You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 5, 2020

The Risk of Trade Secret Misappropriation during Work-from-Home Arrangements

Bangkok Post Human Resources Watch

While we’ve all seen how quickly life has changed during the pandemic, from a business and HR angle the possibility of intellectual property misappropriation and theft occasioned by work-from-home policies may not yet be clear to many. With many employees working outside their company’s normal IT security fence, their increased use of their own computers and devices instead of those in their offices with standard or enhanced security mechanisms has made it more challenging for employers to control access to key business information.

In the rush to set up a fully or partially remote workforce, most companies had little time to establish work-from-home guidelines on protection of their valuable intangible assets like trade secrets and confidential business information. Most employers would likely have sufficient internal guidelines on copying files to USB drives, emailing files to personal accounts, and uploading to cloud storages like Dropbox, Google Drive, or OneDrive, but who could have imagined the need for rules precluding sharing proprietary information over Zoom, Skype, Webex, House Party, Ring Central, or Microsoft Teams?

In addition to willful or unknowing misappropriation by employees, perhaps the biggest threat to many businesses are those unscrupulous hackers who have exploited vulnerable IT protocols and baited people with luring emails related to the current health crisis. Phishing and ransomware emails such as information on vaccines, fake COVID-19 maps, free technology to improve online conferencing platforms, and various other pandemic-related messages have been used to bait people working from home in attempts to access otherwise protected systems. Hacking of smart home devices has resulted in recordings of what was supposed to be confidential conversations being transmitted to not only Amazon, Google, and other providers but to hackers and thieves as well.

While all sectors are suffering from more frequent ransomware attacks, research from Microsoft has shown that the healthcare sector has been particularly affected. The U.S. Department of Health and Human Services faced attempted breaches in early March, but fortunately they survived that scare. However, the University of California, San Francisco, recently suffered a large-scale attack resulting in USD 1.14 million being paid to hackers to prevent the permanent loss of important COVID-19-related research data. Interpol and Europol have taken this threat very seriously, posting COVID-19-specific online cyberthreats to educate the public about these very real and harmful threats. Corporations too should plan out effective incident responses and raise awareness with their employees to prevent future infiltrations.

Given this background, there are a couple of important steps that employers should take to start protecting themselves from theft (either intentional or not) or to enhance existing protocols.

First, each employer should speak to the company’s HR team to make sure he or she understands the existing workplace rules regarding the handling and maintenance of confidential business information.

Now is the time for HR to revisit existing rules and update them for the new normal. This should include a refresher in employment agreements or individual confidentiality agreements (particularly important for key personnel) to accommodate work-from-home realities. In order to successfully prove a case against a trade secret infringer, the owner must show demonstrable evidence that all reasonable care was taken to maintain the confidential information. This would include regular reminders to employees about what is meant by “confidential information” or “trade secrets” and their duty to maintain that confidentiality if they are allowed access.

Employee sharing of business information has accelerated with the increased adoption of some of the platforms mentioned above. While many employees would already be familiar with a company’s rules on disclosing to third parties, such as doing so only under a written non-disclosure agreement, this is complicated with the new ways in which we are all now communicating outside our companies. Document sharing can be controlled by secure transfer tools like password-protected FTP programs, time-limited document viewers, and limitation of the number of downloads.

For businesses in the unfortunate circumstance of having to lay off or furlough employees because of the pandemic, work-from-home realities make the exit interview even more important. In addition to existing requirements such as return of all company property (including loaner devices used from home), HR will want to secure additional undertakings, such as assurances that no unauthorized copying or downloading occurred on any device, no company information is retained in any form, and no confidential information was shared with third parties without proven authorization. Also, if the departing employee was a member of any R&D, design, or engineering team, an enhanced exit interview is an ideal time to effect IP assignments or other declarations necessary to vest all employee-created IP or improvements in the employer (preferably before termination). Even if the research project is incomplete, this might be a good time also to consider filing provisional patent applications with the employee’s written further assurance that subsequent follow-on applications will not be jeopardized.

Second, employers should talk to the company’s IT team about existing security measures and any necessary enhancements.

The IT team will be well placed to complement the HR efforts described above by updating existing security measures, implementing new ones, and explaining any changes to employees. This might include a new personal device use policy (or “bring your own device” policy) with an explanation of the employer’s right to track and monitor its own devices as well as those of the employee who uses them for their work—all legal in Thailand, as it is in most jurisdictions around the world so long as employees are made aware. IT would likely also find this an ideal time to install new or updated antivirus, spyware, and malware protections. Personal devices will be much more at risk of hacking than fenced-in company IT architecture, so the IT team should install necessary security on personal devices as well if these are to be used for company work outside the workplace. If employees are allowed VPNs or other remote access platforms as a backup to the business network, employers should decide whether to place any restrictions on downloading, copying or transferring files.

While no business can completely insulate itself from leakage of its proprietary information, most can take steps to significantly reduce the risk, mitigate damages, and prove that reasonable care was taken to protect their property. In these unique times, the best internal teams employers can turn to for assistance in establishing the necessary safeguards are HR and IT.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks.

