![]() |
中标分类
行业分类
ICS分类
最新标准
|
登录注册 |
您的位置: 标准明细 |
Forword This document is drafted in accordance with GB/T1.1-2020 Guidelines for Standardization: Part 1: Structure and Drafting Rules of Standardization Documents. Please note that some of the contents of this document may involve patents. The issuing agency of this document does not assume the responsibility of identifying the patent. This document is proposed and under the jurisdiction of the National Technical Committee for Information Security Standardization (SAC/TC260). 1 Scope This document specifies the general safety requirements, external data safety requirements, cockpit data safety requirements and management safety requirements for vehicle data processors to collect and transmit vehicle data. This document is applicable to the automobile data processing activities carried out by automobile data processors, the design, production, sales, use and operation and maintenance of automobiles, as well as the supervision, management and evaluation of automobile data processing activities by competent regulatory authorities and third-party evaluation institutions. 2 Normative References The contents in the following documents, through normative references, constitute indispensable provisions of this document. For dated references, only the version corresponding to that date is applicable to this document; For undated references, the latest version (including all amendments) is applicable to this document. GB/T 35273 Information Security Technology Personal Information Security Specification GB/T 40660 Information Security Technology - Basic Requirements for Biometric Information Protection 3 Terms and definitions The following terms and definitions apply to this document. three point one Motor vehicle data Personal information data and important data involved in the process of automobile design, production, sales, use, operation and maintenance. three point two Personal information All kinds of information related to identified or recognizable vehicle owners, drivers, passengers, and people outside the vehicle recorded by electricity or other means do not include anonymous information. three point three Sensitive personal information Once disclosed or illegally used, personal information that may lead to discrimination against the owner, driver, passengers, people outside the vehicle, or serious harm to personal and property safety. Note: Sensitive personal information includes personal information such as track, audio, video, image, medical health, religious belief, biometric information such as fingerprint, rhythm, voice print, and local identification features, personal identity information that can identify specific identity, bank account, authentication information (password) Financial account and other personal property information, as well as personal information of minors less than 14 weeks old. three point four Important data Data that may endanger national security, public interests or the legitimate rights and interests of individuals and organizations once it is tampered, destroyed, disclosed or illegally obtained or used. Note: Important data include geographic information, personnel flow, vehicle flow and other data in important sensitive areas such as military management areas, national defense science and industry units, and party and government organs at or above the county level. Vehicle flow, logistics and other data reflect economic operation. Vehicle charging network operation data includes video and image data outside the vehicle including face information, license plate information, and personal information involving more than 100000 personal information subjects, Other 6 types of data identified by relevant departments that may endanger national security, public interests or the legitimate rights and interests of individuals and organizations. three point five Motor vehicle data processor Organizations that carry out automobile data processing activities, including automobile manufacturers, parts and software suppliers, dealers, maintenance agencies and travel service enterprises. three point six Cabin data Data that may contain personal information collected from the car cabin through cameras, infrared sensors, fingerprint sensors or microphones and other components, as well as data generated after processing. 