HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Corporate Counsel

Where data, confidentiality and IP clauses in cross-border contracts stands now

Data, confidentiality and IP clauses in cross-border contracts. The current cross-border position and what it means in practice. Write to info@lockhartyip.com.

A cross-border contract that looks clean in the signing room can unravel in the day-two operating environment. The governing-law clause fixes the substantive rules. The forum clause fixes the battlefield. But neither clause tells the parties which data-protection regime applies to the flow of personal data between their entities, which legal system will determine whether a confidentiality breach is actionable, or which jurisdiction's rules will govern ownership of IP generated under the agreement. Those questions surface months or years after execution – and they surface under pressure.

Data, confidentiality and IP clauses in cross-border contracts are governed by the law chosen by the parties for the agreement, subject to mandatory overrides imposed by the legal systems in which performance actually takes place. In the Hong Kong hub structure, the governing-law clause and the forum clause together define the baseline – but the Mainland's data-protection and technology rules, the BVI's common-law framework, and the regulatory regimes of the ultimate operating jurisdiction each apply independently, regardless of what the contract says. The interaction of those layers is where the exposure sits.

This analysis covers four questions: what is commercially at stake when these clauses are poorly drafted; how the cross-border interface bites across the Hong Kong–Mainland corridor and outward to the principal offshore centres; what a comparative read of the key legal systems reveals; and where the risk sits now for groups with cross-border exposure.

What is actually at stake: the commercial read before the legal one

The first failure mode is not legal. It is commercial. A confidentiality clause that does not define the scope of protected information with precision leaves a departing counterparty free to argue that the information was already known, already public, or not "confidential" within the ordinary meaning of that word. In practice, the clause is often drafted as boilerplate. The negotiating attention goes to the price, the representations, and the indemnity – not to the definition of confidential information, the carve-outs, or the survival period.

The second failure mode is jurisdictional. A group that has negotiated an agreement under Hong Kong law, with HKIAC arbitration as the dispute-resolution clause, may discover that the IP created under the agreement sits in a Mainland entity, that the data generated by performance flows through a Singapore-based cloud infrastructure, and that the counterparty's obligations are owed by a BVI vehicle with no material assets. The governing-law clause governs the contract. It does not govern the IP ownership question in the jurisdiction where the IP registry sits, the data-transfer question in the jurisdiction where the processing occurs, or the enforcement question in the jurisdiction where the assets are located.

What does that mean in practice? It means that a well-drafted contract clause is a necessary condition, not a sufficient one. The clause defines the starting point for a legal analysis. The cross-border operating reality determines whether that starting point gets you where you need to be.

In our cross-border practice, we regularly advise groups that have discovered this gap after a dispute has already begun. The pattern is consistent: the contract was drafted competently under one system; performance engaged two or three more; and the clause that looked adequate under the governing law provides limited traction in the jurisdiction where enforcement is actually needed.

How does the governing-law clause interact with the cross-border interface?

The governing-law clause operates as a choice-of-law rule within the limits that private international law sets. For a contract governed by Hong Kong law, that means the clause will be given effect by a Hong Kong court or tribunal for matters of contract formation, interpretation, and breach – subject to the forum's mandatory rules. It does not pre-empt the mandatory rules of another jurisdiction, and it does not resolve questions that are characterised as proprietary (such as IP ownership), regulatory (such as data-localisation requirements), or public-law (such as export-control obligations).

The distinction matters because the cross-border contracts our desk most commonly sees – technology licences, joint-development agreements, supply arrangements, and co-operation agreements involving a Mainland operating entity – regularly engage all three categories simultaneously. The contractual framework is chosen by the parties. The proprietary framework is imposed by the IP registry. The regulatory framework is imposed by the relevant authority without reference to what the contract says.

Consider the governing-law clause in a technology licence between a Hong Kong licensor and a Mainland licensee. The clause selects Hong Kong law. It will govern the interpretation of the licence grant, the scope of permitted use, and the consequences of breach. It will not govern whether the Mainland licensee was required under Mainland law to register the licence with the relevant authority, whether the unregistered licence is enforceable against third parties in the Mainland, or whether the cross-border royalty payment triggers withholding-tax or foreign-exchange-control obligations.

The forum clause raises a parallel set of questions. An HKIAC arbitration clause gives the parties a well-tested, common-law-compatible neutral forum. The Arbitration Ordinance (Cap. 609), modelled on the UNCITRAL Model Law, provides the statutory framework. The HKIAC Administered Arbitration Rules – the 2024 Rules, effective 1 June 2024 – govern the procedure. But an award on a confidentiality breach or an IP-ownership dispute will need to be enforced where the assets or the infringing activity sit. For Mainland enforcement, the relevant mechanism is the 1999 Arrangement and the 2020 Supplemental Arrangement between the Mainland and the HKSAR, not the New York Convention. That sequence has its own procedural steps, and the simultaneous-application mechanism available since the 2021 amendment to the Supplemental Arrangement adds a tool that was not available before.

