China has rewritten the rules concerning trade secret protection for the first time since 1995. The new rules took effect on 1 June 2026. This article explains what has changed, what companies should do now, and how to choose between the administrative, civil, and criminal routes if a secret is stolen.


On 24 February 2026, the State Administration for Market Regulation (SAMR) issued the Provisions on the Protection of Trade Secrets (Order No. 126). They took effect on 1 June 2026 and replace the 12-article rules of 1995 with 31 articles. The old rules were written for paper drawings and printed customer lists; the new ones cover data, algorithms, remote working, and cross-border teams. They also bring regulators into line with the Anti-Unfair Competition Law (AUCL), which was amended in 2025 and has applied since 15 October 2025.

Why does this matter? Until now, few companies took trade secret cases to market regulators. SAMR’s own figures show that of 11,036 unfair competition cases handled in 2024, only 120 involved trade secrets. Fines were low and regulators had few powers. That has changed. The new rules also spell out what a company must already have done to own a trade secret at all.

IP Business Support

Need help protecting your trademark in China? Our experts can support registration, enforcement, and risk management.
Schedule a Free Consultation

What changed on 1 June 2026

What counts as a trade secret

The basic test is unchanged. To qualify for protection, a trade secret must not be publicly known, must possess commercial value, and must be protected by reasonable confidentiality measures.

The rules now clarify what qualifies as a trade secret. On the technical side, protected trade secrets may include data, algorithms, software, and source code. On the business side, they may encompass management methods, pricing information, financial data, and customer information, including customers’ purchasing habits and intentions, not merely their contact details.

Results from failed experiments and unfinished R&D also count if they have value, for example by saving a competitor time and money. The old test of “practical applicability” has been replaced by “commercial value”, a lower bar.

Confidentiality measures

Article 9 sets out eight types of measures that regulators will recognize as adequate protection. These include NDAs and confidentiality clauses; internal policies, training, and confidentiality notices; restricted-access areas; tiered access controls, data masking, and activity logs for remote and cross-border work; file labelling, classification, and encryption; restrictions on device access; and exit procedures requiring departing employees to return or delete confidential information and confirm their ongoing confidentiality obligations.

What counts as theft

The rules now provide a clearer definition of hacking. Unauthorized access to a company’s servers, email systems, cloud platforms, or internal networks, as well as access that exceeds authorized permissions, can constitute trade secret theft.

The rules also treat the unauthorized downloading or transfer of trade secrets to a personal email account, personal cloud storage, or a USB drive as misappropriation, even if the information has not yet been used. In addition, third parties that knew, or reasonably should have known, that the information was obtained unlawfully may also be held liable.

Proving the case

If you can show that the other side had access to your secret and is using something substantially the same, the burden shifts. The other side must prove they obtained it lawfully. This mirrors the civil rule in the AUCL.

Penalties and powers

Fines rise from RMB 10,000 (US$1,488) to 200,000 (US$29,760) under the old rules to RMB 100,000 (US$14,880) to 1 million (US$148,801), and to RMB 1 million (US$148,801) to 5 million (US$744,009) in serious cases, with illegal gains confiscated.

Regulators can seize materials and check bank accounts. An order to stop using a secret lasts as long as the information stays secret. Cases now go to city-level regulators rather than county offices, and the rules reach conduct outside China that harms competition inside it.

What is not theft

Developing something independently, reverse engineering a product bought on the open market, a former employee using general skills and experience, and reporting wrongdoing to the authorities are all expressly allowed.

Conduct a trade secret audit now

The new rules make one point clear. A company can only claim trade secret protection if it can show that it took reasonable steps to protect the information. In practice, Article 9 provides regulators with a checklist of the measures they will look for when assessing whether information qualifies as a trade secret. Companies should review five areas in particular.

Know what you have

Identify the information that matters most, whether datasets, source code, formulas, pricing models, customer intelligence, or unsuccessful R&D projects. Record who has access to each category of information and why. Information that has not been identified and classified is much harder to protect.

Documentation

Review confidentiality clauses in employment, supplier, distributor, and other commercial contracts. Use NDAs where appropriate, maintain internal policies on information handling, device use, and remote work, and keep records of employee training and acknowledgements.

Business Advisory Services

We provide tailored advisory on the optimal business structure that aligns with your business goals.
Speak with an Advisor

Technical controls

Assess whether access is restricted on a need-to-know basis. Regulators will look for measures such as role-based permissions, data masking, activity logging, encryption, and controls on USB devices, personal cloud storage, and personal email accounts.

Employee onboarding and offboarding

The new rules place particular emphasis on controlling access throughout the employee lifecycle. Departing employees should return or delete confidential information, document what has been returned, and acknowledge their continuing confidentiality obligations in writing.

This is also where trade secret law intersects with employment law. Under the Supreme People’s Court’s Judicial Interpretation II, a non-compete is generally enforceable only against employees who had access to trade secrets, and only to the extent of that access. The same records that support a non-compete can also help demonstrate that confidential information was properly protected.

Manage hiring risks

The rules cut both ways. Foreign-invested companies can rely on them to protect their own trade secrets, but they can also face scrutiny after recruiting employees from competitors. Companies should therefore ask new hires to confirm in writing that they have not retained or transferred confidential materials belonging to a former employer and should avoid requesting such information during recruitment.

This version ties every item back to the new regulation and removes the feeling that the audit section has been dropped in from a generic compliance checklist. It also flows naturally from the preceding discussion of Article 9.

Choosing the enforcement route

Route

What you get

What you do not get

Best for

Administrative (market regulator) Quick investigation, seizure of evidence, stop orders, and fines; the burden of proof shifts in your favour No compensation; fines go to the state Stopping misuse fast; gathering evidence for a later court case
Civil (people’s courts) Compensation based on your loss or their profit; up to RMB 5 million (US$744,009) where loss is hard to prove; up to five times that amount for deliberate, serious theft; injunctions Slower; you still need strong technical evidence Recovering money; disputes with business partners
Criminal (police and prosecutors) Prison sentences of up to 10 years; the strongest deterrent You lose control of the case; needs losses or gains of at least RMB 300,000 (US$44,640) Deliberate theft by employees or organised competitors

These routes can be combined. A common approach is to file with the regulator first to stop the conduct and secure evidence, then sue for damages. Regulators must pass on cases that reach the criminal threshold. The choice turns on what you need most: speed, money, or deterrence.

How Dezan Shira & Associates can help

The new rules reward companies that can show how they protected what they want to enforce. That takes IP and HR expertise working together.

Dezan Shira & Associates’ IP advisory team helps foreign investors identify and classify trade secrets, build confidentiality frameworks that match the Article 9 list, and weigh the administrative, civil, and criminal options when theft is suspected, including the evidence a regulator will expect.

Our HR and labour advisory team covers the employment side: confidentiality and non-compete clauses that match actual access under Judicial Interpretation II, handbook rules on classification and devices, and joiner and leaver procedures that produce the records the new rules recognise.

To review your trade secret protection or discuss a suspected infringement, please contact our local team.