Data, confidentiality and IP clauses in cross-border contracts
Data, confidentiality and IP clauses in cross-border contracts. How Lockhart & Yip advises foreign principals on the route. Write to info@lockhartyip.com.
Cross-border contracts that touch data, trade secrets or intellectual property require governing-law and forum clauses drafted for the day-two reality, not the signing day. In our cross-border practice, we regularly advise international groups, founders and in-house legal teams on how to structure these clauses so that a breach in one jurisdiction can actually be remedied in another. The governing instrument is the contract itself, read against the law selected to govern it – and Hong Kong's common-law system makes it a reliable choice of law and forum for disputes with counterparties across Greater China and the principal offshore centres.
This page describes the service we run, the sequence of steps, and the decisions that the foreign principal must own at each stage.
When does a foreign principal need this, and what triggers the urgency?
The trigger is almost always a deal in motion. A technology-transfer agreement is about to execute. A joint-venture term sheet has been agreed. A distribution or manufacturing contract is being finalised with a Mainland Chinese counterparty, and the foreign principal's counsel at home has flagged that the confidentiality provisions "look thin" – or, more dangerously, has not flagged it at all.
The window closes at signature. Once a contract is executed, the governing-law clause is set, and the forum for any IP or data dispute is determined. Renegotiating those provisions after a relationship sours is rarely possible. By that point, the question is not which law should apply – it is whether the law that does apply allows any useful remedy at all.
In our cross-border practice, we see three recurring scenarios. First, a manufacturing or supply contract where the foreign principal is sharing technical specifications, process data or product formulas with a Mainland counterparty, and the confidentiality carve-outs are drawn by reference to the counterparty's own standard form. Second, a software or platform licensing arrangement where the IP assignment and licensing-back provisions have not been stress-tested against the law of the assignee's home jurisdiction. Third, a joint-venture formation where the parties have agreed a heads-of-terms but have left data-governance obligations and residuals clauses entirely open.
All three situations carry the same structural risk: the foreign principal believes the contract protects its position, and discovers on day two – when the relationship breaks down – that it does not.
What governs these clauses, and which instruments matter?
The governing instrument is the contract, read under the law the parties have selected. In a cross-border context, that selection determines three things: which substantive rules apply to the confidentiality obligation; what remedies are available on breach; and which forum has jurisdiction to grant them.
Hong Kong law is a well-tested choice for commercial contracts with Greater China exposure. It is a common-law system with a long institutional history of trade-secret protection through the equitable doctrine of breach of confidence and, where applicable, through contractual interpretation under English-origin principles. The courts apply those principles in English – the official working language of the Hong Kong judiciary – and the Court of First Instance has demonstrated consistent treatment of IP and confidentiality disputes with cross-border fact patterns.
Intellectual property rights – patents, trade marks, copyright, design rights – are territorial. They are granted by a jurisdiction and enforceable in that jurisdiction. A well-drafted IP clause in a cross-border contract therefore distinguishes between ownership, licensing, and the procedural question of where each type of right will be enforced. Collapsing those three questions into a single clause, governed by a single law, is one of the most common errors we see in contracts brought to us for review.
Data obligations sit in a separate register. Where a contract involves the transfer of personal data across borders, the obligations of each party depend on which data-protection regime applies. The contract clause cannot override a mandatory legal requirement in the jurisdiction where the data is processed. It can, however, allocate contractual responsibility between the parties and set out the remediation steps if a requirement is breached. Drafting that allocation carefully is the work that determines whether the data provisions are operative or merely cosmetic.
The Arbitration Ordinance (Cap. 609), modelled on the UNCITRAL Model Law, governs arbitral proceedings seated in Hong Kong. Where confidentiality and IP disputes are resolved through Hong Kong-seated arbitration under the HKIAC Administered Arbitration Rules – effective 1 June 2024 – the proceedings themselves are subject to confidentiality obligations under the Rules, which is a material advantage over court litigation for disputes involving trade secrets. The HKIAC Rules also provide for an emergency arbitrator process, ordinarily completed within 14 days of file transmission, which can be used to seek interim relief before a tribunal is constituted – directly relevant where a counterparty threatens to disclose confidential information imminently.
