1. Where the obligation comes from
  2. What counts as confidential information
  3. How the duty behaves during employment
  4. How the duty behaves after employment ends
  5. What remedies are available when the duty is breached
  6. A worked example
  7. How Artificer Legal can help
  8. The contractual layer that goes beyond the common law

Workplace confidentiality is the set of obligations that stop people inside a business from disclosing or misusing information that the business treats as private. It covers a wider field than most owners assume: client lists, pricing models, supplier terms, draft strategy, board papers, source code, personnel records, and anything else the business has chosen to hold close. The legal scaffolding sits across three layers — the employment contract, the common law duty of fidelity, and a handful of statutory duties that apply on top — and each layer does something different.

This article works through what workplace confidentiality actually is in Australian law. It covers:

  • the sources of the obligation (contract, common law, statute);
  • what counts as confidential information in the first place;
  • how the duty behaves during employment and after it ends;
  • the remedies a business can reach for when the duty is breached; and
  • a worked example tying the pieces together.

Where the obligation comes from

Most owners think of confidentiality as a clause in the employment contract. That clause matters, but it is not the only source of the duty.

The first source is contract. A confidentiality clause in a written employment agreement defines what the business treats as confidential, what the employee can and cannot do with it, and — critically — how long the restriction lasts after the employment ends. Without a written clause, the business has to fall back on the next two sources, both of which are harder to enforce.

The second source is the common law duty of fidelity and good faith. Australian courts have long recognised that employees owe an implied duty not to misuse their employer's trade secrets or confidential information, both during and after the employment. The duty exists without anyone writing it down. It is narrower than a well-drafted contractual clause, though: it really only catches information with a genuinely confidential character, and the business has to prove that character in evidence.

The third source is statute. The most direct provision for company officers and employees is s 183 of the Corporations Act 2001 (Cth), which prohibits a person who obtains information because they are, or have been, an officer or employee of a corporation from improperly using that information to gain an advantage for themselves or someone else, or to cause detriment to the corporation. State workplace surveillance laws (for example the Workplace Surveillance Act 2005 (NSW)) also feed into the picture by regulating how a business can monitor employees to detect misuse, and the Australian Privacy Principles regulate how personal information held by the business can be handled.

What counts as confidential information

Not everything inside the four walls is confidential. Courts generally look for three features:

  • The information has a confidential quality. It is not in the public domain. Public news, generic industry knowledge, and skills the employee carried in are not protected.
  • The information was communicated in circumstances importing an obligation of confidence. A document marked "Confidential — Board Only" passed across the table at a board meeting clearly is. An offhand comment in the kitchen is harder.
  • The information has commercial value because it is confidential. A client list assembled over a decade has value precisely because competitors do not have it.

In practice, the categories that come up most often in disputes are: client and customer lists, pricing and margin information, supplier terms, marketing strategy, technical know-how and source code, and personnel information including remuneration data.

A useful test for owners: if a competitor obtained this tomorrow, would the business be measurably worse off? If yes, it is probably confidential and should be labelled, stored, and contracted around as such.

How the duty behaves during employment

While an employee is working, the duty is at its strongest. The employee can use confidential information to do their job, but cannot disclose it externally, take copies for personal use, or send it to a personal email account.

Practically, this is the period in which most businesses prevent breaches rather than respond to them. The standard controls are:

  • restricting access on a need-to-know basis, rather than giving the whole team the keys to everything;
  • requiring company devices for work involving confidential information, with a clear policy on personal devices;
  • logging document access and email forwarding to external addresses; and
  • giving the legally required notice before any workplace surveillance (in NSW, 14 days of written notice before computer or camera surveillance starts, subject to limited exceptions).

If a breach happens mid-employment, the first step is usually a documented conversation. Many "breaches" are an employee who did not realise the business treated something as confidential, or who emailed a file home to keep working that night. Where the conduct is deliberate or repeated, the business may move to formal disciplinary steps up to and including termination, alongside the remedies discussed below.

The Fair Work Ombudsman's workplace privacy best practice guide sets out the general framework for how policies in this space should be written and communicated.

How the duty behaves after employment ends

This is where the layers diverge.

The contractual duty continues for whatever period the clause specifies — often "indefinitely" for genuinely confidential material, with shorter, more specific periods for things that age (a six-month forecast, for example).

The common law duty also continues past termination, but is narrower post-employment. After the employee leaves, the courts protect trade secrets and information of an equivalent character, but not the broader information that was confidential while the employee was inside the tent. Skills and general know-how the employee acquired on the job travel with them. This is one of the reasons a well-drafted contractual clause is worth the effort: it can capture more than the common law would, provided it is reasonable in scope and duration.

