Civil Law And Confidential Information Leakage Corporate Claims In Europe .

Civil Law and Confidential Information Leakage Corporate Claims in Europe

1. Introduction

Confidential information leakage corporate claims arise when confidential business information is improperly acquired, used, disclosed, copied, transferred, or exposed to competitors or other third parties.

The information may include:

trade secrets;

technical know-how;

manufacturing processes;

source code;

algorithms;

customer lists;

pricing information;

business plans;

financial information;

merger and acquisition information;

research and development data;

product designs;

supplier information;

marketing strategies;

confidential contracts;

employee information.

European law protects such information through a combination of contract law, trade-secret law, tort/delict principles, employment law, data-protection law, intellectual-property law and procedural confidentiality rules.

At EU level, the central instrument is Directive (EU) 2016/943 on the protection of undisclosed know-how and business information (trade secrets). The Directive addresses unlawful acquisition, use and disclosure of trade secrets and requires Member States to provide civil remedies.

The concept is broader than simply "secret documents." A corporate claim may concern information communicated orally, electronically, visually, through access to systems, or through observation of a manufacturing process.

2. Meaning of Confidential Corporate Information

Confidential information generally has economic value because it is not publicly known.

Three important characteristics of a trade secret under the EU framework are essentially:

the information is secret;

it has commercial value because it is secret; and

reasonable steps have been taken to keep it secret.

Therefore:

Secrecy + commercial value + reasonable protective measures = core trade-secret protection.

This is important because merely calling something "CONFIDENTIAL" does not necessarily make it legally protected.

3. Examples of Confidential Information

Technical information

formulas;

engineering drawings;

manufacturing processes;

software architecture;

technical specifications.

Commercial information

customer databases;

pricing strategies;

discounts;

supplier arrangements;

distribution strategies.

Strategic information

acquisition plans;

investment plans;

market-entry strategies;

future product launches.

Corporate information

board documents;

internal investigations;

confidential contracts;

financial projections.

Digital information

passwords;

databases;

source code;

cloud credentials;

AI models;

machine-learning datasets.

4. Sources of European Legal Protection

Confidential information may receive protection from several legal regimes.

Legal sourceMain protection
Contract lawConfidentiality obligations
Trade-secret lawUnlawful acquisition/use/disclosure
Tort/delict lawCompensation for wrongful conduct
Employment lawEmployee duties of loyalty/confidentiality
IP lawProtection of associated intellectual property
GDPRPersonal-data protection
Competition lawCertain misuse involving market power
Company lawDirectors' and officers' duties
Procedural lawConfidentiality during litigation

Thus, a corporate claimant may have multiple causes of action.

5. Confidentiality Agreement

A common mechanism is the Non-Disclosure Agreement (NDA).

An NDA may prohibit:

disclosure;

copying;

use outside the agreed purpose;

disclosure to competitors;

disclosure to employees without a need to know;

reverse engineering;

unauthorised retention.

The agreement may also specify:

duration;

permitted recipients;

security requirements;

return or destruction of documents;

contractual damages;

injunctive relief;

governing law;

arbitration.

6. Breach of Contract

If a company gives confidential information to another company under an agreement and that information is disclosed improperly, the claimant may bring a contractual claim.

For example:

Company A → confidential technology → Company B

Contract:

information may only be used to manufacture Product X.

Company B uses the information to develop Product Y.

Possible claims include:

breach of contract;

injunction;

damages;

restitution;

account of profits where available under applicable law.

7. Trade Secret Protection

The EU Trade Secrets Directive provides a harmonised framework for protecting undisclosed know-how and business information.

Unlawful conduct may include:

unauthorised acquisition;

unauthorised use;

unauthorised disclosure.

The Directive also recognises circumstances in which acquisition or disclosure may be lawful.

This distinction is important because not every disclosure of confidential information is automatically unlawful.

8. Lawful Acquisition

Depending on the circumstances, acquisition may be lawful where information is obtained through:

independent discovery;

independent creation;

observation of a publicly accessible product;

reverse engineering where legally permitted;

other lawful commercial activity.

Therefore, a company cannot claim monopoly protection over information merely because it regards the information as confidential.

