Intellectual property leakage risks.
Intellectual Property Leakage Risks
Introduction
Intellectual Property (IP) leakage refers to the unauthorised disclosure, copying, transfer, use, or dissemination of intellectual property belonging to an organisation or another rights holder.
In an employment context, IP leakage can occur when employees, contractors, consultants, vendors, or former employees improperly disclose or use:
- Trade secrets
- Confidential business information
- Source code
- Designs and drawings
- Research and development information
- Customer databases
- Product formulas
- Business strategies
- Copyrighted material
- Patents and inventions
- Proprietary software
- Technical know-how
IP leakage can cause financial losses, loss of competitive advantage, regulatory problems, and litigation.
1. Meaning of Intellectual Property Leakage
IP leakage occurs when protected or confidential information moves outside the authorised environment without permission.
For example, an employee may:
- Copy confidential files to a personal USB drive.
- Email source code to a personal email account.
- Upload confidential documents to a cloud-storage account.
- Share a product design with a competitor.
- Use an employer's trade secret in a competing business after leaving employment.
- Disclose confidential information through social-media or messaging applications.
The leakage may be intentional or accidental.
2. Types of IP Leakage
A. Trade-secret leakage
Trade secrets may include:
- manufacturing processes;
- algorithms;
- formulas;
- customer information;
- pricing information;
- business strategies.
B. Copyright leakage
Employees may improperly copy or distribute:
- software;
- reports;
- manuals;
- photographs;
- databases;
- written material.
C. Patent-related leakage
Confidential technical information may be disclosed before a patent application is filed, potentially affecting patent protection.
D. Trademark-related leakage
Unauthorised use of logos, brand material, or proprietary branding can create infringement issues.
E. Know-how leakage
Technical or commercial know-how may be transferred to competitors or used outside the permitted employment relationship.
3. Common Causes of IP Leakage
3.1 Employee departure
An employee leaving for a competitor may take:
- customer lists;
- business plans;
- software;
- pricing data;
- confidential documents.
3.2 Weak access controls
Employees may have access to information unrelated to their job responsibilities.
3.3 Personal devices
Use of personal phones, laptops, USB drives, and cloud accounts can increase the risk of unauthorised copying.
3.4 Email and messaging
Confidential information can be accidentally sent to an incorrect recipient.
3.5 Remote working
Remote work can increase the number of locations and devices through which company information is accessed.
3.6 Third-party vendors
Contractors and vendors may receive access to confidential technical or commercial information.
4. Employment Contracts and IP Leakage
Employers commonly include confidentiality and intellectual-property clauses in employment agreements.
Such clauses may address:
- ownership of employee-created works;
- confidentiality;
- trade secrets;
- return of company property;
- restrictions on disclosure;
- intellectual-property assignment;
- post-employment obligations.
However, contractual restrictions must comply with applicable law.
In India, Section 27 of the Indian Contract Act, 1872 is particularly relevant to agreements restraining lawful profession, trade, or business.
Therefore, an employer cannot assume that every post-employment restriction will automatically be enforceable.
5. Trade Secrets and Confidential Information
India does not have a comprehensive standalone trade-secrets statute comparable to some jurisdictions. Protection can arise through:
- contracts;
- principles of equity and confidentiality;
- common-law principles;
- intellectual-property laws applicable to particular subject matter;
- employment obligations;
- information-technology and data-protection requirements, where applicable.
Consequently, organisations should identify confidential information clearly and establish appropriate contractual and technical safeguards.
6. Important Indian Case Laws
1. American Express Bank Ltd. v. Priya Puri (2006)
The Delhi High Court considered issues involving confidential information and customer information in an employment context.
The case distinguished between information that could legitimately be treated as confidential and information that may form part of an employee's general knowledge and experience.
Principle
Not every piece of information acquired during employment automatically becomes a protected trade secret.
Relevance
Employers seeking protection against IP leakage should identify the confidential information specifically rather than relying on broad assertions.
