---
title_en: "Shanxi Province Measures for the Administration of the Authorized Operation of Public Data Resources (Trial)"
title_zh: "山西省公共数据资源授权运营管理办法（试行）"
abbreviation: "Shanxi Public Data Authorized Operation Measures"
hierarchy: "rule"
issuing_body: "General Office of the Shanxi Provincial People's Government"
adopted_date: 2025-08-02
effective_date: 2025-09-01
status: "effective"
related_laws: ["public-data-authorized-operation-specifications", "public-data-registration-interim-measures", "public-data-development-utilization-opinions", "public-data-authorized-operation-pricing-notice", "shanghai-public-data-authorized-operation-measures", "dsl"]
domains: ["data-economy", "data-security"]
url: https://datacompliancechina.com/laws/shanxi-public-data-authorized-operation-measures/
summary: "Issued by the General Office of the Shanxi Provincial People's Government on August 2, 2025 as 晋政办发〔2025〕23号 and effective September 1, 2025 for a two-year trial period, these 40-article Measures localize the NDRC/NDA Implementation Specifications for Shanxi. The distinctive feature is a two-tier authorization architecture: the Provincial Data Bureau, acting as implementing institution, selects a single tier-one operating entity that builds and runs the province-wide authorized-operation platform and performs primary data processing, and then, sector by sector, selects tier-two operating entities jointly with the provincial sectoral departments; a third layer of development entities applies for data through the platform under a 'one scenario, one application, one review' rule. Sectoral departments and their affiliates are expressly barred from granting authorization or operating on their own. Terms are capped at five years, plans and agreements pass through 'three majors and one large' deliberation and are filed level by level, fees for industry use are government-guided on a cost-compensation basis, and exiting operators must keep at least three years of work logs. For overseas counsel, the entry shows how a province can insert an intermediary platform operator between government data holders and the market while keeping raw data from leaving the domain."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/shanxi-public-data-authorized-operation-measures/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Shanxi Province Measures for the Administration of the Authorized Operation of Public Data Resources (Trial)", https://datacompliancechina.com/laws/shanxi-public-data-authorized-operation-measures/
**Promulgated by:** General Office of the Shanxi Provincial People's Government (with the approval of the Provincial People's Government).  
**Document No.:** 晋政办发〔2025〕23号 (Jin Zheng Ban Fa [2025] No. 23).  
**Issued August 2, 2025. Effective September 1, 2025. Two-year validity period.**

> *Translation note — DCC. Translated in full from the official Chinese text
> of the issuing notice and the Measures (seven chapters, forty articles), as
> published in the provincial government gazette record. This is Shanxi's local
> implementation of the national [Implementation Specifications for Authorized
> Operation of Public Data Resources](/laws/public-data-authorized-operation-specifications/)
> and sits alongside the [Interim Measures for Registration of Public Data
> Resources](/laws/public-data-registration-interim-measures/). Terminology
> follows DCC's bilingual glossary.*

---

## Notice of the General Office of the Shanxi Provincial People's Government on Issuing the Shanxi Province Measures for the Administration of the Authorized Operation of Public Data Resources (Trial)

To the people's governments of all cities and counties, and all commissions, offices, departments and bureaus of the Provincial People's Government:

The *Shanxi Province Measures for the Administration of the Authorized Operation of Public Data Resources (Trial)* have been approved by the Provincial People's Government and are hereby issued to you. Please implement them conscientiously.

General Office of the Shanxi Provincial People's Government  
August 2, 2025

---

## Shanxi Province Measures for the Administration of the Authorized Operation of Public Data Resources (Trial)

## Chapter I General Provisions

**Article 1.** These Measures are formulated in order to regulate the authorized operation of public data resources in this Province, accelerate the orderly development and utilization of public data resources, unlock the value of public data and promote the cultivation of the data market, in accordance with the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, the Personal Information Protection Law of the People's Republic of China, the Implementation Specifications for the Authorized Operation of Public Data Resources (Trial), the Interim Measures for the Administration of the Registration of Public Data Resources, the Shanxi Province Measures for the Administration of Data Work and other laws, regulations and normative documents, and pursuant to the requirements of the Opinions of the CPC Central Committee and the State Council on Building a Fundamental Data System to Better Leverage the Role of Data as a Factor of Production and the Opinions of the General Office of the CPC Central Committee and the General Office of the State Council on Accelerating the Development and Utilization of Public Data Resources, adhering to the coordination of development and security, and in light of the actual conditions of this Province.

