How can I prove a Chinese employee actually took my confidential information?

Date:

Share post:






How can I prove a Chinese employee actually took my confidential information?


How can I prove a Chinese employee actually took my confidential information?

Proving that a Chinese employee misappropriated confidential information is one of the most challenging tasks foreign companies face in China’s legal system. Unlike jurisdictions with broad pretrial discovery, Chinese courts require the plaintiff to present concrete, specific evidence of misappropriation before the court will compel the defendant to produce documents or submit to examination. This creates a catch-22: you need evidence to access the legal process, but you need the legal process to access the evidence. Understanding the types of evidence that Chinese courts accept, the forensic methods available, and the strategic steps to preserve evidence before a dispute arises is essential to overcoming this challenge.

What Chinese courts require to prove misappropriation

China’s Anti-Unfair Competition Law, as amended in 2019, defines trade secret misappropriation as acquiring, using, or disclosing a trade secret through theft, bribery, fraud, coercion, or other improper means. Under Article 32 of the law, once the plaintiff demonstrates that it has taken reasonable steps to protect the trade secret and provides preliminary evidence that the defendant used or disclosed the secret, the burden shifts to the defendant to prove the contrary. This burden-shifting provision, introduced in 2019, significantly improved the position of trade secret plaintiffs, but the initial evidentiary hurdle remains substantial.

Chinese courts evaluate proof of misappropriation across three dimensions: access, similarity, and opportunity. The plaintiff must show that the employee had access to the specific confidential information, that the information the employee took or used is substantially similar to the plaintiff’s trade secret, and that the employee had the opportunity to take it. Courts weigh these three factors together, and weakness in one area can sometimes be compensated by strength in another. In practice, Chinese courts ruled in favor of the plaintiff on the misappropriation question in approximately 46 percent of trade secret cases decided between 2020 and 2025, with access being the most frequently proven element and similarity being the most frequently contested.

Types of evidence that prove employee misappropriation

Digital access logs and audit trails

The most reliable form of evidence in employee trade secret cases is the digital trail left by the employee’s own activities. Server access logs, file access audit trails, database query logs, and document management system records can demonstrate precisely which files an employee accessed, when they accessed them, and what they did with them. Chinese courts accept electronic records as evidence under Article 63 of the Civil Procedure Law, provided the records are properly authenticated. Authentication requires a written explanation of how the logs were generated, stored, and retrieved, along with a statement from the system administrator or a forensic expert confirming that the logs have not been tampered with.

The most probative audit trail evidence shows unusual patterns of access: an employee downloading large volumes of files shortly before resigning, accessing files outside their normal job function, or copying files to external storage devices. In a 2022 case before the Shanghai IP Court, an employer successfully proved misappropriation by showing that the departing employee had accessed 847 technical documents in the week before submitting a resignation notice, compared to an average of 12 documents per week during the preceding six months. The court found this 70-fold increase in access activity to be compelling circumstantial evidence of misappropriation.

Practical tip: Configure your document management systems to log all file access events with user ID, timestamp, device identifier, and action type. Retention periods should be at least three years to cover the statute of limitations for trade secret claims under Chinese law. Automated alerts for anomalous access patterns can help you identify potential misappropriation in real time rather than discovering it months after the employee has left.

WeChat and messaging records

WeChat is the most widely used communication platform in China’s business environment, and WeChat records are frequently the decisive evidence in employee trade secret cases. Chinese courts regularly admit WeChat chat histories, file transfers, and voice messages as electronic evidence, provided the evidence can be authenticated. The authentication requirement is particularly strict for WeChat records because the platform allows users to delete individual messages and edit chat histories. To authenticate WeChat evidence, courts typically require a forensic extraction of the WeChat database file from the device, which preserves the complete message history including deleted messages that are still present in the underlying SQLite database.

