Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ LAW · JILIN PUBLIC DATA AUTHORIZED OPERATION MEASURES

Jilin Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial).

吉林省公共数据资源授权运营管理办法(试行)

FILED UNDER · Data Economy

Promulgated by: Jilin Provincial Government Services and Digital Development Administration (吉林省政务服务和数字化建设管理局).
Document No.: 吉政数发〔2026〕4号 (Ji Zheng Shu Fa [2026] No. 4).
Issued April 24, 2026. Effective April 24, 2026 (two-year trial period).

Translation note — DCC. Translated in full from the official Chinese text of the issuing notice and the annexed Measures (local normative document, currently in force). The Measures implement the national Implementation Specifications for Authorized Operation of Public Data Resources (Trial) and sit alongside the Interim Measures for Public Data Resource Registration. Terminology follows DCC’s bilingual glossary.


Notice of the Jilin Provincial Government Services and Digital Development Administration on Issuing the Jilin Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial)

To the government services and digital development administrations of each city (prefecture), the Changbai Mountain Administrative Committee and Meihekou City, and relevant central and provincial-level units:

In order to implement the Opinions of the General Office of the CPC Central Committee and the General Office of the State Council on Accelerating the Development and Utilization of Public Data Resources and to regulate the authorized operation of public data resources, and pursuant to the Notice of the National Development and Reform Commission and the National Data Administration on Issuing the Implementation Specifications for Authorized Operation of Public Data Resources (Trial) (Fa Gai Shu Ju Gui [2025] No. 27), we have formulated the Jilin Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial), which are hereby issued to you for compliance and implementation.

Jilin Provincial Government Services and Digital Development Administration

April 24, 2026

Annex: Jilin Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial)


Jilin Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial)

Chapter I General Provisions

Article 1. These Measures are formulated in accordance with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China and other laws and regulations, and pursuant to the Opinions of the General Office of the CPC Central Committee and the General Office of the State Council on Accelerating the Development and Utilization of Public Data Resources and the Notice of the National Development and Reform Commission and the National Data Administration on Issuing the Implementation Specifications for Authorized Operation of Public Data Resources (Trial), in light of the actual conditions of this Province, in order to advance the development and utilization of public data resources and regulate the authorized operation of public data resources in Jilin Province.

Article 2. These Measures apply to public data resource authorized-operation activities carried out within the administrative area of Jilin Province.

Article 3. “Public data resources” refers to collections of data with utilization value generated by Party and government organs at all levels and by enterprises and public institutions in the course of performing their duties in accordance with law or providing public services.

“Authorized operation” (授权运营) refers to the activity of authorizing, in accordance with laws, regulations and relevant requirements, the governance and development of public data resources and the fair provision of data products and technical services to the market.

“Implementing institution” refers to the unit determined by a local people’s government at or above the county level or a sectoral competent department, in light of the authorization model, to be specifically responsible for organizing and conducting authorized-operation activities.

“Operating institution” refers to a legal-person organization that has obtained authorization through standardized procedures and that develops and operates the public data resources within the scope of the authorization.

“Data-source unit” (数源单位) refers to a State organ, an organization authorized by laws and regulations to perform public-affairs management or public-service functions, or an enterprise or public institution that generates data and data collections with utilization value in the course of performing its duties or providing services.

“Implementation plan” refers to a plan, prepared under the lead of the data administration department or the data administration body of a sectoral competent department at or above the county level, or prepared under their guidance by the various implementing institutions of the region or department, that complies with laws, regulations, national policies and the relevant policy documents of Jilin Province and ensures that the authorized operation of public data resources can be implemented and put into effect.

“Public data products and services” refers to data-processing products and data services formed from public data resources after processing, capable of meeting specific needs, such as data interfaces, data models, data verification, data reports and evaluation indices.

