When a Key Employee Leaves: What Happens to Your Business Information?

Why Arizona Business Owners Should Protect Access, Confidential Information, and Digital Assets Before an Employee Resigns

When a key employee leaves a business, most owners immediately think about replacing that person's role.

Who will manage their clients? Who will handle their workload? How quickly can someone new be hired?

But there is another question that deserves just as much attention:

What information and access are leaving with them?

A long-term employee may have access to customer lists, pricing information, internal procedures, passwords, vendor relationships, social-media accounts, cloud storage, company devices, and other information that took years to develop.

Waiting until an employee gives notice to decide how that information should be protected can create unnecessary risk. Arizona businesses should have agreements, access controls, and offboarding procedures in place before someone walks out the door.

Not Everything Confidential Is Automatically a Trade Secret

Business owners often use the terms "confidential information" and "trade secret" interchangeably, but they are not necessarily the same thing.

Under Arizona's Uniform Trade Secrets Act, information may qualify as a trade secret when it has independent economic value because it is not generally known or readily ascertainable and when the business takes reasonable steps to maintain its secrecy.¹

Depending on the circumstances, this could include information such as:

  • Nonpublic customer or prospect lists
  • Pricing strategies
  • Proprietary business processes
  • Internal methods or workflows
  • Financial information
  • Vendor terms
  • Marketing strategies
  • Software, formulas, or technical information

But simply calling something confidential does not automatically make it a trade secret.

The steps a business takes to protect the information matter.

If valuable information is available to every employee, shared through unrestricted accounts, stored without meaningful access controls, or routinely distributed outside the company without confidentiality protections, it may become more difficult to establish that the business treated the information as secret.

That is one reason information protection should be an ongoing business practice—not something addressed for the first time after an employee leaves.

Who Has the Passwords?

This sounds like a small administrative issue until it becomes an emergency.

Consider how many accounts may be controlled by one employee:

Company email. Social media. Website administration. Customer relationship management software. Cloud storage. Accounting platforms. Vendor portals. Scheduling systems. Domain registrations. Online advertising accounts.

Now ask a harder question:

Could the business access every one of those accounts tomorrow if that employee were suddenly unavailable?

A business account should not depend entirely on an employee's personal email address, personal phone number, or memory.

Businesses should maintain clear control over administrative credentials and know who has access to critical systems. Federal cybersecurity guidance also recommends limiting employee access to what is necessary for their jobs and promptly terminating system access when an employee leaves.²

For particularly important systems, multifactor authentication can provide an additional layer of protection, but the business should also make sure recovery methods and administrative control do not reside exclusively with one employee.³

Do You Know Where Your Customer Information Is?

Customer information may exist in more places than the company's primary database.

Employees may have customer contact information stored in email accounts, downloaded spreadsheets, mobile phones, cloud folders, text messages, or local files on a laptop.

That creates two concerns when an employee leaves.

First, the company needs continued access to the information necessary to serve its customers.

Second, the company needs to understand whether copies of sensitive information remain on devices or accounts that are no longer under company control.

This becomes particularly important when the information includes personal data.

Arizona's data-breach law requires certain businesses that experience a security incident involving computerized personal information to investigate whether a security system breach occurred. Depending on the circumstances and the information involved, additional notification obligations may follow.⁴

An employee departure does not automatically constitute a data breach. But unexplained downloads, unauthorized transfers, or continued access after employment ends should not simply be ignored.

Company Devices Need an Exit Plan Too

Laptops and phones are obvious, but company property can extend much further.

A departing employee may possess:

  • Computers or tablets
  • External hard drives
  • USB drives
  • Security keys
  • Building-access cards
  • Physical customer files
  • Credit cards
  • Equipment
  • Authentication devices
  • Printed documents

Businesses should maintain an inventory of company property and establish a consistent return process.

The same principle applies to digital property. Account access should be transferred, passwords changed when appropriate, administrative privileges reassigned, and former employees' access disabled promptly.

The Federal Trade Commission specifically recommends procedures to ensure departing workers no longer have access to sensitive information, including terminating passwords and collecting access credentials as part of the checkout process.⁵

Social Media Can Become a Surprisingly Difficult Problem

A company's social-media account may feel like a marketing tool, but it is also a business asset.

Problems arise when an employee creates or manages an account using a personal email address, personal phone number, or personal login credentials.

If that employee leaves, the business may suddenly discover that it does not have administrative access to an account containing years of content, followers, messages, advertising history, and customer interaction.

Businesses should establish from the beginning that company accounts are created and maintained using business-controlled credentials whenever possible.

