1. What actually makes information "confidential" in Australian law
  2. What counts as commercially confidential in your business
  3. Where confidentiality usually breaks down
  4. The protection checklist that holds up
  5. What the law actually gives you when it goes wrong
  6. Why confidentiality becomes more visible as you grow
  7. When to bring in a lawyer, and what one actually does
  8. Secrecy and the taker's knowledge

A customer list your team spent three years building. A pricing model you tuned over dozens of quotes. A manufacturing process that took months to get right. Any of these, in the wrong hands, can hand a competitor your edge. But under Australian law, none of it is protected simply because you think of it as "ours". What decides whether you can stop someone using it is a set of legal tests about secrecy, value and the circumstances of disclosure, plus the paperwork and systems you had in place before the problem arose.

What actually makes information "confidential" in Australian law

Australia has no trade secrets statute, and no registration system for confidential information. Protection comes from two directions: contract, where the parties have agreed to obligations, and the equitable action for breach of confidence, which can apply even without a written agreement. The equitable action is the one that most business owners misunderstand, because it rests on a three-part test that courts have applied consistently for decades.

The test comes from the English decision in Coco v AN Clark (Engineers) Ltd [1969] RPC 41, which Australian courts have adopted and applied, including the Federal Court in Leica Geosystems Pty Ltd v Koudstaal [2012] FCA 1337. For a claim to succeed, the information must:

  • Have the necessary quality of confidence: it must not be public knowledge or generally known in the relevant industry.
  • Have been imparted in circumstances importing an obligation of confidence: the recipient knew, or should have known, they were receiving something secret.
  • Have been used without authorisation to the detriment of the person who disclosed it: When a court has to decide whether particular information meets the first limb, it weighs practical factors. In Del Casale v Artedomus (Aust) Pty Ltd [2007] NSWCA 172, the New South Wales Court of Appeal listed the relevant considerations: how widely the information is known inside and outside the business, how valuable it is to competitors, how much effort went into developing it, and how difficult it would be for someone else to acquire or duplicate it.

This is where the common advice to take "reasonable steps" comes from. Your day-to-day handling matters twice over. It helps show the information genuinely was secret and valuable, and it helps show the person who received it knew, or should have known, it was confidential. Confidentiality is a status you maintain, not a label you apply.

What counts as commercially confidential in your business

There is no fixed list, because what is confidential depends on what makes your business unique. For most small businesses and startups, the information a competitor would most want includes:

  • Pricing and margins: pricing formulas, discount rules, quote strategies
  • Customer and supplier data: lists, contact details, decision-makers, buying patterns, negotiated terms
  • Financial information: cash flow, runway, forecasts, unit economics
  • Plans and strategy: business plans, go-to-market plans, product roadmaps
  • Technical material: source code, system architecture, technical documentation
  • Processes and know-how: the way you deliver services, onboard customers, or automate work
  • Marketing material: campaign plans, audience data, creative concepts
  • Internal templates: sales scripts, proposal packs, training materials

It can also be the unglamorous details: how you handle customer complaints efficiently, or the exact deal you struck with a key supplier. The test is not whether the information looks impressive. It is whether a competitor would gain an advantage, or you would suffer harm, if it got out.

Confidential information is often confused with intellectual property, but the protection mechanisms are different. Trade marks, patents and designs are registered rights, obtained through application. Copyright protects the way information is expressed, such as a written document or source code, and arises automatically without registration. In Leica Geosystems, for example, the company relied on both copyright in its source code and breach of confidence, and the two claims ran side by side. Confidential information, by contrast, is protected by secrecy and by the obligations people have agreed to or owe in equity. Your customer database might not be registrable as any form of IP, but it can still be your most valuable confidential asset. Conversely, your brand name can be trade marked while the list of your customers stays confidential.

Where confidentiality usually breaks down

Confidentiality problems in small business rarely come from corporate espionage. They come from everyday decisions. The classic failure points are:

  • Sharing too much too early: showing your pricing model, delivery approach or roadmap to win a client or partnership before any confidentiality obligation exists.
  • Contractors with broad access: giving a designer, developer or marketer full system access without a contract covering confidentiality, ownership of work product and what happens at the end of the engagement.
  • Departing employees: a resigning employee carries customer relationships, sales playbooks and pricing knowledge out the door.
  • Founder and shareholder disputes: a falling out can see business plans and customer lists walked away with.
  • Sloppy internal handling: everything treated the same, shared everywhere, nothing labelled, no access controls.

The Woolworths v Olson case shows how quickly this goes from an administrative detail to a legal claim. The executive in Woolworths Ltd v Olson [2004] NSWCA 372 had decided to resign and join a competitor. Before he left, he emailed extremely confidential and valuable project documents to his wife's personal computer, intending to use them in his new role. The courts found that was a flagrant breach of his contractual and fiduciary duties and a breach of confidence, and the employer's post-employment restraint was upheld on appeal. The cautionary detail for every business owner is that the leak went out through the most ordinary channel imaginable: forwarding documents to a personal email address.

Public disclosure is the other silent killer. Posting internal strategy publicly, publishing case studies that reveal sensitive numbers, or sending confidential documents to large email lists can destroy the necessary quality of confidence. Once information is genuinely in the public domain, the equitable action falls away, and no amount of contractual wording revives it for information that was already public when disclosed.

The protection checklist that holds up

Protection works as a combination of legal documents and practical systems, and the two reinforce each other. Each step below serves a purpose in the breach of confidence test: it either keeps the information secret, or it creates evidence of the circumstances in which it was shared:

  1. Identify what is actually confidential: List the "crown jewels". For most small businesses that means customer and lead data, supplier pricing and terms, internal processes, pricing strategy and margins, and product development plans. You cannot protect what you have not identified, and you cannot later prove something was treated as confidential if nothing distinguished it from ordinary business information.
  2. Limit access on a need-to-know basis: Use separate folders for finance, sales and product information, restrict administrator rights for contractors, avoid circulating full customer lists, and turn on audit logs where you can. If a dispute ever arises, showing that you controlled access is part of telling a credible confidentiality story.
  3. Get the documents in place: The core documents are:
    • A non-disclosure agreement (NDA): for conversations with potential partners, contractors and early-stage hires before employment starts. Some investors will not sign NDAs at early stages, in which case control what you share and when, rather than relying on the document.
    • An employment contract: with clear confidentiality obligations, sensible post-employment restraints where appropriate, and assignment of intellectual property created during the role.
    • A contractor agreement: covering confidentiality, permitted use of your information, ownership of work product, and return or deletion obligations when the engagement ends.
    • Customer or client terms: where you share business know-how as part of delivering services, protections around how the customer may use your materials.
  4. Label and handle consistently: Marking a document "Commercial in Confidence" is not legally required, but it removes ambiguity. When there is a dispute, you want it to be obvious that the other party knew, or should have known, the material was confidential. Labelling is evidence of that knowledge.
  5. Train the team: Confidentiality is usually lost through habit, not bad intentions. A short internal checklist can cover the big risks: no forwarding sensitive documents to personal email, no password reuse across tools, no customer lists in public channels, and approved templates for proposals and pricing.
  6. Plan for the worst: Know what happens when a contractor relationship ends suddenly, a team member resigns, or you suspect information has been copied. That means knowing who can investigate internally, what evidence can be preserved (access logs, emails, signed contracts), and who you will call for legal advice. Reconstructing events after the fact is far harder than having the plan in place.

What the law actually gives you when it goes wrong

If someone misuses your confidential information, the remedies available include injunctions to stop the use, damages or equitable compensation, and an account of profits. In Del Casale, the trial court ordered an account of profits for misuse of confidential information, although the permanent injunction was overturned as excessive on appeal. Speed matters: if you become aware of misuse, an urgent application for an interlocutory injunction is often the practical remedy, because stopping the use early preserves the value that damages cannot fully replace.

The springboard doctrine is worth knowing about because it extends protection beyond simple copying. As the Federal Court explained in Mastec Australia Pty Ltd v Trident Plastics (SA) Pty Ltd (No 3) [2018] FCA 99, drawing on Zomojo Pty Ltd v Hurd (No 2) [2012] FCA 1458, equity will restrain a former employee who uses an employer's information as a springboard to gain a head start, even where the information could have been independently obtained. The injunction typically lasts only as long as the head start the misuse created, but that can be commercially decisive.

Where a departing employee is involved, the law draws a line between two categories of information, confirmed in Del Casale following Wright v Gasweld (1991) 22 NSWLR 317. An employee's general skill, experience and know-how belongs to them and they can use it in a new job. Trade secrets and genuinely sensitive commercial information cannot be used after departure unless a valid contractual restraint prevents it. Whether information falls in one category or the other turns on the factors discussed above, and the dividing line is often the central battleground in litigation.

Post-employment restraints themselves are not automatically enforceable. At common law a restraint of trade is presumed void as contrary to public policy unless it protects a legitimate business interest and goes no further than is reasonable, looking at duration, geographic area and the activities restricted. Woolworths v Olson is a useful example of a restraint that survived scrutiny, but the burden is on the employer to justify it. In New South Wales, the Restraints of Trade Act 1976 (NSW) also lets a court read an unreasonable restraint down to what is reasonable, which is one reason restraint drafting is a job for a lawyer who knows the local law.

There are also statutory obligations that sit alongside the equitable action. Under s 183 of the Corporations Act 2001 (Cth), a person who obtains information because they are, or have been, a director, officer or employee of a company must not improperly use it to gain an advantage for themselves or someone else, or to cause detriment to the company. The duty continues after the person leaves, and it is a civil penalty provision. The Court of Appeal in Del Casale noted that improper use under s 183 can encompass a breach of an equitable obligation of confidence, so a departing officer or senior employee can face both a personal statutory duty and a claim in equity.

One more distinction to keep straight. If the information is personal information about individuals, it is regulated separately under the Privacy Act 1988 (Cth). The Act requires entities it covers to comply with the Australian Privacy Principles, including having a privacy policy. A privacy policy is a compliance document about how you handle personal information. It is not a substitute for confidentiality agreements, and confidentiality agreements do not displace your privacy obligations. Most businesses need both, for different purposes.

Why confidentiality becomes more visible as you grow

Raising capital, taking on a strategic partner, or selling the business all put your confidential information in front of people who do not owe you loyalty yet. During investor due diligence you will be asked for financial statements, customer metrics, supplier arrangements and key contracts. That is where controlled data rooms and NDAs, where the investor is willing to sign, earn their keep. Even with a reputable investor, good confidentiality hygiene sets expectations and protects you if the deal does not proceed.

When you sell a business, much of what the buyer is paying for is precisely the information this article covers: customer relationships, internal systems, pricing know-how and processes. The sale agreement needs to identify what is being transferred, how it is being transferred, and what stays behind, and the buyer will want comfort that the information is protected and can actually be handed over. Getting the confidentiality and IP schedules right at that point protects the value of the deal itself.

When to bring in a lawyer, and what one actually does

Much of the protection described here is within reach of any business owner, but the judgement calls are where a lawyer earns their fee. A lawyer will assess whether your particular information is likely to satisfy the breach of confidence test, draft the NDAs, employment contracts and contractor agreements that fit your actual operations, and advise on whether a proposed restraint is worth having at all, given that an unenforceable restraint can be worse than none. When something goes wrong, a lawyer's role is urgent: assessing whether you have a viable claim, applying for interlocutory injunctions before the damage compounds, and preserving the evidence that will decide the case. Getting a document reviewed before you rely on it is far cheaper than litigating after the leak. The team at Artificer Legal can help you work through which of these steps your business actually needs and draft the documents to match.

Secrecy and the taker's knowledge

If there is one point to take from all of this, it is that most confidentiality disputes are decided before the leak happens, by two things: whether the information was genuinely secret and valuable, and whether the person who took it knew they were not entitled to use it. The information you have treated casually, shared widely or published publicly is not confidential, no matter how strongly you feel about it, and a departing employee's general skill and know-how is theirs to keep. The cost of getting this wrong is not a bad outcome in a dispute. It is losing the right to bring the dispute at all.

To summarise the key points: commercial confidentiality in Australia rests on contract and on the equitable action for breach of confidence, which requires information of a confidential character, disclosure in circumstances importing an obligation of confidence, and unauthorised use causing detriment. The practical work of protection, identifying crown jewels, controlling access, putting NDAs, employment and contractor agreements in place, labelling consistently and planning offboarding, exists to satisfy those elements when you need to enforce them. If you are unsure whether your information qualifies, whether your restraint would hold up, or what to do after a suspected leak, a lawyer can assess the position against the tests described here and build the documents and evidence trail that make enforcement possible.