— A Comprehensive Analysis of Data Asset Ownership and Compliance Clauses
In the autumn of 2023, a Beijing-based MarTech (marketing technology) company that had been operating for five years arrived at a crossroads. The company had accumulated behavioral data from over 8 million end users. After cleansing, labeling, and modeling, this data became the company’s single most critical asset—indeed, one could say the company itself was a “data processing factory.” A listed company set its sights on these data assets and made a fairly attractive acquisition offer.
However, the acquisition due diligence exposed a fatal problem: the provisions in the company’s Privacy Policy concerning the “collection, use, and sharing of user data” were vague and ambiguous, and a large volume of user data had been collected without clear records of user consent. More seriously, the company had never established a data classification and grading system; users’ behavioral trajectory data, device identifier data, and personally identifiable information were stored commingled in a single database without any access control measures. The acquirer required the company to prove its “lawful ownership or right to use” the 8 million users’ data. The founder team searched through all their servers but could not find any legal documents satisfying this requirement.
Ultimately, the acquisition was downgraded from a full acquisition to an “asset acquisition plus retention of key personnel,” with the valuation shrinking by more than 60%. The investors not only failed to realize the expected exit returns, but were instead dragged into prolonged negotiations with the acquirer over data compliance issues. And this question of “who owns the data assets” is precisely the pitfall that the vast majority of software startups most easily fall into during their early development—and the most fatal one at that.
This case leads us to a fundamental legal question: In the digital economy era, who actually owns the user data held by a software company? What rights does the company enjoy over such data? And how will the boundaries of these rights affect investment and M&A transactions?
I. Who Truly Owns the Data? — The Legal Maze of Data Asset Ownership
1. Is “Data Ownership” a Pseudo-Concept?
First, we need to dispel a widespread misconception: under China’s current legal system, there is no clear, widely recognized concept of “data ownership.” This stands in stark contrast to the intuitive understanding of many people—especially entrepreneurs and investors.
Although Article 127 of the PRC Civil Code provides that “where the law provides for the protection of data and network virtual property, such provisions shall apply,” this article is a reference clause (meaning it does not itself create specific substantive rights but rather points to the provisions of other laws). Neither the Data Security Law nor the Personal Information Protection Law uses the term “data ownership.” This means: under the current law, data is not a “thing” with a clearly defined ownership, but a special asset that must be legally defined across multiple dimensions.
This is not to say that companies have no rights over data. On the contrary, the law provides a protective framework for enterprises’ legitimate interests in data through multiple dimensions: the dimension of personality rights centered on personal information protection, the dimension of anti-unfair-competition centered on trade secret protection, the dimension of copyright and database rights centered on intellectual property, and the dimension of data transaction and usage rights centered on contract law. Understanding the interplay among these dimensions is the prerequisite for correctly grasping the issue of data asset ownership.
2. Personal Data: The User Is the Subject, the Enterprise Is the Processor
For data containing personal information, the Personal Information Protection Law establishes a system of “rights of individuals in personal information processing activities,” including the right to know, the right to decide, the right to access and copy, the right to rectify and supplement, and the right to delete. This means: the subject of personal information is the user themselves, not the enterprise that collected it. Here, the enterprise plays the role of a “personal information processor”—processing personal information on the basis of the user’s consent or other legitimate grounds provided by law.
This has a direct and far-reaching impact on investment transactions: when a company claims that its core asset is “data of 8 million users,” this does not legally mean that the company “owns” the personal information of 8 million users. What the company owns is a right to process such data formed on the basis of user authorization—a right that is bounded, conditional, and subject to the user’s right to withdraw consent at any time (Article 15 of the Personal Information Protection Law).
By the same token, for data that does not constitute personal information (such as statistical data that has undergone effective anonymization, or aggregated behavioral data without personal identifiers), the enterprise’s scope of rights is much broader. However, it should be noted that “anonymization” is subject to strict legal standards—anonymization as defined in Item 4 of Article 73 of the Personal Information Protection Law means “the process by which personal information is processed so that a specific natural person cannot be identified and the information cannot be restored.” Simply removing names and ID numbers does not constitute anonymization in the legal sense.
3. The Rights Structure of a Company’s Data Assets
Based on the comprehensive existing legal framework, the interests a company enjoys over the data assets it holds can be understood at the following levels:
| Data Tier | Basis of Rights | Principal Limitations |
|---|---|---|
| Raw personal information | User authorization (consent) | User may withdraw consent, request deletion, etc. |
| Desensitized/de-identified data | Processing investment by the data processor | Legal prohibition on re-identification |
| Anonymized data | Enterprise’s own assets (approximating “data ownership”) | Extremely high standard for irreversible technical implementation |
| Labeled data/training data | Labor input + contractual agreement | Legality review of the original data source |
| Data analysis results/models | Copyright, trade secrets, contract | Traceability of input data compliance |
From this table it is clearly evident that China’s legal system adopts a “layered protection” model for the protection of data asset rights—the closer the data is to raw personal information, the more restricted the enterprise’s disposal rights; the closer the data is to deeply processed knowledge products, the more the enterprise’s rights approximate ownership. This provides an important legal coordinate for the design of data asset clauses in investment agreements.
II. Compliance Is the “Title Deed” of Data Assets — Core Obligations in Personal Information Processing
1. The Security Safeguard Obligation Under Article 51 of the Personal Information Protection Law
Article 51 of the Personal Information Protection Law sets forth the security safeguard obligation of personal information processors: “A personal information processor shall, in light of the purposes and means of processing personal information, the types of personal information, the impact on individuals’ rights and interests, and the potential security risks, take the following measures to ensure that the processing activities comply with the provisions of laws and administrative regulations and to prevent unauthorized access, as well as disclosure, tampering, or loss of personal information: (1) formulate internal management systems and operating procedures; (2) implement classified management of personal information; (3) adopt corresponding technical security measures such as encryption and de-identification; (4) reasonably determine the operating permissions for personal information processing and conduct regular security education and training for employees; (5) formulate and organize the implementation of emergency response plans for personal information security incidents; and (6) other measures required by laws and administrative regulations.”
For software startups, this article imposes comprehensive compliance requirements ranging from management systems to technical measures. In particular, the two requirements of “implementing classified management of personal information” and “adopting technical security measures such as encryption and de-identification”—one of the core reasons the aforementioned MarTech company suffered major setbacks in the M&A was the complete absence of these two compliance requirements.
It is particularly worth noting that Article 69 of the Personal Information Protection Law provides for the presumption-of-fault liability for infringement of personal information rights and interests: “Where the processing of personal information infringes upon the rights and interests of personal information and causes damage, and the personal information processor cannot prove that it is without fault, it shall bear tort liability such as damages.” This means that in litigation, the burden of proof is reversed—the enterprise must prove its own absence of fault, rather than the victim having to prove the enterprise’s fault. This is a burden-of-proof allocation extremely unfavorable to enterprises, further underscoring the importance of establishing a compliance management system.
2. The Full-Lifecycle Security Obligation Under Article 27 of the Data Security Law
Article 27 of the Data Security Law provides: “Data processing activities shall be conducted in accordance with the provisions of laws and regulations; a full-process data security management system shall be established and improved, data security education and training shall be organized, and corresponding technical measures and other necessary measures shall be taken to safeguard data security. Where data processing activities are conducted through the internet or other information networks, the aforementioned data security protection obligations shall be performed on the basis of the cybersecurity classified protection system.”
This article extends the data security obligation to the full lifecycle of data processing—from collection, storage, use, processing, transmission, provision, to disclosure, each link requires corresponding security management systems and technical measures as safeguards. For most software startups, this means data security must be incorporated into architectural considerations at the early stage of product design, rather than “patching” it after the product goes live.
3. The Institution-Building Obligation Under Article 23 of the Cybersecurity Law
Article 23 of the Cybersecurity Law requires network operators to “formulate internal security management systems and operating procedures, designate a person responsible for cybersecurity, and implement cybersecurity protection responsibilities.” Although this obligation appears general, in practice it constitutes a fundamental threshold for the legitimacy of data assets. A company that lacks even basic cybersecurity management systems will find it difficult to convince investors or acquirers that its data asset processing has a legitimate basis.
Statute Express
Article 51 (security safeguard obligation), Article 66 (administrative penalty), and Article 69 (presumption of fault liability) of the Personal Information Protection Law
Article 27 of the Data Security Law (full-process security management system)
Article 23 of the Cybersecurity Law (cybersecurity classified protection system)
4. Compliance Investment: From Cost to Asset Value
We often hear entrepreneurs complain that compliance costs are too high—”A large company spends millions on a single privacy compliance system; where would a Series A company like ours get that kind of money?” This puzzlement has its merits, but it also reflects a fundamental cognitive bias: compliance investment is not a cost, but an investment in “confirming the rights” of data assets. Just as real estate requires a title deed to prove ownership, data assets also require a compliance system to prove their legitimacy—data without a compliance system is like a house without a title deed, whose transaction value will be significantly discounted in law.
