1
The Appellant/Plaintiff appeals against the decision of the Sessions Court that dismissed the Appellant’s claim against the Respondent/Defendant for breach of Engagement of Consultancy Agreement (Consultancy Agreement).
WA-12BCY-1-05/2024
High Court of Malaysia3 Mar 2025
The written judgment as the court issued it, with the coram, case number, and source links. Every paragraph has its own anchor.
Citations and treatment detected automatically from later judgments and the authorities this decision relies on.
Later cases and laws citing this decision
Not yet cited by a later decision.
Earlier cases and laws this decision relies on
“Ti [2021] 7 CLJ 104; [2022] MLJU 2370, Leonard David Shim J provided an explanation on what reliance loss was as follows- “Compensation for breach of contract is provided for under section 74 of the Contracts Act 1950. section 74 provides as follows: When a contract has been broken, the party who suffers by the breach”
“verify the originality of this document via eFILING portal 12 ANALYSIS AND FINDINGS Burden of Proof [30] It is trite law that the Plaintiff must prove its case as provided under section 101 of the Evidence Act. In this regard, once the Plaintiff had adduced prima facie evidence of a breach of confidential information,”
“imilarly applicable to the terms in a letter of employment. (See Lim Wen-Chih & Anor v. Mycom Berhad [2013] 7 MLRA 677; [2014] 3 MLJ 691 and Subramanian v. Retnam [1965] 1 MLRH 231; [1966] 1 MLJ 172; [1965] CLJU 169). Confidential Information [33] In this regard, the Federal Court in Dynacast (Melaka) Sdn Bhd & Ors v.”
“vision and control of others more senior in the company hierarchy. At common law, only persons holding a senior management position, owe duties similar to directors: Green v. Bestobell Industries Ltd [1982] WAR 1. [45] In Labour Law by Simon Deakin and Gillian S Morris, 5th edn (2009), Hart Publishing, the learned auth”
“user named Tiger Lai on 26.10.2020. [50] The Defendant did not produce any expert witness to disregard the testimony of the Plaintiff’s expert witness. In Wynn Resorts (Macau) S.A. v. Poh Yang Hong [2019] MLJU 2003; [2019] MLRHU 1845, the court held- [130] In my view, it is significant in this context that PW2’s opinio”
“Lai on 26.10.2020. [50] The Defendant did not produce any expert witness to disregard the testimony of the Plaintiff’s expert witness. In Wynn Resorts (Macau) S.A. v. Poh Yang Hong [2019] MLJU 2003; [2019] MLRHU 1845, the court held- [130] In my view, it is significant in this context that PW2’s opinion on the definiti”
“malware planted by the Defendant. **Note : Serial number will be used to verify the originality of this document via eFILING portal 26 [56] In Shim Yen Lin v. Cedric Wong King Ti [2021] 7 CLJ 104; [2022] MLJU 2370, Leonard David Shim J provided an explanation on what reliance loss was as follows- “Compensation for brea”
Auto-detected from judgment text; not a substitute for a citator check.
1
The Appellant/Plaintiff appeals against the decision of the Sessions Court that dismissed the Appellant’s claim against the Respondent/Defendant for breach of Engagement of Consultancy Agreement (Consultancy Agreement).
2
This Court allows the appeal and the reasons are as deliberated.
3
For ease of reference, the parties will be referred as they were, in the Sessions Court.
4
The Plaintiff is a private limited company incorporated in Malaysia that offers peer-to-peer (P2P) mortgage services through a digital mortgage crowd lending platform. Through a Letter of Engagement for Consultancy dated 31.12.2019, the Plaintiff appointed the Defendant as a Technical Development Lead which includes a monthly fee and potential equity offer, subject to conditions outlined in the Consultancy Agreement.
5
The Plaintiff’s business is based on the Homecrowd Digital Platform as the Plaintiff’s digital mortgage crowd lending platform and the only source of income for the Plaintiff.
6
The Defendant was tasked with developing the Plaintiff’s digital mortgage crowd lending platform (Platform) in stages. In January 2020, the Defendant created the Plaintiff’s GitLab repository (GitLab) using the email address kevin.chew@myhomecrowd.com. Additional email addresses, including personal ones such as “@kevinmvp” and “kevin@byte2c.com,” were also added to the repository system. The Defendant then began development work on the Platform.
7
The Platform was to include various features including Experian Integration, Crowdfunding Listing, Crowdfunding Investment, API Integration, Protocols, SEO, Blog, and Traffic Analysis, as outlined in the development roadmap, with a target completion date of 30.06.2020. Instead of creating afresh, the Defendant had informed the Plaintiff that he will be recycling his earlier projects to be utilised for the Platform.
8
Gitlab is an DevOps software package that allows for the development, security and operation of software and is run by Gitlab Inc, an open-core company. In that regard, Gitlab has the following features, which will be very crucial to the matter at hand-
a
Gitlab has a local repository function;
b
To log into Gitlab, the user account is tied to the user’s email and not the user’s computer;
c
One computer can use or log in to more than one account; and
d
GitLab users can be granted access to one another so they can collaborate on GitLab as a shared platform. [9] The Plaintiff’s Gitlab Account (Gitlab Account) was registered using an email address which was set up for the Defendant, kevin.chew@myhomecrowd.com on 22.1.2020. On the same day, the Defendant gave access to the said Plaintiff’s Gitlab Account by using his personal email address under kevin@byte2c.com and had set the Gitlab ID as @kevinmvp. [10] It is crucial to note that at all material times, the Defendant had the only and sole access to the Gitlab Account for the purposes of developing the Platform. [11] Other than the Consultancy Agreement, there was also Appendix II of the Consultancy Agreement which is a document known as Appendix II Confidential Information and Invention Assignment Agreement (Appendix II) which was executed by the Defendant via electronic means and sent to the Plaintiff’s director, Dave Chew on 30.6.2022. Amongst others, the salient terms under the Consultancy Agreement were- “We wish to engage your services on a full-time IT consultancy basis to be TECHNICAL DEVELOPMENT LEAD at Homecrowd. Please review this summary of terms and conditions for your anticipated consultancy for us.
