Two Chinese State Council decrees entered into force on April 7, 2026 — with no transition period, no grace period, and no implementing guidelines. For any organization subject to EU law that maintains commercial relationships with Chinese entities, these regulations create a structural legal conflict that existing compliance programs are not
equipped to handle.
This post maps the collision, identifies the exposure zones, and outlines what a defensible response looks like.
What Was Just Enacted
Decree 834 — Regulations on Industrial and Supply Chain Security
(Order No. 834)
China’s first dedicated administrative regulation on industrial and supply chain security. Eighteen articles. Immediate effect. Based on the National Security Law, the Anti-Foreign Sanctions Law, and the Foreign Trade Law.
Decree 835 — Regulations on Anti-Undue Extraterritorial Jurisdiction
Issued six days later. Establishes a formal administrative process, centralized within the Ministry of Justice, to identify foreign regulatory measures deemed to assert improper jurisdiction over Chinese entities — and to prohibit compliance with them.
Taken together, these two instruments represent a significant maturation of China’s counter-sanctions legal architecture. They do not introduce entirely new concepts. What they do is consolidate, elevate, and systematize tools that were previously scattered across the Unreliable Entity List regime, MOFCOM Blocking Rules, and the AntiForeign Sanctions Law — and vest them with State Council-level legal force and a cross-agency enforcement infrastructure spanning over fifteen government bodies.
The EU Obligations That Are Now in Conflict
The core problem is straightforward: several EU legal obligations that are currently in force require EU-regulated entities to collect data about, audit, or restrict commercial relationships with Chinese counterparties. Decree 834 and 835 create legal risk for precisely that conduct.
NIS2 — Supply Chain Security (Article 21)
NIS2 obliges essential and important entities to assess and manage cybersecurity risks in their supply chains, including the security practices of their direct suppliers and service providers. This means, in practice, conducting structured security assessments of Chinese technology vendors, cloud providers, and software suppliers — gathering information about their infrastructure, vulnerability management practices, and incident response capabilities.
Article 13 of Decree 834 prohibits supply chain-related “investigations or information collection” within Chinese territory in violation of “relevant state provisions.” The terms are undefined. No implementing rules have been issued. The practical scope of this prohibition —
including whether it captures third-party security audits conducted pursuant to foreign legal obligations — remains entirely within the interpretive discretion of Chinese authorities.
CRA — Cyber Resilience Act
The CRA requires manufacturers and importers of products with digital elements to conduct conformity assessments, maintain documentation of vulnerability handling, and in many cases engage in coordinated vulnerability disclosure. Where a product’s hardware or software components are sourced from Chinese manufacturers, compliance with CRA obligations will require data collection and potentially security testing that implicates Article 13 of Decree 834.
GDPR — Processor Due Diligence (Article 28)
GDPR Article 28 requires data controllers to verify that processors provide sufficient guarantees as to technical and organizational security measures. Where processing is delegated to a Chinese entity, this obligation includes audit rights and inspection. More consequentially, transfer impact assessments under Chapter V of the GDPR require collecting detailed information about the legal environment in the recipient country — including the risk that Chinese authorities may access transferred data. That risk assessment now needs to account for Decree 835.
Where the Legal Conflict Becomes Acute
The sharpest collision occurs in three scenarios.
Scenario 1: Exit or Restriction Decisions
An EU operator, following a NIS2 supply chain risk assessment or a CRA conformity review, decides to restrict or terminate a relationship with a Chinese supplier on security grounds. Article 15 of Decree 834 authorizes Chinese authorities to open a supply chain security
investigation where a foreign actor “interrupts normal transactions” with Chinese counterparties or adopts “discriminatory measures” against them. The terms — “normal transactions,” “discriminatory measures,” “substantial harm” — are deliberately undefined.
This means a compliance-driven decision to exit a Chinese supplier, made in good faith pursuant to binding EU law, is potentially subject to an Article 15 investigation under Decree 834.
Scenario 2: Data Transfer Impact Assessments
A transfer impact assessment conducted pursuant to GDPR Chapter V must evaluate the legal environment in China — including the risk of government access to transferred personal data under the PIPL, DSL, CSL, and now the national security provisions invoked by Decree 835. The act of compiling and documenting that assessment may itself constitute an “information collection” activity within the scope of Article 13 of Decree 834, depending on how Chinese authorities interpret the provision.
Scenario 3: Foreign Law Compliance as a Designated Violation
Decree 835 empowers the Ministry of Justice to formally identify specific foreign regulatory measures as constituting “undue extraterritorial jurisdiction.” Once a measure is designated, Chinese entities are prohibited from complying with it — and foreign entities that enforce or benefit from that compliance may be exposed to countermeasures. The designation criteria are broad and largely undefined. Any EU export control, investment screening, or data localization requirement touching Chinese interests is theoretically within scope.
No designations have been made as of the date of promulgation. The activation of this framework will be shaped by the trajectory of EUChina relations and, critically, by developments in US-China trade policy. The risk is latent but structural.
The Sanctions Exposure
For organizations that fail to map this conflict, the exposure is real:
PRC-side sanctions (under Decree 834/835, the AFSL, and the UEL regime): trade and investment restrictions, market access denial, asset freeze, prohibition orders, and civil litigation. The private right of action under the Anti-Foreign Sanctions Law is no longer theoretical — a 2024 civil claim before the Nanjing Maritime Court resulted in an RMB 99.7
million settlement, subsequently admitted to the Supreme People’s Court case database.
EU-side sanctions (for failure to comply with NIS2, CRA, GDPR): administrative fines under each instrument — up to €10M or 2% of global turnover under NIS2 for essential entities, up to €15M or 2.5% under the CRA, and up to €20M or 4% under GDPR — plus supervisory orders, operational restrictions, and reputational exposure.
The compliance officer who chooses inaction to avoid PRC exposure may find themselves in breach of mandatory EU obligations. The one who proceeds with full EU compliance may trigger Chinese countermeasures. Neither option is currently risk-free. That is the
definition of a structural gap.
Although in a perfect world such structural discrepancies should be remedied at central government level, unfortunately bilateral discussions on such topics are quasi non-existent. Stakeholders will have to come out with appropriate answers.
A Defensible Response Architecture
The objective is not to eliminate the conflict — it cannot be eliminated without legislative intervention on one or both sides. The objective is to document a defensible position on both sides of the ledger simultaneously.
1. Jurisdictional Exposure Mapping
Identify which EU obligations in your compliance program require data collection, audit rights, or restriction authority over Chinese entities. Map those obligations to the specific provisions of Decree 834 and 835 that may be engaged. This mapping becomes the foundation of your legal position under both systems.
2. Restructure Audit Flows
Where NIS2 or CRA obligations require supplier assessments, conduct them through Chinese legal counsel or locally incorporated audit structures. This reduces direct Article 13 exposure while preserving the documentation needed for EU compliance. The substance of the assessment is preserved; the mechanism is adapted.
3. Parallel Documentation of Cross-Border Transfers
Execute Standard Contractual Clauses under GDPR and PIPL Standard Contracts simultaneously. Document the dual-compliance rationale explicitly. This creates a defensible record under both legal systems and supports transfer impact assessment documentation without requiring the extraction of sensitive information about Chinese legal infrastructure.
4. Contractual Risk Allocation
Insert regulatory conflict clauses in China-facing commercial contracts — force majeure provisions that specifically reference Decree 834/835, notice obligations triggered by any designation or investigation, and termination rights structured to avoid the “interruption of normal transactions” framing of Article 15.
5. Early Warning Monitoring
The “key sectors” list under Decree 834 will be compiled and dynamically adjusted by State Council departments. Organizations in technology, telecommunications, healthcare, and critical infrastructure should monitor this list closely — addition to it triggers elevated
obligations and investigative exposure. Similarly, any Decree 835 designation of EU regulatory measures as “undue extraterritorial jurisdiction” requires immediate legal response within the 30-day window under China’s Blocking Rules.
What S8FE.AI Does
S8FE.AI is a cross-border data compliance platform built for exactly
this environment.
Our platform maps your regulatory obligations across jurisdictions — GDPR, NIS2, CRA, PIPL, DSL, CSL — and identifies the specific points of conflict in your data flows and third-party relationships. We automate transfer impact assessments that account for the full PRC legal stack, including Decree 834 and 835. We generate parallel documentation packages that are defensible under both EU and Chinese law.
For DPOs and General Counsel managing China exposure, the question is no longer whether a conflict exists. It is whether you have documented a defensible position on both sides before an enforcement action begins.
Book a demo with S8FE.AI to map your China-EU compliance gap:
https://s8fe.ai/request-demo/
S8FE.AI is a RegTech platform specializing in cross-border data compliance for organizations operating across EU and Asia-Pacific jurisdictions. This post is provided for informational purposes and does not constitute legal advice.