**Article 2.** These Measures apply to the authorized operation of public data resources within the administrative region of Shanxi Province, to the supervision and administration thereof, and to other related activities.

**Article 3.** The following terms in these Measures have the meanings set out below:

(I) "Public data resources" refers to collections of data with utilization value generated by Party and government organs and enterprises and public institutions at all levels in the course of performing their duties in accordance with the law or providing public services.

(II) "Public data products and services" refers to processed data products and data services formed by processing public data resources that are capable of meeting specific needs.

(III) "Authorized operation of public data resources" refers to the activity of authorizing qualified operating entities, in accordance with laws, regulations and relevant requirements, to govern and develop public data resources held by people's governments at or above the county level, and to provide data products and technical services fairly to the market.

(IV) "Public data resource authorized-operation service platform" refers to the platform organized and built by the provincial-level data administration department to support the conduct of authorized operation, processing, and supervision and administration of public data resources; it is the unified platform for the authorized operation of public data resources across the Province (hereinafter, the "authorized-operation platform").

(V) "Implementing institution" refers to the unit specifically responsible for organizing the conduct of authorized-operation activities; the data administration department at or above the county level is the implementing institution at its level.

(VI) Operating entities are divided into tier-one operating entities and tier-two operating entities.

A "tier-one operating entity" refers to a legal-person organization that has obtained authorization through standardized procedures and undertakes the development and construction, day-to-day operation, and operation and maintenance of the authorized-operation platform, as well as the coordination and interfacing of public data resources and the primary processing of data.

A "tier-two operating entity" refers to a legal-person organization that has obtained authorization through standardized procedures and, relying on the authorized-operation platform, develops and operates public data resources within the scope of authorization.

(VII) "Development entity" refers to a legal-person organization that further processes primary-processed public data resources in depth to form data products and services, and provides them to society.

**Article 4.** The authorized operation of public data resources shall follow the principles of legality and compliance, overall planning, fairness and impartiality, public-interest priority, mutual benefit, and security and orderliness. In accordance with the requirement that "raw data does not leave its domain, and data is usable but not visible" (原始数据不出域，数据可用不可见), it shall comply with the laws, rules and systems relating to cybersecurity and data security, and, on the premise of implementing the requirements of the data classification and grading protection system, not endangering national security or the public interest, and not infringing trade secrets, personal privacy, personal information rights and interests or other lawful rights and interests, public data shall be applied for and used by scenario and data products and services provided.

## Chapter II Division of Responsibilities

**Article 5.** The Provincial Data Bureau (省数据局) is the provincial-level data administration department. It is responsible for taking the lead in establishing the Province's coordination mechanism for the authorized operation of public data resources and for coordinating the overall conduct of the authorized operation of public data resources. The office of the coordination mechanism is located in the Provincial Data Bureau and is responsible for implementing and advancing specific work. The data administration departments of each city and county (city, district) shall establish coordination mechanisms at their own level as needed.

Sectoral competent departments and their affiliated enterprises and public institutions shall not grant authorization or conduct operation on their own.

