Promulgated by: China (Tianjin) Pilot Free Trade Zone Administrative Committee, with the Tianjin Municipal Cyberspace Administration, the Tianjin Municipal Commerce Bureau and the Tianjin Municipal Data Bureau.
Approved by the Tianjin Municipal Cyberspace Affairs Commission; filed with the Cyberspace Administration of China and the National Data Administration. Published May 9, 2024.
Translation note — DCC. Translated in full from the official Chinese text published by the Tianjin Municipal Cyberspace Administration. The original presents the list as a four-column table (data category / data sub-category / basic characteristics and description / remarks); the flattened PDF has been reconstructed into a markdown table with the same columns. Terminology follows DCC’s bilingual glossary. The Tianjin list operates under Article 6 of the Provisions on Promoting and Regulating Cross-border Data Flows; for the practitioner overview of the FTZ lists that followed, see DCC’s brief on the FTZ negative lists.
China (Tianjin) Pilot Free Trade Zone Data Export Management List (Negative List) (2024 Edition)
In order to promote the lawful and orderly cross-border flow of enterprise data in the China (Tianjin) Pilot Free Trade Zone (hereinafter the “Tianjin FTZ”), advance high-level opening-up, and better serve the accelerated construction of a new development pattern, the China (Tianjin) Pilot Free Trade Zone Data Export Management List (Negative List) (2024 Edition) (hereinafter the “Negative List”) is formulated.
I. Purpose and significance
To implement the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China, the Measures for Data Export Security Assessment, the Measures on Standard Contracts for the Export of Personal Information, the Provisions on Promoting and Regulating Cross-border Data Flows and other laws and rules; to align with high-standard international economic and trade rules; to explore institutional opening-up in the digital field; and, by building a new model for managing cross-border data flows, to provide convenience for the lawful, orderly and efficient export of enterprise data and effectively improve the business environment and the international competitiveness of enterprises.
II. Basic principles
-
Adhere to overall coordination. Coordinate development and security, hold the bottom line of national data security, and, on the basis of safeguarding the security of important data and protecting personal information rights and interests, promote the orderly flow and development and utilization of data resources and the high-quality development of the digital economy and digital trade.
-
Adhere to convenience and compliance. Give play to the Tianjin FTZ’s policy advantage as a pilot area, study and establish a lawful and orderly model for managing cross-border data flows, and explore a facilitation mechanism for cross-border data flows.
-
Adhere to simplicity and practicality. In accordance with the requirements of the national data-export management systems — data export security assessment, standard contracts for the export of personal information, and personal information protection certification — and in light of the actual data-export needs of enterprises and institutions in the Tianjin FTZ, formulate an operable and implementable Negative List that enterprises can readily grasp and apply.
-
Adhere to dynamic adjustment. Dynamically adjust the content of the Negative List according to the national data security situation and changes in the enterprises and data-export scenarios of the Tianjin FTZ, achieving the unity of safeguarding security and promoting development.
III. Scope of application
The Negative List sets out the circumstances in which enterprises in the Tianjin FTZ providing data abroad must declare a data export security assessment, conclude a standard contract for the export of personal information, or pass personal information protection certification. Enterprises in the Tianjin FTZ providing abroad data outside the Negative List are exempt from declaring a data export security assessment, concluding a standard contract for the export of personal information, and passing personal information protection certification. Data involving State secrets, core data and government data are not brought under Negative List management; the export of such data shall follow the relevant laws, regulations and provisions.
New situations and new problems arising in the use of the Negative List shall be discussed by the Municipal Cyberspace Administration, the Municipal Commerce Bureau, the Municipal Data Bureau and the Tianjin FTZ Administrative Committee together with the relevant departments, which shall jointly study and formulate countermeasures and provide explanations. Where the relevant policies and provisions of the national industry competent departments change and the content of the Negative List is inconsistent with them, those provisions shall prevail.
