주메뉴바로가기본문바로가기
비즈한국 비즈한국

Useful Business Tips
Information Departs, Responsibility Remains… Conditions for Easy 'Secret Management'

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] Companies sometimes make decisions that are difficult to explain by money alone. Understanding the laws or systems hidden behind these decisions can help clarify the situation. ‘Useful Business Tips (Al-Ssul-Bi-Beop)’ introduces clues to help understand business flows.

Types of corporate information leakage are largely divided into external and internal. Corporate information management is a crucial issue that determines the maintenance and survival of a business. Photo=Generative AI
Types of corporate information leakage are largely divided into external and internal. Corporate information management is a crucial issue that determines the maintenance and survival of a business. Photo=Generative AI

One of the core elements of a business is information. Information can be stolen from the outside or leaked from the inside. What are some examples of external theft? A representative case is when a primary contractor abuses its bargaining position in a subcontracting transaction to demand technical data from a subcontractor. Cases where a primary contractor provides a subcontractor's technology to another partner or uses it for their own technology development are all subject to administrative sanctions under the Subcontracting Act as unfair subcontracting practices. These types of cases involve information being taken due to external demands.

What are some cases of internal information leakage? This occurs when an employee in charge of technology development copies company information while changing jobs and uses it for a competitor or their own business. Such actions constitute trade secret infringement and can result in civil and criminal liability under the Unfair Competition Prevention Act.

The reason for enacting special laws to protect a company's key information is that managing this information is a critical issue that determines the maintenance and survival of the business. Large companies with sufficient capital and personnel likely have no trouble utilizing such systems to protect their key information.

However, most small and medium-sized enterprises (SMEs) feel significant burden in utilizing these systems. This is because it is difficult to meet the requirements demanded by individual laws and to prove those facts. For instance, the Unfair Competition Prevention Act requires non-public nature, economic utility, and secret management as requirements to recognize something as a 'trade secret'. Non-public nature refers to a state where information is not publicly known and cannot be easily accessed by anyone. Secret management refers to a state where information is designated as secret and maintained through human, physical, and legal means.

While these may seem like obvious requirements on paper, proving them in actual litigation is extremely difficult. First, because of the non-public nature requirement, information that can be relatively easily obtained or inferred by people in the industry, let alone the general public, is not recognized as a trade secret.

Furthermore, information that can be deduced by combining various pieces of information and experience in the industry, or information exchanged during negotiations with other companies, cannot be recognized as having a non-public nature. In fields with high labor mobility, such as manufacturing, content, and platforms, information circulates and is exchanged frequently, making it difficult to claim non-public nature. Also, information composed of tacit or abstract know-how cannot be recognized as a trade secret because the subject of protection cannot be specifically identified.

Proving 'secret management' is also not easy. Although phrases like 'reasonableness' regarding the level of management were removed through recent legal amendments, appearing to broaden the scope of protection, it does not seem that court rulings are recognizing trade secrets more broadly than before. Specific details of secret management include marking documents as secret, controlling access through technical and physical measures, and imposing security obligations on employees through internal regulations. However, in my experience, I have rarely seen SMEs follow all such procedures and processes.

To protect a company's key information, one should not spare costs or efforts in implementing protective measures.
To protect a company's key information, one should not spare costs or efforts in implementing protective measures.

This is not unrelated to Korea's corporate culture. Overall, there is a tendency to prioritize work efficiency over procedural compliance. Roles and Responsibilities (R&R) are often unclear, leading to multiple staff being assigned to a single project. While this approach helps achieve short-term results, it is inevitably vulnerable in terms of proactive information management for dispute prevention.

The court's stance is that "it is difficult to protect information as a trade secret after the fact if it was not recognized or managed as a secret in the first place." SMEs cite realistic limitations, stating, "It is difficult to perform normal work if all procedures are followed formally." Because of these differing positions, the utilization of the trade secret system is low, except for large corporations or those in high-tech fields.

The technical data protection system under the Subcontracting Act has eased requirements in many ways to protect subcontractors. With the Fair Trade Commission (FTC) recently declaring its intent to enforce the Subcontracting Act in the technical data sector, it is expected that there will be more cases of protection than in the past. However, the Subcontracting Act is, in principle, a law enforced by the FTC, and such administrative investigations and dispositions are not remedies that parties can claim as a matter of right. Thus, there is a structural limitation where individual subcontractors cannot demand immediate and effective relief when an infringement occurs. In particular, the FTC sanctioning a primary contractor for violating the Subcontracting Act does not necessarily restore the subcontractor's damages. The limitation is clear in that the subcontractor must file a civil lawsuit for damages against the primary contractor.

Because of these circumstances, the legal principle of occupational breach of trust is important in the field of information theft and leakage. The Supreme Court ruling (2018Do4794) stated, "If a company employee fails to return or destroy materials that they are obligated to return or destroy upon resignation, with the intent of leaking them to a competitor or using them for their own benefit, even if the material does not necessarily qualify as a trade secret, it constitutes occupational breach of trust if it is at least not disclosed to the unspecified public, cannot be obtained without the holder, constitutes a major business asset that the holder spent significant time, effort, and cost to acquire or develop, and can provide a competitive advantage."

Additionally, the Seoul Central District Court ruling (2021GaDan5196919) ordered a former couple manager at a marriage information company to pay 20 million won, ruling that leaking the information of 470 customers upon resignation constituted an illegal act. The Uijeongbu District Court ruling (2015GoDan3911) sentenced a defendant to 6 months in prison suspended for 1 year, finding that a manager of a mutual aid society's customer management team violated their duty by using the former company's customer information for another company after resignation, viewing the acquisition of property benefits equivalent to the market price of the customer information file and the sales loss of the victim company as property damage.

Ultimately, the legal principle of occupational breach of trust is very important for protecting company information. Although there is recent discussion about abolishing the crime of breach of trust, a compensatory measure that can replace it in terms of information protection must be prepared first before the system is abolished. Companies must also not spare costs or efforts in implementing protective measures for key information. Information to be managed as secret should be separated and stored, access and use should be controlled through technical measures, history of leakage and usage should be managed, and the duty of confidentiality should be imposed on internal members through internal regulations such as employment rules. Just by establishing these basic steps—'Secret classification and marking → Access and removal control → Usage history management'—the effectiveness of information protection can be significantly improved.

This article was automatically translated by AI. There may be errors compared to the original Korean article.
정양훈 법무법인 바른 파트너 변호사
writer@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지