The State Council of the People’s Republic of China has officially promulgated the Regulations on the Sharing of Government Affairs Data, a landmark legislative framework designed to modernize the nation’s administrative capabilities through the "Digital Government" initiative. Effective August 1, 2025, these regulations establish a comprehensive legal basis for the collection, classification, and utilization of data across all levels of government. By integrating the core tenets of the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law (PIPL), the new mandate seeks to eliminate "information silos" while maintaining a rigorous focus on national security and personal privacy.
The regulation applies to all government departments and organizations authorized by law to exercise public affairs management. Under the new rules, "government affairs data" is defined as all types of data generated or collected by these entities during the performance of their legal duties, excluding state or work secrets. This marks a significant shift toward viewing data as a primary resource for governance, aiming to improve service efficacy for citizens and legal persons alike.
A Strategic Framework for Digital Governance
The release of these regulations follows years of incremental progress in China’s digital infrastructure. The central government has identified data as a "fifth factor of production," alongside land, labor, capital, and technology. The Regulations on the Sharing of Government Affairs Data serve as the operational manual for this vision, mandating that government data sharing adhere to the leadership of the Communist Party of China and the "overall national security concept."
At the heart of the regulation is the principle of "coordination, unified standards, and law-based sharing." The state aims to build a national integrated government affairs big data system that functions with a rational layout and collaborative management. This system is intended to be secure, reliable, and capable of supporting cross-regional and cross-departmental business collaboration, which has historically been hindered by fragmented technical standards and departmental reluctance to share information.
Chronology of China’s Data Legislation
The path to the 2025 Regulations reflects a decade of rapid legal evolution in the digital sphere:
- November 2016: The National People’s Congress (NPC) passes the Cybersecurity Law, providing the first foundational layer for network security.
- December 2016: The State Council issues the "14th Five-Year" National Informatization Plan, emphasizing the need for data sharing.
- September 2021: The Data Security Law takes effect, establishing the data classification and grading system.
- November 2021: The Personal Information Protection Law (PIPL) is enacted, setting strict limits on how government and private entities handle individual data.
- June 2024: The State Council completes the draft of the Government Affairs Data Sharing Regulations, following extensive consultation with technical experts and administrative departments.
- August 1, 2025: The Regulations officially take effect, superseding previous localized or departmental trial measures.
The Three-Tier Data Classification System
To balance transparency with security, the regulations introduce a mandatory three-tier classification system for all government data:
- Unconditional Sharing: Data that can be accessed by all government departments without restriction. This typically includes public service information, administrative geographic data, and general economic statistics.
- Conditional Sharing: Data that is accessible only to specific departments for designated purposes. This category often involves sensitive demographic information or specialized industry data where oversight is required to prevent misuse.
- Non-sharing: Data that cannot be provided to other departments due to explicit prohibitions in laws or administrative regulations. This is reserved for data that could impact national security or highly sensitive personal privacy if aggregated.
Article 15 explicitly forbids government departments from arbitrarily adding conditions to impede data sharing. If a department classifies data as "non-sharing," it must provide a legal basis and specific reasoning within the official data catalog.
Administrative Efficiency and the "One-Stop" Principle
A primary objective of the new regulations is to reduce the administrative burden on citizens and businesses. Article 19 introduces a "non-repetition" rule: government departments are prohibited from repeatedly collecting data from individuals or organizations if that data can already be obtained through the national sharing system.
This "collect once, use many times" approach is expected to significantly streamline applications for permits, social security benefits, and business licenses. To support this, the regulations establish strict timelines for data requests:
- Review Period: Providing departments must respond to data requests within 10 working days.
- Provision Period: Once a request is approved, the data must be shared within 20 working days.
- Update Period: If laws or departmental duties change, data catalogs must be updated within 10 working days to ensure the information remains current.
Supporting Data and Economic Context
The necessity for these regulations is underscored by the scale of China’s digital transformation. According to the China Internet Network Information Center (CNNIC), as of early 2024, China’s internet user base reached 1.09 billion people. The digital economy now accounts for more than 40% of the nation’s GDP, exceeding 50 trillion yuan (approximately $7 trillion USD).

Furthermore, a 2023 study on administrative efficiency in major Chinese provinces suggested that fragmented data systems resulted in an average 15% delay in cross-departmental processing times. By centralizing the government affairs big data system, the State Council anticipates a 20% to 30% increase in administrative efficiency over the next five years, potentially saving billions in operational costs and indirect economic losses caused by bureaucratic delays.
Security Safeguards and Personal Information Protection
Given the sensitive nature of centralized data, the regulations place heavy emphasis on security. Article 34 establishes the principle of "whoever manages and uses is responsible." This means that the department requesting and using the shared data bears full legal responsibility for any tampering, destruction, or leakage that occurs under its watch.
The regulations mandate:
- Confidentiality Risk Assessments: Required before any data is added to the sharing catalog.
- Traceability: Demand departments must keep records of data usage, storage, and destruction for at least three years.
- Encryption and Technical Barriers: The use of blockchain, artificial intelligence, and cloud computing is encouraged to ensure data integrity and prevent unauthorized access.
Article 37 specifically links these activities to the Personal Information Protection Law, ensuring that the rights of citizens are not bypassed in the name of administrative convenience. Citizens and legal persons are granted the right to file complaints if they believe their data has been mishandled during the sharing process.
Official Responses and Stakeholder Reactions
While official statements from the State Council emphasize "high-quality development," legal scholars and industry analysts have noted the "teeth" included in Chapter VII regarding legal responsibility.
"This is not just a guideline; it is a disciplinary tool," noted a senior analyst at a Beijing-based policy think tank. "For the first time, we see explicit sanctions for ‘departmentalism’—the tendency of agencies to hoard data to maintain their own power. Under Article 39, officials can face disciplinary action for failing to update catalogs or for adding unauthorized conditions to data access."
Provincial leaders in tech hubs like Zhejiang and Guangdong have reportedly welcomed the move, as these regions have already pioneered local versions of data sharing and have faced challenges when attempting to interface with more restrictive central departments.
Broader Impact and Implications
The implementation of the Regulations on the Sharing of Government Affairs Data is expected to have a profound impact on the relationship between the Chinese state and its citizens. By creating a "unified national market" for data, the government is setting a global precedent for how a large-scale digital state operates.
For the private sector, particularly technology companies involved in government informatization projects, the regulations provide a clearer roadmap for compliance. Article 36 clarifies the obligations of third-party contractors, who are strictly forbidden from accessing or retaining government data without explicit authorization.
In the long term, these regulations may serve as a blueprint for international data governance standards, particularly among nations participating in the "Digital Silk Road." However, the success of the initiative will depend on the consistent enforcement of the dispute resolution mechanisms outlined in Article 28 and the ability of the State Council to maintain a balance between the "orderly flow" of data and the "security and controllability" of the national digital infrastructure.
As the August 2025 deadline approaches, government departments at all levels are now tasked with auditing their existing databases and integrating them into the national integrated government affairs big data system, signaling a new era of data-driven governance in the People’s Republic of China.







Cyberviolence Law of the People’s Republic of China (Draft for Comments)
The People’s Republic of China has unveiled a comprehensive draft law specifically designed to combat the growing prevalence of online abuse, harassment, and the spread of malicious misinformation. This legislative…