Series
Blogs
Series
Blogs
Organisations in China are prohibited from providing foreign judicial and law enforcement bodies with data stored in China without prior approval of the competent Chinese authority.
China has released a series of such blocker laws over the last few years at national level – principally the Data Security Law (DSL) in respect of all data types and, to the extent personal information is involved, the Personal Information Protection Law (PIPL); while many industry-level authorities are imposing similar restrictions on their regulated entities.
For a multinational organisation required by its home jurisdiction to produce information from its China operations, these data export controls can give rise to a compliance impasse within a group if there is not an established channel for information exchange between China’s and the counterpart market’s authorities.
Almost three years since the implementation of the DSL and the PIPL, we are seeing increasing numbers of judicial cases and administrative enforcement where these disclosure restrictions have been tested by non-PRC regulators and judiciaries, such as the US courts. This legal dilemma has recently been underscored in a case between the European Commission (Commission) and the Nuctech group.
Below we set out details of the Nuctech case and some practical steps for multinationals to consider in response to these conflicting requirements.
Facts
In April, the Commission conducted inspections of Nuctech in the Netherlands and Poland, a business specialising in security inspection equipment ultimately owned by a partly Chinese state-owned enterprise.
During the inspection, the Commission requested the content of several employees’ email accounts. The requested data is stored on the servers owned by Nuctech’s parent in China, and relates to correspondence of employees who are Chinese citizens.
Nuctech applied to the General Court of the EU for relief, seeking to resist the Commission's request by arguing that compliance would force Nuctech to breach Chinese law.
The Court has now rejected Nuctech’s application for an interim injunction, upholding the Commission’s right to request the data for its investigation into suspected breaches of EU law, regardless of where the data is stored.
Arguments and rulings
To challenge and seek a suspension of the Commission’s request, Nuctech raised several arguments that touch upon the differences between the laws of the different jurisdictions. These arguments were rejected by the Court.
The Court regarded Nuctech’s arguments as overly general and lacking sufficient detail. The Court emphasised that the lawfulness of the Commission's decision and its implementation measures were assessed solely in light of EU law, not Chinese law. Further, the Court noted that violation of the Chinese law provisions cited by Nuctech would only occur if the data were disclosed without prior authorisation from the Chinese authorities. However, Nuctech had not shown attempts to secure this authorisation, nor had it proposed alternative compliance methods.
Implications
This case underscores the complex and conflicting legal scenarios presented for Chinese-headquartered multinationals, where compliance with domestic data security laws may result in non-compliance with foreign laws in the EU (or other markets) in which they operate.
To mitigate these risks, Chinese companies operating in the EU should consider the following strategies:
There are views in the market that if Nuctech had provided sufficient information on the above points, the Court might have been more sympathetic to it. This highlights the importance of thorough preparation when seeking legal relief.
Take action
Before international conventions or domestic implementation rules in either jurisdiction are enacted, the challenge for companies facing conflicting legal requirements will keep rising, creating a precarious situation where compliance with one set of laws necessitates breaching another.
To navigate these intertwined legal landscapes, Chinese companies need meticulous preparation, strategic communication, and robust IT infrastructure and data management strategies to mitigate the risks resulting from their global footprints. The hardened stance of the EU judiciary shown by this case, in the context of broader geopolitical tensions, should be a call-to-action for legal and compliance teams.
Our international Investigations practice is familiar with handling cross-border disputes and data requests, as well as planning ahead to set internal policies and protocols for your personnel to follow to avoid inadvertent breaches of law in either hemisphere. Please drop us an email to find out more!