Monday, April 25, 2011

Publicly Available Software Code Can Be a Trade Secret if Compilation is Not Generally Known

A recent Fourth Circuit opinion analyzed when a software compilation can qualify for protection as a trade secret. The plaintiff company claimed that although its software used publicly-available mathematical formulas, the combination and implementation of these formulas contained in the source code for the software constitutes a trade secret. The Fourth Circuit agreed, holding that a trade secret may be composed of publicly-available information if the method by which that information is compiled is not generally known. Processes that are publicly known can become trade secrets when combined into a source code and the manner and sequence of the processes is unique and unknown to the public. The case is Decision Insights, Inc. v. Sentia Group, Inc., 2011 U.S. App. LEXIS 5151 (4th Cir. Va. March 15, 2011), and can be foundThe case can be found here.

The case arose when Decision Insights, Inc. (“Decision Insights”) filed a complaint against Sentia Group, Inc. (“Sentia”) and individual former employees alleging that Sentia’s development of a competing software application was based on materials obtained from the Sentia’s misappropriation of Decision Insight’s trade secrets. The question considered by the district court was whether Decision Insight’s software application, as a total compilation, could qualify as a trade secret under Virginia law.

Sentia had hired a former consultant for Decision Insights who worked to develop software for Sentia that would compete with Decision Insights’ software. According to Decision Insights, the software developed by Sentia is almost identical to its own. Decision Insights asserted that all the parameters, variables, and sequencing associated with the programs must have been the same as Decision Insights’ software to obtain such identical software.

The criteria for establishing the existence of a trade secret under Va. Code § 59.1-336 includes whether or not the compilation has independent economic value, is generally known or readily ascertainable by proper means, and is subject to reasonable efforts to maintain secrecy.

On appeal, the court considered whether Decision Insights adduced enough evidence at trial for a jury to reach the conclusion that Decision Insights’ software, as a compilation, is not generally known or ascertainable by proper means. At trial, Decision Insights had introduced two experts who testified that part of the source code was unknown to the public and the sequence of the processes was unique and not publicly available. One expert identified 13 proprietary processes in the source code, and stated that “[t]he collection of these processes as a whole and the sequence of these processes also serve as a proprietary aspect of [Decision Insights’ software].” Opinion at 14.

The court held that due to the evidence offered by the two experts, the trial court erred in concluding that Decision Insights had not satisfied its evidentiary burden to show that its software compilation was not generally known or readily ascertainable by proper means. The court noted that a trade secret may be composed of publicly-available information if the method by which that information is compiled is not generally known. The court cited Servo Corp. of America. v. General Electric Co., which held that a trade secret “might consist of several discrete elements, any one of which could have been discovered by study of material available to the public.” 393 F.2d 551, 554 (4th Cir. 1968). The court also found that numerous variables that were part of the Decision Insights software code were not in public literature or known outside the company.

The court remanded and directed the district court to consider other criteria specified by the Virginia Trade Secret Misappropriation Act, including whether Decision Insights’ software code has independent economic value and whether Decision Insights engaged in reasonable efforts to maintain the secrecy of the software code. See Va. Code. Section 59.1-336.

In the past, parties have claimed that a company’s products or process are not trade secrets unless kept strictly and wholly confidential. This case is important because it allows some components of trade secret information to be publicly known in certain circumstances while maintaining their trade secret status so long as other important information, such as the way those public pieces of software code are put together, remains confidential. The question of whether information was adequately kept confidential frequently arises in unfair business practices cases and this opinion helps clarify the issue.

Friday, February 25, 2011

Press Releases Can Cause Waiver of Work Product

Statements made in a press release, if based on attorney work product information, may waive work product as to the subject matter of the statements. In E.I. DuPont de Nemours and Company v. Kolon Industries, Inc. (E.D. Va. July 30, 2010), click here, the court found that the plaintiff, E.I DuPont de Nemours and Company ("DuPont") waived information that was otherwise non-discoverable work product because DuPont relied upon that information to support a statement in its press release.

