You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 5, 2020

The Risk of Trade Secret Misappropriation during Work-from-Home Arrangements

Bangkok Post Human Resources Watch

While we’ve all seen how quickly life has changed during the pandemic, from a business and HR angle the possibility of intellectual property misappropriation and theft occasioned by work-from-home policies may not yet be clear to many. With many employees working outside their company’s normal IT security fence, their increased use of their own computers and devices instead of those in their offices with standard or enhanced security mechanisms has made it more challenging for employers to control access to key business information.

In the rush to set up a fully or partially remote workforce, most companies had little time to establish work-from-home guidelines on protection of their valuable intangible assets like trade secrets and confidential business information. Most employers would likely have sufficient internal guidelines on copying files to USB drives, emailing files to personal accounts, and uploading to cloud storages like Dropbox, Google Drive, or OneDrive, but who could have imagined the need for rules precluding sharing proprietary information over Zoom, Skype, Webex, House Party, Ring Central, or Microsoft Teams?

In addition to willful or unknowing misappropriation by employees, perhaps the biggest threat to many businesses are those unscrupulous hackers who have exploited vulnerable IT protocols and baited people with luring emails related to the current health crisis. Phishing and ransomware emails such as information on vaccines, fake COVID-19 maps, free technology to improve online conferencing platforms, and various other pandemic-related messages have been used to bait people working from home in attempts to access otherwise protected systems. Hacking of smart home devices has resulted in recordings of what was supposed to be confidential conversations being transmitted to not only Amazon, Google, and other providers but to hackers and thieves as well.

While all sectors are suffering from more frequent ransomware attacks, research from Microsoft has shown that the healthcare sector has been particularly affected. The U.S. Department of Health and Human Services faced attempted breaches in early March, but fortunately they survived that scare. However, the University of California, San Francisco, recently suffered a large-scale attack resulting in USD 1.14 million being paid to hackers to prevent the permanent loss of important COVID-19-related research data. Interpol and Europol have taken this threat very seriously, posting COVID-19-specific online cyberthreats to educate the public about these very real and harmful threats. Corporations too should plan out effective incident responses and raise awareness with their employees to prevent future infiltrations.

Given this background, there are a couple of important steps that employers should take to start protecting themselves from theft (either intentional or not) or to enhance existing protocols.

First, each employer should speak to the company’s HR team to make sure he or she understands the existing workplace rules regarding the handling and maintenance of confidential business information.

Now is the time for HR to revisit existing rules and update them for the new normal. This should include a refresher in employment agreements or individual confidentiality agreements (particularly important for key personnel) to accommodate work-from-home realities. In order to successfully prove a case against a trade secret infringer, the owner must show demonstrable evidence that all reasonable care was taken to maintain the confidential information. This would include regular reminders to employees about what is meant by “confidential information” or “trade secrets” and their duty to maintain that confidentiality if they are allowed access.

Employee sharing of business information has accelerated with the increased adoption of some of the platforms mentioned above. While many employees would already be familiar with a company’s rules on disclosing to third parties, such as doing so only under a written non-disclosure agreement, this is complicated with the new ways in which we are all now communicating outside our companies. Document sharing can be controlled by secure transfer tools like password-protected FTP programs, time-limited document viewers, and limitation of the number of downloads.

For businesses in the unfortunate circumstance of having to lay off or furlough employees because of the pandemic, work-from-home realities make the exit interview even more important. In addition to existing requirements such as return of all company property (including loaner devices used from home), HR will want to secure additional undertakings, such as assurances that no unauthorized copying or downloading occurred on any device, no company information is retained in any form, and no confidential information was shared with third parties without proven authorization. Also, if the departing employee was a member of any R&D, design, or engineering team, an enhanced exit interview is an ideal time to effect IP assignments or other declarations necessary to vest all employee-created IP or improvements in the employer (preferably before termination). Even if the research project is incomplete, this might be a good time also to consider filing provisional patent applications with the employee’s written further assurance that subsequent follow-on applications will not be jeopardized.

