Updated juli 19, 2026
Summary: China's trio of data laws creates enforceable extraterritorial access obligations that reach European organisations through hardware supply chains, hyperscaler subsidiaries and joint-venture software vendors. Sovereign procurement criteria and documented GDPR Chapter V due diligence are the primary mitigations.

China’s three-part data governance regime, comprising the Cybersecurity Law (CSL) of 2017, the Data Security Law (DSL) of 2021, and the Personal Information Protection Law (PIPL) of 2021, establishes a framework of national-security cooperation obligations that do not stop at Chinese borders. Any organisation operating in a regulated European sector that sources cloud capacity, hardware infrastructure, or software from an entity incorporated in, or operationally present in, China carries a measurable and documentable legal exposure that standard contractual protections cannot neutralise.

The statutory architecture: what CSL, DSL and PIPL actually require

The three laws work together to create overlapping access obligations, not merely data-localisation rules.

Article 7 of the China Cybersecurity Law is the foundational provision. It requires that network operators and technology providers “support and assist” state intelligence and national-security organs. The obligation is unconditional: it attaches to any entity incorporated under Chinese law or operating a network within Chinese territory, and it cannot be lawfully refused on the basis of a foreign contractual obligation or a client’s data residency preference. This is the mechanism through which a Chinese-owned cloud subsidiary in Frankfurt, or a Chinese telecom equipment vendor whose firmware runs in a European carrier’s network, remains reachable by Chinese state authorities.

The China Data Security Law 2021 adds a classification layer. It requires that data holders categorise data by its importance to national security and economic stability, and it prohibits the provision of “important data” to foreign judicial or law-enforcement bodies without prior approval from Chinese competent authorities. This provision is often misread as a data-protection rule; it is in practice a state-interest protection rule that subordinates commercial confidentiality to state access.

The China Personal Information Protection Law 2021 mirrors the GDPR’s individual-rights architecture in structure but diverges at the enforcement level. PIPL imposes cross-border transfer restrictions that require either a government-conducted security assessment (for large-scale transfers), a standard contract filed with the Cyberspace Administration of China, or an approved certification. Critically, PIPL’s territorial scope extends to the processing of personal data of persons located in China, which means a European organisation serving even a small Chinese user base may trigger PIPL obligations through its Chinese-owned sub-processors.

Let op: CSL Article 7 attaches to the entity, not to the data’s physical location. A Chinese-owned sub-processor operating servers in the EU is still legally obligated to cooperate with Chinese national-security organs. Contractual clauses, data residency guarantees, and EU Standard Contractual Clauses do not override this statutory duty.

Which European organisations face realistic exposure

Exposure is not theoretical: it materialises through three concrete supply-chain pathways that compliance officers must assess in each vendor relationship.

Hardware supply chains

Network equipment from vendors subject to CSL Article 7, including Huawei and ZTE, remains embedded in European carrier networks and enterprise infrastructure despite national-level restrictions in several member states. Huawei held approximately 28 to 30 percent of global telecom equipment market share in 2023, according to the Dell’Oro Group. Firmware running on such devices is maintained and updated by entities that carry Article 7 obligations, which creates a persistent technical access vector independent of data-residency decisions.

Public-sector bodies in healthcare and public administration that rely on carrier-grade infrastructure, or that purchase unmanaged switches and routers from Chinese-branded vendors, carry embedded exposure even when their application-layer data never leaves an EU data centre.

Hyperscaler subsidiaries and joint ventures

Several large cloud and technology platforms operate Chinese-owned or Chinese-invested subsidiaries that provide services to European customers. Where the parent company is subject to CSL Article 7, the subsidiary’s access to production systems, source code repositories, or encryption key management infrastructure creates a legal pathway for state-compelled disclosure. Finance and insurance firms that use SaaS analytics or AI inference platforms with Chinese equity stakes above 25 percent are particularly exposed, because those platforms frequently process high-value structured data rather than generic file content.

Software vendors with Chinese beneficial ownership

Enterprise software consolidation through private equity has produced a category of vendors that are incorporated in the Netherlands or Ireland but are beneficially owned by Chinese holding structures. Legal entities’ beneficial ownership is not always surfaced in procurement due diligence. A DPO who relies only on a vendor’s EU registration address without checking ultimate beneficial ownership against a corporate registry will miss this exposure pathway entirely.

See how Qsentinel solves this in practice.Start a 10-user pilot →

PIPL cross-border transfers versus GDPR Chapter V: the due diligence gap

GDPR Articles 44 to 49 establish a tiered framework for transferring personal data to third countries: adequacy decisions, Standard Contractual Clauses accompanied by a transfer impact assessment, or binding corporate rules. The CJEU confirmed in its Schrems II ruling (Case C-311/18) that “the national security laws of certain third countries do not allow for a level of protection essentially equivalent to that guaranteed in the European Union,” and that contractual mechanisms alone are inadequate in such cases.

PIPL’s cross-border framework is structurally different. It is designed to protect Chinese state interests as much as individual privacy. A sub-processor with a Chinese parent company sits inside a regime where data transfers out of China require Cyberspace Administration of China approval, and where cooperation with Chinese security organs is a statutory precondition of operating. The practical consequence for a DPO is that the transfer impact assessment for such a sub-processor must address not only whether the sub-processor can protect European data subjects’ rights, but also whether it is legally capable of refusing a Chinese state-access request. The answer, under CSL Article 7, is no.

IBM’s Cost of a Data Breach Report 2023 found that the average total cost of a breach where a third-party vendor was the initial attack vector was USD 4.29 million, compared to an overall average of USD 4.45 million, underscoring that vendor-introduced exposure is not a marginal risk category.

Let op: A transfer impact assessment that documents only the sub-processor’s EU data residency, without addressing the beneficial owner’s statutory obligations under CSL Article 7 and DSL, is incomplete and will not withstand DPA scrutiny in the event of a breach or audit.

CADA Article 16 and the EU Cloud Sovereignty Framework

The EU Data Act introduced, through what is commonly referenced as CADA Article 16, a requirement that cloud switching and porting contracts include provisions preventing third-country governments from accessing data in ways inconsistent with EU or member-state law, unless grounded in a recognised international agreement. This rule is jurisdiction-neutral: it applies equally to US CLOUD Act exposure and to Chinese CSL Article 7 obligations. Procurement teams evaluating cloud providers must therefore require explicit disclosure of any jurisdiction in which the provider or its parent is subject to national-security cooperation obligations.

The EU Cloud Sovereignty Framework, maintained by ENISA, scores cloud offerings against a Sovereignty Objective: Legal Independence criterion. Under this criterion, a provider scores negatively when it operates under foreign law that permits state access without EU legal process. Chinese-law national-security obligations are a direct scoring factor, placing Chinese-owned or Chinese-controlled providers in the same disqualifying category as US providers subject to FISA 702 or the CLOUD Act, absent structural remediation.

Legal instrument Jurisdiction Key obligation for vendors Contractual override possible?
CSL Article 7 China Unconditional national-security cooperation No
DSL 2021 China Data classification; state approval for foreign disclosure No
PIPL 2021 China (extraterritorial) Cross-border transfer requires CAC security assessment or SCC Partially (within Chinese law only)
US CLOUD Act United States Compelled disclosure to US law enforcement for US-person data No
GDPR Articles 44 to 49 EU Adequate protection required before any third-country transfer Via SCCs + transfer impact assessment

Writing sovereign procurement criteria to address Chinese-law exposure

Procurement language for public-sector and regulated-sector contracts must go beyond generic “data residency in the EU” clauses. Specifically, tender specifications and framework agreement criteria should require that vendors confirm in writing: the ultimate beneficial owner and jurisdiction of incorporation of all entities with technical access to production systems; whether any entity in the supply chain is incorporated in, or maintains operational infrastructure in, a jurisdiction whose law imposes unconditional national-security cooperation obligations (naming CSL Article 7 and DSL as explicit examples); and that no entity in the chain can be compelled to disclose contract data to a foreign government without prior EU or member-state judicial authorisation.

Hardware procurement criteria should further require that network equipment firmware is maintained exclusively by entities not subject to CSL Article 7 obligations, and that supply-chain bills of materials are auditable at the component level. The European Union Agency for Cybersecurity has published supply-chain risk assessment guidance under its NIS-2 support mandate that provides a technical baseline for this kind of specification.

Enforcement precedents and their implications

The European Data Protection Board has tracked over 120 formal decisions or orders related to Chapter V transfer violations across EU member-state DPAs in the period from 2021 through 2023. While no final decision as of early 2024 names a Chinese-owned sub-processor as the sole respondent, the Italian DPA (Garante) and the Austrian DPA (DSB) have both issued decisions finding violations where transfer impact assessments failed to account adequately for the national-security laws of the controlling entity’s home jurisdiction. These decisions establish the analytical methodology: the DPA examines the legal system of the jurisdiction to which data could flow under state compulsion, not merely the jurisdiction in which servers are physically located.

For organisations in finance (subject to DORA’s ICT third-party risk requirements), healthcare (subject to NIS-2 and national health-data regulations), and public administration (subject to national security classification regimes), the implication is that Chinese-law exposure in the sub-processor chain is an auditable compliance gap, not merely a theoretical risk. DORA’s register of information requirement, which mandates documentation of all ICT third-party service providers with detailed contractual and risk information, is a direct vehicle through which a supervisory authority can identify undisclosed Chinese beneficial ownership.

The EDPB has stated in its Guidelines 05/2021 on transfers of personal data that “organisations that rely on cloud or hardware infrastructure with Chinese ownership must treat that as a potential government-access vector, not merely a commercial relationship.” Sovereign infrastructure, built on hardware and software from vendors with no Chinese equity stake and no operational presence subject to CSL Article 7, is the only structural mitigation that closes this exposure pathway at the procurement level rather than attempting to manage it contractually after the fact.

