Competitive Intelligence and Benchmarking Toolkit: Lawful Collection, Clean Rooms, and Contamination

By ·

Competitive intelligence is lawful, valuable, and one wrong hire away from a misappropriation claim. This toolkit assembles the working material for practitioners advising businesses that gather information about competitors, benchmark against them, take their products apart, or hire their people. It covers the line between proper and improper means and the source classification scheme that operationalises it. It sets out the documentation that makes a reverse engineering exercise defensible and the clean room procedures that keep a development team demonstrably independent. Later sections cover hiring and onboarding controls, benchmarking aggregation and the information exchange question, and the escalation protocol for the moment contamination is discovered. It closes with clause language, worked scenarios, an authorities table, and the failures that recur.

IP and Technology > Trade Secrets | Toolkit | Published 3 April 2026 - Updated 3 May 2026 | Casey Scott McKay - marksy.us

Summary. Competitive intelligence is lawful and is one wrong hire from a misappropriation claim. This toolkit covers the improper means line, source classification, documentation that makes reverse engineering defensible, clean room construction and its failure modes, hiring and onboarding controls, benchmarking aggregation and the information exchange question, and the contamination escalation protocol for the moment somebody realises what is on a laptop.

Keywords: competitive intelligence · lawful collection · improper means · source classification · reverse engineering records · clean rooms · contamination response · hiring controls · onboarding firewalls · benchmarking aggregation · information exchange · pretexting · scraping and terms · protective order handling · departure forensics


Start Here

Competitive intelligence sits on a line that is clearer in doctrine than in practice.

Acquisition by proper means is lawful. 18 U.S.C. § 1839 defines misappropriation by reference to improper means and expressly excludes reverse engineering, independent derivation, and other lawful means of acquisition. Observing a competitor, buying its products, reading its filings, and analysing its public statements are all proper.

Acquisition by improper means is not. Theft, bribery, misrepresentation, breach of a duty to maintain secrecy, inducement of such a breach, and espionage are improper. So is the classic middle case: E.I. DuPont deNemours & Co. v. Christopher held that aerial photography of a plant under construction was improper even though nothing unlawful was done, because the conduct fell below generally accepted standards of commercial morality.

The line in practice is about people and documents, not about doctrine. Almost every real dispute in this area involves an employee who moved, a document that travelled with them, and a development team that saw something it should not have.

And the exposure runs both ways. A business collecting intelligence risks a misappropriation claim; a business whose people leave risks losing secrets it never documented. The same programme addresses both.

Four questions organise the work.

Where did each piece of information come from, and was that source proper?

Can a development effort be shown to be independent?

What controls apply when somebody joins from a competitor?

And what happens the moment contamination is discovered?

See Learning About Your Competitor Lawfully for the doctrinal treatment, Running a Competitive Intelligence Programme for the sequence, and the Competitive Intelligence Checklist for the working list.


Part one: source classification

The single most useful control in a competitive intelligence programme is a rule that every item of information carries its source.

Green sources — collect freely. Public filings and registrations. Patent and trademark databases. Published financial statements. Marketing material, websites, and price lists. Trade press and analyst reports. Conference presentations and published papers. Job advertisements, which reveal technology choices and expansion plans. Products purchased on the open market. Public regulatory submissions. Court records.

Amber sources — collect with a rule. Customer and supplier conversations, where the counterparty may be under a confidentiality obligation to the competitor. Former employees of the competitor, who may hold obligations. Trade show conversations, where the exhibitor's terms may restrict recording. Site visits, where the visitor's terms may restrict what may be observed. Web scraping, where terms of service apply. Distributor and channel information, which may be contractually restricted.

Red sources — do not collect. Anything obtained by misrepresenting identity or purpose. Anything obtained from a person known or suspected to be breaching a confidentiality obligation. Anything obtained by inducing such a breach. Documents brought by a new hire from a previous employer. Material subject to a protective order in litigation. Anything obtained by unauthorised access to a computer system, which engages 18 U.S.C. § 1030 as narrowed by Van Buren v. United States.

Record the source with the item. A competitive intelligence file that says what a competitor's cost structure is, without saying how that was learned, is an asset in normal times and a liability in a dispute.

