Cross-border data transfers between the EU and China

Converging principles, diverging rules

With the growing digitalisation of business, companies increasingly transfer personal data across borders as part of their daily operations. For organisations active in both Europe and China, understanding the rules governing these transfers is essential not only for compliance, but also for maintaining uninterrupted business operations. This article examines data transfers between the European Union (EU) and China, which are governed respectively by the General Data Protection Regulation (GDPR)[1] and the Personal Information Protection Law (PIPL).[2] Carlo Diego D’Andrea and Jun Jie Yang explain that while both frameworks aim to protect personal data, they reflect different regulatory philosophies and enforcement approaches.


At first glance, the GDPR and the PIPL appear to share a number of common principles. Both have extraterritorial scope, meaning that they may apply to processing activities conducted outside their respective territories when EU or Chinese personal data is involved. Both also emphasise lawful processing, transparency and data security.

However, their underlying structures differ significantly. The GDPR is built around the concept of accountability, placing responsibility on companies to ensure compliance, supported by independent supervisory authorities. The PIPL, by contrast, operates within a broader governance framework that reflects China’s approach to data security and digital sovereignty, where regulatory oversight plays a more central role.

Cross-border transfers under the GDPR

Under the GDPR, personal data may be transferred outside the EU only if one of the conditions set out in Chapter V is satisfied. The most straightforward mechanism is an ‘adequacy decision’ by the European Commission, which confirms that a third country ensures a level of data protection essentially equivalent to that of the EU.

In the absence of an adequacy decision,[3] companies must rely on alternative safeguards. These include Standard Contractual Clauses (SCCs), which are standard agreements approved by the European Commission, or Binding Corporate Rules (BCRs), typically used within multinational groups.

In addition, companies are generally required to carry out a Transfer Impact Assessment (TIA), a risk assessment that examines whether local laws in the destination country (particularly those allowing access to data by public authorities) may affect the level of protection guaranteed to EU personal data.

At present, no adequacy decision exists between the EU and China. As a result, transfers from the EU to China typically rely on SCCs combined with a TIA.

The EU’s approach to international data transfers has been shaped by important court decisions. In particular, the Schrems I[4] and Schrems II[5] judgments of the EU’s Court of Justice invalidated previous transfer frameworks with the United States, emphasising the need for effective safeguards against disproportionate access to personal data.

Cross-border transfers under the PIPL

China’s PIPL adopts a different structure for cross-border data transfers. It provides several compliance pathways depending on the nature of the data and the scale of processing.

Companies transferring personal information outside China may be required to undergo a security assessment organised by the Cyberspace Administration of China (CAC), conclude a standard contract and file it with the CAC, or obtain certification from an approved institution.

In certain cases, simplified procedures or exemptions may apply. For example, some intra-group transfers for human resources or internal administrative purposes may fall outside the main requirements. At the same time, specific categories of operators, such as those processing large volumes of data, may be subject to data localisation obligations, meaning that personal data must generally be stored within China unless specific conditions are met.

This multi-layered system reflects China’s broader regulatory approach, where data protection is closely linked to national security and public interest considerations.

Case study: DeepSeek in Italy

A recent enforcement action shows how these regulatory differences can translate into immediate business risks.

In 2025, the Italian Data Protection Authority ordered the temporary suspension of the AI service offered by DeepSeek in Italy.[6] The measure followed concerns regarding compliance with the GDPR, particularly in relation to transparency obligations and the handling of personal data.

The authority requested detailed information on the categories of personal data processed, the purposes of processing, the legal basis relied upon, and the way in which data was stored and potentially transferred abroad. Particular attention was given to whether the personal data of EU users could be transferred to servers located in China without appropriate safeguards. In the absence of clear and sufficiently detailed explanations, the authority adopted a precautionary approach and restricted access to the service pending further assessment.

This case highlights a key aspect of the GDPR: companies must not only comply with the rules but must also be able to demonstrate compliance at any time.

From a cross-border data transfer perspective, the case also underlines the importance of identifying a valid transfer mechanism, carrying out a meaningful risk assessment and ensuring that users are clearly informed about how their data is handled.

