The handler decides purpose and means; the entrusted party does not become the handler by hosting servers.
PIPL’s ‘personal information handler’ is the organisation or individual that independently decides the purpose and means of processing. That is closer to a GDPR controller than to a processor. An entrusted processor (vendor) processes per the handler’s instructions under an entrusted-processing contract — see that sibling. Joint processing is a different relationship. Overseas handlers targeting PRC individuals may still be handlers and may need a PRC representative. Do not assume the Chinese WFOE is the only handler if HQ sets the purposes.
4 questions before you choose the route.
This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.
Who decided the purpose?
Product, marketing, HR, or a group policy.
PurposeWho picked the tools?
Which vendor and which fields.
MeansIs there an entrusted contract?
Vendor vs joint vs separate handlers.
ContractIs HQ extra-territorial?
Overseas decision-makers can be handlers.
ReachWorking rule: Map the regulated role before marketing or launch in China.
The signal ledger.
These facts move the question beyond a label and into a product, money-flow and control analysis.
Bring a compact evidence docket—not a pitch deck.
Give a compliance team or counsel the operating facts that reveal the perimeter.
Questions people ask before they build.
Short answers for orientation. The right result can change with the service model and current rules.
Is a cloud vendor always entrusted?
If it only hosts to instruction, usually yes. If it mines data for its own models, handler risk.
Do we need a PRC representative?
Overseas handlers in scope may. That is a fact-specific PIPL Art. 53-style question.
Primary authorities
Reviewed sources support orientation, not a fact-specific assessment.