Second, employers should talk to the company’s IT team about existing security measures and any necessary enhancements.

The IT team will be well placed to complement the HR efforts described above by updating existing security measures, implementing new ones, and explaining any changes to employees. This might include a new personal device use policy (or “bring your own device” policy) with an explanation of the employer’s right to track and monitor its own devices as well as those of the employee who uses them for their work—all legal in Thailand, as it is in most jurisdictions around the world so long as employees are made aware. IT would likely also find this an ideal time to install new or updated antivirus, spyware, and malware protections. Personal devices will be much more at risk of hacking than fenced-in company IT architecture, so the IT team should install necessary security on personal devices as well if these are to be used for company work outside the workplace. If employees are allowed VPNs or other remote access platforms as a backup to the business network, employers should decide whether to place any restrictions on downloading, copying or transferring files.

While no business can completely insulate itself from leakage of its proprietary information, most can take steps to significantly reduce the risk, mitigate damages, and prove that reasonable care was taken to protect their property. In these unique times, the best internal teams employers can turn to for assistance in establishing the necessary safeguards are HR and IT.

 

This article was originally published in the Bangkok Post and is reproduced here with permission and thanks.

RELATED INSIGHTS​ 

June 16, 2026
Since the implementation of the Trademark Law 2019 on April 1, 2023, Myanmar has operated under a modern first-to-file trademark system that brings its registration framework closer to international practice. As the new regime continues to develop in practice, applicants are increasingly required to navigate formal examination requirements, substantive objections, and procedural deadlines with greater precision. This article provides a high-level review of the trademark examination process in Myanmar, focusing on the principal stages from initial review to approval, the types of objections commonly raised by the Intellectual Property Department (IPD), and the key considerations for responding effectively. A clear understanding of these issues is essential for applicants seeking to secure registration efficiently and to mitigate avoidable delays or refusals. Examination Process: Key Stages Trademark applications filed with the IPD undergo two stages of review. Formality Examination The IPD first verifies compliance with procedural requirements, including: Correct Nice Classification Clear mark representation Accurate applicant details Clearly defined goods or services Representative details, if the application is filed by a representative Other formality requirements cover translation and transliteration of any non-English or non-Myanmar elements in the mark, color claim details, applicable disclaimers, and payment of official fees. Deficiencies result in an office action requiring correction within 30 days, which may be extended upon request. Registrability Examination The IPD also assesses registrability. A mark may be refused if it: Lacks distinctiveness Is descriptive or generic Misleads the public or violates public order/morality Contains prohibited state symbols Only compliant applications proceed to publication. Responding to Office Actions Applicants must respond within 30 days of notification from the IPD. Depending on the nature of the objection, strategies may include submitting legal arguments for distinctiveness, providing evidence of acquired distinctiveness, filing appropriate disclaimers, clarifying descriptions such as color claims, or amending the listed goods
June 15, 2026
The surge in AI development has led to a desperate demand for large, high-quality training data. However, real-world data can be expensive to collect, difficult to access, and often subject to strict privacy and regulatory constraints. Synthetic data, which consists of artificially generated records that replicate the statistical properties of real-world data without reproducing specific individuals’ information, provides an appealing solution by generating artificial datasets at scale without relying on identifiable personal information. It combines speed, cost efficiency, and regulatory compliance, making it a sensible alternative for organizations seeking to reduce risks while maintaining data utility. When properly anonymized, synthetic datasets may fall outside the scope of laws such as the EU’s General Data Protection Regulation (GDPR) or Thailand’s Personal Data Protection Act (PDPA), reducing compliance burdens while still supporting high-quality model training. However, relying on synthetic data without rigorous legal due diligence could be a strategic mistake. It replaces one set of known risks (scraping, direct privacy liability) with a new set of complex liabilities. The