This guide is general legal information, not legal advice, and does not create an attorney–client relationship. Rules change and vary by state — verify current requirements with official sources or a licensed attorney.
Some of a company's most valuable intellectual property never appears in any government registry. Customer lists, manufacturing processes, pricing models, source code, formulas, and negative know-how ("we tried these ten approaches and they failed") can all be trade secrets — protected indefinitely, with no filing, for as long as they stay secret and the owner takes reasonable steps to keep them that way.
That last clause is where most trade secret cases are won or lost. Unlike a patent or registered copyright, a trade secret exists only if you can prove you treated it like one. This article covers the three pillars of that proof: internal policies, contracts, and — when information walks out the door — misappropriation claims under the federal Defend Trade Secrets Act (DTSA) and state law.
Key takeaways
- Information qualifies as a trade secret only if it has economic value from not being generally known and the owner took reasonable measures to keep it secret.
- The DTSA (2016) created a federal civil claim, codified at 18 U.S.C. § 1836, alongside state law — nearly every state has adopted a version of the Uniform Trade Secrets Act.
- Remedies can include injunctions, actual damages plus unjust enrichment or a reasonable royalty, and up to double damages plus attorney's fees for willful and malicious misappropriation.
- Employee-facing confidentiality agreements must include the DTSA's whistleblower-immunity notice, or the employer forfeits exemplary damages and fees against that employee.
- Reverse engineering and independent development are lawful — trade secret law punishes improper acquisition, not competition.
What actually qualifies as a trade secret
Under the federal definition in 18 U.S.C. § 1839, a trade secret can be virtually any form of financial, business, scientific, technical, or engineering information — formulas, prototypes, methods, programs, codes, compilations — if two conditions hold:
- the information derives independent economic value from not being generally known or readily ascertainable by proper means, and
- the owner has taken reasonable measures to keep it secret.
Both prongs are tested in litigation. Information that is public, easily reverse-engineered from a marketed product, or general employee skill and experience will not qualify. Neither will genuinely secret information the company shared freely, stored without restrictions, or never marked or inventoried — courts routinely deny protection where owners cannot show concrete secrecy efforts.
Trade secrecy and patenting are, for a given piece of information, mutually exclusive paths: a patent application publishes the invention in exchange for a limited exclusivity term, while a trade secret can last forever but evaporates on disclosure. Our guide to utility, design, and provisional patents covers the other side of that tradeoff, and the intellectual property hub compares the full toolkit.
Reasonable measures: the policies courts look for
"Reasonable" does not mean perfect or maximal — it means proportional to the value of the secret and the size of the business. When judges evaluate secrecy efforts, they look for a coherent program rather than a single NDA signed years ago.
- Identify and inventory the company's trade secrets, and designate an owner for the program.
- Mark confidential documents and label sensitive systems and repositories.
- Limit access on a need-to-know basis; log and review who can reach crown-jewel data.
- Use technical controls: passwords, multi-factor authentication, encryption, and monitoring of unusual downloads.
- Require confidentiality agreements from employees, contractors, and business partners before disclosure.
- Train employees on handling confidential information, and repeat the training periodically.
- Run onboarding and exit protocols: collect devices, cut access on departure, and remind departing employees of continuing obligations in writing.
- Restrict and review vendor and visitor access to facilities and systems.
Documentation matters as much as the measures themselves. A dated policy, signed acknowledgments, and access logs are often the difference between winning and losing the "reasonable measures" element.
The agreements that do the work
Contracts convert general secrecy into enforceable duties. The core instruments:
- Nondisclosure agreements (NDAs). Define confidential information precisely, state permitted uses, and set return-or-destroy obligations. Overbroad NDAs that sweep in public information or run forever against everything can be cut down or ignored by courts.
- Employee confidentiality and invention-assignment agreements. These should assign work-related inventions to the employer and survive termination. They work alongside — not as substitutes for — classification and payroll practices; see how worker classification affects which template applies.
- Restrictive covenants. Noncompetes and nonsolicits are sometimes used as secrecy backstops, but their enforceability varies dramatically and is under active regulatory and legislative pressure — our overview of noncompete law state by state explains why confidentiality agreements should never lean on them.
- Separation agreements. Departures are the highest-risk moment for trade secrets. Exit paperwork should reaffirm confidentiality duties; the broader terms are covered in our guide to termination and severance agreements.
Compliance trap: Under 18 U.S.C. § 1833(b), any contract with an employee (broadly including contractors and consultants) that governs trade secrets or confidential information must give notice of the statute's whistleblower immunity — protection for confidential disclosures to the government or an attorney solely to report suspected law violations. Omit the notice and the employer cannot recover exemplary damages or attorney's fees in a DTSA suit against that person. Update legacy templates.