**Article 6.** The provincial-level data administration department assumes the function of overall administration of the authorized operation of public data resources, and is responsible for organizing, guiding, promoting and supervising the authorized operation of public data resources in this Province. Its specific duties are:

(I) establishing and improving the Province's policies, systems, standards and specifications relating to the authorized operation of public data resources, and guiding the cities and the provincial-level sectoral competent departments in carrying out the authorized operation of public data resources;

(II) organizing and guiding the preparation of the Province's implementation plans for the authorized operation of public data resources, and coordinating the organization of catalogue preparation, the establishment of data-supply mechanisms, the selection of operating entities, the evaluation of and incentives for operating effectiveness, the supervision and administration of the authorized-operation process, and other related work;

(III) organizing the construction of the provincial-level authorized-operation platform, and promoting the secure aggregation, standardized governance, and circulation and utilization of all types of public data;

(IV) organizing the establishment of an expert committee to provide business and technical support services for the formulation of policies and systems relating to the authorized operation of public data resources, the review of application scenarios, and the review of data products and services;

(V) disclosing the status of authorized operation in accordance with provisions, regularly disclosing to the public the objects, content, scope and time limits of authorization and other information, and accepting public supervision;

(VI) properly conducting the various filing administration tasks for authorized operation.

The data administration departments of each city and county (city, district) are responsible for coordinating the authorized operation of public data resources within their respective administrative regions.

**Article 7.** Provincial-level sectoral competent departments are responsible for the provincial-level authorized operation of public data resources in their respective sectors, and specifically undertake the following duties:

(I) designating the departments and personnel responsible for public data resource administration and authorized-operation work in their sector;

(II) preparing the implementation plan for the authorized operation of public data resources in their sector;

(III) being responsible for public data quality management in their department and sector, preparing and updating the catalogue of public data resources for authorized operation, providing to the authorized-operation platform the data resources within the scope of authorized operation in their sector, participating in the review of applications for authorized-operation application scenarios, and guiding and supervising the authorized operation of public data resources in their sector;

(IV) working together with the provincial-level data administration department to carry out the selection of tier-two operating entities for their sector and other work;

(V) implementing other work requirements relating to the authorized operation of public data resources set by the national sectoral competent departments and the provincial-level data administration department.

The sectoral competent departments of each city and county (city, district) shall cooperate with the data administration departments in properly conducting the authorized operation of public data resources at their level.

**Article 8.** The government information administration department is responsible for coordinating and dispatching government data resources at its level and, relying on the Province's integrated government big-data system, collaboratively carrying out the authorized operation of public data resources in the government-affairs field.

The development and reform department, together with the data administration department, formulates public data pricing policy and establishes a price-formation mechanism for the authorized operation of public data resources.

The finance department, together with the data administration department, strengthens the administration of the corresponding public data assets in accordance with the division of duties, and incorporates income from the paid use of public data resources that meets the relevant provisions into non-tax revenue administration.

The market regulation department is responsible for supervising and administering monopolistic conduct, unfair competition and other conduct that disrupts the market in the course of authorized operation.

The cyberspace administration, public security, state security, secrecy and other departments shall, in accordance with their respective duties, properly conduct the security supervision of the authorized operation of public data resources.

**Article 9.** A tier-one operating entity specifically undertakes the following duties:

(I) undertaking the development and construction, day-to-day operation, and operation and maintenance of the authorized-operation platform;

(II) providing technical support and business consulting services to data-source departments, tier-two operating entities and development entities for the conduct of authorized-operation activities;

(III) interfacing and coordinating data, carrying out primary processing of public data resources that have been reviewed and approved for authorized operation, tracking and giving feedback on data quality, and ensuring the quality of data services;

(IV) establishing a data security protection system, fulfilling the primary responsibility for data security, strengthening internal-control management and the management of technology and personnel, strictly guarding against data security risks in the links of data processing, handling, operation and service, and formulating emergency response plans for data security incidents;

(V) recording data circulation logs, ensuring that the entire process of data retrieval, governance and processing, and development and utilization is traceable, and providing data-circulation monitoring functions for data-source units, regulatory departments and others;

(VI) undertaking other authorized-operation work assigned by the data administration department.

