A Wuhan new-energy vehicle group proposes to acquire a European battery-management technology company. The target's code repositories, testing records and employee data are stored in Europe. The Chinese buyer wants its Wuhan engineering team to review detailed technical files before signing. The target also licenses technology from U.S. suppliers and sells products to customers in several jurisdictions. The acquisition agreement is expected to use international arbitration.
The transaction is not simply an outbound M&A deal. It is a technology-transfer, data, export-control and dispute-enforcement project. If the buyer opens the data room too broadly, it may receive information that cannot lawfully be transferred or used. If it postpones export-control diligence, it may acquire technology that cannot be moved to China or integrated into the buyer's products. If the arbitration clause is drafted without considering where assets and evidence are located, the buyer may have a strong contract but weak remedies.
The specific issue
The Legal Rule
If the buyer opens the data room too broadly, it may receive information that cannot lawfully be transferred or used.
The Business Impact
Settle the business scope, ownership chain, governance, capital commitments and licence sequence. A formation choice that looks administrative can become expensive to unwind once contracts, staff or regulated activities sit underneath it. Apply that to the facts of Overseas Technology M&A by Chinese NEV Companies: How to Control R&D Data, Export-Control Risk and Arbitration Before Signing.
This article focuses on that integrated risk.
Technology ownership, transferability and staged disclosure
Separate ownership diligence from transferability diligence. A target may own its patents and code yet be unable to transfer or disclose all underlying technology freely. The buyer should create two maps: ownership and transferability. Ownership identifies who holds patents, software copyright, trade secrets and licenses. Transferability asks whether contracts, export-control rules, data restrictions or customer obligations limit disclosure or post-closing use.
This distinction is essential in technology M&A because the most valuable asset may be technically “owned” by the target but practically constrained by third-party licensing or export restrictions.
Stage technical disclosure. The buyer should not request the target's entire R&D repository during first-round diligence. Use staged disclosure. Early review can rely on architecture documents, patent lists, license schedules, product specifications and compliance summaries. More sensitive source code or detailed technical data can be reserved for a clean team, restricted review environment or later diligence stage.
The acquisition agreement can make satisfactory technical verification a signing or closing condition where the technology is central to value. This reduces the incentive to over-collect sensitive material before the transaction is sufficiently certain.
Chinese data law matters even in an outbound acquisition. If the buyer's Wuhan team uploads or receives personal information from China systems during the transaction, the Personal Information Protection Law applies to the processing. Post-closing integration may also involve Chinese employee, customer or vehicle-related data moving to the overseas target. [1]
The CAC's 2024 cross-border data provisions simplified some transfer routes, particularly for certain trade, multinational manufacturing and HR scenarios, but they did not eliminate the need to classify personal information and important data. The buyer should map data flows in both directions rather than assuming the outbound acquisition is legally external to China. [2]
R&D data should be classified by field, not folder name. A file labeled “testing data” may contain engineer names, vehicle identification information, customer data and proprietary technical measurements. Each field can create a different legal issue. The diligence team should distinguish personal information, sensitive personal information, important data where applicable, trade secrets and non-personal technical data.
Where the buyer only needs performance analysis, identifiers should be removed or masked. Data minimization reduces both privacy risk and transaction leakage.
Export-control and contractual restrictions
Export-control diligence starts with the technology stack. The buyer should inventory hardware, software, encryption, technical data and third-party components used in the target's products. For each critical element, identify origin, supplier, license, end-use restrictions and any applicable export-control classification provided by the supplier or target.
The buyer should not treat export control as a representation-only issue. If an indispensable component or technical service cannot be transferred to China, that limitation affects valuation and integration strategy.
China-side export controls can also matter after closing. The Chinese buyer may later send equipment, source code, engineering data or testing services from Wuhan to the acquired company. China's Export Control Law applies to controlled goods, technologies and services and related technical materials and data. The post-closing integration plan therefore needs a China-side classification and end-user review as well as host-country analysis. [3]
This is especially important where the acquisition is intended to create a two-way R&D platform.
