Regulations on the Sharing of Government Data of the PRC — Full English Translation (2025)

Adopted at the 59th executive meeting of the State Council on May 9, 2025

Promulgated by Decree No. 809 of the State Council of the People’s Republic of China on May 28, 2025

Effective: August 1, 2025


Table of Contents


Chapter I — General Provisions

Article 1 — This Regulation is formulated in accordance with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China, and other laws, for the purposes of promoting the secure, orderly, and efficient sharing and utilization of government data, enhancing the government’s digital governance capabilities and the effectiveness of government services, and comprehensively building a digital government.

Article 2 — This Regulation applies to the sharing of government data among government departments and organizations authorized by laws and regulations to perform the function of administering public affairs (hereinafter collectively referred to as government departments), as well as the related work of security, supervision, and administration.

Article 3 — For the purposes of this Regulation, “government data” means all types of data collected or generated by government departments in the course of performing their duties in accordance with law, but does not include data that constitutes state secrets or work secrets.

For the purposes of this Regulation, “sharing of government data” means the act of a government department, as required for performing its duties in accordance with law, using the government data of another government department or providing government data to another government department.

Article 4 — Work on the sharing of government data shall uphold the leadership of the Communist Party of China, implement the holistic approach to national security, coordinate development and security, and follow the principles of overall coordination, unified standards, sharing in accordance with law, reasonable use, and security and controllability.

Article 5 — In carrying out the sharing of government data, laws and regulations shall be observed and the obligation to protect the security of government data shall be fulfilled; national security and the public interest shall not be endangered, and the lawful rights and interests of citizens, legal persons, and other organizations shall not be prejudiced.

Article 6 — The State shall establish a standards system for the sharing of government data and promote the standardization and normalization of work on the sharing of government data.

Article 7 — The State shall encourage management innovation, institutional innovation, and technological innovation in the field of government data sharing, and continuously improve the efficiency, application level, and security assurance capability of government data sharing.

Chapter II — Management System

Article 8 — The people’s governments at all levels shall strengthen the organization and leadership of work on the sharing of government data.

The competent department for government data sharing under the State Council shall be responsible for overall planning and promotion of work on the sharing of government data nationwide.

The competent departments for government data sharing of the local people’s governments at or above the county level shall be responsible for overall planning and promotion of work on the sharing of government data within their respective administrative regions.

The departments under the State Council shall be responsible for work on the sharing of government data in their respective departments, and shall coordinate and guide work on the sharing of government data in their respective industries and fields.

Article 9 — The competent departments for government data sharing shall, together with other government departments, study major matters and important work in the sharing of government data; summarize and promote typical cases and experience in the sharing of government data; and coordinate the promotion of the secure, orderly, and efficient sharing and utilization of government data across levels, regions, systems, departments, and business areas.

Article 10 — Government departments shall fulfill their primary responsibility for the sharing of government data, establish and improve their departments’ working systems for the sharing of government data, and organize the study and resolution of major issues in the sharing of government data.

Article 11 — Government departments shall designate the office responsible for their department’s work on the sharing of government data. The office responsible for government data sharing shall be responsible for the specific work of sharing government data in its department and shall perform the following duties:

(1) organizing the compilation, updating, and maintenance of its department’s government data catalogue;

(2) organizing the submission of applications for the sharing of government data by its department, organizing the review of applications for sharing its department’s government data, and coordinating and sharing its department’s government data;

(3) ensuring that the government data provided by its department complies with the standards and specifications for the sharing of government data;

(4) organizing the submission or handling of applications for verification of government data involving its department;

(5) establishing and improving the systems for data security and personal information protection in its department’s sharing of government data, and organizing security assessments of its department’s sharing of government data;

(6) other work of its department related to the sharing of government data.

Chapter III — Catalogue Management

Article 12 — Government data shall be subject to unified catalogue management. The competent department for government data sharing under the State Council shall formulate the standards and specifications for compiling government data catalogues and organize the compilation of the national government data catalogue. The competent departments for government data sharing of the local people’s governments at or above the county level shall organize the compilation of the government data catalogues within their respective administrative regions.

