On the Institutional Construction of Authorized Operation of Public Data
China attaches great importance to the development of the digital economy. Documents such as the "Opinions of the CPC Central Committee and the State Council on Establishing a More Perfect System and Mechanism for Market-Based Allocation of Production Factors" and the "14th Five-Year Plan for National Economic and Social Development of the People’s Republic of China and the Visionary Goals for 2035" explicitly call for fostering a data-factor market, building new advantages in the digital economy, establishing and improving a national public data resource system, launching pilot programs for authorized operation of government data, and encouraging third parties to deepen their exploration and utilization of public data. Among the vast array of data resources, public data stands out as particularly massive, brimming with enormous economic and social value. Authorized operation of public data represents an important pathway for deeply tapping into and realizing the latent value of public data resources. At the same time, authorized operation of public data plays a leading and driving role in promoting the cultivation and development of the data-factor market, capable of spurring the emergence of more new models, new formats, and new competitive advantages in the digital economy. Currently, several provinces and cities across China have already embarked on practical explorations related to the authorized operation of public data and have made promising attempts at institutional design. However, authorized operation of public data remains a completely new undertaking, and there are still some ambiguities in both legal theory, specific practice, and institutional design. Such explorations are being carried out under conditions where the foundational institutional framework for allocating rights and interests in public data is still lacking; the scope and boundaries of the objects of these rights remain unclear; the content of these rights is not well-defined; and the specific institutional designs for authorized operation of public data are still incomplete. As a result, in practice, the various stakeholders involved in authorized operation of public data lack effective incentive mechanisms, which in turn hinders the deeper utilization of public data and the cultivation of the data-factor market. This has become a core issue that urgently needs to be addressed by local governments as they pursue the authorized operation of public data.
I. The Underlying Logic Behind the Establishment of a Public Data Authorization and Operation System
Any institutional framework must be underpinned by a fundamental underlying logic. What, then, are the foundational principles and logical basis for constructing a system of authorized operation for public data? Should the institutional framework be built from the perspective of government’s management powers, obligations, and responsibilities regarding public data, or should it instead proceed from the standpoint of data resource users, analyzing their rights as utilization entities and then developing the institutional framework accordingly? Currently, there are differing views within academia on this issue. The inadequacy of theoretical research has become a “weak link” in both the institutional development and practical implementation in this field, and it also hinders the specific elaboration and refinement of rules governing the open access and utilization of public data. Therefore, the analysis of the underlying logic behind the construction of a public data authorization and operation system should be grounded in the practical experience of market-oriented operations of public data resources.
(1) An Examination of Public Data Authorization and Operation Practices
Examining current practices in the authorized operation of public data, China mainly features two models: one is a vertically oriented, industry-led model, in which the government regulatory authority of a particular industry or... Enterprises, institutions, and organizations that provide public services Lead and carry out various activities within the industry, including the collection, management, operation, and provision of public data. The government’s competent regulatory authority or... Public-service enterprises and institutions that provide public services As the entity responsible for data collection, control, and centralized management, we are building a public data management platform. We undertake data processing tasks such as data collection, data storage, and data processing, and provide data services to government departments and other social entities. Meanwhile, the government’s data security regulatory authorities fulfill their data security management duties in accordance with laws and regulations, conducting security and compliance oversight of the activities of all parties involved in public data operations. Another operational model is the regionally integrated, centrally operated model. Under this model, data management entities within provinces and cities—typically government functional departments such as big data administration bureaus—take the lead in constructing public data management platforms. These platforms aggregate public data collected by various departments and industries through mechanisms for open data access and data sharing, and then uniformly authorize data operators to use these data resources via the public data management platforms. The regulatory authorities oversee the behavior of entities involved in public data operations in strict accordance with laws and regulations. Comparing these two operational models, the decentralized, industry-led model tends toward internal sharing of public data within vertically structured, top-down systems. In this model, since there is only one entity responsible for public data management and operation, the risk of “data silos” is relatively high, which hinders the effective engagement of external social actors from outside the industry in leveraging public data for innovative applications. By contrast, the regionally integrated, centrally operated model involves the joint participation of multiple stakeholders during its operation, placing higher demands on safeguarding diverse interest claims and preventing data security risks. How responsibilities and rights among these stakeholders should be allocated is precisely the practical issue that currently constrains the implementation of this operational model. Given that the concept of “authorized operation of public data” still lacks a unified and clear definition, and there are differing views on its operational models, practices in real-world implementation also vary considerably.
