Intellectual property leakage risks.

Intellectual Property Leakage Risks

Introduction

Intellectual Property (IP) leakage refers to the unauthorised disclosure, copying, transfer, use, or dissemination of intellectual property belonging to an organisation or another rights holder.

In an employment context, IP leakage can occur when employees, contractors, consultants, vendors, or former employees improperly disclose or use:

  • Trade secrets
  • Confidential business information
  • Source code
  • Designs and drawings
  • Research and development information
  • Customer databases
  • Product formulas
  • Business strategies
  • Copyrighted material
  • Patents and inventions
  • Proprietary software
  • Technical know-how

IP leakage can cause financial losses, loss of competitive advantage, regulatory problems, and litigation.

1. Meaning of Intellectual Property Leakage

IP leakage occurs when protected or confidential information moves outside the authorised environment without permission.

For example, an employee may:

  1. Copy confidential files to a personal USB drive.
  2. Email source code to a personal email account.
  3. Upload confidential documents to a cloud-storage account.
  4. Share a product design with a competitor.
  5. Use an employer's trade secret in a competing business after leaving employment.
  6. Disclose confidential information through social-media or messaging applications.

The leakage may be intentional or accidental.

2. Types of IP Leakage

A. Trade-secret leakage

Trade secrets may include:

  • manufacturing processes;
  • algorithms;
  • formulas;
  • customer information;
  • pricing information;
  • business strategies.

B. Copyright leakage

Employees may improperly copy or distribute:

  • software;
  • reports;
  • manuals;
  • photographs;
  • databases;
  • written material.

C. Patent-related leakage

Confidential technical information may be disclosed before a patent application is filed, potentially affecting patent protection.

D. Trademark-related leakage

Unauthorised use of logos, brand material, or proprietary branding can create infringement issues.

E. Know-how leakage

Technical or commercial know-how may be transferred to competitors or used outside the permitted employment relationship.

3. Common Causes of IP Leakage

3.1 Employee departure

An employee leaving for a competitor may take:

  • customer lists;
  • business plans;
  • software;
  • pricing data;
  • confidential documents.

3.2 Weak access controls

Employees may have access to information unrelated to their job responsibilities.

3.3 Personal devices

Use of personal phones, laptops, USB drives, and cloud accounts can increase the risk of unauthorised copying.

3.4 Email and messaging

Confidential information can be accidentally sent to an incorrect recipient.

3.5 Remote working

Remote work can increase the number of locations and devices through which company information is accessed.

3.6 Third-party vendors

Contractors and vendors may receive access to confidential technical or commercial information.

4. Employment Contracts and IP Leakage

Employers commonly include confidentiality and intellectual-property clauses in employment agreements.

Such clauses may address:

  • ownership of employee-created works;
  • confidentiality;
  • trade secrets;
  • return of company property;
  • restrictions on disclosure;
  • intellectual-property assignment;
  • post-employment obligations.

However, contractual restrictions must comply with applicable law.

In India, Section 27 of the Indian Contract Act, 1872 is particularly relevant to agreements restraining lawful profession, trade, or business.

Therefore, an employer cannot assume that every post-employment restriction will automatically be enforceable.

5. Trade Secrets and Confidential Information

India does not have a comprehensive standalone trade-secrets statute comparable to some jurisdictions. Protection can arise through:

  • contracts;
  • principles of equity and confidentiality;
  • common-law principles;
  • intellectual-property laws applicable to particular subject matter;
  • employment obligations;
  • information-technology and data-protection requirements, where applicable.

Consequently, organisations should identify confidential information clearly and establish appropriate contractual and technical safeguards.

6. Important Indian Case Laws

1. American Express Bank Ltd. v. Priya Puri (2006)

The Delhi High Court considered issues involving confidential information and customer information in an employment context.

The case distinguished between information that could legitimately be treated as confidential and information that may form part of an employee's general knowledge and experience.

Principle

Not every piece of information acquired during employment automatically becomes a protected trade secret.

Relevance

Employers seeking protection against IP leakage should identify the confidential information specifically rather than relying on broad assertions.

