← Back to AI Legal Lab
Insight
Contract ReviewLegal Outsourcing

Managing Trade Secrets: "Confidential" Markings and Access Rights in Practice

Hello, I'm Noriaki Asato, Representative Attorney at Legal Agent.

Labeling a shared folder containing customer information "Confidential." Limiting access to technical materials to the development department. Exchanging confidentiality commitments with employees and contractors. Each of these is an important step to protect information, but the law does not require every company to adopt the same combination of measures.

In managing trade secrets, the starting point is to create a state in which the people who come into contact with the information can tell that "the company treats this information as secret." On that basis, you consider measures to prevent actual leaks and records that allow you to explain how the information was managed if a problem arises. In this column, I will look at shared drives, cloud services, and handling employee departures, while separating the legal requirements for protection from day-to-day management work.

The Three Requirements for Protection as a Trade Secret

Article 2, Paragraph 6 of the Unfair Competition Prevention Act (Japanese) requires that a trade secret be information that is managed as a secret, is useful for business activities, and is not publicly known. These are generally referred to as "secrecy management," "usefulness," and "non-public nature," respectively.

Customer lists, design drawings, cost information, and the like do not become trade secrets merely by virtue of their names. For example, a list compiling publicly available contact details and a database containing non-public transaction terms and sales negotiation histories differ in the content of the information to be examined. In a dispute, you need to identify what information you want to protect and examine the three requirements with respect to that information.

An internal classification of "Confidential" does not automatically determine the legal conclusion either. However, such a marking can be an important means of conveying the intention to treat the information as secret. In my view, it is equally inappropriate to think that a marking is meaningless and to think that a marking alone guarantees protection.

In addition, whether information constitutes a trade secret and whether you can seek an injunction or damages against a particular party are separate questions. You confirm whether the manner of acquisition, use, or disclosure constitutes "unfair competition" under the Act, and examine the respective requirements: for an injunction, infringement or threatened infringement of business interests; for damages, intent or negligence, damage, and so on.

The Core of Secrecy Management Is a State in Which the Information Is Recognizable as Secret

The Ministry of Economy, Trade and Industry's Trade Secret Management Guidelines (revised March 31, 2025) (Japanese) emphasize that the company's intention to manage information as secret should be clearly indicated through management measures and that employees and others should be able to recognize that intention. The guidelines are not rules that bind the courts, but they are an important reference when considering management methods.

What should be noted here is that "access restrictions" and "recognizability as secret" are not each required as independent mandatory conditions. Access restrictions are also one method of conveying that information is secret. As long as a state in which the information is recognizable as secret is maintained, insufficient access restrictions alone do not immediately negate secrecy management.

For example, at a company where all sales staff use customer data, everyone in that department may need viewing rights for business purposes. Rather than reaching a conclusion based on the number of people alone, you confirm whether the intention to treat the information as secret was conveyed through the scope of the target information, confidentiality markings, explanations of handling, internal rules, and so on. At a small company, circumstances such as the limited number of people in charge and clear sharing through oral explanations are also taken into account.

On the other hand, it is not enough if no management measures are taken and the information is merely considered important in the owner's mind. Also, if even published materials are indiscriminately marked "Strictly Confidential," it becomes difficult to tell the scope of the information that truly needs protection. It is important for internal rules to be specific enough that the people using the information can make concrete judgments.

Matching Markings, Access Rights, and Contracts to the Nature of the Information

When considering management methods, first write down "which information" is to be treated as secret, "with respect to whom," and "in what situations." Making the target specific, such as unreleased product specifications, customer-specific pricing terms, or acquisition negotiation materials, makes it easier to decide on the necessary markings and access settings.

For paper documents, possible measures include markings indicating confidentiality and the use of lockable storage. For electronic data, candidates include file and folder names, markings within documents, notices on system screens, passwords, and access rights. The specific examples in the guidelines (Japanese) set out an approach of choosing among such methods according to the nature of the information and the actual circumstances of the business.

From this, it does not follow that "information is not protected unless confidentiality markings, access restrictions, and a non-disclosure agreement are all in place." For example, the appropriate method differs between a case where handling is clearly conveyed by a confidentiality marking and a case where the information is managed on a system used only by specific people in charge. Combining multiple measures is beneficial, but it is important not to treat that combination itself as a uniform legal requirement.

