Skip to main content

Trade Secrets, NDAs, and the Employee Exit Checklist for Small Businesses

Published 12 min readMike ThriftMike Thrift
Trade Secrets, NDAs, and the Employee Exit Checklist for Small Businesses
On this page

Every time an employee resigns, your most valuable assets walk toward the door with them: the client list with five years of buying history, the pricing sheet that took three painful years to calibrate, the supplier terms nobody else in your market gets. Surveys of departing workers consistently find that a majority admit to taking company data with them — one widely cited survey put the figure at 59 percent of ex-employees, and another found that 87 percent take at least the data they created on the job. As many as 72 percent of departing employees admit to taking company data, and an estimated 70 percent of intellectual property theft happens within the 90 days before the resignation announcement.

Here is the part that should worry you most: if you have not taken specific, documented steps to protect that information, the law may agree with the departing employee that it was never a secret at all. Trade secret protection is not automatic. It is earned through reasonable measures — agreements signed at hire, access controls, and an exit process that treats every departure as a handoff, not a farewell. This guide covers what counts as a trade secret, how to write NDAs that hold up, and the exit checklist that protects a small business every time someone leaves.

What Actually Counts as a Trade Secret​

Trade secrets are protected at the federal level by the Defend Trade Secrets Act of 2016 (DTSA), which lets owners sue in federal court, and in nearly every state by some version of the Uniform Trade Secrets Act (UTSA). Both frameworks ask the same three questions before they will protect your information:

  1. Is it actually secret? The information must not be generally known to, or readily ascertainable by, your competitors. A list of local restaurants compiled from a public directory is not a trade secret. Your annotated version — who orders what, at what margin, through which contact, on which cycle — can be.
  2. Does it derive independent economic value from being secret? You must be able to explain why the information is worth more because competitors do not have it. Pricing formulas, customer buying patterns, supplier discounts, and proprietary processes all clear this bar easily.
  3. Have you taken reasonable measures to keep it secret? This is the question that decides most cases, and the one small businesses fail most often. Passwords, need-to-know access, confidentiality markings, signed agreements, and exit procedures are the evidence courts look for.

For a small business, the most common trade secrets are unglamorous: the client list with contact histories and preferences, the bid calculator, the recipe or process, the marketing playbook that actually converts, the supplier price list, and the software customizations you paid a developer to build. None of them needs to be patentable or even particularly clever. It needs to be valuable, secret, and treated as secret.

One nuance worth knowing: a departing employee is generally free to use their own general skills and knowledge at a new job. What they cannot take is your proprietary information — the specific data and compilations that belong to the business. The clearer the line you draw between those two categories in your agreements and your systems, the easier that line is to defend.

Reasonable Measures Are Where Small Businesses Win or Lose​

Most trade secret disputes never reach the question of whether the information was valuable. They are decided on what the owner did to protect it. If every employee could download the full client list, nobody signed a confidentiality agreement, and nothing was ever marked confidential, a court can conclude the information was not a trade secret — no matter how damaging its loss feels.

The good news is that reasonable measures do not require an enterprise security budget. They require consistency and documentation:

  • Limit access on a need-to-know basis. The delivery driver does not need the full customer database. The bookkeeper does not need the bid calculator. Every permission you narrow is evidence that you treated the information as confidential.
  • Mark it. Label sensitive documents and folders as confidential. A "Confidential — Internal Use Only" header costs nothing and signals to employees and courts alike that the contents are protected.
  • Put agreements in place before access, not after. Confidentiality obligations should be signed at hire, before the employee ever sees the client list — not improvised during the exit interview.
  • Control the copies. Know where sensitive files live, who can export them, and whether anyone can sync them to a personal device. A client list that lives in one salesperson's personal phone contacts is barely yours at all.
  • Document everything. Keep signed agreements on file, keep access logs, keep dated versions of key compilations. If you ever need to prove what the secret was and who could see it, your records are your case.

Think of it as a habit rather than a project. Each measure is small; together, they are the difference between "our former employee stole our client list" and "our former employee stole our documented, access-controlled, agreement-protected trade secret."

NDAs That Actually Hold Up​

A nondisclosure agreement is the backbone of trade secret protection, but only if it is written to be enforced rather than to intimidate. An overbroad NDA that claims everything the employee ever sees is confidential, forever, worldwide, is the kind courts narrow or refuse to enforce. A focused one survives. Every small-business NDA should cover these elements:

  • A clear definition of confidential information. Name the categories: customer lists and histories, pricing and margins, supplier terms, business processes, financial data, software and technical information. Specificity beats blanket claims.
  • The employee's obligations. Not to disclose, copy, or use confidential information except for company business, during and after employment.
  • A defined duration. Confidentiality for general business information typically runs one to three years after departure; true trade secrets can be protected for as long as they remain secret. State the distinction.
  • Return of materials. An explicit duty to return or delete all company information — including copies on personal devices — when employment ends.
  • Remedies. Acknowledge that a breach causes harm that money alone may not fix, preserving your ability to seek a court order stopping further disclosure.

The One Paragraph Most Small-Business NDAs Are Missing​

The DTSA requires employers to give employees notice of whistleblower immunity — the right to disclose trade secrets in confidence to government officials to report a suspected violation of law, or under seal in a lawsuit — in any contract governing the use of trade secrets or confidential information. The requirement covers contractors and consultants too, since the statute defines "employee" broadly.

The penalty for omitting it is precise and painful: without the notice, you cannot recover exemplary damages of up to twice the actual damages, or attorneys' fees, under the DTSA against that employee. The notice itself is a single paragraph, and the statute lets you satisfy the requirement with a cross-reference to a policy document given to the employee that sets out your reporting policy. There is no reason to leave the enhanced remedies on the table over one paragraph. If your current NDA template predates 2016, assume it lacks the notice and update it.

