Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ 097 · METEOROLOGICAL-DATA

The CMA Keeps the Keys: China's First Sectoral Rules for Public Meteorological Data Authorized Operation

Qi Ban Fa [2026] No. 23, dated 25 March 2026: a catalogue as the sole basis of authorization, an identity-tag gate on every trade, catalogued development institutions, three-year operating terms against the national five — and silence on the NDA's Data Property Rights register.

In March 2026 the Office of the China Meteorological Administration issued the Measures for the Administration of the Authorized Operation of Public Meteorological Data (Trial) — 公共气象数据授权运营管理办法(试行), Qi Ban Fa [2026] No. 23 — the first complete sector-specific implementation of the NDRC/NDA authorized-operation framework inside a national vertical system that DCC has recorded. DCC has translated the full 39-article text. The design departs from the national baseline in one consistent direction: control. Operating terms are capped at three years against the national five; operating institutions pass a provincial review, a CMA maturity assessment and the CMA's own 'three majors and one large' deliberation before they may even bid; downstream developers become a third catalogued and supervised tier; nobody but an implementing institution may sub-authorize data, even disguised as cooperative development; and no product trades without a CMA-issued meteorological-data identity tag registered on the CMA's circulation supervision platform. Read against the National Data Administration's Data Property Rights Registration Work Guide — whose public-data clause lets products formed through authorized operation take property-rights registration and circulate as certificated market assets — the meteorological version keeps the development right inside the system: what a market entity gets is a term-limited, contract-based service role inside CMA infrastructure, not a registrable right over what it builds.

Editor’s Note — DCC.

On 25 March 2026 the Office of the China Meteorological Administration (CMA) issued the Measures for the Administration of the Authorized Operation of Public Meteorological Data (Trial) (公共气象数据授权运营管理办法(试行), Qi Ban Fa [2026] No. 23), distributed the next day to every provincial meteorological bureau, directly affiliated unit and internal department, and effective from publication. The document carries the publicity attribute “internal disclosure” (内部公开): it circulates within the meteorological system and among cooperating institutions rather than on the CMA’s public website. Its existence and content are publicly confirmed — the CMA’s official newspaper ran a detailed interpretation by CMA Chief Engineer Pan Jinjun on 29 April 2026. DCC has reviewed the full text and published a complete 39-article translation; this brief is our reading of it.

China’s public-data reform has, until now, been written horizontally: the Central Committee’s Data 20 Articles set the three-rights vocabulary, and the NDRC and the National Data Administration (NDA) built the general machinery — the Implementation Specifications for Authorized Operation of Public Data Resources, the registration measures and the price-formation notice, all of January 2025. What has been missing is the vertical answer: how a national sectoral system that actually holds the data — running from a Beijing headquarters down through provincial branches — would put that machinery to work on its own asset.

The meteorological system is, as far as DCC can find, the first to answer in full, and the answer rewards close reading, because weather data is the rare public-data category with an obvious, global, paying market: energy trading and renewables forecasting, insurance and catastrophe modeling, aviation and shipping, logistics, agritech. Whatever the CMA builds here is a template other data-rich verticals will study.

Three tiers, and a catalogue at every layer

The Measures adopt the national framework’s two roles and add a third. An implementing institution (实施机构) — a unit determined by the CMA or a provincial bureau — holds the data, supplies the development environment, and audits. An operating institution (运营机构) — a vetted legal person — is the market-facing “gatekeeper”: it develops and operates data within the authorized scope and provides data and technical services to the market. Below both sits the new tier: the development institution (开发机构), a legal person that cooperates with an operating institution to build concrete products for end users.

