Our Expert in China
No results available
Who this is for: In-house counsel, vendor legal teams, and privacy/compliance officers for SaaS, cloud and adtech vendors operating in or with China.
What you will get: Clause-level DPA drafting and negotiation guidance that complies with the Personal Information Protection Law (PIPL) and the Cybersecurity Law (CSL) regime, including cross-border transfer mechanisms and practical vendor controls.
A data processing agreement china counsel can rely on in 2026 is no longer a back-office formality, it is one of the most scrutinised contractual artefacts in any vendor relationship touching Chinese personal information. Regulators under the PIPL and CSL framework increasingly treat the written allocation of processing duties as evidence of compliance (or the lack of it), and SaaS, cloud and adtech vendors are feeling the pressure most acutely because their data flows are often multi-tenant, cross-border and complex.
This guide delivers a practical, vendor-facing playbook: a clause-by-clause breakdown of what PIPL requires, sample language you can adapt, cross-border transfer mechanics mapped to the Cyberspace Administration of China (CAC) regime, incident-response and audit drafting, and a negotiation plan for risk allocation. Everything below is written for working counsel who need usable text, not high-level summaries.
Note: all sample clauses in this article are provided for educational use only. Obtain jurisdictional validation from a PRC-licensed lawyer before adopting any clause in a binding contract.
The PIPL, adopted by the Standing Committee of the National People’s Congress and in force since 1 November 2021, imposes direct statutory obligations on both personal information handlers (the functional equivalent of controllers) and entrusted processors. Where a handler entrusts another party to process personal information, PIPL requires the parties to agree on the purpose, time limit and method of processing, the categories of personal information, protective measures, and the rights and obligations of each party. That contractual requirement is what makes a well-drafted data processing agreement china regulators will accept so central: the DPA is not an optional annex, it is the mechanism by which statutory duties are allocated and demonstrated.
The Cybersecurity Law adds a second, overlapping layer. The CSL, in force since 1 June 2017, imposes network-operator duties, tiered security protection obligations, and data localisation requirements for critical information infrastructure operators (CIIOs). For many cloud and SaaS vendors, the question of whether they are a network operator, and whether their customer is a CIIO, directly shapes the hosting, localisation and security clauses the DPA must carry. The Data Security Law (DSL), in force since 1 September 2021, further governs data classification and security obligations and should also be considered where important data is involved.
Since 2022, the CAC and allied authorities have moved from guidance to enforcement, publishing penalty decisions and tightening the rules around cross-border transfers. Administrative penalties under PIPL can be severe, for serious violations the law provides for fines of up to RMB 50 million or up to 5% of the preceding year’s turnover, among other measures, and in certain cases criminal liability is possible. Published enforcement announcements and relevant judicial materials indicate a consistent pattern: regulators examine whether contractual arrangements actually assign security measures, sub-processing controls and breach-notification duties, or whether the DPA is boilerplate that does not match operational reality. A data processing agreement china enforcement bodies will respect is one where the paper matches the practice.
For vendors, the practical consequence is that generic EU-style templates ported into the Chinese market may not survive scrutiny. Adtech vendors handling device identifiers, SaaS providers operating multi-tenant platforms, and cloud hosts storing bulk personal information each face distinct localisation and transfer questions. The DPA must therefore be specific: it should name the processing activities, reference the applicable transfer mechanism, and set out technical and organisational measures (TOMs) that align with Chinese standards rather than only foreign equivalents.
PIPL frames its core actor as the personal information handler (个人信息处理者), the party that independently determines the purpose and means of processing. Where that handler entrusts processing to another organisation, the entrusted party performs on instruction and is subject to its own statutory obligations. This differs from the GDPR controller/processor model in an important respect: under PIPL the entrusted processor is subject to direct statutory duties, including security, assistance and return/deletion obligations, and the handler remains responsible for supervising the entrusted party’s processing.
