Selected cases

Court of Appeal of England and Wales · [2021] EWCA Civ 38

Travel Counsellors Ltd v Trailfinders Ltd

The Court of Appeal upheld the finding that TCL was under an obligation of confidence.

Court of Appeal of England and Wales19 Jan 2021

Plain-English explainers, not legal advice. Use the linked official source for section-level detail, and get advice for your situation.

Get legal help

Start here

Quick read

  • Do not assume a new recruit or franchisee is free to bring over a customer list just because they know the customers personally.
  • Travel Counsellors Ltd v Trailfinders Ltd is a leading Court of Appeal warning for businesses that accept customer information from incoming staff or franchisees.

Use this to check

  • A business can owe an obligation of confidence when it receives customer information from incoming staff or franchisees.
  • If a reasonable recipient would ask where the information came from, failing to ask can still create liability.
  • It is enough that some of the information is likely to be confidential, not necessarily all of it.

Decision snapshot

  1. What happened

    • Trailfinders was a travel agent with 37 branches in the UK and Ireland and more than 700 sales consultants.
    • Travel Counsellors Ltd, referred to in the judgment as TCL, was a competing travel business operating through a franchise model with around 1,250 franchisee travel consultants.
    • The dispute arose after a number of Trailfinders sales consultants left to join TCL in 2016.
    • Trailfinders said former consultants had taken client names, contact details and other customer information from its systems.
  2. What the court had to decide

    • The appeal focused on when a recipient of information becomes subject to an equitable obligation of confidence.
    • TCL argued that the trial judge had applied the wrong test and that it was not enough that a reasonable person would have made enquiries about whether the information was confidential.
  3. What the court decided

    • The Court of Appeal dismissed TCL’s appeal.
    • It held that where the circumstances would bring it to the notice of a reasonable person in the recipient’s position that the information, or some of it, may be confidential to another, the reasonable response may be to make enquiries.
    • If the recipient does not do so, an obligation of confidence can arise.

Practical impact

Practical read

  • Do not assume a new recruit or franchisee is free to bring over a customer list just because they know the customers personally.
  • If the volume, format or detail of the information suggests it may have come from a former employer’s systems, your business should stop and ask questions before loading it into your own systems or using it for marketing.
  • A business can be liable even without direct proof that it knew every item was confidential, where a reasonable person in its position would have made enquiries.
  • For small businesses, that means having a clear onboarding rule: no imported client data unless its source and permitted use have been checked and recorded.

Useful next steps

  • A business can owe an obligation of confidence when it receives customer information from incoming staff or franchisees.
  • If a reasonable recipient would ask where the information came from, failing to ask can still create liability.
  • It is enough that some of the information is likely to be confidential, not necessarily all of it.
  • Uploading imported contacts into your systems and using them for marketing can amount to misuse.
  • Clear onboarding rules, confidentiality terms and CRM controls are essential when recruiting from competitors.

The story

This dispute was about customer information moving with staff from one travel business to another. Trailfinders said former sales consultants took client details from its systems when they left and that the competitor they joined, Travel Counsellors Ltd, received and used that information.

The case mattered because the incoming business did not just employ the individuals. The trial judge found it expected people from the travel industry to bring customer contact lists with them and then loaded those contacts into its own systems. That turned the case from a simple employee exit dispute into a wider warning for any business that benefits from information brought in by new hires, franchisees or contractors.

For ordinary businesses, that is the practical hook. Many disputes about confidential information start with a departing employee. This one also focused on the recipient business and what it should have done when information arrived. If your business recruits from competitors, buys books of business, runs a franchise network or asks new joiners to upload contacts into a CRM, the same risk can arise in a much less dramatic setting than a court case.

The Court of Appeal was not deciding whether every customer relationship belongs to a former employer forever. It was dealing with a narrower but important point: when a business receives customer information in circumstances that should raise concern, can it avoid responsibility by not asking questions? The answer was no.

Details that matter

  • Trailfinders operated branches and employed sales consultants
  • TCL was a competitor using a franchise model
  • Former Trailfinders consultants joined TCL in 2016
  • Customer information from Trailfinders systems was said to have been taken and used
  • The appeal focused on TCL's liability for breach of confidence

What information was in dispute

The judgment identifies two Trailfinders systems. “Superfacts” held a wide range of client information and was especially useful when a client called, because the software recognised the number and displayed related information on screen. Staff accessed it with unique logins and passwords.

“Viewtrail” was client-accessible. At the relevant time, a client could access details online using a booking reference number and surname, or through a hyperlink sent by a Trailfinders sales representative. The trial judge found that one former employee had built a contact book containing names, contact details and booking reference numbers that could be used to access customers’ Viewtrail accounts.

That detail matters for business owners because confidentiality disputes often turn on what the information looked like in practice. A rough memory of who your regular customers are is different from a structured list containing names, email addresses, phone numbers, booking references and other account details. The more organised and system-derived the information is, the harder it is to say it was simply carried in someone’s head or gathered from public sources.

The court also noted that some information may be confidential even if not every item in a list is protected. That is important in real business life. A spreadsheet can contain a mix of remembered contacts, public details and confidential internal data. The presence of some non-confidential material does not make the whole exercise safe.

Practical sense check

  • Names and contact details can be confidential business information
  • Booking histories and reference numbers can increase sensitivity
  • Information spread across internal and client-facing systems still needs control
  • Unique logins and passwords help show information was controlled, not public
  • The more detailed and structured the data, the harder it is to argue it was just remembered

What the court decided

The Court of Appeal dismissed TCL’s appeal. It held that if the circumstances are such that a reasonable person in the recipient’s position would realise the information, or some of it, may be confidential to another business, that reasonable person may be expected to make enquiries. If the recipient does not do that, an obligation of confidence can arise.

The court accepted the trial judge’s view that TCL ought to have appreciated that at least part of the contact information brought by the former Trailfinders employees was likely to have been copied from Trailfinders’ customer data. The quantity of information mattered.

The court also relied on findings that TCL encouraged people from a travel background to bring old customer contact lists, did not warn them about breach of confidence risk, and did not ask about the source of the information before loading it into its systems.

The court rejected several narrower arguments from TCL. It said it was not necessary for all the information received to be confidential. It was enough that some of it was likely to be. It also said it was not necessary to prove the recipient had actual knowledge or blind-eye knowledge for this issue. If a reasonable recipient would have made enquiries, but did not, that was enough for the obligation to arise.

On misuse, TCL accepted limited use by storing the information in its systems and using it to send marketing emails. The Court of Appeal left questions about the extent of use and damages to a later inquiry. So the decision is strongest as a liability warning: once risky information is received and used, even in limited ways, the business may already be in difficulty.

What the court focused on

  • It was enough that some of the information was likely to be confidential
  • It was enough that a reasonable recipient would have made enquiries
  • Blind-eye knowledge was not required for this primary liability issue
  • TCL had admitted limited use by storing the information and sending marketing emails
  • Questions about the extent of use and damages were left for the damages inquiry

How to read this for your business

This decision is highly relevant if your business recruits from competitors, runs a franchise network, or asks new joiners to bring leads or customer contacts. The court was not saying that every customer relationship belongs to the former employer forever. But it did make clear that a business cannot safely accept a structured customer list without checking where it came from and whether it can lawfully be used.

For SMEs, the risk often appears in ordinary onboarding steps: importing a spreadsheet into a CRM, asking a recruit for their client book, or sending a welcome campaign to contacts they provide. If the list is large, detailed, or looks like it came from a business system rather than memory or public sources, your business should treat that as a warning sign and pause before using it.

A useful way to read the case is to separate personal relationships from business records. A salesperson may know many customers and may be able to contact some of them from memory or through lawful personal channels. That does not mean they can hand over a structured list copied from a former employer’s systems. The court’s reasoning shows why format and context matter.

A long, organised list with titles, names, email addresses, phone numbers and other details is more likely to trigger questions than a handful of remembered contacts.

The case is also relevant beyond travel. Similar issues can arise in recruitment, real estate, financial services, professional services, trades, software sales, healthcare and any business where repeat custom depends on account histories and relationship data. If your business benefits from incoming contacts, you need a process that distinguishes lawful relationship-building from risky transfer of someone else’s confidential information.

Operating checklist

The practical lesson is to build a process that catches risky information before it is used. This is not only about legal drafting. It is also about training, systems and record-keeping. A short written process can make a major difference if a dispute later arises.

If your business receives customer information from incoming staff, franchisees or contractors, make sure someone is responsible for checking source, permissions and intended use before the data goes live in your systems.

Start with a simple rule: no imported customer list should be uploaded automatically. Ask where it came from, whether it was copied from a former employer’s systems, whether any part came from internal databases, and whether the person has authority to share it. Record the answers. If the explanation is unclear, incomplete or evasive, do not use the list until the issue is resolved.

Then look at your own behaviour. The facts against TCL included encouragement to bring old customer contact lists and a failure to warn about breach of confidence risk. That means your recruitment materials, franchise brochures, manager scripts and onboarding emails all matter. Avoid language that could be read as inviting people to bring competitor customer data.

A safer approach is to require new joiners to confirm that any contacts they provide can lawfully be used and do not include confidential information belonging to another business.

Sense check

  • Do not invite recruits to bring competitor customer lists without checks
  • Require a written explanation of the source of any imported contacts
  • Pause before uploading large or structured lists into your CRM
  • Do not send marketing emails from an unverified list
  • Keep a record of who approved use of the information and why
  • Train managers and onboarding staff to spot warning signs
  • Escalate doubtful cases before the information is used

Documents and controls to review

This case also shows the value of internal controls for the business trying to protect its own customer information. Trailfinders relied on the fact that customer information sat in identified systems with controlled access. For a small business, that kind of evidence can help show the information was treated as confidential and not left open to the world.

Review both sides of the problem: how you stop your own information leaving, and how you avoid receiving someone else’s protected information. Contracts, policies and system settings should work together.

On the protection side, think about what would help you prove confidentiality if a dispute arose. Clear confidentiality wording in employment and contractor terms, individual logins, password controls, restricted exports, prompt removal of access on exit and records of what was returned can all help show that customer information was treated as confidential in practice.

On the receiving side, your documents should make clear that new joiners must not provide third-party confidential information and that any customer data they do provide will be checked before use.

These controls are not just for large organisations. A small team with a shared spreadsheet and informal onboarding can still face the same legal issue. The court’s reasoning rewards businesses that ask sensible questions and keep sensible records.

Documents to keep in order

  • Employment contracts with confidentiality obligations
  • Franchise or contractor onboarding terms dealing with third-party information
  • Acceptable use and data handling policies
  • CRM access controls and user logs
  • Offboarding checklists for departing staff
  • Marketing approval controls for imported contact lists
  • Records showing when access was removed and materials returned

Common questions

Can a business get into trouble just for receiving a customer list from a new hire?

Yes. This case shows that receiving and using a customer list can create legal risk if the circumstances suggest the information may be confidential to the former employer. A business should ask where the list came from and whether it can lawfully be used before uploading or marketing from it.

Does it matter if only part of the information is confidential?

Yes. The Court of Appeal said an obligation of confidence does not fail just because only some of the information is confidential. The obligation can attach to the confidential part, even if other parts may be public or based on personal knowledge.

Is actual knowledge required before a recipient business is at risk?

Not always. The court focused on what a reasonable person in the recipient’s position would have understood and whether that reasonable person would have made enquiries. If the business does not ask obvious questions, that can still lead to liability.

What should a franchisor or employer do when onboarding people from competitors?

Use a written onboarding process. Ban imported client data unless the source is checked, require written confirmation about ownership and permissions, avoid marketing from unverified lists, and train managers not to encourage recruits to bring over competitor customer data.

Related topics

How Sprintlaw can help