Code Brain | Amazon's Ten Overseas Compliance Lessons
Code Brain | Ecosystem Connections, Cognitive Resonance
Compliance is a "sword" hanging over every Chinese company going global. In overseas markets with different cultural environments, regulatory frameworks, and market access requirements, Chinese enterprises often face numerous direct and latent risks due to unfamiliarity with local laws and unwritten rules—especially on compliance, where they have repeatedly become targets.
On the evening of August 12, the fourth installment of Source Code Capital's Going Global series was held online, focusing on "How to Address Compliance Challenges in Overseas Expansion." Source Code Capital invited two guests with extensive hands-on experience in international compliance: Chen Jiao, expert at the Guangdong Cross-Border E-Commerce Industry Research Institute and Solution Director at Chenhai Group, and Zhou Ying, Senior Security and Compliance Specialist at Amazon Web Services. They shared insights on common compliance issues facing Chinese companies going global—including tax and financial compliance, data compliance, privacy compliance, product compliance, and operational compliance—along with practical solutions.
During the two-hour session, the guests engaged in in-depth discussions with participating companies on practical matters such as data migration and tax compliance.

Below is a curated Q&A from the session:
01 Product Compliance
Q: If a company going global uses one brand authorization across multiple overseas sites, are there potential risks?
Chen Jiao: Yes, there are risks of "brand guilt by association" or "brand joint liability."
"Brand guilt by association" mainly refers to the fact that authorized accounts under the same brand are controlled by the same entity. If one brand commits a violation, all other accounts under that brand management are considered jointly liable. Platforms may then require related products on other sites to be taken down. "Brand joint liability" means that identical trademarks share liability—once a brand is blacklisted by Amazon, other trademarks with the same brand name, whether in the same country or different countries, will face sales restrictions.
There are three main corresponding solutions:
- Revoke authorization. Referencing the parent-sub-brand structures used by certain well-known companies can, to some extent, serve as a way to disperse potential risk.
- Brand isolation. Register and file core brands as needed.
- Brand monitoring. This mainly addresses trademark squatting. To prevent trademarks from being preemptively registered, early layout across different sites is necessary.
Q: What mandatory testing and certifications must Chinese companies obtain when taking products overseas?
Chen Jiao: Products must be tested according to EU/UK standards, with corresponding reports and certificates issued upon passing, before they can enter European markets—this is essentially an entry threshold. The main certifications are CE, UKCA, REACH, and ROHS. Overseas manufacturers must designate a natural person or legal entity in the European Economic Area (EEA, including EU and EFTA) or the UK to fulfill specific duties required of manufacturers under EU/UK directives and laws. If you have a local office, you can use your own personnel as your EU/UK representative; otherwise, you need to find a specialized service provider.
German and French EPR (Extended Producer Responsibility) is now mandatory. It's particularly important to note that, based on environmental protection objectives, manufacturing, importing, or selling EPR-covered products in Germany/France requires registration numbers for the relevant products and annual reporting of product weights. Multiple platforms, including Amazon, have notified sellers to register for EPR or face product removal. Amazon required compliance with Germany's Packaging Act by June 30, 2022, and with Germany's WEEE EPR by December 31, 2022.
02 Tax and Financial Compliance
Q: What are the key tax and financial compliance considerations for Chinese companies when planning overseas market entry?
Chen Jiao: Focus on five main points: First, the overseas local market capacity for e-commerce—choose countries with large populations, strong purchasing power, and high e-commerce penetration for company registration. Second, efficiency—consider countries with more digitized government services, as European government offices tend to have lower efficiency. Third, registration costs—developed countries like Germany, France, Italy, and Spain have higher registration fees, suitable for sellers entering mainstream markets; Cyprus, the Netherlands, and others have lower costs and simpler maintenance, better for small and medium sellers. Fourth, logistics and warehousing convenience—prioritize countries with convenient, low-cost logistics and warehousing. Fifth, ongoing company maintenance costs, mainly annual reviews, tax audits, and tax costs.
Q: How can companies going global ensure compliance in tax risk management?
Chen Jiao: I have four recommendations: First, choose a professional and responsible tax agent, preferably after an on-site visit. Second, declare true amounts and file and pay taxes on time. Third, use your own tax ID for formal customs clearance through proper logistics channels. In the past, many people chose "dual customs clearance" gray channels, where cargo rights belong to the freight forwarder—this creates risk for both the forwarder and the company. Once investigated, you face both cargo and tax risks. Fourth, for local stores, monitor remote sales volume, with a recommended threshold of €10,000 per site.
When investigated by tax authorities, you will most likely be asked to provide the following—not necessarily all. One, VAT number and customs clearance ID; two, platform sales figures; three, VAT declaration pre-tax payment vouchers; four, customs clearance documents, import VAT, and tariffs; five, commercial invoices from freight companies with cargo information; six, VAT invoices. Any or all of these may be requested, plus other documents specifically required by the tax bureau. Tax authorities typically notify companies of issues via email, so stay attentive to relevant correspondence from them.
