Adopted at the 59th Executive Meeting of the State Council on May 9, 2025
Promulgated by Order No. 809 of the State Council of the People’s Republic of China on May 28, 2025
Effective: August 1, 2025
Table of Contents
Chapter I — General Provisions
Article 1 — These Regulations are formulated in accordance with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China, and other laws, for the purpose of promoting the safe, orderly, and efficient sharing and utilization of government data, enhancing the government’s digital governance capacity and the effectiveness of government services, and comprehensively building a digital government.
Article 2 — These Regulations apply to the sharing of government data among government departments and organizations authorized by laws or regulations to perform public administration functions (hereinafter collectively referred to as “government departments”), as well as to related security, supervision, and administration work.
Article 3 — For the purpose of these Regulations, “government data” means the various types of data collected and generated by government departments in the course of performing their duties in accordance with the law, but does not include data that constitutes state secrets or work secrets.
For the purpose of these Regulations, “sharing of government data” means the act of a government department using the government data of another government department, or providing government data to another government department, as required for the performance of its duties in accordance with the law.
Article 4 — Government data sharing shall uphold the leadership of the Communist Party of China, implement the holistic approach to national security, coordinate development and security, and follow the principles of overall coordination, unified standards, lawful sharing, reasonable use, and security and controllability.
Article 5 — Government data sharing shall comply with laws and regulations, fulfill the obligations of protecting government data security, and shall not endanger national security or the public interest, or harm the lawful rights and interests of citizens, legal persons, and other organizations.
Article 6 — The state shall establish a standards system for government data sharing and promote the standardization and normalization of government data sharing.
Article 7 — The state encourages management innovation, institutional innovation, and technological innovation in the field of government data sharing, and continuously improves the efficiency, application level, and security safeguard capabilities of government data sharing.
Chapter II — Administrative System
Article 8 — People’s governments at all levels shall strengthen organizational leadership over government data sharing.
The competent department for government data sharing under the State Council shall be responsible for coordinating and advancing government data sharing nationwide.
The competent departments for government data sharing of local people’s governments at or above the county level shall be responsible for coordinating and advancing government data sharing within their respective administrative regions.
The departments of the State Council shall be responsible for government data sharing within their own departments, and shall coordinate and guide government data sharing in their respective industries and fields.
Article 9 — The competent departments for government data sharing shall, in conjunction with other government departments, study major matters and important work in government data sharing, summarize and promote typical cases and good practices of government data sharing, and coordinate and advance the safe, orderly, and efficient sharing and utilization of government data across levels, regions, systems, departments, and businesses.
Article 10 — Government departments shall fulfill their primary responsibilities for government data sharing, establish and improve their own work systems for government data sharing, and organize research and resolution of major issues in government data sharing.
Article 11 — Government departments shall designate their own working organs for government data sharing. The working organs for government data sharing shall be responsible for the specific work of government data sharing in their own departments and shall perform the following duties:
(1) organizing the compilation, updating, and maintenance of the government data catalogue of their own department;
(2) organizing the submission of government data sharing applications of their own department, organizing the review of sharing applications involving the government data of their own department, and coordinating and sharing the government data of their own department;
(3) ensuring that the government data provided by their own department conforms to the standards and specifications for government data sharing;
(4) organizing the submission or handling of government data verification applications involving their own department;
(5) establishing and improving the systems for data security and personal information protection in government data sharing of their own department, and organizing security assessments of government data sharing of their own department; and
(6) other work of their own department related to government data sharing.
Chapter III — Catalogue Management
Article 12 — Government data shall be subject to unified catalogue management. The competent department for government data sharing under the State Council shall formulate the standards and specifications for compiling government data catalogues and organize the compilation of the national government data catalogue. The competent departments for government data sharing of local people’s governments at or above the county level shall organize the compilation of government data catalogues within their respective administrative regions.
Government departments shall, in accordance with their own duties and the standards and specifications for compiling government data catalogues, compile the government data catalogues of their own departments.
