TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Case Studies/Corporate
№ 271 Case Study — Corporate

A one-page audit report and a laptop that would not stay quiet

A Sault Ste. Marie company hiring its first outside executive found unusual file transfers on a departing contractor's laptop. The fix that actually worked was not the one anyone expected.

Corporate8 min readSault Ste. Marie, OntarioWhen confidential information walks out
All Corporate case studies
ClientNasrin, owner of a small company about to make its first executive hire
The issueA contractor's laptop showed large file transfers just before he gave notice
ServiceAssessed the exposure, secured the practical fix, then used a demand letter to lock it in
ResolutionPartial win: the files came back and the contractor signed new terms, but the company accepted it could not prove intent

The situation

The report was one page, printed off a routine access-log audit, and it sat on Nasrin's desk for two days before she called anyone about it. It listed three folders and a set of timestamps: client pricing sheets, a draft supplier agreement, and a spreadsheet of margins by product line, all copied to an external drive over a single evening the week before. The name attached to the login was Jamal, a contractor who had been doing systems work for the company for just over a year and who had, three days earlier, given two weeks' notice.

Nasrin ran a small operation, under a dozen people, and had built it up from nothing after years working as an administrative assistant for a larger firm where she had watched decisions get made without her. She was in the middle of interviewing for the company's first outside executive hire, a vice-president role that would bring someone senior in from outside the founding group for the first time, and she had spent the previous month drafting a confidentiality and non-solicitation package for that role. The irony was not lost on her that the breach, if that was what it was, had come from someone already inside.

Jamal had signed a standard contractor agreement when he started, one with a short confidentiality clause buried in the middle of a longer document about deliverables and invoicing. It said little about what happened to company data after the engagement ended. When Nasrin asked him directly what the files were for, he said he had copied them to back up his own work in case anything was disputed about hours billed, and that he had not shared them with anyone. His partner Marieke, an early childhood educator with no connection to the company, was not involved, but Nasrin found herself wondering, unfairly, whether Jamal had mentioned the pricing sheets at home.

Nasrin's instinct was to send a strongly worded letter threatening legal action and demand the drive be handed over immediately. Her fear was that Jamal was taking the numbers to a competitor, or worse, to whichever company hired him next. But she also knew that a public dispute with a contractor, in a town where business relationships overlap constantly, would follow her into the executive search she was mid-way through. She needed the files back, and she needed to know whether the confidentiality clause she had drafted for the new VP would have stopped this from happening at all.

The legal question

The company's exposure turned less on what Jamal had actually done and more on what could be proven and what the existing contract actually said. A confidentiality clause that never defines what counts as confidential, or that says nothing about copying data to personal devices, is difficult to enforce even when the facts look bad. A business does not have to show a loss it has already suffered in dollars before going to court over leaked information. It does have to show the information was genuinely confidential, that it took reasonable steps to protect it, that the person who took it was under an obligation not to use or disclose it, an obligation that can come from a contract or from the circumstances in which the information was shared, and that the misuse causes it real harm; for an injunction in particular, the court will want to see harm that money cannot repair afterwards. Nasrin's existing contractor agreement made two of those points weak.

The margin spreadsheet and the draft supplier agreement were plainly sensitive, but the pricing sheets had, at one point, been shared informally with a client during a negotiation, which complicated any argument that the company had treated them as strictly confidential throughout. That did not mean the company had no case. It meant the case rested more on the act of copying itself, without authorization and without a stated business reason at the time, than on the contents of the files.

The harder question was what Nasrin actually wanted. Litigation to force forensic imaging of Jamal's personal drive, and a court order compelling deletion, was possible in principle but slow, expensive relative to the size of the company, and almost certain to become known locally regardless of how it resolved. Nasrin's real goal was narrower: get the copies destroyed, get written assurance they had not been shared, and make sure the new VP's contract closed the gap that had let this happen in the first place. That reframed the matter from a dispute to be won into a risk to be contained.

There was also a quieter problem. If the pricing information had already been shown to a client in the ordinary course of business, then the company's own practices, not Jamal's contract, were part of why the information was less protected than Nasrin assumed. Fixing the contract for the new hire would do nothing unless the company also changed how it handled sensitive documents day to day, which was a business decision, not a legal one, and it was the piece that ended up mattering most.

What we did

  1. Reviewed the existing contractor agreement line by line to establish what Jamal was actually bound by, rather than what Nasrin assumed the standard template covered. The confidentiality clause turned out to be generic and undated, which meant any demand had to be framed carefully to avoid overstating the company's legal position and undermining its credibility if the dispute escalated further.
  2. Assessed the strength of a claim for return and destruction of the copied files against the cost and visibility of pursuing it, weighing the value of the information against what a dispute would cost in legal fees, time, and reputation in a business community where Nasrin still needed referrals. We advised that a firm but measured letter, not litigation, matched the actual risk.
  3. Drafted a demand letter setting out the specific files copied, the dates, and what the company required: written confirmation the data had not been shared, permanent deletion from all personal devices and any backup, and a signed acknowledgment of ongoing confidentiality obligations that would survive the end of the engagement. The letter avoided accusing Jamal of wrongdoing outright, keeping the door open to a clean resolution.
  4. Recommended the non-legal fix that ended up doing the real work: before the letter went out, we suggested Nasrin have her office manager revoke Jamal's remote access immediately and change the credentials for the systems he had used, something that should have happened the day he gave notice. This was not a legal step, but it closed the practical exposure faster than any letter could, and it meant the legal work that followed was about locking in the fix, not creating it.
  5. Negotiated directly with Jamal once he retained his own advice, reaching a written agreement rather than pushing for an admission of wrongdoing. Jamal maintained the copying was for legitimate backup purposes, but agreed to certify deletion and sign a clarified confidentiality undertaking, which the company accepted as sufficient given the limited proof available either way. We advised Nasrin that pushing further without stronger evidence of misuse risked turning a containable situation into an expensive and public dispute for little added certainty.
  6. Rebuilt the confidentiality and data-handling terms for the incoming VP role from scratch, defining what counted as confidential information, requiring return or destruction of company data at the end of any engagement, and prohibiting copying to personal devices without written approval, closing the specific gap the incident had exposed. We also added a term addressing what happens to information the VP would inevitably carry in memory rather than on a device, since a contract that only covers files misses the harder, more common way sensitive knowledge actually travels.
  7. Advised on a short internal policy for contractors generally, covering access revocation timing and device handling on notice of departure, so the fix did not depend on someone remembering to think of it the next time. The policy also set out who at the company was responsible for triggering the checklist when a contractor's engagement ended, since the original gap had partly come from no one owning that step.

The outcome

Jamal signed the certification and the clarified undertaking within two weeks, and the matter closed without litigation. The company never obtained forensic proof that the files had not been shared elsewhere, and Nasrin accepted, on our advice, that this was a limit she could not fully close through legal means alone. That is the partial part of the outcome: the paperwork was tightened and the immediate risk was contained, but the underlying uncertainty about what happened to the copied data before deletion was never fully resolved, and could not have been without a level of forensic investigation that the size of the dispute did not justify, and that Nasrin decided, on balance, was not worth the cost or the exposure of pursuing.

What did change was the company's contract with its incoming vice-president, which now specifies confidentiality obligations in enough detail to be enforceable rather than aspirational, and a data-handling practice that treats access revocation as a same-day step rather than an afterthought. Nasrin also changed how the company shared pricing information with clients, keeping a tighter record of what was disclosed and when, which closed the gap that had weakened the original claim. The internal contractor policy we drafted was rolled out to the two other contractors then working with the company, so the fix applied beyond the one relationship that had prompted it.

The executive search proceeded without becoming a local story, which was the outcome Nasrin cared about most. Roughly two months after the letter, the new VP started, working under the revised terms, and the onboarding conversation about confidentiality was, for the first time, a substantive one rather than a page to initial and forget. Jamal, for his part, moved on to a role elsewhere in the region, and the two have had no further contact through the company. Nasrin still does not know for certain whether the files were ever used, and has made peace with the fact that some risks in a small, close business community get managed rather than fully eliminated. The letter and the certification remain on file in case that ever changes.

What you can learn from this

  • A confidentiality clause that never defines what counts as confidential or what happens to data on departure is difficult to enforce, no matter how serious the situation looks later.
  • Revoking access on the day someone gives notice is a practical step, not a legal one, and it often does more to contain a risk than any letter that follows.
  • If your business has ever shared 'confidential' information informally with a client or partner, that history can weaken a later claim that the information was protected.
  • Not every breach can be proven or fully resolved. Deciding what outcome is actually achievable, rather than what feels justified, changes the whole approach.
  • Fixing the contract that caused a problem is only half the job. The habits and processes around it need to change too, or the same gap reopens with the next hire.
This case study is entirely fictional. It does not describe any real client, file, or matter handled by Treadstone Law, and it is not a real file with details changed. All names, people, properties, businesses, dollar amounts, dates, and events are invented, and any resemblance to a real person, business, or situation is coincidental. Fictional scenarios like this one illustrate the kinds of legal issues people in Ontario commonly face and how a lawyer can help. They are general information, not legal advice — no two matters unfold the same way, and nothing here predicts the outcome of any real case. Reading a case study does not create a lawyer-client relationship. If you are facing something similar, speak with a lawyer about your specific circumstances.

This is a corporate problem we handle

Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.

ContactStart a File →