Article 4. All participants in the authorized operation of public data resources shall carry out their work in accordance with the requirement that “raw data does not leave its domain; data is usable but not visible” (原始数据不出域,数据可用不可见), and shall follow the principles of legality and compliance, fairness and transparency, public-interest priority, reasonable returns, and security and controllability.

Chapter II Basic Requirements

Article 5. Public data resources lawfully and compliantly held shall be actively used for authorized operation, except in the following circumstances:

(I) Where national security or the public interest would be endangered;

(II) Where personal privacy, personal information rights and interests, or trade secrets would be infringed;

(III) Where the national sectoral competent department has expressly prohibited authorized operation;

(IV) Where laws and regulations provide that the data may not be developed and utilized by society.

Where public data resources obtained from other regions or departments are to be used for authorized operation, the consent of the data-source unit shall be obtained.

Article 6. The provincial data administration department is responsible for the overall coordination and supervision and administration of public data resource authorized-operation work throughout the Province; it shall strengthen the integration of data resources, enhance data service capacity, fully leverage the scale-of-application effect of public data resources, guide the preparation of public data resource authorized-operation implementation plans, dynamically monitor and evaluate the state of public data resource authorized operation across the Province, and be responsible for the filing administration of implementation plans and authorized-operation agreements throughout the Province.

Municipal- and county-level data administration departments are responsible for the overall coordination of public data resource authorized-operation work within their jurisdictions, strengthening the integration of data resources, and properly conducting supervision and administration.

Sectoral competent departments at all levels shall guide, promote and supervise the authorized operation of public data resources in their sectors in accordance with laws and regulations.

Finance departments at all levels shall strengthen the overall management of the data assets of administrative and public institutions.

Development and reform, data administration and other departments at all levels shall strengthen guidance and supervision over the fees charged for public data authorized-operation services.

Cyberspace administration, public security, State security and other departments at all levels shall, according to their respective duties, be responsible for the supervision and administration of the authorized operation of public data resources.

Chapter III Preparation of Implementation Plans

Article 7. Data administration departments or the data administration bodies of sectoral competent departments at or above the county level shall take the lead in organizing, or shall guide implementing institutions in, the preparation of public data resource authorized-operation implementation plans. An implementation plan shall clearly set out the content of, and the conditions relating to, the public data resource authorized-operation activities, and ensure that the plan can be implemented and put into effect.

Article 8. Data administration departments at or above the county level shall be responsible for, or shall assist in, submitting the implementation plan to the people’s government at the same level for deliberation. The implementation plan shall be implemented after it has been deliberated and approved in accordance with the requirements of the “three majors and one large” (三重一大) decision-making mechanism.

Municipal-level data administration departments shall, within one month, submit the implementation plans deliberated and approved in their regions to the provincial data administration department for filing.

County-level data administration departments shall, within one month, submit the implementation plans deliberated and approved in their regions to the municipal-level data administration department, which shall consolidate them and submit them together to the provincial data administration department for filing.

An implementation plan that has been examined and approved shall in principle not be changed at will; where a major change is genuinely necessary, it shall be resubmitted for deliberation and approval following the original procedure.

Article 9. An implementation plan shall include the following content:

(I) The name of the authorized operation and the implementing institution;

(II) A demonstration of the necessity and feasibility of the authorized operation;

(III) The selection criteria for the operating institution, including but not limited to funding, management, technology, service and security capabilities;

(IV) The authorized-operation model, including overall authorization, field-by-field authorization or scenario-based authorization;

(V) The scope of data resources under authorized operation, the data resource catalogue, the data update frequency and the state of data quality;

(VI) The authorized-operation term, construction content, technical safeguards, implementation schedule, evaluation criteria, exit mechanism and asset management;

(VII) The list of proposed public data products and services, which shall cover the two major categories of support for public governance and public-interest undertakings, and for industrial development and sectoral development, as well as the expected forms of products and services;

(VIII) The accounting mechanism for operating costs and revenue within the operating institution’s authorized scope, and the revenue distribution mechanism;

(IX) Data security and personal information protection measures and emergency-response measures;

(X) The rights and obligations of the implementing institution, the operating institution and other relevant participants;

(XI) Supervision and administration and assessment and evaluation requirements for the authorized operation;

(XII) Other matters that should be clarified.

