When an NDA breach reaches court, the injured party must prove what was disclosed, in what form, and when — without an independent record, that first element defeats claims that succeed on every other ground.
The Solicitors Journal summed up what IlliquidX Ltd v Altana Wealth Ltd & others [2026] EWCA Civ 874 decided: the Court of Appeal dismissed the defendants' appeal on 10 July 2026, upholding the High Court's findings on breach of confidence and misuse of trade secrets. The claimant prevailed on liability.
What the costs judgment at [2025] EWHC 1566 (Ch) revealed was the price of prevailing without precision. Mr Justice Rajah found that the proceedings had been seriously compromised by IlliquidX's failure to specify its confidential information case with the clarity and precision the court expected — a failure so significant that IlliquidX, having won on liability, recovered only 50 per cent of its costs. The deductions reflected both the failed copyright and joint liability claims (10 per cent conceded) and conduct-related reductions for unclear pleadings and disclosure costs.
The defendants spent over £1.1 million disclosing 13,526 documents to IlliquidX in response to its expansive pleadings, of which only 452 were referred to at trial. A claimant that could not specify what was disclosed, when, and in what form paid substantially for that gap, even after winning the case.
This post examines the three evidential elements NDA enforcement requires, why standard document exchange cannot produce the evidence the courts expect, how the UK legal framework has evolved, and what an independently anchored disclosure record requires across the UK, EU, and US frameworks.
Non-disclosure agreements are among the most widely deployed commercial instruments in UK business, used to protect information shared during negotiations, joint ventures, investment discussions, and employment relationships. Their enforcement operates across two overlapping frameworks.
The first is contractual: the NDA creates a binding obligation, and breach gives rise to a claim for damages and potentially an injunction. The second, introduced by the Trade Secrets (Enforcement, etc.) Regulations 2018, provides a standalone civil remedy for misappropriation of qualifying trade secrets — implementing the EU Trade Secrets Directive (Directive (EU) 2016/943) into UK law and providing parallel protection alongside contractual NDA rights. A trade secret under the Regulations must have commercial value arising from its secrecy, not be generally known or readily accessible to relevant professionals and must have been subject to reasonable steps by the holder to keep it secret.
The National Security Act 2023 added a criminal dimension where the foreign power condition is met — making the unauthorised obtaining, copying, recording, retaining, disclosing, or providing access to a trade secret a criminal offence under section 2, carrying a maximum sentence of 14 years' imprisonment. This reflects the growing legislative recognition that confidential commercial information is a national strategic asset as much as a private one.
IlliquidX illustrates the factual pattern that generates UK trade secret litigation most often. IlliquidX entered into a joint venture agreement and an NDA with Altana and Brevent in connection with a proposed Venezuelan distressed debt fund. The venture failed. Altana established its own Venezuelan distressed debt fund in July 2020. At first instance ([2025] EWHC 299 (Ch)), Rajah J found that Altana and Brevent had breached the NDA and misused IlliquidX's confidential information and trade secrets. The Court of Appeal on 10 July 2026 dismissed the appeal and upheld the judgment including on breach of confidence, with Lord Justice Arnold, Zacaroli and Miles LJJ agreeing. IlliquidX won.
The costs judgment exposed the consequence of winning without the evidence a well-prepared case requires.
When an NDA is breached and the injured party pursues a claim, UK courts require proof of three elements. The first is that confidential information was disclosed in breach of the agreement — specifically, what information was disclosed, in what form it was at the time of disclosure, and when the disclosure took place. The second is that the disclosure caused the claimant a loss. The third is what that loss amounts to in pounds, which requires the claimant to identify the specific information disclosed, demonstrate its commercial value, and show how the defendant's use of it caused a measurable financial consequence.
Speculative losses — what the claimant might have made if a competitor had not learned of their idea — are difficult to recover. Courts are trying to restore the position the claimant would have occupied if the breach had not occurred, and doing so requires evidence of what was shared and what it was worth.
In practice, the first element is where most enforcement actions are weakest. The claimant knows something was disclosed. The respondent may deny it, deny that what was shared was confidential information within the scope of the NDA, dispute the form in which it was shared, or contest the timing of disclosure. Without an independent record of what was sent, when, and in what form, the claimant is relying on their own version of events — which courts treat as partisan rather than independent.
The consequences of failing to establish what was disclosed with precision are significant. An injunction — the most immediate remedy and the one most likely to limit ongoing damage — requires the court to be satisfied that specific confidential information was disclosed. Damages require the claimant to identify and quantify the specific information. In the IlliquidX costs judgment, the court's reference to unclear pleadings and shifting case theories was not peripheral criticism. It was the reason a winning party paid half its own costs.
When confidential information is shared under an NDA, it is typically sent as an email attachment, a cloud link, or a direct file transfer. The sender has a copy in their sent folder. The recipient has a copy in their inbox. Neither of those records is independent.