4 General safety requirements four point one The automobile data processor shall process personal information in accordance with the following requirements. All requirements in GB/T 35273 shall be met. Individual consent should be communicated to the individual in at least one significant way. Notable methods include separate chapter and article prompts in the user manual, voice playback, separate pop-up prompts in the on-board display panel, interaction of relevant applications for automobile use, separate chapter and article prompts in the automobile sales agreement, separate chapter and article prompts in the maintenance service agreement, or interaction of travel service applications. The specific situation and necessity of collecting personal information shall be explained to the personal information subject in clear and understandable words. When informing the personal information subject of the retention period of various types of personal information, it should be specific and clear, such as 30 days or 1 year. When the personal information subject is informed of the storage location of his/her personal information, the location of the storage location shall be accurate to the prefecture level city and all storage locations shall be informed. The personal information subject shall be provided with convenient access, copy, deletion and other personal information management functions; When the products or services provided support interactive operation, such as providing websites, on-board applications or mobile communication terminal applications, the personal information management function shall be interactive, and its function entrance shall be at a prominent position easily perceived by the personal information subject. The vehicle data processor shall process sensitive personal information in accordance with the following requirements. Individual consent should be obtained from the personal information subject for each sensitive personal information. Consents should not be obtained for multiple sensitive personal information or multiple processing activities at one time. Note: The car data processor needs to process voice data to provide voice recognition function for the driver. The driver's consent can be obtained by popping up a window for this function separately, and the driver's consent can be obtained by checking the individual options for this function in the notification consent. When obtaining the individual consent of the personal information subject • The consent period for handling sensitive personal information should not be set as "always allowed" or "permanent". Note: The automobile data processor needs to process voice data for the voice recognition function. With the individual consent of the personal information subject, it can provide the personal information subject with options such as single time, seven days, three months and one year. In order to complete the deletion within ten working days after receiving the request for deletion of personal information • In principle, a structured directory of personal information shall be established to realize the traceability management of personal information. In principle, sensitive personal information should not be processed for the purpose of improving service quality, enhancing user experience and developing new products. The vehicle data processor's continuous collection of sensitive personal information meets the following notification requirements. a) The collection status shall be indicated by flashing or lighting of on-board display panel icon or signal bone mounting indicator. b) When continuously prompting to collect sensitive personal information, clear and understandable prompts should be set according to different types of information. Note: The camera icon flashes or lights up for a long time to indicate that video data in the car is being collected. The recording icon flashes or lights up for a long time to indicate that voice data in the car is being collected. The oblique upward triangle icon flashes or lights up for a long time to indicate that position data is being collected. The automobile data processor shall process biometric feature information such as face, voice print or fingerprint in accordance with the following requirements. a) It shall assess whether it is necessary to increase or decrease the traffic safety. Note: The purpose of enhancing traffic safety funds includes identity verification and status monitoring of rolling drivers. b) All requirements of GBT 40660 shall be met. 4.5 The user rights and interests affairs contacts set by the automobile data processor in terms of personal information protection shall meet the following requirements. They should have professional knowledge in personal information protection and personal rights protection. Complaints and reports on personal information protection shall be accepted and handled in a timely manner. The accurate and effective name and contact information shall be informed externally. The contact information includes telephone number, email address, website or instant messaging platform account, etc; If it is inconvenient to inform the real name, the long-term and fixed alias shall be informed. 4.6 Personal information involving cabin data, position track data, video and image data outside the vehicle, as well as personal information involving more than 100000 personal information subjects, shall be stored in the People's Republic of China by vehicle data processors according to law. 4.7 The vehicle data processor shall process important data, and generally conduct other processing after completing desensitization processing; Personal information shall be processed after anonymization or de identification. 5 Safety requirements for external data The anonymization of the data outside the vehicle by the vehicle data processor meets the following requirements. a) The data outside the vehicle shall not be provided outside the vehicle before anonymous processing. b) The anonymized video and image cannot be restored and cannot be associated with the personal information subject, including the following implementations: 1) Complete deletion: when processing the image, the image containing personal information such as face and license plate will be deleted directly; When processing video, delete all video frames containing personal information such as face and license plate; 2) Local contour processing: completely erase the video and image areas containing personal information such as face and license plate, or replace these areas with other images that cannot be associated with personal information subjects and cannot be restored. c) In the process of anonymization, in addition to analyzing and determining the areas containing personal information such as face and license plate, and deleting or local contour processing of these areas, face comparison, gait analysis, speech recognition and other processing shall not be conducted. d) After anonymization, process data shall be deleted immediately and shall not be provided outside the vehicle. 6 Cabin Data Security Requirements Except for the driver's main setting, the car should be set to not collect cockpit data by default, including not turning on the camera, microphone, infrared sensor, fingerprint sensor and other components in the car. The collection can only be started after the driver actively selects through physical keys or touch keys. The car can maintain the state selected by the driver or restore the default state according to the driver's settings. 