You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 5, 2020

The Risk of Trade Secret Misappropriation during Work-from-Home Arrangements

Bangkok Post Human Resources Watch

While we’ve all seen how quickly life has changed during the pandemic, from a business and HR angle the possibility of intellectual property misappropriation and theft occasioned by work-from-home policies may not yet be clear to many. With many employees working outside their company’s normal IT security fence, their increased use of their own computers and devices instead of those in their offices with standard or enhanced security mechanisms has made it more challenging for employers to control access to key business information.

In the rush to set up a fully or partially remote workforce, most companies had little time to establish work-from-home guidelines on protection of their valuable intangible assets like trade secrets and confidential business information. Most employers would likely have sufficient internal guidelines on copying files to USB drives, emailing files to personal accounts, and uploading to cloud storages like Dropbox, Google Drive, or OneDrive, but who could have imagined the need for rules precluding sharing proprietary information over Zoom, Skype, Webex, House Party, Ring Central, or Microsoft Teams?

In addition to willful or unknowing misappropriation by employees, perhaps the biggest threat to many businesses are those unscrupulous hackers who have exploited vulnerable IT protocols and baited people with luring emails related to the current health crisis. Phishing and ransomware emails such as information on vaccines, fake COVID-19 maps, free technology to improve online conferencing platforms, and various other pandemic-related messages have been used to bait people working from home in attempts to access otherwise protected systems. Hacking of smart home devices has resulted in recordings of what was supposed to be confidential conversations being transmitted to not only Amazon, Google, and other providers but to hackers and thieves as well.

While all sectors are suffering from more frequent ransomware attacks, research from Microsoft has shown that the healthcare sector has been particularly affected. The U.S. Department of Health and Human Services faced attempted breaches in early March, but fortunately they survived that scare. However, the University of California, San Francisco, recently suffered a large-scale attack resulting in USD 1.14 million being paid to hackers to prevent the permanent loss of important COVID-19-related research data. Interpol and Europol have taken this threat very seriously, posting COVID-19-specific online cyberthreats to educate the public about these very real and harmful threats. Corporations too should plan out effective incident responses and raise awareness with their employees to prevent future infiltrations.

Given this background, there are a couple of important steps that employers should take to start protecting themselves from theft (either intentional or not) or to enhance existing protocols.

First, each employer should speak to the company’s HR team to make sure he or she understands the existing workplace rules regarding the handling and maintenance of confidential business information.

Now is the time for HR to revisit existing rules and update them for the new normal. This should include a refresher in employment agreements or individual confidentiality agreements (particularly important for key personnel) to accommodate work-from-home realities. In order to successfully prove a case against a trade secret infringer, the owner must show demonstrable evidence that all reasonable care was taken to maintain the confidential information. This would include regular reminders to employees about what is meant by “confidential information” or “trade secrets” and their duty to maintain that confidentiality if they are allowed access.

Employee sharing of business information has accelerated with the increased adoption of some of the platforms mentioned above. While many employees would already be familiar with a company’s rules on disclosing to third parties, such as doing so only under a written non-disclosure agreement, this is complicated with the new ways in which we are all now communicating outside our companies. Document sharing can be controlled by secure transfer tools like password-protected FTP programs, time-limited document viewers, and limitation of the number of downloads.

For businesses in the unfortunate circumstance of having to lay off or furlough employees because of the pandemic, work-from-home realities make the exit interview even more important. In addition to existing requirements such as return of all company property (including loaner devices used from home), HR will want to secure additional undertakings, such as assurances that no unauthorized copying or downloading occurred on any device, no company information is retained in any form, and no confidential information was shared with third parties without proven authorization. Also, if the departing employee was a member of any R&D, design, or engineering team, an enhanced exit interview is an ideal time to effect IP assignments or other declarations necessary to vest all employee-created IP or improvements in the employer (preferably before termination). Even if the research project is incomplete, this might be a good time also to consider filing provisional patent applications with the employee’s written further assurance that subsequent follow-on applications will not be jeopardized.