The sequence of the governing-law clause, the forum clause, and the enforcement route is a chain. Each link is tested independently.

The data-protection layer: where the mandatory overrides live

Data-protection obligations are not contractual. They are regulatory. A cross-border contract that transfers personal data from a Hong Kong entity to a Mainland counterparty – or that shares personal data with a technology vendor in a third country – engages data-protection rules that apply regardless of the governing-law clause. No choice-of-law provision can disapply those rules.

In Hong Kong, the Personal Data (Privacy) Ordinance (the principal data-protection statute, administered by the Privacy Commissioner for Personal Data) sets conditions on the transfer of personal data to a place outside Hong Kong. The relevant condition requires either that the destination provides comparable protection or that the data subject consents or one of the enumerated exceptions applies. The cross-border data-transfer clause in a commercial contract is the document that records the parties' compliance position. If it is absent or inadequate, the transferring party holds the regulatory exposure.

From the Mainland side, the Personal Information Protection Law (PIPL – the Mainland's primary data-protection statute, which came into force in November 2021) imposes its own cross-border data-transfer conditions: a security assessment administered by the Cyberspace Administration, a standard contractual clause mechanism, or certification by a recognised body. Which pathway is available depends on the volume and category of personal information, the nature of the operator, and the technical infrastructure used. These conditions are regulatory obligations of the Mainland entity. A Hong Kong contract clause that purports to allocate data-protection responsibility to the Mainland party does not change the regulatory status of either entity.

The practical consequence is a two-layer drafting requirement. The contract clause defines the parties' obligations to each other: notification, assistance with regulatory filings, allocation of regulatory risk, and termination rights if the data-protection conditions cannot be met. The compliance infrastructure sits alongside the contract: the data-transfer mechanism, the security assessment or standard contract, and the internal records. Our desk sees agreements that have the contractual layer but not the compliance infrastructure, and agreements that have the compliance infrastructure but a contractual layer that contradicts it. Both create exposure.

For groups also engaging Singapore, the Personal Data Protection Act regime, or UAE, the Abu Dhabi Global Market or Dubai International Financial Centre data-protection regimes, the same two-layer logic applies. The contract clause and the regulatory compliance position must be aligned, and they must be reviewed separately.

The sequence above describes the standard position. Your matter turns on the documents, the jurisdictions actually engaged, and the order of steps – which is where the route is won or lost. For a preliminary read on your cross-border data clause position, email info@lockhartyip.com.

Confidentiality clauses across Hong Kong and the Mainland: the comparative read

Confidentiality in Hong Kong is a common-law concept, supplemented by equity and by statute in specific contexts. A well-drafted confidentiality clause in a Hong Kong-law agreement will be enforceable through interim injunctive relief in the Court of First Instance and through a damages claim for breach of confidence. The common-law doctrine of breach of confidence also provides a residual protection independent of contract – relevant where a confidentiality agreement is absent or where the scope of the contractual obligation is disputed. The practical enforcement tool is the interim injunction, and the speed with which the Court of First Instance can grant interim relief is one of the features that makes Hong Kong a credible choice of forum for IP and confidentiality disputes.

On the Mainland, confidentiality protection in commercial contracts operates primarily through contract law and through the Anti-Unfair Competition Law (the principal statute protecting trade secrets – shangye mimi – under Mainland law). The standard of protection has been substantially strengthened by legislative reform over the last several years. The threshold for what qualifies as a protectable trade secret, the available remedies, and the evidence standards for proving misappropriation have all shifted. This matters for cross-border agreements because the applicable standard for a claim brought in a Mainland people's court will be determined by Mainland law, not by the governing-law clause of the contract.

The asymmetry is commercially significant. A group that has invested in building a confidentiality clause suitable for Hong Kong-law enforcement may find that the practical enforcement route is a Mainland court action – because the counterparty, the evidence, and the infringing activity are all Mainland-side. In that proceeding, the Mainland statutory standard applies, and the well-drafted Hong Kong-law clause is relevant evidence of the parties' intent but not the governing standard.

