The Technology & Information Law Blog

Analysis by Charles Gideon Korrell

JPMorgan Chase and Argus trade secret dispute involving regulatory credit-card data, DTSA claims, and state-law territorial limits - The Technology & Information Law Blog by Charles Gideon Korrell

JPMorgan v. Argus: DTSA Ownership, Regulatory Data, and the Territorial Limits of State Trade-Secret Law

·

JPMorgan Chase Bank’s trade-secret case against Argus Information & Advisory Services has now produced two merits opinions that expose an important divide between federal and state trade-secret protection for data moving through regulatory and commercial channels. In February 2025, the District of Delaware held that JPMorgan plausibly stated a claim under the federal Defend Trade Secrets Act even though the disputed credit-card data had been submitted through Argus to federal banking regulators. The court concluded that the regulatory relationship did not necessarily strip JPMorgan of ownership of its data and that contractual restrictions imposed on Argus by the regulators could supply the duty required for DTSA misappropriation. At the same time, the court dismissed JPMorgan’s Delaware Uniform Trade Secrets Act claim because the complaint did not allege that the misappropriation occurred in Delaware.

JPMorgan then amended. In JPMorgan Chase Bank, N.A. v. Argus Information & Advisory Services Inc., No. 1:24-cv-00348-SB (D. Del. Aug. 17, 2026), Third Circuit Judge Stephanos Bibas, sitting by designation, dismissed the repleaded Delaware claim and an alternative Ohio Uniform Trade Secrets Act claim with prejudice. Allegations that Argus and Verisk sold products to companies incorporated, headquartered, or doing business in Delaware or Ohio still did not locate the operative trade-secret use in either state. Those allegations described downstream business transactions, the court reasoned, not where defendants allegedly used JPMorgan’s information to create the accused products.

Read together, the two opinions provide a more significant lesson than the August ruling alone. The same alleged course of conduct can plausibly support a federal DTSA claim while failing under state trade-secret statutes because ownership, duty, statutory territorial reach, and the geographic location of the alleged use are separate questions. For companies that route sensitive data through regulators, vendors, analytics providers, cloud systems, and multiple corporate entities, those distinctions can determine not only whether a claim survives but which body of trade-secret law is available at all. The procedural posture remains important. These are pleading-stage rulings by a federal district court, not findings that the defendants misappropriated JPMorgan’s information or that the information ultimately qualifies as protectable trade secrets. Nor do the decisions establish nationwide rules governing Uniform Trade Secrets Acts. Their importance lies in how Judge Bibas analyzed the statutory and operational structure of the alleged data use, and in the divergence he identified between the federal and state-law theories.

Two Data Streams Created the Core Trade-Secret Problem

According to JPMorgan’s pleadings, federal banking regulators require financial institutions to provide certain credit-card data. Argus historically served as an intermediary, receiving and processing that information for regulators including the Office of the Comptroller of the Currency and the Federal Reserve. Separately, Argus operated a commercial analytics business that used credit-card market data to prepare benchmarking studies and “Flash Reports” for financial-industry customers.

JPMorgan alleged that it once supplied data to Argus for both purposes but stopped participating in Argus’s commercial benchmarking program in 2010. JPMorgan nevertheless continued providing data through the regulatory channel. The complaint alleged that Argus’s government contracts restricted use of regulatory data in its private business and that, after JPMorgan withdrew from the commercial program, Argus improperly used JPMorgan’s regulatory data to fill the resulting gap in its commercial dataset.

That alleged separation between a permitted regulatory stream and a prohibited commercial stream matters throughout the case. It supplies the asserted confidentiality restriction, helps explain JPMorgan’s claimed ownership interest, and frames the later territorial question: if the wrongful act was the use of regulatory data to create commercial analytics products, where did that use actually occur?

The 2025 Opinion Preserved the Federal DTSA Claim

The February 2025 opinion did considerably more than note that the federal claim could proceed. It rejected several threshold arguments that could have ended the DTSA claim before discovery.

First, the court held that JPMorgan had alleged a concrete Article III injury. Judge Bibas reasoned that trade-secret misappropriation has a close historical relationship to the common-law action for breach of confidence. On that view, the alleged unauthorized use itself supplied a concrete injury; JPMorgan did not need to plead some additional category of financial harm merely to establish standing.

Second, the court held that JPMorgan plausibly alleged a trade secret under the DTSA. The complaint alleged confidentiality controls including restricted employee access, passwords, and limitations on access to systems containing the data, and alleged that the information had economic value because competitors did not know it. At the pleading stage, the court treated those allegations as sufficient reasonable measures rather than requiring JPMorgan to show that it had used every conceivable protective measure.

