You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 5, 2020

The Risk of Trade Secret Misappropriation during Work-from-Home Arrangements

Bangkok Post Human Resources Watch

While we’ve all seen how quickly life has changed during the pandemic, from a business and HR angle the possibility of intellectual property misappropriation and theft occasioned by work-from-home policies may not yet be clear to many. With many employees working outside their company’s normal IT security fence, their increased use of their own computers and devices instead of those in their offices with standard or enhanced security mechanisms has made it more challenging for employers to control access to key business information.

In the rush to set up a fully or partially remote workforce, most companies had little time to establish work-from-home guidelines on protection of their valuable intangible assets like trade secrets and confidential business information. Most employers would likely have sufficient internal guidelines on copying files to USB drives, emailing files to personal accounts, and uploading to cloud storages like Dropbox, Google Drive, or OneDrive, but who could have imagined the need for rules precluding sharing proprietary information over Zoom, Skype, Webex, House Party, Ring Central, or Microsoft Teams?

In addition to willful or unknowing misappropriation by employees, perhaps the biggest threat to many businesses are those unscrupulous hackers who have exploited vulnerable IT protocols and baited people with luring emails related to the current health crisis. Phishing and ransomware emails such as information on vaccines, fake COVID-19 maps, free technology to improve online conferencing platforms, and various other pandemic-related messages have been used to bait people working from home in attempts to access otherwise protected systems. Hacking of smart home devices has resulted in recordings of what was supposed to be confidential conversations being transmitted to not only Amazon, Google, and other providers but to hackers and thieves as well.

While all sectors are suffering from more frequent ransomware attacks, research from Microsoft has shown that the healthcare sector has been particularly affected. The U.S. Department of Health and Human Services faced attempted breaches in early March, but fortunately they survived that scare. However, the University of California, San Francisco, recently suffered a large-scale attack resulting in USD 1.14 million being paid to hackers to prevent the permanent loss of important COVID-19-related research data. Interpol and Europol have taken this threat very seriously, posting COVID-19-specific online cyberthreats to educate the public about these very real and harmful threats. Corporations too should plan out effective incident responses and raise awareness with their employees to prevent future infiltrations.

Given this background, there are a couple of important steps that employers should take to start protecting themselves from theft (either intentional or not) or to enhance existing protocols.

First, each employer should speak to the company’s HR team to make sure he or she understands the existing workplace rules regarding the handling and maintenance of confidential business information.

Now is the time for HR to revisit existing rules and update them for the new normal. This should include a refresher in employment agreements or individual confidentiality agreements (particularly important for key personnel) to accommodate work-from-home realities. In order to successfully prove a case against a trade secret infringer, the owner must show demonstrable evidence that all reasonable care was taken to maintain the confidential information. This would include regular reminders to employees about what is meant by “confidential information” or “trade secrets” and their duty to maintain that confidentiality if they are allowed access.

Employee sharing of business information has accelerated with the increased adoption of some of the platforms mentioned above. While many employees would already be familiar with a company’s rules on disclosing to third parties, such as doing so only under a written non-disclosure agreement, this is complicated with the new ways in which we are all now communicating outside our companies. Document sharing can be controlled by secure transfer tools like password-protected FTP programs, time-limited document viewers, and limitation of the number of downloads.

For businesses in the unfortunate circumstance of having to lay off or furlough employees because of the pandemic, work-from-home realities make the exit interview even more important. In addition to existing requirements such as return of all company property (including loaner devices used from home), HR will want to secure additional undertakings, such as assurances that no unauthorized copying or downloading occurred on any device, no company information is retained in any form, and no confidential information was shared with third parties without proven authorization. Also, if the departing employee was a member of any R&D, design, or engineering team, an enhanced exit interview is an ideal time to effect IP assignments or other declarations necessary to vest all employee-created IP or improvements in the employer (preferably before termination). Even if the research project is incomplete, this might be a good time also to consider filing provisional patent applications with the employee’s written further assurance that subsequent follow-on applications will not be jeopardized.

