Promulgated by: National Cultural Heritage Administration (国家文物局).
Document No.: 文物科发〔2026〕17号 (Wen Wu Ke Fa [2026] No. 17).
Issued June 9, 2026. Effective November 1, 2026.
Translation note — DCC. Translated in full from the official Chinese text of the issuing notice and the Measures. Terminology follows DCC’s bilingual glossary; the lifecycle vocabulary (collection, processing, storage, transmission, registration, service) mirrors the Data Security Law, and the registration chapter parallels the NDA’s public data registration and data property rights registration frameworks.
Notice of the National Cultural Heritage Administration on Issuing the Measures for the Administration of State-Owned Cultural Relics Resource Data
To the cultural heritage bureaus (departments/bureaus of culture and tourism) of all provinces, autonomous regions and municipalities directly under the Central Government, the Cultural Heritage Bureau of the Xinjiang Production and Construction Corps, and all directly affiliated units:
In order to regulate the production of state-owned cultural relics resource data, safeguard the security of state-owned cultural relics resource data, and guide the orderly opening and utilization of state-owned cultural relics resource data, this Administration has studied and formulated the Measures for the Administration of State-Owned Cultural Relics Resource Data. They are hereby issued; please implement them accordingly.
This notice is hereby given.
National Cultural Heritage Administration
June 9, 2026
Measures for the Administration of State-Owned Cultural Relics Resource Data
Chapter I General Provisions
Article 1. State-owned cultural relics resource data is a foundational and strategic resource for achieving the high-quality development of the cultural heritage sector and for promoting the creative transformation and innovative development of fine traditional Chinese culture. These Measures are formulated in accordance with the Law of the People’s Republic of China on the Protection of Cultural Relics, the Data Security Law of the People’s Republic of China, the Cybersecurity Law of the People’s Republic of China and other laws and regulations, in order to strengthen the administration of state-owned cultural relics resource data.
Article 2. “State-owned cultural relics resource data” means records, in electronic form, of information on the cultural relics resources under their administration, organized by state-owned cultural relics administration institutions, including raw data, processed data and derived data.
“State-owned cultural relics administration institutions” means state-owned cultural relics collecting units, state-owned cultural relics protection and administration institutions, and other institutions that collect or keep state-owned cultural relics.
Article 3. State-owned cultural relics resource data is owned by the State, and state-owned cultural relics administration institutions undertake the specific responsibilities of administering it.
Article 4. These Measures apply to the collection, processing, storage, transmission, registration, service and other activities relating to state-owned cultural relics resource data.
Article 5. State-owned cultural relics resource data shall be subject to full-lifecycle management, following the principles of clear rights and interests, orderly opening, effective utilization and secure controllability; data services shall give priority to social benefit and achieve the unity of social and economic benefit.
Article 6. The cultural heritage administrative department of the State Council shall be responsible for organizing the formulation of policies and standards for the administration of state-owned cultural relics resource data, establishing a data registration system, and guiding data collection, processing, storage, transmission, registration and service. It shall plan as a whole the construction of national and regional storage centers for state-owned cultural relics resource data.
Local cultural heritage administrative departments shall be responsible for the administration of state-owned cultural relics resource data within their administrative areas and shall guide the state-owned cultural relics administration institutions within their administrative areas in carrying out the collection, processing, storage, transmission, registration and service of state-owned cultural relics resource data.
The Data Center of the National Cultural Heritage Administration shall specifically undertake the construction of the national storage center, regional storage centers and the registration management platform for state-owned cultural relics resource data, and shall carry out data registration services and related work.
State-owned cultural relics administration institutions shall be responsible for the data collection, processing, storage, transmission and service in respect of the cultural relics resources under their administration, shall register state-owned cultural relics resource data as required, and shall safeguard the security of state-owned cultural relics resource data.
Non-governmental forces are encouraged to participate in the collection, processing and related work on state-owned cultural relics resource data; participating institutions may enjoy priority in the use of data services.
Chapter II Data Collection
Article 7. “Data collection” means the activity of obtaining raw data on cultural relics resources by means of digitization technology.
Article 8. State-owned cultural relics administration institutions shall carry out data collection by way of self-collection or entrusted collection. For entrusted collection, the legal-person status, professional capability, collection plan and security contingency plan of the entrusted institution shall be reviewed and an entrustment agreement signed. The state-owned cultural relics administration institution shall assign dedicated personnel to provide on-site guidance and supervision of the entrusted collection activity, so as to ensure the safety of the cultural relics and the security of the data.