Joint handling is also recognised. Where two or more handlers jointly decide on processing purposes and means, PIPL requires them to agree on their respective rights and obligations, and data subjects may in appropriate cases pursue either party, with the parties bearing joint liability where they infringe personal information rights. For a DPA, this means the roles must be identified accurately at the outset, mislabelling a joint handler as a mere processor can leave a party exposed to liabilities it never priced.
A multi-tenant SaaS platform typically acts as an entrusted processor for each customer’s tenant data, while simultaneously acting as an independent handler for its own account, billing and product-telemetry data. The DPA should separate these roles clearly. Where the SaaS vendor uses infrastructure-as-a-service providers, those sub-processors become a further entrusted layer, and the handler’s supervision duty flows down the chain. A DPA China SaaS vendors negotiate should therefore include a documented sub-processor list, a flow-down obligation requiring equivalent TOMs, and a right to object to or approve new sub-processors.
Adtech introduces the hardest classification problems. Where a vendor enriches a customer’s first-party data with third-party identifiers, or participates in real-time bidding, it may determine part of the processing purpose, pushing it towards joint-handler or independent-handler status rather than clean entrusted-processor status. Certain device identifiers and behavioural profiles may, depending on the facts, constitute sensitive personal information or be subject to heightened requirements, triggering PIPL’s separate-consent and necessity requirements. Adtech DPAs must therefore pin down which party determines enrichment purposes, whether the required consent has been obtained, and how identifiers are segregated and deleted.
The following clauses are the operational backbone of any PIPL data processing agreement. Each is set out with its statutory rationale, sample language for adaptation, and negotiation notes.
PIPL requires the parties to agree on the purpose, time limit and method of entrusted processing, and the entrusted party must process only within the agreed scope. Tie the clause to the handler’s documented legal basis.
Sample clause, for educational use: “The Processor shall process Personal Information solely for the purposes set out in Schedule 1 (Processing Details) and strictly in accordance with the documented instructions of the Handler. The Processor shall not process Personal Information for any other purpose, nor retain, transfer or otherwise use the Personal Information for its own account.”
Negotiation tip: Vendors should resist open-ended “and related purposes” language; buyers should insist that any instruction changes be in writing and logged.
PIPL’s minimisation and storage-limitation principles require that retention be limited to the shortest period necessary to achieve the purpose. List categories and retention in an annex.
Sample clause, for educational use: “The categories of Personal Information and data subjects, and the retention period applicable to each, are specified in Schedule 2 (Retention Schedule). Upon expiry of the applicable retention period the Processor shall delete or anonymise the relevant Personal Information in accordance with Clause [Deletion].”
Negotiation tip: Agree a concrete retention schedule rather than “as required by the customer”, ambiguity shifts risk and complicates deletion.
PIPL obliges handlers and entrusted processors to adopt security measures appropriate to the risk, and the CSL’s graded (multi-level) protection scheme supplies a Chinese technical baseline. Reference Chinese standards rather than only foreign frameworks.
Sample clause, for educational use: “The Processor shall implement and maintain the technical and organisational measures set out in Schedule 3 (TOMs), which shall at a minimum satisfy applicable requirements under the Cybersecurity Law and associated national standards, including encryption of Personal Information in transit and at rest, access controls on a least-privilege basis, logging, and regular security testing.”
Negotiation tip: Make the TOMs schedule a living document subject to review; avoid a static list that becomes obsolete.
Because the handler must supervise entrusted processing, and the entrusted processor generally requires the handler’s consent to further entrust processing, the DPA must govern onward delegation. Choose between an approval model and a notice-with-objection model.
Sample clause, for educational use: “The Processor shall not engage any sub-processor without the prior written consent of the Handler. Where consent is given, the Processor shall impose on the sub-processor data protection obligations no less protective than those in this Agreement and shall remain fully liable for the acts and omissions of the sub-processor.”
Negotiation tip: SaaS vendors typically prefer a notice model with a defined objection window; buyers should secure flow-down equivalence and continuing vendor liability.
PIPL grants data subjects rights including access, copying, correction, deletion, portability (in prescribed circumstances) and withdrawal of consent. The entrusted processor should assist the handler in responding.
