Skip to content
Law

An employee left for a competitor with a client database

– what protecting know-how means in practice

Most companies find out how well their know-how is protected a week after a salesperson leaves. That is when it becomes clear whether the data was labelled and secured, or whether it sat in a spreadsheet everyone could open. This article sets out what to do in the first days and what to put in place beforehand.

ARROWS lawyers discuss the protection of know-how and customer database leakage.

Key takeaways

The law only protects information that the company itself has kept secret. The overall security framework is what matters, not a single "confidential" stamp.
Securing evidence is crucial in the first few days: access logs, data exports, company emails, and devices. Without them, data theft cannot be proven.
Claims are not just about money. The most effective remedies are often injunctive relief and the removal of the infringing state of affairs, i.e., a prohibition on further use of the data.
Protection must be established before an employee's departure, not after. Key elements include access rights, confidentiality obligations, and clear offboarding procedures.

DEALING WITH DATA MISUSE BY A FORMER EMPLOYEE?

Contact us. We will be happy to help you effectively protect your company's data.

ARROWS law firm

Decision-making framework: what of the departed data is actually protected

Not everything a departing employee takes with them is legally protected. The decision-making framework has three layers, and the company's position is different in each.

The first layer is information that qualifies as a trade secret. This includes customer lists with business terms, calculations, margins, supplier prices, or technical documentation. However, they are only protected if they are competitively significant, valuable, not commonly available, and genuinely kept secret by the company. This last condition eliminates a large part of what companies consider their secrets. A freely accessible shared drive significantly weakens the ability to prove secrecy, although it is not, in itself, an automatic reason why protection was not established.

The second layer is the personal data of customers and contact persons. Its removal is a separate problem because the company, as the data controller, is responsible for who had access to the data and how that access was terminated. In addition to a dispute with the former employee, the company must also address its own obligations, and both processes run concurrently.

The third layer is the employee's knowledge and experience. They are allowed to take this with them, and any attempt to prohibit it is worthless. However, it is not the case that information ceases to be protected just because an employee has memorised it—what is decisive is the nature of the information and how it is used, not whether it left on a flash drive. General market knowledge remains with the employee, but a specific client's non-public margin or a pricing model may be protected.

Therefore, a single question is key to deciding whether to enter into a dispute: can we prove that the data was protected and how it was handled? A general suspicion that a former employee is contacting our customers is not enough. We also discuss data protection setup in the article Legal Protection of Datasets as a Trade Secret.

Step-by-step procedure

The first week after departure determines whether the company will have evidence or just impressions.

The first step is to secure digital footprints before they are overwritten. This includes CRM access logs, export histories, sent emails, and records of connected external drives. Most systems retain this data for a limited time, so this step cannot be postponed until the company decides whether it wants to pursue a dispute.

The second step is to secure the devices. The laptop and phone are not simply taken back and immediately reinstalled; they are backed up in the state they were returned in, and a handover record is drawn up. The record should also include what was missing from the device, such as deleted folders or logged-out accounts.

The third step is to map out what specifically is missing or was downloaded. Not a generic "customer database," but the specific file, date, time, and scope. Both the court and the opposing party work with concrete figures, and a general claim about a stolen database will not hold up, even in settlement negotiations.

The fourth step is a written demand letter. It identifies the information in question, demands that the recipient refrains from using it, deletes it, and provides written confirmation that no copies remain. The letter is sent to both the former employee and their new employer. The new employer usually responds more quickly than the employee, as their entire company bears the risk.

The fifth step is to assess whether the removed data contains the personal data of customers or contact persons. If it is a security breach that may pose a risk to the data subjects, the company, as the controller, has a deadline to report it to the supervisory authority without undue delay, preferably within 72 hours of becoming aware of it. Every incident must be documented, even those that are not reported. For companies subject to cybersecurity regulations, a separate reporting obligation may also arise.

The sixth step is to decide on the next course of action: a settlement with a written commitment, a preliminary injunction where there is a threat of immediate harm, or an action for unfair competition.

The seventh step is to fix your own setup: reviewing access rights, restricting bulk exports, confidentiality clauses in employment contracts, and revoking access on the day of termination. Companies most often postpone this step, yet it determines the outcome of the next departure.