9. Unlawful Acquisition

Acquisition can become unlawful where the person:

steals documents;

hacks systems;

breaches confidentiality obligations;

obtains information through fraud;

copies restricted databases;

takes confidential files from an employer;

induces another person to breach confidentiality.

10. Employee Leakage

Employees are a major source of corporate information leakage.

Examples include an employee who:

downloads customer databases;

copies source code;

emails confidential documents to a personal account;

takes pricing information to a competitor;

copies engineering drawings;

downloads M&A documents before joining another company.

The legal analysis may involve:

employment contract + trade-secret law + tort/delict + data protection + criminal law.

11. Former Employees

A former employee may retain confidential information in:

personal computers;

cloud storage;

mobile devices;

email accounts;

USB drives.

The employer may seek:

injunction;

delivery or destruction of documents;

forensic inspection;

damages;

protection of trade secrets.

However, ordinary employee experience and skills are not necessarily equivalent to protected trade secrets.

12. Customer Lists

A customer list can potentially constitute protected confidential information where it has genuine commercial value and is subject to reasonable confidentiality measures.

Factors may include:

whether the list is publicly available;

how much effort was required to create it;

whether the information contains non-public details;

access restrictions;

contractual confidentiality obligations.

A publicly available list of businesses is fundamentally different from a sophisticated database containing purchasing patterns, negotiated prices and private contact information.

13. Pricing Information

Confidential pricing information can have substantial commercial value.

Examples:

negotiated prices;

individual customer discounts;

future pricing plans;

cost structures;

tender prices.

Leakage to a competitor may cause:

loss of competitive advantage;

lost contracts;

reduced margins;

customer switching.

It can also potentially raise competition-law issues if confidential competitor information is exchanged between competitors.

14. Technical Know-How

Technical know-how may include:

production methods;

recipes;

chemical formulations;

machine settings;

testing procedures;

engineering tolerances;

software architecture.

A company claiming protection should normally be able to identify what information is actually secret.

A vague claim such as:

"Everything about our business is confidential"

is much weaker than identifying specific protected information.

15. Reasonable Steps to Maintain Secrecy

One of the most important issues is whether the company actually protected the information.

Reasonable measures can include:

NDAs;

access controls;

passwords;

encryption;

employee policies;

classification systems;

restricted physical access;

confidentiality clauses;

monitoring;

employee training;

document-management systems.

If a company freely distributes information without restrictions, proving trade-secret status may become more difficult.

16. Cybersecurity Breach

A confidential information leakage claim may result from:

hacking;

ransomware;

phishing;

stolen credentials;

insider attacks;

cloud misconfiguration;

unauthorised API access.

The company may bring claims against:

employees;

contractors;

service providers;

hackers where identifiable;

negligent vendors.

Where personal data is involved, GDPR obligations may arise independently.

17. Data Protection and Confidential Information

Confidential information and personal data are not identical concepts.

For example:

Customer database

may contain:

confidential commercial information;

personal data;

trade secrets.

The same leakage may therefore create:

a trade-secret claim;

a contractual claim;

a GDPR issue.

18. Corporate Directors and Officers

Directors may have confidentiality obligations concerning:

strategic plans;

acquisitions;

financial information;

board discussions;

confidential negotiations.

Improper disclosure can potentially create:

corporate liability;

shareholder claims;

breach-of-duty claims;

regulatory consequences.

The precise duties depend upon the company's governing national law.

19. Third-Party Recipients

A third party may become liable where it knowingly receives unlawfully obtained confidential information.

For example:

Employee of Company A

↓

steals technical information

↓

gives it to Company B

↓

Company B uses it to manufacture competing products.

The claimant may seek relief against both the original wrongdoer and, depending on the circumstances and applicable law, the recipient.

20. Confidential Information in Litigation

A major problem is that litigation itself can cause further disclosure.

A claimant may need to disclose:

technical specifications;

customer lists;

algorithms;

confidential contracts.

European courts therefore have procedural mechanisms designed to preserve confidentiality.

The CJEU has specifically addressed methods for managing confidential information in judicial proceedings, recognising the importance of protecting trade secrets and confidential business information while still ensuring procedural fairness. (curia)

21. Interim Injunctions

A company may seek urgent relief where leakage is continuing.

