{"id":12349,"date":"2026-09-27T14:19:06","date_gmt":"2026-09-27T06:19:06","guid":{"rendered":"https:\/\/fdlaw.com.tw\/?p=12349"},"modified":"2026-09-27T21:27:55","modified_gmt":"2026-09-27T13:27:55","slug":"former-employee-system-access","status":"publish","type":"post","link":"https:\/\/fdlaw.com.tw\/en\/blog\/former-employee-system-access\/","title":{"rendered":"What if I get sued for logging into the company system or downloading data after leaving the company? First, confirm the authorization, the nature of the records and data. Does it involve violations of the Trade Secrets Act or the Criminal Code&#039;s offense of obstructing computer use?"},"content":{"rendered":"<style>\n.fd-system-access{color:#293746;line-height:1.9}\n.fd-system-access *{box-sizing:border-box}\n.fd-system-access p{margin:0 0 18px;font-size:17px;line-height:1.9}\n.fd-system-access h2{margin:42px 0 18px;padding:15px 20px;border-left:5px solid #b3873c;background:linear-gradient(90deg,#edf3f8 0%,#f8fafc 100%);color:#173a5e;font-size:25px;line-height:1.45;font-weight:700;box-shadow:0 1px 0 rgba(23,58,94,.08)}\n.fd-system-access h3{margin:24px 0 10px;padding:0 0 8px 14px;border-left:3px solid #b3873c;border-bottom:1px solid #dbe4ec;color:#173a5e;font-size:19px;line-height:1.5;font-weight:700}\n.fd-system-access .fd-intro{margin:0 0 34px;padding:24px 26px;border:1px solid #d9e3ec;border-top:4px solid #173a5e;border-radius:6px;background:#f8fafc}\n.fd-system-access .fd-intro p:last-child{margin-bottom:0}\n.fd-system-access .fd-faq{margin-top:42px;padding:4px 24px 20px;border:1px solid #d9e3ec;border-radius:7px;background:#fbfcfd}\n.fd-system-access .fd-faq h2{margin:0 -24px 20px}\n.fd-system-access .fd-cta{margin:42px 0 10px;padding:26px 28px;border:1px solid #d8c49e;border-radius:7px;background:#fffaf1;box-shadow:0 8px 24px rgba(23,58,94,.06)}\n.fd-system-access .fd-cta h2{margin:0 0 18px;padding:0 0 12px;border:0;border-bottom:2px solid #b3873c;background:none;box-shadow:none}\n.fd-system-access .fd-cta p:nth-last-child(-n+3){margin-bottom:10px;font-weight:600}\n@media(max-width:720px){.fd-system-access p{font-size:16px}.fd-system-access h2{margin-top:32px;padding:13px 15px;font-size:21px}.fd-system-access h3{font-size:18px}.fd-system-access .fd-intro,.fd-system-access .fd-cta{padding:20px 18px}.fd-system-access .fd-faq{padding:4px 18px 16px}.fd-system-access .fd-faq h2{margin-left:-18px;margin-right:-18px}}\n<\/style>\n<div class=\"fd-system-access\">\n<div class=\"fd-intro\">\n<p>Being able to log in to your former company&#039;s ERP, CRM, Google Workspace, Microsoft 365, Email, cloud storage, or server after leaving the company does not necessarily mean that you still have the legal right to log in.<\/p>\n<p>Conversely, the presence of login records or downloaded files on a company&#039;s system does not necessarily indicate a criminal offense.<\/p>\n<p>These types of cases really need to be analyzed as two separate issues.<\/p>\n<p>The first question is about &quot;system access&quot;: Did the employee still have company authorization after leaving the company? Did the employee actively enter their account and password to log in, or did the original browser session, sync program, or device remain logged in? What data were actually obtained, downloaded, modified, or deleted?<\/p>\n<p>The second question concerns the &quot;data itself&quot;: Are the downloaded customer lists, quotations, technical documents, source code, design drawings, process data, or other files legally considered trade secrets?<\/p>\n<p>Therefore, when a company sues you for &quot;interference with computer use and trade secrets&quot;, it is not appropriate to simply reply with &quot;My account was not suspended, so I can log in&quot;, nor can you conversely assume that the crime of trade secrets must be established just because the company says &quot;this is confidential information&quot;.<\/p>\n<p>The real defense work involves breaking down the departure date, scope of authorization, account status, system logs, download behavior, nature of materials and subsequent use, one by one.<\/p>\n<p>These types of cases also often involve<a href=\"https:\/\/fdlaw.com.tw\/en\/corporate-criminal\/\">Corporate criminal and white-collar crime cases<\/a>Overall risk assessment.<\/p>\n<\/div>\n<h2>1. If the company did not suspend the account, is it necessarily legal to log in after leaving the company?<\/h2>\n<p>uncertain.<\/p>\n<p>Many companies do not immediately deactivate all accounts on the day an employee leaves. Some accounts may be deactivated a few days later. Synchronization speeds may differ between some systems and Google Workspace, Microsoft 365, VPNs, or other SaaS services, which could result in accounts still being accessible after an employee leaves.