Under Section 2 no. 1 b) of the German Act on the Protection of Trade Secret (GeschGehG), information is protected as a trade secret only if the lawful owner subjects it to “confidentiality measures appropriate under the circumstances.” In the digital workplace, this raises the question of what requirements must be met when sending information via email.
Background
In the spring, the Higher Regional Court of Düsseldorf addressed the question of whether sending information via unencrypted email made that information public (Case No. I-15 U 37/20). In doing so, the court rejected the assumption of public disclosure on the grounds that sending an email does not lead to general public knowledge of the information and that, using fair means, access to the email correspondence cannot be readily obtained. Due to the specific circumstances of the case, the court expressly did not have to address the requirements now set forth in Section 2 GeschGehG. However, the case demonstrates that sending unencrypted emails not only concerns the requirements of Section 2 no. 1 a) GeschGehG but also raises the question of whether adequate confidentiality measures have been implemented in accordance with Section 2 no. 1 b) of the same Act.
Access to email messages
Handling (potential) trade secrets in email correspondence poses particular risks to the confidentiality of information. The exchange of emails takes place through a multi-step technical process in which third parties, in addition to the sender and recipient, may intervene. The sending of an email involves not only the individuals involved but also, at the technical level, various email software programs, the hardware used, and, in particular, various servers. Third parties can therefore exploit various vulnerabilities to disclose and access the content of the message.
To technically prevent unauthorized access, sending encrypted email messages is recommended. Here, a distinction must be made between two types of encryption: transport encryption and end-to-end encryption (for more details, see the website of the Federal Office for Information Security). Transport encryption is now used automatically- that is, without user intervention and, in some cases, without the user’s knowledge – by the majority of email providers. It encrypts the email at the various intermediate stages of its transmission path. However, this path does not run directly from the sender to the recipient but passes through various nodes of the connected servers. The email is then encrypted exclusively along the “transmission path” between these stages. No encryption takes place at the recipient’s end, the sender’s end, or at the time of storage at any of the various nodes. Third parties can access the message at these points via a so-called “man-in-the-middle attack” and view it in unencrypted form.
End-to-end encryption works differently. It does not apply to the transport segments, but to the email itself. In this case, the sender (or the sender’s local software) encrypts the message which the recipient then decrypts. The encryption remains in effect throughout the entire transmission path between the recipient and the sender, making it significantly more difficult for third parties to access the message’s content (more detailed information on the differences in encryption techniques can be found at Digitalization & Law).
Requirements for proportionality
The question now is when and to what extent the encryption of email messages must be ensured. Section 2 no. 1 b) GeschGehG stipulates that appropriate confidentiality measures must be selected depending on the individual case. This case-by-case assessment must be conducted in accordance with objective evaluation criteria and does not require either “optimal protection” or “extreme security” (see also the Higher Regional Court of Düsseldorf, decision of March 11, 2021, Case no.: 15 U 6/20 [unpublished]; regarding the evaluation criteria, see also the previous article).
In the specific context of email encryption, one could also draw on the parallel assessment of email encryption involving personal data under data protection law (you can read more about this at Digitalization & Law).
The Federal Classification Directive (VSA) provides another point of reference. It serves to protect classified information in federal agencies and institutions. The federal states have issued their own, but uniform, directives for state authorities. The VSA establishes a tiered system that sets out the requirements for confidentiality measures. Section 55 (1) VSA stipulates that all classified information must be encrypted when transmitted electronically.
Encryption should therefore always be used when handling trade secrets as well. The choice of specific technology should be based on the importance of the secret. The use of transport encryption should be the norm. If the trade secrets are of greater importance, end-to-end encryption must be used. Finally, one must question whether particularly important secrets should be sent via email at all. For “crown jewels,” other transmission methods may be appropriate even in the age of the digitized workplace.
Conclusion
In the current state of the art, the use of transport encryption appears to have become standard practice. When using a suitable provider, encryption occurs automatically without the individual sender having to initiate their own technical processes. Even the transmission of “less important” trade secrets should always include transport encryption to comply with the requirements of Section 2 no. 1 b) GeschGehG.
However, it does not yet appear to be standard practice to require end-to-end encryption, which is technically more complex in every case. When transmitting particularly important trade secrets, the “crown jewels”, however, such encryption is to be expected. To ensure that confidentiality measures can be verified even in the event of legal proceedings, they should also be adequately documented.