How can you protect your business’s confidential information?
All businesses have information that it considers to be confidential and valuable to it, whether a secret recipe for ketchup or future pricing strategies. The misuse of that confidential information can be very damaging, even though most misuse is preventable.
What is thought of as confidential information will depend on the type of business. It may include trade secrets, know how, customer/supplier details, design details, manufacturing processes, pricing structures, financial information, research & development and human resources issues (including pay and benefits).
Is confidential information protected in law?
It may come as a shock that confidential information is not automatically protected by law.
In general, if a person has received information in confidence they should not use or disclose it without permission. This duty of confidence relates to information which:
- Is not something which is public property or public knowledge; and
- Is disclosed to the person in a way that gives rise to an obligation of confidence (because of the circumstances, a special relationship between the parties, or by contract.)
This is a common-sense approach. However, it may not give a business the protection it would expect. Ex-employees are not automatically obliged to keep all types of information confidential.
While trade secrets are protected both during and after employment, other information which the business regards as confidential might only be protected during employment. For example, ex-employees may not be restricted from using your customer database for their own purposes, unless they have entered into express contractual obligations not to use or disclose the information after their employment has ended.
What practical steps can you take to protect confidential information?
Identify the risks to your business and consider how you can guard against them:
- What confidential information does your business have?
- Where and how is it stored?
- Who has access to it?
- How might it be lost, revealed or disclosed (inadvertently or deliberately)?
- What damage could the business suffer if the confidential information is lost, revealed or disclosed?This might depend on whose hands it comes into.
- Can the information be protected by intellectual property rights? If so, do these need to be registered, such as patents or trademarks?
Here are some examples:
Risk:
Employees/other members of staff
Action:
- Keep confidential information physically and electronically secure (locked cabinets and offices, password protection and encryption).
- Limit access to only those who have a ‘need to know’.
- Include a confidentiality policy in the staff handbook, supported by regular training.
- Ensure employment contracts/consultancy agreements contain non-disclosure provisions and, where appropriate, restrictive covenants (e.g. non-compete, non-solicitation and non-dealing).
- Consider including garden leave provisions in employment contracts to limit exposure to confidential information during notice periods
Risk:
Disclosure to potential and existing suppliers/customers
Action:
- Robust standard terms of trade can include obligations on your suppliers/customers to safeguard any confidential information you disclose to them and confirm that any related intellectual property rights owned by your business do not transfer to them.
- If your business does have such standard terms of trade, they must be used appropriately so as to be effectively incorporated into contracts your business makes with those suppliers/customers.
- Ensure supply agreements contain detailed confidentiality provisions.
- If the confidential information is particularly sensitive, consider requiring the supplier/customer to enter into a non-disclosure agreement (NDA) before the information is disclosed to them.
- Read carefully any third party NDAs you are asked to sign. For example, the information might need to be labelled “confidential” to be protected under it.
Risk:
Visitors to your premises
Action:
- Where appropriate, ask the visitor to enter into an NDA beforehand/upon arrival.
- Escort/monitor the visitor always.
- Limit their visit to only those areas where they need to go (i.e. away from areas where they may obtain or observe confidential information unless they have a ‘need to know’).
Risk:
Disclosure to agents/distributors
Action:
- Ensure agency/distribution agreements contain detailed confidentiality provisions.
- Consider including a list of individuals who are permitted to receive the information.
- If necessary, those individuals could each sign a specific confidentiality undertaking with the business.
- The confidentiality clause should be expressed to survive the termination of the agreement.
Risk:
Compliance – data protection
Action:
Ensure that you meet applicable legal and regulatory requirements for any personal data:
- Collecting/storing it;
- Disclosing it;
- Putting in place policies, procedures and contracts to protect it.
Often, complacency over possible breaches can make the problem worse. Plan for the worst and it is less likely to occur. If you do discover a breach, act promptly because the longer information remains available, the less ‘confidential’ it is likely to become.