You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 5, 2020

The Risk of Trade Secret Misappropriation during Work-from-Home Arrangements

Bangkok Post Human Resources Watch

While we’ve all seen how quickly life has changed during the pandemic, from a business and HR angle the possibility of intellectual property misappropriation and theft occasioned by work-from-home policies may not yet be clear to many. With many employees working outside their company’s normal IT security fence, their increased use of their own computers and devices instead of those in their offices with standard or enhanced security mechanisms has made it more challenging for employers to control access to key business information.

In the rush to set up a fully or partially remote workforce, most companies had little time to establish work-from-home guidelines on protection of their valuable intangible assets like trade secrets and confidential business information. Most employers would likely have sufficient internal guidelines on copying files to USB drives, emailing files to personal accounts, and uploading to cloud storages like Dropbox, Google Drive, or OneDrive, but who could have imagined the need for rules precluding sharing proprietary information over Zoom, Skype, Webex, House Party, Ring Central, or Microsoft Teams?

In addition to willful or unknowing misappropriation by employees, perhaps the biggest threat to many businesses are those unscrupulous hackers who have exploited vulnerable IT protocols and baited people with luring emails related to the current health crisis. Phishing and ransomware emails such as information on vaccines, fake COVID-19 maps, free technology to improve online conferencing platforms, and various other pandemic-related messages have been used to bait people working from home in attempts to access otherwise protected systems. Hacking of smart home devices has resulted in recordings of what was supposed to be confidential conversations being transmitted to not only Amazon, Google, and other providers but to hackers and thieves as well.

While all sectors are suffering from more frequent ransomware attacks, research from Microsoft has shown that the healthcare sector has been particularly affected. The U.S. Department of Health and Human Services faced attempted breaches in early March, but fortunately they survived that scare. However, the University of California, San Francisco, recently suffered a large-scale attack resulting in USD 1.14 million being paid to hackers to prevent the permanent loss of important COVID-19-related research data. Interpol and Europol have taken this threat very seriously, posting COVID-19-specific online cyberthreats to educate the public about these very real and harmful threats. Corporations too should plan out effective incident responses and raise awareness with their employees to prevent future infiltrations.

Given this background, there are a couple of important steps that employers should take to start protecting themselves from theft (either intentional or not) or to enhance existing protocols.

First, each employer should speak to the company’s HR team to make sure he or she understands the existing workplace rules regarding the handling and maintenance of confidential business information.

Now is the time for HR to revisit existing rules and update them for the new normal. This should include a refresher in employment agreements or individual confidentiality agreements (particularly important for key personnel) to accommodate work-from-home realities. In order to successfully prove a case against a trade secret infringer, the owner must show demonstrable evidence that all reasonable care was taken to maintain the confidential information. This would include regular reminders to employees about what is meant by “confidential information” or “trade secrets” and their duty to maintain that confidentiality if they are allowed access.

Employee sharing of business information has accelerated with the increased adoption of some of the platforms mentioned above. While many employees would already be familiar with a company’s rules on disclosing to third parties, such as doing so only under a written non-disclosure agreement, this is complicated with the new ways in which we are all now communicating outside our companies. Document sharing can be controlled by secure transfer tools like password-protected FTP programs, time-limited document viewers, and limitation of the number of downloads.

For businesses in the unfortunate circumstance of having to lay off or furlough employees because of the pandemic, work-from-home realities make the exit interview even more important. In addition to existing requirements such as return of all company property (including loaner devices used from home), HR will want to secure additional undertakings, such as assurances that no unauthorized copying or downloading occurred on any device, no company information is retained in any form, and no confidential information was shared with third parties without proven authorization. Also, if the departing employee was a member of any R&D, design, or engineering team, an enhanced exit interview is an ideal time to effect IP assignments or other declarations necessary to vest all employee-created IP or improvements in the employer (preferably before termination). Even if the research project is incomplete, this might be a good time also to consider filing provisional patent applications with the employee’s written further assurance that subsequent follow-on applications will not be jeopardized.