Sample clause, for educational use: “The Processor shall, taking into account the nature of the processing, provide reasonable assistance to enable the Handler to respond to requests from data subjects exercising their rights under the PIPL, and shall acknowledge any such request forwarded by the Handler within [5] business days.”
Maintaining processing records supports the handler’s accountability and is consistent with security-logging duties under the CSL.
Sample clause, for educational use: “The Processor shall maintain accurate records of its processing activities and security logs for the periods required by applicable law, and shall make such records available to the Handler on reasonable request to demonstrate compliance with this Agreement.”
Where the entrustment ends or the entrustment contract is not performed, the entrusted processor must return or delete the personal information, with certification where appropriate.
Sample clause, for educational use: “Upon termination or expiry of this Agreement, the Processor shall, at the Handler’s election, return or securely delete all Personal Information and existing copies, and shall certify such deletion in writing within [30] days, save where retention is required by applicable PRC law.”
Cross-border transfer is where a data processing agreement china counsel must be most precise. PIPL and CAC rules establish a tiered regime: a CAC security assessment for higher-risk or higher-volume transfers; the CAC standard contract route; and personal-information protection certification, together with any thresholds and exemptions set out in the CAC’s Provisions on Promoting and Regulating Cross-Border Data Flows. The correct mechanism depends on the volume and sensitivity of the data and on whether the exporter is a CIIO. The DPA should name the applicable mechanism and include fallback language if a transfer becomes blocked. Because the applicable thresholds and exemptions are periodically revised, counsel should verify the current rules with the CAC before finalising.
Where the standard-contract route applies, the parties must execute the CAC standard contract in the form published by the regulator, conduct the required personal information protection impact assessment, and file the contract with the provincial CAC as required. The commercial DPA should incorporate it by reference rather than restate it.
Sample clause, for educational use: “Where Personal Information is transferred outside the People’s Republic of China, the parties shall execute and comply with the standard contract for cross-border transfer of personal information published by the CAC, which shall be appended as Schedule 4. In the event of any conflict between this Agreement and the CAC standard contract in respect of the transfer, the CAC standard contract shall prevail.”
Negotiation tip: Do not amend the substantive provisions of the CAC standard contract, its content must match the published template, though supplementary terms may be agreed provided they do not conflict with it. Negotiate only commercial wrappers around it.
For transfers that meet the thresholds triggering a CAC security assessment, the DPA should allocate responsibility for preparing and filing the assessment and for cooperating with the regulator.
Sample clause, for educational use: “Where a CAC security assessment is required for any cross-border transfer, the Handler shall lead the application and the Processor shall provide all information, documentation and cooperation reasonably necessary to complete the assessment. No transfer requiring assessment shall occur until the required clearance has been obtained.”
Where localisation applies, for example to personal information and important data collected and generated by CIIOs under the CSL, or where a transfer cannot be cleared, the DPA needs an architecture fallback.
Sample clause, for educational use: “Where applicable law requires that specified categories of Personal Information be stored within the People’s Republic of China, or where a required transfer mechanism cannot be obtained, the Processor shall store and process the relevant Personal Information on infrastructure located in the PRC and shall not transfer it outside the PRC until a lawful transfer mechanism is in place.”
PIPL requires handlers to take immediate remedial measures on a personal-information leak, tampering or loss, and to notify the competent authorities performing personal information protection duties and the affected individuals (subject to limited exceptions where measures effectively avoid harm). The CSL imposes parallel incident-handling and reporting duties on network operators. The DPA must translate these into concrete processor obligations, because the handler cannot discharge its statutory notification duty without timely, substantive information from the vendor.
Sample clause, for educational use: “The Processor shall notify the Handler without undue delay and in any event within [24] hours of becoming aware of any Personal Information security incident. The initial notice shall describe the nature of the incident, the categories and approximate number of data subjects affected, the likely consequences and the measures taken or proposed. The Processor shall provide a substantive follow-up report within [72] hours and shall preserve all relevant evidence and logs.”