RELATED INSIGHTS​ 

August 31, 2026
Thailand has introduced a new regulatory framework that may expose foreign nationals who violate the Foreign Business Act (FBA) to deportation. The Regulation of the Office of the Prime Minister on Deportation B.E. 2569 was published in the Government Gazette on August 27, 2026. The regulation establishes an administrative process for referring foreign nationals for deportation where this is deemed necessary in the interests of public order or public morality. It does not create new substantive deportation powers, but it expressly identifies unlawful business conduct under the FBA—including nominee arrangements—as grounds for referral. Grounds for Deportation Referral The regulation sets out five grounds that may give rise to a referral to the relevant authorities: Unlawful entry into, or unlawful stay in, Thailand in violation of immigration laws. Unlawful employment or engagement in work in violation of laws governing the employment of foreign nationals. Carrying on business in violation of the FBA, including through the use of nominee arrangements. Forging official documents or using forged official documents. Committing an offense punishable by imprisonment of five years or more. The framework takes a broad approach, extending not only to the perpetrators of these acts but also to those who facilitate, instigate, or otherwise support such acts. Deportation Risk Following a Criminal Judgment Where a foreign national has committed any of the above offenses and has fully served the sentence imposed pursuant to a final judgment, the interior minister has the power to order deportation. This power also applies where a court has issued a final judgment sentencing a foreign national to imprisonment but has suspended the execution of the sentence, or has imposed a fine. A deportation order may also specify a period during which the foreign national is prohibited from reentering Thailand. FBA Noncompliance: Broader Consequences Noncompliance with the FBA—including
August 28, 2026
When considering a franchise, many people first think of a restaurant, retail chain, or service outlet. From a legal perspective, however, the foundation of every franchise lies in the right to use a brand, which is typically granted through a trademark license. Trademarks are often the most valuable assets in a franchise system. Through a trademark license, a franchisor authorizes a franchisee to use its trademarks, logos, and branding while maintaining control over how the brand is presented to customers. The Role of Trademarks in Franchise Businesses Under the Trademark Law 2019, a mark is defined as a sign that is capable of distinguishing the goods or services of one undertaking from those of others in the course of trade. This distinguishing function is particularly important in a franchise arrangement, where the franchisee’s use of the franchisor’s trademark allows consumers to recognize the source, quality, and reputation of the business. In this way, trademarks help preserve brand identity, strengthen market recognition, and protect the commercial value of the franchise system. Legal Foundation for Franchise Brand Protection Myanmar presently does not have a specific statutory framework governing franchise arrangements. As a result, franchise agreements are generally regulated under the broader applicable legal framework, including the Contract Act 1872, the Trademark Law 2019, the Competition Law 2015, the Consumer Protection Law 2019, and the relevant implementing rules and regulations. The licensing of trademarks within a franchise arrangement is particularly governed by the Trademark Law 2019. Franchisors should ensure that the trademarks intended to be licensed to franchisees in Myanmar are registered under the Trademark Law 2019 and that the relevant trademark license is properly recorded with the Intellectual Property Department (IPD). Trademark License Recordal Under the Trademark Law 2019, the owner of a registered trademark may grant a license to another
August 27, 2026
It is generally understood that patents are granted for new designs that have not been widely known or used in Thailand and not been disclosed anywhere prior to the date of the patent application. It is trite law that design law protects the distinctive appearance or products. Under Section 3 of the Thai Patent Act B.E. 2522, as amended by the Patent Act (No. 2) B.E. 2535 and the Patent Act (No. 3) B.E. 2542, a design is defined as “any form or composition of lines or colors that gives a product a special appearance and can serve as a pattern for an industrial or handicraft product.” This raises an important question. Can a patent be issued for a product design that contains text, numerals, trademarks, or symbols that do not fall under the definition of a design? This issue commonly arises when attempting to register packaging, labels, and graphical user interfaces (GUIs). Until a few years ago, applicants could file design applications with the Thai Patent Office for designs that contained such elements, provided that an appropriate disclaimer was included. This practice was generally accepted by Thai design examiners at that time, but the Patent Office has since implemented a change in its practice that could have a significant impact on applicants for design patents. Where design representations are submitted as line drawings or computer-aided design (CAD) drawings, the examiner may now issue an office action requiring their removal. This practice, however, appears to be applied inconsistently, as some examiners still exercise their own discretion in determining whether drawings containing these elements are acceptable. Below are examples of a GUI design, a CAD drawing design, and a photographic design representation that illustrates issues relating to the presence of nonallowable elements. GUI design For this GUI design, the submitted
August 27, 2026
Franchising in Thailand has matured into a sizeable commercial sector, but the rules governing franchisor–franchisee relationships remain scattered across general legislation rather than consolidated in a dedicated franchise statute. In this environment, the decisions of the Trade Competition Commission of Thailand (TCCT) have emerged as valuable practical guidance. Thailand follows a civil-law system in which judicial and administrative decisions do not create binding precedent; however, past rulings are nonetheless influential. This article examines the most instructive recent TCCT decisions and distills the practical compliance considerations for franchisors and franchisees operating in Thailand. Postcontract Changes: Justified or Unfair? A recurring issue is whether a franchisor may alter the terms of engagement after contract execution. The TCCT has established that midterm modifications are not inherently unfair; the determinative factors are whether there was a reasonable business justification, adequate advance notice, and a transparent process. In a 2023 coffee franchise matter, for instance, the TCCT declined to find a violation where a franchisor increased raw material prices, noting the increase had been communicated in advance and supported by demonstrable cost pressures. A bubble tea franchise matter reinforces this principle. The TCCT found that postcontract mandatory purchases of branded syrup and flavorings were justified, as the agreement reserved the franchisor’s right to modify product requirements, the materials were sold at or below market prices, and the branded ingredients possessed distinctive qualities deemed essential to franchise quality. The complaint was dismissed, with the additional requirements characterized as a legitimate measure to preserve brand consistency. Considered together, these decisions indicate that post‑contract modifications will be evaluated against three criteria: (1) whether there is a legitimate business rationale, (2) whether adequate advance notice was provided, and (3) whether franchisees were treated equitably throughout the transition. Discriminatory Treatment: Are Renewals and Information Equal? A 2024 automotive dealership