**Article 10.** A tier-two operating entity specifically undertakes the following duties:

(I) strengthening the introduction and management of development entities, improving the ecosystem for the development and utilization of public data resources, verifying the registration applications of development entities, supervising the development and utilization conduct of development entities, and ensuring that the pricing, flow, scope of use, application scenarios and the like of data resources and data products comply with authorized-operation requirements;

(II) reviewing application scenarios and data needs, and data products and services;

(III) providing development entities, on the basis of the results of the review of application scenarios and data needs, with the primary data products formed after primary processing;

(IV) cooperating with the data administration departments and sectoral competent departments in continuously enriching data resources, properly conducting data quality management, and improving data quality;

(V) carrying out authorized-operation information disclosure in accordance with laws and regulations, publishing the list of development entities and the list of public data products and services, regularly disclosing to the public the use of public data resources, and informing the sectoral competent departments as needed;

(VI) fulfilling the primary responsibility for data security, strengthening internal-control management and the management of technology and personnel, and strictly guarding against data security risks in the links of data processing, handling, operation and service;

(VII) undertaking other authorized-operation work assigned by the relevant sectoral competent departments.

## Chapter III Authorization Mechanism

**Article 11.** The provincial-level model for the authorized operation of public data resources is the "tier-one authorization + tier-two sector-by-sector authorization" model. "Tier-one authorization" means that the provincial-level data administration department authorizes a legal-person organization meeting the selection conditions to undertake the construction, operation and maintenance of the authorized-operation platform, the interfacing and management of data resources, and the primary processing of data. "Sector-by-sector authorization" means that the provincial-level data administration department, through standardized procedures, authorizes public data separately by sector and field to a legal-person organization meeting the selection conditions.

The provincial-level data administration department organizes the selection of the tier-one operating entity and grants tier-one authorization on the basis of the selection results; relying on the Province's coordination mechanism for the authorized operation of public data resources, it organizes sector-by-sector authorization, and regularly reports the authorization situation to the Provincial People's Government.

Cities and counties (cities, districts) are encouraged to select an authorized-operation model in light of local conditions.

**Article 12.** The provincial-level data administration department organizes the preparation of the provincial-level implementation plan for the authorized operation of public data resources. The data administration departments and sectoral competent departments of each city and county (city, district) prepare the implementation plans for the authorized operation of public data resources for their administrative region or sector and field.

Implementation plans shall balance economic and social benefits and ensure that they can be implemented and put into practice. An implementation plan shall include the following content:

the name of the authorized operation; argumentation of the necessity and feasibility of the authorized operation, where the feasibility argumentation shall include but not be limited to full-lifecycle management services for the authorized-operation data, social demand, market scale, expected effectiveness, and risk prevention and control; the selection conditions for operating entities, including capacity in funding, management, technology, service and security; the authorized-operation model, including overall authorization, field-by-field authorization or scenario-based authorization; the scope of data resources for authorized operation, the data resource catalogue, data update frequency and data quality; the authorized-operation period, construction content, technical safeguards, implementation schedule, evaluation standards, exit mechanism and asset administration; the list of public data products and services proposed to be provided, which shall include the two major categories of supporting public governance and public welfare and supporting industry development and sectoral development, as well as the expected form of products and services; the accounting mechanism for operating costs and revenue within the operating entity's authorized scope, and the revenue distribution mechanism; data security and personal information protection measures and emergency-response measures; the rights and obligations of the data administration department, the operating entities and other relevant participants; supervision, administration, and assessment and evaluation requirements for the authorized operation; and other matters that should be clarified.

**Article 13.** The provincial-level implementation plan and the implementation plans of each sector shall be deliberated and approved respectively in accordance with the requirements of the "three majors and one large" (三重一大) decision-making mechanism of the provincial-level data administration department or of the sectoral competent department. The provincial-level data administration department shall submit its implementation plan to the Provincial People's Government for deliberation and properly conduct filing administration. An implementation plan that has been examined and approved shall not, in principle, be arbitrarily changed, other than content expressly designated for dynamic updating; where major changes are genuinely required, it shall be re-submitted for deliberation and approval through the original process.

The implementation plans of each city and county (city, district) shall be submitted by the data administration department at each level, on its own responsibility or by way of assistance, to the people's government at the same level for deliberation, and filed level by level with the data administration department at the next higher level.

