Data Protection and Trade Secrets
Privacy Policy
Whenever you collect, store, or use personal data, you’re dealing with a data protection issue—which, in a digital world, means practically all the time, from cookies and Google Analytics on your website to customer lists on your server and even your human resources department.
It’s always important to weigh what you can do, what you must do, what you’re allowed to do, and what you should absolutely avoid doing. Doing nothing is the worst option. The General Data Protection Regulation (GDPR) serves as the benchmark for what is permissible and what is not, and failure to comply with data protection regulations can result in substantial fines running into the millions and penalties that can affect both companies and business owners personally.
Don’t have a data protection officer? You should, if you employ more than twenty people who regularly handle personal data. Don’t have a record of your company’s data processing activities? You should, because upon request, you must immediately submit such a record to the relevant data protection authority. Do you work with third parties to process your data? If so, you should also be able to provide a data processing agreement, which must include essential provisions. Do you lack a security policy? You should have one—specifically, one that ensures compliance with data protection measures from technical, organizational, and personnel perspectives.
Have you experienced a data breach? This triggers a reporting obligation to the data protection officer, even if that’s not a pleasant prospect for you. You may then be asked questions whose answers make you feel uneasy just reading them. We can often help mitigate that.
We conduct legal audits and, based on our findings, recommend measures to help you meet data protection requirements. On the technical side, we work closely with your IT service providers. We can also recommend third parties who are capable of implementing or optimizing the necessary data protection measures.
All of this serves as a preventive measure and helps avoid unpleasant surprises during inspections by data protection authorities. This protects you from competitors who might use compliance with data protection regulations as a pretext for antitrust disputes—and it prepares you for the event that you decide to enforce compliance with data protection regulations in your market using the tools of antitrust law.
Protection of Trade Secrets
If you want to keep something confidential and prevent know-how and knowledge from leaving the company, you must take action.
Using technical, organizational, and personnel measures, you must ensure that information you’ve identified as worthy of protection cannot be easily disclosed to third parties. If you fail to do so, you’re missing out on opportunities to safeguard your business. This is more important than you think.
Under the Trade Secrets Protection Act, only the data and information you have taken steps to protect are actually protected. Are customer lists freely accessible—either in full or in part—within your company? What about orders, contracts, and cost estimates for customers and projects? Is manufacturing know-how freely accessible on the server? Are recipes, blueprints, or active ingredient compositions sent via email? Are there no defined responsibilities or boundaries in your organizational structure? Are there no security levels in place? Are there no additional rules regarding employment contracts? That could be a serious problem.
Take advantage of the opportunity to optimize workflows and processes through our audits and to safeguard your company’s knowledge assets with technical, organizational, and personnel measures. We’ll work with you to determine what needs to be done and, where appropriate, how you can supplement these measures with intellectual property rights—such as trademark rights, design rights, utility models, patents, or know-how agreements and non-disclosure agreements.