What follows from this? The drafting approach for a cross-border confidentiality clause in a Hong Kong–Mainland agreement needs to be designed to operate across both systems. The definition of protected information, the carve-outs, the obligation to maintain security measures, and the remedial provisions should all be reviewed against both the Hong Kong-law enforcement scenario and the Mainland-law enforcement scenario. The clause that satisfies one system may leave gaps under the other.

IP ownership and licensing across jurisdictions: the proprietary layer

IP ownership questions are characterised as proprietary, not contractual, by most conflict-of-laws systems. That means the governing-law clause determines the interpretation of the agreement between the parties about IP ownership – it does not determine what the IP registry recognises, what third parties are bound by, or what remedies a court in the IP-situs jurisdiction will provide.

In a joint-development agreement between a Hong Kong entity and a Mainland counterparty, the contractual clause may say that all IP vests in the Hong Kong party. Under the governing law, that clause is valid and enforceable between the parties. Under Mainland law, the position for inventions developed by an employee or by a joint-venture entity applying for a patent registration in China is governed by the Mainland's patent law and its implementing regulations – which contain their own rules about ownership of inventions made in the course of employment and joint development. The contractual clause does not pre-empt those rules.

A micro-scenario illustrates the practical problem. A European technology group entered a joint-development arrangement with a Mainland research partner in spring 2024. The agreement was governed by Hong Kong law, with IP ownership vesting in the European party. The research team was Mainland-based. When the relationship broke down, the European party discovered that its contractual IP ownership clause was effective between the contracting parties but that the Mainland employees had made an independent patent application in China under their own names, consistent with the Mainland rules applicable to their employment. The European party had a contract claim. It did not, at that stage, have a clear patent-registration position. Resolving that required an application in China under the relevant Mainland procedures – a step that the Hong Kong-law contract clause did not anticipate and did not address.

The licensing side raises a parallel issue. An IP licence from a Hong Kong licensor to a Mainland licensee transfers contractual rights. Whether that licence is enforceable against a third party in the Mainland – for example, an assignee of the Mainland licensee – depends on whether the licence was registered with the relevant Mainland authority. Registration is a step that the contract clause needs to require and that the compliance infrastructure needs to track. A clause that says the licensee shall register the licence, without a mechanism for verifying that registration has occurred, provides incomplete protection.

For groups with BVI or Cayman holding entities above the operating layer, the IP ownership question also involves the interplay between the offshore entity's common-law framework and the operating jurisdiction's IP registry rules. The offshore entity can own contractual rights to IP. Registering and enforcing IP rights in the Mainland requires a presence in the Mainland system, typically through assignment or registration of a Mainland-facing licence. The holding structure and the IP strategy need to be designed together.

If an earlier filing, structure or enforcement attempt produced an adverse or stalled result, a second read can identify the strategic error and the routes still open. To discuss the IP ownership position in your cross-border agreement, contact info@lockhartyip.com.

Where the risk sits now: our analytical read

Three developments have shifted the risk profile for cross-border data, confidentiality, and IP clauses in recent years, and their combined effect is not yet fully reflected in the contract drafting we review on our desk.

First, the data-localisation and cross-border data-transfer requirements that have emerged across multiple jurisdictions – most significantly in the Mainland, but also in Singapore, the UAE, and a number of European jurisdictions under the General Data Protection Regulation regime – have created a mandatory-override layer that operates independently of the governing-law clause. The volume and category thresholds that trigger the Mainland's security-assessment requirement have practical significance for any group that processes personal information at scale across the border. A contract that was compliant at the time of signing may become non-compliant as the volume of data processed under it increases. That is not a risk that a static governing-law clause manages.

Second, the strengthening of trade-secret and confidentiality protection under Mainland law has, paradoxically, increased the complexity of cross-border enforcement rather than reduced it. A stronger Mainland regime means that the Mainland-side enforcement option is more viable than it was. It also means that the Mainland rules will be applied by Mainland courts in Mainland proceedings, independent of the parties' choice of Hong Kong law. Groups that have relied on a single governing-law strategy for their cross-border confidentiality position need to reassess whether that strategy remains adequate given the expanded Mainland enforcement environment.

Third, the Mainland Judgments in Civil and Commercial Matters (Reciprocal Enforcement) Ordinance (Cap. 645), which came into force on 29 January 2024, has materially changed the enforcement corridor between Hong Kong and the Mainland. Effective Mainland judgments can now be registered with the Court of First Instance in Hong Kong, and Hong Kong judgments can be used in the Mainland, under a connection-based test that removed the old exclusive-jurisdiction requirement. For groups with cross-border data, confidentiality, or IP disputes, this means that a judgment obtained in one system is now more readily transferable to the other. The question of which forum to use for the initial proceedings – arbitration, Hong Kong court, or Mainland court – has become more nuanced, because the enforcement corridor is now broader.

