Skip to content

Trade Secrets and Non-Disclosure Agreements

Legal Aspects of Technology Management - NIT Northern Institute of Technology Management, Hamburg · part of my Technology Management MBA · study notes for revision.


This session begins with a scenario rather than a lecture. We are told to imagine that we work for the ACO Group in Germany, that contract negotiations are running with another company, and that the negotiations concern the sale of important patents belonging to our own company. Our supervisor then splits the room: one group has to draft the non-disclosure agreement, one has to work out the reasonable steps required by Article 2(1) of Directive (EU) 2016/943 and analyse what the Data Act means for our contracts, and one has to draft the content of a cloud agreement. Everybody is told to read the Directive and the German trade secrets material carefully before drafting anything.

The reason for setting it up that way becomes obvious once the law is on the table. A trade secret is not a right that somebody grants you. Nobody registers it, nobody examines it, and there is no certificate to wave at an infringer. It exists only for as long as three conditions hold at the same time, and the third of those conditions is entirely about what you did. If your company never built a system of confidentiality, the information is simply not a trade secret in law, and the claim you wanted to bring against the person who walked off with it does not exist. That is a striking place for a manager to end up: the protection is lost through your own inaction rather than taken away by anybody.

So this chapter has two halves that fit together. The first is the law itself, the definition, what counts as lawful and unlawful, and what a court can order. The second is the practical build, the record of trade secrets, the classification, the protective measures and the confidentiality agreements you conclude with employees and outside partners. The group exercise is exactly the join between them.

Group 1draft the non-disclosure agreement
Group 2undertake the reasonable steps under Art. 2(1) and analyse contract needs under the Data Act
Group 3draft the content of a cloud agreement
The setting for all three: employees of the ACO Group in Germany, negotiating with another company over the sale of important patents held by their own company.

The instructions to each group were quite specific.

  • Everyone. Read Directive (EU) 2016/943 and the session contents carefully before drafting, and read the summary of and introduction into German trade secrets law that was uploaded for the class.
  • Group 1. Start from the old non-disclosure agreement supplied with the course, complete the missing parts so that the agreement fits ACO and the requirements now in force, propose suitable additions to the contract text, and present it to the class. The prompt adds one pointed question: consider whether reverse engineering should be excluded.
  • Group 2. Draft the appropriate record of trade secrets for ACO, taking into account the type of trade secrets, the classification of each one, a risk assessment, and the protective measures taken. Separately, read and analyse the Data Act and work out what kind of clauses agreements should contain with respect to data.
  • Group 3. Read and analyse the cloud agreements, work out which clauses are typical for a cloud agreement, draft the content, and compare it with the cooperation agreement contents from the earlier session, asking whether any clauses are missing and whether the clauses are fair to both parties.

2 · The new law and its German implementation

Section titled “2 · The new law and its German implementation”
Directive (EU) 2016/943, of 8 June 2016protection of undisclosed know-how and business information, that is trade secrets, against their unlawful acquisition, use and disclosure
↓
Transposition deadline: 9 June 2018Art. 19(1): Member States bring the necessary laws into force by that date
↓
German Trade Secrets Act (GeschGehG), in force 26 April 2019implements the Directive into German law
The chain the session asks you to remember. The EU summary adds that the Directive has applied from 5 July 2016 and that national law had to incorporate it by 9 June 2018.

The aim stated in the EU summary is harmonisation: common rules across the Union protecting against the unlawful acquisition, use and disclosure of trade secrets, intended to have a deterrent effect without undermining fundamental rights and freedoms. Article 1(1) also allows Member States to go further and provide more far-reaching protection than the Directive requires, so long as the listed provisions are still complied with.

The headline the session draws from all this is short: the term trade secret has been given a new definition, and it is much more comprehensive than before.

3 · The three-part definition in Article 2(1)

Section titled “3 · The three-part definition in Article 2(1)”

This is the provision to know by heart. Article 2(1) says that trade secret means information which meets all of the following requirements.

