How Can Companies Protect Trade Secrets on Social Networks?

How Can Companies Protect Trade Secrets on Social Networks?

Introduction

Employees increasingly use social networks, messaging applications, cloud platforms, and remote-work tools to communicate about corporate projects. An accidental post, screenshot, forwarded file, or message may expose product plans, customer information, salary data, business strategies, technical processes, or other confidential material.

Philippine law allows companies to protect legitimate confidential information through non-disclosure agreements, reasonable workplace rules, data-protection measures, and appropriate legal action. However, an employer cannot simply label every company-related document as a trade secret. The information must be sufficiently confidential, and any disciplinary penalty must be supported by substantial evidence and a fair rule.

What Information May Qualify as a Trade Secret?

Philippine jurisprudence recognizes that information may receive trade-secret protection when its confidentiality has a factual and commercial basis. Relevant considerations include:

  • the extent to which the information is known outside the business;
  • the extent to which employees and other persons within the business know it;
  • the measures taken to preserve its secrecy;
  • the information’s value to the company and its competitors;
  • the effort or expense incurred in developing it; and
  • the ease with which the information may be obtained independently.

(Air Philippines Corporation v. Pennswell, Inc., G.R. No. 172835, December 13, 2007.)

Examples may include unreleased formulas, technical processes, source materials, confidential research, product-development plans, pricing strategies, customer lists, internal business plans, and nonpublic commercial data. Confidentiality is weakened when the information is already publicly available or has been voluntarily disclosed without meaningful restrictions.

Why Non-Disclosure Agreements Matter

A non-disclosure agreement, or NDA, identifies the information that must remain confidential and states the employee’s duties during and after employment. It may also restrict copying, use, publication, transfer, or disclosure to unauthorized persons.

A properly drafted NDA should describe, as specifically as possible:

  • the categories of confidential information covered;
  • the permitted business purpose for using the information;
  • the persons authorized to receive it;
  • the employee’s security and handling obligations;
  • the duration of confidentiality duties;
  • the return or deletion of company materials; and
  • the contractual consequences of an unauthorized disclosure.

Confidentiality clauses should not be so broad that employees cannot determine what conduct is prohibited. In Yonzon v. Coca-Cola Bottlers Philippines, Inc., G.R. No. 226244, June 16, 2021, the Supreme Court held that a company rule covering broad and undefined categories of information may be unfair and unreasonable. The Court emphasized that workplace rules must be fair and reasonable, and that the penalty must be commensurate with the offense.

Can an Employee Be Dismissed for an Accidental Online Disclosure?

Not automatically. An accidental disclosure may justify discipline only after examining the employee’s position, the nature of the information, the applicable company rule, the circumstances of the disclosure, the employee’s intent or negligence, the actual or probable harm, and the employee’s opportunity to respond.

For dismissal based on loss of trust and confidence, the employee must generally occupy a position of trust—such as a managerial or fiduciary position—and the employer must establish a clearly proven act that justifies the loss of trust. A vague policy or an unsubstantiated claim that information was confidential is insufficient. (Yonzon v. Coca-Cola Bottlers Philippines, Inc., G.R. No. 226244, June 16, 2021.)

Where the employee merely made an inadvertent error, promptly reported it, removed the post, and cooperated with the company’s response, dismissal may be disproportionate. Depending on the circumstances, a warning, retraining, suspension, access restriction, or other proportionate measure may be more defensible.

Confidentiality Rules Must Be Clear and Reasonable

Company policies should distinguish between trade secrets, confidential business information, personal information, and ordinary internal communications. A policy stating that “all company information is confidential” may be challenged if it gives employees no workable standard for determining what may be shared.

In Air Philippines Corporation v. Pennswell, Inc., G.R. No. 172835, December 13, 2007, the Court rejected the idea that an employer’s own characterization conclusively determines whether information is a trade secret. The determination must have a substantial factual basis capable of judicial scrutiny.

Effective policies should identify prohibited conduct, such as:

  • posting unreleased projects or product information;
  • uploading internal files to personal cloud storage;
  • sending company documents through unauthorized messaging accounts;
  • discussing confidential matters in public online groups; and
  • sharing screenshots, recordings, credentials, or internal links.

Trade Secrets and Personal Information Are Not the Same

A corporate project may contain both trade secrets and personal information. For example, a product-development file may include employee names, customer records, compensation data, or contact details. The company should analyze both confidentiality and data-privacy obligations.

The Data Privacy Act of 2012 applies to the processing of personal information. Processing connected with the establishment, exercise, or defense of legal claims may be permissible, but it must still observe the general principles of transparency, legitimate purpose, and proportionality. (NPC 19-030 and NPC 19-132, 2021.)