Second, employers should talk to the company’s IT team about existing security measures and any necessary enhancements.

The IT team will be well placed to complement the HR efforts described above by updating existing security measures, implementing new ones, and explaining any changes to employees. This might include a new personal device use policy (or “bring your own device” policy) with an explanation of the employer’s right to track and monitor its own devices as well as those of the employee who uses them for their work—all legal in Thailand, as it is in most jurisdictions around the world so long as employees are made aware. IT would likely also find this an ideal time to install new or updated antivirus, spyware, and malware protections. Personal devices will be much more at risk of hacking than fenced-in company IT architecture, so the IT team should install necessary security on personal devices as well if these are to be used for company work outside the workplace. If employees are allowed VPNs or other remote access platforms as a backup to the business network, employers should decide whether to place any restrictions on downloading, copying or transferring files.

While no business can completely insulate itself from leakage of its proprietary information, most can take steps to significantly reduce the risk, mitigate damages, and prove that reasonable care was taken to protect their property. In these unique times, the best internal teams employers can turn to for assistance in establishing the necessary safeguards are HR and IT.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks.

RELATED INSIGHTS​ 

September 9, 2026
On August 25, 2026, Thailand’s cabinet approved in principle a draft amendment that would extend mandatory social security coverage to three categories of workers currently excluded from Thailand’s compulsory social security system. The amendment, proposed by the Ministry of Labour, would modify the Royal Decree Prescribing Businesses and Employees Excluded from the Social Security Act B.E. 2560 (2017). Newly Covered Workers The cabinet-approved proposal would remove the exclusions for the following three categories of employees, bringing them within Thailand’s mandatory social security system: Workers in seasonal cultivation (pho pluk), forestry (pa mai), and livestock (liang sat) businesses that do not employ workers year-round and whose operations do not include other types of business activities. Notably, fishery (pramong) workers were excluded from this amendment following objections raised at a Social Security Board meeting on April 30, 2025, because employers and employees in the fishery sector can already agree to opt into social security coverage under fishery labor laws. Domestic workers and other employees of individual employers where the work performed is not part of a business operation (e.g., housekeepers, gardeners, drivers). This group has actively demanded inclusion in the social security system. Workers employed in street-stall businesses operating fixed street stalls (kan kha phaeng loi). The rationale for including street-stall workers is that their employers have fixed, identifiable places of business that can be inspected. Accordingly, workers engaged in itinerant street hawking (kan kha re) remain excluded. The expanded coverage would apply to both Thai and foreign employees who possess valid identity documents and work permits, including migrant workers who have been granted special permission to work in Thailand. The Social Security Act B.E. 2533 (1990) does not restrict social security registration based on nationality, allowing these workers to register as insured persons under section 33. Employer Obligations and Employee
September 7, 2026
Indonesia’s Constitutional Court (Mahkamah Konstitusi) has reinstated a key provision limiting pharmaceutical patent protection, signaling a renewed commitment to balancing patent rights with public access to medicines. In its ruling to Case No. 255/PUU-XXIII/2025, the court partially granted a petition for judicial review of Law No. 65 of 2024, which had amended the country’s Patent Law, and ordered the restoration of a provision that had excluded certain pharmaceutical inventions from patentability. The decision took effect immediately upon its pronouncement at the court’s plenary session on August 28, 2026. Background The petition challenged the removal of article 4(f) from Law No. 13 of 2016 concerning Patents (Patent Law), as amended by Law No. 65 of 2024. Article 4(f) had excluded from patentability certain inventions relating to new uses of known substances. The petitioners argued that removing this provision would open the door to patent protection for second medical use inventions and facilitate patent evergreening—practices that can extend exclusivity periods, delay generic market entry, and reduce public access to affordable medicines. The petitioners included several patient advocacy and public-interest organizations: the Indonesian Dialysis Patients Community Association, the Indonesian Association of Drug Abuse Victims (PKNI), the Indonesian Pulmonary Hypertension Foundation (YHPI), the Rekat Peduli Indonesia Foundation, and the Indonesian Positive Women’s Association (IPPI), along with the Indonesia for Global Justice Association and four individual petitioners. The petitioners also challenged the constitutionality of the phrase “interested party” in article 70(1) of the Patent Law, arguing that it should be construed expressly to clarify who has standing to appeal a decision to grant a patent before the Board of Patent Appeal, and to allow a broader range of parties—such as patent holders, licensees, consumer organizations, prosecutors, aggrieved third parties, and others who may suffer direct or indirect harm from the grant of a patent—to
September 4, 2026
Thailand’s cabinet has approved two draft amendments aimed at improving labor-related judicial proceedings. The proposed amendments to the Act on the Establishment of Labor Courts and Labor Case Procedure B.E. 2522 (1979) and the Act on Procedures for Human Trafficking Cases B.E. 2559 (2016) are intended to make the process more efficient, appropriate, and fair. Key elements of these proposed amendments are outlined below. Expansion of Labor Court Jurisdiction Under the current framework, labor courts generally hear labor disputes, while criminal offenses under labor laws are handled separately. Matters involving both labor and criminal issues may therefore require the parties to pursue proceedings before different courts. To address this, the proposed amendments would expand the jurisdiction of labor courts to cover certain criminal offenses under labor laws. The government states that the change is intended to allow related issues to be heard by judges with expertise in labor law and to reduce the need for parallel proceedings. The proposed amendments also set out the following rules for cases involving multiple offenses. Where a single act gives rise to multiple offenses and at least one of those offenses falls within the jurisdiction of the labor court, the labor court may hear the related offenses as part of the same case. Where multiple connected acts give rise to different offenses, the labor court may hear the matters together or transfer part of the case to the appropriate court, taking into account convenience and the interests of justice. Criminal Offenses Covered The proposed amendments would extend labor court jurisdiction to criminal offenses under 11 labor-related laws, including laws concerning: Home workers protection Labor protection Labor protection in fisheries work Employment and job-seeker protection Management of foreign workers Social security Occupational safety, health, and working environment Compensation Maritime labor State enterprise labor relations
September 2, 2026
Thailand and China have a longstanding and significant trade relationship, which increasingly extends to e-commerce and digitally enabled supply chains. While these channels create new opportunities for businesses to reach consumers across borders, their growth also brings greater exposure to intellectual property (IP) infringement across jurisdictions and online platforms. Effective cooperation between the two countries’ enforcement authorities has therefore become increasingly important. To strengthen cooperation in this area, Thailand and China signed a memorandum of understanding (MOU) on IP enforcement in Beijing on July 20, 2026, during the Thai prime minister’s official visit to China. Officially titled “Memorandum of Understanding Between the State Administration for Market Regulation of the People’s Republic of China and the Ministry of Commerce of the Kingdom of Thailand on Cooperation in the Field of Intellectual Property Enforcement,” the MOU forms part of a broader bilateral agenda covering industrial and supply chains, participation by micro, small, and medium-sized enterprises (MSMEs), cooperation associated with the ASEAN–China Free Trade Area 3.0, and progress on the registration of Thai geographical indications in China. The MOU establishes a bilateral framework for cooperation and coordination in five broad areas: Strengthening dialogue in IP enforcement; Enhancing information sharing; Facilitating the enforcement of IP rights in cases arising in the parties’ domestic markets and on online platforms, in accordance with their respective domestic laws; Promoting cooperation in IP enforcement training and human resource development; and Undertaking other cooperation activities agreed upon by both sides. The Department of Intellectual Property (DIP) will serve as the principal coordinating agency for Thailand, while the Bureau of Law Enforcement and Inspection in China’s State Administration for Market Regulation (SAMR) will serve in that role for China. The framework is particularly relevant to the growth of e-commerce, as it covers infringement in the domestic markets and on