Customer contracts may restrict technology use. Automotive and battery technology companies often develop customer-specific software or testing outputs. The target may have confidentiality, field-of-use or non-transfer obligations. A change of control can also trigger customer consent.
Diligence should therefore identify which technical assets are reusable across the buyer's products and which belong contractually to a particular customer relationship. The buyer should not value customer-funded development as unrestricted target IP without reading the contract.
Employee mobility is part of the IP analysis. The target's technology may depend on a small group of engineers. The buyer should review employee invention assignments, confidentiality, non-competes where enforceable, retention arrangements and change-of-control incentives. Losing the engineering team can reduce the value of legally owned patents and code.
The transaction plan should identify key employees and determine whether retention or new incentive arrangements are required before closing.
Third-party software deserves separate review. A technology target may use open-source components, commercial SDKs, cloud tools or proprietary libraries licensed from suppliers. The buyer should request a software bill of materials where feasible and identify licenses that restrict assignment, change of control, geography or redistribution.
The representation that the target “owns all software” is inadequate if core functionality depends on third-party licenses that may terminate after acquisition.
Data-room architecture and clean-team controls
Data-room access should be auditable. Sensitive technology diligence should use named users, access logs, download restrictions and confidentiality obligations. If the deal fails, the seller should be able to determine what the buyer accessed and require deletion or continued confidentiality.
The buyer also benefits from auditability because it can show that only authorized teams accessed sensitive personal or technical data.
Clean teams can separate competitive risk from legal diligence. Where buyer and target compete directly, disclosure of pricing, customer or future-product information can create competition and trade-secret concerns. A clean team of external advisers or segregated internal personnel can review the information and report conclusions without sharing raw data with commercial decision-makers.
The clean-team protocol should define permitted personnel, information categories, reporting form and destruction or retention after the transaction.
Closing conditions should reflect technology dependencies. If the buyer's investment thesis depends on transfer of specific technology, the acquisition agreement should identify the relevant approvals, third-party consents or license continuations as closing conditions. A broad covenant that the seller will use “reasonable efforts” may be inadequate if one license is essential to the product.
The buyer should quantify the consequence of losing each critical technology asset and negotiate accordingly.
Warranties should distinguish compliance from capability. A seller can warrant that it complies with export-control law, but that does not guarantee the buyer will be permitted to transfer the technology to China after closing. The contract should distinguish historical compliance from future transferability.
The buyer may require a specific warranty about existing classifications and licenses, a covenant to cooperate with post-closing applications and a termination right if a defined critical technology cannot legally be used as intended.
Dispute clauses, evidence and closing conditions
The arbitration clause should follow the asset map. An international acquisition agreement often uses ICC, LCIA, HKIAC or another arbitration institution. The buyer should choose seat, institution and governing law after considering where the seller, escrowed funds, IP and other assets are located.
If urgent relief may be needed to prevent disclosure of technology or dissipation of sale proceeds, counsel should understand which courts can grant interim measures and how the arbitration rules interact with local law.
Related agreements need consistent dispute clauses. The acquisition may include an IP license, transitional services agreement, employment or retention agreements and escrow. If each document uses a different forum, one operational dispute can fragment into multiple proceedings.
The legal team should create a dispute-clause matrix and intentionally decide which disputes belong together. Consistency is especially important for claims involving technology transfer and post-closing integration.
Evidence preservation belongs in the integration plan. If a post-closing dispute arises over code ownership, license compliance or representations, the buyer will need the data-room record, source-code history, contract versions and technical reports. The transaction archive should therefore preserve diligence evidence in a controlled repository.
Do not rely on links to a seller data room that closes thirty days after completion.
Worked acquisition scenario
Case study: battery-management software acquisition. Assume the target owns core algorithms but uses a U.S.-origin commercial library that cannot be exported to certain end users without authorization. The Chinese buyer wants to integrate the algorithms into vehicles produced in Wuhan and export the finished systems globally. During diligence, the target also provides test data containing driver and employee identifiers.
The buyer should separate the target-owned algorithm from the restricted library, confirm whether alternative components exist, minimize or anonymize personal data, and make license continuation a closing condition. The buyer's integration budget should include the cost of replacing the restricted component if authorization is unavailable.
