Quick answer
Act quickly, but do not retaliate or lock out a co-owner without checking the company’s governing documents and authority structure.
A business partner’s use of company clients or confidential information may support claims for breach of contract, breach of fiduciary duty, accounting and return of profits, damages, injunction, or—in appropriate cases—data-privacy or cybercrime violations. The correct remedy depends on whether the business is a corporation, partnership, or sole proprietorship; whether the person is a director, officer, employee, or shareholder; what the contracts say; how the information was obtained and used; and whether clients’ personal data was exposed.
The company does not automatically “own” a client’s freedom to choose a provider. Ordinary competition or contacting people known through personal relationships is not necessarily unlawful. The case becomes stronger when the person diverts an existing company opportunity, misrepresents affiliation, uses restricted records or systems, breaches a valid confidentiality or non-solicitation clause, or secretly earns from transactions that should have belonged to the business.
Your immediate priorities are to:
- stop further unauthorized access without destroying evidence;
- preserve reliable copies of records and system logs;
- identify who legally owns the claim;
- assess any personal-data breach;
- document lost business and diverted profits; and
- obtain urgent legal advice if solicitation, disclosure, deletion, or client transfers are continuing.
First determine what “business partner” legally means
The label used in conversation is not decisive. Check the Securities and Exchange Commission records, articles, bylaws, partnership agreement, shareholders’ agreement, employment or consultancy contract, and board resolutions.
If the business is a corporation
A shareholder does not personally own corporate clients, records, goodwill, or causes of action merely because the shareholder invested in the company. Those assets and claims generally belong to the corporation.
Directors and officers may owe duties of loyalty to the corporation. Section 30 of the Revised Corporation Code can impose personal liability where directors or trustees, among other things, act in bad faith or acquire a personal or pecuniary interest conflicting with their duty. Section 33 requires a director who acquires for himself or herself a business opportunity that should belong to the corporation—and thereby earns profits to its prejudice—to account for and refund those profits, unless the act is ratified by shareholders representing at least two-thirds of the outstanding capital stock. See the Revised Corporation Code, Republic Act No. 11232.
The Supreme Court has applied the corporate-opportunity doctrine where corporate insiders encouraged the company’s brokers to move clients to a competing enterprise. It has also emphasized that liability depends on the person’s duty, the nature of the opportunity, and the proven prejudice to the corporation. See Gokongwei-related corporate-opportunity ruling, G.R. Nos. 200070-71 and Stronghold Insurance Company, Inc. v. Cuenca, G.R. No. 189158.
Normally, the board must decide whether the corporation will demand an accounting or sue. A shareholder considering a derivative action should obtain specific advice before filing. The special rules require, among other matters, that the plaintiff was a shareholder or member when the challenged acts occurred, exerted reasonable efforts to exhaust internal remedies, had no appraisal right available for the complained-of act, and brought the case for the corporation rather than for harassment. Derivative and other intra-corporate cases are governed by A.M. No. 01-2-04-SC and are heard by the appropriate designated Regional Trial Court.
If the business is a legal partnership
The Civil Code imposes direct duties among partners:
- A partner must provide true and full information about matters affecting the partnership.
- A partner must account for benefits and hold in trust for the partnership profits obtained without the other partners’ consent from partnership transactions or use of partnership property.
- A capitalist partner generally may not conduct the same kind of business for his or her own account unless the agreement allows it. Unauthorized profits must be brought into the common fund, while losses are personally borne.
- An industrial partner generally may not engage in business for himself or herself without the partnership’s express permission.
- A partner may demand a formal accounting in the circumstances stated by law.
These rules appear principally in Articles 1789 and 1806–1809 of the Civil Code, Republic Act No. 386.
Do not assume, however, that one partner may unilaterally expel another, seize that partner’s property, dissolve a fixed-term partnership, or cut off all access. Management and dissolution rights depend on the partnership agreement and the Civil Code.
If “partner” only means employee, consultant, distributor, or collaborator
The dispute may primarily be contractual. Review confidentiality, intellectual-property, data-processing, return-of-property, conflict-of-interest, exclusivity, non-solicitation, and post-termination provisions.
