Six departments: Improve the governance of data circulation security to better promote the market-oriented and value-oriented development of data elements
I'm LongbridgeAI, I can summarize articles.The National Development and Reform Commission and five other departments have released an implementation plan aimed at improving the governance of data circulation security and promoting the marketization and valuation of data elements. By the end of 2027, the plan aims to establish a clear governance system, enhance the compliance circulation mechanism for data, support enterprises in improving their data governance capabilities, appoint chief data officers, and ensure the secure handling and supervision of important data. Encouragement is given to conduct research on data desensitization to facilitate data circulation transactions
According to the Zhitong Finance APP, recently, the National Development and Reform Commission and six other departments issued the "Implementation Plan for Improving Data Flow Security Governance to Better Promote the Marketization and Valuation of Data Elements." It mentions that by the end of 2027, a data flow security governance system that is clear in rules, prosperous in industry, and collaborative among multiple parties will be basically established, with a more improved mechanism for compliant and efficient data flow, significantly enhancing governance effectiveness, providing strong support for the prosperity of the data market and the release of data value.
It also mentions supporting enterprises in enhancing data governance capabilities through methods such as compiling data resource catalogs, analyzing security risks in the flow process, and formulating classified and graded protection measures. It encourages enterprises and institutions to establish Chief Data Officer positions to strengthen data governance and data development and utilization. Data processors should identify and declare important data in accordance with national regulations and accept supervision and inspection by regulatory authorities according to the law. For data identified as important, relevant regions and departments should promptly inform or publicly release this information to data processors.
When data processors provide important data externally, they should take necessary security protection measures in accordance with relevant laws and regulations and the requirements of industry regulatory authorities, effectively safeguarding national security, economic operation, social stability, and public health and safety. Research on data desensitization and other studies is encouraged, and data that has been re-identified as general data according to the classification and grading standards of its industry after desensitization or other technical processing can be circulated and traded as general data.
Original text as follows:
Implementation Plan for Improving Data Flow Security Governance to Better Promote the Marketization and Valuation of Data Elements
The rules for data flow security governance are an important part of the data foundational system. In order to implement the decisions and deployments of the Central Committee of the Communist Party of China and the State Council, and to enforce the "Cybersecurity Law of the People's Republic of China," "Data Security Law of the People's Republic of China," "Personal Information Protection Law of the People's Republic of China," "Regulations on the Security Protection of Critical Information Infrastructure," and "Regulations on the Management of Cyber Data Security," better coordinate development and security, establish and improve the data flow security governance mechanism, enhance data security governance capabilities, promote the compliant and efficient flow and utilization of data elements, and release data value, the following opinions are proposed.
- Overall Requirements
Guided by Xi Jinping's Thought on Socialism with Chinese Characteristics for a New Era, deeply implement the spirit of the 20th National Congress of the Communist Party of China and the second and third plenary sessions of the 20th Central Committee, comprehensively implement the overall national security concept, coordinate high-quality data development and high-level security, adhere to systematic thinking and bottom-line thinking, integrate security throughout the entire process of data supply, flow, and use, implement the national data classification and grading protection system, clarify the security governance rules in data flow, strengthen the application of data flow security technology and industry cultivation, improve the rights protection and responsibility definition mechanism, enhance security governance capabilities, prevent data abuse risks, resolutely safeguard national security, protect personal information and trade secrets, achieve optimal security with minimal costs, promote the benign interaction of high-quality data development and high-level security, fully release data value, and promote data development and utilization. By the end of 2027, a data flow security governance system that is clear in rules, prosperous in industry, and collaborative among multiple parties will be basically established, with a more improved mechanism for compliant and efficient data flow, significantly enhancing governance effectiveness, providing strong support for the prosperity of the data market and the release of data value II. Main Tasks
(1) Clarify the security rules for enterprise data circulation. Support enterprises in enhancing data governance capabilities through compiling data resource catalogs, analyzing security risks in circulation processes, and formulating classification and grading protection measures. Encourage enterprises and institutions to establish Chief Data Officer positions to strengthen data governance and data development and utilization. Data processors should identify and declare important data in accordance with national regulations and accept supervision and inspection by regulatory authorities. For data confirmed as important, relevant regions and departments should promptly inform or publicly release this information to data processors. When data processors provide important data externally, they should take necessary security protection measures in accordance with relevant laws and regulations and industry authority requirements to effectively safeguard national security, economic operation, social stability, and public health and safety. Encourage research on data desensitization, and for data that is re-identified as general data based on classification and grading standards of the respective industry after desensitization or other technical processing, circulation and trading can be conducted as general data.
