Civil Law And Confidential Information Leakage Corporate Claims In Europe .
Civil Law and Confidential Information Leakage Corporate Claims in Europe
1. Introduction
Confidential information leakage corporate claims arise when confidential business information is improperly acquired, used, disclosed, copied, transferred, or exposed to competitors or other third parties.
The information may include:
trade secrets;
technical know-how;
manufacturing processes;
source code;
algorithms;
customer lists;
pricing information;
business plans;
financial information;
merger and acquisition information;
research and development data;
product designs;
supplier information;
marketing strategies;
confidential contracts;
employee information.
European law protects such information through a combination of contract law, trade-secret law, tort/delict principles, employment law, data-protection law, intellectual-property law and procedural confidentiality rules.
At EU level, the central instrument is Directive (EU) 2016/943 on the protection of undisclosed know-how and business information (trade secrets). The Directive addresses unlawful acquisition, use and disclosure of trade secrets and requires Member States to provide civil remedies.
The concept is broader than simply "secret documents." A corporate claim may concern information communicated orally, electronically, visually, through access to systems, or through observation of a manufacturing process.
2. Meaning of Confidential Corporate Information
Confidential information generally has economic value because it is not publicly known.
Three important characteristics of a trade secret under the EU framework are essentially:
the information is secret;
it has commercial value because it is secret; and
reasonable steps have been taken to keep it secret.
Therefore:
Secrecy + commercial value + reasonable protective measures = core trade-secret protection.
This is important because merely calling something "CONFIDENTIAL" does not necessarily make it legally protected.
3. Examples of Confidential Information
Technical information
formulas;
engineering drawings;
manufacturing processes;
software architecture;
technical specifications.
Commercial information
customer databases;
pricing strategies;
discounts;
supplier arrangements;
distribution strategies.
Strategic information
acquisition plans;
investment plans;
market-entry strategies;
future product launches.
Corporate information
board documents;
internal investigations;
confidential contracts;
financial projections.
Digital information
passwords;
databases;
source code;
cloud credentials;
AI models;
machine-learning datasets.
4. Sources of European Legal Protection
Confidential information may receive protection from several legal regimes.
| Legal source | Main protection |
|---|---|
| Contract law | Confidentiality obligations |
| Trade-secret law | Unlawful acquisition/use/disclosure |
| Tort/delict law | Compensation for wrongful conduct |
| Employment law | Employee duties of loyalty/confidentiality |
| IP law | Protection of associated intellectual property |
| GDPR | Personal-data protection |
| Competition law | Certain misuse involving market power |
| Company law | Directors' and officers' duties |
| Procedural law | Confidentiality during litigation |
Thus, a corporate claimant may have multiple causes of action.
5. Confidentiality Agreement
A common mechanism is the Non-Disclosure Agreement (NDA).
An NDA may prohibit:
disclosure;
copying;
use outside the agreed purpose;
disclosure to competitors;
disclosure to employees without a need to know;
reverse engineering;
unauthorised retention.
The agreement may also specify:
duration;
permitted recipients;
security requirements;
return or destruction of documents;
contractual damages;
injunctive relief;
governing law;
arbitration.
6. Breach of Contract
If a company gives confidential information to another company under an agreement and that information is disclosed improperly, the claimant may bring a contractual claim.
For example:
Company A → confidential technology → Company B
Contract:
information may only be used to manufacture Product X.
Company B uses the information to develop Product Y.
Possible claims include:
breach of contract;
injunction;
damages;
restitution;
account of profits where available under applicable law.
7. Trade Secret Protection
The EU Trade Secrets Directive provides a harmonised framework for protecting undisclosed know-how and business information.
Unlawful conduct may include:
unauthorised acquisition;
unauthorised use;
unauthorised disclosure.
The Directive also recognises circumstances in which acquisition or disclosure may be lawful.
This distinction is important because not every disclosure of confidential information is automatically unlawful.
8. Lawful Acquisition
Depending on the circumstances, acquisition may be lawful where information is obtained through:
independent discovery;
independent creation;
observation of a publicly accessible product;
reverse engineering where legally permitted;
other lawful commercial activity.
Therefore, a company cannot claim monopoly protection over information merely because it regards the information as confidential.
9. Unlawful Acquisition
Acquisition can become unlawful where the person:
steals documents;
hacks systems;
breaches confidentiality obligations;
obtains information through fraud;
copies restricted databases;
takes confidential files from an employer;
induces another person to breach confidentiality.
10. Employee Leakage
Employees are a major source of corporate information leakage.
Examples include an employee who:
downloads customer databases;
copies source code;
emails confidential documents to a personal account;
takes pricing information to a competitor;
copies engineering drawings;
downloads M&A documents before joining another company.
The legal analysis may involve:
employment contract + trade-secret law + tort/delict + data protection + criminal law.
11. Former Employees
A former employee may retain confidential information in:
personal computers;
cloud storage;
mobile devices;
email accounts;
USB drives.
The employer may seek:
injunction;
delivery or destruction of documents;
forensic inspection;
damages;
protection of trade secrets.
However, ordinary employee experience and skills are not necessarily equivalent to protected trade secrets.
12. Customer Lists
A customer list can potentially constitute protected confidential information where it has genuine commercial value and is subject to reasonable confidentiality measures.
Factors may include:
whether the list is publicly available;
how much effort was required to create it;
whether the information contains non-public details;
access restrictions;
contractual confidentiality obligations.
A publicly available list of businesses is fundamentally different from a sophisticated database containing purchasing patterns, negotiated prices and private contact information.
13. Pricing Information
Confidential pricing information can have substantial commercial value.
Examples:
negotiated prices;
individual customer discounts;
future pricing plans;
cost structures;
tender prices.
Leakage to a competitor may cause:
loss of competitive advantage;
lost contracts;
reduced margins;
customer switching.
It can also potentially raise competition-law issues if confidential competitor information is exchanged between competitors.
14. Technical Know-How
Technical know-how may include:
production methods;
recipes;
chemical formulations;
machine settings;
testing procedures;
engineering tolerances;
software architecture.
A company claiming protection should normally be able to identify what information is actually secret.
A vague claim such as:
"Everything about our business is confidential"
is much weaker than identifying specific protected information.
15. Reasonable Steps to Maintain Secrecy
One of the most important issues is whether the company actually protected the information.
Reasonable measures can include:
NDAs;
access controls;
passwords;
encryption;
employee policies;
classification systems;
restricted physical access;
confidentiality clauses;
monitoring;
employee training;
document-management systems.
If a company freely distributes information without restrictions, proving trade-secret status may become more difficult.
16. Cybersecurity Breach
A confidential information leakage claim may result from:
hacking;
ransomware;
phishing;
stolen credentials;
insider attacks;
cloud misconfiguration;
unauthorised API access.
The company may bring claims against:
employees;
contractors;
service providers;
hackers where identifiable;
negligent vendors.
Where personal data is involved, GDPR obligations may arise independently.
17. Data Protection and Confidential Information
Confidential information and personal data are not identical concepts.
For example:
Customer database
may contain:
confidential commercial information;
personal data;
trade secrets.
The same leakage may therefore create:
a trade-secret claim;
a contractual claim;
a GDPR issue.
18. Corporate Directors and Officers
Directors may have confidentiality obligations concerning:
strategic plans;
acquisitions;
financial information;
board discussions;
confidential negotiations.
Improper disclosure can potentially create:
corporate liability;
shareholder claims;
breach-of-duty claims;
regulatory consequences.
The precise duties depend upon the company's governing national law.
19. Third-Party Recipients
A third party may become liable where it knowingly receives unlawfully obtained confidential information.
For example:
Employee of Company A
↓
steals technical information
↓
gives it to Company B
↓
Company B uses it to manufacture competing products.
The claimant may seek relief against both the original wrongdoer and, depending on the circumstances and applicable law, the recipient.
20. Confidential Information in Litigation
A major problem is that litigation itself can cause further disclosure.
A claimant may need to disclose:
technical specifications;
customer lists;
algorithms;
confidential contracts.
European courts therefore have procedural mechanisms designed to preserve confidentiality.
The CJEU has specifically addressed methods for managing confidential information in judicial proceedings, recognising the importance of protecting trade secrets and confidential business information while still ensuring procedural fairness. (curia)
21. Interim Injunctions
A company may seek urgent relief where leakage is continuing.
