[codicts-css-switcher id=”346″]

Global Law Experts Logo
data processing agreement china

Our Expert in China

  • GOLD

Drafting Data Processing Agreements in China (2026): PIPL & CSL Requirements for Saas, Cloud and Adtech Vendors

By Global Law Experts
– posted 60 minutes ago

Who this is for: In-house counsel, vendor legal teams, and privacy/compliance officers for SaaS, cloud and adtech vendors operating in or with China.

What you will get: Clause-level DPA drafting and negotiation guidance that complies with the Personal Information Protection Law (PIPL) and the Cybersecurity Law (CSL) regime, including cross-border transfer mechanisms and practical vendor controls.

A data processing agreement china counsel can rely on in 2026 is no longer a back-office formality, it is one of the most scrutinised contractual artefacts in any vendor relationship touching Chinese personal information. Regulators under the PIPL and CSL framework increasingly treat the written allocation of processing duties as evidence of compliance (or the lack of it), and SaaS, cloud and adtech vendors are feeling the pressure most acutely because their data flows are often multi-tenant, cross-border and complex.

This guide delivers a practical, vendor-facing playbook: a clause-by-clause breakdown of what PIPL requires, sample language you can adapt, cross-border transfer mechanics mapped to the Cyberspace Administration of China (CAC) regime, incident-response and audit drafting, and a negotiation plan for risk allocation. Everything below is written for working counsel who need usable text, not high-level summaries.

Note: all sample clauses in this article are provided for educational use only. Obtain jurisdictional validation from a PRC-licensed lawyer before adopting any clause in a binding contract.

Why a Data Processing Agreement China Compliance Depends On Matters Under PIPL & CSL in 2026

The PIPL, adopted by the Standing Committee of the National People’s Congress and in force since 1 November 2021, imposes direct statutory obligations on both personal information handlers (the functional equivalent of controllers) and entrusted processors. Where a handler entrusts another party to process personal information, PIPL requires the parties to agree on the purpose, time limit and method of processing, the categories of personal information, protective measures, and the rights and obligations of each party. That contractual requirement is what makes a well-drafted data processing agreement china regulators will accept so central: the DPA is not an optional annex, it is the mechanism by which statutory duties are allocated and demonstrated.

The Cybersecurity Law adds a second, overlapping layer. The CSL, in force since 1 June 2017, imposes network-operator duties, tiered security protection obligations, and data localisation requirements for critical information infrastructure operators (CIIOs). For many cloud and SaaS vendors, the question of whether they are a network operator, and whether their customer is a CIIO, directly shapes the hosting, localisation and security clauses the DPA must carry. The Data Security Law (DSL), in force since 1 September 2021, further governs data classification and security obligations and should also be considered where important data is involved.

Enforcement trends & regulator expectations (PIPL + CAC)

Since 2022, the CAC and allied authorities have moved from guidance to enforcement, publishing penalty decisions and tightening the rules around cross-border transfers. Administrative penalties under PIPL can be severe, for serious violations the law provides for fines of up to RMB 50 million or up to 5% of the preceding year’s turnover, among other measures, and in certain cases criminal liability is possible. Published enforcement announcements and relevant judicial materials indicate a consistent pattern: regulators examine whether contractual arrangements actually assign security measures, sub-processing controls and breach-notification duties, or whether the DPA is boilerplate that does not match operational reality. A data processing agreement china enforcement bodies will respect is one where the paper matches the practice.

Practical consequences for SaaS, cloud and adtech contracts

For vendors, the practical consequence is that generic EU-style templates ported into the Chinese market may not survive scrutiny. Adtech vendors handling device identifiers, SaaS providers operating multi-tenant platforms, and cloud hosts storing bulk personal information each face distinct localisation and transfer questions. The DPA must therefore be specific: it should name the processing activities, reference the applicable transfer mechanism, and set out technical and organisational measures (TOMs) that align with Chinese standards rather than only foreign equivalents.