(a) It is secret the state of the information
  • Not generally known among, or readily accessible to, persons within the circles that normally deal with the kind of information in question
  • Judged both as a body and in the precise configuration and assembly of its components, so a combination of publicly known parts can still be secret
  • German case law has always ruled secrecy out for obvious facts, meaning those generally known or obtainable without particular effort
(b) It has commercial value because it is secret the reason it is worth protecting
  • The value has to flow from the secrecy, not merely coexist with it
  • The German Act phrases the same idea as information that is not generally known or readily accessible and therefore has economic value
(c) It has been subject to reasonable steps the fact about you
  • Reasonable steps under the circumstances, taken by the person lawfully in control of the information, to keep it secret
  • The German Act calls these appropriate confidentiality measures
  • Fail this limb and the objective interest in secrecy, and with it any claim based on it, ceases to exist
The German addition § 2(1) GeschGehG
  • Not generally known or readily accessible, and therefore of economic value
  • Subject to appropriate confidentiality measures
  • There is a legitimate interest in confidentiality

Three related definitions sit alongside it in Article 2. A trade secret holder is any natural or legal person lawfully controlling a trade secret. An infringer is any natural or legal person who has unlawfully acquired, used or disclosed one. Infringing goods are goods whose design, characteristics, functioning, production process or marketing significantly benefits from trade secrets unlawfully acquired, used or disclosed.

The session is emphatic that the term now covers all types of information within the company. It names scientific, technical, strategic, competitive, financial and business interests, as well as trade secrets and know-how generally. The stated purpose of writing it so broadly was to bring the previous case law into legal form.

One small point that catches people out: the interest in secrecy is not destroyed by your own staff knowing. The materials put it plainly, it is harmless, and has no negative effect, that trade secrets are known and accessible to the company’s own employees.

Category from German case lawExamples the materials give
Technical trade secretsOperating procedures, in particular production and manufacturing processes, operating methods of a plant, service inventions, designs, designations, documents on new technical processes or compositions, models, test protocols, chemical formulae, recipes
Business or commercial secretsSales planning, preferential prices, calculation, liquidity, the order situation, the amount of turnover, names and contact details of customers and suppliers such as address, telephone, fax, mobile number, e-mail and Skype name, customer lists, and even hobbies of customers
Expressly not a secretA planned staff reduction was not classified as a business or trade secret
Expressly not a secretObvious facts, meaning those generally known or obtainable without particular effort

The case law the materials cite for these points is: BGH, judgment of 22 March 2018, case I ZR 118/16; LAG Schleswig-Holstein, decision of 20 May 2015, case 3 TaBV 35/14; BAG, decision of 26 February 1987, case 6 ABR 46/87; BAG, judgment of 15 December 1987, case 3 AZR 474/86; and, for the point about employees and documents in section 6 below, BGH, judgment of 3 May 2001, case I ZR 153/99.

5 · Reasonable steps: the limb that decides cases

Section titled “5 · Reasonable steps: the limb that decides cases”

Because limb (c) is the one you control, it is the one the session spends its practical slides on. The instruction is blunt: active action by the management is required to avoid liability. What follows is the required implementation in the company, in the order the materials set it out.

A system of confidentiality the frame
Establish a system for the protection of trade secrets, rather than a scatter of individual habits.

A person entrusted with secrecy the owner
Appoint a Secret Protection Officer entrusted with the task of protecting trade secrets.

Documentation the evidence
That officer establishes documentation on the company’s trade secrets and maintains it on an ongoing basis.

Recording and categorising the inventory
Record, that is inventory, the trade secrets according to their nature or type, and categorise them according to their significance.

The four building blocks. Note that the documentation is not paperwork for its own sake: it is how you will later show a court that limb (c) was satisfied.

The recommended classification. Trade secrets are put into three classes by the size of the harm their loss would cause.

Class 1, for example top secretdanger to the existence or survival of the enterprise
↓
Class 2, for example secret or confidentialdanger to security, or of permanent or serious disadvantages or damage
↓
Class 3, for example for internal use only, sensitive information or classified informationrisk of short-term or moderate to slight disadvantage or damage
The higher the class, the higher or stronger the need for appropriate protective measures. The materials sum it up as high secret equals high protection.

What else the documentation has to specify. Beyond the inventory and the class, the record should set out the possible acts of injury or violation, the greatest threats or risks, a risk assessment, the groups of persons or specialist departments involved, and the protective measures taken.

