You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 1, 2020

The Risk of Trade Secret Misappropriation during Work-from-Home Arrangements

Informed Counsel

While we’ve all seen how quickly life has changed during the pandemic, from a business and HR angle the possibility of intellectual property misappropriation and theft occasioned by work-from-home policies may not yet be clear to many. With many employees working outside their company’s normal IT security fence, their increased use of their own computers and devices, instead of those in their offices with standard or enhanced security mechanisms, has made it more challenging for employers to control access to key business information.

In the rush to set up a fully or partially remote workforce, most companies had little time to establish work-from-home guidelines on protection of their valuable intangible assets like trade secrets and confidential business information. Most employers would likely have sufficient internal guidelines on copying files to USB drives, emailing files to personal accounts, and uploading to cloud storages like Dropbox, Google Drive, or OneDrive, but who could have imagined the need for rules precluding sharing proprietary information over Zoom, Skype, Webex, House Party, Ring Central, or Microsoft Teams?

In addition to misappropriation by employees, many organizations have also seen hackers exploit vulnerable IT protocols and bait people with emails related to the current health crisis. Phishing and ransomware emails have been used to lure people working from home in attempts to access protected systems. Hacking of smart home devices has resulted in recordings of confidential conversations being transmitted to not only Amazon, Google, and other providers but to hackers and thieves as well.

Given this background, there are a couple of important steps that employers should take to start protecting themselves from theft (either intentional or not) or to enhance existing protocols.

HR Tasks

First, each employer should speak to the company’s HR team to make sure they understand the existing workplace rules regarding the handling and maintenance of confidential business information. Now is the time for HR to revisit existing rules and update them for the new normal. This should include a refresher in employment agreements or individual confidentiality agreements (particularly important for key personnel) to accommodate work-from-home realities. In order to successfully prove a case against a trade secret infringer, the owner must show demonstrable evidence that all reasonable care was taken to maintain the confidential information. This would include regular reminders to employees about what is meant by “confidential information” or “trade secrets” and their duty to maintain that confidentiality if they are allowed access.

Employee sharing of business information has accelerated with the increased adoption of some of the platforms mentioned above. While many employees would already be familiar with a company’s rules on disclosing to third parties, such as doing so only under a written non-disclosure agreement, this is complicated with the new ways in which we are all now communicating outside our companies. Document sharing can be controlled by secure transfer tools like password-protected FTP programs, time-limited document viewers, and limitation of the number of downloads.

For businesses in the unfortunate circumstance of having to lay off or furlough employees because of the pandemic, work-from-home realities make the exit interview even more important. In addition to existing requirements such as return of all company property (including loaner devices used from home), HR will want to secure additional undertakings, such as assurances that no unauthorized copying or downloading occurred on any device, no company information is retained in any form, and no confidential information was shared with third parties without proven authorization. Also, if the departing employee was a member of any R&D, design, or engineering team, an enhanced exit interview is an ideal time to effect IP assignments or other declarations necessary to vest all employee-created IP or improvements in the employer (preferably before termination). Even if the research project is incomplete, this might be a good time also to consider filing provisional patent applications with the employee’s written further assurance that subsequent follow-on applications will not be jeopardized.

IT Tasks

Employers should also talk to the company’s IT team about existing security measures and any necessary enhancements. The IT team will be well placed to complement the HR efforts described above by updating existing security measures, implementing new ones, and explaining any changes to employees. This might include a new personal device use policy (or “bring your own device” policy) with an explanation of the employer’s right to track and monitor its own devices as well as those of the employee who uses them for their work—all legal in Thailand, as it is in most jurisdictions around the world so long as employees are made aware. IT would likely also find this an ideal time to install new or updated antivirus, spyware, and malware protections. Personal devices will be much more at risk of hacking than fenced-in company IT architecture, so the IT team should install necessary security on personal devices as well if these are to be used for company work outside the workplace. If employees are allowed VPNs or other remote access platforms as a backup to the business network, employers should decide whether to place any restrictions on downloading, copying, or transferring files.

While no business can completely insulate itself from leakage of its proprietary information, most can take steps to significantly reduce the risk, mitigate damage, and prove that reasonable care was taken to protect their property. In these unique times, the best internal teams employers can turn to for assistance in establishing the necessary safeguards are HR and IT.

