Can Freelancers Face Liability for Selling Source Code?
Introduction
Private software developers and freelancers often receive access to proprietary source code, technical specifications, algorithms, databases, and other confidential business information. A serious legal issue arises when a developer transfers that information to a rival entity without the client’s consent.
Article 292 of the Revised Penal Code penalizes the revelation of industrial secrets by certain persons connected with a manufacturing or industrial establishment. However, not every unauthorized disclosure by a freelancer automatically constitutes a criminal offense under this provision. Liability depends on the developer’s legal relationship with the client, the nature of the information disclosed, the prejudice caused, and the evidence establishing the offense.
What Does Article 292 Penalize?
Article 292 of the Revised Penal Code, as amended by Republic Act No. 10951, provides that a person in charge, employee, or workman of a manufacturing or industrial establishment may be punished for revealing the secrets of the industry to the prejudice of the owner.
The current penalty is prision correccional in its minimum and medium periods and a fine not exceeding P100,000. The amendment increased the fine from the former amount of P500.
The provision is directed at an unlawful disclosure of an industrial secret by a person who has a qualifying connection with the establishment that owns the secret. It is not a general criminal prohibition against every breach of confidentiality involving software or digital information.
Who May Be Criminally Liable?
Article 292 identifies three categories of possible offenders: the person in charge, an employee, or a workman of a manufacturing or industrial establishment. The wording requires more than proof that the accused merely came into possession of confidential information.
A freelancer may potentially fall within the provision if the evidence shows that the freelancer functioned as a person in charge, employee, or workman of an industrial establishment, or occupied a substantially similar position within the establishment’s operations. The classification will depend on the actual relationship of the parties rather than the label used in the contract.
A developer described as an independent contractor may therefore still face criminal exposure if the facts show that the person was integrated into the client’s industrial operations, worked under the client’s direction, and obtained the information because of that role. Conversely, a genuinely independent consultant who merely received code under a commercial contract may not automatically be covered by Article 292.
What Information May Qualify as an Industrial Secret?
Article 292 does not define “secrets of the industry” in detail. In the software setting, the information may include source code, proprietary algorithms, system architecture, encryption methods, technical documentation, deployment scripts, database structures, and unpublished software processes.
Confidentiality alone, however, does not necessarily establish that information is an industrial secret. The owner should be able to show that the information has commercial or operational value, is not generally known, and was treated as confidential through reasonable safeguards.
In Air Philippines Corporation v. Pennswell, Inc., G.R. No. 172835, 13 December 2007, the Supreme Court recognized that trade secrets, including technical formulations and compositions, may be protected from compulsory disclosure in judicial proceedings. The decision supports the broader principle that commercially sensitive technical information deserves protection when disclosure would undermine the owner’s legitimate business interests.
Elements of the Offense
For Article 292 to apply, the prosecution must establish the following circumstances:
- The accused was a person in charge, employee, or workman of a manufacturing or industrial establishment.
- The information was an industrial secret belonging to the establishment or its owner.
- The accused revealed the secret to another person or entity.
- The disclosure was made to the prejudice of the owner.
- The accused acted with the required criminal intent or knowingly performed the prohibited disclosure.
The prosecution must connect the accused to the establishment and to the confidential information. It must also prove that an actual revelation occurred, such as sending source-code files, uploading code to a rival’s repository, giving access credentials, or providing technical instructions that enable the rival to use the protected system.
Does Selling Source Code Automatically Constitute a Violation?
No. The sale or transfer of source code does not automatically constitute a violation of Article 292.
The transaction becomes potentially criminal when the code is an industrial secret, the developer was covered by the categories identified in Article 292, the transfer was unauthorized, and the disclosure prejudiced the owner. The prosecution must prove these facts beyond reasonable doubt.
For example, a developer who sells a client’s unpublished proprietary platform to a direct competitor, despite an express confidentiality obligation and restricted access, may expose himself or herself to criminal, civil, and administrative consequences. By contrast, a developer who sells software that was expressly commissioned for unrestricted resale, or who transfers code that was already publicly available, presents a materially different case.
Effect of Confidentiality and Intellectual Property Agreements
A confidentiality agreement, non-disclosure agreement, intellectual property clause, or employment contract may provide important evidence that the information was confidential and that the developer knew disclosure was prohibited.
These agreements do not, by themselves, create criminal liability where the statutory elements of Article 292 are absent. A contractual breach is not automatically a criminal offense. It may instead support a civil action for damages, injunction, specific performance, or other relief under the contract and applicable law.
