Journal

Confidentiality clause for shareholder data and trade secrets

An effective clause protects trade secrets and shareholder data without broadly excluding statutory and contractual information rights.

Shareholders need information to assess annual accounts, management conduct and important resolutions. The same documents may reveal customer terms, pricing calculations, technical knowledge or personal data. A confidentiality clause therefore has to combine two objectives: enabling legitimate access and preventing misuse. A blanket prohibition does not resolve that tension. The agreement needs defined information classes, secure access routes and proportionate consequences for actual breaches.

Quick assessment

Where is action currently needed?

Select the reason for the review and the type of information involved. The result identifies the first issue to examine.

Already know you want to get in touch? Go straight to the enquiry form.

01 Question 1

What prompted the review?

All paths at a glance

Overview of all answers.

01

Define the protected information classes and verify the confidentiality measures actually used in the business.

Define the protected information classes and verify the confidentiality measures actually used in the business.
02

Separate the corporate information need, the data protection purpose and the permitted recipients.

Separate the corporate information need, the data protection purpose and the permitted recipients.
03

Classify the records by protection level rather than releasing the entire set under one access rule.

Classify the records by protection level rather than releasing the entire set under one access rule.
04

Assess the specific competitive relevance. Access through a professionally bound adviser may provide a suitable safeguard.

Assess the specific competitive relevance. Access through a professionally bound adviser may provide a suitable safeguard.
05

Clarify scope, purpose and secure delivery instead of blocking the information right as a precaution.

Clarify scope, purpose and secure delivery instead of blocking the information right as a precaution.
06

Preserve access logs and affected files. Restrict further access and assess injunctive relief.

Preserve access logs and affected files. Restrict further access and assess injunctive relief.

Aligning information rights with confidentiality

Section 22(2) of the Austrian GmbH Act grants shareholders a statutory inspection right in connection with the annual accounts. Austrian Supreme Court case law also recognises a general information right that enables shareholders to exercise their control, governance and membership rights properly. A clause should therefore not place every information request at the unrestricted discretion of management.

A shareholder may not use information received in any way they choose. The Austrian Supreme Court derives from the corporate duty of loyalty an obligation to respect the GmbH interest in keeping internal matters confidential. A breach may support injunctive relief and damages even without a separate clause. If the clause also creates a contractual duty, a damages claim requires an attributable breach and resulting loss. A sound provision therefore identifies the permitted purpose, recipients, technical access and the handling of information after a shareholder exits.

The starting point remains the shareholder rights and voting rights provided by law and the agreement. Confidentiality is not a separate power to defeat every information request. It protects the handling of information made available because of the shareholding.

Confidential information is not always a trade secret

Section 26b of the Austrian Unfair Competition Act sets three requirements for a trade secret. The information must not be generally known or readily accessible. It must have commercial value because it is secret. It must also be subject to confidentiality measures that are reasonable in the circumstances. Merely labelling a file confidential is not enough if price lists are freely circulated, access rights are never revoked or sensitive records are stored in an unprotected shared folder.

Examples may include detailed pricing calculations, customer terms, supplier prices, technical processes, product plans, sales strategies, budget assumptions and transactions that have not been announced. Whether a particular item qualifies depends on its content and the protection actually applied. The articles can identify categories while allowing the company to update the classification through a documented resolution.

Shareholder data forms a separate category. Names and shareholdings may already appear in public registers. Private contact details, bank information, tax records, family information, signature samples and correspondence are not thereby open for unrestricted use. A single document may contain both personal data and trade secrets. Mixed records require differentiated access rules rather than one general confidentiality label.

What the confidentiality clause should regulate

1. Protected scope: The clause should define information classes and give useful examples. It should exclude information that is public, lawfully received from a third party or developed independently. An unlimited catch all phrase provides little certainty.

2. Permitted use: Shareholders may need information to exercise membership rights, prepare resolutions and pursue rights arising from the company relationship. Use for a competing business, a private negotiation or the solicitation of company customers can be prohibited.

3. Permitted recipients: Lawyers, tax advisers, auditors or financing parties may need information for a legitimate purpose. The clause should define the recipient group and require equivalent confidentiality protection. If an outside recipient is to owe a duty directly to the GmbH, that person should give a suitable undertaking before access. An agreement made only between shareholders does not automatically bind a third party.

4. Delivery and security: Appropriate measures include named accounts, two factor authentication, tiered folder permissions, watermarks and access logs. Highly sensitive records may be made available for inspection only. Copying can be limited where an objective reason exists.

5. Duration and return: The obligation should not automatically end when the shares are sold. For a trade secret it may continue while the legal protection requirements remain satisfied. Other confidential information needs a defined period and rules for return, deletion and backup copies.

6. Remedies: Injunctive relief, removal and damages should not be displaced by an unclear lump sum. A contractual penalty is distinct from a damages claim and should be proportionate to the potential breach. The agreement should also state whether and to what extent loss exceeding the penalty may be claimed.

A tiered access model reduces unnecessary conflict

Many disputes arise not from the information right itself but from a false choice between a complete data export and a complete refusal. Practical options exist between those extremes. The GmbH can first provide a structured report. Supporting documents, individual contracts or source data can follow if the review requires them. Particularly sensitive details may be inspected in a protected data room or at the company premises.

A tiered model must still achieve the legitimate information purpose. Highly aggregated figures may be insufficient if a shareholder needs to examine a specific management measure. Conversely, exporting every customer record is unnecessary when anonymised or aggregated information answers the question for the proposed resolution.

The process should be documented. The request, records provided, reason for any restriction, permitted recipients and follow up questions should be recorded. Proper minutes of shareholder resolutions can later establish the access arrangement and the safeguards that were approved.

Special safeguards where a shareholder competes

A competitive relationship does not automatically justify withholding all information. Austrian case law requires the GmbH to identify the specific risk and the competitive relevance of the records concerned. If the concern is only abstract, the question remains whether a narrower form of access can serve the legitimate corporate purpose.

Current unit prices, unpublished terms, identifiable customer lists, purchasing strategy and detailed forecasts are especially sensitive. Historical or aggregated data may be considerably less sensitive. The assessment still depends on the market, the level of detail and the intended use.

In decision 6 Ob 165/21i the Austrian Supreme Court confirmed that a shareholder may involve experts such as lawyers, auditors or tax advisers when exercising information rights. This can provide a proportionate safeguard. The expert reviews the records and reports only what is needed for the corporate purpose. In decision 6 Ob 89/16f, however, the Court expressly left open whether a contract with protective effect for the GmbH by itself makes the expert directly liable to the company. A direct confidentiality undertaking to the GmbH provides greater clarity.

Shareholder data requires a separate data protection review

The General Data Protection Regulation protects personal data relating to natural persons. Information concerning the GmbH alone does not fall within that regime merely because it is confidential. If records identify shareholders, employees, customers or other individuals, the GmbH needs a valid legal basis and a specified purpose for disclosure and further processing. The corporate information interest forms part of that assessment but does not replace it. A confidentiality clause does not by itself create permission to process personal data.

The company should first determine which data is necessary for the particular shareholder question. Irrelevant private contact details, account numbers or family information can be redacted. If identity or an individual amount is essential to the control function, anonymisation must not defeat the review purpose. The decision should be made for the relevant document set rather than by a blanket rule.

Transmission security also matters. Unencrypted group emails are rarely appropriate for sensitive shareholder data. Role based access, short availability periods and logged downloads provide better protection and evidence. The company also needs an internal process to assess and contain a personal data breach and to make any required notification.

Immediate steps after an unauthorised disclosure

The first task is to establish the actual scope. Which file was accessed or disclosed? Who had access? Did it contain a trade secret, personal data or information that was already public? Preserve access logs, messages and available file versions. Further permissions can be restricted to what remains necessary.

The next assessment concerns the legal basis and urgency of the response. A breach of the corporate confidentiality duty may support injunctive relief and damages. Sections 26a and following of the Austrian Unfair Competition Act may also apply to trade secrets. Section 26c specifically covers use or disclosure in breach of a confidentiality agreement. The information must still satisfy the statutory definition of a trade secret.

Not every disclosure is unlawful. Disclosure required by law, action protecting a recognised legitimate interest and certain reports of unlawful conduct may be permitted. The clause should acknowledge these situations. It can provide an orderly reporting channel while preserving mandatory legal rights.

Documents needed for a reliable clause review

A review requires the current articles, all amendments, the shareholders agreement, management rules and existing confidentiality agreements. Typical shareholder information packs, resolution minutes, role and permission concepts and examples of highly sensitive records are also useful.

For a live dispute, provide the particular information request, the GmbH response, the stated purpose and evidence of any competitive relationship. For a suspected breach, access logs, delivery records, recipient lists and documented protection measures are relevant. They reveal whether the weakness lies in the clause, the access process or enforcement in practice.

The objective is not the longest possible prohibition. The business needs a system that can be applied in daily operations: defined protection classes, traceable approvals, secure technology and a response proportionate to the breach.

Frequently asked questions on GmbH confidentiality

Can a GmbH refuse all inspection because records contain trade secrets?

Not as a general rule. The specific information purpose, sensitivity and options for tiered access must be assessed. An allegation of misuse requires concrete supporting circumstances.

Is a confidentiality clause enough to obtain trade secret protection?

No. Section 26b of the Austrian Unfair Competition Act also requires reasonable measures actually protecting the information. Suitable permissions, secure storage and consistent handling are important.

May a shareholder show records to a lawyer or tax adviser?

Involving a professionally bound expert can be permitted and may be particularly suitable for sensitive records. The scope and role should match the information purpose and be defined in the access model.

How long should confidentiality continue after a shareholder exits?

For trade secrets it should cover the period during which the information remains secret and commercially valuable. Other confidential information should have an appropriate defined duration.

Book an initial consultation (€72)

Review and structure GmbH articles with Brandauer Rechtsanwälte in Austria.

Contact