Second, employers should talk to the company’s IT team about existing security measures and any necessary enhancements.

The IT team will be well placed to complement the HR efforts described above by updating existing security measures, implementing new ones, and explaining any changes to employees. This might include a new personal device use policy (or “bring your own device” policy) with an explanation of the employer’s right to track and monitor its own devices as well as those of the employee who uses them for their work—all legal in Thailand, as it is in most jurisdictions around the world so long as employees are made aware. IT would likely also find this an ideal time to install new or updated antivirus, spyware, and malware protections. Personal devices will be much more at risk of hacking than fenced-in company IT architecture, so the IT team should install necessary security on personal devices as well if these are to be used for company work outside the workplace. If employees are allowed VPNs or other remote access platforms as a backup to the business network, employers should decide whether to place any restrictions on downloading, copying or transferring files.

While no business can completely insulate itself from leakage of its proprietary information, most can take steps to significantly reduce the risk, mitigate damages, and prove that reasonable care was taken to protect their property. In these unique times, the best internal teams employers can turn to for assistance in establishing the necessary safeguards are HR and IT.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks.

RELATED INSIGHTS​ 

June 4, 2026
On May 19, 2026, the Cabinet of the Royal Thai Government approved, in principle, revisions to Thailand’s visa exemption scheme and visa on arrival (VOA) program, as proposed by the Ministry of Foreign Affairs and the Ministry of Tourism and Sports. The revisions represent a tightening of Thailand’s immigration framework and will affect a broad range of short-term visitors. Background On July 15, 2024, Thailand expanded its visa exemption scheme by increasing the permitted period of visa-exempt stay from 30 days to 60 days in order to promote tourism, support the country’s post-pandemic economic recovery, and facilitate international travel. Under this revised scheme, passport holders from 93 countries and territories (an increase from the previous 57 countries and territories) have been permitted to enter Thailand without a visa and remain in the country for up to 60 days per entry for purposes including tourism, business engagements, urgent work, and ad hoc assignments. In addition, eligible visitors may apply at the Thai Immigration Bureau for a further 30-day extension of stay. Key Changes The proposed revisions would revoke the current 60-day exemption and reinstate the previous stay period, thereby reducing the maximum permitted stay for eligible travelers to 30 days per entry. In addition, the number of countries and territories eligible under the 30-day visa-exemption scheme is expected to be reduced to 54. The scope of the VOA scheme would likewise be significantly narrowed, with the number of eligible countries reduced from 31 countries to just four (Azerbaijan, Belarus, Serbia, and India). Further, Thailand is expected to introduce a new 15-day visa exemption category for nationals of Seychelles, the Maldives, and Mauritius. The revised framework would also limit each country or territory to a single visa exemption privilege in order to simplify Thailand’s immigration framework and reduce overlapping immigration privileges.
May 22, 2026
Intellectual property specialists from Tilleke & Gibbins in Vietnam have contributed an updated Intellectual Property Transactions in Vietnam overview for Thomson Reuters Practical Law, an online publication that provides comprehensive legal guides for jurisdictions worldwide. The Vietnam overview was authored by Linh Thi Mai Nguyen, Thanh Phuong Vu, Chi Lan Dang, Son Thai Hoang, and Duc Anh Tran. The chapter provides a high-level examination of key aspects of IP transactions law in Vietnam, including IP assignment and licensing, research and development collaborations, IP in mergers and acquisitions (M&A), lending and taking security over intellectual property rights, settlement agreements, employee- and consultant-created IP, competition law, taxation, and non-tariff trade barriers. Key topics covered in the chapter include: IP assignment: Basis and formalities for assignments of patents, utility models, trade marks, copyright, design rights, trade secrets, confidential information, and domain names in Vietnam. IP licensing: Scope, formalities, and recordal requirements for licensing patents, trade marks, copyright, design rights, and trade secrets. Research and development collaborations: Treatment of improvements, derivatives, and joint ownership of IP, including exploitation and enforcement issues. IP aspects of M&A and security: Due diligence, warranties, transfer formalities, and taking security over intellectual property rights. Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The Intellectual Property Transactions Global Guide is a valuable resource for legal practitioners seeking comparative insight into transactional IP issues across multiple jurisdictions. To view the latest version of the Intellectual Property Transactions in Vietnam overview, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