Train on the amber category, because that is where good people make mistakes. A sales representative who learns something useful from a customer under a confidentiality obligation has not done anything wrong; the business that acts on it may have.

Prohibit pretexting absolutely. Misrepresenting identity to obtain information is improper means, is a deceptive practice under 15 U.S.C. § 45, and in some contexts is criminal. It is also the technique most likely to be used by an external agency the business has engaged and never asked about methods.

Contract with agencies accordingly, requiring compliance with a stated methods policy, prohibiting pretexting and inducement, and requiring source disclosure with every deliverable.


Part two: reverse engineering, documented

Reverse engineering is expressly lawful as a means of acquisition, and the whole value of that lies in being able to prove it happened.

Establish lawful acquisition of the article. A product bought on the open market, with an invoice, is the strongest position. A sample obtained from a customer under a confidentiality obligation is not, and neither is a unit obtained by misrepresenting who the buyer is.

Check the terms. A purchase subject to a contract prohibiting reverse engineering raises a contract question distinct from the trade secret one, and enforceability varies. Software licences routinely contain such clauses; consumer purchases of hardware rarely do.

Address access controls. Where analysis requires circumventing a technological protection measure, 17 U.S.C. § 1201 applies, with a narrow interoperability exception in subsection (f). The copyright analysis for intermediate copying during analysis runs through Sega Enterprises Ltd. v. Accolade, Inc., Sony Computer Entertainment, Inc. v. Connectix Corp., and, for interface reimplementation, Google LLC v. Oracle America, Inc.. See Taking It Apart and Running a Reverse Engineering or Interoperability Program.

Document contemporaneously. Date of purchase, source, serial number, photographs before disassembly, the analysis performed, the personnel involved, and the findings. A file assembled after a claim is filed is worth a fraction of one assembled as the work happened.

Separate the analysis from the development. The team that takes the product apart should not be the team that designs the replacement, which brings us to clean rooms.

Keep the outputs classified. A reverse engineering report is a document that will be produced in any subsequent litigation, and its tone matters. "We determined the competitor achieves X by Y" is a finding. "We copied their approach to X" is an admission of something the writer probably did not mean.

And remember that the design patent and trade dress questions are separate. A functional insight learned lawfully may be used; a visual design protected by a design patent under 35 U.S.C. § 171 may not be copied, and the ordinary observer test of Egyptian Goddess, Inc. v. Swisa, Inc. applies regardless of how the design was learned.


Part three: clean rooms

A clean room is a procedure for demonstrating independent development, and it fails in predictable ways.

The two-team structure. A specification team analyses the target and produces a functional specification stripped of implementation detail. A development team, with no exposure to the target, builds from that specification. A gatekeeper reviews everything passing between them.

The specification is the control point. It should describe what the product must do, not how the target does it. Implementation detail passing through the gate contaminates the development team and defeats the exercise.

Personnel isolation must be real. Separate physical or logical workspaces, separate document repositories, no shared meetings, and no informal conversations. The most common failure is two people who sit near each other and talk.

Screen the development team. Nobody who has previously worked on the target, worked for the competitor, or seen the target's confidential material.

Log everything. Who was in which team, when, what passed the gate, who approved it, and what each person had access to. The log is the evidence.

Independent supervision. A gatekeeper who reports outside the product organisation, ideally through counsel, so that commercial pressure to pass "just this one detail" meets resistance.

Duration and closure. State when the clean room ends and what happens to the materials.

And be realistic about cost. A clean room roughly doubles the effort of a development project. It is worth it where the alternative is a misappropriation claim with the company's product as the remedy, and it is not worth it for work with no plausible connection to a competitor's confidential information. Decide deliberately rather than by default in either direction. See the Interoperability and Reverse Engineering Checklist.


Part four: hiring, onboarding, and the contaminated laptop

Most trade secret disputes begin with a hire, and most are preventable at the interview.

Screen at the interview. Ask what agreements the candidate is subject to — assignment, confidentiality, non-competition, non-solicitation, and any holdover clause — and obtain copies where they exist. Record the answers.

Do not ask what they know. An interviewer who asks a candidate from a competitor how the competitor solved a technical problem has created a document trail nobody wants.

Assess the risk profile. A candidate moving into a directly overlapping role at a direct competitor is a different proposition from one changing sector. High-risk hires warrant a documented plan.

Give the contamination instruction in writing, before the first day: no documents, no code, no notes, nothing reproduced from memory that is known to be confidential. Obtain a signed acknowledgement. This document is the single best evidence available if a claim is later made.

Do not accept anything. If a new hire offers a document, decline it, record the offer and the refusal, and consider whether the offer itself creates a duty to act.

Check the devices. New hires routinely bring personal laptops and cloud accounts containing former-employer material without any wrongful intent. A pre-start scan or a written attestation reduces this materially.

Consider a temporary assignment away from the directly overlapping area for a defined period, which is the practice most likely to defeat an inevitable disclosure argument of the kind advanced in PepsiCo, Inc. v. Redmond.

Mind the mobility landscape. Restrictive covenant enforceability varies sharply by state, and a hiring business should know the position where the candidate worked and where they will work. See Where an Employee Can Go and the Restrictive Covenant and Departure Checklist.

And run the same discipline on the way out, because the business that hires from competitors is also the business competitors hire from. See the Trade Secret Protection and Departure Checklist.


Part five: benchmarking and the information exchange problem

Benchmarking is competitive intelligence conducted cooperatively, and it raises a different body of law.

Direct exchange between competitors is the danger. Current or forward-looking information about prices, costs, capacity, output, or commercial terms, exchanged between competitors, is the classic concern regardless of whether any agreement follows.

The safe-harbour architecture developed for industry benchmarking has recognisable elements: a neutral third party collects and aggregates; the data is historical rather than current or forward-looking; a minimum number of contributors, with no one contributor dominating any reported figure; outputs are aggregated so that no participant's data is identifiable; and participants receive only the aggregate, not each other's inputs.

Apply those elements deliberately rather than assuming a benchmarking product is fine because everybody does it.

Vendor-mediated benchmarking is the modern form, and it concentrates the risk in the vendor's configuration: contributor counts, aggregation thresholds, lag, and query controls. The vendor's settings become the participants' compliance position.

Trade association activity requires particular care, since the association is a place where competitors meet, and benchmarking is one of the reasons they meet.

The intellectual property overlay matters too: contributed data is licensed rather than transferred, and the licence should address what the vendor may do with it, whether it may serve other industries, what happens on a contributor's withdrawal, and who owns the aggregate.

Document the design. A written aggregation methodology, retained, is what allows the arrangement to be explained years later.

And route the design through competition counsel before the data terms are drafted, because the answer may change the structure. See Where Intellectual Property Stops and Antitrust Starts, Structuring IP Arrangements That Survive Antitrust Review, and the IP Antitrust Checklist.


Part six: contamination response

The moment somebody realises that confidential material of a competitor is inside the business is the moment the programme is tested.

Stop. Suspend the work stream that may be affected, immediately, before anything else.

Preserve. Do not delete. Deletion after discovery is the single worst available response and converts a manageable problem into a spoliation finding under Fed. R. Civ. P. 37(e). Image the devices, preserve the accounts, and suspend automatic deletion.

Escalate to counsel immediately, and conduct the investigation at counsel's direction so that privilege can attach. See Protecting Privilege in an IP Matter.

Scope it. What material, from what source, held by whom, accessed by whom, and used in what.

Isolate and quarantine. Remove access, segregate the material, and record every step.

Assess use. Whether the material influenced any design, decision, or document, which determines whether remediation requires rebuilding rather than deleting.

Consider notification to the other party. This is a genuine judgment call: notification can defuse a matter and can also start one. It is more often right than clients expect, particularly where the material arrived innocently and the business acted promptly.

Remediate. Delete under supervision with certification, retrain the personnel involved, and where work product may be tainted, re-derive it through a clean room.

Record the whole sequence, because the quality of the response is what a court will assess, and a business that discovered a problem and dealt with it promptly is in a very different position from one that discovered it and continued.

And fix the intake. A contamination event that produces no change to hiring, onboarding, or source classification will be followed by another. The claim framework is 18 U.S.C. § 1836, and the litigation shape is set out in Litigating a Trade Secret Misappropriation Claim and the Trade Secret Litigation Checklist.


Clause bank

Agency methods policy. Supplier shall conduct all research in accordance with the Methods Policy at Schedule [A]. Supplier shall not, and shall procure that its personnel and subcontractors shall not: misrepresent their identity, employer, or purpose to any person; approach any current employee of a Target Company; induce any person to breach an obligation of confidence; access any computer system without authorisation; or accept any document that a person is not free to provide. Supplier shall record the source of every item in each deliverable and shall provide the source record with the deliverable. Supplier shall notify Client within [24] hours if any information may have been obtained otherwise than in accordance with this clause.

Reverse engineering record. Before any analysis begins, the Programme Lead shall record: the acquisition source and date of the Article, with supporting invoice; the serial or identifying number; the terms, if any, under which it was supplied; confirmation that no technological protection measure will be circumvented other than as permitted; and the personnel assigned. Photographs shall be taken before disassembly. All findings shall be recorded in the Analysis File, which shall be maintained contemporaneously and retained for [7] years. No member of the Analysis Team may join the Development Team for the Programme.

Clean room protocol. The Specification Team shall have access to the Reference Material. The Development Team shall not. All communication between the teams shall pass through the Gatekeeper, who shall review each item and shall record: the item, the date, the requester, and the decision. The Gatekeeper shall reject any item disclosing implementation detail of the Reference Material. Members of the Development Team shall confirm in writing that they have had no exposure to the Reference Material, no prior employment with [Target], and no access to [Target]'s confidential information. The Gatekeeper reports to the General Counsel and not to the Programme Lead.

Onboarding contamination acknowledgement. I confirm that I have not brought, and will not bring, to [Company] any document, file, code, data, or other material belonging to or obtained from any former employer or other third party. I will not use or disclose in the course of my employment any confidential information of any former employer, whether recorded or recalled from memory. I have disclosed to [Company] all agreements to which I am subject that could restrict my activities, and I have provided copies. I understand that [Company] does not want and will not accept such material, and that I should raise any doubt with the General Counsel before acting.

Benchmarking aggregation standard. The Administrator shall publish no output unless it: aggregates data from no fewer than [N] Participants, with no Participant contributing more than [X] per cent of any reported figure; relates to a period ending no less than [period] before publication; excludes current or forward-looking pricing, cost, capacity, and output information; and cannot be used, alone or with other published outputs, to derive any individual Participant's data. Participants shall not receive one another's inputs. The Administrator shall retain the aggregation methodology and shall make it available to any Participant and to any regulator on request.

Contamination escalation. Any person who becomes aware that material belonging to a third party and obtained otherwise than by proper means may be present within [Company], or that any work may have been influenced by such material, shall notify the General Counsel immediately and shall take no other step. On notification the General Counsel shall: suspend the affected work stream; issue a preservation instruction and suspend automatic deletion; instruct forensic imaging of the relevant devices and accounts; and conduct or direct an investigation. No material shall be deleted, and no device shall be reimaged, without the General Counsel's written authorisation.


Worked scenarios

The helpful new hire. A senior engineer joins from a direct competitor and, wanting to be useful in week one, shares a spreadsheet of the competitor's component costs. Three people see it before anybody objects. The response determines everything: the company suspends the pricing work, preserves the material, images the laptop, investigates under privilege, determines that the sheet influenced no decision, deletes it under supervision with certification, retrains the team, and notifies the competitor. The competitor is unhappy and does not sue, because the response is unimpeachable. A company that had quietly deleted the file and said nothing would have been in a materially worse position when the engineer's former employer ran its own exit forensics — which it did, and which is how the matter came to light.

The clean room that leaked at lunch. A development programme is properly structured with two teams and a gatekeeper. The specification team and the development team sit on the same floor. Over four months, implementation details pass in conversation, and one development engineer's notebook contains a sketch that is recognisably the target's architecture. The clean room documentation is impeccable and the physical arrangement defeated it. The remediation is a genuine relocation and a re-derivation of the affected module.