Choosing the measures. The materials give six criteria for selecting appropriate protective measures, and they are worth listing because they are how you argue proportionality later.

The value of the trade secretDevelopment costsThe nature of the informationThe importance of the information to the enterpriseThe size of the enterpriseThe implementation costs of the protective measure

The record should then refer to the existing technical and organisational measures. The materials note that for data protection reasons these should already be documented as the company’s standard security measures under Article 25 GDPR, so the secrecy documentation can simply cross-refer to them. On top of that standard, the record should name the further protective measures taken specifically for particular trade secrets: certain designations, access restrictions to certain groups of persons or departments, password protection, encryption, and so on.

Who gets to know. The involved departments or groups of persons belong in the documentation, and the rule for them is narrow. Only those people whose task requires the knowledge should receive it, and, as far as possible and practicable, the knowledge should not be comprehensive but limited to what is absolutely necessary for the task. The principle the materials state is knowledge only when necessary.

Agreements, training and audits. Non-disclosure agreements should be concluded with employees and with external service providers, contractors or business partners. Employees should be regularly trained in handling trade secrets and given concrete instructions. The examples listed are: appropriate labelling of files or documents, locking the screen at the workplace, handling of passwords, securing trade secrets before leaving the workplace, disclosure to third parties only after consultation with the management of the department, transmitting, transporting or carrying trade secrets outside the workplace only if absolutely necessary and then if possible only in encrypted form or in a secure container, and not storing or recording trade secrets on private devices. Finally, there should be regular reviews or audits, for example annually and in the form of a self-audit, of the protective measures taken for the documented trade secrets.

6 · Employees, loyalty and what stays in the head

Section titled “6 · Employees, loyalty and what stays in the head”
What binds the employee even with no special agreement
  • As a matter of principle, employees are bound by the duty of loyalty under labour law to keep trade secrets confidential
  • That duty continues after they leave the company, and it applies even without a special agreement
  • A non-competition clause may apply in addition, prohibiting the employee from using their knowledge and skills for a certain period after leaving
What the employee may still use the limit of the duty
  • Unless a non-competition clause also applies, a departing employee may use the professional knowledge or experience acquired in good faith during the employment
  • This covers only information former employees have kept in their minds
  • Accessing, taking away or stealing documents made during the employment is unauthorised and therefore unlawful
The line the materials draw runs between memory and material. Knowledge carried in a person’s head is theirs to use, absent a non-compete; documents are not.

7 · Lawful and unlawful acquisition, use and disclosure

Section titled “7 · Lawful and unlawful acquisition, use and disclosure”

The Directive sets out both sides. Article 3 lists what is lawful, Article 4 what is not, and Article 5 the situations in which an application has to be dismissed even though a trade secret was involved.

Lawful acquisition Art. 3(1)
  • (a) Independent discovery or creation
  • (b) Observation, study, disassembly or testing of a product or object that has been made available to the public, or that is lawfully in the possession of the acquirer where the acquirer is free from any legally valid duty to limit the acquisition
  • (c) Exercise of the right of workers or workers’ representatives to information and consultation under Union law and national laws and practices
  • (d) Any other practice which, under the circumstances, is in conformity with honest commercial practices
  • Art. 3(2) adds that acquisition, use or disclosure is lawful to the extent it is required or allowed by Union or national law
Unlawful acquisition, use, disclosure Art. 4
  • Acquisition without the holder’s consent is unlawful when carried out by unauthorised access to, appropriation of, or copying of documents, objects, materials, substances or electronic files lawfully under the holder’s control that contain the secret or from which it can be deduced
  • Or by any other conduct considered, under the circumstances, contrary to honest commercial practices
  • Use or disclosure without consent is unlawful by a person who acquired the secret unlawfully, who is in breach of a confidentiality agreement or any other duty not to disclose, or who is in breach of a contractual or other duty to limit the use of the secret
  • It is also unlawful where the person knew or ought to have known that the secret came, directly or indirectly, from someone who was using or disclosing it unlawfully
  • Producing, offering or placing infringing goods on the market, or importing, exporting or storing them for those purposes, counts as unlawful use on the same knowledge test
Article 4(3)(b) is the reason NDAs matter so much here: a breach of the confidentiality agreement is itself what makes the use or disclosure unlawful.