Article 9. Data collection shall comply with the technical standards for the digital collection of cultural relics, shall be performed by personnel with professional technical capability and knowledge of cultural relics safety, and such personnel shall sign a data confidentiality undertaking. Raw data collected shall be verified and handed over promptly; the entrusted institution and individual staff members shall not retain or use it without authorization. Movable cultural relics shall be collected on the premises of the state-owned cultural relics administration institution. Where raw data already collected is able to satisfy data-use requirements, it shall not be collected again.
Chapter III Data Processing
Article 10. “Data processing” means the activity of carrying out standardized handling of raw data — extraction, transformation, categorization and the like — to form processed data.
Article 11. State-owned cultural relics administration institutions shall process raw data by way of self-processing or entrusted processing. An entrustment agreement shall be signed for entrusted processing.
Article 12. Data processing shall comply with the technical standards for the processing of cultural relics data; the processing premises shall be specified, sound physical security protection facilities deployed, and control measures such as access control and operation auditing adopted. Processed data shall be handed over promptly; the entrusted institution and individual staff members shall not retain or use it without authorization, and temporary and cached data and files generated in the course of processing shall be deleted promptly.
Chapter IV Data Storage
Article 13. “Data storage” means the activity of securely preserving and organizing and managing state-owned cultural relics resource data.
Article 14. State-owned cultural relics administration institutions shall establish a data preservation management system, equip themselves with the necessary facilities for data storage, management and service security, designate a person responsible for data security and a management department, and strengthen data security controls.
Article 15. The national and regional storage centers shall establish a whole-process data management system, be equipped with professional storage facilities and security management measures, and build a security protection system including functions such as periodic verification and repair, backup verification, user authentication and privilege management, so as to ensure the integrity and security of the data.
Article 16. State-owned cultural relics administration institutions shall store backups of state-owned cultural relics resource data at the national or a regional storage center for state-owned cultural relics resource data.
Chapter V Data Transmission
Article 17. “Data transmission” means the act of conveying state-owned cultural relics resource data from a sending end to a receiving end by means of signals or media.
Article 18. Data transmission shall generally be carried out online; online transmission shall be conducted through a data transmission platform that has passed national security management certification. Where the volume of data to be transmitted is enormous and offline transmission is genuinely necessary, encrypted storage media shall be delivered by dedicated personnel and handover records properly kept.
Article 19. The data transmission process must provide data verification and identity authentication safeguards to ensure data integrity and traceability. Online transmission must adopt secure and reliable encryption techniques to safeguard data security.
Chapter VI Data Registration
Article 20. “Data registration” means the act of recording, in accordance with uniform rules, the source, description, content and other particulars of state-owned cultural relics resource data and issuing a registration certificate.
Article 21. State-owned cultural relics administration institutions are the entities responsible for data registration and shall, upon completion of the collection and processing of state-owned cultural relics resource data, go through the data registration formalities on the registration management platform for state-owned cultural relics resource data.
Article 22. The types of data registration are initial registration, change registration and cancellation of registration.
(1) Initial registration: the registrant submits registration application information to the registration institution, including the data name, the lawful and compliant source of the data, product and service information, the institution to which the data belongs, data size and data thumbnails. Where, upon examination and public notice by the registration institution, no objection is raised, the registration institution shall issue a registration certificate.
(2) Change registration: where there is an important update or major change in the data source, the status of the data resources, product and service information or the evidence-deposit status, or a major change in the registrant’s information, the registrant shall promptly apply to the registration institution for change registration.
(3) Cancellation of registration: where, after registration, the registration institution finds that the registrant concealed the true circumstances of the data, obtained registration by forging materials, or does not comply with laws, regulations or these Measures, the registration institution shall cancel the registration.
Chapter VII Data Services
Article 23. “Data services” means the act of providing processed data as a service for different application scenarios.
Article 24. Data services shall follow the principles of impartiality, fairness and convenience to the public, and shall provide processed data to society as a service in accordance with the requirement that “raw data does not leave the domain, and data is controllable and measurable.”
Article 25. State-owned cultural relics administration institutions shall select processed data of reliable quality that is non-sensitive, non-confidential and of clear ownership of rights and interests for provision to society as a service.
Data shall not be provided to society as a service in any of the following circumstances:
(1) it involves State secrets or endangers national security;
(2) it is contrary to public order, good morals or ethics;
(3) it harms the lawful rights and interests of individuals or organizations;
(4) its source is unclear and its publication has not been permitted;
(5) it is data on donated cultural relics and the donation agreement stipulates that it shall not be made public;
(6) other circumstances not permitted by laws, regulations or departmental rules.
Article 26. State-owned cultural relics administration institutions shall provide services such as proactive publication and licensed use for the following application scenarios:
(1) State-owned cultural relics administration institutions shall, through their official websites or the registration management platform for state-owned cultural relics resource data, proactively publish the corresponding processed data in a planned and phased manner for the public to browse, appreciate, study and otherwise use, and shall provide query and application-for-download services.
