What Should You Do If an Employee Takes the Client Database?
Is taking a client database a legal violation?
If an employee copies the company’s client database, sends it to a personal email, transfers it to a competitor, or starts using it for personal business, this may be a serious violation of the employer’s rights.
A client database may include names, phone numbers, application history, contracts, payment data, correspondence, personal data, and commercial information. Therefore, unauthorized use of such information may lead to labor, civil, administrative, or even criminal consequences.
A client database is not just an Excel spreadsheet. For many businesses, it is one of the most valuable assets.
What should the employer do first?
The employer should act quickly, but carefully. It is not advisable to threaten the employee, take their personal phone, or create a conflict. The first step is to preserve evidence.
Immediate actions may include:
- Block the employee’s access to CRM, email, WhatsApp Business, website, Google Drive, Telegram, Instagram, and other systems.
- Change passwords.
- Save CRM and email logs.
- Check file download and export history.
- Take screenshots of correspondence and suspicious activity.
- Prepare an internal incident report.
- Request a written explanation from the employee.
- Record client complaints if the employee started contacting them.
- Consider notarizing online evidence or correspondence.
- Prepare a written claim or court action.
The key point is evidence. It is not enough to say “the employee took the database.” The employer must show what was copied, when, how, and what damage was caused.
Can a client database be a trade secret?
Yes, a client database may be treated as a trade secret if the company has taken measures to protect it.
It is advisable for the company to have:
- internal trade secret rules;
- a confidentiality agreement;
- confidentiality clauses in the employment contract;
- restricted access to the database;
- individual logins and passwords;
- a ban on copying or transferring the database;
- proof that the employee was informed about confidentiality obligations.
If these documents exist, the employer’s position is much stronger. If they do not exist, the case is more difficult, but protection may still be possible.
What if the database contains personal data?
If the client database contains names, phone numbers, personal identification numbers, addresses, application details, payment information, or other personal information, it may include personal data.
Unauthorized copying, transfer, or use of such data may violate personal data protection rules.
The employer may:
- record the fact of unauthorized access or copying;
- demand deletion of the data;
- demand that the employee stop using the database;
- contact competent authorities;
- assess the risk of a client data leak.
Businesses that work with client data should not treat databases as ordinary contact lists. Such information requires legal and technical protection.
What claims can be made against the employee?
Depending on the situation, the employer may bring several claims against the employee.
1. Return of the client database
If the employee took files, CRM exports, documents, client lists, or other materials, the employer may demand their return.
2. Stop using the database
The employer may demand that the employee stop using the database for personal purposes, for a competitor, or for poaching clients.
3. Delete unlawfully copied data
If the database is stored on the employee’s personal email, phone, flash drive, cloud storage, or messenger, the employer may demand deletion.
4. Stop contacting company clients
If the contract or confidentiality agreement includes a non-solicitation clause, the employer may demand that the employee stop contacting or poaching clients.
5. Compensation for damages
If the company lost clients, income, or incurred expenses because of the employee’s actions, the employer may claim damages.
6. Contractual penalty
If the employment contract, confidentiality agreement, or internal document provides for a penalty for breach of confidentiality, the employer may claim it.
7. Disciplinary action
If the employee still works for the company, disciplinary action may be considered, provided that the proper procedure is followed.
8. Court claim
If the employee refuses to return the database, continues using it, or causes damage, the employer may file a court claim.
9. Police report
If there are signs of illegal acquisition, disclosure, sale, or transfer of commercial information, the employer may consider filing a police report.
Should the employer request a written explanation?
Yes. The employer should request a written explanation from the employee. The explanation may show:
- whether the employee copied the client database;
- why they did it;
- where the file was sent;
- whether third parties received the information;
- where the database is stored now;
- whether it was used after termination.
If the employee refuses to provide an explanation, the employer should prepare a written act of refusal.
Can disciplinary action be applied?
Yes, if the employee violated labor duties, confidentiality obligations, or internal company rules, the employer may consider disciplinary action.
The procedure should be followed carefully:
- record the violation;
- request an explanation;
- collect evidence;
- issue an order;
- inform the employee.
If the procedure is violated, the employee may challenge the disciplinary measure.
What can be claimed in court?
Through court, the employer may request:
- return of the client database;
- prohibition on using confidential information;
- deletion of unlawfully copied data;
- compensation for damages;
- contractual penalty, if provided;
- recognition of the employee’s actions as unlawful;
- an obligation to stop violating the company’s rights.
Before filing a court claim, it is advisable to send a written demand to the employee.
When should the employer contact the police?
A police report may be considered if:
- the employee intentionally copied the database;
- transferred it to a competitor;
- sold the database to third parties;
- accessed CRM, email, or accounts unlawfully;
- used logins and passwords without permission;
- started mass poaching of clients;
- caused significant damage to the company.
The report should describe specific facts: what database was taken, when it happened, who had access, what evidence exists, and what damage was caused.
What evidence is needed?
The employer should collect:
- employment contract;
- job description;
- confidentiality agreement;
- internal trade secret policy;
- acknowledgments signed by the employee;
- CRM logs;
- file export history;
- WhatsApp, Telegram, and email correspondence;
- client complaints;
- screenshots of messages;
- internal investigation report;
- employee explanation;
- calculation of damages;
- proof of lost clients.
The more specific the evidence, the stronger the employer’s position.
What if there is no confidentiality agreement?
If there is no separate NDA or trade secret policy, the situation becomes more difficult. However, this does not mean the company has no protection at all.
The employer may rely on:
- employment contract;
- proof that the database belongs to the company;
- technical logs;
- correspondence;
- evidence of transfer to third parties;
- personal data protection rules;
- actual damage caused to the company.
For the future, it is better to implement a confidentiality system and internal rules for protecting client data.
How can the company prevent this in advance?
The company should create a data protection system:
- sign confidentiality agreements with employees;
- include trade secret clauses in employment contracts;
- approve internal information protection rules;
- restrict access to the database by role;
- use individual logins;
- enable two-factor authentication;
- control data export;
- block access immediately after termination;
- sign an access and materials return act;
- store the client database in a CRM, not in managers’ personal phones.
Prevention is cheaper than litigation, especially when the client database is the heart of the sales system.
Conclusion
If an employee takes the client database, the employer should immediately block access, preserve evidence, prepare an internal report, request an explanation, and send a written demand. Depending on the case, the employer may apply disciplinary measures, file a court claim, or submit a police report.
To protect the business, the company should prepare confidentiality agreements, trade secret rules, CRM access policies, and offboarding procedures in advance. Without documents, the dispute may become “word against word.” With documents, it becomes a legal position.
FAQ
What should an employer do if an employee copies the client database?
The employer should block access, preserve logs and screenshots, prepare an internal report, request an explanation, and send a written demand.
Can the employer recover damages?
Yes, if the employer proves the violation, the amount of damage, and the connection between the employee’s actions and the company’s losses.
Can a client database be a trade secret?
Yes, if the company has established confidentiality rules, restricted access, and informed employees about their obligations.
Can the employer contact the police?
Yes, if there are signs of illegal acquisition, transfer, sale, or use of the client database.
What if the employee poaches clients?
The employer should collect messages, call records, client complaints, screenshots, and correspondence, then send a demand or file a claim.
Can the database be protected without an NDA?
It is possible, but harder. The employer must prove that the database belongs to the company, that it was copied unlawfully, that it contains protected data, and that damage was caused.
How can a company prevent database theft?
Use CRM access controls, confidentiality agreements, trade secret policies, individual logins, export restrictions, and immediate access blocking after termination.

