Outsourcing Personal Data Processing: Essential Contract Clauses to Mitigate Risks
Discover the five critical clauses every outsourcing contract needs to protect personal data under Taiwan's Personal Data Protection Act and avoid hefty fines.
ChCharles TuFounder & CEO, WCTech · Former IPO General CounselWhen outsourcing personal data processing, standard contracts are insufficient. Taiwan's Personal Data Protection Act requires specific clauses addressing notification, lawful basis, security, oversight, and data return/destruction. Failing to include these can lead to significant legal and reputational damage. Ensure your outsourcing agreements are robust to comply with regulations and protect your business.
Outsourcing Personal Data Processing: Essential Contract Clauses to Mitigate Risks
Many companies believe a standard outsourcing agreement is sufficient when entrusting client data to third parties. However, with increasingly stringent data protection regulations, particularly the Personal Data Protection Act (PDPA), crucial clauses regarding the processing, use, and protection of personal data are often overlooked in outsourcing contracts. This oversight can expose businesses to substantial fines, damage their reputation, and even trigger litigation. Today, we will discuss five core clauses that must be included in outsourcing agreements under the PDPA framework.
1. Duty to Inform and Obtain Consent: Ensuring Client Peace of Mind and Your Legal Standing
When engaging a third party to process client personal data, the primary principle is to uphold the client's right to know. This means clearly informing clients about what data will be provided, to whom, and for what purpose before transferring their information to an outsourcing vendor. This is not only a "duty to inform" as required by Article 8 of the PDPA but also the cornerstone of building client trust.
Why is this important? Imagine clients discovering their data has been shared with a third-party vendor without their knowledge. Even if the outsourcing is legally compliant, it can lead to client dissatisfaction and suspicion. While cases directly resulting in a loss due to "failure to inform about outsourcing" are less common, if the outsourcing process involves other PDPA disputes, such as processing data beyond the original collection purpose, the "failure to fulfill the duty to inform" can significantly aggravate the court's finding of negligence against the company.
How to revise?
Your agreements with clients, or your privacy policy, should clearly state: "Our company may entrust third parties with the processing of your personal data, including but not limited to (list outsourcing items, e.g., cloud storage, customer service, data analysis, etc.). We will ensure that commissioned vendors comply with our company's privacy policy and the relevant provisions of the Personal Data Protection Act." Simultaneously, ensure that when collecting personal data from clients, you have obtained their consent or have another lawful basis.
Sample clause: "The client agrees that the company may entrust third parties (including but not limited to (list service types, e.g., cloud service providers, customer service centers, data analysis companies, etc.)) to process, use, or store the client's personal data for the specific purpose of (clearly list outsourcing purposes, e.g., providing cloud storage services, conducting customer service, data analysis, etc.). The company will ensure that the entrusted third parties strictly adhere to the Personal Data Protection Act and the company's privacy policy, and will exercise due diligence in safeguarding the confidentiality of the client's personal data."
2. Specific Purpose and Lawful Basis: Ensuring Data Processing Stays Within Bounds
Article 5 of the PDPA stipulates that the collection, processing, or use of personal data shall be within the necessary scope of the specific purpose for collection. This implies that the data entrusted to a third party for processing must be closely related to the "specific purpose" for which the data was originally collected and must not exceed the necessary scope of that purpose. When outsourcing data processing, defining this "specific purpose" becomes even more critical.
If the purpose for which the outsourcing vendor processes the data does not align with the original purpose of data collection, or if it exceeds the necessary scope, the entire data processing flow may violate the PDPA. For example, if client data was collected to provide Service A, but the outsourcing vendor uses this data for marketing related to Service B, it could constitute processing beyond the original purpose.
Courts strictly examine whether the collection, processing, and use of data comply with the "specific purpose" and "necessary scope" when adjudicating PDPA cases. Although the "111年度憲判字第13號" (Judicial Yuan Interpretation No. 13 of 2022) judgment primarily discusses the non-consensual provision of health insurance data, its core spirit emphasizes that the use of personal data must have a clear legal basis and comply with the principle of proportionality, and cannot be arbitrarily expanded. This serves as a reminder that outsourcing agreements must clearly stipulate that the outsourcing vendor may only process data based on the "specific purpose" defined by us.
How to revise?
In the outsourcing agreement, clearly list the "specific purposes" for which data will be outsourced and require the outsourcing vendor to commit to processing data only within this scope. Also, stipulate that if the outsourcing vendor needs to use the data for other purposes, they must obtain our written consent in advance, and such consent must comply with relevant PDPA provisions.