Pre-signing risk schedule and integration planning
Build a pre-signing technology risk schedule. The schedule should list every critical technical asset, owner, license, export classification, data category, required consent, transfer destination and business consequence if unavailable. Each item should be labeled green, remediable or blocking.
The investment committee should see this schedule before approving final price. Technology risk should not be buried in a legal due-diligence appendix.
Plan the first one hundred days before closing. The integration plan should include data-access changes, repository permissions, employee retention, technology-license transition, export-control screening, China-to-overseas technical transfer controls and dispute-record preservation. The buyer should not wait until day one to decide which engineers can access the acquired systems.
A controlled integration protects both regulatory compliance and the value of the acquired technology.
Vehicle, HR and development-tool data
Vehicle and product data require a separate map. An NEV acquisition may involve vehicle telemetry, diagnostic data, test-fleet information and customer service records. The buyer should not classify all of this as ordinary R&D. Some data may contain personal information, precise location, identifiers or other regulated fields. Others may be commercially sensitive but not personal.
The data team should document why each category is required for diligence and whether review can occur through sampling, anonymization or in-country access. A buyer that merely wants to verify technical performance may not need raw driver-level records.
Cross-border HR diligence should use role-level information first. Before signing, the buyer usually needs to understand headcount, compensation, key talent, incentive liabilities and employment disputes. It rarely needs passports, health records or complete personnel files for every employee. Use aggregated or redacted HR data until individual information is necessary for a defined purpose.
This approach better aligns with PIPL necessity and reduces risk if the transaction later fails.
Export-control diligence should include development tools. Technology companies may rely on software development kits, encryption tools, simulation software or cloud services that have export-control conditions. The buyer should identify not only components embedded in the final product but the tools required to maintain and develop it.
A post-closing team can own the source code yet be unable to compile, test or update the product if a critical development environment becomes unavailable.
Sanctions, access matrices and transitional services
Sanctions clauses need a business-impact analysis. Third-party licenses and customer contracts may contain sanctions and export-control clauses broader than mandatory law. The buyer should identify termination rights triggered by change of control, Chinese ownership or use in specified markets.
A seller warranty that it has never breached sanctions clauses does not solve the future risk that the acquisition itself creates a contractual termination right.
Build an integration-access matrix. For the first one hundred days, list each system, repository and data set; the personnel who need access; the legal entity employing them; their location; and the legal basis for access. This prevents the common post-closing practice of giving the whole buyer engineering team administrator rights to the target's systems.
Access should expand only as integration needs are verified.
Transitional services can protect the buyer from rushed transfer. Where licensing or data issues cannot be resolved by closing, the seller or retained group may provide transitional services. The TSA should define systems, service levels, security, data handling, intellectual property, cost and termination.
A transition period can give the buyer time to obtain licenses or rebuild systems without forcing an unlawful or technically unsafe transfer on day one.
Representations, indemnities and confidentiality
Representations should be backed by disclosure schedules. For data, IP and export control, generic warranties are difficult to enforce if the seller has made broad data-room disclosures. Require structured schedules listing material licenses, known restrictions, investigations, export classifications where available, data incidents and cross-border transfer arrangements.
The buyer should decide which disclosed risks it accepts and which require remediation or price protection.
Use specific indemnities for known compliance exposure. If diligence discovers a historic data breach, unlicensed component or export-control issue, a general compliance warranty may be inadequate. A specific indemnity can allocate the identified liability, with agreed caps, survival periods and control of defense.
Known issues should be priced and documented, not buried in disclosure.
Arbitration confidentiality does not replace trade-secret procedure. Although international arbitration is private, sensitive technical information still needs controlled handling. The parties may need confidentiality orders, restricted expert access and secure document exchange. The arbitration clause or procedural agreement should allow the tribunal to protect trade secrets effectively.
This is especially important where the dispute itself concerns the technology acquired.
Pre-signing investment committee checklist. The committee should receive a one-page heat map showing: critical technology; ownership; third-party license restrictions; export-control dependencies; personal and important data categories; key employee retention; customer consents; integration blockers; and arbitration/enforcement strategy.
