For many years, the common belief about protecting trade secrets—both in China and internationally—was straightforward: if an employee copies confidential information but neither shares it with a competitor nor uses it, at worst they have broken company rules but not committed a legal offense. The logic was that without sharing, no information leaks; without use, no competitive harm occurs; and without harm, the law has no grounds to act. As a result, many employers who found that a departing engineer had copied source code onto a personal device often dismissed it, retrieved the device, and moved on. Likewise, many employees thought that as long as the copied files stayed on their private drives, they were operating in a legal gray area at most.
That intuitive approach has now officially ended. In 2024, China’s Supreme People’s Court Intellectual Property Tribunal issued a landmark appellate ruling (case number (2023) Zui Gao Fa Zhi Min Zhong No. 539) establishing that unauthorized acquisition of trade secrets—even if there is no disclosure or use—constitutes infringement under Article 9 of the Anti-Unfair Competition Law. Then, in 2025, the Tianjin Third Intermediate People’s Court applied the same principle to a case involving remote electronic intrusion, reinforcing that infringement now occurs at the moment of acquisition, not only upon disclosure or use.
For foreign companies operating R&D centers, engineering teams, or technology businesses in China, these rulings represent a fundamental shift in the legal landscape. They serve both as a warning and an opportunity: a warning that theft of your source code, technical drawings, and proprietary algorithms can now be stopped and remedied much earlier than before; and an opportunity to develop enforcement strategies that were previously considered legally unfeasible. This article analyzes both judgments in detail, explains the legal reasoning behind them, explores the limits the courts have set, and advises how foreign companies should respond in terms of compliance and litigation.
The Game Company Case: Gradual Copying, Altered Logs, and a Complete Reversal on Appeal
The facts of the Supreme People’s Court case are important because they reflect a scenario common to foreign tech companies. Cao was head of technical middle-platform operations at a Chinese gaming company, with legitimate access to the source code of core game projects. In the month before leaving, Cao copied the source code in stages onto his personal Apple computer and took it home.
When the company found out, it sued Cao, a colleague named Wang who allegedly encouraged the copying, and a new competing company Wang had founded. The company claimed Cao stole its trade secrets, Wang orchestrated the scheme, and the new company was set to receive the stolen technology.
At first, the court rejected all claims. It reasoned that Cao had authorized access to the source code, there was no evidence of theft, hacking, or other improper means, and no proof that Cao disclosed or provided the code to Wang. Under the traditional interpretation requiring proof of disclosure or use, the claim failed. The company left empty-handed.
The Supreme People’s Court, however, took a very different view. It emphasized that having authorized access does not mean the method of acquisition was lawful. An employee allowed to work with source code on company systems is not authorized to copy it onto personal devices and remove it. Cao knowingly violated confidentiality obligations by gradually copying the code over time, transferring it to a private computer, and taking it out of the office. He also altered login records and deleted operation logs, which the court saw as strong evidence of awareness of wrongdoing.
The court’s key ruling was that Cao’s actions, by their nature and circumstances, could transfer the source code to a competitor. Even without proof of use or disclosure, the copying caused—or could cause—the company to lose effective control over its trade secrets. This loss of control is exactly what the law forbids. Article 9 of the Anti-Unfair Competition Law prohibits acquiring trade secrets by theft, bribery, fraud, coercion, electronic intrusion, or other improper means. The law does not require proof of use, disclosure, or damages. The first court erred by equating authorized access with lawful acquisition and by adding a requirement of disclosure or use that the statute does not include.
As a result, Cao, Wang, and the competing company were ordered to stop the infringement immediately and held jointly liable for economic losses and enforcement costs totaling RMB 900,000. Although less than the RMB 4.28 million sought, the monetary amount is less important than the fact that China’s highest IP court has redefined unlawful acquisition to begin at unauthorized copying, not at leakage.
The Tianjin Robot Case: Remote Intrusion at 3 A.M. and Liability Without Harm
While the Supreme Court case involved physical removal of source code, the Tianjin case shows how the same principles apply to remote work, now common since the pandemic, and how courts consider cases where the infringer is an individual whose career might be saved.
In May 2025, the Tianjin Third Intermediate People’s Court ruled on a case involving Xiao, a mechanical design engineer at an industrial robotics company. Before leaving, in the early morning hours, Xiao remotely accessed a company computer and downloaded over 100 technical documents he was not authorized to view. The company reported the intrusion to police and sued for RMB 1 million in damages. Xiao’s defense was that he did not share the files and had deleted them.
The court was clear: remotely accessing a company computer without authorization and downloading documents without permission constitutes acquisition of trade secrets by electronic intrusion, which Article 9 prohibits. Lack of disclosure or use does not excuse the violation. The acquisition itself is infringement.
However, the court also considered mitigating factors: Xiao acted out of poor judgment, caused no significant harm, and the company was preparing for an IPO and did not want to ruin a young engineer’s career. Through court mediation, Xiao apologized, permanently deleted the files, and the company dropped most of its damages claim. While not a strict precedent, the court’s legal characterization aligns with the Supreme Court’s ruling, showing that the doctrine applies fully to electronic intrusion but courts retain flexibility in remedies once liability is established.
