Employee Departures: Mind the Confidentiality Gap
When employees leave, they take the skills and knowledge they have learned. While they aren’t allowed to damage business interests at any time, there are limits to what controls the employer can impose during and post employment.
Real-world Example
A Data Protection Officer (DPO) employed by a specialist DPO services company is assigned to support a client organisation. As part of their professional development, the DPO wants to attend and speak at industry events for DPOs and privacy professionals — some run by organisations that technically compete with their employer because they also provide outsourced DPO support.
The events are focused on regulatory updates, shared learning, and professional networking, rather than selling services. The DPO also posts general thought leadership on LinkedIn in their own name, without referring to client work or disclosing confidential information.
The employer becomes uneasy, interpreting this visibility as a sign the DPO may be preparing to leave or set up independently. Tension follows, not because of anything said, but because of what the visibility is perceived to represent.
What do you think is happening with the DPO?
This sits at the heart of a recurring problem in modern workplaces: the gap between what organisations want to protect, and what professionals are entitled to take forward as part of their careers.
There is a fine but a definitive line of what is allowed when employees leave (usually defined in case law about trade secrets).
Probably more of the burden to protect confidential data (CD) falls on the employer, for example by defining what CD is, implementing and monitoring policies, training employees. That of course does not absolve the employee from responsibility but as long as they stay away from the confidentiality line and don’t damage the employer’s reputation, little else can be a problem.
Everybody Leaves (Jobs)
Staff is your biggest risk and your biggest asset. It’s almost certain your best people will move on at some point even after some decades (for example, if you are a start-up and they are there from the beginning).
What employees can take and employers can’t usually stop them from taking is:
Knowledge about how to do the job;
General learning because of the work the employer gave them;
Their own pre-existing skills that benefited the employer and got them clients / work;
Developed professional judgment that will help someone else from now on;
Mastery of something specific they learned to do while working at that company.
This can be frustrating for employers because, often, the employee might not have developed this experience but for this opportunity, so the employer might feel like they “own” them.
What employees cannot legally take is whatever the CD is for the business:
Client’s lists
Chemical / mathetmical formulae
Pricing strategy
Source code
Drawings for a new building
The company’s intellectual property (IP)
Anything that has been documented and described as CD.
Example:
Sonya learned negotiation skills at Company A (okay). Sonya downloaded the company’s pricing playbook and prospect list to prep for a new role (not okay).
“In the Course of Employment”
This is a key phrase in all employment contracts and case law when there is a dispute between an employee and an employer. In a few words, as an employee, everything you do in the course of employment, i.e. to do the job, that your employer has asked you to do, related to your job spec, is IP you create that automatically belongs to your employer.*
This may be:
Code you write;
White papers you produce;
Training you develop;
Articles you write.
Some employers make this very tight and try to “own the employee’s brain” as long as they are on the job and do something vaguely similar in their free time. This is where employers should get legal advice what is reasonable because if they make this too strict, it becomes unfair on the employee and is thus unenforceable.
The more a company values its IP, the stricter the IP clause will be. Read yours today.
Especially today, “in the course of employment” gets confusing because of hybrid work:
Allowing work on personal devices.
Cloud tools and “I’ll just forward this to myself”.
LinkedIn connections and personal branding.
Side hustles in adjacent spaces.
Employers trying to “lock down” development to reduce flight risk.
What is a Trade Secret and What is Own Knowledge?
It’s easy to say employees can’t take away trade secret but can keep own knowledge, so we should define these for clarity.
Trade secrets features (practical definition):
Not generally known.
Competitors would benefit from knowing it.
Has commercial value because it’s secret.
Reasonable steps were taken to keep it secret (access controls, labeling, need-to-know, policies, training).
Own knowledge features:
General expertise, industry know-how, non-confidential techniques
Lessons learned, problem-solving approaches, leadership skills
Publicly available information + own interpretation (with care)
Employers should focus on their industry and business and define their trade secrets, if any, and tell employees about them.
Employee Obligations During and After Employment
There is a difference between ongoing loyalty to the business and post-exit restrictions. Some business leaders say “we are a family” or, when someone leaves, they tell them they will always be part of the family. A business is not a family, and that’s okay. People are not connected in the same way so this is misleading (albeit well intended, I am sure).
Good Faith While Employed
Once employed, the employee owns a duty of confidentiality (DoC) to the employer not to share anything confidential outside the business (amongst other things).