Misappropriation claims: DTSA and state law
Misappropriation means acquiring a trade secret through improper means — theft, bribery, misrepresentation, breach of a duty of secrecy, espionage — or using or disclosing it when you knew or should have known it came through such means. Reverse engineering a lawfully purchased product and independent invention are expressly proper.
Since the Defend Trade Secrets Act of 2016, owners can sue in federal court under 18 U.S.C. § 1836 for secrets connected to interstate or foreign commerce, while state claims — almost everywhere, a version of the Uniform Trade Secrets Act (UTSA); New York being the notable common-law holdout — remain available and are often pleaded together with the federal claim.
| Feature | DTSA (federal) | UTSA-based state claims |
|---|---|---|
| Forum | Federal court nationwide | State court (or federal on other grounds) |
| Limitations period | 3 years from discovery | Commonly 3 years, but varies by state |
| Ex parte seizure | Available in extraordinary circumstances to prevent dissemination | Generally unavailable |
| Damages | Actual loss + unjust enrichment, or reasonable royalty; up to 2x exemplary damages if willful and malicious | Similar structure; caps and standards vary by state |
| Whistleblower notice rule | Required in employee agreements to preserve exemplary damages/fees | No equivalent, but the federal immunity still applies |
Remedies and timing
Courts can enjoin actual or threatened misappropriation, though a DTSA injunction cannot simply bar someone from taking a job — restrictions on employment require evidence of threatened misappropriation, not just what the person knows. Money remedies track actual damages plus the defendant's unjust enrichment, or a reasonable royalty; willful and malicious conduct can double the award and shift attorney's fees, while bad-faith claims can shift fees the other way. The federal limitations period is three years from when the misappropriation was or should have been discovered, so early investigation matters. In extreme cases, the DTSA's civil seizure provision lets a court order property seized without advance notice to stop imminent dissemination — an extraordinary remedy with strict safeguards.
When a departure goes wrong: first 30 days
Most trade secret cases begin with an employee leaving for a competitor. A disciplined early response preserves both the secrets and the claim: preserve the departing employee's devices, accounts, and logs before anything is wiped; review recent download and transfer activity; send a preservation and reminder-of-obligations letter to the former employee (and, where appropriate, the new employer); and assess quickly whether the facts justify seeking a temporary restraining order, since delay undercuts any claim of irreparable harm. Companies on the hiring side should run the mirror-image protocol — written instructions not to bring or use prior-employer information — because DTSA defendants include businesses that knowingly benefit from tainted information.
Frequently asked questions
How long does trade secret protection last?
Indefinitely — as long as the information keeps its economic value from secrecy and the owner keeps taking reasonable protective measures. There is no term and no renewal. Protection ends the moment the information becomes generally known, whether through a leak, a publication, a patent application, or lawful reverse engineering of a public product.
Is reverse engineering illegal under trade secret law?
No. Both the DTSA and state UTSA statutes treat reverse engineering of a lawfully acquired product as a proper means of discovery, along with independent development. What the law forbids is acquisition through improper means — theft, hacking, bribery, deception, or breach of a confidentiality duty. Contracts can sometimes restrict reverse engineering separately, but that is a contract claim, not misappropriation.
Do I need an NDA for information to count as a trade secret?
Not strictly — the legal test is "reasonable measures," and confidentiality can sometimes be implied from the relationship. In practice, though, disclosing sensitive information to an outsider without an NDA is strong evidence against reasonable measures, and many courts treat unprotected disclosures as fatal. Written agreements remain the cheapest, clearest proof of secrecy efforts.
Can I sue under both federal and state law at once?
Usually yes. The DTSA expressly coexists with state trade secret law rather than preempting it, so plaintiffs commonly plead DTSA and state UTSA claims together in federal court, sometimes alongside contract and fiduciary-duty claims. Strategy varies: state law may offer different damages rules or limitation periods, while the DTSA guarantees a federal forum and the seizure remedy.
What should a company do before sharing secrets with a potential partner?
Sign an NDA first, then share in stages. Disclose the minimum needed for the evaluation, mark everything confidential, keep records of exactly what was shared and when, and include return-or-destroy and no-use clauses. If the deal involves deep technical disclosure, consider a clean-room protocol so the partner can later prove independent development of its own work.
Hardening your program before you need it
Trade secret protection is built in peacetime. Inventory what the business actually depends on, match access controls and contracts to those crown jewels, add the § 1833(b) notice to every employee-facing template, and rehearse the departure protocol before a key engineer resigns. When information does escape, move within days, not months: the evidence, the injunction, and the three-year clock all favor owners who act early. For high-stakes matters — an ex parte seizure request, a cross-border leak, or a claim against a well-funded competitor — experienced trade secret counsel is worth engaging before the first letter goes out.