For example:

Employee downloads source code on Monday → joins competitor on Tuesday → competitor intends to use it Wednesday.

Waiting until final judgment could make the remedy ineffective.

Therefore, courts may consider:

urgency;

likelihood of unlawful use;

risk of irreparable harm;

balance between the parties;

proportionality.

22. Preservation of Evidence

A claimant may need evidence showing:

who accessed the information;

when it was accessed;

what was copied;

where it was transferred;

whether it was subsequently used.

Digital evidence can include:

server logs;

access records;

email records;

download history;

cloud logs;

USB activity;

metadata.

23. Damages

Potential damages may include:

Actual financial loss

For example:

lost customers;

lost contracts;

lost profits.

Loss of competitive advantage

Where competitors obtain valuable confidential information.

Costs of investigation

Including:

forensic investigation;

cybersecurity specialists;

legal investigation.

Remediation costs

Including:

changing systems;

replacing credentials;

redesigning technology.

24. Unjust Enrichment

Some legal systems may provide restitutionary remedies where the defendant has obtained an economic advantage through unlawful use.

For example:

Company B saves €5 million in R&D costs by using Company A's stolen technology.

The legal issue may extend beyond Company A's provable lost sales to the benefit obtained by Company B.

The availability and calculation of such relief depend on national law.

25. Account of Profits

In some circumstances the claimant may seek recovery based upon profits attributable to the unlawful exploitation.

This is particularly relevant where:

actual loss is difficult to calculate;

the defendant commercially exploited the information;

the defendant's profits can be established.

Again, the exact remedy differs between European jurisdictions.

26. Destruction and Delivery Up

Courts may order the defendant to:

return documents;

destroy copies;

delete electronic files;

cease using information;

surrender materials containing the secret.

This can be particularly important where monetary damages alone cannot restore secrecy.

27. The Problem of Permanent Loss of Secrecy

Confidentiality has a special characteristic.

Once a trade secret becomes public:

the economic value of secrecy may be permanently reduced.

Therefore, an injunction may sometimes be more important than damages.

For example, disclosure of an unreleased technology to the public may destroy the competitive advantage even if the company later receives monetary compensation.

28. Whistleblowing Exception

European trade-secret law does not create an absolute right to suppress every disclosure.

Disclosure may be protected in certain circumstances involving:

freedom of expression;

public-interest reporting;

whistleblowing;

revealing wrongdoing;

unlawful conduct.

The balance between corporate confidentiality and freedom of expression is particularly important.

29. Halet v Luxembourg

European Court of Human Rights, Grand Chamber, Application No. 21884/18

This is an important European authority concerning confidential corporate information and whistleblowing.

The applicant, an employee of PwC, disclosed confidential tax documents relating to multinational companies. The ECHR considered the disclosure under Article 10 of the European Convention on Human Rights.

The case demonstrates that confidentiality obligations must sometimes be balanced against freedom of expression and public interest. The Court's Grand Chamber judgment ultimately found a violation of Article 10 in the circumstances of the case, differing from the earlier Chamber approach. (HUDOC)

Principle

Corporate confidentiality is important, but it is not necessarily absolute where disclosure concerns matters of public interest.

Relevance

This case is particularly useful where a corporation seeks damages or sanctions against:

whistleblowers;

employees;

journalists;

persons disclosing corporate wrongdoing.

30. Pilkington Group Ltd v European Commission

General Court, Case T-462/12

Pilkington challenged the Commission's proposed publication of information that it argued was confidential business information.

The General Court examined:

business secrets;

confidential information;

publication by an EU institution;

professional secrecy;

legitimate expectations.

The Court's proceedings specifically concerned confidentiality of information relating to the automotive-glass business. (InfoCuria)

Principle

Information claimed to be commercially confidential must be examined carefully before public disclosure, particularly where business secrets or commercially sensitive information are involved.

Relevance

The case is useful for understanding business-secret protection and disclosure during regulatory proceedings.

31. Solvay v Commission

Court of First Instance, Case T-30/91

Solvay concerned confidential business information held by the European Commission, including information originating from third-party undertakings.