<\/p>\n<p>However, &quot;being able to log in technically&quot; and &quot;being legally authorized to log in&quot; are two different things.<\/p>\n<p>For example, if the company clearly notifies employees that they should not log in to the system after their departure date, the handover process has been completed, or the account was originally intended for use only during their employment to perform company work, then the fact that IT did not immediately close the account does not necessarily mean that the company agrees to allow the former employee to continue logging in.<\/p>\n<p>Conversely, if a company still requires a former employee to assist with handover, data modification, customer service, case response, or remote technical support after the employee leaves, and the company is aware that the employee is still using the original account, these facts may conflict with the claim of &quot;completely unauthorized intrusion&quot;.<\/p>\n<p>Therefore, the first thing to check is not &quot;whether the account can be used&quot;, but what the two parties actually agreed upon after the departure.<\/p>\n<h2>2. Could logging in with the original account after leaving the company be subject to Article 358 of the Criminal Law?<\/h2>\n<p>Article 358 of the Criminal Law mainly deals with acts of unjustifiably entering other people&#039;s account passwords, cracking computer protection measures, or using system vulnerabilities to invade other people&#039;s computers or related equipment.<\/p>\n<p>The current statutory penalty is imprisonment for up to three years, detention, or a fine of up to NT$300,000, or both.<\/p>\n<p>However, in cases involving former employees, one cannot simply jump to Article 358 based solely on the fact that &quot;there is a Login Log after leaving the company&quot;.<\/p>\n<p>First, you need to confirm the actual login method.<\/p>\n<p>The technical reality may differ between re-entering your former company&#039;s account and password to log in to the company&#039;s ERP, VPN, cloud system, or server after leaving the company, and situations where the browser retains the login status, the app automatically syncs, or the old computer still has a token or session.<\/p>\n<p>Secondly, it is necessary to confirm whether the authorization has been terminated.<\/p>\n<p>The account was indeed originally given to the employee by the company, which is not entirely the same as a typical case of &quot;stealing someone else&#039;s account password&quot;. Therefore, the case still needs further confirmation regarding the effective date of resignation, company information security regulations, resignation documents, account usage rules, and whether there was any handover or other authorization after resignation.<\/p>\n<p>&quot;This account used to belong to me&quot; is not a valid reason for innocence.<\/p>\n<p>However, the fact that &quot;the system can still be accessed after leaving the company&quot; is not necessarily evidence of guilt.<\/p>\n<h2>3. What if the system is already logged in, instead of requiring a new password?<\/h2>\n<p>This is a problem that is easily overlooked in practice.<\/p>\n<p>Many enterprise systems now do not require users to re-enter their account and password for every operation.<\/p>\n<p>Users may already be logged into Google Workspace, Microsoft 365, Slack, Dropbox, VPN, CRM, or ERP on their company laptops, and the system maintains access through cookies, tokens, sessions, or sync programs.<\/p>\n<p>Therefore, if the prosecution or the company claims &quot;login to the system after leaving the company,&quot; the defendant should further confirm how this access actually occurred.<\/p>\n<p>Did you re-enter your account and password?<\/p>\n<p>Did you pass the MFA?<\/p>\n<p>Did you use a VPN?<\/p>\n<p>Which device is it?<\/p>\n<p>Which IP address is it?<\/p>\n<p>Does the system sync automatically?<\/p>\n<p>Is the file already in the local cache or a synchronized folder?<\/p>\n<p>Has the account been re-verified?<\/p>\n<p>These technical details can directly affect the legal evaluation of a case.<\/p>\n<p>You cannot assume that all computers have the same access process just because you take a screenshot of the &quot;login time&quot;.<\/p>\n<h2>IV. Could downloading company materials after leaving a job be a violation of Article 359 of the Criminal Law?<\/h2>\n<p>Besides login behavior, another common offense is Article 359 of the Criminal Code.<\/p>\n<p>This provision states that obtaining, deleting, or altering the electromagnetic records of another person&#039;s computer or related equipment without cause, and causing harm to the public or others as a result, may constitute a crime related to obstructing computer use.