Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Stop Treating Noncompetes Like IP ProtectionEthics & Conduct
5 min readFor Compliance Officers

Stop Treating Noncompetes Like IP Protection

Rethinking Noncompetes

Your compliance team might view noncompete agreements as critical for safeguarding intellectual property. The reasoning seems straightforward: you've invested in training employees who now have access to trade secrets and customer relationships, so you need a legal tool to prevent them from joining competitors. Without noncompetes, you might feel exposed.

This perspective has shaped employment law for decades. When the FTC moved to ban noncompete agreements, potentially nullifying 99% of them by September, the U.S. Chamber of Commerce quickly promised litigation. Their stance was clear: noncompetes are non-negotiable.

The Flaws in Traditional Thinking

Noncompetes don't protect what you think they do, and they introduce compliance risks you might not have considered.

First, the protection is misleading. If your IP security relies on stopping employees from leaving, you've already lost. Trade secrets law, non-disclosure agreements, and confidentiality obligations protect actual proprietary information. A noncompete merely stops someone from working in their field. These are different issues needing different solutions.

Second, noncompetes create a policy management headache that many compliance teams underestimate. Their enforceability varies greatly by jurisdiction. California won't enforce them at all. Massachusetts limits them to 12 months and excludes hourly workers. You're dealing with a patchwork of state-level restrictions that change faster than your Policy Gap Analysis cycles.

Third, noncompetes can undermine the culture you're trying to build. You can't tell employees "speak up, we value your voice" while also saying "sign this agreement that restricts where you can work for two years after you leave." Employees notice this contradiction. It affects your hotline utilization rates, exit interview data, and your ability to identify problems early.

Understanding the Evidence

The FTC's rule defines noncompetes as any agreement preventing an employee from taking a similar role elsewhere or starting a competing business. This is broader than many compliance teams realize. It includes garden leave provisions, customer non-solicitation clauses that are too broad, and confidentiality agreements that act as employment restrictions.

The rule excludes senior executives, defined as those earning more than $151,165 annually who hold policy-making positions for the entire enterprise. The FTC aligned this with SEC executive officer definitions: few in number, true decision-makers. If you're classifying 97 people across 14 divisions as senior executives, you're setting yourself up for a challenge you'll lose.

The FTC made it clear: companies can't use non-solicitation, non-disclosure, or trade secrets clauses if they're "so broad or onerous that [they have] the same functional effect" as a noncompete. This isn't a loophole, it's a clear test. Your alternative protections need to protect specific business interests, not restrict employment generally.

The economic argument is significant too. The FTC estimates the ban could generate $400 billion in higher wages over the next decade and create an additional 8,500 new businesses annually. Whether you agree with those projections or not, they signal regulatory intent: the government views noncompetes as labor market restrictions, not IP protection mechanisms.

Practical Steps Forward

Build actual IP controls rather than employment restrictions.

Identify what you're protecting. Run a data processing register that identifies trade secrets, customer lists, proprietary methodologies, and confidential business information. Map these to specific employees and roles. If you can't articulate what competitive harm would occur from an employee leaving, you don't have a protectable interest worth restricting.

Create narrow, defensible contractual protections. Non-disclosure agreements should specify exactly what information is confidential and what the employee can't disclose. Non-solicitation clauses should name specific customers or employees, not ban all contact with anyone connected to your business. Trade secrets provisions should reference your actual trade secrets, not serve as catch-all employment restrictions.

Work with outside counsel to test these against the FTC's functional effect standard. If your NDA would prevent someone from working in their field, it's a noncompete in disguise.

Enhance your policy management infrastructure. You need state-by-state analysis of noncompete restrictions, not a single national policy. Build a Policy Exception Registry that tracks which jurisdictions allow what restrictions. Train hiring managers on what they can and can't include in employment agreements based on location. Document everything.

This isn't optional. A manager in Massachusetts who asks an hourly worker to sign a noncompete exposes you to litigation risk even if the agreement wouldn't be enforceable. You need controls that prevent the ask, not just language that disclaims enforceability.

Accurately identify senior executives. If the FTC rule takes effect as written, you'll need to document which executives meet both the compensation threshold and the policy-making position requirement. This should be a small list. If it's not, you're misclassifying roles and creating regulatory exposure.

When Noncompetes Make Sense

Noncompetes do make sense in specific situations, and the FTC rule acknowledges this by exempting senior executives temporarily.

If you're a private equity firm and your partners have access to deal flow, portfolio strategy, and investor relationships across your entire business, a noncompete protects legitimate interests that other contractual mechanisms can't address. The same applies to C-suite executives who set enterprise-wide strategy and have comprehensive access to competitive positioning.

The key word is comprehensive. If someone's competitive knowledge is limited to one product line, one region, or one customer segment, you don't need a noncompete. You need better information security controls and a properly scoped NDA.

Noncompetes also remain relevant during M&A transactions involving business owners. If you're acquiring a company and the founder has customer relationships that are the primary asset, a time-limited noncompete as part of the purchase agreement serves a different function than an employment noncompete.

But for most of your workforce, including many you currently classify as executives, noncompetes are the wrong control. They don't protect what you think they protect, they create unnecessary compliance complexity, and they damage the culture you're trying to build.

The FTC's rule is prompting a conversation compliance teams should have started years ago. Whether the ban survives litigation or not, you should be asking: what are we actually trying to protect, and what's the right control to protect it?

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like