Skip to main content
China Legal Guides · National framework

Software and SaaS Contracts in China

A practical guide to software and SaaS contracts in China covering scope, licensing, implementation, SLAs, IP, data, security, subcontractors and exit.

63lawyer profiles listed
Updated10 Sep 2026
AudienceForeign businesses & individuals
Author China Legal Portal Editorial · Reviewer Shangjin Hou · Last reviewed · 6 min read · Editorial policy · AI content policy · Disclaimer · Not legal advice — confirm current rules with counsel and authorities

At a glance

Practice: typical process stages

Four high-level stages — details and local variations are in the guide below.

  1. FrameMap facts to PRC rules
  2. PlanOptions, risks & timeline
  3. ExecuteFilings, contracts, forums
  4. ReviewCompliance & next steps
City hubs

Local guides & lawyers

Drill into city × practice hubs where available, or open the city legal market guide.

Legal planning desk with source documents, authority records and evidence file
Working file · authority, workflow and evidence

A China software or SaaS agreement must describe the actual service, not merely label it “cloud” or “SaaS.” The contract should identify licensed software and hosted functions, users and territory, implementation and acceptance, service levels, support, fees, intellectual-property rights, data roles, security obligations, subcontractors and the exit process.

Contract drafting cannot cure a regulatory mismatch. The provider’s hosting, connectivity, platform and data architecture should be checked separately under China’s telecom, cybersecurity, personal-information, data-security and cross-border rules. The agreement should allocate the resulting tasks and evidence without stating that a customer contract itself supplies a required licence or regulatory approval.

Direct answer

Begin with a product and data-flow map, then make the contract match it. Identify which entity provides each feature, where infrastructure and support teams are located, what the customer receives, who owns each data set and deliverable, and what happens when the service changes or ends. Attach measurable specifications rather than relying on sales materials.

For a subscription service, the most important operational terms are often implementation, availability, support, change control, security, data portability and transition assistance. For licensed or customized software, add delivery, acceptance, source materials, maintenance, ownership and third-party component terms.

Define the transaction

“Software” can describe an on-premises licence, hosted application, mobile app, API, managed service, implementation project or combination. State each component and its legal and commercial treatment.

The scope should identify:

  • customer entities, permitted users and authorized locations;
  • production, test and disaster-recovery environments;
  • modules, features, capacity and usage limits;
  • implementation, configuration, migration and training;
  • interfaces, dependencies and customer responsibilities;
  • support and maintenance; and
  • excluded services and assumptions.

If an order form, statement of work and online policy all apply, establish precedence and a controlled method for amendments. Avoid allowing a webpage to change negotiated risk terms without meaningful notice and agreement.

Licence and access rights

For licensed software, define the rights granted, term, territory, users, devices, affiliates, contractors, backup copies and restrictions. Address whether the customer may configure, integrate, test, benchmark, reverse engineer where legally permitted, or use APIs and documentation.

For SaaS, describe the access right and service rather than implying transfer of ownership. State account administration, authentication, acceptable use, suspension grounds and responsibility for users. Suspension should be proportionate and should not become an unchecked way to disable a customer during a payment or security dispute.

Implementation and acceptance

Separate subscription commencement from implementation milestones. Define inputs, project governance, dependencies, delivery dates, testing environment and objective acceptance criteria. State what happens when a deliverable fails, when a customer delays testing and whether deemed acceptance applies.

Use a written defect and remediation process. A vague requirement that the system be “satisfactory” is difficult to administer; a deemed-acceptance clause that ignores material defects can be equally problematic. Preserve test scripts, results, tickets, meeting decisions and change orders.

Service levels and support

Specify availability measurement, exclusions, maintenance windows, severity levels, response and restoration targets, escalation, reporting and service credits. Clarify whether credits are the sole remedy and what repeated or serious failures permit.

Availability percentages mean little without defining the measurement point and denominator. Address failures involving third-party cloud, connectivity, customer systems and force majeure. Keep status logs and incident tickets long enough to resolve billing and breach disputes.

Fees, tax and usage changes

Define subscription, implementation, support and pass-through charges; billing currency; tax and invoice treatment; payment dates; disputed invoices; late payment; and renewal pricing. For consumption pricing, identify the authoritative meter, audit access and anomaly process.

Control price and feature changes at renewal. If exchange rates, cloud inputs or law changes may affect fees, use a transparent adjustment mechanism rather than an unrestricted unilateral right.

Intellectual property

Distinguish pre-existing software, customer materials, configurations, custom development, feedback, documentation, models, data and outputs. State who owns each category and which licences are needed to operate and exit.