The agreement should identify the protected information, define permitted uses, restrict disclosure to third parties, address return or destruction of files, and specify ownership of newly developed code. Vague provisions may make it more difficult to establish that the particular code transferred was protected and confidential.
Distinguishing Article 292 from Article 209
Article 209 of the Revised Penal Code concerns betrayal of trust by an attorney or solicitor, including the revelation of client secrets learned in a professional capacity. Republic Act No. 10951 amended the provision and increased the applicable fine to between P40,000 and P200,000.
Article 209 generally does not apply to an ordinary software developer who is not a lawyer or an authorized legal representative. The provision is relevant when the person entrusted with confidential information is an attorney or another person authorized to represent or assist a party in a case.
For a private software developer, Article 292 is the more relevant penal provision among the authorities identified here, although the developer’s actual employment or contractual status must first be established.
Possible Civil and Commercial Consequences
Even if a criminal prosecution under Article 292 cannot be sustained, the client may have other remedies. Depending on the agreement and the evidence, the client may seek:
- damages for breach of contract or unauthorized disclosure;
- an injunction against the continued use or distribution of the source code;
- return or deletion of confidential files and access credentials;
- accounting of profits earned from the unauthorized sale; and
- termination of the developer’s engagement for cause.
The owner may also seek urgent relief when the rival entity is actively using the code or preparing to release a competing product. The availability and form of relief will depend on the contract, the nature of the information, and the procedural posture of the dispute.
Evidence Needed to Establish Liability
A complaint should be supported by evidence showing both the confidential character of the code and the unauthorized transfer. Useful evidence may include:
- the development agreement and confidentiality provisions;
- repository access logs and download histories;
- email, messaging, or payment records showing the sale;
- file hashes, timestamps, and version-control records;
- forensic comparisons between the client’s code and the rival’s software; and
- proof that the owner restricted access and treated the material as confidential.
Digital evidence should be preserved in a manner that supports authentication and integrity. The complainant should avoid altering the original repository, device, or server data before forensic preservation is completed.
Common Scenarios
Employee transfers proprietary code to a competitor. This presents the strongest potential case under Article 292 when the employee worked for an industrial or technology-driven establishment, the code was protected as confidential, and the transfer caused commercial prejudice.
Freelancer sells code created under a custom development contract. The result depends on the freelancer’s actual relationship with the client and the contract’s ownership and confidentiality provisions. The conduct may clearly constitute a contractual breach even if the statutory requirements of Article 292 are disputed.
Developer sells publicly available or open-source code. Article 292 is unlikely to apply if the information was not secret. Other legal issues may still arise if the developer falsely represented ownership, violated an open-source license, or incorporated restricted third-party code.
Developer sells only a general coding technique. General knowledge, skills, and experience ordinarily differ from a client’s particular source code or confidential system design. The owner must identify the specific secret allegedly revealed.
Important Limitations
Article 292 should not be applied merely because a client dislikes the developer’s subsequent work for another company. Competition, employee mobility, and the use of general professional skills are not equivalent to the revelation of an industrial secret.
The prosecution must also establish prejudice to the owner. Evidence of lost sales, duplicated development costs, loss of competitive advantage, unauthorized commercialization, or exposure of security weaknesses may help prove this requirement.
Because criminal statutes are strictly construed against the State, courts should not expand the terms “person in charge,” “employee,” “workman,” or “industrial secret” beyond their legal meaning. A claimant should therefore identify the precise statutory basis for the complaint and distinguish criminal liability from contractual or civil liability.
Recommended Measures for Clients and Developers
Clients should classify confidential code, limit repository permissions, use individual credentials, maintain access logs, require written approval for disclosure, and conduct exit procedures when a developer’s engagement ends.
Developers should review the scope of confidentiality and intellectual property clauses before accepting work for another entity. They should not copy, retain, disclose, or sell client code unless the client has provided clear written authorization.
When a suspected transfer occurs, the client should preserve electronic evidence, suspend compromised credentials, document the commercial harm, and obtain technical and legal assessments before filing a criminal complaint.
Conclusion
Article 292 of the Revised Penal Code may apply when a developer who is legally connected with an industrial establishment reveals its proprietary source code or other industrial secret to a rival and thereby prejudices the owner. The provision does not automatically cover every freelancer or every breach of a software contract.
The decisive issues are the developer’s actual relationship with the establishment, the secret character of the information, the unauthorized revelation, the resulting prejudice, and the quality of the evidence. Parties should therefore distinguish carefully among criminal liability under Article 292, contractual liability, civil remedies, and other protections available under Philippine law.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

