Regingada
Sector · Digital business

The EU-China bridge — two regimes, one data flow

Sector profile · Source: Funk corpus (CELEX/ELI-anchored) · Status: 2026-08

This profile covers two mirrored situations: a Chinese provider serving the EU market, and a European company running operations in China. Both look at the same pipe from opposite ends, and both discover that the pipe is governed twice over. On the European side the GDPR asks who represents the company in the Union and under which instrument data leaves it; the DSA and the AI Act add designation duties where the services or products fall within their scope. On the Chinese side the PIPL asks on what basis personal information is handled at all, and which of the cross-border mechanisms carries a provision abroad. Neither side accepts the other's paperwork as its own, which is why the documentation has to exist twice and stay consistent.

  • GDPR · Art. 27 + Chapter V
  • DSA · Art. 13 · intermediary services only
  • AI Act · Art. 22 / Art. 54 · where in scope
  • PIPL · cross-border provision
  • DSL and CSL
  • NIS2 · not activated by a data flow alone

Sector profile for orientation, strictly regulatory. It describes what the norms provide for a constellation of this shape. Whether they reach a concrete company, and in which role, is a legal assessment and belongs to a mandate — not to a sector page.

1 · Regime footprint

Both ends of the pipe, listed separately

The table keeps the two sides apart on purpose. Mixing them is how transfer files end up describing one direction well and the other not at all. Read the European rows for what the Union expects of a company that reaches its market, and the Chinese rows for what applies to the handling and outbound provision of personal information. The Chinese framework has been moving: exemption rules and free-trade-zone negative lists have narrowed which transfers need a formal mechanism, and those lists change — so the position is re-checked rather than assumed.

Regime footprint

Regime & norm Why it applies What to do first
GDPR · Art. 3 and Art. 27 A controller or processor without an establishment in the Union that offers goods or services to people in the EU or monitors their behaviour falls within the GDPR and, subject to the exemptions, has to designate a representative in the Union. Settle the extraterritorial question first, then the exemption in Art. 27(2), then designate and name the representative in the privacy notice.
GDPR · Art. 44 to Art. 49 Any transfer to a third country needs an instrument: an adequacy decision, appropriate safeguards such as standard contractual clauses or binding corporate rules, or one of the narrow derogations. Map the flows before choosing instruments — including remote access, support and backup, which are transfers even when nothing is copied on purpose.
DSA · Art. 13 Providers of intermediary services without an establishment in the Union that have a substantial connection to it designate a legal representative and make the details publicly available. Determine first whether a service is an intermediary service at all; an online shop selling its own goods is not one, a hosting or platform component may well be.
AI Act · Art. 22 and Art. 54 Providers outside the Union that make high-risk AI systems or general-purpose models available in the Union appoint an authorised representative by written mandate — two separate duties with separate triggers. Classify the product first: high-risk system, general-purpose model, or neither. The classification decides which of the two appointments is owed.
PIPL · consent and separate consent The PIPL builds on notice and, in many constellations, on consent — and it requires a separate consent for specified operations, including provision of personal information to another handler and provision outside the country. Check whether the existing consent architecture actually separates those operations, rather than bundling them into one acceptance.
PIPL · Art. 38 to Art. 40 Outbound provision runs through one of the routes the law provides: a security assessment by the authority, a standard contract with filing, or certification. Operators of critical information infrastructure and volume thresholds bring localisation into play. Establish the route per flow and per volume, and re-check it — the thresholds and the exemption rules have changed more than once.
DSL and CSL · classification and network security Alongside personal information, the Data Security Law works with data classification and the category of important data, while the Cybersecurity Law carries network-operation and protection duties. Both can attach to the same systems as the PIPL. Inventory what data the local operation actually holds before designing the transfer — classification decides more than the destination does.

Not activated by a data flow on its own: NIS2, which attaches to listed sectors and size thresholds, and the Data Act chapters on connected products. They arrive through what the company operates, not through where its data travels.

