No Employee NDA? Your Trade Secret Claim May Still Survive
What You Need to Know
Key takeaway #1
A missing employee NDA does not automatically defeat a trade secret claim if the company can show it used other reasonable measures to protect confidential information.Key takeaway #2
Trade secret protection is evaluated holistically, so strong technical, physical, and procedural safeguards may help compensate for imperfect documentation.
Client Alert | 2 min read | 08.19.26
A Virginia federal court recently delivered a useful reminder for trade secret owners: a missing NDA is not automatically fatal if the company can show it treated the information as genuinely confidential. In WeightPack, Inc. v. Mitchell, No. 3:25-cv-927 (E.D. Va. July 23, 2026), the court denied a former employee’s motion to dismiss trade secret claims under both the Defend Trade Secrets Act (DTSA) and the Virginia Uniform Trade Secrets Act (VUTSA). The court held that the employer had plausibly alleged reasonable measures to protect secrecy even though the employee never signed a nondisclosure or confidentiality agreement.
The ruling comes at the pleading stage, so it is not a final determination that the information qualifies as a trade secret or that misappropriation occurred. But the opinion is still notable because it reinforces a practical point that courts assess secrecy measures holistically, not as a checklist. The absence of a single safeguard, even one as common as a non-disclosure agreement (NDA), is not necessarily dispositive.
WeightPack alleged that its confidential information included a large body of technical and commercial data — drawings, schematics, control software, machine designs, and customer and pricing information. The former employee moved to dismiss, arguing in part that the company had not adequately alleged trade secret protection because he was never required to execute an NDA or confidentiality agreement.
The court rejected that argument. It pointed to a series of protective measures that WeightPack alleged it had in place, including:
- Storing trade secrets on a controller server, a managed cloud drive, and a virtual private network (VPN) connected server, each requiring authorized usernames and passwords.
- Keeping the onsite server in a locked room.
- Maintaining and communicating a company-wide policy requiring employees to conduct business only on company-issued devices and accounts.
- Providing employees with company laptops, phones, and email accounts.
- Immediately revoking access credentials and retrieving company devices upon termination.
Taken together, the court found that the absence of a signed confidentiality agreement did not change the fact that the company had taken significant, reasonable measures to protect the secrecy of its information. This makes the case particularly useful for companies that, for whatever reason, do not have perfect paperwork in place. WeightPack suggests that a company can still be in a strong position if it can point to layered protections: technical access controls, physical safeguards, device-use policies, and disciplined offboarding procedures.
The best practice, of course, remains to use well-drafted confidentiality and IP agreements whenever possible — WeightPack is not a reason to abandon them. It is better read as reassurance that trade secret protection is judged by substance as well as form. When a company consistently restricts access, communicates expectations, controls devices and systems, and acts decisively at termination, a court may find that reasonable measures were taken even without a signed NDA.
Contacts
Insights
Client Alert | 7 min read | 08.19.26
CMS’s Final Rule Bans Federal Medicaid Funding for Youth Gender-Affirming Care
On August 13, 2026, the Centers for Medicare and Medicaid Services (CMS) published its final rule banning the use of federal funds — through Medicaid and the Children’s Health Insurance Program (CHIP) — to pay for gender-affirming care for children and youth. The final rule takes effect October 13, 2026 (“Prohibition on Federal Medicaid and Children's Health Insurance Program Funding for Sex-Rejecting Procedures Furnished to Children”). While CMS finalized several key elements of its late-2025 proposed rule (Client Alert December 24, 2025), the proposed Medicare hospital Condition of Participation rule remains in proposed form.
Client Alert | 7 min read | 08.17.26
Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule
Client Alert | 4 min read | 08.14.26
License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations
Client Alert | 4 min read | 08.13.26
Supreme Court Confirms Contractual Loss of Bargain Without Repudiatory Breach