Government departments shall, in accordance with their respective duties and the standards and specifications for compiling government data catalogues, compile their own departments’ government data catalogues.

Article 13 — When compiling a government data catalogue, a government department shall, in accordance with law, conduct assessments of confidentiality risks and the impact on personal information protection, among others, and obtain the approval of the person in charge of the department after review.

A government data catalogue shall specify the catalogue name, data items, providing entity, data format, data update frequency, sharing attributes, sharing methods, conditions of use, data classification and grading, and other information.

Article 14 — Government data shall be classified, according to its sharing attributes, into three categories: sharing without conditions, sharing with conditions, and no sharing:

(1) government data that may be provided to all government departments for sharing and use shall belong to the category of sharing without conditions;

(2) government data that may be provided to relevant government departments for sharing and use under certain conditions shall belong to the category of sharing with conditions;

(3) government data that laws, administrative regulations, and decisions of the State Council expressly provide cannot be provided to other government departments for sharing and use shall belong to the category of no sharing.

Article 15 — Government departments shall determine the sharing attributes of government data in a scientific and reasonable manner and shall not obstruct or affect the sharing of government data by, among other means, arbitrarily adding conditions.

For government data belonging to the category of sharing with conditions, the government department shall specify in the government data catalogue the conditions for sharing and use, such as the scope of sharing and the purposes of use. For government data belonging to the category of no sharing, the government department shall state the reasons in the government data catalogue and specify the corresponding basis in laws, administrative regulations, and decisions of the State Council.

Article 16 — Government departments shall submit the government data catalogues they have compiled to the competent department for government data sharing at the same level for review. After the competent department for government data sharing approves the catalogues upon review, it shall uniformly notify the government departments.

Government departments shall, in accordance with the uniformly published government data catalogues, enrich government data resources, ensure the quality of government data, and share government data in accordance with law.

Article 17 — Government data catalogues shall be subject to dynamic updating.

Where a government data catalogue needs to be updated as a result of adjustments to laws, administrative regulations, or decisions of the State Council, or changes in the duties of a government department, the government department shall complete the update of the government data catalogue within 10 working days from the date on which the adjustment or change occurs, and submit it to the competent department for government data sharing at the same level for review. Where the update period needs to be extended for special reasons, it may be extended by 5 working days with the consent of the competent department for government data sharing at the same level.

The competent department for government data sharing shall complete the review and publish the updated government data catalogue within 2 working days from the date of receipt thereof.

Chapter IV — Sharing and Use

Article 18 — Government departments shall establish and improve a whole-process quality management system for government data, enhance their capacity for government data quality management, and strengthen the standardized management of the collection, storage, processing, transmission, sharing, use, and destruction of government data.

Article 19 — Government departments shall collect government data in accordance with statutory powers, procedures, and standards and specifications. Where the government data obtained through sharing can meet the needs of performing duties, government departments shall not repeatedly collect such data from citizens, legal persons, and other organizations.

Where the collection of government data involves multiple government departments, the competent department for government data sharing shall designate the government department leading the collection and treat it as the data source department. The data source department shall strengthen coordination, cooperation, and information communication with other relevant government departments, promptly improve and update government data, ensure the completeness, accuracy, and availability of government data, and uniformly provide government data sharing services.

Article 20 — The competent department for government data sharing shall establish a mechanism for matching the supply and demand of government data sharing and specify the working procedures.

A government data demand department shall, based on the needs of performing its duties and in accordance with the uniformly published government data catalogues, submit an application for the sharing of government data in accordance with law after obtaining the consent of the person in charge of its office responsible for government data sharing, specifying the basis, scenarios, scope, method, and duration of use, and shall ensure the authenticity, legality, and necessity of the application for the sharing of government data.

A government data providing department shall review, within the time limit specified in Article 21 of this Regulation, an application for the sharing of government data submitted by a government data demand department, and make a reply after obtaining the consent of the person in charge of its office responsible for government data sharing.

Article 21 — Where the government data for which a government data demand department applies to share belongs to the category of sharing without conditions, the government data providing department shall make a reply within 1 working day from the date of receipt of the application for sharing. Where it belongs to the category of sharing with conditions, the government data providing department shall make a reply as to whether to consent to the sharing within 10 working days from the date of receipt of the application. Where the time limit for reply needs to be extended for special reasons, the government data providing department shall report to and obtain the consent of the competent department for government data sharing at the same level and notify the government data demand department; the extension shall not exceed 10 working days.

Where the application materials submitted by a government data demand department are incomplete, the government data providing department shall notify it at one time of the materials that need to be supplemented and shall not directly refuse the application. Where a government data providing department does not consent to the sharing, it shall state the reasons.

Article 22 — A government data providing department shall share the government data within 20 working days from the date on which it makes a reply consenting to the sharing.

A government data providing department may share government data with a government data demand department by means such as service interfaces, batch exchange, and file downloading.

Article 23 — The State shall encourage government departments at all levels to optimize the review procedures for the sharing of government data and shorten the time for review and for providing shared government data.

Article 24 — A higher-level government department shall, based on the needs of lower-level government departments in performing their duties and on the premise of ensuring the security of government data, promptly and completely return the government data collected and generated by its business information systems within the administrative regions of lower-level governments, and properly carry out system interconnection and business coordination, and shall not set additional restrictive conditions.

After obtaining the returned government data, a lower-level government department shall share and use it in accordance with the needs of performing its duties and ensure the security of the relevant government data.

Article 25 — Where a government department obtains government data through sharing, it shall not expand the scope of use without authorization, use the data for or in disguised form for other purposes, or provide the obtained government data to a third party without authorization. Where it is indeed necessary to expand the scope of use, use the data for other purposes, or provide the data to a third party, the consent of the government data providing department shall be obtained.

The competent departments for government data sharing and other government departments shall take measures to prevent the risk of leakage arising from the aggregation and correlation of government data.

Article 26 — The competent department for government data sharing under the State Council shall make overall arrangements to establish a system for the verification and correction of government data.

Government departments shall, in accordance with their respective duties, establish rules for the verification and correction of government data and provide channels for correction. A government data demand department shall record the status of use of government data; where it discovers that government data is inaccurate or incomplete, it shall promptly submit an application for verification of the government data to the government data providing department. The government data providing department shall, within 10 working days from the date of receipt of the application for verification, verify and correct the government data and feed back the results of the verification and handling.

Article 27 — Where the purpose of sharing government data obtained by a government data demand department through sharing has been achieved or cannot be achieved, or the data is no longer necessary for achieving the purpose of sharing, the government data demand department shall properly dispose of the data in accordance with the requirements of the government data providing department.

Where a government data demand department uses government data beyond the scope of use or the purpose of sharing without authorization, or provides government data to a third party without authorization, the competent department for government data sharing or the government data providing department shall suspend its authority to share government data and urge it to rectify the matter within a specified time limit; where it refuses to rectify the matter or fails to rectify it properly, the sharing may be terminated.

A government data providing department shall not terminate or change the government data sharing services it has already provided without justifiable reasons. Where it is indeed necessary to terminate or change the services, the government data providing department shall consult with the government data demand department and report to the competent department for government data sharing at the same level for the record.

Article 28 — The competent departments for government data sharing shall establish and improve a mechanism for resolving and handling disputes over the sharing of government data.

Where a dispute over the sharing of government data arises between a government data demand department and a government data providing department at the same level, the dispute shall be resolved through consultation; where consultation fails, an application shall be made in accordance with the procedures to the competent department for government data sharing at the same level for coordinated handling. Where a dispute arises over the sharing of government data across levels or across regions, it shall be handled through coordination by the common higher-level competent department for government data sharing. Where no consensus is reached even after coordinated handling by the competent department for government data sharing, the matter shall be reported to the people’s government at the same level as the competent department for government data sharing for decision.

Article 29 — The competent departments for government data sharing shall supervise and inspect the sharing of government data and may circulate a notice of criticism for conduct that violates this Regulation.

A government data demand department shall keep records of the usage scenarios, usage process, application results, storage, and destruction of shared government data, and the relevant records shall be kept for a period of not less than 3 years. The competent department for government data sharing and the government data providing department may consult the relevant records of the government data demand department. Where laws or administrative regulations provide otherwise, such provisions shall prevail.

Chapter V — Platform Support

Article 30 — The State shall make overall arrangements for the construction of data infrastructure, improve the capability to safeguard government data security, and integrate and build a nationally integrated government big data system with unified standards, a reasonable layout, coordinated management, and security and reliability.

The competent department for government data sharing under the State Council shall make overall arrangements for the construction and management of the nationally integrated government big data system, be responsible for integrating and building the national government big data platform, achieve interconnection with the government data platforms of the relevant departments under the State Council and the government data platforms of all regions, and provide platform support for the sharing of government data.

The competent departments for government data sharing of the local people’s governments at or above the county level shall be responsible for the construction and management of government data platforms within their respective administrative regions, and shall share government data with townships (subdistricts) and villages (communities) as needed.

The relevant departments under the State Council shall be responsible for building and optimizing their own departments’ government data platforms, and may support work on the sharing of government data in their respective industries and fields. Where a government data platform has not been built, the department may carry out work on the sharing of government data through the national government big data platform.

Article 31 — The government data platforms already built by government departments shall be incorporated into the nationally integrated government big data system. Unless laws or administrative regulations provide otherwise, in principle, cross-level, cross-regional, cross-system, cross-departmental, and cross-business sharing of government data shall not be carried out by newly building government data sharing and exchange systems.

Article 32 — Government departments shall carry out work related to the sharing of government data through the nationally integrated government big data system.

Article 33 — The State shall encourage and support the application of new technologies such as big data, cloud computing, artificial intelligence, and blockchain in the sharing of government data.

Chapter VI — Safeguard Measures

Article 34 — The competent departments for government data sharing shall, together with the departments for cyberspace affairs, public security, national security, confidentiality administration, and cryptography administration at the same level, promote the development of security management systems for the sharing of government data in accordance with the classified and graded data protection system; identify, in accordance with the principle that whoever manages or uses the data is responsible for it, the entities responsible for security in each link of the sharing of government data; and urge the fulfillment of security management responsibilities for the sharing of government data.

Where, in the course of using government data shared in accordance with law, government data is tampered with, destroyed, leaked, or illegally exploited, the government data demand department shall bear security management responsibility.

Article 35 — Government departments shall establish and improve security management systems for the sharing of government data, fulfill their primary responsibility for security management of the sharing of government data and the requirements for classified and graded management of government data, and ensure the security of the sharing of government data.

Government departments shall take technical measures and other necessary measures to prevent government data from being tampered with, destroyed, leaked, or illegally obtained or exploited.

Government departments shall strengthen the monitoring of government data security risks; where a government data security incident occurs, they shall immediately activate emergency response plans, take corresponding emergency response measures, prevent the expansion of harm, eliminate security hazards, and report to the relevant competent departments in accordance with regulations.

Article 36 — Where a government department entrusts others to participate in the construction, operation, and maintenance of government informatization projects and to store or process government data, it shall complete the approval procedures in accordance with relevant State regulations, specify the working rules and standards, take necessary technical measures, and supervise the entrusted party’s fulfillment of the corresponding obligations to protect government data security. The entrusted party shall fulfill the obligations to protect government data security in accordance with the provisions of laws and administrative regulations and the terms of the contract, and shall not access, obtain, retain, use, or disclose government data or provide it to others without authorization.

Entities building and managing government data platforms shall, in accordance with the provisions of laws and administrative regulations and the mandatory requirements of national standards, ensure the secure and stable operation of the platforms and safeguard the security of government data.

