IP Protection When Manufacturing in China: A Practical Risk-Management Guide
IP protection in China: the real risks, legal context, NDAs, segmented supply chain and practical safeguards.
IP Protection · Manufacturing in China IP Protection When Manufacturing in China: A Practical Risk-Management Guide Intellectual property risk in China is real, but it is a solvable engineering problem — one you manage with segmentation, registration, contracts, and supplier selection. This guide covers the risks that matter, what Chinese IP law protects, and the safeguards that work. Request a quoteSkip to the safeguards Every hardware founder eventually asks the same question: if I manufacture in China, will my design walk out the door? The risk is real, uneven, and mostly under your control. Counterfeiting, design leakage, and gray-market diversion are three separate problems with three separate defenses. China has a functioning IP system — patents, utility models, trademarks, and trade secrets all receive legal protection — but it rewards whoever files first and keeps their own house in order. This is a practical risk-management manual, not a scare story and not a sales pitch. The three risks that actually matter IP loss is not one event; it is three, and each needs its own defense. Most buyers who worry about “IP theft” are really worrying about one of these without naming it, which is why their protections miss. Counterfeiting is a third party copying your product and selling it under your brand — or a lookalike — usually after you have shipped and proven demand. The leak point is rarely the contract manufacturer; it is more often a distributor, a reseller, a disgruntled employee, or a mold shop that kept a copy of the tool. Design leakage is your own supplier — or someone inside it — reusing your drawings, board layout, or process on someone else’s program. Gray-market diversion is the quieter one: overproduction or “second-shift” production of your own genuine product, sold through channels you never authorized. RiskWhat it looks likePrimary defense CounterfeitingCopies sold under your brand after you shipRegistered trademark and patent in China, customs recordal Design leakageYour drawings or board reused on another programSegmented supply chain, audited supplier, NDA with teeth Gray-market diversionOverproduction sold outside your channelsContracted output, locked firmware, reconciliation The pattern worth noticing: two of the three are enabled by your own supply chain, and the third is largely a legal-registration problem. That is why this guide spends most of its length on how you structure work, not on what the law says. What China’s IP law actually protects China’s IP regime is comprehensive and, in the mechanical and electronics space, genuinely useful — if you register in China, not just at home. IP is territorial: a US or EU filing gives you nothing inside China until you register there. The instruments that matter for hardware fall into four families. Patents. An invention patent protects a technical solution — a product or a method — and is substantively examined before grant, making it the strongest but slowest tool; protection runs 20 years from filing. A utility model protects the shape or structure of a product, is granted quickly with only a formality examination, and lasts 10 years; because it is not examined, it is weaker and easier to invalidate, but it is a fast, cheap placeholder for a mechanical design while an invention patent crawls through examination. A design patent protects visual appearance — shape, pattern, color — and now runs 15 years. For an enclosure or a distinctive mechanical form, it stops a lookalike. Trademarks. Trademark rights protect the brand, not the technology, and are class-based — registration covers the specific classes of goods you name, for 10 years at a time, renewable. Because China is first-to-file, a third party can register a name you have been using and then block or charge you for it. Register the brand early, in the classes you actually sell into. Trade secrets. China protects trade secrets under the Anti-Unfair Competition Law, and one practical rule dominates: information counts as a trade secret only if you took reasonable steps to keep it confidential. An NDA, access controls, and compartmentalization are what make your design protected at all. Share it freely with no controls, and the law may treat you as having given it away. Copyright. Technical drawings and software enjoy automatic copyright on creation, and registration in China provides evidence of ownership and a date stamp — cheap insurance when a dispute turns on who drew what, and when. RightWhat it protectsExaminationTerm Invention patentTechnical solution (product or method)Substantive20 years Utility modelShape or structure of a productFormality only10 years Design patentVisual appearanceFormality only15 years TrademarkBrand name and mark, by classExamination10 years, renewable Trade secretConfidential technical or business informationNone — requires confidentiality measuresIndefinite, while secret CopyrightDrawings and softwareNone (automatic)Long, by category First to file: register before you share China operates on a first-to-file basis for both patents and trademarks: the right goes to whoever files first, not whoever invented first. If a factory, competitor, or third party files your design before you do, your position flips from owner to challenger, and you may lose the chance entirely. The sequence is simple and cheap relative to the product. File a utility model or design patent in China — or lodge a priority filing — before you send full drawings to a supplier for quoting, and definitely before a tool is cut. A utility model is inexpensive, fast, and structurally suited to a machined enclosure or mechanism. File the trademark for your brand and product name in the classes you sell into at the same time. You can extend abroad later through the priority mechanism; the early Chinese filing fixes your date where the work is being done. None of this prevents a determined bad actor from copying you; it changes what happens after. A registered right is what lets customs seize suspected infringing goods at the border and what gives a cease-and-desist letter something to point at. How the manufacturing contract fits in. Segment the supply chain: never hand one supplier the full design The single most effective safeguard is also the least