NDA breach by an ex-employee — your enforcement optionsEnforcing a non-disclosure obligation against a departed employee in India runs on five parallel tracks. The contractual route — damages under Section 73 and liquidated damages under Section 74 of the Indian Contract Act, 1872, plus a negative-covenant injunction under Section 42 of the Specific Relief Act, 1963. The common-law breach-of-confidence route — the three-element test in Coco v A N Clark (Engineers) Ltd, [1969] RPC 41 received into India through John Richard Brady Five tracks — Contract Act damages, SpecificRelief Act injunction
[ Everyday Law ]

NDA breach by an ex-employee — your enforcement options

When an employer discovers that a departed employee has taken away source code, a customer database, a pricing matrix, or a product-roadmap document and is using it for a competitor or for her own venture, the enforcement architecture in India runs on five parallel tracks — and the choice between them is shaped by what was taken, who took it, and what relief is wanted. The contractual track relies on Sections 73 and 74 of the Indian Contract Act, 1872 and on Section 42 of the Specific Relief Act, 1963 for the negative-covenant injunction. The breach-of-confidence track, drawn from Saltman Engineering Co Ltd v Campbell Engineering Co Ltd, [1948] 65 RPC 203 and Coco v A N Clark (Engineers) Ltd, [1969] RPC 41, has been received into India through John Richard Brady v Chemical Process Equipment (P) Ltd, AIR 1987 Del 372, Burlington Home Shopping Pvt Ltd v Rajnish Chibber, (1995) 61 DLT 6 and Diljeet Titus, Advocate v Alfred A Adebare, (2006) 130 DLT 330. The intellectual-property overlay supplies copyright protection for literary works, design protection for registered designs, and passing-off protection for unregistered trade marks. The Information Technology Act, 2000 supplies a civil and criminal layer for electronic material — Sections 43, 65, 66, 72 and 72A. The Bharatiya Nyaya Sanhita, 2023 supplies the criminal-law backstop through Sections 314, 318 and 319.

India has no dedicated trade-secrets statute. What the law supplies instead is a layered architecture — contractual, equitable, statutory and criminal — through which a non-disclosure obligation against a former employee is enforced. The architecture is not always understood as layered, which is why an employer's first response to a discovered breach is often a generic civil suit framed only as a contract-of-employment claim. The more precise response identifies the categories of information taken, maps each to the statute that protects it most effectively, and packages the relief as a combination of injunction, damages and (where the facts cross the criminal threshold) a complaint under the Bharatiya Nagarik Suraksha Sanhita, 2023. This article walks the five tracks and the practical join-points — what an interim injunction looks like, how the springboard doctrine operates, and where the criminal complaint actually goes.

The law in plain English — what an NDA actually does in India

A non-disclosure agreement in India operates on two parallel juristic bases. The first is the express contractual obligation — the agreement itself, signed by the employee at the start of the employment, identifying defined categories of confidential information and imposing a contractual duty of non-disclosure and non-use during and after the term. The second is the equitable duty of confidence — which arises by operation of law from the relationship between the employer and a senior employee, and exists independently of any written NDA. The duty of confidence is the older root and remains the more flexible remedy — it applies even where the written NDA is silent on a particular category of information, or where the employee never signed an NDA at all.

The contractual obligation gives the employer access to Sections 73, 74 and 75 of the Indian Contract Act, 1872 — Section 73 for compensation for loss or damage caused by the breach, Section 74 for reasonable compensation up to the liquidated-damages amount stipulated in the contract, Section 75 for compensation when the contract has been rescinded for breach. The contractual obligation also gives access to Section 42 of the Specific Relief Act, 1963, which preserves the court's power to grant an injunction restraining the breach of a negative covenant even where the affirmative side of the contract is not specifically enforceable. This is the doorway through which an employer obtains an injunction restraining further use or disclosure of confidential information by a former employee.

The equitable duty of confidence — drawn from the line in Saltman Engineering Co Ltd v Campbell Engineering Co Ltd, [1948] 65 RPC 203 — supplies a remedy in three classes of case in which the contractual route is weak. First, where the information taken is not specifically identified in the NDA but is plainly confidential from the circumstances. Second, where the obligation arises from the relationship itself rather than from an express clause — the duty of fidelity of a senior employee, the lawyer-client relationship, the director's fiduciary duty. Third, where the breach is by a third party who received the information knowing of its confidential character (the principle of third-party confidence). The Delhi High Court in John Richard Brady v Chemical Process Equipment (P) Ltd, AIR 1987 Del 372 confirmed that the equitable doctrine of confidence operates in Indian law independently of any contractual nexus.