A party's own sent folder is produced and held by a party with an interest in the outcome. Email metadata can be altered by anyone with administrative access to the relevant server. File system timestamps reflect activity on a specific device and can be altered by re-saving, transferring, or changing system settings. The recipient's copy, if disputed, cannot be independently verified against what was sent. Courts treat all of these records as partisan rather than independent, for the same reason they would not accept either party's unverified account at face value.
The position becomes more complicated when confidential information has been shared across multiple iterations. A business plan updated three times during negotiations, a financial model revised after each meeting, a technical specification updated before final disclosure: each version may carry different commercial significance. Without an independently anchored record of each version at the moment it was shared, the question of which iteration was disclosed when — and what it contained at that moment — becomes a contest of competing assertions.
The IlliquidX case stretched across five years of litigation partly because specifying what exactly was disclosed, to whom, and in what form proved difficult to pin down with the precision the court required.
The requirement to prove what was disclosed and when is not unique to UK proceedings. Every major legal system that protects confidential commercial information imposes the same first burden on the claimant.
In the European Union, Article 6 of the Trade Secrets Directive requires a claimant to identify the trade secrets at issue with sufficient clarity to constitute them as confidential. This requirement is implemented in the UK through the 2018 Regulations. The need to specify the confidential information with particularity — not in vague or general terms — is a threshold the court cannot dispense with, since it is the basis for any injunction, damages assessment, or enforcement order.
Under the EU framework, eIDAS Article 41 provides that a qualified electronic timestamp from an accredited Qualified Trust Service Provider carries a legal presumption of accuracy as to the date of the timestamp and the integrity of the bound data. Applied to a disclosure record, this provides the independent evidentiary anchor the proceedings will require.
US federal law extended the same framework in 2016, when the Defend Trade Secrets Act (DTSA) created a federal civil cause of action for trade secret misappropriation. The plaintiff must identify the trade secret with reasonable particularity and show that the defendant acquired, disclosed, or used it through improper means. Courts have been consistently strict on the identification requirement: a plaintiff who cannot describe the secret with sufficient specificity to distinguish it from publicly available information cannot proceed. The DTSA is supplemented by the Economic Espionage Act 1996, which criminalises trade secret theft — with 10 years' imprisonment for theft of trade secrets generally and 15 years where a foreign power benefits.
Federal Rules of Evidence 902(13) and 902(14) provide a self-authentication route for electronic records generated by, or copied from, electronic devices, with a certification from a qualified person establishing the accuracy of the process. A timestamped, cryptographically verified record of a disclosure event falls squarely within what those rules were designed to authenticate.
The US, EU, and UK frameworks each require the claimant to identify what was disclosed with particularity. In each, a claimant relying on records they produced and held themselves — email sent folders, cloud storage logs, file system timestamps — is relying on partisan evidence that the defendant can challenge and the court must discount. The answer is an independent record made at the time of disclosure, held beyond any party's control, in a form that cannot be altered.
An evidential record of a disclosure that can withstand challenge in UK, EU, or US proceedings must satisfy three requirements. First, it must be independent — created by a source with no stake in the outcome of any dispute. Second, it must be contemporaneous — recorded at or near the moment of disclosure, not reconstructed from system logs after the dispute began. Third, it must be verifiable — checkable by any court, expert, or counterparty using tools neither party controls.
Cryptographic prior proof at the qualified standard delivers all three:
Applied across a negotiation or joint venture, this approach creates an anchored version history for every document disclosed under the NDA — each iteration independently dated and verifiable, each answering the question the court will ask: what exactly was disclosed, in what form, and at what moment.
The value of an independently anchored disclosure record does not begin at the moment of breach. It begins at the moment of disclosure, and it changes the position of both parties from there.
A recipient who knows that the confidential material they received is independently fingerprinted and timestamped in a form that cannot be altered operates differently from one who received a file with no independent record attached. The record does not prevent misuse. What it does is make misuse immediately traceable to the specific version of the specific document disclosed at the specific moment — removing any ambiguity about what was received, when, and what it contained.
When a breach does occur, the claimant's position changes in kind. The first element of proof — what was disclosed, in what form, and when — is answered by the record rather than by a contest of competing assertions. The evidence that IlliquidX spent five years of litigation and £1.1 million in disclosure costs trying to establish would have been fixed in advance for a fraction of that cost. The case would have been faster to plead, cheaper to litigate, and more expensive for the defendants to resist.
An NDA creates the obligation. The independent record of disclosure is what makes that obligation enforceable when it matters.
Developments in UK Trade Secret Litigation for 2025 — IPWatchdog
IlliquidX Ltd v Altana Wealth Ltd & others [2026] EWCA Civ 874 — Solicitors Journal analysis
Trade Secrets (Enforcement, etc.) Regulations 2018 — full text
CPR 32.19: What UK Courts Require to Prove a Document Is Authentic
This post provides general information about the role of cryptographic evidence. It is not legal advice. For advice on a specific matter, consult a qualified lawyer in your jurisdiction.
James Snell is the founder of Provlyn, a platform providing cryptographic prior proof of IP ownership. provlyn.com