Trade Secret Protection Before a Lawsuit

Trade secret protection depends on conduct before a dispute. A business that treats valuable information as confidential only after an employee leaves or a transaction fails may have difficulty establishing that the information qualified as a trade secret when the alleged misappropriation occurred.

The Texas Uniform Trade Secrets Act and the federal Defend Trade Secrets Act protect information that derives actual or potential economic value from not being generally known or readily ascertainable through proper means. Both statutes also require the owner to have taken reasonable measures under the circumstances to keep the information secret.

Those requirements make preparation part of the claim. The owner needs evidence identifying the information, explaining its value, documenting the measures used to protect it, and connecting the defendant to an acquisition, disclosure, or use that meets the statutory definition of misappropriation.

What Qualifies as a Trade Secret

Texas law recognizes many forms of information as potential trade secrets. The statutory definition includes business, scientific, technical, economic, and engineering information, as well as formulas, designs, prototypes, plans, compilations, programs, methods, processes, financial data, and customer or supplier lists.

A statutory category isn't enough by itself. The information must derive economic value from its secrecy, and the owner must use reasonable measures to preserve that secrecy. Public information, ordinary industry knowledge, and information readily ascertainable through lawful means don't become trade secrets merely because a company calls them confidential.

Texas also recognizes independent development and lawful reverse engineering as proper means of acquiring information. Trade secret law protects secrecy against improper acquisition, disclosure, or use. It doesn't grant an exclusive right against someone who develops the same information independently or discovers it through another lawful method.

The business should identify its claimed secrets with enough detail to distinguish them from public information and an employee's general knowledge. Descriptions such as "business methods," "customer information," or "technical know how" may be too broad unless the company identifies the particular information within those categories.

A Claim Requires More Than Valuable Information

A Texas misappropriation claim requires more than evidence that the information was valuable and reasonably protected. The claimant also needs ownership or the right to enforce rights in the trade secret and evidence of acquisition, disclosure, or use that satisfies the statutory definition of misappropriation.

Improper means include theft, bribery, misrepresentation, electronic espionage, and a breach or inducement of a duty to maintain secrecy. Misappropriation may also occur when someone acquires a secret while knowing or having reason to know that another person obtained it through improper means.

The federal statute applies when the trade secret relates to a product or service used or intended for use in interstate or foreign commerce. It provides original jurisdiction in federal district court but doesn't eliminate a parallel claim under Texas law.

The distinction between access and misappropriation is important. In Galderma Laboratories, L.P. v. Brenner, the Texas Business Court found that past access to confidential information and later employment with a competitor didn't establish actual or threatened misappropriation of the asserted trade secrets. The evidence didn't show current possession, copying, transfer, disclosure, or use of the information.

Identifying the Information Before a Dispute

A trade secret program begins with an inventory. The business should identify the information it regards as secret, who owns it, where it is stored, who receives access, and why secrecy provides economic value.

The inventory doesn't need to disclose the secret itself in a broadly available policy. It should describe the information with enough precision to support internal controls and later testimony. The description may identify a particular pricing model, manufacturing process, source code repository, customer analysis, product plan, or combination of data.

The business should also separate its own information from material received from customers, vendors, licensors, and transaction partners. Contractual duties owed to those parties may require controls different from the measures used for information the company itself generated.

An inventory also exposes inconsistent treatment. A business may discover that information labeled confidential is available to every employee, that former workers retain access, or that the same information appears in public marketing materials.

Matching the Measures to the Information and Risk

Neither statute requires perfect secrecy. The question is whether the owner used reasonable measures under the circumstances, which makes the analysis specific to the information, the business, and the risks involved.

Sensitive information ordinarily requires access limited according to job responsibilities. Password protection, encryption, multifactor authentication, permission records, download restrictions, and access logs may support that structure when they fit the system and the information.

Physical records may require locked storage, controlled work areas, visitor procedures, and limits on copying or removal. A business that permits unrestricted access to confidential files may have difficulty reconciling that practice with a later claim that the same information was closely guarded.

Labels such as "Confidential" or "Trade Secret" may help communicate how information must be handled. A label isn't mandatory in every case, however, and it doesn't transform public or unprotected information into a trade secret. The company's actual practices remain more important than the label alone.

Consistency across systems and departments is part of the analysis. Restrictions that apply only to one copy of a document may accomplish little when identical information appears in an open folder, an unrestricted collaboration platform, or a presentation distributed outside the company.

Contracts Support the Secrecy Record

Confidentiality and nondisclosure agreements help define who may receive information and how the recipient may use it. They are one part of the reasonable measures analysis, not an automatic condition of protection or a substitute for actual controls.

The agreement should identify the protected categories with enough precision for the relationship. It should also state the permitted purpose, authorized recipients, required safeguards, disclosure exceptions, and the obligations that apply when the relationship ends.

Return and destruction provisions should account for company devices, personal devices used with authorization, cloud storage, email, backups, and records that must be retained by law. The agreement should also address compelled disclosure and the procedure for notifying the owner when legally permitted.