**Article 14.** The provincial-level data administration department publicly issues the notice for the selection of operating entities for the authorized operation of public data resources. The tier-one operating entity is selected by the provincial-level data administration department through fair-competition methods such as public bidding, invited bidding or negotiation; tier-two operating entities are selected by the provincial-level data administration department and the sectoral competent departments through fair-competition methods such as public bidding, invited bidding or negotiation.

**Article 15.** Operating entities shall meet the following conditions:

(I) sound business and credit standing;

(II) no cybersecurity or data security incident in the past three years, compliance with the State's data security protection requirements, and capacity for risk monitoring and emergency response;

(III) stable business operations; a tier-one operating entity shall possess the professional team, service capacity and technical capacity required for the construction and operation of the authorized-operation platform and the processing of public data, and a tier-two operating entity shall possess the professional team, service capacity and technical capacity required for public data operation and management work;

(IV) compliance with other provisions and requirements for the authorized operation of public data resources.

The data administration departments of each city and county (city, district) may select operating entities at their level with reference to these provisions; the results shall be publicized to the public and filed level by level with the data administration department at the next higher level.

**Article 16.** After deliberation and approval by the "three majors and one large" decision-making mechanism of the provincial-level data administration department or of the sectoral competent department, a public data resource authorized-operation agreement shall be signed with the operating entity selected in accordance with laws and regulations. The data administration departments of each city and county (city, district) shall, with reference to these provisions, select operating entities and sign authorized-operation agreements. All types of authorized-operation agreements shall be filed level by level with the data administration department at the next higher level.

A public data resource authorized-operation agreement shall comply with the requirements of the relevant laws and regulations, and shall include, but not be limited to, the following content:

(I) the scope and data resource catalogue of the public data resources under authorized operation;

(II) the operating period, which in principle shall not exceed five years;

(III) the list of public data products and services proposed to be provided, and the technical standards, security review requirements and business-compliance review requirements applicable to them;

(IV) the technical support platform for the authorized operation of public data resources;

(V) asset ownership, including ownership of software and hardware equipment and of public data products and services;

(VI) information-disclosure requirements regarding the authorized operation, and the requirement that the operating institution shall not directly or indirectly participate in further development;

(VII) accounting requirements for operating costs and revenue within the operating institution's authorized scope, and the revenue distribution mechanism;

(VIII) data security and personal information protection requirements, and risk monitoring and emergency-response measures;

(IX) evaluation of operating effectiveness, and the renewal or exit mechanism;

(X) liability for breach of contract;

(XI) dispute resolution methods;

(XII) conditions for modification and termination of the agreement;

(XIII) other matters requiring clarification.

**Article 17.** Where a public data resource authorized-operation agreement is terminated or revoked, the operating entity's rights of access to the public data resources and the authorized-operation platform shall be promptly terminated, and work logs shall be retained for not less than three years in accordance with provisions; where the operating period is less than three years, all work logs shall be retained. An exiting operating entity shall cooperate with the data administration department and the sectoral competent departments in properly completing the handover.

**Article 18.** In accordance with the principles of unified administration and intensive efficiency, the authorized-operation platform is organized for construction by the provincial-level data administration department through the tier-one operating entity, and provincial-level authorized-operation work shall in principle be conducted relying on the authorized-operation platform.

The data administration department of each city shall, in accordance with the Province's unified plan, build the module for its own level on the authorized-operation platform. Where there is a genuine need to build a municipal-level platform, it shall be built in a coordinated manner in accordance with the relevant construction requirements and be interconnected with the province-wide platform.

## Chapter IV Data Supply

**Article 19.** Public data resources are subject to unified catalogue administration. The provincial-level data administration department is responsible for organizing the preparation of the public data classification and grading guide and other relevant standards and specifications, establishing a mechanism for the administration and dynamic updating of public data resource catalogues, establishing the province-wide catalogue of public data resources for authorized operation, and disclosing it to the public. The data administration departments of each city and county (city, district) are responsible for organizing the sectoral competent departments at their level in preparing catalogues of public data resources for authorized operation, and for reporting and consolidating them level by level to the provincial-level data administration department.