2. Diljeet Titus v. Alfred A. Adebare (2006)
The Delhi High Court dealt with copyright and confidential information relating to a law firm's materials and databases.
The court considered protection available for proprietary material and the circumstances in which former personnel could use or retain such information.
Principle
Confidential and proprietary business material can receive legal protection, and unauthorised use can give rise to injunctive relief where the legal requirements are satisfied.
Relevance
The case is particularly useful for understanding IP leakage involving databases, documents, and professional-service organisations.
3. Navigators Logistics Ltd. v. Kashif Qureshi (2018)
The Delhi High Court considered allegations concerning confidential information and employee movement to a competing business.
Principle
Courts examine whether information claimed to be confidential actually possesses the necessary characteristics of confidential information.
Relevance
The case illustrates the importance of establishing the nature of the allegedly leaked information rather than merely asserting that all information obtained during employment is confidential.
4. American Express Bank Ltd. v. Ms. Priya Puri, 2006
This decision is also important in discussions of employee movement and confidential customer information.
The court considered the distinction between confidential information belonging to the employer and knowledge, skill, and experience acquired by an employee during employment.
Relevance
This distinction is crucial when an employer alleges that a former employee has taken proprietary information to a competitor.
5. John Richard Brady v. Chemical Process Equipments P. Ltd. (1987)
The Delhi High Court dealt with protection of confidential technical information and know-how.
Principle
Courts may protect confidential technical information where the circumstances establish that the information possesses a confidential character and has been improperly used or threatened with disclosure.
Relevance
The case is significant for businesses whose competitive advantage depends upon technical know-how.
6. Burlington Home Shopping Pvt. Ltd. v. Rajnish Chibber (1995)
The Delhi High Court considered protection of confidential information and customer-related databases.
Principle
A compilation or database may possess protectable characteristics where sufficient originality, confidentiality, or proprietary interest is established.
Relevance
The case is particularly relevant to modern businesses that maintain valuable customer databases and commercially sensitive information.
7. Zee Telefilms Ltd. v. Sundial Communications Pvt. Ltd. (2003)
The Bombay High Court considered confidentiality and copyright-related issues concerning creative material.
Principle
Confidential creative material can receive legal protection in appropriate circumstances, particularly where information is disclosed under circumstances giving rise to an obligation of confidence.
Relevance
The case demonstrates that IP leakage is not limited to technical information; creative and commercial material may also be protected.
7. IP Leakage Through Employees
Employees are often given access to valuable information because they need it to perform their duties.
This creates a balance between:
Employee's legitimate use of knowledge and skills
and
Employer's right to protect genuinely confidential information.
For example, an employee leaving a company can generally take their general professional skills and experience with them. That does not necessarily mean they can take confidential source code, proprietary databases, secret formulas, or confidential customer information.
8. IP Leakage During Employee Exit
The employee-exit process is an important stage for preventing leakage.
Organisations should consider:
Before exit
- Review access permissions.
- Identify sensitive projects.
- Preserve relevant records.
- Confirm confidentiality obligations.
During exit
- Recover laptops and other devices.
- Disable access credentials.
- Recover company documents.
- Remove access to cloud systems.
- Confirm return/deletion obligations.
After exit
- Monitor for unauthorised use where legally appropriate.
- Preserve evidence of suspected leakage.
- Send appropriate legal notices where justified.
- Seek judicial remedies where necessary.
9. Role of HR
HR has an important role in preventing IP leakage.
HR can ensure that:
- employment contracts contain appropriate confidentiality provisions;
- IP ownership provisions are properly drafted;
- employees receive confidentiality training;
- exit procedures are documented;
- company property is returned;
- access is removed promptly after termination;
- disciplinary procedures are followed for suspected misconduct.
10. Role of IT and Cybersecurity Teams
IP protection is not solely an HR responsibility.
