viber

NDA in Protection System of IT Company’s Trade Secrets

Condition 1. Define a list of information that you would like to consider as trade secrets.

First of all, let's look at the characteristics of trade secrets. The following information may be considered as trade secret:

  1. any kind of information - production, financial, technical etc.;
  2. is not commonly known;
  3. is not easy accessible to third parties (who regularly works with such information);
  4. allows to get commercial benefits, since they are unknown to third parties;
  5. does not apply to IP;
  6. is not state secrets;
  7. and, finally, regarding to which a trade secret regime has been established.

During resolving the issue of the possibility of classifying any information as a trade secret, besides analyzing common characteristics, remember that certain information can NOT be a trade secret due to a direct prescription of the law. For example, information about legal entities and individual entrepreneurs entered in the Register; information from the charter of the legal entity; information on the composition of the property of a legal entity with a state share; information about the number of employees; information about violations of the law, etc.

Condition 2. Begin development of the Regulation on trade secrets.

Define the circle of persons who will be responsible for the implementation of such an assignment. The most important criterion in the preparation of the document is the maximum clarity of text.

It is important for IT companies to classify the following information as a trade secret:

  • algorithms used in the software;
  • software source codes;
  • new ideas;
  • projects;
  • customers / contractors;
  • interaction with the third parties;
  • technical documentation;
  • technical specifications;
  • the financial side of the activity, etc.

In practice, a fairly common question is the possibility of classifying salary information as an organization’s trade secret. There are diametrically opposed points of view on this issue. Read again all the characteristics indicated in Condition 1. Particularly pay attention to the 3rd point. The Labor Code establishes the obligation of the employer to issue a certificate to the employee (even previously dismissed), containing a number of information, including the amount of wages. However, the purpose of using the certificate may be different.

The employee himself decides to whom to provide it (classic situations: the need to obtain a loan, a credit, maternity allowance). We conclude: information about the amount of wages is readily available to people who usually deal with such information, which means that such information cannot be recognized as a trade secret. Note that in foreign practice, such information is often referred to as a trade secret, as awareness of this issue can create the basis for attracting competitors to employees.

So, the key points that should be contained in the Regulation on trade secrets:

  • a specific list of information constituting a trade secret (it can be made out as an appendix);
  • measures to protect trade secret;
  • admission to trade secret;
  • handling and monitoring of trade secret carriers;
  • responsibility;
  • other information.

The provision must be approved by an authorized person by issuing an order.

Condition 3. Determine the circle of persons to whom the trade secret regime will apply

The list of people may include person:

  • who work in the organization or act on its behalf (“those who are inside”);
  • with whom the IT company cooperates (“those who are outside”).

Each of the groups of persons has its own specifics. We will conditionally call them “workers” and “counterparties”. But the subjective composition can actually be much wider.

Condition 4. Familiarize employees who have access to trade secrets with the Regulation and ask them to sign it

It is advisable not only to provide a document for reading, but to explain in detail what each item includes. As an annex to the Regulation, fill out a familiarization sheet. After familiarization, edit the job descriptions of employees with the obligation to comply with the trade secret regime. An employee should have a clear understanding of what is a trade secret and what consequences may occur when it is disclosed.

To divulge a trade secret means to disclose it to at least one person who in reality should not have such information.

Disclosure = transmission of information + perception by another person.

Types of liability that may arise in case of violation of obligations to preserve trade secret:

Disciplinary.

The main measures of disciplinary action: remark, reprimand, deprivation of incentive payments for up to 12 months, dismissal.

Extreme measure, i.e. dismissal may be undertaken:

  1. in a situation where the employee needs access to trade secrets to fulfill his duties, but he refuses to sign the NDA;
  2. in a situation when a trade secret regime was introduced in the organization, the employee got acquainted with it and signed the NDA, but disclosed the trade secret.

Liability is expressed in reimbursement of the IT company for real damage.

Conditions of liability = damage + wrongful behavior + causal relationship between them + guilt.

Civil liability in the form of:

  • termination of disclosure;
  • damages.

Administrative liability (Article 22.13 of the Code of Administrative Offenses)

It comes for the disclosure of trade secrets, which became known in the process of labor activity (without the consent of its owner). Moreover, the disclosure must be intentional from the point of view of the subjective side.

