By Emmanuel Delplanque, Co-Founder & CEO, BE-CAUSE
In a world where supply chains have become the nerve center of economic and geopolitical strategy, multinational corporations find themselves caught between unprecedented demands for transparency and strict national security imperatives. On one side, Europe and the United States are deploying a legislative arsenal — CSDDD, UFLPA, LkSG, the French Duty of Vigilance Law — demanding total visibility into the environmental and social practices of suppliers, down to Tier-3 or Tier-4 subcontractors. On the other side, China is pushing back with Decrees 834 and 835, erecting a legal shield in April 2026 to protect its industrial data and counter the extraterritoriality of Western laws.
This clash of regulatory sovereignties is not an abstract phenomenon. It plays out daily in the offices of procurement directors, on the servers of ESG teams, and in the courtrooms of Chinese tribunals. Companies that have not yet adapted their compliance architecture to this new reality expose themselves to what could be called a 'double jeopardy': being sanctioned in the West for a lack of transparency, and in the East for excessive investigative zeal.
This article serves as a pedagogical and practical guide. We decipher the concrete obligations of the European Corporate Sustainability Due Diligence Directive (CSDDD), the constraints imposed by the new Chinese decrees, the landscape of other relevant international regulations, and — crucially — the concrete business impact for companies that must now juggle ethical compliance and operational survival.
Executive summary
- CSDDD (revised by Omnibus I in December 2025) still captures ~1,447 corporate groups globally — one third headquartered outside the EU — with fines up to 3% of worldwide turnover.
- Non-EU groups generating > €1.5 bn of net turnover in the EU are directly in scope, including 182 US, 69 UK, 51 Japanese and 47 Swiss corporate groups.
- UFLPA blocked $1.79 bn of imports at US customs in 2024; LkSG and the French Duty of Vigilance add layered exposure for companies operating in Germany and France.
- China's Decrees 834 (effective 7 April 2026) and 835 (effective 13 April 2026) criminalize core parts of the Western due-diligence playbook: Tier-2+ mapping, raw-data exports and termination based on foreign ESG laws.
- The only viable architecture is 'Segregation of Data, Aggregation of Insights': raw evidence stays in China, only computed scores and emissions cross the border, after explicit PIPL consent.
1. The European and American vise: the era of mandatory transparency
For decades, corporate responsibility stopped at the factory gates. Outsourcing allowed companies to externalize not only production but also social and environmental risks. Today, the law forces them to look far beyond, all the way to a Tier-3 or Tier-4 supplier located on the other side of the world. This paradigm shift is driven by a wave of regulations that transform 'due diligence' from a good CSR practice into a strict legal obligation, backed by significant financial penalties.
1.1. The CSDDD: the flagship of European due diligence
Adopted by the Council of the European Union in May 2024 and revised via the 'Omnibus I Package' in December 2025, the Corporate Sustainability Due Diligence Directive (CSDDD, also known as CS3D) is arguably the most ambitious legislation ever conceived regarding supply chain sustainability. Its fundamental ambition is to end the era of impunity in global value chains: large companies must identify, prevent, mitigate and account for the negative impacts of their activities on human rights (forced labor, child labor, dangerous working conditions) and the environment (water pollution, deforestation, greenhouse gas emissions). This obligation does not stop at the company's borders: it applies to its own operations, those of its subsidiaries, and its entire 'chain of activities'.
In concrete terms, a company subject to the CSDDD must implement a structured due diligence process in several stages: map its supply chain to identify risk areas, conduct in-depth assessments with problematic suppliers, establish preventive and corrective action plans, create complaint mechanisms accessible to stakeholders (workers, local communities), and publish an annual report on its due diligence activities.
The Omnibus I compromise of December 2025 relaxed several parameters under pressure from industry: scope was narrowed (capturing roughly 70% fewer companies directly), but the directive remains a profound transformation of European business law. Companies below the thresholds that are suppliers to CSDDD-bound companies will be indirectly forced to provide verifiable ESG data to their clients.
“Buyer alert: even if your company is not directly subject to the CSDDD, your CSDDD-bound clients will demand verifiable ESG data from you. A lack of traceability in your supply chain can lead to the termination of major commercial contracts, with no possibility of appeal.”