Article 13 — When compiling government data catalogues, government departments shall conduct assessments of confidentiality risks and personal information protection impacts in accordance with the law, and the catalogues shall be reviewed and approved by the responsible persons of the departments.
A government data catalogue shall specify the name of the data catalogue, data items, the providing unit, the data format, the data update frequency, as well as the sharing attributes, sharing methods, conditions of use, and data classification and grading, among other information.
Article 14 — Government data shall be classified, according to sharing attributes, into three categories: data subject to unconditional sharing, data subject to conditional sharing, and data not to be shared:
(1) government data that may be provided to all government departments for sharing and use is data subject to unconditional sharing;
(2) government data that may be provided to relevant government departments for sharing and use under certain conditions is data subject to conditional sharing; and
(3) government data that laws, administrative regulations, and decisions of the State Council expressly provide may not be provided to other government departments for sharing and use is data not to be shared.
Article 15 — Government departments shall determine the sharing attributes of government data in a scientific and reasonable manner, and shall not obstruct or affect government data sharing by adding conditions without authorization or through other means.
For government data subject to conditional sharing, government departments shall specify in the government data catalogue the conditions of sharing and use such as the scope of sharing and the purposes of use. For government data not to be shared, government departments shall specify the reasons in the government data catalogue and identify the corresponding basis in laws, administrative regulations, and decisions of the State Council.
Article 16 — Government departments shall submit the compiled government data catalogues to the competent department for government data sharing at the same level for review. The competent department for government data sharing shall uniformly notify government departments after the review is passed.
Government departments shall, by reference to the uniformly published government data catalogues, enrich government data resources, ensure the quality of government data, and share government data in accordance with the law.
Article 17 — Government data catalogues shall be subject to dynamic updating.
Where a government data catalogue needs to be updated as a result of adjustments to laws, administrative regulations, or decisions of the State Council, or changes in the duties of a government department, the government department shall complete the update of its government data catalogue within 10 working days from the date on which the adjustment or change occurs, and submit it to the competent department for government data sharing at the same level for review. Where the update period needs to be extended for special reasons, it may be extended by 5 working days with the consent of the competent department for government data sharing at the same level.
The competent department for government data sharing shall complete the review and publication within 2 working days from the date of receipt of the updated government data catalogue.
Chapter IV — Sharing and Use
Article 18 — Government departments shall establish and improve a quality management system for the entire process of government data, improve their capabilities for managing government data quality, and strengthen standardized management of the collection, storage, processing, transmission, sharing, use, and destruction of government data.
Article 19 — Government departments shall collect government data in accordance with the statutory powers, procedures, and standards and specifications. Where government data obtained through sharing can meet the needs of performing duties, government departments shall not repeatedly collect it from citizens, legal persons, and other organizations.
Where the collection of government data involves multiple government departments, the competent department for government data sharing shall designate the government department that takes the lead in collection as the data source department. The data source department shall strengthen coordination, cooperation, and information communication with other relevant government departments, improve and update government data in a timely manner, ensure the integrity, accuracy, and availability of government data, and uniformly provide government data sharing services.
Article 20 — The competent department for government data sharing shall establish a mechanism for matching the supply and demand of government data sharing and specify the work process.
Government data demand departments shall, according to the needs of performing their duties and in accordance with the uniformly published government data catalogues, submit government data sharing applications in accordance with the law with the consent of the responsible persons of their own government data sharing working organs, specifying the basis of use, the scenarios of use, the scope of use, the sharing method, and the time limit of use, and shall guarantee the authenticity, legality, and necessity of the government data sharing applications.
Government data providing departments shall review the government data sharing applications submitted by government data demand departments within the time limit prescribed in Article 21 of these Regulations, and make a reply with the consent of the responsible persons of their own government data sharing working organs.
Article 21 — Where the government data for which a government data demand department applies to share falls within the category subject to unconditional sharing, the government data providing department shall make a reply within 1 working day from the date of receipt of the government data sharing application; where it falls within the category subject to conditional sharing, it shall make a reply on whether to consent to the sharing within 10 working days from the date of receipt of the government data sharing application. Where the reply period needs to be extended for special reasons, the government data providing department shall report to the competent department for government data sharing at the same level for consent and notify the government data demand department, and the extended period shall not exceed 10 working days.
Where the application materials submitted by a government data demand department are incomplete, the government data providing department shall inform it, at one time, of the materials that need to be supplemented, and shall not directly refuse. Where the government data providing department does not consent to the sharing, it shall explain the reasons.
Article 22 — The government data providing department shall share the government data within 20 working days from the date of making the reply consenting to the sharing.
The government data providing department may share government data with the government data demand department through service interfaces, batch exchange, file download, or other means.
Article 23 — The state encourages government departments at all levels to optimize the review process for government data sharing and shorten the time for reviewing and providing government data for sharing.
Article 24 — Higher-level government departments shall, according to the needs of lower-level government departments in performing their duties and on the premise of ensuring the security of government data, promptly and completely return the government data within the administrative regions of lower-level governments that is collected and generated by business information systems, and shall ensure system connection and business coordination, and shall not set additional restrictive conditions.
After obtaining the returned government data, lower-level government departments shall share and use it according to the needs of performing their duties, and ensure the security of the relevant government data.
Article 25 — Government departments that obtain government data through sharing shall not expand the scope of use without authorization, use it for other purposes directly or in disguised form, or provide the obtained government data to third parties without authorization. Where it is genuinely necessary to expand the scope of use, use it for other purposes, or provide it to third parties, the consent of the government data providing department shall be obtained.
The competent department for government data sharing and other government departments shall take measures to prevent the risk of disclosure arising from the aggregation and correlation of government data.
Article 26 — The competent department for government data sharing under the State Council shall make overall arrangements to establish a government data verification and error correction system.
Government departments shall, in accordance with their own duties, establish rules for government data verification and error correction and provide error correction channels. Government data demand departments shall record the status of use of government data and, where they discover that government data is inaccurate or incomplete, promptly submit government data verification applications to the government data providing departments. Government data providing departments shall verify and correct the data within 10 working days from the date of receipt of the government data verification application and give feedback on the results of verification and correction.
Article 27 — Where the purpose of sharing of government data obtained by a government data demand department through sharing has been achieved, cannot be achieved, or is no longer necessary for achieving the sharing purpose, the government data demand department shall properly dispose of the data in accordance with the requirements of the government data providing department.
Where a government data demand department uses government data beyond the scope of use or the sharing purpose without authorization, or provides government data to third parties without authorization, the competent department for government data sharing or the government data providing department shall suspend its government data sharing authority and urge it to make rectification within a prescribed period; where it refuses to make rectification or the rectification is not in place, the sharing may be terminated.
The government data providing department shall not terminate or change the government data sharing services already provided without justified reasons. Where it is genuinely necessary to terminate or change the services, the government data providing department shall consult with the government data demand department and report to the competent department for government data sharing at the same level for the record.
Article 28 — The competent department for government data sharing shall establish and improve a mechanism for resolving disputes in government data sharing.
Where a dispute over government data sharing arises between government data demand departments and government data providing departments at the same level, they shall resolve it through consultation; where consultation fails, they shall apply to the competent department for government data sharing at the same level for coordination and handling in accordance with procedures. Where a dispute arises over government data sharing across levels or regions, it shall be coordinated and handled by the common higher-level competent department for government data sharing. Where no consensus is reached after coordination and handling by the competent department for government data sharing, the matter shall be reported to the people’s government at the same level as the competent department for government data sharing for decision.
Article 29 — The competent department for government data sharing shall supervise and inspect government data sharing and may give notice of acts in violation of these Regulations.
