---
title_en: "Shenzhen Implementation Guide for the Classification and Grading of Health Data (Trial)"
title_zh: "深圳市卫生健康数据分类分级实施指南（试行）"
abbreviation: "Shenzhen Health Data Classification Guide"
hierarchy: "rule"
issuing_body: "Shenzhen Municipal Health Commission"
adopted_date: 2026-05-01
effective_date: 2026-05-01
status: "effective"
related_laws: ["shenzhen-health-data-management-measures", "healthcare-institutions-data-security-pi-measures", "national-health-medical-big-data-measures", "data-classification-grading-rules", "network-data-security-regulations", "shenzhen-sez-data-regulations", "electronic-medical-records-application-specification", "population-health-information-measures", "dsl", "pipl"]
domains: ["health", "data-security"]
url: https://datacompliancechina.com/laws/shenzhen-health-data-classification-grading-guide/
summary: "Issued by the Shenzhen Municipal Health Commission by notice in May 2026, this 30-article Guide with fourteen annexes is the third layer of a classification-and-grading lineage — the National Health Commission's sector guide, the Guangdong provincial implementation guide, and now a municipal guide — that turns the Data Security Law's classified-and-graded protection duty into a working catalogue for Shenzhen's hospitals and health authorities. It applies to district health authorities and healthcare institutions at every level, and serves as a reference for security assessors. Classification follows WS/T 787-2021 in four tiers: three level-1 classes (basic resources, business resources, thematic resources), 22 level-2 classes, and level-3 and level-4 classes catalogued in Annex 2, whose roughly 580 leaf entries each carry data examples and a recommended minimum level. Grading uses a five-rung ladder — core data, important data, and general data at grades 3, 2 and 1 — with a four-step method (define the object, identify grading factors, analyze affected parties and severity, determine the level) and a decision matrix mapping six affected parties against three degrees of harm. The numeric thresholds are the operative part: core-data candidates include personal information of 10 million or more individuals or sensitive information of 1 million, and 10-million-person derived data affecting national security; important-data candidates include personal information of 1 million or sensitive information of 100,000, population health, diagnosis, rescue-support or drug-trial data on 100,000, and ethnic biometric or medical-resource data on 10,000; sensitive personal information is never below general grade 3 and ordinary personal information never below grade 2. Institutions must inventory all data, file classification lists and important-data and core-data proposals up the chain to the NHC for confirmation, re-grade when population coverage shifts by 20% or 100,000 people, and treat data used in an epidemic response as one grade higher for the duration. Annex 10-1 adapts the eighteen national important-data factors to health, with worked examples from emergency stockpiles to gene-editing protocols and cross-border drug development."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/shenzhen-health-data-classification-grading-guide/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Shenzhen Implementation Guide for the Classification and Grading of Health Data (Trial)", https://datacompliancechina.com/laws/shenzhen-health-data-classification-grading-guide/
> *DCC summary with translated core provisions.* The Guide was circulated
> as a scanned PDF; DCC's page translates the notice, the body articles and
> the short annexes in full below, and summarizes Annex 2 — the four-level
> catalogue — rather than reproducing its several hundred rows. The exact
> day of issue is illegible on the scan ("2026年5月×日"); the notice's
> contact-person details are omitted.

**Promulgated by:** Shenzhen Municipal Health Commission (深圳市卫生健康委员会).  
**Issued by notice in May 2026 to district health authorities and municipal healthcare institutions; effective on issue.**

## Issuing notice

The Commission's notice, addressed to the district health authorities, the Commission's affiliated medical institutions and the Shenzhen University General and South China hospitals, states that the Guide was formulated to implement the National Health Commission's *Guide for the Classification and Grading of Data in the Health Sector (Trial)* and the *Guangdong Province Implementation Guide for the Classification and Grading of Health Data (Trial)*, to unify the rules for classifying health data and grading its handling, and to advance classification and grading across the sector; it is issued for implementation with specific requirements and all units are asked to implement it conscientiously.

## Body of the Guide

**Chapter I — General provisions.** Article 1 grounds the Guide in the unified arrangements of the national data security work coordination mechanism, the Data Security Law, the Regulations on Network Data Security Management, the NHC sector guide and the Guangdong guide. Article 2 defines health data as data relating to health generated in disease prevention and treatment, health management, medical education and research, medical administration and sector administration. Article 3 defines data processors and data processing (collection, storage, use, processing, transmission, provision, disclosure, deletion). Article 4 applies the Guide to the municipal and district health authorities and healthcare institutions at all levels, as a reference for data security assessors, and excludes State secrets.

