Tianchan Ren

2025.1.2Peking University Law Journal

DOI: 10.1080/20517483.2025.2561309

Abstract

ABSTRACT The increasing data flow leads to the prosperity of digitalization, while upbring states’ attention to implementing data regulations concerning various interests. The borderless and replicable features of data raise new challenge to the territorial principle in the jurisdiction and create potential conflicts inside the data-related laws enacted by the countries. This article examines the complexities of extraterritorial application of jurisdiction in data protection laws, focusing on the General Data Protection Regulation (GDPR) and China’s Personal Information Protection Law (PIPL). It explores how these laws, despite their similar aims, create overlapping jurisdictions that often result in conflicts. The analysis begins by discussing the concept of jurisdiction and its evolving application in the digital era, particularly concerning the territoriality principle. This article then delves into specific cases, highlighting how governments assert control over data stored or processed beyond their borders, leading to challenges for multinational companies (MNC) navigating these regulations. It further investigates the potential conflicts arising from data transfer and storage regulations between different jurisdictions, especially between the EU, China and the US. This article concludes by emphasizing the need for a balanced approach in data regulation, one that considers both national interests and the operational realities of global tech companies, while recognizing the limitations of current international law in addressing these overlapping jurisdictions

Citation format

REN, Tianchan. Navigating the complexities of extraterritorial application of jurisdiction in data protection laws. Peking University Law Journal, 2025, 13: 123–144.