1.2. The global reach of CSDDD: foreign companies in the crosshairs
One of the most controversial and consequential aspects of the CSDDD is its extraterritorial reach. The directive does not only target companies headquartered in the European Union; it directly applies to foreign (non-EU) companies that generate significant revenue within the EU single market. Under the revised Omnibus I thresholds, non-EU companies must comply with the CSDDD if they generate a net turnover of more than €1.5 bn in the EU in the year preceding the last financial year, or if they enter into franchising/licensing agreements in the EU with royalties exceeding €75 m and total EU net turnover above €275 m. They must designate an authorized representative in an EU Member State and face the same fines (up to 3% of worldwide turnover) as their European counterparts.
According to the updated CSDDD Datahub maintained by SOMO (Centre for Research on Multinational Corporations), the weakened Omnibus I thresholds still capture approximately 1,447 corporate groups globally — and one third of these are headquartered outside the EU. The breakdown of the most affected non-EU countries reveals a massive impact on American and Asian multinationals.
| Country | Corporate groups in scope |
|---|---|
| United States | 182 |
| United Kingdom | 69 |
| Japan | 51 |
| Switzerland | 47 |
The €1.5 bn EU revenue threshold means that the world's largest technology, pharmaceutical, energy, automotive, electronics, F&B, fashion, retail and cosmetics groups are directly in scope. A report by the Hudson Institute estimated that American firms alone will need to spend nearly $1 trillion in one-time compliance costs to adopt the CS3D requirements, with annual recurring costs exceeding $10 bn. If an American or Japanese company fails to comply, European regulators can levy fines based on its global turnover — effectively extracting billions of dollars from non-EU shareholders.
1.3. The French Duty of Vigilance Law: the global pioneer
In 2017, France was the first country in the world to adopt a law obliging large companies to conduct due diligence regarding human rights and the environment. The 'Loi de Vigilance' applies to companies headquartered in France with more than 5,000 employees in France or more than 10,000 worldwide (including subsidiaries). The core of the law is the 'vigilance plan': a public document, updated annually, that must map the risks in the activities of the company, its subsidiaries, its subcontractors, and suppliers. In case of non-compliance, third parties (associations, unions, victims) can take the company to court to force compliance, with fines reaching up to €10 m, or even €30 m if the failure caused harm.
1.4. The German LkSG: the precursor to the CSDDD
Entering into force on 1 January 2023, the German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz, or LkSG) served as a direct model for the CSDDD. It applies to companies with at least 1,000 employees in Germany (since 2024) and obliges them to establish a risk management system to identify and prevent human rights violations and environmental damage in their supply chains. The LkSG exhaustively lists eleven international human rights conventions that companies must guarantee are respected. Fines can reach €8 m or 2% of annual global turnover for companies with over €400 m in revenue.
1.5. The American UFLPA: the most radical approach
The Uyghur Forced Labor Prevention Act (UFLPA), signed in December 2021 and effective since June 2022, represents the most draconian approach to combating forced labor in supply chains. Its logic is inverted compared to other laws: instead of requiring proof of a violation, it establishes an irrebuttable presumption that any good manufactured, wholly or in part, in the Xinjiang Uyghur Autonomous Region (XUAR) is the product of forced labor. Any American importer whose goods have a link to Xinjiang sees their shipments blocked at US customs; to release them, they must provide clear and convincing evidence that the goods were not produced with forced labor. In 2023, US customs detained merchandise valued at $1.42 bn under the UFLPA; in 2024, the figure rose to $1.79 bn.
1.6. Complementary European regulations: EUFLR and EUDR
The EU completes its regulatory arsenal with two major sectoral regulations. The European Forced Labour Regulation (EUFLR), whose application guidelines were published in June 2026, prohibits the placing on the European market of any product made with forced labor, whether imported or produced in the EU. The European Deforestation Regulation (EUDR), applicable to large companies since late 2025, requires that agricultural products (coffee, cocoa, soy, palm oil, wood, rubber, beef) sold in the EU do not contribute to deforestation. These two regulations further reinforce the need for granular and verifiable traceability.
2. The Chinese pushback: Decrees 834 and 835
Faced with this growing regulatory pressure, China has not remained passive. In April 2026, the Chinese State Council — the country's supreme executive body — promulgated two decrees that radically redraw the rules of the game for any company collecting ESG data on its territory.
2.1. The geopolitical context: why now?
The simultaneous promulgation of Decrees 834 and 835 is no coincidence. It occurs within a context of exacerbated geopolitical tensions: escalating Sino-American tariffs, US pressure on allies to reduce dependence on Chinese supply chains (particularly in semiconductors and critical minerals), and emblematic cases such as the Dutch takeover of chipmaker Nexperia (of Chinese origin) or CK Hutchison's loss of control over Panama Canal ports under US pressure. These decrees also align with the 15th Five-Year Plan (2026–2030), which explicitly calls to 'accelerate the construction of the rule of law system with international dimensions'. For Beijing, this is a rebalancing of sovereignty: if the West can legislate on the practices of its Chinese suppliers, China can legislate in return on the practices of Western buyers operating on its soil.