IV. Main considerations
-
Implement the requirements for classified and graded data management. Strictly follow the classification and grading requirements of laws, regulations and the national industry competent departments; important data identified by the national industry competent departments or by this Municipality is brought under the management of this list, in compliance with the relevant national data-export management requirements.
-
Strengthen personal information protection. Around protecting personal information rights and interests, regulating personal information processing activities and promoting the reasonable use of personal information, bring exports of personal information of different scales and types under Negative List management.
-
Serve the high-quality development of enterprises. According to enterprises’ data-export needs for international trade and external exchange, specify the categories, basic characteristics and descriptions of data subject to export management, reduce the compliance costs of data export for enterprises and institutions, and enhance competitiveness.
-
Regulate data-export conduct. Strengthen the building of data-export security risk-monitoring capabilities in the Tianjin FTZ, enhance in-process and post-hoc supervision of data export in terms of institutions, teams and technical means, and promptly discover and handle unlawful data-export conduct. Strengthen the publicizing and interpretation of the Tianjin FTZ’s data-export policies, systems and standards, and raise enterprises’ compliance awareness.
This list will be revised at appropriate times in accordance with the relevant laws and regulations and the actual needs of this Municipality.
China (Tianjin) Pilot Free Trade Zone Data Export Management List (Negative List) (2024 Edition)
Part I — Data requiring a data export security assessment
| Data category | Data sub-category | Basic characteristics and description | Remarks |
|---|---|---|---|
| I. Strategic materials and bulk commodities | 1. Oil, petrochemicals, natural gas | Data on product output, international trade and the like from which the operating conditions, development trends, growth rates and other aspects of important fields involving major national strategies could be inferred — e.g. storage and trading data, international trade data, strategic reserve data. | Data generated in ordinary commercial activities such as business negotiations and import–export trade are excluded. |
| 2. Agricultural products | International cooperation data, international trade data and strategic reserve data on bulk agricultural products such as grain, cotton, edible vegetable oil, sugar, meat and dairy products, and agricultural geographic information data reaching a certain precision or not publicly released — e.g. international cooperation data, international trade data, strategic reserve data. | Same as above. | |
| II. Natural resources and environment | 3. Basic geographic information | Basic geographic information data reaching the coverage, precision, scale or other thresholds prescribed by the State, or depicting sensitive areas and targets — e.g. positioning base data, place-name and address data, terrain and landform data. | |
| 4. Remote-sensing imagery | Remote-sensing imagery data reaching the coverage, precision, scale or other thresholds prescribed by the State, or depicting sensitive areas and targets — e.g. raw imagery data, imagery product data. | ||
| 5. Meteorology | Meteorological monitoring data and disaster-prevention data of all kinds serving the military, defense research and high-technology fields — e.g. meteorological support data for major events, data on important sensitive areas, climate-change response and crop-yield forecast data, Fengyun satellite Level-0 data and telemetry data, radar base data, ground-based weather-modification operation site data, historical meteorological archives and derived data, meteorological government-service data, meteorological critical information infrastructure data. | Data already publicly released by the meteorological and other relevant departments are excluded. | |
| 6. Environmental protection | Undisclosed environmental data bearing on public security or foreign affairs — e.g. environmental monitoring, enforcement or environmental-impact information. | Data that have been disclosed individually but not publicly released after statistical compilation by region or industry are brought under list management. | |
| 7. Water resources | Water-resources data bearing on public security — e.g. dangerous works and sections, building information models of important water-conservancy projects, flood and drought disaster conditions, comprehensive analysis and evaluation data. | Data already publicly released by the water-resources and other relevant departments are excluded. | |
| 8. Oceans | Marine environmental monitoring data of military value unsuitable for public release — e.g. undisclosed marine water-body data, marine geographic data. | Data already publicly released by the natural-resources and other relevant departments are excluded. | |