Chapter IV Execution of Operating Agreements

Article 10. The implementing institution shall, on the basis of the examined and approved implementation plan and in accordance with the requirements of laws and regulations, select the operating institution through fair-competition methods such as public bidding, invited bidding or negotiation, and shall publicly announce the result to society as required by the relevant laws and regulations. Where no objection is raised during the public announcement period, the implementing institution shall, independently or together with the relevant business-competent departments at the same level, enter into a public data resource authorized-operation agreement with the lawfully selected operating institution. The content of the authorized-operation agreement shall fully solicit the opinions of all parties, shall be executed after deliberation and approval by the implementing institution’s “three majors and one large” decision-making mechanism, and shall be submitted to the data administration department at the same level for filing.

Municipal-level data administration departments shall, within one month, submit the authorized-operation agreements deliberated and approved in their regions to the provincial data administration department for filing.

County-level data administration departments shall, within one month, submit the authorized-operation agreements deliberated and approved in their regions to the municipal-level data administration department, which shall consolidate them and submit them together to the provincial data administration department for filing.

Article 11. An operating institution shall meet the following conditions:

(I) Sound business and credit standing, good public credibility, no record of major violations of law, and not having been placed on the list of dishonest judgment debtors, the list of parties to major tax violation cases, the list of seriously dishonest entities or similar lists;

(II) Capacity for data security assurance, risk monitoring and emergency response;

(III) Capacity to serve the healthy development of the public data resource operating ecosystem;

(IV) The office facilities, professional team and technical capacity required for the authorized operation of public data resources, including but not limited to technical, operational and management personnel;

(V) A clearly designated person in charge of data security and a management department; an established internal management and security assurance system for the authorized operation of public data resources; the environment and conditions for access to the government-affairs network; the software and hardware environment for acquiring, managing and applying public data resources; the technical management capacity needed to respond promptly to government regulatory requirements; and no high-risk items in the results of its public data security system assessment.

Article 12. The content of a public data resource authorized-operation agreement shall include:

(I) The scope and data resource catalogue of the public data resources under authorized operation;

(II) The operating term, which in principle shall not exceed five years;

(III) The list of proposed public data products and services, and the technical standards, security review requirements and business-compliance review requirements applicable to them;

(IV) The technical support platform for the public data resource authorized-operation work;

(V) Asset ownership, including ownership of software and hardware equipment and of public data products and services;

(VI) Information-disclosure requirements regarding the authorized operation, and the requirement that the operating institution shall not directly or indirectly participate in further development;

(VII) Accounting requirements for operating costs and revenue within the operating institution’s authorized scope, and the revenue distribution mechanism;

(VIII) Data security and personal information protection requirements, and risk monitoring and emergency-response measures;

(IX) Operating-effectiveness evaluation, and the renewal or exit mechanism;

(X) Liability for breach of contract;

(XI) Dispute resolution methods;

(XII) Conditions for modification and termination of the agreement;

(XIII) Other matters requiring clarification.

Chapter V Operation and Implementation

Article 13. The operating institution shall, on the basis of the Multi-Level Protection Scheme (网络安全等级保护制度) for cybersecurity, establish and improve an efficient technical protection and operational management system, safeguard the security of public data resources, and effectively protect personal information.

The operating institution shall formulate an emergency-response plan for data security incidents and organize drills regularly. When a data security incident occurs or a major risk is discovered, it shall immediately activate the emergency-response plan, take corresponding emergency-response measures to prevent the harm from spreading and eliminate security hazards, and report to the implementing institution and the relevant competent departments.

