주메뉴바로가기본문바로가기
비즈한국 비즈한국

Useful Business Tips
The Key to Information Leakage Lawsuits: 'Traces of Management' over 'Value'

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] Companies sometimes make decisions that are difficult to explain based solely on money. Understanding the laws and systems hidden within those decisions allows for a deeper insight into the circumstances. 'Useful Business Tips (Al-Sseul-Bi-Beop)' introduces clues to help understand business flows.

There is little a company can do when a former employee leaks information. Photo=Generative AI

If a company discovers, after the fact, that a former employee walked away with company data, what can it do? To put it bluntly, there is not much that can be done at that point. Courts generally view lawsuits filed by companies against employees negatively. Even if a security pledge or non-disclosure agreement (NDA) was signed, there are many cases where the effectiveness of the document itself is denied, and it is common for claims for damages or liquidated damages based on such documents to be rejected. Recently, even when evidence proved that an employee had transmitted a large amount of company data via KakaoTalk just before leaving, the court dismissed the company's claim on the grounds that "there was a business need and KakaoTalk had been used for work purposes as a routine matter."

Therefore, information protection is not a matter of post-incident response, but of pre-design. However, that design must be more concrete than one might commonly think. A point of confusion in information leakage cases is the "value" of the information. People often try to prove the value of the information, arguing that they are entitled to damages because the leaked information was highly valuable.

However, this is an easy argument to rebut. One can argue that general business information, as opposed to highly advanced technical information, can be created by anyone given enough time. Furthermore, proving that information is critical enough to determine the fate of a company is practically impossible. In other words, an approach that seeks to calculate damages based on an objective valuation of the information is generally unrealistic.

For this reason, recent practice has shifted toward focusing on how information has been managed, rather than its inherent value. In the Seoul Northern District Court judgment 2023Gadan100497, the court upheld a claim for damages against a former employee and ordered 15 million KRW in compensation. In this case, the employee had signed a pledge upon entering the employment contract, promising not to leak or use trade secrets and confidential data acquired at the company without authorization, both during and after their tenure. Despite this, the employee leaked customer and issue information, which was confirmed through objective evidence.

To prevent the leakage of important information, the company provided employees with laptops and PCs for work; however, this employee unilaterally notified the company they would use a personal laptop and downloaded customer information onto it. The court, based on the legal principle that a reasonable amount of compensation can be determined when damages are acknowledged but the exact amount is difficult to prove, determined the compensation amount by taking into account the circumstances and manner of the leak, whether the employee joined a competitor or started a business, and whether existing clients had left.

There are three key takeaways from this ruling. First, security pledges must be written clearly. The most important factor is not the objective value of the information, but whether physical and legal management was in place. Second, the fact of the leakage must be proven through objective methods. This means that information leakage must be recorded and managed through technical means on a constant basis. Third, the consequences of the leakage are merely one factor to consider in calculating damages.

Similar trends can be observed elsewhere. Looking at recent amendments to the Subcontracting Act and the enforcement practices of the Korea Fair Trade Commission, the prevailing interpretation is that if information is managed as a secret and deemed to have business value, it is only natural to protect it, rather than debating its objective value. How much economic value the information generated is not the primary issue.

The court considers how the company managed its secrets more important than how valuable the leaked company information actually is. Photo=Generative AI

In summary, what a company must prove is not "how incredible this information is," but "whether we have treated this information as a secret." Leaving traces of management is equivalent to legal defense capability. There are six ways to leave those traces.

First, don't just receive a pledge; design it. Many companies feel at ease after simply collecting a signed pledge at the time of hiring. However, the composition of the pledge is more important than the fact that the document exists. First, redefine the scope of protected information. If the scope is set too broad, it may raise issues of unfairness; if set too narrow, the practical benefit of having the document disappears. The same applies to liquidated damages. If the amount is excessive, the provision itself may be declared invalid and unusable when actually needed, so it is safer to redesign it to be proportional to the actual salary paid. Additionally, you must secure prior consent for forensic investigations of electronic devices in case a leak is suspected. Without this consent, you will be blocked from the very start of the evidence-gathering phase.

Second, there is no legal control without technical control. Protecting information assets cannot be accomplished through legal documents alone. You must implement measures such as migrating company data to the cloud to prevent copies from remaining on personal devices and installing security monitoring programs on work PCs to centrally track file usage and transfer history. Such technical measures are more significant in that they not only prevent leaks but also leave objective evidence of who transferred what and when. The fact that the company provided work devices in the aforementioned ruling influenced the decision in this same context. However, as the introduction of technology is not an end in itself, it is necessary to consult with security firms in advance to ensure it aligns with legal control and management systems.

Third, do not stop at establishing regulations; execute them. Incorporate security regulations into the employment rules, pass them through a board resolution, and post them on the company intranet. Explicitly state in the regulations that transmitting company data via non-official channels—such as personal KakaoTalk or Telegram accounts—regardless of the business purpose or recipient, is a violation of company policy. The reason for this becomes clear when recalling the aforementioned case where the excuse of "business necessity" was accepted. Furthermore, monitor employee PCs periodically to produce security audit reports and share the results. This is because you must be able to objectively show that the regulations are not just declarations but are actually being enforced.

Fourth, education must precede regulations. Before collecting pledges and implementing security regulations, conduct training to explain the purpose behind them. Imposed controls without context breed resistance, and that resistance becomes ammunition for challenging the validity of the agreements later. The record of having conducted training is, in itself, evidence that the company has taken information management seriously.

Fifth, the final hurdle is the offboarding process. Standardize response procedures for resignations. Establish individual steps—such as exit interviews, collection of electronic devices, conducting forensics if necessary, and signing return and data destruction confirmation forms—and apply them without exception. Most disputes arise in this short window where evidence is either created or destroyed.

Sixth, provide compensation in exchange for control. Policies that mandate company-provided PCs, ban the use of personal laptops, and restrict the use of personal messengers are inherently inconvenient for employees. Therefore, consider paying a separate "information protection allowance." This not only increases employee acceptance but also demonstrates that there was compensation corresponding to the controls, which can work in the company's favor if the validity of the agreement is challenged later.

To summarize the above: First, what convinces the court is not the value of the information, but the traces of management. Second, pledges, security regulations, technical controls, and offboarding procedures do not work as isolated measures but as a single set. Third, the cost of all these measures is far less than the time and money required for a single information leakage lawsuit. A company's information assets are the product of trust and effort accumulated over a long time. Protecting them must start now, while nothing has happened, rather than after a crisis occurs.

This article was automatically translated by AI. There may be errors compared to the original Korean article.
정양훈 법무법인 바른 파트너 변호사

필자 정양훈은 법무법인 바른 공정거래그룹의 구성원 변호사이다. 공정거래위원회 사건과 컴플라이언스, 하도급·가맹·대리점 등 유통분야 사건을 전문적으로 수행하고 있다. 대한법률구조공단, 서울고등검찰청(국가소송팀) 등을 거쳐 바른에 합류하였으며, 강연과 기고를 통해 공정거래 분야의 이슈와 실무를 알기 쉽게 전달하는데 힘쓰고 있다.

writer@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지