A post-employment restraint is not automatically valid merely because it appears in a signed agreement. Philippine courts examine whether a restraint is reasonably limited and no broader than necessary to protect a legitimate business interest. Restrictions may be vulnerable if their duration, territory, activity, or practical effect is excessive. See Tiu v. Platinum Plans Philippines, Inc., G.R. No. 163512.
When a client list or business record is genuinely confidential
Not every collection of names is a protectable secret. A claim is more credible when the information:
- is not publicly available or readily reconstructed;
- includes non-public contacts, pricing, purchase history, requirements, credit terms, margins, proposals, renewal dates, or decision-maker notes;
- has commercial value because competitors do not know it;
- was obtained through the person’s company role;
- was stored behind access controls or marked confidential;
- was covered by a confidentiality policy or agreement; and
- was disclosed only to people who needed it for company work.
Protection is weaker where the information came from public directories, the client independently approached the departing person, the company freely circulated the information without restrictions, or the supposed “list” consists only of names remembered from ordinary dealings.
Even without a standalone claim based solely on the label “trade secret,” misuse may violate a contract, fiduciary obligations, privacy law, intellectual-property rights, or the general Civil Code duties to act with justice and good faith. The precise cause of action must be matched to the proven facts.
What to do immediately
1. Preserve the situation before confronting anyone
Create a written incident timeline identifying:
- when the suspected activity began;
- who discovered it and how;
- the systems, accounts, files, and clients involved;
- each observed download, export, forwarding event, deletion, or login;
- client communications or transfers already confirmed; and
- the steps taken in response.
Ask qualified IT personnel or a forensic professional to preserve relevant email, CRM, cloud-storage, accounting, access-control, and device logs. Preserve metadata and original files where possible. A screenshot alone may omit the sender, timestamp, URL, headers, or other authentication details.
Electronic evidence must still satisfy admissibility and authentication requirements. The person presenting an electronic document bears the burden of proving authenticity under the Rules on Electronic Evidence, A.M. No. 01-7-01-SC.
Do not alter, annotate, or repeatedly open the only copy. Record who collected each item, from where, on what date, and how it was stored.
2. Secure company-controlled systems
Subject to the person’s legal authority and the company’s access policies:
- reset or revoke compromised credentials;
- terminate unauthorized sessions and API tokens;
- preserve logs before disabling or reconfiguring accounts;
- restrict bulk exports and forwarding;
- rotate shared passwords;
- secure physical files and backup media;
- review administrator and remote-access privileges; and
- notify relevant service providers to preserve account records.
Avoid entering a partner’s personal phone, email, cloud account, or social-media account without consent or lawful authority. Evidence obtained through unauthorized access can create separate civil, privacy, or cybercrime exposure.
Where the person remains a director, officer, partner, or authorized user, have counsel assess whether a board resolution, partners’ vote, or other formal approval is required before access is restricted. A technically possible lockout is not necessarily a legally valid one.
3. Collect the governing documents
Preserve complete, signed copies of:
- articles of incorporation or partnership;
- bylaws and shareholders’ or partnership agreements;
- board and partners’ resolutions;
- employment, consultancy, distribution, and data-processing contracts;
- confidentiality and non-solicitation agreements;
- privacy notices and security policies;
- acceptable-use and monitoring policies;
- client contracts, proposals, and account histories;
- intellectual-property assignments; and
- exit clearances, equipment acknowledgments, and return-of-information certifications.
Check dispute-resolution clauses carefully. A contract may require notice, negotiation, mediation, or arbitration before court proceedings, although urgent interim relief may sometimes remain available.
4. Identify exactly what was taken and how it was used
Build an itemized evidence table. For each file or client, record:
- the company source;
- why the material was confidential;
- who had authorized access;
- the suspected access or transfer;
- the competing communication or transaction;
- the client’s response;
- revenue, costs, and expected margin;
- the wrongdoer’s apparent benefit; and
- the supporting documents and witnesses.
Separate confirmed facts from inference. A customer’s departure by itself does not prove that confidential information was taken.
