Skip to main content

Data Privacy & Cybersecurity · Counsel brief · 11 min · Updated 9 Aug 2026

GDPR for Chinese Companies: DPO, EU Representative and the China-Return Data Flow

GDPR for Chinese companies: when it applies, the Article 27 EU Representative vs the Article 37 DPO, and how to build a lawful EU-to-China data flow under SCCs and PIPL.

Key takeaways
  1. This guide is published for research orientation on China Legal Portal.
  2. Statutes, procedures, thresholds and practical outcomes may change.
  3. Confirm current primary sources and obtain advice from appropriately qualified counsel before relying on this material for a transaction or filing.
Cite this article
Article
GDPR for Chinese Companies: DPO, EU Representative and the China-Return Data Flow
Author
Niamh Walsh
Last updated
9 Aug 2026
Publisher
China Legal Portal

Niamh Walsh. “GDPR for Chinese Companies: DPO, EU Representative and the China-Return Data Flow.” China Legal Portal, updated 9 Aug 2026. https://chinalegalportal.com/gdpr-chinese-companies-dpo-eu-representative-china-return-data-flow

Related Legal Guide: Use the complete Overseas Data Operations for Chinese Companies framework to map roles, vendors, security, incidents and China-return transfers.

Chinese tech, e-commerce and gaming companies expanding into the European Single Market are discovering that a European launch is, first and foremost, a data-law project. The General Data Protection Regulation (GDPR) reaches far beyond the EU's borders, and it now sits on top of a second, equally demanding layer: China's Personal Information Protection Law (PIPL), Data Security Law (DSL) and Cybersecurity Law (CSL). Generic GDPR guides written for European startups do not answer the questions a Beijing or Shenzhen headquarters actually faces, because they ignore the China-return flow — the movement of EU customer and employee data back to mainland China for R&D, product, service or HR purposes.

This guide explains when the GDPR applies to a mainland Chinese business, the difference between the Article 27 EU Representative and the Article 37 Data Protection Officer, and how to build a lawful architecture for the EU-to-China data pipeline. It is written for decision-makers who need the compliance logic, not a statute recital. For a compliance programme tailored to your exact structure, consult Niamh Walsh, EU data protection counsel in Dublin.

1. Does the GDPR apply to your mainland Chinese business?

The short answer is: more often than you think. Article 3(2) of the GDPR extends the regulation to a controller or processor not established in the Union where the processing relates to (a) the offering of goods or services to data subjects in the EU, regardless of whether payment is required, or (b) the monitoring of their behaviour in so far as their behaviour takes place within the Union.

Two misconceptions are common among Chinese multinationals. First, the belief that having no physical office in Europe means the GDPR cannot apply. Under Article 3(2), a Chinese SaaS platform selling subscriptions in EUR, a gaming company with EU users, or an e-commerce site shipping to Germany all fall squarely within scope. Second, the belief that routing data through Hong Kong creates an exemption. Hong Kong is a third country for EU data-protection purposes; it does not make EU personal data invisible to the GDPR, and the Hong Kong route adds a third transfer layer rather than removing the first.

The enforcement stakes are not theoretical. Article 83(5) permits administrative fines of up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher, for core violations such as processing without a lawful basis, unlawful transfers, or failing to comply with an EU data-protection order. Beyond fines, EU supervisory authorities can impose operational bans under Article 58(2)(f), which in practice can stop a product feature, an ad campaign, or an entire processing activity overnight.

The leading case is the Court of Justice of the European Union's judgment in Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (Case C-311/18, 16 July 2020), known as Schrems II. The CJEU invalidated the EU-US Privacy Shield and confirmed that transfers under Standard Contractual Clauses remain valid only where a Transfer Impact Assessment (TIA) shows the destination country's law does not undermine the protection SCCs are meant to guarantee. For transfers to mainland China, that assessment must engage directly with Chinese law — the National Intelligence Law, the Counter-Espionage Law, the Data Security Law and the Cybersecurity Law — and with the access powers those laws confer.

2. EU Representative (Article 27) vs Data Protection Officer (Article 37)

Chinese companies without an EU establishment frequently confuse two distinct roles. They are not interchangeable and both may be required.

The Article 27 EU Representative is mandatory for a controller or processor not established in the EU that processes data in a way that falls under Article 3(2) (offering goods or services to EU data subjects, or monitoring their behaviour). The representative must be established in an EU Member State where the data subjects whose data is processed are located, and must be designated in writing. Its function is to be the local point of contact for supervisory authorities and data subjects, and to cooperate with them. It can be an individual or an organisation, and it can act for several controllers or processors — but it must have sufficient powers and resources to cooperate. The Article 27 GDPR and the European Data Protection Board Guidelines 3/2018 set out the requirements, and the representative can face enforcement actions or proceedings in the Member State where it is established.

The Article 37 Data Protection Officer is a different creature. A DPO is mandatory where the core activities of the controller or processor consist of (a) processing operations which, by virtue of their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale, or (b) large-scale processing of special categories of data or data relating to criminal convictions. The DPO's job is internal: to inform and advise, to monitor compliance, to cooperate with the supervisory authority, and to act as its contact point. Article 38(3) requires that the DPO does not receive instructions from executive management regarding the exercise of DPO tasks, and must not be dismissed or penalised for performing them. A Chinese parent company that treats its DPO as a reporting employee who must follow HQ instructions has already breached the GDPR's independence requirement.

FeatureEU Representative (Article 27)Data Protection Officer (Article 37)
TriggerNon-EU controller/processor offering goods/services or monitoring EU data subjectsCore activities involve regular/systematic large-scale monitoring, or large-scale special-category processing
LocationMust be in an EU Member State where the data subjects areCan be inside or outside the EU, provided accessibility
RoleExternal liaison for authorities and data subjectsInternal compliance advisor and monitor
IndependenceActs under the controller's instructionMust not receive instructions from management
Diagram in text
  • Analytical diagram showing when GDPR Article 3(2) applies to a mainland Chinese business without EU establishment, that Hong Kong routing is not an exemption, and the non-interchangeable roles of the Article 27 EU Representative and the Article 37 Data Protection Officer.
  • GDPR territorial scope and Art. 27 EU Representative versus Art. 37 DPO for Chinese companies.
  • Article 3(2) extraterritorial scope + two roles Chinese HQ must not confuse
  • Controller / processor not established in the EU
  • Beijing / Shenzhen HQ · no EU office · China-return data still in scope

3. Solving the China-return data flow (EU to China transfers)

Chapter V of the GDPR (Articles 44-49) governs transfers of personal data to third countries. China has no European Commission adequacy decision, so every EU-to-China transfer must be justified by an appropriate safeguard under Article 46 — in practice, the EU Standard Contractual Clauses (SCCs) adopted by Commission Implementing Decision (EU) 2021/914 — or by a derogation under Article 49. The derogations are narrow; for most Chinese groups operating a genuine EU business, SCCs are the working tool.

Under Schrems II, executing SCCs is not enough. The exporter must assess, case by case, whether the law of the destination country impinges on the effectiveness of the safeguards. That means a Transfer Impact Assessment that looks at Chinese law and at the technical and organisational measures in place. Where the TIA identifies a problem, the exporter must add supplementary measures: end-to-end encryption where technically feasible with keys held outside mainland China, strict identity and access management, pseudonymisation, and limitations on who in the Chinese organisation can access EU data and from where.

There is also a second set of filings that European advisers alone do not manage: China-side requirements. When personal information collected in China is transferred out of mainland China, the PIPL requires one of the three mechanisms in Article 38: passing a security assessment by the Cyberspace Administration of China (CAC) for cross-border transfers of important data or large volumes of personal information, executing a standard contract filed with the CAC (the Measures for Standard Contracts for Outbound Transfer of Personal Information, effective 1 June 2023), or obtaining personal-information protection certification. The China-return flow is therefore a two-sided compliance problem: the EU side demands SCCs, a TIA and possibly supplementary measures; the China side demands a CAC mechanism, filings and impact assessments. A workable architecture coordinates the two so the same data journey satisfies both regimes — which is why the design work belongs in the hands of counsel who can see both ends of the pipeline.

Diagram in text
  • Flow chart of the EU-to-China return data pipeline: map ROPA, appoint Art. 27 and Art. 37 roles, set lawful bases, execute SCCs with Transfer Impact Assessment and supplementary measures, run China-side PIPL CAC mechanisms, and plan dual-jurisdiction incident response on a quarterly review calendar.
  • Two-sided China-return data flow and six-step GDPR-PIPL compliance blueprint.
  • EU Chapter V + mainland PIPL / DSL / CSL must both be satisfied for the same journey
  • EU SIDE — GDPR Chapter V
  • No China adequacy · SCCs (EU 2021/914) + TIA

4. A practical compliance blueprint for Chinese companies

  1. Map first. Build the Records of Processing Activities (ROPA) under Article 30, highlighting every flow that touches mainland China: which systems, which processors, which employee groups, which vendors.
  2. Appoint the local roles. Designate the Article 27 EU Representative in a Member State where your users are, and decide whether Article 37 requires a DPO — and if so, appoint one with genuine independence from HQ.
  3. Re-architect consent and lawful bases. GDPR lawful basis under Article 6 is not the same as PIPL 'separate consent' under Articles 23 and 39. The user interfaces you ship in the EU must satisfy the EU standard without assuming that the Chinese consent framework carries over.
  4. Execute and assess. Sign SCCs (EU 2021/914) for every EU-to-China processor and intra-group transfer, run the TIA, and implement supplementary measures where the TIA demands them.
  5. Run the China side. Determine which PIPL mechanism applies to the return flow, prepare the CAC security assessment or standard contract filing, and keep the impact assessments current.
  6. Plan for incidents. Article 33 gives 72 hours for notification to the supervisory authority; Article 34 requires data-subject notification where risk is high. Your incident runbook must work across the EU and China teams simultaneously.

None of this is a one-time project. Transfer mechanisms, adequacy findings, regulator guidance and enforcement practice change continuously. A structured quarterly review, with immediate re-assessment when the CAC or the European Commission moves, keeps the architecture lawful on both sides of the pipeline.

General information only, not legal advice. Laws, guidance and enforcement practice change. For a compliance programme tailored to your company's structure and data flows, consult qualified counsel.

5. The questions Chinese boards actually ask

"We only hold data for development. Is that still processing?" Yes. Development access is processing, and if the data belongs to EU data subjects, the full GDPR framework attaches to it. The common engineering pattern — an EU production database, a Beijing R&D team with remote access, and a shared analytics warehouse — is a continuing cross-border transfer that requires its own SCC and TIA, not an internal detail.

"Our EU entity is the controller, so the parent is outside scope." Not necessarily. Where the Chinese parent decides the purposes and means of processing, it is a joint controller under Article 26 or a controller in its own right, and it needs its own legal basis, its own records and its own transfer mechanism. The entity chart is not the same as the processing map.

"Can our DPO sit in Beijing?" Article 37 allows a DPO to be located anywhere provided accessibility, but the independence requirement in Article 38(3) is the real test: a DPO who reports to the same executive who approves the processing is not independent in practice. Most Chinese groups find that an external DPO with EU presence gives both the compliance substance and the credibility that supervisory authorities expect.

"What happens if we ignore this until we are investigated?" The DPC and other supervisory authorities increasingly start from data-mapping and ROPA requests. A company that cannot produce records of processing, named EU representation and transfer documentation at the first request has already converted a compliance gap into an aggravating factor for fines under Article 83(2).

6. Keeping the architecture current

The EU data-protection landscape moves in three directions at once. First, adequacy and transfer mechanisms: the European Commission has continued to expand its adequacy decision list, and new SCC modules and supplementary-measure guidance appear regularly, so an architecture validated in 2023 may not survive 2026 unchanged. Second, China-side regulation: the CAC has implemented the security-assessment and standard-contract regimes under the PIPL with increasing enforcement activity, including the Measures on Standard Contracts (effective 1 June 2023) and the updated Measures for Security Assessment of Data Export (effective 15 March 2024). Third, enforcement practice: fines, operational orders and DPO-related sanctions are accumulating, and the EDPB continues to issue guidance that changes how TIAs are documented.

For a Chinese group, the practical answer is a rolling compliance calendar: quarterly review of transfer mechanisms and ROPA, immediate re-assessment on any CAC or Commission movement, and an annual audit that tests whether the documentation matches what the systems actually do. The cost of the calendar is small; the cost of discovering a broken transfer at the moment a regulator asks for it is very large.

7. When to instruct counsel

The threshold for involving counsel is lower than most Chinese companies expect. Any of the following should trigger a structured review before the next product release, vendor contract or HR rollout: a new EU market entry or expansion; a new EU customer segment with employee, payment or health data; a remote-access architecture change that moves EU data into mainland China; a CAC security assessment or standard-contract filing that has not been aligned with the EU transfer documentation; or a regulator inquiry, data subject complaint or breach notification. The cost of aligning documentation after the fact is routinely several times the cost of building it correctly, and the risk profile — a 4% of worldwide turnover fine under Article 83(5), or an operational ban under Article 58(2)(f) — justifies treating data compliance as a launch requirement rather than an afterthought.

End of brief

Niamh Walsh, Data Privacy & Cybersecurity lawyer

Author

Niamh Walsh

Ashford Data Law LLP, Dublin · Data Privacy & Cybersecurity

Ashford Data Law LLP, Dublin · Verified listing. This insight is educational and does not create an attorney–client relationship.

View lawyer profile

Data Privacy & Cybersecurity

Need a next step?

Take a focused intake, or browse listed data privacy & cybersecurity practitioners.

Request a consultation Find listed counsel

In the library

Go deeper on this topic

Educational information only — not legal advice. Laws change; consult qualified counsel for your situation. No attorney–client relationship is formed by using this site.

Disclaimer Editorial policy AI content policy

READER DISCUSSION

Comments

Share experience or questions about this topic. This is a public discussion — not legal advice. Do not post confidential case details.

Be the first to start the discussion, or Ask a Lawyer for a free initial consultation.

Comments are moderated. China Legal Portal is a directory and information resource; no attorney–client relationship is formed by posting here.