What exactly is “public data authorization and operation”? Some scholars, in their research on government data and from the perspective of data governance, have categorized the flow of government data into three main types: government data sharing, data openness, and authorized operation. Government data sharing refers to the flow of government data among different departments and at different levels within the government system itself. Government data openness involves governments at all levels making government data freely available to the public—this represents a flow of government data outward from the government system. Government data authorization and operation, on the other hand, refers to the practice where the government authorizes certain entities to operate government data through market-oriented approaches, thereby facilitating the use of such data by external parties. Other perspectives hold that public data authorization and operation entails specialized institutions—authorized by public data management authorities and other relevant data management bodies in accordance with applicable laws and regulations—that possess professional operational capabilities. These institutions, building upon a secure and controllable development environment, organize upstream and downstream entities in the industrial chain to carry out data processing, value extraction, and other related operational activities around public data according to established rules, ultimately generating data products and services. Public data authorization and operation comprises five key stages: data supply, data operation, transaction and circulation, application traceability, and effectiveness evaluation. According to this definition, data supply is the prerequisite for public data authorization and operation. In terms of operational procedures, it involves data collection and storage conducted initially by the data supplier. On this basis, the data supplier then grants authorization to qualified operators, who proceed to perform specific operational activities such as data cleansing, processing, analysis, mining, and the development of data products and services. Additionally, these operators undertake data management, data circulation and trading, and data security oversight. Operators may provide data to data consumers (also referred to as data users) either through free data openness or paid data transactions. Alternatively, when data is not circulated externally, operators can offer data retrieval services, data analysis report services, and “data sandbox” services.
(2) Government To The management authority over public data has become the fundamental logical basis for institutional development.
The concept of “public data” is a relatively recent one, emerging more recently after such concepts as government information, administrative information, government data, and administrative data. It is generally recognized that although public data differs significantly from government information and government data in terms of both connotation and extension, there is nonetheless a certain institutional connection between the sharing and opening of public data and the disclosure of government information. Government information disclosure is an obligation that administrative bodies are legally required to fulfill in the course of performing their duties. The Regulations on the Disclosure of Government Information explicitly stipulate that disclosing government information is essential for ensuring that citizens, legal persons, and other organizations can obtain government information in accordance with the law, enhancing the transparency of government work, and meeting the needs of building a government based on the rule of law. Governments should actively promote government information disclosure efforts and gradually expand the scope of information made available to the public. The Data Security Law further specifies that state organs shall, in accordance with prescribed rules, promptly and accurately disclose administrative data following the principles of fairness, equity, and convenience for the public. Clearly, in terms of the scope of information disclosed, administrative data encompasses a broader range than government information. The 14th Five-Year Plan for National Economic and Social Development of the People’s Republic of China and the Visionary Goals for 2035 further call for deepening the exploration and utilization of public data. Local governments have taken the lead in conducting legislative explorations related to public data, incorporating public data into the scope of data managed by the government and thereby launching practical initiatives for the authorized operation of public data.
Through an examination of the evolution of legislation and the current state of public data authorization and operation practices, we find that public data management agencies—including government departments—(for convenience of expression, hereinafter collectively referred to as “government” or “government departments”) exercise control and management over data by collecting and storing it, thereby effectively becoming the “data owners” and suppliers of public data. Based on their role as “owners” of public data, governments control and manage the data and then open and operate it for public use. In the authorization and operation model, in addition to the owner, there are also data authorization operators, data users, and data regulators. Consequently, public data authorization and operation is characterized by multiple actors, diverse roles, and varied interests. It is precisely based on this underlying logic that the institutional framework for public data authorization and operation is generally constructed along the following path: "rights confirmation—authorization—operation—utilization—regulation." This institutional approach is characterized by taking data rights confirmation as the cornerstone of the institutional architecture, aiming at establishing a stable production, efficient allocation, lawful utilization, and secure and controllable public data resource system. It seeks to build a clear-cut institutional ecosystem in which all participating entities have clearly defined boundaries of rights, responsibilities, and benefits. This includes a rule system for data generation—that is, a set of rules governing data collection and storage designed to protect the rights of data subjects (data generators), such as their right to be informed and other personal information rights; a rule system for data controllers, data operators, and data users—that is, a set of rules governing the allocation of data rights and the assignment of responsibilities among the participants in data authorization and operation; a rule system for data circulation—that is, a set of rules covering the operation of public data platforms, the valuation of data assets, the delivery of data assets, the distribution of revenues from data assets, and the evaluation of operational performance; and a rule system for the supervision and assurance of public data operations—that is, technical and procedural rules ensuring the trustworthiness, controllability, and security of every stage and element involved in public data operations. Guided by bottom-line considerations such as data security, public interest, and the preservation and enhancement of public data assets, the corresponding institutional framework places particular emphasis on meeting the institutional needs on the “supply-side” end.
