Vassilev & Chisuse Law Firm ยท 2026-09-23
Unauthorised copying or transfer of corporate information by an employee through a USB device, personal email account, cloud storage or another external channel may engage several areas of Bulgarian law simultaneously, including trade secret protection, employment law, competition law, data protection and, in certain circumstances, criminal law.
Particularly sensitive information may include pricing models, cost calculations, individual discounts, customer and supplier databases, algorithms, project documentation, technological information and know-how. Not every piece of internal or confidential information, however, qualifies as a trade secret, and not every unauthorised transfer gives rise to the same legal consequences.
The legal position depends primarily on whether the information satisfies the statutory criteria for a trade secret, what protective measures the company had implemented, how the employee acquired and used the information and what damage or other consequences can be established.
When Does Corporate Information Qualify as a Trade Secret?Under Article 3 of the Bulgarian Trade Secret Protection Act, information qualifies as a trade secret only if three cumulative conditions are met. The information must be secret, it must have commercial value because it is secret, and measures must have been taken by the person controlling the information to preserve its secrecy.
A customer list, pricing policy, algorithm or technological process therefore does not automatically become a trade secret merely because the employer describes it as confidential. The company must also be able to demonstrate the commercial significance of the information and the actual arrangements used to restrict and control access to it.
The Trade Secret Protection Act treats the acquisition of a trade secret without the holder's consent as unlawful where it results from unauthorised access to, appropriation or copying of documents, materials or electronic documents containing the trade secret or information from which it can be derived. Subsequent use or disclosure may also be unlawful.
Is a General Confidentiality Clause Sufficient?A confidentiality clause is an important part of the protection framework, but it does not by itself guarantee that every category of information identified by the employer will qualify for statutory trade secret protection. Protection under the Trade Secret Protection Act also depends on evidence that measures were actually taken to preserve secrecy.
Employers should therefore identify protected categories of information with sufficient precision, restrict access according to employees' functions, document access permissions and implement technical and organisational safeguards appropriate to the nature and value of the information.
In Decision No. 50077 of 11 May 2023 in Civil Case No. 2835/2022, the majority of the Bulgarian Supreme Court of Cassation accepted that a confidentiality agreement may validly specify categories of confidential information. In the same judgment, the particular pre-agreed penalty clause was held invalid, with the Court stating that the actual damage and its amount had to be proven. The judgment contains a dissenting opinion, so the decision should not be reduced to a broader proposition that every contractual penalty connected with confidentiality is either valid or invalid regardless of its legal structure and circumstances.
Can a Former Employee Join a Competitor?Trade secret legislation does not provide a general legal basis for restricting employee mobility. Both the Bulgarian Trade Secret Protection Act and Directive (EU) 2016/943 preserve employees' ability to use information that is not a trade secret, as well as experience and skills honestly acquired in the normal course of employment.
The Bulgarian Supreme Court of Cassation has held that a clause in an employment agreement or an annex restricting an employee from working for a competitor for a specified period after termination conflicts with the constitutionally protected freedom to choose an occupation and place of work.
This does not entitle a former employee to copy, disclose or use another party's trade secrets. The relevant distinction is between the legitimate use of professional experience and skills and the unlawful use of specific protected information. Statutory trade secret protection continues for as long as the information satisfies the requirements of the Trade Secret Protection Act.
What Liability May the Employee Face?While the employment relationship remains in force, unauthorised extraction or disclosure of confidential information may give rise to disciplinary consequences. Article 126(9) of the Bulgarian Labour Code requires employees to remain loyal to their employer, refrain from abusing the employer's trust and refrain from disclosing confidential information. Abuse of trust and disclosure of confidential information are breaches of employment discipline, and Article 190(1)(4) allows disciplinary dismissal where the statutory requirements are met and the seriousness of the particular breach justifies that sanction.
Financial liability must be assessed according to the relevant legal basis and the form of fault. Where an employee negligently causes damage in or in connection with the performance of employment duties, the Labour Code provides for limited financial liability. The employee is liable for actual loss but not lost profits, normally up to the agreed monthly remuneration. Where the damage is caused by a manager in or in connection with the performance of managerial functions, liability may reach three times the agreed monthly remuneration.
The Trade Secret Protection Act contains a separate rule for damage resulting from the unlawful acquisition, use or disclosure of an employer's trade secret. Under Article 18(2), where an employee did not act intentionally, liability may not exceed three times the agreed remuneration. Where the conduct was intentional, that specific statutory cap does not apply, while Article 18(1) provides for compensation for damage and lost profits that are a direct and immediate consequence of the infringement, subject to the other statutory conditions.
Criminal liability does not arise from every trade secret leak. Depending on the facts, the Criminal Code provisions on unauthorised access to an information system and on the unlawful copying, use, transfer, alteration or deletion of computer data may become relevant. Where an advantage is requested, offered or provided in return for conduct in breach of duties in commercial activity, the relevant commercial bribery provisions may also need to be considered. Criminal liability requires all elements of the particular offence to be established and should not be inferred merely from the fact that corporate information has been copied.
Can the Competitor Receiving the Information Be Liable?Liability may extend to a company that acquires or uses unlawfully obtained trade secrets. Under Article 8(3) of the Trade Secret Protection Act, acquisition, use or disclosure is unlawful where, at the relevant time, the recipient knew or, in the circumstances, ought to have known that the trade secret had been obtained directly or indirectly from another person who was using or disclosing it unlawfully.