Third, and more significantly for data-sharing arrangements, Judge Bibas rejected the defendants’ contention that the duty supporting misappropriation had to be owed directly to JPMorgan. Section 1839(5)(B)(ii)(II) addresses use of a trade secret by a person who knew or had reason to know that the secret was acquired under circumstances giving rise to a duty to maintain secrecy or limit use. The court read that language according to its terms and held that the statute does not require the relevant duty to run specifically to the trade-secret plaintiff. Argus’s alleged contractual obligations to the regulators not to use regulatory data in its commercial business could therefore support JPMorgan’s DTSA theory even though JPMorgan was not the promisee of those restrictions.

That is a potentially important point for technology and data ecosystems involving intermediaries. Confidential information often passes through processors, vendors, regulators, consultants, or platform providers subject to restrictions imposed by someone other than the eventual trade-secret plaintiff. The 2025 opinion suggests, at least at the pleading stage, that such a use restriction may matter under the DTSA if the defendant knew the information was subject to a duty to maintain secrecy or limit use.

Regulatory Submission Did Not Necessarily Transfer Away JPMorgan’s Trade-Secret Rights

The 2025 opinion also addressed a difficult ownership question that the August 2026 order largely assumes rather than revisits. Defendants argued that JPMorgan could not sue as an “owner” under 18 U.S.C. § 1836(b)(1) because federal contracts and banking regulations gave the regulators ownership rights in the information submitted through Argus.

Judge Bibas rejected that argument. He read Argus’s government contracts as allocating rights between Argus and the regulators, not as transferring JPMorgan’s preexisting rights to the government. Because the defendants did not contend that JPMorgan had transferred its ownership rights to Argus, the court reasoned that Argus could not transfer rights it did not possess. The opinion similarly interpreted Federal Reserve and OCC regulations describing certain information as government “property” as protecting the regulators’ control over access and disclosure, not as extinguishing a bank’s intellectual-property interests in information the bank created and submitted.

The practical significance is broader than banking regulation. Companies in heavily regulated sectors routinely disclose proprietary information to regulators, certification bodies, testing organizations, and other government contractors. The opinion does not establish that regulatory submission can never affect trade-secret rights, and its analysis depended on the particular contracts and regulations before the court. But it rejects the assumption that submitting confidential data into a regulatory process automatically transfers away every private right needed to maintain a DTSA claim.

The court also declined to carve pre-2016 conduct out of the case at the motion-to-dismiss stage. The DTSA applies only to misappropriation occurring on or after May 11, 2016, but JPMorgan alleged continued misuse after that date. Determining when particular data were first used, whether use continued, and whether pre-2016 data persisted in later products required factual development. The court therefore left those temporal questions for a later stage.

The Delaware Claim Failed in 2025 Because the Complaint Did Not Locate the Misappropriation in Delaware

The federal claim survived, but the Delaware claim did not. In the same February 2025 opinion, Judge Bibas concluded that DUTSA does not reach conduct occurring outside Delaware absent a sufficient basis for extraterritorial application. JPMorgan had alleged several Delaware connections: the parties were incorporated there, JPMorgan operated aspects of its credit-card business there, its employees allegedly prepared and transmitted information from Delaware, and Argus sold benchmarking studies to Delaware companies. But the complaint did not allege that defendants actually used or disclosed the asserted trade secrets in Delaware.

The court therefore dismissed the DUTSA claim without prejudice and gave JPMorgan a specific path to amendment: it could plead facts bringing the alleged conduct within DUTSA or identify another state law that reached the defendants’ conduct. That procedural history makes the August 2026 dismissal more consequential. The later opinion was not the court’s first encounter with an underdeveloped geographic theory; it was the result of JPMorgan’s second attempt to solve a defect the court had already identified.

The 2026 Opinion Draws a Line Between Trade-Secret Use and Downstream Sales

JPMorgan’s amended complaint added more geographic detail and asserted DUTSA or, alternatively, the Ohio Uniform Trade Secrets Act. But the additional allegations again focused on customers and commercial contacts. JPMorgan alleged that Argus and Verisk sold products to entities incorporated, headquartered, or doing business in Delaware and Ohio.

