An employee left for a competitor with a client database
– what protecting know-how means in practice
Most companies find out how well their know-how is protected a week after a salesperson leaves. That is when it becomes clear whether the data was labelled and secured, or whether it sat in a spreadsheet everyone could open. This article sets out what to do in the first days and what to put in place beforehand.

Key takeaways
Decision-making framework: what of the departed data is actually protected
Not everything a departing employee takes with them is legally protected. The decision-making framework has three layers, and the company's position is different in each.
The first layer is information that qualifies as a trade secret. This includes customer lists with business terms, calculations, margins, supplier prices, or technical documentation. However, they are only protected if they are competitively significant, valuable, not commonly available, and genuinely kept secret by the company. This last condition eliminates a large part of what companies consider their secrets. A freely accessible shared drive significantly weakens the ability to prove secrecy, although it is not, in itself, an automatic reason why protection was not established.
The second layer is the personal data of customers and contact persons. Its removal is a separate problem because the company, as the data controller, is responsible for who had access to the data and how that access was terminated. In addition to a dispute with the former employee, the company must also address its own obligations, and both processes run concurrently.
The third layer is the employee's knowledge and experience. They are allowed to take this with them, and any attempt to prohibit it is worthless. However, it is not the case that information ceases to be protected just because an employee has memorised it—what is decisive is the nature of the information and how it is used, not whether it left on a flash drive. General market knowledge remains with the employee, but a specific client's non-public margin or a pricing model may be protected.
Therefore, a single question is key to deciding whether to enter into a dispute: can we prove that the data was protected and how it was handled? A general suspicion that a former employee is contacting our customers is not enough. We also discuss data protection setup in the article Legal Protection of Datasets as a Trade Secret.
Step-by-step procedure
The first week after departure determines whether the company will have evidence or just impressions.
The first step is to secure digital footprints before they are overwritten. This includes CRM access logs, export histories, sent emails, and records of connected external drives. Most systems retain this data for a limited time, so this step cannot be postponed until the company decides whether it wants to pursue a dispute.
The second step is to secure the devices. The laptop and phone are not simply taken back and immediately reinstalled; they are backed up in the state they were returned in, and a handover record is drawn up. The record should also include what was missing from the device, such as deleted folders or logged-out accounts.
The third step is to map out what specifically is missing or was downloaded. Not a generic "customer database," but the specific file, date, time, and scope. Both the court and the opposing party work with concrete figures, and a general claim about a stolen database will not hold up, even in settlement negotiations.
The fourth step is a written demand letter. It identifies the information in question, demands that the recipient refrains from using it, deletes it, and provides written confirmation that no copies remain. The letter is sent to both the former employee and their new employer. The new employer usually responds more quickly than the employee, as their entire company bears the risk.
The fifth step is to assess whether the removed data contains the personal data of customers or contact persons. If it is a security breach that may pose a risk to the data subjects, the company, as the controller, has a deadline to report it to the supervisory authority without undue delay, preferably within 72 hours of becoming aware of it. Every incident must be documented, even those that are not reported. For companies subject to cybersecurity regulations, a separate reporting obligation may also arise.
The sixth step is to decide on the next course of action: a settlement with a written commitment, a preliminary injunction where there is a threat of immediate harm, or an action for unfair competition.
The seventh step is to fix your own setup: reviewing access rights, restricting bulk exports, confidentiality clauses in employment contracts, and revoking access on the day of termination. Companies most often postpone this step, yet it determines the outcome of the next departure.
What is standard practice and what is a warning sign
In companies that have this under control, it is standard for sensitive documents to be marked as confidential with access limited to those who need it, and for bulk exports from the CRM to be either prohibited or logged and approved.
It is also standard for the business terms of key customers to be known by more than just one sales representative and for the company to manage them in a system, not in the employee's personal notes.
A written confidentiality clause in the employment contract, and a separate agreement for partners, is also standard; we discuss its form in the article NDA Template with a Lawyer's Commentary.
Warning signs can be spotted before a person leaves. The first is a sales representative who keeps their own long-term records of customers outside the company's system, as the company then has no control over what they possess. The second is an increase in exports and downloads during the period when the employee has given or is preparing to give notice.
The third sign is a situation where no one other than a single sales representative knows the relationships with key customers. This is prevented by sharing contacts within the team, not by legal regulation. A related tool is a non-compete agreement, which we discuss in the article The Non-Compete Clause in Commercial Law Relationships.