Depending on the particular conduct, the Bulgarian Protection of Competition Act may also apply, including its rules on unfair competition and the unlawful use or disclosure of another undertaking's production or trade secrets. For infringements falling within Chapter Seven of the Act, the Bulgarian Commission for Protection of Competition may impose a pecuniary sanction of up to 10 per cent of the undertaking's total turnover for the preceding financial year. This sanction framework remains applicable following the amendments to the Protection of Competition Act adopted in 2026.
In addition to administrative proceedings, an injured party may seek compensation where the statutory requirements are satisfied. The existence of an infringement, causation and the amount of the claimed damage must be established in the particular proceedings.
What If the Leaked Files Contain Personal Data?Where copied files contain names, telephone numbers, email addresses, job titles or other information relating to identified or identifiable individuals, the incident must also be assessed under the General Data Protection Regulation (GDPR).
Unauthorised disclosure of or access to personal data may constitute a personal data breach. Under Article 33 GDPR, the controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. In Bulgaria, the supervisory authority is the Commission for Personal Data Protection.
Where the personal data breach is likely to result in a high risk to the rights and freedoms of individuals, Article 34 GDPR requires the controller to communicate the breach to the affected data subjects without undue delay, subject to the exceptions expressly provided by the Regulation.
For an ordinary private-sector employer, the notification regime for this type of incident is based on Articles 33 and 34 GDPR. Articles 63 and 67 of the Bulgarian Personal Data Protection Act form part of the separate regime governing processing by competent authorities for criminal law enforcement purposes and should not be treated as the general statutory basis for corporate data breach notifications.
What Court Protection Is Available?The Trade Secret Protection Act allows protective measures to be sought before the dispute has been finally resolved. Under Article 14, a trade secret holder may request provisional measures before the claim is filed or while the proceedings are pending, including temporary cessation or prohibition of the use or disclosure of the trade secret. The Act also provides measures relating to goods and services connected with the alleged infringement.
In the main proceedings, Article 10 allows the trade secret holder to seek a finding of unlawful acquisition, use or disclosure, compensation for damage and lost profits, cessation or prohibition of use or disclosure and, where appropriate, the destruction or surrender of documents, materials and electronic documents containing the trade secret.
Speed can be particularly important in cases involving electronic information because the ability to prove what occurred may depend on preserving technical evidence that can otherwise be altered or lost.
How Can Unauthorised Copying and Damage Be Proven?Technical evidence can be central to disputes involving the alleged extraction of corporate files. A forensic computer examination may assist in establishing the use of external devices, the chronology of file operations, access to information systems and other digital traces, provided that the relevant evidence has been collected and preserved lawfully.
System logs, corporate email and cloud records, access information from CRM or ERP systems and document metadata may help establish the time, method and scope of a particular transfer. No individual technical indicator should, however, automatically be treated as conclusive evidence that a trade secret was unlawfully used. The available evidence must be assessed as a whole.
Damage and lost profits must also be proven. The fact that information was unlawfully copied does not in itself establish the amount of an alleged loss of customers or future revenue. A damages claim must be supported by concrete facts demonstrating a causal link between the infringement and the economic loss claimed. Article 18 of the Trade Secret Protection Act expressly limits recoverable damage and lost profits to those that are a direct and immediate consequence of the unlawful acquisition, use or disclosure.
How Can Businesses Protect Trade Secrets Before an Incident?Effective protection requires a combination of legal, organisational and technical measures. The objective is not merely to label information as confidential, but to ensure that the company can subsequently demonstrate how the information was identified and protected.
An internal trade secret policy may define protected categories with sufficient precision, including pricing, customer and supplier databases, technological documentation, algorithms and know-how. Employment agreements, job descriptions and separate confidentiality documentation may further specify applicable duties without attempting to expand the statutory concept of a trade secret beyond its legal requirements.
Access to sensitive systems may be structured on a Need-to-Know basis so that employees can access only the information required for their functions. Depending on the particular risk, safeguards may include restrictions on external storage devices, encryption, Data Loss Prevention systems and reliable logging of access, copying, export and deletion activities.
A documented exit procedure may provide for timely termination of access to corporate email, CRM and ERP systems, VPN services and cloud environments, return of company devices and confirmation of continuing confidentiality obligations.
These measures have a dual purpose. They reduce the practical risk of information leakage and can help demonstrate one of the core requirements under Article 3 of the Trade Secret Protection Act, namely that measures were taken to preserve the secrecy of the information.
Legal Assistance with Employee Trade Secret LeaksVassilev & Chisuse Law Firm provides legal assistance in matters involving trade secret protection, employment law, competition law and data protection. The assistance may include preparing and reviewing internal information classification and protection rules, confidentiality agreements and clauses, legal review of information security and GDPR compliance procedures, as well as representation in trade secret claims, applications for provisional measures, damages proceedings and proceedings before the Bulgarian Commission for Protection of Competition.
This material is provided for general information purposes only. It does not constitute individual legal advice or a binding recommendation to take or refrain from any particular action. The legal classification of a particular incident and the appropriate response to unauthorised access, copying or use of corporate information depend on the specific facts, contractual arrangements and available evidence.