Policy and Internet

Laws, Enforcement, and Strategy: A Multi‐Layered Qualitative Study of Multinational Enterprise Compliance Under European Union and Chinese Data Protection Regimes

2026-04-02

In an era of proliferating but divergent data protection regimes, the European Union's rights‐based approach and China's sovereignty‐centric model have become two dominant poles of global data governance. This article examines how multinational enterprises navigate compliance under these dual systems and how that compliance is shaped through interaction with regulators and courts. Using a multi‐level qualitative framework, we combine macro analysis of legal regimes, meso assessment of enforcement, and micro case studies of TikTok in the EU and Accor in China. We show that both jurisdictions assert extraterritorial control and intensify enforcement through distinct institutional pathways. Confronted with conflicting obligations, firms segment data architectures and embed compliance in technical design, trading interoperability for legal certainty. These dynamics reveal a recursive relationship between law, enforcement, and organisational adaptation, in which the practical meaning of compliance is produced through rules‐in‐use and firms exercise bounded agency rather than full autonomy.

Full text

DOI https://doi.org/10.1002/poi3.70037