A second micro-scenario illustrates the current environment. A mid-market Asian group with a Cayman holding structure and a Mainland joint-venture partner came to our desk in late 2025 following a dispute over alleged misuse of confidential technical information. The joint-venture agreement was governed by Hong Kong law with HKIAC arbitration. The alleged misuse had occurred in the Mainland. The technical information had been shared with Mainland-side employees under a confidentiality schedule attached to the agreement. The immediate question was whether to pursue the HKIAC arbitration or to apply for interim relief in the Mainland courts pending that arbitration – a mechanism available under the interim-measures Arrangement in effect since 1 October 2019. The answer depended on the nature of the relief needed, the location of the assets and the infringing activity, and the timeline. The governing-law clause was the starting point. The enforcement architecture was the operative question.

Common drafting failures and what foreign counsel get wrong

Foreign counsel – including well-resourced transactional teams from European and US practices – routinely make a specific set of errors when drafting cross-border data, confidentiality, and IP clauses for agreements with a Hong Kong or Mainland nexus. These are worth naming directly, because they recur on our desk with sufficient frequency to constitute a pattern.

The first error is treating the governing-law clause as a comprehensive solution. It is not. It governs the contract. It does not govern the regulatory obligations, the IP registry position, or the enforcement route in a third jurisdiction. Counsel who have drafted excellent agreements under New York or English law sometimes carry the assumption that a well-chosen governing law resolves all the downstream questions. In a Hong Kong–Mainland cross-border context, it does not.

The second error is importing a GDPR-compliant data-transfer clause without adapting it for the Mainland's PIPL regime or for Hong Kong's Personal Data (Privacy) Ordinance. The three regimes share conceptual similarities – consent, purpose limitation, data-subject rights – but their compliance mechanisms are materially different, and the standard contractual clause approved under GDPR does not satisfy the Mainland's standard-contract mechanism or the security-assessment pathway. An agreement that recites GDPR-compliant language for its data-transfer provisions may be non-compliant with both the Hong Kong and the Mainland requirements.

The third error is drafting IP ownership and assignment provisions without addressing the registration requirement in the operating jurisdiction. As noted above, a contractual assignment of IP rights between the parties is valid between them. It does not automatically update the relevant IP registry. The contract needs to require the registration step, and the parties' compliance with that step needs to be tracked.

The fourth error – less common but consequential – is failing to account for the choice-of-forum asymmetry in the confidentiality context. If the counterparty is a Mainland entity, the practical ability to obtain an interim injunction in the Court of First Instance in Hong Kong depends on the court's jurisdiction over the defendant. If the Mainland entity has no assets and no presence in Hong Kong, the interim injunction may be unenforceable as against that entity absent the Mainland interim-measures mechanism. That mechanism requires a Hong Kong-seated arbitration – which is why the forum clause and the governing-law clause need to be drafted together with the enforcement architecture in mind.

Our desk sees these errors in agreements reviewed both before and after signing. Pre-signing review costs a fraction of the enforcement or remediation effort that follows if the errors are not caught.

Decision matrix: governing law, forum, and the cross-border position

The choice of governing law and forum for a cross-border agreement involving data, confidentiality, or IP has no universal answer. The right combination depends on the nature of the agreement, the location of the parties and their assets, the regulatory regimes engaged by performance, and the enforcement scenario the parties are actually trying to optimise for. The following matrix in prose form sets out the principal scenarios we see and the analysis that follows from each.

Where both parties are Hong Kong entities and performance is Hong Kong-centred, Hong Kong law with Hong Kong court jurisdiction (or HKIAC arbitration) is the natural choice. The Court of First Instance provides common-law remedies, interim injunctive relief, and a well-tested confidentiality and IP jurisdiction. The HKIAC arbitration option adds confidentiality of the proceeding itself – relevant for commercial disputes involving proprietary information.

Where one party is a Mainland entity and performance involves Mainland operations, Hong Kong law with HKIAC arbitration allows the parties to maintain a common-law governing framework while accessing the interim-measures mechanism under the 2019 Arrangement for Mainland interim relief. The enforcement route for a resulting award uses the 1999 and 2020 Supplemental Arrangements. This is a well-tested combination for cross-border technology and confidentiality disputes with a Mainland operating dimension.

Where a BVI or Cayman holding entity is the contracting party but performance is Mainland-side, the holding entity's common-law framework provides the contractual layer, but the Mainland regulatory and IP-registry obligations attach to the Mainland operating entity regardless. The holding-entity contract governs the relationship between the holding entity and the Mainland counterparty. It does not substitute for the Mainland-level compliance steps.

