---
title_en: "Zhejiang Province Administrative Measures for the Authorized Operation of Public Data Resources"
title_zh: "浙江省公共数据资源授权运营管理办法"
abbreviation: "Zhejiang Public Data Authorized Operation Measures"
hierarchy: "rule"
issuing_body: "Zhejiang Provincial People's Government (issued by its General Office)"
adopted_date: 2025-09-01
effective_date: 2025-10-01
status: "effective"
related_laws: ["public-data-authorized-operation-specifications", "public-data-registration-interim-measures", "public-data-development-utilization-opinions", "public-data-authorized-operation-pricing-notice", "shanghai-public-data-authorized-operation-measures", "dsl"]
domains: ["data-economy", "data-security"]
url: https://datacompliancechina.com/laws/zhejiang-public-data-authorized-operation-measures/
summary: "Issued by the General Office of the Zhejiang Provincial People's Government on September 1, 2025 as 浙政办发〔2025〕30号 and effective October 1, 2025, these Measures replace Zhejiang's 2023 trial rules and serve as the province's overall implementation plan under the NDRC/NDA Implementation Specifications. Zhejiang's model is distinctive in three respects: it adopts scenario-based authorization (依场景授权) as the default rather than whole-package authorization, it makes the data administration authority at each level the implementing institution, and it builds the whole regime around an 'authorized-operation domain' (授权运营域) — a secure enclave on the province's integrated intelligent public data platform or a trusted data space, from which raw data may not leave and through which every product must pass an exit review. Operating institutions are chosen through an open scenario-application and review process rather than bidding, agreements generally run no more than three years (shorter than the national five-year cap), data-source units must review data requests within five working days, and operators price their products under a legality, universality and reasonable-return standard while implementing institutions may charge for cloud, computing and technical services. Overseas counsel advising data-product ventures in Zhejiang should read this alongside the national Specifications and the Zhejiang Public Data Regulations."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/zhejiang-public-data-authorized-operation-measures/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Zhejiang Province Administrative Measures for the Authorized Operation of Public Data Resources", https://datacompliancechina.com/laws/zhejiang-public-data-authorized-operation-measures/
**Promulgated by:** Zhejiang Provincial People's Government (notice issued by the General Office of the Zhejiang Provincial People's Government).  
**Document No.:** 浙政办发〔2025〕30号 (Zhe Zheng Ban Fa [2025] No. 30).  
**Issued September 1, 2025. Effective October 1, 2025.**

> *Translation note — DCC. Translated in full from the official Chinese text
> of the issuing notice and the Measures (local normative document, 效力级别:
> 地方规范性文件). The Measures are drafted in numbered parts and items rather
> than articles; DCC preserves the source numbering. Terminology follows DCC's
> bilingual glossary and is aligned with the [Implementation Specifications for
> Authorized Operation of Public Data Resources (Trial)](/laws/public-data-authorized-operation-specifications/)
> and the [Public Data Resource Registration Interim Measures](/laws/public-data-registration-interim-measures/).*

---

## Notice of the General Office of the Zhejiang Provincial People's Government on Issuing the Zhejiang Province Administrative Measures for the Authorized Operation of Public Data Resources

To the people's governments of all municipalities and counties (county-level cities and districts), and all units directly under the Provincial Government:

The *Zhejiang Province Administrative Measures for the Authorized Operation of Public Data Resources* have been approved by the Provincial Government and are hereby issued to you. Please implement them conscientiously in light of actual conditions.

General Office of the Zhejiang Provincial People's Government  
September 1, 2025

---

## Zhejiang Province Administrative Measures for the Authorized Operation of Public Data Resources

These Measures are formulated in accordance with the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, the Personal Information Protection Law of the People's Republic of China, the Zhejiang Province Public Data Regulations and other relevant laws and regulations, and with the requirements of the National Development and Reform Commission and National Data Administration documents on the implementation specifications for the authorized operation of public data resources, in light of the actual circumstances of this Province, in order to regulate the administration of the authorized operation of public data resources, accelerate the orderly development and utilization of public data resources, and cultivate the data factor market.

## I. General Provisions

**(1) Overall requirements.** Implement the State's overall deployment on accelerating the development and utilization of public data resources; coordinate development and security; balance efficiency and fairness; follow the principles of legality and compliance, fairness and impartiality, public-interest priority, reasonable returns, and security and controllability; and carry out the authorized operation of public data resources in accordance with the requirement that "raw data does not leave the domain, and data is usable but not visible" (原始数据不出域、数据可用不可见). Strengthen the pull of scenario demand, empower economic development, stimulate social vitality, catalyze technological innovation, produce a batch of landmark major results, accelerate the building of an innovative Zhejiang, and create a highland for the innovative development of artificial intelligence and a Zhejiang model of Digital China.

