You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 5, 2020

The Risk of Trade Secret Misappropriation during Work-from-Home Arrangements

Bangkok Post Human Resources Watch

While we’ve all seen how quickly life has changed during the pandemic, from a business and HR angle the possibility of intellectual property misappropriation and theft occasioned by work-from-home policies may not yet be clear to many. With many employees working outside their company’s normal IT security fence, their increased use of their own computers and devices instead of those in their offices with standard or enhanced security mechanisms has made it more challenging for employers to control access to key business information.

In the rush to set up a fully or partially remote workforce, most companies had little time to establish work-from-home guidelines on protection of their valuable intangible assets like trade secrets and confidential business information. Most employers would likely have sufficient internal guidelines on copying files to USB drives, emailing files to personal accounts, and uploading to cloud storages like Dropbox, Google Drive, or OneDrive, but who could have imagined the need for rules precluding sharing proprietary information over Zoom, Skype, Webex, House Party, Ring Central, or Microsoft Teams?

In addition to willful or unknowing misappropriation by employees, perhaps the biggest threat to many businesses are those unscrupulous hackers who have exploited vulnerable IT protocols and baited people with luring emails related to the current health crisis. Phishing and ransomware emails such as information on vaccines, fake COVID-19 maps, free technology to improve online conferencing platforms, and various other pandemic-related messages have been used to bait people working from home in attempts to access otherwise protected systems. Hacking of smart home devices has resulted in recordings of what was supposed to be confidential conversations being transmitted to not only Amazon, Google, and other providers but to hackers and thieves as well.

While all sectors are suffering from more frequent ransomware attacks, research from Microsoft has shown that the healthcare sector has been particularly affected. The U.S. Department of Health and Human Services faced attempted breaches in early March, but fortunately they survived that scare. However, the University of California, San Francisco, recently suffered a large-scale attack resulting in USD 1.14 million being paid to hackers to prevent the permanent loss of important COVID-19-related research data. Interpol and Europol have taken this threat very seriously, posting COVID-19-specific online cyberthreats to educate the public about these very real and harmful threats. Corporations too should plan out effective incident responses and raise awareness with their employees to prevent future infiltrations.

Given this background, there are a couple of important steps that employers should take to start protecting themselves from theft (either intentional or not) or to enhance existing protocols.

First, each employer should speak to the company’s HR team to make sure he or she understands the existing workplace rules regarding the handling and maintenance of confidential business information.

Now is the time for HR to revisit existing rules and update them for the new normal. This should include a refresher in employment agreements or individual confidentiality agreements (particularly important for key personnel) to accommodate work-from-home realities. In order to successfully prove a case against a trade secret infringer, the owner must show demonstrable evidence that all reasonable care was taken to maintain the confidential information. This would include regular reminders to employees about what is meant by “confidential information” or “trade secrets” and their duty to maintain that confidentiality if they are allowed access.

Employee sharing of business information has accelerated with the increased adoption of some of the platforms mentioned above. While many employees would already be familiar with a company’s rules on disclosing to third parties, such as doing so only under a written non-disclosure agreement, this is complicated with the new ways in which we are all now communicating outside our companies. Document sharing can be controlled by secure transfer tools like password-protected FTP programs, time-limited document viewers, and limitation of the number of downloads.

For businesses in the unfortunate circumstance of having to lay off or furlough employees because of the pandemic, work-from-home realities make the exit interview even more important. In addition to existing requirements such as return of all company property (including loaner devices used from home), HR will want to secure additional undertakings, such as assurances that no unauthorized copying or downloading occurred on any device, no company information is retained in any form, and no confidential information was shared with third parties without proven authorization. Also, if the departing employee was a member of any R&D, design, or engineering team, an enhanced exit interview is an ideal time to effect IP assignments or other declarations necessary to vest all employee-created IP or improvements in the employer (preferably before termination). Even if the research project is incomplete, this might be a good time also to consider filing provisional patent applications with the employee’s written further assurance that subsequent follow-on applications will not be jeopardized.