**Chapter II — Responsibilities.** Work follows the principle that "whoever manages the business manages the data and its security" (Article 5). The municipal health authority plans, guides, assesses and supervises district authorities and municipal institutions, reviews and consolidates the city's inventories and implements controls (Article 6); district authorities do the same within their districts (Article 7); each healthcare institution inventories its data resources, adopts its own detailed rules, classifies and grades, reviews the results, forms a classification-and-grading list, an important-data catalogue and core-data proposals, labels the data, reports the catalogues through the prescribed procedure, and maintains a dynamic-update mechanism (Article 8).

**Chapter III — Classification.** Following WS/T 787-2021 (national health information resource classification and coding), data is classified by resource attribute, business field and business attribute into four tiers (Article 9). Level 1 has three classes; level 2 has 22: basic resources (service scope and subjects, geographic features, laws and regulations, legal entities, staffing and structure, plans and contingency plans, human resources, financial resources, equipment resources, health informatization — ten classes), business resources (public health, hospital medical services, primary-care medical services, medical insurance, drug supply, family planning, comprehensive administration — seven classes) and thematic resources (whole-population data, electronic medical records, electronic health records, medical research data, other data — five classes); levels 3 and 4 are in Annexes 1 and 2 (Article 10). Article 11 prescribes the method: use Annex 3 to fix the level-1 class from the data-resource type, then match level 2–4 classes by data object (basic resources, Annex 2 Table 1), by object, scenario and activity (business resources, Table 2) or by object and integration theme (thematic resources, Table 3).

**Chapter IV — Grading.** Health data is graded from high to low into core data, important data, and general data grades 3, 2 and 1, by importance to economic and social development and by the harm to national security, economic operation, social order, the public interest, organizations' rights and individuals' rights if leaked, tampered with, destroyed or unlawfully obtained, used or shared (Article 12). Article 13 sets four steps: define the grading object (data item, dataset, derived data, cross-sector data); identify grading factors — field, group, region, precision, scale, depth, coverage, importance, security risk (Annex 5); analyze the affected parties (Annex 6) and severity (Annex 7); and determine the level under Annexes 8–10. Notes carry the NHC definitions: core data is important data with high coverage, precision, scale or depth whose unlawful use or sharing could directly affect political security; important data is data of specific fields, groups or regions, or of a certain precision and scale, whose leakage, tampering or destruction could directly endanger national security, economic operation, social stability, or public health and safety — data affecting only an organization or an individual is generally not important data.

*Article 14 — recommended scope of core data (any one condition):* (1) personal information of 10 million or more natural persons, or sensitive personal information of 1 million or more; (2) data covering every individual of an important specific group or specific disease, or group data for a specific period and region; (3) derived data on 10 million or more persons, generated by computation, that profiles its subjects in depth and affects national security; (4) other data assessed by the competent authority.

*Article 15 — recommended scope of important data (any one condition):* (1) personal information of 1 million or more natural persons, or sensitive personal information of 100,000 or more; (2) data on 100,000 persons concerning group health and physiological status, diagnosis and treatment, medical rescue support, or specific drug trials; (3) ethnic-group biometric data or medical-resource data on 10,000 persons; (4) individual data on an important specific group or disease that the processor focuses on, or group data for a specific period and region; (5) other data assessed by the competent authority.

Article 16 makes everything else general data, graded by reference to Annex 2 or by analogy where the catalogue is silent. Article 17 grades cross-sector data by the source sector's rules, treats fused cross-sector data as derived data, applies the "highest and strictest" principle where several factors, parties or degrees are involved, and grades derived data from the original data's level adjusted for depth and other factors.

**Chapter V — Workflow.** Each unit inventories all structured and unstructured resources — database tables, data items, files — recording content, volume, location, retention, processing purpose and systems, and external provision (Article 18); forms its classification list, classification-and-grading list (Annex 12) and important-data catalogue and core-data proposals (Annex 13), reviews and files them level by level (Annex 14), with district authorities and municipal institutions reporting to the municipal authority (Article 19); the municipal authority consolidates and proposes the city's important-data and core-data catalogues for confirmation up to the NHC (Article 20) and relays confirmed results down to districts and institutions (Article 21).

**Chapter VI — Updating and protection.** Rules, lists, catalogues and labels are updated dynamically with policy, business, importance and harm; changes to core or important data are reported level by level to the NHC and implemented only after approval (Article 22). Each unit adopts a full-process, full-lifecycle classified protection strategy — strict management of core data, focused protection of important data, compliant security for personal information, and protection of general data (Article 23).

**Chapter VII — Supervision.** Classification and grading is incorporated into each unit's data security system with a responsible person and management body (Article 24); health authorities inspect processors' implementation (Article 25), review submitted lists and catalogues and return failed submissions with reasons and a deadline (Article 26), may interview processors presenting significant risks and require rectification (Article 27), and build evaluation mechanisms that feed institutional performance appraisal (Article 28). Failure to implement classification and grading draws an order to rectify within a deadline and, on default, handling under the Data Security Law, the PIPL, the Shenzhen Special Economic Zone Data Regulations and the Shenzhen medical and health regulations (Article 29). The Guide takes effect on issue and is interpreted and revised by the Commission (Article 30).

## Annexes

**Annex 1 — classification structure (levels 1–3).** Lists the three level-1 classes, 22 level-2 classes and their level-3 classes — for example, under public health: disease control, health supervision and enforcement, maternal and child health, health education, emergency medical care, blood management, occupational health; under hospital medical services: clinical services, medical administration, operations management; under drug supply: fourteen classes from basic database management to high-value consumables procurement; under thematic resources: whole-population information; EMR business operations, clinical diagnosis and treatment, electronic medical records, basic dictionaries; health-archive basic datasets, disease management, disease control, child and women's health; research project, funding, subject, achievement and dataset management; and sixteen "other" databases including EMR and health-record summaries, population information sharing, telemedicine, internet-plus healthcare, family-doctor contracting, supervision, personal disease archives, health hazard factors, vaccine and cold-chain management, and service-quality evaluation.

**Annex 2 — classification to level 4 with minimum levels (summarized).** Three tables (basic, business and thematic resources) extend every level-3 class into level-4 classes, each with data examples and a recommended minimum level; entries marked with an asterisk differ from the Guangdong provincial table. DCC's OCR of the scan counts roughly 580 leaf entries with a minimum-level recommendation. The pattern visible in the basic-resources table is characteristic: patient, healthy-person, medical-staff and administrator basic information (name, date of birth, ID number, marital status, date of death) and contact information (phone, email, home address) are set at general grade 3; work and education information at grade 2; and practitioner qualification information (practice location, category, scope, registration status) at grade 1. The full catalogue is available only in the Chinese original.

**Annex 3 — mapping data resources to level-1 classes.** Maps system and table types to classes: base tables with domain-wide unique keys and dimension tables are basic resources; OLTP transaction tables and simple summaries are business resources; complex cross-business summaries and OLAP detail, mid-level, mart and wide tables are thematic resources; ODS staging tables take the class of their source.

**Annex 4 — grading steps.** A flow from defining the object, through parallel analysis of impact on national security, social order and the public interest, on healthcare institutions, and on patients, to a consolidated assessment and level determination.

**Annex 5 — grading factors.** Twelve factors with illustrative considerations: field (industry, business line, activity, process, content), group (populations, organizations, systems, resources, components, projects, infrastructure), region (administrative division, specific area, geography, important places, cyberspace), precision (numeric, spatial, temporal, process, image, remote-sensing, instrument), scale (storage volume, valuation, capacity, throughput, reserves, transactions, group size), depth (economic and industry analysis, feature analysis, tracks, relationships, history, supply chains), coverage (by field, group, region, time), importance (to the digital economy, digital government, culture, society, ecology, national security), security risk (leakage, tampering, destruction, unlawful acquisition, use and sharing), timeliness, application scenario (research, insurance claims, drug development, clinical care) and processing method (aggregation, cleansing, sharing, encryption). Field, group, region and importance are qualitative; precision, scale and coverage quantitative; depth applies to derived data.

**Annex 6 — affected parties.** Detailed considerations for six parties: national security (political, territorial, economic, scientific and export-control, cultural, governance, ecological, military, cyberspace and CII, nuclear, biosecurity and human genetic resources, space, polar and deep-sea, overseas interests), economic operation, social order, the public interest, organizations' rights, and individuals' rights.

**Annex 7 — severity by party.** For each party, the considerations that mark harm as especially serious, serious or ordinary, mapped to the resulting level — for example, especially serious harm to the public interest (paralysis of public-resource supply across most of a province affecting 10 million or more, especially major cybersecurity or work-safety incidents, Level I public-health emergencies) yields core data; serious harm (Level II public-health emergencies, supply interruptions affecting 1 million or more) yields important data; harm to organizations or individuals, however severe, yields general data at grade 3, 2 or 1.

**Annex 8 — level-determination rules.** Core data: especially serious or serious harm to national security, or especially serious harm to economic operation, social order or the public interest, high-coverage or high-precision important data directly affecting political security, or data confirmed by the authorities. Important data: ordinary harm to national security, serious harm to economic operation, social order or the public interest, data of specific fields, groups or regions, or of a certain precision, scale, depth or importance, bearing directly on national security, economic operation, social stability or public health, or data confirmed by sector regulators. General data: grade 1 for ordinary or no harm to individuals or organizations, grade 2 for serious harm, grade 3 for especially serious harm to individuals or organizations or ordinary harm to economic operation, social order or the public interest. Minimum-level floors: sensitive personal information not below grade 3 and ordinary personal information not below grade 2; public data barred from sharing not below grade 3 and conditionally shareable public data not below grade 2; data meeting important- or core-data conditions but not yet confirmed by the superior authority is treated accordingly.

**Annex 9 — decision matrix.** Rows for national security, economic operation, social order, the public interest, and organizations' and individuals' rights against columns for especially serious, serious and ordinary harm, yielding core data for the top-left cells, important data for the middle band, and general grades 3, 2 and 1 for the rest; sourced to GB/T 43697-2024 and the Guangdong guide.

**Annex 10 — consolidated determination.** Apply the rules; identify important data under Annex 10-1; apply the highest-and-strictest principle; default a dataset to the highest level of its items while considering scale effects; grade general data further by Annex 2; grade derived data by Annex 10-2; grade cross-sector data by source-sector rules or as derived data; and update dynamically per Annex 11. *Annex 10-1* adapts the eighteen national important-data identification factors to health with a table of examples across ten fields — medical rescue support (emergency rosters, strategic drug stockpiles, command-center logs), sensitive-facility security (national medical center drawings, vaccine-plant process diagrams, hospital coordinates), core medical technology and controlled items (CRISPR optimization protocols, CAR-T clinical data, the medical entries in the technology export-control catalogue), medical CII (EMR system availability, server inventories, unpatched software lists, topology diagrams), environmental health monitoring, nuclear medicine, biosecurity core data (genetic-engineering vaccine routes, ethnic physical-anthropology datasets, population-specific SNP databases, infectious-disease reports, P3 laboratory certificates, pathogen genomes), group health and disease control (fitness surveys, prevalence reports, vaccine adverse-reaction rates, drug assay reports), strategic-frontier health data (astronaut, polar and deep-sea medical records), AI applications (diagnostic model parameters, EMR AI output databases), and public-health data that could cause panic, affect the economy or disrupt social order. *Annex 10-2* grades derived data — de-identified, labeled, statistical and fused — relative to the original: de-identified data may be graded lower, labeled and statistical data lower or higher, and fused data higher where aggregation deepens sensitivity or lower where identifiability falls.

**Annex 11 — dynamic-update triggers.** Re-grade when the number of natural persons covered changes by more than 20% or by 100,000 or more since the last grading; raise the grade by one level immediately while data is used in a major infectious-disease or unexplained-illness emergency response, until the event ends; and re-grade on changes in timeliness, scenario or processing, on merger or partial merger of datasets, on fusion into new categories, on de-identification or anonymization, after a security incident, on regulatory instruction, and for special diseases such as infectious diseases and HIV. A table of examples shows upgrades (individual to group health data; disease-specific data reaching national precision thresholds; linking medical with disease-control data; linking diagnosis with cost data into insurance-payment data; data used in a major public-health emergency; health data for cross-border joint drug development) and downgrades (statistics once published in the health yearbook; dermatology facial images after de-identification; identified medical data after anonymization confirmed by a qualified third party under GB/T 37964-2019).

**Annexes 12–14 — templates and flow.** A classification-and-grading summary form (categories, de-duplicated volume, grading basis by affected party, approval status, security status, self-assessment date), an important-data identification summary form (data basics, responsible entity, processing, carrier, MLPS level, CII status, core-data recommendation, cross-border transfer, risk assessment), with filing notes defining cross-entity flow and foreign-related data, and a flowchart showing institutions reporting to district or municipal authorities, review and return, consolidation, and confirmation of important- and core-data catalogues by the provincial and national commissions.

## How it fits the regime

The Guide is the municipal end of the chain that the [Data Security Law](/laws/dsl/) and the [Network Data Security Regulations](/laws/network-data-security-regulations/) set in motion: national coordination mechanism, sector guide from the NHC, provincial guide from Guangdong, municipal guide from Shenzhen, and finally each hospital's own detailed rules and catalogue. It applies the method of [GB/T 43697-2024](/laws/data-classification-grading-rules/) — factors, affected parties, severity, matrix — but with a five-rung ladder that splits general data into three grades, matching the approach in the transport and financial sector guides. Its practical weight for overseas institutions lies in three places: the numeric thresholds in Articles 14–15 and Annex 8, which decide when a hospital's or research partner's dataset becomes important or core data and so subject to catalogue filing, annual risk assessment and export restrictions; the Annex 11 rule that cross-border joint drug development elevates the health data involved; and the identification examples in Annex 10-1, which name gene-editing protocols, CAR-T trial data, population SNP databases and ethnic anthropometric datasets as important data — the categories most often at issue in international research collaborations under the [Human Genetic Resources Regulation](/laws/hgr-regulation/). It operates alongside the [Shenzhen Health Data Management Measures](/laws/shenzhen-health-data-management-measures/) and the NHC's [healthcare-institution data security measures](/laws/healthcare-institutions-data-security-pi-measures/).
