A China-facing data processing agreement should begin with role mapping. Under the Personal Information Protection Law, a vendor processing personal information on a customer’s instructions may be an entrusted processor. The parties must agree the purpose, duration, method, information categories, protection measures, and their rights and duties, while the customer supervises the entrusted activity.
Not every recipient is an entrusted processor. A vendor that determines its own purpose and method may be an independent personal information processor; jointly determined purposes and methods may create joint-processing obligations. The contract, privacy notice, consent analysis, security measures and cross-border mechanism must reflect what the parties actually do rather than labels imported from another jurisdiction.
Direct answer
Map each data flow and processing purpose, then assign the PIPL role activity by activity. For entrusted processing, document instructions and all mandatory Article 21 topics, restrict secondary use and sub-entrustment, require appropriate security and incident cooperation, establish supervision and audit evidence, and provide for return or deletion when the arrangement ends.
If the recipient acts independently, use the Article 23 provision framework and update notice and separate-consent analysis as required. If information leaves China, add the applicable cross-border mechanism and overseas-recipient terms; calling the arrangement “processing” does not avoid export rules.
Role mapping before drafting
Create a schedule for each activity showing the business purpose, personal-information categories, individuals, systems, locations, retention, decision-maker, instructions, recipients and onward disclosures. Ask who decides why the data is processed and the essential means.
One vendor can hold different roles. A payroll provider may process employee records on instructions, while independently processing contact or billing information for its own administration or legal duties. Draft separate rows rather than forcing the whole relationship into one label.
Use PIPL terminology deliberately. “Controller,” “processor” and “subprocessor” can help international teams communicate, but they do not replace analysis of personal information processor, entrusted processor, joint processing and provision to another processor under Chinese law.
Entrusted processing under Article 21
Where a personal information processor entrusts processing, the parties must agree the entrusted purpose, duration, method, personal-information categories, protection measures, and rights and duties. The entrusting party must supervise the entrusted party’s activities.
The entrusted party must process according to the agreement and cannot exceed the agreed purpose or method. When the arrangement is ineffective, invalid, revoked or terminated, it must return or delete the personal information and cannot retain it, subject to any governing-law issue that needs specific resolution.
The existing entrusted-processing page remains the concise statutory explanation; this guide owns the contract architecture and operating schedule.
Instructions, purpose and scope
Define permitted purposes and processing operations precisely enough to control conduct. Attach documented instructions and a method for authorized changes. State what the vendor may do to provide, secure, support and troubleshoot the service and what uses are prohibited.
Do not grant an unrestricted right to use customer personal information for “business purposes,” product development or artificial-intelligence training. If the vendor proposes an independent use, analyze it separately, update transparency and consent where required, and do not disguise it as an instruction.
Data schedule and minimization
List personal-information categories, sensitive information, data subjects, sources, systems, storage locations, transfers and retention. Identify minors’ data and regulated-sector information. Limit collection and access to what is necessary for the defined purpose.
The schedule should be operationally testable. Generic terms such as “all customer data” do not tell security, engineering or auditors what is permitted. Link the schedule to architecture and record-of-processing materials.
Security measures
Require measures proportionate to the information and risk, including access control, identity management, encryption where appropriate, logging, vulnerability management, secure development, backups, recovery, personnel confidentiality and physical security. Allocate responsibility for customer configuration and shared controls.
Set evidence requirements: policies, certifications, test summaries, remediation records and incident exercises. A certification can support diligence but does not prove every contractual control is operating or satisfy every PIPL duty.
Sub-entrustment
PIPL restricts an entrusted party from sub-entrusting without the entrusting party’s consent. The agreement should identify approved providers or establish prior notice, information and approval. Cover service location, function, personal-information categories and material changes.
Flow down purpose, instructions, security, confidentiality, incidents, rights assistance, audit and return/deletion duties. The primary vendor should remain accountable under the main agreement for promised performance; contractual allocation should not obscure the statutory role analysis.
Individual rights and complaints
Require the vendor to route requests and complaints promptly and assist the personal information processor with search, access, copy, correction, deletion, withdrawal and other applicable rights. Define identity-verification boundaries so the vendor does not disclose information without authority.
Test the workflow before launch. The contract should identify systems, response contacts, export formats, exceptions and evidence of completion.
Security incidents
Define what constitutes an incident and require notification without waiting for perfect certainty. Specify the initial channel, available facts, continuing updates, containment, forensic preservation, access, remediation and cooperation with notifications or reports.
Allocate decision-making for communications while preserving each party’s independent legal duties. Include cost and responsibility principles but do not let a liability dispute delay containment or legally required action.
Supervision, audits and records
Because the entrusting party must supervise entrusted processing, give it workable assurance rights. A tiered model can use questionnaires, document review, certifications, interviews, test reports and targeted onsite or technical audits based on risk.
Avoid an audit clause that is either meaningless or operationally unlimited. Address notice, frequency, confidentiality, security, regulator access, remediation and allocation of reasonable costs. Preserve findings, exceptions and closure evidence for compliance audits.
Retention, return and deletion
Set retention by data category and purpose. On expiry or termination, require return in an agreed usable format and deletion from active systems within a defined process, followed by backup expiration under a documented cycle and certification.
Identify any legal retention claimed by the vendor and isolate retained information from other use. A general right to keep anonymized data should define the standard and prohibit re-identification; pseudonymization alone does not necessarily remove information from PIPL.
Independent provision under Article 23
Where personal information is provided to another independent personal information processor, PIPL requires specific notice about the recipient and processing and generally separate consent. The recipient must process within the disclosed purpose, method and categories; changes can require consent again.
The commercial agreement should cover permitted use, independent compliance, security, rights coordination, onward provision, incidents and deletion, but should not falsely state that the recipient acts only on instructions.
Joint processing
Where parties jointly decide purposes and methods, PIPL requires an agreement on their respective rights and obligations and provides a framework affecting responsibility to individuals. Define decision rights, notices, consent, rights intake, security, incidents and liabilities.
Joint processing should not be selected merely to share responsibility. It reflects actual shared decision-making and can increase exposure.
Cross-border processing
Remote access from outside China, offshore support, overseas hosting and onward transfers may constitute provision abroad. Map the exporter, overseas recipient, purpose, data, individuals, volume and infrastructure, then determine the current security assessment, certification, standard-contract or exemption route.
Add the required overseas-recipient obligations, impact assessment, notice and separate-consent treatment where applicable. The separate cross-border guides remain the owners of thresholds and filing procedures.
DPA checklist
- Data-flow and role matrix by activity.
- Purpose, duration, method and documented instructions.
- Information and data-subject schedule.
- Minimization, retention and location.
- Technical and organizational security measures.
- Confidentiality and personnel access.
- Sub-entrustment approval and flow-down.
- Rights, complaints and regulator cooperation.
- Incident notification and evidence preservation.
- Supervision, audit, remediation, return and deletion.
- Independent provision and joint-processing modules where applicable.
- Cross-border mechanism and overseas-recipient terms.
Common mistakes
- Copying a GDPR DPA without mapping PIPL roles.
- Calling an independent recipient an entrusted processor.
- Omitting purpose, method, categories or protection measures.
- Allowing secondary use or AI training through vague language.
- Treating certification as a substitute for supervision.
- Permitting undisclosed sub-entrustment.
- Waiting for a completed forensic report before incident notice.
- Promising deletion without addressing backups and legal retention.
- Assuming an Article 21 agreement is a cross-border transfer mechanism.
Sources
- Personal Information Protection Law of the PRC, Cyberspace Administration of China.
- Personal Information Protection Compliance Audit Measures, Cyberspace Administration of China; effective 1 May 2025.
General legal information only; not legal advice for a particular vendor, system, transfer, incident or processing arrangement.