**(2) Scope of application.** These Measures apply to activities for the authorized operation of public data resources within the administrative region of this Province.

**(3) Meaning of terms.**

"Authorized operation of public data resources" means the act by which a people's government at or above the county level, on the premise of ensuring data security and in accordance with laws, regulations and relevant requirements, authorizes a qualified operating institution to process public data resources, develop them into data products and services, and provide them to society.

"Implementing institution" (实施机构) means the unit specifically responsible for organizing and carrying out authorized-operation activities. The data administration authority at each level performs the duties of implementing institution within its administrative region.

"Operating institution" (运营机构) means a legal-person organization that has obtained authorization through standardized procedures and develops and operates public data resources within the scope of authorization.

"Authorized-operation domain" (授权运营域) means a specific secure domain, built on the integrated intelligent public data platform or a trusted data space, that provides operating institutions with services for the processing of public data under authorized operation, and that has functions such as secure de-sensitization, access control, algorithm modeling, regulatory tracing, interface generation, and sealing and destruction.

"Data products and services" means data sets, data models, data interfaces, data services, data reports, business services and the like formed by processing public data resources.

## II. Division of Responsibilities

**(1) Implementing institutions.** Responsible for organizing the specific implementation of the authorized operation of public data resources in their region; preparing implementation plans for authorized-operation scenarios; building and managing the authorized-operation domain of their region; establishing and improving management systems, standards and specifications, and working mechanisms; selecting, managing and evaluating operating institutions in accordance with laws and regulations; supervising the performance of authorized-operation agreements; and strengthening whole-process security control.

**(2) Operating institutions.** Responsible for developing and operating public data resources within the scope of authorization; developing data products and services within the authorized-operation domain; bearing primary responsibility for data security; accepting the supervision of the implementing institution; reporting the operational results of scenarios as required by the implementing institution; and advancing market-oriented operation.

**(3) Public administration and service institutions.** Responsible for the governance, application review, security management and other work related to authorized operation for the public data resources of their department, system and field, and for ensuring the timeliness, accuracy and completeness of data. They shall collaboratively advance scenario construction in their field and participate in the management of data-application effectiveness organized by the implementing institution.

**(4) Coordination and collaboration.** The data administration authority shall, together with the cyberspace administration, development and reform, economy and information technology, public security, state security, judicial administration, finance, market regulation and other relevant departments, strengthen coordination and collaboration in the authorized operation of public data resources according to the division of responsibilities.

## III. Basic Conditions for Operating Institutions

**(1) Basic requirements.** Sound business condition; possession of the professional qualifications, professional personnel, technical accumulation and production and service capacity required in the field of authorized operation; and satisfaction of the corresponding credit conditions, not having been listed by "Credit China", "Credit Zhejiang" or the like in the list of abnormal business operations (activities) or the list of seriously untrustworthy entities.

**(2) Technical and security requirements.**

1. Designate a person responsible for data security and a management department, and establish internal management and security-safeguard systems for the authorized operation of public data resources.

2. Possess mature data management and security-safeguard capabilities, and have practical experience in the development and operation of related systems.

3. No major cybersecurity or data security incident within the past three years.

**(3) Application-scenario requirements.**

1. The application scenario for authorized operation has major economic value or social value.

2. The application scenario is highly implementable, with clear objectives and plans within the authorized-operation period, and is capable of achieving the expected results.

3. Public data resources are applied for and used according to the application scenario.

**(4) Specific requirements for key fields.** To be studied and determined by the implementing institution together with the competent department of the relevant field.

## IV. Method of Authorization

**(1) Authorization model.** The authorization model is scenario-based authorization (依场景授权). Each locality and department may, in light of actual circumstances, explore scenario-based whole-package authorization and field-by-field authorization.

