When a business says it wants to "protect confidential information", it is usually pointing at three different things at once: a category of information, a set of legal duties that attach to that information, and a stack of contractual and policy mechanisms that make those duties enforceable in practice. The legal duties exist whether or not you write anything down. The contractual mechanisms decide how cleanly you can enforce them when something goes wrong.
This article walks through what workplace confidentiality actually is in Australia, broken down into the parts an employer needs to handle distinctly:
- What counts as confidential information at law
- The duties employees owe without a written agreement
- The contractual layer (confidentiality clauses, non-competes, non-solicits)
- The policy and operational layer
- Where the duties end (resignation, exit, post-employment)
- A worked example pulling these threads together
- When to bring in a lawyer
What counts as confidential information
At general law, information is "confidential" if it has the necessary quality of confidence, was communicated in circumstances importing an obligation of confidence, and is being (or about to be) used in a way the discloser would object to. That is the equitable duty of confidence, and it sits underneath every employment relationship without needing to be drafted.
In a workplace, the category typically covers:
- Trade secrets — formulas, source code, manufacturing processes, algorithms, proprietary methods
- Commercial information — pricing models, margins, supplier terms, customer lists, pipeline data, financial accounts not in the public domain
- Strategic information — product roadmaps, M&A plans, marketing strategy, unreleased branding
- Personal information about employees, customers, or third parties (which also engages the Privacy Act 1988 (Cth) for most businesses with annual turnover above $3 million)
Two things are not confidential, no matter what a contract says. Information that is already public, and the employee's own general skill and knowledge built up over the course of their job. Australian courts will not let an employer use a confidentiality clause to lock down an employee's career capital. The line between "employer's confidential information" and "employee's general skill" is the single most contested issue in confidentiality disputes.
Duties employees owe without a written agreement
Even with no employment contract, an employee owes their employer:
- An implied duty of fidelity during employment — they cannot moonlight for a direct competitor, divert opportunities to themselves, or copy and remove confidential files for later use
- An equitable duty of confidence that survives the employment ending — they cannot use or disclose information they know is confidential, even after they leave
- Fiduciary duties if they are senior enough that the role carries discretion over the employer's interests (most commonly: directors, and some senior executives)
The practical limitation is that these duties are hard to prove and hard to scope. An equitable duty of confidence applies only to information that is genuinely confidential. If the employer cannot point to specific information, specific protections it took to keep that information confidential, and specific misuse, the claim collapses. This is why the contractual layer matters — not because the duties don't exist without it, but because the contract is what lets you prove the scope.
The contractual layer
A well-drafted employment contract gives an Australian employer three distinct levers, and it pays to understand them separately rather than lumping them together as "the confidentiality clause".
Confidentiality clause
Defines what counts as confidential information for the purposes of the contract, prohibits use and disclosure outside the role, and survives termination. The drafting choices that matter:
- A definition broad enough to cover the actual information the business holds, but specific enough that a court can identify what is captured. "All information the employee learns" is too broad; an itemised category list with examples is enforceable.
- Carve-outs for information already public, information the employee already knew, and information they are legally required to disclose (subpoena, regulator)
- A return-and-destroy obligation triggered by termination
- A survival clause that keeps the obligation alive after the employment ends
Non-solicitation clauses
Prevents a departing employee from approaching the employer's customers, suppliers, or other employees for a defined period. Courts treat these more favourably than non-competes because they are narrower — they protect a legitimate interest (customer relationships, workforce stability) without preventing the employee from working.
Non-compete clauses (restraints of trade)
Prevents a departing employee from working for a competitor or starting a competing business for a defined period in a defined area. These are presumed void at common law as an unreasonable restraint of trade. They are enforceable only to the extent they protect a legitimate business interest (confidential information, customer connection, goodwill) and only to the extent they are reasonable in scope, duration, and geography.
New South Wales has its own statutory overlay — the Restraints of Trade Act 1976 (NSW) — which lets a court read down an unreasonable restraint to the point where it would be reasonable, rather than striking it out entirely. Other states apply the common law position only: if the restraint as drafted is unreasonable, it falls in full unless it is written in clearly severable "cascading" tiers (e.g. 12 months / 6 months / 3 months across multiple geographic radii).
A reform note worth tracking: the Commonwealth Government has announced an intention to ban non-compete clauses for workers earning under the Fair Work Act high-income threshold (currently $183,100 from 1 July 2025), with reforms targeted to take effect from 2027. Treasury consultation closed in September 2025. The position for senior employees above the threshold is the same as it has always been. The position for everyone else is in flux.
The policy and operational layer
Contracts alone do not maintain confidentiality. They give you a cause of action when something goes wrong. Day-to-day protection is operational.
A confidentiality policy sets the standard for the workforce — what information is sensitive, how it should be handled, who can access what, what to do when something is leaked or lost. It works as a contractual document if the employment contract incorporates it by reference and uses promissory language ("the employee must comply with"), and as a managerial document either way.
