Protecting Confidential Information — Trade Secrets & Post-Employment

An Employee Downloads the Company’s Client List to Their Personal Laptop the Week Before Leaving for a Competitor. They Built Those Relationships. Does the List Belong to Them?

A real trade secret and confidentiality scenario — with three decision options and the right answer.

Quick Answer

Does an employee who built client relationships over several years own the client list — and can they take it when they leave?

No. A client list — including names, contact details, purchasing history, account notes, and relationship intelligence stored in a company’s CRM — is a trade secret that belongs to the employer regardless of who built the underlying relationships. Under the Defend Trade Secrets Act and most state equivalents, the employee’s personal contribution to building those relationships does not change who owns the data. Downloading a client list to a personal device before departure is a trade secret misappropriation regardless of intent — and the receiving company that accepts or uses that list has its own legal exposure.

The Situation

A senior account manager at a financial services firm has accepted a position at a direct competitor. In the final week before their last day, they spend an hour exporting the firm’s full client database — approximately 340 accounts including contact details, revenue figures, notes on client preferences, and relationship history — to their personal laptop. They tell themselves it is not a big deal: these are relationships they built over six years, the contacts are people they know personally, and they will not use the information to “hurt” the firm — only to stay in touch.

In their first week at the new firm, a colleague asks how they plan to build their book. They mention they have their full contact list from their previous role. The colleague mentions it to their manager. The manager mentions it to Legal.

By Friday, the account manager is on administrative leave at the new firm while Legal assesses the situation. The previous firm’s outside counsel has sent a preservation notice.

What Should Have Happened?

Choice AThe download was fine. The account manager built those relationships personally. The contacts know them, not the firm. Taking your professional network when you leave is standard practice and the list is essentially their own contact book.

Choice BDo not download the client database. Leave without taking any company data. At the new employer, build a new book using publicly available information — LinkedIn, industry directories, professional connections — not data extracted from the former employer’s CRM.

Choice CDownload the list, but keep it personal. Don’t load it into the new employer’s systems or share it with anyone. Use it only as a private reference for reconnecting with people you know. What the new employer doesn’t know won’t create a problem for them.

The Right Call

Choice B — Leave without taking any company data.

Choice C is the rationalization most employees in this situation choose — and it creates nearly the same legal exposure as Choice A while adding a layer of concealment. The download has already occurred. The data is on the personal device. The trade secret misappropriation occurred at the time of export, not at the time of use. “Keeping it personal” doesn’t undo the violation, and it doesn’t protect the new employer, which, once aware of the list’s existence, faces its own disclosure and liability problems. Choice B is the only option that avoids the misappropriation entirely. The professional relationships the employee built are real and portable — the CRM data that documents them is not.

Why This Is Harder Than It Looks

“I built those relationships” is the most convincing wrong answer in trade secret law.

The account manager’s reasoning is understandable and almost universal. Employees who spend years building client relationships develop a genuine sense of ownership over those connections. The legal reality — that the data documenting those relationships belongs to the employer regardless of who did the relationship work — is genuinely non-intuitive. A client list stored in a company CRM behind a login, covered by an employment confidentiality agreement, qualifies as a trade secret under the DTSA regardless of the employee’s contribution to building it.

The violation occurs at download — not at use.

Most employees who take client lists believe their intent matters — that they haven’t done anything wrong because they haven’t harmed the company yet. Intent affects the damages calculation in a trade secret case. It does not affect whether the misappropriation occurred. The export to a personal device is the violation. The question of whether and how the data was subsequently used determines how serious the consequences are — not whether a violation happened at all.

The new employer’s exposure is the part nobody talks about.

A company that receives a competitive hire who brings their former employer’s client database — even passively, even without asking for it — has potentially acquired stolen trade secrets. The DTSA allows the original employer to pursue the receiving company for misappropriation by acquisition when the company knew or should have known the information was obtained improperly. “Should have known” is a low bar when the new hire has just joined from a direct competitor and mentions bringing their full contact list on day one. The Legal team that put the account manager on administrative leave was doing exactly the right thing — protecting the company from that liability.

