Add The Wire As Your Trusted Source
For the best experience, open
https://m.thewire.in
on your mobile browser.
AdvertisementAdvertisement

IP Proceedings or Fishing Expeditions? A Bombay HC Privacy Shield for the Cloud Era

The court’s message seemed pretty clear, that suspicion by itself does not justify rummaging through the cloud storage of a third party.
The court’s message seemed pretty clear, that suspicion by itself does not justify rummaging through the cloud storage of a third party.
ip proceedings or fishing expeditions  a bombay hc privacy shield for the cloud era
Illustration: The Wire, with Canva.
Advertisement

On March 30, 2026, the Bombay high court passed a fairly calm but still consequential order, something that may end up nudging how Indian courts deal with digital evidence inside intellectual property fights. The matter, UBS Business Solutions v. Nisheet Singh, kind of turned on a straightforward issue: basically how far an employer can go when ‘searching’ for alleged trade secret theft across a former employee’s cloud accounts.

The court’s take: not so far that it would count as a proper fishing expedition.

The cloud discovery question

UBS Business Solutions sued its former employee, Nisheet Singh, claiming copyright infringement tied to its proprietary software platforms, “OneHRIS” and “MyShop”. The firm had already secured a court-appointed specialist from FTI Consulting, along with a court receiver (an officer appointed by the court to take temporary custody and control of the 18 devices belonging to Singh) to oversee the secure deletion of the company’s confidential data from those devices. That deletion process, for the most part, proceeded without incident.

Still, UBS wasn’t done. It wanted access to three cloud accounts linked to Singh, this time from his earlier workplaces. Their theory, though, was based on suspicion, not hard proof, that the data might actually be sitting there.

Advertisement

Justice Gauri Godse did not go along. “In the absence of any nexus of plaintiff’s confidential data with the cloud accounts or in the absence of any apprehension expressed that the confidential data of the plaintiff is likely to have been stored on the third party’s cloud accounts, I do not see any reason to issue any directions,” the court said.

The ‘nexus’ requirement

Advertisement

The court’s message seemed pretty clear, that suspicion by itself does not justify rummaging through the cloud storage of a third party – in this case, Intellibonds Limited, a former employer of Singh’s, whose cloud accounts UBS sought to access without any concrete evidence that his data resided there.

It’s also an important curb in a time where digital traces are, well, everywhere, and employers often ask for broad forensic access. The ruling, at least in practice, seems to recognise that without limits, intellectual property proceedings can slide towards digital harassment, something that hits hardest when someone moves between rival firms.

Advertisement

That said, the door was not shut completely. Singh’s LinkedIn page showed he ‘owned’ a startup named Legal and Compliance and Whistle Blower Protection Private Limited, which was said to operate one of the three cloud accounts UBS was seeking access to. So the court found it “not believable” that he wouldn’t have access to that account. As a result, Singh was told to file an affidavit of disclosure regarding the entity’s cloud account.

Advertisement

Illustration: Pariplab Chakraborty.

Illustration: Pariplab Chakraborty.

For Singh, counsel Ashutosh Srivastava argued that UBS’s request was an unsupported and intrusive demand on his client’s digital privacy, especially after FTI Consulting had already carried out the “irreversible and secure deletion” from the main devices. The court agreed that the missing concrete material meant Singh, and his prior employers, could not be dragged into speculative requests.

In his disclosure affidavit filed on April 27, Singh claimed that he “inadvertently and casually” mentioned that he owned Legal and Compliance and Whistle Blower Protection. There is no entity in operation with that name and ‘there is no user name, password or login credentials’, the high court cited him as saying. It ruled that the issues UBS raised in its application are open to be decided at trial.

The trade secret vacuum

This ruling also matters in light of India’s uneven trade secret landscape. At the moment, trade secrets are protected through a patchwork of provisions rather than a dedicated statute. Protection flows mainly from contract tools (including non-disclosure agreements), the equitable doctrine of breach of confidence and criminal provisions found in the Bharatiya Nyaya Sanhita along with the Information Technology Act, 2000.

Because the structure is piecemeal, uncertainty follows. There is no single statutory meaning of a “trade secret”, no consistent benchmark for “reasonable measures” required to keep secrecy intact and no unified enforcement apparatus. So outcomes can end up inconsistent, and the system becomes more reactive than preventive.

The 22nd Law Commission of India, in its 289th report titled “Trade Secrets and Economic Espionage” published in March 2024, expressly noted this gap, and it suggested a draft Protection of Trade Secrets Bill, 2024. The draft proposes a three-part definition of a trade secret, echoing Article 39 of the TRIPS Agreement: the information is not generally known, it has commercial worth because it stays secret and it is guarded by reasonable confidentiality practices.

Under the Bill, civil remedies would include injunctions, damages and accounts of profits. It would also carve out exceptions for reverse engineering, independent discovery and whistleblower protection.

Importantly, the commission recommended that Rules framed for the Bill if it is passed should bring in the concept of confidentiality clubs, which allow the analysis of confidential information filed before the court in a sealed cover by limiting access to a few people, including representatives from both sides in a litigation in addition to experts. This means courts could shield sensitive material while still deciding the dispute.

However, the government is yet to act on the draft Bill. Until then, courts are basically improvising boundaries for the digital era precisely what Justice Godse did in UBS v. Nisheet Singh.

A privacy shield for the cloud era

Indian courts have consistently held that non-compete clauses – which seek to restrain someone from competing with a former employer – are unenforceable after employment ends under Section 27 of the Contract Act, 1872. Confidentiality duties can still survive, but only if they are kept narrowly framed and not pushed too wide a net. In Hi-Tech Systems v. Suprabhat Ray (Calcutta high court, 2015), the idea was that trade secrets get real protection when misuse gives someone a kind of “springboard” benefit.

That said, ordinary know-how or routine skills can’t be locked up in a monopolistic way.

Now the UBS decision seems to add another layer here: employers cannot simply access third-party cloud accounts unless there is a particularised suspicion, not just a generic feeling. This “nexus” requirement fits with Arjan Dugal (2025), where client databases were shielded, and also with Varun Tyagi (2025), which pushed back against overly broad non-competes.

The balance struck is twofold: it protects employees and former employees from digital harassment and unwarranted privacy intrusions, while also shielding unrelated third-party entities from being dragged into speculative discovery requests by litigants. In essence, the ruling affirms that trade secret protection does not entitle employers to conduct digital espionage against individuals or their previous workplaces without evidentiary justification.

Why this matters

India’s GDP is growing at around 6.5%, yet the absence of a dedicated trade secrets statute, a legislative feature present in jurisdictions like the USEU and China which leaves fintech, pharma and AI companies vulnerable to misappropriation. The UBS ruling, at least for now, offers a sort of stopgap by trying to prevent litigation from turning into digital harassment. For employees, a former employer can’t go rummaging through unrelated cloud storage on suspicion alone. For employers, if they want forensic access, the requests must be specific and backed by evidence, not just suspicion written down.

The next hearing was scheduled for June 15 (a soft copy of the proceedings are awaited on the high court’s website). Justice Godse’s “nexus” ruling likely stays in place, and the 289th Law Commission Report has already laid some groundwork. But until parliament moves, courts will keep trying to fill the gap as best as they can.

Sakkcham Singh Parmaar is a third-year BA LLB (Hons.) student at Jindal Global Law School.

This piece was first published on The India Cable – a premium newsletter from The Wire – and has been updated and republished here. To subscribe to The India Cable, click here.

This article went live on June nineteenth, two thousand twenty six, at twenty-three minutes past two in the afternoon.

The Wire is now on WhatsApp. Follow our channel for sharp analysis and opinions on the latest developments.

Advertisement
Advertisement
tlbr_img1 Series tlbr_img2 Columns tlbr_img3 Multimedia