Article 5 exceptions. An application for the measures, procedures and remedies must be dismissed where the alleged acquisition, use or disclosure was carried out for exercising the right to freedom of expression and information under the Charter, including respect for the freedom and pluralism of the media; for revealing misconduct, wrongdoing or illegal activity, provided the respondent acted to protect the general public interest; as disclosure by workers to their representatives where necessary for the legitimate exercise of those representatives’ functions; or for protecting a legitimate interest recognised by Union or national law.

8 · Reverse engineering is lawful unless you exclude it

Section titled “8 · Reverse engineering is lawful unless you exclude it”

This is the single most practical drafting point in the session, and it follows straight from Article 3(1)(b). Taking a product apart to learn how it works is a lawful way to acquire a trade secret. The materials therefore state the rule for drafters directly: in the confidentiality agreement, reverse engineering must be expressly excluded, because it is otherwise generally permitted by law. Reverse engineering is described as the imitation of a product or service through investigation, dismantling, testing and similar means. For German law the materials give the reference as § 3(1) No. 2b GeschGehG.

Article 6 requires Member States to provide measures, procedures and remedies ensuring civil redress, and they must be fair and equitable, not unnecessarily complicated or costly, not entail unreasonable time limits or unwarranted delays, and be effective and dissuasive. Article 7 adds that they must be proportionate, must avoid creating barriers to legitimate trade in the internal market, and must include safeguards against abuse, with the court able to act against an applicant who brings a manifestly unfounded claim abusively or in bad faith.

ProvisionWhat it gives you
Art. 8Member States lay down limitation periods, and the duration must not exceed 6 years
Art. 9Confidentiality during the proceedings: participants may not use or disclose a secret the court has identified as confidential, and the court can restrict access to documents and hearings to a limited number of persons and publish a redacted version of the decision
Art. 10Provisional and precautionary measures: provisional cessation or prohibition of use or disclosure, prohibition of producing, offering, placing on the market, importing, exporting or storing infringing goods, and seizure or delivery up of suspected infringing goods
Art. 11The applicant must satisfy the court with sufficient certainty that a trade secret exists, that the applicant is the holder, and that it has been unlawfully acquired, used or disclosed, or that such conduct is imminent
Art. 12Injunctions and corrective measures on the merits: cessation or prohibition of use or disclosure, prohibition on infringing goods, corrective measures including recall from the market, depriving goods of their infringing quality, destruction or withdrawal, and destruction or delivery up of documents and files embodying the secret, normally at the infringer’s expense
Art. 13The court weighs the circumstances, including the value of the secret and the measures taken to protect it, the infringer’s conduct, the impact, the parties’ and third parties’ legitimate interests, the public interest and fundamental rights; and it may order pecuniary compensation instead of the measures on strict conditions
Art. 14Damages appropriate to the actual prejudice suffered, taking account of lost profits, unfair profits made by the infringer and, in appropriate cases, moral prejudice; alternatively a lump sum based at a minimum on the royalties that would have been due
Art. 15Publication of the decision, at the applicant’s request and the infringer’s expense, while preserving the confidentiality of the secret
Art. 16Sanctions on anyone who fails or refuses to comply with a measure adopted under Articles 9, 10 and 12, including recurring penalty payments, and the sanctions must be effective, proportionate and dissuasive

Two of those rows should change how you manage. Article 11(2)(b) and Article 13(1)(b) both tell the court to look at the measures taken to protect the trade secret when deciding whether to grant relief and how far to go. Your reasonable-steps file is therefore evidence twice over: once to prove the secret exists at all, and again to argue for a strong remedy.

10 · Trade secrets against registered rights such as patents

Section titled “10 · Trade secrets against registered rights such as patents”

The Directive’s own recitals put the choice in strategic terms. Businesses invest in know-how, which recital 1 calls the currency of the knowledge economy, and they have different means of appropriating the results of innovation when openness does not allow full exploitation of the investment. Intellectual property rights such as patents, design rights or copyright are one such means. The other is to protect access to, and exploit, knowledge that is valuable and not widely known, which is the trade secret. Recital 2 adds that businesses of every size value trade secrets as much as patents and other IP rights, that they use confidentiality as a competitiveness and research management tool across information reaching well beyond technology into customer and supplier data, business plans, market research and strategy, and that SMEs rely on them even more. Trade secrets work as a complement or as an alternative to IP rights.