Government data demand departments shall keep records of the scenarios of use, the process of use, the application results, the storage conditions, and the destruction of shared government data, and the relevant records shall be kept for not less than 3 years. The competent department for government data sharing and the government data providing departments may consult the relevant records of government data demand departments. Where laws or administrative regulations provide otherwise, such provisions shall prevail.
Chapter V — Platform Support
Article 30 — The state shall make overall arrangements for the construction of data infrastructure, improve the capabilities for safeguarding government data security, and integrate and build a nationally unified government big data system with unified standards, reasonable layout, coordinated management, and safety and reliability.
The competent department for government data sharing under the State Council shall make overall arrangements for the construction and management of the nationally unified government big data system, be responsible for integrating and building the national government big data platform, realize interconnection and interoperability with the government data platforms of the relevant departments of the State Council and the government data platforms of various regions, and provide platform support for government data sharing.
The competent departments for government data sharing of local people’s governments at or above the county level shall be responsible for the construction and management of government data platforms within their respective administrative regions, and share government data with townships (subdistricts), villages, and communities as needed.
The relevant departments of the State Council shall be responsible for building and optimizing their own government data platforms, which may support government data sharing in their respective industries and fields. Departments that have not built government data platforms may carry out government data sharing of their own departments through the national government big data platform.
Article 31 — Government data platforms already built by government departments shall be incorporated into the nationally unified government big data system. Except as otherwise provided by laws or administrative regulations, in principle no new government data sharing and exchange systems shall be built to carry out government data sharing across levels, regions, systems, departments, and businesses.
Article 32 — Government departments shall carry out work related to government data sharing through the nationally unified government big data system.
Article 33 — The state encourages and supports the application of new technologies such as big data, cloud computing, artificial intelligence, and blockchain in government data sharing.
Chapter VI — Safeguard Measures
Article 34 — The competent department for government data sharing shall, in conjunction with the cyberspace administration, public security, state security, confidentiality administration, and cryptography administration departments at the same level, and in accordance with the system for classified and graded protection of data, advance the construction of the security management system for government data sharing, specify the entities responsible for security at each link of government data sharing in accordance with the principle that whoever manages is responsible and whoever uses is responsible, and supervise the implementation of security management responsibilities for government data sharing.
Where government data demand departments cause the tampering, destruction, disclosure, or unlawful use of government data in the course of using government data shared in accordance with the law, they shall bear security management responsibilities.
Article 35 — Government departments shall establish and improve security management systems for government data sharing, implement the primary responsibilities for security management of government data sharing and the requirements for classified and graded management of government data, and ensure the security of government data sharing.
Government departments shall take technical measures and other necessary measures to prevent government data from being tampered with, destroyed, disclosed, or unlawfully obtained or unlawfully used.
Government departments shall strengthen the monitoring of government data security risks and, when a government data security incident occurs, immediately activate the emergency response plan, take corresponding emergency response measures, prevent the expansion of harm, eliminate security risks, and report to the relevant competent departments in accordance with the provisions.
Article 36 — Where government departments entrust others to participate in the construction, operation, or maintenance of government informatization projects or to store or process government data, they shall perform the approval procedures in accordance with the relevant state provisions, specify work specifications and standards, take necessary technical measures, and supervise the entrusted party in fulfilling the corresponding obligations to protect government data security. The entrusted party shall fulfill the obligations to protect government data security in accordance with the provisions of laws and administrative regulations and the contract, and shall not access, obtain, retain, use, disclose, or provide government data to others without authorization.
The units responsible for building and managing government data platforms shall, in accordance with the provisions of laws and administrative regulations and the mandatory requirements of national standards, ensure the safe and stable operation of the platforms and maintain the security of government data.
Article 37 — Government departments and their staff shall, when carrying out government data sharing activities involving personal information, comply with the provisions of the Personal Information Protection Law of the People’s Republic of China, the Regulations on the Administration of Network Data Security, and other laws and administrative regulations.