used: do not give any one supplier everything. IP leaks when one party holds the complete, ready-to-copy design. Segmentation splits the work so no single vendor — and no single person inside it — can reconstruct the whole product. It maps onto how a product is built. One vendor machines the enclosure; another assembles the board; a third flashes firmware; a fourth handles box build, if you do not do it yourself. Each party gets only the files it strictly needs, and none sees the complete bill of materials. The enclosure shop does not need your schematic; the assembler does not need your mechanical tolerances; the flasher needs the compiled image, not the source code. The cost of segmentation is coordination: you become the integrator and absorb the handoffs. But for a product whose design is the company, that coordination cost is the price of not handing the whole crown to one table. How to audit the suppliers you split between. Split the BOM and the PCB across vendors Electronics deserve a sharper version of the same rule, because a board is a near-complete product in one file. Two tactics do most of the work. Split the BOM. Publish the bill of materials to your assembler without the firmware, and without the component that makes the product work — the programmed microcontroller, a security chip, or a custom module you source and provision yourself. The assembler can place and solder everything and never hold a functioning device. Split the PCB. Have one shop fabricate the bare board and a different shop assemble it, so the fabricator never sees components and the assembler never sees the finished stack. Where the design allows, keep a daughterboard or the RF section built and programmed separately, married at final assembly. The aim is not paranoia; it is that a leak yields a fragment rather than a product. A stolen bare board, a component list, or a binary is far less useful than a complete build packet, and none alone is a sellable copy. Where these splits sit in the NPI gates. Lock the firmware and provision your own keys For connected or software-defined products, firmware is often the real crown jewels — and the cheapest thing to lock. A few controls do most of the work. Ship compiled binaries only, never source. Use readout protection on the microcontroller so flash cannot be dumped. Sign and encrypt the image so a modified binary will not boot. Provision unique keys or IDs yourself, or through a service you control — a factory that holds your device keys can clone activation, bypass licensing, or build gray-market units that pass as genuine. Where security matters, consider a secure element that stores the key. The factory still needs to flash and test the board, so give it a test image that exercises the hardware without exposing production functionality, then perform final secure provisioning at a stage you control. A board leaving the floor should be inert until the legitimate software and keys are applied. The EMS build path in detail. NDAs and contracts: what they can and cannot do An NDA is necessary and nowhere near sufficient. Its job is twofold: it sets the legal expectation of confidentiality, and — because a trade secret requires “reasonable measures” — it is part of what converts your design into a protected trade secret under Chinese law. A signed NDA is not a guarantee nothing leaks; it is the difference between a prosecutable leak and information you simply gave away. Make the NDA bilateral where you can, name the information, and bind it to the people who will actually see the files, not just the corporate shell. State a retention and return obligation for drawings, tooling files, and firmware. Be realistic about enforcement: litigating an NDA breach across a border is slow and expensive, and recovery is often smaller than the loss. That is exactly why the structural safeguards matter more than the contract — the NDA is the backstop, segmentation is the front line. In the manufacturing agreement, a few clauses earn their place: an explicit statement that the supplier builds to your design and acquires no rights in it; a restriction on reuse of your tooling, drawings, and firmware; a no-overproduction or output-reconciliation term for gray-market control; and a return-of-materials obligation at program end. Selecting a partner you can hold to these. Due diligence: audit the supplier’s IP habits, not just its machines Most supplier audits check tolerances and certificates and never ask a single question about intellectual property. That is why a shop can pass an audit and still be the weak link in your IP. Add IP to the checklist. Ask how customer files are stored and who can access them. A serious shop keeps customer data segregated and controlled — encrypted at rest, on access-restricted systems, with no shared desktop folder. Ask whether it will sign an NDA before you send drawings, and watch the reaction: a supplier that hesitates is telling you how the whole program will treat your data. Ask who inside the factory sees a full design, and whether any one person can export it. Ask what happens to files and tooling when a program ends. A confident, specific answer is the signal; vagueness is the finding. Look at the facility’s structure as an IP control in itself. Every subcontractor is another party that touches your design, so a partner that keeps machining and electronics assembly under one roof and one quality system inherently reduces the number of third parties who see your files. That is a security property, not just a convenience. Structure the relationship like a risk program IP protection is not a one-time document; it is how the relationship runs day to day. A few choices keep a good supplier honest and make a bad one easier to spot. One named owner on each side. A single accountable person on your side, matched to one on theirs, shrinks the surface where files float. Version-controlled handoffs. Send drawings and firmware through a controlled, revision-stamped channel. Least-privilege sharing. Release only what a stage needs: a quote needs geometry, not a schematic; a tooling shop needs the cavity, not the electronics. Audit at the gates. Revisit the supplier at EVT, DVT, and PVT, verifying not just quality but that your data stays where it belongs. An exit plan. Agree up front what returns to you — drawings, tooling, firmware, fixtures, remaining parts — when the program ends or moves. None of this is hostile. A good