Article 14. The operating institution shall conduct business within the scope of the authorization in accordance with laws and regulations, and shall not directly or indirectly participate in the further development of public data products and services already delivered within the authorized scope. Other operating entities are encouraged to further develop the public data products and services delivered by operating institutions, integrate multi-source data, enhance the value of data products and services, and contribute to a flourishing data-industry development ecosystem.

Article 15. Public data resources brought within the scope of authorized operation, and the data products and services developed from them, shall undergo public data resource registration. Where public data resource authorized operation has already been carried out, supplementary registration shall be made.

Article 16. Before releasing data products and services developed from public data resources, the operating institution shall submit an evaluation report to the data administration department at the same level and to the data-source unit. The report shall cover the legality, accuracy, consistency, regularity, completeness, timeliness and accessibility of the data, the risks of circulation and trading, the de-identification of sensitive data, the informed consent of specific subjects, and similar matters.

Article 17. During the operating term, the operating institution shall submit an annual report on the authorized operation of public data resources to the implementing institution. The report shall cover the authorized storage, processing, analysis and mining, integrated utilization and market operation of the relevant data resources, among other matters.

The implementing institution and the operating institution shall disclose the state of their work in accordance with relevant provisions.

Article 18. Public data products and services used for public governance and public-interest undertakings may be used free of charge subject to conditions; those used for industrial development and sectoral development are subject to government-guided pricing (政府指导价), implemented in accordance with the relevant policies.

Chapter VI Operational Administration

Article 19. The authorized operation of public data resources shall attach equal importance to development and security, follow the principles of legality and compliance, market-based operation, combining unified and decentralized management, reasonable returns, and security and controllability, and, in accordance with the requirement that “whoever authorizes is responsible, whoever implements is responsible, whoever operates is responsible, and whoever uses is responsible,” promote the orderly flow and utilization of public data.

Article 20. The implementing institution shall improve the security management system for the authorized operation of public data resources; formulate institutional norms and technical standards for authorized-operation security protection, such as security-compliance review, risk assessment, monitoring and early warning, and emergency response; clarify the cybersecurity, data security and other security responsibilities, codes of conduct and management requirements of the entities participating in data operation, so as to ensure that the entire process of data access, processing, development and utilization, and service support is secure and controllable; strictly control the direct entry into the market of raw public data resources that have not been made public in accordance with laws and regulations; and strengthen internal-control audits of the operating institution in respect of the authorized operation of public data resources.

Article 21. The implementing institution shall, together with the relevant units or by entrusting a third-party institution, regularly evaluate the operating institution’s operations. The evaluation results shall serve as an important basis for whether the operating institution continues to carry out authorized operation or applies for authorized operation again, and the state of public data resource authorized operation and the evaluation results shall be reported to the data administration department at the same level.

Article 22. Failure to comply with the provisions of laws and regulations on anti-monopoly, anti-unfair competition, consumer rights protection and the like shall be dealt with by the relevant departments in accordance with law and their duties, and the relevant adverse information shall be recorded in the credit file of the party concerned in accordance with law.

Article 23. The operating institution shall comply with the following requirements:

(I) The operating institution shall strictly follow the overall requirement that “raw data does not leave its domain; data is usable but not visible,” establish a monitoring and early-warning mechanism for tracing data leakage and for data tampering and non-compliant use, and shall not in any manner provide or sub-authorize the public data resources under authorized operation to a third party. Where non-compliant use, resale, leakage or other improper application is discovered, it shall take measures such as suspending or terminating the cooperation to prevent losses from spreading;

(II) The operating institution shall not in any manner export or copy raw data, shall not restore raw data through reversible models or algorithms, and shall not trade in raw data;

(III) The operating institution shall carry out the authorized operation of public data resources in a regulated manner in accordance with law, shall not provide, or provide in disguised form, raw data that has not been made public in the course of operation, and shall ensure that data processing activities are carried out in a secure, compliant and trusted environment;