2.2. Decree 834: industrial chain security
Entering into force on 7 April 2026, Decree 834 is China's first comprehensive and autonomous regulation on supply chain security. It revolves around three fundamental mechanisms. First, it establishes a list of key sectors (publication still pending) subject to enhanced monitoring tools: risk surveillance and early warning systems, material reserve and production-capacity mechanisms, and government emergency intervention powers. Sectors likely to be included include batteries, renewable energies, graphite, lithium and rare earths.
Second — and most impactful for Western ESG teams — Article 13 subjects the collection of information on Chinese supply chains to enhanced regulatory scrutiny. This article acts as a cross-reference to existing laws (Data Security Law, PIPL, Anti-Espionage Law) and elevates the risk profile of any due diligence activity perceived as serving hostile foreign regulatory interests. Intrusive ESG audits, Tier-2 or Tier-3 mapping, and UFLPA-style investigations into forced labor are now squarely in the crosshairs of Chinese authorities.
Third, Article 15 establishes an investigation mechanism allowing Chinese authorities to examine any conduct affecting industrial security and to impose countermeasures on foreign entities, including investment and trade bans. This mechanism can be triggered by the simple termination of a contract with a Chinese supplier if this termination is perceived as a 'discriminatory measure'.
2.3. Decree 835: counter-extraterritoriality
Entering into force on 13 April 2026, Decree 835 is Beijing's direct response to the extraterritorial application of laws like the UFLPA or the CSDDD. It consolidates and strengthens existing mechanisms (notably the 2021 Anti-Foreign Sanctions Law) by elevating them to the State Council level. The decree introduces four key concepts: (1) China asserts the right to exercise extraterritorial jurisdiction over acts having an 'appropriate connection' with China; (2) the Ministry of Justice is designated as the lead authority to identify 'inappropriate' foreign measures; (3) an 'Unreliable Entity List' targets foreign organizations and individuals who promote or participate in the implementation of inappropriate extraterritorial measures — listed entities may face entry bans, investment restrictions, transaction bans and asset freezes; (4) Chinese counterparties may sue Western buyers in Chinese courts for damages.
“Buyer alert: a European or American company that terminates a contract with a Chinese supplier by explicitly invoking non-compliance with the CSDDD or the UFLPA exposes itself to a double threat — being placed on the Chinese Unreliable Entity List AND being sued for damages by its former supplier in Beijing courts. A 2024 judicial precedent already saw a Chinese plaintiff obtain compensation after a non-Chinese counterparty suspended payments to comply with US sanctions.”
2.4. Integrating the Chinese manufacturing context
China accounts for approximately 28% of global manufacturing output. It is the world's leading supplier of solar panels, lithium-ion batteries, rare earths, textiles and electronics. Any due diligence strategy that ignores Chinese regulation would not only be incomplete but potentially suicidal from an operational standpoint. Asking a Chinese supplier to reveal the identity of its own suppliers (Tier-2) is now perceived as the collection of strategic information that could threaten national security. Similarly, exporting raw evidence — electricity bills, payrolls, raw-material origin certificates — outside of China to prove ESG compliance runs afoul of strict data-localization laws (Data Security Law, PIPL).
3. The business impact: navigating a regulatory minefield
3.1. The legal risk of 'double jeopardy'
The primary risk is the conflict of laws. Companies find themselves in an unprecedented situation where obeying the law of their home country (or their major market) leads them to violate the law of their country of production.
- Scenario A — Inaction: you ignore CSDDD and UFLPA to maintain Chinese commercial relationships without intrusive audits. You risk massive fines in Europe (up to 3% of global turnover), goods seized at US customs, exclusion from European public procurement, and a collapse of your reputation with ESG investors.