Sample clause: "The outsourcing vendor agrees to process and use the client's personal data solely for the specific purposes set forth in this Agreement (as detailed in Appendix 1 hereto). The outsourcing vendor shall not process, use, or disclose the client's personal data for any other purpose, or beyond the necessary scope of the aforementioned specific purposes. If the outsourcing vendor intends to use the client's personal data for purposes other than those stipulated in this Agreement, prior written consent from our company must be obtained, and such consent shall comply with the relevant provisions of the Personal Data Protection Act."
3. Security Safeguards and Confidentiality Obligations: The Last Line of Defense Against Data Breaches
Article 27 of the PDPA requires non-governmental organizations to take appropriate security measures to prevent personal data from being stolen, altered, damaged, lost, or leaked. When we outsource data processing, it's akin to entrusting our data to another party's care. Therefore, the outsourcing vendor's security capabilities become a critical component of our compliance. The contract must clearly require the outsourcing vendor to possess adequate security measures and undertake corresponding confidentiality obligations.
In practice, many companies face regulatory fines or client claims due to data breaches caused by the negligence of their outsourcing vendors. For instance, in the case between "a service provider" and "the defendant in that case," although the judgment summary did not detail the specific cause of the data breach, if the breach occurred due to the outsourcing vendor's failure to properly safeguard the data, the contracting party (us) might bear joint liability due to our obligation to supervise the vendor.
How to revise?
The contract should require the outsourcing vendor to describe the information security measures they employ, such as encryption technologies, access control, and regular security audits. It should also clearly stipulate that if a data breach occurs due to the outsourcing vendor's negligence, the vendor shall bear full liability for damages and cooperate with us in subsequent actions (e.g., notifying affected clients, cooperating with regulatory investigations).
Sample clause: "The outsourcing vendor shall implement all reasonably feasible technical and organizational measures to ensure the security of the client's personal data, preventing unauthorized access, processing, use, modification, destruction, loss, or leakage. The outsourcing vendor shall comply with the company's information security policies and relevant regulations. If the client's personal data undergoes the aforementioned events due to the vendor's intentional act or negligence, the outsourcing vendor shall be liable for damages to the company and affected clients, and shall immediately notify the company and fully cooperate with the company in handling related matters."
4. Supervision and Audit Rights: Ensuring Vendor Compliance
Article 27 of the PDPA also implies a duty of supervision by the contracting party over the commissioned party. We cannot simply hand over data and disengage; we must have the right to verify that the outsourcing vendor is indeed adhering to the data protection clauses in the contract. This is akin to how internal legal or cybersecurity departments regularly audit data processing activities across various departments.
If we do not stipulate supervision rights, and a problem arises, it may be difficult to obtain evidence of the outsourcing vendor's breach of contract or even to understand the root cause of the issue. This places us in a highly disadvantageous position when facing regulatory investigations or client inquiries.
How to revise?
The contract should clearly state that we (or our designated third party) have the right to audit the outsourcing vendor's data processing activities within a reasonable timeframe, including requesting relevant documentation and conducting on-site inspections. It should also stipulate that the outsourcing vendor is obligated to cooperate with our audit requests and provide necessary information promptly.
Sample clause: "The company reserves the right, within a reasonable timeframe, to audit the outsourcing vendor's operations related to the processing of client personal data, including but not limited to requesting relevant security measure certifications and conducting on-site inspections. The outsourcing vendor shall unconditionally cooperate with the company's audit requests and provide necessary assistance. If the audit reveals any violation of this Agreement or the Personal Data Protection Act by the outsourcing vendor, the vendor shall immediately rectify the situation within the timeframe specified by the company's instructions."
5. Contract Termination and Data Return/Destruction: Ensuring Final Data Disposition
Contract termination signifies the end of the business relationship. At this stage, the final disposition of the personal data we entrusted for processing becomes paramount. We must ensure that after contract termination, the outsourcing vendor does not continue to retain, process, or use this data, thereby preventing new data protection risks.
If, after contract termination, the outsourcing vendor fails to return or destroy the data as agreed, it constitutes not only a breach of contract but also potentially ongoing data protection infringements. Especially when we request proof of data destruction, if the vendor cannot provide it, we cannot be certain that the data has been securely removed.
How to revise?
The contract should clearly stipulate that upon termination, expiration, or mutual agreement to terminate the contract, the outsourcing vendor shall, within a specified period, return all personal data provided by us (including backup data) in a secure and verifiable manner, or destroy it according to our instructions, and provide proof of destruction. It should also stipulate that the outsourcing vendor shall delete all copies of personal data related to our clients from its systems.
Sample clause: "Upon termination, expiration, or termination for any reason of this Agreement, the outsourcing vendor shall, within (e.g., seven business days), return all client personal data provided by the company (including but not limited to original data, copies, backup data, etc.) to the company in a secure and verifiable manner, or, at the company's written instruction, destroy said data and provide satisfactory proof of destruction. The outsourcing vendor shall also ensure that no information related to the company's client personal data remains in its systems."