IT departments can implement:
- role-based access;
- multi-factor authentication;
- encryption;
- data-loss prevention systems;
- download restrictions;
- audit logs;
- endpoint security;
- secure cloud access;
- USB restrictions;
- monitoring consistent with applicable law and company policy.
11. Accidental vs Intentional Leakage
The organisation should distinguish between different types of incidents.
Accidental leakage
Example:
An employee accidentally sends a confidential document to the wrong email address.
The appropriate response may involve:
- containment;
- deletion/recall where possible;
- investigation;
- training;
- security improvements.
Deliberate leakage
Example:
An employee intentionally copies proprietary source code before joining a competitor.
This may justify a more serious response, depending on the evidence and applicable law.
12. Evidence in IP Leakage Cases
Evidence may include:
- emails;
- access logs;
- download records;
- document metadata;
- company laptops;
- cloud logs;
- USB activity;
- employee communications;
- confidentiality agreements;
- employment contracts;
- audit records.
Organisations must obtain and use such evidence consistently with applicable privacy, employment, and procedural requirements.
13. Remedies for IP Leakage
Depending on the circumstances and applicable law, an organisation may seek:
Injunction
A court may restrain further disclosure or use of protected information where the legal requirements are satisfied.
Damages
A claimant may seek monetary compensation for legally actionable loss.
Account of profits
In appropriate IP disputes, a claimant may seek an account of profits.
Delivery-up or destruction
Courts may order the surrender or destruction of infringing or confidential material in appropriate cases.
Disciplinary action
Where an employee breaches established workplace obligations, the employer may initiate disciplinary proceedings in accordance with applicable employment rules.
Criminal remedies
Certain forms of conduct may also attract criminal liability under applicable legislation, depending upon the facts.
14. Preventive Compliance Framework
An organisation can reduce IP leakage through a combination of legal and technical controls.
Step 1 – Identify valuable IP
Create an inventory of:
- patents;
- trade secrets;
- source code;
- databases;
- designs;
- confidential documents.
Step 2 – Classify information
For example:
Public → Internal → Confidential → Highly Confidential
Step 3 – Restrict access
Employees should receive access according to their actual job requirements.
Step 4 – Use contractual protections
Employment and vendor agreements should appropriately address:
- confidentiality;
- IP ownership;
- permitted use;
- return of information.
Step 5 – Train employees
Employees should understand what constitutes confidential information and what conduct is prohibited.
Step 6 – Monitor appropriately
Use technical controls and audit mechanisms consistent with applicable law and organisational policy.
Step 7 – Implement exit controls
Access should be revoked and company property recovered promptly when employment ends.
15. Key Distinction: Confidential Information vs General Knowledge
One of the most important principles in employment-related IP disputes is the distinction between:
Protected confidential information
and
an employee's general knowledge, skill, experience, and professional ability.
An organisation cannot ordinarily convert everything an employee learns during employment into a perpetual proprietary asset.
For example:
- Knowledge of a general programming language → generally professional skill.
- Knowledge of a company's secret source code → potentially confidential/proprietary information.
- General sales experience → professional experience.
- A confidential customer database → potentially protectable information.
The precise legal position depends on the facts and applicable law.
Conclusion
Intellectual property leakage risks arise when proprietary or confidential information is improperly disclosed, copied, transferred, retained, or used. Employment relationships create particular risks because employees and contractors often have legitimate access to valuable organisational information.
Indian courts, including in American Express Bank v. Priya Puri, Diljeet Titus v. Alfred A. Adebare, John Richard Brady v. Chemical Process Equipments, Burlington Home Shopping v. Rajnish Chibber, Zee Telefilms v. Sundial Communications, and Navigators Logistics v. Kashif Qureshi, have addressed different aspects of confidentiality, proprietary information, databases, know-how, and employee-related IP disputes.
Effective protection therefore requires a combination of clear contractual obligations, proper classification of confidential information, access controls, employee training, cybersecurity measures, documented exit procedures, and appropriate legal remedies.

comments