Where the legal line is drawn
The law provides a company with powerful tools but makes them conditional on the company having protected the information itself.
The definition is fundamental. According to Section 504 of the Civil Code, a trade secret consists of competitively significant, identifiable, valuable facts that are not commonly available in the relevant business circles, relate to the business, and whose owner ensures their secrecy in an appropriate manner in their own interest. This last condition is decisive in practice and is assessed based on the overall protection setup: access restrictions, authentication, internal policies, contractual confidentiality, and logging. The word 'confidential' alone is not enough, and conversely, a freely accessible file is difficult to defend as secret.
The act itself is defined in Section 2985 of the Civil Code. A breach of a trade secret is an act by which someone unlawfully discloses, makes accessible, or uses for themselves or another a trade secret that can be used in competition and which they learned because it was entrusted to them or became accessible through their employment or other relationship with a competitor. The new employer may also be held liable, especially if they know or, given the circumstances, ought to know that they are using an unlawfully obtained trade secret.
The available claims are listed in Section 2988 of the Civil Code. A person whose right has been threatened or infringed by unfair competition may demand that the infringer refrains from the act or rectifies the defective situation, and may also claim reasonable satisfaction, damages, and the surrender of unjust enrichment. The right to an injunction is key, as it aims to stop the further use of the information. However, filing a lawsuit does not stop anything on its own; if it is necessary to intervene before a final decision, a preliminary injunction is the way to go. Furthermore, under Section 5a of Act No. 221/2006 Sb., if the infringer was aware of the breach of the trade secret, the court may award damages and satisfaction as a lump sum based on the usual licence fee.
During the term of employment, Section 304 of the Labour Code helps, stating that employees may only engage in gainful activity that is identical to the employer's business with the employer's prior written consent.
For the period after the termination of employment, a special regime applies, and the general provisions on non-compete clauses from the Civil Code do not apply to employees. According to Section 310 of the Labour Code, an employee may undertake to refrain from gainful activity identical to the employer's business or of a competitive nature for a maximum period of one year. The clause must include a commitment by the employer to provide reasonable financial compensation for each month, amounting to at least half of the average monthly earnings, and the clause must be in writing. It can only be agreed upon where it can be fairly required, given the nature of the information and knowledge acquired.
Attention must also be paid to the method of securing evidence. According to Section 316 of the Labour Code, an employer may reasonably check whether an employee is using work equipment for personal use, but may only infringe on their privacy by monitoring electronic mail for a serious reason arising from the special nature of their business, and even then, must inform the employee in advance about the scope and method of monitoring.
Database protection offers a separate path. According to Section 88a of the Copyright Act, the maker of a database has a special right if its creation represented a substantial investment, regardless of copyright protection. For a bulk-exported CRM, this provides a second legal basis in addition to trade secrets.
Potential problems | How ARROWS can help (consultation@arws.cz) |
|---|---|
Missing evidence of data removal: logs have been overwritten and the device has been reinstalled | We will establish a procedure for the immediate securing of digital footprints and a formal handover of the device. We will assess what can be proven retroactively |
Data does not meet the conditions for a trade secret: files were accessible to everyone | We will set up a secrecy regime, labelling, and access rights. In an ongoing dispute, we will look for an alternative legal basis |
The new employer is using the data: orders are going to a competitor | We will prepare a demand letter for both the employee and their new employer. We will file for an injunction and a preliminary injunction |
Invalid non-compete clause: missing financial compensation or agreed for a longer period than the law allows | We will redraft the clause into an enforceable form. We will assess what can be enforced from the current wording |
Leak of customers' personal data: the data departure also creates an obligation for the data controller | We will assess the obligations towards the supervisory authority. We will set up a process for employee departure and access revocation |
Final summary
The outcome of a dispute over know-how is decided twice. First, when setting up access rights, and second, in the first week after the employee's departure, when evidence is being secured. A company that handles both well is in a position where the other party usually prefers to settle rather than litigate.
The legal boundary cannot be circumvented by a clause in a contract. What is protected is what the company itself kept secret. An employee cannot be forbidden from using their own experience, and they can only be restricted after departure by a non-compete clause under the Labour Code, i.e., for a maximum of one year and in exchange for financial compensation. The ARROWS law firm handles these disputes as part of its Commercial and Court Disputes service and is insured for professional liability up to a limit of CZK 350,000,000. Write to us at consultation@arws.cz.