II. Practical Dilemmas in Building a Public Data Authorization and Operation System Under the Existing Underlying Logic
Although there have already been explorations and reforms in the authorized operation of public data, the institutional framework—when overly focused on the logic of “management authority”—inevitably leads to a one-sided interpretation of the relevant regulations governing the authorized operation and management of public data as matters solely decided by the government. This, in turn, hinders the effective mining and utilization of public data and makes it difficult to establish a corresponding ecosystem. Such institutional construction is primarily reflected in three key aspects:
(1) The boundaries of public data operations have become a legislative challenge.
“Public data” as a conceptual tool, The concept of “public data” is frequently mentioned in numerous laws, regulations, and policy documents at the central level in China. For instance, laws and regulations such as the “E-Commerce Law of the People’s Republic of China,” the “Cybersecurity Law of the People’s Republic of China,” and the “Telecommunications Regulations of the People’s Republic of China” all employ the term “public data.” However, current national legislation has yet to provide a clear definition of the concept of “public data,” including its precise meaning and scope. Only the “Regulations on Network Data Security Management (Draft for Comments),” issued by the Office of the National Internet Information Office on November 14, 2021, defines “public data” as various types of data collected or generated by state organs and organizations authorized by laws and administrative regulations to perform public management functions or provide public services in the course of fulfilling their public management duties or delivering public services, as well as other types of data collected or generated by organizations when providing public services that involve public interests. Definitions of “public data” are more commonly found in local-level legislation. For example, the “Data Ordinance of the Shenzhen Special Economic Zone” defines “public data” as data generated and processed by public management and service agencies in the course of performing their public management duties or providing public services in accordance with the law. The “Regulations on the Management and Application of Public Data of Chengdu City,” promulgated as early as 2018, define “public data” as various information resources—such as texts, data, images, audio, and video—that are recorded and preserved in certain forms and generated and managed by government departments in the course of performing their duties according to law. The “Measures for the Management of Public Data of Guangdong Province,” implemented in 2021, define “public data” as “information recorded in electronic or non-electronic form that is produced or obtained by public management and service agencies in the course of performing their duties and providing public services in accordance with the law.” At the same time, these measures exclude from the scope of “public data” data collected, used, and managed by public enterprises, institutions, and social organizations—including those engaged in electricity, water supply, gas supply, telecommunications, public transportation, and urban infrastructure services—in activities beyond the provision of public services. The “Shanghai Data Ordinance,” effective January 1, 2022, defines “public data” as “data collected and generated by state organs, public institutions, and organizations authorized by law to perform public management functions (hereinafter collectively referred to as public management and service agencies) as well as organizations providing public services such as water supply, power supply, gas supply, and public transportation, in the course of performing their public management and service duties.” Subsequently enacted local legislations, such as the “Zhejiang Provincial Public Data Ordinance,” the “Fujian Provincial Big Data Development Ordinance,” and the “Shandong Provincial Public Data Openness Measures,” have similarly defined the concept of “public data.” As data openness practices continue to unfold and legislative efforts deepen, legislators’ understanding of the concept of “public data” has gradually converged, though no consensus has yet been reached. For example, the “Jiangxi Provincial Public Data Management Measures” define the scope of “public data” as “any records of information—whether in electronic or other forms—generated or obtained by administrative agencies at all levels and public institutions with public management and service functions (hereinafter collectively referred to as public management and service agencies) in the course of performing their duties and providing public services in accordance with the law.” Clearly, the Jiangxi Provincial Public Data Management Measures do not include data collected and generated by enterprises providing public services within the scope of “public data”; instead, they stipulate only that “the management of public data generated or obtained by public utilities during the provision of public services shall be governed by these Measures by analogy.” Moreover, some provincial local legislations have introduced the concept of “public data” but still adopt a vague approach in defining its scope. For instance, the “Liaoning Provincial Big Data Development Ordinance” states: “Public