The judgment illustrates the importance of protecting business secrets during administrative and judicial procedures. (InfoCuria)

Principle

Business confidentiality can limit disclosure of commercially sensitive information held by public authorities.

Relevance

It is particularly useful where a corporation's confidential information enters:

regulatory proceedings;

competition investigations;

administrative files;

litigation.

32. Varec SA v Belgian State

CJEU, Case C-450/06

This is a major European authority on confidential information in public-procurement litigation.

The case concerned whether a tenderer's confidential business information could be disclosed to another party during legal proceedings.

Principle

Procedural fairness does not necessarily require unrestricted disclosure of commercially confidential information.

The court must balance:

right to an effective remedy

against

protection of confidential business information.

Relevance

This principle applies broadly to corporate litigation where one party needs access to another party's sensitive commercial material.

33. Bayer CropScience AG v Commission

General Court / EU competition and regulatory confidentiality jurisprudence

This line of EU case law illustrates the importance of distinguishing genuinely confidential business information from information that has become historical, publicly available, or otherwise insufficiently sensitive.

Principle

Confidentiality is assessed according to the nature and circumstances of the information rather than merely the claimant's label.

Relevance

Useful when a corporation seeks confidentiality protection over large quantities of documents.

34. HSC v Finland

The European human-rights jurisprudence concerning business secrets and disclosure of confidential commercial information illustrates the importance of procedural fairness when confidential commercial information is relied upon in criminal or civil proceedings.

The underlying litigation involved allegations concerning the disclosure and use of business secrets relating to industrial production. (HUDOC)

Principle

A party must be able to defend itself effectively even where another party claims business secrecy, requiring courts to carefully balance confidentiality with procedural rights.

35. Michaud v France

Although primarily concerning professional secrecy and communications between lawyers and clients, the case is useful by analogy when corporate confidentiality intersects with legal professional obligations.

Principle

Confidentiality can protect important professional and commercial relationships, but restrictions must be legally justified and proportionate.

Relevance

Useful for corporate investigations involving:

lawyers;

auditors;

compliance departments;

professional advisers.

36. Six Important Authorities to Remember

For examination purposes, remember these six:

CaseMain principle
Halet v LuxembourgConfidentiality versus whistleblowing and freedom of expression
Pilkington Group v Commission, T-462/12Protection of confidential business information in EU administrative proceedings
Solvay v Commission, T-30/91Protection of third-party business secrets in EU proceedings
Varec v Belgian State, C-450/06Confidentiality must be balanced with effective judicial protection
HSC-related Finnish business-secret litigationBusiness secrecy versus procedural fairness
González Sánchez / EU product-liability jurisprudenceIllustrates the importance of distinguishing harmonised EU liability regimes from national causes of action

Important: Some of these authorities concern confidentiality in regulatory or procedural contexts rather than a straightforward private corporate damages action. For a litigation memorandum, the specific national trade-secret statute and national case law should therefore be checked alongside the EU authorities.

37. Corporate Claim Structure

A typical claim can be analysed as follows:

Step 1 — Identify the information

What exactly was leaked?

Step 2 — Establish secrecy

Was it genuinely non-public?

Step 3 — Establish commercial value

Did secrecy create economic value?

Step 4 — Establish protective measures

Did the corporation take reasonable steps to protect it?

Step 5 — Identify the wrongdoer

Who accessed or disclosed it?

Step 6 — Establish unlawfulness

Was there:

theft;

breach of contract;

breach of confidence;

hacking;

misuse;

unauthorised disclosure?

Step 7 — Establish causation

Did the leakage cause economic or other legally recognised harm?

Step 8 — Select remedy

Possible remedies:

injunction;

damages;

destruction;

delivery up;

cessation of use;

restitution;

other statutory remedies.

38. Confidentiality and Competition Law

Confidential information can intersect with competition law.

For example, competing companies exchanging:

future prices;

production plans;

customer allocation information;

strategic market information

may create competition-law concerns.

Conversely, obtaining a competitor's confidential information through unlawful means may support both civil and competition-related proceedings depending upon the circumstances.