The operational measures that matter most:
- Access controls — least-privilege defaults on systems, role-based permissions, MFA, audit logs
- A clean exit process — IT access revoked at the point of resignation announcement (not the last day), devices returned, cloud accounts cut, customer-facing handovers supervised
- Training on what to flag — phishing, social engineering, "innocent" requests from former employees for "just one file"
- A breach response playbook — who is told, in what order, when external counsel is engaged, when notification obligations under the Notifiable Data Breaches scheme are triggered
Employee records themselves are largely exempt from the Privacy Act where the record is directly related to the current or former employment relationship, but the exemption does not cover prospective employees who are not hired, third-party contractors handling employee data, or use of the record outside the employment relationship.
Where the duties end
The duties do not switch off on the last day. They reshape.
During employment. Full implied duty of fidelity, full equitable duty of confidence, contractual obligations on top. The strongest position for the employer.
At the point of resignation. The risk window opens. An employee on notice is still bound, but their incentive to comply slips. This is when bulk-download incidents happen — emailing client lists to personal addresses, copying files to USB, forwarding pipeline reports "to read at home". Most disputes that end up in court started in this window.
After termination. The implied duty of fidelity ends. The equitable duty of confidence continues, but only for genuinely confidential information — not general skill and knowledge. Contractual confidentiality clauses continue if drafted to survive. Non-solicitation and non-compete restraints run for their drafted period, subject to enforceability.
A worked example
A 25-person Sydney software business hires a senior account manager, Priya, on a $160,000 salary. Her contract contains:
- A confidentiality clause defining customer data, pricing, and the company's roadmap as confidential, surviving termination indefinitely
- A 12-month post-employment non-solicitation of customers she dealt with in the final 12 months
- A cascading non-compete: 12 months / 6 months / 3 months, across Australia / NSW / Sydney metropolitan
Eighteen months in, Priya resigns to join a direct competitor. In her final week she downloads a customer-pipeline export from the CRM to her personal Google Drive. Three months after she leaves, two of her former accounts terminate their contracts and sign with her new employer.
The employer's position:
- The download is a clear breach of the confidentiality clause and probably the equitable duty as well. Customer pipeline data is the textbook case of protectable confidential information. The action is straightforward: letter of demand, application for delivery-up and destruction of the data, and damages or an account of profits if the data has already been used.
- The non-solicitation of the two former accounts is the more contestable claim. The employer would need to show Priya actually approached them, that they were customers she dealt with in the relevant window, and that 12 months and the defined scope are reasonable. The strongest evidence here is contemporaneous — emails, LinkedIn messages, internal records at the new employer obtained via discovery.
- The non-compete is the weakest claim. A 12-month Australia-wide restraint on a $160,000 account manager is unlikely to be reasonable. The cascading drafting helps — a court in NSW could read it down to 3 months in Sydney metropolitan, and the proposed federal reforms would not catch Priya at $160,000 if they were in force, because she sits below the high-income threshold.
The lesson: the confidentiality clause does the real work. The non-solicit is the secondary layer. The non-compete is a deterrent that may or may not survive challenge — useful at the time of negotiation, less useful at the time of enforcement.
Where Artificer Legal can help
The confidentiality stack is one of the highest-leverage things a small-to-medium business can get right early, because the cost of fixing it later — after an employee has walked out with the customer list — is an order of magnitude higher than the cost of drafting it well at the start.
Artificer Legal typically works through the stack in this order:
- Audit what the business actually treats as confidential, and what it would lose if a competitor had it
- Map that against existing contracts (founders, employees, contractors) and policies
- Redraft the confidentiality, non-solicitation, and restraint clauses to match the legitimate interest being protected — not boilerplate
- Build a confidentiality policy and incorporate it into the contract
- Sit alongside the operational fixes (access controls, exit process) so the legal layer and the operational layer line up
- When something has already gone wrong, run the breach response — letter of demand, urgent injunctive relief if needed, evidence preservation, regulator notification if required
The work scales to the size of the business. A 5-person startup needs a tight set of templates and a sensible policy. A 200-person company with international hires needs a layered set of contracts, a confidentiality policy that interacts with privacy obligations, and a documented exit process. The principles are the same; the depth changes.
Closing the loop
Workplace confidentiality is not a single clause. It is a stack — equitable duties, contractual layers, operational controls, and a response plan — and each layer protects a slightly different surface area.
The category of confidential information needs to be defined narrowly enough to be enforceable and broadly enough to cover what the business actually holds. Employees already owe duties without a contract, but the contract is what makes those duties provable. The confidentiality clause does most of the post-employment work; non-solicitation is the practical second layer; non-compete clauses are the most contested and, for non-senior workers, are heading for statutory restriction. Operational controls — access, exit, training — keep the legal layer from ever needing to be used. And when it does need to be used, the early steps (letter of demand, evidence preservation, fast injunctive relief) matter more than the eventual judgment.