mens suits and coats
*GB/T 14272-2011 Down Garments
*GB/T 14272-2021 Down garments
*GB 4706.1-2005 Household and Similar Electrical Appliances – Safety - Part 1: General Requirements
*GB 4806.7-2016 National Food Safety Standard - Food Contact Plastic Materials and Articles
*GB 18401-2003 National General Safety Technical Code for Textile Products
*GB 18401-2010 National general safety technical code for textile products
GB/T 40660-2021 is referred in:
*GB/T 41871-2022 Information security technology—Security requirements for processing of motor vehicle data
*YY/T 0243-2003 Plunger of sterile syringes for single use
*YY/T 0243-1996 Plunger seal of sterilized syringes for single use
*YY/T 0243-2016 Plunger seal of syringes for single use
*GB/T 4336-1984 Method for photoelectric emission spectroscopic analysis of carbon steel medium and low alloy steel
*GB/T 4336-2002 Standard Test Method for Spark Discharge Atomic Emission Spectrometric Analysis of Carbon and Low-Alloy Steel (Routine Method)
*GB 14621-1993 Emission standard for exhaust emissions from motorcycle
*GB 14621-2002 Limits and measurement methods for exhaust emissions from motorcycles and mopeds at idle speed
*GB 9689-1988 Hygienic STANDARD for polystyrene products used as food containers and table wares
*GB/T 26703-2011 Determination of abrasion resistance for top piece of leather shoes - Rotation cylindrical drum method
*GB/T 26703-2021 Determination of abrasion resistance for top piece of leather shoes
*TB 10063-1999 Code for design on fire prevention of railway engineering
*TB 10063-2007 Code for design on fire prevention of railway engineering
*TB 10063-2016 Code for Design of Fire Prevention for Railway Engineering
*GB/T 5373-1994 Measuring method of dimensions and masses parameter for motorcycles and mopeds
*GB/T 2101-1989 Generel provisions on acceptance, package, marking and quality certificate for profile steel
*GB/T 2101-2008 General requirement of acceptance packaging marking and certification for section steel
*GB/T 42981-2023 Information technology—Biometrics—Test methods for face recognition system
*GB/T 41773-2022 Information security technology—Security requirements of gait recognition data
*GB/T 41807-2022 Information security technology—Security requirements of voiceprint recognition data
*GB/T 41819-2022 Information security technology—Security requirements of face recognition data
Code of China
Standard
GB/T 40660-2021  Information security technology—General requirements for biometric information protection (English Version)
Standard No.GB/T 40660-2021
Statusvalid
LanguageEnglish
File FormatPDF
Word Count6000 words
Price(USD)180.0
Implemented on2022-5-1
Deliveryvia email in 1 business day
Detail of GB/T 40660-2021
Standard No.
GB/T 40660-2021
English Name
Information security technology—General requirements for biometric information protection
Chinese Name
信息安全技术 生物特征识别信息保护基本要求
Chinese Classification
Professional Classification
GB
ICS Classification
Issued by
SAMR; SAC
Issued on
2021-10-11
Implemented on
2022-5-1
Status
valid
Superseded by
Superseded on
Abolished on
Superseding
Language
English
File Format
PDF
Word Count
6000 words
Price(USD)
180.0
Keywords
GB/T 40660-2021, GB 40660-2021, GBT 40660-2021, GB/T40660-2021, GB/T 40660, GB/T40660, GB40660-2021, GB 40660, GB40660, GBT40660-2021, GBT 40660, GBT40660
Introduction of GB/T 40660-2021
Codeofchina.com is in charge of this English translation. In case of any doubt about the English translation, the Chinese original shall be considered authoritative. This document is developed in accordance with the rules given in GB/T 1.1-2020 Directives for standardization—Part 1: Rules for the structure and drafting of standardizing documents. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. The issuing body of this document shall not be held responsible for identifying any or all such patent rights. This document was proposed by and is under the jurisdiction of National Information Security Standardization Technical Committee (SAC/TC 260). Information security technology— General requirements of biometric information protection 1 Scope This document specifies the basic principles and relevant security requirements which shall be followed during biometric information processing activities like collection, storage, use, entrusted processing, sharing, transfer, public disclosure and deletion carried out by the biometric information controller. This document is applicable to standardizing all kinds of biometric information controllers to carry out biometric information processing activities, and is also applicable to third-party organizations to evaluate biometric information processing activities. 2 Normative references The following referenced documents are indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies. GB/T 25069 Information security technology glossary GB/T 35273-2020 Information security technology—Personal information security specification 3 Terms and definitions For the purposes of this document, the terms and definitions given in GB/T 25069, GB/T 35273-2020 and the following apply. 