9 min read

A Departing Employee Took Your Source Code: Trade Secret Claims in Illinois

By Ismail Cem Kuru

Trade SecretsSoftware LitigationDTSAIllinois Trade Secrets ActStartupsIP LitigationTechnologyEmployment

The Scenario Every Founder Dreads

Your senior engineer resigns on a Friday. The following week, your access logs show that in her final days she cloned the main product repository to a personal device, exported the customer database, and forwarded the product roadmap to a personal email address. On Monday you learn she has joined your closest competitor. Or worse, incorporated one.

This fact pattern, with variations, is one of the most common ways technology companies end up in litigation. The good news is that the law here is strong and the remedies are fast, if you move quickly and preserve the evidence correctly. The first days matter more than almost anything else.

What follows is general information about how these cases work in Illinois, not legal advice for your specific situation.

What Actually Counts as a Trade Secret

People assume "trade secret" is a special legal status you register somewhere. It is not. Under the Illinois Trade Secrets Act, information qualifies as a trade secret if two things are true: it is valuable because it is not generally known, and you took reasonable measures to keep it secret.

For a software company, trade secrets commonly include:

  • Source code and system architecture
  • Algorithms, models, and training data pipelines
  • Customer lists and customer usage data, when compiled and guarded rather than publicly known
  • Pricing structures, margins, and deal terms
  • Product roadmaps and unreleased features

What does not qualify: the general skill, experience, and knowledge an employee builds up doing the job. A departing engineer is allowed to be good at what you taught her to be good at. She is not allowed to take your code, your data, or your files with her.

The "reasonable measures" half of the definition is where cases are won and lost. Access controls, confidentiality agreements, need-to-know restrictions, and offboarding procedures are the evidence that you treated the information as secret. A company that shared its "crown jewels" freely, with no NDAs and no access restrictions, will struggle to claim them as trade secrets later.

Two Statutes, One Case

Illinois companies get two overlapping tools:

The federal Defend Trade Secrets Act (DTSA), 18 U.S.C. § 1836. Enacted in 2016, the DTSA lets you sue in federal court for misappropriation of trade secrets related to products or services in interstate commerce, which describes virtually all software. Claims must be brought within 3 years of when the misappropriation was discovered or reasonably should have been.

The Illinois Trade Secrets Act (ITSA), 765 ILCS 1065. The state analogue, with a longer 5-year limitations period, also running from discovery.

In practice, most cases plead both. The DTSA provides a federal forum, which is often preferable in cases involving out-of-state defendants or coordinated forensic discovery. Nothing about either statute requires a non-compete agreement. Trade secret law protects the information itself, regardless of what the employee did or did not sign.

What You Have to Prove

Misappropriation comes in two basic flavors: acquiring a trade secret through improper means (theft, hacking, breach of a duty to maintain secrecy), or using or disclosing a trade secret that was acquired improperly or under a duty of confidence.

A typical departing-employee case is built on three pillars:

  1. The information is a trade secret. Defined specifically, not "everything the company knows." Courts are increasingly impatient with vague trade secret identifications.
  2. You took reasonable secrecy measures. NDAs, access controls, and policies, actually enforced.
  3. The employee took or is using it. This is where forensics carry the case: git logs, download histories, USB device records, cloud sync logs, personal email forwarding.

The Remedies Are Serious

Courts can act fast in these cases, and the remedies have real teeth:

  • Emergency injunctions. A temporary restraining order and preliminary injunction can bar the former employee (and often the new employer) from using or disclosing the material, require its return or destruction, and in some cases pause the competing work while the case proceeds.
  • Damages. Both statutes allow recovery of actual losses plus the defendant's unjust enrichment, and where neither can be proven, a reasonable royalty for the unauthorized use.
  • Double damages. Where the misappropriation is willful and malicious, both the ITSA and the DTSA authorize exemplary damages of up to twice the underlying award.
  • Attorney fees. Available for willful and malicious misappropriation, and also against plaintiffs who bring bad-faith claims.
  • Ex parte seizure. In extraordinary circumstances, the DTSA allows a court to order federal marshals to seize misappropriated materials without advance notice. It is rarely granted, but its existence changes settlement conversations.

