It is no exception that employees shortly before leaving their old employer download files that could be useful later. Increasingly, these employees are caught because this "theft" is noticed within the IT environment. In most cases, the employer will recover any damages from the employee through the civil route; we wrote an extensive article about this. But in some cases, compensation, fines or injunctions are insufficient. For this reason, the misappropriation of trade secrets can also be criminally sanctioned.
Last week, it was reported in the news that a former Callebaut employee in Belgium was sentenced to six months in prison for “stealing chocolate recipes.”[1] Shortly before moving to a competitor, the employee had downloaded 19,000 confidential files (including recipes and marketing strategies) from the company’s cloud and saved them to a USB drive. The Belgian court ruled that this constituted a breach of trust. This sentence was imposed despite the lack of evidence that the files were actually shared or sold.
This raises the question of whether in Dutch courts could have reached a similar verdict? The short answer is: yes, but the test seems tougher in the Netherlands than in Belgium. Due to the recent ruling in the Politiemol judgment[2] (2021), in which misusing one's own login credentials to unlock information was classified as "intrusion using a false key," it might just be that criminal prosecution for theft of trade secret information has become easier. Below we cover all the cases we have been able to find on the subject through public sources.
Background - two criminal brackets
In the Netherlands, the unlawful copying of trade secrets and business data is governed by two provisions of the Criminal Code:
- Article 273 of the Criminal Code, which lists two relevant provisions:
- First, any person who, as an (former) employee, intentionally discloses details about a company that are subject to a duty of confidentiality is guilty of a criminal offense (paragraph 1, subparagraph 1°).
- Second, any person who intentionally discloses information or uses it for financial gain, while knowing or reasonably suspecting that such information was obtained through a criminal act from a company’s computerized system, is liable to prosecution (paragraph 1, subparagraph 2°).
In both variants, therefore, the core component is not the "taking" as such, but rather the disclosure or use of the information. It is also important to note that prosecution only takes place after a complaint by the company's management (para. 3).
- Article 138ab Criminal Law, which criminalizes computer hacking. This article covers intentional and unlawful intrusion into a digital environment. In any case, "intrusion" occurs when access is obtained, for example, by breaking through a security system, a technical intervention, false signals or a false key, or by assuming a false capacity.
Thus, the law provides for the possibility to criminally prosecute someone for taking and/or using illegally obtained trade secret information.
Practice in the Netherlands
Anyone searching rechtspraak.nl and legal databases for rulings in which Articles 273 or 138ab of the Criminal Code appear in conjunction with trade secrets will find only a handful of rulings.[3] We will first discuss the most recent rulings here, as these are the most instructive. We will then examine a number of older cases, which provide an interesting insight into the case law. We have chosen not to discuss the merits of one case from 2018[4] involving clear criminal law and trade secret elements, because the court’s reasoning in that case is completely contradicted by several Supreme Court rulings issued after that date.
HR November 30, 2021 (the "Politiemol"), ECLI:NL:HR:2021:1691
In this case[5], a police officer abused his own access to the Blue View police system. He queried the system for information on individuals without a work-related reason, exported the results, and provided them to criminals.
The Supreme Court upheld that such improper use of a valid account could qualify as computer hacking by "intrusion using a false key" (art. 138ab (1)(c) Sr), because the authorization was used for a purpose for which it was not granted. This ruling is relevant as a correction after the aforementioned 2018 ruling: it opens the door to bring abuse of one's own authorizations under circumstances indeed under 138ab Sr, even without classic hacking acts. Something that seemed to be excluded after the aforementioned ruling precisely. The line taken here, is clearly reflected in the rulings after this date.
HR 18 April 2023, ECLI:NL:PHR:2023:37 and ECLI:NL:HR:2023:610
In this case[6] a (former) bookkeeper repeatedly logged into his employer's server with his own login data, downloaded company files. He then provided these documents to a dismissed employee to use as evidence in his dismissal proceedings against the company. The court qualified this downloading and provision as computer infringement (art. 138ab Sr) because the use of the authorizations was clearly outside the agreed task and thus "at that time" qualified as use of a false key; subsequently, art. 273 Sr (subsection 1 under 2°) was also applied because the data obtained through computer infringement was knowingly disclosed by bringing it into court. The court imposed a community service penalty of 120 hours; the conviction was upheld in cassation, with sentence reduced only because the reasonable time limit was exceeded (to 108 hours).
Rb. Rotterdam July 10, 2025 (ASML and NXP data)
In this case[7], an employee in the high-tech sector stood trial because he (i) shared technical information with a contact in Russia after sanctions against Russia took effect and (ii) copied large quantities of his employers’ business files onto personal storage devices. The court acquitted him of embezzlement in the course of employment, because digital files do not qualify as “goods”: copying them does not cause the employer to lose actual control. However, the court found him guilty of computer trespass (Art. 138ab of the Dutch Criminal Code): the defendant logged in using his own credentials but did so for a purpose other than that for which access was granted, thus constituting “intrusion using a false key.” In combination with the proven penalty offense, the judge imposed a prison sentence of 3 years.
Rb Haarlem 9 April 2009 (Postbank fraud).
In an earlier case, a defendant was convicted of hacking into the computer systems of the former Postbank over an extended period of time.[8] This was not a “pure” trade secret case, but rather a sophisticated chain of events involving the manipulation of individuals and the abuse of internal authorizations, through which the suspect gradually gained increasing access to customer and account data.
A bank employee illegally accessed accounts and passed on balance information and signature cards, among other things, after which accomplices pretended to be account holders by telephone via the "Girofoon", had codes activated and initiated transactions. The stolen data thus served as leverage for concrete fraud (swindling and transfers), whereby the court reached a conviction partly through article 273 Sr (paragraph 1 under 2°). This was because it involved the disclosure/utilization of data obtained from an automated work through a crime.
Rb Gelderland 17 November 2014
This case[9] involved the sharing of confidential customer and booking data of a travel agency; addresses and in particular periods of absence of customers. The defendant (employed by the travel agency) accessed this data through the internal system, compiled lists and provided them to a third party, who used this information as "intelligence" for residential burglaries. The court found (in addition to complicity in burglaries) violation of trade secrets ex art. 273 Sr. The criminal accusation was in the disclosure of non-publicly known business information from which harm was to be expected. The young woman (19 years old) was given a suspended prison sentence of 3 months and community service of 150 hours.
Conclusion: criminal law route seems to be cautiously pursued
The criminal route is open (and has become more real), especially where there is abuse of authorizations and data takeover. This applies not only to serious espionage-like files (such as the ASML case), but also to situations that look more innocent, such as "helping a former colleague" by downloading and forwarding company files. Since the Supreme Court confirmed in the Politiemol judgment that misuse of one's own valid login credentials can also constitute computer hacking (art. 138ab Sr), the framework is clear: anyone who logs in with a valid account for a purpose for which that access was not given can still commit "unlawful intrusion."
This makes prosecution under art. 138ab Sr more practical: you don't necessarily have to prove a "hack," but mainly that someone was using systems outside his duty/appointment and then taking data (download/export/mail/USB). And if that data is then also shared or deployed (for example, in litigation), art. 273 Sr is more likely to come into the picture. In short: criminal law is no longer a theoretical stick; in the right fact constellation, it is a real option.
Civil or criminal law: practical consideration
In most cases, the civil route (in the Netherlands especially under the Trade Secrets Protection Act) remains the most logical: swift action, possibly an (evidence) seizure and (where appropriate) damages instruments. The threshold is lower, control lies more with the aggrieved party, and the remedies are more in line with the goal: to stop, secure, and limit and recover damages.
But that does not mean that criminal law is a remedy that should be disregarded. As the case against the accountant shows, a criminal charge can send a clear norm-setting and corrective signal. The penalty here was relatively limited (108 hours of community service), but the enforcement value and deterrent effect can be significant in practice, especially compared to a purely civil course. For serious violations - particularly where there is misuse of systems or authorizations - it may therefore be appropriate to consider criminal action as well. This would be in combination with a parallel civil route.
Contact
We assist both companies facing (possible) misuse or misappropriation scenarios involving confidential information, and individuals suspected of such conduct. We are not a criminal law firm and therefore will not act as criminal defense counsel. However, we can - from our trade secrets and civil law expertise - interpret the factual and legal position, lay out the civil options and assess the strategic confluence with a possible criminal route. If specialist criminal law assistance is required, we will coordinate with colleagues specialized in this area.
For questions or consultation, please feel free to contact us!
[1] https://nos.nl/artikel/2598058-oud-werknemer-callebaut-krijgt-celstraf-voor-stelen-van-chocoladerecepten
[2] Supreme Court November 30, 2021, ECLI:NL:HR:2021:1691
[3] While there are a large number of court rulings on computer trespass, these cases involve hacking and extortion of individuals. We have not addressed these rulings here.
[4] Court of The Hague March 26, 2018, ECLI:NL:RBDHA:2018:3396
[5] Supreme Court November 30, 2021, ECLI:NL:HR:2021:1691
[6] Supreme Court April 18, 2023, ECLI:NL:HR:2023:610
[7] Rotterdam District Court July 10, 2025, ECLI:NL:RBROT:2025:8322
[8] https://uitspraken.rechtspraak.nl/details?id=ECLI:NL:RBHAA:2009:BI9061
[9] https://uitspraken.rechtspraak.nl/details?id=ECLI:NL:RBGEL:2014:7126