data refers to data resources obtained by public management and service agencies in the course of performing their duties and providing public services in accordance with the law, as well as other data resources specified by laws and regulations to be included in public data management.” Liaoning’s local legislation leaves the definition of the scope of “public data” to higher-level legislation, thus leaving room for future clarification of the scope of “public data.” Through a review of these provisions, it becomes evident that there is a general consensus across different regions that “public data” refers to various types of data collected and generated by public management and service agencies at all levels in the course of performing their duties according to law. However, specific definitions of the scope of public management and service agencies remain somewhat unclear. While state organs, public institutions, and organizations authorized by law to manage public affairs are explicitly recognized as public management and service agencies, whether public utility enterprises—including those operating electricity, water supply, gas supply, telecommunications, and public transportation—as well as public enterprises, institutions, and social organizations providing urban infrastructure services, should also be considered part of this category remains a matter of differing interpretations. 。
The greatest challenge in defining “public data” lies in the inherent “uncertainty” of the concept itself. This uncertainty is reflected in the ambiguity of the subjects involved—primarily the data collectors and data managers—as well as in the uncertainty of the data sources, which mainly refer to the data subjects themselves, namely the natural persons, legal entities, and non-legal organizations to whom the relevant data pertain. Furthermore, there are differing interpretations and understandings of this concept within academia. Some argue that “public data should encompass two components: government agencies’ official data and non-private data generated by various entities in public spaces.” Some scholars have proposed that the definition of “public data” involves two key elements: the subject and the conduct. First, the subject element requires that the institutions collecting and generating public data must possess public characteristics. Second, the conduct element stipulates that public data are those collected and generated by the aforementioned institutions in the course of performing their public management and service functions. Other scholars suggest that “public data are data resources obtained through a ‘specific subject + specific purpose + specific conduct,’ meaning that the scope and boundaries of public data are delineated by the purpose, subject, and conduct elements.” This view further argues that the subject, purpose, and conduct elements used to define public data should all align closely with the goals of “public management and services” and the public interest, since public data represent a resource endowed with public character, and their purpose is precisely to serve the public good. It is worth noting that, at the national legislative level, the Cyberspace Administration of China’s “Regulations on the Security Management of Network Data (Draft for Comments)” defines the scope of public data broadly as “all types of data collected or generated by state organs and organizations authorized by laws and administrative regulations to perform public administration duties or provide public services, as well as various types of data collected or generated by other organizations in the provision of public services that involve the public interest.”
Even so, the definition of the “public interest” element in public data remains vague and uncertain. While public interest provides a legitimate basis for relevant entities to collect, utilize, and process data subjects’ information, it also serves as a statutory ground for restricting data subjects’ rights, thereby narrowing the scope of those rights and curtailing their interests. A typical conflict arises when public data processing intersects with issues such as personal information protection, protection of corporate trade secrets, and national security. For instance, core principles of personal information protection—such as the rule of informed consent and the principle of purpose limitation—cannot be readily applied to the context of public data operations. To some extent, this also involves legal questions concerning the entities responsible for collecting public data, the authorization mechanisms for data subjects’ use of their data, the authorized entities involved in data operation, the operational entities themselves, the delineation and limitations of the scope of data subject to authorized operation, and the definition of responsibilities and liabilities associated with authorized operations. Although some regions have adopted a tiered classification approach to managing public data, from a practical standpoint, the methods and standards for such classification remain difficult to clearly define. In short, the unclear conceptual boundaries and scope of public data lead to ambiguity regarding operational boundaries; the institutional focus on the “supply side” results in limited provision of public data, creating an imbalance between supply and demand for public data.
(2) The allocation of data rights has become a dilemma in institutional development.
