Meaning
Statutory provision within the Chinese privacy framework defines the obligations of parties who jointly determine the purposes and methods of data processing. When entities fall under article 20 pipl, they must agree on their respective rights and duties through a formal contract. This agreement ensures that individuals can exercise their rights against any of the involved parties.
If the processing causes harm to the data subject, the entities bear joint and several liability under the law.
Joint Responsibility
Contractual arrangements between multiple processors specify how personal information is handled and protected. This requirement ensures that no gap in accountability exists when data moves between partners. Under article 20 pipl, the primary focus is the protection of the individual whose data is at stake.
The law mandates that the core content of the agreement must be available to the person whose information is processed.
Processor Contract
Written agreements provide the legal basis for operational coordination between data controllers. Parties operating under article 20 pipl find that a lack of clear documentation leads to administrative penalties from the Cyberspace Administration of China. The contract defines who handles requests for data deletion or correction.
It also outlines the reporting chain for security incidents.
Liability Allocation
Legal rules dictate that all controllers in a joint arrangement remain responsible for the total damage caused by a breach. While article 20 pipl allows parties to distribute financial risks internally through indemnity clauses, such private agreements do not shield them from public claims. Regulatory authorities look at the actual control over the data rather than just the text of the contract.
The arrangement ensures that a victim can seek full compensation from whichever entity is easiest to reach. Financial recovery between the controllers then happens through separate civil litigation.