2. Diljeet Titus v. Alfred A. Adebare (2006)

The Delhi High Court dealt with copyright and confidential information relating to a law firm's materials and databases.

The court considered protection available for proprietary material and the circumstances in which former personnel could use or retain such information.

Principle

Confidential and proprietary business material can receive legal protection, and unauthorised use can give rise to injunctive relief where the legal requirements are satisfied.

Relevance

The case is particularly useful for understanding IP leakage involving databases, documents, and professional-service organisations.

3. Navigators Logistics Ltd. v. Kashif Qureshi (2018)

The Delhi High Court considered allegations concerning confidential information and employee movement to a competing business.

Principle

Courts examine whether information claimed to be confidential actually possesses the necessary characteristics of confidential information.

Relevance

The case illustrates the importance of establishing the nature of the allegedly leaked information rather than merely asserting that all information obtained during employment is confidential.

4. American Express Bank Ltd. v. Ms. Priya Puri, 2006

This decision is also important in discussions of employee movement and confidential customer information.

The court considered the distinction between confidential information belonging to the employer and knowledge, skill, and experience acquired by an employee during employment.

Relevance

This distinction is crucial when an employer alleges that a former employee has taken proprietary information to a competitor.

5. John Richard Brady v. Chemical Process Equipments P. Ltd. (1987)

The Delhi High Court dealt with protection of confidential technical information and know-how.

Principle

Courts may protect confidential technical information where the circumstances establish that the information possesses a confidential character and has been improperly used or threatened with disclosure.

Relevance

The case is significant for businesses whose competitive advantage depends upon technical know-how.

6. Burlington Home Shopping Pvt. Ltd. v. Rajnish Chibber (1995)

The Delhi High Court considered protection of confidential information and customer-related databases.

Principle

A compilation or database may possess protectable characteristics where sufficient originality, confidentiality, or proprietary interest is established.

Relevance

The case is particularly relevant to modern businesses that maintain valuable customer databases and commercially sensitive information.

7. Zee Telefilms Ltd. v. Sundial Communications Pvt. Ltd. (2003)

The Bombay High Court considered confidentiality and copyright-related issues concerning creative material.

Principle

Confidential creative material can receive legal protection in appropriate circumstances, particularly where information is disclosed under circumstances giving rise to an obligation of confidence.

Relevance

The case demonstrates that IP leakage is not limited to technical information; creative and commercial material may also be protected.

7. IP Leakage Through Employees

Employees are often given access to valuable information because they need it to perform their duties.

This creates a balance between:

Employee's legitimate use of knowledge and skills

and

Employer's right to protect genuinely confidential information.

For example, an employee leaving a company can generally take their general professional skills and experience with them. That does not necessarily mean they can take confidential source code, proprietary databases, secret formulas, or confidential customer information.

8. IP Leakage During Employee Exit

The employee-exit process is an important stage for preventing leakage.

Organisations should consider:

Before exit

  • Review access permissions.
  • Identify sensitive projects.
  • Preserve relevant records.
  • Confirm confidentiality obligations.

During exit

  • Recover laptops and other devices.
  • Disable access credentials.
  • Recover company documents.
  • Remove access to cloud systems.
  • Confirm return/deletion obligations.

After exit

  • Monitor for unauthorised use where legally appropriate.
  • Preserve evidence of suspected leakage.
  • Send appropriate legal notices where justified.
  • Seek judicial remedies where necessary.

9. Role of HR

HR has an important role in preventing IP leakage.

HR can ensure that:

  • employment contracts contain appropriate confidentiality provisions;
  • IP ownership provisions are properly drafted;
  • employees receive confidentiality training;
  • exit procedures are documented;
  • company property is returned;
  • access is removed promptly after termination;
  • disciplinary procedures are followed for suspected misconduct.

10. Role of IT and Cybersecurity Teams

IP protection is not solely an HR responsibility.