For custom work, address source code, build materials, developer assignments, acceptance and reuse of generic components. Identify open-source and third-party software, applicable terms and responsibility for infringement claims. Escrow may help for critical software but is useful only if deposits are current, complete and releasable on workable triggers.

Data roles and instructions

Map each processing activity under the Personal Information Protection Law rather than copying GDPR labels mechanically. A vendor acting on the customer’s instructions may be an entrusted processor; for other activities it may determine purposes and methods independently. The contract should reflect each role.

For entrusted processing, address purpose, duration, method, information types, protection measures, party rights and duties, supervision, sub-processing, return or deletion and assistance with individual requests. Independent provision and cross-border transfers can trigger different notice, consent and mechanism requirements.

Keep a data schedule covering sources, locations, retention, access, transfers and deletion evidence. The separate data-processing-agreement guide should own the full PIPL vendor-term analysis.

Security and incidents

Set proportionate technical and organizational measures, access controls, encryption, logging, vulnerability handling, backups, recovery testing and personnel controls. Identify applicable standards without promising certifications the provider does not hold.

Define incident notification triggers, initial timing, required information, containment cooperation, forensic access, regulatory and customer communications, costs and preservation. Avoid a clause that delays notice until every fact is confirmed.

Hosting, telecom and regulatory dependencies

Identify the operating and contracting entities, infrastructure location, cloud or IDC provider, domain and app arrangements, and user connectivity. “SaaS” is not itself one Chinese licence category. Features and architecture may engage ICP filing, value-added telecom, cloud, app, content or sector rules and foreign-investment restrictions.

The contract should state which party maintains identified approvals and what happens if a licence, hosting arrangement or transfer mechanism changes. The existing China SaaS regulatory guide and outbound-compliance article remain the owners of that analysis.

Subcontractors and change control

List material subprocessors and service providers or establish a notice-and-objection process. The primary provider should remain responsible for contracted performance. Flow down security, confidentiality, data and deletion duties.

Use change control for features, integrations, security architecture, data locations and regulatory requirements. Distinguish emergency security changes from commercial reductions in functionality. Record approvals and the effect on fees, timetable and acceptance.

Termination and exit

State termination grounds, cure rights, suspension sequence and the effect of termination on fees and licences. Provide an export period, format, assistance, transition access, deletion timetable, certification and treatment of backups. Address business continuity if the provider becomes insolvent or loses a key licence.

Confidentiality, accrued payment, IP, audit, dispute, liability and required data duties may survive. Do not let the exit clause depend on a proprietary export that the customer cannot use.

Contract checklist

  1. Product, entity, infrastructure and data-flow map.
  2. Order form, scope, specifications and document precedence.
  3. Licence/access rights and acceptable use.
  4. Implementation, dependencies and acceptance.
  5. SLA, support and service records.
  6. Fees, tax, metering and renewal.
  7. IP ownership, third-party components and infringement process.
  8. PIPL roles, data schedule and cross-border route.
  9. Security, incidents, audit and regulatory cooperation.
  10. Subcontractors, change control, termination and portable exit.

Sources

General legal information only; not legal advice for a particular software product, licence, service architecture, data flow or contract.

Legal source archive with indexed legislation and official records
Source register · primary authorities and verification
Sources & trust

How to use this guide

MIIT telecom catalogue; ICP/VATS practice; cloud licensing overlays. Editorial source-check 2026-09-06.

Editorial, AI and verification policies

This page is general information for orientation. It is not legal advice and does not create an attorney–client relationship.

Review the Editorial Policy, AI Content Policy, and Lawyer Verification Policy.

Consultation preparation

What to prepare before contacting counsel

Send a focused first package so counsel can check conflicts, understand scope, and identify urgent deadlines.

  • A concise timeline and the result you want to achieve.
  • Names of all parties and affiliates for a conflict check.
  • Key contracts, notices, correspondence, filings, or decisions.
  • Known deadlines, preferred language, location, and budget constraints.
Directory

Practice lawyer profiles

China-based listings shown first. Review profiles for practice, then submit an initial enquiry.

Status shown per profileFree initial intakeChina-first directory sort

Browse practice directory →

Cross-border legal details arranged for a prepared counsel enquiry
Next route · prepared enquiry

Move from orientation to a properly prepared legal brief.

Bring the parties, objective, relevant documents, chronology, known deadlines and the decision you need counsel to make.

Prepare your legal enquiry →

Need counsel on practice?

Review listed lawyer profiles and submit an initial enquiry. No obligation.