Promulgated by: Shandong Provincial Big Data Bureau (山东省大数据局), with the approval of the Shandong Provincial People’s Government.
Document No.: 鲁数发〔2025〕3号 (Lu Shu Fa [2025] No. 3).
Issued April 2, 2025. Effective May 1, 2025. Valid until May 1, 2028.
Translation note — DCC. Translated in full from the official Chinese text of the issuing notice and the Measures (local normative document, currently in force). The Measures implement the national Implementation Specifications for Authorized Operation of Public Data Resources (Trial); Article 19 applies the Interim Measures for Public Data Resource Registration to operator-developed products. Terminology follows DCC’s bilingual glossary.
Notice of the Shandong Provincial Big Data Bureau on Issuing the Shandong Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial)
To all departments and units directly under the Provincial Government, and the big data bureaus of all cities:
The Shandong Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial) have been approved by the Provincial Government and are hereby issued to you. Please comply with and implement them conscientiously.
Shandong Provincial Big Data Bureau
April 2, 2025
Shandong Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial)
Chapter I General Provisions
Article 1. These Measures are formulated in accordance with the Opinions of the General Office of the CPC Central Committee and the General Office of the State Council on Accelerating the Development and Utilization of Public Data Resources, the Notice of the National Development and Reform Commission and the National Data Administration on Issuing the Implementation Specifications for Authorized Operation of Public Data Resources (Trial) and other provisions, in light of actual conditions, in order to advance the development and utilization of public data resources, regulate the authorized operation of public data resources, and promote the release of the value of data as a factor of production.
Article 2. These Measures apply to the authorized operation of public data resources and related administrative activities carried out within the administrative area of Shandong Province.
Article 3. “Public data resources” refers to collections of data with utilization value generated by Party and government organs at all levels and by enterprises and public institutions in the course of performing their duties in accordance with law or providing public services.
“Authorized operation” (授权运营) refers to the activity of authorizing qualified operating institutions, in accordance with laws, regulations and relevant requirements, to govern and develop public data resources held by people’s governments at or above the county level, and to provide public data products and services fairly to the market.
“Implementing institution” refers to the unit specifically responsible for organizing and conducting authorized-operation activities; the data administration department at or above the county level is the implementing institution for its level.
“Operating institution” refers to a legal-person organization that has obtained authorization through standardized procedures and that develops and operates the public data resources within the scope of the authorization.
Article 4. The authorized operation of public data resources shall follow the principles of legality and compliance, fairness and impartiality, public-interest priority, reasonable returns, and security and controllability.
Article 5. The provincial data administration department is responsible for improving the policies, management systems, standards and norms relating to the authorized operation of public data resources, undertaking the administration of the authorized operation of provincial-level public data resources, and guiding and supervising the administration of public data resource authorized operation throughout the Province. Data administration departments at or above the county level shall organize the authorized operation of the public data resources of their own level, on the premise of implementing the requirements of the data classification and grading protection system, not endangering national security or the public interest, and not infringing trade secrets, personal privacy, personal information rights and interests or other lawful rights and interests.
Sectoral competent departments are responsible for the preparation of the public data resource catalogues, the aggregation of public data resources, and data quality management for their departments and sectors, and shall cooperate in the administration of public data resource authorized operation.
The development and reform, finance, market regulation, taxation and other departments are responsible, according to their respective duties, for the business supervision of the authorized operation of public data resources.
The cyberspace administration, public security, State security, secrecy and other departments shall, according to their respective duties, carry out security supervision of the authorized operation of public data resources.
Chapter II Data Supply
Article 6. Public data resources are subject to unified catalogue management. The provincial data administration department is responsible for formulating the standards for preparing public data resource catalogues, and data administration departments at each level shall organize the preparation and maintenance of the public data resource catalogue of their level. Public data resource provider units shall prepare their own public data resource catalogues in accordance with the catalogue preparation standards.
Article 7. Public data resource provider units shall, in accordance with the principle that all data that should be aggregated is aggregated, aggregate their public data resources in full to the provincial integrated big data platform, and shall be responsible for the dynamic updating of the data.
Article 8. Public data resource provider units shall strengthen data quality control at the source, and shall, through the provincial integrated big data platform, carry out the sharing, opening, verification, updating and security management of public data resources in accordance with laws and regulations, so as to ensure the completeness, consistency, accuracy and timeliness of the data.