A business sharing information with a vendor or transaction partner may need restrictions on subcontractors and affiliates. Access should remain limited to people working on the permitted purpose, and the recipient should remain responsible for downstream compliance to the extent stated in the agreement.

Federal law imposes a separate drafting requirement. Under 18 U.S.C. § 1833(b), an employer must provide notice of federal whistleblower immunity in agreements governing trade secrets or other confidential information that were entered into or updated after May 11, 2016. The statute permits a cross reference to a policy containing the required reporting provisions.

For this requirement, an employee includes an individual working as a contractor or consultant. An employer that omits the notice may not recover exemplary damages or attorney fees under the DTSA in an action against the individual who didn't receive it.

Training and Employee Departures

Policies and agreements are more useful when employees understand them. Training should explain which information requires protection, where it is stored, who may receive it, and how to report an accidental disclosure or suspected misuse.

The business should document attendance and retain the operative version of each policy and agreement. Those records help establish what instructions applied when an employee received access.

Departure procedures should begin promptly when employment ends. Appropriate steps may include disabling access, collecting company property, preserving relevant account records, reviewing recent downloads or transfers, and reminding the employee of continuing contractual duties.

The review must distinguish protected information from the employee's general knowledge, skill, and experience. Section 134A.003 of TUTSA prevents an injunction from prohibiting a person from using general knowledge, skill, and experience acquired during employment.

Suspicion alone shouldn't become an accusation. The company should preserve evidence and investigate what happened before asserting that an employee or competitor possesses or used a trade secret.

Vendors and Business Transactions

Businesses disclose sensitive information during outsourcing arrangements, licensing negotiations, investments, acquisitions, and other transactions. Each disclosure should have a defined purpose and an identified group of recipients.

A staged disclosure process may reduce exposure. The company may provide general information first and reserve source code, pricing details, customer level data, or technical methods for a subsequent diligence stage with tighter access.

A controlled data room can record who viewed or downloaded material. Those records are especially useful when several bidders, advisers, lenders, or consultants participate in the transaction.

When negotiations end, the parties should follow the agreement's return or destruction procedure. The disclosing party should also close data room access and retain the records needed to document what each recipient received.

Responding to Suspected Misappropriation

The first response should preserve evidence. Relevant sources may include access logs, email, file transfer records, collaboration platforms, company devices, security alerts, personnel records, and communications with the suspected recipient.

The company should issue an appropriate litigation hold and obtain legal and forensic advice before altering devices or accounts. An improvised investigation may overwrite evidence, exceed the company's authority, or interfere with a later forensic examination.

The investigation should identify the specific information at issue and determine whether the suspected person acquired, disclosed, or used it. It should also assess how the information was protected and whether any disclosure occurred through proper means or with authorization.

Texas and federal claims generally must be filed within three years after the misappropriation was discovered or should have been discovered through reasonable diligence. Under both statutes, continuing misappropriation is treated as a single claim for limitations purposes.

Remedies Depend on the Evidence

TUTSA permits an injunction against actual or threatened misappropriation. A Texas injunction may not prevent a person from using general knowledge, skill, and experience. Any restriction must fit the information and conduct supported by the evidence.

Texas damages may include actual loss and unjust enrichment that wasn't included in the calculation of actual loss. A court may instead impose liability based on a reasonable royalty for unauthorized disclosure or use.

If the claimant establishes willful and malicious misappropriation by clear and convincing evidence, a court may award exemplary damages of no more than twice the compensatory damages. TUTSA also permits a discretionary attorney fee award for a bad faith claim, a bad faith motion concerning an injunction, or willful and malicious misappropriation.

The DTSA provides comparable damages and injunction remedies. Its employment protections prevent an injunction from barring a person from entering an employment relationship and require any employment conditions to rest on evidence of threatened misappropriation rather than merely on information the person knows.

Federal law also permits an ex parte seizure order in extraordinary circumstances. The applicant must submit a verified complaint or affidavit and satisfy detailed statutory requirements, including why ordinary injunctive relief would be inadequate, why immediate and irreparable injury is likely, what property the defendant possesses, and why notice would risk destruction, concealment, or removal. The remedy is far narrower than an ordinary request to preserve evidence.

Protection Is an Operating Practice

A trade secret program should fit the information and the way the business operates. An elaborate written policy has limited value when employees routinely ignore it, while practical restrictions consistently applied may supply persuasive evidence of reasonable measures.

The strongest record combines identification, limited access, appropriate contracts, training, departure procedures, and prompt investigation of suspected disclosures. Each part supports the same conclusion that the business treated the information as secret before litigation began.

Trade secret protection is therefore daily operating practice rather than an emergency response after information disappears. By the time a lawsuit begins, the conduct that determines whether the information qualified for protection has usually occurred.

This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.

Need advice tied to your business issue?

Share the issue. Get direct attorney review. Receive a concrete recommendation.

Submit an Inquiry