Santa Cruz Trade Secrets Attorney

Trade Secrets. Safeguarding your confidential business information.

Attorney: · California Bar #199874 · Practicing since 1998.

What Qualifies as a Trade Secret Under California Law?

California Civil Code section 3426.1 defines a trade secret as specified information—including a formula, pattern, compilation, program, device, method, technique, or process—that derives actual or potential independent economic value from not being generally known to, and not readily ascertainable by proper means by, others who can obtain value from disclosure or use, and is subject to reasonable secrecy efforts.

A business should identify the information with enough specificity to distinguish it from general skill, public knowledge, and ordinary business records. Examples may include source code, algorithms, manufacturing processes, formulas, pricing methods, nonpublic customer data, product roadmaps, test results, negative know-how, and strategic plans. Calling every document confidential weakens prioritization and can make later identification less credible.

Value and secrecy require evidence. Who uses the information? How does it create advantage? What would a competitor save by obtaining it? Is it available in publications, products, filings, websites, or common industry practice? When was it created and updated? An inventory should record owner, custodian, location, access group, classification, contractual protection, and business reason for secrecy.

Trade secret, patent, copyright, privacy, and contract rights can overlap but do different work. A patent requires public disclosure and can provide exclusion for claimed inventions. Copyright protects expression, not an underlying method. Privacy law protects specified personal information. A confidentiality agreement can cover material broader than trade secrets. Strategy should identify each right instead of assuming one label covers all risk.

What Counts as Reasonable Efforts to Protect Secrecy?

Reasonableness depends on value, sensitivity, threats, company size, technology, workforce, and industry. Core measures can include classification, need-to-know access, strong authentication, encryption, logging, approved repositories, physical controls, visitor procedures, clean desks, secure disposal, and restrictions on downloads or external sharing. No single control is always required, but paper promises without operational controls are vulnerable.

Information should be labeled and handled according to a usable policy. Define public, internal, confidential, and trade secret tiers; list examples; assign owners; state permitted storage and sharing; and provide an exception process. Overclassification produces warning fatigue. High-value secrets should receive stronger access, monitoring, backup, and incident response than routine internal material.

Vendor and collaboration controls matter because secrets often leave company systems. Conduct diligence, limit purpose and access, require written confidentiality and security duties, control subcontractors, set incident notice, permit audits where proportional, and require return or destruction. Data rooms should use named accounts, expiration, watermarking, logs, and staged disclosure during financing or sale.

Training and enforcement demonstrate real practice. Employees should know what information matters, where it belongs, how to share it, and how to report suspicious activity. Managers must follow the same rules. Investigate violations consistently and document remediation. Policies that exist only in an unread handbook may provide weaker evidence of reasonable efforts.

How Should Employers and Business Partners Handle Confidential Information?

Onboarding should secure signed confidentiality and invention agreements before access. Explain role-specific secrets, approved systems, outside-work rules, device policy, and reporting. Provision only necessary access. Record equipment, credentials, repositories, and acknowledgments. California restrictions on invention assignment and restraints on lawful work require current review; a national form may not fit.

During employment, update access as responsibilities change. Separate development, production, finance, and customer systems where appropriate. Monitor abnormal downloads through lawful, disclosed security controls. Require approval for personal devices, removable media, external repositories, AI tools, and collaboration platforms. Legal, privacy, security, and HR teams should coordinate monitoring rather than create an undisclosed surveillance risk.

Offboarding is a high-risk event. Preserve relevant evidence, disable access at the right time, recover devices and credentials, confirm return or deletion, remind the person of continuing duties, and transfer accounts and knowledge. Exit interviews should be factual, not accusatory. If suspicious activity appears, involve counsel before remotely wiping, searching personal property, or contacting a new employer.

Joint ventures, investors, prospective buyers, manufacturers, and consultants need purpose-limited disclosure. Use staged information, clean teams, anonymization, demonstrations, or summaries when full access is unnecessary. Agreements should address ownership of feedback and improvements, residual-memory clauses, compelled disclosure, permitted recipients, and what happens when the deal does not close.

What Should a Company Do When Misappropriation Is Suspected?

Act quickly but preserve accuracy. Secure relevant accounts, logs, devices, messages, repositories, access records, contracts, and file versions. Document who collected data and how. Do not alter source evidence, accuse people publicly, access private accounts without authority, or destroy business material. Forensic specialists may be needed to create defensible images and distinguish normal work from unusual transfer.

Civil Code section 3426.1 defines misappropriation through specified improper acquisition, disclosure, or use. Independent development, reverse engineering, observation of public use, and other proper means may defeat a claim. The company must identify the secret, ownership, reasonable measures, improper conduct, use or disclosure, and harm with evidence—not merely show that someone left for a competitor.

Potential relief can include injunction under section 3426.2 and damages under section 3426.3 when statutory requirements are met. Injunctions must account for actual or threatened misappropriation and statutory limits; they should not become unlawful restraints on a person's work. Damages may involve actual loss, unjust enrichment, or a reasonable royalty where applicable, with enhanced remedies for specified willful and malicious conduct.

Response options include internal remediation, preservation letter, demand, negotiated return and certification, standstill, forensic protocol, notice to a business partner, mediation, or litigation. Insurance, indemnity, employment, privacy, criminal referral, and customer-notice issues may intersect. The response should protect secrecy; public filings and broad internal circulation can disclose what the company seeks to protect.

How Can Trade Secret Counsel Build and Enforce a Protection Program?

Counsel can lead a cross-functional inventory and risk assessment. Rank assets, map data flows, identify insiders and outsiders with access, review contracts, and test controls. Assign remediation by priority and owner. A short list of genuinely valuable secrets with strong measures is more useful than a claim that every file, conversation, and customer name has the same status.

Contracts should align across employees, contractors, vendors, customers, investors, and transaction partners. Define protected information, purpose, exclusions, recipients, care, compelled disclosure, ownership, return, destruction, survival, and remedies. Avoid terms that conflict with whistleblower, protected activity, professional mobility, or other law. Operational teams must be able to follow the obligations promised.

Incident plans should identify legal, HR, security, executive, communications, and insurance contacts. Preserve first; then scope access, containment, business continuity, reporting, and evidence. Predetermine which events require outside forensics or emergency court review. Practice with realistic scenarios such as mass downloads before resignation, vendor compromise, misdirected data-room access, or public repository exposure.

Civil Code section 3426.6 provides a three-year limitation period after misappropriation is discovered or by reasonable diligence should have been discovered, with continuing misappropriation treated as a single claim. Accrual is fact-specific. Prompt investigation protects timing and helps determine whether suspicious events are linked.

Brodsky Law advises California businesses on confidentiality agreements, invention assignments, vendor terms, information controls, departures, investigations, demands, and trade secret litigation. Sasha Brodsky has practiced California law since 1998 and coordinates forensic, employment, privacy, or criminal specialists when needed.

Protection programs need review after new products, acquisitions, remote-work changes, cloud migrations, layoffs, incidents, or major partnerships. Update the inventory, access, agreements, training, and response plan. A control designed for office file cabinets may not protect secrets moving through repositories, personal devices, messaging, and AI systems.

Frequently Asked Questions

Does a nondisclosure agreement automatically create a trade secret?

No. An NDA supports secrecy but does not make public, readily ascertainable, or valueless information a trade secret. California Civil Code section 3426.1 also requires independent economic value from secrecy and reasonable efforts under the circumstances. Classification, access, security, training, vendor controls, and exit procedures should support the contract.

Can a company stop a former employee from working for a competitor?

California generally rejects restraints on lawful professions, trades, and businesses, subject to statutory exceptions. Trade secret law can prohibit actual or threatened misappropriation but should not become a de facto noncompetition order based only on knowledge or a new job. Relief depends on identified secrets, reasonable measures, evidence, and statutory standards. Obtain employment and trade secret advice promptly.

How long does a California trade secret claimant have to sue?

Civil Code section 3426.6 provides three years after misappropriation is discovered or, through reasonable diligence, should have been discovered. Continuing misappropriation constitutes a single claim under the statute. Accrual and discovery depend on facts. Preserve evidence and investigate promptly instead of waiting for complete damage or public proof.

References

California Civil Code § 3426.1 — trade secret and misappropriation definitions.

California Civil Code § 3426.2 — injunctive relief.

California Civil Code § 3426.3 — damages.

California Civil Code § 3426.6 — limitation period.

Related services: Intellectual Property, Labor and Employment, Injunctions and TROs. Contact Sasha Brodsky to discuss a California matter. This page provides general information, not legal advice.