The provincial data administration department shall establish working norms for data quality monitoring and evaluation, the correction of problem data, and the verification and handling of objections; shall verify and confirm public data resources; and shall urge public data resource provider units to complete the rectification of problem data within the prescribed period.
Chapter III Data Authorization
Article 9. The public data resource authorized-operation models include overall authorization, field-by-field authorization and scenario-based authorization.
The authorized operation of public data resources shall in principle be based primarily on overall authorization, organized and implemented by the implementing institution. Where genuinely necessary, the implementing institution shall organize and implement field-by-field authorization and scenario-based authorization together with the sectoral competent departments.
Article 10. The provincial data administration department is responsible for building a unified public data resource authorization-management module on the provincial integrated big data platform and for the operation and maintenance of the module. Data administration departments at or above the county level shall organize public data resource authorized-operation applications, reviews, service monitoring and related work through the unified public data resource authorization-management module.
Article 11. Data administration departments at or above the county level shall take the lead in organizing, or shall together with the sectoral competent departments, prepare public data resource authorized-operation implementation plans in accordance with the requirements of the relevant national documents. An implementation plan shall balance economic and social benefits and ensure that it can be implemented and put into effect.
Article 12. A public data resource authorized-operation implementation plan shall, in accordance with the “three majors and one large” (三重一大) decision-making mechanism, be deliberated and approved by the people’s government at the same level, and shall be submitted to the provincial data administration department for filing within 20 working days.
An implementation plan that has been examined and approved shall in principle not be changed at will. Where the authorized-operation model is adjusted, the scope of data resources under authorized operation is changed, or the revenue distribution mechanism is adjusted, the plan shall be resubmitted for deliberation and approval following the original procedure.
Article 13. Public data resources shall be authorized according to the following procedure:
(I) The implementing institution publishes an application announcement for the authorized operation of public data resources, specifying the application conditions;
(II) Units applying for the authorized operation of public data resources submit their applications to the implementing institution within the prescribed period;
(III) The implementing institution, on the basis of the examined and approved implementation plan and in accordance with the requirements of laws and regulations, selects the operating institution through fair-competition methods such as public bidding, invited bidding or negotiation;
(IV) The implementing institution publicly announces the award result to society;
(V) Where no objection is raised during the public announcement period, the implementing institution enters into a public data resource authorized-operation agreement with the operating institution; the agreement is executed after deliberation and approval by the implementing institution’s “three majors and one large” decision-making mechanism;
(VI) The provincial data administration department shall properly conduct filing administration for the various authorized-operation agreements within the administrative area and strengthen dynamic tracking of agreement performance.
Article 14. A legal-person organization meeting the following conditions may apply to become an operating institution:
(I) Sound business and credit standing;
(II) Corresponding capacity for system construction and operation and maintenance, data-application compliance monitoring, and emergency response;
(III) A professional technical team with service capacity;
(IV) An established security assurance system and data security protection capacity, with no data security incident in the past three years that had a significant impact on national security, social order, economic development or the public interest;
(V) Compliance with the other prescribed requirements for the authorized operation of public data resources.
Article 15. The content of the agreement shall include, without limitation, the scope of the public data resources under authorized operation, the data resource catalogue, the authorized-operation term, the list of proposed public data products and services and the compliance review requirements applicable to them, the technical support platform, asset ownership, data security requirements and rights and obligations, risk monitoring and effectiveness evaluation criteria, data confidentiality requirements, information disclosure, cost and revenue accounting requirements, revenue distribution, liability for breach of contract, the renewal or exit mechanism, and other matters requiring clarification.
The content of the bidding, procurement and negotiation documents relating to the authorized-operation agreement shall fully solicit the opinions of all parties; content involving revenue distribution shall be submitted for the opinion of the finance department at the same level.
Article 16. Authorized operation shall not be carried out where, following authorization, national security would be or might be endangered, or the public interest might be harmed.
Chapter IV Data Operation
Article 17. The operating institution shall submit an application for the public data resources it needs and shall obtain the public data resources after the application has been reviewed and approved by the data administration department and the sectoral competent department.
