Data breaches caused by ex-employees.

Data Breaches Caused by Ex-Employees

A data breach caused by an ex-employee occurs when a former employee, after resignation, termination, or dismissal, improperly accesses, copies, discloses, transfers, sells, or destroys confidential information belonging to the former employer. The information may include customer databases, employee records, trade secrets, source code, passwords, financial information, business strategies, or personal data.

Such breaches can create liability under employment contracts, confidentiality obligations, data-protection laws, trade-secret laws, computer-crime legislation, and general civil law. The employer may also face regulatory consequences if inadequate security controls contributed to the breach.

1. Common Ways Ex-Employees Cause Data Breaches

Former employees may cause breaches through:

  • Retaining company laptops, phones, or storage devices after leaving.
  • Copying customer or employee databases before termination.
  • Using passwords that were not disabled immediately.
  • Accessing cloud storage after employment ends.
  • Sending confidential files to personal email accounts.
  • Downloading source code or proprietary documents.
  • Taking trade secrets to a competing business.
  • Using previously issued access tokens or authentication credentials.
  • Sharing confidential information with competitors.
  • Deleting or damaging company data before departure.
  • Using information obtained during employment for personal commercial benefit.

2. Employer's Responsibility

An employer should not assume that confidentiality obligations alone will prevent a breach. Effective protection normally requires technical and organisational controls, including:

  1. Immediate termination of system access.
  2. Disabling email and VPN accounts.
  3. Revoking cloud-storage permissions.
  4. Recovering company devices.
  5. Changing shared passwords.
  6. Cancelling authentication tokens and API keys.
  7. Reviewing unusual downloads before departure.
  8. Conducting an exit interview.
  9. Reminding the employee of continuing confidentiality obligations.
  10. Preserving logs and evidence where misconduct is suspected.

The employer should also follow the principle of least-privilege access, ensuring that employees have access only to information necessary for their work.

3. Contractual Liability

Employment agreements frequently contain:

  • Confidentiality clauses;
  • Non-disclosure agreements;
  • Intellectual-property provisions;
  • Data-security obligations;
  • Return-of-property clauses; and
  • Post-employment restrictions.

A former employee may remain bound by confidentiality obligations even after the employment relationship ends, particularly concerning genuine trade secrets and confidential information.

However, contractual restrictions must comply with applicable law. Courts may distinguish between protecting legitimate confidential information and imposing an unlawful restraint on a person's ability to work.

4. Trade Secrets and Confidential Information

An ex-employee taking information does not automatically mean that every piece of information qualifies as a trade secret.

Generally, stronger protection exists where the employer can establish that the information:

  • Was commercially valuable;
  • Was not publicly available;
  • Was subject to reasonable confidentiality measures;
  • Was accessed because of the employment relationship; and
  • Was improperly acquired, used, or disclosed.

Employers should therefore maintain evidence showing how confidential information was classified and protected.

5. Data-Protection Liability

Where an ex-employee obtains personal data—such as customer names, addresses, financial information, identification information, or employee records—the incident can become a personal-data breach.

The organisation may need to determine:

  • What information was accessed;
  • Whose information was affected;
  • Whether information was actually copied or disclosed;
  • Whether the former employee acted alone or with another person;
  • Whether notification is legally required;
  • Whether regulators must be informed; and
  • What remedial measures are necessary.

The organisation's liability may depend not only on the employee's misconduct but also on whether the organisation had reasonable security and access controls.

Important Case Laws

1. IBM India Pvt. Ltd. v. S. M. Nair

Indian courts have repeatedly recognised the importance of protecting confidential business information and contractual obligations arising from employment. The case is useful when considering the extent to which an employee's contractual obligations survive the employment relationship.

Principle: Confidentiality obligations can provide an important basis for preventing misuse of sensitive business information.

2. American Express Bank Ltd. v. Priya Puri

The Delhi High Court considered the distinction between legitimate confidential information and information concerning customers and business relationships.