Registered right, for example a patentTrade secret
How it comes into beingGranted as an intellectual property right, and used as one means of appropriating innovation resultsExists only while the three requirements of Art. 2(1) are all met at once
What you must do to keep itThe right, once held, is the thing you rely onYou must keep taking reasonable steps, continuously, or the protection lapses
Reverse engineering by a competitorNot addressed in these materialsLawful under Art. 3(1)(b), so a secret embodied in a marketed product is exposed unless a contract excludes it
Independent creation by a competitorNot addressed in these materialsLawful under Art. 3(1)(a), and you have no claim against them
Range of subject matterIP rights such as patents, design rights, copyrightAll types of information in the company, from manufacturing processes to customer lists and hobbies of customers
How it endsNot addressed in these materialsWhen the information becomes generally known or readily accessible, or otherwise stops meeting Art. 2(1)

11 · Non-disclosure agreements: what the session actually requires

Section titled “11 · Non-disclosure agreements: what the session actually requires”

An NDA is the contractual half of the reasonable-steps duty. It is what turns other people’s obligation to stay quiet into something you can enforce, and Article 4(3)(b) makes the link explicit: use or disclosure in breach of a confidentiality agreement is unlawful under the Directive. Without the agreement you are left arguing about honest commercial practices; with it you can point at a duty the other side accepted.

The requirements the session states for confidentiality agreements are these, and I am listing only what the materials contain.

Conclude them with the right peopleemployees, and external service providers, contractors or business partners
↓
Expressly exclude reverse engineeringimitation of products or services through investigation, dismantling, testing and the like, otherwise generally permitted by law
↓
Attach an abridged record of trade secretsotherwise the legal requirements are not met and the information loses its protection as a trade secret
↓
Keep the record alive behind itongoing maintenance, training and regular audits, because the attachment is only as good as the documentation it summarises
The NDA and the record of trade secrets are one instrument in two parts. The agreement binds the recipient; the attached record identifies what is bound and evidences the reasonable steps.

The situation. You are employees of the ACO Group in Germany. Contract negotiations are under way with another company, and the subject of them is the sale of important patents belonging to your company. Before any real information moves, your supervisor divides the work: Group 1 drafts the non-disclosure agreement, Group 2 undertakes the reasonable steps required by Article 2(1) of Directive (EU) 2016/943 and analyses the contract needs arising from the Data Act, and Group 3 drafts the content of a cloud agreement. Everyone is told to read the Directive and the German trade secrets material first.

What made the setting sharp. A sale negotiation over patents is exactly the moment when the two protection regimes rub against each other. The patents themselves are registered rights, but the material you have to show a buyer during due diligence is not only the patent specifications. It is the manufacturing know-how around them, the test protocols, the cost calculations, the order situation, the customer list. Every one of those is squarely inside the broad definition the session teaches, and every one of them loses its protection the moment you hand it over without reasonable steps in place.

A good answer for Group 1, the NDA. Take the old agreement, and work through it against the requirements now in force. Adapt it so that it binds the counterparty in the negotiation and, on your own side, so that equivalent agreements exist with the employees and external service providers who will handle the data room. Add the express exclusion of reverse engineering, because Article 3(1)(b) makes disassembly and testing lawful by default and the materials say the exclusion must be explicit. Attach the abridged record of trade secrets, since without it the legal requirements are not met and the information can lose its protection. Then present the additions to the class with the reason for each one, which is what the prompt asks for.