In practice, you check not only how markings are applied but also whether the secret treatment carries over to copied files and excerpted materials. Even if the original folder is marked, if materials attached to an email bear no indication, the explanation to the recipient may be insufficient. When providing information to a business partner, confirm the subject matter, the purpose of use, and the conditions for onward provision both in the contract and in the actual method of sending.

As for internal rules and training, I think it is better not to stop at simply conveying that "you must not leak secrets." Showing what in which folders is covered, whose decision is needed for external sharing, and where to consult when in doubt leads to action on the ground.

Managing the Cloud and Employee Departures with Leak Prevention and Records in Mind

Information does not lose its character as a trade secret merely because it is stored in the cloud. The guidelines also contemplate the use of the cloud as one method of managing electronic information. What you want to check is not so much the name of the service you use as the sharing scope, the administrator settings, the explanations given to users, and the conditions for external provision.

For example, even if you think you have shared something only with internal members, the setting may allow "anyone with the link" to view it. In such a case, separate questions may arise beyond secrecy management, such as who was actually able to obtain the information and whether the information became publicly known. Rather than checking the settings screen once and stopping there, an operation of regularly cross-checking the list of external shares against the people in charge is necessary.

With respect to departing employees and contractors after the end of their contracts, the IT department alone may not be able to fully grasp the services in use. HR, business divisions, and administrative departments cooperate to check accounts, shared links, external invitations, copies on devices, API keys, and so on. Possible measures include adjusting access rights to match the departure date or the end date of the engagement, and recording the return or deletion of materials and the results of handover.

However, it cannot be concluded that secrecy management is automatically lost merely because the suspension of an account was temporarily delayed. The guidelines also distinguish between temporary lapses in management that do not significantly affect recognizability and a state in which management has become a mere formality. The legal evaluation depends on the specific circumstances, but the need to correct the situation promptly to reduce the actual risk of leaks remains unchanged.

In preparation for problems, keeping the version of the rules, the date they were communicated, training records, the history of access right changes, approval records for external sharing, and the like makes it easier to explain the state of affairs at the time. If logs are deleted or original files are overwritten after an investigation begins, verification becomes difficult, so I think it is a good idea to decide in advance what should be preserved and who is responsible.

The Scope of Protection Under an NDA and the Scope of Trade Secret Protection

A non-disclosure agreement (NDA) can define confidential information more broadly than trade secrets under the Unfair Competition Prevention Act. Even information that does not qualify as a legal trade secret may be protected in accordance with the terms of the contract. However, the requirements for a claim, such as a breach of contract and the occurrence of damage, must be confirmed separately.

Conversely, a broad definition in the contract does not make all information a trade secret under the Unfair Competition Prevention Act. An NDA can also serve as a means of conveying the intention to treat information as secret, but it is examined together with the content of the information and how it was handled at the time of disclosure. In relation to third parties who bear no contractual obligations, the types of acquisition, use, and disclosure prescribed by the Act and the knowledge of that third party, among other things, become the issues.

If you are going to start somewhere, I think it is a good idea to select a few types of particularly important information and summarize on a single page where they are stored, who uses them, how their confidentiality is communicated, the procedure for external sharing, and the person responsible for management. Check that content against your rules and NDAs, and fix any points that diverge from the actual settings. It is important not to aim solely at tightening management, but to clarify the scope of what is treated as secret while continuing the use necessary for business.

For reviewing contract provisions, please also see Reviewing Confidentiality Clauses in Practice, and for measures against competition by departing employees and others, The Practical Limits of Non-Compete Obligations.

Related articles

Articles connected to this topic.

Insight / 2026.10.03 Internal Use and Copyright: What to Check When Sharing Articles, Preparing Training Materials, and Using AI Summaries Insight / 2026.10.02 How to Draft a Data Provision Agreement: Scope of Use, AI Training, and Treatment on Termination Insight / 2026.09.28 Export Control Basics: What to Check Before Providing Technology Abroad and Deemed Exports

Services connected to this topic

Legal outsourcing Ongoing legal team support for contract review and legal operations.
View AI Legal Lab articles