Principle: An employer seeking protection must identify genuinely confidential information rather than treating all knowledge acquired by an employee as confidential.

This is particularly relevant when an ex-employee takes customer information to a competing organisation.

3. Diljeet Titus v. Alfred A. Adebare

The Delhi High Court dealt with copyright and confidential material in the employment/business context.

Principle: Courts can protect proprietary and confidential material where the claimant establishes a legitimate proprietary interest and misuse of that material.

This can apply where former employees copy databases, documents, software material, or other proprietary content.

4. John Richard Brady v. Chemical Process Equipments P. Ltd.

The Delhi High Court recognised the protection that can be afforded to confidential information and know-how.

Principle: Confidential business information and technical know-how can receive legal protection against unauthorised use or disclosure.

The case is relevant where an ex-employee takes technical information to a competitor.

5. Niranjan Shankar Golikari v. Century Spinning & Manufacturing Co. Ltd.

The Supreme Court of India examined contractual restrictions relating to employment.

Principle: Courts may enforce certain negative contractual obligations during the subsistence of employment, while restrictions operating after employment require careful examination under Section 27 of the Indian Contract Act, 1872.

For data-breach disputes, this distinction is important because an employer cannot automatically enforce every post-employment restriction merely by inserting it into an employment agreement.

6. Percept D'Mark (India) Pvt. Ltd. v. Zaheer Khan

The Supreme Court considered post-employment restraints and Section 27 of the Indian Contract Act.

Principle: A contractual restriction preventing a person from carrying on a lawful profession or business after termination of employment may face the prohibition against restraint of trade.

The case is relevant to ex-employee data disputes because employers must distinguish protecting confidential information from unlawfully preventing competition.

7. Burland v. Earle

This English case is an important authority concerning the fiduciary obligations of persons who obtain information or opportunities through a business relationship.

Principle: A person occupying a position of trust cannot improperly exploit information or opportunities obtained through that relationship.

It is relevant where a former employee has obtained commercially sensitive information because of their position.

8. Faccenda Chicken Ltd v Fowler

This leading English employment case categorised information acquired by employees and considered the extent of continuing confidentiality obligations after employment.

Principle: Not every piece of information learned during employment remains confidential indefinitely. However, information amounting to a genuine trade secret or highly confidential information may continue to receive protection.

This is one of the most directly relevant authorities for disputes involving former employees and confidential information.

6. Evidence in an Ex-Employee Data-Breach Case

An employer should preserve evidence such as:

  • Server access logs;
  • Login and authentication records;
  • Download history;
  • Email records;
  • USB/device activity;
  • Cloud-access logs;
  • File-transfer records;
  • CCTV where lawfully available;
  • Company-device forensic images;
  • Access-control records;
  • Employment and confidentiality agreements; and
  • Exit documentation.

The evidence should establish who accessed the information, what was accessed, when it was accessed, how it was transferred, and whether it was subsequently disclosed or used.

7. Remedies Available to Employers

Depending on the facts and applicable law, an employer may seek:

  • Injunctions preventing further disclosure;
  • Return or destruction of confidential material;
  • Damages or compensation;
  • Recovery of misappropriated property;
  • Enforcement of contractual confidentiality obligations;
  • Civil action for misuse of confidential information;
  • Criminal proceedings where unauthorised computer access or other criminal conduct is established; and
  • Regulatory reporting where personal-data laws require it.

Conclusion

Data breaches caused by ex-employees are both an employment-law and information-security problem. The former employee may face liability for unauthorised access, disclosure, misuse of confidential information, or misappropriation of trade secrets. At the same time, the employer should demonstrate that it implemented reasonable safeguards, particularly prompt termination of access and proper control of confidential information.

The strongest legal case generally arises where the employer can prove (1) the information was genuinely confidential, (2) the former employee had access because of employment, (3) the employee improperly retained/accessed/used/disclosed it, and (4) the employer took reasonable measures to protect the information.

LEAVE A COMMENT