May 13, 2026
Laos has significantly broadened its industrial property administrative review framework, most notably by extending it to cover copyright and related rights for the first time. Decision No. 0306/IC on the Administrative Resolution of Disputes Concerning Industrial Property Registration, New Plant Variety Registration, and Copyright and Related Rights Recordation took effect on April 24, 2026, replacing the previous rules from 2023, which had covered only industrial property and new plant variety matters. Decision No. 0306/IC governs how Laos’ Department of Intellectual Property (DIP) and provincial offices handle formal challenges to industrial property registrations and applications. The proceedings covered include oppositions to pending applications, appeals of refused applications, requests for cancellation of existing registrations, and—newly—disputes concerning the recordation and interpretation of copyright and related rights. These administrative proceedings within the DIP are heard by a government-appointed Administrative Dispute Resolution Committee, which functions similarly to the opposition and review boards found in other jurisdictions. Key Changes Decision No. 0306/IC covers four categories of administrative proceedings: Oppositions: Third-party challenges to a pending industrial property application before it is granted. Refusal appeals: Challenges to the DIP’s decision to refuse their application. Cancellation or deletion requests: Applications to invalidate an existing registered right on the grounds that it should not have been granted. Copyright and related rights disputes: Challenges to or interpretations of copyright and related rights recordations, including determinations of whether a work qualifies for copyright protection under Lao law. The most significant development is the committee’s new jurisdiction over copyright matters. The committee is now empowered to resolve disputes concerning copyright and related rights recordation—this includes the authority to determine whether a work qualifies for copyright protection and to interpret the scope of an existing recordation. Parties who believe a competitor has improperly recorded copyright over a work, or who wish to contest
April 30, 2026
Vietnam’s Decree No. 134/2026/ND‑CP, which took effect on 9 April 2026, plays an important role in detailing and implementing Vietnam’s Intellectual Property (IP) Law in the context of rapid digital transformation and the growing application of artificial intelligence (AI). The new decree provides comprehensive guidance on the application of copyright and related‑rights regulations, addressing key issues such as authorship, ownership, statutory exceptions and limitations, registration procedures, and enforcement mechanisms. Through these measures, Decree 134 seeks to achieve an appropriate balance between safeguarding the legitimate interests of rightsholders and fostering innovation, research, and technological advancement, thereby strengthening the state’s framework for the effective management, protection, and exploitation of intellectual property in the digital and AI‑driven environment. Some notable aspects of Decree 134 are discussed below. Copyright for AI-Created Works Decree 134 provides important guidance on the determination of copyright and related rights in works created with the assistance of AI. Article 5a reaffirms the principle that human creativity remains central to copyright protection, clarifying that copyright or related rights arise only where a human makes a substantial and decisive intellectual contribution, exercises effective control over the creative outcome, and assumes responsibility for the content and its legality. At the same time, the provision confirms that AI is regarded solely as a technological tool rather than a rights‑holding subject, thus ensuring consistency with the fundamental concepts of authorship and ownership under the IP Law. By introducing requirements on transparency, proof of human contribution, and compliance with AI‑specific labelling and technical marking obligations, Decree 134 establishes a clear and enforceable legal framework for the responsible use of AI in creative activities. Lawful Use of Copyrighted Texts and Data Article 37a of Decree 134 sets out the specific conditions under which copyrighted texts and data may be lawfully used for scientific research, experimentation,