Second, employers should talk to the company’s IT team about existing security measures and any necessary enhancements.

The IT team will be well placed to complement the HR efforts described above by updating existing security measures, implementing new ones, and explaining any changes to employees. This might include a new personal device use policy (or “bring your own device” policy) with an explanation of the employer’s right to track and monitor its own devices as well as those of the employee who uses them for their work—all legal in Thailand, as it is in most jurisdictions around the world so long as employees are made aware. IT would likely also find this an ideal time to install new or updated antivirus, spyware, and malware protections. Personal devices will be much more at risk of hacking than fenced-in company IT architecture, so the IT team should install necessary security on personal devices as well if these are to be used for company work outside the workplace. If employees are allowed VPNs or other remote access platforms as a backup to the business network, employers should decide whether to place any restrictions on downloading, copying or transferring files.

While no business can completely insulate itself from leakage of its proprietary information, most can take steps to significantly reduce the risk, mitigate damages, and prove that reasonable care was taken to protect their property. In these unique times, the best internal teams employers can turn to for assistance in establishing the necessary safeguards are HR and IT.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks.

RELATED INSIGHTS​ 

July 9, 2026
Recycling, upcycling, and refill-packaging models are now widely promoted as ways to reduce waste, lower carbon emissions, and respond to consumer demand for sustainable products. However, complications arise when these environmentally driven trends intersect with intellectual property law—particularly where reused or altered packaging continues to display third parties’ registered trademarks. Adding to this complexity, Thailand’s draft Sustainable Packaging Management Act aims to introduce new environmental compliance obligations that businesses must navigate alongside existing trademark concerns. Recycling and upcycling packaging may infringe trademark rights, especially in cases not protected by the first-sale doctrine—the principle that a trademark owner’s rights over a particular mark-bearing product end once the owner first sells it. Furthermore, even refill packaging carries legal risk due to specific statutory prohibitions under Thai law. Compounding these challenges, the draft Sustainable Packaging Management Act will impose extended producer responsibility (EPR) obligations on manufacturers and brand owners, requiring them to manage packaging throughout its lifecycle. These overlapping legal frameworks could deter manufacturers from pursuing ESG-aligned business models unless businesses understand how to navigate both trademark and environmental requirements. Under Thai law, this issue remains uncertain because the Trademark Act does not expressly codify the first sale doctrine, also known as the exhaustion of trademark rights. Generally, this doctrine provides that once a trademark owner has lawfully sold goods bearing its trademark, the owner’s right to control further resale of those particular goods is exhausted. The rationale is that the owner has already received commercial benefit from the first authorized sale; therefore, the purchaser should be free to resell or otherwise dispose of the goods. Although the doctrine is not expressly codified in the Trademark Act, Thai courts have recognized it in relation to genuine goods and parallel imports, as seen in a Supreme Court Judgment No. 2817/2543 in which the
July 6, 2026
Indonesia’s regulation on reporting online intellectual property (IP) infringement provides comprehensive procedural guidance for IP rights holders and their licensees in reporting online infringement complaints. Issued in December 2025 by the Ministry of Law as Regulation No. 47 of 2025 regarding Handling of Intellectual Property Infringement Reports in Electronic Systems, this regulation covers all types of IP rights. It also specifies documentation when reporting infringement, and lays out the procedures for examination, verification, and enforcement actions. Submission of Complaints Complainants may submit reports through the online system of the Directorate General of Intellectual Property (DGIP) or in person at the DGIP office. Complaints may also be filed through an authorized proxy. Under the regulation, complainants are required to provide the following information and documents: Personal details of the complainant; Brief description of the protected work or subject matter (i.e., type of IP and name or address of the infringing website, portal, account, or application, or a link to the location of the infringing content); Complete description of the alleged infringement; Certificate of registration or recordal of the relevant IP; Recordal of IP license agreement, if any; and Other supporting evidence. Verification and Examination Process Upon receiving a complaint, the responsible formality officer may request clarification or additional supporting documents. In the latter case, the complainant must then submit the necessary administrative documents within 14 days of the notification date. Once the documentation is deemed complete and sufficient, the case will be formally registered. Subsequently, the DGIP will establish a verification team to handle online IP violations, which will include the Civil Servant Investigator (PPNS), the Ministry of Communication and Digital Affairs, experts with relevant expertise in IP, and representatives from related associations such as AVISI (Indonesian Video Streaming Association). After examining the report, the team will prepare the Minutes
June 30, 2026
Customs recordation is an enforcement mechanism in Myanmar that enables intellectual property (IP) rights holders to seek prevention of the cross-border movement of infringing goods. The enactment of Myanmar’s IP laws in 2019 has enabled customs recordation for registered marks and copyrights under the Trademark Law 2019 and the Copyright Law 2019. By contrast, the Patent Law 2019 and the Industrial Design Law 2019 do not provide a practical framework for customs recordation, and accordingly such rights are not subject to the customs recordation regime. Under the Trademark Law 2019, rights holders may apply for customs recordation and may also ask the Customs Department to suspend the release of goods suspected of bearing counterfeit marks. Likewise, the Copyright Law 2019 allows for customs intervention in relation to pirated works. These provisions reflect Myanmar’s gradual alignment with international standards on border measures, although the implementation framework remains at a relatively early stage of development. Customs Recordation Pursuant to the Trademark Law 2019 and the Copyright Law 2019, the relevant authorities have issued customs rules concerning the protection of registered marks and copyrights. In practice, the process generally begins with the submission of an application to the Customs Department together with supporting documentation. This typically includes proof of registration in Myanmar; details of the rights holder, applicant, and any authorized representative; and a comprehensive description of the genuine goods. Product identification materials—such as photographs, packaging samples, and distinguishing features—are particularly important in helping customs officers identify suspected infringing goods. A recordation remains valid for two years from the date of approval. It may be renewed for additional two-year terms, provided that the renewal application is filed within the thirty days prior to expiry for marks and up to thirty days in advance of the expiry date for copyrights, in accordance with
June 24, 2026
Patent enablement requirements are provided under Article 102 of Vietnam’s Law on Intellectual Property (IP Law). In particular, a patent specification must “fully and clearly disclose the nature of the invention to such an extent that, based on the specification, a person having ordinary skill in the relevant art can implement the invention.” In pharmaceutical and biotechnology patents, this requirement is more complicated and subject to more rigorous assessment. The Patent Examination Guidelines (Guidelines) of the Intellectual Property Office of Vietnam (IP Office) were amended in March 2026 to introduce Annexes III and IV for the pharmaceutical and biotechnology sectors, in which Annex III provides detailed guidelines on the assessment of specification requirements. These amendments were made under a project for strengthening capacity in industrial property examination between the Japan International Cooperation Agency (JICA) and the IP Office. Annex III provides detailed instructions on how examiners assess enablement in a pharmaceutical or biotechnology application, and offers examples of acceptable and unacceptable descriptions with regard to the enablement aspect. Enablement Requirements in Pharma and Biotech Patents Article 12.7 of Circular 10/2026/TT-BKHCN (Circular 10) adds to the requirements of Article 102 of the IP Law that the description must demonstrate the novelty, inventive step, and industrial applicability of the technical solution. For pharmaceutical composition subject matters, Article 12.9 of Circular 10 sets out that the description must present the results of clinical trials and/or the pharmacological effects of the claimed pharmaceutical composition, and must include at least the following information: Substance/mixture used. Testing method (system) employed. Information on the test results. Correlation between the pharmacological effects obtained from the tests and the application of the pharmaceutical product in the prevention, diagnosis, and treatment of diseases. The Guidelines note that pharmacological study results should be presented in a quantified manner, and pharmacological