How does the Hong Kong cross-border interface work in practice?
Hong Kong sits at the intersection of the common-law world and the Mainland Chinese legal system. That positioning creates both an opportunity and a structural requirement that foreign principals regularly underestimate.
The opportunity: a governing-law clause selecting Hong Kong law, combined with a Hong Kong-seated arbitration agreement, gives the foreign principal access to a well-established enforcement route into the Mainland through the mutual-enforcement arrangements between Hong Kong and the Mainland. Where an award is made in Hong Kong-seated arbitration, that award can be enforced in the Mainland through the 1999 Arrangement and the 2020 Supplemental Arrangement, which permits simultaneous enforcement applications in both jurisdictions. For a confidentiality or IP dispute where the counterparty's assets sit in the Mainland, this is a material practical advantage.
For those disputes pursued through the courts rather than arbitration, the position changed substantially when the Mainland Judgments in Civil and Commercial Matters (Reciprocal Enforcement) Ordinance (Cap. 645) came into force on 29 January 2024. Under Cap. 645, effective Mainland court judgments can be registered with the Court of First Instance, and Hong Kong judgments can be recognised by Mainland people's courts, without requiring that the original contract contained an exclusive jurisdiction clause – a condition that had limited the utility of the prior regime. The connection-based test under Cap. 645 is a more workable standard for most commercial contracts.
The structural requirement: Lockhart & Yip advises on international and foreign law. Matters of Hong Kong law – including the preparation of Hong Kong-law governed contracts, Hong Kong court filings, and Hong Kong-law opinions – are handled together with locally licensed firms. In our cross-border practice, we coordinate that interface as a matter of course. The foreign principal engages us as the international counsel layer; the locally licensed Hong Kong firm handles the Hong Kong-law execution under our coordination. That division does not create a gap for the client; it creates a clear chain of responsibility.
Where the contract also touches a third jurisdiction – a BVI or Cayman holding entity, a UAE or Singapore distribution vehicle, a UK or European licensor – we coordinate across the relevant layers. The cross-border contract is not a bilateral document; it is a multi-jurisdictional instrument, and the confidentiality, data and IP clauses must be drafted with that architecture in mind.
For a practical read on annual compliance obligations affecting the corporate layer that sits above the contract counterparty, see our guide to annual compliance and corporate maintenance in Hong Kong.
What is the step-by-step route we run?
The engagement begins with a document review and a position-mapping call. We read the existing contract draft, identify the governing-law clause, the confidentiality provisions, the IP ownership and licensing structure, and the dispute-resolution clause. We then map the jurisdictions actually engaged – where each party is incorporated, where the assets or IP registrations sit, where performance will occur, and where a breach is most likely to be felt.
From that mapping, we produce a written position note. It identifies the clause-by-clause risk, the enforcement consequence of each risk, and the recommended revision. That note is the foundation of everything that follows. We do not revise a contract without first setting out the reasons in a form the client can own and use internally.
The second step is clause drafting. We draft or redraft the confidentiality, data-transfer, IP ownership, IP licensing, residuals, and dispute-resolution provisions. Each clause is drafted against the law selected to govern it and tested against the enforcement route available in the relevant jurisdiction. Where the contract selects Hong Kong law, we co-ordinate with locally licensed Hong Kong counsel on the Hong Kong-law provisions. Where a Mainland-law analysis is needed, we identify the point at which Mainland-law specialist input is required and coordinate that input.
The third step is negotiation support. We prepare the client for counterparty pushback by identifying which provisions are negotiating positions and which are structural requirements. In our experience, counterparties with standard-form confidentiality clauses often push back on carve-outs that are, in fact, critical to the enforceability of the obligation. We prepare the client's response to that pushback with the enforcement consequence made explicit.
The fourth step is execution-readiness review. Before signature, we review the final form of the contract against the position note. The purpose is to confirm that the clauses the client must own – governing law, forum, IP ownership, confidentiality scope and carve-outs, data-transfer allocation, residuals – are in the form agreed, and that no last-minute redline has introduced a structural weakness.
