Developments in Supply Chain Security and Cross-Border Compliance for FIEs in China
Published 23 June 2026
Sarah Xuan
Over the past two years, China has markedly accelerated the development of its regulatory regimes concerning supply chain security, export controls, cross-border data transfers, foreign investment access, and countermeasures against long-arm jurisdiction. For foreign-invested enterprises in China, China compliance has expanded from traditional matters such as corporate establishment, industry licensing, taxation, and labor and employment to more complex issues including supply chain resilience, the flow of technology and data, conflicts involving foreign sanctions, the implementation of intra-group instructions, and the coordination of global compliance systems. When multinational enterprises operate in China, they need to understand both China’s policy direction of expanding openness and the trend toward strengthened security and compliance rules, and to establish more refined coordination mechanisms between globally unified compliance policies and local Chinese legal requirements.
I. Supply Chain Security Has Become an Independent Regulatory Theme
State Council Order No. 834, namely the Regulations of the State Council on Industrial and Supply Chain Security, which were promulgated and implemented in 2026, is one of the recent regulatory instruments most deserving of attention by foreign-invested enterprises. The Regulations were adopted at the State Council executive meeting on March 13, 2026, signed and promulgated by the Premier of the State Council on March 31, 2026, and came into force as of the date of promulgation. Their legislative purpose is to prevent security risks in industrial and supply chains, enhance the resilience and security level of industrial and supply chains, and maintain economic and social stability as well as national security.
The significance of the Regulations lies in the further institutionalization of supply chain security. Chinese competent authorities may establish security work mechanisms around industrial and supply chains in key sectors, and carry out risk monitoring, risk prevention, and emergency response. For foreign-invested enterprises, the relevant impact may arise in multiple links, including procurement, production, supply, logistics, technical support, after-sales services, raw material assurance, and the supply of key components. In particular, where key sectors or important industrial chains are involved, an enterprise’s unilateral interruption of supply, restriction of transactions, implementation of foreign sanctions, or adoption of discriminatory measures may no longer be merely an issue of contractual performance, but may also fall within the perspective of China’s regulation of industrial and supply chain security.This means that when formulating China supply chain strategies, multinational enterprises need to assess “China supply chain security” as a separate compliance dimension. Decisions made by headquarters based on global risk control, export controls, sanctions policies, or business restructuring, if they will affect Chinese customers, suppliers, or nodes in the industrial chain, should be assessed in advance for enforceability under Chinese law, contractual liability, regulatory communication requirements, and potential countermeasure risks.
II. Rules Countering Long-Arm Jurisdiction Strengthen Multinational Enterprises’ Management of Sanctions ConflictsState Council Order No. 835, namely the Regulations of the People’s Republic of China on Countering Unjustified Extraterritorial Jurisdiction by Foreign States, was adopted at the State Council executive meeting on March 27, 2026, signed and promulgated by the Premier of the State Council on April 7, 2026, and came into force as of the date of promulgation. The Regulations are intended to safeguard national sovereignty, security, and development interests, protect the lawful rights and interests of Chinese citizens and organizations, and establish a response mechanism for foreign laws, measures, and enforcement acts that China considers to constitute unjustified extraterritorial jurisdiction.
Together with the Law of the People’s Republic of China on Countering Foreign Sanctions, the Ministry of Commerce’s Rules on Counteracting Unjustified Extraterritorial Application of Foreign Legislation and Other Measures, and the Unreliable Entity List regime, the Regulations form an important institutional framework through which China responds to foreign sanctions, export controls, and long-arm jurisdiction. The Law of the People’s Republic of China on Countering Foreign Sanctions was adopted, promulgated, and implemented on June 10, 2021, and it makes clear that China has the authority to take corresponding countermeasures against discriminatory restrictive measures imposed by foreign states on Chinese citizens and organizations under their domestic laws. The Provisions on Implementing the Law of the People’s Republic of China on Countering Foreign Sanctions, promulgated in 2025, further refined the relevant implementation mechanisms and came into force as of the date of promulgation.
