The development of Chinese legal autonomy: the lock-down of Chinese data and the growing extraterritoriality of export and supply chain controls

Within a few months, China has adopted a series of regulations establishing a legal framework with extraterritorial reach, combining information lockdown, resistance to foreign compliance obligations and the extension of export and supply chain controls. For European companies operating in China or exposed to the Chinese market, this "triple compliance" regime (EU, U.S. and China) now requires an urgent review of their conflicting obligations, their contractual chains and their data governance.

In the space of a few weeks, China has adopted a series of State Council instruments outlining a legal architecture with extraterritorial reach: the Regulations on Industrial and Supply Chain Security (Decree No. 834, March 2026, accompanied by MOFCOM Announcement No. 24), the Regulation on Countering Foreign Inappropriate Extraterritorial Jurisdiction (Decree No. 835, April 2026) and the Regulation on Outbound Investment (Decree No. 837, June 2026). These instruments complement the legal arsenal of economic and national security that China has progressively built, the most emblematic applications of which include export controls on rare earths and semiconductors. They form part of a clearly asserted regulatory strategy: to equip China with a normative framework that rivals the extraterritorial legal arsenals of the United States and the European Union. For foreign companies operating in China or maintaining commercial relationships with Chinese partners, navigating contradictory imperatives without exposure to legal risk has become an increasingly difficult equation to solve.

I. The Defensive Dimension: Resistance to Foreign Extraterritoriality and Control of Data

Entering into force on 31 March 2026, the Regulations on Industrial and Supply Chain Security (Decree No. 834) reinforce an already dense information control framework [1]. The Decree targets any conduct liable to harm the security of Chinese industrial and supply chains, and in particular investigative and information-gathering activities carried out by foreign organisations or individuals in violation of Chinese law. Rather than creating new substantive obligations, the Decree operates as a strengthened enforcement mechanism for existing legislation: the Data Security Law, the Cybersecurity Law, the Statistics Law, measures governing foreign-related investigations, and counter-espionage provisions — providing for countermeasures referred to as “disposition measures”, the precise content of which remained undefined prior to MOFCOM Announcement No. 24 published on 22 June 2026 [2], entitled “Measures for Industrial and Supply Chain Security Investigations”.

MOFCOM Announcement No. 24 sets out, first, the criteria to be considered in assessing the significance of harm to industrial and supply chain security: impacts on critical materials, technologies, data and personnel; the smooth flow of logistics, trade, financial and informational flows; international competitiveness; and “other relevant circumstances”. The Announcement also establishes a procedural framework for investigations (hearings, document inspections, etc.) and, most significantly, expressly confers jurisdiction on MOFCOM to conduct on-site investigations abroad, subject to approval from the relevant foreign jurisdiction. Beyond the standard sanctions of import and export restrictions or entry bans, MOFCOM also announces its ability to levy “special charges” applicable to services, data transfers and port activities.

China has indeed erected a framework of informational impermeability resting on three structural pillars. First, Article 32 of the 2020 Export Control Law [3] expressly prohibits the provision to foreign parties of export control-related information where such disclosure could harm China’s national security or national interests, thereby capturing situations in which a company transmits information to a foreign authority in the context of a sanctions or export control investigation. Second, Article 38 of the 2024 Regulations on the Export Control of Dual-Use Items [4] requires legal and natural persons established in China to report to the competent authorities any request from a foreign government concerning export controls, creating an indirect surveillance mechanism over interactions between operators and foreign authorities. Third, Article 4 of the Provisions on Security Assessment of Data Exports [5] subjects the export of all “important data” to prior review; the 2022 Important Data Identification Guide clarifies that this category includes trade secrets, unpublished statistical data and strategic customer lists.

Compliance with these provisions is ensured through the threat of sanctions against foreign actors, as well as the proliferation of reporting channels available to Chinese parties to flag suspected regulatory breaches. This week, such mechanisms were established both by MOFCOM Announcement No. 24 of 2026 on supply and production chain security, and by MOFCOM Announcement No. 26 of 24 June 2026 [6], directed more specifically at the reporting of suspected violations of strategic dual-use export controls in the mining sector.