Illinois has one more doctrine worth knowing. In PepsiCo, Inc. v. Redmond, 54 F.3d 1262 (7th Cir. 1995), the Seventh Circuit affirmed an injunction against an executive whose new role would inevitably lead him to rely on his former employer's trade secrets, even without proof he had taken documents. This "inevitable disclosure" doctrine is applied narrowly and depends heavily on the facts, but in the right case it means you do not have to wait for the damage to happen before a court will act.

The First 72 Hours: A Checklist

What you do immediately after discovering the problem often determines the outcome.

  1. Preserve first, investigate second. Do not let IT reimage the departed employee's laptop. Do not have colleagues poke through her accounts. Preserve the device, the logs, and the accounts forensically, so the evidence is usable in court.
  2. Pull the records. Repository access logs, file download histories, badge records, email forwarding rules, cloud sync activity, USB connection logs. Build the timeline of what was accessed and when.
  3. Cut remaining access. Confirm every credential, token, and shared account is revoked. You would be surprised how often something is missed.
  4. Issue a litigation hold. Preserve relevant documents and communications internally before anything is auto-deleted.
  5. Do not tip off the employee before you have preserved the evidence. A premature confrontation invites deletion. Once preservation is done, a well-drafted demand letter to the employee, and often to the new employer, is frequently the next step. Sometimes it resolves the matter. Sometimes the answer confirms you need a TRO.
  6. Move. Delay undercuts both the emergency remedies and your credibility. Courts asked for urgent relief will ask what you did when you found out, and "waited three months" is a bad answer.

Prevention Is Cheaper: Three Things to Fix Now

Paper. Every employee and contractor should have signed a confidentiality agreement and an IP assignment. One drafting note that trips up even sophisticated companies: the DTSA conditions the recovery of exemplary damages and attorney fees against an employee on the agreement including the statute's whistleblower immunity notice (18 U.S.C. § 1833(b)). If your NDA template predates 2016 or was never reviewed for this, it is worth fixing.

Access. Need-to-know beats trust. Limit repository and database access to roles that need it, log everything, and review access when roles change.

Offboarding. A consistent exit process, return of devices, revocation of credentials, a reminder of confidentiality obligations, and a certification that company data has been returned, both deters theft and builds your "reasonable measures" record.

One more Illinois-specific point: do not assume a non-compete will save you. The Illinois Freedom to Work Act (820 ILCS 90) makes non-competes unenforceable against employees earning $75,000 a year or less, and non-solicitation covenants unenforceable below $45,000, with strict requirements even above those thresholds. For many technology teams, trade secret law and well-drafted confidentiality agreements do most of the real work.

Talk to Us Early

Our practice combines software and technology litigation with intellectual property litigation, and departing-employee trade secret matters sit exactly at that intersection. Whether you need to stop an active leak or pressure-test your protections before there is a problem, contact The Law Office of Krista Krepp at contact@krepplaw.com or schedule a consultation online.

Frequently Asked Questions

The employee never signed a non-compete. Can we still sue? Yes. Trade secret claims do not require a non-compete. The DTSA and ITSA protect the information itself. A confidentiality agreement strengthens the case, but even without one, an employee who takes company data can be liable for misappropriation.

Is our customer list a trade secret in Illinois? It can be, but it is not automatic. A curated list with contact histories, pricing, and preferences that the company restricted access to is a much stronger candidate than a list of names that could be reconstructed from LinkedIn. How you guarded the list matters as much as what is in it.

How fast do we need to act? The limitations periods are 3 years under the DTSA and 5 years under the ITSA, but those numbers are misleading. The remedies that actually protect a business, TROs and preliminary injunctions, depend on urgency. Weeks matter; months can be fatal to emergency relief.

Should we sue in federal or state court? It depends on the defendants, the forensic discovery you need, and strategy. The DTSA opens the federal courthouse door, and most software cases qualify. We often plead both statutes and choose the forum based on the specific case.

We cannot prove any lost sales yet. Is it worth pursuing? Often, yes. Damages can be measured by the defendant's unjust enrichment or a reasonable royalty, not just your lost profits. And in many cases the injunction, stopping the use before it becomes a competing product, is worth more than any damages award.

What counts as "reasonable measures" to protect a trade secret? Courts look at the whole picture: confidentiality agreements, access controls, password and encryption practices, marking or segregating sensitive material, and how the company handled departures. Perfection is not required. Indifference is disqualifying.

Have a Question About Your Case?

Based in Chicago. Licensed in Illinois and Wisconsin. Serving clients nationwide. Free consultations.

Schedule a Consultation