1. What counts as confidential information
  2. Breach of confidence: the equitable foundation
  3. How contracts reinforce your position
    1. Non-disclosure agreements
    2. Employment contracts and post-employment obligations
    3. IP assignment
  4. Where businesses usually go wrong
  5. Protecting confidential information when working with third parties
  6. What to do if confidential information is leaked or misused
  7. How Artificer Legal can help
  8. Conclusion

Every growing business collects information that is worth protecting — the pricing model you spent months refining, the supplier terms you negotiated hard for, the customer segmentation data that drives your conversions. That information does not register anywhere. No certificate is issued. But it can still be one of your most valuable commercial assets, and Australian law gives you real tools to protect it — provided you use them properly.

This article explains what confidential information is in a legal sense, how the equitable doctrine of breach of confidence works, where contracts and employment obligations fit in, and what practical steps you need to take to make those protections actually hold up. We will also cover the most common mistakes businesses make and where professional advice makes the difference.

What counts as confidential information

Not every piece of internal information is legally protectable. Australian courts have consistently required three qualities before treating information as confidential in any meaningful legal sense:

  • It must not be in the public domain. Once information is freely available — published on a website, disclosed in a patent, or common industry knowledge — it loses the quality of confidence. The protection attaches to secrecy, not just sensitivity.
  • It must have commercial value because it is secret. A list of customers you painstakingly built is valuable precisely because competitors do not have it. A generic process that anyone in the industry follows is not. The value must derive from the information being kept from others.
  • Reasonable steps must have been taken to keep it confidential. This is the element most businesses underestimate. Courts will look at whether you actually treated the information as a trade secret — through contracts, access controls, labelling, and training — not just whether you assumed everyone understood it was private.

These requirements flow from the broader equitable doctrine explained below, but they also shape what goes into a practical protection program. The categories of information that tend to qualify include formulas, algorithms and source code; product roadmaps and R&D data; customer lists, pricing models and margin data; manufacturing processes and operational procedures; and marketing strategies and performance data. What they have in common is that they give you an edge your competitors would love to have.

Breach of confidence: the equitable foundation

Before you even think about contracts, Australian law gives you an equitable cause of action for breach of confidence. This is a remedy that courts have developed over a long time to protect people and businesses whose confidential information has been misused — regardless of whether there is a contract in place.

The classic statement of what you need to prove comes from Coco v AN Clark (Engineers) Ltd [1969] RPC 41, where Megarry J identified three elements:

  1. The information must have the necessary quality of confidence — it is not public knowledge and carries the character of confidentiality.
  2. The information must have been imparted in circumstances importing an obligation of confidence — the recipient knew, or ought to have known, that the information was being shared in confidence.
  3. There must have been an unauthorised use of that information to the detriment of the party who communicated it.

Australian courts have applied and refined this test across commercial disputes. The third element — detriment — has sometimes been treated flexibly in commercial cases, but the first two are consistently required. What this means practically is that if a business partner, contractor, or former employee walks away with your customer database or technical specifications and uses them for their own benefit, you may have an equitable claim even if your NDA was defective or you had no contract at all.

That said, equity has limits. If you never treated the information as confidential in the first place — if you discussed it freely in meetings with no confidentiality understood, emailed it without restriction, or let it circulate beyond those who needed it — a court is unlikely to find that the circumstances imported an obligation of confidence. The equitable protection and the practical steps you take are two sides of the same coin.

How contracts reinforce your position

Equity provides a floor. Contracts raise it significantly. The three main contractual tools for most Australian businesses are non-disclosure agreements, employment contracts with tailored confidentiality provisions, and IP assignment clauses.

Non-disclosure agreements

A non-disclosure agreement (NDA) defines exactly what information is confidential, sets out how it may be used, specifies who it can be shared with, and states how long the obligations last. Used well, an NDA removes the ambiguity that can undermine an equitable claim — the recipient cannot argue they did not understand the information was confidential or that the circumstances were informal.

NDAs can be one-way (where only one party is disclosing) or mutual (where both parties are sharing confidential information with each other). Use them before sharing sensitive details with potential partners, advisors, suppliers, investors, or collaborators. Getting an NDA signed after the disclosure has already happened provides much weaker protection and may not fill the gaps at all.

Employment contracts and post-employment obligations

Employees present the highest-risk category because they access the most sensitive information as part of their ordinary role. Australian law implies a duty on employees not to disclose or misuse an employer's trade secrets or confidential information during the course of employment. That implied duty, however, narrows considerably once employment ends.

For confidential information to remain protected after departure, you need express contractual obligations. A well-drafted employment contract should:

  • Define what information the business regards as confidential and bind the employee to keep it so both during and after employment
  • Include specific obligations around how confidential material is to be handled — storage, access, and return or destruction on exit
  • Contain an IP assignment clause ensuring that work product created in the role belongs to the business

For senior or key employees who have genuine access to trade secrets or client relationships, post-employment restraints — non-compete and non-solicitation clauses — can provide additional protection. These provisions are enforceable in Australia, but only to the extent they are reasonable in scope, duration, and geography. A blanket prohibition on working in an industry for five years nationally is unlikely to survive challenge. A narrower prohibition targeted at the specific legitimate interest — say, preventing a senior sales manager from soliciting clients they personally managed for twelve months within a defined region — stands on much firmer ground.

In New South Wales, the Restraints of Trade Act 1976 (NSW) gives courts power to read down an excessive restraint rather than void it entirely, which provides some flexibility for employers. In other states, courts apply the common law's all-or-nothing approach at the clause level, which is why cascading or laddered restraint clauses — setting out multiple fallback positions in the one clause — are commonly used.

IP assignment

If employees or contractors are creating anything — software, designs, processes, written materials — you need a written IP assignment confirming ownership rests with the business. The default position under Australian law is not always intuitive, and assumptions about who owns contractor-created work have caught many businesses off guard. An express assignment in the employment or services contract, or as a standalone document, is the cleanest solution.

Where businesses usually go wrong

The gap between having protections in theory and having them hold up in practice is almost always caused by one of the following failures.

Contracts are signed too late or not at all. Information shared before an NDA is executed is not retroactively protected by that NDA. Many businesses share detailed technical or commercial information during exploratory conversations and only think about confidentiality once a partnership is underway. By then, a significant part of the risk has already materialised.

Employment contracts are generic or outdated. A template employment contract that lumps confidentiality into a one-line clause — or that was drafted ten years ago and has never been reviewed — will often fail to cover the specific information the business actually wants to protect. Courts interpret ambiguous confidentiality clauses narrowly.

Practical controls are absent. Even a well-drafted NDA can be undermined if the business itself treats the information casually. Sharing a confidential pricing spreadsheet via a public link, giving every employee broad access to sensitive systems, or never training the team on confidentiality obligations all work against you if you later claim the information was treated as a trade secret.

Exit processes are overlooked. Many leaks happen at the point of departure — departing employees take templates, contact databases, or technical files with them, often reasoning that it saves time. An offboarding checklist that covers device return, credential revocation, system access removal, and a written reminder of ongoing confidentiality obligations is a simple measure that significantly reduces this risk.

Restraints are drafted too broadly. An unenforceable restraint provides no protection at all. Businesses that copy a competitor's restraint clause, or draft maximum-scope provisions hoping a court will trim them, often end up with a clause that is struck down entirely in states outside NSW, or that will not withstand the scrutiny of a summary enforcement application when it matters.

Protecting confidential information when working with third parties

Sharing information with suppliers, development partners, investors, and service providers is a commercial reality. The goal is to share intentionally, with guardrails in place.

Before disclosing anything sensitive, stage the process: share enough for the counterparty to assess the opportunity, then deepen the disclosure as the relationship progresses and protections are in place. Set clear rules about who within the counterparty's organisation can access the information and in what form. Specify what happens to the information when the engagement ends — return, destruction, or certified deletion.

