IT Forensics · Business
Why should a company engage LanCologne at an early stage if it suspects data theft or a breach of trade secrets?
In the event of potential data leaks, evidence may be lost through normal use, account deactivation, the reallocation of devices, data retention or hastily implemented countermeasures.
Why this question is important for a business
In the event of potential data leaks, significant economic assets, customer relationships, development know-how or competitive advantages are often at stake. A robust investigation must therefore precisely establish what data movements actually took place, without jumping to the conclusion that a legal infringement has occurred merely on the basis of a suspicion.
Technical investigative approach
LanCologne works with the client to define a specific technical question to be investigated, obtains relevant data sets, reconstructs possible pathways of transfer, and documents both incriminating and exonerating findings in a reproducible manner.
Where the limits of what can be said lie
Our remit is not to convict an employee of stealing confidential information. We identify which data movements can be technically verified and where the evidence ends.
Why LanCologne?
Any suspicion of data theft or the loss of confidential company information can have significant financial and legal consequences. This is precisely why the investigation must not begin with the desired outcome in mind.
LanCologne first translates the facts of the case into specific technical questions of evidence: Which files or data sets are affected? Were they actually opened, copied, exported, archived or transferred? Which technical transmission route can be verified? When did this take place? Which device, account or session context can be substantiated?
In this context, we make a strict distinction between the possibility of access, actual access, the copying process and a successful transfer. In practice, these terms are often used interchangeably, even though they describe technically distinct phenomena.
Key findings are, as far as possible, verified against primary data and cross-referenced with independent sources. An automated alert, a tool report or an individual timestamp is not accepted as evidence without verification.
Similarly, standard alternative explanations are investigated. Handover processes, project archives, backups, synchronisation, software updates or authorised cloud usage can generate traces that appear suspicious without context. Only once such explanations have been narrowed down on the basis of the data is a robust technical assessment possible.
For LanCologne, even a finding that exonerates the suspect constitutes a complete investigation result. If an alleged data transfer cannot be confirmed, this is documented in the same way as a verifiable transfer.
How we work
A trade secret is a legal classification – data movement is a technical question of evidence
We can determine or narrow down which files were present, what technical protection measures were in place, and which acts of access, copying or transfer can be verified. Whether the information in question meets the criteria for a trade secret and whether an act was unauthorised or unlawful is assessed separately from a legal perspective.
No jumping to conclusions – not even when transfer patterns are conspicuous
Unusually high file access, a USB connection or a cloud login may give rise to further investigation, but do not in themselves constitute a conclusion. Alternative workflows are also examined. Where several explanations remain possible, this uncertainty is not replaced by an assumption.
Why LanCologne in the context of data portability and trade secrets?
LanCologne does not carry out investigations with the aim of confirming a pre-existing suspicion. We answer the specific technical question of evidence, document the underlying primary data and state just as clearly what cannot be proven. This provides the management and legal department with a factual basis that can also withstand subsequent technical cross-checking.
Legal framework
Where employees are concerned, Section 26 of the Federal Data Protection Act (BDSG) remains a key starting point. For the detection of criminal offences, Section 26(1) of the BDSG requires, amongst other things, documented factual grounds, necessity and proportionality; the employee’s legitimate interest must not outweigh these considerations. In addition, the principles of the GDPR apply, in particular lawfulness, purpose limitation and data minimisation.
The GeschGehG is central to trade secrets. Under Section 2(1) of the Trade Secrets Act, not all confidential information is sufficient: amongst other things, the information must have economic value because it is not generally known or readily accessible; it must be subject to confidentiality measures appropriate to the circumstances; and there must be a legitimate interest in maintaining its confidentiality.
Section 4 of the Trade Secrets Act (GeschGehG) prohibits, under certain conditions, amongst other things, unauthorised access to, unauthorised appropriation of, or unauthorised copying of electronic files that contain a trade secret or from which one can be derived. Use and disclosure may also be prohibited. It is not for the IT forensic expert to determine whether a technically verified incident fulfils the legal elements of an offence.
The Business Secrets Protection Act (GeschGehG) also contains exceptions. Section 5 specifically lists certain acts carried out to protect legitimate interests, including, subject to certain conditions, the disclosure of unlawful acts or professional or other misconduct. In addition, the Whistleblower Protection Act may be relevant. Section 6 of the HinSchG governs, under certain conditions, the disclosure or revelation of trade secrets in the context of protected reports. A suspected data leak must therefore not automatically be equated with an unlawful breach of confidentiality.
The GeschGehG provides for potential civil law claims in the event of established infringements, including rectification and injunctions (Section 6), further measures under Section 7, certain rights to information under Section 8, and compensation for damages under Section 10. Which claims apply in individual cases must be assessed from a legal perspective. IT forensics merely provides the technical factual basis for this.
Where technical equipment is used for the monitoring of staff, the works council’s rights of participation, in particular under Section 87(1)(6) of the Works Constitution Act (BetrVG), may also be relevant. The specific admissibility of such measures will be clarified by the relevant internal and legal bodies prior to the investigation.
Frequently Asked Questions
Why should a company engage LanCologne at an early stage if it suspects data theft or a breach of trade secrets?
How is such a technical investigation carried out in practice?
Does the investigation always produce a clear-cut result, either for or against a person involved?
Is there a legal basis for this?
The GeschGehG is central to trade secrets. Under Section 2(1) of the Trade Secrets Act, not all confidential information is sufficient: amongst other things, the information must have economic value because it is not generally known or readily accessible; it must be subject to confidentiality measures appropriate to the circumstances; and there must be a legitimate interest in maintaining its confidentiality.
Section 4 of the Trade Secrets Act (GeschGehG) prohibits, under certain conditions, amongst other things, unauthorised access to, unauthorised appropriation of, or unauthorised copying of electronic files that contain a trade secret or from which one can be derived. Use and disclosure may also be prohibited. It is not for the IT forensic expert to determine whether a technically verified incident fulfils the legal elements of an offence.
The Business Secrets Protection Act (GeschGehG) also contains exceptions. Section 5 specifically lists certain acts carried out to protect legitimate interests, including, subject to certain conditions, the disclosure of unlawful acts or professional or other misconduct. In addition, the Whistleblower Protection Act may be relevant. Section 6 of the HinSchG governs, under certain conditions, the disclosure or revelation of trade secrets in the context of protected reports. A suspected data leak must therefore not automatically be equated with an unlawful breach of confidentiality.
The GeschGehG provides for potential civil law claims in the event of established infringements, including rectification and injunctions (Section 6), further measures under Section 7, certain rights to information under Section 8, and compensation for damages under Section 10. Which claims apply in individual cases must be assessed from a legal perspective. IT forensics merely provides the technical factual basis for this.
Where technical equipment is used for the monitoring of staff, the works council’s rights of participation, in particular under Section 87(1)(6) of the Works Constitution Act (BetrVG), may also be relevant. The specific admissibility of such measures will be clarified by the relevant internal and legal bodies prior to the investigation.
🔗 Related topics
LanCologne – IT Forensics for Businesses
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How can a company find out exactly which files have been copied onto a USB storage device?
- How can one check whether source code was copied or exported before a developer left the company?
- How can a company arrange for a forensic investigation into the possible misappropriation of customer lists?
- How can the possible unauthorised copying of price lists, cost calculations or quotation data be technically verified?