Introduction: Two Contract Models for Data Transfers
Foreign companies transferring personal information from China to overseas recipients must enter into a legally binding data transfer agreement. They have two primary options: the CAC-prescribed Standard Contractual Clauses (SCCs) — a template agreement that cannot be substantively modified — or an ad-hoc agreement (a custom-drafted data transfer contract negotiated between the parties). While SCCs offer speed, regulatory acceptance, and lower legal costs, ad-hoc agreements provide greater flexibility to address complex commercial arrangements and specific risk profiles. This comparison examines ten critical dimensions to help foreign companies determine which contract model best suits their data transfer needs.
The Measures on the Standard Contract for Cross-border Transfer of Personal Information (effective June 1, 2023) prescribe a mandatory template for SCC filings under the PIPL. The template is published by the CAC and includes specific clauses covering the purpose and scope of data transfer, data subject rights, the overseas recipient’s obligations, liability allocation, termination conditions, governing law, and dispute resolution. The SCC template is designed to be used as-is — the CAC explicitly states that “the parties shall not substantively modify the standard clauses.” However, the parties are permitted to add supplementary clauses that do not conflict with the standard terms.
An ad-hoc agreement, by contrast, is a custom-negotiated data transfer contract that incorporates PIPL requirements but is drafted to fit the specific commercial relationship, data types, risk allocation preferences, and operational realities of the parties. Ad-hoc agreements are less commonly used because they carry higher legal costs and potentially greater regulatory scrutiny — the CAC may question whether an ad-hoc agreement provides equivalent protections to the standard SCC template.
Key Differences: SCC Template vs Ad-Hoc Agreement
| Dimension | CAC Standard Contractual Clauses (SCCs) | Ad-Hoc Agreement |
|---|---|---|
| Regulatory approval status | Pre-approved template — minimal CAC review upon filing | Not pre-approved — subject to CAC scrutiny during filing; may trigger additional review |
| Negotiation time | Minimal (no substantive negotiation permitted) | Lengthy — 4–12 weeks of negotiation between parties’ legal teams |
| Flexibility | Low — must use CAC template as-is; supplementary clauses only if non-conflicting | High — fully customisable to specific data flows, risk profiles, and commercial arrangements |
| Legal costs | RMB 30,000–80,000 (template review + minor supplementary clauses) | RMB 100,000–300,000 (full drafting, negotiation, and regulatory risk assessment) |
| CAC filing complexity | Simple — template recognised, minimal documentation beyond signed SCC | Complex — must demonstrate to CAC that ad-hoc agreement provides equivalent protections; may require legal opinion letter |
| Suitable for | Straightforward data transfers (routine HR data, standard B2B processing) | Complex arrangements (joint controllership, multi-party data flows, novel processing activities) |
When the SCC Template Is the Right Choice
The CAC Standard Contractual Clauses are the default and recommended choice for most foreign companies for the following reasons:
- Speed to compliance: The SCC template is ready-to-use. Once the parties fill in the appendices (identifying the specific data transferred, the recipient’s details, and technical security measures), the contract is complete. Filing with the provincial CAC is straightforward because the regulator is already familiar with the template — there is no need to review custom clauses for PIPL compliance.
- Lower legal costs: Because the substantive clauses cannot be modified, the legal work is limited to: (a) ensuring the appendices accurately describe the data flows, (b) drafting any supplementary clauses (such as additional indemnification or confidentiality provisions) that do not conflict with the standard terms, and (c) managing the filing process.
- Regulatory certainty: The CAC has explicitly endorsed the SCC template. A properly filed SCC with complete appendices and a compliant DPIA will almost certainly be accepted. There is no risk of the CAC rejecting the agreement because it lacks required clauses — the template inherently includes all PIPL-mandated provisions.
- Third-party beneficiary rights: The SCC template includes standard third-party beneficiary clauses that give data subjects the right to enforce the SCC directly against the overseas recipient. This is a PIPL requirement (Article 39), and the template handles it cleanly. An ad-hoc agreement must create equivalent third-party rights, which requires careful drafting in jurisdictions that may not recognise third-party beneficiary concepts.
- Multi-recipient efficiency: If a foreign company transfers data to multiple overseas recipients (e.g., a global payroll provider, a cloud service provider, and an analytics platform), the SCC template can be used for each recipient with minimal modification — just update the recipient details and data categories in the appendices.
