Trade secret protection is not only about preventing theft. It is also about preserving enterprise value. Trade secrets might be the most convenient form of protection but also most vulnerable assets. The misappropriation most frequently occurs by continual increase of portability of information, which results in greater likelihood of trade secrets misfortune (read the article about Trade Secrets Misuses by Employees under the link).
Since a trade secret cannot be classified as a “normal” confidential information, in order to protect it, a trade secret owner shall focus on most effective tools to prevent its disclosure to unauthorized third parties.
Firstly, one shall. Start by determining what information qualifies as a trade secret – which information is commercially valuable because of being kept a secret? This might include a secret manufacturing process, strictly confidential business plans, R&D data, or proprietary algorithms that are likely to be known only to some employees who are desired to have a particular position of trust.
The special employee privilege leads us to the second step, which is to limit access. Give employee access only to information needed for their jobs and separate information only on a need-to-know basis. Permissions must be regularly reviewed and – if necessary – invoked when they are no longer applicable.
Nevertheless, physically limiting access to most vulnerable information would not be sufficient without strong employment agreements. The third preventive step focuses on enforcing legal measures in employment (or other) contracts which include, but are not limited to:
- Strong confidentiality clauses or separate NDAs covering specific purpose of disclosure and use of confidential information;
- Intellectual property assignment clauses;
- Where legally enforceable, introduction of post-employment confidentiality obligations;
Strong agreements shall not only be applied to insiders but also to secure third-party relationships. One shall not forget about requiring vendors, contractors or consultants to sign properly drafted NDAs, restricting shared information only to a need-to-know basis, introducing requirements to return or destroy company property upon a certain period of time with an obligation to certify such destruction and, in master services agreements, require the other party to follow specific security (and cybersecurity) measures.
At the same time, it shall be highlighted not to willingly share or provide a list of trade secrets when negotiating an NDA with a third party. Such actions are neither satisfactory for a party receiving confidential information (due to a risk of contamination), nor for the party disclosing such trade secrets due to a risk of not meeting the legal criterion of trade secrets protection which is making reasonable steps to keep the information a secret in order to qualify as a trade secret.
The fifth measure would focus on implementing technical controls in order toprotect confidential data and trade secrets, such as multi-factor authentication, encryption of sensitive data, data loss prevention systems.
One of the most crucial factors which requires to be highlighted is to regularly train employees on confidential information, data loss prevention, trade secrets importance and at the same time, enforcing clear operating policies, such as:
- Remote work security policy;
- Personal device rules;
- Use of public AI tools and public cloud services;
- Third party data sharing;
- Confidential information leakage policies;
Most of employees commit IP theft because they honestly do not understand the ownership of IP rights in course of employment. Hence, it has to be employers’ first point to educate workers about the importance of trade secrets.
The eighth point on trade secrets protection is to monitor appropriately large downloads, transfers to USB devices, uploads to personal cloud storage or unusual login locations or times.
Another measure does not immediately spring to mind, although is crucial in enhancing employees’ loyalty towards company’s vulnerable information. Many insider incidents are motivated by dissatisfaction or perceived unfairness at the workplace. How is it possible for the employee to easily “walk out the door with thecompany in his pocket” having no ethical concerns towards such behaviour? Theanswer might be found in the basis of employee’s attitude towards ownership andcertain behavioural patterns. As such, the risk of a trade secret’s loss may be reduced by keeping positive relations at the workplace by e.g. encouraging open communication, recognizing employee contributions or building trust and accountability by addressing workplace concerns promptly.
Although preparing employees for the processing of trade secrets at the workplace, incidents may still occur. In order to effectively protect vulnerable information, it is crucial to prepare an incident response plan. Such plan shall include enforcing procedures for potential detecting trade secrets theft, promptly notifying legal counsel or data protection officer about the leakage in order to meet any reporting obligations, and pursuing civil or criminal remedies where appropriate.
Last, but not least, it is important to review or audit periodically all preventive measures, such as security controls, the effectiveness of policies and training effectiveness, and who has access to sensitive information, including trade secrets.
An effective trade secrets strategy protection requires a combination of legal protections, technical controls, organizational practices, and a healthy workplace culture. No single measure is sufficient on its own.
The consequences of inadequate protection may extend far beyond legal disputes.This may include:
- loss of competitive advantage;
- reduced market share;
- diminished company valuation;
- reputational damage;
- increased cybersecurity risks;
- costly litigation;
- loss of investor confidence;
- disclosure of proprietary technologies.
In many industries, confidential know-how represents years of research and substantial financial investment. Once disclosed publicly, it often cannot be restored to its original level of exclusivity.
As such, trade secret protection should not be viewed as the sole responsibility of the legal department. Effective protection requires cooperation across the entire organization, including management, human resources, information technology, compliance, cybersecurity, and business operations. Only a coordinated, organization-wide approach can ensure that valuable confidential information remains protected and qualifies for legal protection as a trade secret.