首頁 / News & Insights / International Legal Updates
Is Signing an NDA Before Cross-Border Cooperation Effective? Protecting Technical Data and Business Information Through Confidentiality Obligations
2026/7/14
In cross-border cooperation, businesses often disclose certain technical data or business information to potential partners before formally entering into licensing agreements, manufacturing contracts, investment agreements, or agency and distribution agreements. Such information may include product design drawings, specifications, test reports, source code, process parameters, quotation terms, customer lists, supplier information, cost structures, or market development plans.
Once this information is leaked, technologies may be imitated, customers may be poached, pricing strategies may be exposed, product launch schedules may be affected, and businesses may even lose their advantage in subsequent negotiations. Therefore, signing an NDA (Non-Disclosure Agreement) before cross-border cooperation is generally an important first step for businesses seeking to protect technical data and business information.
An NDA Is Useful, but Protection Cannot Be Achieved Through a Signature Alone
The practical value of an NDA lies in expressly establishing confidentiality obligations through a contract, restricting the purposes for which information may be used, regulating the personnel permitted to access the information, specifying how information must be returned or destroyed, and providing an important basis for asserting liability for breach of contract or trade secret infringement when information is leaked or improperly used.
However, businesses should note that an NDA does not mean that all information automatically becomes a trade secret once the agreement is signed. Under the current Trade Secrets Act, a trade secret must satisfy three requirements: it must not be known to persons generally involved with information of that type, it must have actual or potential economic value due to its secrecy, and its owner must have taken reasonable measures to maintain its secrecy.
Therefore, an NDA should be accompanied by actual information-control measures. If a business does not mark information as confidential, does not implement access classifications, does not prohibit forwarding information to private email accounts or personal cloud storage, and does not record the recipients to whom information is delivered, it may face evidentiary difficulties even if it subsequently alleges that the opposing party disclosed confidential information.
Key Judicial Considerations: The Scope of Confidentiality Must Be Clear, and Management Measures Must Be Implemented
Judgments concerning trade secrets compiled by the Intellectual Property Office show that courts do not consider only whether a confidentiality agreement was signed. They also examine whether the confidential information is sufficiently specific, reasonable, not generally known, and subject to confidentiality measures designed to prevent third parties from obtaining it.
| Practical Consideration | Judicial or Regulatory Observation | Considerations for Businesses |
|---|---|---|
| An NDA can protect confidential information within a defined scope | Judicial opinions have held that confidential information subject to confidentiality under an agreement does not necessarily have to be entirely identical to the definition of a "trade secret" under the Trade Secrets Act. | An NDA may be used to protect non-public information such as technical data, financial information, customer strategies, personnel and salary information, costs, and quotations. |
| The scope of confidentiality cannot be expanded without limitation | Courts have also indicated that the scope of confidentiality must remain specific and reasonable and cannot be expanded to mean that all information falls within the scope of confidentiality. | It is inadvisable to state only that "all information is confidential." Categories such as technical, commercial, financial, customer, process, sample, and drawing information should be expressly identified. |
| Reasonable confidentiality measures are essential | If a company does not expressly prohibit employees from storing confidential information through private email accounts, personal USB drives, or personal cloud storage and relies only on employee self-discipline, it may be found not to have taken reasonable confidentiality measures. | Before cross-border cooperation, businesses should establish information classification, access controls, download restrictions, watermarks, transmission records, and delivery lists. |
| Breach of contract and trade secret infringement may apply concurrently | If information satisfies the requirements for a trade secret and the opposing party obtains, uses, or discloses it in breach of a confidentiality obligation, the conduct may constitute infringement under the Trade Secrets Act. | An NDA should address both contractual liability and trade secret protection strategies rather than relying on a single legal basis. |
Information Commonly Requiring Protection in Cross-Border Cooperation
Cross-border cooperation involves different countries, languages, jurisdictions, and enforcement procedures. Once information is transmitted abroad, the subsequent costs of investigation and enforcement are generally higher. Therefore, before disclosing information, businesses should first identify which information should be protected under the NDA.
| Information Type | Common Content | Key Protection Measures |
|---|---|---|
| Technical Data | Design drawings, specifications, process parameters, formulas, test reports, source code, technical documents, and sample data. | Restrict the purposes of use, prohibit reverse engineering and unauthorized reproduction, and require the return or destruction of information. |
| Business Information | Quotations, costs, suppliers, customer lists, procurement strategies, sales plans, market deployment, and cooperation terms. | Prevent the cooperating party from using the information to contact customers, circumvent the original business relationship, or negotiate against the disclosing party. |
| Product and Sample Information | Unreleased products, prototypes, molds, industrial designs, test samples, packaging designs, and certification information. | Specify that the products or samples may not be disassembled, photographed, delivered to third parties, separately manufactured, or provided to competitors for use. |
| Cooperation and Negotiation Information | Investment terms, merger and acquisition information, licensing proposals, cooperation structures, royalty calculations, and projected orders. | Specify that the existence of negotiations, transaction terms, and undisclosed details of the proposed cooperation may not be disclosed externally. |
Core Provisions That an NDA Should Include
A cross-border NDA should not rely on an overly simplified template. Different cooperation models involve different types of confidential information, methods of disclosure, purposes of use, authorized personnel, and risks of breach. The provisions should therefore be adjusted according to the transaction circumstances.
- Definition of confidential information: Clearly identify categories such as technical information, processes, designs, samples, prices, customers, financial information, and business plans, while excluding information that is already public, was lawfully known to the receiving party, or was independently developed.
- Restrictions on the purpose of use: Specify that the information may be used only to evaluate cooperation, prepare quotations, conduct testing or development, or perform a specific contract, and may not be used for competition, employee or customer poaching, transaction circumvention, or cooperation with third parties.
- Restrictions on personnel with access: Limit access to employees, consultants, or personnel of affiliated enterprises who need to know the information for the purposes of the cooperation, and require them to assume equivalent confidentiality obligations.
- Controls on copying and transmission: Specify that the information may not be copied, downloaded, photographed, forwarded, uploaded to cloud storage, delivered to third parties, or stored on personal devices without consent.
- Return and destruction of information: When cooperation ends, negotiations fail, or the disclosing party makes a request, the receiving party must return or destroy the information and may be required to provide proof of destruction.
- Liability for breach and remedies: Remedies may include damages, liquidated damages, cessation of use, return of information, deletion of files, and prohibition of further disclosure. However, liquidated damages should remain reasonable to avoid excessive imbalance.
- Governing law and dispute resolution: Cross-border cooperation agreements should clearly specify the applicable law, court jurisdiction or arbitral institution, the effect of each language version, and methods of service.
Signing an NDA Alone Is Still Insufficient; Businesses Should Establish Management Measures Concurrently
Judicial decisions demonstrate that businesses cannot rely solely on contractual language and should implement objectively identifiable confidentiality measures. If a business claims that certain information is confidential but has not restricted who may download it, marked it as confidential, controlled the use of personal devices, or recorded the recipients to whom it was delivered, it may be difficult to prove in subsequent litigation that reasonable confidentiality measures were taken.
| Management Measure | Recommended Practice |
|---|---|
| Information Classification | Classify information as general, internal, confidential, or highly confidential, and restrict disclosure recipients according to the classification level. |
| Confidentiality Markings | Mark documents, presentations, drawings, electronic files, sample packaging, and data rooms with "Confidential" or equivalent confidentiality wording. |
| Access Controls | Establish accounts, passwords, tiered permissions, read-only access, download restrictions, watermarks, and access records. |
| Delivery Records | Record the delivery date, file name, version, recipient, purpose, transmission method, and whether the information has been returned or destroyed. |
| Device and Cloud Restrictions | Expressly prohibit the unauthorized use of private email accounts, personal USB drives, personal cloud storage, personal messaging applications, or unapproved platforms to store information. |
| Handling Upon Termination of Cooperation | Require the return or deletion of information, provision of proof of destruction, cessation of the use of samples and technical documents, and confirmation that third-party recipients have also completed the required handling. |
Special Risks of Cross-Border Cooperation
The primary difference between cross-border cooperation and domestic transactions is that once information is transferred abroad, businesses may face different legal systems, difficulties in collecting evidence, higher costs of enforcing judgments or arbitral awards, and difficulties tracing information after the cooperating party transfers it to a third party.
Under the current Trade Secrets Act, where an offender intends to use a trade secret in a foreign country, Mainland China, Hong Kong, or Macao and commits a relevant criminal offense under the Trade Secrets Act, the law provides for heavier criminal penalties. This also demonstrates that the cross-border use of trade secrets is regarded under current law as a higher-risk protection scenario.
Therefore, if a business intends to disclose core technical data to a foreign cooperating party, it should not only sign an NDA but also confirm whether the country in which the other party is located has an effective confidentiality or trade secret protection regime. The agreement should also specify the governing law, dispute-resolution method, location where information is stored, personnel authorized to access it, and remedies available following a breach.
Practical Recommendations for Cross-Border Legal Matters
AIPT Group recommends that, before undertaking cross-border technical cooperation, product development, OEM/ODM arrangements, agency and distribution arrangements, investment negotiations, or licensing transactions, businesses treat the NDA as part of their overall intellectual property and commercial risk-management framework rather than as a standalone document.
- Sign the NDA before disclosing core information: Before formally disclosing technologies, samples, quotations, customer information, or business plans, confirm that confidentiality obligations have been established.
- Disclose information in stages: Disclose only the necessary information during the initial stage, and disclose more critical information only after cooperation terms, payment, licensing scope, or development responsibilities have been confirmed.
- Preserve evidence of information delivery: Retain transmission records, download records, versions of meeting presentations, recipient information, acknowledgment records, and delivery lists.
- Avoid an excessively general confidentiality scope: Describe the types of confidential information specifically to avoid the scope subsequently being considered unclear or unreasonable.
- Review patent and trade secret strategies concurrently: If a technology is suitable for disclosure in exchange for patent rights, a patent application may be considered. If it is unsuitable for disclosure, trade secret and NDA management should be strengthened.
- Obtain consent before the cooperating party engages a subcontractor: If a foreign cooperating party intends to provide the information to a contract manufacturer, testing laboratory, consultant, or affiliated enterprise, prior written consent and equivalent confidentiality obligations should be expressly required.
Conclusion
Signing an NDA before cross-border cooperation is useful, but its effectiveness depends on whether its provisions are clear, whether the confidential information requires protection, whether the business has actually taken reasonable confidentiality measures, and whether complete evidence can be submitted if a dispute arises.
Current laws and judicial decisions demonstrate that courts will not automatically grant protection merely because a business asserts that certain information is confidential. However, if a business can demonstrate through an NDA, information classification, access controls, confidentiality markings, delivery records, and return and destruction procedures that it has genuinely managed the information as confidential, it will have a greater opportunity to assert contractual liability or trade secret protection in subsequent disputes.
For businesses preparing for overseas expansion, technical cooperation, licensing transactions, or multinational supply-chain cooperation, an NDA is not merely a formality before signing a contract but an important legal instrument for protecting technological value, business information, and negotiating advantages.
Sources: Laws & Regulations Database of the Republic of China|Trade Secrets Act
Laws & Regulations Database of the Republic of China|Civil Code
Intellectual Property Office, Ministry of Economic Affairs|Selected Compilation of Trade Secret Judgments