Criminal liability - Article 255 of the Criminal Code

The objective side of the crime = action in the form of disclosing trade secrets + consequences in the form of large-scale damage (1000 or more basic units) + causal relationship between them.

Subjective side = intent + selfish interest. Earlier, mercenary interest entailed increased responsibility for part 2, now this feature is constructive to hold accountable for part 1.

If a person is involved in the illegal collection or abduction of trade secret, he can be prosecuted for commercial espionage. However, it is necessary to establish the existence of one of the goals: subsequent disclosure of information or its illegal use.

Condition 5. Conclude NDA

Condition 3 dealt with a circle of persons who may have access to trade secrets. The concept of "NDA" is a common one. The legislator in relation to employees uses the wording “obligation to non-disclosure of trade secrets”, and in relation to counterparties - “confidentiality agreement”.

As you can already conclude, in addition to the name of the document, there is a specific procedure for each of the groups of persons.

In order to ensure the protection of trade secrets in the framework of labor relations, it is necessary:

  1. to familiarize the employee with the Regulation on trade secrets under signature;
  2. to include the relevant conditions in the employment contract;
  3. to sign an agreement.

The most common, key points regarding the maintenance of trade secrets (with reference to the current Regulation on commercial secrets) should be provided for in the labor agreement (contract). If the employee violates this condition, the employer will have the opportunity to apply disciplinary measures. You must understand that in reality just including such a condition in an employment contract will not fully protect trade secrets. Because of this reason, we also recommend concluding a non-disclosure of trade secret obligation (our NDA).

Please note: a non-disclosure obligation is a contract of civil law nature. So it is under the scope of civil law (!), and not labor law. Hence the consequence: if the parties do not agree on all the essential conditions, the agreement will be considered non-concluded.

In the NDA with the employee, it is mandatory to prescribe:

  • a set of rights and obligations of both parties;
  • mechanism of access to trade secret;
  • duration of the obligation;
  • the obligation of the employer to notify the employee of a change or cancellation of the trade secret regime (in full or in relation to certain information).

Optionally, the employer may include the conditions:

  • on remuneration to the employee if he fulfills the obligation;
  • on employee liability in case of violation of an obligation.

We focus on the period during which it is necessary to comply with the non-disclosure obligation. There can be 2 options:

  1. until the term directly specified in the obligation;
  2. until the cancellation of the trade secret regime (this situation works when the trade secret regime was canceled before the obligation expired, as any meaning in the validity of the document is lost).

The trade secret regime involves keeping records of those who have gained access to trade secret. Therefore, for the purposes of systematization, design an accounting journal indicating the name of the employee, position, date of admission and dismissal.

To preserve the information important to you within the framework of the contractual relationship, you can optionally:

  1. Sign a confidentiality agreement before concluding a “main” agreement;
  2. Include the relevant conditions in the "main" contract;
  3. Provide general provisions in the “main” contract, and more detailed ones in the agreement supplementing it.

When entering into a confidentiality agreement (NDA), you must consider:

  • specific information constituting the trade secret / procedure for their determination;
  • limits of trade secret use;
  • validity.

Please note: even with the invalidity of a civil contract, the terms of trade secrets will remain valid.

Condition 6. Take technical measures

Let's talk about one more important detail. If you comply with all the above conditions, it is great. But information security has, in addition to documentary and organizational, other aspects. They are inextricably linked. Simply developing, signing documents and appointing responsible persons is not enough. You need to create such conditions so that the person has an objective opportunity to observe the regime of trade secrets.

In particular, use:

  • “Trade secret” inscription (in the upper right corner of the 1st sheet of the document with the details of the organization), warning labels when sending emails;
  • passwords;
  • corporate e-mail for work;
  • safes for storing the most important documents;
  • restriction of access of strangers;
  • restriction on the removal of documents and other storage media outside the office;
  • video surveillance (if necessary and subject to objective availability).

 

Based on the foregoing, we conclude that the NDA is useless when:

  1. The organization has not introduced a trade secret regime;
  2. The company is trying to protect the information that, in accordance with the law, is not classified as a trade secret.

Our recommendation: if you have the goal of protecting trade secrets, observe all of the above conditions and do not try to protect the “unguarded”.