unternehmensnachfolge-anwalt.at

Trade secrets and confidentiality during the succession transition

Mag. Bernhard Brandauer, Rechtsanwalt

Protect trade secrets during a business succession transition: stage data-room disclosure, control access, regulate handover and document return or deletion.

A business succession transition regularly requires the disclosure of highly sensitive information. This may include pricing logic, customer relationships, production methods, calculations and unpublished plans. Disclosing that information too early, too broadly or without clear responsibility can harm both negotiations and the operating business.

Trade-secret protection, contractual confidentiality and data protection pursue different aims. Under section 26b UWG, a trade secret requires, among other things, reasonable secrecy measures. The GDPR protects personal data. A confidentiality clause additionally regulates what the parties must do or must not do under their agreement.

A staged process is therefore useful. The succession-planning topic provides the wider framework. The existing article on transfer-agreement points is complemented here by information classes, access controls and the period after the changeover.

Confidentiality check

Which protection measure should be organised first?

This quick check separates disclosure, access control and the period after the transfer date.

Already know you want to get in touch? Go straight to the enquiry form.

01 Question 1

Where is the main problem in the transition?

All paths at a glance

Overview of all answers.

01

Organise information by protection level and recipient group.

Create an information list before disclosure. For each class, record recipients, purpose, scope, approval and end date. Confidentiality is then implemented in the process rather than merely asserted.

02

Separate personal accounts and record approvals.

Use personal accounts with only the required permission. Review active sessions, export options, multi-factor authentication and logs. Shared credentials make later evidence preservation more difficult.

03

Regulate return, deletion and continuing duties together.

Specify which documents must be returned or deleted, who confirms this and which statutory retention or evidence-preservation duties create an exception. Confidentiality can continue after the transfer date.

Separate trade secrets, contract duties and data protection

Section 26b UWG protects information only when the statutory requirements are met together. The information must be secret, have commercial value because it is secret and be protected by reasonable measures. Value alone is not enough. Calling information confidential does not replace an effective protection concept.

A contractual confidentiality duty operates between the agreed parties. It can regulate recipients, purpose, onward disclosure, return, deletion, advisers and the consequences of a breach. Section 26c UWG shows why a breach of such a duty may matter when the acquisition, use or disclosure of information is assessed.

Data protection is a separate field. Once customer, employee or contact-person data is included, purpose, legal basis, recipient group and security must be reviewed. Information can be both personal data and a trade secret. The GDPR does not replace UWG secrecy measures or the contractual organisation of the transition.

Prepare staged disclosure in the data room

Before opening the data room, list which information class is needed for which decision. Aggregated figures or redacted documents may be enough for an initial assessment. Detailed customer lists, margins, recipes or technical parameters do not automatically need to be visible at the first stage.

Every release needs a purpose and a recipient group. Check whether the recipient is a party to the transaction, whether advisers must be involved and whether those advisers are bound to an equivalent standard. Access merely because someone works on the project is too vague.

The holder's consent is an important lawful route under section 26d UWG. It is not a general permission for every onward disclosure. Consent should relate to the information, purpose, people and period concerned. A release record supports later traceability.

Control access, roles and logs in practice

Protection measures must work in daily operations. Personal accounts, graduated roles and suspension of unnecessary access form the foundation. For particularly sensitive information, consider additional approvals, multi-factor authentication and restrictions on exports.

In 4Ob195/24s, the Supreme Court highlighted the importance of reasonable secrecy measures and suspending access after an employee leaves. This is especially clear during succession: an old account can become an open vulnerability after responsibilities change, even where a confidentiality undertaking was signed earlier.

Logs should not be searched for only after a dispute. Record who approved a release, who downloaded documents, when permissions changed and when devices or storage media were returned. This protects the business and can assist in reconstructing events later.

Carry confidentiality duties into the transfer agreement

A transfer agreement should not simply state that all business documents are handed over. It should connect information classes, permitted use, recipients, advisers, technical handover and the duties of transferor and successor.

The period between signing and completion deserves particular attention. The successor may need information for financing, review and preparation without being entitled to make every operational decision. The transferor may still have access, but that access should be limited to the agreed purpose.

Different information classes may require different periods. Protection should not automatically end on the transfer date. Rules for subcontractors, affiliated companies, professional advisers and permitted disclosure to authorities or courts prevent later interpretation disputes.

Organise return and deletion after the handover

After the transfer date, record the access rights, copies and storage media that are no longer needed. This is not limited to paper files. Local downloads, private cloud storage, backups, mailboxes and mobile devices may also contain relevant copies.

Deletion is not always immediate or permissible. Statutory retention duties, pending proceedings and necessary evidence preservation may require limited retention. The agreement should distinguish return, deletion, blocking and secure archiving.

A return or deletion record should identify the categories, date, responsible person and any exception. This makes clear which information may no longer be used and which documents remain stored for a specific reason.

Secure evidence and access quickly in a conflict

If unauthorised use or disclosure is suspected, do not reflexively delete all data. First preserve the affected systems, permissions, logs, messages and approvals. Access can then be limited in a targeted way without destroying the evidence position.

Section 26c UWG addresses unlawful acquisition, use or disclosure in particular. Section 26e UWG provides, among other things, for injunctive, corrective and damages claims in such cases. The appropriate response depends on the information, recipient and risk of further dissemination.

A premature allegation can make the succession more difficult. A reliable chronology is better: identify the information, permission, access, disclosure, commercial importance and protection measures. In an ongoing succession dispute, review the contractual escalation and cooperation duties as well.

Common errors when protecting trade secrets

First, the entire data room is opened to every participant. That conflicts with purposeful and staged disclosure.

Second, shared accounts are used. It may then be impossible to tell who opened, copied or disclosed a file.

Third, protection is treated as ending when the transfer agreement is signed. The period before completion and the period after the transfer date both need clear rules.

Fourth, trade-secret protection is treated as the same as data protection. Both may apply, but they require different reviews.

Fifth, return and deletion are ordered without considering retention and evidence preservation. A differentiated record is safer and easier to implement.

Make the transition manageable before the transfer date

Start with a list of sensitive information classes and their holders. Then identify the people who need access for review, financing, advice and operational preparation. Each release should have a purpose, scope and period.

Next review technical access and contractual foundations. These include data-room rules, employment and adviser agreements, licence terms, confidentiality undertakings, the transfer agreement and any disputes. The article on information rights for passive family shareholders supports the separate personal-data review.

The completion plan should include access changes, a handover record and a follow-up plan. The article on company register and powers of attorney covers the technical side. If information is already disputed, the article on a dispute between an active successor and passive siblings provides a related perspective.

Current guidance on business succession

For updates on business succession, you can find current guidance in the Brandauer newsletter.

Frequently asked questions about trade secrets in transition

Is every internal piece of information automatically a trade secret?

No. Under section 26b UWG, the information must be secret, have commercial value because it is secret and be protected by reasonable secrecy measures. An internal label alone is not enough.

Can the successor see every document before the transfer date?

Not automatically. Scope and timing should be staged by purpose, information class and recipient group. Redacted or aggregated documents may initially be sufficient for particularly sensitive material.

Must every document be deleted after the handover?

Not necessarily. Return and deletion must be reconciled with statutory retention, pending proceedings and necessary evidence preservation. The transfer agreement should also regulate blocking and limited archiving.

Plan succession, keep control, avoid disputes.

Book an initial consultation. We clarify the legal framework, critical documents and next steps. Callback within one working day.

Contact us