More broadly, it illustrates the different regulatory logic of the two systems. While the PIPL allows cross-border transfers subject to compliance with procedural requirements, the GDPR places strong emphasis on individual rights and enables supervisory authorities to intervene rapidly where risks are identified.

Practical implications for multinational companies

For multinational companies operating across Europe and China, aligning compliance with both the GDPR and the PIPL can be complex, but it is increasingly necessary.

A key starting point is mapping data flows. Companies need to understand where personal data is collected, how it is processed, where it is stored, and whether it is transferred across borders. Clear and consistent documentation is equally important. Privacy notices, internal policies and contractual arrangements should be aligned, while still reflecting the specific requirements of each jurisdiction. In practice, many organisations adopt a dual compliance approach, with separate documentation and procedures for EU and China operations.

Risk assessments should also be treated as practical tools rather than formalities. Whether under the GDPR or the PIPL, these assessments help identify legal and operational risks and support informed decision-making. Finally, companies should be prepared for regulatory scrutiny. As illustrated by the DeepSeek case, enforcement actions may occur quickly and can lead to operational disruption, including restrictions on services or data flows.

A gradual convergence

Despite their differences, the GDPR and the PIPL are showing signs of gradual convergence around key principles such as transparency, accountability and data security.

For companies operating across both jurisdictions, developments in one system may increasingly support compliance in the other. Concepts such as privacy by design and strong internal governance are becoming central in both frameworks.

In an increasingly interconnected digital environment, a proactive and integrated approach to data protection is essential. Companies that invest in clear governance structures and cross-jurisdictional expertise are generally better positioned to manage risk while maintaining operational flexibility.

In practical terms, businesses should regularly map their data flows, review privacy notices and internal policies, verify the legal basis for international transfers, and ensure that contracts with service providers and business partners contain appropriate data protection provisions. Employee training and internal compliance procedures are also becoming increasingly important, particularly for companies handling customer data across multiple jurisdictions.

Given the complexity of cross-border data transfers and the continuing evolution of both regulatory systems, companies should consider seeking advice from qualified legal practitioners whenever there is uncertainty regarding the applicability of transfer requirements, data localisation obligations or the compliance of international data processing operations.


Carlo Diego D’Andrea is the founder and managing partner of D’Andrea & Partners Legal Counsel, vice president of the European Chamber and chair of its Shanghai Chapter. Based in China since 2005, he advises multinational companies on regulatory compliance, foreign investment, intellectual property and data protection.

Jun Jie Yang is an Italian-qualified lawyer and associate at D’Andrea & Partners Legal Counsel in Shanghai, focussing on data protection, regulatory compliance and cross-border legal matters between Europe and China.

D’Andrea & Partners Legal Counsel is an international law firm assisting companies with cross-border legal and regulatory matters between Europe and Asia. With offices in China, Italy and other international markets, the firm advises multinational businesses on corporate, compliance, dispute resolution and data protection matters.


[1] REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), European Union, 27th April 2016, viewed 18th May 2026, <https://eur-lex.europa.eu/eli/reg/2016/679/oj>

[2] Personal Information Protection Law of the People’s Republic of China, Cyberspace Administration of China, 20th August 2021, viewed 18th May 2026, <https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm>

[3] For a list of adequacy decisions, see: Adequacy decisions, European Commission, last updated 10th February 2026, viewed 18th May 2026, <https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en>

[4] To see the details of the judgement, search the term ‘C-362/14’ on the Court of Justice of the European Union’s InfoCuria database. See: InfoCuria, European Union, viewed 18th May 2026, <https://infocuria.curia.europa.eu/>

[5] The CJEU judgment in the Schrems II case, European Parliament, September 2020, viewed 18th May 2026, <https://www.europarl.europa.eu/RegData/etudes/ATAG/2020/652073/EPRS_ATA(2020)652073_EN.pdf>

[6] Artificial Intelligence: The Italian Data Protection Authority blocks DeepSeek, Garante per la protezione dei dati personali, 30th January 2025, viewed 18th May 2026, <https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/10097450#english>