You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 5, 2020

The Risk of Trade Secret Misappropriation during Work-from-Home Arrangements

Bangkok Post Human Resources Watch

While we’ve all seen how quickly life has changed during the pandemic, from a business and HR angle the possibility of intellectual property misappropriation and theft occasioned by work-from-home policies may not yet be clear to many. With many employees working outside their company’s normal IT security fence, their increased use of their own computers and devices instead of those in their offices with standard or enhanced security mechanisms has made it more challenging for employers to control access to key business information.

In the rush to set up a fully or partially remote workforce, most companies had little time to establish work-from-home guidelines on protection of their valuable intangible assets like trade secrets and confidential business information. Most employers would likely have sufficient internal guidelines on copying files to USB drives, emailing files to personal accounts, and uploading to cloud storages like Dropbox, Google Drive, or OneDrive, but who could have imagined the need for rules precluding sharing proprietary information over Zoom, Skype, Webex, House Party, Ring Central, or Microsoft Teams?

In addition to willful or unknowing misappropriation by employees, perhaps the biggest threat to many businesses are those unscrupulous hackers who have exploited vulnerable IT protocols and baited people with luring emails related to the current health crisis. Phishing and ransomware emails such as information on vaccines, fake COVID-19 maps, free technology to improve online conferencing platforms, and various other pandemic-related messages have been used to bait people working from home in attempts to access otherwise protected systems. Hacking of smart home devices has resulted in recordings of what was supposed to be confidential conversations being transmitted to not only Amazon, Google, and other providers but to hackers and thieves as well.

While all sectors are suffering from more frequent ransomware attacks, research from Microsoft has shown that the healthcare sector has been particularly affected. The U.S. Department of Health and Human Services faced attempted breaches in early March, but fortunately they survived that scare. However, the University of California, San Francisco, recently suffered a large-scale attack resulting in USD 1.14 million being paid to hackers to prevent the permanent loss of important COVID-19-related research data. Interpol and Europol have taken this threat very seriously, posting COVID-19-specific online cyberthreats to educate the public about these very real and harmful threats. Corporations too should plan out effective incident responses and raise awareness with their employees to prevent future infiltrations.

Given this background, there are a couple of important steps that employers should take to start protecting themselves from theft (either intentional or not) or to enhance existing protocols.

First, each employer should speak to the company’s HR team to make sure he or she understands the existing workplace rules regarding the handling and maintenance of confidential business information.

Now is the time for HR to revisit existing rules and update them for the new normal. This should include a refresher in employment agreements or individual confidentiality agreements (particularly important for key personnel) to accommodate work-from-home realities. In order to successfully prove a case against a trade secret infringer, the owner must show demonstrable evidence that all reasonable care was taken to maintain the confidential information. This would include regular reminders to employees about what is meant by “confidential information” or “trade secrets” and their duty to maintain that confidentiality if they are allowed access.

Employee sharing of business information has accelerated with the increased adoption of some of the platforms mentioned above. While many employees would already be familiar with a company’s rules on disclosing to third parties, such as doing so only under a written non-disclosure agreement, this is complicated with the new ways in which we are all now communicating outside our companies. Document sharing can be controlled by secure transfer tools like password-protected FTP programs, time-limited document viewers, and limitation of the number of downloads.

For businesses in the unfortunate circumstance of having to lay off or furlough employees because of the pandemic, work-from-home realities make the exit interview even more important. In addition to existing requirements such as return of all company property (including loaner devices used from home), HR will want to secure additional undertakings, such as assurances that no unauthorized copying or downloading occurred on any device, no company information is retained in any form, and no confidential information was shared with third parties without proven authorization. Also, if the departing employee was a member of any R&D, design, or engineering team, an enhanced exit interview is an ideal time to effect IP assignments or other declarations necessary to vest all employee-created IP or improvements in the employer (preferably before termination). Even if the research project is incomplete, this might be a good time also to consider filing provisional patent applications with the employee’s written further assurance that subsequent follow-on applications will not be jeopardized.

Second, employers should talk to the company’s IT team about existing security measures and any necessary enhancements.

The IT team will be well placed to complement the HR efforts described above by updating existing security measures, implementing new ones, and explaining any changes to employees. This might include a new personal device use policy (or “bring your own device” policy) with an explanation of the employer’s right to track and monitor its own devices as well as those of the employee who uses them for their work—all legal in Thailand, as it is in most jurisdictions around the world so long as employees are made aware. IT would likely also find this an ideal time to install new or updated antivirus, spyware, and malware protections. Personal devices will be much more at risk of hacking than fenced-in company IT architecture, so the IT team should install necessary security on personal devices as well if these are to be used for company work outside the workplace. If employees are allowed VPNs or other remote access platforms as a backup to the business network, employers should decide whether to place any restrictions on downloading, copying or transferring files.

While no business can completely insulate itself from leakage of its proprietary information, most can take steps to significantly reduce the risk, mitigate damages, and prove that reasonable care was taken to protect their property. In these unique times, the best internal teams employers can turn to for assistance in establishing the necessary safeguards are HR and IT.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks.

RELATED INSIGHTS​ 

April 29, 2026
Across the region, local brands have become key drivers of economic growth, cultural identity, and innovation, and Myanmar is no exception. From traditional products and creative industries to modern startups and small and medium‑sized enterprises (SMEs), Myanmar’s local brands are increasingly shaping domestic markets. However, as local brands grow, they also face higher risks of imitation, misuse, and unfair competition. In this context, protecting brand identity, creativity, and innovation through proper intellectual property (IP) strategies is essential to ensure that Myanmar’s homegrown businesses can grow sustainably, compete confidently, and retain the value of what they create. The Key IP Laws for Local Brands In 2019, Myanmar enacted a comprehensive suite of four IP laws, aligning the nation’s IP enforcement framework with international standards. Trademark Law 2019: This law introduced the “first-to-file” system into the country, with trademark rights primarily obtained through registration with the Intellectual Property Department (IPD). Trademarks protect brand names, logos, and other signs that distinguish goods or services. Registration grants the exclusive rights to use the mark and to prevent others from using identical or confusingly similar marks. Each registration lasts for 10 years from the filing date and can be renewed for subsequent 10-year periods. Copyright Law 2019: Copyright, which arises automatically upon creation, protects literary, artistic, musical, and audiovisual works, including software, advertisements, artwork, and social media content. While registration with the IPD is not mandatory under this law, it can be helpful for establishing evidence and supporting any future enforcement. The terms of protection for economic rights associated with copyrights vary depending on the type of work involved. In contrast, the protection for moral rights lasts indefinitely—continuing even after the author’s death. Industrial Design Law 2019: Under this law, any industrial design that is new and independently created can be filed with the
April 29, 2026
Vietnam’s education sector is entering a new regulatory era. On December 10, 2025, the National Assembly adopted a series of new and amended laws in the field of education, including the 2025 Law on Vocational Education, the 2025 Law on Higher Education, and the amended Law on Education No. 123/2025/QH15 (Amended Law on Education). These laws together took effect on January 1, 2026, marking a significant reform of Vietnam’s legal framework governing the education sector. The legislative package introduces a new lawmaking approach under which foundational and principle-based provisions are codified in the Amended Law on Education, while the Law on Higher Education and the Law on Vocational Education serve as specialized statutes providing supplementary, sector-specific regulatory detail tailored to their respective subsectors. The Amended Law on Education fundamentally restructures how educational institutions are established, governed, and licensed, with direct implications for private investors, foreign-invested entities, and education service providers operating in Vietnam. Below are several highlights of the key changes under the amended law, especially in the private sector, that stakeholders should understand: Change in the National Education System In addition to primary education, lower secondary (junior high school) education is now compulsory in Vietnam. Accordingly, diplomas are no longer awarded upon completion of lower secondary school but only for upper education levels. The national education system is also expanded through the introduction of vocational high school as a new level of vocational education. Such reform creates additional learning pathways that not only enable learners to pursue both further education and participate in the labor market, but also better align education and training with socioeconomic development needs. New Hurdle for Joint Investors: Mandatory Corporate Entity Requirement Where two or more investors jointly establish an education institution, the investors are no longer permitted to directly establish such an institution.
April 21, 2026
Vietnam continues to refine its intellectual property framework to align with the 2025 amendments to the Law on Intellectual Property (IP Law). On March 31, 2026, the government issued Decree 100/2026/ND-CP (Decree 100), which substantially amends Decree 65/2023/ND-CP detailing the implementation of the IP Law (Decree 65). On the same day, the Ministry of Science and Technology released Circular 10/2026/TT-BKHCN (Circular 10), providing detailed procedural guidance and new forms. Both instruments took effect on April 1, 2026, along with the amended IP Law. While the updates touch on every IP right, trademark owners and brand strategists will find several practical and forward-looking changes that directly affect filing strategy, examination timelines, portfolio management, and enforcement readiness. 1. Fast-Track Substantive Examination for Eligible Applications One of the most business-friendly innovations is the new fast-track substantive examination pathway for applications meeting specified eligibility criteria. Successful fast-track applications enjoy a shortened substantive examination period of three months. This offers a significant competitive edge for tech-driven or regulated-sector brands. If the mark is identical or similar to a mark in another person’s trademark application with an earlier filing date in the case of a priority application that has not yet been processed, the fast-track process will return to the ordinary process. However, the law does not touch on cases where marks under fast-track examination face office action due to other reasons (i.e. lack of distinctiveness, confusingly similar to others’ copyright, trade name, industrial design, etc.) 2. AI-Generated Trademarks Receive Clear Protection Pathway Decree 100 explicitly addresses the use of artificial intelligence (AI) in IP creation, amending Article 10a of Decree 65 to confirm that trademarks created with AI systems are fully protectable, provided they meet the standard requirements of registration. Trademarks face no additional “human authorship” hurdle (unlike patents or industrial designs). Brand owners
April 20, 2026
Myanmar’s industrial design registration regime has been steadily gaining momentum since the country officially began accepting applications under the Industrial Design Law of 2019. The Industrial Design Division of Myanmar’s Intellectual Property Department (IPD) has actively advanced examination and registration procedures, and as of March 2026, approximately 300 industrial design applications have been published in the IPD’s publicly accessible database—a meaningful milestone in the development of Myanmar’s emerging intellectual property framework. This figure reflects only published applications; additional filings remain pending and will be published after the conclusion of ongoing examination. Filing Requirements in Practice Compliance with a defined set of mandatory requirements is the foundation for filing a valid design application. These mandatory particulars must be provided at the time of filing in order to establish a filing date. These include the applicant’s and creator’s identifying details, a notarized appointment of representative form, the Locarno Classification of the associated product, and a set of graphic representations of the design across multiple standard views. Applicants must also provide a written description of the design and, where applicable, information relating to any priority claim or request for deferred publication. Filing fees are payable at the time of submission. Beyond these core requirements, applicants typically need to provide supplementary documentation, either at the time of filing or in response to a formality examination. This may include evidence of the applicant’s legal entitlement to the design—particularly where the applicant and creator are different parties—as well as supporting corporate and authorization documents. Where priority rights are claimed, the relevant documents must generally be submitted within three months of the Myanmar filing date, with certified English translations required for any non-English priority applications. The supplementary requirements may vary depending on the nature of the application and the examiner’s requests during the formality examination process.