Judge Bibas held that those allegations did not identify the location of the misappropriation. Relying in part on Montway LLC v. Navi Transport Services LLC, 809 F. Supp. 3d 200, 213 (D. Del. 2025), he distinguished the allegedly wrongful use of the information from later transactions involving products created from that information. On JPMorgan’s own theory, the relevant use occurred when defendants allegedly incorporated its data into the Flash Reports and benchmarking studies. The amended complaint still did not allege that this product-development activity occurred in Delaware or Ohio.

That distinction has obvious importance for software, AI, and data cases. A product may be licensed to a Delaware corporation, an analytics service may generate revenue from customers in Ohio, or an AI system may deliver outputs across the country. Those market contacts do not necessarily answer where source code, training data, models, customer information, or other asserted trade secrets were actually used. A plaintiff invoking a territorial state statute may need facts about the operational process itself, not simply where the resulting product was sold.

The Court Reconsidered Its Earlier Reading of J.E. Rhoads

The August opinion also refined the court’s own earlier reasoning. In 2025, Judge Bibas had described J.E. Rhoads & Sons, Inc. v. Ammeraal, Inc., 1988 WL 116423 (Del. Super. Ct. Oct. 21, 1988), as a possible exception in which Delaware law had been applied to misappropriating acts scattered across the country. On reconsideration, he concluded that J.E. Rhoads was better understood as a choice-of-law decision rather than an extraterritoriality decision.

That correction sharpens the article’s central doctrinal point. Choice of law asks which jurisdiction’s law governs a dispute. Statutory territorial reach asks what conduct the selected statute regulates. Citing Cruz v. Chesapeake Shipping, Inc., 932 F.2d 218, 224 (3d Cir. 1991), the court explained that deciding Delaware law governs does not itself establish that DUTSA reaches conduct occurring outside Delaware.

The distinction is particularly important in technology contracts because parties and courts often devote substantial attention to governing law. A choice-of-law analysis may identify Delaware law as the applicable body of law, but a statutory claim can still fail if the particular Delaware statute does not reach the conduct alleged. The August opinion did not decide the effect of a contractual choice-of-law clause, so it should not be read as announcing a rule about such clauses. Its narrower point is that governing law and statutory geographic reach are separate inquiries.

Ohio Law Did Not Cure the Same Geographic Defect

JPMorgan encountered the same problem under Ohio law. Because the amended complaint did not allege an operative use in Ohio, JPMorgan argued that OUTSA itself could reach out-of-state conduct. Its principal authority was AtriCure, Inc. v. Jian Meng, 842 F. App’x 974 (6th Cir. 2021), a nonprecedential Sixth Circuit decision upholding an injunction under OUTSA that restricted conduct beyond Ohio.

Judge Bibas distinguished the territorial reach of a remedy from the territorial reach of liability. AtriCure addressed how broadly a court could frame injunctive relief once OUTSA applied. It did not squarely decide whether OUTSA creates liability for the domestic, out-of-state conduct alleged in JPMorgan’s case. The August opinion also relied on Harris v. Vision Energy, LLC, 250 N.E.3d 208, 217–18 (Ohio Ct. App. 2024), as evidence that Ohio courts apply a presumption against extraterritorial application absent a clear legislative signal.

The court therefore declined to extend OUTSA to the pleaded conduct. That conclusion should be stated narrowly. Judge Bibas was predicting Ohio law as a federal judge, and the decision does not bind Ohio appellate courts. Nor did he reject AtriCure’s conclusion that effective injunctive relief may sometimes extend across geographic borders. The point was that remedial scope does not answer whether the statute creates liability for the underlying conduct in the first place.

A Separate 2025 Discovery Opinion Addressed Settlement Communications

The case also produced a separate published discovery opinion in October 2025, reported at 802 F. Supp. 3d 733. During discovery, Argus produced and then sought to claw back a communication related to compromise discussions with the government. JPMorgan moved to compel production.

Judge Bibas held that Federal Rule of Evidence 408 limits the admissibility of settlement-related evidence for specified purposes but does not itself impose a heightened discovery standard. Because the defendants did not claim attorney-client privilege, work-product protection, or another recognized discovery protection, the court applied the ordinary relevance and proportionality standard of Rule 26 and denied the clawback.

That ruling is not part of the territorial trade-secret analysis and should not be conflated with the merits decisions. It is nevertheless relevant procedural context because the underlying dispute involves alleged misuse of data subject to government contracts and a prior government enforcement resolution. For litigants in similar cases, it is a reminder that communications connected to regulatory or settlement activity are not automatically insulated from civil discovery merely because Rule 408 may later limit their admissibility.