Crucially, while they are in employment, they have an ongoing duty to act in good in faith, meaning:
Not to compete
Not to tarnish the employer’s reputation
Not to divert business elsewhere
Not to misuse time and resource for something not related.
Example
Sonya does not share any confidential about her employer’s business (okay). Sonya builds out her own client base during her 9-5 using her company-issue laptop (not okay; not acting in good faith).
Duty of Confidentiality Post Employment
When an employee leaves, the duty to act in good faith usually stops being relevant (unless they held a very senior position).
However, DoC continues, and often the so-called restrictive covenants come into play. These covenants are usually clauses in the employment contract that will restrict certain activities, such as not to approach the company’s clients for six months. These have to be reasonable as well otherwise the employer risks restricting the employee’s freedom to find work.
These clause are different in different jurisdictions.
Employer Controls and Employee Development
Employers should lead and steer the conversation so that all employees know what they are supposed to do (and they don’t have an excuse if they do something wrong). This includes, for example:
Clear confidentiality clauses and trade secret handling rules
IP assignment for work created in the scope of employment
Conflict-of-interest policy, plus clear guidance on what employees must do if they want a side hustle
Narrow non-solicit (clients and staff), garden leave (where lawful), return-of-property clauses
Restrictions / policies on using own devices, social media, and sharing information with yourself outside of work.
I have seen organisations get to keen and overreach sometimes. What might backfire is:
Blanket bans on learning in a field
Vague “anything you think about belongs to the company”
Intrusive monitoring without transparency
“Non-compete by policy” with no tailoring.
Our DPO Example
Returning to our outsourced DPO example, the tension wasn’t really about confidentiality at all but about visibility.
The truth is that personal branding and positioning is big now. The DPO commentator world is huge. Recruiters, journalists, other commentators and platforms like LinkedIn like active profiles. Modern careers require visibility.
This doesn’t mean that if you’re not commenting on LinkedIn your career will fail or people won’t come to you for advice. Sometimes, however, either employees are encouraged to build profiles and share insights, they feel they need to to succeed, or, simply, they just like it and want to contribute to the industry (like me).
As a general rule, employers cannot limit professional insight and industry contributions simply because they create discomfort outside clear confidentiality, conflict, or contractual limits. This is subject to the employee’s ongoing duties of fidelity, good faith, and any reasonable conflict-of-interest restrictions while employed. In fact, there is a chance that the more senior the DPO is, the more likely it is that they will have insights on various things (which only benefits their business if they are measured and reasonable).
A few important things to note here:
Employers cannot (and should not) stop people thinking, learning, or contributing to their profession.
Employees must still act in good faith and not monetise or disclose what belongs to the business (including respecting employer-owned IP and trade secrets, even where the underlying expertise or skill is part of the employee’s general professional knowledge).
The boundary is not “don’t speak” – it’s what you speak about, how you frame it, whose assets you use, and if the activity is competing.
Posting on LinkedIn
Firstly, if the employer does not have a social media policy, tied to the staff privacy policy, it’s much harder to manage expectations beyond existing duties of confidentiality and good faith.
Secondly, employers risk appearing “creepy” if they try to control what employees are posting which is just a commentary and not anything relating to the business. From a data protection perspective, monitoring or policing employees’ personal social media activity is itself a form of personal data processing and must be lawful, transparent, and proportionate.
Practical guardrails for employees:
Add “views my own” and that they don’t represent any employer’s views, but don’t rely on it as a shield.
Avoid internal terminology that isn’t public-facing.
Keep drafts neutral enough that you’d be comfortable showing them to your employer (or anyone).
Be kind.
Practical guardrails for employers:
Avoid blanket bans on posting or speaking.
Focus policies on confidentiality, endorsement, and conflicts, not silence.
Recognise that visible employees can enhance reputation, not just create risk.
In consultancy and professional services firms, this issue often reflects:
Founder anxiety about retention
Fear of knowledge leakage framed as loyalty
Discomfort with employees having independent professional standing
Blurred lines between “our brand” and “your career”
This is not solved by restriction. It is solved by clear boundaries and open communication.
All in all, the confidentiality gap needs to be acknowledged and communicated. Building a professional profile is not the same as building a competing business; treating it as such creates more risk than it prevents. Confusing the two undermines trust and stifles development – both of the business and of the people within it.
* See and compare sections 9(1) and 11 of the Copyright, Designs and Patents Act 1988.