Apple has filed a lawsuit accusing OpenAI and two former Apple employees of stealing confidential information, as the two companies gear up to compete more directly in consumer electronics. It's the kind of story that reads as a distant Silicon Valley drama — nine-figure legal teams, years of litigation, information most small businesses will never generate in the first place.

It's also, underneath the scale, a completely ordinary business problem: what happens to the confidential information in an employee's head when they leave and go to work for a competitor.

Why this actually matters at any size

Apple can afford to sue. Most businesses can't, and won't ever need to on this scale — but the underlying exposure is identical whether you're a global tech giant or a five-person agency. Client lists, pricing structures, supplier terms, the specific way you deliver a service that took years to refine: all of it walks out the door in someone's head the day they hand in their notice, whether or not you've ever thought about it as 'trade secrets'.

You don't need Apple's legal team to have Apple's problem. You just need a valuable competitive advantage and an employee who knows it.

What UK law actually gives you here

Confidential information in the UK is protected by a mix of things: the implied duty of confidentiality that exists in every employment relationship even without a written clause, the Trade Secrets (Enforcement, etc.) Regulations 2018 for genuinely secret commercial information, and whatever specific confidentiality and restrictive covenant clauses you've actually put in the contract. The first two are useful backstops. Neither is a substitute for the third, because both require you to prove, after the fact, that something specific and genuinely secret was taken — a much harder and slower fight than pointing a court at a clause the employee already signed.

Restrictive covenants — non-compete, non-solicitation of clients, non-dealing with clients, non-poaching of staff — are enforceable in the UK, but only if they go no further than reasonably necessary to protect a genuine business interest. A blanket 'you can never work in this industry again' clause copied from a template is likely to be struck down entirely if it's ever tested, which means it was never really protecting you at all. A narrower clause — no contact with the specific clients they actually worked with, for a defined period, typically six to twelve months for most small businesses — is far more likely to hold up if it matters.

What actually protects you, realistically

A lawsuit is the last resort, not the plan. The businesses that handle this well do three unglamorous things long before anyone hands in their notice: a clear, signed confidentiality agreement for anyone with access to genuinely sensitive information; a proper offboarding process that revokes access to systems and files the day someone leaves, not whenever it's convenient; and being deliberate about who actually has access to the most sensitive information in the first place, rather than defaulting to giving everyone everything.

None of this requires a legal budget anywhere near Apple's. A solicitor reviewing a standard confidentiality and non-compete clause for your contracts is a modest one-off cost, and it's the difference between having a real option if the worst happens and having no recourse at all beyond an awkward phone call.

The offboarding checklist most small businesses skip

Revoke access to email, shared drives, the CRM and any client-facing systems on the employee's actual last day, not whenever IT gets round to it — a surprising number of data walkouts happen in the gap between someone's final day and someone remembering to switch off their login. Get a short written acknowledgement that they understand what remains confidential after they've left; it costs nothing and removes any later claim that they didn't realise. And if the departure is to a direct competitor, or the role gave genuinely sensitive access, a short, paid period of garden leave — keeping them employed but out of the building for the notice period — is a legitimate, proportionate tool that buys time for client relationships to settle and information to go stale before they start a new role.

There's a data protection angle here too that's easy to miss: if what walks out the door includes a client list with personal data on it, that's not just a confidentiality breach, it's potentially a UK GDPR issue for whoever ends up holding or using that data without a lawful basis. It's one more reason the offboarding conversation is worth having properly, not as an afterthought on someone's last afternoon.

The bit most owners actually get wrong

It's rarely the contract that's missing entirely — most businesses have something in writing. It's that the something was copied from a template years ago, was never reviewed against what the business actually considers sensitive today, and nobody in the business could confidently say what it actually covers. A confidentiality clause nobody remembers the details of isn't much more protection than having nothing at all.

What to do this week

Pull up the contract template you actually use for new starters and read the confidentiality and restrictive covenant clauses properly, not just skim them. Ask yourself honestly whether they name what your business actually considers sensitive — your specific client list, your pricing structure, your supplier terms — or whether they're generic boilerplate that could belong to any business. If it's the latter, a modest one-off session with an employment solicitor to tighten the wording is far cheaper than finding out its limits the day someone senior hands in their notice and walks straight to a competitor.

This isn't a story about you needing to sue anyone. It's a reminder to check, once, that the basic protections are actually in place — before you're the one finding out the hard way what 'confidential' meant in a contract nobody's looked at since it was signed.

Common questions

What actually counts as a trade secret in a small business?

Information that is genuinely secret, has commercial value because it is secret, and that you have taken reasonable steps to keep secret — that is the test in the Trade Secrets (Enforcement, etc.) Regulations 2018. In practice that covers your pricing structure and margins, your supplier terms, the detail sitting behind your client list, and any process you have refined that a competitor could not simply look up. It does not cover the general skill and experience an employee picked up doing the job; the courts draw that line firmly and you cannot stop someone being good at their trade. The third limb catches small businesses out. If the secret sits in a shared drive everyone can open, with no confidentiality clause and no access controls, you have not taken reasonable steps and the protection may not be there when you need it.

Are non-compete clauses actually enforceable in the UK?

Yes, but only so far as they go no further than is reasonably necessary to protect a legitimate business interest — and a court will strike out a clause that overreaches rather than politely trimming it back for you. Duration, geography and scope all matter. Six to twelve months is the range that usually survives for a small business; barring someone from an entire industry nationwide for three years almost certainly will not. A narrower non-solicitation clause, stopping them approaching the specific clients they actually dealt with, is far easier to enforce and usually protects what you really care about anyway. Reform is being looked at — the government published a working paper in November 2025 setting out options including a three-month statutory cap — but nothing has been legislated, so the reasonableness test still governs.

An employee has left and taken my client list. What can I do?

Act in the first week, because speed matters here more than anything else. Write to them immediately setting out the confidentiality obligations they remain under and asking for written confirmation that the information has been returned or deleted — a firm letter resolves far more of these than a court ever does. Preserve your own evidence at the same time: system access logs, email forwarding rules, file downloads in the days before they resigned. If a client database went to a personal email account, that is also a personal data breach on your side, and you have 72 hours from becoming aware to decide whether it needs reporting to the ICO. Then take advice quickly. Injunctions are available, and they reward employers who moved fast.

Do I need to make freelancers and contractors sign an NDA too?

Yes, if they see anything you would mind a competitor seeing — and the case is stronger for contractors than for employees, not weaker. An employee owes an implied duty of confidentiality simply by being an employee. A self-employed contractor does not owe that duty in the same way, so whatever the written agreement says is very close to the whole of your protection. A short mutual confidentiality agreement signed before work starts covers it; two pages is enough and it does not need to be expensive. Do the same for anyone else with real access — bookkeepers, virtual assistants, agencies, developers. The awkward version is asking someone to sign after they have already had the access, which is exactly why it belongs in standard onboarding.

Can I just write one broad confidentiality clause and cover everything?

No — a blanket clause is weaker than a specific one, and some things cannot be gagged at all. A clause naming what your business actually treats as confidential, such as pricing, supplier terms, the client list or a particular method, is far more likely to be enforced than boilerplate claiming everything is secret, because the wider it reaches the easier it is to argue it is unreasonable. Two hard limits apply whatever the wording. Nothing can stop a worker making a protected disclosure — whistleblowing about wrongdoing — and any clause purporting to do so is void. And under the Employment Rights Act 2025, clauses preventing a worker speaking about harassment or discrimination will be void, with those provisions expected to commence in 2027.