How Can Companies Protect Trade Secrets During Digital Layoffs?

How Can Companies Protect Trade Secrets During Digital Layoffs?

Introduction

Digital layoffs and corporate restructuring create an immediate information-security risk. An exiting employee may still control official social media accounts, cloud applications, email systems, customer databases, or administrative tools after the employment relationship has ended.

Companies should therefore treat offboarding as both an employment process and an information-security process. Access to official social media accounts should be reviewed and, where appropriate, disabled immediately upon the employee’s exit or loss of authority. This reduces the risk of unauthorized posts, deletion of content, disclosure of confidential information, impersonation, and other forms of digital sabotage.

Philippine law protects trade secrets, confidential business information, and client information, but the employer must also show that it took reasonable measures to preserve secrecy. A written confidentiality policy, controlled access, prompt credential revocation, and documented turnover process are therefore important both for prevention and for possible litigation.

What Are Trade Secrets and Confidential Business Information?

Trade secrets may include formulas, processes, technical information, marketing strategies, customer information, business plans, pricing data, internal reports, and other information that has commercial value because it is not generally known.

The Supreme Court has recognized that trade secrets are privileged and protected from compulsory disclosure, subject to a compelling and indispensable reason for their production in judicial proceedings. The Court also identified relevant factors in determining whether information is a trade secret, including how widely the information is known, the measures taken to protect it, its value to the employer and competitors, the resources spent in developing it, and the ease with which it may be independently obtained ([Air Philippines Corporation v. Pennswell, Inc. (2007)](#J2.9)).

An employer’s unilateral declaration that information is confidential is not conclusive. The employer must have a substantial factual basis that can withstand judicial scrutiny; otherwise, almost any information could be labeled a trade secret and used unfairly against an employee ([Air Philippines Corporation v. Pennswell, Inc. (2007)](#J2.9)).

Why Official Social Media Accounts Require Immediate Protection

An official company account is more than a communications channel. It may provide access to customer messages, advertising accounts, payment settings, analytics, unpublished campaigns, personal information, and other connected business systems.

If an exiting employee retains administrator privileges, the employee may be able to:

  • publish unauthorized statements or announcements;
  • delete posts, pages, advertisements, or account records;
  • change passwords, recovery emails, or administrator roles;
  • disclose confidential business information;
  • impersonate company officers or representatives;
  • redirect customers to unauthorized accounts or payment channels; or
  • use connected systems to access additional company data.

The available authorities do not establish a universal statutory rule using the exact phrase “instant revocation” of social media access in every layoff. Nevertheless, prompt revocation is a sound security measure consistent with the employer’s duty to protect confidential and proprietary information and the lawyer’s separate duty to safeguard client confidences where legal professionals are involved.

What Philippine Laws Apply?

Trade-secret protection under the Revised Penal Code

The Revised Penal Code penalizes the disclosure of a principal’s or employer’s secrets by a manager, employee, or servant who learned them because of the position. Article 291, as amended, imposes arresto mayor and a fine not exceeding P100,000 on the responsible person ([Republic Act No. 10951 (2017)](#L5.76)).

Article 292 separately penalizes the revelation of industrial secrets by a person in charge, employee, or workman of a manufacturing or industrial establishment, when the disclosure prejudices the owner ([Revised Penal Code (1930)](#L6.299)).

These provisions do not mean that every internal company document is automatically a protected secret. The employer should be able to establish the confidential character of the information, the employee’s access to it by reason of employment, the unauthorized disclosure, and the resulting or intended prejudice.

Data privacy and information-security duties

Where an employee has access to personal information, the employer must implement reasonable and appropriate organizational, physical, and technical measures against accidental or unlawful destruction, alteration, disclosure, and other unlawful processing. This requirement is reflected in Section 20 of the Data Privacy Act and in National Privacy Commission guidance and decisions ([NPC BN 18-194 (2023)](#I10.8)).

For telecommuting arrangements, the employer and employee must agree on minimum standards protecting personal information. The employer is responsible for appropriate protective measures, while the employee must comply with company data-privacy rules and protect confidential and proprietary information ([Implementing Rules and Regulations of Republic Act No. 11165 (2019)](#I9.4)).

Accordingly, access revocation should cover not only social media accounts but also business email, cloud storage, customer relationship systems, collaboration platforms, advertising accounts, password managers, and other systems containing personal or confidential information.

Lawyer confidentiality and social media

Where the company or employee is a lawyer, the Code of Professional Responsibility and Accountability requires a lawyer who uses social media in relation to client confidences or information to exert efforts to prevent inadvertent or unauthorized disclosure, unauthorized use, or unauthorized access to the account ([Code of Professional Responsibility and Accountability (2023)](#L1.47)).

This duty supports strict access controls for law-firm pages, professional accounts, client communications, and social-media management platforms. A departing lawyer or staff member should not retain access merely because the person created the account or previously administered it.

Can an Employer Discipline or Dismiss an Employee for Disclosure?

Yes, but the employer must establish the legal and factual basis for the disciplinary action. A dismissal based on loss of trust and confidence generally requires that the employee occupy a position of trust and that there be a clearly established act justifying the loss of confidence.

The Supreme Court has also ruled that vague or overly broad company rules on confidential information cannot automatically support dismissal. A disclosure made in good faith and for a legitimate purpose, such as pursuing a legal claim, may not justify termination ([Yonzon v. Coca-Cola Bottlers Philippines, Inc. (2021)](#J3.5)).

Employers should therefore avoid relying solely on a general statement that “all company information is confidential.” Policies should identify protected categories, explain permitted disclosures, define authorized recipients, and state the consequences of unauthorized access or disclosure.

When Should Social Media Access Be Revoked?