Article 18. An application by the operating institution for public data resources shall meet the following requirements:
(I) The application scenario is clear, the data needs are well defined, and there is significant social or economic value;
(II) The application scenario is highly implementable, with clear objectives and plans within the authorized-operation term, and the applicant has the capacity to put it into effect and achieve notable results;
(III) The application to use public data resources complies with the principle of minimum necessity and with the provisions of the relevant laws, regulations and rules.
Article 19. The operating institution shall conduct business within the scope of the authorization in accordance with laws and regulations, and shall register the public data products and services it develops in accordance with the administrative requirements for public data resource registration.
Article 20. The operating institution shall establish a review mechanism for the entities that use its public data products and services, and adopt the necessary control measures and technical means to ensure the secure and compliant use of public data products and services. The operating institution shall provide the necessary development and utilization environment for other operating entities to further develop the public data products and services it has delivered.
Article 21. Public data products and services are subject to the relevant national and Shandong Province policies on the administration of public data prices.
Article 22. Where the public data products and services delivered by the operating institution are to be circulated and traded, the trading shall be conducted at a data trading institution.
Article 23. Authorized operation shall protect the lawful rights and interests of all participants, and the operating institution may obtain reasonable returns according to the value contribution of its public data products and services. Implementing institutions and operating institutions are encouraged to support the data-governance and service-capacity building of departments at all levels through technology, products and services, revenue and other means, in accordance with laws and regulations.
Article 24. In carrying out authorized-operation activities, administrative power or a dominant market position shall not be abused to exclude or restrict competition, and data, algorithmic, technological or capital advantages shall not be used to engage in monopolistic conduct.
During the operating term, the operating institution shall submit a report on the state of its public data resource authorized-operation work to the data administration department at the same level each year, and shall accept supervision and inspection.
Article 25. The operating institution shall strengthen the internal management of the costs, revenue and expenditure related to public data products and services, manage the financial receipts and payments related to public data products and services in accordance with the existing financial management system, and accept supervision in accordance with law.
Article 26. The following conduct is prohibited in the authorized operation of public data resources:
(I) The operating institution shall not leak, steal, tamper with, destroy, lose or improperly use public data resources, and shall not in any manner provide or sub-authorize the public data resources under authorized operation to a third party;
(II) The operating institution shall not in any manner export raw data, shall not restore raw data through reversible models or algorithms, and shall not trade in raw data;
(III) The operating institution shall not carry out data operations outside the scope of the authorization, shall not use, or use in disguised form, the relevant public data products and services for application scenarios that have not been approved, and shall not, without having passed review, import other data or engage in technical-service cooperation with third parties;
(IV) Other conduct prohibited by laws and regulations.
Article 27. Exit by an operating institution includes the following circumstances:
(I) Where the authorized-operation term expires and the operation terminates, or the operation is terminated early;
(II) Where the operating institution breaches the provisions of the relevant agreement and its rectification is ineffective or it refuses to rectify;
(III) Where the operating institution is subject to administrative penalties such as restriction of data-related production and business activities, the emergence of a major business risk, or an order to suspend production or business, or to criminal penalties;
(IV) Other circumstances in which it is unsuitable to carry out authorized-operation activities.
Chapter V Security Safeguards
Article 28. In accordance with the principle that “whoever collects is responsible, whoever holds is responsible, whoever uses is responsible, and whoever operates is responsible,” the sectoral competent departments, data administration departments, implementing institutions and operating institutions, and all other relevant parties, bear the corresponding security responsibilities.
Article 29. The implementing institution shall establish and improve a full-lifecycle security-compliance management mechanism for public data products, and formulate institutional norms and technical standards for authorized-operation security protection such as security-compliance review, risk assessment, monitoring and early warning, and emergency response; shall strictly control the direct entry into the market of raw public data resources that have not been made public in accordance with laws and regulations; and shall strengthen internal-control audits of the operating institution in respect of the authorized operation of public data resources.
The operating institution shall, in accordance with the requirements for the classified and graded management of public data resources, establish and improve a security management system for public data resources, strengthen full-lifecycle security and lawful-use management of data in the course of authorized operation, and ensure that the source of data is traceable, its destination can be checked, conduct leaves a record, and responsibility can be pursued.
