Promulgated by: Department of Commerce of Guangxi Zhuang Autonomous Region; China (Guangxi) Pilot Free Trade Zone Work Office; Cyberspace Administration of Guangxi Zhuang Autonomous Region; Big Data Development Bureau of Guangxi Zhuang Autonomous Region (with the relevant departments).
Filed with the Cyberspace Administration of China and the National Data Administration. Issued August 2025; effective on publication for a trial period of two years.
Translation note — DCC. Translated in full from Annex 1 to the joint issuing notice as published by the Guangxi government. The original numbers its clauses “1.” to “18.” with bracketed captions【】, which are kept as bold run-in labels; the annexed Reference Rules table has been reconstructed from the flattened source. In the table, the fourth column (“reference rules for identifying important data — examples”) spans several sub-categories in the original; it is shown once per category. Terminology follows DCC’s bilingual glossary. The companion list is the Guangxi negative list (2025 edition); the enabling provision is Article 6 of the Provisions on Promoting and Regulating Cross-border Data Flows.
China (Guangxi) Pilot Free Trade Zone Measures for the Administration of the Data Export Negative List (Trial)
Chapter I General Provisions
1. [Purpose and basis] These Measures are formulated in accordance with the Data Security Law of the People’s Republic of China, the Cybersecurity Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China and the Cyberspace Administration of China’s Provisions on Promoting and Regulating Cross-border Data Flows, in order to safeguard national data security, protect personal information rights and interests, enhance the data-export management capability and convenience of the China (Guangxi) Pilot Free Trade Zone (hereinafter the “Guangxi FTZ”), promote the efficient, convenient and secure cross-border flow of data, accelerate alignment with high-standard international economic and trade rules, steadily expand institutional opening-up, and accelerate the building of a high-standard, high-quality free trade zone leading China–ASEAN opening-up and cooperation.
2. [Scope of application] These Measures apply to data processors — enterprises, public institutions, organizations, associations and other entities — registered within the Guangxi FTZ that carry out data export and related activities.
3. [Basic principles]
(1) Hold the security bottom line. Negative-list management shall comply with national law, adopt effective technical and management security measures, improve security management mechanisms and technical assurance capabilities, and promote the lawful and orderly flow of data on the premise of ensuring data security.
(2) Legitimate and necessary need. When carrying out data export activities, data processors shall ensure that the data exported is limited to the minimum types and quantity of information necessary for business functions, and shall not harm the lawful rights and interests of the natural persons, legal persons and unincorporated organizations concerned.
(3) Classified and graded management. Follow the State’s requirements for classified and graded data protection and manage data by classification and grade according to the industry and field to which it belongs. Data on the negative list may be divided by sensitivity into data subject to data export security assessment and data subject to filing of a standard contract for the export of personal information or personal information protection certification.
(4) Promote industrial development. Give full consideration to data processors’ actual data-export needs and the state of industrial development, formulate scenario-based data classification lists scientifically and reasonably, facilitate data export activities to the greatest extent, and promote the high-quality development of cross-border business.
Chapter II Responsibilities and Division of Labor
4. [Administering bodies] The Cyberspace Administration of the Autonomous Region, the Data Bureau of the Autonomous Region, the Department of Commerce of the Autonomous Region and the China (Guangxi) Pilot Free Trade Zone Work Office (hereinafter the “Autonomous Region FTZ Office”) are responsible for the overall coordination of data-export work in the Guangxi FTZ and carry out data export security assessment and supervision in accordance with their duties.
The Public Security Department of the Autonomous Region and the Guangxi State Security Department shall strengthen guidance and supervision of data processors’ data export activities and strengthen whole-chain, all-field supervision before, during and after the event.
The industry competent departments of the Autonomous Region shall carry out data classification and grading in their industries and fields, assist in formulating the negative lists for their industries and fields, and strengthen inspection of data processors’ data export activities.
