
Sharing your secrets with staff can be an occupational hazard. You need to trust them with your clients, your pricing, your systems, and the stuff you spent years building for them to do their jobs, but it’s extremely annoying when they resign, shake your hand and take everything with them.
Before you fire off an angry email at 11pm, stop and collect your evidence. Work out exactly what's gone and how you know.
If you have an IT Partner, get them on the case to help you do this and if the offending employee is still employed by you, lock down their access to your system before they can take anything else.
Save your evidence somewhere they can't reach. The moment someone realises they've been caught, and they still have access to your system, evidence has a funny way of disappearing.Lock it down first, confront second.
Check their contract
Dig out their contract of employment and/or confidentiality agreement that you issued to them. You're looking for three things:
1. A confidentiality clause - the one that says"our confidential information stays confidential, during your employment and after it."
2. A restrictive covenant - the clause stopping them dealing with clients, staff and suppliers for a set period.
3. An intellectual property clause - the one confirming that work created for you belongs to you, not them.
If those clauses are there and properly drafted, you're in a stronger position, particularly if they have signed the agreement(s).
No clause? You still have some protection
Even if their contract is a two-line letter from 2015 with nothing useful in it or there is one, but it’s not signed, employees still owe you an implied duty of confidence. Your genuinely confidential information, such as client lists, trade secrets, the real commercially sensitive information, is protected. It's a weaker position than a watertight signed contract, but not hopeless.
The best next step: a firm letter
Nine times out of ten, a strongly worded factual letter that makes them realise the game is up is sufficient to mitigate the risk of misuse of your IP.
A good letter does three things: it reminds them, clearly, of the obligations they're under. It demands they return or permanently delete everything, including any copies. And it asks them to confirm in writing that they've done it by providing a signed undertaking to you.
Keep it calm and factual. No ranting or threats that you won't follow through on. A measured letter that quietly demonstrates you know exactly what they took and exactly what your rights are is far more impactful than a furious one. Most people fold the moment they realise this isn't going to quietly blow over.
When they don't play ball
Sometimes they ignore you, or worse, they're already using your data to chase your clients. That's when you escalate and this is the point to get a solicitor involved rather than going it alone.
Your options include a formal cease and desist letter before action, an application to court for an injunction (an order forcing them to stop using or disclosing the information), an order for delivery up or deletion of the data, and where they've used your material to get a head start, a springboard injunction, which is designed to remove the unfair advantage they gained by cheating. You can also pursue damages for any losses their breach has caused you.
These are the heavy, expensive options and in most cases you won't need them. But it helps enormously to know they exist - and to let the person who took your files know about them too.
Handling a data privacy breach
If what they took includes personal data such as customer contact details, staff records, anything with names and numbers attached you may have a data protection issue on your hands as well as a confidentiality one and there is an obligation on you to handle the data breach properly. If in doubt, flag it early and take advice on whether it's reportable and what you need to do to comply with your GDPR duties.
And next time - shut the door on the way out
Once the dust settles, review your contracts to ensure that they contain clear confidentiality, IP and restrictive covenant clauses that are fit for purpose and tailored to your business.
You should also review your offboarding process and include a data risk assessment for leavers if you don’t already carry one out.
If someone is going to take your data, they often do it before they resign and so it’s worth checking your systems as soon as you get the resignation. If you need someone to work their notice period, keep a close eye on their activities, particularly if they are going to work for a competitor and/or remain in your sector.
Consider when to turn off access to your systems and data. Access is the tap. Turn it off and the data stops flowing.
This blog is general guidance, not legal advice for your specific situation. If you're dealing with an ex-employee who's taken your data, get in touch and we'll help you handle it properly.