Note: In September 2025, Xiaomi Group quickly fired an internal executive for leaking company confidential information and involving conflicts of interest, which aroused strong concern in public opinion. Although the exact scope and motives of the leak remain controversial, the incident highlights the information security and compliance risks that companies face as they globalize.
For Chinese companies planning to go overseas to Singapore, this incident is not only a public opinion crisis, but also a clear legal compliance signal: in cross-border operations, how to effectively protect the core information of the company through legal tools (especially confidentiality agreements) and avoid repeating the same mistakes in an unfamiliar legal and business environment is an issue that cannot be ignored.
1. Event review
On September 8, 2025, Xiaomi Group issued an internal notice: Wang, the general manager of the company's marketing department in China and the general manager of the Redmi brand, was seriously dismissed by the company due to serious violations of regulations and disciplines such as "leakage of company confidential information" and "conflict of interest". Wang later publicly apologized on Weibo, saying that he was ashamed and accepted the price. "It was rumored on the Internet that he leaked core data such as Xiaomi's car pricing strategy in exchange for consulting fees, but relevant people denied it.
This is not the first time Xiaomi Group has been punished for "leakage". It is reported that as early as 2022, Wang was deemed a "Level 2 leak" and was fined, promoted and canceled for revealing the release time of the Redmi K50 standard version on Weibo.
The Xiaomi incident highlights the risks of "insider leaks" and "conflicts of interest" that may arise in corporate governance processes. For Chinese companies planning to enter the Singapore market, this is a direct warning: if it is difficult to completely eliminate such risks in the domestic market, then in unfamiliar overseas markets, such risks will only be amplified and may bring more serious legal and business consequences.
2. Risks of confidentiality agreements under the Singapore legal framework
In cross-border operations, especially when entering the Singapore market, although confidentiality agreements are a simple and low-cost tool, they are related to whether core information can truly be protected. Only by deeply understanding and rationally applying the terms and obligations in the confidentiality agreement can companies effectively prevent legal risks and avoid making the same mistakes in the process of internationalization.
1. Dual application of contractual obligations and equitable confidentiality obligations
In Singapore, contractual obligations of confidentiality exist side by side with equitable obligations of confidentiality.
- Contractual obligations: If the company signs a confidentiality agreement with its employees and partners, the contract terms will become the main basis for judging the rights and obligations of both parties.
- Equitable obligations: Even if there is no contract, if the information is of a confidential nature and is transmitted under confidential circumstances, equity will intervene to force the recipient to bear the duty of confidentiality.
Enlightenment: When conducting business in Singapore, companies cannot rely solely on the terms of the contract. They must also ensure that the information itself meets the legal definition of “confidential information”. Otherwise, the terms of the agreement may be deemed invalid by the court as being overly broad or unreasonable.
2. Rights of parties to the agreement and third parties
The parties to a confidentiality agreement usually include the disclosing party and the receiving party. It is very important that the names and contact information of both parties are clearly stated in the agreement. Depending on the partnership, common forms of confidentiality agreements include:
- One-way confidentiality agreement: one party has an obligation to keep the other party's information confidential, but the other party does not bear the same obligation.
- Two-way confidentiality agreement: Certain information disclosed by both parties in the course of business is required to be kept confidential.
- Multi-Party Confidentiality Agreement: Multiple parties are bound by a single contract, often found in complex and negotiation-intensive transactions.
Under Singapore law, the Contracts (Rights of Third Parties) Act 2001 expressly allows a third party to be named in a contract to acquire contractual rights and have a right of action even if it is not a direct party to the contract. At the same time, the other parties to the contract may not revoke or modify this right without the consent of the third party. Therefore, if the name and contact details of the third party are listed in the confidentiality agreement, the agreement will also be effective for that party.
Enlightenment: Use clauses to make it clear that third parties can only use information within the necessary scope, and provide a liability recourse mechanism, or directly exclude third parties from enjoying relevant rights in the agreement. .
3. Disputes over the definition and scope of confidential information
In practice, one of the biggest risks is that the scope of confidentiality is too broad or vague. For example, Xiaomi's internal information involves the pricing strategy of new models. If the terms of the confidentiality agreement do not clearly distinguish what is "proprietary information", in the event of a dispute, the court may limit the interpretation based on the intentions of both parties when they signed it.
Inspiration:
- Businesses should clearly define confidential information in the confidentiality agreement and exclude information that is in the public domain, independently developed, or known before signing.
- Protection levels can be set hierarchically for key business secrets (such as algorithm codes, marketing plans, and customer lists) to avoid confusion with ordinary information.
4. Information return and destruction obligations
Singapore confidentiality agreements usually require the recipient to return or destroy confidential information after the cooperation ends or the employment relationship is terminated. If performance is not performed, the party may be liable for breach of contract.
Inspiration:
- When companies go overseas, they should establish a regular audit mechanism and require partners or employees to confirm return/destruction in writing.
- For situations involving cloud storage or cross-border data transfer, the agreement should stipulate specific technical measures and compliance requirements.
5. Duration and enforceability of confidentiality obligations
If the confidentiality agreement stipulates that the period is too long, it may be regarded as a "restriction of trade" by the court and invalid.
Inspiration:
- Enterprises should set reasonable periods in contracts (e.g. 2 – 5 years) and set differentiated protection periods for different types of information (trade secrets, general financial data).
- For long-term partners, you can consider adding a non-compete clause to the confidentiality agreement, but you must avoid violating the Singapore Competition Act and constituting a "restriction of trade".
6. Risks of third-party information sharing
Confidentiality agreements may bind the conduct of third parties within the scope of the contract. If the company ignores this, information may be leaked through third parties, and the company may be held responsible for the third party's misconduct.
Inspiration:
- Enterprises should clearly list the third parties allowed to have access to information and their responsibilities in the confidentiality agreement to avoid liability blind spots.
- For key sensitive information, add a "access only in a controlled environment" clause to reduce the probability of leaks.
In conclusion
The Xiaomi leak incident once again reminds companies that information security and confidentiality agreements are not only internal management issues, but also legal risk points that affect international layout. For companies planning to go overseas to Singapore, the confidentiality agreement must clearly define the responsibilities of the parties and third parties, reasonably clear the scope of confidentiality, and set the time limit and liability for breach of contract appropriately to comply with the local legal framework and business practices. Only by combining institutional constraints, legal tools and corporate culture can we truly protect core secrets, establish a trustworthy international image, and achieve long-term and steady development in overseas markets.
This article is general information and not legal advice. Specific matters require assessment by appropriately qualified professionals.