narrative that synthetic data is a “silver bullet” for privacy and IP compliance is dangerous and could be misleading. While synthetic data addresses data scarcity, it also introduces new legal uncertainties. Legal counsel should anticipate downstream risks arising from compromised data sources. Models trained on unlawfully obtained data may need to be decommissioned, even if their outputs appear lawful. What is synthetic data? Synthetic data refers to artificially generated information created using AI techniques such as deep learning and generative models. Instead of copying real records, it reproduces the statistical patterns and relationships found in the original dataset. Synthetic data generally falls into three categories: Fully synthetic data – Entirely new data points generated from learned patterns. The model studies the structure of the original data and produces records that resemble real-world
June 10, 2026
In March 2026, the Intellectual Property Office of Vietnam (IP Office) issued a decision refusing a trademark application after considering an opposition based primarily on copyright grounds. The outcome is noteworthy because the foreign brand owner had neither trademark registrations nor applications in Vietnam at the time the opposition was filed, and the IP Office has historically applied a stringent approach to oppositions relying on copyright. The Opposition Maurten is a well-known Swedish sports nutrition brand recognized globally for its innovative hydrogel technology, which is designed to help endurance athletes fuel more effectively without gastrointestinal discomfort. The brand’s distinctive logo is characterized by clean lines and a bold black-and-white color scheme, and has long been associated with the company’s performance products. The brand’s logo is displayed above. An identical mark was filed for registration by a Vietnamese trademark squatter. In 2023, a Vietnamese individual filed an application for registration of an identical mark (Application No. 4-2023-38668), a practice commonly observed in Vietnam as trademark squatting. The brand owner engaged Tilleke & Gibbins to assist with strategy and filing an opposition to the mark. At the time, Maurten had no trademark rights or meaningful use in Vietnam, and global marketing data showed only modest figures without any local presence. Thus, to convince the IP Office to refuse the squatter’s application, instead of relying on trademark rights or use evidence, the opposition strategy centered on the copyright protection of the logo itself, as copyright arises automatically in Vietnam upon creation of the work and does not require registration. (It is worth noting, however, that the IP Office has traditionally been cautious in accepting copyright as a basis for refusing trademark applications.) On September 24, 2024, an opposition was filed on three main grounds: confusing similarity, copyright infringement of the artistic work,
June 10, 2026
For multinational franchisors operating in Thailand, a key risk after franchise termination is that former outlets may continue operating in ways that could easily mislead consumers into believing they remain within the authorized network. To justify such operations, former franchisees often argue that the termination was invalid or ineffective. As a result, these cases are often treated as contractual disputes, making it difficult for franchisors to obtain injunctive relief before a final judgment confirms that the termination was lawful. Franchisors face significant commercial and reputational harm during lengthy proceedings, including consumer confusion, disruption to franchise restructuring, and damage to brand reputation and customer trust. In an encouraging development, the Thai court in a 2025 case responded to the problem of unauthorized post-termination franchise operations by granting interim relief, recognizing broader brand and consumer harm, and awarding substantial damages, highlighting a successful litigation strategy of framing the dispute not merely as a contractual termination issue but as trademark infringement causing ongoing commercial injury. The Subway Case From December 2024 to mid-2025, an unauthorized “Subway®” franchise operation in Thailand attracted substantial public and media attention. Reports and online discussions about unauthorized Subway® stores circulated widely after complaints arose about food quality and customer experience at certain outlets that were allegedly operating after their franchise rights had expired. Because these stores continued to use Subway® trademarks, trade dress, and overall commercial appearance, many consumers were unable to distinguish them from authorized operations, resulting in reputational risks and customer confusion that affected the franchisor’s brand and franchise system in Thailand. Subway treated this matter with the utmost seriousness and moved promptly to protect its brand, franchise system, and customers. It filed a civil action with the IP&IT Court seeking a permanent injunction and damages. During the proceedings, the court granted a preliminary injunction