Proactive Strategy for EU Regulatory Investigations: the Nuctech Case

Nuctech headquarters

Ling Xujie (凌许婕)

I. Introduction

Multinational corporations operating across borders increasingly find themselves caught in the crossfire of overlapping and contradictory regulatory regimes. While Chinese technology companies entering the European market serve as a prominent example, they are by no means the only foreign entities facing severe compliance bottlenecks under European Union (EU) law; any non-EU enterprise backed by foreign capital or operating across borders faces similar exposure under the EU’s expanding regulatory toolkit. A prime example of this cross-border regulatory conflict is the legal challenge brought by Nuctech—a Chinese security equipment manufacturer—against the European Commission’s unannounced inspections under the newly enacted Foreign Subsidies Regulation (FSR)[1].

Nuctech’s lawsuit was not just a procedural matter. It raises a deeper question: if the company under investigation is an EU subsidiary, can the EU’s regulatory authorities access the data of companies located in China or elsewhere in the world? This case encounters the dilemma of having to comply with both legal systems; complying with one side’s law may violate the other’s. This paper advances two core arguments in response to this tension: the Nuctech case demonstrates that the EU intends to use the effects doctrine[2] to expand its own regulatory scope, and also illustrates that companies relying on conflicts of foreign laws for their defense will find such arguments legally ineffective before EU courts. Building on this case and related commentary, this paper develops a proactive compliance strategy across legal, operational, and diplomatic dimensions for transnational firms navigating EU investigations.

From the perspective of EU regulatory extraterritoriality theory, the Nuctech case is also a typical manifestation of the “Brussels Effect”[3]. The EU, by virtue of its large internal market and strict regulatory standards, forces non-EU enterprises to comply with its rules even outside its territory. For Chinese tech companies, this means that their EU subsidiaries are bound by EU regulations, and their parent companies’ data stored in China may also be subject to EU investigative powers, which conflicts with China’s data sovereignty framework. This dynamic raises the broader question of whether foreign jurisdictions will react by erecting counter-statutes, potentially giving rise to a parallel “Beijing Effect” in global data governance. To evaluate these competing regulatory frameworks, Section II provides the factual and legal background necessary for this analysis, followed by an in-depth examination of the Nuctech litigation in Section III to V.

II. Factual and Legal Background

To analyze the legal conflict in Nuctech, it is necessary first to establish the specific factual circumstances that led the company to challenge the Commission, alongside the core statutory provisions of the EU FSR and China’s data security framework.

  1. Factual background

Nuctech Company Limited, a Chinese manufacturer controlled by Tsinghua Tongfang Co. Ltd., operates in the EU market through its wholly owned subsidiaries, Nuctech Warsaw in Poland and InsTech Netherlands. In April 2024, European Commission officials conducted unannounced inspections (dawn raids) at Nuctech’s Polish and Dutch premises under the FSR, investigating alleged market-distorting foreign state subsidies. During the inspection, Commission officials demanded access to employee email accounts maintained on servers physically located in China. Citing severe penalties under Chinese data security and state secrecy laws, Nuctech refused immediate transmission, leading the Commission to issue a formal legal hold demanding access. Facing potential EU fines for non-compliance alongside domestic criminal and administrative exposure in China, Nuctech took the unusual step of suing the Commission in the EU General Court to suspend the inspection decisions.

  1. The EU’s Foreign Subsidies Regulation

The Commission’s authority to examine “information accessible to the entity subject to inspection” became the central legal issue in Nuctech. The FSR (Regulation 2022/2560) was enacted to close what the Commission perceived as a major regulatory gap in competition law: foreign government subsidies granted to non-EU governments to companies active in the internal market, which distorted fair competition compared to EU firms subject to strict State Aid rules. Articles 13 to 15 confer sweeping investigative powers, including the ability to inspect undertakings within the Union and to access records “irrespective of the medium or storage location.” This phrasing is not unusual in EU regulation; it directly reflects the Commission’s long-standing practice under EU competition law (such as Regulation 1/2003), signaling that investigative reach cannot be frustrated by digital or territorial barriers. From the perspective of EU extraterritorial jurisdiction theory, this provision is an extension of the qualified effects doctrine in the field of foreign subsidy regulation, which means that as long as the data is accessible to EU subsidiaries, regardless of its storage location, it falls within the scope of EU regulatory jurisdiction. This “operational control” standard[4] has been routinely applied by EU regulators against non-Chinese multinational enterprises as well, demonstrating its general applicability.