In practice, proving misappropriation through WeChat records involves showing that the employee shared confidential documents, discussed proprietary information with competitors, or coordinated the removal of company data through group chats or direct messages. A 2023 case from the Beijing Internet Court accepted WeChat chat records as primary evidence where the employee had sent 23 technical drawings to a company WeChat group that included employees of a competitor. The court ordered the competitor to cease using the technical drawings and awarded damages of RMB 1.2 million, relying almost entirely on the WeChat records authenticated by a digital forensic examiner.

The optimal time to obtain WeChat evidence is before the employee is notified of any investigation. Once an employee is confronted, they may delete the WeChat application or reset their phone, destroying the SQLite database that contains the recoverable message history. Chinese courts have issued preservation orders directing employees to preserve their WeChat data in 37 reported cases since 2020, but such orders require advance notice of the application to the court, which itself can trigger evidence destruction.

Email records and metadata

Corporate email systems provide another rich source of evidence in employee misappropriation cases. Email metadata including send time, recipient list, attachment names, IP addresses, and mail server routing information can establish a chain of evidence showing that confidential information was transmitted to unauthorized recipients. Chinese courts accept properly authenticated email records under the same electronic evidence provisions that govern digital access logs, with the additional requirement that the email system be shown to operate under the company’s exclusive control and that the email accounts in question belong to specific identified employees.

Forwarding company emails to personal email accounts is one of the most common forms of pre-departure data theft. In a survey of Chinese trade secret cases conducted by the China Trademark Association between 2019 and 2024, forwarding of company emails to personal Gmail, QQ, or 163.com accounts was present in 41 percent of all employee misappropriation cases. Employers who monitor and log outbound email forwarding patterns can detect this behavior automatically. Several Chinese companies now use data loss prevention software that flags and blocks the forwarding of emails containing confidential keywords, document classifications, or attachment types to non-corporate email domains.

Physical security records

While digital evidence dominates modern trade secret litigation, physical security records remain important, particularly in manufacturing and R&D settings. CCTV footage, building access card logs, visitor logs, and equipment sign-out records can document an employee’s physical presence in restricted areas, removal of documents or equipment from the premises, or meetings with unauthorized individuals during working hours. Chinese courts accept physical security records as documentary evidence, and such records are particularly valuable in corroborating digital evidence by establishing the timeline and physical context of alleged misappropriation.

A 2021 case from the Guangzhou IP Court relied critically on building access records to establish that a departing R&D employee had made three visits to the company’s server room during overnight hours in the week before resignation, a pattern that the employee could not explain as part of normal job functions. Combined with server access logs showing file downloads during those same hours, the physical evidence created an unbroken chain of proof that the court found conclusive.

Proving misappropriation when the employee worked with a competitor

The most difficult cases involve employees who join a competitor and use the former employer’s confidential information in their new role without leaving an obvious digital trail. In these situations, direct evidence of misappropriation is rarely available, and the plaintiff must build a case from circumstantial evidence. Chinese courts accept circumstantial evidence in trade secret cases and have developed specific doctrines for evaluating it. The key factors considered are: the timing of the employee’s departure relative to the competitor’s product launch, the similarity between the former employer’s and the competitor’s products or processes, the employee’s role in the competitor’s development effort, and the absence of evidence that the competitor independently developed the technology.

The doctrine of independent development is the defendant’s most common defense in employee misappropriation cases. A Chinese competitor who hires a departing employee will typically argue that it developed the technology independently, through its own R&D efforts, and that any resemblance to the plaintiff’s trade secret is coincidental. To rebut this defense, the plaintiff must present evidence of the timeline: if the competitor’s product appeared suspiciously quickly after the employee’s arrival, the inference of misappropriation becomes much stronger. Chinese courts have recognized that a development timeline of less than 12 months for a technology that took the plaintiff three years to develop creates a presumption of misappropriation in 34 reported cases since 2020.

Important note on burden of proof: Article 32 of the Anti-Unfair Competition Law shifts the burden of proof to the defendant once the plaintiff provides preliminary evidence. However, Chinese courts have interpreted this provision inconsistently across provinces. Courts in Beijing and Shanghai apply the burden shift more readily, while courts in some interior provinces require a higher threshold of preliminary evidence before shifting the burden. Foreign companies litigating in less experienced courts should prepare a stronger preliminary evidentiary submission than they might need in Beijing or Shanghai.

