全球跨境监管如何进入端到端的矩阵合规时代?
In 2026, the regulation of global cross-border trade and investment has reached a historic turning point. From Europe to Asia, and from customs clearance to data flows, compliance requirements are evolving from isolated checkpoints to end-to-end, matrix-based frameworks. Recently, the Council of the European Union granted final approval to the revised Union Customs Code, China's "Provisions of the State Council on Outbound Investment" (Decree No. 837) officially came into effect, and Indonesia's Personal Data Protection Law fully entered into force. Facing an increasingly complex international regulatory environment, how can expanding enterprises accurately identify risks and build systematic compliance architectures? The Zhonghui Consulting team provides an in-depth breakdown of these three core regulatory updates, offering enterprises forward-looking compliance guidance.
欧盟海关法典修订后电商平台需承担哪些进口商责任?
On September 3, 2026, the Council of the European Union granted final approval to the revised Union Customs Code, marking the most comprehensive reform of the EU customs framework in decades. The new regulations directly shift the import customs responsibilities for consumer-facing goods to the sales platforms, fundamentally transforming previous customs clearance logic.
Elevated Platform Responsibilities and Severe Penalties
The new regulations explicitly stipulate that non-EU e-commerce platforms will act as the "Importer of Record," responsible for handling all customs procedures and duty payments. In 2025, EU customs processed approximately 6 billion e-commerce parcels, over 90% of which originated from China. This massive volume prompted regulators to decisively reshape the rules. For non-compliance, the new framework imposes stringent punitive mechanisms; in the most severe cases, fines can reach up to 6% of the total value of goods imported by the enterprise in the previous year, alongside potential revocation of specific customs privileges or restrictions on platform access.
Small Parcel Handling Fee and Abolition of Duty Exemptions
To address the regulatory costs associated with the massive influx of small parcels, the EU will comprehensively impose a small parcel handling fee starting November 1, 2026. Concurrently, the previous duty exemption for imported goods valued under 150 euros has been officially abolished. These two measures completely seal the duty-free loopholes for low-value direct-mail parcels, requiring e-commerce platforms to integrate end-to-end customs declarations and tax payments into their core fulfillment processes, rather than merely focusing on logistics fulfillment.
837号令实施后,对外投资怎样进入矩阵合规时代?
On July 1, 2026, Decree No. 837 officially came into effect, marking the upgrade of China's outbound investment regulation from single-node compliance to a comprehensive, multi-dimensional matrix compliance obligation system. Expanding enterprises must establish systematic compliance matrices to cope with look-through regulatory scrutiny.
Breakdown of the Six Core Compliance Matrices
Zhonghui Consulting has organized the core compliance requirements under Decree No. 837 as follows for enterprises to benchmark and self-inspect:
| Compliance Module | Core Regulatory Requirements and Upgrades |
|---|---|
| Approval and Filing | Enterprises must fulfill the filing obligations of both the NDRC and MOFCOM simultaneously. "Investing before filing" will result in severe consequences, including confiscation of illegal gains and ordered disposal of assets within a time limit. |
| Foreign Exchange Compliance | Grey channels such as nominee holdings and "ant moving" (smurfing) are blocked. Bank big data comparisons will directly intercept non-compliant funds, ensuring a transparent and closed-loop repatriation of profit dividends. |
| Export Control | Regulators will pierce through contractual forms, strictly prohibiting the disguised transfer of restricted export technologies, services, and data via personnel dispatch, training, or other means. |
| Security Review | An independent national security review system for outbound investment is established, covering the entire lifecycle of direct/indirect investments and the transfer or disposal of overseas assets. |
| Cross-Border Data Transfer | Investment filing does not exempt enterprises from cross-border data transfer approvals. Transfers involving important data or personal information of over one million individuals must undergo a security assessment. |
| Employment Risk Control | Cross-border employment encompasses data security and trade secret management. Employees carrying intangible resources across borders are subject to export control regulations. |
Substance-Over-Form Scrutiny Under Look-Through Regulation
Decree No. 837 emphasizes "look-through verification." Regulation is no longer confined to the outbound capital pathways but strikes directly at the substance of the investment. For instance, circumventing ODI filing through QDII channels, or failing to complete ODI filing for debt-to-equity swaps under foreign debt registration, are both defined as high-risk behaviors. For common business scenarios such as cross-border e-commerce payment aggregation, overseas warehouse investments, and overseas independent site operations, completing the full suite of ODI filings is mandatory. Enterprises must introduce compliance reviews at the early stages of project decision-making to avoid fragmented responses.
印尼PDP法生效后,过渡期有哪些合规窗口与应对?
Since Indonesia's Personal Data Protection Law (PDP Law) fully entered into force in October 2024, it is currently in a unique transition period characterized by "law in effect, but agency absent." Looking back at the legislative history of data protection in Indonesia, several far-reaching data breach incidents acted as catalysts. Following the implementation of the new regulations, similar incidents will directly trigger administrative fines of up to 2% of annual revenue and criminal liabilities.
The "Law Without Penalties" Reality and Criminal Enforcement Risks
Although the independent Personal Data Protection Agency (PDP Agency) has not yet been established, making administrative fines temporarily unenforceable, this does not imply a regulatory vacuum. Currently, criminal enforcement has become the only active enforcement channel. Furthermore, legacy regulations (such as Electronic System Operator registration) remain applicable. If enterprises neglect basic compliance, they may still face severe criminal risks and business disruptions.
Key Points for Basic Compliance Construction by Expanding Enterprises
The Indonesian PDP Law applies to any data processing activities that have a legal impact on data subjects within Indonesia, regardless of where the processor is located. Operating platforms targeting Indonesian users and collecting their data may trigger compliance obligations.
Zhonghui Consulting advises expanding enterprises to seize the window of opportunity and implement the following foundational infrastructure:
1. Establish a data classification inventory, distinguishing between general and specific personal data;
2. Improve user consent mechanisms and equally accessible withdrawal channels;
3. Formulate emergency response plans for notifying regulators and data subjects within 72 hours of a data breach;
4. Appoint a Data Protection Officer (DPO) in accordance with the law when statutory conditions are met;
5. Ensure the completion of Electronic System Operator registration and obtain the certificate.
如何构建端到端合规体系?结论与未来展望是怎样的?
In summary, the global cross-border compliance regulation in 2026 has exhibited distinct characteristics of being "end-to-end, look-through, and substance-focused." Whether it is the front-loading of responsibilities in EU customs, the matrix-based regulation of China's ODI, or the baseline requirements of Indonesia's data protection, it is evident that single-node "patchwork" compliance can no longer adapt to current international competition.
Expanding enterprises urgently need to integrate compliance management into their business DNA, establishing a closed-loop system of "diagnosis—policies—processes—continuous improvement." Facing a complex and volatile overseas regulatory environment, Zhonghui Consulting relies on profound professional expertise and a global perspective to provide enterprises with customized cross-border compliance diagnostics and implementation services. We will assist you in accurately identifying potential risks and optimizing your compliance architecture, safeguarding your global expansion strategy.