The Regulation on Countering Foreign Inappropriate Extraterritorial Jurisdiction (Decree No. 835, entering into force on 13 April 2026) [7] targets foreign companies more directly. It mandates the Ministry of Justice to identify foreign “inappropriate” extraterritorial jurisdiction measures, assessed against the legitimacy of those measures and their impact on China’s sovereign or economic interests. Once identified and published, no legal or natural person may implement such measures or assist in their implementation. Decree No. 835 also creates a “malicious entities list” to target individuals and legal persons that have promoted such measures, with countermeasures ranging from visa refusals to asset freezes in China or bans on commercial activity within the country.

These measures raise a major practical challenge for European companies subject to foreign compliance obligations. The CSDDD, ESG due diligence requirements, supplier audits, the application of “best efforts” clauses in the context of Russia sanctions, and internal investigations conducted in China under global compliance programmes are all exposed to the risk of being characterised as inappropriate measures under these Decrees. More broadly, a company that terminates a supplier relationship or refuses a transaction in order to comply with a foreign obligation faces the risk that such a decision may be interpreted as a discriminatory cessation of a commercial relationship, potentially exposing the company to designation on an individual sanctions list or to liability before Chinese courts.

II. The Offensive Dimension: Growing Extraterritoriality of Export Controls, Proliferation of Individual Sanctions Lists and Control of Outbound Investment

Conversely, access to Chinese export licences represents, for the authorities, an opportunity for economic intelligence. The authorities enjoy broad discretionary powers enabling them to assess end-users, declared uses and national security risks prior to the granting of a licence — which in practice requires the disclosure of detailed information on supply chains and the conditions of use of the goods concerned. This requirement may go beyond a mere ex ante control and approach a systematic collection of sensitive data on foreign applicant companies, an informational asymmetry that foreign economic operators now have every interest in factoring into their licensing strategy.

In a related but distinct register, Decree No. 837 on Outbound Investment, published on 1 June 2026 [8], constitutes a further mechanism enabling the administration to gather substantial information, while comprehensively regulating Chinese investment abroad. Its scope is deliberately broad: under the concept of “Chinese investor”, the Regulations cover not only companies established in China, but also, for the first time at this level, Chinese resident natural persons and foreign-invested enterprises incorporated in China. Outbound investment is itself extensively defined, capturing notably any direct or indirect acquisition of rights over enterprises or assets abroad and investments in foreign financial markets.

The Decree establishes a security review mechanism applicable not only to the initial investment, but also to any subsequent disposal or restructuring capable of affecting China’s national security: any asset of Chinese origin or held by Chinese parties, regardless of its location, may be subject to review upon a share transfer or intra-group reorganisation. Decree No. 837 thereby extends the Chinese export control regime to both foreign-invested enterprises incorporated in China and foreign companies held or controlled by Chinese entities in the context of their outbound investments.

In conjunction with the 2021 Anti-Foreign Sanctions Law [9], the Decree authorises the listing of companies or individuals that have participated in the elaboration or implementation of discriminatory measures against Chinese investors. This implies that European companies may be subject to countermeasures on account of conduct adopted vis-à-vis a non-Chinese company that is nonetheless held by Chinese shareholders.

Since 2020, China has progressively extended the extraterritorial reach of its export controls beyond the strict perimeter of goods formally inscribed on control lists. Since July 2023, starting with gallium and germanium, MOFCOM has continuously extended export controls over critical minerals and rare earths. Chinese regulations furthermore require export licences for products manufactured abroad incorporating components or technologies of Chinese origin, according to variable and non-uniform thresholds, following an evolving and sector-specific approach.

The proliferation and growing weight of individual designation instruments constitute the other hallmark of this extension of regulatory jurisdiction. Alongside the new “malicious entities list” established by Decree No. 835, the unreliable entities list [10] has seen accelerated activation since 2025: not only US companies, but also European and Japanese defence sector operators that have complied with US export controls targeting China have progressively been listed. This proliferation of lists — where listing is subject to broad discretionary authority — creates significant risk for foreign companies seeking to implement harmonised global compliance frameworks.

The decrees adopted in spring 2026 establish a genuine “dual compliance” regime, requiring companies operating in China to simultaneously assess their obligations under foreign legislation and those arising under Chinese law in respect of the same restrictive measure. The objective is clear: to enable Chinese authorities to block, challenge or control the implementation of any foreign obligation liable to affect “Chinese interests” — a deliberately broad notion conferring on the government considerable discretionary latitude. In this context there also emerges the logic of “piercing rules”, which introduces a compliance function more firmly grounded in substance than in form: the nationality of a company, within the meaning of Chinese law, is no longer determined by its registered seat alone but is assessed against a range of substantive criteria such as the technology employed, the design teams, or the intellectual property chain — enabling China to extend its control to entities formally foreign but possessing a form of “functional Chinese nationality” and participating in activities deemed sensitive to its interests.

