Answer first: Trade secrets have become critical intangible assets in the EU, requiring active identification, governance, and integration with organisational culture and cybersecurity. This article explores the life cycle of trade secrets, the legal standard of reasonable steps as a proxy for good management, and sectoral variatio…
Patents context for IP teams
Trade secrets are increasingly vital assets that businesses must actively identify, govern, and maintain to preserve competitive advantage. Their importance has grown in the context of digitalisation, workforce mobility, open innovation, and the rising value of data, software, and processes. This article reframes trade secrets as a life cycle—from initial identification through eventual loss or release—and argues that the legal test of reasonable steps to protect secrecy functions best as a proxy for effective management rather than a mere checklist.
Across jurisdictions, trade secret law has converged on a core definition: information that is secret, has commercial value because it is secret, and is subject to reasonable steps to maintain secrecy. This tripartite test forms the global baseline, although enforcement mechanisms and remedies differ among countries.
Key takeaways for EU trade secrets law
- Confirm how the development affects patents ownership, enforcement, licensing, or portfolio records.
- Separate confirmed facts from legal interpretation before advising business teams.
- Map deadlines, affected assets, contracts, and evidence files to the responsible internal owner.
- Use the issue as a prompt for monitoring, filing strategy, dispute preparation, or member education.
Practical analysis
However, legal definitions only partially capture the nature of trade secrets. Unlike patents or copyrights, secrecy is not created by law but is a fundamental human behaviour applied in business contexts. The law primarily acts as a fallback when organisational management of secrecy fails. Trade secrets exist and are lost through organisational behaviour—how information is defined, who accesses it, how it is shared, and the seriousness with which secrecy norms are enforced. From this perspective, the requirement of reasonable steps is best understood as an indicator of good management rather than a formalistic standard. Furthermore, secrecy and openness are not mutually exclusive; they are dynamically combined. Effective trade secret management can align with openness strategies such as open science and open innovation.
In practice, trade secrets rarely stand alone. Firms typically combine them with patents, trademarks, design rights, and contracts, using each form of protection for different aspects of the same innovation. Their value lies not only in concealment but also in selective disclosure—sharing enough information to collaborate, commercialise, or comply with regulations while retaining control over the most valuable know-how, data, and processes. This interplay varies significantly by industry.
In the automotive and connected vehicle sectors, the combination of IP rights is shaped by data access and regulatory frameworks. Manufacturers may patent technical systems and control methods, protect brands and digital services through trademarks, and keep calibration data, testing methods, and integration knowledge as trade secrets. As users gain rights to access and share in-vehicle data, competitive advantage shifts toward systems, interpretation, and embedded knowledge that remain under firm control. This shift is reinforced by the EU Data Act, which will be discussed further.
In pharmaceuticals and biotechnology, patents often protect compounds, formulations, or therapeutic methods, while trade secrets cover manufacturing knowledge, process parameters, cell lines, and scale-up expertise. The most commercially valuable knowledge frequently lies not in the patent itself but in the practical ability to reproduce, refine, and manufacture at scale. The COVID-19 pandemic illustrated this dynamic, with a voluntary, time-limited non-enforcement pledge on patents for vaccines. The competitive edge resided in manufacturing knowledge and scale-up capacity, with patent enforcement and conflicts resuming after the pledge expired.
In software, particularly AI and software-as-a-service (SaaS) business models, formal IP rights play a more uneven role. Copyright protects code, and patents may cover certain technical inventions, but much of the commercial value lies in trade secrets related to data, model tuning, deployment, and internal workflows. Open-source software exemplifies this: firms may open code to accelerate adoption and ecosystem growth while retaining control over key knowledge, operational practices, and structured data assets. The EU Data Act similarly impacts this sector by expanding access to raw data, making it harder to rely on secrecy over the data itself. Competitive advantage may shift toward curated databases and structured datasets, especially where database rights or other controls apply. Managing openness and secrecy in a disciplined way is thus critical, with programmers playing a key role in developing procedures that balance these aspects.
Trade secrets offer several advantages: no registration fees, no examination delays, and no fixed term. Protection can last indefinitely if secrecy is maintained. For rapidly evolving technologies, algorithms, data sets, manufacturing processes, and business methods, this flexibility can be more attractive than patent protection. The scope of trade secrets is adaptable; matter can be added or partially published. This flexibility is most valuable when secrets are managed alongside other IP rights and supported by aligned organisational behaviour.
Trade secrets also facilitate collaboration. Research indicates that having trade secrets signals strength to potential partners similarly to patents. Clearly defined and protected secrets can be licensed, exchanged, and shared under controlled conditions. Trade secrets provide the foundation for contracts, non-disclosure agreements, and collaboration agreements. Unlike patents or trademarks, trade secret transactions typically involve transfer of control with continuing confidentiality obligations rather than outright assignment. For example, a contract may stipulate that the assignor will not use the secret but will maintain it, while the assignee manages it further.
The greatest risk to trade secrets rarely comes from external espionage; instead, current or former employees are the main vectors of loss. Information leaks occur through routine work, job changes, and informal conversations. Consequently, people management is a critical component of trade secret protection. Research shows that positive incentives are more effective than punitive contractual threats or overly strict non-compete clauses.
Labour mobility is socially valuable and often encouraged by policymakers. Major technology hubs, such as Silicon Valley, rely on spillover effects where knowledge sharing through employee movement fosters innovation. However, workforce mobility creates persistent tension for firms dependent on confidential information. It is increasingly difficult to delineate an employee’s general competence from an employer’s trade secrets, particularly in digital and data-driven environments.
Digital transformation has amplified both the value and vulnerability of trade secrets. Centralised data, cloud services, and remote work expand the attack surface. Human behaviour remains the weakest link, making alignment of trade secret management with people management a best practice that also supports cybersecurity. Concerns about AI disclosing trade secrets are nuanced; many past disclosures resulted from human error, such as misconfigured servers accessible via search engines. A new challenge posed by AI is that the first element of the trade secret test—information being secret—is nuanced. Secrecy does not require absolute novelty but that the information is not generally known within relevant circles. AI technologies increasingly make more information generally known and widely available across commercial sectors.
Because trade secrets are unregistered, proving their existence, scope, and misappropriation is inherently difficult. Courts scrutinise whether information was genuinely secret and whether reasonable steps were taken to protect it. Poor documentation and inconsistent practices undermine enforcement. For technology-based secrets, patent attorneys are often adept at documenting essential features. For commercial secrets, auditors may assist, and accounting perspectives can be useful when reflecting the value of IP, including trade secrets, on balance sheets.
Reasonable steps have become the fulcrum of trade secret protection. Courts interpret these steps contextually, considering industry norms, company size, and the nature of the information. Effective protection depends on integrated organisational, legal, and technical measures. Employees must be able to recognise what information is secret and understand their role in protecting it. Secrecy is a learned behaviour and an integral part of organisational culture.
Related IIPLA reading
EU Trade Secrets Law: Integrating Legal Protection with Organisational Strategy Amid Digital and Regulatory Shifts Trade secrets have become critical intangible assets in the EU, requiring active identification, governance, and integration with organisational culture and cybersecurity. This article explores the life cycle of trade s... Read the full IIPLA blog post: https://iipla.org/blog/eu-trade-secrets-law-integrating-legal-protection-with-organisational-strategy-amid-digital-and-regulatory-shifts