Each tier is catalogued. Article 12 makes the authorized-operation data catalogue “the sole basis” on which implementing institutions authorize and operating institutions operate — the CMA’s Data Resources Department compiles the national catalogue and approves every provincial one. Operating institutions reach the market only through a funnel that ends in a CMA-maintained recommended catalogue of operating institutions (Arts. 13–16). Development institutions get their own recommended catalogue, kept by provincial bureaus, which also “guide, evaluate and supervise” them (Art. 26) — and operating institutions must capability-assess their development partners and periodically audit their data use (Art. 32). The official interpretation describes the catalogue as the system’s switch and pipeline, built to “start small, then expand.” Whichever metaphor one prefers, the legal effect is the same: nothing enters this market that is not on a list the CMA system maintains.

The identity tag: registration as supervision

Article 22 is the operative chokepoint. The CMA runs a meteorological-data identity tag (气象数据身份标识) mechanism — introduced a year earlier in the AI Meteorological Services Measures, which already require AI weather-service providers to source only tagged data. Under the new Measures, implementing institutions, operating institutions and development institutions must each register what they hold — the authorized source data and everything formed through re-development — on the CMA’s meteorological data circulation supervision platform. Then the gate:

Meteorological data products and services without a meteorological-data identity tag are not permitted to be traded. (Art. 22)

Registration in this design is a supervision instrument. It makes every product traceable to its authorization chain, and it makes the CMA’s platform the infrastructure through which the whole meteorological data economy clears — disclosure of re-developed product lists runs through the same platform (Art. 25). That is a coherent regulatory choice, and the security chapter says the quiet part plainly: implementing institutions must “strictly control the direct entry into the market” of undisclosed raw data (Art. 31).

Tighter than the national baseline, at every margin

Set beside the NDRC/NDA Specifications it expressly incorporates — Articles 9 and 18 adopt the national plan-content and agreement-content requirements by reference — the meteorological version tightens every parameter it touches:

  • Term. Operating periods run three years at most, in principle (Art. 18), against the national framework’s five. Renewal is not a formality: the agreement terminates automatically at expiry, the institution re-applies from the start, and a terminated operator must delete the authorized data it retains (Art. 20).
  • Entry. The national Specifications let implementing institutions select operators through plan-based fair competition. The CMA adds a national pre-clearance: provincial preliminary review (30 working days, publicized), a CMA-organized operation-capability maturity assessment (publicized again), deliberation by the CMA under the “three majors and one large” mechanism — and only then eligibility for the bidding the implementing institution runs (Arts. 13–16). Note also who can realistically apply: Art. 13 wants MLPS Level 3 and commercial-cryptography assessment experience, a three-year clean incident record, and platforms already connected to the CMA circulation supervision platform.
  • Downstream. The national Specifications bar the operator from re-developing its own delivered products precisely so that other market entities can — an open downstream, backed by the Specifications’ anti-monopoly clause. The CMA replaces that open downstream with the catalogued development-institution tier described above.
  • Sub-authorization. Article 19 closes the side doors: no one but an implementing institution may pass meteorological data onward — “including in disguised form through cooperative development or entrusted development” — without CMA Data Resources Department approval. Structures that look routine elsewhere in the data economy (a licensed reseller layering sub-licenses, a JV framed as co-development) are, in this system, approval events.

None of this is hidden; the official interpretation presents the design as safety-first sequencing for a trial period. The fault-tolerance clause (Art. 38, echoing the Data 20 Articles’ explore-and-tolerate posture) and the data-exchange encouragement (Art. 28) show a system that intends to open — on its own schedule, through its own pipes.

The instructive contrast: the NDA’s register

The sharpest way to see what the CMA has chosen is to put Article 22 next to the public-data clause of the NDA’s Data Property Rights Registration Work Guide (Trial), issued 1 July 2026. Article 15 of that Guide draws a national map for exactly the situation the CMA regulates: raw public data collected by organs performing statutory duties gets no property-rights registration — but “public data products and services formed through development” after authorized operation may take Data Property Rights registration, once public-data-resource registration is complete. A registered product carries a certificate the Guide makes commercially meaningful: proof of rights in transactions, collateral context in financing, evidence in disputes (Art. 31). That is the rights-confirmation route — the operator’s development work crystallizes into an asset the operator holds and can carry to market. (The final Guide softened this clause from the draft’s “shall” to “may” — see DCC’s draft-to-final diff — a hedge that now looks less like drafting caution and more like deference to sectoral systems deciding for themselves.)

