IT Forensics · Business

How can a company check whether a departing employee has taken company data with them?

When an employee leaves the company, there may be a suspicion that company data has been copied or transferred. However, the timing alone does not prove that data has been taken.

Enquire without obligation

Why this question is important for a business

In the event of potential data leaks, significant economic assets, customer relationships, development know-how or competitive advantages are often at stake. A robust investigation must therefore precisely establish what data movements actually took place, without jumping to the conclusion that a legal infringement has occurred merely on the basis of a suspicion.

Technical investigative approach

We identify the specific relevant data sets and examine suitable traces relating to file operations, external storage media, cloud storage, email or other transmission channels.

Where the limits of what can be said lie

Increased file activity shortly before leaving the organisation is not in itself proof of unauthorised removal of data. Handover, archiving or project work must be considered as alternative explanations.

Why LanCologne?

Any suspicion of data theft or the loss of confidential company information can have significant financial and legal consequences. This is precisely why the investigation must not begin with the desired outcome in mind.

LanCologne first translates the facts of the case into specific technical questions of evidence: Which files or data sets are affected? Were they actually opened, copied, exported, archived or transferred? Which technical transmission route can be verified? When did this take place? Which device, account or session context can be substantiated?

In this context, we make a strict distinction between the possibility of access, actual access, the copying process and a successful transfer. In practice, these terms are often used interchangeably, even though they describe technically distinct phenomena.

Key findings are, as far as possible, verified against primary data and cross-referenced with independent sources. An automated alert, a tool report or an individual timestamp is not accepted as evidence without verification.

Similarly, standard alternative explanations are investigated. Handover processes, project archives, backups, synchronisation, software updates or authorised cloud usage can generate traces that appear suspicious without context. Only once such explanations have been narrowed down on the basis of the data is a robust technical assessment possible.

For LanCologne, even a finding that exonerates the suspect constitutes a complete investigation result. If an alleged data transfer cannot be confirmed, this is documented in the same way as a verifiable transfer.

How we work

1Document the grounds for suspicion and the specific technical issue to be established.
2Define the legal framework and responsibilities in consultation with the company or legal advisers.
3Narrow down the relevant data sets, devices, accounts and time periods.
4Obtain variable evidence data at an early stage.
5Document data sources, provenance and integrity information.
6Separate access, copying, exporting, archiving and transfer from one another from a technical perspective.
7Identify target media and transmission routes solely on the basis of specific evidence.
8Do not confuse device, account and user assignments.
9Also check standard work processes and other possible explanations.
10Document the technical measures taken to protect alleged trade secrets, where relevant.
11Present positive, negative and inconclusive findings on an equal footing.
12Make a clear distinction between technical findings and legal assessments.

A trade secret is a legal classification – data movement is a technical question of evidence

We can determine or narrow down which files were present, what technical protection measures were in place, and which acts of access, copying or transfer can be verified. Whether the information in question meets the criteria for a trade secret and whether an act was unauthorised or unlawful is assessed separately from a legal perspective.

No jumping to conclusions – not even when transfer patterns are conspicuous

Unusually high file access, a USB connection or a cloud login may give rise to further investigation, but do not in themselves constitute a conclusion. Alternative workflows are also examined. Where several explanations remain possible, this uncertainty is not replaced by an assumption.

Why LanCologne in the context of data portability and trade secrets?

LanCologne does not carry out investigations with the aim of confirming a pre-existing suspicion. We answer the specific technical question of evidence, document the underlying primary data and state just as clearly what cannot be proven. This provides the management and legal department with a factual basis that can also withstand subsequent technical cross-checking.

Legal framework

Where employees are concerned, Section 26 of the Federal Data Protection Act (BDSG) remains a key starting point. For the detection of criminal offences, Section 26(1) of the BDSG requires, amongst other things, documented factual grounds, necessity and proportionality; the employee’s legitimate interest must not outweigh these considerations. In addition, the principles of the GDPR apply, in particular lawfulness, purpose limitation and data minimisation.

The GeschGehG is central to trade secrets. Under Section 2(1) of the Trade Secrets Act, not all confidential information is sufficient: amongst other things, the information must have economic value because it is not generally known or readily accessible; it must be subject to confidentiality measures appropriate to the circumstances; and there must be a legitimate interest in maintaining its confidentiality.