Who Is Controller and Processor Under PIPL, Implications for DPA Drafting

PIPL frames its core actor as the personal information handler (个人信息处理者), the party that independently determines the purpose and means of processing. Where that handler entrusts processing to another organisation, the entrusted party performs on instruction and is subject to its own statutory obligations. This differs from the GDPR controller/processor model in an important respect: under PIPL the entrusted processor is subject to direct statutory duties, including security, assistance and return/deletion obligations, and the handler remains responsible for supervising the entrusted party’s processing.

Joint handling is also recognised. Where two or more handlers jointly decide on processing purposes and means, PIPL requires them to agree on their respective rights and obligations, and data subjects may in appropriate cases pursue either party, with the parties bearing joint liability where they infringe personal information rights. For a DPA, this means the roles must be identified accurately at the outset, mislabelling a joint handler as a mere processor can leave a party exposed to liabilities it never priced.

SaaS vendor scenarios (multi-tenant, sub-processors, hosting)

A multi-tenant SaaS platform typically acts as an entrusted processor for each customer’s tenant data, while simultaneously acting as an independent handler for its own account, billing and product-telemetry data. The DPA should separate these roles clearly. Where the SaaS vendor uses infrastructure-as-a-service providers, those sub-processors become a further entrusted layer, and the handler’s supervision duty flows down the chain. A DPA China SaaS vendors negotiate should therefore include a documented sub-processor list, a flow-down obligation requiring equivalent TOMs, and a right to object to or approve new sub-processors.

Adtech data flows and third-party enrichment (cookies, IDs)

Adtech introduces the hardest classification problems. Where a vendor enriches a customer’s first-party data with third-party identifiers, or participates in real-time bidding, it may determine part of the processing purpose, pushing it towards joint-handler or independent-handler status rather than clean entrusted-processor status. Certain device identifiers and behavioural profiles may, depending on the facts, constitute sensitive personal information or be subject to heightened requirements, triggering PIPL’s separate-consent and necessity requirements. Adtech DPAs must therefore pin down which party determines enrichment purposes, whether the required consent has been obtained, and how identifiers are segregated and deleted.

Core Clauses Your Data Processing Agreement China Regulators Expect Under PIPL

The following clauses are the operational backbone of any PIPL data processing agreement. Each is set out with its statutory rationale, sample language for adaptation, and negotiation notes.

Purpose & scope of processing

PIPL requires the parties to agree on the purpose, time limit and method of entrusted processing, and the entrusted party must process only within the agreed scope. Tie the clause to the handler’s documented legal basis.

Sample clause, for educational use: “The Processor shall process Personal Information solely for the purposes set out in Schedule 1 (Processing Details) and strictly in accordance with the documented instructions of the Handler. The Processor shall not process Personal Information for any other purpose, nor retain, transfer or otherwise use the Personal Information for its own account.”

Negotiation tip: Vendors should resist open-ended “and related purposes” language; buyers should insist that any instruction changes be in writing and logged.

Data categories & retention limits

PIPL’s minimisation and storage-limitation principles require that retention be limited to the shortest period necessary to achieve the purpose. List categories and retention in an annex.

Sample clause, for educational use: “The categories of Personal Information and data subjects, and the retention period applicable to each, are specified in Schedule 2 (Retention Schedule). Upon expiry of the applicable retention period the Processor shall delete or anonymise the relevant Personal Information in accordance with Clause [Deletion].”

Negotiation tip: Agree a concrete retention schedule rather than “as required by the customer”, ambiguity shifts risk and complicates deletion.

Security measures & technical and organisational measures (TOMs)

PIPL obliges handlers and entrusted processors to adopt security measures appropriate to the risk, and the CSL’s graded (multi-level) protection scheme supplies a Chinese technical baseline. Reference Chinese standards rather than only foreign frameworks.

Sample clause, for educational use: “The Processor shall implement and maintain the technical and organisational measures set out in Schedule 3 (TOMs), which shall at a minimum satisfy applicable requirements under the Cybersecurity Law and associated national standards, including encryption of Personal Information in transit and at rest, access controls on a least-privilege basis, logging, and regular security testing.”

Negotiation tip: Make the TOMs schedule a living document subject to review; avoid a static list that becomes obsolete.

