Protecting confidential business information

Question
How do I protect confidential business information?

Protecting confidential business information is an important area where several legal tools and practical measures work together. Here is a structured overview of the main options available under the law of England and Wales.

What counts as confidential information:

Confidential business information can include trade secrets, customer lists, pricing strategies, supplier terms, financial data, technical know-how, algorithms, product designs, business plans, and similar material. The key legal requirement is that the information must have the necessary quality of confidence, meaning it is not public knowledge and the holder treats it as confidential. This comes from the well-established principles in Coco v AN Clark (Engineers) Ltd [1969].

Contractual protection:

1. Non-disclosure agreements (NDAs) are the single most common tool. These should clearly define what information is confidential, who is bound, the duration of the obligation, permitted uses, and the consequences of breach. NDAs can be mutual or one-way depending on the relationship.

2. Employment contracts should contain express confidentiality clauses. These are important because implied duties of confidence exist during employment but become much weaker after employment ends. Post-termination restrictive covenants, such as non-compete, non-solicitation, and non-dealing clauses, can help but must be reasonable in scope and duration to be enforceable. Overly broad restrictions risk being struck down entirely.

3. Consultancy, supplier, and partnership agreements should all contain tailored confidentiality provisions. Do not rely on generic templates without considering what information is actually at risk in each relationship.

Equitable duty of confidence:

Even without a contract, the equitable doctrine of confidence can protect information if three conditions are met: the information has the necessary quality of confidence, it was imparted in circumstances importing an obligation of confidence, and there was unauthorised use or disclosure. This provides a safety net but is harder to enforce than a clear contractual term, so it should not be relied upon as the primary safeguard.

Trade Secrets (Enforcement, etc.) Regulations 2018:

These regulations implemented the EU Trade Secrets Directive and remain in force. They provide a specific statutory framework for protecting trade secrets, defined as information that is secret, has commercial value because it is secret, and has been subject to reasonable steps to keep it secret. The regulations provide remedies including injunctions, damages, and orders for delivery up or destruction of infringing goods. They also set a limitation period of six years from the date of the unlawful acquisition, use, or disclosure.

Practical internal measures:

Legal protections are only as strong as the practical steps you take to demonstrate that you treated the information as confidential. Courts will look at what reasonable steps you took. Key practical measures include:

1. Marking documents as confidential where appropriate.
2. Restricting access to sensitive information on a need-to-know basis.
3. Using password protection, encryption, and secure storage for digital and physical records.
4. Conducting regular training so that employees and contractors understand their obligations.
5. Controlling and monitoring access to IT systems and data.
6. Having clear policies on use of personal devices, email, cloud storage, and removable media.
7. Implementing proper exit procedures when employees or contractors leave, including return of materials and reminders of ongoing obligations.

Intellectual property rights:

Where the confidential information is also capable of protection as a patent, registered design, copyright, or database right, consider whether formal IP registration or reliance on those rights adds an additional or alternative layer of protection. Patents require public disclosure, so there is a strategic choice between patent protection and keeping something as a trade secret.

Enforcement and remedies:

If confidential information is misused, the main remedies are:

1. Interim injunctions, which can be sought urgently to prevent further disclosure or use. Speed is essential here; delay in acting can undermine your case.
2. Final injunctions to restrain ongoing or threatened misuse.
3. Damages or an account of profits.
4. Delivery up or destruction of confidential materials.
5. In serious cases, search orders or freezing orders may be available.

Before launching court proceedings, consider whether a well-drafted cease and desist letter might resolve the matter, or whether the evidence needs to be preserved first.

Key things to be aware of:

The biggest practical weaknesses tend to be vague or poorly drafted contractual terms, failure to treat the information as confidential internally, and delay in taking action when a breach is suspected. Courts are far more sympathetic to claimants who can demonstrate a consistent and serious approach to protecting their information.

If you can share more detail about the particular context, for example whether this relates to employees, a business partner, a potential investor, or a specific suspected breach, I can give more targeted guidance.

Was this helpful?
527 people found this helpful

Ready to stop guessing?

The above is just an example answer. Sign up now to get personalised guidance and ask follow-up questions based on your own situation. Bring your legal issue, your contract, or your question. Lawyer Destroyer gives you clear, practical guidance so you can move forward with confidence.