factory prefers a structured relationship because it reduces its own exposure. The suppliers who resist these terms are precisely the ones the terms exist to filter out. If something leaks: what enforcement looks like in practice Honesty about enforcement is part of the calculus, so here is the unvarnished version. China has the machinery — administrative enforcement through market regulators, civil litigation, customs recordal that lets customs seize suspected infringing goods at the border, and criminal liability for serious trade-secret theft. All of it exists and is used. But enforcement is slow, expensive, and favors the party with the better evidence and the registered rights. If you filed nothing in China, your position is weak regardless of the facts. If you registered early, kept your confidentiality measures, and segmented your supply chain, you enter a dispute with documentation and rights, not a story. The realistic objective is not to litigate your way to full recovery — it is to make copying costly enough that it does not happen, and to hold the rights that make a cease-and-desist or a customs seizure land with force. The honest bottom line: the law rewards prevention, not reaction. Think about enforcement before the first drawing leaves your server, because every safeguard you put in place then is the evidence you lean on later. How Nex-G handles your IP We hold ourselves to the same bar this guide sets, because the founders and sourcing teams we work with should be able to audit us on IP the way they audit us on tolerance. Here is the checkable version. NDA on request. We sign a mutual NDA before you send drawings — no hesitation, no minimum spend first. It binds the people who see your files, not just the company name. Encrypted and locked storage. Customer drawings, board files, and firmware are held on encrypted, access-restricted systems — not a shared desktop folder and not a laptop that walks out the door. Access is limited to the people who need it to build your product. Fewer third parties by design. Nex-G runs EMS and CNC machining under one roof in Dongguan Hengli, Guangdong — a 6,800 m² facility with 100+ staff, operating since 2006. Because SMT, box build, testing, and machining sit in the same building under the same quality system, your enclosure, brackets, and board move through one accountable partner instead of three subcontractors. Every handoff you remove is one fewer party that touches your design. The full capability sheet. 1roof — EMS and CNC in one Hengli facility 6,800m² floor, 100+ staff, since 2006 0design ownership — IATF 16949, clause 8.3 excluded 2027next URS surveillance audit due We build to your design, not our own. Our IATF 16949 certificate is scoped to manufacture and explicitly excludes product design under clause 8.3 — we take your drawing and your tolerance and build to it, without acquiring or asserting rights in it. ISO 9001 and ISO 14001 sit alongside, current and verifiable, with the next URS surveillance audit due in 2027. No MOQ, staged gates. We run from a one-piece prototype through EVT, DVT, and PVT to mass production with no minimum order — so you can validate a single supplier with a small build before you trust it with volume, and never hand over the full design before the relationship has earned it. Why no-MOQ changes the risk math. Frequently asked questions Is IP theft in China as common as the horror stories suggest?It happens, but it is concentrated and largely preventable. Most loss is design leakage or gray-market overproduction enabled by an unsegmented supply chain, not some inevitable property of manufacturing in China. Segmentation, registration, locked firmware, and an audited partner remove most of that surface. Do I need to register my IP in China specifically?Yes. IP is territorial, so a US or EU patent or trademark gives you nothing inside China until you register there. Because China is first-to-file, register a utility model or design patent and your trademark early — before you share full drawings for quoting. Will an NDA actually protect my design?Partly. An NDA is necessary and is part of what makes your design a protected trade secret under Chinese law, but it is a backstop, not a front line. Real protection comes from segmenting the supply chain so no single party holds the full design, plus locked firmware and registration. Should I split my product across multiple suppliers?Usually yes, and you can do it without chaos. Split machining from assembly from firmware provisioning, and split bare-board fabrication from assembly. Each party gets only what it needs, so a leak yields a fragment, not a sellable copy. How do I keep a factory from cloning my firmware?Ship compiled binaries only, enable readout protection, sign and encrypt the image, and provision device keys yourself rather than letting the factory generate them. Give the factory a test image for build and test, then apply the secure production firmware and keys at a stage you control. What should an IP audit of a supplier look like?Ask how customer files are stored and who can access them, whether it will sign an NDA before you send drawings, who internally can export a full design, and what happens to files and tooling when a program ends. A specific, confident answer is the signal; vagueness is the finding. What can I actually do if my product is copied?If you registered in China and kept confidentiality measures, you can pursue administrative enforcement, civil action, or a customs seizure through recordal. It is slow and favors the better-evidenced side, which is why the objective is prevention — registration and segmentation make copying costly before it happens. Does Nex-G sign NDAs and protect customer files?Yes. We sign a mutual NDA on request before you send drawings, hold customer files on encrypted, access-restricted systems, and run EMS and CNC under one roof so fewer third parties touch your design. Our IATF 16949 scope excludes product design under clause 8.3 — we build to your design, not our own. Protect the design before you ship the drawingsSend your NDA request and your drawing to [email protected] → we will sign before you share, explain exactly who will see the files and how they are stored, and quote your part with one accountable partner in Dongguan Hengli.Request a quote Related articlesContract Manufacturing in ChinaPCB Assembly in China: How to Vet an EMS PartnerChina vs India Manufacturing