Second, employers should talk to the company’s IT team about existing security measures and any necessary enhancements.

The IT team will be well placed to complement the HR efforts described above by updating existing security measures, implementing new ones, and explaining any changes to employees. This might include a new personal device use policy (or “bring your own device” policy) with an explanation of the employer’s right to track and monitor its own devices as well as those of the employee who uses them for their work—all legal in Thailand, as it is in most jurisdictions around the world so long as employees are made aware. IT would likely also find this an ideal time to install new or updated antivirus, spyware, and malware protections. Personal devices will be much more at risk of hacking than fenced-in company IT architecture, so the IT team should install necessary security on personal devices as well if these are to be used for company work outside the workplace. If employees are allowed VPNs or other remote access platforms as a backup to the business network, employers should decide whether to place any restrictions on downloading, copying or transferring files.

While no business can completely insulate itself from leakage of its proprietary information, most can take steps to significantly reduce the risk, mitigate damages, and prove that reasonable care was taken to protect their property. In these unique times, the best internal teams employers can turn to for assistance in establishing the necessary safeguards are HR and IT.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks.

RELATED INSIGHTS​ 

July 24, 2026
Indonesia has updated its fee framework for intellectual property (IP)-related government services, with implications for IP owners, licensees, lenders, digital platforms, and businesses operating in the country. Government Regulation No. 30 of 2026 on Types and Tariffs of Non-Tax State Revenue Applicable to the Ministry of Law (GR 30/2026) was promulgated on July 2, 2026, and will take effect on August 1, 2026. Key Takeaways GR 30/2026, which replaces the relevant IP service fees under Government Regulation No. 45 of 2024, reorganizes the fee schedule into separate categories for copyright, industrial designs, patents, layout designs of integrated circuits, trade secrets, trademarks, geographical indications, IP enforcement, and other categories. The most commercially relevant changes include a new copyright recordation tariff exemption for songs and music, higher fees for several trademark and geographical indication services, new IP enforcement service fees, and a new fee type for registration of fiduciary security over IP rights objects. In addition, this is the first major update for trademark fees in approximately 10 years. GR 30/2026 is significant not only as a fee update but also as a further indication of Indonesia’s increasing recognition of IP as a financeable commercial asset. By expressly assigning fees to the registration of fiduciary security over IP rights objects, the regulation places IP-backed collateral filings within the Ministry of Law’s administrative service framework. While GR 30/2026 does not create a new secured-transactions regime, this development is relevant for lenders, borrowers, and IP owners structuring financing arrangements secured by trademarks, patents, copyrights, industrial designs, or other registrable IP rights in Indonesia. Copyright: New Fee Exemption for Songs and Music Recordation For copyright, GR 30/2026 creates a fee-exempt category for recordation of works or related-rights products for songs or music, while maintaining a separate category for other works and related-rights products. It
July 21, 2026
Thailand’s Ministry of Digital Economy and Society (MDES) published a notification establishing an expedited court-ordered takedown mechanism for online content in cases of “urgent necessity.” The notification, which was issued on July 17, 2026, under the Computer Crime Act B.E. 2550 (2007), as amended, took effect the following day. It significantly expands the categories of content subject to rapid government-initiated removal. Content Categories Subject to Takedown The notification defines “urgent necessity” (section 20, paragraph 5, of the Computer Crime Act) as circumstances where any delay in suppressing computer data may impact national security, religion, the monarchy, good morals, social culture, or public order. In this regard, it establishes four broad categories of content: Computer Crime Act offenses. National security offenses. IP and other criminal offenses, where it is contrary to public order or good morals and a competent officer has requested its suppression. Content contrary to public order or good morals, a broad residual category encompassing 14 subcategories approved by the Computer Data Screening Committee. The fourth category is the most expansive. Its 14 subcategories include: Content defaming, mocking, satirizing, or devaluing the monarchy. Online gambling advertising or facilitation. Offering