  1. Chinese Data-Sovereignty Framework

While the EU has granted itself huge investigative powers under the FSR, powers meant to protect transparency and guarantee fair competition in the single market, this authority inevitably runs up against jurisdictions that put strict limits on moving data across borders, with China being an example. In China, the outbound transfer of strategic or sensitive data is regulated by a triad of statutes: the Data Security Law (DSL), the Personal Information Protection Law (PIPL), and the Guarding State Secrets Law all restrict the outbound transfer of sensitive or strategic data. These statutes require prior security assessments or government authorization before cross-border transfers, with criminal and administrative penalties for violations.

III. The Nuctech Case

1. Facts and Procedural History

In April 2024, the European Commission conducted unannounced inspections at the premises of Nuctech Warsaw and Nuctech Netherlands under Article 14 FSR, investigating whether the group had received distortive state subsidies. During the inspection, Commission officials demanded access to corporate emails and internal correspondence, some stored on servers managed by Nuctech’s Chinese parent company. The Commission imposed a legal hold, requiring the subsidiaries to preserve the data and ensure future access by May 2024.

Nuctech refused, asserting that compliance would contravene Chinese data security laws and state secrecy laws, exposing it to administrative or even criminal sanctions. The company sought interim relief before the General Court (Case T-284/24 R[5]) to suspend the Commission’s request. On 12 August 2024, the Court’s President dismissed the application. The Court of Justice, on appeal (C-720/24 P(R)[6]), confirmed the decision on 21 March 2025.

In December 2025, the European Commission officially opened an in-depth investigation under Article 10(3) FSR into Nuctech (Case FS.100068), while the main action on the lawfulness of the dawn raids and Chinese server data requests proceeded to oral hearings before the EU General Court in April 2026.

2. The Courts’ Reasoning

(a) On Urgency and Irreparable Harm

Nuctech argued that possible Chinese punishments were “serious and cannot be fixed”. However, the company only put forward general statements about the risks of Chinese penalties, but failed to provide specific financial data to prove that the penalties would endanger its financial viability, nor did it provide evidence of the stigma effect of administrative penalties. The court refused this argument and said that even if there are administrative fines or reputational harm, these are still money-related issues and can be made up for, unless the company shows that it might lose its ability to make money. Citing Lagardère v Commission (C-89/24 P(R)) and Janssen-Cases v Commission (T-688/16), the Court reiterated that a mere speculation about reputation loss or media exposure does not meet the urgency requirement.

In its judgment, the Court also stated that for there to be a finding of serious and irrepairable damage, it is not necessary to show with absolute certainty that the damage has occurred and will occur soon; it is enough to show that the damage is foreseeable with a certain degree of probability. But the applicant needs to give clear and exact signs, with lots of papers to show what’s happening. The Court held that administrative penalties imposed by third-country authorities cannot be equated with criminal penalties, and their stigma effect is not sufficient to constitute irreparable damage.

(b) On Conflict of Laws

The court determined that Nuctech had failed to show that compliance was impossible. It had made some general statements regarding Chinese secrecy and cybersecurity regulations, but there was no proof that it had sought and been denied transfer authorization. Furthermore, Nuctech failed to specify which emails actually contained protected “state secrets”.

(c) On EU Investigatory Powers

Against the expanding extraterritorial reach of EU competition and subsidy enforcement, the EU has been granted sweeping, territory-agnostic investigatory powers under the FSR, allowing regulators to access cross-border data held by multinational firms operating within the Single Market. Relying on the qualified effects test, the General Court confirmed that EU jurisdiction extends to conduct outside the EU when it has foreseeable, immediate, and substantial effects within the internal market. As the subsidiaries operated within the EU, data located abroad but “accessible” to them fell within the Commission’s reach. The Court thus reaffirmed that participation in the EU market entails submission to EU investigative authority, regardless of physical data location.