5. Consider a carefully drafted demand
Counsel may send a demand requiring the recipient to:
- stop using or disclosing identified information;
- preserve relevant devices, accounts, messages, and records;
- return company property;
- identify recipients of the information;
- confirm deletion of unauthorized copies after preservation obligations are addressed;
- stop making false claims of company authority;
- provide an accounting of diverted transactions and profits; and
- comply with contractual dispute procedures.
A demand should be specific enough to identify the conduct without disclosing more personal or confidential information than necessary. It should not demand immediate destruction of evidence that may be needed in litigation.
6. Communicate with clients cautiously
A neutral notice may be appropriate where clients must verify authorized representatives, redirect payments, reset portal access, or protect personal information. Keep it factual.
Do not publicly accuse the person of theft, fraud, or a crime before the facts and legal basis are established. Avoid publishing internal allegations, client details, or personal data. A reckless announcement can worsen the dispute and create defamation or privacy exposure.
Check whether personal data was involved
Client data may include personal information even in a business-to-business database—for example, an individual contact’s name, mobile number, email address, signature, identification document, bank information, or transaction history.
Under the Data Privacy Act of 2012, Republic Act No. 10173, an organization controlling personal data must use reasonable and appropriate organizational, physical, and technical safeguards. Unauthorized processing, access, use, or disclosure may lead to administrative, civil, or criminal consequences depending on the facts.
Immediately involve the company’s data protection officer or privacy lead. Determine:
- what personal data was affected;
- whether access, acquisition, disclosure, alteration, loss, or destruction was unauthorized;
- whose data was involved;
- whether sensitive personal information or information enabling identity fraud was included;
- whether the incident is likely to create a real risk of serious harm;
- whether the data was encrypted or otherwise rendered unusable; and
- when the company acquired knowledge or reasonable belief of the breach.
Under NPC Circular No. 16-03, notification to the National Privacy Commission and affected data subjects is mandatory when the regulatory conditions are met. The notification generally must be made within 72 hours from knowledge of, or reasonable belief that, a personal-data breach occurred. Available information may be submitted within that period and supplemented as permitted. Do not wait for absolute certainty if the mandatory-notification threshold appears satisfied.
The NPC requires personal-data breach notifications and annual security incident reports through its Data Breach Notification Management System. Its official breach-reporting guidance explains the notification framework.
Not every misuse of a company file is a mandatorily reportable personal-data breach. Conversely, the existence of a business dispute does not excuse privacy compliance. Have the data protection officer and counsel document the threshold analysis even if they conclude that notification is not required.
An affected individual may also use the NPC’s official complaint procedure. A company’s commercial claim and an individual’s data-privacy complaint are distinct matters.
When cybercrime may be involved
The Cybercrime Prevention Act of 2012, Republic Act No. 10175, covers conduct including access to a computer system without right, data interference, and specified misuse of devices or access credentials.
Possible warning signs include:
- accessing company systems after authority was revoked;
- using another person’s password;
- bypassing security controls;
- deleting or altering records without right;
- installing tools intended to capture credentials; or
- damaging data or systems to conceal activity.
A mere breach of an internal policy does not automatically prove a cybercrime. Whether access was “without right,” and whether the required intent or other statutory elements existed, must be established from the authority granted, system records, and surrounding facts.
Do not attempt to recover evidence by hacking the suspected person’s accounts or secretly installing intrusive software. For suspected cybercrime, counsel can coordinate with the National Bureau of Investigation or Philippine National Police, the law-enforcement agencies identified by the Act. The Department of Justice’s Office of Cybercrime also provides government information on cybercrime complaints and referrals.
Possible civil remedies
Depending on the legal relationship and evidence, remedies may include:
- enforcement of confidentiality, return-of-property, non-solicitation, or other valid contractual obligations;
- damages for proven losses caused by breach;
- an accounting of transactions and profits;
- return or disgorgement of profits obtained through a partnership transaction, partnership property, or corporate opportunity;
- recovery of company records or property;
- declaratory relief concerning authority or contractual rights;
- dissolution, buyout, or other governance relief where legally available;
- protection against misleading representations or misuse of company branding; and
- a temporary restraining order or preliminary injunction.
