Trade-Secret Cases Are Won Years Before Anyone Resigns. Ask Faccenda Chicken.
Apple's fight with OpenAI over two departed engineers turns on boundaries drawn, or never drawn, long before anyone resigned. English law scores it the same way, and has since a chicken firm sued its own sales manager in the 1980s.
"How do I protect trade secrets when an employee leaves?" is the question every general counsel eventually hears, and it arrives in the wrong tense. By the time the resignation letter lands, the strength of any future claim has already been fixed, not by lawyers but by identity and account decisions made years earlier. English law has kept score this way for nearly forty years. Most IT estates were never built to match it.
The live demonstration is Apple suing its own former engineers. Apple's complaint names Tang Tan and Chang Liu, two former Apple employees now at OpenAI, and accuses them of taking confidential information and recruiting colleagues on the way out. Those are allegations, not findings. OpenAI has moved to dismiss the case, while Apple seeks a preliminary injunction blocking any use of the claimed secrets while the litigation grinds through a California federal court. Strip out the brand names and the venue and you have the standard shape of every departing-talent fight, in Leeds as much as in Cupertino: one side says "they took our documents", the other says "show me the trade secret".
What does English law protect when an employee walks out?
Less than most employers assume, and the leading authority is about chickens. In Faccenda Chicken v Fowler, the Court of Appeal considered a sales manager who left with the company's delivery routes, customer names and pricing in his head and set up in competition. It held that once employment ends, the implied duty of confidence protects only trade secrets in the strict sense. Confidential information that has merged into an employee's own skill, memory and experience goes with them, unless a valid restrictive covenant says otherwise. Knowledge in the head is protected mobility; files in a bag are a potential claim. A company whose systems can't tell those two apart has no way to enforce a difference the law insists on.
Statute later added a second route, with a sting in it. The Trade Secrets (Enforcement, etc.) Regulations 2018 define a trade secret as information that is secret, has commercial value because it is secret and has been "subject to reasonable steps under the circumstances" to keep it secret. Be precise about jurisdiction here, because most commentary isn't. America's Defend Trade Secrets Act bakes a similar "reasonable measures" requirement into a single federal definition, and that is the test Apple must meet. England is messier: the 2018 Regulations sit alongside the older action for breach of confidence, which carries no statutory reasonable-steps limb, so a claimant here has two routes rather than one. The comfort is limited. Fail the reasonable-steps test and you forfeit the statutory route outright, and you hand the defence its cross-examination script for the other.
Why does linking personal accounts to work devices matter?
Because "reasonable steps" is judged on what actually happened across your estate, not on what the policy document said. One allegation orbiting Apple should worry every business that runs on convenience: a separate employee lawsuit, reported by the Los Angeles Times, alleges that staff commonly link company-issued devices to personal iCloud accounts. An allegation, in a different dispute, and unproven. But the pattern it describes is close to universal, because it's the pattern the platforms reward. Running two hermetically separate identities on consumer-grade ecosystems means two sign-ins, two photo libraries, two payment methods and constant toggling. Staff link accounts because linking is the path of least resistance, and nobody objects on day one. The company banks the convenience immediately and pays for it years later, in the only currency courts accept: a provable boundary. If a judge asks how the crown jewels were protected and the honest answer is "they lived in an account that also held the employee's holiday photos", the reasonable-steps argument is over before disclosure starts.
The exposure cuts both ways. The hiring company inherits the ambiguity: if your new principal engineer arrives with a personal account full of material nobody can cleanly classify, their former employer's sloppiness has just become your litigation risk.
How do you measure your own exposure?
Run one count this week; no lawyers required. Pull the device inventory from whatever MDM you operate and count the managed devices that also have a consumer identity signed in alongside the work profile: a personal Apple ID syncing iCloud Drive or Photos, a personal Google account with Drive enabled, a personal Microsoft account sitting in the browser. If your tooling can't surface that, sample twenty laptops by hand; the manual version is humbling enough. The resulting percentage is your commingling rate, and it doubles as a preview of the disclosure exercise you'd face in litigation, because every one of those devices is a place where company documents and private material share a container you would be asking a court to believe was kept separate.
Then ask two follow-ups. How much of your genuinely secret material, the strict-sense category Faccenda protects, is restricted to a named list of people rather than to "all staff"? And when you last offboarded someone, could you produce within a day the full list of systems their account could reach? Shrugs at either question mean your trade secrets are currently protected by hope.
How do you protect trade secrets when an employee leaves?
Mostly at onboarding; the exit itself just harvests the evidence. Four moves do most of the work. Make the corporate identity the path of least resistance, so nobody needs a personal fallback to do their job. Tie classification to containers, because a secret that lives everywhere satisfies no definition of one. Make revocation map to reality: pulling an account only works if that account was the sole door. And run exits that name specific artefacts rather than waving at "confidential information", since Faccenda and the 2018 Regulations both reward specificity. None of this is an IT ticket. It is a strategy decision about how your organisation's systems embody its legal position, and it sharpens as software agents start holding credentials of their own: the same boundary logic underpins secure agentic systems, where the "employee" who might walk off with your data is a process.
The blunt version: English law won't stop knowledge leaving the building, and it will only stop documents if you treated them as secrets while you still had them. Count your commingled devices this week and you'll know which side of that line you're on before a court ever tells you.
Questions people ask
Can a company stop a former employee from using what they learned on the job?
Generally no. Since Faccenda Chicken v Fowler, English courts have held that skill, experience and general know-how absorbed during employment belong to the employee and leave with them; only trade secrets in the strict sense remain protected after the exit, unless an enforceable restrictive covenant adds more. The practical fight is therefore almost always about artefacts (documents, files, code, customer data) and the systems that held them, not about knowledge.
What counts as reasonable steps to protect trade secrets in the UK?
The Trade Secrets (Enforcement, etc.) Regulations 2018 make "reasonable steps under the circumstances" part of the definition of a trade secret itself, so a claimant who can't show them has no statutory claim to bring. Courts look at what actually happened day to day: access limited to people who needed it, material marked and stored in controlled locations, confidentiality terms in contracts, and revocation that genuinely cut off access at exit. The older breach-of-confidence route has no statutory steps test, but the same sloppiness undermines it in practice.
Should employees be allowed to sign in to personal accounts on work devices?
Only if you contain it deliberately. Blanket bans usually fail because they fight the platform's incentives; people link accounts because separation is painful. The workable approach is making the corporate identity fully sufficient for the job, using managed profiles or containers to keep data segregated, and accepting that any convenience which merges the two identities is also merging your future evidence.
Related
- On Ubuntu 26.04 LTS, the coreutils Your Build Depends On Isn't GNU Anymore
- The Sovereignty Premium: Why Sovereign AI Solutions for Enterprise Are Winning on Access, Not Speed
- OS-Level Age Verification Will Split the Operating System Market in Two
- Security & Trust
Written by an AI editorial persona of Abyshire's proprietary editorial system and reviewed by our team.