Sectoral competent departments at all levels shall, in accordance with the relevant requirements for the authorized operation of public data resources, implement the classification and grading of public data, prepare and update their department's catalogue of public data resources for authorized operation, and report and consolidate it to the data administration department at the same level.

The provincial government information administration department is responsible for preparing the province-wide catalogue of government data resources and regularly pushing it to the provincial-level data administration department.

**Article 20.** The data administration department of each city shall, in accordance with the Province's relevant provisions on public data administration, promote the aggregation, governance, and classification and grading of public data at its level, and provide to the authorized-operation platform public data whose use has been authorized and consented to.

Provincial-level sectoral competent departments organize the source governance of their department's public data and, in accordance with the principle of intensification, may, through the government data sharing and exchange platform and other existing information-technology platforms, cooperate with or coordinate the relevant units in providing to the authorized-operation platform public data whose use has been authorized and consented to.

The provincial government information administration department is responsible for providing to the authorized-operation platform, through the government data sharing and exchange platform, public data whose use has been authorized and consented to. Where public data of other regions or departments obtained by way of government data sharing is used for authorized operation, the consent of the unit providing the shared data shall be obtained.

## Chapter V Operation and Implementation

**Article 21.** Party and government organs and public institutions that hold or manage public data resources shall, in accordance with the requirements of the national and provincial measures for the administration of the registration of public data resources, register the public data resources included in the scope of authorized operation. Legal-person organizations authorized to conduct operation activities are encouraged to register the data products and services formed by processing the public data resources authorized to them. Public utilities such as water supply, gas supply, heat supply, electricity supply and public transport are encouraged to register the public data resources they directly hold or manage and the products and services formed therefrom.

**Article 22.** A legal-person organization meeting the following conditions may apply to become a development entity:

(I) sound business and credit standing;

(II) the capacity to develop public data products, services or application scenarios;

(III) mature data management capacity and data security safeguard capacity;

(IV) compliance with other provisions and requirements for the development and utilization of public data resources.

The development entity submits the platform-onboarding application materials as required; the tier-two operating entity verifies them in accordance with unified standards, reports the verification results to the data administration department at the same level for filing, and informs the sectoral competent department.

**Article 23.** Development entities submit applications for application scenarios and data needs on the basis of the authorized-operation platform.

**Article 24.** The authorized operation of public data resources is subject to "one scenario, one application, one review." The data administration department and the sectoral competent department, together with the expert committee and the tier-two operating entity, review the security, compliance, suitability and application effectiveness of the scenario.

**Article 25.** After an application for an application scenario and data needs has been approved, the tier-two operating entity signs a public data resource development and utilization service agreement with the development entity. The agreement shall include, but not be limited to, the rights and obligations of the parties, the application scenario, the data list, security requirements, the method of data retrieval, the period of use, revenue distribution, liability and supervision mechanisms, and confidentiality clauses.

**Article 26.** The tier-one operating entity, in accordance with the review results, the data classification and grading control requirements of the sectoral competent departments and the development and utilization agreement, and following the principle that "raw data does not leave its domain," coordinates the retrieval of data from the relevant sectoral competent departments and carries out primary processing, so as to ensure the security of data use.

**Article 27.** Tier-two operating entities and development entities shall, on the premise of ensuring data security and public security, develop public data products and services on the basis of primary data products by means of "raw data does not leave its domain, and data is usable but not visible." Where personal information or trade secrets are involved, the data shall be used according to the application scenario after genuine, valid and secure authorization has been obtained, with de-sensitization and de-classification properly carried out, so as to safeguard lawful rights and interests.

**Article 28.** Tier-two operating entities shall conduct compliance and security review of the public data products and services developed. Public data products and services shall not be used, or used in disguised form, for application scenarios that have not been reviewed.

**Article 29.** Unless otherwise provided by the State or this Province, subject matter of data trading formed from public data resources shall, in principle, be traded through data trading venues established in accordance with the law.

**Article 30.** The establishment of a contribution-incentive mechanism for public data resources shall be explored, and mechanisms for revenue feedback and technical-service incentives in the authorized operation of public data resources shall be explored and studied, so as to promote positive interaction between market development entities and data-source units.

Public data products and services developed in accordance with laws and regulations may, where used for public governance and public welfare, be used free of charge on a conditional basis; where used for industry development and sectoral development, a public data operation service fee may be charged, subject to government-guided pricing, with the fee standard determined in accordance with the principles of cost compensation and reasonable profit and adjusted dynamically.

**Article 31.** During the operating period, operating entities shall regularly submit reports on the authorized operation of public data resources to the data administration department at their level, inform the sectoral competent departments, and accept supervision and inspection.

## Chapter VI Security Supervision and Legal Liability

**Article 32.** Data administration departments and sectoral competent departments shall establish and improve the security management system for public data under authorized operation, guide and urge operating entities and development entities in accordance with provisions to properly conduct data classification and grading protection, and strictly prevent and control raw public data resources included in the scope of authorized operation from entering the market directly.

**Article 33.** Data administration departments shall, together with the cyberspace administration, public security, state security, secrecy and other departments, establish and improve supervision mechanisms, regularly strengthen, on their own or by entrusting third-party institutions, the supervision and inspection of security and compliance in the operation of the authorized-operation platform, data management, and development and utilization, and urge rectification and implementation. Conduct in violation of laws, regulations, rules and relevant provisions shall be dealt with in accordance with the law.

**Article 34.** The principal persons in charge of tier-one and tier-two operating entities are the persons bearing primary responsibility for the authorized operation of public data resources, and operating entities shall fulfill their primary responsibility for security in accordance with the relevant national and provincial requirements for authorized-operation specifications. Operating entities shall perform the following duties:

(I) establishing and improving a security management system for the authorized operation of public data resources, and strengthening pre-employment training for relevant management and technical personnel;

(II) establishing an audit and supervision system, using blockchain and other technologies to conduct whole-process supervision and retain records, so as to achieve traceability;

(III) accepting supervision and inspection by the relevant competent departments, and truthfully reporting and disclosing the day-to-day status of the authorized operation of public data resources;

(IV) establishing an emergency response plan for security incidents in the authorized operation of public data resources; where security risks arise from data development and utilization conduct, immediately ceasing the relevant conduct, activating the emergency response plan, and promptly reporting to the data administration department.

**Article 35.** Where an operating entity fails to perform its security obligations or uses authorized public data resources in violation of laws and regulations, it shall formulate a rectification plan as required by the data administration department and rectify within a prescribed period.

**Article 36.** Where data administration departments, sectoral competent departments, operating entities and relevant personnel violate national laws, regulations and other relevant provisions, infringe trade secrets, personal privacy or other lawful rights and interests, or cause property losses, they shall bear corresponding legal liability; where a crime is constituted, criminal liability shall be pursued in accordance with the law.

## Chapter VII Supplementary Provisions

**Article 37.** The authorized operation of public data resources held by Party committees at the provincial, municipal and county levels; the authorized operation of public data resources involving organs of central State organs stationed in this Province or their dispatched agencies, and central enterprises based in Shanxi; and the authorized operation of public data resources held by public utilities such as water supply, gas supply, heat supply, electricity supply, telecommunications and public transport, together with the related administration activities, may be implemented with reference to these Measures.

**Article 38.** The data administration department of each city may implement these Measures by reference, or formulate systems relating to the authorized operation of public data resources for its own administrative region, which shall be implemented after being submitted to and deliberated and approved by the people's government at the same level, and filed with the provincial-level data administration department.

**Article 39.** Where the State or this Province provides otherwise on the administration of the authorized operation of public data resources, those provisions shall prevail.

**Article 40.** These Measures shall come into force on September 1, 2025, and shall be valid for two years.
