Commercial Director Handover: An Unprotected Client Base

You have been appointed commercial director or head of sales at an operating company. In practice, you have inherited a CRM with client history, a dealer network, and a sales team. Legal protection for all of it, in all likelihood, does not exist: the trade secret regime is either not in place or was introduced with defects, exclusivity clauses in dealer agreements may turn out to be unenforceable, and a departing sales manager has every legal right to take the client base to a competitor. The problem is that this only comes to light after the fact — once the clients are already gone, and introducing protection retroactively is useless. The sections below cover what to check and put in place during the first weeks.

What You Are Actually Inheriting Along With the CRM

The key mistake is assuming that because the client base physically sits in the company’s CRM, it is already legally protected. It is not: without a properly introduced protection regime, a departing sales manager is free to work with the same clients at a competitor, and a court will not stop them.

Two independent legal tools are often confused here:

Trade secret regime (Federal Law No. 98-FZ of 29 July 2004 “On Trade Secrets”) is actively maintained confidentiality. It protects the database only for as long as you take and document specific measures to safeguard it, and it works exclusively going forward: you cannot introduce the regime today and bring a claim over a leak that happened yesterday.

The exclusive right of a database maker (Articles 1333–1336 of the Civil Code) is a fundamentally different mechanism. It does not require confidentiality at all and arises automatically for whoever organized the creation of the database, provided substantial financial, material, or organizational resources were spent on building and maintaining it. Clause 2 of Article 1334 of the Civil Code sets out a convenient presumption: if the database contains at least 10,000 independent information elements (essentially, contact records and related entries), the substantiality of the investment is presumed by default, and there is no need to prove it separately. This right protects against extraction and use of a substantial part of the database even when no employee ever signed an NDA and the trade secret regime is shaky — and it is almost never considered, with protection built solely around trade secrecy instead.

The second tool does not replace the first — they work together and cover different situations.

Auditing and Protecting the CRM in the First Days

Access rights. The first step is a review of CRM accounts: who has rights to bulk export and data extraction, whether access has been revoked for employees who have left or are leaving, and whether logging and download restrictions are in place (a DLP system, or at minimum a routine audit log of actions). This is not a formality: this kind of monitoring genuinely helps prove a violation in court. In 2013, for instance, FosAgro’s security team discovered that an employee had set up automatic forwarding of emails from his work address to an external one and was using it to pass trade secret information to the company’s business partner — following the investigation, he was convicted under Article 183 of the Criminal Code and sentenced to 1 year and 9 months of correctional labor (Gagarinsky District Court of Moscow). This case does not concern a client base being taken at the moment of resignation — it concerns disclosure during employment — but the principle is the same: control over what leaves work accounts, and to where, is a working evidentiary tool, not a mere formality.

Assessing the database under the database maker’s right. Count the number of unique records in the database — if there are 10,000 or more, the company already holds the right under Article 1334 of the Civil Code, even if no one has thought about it. If there are fewer, document the actual costs of building and maintaining the database (CRM licenses, salaries of the staff responsible for populating and updating it) so that there is documentation available to substantiate the investment if required.

Counterparties’ personal data. A client database is, as a rule, also personal data belonging to individuals: contact persons at counterparties, sole proprietors, self-employed contractors. There are two distinct violations here with different penalties under Article 13.11 of the Administrative Offences Code, and they should be reviewed separately. If the personal data processing policy is not published and freely accessible (Part 3) — the fine for a legal entity is 30,000 to 60,000 rubles. Processing data without written consent where it is required (Part 2) is already 300,000 to 700,000 rubles, and for a repeat violation (Part 2.1) — 1 to 1.5 million rubles. For a large-scale personal data leak, a turnover-based fine applies — 1% to 3% of annual revenue, though not less than 20 million and not more than 500 million rubles (Parts 15 and 18 of the same article).

Trade Secret Regime and NDAs for Sales Managers

Article 10 of Federal Law No. 98-FZ sets out five mandatory measures, and the regime is considered introduced only when all five are met together — not just some of them:

  1. A defined list of information constituting a trade secret (the client base, terms of contracts with key clients, pricing policy, dealer network).
  2. Restricted access — a documented procedure for handling the information and monitoring compliance with it.
  3. A record of individuals who have been granted access to the information, and of anyone to whom it has been disclosed or transferred.
  4. Contractual regulation of how the information is used — with employees (an NDA as part of the employment contract or a separate agreement) and with counterparties.
  5. The “Trade Secret” designation affixed to physical media, along with the name of the information’s owner.

Missing any single element means the regime is not legally in place: a court will refuse to award damages, and holding an employee to civil or criminal liability becomes impossible. Article 243 of the Labour Code allows for an employee’s full liability for disclosing legally protected secrets only “in cases provided for by federal law” — meaning precisely when a regime is in force under Federal Law No. 98-FZ. Criminal liability under Article 183 of the Criminal Code (up to 4 years’ imprisonment, 3 to 7 years for serious consequences — penalties were increased by Federal Law No. 175-FZ of 24 June 2025) works on the same logic: without a properly introduced regime, the very subject matter of the offense is absent.

What about a ban on working for a competitor after leaving? Russian law has no separate non-compete institution, and a direct ban cannot be written into the employment contract itself — that would conflict with Article 9 of the Labour Code, which prohibits terms that restrict an employee’s rights compared to labor legislation. Court practice here is genuinely inconsistent, not steadily softening. In one case, the Moscow City Court overturned a lower court’s ruling and denied a former employee compensation under a separate civil-law non-compete agreement — precisely because the employee had violated its terms himself. In other words, the court treated such an agreement as valid (case No. 33-52632/2018). In another case — the opposite scenario: a consulting firm had included a clause in its contract with a client agroholding banning the poaching of its staff; the agroholding violated it by hiring 24 of the firm’s specialists directly, and the first-instance court awarded the consulting firm nearly 41 million rubles from the agroholding — a year’s salary for each poached employee, exactly as the contract provided (case No. А40-230924/2018). The appellate court overturned that ruling, finding the clause unenforceable as a violation of an employee’s right to freely choose their place of work (9th Commercial Court of Appeal, November 2019) — and every subsequent instance, up to and including the Supreme Court of the Russian Federation, upheld that position, ultimately confirming that the clause was unenforceable. The practical takeaway: a bare ban in an employment contract is almost certain not to hold up in court; the only real chance lies with a separate, paid civil-law agreement — and even then there is no guarantee.

Auditing Exclusive Dealer Agreements — a Risk That Is Usually Overlooked

This is the least obvious part of the audit, which is exactly why it is most often overlooked. The wording “the dealer agrees not to sell goods similar to or competing with the supplier’s goods” is a standard clause in almost any exclusive dealer agreement. The problem is that this exact term is directly prohibited by Part 2 of Article 11 of Federal Law No. 135-FZ of 26 July 2006 “On Protection of Competition”: a vertical agreement obligating a buyer (dealer) not to sell goods competing with the seller’s goods is prohibited — unless the agreement falls under the exceptions in Article 12 of the same law.

There are two exceptions: (1) the agreement is structured as a commercial concession (franchise) contract under Article 1027 of the Civil Code, or (2) neither party’s share of the relevant product market exceeds 20%. If neither condition is met, the exclusivity clause on the dealer’s side is legally void: despite the signature on the contract, the dealer is formally free to sell competitors’ goods, and the mere presence of such a clause is itself grounds for a competitor or an unhappy dealer to complain to the Federal Antimonopoly Service (FAS).

It is important not to confuse the direction: the same rule applies only to the dealer’s obligation. Reverse exclusivity — a supplier’s obligation not to appoint other dealers in a given territory — is not prohibited by this rule and remains a standard, lawful distribution tool.

What to check in every current dealer agreement:

  • whether the agreement contains a clause banning the dealer from selling competitors’ goods;
  • if so — whether the agreement is structured as a commercial concession, or whether the parties’ market shares have been calculated;
  • if neither is documented — the clause needs to either be revised, or you need to be prepared for it to have no legal force.

If the Client Base Has Already Leaked Before Your Time

If the audit shows that a departing manager took clients before your appointment, and the trade secret regime was not properly in place at the time, it cannot be fixed retroactively: both civil and criminal liability require the regime to have been in force at the moment of the violation, not introduced after the fact. If some of the requirements of Federal Law No. 98-FZ were nonetheless met (say, the employee signed an NDA but the documents were not marked), whether a claim can be brought depends on the specific facts — this should be assessed by a lawyer rather than determined independently on the basis of a single factor.

Either way — document what you found in a formal act or internal memo, and close all five elements of the regime going forward at the same time: the goal now is no longer to punish the past, but to avoid repeating the situation with the next employee.

Frequently Asked Questions

Can I pursue a former manager if they took the client base before my appointment? Only if the trade secret regime was properly in place at the time of the leak — you cannot introduce it retroactively and then bring a claim. If some elements of the regime were only partially in place, the chances depend on the specific circumstances.

Is it legal to require a dealer not to sell competitors’ goods? By default, no: Part 2 of Article 11 of Federal Law No. 135-FZ directly prohibits this clause for vertical agreements. It is only permitted within a commercial concession (franchise) arrangement, or if neither party’s market share exceeds 20% (Article 12 of the same law).

Does a post-employment non-compete work in Russia? A court will almost certainly not uphold a direct ban in an employment contract — it conflicts with Article 9 of the Labour Code. Courts sometimes recognize a separate, paid civil-law non-compete agreement, but the practice is inconsistent and there are no guarantees.

What protects the client base if an employee never signed an NDA? The database maker’s exclusive right under Articles 1333–1336 of the Civil Code — it does not depend on an NDA or a trade secret regime, and arises automatically where substantial costs were incurred to build the database (presumed from 10,000 records). This is an independent form of protection against extraction of a substantial part of the database, not a substitute for a trade secret regime.

Read Also

Guide “Commercial Director Handover” — 5,000 rubles

A checklist for the first weeks, an NDA template for sales managers, and a checklist for auditing dealer agreements for antitrust risk — a practical companion to this article, so that nothing has to be tracked manually. The guide is emailed to you after payment in two formats: a PDF for the NDA template, which is easy to print and sign by hand, and an interactive HTML checklist where you can tick off completed items directly in your browser and track your progress. Request the guide →


Have you taken over a sales department and are you unsure whether the client base and dealer network are legally protected — rather than merely password-protected in the CRM? Contact us. We will audit the trade secret regime, review dealer agreements for antitrust risk, and build a contractual framework for your sales team so that any manager’s departure does not automatically mean losing clients.

Need legal advice?

Submit a request — we respond within 24 hours

Submit a Request