6.2 The vehicle shall not provide cabin data outside the vehicle, except for the following circumstances. In order to realize the voice recognition function to judge the vehicle control command in real time, the voice command data is processed outside the vehicle and the consent of the personal information subject is obtained. After the function is realized, the original data and processing results are deleted immediately. In order to realize the function of remote viewing of in car conditions or cloud storage, provide users with data, obtain the consent of the personal information subject, and take security measures. Other organizations and individuals other than users cannot access. Road transport vehicles shall transmit data to the monitoring platform, public management platform and regulatory authority of their transport enterprises according to relevant regulations. Operating vehicles such as taxis and buses transmit data to regulators. After the road traffic accident, the data shall be transmitted according to the requirements of the law enforcement department. 6.3 The vehicle data processor shall provide a convenient way to stop collecting cockpit data, including physical buttons, voice control, touch buttons, and applications related to vehicle use. Under the condition of ensuring driving safety and personal safety, the driver should turn off the microphone and camera in the vehicle and other components collecting cockpit data after choosing to stop collection. To ensure driving safety and personal safety, relevant parts may not be closed under the following conditions: a) Road transport vehicles providing road operation services continuously collect cockpit data: b) Buses providing travel services continuously collect cockpit data. 7 Management safety requirements 7.1 The automobile data processor shall carry out automobile data risk assessment. The assessment content generally includes automobile data identification, number recognition according to processing activities, automobile data security risk identification and risk analysis and assessment, which can be conducted in the form of self-assessment or third-party assessment. 7.2 The person in charge of automobile data security management shall be the main person in charge of automobile data processing or the person in charge of data security, and shall be familiar with China's data security and personal information protection policies and regulations, and have security management experience. 7.3 The vehicle data processor shall establish and improve the emergency response mechanism for safety incidents. At least one emergency drill shall be carried out every year, and it is advisable to support the evidence collection and analysis after the occurrence of safety incidents through vehicle data storage, vehicle data traceability and other mechanisms. 7.4 The automobile data processor shall accept the complaint about the security of the automobile data through telephone or instant messaging platform, and generally handle it within 10 working days after receiving the complaint, and make a complete record of the processing process and the processing results. 7.5 The automobile manufacturer shall fully master the data collection and transmission of all parts contained in the whole vehicle produced by it. It shall restrict and supervise the behavior of parts suppliers in processing automobile data. The complete information of automobile data transmission to the outside shall be disclosed to the user every year or in case of major changes. 8 Exceptions Except where necessary, the requirements of this document do not apply to the following data processing activities: Data processing activities of police cars, fire engines, ambulances and engineering rescue vehicles when performing emergency tasks; Vehicle data processing activities when operating vehicles with special equipment or appliances are engaged in operating activities in a closed place; Vehicle data processing activities when testing vehicles carry out scientific research, type approval test and other activities in a closed field. Forword 1 Scope 2 Normative References 3 Terms and definitions 4 General safety requirements 5 Safety requirements for external data 6 Cabin Data Security Requirements 7 Management safety requirements 8 Exceptions 前言 本文件按照GB/T1.1-2020《标准化工作导则︰第1部分:标准化文件的结构和起草规则》的规定起草。 请注意本文件的某些内容可能涉及专利。本文件的发布机构不承担识别专利的责任。本文件由全国信息安全标准化技术委员会(SAC/TC260)提出并归口。 1范围 本文件规定了汽车数据处理者对汽车数据进行收集、传输等处理活动的通用安全要求、乍外数据安全要求、座舱数据安全要求和管理安全要求。 本文件适用于汽车数据处理者开展汽车数据处理活动,适用于汽车的设计、生产、销售、使用和运维.也适用于主管监管部门和第三方评估机构等对汽车数据处理活动进行监督、管理和评估。 2规范性引用文件 下列文件中的内容通过文中的规范性引用而构成本文件必不可少的条款。其中注日期的引用文件.仅该日期对应的版本适用于本文件;不注日期的引用文件,其最新版本(包括所有的修改单)适用于本文件。 GB/T 35273信息安全技术个人信息安全规范 GB/T 40660信息安全技术生物特征识别信息保护基本要求 3术语和定义 下列术语和定义适用于本文件。 3.1 汽车数据motor vehicle data 汽车设计、生产、销售、使用、运维等过程中涉及的个人信息数据和重要数据。 3.2 个人信息personal information 以电了或者其他方式记录的与已识别或者可识别的车主、驾驶人、乘车人、车外人员等有关的各种信息,不包括匿名化处理后的信息。 3.3 敏感个人信息sensitive personal information 一旦泄露或者非法使用,可能导致车主、驾驶人、乘车人、车外人员等受到歧视或者人身、财产安全受到严重危害的个人信息。 注:敏感个人信息包括行踪轨迹、音频、视频、图像、医疗健康、宗教信仰等个人信息.指纹、心律、声纹、而部识别特征等生物识别特征信息,居民身份证、军官证、工作证、社保卡、居住证等能标识特定身份的个人身份信息.银行账户、鉴则信息(口令)、金融账户等个人财产信息.以及不满十四周步未成年人的个人信息。 3.4 重要数据important data 一旦遭到篡改、破坏、泄露或者非法获取、非法利用,可能危害国家安全、公共利益或者个人、组织合法权益的数据。 注:重要数据包括军事管理区、国防科工单位以及县级以上党政机关等重要敏感区域的地理信息、人员流量、车辆流量等数据车辆流量、物流等反映经济运行情况的数据汽车充电网的运行数据•包含人脸信息、车牌信息等的车外视频、图像数据,涉及个人信息主体超过10万人的个人信息,有关部门确定的其他可能危害国家安全、公共利益或者个人、组织合法权益的数据等6类数据。 3.5 汽车数据处理者motor vehicle data processor 开展汽车数据处理活动的组织.包括汽车制造商、零部件和软件供应商、经销商、维修机构以及出行服务企业等。 3.6 座舱数据cabin data 通过摄像头、红外传感器、指纹传感器或传声器等部件从汽车座舱采集的可能包含个人信息的数据,以及对其进行加工后产生的数据。 4通用安全要求 4.1 汽车数据处理者处理个人信息符合下列要求。 应符合GB/T 35273中的全部要求。 取得个人同意时应通过至少一种显著方式向个人告知。显著方式包括用户手册单独章条提示、语音播放、车载显示面板单独弹窗提示、汽车使用相关应用程序交互、汽车销售协议单独章条提示、维修服务协议单独章条提示或出行服务应用程序交互等。 应使用清晰易懂的文字向个人信息主体说明收集个人信息的具体情境和必要性。 向个人信息主体告知各类型个人信息的保存期限时,应具体且明确,例如30天或1年等。向个人信息主体告知其个人信息保存地点时,应将保存地点位置精确到地级市并告知所有保存地点。 应为个人信息主体提供便捷的查阅、复制和删除等个人信息管理功能;提供的产品或服务支持交互操作时,例如提供网站、车载应用程序或移动通信终端应用程序等,个人信息管理功能应为交互式,且其功能入口应处于个人信息主体容易察觉的显著位置。 汽车数据处理者处理敏感个人信息符合下列要求。 应对每项敏感个人信息取得个人信息主体单独同意.不应一次性针对多项敏感个人信息或多种处理活动取得同意。 注:汽车数据处理者为驾驶人提供语音识别功能需要处理语音数据.可针对该功能单独弹窗取得驾驶人同意,也町在告知同意中针对该功能设置.可勾选的单独选项取得咒驶人同意。 取得个人信息主体单独同意时•处理敏感个人信息的同意期限不应设置为“始终允许”或“永久”。 注:汽车数据处理者为语音识别功能需要处理语音数据,取得个人信息主体单独同意时,可为个人信息主体提供单次、七天、三个月和一年等选项。 为了在收到删除个人信息请求后十个工作日内完成删除•原则上应建立个人信息结构化目录,实现个人信息的可追溯管理。 原则上不应以改善服务质量、提升用户体验以及研发新产品等为目的处理敏感个人信息。 汽车数据处理者持续收集敏感个人信息符合下列告知要求。 a)应通过车载显示面板图标或信号装骨指示灯的闪烁或K亮等方式提示收集状态。 b)持续提示收集敏感个人信息时,应根据信息类型的不同设置差异明显日•清晰易懂的提示。 注:町通过摄像图标闪烁或长亮提示正在收集车内视频数据.通过录音图标闪烁或长亮提示正在收笑车内语音数据.通过斜向上三角图标的闪烁或长亮提示正在收集位置数据。 汽车数据处理者处理人脸、声纹或指纹等生物识别特征信息符合下列要求。 a)应评估是否具有增损行车安全的目的和充分的必要性。 注:增强行车安金的目的包括身份验证以及卷驶人状态监测等。 b)应符合GBT 40660的全部要求。 4.5汽车数据处理者在个人信息保护方面设置的用户权益事•务联系人符合下列要求。 应具备个人信息保护和个人权益保护等方面的专业知识。 应及时受理并处置个人信息保护方面的投诉和举报。 应对外告知准确有效的姓名和联系方式.联系方式包括电话号码、邮箱地址、网址或即时通信平台账号等;不便对外告知真实姓名的,应告知长期且固定使用的别名。 4.6涉及座舱数据、位置轨迹数据、车外视频和车外图像数据,以及涉及个人信息主体超过10万人的个人信息.汽车数据处理者应依法在中华人民共和国境内存储。 4.7汽车数据处理者处理重要数据,一般应在完成脱敏处理后再进行其他处理;处理个人信息,一般应在匿名化处理或去标识化处理后再进行其他处理。 5车外数据安全要求 汽车数据处理者对车外数据进行匿名化处理符合以下要求。 a)车外数据未完成匿名化处理前,不应向车外提供。 b)经过匿名化处理的视频以及图像应无法复原且无法关联个人信息主体.包括以下实现方式: 1)完整删除:处理图像时,将包含人脸以及车牌等个人信息的图像直接删除;处理视频时删除视频中所有包含人脸以及车牌等个人信息的视频帧; 2)局部轮廓化处理:将视频以及图像中包含人脸以及车牌等个人信息的区域彻底擦除,或者将这些区域替代为无法关联个人信息主体且不可复原的其他图像。 c)匿名化处理过程中.除分析确定包含人脸以及车牌等个人信息的区域.以及对这些区域进行删除或局部轮廓化处理外.不应进行人脸比对、步态分析以及语音识别等其他处理,d)匿名化处理完成后.过程数据应立即删除,不应向车外提供。 6座舱数据安全要求 除非驾驶人|'|主设定.汽车应默认设定为不收集座舱数据的状态,包括不打开车内的摄像头、传声器、红外传感器和指纹传感器等部件.当驾驶人通过实体按键或触摸按键等方式主动选择后才能开始收集.汽车可根据驾驶人设定,保持驾驶人选择的状态或恢复默认状态。 6.2汽车不应向车外提供座舱数据,下列情形除外。 为实现语音识别功能以实时判断汽车控制指令.将语音指令数据在车外处理,取得个人信息主体同意.功能实现后即时删除原始数据及处理结果。 为实现远程查看车内情况或云存储功能,向使用者提供数据.取得个人信息主体同意,并采取安全措施,除使用者外的其他组织和个人不能访问。 道路运输车辆依据相关规定向所属运输企业监控平台、公共管理平台和监管机构传输数据。出租汽车和公共汽车等营运车辆向监管机构传输数据。 道路交通事故发生后按执法部门要求传输数据。 6.3汽车数据处理者应提供便利的终止收集座舱数据的方式.包括实体按键、语音控制、触摸按键以及汽车使用相关应用程序等。在保证行车安全以及人身安全的情况下,驾驶人选择终止收集后应关闭车内传声器和摄像头等收集座舱数据的部件。为保证行车安全以及人身安全下列情况可不关闭相关部件: a)正在提供公路营运服务的道路运输乍辆持续收集座舱数据: b)正在提供出行服务的公共汽车持续收集座舱数据。 7管理安全要求 7.1汽车数据处理者开展汽车数据风险评估,评估内容一般包括汽车数据识别、数'应据处理活动识别、汽车数据安全风险识别和风险分析及评价等,可采取自评彷或第三方评估的形式进行。 7.2汽车数据安全管理负责人应由汽车数据处理者主要负责人或分管数据安全负责人担任,并应熟悉我国数据安全和个人信息保护政策法规.具备安全管理工作经历。 7.3汽车数据处理者应建立健全安全事件应急处置机制.每年至少开展一次应急演练,并宜通过汽车数据存证、汽车数据溯源等机制支撑安全事件发生后的取证分析。 7.4汽车数据处理者应通过电话或即时通信平台等方式受理汽乍数据安全投诉,在接到投诉后一般在10个工作日内处理完成,并对处理过程以及处理结果进行完整记录。 7.5汽车制造商应全面掌握其生产的整车所含各零部件收集、传输数据情况.对零部件供应商处理汽车数据的行为进行约束和监督.汽车数据向外传输的完整情况应每年或在出现重大变更时向用户披露。 8特例 除有需要外,本文件各项要求不适用于以下数据处理活动: 警车、消防车、救护车以及工程救险车等执行紧急任务时的汽车数据处理活动; 装置有专用设备或器具的作业车辆在封闭场所内从事作业活动时的汽车数据处理活动; 测试车辆在封闭场地开展科研以及定型试验等活动时的汽车数据处理活动。
|
联系我们
|
微信联系客服
![]() |
关于我们 | 联系我们 | 收费付款 |
服务热线:400-001-5431 | 电话:010-8572 5110 | 传真:010-8581 9515 | Email: bz@bzfyw.com | |
版权所有: 北京悦尔信息技术有限公司 2008-2020 京ICP备17065875号-1 51La |
本页关键词: |
GB/T 41871-2022, GB 41871-2022, GBT 41871-2022, GB/T41871-2022, GB/T 41871, GB/T41871, GB41871-2022, GB 41871, GB41871, GBT41871-2022, GBT 41871, GBT41871 |