Trade secrets: how to keep them secret, legally
A trade secret stays legally protected only as long as you treat it like a secret. In the US, the UK, the EU and most other places, the law protects valuable business information that isn’t generally known, but only if you’ve taken reasonable steps to keep it confidential. In practice that means limiting who sees it, putting confidentiality duties in writing, and keeping enough records to prove both if it ever ends up in court.
What counts as a trade secret
Most legal systems use the same three tests. The information has to be secret, meaning it isn’t generally known or easy to find in your industry. It has to be commercially valuable because it’s secret. And you have to have made a real effort to keep it that way.
That covers far more than a secret recipe. Think about a coffee roaster in Portland with 30 wholesale customers. Its roast profiles, the prices it pays three small farms in Colombia, and its list of cafés (with volumes and discounts) are all likely trade secrets. So is what it learned the hard way, like which roasting approaches failed. Typical examples for a small business:
- Customer lists with contacts, order history and pricing
- Pricing models, margins and how you bid
- Source code, algorithms and system design
- Processes, formulas and supplier terms
- Product roadmaps, unreleased designs and marketing plans
- Negative know-how: what you tried and found doesn’t work
There’s no registration, no fee and no expiry date. Protection can last for decades. The catch is that you carry the burden of proving, after the damage is done, that you actually protected it.
The law behind it, briefly
In the US, trade secrets are protected by state law (nearly every state has adopted a version of the Uniform Trade Secrets Act) and by the federal Defend Trade Secrets Act, which lets you sue in federal court. The EU harmonized the basics with a directive in 2016. The UK has its own trade secrets regulations alongside the older law of breach of confidence, and Canada and Australia rely mainly on breach of confidence and contract.
The wording differs, but courts everywhere look hard at how you treated the information. Even where “reasonable steps” isn’t a formal test, a business that left its trade secrets on a shared drive open to every contractor, and never asked anyone to sign anything, is going to struggle.
Reasonable steps when you don’t have an IT department
Nobody expects a twelve-person agency to run bank-grade security. What courts do expect is that you did something sensible and did it consistently. A realistic baseline looks like this.
Access
- Know where your most valuable information lives. A one-page list is enough.
- Give access on a need-to-know basis. Your junior designer doesn’t need the full client pricing sheet.
- Turn on logging in the tools you already pay for (your email suite, file storage, CRM) so you can see who downloaded what.
- Use multi-factor authentication, and remove access on someone’s last day, not a month later.
Labels and policies
- Mark the sensitive documents as confidential. Don’t mark everything. If the lunch menu says “Confidential,” the label stops meaning anything.
- Write a short confidentiality policy and get people to acknowledge it.
- Cover it in onboarding, and keep a note that you did.
Leavers
- Remind departing staff of their obligations in writing.
- Collect devices and get written confirmation that company files have been returned or deleted.
- Check access logs for unusual downloads in the weeks before someone leaves.
The contracts that do most of the work
When a dispute starts, the first thing anyone asks for is the paperwork. You’ll usually want several layers:
- Employment contracts with a confidentiality clause that keeps applying after the job ends.
- Contractor and consultant agreements with confidentiality terms and an IP assignment, so what they build for you is yours.
- NDAs before you share anything with potential partners, investors, suppliers or buyers.
- Customer and supplier contracts that limit how each side uses the other’s information.
Two details get missed a lot. In the US, if you want the full set of remedies under the Defend Trade Secrets Act against an individual, your agreements with employees, contractors and consultants need a notice about whistleblower immunity. Leave it out and you can lose the right to extra damages and attorney fees against that person. And watch for a residuals clause in NDAs from bigger companies. It lets their people use whatever they remember from your information, which quietly guts protection for know-how.
Restrictive covenants are a separate tool, and a patchy one. A non-compete can keep a key person away from a rival for a while, but California voids most employee non-competes, several other US states restrict them heavily, and the FTC’s attempt at a nationwide ban was blocked in court and later dropped. In the UK they have to be reasonable in scope and length to stand up. A non-solicitation clause covering customers and staff is often easier to enforce and more useful day to day.
What trade secret law won’t stop
Protection is narrower than most owners assume. In most places it’s perfectly legal for someone to:
- Come up with the same thing on their own. Independent development isn’t misappropriation.
- Reverse engineer a product they bought legitimately, unless a valid contract says they can’t.
- Use their general skill and experience. A former employee can take what they learned about doing the job well. They can’t take your specific confidential information.
If a competitor could work out your secret just by buying your product and taking it apart, a patent may be the better route, assuming the invention qualifies.
| Trade secret | Patent | |
|---|---|---|
| Registration | None | Application, examination and fees |
| How long it lasts | As long as it stays secret | Usually 20 years from filing |
| Disclosure | Must stay confidential | Published to the world |
| Stops independent invention | No | Yes |
| Best for | Processes, data and know-how nobody can see from the product | Inventions competitors could copy from the product itself |
When a secret walks out the door
Say your sales manager resigns on a Friday, and on Monday you notice she exported all 2,300 CRM contacts, pricing notes included, the week before. Move quickly. Courts are more willing to grant urgent orders to businesses that act fast.
- Preserve evidence. Secure her laptop, email account and the access logs before anything gets wiped or reassigned.
- Work out exactly what was taken and why it qualifies as a trade secret.
- Pull the contracts and check the confidentiality, return-of-materials and survival terms.
- Consider a firm letter to her and, where appropriate, to her new employer.
- If the harm is serious and ongoing, talk to a lawyer about injunctive relief to stop the information being used while the dispute plays out.
Don’t sit on it. The statute of limitations for trade secret claims varies by jurisdiction and usually runs from when you found out, or should have found out, about the misuse. Delay also makes a judge wonder how much the secret really mattered to you.
Next steps
- Name your five most valuable pieces of confidential information and check who can access each one today.
- Review your employee, contractor and NDA templates for confidentiality, IP ownership and, in the US, the whistleblower notice.
- Write a one-page exit checklist and use it every time someone leaves.
- Before your next pitch or partnership talk, start from a mutual NDA or one-way NDA template and adapt it to the deal.
You can check NDAs and contractor agreements for weak confidentiality terms or a buried residuals clause with LegalWolf.
This article is general information, not legal or tax advice. Laws differ between countries and states and change over time, so check the rules that apply to you or speak to a qualified professional.