For example:
Employee downloads source code on Monday → joins competitor on Tuesday → competitor intends to use it Wednesday.
Waiting until final judgment could make the remedy ineffective.
Therefore, courts may consider:
urgency;
likelihood of unlawful use;
risk of irreparable harm;
balance between the parties;
proportionality.
22. Preservation of Evidence
A claimant may need evidence showing:
who accessed the information;
when it was accessed;
what was copied;
where it was transferred;
whether it was subsequently used.
Digital evidence can include:
server logs;
access records;
email records;
download history;
cloud logs;
USB activity;
metadata.
23. Damages
Potential damages may include:
Actual financial loss
For example:
lost customers;
lost contracts;
lost profits.
Loss of competitive advantage
Where competitors obtain valuable confidential information.
Costs of investigation
Including:
forensic investigation;
cybersecurity specialists;
legal investigation.
Remediation costs
Including:
changing systems;
replacing credentials;
redesigning technology.
24. Unjust Enrichment
Some legal systems may provide restitutionary remedies where the defendant has obtained an economic advantage through unlawful use.
For example:
Company B saves €5 million in R&D costs by using Company A's stolen technology.
The legal issue may extend beyond Company A's provable lost sales to the benefit obtained by Company B.
The availability and calculation of such relief depend on national law.
25. Account of Profits
In some circumstances the claimant may seek recovery based upon profits attributable to the unlawful exploitation.
This is particularly relevant where:
actual loss is difficult to calculate;
the defendant commercially exploited the information;
the defendant's profits can be established.
Again, the exact remedy differs between European jurisdictions.
26. Destruction and Delivery Up
Courts may order the defendant to:
return documents;
destroy copies;
delete electronic files;
cease using information;
surrender materials containing the secret.
This can be particularly important where monetary damages alone cannot restore secrecy.
27. The Problem of Permanent Loss of Secrecy
Confidentiality has a special characteristic.
Once a trade secret becomes public:
the economic value of secrecy may be permanently reduced.
Therefore, an injunction may sometimes be more important than damages.
For example, disclosure of an unreleased technology to the public may destroy the competitive advantage even if the company later receives monetary compensation.
28. Whistleblowing Exception
European trade-secret law does not create an absolute right to suppress every disclosure.
Disclosure may be protected in certain circumstances involving:
freedom of expression;
public-interest reporting;
whistleblowing;
revealing wrongdoing;
unlawful conduct.
The balance between corporate confidentiality and freedom of expression is particularly important.
29. Halet v Luxembourg
European Court of Human Rights, Grand Chamber, Application No. 21884/18
This is an important European authority concerning confidential corporate information and whistleblowing.
The applicant, an employee of PwC, disclosed confidential tax documents relating to multinational companies. The ECHR considered the disclosure under Article 10 of the European Convention on Human Rights.
The case demonstrates that confidentiality obligations must sometimes be balanced against freedom of expression and public interest. The Court's Grand Chamber judgment ultimately found a violation of Article 10 in the circumstances of the case, differing from the earlier Chamber approach. (HUDOC)
Principle
Corporate confidentiality is important, but it is not necessarily absolute where disclosure concerns matters of public interest.
Relevance
This case is particularly useful where a corporation seeks damages or sanctions against:
whistleblowers;
employees;
journalists;
persons disclosing corporate wrongdoing.
30. Pilkington Group Ltd v European Commission
General Court, Case T-462/12
Pilkington challenged the Commission's proposed publication of information that it argued was confidential business information.
The General Court examined:
business secrets;
confidential information;
publication by an EU institution;
professional secrecy;
legitimate expectations.
The Court's proceedings specifically concerned confidentiality of information relating to the automotive-glass business. (InfoCuria)
Principle
Information claimed to be commercially confidential must be examined carefully before public disclosure, particularly where business secrets or commercially sensitive information are involved.
Relevance
The case is useful for understanding business-secret protection and disclosure during regulatory proceedings.
31. Solvay v Commission
Court of First Instance, Case T-30/91
Solvay concerned confidential business information held by the European Commission, including information originating from third-party undertakings.
The judgment illustrates the importance of protecting business secrets during administrative and judicial procedures. (InfoCuria)
Principle
Business confidentiality can limit disclosure of commercially sensitive information held by public authorities.
Relevance
It is particularly useful where a corporation's confidential information enters:
regulatory proceedings;
competition investigations;
administrative files;
litigation.
32. Varec SA v Belgian State
CJEU, Case C-450/06
This is a major European authority on confidential information in public-procurement litigation.
The case concerned whether a tenderer's confidential business information could be disclosed to another party during legal proceedings.
Principle
Procedural fairness does not necessarily require unrestricted disclosure of commercially confidential information.
The court must balance:
right to an effective remedy
against
protection of confidential business information.
Relevance
This principle applies broadly to corporate litigation where one party needs access to another party's sensitive commercial material.
33. Bayer CropScience AG v Commission
General Court / EU competition and regulatory confidentiality jurisprudence
This line of EU case law illustrates the importance of distinguishing genuinely confidential business information from information that has become historical, publicly available, or otherwise insufficiently sensitive.
Principle
Confidentiality is assessed according to the nature and circumstances of the information rather than merely the claimant's label.
Relevance
Useful when a corporation seeks confidentiality protection over large quantities of documents.
34. HSC v Finland
The European human-rights jurisprudence concerning business secrets and disclosure of confidential commercial information illustrates the importance of procedural fairness when confidential commercial information is relied upon in criminal or civil proceedings.
The underlying litigation involved allegations concerning the disclosure and use of business secrets relating to industrial production. (HUDOC)
Principle
A party must be able to defend itself effectively even where another party claims business secrecy, requiring courts to carefully balance confidentiality with procedural rights.
35. Michaud v France
Although primarily concerning professional secrecy and communications between lawyers and clients, the case is useful by analogy when corporate confidentiality intersects with legal professional obligations.
Principle
Confidentiality can protect important professional and commercial relationships, but restrictions must be legally justified and proportionate.
Relevance
Useful for corporate investigations involving:
lawyers;
auditors;
compliance departments;
professional advisers.
36. Six Important Authorities to Remember
For examination purposes, remember these six:
| Case | Main principle |
|---|---|
| Halet v Luxembourg | Confidentiality versus whistleblowing and freedom of expression |
| Pilkington Group v Commission, T-462/12 | Protection of confidential business information in EU administrative proceedings |
| Solvay v Commission, T-30/91 | Protection of third-party business secrets in EU proceedings |
| Varec v Belgian State, C-450/06 | Confidentiality must be balanced with effective judicial protection |
| HSC-related Finnish business-secret litigation | Business secrecy versus procedural fairness |
| González Sánchez / EU product-liability jurisprudence | Illustrates the importance of distinguishing harmonised EU liability regimes from national causes of action |
Important: Some of these authorities concern confidentiality in regulatory or procedural contexts rather than a straightforward private corporate damages action. For a litigation memorandum, the specific national trade-secret statute and national case law should therefore be checked alongside the EU authorities.
37. Corporate Claim Structure
A typical claim can be analysed as follows:
Step 1 — Identify the information
What exactly was leaked?
Step 2 — Establish secrecy
Was it genuinely non-public?
Step 3 — Establish commercial value
Did secrecy create economic value?
Step 4 — Establish protective measures
Did the corporation take reasonable steps to protect it?
Step 5 — Identify the wrongdoer
Who accessed or disclosed it?
Step 6 — Establish unlawfulness
Was there:
theft;
breach of contract;
breach of confidence;
hacking;
misuse;
unauthorised disclosure?
Step 7 — Establish causation
Did the leakage cause economic or other legally recognised harm?
Step 8 — Select remedy
Possible remedies:
injunction;
damages;
destruction;
delivery up;
cessation of use;
restitution;
other statutory remedies.
38. Confidentiality and Competition Law
Confidential information can intersect with competition law.
For example, competing companies exchanging:
future prices;
production plans;
customer allocation information;
strategic market information
may create competition-law concerns.
Conversely, obtaining a competitor's confidential information through unlawful means may support both civil and competition-related proceedings depending upon the circumstances.
