---
title: "The CMA Keeps the Keys: China's First Sectoral Rules for Public Meteorological Data Authorized Operation"
author: "DCC Editorial"
published: 2026-08-07T09:00:00.000Z
url: https://datacompliancechina.com/posts/public-meteorological-data-authorized-operation-measures/
description: "In March 2026 the Office of the China Meteorological Administration issued the Measures for the Administration of the Authorized Operation of Public Meteorological Data (Trial) — 公共气象数据授权运营管理办法（试行）, Qi Ban Fa [2026] No. 23 — the first complete sector-specific implementation of the NDRC/NDA authorized-operation framework inside a national vertical system that DCC has recorded. DCC has translated the full 39-article text. The design departs from the national baseline in one consistent direction: control. Operating terms are capped at three years against the national five; operating institutions pass a provincial review, a CMA maturity assessment and the CMA's own 'three majors and one large' deliberation before they may even bid; downstream developers become a third catalogued and supervised tier; nobody but an implementing institution may sub-authorize data, even disguised as cooperative development; and no product trades without a CMA-issued meteorological-data identity tag registered on the CMA's circulation supervision platform. Read against the National Data Administration's Data Property Rights Registration Work Guide — whose public-data clause lets products formed through authorized operation take property-rights registration and circulate as certificated market assets — the meteorological version keeps the development right inside the system: what a market entity gets is a term-limited, contract-based service role inside CMA infrastructure, not a registrable right over what it builds."
tags: ["meteorological-data", "public-data", "authorized-operation", "cma", "nda", "data-property-rights", "data-element-market", "identity-tag", "sectoral-rules", "government-guided-pricing"]
laws_cited: ["public-meteorological-data-authorized-operation-measures", "public-data-authorized-operation-specifications", "data-property-rights-registration-guide-draft", "public-data-registration-interim-measures", "ai-meteorological-services-measures", "data-foundation-system-opinions", "dsl"]
domains: ["data-economy", "data-security"]
original_title: "中国气象局办公室关于印发《公共气象数据授权运营管理办法（试行）》的通知"
original_author: "中国气象局办公室 (Office of the China Meteorological Administration)"
original_publication: "CMA Office document Qi Ban Fa [2026] No. 23 (气办发〔2026〕23号), publicity attribute: internal disclosure (内部公开)"
source_language: "zh"
---

> **Source: Data Compliance China** — https://datacompliancechina.com/posts/public-meteorological-data-authorized-operation-measures/ · China data law, translated and annotated for overseas counsel. Cite as: Data Compliance China, "The CMA Keeps the Keys: China's First Sectoral Rules for Public Meteorological Data Authorized Operation", https://datacompliancechina.com/posts/public-meteorological-data-authorized-operation-measures/
> *Editor's Note — DCC.*
>
> On **25 March 2026** the Office of the China Meteorological Administration
> (CMA) issued the *Measures for the Administration of the Authorized Operation
> of Public Meteorological Data (Trial)* (公共气象数据授权运营管理办法（试行）,
> **Qi Ban Fa [2026] No. 23**), distributed the next day to every provincial
> meteorological bureau, directly affiliated unit and internal department, and
> effective from publication. The document carries the publicity attribute
> **"internal disclosure" (内部公开)**: it circulates within the meteorological
> system and among cooperating institutions rather than on the CMA's public
> website. Its existence and content are publicly confirmed — the CMA's
> official newspaper ran a [detailed interpretation by CMA Chief Engineer Pan
> Jinjun on 29 April 2026](https://www.zgqxb.com.cn/zx/jd/202604/t20260429_7764313.html).
> DCC has reviewed the full text and published a
> [complete 39-article translation](/laws/public-meteorological-data-authorized-operation-measures/);
> this brief is our reading of it.

China's public-data reform has, until now, been written horizontally: the
Central Committee's Data 20 Articles set the three-rights vocabulary, and the
NDRC and the National Data Administration (NDA) built the general machinery —
the [Implementation Specifications for Authorized Operation of Public Data
Resources](/laws/public-data-authorized-operation-specifications/), the
[registration measures](/laws/public-data-registration-interim-measures/) and
the price-formation notice, all of January 2025. What has been missing is the
vertical answer: how a national sectoral system that actually *holds* the data
— running from a Beijing headquarters down through provincial branches — would
put that machinery to work on its own asset.

The meteorological system is, as far as DCC can find, the first to answer in
full, and the answer rewards close reading, because weather data is the rare
public-data category
with an obvious, global, paying market: energy trading and renewables
forecasting, insurance and catastrophe modeling, aviation and shipping,
logistics, agritech. Whatever the CMA builds here is a template other
data-rich verticals will study.

## Three tiers, and a catalogue at every layer

The Measures adopt the national framework's two roles and add a third. An
**implementing institution** (实施机构) — a unit determined by the CMA or a
provincial bureau — holds the data, supplies the development environment, and
audits. An **operating institution** (运营机构) — a vetted legal person — is
the market-facing "gatekeeper": it develops and operates data within the
authorized scope and provides data and technical services to the market. Below
both sits the new tier: the **development institution** (开发机构), a legal
person that cooperates with an operating institution to build concrete products
for end users.

Each tier is catalogued. Article 12 makes the authorized-operation data
catalogue "the **sole basis**" on which implementing institutions authorize and
operating institutions operate — the CMA's Data Resources Department compiles
the national catalogue and approves every provincial one. Operating
institutions reach the market only through a funnel that ends in a
CMA-maintained **recommended catalogue of operating institutions** (Arts.
13–16). Development institutions get their own **recommended catalogue**, kept
by provincial bureaus, which also "guide, evaluate and supervise" them (Art.
26) — and operating institutions must capability-assess their development
partners and periodically audit their data use (Art. 32). The official
interpretation describes the catalogue as the system's switch and pipeline,
built to "start small, then expand." Whichever metaphor one prefers, the legal
effect is the same: nothing enters this market that is not on a list the CMA
system maintains.

## The identity tag: registration as supervision

Article 22 is the operative chokepoint. The CMA runs a **meteorological-data
identity tag** (气象数据身份标识) mechanism — introduced a year earlier in the
[AI Meteorological Services Measures](/laws/ai-meteorological-services-measures/),
which already require AI weather-service providers to source only tagged data.
Under the new Measures, implementing institutions, operating institutions *and*
development institutions must each register what they hold — the authorized
source data and everything formed through re-development — on the CMA's
**meteorological data circulation supervision platform**. Then the gate:

> Meteorological data products and services without a meteorological-data
> identity tag are not permitted to be traded. (Art. 22)

Registration in this design is a supervision instrument. It makes every
product traceable to its authorization chain, and it makes the CMA's platform
the infrastructure through which the whole meteorological data economy clears —
disclosure of re-developed product lists runs through the same platform (Art.
25). That is a coherent regulatory choice, and the security chapter says the
quiet part plainly: implementing institutions must "strictly control the direct
entry into the market" of undisclosed raw data (Art. 31).

## Tighter than the national baseline, at every margin

Set beside the NDRC/NDA Specifications it expressly incorporates — Articles 9
and 18 adopt the national plan-content and agreement-content requirements by
reference — the meteorological version tightens every parameter it touches:

- **Term.** Operating periods run **three years** at most, in principle (Art.
  18), against the national framework's five. Renewal is not a formality: the
  agreement terminates automatically at expiry, the institution re-applies from
  the start, and a terminated operator must delete the authorized data it
  retains (Art. 20).
- **Entry.** The national Specifications let implementing institutions select
  operators through plan-based fair competition. The CMA adds a national
  pre-clearance: provincial preliminary review (30 working days, publicized),
  a CMA-organized **operation-capability maturity assessment** (publicized
  again), deliberation by the CMA under the "three majors and one large"
  mechanism — and only then eligibility for the bidding the implementing
  institution runs (Arts. 13–16). Note also who can realistically apply: Art.
  13 wants MLPS Level 3 and commercial-cryptography assessment experience, a
  three-year clean incident record, and platforms **already connected** to the
  CMA circulation supervision platform.
- **Downstream.** The national Specifications bar the operator from
  re-developing its own delivered products precisely so that *other market
  entities* can — an open downstream, backed by the Specifications'
  anti-monopoly clause. The CMA replaces that open downstream with the
  catalogued development-institution tier described above.
- **Sub-authorization.** Article 19 closes the side doors: no one but an
  implementing institution may pass meteorological data onward — "including in
  disguised form through cooperative development or entrusted development" —
  without CMA Data Resources Department approval. Structures that look routine
  elsewhere in the data economy (a licensed reseller layering sub-licenses, a
  JV framed as co-development) are, in this system, approval events.

None of this is hidden; the official interpretation presents the design as
safety-first sequencing for a trial period. The fault-tolerance clause (Art.
38, echoing the Data 20 Articles' explore-and-tolerate posture) and the
data-exchange encouragement (Art. 28) show a system that intends to open — on
its own schedule, through its own pipes.

## The instructive contrast: the NDA's register

The sharpest way to see what the CMA has chosen is to put Article 22 next to
the public-data clause of the NDA's [Data Property Rights Registration Work
Guide](/laws/data-property-rights-registration-guide-draft/) (Trial), issued 1
July 2026. Article 15 of that Guide draws a national map for exactly the
situation the CMA regulates: raw public data collected by organs performing
statutory duties gets **no** property-rights registration — but "public data
products and services formed through development" after authorized operation
**may** take Data Property Rights registration, once public-data-resource
registration is complete. A registered product carries a certificate the Guide
makes commercially meaningful: proof of rights in transactions, collateral
context in financing, evidence in disputes (Art. 31). That is the
rights-confirmation route — the operator's development work crystallizes into
an asset the operator holds and can carry to market. (The final Guide softened
this clause from the draft's "shall" to "may" — see DCC's
[draft-to-final diff](/posts/data-property-registration-guide-final-draft-diff/)
— a hedge that now looks less like drafting caution and more like deference to
sectoral systems deciding for themselves.)

The CMA Measures never mention that route. Registration, in the meteorological
system, happens on the CMA's platform, under the CMA's rules, for the CMA's
supervisory purposes; the only rights allocation the text provides is
contractual — Article 29 tells the parties to divide returns by agreement under
the principle of "who invests, who contributes, who benefits." The door to the
NDA register is not closed in words. It simply is not on the CMA's map, and
every practical path to market runs through CMA infrastructure regardless: a
product with a national property-rights certificate but no meteorological
identity tag still cannot lawfully trade. The interpretation's mention of
future mutual recognition between the meteorological tag and national
data-circulation identifiers confirms both that the systems are separate and
that bridging them is, for now, an aspiration.

The net position for a market entity is therefore narrower than the national
framework advertises. Under the horizontal regime, authorized operation was
the mechanism that turned the state's data holdings into the private sector's
development right — the [operating-right debates](/posts/data-operation-right-why-upstream-wont-share/)
have always been about how much of that right upstream holders would actually
share. The meteorological answer: what a market entity receives is a
**three-year, contract-based, catalogued service role inside a supervised
platform** — revocable for non-compliance (Art. 37), deletion-bound at exit
(Art. 20), and nowhere convertible into a registered right over what it built.
Counsel should not read this as the authorized-operation model failing; it is
one pole of the model's possibility space, occupied deliberately. Provincial
implementations of the same framework —
[Guangdong's price-management measures](/posts/guangdong-public-data-operation-pricing-measures/),
which regulate the operator like a utility but leave the national framework's
structure otherwise intact — show how much variation the model tolerates.
Where other data-rich verticals (health, transport, natural resources) land
between the poles is now the question that matters.

## Money and the meter

The fee design tracks the national price-formation mechanism (NDRC/NDA notice
Fa Gai Jia Ge [2025] No. 65). Uses for public governance and public welfare
are **free**; industrial and sectoral development pays a **public
meteorological data operation service fee** under **government-guided pricing**
(Arts. 23–24). Data generated by centrally funded government-informatization
projects may not, in principle, carry service fees at all. Operating
institutions keep separate books for data-related costs and revenue and accept
supervision over them (Art. 32) — pricing power is not among the things the
three-year authorization confers.

## What overseas counsel should take from this

**If your client buys Chinese weather data** — for energy trading, catastrophe
models, route optimization, agritech — the compliance chain behind the vendor
now has a definite shape. Diligence questions write themselves: Is the vendor
an operating institution in the CMA's recommended catalogue, or a development
institution cooperating with one? Do the products carry meteorological-data
identity tags, registered on the circulation supervision platform? Where in
the three-year authorization window does the vendor sit, and what happens to
continuity — and to retained data, which the vendor must delete — if renewal
fails? An untagged product is not a bargain; after Article 22 it is an
unlawful one.

**If your client is structuring into the market**, Article 19 is the clause to
read twice. Cooperative-development and entrusted-development structures — the
standard vehicles for foreign participation at arm's length — are treated as
disguised sub-authorization when they move data beyond the authorized chain,
and need CMA Data Resources Department sign-off. And the asset your client
thinks it is building may not be an asset in the registrable sense: model the
position as a term service concession with contractual revenue rights, not as
ownership of a data product. The [general rule that authorization is an entry
ticket, not a compliance waiver](/posts/public-data-authorized-operation-not-a-shield/),
applies here with extra force — the PIPL/DSL stack underneath is untouched,
and the CMA adds its own incident-reporting line (15 working days to the Data
Resources Department, Art. 35) on top of the generally applicable regimes, not
in place of them.

**If you advise on China's data-element market generally**, file this as the
first complete instance of a sectoral system metabolizing the 2025 national
framework — and note the direction of every deviation. The Data 20 Articles
promised structural separation of holding, use and operation so that market
entities could hold real positions in public-data development. The first
vertical to implement has separated the functions — and kept every key on the
regulator's ring.

— Not legal advice.