When an Ad-Hoc Agreement May Be Preferable
Despite the advantages of SCCs, there are scenarios where an ad-hoc agreement is the better — or only viable — choice:
- Joint controllership arrangements: When the Chinese data processor and the overseas recipient are joint controllers of the personal information (both determining the purposes and means of processing), the SCC template’s processor-controller framework does not fit. The template assumes a controller-to-processor or controller-to-controller relationship with clear boundaries. Ad-hoc agreements can properly allocate joint controllership responsibilities.
- Multi-party data flows: When data flows involve more than two parties — for example, a Chinese data processor transfers data to an overseas processor, who then sub-processes through a third-party sub-processor in another jurisdiction — the SCC template may not adequately cover the multi-party chain. An ad-hoc agreement can define the obligations of all parties in a single contract.
- Novel or unusual processing activities: If the cross-border data transfer involves processing activities that are not contemplated by the SCC template (such as AI/ML training data flows, biometric data for research, or complex data analytics with onward transfer), an ad-hoc agreement provides the flexibility to draft bespoke clauses addressing the specific risks and obligations.
- Commercial risk allocation: The SCC template has fixed liability and indemnification provisions that may not align with the parties’ commercial agreement. For example, the template imposes joint and several liability on both parties for damages caused to data subjects. In a commercial relationship where the overseas recipient is better positioned to manage data security risks, the parties may prefer an ad-hoc agreement with different liability allocation.
- Survival and termination provisions: The SCC template has specific provisions about what happens when the contract terminates — data must be deleted or returned, and the recipient must certify deletion. For complex multi-year data processing relationships, an ad-hoc agreement can provide more nuanced termination and transition provisions, including phased data deletion, audit rights post-termination, and data escrow arrangements.
Supplementary Clauses: Extending the SCC Without Breaking It
Many foreign companies use the SCC template as a foundation and add supplementary clauses to address specific commercial or operational needs. The CAC’s regulations permit this, provided the supplementary clauses do not conflict with or undermine the standard clauses.
| Supplementary Clause Type | Permissible? | Example |
|---|---|---|
| Additional confidentiality obligations | Yes — strengthens existing clause | “Recipient shall maintain confidentiality for 5 years post-termination” |
| Higher data security standards | Yes — exceeds minimum requirements | “Recipient shall maintain ISO 27001 certification throughout the contract term” |
| More frequent audit rights | Yes — supplements annual audit clause | “Processor may conduct audits at 6-month intervals” |
| Limitation of liability (lower than SCC) | No — conflicts with SCC’s joint liability framework | “Either party’s liability shall not exceed RMB 100,000” — rejected |
| Waiver of data subject rights | No — violates PIPL mandatory provisions | “Data subjects waive right to compensation under the SCC” — rejected |
| Governing law other than PRC law | No — SCC requires PRC law for data subject claims | “This agreement is governed by the laws of Singapore” — rejected |
Regulatory Scrutiny: How the CAC Reviews Each Model
The CAC’s approach to reviewing the two contract models differs fundamentally:
SCC review: When an SCC is filed, the provincial CAC checks: (a) whether the template is the correct, current CAC-prescribed version, (b) whether the appendices are complete and accurately describe the data transfer, (c) whether the DPIA supports the transfer, and (d) whether data volume thresholds are correctly assessed (to ensure the SCC is the appropriate mechanism). The review is procedural — the CAC does not re-evaluate the substantive terms of the SCC because it has already pre-approved the template. This is why SCC filings typically proceed without objection within the 15-working-day review period.
Ad-hoc agreement review: When an ad-hoc agreement is filed (for transfers that qualify for SCC eligibility but where the parties have chosen an ad-hoc model), the provincial CAC must review whether the agreement provides equivalent protections to the CAC standard template. This is a substantive review that involves: (a) clause-by-clause comparison with the SCC template to identify gaps, (b) evaluation of supplementary clauses for PIPL compliance, (c) assessment of whether the governing law and dispute resolution provisions adequately protect data subjects, and (d) review of third-party beneficiary rights. The CAC may request supplementary materials, including a legal opinion letter from China-qualified counsel confirming the agreement’s equivalence. This can extend the filing timeline from 15 working days to 30–45 working days or longer.