| III. Industry | 9. Defense industry | Data comprehensively reflecting the research and production capabilities of important enterprises and institutions of the defense science and technology industry, data which when aggregated reflect the overall situation of the defense industry, and distinctive important data of the defense industry field — e.g. internal names, geographic location information, construction plans, security planning, guard and protection arrangements, production and operation conditions and product transaction conditions of defense research and production units. | |
| 10. Chemical industry | Data on the monitoring of key hazardous chemicals, key processes, equipment operation, output and reserves — e.g. information on hazardous-chemical production sites and transport route planning, production and sales conditions, manufacturing methods. | ||
| 11. Steel, non-ferrous metals | Data on reserves, output and procurement volumes of non-ferrous metals with important military and civilian value; national strategic reserve data on steel and non-ferrous metals or important geological data on strategic non-ferrous-metal deposits; data on mining areas rich in important associated mineral resources — e.g. production-capacity data, process routes, capacity data, reserve information and consumption-destination data for special steel; statistical data on reserves, capacity data, procurement volumes and international cooperation with relevant countries for non-ferrous metals with important application value in the defense industry and key sectors of the national economy. | Data generated in ordinary commercial activities such as business negotiations and import–export trade are excluded. | |
| 12. Rare earths | Data on rare-earth mining, smelting and other production technologies uniquely mastered by China — e.g. rare-earth resource storage and development conditions, international cooperation conditions. | Same as above. | |
| 13. Other minerals | Data reflecting the State’s important resource-reserve capacity and affecting relevant international cooperation — e.g. statistical reserve data (excluding radioactive minerals), international cooperation conditions, international trade negotiation conditions, the layout of mineral-related industrial development. | Same as above. | |
| 14. Electricity | Design and construction drawings (including location coordinates within 100-meter precision) of electricity infrastructure such as large hydropower stations, large pumped-storage stations, nuclear power stations, thermal power stations with single-unit capacity of 1 GW or more or total installed capacity of 3 GW or more, substations (switching stations) and converter stations above 500 kV (exclusive), and remote dispatch control centers; raw data on the electricity consumption of top-grade electricity users; and the like. | ||
| 15. Electronic information | Data on advanced technologies of the electronic-information industry, advanced integrated-circuit design and manufacturing technologies, design data, algorithms and software–hardware architectures of major computing equipment, and the domestic-production rate of important electronic components and equipment — e.g. parameters, source code, integrated-circuit layouts and product test data of basic electronic-information products such as key chips, operating systems and large software, and the sale and service of products to the defense industry, government and similar fields. | ||
| 16. Civil nuclear facilities | Data which, if tampered with, leaked or unlawfully used, could affect the safety of nuclear materials or nuclear facilities — e.g. experimental or test data in civil nuclear facility research, design and manufacturing processes of nuclear facilities, operational monitoring data of nuclear facilities. | ||
| 17. Industrial equipment | Data reflecting the State’s level of high-end manufacturing and embodying the State’s core competitiveness in the industrial field — e.g. the research, development and production of high-technology equipment applied in military, aerospace and similar fields, and of large equipment or important equipment with core technologies. | ||
| 18. Industrial internet and industrial control systems | Data safeguarding the secure operation of industrial internet or industrial control systems used by above-scale industrial enterprises — e.g. parameters and operation, maintenance and test data of industrial internet or industrial control systems used by industrial enterprises with annual output value of RMB 400 million or more; parameters and operation, maintenance and test data of automatic control systems for urban water, gas and heat supply. | ||
| 19. Intelligent vehicles | Data reflecting the geographic location and operating conditions of important sensitive areas, and data relating to the sensitive personal information of 100,000 or more intelligent-vehicle consumers — e.g. geographic information, pedestrian-flow and vehicle-flow data on important sensitive areas such as military administrative zones, defense-industry units and Party and government organs at or above the county level obtained during intelligent-vehicle operation, and OTA data. | ||