5. [Cross-border data flow coordination working group] The Cyberspace Administration, the Data Bureau, the Department of Commerce, the FTZ Office, the Public Security Department, the Guangxi State Security Department and the industry competent departments of the Autonomous Region shall jointly establish the Guangxi FTZ cross-border data flow coordination working group (hereinafter the “coordination working group”).
The coordination working group shall comprehensively coordinate and resolve major issues relating to data export; plan as a whole the formulation of development plans, work plans and policy measures for data export in the Guangxi FTZ and establish and improve the relevant rules and systems; plan as a whole the formulation or updating, in batches, of the negative lists for each industry and field; serve and guide data export and organize the implementation of the negative lists; promote the establishment of a cross-border data flow service platform providing data processors in the Guangxi FTZ with comprehensive data-compliance services such as assessment of the type of data to be exported, data export security assessment and filing of standard contracts for the export of personal information; and promote the improvement of the data export security assessment system and strengthen guidance and supervision of data processors’ data export activities.
6. [Data processors] Data processors are divided into critical information infrastructure operators and data processors other than critical information infrastructure operators.
Data processors bear primary responsibility for the security of their data exports. They shall carry out classified and graded data management in accordance with the classification and grading standards published by the industry competent departments and the relevant provisions such as the China (Guangxi) Pilot Free Trade Zone Reference Rules for Data Classification and Grading, with reference to national standards such as Data Security Technology — Rules for Data Classification and Grading (GB/T 43697-2024), and shall actively participate in the formulation of the negative lists for their industries and fields.
Data processors shall identify and declare important data in accordance with the relevant provisions. Where data has not been notified by the relevant departments or regions, or publicly released, as important data, the data processor need not declare it for data export security assessment as important data.
Data processors shall carry out data export activities in accordance with the requirements of the coordination working group and cooperate in follow-up verification, supervision and inspection.
Chapter III Data Management
7. [Classified and graded data management] Data shall be managed by classification and grade in accordance with the State’s requirements for classified and graded data protection.
Classification management: in accordance with the industry and field classification and grading standards published by the industry competent departments, data shall be managed by first classifying by industry and field and then by business attribute.
Grading management: in accordance with the Data Security Law, data is graded from high to low into three levels — core data, important data and general data.
Data collected and generated in activities such as international trade, cross-border transport, academic cooperation, transnational manufacturing and marketing that is provided abroad and contains no personal information or important data is exempt from declaring a data export security assessment, concluding a standard contract for the export of personal information, and passing personal information protection certification.
8. [Negative list] The negative list is the list of data that, under policies, laws and regulations such as the Regulations on Network Data Security Management, the Measures for Data Export Security Assessment, the Measures on Standard Contracts for the Export of Personal Information and the Provisions on Promoting and Regulating Cross-border Data Flows, must be brought within the scope of management by data export security assessment, standard contract for the export of personal information, or personal information protection certification.
The Guangxi FTZ may formulate negative lists in light of the characteristics of each industry and field, enterprise needs and other factors.
Negative lists shall be formulated in batches by industry and field.
Data bearing on national security, the lifelines of the national economy, important people’s livelihoods and major public interests is national core data, subject to a stricter management regime, and is not brought under negative-list management.
Important data whose source is collection and generation by government departments, and for which authorization for use has not been obtained, is not brought under negative-list management and shall be handled in accordance with the relevant laws, administrative regulations and provisions.
Where, in the industries and fields covered by a negative list, the data to be exported involves technical materials relating to controlled items under the Export Control Law of the People’s Republic of China or matters of technology export management under the Foreign Trade Law of the People’s Republic of China, the Export Control Law, the Foreign Trade Law and other laws, regulations and rules shall apply.
The Guangxi FTZ may implement by reference the negative lists formally published by other pilot free trade zones nationwide.
Chapter IV Formulation and Administration of the Negative List
9. [Formulation of the negative list] The formulation of a negative list mainly comprises the following steps:
(1) Demand research. Focusing on the industrial development of the Guangxi FTZ and the actual needs of data processors, select key industries and fields and organize research, ascertaining the state of data export in terms of business scenarios, categories, volumes and fields, as the basis for formulating the negative list.
