Key takeaway
Removing names can leave the secret process intact. Review what the package reveals and whose permission covers that disclosure.
Start with the process the records reveal
A repair archive can reveal more than who bought a service. Its sequence of failed settings, successful corrections and acceptance tolerances may expose a production method. Deleting a customer name does not change what a technically informed recipient can learn from those details.
As reviewed on 7 October 2026, the US federal definition in 18 U.S.C. §1839 includes secrecy measures and independent economic value from secrecy. Its misappropriation provisions include specified disclosure or use connected to duties of secrecy. WIPO also explains that a confidential combination of public elements may qualify. These are starting points for review, not a finding that this archive is a trade secret.
This agenda addresses US federal trade-secret concerns and practical agreement triage. State law, contracts, sector rules and other countries may change the analysis. No private agreement has been examined here. The next decision is whether a particular disclosure is within the business’s authority, rather than whether the records look anonymous.
Worked example: a restricted-process matrix
The following hypothetical archive belongs to an equipment-service company. The company keeps job records in its own system, but some customers supplied process settings and one vendor supplied a troubleshooting recipe under a limited-use arrangement. Possession is established in the illustration; authority to grant a new external use is not.
The completed matrix distinguishes internally developed material from material learned through another relationship. Each decision concerns an external AI-evaluation proposal. No records or customer processes in this example are real.
| Material | How the company obtained it | Completed disclosure decision |
|---|---|---|
| Generic inspection checklist | Company-authored ordinary service procedure | Candidate for further review; check attachments and actual agreements |
| Customer coating settings and test failures | Customer supplied for repair under confidential project terms | Exclude from proposed package; refer agreement/use question to counsel |
| Vendor sequence for recalibrating a machine | Vendor supplied for servicing use only in this illustration | Hold pending confirmation of permitted onward use |
| Technician summary of successful corrections | Company employee summarized the restricted customer process | Exclude with underlying restricted material; authorship does not remove the embedded know-how |
| Ordinary equipment fault count | Derived count proposed without process settings | Review linkage and inference risk before treating it as a separate candidate |
Read the restriction beside the proposed use
A reviewer should place the actual agreement next to the exact fields, attachments and intended recipient activity. A clause allowing servicing can be relevant to the company’s original access without answering whether it may provide training examples externally. Likewise, a nondisclosure agreement with a prospective recipient is not permission from the party whose process appears in the archive.
For the hypothetical customer settings, the review file should contain the project agreement, confidentiality provisions, any downstream restrictions, material provenance and the proposed disclosure description. Mark which documents were actually found and which remain missing. The operational owner can explain the process; counsel must assess the legal effect of the documents.
Do not assume a renamed customer or rewritten narrative solves the issue. In this illustration, the technician’s summary still describes the successful process. Rewriting changes the expression, but the decision remains blocked because the same restricted knowledge is exposed.
Test whether narrowing removes the dependency
The illustrative owner proposes a smaller package containing only fault categories and broad service outcomes. Before sending it, a technically knowledgeable reviewer asks whether rare combinations identify a process recipe and whether linked fields restore excluded tolerances. Keep that examination in the internal review record.
The completed decision is to hold the restricted process material, prepare only an approved company-level description of the remaining candidate and request a separate assessment of the narrower field set. This is an exclusion decision, not an anonymization certification or proof that a recipient cannot infer anything confidential.
A synthetic example may help explain a schema without disclosing the underlying process, but it must be independently designed and clearly labeled. Copying a confidential sequence and changing numbers can preserve the very pattern that prompted the restriction.
Separate permission from protective handling
If a disclosure is later authorized, its access controls, intended use, onward-access limits and return or deletion terms still need attention. Those protections address handling; they do not cure missing authority at the start. The file should retain the version authorized and the person who approved that particular use.
Use rights review to list agreements and unresolved ownership or confidentiality questions. An introduction brief should stay within its named recipient and approved metadata. VOID can coordinate a permissioned fit discussion without taking custody of the source archive or certifying its secrecy review.
The reader’s next action is concrete: identify the process owner, locate the relevant agreement, classify the proposed fields and record an include, exclude or hold decision with a reason. Where the crucial agreement cannot be found, keep that material out of the proposed disclosure until the authority question is resolved.
Use this review agenda with your legal and privacy advisers. Requirements depend on the records, jurisdictions and intended use.