Article 30. The operating institution shall provide pre-employment security training for practitioners, strengthen security education and management of practitioners, enter into confidentiality agreements with practitioners, and ensure that practitioners’ data operations are recorded and auditable.
Article 31. The implementing institution and the operating institution shall make full use of privacy computing (隐私计算) and other security technologies and methods, establish and improve an efficient security technical protection and operating system, strengthen security protection and monitoring and early warning across the entire process of public data resource authorized operation, guard against risks from data correlation and aggregation, ensure the security of public data resources, and effectively protect personal information.
Article 32. The data administration department shall regularly conduct security inspections of the business and information systems related to authorized operation, the state of data use, and security assurance capacity. The operating institution shall cooperate actively, provide the relevant materials as required by the work, promptly rectify problems found in inspections, and guard against data security risks.
Article 33. The data administration department shall, together with the relevant departments, formulate an emergency response plan for security incidents and organize the operating institution to conduct emergency drills. When a data security incident occurs, the operating institution shall activate emergency response in accordance with the emergency response plan, report immediately to the data administration department at the same level, closely cooperate with the data administration department in the handling and investigation of the data security incident, actively take measures to eliminate security hazards and prevent the harm from spreading, and bear the corresponding responsibility.
Chapter VI Supervision and Administration
Article 34. Data administration departments and sectoral competent departments at or above the county level shall strengthen supervision and inspection of the authorized operation of public data resources to ensure that authorized operation complies with laws and regulations.
Article 35. Data administration departments and sectoral competent departments at or above the county level shall, together with the relevant units or by entrusting a third-party institution, regularly evaluate the state of public data resource authorized operation within their administrative areas. The evaluation results shall serve as an important basis for the termination or revocation of an operating institution’s authorization or for its re-application for authorized operation.
The operating institution shall cooperate in the evaluation, truthfully provide the relevant materials, and shall not refuse, obstruct or evade the evaluation, nor misreport, conceal or withhold the relevant circumstances.
Article 36. The implementing institution shall make public the state of the authorized operation in accordance with the relevant provisions, regularly disclose to society the authorized parties, content, scope and term, and accept social supervision.
The operating institution shall make public the list of public data products and services, regularly disclose to society the state of use of public data resources, and accept social supervision.
Article 37. Where authorized-operation activities involve the paid use or disposal of data assets, the examination and approval procedures for State-owned asset management shall be strictly followed. Income obtained by administrative and public institutions shall be managed in accordance with the relevant provisions on government non-tax revenue and centralized treasury collection. In carrying out authorized operation, the security hazards arising from improper data assetization (数据资产化) and data asset capitalization (数据资产资本化) shall be effectively identified and controlled, and financial risks shall be effectively prevented and defused.
Article 38. Where an operating institution falls within any of the following circumstances, the data administration departments and sectoral competent departments at each level shall urge it in accordance with law to rectify within a specified period and shall temporarily close its access rights to the relevant public data resources. Where the operating institution fails to complete rectification as required within the prescribed period, its operating authorization for the relevant public data resources shall be revoked in accordance with the relevant provisions or the agreement:
(I) Harming the interests of the State, the social public interest, or the lawful rights and interests of others;
(II) Failing to adopt data security safeguard measures in accordance with the relevant data security requirements;
(III) Other violations of the administrative requirements for the authorized operation of public data resources.
Where an operating institution or its relevant personnel violates national laws and regulations and infringes personal information, trade secrets or other lawful rights and interests, causing property loss, it shall bear the corresponding legal liability; where a crime is constituted, criminal liability shall be pursued in accordance with law.
Article 39. The authorized operation of public data resources shall encourage and protect officials who take responsibility and act, and foster an entrepreneurial atmosphere that encourages and tolerates innovation, while resolutely preventing the use of data for private gain.
Chapter VII Supplementary Provisions
Article 40. The development and utilization of public data resources held by public utility enterprises such as water, gas, heat, electricity and public-transport suppliers may be authorized for use with reference to the relevant procedural requirements of these Measures, safeguarding the public interest and the enterprises’ lawful data rights and interests, and subject to government and social supervision.
Article 41. These Measures take effect from May 1, 2025 and are valid until May 1, 2028. Where the State or the Provincial Government makes new provisions on the administration of the authorized operation of public data resources, those provisions shall prevail.