| IV. Finance | 20. Banking | Data which, if leaked, could threaten national security, the security of the banking institution itself, or the security of 1 million or more customers — e.g. bank security data; account information, loan data and transaction data of important enterprises and institutions. | |
| 21. Insurance | Data which, if leaked, could threaten the security of 1 million or more customers, or threaten national security or the operational security of important units and facilities — e.g. insurance and claims data on important facilities, equipment and personnel involving national security; underwriting or claims data processed by insurance institutions for enterprises and institutions undertaking major national projects or construction projects in important fields of national economic and social development. | ||
| 22. Financial leasing | Data which, if leaked or exploited by another country, could threaten the security of 1 million or more customers or affect the operations of the relevant enterprises — e.g. financial-leasing data involving Party and government organs and defense-industry enterprises. | ||
| V. Statistics | 23. Economic statistics | Data reflecting macroeconomic operation in some respect and affecting the lawful rights and interests of a certain number of enterprises and individuals — e.g. Tianjin grassroots data and comprehensive data before public release, sample-survey data from which aggregate data at the Tianjin level or above could be inferred, and statistical data on output and capacity of important industrial and agricultural products by variety. | Data already publicly released by the statistics and other relevant departments are excluded. |
| 24. Social statistics | Data which, if unlawfully used, could affect national security or social stability — e.g. data reflecting the characteristics of China’s language and script, history, customs and ethnic values. | ||
| VI. Communications and broadcasting | 25. Telecommunications | Data on basic telecommunications backbone networks and emergency-communications deployment — e.g. backbone-network planning and construction, operation and maintenance data, key-resource data (such as IP addresses and access-network resources), emergency-communications deployment. | |
| 26. Radio, television and online audio-visual | Data on the planning, construction, operation and maintenance and key resources (such as IP addresses and access-network resources) of broadcasting networks, and media data whose misuse could affect ideological security or public security — e.g. undisclosed audio-visual creative content, transmission-coverage conditions of audio-visual institutions at the provincial level or above, audio-visual monitoring and regulatory data, and the planning, construction, resource deployment and security assurance of critical information infrastructure in the broadcasting industry, of important networks and information systems at MLPS Level 3 or above, and of important networks and information systems of audio-visual institutions with 100 million or more users. | Industry-management data already publicly released by the broadcasting and other relevant departments are excluded. | |
| 27. New media | Data usable for social mobilization which, if unlawfully used, could affect cultural security or public security — e.g. undisclosed or restricted media resource files, online-behavior data of 100,000 or more users. | ||
| VII. Housing and construction | 28. Housing provident fund | Data which could cause the leakage of the sensitive personal information of 100,000 or more persons, affect the daily operations of enterprises, or be used after aggregation to analyze real-estate market conditions — e.g. basic information and account information of housing provident fund contributors and contributing units, and provident fund contribution, withdrawal and use data. | |
| VIII. Transport | 29. Postal services | Data which, if tampered with or leaked, could cause the leakage of the sensitive personal information of 100,000 or more persons or lead to telecommunications fraud or similar activities — e.g. the results of big-data mining and analysis of waybill data. | |
| 30. Transport | Control-category data affecting production safety in railway, highway, road transport, urban transport, waterway transport, civil aviation and similar fields; natural-resources data obtained in the course of construction; undisclosed route maps, key-station data and the like; and data whose leakage or tampering could cause major transport accidents. | ||
| IX. Public health | 31. Health and medical | Genetic-resource data reflecting the overall situation of an ethnic group or bearing on biosecurity; biosecurity and disease-control data bearing on national security, life safety and the safety of humankind — e.g. individual diagnosis and treatment or health-management data that would lead to the leakage of the sensitive personal information of 100,000 or more persons and infringe citizens’ privacy; electronic medical records, examination and test results, health-archive data and the results of their development and utilization. | |