An injunction is not automatic. Under Rule 58 of the Rules of Court, the applicant must establish a present right requiring protection and an actual or threatened violation that may cause serious or irreparable injury. The application must be verified, and the court generally requires an injunction bond. Courts will not issue an injunction merely because competition is inconvenient or damages are alleged in general terms.
Urgent applications should identify the specific information, accounts, conduct, or client communications to be restrained. An overbroad request to prohibit all competition may fail even where narrower protection is justified.
Who should bring the claim
Correct standing is essential:
- A corporation ordinarily brings a claim for injury to corporate assets, opportunities, or profits.
- An authorized representative must act for the corporation under proper corporate authority.
- A shareholder may bring a personal claim only for a direct injury distinct from the corporation’s injury.
- A qualifying derivative action is brought on the corporation’s behalf when management wrongfully refuses or is unable to protect it.
- A partnership may sue over partnership property and transactions, while a partner may seek an accounting or enforce rights granted by the agreement and Civil Code.
- Clients or other data subjects may separately assert their own privacy or contractual rights.
Filing in the wrong plaintiff’s name can result in dismissal or delay. Before sending a demand or commencing proceedings, confirm who owns the information and claim, who can authorize counsel, and whether the dispute is intra-corporate or an ordinary civil action.
Deadlines should not be guessed
The limitation period depends on the cause of action, not the general description “client stealing.”
Under the Civil Code, an action based on a written contract or an obligation created by law generally must be brought within 10 years from accrual, while an action based on injury to rights or quasi-delict generally must be brought within four years. Other claims, offenses, administrative proceedings, or contractual mechanisms may have different periods and triggering dates. Continuing conduct does not necessarily restart the period for every earlier act.
Do not treat these general periods as a reason to wait. Delay can cause:
- deletion or overwriting of logs;
- loss of witnesses;
- further client transfers;
- arguments that secrecy was not seriously protected;
- difficulty proving causation and damages; and
- loss of any realistic basis for emergency injunctive relief.
Ask counsel to identify the applicable deadline for each proposed claim as soon as the essential facts are known.
Evidence worth preserving
Preserve lawful, complete copies of:
- CRM export and audit logs;
- email headers and forwarding rules;
- cloud-storage access and sharing records;
- login history, device identifiers, and administrator logs;
- file versions and deletion records;
- messaging-app exports obtained from authorized company accounts;
- client instructions, cancellations, and transfer requests;
- proposals, invoices, purchase orders, and payment records;
- meeting minutes and approvals;
- confidentiality markings and access-control records;
- training acknowledgments and policy receipts;
- evidence showing how the information was developed and protected;
- the suspected competing entity’s lawful public representations; and
- records supporting lost revenue, avoided costs, and profit margins.
Forensic collection should be proportionate and privacy-conscious. Preserve only what is relevant and legally accessible, restrict the evidence repository, and document every transfer.
Common mistakes
Treating clients as property
Clients may choose whom to hire. The legal issue is usually the method used to obtain or divert the business—not the mere fact that a client moved.
Relying only on an NDA label
Calling every file “confidential” does not prove secrecy. Show the information’s content, commercial significance, restricted access, and actual protective measures.
Taking matters into your own hands
Do not seize personal devices, impersonate the suspected person, enter private accounts, threaten family members, or publish accusations.
Destroying evidence while trying to contain the incident
Preserve logs, mailboxes, file versions, and relevant devices before routine retention policies overwrite them. A deletion demand should account for litigation-preservation needs.
Locking out a co-owner without authority
A partner, director, or officer may have governance or inspection rights. Use valid corporate or partnership procedures and tailor restrictions to the actual security risk.
Contacting clients with an inflammatory accusation
Use a verified, need-to-know notice. Do not pressure clients to give a preferred statement or reveal another person’s private information.
Claiming all projected revenue as damages
Lost profits must be supported by evidence and causation, not speculation. Track historical purchases, committed orders, margins, cancellation reasons, replacement business, and diverted receipts.