The Doctrinal Shift: From “Disclosure Plus Use” to “Acquisition Alone”
Together, these cases mark a judicial shift foreign companies must understand. Previously, trade secret liability was triggered by downstream effects: the secret had to be disclosed or used in a competing product before legal action. This created a difficult evidentiary burden. An employee who copied your entire codebase before joining a competitor was untouchable unless you could prove the code appeared in the competitor’s product—a standard often impossible to meet, especially for software.
Article 9 of the Anti-Unfair Competition Law never required this. It prohibits acquiring trade secrets by improper means, period. The Supreme People’s Court has restored the law to its text. The rationale is that once an unauthorized copy exists outside the owner’s control, the secrecy that gives the asset value is compromised. Whether the copy is later used is a matter of degree, not kind. Protection now begins at acquisition.
For foreign companies, this shift changes enforcement in three ways. First, the evidentiary burden is much lower: you no longer need to prove what the employee did with the code after leaving, only how they took it. Logs, access records, device forensics, and data loss prevention alerts now carry full weight. Second, remedies become more accessible and urgent: injunctions, preservation orders, and early damage claims can be pursued before a competitor’s product hits the market, containing harm. Third, the deterrent effect on employees is stronger: copying before leaving is no longer a gray area but infringement that can cost them personally, including financial penalties and social credit consequences.
The Limits: What the Courts Did Not Say
It would be wrong to think that any downloading by a departing employee is now illegal. The Supreme People’s Court stressed that improper acquisition requires a full review of intent and conduct. Aggravating factors include tampering with logs, acting at others’ instigation, and preparing to join or start a competitor. If none of these exist—such as an employee downloading materials needed for ongoing work during notice, using company systems normally—the acquisition is not improper.
The Tianjin court drew a similar line: remote access without credentials in the middle of the night is electronic intrusion, distinct from normal remote work or legitimate downloads by authorized employees. The key distinction is whether the movement of files violated confidentiality and bypassed company controls. Employees working within granted permissions are safe; those circumventing controls, copying to personal devices, or deleting traces have crossed the line, regardless of what happens to the files later.
This approach aligns broadly with other advanced jurisdictions like the U.S., where unauthorized taking can violate trade secret laws even without proven use. But foreign companies should not assume the analysis is identical. Chinese courts emphasize clear confidentiality agreements, company control measures, and consequences tied to bad-faith conduct in IP matters. Local legal advice is essential.
What Foreign Companies Should Do Now
These rulings invite companies to review their compliance systems. Courts favor companies with clear rules and technical safeguards and penalize those without. Key steps include:
- Update confidentiality agreements and employee handbooks to explicitly prohibit removing confidential information or transferring it to non-company devices without permission; define large-scale downloading before departure as breach and infringement; and require mandatory data audits upon resignation. Clear contractual rules strengthen litigation positions and remove employee ambiguity.
- Enhance technical controls: deploy or upgrade data loss prevention systems to monitor and block downloads, external transmissions, and printing of sensitive files in real time; implement tiered access so no single employee can easily copy entire codebases; and establish departure protocols that immediately restrict access upon resignation and audit data activity over a defined period. Early alerts can detect staged copying like in the Supreme Court case.
- Prepare evidence preservation plans: when suspicious downloads or intrusions occur, promptly preserve logs, network records, device inventories, and access histories through notarization or timestamping. For remote work, require company devices with activity logging to distinguish legitimate from unauthorized downloads. Courts rely on detailed, contemporaneous records, which are easier to create proactively than reconstruct later.
Enforcement Strategy When It Has Already Happened
For foreign companies discovering that a departing or former employee copied source code or technical documents, the new legal reality changes strategy. Previously, litigation was premature without proof of use; now, the key question is whether you can prove how the information was taken.
Effective response involves quickly preserving digital evidence before it degrades; sending carefully crafted cease-and-desist letters based on the clarified legal standard; and, if needed, litigating with a focus on conduct such as staged copying, tampering, intrusion, and instigation identified by the Supreme People’s Court. If the employee joined or founded a competitor, the loss-of-control doctrine allows seeking injunctions and damages early, protecting assets before damage appears in products.
The reverse is also true: foreign companies are employers, and their employees in China now face personal liability—including joint liability for instigators and recipients—under a standard many do not yet understand. Companies that fail to educate staff, lack clear confidentiality documents, or cannot show effective controls may find themselves in difficult positions, pursuing claims while lacking the compliance infrastructure that would make them strong. Courts notice when a rights holder’s own house is not in order.
How We Can Help
Our practice focuses on trade secret protection and technology disputes in China for foreign companies, and these rulings have reshaped our advice and litigation approach. We assist clients throughout the process. Before issues arise, we review and update confidentiality agreements, employee handbooks, and departure protocols to reflect the conduct-based standards now enforced, and collaborate with IT and security teams to design data loss prevention, access controls, and forensic readiness plans that hold up in Chinese courts.
China’s highest court’s message is clear: unauthorized taking of trade secrets is no longer a waiting game requiring proof of use. The law now addresses wrongdoing at acquisition. Foreign companies that understand this shift, build controls accordingly, and prepare to enforce it will better protect their valuable assets in China than ever before. Those that do not will continue to find empty folders, deleted logs, and former engineers who believed copying without use was not theft—until these judgments arrived.
If your company faces suspected trade secret theft, is revising internal controls for the post-2024 standard, or wants to understand how these rulings affect its risk in China, we invite you to contact us. The window between acquisition and damage has never been more critical—and the time to act is now.