This “mirror jurisdiction” dynamic carries major implications for European companies. They must now map potential inter-jurisdictional conflicts, anticipate the risks of normative contradiction, and take account of the fact that any activity conducted by a Chinese subsidiary — including mere compliance with a foreign rule — may become a vector of Chinese extraterritoriality and heightened oversight by national authorities. In practice, an increasingly precise mapping of China-related relationships, regulatory force majeure clauses, adaptation of contractual provisions on economic sanctions and export controls in pursuit of a safe harbour, combined with an assumed data governance framework, are all imperative for any foreign company with direct or indirect exposure to the Chinese market, its clients or its suppliers.


[1] State Council of the People’s Republic of China, Regulations on Industrial and Supply Chain Security (产业链供应链安全规定), Decree No. 834, entering into force on 31 March 2026.

[2] Ministry of Commerce of the People’s Republic of China, Measures for Industrial and Supply Chain Security Investigations (产业链供应链安全调查办法), MOFCOM Announcement No. 24 of 2026, published 22 June 2026, entering into force on the date of publication.

[3] Standing Committee of the National People’s Congress, Export Control Law of the People’s Republic of China (中华人民共和国出口管制法), adopted 17 October 2020, entering into force 1 December 2020.

[4] State Council of the People’s Republic of China, Regulations on the Export Control of Dual-Use Items (两用物项出口管制条例), adopted 19 October 2024, entering into force 1 December 2024.

[5] Cyberspace Administration of China, Provisions on Security Assessment of Data Exports (数据出境安全评估办法), published 7 July 2022, entering into force 1 September 2022. See also: Important Data Identification Guide (重要数据识别指南), 2022.

[6] Ministry of Commerce of the People’s Republic of China, Measures on Reporting Suspected Violations of Strategic Dual-Use Export Controls in the Mining Sector, MOFCOM Announcement No. 26 of 2026, published 24 June 2026.

[7] State Council of the People’s Republic of China, Regulation on Countering Foreign Inappropriate Extraterritorial Jurisdiction (中华人民共和国反外国不当域外管辖条例), Decree No. 835, adopted 27 March 2026, published and entering into force 13 April 2026.

[8] State Council of the People’s Republic of China, Regulations on Outbound Investment (国务院关于对外投资的规定), Decree No. 837, signed 5 May 2026, published 1 June 2026, entering into force 1 July 2026.

[9] Standing Committee of the National People’s Congress, Anti-Foreign Sanctions Law of the People’s Republic of China (中华人民嘱和国反外国制裁法), adopted and entering into force 10 June 2021.

[10] Ministry of Commerce of the People’s Republic of China, Provisions on the Unreliable Entity List (不可靠实体清单规定), MOFCOM Order No. 4, published 19 September 2020, entering into force on the date of publication.

Foreign Investment Screening: The European Union Strengthens and Harmonises Its Framework

Against a backdrop of increased scrutiny of foreign investment within the European Union, Regulation (EU) 2026/1386 replaces the framework established in 2019. While it does not create a single EU-level authorisation procedure, it further harmonises national screening mechanisms and broadens the range of transactions that may be subject to review.

Turnberry Agreement: the European Union implements its tariff preferences subject to conditions

Since this 1 July, the main provisions of the Turnberry Agreement concluded between the United States and the European Union are applicable in the European regulatory framework. Some industrial and agri-food products imported from the United States are now subject to a preferential rate of 0% in the European Union, while others are subject to a preferential rate within the limits of specified volumes.

The development of Chinese legal autonomy: the lock-down of Chinese data and the growing extraterritoriality of export and supply chain controls

Within a few months, China has adopted a series of regulations establishing a legal framework with extraterritorial reach, combining information lockdown, resistance to foreign compliance obligations and the extension of export and supply chain controls. For European companies operating in China or exposed to the Chinese market, this "triple compliance" regime (EU, U.S. and China) now requires an urgent review of their conflicting obligations, their contractual chains and their data governance.