Setting a short internal notification window (for example 24 hours) between vendor and handler gives the handler room to meet its own statutory obligation to act promptly and notify authorities and individuals.
Audit rights are essential vendor-management tools supporting the handler’s supervision duty under PIPL. A balanced clause distinguishes routine evidence (certifications, questionnaires, penetration-test summaries) from invasive on-site inspection reserved for cause.
Sample clause, for educational use: “The Processor shall, on reasonable notice and no more than once per year save where a security incident or regulatory inquiry has occurred, allow the Handler or its appointed auditor to audit the Processor’s compliance with this Agreement. Audits may be conducted remotely through documentary review; on-site inspection shall be limited to areas relevant to the Handler’s Personal Information and shall respect the confidentiality and security of other customers’ data.”
Negotiation tip: Vendors should cap audit frequency and require confidentiality; buyers should preserve an uncapped right to audit following a breach or regulator request, and the right to rely on independent third-party reports.
Risk allocation in a Chinese DPA is complicated by the fact that administrative penalties and potential criminal liability under PIPL attach to the responsible party by operation of law and cannot be contracted away in their entirety. The contract can nonetheless shape how the parties bear the financial consequences of a breach as between themselves.
A usable sample DPA for the Chinese market pulls the clauses above into a coherent instrument: an operative body covering roles, instructions, security, sub-processing, assistance, incident response, audit, transfer and termination; plus schedules for processing details, retention, TOMs and the CAC standard contract. The clause bank approach lets teams assemble a data processing contract china counterparties will recognise while swapping modules in and out for SaaS, cloud and adtech scenarios. Until a companion clause bank is published, the sample language above can seed internal templates, subject always to PRC-licensed review.
The table below highlights where a China DPA diverges from a familiar GDPR DPA so that teams adapting European templates do not carry across assumptions that do not hold.
| Topic | PIPL (China) | GDPR (EU) | Drafting note |
|---|---|---|---|
| Legal basis for processing | Requires a statutory basis under PIPL Article 13 (notably consent, contract necessity, legal obligation and certain others); separate consent and necessity rules for sensitive personal information; cross-border rules are strict | Several legal bases available (consent, contract, legal obligation, legitimate interest and others) | Make the explicit legal basis and the handler’s responsibilities clear in the DPA |
| Cross-border transfers | CAC security assessment, CAC standard contract, or certification, subject to current thresholds and exemptions; may require additional approvals | SCCs, adequacy decisions, BCRs | Include a fallback and an operational transfer plan specific to China |
| Processor obligations | Entrusted processors carry direct statutory obligations; the handler retains a supervision duty | Processor obligations flow through the DPA; the controller remains primarily liable | Allocate operational controls and compliance duties clearly and precisely |
| Fines & enforcement | Significant administrative penalties (for serious violations up to RMB 50 million or 5% of prior-year turnover); potential criminal liability for severe breaches | Fines up to 4% of global annual turnover or EUR 20 million, whichever is higher | Use narrowly drafted indemnities and compliance warranties; fines cannot be wholly contracted away |
For deeper context on the firm-side process, see the Data Protection (China) practice area page and the directory of Global Law Experts, China data protection lawyers.
A data processing agreement china regulators will respect in 2026 is a precise, operational instrument, not a repurposed foreign template. It must name roles accurately under PIPL, embed security measures aligned to the Cybersecurity Law and the Data Security Law, select and incorporate the correct cross-border transfer mechanism, set firm incident and audit duties, and allocate risk in a way that reflects the hard limits on contracting away statutory penalties. SaaS, cloud and adtech vendors that get these clauses right will negotiate faster, pass regulator and customer scrutiny more easily, and avoid the gap between paper and practice that enforcement authorities target.
Use the sample clauses above as a starting point, adapt them to your specific data flows, and obtain sign-off from a PRC-licensed lawyer before execution.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Maggie Meng at Beijing Global Law Office, a member of the Global Law Experts network.
posted 18 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message