1
Your services will be provided to HomeCrowd starting on the 15th of January 2020 for an initial period of one (1) year. During the period of your engagement, you would report directly to the Company’s Director(s).
2
You will be required to be based in the HomeCrowd office or other location as may required from time to time by the management of HomeCrowd. As this is a full-time consultancy, you will be required to be present during the official office hours (9.00am to 6.00pm) from Monday to Friday to support HomeCrowd as well as to carry out your role. You may also be required to provide your service after office hours.
3
During the time while you are providing consulting services to this Company, you will not engage in any employment, consulting or other business activity (whether full-time or part time) that would create a conflict of interest with the Company. By signing this letter of agreement, you confirm that you have no contractual commitments or other legal obligations that would prohibit you from performing your duties for the Company. Any form of breach will result in a fine.
4
You will be paid for your services at the rate of RM 6,000 per month, prorated according to the number of business days worked, at the end of each month.
5
This engagement may be terminated by either party by giving written notice of 1 month during the first three months and by giving written notice of 2 months thereafter. …
9
Confidential Information and Invention Assignment Agreement As we are a technology company, you are required to adhere to the additional clause in the Appendix II as attached.” [12] While the Salient terms of Appendix II, amongst others, were-
2
“Clause 2 Duties. I will perform for the Company such duties as may be designated by the Company from time to time or that are otherwise within the scope of the Relationship and not contrary to instructions from the Company. During the Relationship, I will devote my entire best business efforts to the Interests of the Company and will not engage in other employment or in any activities detrimental to the best interests of the Company without the prior written consent of the Company.
3
Clause 3 Confidential Information a. Protection of Information. I understand that during the Relationship, the Company intends to provide me with information, including Confidential Information (as defined below), without which I would not be able to perform my duties to the Company, I agree, at all times during the term of the Relationship and thereafter, to hold in strictest confidence, and not to use, except for the benefit of the Company to the extent necessary to perform my obligations to the Company under the Relationship, and not to disclose to any person, firm, corporation or other entity, without written authorization from the Company in each instance, any Confidential Information that I obtain, access or create during the term of the Relationship, whether or not during working hours, until such Confidential Information becomes publicly and widely known and made generally available through no wrongful act of mine or of others who were under confidentiality obligations as to the item or items involved. I further agree not to make copies of such Confidential Information except as authorized by the Company. b. Confidential Information. I understand that "Confidential Information" means information and physical material not generally known or available outside the Company and information and physical material entrusted to the Company in confidence by third parties. Confidential Information includes, without limitation: (i) Company Inventions (as defined below); and (ii) technical data, trade secrets, know-how, research, product or service ideas or plans, software codes and designs, algorithms, developments, inventions, patent applications, laboratory notebooks, processes, formulas, techniques, biological materials, mask works, engineering designs and drawings, hardware configuration information, agreements with third parties, lists of, or information relating to, employees and consultants of the Company (including, but not limited to, the names, contact information, jobs, compensation, and expertise of such employees and consultants), lists of, or information relating to, suppliers and customers (including, but not limited to, customers of the Company on whom I called or with whom I became acquainted during the Relationship), price lists, pricing methodologies, cost data, market share data, marketing plans, licenses, contract information, business plans, financial forecasts, historical financial data, budgets or other business information disclosed to me by the Company either directly or indirectly, whether in writing, electronically, orally, or by observation. c. Third Party Information. My agreements in this Section 3 are intended to be for the benefit of the Company and any third party that has entrusted information or physical material to the Company in confidence. I further agree that, during the term of the Relationship and thereafter, I will not improperly use or disclose to the Company any confidential, proprietary or secret information of my former employers) or any other person, and I agree not to bring any such information onto the Company's property or place of business. d. Other Rights. This Agreement is intended to supplement, and not to supersede, any rights the Company may have in law or equity with respect to the protection of trade secrets or confidential or proprietary information
8
Clause 8 Solicitation of Employees, Consultants and Other Parties. As described above, I acknowledge and agree that the Company’s Confidential Information includes information relating to the Company’s employees, consultants, customers and others, and that I will not use or disclose such Confidential Information except as authorized by the Company, I further agree as follows: a. Employees, Consultants. I agree that during the term of the Relationship, and for a period of twelve (12) months immediately following the termination of the Relationship for any reason, whether with or without cause, I shall not, directly or indirectly, solicit, induce, recruit or encourage any of the Company's employees or consultants to terminate their relationship with the Company, or attempt to solicit, induce, recruit, encourage or take away employees or consultants of the Company, either for myself or for any other person or entity. b. Other Parties. I agree that during the term of the Relationship, I will not negatively influence any of the Company's clients, licensors, licensees or customers from purchasing Company products or services or solicit or influence or attempt to influence any client, licensor, licensee, customer or other person either directly or indirectly, to direct any purchase of products and/or services to any person, firm, corporation, institution or other entity in competition with the business of the Company. In addition, I acknowledge that the Company has valuable Trade Secrets (as defined by applicable law from time to time) to which I will have access during the term of the Relationship. I understand that the Company intends to vigorously pursue its rights under applicable Trade Secrets law if, during a period of twelve
