To protect trade secrets, the holder must take appropriate protective measures, including in the area of work organization. In a recently issued decision, the Saxony Regional Labor Court clarified that repeated violations of organizational protective measures justify the termination of an employee (Judgment of April 7, 2022 – 9 Sa 250/21).
The Clean Desk Policy as a protective measure
As is now widely known, the key innovation of the Act on the Protection of Trade Secrets (GeschGehG) is the requirement that the trade secret holder must take appropriate protective measures (Section 2 no. 1 (a) GeschGehG). It is not possible to make a blanket statement about which measures are appropriate in individual cases. We have already reported on various decisions that offer some guidance here and here.
In the area of work organization, strict adherence to the “need-to-know” principle is a basic standard. Furthermore, the trade secret holder must ensure that employees handle trade secrets with care in their daily work to prevent the risk of third parties gaining knowledge of them from the outset. A “clean desk policy”, which requires employees not to leave trade secrets lying around in plain sight or recognizable form when leaving their desks, is often a sensible and integral part of organizational trade secret protection.
The case decided by the Saxony Regional Labor Court (LAG Sachsen) involved a bank where a “Work Instruction: Procedure for Information Security in the Workplace and Clean Desk Policy” was in effect. This work instruction contained the following provisions:
Care must be taken to ensure that sensitive or confidential information- whether in paper form or on the screen – cannot be viewed by third parties.
When leaving the workstation or when it is unattended:
– Confidential files, data storage media, or hardware containing information must be properly locked away or disposed of in accordance with procedures. For laptops, the following point applies.
– Care must be taken to ensure that the respective device is always locked, meaning at least the screen saver is active.
– Printouts containing confidential information and data storage media must not be left out in the open but must be locked away in a drawer, cabinet, or similar secure location.
– The key to rolling file cabinets or cabinets containing confidential information must not be left at the workstation or attached to the locks.
– Passwords must never be stored in plain sight (on a sticky note attached to the monitor or in an easily accessible location, such as under the desk mat, in an unlocked desk drawer, or under the keyboard or mouse pad).
– At the end of the workday, employees must log out of and shut down IT systems. Exceptions apply to systems that, for technical or organizational reasons, must not be rebooted.
Failure to comply with the Clean Desk Policy as grounds for termination
The employee, who filed a wrongful termination lawsuit to challenge her ordinary termination for cause, was employed by the company as a loan officer in the mortgage lending division. She had repeatedly left paper loan files and printed emails on her desk despite being absent or had failed to lock them away.
In some cases, loan numbers were noted on slips of paper that were not properly disposed of. Furthermore, the employee had repeatedly failed to log out of the IT systems at the end of the workday. Due to these breaches of duty, the employee had already received several warnings and formal notices before she was terminated for cause following yet another breach of duty.
The Saxony Regional Labor Court (and previously the Leipzig Labor Court) considers the termination to be justified. There is no doubt regarding the clarity of the provisions in the work instructions. Nor were these merely breaches of secondary duties. Even if the individual violations were not serious, there were repeated violations despite relevant and properly issued warnings and reprimands. The company was therefore entitled to use the further violation as grounds for termination, which also proved to be proportionate based on a negative prognosis regarding future conduct.
Practical assessment of the GeschGehG
The primary purpose of the Clean Desk Policy in this company was less the protection of trade secrets than compliance with data protection regulations. However, the Clean Desk Policy cited above, with exactly this wording, could also be applied exclusively for the purpose of protecting trade secrets in a research department.
It is important to note for practical purposes that a violation of data protection regulations was not, in any case, objected to by third parties, meaning that apparently no data was leaked to the outside. The court also clarified that the open display of individual loan numbers was of minor relevance. This did not alter the fact that a breach of duty had occurred. Finally, the court did not attach any significance to the fact that the premises where the employee worked were not open to the public and could only be accessed with an access card. There is good reason to believe that a labor court would, at the very least, not attach any less importance to the protection of trade secrets. Repeated violations can therefore justify termination for cause of employees who do not take trade secret protection seriously, even in the absence of a concrete threat to or actual loss of trade secrets.