<\/p>\n<p>The current statutory penalty is imprisonment for up to five years, detention, or a fine of up to NT$600,000, or both.<\/p>\n<p>Therefore, if a company claims that a former employee logged into the server after leaving the company and downloaded a large amount of customer data, technical documents, or company files, the case may not only involve the &quot;login&quot; issue under Article 358, but may also further involve the &quot;obtaining electromagnetic records&quot; issue under Article 359.<\/p>\n<p>However, Article 359 is not necessarily true just because you see the word &quot;download&quot;.<\/p>\n<p>It is still necessary to determine whether the acquisition was &quot;unjustified&quot; and whether it has caused the legally required harm.<\/p>\n<p>For example, the data was already in the employee&#039;s company laptop&#039;s sync folder, and the actual structure is not exactly the same when the employee logs into the company server after leaving the company to search for and download a batch of files that they never owned.<\/p>\n<h2>5. Deleting or modifying company files typically carries a higher risk of criminal charges.<\/h2>\n<p>If the dispute involves more than just downloading, but also includes actions such as deleting company files, modifying customer information, changing system settings, deleting emails, overwriting code, or altering account permissions after leaving the company, the criminal risk increases further.<\/p>\n<p>Article 359 of the Criminal Law itself includes situations where someone &quot;deletes&quot; or &quot;alters&quot; another person&#039;s electromagnetic records without cause, resulting in harm.<\/p>\n<p>In addition, if a company&#039;s computer or related equipment is interfered with by using programs or other electromagnetic means, causing the system to be affected, it may further involve Article 360 of the Criminal Code.<\/p>\n<p>Therefore, the defendant cannot simplify all situations to &quot;I was just downloading data&quot;.<\/p>\n<p>Whether it was just reading and copying, or whether there was also deletion, modification, permission change, or system interference, must be confirmed by checking the logs, file version records, and digital forensics data.<\/p>\n<h2>6. Does the fact that the company system&#039;s log shows my account logged in necessarily prove that it is me?<\/h2>\n<p>uncertain.<\/p>\n<p>Login records are important, but the account and the actual operator are not necessarily the same thing.<\/p>\n<p>Enterprises sometimes share accounts, passwords, remote desktops, jump servers, system service accounts, APIs, automation programs, or device synchronization.<\/p>\n<p>Even for personal accounts, it is necessary to further verify the login source IP, device identification information, login method, MFA record, browser, VPN, device location, and the person who actually possessed the device at the time.<\/p>\n<p>For example, if a company requests a login record from 2 AM, the real response needed is:<\/p>\n<p>Which device is logged in?<\/p>\n<p>Where is the IP address?<\/p>\n<p>Is there an MFA verification?<\/p>\n<p>What did I do after logging in?<\/p>\n<p>Is it possible that this account is stored on other devices?<\/p>\n<p>Is it just an automatic connection for the synchronization service?<\/p>\n<p>Only by linking the login process with subsequent actions can we better determine who actually performed the operation.<\/p>\n<h2>7. Distinguish between different types of &quot;downloads&quot;: manual downloads, automatic syncs, and files already installed on your computer.<\/h2>\n<p>In digital evidence cases, &quot;having files on a personal computer&quot; does not necessarily mean that the files were illegally downloaded after leaving the company.<\/p>\n<p>For example, if an employee previously used the company&#039;s OneDrive, Google Drive, or Dropbox, their data may have already been synced to the company laptop while they were still employed; or their files may have been stored on their local machine before they left the company due to normal work.<\/p>\n<p>It&#039;s also possible that the synchronization software continues to operate automatically after you leave the company, updating the data to the device you were already logged into.<\/p>\n<p>These situations differ significantly from deliberately accessing a folder one doesn&#039;t normally have access to after leaving a job, selecting a large number of files, and downloading them to a personal device, in terms of evidentiary evaluation.<\/p>\n<p>Therefore, the case should at least be clarified as follows:<\/p>\n<p>The time when the file first appeared on the device.<\/p>\n<p>The actual download time.<\/p>\n<p>The creation time, modification time, and access time of the archive.<\/p>\n<p>Synchronization software records.<\/p>\n<p>System download history.<\/p>\n<p>Transfer records via USB, external hard drive, or private cloud.<\/p>\n<p>Only by confirming &quot;when, how, and from where&quot; the data was collected can responsibility be determined more accurately.<\/p>\n<h2>8. Does downloading customer lists or technical information after leaving a job necessarily constitute a crime of exposing trade secrets?<\/h2>\n<p>uncertain.<\/p>\n<p>The trade secret law and the crime of obstructing computer use deal with different issues.<\/p>\n<p>Even if the method of logging in or obtaining information is disputed, it does not mean that every piece of information obtained is necessarily a &quot;trade secret&quot;.<\/p>\n<p>According to Article 2 of the Trade Secrets Act, the information claimed by a company must meet three requirements: confidentiality, actual or potential economic value due to its confidentiality, and reasonable confidentiality measures taken by the company.<\/p>\n<p>Therefore, customer lists, quotations, cost data, drawings, code, technical parameters, SOPs, or design documents cannot be considered trade secrets simply because they exist on the company&#039;s server.<\/p>\n<p>The company still needs to provide specific details:<\/p>\n<p>Which document is secret?<\/p>\n<p>What exactly is the secret?<\/p>\n<p>Why don&#039;t most people in the industry know this?<\/p>\n<p>Why does it have economic value?<\/p>\n<p>How does the company usually restrict contact?<\/p>\n<p>Who can download it?<\/p>\n<p>Are there access restrictions, passwords, confidentiality tags, NDAs, or download limitations?<\/p>\n<p>If any employee of the company can freely access, send, or copy the information, or if the information itself has already been made public, the trade secret requirement may become a major point of contention.<\/p>\n<h2>9. However, having the right to view documents does not mean that one can take them all with them when leaving the company.<\/h2>\n<p>Another common misconception among defendants is: &quot;These materials were originally part of my work, and I used to be able to look at them every day, so there&#039;s no problem with me taking them away.&quot;<\/p>\n<p>This cannot be generalized.<\/p>\n<p>Article 13-1 of the Trade Secrets Act not only punishes cases of obtaining trade secrets by theft, misappropriation, fraud, or other improper means.<\/p>\n<p>If a person originally knew or possessed trade secrets legally through a work relationship, but later reproduced, used, or disclosed them without authorization or beyond the scope of authorization, and had the intent to gain illegal benefits or cause harm as required by law, they may also be subject to criminal liability.<\/p>\n<p>So the real question in this case is:<\/p>\n<p>What is the purpose of the authorization granted during the term of office?<\/p>\n<p>Does being allowed to read for work purposes equate to being able to copy it to a personal computer?<\/p>\n<p>If I can download files to my company laptop, does that mean I can upload them to my own Google Drive?<\/p>\n<p>Does being able to retain work results mean that they can be handed over to a new company for use after leaving the company?<\/p>\n<p>The scope of permissions is the key, not simply &quot;what I could see before&quot;.<\/p>\n<h2>10. Can the acts of obstructing computer use and the infringement of trade secrets be established simultaneously?<\/h2>\n<p>possible.<\/p>\n<p>The two types of laws protect different legal interests and have different focuses in their judgments.<\/p>\n<p>Interference with computer use mainly deals with acts of unauthorized intrusion, acquisition, deletion, alteration of electromagnetic records, or interference with computer systems.<\/p>\n<p>The trade secret law places greater emphasis on whether the information obtained or used itself constitutes a trade secret, and whether the actor has engaged in unauthorized, unauthorized reproduction, use, or disclosure.<\/p>\n<p>Therefore, several different results may occur.<\/p>\n<p>The system login itself had a problem, but the downloaded data was not a trade secret at all.<\/p>\n<p>It&#039;s also possible that the login itself was originally authorized, but copying trade secrets to a personal device and intending to use them after leaving the company could create trade secret law issues.<\/p>\n<p>Or both are controversial.<\/p>\n<p>Just because one charge is unfounded does not automatically mean that the other is also unfounded.<\/p>\n<h2>11. Does the company&#039;s failure to suspend the account help the defendant?<\/h2>\n<p>It could be important evidence, but it doesn&#039;t automatically grant acquittal.<\/p>\n<p>The company&#039;s failure to suspend trading immediately likely involves at least several issues that require further investigation.<\/p>\n<p>First, when exactly did the company consider the departure date to be officially effective?<\/p>\n<p>Second, whether the employee is still required to handle work or hand over responsibilities after leaving the company.<\/p>\n<p>Third, was the company aware that the account was still open?<\/p>\n<p>Fourth, the company<a href=\"https:\/\/fdlaw.com.tw\/en\/trade-secret-information-security\/\">Information security policy<\/a>Is there a clear rule that funds cannot be deposited or withdrawn after leaving the company?<\/p>\n<p>Fifth, does the person concerned have reasonable grounds to believe that they are still allowed to use the system?<\/p>\n<p>If a company tacitly allows former employees to assist with cases after leaving the company, or even actively asks them to log in again to download certain documents, these facts are certainly different from completely secret, unauthorized logins.<\/p>\n<p>However, simply stating &quot;IT forgot to close the account&quot; is usually not equivalent to company authorization.<\/p>\n<h2>12. After being sued, the most important thing is to establish a complete &quot;digital timeline&quot;.<\/h2>\n<p>The worst thing you can do in these types of cases is to answer based solely on memory.<\/p>\n<p>A more comprehensive defense should begin with creating a timeline that integrates the four lines of departure, personnel, systems, and data.<\/p>\n<p>The first item is the personnel timeline.<\/p>\n<p>What is the last working day?<\/p>\n<p>When should I submit my resignation?<\/p>\n<p>When will the handover take place?<\/p>\n<p>What is the effective date of resignation?<\/p>\n<p>Does the company require assistance after leaving the company?<\/p>\n<p>The second line is the account permission line.<\/p>\n<p>When are each ERP, CRM, Email, VPN, Google Workspace, Microsoft 365, or Server account activated and deactivated?<\/p>\n<p>Is there an MFA?<\/p>\n<p>Has any company notified us to stop using it?<\/p>\n<p>The third line is the system operation line.<\/p>\n<p>On which day, from which IP address, and from which device did you log in?<\/p>\n<p>What materials did you view after logging in?<\/p>\n<p>How much will it cost to download?<\/p>\n<p>Has anything been deleted or modified?<\/p>\n<p>The fourth line is the data usage line.<\/p>\n<p>Where did the files end up?<\/p>\n<p>Did you send it to anyone?<\/p>\n<p>Did you upload it to a private cloud?<\/p>\n<p>Has it been handed over to a new company?<\/p>\n<p>Has it actually been used?<\/p>\n<p>If the four lines are not placed on the same graph, it is easy to misinterpret a single Login Log entry.<\/p>\n<h2>Thirteen, what are the most important pieces of digital evidence in this type of case?<\/h2>\n<p>The most important thing is usually not a single screenshot, but whether records from different systems can be mutually verified.<\/p>\n<p>Common data includes login logs, IP addresses, VPN records, MFA verification records, device identification information, Google Workspace or Microsoft 365 Audit Logs, ERP\/CRM access records, server logs, file version records, download records, USB usage records, private email forwarding, cloud synchronization records, and device identification results.<\/p>\n<p>The defendant should also pay attention to objective information that is favorable to them.<\/p>\n<p>For example, the company continues to send work instructions.<\/p>\n<p>Even after leaving the company, the supervisor still required the employee to log into the system for handover.<\/p>\n<p>The download occurred before I left the company.<\/p>\n<p>The data was already on this machine.<\/p>\n<p>The file has not been opened or used.<\/p>\n<p>The new company&#039;s documents come from independent sources.<\/p>\n<p>These are all more valuable evidence than simply saying &quot;I had no malicious intent&quot; afterward.<\/p>\n<h2>14. How to attack and defend against IP addresses, accounts, and file records?<\/h2>\n<p>Digital evidence cannot be judged solely by its name.<\/p>\n<p>For example, if a login record shows that an account accessed the network from a certain IP, it is still necessary to ask whether that IP is a fixed IP, a corporate VPN, NAT, a mobile network, or a shared network.<\/p>\n<p>A record showing a creation date does not necessarily equal the actual acquisition date.<\/p>\n<p>Archive metadata may change due to copying, synchronization, backup, or system transfer.<\/p>\n<p>Similarly, when a file exists on a computer, the steps of &quot;who put it in&quot;, &quot;when it was put in&quot;, &quot;whether it is opened&quot;, and &quot;whether it has been sent out&quot; cannot be skipped.<\/p>\n<p>If a case heavily relies on digital evidence, it may be necessary to re-examine the original records through digital forensics, rather than simply accepting the other party&#039;s edited Excel spreadsheets or screenshots.<\/p>\n<h2>fifteen,<a href=\"https:\/\/fdlaw.com.tw\/en\/blog\/criminal-investigation\/\">Received notification from the police, investigation bureau or district prosecutor&#039;s office<\/a>After that, what things should you not do first?<\/h2>\n<p>First, do not delete the relevant files on your personal computer immediately out of fear.<\/p>\n<p>Deletion may cause information that could prove the time of acquisition, source, or unused status to disappear, and may also create new disputes over evidence.<\/p>\n<p>Second, do not reinstall your computer, clear your browser, format your phone, or reset your cloud account.<\/p>\n<p>Third, don&#039;t rush to contact former colleagues and demand that everyone give the same answer.<\/p>\n<p>Fourth, do not create fictitious handover documents or messages after the fact to strengthen your own account.<\/p>\n<p>Fifth, do not ignore system evidence that interferes with computer use just because the other party is suing for &quot;trade secrets,&quot; and do not only deal with login records while ignoring whether the data is actually a trade secret.<\/p>\n<p>A safer approach is to first preserve the original state of the equipment and data, and then create a timeline based on objective records.<\/p>\n<h2>XVI. Articles 358 to 360 of the Criminal Law are all based on complaint; this is very important.<\/h2>\n<p>Article 363 of the Criminal Law clearly stipulates that crimes under Articles 358 to 360 must be brought to justice upon complaint.<\/p>\n<p>This means that, in addition to the substantive requirements, the procedure must also confirm whether the lawful complaint was filed within the time limit.<\/p>\n<p>According to Article 237 of the Criminal Procedure Law, a crime is prosecuted upon complaint, and in principle, the complainant should file a complaint within six months from the time the person who is willing to file the complaint becomes aware of the offender.<\/p>\n<p>Therefore, in addition to analyzing &quot;whether there was login&quot; and &quot;whether there was download&quot;, the defendant should also confirm when the company knew about the incident and the perpetrator, when it formally filed the lawsuit, and whether the party filing the lawsuit is qualified.<\/p>\n<p>Offenses under Article 13-1 of the Trade Secrets Act are also subject to prosecution upon complaint, according to Article 13-3 of the same Act.<\/p>\n<p>Therefore, the period during which the complaint is filed is not a trivial matter, but one of the important procedural issues in this type of case.<\/p>\n<h2>17. The risk is even higher if the data is alleged to be taken to China or used overseas.<\/h2>\n<p>If the trade secrets in a case are alleged to be used in a foreign country, mainland China, Hong Kong, or Macau, the Trade Secrets Law has more severe criminal provisions.<\/p>\n<p>Therefore, if a former employee joins an overseas competitor after leaving the company, uploads data to an overseas server, sends it to an overseas team, or is accused of intending to use it overseas, the risks involved in such cases differ from those of typical domestic use.<\/p>\n<p>But we still can&#039;t skip the most basic questions.<\/p>\n<p>Is the information claimed by the company a trade secret?<\/p>\n<p>What did the defendant actually obtain?<\/p>\n<p>Has it been reproduced or used?<\/p>\n<p>What evidence is used to determine the intent to use something overseas?<\/p>\n<p>Just because a new company is located overseas does not automatically mean that all the data was obtained for overseas use.<\/p>\n<h2>18. The Six Most Important Defense Issues for the Defendant<\/h2>\n<p>First, does the employee still have authorization after leaving the company?<\/p>\n<p>Second, how exactly does the &quot;login&quot; mentioned by the prosecution technically occur?<\/p>\n<p>Third, who actually operates the accounts and devices?<\/p>\n<p>Fourth, was the data legally obtained before leaving the company, or was it downloaded again after leaving?<\/p>\n<p>Fifth, does the allegedly submitted information truly meet the requirements?<a href=\"https:\/\/fdlaw.com.tw\/en\/blog\/trade-secret\/\">The three elements of trade secrets<\/a>?<\/p>\n<p>Sixth, after the data was obtained, was it actually reproduced, used, leaked, or caused damage?<\/p>\n<p>If these six questions are not clarified first, simply saying &quot;the company forgot to close the account&quot; or &quot;I did all the data&quot; is usually insufficient to handle the full criminal risks.<\/p>\n<h2>19. Cases of obstructing computer use and<a href=\"https:\/\/fdlaw.com.tw\/en\/blog\/former-employee-trade-secret-defense\/\">Cases involving defendants who evade general trade secrets<\/a>What&#039;s the difference?<\/h2>\n<p>If the core of the case is &quot;whether this technical information is a trade secret&quot;, &quot;whether the company has reasonable confidentiality measures&quot;, and &quot;whether the former employee has exceeded the authorization to use it&quot;, the focus is more on trade secret law.<\/p>\n<p>If the core of the case is &quot;why did you still log in after leaving the company&quot;, &quot;whether the account still has permissions&quot;, &quot;whether you used the old password&quot;, or &quot;whether you downloaded, deleted or modified system data&quot;, then evidence of information system interference with computer use will be more important.<\/p>\n<p>Many cases involve both factors simultaneously.<\/p>\n<p>Therefore, this type of case cannot be handled solely from the perspective of trade secrets, nor can it be treated as a typical hacking case.<\/p>\n<p>Enterprises already have existing accounts, permissions, work data, and handover relationships, which are completely different from external intrusion by strangers.<\/p>\n<div class=\"fd-faq\">\n<h2>Frequently Asked Questions<\/h2>\n<h3>If my account wasn&#039;t closed after I left the company, will I be sued if I log in even once?<\/h3>\n<p>There is a possibility of being prosecuted, but whether a crime has been committed cannot be determined solely by whether the account is still usable. It is also necessary to determine whether there was authorization after leaving the company, the actual method of login, the purpose of login, and subsequent actions.<\/p>\n<h3>I&#039;m just logging in to take a look; I didn&#039;t download any materials. Will there still be a problem?<\/h3>\n<p>Article 358 of the Criminal Code may still need to be examined, but whether it is established depends on the login method, authorization status, and specific facts. If no electronic records were obtained, deleted, or altered, the analysis of Article 359 will be different.<\/p>\n<h3>I didn&#039;t re-enter my password, but the browser kept me logged in. Does that count as an intrusion?<\/h3>\n<p>It is not possible to judge based solely on general semantics. Article 358 of the Criminal Law has specific behavioral requirements, and it is necessary to confirm the token, session, automatic login, synchronization mechanism, and actual technical process. One cannot draw conclusions based solely on the system displaying &quot;login&quot;.<\/p>\n<h3>Does having a company&#039;s client list on my computer automatically make it a trade secret?<\/h3>\n<p>Not necessarily. It is still necessary to confirm the confidentiality, economic value, and reasonable security measures, as well as when and how the files were accessed by the device.<\/p>\n<h3>I already had permission to download, so is it illegal to back up my work data before leaving the company?<\/h3>\n<p>Not necessarily, but there are criminal risks. It depends on the purpose of the download, the scope of authorization, the nature of the data, whether it was moved to a personal device, and whether it was used or leaked after leaving the company.<\/p>\n<h3>The company only has my account login records and did not see me personally making any moves. Can this be used to convict me?<\/h3>\n<p>Account records are important evidence, but they usually need to be cross-referenced with IP address, device, MFA, operation logs, file flow, and other objective data to determine the actual operator.<\/p>\n<h3>Is obstructing computer use a criminal offense subject to complaint?<\/h3>\n<p>Articles 358 to 360 of the Criminal Law, and Article 363, all pertain to cases initiated by complaint. In principle, the six-month statute of limitations for filing a complaint as stipulated in the Criminal Procedure Law should also be noted.<\/p>\n<h3>I have received<a href=\"https:\/\/fdlaw.com.tw\/en\/blog\/police-search\/\">Search Ticket<\/a>If you have received a summons from the District Attorney&#039;s Office, what is the first step?<\/h3>\n<p>First, save the equipment and original data; do not delete, reinstall, or modify the records. Next, organize the departure date, handover details, account permissions, system logins, downloaded data, and subsequent uses. Then, prepare for the interrogation and written response.<\/p>\n<\/div>\n<div class=\"fd-cta\">\n<h2>Have you been sued for logging into the company system or downloading data after leaving the company?<\/h2>\n<p>If you have received a notice from the police, investigation bureau, or district prosecutor&#039;s office alleging that you logged into the company&#039;s ERP, CRM, Email, Google Workspace, Microsoft 365, VPN, or server after leaving the company, or downloaded or copied customer data, technical documents, quotations, code, or other company files, it is recommended that you save your current devices and digital data to their original state.<\/p>\n<p>Fidelity Law Firm can comprehensively assess the criminal risks of obstructing computer use and protecting trade secrets by examining departure and handover records, account authorizations, system logs, IP addresses, devices, download records, file metadata, trade secret requirements, and subsequent usage. Depending on the stage of the case, the firm can prepare for police inquiries, investigation bureau questioning, district prosecutor&#039;s office investigations, and subsequent criminal defense.<\/p>\n<p>Tel:<a href=\"tel: 886277093611\">02-7709-3611<\/a><\/p>\n<p>LINE:<a href=\"https:\/\/line.me\/R\/ti\/p\/@fdlaw\" target=\"_blank\" rel=\"noopener\">@fdlaw<\/a><\/p>\n<p>Email:<a href=\"mailto:info@fdlaw.com.tw\">info@fdlaw.com.tw<\/a><\/p>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>\u96e2\u8077\u5f8c\u9084\u80fd\u767b\u5165\u539f\u516c\u53f8\u7684 ERP\u3001CRM\u3001Google Workspace\u3001Microsoft 365\u3001Emai [&hellip;]<\/p>","protected":false},"author":1,"featured_media":12353,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"qubely_global_settings":"","qubely_interactions":"","footnotes":""},"categories":[77,40],"tags":[41],"class_list":["post-12349","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-taipei-criminal-lawyer","category-trade-secret-law","tag-41"],"blocksy_meta":[],"qubely_featured_image_url":{"full":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-scaled.jpeg",2560,1396,false],"landscape":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-1200x750.jpeg",1200,750,true],"portraits":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-540x320.jpeg",540,320,true],"thumbnail":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-150x150.jpeg",150,150,true],"medium":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-300x164.jpeg",300,164,true],"medium_large":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-768x419.jpeg",768,419,true],"large":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-1024x559.jpeg",1024,559,true],"1536x1536":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-1536x838.jpeg",1536,838,true],"2048x2048":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-2048x1117.jpeg",2048,1117,true],"trp-custom-language-flag":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-18x10.jpeg",18,10,true],"qubely_landscape":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-1200x750.jpeg",1200,750,true],"qubely_portrait":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-540x320.jpeg",540,320,true],"qubely_thumbnail":["https:\/\/fdlaw.com.tw\/wp-content\/uploads\/2026\/09\/Gemini_Generated_Image_5b1i995b1i995b1i-140x100.jpeg",140,100,true]},"qubely_author":{"display_name":"\u53f0\u5317\u5f8b\u5e2b\u63a8\u85a6","author_link":"https:\/\/fdlaw.com.tw\/en\/author\/admin\/"},"qubely_comment":0,"qubely_category":"<a href=\"https:\/\/fdlaw.com.tw\/en\/blog\/category\/taipei-criminal-lawyer\/\" rel=\"category tag\">\u5211\u6cd5\u53ca\u5211\u4e8b\u8a34\u8a1f<\/a> <a href=\"https:\/\/fdlaw.com.tw\/en\/blog\/category\/trade-secret-law\/\" rel=\"category tag\">\u71df\u696d\u79d8\u5bc6\u6cd5<\/a>","qubely_excerpt":"\u96e2\u8077\u5f8c\u9084\u80fd\u767b\u5165\u539f\u516c\u53f8\u7684 ERP\u3001CRM\u3001Google Workspace\u3001Microsoft 365\u3001Emai&hellip;","_links":{"self":[{"href":"https:\/\/fdlaw.com.tw\/en\/wp-json\/wp\/v2\/posts\/12349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fdlaw.com.tw\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fdlaw.com.tw\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fdlaw.com.tw\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fdlaw.com.tw\/en\/wp-json\/wp\/v2\/comments?post=12349"}],"version-history":[{"count":4,"href":"https:\/\/fdlaw.com.tw\/en\/wp-json\/wp\/v2\/posts\/12349\/revisions"}],"predecessor-version":[{"id":12357,"href":"https:\/\/fdlaw.com.tw\/en\/wp-json\/wp\/v2\/posts\/12349\/revisions\/12357"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fdlaw.com.tw\/en\/wp-json\/wp\/v2\/media\/12353"}],"wp:attachment":[{"href":"https:\/\/fdlaw.com.tw\/en\/wp-json\/wp\/v2\/media?parent=12349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fdlaw.com.tw\/en\/wp-json\/wp\/v2\/categories?post=12349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fdlaw.com.tw\/en\/wp-json\/wp\/v2\/tags?post=12349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}