The Coco v Clark three-element test — received into India

The operating test for whether an obligation of confidence has arisen is the three-element test laid down by Megarry J in Coco v A N Clark (Engineers) Ltd, [1969] RPC 41 — adopted by the Delhi High Court and applied across the High Courts that have decided trade-secret matters. The three elements are: first, the information must have the necessary quality of confidence about it — that is, it must not be something in the public domain or something an employee is free to take with her as part of her general skill and knowledge; second, the information must have been imparted in circumstances importing an obligation of confidence — typically the employment relationship, but also negotiations in contemplation of a contract; third, there must be an unauthorised use of that information to the detriment of the party who imparted it. Where all three are satisfied, the court grants relief — an injunction restraining further use or disclosure, an order for delivery-up of the materials, and an account of profits or damages.

The application of Coco v Clark in Indian decisions has been substantial. John Richard Brady v Chemical Process Equipment (P) Ltd, AIR 1987 Del 372 applied the doctrine to know-how and drawings received in commercial negotiations and granted an injunction notwithstanding the absence of a concluded contract. Burlington Home Shopping Pvt Ltd v Rajnish Chibber, (1995) 61 DLT 6 applied the doctrine to a customer database compiled by an employer and protected it against use by the defendant, who had been an employee of the plaintiff. Diljeet Titus, Advocate v Alfred A Adebare, (2006) 130 DLT 330 applied the doctrine to a law firm's client-base and case-records — the Delhi High Court restrained the departing partner from soliciting the firm's clients and using its case-data; the case has become a leading authority on confidence-protection in professional-services firms. Bombay Dyeing & Manufacturing Co Ltd v Mehar Karan Singh, (2010) 112 Bom LR 3759 — Bombay High Court — collected the Indian and English authorities and laid out an operating framework that is now routinely cited in interim-injunction applications.

The doctrine has one important limit that the Indian decisions have been careful to mark — the protection does not extend to the general skill, experience and know-how that an employee acquires in the course of her employment and carries with her on leaving. This is the line drawn in American Express Bank Ltd v Priya Puri, (2006) 110 FLR 1061 — Krishna J, Delhi High Court — holding that information that has become part of the employee's general professional capability is not "trade-secret" material whose use can be enjoined. The line between confidential information and general skill is fact-specific, and Indian decisions have, in keeping with the English line, leaned protective of the employee's right to take her experience to the next employer.

The springboard doctrine and the quia-timet injunction

Where the employee has taken confidential information but has not yet used it, the law supplies two related tools. The springboard doctrine — drawn from the English authorities and adopted into the Indian breach-of-confidence line — restrains the misuse of confidential information even after the information has become public, on the rationale that the wrongdoer must not be allowed to use the confidential information as a "springboard" to gain a head-start over the employer. The doctrine is most useful where the information would become public over time (a soon-to-be-launched product, a forthcoming financial result) but has been used by the defendant in the window before public disclosure. The Delhi High Court applied the springboard doctrine in Mr Anil Gupta v Mr Kunal Dasgupta, (2002) 25 PTC 1 (Del) — the concept-and-format for a television series, disclosed under an obligation of confidence, could not be used by the defendant for his own production even after the format gained currency.

The quia-timet injunction — an injunction in anticipation of a threatened breach, granted before any breach has occurred — is the second tool. Sections 38 and 39 of the Specific Relief Act, 1963 supply the statutory basis for a perpetual or mandatory injunction; Section 41 enumerates the cases in which an injunction cannot be granted (and is a critical filter on quia-timet relief). The employer who has discovered preparatory acts by a departing employee — copying files to a personal device, organising a competing venture during the notice period, contacting customers in anticipation of departure — can move the court for a quia-timet injunction restraining the threatened breach. The relief is interim in the first instance, granted on the standard balance-of-convenience and prima-facie-case tests. Speed matters: the longer the delay between discovery and approach to court, the harder the case for emergency relief.

The IT Act 2000 — civil and criminal teeth for electronic material

Almost all modern NDA breaches involve electronic material — files copied to a personal laptop or a USB drive, source code pushed to a personal repository, customer lists e-mailed to a personal address. The Information Technology Act, 2000 supplies a parallel layer of remedies that runs alongside the contractual and breach-of-confidence tracks.