3.1 biometric original information analog or digital representation of physical, biological or behavioral features of natural persons obtained by means of collecting and preprocessing Note: Like samples, images, etc. 3.2 biometric comparison information information obtained by technical processing of the biometric original information and used for comparison 3.3 biometric information personal information obtained by technical processing of physical, biological or behavioral features of a natural person, which can identify the information of the natural person alone or in combination with other information Note 1: The biometric information includes personal facial recognition features, iris, fingerprint, gene, voiceprint, gait, palmprint, auricle, eyeprint, etc. Note 2: The biometric information covers biometric original information and biometric comparison information. 3.4 biometric information subject natural person identified by or connected to biometric information 3.5 biometric information controller organization or individual that has the power to determine the purpose, manner, etc. of the processing of biometric information 3.6 revoke behavior preventing a specific biometric comparison information and corresponding identity-related information from passing verification. Note: A biometric information subject may be rejected because it has been added to the revoke list. 3.7 irreversibility property impossible to infer the biometric original information from the biometric comparison information 3.8 unlinkability property of two or more pieces of biometric comparison information that cannot be linked to each other Note: With unlinkability, one user can use different programs, resources and services for multiple times, while others cannot associate these uses through biometric comparison information.   4 Basic principles for protection of biometric information The basic principles for protection of biometric information are as follows: a) All requirements for personal information controllers in GB/T 35273-2020 shall be met. b) The basic principles of personal information security in Clause 4 of GB/T 35273-2020 as well as the following principles shall be followed: 1) Independently selecting——ensure that individuals have the right to select whether to use biometric information or not, that individuals provide biometric information through direct means voluntarily, and that individuals have continuous right of control over their biometric information in the scene where activities related to identification are conducted; 2) Diversity and updatability—use biometric comparison information with characteristics of irreversibility, unlinkability, diversity and updatability; 3) Fully informed——ensure that the biometric information subject has the right to be informed for biometric information processing and security incidents. 5 Collection of biometric information The requirements for biometric information controllers are as follows. a) The collection of biometric information shall not be limited as the only way to achieve business objectives, except for the scenarios stipulated by laws and regulations and the scenarios of protecting public interests and important personal interests. b) Before collecting biometric information, the following information shall be informed to the biometric information subject and the explicit consent of the biometric information subject shall be obtained: 1) Purpose, method and scope of collecting and using biometric information, as well as the authorized storage time, etc.; 2) Description of the processing method of the collected biometric information; 3) Contact details of the biometric information controller, including organization information, contact information, etc.; 4) Methods used by the biometric information subject to view, modify and withdraw its consent. c) It shall be avoided to collect biometric information that does not belong to the biometric information subject, including biometric original information. d) It shall be avoided to obtain the information from the non biometric information subject in an indirect way. e) When the biometric information subject is unable to complete the information collection, the subsequent available alternative processing flow shall be informed. f) When biometric information is collected according to relevant national laws and regulations, the biometric information subject shall be informed of relevant requirements and the type of biometric information collected. g) The risk of interference and attack shall be fully considered. The factors to be considered include but are not limited to different attack forms such as physical and virtual forms, different attack materials such as paper and plastic, and different attack environments such as presentation angles and light conditions.
Contents of GB/T 40660-2021
Foreword i 1 Scope 2 Normative references 3 Terms and definitions 4 Basic principles for protection of biometric information 5 Collection of biometric information 6 Storage of biometric information 7 Use of biometric information 8 Rights of biometric information subject 9 Entrusted processing, sharing, transfer and public disclosure of biometric information 10 Processing of biometric information security incidents 11 Requirements for biometric information security management Bibliography
About Us   |    Contact Us   |    Terms of Service   |    Privacy   |    Cancellation & Refund Policy   |    Payment
Tel: +86-10-8572 5655 | Fax: +86-10-8581 9515 | Email: coc@codeofchina.com | QQ: 672269886
Copyright: Beijing COC Tech Co., Ltd. 2008-2040
 
 
Keywords:
GB/T 40660-2021, GB 40660-2021, GBT 40660-2021, GB/T40660-2021, GB/T 40660, GB/T40660, GB40660-2021, GB 40660, GB40660, GBT40660-2021, GBT 40660, GBT40660