The fifth step is day-two planning. For relationships where the cross-border risk is material – a technology-transfer with a counterparty that has access to genuinely sensitive technical data – we prepare a breach-response outline. It sets out the interim-measures route, the evidence-preservation steps, and the filing sequence in each relevant jurisdiction. That outline is not a guarantee of any outcome; it is the decision-tree the client can activate without delay if a breach occurs.
The sequence above describes the standard position. Your matter turns on the documents, the jurisdictions actually engaged, and the order of steps – which is where the route is won or lost. To discuss where your contract currently stands, write to us at info@lockhartyip.com.
Which documents and decisions must the client own?
The client must own the governing-law choice. That is not a drafting decision – it is a strategic decision about which legal system will govern the relationship and provide the remedies. We can advise on the options and their consequences; we cannot make that choice for the client. The client must understand why Hong Kong law was chosen (or why another law was chosen), what that law provides on confidentiality and IP, and what it does not.
The client must own the IP ownership structure. In a joint-venture or technology-transfer context, the question of who owns what – including improvements, derivatives, and residuals – must be decided by the client before the lawyer can draft it. We regularly see clients arrive with a commercial understanding that does not translate into the clause as drafted, because the business team and the legal team have not aligned on the precise ownership position. That misalignment is best corrected before the contract is signed, not after.
The client must own the confidentiality scope. The definition of confidential information, the carve-outs from that definition, and the permitted-use restrictions are commercial decisions. They determine what the obligation actually covers. An over-broad definition creates an obligation that cannot be practically administered. A narrow definition leaves material information outside the protection. The client must understand the scope and approve it explicitly.
The client must own the data-transfer decisions. If the contract involves the transfer of personal data across a border, the client must understand which regulatory regime applies in each jurisdiction and what the contractual allocation of responsibility means in practice. We provide that analysis; the client must confirm the operational position to which the analysis applies.
Finally, the client must own the dispute-resolution choice. Arbitration or litigation; which seat; which rules; which language. These are decisions with enforcement consequences, and the client must understand those consequences before the clause is finalised.
If an earlier filing, structure or enforcement attempt produced an adverse or stalled result – or if an existing contract is now the subject of a dispute – a second read can identify the strategic error and the routes still open. Write to us at info@lockhartyip.com to describe the position.
What do foreign counsel commonly get wrong?
The most common error is treating a cross-border commercial contract as a bilateral document. A contract between a European licensor and a Mainland distributor, for example, involves the law of the licensor's home jurisdiction (which may govern the IP registration and the licensor's corporate obligations), the law selected to govern the contract, and the law of the Mainland jurisdiction where performance occurs and where any breach will first be felt. Each of those legal systems has something to say about the confidentiality and IP provisions. A contract that has been reviewed only against one system is a contract that has been partially reviewed.
The second error is treating the governing-law clause and the dispute-resolution clause as standard form. They are not. The governing-law clause determines the substantive rights. The dispute-resolution clause determines the enforcement route. A mismatch – for example, a Mainland governing-law clause combined with a Hong Kong-seated arbitration agreement – can create a situation where the arbitral tribunal applies a law whose remedies are not aligned with what the arbitral rules permit. That mismatch is avoidable at the drafting stage and very difficult to correct afterwards.
The third error is failing to address residuals. A residuals clause (a provision permitting a party to use in its unaided memory the ideas and concepts it has encountered through the relationship, without liability) is standard in technology-sector contracts in some jurisdictions and unknown in others. A Mainland counterparty's standard form may not contain a residuals clause; a US or European principal's standard form may include one as a matter of course. The absence of any alignment on this point is a structural risk that neither party has priced.
The fourth error is relying on a non-disclosure agreement entered at the heads-of-terms stage as the operative confidentiality document. An NDA entered before the substantive relationship is not a substitute for a well-drafted confidentiality provision in the operative contract. The NDA typically covers the negotiation phase; the operative contract covers the performance phase. If the operative contract's confidentiality provisions are thin, the NDA provides no comfort for the performance-phase exposure.
For a practical read on cross-border restructuring decisions that frequently intersect with these contractual positions, see our briefing on corporate restructuring across Hong Kong and the UAE.