Section 43 of the Information Technology Act, 2000 imposes civil liability — compensation by way of damages — on any person who, without permission of the owner or person-in-charge of a computer, computer system or computer network, accesses or downloads, copies or extracts any data, computer database or information held in any removable storage medium. The clause-by-clause structure of Section 43(a) to (j) covers unauthorised access, downloading, virus introduction, damage, disruption, denial-of-access, assistance to enable contravention, charging for services on another's account, destruction of source code, and stealing or concealing source code. Compensation under Section 43 is adjudicated by the adjudicating officer appointed under Section 46 — no monetary cap operates under the post-2008-amendment provision. Section 43A imposes liability on a body corporate that, possessing sensitive personal data, fails to implement reasonable security practices — a separate cause of action against the employer's competitor where the competitor has received sensitive personal data from the departed employee.

Section 66 of the IT Act, 2000 is the criminal-law analogue of Section 43 — any person who, dishonestly or fraudulently, does any act referred to in Section 43 is punishable with imprisonment up to three years or with fine up to five lakh rupees or with both. The Section 66 path requires proof of mens rea (dishonestly or fraudulently, as defined under the old IPC and now retained under the BNS) — the simple downloading of data without bad intent does not cross the Section 66 threshold and remains civil-only under Section 43. Section 65 makes a separate offence of tampering with computer source code where the source code is required by law to be kept or maintained — a narrower provision but useful in cases involving deletion of audit trails or system logs.

Section 72 of the IT Act, 2000 is the breach-of-confidentiality provision — any person who, having secured access to any electronic record, book, register, correspondence, information, document or other material in pursuance of any of the powers conferred under the Act and its rules, discloses such material to any other person without consent, is punishable with imprisonment up to two years or fine up to one lakh rupees or both. Section 72A — inserted by the 2008 amendment — extends the same logic to any person, including an intermediary, who, while providing services under a lawful contract, discloses material containing personal information without consent and with intent to cause or knowing it likely to cause wrongful loss or wrongful gain — punishable with imprisonment up to three years or fine up to five lakh rupees or both. Section 72A is the most useful single provision for an employer pursuing a former employee who has disclosed customer-personal-data to a competitor — it does not require proof that the data was a trade secret, only that it was personal information disclosed in breach of a lawful contract.

Section 66B of the IT Act, 2000 supplements the criminal route where the employee has dishonestly received or retained stolen computer resources or communication devices — the section's commentary expressly contemplates the "rogue employees often resign without giving notice and often do not return back these communication devices" scenario, and brings the dishonest retention of company-issued laptops and phones within the criminal penalty.

The criminal-law overlay — BNS 2023 and BNSS 2023

Where the facts cross the dishonest-intent threshold, the criminal-law overlay supplies prosecutable offences under the Bharatiya Nyaya Sanhita, 2023, prosecuted through the Bharatiya Nagarik Suraksha Sanhita, 2023. The three most-used provisions are these.

Section 314 of the BNS, 2023 — criminal breach of trust — punishes any person, being in any manner entrusted with property or with any dominion over property, who dishonestly misappropriates or converts to her own use that property, or dishonestly uses or disposes of that property in violation of any direction of law prescribing the mode in which such trust is to be discharged, or of any legal contract, express or implied, which she has made touching the discharge of such trust. The classical "confidential information" itself is not "property" for purposes of Section 314 in every High Court reading — the issue is somewhat unsettled — but tangible documents, devices, source-code-bearing media, customer-list printouts and database backups are property, and their dishonest misappropriation by an employee who was entrusted with them attracts Section 314.

Section 318 of the BNS, 2023 — cheating — applies where the employee, by deception practised at the time of hiring or during the employment, dishonestly induced the employer to part with property or to do or omit to do anything which the employer would not otherwise have done or omitted. The path is narrow — it requires proof that the deception preceded the parting with property — and is most often used where the employee was hired specifically to access and remove confidential information, against a back-drop of false representations at hiring. Section 319 BNS supplies the cheating-by-personation offence; less commonly used in NDA cases.

The investigative gateway is Section 173 of the BNSS, 2023 (the BNSS successor to Section 154 CrPC) for the recording of information about a cognizable offence and Section 175 of the BNSS, 2023 (the successor to Section 156(3) CrPC) for the magistrate's order to investigate. The employer's first criminal step is a written complaint to the local police station identifying the property misappropriated, the dishonest intent, and the supporting digital trail (e-mail logs, access logs, USB-mount records). Where the police refuse to register an FIR, the Section 175 BNSS application moves the magistrate. The Supreme Court's guidance in Lalita Kumari v Govt of UP, (2014) 2 SCC 1 — that an FIR must be registered where the information discloses a cognizable offence — applies to BNSS 173 in identical terms.