Citizens, legal persons, and other organizations have the right to complain about and report acts that infringe upon their lawful rights and interests in the course of government data sharing, and the government departments receiving the complaints or reports shall handle them in a timely manner in accordance with the provisions.
Article 38 — The people’s governments at or above the county level shall include the funds required for government data sharing in the budgets at the corresponding level. The people’s governments at or above the county level and their relevant departments shall implement performance-based budget management for the entire process of the funds related to government data sharing. The situation of government data sharing shall serve as an important basis for determining the construction investment, operation and maintenance funds, and post-project evaluation results of government informatization projects.
The competent department for government data sharing shall strengthen supervision over the timeliness of data sharing and the quality of data of government data providing departments within its administrative region, as well as the data application and security safeguard measures of government data demand departments, and report to the people’s government at the same level.
Chapter VII — Legal Liability
Article 39 — Where a government data providing department violates these Regulations under any of the following circumstances, the competent department for government data sharing at the same level shall order it to make corrections; where it refuses to make corrections or the circumstances are serious, the leading personnel and directly responsible personnel shall be given sanctions in accordance with the law:
(1) failing to compile or update the government data catalogue as required;
(2) obstructing or affecting government data sharing by adding conditions without authorization or through other means;
(3) failing to cooperate with the data source department in improving and updating government data in a timely manner;
(4) failing to reply to government data sharing applications on time or failing to share government data on time without justified reasons;
(5) failing to return, as required, the government data within the administrative regions of lower-level governments collected and generated by business information systems to the lower-level government departments;
(6) failing to verify and correct government data on time after receiving government data verification applications;
(7) terminating or changing government data sharing services already provided without authorization;
(8) failing to incorporate already built government data platforms into the nationally unified government big data system as required; or
(9) other circumstances in violation of these Regulations.
Article 40 — Where a government data demand department violates these Regulations under any of the following circumstances, the competent department for government data sharing at the same level shall order it to make corrections; where it refuses to make corrections or the circumstances are serious, the leading personnel and directly responsible personnel shall be given sanctions in accordance with the law:
(1) repeatedly collecting government data that can be obtained through sharing;
(2) using government data obtained through sharing beyond the scope of use or the sharing purpose without authorization;
(3) providing government data obtained through sharing to third parties without authorization;
(4) failing to properly dispose of government data obtained through sharing as required where the sharing purpose has been achieved, cannot be achieved, or is no longer necessary for achieving the sharing purpose;
(5) failing to keep records related to government data obtained through sharing as required;
(6) failing to fulfill security management responsibilities for government data obtained through sharing; or
(7) other circumstances in violation of these Regulations.
Article 41 — Where the competent department for government data sharing violates these Regulations under any of the following circumstances, the people’s government at the same level or the competent department at a higher level shall order it to make corrections; where it refuses to make corrections or the circumstances are serious, the leading personnel and directly responsible personnel shall be given sanctions in accordance with the law:
(1) failing to designate the data source department as required;
(2) failing to coordinate and handle disputes over government data sharing as required; or
(3) other circumstances in violation of these Regulations.
Article 42 — Where government departments and their staff disclose, sell, or unlawfully provide to others the personal privacy, personal information, trade secrets, or confidential business information that they have learned in the course of government data sharing, or neglect their duties, abuse their powers, or engage in malpractices for personal gain in government data sharing, they shall be given sanctions in accordance with the law; where the act constitutes a crime, criminal liability shall be pursued in accordance with the law.
Chapter VIII — Supplementary Provisions
Article 43 — The state promotes government departments and other state organs to carry out data sharing by reference to these Regulations according to their respective needs in performing their duties.
Article 44 — These Regulations shall come into force on August 1, 2025.
Disclaimer: This translation is provided for informational and reference purposes only and is not an official translation. While every effort has been made to ensure accuracy, in the event of any discrepancy between this translation and the original Chinese text, the original Chinese text shall prevail. This translation does not constitute legal advice, and readers should consult qualified legal professionals for advice on specific matters.