The Hidden Legal Risks in Acquiring a China Data Center — Part B: Infrastructure Risks Buyers Don't See Coming
Part B of the series: five infrastructure risks a standard document review misses in China data center deals — internet resources (IP/ASN/BGP), carrier agreements, land and fire safety, energy quota and power capacity, and change-of-control in customer contracts.
PRC law position reviewed as of .
Part B: The Infrastructure Risks Buyers Don't See Coming
Buyers usually assume they are buying a building with good uptime numbers. In reality, they are buying a set of relationships — with a telecom regulator, with carriers, with a local grid operator — that keep that uptime number true. Part A covered the license and foreign investment. This part covers five places where the gap between "documented" and "actually works" is widest, and where that gap almost never surfaces until after closing.
Quick reference — what this part covers:
| Risk Area | Deal-Breaker? | Where It Bites |
|---|---|---|
| Internet resources (IP / ASN / BGP) | Yes | Connectivity after closing |
| Carrier agreements | Often | Network redundancy, renewal cost |
| Land, construction, fire safety | Sometimes | Occupancy, insurance coverage |
| Energy quota, power capacity, PUE | Yes | Expansion capacity, outage liability |
| Customer contracts (change of control) | Often | Revenue retention |
LICENSE → ENERGY & POWER → INTERNET & CARRIER → CUSTOMERS → PEOPLE
Each link in that chain can hold on its own and still take the deal down if the next one fails. This part covers the middle three.
Risk 3: Internet Resources — the Risk Almost Everyone Misses
Of everything in this series, this is the one I see foreign buyers miss most consistently — and the one that most clearly separates a data center from a piece of real estate.
A facility's actual connectivity depends on a small set of scarce technical resources: its autonomous system number, its IPv4/IPv6 address blocks, its BGP routing relationships, and a specific "internet resource cooperation services" qualification. These are allocated by the telecom regulator or CNNIC, or sub-allocated by an upstream carrier. In a meaningful number of smaller IDC operators, the IP and ASN resources are not actually held by the operating company. They sit with an affiliate, an upstream agent, or the carrier, made available through an informal internal arrangement that nobody bothers to write down carefully, because it has never yet been tested by a change of control.
Holding an IP allocation certificate in the target's name does not mean the target controls that resource independently. If it is rented, sub-licensed, or held through an affiliate, the arrangement itself may be built specifically to work around allocation rules. And if a change of control causes the upstream allocator to pull the resource, the target loses its IP addresses, its ability to broadcast BGP routes, and its internet egress. The facility can have perfect power and a full staff, and its customers still cannot reach the internet.
This is one of the few risks in the entire deal that can sit dormant through years of due diligence on other transactions, and then destroy value the moment this particular change of control happens — without ever appearing in a conventional legal checklist.
Questions worth asking:
- A complete inventory of every IP block and ASN in the target's name, with the allocating authority and underlying documentation.
- Is each resource held directly, or in substance borrowed from an affiliate or carrier?
- Do the BGP peering arrangements and the internet resource cooperation license actually match the network as built?
- How long, and at what cost, would it take to re-register these resources if the current arrangement breaks?
Make independently verified, directly held internet resources a condition to closing, verified by technical review, not legal review alone. Where resources are borrowed, require the seller to complete a formal transfer before closing, or sign a long-term, non-terminable usage agreement backed by a dedicated indemnity.
Practical takeaway: ask for the IP/ASN allocation documents before you ask for anything else in the technical data room. If the answer is vague, that vagueness is the finding.
Risk 4: Carrier Agreements — the Myth of Redundancy
Data center marketing loves the phrase "multi-line BGP" or "multi-carrier redundant access." I would treat that phrase, on its own, as marketing rather than fact until proven otherwise. A lot of facilities run their physical links over a single carrier's infrastructure, or a single fiber route, with redundancy that exists only at the logical layer. If that carrier goes down, or the contract ends, the redundancy disappears with it.
The access agreements themselves are valid contracts. The risk sits in the gap between the contracted bandwidth, SLA, and service scope on paper, and what the facility can actually deliver — and whether the diversity the buyer is paying for is real.
Questions worth asking:
- Expiry dates, renewal terms, minimum purchase commitments, exclusivity clauses, and change-of-control or early-termination provisions in every carrier agreement.
- A full list of points of presence and the actual fiber routing, ideally verified by an independent third party confirming genuine physical diversity, not just logical diversity.
- Any leased-line resources (MPLS, SDH, OTN), and whether they are properly licensed and will survive the deal.
