Skip to main content
Corporate Transactions9 min read

The Hidden Legal Risks in Acquiring a China Data Center — Part C: Money, Data & the People Who Keep the Lights On

Part C of the series: the risks that surface in the numbers and the org chart — cybersecurity and data-protection exposure, equipment financing leases, change-of-control in financing documents, and retaining the key operations team after closing.

By Xingkang LiuPublished

PRC law position reviewed as of .

Part C: Money, Data, and the People Who Keep the Lights On

Part A covered the license and foreign investment. Part B covered internet resources, carriers, land, power, and customer contracts. This part covers the risks that show up in the numbers and in the org chart rather than in the technical data room — and one of them, the financing change-of-control clause, is the single issue I would put at the top of the list if I could only flag one.

Quick reference — what this part covers:

Risk Area Deal-Breaker? Where It Bites
Cybersecurity & data protection Sometimes Regulatory exposure, undisclosed incidents
Equipment ownership / financing leases Sometimes Deliverable capacity
Financing documents (change of control) Often Cash flow, asset integrity
Key operations team / people Often Post-closing service continuity

Risk 8: Cybersecurity, Data Protection, and Critical Information Infrastructure

Before assessing compliance, pin down the target's actual legal role. Is it just providing cabinets, power, and connectivity? Or is it an entrusted data processor, or does it independently decide how data is processed? Does it host government, financial, healthcare, industrial, or transportation data classified as "important"? Does it serve a designated critical information infrastructure operator? The answer sets the compliance tier, and it is worth getting right before anything else in this section, because everything downstream depends on it.

Diligence points: the target's data-role classification; its multi-level protection scheme filing and assessment status — filing is not assessment, and assessment is not remediation; historical security incidents, breaches, or outages that were never disclosed; cross-border remote operations or offshore backups; and whether this transaction itself counts as a transfer of personal information or important data requiring a report.

Where the target handles important data or a lot of personal information, treat data compliance as its own workstream, not a subset of IT diligence. Build dedicated reps, warranties, and indemnities around historical breaches and undisclosed regulatory inquiries.

Practical takeaway: ask separately about filing, assessment, and remediation. Most sellers will answer the first question confidently and go quiet on the third.

Risk 9: Equipment Ownership, Financing Leases, and Liens

Sale-and-leaseback deals and supplier retention-of-title clauses mean the target does not always own the equipment sitting in its own facility. Equipment under mortgage or financing lease can be reclaimed on default, which directly cuts deliverable capacity. A gap between the equipment list and actual sellable capacity is not an accounting nuance — it is a misrepresentation of what the buyer is paying for.

Practical takeaway: reconcile the equipment list against title documents line by line before you rely on a capacity number in the model.

Risk 10: Financing Documents — the Change-of-Control Time Bomb

If I had to name the single most underweighted risk in this entire series, it would be this one. It is also, in my experience, the most common actual reason a China IDC deal blows up in the final weeks rather than closing on schedule.

Large IDC projects typically carry syndicated loans, project financing, or equipment financing leases in the billions of RMB. Those financing documents almost always contain strict change-of-control provisions, and everyone on the deal team knows they exist — right up until someone has to actually read them closely enough to model the consequences.

A change-of-control clause in a financing document is a standard, valid lender protection. But once this acquisition falls within that definition — an indirect change of control in a share deal, or a transfer of substantially all assets in an asset deal — the lender can demand immediate repayment of everything outstanding, reprice the loan, demand more collateral, or simply declare a default. That can trigger enforcement against pledged assets: the facility, the equipment, the land. It can compromise the target's asset base the moment the deal closes, which is exactly the moment nobody wants to discover a problem.

Diligence points:

  • Every material financing document at the target and controlling-shareholder level: syndicated loans, project loans, equipment financing leases, supply chain financing.
  • The exact change-of-control definition in each one (direct and indirect thresholds), the notice period, and what percentage of lenders has to agree to a waiver.
  • The total principal, interest, and penalties due if early repayment triggers, and what that does to cash flow.
  • Whether pledged assets cover the core facility, the equipment, and the land use rights.

Make written lender consent or waiver a condition precedent. Where full waivers are not available before closing, build in refinancing arrangements, price holdbacks, or third-party escrow to cover the exposure.

Practical takeaway: ask for the financing documents in week one, not week six. Lender consent has the longest lead time of anything on this list, and it is usually the item that determines the actual closing date.

Risk 11: People — the Team That Actually Runs the Facility

Unlike real estate or manufacturing assets, a data center's stable operation depends heavily on the tacit knowledge sitting in its key network engineers' and operations staff's heads: network topology, customer relationships, incident-response history. In my experience, this is the risk foreign buyers price least accurately of anything in this series, usually because it does not show up as a line item anywhere.

Non-compete and confidentiality agreements with key staff are valid on paper. Their real-world enforceability depends on whether compensation was actually paid in full, on time, and for a term within the legal limit — and a lot of companies underpay this, which weakens enforceability exactly when it matters. If the operations team leaves in large numbers around closing, with no transition plan, the result is an immediate gap in network knowledge, customer relationships, and incident-response experience. That shows up fast: degraded service, SLA breaches, security incidents, inside the first few weeks.