For any engagement where a third party is developing something on your behalf — software, a product design, a process — include an express IP ownership clause. "Background IP" (what each party brings to the table) should stay with its owner, and "foreground IP" (what is created in the engagement) should be assigned as agreed in the contract.

If the counterparty will handle your data or the personal information of your customers, their security obligations should be addressed in the contract or a security schedule. This is not only commercially prudent but also relevant to your own obligations if you are an entity covered by the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).

What to do if confidential information is leaked or misused

Speed matters. The sooner you act after discovering a breach, the better your chance of containing the damage and preserving your legal options.

Contain first. Revoke access, lock accounts, pull down shared links, and secure any devices involved. Preserve logs, screenshots, and other evidence without altering the compromised materials unnecessarily — maintaining a clear audit trail is important if you later seek urgent court orders.

Assess your contractual position. Identify which agreements apply and review the specific confidentiality clauses and remedies they provide. Your options may include a formal cease and desist letter, negotiated undertakings, or an application for urgent injunctive relief to stop further misuse. An injunction is often the priority because information, once disseminated, cannot be recovered.

Consider notification obligations. If personal information was involved, you may be required to assess whether the incident is an eligible data breach under the Notifiable Data Breaches scheme and, if so, notify affected individuals and the Office of the Australian Information Commissioner (OAIC). The Privacy Act 1988 (Cth) requires entities covered by the scheme to take reasonable steps to complete a data breach assessment within 30 days of becoming aware that grounds exist to suspect an eligible data breach has occurred.

Close the gap. Once the immediate situation is under control, review how the incident happened and update your policies, contracts, and controls accordingly. An incident is an opportunity to identify the weakest point in your program.

The legal issues around confidential information rarely sit neatly in one box. An effective protection strategy involves equitable principles, contract drafting, employment law, and intellectual property — often all at once. That is where having a lawyer involved from the beginning, rather than after a breach, makes a material difference.

Artificer Legal can assist with:

  • Reviewing or drafting NDAs tailored to your situation — whether you are entering a development partnership, approaching investors, or engaging contractors — rather than using a generic template that may not cover what you actually need to protect
  • Auditing your employment contracts to ensure confidentiality and IP assignment clauses are clear, current, and fit for the roles in question
  • Drafting or reviewing post-employment restraints calibrated to what courts are likely to enforce, including cascading clauses and geographic scoping appropriate to your market
  • Advising on an information security framework that supports your legal position — the practical measures that tell a court you treated the information seriously
  • Responding to a breach — from the initial containment steps through to assessing whether to seek injunctive relief, managing notification obligations, and advising on remedies

The earlier Artificer Legal is involved, the more options are available. Once information has been misused and has spread, the remedies narrow considerably and the cost escalates.

Conclusion

The single most important thing to understand about confidential information protection is that the law rewards preparation. Courts ask whether you treated the information as a trade secret — and the answer has to be demonstrated through your contracts, your controls, and your conduct, not just asserted after the fact.

Here are the key points to take away from this article:

  • Australian law protects confidential business information through the equitable doctrine of breach of confidence, requiring the information to have quality of confidence, to have been shared in circumstances importing an obligation, and to have been used without authorisation.
  • Contracts — NDAs, employment agreements, and IP assignments — are essential complements to equitable protection. They remove ambiguity, extend obligations beyond the period of employment, and give you clearer remedies.
  • Post-employment restraints are enforceable in Australia only to the extent they are reasonable in scope, time, and geography; in NSW, courts can read them down rather than void them.
  • Practical controls — access management, labelling, training, and offboarding checklists — are what courts look at when assessing whether "reasonable steps" were taken to keep information confidential.
  • When working with third parties, stage disclosures, set security expectations in the contract, and plan for what happens to the information at the end of the engagement.
  • If a breach occurs, act quickly: contain, preserve evidence, assess your contractual remedies, consider notification obligations under the Privacy Act, and then systematically close the gap.