The benchmarking product that drifted. An industry data vendor's benchmark begins as a historical aggregate and, over three years, adds more granular cuts and shorter lags in response to customer demand. No single change was significant. The cumulative effect is a product reporting near-current pricing by narrow segment with few contributors per cell. Nobody reviewed the design after launch. The fix is a return to the original architecture, and the lesson is that aggregation standards need periodic re-review rather than one-time approval.

The agency nobody asked. A business engages a research firm to profile a competitor's manufacturing operation. The report is unusually detailed. Asked how it was obtained, the agency describes calls made to the competitor's suppliers by a researcher who described themselves as a prospective customer. That is pretexting, it is improper means, and the client now holds a report it cannot use and a problem it did not know it had commissioned. The methods policy clause above costs a paragraph.


Failures that recur

Intelligence held with no record of its source.

An external agency engaged with no methods policy and no source disclosure requirement.

Pretexting by somebody the business did not know it had authorised.

An interviewer asking a candidate how their current employer solves a problem.

A new hire's documents accepted rather than declined.

No written contamination instruction at onboarding, and therefore no evidence of the instruction.

A clean room whose teams share a floor.

Implementation detail passing the gate because the gatekeeper reported to the programme lead.

A reverse engineering file assembled after the claim rather than during the work.

Deletion on discovery, converting a contamination problem into a spoliation problem.

A benchmarking product that drifted toward current, granular, thinly aggregated data without review.

And no exit discipline, so the business that guards against incoming contamination leaks outgoing secrets.



Part seven: building the programme

Name an owner. Competitive intelligence tends to be performed by everybody and governed by nobody: sales gathers it, product analyses it, strategy commissions it, and legal hears about it afterwards.

Write a one-page methods policy. What may be collected, from where, by whom, and what is prohibited. One page, in plain language, distributed to everybody who talks to customers, attends trade shows, or reads competitor material — which is most of the commercial organisation.

Train on the amber cases, since the red ones are obvious and the green ones need no training. The training that changes behaviour is the scenario: a customer offers you a competitor's proposal; a former competitor employee offers to explain their pricing model; a supplier mentions a competitor's volumes.

Build the source field into the system. If intelligence is stored anywhere — a competitor wiki, a battle card repository, a research library — the source field should be mandatory. Items without a source should be flagged rather than usable.

Route all external research through the methods policy, with the agency contract clause above, and audit one deliverable a year against its stated sources.

Establish the clean room decision. A written test for when a development programme needs one, applied at project initiation rather than at legal review, so that the cost is budgeted and the structure is in place from the start.

Integrate with hiring. The interview screen, the offer-stage disclosure, the pre-start contamination instruction, and the high-risk hire plan should be part of the standard recruitment process rather than a legal add-on triggered by seniority.

Rehearse the contamination response once, on paper, with the people who would actually run it. The failure mode is not ignorance of the protocol; it is a manager who deletes a file at nine in the evening because it seemed like the tidy thing to do.

And report it. An annual note to the board covering sources used, agencies engaged, clean rooms run, contamination events and their handling, and any change in the mobility landscape. It takes an hour and it converts an invisible risk into a governed one.


Part eight: the defensive side

Every control in this toolkit has a mirror image, because a business that collects intelligence is also a target.

Know what you are protecting. A trade secret inventory — what it is, where it lives, who has access, and why it qualifies — is the precondition for every other control and for any subsequent claim. Businesses routinely discover at the moment of a departure that their most valuable know-how was never identified as anything.

Segment access. The reasonable measures analysis in Rockwell Graphic Systems, Inc. v. DEV Industries, Inc. turns on what was actually done, and undifferentiated access to everything by everybody defeats it.

Mark deliberately. Over-marking is as damaging as under-marking, because a business that stamps everything confidential has told a court that it treated nothing as special.

Control the plant tour, the conference presentation, the technical paper, and the customer proposal — the four routes by which most genuine secrets leave a business voluntarily.

Watch the supplier layer. A contract manufacturer, an engineering consultancy, or a testing house may hold more of a company's technical detail than any employee. See the Contract Manufacturing IP Checklist.

Run exit forensics on departures to competitors: preserve before reimaging, review access and download logs for the final weeks, and record the destination.