Practical Guidance: If you are considering an ad-hoc agreement instead of the SCC template, prepare a “clause mapping” document that maps each provision of your ad-hoc agreement to the corresponding clause in the SCC template, highlighting any deviations and providing legal justification for each deviation. This document, submitted as part of the filing, demonstrates good faith and significantly reduces the CAC’s review burden.
Cost-Benefit Analysis: Choosing the Right Model
The decision between SCCs and an ad-hoc agreement involves a trade-off between flexibility, cost, and regulatory certainty:
| Scenario | Recommended Model | Rationale |
|---|---|---|
| Routine HR data transfer to overseas HQ | SCCs | Simple controller-to-controller transfer; SCC template fits perfectly |
| Customer data to global CRM provider | SCCs + supplementary clauses | SCC template + additional data security and audit provisions |
| Joint controllership with overseas partner | Ad-hoc agreement | SCC template does not accommodate joint controllership properly |
| Multi-party supply chain data flow | Ad-hoc agreement | Need to define obligations across 3+ parties in one contract |
| AI/ML training data with onward transfer | Ad-hoc agreement | Novel processing; need bespoke clauses for data use limitations |
| Data transfer to low-risk jurisdiction with strong DPA | SCCs | Low regulatory risk; SCC provides sufficient protections |
| High-value data with complex liability allocation | SCCs + supplementary clauses (if liability compatible) or Ad-hoc | Assess whether supplementary clauses can achieve desired allocation without conflicting with SCC template |
Hybrid Approach: SCC Framework with Custom Addendums
For many foreign companies, the optimal approach is a hybrid model: use the CAC SCC template as the base agreement, supplemented by a custom addendum that addresses specific commercial or operational requirements without modifying the standard clauses. This approach combines the regulatory certainty of SCCs with the flexibility to add:
- Service level agreements (SLAs): Define data processing performance standards, uptime guarantees, and response times for data subject requests.
- Detailed data breach notification procedures: Specify notification timelines, contact points, and breach response coordination beyond the SCC template’s general provisions.
- Insurance requirements: Require the overseas recipient to maintain cyber liability or data breach insurance at specified coverage levels.
- Business continuity and disaster recovery: Define data backup, recovery, and business continuity requirements specific to the data processing arrangement.
- Sub-processor management: If the overseas recipient engages sub-processors, define the approval process, notice requirements, and contractual flow-down of SCC obligations.
The hybrid approach works well because the addendum is explicitly referenced as a supplementary document in the SCC, and the CAC’s review focuses on ensuring the addendum does not conflict with the standard clauses. Most foreign companies using SCCs eventually adopt this model once they gain experience with the base template.
Practical Recommendations for Foreign Companies
- Start with SCCs. Unless your data transfer arrangement clearly falls outside the SCC template’s scope (joint controllership, multi-party flows, novel processing), use the CAC SCC template. It is faster, cheaper, and carries the lowest regulatory risk.
- Keep a supplementary clause register. Before adding supplementary clauses to an SCC, document each proposed clause and confirm it does not conflict with the standard terms. Maintain this register as part of your compliance documentation for CAC inspection.
- Use separate annexes for complex data categories. If you transfer multiple categories of personal information to different recipients under different arrangements, use separate SCC annexes for each data category rather than trying to cover everything in one agreement. This simplifies future amendments when data flows change.
- Negotiate addendums early. If you know you will need supplementary provisions (SLAs, insurance, sub-processor controls), negotiate the addendum simultaneously with the SCC template — do not sign the SCC first and try to add provisions later, as the signed SCC creates a baseline that the other party has little incentive to modify.
- Seek legal advice before deviating from the template. If you believe your arrangement requires an ad-hoc agreement, obtain a written legal opinion from China-qualified counsel confirming that the SCC template cannot accommodate your arrangement and that the proposed ad-hoc agreement provides equivalent protections. This opinion is invaluable if the CAC questions the ad-hoc model during filing.
This article is for informational purposes only and does not constitute legal advice. Foreign companies should consult qualified Chinese legal counsel for advice tailored to their specific circumstances. First published on china-gateway360.com. For more guidance on China data transfer agreement models, explore our data transfer contract resources or contact our China data compliance team. Ready to draft your data transfer agreement? Launch Your China Business with Confidence.