12
months immediately following the termination of the Relationship for any reason, whether with or without cause, 1 solicit or influence or attempt to influence any client, licensor, licensee, customer or other person either directly or indirectly, to direct any purchase of products and/or services to any person, firm, corporation, institution or other entity in competition with the business of the Company. Thereafter, the Company intends to vigorously pursue its rights under applicable Trade Secrets law as the circumstances warrant.”. [13] Among the Defendant’s responsibilities, were as listed in the table below- [14] The abovementioned milestone table (Product Roadmap) was prepared by the Defendant himself. [15] On 7.9.2020, the Defendant resigned and served a notice of termination to the Plaintiff. The Defendant was supposed to serve a two
2
months’ notice as stipulated in the Consultancy Agreement. However, the Defendant had failed to serve the said requisite two (2) months’ notice. The Plaintiff acknowledged receipt of the notice and agreed to a one-month notice period, conditional, upon proper handover of the Defendant’s work. However, from 01.09.2020, the Defendant had ceased attending the Plaintiff’s office and the Plaintiff alleges that there was no proper handover conducted. Discovery of the Trojan/Backdoor [16] On or around 8.2.2021, the Plaintiff’s intern, one Kong Woon Kit, discovered that there was a suspicious malicious code in the Plaintiff’s codes in Gitlab. [17] Subsequently, the Plaintiff had around March 2021 engaged a cyber-security firm, AKATI Sekurity (M) Sdn Bhd to identify, analyse and investigate any anomalies in the two (2) repositories of source codes belonging to the Plaintiff. [18] The forensic analysis was conducted in April 2021 and had revealed that there were five (5) suspicious files (which includes 4 infected files and 1 error file) and the files match the consistency and behaviours of a “Trojan/Backdoor”. [19] Furthermore, it was identified that the act of committing the code into the master repository of the Plaintiff was carried out by a user “Kevin” with email of kevin@byte2c.com on or around 22.1.2020 who is the Defendant. [20] During and after the termination period, third-party individuals were granted access to the GitLab repository without the Plaintiff’s consent. Access for certain company directors was also removed. The Plaintiff subsequently has to rebuild its digital platform. [21] Hence, the Plaintiff filed this claim at the Sessions Court against the Defendant for breach of his fiduciary obligations and for damages for such breach, alleging that the Defendant breached the Consultancy Agreement dated 30.12.2019 by failing to complete key platform features, not properly handing over work after termination, granting unauthorized third-party access to the GitLab repository, revoking access for company directors, and embedding a “Trojan/Backdoor” into the repository with malicious intent. [22] After a full trial, the Sessions Court Judge (SCJ) dismissed the Plaintiff’s claim on the basis that there was no evidence to show that the Defendant had intentionally and in bad faith embedded a Trojan or Backdoor into the Plaintiff’s back-end repository. Additionally, the Product Roadmap relied upon by the Plaintiff to demonstrate the Defendant’s failure to complete certain tasks was not part of the Agreement and therefore could not be used to establish breach. [23] Dissatisfied with the decision of the Learned SCJ, the Plaintiff filed an appeal to this Court. Plaintiff’s Contention [24] The Plaintiff contended that the Defendant has indeed breached the terms of the Consultancy Agreement when he failed to develop and launch key features of the Platform—namely Crowdfunding Listing, Crowdfunding Investment, and Crowdfunding Protocol. [25] Further, upon termination, the Defendant did not properly hand over his work to other team members. He even granted unauthorized access of GitLab repository to third parties and revoked access for the Plaintiff’s directors. There was also in existence of malware, specifically a “Trojan/Backdoor,” in the master repository, which disrupted operations and caused the Plaintiff to rebuild the Platform from the beginning. These actions caused the Plaintiff to suffer substantial losses, rendering all development efforts and expenses incurred since January 2020 to be futile. Defendant’s Contention [26] The Defendant contended that the Plaintiff did not provide company equipment or infrastructure, which led him to use his personal GitLab account to manage the repository. This arrangement was known to the Plaintiff, and access was available to its directors throughout the engagement. [27] The Defendant also contended that the Plaintiff had alleged that the Defendant breached the Consultancy Agreement by allowing third parties—namely Tiger Lai, Jordan Ng, and nyo1004 to access GitLab repository. However, the Plaintiff did not identify specifically what confidential information was allegedly disclosed or compromised. In this case, the Plaintiff failed to meet that evidentiary threshold. [28] The Defendant further contended that the credibility of the Plaintiff’s witnesses was questionable. It is trite law that appellate courts are slow to interfere with findings of fact based on witness credibility, as the trial court enjoys the visual and auditory advantage in assessing demeanor and consistency. Throughout the trial, the Plaintiff’s witness, Dave, was observed to be uncooperative, evasive, and inconsistent in his responses. These credibility issues undermine the reliability of the Plaintiff’s narrative and the weight of its evidence. [29] Therefore, the Defendant contended that the Plaintiff had