Understand what cannot be stopped. General skill and knowledge leaves with the person. A business whose competitive position depends on preventing that is depending on something no law provides.

And decide the enforcement posture in advance. Litigating a trade secret claim requires identifying the secret with particularity, which is itself a disclosure, and the decision to sue should be taken knowing that. See Trying a Trade Secret Case.


Part nine: sector variations

The framework is general; the pressure points differ.

Software and platforms. Reverse engineering questions dominate, with the intermediate copying and circumvention analysis doing most of the work. Scraping of competitor sites is common and engages terms of service more than the computer access statute. Personnel movement between platform companies is constant and the covenant landscape is frequently hostile to restraint.

Semiconductors and hardware. Physical teardown is routine and industrialised, with commercial teardown reports sold openly — which makes the "how did you learn this" question easy to answer if the report was purchased. Mask work and design rights sit alongside patents. Process technology is the real secret and is not learnable from a teardown.

Pharmaceuticals and life sciences. Regulatory filings disclose a great deal, competitor intelligence is heavily conference-driven, and the personnel risk concentrates in a small number of scientists. Formulation and process know-how are the protected assets.

Financial services. Model and algorithm secrecy is the whole game, quantitative staff move constantly, and the sector's compensation structures make the mobility question acute. See the Financial Technology and Payments IP Toolkit.

Consumer products. Pricing and promotional intelligence is gathered from retailers, which raises the amber-source problem constantly, and retailer relationships are themselves a route by which competitor information circulates.

Industrial and capital equipment. Long sales cycles produce detailed competitor proposals in customer hands, and customers share them. A proposal received from a customer is the most common amber source in the sector.

Professional services. The secret is the client relationship and the methodology, both of which walk, and the covenant question is the entire dispute.

And regulated sectors generally produce public filings that are the richest lawful source available and that competitors systematically under-use, preferring more exotic methods with worse risk profiles.


Part ten: the three-day test

The quickest diagnostic on a competitive intelligence programme takes three days. Pick the most-used competitor intelligence document in the business — the battle card, the pricing comparison, the technology roadmap analysis — and ask five questions.

Where did each material assertion in it come from, item by item? Is that source recorded anywhere other than in somebody's memory? Was any of it obtained from a person who was under an obligation of confidence to the competitor? Did any of it come from an employee who joined from that competitor, and if so when and how? And would the business be comfortable if the document, with its source record, were produced in litigation tomorrow?

A business that answers all five has a governed programme. A business that answers two has the ordinary position. A business that cannot answer the first has an asset it cannot defend and a document it would rather not produce — which is the most common finding, and which is fixable in a quarter with a mandatory source field and a one-page methods policy.


One paragraph to remember

Reverse engineering and independent derivation are expressly lawful; theft, pretexting, and inducing a breach of confidence are not; and almost every real dispute turns on a person who moved and a document that moved with them. Record the source of everything, contract your research agencies to a methods policy, document the reverse engineering as it happens rather than after, keep the specification team and the development team physically apart, give every new hire a written contamination instruction and decline anything they offer, and if contamination is discovered, stop, preserve, and call counsel — because the one response that converts a manageable problem into an unmanageable one is deleting the file.


Documents that must exist

For each item: does it exist, where does it live, who owns it, and can it be produced in three days?


A note on tone and proportion

Two failure modes bracket this practice and both are common.

The over-cautious position treats all competitor information as radioactive, prohibits ordinary market awareness, and drives the activity underground. Sales teams still learn things; they simply stop telling legal. The programme becomes a fiction and the business is worse off than if it had none, because the informal practice is now undocumented and unadvised.

The under-cautious position treats the whole area as commercial common sense, engages agencies without asking about methods, hires aggressively from competitors, and discovers the problem when a letter arrives. The remediation then happens under litigation conditions, at the worst possible cost.

The workable position is procedural rather than attitudinal. Collect freely from green sources — and most of what a business needs is in green sources, which is the point that gets lost. Apply a rule to amber. Prohibit red, in writing, and mean it. Document the source of everything. And build the response protocol before it is needed.

A programme designed that way lets a business be genuinely well informed about its competitors, which is what it wanted, while making the misappropriation claim substantially harder to bring and substantially easier to defend. That is the whole objective, and it is achieved with a one-page policy, a mandatory field in a database, and a conversation at every interview.


One last observation

The most valuable competitive intelligence in almost any market is sitting in public filings, published patents, job advertisements, and the competitor's own marketing, and it is systematically under-read because it is unglamorous. The businesses that get into trouble in this area are rarely the ones that needed to; they are the ones that reached for a shortcut before exhausting the material that was lying in the open, waiting to be assembled by somebody patient.

Key Authorities at a Glance

Trade secret framework. 18 U.S.C. § 1836 provides the federal civil action; 18 U.S.C. § 1839 defines trade secret, misappropriation, and improper means, and expressly excludes reverse engineering and independent derivation; 18 U.S.C. § 1832 creates criminal liability for theft of trade secrets. E.I. DuPont deNemours & Co. v. Christopher on improper means below the threshold of illegality; Kewanee Oil Co. v. Bicron Corp. on the coexistence of trade secret and patent law and the legitimacy of reverse engineering; Rockwell Graphic Systems, Inc. v. DEV Industries, Inc. on reasonable measures; PepsiCo, Inc. v. Redmond on inevitable disclosure.

Copyright and access. 17 U.S.C. § 107 with Sega Enterprises Ltd. v. Accolade, Inc., Sony Computer Entertainment, Inc. v. Connectix Corp., and Google LLC v. Oracle America, Inc.; 17 U.S.C. § 1201, including the interoperability exception; 17 U.S.C. § 102(b) on the unprotectability of methods.

Computer access. 18 U.S.C. § 1030 with Van Buren v. United States and hiQ Labs, Inc. v. LinkedIn Corp., both of which narrowed the statute's reach against terms-based access restrictions.

Deception and unfair practices. 15 U.S.C. § 45; 15 U.S.C. § 1125(a) where the conduct involves false statements to the market.

Design and appearance. 35 U.S.C. § 171 with Egyptian Goddess, Inc. v. Swisa, Inc.; trade dress functionality under TrafFix Devices, Inc. v. Marketing Displays, Inc..

Preservation and sanctions. Fed. R. Civ. P. 37(e); Fed. R. Civ. P. 26(c) for protective orders; Fed. R. Evid. 502 for non-waiver orders during an investigation.

Competition. Information exchange between competitors is assessed under the antitrust framework; see Where Intellectual Property Stops and Antitrust Starts and Information Exchange Guidance.

| Authority | Governs | Practical consequence | | --- | --- | --- | | 18 U.S.C. § 1839 | Improper means | Reverse engineering is expressly proper | | DuPont v. Christopher | Commercial morality | Lawful conduct can still be improper | | Kewanee Oil | Trade secret and patent | Reverse engineering is legitimate | | PepsiCo v. Redmond | Inevitable disclosure | Why temporary reassignment helps | | Sega v. Accolade | Intermediate copying | Analysis copying can be fair use | | 17 U.S.C. § 1201(f) | Interoperability | Narrow circumvention exception | | Van Buren | Computer access | Terms breach is not access breach | | 18 U.S.C. § 1832 | Criminal exposure | Why pretexting is not a grey area | | Fed. R. Civ. P. 37(e) | Spoliation | Never delete on discovery | | Fed. R. Evid. 502 | Privilege | Investigate at counsel's direction | | 35 U.S.C. § 171 | Designs | Function may be learned; appearance may not be copied | | 15 U.S.C. § 45 | Deception | Pretexting is an unfair practice |


Related Documents

The triad

Reverse engineering and interoperability

Trade secret programme and disputes

People and mobility

Competition, data, and discovery


Marksy is not a law firm. This toolkit is provided for general informational purposes and does not constitute legal advice. Trade secret standards, restrictive covenant enforceability, and information exchange analysis vary by jurisdiction and by facts. Clause language is illustrative and must be adapted to the arrangement. Nothing here creates an attorney-client relationship. Consult qualified counsel before establishing a competitive intelligence programme, commencing a reverse engineering exercise, or responding to a contamination event.

Read this article on Marksy