A client list is protectable. A vendor list is protectable. A contact on LinkedIn is not.

The distinction worth understanding: a client’s name and public contact information that could be found on LinkedIn or through a Google search has weakened trade secret protection because it is publicly available and independently derivable. A CRM record containing purchase history, pricing, relationship notes, internal contacts, and account-specific intelligence that exists nowhere in the public domain has strong trade secret protection because the only way to get it is from the employer’s system. The account manager can reconnect with clients they know personally using publicly available information. They cannot take the CRM record that documents everything the company knows about those clients.


Frequently Asked Questions

Does a client list qualify as a trade secret even if the employee built the relationships personally?

Yes. Under the Defend Trade Secrets Act and most state equivalents, a client list qualifies as a trade secret when it derives economic value from not being generally known and the employer has taken reasonable steps to keep it confidential — which virtually every organization does through password-protected CRM systems and employment confidentiality agreements. The employee’s personal contribution to building the relationships is not a factor in the ownership analysis. The data belongs to the employer.

What should a departing employee do if they want to stay in touch with clients they worked with?

Connect with clients on LinkedIn before departure using the platform’s standard connection tools — that is public information the employee can legitimately maintain. Do not export CRM records, email contact lists, or any data from the employer’s systems to a personal device or account. The professional relationship belongs to the employee. The data documenting it belongs to the employer. That distinction is the line between legitimate networking and trade secret misappropriation.

What should the receiving company do when a new hire mentions they brought their former employer’s client list?

Stop, involve Legal immediately, and do not allow the list to be used in any way. The company should preserve all communications with the new hire about the list, instruct the new hire not to use or distribute the data, and assess whether the company’s receipt of the information creates DTSA exposure. The new hire should be placed on administrative leave pending Legal’s assessment. The correct response is not to ask to see the list — it is to treat its existence as a legal problem that requires immediate counsel.

What is the difference between a trade secret client list and public contact information?

Public contact information — a name and email that appears on LinkedIn or a company website — is not a trade secret because it is generally known and independently derivable. A CRM record containing purchase history, pricing data, relationship notes, internal contacts, and account-specific intelligence is a trade secret because it exists only in the employer’s system and cannot be independently reconstructed. The employee who reconnects with clients using LinkedIn is using publicly available information. The employee who downloads the CRM record documenting those clients is taking a trade secret.

How to Use This Scenario in Training

Recommended for all employees in client-facing roles — account managers, sales, business development, and relationship managers — and for HR teams managing competitive departures. This scenario has two critical training audiences simultaneously: the departing employee who needs to understand the trade secret line, and the receiving company’s hiring managers who need to understand their own exposure when a new hire offers to bring their former employer’s data.

This scenario is built on the Decision Readiness Engine™ — specifically the rationalization principle: “I built those relationships, the contacts belong to me” is one of the most convincing and most legally incorrect rationalizations in trade secret law. Decision-ready employees are trained to recognize the moment before the download — not after — when the rationalization is forming and the right action is still available.

More Confidentiality & Trade Secret Scenarios

Trade Secrets

A data scientist rebuilds a proprietary algorithm from memory at a competitor. No files taken. Still a problem.

Post-Employment

My new manager asked me to share my former employer’s pricing strategy. It’s in my head. Is that a problem?

Full Cluster

Browse all scenarios for confidentiality and workplace gossip compliance training.

Want This Scenario in Your Compliance Program?

Xcelus builds scenario-based confidentiality and trade secret training for client-facing teams, hiring managers, and HR professionals navigating competitive departures and onboarding.

View the Compliance Reinforcement Kit →
Contact Xcelus

© 2005–2026 Xcelus LLC. All rights reserved. Scenario content is original work protected by copyright. You may link freely — reproduction or adaptation without written permission is prohibited.

© 2005–2026 Xcelus LLC. All rights reserved. This content is for training and discussion only and is not legal advice; consult qualified counsel about your organization’s specific obligations.