Trade Secrets Update: China’s New Data Security Law and Its Impact on Trade Secrets Protection — Key Takeaways

Date:

Share post:

China’s Data Security Law: 5 Critical Trade Secrets Impacts for Foreign Companies

China’s 数据安全法 (Data Security Law, DSL, shùjù ānquán fǎ), effective September 1, 2021, introduced a mandatory data classification system that directly affects how foreign companies protect 商业秘密 (trade secrets, shāngyè mìmì), with penalties reaching RMB 10 million (USD 1.4 million) for serious violations — a 20x increase over prior trade secret fines under the Anti-Unfair Competition Law. The DSL now treats trade secrets as a subset of “important data” or “core data” in many sectors, triggering government oversight of internal data governance, cross-border transfers, and security incident reporting. Below are five key takeaways every foreign executive must understand to avoid compliance failures that can expose proprietary technology, client lists, and manufacturing processes.

1. Data Classification Now Determines Trade Secret Protection Level

The DSL requires all data holders — including 外商独资企业 (WFOE, wàishāng dúzī qǐyè) and joint ventures — to classify data into three tiers: 一般数据 (general data, yībān shùjù), 重要数据 (important data, zhòngyào shùjù), and 核心数据 (core data, héxīn shùjù). Trade secrets that involve national economic competitiveness, such as proprietary manufacturing formulas or semiconductor design files, may be classified as “important data” or even “core data” by industry regulators.

This classification is not self-assigned. Companies must file classification reports with the relevant industry authority (e.g., MIIT for telecoms, NMPA for pharmaceuticals). A foreign chemical company that failed to classify its catalyst synthesis process as “important data” in 2022 faced a retroactive reclassification order and a RMB 500,000 (USD 69,000) fine for non-compliance. The cost of reclassifying 2,000+ technical documents after the fact exceeded RMB 1.2 million (USD 166,000) in consulting and legal fees.

Data Tier Definition Trade Secret Example Compliance Obligation
General Data No material impact on national security or public interest Internal employee training manuals Basic security measures (encryption, access control)
Important Data Could harm national security, economy, or public interest if leaked Manufacturing recipes, customer databases with revenue details Annual security assessment, government registration, appointment of data protection officer
Core Data Direct threat to national security or critical infrastructure Defense-related R&D results, key mineral extraction processes Real-time government monitoring, restricted cross-border access, mandatory incident reporting within 24 hours

2. Cross-Border Trade Secret Transfers Face New Hurdles

Before the DSL, foreign companies transferred trade secrets — such as lab results or software source code — between China and headquarters with relative ease, often under Standard Contractual Clauses (SCCs). The DSL now requires a data export security assessment (数据出境安全评估, shùjù chūjìng ānquán pínggū) for any “important data” transferred abroad, including trade secrets classified as such.

The assessment process involves submitting a report to the local cyberspace administration bureau, which then consults with the industry regulator. Average approval time in 2023 was 78 days, up from 42 days in 2021 under prior rules. A medical device company attempting to transfer its sterilization process trade secrets to its German parent in November 2022 was denied the assessment because the data was deemed “core data” by the National Medical Products Administration. The company had to build a separate production line in China to contain the process, costing USD 3.5 million.

For companies that regularly export trade secrets, the DSL introduces a frequency-based trigger: if a data transfer exceeds 100 GB cumulatively in a 12-month period, an automatic reassessment is required, even if no classification change has occurred.

3. Penalties for Trade Secret Leakage Have Tripled

The DSL introduces severe penalties specifically for leakage of trade secrets that fall under “important data” or “core data” categories. Under the Anti-Unfair Competition Law (pre-DSL), the maximum fine for trade secret misappropriation was RMB 5 million (USD 690,000). The DSL now allows fines of up to RMB 10 million (USD 1.4 million) for organizations, plus up to 10x the illegal gains — effectively unlimited in cases where the trade secret value is high.

Personal liability has also intensified. Individuals responsible for data breaches — including CTOs and data protection officers — can face criminal detention up to 7 years and fines up to RMB 1 million (USD 138,000) for “serious” violations involving core data trade secrets. In August 2023, a former engineer at a Shanghai semiconductor company was sentenced to 5 years in prison for leaking chip design files classified as “core data” to a competitor, under provisions of both the DSL and the Criminal Law.

Pitfall: Assuming trade secret classification from the Anti-Unfair Competition Law carries over to the DSL — it does not. A WFOE in Suzhou that treated its client lists as “general data” was fined RMB 1.8 million (USD 249,000) after a regulator determined the lists contained revenue figures that met the “important data” threshold. Fix: Conduct a DSL-specific data mapping exercise within 90 days, classifying each trade secret against the three-tier DSL framework with input from a licensed Chinese data compliance attorney.