Decision matrix: situation, instrument, route, timing, and risk
Situation A: the client is entering a technology-transfer or licensing contract with a Mainland counterparty, and performance – including data transfer and access to technical specifications – will occur in the Mainland. The recommended instrument is a Hong Kong-law governed contract with a Hong Kong-seated arbitration clause under the HKIAC Administered Arbitration Rules. The route on breach is an emergency arbitrator application (ordinarily completed within 14 days of file transmission) followed by a substantive arbitration. The timing for interim relief is measured in days; the timing for a final award is governed by the HKIAC Rules. The risk is that the client's standard NDA, drafted under the law of its home jurisdiction, has been incorporated by reference without review against Hong Kong law – which may produce a confidentiality obligation that is effective in the home jurisdiction and untested in Hong Kong.
Situation B: the client is a joint-venture party with a BVI or Cayman holding entity above the operating company, and the joint-venture agreement allocates IP ownership at the operating-company level. The recommended instrument is a joint-venture agreement with IP assignment and licensing provisions drafted under Hong Kong law (or, where the operating company is a BVI entity, under BVI law with Hong Kong as the dispute-resolution forum), with a clear chain of assignment from the operating entity to the holding entity. The route on breach is arbitration at the holding-company level, with enforcement through the applicable mutual-enforcement arrangement. The timing for the IP chain of assignment is determined by when the IP is created or acquired during the joint venture, not by the date of the joint-venture agreement – which means the assignment provisions must be operative from the outset. The risk is that the IP is created at the operating level, never assigned upward, and is therefore unavailable to the holding entity at the time of exit.
Situation C: the client is a data-processing service provider with Mainland Chinese data subjects and a European principal. The contract must address both the Mainland data-governance requirements and the European data-transfer obligations. The recommended instrument is a data-processing agreement with separate governing-law provisions for the data-protection obligations (which may be mandatory and not subject to party choice) and the contractual obligations (which can be governed by the chosen law). The route on breach is litigation or arbitration in the chosen forum, but the regulatory consequence of a data-transfer breach may be independent of and additional to the contractual consequence. The risk is that the client has addressed the regulatory position in the home jurisdiction and the counterparty's jurisdiction, but has not addressed the position in the transit jurisdiction – typically, the server location – which may impose its own requirements.
Self-assessment: is your cross-border contract ready?
The following questions identify the most common structural gaps we encounter on first review. These are not a comprehensive audit; they are a preliminary signal.
- Has the governing-law choice been made deliberately, with an understanding of what that law provides on confidentiality and IP remedies?
- Is the dispute-resolution clause consistent with the governing-law choice, and does it produce an enforceable award or judgment in the jurisdiction where the counterparty's assets sit?
- Does the confidentiality definition cover all categories of information the client actually needs to protect, including technical data, commercial terms, and personal data?
- Are the IP ownership provisions clear about who owns improvements and derivatives created during the relationship?
- Is there a residuals clause, and if so, has the client understood what it permits the counterparty to use after the relationship ends?
- Has the data-transfer allocation been reviewed against the data-protection requirements of each jurisdiction where data will be processed?
- Is there a breach-response plan – an interim-measures route and an evidence-preservation protocol – that can be activated without further instruction if a breach is suspected?
If the answer to any of these questions is uncertain, the contract has a structural gap. The gap is easiest to close before execution. Our corporate counsel practice is structured to work through these questions in a defined sequence and produce a position note the client can own and act on.
Related practices
- Disputes & Arbitration – enforcement of IP and confidentiality obligations across the Mainland–Hong Kong boundary
- Holding Structures – structuring the IP ownership layer above the operating contract counterparty
- Tech & Web3 – licensing, data governance and regulatory compliance for technology-sector contracts
Frequently asked questions
How long does data, confidentiality and IP clauses in cross-border contracts usually take?
What documents are needed for data, confidentiality and IP clauses in cross-border contracts?
How does the cross-border element affect data, confidentiality and IP clauses in cross-border contracts?
Speak with Lockhart & Yip
For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →
Related
- Corporate Counsel
- Annual Compliance Corporate Maintenance Hong Kong Guide 2
- Corporate Restructuring Across Hong Kong Uae Uae Briefing
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.