What EU cyber attachés and trade counsellors need to know about CSA2 and the WTO.
In a rather unusual move, the Ministry of Commerce (MOFCOM) of the People’s Republic of China filed its formal comments on the revised Cybersecurity Act, but not via a diplomatic démarche but by uploading them to the Commission’s open public consultation page.
Anyone reading the 30-page brief won’t miss that it is a thinly veiled threat of retaliation and litigation, wrapped in WTO doctrines and countermeasures, addressed to those ambivalent Member States to convert a Council split into a constitutional veto.
The Legal Fork Between WTO Rules and CSA
China presents the EU with what appears to be a closed legal trap. Internally, CSA2 rests on the legal basis of internal market harmonisation, wary of the national security exception under Art 4(2). China then argues that the only available defence for excluding Chinese suppliers on the basis of their country of origin is the national security exception under Article XXI of the GATT.
China’s argument here is that these two grounds are incompatible: if the EU defends CSA2 in a WTO dispute as a national security measure, it will concede that it is exercising a competence reserved to the Member States under Article 4(2) TEU, and the Article 114 legal basis would collapse internally. If it defends CSA2 internally as a market harmonisation measure, it has no Article XXI defence at the WTO, and the measure is plainly discriminatory under a catalogue of WTO treaties on goods, services, technical barriers to trade, and intellectual property.
This legal strategy is well-constructed. Either CSA2 is a national security measure – in which case China alleges the EU has no internal legal basis, or it is not – in which case it has no WTO defence. However, it could nonetheless fall short on two counts.
WTO Does Not Ask Which EU Legal Basis the Law Rests On
First, the EU does not appear before the WTO’s dispute settlement body as the Union and the holder of EU competences. The EU appears as the legal interface for the entire EU legal order, including Member State law, and the security interests protected by the Member State law. Whether security is internally regulated at Union or Member State level is a question for the CJEU, but not for a WTO panel.
Moreover, the Union has routinely defended national laws in WTO disputes, most recently French national taxation of biofuels in EU—Palm Oil Biofuels (DS593, DS600). In other words, China’s argument that defending CSA2 at the WTO requires conceding internal competence is likely not the legal dead-end MOFCOM thinks it is.
Security Exception is Not the Only Defence Available
Second, China is right that WTO jurisprudence from Russia—Traffic in Transit (DS512) and later cases that the national security exception in GATT Art XXI is not unlimited.
Although the national security exception under WTO law is more permissive than under EU law (where it is subject to a necessity and proportionality test), it only applies to genuine “emergency in international relations” and is not intended for permanent supplier exclusions due to the “governance character” of their countries.
This is also a point that the EU has spent the last six years arguing in its complaint against the US in the steel and aluminium tariffs (DS548). While China hawks may take offence, the EU and China are also not in an emergency-like situation, at least not in the material standards of WTO law. China is therefore right: The EU cannot credibly invoke the national security exception for CSA2 without abandoning its opposition against the US invoking the same exception.
But the question is whether the EU needs to: CSA2 is a measure that protects the right of EU subjects to effective judicial redress against intelligence collection by foreign state authorities, which is not a security interest, but fundamental rights enshrined in EU and national law.
Brussels has already demonstrated this objective against US online platforms. The CJEU did not strike down the EU-US Privacy Shield on national security grounds; it was declared invalid because of the absence of checks and balances in US intelligence laws and effective judicial redress, which violated the Charter. CSA2 protects the same interest and applies to the same theory of harm.
Such laws, which uphold societal values, fall under a general exception for public morals, which the WTO Panels and Appellate Body have repeatedly upheld in past disputes (EC—Seal Products and US—Gambling), provided that they do not impose double standards, or are more restrictive than necessary, which some EU laws have admittedly failed to do.
Whether the CSA2 is such a double standard is the next question. However, the CSA2 is an Article 114 measure on the inside and a public morals intervention on the outside – defensible at the WTO under the General Exceptions rather than the Security Exception – that effectively takes the EU out of the fork.
Judicial redress as a Coordinate Factor
CSA2 reframes the matter at hand as a question of judicial redress rather than of security, as it is organised around judicial redress as an objective criterion. Its draft Article 100(1)(c) sets out judicial redress as one of five coordinate factors supporting designation.
Here, China will argue that the criteria are open-ended and arbitrary, citing the US intelligence laws as a comparator to claim that any judicial redress test is applied discriminatorily.
However, the CJEU (in Schrems II) identified a judicial redress deficit in US law, resulting in a similar threat of exclusion of US online services. In response to that threat, the Biden administration enacted Executive Order 14086, establishing the Data Protection Review Court with binding remediation authority and designating the EU as a qualifying state.
In comparison, China’s National Intelligence Law of 2017 imposes a general, non-waivable obligation on all Chinese private entities to support, assist, and cooperate with intelligence work, with no published limits on its scope or targets. The revised Counter-Espionage Law further empowered security organs to summon, detain, and search without judicial authorisation.
More importantly, administrative lawsuits involving national security and foreign policy fall outside the jurisdiction of the People’s Courts. Article 13(1) of China’s Administrative Litigation Law provides that the People’s Courts shall not accept administrative lawsuits brought against “acts of state”, such as those in national defence and foreign affairs. The exclusion is categorical and likely to apply to both domestic and foreign entities for claims arising from intelligence collection.
WTO law does not require the EU to grant identical outcomes but asks whether differential treatment is “arbitrary or unjustifiable.” A jurisdiction that has negotiated a bilateral redress instrument is not in the same legal position as a jurisdiction whose statute makes any such instrument structurally foreclosed until its intelligence and litigation laws are amended.
What This Means for the CSA2 File
In conclusion, the EU will argue that it is not treating China differently simply because it is China, or due to some supposed “systemic rivalry” with it. The EU is treating China differently because Chinese law makes effective judicial protection for EU citizens categorically impossible – a condition the US has at least formally committed to remedy, after facing threats of market exclusion. This is a cognisable and legally operative distinction, and one which the WTO general exceptions are designed to admit.
Nonetheless, MOFCOM’s WTO legal brief is unequivocal, elaborate, and sophisticated. But it is also a trap that only works if Brussels defends CSA2 on the wrong legal ground. The fork closes only if the EU walks into it – which the Chinese WTO lawyers must be well aware of.
The more likely outcome than a legal dispute is found in the closing pages of their submission, where China uncharacteristically threatens investigations into EU firms, license denials, and market access restrictions under China’s Foreign Trade Law, Data Security Law, and Personal Information Protection Law. In the past, China halted graphite supplies to Sweden after a drafting error in its 5G decision that inadvertently named China and Huawei, indirectly contributing to the Northvolt bankruptcy.
Moreover, the State Council has recently promulgated the Industrial & Supply Chain Security Regulation, which, together with the Anti-Foreign Sanctions Law, authorises countermeasures against businesses or jurisdictions that violate “normal market principles” and prohibits all entities from complying with EU regulatory investigations.
And where China seeks to retaliate rather than litigate, the EU is pressing its own fork against China: Brussels will legislate unless Beijing is willing to negotiate – in the same fashion as successive US administrations were forced into concessions after Schrems I–II and the GDPR. But without the mounting pressure from CSA2, the Industrial Accelerator Act, and a forthcoming overcapacity instrument, Brussels cannot reach an outcome to its advantage.
See also the recent post by Lee-Makiyama on the Member States objections against the CSA2 draft.
One response to “China Brings Trade Law to Cybersecurity”