Navigating Regulatory Fragmentation: What China's Evolving Data Governance Means for International Businesses
China has long been viewed as a market requiring compliance with a distinct set of local rules on data, cybersecurity and foreign investment. Recent regulatory developments, however, signal a broader shift. As geopolitical tensions intensify and governments around the world seek greater control over technology, critical infrastructure and supply chains, businesses are finding themselves caught between competing regulatory systems. In this sense, China is deploying a growing range of legal instruments that are not primarily aimed at domestic compliance, but at managing the interaction between Chinese interests and foreign regulatory measures. These measures appear to reflect a broader policy objective of strengthening China's ability to protect national security interests. At the same time, regulators in the European Union, the United States and other jurisdictions are imposing ever more far-reaching obligations, including export controls, cross-border investigations, and other regulatory regimes with extraterritorial effects.
China's Expanding Data Governance Framework
More fundamentally, however, these measures form part of a broader transformation in China's regulatory approach. Chinese regulators are focusing not only on personal data, but also, to a growing extent, on non-personal data that may reveal information about industrial capabilities, supply chains, technology development, critical infrastructure or economic activity.
For multinational companies, this shift is particularly relevant because connected products, digital services and global operations generate large volumes of operational and product-related data. Information such as software logs, sensor data, manufacturing information and supplier data is routinely shared across borders for product development, compliance, cybersecurity and regulatory purposes.
Current initiatives suggest that China is placing greater emphasis on how these information flows are governed. Alongside regulatory measures, initiatives such as the World Data Organisation (WDO) demonstrate China's strategic interest in shaping discussions around global data governance, cross-border data transfers and international standards. Although the practical role and influence of the WDO remain to be seen, the initiative highlights China's ambition to play a leading role in defining how data is governed beyond its borders, particularly across emerging economies.
A similar trend can be observed at the sector level. In the automotive industry, for example, the new vehicle data guidance further clarifies what may qualify as “important data” and may therefore become subject to stricter governance and cross-border transfer requirements. Although confined to a specific sector, the guidance highlights growing regulatory scrutiny of commercially and strategically significant data.
Together, these measures form part of a broader effort to safeguard China's strategic interests in a more fragmented geopolitical and regulatory environment. Viewed collectively, they suggest that businesses should no longer regard data merely as a compliance issue, but as a strategic asset that is becoming subject to heightened regulatory oversight.
Implications for International Businesses
International companies are increasingly subject to regulatory obligations that require the collection, disclosure or transfer of information and data across borders. Against this backdrop, the new Chinese regulations introduce an additional layer of legal uncertainty. An international company may be placed in a position where meeting one set of legal obligations increases exposure under another regulatory framework. A mandatory disclosure to a foreign regulator could be seen as harming China's security interests or industrial goals, simultaneously exposing the company to penalties under Chinese law.
These developments demonstrate that the risks are not merely theoretical. Chinese authorities have already indicated that certain foreign measures involving China-based information and operations may be subject to regulatory review. Consequently, multinational companies should not assume that obligations arising under different regulatory regimes can be assessed or managed independently of one another.
In this environment, companies should reassess how China-related risks are identified, managed and escalated across the organisation. Key considerations should include:
- Mapping China-related data and supply chains
- Reviewing governance and escalation procedures
- Integrating China considerations into existing compliance frameworks
- Assessing potential regulatory conflicts
The implications of these developments extend beyond individual compliance obligations. As regulatory frameworks continue to intersect across jurisdictions, multinational companies may face situations in which compliance with one set of regulatory expectations creates risk under another. With legal, operational and geopolitical considerations becoming ever more intertwined, success will depend not only on compliance, but on the ability to identify and navigate competing risks across a fragmented regulatory landscape.