For foreign-invested enterprises in China, the most practical impact of this combination of regimes is “sanctions conflict.” For example, based on sanctions, export controls, or other foreign legal requirements of its home jurisdiction, a foreign parent company may require its Chinese subsidiary to cease supplying a particular Chinese customer, terminate services, or refuse to perform an existing contract. If the transaction is not prohibited under Chinese law, but the cessation of transactions is viewed by Chinese competent authorities as implementing unjustified foreign extraterritorial measures, harming the lawful rights and interests of Chinese enterprises, or affecting China’s supply chain security, the Chinese subsidiary may face compliance risks under Chinese law. Accordingly, multinational enterprises cannot rely solely on headquarters sanctions lists or global policies as the sole basis for actions in China, and should establish mechanisms for Chinese law review, conflict-of-laws assessment, exemption applications, internal escalation, and recordkeeping of local implementation.
III. Export Controls Have Extended from the Administration of Goods to Technology, Services, and Data
State Council Order No. 792, the Regulations of the People’s Republic of China on Export Control of Dual-Use Items, was promulgated on September 30, 2024, and came into force on December 1, 2024. The Regulations apply to the export control of dual-use items, and define dual-use items as goods, technologies, and services that have both civil and military uses or that contribute to enhancing military potential, including data such as relevant technical materials.
This regulation is of significant importance to enterprises in manufacturing, electronics, semiconductors, aerospace, chemicals, life sciences, advanced materials, software, equipment maintenance, and engineering services. The focus of export control compliance is no longer limited to the export of physical items, but also includes technical materials, design drawings, software, source code, testing data, remote maintenance support, cross-border research and development collaboration, and intra-group technology sharing. When foreign-invested enterprises conduct research and development, production, or after-sales support in China, they should identify whether their products, technologies, and services involve dual-use item controls, and review the end users, end uses, transaction paths, and overseas recipients.
In practice, many enterprises tend to underestimate the compliance risks of “non-physical exports.” Engineers sending technical documents by email to overseas teams, overseas headquarters remotely accessing design data stored on servers in China, Chinese teams providing equipment commissioning parameters to overseas customers, or Chinese maintenance teams providing technical support to overseas affiliates may all need to be brought within the dual review scope of export controls and data export. Foreign-invested enterprises should integrate export controls, technology transfers, cross-border data transfers, and intellectual property management into a unified technology-flow review process.
IV. Cross-Border Data Rules Have Entered a Stage of Refined Application
Data compliance remains one of the core issues for foreign-invested enterprises operating in China. State Council Order No. 790, the Regulations on Network Data Security Administration, was promulgated on September 24, 2024, and came into force on January 1, 2025. The Regulations apply to network data processing activities within China, and also apply in specific circumstances to activities conducted overseas to process the personal information of natural persons within China, as well as overseas network data processing activities that harm China’s national security, public interests, or the lawful rights and interests of Chinese citizens or organizations.
At the same time, the Cyberspace Administration of China promulgated and implemented the Provisions on Promoting and Regulating Cross-Border Data Flows on March 22, 2024. The Provisions optimize and coordinate mechanisms including security assessments for data exports, standard contracts for the outbound transfer of personal information, and personal information protection certification, and specify that data processors shall identify and declare important data in accordance with the relevant provisions; where data has not been notified by the relevant departments or regions, or publicly released, as important data, data processors are not required to declare a data export security assessment on the basis that the data is important data. Official interpretations have also indicated that the Provisions optimize the filing criteria for security assessments of important data exports, certain exemption scenarios, and facilitation arrangements for cross-border data flows.For foreign-invested enterprises, cross-border data compliance has shifted from a single determination of “whether data may be exported” to a more granular determination of “what data, what scenario, what path, and what obligations.” Group human resources systems, customer relationship management systems, global financial shared service platforms, after-sales service systems, supplier management platforms, compliance investigation systems, research and development collaboration platforms, and cloud service architectures may all involve the transfer of personal information, important data, or business data within China to overseas headquarters, regional centers, overseas service providers, or other affiliates.
The current rules provide clearer pathways in a number of ordinary commercial scenarios, but enterprises must still perform obligations such as personal information notices, separate consent, personal information protection impact assessments, data processing agreements, access controls, security incident response, and recordkeeping management. For manufacturing and high-technology enterprises, if the data involves production operations, supply chain nodes, industrial control systems, key equipment, location information, research and development data, or important data identified by industry competent authorities, compliance reviews should be conducted with greater prudence.
V. Foreign Investment Access Continues to Be Liberalized, While Operational Compliance Requirements Increase in Parallel
With respect to foreign investment access, the Special Administrative Measures (Negative List) for Foreign Investment Access (2024 Edition) were issued by the National Development and Reform Commission and the Ministry of Commerce under Order No. 23 of 2024, and came into force on November 1, 2024. This edition is the latest effective version of the national negative list for foreign investment access that can currently be confirmed. Official interpretations state that the 2024 edition of the national negative list for foreign investment access reduced restrictive measures from 31 to 29, and completely removed foreign investment access restrictions in the manufacturing sector.
This change is of positive significance for foreign-invested enterprises, particularly advanced manufacturing, industrial equipment, automotive components, electronic information, materials, intelligent manufacturing, and research-and-development-oriented projects. The removal of foreign investment access restrictions in manufacturing at the national level is conducive to multinational enterprises establishing more complete production, research and development, and supply chain systems in China.
However, liberalized access does not mean that operational compliance burdens have been reduced. Foreign-invested enterprises still need to verify whether their specific businesses involve sectors retained on the negative list, the market access negative list, industry licensing, approval or filing of fixed-asset investment, environmental protection, energy consumption, work safety, cybersecurity, data export, export controls, antitrust, and other requirements. For multinational enterprises, China’s regulatory trend is characterized by “more open access, more refined operations, and more integrated risks.” The threshold for enterprises to enter the Chinese market has been lowered in certain sectors, but after entry they must face more systematic compliance requirements across the full life cycle.
Implications
The above regimes show that China’s recent regulatory development has several common features. First, security factors occupy a more important position in supply chains, data, technology, and cross-border transactions. Second, the targets of regulation have extended from single legal entities to groups, affiliates, overseas headquarters, overseas service providers, and transaction chains. Third, compliance risks are gradually moving forward from ex post penalties to the stages of transaction design, supply chain decision-making, data architecture, and the implementation of internal instructions. Fourth, conflicts between Chinese rules and foreign sanctions, export controls, data protection, and supply chain due diligence rules have become more common.
Foreign-invested enterprises in China should adjust their compliance governance accordingly. Enterprises may proceed from four aspects. First, they should establish supply chain risk assessment mechanisms under Chinese law and conduct compliance reviews of key suppliers, key customers, key materials, alternative supply, contract termination, and supply interruption arrangements. Second, they should incorporate export controls, technical materials management, cross-border data transfers, and research and development collaboration into a unified approval process, so as to avoid business departments bypassing legal review on the ground of commercial convenience. Third, they should establish sanctions conflict handling mechanisms, under which Chinese legal, compliance, and business teams and headquarters compliance teams jointly assess the consequences under Chinese law when foreign headquarters proposes requirements to cease transactions, freeze cooperation, refuse services, or restrict supply. Finally, they should continuously update mechanisms for foreign investment access, industry licensing, data compliance, and government list screening, so that the daily operations of Chinese subsidiaries can promptly reflect regulatory changes.
China is continuing to expand high-standard opening-up, while also establishing a more complete regulatory framework for supply chain security, data security, technology exports, and countermeasures against long-arm jurisdiction. For foreign-invested enterprises, this environment provides new market opportunities while also requiring enterprises to manage cross-border operational risks to a higher standard. In the coming period, the compliance focus for foreign-invested enterprises in China will no longer be limited to the application of a single regulation; rather, it will require a comprehensive assessment of the cross-cutting effects among supply chains, technology, data, sanctions conflicts, and foreign investment operations. Enterprises that can establish localized, cross-functional, and executable compliance systems at an early stage will be better positioned to maintain business continuity and transaction security under the new regulatory environment.