The CMA Measures never mention that route. Registration, in the meteorological system, happens on the CMA’s platform, under the CMA’s rules, for the CMA’s supervisory purposes; the only rights allocation the text provides is contractual — Article 29 tells the parties to divide returns by agreement under the principle of “who invests, who contributes, who benefits.” The door to the NDA register is not closed in words. It simply is not on the CMA’s map, and every practical path to market runs through CMA infrastructure regardless: a product with a national property-rights certificate but no meteorological identity tag still cannot lawfully trade. The interpretation’s mention of future mutual recognition between the meteorological tag and national data-circulation identifiers confirms both that the systems are separate and that bridging them is, for now, an aspiration.

The net position for a market entity is therefore narrower than the national framework advertises. Under the horizontal regime, authorized operation was the mechanism that turned the state’s data holdings into the private sector’s development right — the operating-right debates have always been about how much of that right upstream holders would actually share. The meteorological answer: what a market entity receives is a three-year, contract-based, catalogued service role inside a supervised platform — revocable for non-compliance (Art. 37), deletion-bound at exit (Art. 20), and nowhere convertible into a registered right over what it built. Counsel should not read this as the authorized-operation model failing; it is one pole of the model’s possibility space, occupied deliberately. Provincial implementations of the same framework — Guangdong’s price-management measures, which regulate the operator like a utility but leave the national framework’s structure otherwise intact — show how much variation the model tolerates. Where other data-rich verticals (health, transport, natural resources) land between the poles is now the question that matters.

Money and the meter

The fee design tracks the national price-formation mechanism (NDRC/NDA notice Fa Gai Jia Ge [2025] No. 65). Uses for public governance and public welfare are free; industrial and sectoral development pays a public meteorological data operation service fee under government-guided pricing (Arts. 23–24). Data generated by centrally funded government-informatization projects may not, in principle, carry service fees at all. Operating institutions keep separate books for data-related costs and revenue and accept supervision over them (Art. 32) — pricing power is not among the things the three-year authorization confers.

What overseas counsel should take from this

If your client buys Chinese weather data — for energy trading, catastrophe models, route optimization, agritech — the compliance chain behind the vendor now has a definite shape. Diligence questions write themselves: Is the vendor an operating institution in the CMA’s recommended catalogue, or a development institution cooperating with one? Do the products carry meteorological-data identity tags, registered on the circulation supervision platform? Where in the three-year authorization window does the vendor sit, and what happens to continuity — and to retained data, which the vendor must delete — if renewal fails? An untagged product is not a bargain; after Article 22 it is an unlawful one.

If your client is structuring into the market, Article 19 is the clause to read twice. Cooperative-development and entrusted-development structures — the standard vehicles for foreign participation at arm’s length — are treated as disguised sub-authorization when they move data beyond the authorized chain, and need CMA Data Resources Department sign-off. And the asset your client thinks it is building may not be an asset in the registrable sense: model the position as a term service concession with contractual revenue rights, not as ownership of a data product. The general rule that authorization is an entry ticket, not a compliance waiver, applies here with extra force — the PIPL/DSL stack underneath is untouched, and the CMA adds its own incident-reporting line (15 working days to the Data Resources Department, Art. 35) on top of the generally applicable regimes, not in place of them.

If you advise on China’s data-element market generally, file this as the first complete instance of a sectoral system metabolizing the 2025 national framework — and note the direction of every deviation. The Data 20 Articles promised structural separation of holding, use and operation so that market entities could hold real positions in public-data development. The first vertical to implement has separated the functions — and kept every key on the regulator’s ring.

— Not legal advice.

— Not legal advice.


§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →