Case law on reasonable confidentiality measures

Legal uncertainty persists for holders of trade secrets regarding the specific requirements for “reasonable confidentiality measures” within the meaning of Section 2 no. 1 b) of the German Act on the Protection of Trade Secret (GeschGehG). The interpretation of the concept of “reasonableness” is currently based on only a few court decisions.

It is clear from the explanatory memorandum to the directive and the law that the adequacy of protective measures must be assessed by taking a number of factors into account:

  • Value of the trade secret
  • Development costs
  • nature of the information
  • importance of the information to the company
  • size of the company
  • standard confidentiality measures within the company
  • method of identifying the information
  • contractual provisions with employees and business partners.

What this means in concrete terms must ultimately be decided by the courts on a case-by-case basis. We have summarized the current state of affairs.

Case law in Germany

German courts have considered the following to be appropriate confidentiality measures:

  • IT policies stipulating that the email system may be used exclusively for business purposes within the employment relationship (Baden-Württemberg Regional Labor Court, 4 SaGa 1/21)
  • A prohibition on removing internal company data in any analog or digital form from the company premises (Baden-Württemberg Regional Labor Court, 4 SaGa 1/21)
  • Establishment of a corporate compliance system with clearly defined audit responsibilities (Baden-Württemberg Regional Labor Court, 4 SaGa 1/21)
  • Disclosure of information only to individuals who need it (“need-to-know”) and who are aware that they are subject to a confidentiality agreement (Baden-Württemberg Regional Labor Court, 4 SaGa 1/21; Stuttgart Higher Regional Court, Case No.: 2 U 575/19, Schaumstoffsysteme)
  • Prohibition on storing data on private storage media without password protection (Stuttgart Higher Regional Court, Case No.: 2 U 575/19, Schaumstoffsysteme)
  • Securing paper documents against access by unauthorized persons by locking the documents or the room (Stuttgart Higher Regional Court, Case No.: 2 U 575/19, Schaumstoffsysteme)
  • Building security through door locking with access via an intercom system (Higher Regional Court of Düsseldorf, Case No.: 15 U 6/20, GRUR-RS 2021, 17483 [not publicly accessible])
  • Confidentiality agreement remaining in effect after termination of employment and the obligation to return all company documents, data storage media, copies, etc., upon leaving the company (Higher Regional Court of Düsseldorf, Case No.: 15 U 6/20, GRUR-RS 2021, 17483 [not publicly accessible]; regarding the confidentiality agreement: Baden-Württemberg Regional Labor Court, 4 SaGa 1/21)
  • Work instructions regarding the use of company-owned smartphones, such as a prohibition on installing apps without the administrator’s consent, mandatory password protection, SIM card lock, and data deletion via the WIPE function in the event of smartphone loss (Higher Regional Court of Düsseldorf, Case No.: 15 U 6/20, GRUR-RS 2021, 17483 [not publicly accessible])
  • Securing digital data via a firewall, a secure VPN connection, and a login function with an individual username and password; tailoring sharing permissions and access rights to data (Düsseldorf Higher Regional Court, Case No.: 15 U 6/20, GRUR-RS 2021, 17483 [not publicly accessible])
  • Indicating that the data is protected by adding a label to the data, including in analog form (Higher Regional Court of Düsseldorf, Case No.: 15 U 6/20, GRUR-RS 2021, 17483 [not publicly accessible])
  • Review of existing measures in cases of suspected unauthorized removal, consistent prosecution of violations, and adaptation of the relevant systems (Hamm Higher Regional Court, 4 U 177/19 – not final)

Case Law Abroad

It is also informative to consider foreign court decisions, some of which have already addressed this issue at an earlier stage. This is due, on the one hand, to the fact that compliance with appropriate confidentiality measures was already a prerequisite for the recognition of a trade secret. On the other hand, in the case of EU member states, the Trade Secrets Directive was implemented at an earlier date.

Practical Tip

At this time, a certain degree of caution is still required when assessing one’s own confidentiality measures. However, a consideration of the overall circumstances may well lead to the conclusion that simple access restrictions satisfy the requirement of Section 2 no. 1 b) GeschGehG. Ultimately, however, the necessity of a measure always depends on the value of the secret – the much-cited Crown Jewels must, of course, be secured accordingly (click here to visit the Tower of London’s website).

The issue discussed here is also of scientific significance. For a detailed discussion, see also: Leistner, WRP 2021, 835.