Confidential information can be the whole commercial value of a small business. A customer list, a supplier's pricing schedule, a recipe, a quoted method of pricing jobs, or the source code behind your only product can be what separates you from a competitor that is otherwise identical. When that information leaks, the loss is rarely a matter of hurt feelings. It can be lost customers, a vanished head start, and a dispute that runs for years.
The law that protects this information is not one single statute you can point to. It is a set of overlapping rules drawn from contract, equity, the employment relationship, and, in some situations, statute and privacy law. This article walks through how that protection actually works: what must be true for information to be protected, where the obligation to keep it secret comes from, what a breach looks like, and what a business can realistically do about it.
The three elements of a breach of confidence
At the core of most confidentiality disputes is an equitable action known as breach of confidence. It has no statutory footing. It grows out of the principle that a person who receives information in confidence should not use or disclose it outside the terms on which it was given.
Australian courts consistently apply a test with three limbs, drawn originally from the English decision in Coco v AN Clark (Engineers) Ltd [1969] RPC 41 and adopted here in cases such as Moorgate Tobacco Co Ltd v Philip Morris Ltd [No 2] (1984) 156 CLR 414 and Smith Kline & French Laboratories (Australia) Ltd v Department of Community Services and Health (1990) 22 FCR 73. The three questions are:
- Quality of confidence: the information must have the necessary quality of confidence about it. In practice this means it is not generally known or publicly available, and it has value precisely because it is secret.
- Circumstances of confidence: the information must have been imparted in circumstances importing an obligation of confidence, meaning the recipient knew, or should have known, that it was meant to stay private.
- Unauthorised use: there must be an unauthorised use or disclosure of the information that causes, or threatens to cause, detriment to the party who shared it.
Every limb has to be made out. A business that cannot show the information was genuinely confidential, or that cannot show it was given in a way that carried an expectation of secrecy, will struggle no matter how clearly the other side used it.
Where the obligation to keep information secret comes from
Before asking whether there has been a breach, it helps to ask why the other party owed a duty of confidence at all. In Australian law there are several sources, and a single relationship can involve more than one.
Who is usually involved in a confidentiality dispute
Who ends up in a confidence dispute is worth setting out, because it explains why the law touches so many small businesses. The most common parties are an employer and a departing employee or director, a business and a former contractor or supplier, or a business and a prospective buyer, investor or partner who saw confidential material during negotiations and never signed a deal. In each relationship the same underlying question runs through the dispute: was the information confidential, was it received under an obligation of confidence, and was it then used without authority.
There is usually no regulator and no administrative complaint that adjudicates a breach of confidence. It is a private dispute settled in the courts, which means the business that wants protection has to bring the claim itself and carry the cost and risk of doing so. That is a practical difference from an area like privacy, where a regulator may act alongside the affected individual.
Express contract terms
The cleanest source of a confidentiality obligation is a written term. A confidentiality clause in an employment contract, a contractor agreement, a supplier agreement, a joint venture agreement, or a non-disclosure agreement (NDA) signed before a deal starts defines what counts as confidential information, what it may be used for, who it can be disclosed to, how it must be stored, and what happens when the relationship ends, including any duty to return or delete materials.
A well-drafted clause matters because it converts an open-ended equitable duty into concrete, enforceable obligations. It also makes a later dispute far easier to run, because the scope of the duty is set out on the page rather than having to be inferred.
The equitable duty of confidence
The equitable duty operates even where there is no written contract. If information is shared in circumstances that clearly import an expectation of secrecy, an obligation of confidence can arise by implication. A prospective buyer who is handed your pricing model during due diligence, or a potential partner who is walked through your process during negotiations, may owe an equitable duty even if nothing is ever signed.
The trade-off is that an implied duty can be harder to establish and its scope more open to argument than an express clause. It is the reason a simple NDA before sensitive discussions is usually worth the effort.
The employment relationship
Employees stand in a special position. During employment, an employee owes an implied duty of good faith and fidelity to the employer, which extends to not using the employer's confidential information against its interests. The position changes once the employment ends. After termination, the general duty of fidelity lapses, and the employee's continuing obligations depend on what the contract says and on whether the information rises to the level of a trade secret or otherwise stays protected.