Access should be revoked at the earliest point when the employee no longer needs it for legitimate business purposes. In ordinary circumstances, this should occur at the same time that the resignation, termination, layoff, or reassignment becomes effective.

Earlier action may be appropriate when there is a credible risk of sabotage, threatened disclosure, unauthorized access, hostility, or misuse of company systems. In that situation, the employer may disable access before communicating the employment decision, provided that the action is handled consistently with due process, company policy, employment agreements, and applicable labor rules.

The revocation process should be coordinated with Human Resources, information technology, communications personnel, and the employee’s supervisor. No single department should assume that disabling an email account automatically removes access to all connected platforms.

What Should an Offboarding Protocol Include?

A sound digital-offboarding protocol should include the following measures:

AreaRecommended measure
Identity and credentialsDisable company email, single-sign-on credentials, VPN access, password-manager access, and multi-factor authentication tokens.
Social mediaRemove the employee from administrator, editor, advertiser, analyst, and recovery roles on all official accounts.
PasswordsChange shared passwords and recovery details, particularly where credentials were previously known by the employee.
Connected applicationsRevoke access to cloud storage, advertising tools, customer platforms, messaging applications, and third-party integrations.
Company property and dataRecover devices, preserve relevant records, and require the return or deletion of company information subject to lawful preservation duties.
DocumentationRecord the date, time, systems affected, persons who approved the action, and confirmation that access was disabled.

How Should Companies Preserve Evidence?

Before deleting or altering an account, the company should preserve relevant evidence when litigation, an administrative complaint, a criminal investigation, or a data-breach inquiry is reasonably anticipated. This may include login records, audit trails, messages, screenshots, access lists, system alerts, and copies of unauthorized posts.

Evidence should be collected in a manner that preserves authenticity and chain of custody. The company should avoid unnecessary alteration of the account or device and should limit access to personnel authorized to conduct the investigation.

Under the Rules on Cybercrime Warrants, specialized procedures apply to the preservation, disclosure, interception, search, seizure, examination, and custody of computer data in appropriate criminal investigations ([Rules on Cybercrime Warrants (2018)](#J7.0)). Companies should obtain legal advice before conducting invasive searches of personal devices or accounts, particularly where privacy rights or employee-owned equipment are involved.

What If the Employee Posts Unauthorized Content?

The company should first secure the account, preserve evidence, and determine whether the post contains personal information, trade secrets, defamatory statements, fraudulent representations, or other unlawful content.

If the post involves personal information, the company should assess whether an unauthorized disclosure or security incident occurred and whether notification or remedial action is required. The Data Privacy Act requires personal information controllers to maintain reasonable and appropriate security measures, while applicable breach rules may require timely action after knowledge or reasonable belief of a qualifying breach ([NPC BN 23-027 (2023)](#I4.2)).

If the conduct involves unauthorized access or computer-related offenses, the company may consider civil, administrative, or criminal remedies, subject to the evidence and the specific elements of the offense. The Cybercrime Prevention Act also provides mechanisms for restricting or blocking computer data that is prima facie found to violate the statute ([Republic Act No. 10175 (2012)](#L4.24)).

Can a Company Restrict an Employee’s Post-Employment Activities?

A confidentiality obligation may continue after employment ends, particularly where the information remains confidential and the agreement is reasonable. A non-involvement or non-compete clause is not automatically void, provided that it is reasonable as to time, trade, and place and is no greater than necessary to protect the employer’s legitimate interests ([Tiu v. Platinum Plans Phil., Inc. (2007)](#J5.7)).

Confidentiality restrictions should not be drafted so broadly that they prevent an employee from using general knowledge, experience, or publicly available information. The agreement should identify the protected information and distinguish it from ordinary skills and information in the public domain.

Illustrative Scenarios

Scenario 1: Marketing administrator after termination

An employee who managed the company’s Facebook and advertising accounts is terminated at 5:00 p.m. The company should remove the employee’s administrator access at or before the effective time, change shared credentials, verify recovery settings, and preserve the account’s audit history.

Scenario 2: Employee retains access after resignation

An employee resigns but remains available for a two-week turnover period. Continued access may be permitted if genuinely necessary, but it should be limited to identified systems and monitored. Administrative privileges should be removed as soon as the business need ends.

Scenario 3: Unauthorized disclosure of customer information

A departing employee posts customer names and contact details on a personal account. The company should immediately secure the affected systems, preserve the post and access records, assess the incident under the Data Privacy Act, and consider appropriate employment, civil, administrative, or criminal remedies.

Recommended Company Policy Language

A company policy may state that all employees must surrender or cease using company credentials, devices, accounts, and information upon separation or whenever access is withdrawn. It may also provide that the company may immediately suspend or revoke access where necessary to protect company systems, personal information, trade secrets, customers, or business operations.

The policy should identify the company’s official accounts, designate authorized administrators, prohibit credential sharing, require multi-factor authentication where available, and impose a duty to report suspected unauthorized access. It should also state that access revocation does not authorize the company to disregard applicable privacy, labor, evidence-preservation, or due-process requirements.

Final Observations

Immediate access revocation is an important control during digital layoffs and corporate restructuring, but it should form part of a documented offboarding system rather than operate as an isolated technical reaction.

Companies should maintain updated access inventories, assign at least two authorized administrators to official social media accounts, use individual credentials instead of shared passwords, require multi-factor authentication, conduct exit interviews, preserve evidence when appropriate, and review confidentiality and data-privacy policies regularly.

These steps help establish that the company took reasonable measures to protect confidential information. They also reduce the risk that a former employee can use company accounts to publish unauthorized material, disclose personal information, compromise business systems, or interfere with the company’s operations.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH