For most businesses, some of the most valuable assets never appear on the balance sheet. A product formula, customer database, pricing strategy, source code, manufacturing process, vendor terms or internal business plan may be worth far more than the physical property used to run the business. When such information is copied, taken or disclosed without permission, the damage can extend well beyond a simple breach of employment terms.
In India, however, there is an important legal distinction to understand. India does not currently have a single, dedicated statute governing trade secrets. Protection is instead drawn from contracts, principles of confidentiality and common law, along with provisions of criminal and cyber laws that may apply depending on how the information was obtained or misused. Recent Indian judicial decisions have reaffirmed this position.
What Qualifies as a Trade Secret or Confidential Information?
Trade secrets generally refer to information that has commercial value because it is not publicly known and the business takes reasonable steps to keep it secret. This can include technical information, manufacturing know-how, software, source code, formulas, research data, business methods, customer information, pricing details and strategic plans.
Confidential information is a wider category. It may include information that does not technically qualify as a trade secret but is still disclosed in circumstances creating an obligation of confidence.
The courts have made it clear that simply calling something “confidential” does not automatically make it legally protected. A business should be able to identify what the information is, why it is confidential and what measures it has taken to prevent unauthorised access. In Navigators Logistics Ltd. v. Kashif Qureshi, the Delhi High Court noted the importance of specifically identifying confidential information and distinguishing it from general industry knowledge.
This is particularly relevant when businesses seek criminal action. A vague allegation that an employee “stole confidential information” may not be enough. The nature of the information, the manner in which it was accessed and the intention behind its use or disclosure all matter.
Is Misuse of a Trade Secret Automatically a Criminal Offence?
No. This is one of the most important points for businesses to understand.
There is no standalone criminal offence in India called “theft of trade secrets”. A person cannot be prosecuted merely because information qualifies as a trade secret. Criminal liability generally has to arise from some other offence recognised under applicable law.
The Bharatiya Nyaya Sanhita, 2023 (BNS), which came into force on 1 July 2024, contains offences such as theft, dishonest misappropriation, criminal breach of trust, receiving stolen property and cheating.
For example, Section 316 of the BNS deals with criminal breach of trust. It applies where property has been entrusted to a person and that person dishonestly misappropriates, converts, uses or disposes of it in violation of law or a legal contract.
Whether confidential information can constitute “property” for a particular criminal provision is a matter that must be examined carefully on the facts. Simply copying a document or downloading a database should not automatically be described as theft under Section 303, because the BNS provision is framed around movable property being moved from another person’s possession without consent.
The criminal case therefore needs to be built around the actual conduct, rather than merely attaching the label of “trade secret theft”.
Criminal Remedies for Digital Theft of Confidential Information
The Information Technology Act, 2000 becomes particularly relevant when confidential information is accessed, copied or extracted electronically.
Section 43 covers unauthorised acts involving computer systems, including accessing a computer resource without permission and downloading, copying or extracting data, databases or information.
Where an act covered by Section 43 is carried out dishonestly or fraudulently, Section 66 can make the conduct a criminal offence, punishable with imprisonment of up to three years, or fine, or both.
This can become relevant where, for example, an employee uses another person’s credentials to access a restricted database, copies confidential files before leaving the organisation, or obtains information from a system without the required authority.
Other provisions may also become relevant depending on the conduct. Section 66B addresses dishonest receipt or retention of a stolen computer resource or communication device, while Section 66C deals with fraudulent or dishonest use of another person’s electronic signature, password or unique identification feature.
Breach of Confidentiality Under the IT Act
Sections 72 and 72A of the IT Act also deserve attention, although their present form is sometimes misunderstood.
Section 72 deals with disclosure of electronic records, information or other material by a person who obtained access through powers under the IT Act, rules or regulations, without the concerned person’s consent. The provision currently imposes a monetary penalty.
Section 72A concerns disclosure of information obtained while providing services under a lawful contract, where the disclosure is made without consent or in breach of the contract with the intent to cause, or knowledge that it is likely to cause, wrongful loss or wrongful gain. Following amendments, the provision now provides for a penalty that may extend to ₹25 lakh.
Therefore, businesses should not assume that every confidentiality breach under the IT Act automatically results in imprisonment. The precise statutory provision and its current wording matter.
The Role of Criminal Breach of Trust
Employment relationships often involve access to information that the employee would never have received personally. An employee may be given access to customer databases, internal financial information, product specifications or confidential business documents solely because of their position.
Where the facts satisfy the requirements of criminal breach of trust, Section 316 of the BNS may become relevant. The provision specifically recognises misuse of property entrusted to a person in violation of a legal contract.
But the existence of a confidentiality clause alone does not establish criminal breach of trust. The prosecution must still establish the ingredients of the offence, including entrustment, dishonest conduct and the relevant misuse or conversion.
Why Evidence Matters
Trade secret disputes often turn on evidence. A business should be able to establish what information was confidential, who had access to it, what restrictions existed and what happened when the suspected misuse occurred.
Access logs, emails, download histories, device records, authentication logs, CCTV footage, internal policies, employment agreements and forensic copies of electronic devices can become important. Businesses should also be careful not to destroy or alter potentially relevant electronic records after discovering an incident. The BNS separately addresses destruction or concealment of documents or electronic records intended to prevent their production as evidence.
The earlier Delhi High Court decision in John Richard Brady v. Chemical Process Equipments Pvt. Ltd. remains an important authority on confidential information. It recognised that an employee who receives confidential information during employment may be under an obligation to maintain its confidence, even where the contractual document does not expressly spell out every aspect of that obligation.
Criminal Action Should Not Replace Civil Protection
A criminal complaint is not always the best or only response. Trade secret disputes frequently require urgent steps to stop further disclosure, recover confidential material and prevent continued use.
Indian courts have traditionally granted civil remedies such as injunctions, delivery-up of confidential material and compensation where breach of confidence is established.
The practical approach is therefore often a combination of remedies. Where the facts disclose a criminal offence, appropriate criminal proceedings may be considered alongside civil proceedings seeking immediate protection.
For businesses, the better strategy begins much earlier. Confidential information should be identified, access should be limited, employees and consultants should be bound by clear confidentiality obligations, digital access should be monitored appropriately and exit procedures should address the return or deletion of confidential material.
The law can provide remedies after a leak, but a well-designed confidentiality system can make proving that leak far easier.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. The content may not reflect the most current legal developments and is not guaranteed to be accurate, complete, or up-to-date. Readers should consult a qualified legal professional before taking any action based on the information provided. The authors and publishers disclaim any liability for any loss or damage incurred as a result of reliance on this article. This article does not create an attorney-client relationship.
