Guide · Workplace and corporate
How do you prove trade secret theft when an employee leaves?
These cases are won or lost on the forensic trail in the weeks before departure — bulk downloads, USB connections, files emailed to personal accounts, access outside normal hours. Preserve the employee's device and account data before reissuing either, because reimaging the laptop destroys the case more reliably than the employee could.
Written and reviewed by licensed Tennessee investigators · Statutes cited
- Licensed Tennessee investigators
- Written and reviewed in-house
- Tennessee statutes cited
- Backed by Delator Group
What the claim requires, and where the proof lives
- Governing law
- Tennessee Uniform Trade Secrets Act, T.C.A. § 47-25-1701 et seq.
- Element 1
- The information actually qualifies as a trade secret
- Element 2
- You took reasonable steps to keep it secret
- Element 3
- It was acquired or used by improper means
- Where proof lives
- Device forensics, access logs, email, cloud sync and USB history
- Fatal mistake
- Reimaging the departing employee's laptop before it is imaged forensically
Employers usually know an employee took something. Proving it to the standard a court requires is a different exercise, and the window to gather what proves it is short — often measured in days after the resignation, and closed permanently the moment IT wipes the laptop for the next hire.
What has to be proved?
Under the Tennessee Uniform Trade Secrets Act the information must derive independent economic value from not being generally known, and must be the subject of reasonable efforts to maintain its secrecy. Then you must show misappropriation — acquisition by improper means, or use or disclosure by someone who knew it was improperly acquired.
The second element is where employers most often lose. A client list that was emailed around freely, stored on an open share, never marked confidential and covered by no agreement is hard to characterize as the subject of reasonable secrecy efforts. The case is frequently decided by what the company did before anyone left.
Where does the evidence actually live?
- USB and removable-device history — connections, timing, and often what was copied
- Bulk download and file-access patterns — volume spikes in the weeks before notice
- Email to personal accounts — attachments forwarded to a private address
- Cloud sync — personal Dropbox, Drive or OneDrive clients installed on a work machine
- Printing logs — still common and still overlooked
- Access outside normal hours — badge and VPN records around the departure date
- The new employer's conduct — solicitation of your clients on a timeline that only works if they had your list
What is the single most damaging mistake?
Reissuing the device. The standard IT process on a departure is to wipe and reimage the laptop, and that process destroys precisely the artefacts that would have proved the case — deleted file remnants, USB history, browser and sync records. Companies do this routinely within days, and then discover the theft weeks later when clients start leaving. The device should be pulled from service and imaged forensically before anything else happens to it.
The same applies to email accounts. Deleting or recycling a departed employee's mailbox removes the record of what they forwarded to themselves.
How soon does this need to happen?
Immediately on any resignation where the employee had access to genuinely sensitive material, and certainly before the device is reissued. Preserving is cheap; you can image a laptop and never use it. Recovering an image that no longer exists is impossible. Many employers make preservation a standing part of the offboarding process for defined roles, which removes the need to make a judgement call in the moment.
What can an investigator contribute beyond forensics?
The conduct side, which is often what demonstrates use rather than mere possession. Whether the former employee is now soliciting your clients, what they have represented about their new role, corporate filings showing a competing entity formed before departure, public professional profiles and announcements, and interviews with clients who were approached. A forensic image proves data left. The investigative work proves it was used, and use is usually what drives the remedy.
- Tennessee Uniform Trade Secrets Act, T.C.A. § 47-25-1701 et seq., defines trade secrets and misappropriation and provides remedies including injunctive relief.
- The federal Defend Trade Secrets Act, 18 U.S.C. § 1836, provides a parallel federal civil cause of action.
- Spoliation principles apply to the employer as well: destroying the device image once litigation is anticipated can draw an adverse inference.
What sinks trade secret claims
Three of these are employer self-inflicted. The fourth is a misunderstanding of the law.
Knowing and proving are different. The wipe destroys the USB history, deleted-file remnants and sync records that would have proved it.
It must derive value from secrecy and be subject to reasonable secrecy efforts. Information that circulated freely and unmarked rarely qualifies.
An agreement helps establish expectations, but you still have to prove what was taken and used. Enforceability is its own contested question.
The forensic window closes when the device is reissued, which is usually days. Preserve now, decide later.
When a sensitive employee resigns
The first two items are time-critical. Everything else can follow at your pace.
- Pull the device from service and have it imaged forensically before any reimaging
- Preserve the email mailbox, cloud accounts and access logs rather than recycling them
- Pull USB, printing, VPN and badge records for the weeks before notice
- Document what secrecy measures were actually in place, with dates
- Watch for client solicitation and corporate filings suggesting a competing entity
- Involve counsel early; injunctive relief depends on moving quickly
Find any Watchtower service
Search all 73 investigation and process serving services by situation, service or city. Every result opens its own page.
Browse all 73 services below
Core services
- Surveillance InvestigationsCovert, time-stamped observation for personal, legal and business cases.
- Infidelity InvestigationsDiscreet answers when you suspect a spouse or partner.
- Child Custody InvestigationsDocumented facts for parenting-time and child welfare disputes.
- Skip Tracing & LocatesVerified current addresses for people who moved or went quiet.
- Asset SearchesProperty, business interests and financial red flags, traced.
- Criminal Defense InvestigationsIndependent fact-finding for defense attorneys and the accused.
- Insurance InvestigationsClaim verification and activity checks for carriers and TPAs.
- Corporate InvestigationsInternal theft, vendor fraud, misconduct and due diligence.
- Physical Penetration TestingPhysical access and social engineering tests for businesses.
- General InvestigationsNot sure which service fits? Start here.
- Process ServingDocumented service of legal papers across Tennessee.
- Service Inside the Governor's ClubProcess serving inside Brentwood's gated Governor's Club.
Specialty casework · 61 case types
Relationship & Domestic Matters4
Covert Surveillance6
Vetting & Records Research7
Digital Privacy1
Business & Corporate Matters11
- Merger & Acquisition VettingFranklin
- Trade Secret Theft InquiriesWilliamson County
- Internal Theft InquiriesMemphis
- Inventory Shrinkage InquiriesShelby County
- Executive Misconduct InquiriesBrentwood
- Misconduct Fallout ContainmentMiddle Tennessee
- Public Statement Fact VerificationTennessee
- Vendor & Bid Collusion InquiriesClarksville
- Pre-Acquisition Red Flag ReviewWilliamson County
- Property Transaction VettingDavidson County
- Ongoing Risk AdvisoryTennessee
Defense Case Support4
Employment Disputes3
Security & Readiness Reviews5
People Locating6
Difficult Circumstances4
Property Loss & Theft3
Facility & Care Oversight2
Vehicle & Repair Disputes3
Nothing matched that wording. Try a broader word, start with General Investigations, or call (629) 310-8667 and describe it.
Have a situation this applies to?
Tell us what happened and we will tell you what can still be recovered, what it costs, and whether an investigator is the right answer. The consultation is free.
Call (629) 310-8667 · Email contact@delatorgroup.com
Watchtower Investigations · Nashville, Tennessee · Delator Group’s Nashville hub