More importantly, administrative penalties for major data compliance deficiencies are being intensified. Article 66 of the Personal Information Protection Law provides that serious violations may be subject to a fine of not more than RMB 50 million or 5% of the turnover of the preceding year. For many software startups, such a penalty amount is sufficient to directly destroy the company.
III. The “Data Portability Right” — An Underestimated Transaction Variable
1. What Is the Data Portability Right?
Paragraph 3 of Article 45 of the Personal Information Protection Law provides: “Where an individual requests the transfer of their personal information to a designated personal information processor, and the conditions prescribed by the national cyberspace affairs department are met, the personal information processor shall provide the means for such transfer.” This is the so-called “data portability right”—the user’s right to require the company to transfer their personal information to another company.
The data portability right has a far-reaching impact on investment transactions in the software industry. It means: a company’s data assets do not possess the high degree of exclusivity and stability of a factory building or equipment—if users exercise the portability right, the company’s data assets may be substantially drained away within a short period. This constitutes a unique risk factor for the valuation of data-driven companies.
2. The Impact of the Data Portability Right on Investment Valuation
In investment due diligence and valuation, the data portability right affects the company’s data asset value along at least the following three dimensions:
- User Stickiness and Switching CostsIf a competitor’s product experience far surpasses that of the company, and users’ switching costs are sufficiently low, the data portability right may accelerate user migration. The company’s technical user stickiness (such as the closed nature of data formats) will lose its protective effect in law.
- Assessment of the “Substitutability” of Data AssetsIf the company’s core value lies in the users’ data itself (rather than the unique models and analytical capabilities built upon such data), then the data portability right means that this data is theoretically substitutable—users may request that the data be transferred to a competitor.
- Obstacles to Data Integration in M&AIn an M&A transaction, the acquirer hopes to integrate the acquired company’s user data into its own systems. But if the user privacy policy does not adequately disclose such data sharing arrangements, or the corresponding user consent was not obtained, the exercise of the data portability right may cause a substantial shrinkage of the acquired company’s data assets.
3. How to Address Data Portability Right Risks in Investment Agreements?
- Representations and Warranties ClauseRequire the founder to warrant that the company’s privacy policy fully and conspicuously discloses to users how their personal information is processed, and that the legally required consent has been obtained. At the same time, require the founder to warrant that the company has not received any large-scale requests to exercise the data portability right during a specified prior period.
- Data Asset Value Protection ClauseAgree in the agreement that if, within a certain period after the investment closing (e.g., 24 months), the exercise of the data portability right causes the company’s active-user data processing volume to decline by more than an agreed proportion (e.g., 20%), the valuation adjustment mechanism shall be triggered.
- Product Design ConstraintsEncourage the company to build user stickiness at the product design level—not merely relying on the closed nature of data, but more importantly reducing users’ willingness to exercise the data portability right through unique features, algorithms, and user experience. This, in effect, transforms the pressure of legal compliance into a driving force for product innovation.
IV. Data Breaches — On the Nightmare of “Joint and Several Liability”
1. The Civil Compensation Mechanism for Data Breaches
Article 69 of the Personal Information Protection Law establishes a tort liability framework extremely unfavorable to enterprises—presumption of fault. Once a data breach causes damage to users’ rights and interests, the burden of proof lies with the enterprise. This means the enterprise must bear not only the direct losses of the data breach (such as system remediation costs and business interruption losses), but also compensation liability to affected users.
For investors, the losses from a data breach go far beyond this. A company that suffers a major data breach will face:
- collapse of user trust and the ensuing user churn;
- substantial regulatory fines (up to RMB 50 million or 5% of the prior year’s turnover);
- breach-of-contract claims from downstream customers and partners—particularly B-end customers who, by contract, require the data processor to possess specific security capabilities;
- freezing of financing and M&A transactions—prospective investors and acquirers will be highly wary of companies with a data breach record.