There should also be more than one authorized administrator for critical accounts.

The goal is simple: the business should not lose access to an important digital asset simply because one employee leaves.

Written Agreements Matter Before the Relationship Ends

Good employee documentation can help establish expectations while the relationship is still healthy.

Depending on the employee's position and access, agreements or policies may address:

  • Confidentiality obligations
  • Use of proprietary information
  • Ownership of company-created materials
  • Acceptable use of company systems
  • Return of company property
  • Password and account management
  • Data-security responsibilities
  • Obligations that continue after employment ends

For information that may qualify as a trade secret, these agreements can also help demonstrate that the business has taken steps to maintain confidentiality.

Arizona law permits remedies for actual or threatened trade-secret misappropriation, including injunctive relief and, in appropriate circumstances, monetary damages.⁶ Federal trade-secret law may provide additional remedies when its requirements are satisfied.⁷

Employers should also be aware that federal law contains specific whistleblower-immunity notice requirements for certain agreements governing the use of trade secrets or confidential information. Failure to include the required notice can affect an employer's ability to recover certain remedies under the federal Defend Trade Secrets Act.⁸

This is one reason copying a generic confidentiality agreement from the internet may not provide the protection a business assumes it does.

Create an Offboarding Process Before You Need One

The best time to create an employee offboarding procedure is not the afternoon someone resigns.

A practical process might include:

  1. Identifying the systems, files, and physical property the employee can access.
  2. Transferring responsibility for customers, projects, and accounts.
  3. Recovering company-owned equipment and records.
  4. Removing access to email, cloud platforms, databases, and other systems.
  5. Changing shared passwords when necessary.
  6. Confirming administrative control of websites and social-media accounts.
  7. Reviewing confidentiality and post-employment obligations.
  8. Preserving business records that may be needed later.
  9. Documenting that access and property have been returned.

Not every employee presents the same level of risk. A receptionist, senior salesperson, IT administrator, and chief financial officer may require very different offboarding procedures.

Your process should reflect what each person can access.

Protect the Business Before There Is a Problem

Most employee departures are professional and uneventful.

Good policies are not about assuming every departing employee intends to harm the business. They are about making sure the business continues to control its own information, accounts, relationships, and property regardless of who comes and goes.

A few thoughtful steps taken while an employee is still with the company can prevent significant uncertainty later.

At Obsidian Ridge Law, we help Arizona business owners create agreements and legal processes designed to protect the businesses they have worked hard to build.

If you have questions about confidentiality agreements, business policies, or protecting your company's information when employees come and go, schedule a free 15-minute consultation with Obsidian Ridge Law.

¹ A.R.S. § 44-401(3), Arizona Uniform Trade Secrets Act. Arizona defines a trade secret to include certain information that derives actual or potential independent economic value from not being generally known or readily ascertainable and is subject to efforts that are reasonable under the circumstances to maintain its secrecy.
² Federal Trade Commission, Protecting Personal Information: A Guide for Business. The FTC recommends restricting access to sensitive information based on business need and maintaining procedures to prevent departing workers from retaining access.
³ Cybersecurity and Infrastructure Security Agency, Require Multifactor Authentication. CISA recommends MFA for business systems, particularly email, file storage, remote access, administrative accounts, and systems containing sensitive information.
⁴ A.R.S. §§ 18-551 and 18-552, Arizona's security-breach statutes. Arizona law defines security incidents and breaches involving certain computerized personal information and requires a business that becomes aware of a qualifying security incident to investigate whether a breach occurred.
⁵ Federal Trade Commission, Protecting Personal Information: A Guide for Business; Start with Security. FTC guidance recommends disabling access and passwords for departing employees and incorporating credential and property recovery into the employee checkout process.
⁶ A.R.S. §§ 44-402 and 44-403. Arizona's Uniform Trade Secrets Act authorizes injunctive relief for actual or threatened misappropriation and provides for damages in appropriate cases.
⁷ 18 U.S.C. § 1836, Defend Trade Secrets Act. Federal law permits an owner of a qualifying trade secret related to interstate or foreign commerce to bring a civil action for misappropriation and provides various remedies where statutory requirements are met.
⁸ 18 U.S.C. § 1833(b). Federal law requires employers to provide notice of specified whistleblower immunity in certain contracts or agreements with employees governing trade secrets or confidential information. The statute defines “employee” for this purpose to include contractors and consultants and limits certain federal remedies when the required notice is not provided.

Next
Next

Has Your Service-Connected Condition Gotten Worse?