By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)
India has no standalone Trade Secret Act, so the protection a Kerala startup has for its undisclosed know-how — pricing models, customer lists, training datasets, process know-how, source code that is not published — depends not on registration but on whether the business creates confidentiality by contract under the Indian Contract Act, 1872 and by conduct through access controls, with statutory support from Section 43A and Section 72 of the IT Act, 2000 and — where entrustment and misappropriation are made out — Section 316 of the Bharatiya Nyaya Sanhita, 2023. An NDA signed after disclosure, or a non-compete so broad it is void under Section 27 Contract Act, is not protection — it is paperwork that fails when tested.
How is a trade secret defined when there is no Trade Secret Act?
No statute supplies a definition, so courts and commentators apply the classic three-part test drawn from TRIPS Article 39 and Indian breach-of-confidence jurisprudence:
| Element | What the business must show |
|---|---|
| Secrecy | The information is not generally known or readily accessible to persons who normally deal with that kind of information |
| Commercial value because it is secret | The information has economic value precisely because it is not public — a customer list, a trained model’s weights, a process yield — and disclosure would erode that value |
| Reasonable steps to keep it secret | The holder took measures that a reasonable business would take to preserve confidentiality — NDAs, need-to-know access, marking, technical controls, exit procedures |
A business that cannot show the third element — reasonable steps — fails even where the first two are made out. A pitch deck emailed without an NDA, a codebase accessible to every intern, and a customer database downloadable to personal devices are not trade secrets in practice, because no reasonable steps were taken to keep them secret. The DPDP Act reinforces this logic from the data side: Rule 6 DPDP Rules, 2025 requires encryption or masking, access controls and logging — the same controls that support a trade-secret claim.
What laws actually protect trade secrets in India?
| Source | What it does | Limit |
|---|---|---|
| Contract — Sections 27, 73, 74 Contract Act, 1872 | Enforces NDAs, confidentiality clauses, non-solicitation and — where reasonable — limited post-contract restraints; damages for breach under Sections 73 and 74 | Section 27 voids agreements in restraint of trade — a blanket non-compete preventing a former employee from working in the same field anywhere is typically void; non-disclosure is distinct and generally enforceable |
| Equity — breach of confidence | Injunction and damages where confidential information was imparted in circumstances importing confidence and was misused — available even without a written NDA where the circumstances show confidence | Requires proof of the confidential character and the circumstances of disclosure |
| IT Act — Section 43A | Compensation for negligent failure to implement reasonable security practices where wrongful loss or gain results from handling of sensitive personal data — relevant where the trade secret includes personal data | Civil compensation; complements DPDP Section 8(5) safeguards (up to two hundred and fifty crore rupees for safeguard failure) |
| IT Act — Section 72 | Penalty for breach of confidentiality and privacy by a person who has secured access to electronic records under the IT Act — penalty up to five lakh rupees (substituted for imprisonment and fine by the Jan Vishwas (Amendment of Provisions) Act, 2023) | Applies where access was obtained under IT Act powers or duties; narrower than Section 72A’s contractual disclosure route |
| IT Act — Section 72A | Penalty for disclosure of personal information in breach of a lawful contract, intending or knowing wrongful loss or gain — penalty up to twenty-five lakh rupees (substituted for imprisonment and fine by the Jan Vishwas (Amendment of Provisions) Act, 2023) | Requires a lawful contract and the mental element of wrongful loss or gain |
| BNS — Section 316 (criminal breach of trust) | Punishment where property is entrusted and dishonestly misappropriated or converted — invoked where an employee or partner entrusted with data or materials misappropriates them | Requires entrustment and dishonest misappropriation — not every NDA breach qualifies |
| BNS — Section 336 (forgery), Section 353 (statements conducing to public mischief) | Where misuse involves fabrication of records or misrepresentation | Fact-specific |
Practical observation: Most startup trade-secret disputes are won or lost on contract and on evidence of reasonable steps, not on the criminal provisions. The criminal track is fact-heavy and is not a substitute for a well-drafted NDA and an access-control programme.
What makes an NDA enforceable — and what makes it fail under Section 27?
Section 27 Contract Act — every agreement by which anyone is restrained from exercising a lawful profession, trade or business of any kind is to that extent void — is the provision founders fear and counterparties invoke. The fear is partly misplaced because courts distinguish:
- Non-disclosure — generally enforceable. An obligation not to disclose specific confidential information is a restraint on disclosure, not on the ability to carry on a trade. It is not the restraint Section 27 targets.
- Non-compete — closely scrutinised and often void post-employment. A clause that says a former employee cannot work for any competitor anywhere for two years is a restraint on trade and is typically void under Section 27. A narrowly drawn restraint — for example, not to solicit the employer’s customers with whom the employee actually dealt, for six months, within a defined territory where the employer operates — has a better chance, but remains difficult. During employment, reasonable exclusivity and non-compete terms are more readily enforced; post-employment, the bar is higher.
- Non-solicitation — more readily enforced where reasonable. Not to solicit employees or customers of the former employer, limited in time, scope and geography, tied to genuine confidential relationships.
An NDA that fails usually fails for one of these reasons:
- Signed after disclosure. The information was already shared before the NDA existed — there was no confidential basis at the time of sharing.
- No definition of confidential information. A clause that says everything is confidential is not credible; a schedule of categories with exclusions (publicly available information, independently developed information, information rightfully received from a third party without breach) is.
- Unreasonable duration or geography. Perpetual confidentiality for every casual disclosure is harder to enforce than a defined period tied to the sensitivity of the information and the commercial context.
- No return-or-delete obligation. The NDA allows the recipient to retain copies indefinitely, which undermines the secrecy claim.
- No injunctive-relief acknowledgement. The agreement does not acknowledge that breach would cause irreparable harm for which damages are inadequate — the language that supports an interim injunction.
What should a Kerala startup’s NDA and confidentiality programme actually contain?
The NDA — clauses that matter
- Definition and exclusions. Define confidential information by categories relevant to the startup — code, datasets, models, customer lists, financials, roadmaps — and list exclusions (public domain through no breach, independently developed, rightfully received from a third party).
- Purpose limitation. State the specific purpose of disclosure (evaluation of a partnership, employment, investment diligence) and prohibit use beyond that purpose.
- Standard of care. Require at least the same care the recipient uses for its own confidential information, and in any event reasonable care — including technical safeguards where the information is electronic.
- No licence or assignment. Clarify that disclosure does not transfer ownership — copyright stays with the author or employer under Sections 17 to 19 of the Copyright Act (see the software copyright guide), and patent rights are not licensed by the NDA.
- Duration. A confidentiality period appropriate to the information — often two to five years for general commercial information, longer or indefinite for true trade secrets where the parties genuinely intend perpetual secrecy and the information qualifies.
- Return or certified deletion. On termination or on demand, return or certify deletion of confidential information and copies, including from backups where technically feasible, with a written certificate of deletion.
- Residual knowledge. Address whether general skills and knowledge retained in unaided memory are excluded — a point that matters for employee mobility and that should be addressed explicitly rather than left to argument.
- Personal-data handling. Where confidential information includes personal data, require compliance with the DPDP Act — lawful basis, purpose limitation, Rule 6 security safeguards, Rule 7 breach notification — so the NDA and the DPDP processor obligations reinforce each other (see the DPDP countdown guide and the cross-border transfer guide).
- Remedies. Acknowledge irreparable harm and the availability of injunctive relief in addition to damages under Sections 73 and 74 Contract Act, and provide for governing law and dispute resolution (arbitration in Kochi is common for startups).
- Reasonable post-employment restraints. If sought, draw non-compete and non-solicitation narrowly — limited customers, limited geography, short duration — so they have a chance of surviving Section 27 scrutiny, and consider garden-leave or notice-period mechanisms during employment where appropriate.
The programme — conduct that proves reasonable steps
An NDA without a programme is a contract without evidence. The reasonable-steps file a court or an investor looks for:
- Marking. Confidential documents and repositories marked as such — not every email, but every genuinely sensitive disclosure.
- Need-to-know access. Role-based access, least privilege, and logging of who accessed what — the same controls Rule 6 DPDP requires for personal data, applied to trade secrets.
- Onboarding and exit. Confidentiality acknowledgements at joining, periodic reminders, and a structured exit process that revokes access, collects devices, and reminds the departing person of surviving obligations in writing.
- Vendor handling. Every contractor, agency and cloud provider signs confidentiality and data-processing terms before access — not after — with sub-processing controls where personal data is involved.
- Logging for proof. Access logs retained for at least the periods the business has chosen (the DPDP Rule 6 minimum is one year for personal-data logs; the CERT-In Directions require 180 days for ICT logs) so that misuse can be reconstructed and proved under Section 63 BSA if needed.
How do trade secret, copyright, patent and DPDP fit together?
For a typical Kerala SaaS or healthtech startup, the portfolio is:
- Trade secret — for undisclosed know-how, pricing, customer insights, and model weights that must stay confidential and that derive value from secrecy.
- Copyright — for code expression and documentation automatically under Section 2(o) Copyright Act, strengthened by Form XIV registration and the Section 48 certificate.
- Patent — for the inventive technical solution where the Section 3(k) and CRI Guidelines 2025 technical-effect test is met, accepting that publication in the specification ends secrecy for that invention.
- Trademark — for the brand (see the online trademark infringement guide).
- DPDP compliance — for personal data within the know-how (customer data, user data) under the DPDP Act and Rules, with the same technical controls serving both trade-secret and data-protection purposes.
Primary sources
- Indian Contract Act, 1872 — India Code (Sections 27, 73, 74)
- Information Technology Act, 2000 — India Code (Sections 43A, 72, 72A)
- Bharatiya Nyaya Sanhita, 2023 — India Code (Sections 316, 336)
- Copyright Act, 1957 — India Code (Sections 2(o), 17, 18, 19, 48)
- Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY (Section 8(5), Rule 6)
- Bharatiya Sakshya Adhiniyam, 2023 — India Code (Section 63 — proving electronic logs)
FAQ