Since the release of the “Opinions of the CPC Central Committee and the State Council on Establishing a More Perfect System and Mechanism for Market-Based Allocation of Production Factors” in 2020, the state has recognized data as a key market factor—on an equal footing with capital, land, labor, and technology—and has gradually begun fostering the data-factor market. Promoting data property rights clarification, facilitating smooth data transactions and flows, and ensuring equitable distribution of data-factor revenues have become pressing practical and theoretical challenges that urgently require exploration. Among these, how to effectively harness public data has emerged as a central issue in cultivating the data-factor market. Traditional economic theory holds that clearly defined property rights are a prerequisite for optimizing resource allocation. Given the diverse and complex nature of the actors and interests involved in data factors, scientifically defining data ownership and clearly delineating the boundaries of data rights among different stakeholders have become essential prerequisites and foundations for optimizing data resource allocation and making effective use of data resources during the development of the data-factor market. However, existing legal regulations have yet to provide clear definitions regarding data ownership and the content of data rights, presenting a significant legislative challenge. Although related theoretical research is thriving, reaching a consensus remains difficult, and practical approaches remain highly divergent.
Specifically regarding the issue of authorized operation of public data, a key practical challenge lies in the numerous legal gaps that currently exist. These gaps include: which types of public data can be authorized for operation; who should serve as the authorizing entity for such operations; who is eligible to obtain authorization; what exactly constitutes “operation” in the context of authorized public data management; and how the revenues generated from authorized public data operations should be distributed—all of these remain unresolved and lack a consensus. In practice across various regions, efforts to authorize and operate public data have been undertaken without sufficient higher-level legal support regarding the attribution of public data rights and without clear definitions of the content of those rights. In reality, the logical starting point for establishing relevant institutional frameworks has been the premise of controlling and processing public data. The entities collecting public data gain control over it and subsequently engage in data-processing activities. Under this logical premise, regardless of whether ownership of public data has been formally defined or whether the government directly holds property rights over the data, government and other public administration and service agencies—through their data-collection, aggregation, and sharing activities—have become data controllers. Consequently, they proceed to share, open, and operate public data precisely on the basis of this control. However, this approach of processing data based on control and then authorizing external use also raises another critical issue: it effectively sidesteps the question of whether the data was obtained lawfully in the first place, or else tacitly assumes that the acquisition of public data inherently carries legal legitimacy.
Some regions are also experimenting with treating public data as a new type of state-owned asset and operating it in a market-oriented manner. Specifically, public data is granted to state-owned enterprises, which then meet the economic and social development needs for public data through market-based service offerings, while simultaneously ensuring the preservation and appreciation of government data assets. The underlying logic behind this approach to authorized operation of public data is that the government treats public data as a state-owned asset. Without altering the existing data management authority held by government agencies and other public administration and service institutions, the government authorizes external entities to operate and utilize these public data resources. A deeper issue underlying such attempts is that, at the national level, there is still no legislative confirmation establishing that public data constitutes state-owned assets; nor has this concept been further substantiated in theory. Some scholars argue that “when state organs process personal information and collect and use data, their purpose is ‘to fulfill statutory duties’ or serve the public interest—not to acquire or increase property—and thus there is no need to provide economic incentives for state organs. If property interests were allocated, it could potentially hinder the full and effective utilization of such data by the general public.” Even setting aside the question of state ownership of public data, from the perspective of management and usage rights derived from control, the principle of “whoever manages is responsible,” “whoever provides is responsible,” and “whoever uses is responsible” serves as a guiding principle for handling public data. This principle plays a normative and positive role in facilitating data sharing among government departments and promoting government data openness. However, in the context of public data openness and authorized operation, since public data flows beyond the direct control of its original managers, the authorized operation involves multiple stakeholders—including data providers, data operators, data users, and government agencies responsible for managing and overseeing data authorization—each with distinct roles, responsibilities, and interests. How these roles and responsibilities are clearly delineated directly affects the flow of public data. For instance, what exactly does management authority encompass? In particular, what is the scope of management authority held by market entities providing essential public services such as water supply, electricity supply, gas supply, and public transportation, and according to what standards should this authority be exercised? Moreover, how can we prevent over-management by competent authorities? These are all practical challenges that persist. Especially under the constraints imposed by data security laws, national secrecy regulations, commercial confidentiality rules, and personal information protection frameworks, data-providing entities may refuse to share public data out of concern for safeguarding their own interests. The Data Security Law explicitly stipulates that “each region and each department is responsible for the data collected and generated in their respective areas and departments, as well as for data security.” As the entity responsible for the centralized collection and unified external authorization of public data, the government, driven by risk prevention and a bottom-line mindset, may find it even more difficult to actively authorize data sharing. When the boundaries of rights, responsibilities, and benefits among various stakeholders involved in the authorized operation of public data remain unclear, it becomes impossible to create positive incentives for the full utilization of public data, thereby giving rise to a fundamental institutional dilemma that hinders the free flow of data.
(3) There is a legislative gap regarding the legal nature of authorized operation of public data.
Public data authorization and operation serve as a complement to the open access of public data. While public data openness focuses on enabling the public to “know” about the data, public data operation emphasizes the public’s ability to “use” the data. Public data openness is provided free of charge, whereas public data operation involves fees; the value of authorized operation lies precisely in “public data that is conditionally open.” Public data management agencies not only act as stewards of public data but also serve as its primary users. Given the ongoing economic investment required to manage public data, allowing these agencies to engage in value-added utilization of public data helps provide the necessary support for ensuring the sustainable supply of such data—a crucial mechanism for leveraging profits to benefit the public good. Building on this foundation, public data authorization and operation introduces the participation of market entities, empowering them to explore and exploit the value of public data through operational activities and to share the resulting economic benefits. This undoubtedly serves as a positive incentive for the market-oriented operation of public data. This article does not delve into the theoretical debate over ownership of public data nor the legitimacy of government revenue. However, it remains unclear whether the relationship between the authorizing entity and the authorized party should be characterized as an administrative licensing legal relationship, a utility franchise relationship, or a contractual agency relationship based on delegation—clarifying this point will determine how government data authorization and operation should be regulated. Since public data authorization and operation differs from the free, open access of public data, it is essential to ask: Under what legal framework should authorization be granted, and to whom? Moreover, after authorization and operation are established, concerns may arise regarding the potential for substantive monopolization of public data and whether equitable public access to such data might be unduly restricted. These issues must be addressed through appropriate institutional mechanisms.
First, although the legal relationship of government data authorization and operation exhibits certain characteristics of entrustment, it cannot be simply equated with the data entrustment processing relationship under data law. Data entrustment processing refers to the data processing activities in which a data processor entrusts a third party to carry out data processing operations according to the agreed-upon purposes and methods. The Personal Information Protection Law, the Cybersecurity Law, and the Data Security Law constitute the foundational legal frameworks for data processing, and any related data processing activities must also comply with the behavioral rules and principles set forth in these laws. Taking personal information processing as an example, according to the definition in the Personal Information Protection Law, a personal information processor refers to an organization or individual that independently determines the purpose and methods of processing personal information in its processing activities. Correspondingly, a trustee can be understood as an organization or individual that, in personal information processing activities, does not have the autonomy to determine the purpose and methods of processing. In other words, whether a “third party” can “independently determine” the purpose and methods of processing will become the key factor in determining whether a given situation qualifies as “entrustment processing.” In an entrustment processing relationship, the trustee is not authorized to make decisions independently; its processing activities, purposes, and methods concerning public data must all remain within the scope of the agreement. Under the government data authorization and operation model, while the operator has the right to process and handle the government data that has been authorized for operation, it can also provide data products and services externally in its own name. Thus, within the scope of authorization, the operator enjoys a relatively high degree of autonomy. Consequently, the legal relationship between the government and the operator differs from that of data entrustment processing.
Second, although government data authorization and operation are subject to strict eligibility requirements, they differ from the management of administrative licensing. Administrative licensing refers to the act by which an administrative agency, upon receiving an application from a party concerned and conducting a lawful review, grants permission for that party to engage in specific activities. According to Article 12 of the Administrative Licensing Law, “matters requiring the granting of specific rights—such as the development and utilization of limited natural resources, the allocation of public resources, and market access in specific industries directly related to public interests”—may be subject to administrative licensing. Public data is a type of public resource, and given its high-risk profile in terms of data security, its operation should be entrusted only to entities meeting certain specified conditions. Administrative licensing can effectively address the issue of qualification-based access. Moreover, based on current practice, government data authorization and operation are often led and directly granted by the government to specific entities, exhibiting a unidirectional empowerment characteristic. Thus, public data authorization and operation shares some characteristics with administrative licensing. However, in general administrative licensing, the licensee acquires the right to engage in a particular activity, and obtaining such a right typically does not require payment of consideration. Although free access is one of the core principles underlying government data openness, in practice not all data are uniformly made available free of charge without exception. Judging from the current state of public data authorization and operation, it is usually the case that the authorized operator is required to pay a fee or consideration.
