Personalized access credentials (passwords) are one of the typical means of protecting digitally stored trade secrets from unauthorized access. The Regional Court of Nuremberg-Fürth recently ruled that such access credentials may themselves constitute trade secrets. In its well-reasoned decision, the court thus addressed the classification of information as a trade secret within the meaning of Section 2 no. 1 of the German Act on the Protection of Trade Secrets (GeschGehG) in two distinct ways. (Regional Court of Nuremberg-Fürth, Judgment of Dec. 27, 2024, Case No. 19 O 556/24, available here).
Facts of the case
The plaintiff operates a database that, among other things, provides continuously updated overviews of dates and legislation in health policy. The plaintiff’s customers include a total of 90 different companies and organizations from the healthcare industry. Access to the database is only possible after entering into a license agreement.
The defendant entered into a license agreement that permits use by ten users for an annual fee of 15,000 euros. The agreement expressly stipulates that only those individuals who are in a service, employment, or training relationship with the defendant are authorized users. The respective users must be named individually, although changes are permitted at any time. Each user receives a unique password from the plaintiff. Both the defendant and the individual users are prohibited from disclosing the passwords to third parties.
An employee of the defendant – with the defendant’s consent – disclosed his password to employees of an affiliated company. After the plaintiff learned of this disclosure (presumably by chance), he asserted claims for injunctive relief, damages, and disclosure, citing, among other things, claims under the GeschGehG.
The compilation of information in a database may constitute a trade secret
Section 2 no. 1 GeschGehG sets forth three requirements for the existence of a trade secret: The information must not be known in the relevant circles or readily accessible and must therefore have independent economic value. Furthermore, the information must be subject to appropriate confidentiality measures, and the owner must have a legitimate interest in maintaining confidentiality.
With regard to the plaintiff’s database, there are – even if the defendant assesses the situation differently – only a few issues to consider in this regard: The structured collection of data may have a confidential nature, even if the data itself is publicly accessible. The decisive factor in this regard is that the specific compilation is not publicly accessible. This, incidentally, also corresponds to the assessment in the Federal Court of Justice (BGH) decision “MOVICOL-Zulassungsantrag” (judgment of February 23, 2012, I ZR 136/10), in which the trade secret comprised a specific selection and compilation of publicly available studies and information on a particular topic.
The fact that as many as 90 companies and organizations have access to the database does not, either, negate its confidential nature. The court clarifies that the information in the database is not readily accessible because the plaintiff grants access only to those individuals who enter into a corresponding contract with him, agree to confidentiality obligations, and pay a substantial fee for the right to use the database. The information is therefore not accessible without a significant investment of time and money. The economic value of the database is evident from the fact that the defendant was willing to set a license fee of 15,000 euros. The Regional Court also had no doubt regarding the appropriateness of the (detailed) additional protective measures.
Even (merely) the individualized access credentials to a database can constitute a trade secret
Of particular interest is the assessment of passwords – that is, the confidentiality measures themselves – as (additional) trade secrets within the meaning of Section 2 no. 1 GeschGehG:
The court first clarifies that access credentials are also “information” and can therefore, in principle, constitute a trade secret. However, the question arises, in particular, as to whether the confidentiality measure – that is, the access credentials to the database – possesses an independent economic value. For this to be the case, it is sufficient that the disclosure of the information would entail economic disadvantages for the holder of the secret (Alexander in: Köhler/Feddersen, UWG, 43rd ed., 2025). The success of the business model in this case depended precisely on the plaintiff’s ability to control access to the database via the access credentials, as this is the only way the licensing model can be successful. If anyone could access the database, then no one would need a license. The court adds that it is a matter of record that passwords are traded on the black market, which further supports their economic value. They therefore have an economic value of their own.
Appropriate confidentiality measures were also in place for the access credentials: By stipulating in detail in the contract that individuals who were to receive access credentials must, first, be in a service, employment, or training relationship with the license holder; second, be reported to the plaintiff; and third, that the disclosure of passwords is contractually prohibited, the access credentials constitute a trade secret.
Conclusion: Well-drafted contracts provide enhanced protection for database operators
With regard to access data, the exact terms of the agreement are crucial. Such data may, but need not, have independent secret value. The assessment would likely be different if there were no individualization of authorized users. The assessment would also differ if the user were able to choose a personal password. In that case, the licensor would no longer be the “owner” of the information pursuant to Section 2 No. 2 GeschGehG (Hauck, GRUR-Prax 2025, 162).
Another interesting question is whether the protection of a password-protected database is limited due to the sheer number of authorized users.
The ruling by the Regional Court of Nuremberg-Fürth makes it clear that information is not considered generally known or readily accessible merely because a large group of employees or external parties is aware of it or has access to it. The decisive factor is whether disclosure is controlled and whether the data is accessible without significant time or cost. Therefore, even information from the legal database “beck-online” – which, according to its own statements, has more than 50,000 users – can constitute trade secrets, provided that the disclosure of the access credentials and the information in the database is controlled. Access to “beck-online” is password-protected following the conclusion of a contract, using the access credentials assigned to the customer by the publisher. If the subscription is taken out for multiple users, each authorized user receives their own login credentials and password. Beck-online also requires its customers to keep login credentials and passwords confidential and to prevent unauthorized use by third parties (Section 5.1 of the Terms and Conditions). Consequently, even information from databases with a particularly large user base, such as beck-online, can constitute trade secrets.
The decision has significant practical implications because it substantially strengthens the protection of specialized databases with a customer base that is still reasonably manageable. With appropriate contract drafting, operators can invoke the GeschGehG in addition to potential claims for breach of contract. This offers comprehensive procedural advantages: In addition to the triple damages calculation, it facilitates the enforcement of claims for disclosure. Furthermore, local jurisdiction may lie with the court at the infringer’s place of business, which – depending on the court’s location – is an attractive option. Finally, it should not be overlooked that if the disclosure of a password is classified as a violation of the GeschGehG, criminal proceedings are also possible (Section 23 GeschGehG). Whether this is a sensible tactic in the case of a customer is a decision the operator must make for itself. In any case, the options available on this basis are significantly stronger than in the case of a mere breach of contract.