When a former employee takes client data, a Jamaican business may face several problems at once: loss of confidential information, possible misuse of personal data and an urgent dispute about what the employee can keep or use. A client list sent to a personal email account is not automatically proof of criminal conduct, but it is a reason to act promptly.
The immediate priorities are to stop further access, preserve evidence and assess whether urgent legal protection or regulatory reporting is required. Avoid demanding immediate deletion before the evidence has been secured. That can make it harder to establish what was taken, where it went and whether anyone else received it.
What to do first when a former employee takes client data
Restrict access without destroying the record
Ask your IT team or service provider to disable the former employee’s access to company email, cloud storage, client databases and remote connections. Revoke active sessions and review shared passwords, recovery accounts and forwarding rules. Removing a user from the staff directory does not necessarily terminate every route into your systems.
Where possible, preserve relevant logs and account information before making changes that could overwrite them. If unauthorised access is continuing, containment should not wait for a perfect forensic copy. Record what was changed, by whom and at what time.
Do not remotely wipe a personal device simply because it contains company information. Device ownership, contractual permissions and the privacy of unrelated information all need consideration.
Preserve the evidence behind the suspicion
Secure the records that show what happened, rather than relying on a manager’s recollection or a screenshot alone. Relevant evidence may include:
Email exports showing attachments, recipients and message headers.
Client database logs showing downloads, exports or unusual searches.
Cloud-sharing records, forwarding rules and access history.
Device records, exit correspondence and applicable employment agreements.
Client messages indicating that someone used information obtained through the business.
Retain originals where possible and document who collected or handled each item. A digital forensic specialist can help preserve metadata and distinguish an ordinary work activity from a suspicious transfer. Opening files, resetting devices or running improvised recovery tools can alter the evidence.
Put one person in charge of the response
Assign a response lead to coordinate management, IT, HR, your data protection officer where applicable and legal counsel. Keep a factual timeline separating confirmed events from assumptions.
Establish the departure date, when the suspected transfer occurred and when the organisation first became aware of it. These dates may matter both to an urgent court application and to data protection reporting. Run the recovery and regulatory workstreams in parallel, rather than waiting for one to finish before starting the other.
Identify what was taken and what rights are involved
“Client data” can describe very different material. A publicly available company telephone number is not the same as a confidential pricing schedule, identity document or privileged legal file.
The nature of the information determines which duties and remedies may apply.
Material involved | Potential legal issue | Question to resolve |
Names, contact details or identification documents relating to individuals | Personal data protection | Which individuals are affected, and who received their information? |
Non-public client lists, pricing or account histories | Confidentiality and contractual obligations | Was the material confidential, and what restrictions governed its use? |
Documents, reports or other original work | Intellectual property and contractual rights | Who owns the work, and what permissions existed? |
Legal advice or litigation-related communications | Confidentiality and possible legal professional privilege | Does the material contain privileged communications requiring special protection? |
These categories can overlap. A customer database may contain both commercially sensitive information and personal data.
A business does not own its clients or automatically control every future interaction with them. Distinguish copied records from the former employee’s general experience, public information and relationships developed during employment. The evidence must support the particular restriction you seek to enforce.
Check Jamaica’s data protection reporting duties immediately
If the material identifies individuals, assess the incident under Jamaica’s Data Protection Act, 2020. A corporate client’s contact-person details may be personal data even though the client itself is a company.
An unauthorised disclosure can raise data protection issues without a hacker being involved. Equally, not every disputed transfer establishes a reportable contravention: permissions, purpose and the facts of the incident must be examined.
Check the Act’s 72-hour reporting requirement immediately. Counsel should confirm the applicable trigger, when the clock began, what must be reported to the Office of the Information Commissioner and whether affected individuals must also be notified. Do not assume that a foreign jurisdiction’s reporting exceptions apply in Jamaica, or wait for a completed investigation before assessing your obligations.
Record what you know, what remains uncertain and the reasons for your notification decisions. Client contracts may also contain separate incident-notification duties. For the wider regulatory response, the firm’s guidance on data breach response steps for Jamaican companies addresses the broader incident-management process.
Investigate lawfully, especially on personal devices
The need to recover business information does not give an employer unrestricted access to a former employee’s private accounts or devices.
Review employment terms, acceptable-use policies, monitoring notices and device agreements before collecting information. An investigation should have a defined scope: the relevant files, accounts, recipients and time period. Avoid collecting unrelated personal messages simply because they are technically accessible.
The distinction between company-owned and personally owned equipment matters, but ownership alone does not settle every privacy question. The firm’s article on electronic privacy risks on workplace devices explains why access and monitoring need careful boundaries.
If the employee refuses access to a personal device, seek advice about consent, a controlled forensic review or appropriate court relief. Do not access a private account using a saved password or impersonate the former employee.
Where litigation is reasonably anticipated, counsel should also consider how to structure the investigation and protect legal professional privilege. Copying a lawyer into an ordinary operational email does not automatically make it privileged.
Send a focused preservation and recovery demand
Once the immediate facts are sufficiently clear, counsel can prepare a written demand identifying the information and the legal basis for requiring its return or restricting its use. A precise letter is more useful than a broad accusation that the employee has “stolen everything”.
Depending on the circumstances, the demand may seek:
An immediate stop to further access, use or disclosure of identified information.
Preservation of relevant files, messages, logs and devices pending a lawful review.
Identification of copies, storage locations and people who received the material.
Return of company property and information through an agreed process.
Written undertakings and verified deletion once evidence-preservation duties have been addressed.
Return, preservation and deletion are separate steps. An employee’s statement that they have deleted the files does not establish whether copies remain in another account, on a storage device or with a third party. Conversely, demanding blanket deletion can destroy records needed to resolve the dispute.
Any undertaking should clearly define the information covered, the conduct prohibited and the verification process. Its scope should not unnecessarily prevent lawful work or ordinary competition.
Do not use unpaid wages, contractual payments or unfounded threats of arrest as informal leverage. Any deduction or withholding requires its own lawful basis, separate from the data dispute.
Consider an urgent injunction if misuse may continue
A demand letter may not be enough if the former employee is actively using confidential information, sharing it with a competitor or refusing to preserve evidence. Legal advice should address whether an interim injunction or another preservation order is justified.
Explain why waiting would cause harm
The court will need evidence supporting the rights claimed and the urgency of the application. Counsel will consider the applicable legal tests, including whether damages would adequately address the harm and the balance of convenience.
Useful evidence may include a verified download, a message attaching confidential records or client communications suggesting that non-public information is being used. A general fear that an employee might compete is a weaker basis than documented misuse.
Act promptly once credible evidence emerges. Delay can undermine an assertion that immediate protection is necessary. An application made without notice carries additional duties, including full and frank disclosure of material facts. The court may also require an undertaking relating to losses caused by an injunction later found to have been unjustified.
Assess contractual restrictions separately
Confidentiality obligations, non-solicitation clauses and non-compete provisions do not all do the same job. Their enforceability depends on their wording and the applicable law. Do not assume that a signed clause automatically prevents a former employee from working for a competitor.
Where another business has received the information, counsel can assess its knowledge, conduct and any basis for proceedings against it. Overseas recipients or storage locations can introduce jurisdiction and enforcement issues.
Communicate with clients without overstating the evidence
Client communication should distinguish confirmed facts from concerns still under investigation. Do not describe information as “sold”, “stolen” or “published” unless the evidence supports that statement.
Where notification is required or appropriate, explain what information is involved, what containment steps have been taken and what the recipient should do. If sensitive records create a risk of impersonation or payment fraud, practical warnings may be necessary. Avoid assurances that the information is secure again unless you can substantiate them.
Ask clients to preserve relevant messages from the former employee, including attachments and dates. They should not be encouraged to confront the individual or obtain information through deception.
Keep internal communications equally restrained. Staff need instructions on access, preservation and handling enquiries, not a company-wide account of unproven allegations. A single authorised spokesperson can reduce inconsistent statements and unnecessary disclosure.
Fix the offboarding weakness after containment
An incident often reveals a gap between written policy and the way people actually leave the business. Review whether access was revoked on time, client responsibilities were reassigned and company records were separated from personal accounts.
Reduce future exposure through role-based access, appropriate export controls, clear rules for personal devices and documented exit procedures. Monitoring should remain proportionate and transparent; collecting more employee information is not automatically a better safeguard.
Employment agreements should explain confidentiality obligations and the handling of business records at departure. Operational arrangements matter too: a client database should not depend on one employee’s personal account.
The firm’s guidance on what businesses should do when a key employee resigns covers the broader transition issues. After this incident, translate the findings into specific changes with named owners and completion dates.
Frequently asked questions
Is taking a client list automatically a criminal offence? No. The circumstances may raise contractual, confidentiality, data protection or criminal issues, but the label alone does not establish an offence. Relevant factors include the nature of the information, how it was obtained, the employee’s authority and what happened afterwards. Seek advice before making criminal allegations.
Can a former employee contact our clients? Sometimes. A business does not own its clients. The position depends on any enforceable restrictions, confidentiality duties and whether copied information is being misused. Contact based on public information may require a different analysis from solicitation using a confidential database.
Should we demand immediate deletion of every copy? Not before addressing evidence preservation. A controlled process may require preservation, identification of recipients, return and then verified deletion. Blanket deletion can obscure the extent of the transfer and destroy relevant evidence.
What if the employee says the download was accidental? Preserve that explanation and compare it with the records. An accidental transfer may still require containment and a data protection assessment, but it should not be treated as deliberate misconduct without supporting evidence.
Get advice before the evidence or recovery options change
If you suspect a former employee has removed client information, obtain advice while IT preserves the records and restricts further access. Prepare the employment agreement, relevant policies, incident timeline and available transfer evidence for that discussion.
Henlin Gibson Henlin provides legal services in data privacy, compliance and risk, commercial litigation and intellectual property. Legal advice can help align the recovery demand, reporting assessment and any urgent court application with the facts of the incident.
This article provides general information about Jamaican law, not legal advice on a particular matter.