The intellectual-property overlay — copyright, designs, passing-off

Three IP statutes sometimes supply an additional foothold. The Copyright Act, 1957 — particularly Sections 13, 14 and 17 — confers copyright on original literary, dramatic, musical and artistic works including computer programmes (a "literary work" under Section 2(o) read with Section 13). Section 17(c) makes the employer the first owner of copyright in a work made by an employee in the course of employment. Source code, software documentation, training materials, original databases (qua "compilations" with sufficient skill and effort) all attract copyright. The departed employee who uses or further distributes such material commits infringement under Section 51 — and the employer can sue for an injunction, damages, and an account of profits. The advantage of the copyright route is that it does not depend on confidentiality; even publicly-disclosed copyrighted material is protected against unauthorised reproduction.

The Designs Act, 2000 protects registered designs — the shape, configuration, pattern or ornamentation of an article. Section 22 makes piracy of a registered design actionable. Where the departed employee carries away product-design files and uses them for a competing product, the registered-design route supplies a remedy independent of the breach-of-confidence track. Where the design is not registered, passing-off under Section 27 of the Trade Marks Act, 1999 may supply a parallel route for product get-up — passing-off operates on the goodwill the employer has built up, and the departed employee's use of confusingly-similar get-up for a competing product is actionable.

The IP overlay is most useful where the material taken is itself susceptible of IP protection — source code (copyright), product designs (design or copyright), customer-lists structured as databases (copyright in the compilation), original written manuals and training materials (copyright). It supplies a self-standing cause of action that does not depend on proving that the material was a trade secret or that the NDA covered it. For source code in particular, copyright and IT Act 2000 Section 65 in combination supply the cleanest set of remedies.

Step by step — what the employer does in the first seventy-two hours

The investigative-and-litigation playbook in the first seventy-two hours after a suspected NDA breach is settled. First — preserve the digital trail. Take a forensic image of the departed employee's laptop, mobile device and e-mail account. Pull the access logs from the document-management system, the version-control system (Git, SVN), the customer-relationship management system. Identify what was accessed, copied or e-mailed in the thirty days preceding departure. Engage a forensic vendor — the chain-of-custody record will matter for civil and criminal proceedings.

Second — send a legal notice. The notice should be specific: identify the categories of confidential information taken (or reasonably believed to be taken), call out the contractual and confidence obligations breached, demand return of all materials and devices, demand an undertaking not to use or disclose, and reserve the right to civil and criminal action. The notice is a procedural prerequisite for an injunction application — courts expect to see that the breach was first put to the defendant.

Third — file an interim-injunction application. The civil suit is for a permanent injunction under Sections 38 and 39 of the Specific Relief Act, 1963 read with the negative-covenant power in Section 42; the interim application is for an ad-interim and a temporary injunction under Order XXXIX Rules 1 and 2 of the Code of Civil Procedure, 1908. The relief sought includes: restraint on use or disclosure of identified categories of confidential information; restraint on solicitation of identified categories of customers; order for delivery-up of materials and devices; appointment of a court commissioner to take inventory and a forensic image. Where the new employer is on notice of the confidentiality, it can be joined as a co-defendant on the third-party-confidence doctrine.

Fourth — assess the criminal route. Where the facts disclose dishonest misappropriation of property (devices, documents, hard copies), or dishonest disclosure of personal information of customers by an employee with lawful access, the BNS 2023 Section 314 and IT Act 2000 Section 72A complaint should be filed in parallel under BNSS 2023 Section 173. The criminal complaint should be filed close in time to the civil suit — late filing invites the inference that the criminal route is being used to coerce a civil settlement, an inference the Supreme Court has consistently disapproved (see the State of Haryana v Bhajan Lal, 1992 Supp (1) SCC 335 line).

Watch for — the points at which breach-of-confidence claims fail

The points at which breach-of-confidence claims fail in Indian courts are predictable. The first is failure to identify the confidential information with specificity. A claim that the defendant has taken "confidential information of the plaintiff" without identifying which information, which categories, and what its specific commercial value is, is dismissed at the interim stage. The Delhi High Court's reasoning in American Express Bank Ltd v Priya Puri, (2006) 110 FLR 1061 turned in significant part on the bank's inability to identify what specifically was confidential as against the general client-handling skill the employee had built up over the years. The second is failure to keep the information confidential in the first place. Information that has been disclosed at conferences, published on the company website, shared with third parties without confidentiality protections, or is routinely shared internally without need-to-know controls, loses its quality of confidence and falls outside the Coco v Clark test.

The third is overreach in the relief sought. An injunction application that asks the court to restrain the former employee from working in the industry at all, or from using any skill she acquired during the employment, will fail on the Section 27 Contract Act analysis (see the companion article on non-compete enforceability) and on the right-to-livelihood reading of Article 19(1)(g) of the Constitution. The relief must be narrowly tailored — restraint on use of identified categories of confidential information, not restraint on competing. The fourth is delay. Equitable relief is discretionary; an employer who has known of the breach for months before approaching the court has weakened the case for emergency relief. The Indian courts apply the doctrine of laches with rigour at the interim stage.

Where things go wrong — the four most common failures

The four enforcement failures that produce the most disappointing outcomes are these.

Treating the NDA as if it were a non-compete clause. The employer who frames the claim as "the employee has joined a competitor in breach of her NDA" is on Section 27 ground — and on that ground the post-termination restraint is void. The framing must be "the employee has taken and is using identified confidential information of the plaintiff in breach of her contractual and equitable obligations of confidence" — that framing is enforceable, and is what the courts in Burlington Home Shopping and Diljeet Titus protected.

Letting the digital trail go cold. The single highest-leverage piece of evidence in an NDA case is the access-log-and-forensic-image record from the seventy-two hours before the employee's last working day. Employers who do not preserve this record at the time of departure are left with circumstantial evidence and lose the interim application. The forensic preservation has to happen at exit, not at discovery of breach weeks later.

Skipping the legal notice and rushing to court. Courts expect to see the breach put to the defendant and a reasonable opportunity given to respond before injunctive relief is sought. The employer who files the suit and the interim application on the same day, without a prior notice, encounters resistance even where the merits are strong. The legal notice can be brief — three to seven days, depending on urgency — but its absence is a real procedural deficit.

Misframing the criminal complaint. A criminal complaint that alleges merely that the employee has taken "confidential information" without identifying the property entrusted, the dishonest misappropriation, and the supporting digital evidence will be returned by the magistrate or refused by the police. The complaint should be drafted in the language of BNS 2023 Section 314 (entrustment + dishonest misappropriation) and IT Act 2000 Section 72A (lawful contract + disclosure of personal information + intent to cause wrongful loss/gain), with the digital trail attached. A vaguely-drafted complaint produces a refusal-to-register, which then has to be challenged under BNSS 2023 Section 175 — a delay the employer cannot afford.

Outcome — what the architecture actually delivers

The five-track architecture delivers, in practice, a layered package: an interim injunction restraining further use or disclosure of identified confidential information (Specific Relief Act, 1963 Section 42 read with breach-of-confidence doctrine); an order for delivery-up of materials and devices; damages assessed on the Contract Act Section 73 measure plus Section 74 liquidated damages capped at a reasonable sum; copyright-infringement relief where the material taken is copyrighted (Copyright Act, 1957 Section 51); compensation under the IT Act 2000 Section 43 for unauthorised data download adjudicated by the adjudicating officer; criminal proceedings under BNS 2023 Section 314 and IT Act 2000 Section 72A where the dishonest-intent threshold is met. The competing employer can be joined as a co-defendant on the third-party-confidence doctrine where it is on notice.

What the architecture does not deliver — and what the employer must accept — is restraint on the former employee's right to work in the industry, on the general skill and experience she has built up, or on customer-contact she has built up over the course of the employment. The Section 27 line in Krishan Murgai and Percept D'Mark closes that route, and the right-to-livelihood reading in American Express Bank v Priya Puri reinforces it. The genuine protection sits on the confidential-information side, not on the competing-activity side — and this is the matter to which the drafting and the litigation strategy should be directed.

The unresolved questions are at the edges. Whether confidential information itself qualifies as "property" for purposes of BNS 2023 Section 314 (criminal breach of trust) is contested across High Courts — the safer route is to anchor the criminal complaint on tangible materials (devices, documents, source-code-bearing media) rather than on the abstract information. The proper measure of damages in a confidence-breach case — particularly where the misuse has produced no measurable revenue loss — remains under-developed in Indian decisions; courts have tended to award nominal damages on the breach-of-confidence side, with the substantial relief delivered through the injunction. Until those points are settled, the operating playbook is the five-track architecture above — preserve, notice, sue, prosecute — applied at speed.