Where the agreement involves multiple jurisdictions – for example, a technology licence with a Hong Kong licensor, a Mainland licensee, and a Singapore-based data-processing sub-contractor – a single governing-law clause will not cover the full regulatory picture. Each regulatory layer needs to be identified, the relevant compliance mechanism for that layer needs to be implemented, and the contract needs to allocate responsibility for maintaining compliance with each layer over the term of the agreement.

Situation: IP-heavy joint development, Mainland-based research team, Hong Kong governing law. Route: HKIAC arbitration with Mainland interim-measures access; IP registration obligation on the Mainland licensee; compliance audit right on the licensor side. Timing: at signing and at each major IP-delivery milestone. Risk: employee-invention claims and unregistered-licence third-party enforceability.

Situation: data-sharing agreement, personal information crossing the Hong Kong–Mainland border at scale. Route: data-transfer impact assessment before execution; security-assessment pathway or standard-contract mechanism as required by the Mainland regime; contractual assistance obligations and termination rights. Timing: before first data transfer. Risk: volume threshold breach triggering security-assessment requirement mid-contract.

Self-assessment: does your cross-border contract hold?

Before committing to a cross-border agreement involving data, confidentiality, or IP, principals and general counsel should be able to answer the following questions with specificity, not with a reference to the governing-law clause.

Does the confidentiality clause define protected information by category, by format, or by marking requirement? Is the definition adequate for the type of information that will actually be shared under this agreement? Does it survive termination for a period that reflects the commercial sensitivity of the information?

Does the data-transfer clause identify the regulatory regime applicable in each jurisdiction where personal data will be processed? Does it assign responsibility for completing the applicable compliance mechanism – security assessment, standard contract, or certification – to the party that bears the regulatory obligation? Does it give the other party audit rights and termination rights if the compliance position is lost?

Does the IP clause address ownership of background IP, foreground IP (IP created under the agreement), and improvement IP separately? Does it require registration of assigned or licensed rights in each relevant IP registry? Does it address the employee-invention rules in each jurisdiction where development will occur?

Does the forum clause create a route to interim relief that is practically available against the counterparty – given where the counterparty's assets and activities are located? If the forum clause designates HKIAC arbitration, does the agreement address the interim-measures mechanism for Mainland-side activity?

If the answer to any of these questions is "I am not sure", the drafting review is the appropriate next step – before the agreement is signed, not after performance has begun.

Related practices

  • Corporate Counsel – cross-border contract structuring, governance and operational legal support
  • Disputes & Arbitration – Hong Kong and cross-border enforcement, HKIAC arbitration, interim measures
  • Holding Structures – BVI, Cayman and Hong Kong holding entity design and IP ownership architecture

Frequently asked questions

What is the first step in reviewing data, confidentiality and IP clauses in a cross-border contract?
The first step is a jurisdictional mapping exercise: identify every legal system engaged by performance of the agreement, not just the governing law chosen by the parties. That means identifying where personal data will be processed, where IP will be created or registered, where the counterparty's assets sit, and which regulatory regimes apply in each location. The governing-law clause is the starting point for that analysis, not the conclusion. The mapping exercise determines which compliance mechanisms need to be implemented alongside the contractual provisions and which enforcement routes are practically available if a dispute arises.
Do I need a Hong Kong adviser for data, confidentiality and IP clauses in cross-border contracts?
For agreements with a Hong Kong–Mainland cross-border dimension, an adviser with cross-border experience across both systems adds material value at the drafting stage. The governing-law and forum clauses, the data-transfer compliance mechanisms, and the IP registration requirements in the Mainland each involve a cross-border interface that is not well-managed by counsel familiar with only one system. Hong Kong serves as the neutral hub for many of these arrangements, and the HKIAC arbitration mechanism with Mainland interim-measures access is a tool that requires Hong Kong-seated expertise to deploy effectively. We work alongside locally licensed firms on matters requiring Hong Kong-law advice.
How long does reviewing and restructuring data, confidentiality and IP clauses in cross-border contracts usually take?
For a pre-signing review of an existing draft, the analysis of the clause architecture across the relevant jurisdictions can typically be completed within a few weeks, depending on the complexity of the agreement and the number of jurisdictions engaged. Implementing the compliance infrastructure alongside the contractual provisions – completing a Mainland data-transfer assessment, registering a licence, or documenting an IP assignment – takes longer and depends on the relevant regulatory or registry timelines in each jurisdiction. Parties should verify the current position before relying on any specific timeline, as regulatory processes and registry procedures can change.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy