Resources / Enterprise / Trade secrets: documenting your protection

Trade secrets: documenting your protection

2 min read

A recipe, a manufacturing process, an algorithm, a customer database, a pricing strategy. Many companies draw their edge from information they neither patent nor publish. French law protects it as a trade secret, on a condition that is often underestimated: the company must prove that it protected it.

What trade secret law protects

The French Commercial Code protects information that meets three criteria.

It is not known to the public or readily accessible to professionals in the sector.

It has commercial value, actual or potential, because it is secret.

It is subject to reasonable protective measures taken by the company.

The first two criteria describe the information. The third describes your conduct. A dispute often turns on this point. If a former employee or a partner uses your information, you will have to show that you had taken suitable precautions, and since when.

Reasonable measures

No official list sets out these measures. The judge assesses them according to the size of the company, the value of the information and the context. The following practices are commonly expected.

Identify the sensitive information. List the company's strategic information. This is often called mapping. You cannot protect what you have not identified.

Mark documents. A "confidential" label on sensitive documents clearly signals their status to those who receive them.

Restrict access. Only the people who need it have access to sensitive information. IT access rights put this rule into practice.

Cover it by contract. Employment contracts, service contracts and non-disclosure agreements remind everyone of their obligations.

Raise awareness in your teams. A short training session or an internal memo explains what is confidential and why.

Manage departures. When an employee leaves, equipment is returned, access is closed and confidentiality obligations are recalled.

Documenting means proving

These measures only carry weight before a judge if you can show them, with their date. A confidentiality policy written after an incident is far less convincing than one in place for two years.

Timestamp the documents that describe your approach: mapping, internal policy, training materials, access lists. Timestamp the sensitive information itself as well. You will then be able to show what you held, since when, and how you protected it.

Update these documents regularly, and timestamp each new version. The history shows that protection is maintained over time.

With Ipocamp, in practice

Ipocamp timestamps each document within seconds. The certificate relies only on the file fingerprint. When the file itself is stored, it is transferred encrypted and its content remains accessible only in your space. This matters precisely when the information is confidential.

You can timestamp your sensitive information, your mapping, your internal policy and their updates. For a team, the shared workspace helps organize these deposits. Find out more about trade secrets with Ipocamp.

This article is for informational purposes only and does not constitute legal advice.

Don't see your question?

Describe your situation: an expert will reply within one business day.

Contact us