A good answer for Group 2, the reasonable steps. Build the record of trade secrets ACO would need. Inventory the secrets by type. Classify each into Class 1 where loss would endanger the existence or survival of the enterprise, Class 2 where it would endanger security or cause permanent or serious damage, and Class 3 where the damage would be short-term or moderate to slight. For each entry, name the possible acts of injury and greatest risks, record a risk assessment, name the departments and groups of persons involved, and list the protective measures taken. Choose those measures against the six criteria: value of the secret, development costs, nature of the information, importance to the enterprise, size of the enterprise, and implementation cost. Cross-refer to the existing technical and organisational measures documented as standard security under Article 25 GDPR, and then add the specific extras, designations, access restrictions, password protection and encryption, for the higher classes, because high secret means high protection. Apply knowledge only when necessary to the data room. Conclude the NDAs, train the people, and schedule the annual self-audit.

Take one plausible ACO secret: the process parameters and test protocols for a drainage channel casting line, the practical know-how that makes the patented design manufacturable at yield. Classify it as Class 1, because losing it to a competitor during a failed sale negotiation would endanger the commercial position the patents are supposed to protect. Here is the reasonable-steps audit I would build for it, with the evidence column being the part people forget.

Measure categoryWhat I would actually put in placeHow I would evidence it later in court
GovernanceAppoint the Secret Protection Officer and make the process file their responsibilityAppointment record, and the officer’s dated maintenance log for the documentation
Inventory and classificationOne entry in the record of trade secrets: type, description, Class 1, owner departmentThe record itself, with version history showing it predates the negotiation
Risk assessmentNamed acts of injury and greatest threats: data-room download, departing process engineer, contractor laptopThe written risk assessment held with the entry
Selection reasoningJustify the measures against the six criteria: value, development costs, nature, importance, company size, implementation costThe reasoning written into the record, which is what shows the steps were reasonable under the circumstances
Technical measuresEncryption at rest and in transit, password protection, access restricted to a named list, watermarked and download-disabled data roomCross-reference to the standard technical and organisational measures documented under Art. 25 GDPR, plus the extra measures logged against this entry
Organisational measuresKnowledge only when necessary: the parameter set split so no single external reviewer sees the whole configuration; disclosure to third parties only after consultation with department managementAccess list, approval records, and the departmental sign-offs
Physical and handlingNo storage on private devices, transport only if absolutely necessary and then encrypted or in a secure container, screens locked, documents labelled with the classTraining material, signed instructions, spot-check records
ContractualNDA with the counterparty, plus NDAs with employees and external service providers touching the data room, reverse engineering expressly excluded, abridged record attachedExecuted agreements with the attachment, and the distribution list showing who signed
TrainingRegular training on handling trade secrets, with the concrete instructions listed in the materialsAttendance records and dated training content
ReviewAnnual self-audit of the protective measures for the documented secretsAudit reports, showing the file was maintained rather than written once

The NDA skeleton that goes with it. Two of these headings come straight from the session materials and the rest are my own drafting suggestions built on them, so I have marked which is which.

From the materials required
An express exclusion of reverse engineering, meaning imitation of products or services through investigation, dismantling, testing and the like; and an abridged record of trade secrets attached as a schedule, which is also what identifies the protected information.

My own additions drafting suggestions
Recipients limited on a knowledge-only-when-necessary basis, mirroring the internal principle; an acknowledgement that the counterparty will handle the material consistently with the attached record; and, because Art. 4(3) makes breach of the agreement the trigger for unlawfulness, a clear statement of the duty not to disclose and the duty to limit use.

Not written here unsourced
Definition and exclusion clauses for confidential information, permitted purpose, duration, return or destruction, contractual penalty, and governing law and forum. These materials do not prescribe them, so I have not presented them as course requirements.

Keeping the sourced and the invented visibly apart is itself good legal hygiene, and it is the honest way to revise from an incomplete deck.
  1. Write down the information itself, precisely. Not our know-how, but this parameter set, this customer list, this calculation. Article 2(1) is tested against a defined body of information, including its precise configuration and assembly, so a vague description cannot be defended.

  2. Test limb (a) honestly. Is it generally known among, or readily accessible to, the people who normally deal with this kind of information? If it is an obvious fact obtainable without particular effort, stop, because there is nothing to protect.

  3. Test limb (b). Does it have commercial value because it is secret? Write the sentence that explains the causal link, since that is what you will have to say later.

  4. Put it in the record and give it a class. Class 1 if losing it endangers the existence or survival of the company, Class 2 if it endangers security or causes permanent or serious damage, Class 3 if the damage is short-term or moderate to slight.