illegal firearms for sale. Offering baraku (hookah) products or e-cigarettes for sale. Offering cannabis inflorescences or processed cannabis products for sale. Advertising or soliciting prostitution. Content inciting violence, hatred, or social division. Unauthorized overseas employment advertising. Offering boiled kratom juice for sale. Online sale or advertising of alcoholic beverages. Content satirizing or degrading Buddhism. Money lending at interest rates exceeding legally prescribed limits. Advertising or disseminating information about surrogacy services. Forgery of documents, cards, or official documents. Enforcement Procedure In cases of urgent necessity, a competent official assigned by the MDES permanent secretary must file a petition with supporting evidence to the court with jurisdiction, requesting an order to
July 15, 2026
Ambush marketing refers to a strategy in which a business associates itself with an event, campaign, or brand without paying for official sponsorship rights. The tactic is most visible in sports, concerts, and festivals, where official sponsors have invested substantially for exclusivity. Ambush marketers may use suggestive wording, event-themed imagery, athlete endorsements, venue-adjacent promotions, or social media campaigns implying a commercial connection with the event. Common Forms of Ambush Marketing Ambush marketing typically takes one of the following forms: Direct ambushing: using event names, logos, or mascots suggesting authorization Coattail ambushing: sponsoring an athlete or broadcaster connected with the event Subtle ambushing: themed advertising, venue-adjacent campaigns, or similar visual cues The legal analysis in each case turns on whether the marketing crosses from permissible event-based advertising into infringement, passing off, deception, or wrongful exploitation of goodwill, and the risk assessment is necessarily fact-specific. Thailand has no dedicated ambush marketing statute, so legality depends on execution. A campaign that merely comments on a public event may be permissible, but one that uses protected marks, creates consumer confusion, misrepresents sponsorship status, or makes unsubstantiated claims may trigger liability under various Thai laws, as laid out below. Ambush Marketing and Thailand’s Trademark Act The Trademark Act B.E. 2534 (1991) is the primary tool for addressing campaigns that use registered trademarks, event names, logos, mascots, or confusingly similar signs. The law gives registered trademark owners the exclusive right to use their mark for registered goods, and infringement risk arises when a nonsponsor uses an event mark or a confusingly similar sign in advertising. Even referential or playful use may create liability if it causes public confusion as to sponsorship or commercial connection. The law also preserves passing-off claims for unregistered marks. This matters because event names, taglines, or mascots may not always be
July 13, 2026
When Decree No. 186/2026/ND-CP (Decree 186) takes effect on July 15, 2026, it will introduce the most significant reform of Vietnam’s administrative IP enforcement framework since Decree 99/2013/ND-CP was issued in 2013. These changes are expected to make administrative enforcement faster, more accessible, and better suited to the realities of modern IP disputes. Below are the principal reforms and their practical implications for rights holders and enforcement practitioners. The End of Notarization and Consular Legalization Among the most welcome procedural changes is the abolition of the notarization and consular legalization requirement for powers of attorney (POA) submitted in administrative enforcement proceedings. Under the previous regime, foreign rights holders were generally required to execute a POA, then have it notarized and consular legalized (if seeking customs recordal). In practice, this process frequently delayed enforcement by four to eight weeks, often long enough for infringing goods to disappear before authorities could intervene. Decree 186 removes this bottleneck, now requiring only an original or certified copy of the POA. If the document is in a foreign language, a Vietnamese translation is sufficient, provided it is certified by a competent authority or confirmed by the authorized Vietnamese IP representative. Consular legalization and notarization are no longer required. For rights holders, the practical impact is substantial. Administrative enforcement files that previously took weeks to prepare can now be completed in a matter of days, allowing much faster responses in time-sensitive matters such as warehouse raids, border interventions, and trade-fair enforcement. The decree also introduces a useful administrative simplification. Where an original POA has already been submitted to the same enforcement authority and remains valid, applicants may rely on a copy of that earlier submission by identifying the previous case file. This eliminates unnecessary duplication for rights holders pursuing multiple enforcement actions before the same