One-Sentence Checklist
- Does the outsourcing contract clearly inform clients about data outsourcing and obtain their consent?
- Does the contract clearly define the "specific purpose" of outsourcing and prohibit exceeding this scope?
- Does the contract require the outsourcing vendor to implement adequate security measures and specify liability for data breaches due to negligence?
- Does the contract grant us the right to supervise and audit the vendor's data processing activities?
- Does the contract stipulate that upon termination, the vendor must return or destroy all personal data and provide proof?
A Common Misconception
Misconception: Simply stating in the contract that "the outsourcing vendor shall comply with the PDPA" is foolproof.
Analysis: While this is a basic requirement, it is too vague. The PDPA covers numerous aspects, including collection, processing, use, security, notification duties, and specific purposes. A single sentence stating "shall comply with the PDPA" does not specifically define the rights and obligations of the parties or require the vendor to take concrete actions. In case of a dispute, this phrase is unlikely to serve as effective legal grounds and cannot effectively prevent risks. The requirements of the PDPA must be translated into specific, actionable clauses within the contract.
FAQ
What if the outsourcing vendor refuses to sign these clauses?
This is a common challenge. If an outsourcing vendor is unwilling to sign a contract that includes comprehensive data protection clauses, it can be a red flag. It may indicate insufficient awareness of data protection or internal processes that do not meet regulatory requirements. In such a situation, you need to assess: 1) the sensitivity and volume of personal data the vendor handles; 2) the potential risks and impact of a data breach; and 3) whether alternative, more compliant vendors are available. In some cases, you may need to consider changing vendors or engaging in deeper discussions with the current vendor, explaining the importance of regulatory requirements and seeking a compromise (e.g., providing a more detailed standard contract template for them to sign).
Our company is small and doesn't handle large volumes of data. Do we still need to be this rigorous?
Yes, the PDPA applies regardless of company size. The PDPA protects "personal data," and regardless of the volume, a breach or improper use can cause harm to individuals, leading to legal liability. Small businesses often have limited resources, making it even more crucial to standardize contract clauses and institutionalize risk management mechanisms to achieve maximum compliance benefits at the lowest cost. It is better to prevent issues beforehand than to spend more resources handling crises afterward.
If the contract states the vendor must comply with the PDPA, but the vendor violates it, is our company responsible?
This depends on the specific circumstances. Generally, if we have exercised the due diligence expected of a prudent administrator—for example, by carefully selecting the outsourcing vendor, signing a contract with appropriate data protection clauses, and conducting reasonable supervision—we may not be fully responsible if the vendor violates the law. However, if we failed to exercise our duty of supervision in the contract or chose a vendor clearly lacking in security capabilities, the court might find us partially negligent, thus holding us partially liable. Therefore, both the supervision clauses in the contract and the actual supervisory actions are very important.
What is a "specific purpose"? How should we define it?
A "specific purpose" refers to the concrete and clear objective that we aim to achieve when collecting, processing, or using personal data. Examples include "customer management and service," "providing online shopping services," "sending marketing information (with client consent)," and "contract performance management." When defining specific purposes, they should be as concrete as possible and avoid being overly vague. For instance, instead of just writing "business needs," it should specify "to provide the goods you have ordered and related after-sales services." In outsourcing agreements, we must clearly communicate these specific purposes for data collection to the outsourcing vendor and stipulate that the vendor may only process data within this scope.
How can we judge if the security measure certifications provided by the outsourcing vendor are adequate?
This requires professional judgment. You can ask the vendor to provide their information security policy, international certifications such as ISO 27001 (if available), or their internal security audit reports. If your company lacks sufficient in-house expertise for evaluation, consider engaging external information security consultants. The key is to ensure that the measures taken by the vendor can reasonably prevent common data breach risks, such as unauthorized access, malware attacks, and physical security vulnerabilities.
If the outsourcing vendor is an overseas company, are there any special considerations regarding PDPA applicability?
If the outsourcing vendor is an overseas company but processes personal data of individuals within Taiwan (e.g., data of Taiwanese customers), Taiwan's PDPA still applies. In such cases, in addition to the five core clauses mentioned above, special attention should be paid to: 1) the rigor of the data protection laws in that country; 2) how to ensure the enforceability of Taiwanese legal judgments; and 3) clearly stipulating the application of Taiwanese law and the jurisdiction for dispute resolution in the contract. Furthermore, cross-border data transfers must comply with Article 20 of the PDPA regarding international transfers of personal data by non-governmental organizations, such as obtaining the data subject's consent or having another lawful basis.
- §111年度憲判字第13號
This article draws on the following published Taiwan court judgments; the original judgment text governs the facts and holdings of each case.
This article is general legal information, not legal advice for any specific case. Please consult a qualified lawyer for your situation.