Skip to main content
China Legal Guides · National framework

Data Processing Agreements Under China’s PIPL

Structure China PIPL data-processing agreements by mapping entrusted processing, independent recipients, security, subcontracting, incidents, audits and deletion.

63lawyer profiles listed
Updated10 Sep 2026
AudienceForeign businesses & individuals
Author China Legal Portal Editorial · Last reviewed · 6 min read · Editorial policy · AI content policy · Disclaimer · Not legal advice — confirm current rules with counsel and authorities

At a glance

Practice: typical process stages

Four high-level stages — details and local variations are in the guide below.

  1. FrameMap facts to PRC rules
  2. PlanOptions, risks & timeline
  3. ExecuteFilings, contracts, forums
  4. ReviewCompliance & next steps
City hubs

Local guides & lawyers

Drill into city × practice hubs where available, or open the city legal market guide.

Legal planning desk with source documents, authority records and evidence file
Working file · authority, workflow and evidence

A China-facing data processing agreement should begin with role mapping. Under the Personal Information Protection Law, a vendor processing personal information on a customer’s instructions may be an entrusted processor. The parties must agree the purpose, duration, method, information categories, protection measures, and their rights and duties, while the customer supervises the entrusted activity.

Not every recipient is an entrusted processor. A vendor that determines its own purpose and method may be an independent personal information processor; jointly determined purposes and methods may create joint-processing obligations. The contract, privacy notice, consent analysis, security measures and cross-border mechanism must reflect what the parties actually do rather than labels imported from another jurisdiction.

Direct answer

Map each data flow and processing purpose, then assign the PIPL role activity by activity. For entrusted processing, document instructions and all mandatory Article 21 topics, restrict secondary use and sub-entrustment, require appropriate security and incident cooperation, establish supervision and audit evidence, and provide for return or deletion when the arrangement ends.

If the recipient acts independently, use the Article 23 provision framework and update notice and separate-consent analysis as required. If information leaves China, add the applicable cross-border mechanism and overseas-recipient terms; calling the arrangement “processing” does not avoid export rules.

Role mapping before drafting

Create a schedule for each activity showing the business purpose, personal-information categories, individuals, systems, locations, retention, decision-maker, instructions, recipients and onward disclosures. Ask who decides why the data is processed and the essential means.

One vendor can hold different roles. A payroll provider may process employee records on instructions, while independently processing contact or billing information for its own administration or legal duties. Draft separate rows rather than forcing the whole relationship into one label.

Use PIPL terminology deliberately. “Controller,” “processor” and “subprocessor” can help international teams communicate, but they do not replace analysis of personal information processor, entrusted processor, joint processing and provision to another processor under Chinese law.

Entrusted processing under Article 21

Where a personal information processor entrusts processing, the parties must agree the entrusted purpose, duration, method, personal-information categories, protection measures, and rights and duties. The entrusting party must supervise the entrusted party’s activities.

The entrusted party must process according to the agreement and cannot exceed the agreed purpose or method. When the arrangement is ineffective, invalid, revoked or terminated, it must return or delete the personal information and cannot retain it, subject to any governing-law issue that needs specific resolution.

The existing entrusted-processing page remains the concise statutory explanation; this guide owns the contract architecture and operating schedule.

Instructions, purpose and scope

Define permitted purposes and processing operations precisely enough to control conduct. Attach documented instructions and a method for authorized changes. State what the vendor may do to provide, secure, support and troubleshoot the service and what uses are prohibited.

Do not grant an unrestricted right to use customer personal information for “business purposes,” product development or artificial-intelligence training. If the vendor proposes an independent use, analyze it separately, update transparency and consent where required, and do not disguise it as an instruction.

Data schedule and minimization

List personal-information categories, sensitive information, data subjects, sources, systems, storage locations, transfers and retention. Identify minors’ data and regulated-sector information. Limit collection and access to what is necessary for the defined purpose.

The schedule should be operationally testable. Generic terms such as “all customer data” do not tell security, engineering or auditors what is permitted. Link the schedule to architecture and record-of-processing materials.

Security measures

Require measures proportionate to the information and risk, including access control, identity management, encryption where appropriate, logging, vulnerability management, secure development, backups, recovery, personnel confidentiality and physical security. Allocate responsibility for customer configuration and shared controls.

Set evidence requirements: policies, certifications, test summaries, remediation records and incident exercises. A certification can support diligence but does not prove every contractual control is operating or satisfy every PIPL duty.

Sub-entrustment

PIPL restricts an entrusted party from sub-entrusting without the entrusting party’s consent. The agreement should identify approved providers or establish prior notice, information and approval. Cover service location, function, personal-information categories and material changes.

Flow down purpose, instructions, security, confidentiality, incidents, rights assistance, audit and return/deletion duties. The primary vendor should remain accountable under the main agreement for promised performance; contractual allocation should not obscure the statutory role analysis.

Individual rights and complaints

Require the vendor to route requests and complaints promptly and assist the personal information processor with search, access, copy, correction, deletion, withdrawal and other applicable rights. Define identity-verification boundaries so the vendor does not disclose information without authority.

Test the workflow before launch. The contract should identify systems, response contacts, export formats, exceptions and evidence of completion.

Security incidents

Define what constitutes an incident and require notification without waiting for perfect certainty. Specify the initial channel, available facts, continuing updates, containment, forensic preservation, access, remediation and cooperation with notifications or reports.

Allocate decision-making for communications while preserving each party’s independent legal duties. Include cost and responsibility principles but do not let a liability dispute delay containment or legally required action.

Supervision, audits and records

Because the entrusting party must supervise entrusted processing, give it workable assurance rights. A tiered model can use questionnaires, document review, certifications, interviews, test reports and targeted onsite or technical audits based on risk.

Avoid an audit clause that is either meaningless or operationally unlimited. Address notice, frequency, confidentiality, security, regulator access, remediation and allocation of reasonable costs. Preserve findings, exceptions and closure evidence for compliance audits.

Retention, return and deletion

Set retention by data category and purpose. On expiry or termination, require return in an agreed usable format and deletion from active systems within a defined process, followed by backup expiration under a documented cycle and certification.

Identify any legal retention claimed by the vendor and isolate retained information from other use. A general right to keep anonymized data should define the standard and prohibit re-identification; pseudonymization alone does not necessarily remove information from PIPL.

Independent provision under Article 23

Where personal information is provided to another independent personal information processor, PIPL requires specific notice about the recipient and processing and generally separate consent. The recipient must process within the disclosed purpose, method and categories; changes can require consent again.

The commercial agreement should cover permitted use, independent compliance, security, rights coordination, onward provision, incidents and deletion, but should not falsely state that the recipient acts only on instructions.

Joint processing

Where parties jointly decide purposes and methods, PIPL requires an agreement on their respective rights and obligations and provides a framework affecting responsibility to individuals. Define decision rights, notices, consent, rights intake, security, incidents and liabilities.

Joint processing should not be selected merely to share responsibility. It reflects actual shared decision-making and can increase exposure.

Cross-border processing

Remote access from outside China, offshore support, overseas hosting and onward transfers may constitute provision abroad. Map the exporter, overseas recipient, purpose, data, individuals, volume and infrastructure, then determine the current security assessment, certification, standard-contract or exemption route.

Add the required overseas-recipient obligations, impact assessment, notice and separate-consent treatment where applicable. The separate cross-border guides remain the owners of thresholds and filing procedures.

DPA checklist

  1. Data-flow and role matrix by activity.
  2. Purpose, duration, method and documented instructions.
  3. Information and data-subject schedule.
  4. Minimization, retention and location.
  5. Technical and organizational security measures.
  6. Confidentiality and personnel access.
  7. Sub-entrustment approval and flow-down.
  8. Rights, complaints and regulator cooperation.
  9. Incident notification and evidence preservation.
  10. Supervision, audit, remediation, return and deletion.
  11. Independent provision and joint-processing modules where applicable.
  12. Cross-border mechanism and overseas-recipient terms.

Common mistakes

  • Copying a GDPR DPA without mapping PIPL roles.
  • Calling an independent recipient an entrusted processor.
  • Omitting purpose, method, categories or protection measures.
  • Allowing secondary use or AI training through vague language.
  • Treating certification as a substitute for supervision.
  • Permitting undisclosed sub-entrustment.
  • Waiting for a completed forensic report before incident notice.
  • Promising deletion without addressing backups and legal retention.
  • Assuming an Article 21 agreement is a cross-border transfer mechanism.

Sources

General legal information only; not legal advice for a particular vendor, system, transfer, incident or processing arrangement.

Legal source archive with indexed legislation and official records
Source register · primary authorities and verification
Sources & trust

How to use this guide

Editorial, AI and verification policies

This page is general information for orientation. It is not legal advice and does not create an attorney–client relationship.

Review the Editorial Policy, AI Content Policy, and Lawyer Verification Policy.

Consultation preparation

What to prepare before contacting counsel

Send a focused first package so counsel can check conflicts, understand scope, and identify urgent deadlines.

  • A concise timeline and the result you want to achieve.
  • Names of all parties and affiliates for a conflict check.
  • Key contracts, notices, correspondence, filings, or decisions.
  • Known deadlines, preferred language, location, and budget constraints.
Directory

Practice lawyer profiles

China-based listings shown first. Review profiles for practice, then submit an initial enquiry.

Status shown per profileFree initial intakeChina-first directory sort

Browse practice directory →

Cross-border legal details arranged for a prepared counsel enquiry
Next route · prepared enquiry

Move from orientation to a properly prepared legal brief.

Bring the parties, objective, relevant documents, chronology, known deadlines and the decision you need counsel to make.

Prepare your legal enquiry →

Need counsel on practice?

Review listed lawyer profiles and submit an initial enquiry. No obligation.