Diligence points:

  • Key network engineering, operations, on-call, and customer-relationship staff, their tenure, and how concentrated the flight risk is.
  • Non-compete coverage, actual compensation payment records, and remaining term.
  • Whether key people know about the deal, and what they think of it — a retention package before signing can lock this down early.

Make retention agreements or non-compete commitments from core team members a condition to closing. Pair the deal with a post-closing Transition Services Agreement, typically three to twelve months, where the seller or its designated team keeps running network operations, security operations, monitoring, and incident response.

Practical takeaway: price the team before you price the facility. A fully staffed NOC with no retention plan is a depreciating asset the moment the deal is announced.

Building the Deal Protection Toolkit

Three tiers, ranked by negotiating priority, not necessarily by legal importance.

Tier 1 — the floor. Do not negotiate this away.

  • Dedicated reps and warranties on the license, foreign investment position, land, energy, power, fire safety, and data compliance.
  • Independently verified continuity of internet resources and core carrier agreements, with written carrier confirmation on the change of control.
  • Regulatory approvals, major customer consent, and lender consent, all as conditions precedent.
  • Uncapped or high-cap indemnities, outside the general basket, for historical unlicensed operation, tax exposure, data breaches, and subsidy clawback.
  • Price escrow or holdback, released against key permits or metrics.
  • Pre-closing covenants blocking new encumbrances, early customer collections, unusual discounts, related-party deals, and transfers of customers or key staff.

Tier 2 — important, but structurally negotiable.

  • Locked-box versus completion-accounts pricing. The choice matters more here than in most sectors, given how volatile IDC cash flow can be. Add a working capital adjustment.
  • Earn-outs tied to actual deliverable megawatts, energized cabinet count, and customer renewal.
  • Retention agreements and non-competes for key staff, paired with a Transition Services Agreement.
  • Staged payments tied to filings, remediation, and audit confirmation.
  • MAC clauses and bring-down of reps at closing.
  • Extended survival for tax and regulatory indemnities, matched to the statute of limitations.

Tier 3 — tradeable.

  • The exact numbers on general rep baskets and caps.
  • Reasonable extensions on non-core remediation timelines.
  • Limited buyer autonomy during transition.
  • Post-closing cure rights for non-material customer consents.
  • Seller guarantees or a security deposit instead of part of the price holdback.

The Deal-Breaker List

Treat these as closing blockers until resolved, priced, or escrowed:

  • No license, or a scope that misses actual facilities or business lines, or a borrowed license.
  • A foreign investment structure that does not fit the license, with no viable pilot-zone path.
  • No lawful energy quota, a failed energy review, or usage well over the approved quota.
  • Fundamentally non-compliant land use, or a fundamental fire-safety gap at the core facility.
  • Power capacity that cannot be sustained, or "dual feed" that is single-sourced in substance.
  • Major customers holding an unwaived change-of-control termination right.
  • Undisclosed material outages, breaches, or regulatory investigations.
  • Core equipment not owned by the target, or fully encumbered under retention-of-title financing.
  • Material misstatement of cabinet count, deliverable megawatts, occupancy, or PUE.
  • A target that is, in substance, a licensed shell, with assets, staff, customers, and cash flow actually sitting in an affiliate.
  • No independently held, sustainable internet resources, with total dependence on a third party and no transfer path.
  • Core carrier agreements about to expire, facing adverse change with no carrier consent, or "multi-line" that is single-sourced with no real redundancy.
  • Unwaivable financing acceleration, with no viable refinancing path.
  • Clear signs of mass departure among key operations staff, with no achievable transition plan or retention deal.

Key Takeaways

  • The financing change-of-control clause is the single most underpriced risk across this whole series — get the documents early.
  • Data compliance deserves its own workstream once the target handles important data; do not fold it into general IT diligence.
  • The operations team is an asset with a shelf life. Price it, and protect it, before signing, not after.
  • Build the deal protection toolkit in tiers. Know which provisions are the floor and which are genuinely negotiable before you sit down at the table.

The Real Lesson

The legal issues that derail a China data center acquisition rarely come from the documents that look most problematic. They come from the operating resources buyers assume will just continue after closing: internet connectivity, carrier relationships, financing covenants, the people who run the place. Those resources depend on regulatory approval, third-party cooperation, or a handful of engineers staying put — none of which shows up as a defect in any document you can review. Recognizing that distinction early is usually what separates a clean acquisition from an expensive lesson.


This article is a general knowledge resource on PRC data center M&A practice. It does not describe any actual transaction and is not legal advice. Consult qualified PRC counsel on the facts of any specific deal. Regulatory references are current as of the time of writing and are subject to change.

Corporate TransactionsForeign InvestmentCross-border

If your business is facing similar issues, please contact me to discuss how I may assist.

All legal analysis