  5. Write the risk assessment. Name the possible acts of injury, the greatest threats, and the departments and groups of persons involved.

  6. Choose protective measures against the six criteria and write the reasoning down: value, development costs, nature of the information, importance to the enterprise, size of the enterprise, implementation cost. The higher the class, the stronger the protection has to be.

  7. Cross-refer to your technical and organisational measures, already documented as standard security under Article 25 GDPR, then add the specific extras for this secret: designations, access restrictions, password protection, encryption.

  8. Narrow the circle to knowledge only when necessary, and remember that your own employees knowing does not harm the interest in secrecy, so the point is need, not paranoia.

  9. Conclude the NDAs with employees and with external service providers, contractors and business partners, expressly exclude reverse engineering, and attach the abridged record.

  10. Train people and audit annually. Regular instruction on labelling, screen locking, passwords, transport and private devices, plus a yearly self-audit, is what turns a one-off document into continuing reasonable steps.

  11. Keep the file, because it is your evidence. Articles 11 and 13 both direct the court to look at the measures taken to protect the secret, so the record decides both whether you have a claim and how strong a remedy you get.

TermWhat it means in plain words
Trade secretInformation that is secret, has commercial value because it is secret, and has been kept secret by reasonable steps; all three at once, under Art. 2(1)
Secret, limb (a)Not generally known among, or readily accessible to, people in the circles that normally deal with that kind of information, judged as a body and in its precise configuration
Commercial value because secret, limb (b)The worth of the information flows from the fact that others do not have it
Reasonable steps, limb (c)The measures the person lawfully in control actually took, under the circumstances, to keep it secret; called appropriate confidentiality measures in the German Act
Trade secret holderAny natural or legal person lawfully controlling a trade secret
InfringerAny natural or legal person who has unlawfully acquired, used or disclosed a trade secret
Infringing goodsGoods whose design, characteristics, functioning, production process or marketing significantly benefits from a trade secret unlawfully acquired, used or disclosed
GeschGehGThe German Trade Secrets Act, in force from 26 April 2019, implementing the Directive into German law
Secret Protection OfficerThe person appointed to be entrusted with protecting trade secrets and maintaining the documentation
Record of trade secretsThe maintained documentation: inventory by type, classification by significance, risks, people involved, and protective measures
Class 1, 2 and 3Danger to the existence of the enterprise; danger to security or permanent or serious damage; risk of short-term or moderate to slight damage
Knowledge only when necessaryOnly people whose task requires the knowledge get it, and only to the extent absolutely necessary
Reverse engineeringImitating a product or service through investigation, dismantling, testing and the like; lawful by default, so it has to be excluded expressly by contract
Non-disclosure agreementThe confidentiality contract concluded with employees and outside partners; breaching it is what makes a disclosure unlawful under Art. 4(3)(b)
Honest commercial practicesThe Directive’s catch-all standard: conduct conforming to it is lawful acquisition, conduct contrary to it is unlawful
Limitation periodThe window for bringing a claim, which Member States set and which under Art. 8 may not exceed 6 years
Corrective measuresCourt orders under Art. 12 such as recall from the market, depriving goods of their infringing quality, destruction or withdrawal, and destruction or delivery up of documents
Article 5 exceptionsFreedom of expression and information, revealing wrongdoing in the public interest, disclosure by workers to their representatives, and protecting a legitimate interest
  1. State the three requirements in Article 2(1) of Directive (EU) 2016/943 and say which of them is normally the one a company loses on, and why.
  2. Which four means of acquiring a trade secret does Article 3(1) treat as lawful, and what does that mean for the drafting of a confidentiality agreement?
  3. Name the three classes recommended for a record of trade secrets and the six criteria for choosing appropriate protective measures.
  4. A software engineer leaves the company. What may they take with them, and what may they not?
  5. Which four situations under Article 5 force a court to dismiss an application, and what is the maximum limitation period under Article 8?
  6. Why do Articles 11 and 13 make your internal documentation worth building even before anything goes wrong?

Next: Cooperation, Service & Cloud Agreements → - the contracts that govern working together.