A manufacturer sends attendance data to a payroll vendor. A retailer pipes membership data into a marketing platform. A property manager hosts access-control face data in the equipment vendor's cloud. The common mistake is to think the duty left with the data. It did not. The personal-information handler remains responsible for what the vendor does, and usually remains liable to the individual if the vendor causes harm.

1. Draw the line first: processor, or a controller of its own

This is the start of the arrangement, and the step most often got wrong. The test is not the title of the contract. It is who decides the purpose and the means.

The cost of getting this wrong is not symmetrical. Treating a provision as a mere engagement leaves out the separate consent. That is hard to repair later. At intake, ask: will you use this project's data for any purpose outside this project? If the answer is not a clear no, treat it as a provision to a third party.

2. Three documents

1. A data-processing agreement

It may be an annex. A confidentiality clause in the main contract is not enough. Cover at least: purpose, term and means; types and scope of data; the vendor's security measures; no sub-processing without prior written consent; help with individual rights requests and the time to respond; how data is returned or deleted at the end, with proof; and how loss is shared.

2. A security-assessment record

A written conclusion at intake is the most direct evidence that the supervision duty was performed: qualifications and certifications, where the data sits and whether it leaves the country, access control, and any past incidents. Keep the form.

3. An updated notice and consent

If the arrangement is a provision to a third party, the privacy notice and the consent step have to name the recipient. This is often missed because it sits with product or marketing, not procurement.

3. An audit right that can be used

Most DPAs say the company may audit the vendor. To make that real, add three things: how it is started (notice, a yearly cap), what can be seen (types of logs and files, not "relevant materials"), and a substitute (a third-party audit report in place of a site visit).

The substitute is usually the realistic path. Large cloud vendors will not take a site audit from one customer. They will produce a standard report. Agree in advance which reports count.

4. Cross-border as a separate layer

If the vendor's servers are outside the mainland, or an overseas affiliate can see the data, a cross-border path is required (security assessment, standard-contract filing or certification, depending on type and scale). A DPA clause does not replace that. The intake questionnaire should ask, in so many words, where the data is stored and which overseas entities can reach it.

5. A place to start

A full system is not required on day one. Start with a vendor data register: every vendor that sees personal information, with type, volume, whether it is sensitive, whether it leaves the country, and whether the contract has a DPA. Priority then becomes obvious — a small share of vendors usually holds most of the exposure.

This is a general compliance path, not an opinion. The data types, the sector rules and the business model all have to be read together.

This note is general information from Shanghai Shen Yong Law Firm. It is not advice on a particular matter and does not create a retainer. For a specific question, write to info@sylegal.cn.
← Insights