Chapter V Security and Openness of Government Data Article 37 The State shall vigorously advance the construction of e-government, increases the rationality, accuracy, and timeliness of government data, and enhance the capabilities to use data to serve economic and social development. Article 38 Where any state organ needs to collect or use data to perform its statutory duties, it shall do so within the scope of its statutory duties and according to the conditions and procedures prescribed in laws and administrative regulations; any data it comes to know in the course of performing its duties, including personal privacy, personal information, trade secret and confidential business information, shall be kept confidential and shall not be leaked or illegally provided to others. Article 39 State organs shall, in accordance with laws and administrative regulations, establish and perfect data security management systems, implement data security protection responsibilities, and ensure the security of government data. Article 40 Where state organs entrust others maintain and construct any government system, or to store or process government data, they shall undergo strict approval procedures, and shall supervise the entrusted parties in terms of their fulfillment of the corresponding data security protection obligations. The entrusted parties shall perform their data security protection obligations in accordance with laws, regulations and any contractual agreement, and shall not retain, use, leak or provide to others any government data without permission. Article 41 State organs shall promptly and accurately publish government data as required under the principles of fairness, impartiality, and convenience for the people, except where the data shall not be disclosed in accordance with the law. Article 42 The State shall formulate open catalogues for government data, and build a uniform and standard, interconnected and interactive, secure and controllable government data open platform, to promote the open use of government data. Article 43 Where organizations with public affairs management functions, as authorized by laws and regulations, conduct data handling activities in order to perform their statutory duties, this chapter shall apply. Chapter VI Legal Liability Article 44 When the relevant competent departments discover any major security risk in data handling activities in the course of performing their data security supervision duties, they may, according to the prescribed authority and procedures, conduct interviews with the relevant organizations and individuals, and require them to take measures for rectification to eliminate hazards. Article 45 Where any organization and individual fails to fulfill the data security obligations stipulated in Articles 27, 29, and 30 hereof in conducting data handling activities, relevant competent departments shall order such organization and individual to make correction, give warnings, and may impose a fine of no less than CNY50,000 but no more than CNY500,000 concurrently; the directly responsible officers and other persons directly liable may be imposed a fine of no less than CNY10,000 but no more than CNY100,000; those who refuse to make correction or cause major data leakages or other serious consequences shall be imposed a fine of no less than CNY500,000 but no more than CNY2 million, and may concurrently be ordered to suspend relevant business or stop operation for rectification, or be subject to revocation of relevant 6

Select target paragraph3