China trade secrets protection act 2026: New rules, risks and corporate compliance duties
China’s State Administration for Market Supervision (SAMR) has significantly expanded the scope of trade secret protection. This protection now covers far more than before. Ecovis experts advise companies operating in China to actively adjust their compliance practices to benefit from the new regulations and protect themselves against associated risks. The new regulation entered into force on 1 June 2026.
The SAMR has expanded the scope of the regulation from 12 to 31 articles. This entails numerous new tasks for companies.
Contact Person
Broader scope of the trade secrets protection act
“Practical applicability” is replaced by “commercial value”, focusing on the information’s actual or potential worth rather than proven profit. Failed experiments, unfinished research, or draft test plans can now qualify as trade secrets even without a finished product if they cut future costs or preserve competitive advantage. The protectable categories are also expanded and include:
- algorithms
- source code
- customer records
- operational data
- financials
- sales strategy
The standard for confidentiality is now significantly clearer
Information only loses protection if it is common industry knowledge or easily found by professionals. Even if individual data points exist publicly, a compilation requiring real time, cost, or expertise to assemble can still qualify – distinguishing trade secrets from patent novelty rules and better fitting data-driven assets.
We support companies in China in aligning their compliance practices with current regulations.
Richard Hoffmann, Lawyer, ECOVIS Rechtsanwaltskanzlei Richard Hoffmann, Ladenburg, Germany
Concrete confidentiality checklist
For the first time, the regulation lists typical safeguards:
- confidentiality agreements
- internal policies and training
- restricted access
- remote-work safeguards
- document encryption and classification
- limits on copying/downloading
- offboarding procedures
The points on the checklist will also serve as evidence in future legal disputes.
Digital era infringement
Sending trade secrets to a personal email, cloud, or device without authorisation is now explicit improper acquisition – even before resignation. Unauthorised access to company systems to obtain trade secrets is also expressly infringement.
Recommendations for action for companies
With protection broader but enforcement more digitally focused, companies should audit their trade-secret assets, tighten NDAs and employment contracts, document how information is created and protected, and fold trade secret protection into their wider compliance strategy alongside data security and cybersecurity.