- Scenario B — Ill-adapted action: you demand UFLPA-style audits (full Tier-2/Tier-3 mapping, raw documentary evidence) and break contracts with non-compliant suppliers. You risk being placed on the Chinese Unreliable Entity List, having local assets frozen, being sued by former partners, and losing access to the Chinese market for your subsidiaries.
| Regulation | Jurisdiction | Trigger | Maximum penalty |
|---|---|---|---|
| CSDDD (Omnibus I) | EU | > €1.5 bn EU net turnover | 3% of worldwide turnover |
| French Duty of Vigilance | France | >5,000 FR / 10,000 global employees | €10 m / €30 m if harm caused |
| LkSG | Germany | >1,000 DE employees | €8 m or 2% of global turnover |
| UFLPA | USA | Any link to Xinjiang | Goods detained at customs |
| Decree 834 | China | Foreign ESG audit / Tier-n mapping | Investment & trade bans |
| Decree 835 | China | Compliance with 'inappropriate' foreign law | Unreliable Entity List + civil suits |
3.2. The most exposed sectors
Certain sectors are particularly vulnerable to this regulatory clash, as they combine a high dependence on Chinese supplies with high exposure to due diligence regulations. Green technology is on the front lines: solar panels, EV batteries and wind turbines rely heavily on polysilicon, lithium, cobalt and rare earths concentrated in China, often in sensitive regions, and are simultaneously subject to UFLPA (US), CSDDD (EU) and Decrees 834/835 (China). Textiles and apparel remain under intense scrutiny, with Xinjiang cotton at the heart of UFLPA/Decree 835 tensions. Electronics and semiconductors face extremely complex supply chains where components cross multiple countries before assembly — traceability is particularly difficult to establish.
3.3. Buyer alert: the cost of opacity
In this context, the message for procurement departments is unambiguous: a lack of traceability has become a major financial and existential risk, not just a compliance issue. The inability to map one's supply chain no longer allows a company to plead ignorance. Under the UFLPA, $1.79 bn of goods were blocked at US customs in 2024, paralyzing production lines. With the progressive entry into force of CSDDD and EUDR, Europe will apply similar mechanisms. Buyers who have not invested in adapted technological and legal solutions will find themselves unable to sell their products in Western markets.
4. Solutions: how to adapt to this new world
Faced with this puzzle, traditional due-diligence approaches — long Excel questionnaires, unannounced audits by Western consultants, requests for raw documentation — are not only ineffective but potentially dangerous in the context of Decrees 834 and 835. Companies must rethink their compliance architecture from the ground up.
4.1. The founding principle: Segregation of Data, Aggregation of Insights
The only viable path to operating in China while satisfying Brussels and Washington is both technological and contractual. It relies on a simple but powerful principle: raw data remains in the country of origin; only aggregated and anonymized results cross borders.
- Step 1 — Local hosting of raw data: raw data from Chinese suppliers (electricity bills, subcontractor lists, employment contracts, origin certificates) remains stored on servers located in mainland China (e.g., Alibaba Cloud or Tencent Cloud). This complies with the Data Security Law and Decree 834, which prohibit the export of potentially sensitive industrial data.
- Step 2 — Closed-loop processing and calculation: ESG calculations (Scope 2 carbon footprint, social maturity score, governance indicators) are performed locally, within the Chinese legal perimeter. The supplier does not share its raw data, but the results of its processing.
- Step 3 — Exporting results only: only aggregated, anonymized results and final scores cross the border. Instead of sending a factory's raw electricity bill, the platform sends only '1,200 tCO₂e of Scope 2 emissions for FY 2025' and a maturity score of '4/5'. The buyer gets what they need for reporting, without the supplier violating Decree 834.
- Step 4 — Explicit supplier consent: under PIPL, the Chinese supplier must give explicit consent before any result is shared with the Western buyer. This protects the supplier and gives the buyer a solid legal basis.
4.2. Localizing audits and aligning with local standards
For Level 3 audits (physical verification by an independent third party), Western companies must imperatively use auditors of Chinese nationality, employed by local entities of internationally recognized certification firms — the kind of internationally acknowledged third-party verification bodies that Western buyers already trust for ISO, GHG and social-compliance assurance. Detailed audit notes, photographic evidence and underlying documents remain on Chinese servers, in compliance with Decree 834 and the Data Security Law. Only the final certificate — redacted of industrial secrets and commercially sensitive information — is transmitted to the Western buyer, after explicit supplier consent.
Regarding the content of questionnaires, ESG teams must undergo a profound cultural transformation. Questionnaires must be purged of any politically sensitive questions (e.g., direct questions about Xinjiang or political affiliations) — these are direct triggers for Article 13 of Decree 834. Instead, assessments must align with local frameworks: the 'Dual Carbon' (双碳) policy aiming for carbon neutrality by 2060, the Chinese Emissions Trading System (CN ETS), the standards of the official ACFTU trade-union federation, and locally recognized ISO certifications. This 'local first' approach considerably reduces the risk of being qualified as a 'discriminatory measure' under Decree 835.
