Managing Former Employee Risks: Confidential Info, IP & Access

Alex Solo
byAlex Solo11 min read

When an employee leaves, the legal risk does not always leave with them. New Zealand businesses often focus on the resignation itself, then miss the practical issues that matter most: old logins still working, customer lists copied to a personal device, unclear ownership of work created during employment, or a restraint clause that looks strong but is too broad to enforce. Those gaps can turn a routine departure into a loss of clients, data, goodwill or valuable know how.

The main risk is not just bad behaviour by a former worker. It is poor preparation before you sign an employment agreement, weak offboarding, and assumptions about who owns what. This guide explains what managing former employee risks means for New Zealand businesses, what to check in your contracts and processes, and the common mistakes that catch founders and SMEs out.

Overview

Managing former employee risks means making sure your business can protect confidential information, secure access to systems, and confirm ownership of work product after an employee leaves. The strongest position usually comes from a mix of well-drafted employment terms, clear policies, and a practical offboarding process that people actually follow.

  • Confirm who owns intellectual property created in the role, including code, designs, documents, processes and marketing assets.
  • Define confidential information clearly and require its return or deletion when employment ends.
  • Review post-employment restraints carefully, including non-solicitation, non-dealing and non-compete clauses.
  • Shut off access promptly to email, cloud storage, customer databases, payment systems and social media accounts.
  • Check privacy obligations if personal information sits in copied files, inboxes or personal devices.
  • Use an exit process that covers devices, passwords, records, clients, and written reminders of ongoing obligations.

What Managing Former Employee Risks Means For New Zealand Businesses

For most New Zealand businesses, managing former employee risks is about protecting business assets without overreaching. You want terms and processes that are fair, commercially sensible, and more likely to hold up if challenged.

Founders often think this issue only matters when a senior employee joins a competitor. In practice, risk also arises when a junior staff member has broad system access, a salesperson knows key pricing and leads, or a contractor style hire has created valuable work without clear IP wording.

Confidential information

Confidential information can include much more than a secret formula or a product roadmap. In an SME, it often covers customer lists, pricing models, supplier terms, margins, marketing plans, sales scripts, internal procedures, unpublished financials, code repositories, product specs and strategic plans.

New Zealand businesses should avoid relying on a vague assumption that all internal information is automatically protected forever. Your employment agreement should describe confidential information in a practical way, set out permitted use during employment, and make clear that confidentiality continues after employment ends where the information remains genuinely confidential.

The wording also needs to reflect reality. Information that is public, already known independently, or no longer confidential is treated differently from true trade secrets or sensitive commercial material.

Intellectual property created by employees

IP ownership should be dealt with expressly before you hire your first worker and before you sign. If an employee creates software, designs, written content, training material, databases, product improvements or branding assets as part of their role, your contract should say who owns those rights and when ownership passes.

This matters because businesses often invest in a website, app, internal systems or brand material, then discover later that the paperwork does not clearly assign rights. The issue gets harder where the employee used personal equipment, worked remotely, developed ideas across work and home time, or had a role that evolved well beyond the original job description.

A practical employment agreement will usually address:

  • what kinds of IP are covered;
  • whether ownership vests in the employer automatically or is assigned on creation;
  • the employee's obligation to sign further documents if needed;
  • limits around pre-existing material the employee brings into the role; and
  • treatment of moral rights or consents where relevant.

Access to business systems and accounts

Access risk is often the fastest moving problem. A former employee with live credentials can download files, redirect enquiries, change passwords, message customers or copy data in minutes.

This is where founders often get caught. They cancel email access, but forget shared drives, password managers, payroll portals, project tools, advertising accounts or social channels linked to a personal login.

The legal point is simple: contract terms help, but operational control matters just as much.

Post-employment restraints

Restraint clauses can help, but broad wording is not automatically better. In New Zealand, post-employment restraints need to protect a legitimate business interest and be reasonable in scope, duration and geography.

For many SMEs, a non-solicitation or non-dealing clause is more realistic than a wide non-compete. A blanket ban on working in the same industry may be difficult to justify, especially for junior workers or roles with limited access to sensitive information. A more tailored clause aimed at poaching clients, staff or confidential material is often a better starting point.

Privacy and business records

If a departing worker holds customer or employee personal information, privacy issues can sit alongside employment issues. You may need to assess what personal information was accessible, whether files were copied, whether devices need to be returned, and whether your internal policies cover storage on personal drives or messaging apps.

That is not just an IT issue. Under New Zealand privacy rules, the way personal information is collected, stored, accessed and retained matters. A weak offboarding process can expose both commercial information and personal information at the same time.

The best time to manage former employee risks is before the employment relationship starts. Once someone has left, your options are narrower, more expensive and more dependent on the wording you already have.

Get the employment agreement right

Your employment agreement should do more than cover pay, duties and leave. It should deal directly with confidential information, intellectual property, return of property, post-employment obligations and restraints where they are appropriate.

Before you sign, review whether the agreement:

  • defines confidential information with examples relevant to your business;
  • states that confidential information must only be used for the business's benefit during employment;
  • requires return of documents, devices, keys, records and data on termination;
  • prohibits unauthorised copying, downloading or external storage of business material;
  • confirms ownership or assignment of IP created in the course of employment;
  • deals with pre-existing employee IP or third party material;
  • includes restraint clauses that match the employee's real level of risk; and
  • allows the employer to monitor, secure and recover business systems and property where lawful and reasonable.

If the person is actually a contractor, the drafting needs extra care. Before you classify someone as a contractor, remember that misclassification can create a separate employment issue, and contractor IP ownership should not be assumed either.

Match restraints to the actual role

A restraint should be drafted for the person in front of you, not copied from another contract. The legal test usually turns on whether the restraint goes no further than reasonably necessary to protect legitimate interests such as confidential information, customer relationships or workforce stability.

For example, a founder hiring a head of sales may reasonably want limits around soliciting key clients for a defined period. The same clause may be too wide for a junior administrator with no strategic client contact. If the restraint looks like punishment rather than protection, it becomes harder to rely on.

Use workplace policies to support the contract

Employment agreements do not need to carry every operational rule. Policies can support the contract by setting expectations around devices, passwords, remote work, file storage, AI tools, messaging apps, customer data and social media access.

Useful policy topics include:

  • which systems employees may use for business records;
  • whether personal devices are allowed and on what conditions;
  • how passwords and shared credentials are managed;
  • where confidential information may be stored or transferred;
  • what happens to social media and digital account access; and
  • what employees must do at exit, including deletion and return obligations.

Policies should align with the agreement. A policy cannot fix a contract that says nothing important, but it can make your expectations much clearer and easier to enforce internally.

Plan your offboarding before there is a problem

Exit risk is highest when nobody owns the process. Before you hire your first worker, set a repeatable offboarding checklist so your team can act quickly when someone resigns or is dismissed.

Your checklist should cover:

  • who is notified and when, including IT, payroll, managers and account owners;
  • when system access is changed or shut off;
  • what devices, cards, keys and documents must be returned;
  • how cloud folders, shared drives and email forwarding are handled;
  • how client relationships are transferred;
  • what written reminder of ongoing obligations will be given at exit; and
  • what records the business will keep about the handover and access changes.

This is especially important for startups where one person may have had informal access to many tools set up in the early days.

Think about evidence, not just rights

A legal right is much easier to use if your records are clean. Keep signed agreements, policy acknowledgements, access logs, device registers, and written exit communications in one place.

If a dispute later arises over copied data, client contact or IP ownership, these records can matter as much as the clause itself. Businesses often have a reasonable case, but poor internal records make it harder to prove what happened.

Common Mistakes With Managing Former Employee Risks

The most common mistakes are practical, not dramatic. Businesses usually lose control because the basics were not sorted out before they needed them.

Assuming confidentiality is obvious

Many founders think a court or mediator will simply accept that internal information is confidential. Some information will clearly be sensitive, but not every internal file is protected in the same way. If your agreement is vague and your business treats sensitive material casually, the argument becomes harder.

Label genuinely sensitive material, limit access, and avoid mixing strategic files with general business records where everyone can download them freely.

Using the same clause for every employee

A template can be a useful starting point, but one-size-fits-all restraints cause problems. Overly broad clauses may be hard to enforce, and unnecessarily aggressive wording can also create friction when hiring.

Different roles justify different protections. Senior leadership, sales, product, engineering and operations staff may each need a different mix of confidentiality, IP and restraint terms.

Forgetting about intellectual property created during the job

This often comes up after a business grows. The employee helped build the website, wrote code, created onboarding materials, designed packaging, or developed a process that became commercially valuable. Years later, the business wants to sell, raise capital or grant licences, and the due diligence question is simple: do you actually own it?

If the paperwork is unclear, the issue can delay deals and increase legal costs. The cleaner approach is to confirm ownership from the start and review contracts whenever responsibilities change significantly.

Leaving access live after the person exits

This is one of the easiest mistakes to avoid and one of the most damaging when missed. Shared admin logins, social media accounts linked to a personal email, and cloud folders with no central owner are common weak points.

Make one person responsible for digital offboarding. If access needs to stay on briefly for handover reasons, document the reason, limit the access, and set a clear shut-off time.

Ignoring data on personal devices

Hybrid and remote work increase this risk. Staff may have business contacts in a personal phone, synced files on a home computer, or messages containing customer information in personal apps. If your business has no clear policy, retrieval and deletion become much harder.

The answer is not necessarily banning all personal device use. The better approach is setting conditions early, including what can be stored, what security is required, and what must happen when employment ends.

Relying on a threatening exit conversation instead of a process

A tense handover meeting does not replace proper documentation. If you are worried about misuse of confidential information or client poaching, follow your process, gather facts, preserve records, and communicate carefully.

Overstating your legal position can backfire, especially if the contract is weak. A calm, documented and proportionate approach usually puts the business in a better position.

Not updating agreements as the business changes

A startup's first employment contracts often stop fitting after growth. Roles expand, access broadens, products change, and employees move into positions with stronger customer or strategic influence.

Review contracts when someone is promoted, given access to sensitive systems, moves into product development, or starts managing key accounts. Waiting until they resign is too late.

FAQs

Can a former employee use our customer list after they leave?

Often, no, if the list is genuinely confidential and your agreements and business practices support that position. The stronger your confidentiality wording, access controls and exit process, the easier it is to protect.

Do we automatically own work an employee created for the business?

Not always in the simple way founders assume. Clear employment terms dealing with IP ownership or assignment are the safest approach, especially for software, designs, marketing assets and internal systems.

Are non-compete clauses enforceable in New Zealand?

Sometimes, but only where they protect a legitimate business interest and are reasonable. A narrower non-solicitation or non-dealing clause is often more realistic than a broad ban on working for a competitor.

What should happen on an employee's last day?

Your business should collect devices and records, disable or limit access, change relevant passwords, confirm handover steps, and remind the employee in writing about confidentiality, IP and any post-employment obligations.

What if the employee used a personal phone or laptop for work?

You should check what business data may be stored there and what your policies and agreement allow you to require on exit. Clear bring-your-own-device rules make return, deletion and verification much easier.

Key Takeaways

  • Managing former employee risks starts before you sign, not after the employee resigns.
  • Your employment agreement should clearly cover confidential information, IP ownership, return of property, access issues and any tailored post-employment restraints.
  • Restraint clauses need to be reasonable and matched to the worker's role, access and influence.
  • Operational controls matter just as much as contract wording, especially system access, password management and offboarding.
  • Privacy issues can arise where former staff hold customer or employee personal information on devices, inboxes or cloud accounts.
  • Regular contract reviews help when roles change and employees gain access to more valuable information or client relationships.
  • If you are reviewing or negotiating managing former employee risks and want help with employment agreements, contract drafting, confidentiality clauses, IP ownership terms, workplace policies, and offboarding processes, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Protect your brand

What intellectual property should you protect?

If a name, logo, design or other creative work matters to the business, check who owns it, what permissions you need and whether clearance or registration is appropriate.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Protect your brand

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.