Sub-processing and subcontractor rules

Because the handler must supervise entrusted processing, and the entrusted processor generally requires the handler’s consent to further entrust processing, the DPA must govern onward delegation. Choose between an approval model and a notice-with-objection model.

Sample clause, for educational use: “The Processor shall not engage any sub-processor without the prior written consent of the Handler. Where consent is given, the Processor shall impose on the sub-processor data protection obligations no less protective than those in this Agreement and shall remain fully liable for the acts and omissions of the sub-processor.”

Negotiation tip: SaaS vendors typically prefer a notice model with a defined objection window; buyers should secure flow-down equivalence and continuing vendor liability.

Assistance to the handler (data subject rights)

PIPL grants data subjects rights including access, copying, correction, deletion, portability (in prescribed circumstances) and withdrawal of consent. The entrusted processor should assist the handler in responding.

Sample clause, for educational use: “The Processor shall, taking into account the nature of the processing, provide reasonable assistance to enable the Handler to respond to requests from data subjects exercising their rights under the PIPL, and shall acknowledge any such request forwarded by the Handler within [5] business days.”

Logs, records & compliance reporting

Maintaining processing records supports the handler’s accountability and is consistent with security-logging duties under the CSL.

Sample clause, for educational use: “The Processor shall maintain accurate records of its processing activities and security logs for the periods required by applicable law, and shall make such records available to the Handler on reasonable request to demonstrate compliance with this Agreement.”

Deletion or return of data on termination

Where the entrustment ends or the entrustment contract is not performed, the entrusted processor must return or delete the personal information, with certification where appropriate.

Sample clause, for educational use: “Upon termination or expiry of this Agreement, the Processor shall, at the Handler’s election, return or securely delete all Personal Information and existing copies, and shall certify such deletion in writing within [30] days, save where retention is required by applicable PRC law.”

Cross-Border Transfers: Mechanisms & Sample Clauses

Cross-border transfer is where a data processing agreement china counsel must be most precise. PIPL and CAC rules establish a tiered regime: a CAC security assessment for higher-risk or higher-volume transfers; the CAC standard contract route; and personal-information protection certification, together with any thresholds and exemptions set out in the CAC’s Provisions on Promoting and Regulating Cross-Border Data Flows. The correct mechanism depends on the volume and sensitivity of the data and on whether the exporter is a CIIO. The DPA should name the applicable mechanism and include fallback language if a transfer becomes blocked. Because the applicable thresholds and exemptions are periodically revised, counsel should verify the current rules with the CAC before finalising.

Standard Contract clause (sample text & negotiation notes)

Where the standard-contract route applies, the parties must execute the CAC standard contract in the form published by the regulator, conduct the required personal information protection impact assessment, and file the contract with the provincial CAC as required. The commercial DPA should incorporate it by reference rather than restate it.

Sample clause, for educational use: “Where Personal Information is transferred outside the People’s Republic of China, the parties shall execute and comply with the standard contract for cross-border transfer of personal information published by the CAC, which shall be appended as Schedule 4. In the event of any conflict between this Agreement and the CAC standard contract in respect of the transfer, the CAC standard contract shall prevail.”

Negotiation tip: Do not amend the substantive provisions of the CAC standard contract, its content must match the published template, though supplementary terms may be agreed provided they do not conflict with it. Negotiate only commercial wrappers around it.

Security Assessment / regulatory liaison clause (when CAC approval is required)

For transfers that meet the thresholds triggering a CAC security assessment, the DPA should allocate responsibility for preparing and filing the assessment and for cooperating with the regulator.

Sample clause, for educational use: “Where a CAC security assessment is required for any cross-border transfer, the Handler shall lead the application and the Processor shall provide all information, documentation and cooperation reasonably necessary to complete the assessment. No transfer requiring assessment shall occur until the required clearance has been obtained.”

Localisation & hosting fallback clause (when data must remain in the PRC)

Where localisation applies, for example to personal information and important data collected and generated by CIIOs under the CSL, or where a transfer cannot be cleared, the DPA needs an architecture fallback.

Sample clause, for educational use: “Where applicable law requires that specified categories of Personal Information be stored within the People’s Republic of China, or where a required transfer mechanism cannot be obtained, the Processor shall store and process the relevant Personal Information on infrastructure located in the PRC and shall not transfer it outside the PRC until a lawful transfer mechanism is in place.”

Incident Response, Regulator Cooperation & Audit Rights, Contract Drafting Tips

PIPL requires handlers to take immediate remedial measures on a personal-information leak, tampering or loss, and to notify the competent authorities performing personal information protection duties and the affected individuals (subject to limited exceptions where measures effectively avoid harm). The CSL imposes parallel incident-handling and reporting duties on network operators. The DPA must translate these into concrete processor obligations, because the handler cannot discharge its statutory notification duty without timely, substantive information from the vendor.

Incident notification clause (sample timeline & content)

Sample clause, for educational use: “The Processor shall notify the Handler without undue delay and in any event within [24] hours of becoming aware of any Personal Information security incident. The initial notice shall describe the nature of the incident, the categories and approximate number of data subjects affected, the likely consequences and the measures taken or proposed. The Processor shall provide a substantive follow-up report within [72] hours and shall preserve all relevant evidence and logs.”

Setting a short internal notification window (for example 24 hours) between vendor and handler gives the handler room to meet its own statutory obligation to act promptly and notify authorities and individuals.

Audit & inspection rights (on-site vs remote; frequency & scope)

Audit rights are essential vendor-management tools supporting the handler’s supervision duty under PIPL. A balanced clause distinguishes routine evidence (certifications, questionnaires, penetration-test summaries) from invasive on-site inspection reserved for cause.

Sample clause, for educational use: “The Processor shall, on reasonable notice and no more than once per year save where a security incident or regulatory inquiry has occurred, allow the Handler or its appointed auditor to audit the Processor’s compliance with this Agreement. Audits may be conducted remotely through documentary review; on-site inspection shall be limited to areas relevant to the Handler’s Personal Information and shall respect the confidentiality and security of other customers’ data.”

Negotiation tip: Vendors should cap audit frequency and require confidentiality; buyers should preserve an uncapped right to audit following a breach or regulator request, and the right to rely on independent third-party reports.

Risk Allocation, Indemnities, and Penalties, Negotiating Playbook

Risk allocation in a Chinese DPA is complicated by the fact that administrative penalties and potential criminal liability under PIPL attach to the responsible party by operation of law and cannot be contracted away in their entirety. The contract can nonetheless shape how the parties bear the financial consequences of a breach as between themselves.

  • Distinguish categories of loss. Separate third-party damages, data-subject claims, and regulatory fines. Each should be addressed explicitly rather than swept into a single indemnity.
  • Use narrowly drafted indemnities. Vendors should offer indemnities tied to their own breach of the DPA or of applicable law, with exclusions for the handler’s own instructions, and appropriate carve-outs for willful misconduct operating against the breaching party.
  • Negotiate caps and baskets. General liability caps and a de minimis basket control exposure; data-breach and confidentiality liabilities are frequently negotiated to a higher super-cap given their severity.
  • Treat regulatory fines carefully. Because fines often cannot be fully shifted, pair any fine-related indemnity with mitigation and cooperation obligations so that the party best placed to prevent or reduce a penalty is incentivised to do so.
  • Back indemnities with warranties. Compliance warranties, that each party will process in accordance with PIPL, the CSL and the DSL, give the indemnity something concrete to bite on.

Practical DPA Clause Bank and Sample Data Processing Agreement China Teams Can Adapt

A usable sample DPA for the Chinese market pulls the clauses above into a coherent instrument: an operative body covering roles, instructions, security, sub-processing, assistance, incident response, audit, transfer and termination; plus schedules for processing details, retention, TOMs and the CAC standard contract. The clause bank approach lets teams assemble a data processing contract china counterparties will recognise while swapping modules in and out for SaaS, cloud and adtech scenarios. Until a companion clause bank is published, the sample language above can seed internal templates, subject always to PRC-licensed review.

The table below highlights where a China DPA diverges from a familiar GDPR DPA so that teams adapting European templates do not carry across assumptions that do not hold.

Topic PIPL (China) GDPR (EU) Drafting note
Legal basis for processing Requires a statutory basis under PIPL Article 13 (notably consent, contract necessity, legal obligation and certain others); separate consent and necessity rules for sensitive personal information; cross-border rules are strict Several legal bases available (consent, contract, legal obligation, legitimate interest and others) Make the explicit legal basis and the handler’s responsibilities clear in the DPA
Cross-border transfers CAC security assessment, CAC standard contract, or certification, subject to current thresholds and exemptions; may require additional approvals SCCs, adequacy decisions, BCRs Include a fallback and an operational transfer plan specific to China
Processor obligations Entrusted processors carry direct statutory obligations; the handler retains a supervision duty Processor obligations flow through the DPA; the controller remains primarily liable Allocate operational controls and compliance duties clearly and precisely
Fines & enforcement Significant administrative penalties (for serious violations up to RMB 50 million or 5% of prior-year turnover); potential criminal liability for severe breaches Fines up to 4% of global annual turnover or EUR 20 million, whichever is higher Use narrowly drafted indemnities and compliance warranties; fines cannot be wholly contracted away

For deeper context on the firm-side process, see the Data Protection (China) practice area page and the directory of Global Law Experts, China data protection lawyers.

Conclusion and Next Steps

A data processing agreement china regulators will respect in 2026 is a precise, operational instrument, not a repurposed foreign template. It must name roles accurately under PIPL, embed security measures aligned to the Cybersecurity Law and the Data Security Law, select and incorporate the correct cross-border transfer mechanism, set firm incident and audit duties, and allocate risk in a way that reflects the hard limits on contracting away statutory penalties. SaaS, cloud and adtech vendors that get these clauses right will negotiate faster, pass regulator and customer scrutiny more easily, and avoid the gap between paper and practice that enforcement authorities target.

Use the sample clauses above as a starting point, adapt them to your specific data flows, and obtain sign-off from a PRC-licensed lawyer before execution.

Two Lawyers Reviewing A Data Processing Agreement China Compliance Checklist

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Maggie Meng at Beijing Global Law Office, a member of the Global Law Experts network.

Sources

  1. Cyberspace Administration of China (CAC)
  2. National People’s Congress (NPC)
  3. State Council of the People’s Republic of China (gov.cn)
  4. Ministry of Public Security (MPS)

FAQs

What must be included in a data processing agreement under China's PIPL?
Core items include the purpose, time limit and method of processing; the categories of personal information and data subjects; retention periods; security measures; sub-processor rules; assistance with data subject rights; incident-notification duties; and the applicable cross-border transfer mechanism. PIPL requires the parties to agree these matters, and the DPA should reference the handler’s legal basis and the parties’ respective obligations.
Not always. DPA language may be sufficient only when the parties also use one of the lawful transfer mechanisms, for example executing the CAC standard contract in its published form and completing any required filing and impact assessment. For larger or more sensitive datasets, or where the exporter is a critical information infrastructure operator, a CAC security assessment or additional approvals may be required before any transfer occurs. Current thresholds and exemptions should be checked against the CAC’s rules.
Use a clear approval or notice-with-objection regime, require sub-processors to adhere to equivalent technical and organisational measures, maintain a documented sub-processor list, preserve a right to audit, and require deletion or return of data on termination. The vendor should remain fully liable for its sub-processors.
Specify prompt notification on detection and a concrete timeline for substantive reporting, for example an initial notice within 24 hours and a fuller report within 72 hours, so that the handler can meet its own duty under PIPL and the CSL to take immediate remedial measures and notify authorities and affected individuals where required.
Vendors can use limited indemnities with carve-outs for willful misconduct, negotiate liability caps and baskets, and draft warranties narrowly. However, administrative penalties and criminal liability under PIPL often cannot be contracted away entirely, so pair any fine-related provision with mitigation and cooperation obligations.
eu trademark opposition germany
By Global Law Experts

posted 18 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Drafting Data Processing Agreements in China (2026): PIPL & CSL Requirements for Saas, Cloud and Adtech Vendors

Send welcome message

Custom Message