2 · Where it gets expensive

Three seams that cost coordination

  • Two transfer mechanics, both directions at once

    A support case that travels from a European subsidiary to a Chinese engineering team and back is not one transfer but two, and each end is governed by its own rulebook: a Chapter V instrument on the European side, one of the Art. 38 routes plus its own consent layer on the Chinese side. Building only the outbound direction is the most common gap, because the return leg feels like the same conversation. Two instruments, two files, two authorities — on one ticket.

  • Consent is not the same word twice

    The GDPR sets its own conditions for valid consent and treats consent-based transfers as a narrow derogation rather than a working default. The PIPL uses consent far more centrally and asks for a separate consent for specific operations, including provision abroad. A text drafted for one regime therefore does not carry the other, and a bridge built on consent alone is fragile at both ends. The instruments have to be chosen per direction, not per company.

  • Localisation against access from the EU

    Where rules keep certain data inside the country while European teams need access for support, security monitoring or audit, the question is not where the storage sits. Remote access is itself a provision, and a read-only console does not change that. The design question is therefore an access question: who sees what, from where, under which mechanism — and it has to be answered before the architecture is built, because afterwards it can only be documented.

The full map of the seams inside EU digital law: the collision map.

3 · Companies without an EU establishment

The designations stack, they do not substitute

A provider from outside the Union serving the EU market can owe designations under several acts at once: the representative under Art. 27 GDPR, the legal representative under Art. 13 DSA for intermediary services, and the authorised representative under Art. 22 or Art. 54 AI Act. The functions sound alike and the acts are separate, so a designation made under one of them discharges nothing under another. Which of them actually fire depends on what the company offers in the Union, service by service.

Where the duties come from and how they stack: EU representation overview and the representative compass. Regingada UG (haftungsbeschränkt) takes on appointed representative functions; whether a concrete company owes one, and under which act, is a legal assessment in a separate mandate.

A practical note for teams working from the mainland: this site runs a Chinese edition at cn.regingada.com, and the suite is reachable from there, so a joint EU-China project does not have to be coordinated through a channel that only one side can open.

4 · What the twin delivers

One profile, both rulebooks visible

  • Obligation cockpit for the European sideThe duties that the EU acts attach to the role in question, with the designation duties shown as a stack rather than a single generic representative. Each entry carries its source node, so the list reads back to the norm text instead of resting on trust.
  • Transfer view per flowFlows listed by direction, with the instrument shown for each end instead of a single label for the relationship. Remote access and support paths appear as flows in their own right.
  • Collision mapThe seams that this constellation produces — two transfer mechanics, two consent concepts, access against localisation — as explicit connections rather than a list of separate checklists.
  • Radar watchChange entries tagged to the profile rather than a general newsfeed: movement in transfer instruments, guidance and lists on the Chinese side, timetables on the European side. The radar reports the state of its watchlist with a date; it does not claim to be a live feed.
  • Deliverables, marked DRAFTObligation register, gap report, a flow inventory and an outline for the transfer documentation. Everything the suite produces is a DRAFT: no signature, no assessment, no liability. It becomes an assessment when the law firm Theo Funk takes it into a mandate and signs it off — and questions of Chinese law belong to advisers qualified in that jurisdiction.
5 · Step 2

Where the software stops

Everything above is orientation: a map of what a constellation of this shape reaches, drawn from a public corpus and readable back to its sources. It is structured self-assessment and decision support, not an evaluation of a specific company and not legal advice. Which instrument carries a given flow, whether a designation is owed and how the two files stay consistent is the second step. On the European side that step belongs to the law firm Theo Funk under a separate mandate; questions of Chinese law belong to advisers qualified there. Regingada UG (haftungsbeschränkt) builds the software and takes on appointed EU-representative functions; the firm does the legal work.

Worked through on a fictional demo profile: a provider seated outside the Union with three appointments inside it.

Disclaimer

Orientation, not legal advice

This sector page and the suite provide orientation and information only. They are not legal advice, and the description of non-EU law is a summary of published rules rather than advice on them. Individual-case advice on EU law is provided exclusively by the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) — the software company and appointed EU representative — and the law firm are strictly separated.