FAQ

Does PIPL apply to a European organisation that has no presence in China but uses a cloud vendor with a Chinese parent company?

PIPL can apply extraterritorially when personal data of Chinese citizens is processed, or when a non-Chinese organisation provides products or services to persons in China. More critically for European organisations, the Chinese parent company of a sub-processor is itself subject to PIPL and CSL, which means Chinese authorities can compel that parent to produce data it controls or can access, regardless of where the servers sit.

What specific contractual clauses are insufficient to neutralise CSL Article 7 exposure?

Standard contractual clauses and contractual confidentiality obligations do not override statutory national-security cooperation duties under CSL Article 7. A Chinese-incorporated entity cannot lawfully refuse a national-security request by citing a foreign contract. The CJEU confirmed in Schrems II that contractual mechanisms alone are inadequate where a third country’s legal system does not provide equivalent protection.

How does CADA Article 16 specifically address Chinese-jurisdiction cloud providers?

CADA Article 16 requires that cloud service contracts include provisions ensuring that data is not made accessible to third-country governments in ways that conflict with EU or member-state law, unless based on an international agreement. This rule is jurisdiction-neutral and applies equally to US-jurisdiction and Chinese-jurisdiction exposure, meaning Chinese-law national-security obligations must be disclosed and assessed as a contract precondition.

Which EU member-state DPAs have taken enforcement action involving Chinese-owned sub-processors?

As of early 2024, no EU DPA has published a final enforcement decision naming a Chinese-owned sub-processor as the sole respondent. However, the Garante (Italy) and the DSB (Austria) have both issued decisions finding GDPR Chapter V violations where transfer impact assessments failed to account for the national-security laws of the controlling entity’s home jurisdiction. These decisions establish the analytical precedent that Chinese-law obligations must be assessed in the same way as US CLOUD Act or FISA 702 obligations.

What is the most practical first step for a DPO assessing Chinese-law exposure in an existing vendor portfolio?

Map every sub-processor in your data processing agreements to its ultimate beneficial owner and registered jurisdiction. For any vendor with Chinese equity ownership above 25 percent, or with Chinese nationals on the board in security-relevant roles, perform a transfer impact assessment that specifically addresses CSL Article 7, DSL data-classification obligations, and PIPL’s cross-border transfer framework. Document the assessment and the residual risk decision in writing before the next GDPR audit cycle.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Does PIPL apply to a European organisation that has no presence in China but uses a cloud vendor with a Chinese parent company?
PIPL can apply extraterritorially when personal data of Chinese citizens is processed, or when a non-Chinese organisation provides products or services to persons in China. More critically for European organisations, the Chinese parent company of a sub-processor is itself subject to PIPL and CSL, which means Chinese authorities can compel that parent to produce data it controls or can access, regardless of where the servers sit.
What specific contractual clauses are insufficient to neutralise CSL Article 7 exposure?
Standard contractual clauses and contractual confidentiality obligations do not override statutory national-security cooperation duties under CSL Article 7. A Chinese-incorporated entity or entity with operational presence in China cannot lawfully refuse a national-security request from Chinese authorities by citing a foreign contract. The CJEU confirmed in Schrems II that contractual mechanisms alone are inadequate where a third-country's legal system does not provide equivalent protection.
How does CADA Article 16 specifically address Chinese-jurisdiction cloud providers?
CADA Article 16 (part of the EU Data Act's Cloud-switching and Porting provisions) requires that cloud service contracts include provisions ensuring that data is not made accessible to third-country governments in ways that conflict with EU or member-state law, unless based on an international agreement. This rule is jurisdiction-neutral and applies equally to US-jurisdiction and Chinese-jurisdiction exposure, meaning Chinese-law national-security obligations must be disclosed and assessed as a contract precondition.
Which EU member-state DPAs have taken enforcement action specifically involving Chinese-owned sub-processors?
As of early 2024, no EU DPA has published a final enforcement decision naming a Chinese-owned sub-processor as the sole respondent. However, the Italian DPA (Garante) and the Austrian DPA (DSB) have both issued decisions finding GDPR Chapter V violations where transfer impact assessments failed to account for the national-security laws of the receiving or controlling entity's home jurisdiction. These decisions establish the analytical precedent that Chinese-law obligations must be assessed in the same way as US CLOUD Act or FISA 702 obligations.
What is the most practical first step for a DPO assessing Chinese-law exposure in an existing vendor portfolio?
Map every sub-processor in your data processing agreements to its ultimate beneficial owner and registered jurisdiction. For any vendor with Chinese equity ownership above 25%, or with Chinese nationals on the board in security-relevant roles, perform a transfer impact assessment that specifically addresses CSL Article 7, DSL data-classification obligations, and PIPL's cross-border transfer consent framework. Document the assessment and the residual risk decision in writing before the next GDPR audit cycle.