If management cannot explain how the buyer will legally access and use the target's core technology after closing, the deal is not ready for final valuation.
Cybersecurity, cloud, source code and government grants
Review cybersecurity representations against actual architecture. The target should disclose material security incidents, penetration-test results, key third-party infrastructure and security certifications. A warranty that the company maintains “industry-standard security” is difficult to evaluate unless the buyer understands the systems that hold core code and data.
For a technology acquisition, a known security weakness can affect both valuation and post-closing integration. The buyer should identify whether remediation must occur before connecting the target to group networks.
Cloud hosting can create hidden transfer constraints. The target may host repositories or customer data in a cloud region selected years earlier. The buyer should identify data location, subprocessors, contractual migration rights and whether the hosting agreement allows change of control.
If the buyer plans to move data into a China-based or global group cloud, that migration should be analyzed as a separate legal and technical project rather than assumed to occur automatically after closing.
Source-code escrow and continuity rights may be material. Some customers or licensors use source-code escrow arrangements. The buyer should review triggering events and whether a change of control affects escrow release. Likewise, if the target depends on a supplier's source escrow, the buyer should confirm that the benefit continues after acquisition.
These arrangements can become important when a critical software supplier fails or terminates support.
Government grants can restrict technology relocation. A technology company may have received research grants or local subsidies that impose location, employment or commercialization conditions. Moving R&D to Wuhan or sharing technology with another group company may affect those commitments.
The diligence team should inspect grant agreements rather than treating subsidies solely as financial income.
Build a failed-deal data destruction protocol. The NDA should state what happens if negotiations end. The target should be able to require deletion or return of sensitive data, while the buyer may need to retain limited copies for legal or compliance reasons. The protocol should distinguish archived legal records from information that engineering teams must delete.
Named custodians should certify completion rather than relying on a generic corporate statement.
Integration governance and decision record
Integration steering committee. Create a committee including M&A, legal, data protection, export control, IT security, R&D and HR. Each workstream should have a defined scope and escalation path. Technical integration should not outrun legal permissions.
The committee should meet before closing and during the first one hundred days, with a register of access decisions and unresolved restrictions.
Final safeguard. If core technology cannot be transferred to China, management should decide whether the business case still works with the technology remaining overseas. If key licenses terminate on change of control, consider a condition precedent or price reduction. If data transfer is restricted, consider local processing or clean-room access. If all three issues remain unresolved, the buyer should reconsider the valuation or structure rather than betting on post-closing fixes.
Deal-team record retention. The buyer should preserve the final technical risk schedule, data-transfer analysis, export-control conclusions and access logs as part of the permanent transaction record. Those documents may be needed years later if a seller warranty claim, regulatory inquiry or technology dispute arises. The archive should record which version of the target systems and licenses was reviewed at signing and closing rather than preserving only a final board presentation.
Conclusion
Overseas technology M&A by a Chinese NEV company is not complete when the shares transfer. The buyer must know whether technology can be disclosed, transferred, integrated and defended across jurisdictions. Data classification, export controls, licensing and arbitration should therefore be part of the transaction structure, not post-closing cleanup.
The core rule is: do not value technology until you know both who owns it and who may lawfully use it after closing.
Legal and regulatory sources
[1] Personal Information Protection Law of the PRC: https://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html
[2] CAC Provisions on Promoting and Regulating Cross-Border Data Flows, effective March 22, 2024: https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm
[3] Export Control Law of the PRC: https://www.npc.gov.cn/englishnpc/c2759/c23934/202112/t20211209_384804.html
[4] Regulations on Export Control of Dual-Use Items, effective December 1, 2024: https://exportcontrol.mofcom.gov.cn/article/zcfg/gnzcfg/gzjgfxwj/202410/1057.html
General legal information only; not advice on a specific acquisition.
Discussion
Share experience or questions about this topic. This is a public discussion — not legal advice. Do not post confidential case details.
Have a question after reading? Leave it here, or Ask a Lawyer for a free initial intake.
Comments are moderated. China Legal Portal is a directory and information resource; no attorney–client relationship is formed by posting here.