Entrusted processing is instruction-only — if the vendor sets new purposes, it is not entrusted.
When a handler engages a vendor to process PI, PIPL requires an entrusted-processing agreement covering purpose, period, types, protection measures, and the vendor’s duty to return or delete. The vendor must process per instructions and cannot subcontract or change purposes casually. A PIA is typically required before entrusting. If the vendor is overseas, you still need a CBDT tool — the DPA is not an export licence. Joint processing (two handlers deciding together) is a sibling. GDPR processor clauses are a start, not a finish.
4 questions before you choose the route.
This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.
Who is handler vs vendor?
Who decides purpose and means.
RoleIs the contract PIPL-complete?
Purpose, types, period, security, return/delete.
ContractIs a PIA done?
Entrusting is a listed PIA trigger.
PIADoes PI leave China?
Then add SCC/assessment/certification.
ExportWorking rule: Map the regulated role before marketing or launch in China.
The signal ledger.
These facts move the question beyond a label and into a product, money-flow and control analysis.
Bring a compact evidence docket—not a pitch deck.
Give a compliance team or counsel the operating facts that reveal the perimeter.
Questions people ask before they build.
Short answers for orientation. The right result can change with the service model and current rules.
Is a US DPA enough for a Shanghai vendor?
If both are in the PRC and the vendor only follows instructions, a PIPL entrusted contract is the right instrument — still map the clauses.
Can the vendor keep backups after exit?
Generally return or delete, subject to legal holds. Spell it out.
Primary authorities
Reviewed sources support orientation, not a fact-specific assessment.