A Note on Noncompetes​

NDAs are not noncompetes, and the distinction matters more than ever. A noncompete restricts where someone can work; an NDA restricts what information they can use. Noncompete enforcement varies widely by state — several states sharply limit or ban them for most workers — while well-drafted NDAs are enforceable nationwide. For most small businesses, the practical stack is a solid NDA plus, where your state allows it, a narrowly drawn nonsolicitation clause covering the customers the employee actually served. Have local counsel review the combination; employment law is state-specific, and a template downloaded from another jurisdiction is a gamble.

The 90-Day Window Before a Resignation​

Because most insider data theft happens in the months before the departure is announced, protection starts before anyone gives notice. You cannot — and should not — treat every employee as a suspect. But you can build routines that make quiet exfiltration difficult:

  • Audit access periodically. Review who has administrative or export rights to your CRM, accounting system, file storage, and email. Revoke what each role no longer needs.
  • Watch for bulk exports. Many cloud tools log large downloads and forwarding rules. A sudden spike in exports from one account in the weeks before a resignation is the classic pattern.
  • Keep personal devices out of the loop. If employees access company data from personal phones or laptops, use a written bring-your-own-device policy that requires company data to stay in managed apps you can remotely wipe.
  • Separate the person from the relationships. If one employee is the sole relationship-holder for key accounts, your client list is only half the exposure — the relationships walk out too. Introduce backup contacts to major accounts as standard practice.

None of this requires surveillance software or suspicion. It requires treating access as something granted for a role and reviewed on a schedule, rather than something accumulated forever.

The Exit Checklist: Run It the Same Way Every Time​

Consistency is the point. A checklist you run for every departure — friendly or not — protects information and creates a paper trail showing you did. Adapt this to your business and run it start to finish each time:

  1. Revoke access on the last day, not the week after. Disable logins, VPN, email, CRM, accounting, file storage, and any shared accounts the moment employment ends. Remove their multi-factor registrations and rotate shared passwords and API keys they knew.
  2. Collect company property and confirm return of data. Laptops, phones, keys, badges, and documents — plus a written confirmation that they have returned or deleted all company information, including copies on personal devices and personal cloud storage.
  3. Hold the exit interview and restate obligations in writing. Remind the departing employee of their confidentiality duties, what information is covered, and that the obligations survive departure. Get a signed acknowledgment. This is a reminder, not a negotiation — the agreement was signed at hire.
  4. Reassign client relationships immediately. Personally introduce the replacement contact to key accounts within days. Clients who hear from you first stay yours; clients who hear from your former employee first are already being courted.
  5. Review what they accessed. Check audit logs for unusual downloads, exports, or forwarding rules in their final weeks. If you find something concerning, preserve the evidence before accounts are deleted — consult counsel about a litigation hold rather than improvising.
  6. Close out payroll and benefits cleanly. Deliver final pay on your state's required timeline, provide any required benefits notices, and document everything. A sloppy final paycheck is how an amicable departure turns adversarial.
  7. Update your own records. Note the departure date, access revocation date, property returned, and acknowledgment signed. File it with the employee's agreement. This file is what proves your reasonable measures if it ever matters.

For contractors and consultants, run the same list — access, property, data return, acknowledgment — at the end of every engagement, not just employment relationships. The DTSA's notice requirement applies to them precisely because they so often hold the keys to sensitive systems.

Mistakes That Quietly Destroy Your Protection​

Most small businesses do not lose trade secret protection in dramatic fashion. They lose it through ordinary neglect:

  • No signed agreement at all. Verbal understandings about confidentiality are nearly worthless. If someone started work without signing, fix it now — though note that in some states, asking a current employee to sign a new restrictive agreement mid-employment requires fresh consideration beyond continued employment.
  • The client list lives outside your systems. When the definitive customer database is a salesperson's personal spreadsheet, personal phone, or personal email history, you will struggle to prove the information was yours, secret, or controlled. Centralize it.
  • Treating contractors casually. The developer, the marketing freelancer, and the virtual assistant often see more sensitive data than employees do — with no agreement at all. Every contractor with system access signs before getting credentials.
  • Claiming everything is confidential. When the employee handbook labels the office Wi-Fi password and the client list with equal solemnity, nothing looks like a genuine trade secret. Reserve the strong protections for genuinely sensitive information.
  • Waiting until they join a competitor. Once your former employee is working across the street with your pricing sheet, your options are lawyers and damage control. Every measure in this guide is cheaper before the departure than after it.

Your Records Are Your Proof​

Notice how often this guide comes back to documentation: signed agreements on file, dated versions of key compilations, access logs showing who could see what and when, exit checklists proving the handoff happened. Trade secret protection is ultimately a recordkeeping discipline. The business that can show a dated client list, the access controls around it, the agreement signed before access was granted, and the exit acknowledgment signed at departure is the business a court believes.

That same discipline pays off far beyond trade secrets. Clean, version-controlled financial records tell you what each client relationship is actually worth, track what you spend protecting the business — legal fees for agreement templates are an ordinary business expense — and give you the paper trail every audit, dispute, and loan application eventually demands. Tracking these expenses in separate accounts from day one makes them trivially easy to substantiate later, and your documentation habits in finance and in confidentiality reinforce each other.

Keep Your Business Records as Tight as Your Trade Secrets​

As you put these protections in place, make sure the financial side of the house gets the same treatment: clear records, full history, nothing locked in a black box. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — version-controlled, auditable, and AI-ready. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Source: https://beancount.io/blog/2026/10/03/trade-secrets-ndas-employee-exit-checklist-small-business-guide

Published: October 3, 2026