IT departments can implement:

  • role-based access;
  • multi-factor authentication;
  • encryption;
  • data-loss prevention systems;
  • download restrictions;
  • audit logs;
  • endpoint security;
  • secure cloud access;
  • USB restrictions;
  • monitoring consistent with applicable law and company policy.

11. Accidental vs Intentional Leakage

The organisation should distinguish between different types of incidents.

Accidental leakage

Example:

An employee accidentally sends a confidential document to the wrong email address.

The appropriate response may involve:

  • containment;
  • deletion/recall where possible;
  • investigation;
  • training;
  • security improvements.

Deliberate leakage

Example:

An employee intentionally copies proprietary source code before joining a competitor.

This may justify a more serious response, depending on the evidence and applicable law.

12. Evidence in IP Leakage Cases

Evidence may include:

  • emails;
  • access logs;
  • download records;
  • document metadata;
  • company laptops;
  • cloud logs;
  • USB activity;
  • employee communications;
  • confidentiality agreements;
  • employment contracts;
  • audit records.

Organisations must obtain and use such evidence consistently with applicable privacy, employment, and procedural requirements.

13. Remedies for IP Leakage

Depending on the circumstances and applicable law, an organisation may seek:

Injunction

A court may restrain further disclosure or use of protected information where the legal requirements are satisfied.

Damages

A claimant may seek monetary compensation for legally actionable loss.

Account of profits

In appropriate IP disputes, a claimant may seek an account of profits.

Delivery-up or destruction

Courts may order the surrender or destruction of infringing or confidential material in appropriate cases.

Disciplinary action

Where an employee breaches established workplace obligations, the employer may initiate disciplinary proceedings in accordance with applicable employment rules.

Criminal remedies

Certain forms of conduct may also attract criminal liability under applicable legislation, depending upon the facts.

14. Preventive Compliance Framework

An organisation can reduce IP leakage through a combination of legal and technical controls.

Step 1 – Identify valuable IP

Create an inventory of:

  • patents;
  • trade secrets;
  • source code;
  • databases;
  • designs;
  • confidential documents.

Step 2 – Classify information

For example:

Public → Internal → Confidential → Highly Confidential

Step 3 – Restrict access

Employees should receive access according to their actual job requirements.

Step 4 – Use contractual protections

Employment and vendor agreements should appropriately address:

  • confidentiality;
  • IP ownership;
  • permitted use;
  • return of information.

Step 5 – Train employees

Employees should understand what constitutes confidential information and what conduct is prohibited.

Step 6 – Monitor appropriately

Use technical controls and audit mechanisms consistent with applicable law and organisational policy.

Step 7 – Implement exit controls

Access should be revoked and company property recovered promptly when employment ends.

15. Key Distinction: Confidential Information vs General Knowledge

One of the most important principles in employment-related IP disputes is the distinction between:

Protected confidential information

and

an employee's general knowledge, skill, experience, and professional ability.

An organisation cannot ordinarily convert everything an employee learns during employment into a perpetual proprietary asset.

For example:

  • Knowledge of a general programming language → generally professional skill.
  • Knowledge of a company's secret source code → potentially confidential/proprietary information.
  • General sales experience → professional experience.
  • A confidential customer database → potentially protectable information.

The precise legal position depends on the facts and applicable law.

Conclusion

Intellectual property leakage risks arise when proprietary or confidential information is improperly disclosed, copied, transferred, retained, or used. Employment relationships create particular risks because employees and contractors often have legitimate access to valuable organisational information.

Indian courts, including in American Express Bank v. Priya Puri, Diljeet Titus v. Alfred A. Adebare, John Richard Brady v. Chemical Process Equipments, Burlington Home Shopping v. Rajnish Chibber, Zee Telefilms v. Sundial Communications, and Navigators Logistics v. Kashif Qureshi, have addressed different aspects of confidentiality, proprietary information, databases, know-how, and employee-related IP disputes.

Effective protection therefore requires a combination of clear contractual obligations, proper classification of confidential information, access controls, employee training, cybersecurity measures, documented exit procedures, and appropriate legal remedies.

LEAVE A COMMENT