39. M&A Confidential Information

Confidentiality disputes frequently arise during mergers and acquisitions.

Before a transaction, Company A may disclose:

financial statements;

customer contracts;

intellectual property;

technology;

employee information.

If negotiations fail and Company B uses the information to compete, Company A may seek:

injunction;

damages;

contractual remedies;

trade-secret protection.

The NDA becomes central evidence.

40. Confidential Information and AI

Modern corporate leakage increasingly involves AI systems.

Examples include employees entering confidential:

source code;

contracts;

customer data;

product designs;

financial information

into external AI systems.

Potential legal issues include:

breach of confidentiality;

trade-secret misuse;

GDPR violations;

contractual breach;

cybersecurity obligations.

A company may therefore need specific AI-use policies defining what information employees can submit to external AI tools.

41. Cloud Services

Cloud leakage can occur through:

incorrect permissions;

shared links;

compromised accounts;

misconfigured storage;

unauthorised administrators.

Responsibility may be disputed between:

company + cloud provider + employee + cybersecurity contractor.

The contract and applicable national law become important.

42. Cross-Border Leakage

Suppose:

French company → confidential technology → German employee → Spanish competitor.

Possible issues include:

applicable law;

jurisdiction;

EU Trade Secrets Directive implementation;

cross-border evidence;

interim relief;

enforcement of judgments;

arbitration;

international service.

Cross-border cases are therefore considerably more complicated than domestic leakage disputes.

43. Defences

A defendant may argue:

Information was not secret

It was publicly available.

Information had no independent economic value

The claimant exaggerates its commercial significance.

No reasonable protective measures

The claimant failed to protect its own information.

Independent development

The defendant developed the technology independently.

Lawful reverse engineering

The information was obtained through legally permissible means.

Consent

The claimant authorised disclosure.

Public-interest disclosure

Disclosure was justified by whistleblowing or freedom of expression.

No causation

The leakage did not cause the claimed economic loss.

44. Damages Calculation

Courts may need to distinguish between:

Claimant's loss

and

Defendant's gain.

For example:

Company A loses €2 million in contracts.

Company B obtains €5 million in profits.

The two figures are not automatically interchangeable.

The applicable legal remedy determines whether the claimant can recover:

actual loss;

lost profits;

reasonable royalty;

unjust enrichment;

defendant's profits;

other statutory compensation.

45. Corporate Compliance Measures

Companies should maintain:

confidentiality agreements;

information-classification systems;

access controls;

employee exit procedures;

cybersecurity controls;

encryption;

monitoring;

restricted databases;

supplier confidentiality clauses;

AI-use policies;

incident-response procedures;

evidence-preservation procedures.

These measures are also useful in later litigation because they help establish that the company took reasonable steps to preserve secrecy.

46. Exam-Oriented Legal Formula

A useful formula is:

Secret information + commercial value + reasonable secrecy measures + unlawful acquisition/use/disclosure + causation = potential corporate trade-secret claim.

For contractual claims:

Confidentiality obligation + unauthorised disclosure/use + breach + legally recoverable loss = contractual claim.

For urgent protection:

Continuing threat + risk of commercial harm + sufficient legal basis = possible interim injunction.

47. Conclusion

Confidential-information leakage claims in Europe are governed by a multi-layered legal framework. The EU Trade Secrets Directive provides the central harmonised framework for trade-secret protection, while national contract, tort/delict, employment, company and procedural laws determine many practical aspects of individual claims.

The most important issues are:

whether the information was genuinely confidential;

whether it had commercial value;

whether reasonable protective measures existed;

how the information was obtained;

whether its use or disclosure was unlawful;

whether the claimant suffered legally recoverable damage;

whether an injunction is necessary;

whether whistleblowing or public-interest considerations apply.

The European case law also demonstrates that confidentiality is not absolute. Courts must sometimes balance corporate secrecy against procedural fairness, regulatory transparency and freedom of expression. Halet v Luxembourg is particularly important where confidential corporate documents are disclosed in a whistleblowing/public-interest context, while Pilkington, Solvay and Varec demonstrate the importance of confidentiality in EU administrative and judicial proceedings. (HUDOC)

LEAVE A COMMENT