The Combined Opinions Put Operational Data Governance at the Center of Trade-Secret Litigation

Taken together, the rulings show why operational facts can matter as much as formal legal relationships in multistate data disputes. Ownership turns on what rights a data provider actually transferred. Misappropriation can turn on restrictions attached to the data even when those restrictions arise from a third-party relationship. Territoriality turns on where the allegedly wrongful use occurred. And the DTSA’s effective date can require tracing whether information supplied before 2016 remained embedded in products or continued to be used afterward.

For data providers, that makes data lineage and rights documentation strategically important. A company that sends proprietary information to regulators or intermediaries should understand what rights are being granted, what rights are retained, what downstream uses are permitted, and what confidentiality restrictions bind each participant. Where litigation is foreseeable, records showing how information moved through the system may become relevant not only to secrecy and use, but also to ownership, timing, and territorial reach.

For recipients and processors, the allegations illustrate the value of operational segregation. When the same organization receives restricted data for one purpose and operates a commercial analytics or product-development business that could benefit from the same data, access controls, dataset separation, documented permitted-use rules, and auditable processing workflows can help establish whether the two streams actually crossed. JPMorgan does not hold that any particular control is legally required, but the litigation shows why such evidence can become central.

For litigators, the case counsels against treating federal and state trade-secret claims as interchangeable. The federal DTSA claim survived a series of ownership, duty, and timing challenges, while the state claims failed because of geographic limitations. That divergence is not merely procedural. It reflects materially different statutory questions that should be investigated before a complaint is filed and tested separately on a motion to dismiss.

Dismissal With Prejudice Shows the Cost of Solving the Wrong Pleading Problem

The August 2026 opinion ultimately denied JPMorgan another opportunity to amend. The court had already told JPMorgan in 2025 that it needed either a state statute reaching the alleged conduct or facts bringing the conduct within DUTSA. When JPMorgan amended, it stated that it did not believe further factual allegations were necessary. The amended complaint then added more downstream corporate and customer contacts without locating the operative use in Delaware or Ohio.

The result is a practical pleading lesson. Once a court identifies the location of the alleged misappropriation as the defect, allegations about incorporation, headquarters, customers, revenue, or market effects may not cure it. The amendment must address the act the statute treats as misappropriation. In data-intensive cases, that may require counsel to understand the technical and organizational workflow earlier than conventional pleading practice might otherwise demand.

Key Takeaways

  • The February 2025 and August 2026 opinions should be read together. The first preserved JPMorgan’s DTSA theory while dismissing DUTSA without prejudice; the second dismissed the repleaded Delaware and Ohio theories with prejudice.
  • Regulatory submission does not necessarily extinguish private trade-secret ownership. On the pleadings before it, the court held that government contracts and banking regulations did not transfer away all of JPMorgan’s rights in the underlying data.
  • Under the court’s reading of the DTSA, the duty supporting misappropriation need not necessarily be owed directly to the trade-secret plaintiff. A use restriction arising from Argus’s regulatory contracts could support JPMorgan’s federal claim.
  • Customer sales are not necessarily trade-secret use. The court treated preparation of the accused analytics products as the alleged use and rejected later sales and corporate contacts as insufficient to place that use in Delaware or Ohio.
  • Choice of law, statutory territorial reach, and remedial reach are distinct. Selecting Delaware law does not itself make DUTSA extraterritorial, and an injunction capable of regulating out-of-state conduct does not necessarily establish that the underlying statute creates liability for wholly out-of-state conduct.
  • The precedential scope remains limited. These are District of Delaware rulings at the pleading and discovery stages. They do not establish that JPMorgan ultimately owns protectable trade secrets, that defendants misappropriated them, or that Delaware and Ohio appellate courts would adopt every aspect of the territorial analysis.

Related Analysis

  • Motorola v. Hytera provides the strongest federal-law contrast, addressing the DTSA’s extraterritorial reach and showing why federal and state territorial analyses should not be collapsed.
  • Citibank v. Mitchell addresses what can constitute “use” of a trade secret and provides a useful comparison to JPMorgan’s focus on the location of the operative use rather than possession or downstream sales.
  • Coda Development v. Goodyear analyzes Ohio trade-secret law and the evidentiary requirement to prove actual use, making it a useful companion to JPMorgan’s OUTSA discussion.
  • Insulet v. EOFlow addresses a different DTSA threshold issue, claim accrual and timeliness, and reinforces the need to analyze parallel trade-secret theories under the requirements of the particular statute involved.

By Charles Gideon Korrell