Guide · Workplace and corporate

How do you prove trade secret theft when an employee leaves?

Short answer

These cases are won or lost on the forensic trail in the weeks before departure — bulk downloads, USB connections, files emailed to personal accounts, access outside normal hours. Preserve the employee's device and account data before reissuing either, because reimaging the laptop destroys the case more reliably than the employee could.

Written and reviewed by licensed Tennessee investigators · Statutes cited

  • Licensed Tennessee investigators
  • Written and reviewed in-house
  • Tennessee statutes cited
  • Backed by Delator Group
Workplace and corporate

What the claim requires, and where the proof lives

Governing law
Tennessee Uniform Trade Secrets Act, T.C.A. § 47-25-1701 et seq.
Element 1
The information actually qualifies as a trade secret
Element 2
You took reasonable steps to keep it secret
Element 3
It was acquired or used by improper means
Where proof lives
Device forensics, access logs, email, cloud sync and USB history
Fatal mistake
Reimaging the departing employee's laptop before it is imaged forensically

Employers usually know an employee took something. Proving it to the standard a court requires is a different exercise, and the window to gather what proves it is short — often measured in days after the resignation, and closed permanently the moment IT wipes the laptop for the next hire.

What has to be proved?

Under the Tennessee Uniform Trade Secrets Act the information must derive independent economic value from not being generally known, and must be the subject of reasonable efforts to maintain its secrecy. Then you must show misappropriation — acquisition by improper means, or use or disclosure by someone who knew it was improperly acquired.

The second element is where employers most often lose. A client list that was emailed around freely, stored on an open share, never marked confidential and covered by no agreement is hard to characterize as the subject of reasonable secrecy efforts. The case is frequently decided by what the company did before anyone left.

Where does the evidence actually live?

  • USB and removable-device history — connections, timing, and often what was copied
  • Bulk download and file-access patterns — volume spikes in the weeks before notice
  • Email to personal accounts — attachments forwarded to a private address
  • Cloud sync — personal Dropbox, Drive or OneDrive clients installed on a work machine
  • Printing logs — still common and still overlooked
  • Access outside normal hours — badge and VPN records around the departure date
  • The new employer's conduct — solicitation of your clients on a timeline that only works if they had your list

What is the single most damaging mistake?

Reissuing the device. The standard IT process on a departure is to wipe and reimage the laptop, and that process destroys precisely the artefacts that would have proved the case — deleted file remnants, USB history, browser and sync records. Companies do this routinely within days, and then discover the theft weeks later when clients start leaving. The device should be pulled from service and imaged forensically before anything else happens to it.

The same applies to email accounts. Deleting or recycling a departed employee's mailbox removes the record of what they forwarded to themselves.

How soon does this need to happen?

Immediately on any resignation where the employee had access to genuinely sensitive material, and certainly before the device is reissued. Preserving is cheap; you can image a laptop and never use it. Recovering an image that no longer exists is impossible. Many employers make preservation a standing part of the offboarding process for defined roles, which removes the need to make a judgement call in the moment.

What can an investigator contribute beyond forensics?

The conduct side, which is often what demonstrates use rather than mere possession. Whether the former employee is now soliciting your clients, what they have represented about their new role, corporate filings showing a competing entity formed before departure, public professional profiles and announcements, and interviews with clients who were approached. A forensic image proves data left. The investigative work proves it was used, and use is usually what drives the remedy.

  • Tennessee Uniform Trade Secrets Act, T.C.A. § 47-25-1701 et seq., defines trade secrets and misappropriation and provides remedies including injunctive relief.
  • The federal Defend Trade Secrets Act, 18 U.S.C. § 1836, provides a parallel federal civil cause of action.
  • Spoliation principles apply to the employer as well: destroying the device image once litigation is anticipated can draw an adverse inference.
Commonly believed, and wrong

What sinks trade secret claims

Three of these are employer self-inflicted. The fourth is a misunderstanding of the law.

IT can just wipe the laptop, we already know what he took.

Knowing and proving are different. The wipe destroys the USB history, deleted-file remnants and sync records that would have proved it.

Everything we consider confidential is a trade secret.

It must derive value from secrecy and be subject to reasonable secrecy efforts. Information that circulated freely and unmarked rarely qualifies.

The non-compete agreement settles it.

An agreement helps establish expectations, but you still have to prove what was taken and used. Enforceability is its own contested question.

We have months to decide whether to pursue this.

The forensic window closes when the device is reissued, which is usually days. Preserve now, decide later.

What to do with this

When a sensitive employee resigns

The first two items are time-critical. Everything else can follow at your pace.

  • Pull the device from service and have it imaged forensically before any reimaging
  • Preserve the email mailbox, cloud accounts and access logs rather than recycling them
  • Pull USB, printing, VPN and badge records for the weeks before notice
  • Document what secrecy measures were actually in place, with dates
  • Watch for client solicitation and corporate filings suggesting a competing entity
  • Involve counsel early; injunctive relief depends on moving quickly

Find any Watchtower service

Search all 73 investigation and process serving services by situation, service or city. Every result opens its own page.

Browse all 73 services below

Core services

Specialty casework · 61 case types

Relationship & Domestic Matters4
Covert Surveillance6
Vetting & Records Research7
Digital Privacy1
Business & Corporate Matters11
Defense Case Support4
Employment Disputes3
Security & Readiness Reviews5
People Locating6
Difficult Circumstances4
Property Loss & Theft3
Facility & Care Oversight2
Vehicle & Repair Disputes3
Fraud & Deception2

Have a situation this applies to?

Tell us what happened and we will tell you what can still be recovered, what it costs, and whether an investigator is the right answer. The consultation is free.

Call (629) 310-8667 · Email contact@delatorgroup.com
Watchtower Investigations · Nashville, Tennessee · Delator Group’s Nashville hub

Guide last reviewed by Watchtower Investigations, a licensed Tennessee private investigation agency and part of Delator Group. This guide is general information about Tennessee law and practice, not legal advice; for advice about your situation, speak with a Tennessee attorney. Back to top ↑