2. Joint and Several Liability of Joint Processors and Entrusted Processors
The Personal Information Protection Law distinguishes between “joint processors” and “entrusted processors,” and the liability structures of these two roles differ entirely in the context of a data breach:
- Joint Processor (Article 20 of the Personal Information Protection Law): where two or more personal information processors jointly determine the purposes and means of processing personal information, they shall agree on their respective rights and obligations. However, such agreement does not affect an individual’s right to claim against any one of the personal information processors—that is, joint processors bear joint and several liability externally.
- Entrusted Processor (Article 21 of the Personal Information Protection Law): where a personal information processor entrusts another person to process personal information, it shall agree with the entrusted party on the purposes, duration, means, categories of information, and protective measures of the processing, as well as the rights and obligations of both parties, and shall supervise the entrusted party’s personal information processing activities. The entrusted party shall process personal information in accordance with the agreement and shall not process personal information beyond the agreed purposes and means of processing.
For software startups, the most common risk scenario is the data processing relationship between a SaaS service provider and its customers. If the company promised a specific level of security protection for customer data in its contract, but a data breach occurs in actual performance, the company will face both tort claims from users and breach-of-contract claims from customers. This dual liability may deal a devastating blow to a startup that has not yet achieved profitability.
3. Designing Data Breach Clauses in Investment Agreements
Based on the above analysis, we recommend designing dedicated data security and data breach clauses in investment agreements:
- Warranty on Data Security Management SystemThe founder shall represent and warrant that the company has established a data security management system and technical measures that comply with the requirements of the Personal Information Protection Law, the Data Security Law, and the Cybersecurity Law.
- Disclosure of Historical Data BreachesThe founder shall disclose all data security incidents that occurred within the past three years, including but not limited to data breaches, unauthorized access, and system attacks—regardless of whether actual losses were caused.
- Post-Investment Security Audit MechanismThe investor shall have the right, after the investment closing, to engage a third-party institution to conduct periodic data security audits of the company, with the audit costs borne by the company (or reserved from the investment amount).
- Valuation Adjustment for Major Security IncidentsIf, after the investment closing, the company experiences a data security incident of major impact (such as an administrative penalty at or above the million-yuan level, or a personal information breach affecting over 100,000 individuals), the investor shall have the right to demand the initiation of the valuation adjustment mechanism or the redemption right.
- Cybersecurity Insurance RequirementRequire the company to procure appropriate cybersecurity insurance to cover the financial losses that may arise from a potential data breach incident.
V. Summary of Practical Points
1. Dispel the Illusion of “Data Ownership”
China’s legal system does not recognize a generalized concept of “data ownership.” An enterprise’s rights over data are a layered, conditional bundle of legal interests, rather than an absolute and exclusive right.
2. Compliance Is the “Infrastructure” of Data Assets
Data assets without a compliance system to support them are like a building without a foundation. Compliance investment is not a cost, but a necessary investment in confirming the rights of data assets.
3. The Data Portability Right Must Not Be Overlooked
Incorporate the impact of the data portability right into investment valuation and agreement design, so as to avoid overvaluing data assets due to neglecting this right.
4. Manage Data Breach Risks Up Front
Clarify the historical breach disclosure obligation, post-investment audit mechanism, and security incident trigger clauses in investment agreements, and incorporate data breach risk into the investment risk management framework.
5. Investors’ Pre-Investment Due Diligence Must Be Data-Savvy
Due diligence on data assets cannot rely solely on finance and law; it also requires the participation of technical experts in order to fully assess the company’s data compliance status and data asset value.
VI. Risk Disclosures
- Law Is Still EvolvingChina’s legal and regulatory system in the data field is still developing rapidly, and relevant supporting rules and standards are still being formulated. A processing method that is lawful today may face new compliance requirements tomorrow. It is advisable to include flexibility clauses in investment agreements to adapt to changes in the legal environment.
- Additional Risks of Cross-Border Data TransfersIf the company’s business involves cross-border data transfers (such as using overseas cloud services or providing data services to overseas customers), it must additionally comply with cross-border transfer rules such as the security assessment for outbound data. The consequences of violating these rules may be more severe than domestic data violations.
- Tightening Regulation of Data Classification and GradingAs the data classification and grading system supporting the Data Security Law advances, if the data held by the company is classified into the category of “important data” or “core data,” it will face more stringent compliance requirements.