The case involves allegations by DuPont that the defendant Kolon Industries, Inc. ("Kolon") misappropriated DuPont’s secret processes and technologies for manufacturing Kevlar. In addition to the civil litigation filed by DuPont, the F.B.I. had previously conducted a criminal investigation of a Kolon employee. During that criminal investigation, DuPont's general counsel office had worked closely with government officials. In a previous opinion, the Court held that work product was not waived by Dupont's sharing of documents with law enforcement agencies that were investigating the alleged misconduct. E.I. DuPont de Nemours and Company v. Kolon Industries, Inc., (E.D. Va. Apr. 13, 2010).

However, DuPont's issuance of the press release was another story. The controversial statement read: "FBI investigation has revealed that, in August 2008, three Kolon managers flew to Richmond, the location of our global Kevlar technology and business headquarters, expressly for the purpose of obtaining confidential DuPont process technology." DuPont was distributing the press release to DuPont’s customers, presumably in an attempt to gain a competitive advantage. Press releases are, of course, a common tactic used by companies to protect and bolster public opinion and brand name.

Kolon sought discovery of work product information, contending that DuPont had waived its work product relating to the subject matter of the statement because the information relating to manager’s intent could have only be based on protected information. DuPont responded that the press release was based solely on publicly available information.

The court found that the press release statement relied on more than just public information. The court based its finding, in part, on its conclusion that the in-house counsel who drafted the statement had reviewed multiple rources of information relating to the meeting, and in drafting the statement in question, he could not possibly have "segregated the various categories of [publicly available and protected] information." Therefore, the press release was not based solely on public information. Rather, the statement about Kolon's purpose in attending the meeting was most likely based at least partly on privileged information that the in-house counsel had been exposed to throughout the course of his work with the government investigation.

The court also addressed the scope of the waived subject matter. Kolon sought production of "all communications in DuPont's possession relating to the Government's investigation of [Kolon's employee] and Kolon." The Court, however, more narrowly defined the scope of the waived subject matter to be those documents that "provide the factual basis for the statement in the press release that, in arranging for and attending . . . the meeting, Kolon had the purpose stated in the press release."

The Court also limited the waiver to fact work product and refused Kolon's request for opinion work product to be produced, finding that opinion work product is only discoverable in extreme circumstances. And the court found that an issuance of a press release is a common, not an extraordinary, circumstance in business.

This case serves as another warning to companies in litigation to carefully monitor the process of drafting press releases and what statements to include in them because press releases can lead to sanctions, waiver of work product and privileged information, and increase litigation costs. At the same time, companies in litigation often feel compelled to try to shape the public's perception of the litigation and the companies themselves. This is particularly true in cases involving unfair business practices or competition when the survival of a company's business model can be at stake. But, in doing so, they need to carefully weigh the risks of what they are saying publicly.

Tuesday, September 7, 2010

Court Recognizes Federal Claim for Employees' Theft of Electronic Documents

Some time ago (March 27, 2009), we wrote a post describing the applicability of the federal Computer Crimes and Abuse Act, 18 U. S. C. § 1030, (the “CFAA” or the “Act”) to unfair business practices cases. The Act provides a federal remedy for anyone who intentionally accesses a protected computer without authorization, or exceeds authorized access, and obtains information or who knowingly and with intent to defraud and in furtherance of the fraud, obtains something of value, unless the only thing obtained is the use of the computer and that use is not valued at more than $5000 in a one year period. An employer owned computer is “protected” under the statute.

It is becoming increasingly common for plaintiffs to use this Act as a vehicle for obtaining access to federal courts where diversity jurisdiction does not exist. As might be expected, a split of authority exists as to whether this statute may be so used, or whether it is intended only to address actions by computer hackers. At the present time, three federal Circuit Courts of Appeals (1st, 5th and 7th), as well as a number of District courts, have adopted a broad view of the statute and allow claims where an employee permissively accesses an employer’s computer system for an improper purpose. A common example is where an employee, who has accepted a job with a competitor or who intends to start a competitive company, copies proprietary electronic data from his employer’s system for use in his new job with the competitive company.