- Historical carrier pricing trends and the real risk of cost increases at renewal.
Make it a closing condition that core carrier agreements will not terminate or change adversely because of the transaction, and that independent technical review has confirmed genuine route diversity. Get written no-objection confirmation from major carriers before closing.
Practical takeaway: never rely solely on carrier marketing materials. Require independent technical verification before signing, and put the finding — good or bad — in the valuation, not a footnote.
Risk 5: Land, Construction, and Fire Safety
Every facility needs its own title-and-permit file: land use rights, real property title, and whether the permitted use even allows a data center, plus project filing, planning permits, construction permits, completion inspection, and fire safety review and acceptance. A lot of IDC facilities are retrofitted industrial or warehouse space, so the landlord's title and its right to sublease matter as much as the target's own paperwork.
No title certificate does not automatically invalidate a lease. But unauthorized renovation, unapproved construction, or an unauthorized change of use all weaken the target's rights, and property under mortgage, seizure, or expropriation risk directly threatens continued occupation. A fire-safety gap can trigger a shutdown order, and gives an insurer grounds to deny a property or business-interruption claim later, when it matters most.
Make valid land use, construction, and fire safety documentation, free of seizure or expropriation proceedings, a closing condition for core facilities. For historical procedural gaps, pair a remediation covenant with a holdback or staged payment.
Practical takeaway: treat the landlord's title as carefully as the target's. A tenant cannot cure a defect in someone else's ownership.
Risk 6: Energy Quota, Power Capacity, and PUE
For a data center, power matters more than land. The deal's real value usually comes down to sustainable power supply and room to grow, not square footage. That means the energy conservation review and carbon assessment, energy conservation acceptance, grid connection approval, power supply agreements, transformer and dedicated-line capacity, whether the facility genuinely has dual power feeds from different substations, diesel generator and fuel storage compliance, and whether the quoted PUE is a design number, a filed number, or an actually measured one.
Building or operating without the required energy conservation review, or proceeding after a failed review, is a legality problem, not a paperwork problem. A valid power supply agreement does not mean the contracted capacity is real or expandable. Insufficient energy quota caps expansion, which is often the entire commercial point of the acquisition. And if the "dual feed" runs through the same single point of failure, the promised redundancy is fiction, and the outage liability lands on the new owner the first time it is tested.
Make sufficient, lawfully obtained energy quota, and independently verified power capacity and true dual-feed independence, a closing condition. Never take this from the paper filing alone. Consider earn-outs tied to actual deliverable megawatts and energized cabinet counts.
Practical takeaway: ask for the measured PUE, not the filed one, and ask who measured it. The gap between the two numbers is usually where the real risk lives.
Risk 7: Customer Contracts and Change-of-Control Termination Rights
Change-of-control termination or re-tender clauses are entirely valid on their own terms. The risk is that this acquisition, once it counts as a change of control under the contract, can give a major customer an unqualified right to walk away or force a re-tender. Government, financial-sector, and state-owned customers often carry independent supplier-qualification requirements on top of that, which survive, or are triggered by, the ownership change.
Identify every material contract with a change-of-control clause and quantify the revenue at risk before you agree on price, not after. Get customer consent or a waiver for the largest accounts as a closing condition where possible, and tie price adjustments to customer retention for the rest.
Practical takeaway: a revenue number built on customer contracts you have not checked for change-of-control clauses is not a real revenue number yet.
Key Takeaways
- Internet resources and carrier redundancy are the two risks most likely to be invisible in a standard document review — insist on independent technical verification for both.
- Never accept a filed or design PUE figure as a substitute for a measured one.
- Land and fire-safety gaps are usually fixable with time and money; the real question is whether the transaction timeline allows for the fix.
- Price customer contract change-of-control exposure into the deal before signing, not as a post-closing surprise.
Coming up in Part C: cybersecurity and data protection, equipment ownership and financing liens, the financing change-of-control trap that quietly derails more deals than any other single issue, and the operations team that actually keeps the facility running.
This article is a general knowledge resource on PRC data center M&A practice. It does not describe any actual transaction and is not legal advice. Consult qualified PRC counsel on the facts of any specific deal.
Related Legal Analysis
- The Hidden Legal Risks in Acquiring a China Data Center — Part A: License, Ownership & Deal Structure
Corporate TransactionsAnalysis8 min read
- The Hidden Legal Risks in Acquiring a China Data Center — Part C: Money, Data & the People Who Keep the Lights On
Corporate TransactionsAnalysis9 min read
Related Practice Areas
If your business is facing similar issues, please contact me to discuss how I may assist.