Examining current practices, institutional design has generally followed a “administrative licensing + operational authorization” model. However, this approach has quite obvious shortcomings. First, in terms of legislation, the specific content of “authorization”—particularly the intended purposes for which it is granted—remains difficult to exhaustively define and regulate. The legal framework governing the opening and utilization of public data encompasses not only the order of data disclosure itself but also data security and the protection of personal privacy throughout the data utilization process. Since the content of “authorization” cannot be precisely or simply generalized, it becomes challenging to effectively implement the principles of “informed consent” and “purpose limitation,” thereby making it difficult to ensure effective redress for data subjects’ rights. Second, fee-setting and pricing have yet to be incorporated into the legal framework governing administrative fees; as a result, the mechanisms for setting data fees, pricing procedures, and related processes remain incomplete and inadequate.
III. Path Selection for Building a Public Data Authorization and Operation System
(1) A Legislative Approach Rooted in Societal Priorities and Problem-Oriented Thinking
As previously mentioned, the institutional framework built upon existing logic faces significant challenges in legislative advancement, owing to theoretical controversies and a lack of robust legal underpinnings. Some scholars have proposed establishing the institutional framework for open public data based on the right to equitable use of public data, shifting the focus from institutional design centered on data ownership regulations to one that emphasizes rights related to data utilization. By specifying the content of the right to equitable use of public data and establishing mechanisms for redress of such rights, these scholars seek to refine the legal framework governing the open use of public data. This approach avoids placing governmental policy considerations at the heart of the system, while also neglecting the participation and oversight mechanisms involving data users themselves, thereby ensuring that diverse user groups enjoy a fair and equitable environment for data utilization. Other scholars, from the perspective of fostering digital markets, argue that cultivating digital markets and establishing property rights over data elements represent two distinct yet interconnected issues. To nurture the data element market, we must break free from the path dependency associated with data property rights. Instead, through effective infrastructure design and ecosystem development, we can flexibly adjust legal relationships among multiple stakeholders via contractual arrangements rather than rigid legal rules, thus ensuring the security and orderly functioning of the data market’s production and circulation processes. Regardless of which approach is adopted, all paths ultimately hinge on the core requirement of an authorization and operation system: unlocking the latent value of public data and serving society as a whole. Therefore, when designing the institutional framework for authorized operation of public data, we must prioritize social interests above all else. The principle of social interest centrality demands that legislation take the overall societal interest as its starting point, respecting individual interests while using the collective good as the foundation for institutional design. As the author has noted earlier, the concept of public interest itself is an indeterminate legal notion; although its boundaries may be fluid and ever-changing, at the very least, the overall institutional design should uphold the values of safety, efficiency, and fairness. The issue of legislation governing the authorized operation of public data involves the intersection of multiple branches of law and inherently possesses openness, applicability, and novelty. Consequently, legislative efforts must strike a careful balance among multiple competing value objectives. In terms of legislative methodology, we can shift away from the traditional private-law rights-based approach and instead emphasize the priority of confirming transactional property rights. Adopting a “field-specific legal” mindset, we should remain problem-oriented, foregoing the pursuit of systemic completeness or logical consistency. Institutional design should revolve around specific problems and fully respond to the real needs of society. Throughout the entire process—ranging from setting authorization powers and selecting authorized entities, defining the scope of publicly available data that can be developed, to determining the content and format of authorization agreements—we must consistently orient our efforts toward realizing the public interest. This will help prevent the concentration of power, rent-seeking behavior, harm to social interests, negative impacts of individual actions, and unchecked pursuit of profit by individuals.