Frequently asked questions about an employee leaving with data

1. Can we prohibit an employee from contacting our customers?

After the employment relationship ends, only through a non-compete clause under the Labour Code, i.e., for a maximum of one year and in exchange for financial compensation. The mere fact that they know the customers does not prevent them from dealing with them.

2. Is downloading data from a CRM theft?

The criminal law aspect is a separate issue and depends on the circumstances of the specific case and the volume of data. From a commercial perspective, the faster route is through unfair competition, as claims can be asserted immediately.

3. What if they sent the data to a private email address while still an employee?

This is the most common scenario and also the easiest to prove. An email sent from a company account is often a strong digital footprint and, in a simple case, can stand up without an expert opinion; if the other party challenges the authenticity or completeness of the records, a forensic analysis is appropriate.
ARROWS law firm

What is standard practice and what is a warning sign

In companies that have this under control, it is standard for sensitive documents to be marked as confidential with access limited to those who need it, and for bulk exports from the CRM to be either prohibited or logged and approved.

It is also standard for the business terms of key customers to be known by more than just one sales representative and for the company to manage them in a system, not in the employee's personal notes.

A written confidentiality clause in the employment contract, and a separate agreement for partners, is also standard; we discuss its form in the article NDA Template with a Lawyer's Commentary.

Warning signs can be spotted before a person leaves. The first is a sales representative who keeps their own long-term records of customers outside the company's system, as the company then has no control over what they possess. The second is an increase in exports and downloads during the period when the employee has given or is preparing to give notice.

The third sign is a situation where no one other than a single sales representative knows the relationships with key customers. This is prevented by sharing contacts within the team, not by legal regulation. A related tool is a non-compete agreement, which we discuss in the article The Non-Compete Clause in Commercial Law Relationships.

Where the legal line is drawn

The law provides a company with powerful tools but makes them conditional on the company having protected the information itself.

The definition is fundamental. According to Section 504 of the Civil Code, a trade secret consists of competitively significant, identifiable, valuable facts that are not commonly available in the relevant business circles, relate to the business, and whose owner ensures their secrecy in an appropriate manner in their own interest. This last condition is decisive in practice and is assessed based on the overall protection setup: access restrictions, authentication, internal policies, contractual confidentiality, and logging. The word 'confidential' alone is not enough, and conversely, a freely accessible file is difficult to defend as secret.

Who can you turn to?

Mgr. Jakub Oliva, LL.M., MSc.

Mgr. Jakub Oliva, LL.M., MSc.

advokát, partner

oliva@arws.cz
Mgr. Klára Megová

Mgr. Klára Megová

advokátní koncipientka

megova@arws.cz
ARROWS law firm

The act itself is defined in Section 2985 of the Civil Code. A breach of a trade secret is an act by which someone unlawfully discloses, makes accessible, or uses for themselves or another a trade secret that can be used in competition and which they learned because it was entrusted to them or became accessible through their employment or other relationship with a competitor. The new employer may also be held liable, especially if they know or, given the circumstances, ought to know that they are using an unlawfully obtained trade secret.

The available claims are listed in Section 2988 of the Civil Code. A person whose right has been threatened or infringed by unfair competition may demand that the infringer refrains from the act or rectifies the defective situation, and may also claim reasonable satisfaction, damages, and the surrender of unjust enrichment. The right to an injunction is key, as it aims to stop the further use of the information. However, filing a lawsuit does not stop anything on its own; if it is necessary to intervene before a final decision, a preliminary injunction is the way to go. Furthermore, under Section 5a of Act No. 221/2006 Sb., if the infringer was aware of the breach of the trade secret, the court may award damages and satisfaction as a lump sum based on the usual licence fee.

During the term of employment, Section 304 of the Labour Code helps, stating that employees may only engage in gainful activity that is identical to the employer's business with the employer's prior written consent.

For the period after the termination of employment, a special regime applies, and the general provisions on non-compete clauses from the Civil Code do not apply to employees. According to Section 310 of the Labour Code, an employee may undertake to refrain from gainful activity identical to the employer's business or of a competitive nature for a maximum period of one year. The clause must include a commitment by the employer to provide reasonable financial compensation for each month, amounting to at least half of the average monthly earnings, and the clause must be in writing. It can only be agreed upon where it can be fairly required, given the nature of the information and knowledge acquired.