(2) For non-profit needs such as academic research, academic publication, public-welfare exhibitions and public-welfare publicity, the user shall submit an application for use. The state-owned cultural relics administration institution shall, on a non-profit basis, specify the scope of free use or determine reasonable service-fee standards, publish them to the public, and provide the corresponding processed data by way of licensing.
(3) For profit-making needs such as commercial exhibitions and displays, the design and development of cultural and creative products, film, television and animation production, advertising and publicity, and game development, the user shall submit an application, and the state-owned cultural relics administration institution shall determine the scope of licensed use and the service fee through negotiation and provide the corresponding processed data.
(4) State-owned cultural relics administration institutions are encouraged jointly to process high-quality thematic datasets and cooperate in providing licensed-use services.
Article 27. State-owned cultural relics administration institutions providing data services shall satisfy the following requirements:
(1) the data provided shall be lawful, compliant and of reliable quality; a data-service management system shall be formulated and the relevant information published externally;
(2) basic information on the data shall be provided, and licensed use shall indicate the permissible scope of use or restrictions on use;
(3) for licensed use, the basic personal information or legal-person status, credit record, business status and the like of the user shall be reviewed and a license agreement signed, stipulating the content of the license, the scope of use, the term of use, the service fee, and rights and obligations;
(4) data-provenance technologies shall be used to provide a unique identifier for the licensed data, ensuring that the whole process of circulation of state-owned cultural relics resource data is traceable.
Article 28. Derived data generated in the course of data services through professional knowledge production, modeling and analysis, extraction of key information and similar means, which by negotiated agreement belongs to the state-owned cultural relics administration institution, shall be stored, transmitted, registered and served in accordance with the administrative requirements for state-owned cultural relics resource data.
Chapter VIII Supervision and Liability
Article 29. Cultural heritage administrative departments, state-owned cultural relics administration institutions and other relevant entities shall, in accordance with the relevant national laws and regulations and upholding the principles that “whoever administers is responsible” and “whoever uses is responsible,” strictly implement their responsibilities for the administration of state-owned cultural relics resource data. Data involving State secrets shall be handled in accordance with the State’s confidentiality provisions.
Article 30. The cultural heritage administrative department of the State Council shall establish, as a whole, a mechanism for the supervision of security risks and emergency response in respect of state-owned cultural relics resource data, guide risk assessment and monitoring and early warning for state-owned cultural relics resource data, and organize and coordinate the handling of major data security risk incidents.
Provincial cultural heritage administrative departments shall conduct security inspections of state-owned cultural relics resource data within their administrative areas, take timely measures to handle data security risk incidents, and report major data security risk incidents to the cultural heritage administrative department of the State Council.
State-owned cultural relics administration institutions shall carry out security risk assessment and monitoring and early warning for state-owned cultural relics resource data and accept the supervision and inspection of the cultural heritage administrative department at the next higher level. Abnormal situations discovered shall be handled promptly. Where a data security risk incident occurs, it shall be reported promptly to the cultural heritage administrative department at the next higher level.
Article 31. Where a state-owned cultural relics administration institution commits any of the following acts, the cultural heritage administrative department at or above the county level shall order it to make corrections. Where there is a violation of laws or regulations, the corresponding liability shall be pursued in accordance with law. Where a crime is constituted, criminal liability shall be pursued in accordance with law:
(1) failing to perform its responsibilities for the administration of state-owned cultural relics resource data in accordance with these Measures, causing adverse effects;
(2) dereliction of duty by staff of the state-owned cultural relics administration institution causing state-owned cultural relics resource data to be damaged or leaked, or leading to irreversible harm or other serious consequences;
(3) committing other acts that infringe the security of state-owned cultural relics resource data or obstruct the processing and use of state-owned cultural relics resource data.
Article 32. Where any other relevant entity commits any of the following acts, it shall be dealt with in accordance with the relevant laws and regulations. Where harm is caused to a third party, civil liability shall be borne in accordance with law. Where a crime is constituted, criminal liability shall be pursued in accordance with law:
(1) obtaining state-owned cultural relics resource data by theft or other unlawful means;
(2) in breach of the agreement, distributing, transferring or leaking to others state-owned cultural relics resource data obtained under license, or using state-owned cultural relics resource data obtained under license beyond the scope of the licensed use;
(3) making improper use of state-owned cultural relics resource data in a manner that harms the interests of the State, the public interest or the lawful rights and interests of others;
(4) committing other acts in violation of the State’s laws and regulations on data administration.
Chapter IX Supplementary Provisions
Article 33. These Measures shall come into force on November 1, 2026.