- Investors’ Own Data ResponsibilitiesDuring due diligence, investors will gain access to a large amount of the target company’s data (including the personal information of its customers and users). Investors themselves must also comply with the confidentiality and security obligations under the Personal Information Protection Law; otherwise they may independently bear legal liability.
VII. Action Recommendations
Recommendations for Entrepreneurs:
- Take data compliance seriously from day one of the company’s founding; even with only a few hundred users, establish a basic privacy policy and data security management system—these will be crucial legal documents in future financing and M&A;
- Consider the dimension of data compliance in every product iteration, embedding the concept of “privacy by design” into the product development process;
- Establish a data asset ledger that clearly records the source, type, processing method, and compliance status of data; this not only facilitates management but also serves as a powerful tool to demonstrate data asset value to investors during financing;
- Do not underestimate the impact of the data portability right on enterprise value—enhancing the competitiveness of the product itself to reduce users’ willingness to “move away” is more sustainable than retaining users through technological lock-in.
Recommendations for Investors:
- Upgrade data asset due diligence from an “optional item” to a “mandatory item,” especially when investing in data-driven startups;
- Add the following items to the due diligence checklist: privacy policy review, spot checks of user consent records, data classification and grading status, review of third-party data processing contracts, records of historical data security incidents, and the status of data portability right implementation;
- Design a data compliance “compliance attainment mechanism” in the investment agreement—if the company fails to meet the agreed compliance standards within the prescribed period, the installment payment of the investment amount or the VAM conditions shall be adjusted accordingly;
- Encourage the portfolio company to procure cybersecurity insurance, which serves both as a risk transfer tool and as a signal demonstrating risk management awareness to the next-round investors and potential acquirers.
Recommendations for In-House Counsel:
- Incorporate data asset clauses into the standard modules of investment agreements, rather than adding them ad hoc only when dealing with “internet companies”;
- Establish a “pre-financing health check” service process for data compliance—conduct a systematic data compliance review of the company before each financing round, identify and resolve potential issues, and only then bring it to market;
- Follow the development of data asset valuation methodologies, coordinate with financial advisors and technical experts, and reasonably reflect the compliance level of data assets in the valuation.
Data assets are the oil of the digital economy era, but the extraction, transportation, and use of oil are all subject to strict legal regulation. For entrepreneurs and investors in the software industry, understanding the legal attributes of data assets and establishing a sound compliance system is not a shackle that restrains innovation, but armor that protects the fruits of innovation. In every investment agreement, taking the ownership and compliance clauses of data assets seriously is taking the company’s most core value itself seriously.
User data ultimately belongs to the users. The enterprise’s task is not to argue “who owns the data,” but to prove through technology, compliance, and business model that even though the data ultimately belongs to the users, the unique value created through lawful and compliant data processing unquestionably belongs to the enterprise itself.
Disclaimer
This article is for general reference only and does not constitute legal opinion or advice. For specific legal issues, please consult a professional lawyer. The cases in this article are adapted from real events, and the company names and details involved have been anonymized.
Lawyer Kevin Jun Lin
Senior Corporate Lawyer · Industry Legal Practice Expert
💬 Feel free to leave your thoughts and reasons in the comments section
About the Zhenpin Lawyer Team |
Lawyer Kevin Jun Lin — Today’s Lead Author Currently enrolled doctoral candidate in Civil and Commercial Law at China University of Political Science and Law. Combines theoretical depth in company law with extensive practical experience, focusing on company law, shareholder disputes, corporate compliance system building, data compliance, and product quality disputes. |
Lawyer Yan Ge: Founding partner of the law firm, with decades of frontline legal experience, possessing hands-on practical experience across the four dimensions of courts, supervision, justice, and enterprise. |
Lawyer Lin Bing: 27 years in practice, with a dual background in law and finance, having handled over 2,000 litigation and non-litigation matters. |
📞 Tel: 0755-82222148 📱 Mobile: 18938871445 (v) 18938871445 (v) 📧 Email: 1160727593@qq.com 🌐 Website: www.zhenpinlaw.com 📍 Address: 40F, Room 4004, Block B, Shenfang Plaza, Renmin South Road, Luohu District, Shenzhen |
Further Reading
If you require professional support in shareholders’ agreements, review of investment terms, or shareholder disputes, please contact Lawyer Kevin Jun Lin (Shenzhen corporate lawyer) for a one-on-one consultation.







Leave a Reply