Assuming a criminal complaint will resolve the commercial dispute
Criminal, privacy, corporate, contractual, and employment issues have different elements and remedies. A criminal complaint should not be used merely as leverage in a private payment or ownership dispute.
When legal help is urgent
Seek same-day advice from a Philippine lawyer experienced in corporate or partnership disputes, privacy, and technology when:
- files are still being downloaded, deleted, or disclosed;
- the person retains administrator access;
- sensitive personal information or identity documents may be exposed;
- the 72-hour breach-notification period may be running;
- clients are being told to redirect payments;
- the person is impersonating the company or using its accounts;
- a major contract, regulated record, or source code is involved;
- an upcoming board or partners’ meeting may change control;
- company funds or opportunities are being diverted;
- you may need a temporary restraining order; or
- there is a threat to destroy evidence.
Bring the lawyer a concise timeline, entity documents, contracts, a list of affected systems and clients, preserved evidence, and the names and roles of the people involved.
Frequently asked questions
Can a business partner contact company clients after leaving?
Possibly. Clients remain free to choose, and general competition is not automatically unlawful. Liability may arise if the former partner uses protected information, violates a reasonable contractual restriction, misrepresents company affiliation, or exploits a partnership transaction or corporate opportunity in breach of an existing duty.
Is a client list automatically a trade secret?
No. Protection depends on what the list contains, whether the information is genuinely non-public and commercially valuable, how it was obtained, and whether the business took reasonable measures to keep it confidential.
Can we immediately disable the partner’s access?
You should contain unauthorized access, but the method must respect the person’s continuing governance, contractual, and inspection rights. Preserve evidence first and obtain the required corporate or partnership authorization whenever feasible. Emergency restrictions should be documented and narrowly tailored.
Can we inspect the partner’s personal phone or email?
Not without consent or another lawful basis. Ownership of the business does not create unlimited authority over another person’s private accounts or devices. Preserve company-side records and seek lawful forensic or court-assisted processes.
Should we report the incident to the National Privacy Commission?
Only after applying the statutory and regulatory breach-notification criteria—but do that assessment immediately. If mandatory notification is triggered, the general deadline is 72 hours from knowledge of or reasonable belief in the breach, not from completion of the investigation.
Can the company recover the partner’s profits?
Potentially. A legal partnership may demand an accounting and return of benefits or profits covered by Articles 1807 and 1808 of the Civil Code. A disloyal corporate director who appropriates a qualifying corporate opportunity may have to account for and refund profits under Section 33 of the Revised Corporation Code. The result depends on the person’s role, consent or ratification, the source of the opportunity, and proof of profits and prejudice.
Is a non-solicitation or non-compete clause always enforceable?
No. Courts examine the wording, legitimate interest protected, scope, duration, territory, and practical restraint. A narrowly tailored confidentiality or non-solicitation obligation may be easier to justify than a blanket ban on earning a livelihood, but enforceability remains fact-specific.
Do we need to prove actual lost clients before asking for an injunction?
Not necessarily, but you must show a clear existing right and an actual or threatened violation creating the kind of serious or irreparable injury that warrants provisional relief. Suspicion, generalized fear of competition, or an unidentified claim of confidentiality is ordinarily insufficient.
Official legal references
- Civil Code of the Philippines, Republic Act No. 386
- Revised Corporation Code, Republic Act No. 11232
- Data Privacy Act of 2012, Republic Act No. 10173
- Data Privacy Act Implementing Rules and Regulations
- NPC personal-data breach guidance
- Cybercrime Prevention Act of 2012, Republic Act No. 10175
- Rules on Electronic Evidence, A.M. No. 01-7-01-SC
- Interim Rules for Intra-Corporate Controversies, A.M. No. 01-2-04-SC
- Rules of Court, including Rule 58 on injunctions
This article provides general Philippine legal information, not legal advice or a prediction of any case’s outcome. Rights and remedies depend on the entity documents, contracts, authority records, data involved, and admissible evidence. Official sources and procedures were checked as of 3 September 2026.