This article examines how a small online culinary business in Karawang, Indonesia, operationalizes trade secret protection in its daily activities. It addresses a socio-legal gap by exploring how the statutory requirements of secrecy, economic value, and reasonable protective measures under Indonesian trade secret law are implemented in small digital enterprises. The study employs a qualitative single-case design, combining a semi-structured interview with the owner-manager and doctrinal analysis of Law Number 30 of 2000 on Trade Secrets. The interview data were analyzed thematically through the perspective of legal consciousness. The findings show that the business protected its recipe through role-based access, individual credentials, two-factor authentication, standard operating procedures, confidentiality clauses in employment contracts, access monitoring, and credential revocation. Although an unauthorized access incident reduced the owner’s trust in employees, the available access log established only access, not copying, disclosure, or commercial use. Despite limited knowledge of trade secret law, the owner adopted a graduated dispute-resolution approach, beginning with warning and deliberation before pursuing formal legal remedies. The article argues that digital self-protection represents the practical operationalization of the “reasonable measures” requirement under Article 3 of Law Number 30 of 2000, while its effectiveness depends on sound evidence management, written governance, and accessible legal support for small enterprises.
Copyrights © 2026