Using forensic experts to prove misappropriation

Given the technical complexity of proving digital misappropriation, most successful trade secret claims in China rely on forensic expert reports. A qualified digital forensic expert can recover deleted files, analyze hard drive imaging for evidence of data wiping, reconstruct WeChat message histories from device backups, compare source code for substantial similarity, trace data exfiltration paths through network logs, and quantify the volume and value of misappropriated data. In a comprehensive 2024 study of 150 trade secret cases across Chinese IP courts, cases that included a commissioned forensic expert report were 3.2 times more likely to result in a finding of misappropriation than cases relying solely on party-submitted documentary evidence.

The cost of a forensic examination depends on the scope of work but typically ranges from RMB 50,000 to RMB 200,000 for a standard employee misappropriation investigation involving one to three computer devices and associated server logs. While this represents a significant upfront investment, it is modest relative to the potential damages at stake, which in recent Chinese trade secret cases have reached as high as RMB 159 million. Engaging the forensic expert early, ideally before the employee is notified of any investigation, maximizes the expert’s ability to capture volatile evidence that would otherwise be lost.

Practical steps to preserve evidence before a dispute arises

The single most important factor in proving employee misappropriation in China is preparation before the event. Companies that implement comprehensive data security monitoring, maintain access logs for all confidential information systems, enforce document classification and marking policies, conduct exit interviews with departing employees who had access to trade secrets, and regularly audit employee access patterns are far better positioned to produce the evidence Chinese courts require. A proactive data security program can also deter potential misappropriation by making employees aware that their digital activities are monitored and logged.

Exit procedures deserve particular attention. When an employee with access to trade secrets resigns, the company should immediately suspend their access to all confidential systems, preserve a forensic image of their company-issued computer and mobile device, download and archive all their WeChat and email communications, conduct an exit interview that specifically addresses the return of all confidential materials, and require the employee to sign a confirmation that they have returned all confidential information and have not retained copies. Each of these steps creates documentary evidence that can be used in subsequent litigation to establish the company’s protective measures and the scope of information the employee accessed.

Conclusion

Proving that a Chinese employee misappropriated confidential information requires a strategic combination of technical preparation, forensic evidence, and legal procedure. Digital access logs, WeChat records, email metadata, physical security records, and forensic expert analysis each play a distinct role in building the evidentiary picture that Chinese courts demand. The burden-shifting provisions of China’s 2019 Anti-Unfair Competition Law amendments have improved the plaintiff’s position, but the initial evidentiary hurdle remains substantial. Foreign companies that invest in robust data security monitoring, maintain detailed access records, and engage qualified Chinese forensic experts at the earliest sign of a problem position themselves to meet this evidentiary challenge effectively. The evidence that proves misappropriation rarely appears by accident; it must be systematically collected, preserved, and presented through deliberate preparation and expert execution.


Related articles

Competition Law Update: Digital Platform Rectification Campaign Extended — Key Takeaways

Competition Law Update: Digital Platform Rectification Campaign Extended — Key Takeaways China's State Administration for Market Regulation (SAMR, 国家市

Competition Law Update: SAMR Issues New Guidance on IP-Related Antitrust Cases — Key Takeaways

Competition Law Update: SAMR Issues New Guidance on IP-Related Antitrust Cases — Key Takeaways On December 15, 2024, China's State Administration for

Competition Law Update: China and ASEAN Sign Cross-Border Competition Enforcement Agreement — Key Takeaways

China and ASEAN Sign Landmark Cross-Border Competition Enforcement Agreement — What Foreign Companies Must Know On March 18, 2025, China's State Admin

How long does a CAC security assessment for data export take in China?

How long does a CAC security assessment for data export take in China? A standard CAC security assessment for cross-border data transfer takes between