Those courts adopting the broader view reason that once an employee decides to join a competing company or has made arrangements to form one, his loyalty is divided between his existing employer and the new one. In that circumstance, by accessing the employer’s network and copying files, the employee violates his fiduciary duty of loyalty to his employer. Such conduct satisfies the CFAA requirement that the defendant “exceeds authorized access” to the computer system.

In a recent case, the federal district court for the Southern District of New York, Starwood Hotels & Resorts Worldwide, Inc. v. Hilton Hotels Corporation et al., 09-cv-3862 (June 16, 2010) joined those courts adopting the broader view. Click here for the opinion. The facts of the case, as alleged, are extreme. But they should serve as a cautionary tale to employees who are considering joining a competitive firm and as a roadmap for employers who have been victimized by departing employees.

In this case, two of Starwood’s executive officers who worked on its luxury hotel brands were recruited to join Hilton and accepted offers of employment. Both had access to Starwood’s most confidential data and both were subject to confidentiality agreements requiring that they safeguard Starwood’s confidential information and, once their employment ended, return all such information to Starwood and not disclose it to anyone.

After signing an employment agreement with Hilton but before notifying Starwood of his intent to resign, one of the executives asked his staff to compile a significant amount of confidential information for him that he then forwarded to his personal email account. This included digital images of thousands of documents that Starwood used in designing and branding its luxury hotels. As alleged, he forwarded this information to Hilton. He also copied electronic documents to his personal laptop computer and used that information to benefit Hilton. In addition, once he joined Hilton he solicited additional confidential information from other Starwood employees who used their personal email accounts to convey Starwood’s proprietary information to their former superior.

The other executive, while still at Starwood and after engaging in discussions with Hilton representatives, allegedly acted as a corporate spy for Hilton and collected and forwarded to Hilton confidential information related to Starwood’s business and development opportunities.

Starwood knew nothing of the extent of this piracy until, in discovery, Hilton produced eight large boxes of computer hard drives, thumb and zip drives and paper records containing large quantities of Starwood documents. Indeed, the computer drives contained over 100,000 downloaded files.

At issue in the recent opinion was Hilton’s motion to dismiss the count for a violation of the CFAA because the Act was not intended to cover such conduct. The court noted at the outset that this case did not involve an employee who accessed his employer’s computer in the ordinary course of his duties and then, at some later time, used some of that information to benefit a competitor. Rather, here the information was obtained with the specific intent to use it against the employer through “trickery and deceit.” The court concluded that once the executives accepted employment with Hilton, they “no longer had Starwood’s authorization to access this information. Thus, even construing the statute narrowly to prohibit only accessing computer information without permission, Starwood’s complaint adequately alleges a claim under the CFAA.”

The court also held that Hilton could potentially be liable under the Act because, as alleged, it used one of the executives, as well as others, as corporate spies to steal Starwood’s confidential information. Finally, the court found that Starwood’s expenditure of sums to investigate the damage sustained as a result of the former employees’ actions, which exceeded $5000, met the damages requirement of the statute. Thus, Hilton’s motion to dismiss the claim was denied.

Unquestionably, these actions were extreme. But apart from the volume of electronic documents that were pilfered, the story line is not that unusual. Departing employees often take confidential information belonging to their employer for use in their new employment, thinking that it will make them more valuable to the new employer. And it is not unusual for them to contact former colleagues, once at the new employer, and ask for information they “forgot” to take with them. This case adds to the growing line of authorities that recognize that, under such circumstances, the CFAA provides a potential remedy to the former employer. Moreover, unlike in Starwood, where confidentiality agreements existed, such agreements are not an essential predicate to applicability of the statute. The common law duty of loyalty prohibits employees from using confidential information to benefit a new employer.