(2) Institutional Development Driven by Problem-Oriented Approaches
1. Establish the core institutional framework for building a data market ecosystem.
The purpose of authorizing and operating public data is to leverage market forces to specifically develop public data, thereby providing society with more value-added services. From this perspective, while the development of public data’s application value does not necessarily require prior data rights confirmation, realizing the full potential of public data applications nonetheless depends on an effectively functioning market ecosystem. Through multi-stakeholder participation in the market, we can establish market rules that facilitate data sharing and utilization, promote value creation, and ensure that only qualified market entities—those meeting stringent准入 criteria and possessing genuine capabilities for operating public data—are selected and admitted. To foster a broad societal atmosphere of active participation in and exploitation of public data resources, an array of industry ecosystem enterprises specializing in data valuation, pricing, trading, brokerage, application, and value-added services will emerge in large numbers, gradually driving the development of the entire data-factor market. At the heart of cultivating this market ecosystem lies a core institutional framework that includes at least the following: (1) a public data aggregation system based on data supply, covering data collection, storage, tiered classification, and... Registration and quality management standards; (2) an operational management oversight system and a data security assurance system based on data-driven operations, Establishing operational rules involves focusing on key issues such as the attributes of the operating entity, operational procedures, business boundaries, obligations and responsibilities, and safety management. Grounded in multiple dimensions—including public interest, market fairness, and risk prevention—these rules will center on aspects like the admission of operational service providers, capability assessment, and safety management, thereby constructing a set of operational management rules for public data. (3) A data demand delivery management system based on data utilization, focusing on: Transaction circulation primarily includes rules governing value assessment, data product delivery, and revenue distribution. ; (4) The effectiveness evaluation system refers to the process by which the competent authority for public data operations, through the establishment of a public data operation effectiveness evaluation framework, organizes and conducts assessments of the effectiveness of public data operations.
2. Improve the existing rules for classifying and grading public data.
Scientifically sound data classification and grading rules are essential prerequisites for ensuring the secure flow and efficient utilization of data. By establishing data “classes” and “levels” in a scientifically rational manner, we can, to some extent, address the shortage of publicly available data and break the passive state in which governments are hesitant—or even unable—to provide public data due to concerns about risks, capacity, or willingness. Adhering to the principles of balancing data resource development with protection, integrating security with development, pursuing both innovative breakthroughs and prudent, inclusive regulation, promoting the open application of public data, implementing classified and graded protection measures, prioritizing public interests, and strengthening personal information protection—given the diverse characteristics of data subjects and data objects, the risks and values associated with different types of data also vary significantly. Some data have strong time sensitivity, while others can fully realize their value only under long-term, stable conditions; some data are inherently assets, whereas others require processing and refinement before they can demonstrate their utility. The mixed nature of data poses significant challenges to data openness. Therefore, based on scenario-based data applications and considering the different stages at which data exist, we can establish dynamically adjustable public data classification and grading rules.
3. Improve technical specifications
The operation of public data is inseparable from data platforms—including data operation platforms, data trading platforms, data valuation platforms, and various technical tools. Perfecting technical standards provides a favorable operational environment and critical technological support for public data operations. By refining these technical standards, we can ensure the security and reliability of the public data authorization process.
IV. Conclusion
This article explores the issue of constructing a legal framework for the authorized operation of public data, aiming to provide a theoretical response to the ongoing practices of authorized public data operations being carried out across various regions nationwide. Currently, there is no national legislation explicitly defining the legal nature of public data authorization; moreover, the allocation of data rights falls under the legislative authority of the central government. Local legislative efforts are thus being undertaken in a context where the ownership of public data remains unclear. Given this situation, and considering that the authorized operation of public data will be a crucial initiative for unlocking the potential of data as a key production factor in the future, it is essential to build a corresponding legal and institutional framework that meets current practical needs. The construction of such a framework should focus on fostering a healthy market ecosystem and facilitating a shift from the current government-led administrative allocation model toward a more market-oriented approach. At the same time, the utilization of public data must not come at the expense of compromising its security, fairness, or public interest. In short, the core objective of institutional development is to achieve collaborative governance involving multiple stakeholders working together in a coordinated manner.
Prev: Institutional Framework for the Authorized Operation of Government Public Data
Next: Key Areas and Legal Services for the Mixed-Ownership Reform of State-Owned Enterprises