(2) Identification of important data. Under the overall coordination of the Autonomous Region’s data security work coordination mechanism, the industry competent departments of the Autonomous Region shall, in accordance with the Data Security Law and the relevant laws, regulations and provisions, specify the criteria for identifying important data, classify and grade data, form the Guangxi FTZ important-data catalogue, and file it with the Office of the National Data Security Work Coordination Mechanism in accordance with procedures. Where an industry competent department has publicly released, or released within the industry, classification and grading standards for its industry and field, important data shall be identified according to those standards in priority; where the industry competent department has not specified the criteria, important data shall be identified according to the China (Guangxi) Pilot Free Trade Zone Reference Rules for Data Classification and Grading.
(3) Business-scenario analysis. In light of the research results and the results of important-data identification, select business scenarios with urgent data-export needs and frequent flows, analyze the scale, scope and frequency of data export, and set data items and data volumes reasonably for business scenarios in which the risk of data export is controllable.
(4) Review and consultation. Invite experts in the relevant industry, law, data security and other fields to conduct review and appraisal, and seek the views of the relevant industry competent departments and functional departments for further revision and improvement.
(5) Approval and filing. The negative list shall be examined and approved by the Autonomous Region’s data security work coordination mechanism, then submitted to the Autonomous Region Cybersecurity and Informatization Commission for approval, and filed jointly by the Cyberspace Administration and the Data Bureau of the Autonomous Region with the national cyberspace administration and the national data administration department.
10. [Content of the negative list] A negative list shall contain at least the following two parts:
(1) A list of data requiring a data export security assessment, mainly comprising: provision abroad by a critical information infrastructure operator of personal information or important data; provision abroad by a data processor other than a critical information infrastructure operator of important data, or of personal information reaching the threshold at which the negative list requires declaration of a data export security assessment.
(2) A list of data requiring filing of a standard contract for the export of personal information or personal information protection certification, mainly comprising: provision abroad by a data processor other than a critical information infrastructure operator of personal information reaching the threshold at which the negative list requires conclusion of a standard contract for the export of personal information or personal information protection certification.
11. [Operation of the negative list] The negative list applies to data processors registered within the Guangxi FTZ that carry out data export activities and whose data to be exported belongs to an industry or field covered by the negative list.
Before carrying out a data export activity, a data processor shall itself identify and determine the type and quantity of the data to be exported and assess whether the negative list applies to that data.
Where the data to be exported belongs to an industry or field covered by the negative list and, on assessment, falls within the negative list, the data processor shall declare a data export security assessment, conclude a standard contract for the export of personal information or pass personal information protection certification as the negative list requires; where the data to be exported does not fall within the negative list, the data processor may provide it abroad on its own.
Where the data to be exported does not belong to an industry or field covered by the negative list, the relevant national provisions — the Regulations on Network Data Security Management, the Measures for Data Export Security Assessment, the Measures on Standard Contracts for the Export of Personal Information, the Provisions on Promoting and Regulating Cross-border Data Flows and the like — shall apply.
Chapter V Supervision and Administration
12. [Supervision and inspection] The Cyberspace Administration, the Data Bureau, the Public Security Department and the Guangxi State Security Department of the Autonomous Region shall, together with the industry competent departments of the Autonomous Region, strengthen supervision, inspection and spot checks of data processors’ data export activities, and data processors shall cooperate actively.
13. [Emergency plans] Data processors shall establish data security emergency plans and, in the event of a security incident in a data export activity, promptly stop the data export activity.
14. [Handling of violations] Where a data processor fails strictly to perform the relevant undertakings in the course of data export, or commits other violations, the relevant authorities may immediately suspend or terminate the data export. A data processor that needs to continue data export shall rectify as required and submit a rectification report.
15. [Accountability for violations] Data processors bear legal responsibility for the truthfulness, security and compliance of the materials they submit; where conduct in violation of the relevant laws and regulations is found, the relevant authorities shall pursue legal liability in accordance with law.