The statutory duty under s 183 of the Corporations Act also survives. A former officer or employee who improperly uses information obtained during employment to gain an advantage — for example, by approaching the former employer's clients with the benefit of pricing data they took with them — exposes themselves to civil penalty proceedings brought by ASIC, and to compensation orders.

The standard end-of-employment steps that lock the duty in are:

  • a final-day checklist returning company property and disconnecting access;
  • a written reminder of ongoing confidentiality obligations under the contract; and
  • where the exit is contested or the role had sensitive access, a deed of release that re-states the confidentiality obligations and, where appropriate, adds undertakings about destruction of any copies the employee may still hold.

What remedies are available when the duty is breached

A business that suspects misuse of its confidential information has a layered set of options.

A letter of demand is usually the first move. It identifies the information, identifies the conduct alleged, demands that the conduct stop, and asks for an undertaking — a binding promise — to delete or return the material. Many disputes resolve at this stage because the letter signals that the business has the evidence and is prepared to litigate.

An interlocutory injunction is the urgent court-ordered restraint that stops the conduct while the substantive case is prepared. To obtain one, the business generally has to show a serious question to be tried, that the balance of convenience favours the restraint, and that damages would not be an adequate remedy. The threshold is not trivial and the application is usually run by litigation lawyers on short notice.

A final injunction and damages, or an account of profits, are the substantive remedies at the end of the case. Damages compensate the business for loss caused by the breach; an account of profits requires the breaching party to hand over the gain they made by the misuse.

Where the breach involves a current employee, financial loss caused by the breach cannot simply be deducted from wages. The Fair Work framework restricts unilateral deductions from pay, so any recovery has to run through the civil claim, not the payroll.

A worked example

A boutique recruitment firm employs a senior consultant with a written employment agreement containing a confidentiality clause. Over three years she builds a working list of placed candidates and the salary bands they accepted, kept in the firm's CRM.

She resigns to start a competing agency. On her last day she returns the laptop and disconnects from email. A month later, two of her former candidates email the firm to say they have been approached with offers using salary figures only the CRM contained.

The firm's options sit on the three-layer stack. The contractual clause is the cleanest hook: it prohibits use of confidential information post-employment, and the salary data clearly falls within it. The common law duty supports the same conclusion, because a curated candidate-and-salary list of this kind has been treated by courts as the sort of trade-secret-adjacent information that survives termination. Section 183 of the Corporations Act gives a third overlapping hook against a former employee who has improperly used information obtained during employment to gain an advantage.

A letter of demand goes first, asking for an undertaking that she stop contacting the candidates and delete any copies. If she refuses or does not respond inside the deadline, the firm applies for an interlocutory injunction restraining further use of the list while it prepares the substantive claim for damages.

Workplace confidentiality is one of those areas where the work done before anything goes wrong is the work that matters. Artificer Legal helps Australian businesses with:

  • drafting confidentiality clauses in employment agreements that hold up post-termination, including survival periods that fit the actual information being protected;
  • writing the matching policies — acceptable use of company systems, personal device rules, surveillance notices that meet the state-by-state notice requirements, and exit procedures;
  • preparing tailored deeds of release for sensitive exits, with the confidentiality and undertakings drafted in; and
  • running the response when a breach has happened — letter of demand, urgent injunction application, and the substantive claim that follows.

The earlier the contractual and policy layer is in place, the cheaper the response layer is when the firm needs to use it.

The contractual layer that goes beyond the common law

The contractual layer is what gives the business reach beyond the common law. The common law and the Corporations Act protect a narrow band of genuinely secret information; a well-drafted clause, supported by sensible labelling and access controls, protects the much wider band of information the business actually relies on.

Workplace confidentiality runs on three sources of obligation — contract, common law, and statute — that overlap but do not duplicate each other. The contract defines the scope and duration; the common law catches trade secrets even without a clause; and s 183 of the Corporations Act picks up improper use of information by current and former officers and employees. The information needs to have a genuinely confidential character, be communicated in confidence, and carry commercial value because it is confidential. During employment, the controls are mostly preventative — access restriction, device policy, and lawful surveillance. After employment, the contractual clause does most of the heavy lifting, supported by an exit process that returns property and re-states the obligation. When a breach happens, the standard escalation is letter of demand, interlocutory injunction, and substantive proceedings for damages or an account of profits.