The leading New South Wales authority, Del Casale v Artedomus (Aust) Pty Ltd [2007] NSWCA 172, examined what happens when former directors and employees used knowledge of a supplier's identity and the source of a distinctive product to set up in competition after leaving. The case highlights a crucial distinction the courts draw between a genuine trade secret and the general skill and knowledge an employee takes away in their head. General know-how accumulated over a career is not confidential in the same way; a specific, protected secret is. Express confidentiality clauses and, for directors and officers, duties such as those in the Corporations Act 2001 (Cth) can sharpen and extend what would otherwise be protected.
What counts as a breach
A breach of confidence is an unauthorised use or disclosure of protected information. It does not need to be deliberate. An employee who forwards a confidential proposal to the wrong email address, a contractor who reuses a client's template for a second customer, or a departing team member who copies the customer list before leaving can each commit a breach even where there was no plan to harm.
Much of the risk in a small business clusters around a small number of moments: a resignation, a termination, a contractor finishing a job, a negotiation falling over, or a password that is shared and never changed. Those are the points at which access is easiest to lose control of and where a leak is most likely to surface.
The remedies a business can seek
If a breach is established, the court has a range of discretionary remedies. Which one fits depends on what was taken, whether the information is still being used, how urgent the situation is, and what evidence the business holds:
- Injunction: an order restraining the other party from using or disclosing the information. In an urgent case a business can apply quickly for an interlocutory injunction to freeze the harm pending a full hearing, which is often the single most valuable step.
- Damages or equitable compensation: monetary relief for the loss suffered, such as lost profits or the value of the advantage wrongly taken.
- Account of profits: an order requiring the wrongdoer to hand over the profit they made from the misuse, rather than compensation for the victim's loss.
- Delivery up and destruction: an order requiring the return of physical and digital material and confirmation that copies have been deleted.
Getting the right remedy, and acting early, usually determines how much of the damage can actually be undone. An injunction is far more useful before the information has been widely distributed than after.
Where the mechanism tends to break down
A few recurring problems trip up businesses trying to rely on confidentiality law, and they are worth knowing before you need them.
First, evidence. To run the three-limb test you need to show what was taken, when, by whom, and where it went. That means preserving emails, system logs, file access records and copies of the relevant agreements early, before they are deleted or overwritten. This is easier if access controls and individual logins were in place in the first place, because they leave a trail that shows who touched what.
Second, the trade secret versus know-how line. A former employee is free to carry the general skill and expertise of their trade to a new job. Trying to restrain that can fail, or worse, be struck down as an unenforceable restraint of trade. The protection realistically extends to specific, identified confidential information, which is another reason written definitions matter.
Third, the confusion between confidentiality and privacy. Confidentiality concerns commercially sensitive information shared in confidence. Privacy law, principally the Privacy Act 1988 (Cth), governs how personal information about individuals is collected, used, stored and disclosed. A customer list can be both confidential and personal data at once, and a business may have obligations on both sides. Whether the Privacy Act applies to a small business depends on matters such as annual turnover and what the business does with the data, so it is worth checking rather than assuming.
Where a lawyer fits in
A commercial lawyer's value in this area sits at two very different points. The first is prevention: drafting confidentiality clauses, NDAs, employment terms and offboarding procedures so that the boundaries of what is protected are clear and enforceable before a dispute begins. Most confidentiality problems are far cheaper to design out than to litigate.
The second is response. When a leak is suspected, timing is everything. A lawyer can help confirm what happened without destroying evidence, contain the damage by advising on lockdown and access measures, and assess whether a formal letter, an urgent injunction application, or some other path is the right escalation. Doing this strategically, rather than reacting in panic, materially improves the outcome.
The value concentrates in the first twenty-four hours
For most small businesses the decision that matters most is made in the first hours after a suspected leak, before the information has spread and while an injunction can still stop the harm rather than simply measure it. That is the moment to decide whether you have evidence of a genuine secret, whether a confidentiality obligation exists, and whether to move urgently. Getting legal help at that instant, rather than after the damage is done, is usually the difference between containing a problem and litigating the remains of one. A first conversation does not commit you to a court fight, and it is the cheapest way to learn which of the remedies above are realistically on the table for your situation.