**(2) Requirements for the construction and management of authorized-operation domains.** Provincial- and municipal-level implementing institutions shall organize the construction of authorized-operation domains; counties (county-level cities and districts) shall carry out authorized-operation work relying on the municipal-level authorized-operation domain and, where genuinely necessary, may build a separate authorized-operation domain. The provincial data administration authority is responsible for formulating the technical standards and management specifications for authorized-operation domains built on the integrated intelligent public data platform or trusted data spaces, and for organizing acceptance inspections. The data administration authority at each level shall establish the institutional rules and the operation and maintenance mechanism for the authorized-operation domain at its level; strengthen operation and maintenance capabilities such as behavior auditing, online filing and abnormality handling in the authorized-operation domain; implement whole-process security supervision and risk early warning covering operating institutions, personnel, and data development and utilization; and carry out security patrol inspections of the authorized-operation domain at its level. Municipal- and county-level data administration authorities shall promptly report relevant supervisory data to the provincial data administration authority and accept the security guidance and supervision of the provincial data administration authority.

**(3) Scenario implementation requirements.**

1. *Scenario application.* The implementing institution shall, on the principle of fair competition, publish an announcement on the conduct of authorized operation, specifying the application conditions and evaluation criteria. Applicants for authorized operation shall submit scenario application proposals to the implementing institution within the prescribed time, including the authorized-operation application form, financial and accounting reports, a data security undertaking, a security risk self-assessment report and other materials.

2. *Review of application proposals.* The implementing institution shall organize the argumentation of scenario application proposals, assessing and comparing the economic value, social value and business model of the scenarios, as well as their feasibility, compliance and security, and shall, according to the review results, determine the scenario application proposals selected.

3. *Review by data-source units.* The implementing institution shall submit the public-data requirements in the scenario application proposal to the data-source unit (数源单位) for review of their reasonableness and necessity. The data-source unit shall uphold the principle of fairness and impartiality and complete the review within five working days. Where the review period needs to be extended because the national sectoral competent authority provides otherwise or for similar reasons, the data-source unit shall report to the implementing institution at the same level for consent, and the extension shall not exceed five working days.

4. *Preparation of implementation plans.* The implementing institution shall guide the applicant for authorized operation in refining the scenario application proposal into a scenario implementation plan, which takes effect after deliberation under the implementing institution's "three majors and one large" (三重一大) decision-making mechanism and approval through multi-department joint review.

5. *Execution, modification and termination of agreements.*

The content of the authorized-operation agreement shall be determined according to the scenario implementation plan, and shall include rights and obligations, the scope of authorized operation, the operating period, the method of calculating reasonable returns, data security requirements, disposal of assets upon expiry of the period, the exit mechanism, liability for breach and other matters. Authorized-operation agreements shall be executed in accordance with the requirements of relevant laws, regulations and national policy documents, and the authorized-operation period shall generally not exceed three years. Municipal- and county-level authorized-operation agreements shall be filed with the data administration authority at the next higher level.

Where, after the authorized-operation agreement is executed, the operating institution proposes a change to its public-data requirements, it shall provide supplementary application materials as required and, after review by the data-source unit, a supplementary agreement shall be executed in accordance with the requirements of relevant laws, regulations and policy documents. Where, upon expiry of the authorized-operation agreement, authorized operation is to continue under the original scenario, the operating institution shall submit an application for renewal of the agreement and, after the implementing institution organizes a review and approves it, the agreement shall be renewed in accordance with the requirements of relevant laws, regulations and policy documents.

Where an authorized-operation agreement is terminated or revoked, the implementing institution shall promptly close the operating institution's access rights to the authorized-operation domain, delete the relevant data within the authorized-operation domain, and retain network logs for not less than three years; the operating institution shall cease using the data products and services derived from the original public data resources.

6. *Public disclosure.* The implementing institution shall, through the data open website and other official channels, disclose to society the circumstances of authorized-operation scenarios, including the authorized parties, content, scope and time limits, and accept social supervision.

7. *Development of data products and services.* The operating institution shall process public data resources relying on the authorized-operation domain and form data products and services.

8. *Exit review of data products and services.* The implementing institution shall organize the exit review (出域审核) of data products and services, covering information consistency, de-sensitization of sensitive data, and the informed consent of specific subjects, so as to ensure that raw data does not leave the domain.

## V. Rights and Conduct Norms of Operating Institutions

**(1)** Where an operating institution discovers public-data quality problems in the course of data processing or service provision, it may submit data-governance requirements to the implementing institution. The implementing institution shall urge the data-source unit to complete data governance within the prescribed period and shall, together with the relevant units, provide the necessary support.