39. M&A Confidential Information
Confidentiality disputes frequently arise during mergers and acquisitions.
Before a transaction, Company A may disclose:
financial statements;
customer contracts;
intellectual property;
technology;
employee information.
If negotiations fail and Company B uses the information to compete, Company A may seek:
injunction;
damages;
contractual remedies;
trade-secret protection.
The NDA becomes central evidence.
40. Confidential Information and AI
Modern corporate leakage increasingly involves AI systems.
Examples include employees entering confidential:
source code;
contracts;
customer data;
product designs;
financial information
into external AI systems.
Potential legal issues include:
breach of confidentiality;
trade-secret misuse;
GDPR violations;
contractual breach;
cybersecurity obligations.
A company may therefore need specific AI-use policies defining what information employees can submit to external AI tools.
41. Cloud Services
Cloud leakage can occur through:
incorrect permissions;
shared links;
compromised accounts;
misconfigured storage;
unauthorised administrators.
Responsibility may be disputed between:
company + cloud provider + employee + cybersecurity contractor.
The contract and applicable national law become important.
42. Cross-Border Leakage
Suppose:
French company → confidential technology → German employee → Spanish competitor.
Possible issues include:
applicable law;
jurisdiction;
EU Trade Secrets Directive implementation;
cross-border evidence;
interim relief;
enforcement of judgments;
arbitration;
international service.
Cross-border cases are therefore considerably more complicated than domestic leakage disputes.
43. Defences
A defendant may argue:
Information was not secret
It was publicly available.
Information had no independent economic value
The claimant exaggerates its commercial significance.
No reasonable protective measures
The claimant failed to protect its own information.
Independent development
The defendant developed the technology independently.
Lawful reverse engineering
The information was obtained through legally permissible means.
Consent
The claimant authorised disclosure.
Public-interest disclosure
Disclosure was justified by whistleblowing or freedom of expression.
No causation
The leakage did not cause the claimed economic loss.
44. Damages Calculation
Courts may need to distinguish between:
Claimant's loss
and
Defendant's gain.
For example:
Company A loses €2 million in contracts.
Company B obtains €5 million in profits.
The two figures are not automatically interchangeable.
The applicable legal remedy determines whether the claimant can recover:
actual loss;
lost profits;
reasonable royalty;
unjust enrichment;
defendant's profits;
other statutory compensation.
45. Corporate Compliance Measures
Companies should maintain:
confidentiality agreements;
information-classification systems;
access controls;
employee exit procedures;
cybersecurity controls;
encryption;
monitoring;
restricted databases;
supplier confidentiality clauses;
AI-use policies;
incident-response procedures;
evidence-preservation procedures.
These measures are also useful in later litigation because they help establish that the company took reasonable steps to preserve secrecy.
46. Exam-Oriented Legal Formula
A useful formula is:
Secret information + commercial value + reasonable secrecy measures + unlawful acquisition/use/disclosure + causation = potential corporate trade-secret claim.
For contractual claims:
Confidentiality obligation + unauthorised disclosure/use + breach + legally recoverable loss = contractual claim.
For urgent protection:
Continuing threat + risk of commercial harm + sufficient legal basis = possible interim injunction.
47. Conclusion
Confidential-information leakage claims in Europe are governed by a multi-layered legal framework. The EU Trade Secrets Directive provides the central harmonised framework for trade-secret protection, while national contract, tort/delict, employment, company and procedural laws determine many practical aspects of individual claims.
The most important issues are:
whether the information was genuinely confidential;
whether it had commercial value;
whether reasonable protective measures existed;
how the information was obtained;
whether its use or disclosure was unlawful;
whether the claimant suffered legally recoverable damage;
whether an injunction is necessary;
whether whistleblowing or public-interest considerations apply.
The European case law also demonstrates that confidentiality is not absolute. Courts must sometimes balance corporate secrecy against procedural fairness, regulatory transparency and freedom of expression. Halet v Luxembourg is particularly important where confidential corporate documents are disclosed in a whistleblowing/public-interest context, while Pilkington, Solvay and Varec demonstrate the importance of confidentiality in EU administrative and judicial proceedings. (HUDOC)

comments