Q: What are common "pitfalls" in capital flow for cross-border e-commerce sellers?
Chen Jiao: The common "pitfalls" in cross-border sellers' capital flows manifest in four areas:
- When receiving payments, the vast majority of sales revenue is withdrawn directly by third-party payment platforms to personal private cards in China, in huge amounts without being recorded as company revenue or declared for tax purposes. The source of funds cannot be reasonably explained to authorities, potentially triggering investigation risks.
- When purchasing, using private cards for transactions, with large amounts and high frequency—under Golden Tax Phase IV (the fourth phase of the national Golden Tax project), this is easily flagged by bank monitoring and frozen, further impacting partnerships and supply stability.
- When exporting, the vast majority of goods go through dual customs clearance with tax included, without using the company's own name for proper customs declaration. Nominal cargo rights don't belong to the company, there are no proper customs declarations, and this is treated as domestic sales with supplementary taxes owed.
- In management, employee salaries are settled privately without legally withholding individual income tax. If current or former employees report this, tax bureau investigations can easily penetrate to other tax-related issues at various levels.
Q: How can these capital flow "pitfalls" be effectively avoided?
Chen Jiao: To address these risks, the main approach is to build domestic and overseas structures to ensure compliant and smooth equity flows, goods flows, and capital/tax flows—with all money moving through the company. The evolution of domestic and overseas structures has gone through Phase 1.0 trade-oriented going-global structures, Phase 2.0 integrated industry-trade structures, to today's Phase 3.0 local branding going-global structures (see diagram below).

Image source: Guest presentation
The benefits of establishing overseas local companies mainly include:
- Avoiding platform withholding and remittance—local stores don't have platforms withhold and remit VAT, significantly easing capital tie-up issues.
- Compliant customs clearance—local companies handle unified import customs clearance, with import VAT eligible for deferral.
- Local brand building—creating local flagship stores better enhances brand influence, and local brands receive platform traffic preference, benefiting credit valuation.
- Expanded sales channels—after unified overseas import customs clearance, you can further sell to local distributors, supermarkets, etc., doing B2B business, and also facilitating sales of slow-moving inventory.
- Profit transfer—you can transfer lower-selling or slow-moving products to non-affiliated companies, shifting profits to group-affiliated companies.
- Lower risk—overseas local stores face lower investigation probability compared to cross-border stores.
Q: When mainland companies ship goods but Hong Kong companies receive payments, with mismatched capital and goods flows, how should the tax risks from this misalignment of business flow, capital flow, and tax flow be handled?
Chen Jiao: All capital flows are based on business models, which may involve goods trade or service trade. Once goods trade is involved, export customs declarations become particularly important.
For example, when goods are shipped from a domestic export company to an overseas warehouse, the customs declaration needs to show two company names: first, the export company's name, and second, the Hong Kong company's name. In terms of goods flow, the goods don't need to pass through Hong Kong, but in business flow, the goods are essentially first sold to the Hong Kong company, which then sells them overseas—this needs to be reflected on the customs declaration. This way, after the Hong Kong company receives money, it can remit it back to the export company as payment for goods.
If service trade is involved, with revenue concentrated in the Hong Kong company, profits can be repatriated to the mainland through service trade. For example, if company staff are all based in the mainland but actually provide services for the Hong Kong company's business, the mainland company can issue proforma invoices and contracts to the Hong Kong company, which then remits profit income back to the mainland as service trade. It's particularly important to note that mainland service companies need to apply for VAT exemption filing with tax authorities—without this filing, VAT on service fees must be paid.
03 Privacy Compliance
Q: How costly are violations of personal information regulations?
Zhou Ying: Many companies are very focused on privacy compliance, partly because it's closely tied to their business, and partly because the cost of personal information violations is very high. Generally, the costs of personal information violations fall into two categories: first, product bans or removals; second, substantial fines.
In June 2022, the Ministry of Industry and Information Technology announced it had cumulatively removed nearly 300 non-compliant apps, mainly for illegally collecting personal information. Beyond China, the United States, India, the EU, Australia, and Indonesia also ban apps that violate content safety or personal information regulations.
Beyond bans and removals, fines are the more common penalty. DiDi was recently fined over $1 billion, setting a new record for highest penalty. Before that, the highest fine was the British Airways data breach case at €204 million. The main events triggering fines are: first, data breach incidents; second, marketing-related cases, including telemarketing and targeted advertising push notifications.
Q: What data security risks and hidden dangers do Chinese companies face in overseas digital marketing?
Zhou Ying: In digital marketing, we frequently encounter push notifications via email. Of course, it's best to obtain user consent first, but requirements vary by country.
The EU, China, Singapore, and Brazil require obtaining user consent before pushing, while the United States and Japan don't, as they aim to promote industry development—but they must have an "unsubscribe" function and explain in the privacy policy that collected user information will be used for marketing pushes.
Q: With different laws in each country, how should companies with cross-border multi-country operations build a privacy compliance system?
Zhou Ying: After analyzing personal information protection laws in over 130 countries, we found that these countries' legal frameworks are fundamentally similar, all containing data processing principles, lawful basis for processing, data subject rights, accountability and governance, and cross-border data transfers. For companies with multi-country overseas operations, we recommend building your privacy compliance system based on GDPR (the EU's General Data Protection Regulation) and CDPA (Virginia's Consumer Data Protection Act in the United States).

Image source: Guest presentation
Specifically, when building your own privacy compliance system, we recommend a three-step approach:
- First, establish user perception—add privacy settings features in customer-facing products or clients, such as toggles for non-essential permissions, turning off personalized recommendations and marketing push notifications, and providing account cancellation, account deletion, and personal data download functions.
- Build backend capability support—mainly constructing three centers: a privacy control center, a compliance intelligence center, and a personal information breach incident response center. I strongly advise companies to monitor user complaints carefully, because users in the EU and United States have strong personal information protection awareness, and their regulatory agencies' websites have direct complaint portals. So if consumers don't get satisfactory resolution after appealing to the company, they'll go directly to regulators to complain, causing incidents to escalate. Therefore, we recommend companies reserve channels for handling customer complaints.
- Obtain third-party certification—after completing internal privacy compliance construction, we recommend finding a third-party certification body to certify your achievements, which can also help companies better respond to overseas regulation.
Q: What cross-border data compliance challenges do companies going global face at different development stages?
Zhou Ying: Through our exchanges with many companies going global, we categorize them into three stages:
Stage One—Testing the waters. The main challenge at this stage is business survival. Companies prioritize business development with limited compliance investment. We recommend that companies plan their overseas data compliance roadmap in advance to avoid unnecessary pitfalls.
Stage Two—Getting established. At this point, the company's overseas foundation is stable. The main challenges are splitting domestic and overseas operations and evaluating suitable overseas regions. Meanwhile, cross-border access and transfers begin to emerge, requiring cross-border data monitoring.
Stage Three—Maturity. As business volume grows and the number of countries increases, the regulatory landscape becomes more complex, requiring new regional splits for international data. The challenges at this stage are mainly international business segmentation, region adjustment, localization in new countries, and increasingly complex scenarios for cross-border data access and transfers. We recommend evaluating and considering storing data in appropriate regions, and on the foundation of cross-border data monitoring, forming a cross-border data map, and if necessary, building data isolation warehouses.
Q: Based on Amazon's own practices, what compliance experiences and methods are worth learning from for Chinese companies?
Zhou Ying: Ten key areas deserve attention:
- Find the right equilibrium point—company compliance should achieve a continuously dynamic balance between business development and meeting regulatory requirements, always maintaining appropriate compliance.
- Compliance workflows must be end-to-end, including evidence collection, gap analysis, improvement measures... there needs to be a lead department responsible from start to finish, solving compliance issues end-to-end.
- Security compliance must focus on both points and surfaces, and must stay ahead of business development.
- Data compliance must be embedded in product development—product development teams should have dedicated security engineers who begin security compliance design and review from the first line of code.
- Proactively communicate with regulators, actively participate in developing various national and international standards, and practice proactive compliance.
- Move quickly—because compliance issues are extremely broad, once you've established your business scope and applicable data compliance standards, act fast.
- Transform data compliance requirements into operable technical requirements—security compliance requirements are relatively dry and need to be translated into more understandable business language.
- Make security compliance and data compliance training routine.
- Strengthen the technical capabilities of your security compliance team.
- Pay attention to automation—if something happens repeatedly, consider introducing automation. For example, repeated compliance issue raising, repeated compliance evidence collection, or repeated compliance technology use.


Code Brain Issue 30 | 60 Hours of "Practical Leadership": Full Highlights!
Code Brain Issue 29 | Zheng Yunduan: What Really Drives Organizations?
Code Brain Issue 28 | Understanding Human Nature to Build a Going-Global "Vanguard"
Code Brain Issue 27 | The Origins and Destinations of Carbon
Code Brain Issue 26 | Overseas Marketing Matters
Code Brain Issue 25 | Mastering Liu Genghong's Traffic Code
Code Brain Issue 24 | The "Changing" and "Unchanging" of Equity Financing
Code Brain Issue 23 | Eight Questions on Going Global: Where Are the New Business Opportunities?
Code Brain Issue 22 | Navigating Supply Chains Amid "Turbulence"
Code Brain Issue 21 | Clear Despair Beats Vague Hope: On ToB Sales During the Pandemic
Code Brain Issue 20 | Is Your Cash Flow Still Healthy During the Pandemic?
More MaHui members can click "Read Original" to view