4.3. Rethinking commercial contracts and termination clauses
Standard contractual clauses requiring 'full compliance with European and American laws' must be carefully rewritten. The Chinese subsidiaries of multinational groups must adopt more nuanced formulations to justify the termination of a contract on purely commercial (quality, delays, price) or technical grounds, rather than explicitly invoking Western sanctions or ESG audit conclusions. Explicitly invoking the UFLPA or the CSDDD to justify a termination is now one of the riskiest actions a company can undertake in China. Corporate lawyers must work closely with Chinese-law specialists to develop force majeure and termination clauses adapted to this new context.
4.4. Supply chain diversification: a long-term strategy
Beyond short-term solutions, the most exposed companies must engage in strategic thinking about the geographic diversification of their supply chains. The so-called 'China+1' movement — maintaining a presence in China while developing alternative capacities in India, Vietnam, Mexico or Eastern Europe — responds precisely to this need for regulatory resilience. This diversification does not happen overnight and involves significant investments, but companies that have anticipated this transition will be better equipped to navigate a regulatory environment that will only become more complex in the years to come.
5. How BE-CAUSE operationalizes the triple compliance trap
BE-CAUSE was designed from day one around the Segregation of Data, Aggregation of Insights principle. The platform runs two parallel environments: a China environment (Alibaba Cloud / Tencent Cloud, mainland China) that hosts Chinese supplier and Chinese buyer accounts and stores all raw data, documentary evidence and supplier identification information; and a Global environment (AWS / Azure, EU/US) that hosts Western buyer accounts and the data of non-Chinese suppliers and receives only aggregated outputs from the China environment.
- Stays in China: raw data, names of sub-contractors (Tier-2), evidence documents and precise factory geolocation.
- Crosses the border: only aggregated, anonymized or computed outputs — scores and emissions figures, after explicit PIPL consent from the supplier inside the China environment.
- Questionnaires: quantitative ESG data (GHG, energy, waste) and management processes (ISO), aligned with 双碳, CN ETS, PIPL and ACFTU — no politically sensitive triggers under Article 13.
- Scoring: supportive and remediation-oriented, not punitive — reducing the risk of qualifying as a 'discriminatory measure' under Article 15.
Conclusion: toward a 'balkanization' of due diligence
The era of the fluid, transparent global supply chain governed by a single regulatory framework is over. The entry into force of the CSDDD in Europe, the UFLPA in the United States, and Decrees 834/835 in China marks the beginning of an era that can be described as the 'balkanization' of ESG compliance. Companies can no longer apply a single due diligence model globally. They must deploy 'glocal' strategies: global sustainability objectives imposed by the CSDDD and investor expectations, executed via strictly local and siloed data infrastructures and audit processes, compliant with Chinese laws. This is not a capitulation to Beijing's demands — it is the only architecture that satisfies Brussels, Washington and Beijing simultaneously.
For executives, procurement directors and ESG managers, the message is urgent and unequivocal: compliance is no longer just a matter of environmental reporting or reputation management. It has become an exercise in high-level geopolitical tightrope walking, where every procurement decision, every audit, every contractual clause must be weighed against three potentially contradictory legal systems. Those who fail to adapt their data architecture, audit processes and contracts to this new reality risk seeing the doors of Western markets (for lack of transparency) and Chinese markets (for excessive intrusion) close simultaneously. Investing in adapted technological and legal solutions is no longer a luxury — it is a condition of survival.
常见问题
参考资料
- A&O Shearman — Agreement on the CSRD/CS3D Omnibus Package: Key Changes and Implications (December 2025)
- EUR-Lex — Corporate sustainability due diligence, Directive (EU) 2024/1760
- Linklaters — EU CSDDD: impact on non-EU companies (May 2026)
- SOMO — Updated Datahub shows 1,400 corporate groups covered by weakened CSDDD (April 2026)
- Worldfavor — All You Need to Know About France's Corporate Duty of Vigilance Law
- German Federal Ministry of Labour and Social Affairs — Supply Chain Act (LkSG)
- U.S. Customs and Border Protection — Uyghur Forced Labor Prevention Act (UFLPA)
- Steptoe — Two Regulations, One Direction: China's Expanding Economic Security Playbook (April 2026)
- Freshfields — China's new 2026 Supply Chain Security and Counter-Extraterritoriality Rules (June 2026)
- Morgan Lewis — China Enacts First Comprehensive Regulations on Industrial and Supply Chain Security (April 2026)
- Sidley Austin — China's New Supply Chain Security Regulations: Key Takeaways (June 2026)
- FREOPP — European overreach: How CS3D threatens American jobs and undermines EU-U.S. trade relations (April 2026)