(d) Balancing of Interests

The Court concluded that the public interest in enforcing the FSR outweighed the appellants’ private interests. Even assuming procedural errors, lack of urgency was dispositive. The appeal was therefore dismissed in its entirety.

IV. Key Legal and Practical Issues

1. The Extraterritorial Reach of EU Law

The Nuctech case takes the qualified effect doctrine out of antitrust and into the new FSR context. The Commission’s insistence on getting data from Chinese servers shows that it wants to use EU law outside its own country. The legal basis is stated as an inspection “within the Union”, but the result is that it can enter other countries’ data systems when subsidiaries have remote access credentials. This approach integrates the EU’s digital sovereignty plan but creates tension under public international law, especially the ideas of territory and non-intervention.

The Court avoided the questions by focusing on operation control. If the EU subsidiary has access to the data, so does the Commission. In practice, this rule puts transnational companies in a dilemma, if they refuse to comply with it, they risk being fined under EU laws; if they do comply, they might violate their home country’s secrecy laws.

2. Evidentiary Burden on Companies

A key takeaway for foreign companies is the heavy evidentiary burden required by EU courts. As demonstrated in prior cases like Intel v Commission and Google v Commission, abstract references to foreign law conflicts or unquantified harm will not succeed. Nuctech should have foreseen this strict evidentiary requirement from established EU judicial precedent. Companies must present extensive documentation, including official refusal letters from domestic regulators, detailed legal opinions linked to specific data sets, and financial proof quantifying potential fines.

3. Fragmentation of Global Data Governance

The case illustrates the ongoing fragmentation of global data governance. While the EU enforces open market rules under the FSR, foreign regimes protect data sovereignty through statutes like China’s DSL and PIPL. Having voluntarily entered the EU market, enterprises must recognize that they cannot simply claim protection under home-country data laws to evade EU regulatory jurisdiction.

V. Analysis

At the heart of the Nuctech case lies a classic conflict-of-laws dilemma. From Nuctech’s perspective, complying with the Commission’s request to export employee emails to the EU could trigger liability under domestic statutes. The company thus claimed “legal impossibility” of compliance. These statutes, where the EU’s FSR demanding access, while China’s DSL prohibits export, create a typical conflict of laws. The Nuctech litigation thus showed how EU courts balance regulatory effectiveness against international comity.

However, the decisive issue in this case was not the abstract conflict itself, but the evidentiary burden that companies must bear when invoking such a conflict. Heavy burden of proof is a loud alarm for foreign companies. Without documentary proof of impossibility or impending bankruptcy, claims of “unrepairable damage” or “contradiction of laws” will not succeed.

A key question for Nuctech here is whether it could have foreseen such a heavy evidentiary burden from earlier cases or general principles about the burden of proof. Yes, the high threshold placed upon Nuctech by the EU courts was due to EU judicial precedent and procedural laws that existed long before the Nuctech case. EU courts have always asked for real, specific facts about each case instead of just talking about rules, and they did that even before the Nuctech case started. In major competition law cases such as Intel v Commission and Google v Commission, the EU General Court and Court of Justice dismissed corporate defenses grounded on nebulous legal conflicts or unfixable damage. Rather than relying on such vague claims, they sought out documentary evidence such as official letters from domestic regulatory bodies, detailed information on the potential financial damage, or specific legal opinions related to the case. Nuctech should have foreseen the evidentiary requirements of earlier EU cases and fundamental procedural principles.

Consistent with these well-established precedents, the Court in Nuctech applied the same rigorous standard—and found the company’s evidentiary record gravely deficient. As established in EU competition precedents such as Intel v Commission and Google v Commission, a company claiming that EU rules violate foreign law must provide documentary evidence. Nuctech failed to do so, making its defense of legal impossibility untenable. Furthermore, the court found that Nuctech did not prove that the emails in question contained state secrets, nor did it prove that it had taken necessary steps to obtain approval for disclosure under Chinese law, thus weakening its argument.

VI. Implications for Transnational Enterprises

1. Regulatory Risk and Dual Exposure

For non-EU enterprises, the Nuctech case sends a clear warning that EU regulatory obligations cannot be avoided by relying on data location or home-country legal regimes. The main takeaway is that EU subsidiaries of non-EU groups are not protected from foreign data restrictions. They need to anticipate EU investigatory powers because they operate within the EU internal market. As Camesasca and Sideri commentary noted, “you cannot hide your dirty laundry in a cupboard outside.”[7] Chinese and other foreign-invested companies face dual exposure: complying with EU demands might violate domestic data laws, while non-compliance risks EU fines according to Article 17 FSR (up to 1% of turnover). Corporate boards must spend time analyzing the implications of entering the EU market and integrate cross-border legal research into their risk control system prior to market entry.

2. Limits of Litigation as a Defensive Tool

Nuctech indicates that litigation is an unreliable defensive shield during emergency dawn raids. Because the conditions for interim relief are cumulative, failing to establish urgency is sufficient for courts to reject suspension requests. The real battle is not about suspension requests; it lies in preparing the inspection through advance compliance planning.

3. Operational Uncertainty for Subsidiaries

Subsidiaries are caught in the middle of conflicting orders, with parent headquarters bound by domestic data laws and EU regulators demanding disclosure. Without predefined governance protocols, local subsidiaries face severe operational uncertainty during unannounced inspections.

4. Jurisprudential Perspective and Policy Significance

Jurisprudentially speaking, Nuctech extends the EU’s functional extraterritoriality model where jurisdiction follows the effects of the market instead of its location. According to Camesasca and Sideri, the court used well-established competition law principles on a new area.[8]

This decision also indicates the judicial institution’s respect for the commission on economic regulation. The court sidestepped sovereignty by treating the problem as a matter-of-fact shortage rather than principle. This doctrinal pragmatism guarantees continuity but does nothing to resolve the more fundamental question of how EU law exists alongside non-EU legal systems.

At the policy level, Nuctech shows that the EU values its own market above all else. In the Nuctech case ruling, it turns the FSR from a symbol into a real regulatory weapon. Foreign regulators and enterprises should not be surprised that the EU is ready to use the FSR to actively inspect foreign-subsidized companies operating in its market.

To Chinese regulators and other foreign regulators, Nuctech might present a challenge to national data sovereignty. But it can also be a signal for cross-border talks.

VII. Toward a Proactive Compliance Strategy

Nuctech case indicates that if the company waits for inspection, and then use foreign secrecy laws as excuses for not providing data, it would definitely lose the case. Courts do not care about abstract arguments about sovereignty, or mere risk of domestic punishment, but require some actual and concrete harm proved. Transnational corporations should adopt a preliminary strategy rather than waiting to respond the lawsuits. And if the case finally has to get into the court, the corporations need to bring enough prepared evidences ready for the lawsuit.

1. Internal Governance and Data Architecture

Internal governance comes first. Instead of leaving sensitive data insider China’s boundaries, companies should create local data mirrors inside the EU. These local mirrors aren not just backup copies, they’re main business records kept according to EU laws.

Operating such a system presupposes a cross-border compliance committee that fuses legal, IT-security, government-affairs and finance expertise. The committee tracks regulatory amendments in both EU and other jurisdictions, updates data mirrors. The objective is to make the EU subsidiary an autonomous, inspection-ready entity that can satisfy the Commission without ever asking parent company outside EU for permission. From the perspective of data governance in transnational enterprises, establishing a localized data management system in the EU is conducive to complying with EU regulatory requirements and reducing the risk of data cross-border transfer[9]. At the same time, the cross-border compliance committee can help enterprises monitor regulatory changes in a timely manner and adjust compliance strategies accordingly.

2. Pre-Inspection Evidentiary Preparation

The second layer is evidentiary preparation.

If certain datasets genuinely cannot be localized, e.g., they contain state-secret-level technical parameters or personal biometric data, companies must secure, long before any investigation, written pre-authorizations from domestic regulator.