In Yonzon v. Coca-Cola Bottlers Philippines, Inc., G.R. No. 226244, June 16, 2021, the Court considered the argument that employee salary information could be processed for the protection of lawful rights and legal claims. The existence of a privacy interest, however, does not by itself establish that an employee committed a dismissible offense. The employer must still prove the violation and apply a valid, sufficiently definite rule.

Special Duties for Remote and Telecommuting Employees

Employers remain responsible for taking appropriate measures to protect data used and processed by telecommuting employees for professional purposes. Employees must also protect confidential and proprietary information at all times.

(Republic Act No. 11165, Section 6.)

For remote work, companies should use access controls, multi-factor authentication, encrypted storage, approved communication tools, screen-locking requirements, clean-desk rules, and restrictions on downloading or forwarding files. These measures help establish that the company took reasonable steps to preserve secrecy.

What Legal Actions May a Company Take?

Internal investigation and disciplinary proceedings

The company should preserve the relevant post, message, file history, access logs, and witness accounts. It should then issue a notice describing the alleged violation and provide the employee a meaningful opportunity to respond.

The investigation should determine whether the disclosure was intentional, negligent, or genuinely accidental; whether the information was confidential; whether the employee was authorized to access or share it; whether the post was public or limited to a private group; and whether the employee took corrective action.

Contractual remedies

An NDA may support a claim for damages or other contractual relief if the company proves a binding obligation, a prohibited disclosure or use, and resulting damage or a legally recognized basis for relief. The company should also examine whether the NDA was signed by the proper parties and whether the person bringing the action has the right to enforce it.

In Todd A. Fitts v. Kimes Food International, Inc., IPO Bureau of Legal Affairs Decision No. 2016-03, 2016, the Bureau recognized that enforcement of an NDA belongs to the proper contracting party or an authorized successor. A person who is not the contracting party or authorized representative may lack a legal basis to enforce the agreement.

Judicial protection against disclosure

Trade secrets may receive protection in judicial proceedings. Under the Rules on Evidence, a person generally cannot be compelled to testify about a trade secret unless withholding the information would conceal fraud or otherwise work injustice. When disclosure is ordered, the court must take protective measures appropriate to the owner’s interests, the parties’ interests, and the administration of justice.

(2019 Amendments to the 1989 Revised Rules on Evidence, Rule 130, Section 26.)

The Supreme Court has also recognized that trade secrets are privileged and should not be compelled without a compelling and indispensable reason. A party seeking disclosure must show more than ordinary usefulness to its defense in a civil case.

(Air Philippines Corporation v. Pennswell, Inc., G.R. No. 172835, December 13, 2007.)

Data-privacy and breach-response measures

If the online disclosure involves personal information, the company should assess whether a personal-data breach occurred and whether notification or other regulatory action is required. Internal policies should identify responsible personnel, escalation procedures, documentation requirements, and coordination with the data-protection officer.

Companies should not automatically characterize every incident as a reportable breach. The assessment should consider the information involved, the persons who received it, the likelihood of harm, containment measures, and the applicable requirements of the Data Privacy Act and National Privacy Commission issuances.

Typical Examples

Accidental photograph of a confidential presentation. An employee posts a workplace photograph showing an unreleased product design. The company should immediately request deletion, preserve evidence, determine the audience and duration of exposure, and assess whether the employee violated a clear policy.

Forwarding a project file to a personal account. An employee sends a confidential file to a personal email address to work from home. The conduct may violate security rules even without an intent to disclose, but the proper sanction depends on the employee’s explanation, the sensitivity of the file, the company’s policy, and whether unauthorized persons accessed it.

Disclosure to support a legal claim. An employee shares limited company information with counsel or a government authority to pursue a lawful claim. A company should assess whether the disclosure was necessary, proportionate, and legally permitted before imposing discipline. A blanket confidentiality rule cannot validly prohibit every disclosure made for a legitimate legal purpose.

Recommended Company Measures

  • Use an NDA that defines confidential information with reasonable specificity.
  • Adopt a separate social-media, acceptable-use, and information-security policy.
  • Classify information according to sensitivity and apply access restrictions.
  • Train employees using realistic examples involving posts, screenshots, messaging applications, and remote work.
  • Require immediate reporting of mistaken disclosures and reward prompt containment.
  • Maintain access logs and documented incident-response procedures.
  • Apply discipline consistently and proportionately.
  • Review policies periodically to account for new platforms and communication tools.

Conclusion

Protecting corporate trade secrets on social networks requires more than a broad confidentiality clause. The company must identify genuinely confidential information, impose clear and reasonable duties, use technical safeguards, train personnel, and investigate incidents fairly.

An inadvertent disclosure may justify corrective action, but dismissal or litigation should follow only after the company establishes the confidential nature of the information, the employee’s breach of a valid duty, the applicable degree of fault, and the proportionality of the response. Prompt containment, careful documentation, and a properly drafted NDA provide the strongest basis for protecting business information while respecting employee rights.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH