home  /  trade secrets  /  reasonable measures
trade secrets · existence, protection, taking

Reasonable measures.

The requirement asks whether you behaved like the information was secret. Many owners discover the answer during litigation.

begin here

What is being asserted, and how far along is it?

Start a conversation with the IP Concierge, already scoped to reasonable measures. Pick a starting point, or describe the matter directly.

IP Conciergereasonable measures · orientation, not an opinion on your patent
Tell me roughly how the information is held, who can reach it, and what agreements are in place. I will help you see how a protection record is assessed. I will not tell you whether your measures were reasonable.

Protection is an element of the claim, not a best practice. Information only qualifies as a trade secret if its owner took reasonable steps, in the circumstances, to keep it secret — and this is where otherwise strong cases quietly fail. The standard is proportionality rather than perfection: a company is not required to have implemented every control available, only measures reasonable given the value of the information and the size and nature of the business. What defeats claims is not a sophisticated attacker but ordinary organizational drift. Agreements that were never signed. A share drive open to everyone because restricting it was inconvenient. Departing employees who were never asked to return anything and never reminded of anything.

mechanisms

What the record is examined for.

The measures assessed, and what each is asked to show.

Agreements actually executed

Confidentiality and assignment terms in force for the relevant people, with signatures on file — the gap between policy and executed document is the usual finding.

Access control

Whether access was limited to those who needed it, and whether that limitation was real or nominal.

Marking and classification

Whether confidential material was identified as such consistently, rather than everything or nothing being marked.

Onboarding and training

What employees were told, when, and whether it was recorded.

Exit process

Return of devices and materials, reminder of obligations, and prompt revocation of access.

Third-party handling

How the information traveled to vendors, contractors and partners, and under what terms.

methodology

What the evidence shows — and what we examine.

How the protection record is assessed.

Agreement coverage auditWhich of the relevant people were actually under obligation, and from when.
Effective access reviewNot the policy, but who could actually open the files on the relevant dates.
Proportionality assessmentMeasures weighed against the value of the information and the size of the business.
Timeline reconstructionWhat was in place when, since the question is asked as of the misappropriation.
what's at stake

What turns on it

Whether the information qualifies for protection at all.

whether a trade secret exists in law summary judgment exposure which items survive out of a claimed list the company’s posture in future disputes what a remediation program should fix first

The unsigned agreement is the most common single point of failure.

Companies routinely believe every employee is under a confidentiality obligation and discover in litigation that the relevant person’s document was never countersigned, never executed at all, or superseded by a later contract that dropped the clause. It is checkable in an afternoon and almost never checked before it matters.

common questions

Reasonable measures — practical questions

Do we need enterprise-grade security to satisfy this?

No. The requirement is reasonableness in the circumstances, and courts have consistently accepted that a small company is not held to the practices of a large one. What is assessed is whether the measures were sensible given the value of the information and the resources available — a modest business with signed agreements, limited access and a real exit process is generally in a stronger position than a large one with elaborate written policies nobody followed.

Does marking everything confidential help?

It tends to hurt. Blanket marking is routinely characterized as evidence that the owner did not distinguish genuinely sensitive material from ordinary business records, which undermines both the reasonable measures element and the identification. Selective, consistent marking is far more persuasive than universal marking, and considerably more persuasive than none.

What if a third party had the information under NDA?

Disclosure under an appropriate confidentiality agreement generally does not destroy secrecy — that is precisely what such agreements are for. The questions are whether the agreement was actually in force, whether its terms covered this information, and whether the disclosure stayed within them. Failures here are usually administrative: an expired agreement, a disclosure outside its scope, or a partner who was sent material before anything was signed.

When is the question asked, exactly?

As of the misappropriation, which is why timeline reconstruction matters more than a description of current practice. Measures introduced after a departure or after suspicion arose are prudent and largely irrelevant to whether the information qualified when it was taken. The evidence that counts is what was in force on the relevant dates, and it needs to be shown with dated documents rather than described.

related

Related specialization areas & resources.

Check the agreements before you need them.

Describe how the information is held and who has it. The Institute will help you see how the record reads.

IP conciergeorientation · not an opinion on your patent
Tell me roughly how the information is held, who can reach it, and what agreements are in place. I will help you see how a protection record is assessed. I will not tell you whether your measures were reasonable.