(2) Strengthen the security management of public data circulation. In the process of sharing government data, data providers should clarify the scope, purpose, and conditions of government data sharing according to the principle of "whoever is in charge, provides, and is responsible," and bear the security management responsibility prior to data provision. Explore the establishment of a data security management risk assessment system for data recipients to ensure orderly sharing of data under secure conditions. Data recipients should bear the security management responsibility after receiving data according to the principle of "whoever handles, uses, manages, and is responsible." Relevant localities and departments conducting authorized operations of public data should clarify the security management responsibilities of authorized public data operation agencies based on relevant requirements, establish and improve data security management systems, take necessary security measures, strengthen the identification and control of associated risks, and protect public data security.
(3) Strengthen the protection of personal data circulation. Improve the mechanism for safeguarding personal data rights and interests. For the circulation of personal data, consent from individuals should be obtained in accordance with laws and regulations or processed anonymously, and consent should not be obtained through coercion, fraud, or misleading methods. Develop relevant standards and specifications for personal information anonymization, clarifying anonymization operation specifications, technical indicators, and circulation environment requirements. Encourage the use of various methods, such as national network identity authentication public services, to strengthen personal information protection. Improve channels for complaints, reports, acceptance, and handling of personal information protection.
(4) Improve the mechanism for defining security responsibilities in data circulation. Data providers should ensure the legality of data sources, and data recipients should strictly use data according to requirements to prevent unauthorized use. Encourage both supply and demand sides to specify their respective rights and responsibilities in data circulation transaction contracts, clearly defining the boundaries of rights and responsibilities. Explore the establishment of data circulation security audit and traceability mechanisms, integrating technologies such as digital watermarking, data fingerprinting, and blockchain to efficiently support evidence collection and accountability in the data circulation process. Support pilot projects in free trade pilot zones (ports) and other locations to explore new governance models around data circulation transaction traceability mechanisms, key scenario security governance standards, and key scenario security responsibility definition mechanisms to improve governance effectiveness.
(5) Strengthen the application of security technologies in data circulation. Support innovation in data circulation security technologies, improve data circulation security standards, and guide enterprises to adopt different security technologies for data circulation according to data classification and grading protection requirements. For general data that does not involve risk issues, encourage enterprises to take necessary security measures for circulation and utilization For data not classified as important but deemed to involve significant operational information by enterprises, data providers and recipients are encouraged to connect and utilize data circulation infrastructure to facilitate the secure flow of data. For important data, under the premise of protecting national security, personal privacy, and ensuring public safety, it is encouraged to achieve data value development in accordance with laws and regulations through methods such as "original data not leaving the domain, data being available but not visible, and data being controllable and measurable."
(6) Enrich the supply of data circulation security services. Promote the data security service market, expand the scale of data security governance services, and innovate data security service formats. Support data security service institutions in strengthening fundamental theoretical research, tackling core technological challenges, and innovating product applications, developing in a direction of scale, specialization, and integration, enhancing the effectiveness of security services, and reducing application costs. Cultivate services such as data circulation security testing and evaluation, and security auditing, and improve market mechanisms conducive to mutual trust among data circulation entities. Enrich services such as data hosting, explore feasible solutions for providing insurance protection for data security, and encourage qualified enterprises to expand data security hosting services aimed at small and medium-sized enterprises.
(7) Prevent the risk of data misuse. Strictly crack down on the illegal acquisition, sale, or provision of data by black and gray industries in accordance with the law, strengthen the protection of sensitive personal information, and restrict the use of personal information beyond the authorized scope. Punish behaviors that utilize data for monopolistic or unfair competition in accordance with laws and regulations, safeguarding the rights and interests of all parties and maintaining fair competition in the market. Under the coordination of the national data security work coordination mechanism, strengthen data security risk monitoring in key industries and sectors, continuously enhance risk analysis, monitoring, and disposal capabilities, prevent systemic and large-scale data security risks, and maintain national security and economic and social stability. Research and improve mechanisms for handling data circulation security incidents or disputes, and enhance the ability to respond to circulation risks. Strengthen departmental collaboration, enhance law enforcement cooperation in data security and personal information protection, promote information sharing, situation reporting, and coordinated cooperation in administrative law enforcement, and improve regulatory effectiveness. Organize and publish typical cases of data circulation security governance, fully leverage their demonstration effect, create an innovative environment of "local innovation, national sharing" and "one enterprise innovation, multiple enterprises reuse," and promote the orderly circulation of data security.
This article is selected from the official website of the National Development and Reform Commission, edited by Chen Xiaoyi of Zhitong Finance.
