Part 5 of 8. Part 4 looked at what courts and regulators have decided.
What this post covers
- Law that reaches companies in other countries.
- What France made of it.
- Older worries about commercial information.
- Pressure applied through trade.
- Assumptions that travel with a product.
Law that reaches companies in other countries
Part 2 explained how one country’s law can reach data held by a company it controls.
The same principle reaches companies themselves, and the effects can be a good deal bigger.
The best documented example in Europe is Alstom, a French engineering company.
In 2014 Alstom pleaded guilty in the United States and agreed to pay $772 million. The case came under the Foreign Corrupt Practices Act, an American anti-bribery law. The United States Department of Justice published the detail.
The bribery was real. This is not a tale about an innocent company.
An Alstom executive was also arrested while travelling through the United States, and spent time in prison.
Around the same period Alstom sold its power business to General Electric, an American company.
The executive has since argued that the unresolved case worked as pressure during that sale. United States prosecutors have denied acting to help an American buyer.
That disagreement has never been settled, and as such this post cannot settle it either.
What France made of it
What can be shown is what the French state concluded afterwards.
In June 2019 a report went to the French Prime Minister. It is known as the Gauvain report, and its title is about restoring French and European sovereignty and protecting companies from laws with extraterritorial reach.
Extraterritorial means a law that applies beyond the borders of the country that made it.
The report found 3 things worth repeating here.
- Very large penalties, running to tens of billions of dollars, had been imposed on French, European and other non-American companies.
- Much of the conduct had little direct connection to United States territory.
- French companies had no effective legal tools to defend themselves.
It also noted that American companies were rarely the target.
France then updated its blocking statute, a law limiting what information French companies may hand to foreign authorities. An earlier parliamentary inquiry had looked at the same subject in 2016.
You do not have to swallow every conclusion in that report. It is enough that a national parliament looked at the question and decided it was a matter of sovereignty.
For your own planning the point is short.
Legal exposure to another country is a commercial exposure. Not just a compliance one.
Older worries about commercial information
This worry is not new, and it is worth knowing how far back it runs.
In 2001 the European Parliament published a report on a global communications interception system, then known as ECHELON. The Parliament has since published a study revisiting that work.
The report concluded such a system existed. It also examined claims that intercepted information had been used for commercial advantage, including European companies.
Those claims were contested at the time and remain hard to prove.
The reason to mention it is not to settle them. It is that the European Parliament took the question seriously enough to run a formal inquiry 25 years back, and it has not gone away since.
Pressure applied through trade
Part 2 covered tariffs on kit, and Canada dropping its digital services tax after trade talks were called off.
There is one more step worth recording on its own, because it applies to people rather than goods.
In January 2026 the United States State Department imposed visa restrictions on 5 European officials. They had worked on the Digital Markets Act and the Digital Services Act, the European laws governing large online platforms.
It came alongside tariff threats connected to European enforcement action.
The Centre for Strategic and International Studies has described this as using trade measures to discourage digital regulation.
The Istituto Affari Internazionali, an Italian institute, has looked at whether enforcement of the Digital Markets Act is becoming negotiable as a result.
That is the open question. If European technology rules can be shifted by trade pressure, the protection they give you is less certain than the text suggests.
It is only fair to add that trade pressure is a normal tool of statecraft, used by plenty of countries including European ones. The point here is what it is being used on.
Assumptions that travel with a product
The last item is quieter than the rest — no court case, no fine — and it affects you every day.
Software gets built for the market its makers know best. That market’s assumptions travel with it.
Some you will recognise straight away.
- Privacy settings often default to sharing, because that is the common approach in the United States. European law starts from asking permission.
- Staff management tools often assume employment can end at short notice, and that there is no works council to consult.
- Standard contract terms often want disputes heard in a United States court, under United States law, even for a European customer.
- Content rules follow 1 country’s approach to free expression, then get applied worldwide.
- Support for smaller languages turns up last, and sometimes not at all.
None of this is done to cause bother — it is the ordinary result of building for a home market and selling the result everywhere else.
It does explain something about the wider argument, though.
The General Data Protection Regulation, the Digital Markets Act and the Digital Services Act are mostly Europe stating that it is a separate legal area with its own settled rules.
The answer to that has included the trade measures above.
What it means for you
Three practical points fall out of this.
Read the governing law clause. Check whose courts would hear a dispute. On a large contract that is worth negotiating.
Ask where your supplier’s parent company is registered. That answer decides more than the address of the data centre.
Check a product fits your legal setting before you buy. Consent, employment rules and record keeping are the usual places an imported default does not match local law.
Nowt there needs a view on any government. It is ordinary supplier diligence, applied to a question most procurement checklists still miss out.
Part 6 looks at security, and at the standard applied when a supplier is shut out on national security grounds.
First published: 2026-08-25. Last updated: 2026-08-25.