RELATED INSIGHTS​ 

August 20, 2026
As part of its membership in Lex Mundi, Tilleke & Gibbins has released the latest edition of its Guide to Doing Business in Thailand, providing an overview of the legal, regulatory, and commercial considerations for companies establishing or expanding operations in Thailand. The 2026 edition offers practical insight into the country’s business environment, investment framework, and operational requirements. The guide covers a wide range of topics relevant to foreign and domestic investors, including: Investment incentives and promotion schemes Financial facilities and banking regulations Exchange controls and money transfers Import and export regulations Business structures and incorporation options Requirements for establishing a business Operational and compliance considerations Business cessation and insolvency procedures Employment and labor laws Taxation Immigration and visa requirements Prepared by Tilleke & Gibbins lawyers across multiple practice areas, the publication outlines key aspects of doing business in Thailand, including foreign investment restrictions, regulatory compliance obligations, corporate structures, employment requirements, and recent legal and economic developments affecting investors. The publication forms part of Lex Mundi’s Country Guides series, a global collection of jurisdiction-specific reference materials prepared by member firms around the world. Together, these guides help companies evaluate opportunities, compare regulatory environments, and plan international business activities across multiple markets. The full Guide to Doing Business in Thailand 2026 is available through the button below.
August 13, 2026
Modern agricultural machinery is no longer purely mechanical but instead technology dependent. Modern tractors, harvesters, and other farm equipment increasingly incorporate embedded software, electronic control units, sensors, and digital diagnostic systems. While such technologies enhance efficiency, productivity, and precision farming, they also affect the manner of equipment repair and maintenance. As a result, farmers and independent repair providers may have little practical choice but to rely on authorized dealers, even for routine maintenance and repairs. Section 36 of Thailand’s Patent Act reflects the principle that the authorized sale of a patented invention usually exhausts the exclusive right of the patent owner over the specific product. This means that upon legal sale of the patented product, it can typically be used or resold without further authorization from the patent holder. This principle is relatively straightforward when applied to traditional mechanical equipment. Ownership of a machine ordinarily carries with it the practical ability to diagnose faults, replace worn parts, and restore the equipment to working order. Modern agricultural machinery, however, increasingly depends on embedded software, proprietary diagnostic systems, firmware updates, and other digital resources that may remain under the control of the manufacturer or patent holder. This tension lies within the “right to repair” debate. In the United States, on July 8, 2026, the Federal Trade Commission and five states announced a settlement with Deere & Company resolving allegations that Deere had unlawfully restricted farmers’ and independent repair providers’ ability to repair their equipment. Under the terms of the settlement, for the next ten years, Deere must provide repair resources, including software capabilities, on terms equivalent to those provided to authorized dealers. The Deere settlement highlights that the nature of ownership is changing, but legal concepts have not kept pace. Traditional patent-law concepts, including patent exhaustion, were developed with physical products
August 10, 2026
Thailand has finalized its social media KYC (“know your customer”) rules under Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers (No. 2), which was published in the Government Gazette on May 5, 2026, and will take effect on November 1, 2026. While an early draft of the notification proposed requiring social media platforms to arrange identification of every user account, the final notification is significantly more targeted, focusing on paid online advertising and advertiser identity verification. Though the regulatory initiative primarily aims to combat online fraud and technology-related crimes, it also has important consequences for intellectual property enforcement, because the verified platform records that will be generated under the new requirements can help IP rights holders to identify anonymous online infringers. Key Regulatory Mandates The notification requires social media service providers to verify the identity of advertisers before their paid advertisements are published and disseminated in Thailand through social media, regardless of whether the advertising fees come from the advertisers or third parties. Verification of an advertiser is valid for one year, after which verification would have to be performed again before the platform could publish additional paid advertisements from the advertiser. Permitted verification methods are specified under the notification. A platform may verify an advertiser by checking identity evidence and confirming the connection between the advertiser and that identity evidence, with the notification giving facial comparison against certain government-issued identity documents as an example. Alternatively, platforms may verify advertisers through a digital identity verification and authentication system with an identity-proofing assurance level not lower than the level prescribed by Thailand’s Electronic Transactions Commission. The notification further requires platforms to retain only the advertiser’s information necessary to identify the advertiser, beginning from the start of the advertising activity and for
August 6, 2026
Introduction: A Trademark Paradox in Sustainable Packaging Walk into any Thai supermarket, and the label-free water bottle is no longer a novelty. Thailand’s packaging market, valued at approximately USD 15.68 billion in 2025, is shifting toward minimalist, plastic-light designs as ESG pressures reshape how brands present their products. The country generated roughly 5.68 million tons of plastic waste in 2021, with a recycling rate of only 19 percent, and regulators are now considering rules that would allow label-free bottled water relying on embossing, laser printing, or QR codes instead of wrap-around labels. As packaging itself becomes the brand identifier, a paradox emerges: designs built to say the least often struggle hardest for protection under Thai intellectual property law. The Trademark Barrier: When Shape Is Not Enough Section 7, paragraph 2(10) of the Thai Trademark Act deems a shape distinctive only if it is not the natural form of the goods, is not necessary to achieve a technical result, and does not add value to the goods. The Department of Intellectual Property’s 2022 examination guidelines apply this test conservatively, as the following examples illustrate. A plain water bottle relying on subtle contours to signal its brand is typically read as just another bottle, not a source identifier. Acquired distinctiveness offers a theoretical escape route, but it demands extensive evidence of sales, advertising, and consumer recognition—an especially heavy burden for new entrants whose minimalist packaging has not yet achieved market prominence. The result is a structural bias against precisely the design innovation that sustainability goals are meant to encourage. Design Patents: A Partial, Imperfect Substitute Design patent protection, covering a product’s shape, configuration, or ornamentation, appears to offer an alternative route. In practice, it is constrained by the same forces driving the minimalist trend. Because many brands converge on similar solutions—clear