| 32. Food | Data which, if tampered with or leaked, could cause a major food-safety incident or affect food-safety traceability — e.g. food-safety traceability identification information, parameters and control data of automatic control systems in food production. | ||
| 33. Drugs | Data bearing on the safety of the public’s medication and affecting biosecurity and public security — e.g. experimental data involving specific drugs, and test data relating to drug production processes and production facilities. | ||
| 34. Biosecurity | Data bearing on national security, public security and biosecurity, reflecting major progress in biological-science research, and having military value or major economic value — e.g. virus research conditions, data relating to biological laboratories. | ||
| 35. Disease-control data | Data reflecting the prevention and control of infectious diseases in a given area and bearing on public security and biosecurity — e.g. sudden public-health events and epidemic, treatment, vaccine and cause-of-death conditions relating to infectious diseases. | ||
| X. Public security | 36. Physical security | Data which, if unlawfully used, could enable attacks on physical targets, endanger the safety of nuclear materials and facilities, threaten citizens’ lives, or affect national security and public security — e.g. basic information and security-deployment data of important targets and premises. | |
| 37. Cybersecurity | Tianjin cybersecurity situational data; the construction layout and planning and supply-chain management of critical information infrastructure and of important networks and information systems at MLPS Level 3 or above; undisclosed cybersecurity vulnerabilities; and the like. | ||
| 38. Emergency management | Data which could have a major effect on emergency response, disaster prevention and relief, or work safety — e.g. precise location and key-parameter data of key targets, monitoring data of specific areas reaching a certain precision and covering a certain range, data on emergency supplies and rescue equipment reaching a certain scale, and rescue-process data for disasters and accidents of major grade or above. | The specific requirements for “a certain precision,” “a certain range” and “a certain scale” are as set out in the policy documents issued by the emergency-management and other relevant departments. | |
| XI. Internet services and e-commerce | 39. Service outsourcing | Result data generated by introducing domestic important data, or the personal information of 1 million or more persons (excluding sensitive personal information) or the sensitive personal information of 10,000 or more persons, in the course of processing overseas data; result data generated by processing overseas data using technologies uniquely mastered by China. | |
| 40. Internet platform services | Data held by internet platforms that have public-opinion attributes or social-mobilization capability — e.g. behavioral-analysis data on sensitive groups such as government officials and veterans, and service-record data involving defense-industry, Party and government organ and critical information infrastructure customers. | ||
| XII. Science and technology | 41. Export-controlled items | Data relating to items controlled under the Export Control Law of the People’s Republic of China. | |
| 42. Technologies prohibited or restricted from export | Data relating to technologies listed in the Catalogue of Technologies Prohibited or Restricted from Export from China. | ||
| 43. Important intellectual property and major discoveries | Intellectual-property data involving national security — e.g. research papers, observational data and industrialization results that could significantly enhance national security capabilities or directly affect national security. | Intellectual-property data already made public in accordance with law are excluded. | |
| XIII. Personal information | 44. Provision of personal information abroad by critical information infrastructure operators. | The circumstances provided for in Articles 3, 4 and 5 of the Provisions on Promoting and Regulating Cross-border Data Flows are excluded. | |
| 45. Provision abroad by a data processor other than a critical information infrastructure operator, cumulatively from January 1 of the current year, of the personal information of 1 million or more persons (excluding sensitive personal information) or the sensitive personal information of 10,000 or more persons. | Same as above. |
Part II — Data requiring a standard contract for the export of personal information or personal information protection certification
| Basic characteristics and description | Remarks |
|---|---|
| 46. Provision abroad by a data processor other than a critical information infrastructure operator, cumulatively from January 1 of the current year, of the personal information of 100,000 or more but fewer than 1 million persons (excluding sensitive personal information), or the sensitive personal information of fewer than 10,000 persons. | The circumstances provided for in Articles 3, 4 and 5 of the Provisions on Promoting and Regulating Cross-border Data Flows are excluded. |