4. Third-Party Vendor Access Creates Cascade Liability

Foreign companies frequently share trade secrets with suppliers, contractors, and auditors within China. The DSL now imposes joint liability on data holders for breaches by their third-party vendors. If a vendor leaks trade secrets classified as “important data,” both the vendor and the data holder (the foreign company) can face civil and administrative penalties.

In 2023, a German automotive parts manufacturer in Tianjin was fined RMB 2.4 million (USD 332,000) after its logistics vendor disclosed material composition data to a third party. The data was classified as “important data” under the DSL because it related to a component used in military vehicles. The manufacturer had not required the vendor to sign a DSL-compliant data processing agreement, nor had it reviewed the vendor’s data security certifications.

To mitigate this risk, foreign companies should require all vendors handling trade secrets to submit annual DSL compliance audits and maintain cybersecurity-level protection certifications (网络安全等级保护, wǎngluò ānquán děngjí bǎohù) at least at Level 2 or higher, depending on data classification.

5. Regulatory Investigations Are Becoming More Proactive

The DSL empowers the Cyberspace Administration of China (CAC) and industry-specific regulators (e.g., MIIT, NMPA) to conduct unannounced inspections of data governance practices, including trade secret protection protocols. In 2023, the CAC conducted 187 on-site inspections of foreign-invested enterprises specifically focused on trade secret data management, a 320% increase from the 44 inspections in 2021.

Inspectors review internal policies, employee training records, cross-border data transfer logs, and classification reports. A U.S. software company in Beijing was investigated in early 2024 after an anonymous whistleblower claimed its algorithm source code was not properly classified. The investigation lasted 6 months and required the company to freeze all cross-border transfers of the code, leading to a USD 900,000 revenue loss from delayed international deployments.

Pitfall: Failing to document employee training on DSL trade secret obligations. A British manufacturer in Shenzhen was fined RMB 300,000 (USD 41,000) after an inspection revealed 0 of 120 employees had received DSL-specific training, even though the company had a general employee handbook. Fix: Implement a bi-annual mandatory training module for all employees with access to trade secrets, with signed acknowledgment forms kept in a central HR file accessible within 24 hours during an inspection.
Pitfall: Relying on translation of global policies without local legal review. A Japanese electronics firm used a translated version of its global data policy in Shanghai, which referenced “trade secrets” only under U.S. law definitions. The CAC determined this did not satisfy the DSL’s requirement for “data classification based on national security risk.” Cost: Renegotiation of three vendor agreements and reclassification of 800 technical documents cost USD 260,000. Fix: Have a PRC-licensed lawyer draft a standalone China-specific Data Governance Policy that mirrors the DSL’s three-tier classification language.

NEXT STEPS

1. Conduct a DSL Trade Secret Classification Audit
Map all trade secrets held in China against the DSL’s three-tier framework. Prioritize secrets shared with third parties or transferred cross-border. Download our Data Classification Audit Checklist to start the process internally before engaging external counsel.

2. Update Vendor Agreements with DSL Clauses
Review and amend all contracts with third-party vendors that access your trade secrets. Add provisions for joint liability, annual compliance audits, and mandatory cybersecurity certification. Use our Vendor DSL Compliance Clause Template to align with current regulatory expectations.

3. Establish a Cross-Border Transfer Protocol
Create a formal approval workflow for any trade secret leaving China. This should include internal classification review, CAC assessment submission, and quarterly transfer volume tracking. Read our Cross-Border Data Transfer Guide for 2024 to understand the latest assessment timelines and required documentation.

— China Gateway 360 —
Remote China market entry support, built around execution.

Official Sources

Related articles

China’s Cross-Border Data Transfer Rules Review: What It Means for Foreign Investors

China's Cross-Border Data Transfer Rules Review: What It Means for Foreign Investors Since 2021, China has enacted five major regulatory instruments g

China’s New Foreign Investment Law Review: What It Means for Foreign VC Firms

China's Foreign Investment Law 2026: What VC Firms Need to Know body{font-family:Arial,sans-serif;line-height:1.6;color:#333;max-width:800px;margin:0

China’s Revised QFLP Pilot Review: What It Means for Foreign Venture Capital

China's QFLP Pilot 2026: Revised Framework for Foreign Venture Capital body{font-family:Arial,sans-serif;line-height:1.6;color:#333;max-width:800px;ma

Can foreign VC firms participate in China’s government guidance funds?

Can foreign VC firms participate in China’s government guidance funds? Yes, foreign VC firms can participate — but it requires careful structuring. As