Attention must also be paid to the method of securing evidence. According to Section 316 of the Labour Code, an employer may reasonably check whether an employee is using work equipment for personal use, but may only infringe on their privacy by monitoring electronic mail for a serious reason arising from the special nature of their business, and even then, must inform the employee in advance about the scope and method of monitoring.

Database protection offers a separate path. According to Section 88a of the Copyright Act, the maker of a database has a special right if its creation represented a substantial investment, regardless of copyright protection. For a bulk-exported CRM, this provides a second legal basis in addition to trade secrets.

Potential problems

How ARROWS can help (consultation@arws.cz)

Missing evidence of data removal: logs have been overwritten and the device has been reinstalled

We will establish a procedure for the immediate securing of digital footprints and a formal handover of the device. We will assess what can be proven retroactively

Data does not meet the conditions for a trade secret: files were accessible to everyone

We will set up a secrecy regime, labelling, and access rights. In an ongoing dispute, we will look for an alternative legal basis

The new employer is using the data: orders are going to a competitor

We will prepare a demand letter for both the employee and their new employer. We will file for an injunction and a preliminary injunction

Invalid non-compete clause: missing financial compensation or agreed for a longer period than the law allows

We will redraft the clause into an enforceable form. We will assess what can be enforced from the current wording

Leak of customers' personal data: the data departure also creates an obligation for the data controller

We will assess the obligations towards the supervisory authority. We will set up a process for employee departure and access revocation

ARROWS law firm

Final summary

The outcome of a dispute over know-how is decided twice. First, when setting up access rights, and second, in the first week after the employee's departure, when evidence is being secured. A company that handles both well is in a position where the other party usually prefers to settle rather than litigate.

The legal boundary cannot be circumvented by a clause in a contract. What is protected is what the company itself kept secret. An employee cannot be forbidden from using their own experience, and they can only be restricted after departure by a non-compete clause under the Labour Code, i.e., for a maximum of one year and in exchange for financial compensation. The ARROWS law firm handles these disputes as part of its Commercial and Court Disputes service and is insured for professional liability up to a limit of CZK 350,000,000. Write to us at consultation@arws.cz.

Frequently asked questions about know-how protection

1. Is it enough to state in the employment contract that everything is confidential?

No. A blanket statement without specifying what is protected and without actual security measures is weak in a dispute. It is better to define categories of information and supplement them with technical measures.

2. Can we monitor an employee's company email?

An employer can reasonably monitor the use of company resources. However, monitoring the content of electronic mail is significantly more sensitive, and the Labour Code permits it only if special conditions are met. The procedure should be targeted and described in advance in an internal policy; otherwise, the evidence may be challenged.

3. What is the time limit for filing claims for unfair competition?

They are subject to general statutes of limitations, but speed is crucial. An injunction makes sense where the data is just beginning to be used.

4. Is a customer database also protected by copyright?

These are two different things. Copyright protection may apply if the selection or arrangement of the content is creative. In addition, the maker of a database has a special right if they have made a substantial investment in its creation, regardless of copyright protection.

5. What should we do if customers leave on their own?

A customer leaving is not illegal. The decisive factor is whether it happened through the use of protected information or simply due to a personal relationship.

6. Is it worthwhile to agree on a contractual penalty for a breach of confidentiality?

Yes, as it eliminates the difficult process of proving the amount of damages. The penalty must be proportionate to the value of the protected information; otherwise, a court may reduce it upon request.

DO YOU HAVE MORE QUESTIONS? GET IN TOUCH

ARROWS law firm

About the author

JUDr. Jakub Dohnal, Ph.D., LL.M.
JUDr. Jakub Dohnal, Ph.D., LL.M.

Associate, managing partner

Jakub Dohnal is a solicitor and managing partner at ARROWS. He specialises in company sales, investor equity investments and property transactions — most often representing the owner who is selling a company whose value they have built up over many years and who needs the transaction to be completed on the agreed terms.