Your contextContext not defined
Country of the organisation assessedNot provided
What it providesNot provided
Relationship with the EUNot provided
Home / Sensitive information

Sensitive information

Trade secrets and industrial confidentiality

Plans, processes, technical files and know-how may create protection requirements regardless of whether the supply is digital or physical in nature.

Effect of this requirement

This rule cannot be read in isolation.

Applicability to be qualified
Transfers
Bilateral relationship
Country sources reviewed on
Assumptions, limitations and sources of this reading

Reading point

Trade secrets are protected through everyday practices

Confidentiality commitments must extend to workshops, tools, copies and subcontractors.

  • Classification and inventory of entrusted information
  • Need-to-know access and control over copies
  • Authorised sites, teams and subcontractors
  • Exchange channels, traceability, return and destruction
  • Recourse to a specialist for sector-specific or export control rules

Journey of sensitive information

Protect a plan, prototype or piece of know-how throughout the industrial relationship.

01

Receive

Classification, authorised channel and authorised persons.

02

Use

Need-to-know, roles, workshops, distribution and collaboration tools.

03

Share

Subcontractors, countries, grounds, authorisations and restrictions.

04

Return

Inventory, return, destruction, evidence and handling of backups.

Decision path

Protect information beyond the confidentiality agreement

The defensibility of the arrangement depends on the concrete control of copies, access and transmissions throughout the entire execution.

01Classified information

Inventory plans, processes, prototypes, files and know-how entrusted, with their sensitivity level and owner.

02Authorised use

Limit people, positions, workstations, tools, printouts and copies to the need-to-know established for the engagement.

03Sharing chain

Identify every site, country and subcontractor liable to receive the information before any transfer takes place.

04Verifiable exit

Remove access, return or destroy copies and document the handling of backups and residual copies.

Protection of know-how

The controls that extend the confidentiality agreement into execution.

Questions to address

  • What plans, processes or technical files leave the European organisation
  • Which people, entities and locations can access it
  • How copies, printouts and transfers are controlled
  • How the return or destruction is demonstrated at the end of the relationship

Elements that support the response

  • Classified inventory of information entrusted
  • Access matrix and assigned confidentiality agreements
  • Log of exchanges, copies and access to sensitive spaces
  • Return or destruction record and access removal

Confusions to avoid

  • Reduce trade secret protection to a generic confidentiality clause
  • Sharing a full technical file when an extract would have sufficed
  • Allowing an undeclared subcontractor to keep a copy
  • Assuming that a bilateral commercial agreement protects secrets without operational control
Assurance file, PV-052Demonstration example
Client requestEvidence of monthly vulnerability reviewsFinding
Actual controlReviews do take place every monthFinding
Evidence producedScreenshot with no date or scopeFinding
Divergence observedThe work exists, but the evidence does not demonstrate itGap
ImpactA control that genuinely exists may be treated as absent by the reviewerGap
ActionProduce a dated, scoped and attributed export every monthDecision
Reading the coloursFactual observationGap or riskDecision or action

Demonstration

Sustain confidentiality right through to copies and subcontractors.

The case tracks a piece of sensitive information from receipt through to delivery, making visible the uses, locations and people that must be authorised.

Understanding how evidence is qualified →

Apply this reading

Identify the sensitive information entrusted during performance.

The inventory of plans, files or know-how entrusted makes it possible to target the uses, copies, sites and subcontractors that require authorisation.