Section 4 of the Trade Secrets Act (GeschGehG) prohibits, under certain conditions, amongst other things, unauthorised access to, unauthorised appropriation of, or unauthorised copying of electronic files that contain a trade secret or from which one can be derived. Use and disclosure may also be prohibited. It is not for the IT forensic expert to determine whether a technically verified incident fulfils the legal elements of an offence.

The Business Secrets Protection Act (GeschGehG) also contains exceptions. Section 5 specifically lists certain acts carried out to protect legitimate interests, including, subject to certain conditions, the disclosure of unlawful acts or professional or other misconduct. In addition, the Whistleblower Protection Act may be relevant. Section 6 of the HinSchG governs, under certain conditions, the disclosure or revelation of trade secrets in the context of protected reports. A suspected data leak must therefore not automatically be equated with an unlawful breach of confidentiality.

The GeschGehG provides for potential civil law claims in the event of established infringements, including rectification and injunctions (Section 6), further measures under Section 7, certain rights to information under Section 8, and compensation for damages under Section 10. Which claims apply in individual cases must be assessed from a legal perspective. IT forensics merely provides the technical factual basis for this.

Where technical equipment is used for the monitoring of staff, the works council’s rights of participation, in particular under Section 87(1)(6) of the Works Constitution Act (BetrVG), may also be relevant. The specific admissibility of such measures will be clarified by the relevant internal and legal bodies prior to the investigation.

Frequently Asked Questions

How can a company check whether a departing employee has taken company data with them?+
In the event of potential data leaks, significant economic assets, customer relationships, development know-how or competitive advantages are often at stake. A robust investigation must therefore precisely establish what data movements actually took place, without jumping to the conclusion that a legal infringement has occurred merely on the basis of a suspicion.
How is such a technical investigation carried out in practice?+
We identify the specific relevant data sets and examine suitable traces relating to file operations, external storage media, cloud storage, email or other transmission channels.
Does the investigation always produce a clear-cut result, either for or against a person involved?+
Increased file activity shortly before leaving the organisation is not in itself proof of unauthorised removal of data. Handover, archiving or project work must be considered as alternative explanations.
Is there a legal basis for this?+
Where employees are concerned, Section 26 of the Federal Data Protection Act (BDSG) remains a key starting point. For the detection of criminal offences, Section 26(1) of the BDSG requires, amongst other things, documented factual grounds, necessity and proportionality; the employee’s legitimate interest must not outweigh these requirements. In addition, the principles of the GDPR apply, in particular lawfulness, purpose limitation and data minimisation. The Trade Secrets Act (GeschGehG) is central to the protection of trade secrets. Under Section 2(1) of the Trade Secrets Act (GeschGehG), not all confidential information is sufficient: the information must, amongst other things, have economic value because it is not generally known or readily accessible; it must be subject to confidentiality measures appropriate to the circumstances; and there must be a legitimate interest in maintaining confidentiality. Section 4 of the Trade Secrets Act (GeschGehG) prohibits, under certain conditions, amongst other things, unauthorised access to, unauthorised appropriation of or unauthorised copying of electronic files which contain a trade secret or from which one can be derived. Use and disclosure may also be prohibited. It is not for the IT forensic expert to determine whether a technically verified incident fulfils the legal elements of an offence. The GeschGehG also contains exceptions. Section 5 specifically lists certain acts carried out to protect legitimate interests, including, under certain conditions, the detection of unlawful acts or professional or other misconduct. In addition, the Whistleblower Protection Act may be relevant. Section 6 of the Whistleblower Protection Act (HinSchG) regulates, under certain conditions, the disclosure of trade secrets in the context of protected reports. A suspicion of data leakage must therefore not automatically be equated with an unlawful breach of confidentiality. The Trade Secrets Act (GeschGehG) provides for possible civil law claims in the event of established infringements, including rectification and injunctions (Section 6), further measures under Section 7, certain rights to information under Section 8 and compensation for damages under Section 10. Which claims apply in individual cases must be assessed from a legal perspective. IT forensics merely provides the technical factual basis for this. Where technical devices are used for employee monitoring, the works council’s rights of participation, in particular under Section 87(1)(6) of the Works Constitution Act (BetrVG), may also be relevant. The specific admissibility of such measures must be clarified by the relevant company and legal authorities prior to the investigation.

LanCologne – IT Forensics for Businesses

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now