← Back to blog
Business & Legal

Trade Secrets After Employment Ends: Proving What Existed Before They Left

By James A Snell·13 August 2026

When an employee leaves with a trade secret, the case turns not on what they took but on whether the employer can prove the secret existed in a defined form, protected by reasonable measures, before the departure.

The Element Most Trade Secret Claims Fail On

The intuition in a trade secret case is that the hard part is proving the departing employee took something. In practice, the claims that fail most often do not fail on the taking. They fail on the first element: proving that a trade secret existed at all, defined with enough particularity to distinguish it from the general skill and knowledge the employee is free to carry to a new job.

United States appellate courts have made this the recurring theme of trade secret litigation. To prove misappropriation, a plaintiff must show the existence of a trade secret, its improper acquisition, and its unauthorised use. The existence element comes first, and courts dismiss claims that cannot satisfy it before the question of the employee's conduct is ever reached.

In Double Eagle Alloys v Hooper, decided by the Tenth Circuit in April 2025, the court affirmed summary judgment against a trade secret holder because it had not identified its trade secrets with sufficient particularity — it pointed to categories of information, specifications, pricing, costs, customer drawings, without distinguishing what qualified as a secret from what had been disclosed to customers without restriction.

The same pattern appears in DeWolff, Boberg & Associates v Pethick, where the Fifth Circuit in April 2025 affirmed summary judgment against the trade secret holder on alternative grounds: it had failed both to identify specific trade secrets within its databases with particularity, and to show that the departing employee had used or disclosed any protected information. The existence element and the use element each independently defeated the claim.

Courts have separately noted the risk that a plaintiff will tailor the scope of its misappropriation claims mid-litigation based on what discovery reveals — a risk that a fixed, dated definition of the trade secret forecloses. When a company cannot point to a fixed, dated, defined record of what its trade secret was before the dispute began, the claim becomes a moving target, and courts treat that as a reason to dismiss.

Why the Departing Employee Is the Hardest Case

Every trade secret holder faces the existence and reasonable-measures problems in the abstract. The departure of an employee is what turns the abstract problem into a live one, because it introduces a defence that is unavailable in most other misappropriation scenarios: the general skill and knowledge defence.

An employee is entitled to leave a job and use the general skill, experience, and knowledge they acquired. They are not entitled to take the employer's trade secrets. The line between the two is the entire battleground of trade secrets after employment ends, and it is a line that can only be drawn if the employer can show precisely what the trade secret was — as a defined thing that existed at a specific time — rather than as a general body of know-how the employee accumulated over years of work.

This is why the existence element bites hardest in the departing-employee case. The employee will argue that whatever they are using is their own general expertise. The employer must answer with a specific, defined, dated trade secret that predates the employee's departure and is distinct from their general skill. Without a record that fixes the trade secret in a defined form at a defined time, the employer is left arguing about the boundary between secret and skill with no anchor — and the employee's version, that it was all general knowledge, becomes difficult to rebut.

The forensic evidence of the departure itself — the download spike in the final days, the files copied to a personal device — is valuable, but it addresses the wrong element. It goes to acquisition and use. It does not establish that what was taken was a defined trade secret that existed before the employee left. A company can prove an employee downloaded ten thousand files on their last day and still lose, if it cannot prove those files contained a trade secret defined with particularity.

The reverse is also true: misappropriation can occur with nothing downloaded at all. In Citibank N.A. v Mitchell (N.D. Cal. 2024), the court granted a temporary restraining order against a departing private banker on the basis of client information he retained and used, holding that non-public details of clients' holdings and cash positions were protectable trade secrets under California law.

The information did not need to leave on a device to be misappropriated — but it did need to be defined and shown to qualify as a secret. Whether the misappropriation is a mass download or the use of information carried in memory, the holder's task is the same: define the trade secret with particularity and prove it existed in that form beforehand.

The Reasonable Measures Burden

The existence of a trade secret is only the first element the holder must prove. The second, under every major trade secret regime, is that the holder took reasonable measures to keep the information secret. Under the US Defend Trade Secrets Act, the EU Trade Secrets Directive, and the UK Trade Secrets (Enforcement, etc.) Regulations 2018 that implement the Directive in UK law, the burden of proof on reasonable measures sits with the holder.

That burden is evidential, and it is heavier than most companies assume. The EU Trade Secrets Directive does not require that the holder successfully kept the information secret — a security breach does not automatically defeat protection. It requires the holder to demonstrate that reasonable, objective steps were taken to protect the information. German commentary on the implementing law makes the point sharply: it is not enough to state that measures were taken. The holder must present and substantiate the details, and this requires careful, dated documentation of the measures as they were applied in day-to-day operations.

For the departing-employee case, the reasonable-measures element connects directly to the individual who left. Reasonable measures include access controls, confidentiality agreements, and exit procedures — and each of these produces a record only if it was documented at the time. When a company can show that a specific document was designated confidential, access-restricted, and covered by an agreement the departing employee signed, on dates that precede the departure, it satisfies the reasonable-measures element with evidence rather than assertion. When it can only describe its general practices after the fact, it is asking the court to take its word.

Why Standard Records Fall Short

Most companies believe they can reconstruct the necessary proof from their existing systems. The document management system holds the file. The HR system holds the signed confidentiality agreement. The access logs show who could reach what. In principle, the record exists.

The problem is the same one that undermines any self-generated record in an adversarial proceeding. The document management system's metadata is produced and held by the company itself. The access logs are maintained on infrastructure the company controls. The confidentiality agreement is a signed document, but proving it existed in its signed form on a date before the departure — rather than being produced or modified later — depends on the company's own attestation.

In a dispute where the departing employee and their new employer are motivated to challenge every element, self-generated records invite the response that they cannot be independently verified. That is a weakness at the foundation of the claim.

This is the specific evidential gap. The company may well have had the trade secret, defined and protected, before the employee left. But if the only proof is records the company itself produced and controls, the employee can argue that the definition was constructed after the departure to fit the litigation, and that the protective measures are being described more rigorously in hindsight than they were applied at the time. The existence element and the reasonable-measures element both depend on proving what existed, and when — and that is precisely what self-generated records struggle to establish independently.

What a Defensible Trade Secret Record Looks Like

The gap between what a company has and what a trade secret claim requires is closed by making an independently anchored record of the trade secret, and of the measures protecting it, at the point they exist — not reconstructed after an employee leaves.

When a document defining a trade secret is deposited — a specification, a formula, a process description, a customer analysis, a source file — the file is hashed using SHA-256, the hash is timestamped by an accredited Trust Service Provider under RFC 3161, and the timestamped hash is anchored to the Bitcoin blockchain via OpenTimestamps. This is a single automated sequential process — each step depends on the output of the preceding one. The result is a portable certificate recording the file name, the cryptographic fingerprint, the timestamp, and the blockchain anchor.

A free RFC 3161 timestamp from an unaccredited service produces a technically valid record but carries no legal presumption — the holder would have to argue for its accuracy in any proceeding. With optional eIDAS Article 41 qualification from an accredited QTSP, the timestamp carries a legal presumption of accuracy across all 27 EU member states. Under US Federal Rule of Evidence 902(14), a certified record of a process producing an accurate hash of data can be self-authenticating.

The application to the departing-employee problem is direct. The trade secret is deposited at the point it is defined, establishing that it took that precise form on that date — before any particular employee's departure, and distinct from their general knowledge. The reasonable measures are captured in the same way: the confidentiality agreement, the access-control policy, the classification of the document as confidential, each deposited when it is created. When an employee later leaves and a dispute arises, the company holds an independently anchored record proving the trade secret existed in a defined form, and was protected by documented measures, on dates that precede the departure.

The record answers the two questions on which the claim turns. What was the trade secret, defined with particularity? The certificate fixes the answer. Were reasonable measures in place before the departure? The anchored record of the agreements and controls establishes the point. Neither answer depends on the company's own systems, and neither can be dismissed as constructed after the fact to fit the litigation.

Why This Matters for Employers, Departing Employees, and Counsel

The value of the record differs by role, though each role has a direct stake in the same proof.

For an employer, the anchored record converts the two hardest elements of a trade secret claim from assertion into proof. When an employee leaves and the company suspects misappropriation, the existence and reasonable-measures elements are already established by records made before the departure, allowing the case to focus on acquisition and use rather than fighting a rearguard action on whether a protected trade secret existed at all.

For a departing employee, the same infrastructure offers a protection that is easy to overlook. An employee who deposits their own prior work — the general skill and knowledge they brought to the job, the projects they built before joining — holds an independent record of what was theirs before they arrived. In a dispute where a former employer claims that everything the employee knows is its trade secret, a dated record of the employee's pre-existing expertise is a defence against an overreaching claim.

For counsel on either side, an independently anchored record changes the evidential position. Rather than litigating the existence of a trade secret through documents the other side will attack as self-serving, counsel can point to a certificate that fixes what existed and when, through a process a court can verify without relying on either party's own systems. The dispute narrows to the questions that should decide it, rather than collapsing into an argument about whether the foundational records can be trusted.

The departure of a key employee is the most common trigger for trade secret litigation, and it is the scenario in which the burden on the holder is heaviest. The claim turns on proving what the trade secret was, and that it was protected, before the employee left — questions of existence and timing that self-generated records struggle to answer independently. For companies whose competitive position depends on trade secrets, and for employees who need to defend the knowledge that is rightfully their own, the time to make an independently anchored record is while the relationship is intact, not after it ends.

This post provides general information about the role of cryptographic evidence in trade secret disputes. It is not legal advice. For advice on a specific matter, consult a qualified lawyer in the relevant jurisdiction.

Related Reading

Double Eagle Alloys v Hooper: Prove the Existence of a Trade Secret — Cowles Thompson

What Standard Disclosure Cannot Prove: The NDA Enforcement Evidence Gap

Research Priority: How to Prove You Were First

James Snell is the founder of Provlyn, a platform providing cryptographic prior proof of IP ownership. provlyn.com

Trade Secrets After Employment Ends: The Proof | Provlyn