**(2)** Operating institutions shall carry out public-data operation in accordance with laws and regulations; shall not leak, steal, tamper with, damage, lose or improperly use public data resources; and shall not provide the public data resources under authorized operation to third parties. They shall regularly report on the storage, processing, analysis and utilization, security management and market operation of data products and services, and accept the supervision and inspection of the implementing institution regarding the business and information systems involved in authorized operation, data usage, security-safeguard capability and the like. They shall improve public-data security systems and establish sound and efficient technical protection and operation-management systems to ensure public-data security. Public data involving personal information, trade secrets or confidential business information shall be obtained only after de-sensitization and de-classification treatment reaching the standard of anonymization, or after the specific natural person, legal person or unincorporated organization to which the data relates has lawfully given authorization and consent.

**(3)** The processing of public data by operating institutions shall meet the following requirements:

1. All personnel of the operating institution participating in data processing must undergo real-name authentication, filing and vetting, and sign confidentiality agreements; their operations shall be recorded and reviewable.

2. Subject to review and approval by the implementing institution, the operating institution may import social data lawfully obtained in accordance with regulations into the authorized-operation domain for integrated computation with public data resources.

3. Data products and services formed by the operating institution shall be subject to review by the implementing institution to ensure that raw data cannot be reconstructed from them.

**(4)** Operating institutions shall determine the prices of data products and services in adherence to the principles of legality and compliance, universal benefit and fairness, and reasonable returns.

**(5)** Operating institutions shall publish the list of public data products and services, regularly disclose to society the use of public data resources, and accept social supervision.

**(6)** Operating institutions shall establish public-data operation archives and, in accordance with relevant national and provincial provisions, completely collect and preserve records of the entire public-data operation process.

## VI. Data Security and Supervision

**(1)** The authorized operation of public data resources adheres to the principle of coordinating development and security; in accordance with the requirements of public-data classification and grading, it strengthens whole-lifecycle security and lawful-use management of public data, ensuring that data sources are traceable, data destinations are ascertainable, conduct leaves a record, and responsibility can be pursued.

**(2)** The security of the authorized operation of public data resources adheres to the principle that "whoever operates is responsible, and whoever uses is responsible." The implementing institution shall strengthen public-data security and supervision, and the principal responsible person of the operating institution is the first person responsible for the security of the public data under operation.

**(3)** The data administration authority shall, together with the cyberspace administration, cryptography administration, secrecy administration, public security, state security and other departments, according to their respective responsibilities, carry out security supervision of authorized operation, formulate emergency response plans, organize emergency drills, and carry out emergency handling.

**(4)** The development and reform, economy and information technology, finance, market regulation and other departments shall, according to their respective responsibilities, carry out the supervision and administration of the circulation and trading of data products and services, and improve the market-oriented operation and management system for data products and services.

**(5)** The data administration authority shall properly archive all categories of materials relating to authorized-operation work and handle the filing of scenario implementation plans, authorized-operation agreements and the like.

**(6)** Implementing institutions, operating institutions, and public administration and service institutions shall, in accordance with the relevant national and provincial requirements for the registration administration of public data resources, carry out the registration of public data resources and of public data products and services.

**(7)** The competent intellectual property department shall, together with the development and reform, economy and information technology, judicial administration and other departments, establish a data intellectual property protection system and advance the protection and utilization of data intellectual property.

**(8)** The implementing institution shall lead, or entrust a third-party institution to conduct, an annual assessment of the authorized-operation activities of operating institutions at its level, implement dynamic management of operating institutions, and use the assessment results as an important basis for any renewed application for authorized operation.

**(9)** Implementing institutions in each locality are encouraged to explore charging mechanisms for the cloud resources, computing power, technical services, data products and services and the like used by operating institutions in the course of authorized operation.

**(10)** Where an operating institution violates the relevant laws and regulations on cybersecurity, data security, personal information protection and the like, the cyberspace administration, public security and other relevant departments shall investigate and punish it in accordance with the law according to their responsibilities, and the relevant adverse information shall be recorded in its credit archives in accordance with the law.

## VII. Supplementary Provisions

**(1)** These Measures serve as the overall implementation plan for the authorized operation of public data resources in this Province. All municipalities and counties (county-level cities and districts) shall carry out the authorized operation of public data resources in accordance with these Measures.

**(2)** These Measures shall come into force on October 1, 2025. The *Notice of the General Office of the Zhejiang Provincial People's Government on Issuing the Zhejiang Province Administrative Measures for the Authorized Operation of Public Data (Trial)* (浙政办发〔2023〕44号) is repealed at the same time. Where the State or the Province issues new provisions on the administration of the authorized operation of public data resources, those provisions shall prevail.
