The Burden of Proof Has Always Fallen on the Victim — That Is Changing
There is a structural reason why misappropriation of technical data keeps recurring in subcontracting relationships: almost all of the evidence sits on the other party's servers and in their document systems. The supplier may be certain its technology was taken, yet it is the one required to prove when and how the leak occurred. That imbalance is why many cases never reach a courtroom.
The legal framework is shifting. Under the Subcontracting Act, punitive damages for misappropriation of technical data have been raised from three times to five times actual damages, and the Win-Win Cooperation Act now carries its own punitive damages provision covering demands for and misuse of technical data by contracting firms. Higher damage multipliers change the weight a supplier carries at the negotiating table.
One distinction matters. Expanded disclosure orders are still under discussion in the National Assembly. Bills have been introduced that would let courts order broad production of materials needed to assess infringement, and treat the opposing party's claims as established if production is refused without cause — but this is not yet settled law. The riskiest choice is to postpone preparation on the assumption that proving infringement is about to get easier.
How Enforcement Is Tightening
More ex officio investigations: In sectors where misappropriation is frequent, ex officio investigations are increasing from twice a year to three or more. Patent attorneys and professional engineers are being brought into these investigations, so misuse is now assessed by people who actually understand the technology at issue.Mandatory NDAs: Executing a confidentiality agreement is now required when technical data is provided in a subcontracting relationship. The clauses most often left out are a specific statement of purpose, the timing and verification method for return or destruction, a ban on passing data to lower-tier subcontractors, and the survival period after contract termination. An NDA that exists only in form carries little weight in a dispute.There is a gap that is easy to miss. Even with tougher sanctions, the burden of showing when your company came to possess the technology remains yours. If the counterparty claims independent development, the case becomes a fight over timing — which is exactly why escrow, covered below, matters so much.
What 2026 SME Technology Protection Programs Offer at Little or No Cost
Technical data escrow: Depositing technical materials with a neutral third-party institution creates an official record of when you held them. At a cost of a few hundred thousand won a year — with fee reductions for SMEs — it is the highest-leverage defensive measure available.Technology protection vouchers: A package covering tailored consulting, employee training, security solution adoption, and digital forensics.Tech Guard monitoring service: Free security monitoring for internal data leakage and malware detection.Technology protection policy insurance: Covers legal costs in a dispute, with a large share of the premium subsidized.Damage calculation support: Accounting and technical experts assist with quantifying damages — the hardest element to prove in litigation.A technology protection readiness assessment taken before applying will surface your weak points, and support levels are tiered according to that score. Start with the assessment.
Five Things to Set Up Before You Deal With a Large Buyer
Inventory and classify your technical data into three tiers: freely disclosable, conditionally disclosable, and never disclosed. Without tiers, a project engineer decides on the spot — and that is where leaks begin.Log every disclosure: date, recipient, exact files, and the contractual basis. The fact that data was demanded at all often becomes central evidence.Review contract terms: return and destruction obligations, restrictions on use beyond the stated purpose, limits on passing data down the supply chain, and jurisdiction and governing law.Choose the right instrument: patent protection where the technology is embodied in a product and can be reverse-engineered; trade secret status for process and formulation know-how, reinforced with escrow to fix the date.Close off human leakage paths: minimum necessary access rights, immediate account revocation for departing employees, and export logging. Most incidents come from insiders, not external hacking.A 90-Day Response Plan When You Suspect Infringement
Days 0–14, preserve evidence: Secure timestamps on servers, email, and deliverables in their original state. Opening files on a personal PC can destroy metadata, so bring in forensic support early.Days 15–45, choose your route: After consulting the integrated technology protection help and reporting center, decide between mediation, administrative investigation, and civil litigation. Mediation concludes within months at low cost but requires the other side's consent; an administrative investigation carries strong sanctions but does not itself recover losses; litigation offers the best recovery but takes years.Days 46–90, design the negotiation: Ending the commercial relationship is often not realistic. Use the evidence you secured as leverage — first demand preventive measures and fair compensation, and escalate to formal proceedings only if talks break down.Building Your Technology Protection System With KITIM
Technology protection works only when it is set up before the transaction begins, not after an incident. KITIM supports classification of technical data and selection of escrow targets, design of a protection mix across patents, trade secrets, and escrow, advisory on technology protection program applications, and pre-signature review of NDAs and contracts. Start with our free corporate diagnosis to identify where your technology protection is weakest. Contact KITIM today and our consultants will design a defense framework matched to the stage of your transaction.