Chapter VI Supplementary Provisions
16. [Application of law] Where laws, administrative regulations, the national cyberspace administration or the industry competent departments provide otherwise, those provisions shall prevail.
17. [Encouragement and support] Enterprises, research institutes, institutions of higher education, industry associations and the like are encouraged to participate in formulating the negative lists for their industries and fields and shall be given corresponding support.
18. [Interpretation and trial period] The Cyberspace Administration, the Data Bureau, the Department of Commerce and the FTZ Office of the Autonomous Region are responsible for the interpretation of these Measures, which shall be implemented on a trial basis from the date of publication for a period of two years.
Annexed Table: China (Guangxi) Pilot Free Trade Zone Reference Rules for Data Classification and Grading
Unified reference rules for identifying important data:
-
These reference rules apply to non-classified data; classified data shall be handled in accordance with the relevant provisions.
-
Personal information of 10 million or more individuals (excluding sensitive personal information) held by Guangxi FTZ enterprises; sensitive personal information of 1 million or more individuals; sensitive personal information of 100,000 or more individuals that includes personal bank accounts, personal insurance accounts, personal registered accounts, personal diagnosis and treatment data or the like.
-
Personal information of 100,000 or more individuals held by operators identified by the State as critical information infrastructure.
-
High-value sensitive data relating to industry competitiveness or industry production safety collected and generated by Guangxi FTZ enterprises in the course of research and design, manufacturing, and operation and management; enterprise supply-chain data involving national security.
-
Parameters and control, operation and maintenance and test data of automatic control systems in fields bearing on the national economy and people’s livelihoods held by Guangxi FTZ enterprises.
| Level-1 category | Level-2 category | Basic description of the data | Reference rules for identifying important data (examples) |
|---|---|---|---|
| (1) Strategic materials and bulk commodities | 1. Oil, petrochemicals and natural gas | Including storage and trading data, international trade data, etc. | Product output data, international trade data and the like in the oil, petrochemical and natural gas fields from which the operating conditions, development trends and growth rates of important fields involving major national strategies could be inferred. Strategic reserve data and undisclosed international cooperation and international trade data on bulk agricultural products such as grain, cotton, edible vegetable oil, sugar, meat and dairy products; data on the categories and quantities of rare and endangered germplasm resources (including genes) of crops, livestock, poultry and aquatic species that could affect biosecurity; undisclosed agricultural and rural statistical data, inspection and monitoring data, and epidemic-prevention and quarantine data; geographic information data reaching a certain precision or not publicly released. |
| 2. Agricultural products | Including germplasm-resource data, international cooperation data, international trade data, strategic reserve data, etc. | ||
| (2) Natural resources and environment | 3. Geographic information | Including basic geographic information data, subdivisible into positioning base data, place-name and address data, terrain and landform data, basic geographic entity data and other basic geographic information data; remote-sensing imagery data, subdivisible into raw imagery data, imagery product data and other remote-sensing imagery data; thematic geographic information data, subdivisible into thematic geographic information in fields such as natural resources and the ecological environment. | Basic geographic information data and remote-sensing imagery data reaching the coverage, precision, scale or other thresholds prescribed by the State, or depicting sensitive areas and targets. Meteorological monitoring data of all kinds serving the military, defense research and high-technology fields. Marine environmental monitoring data and disaster-prevention data of military value unsuitable for public release. Flood and drought disaster-defense business data capable of reflecting flood and drought conditions and project dangers; basic water-resources data such as dangerous works and sections; national water-resources and water-environment base data, water-regime information and hydrological observation data unsuitable for disclosure; remote-sensing imagery and digital-twin water-resources geospatial data meeting certain precision requirements; the physical security protection of key water-conservancy projects; and the like. |
| 4. Meteorology | Including meteorological monitoring data, space-weather monitoring data, meteorological support data, regional meteorological data, radar base data, weather-station metadata, etc. | ||
| 5. Oceans | Including marine environmental data and marine resource data. | ||
| 6. Environmental protection | Including self-monitoring data reflecting pollutant discharge levels, administrative penalties received, and other pollutant-discharge data. | ||
| 7. Water resources | Including basic water-resources data on rivers, lakes, water-conservancy projects and monitoring stations; water-resources business data on flood and drought defense, water resources, hydrology, water environment, water conservation and resettlement; digital-twin water-resources geospatial data; etc. | ||
| (3) Industry | 8. Steel, non-ferrous metals | Identified by reference to the Guide to the Identification of Important Data in the Industrial Sector (YD/T 4981-2024). | Data on reserves, output and procurement volumes of non-ferrous metals with important military and civilian value; national strategic reserve data on steel and non-ferrous metals or important geological data on strategic non-ferrous-metal deposits; data on mining areas rich in important associated mineral resources. Data on rare-earth mining, smelting and other production technologies uniquely mastered by China. Bulk raw-material information and data capable of determining pricing power in raw-material procurement. |
| 9. Rare earths | Identified by reference to YD/T 4981-2024. | ||
| 10. Other minerals | Including reserve data, international cooperation data, international trade negotiation data, and the layout of mineral-related industrial development. | ||
| 11. Chemical industry | Identified by reference to YD/T 4981-2024. | Data on the monitoring of key hazardous chemicals, key processes, equipment operation, output and reserves held by Guangxi FTZ enterprises. Research and test data and operational monitoring data in the civil nuclear facilities field. Information on advanced technologies of the electronic-information industry, advanced integrated-circuit design and manufacturing technologies, design data, algorithms and software–hardware architectures of major computing equipment, and the domestic-production rate of important electronic components and equipment. | |
| 12. Electricity | Including power-plant production data, transmission and distribution data, and construction, operation and maintenance data. | ||
| 13. Electronic information | Identified by reference to YD/T 4981-2024. | ||
| 14. Civil nuclear facilities | Including experimental or test data in civil nuclear facility research, design and manufacturing process information relating to nuclear facilities, and operational monitoring data of nuclear facilities. | ||
| 15. Industrial equipment | Identified by reference to YD/T 4981-2024. | Research and production data on key automotive components bearing on China’s scientific and technological strength and international competitiveness, such as research data on vehicle stability control systems and active damper systems. Training data for autonomous-driving models of intelligent connected vehicles used in research and production. Data safeguarding the secure operation of industrial internet or industrial control systems used by above-scale industrial enterprises. | |
| 16. Intelligent connected vehicles | Identified by reference to YD/T 4981-2024. | ||
| 17. Other | Identified by reference to YD/T 4981-2024. | ||
| (4) Defense science and technology industry | 18. Defense science and technology industry | Including operation and management, research and design, manufacturing, testing and verification, and maintenance and support data. | Data relating to national military, economic, scientific and technological and cyber security; data comprehensively reflecting the research and production capabilities of important enterprises and institutions of the defense science and technology industry; data which when aggregated reflect the overall situation of the defense industry; and distinctive important data of the defense industry field. |
| (5) Telecommunications | 19. Telecommunications | Identified by reference to the Guide to the Identification of Important Data in the Telecommunications Sector (YD/T 3867-2024). | Construction-planning data, performance-parameter data, monitoring and analysis data, operation and maintenance data, statistical analysis data and the like of important network facilities and information systems. |
| (6) Radio, television and online audio-visual | 20. Radio and television | Including data processed in the collection and filming, production and broadcast, transmission and coverage, distribution and service, and monitoring and supervision of radio and television programs. | Undisclosed audio-visual creative content; audio-visual content whose misuse could affect ideological security or public security; transmission and coverage data of broadcasting institutions at the provincial level or above; broadcasting and audio-visual monitoring and regulatory data; and planning and construction data, operation and maintenance data, key resources and security-assurance data of critical information infrastructure and important networks and information systems in the broadcasting industry. |
| 21. Online audio-visual | Including data processed in the collection and filming, production and broadcast, distribution and service, and monitoring and supervision of online audio-visual programs. | ||
| (7) Finance | 22. Banking | Including bank customer data, business data, operation and management data, and system operation and security management data. | Institutional security information in the banking, insurance, securities and futures and financial-leasing fields, and business data of important enterprises and institutions processed by them, including information relating to defense-industry enterprises and enterprises bearing on national security. |
| 23. Insurance | Including insurance institutions’ customer data, business data, operation and management data, and system operation and security management data. | ||
| 24. Securities and futures | Including investor data, technical data, business data, etc. | ||
| 25. Financial leasing | Including customer data, enterprise transaction data, operation and management data, etc. | ||
| (8) Transport | 26. Transport | Including railway, highway, road transport, urban transport, waterway, civil aviation, postal administration and comprehensive management data. | Control-category data affecting production safety in the railway, highway, road transport, urban transport, waterway, civil aviation and postal administration fields; natural-resources data obtained in the course of construction; undisclosed route maps and key-station data; and data whose leakage or tampering could cause major transport accidents. |
| (9) Health and food and drugs | 27. Genetic resources | Including natural persons’ genetic data, human genetic resource information and other data relating to ethnic and population health. | Genetic-resource data reflecting the overall situation of an ethnic group or bearing on biosecurity; food, drug, biosecurity and disease-control data bearing on national security, life safety and the safety of humankind; medical diagnosis and treatment data involving the life, health and safety of the public in specific fields, specific groups or specific regions, or reaching a certain precision and scale. |
| 28. Health and medical | Including medical services, electronic medical records, electronic health archives, medical research and other data; health data, medical rescue support data, experimental data on specific drugs; or the results of developing and utilizing patients’ health and medical data. | ||
| 29. Food | Including food-safety traceability identification data and parameters and control data of automatic control systems in food production. | ||
| 30. Drugs | Including experimental data submitted in drug supply and drug approval, and test data relating to drug production processes and production facilities. | ||
| 31. Biosecurity | Including data relating to virus research or biological laboratories. | ||
| 32. Disease-control data | Including sudden public-health events and epidemic, treatment, vaccine and cause-of-death data relating to infectious diseases. | ||
| (10) Public security | 33. Physical security | Including basic building data, security-equipment data, etc. | Basic data on important targets, security-equipment data and security-deployment data of sensitive premises which, if unlawfully used, could cause serious harm to social stability; planning and secure-operation data of critical information infrastructure or important networks. |
| 34. Cybersecurity | Including design and operation data of FTZ enterprises’ information systems, network-facility topology data, security-assurance data, etc. | ||
| (11) Internet services and e-commerce | 35. Internet platform services | Including data of all kinds generated in the course of providing internet services. | Data generated in the course of providing internet services that could be used for social mobilization; digital-profile data on sensitive groups such as veterans; data recording and tracking defense-industry and government customers. AI training data, algorithm source code, key-component data, control programs and similar data that could affect national security and the public interest. |
| 36. AI services | Including AI training data, algorithm source code, key-component data, control programs and similar data. | ||
| (12) Science and technology | 37. Intellectual property and major discoveries | Including intellectual property involving national defense or national security or otherwise undisclosed, and other research papers, observational data and industrialization results that could significantly enhance national security capabilities or directly affect national security. | Intellectual-property data involving national defense or national security. Data relating to items listed in the Catalogue of Technologies Prohibited or Restricted from Export from China. |
| 38. Technologies prohibited or restricted from export | Including data relating to technologies listed in the Catalogue of Technologies Prohibited or Restricted from Export from China. | ||
| (13) Other data | 39. Data controlled under the Export Control Law | Including data on items included in the national export-control lists. | Data controlled under the Export Control Law relating to national security and interests and the performance of international obligations such as non-proliferation. Other data meeting the definition of important data that could affect national political, territorial, military, economic, cultural, social, scientific and technological, cyber, ecological, resource, nuclear, overseas-interest, space, polar, deep-sea, biological or other security. |
| 40. Other data that could affect national political, territorial, military, economic, cultural, social, scientific and technological, cyber, ecological, resource, nuclear, overseas-interest, space, polar, deep-sea, biological or other security. |