(IV) The operating institution shall regulate its data-use conduct, strictly control the scope of data acquisition and application, strengthen full-lifecycle data security and lawful-use management, ensure that the destination of data can be checked, that conduct leaves a record, that data is used only for its designated purpose and to the minimum necessary extent, and prohibit the excessive acquisition, misuse or abuse of data;

(V) The operating institution shall establish a standardized operational management system, strengthen quality control of public data products and services, and raise the standard and value of public data products and services;

(VI) The operating institution shall provide pre-employment security training for practitioners, strengthen security education and management of practitioners, enter into confidentiality agreements with practitioners, and ensure that practitioners’ data operations are recorded and auditable;

(VII) The operating institution shall not engage in other prohibited conduct provided for by laws and regulations or conduct that breaches the authorized-operation agreement.

Where the operating institution fails to comply with the above requirements or engages in prohibited conduct, the implementing institution shall immediately close the operating institution’s relevant access rights and order it to delete the relevant data retained for the authorized operation.

Article 24. Exit by an operating institution includes the following circumstances:

(I) Where the authorized-operation term expires and the operation terminates, or the operation is terminated early;

(II) Where the operating institution breaches the provisions of the relevant agreement and its rectification is ineffective or it refuses to rectify;

(III) Where the operating institution is subject to administrative penalties such as restriction of data-related production and business activities or an order to suspend production or business, or to criminal penalties;

(IV) Where the operating institution has engaged in prohibited conduct that has not caused serious consequences, but its rectification is ineffective or it refuses to rectify;

(V) Where the operating institution has engaged in prohibited conduct that has caused serious consequences;

(VI) Other circumstances in which it is unsuitable to carry out authorized-operation activities.

Where any of the above circumstances applies, the implementing institution shall terminate or rescind the public data resource authorized-operation agreement. Network logs for the authorized-operation period shall be retained in full for no less than five years. The operating institution shall ensure the smooth transition of existing services during the handover period, properly hand over the relevant business and data, and avoid service interruption or data security hazards caused by its exit. The implementing institution shall strengthen the management of the operating institution’s exit and promptly report the relevant circumstances to the data administration department at the same level.

Article 25. A data-source unit shall perform the following duties and obligations:

(I) Be responsible for the aggregation, updating and governance of the relevant public data resources, the preparation of the public data resource catalogue, and public data resource registration;

(II) Be responsible for the quality management of the relevant public data resources, ensure the completeness, timeliness and accuracy of the data resources provided, and cooperate with and assist the implementing institution and the operating institution in improving the quality of data supply;

(III) Be responsible for the coordination and implementation of data security maintenance, risk assessment, compliance management and personal information protection.

Article 26. In carrying out authorized operation, the security hazards arising from improper data assetization (数据资产化) and data asset capitalization (数据资产资本化) shall be effectively identified and controlled, and financial risks shall be effectively prevented and defused.

Article 27. The authorized operation of public data resources shall take full account of the unknown variables in the data field, implement the “three distinctions” (三个区分开来), encourage and protect officials who take responsibility and act, and support active exploration of feasible paths in respect of institutional mechanisms, authorization in accordance with rules, price formation and revenue distribution, while resolutely preventing the use of data for private gain. Where deviations occur in the course of exploration due to force majeure or factors that were difficult to foresee, but no private gain was sought, the relevant supervisory duties and obligations were performed, and active remedial measures were taken after the problem was discovered, the liability of the relevant entities shall, following evaluation in accordance with the relevant provisions of the State and the Province, be exempted or mitigated where the conditions are met.

Chapter VII Supplementary Provisions

Article 28. The Jilin Provincial Government Services and Digital Development Administration is responsible for the interpretation of these Measures.

Article 29. These Measures take effect from the date of publication, with a trial period of two years. During that period, where laws and regulations, national policies or the Jilin Provincial People’s Government make new provisions on the authorized operation of public data resources, those provisions shall prevail.

§ RELATED LAWS

See also.

§ COMMENTARY

Briefs on this law.

No briefs filed yet under this law.

§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →