
Two Chinese State Council decrees. No transition period. No implementing guidelines. Immediate effect.
If your organization is subject to NIS2, the CRA, or GDPR — and you have Chinese suppliers or processors — you are now operating inside a structural legal conflict. 🌍
What Happened
Decree 834 (April 7, 2026) — China’s first dedicated supply chain security regulation — prohibits supply chain-related “investigations or information collection” within Chinese territory.
The scope is undefined. No implementing rules exist. ❗
Regulatory collision:
• NIS2 Article 21 → requires supplier security assessments
• CRA → requires conformity assessments on Chinese hardware/software
• GDPR Article 28 → requires audit rights over processors
All of that is now potentially in scope of Decree 834.
Decree 835 (April 13, 2026) — empowers China’s Ministry of Justice to designate foreign regulatory measures as “undue extraterritorial jurisdiction” — and prohibit compliance.
No designations yet. Criteria undefined. Discretion is broad.
The Trap
• Comply fully with NIS2/CRA/GDPR → risk triggering PRC investigation or countermeasures
• Pull back to avoid PRC exposure → breach binding EU obligations
Neither option is clean. This is a structural gap.
Exposure on both sides:
• PRC civil claims under Anti-Foreign Sanctions Law already active (RMB 99.7M settlement, 2024)
• EU fines under NIS2 / CRA / GDPR → 2–4% of global turnover
A defensible position requires:
• Jurisdictional conflict mapping before enforcement
• Parallel documentation under EU + Chinese law
• Transfer impact assessments covering full PRC legal stack
• Contractual architecture allocating regulatory conflict risk clearly
How S8fe.ai Supports
We map cross-border obligations, identify conflict points in data flows and third-party relationships, and generate documentation defensible under both legal systems simultaneously.
If you are a DPO or GC with China exposure, the question is not whether this affects you. It is whether you have a documented position before your regulator asks.