failed to establish causation between the alleged breach and the damages claimed. The Plaintiff abandoned its back-end GitLab repository on 26.10.2020, yet claimed to have discovered a Trojan/Backdoor on 08.02.2021. This delay renders the allegation irrelevant and speculative. Furthermore, the Plaintiff, by its conduct, waived the requirement for the Defendant to serve a two-month notice period and instead requested only one month. Before the completion of that one-month period, the Plaintiff’s representative, Dave, had already pressured the Defendant to leave. The Plaintiff also failed to prove that the Defendant profited from the alleged planting of the Trojan/Backdoor, which is a necessary element to justify exemplary damages. As such, the claim for exemplary damages is unfounded. ANALYSIS AND FINDINGS Burden of Proof [30] It is trite law that the Plaintiff must prove its case as provided under section 101 of the Evidence Act. In this regard, once the Plaintiff had adduced prima facie evidence of a breach of confidential information, the evidential burden shifted to the Defendant to rebut and refute. [31] Therefore, the Plaintiff must prove that the information is a confidential information, and that the Defendant had breached his Consultancy Agreement, and that the Defendant owed a fiduciary duty to the Plaintiff but had breached that duty while he was employed by the Plaintiff. [32] Accordingly, parties are bound by the terms of a contract executed and this would be similarly applicable to the terms in a letter of employment. (See Lim Wen-Chih & Anor v. Mycom Berhad [2013] 7 MLRA 677; [2014] 3 MLJ 691 and Subramanian v. Retnam [1965] 1 MLRH 231; [1966] 1 MLJ 172; [1965] CLJU 169). Confidential Information [33] In this regard, the Federal Court in Dynacast (Melaka) Sdn Bhd & Ors v. Vision Cast Sdn Bhd & Anor [2016] 4 MLRA 346; [2016] 3 MLJ 417; [2016] 6 CLJ 176; [2016] 3 AMR 725 held that to prove confidentiality of a document, there are three (3) elements to fulfil-
a
The information itself must have the necessary quality of confidence;
b
The information must have been imparted in circumstances importing an obligation of confidence; and
c
There must be an unauthorised use of that information, to the detriment of the party communicating it. [34] Additionally, in Seven Seas Industries Sdn Bhd v. Phillips Electronic Supplies (M) Sdn Bhd & Anor [2008] 5 MLJ 157; [2008] 4 CLJ 217, the Court of Appeal held- “(i) the information sought to be protected has the necessary quality of confidence;
II
(ii) the information was communicated in circumstances importing an obligation of confidence; and
III
(iii) there must be unauthorised use of that information to the detriment of the party communicating it.”. [35] Further, in the case of Schmidt Scientific Sdn Bhd v. Ong Han Suan [1997] 5 MLJ 632; [1998] 1 CLJ 685, it was held that trade secrets include information relating to name list and addresses of the plaintiff’s customers and suppliers- “It is my judgment that trade secrets are not limited to manufacturing processes or secret formulae but extend to information relating to the list of names and addresses of the customers and suppliers, specific questions sent to the customers, costs prices, specific needs and requirements of the customers and status of the ongoing negotiation with the customers. Therefore, it is my finding that in the light of the particular trade setting of the plaintiff's business, the above mentioned information had the necessary quality of confidentiality.” [36] In determining whether the Plaintiff has successfully established its claim that the Defendant had breached the terms in the Consultancy Agreement, it is apt that this Court refers to the relevant clauses. The relevant terms on confidential information are as reproduced-Consultancy Agreement “10. Confidential Information and Invention Assignment Agreement As we are a technology company, you are required to adhere to the additional clause in the Appendix II as attached.” Apendix II
2
“Clause 2 Duties. I will perform for the Company such duties as may be designated by the Company from time to time or that are otherwise within the scope of the Relationship and not contrary to instructions from the Company. During the Relationship, I will devote my entire best business efforts to the Interests of the Company and will not engage in other employment or in any activities detrimental to the best interests of the Company without the prior written consent of the Company.
3
Clause 3 Confidential Information a. Protection of Information. I understand that during the Relationship, the Company intends to provide me with information, including Confidential Information (as defined below), without which I would not be able to perform my duties to the Company, I agree, at all times during the term of the Relationship and thereafter, to hold in strictest confidence, and not to use, except for the benefit of the Company to the extent necessary to perform my obligations to the Company under the Relationship, and not to disclose to any person, firm, corporation or other entity, without written authorization from the Company in each instance, any Confidential Information that I obtain, access or create during the term of the Relationship, whether or not during working hours, until such Confidential Information becomes publicly and widely known and made generally available through no wrongful act of mine or of others who were under confidentiality obligations as to the item or items involved. I further agree not to make copies of such Confidential Information except as authorized by the Company. b. Confidential Information. I understand that "Confidential Information" means information and physical material not generally known or available outside the Company and information and physical material entrusted to the Company in confidence by third parties. Confidential Information includes, without limitation: (i) Company Inventions (as defined below); and (ii) technical data, trade secrets, know-how, research, product or service ideas or plans, software codes and designs, algorithms, developments, inventions, patent applications, laboratory notebooks, processes, formulas, techniques, biological materials, mask works, engineering designs and drawings, hardware configuration information, agreements with third parties, lists of, or information relating to, employees and consultants of the Company (including, but not limited to, the names, contact information, jobs, compensation, and expertise of such employees and consultants), lists of, or information relating to, suppliers and customers (including, but not limited to, customers of the Company on whom I called or with whom I became acquainted during the Relationship), price lists, pricing methodologies, cost data, market share data, marketing plans, licenses, contract information, business plans, financial forecasts, historical financial data, budgets or other business information disclosed to me by the Company either directly or indirectly, whether in writing, electronically, orally, or by observation. c. Third Party Information. My agreements in this Section 3 are intended to be for the benefit of the Company and any third party that has entrusted information or physical material to the Company in confidence. I further agree that, during the term of the Relationship and thereafter, I will not improperly use or disclose to the Company any confidential, proprietary or secret information of my former employers) or any other person, and I agree not to bring any such information onto the Company's property or place of business. d. Other Rights. This Agreement is intended to supplement, and not to supersede, any rights the Company may have in law or equity with respect to the protection of trade secrets or confidential or proprietary information
8
Clause 8 Solicitation of Employees, Consultants and Other Parties. As described above, I acknowledge and agree that the Company’s Confidential Information includes information relating to the Company’s employees, consultants, customers and others, and that I will not use or disclose such Confidential Information except as authorized by the Company, I further agree as follows: a. Employees, Consultants. I agree that during the term of the Relationship, and for a period of twelve (12) months immediately following the termination of the Relationship for any reason, whether with or without cause, I shall not, directly or indirectly, solicit, induce, recruit or encourage any of the Company's employees or consultants to terminate their relationship with the Company, or attempt to solicit, induce, recruit, encourage or take away employees or consultants of the Company, either for myself or for any other person or entity. b. Other Parties. I agree that during the term of the Relationship, I will not negatively influence any of the Company's clients, licensors, licensees or customers from purchasing Company products or services or solicit or influence or attempt to influence any client, licensor, licensee, customer or other person either directly or indirectly, to direct any purchase of products and/or services to any person, firm, corporation, institution or other entity in competition with the business of the Company. In addition, I acknowledge that the Company has valuable Trade Secrets (as defined by applicable law from time to time) to which I will have access during the term of the Relationship. I understand that the Company intends to vigorously pursue its rights under applicable Trade Secrets law if, during a period of twelve (12) months immediately following the termination of the Relationship for any reason, whether with or without cause, 1 solicit or influence or attempt to influence any client, licensor, licensee, customer or other person either directly or indirectly, to direct any purchase of products and/or services to any person, firm, corporation, institution or other entity in competition with the business of the Company. Thereafter, the Company intends to vigorously pursue its rights under applicable Trade Secrets law as the circumstances warrant.”. [37] Clearly the provisions of the Consultancy Agreement and Annexure II had stated that the Defendant must abide by the terms of his employment and that to maintain confidentiality of such information at all times and, must not be used without the written consent of the Plaintiff. [38] Notably, in the Amended Statement of Claim (SOC), the Plaintiff stated-
6
“TERMA-TERMA TERSIRAT Selain itu, Defendan juga wajib mematuhi terma-terma tersirat Perjanjian tersebut, termasuk tetapi tidak terhad kepada:-
6
6.1 Defendan mesti sentiasa ikhlas dan taat kepada Plaintif. Defendan mesti melaksanakan semua arahan yang diberikan oleh Plaintif. Defendan mesti dalam semua keadaan melakukan perkara yang munasabah bagi menjaga kepentingan Plaintif.
6
6.2 Defendan harus melakukan perkara yang munasabah bagi melindungi harta benda Plaintif.
6
6.3 Defendan tidak boleh membongkar atau menyebarkan maklumat rahsia Plaintif. Defendan perlu melindungi Plaintif dengan tidak mendedahkan maklumat rahsia Plaintif.
6
6.4 Defendan harus melakukan tugas yang diberikan cekap. Defendan juga mempunyai tanggungjawab tersirat untuk melaksanakan Defendan harus melakukan tugas sebagaimana yang diarahkan oleh Plaintif dalam masa yang ditetapkan. …
10
10.4 Defendan juga telah membenarkan pihak ketiga, iaitu Tiger Lai, Jordan Ng dan nyo1004 akses ke repositori induk Plaintif di Gitlab tanpa kebenaran Plaintif. Defendan juga telah memberhentikan akses akaun pengarah Plaintif iaitu “Dave Chew @homeCrowdAdmin” dan “HaoChenLiu” ke repositori induk Plaintif di Gitlab.”. [39] Obviously, the Plaintiff’s GitLab account contains information that is confidential, as it was a data of information which only accessible to the Plaintiff and surely is not a public information. [40] In Karen Yap Chew Ling v. Binary Group Services Bhd and another appeal [2023] 4 MLJ 792; [2023] 7 CLJ 534, the Court of Appeal held that confidentiality may be protected both under common law and contract and the employee is required to observe strict confidentiality in respect of confidential information belonging to the plaintiff during and after the termination of the contract of employment. [41] Likewise, in Svenson Hair Center Sdn Bhd v. Irene Chin Zee Ling [2008] 7 MLJ 903; [2008] 2 MLRH 339; [2008] 8 CLJ 386, the Court held that the plaintiff’s customer’s names, lists and details are regarded as confidential information. [42] The Defendant has not denied that he had allowed a third party to access the GitLab account. As such, this Court is of the considered view that paragraph 6.3 of the SOC as sufficient to justify the Plaintiff’s claim that the Defendant owed such obligation and had breached the Consultancy Agreement and Appendix II by allowing a third party to access GitLab account. Further, in the SOC, it was stated at paragraph 10.4 the particulars where the Defendant had allowed a third party, to access Gitlab without the consent of the Plaintiff. Gitlab contains confidential information of Plaintiff’s users’ personal data and external partner which is Experian Information Services (M) Sdn. Bhd. It contains data and details which include the source codes within the GitLab repository and users’ data privacy which will be of utmost importance upon the launch of the Platform. Gitlab account is confidential in nature, as it also constitutes private information of the Plaintiff. This information is not publicly available and accessible. [43] Consequently, this Court is of the opinion that the case of Zaharen Hj Zakaria V. Redmax Sdn Bhd & Other Appeals [2016] 7 CLJ 380, is of relevancy, where the Court of Appeal deliberated and explained that it is an implied term that an employee must have regard to his employer’s interest. The Court of Appeal held- “[44] Under the law, an employee of a company has a duty of fidelity to be observed at all times during his employment with the company. What is this duty of fidelity? Every employment contract contains an implied term that an employee will serve his employer with good faith and fidelity (the duty of fidelity). The duty of fidelity is owed by all employees and is to be distinguished from a fiduciary duty. A fiduciary duty requires an employee to act in the interests of his employer, whereas the duty of fidelity requires an employee to have regard to his employer's interests. Inherent in that duty to have regard to his employer's interests must be a duty not to act in a manner which would be to disregard his employer's interests. Such acts must include acts that are inherently detrimental to his company's interests.” (Emphasis Added) [44] As such, it is obvious that disclosing/exposing confidential information is a disregard to the employer’s interest. This Court finds that Appendix II is an important document to show the obligations of the Defendant to protect confidential information pertaining to his work with the Plaintiff. Therefore, the SCJ had erred in failing to appreciate that Appendix II had to be read together with the Consultancy Agreement and that those obligations to protect the confidential information were provided in Appendix II which the Defendant had failed to abide. Based on these express provisions, this Court finds that the Defendant had breached his employment contract. Breach of Fiduciary Duty [45] In this regard, the Federal Court in the case of The Board of Trustees of the Sabah Foundation & Ors v. Datuk Syed Kechik Syed Mohamed & Anor [2008] 5 MLJ 469 cited the following passage by Millet LJ in the English case of Bristol and West Building Society v. Mothew [1988] Ch. 1 ('Bristoland West Building Society') for fiduciary obligations that is owed by an employee- “We would approach the issue raised in this appeal by first examining whether DSK is in a position of a fiduciary. It further follows if DSK is in the position of a fiduciary whether he had committed any breach of fiduciary duty. In law the position of the fiduciary and his obligation have been succinctly stated by Millet L.J. in the English case of Bristol and West Building Society v. Mathew [1988] Ch. 1 to be as follows: "A fiduciary is someone who has undertaken to act for or on behalf of another in a particular matter in circumstances which give rise to a relationship of trust and confidence. The distinguishing obligation of a fiduciary is the obligation of loyalty. The principal is entitled to the single-minded loyalty of his fiduciary. This core liability has several facets. A fiduciary must act in good faith; he must not make a profit out of his trust; he must not place himself in a position where his duty and his interest may conflict; he may not act for his own benefit or the benefit of a third person without the informed consent of his principal. This is not intended to be an exhaustive list, but it is sufficient to indicate the nature of fiduciary obligations. They are the defining characteristics of the fiduciary. The nature of the obligation determines the nature of the breach. The various obligations of a fiduciary merely reflect different aspects of his core duties of loyalty and fidelity. Breach of fiduciary obligation, therefore, connotes disloyalty or infidelity. Mere competence is not enough. A servant who loyally does his incompetent best for his master is not unfaithful and is not guilty of a breach of fiduciary duty."” [46] Further, the Court of Appeal in the case of Karen Yap (supra) held- “[46] Moreover, the defendant Karen Yap was also a fiduciary and owed fiduciary duties to the plaintiff. In her position as the Head of Marketing, she was also entrusted with the custody of the Apricorn Disk representing the data bank of the plaintiff updated on a daily basis containing confidential information. It goes without saying that she knows that she was not to breach the plaintiff’s confidence reposed with her especially when she was leaving for Spectre.ai, a direct competitor of Binary.com. In transgressing the trust reposed on her by the plaintiff, she had transferred the whole treasure trove of confidential information to herself by making copies of it and then sought to cover any trail of such clandestine copying. [47] We need not go further and farther than the observation of Millet LJ in Bristol and West Building Society v Mothew (t/a Stapley & Co) [1998] Ch 1 at p 11 on who is a fiduciary as follows: A fiduciary is someone who has undertaken to act for or on behalf of another in a particular matter in circumstances which give rise to a relationship of trust and confidence. The distinguishing obligation of a fiduciary is the obligation of loyalty. The principal is entitled to the single-minded loyalty of his fiduciary. This core liability has several facets. A fiduciary must act in good faith; he must not make a profit out of his trust; he must not place himself in a position where his duty and his interest may conflict; he may not act for his own benefit or the benefit of a third person without the informed consent of his principal. This is not intended to be an exhaustive list, but it is sufficient to indicate the nature of fiduciary obligations. They are the defining characteristics of the fiduciary.” (Emphasis Added) [47] Likewise, in the case of Soh Chee Gee v. Syn Tai Hung Trading Sdn Bhd [2019] 6 CLJ 516; [2019] 2 MLJ 379, the Court of Appeal held that fiduciary duties are imposed on persons holding a senior management position: “[44] In Concise Principles of Company Law in Malaysia, 2nd edn. (2010), Lexis Nexis, the learned authors stated as follows: Fiduciary duties are imposed on persons who are involved in the management of a company. This obviously includes directors. The definition of a 'director' also includes persons other than directors, to whom the board has delegated managerial duties and other persons who act as a director even though they have not been validly appointed... It is therefore necessary to distinguish between persons involved in management and mere employees. Persons taking part in the management of a company have authority to act in an independent and significant manner and are not subject to the close supervision and control of others more senior in the company hierarchy. At common law, only persons holding a senior management position, owe duties similar to directors: Green v. Bestobell Industries Ltd [1982] WAR 1. [45] In Labour Law by Simon Deakin and Gillian S Morris, 5th edn (2009), Hart Publishing, the learned authors stated as follows:
II
(ii) Employees as Fiduciaries 4.110 The implied duty of fidelity operates as a term of the contract of employment, which arises as an incident of the employment relationship; it must therefore be distinguished from the separate notion of a fiduciary obligation which may (added: be) incurred by an employee to his or her employer. Only employees who undertake particular duties and responsibilities, normally associated with a senior position, will become fiduciaries and thereby assume the wide-ranging legal duties which are attached to that status. In particular, fiduciaries come under an open-ended duty of disclosure which is not part of the employee's general duty of fidelity under the contract of employment.” (Emphasis Added) [48] The Defendant was responsible for developing the Plaintiff’s digital mortgage crowdlending Platform and had failed to deliver the milestones for the Platform according to the roadmap’s timeline prepared by the Defendant himself, which formed a vital part of his obligations to the Plaintiff as well as that trojan and/or malware was uploaded and/or planted by the Defendant from the evidence presented by Krishna Rajagopal (PW- 2). Furthermore, the Defendant had failed to remove the trojan and/or malware despite being aware that the said trojan and/or malware had been planted on or around 22.1.2020 and the damage caused due to the malware. [49] In summary, PW2 concludes as follows-
a
The biggest user and / or contributor is the user named Kevin and with the email kevin@byte2c.com. The said email is one of the emails used by the
b
The suspicious “Favicon” files were uploaded by the said kevin@byte2c.com;
c
Another user named Tiger was allowed access to the repositories;
d
The Respondent was last seen on 23.10.2020 in his last log activity in Gitlab where the Respondent made some changes to some data base files;
e
The Back-end Repository was left idle since 26.10.2020; and
f
The last access on the Back-End repository was by a 3rd party user named Tiger Lai on 26.10.2020. [50] The Defendant did not produce any expert witness to disregard the testimony of the Plaintiff’s expert witness. In Wynn Resorts (Macau) S.A. v. Poh Yang Hong [2019] MLJU 2003; [2019] MLRHU 1845, the court held- [130] In my view, it is significant in this context that PW2’s opinion on the definition and distinction between gaming credit and wagering contract was not met with any expert counter-opiniop from the defendant’s side. I find that there is no credible reasori or basis to conclude that PW2’s opinion on the definition and distinction between gaming credit and wagering contract is in any way erroneous or indefensible. I accept that the PW2’s opinion ought to be accepted. In this regard, it is relevant to quote from the. Court of Appeal’s decision in Majuikan [supra] where it was said (per ArifMohd Yusoff JCA):- … [35] We are in agreement with these principles and in our view, a judge who is not an expert himself, should defer to expert opinion unless that evidence is obviously indefensible and is not supported by the basic facts of the case. Where there are conflicting expert opinions, the judge is of course entitled to bring to bear his own judicial appreciation of the matter, and choose one over the other, but where there is only one expert opinion, he should not as a rule reject that opinion outright without judiciously considering whether it is obviously indefensible and unsupported by the basic facts of the case. Such a principle is in accord with the principle that the court is the final arbiter, as stated in Dr Shanmuganathan v Periasamys/o Sithambaram Pillai [1997]3 MLJ 61: ... the principal object of expert evidence is to assist the court to form its own opinion. An expert should give his reasons. The court is the final arbiter, not the experts or witnesses ... The learned judge should have considered the reasoning given by the expert and with that assistance arrive at the conclusion. In failing to do so the learned judge had abdicated his function. The learned judge is entitled to reject the evidence but not before considering such evidence ... [51] Other than that, the Defendant had failed to develop and launch the new features of the Platform by 1.9.2020 as undertook by the Defendant. Also. the Defendant had failed to handover the works to the other team members in a proper manner prior to his resignation. [52] Therefore, on a balance of probabilities, the Defendant had breached the terms of his employment with the Plaintiff and had breached his duty and/or fiduciary duty owed to the Plaintiff and thus, the Plaintiff claims for loss of expense due to the Defendant’s breach of his duties towards the Plaintiff and more importantly for the damage caused to the Platform as a result of the planted malware. Damages [53] In the Federal Court case of Tan Sri Khoo Teck Puat & Anor v. Plenitude Holdings Sdn Bhd [1994] 1 LNS 284; [1994] 3 MLJ 777; [1995] 1 CLJ 15, the Federal Court referred to the judgment of Lord Goddard in Bonham Carter v. Hyde Park Hotel Ltd 64, TLR 177, 178 that the Plaintiffs must prove for damages. It was held- [45] Having set out the legal principle that the Plaintiff must prove their claim for the losses. The law is clear that the person seeking a claim for damages has the burden of proving both the fact and the amount of damages before he can recover them. Damages must be proved with real or factual evidence as opposed to mere particulars, summaries, estimations, or general conclusion in order for a party to recover them - See PB Malaysia Sdn Bhd v. Samudra (M) Sdn Bhd [2008] 1 LNS 679; [2009] 7 MLJ 660.” (Emphasis Added) [54] The law is clear that the person seeking a claim for damages has the burden of proving both the fact and the amount of damages before he can recover them. Damages must be proved with real or factual evidence as opposed to mere particulars, summaries, estimations, or general conclusion in order for a party to recover them (PB Malaysia Sdn Bhd v. Samudra (M) Sdn Bhd [2008] 1 LNS 679; [2009] 7 MLJ 660). [55] The Plaintiff’s is seeking for “reliance loss” against the Defendant. Basically, the Plaintiff’s claim is for the wasted expenditure and expenses incurred by the Plaintiff solely in the course of the development of the Platform that have been rendered useless as a result of the malware planted by the Defendant. [56] In Shim Yen Lin v. Cedric Wong King Ti [2021] 7 CLJ 104; [2022] MLJU 2370, Leonard David Shim J provided an explanation on what reliance loss was as follows- “Compensation for breach of contract is provided for under section 74 of the Contracts Act 1950. section 74 provides as follows: When a contract has been broken, the party who suffers by the breach is entitled to receive, from the party who has broken the contract, compensation for any loss or damage caused to him thereby, which naturally arose in the usual course of things from the breach, or which the parties knew, when they made the contract, to be likely to result from the breach of it. Such compensation is not to be given for any remote and indirect loss or damage sustained by reason of the breach. It is a codification of the common law rule laid down in Hadley v Baxendale (1854) 9 Exch 341 at page 342. The rule has two limbs to it and is stated as this, "Where two parties have made a contract which one of them has broken, the damages, which the other ought to receive in respect of such breach of contract, should be such as may fairly and reasonably be considered either arising naturally, ie according to the usual course of things from such breach of contract itself, or such as may reasonably be supposed to have been in contemplation of both parties, at the time they made the contract, as the probable result of the breach of it." The learned author, Andrew Phang Boon Leong in his book 'CHESHIRE, FIFOOT & FURMSTON'S LAW OF CONTRACT, Singapore and Malaysian Edition at pages 848 - 849 explained that in the context of this rule what the court must be concerned with is that the damages claimed from the breach is not too remote and the kind of loss for which the plaintiff is entitled to be compensated are two : expectation loss and reliance loss. Expectation loss said the learned author is the loss which the plaintiff would have received if the contract had been performed and the most obvious of such a loss is a loss of profit. Reliance loss is when the plaintiff suffered losses when he relied upon the defendant honouring his contract and had incurred expenditure in the process. These are the two losses which are provided in section 74(1) and in my view, the plaintiff is entitled to claim one or the other and not both. Why I say so is explained in the Federal Courts case of Teoh Kee Keong v Tambun Mining Co. Ltd [1968] 1 MLJ 39 at pages 41 - 42 where Ong Hock Thye FJ said as follows: "The yardstick could either be loss of profits on in the alternative, compensation for capital loss and expenses rendered futile by the breach. On this point the law is as stated in a passage in Mayne & McGregor on Damages (12th Edition) para 22:- "Sometimes however the plaintiff may be compelled by law or by circumstances to frame his suit on a different basis as to damages, not on the basis of the loss of his bargain but on the basis of his out-of-pocket loss. In other words, he is claiming not to be put into the position he would have been in had the contract been performed, but to be put into the position he would have been in had it never been made, which is a normal measure of damages akin to that in tort. In such cases expenses incurred in preparation or in part performance will be properly recoverable and will not involve an inconsistency of compensation." [57] Accordingly, the Plaintiff’s claim of RM147,427.16 which was allowed is as follows-Losses and Damages Amounts Defendant’s failure to serve notice of resignation of 2 months RM12,000.00 Cost of cybersecurity investigation RM9,000.00 Salaries of employees and team members (January – September 2020) RM121,183.51 Office Rental and Staff Welfare RM5,243.64 Total RM147,427.16 CONCLUSION [58] This Court finds that the Defendant had breached his duties under the Consultancy Agreement read together with Appendix II in allowing unauthorized third-party access to the GitLab repository and revoking access of the Plaintiff’s directors access to the Plaintiff’s Platform which include the confidential information of the Plaintiff’s users’ personal data and external partner. Therefore, this Court is of the view that the Plaintiff has satisfied all the elements pertaining to the confidential information. The Plaintiffs’ clients’ details and database are indeed confidential in nature. [59] The act of the Defendant by using Gitlab that was embedded with a “Trojan/Backdoor” into the repository, shows a malicious intent for failure to ensure due diligence in his work despite being a professional in his area of expertise. Furthermore, there was an undisputed fact that the malware by the act of the Defendant was still not removed. This was derived from the fact that it was identified that the act of committing the code into the master repository of the Plaintiff was carried out by a user “Kevin” with email of kevin@byte2c.com on or around 22.1.2020 who is the Defendant. Thus, it clearly shows that the Defendant has breached the Consultancy Agreement. [60] Additionally, the breach of his fiduciary obligations includes failing to complete key platform features and not properly handing over work after termination. [61] Based on the above deliberations, the appeal is allowed with costs. Dated: 21 September 2025 -SGD- (SUZANA BINTI MUHAMAD SAID) Judicial Commissioner of the High Court NCVC1 Kuala Lumpur COUNSELS For The Appellant : Tham Keng Yin & Cheong Chun Hui Messrs. Gary Lee & Partners For The Respondent :
Wrong text, a broken link, out-of-date content, or a removal request — tell us and we'll check it against the official source.