Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. Technology Quotient
  4. Navigating Regulatory Fragmentation: What China's Evolving Data Governance Means for International Businesses
4MIN

Navigating Regulatory Fragmentation: What China's Evolving Data Governance Means for International Businesses

Aug 13 2026

China has long been viewed as a market requiring compliance with a distinct set of local rules on data, cybersecurity and foreign investment. Recent regulatory developments, however, signal a broader shift. As geopolitical tensions intensify and governments around the world seek greater control over technology, critical infrastructure and supply chains, businesses are finding themselves caught between competing regulatory systems. In this sense, China is deploying a growing range of legal instruments that are not primarily aimed at domestic compliance, but at managing the interaction between Chinese interests and foreign regulatory measures. These measures appear to reflect a broader policy objective of strengthening China's ability to protect national security interests. At the same time, regulators in the European Union, the United States and other jurisdictions are imposing ever more far-reaching obligations, including export controls, cross-border investigations, and other regulatory regimes with extraterritorial effects.

For multinational companies, the challenge now extends beyond simply complying with Chinese regulations on the one hand and foreign regulations on the other. Businesses must navigate situations in which regulatory expectations from different jurisdictions overlap, compete or even directly conflict. Information that may need to be disclosed to a foreign regulator could simultaneously attract scrutiny from a Chinese regulatory perspective. 
As a result, China-related compliance must be assessed within a broader cross-border regulatory context. Businesses should consider not only the requirements of Chinese law, but also how foreign regulatory measures may be viewed by Chinese authorities. This dynamic is reflected in several recent regulatory developments that merit particular attention.

China's Expanding Data Governance Framework 

China's regulatory approach has evolved from a predominantly domestic focus to one that increasingly addresses cross-border and geopolitical considerations. It now encompasses a growing set of instruments designed to safeguard national security interests, economic priorities and strategic industries. Recent attention has focused on two key developments: the Regulations on Countering Improper Extraterritorial Jurisdiction by Foreign States and the Provisions on the Security of Industrial and Supply Chains. Both measures provide Chinese authorities with additional tools to address perceived risks arising from foreign regulatory action and strategic dependencies. (For a more detailed discussion of the supply chain and ESG implications of these regulations, see our colleagues' recent analysis.)

More fundamentally, however, these measures form part of a broader transformation in China's regulatory approach. Chinese regulators are focusing not only on personal data, but also, to a growing extent, on non-personal data that may reveal information about industrial capabilities, supply chains, technology development, critical infrastructure or economic activity.

For multinational companies, this shift is particularly relevant because connected products, digital services and global operations generate large volumes of operational and product-related data. Information such as software logs, sensor data, manufacturing information and supplier data is routinely shared across borders for product development, compliance, cybersecurity and regulatory purposes.

Current initiatives suggest that China is placing greater emphasis on how these information flows are governed. Alongside regulatory measures, initiatives such as the World Data Organisation (WDO) demonstrate China's strategic interest in shaping discussions around global data governance, cross-border data transfers and international standards. Although the practical role and influence of the WDO remain to be seen, the initiative highlights China's ambition to play a leading role in defining how data is governed beyond its borders, particularly across emerging economies. 

A similar trend can be observed at the sector level. In the automotive industry, for example, the new vehicle data guidance further clarifies what may qualify as “important data” and may therefore become subject to stricter governance and cross-border transfer requirements. Although confined to a specific sector, the guidance highlights growing regulatory scrutiny of commercially and strategically significant data. 

Together, these measures form part of a broader effort to safeguard China's strategic interests in a more fragmented geopolitical and regulatory environment. Viewed collectively, they suggest that businesses should no longer regard data merely as a compliance issue, but as a strategic asset that is becoming subject to heightened regulatory oversight. 

Implications for International Businesses

International companies are increasingly subject to regulatory obligations that require the collection, disclosure or transfer of information and data across borders. Against this backdrop, the new Chinese regulations introduce an additional layer of legal uncertainty. An international company may be placed in a position where meeting one set of legal obligations increases exposure under another regulatory framework. A mandatory disclosure to a foreign regulator could be seen as harming China's security interests or industrial goals, simultaneously exposing the company to penalties under Chinese law. 

These developments demonstrate that the risks are not merely theoretical. Chinese authorities have already indicated that certain foreign measures involving China-based information and operations may be subject to regulatory review. Consequently, multinational companies should not assume that obligations arising under different regulatory regimes can be assessed or managed independently of one another. 

In this environment, companies should reassess how China-related risks are identified, managed and escalated across the organisation. Key considerations should include:

  • Mapping China-related data and supply chains
  • Reviewing governance and escalation procedures
  • Integrating China considerations into existing compliance frameworks
  • Assessing potential regulatory conflicts

The implications of these developments extend beyond individual compliance obligations. As regulatory frameworks continue to intersect across jurisdictions, multinational companies may face situations in which compliance with one set of regulatory expectations creates risk under another. With legal, operational and geopolitical considerations becoming ever more intertwined, success will depend not only on compliance, but on the ability to identify and navigate competing risks across a fragmented regulatory landscape.

Authors

Vienna

Ludwig Hartenau

Partner
Vienna

Markus Kattnig

Associate
Vienna

Thomas Satzinger

Associate
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome