Operational checklist (within 48 h)
- Preserve evidence: freeze access (SSO, Git, CI/CD), retain logs, commission an official report by a judicial officer, and clone and timestamp repositories.
- Emergency measures: precautionary suspension, withdrawal of access rights, and recovery of equipment and API keys.
- Immediate legal action: send a formal demand requiring return/deletion, seek interim relief to stop use and obtain an injunction backed by a penalty payment; file a criminal complaint.
- Legal characterisation: combine software copyright, trade secrets, criminal offences (misappropriation of entrusted property, unauthorised access), and unfair competition.
- GDPR: if personal data is involved, initiate the breach notification procedure within 72 h.
Useful authorities and legislation: Intellectual Property Code and Criminal Code (Legifrance), Directive (EU) 2016/943 on trade secrets (EUR-Lex), CNIL – data breaches, Justice.fr – criminal complaints and interim relief, Service Public Pro — business guidance, INPI – evidence of creation, DGSI – cyber/software risks.
1) Legal grounds to use
Software copyright and infringement
The source code is automatically protected as a software work (art. L.112‑2 CPI). Economic rights in software created by an employee in the course of their duties belong to the employer (art. L.113‑9 CPI), enabling action against unauthorised use, copying or distribution of the code by the former employee or a third party. Infringement gives rise to civil remedies (damages, cessation, destruction of copies) and criminal penalties (art. L.335‑2 CPI) (Legifrance). For technical material, an infringement seizure (saisie‑contrefaçon) is the principal tool for urgently securing evidence and preventing further activity under judicial supervision.
Trade secrets
Act no. 2018‑670 transposing Directive (EU) 2016/943 protects information with economic value kept secret through reasonable confidentiality measures (art. L.151‑1 et seq. C. com.). Unlawful acquisition, use or disclosure may be prohibited and subject to civil remedies (injunctions, penalty payments, damages) (EUR‑Lex – Directive 2016/943) and (Legifrance – Commercial Code).
Potential criminal offences
- Misappropriation of entrusted property (abus de confiance) (art. 314‑1 C. pén.): misappropriation of property entrusted to someone, often recognised for data extracted contrary to instructions (Legifrance).
- Unauthorised access to and remaining in an information system, data extraction, reproduction and transmission (art. 323‑1 to 323‑3 C. pén.) where Git repositories, S3, etc. are copied (Legifrance).
- Disclosure of a manufacturing secret by an employee (art. L.1227‑1 C. trav.) where the code incorporates industrial know-how (Legifrance).
In practice, these classifications are not mutually exclusive. Copyright infringement, trade secrets and one or more computer offences are often combined. See also the specialist analysis of source-code theft and its criminal classifications.
Unfair competition and contractual breaches
Independently of specific legislation, the former employee or their new employer may incur tort liability for unfair competition (misappropriation of files, disruption) under art. 1240 C. civ. An NDA, a confidentiality clause or a non-compete clause further strengthens your options. To address these matters contractually, see our guidance on confidentiality agreements and non-compete/non-solicitation provisions in tech startups. For litigation strategy, our guide to taking action against unfair competition and free-riding details the evidence and quantified claims.
2) Procedures: criminal, civil and urgent interim relief
Criminal complaint
File without delay a complaint for misappropriation of entrusted property and computer offences with the public prosecutor or an investigating authority. Practical information is available on Justice.fr (filing a complaint, joining proceedings as a civil party). Criminal investigations allow searches, seizures and interviews, helping identify accomplices and the media used.
Civil interim proceedings and protective measures
In parallel, apply to the judge hearing interim applications for: a prohibition on using and disclosing the code, deletion of copies under a judicial officer's supervision (commissaire de justice), repository blocking, delivery of media, penalty payments and potentially appointment of an expert. Step-by-step business procedures are available on Service Public Pro — business guidance and court access information on Justice.fr. In infringement cases, an infringement seizure may be authorised to collect evidence and preserve the position.
Jurisdiction and time limits
- Jurisdiction: the Tribunal judiciaire (specialist IP divisions) for infringement/trade secrets; the commercial court may hear unfair competition claims between businesses.
- Time limits: in civil IP matters, infringement claims are generally subject to a 5-year limitation period from knowledge of the facts; criminal offences generally have a 6-year limitation period (Legifrance). Do not delay: technical evidence can disappear quickly.
3) Evidence: what to collect and how
- Logs and traces: export access logs (SSO, VPN, Git, cloud), CI/CD logs, DLP/EDR alerts and internal emails. Secure the timestamps.
- Judicial officer's report: certified captures of repositories, messaging systems, cloud spaces and returned media. The report is key for the judge hearing interim applications.
- Hashes, versions and comparisons: calculate version hashes, draw up a correspondence table (commits, branches, authors), and isolate identical snippets.
- Evidence deposit: deposit the code or its hashes with a trusted third party (INPI, evidential archiving/escrow solutions). See the options and good practices on the INPI website and the practical article on source-code intellectual property.
- Cyber hygiene: the DGSI lists the risks of failing to protect industrial software — encryption, access controls and policy reviews (DGSI).
For ongoing protection (copyright, documentation, traceability), see our guide to protecting a startup's source code.
4) HR issues: discipline and departure
- Preliminary disciplinary meeting and precautionary suspension if necessary.
- Serious misconduct (faute grave) is often established where extraction and use are unlawful.
- Return of equipment, badges and API keys; certification that copies have been erased.
- Contractual reminders: confidentiality, intellectual property and any non-compete clauses. See our guide to non-compete clauses.
5) GDPR: where personal data has “travelled” with the code
If personal data (test accounts, datasets) has been copied, you must assess the risk and, where applicable, notify the CNIL within 72 h and inform the individuals concerned. The detailed procedure is on the CNIL website. To govern transfers and processors, use our guide to DPAs (data processing agreements).
6) Litigation strategy: quantifying and obtaining relief
- In interim proceedings: immediate prohibition, deletion of copies, penalty payments, custody of media and appointment of an expert.
- On the merits: damages (R&D costs, lost opportunities, reputational harm), court-ordered publication, surrender of improper profits (a measure inspired by IP/trade-secret legislation).
- Against the new employer: joint action for complicity in infringement, trade-secret violations and unfair competition.
Case law and practice accept multiple legal grounds where the facts warrant them. A useful reminder of the offences is provided by Lexing.
7) Preventing recurrence: 10 measures to deploy
- Robust contractual clauses (IP, confidentiality, return of materials, competition): see when and how to use an NDA.
- Internal policies (security, classification, need‑to‑know, BYOD, employee departures).
- Access controls (SSO, MFA, PAM), logs and DLP.
- Open-source review and licences; software licence agreements.
- Escrow/evidential deposit (INPI, specialist solutions) and cryptographic hashes.
- DevOps traceability (repository owners, mandatory code reviews, merge policies).
- Segregated environments and anonymised data for test datasets (GDPR).
- Offboarding process (access checklist, recovery of secrets, rotation).
- Ongoing training on IP/trade secrets; CNIL and DGSI materials.
- Incident response plan combining legal and IT teams.
Formal demand template (key points)
In your letter, require: (i) immediate cessation of all use of the code; (ii) return of media and certified deletion of copies; (iii) provision within 24 h of a list of recipients and transfers; (iv) written confirmation under oath; (v) failing this, an application for interim relief and a criminal complaint.
Quick FAQ
Can we act if the former employee has not yet commercialised the code?
Yes. Acquisition or attempted unlawful use of a trade secret may already be prohibited; infringement covers unauthorised reproduction. Interim relief prevents harm.
What if the code is rewritten “from scratch” at a competitor?
Substantial similarity and traces of copying (structures, bugs, comments) suffice to establish infringement. Otherwise, appropriation of know-how may fall under trade secrets and unfair competition.
Must I report to the CNIL?
Only if personal data was involved (e.g. a customer database included in the repository). Follow the CNIL's 72 h procedure here.
How long do I have to act?
Act immediately. As a guide, civil infringement claims generally have a 5-year limitation period (knowledge of the facts), and criminal offences generally have a 6-year limitation period (Legifrance).
Should I negotiate a settlement?
A settlement is possible (return, undertakings, compensation). First make sure to preserve the position through interim relief and secure the evidence before any discussions.
Useful references: Legifrance (CPI, C. pénal, C. com., C. trav.), Directive (EU) 2016/943, CNIL, Justice.fr, Service Public Pro — business guidance, INPI, DGSI, Vaultinum, Lexing.
Further reading
Related resources
Frequently asked questions
FAQ
What should I do first if an employee copied the Git repository?
Immediately revoke their access, secure and export the logs, appoint a judicial officer to record the evidence, then initiate interim proceedings and a criminal complaint.
Is the code automatically protected?
Yes. Source code is protected as software under the CPI. Economic rights in employee-created software belong to the employer (art. L.113-9 CPI).
Must I choose between criminal and civil action?
No. Claims are often combined: criminal (misappropriation of entrusted property, unauthorised access), civil (infringement, trade secrets, unfair competition).
Can I act without complete proof of copying?
Yes. Seek an infringement seizure and investigative measures in interim proceedings to preserve evidence, with penalty payments and custody of media.
Must I notify the CNIL?
Only if personal data is involved. Assess the risk and notify within 72 h if necessary, in accordance with CNIL rules.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.