In the process, applications, correspondence and formal refusals are preserved with certified translations, time-stamped and notarized, so that when the EU Commission demands access the firm can produce a dossier proving that a good-faith effort was made and that criminal or administrative liability is more than hypothetical.

Also, Independent opinions from local law firms should cite the exact statutory articles, maximum penalties and recent enforcement precedents, while accountants quantify the potential fines and model the cash-flow impact of business-suspension orders. This transforms legal arguments from theoretical to evidentiary, meeting the standard required by EU courts.

3. Diplomatic and Policy Channels

To stop the current situation, it is unreasonable for a single company to fight for its data rights, it has to seek help from diplomatic talks, in which clearly treat data access as general regulation instead of a political crime. Companies can get aid from industry groups or chambers of commerce, with more uniform and bigger power, these organizations can fight for EU-China bilateral data transfer agreements. For instance, the European Union Chamber of Commerce in China helped facilitate the establishment of the EU-China Cross-Border Data Flow Communication Mechanism in August 2024, a government-to-government platform addressing European businesses’ data transfer concerns.

4. Compliance Culture

Transnational companies should change from defensive secrecy to proactive documented transparency. They have to understand that when they want to do business inside EU, they have to abide by the EU’s investigatory rules and mode.

When the companies view data compliance as a living and processing culture instead of simply a general theory on the paper, the data compliance can be really enforced inside the companies to prevent risks. Then, company managers can be more sensitive to jurisdictional issues when considering starting new business, and engineers would include the logic in their code, and boards of directors can treat the data security more serious in deciding the company’s development. In this situation, working under the EU inspectors’ requirement would become a regular part of company business, not something that happens at the last moment.

5. Better Prepare for Litigation

Under the EU’s strict evidentiary standards shown by the Nuctech case, enterprises should have anticipated per prior cases and general proof principles. Also, they should in advance map litigation requirements and prepare corresponding materials and argumentation frameworks.

VIII. Conclusion

The Nuctech litigation marks the judicial elaboration of the Foreign Subsidies Regulation’s investigatory powers. The case demonstrates that the EU jurisdiction can reach data stored abroad when accessible from within the Union; claims of foreign-law conflicts will fail absent concrete, contemporaneous evidence; reputational or financial harms rarely meet the threshold for interim relief.

For transnational companies, the lesson is that they should always one step before the EU on compliance issues, so that they don’t have to fail in the lawsuits. Companies should put more money into the inside systems for handling information, getting ready for the documentary of evidences, and keeping communication with the inspectors from the EU.

Nuctech is a warning shot in a global economy where data and information is both an asset and a liability. The only lasting defense is not to fight for sovereignty, but to create compliance structures that can withstand it.

  1. Regulation (EU) 2022/2560 on Foreign Subsidies Distorting the Internal Market.
  2. Peter Behrens, The Extraterritorial Reach of EU Competition Law Revisited: The “Effects Doctrine” Before the ECJ, Europa-Kolleg Hamburg Discussion Paper No. 3/16 (2016).
  3. Anu Bradford, The Brussels Effect: How the European Union Rules the World, 2020, Reviewed by Peter L. Lindseth, DOI: 10.1093/oso/9780190088583.001.0001.
  4. Lena Hornkohl, The Extraterritorial Application of Statutes and Regulations in EU Law, Max Planck Institute Luxembourg for Procedural Law, Research Paper Series No. 4 (2019).
  5. Case T-284/24 R Nuctech Warsaw Company Ltd and Nuctech Netherlands v Commission, Order of 12 Aug 2024.
  6. Case C-720/24 P(R) Appeal Order of 21 Mar 2025.
  7. Peter D. Camesasca, Konstantina E. Sideri, European Commission’s inspection powers under the EU FSR outside the European Union: Case T-284/24 R Nuctech, 16 J. EUR. COMPETITION L. & PRAC. 33 (2025), https://doi.org/10.1093/jeclap/lpae070.
  8. Id. at 7.
  9. Paul M. Schwartz & Karl-Nikolaus Peifer, Transatlantic Data Privacy Law, 106 GEO. L.J. 115 (2017).

 

Leave a Reply

Your email address will not be published. Required fields are marked *