Article 37 — When carrying out government data sharing activities involving personal information, government departments and their staff shall comply with the provisions of the Personal Information Protection Law of the People’s Republic of China, the Regulations on the Administration of Network Data Security, and other laws and administrative regulations.

Citizens, legal persons, and other organizations shall have the right to make complaints and reports against conduct that infringes their lawful rights and interests in the course of the sharing of government data, and the government department that receives such complaints and reports shall handle them in a timely manner in accordance with regulations.

Article 38 — The people’s governments at or above the county level shall include the funds required for work on the sharing of government data in their budgets at the corresponding level. The people’s governments at or above the county level and their relevant departments shall implement whole-process budget performance management for the funds related to the sharing of government data. The sharing of government data shall serve as an important basis for determining the construction investment and operation and maintenance funds for government informatization projects and the results of post-project evaluation.

The competent department for government data sharing shall strengthen supervision over the timeliness of data sharing and the quality of data of government data providing departments, the application of data by government data demand departments, and the security safeguard measures within its administrative region, and shall report to the people’s government at the corresponding level.

Article 39 — Where a government data providing department violates this Regulation and falls under any of the following circumstances, the competent department for government data sharing at the same level shall order it to make corrections; where it refuses to make corrections or the circumstances are serious, the leading personnel and directly responsible personnel who are responsible shall be given sanctions in accordance with law:

(1) failing to compile or update a government data catalogue as required;

(2) obstructing or affecting the sharing of government data by, among other means, arbitrarily adding conditions;

(3) failing to cooperate with the data source department in promptly improving and updating government data;

(4) failing to reply to an application for the sharing of government data or to share government data on time without justifiable reasons;

(5) failing to return, as required, the government data collected and generated by its business information systems within the administrative regions of lower-level governments to lower-level government departments;

(6) failing to verify and correct government data on time after receiving an application for verification;

(7) terminating or changing the government data sharing services already provided without authorization;

(8) failing to incorporate, as required, the government data platforms already built into the nationally integrated government big data system;

(9) other circumstances in violation of this Regulation.

Article 40 — Where a government data demand department violates this Regulation and falls under any of the following circumstances, the competent department for government data sharing at the same level shall order it to make corrections; where it refuses to make corrections or the circumstances are serious, the leading personnel and directly responsible personnel who are responsible shall be given sanctions in accordance with law:

(1) repeatedly collecting government data that can be obtained through sharing;

(2) using government data obtained through sharing beyond the scope of use or the purpose of sharing without authorization;

(3) providing government data obtained through sharing to a third party without authorization;

(4) failing to properly dispose of government data obtained through sharing as required where the purpose of sharing has been achieved or cannot be achieved, or the data is no longer necessary for achieving the purpose of sharing;

(5) failing to keep the relevant records of government data obtained through sharing as required;

(6) failing to fulfill security management responsibilities for government data obtained through sharing;

(7) other circumstances in violation of this Regulation.

Article 41 — Where a competent department for government data sharing violates this Regulation and falls under any of the following circumstances, the people’s government at the corresponding level or the competent department at a higher level shall order it to make corrections; where it refuses to make corrections or the circumstances are serious, the leading personnel and directly responsible personnel who are responsible shall be given sanctions in accordance with law:

(1) failing to designate the data source department as required;

(2) failing to coordinate and handle disputes over the sharing of government data as required;

(3) other circumstances in violation of this Regulation.

Article 42 — Where a government department or its staff discloses, sells, or illegally provides to others personal privacy, personal information, trade secrets, or confidential business information learned in the course of work on the sharing of government data, or neglects duty, abuses power, or commits fraud for personal gain in the sharing of government data, sanctions shall be imposed in accordance with law; where a crime is constituted, criminal liability shall be investigated in accordance with law.

Chapter VIII — Supplementary Provisions

Article 43 — The State shall promote the sharing of data between government departments and other state organs, in accordance with the needs of performing their respective duties, by reference to the provisions of this Regulation.

Article 44 — This Regulation shall come into force on August 1, 2025.

Wechat

WhatsApp

WhatsApp

WhatsApp
[email protected]
+86 18565453956