When Does Competitive Intelligence Become Corporate Espionage? Lessons from Uber and GoCatch

What the Surfcam dispute and subsequent court findings reveal about data provenance, breach of confidence and corporate investigation readiness

PUBLISHED: 31 August 2026   |   CATEGORY: Analysis and Briefings

A governance and investigation framework for boards, legal teams, risk leaders and corporate intelligence functions.

Competitive intelligence becomes difficult to defend when an organisation cannot give a credible account of where competitor information came from, who authorised its collection, how it was obtained, what use was permitted and which records support that account. The Uber–GoCatch litigation shows why that provenance matters. A court may reject one pleaded cause of action while still condemning particular conduct or finding a separate breach.

The practical lesson is not that businesses should stop analysing competitors. It is that collection methods need the same governance as any other activity involving sensitive information, automated tools, external investigators or access to another organisation’s systems. “Competitive intelligence” is a business purpose, not a legal authority.

Why the Story Changed After the Original Report

NSI Global’s original 2024 report covered allegations made during proceedings brought by Taxi Apps Pty Ltd, the operator of GoCatch, against companies in the Uber group. At that stage, the trial had begun but the court had not decided the case. Contemporary reporting said Taxi Apps accused Uber of corporate espionage, hacking competitor systems and using a tool known as Surfcam to obtain driver data. Uber disputed the central claim that its conduct caused GoCatch’s loss.

The Supreme Court of Victoria delivered judgment on 25 August 2025 in Taxi Apps Pty Ltd v Uber Technologies Inc & Ors [2025] VSC 514. That decision makes a simple allegation-led update inadequate. A defensible account must now distinguish between what Taxi Apps alleged, what Uber admitted, what the court found and what Taxi Apps failed to prove.

The result was mixed in a way that matters for corporate risk teams:

  1. Taxi Apps did not establish its conspiracy-by-unlawful-means claim.
  2. The court found the required intention to harm in relation to Uber’s operation in New South Wales, but not in Victoria, Queensland or Western Australia.
  3. The statutory licensing breaches relied on by Taxi Apps did not constitute “unlawful means” for this tort in the required legal sense.
  4. Separately, the court found that Uber Australia breached a duty of confidence when it surreptitiously obtained a list of Taxi Apps drivers.
  5. The court described that confined incident as wrong and unconscionable and marked its disapproval, even though it did not grant the declaration sought.

These findings do not support either extreme narrative. It would be inaccurate to say that the conspiracy allegation succeeded. It would be equally misleading to present dismissal of that claim as judicial approval of every collection practice examined in the proceeding.

What the Court’s Decision Actually Means

An unsuccessful conspiracy claim does not answer every question about how a business obtained or used competitor information. The tort required Taxi Apps to prove a particular combination of agreement, unlawful conduct, intention and causation. Failure on those elements determined that cause of action; it did not make the underlying history disappear.

Legal analysis of the judgment records that the Uber entities admitted knowing unlawful conduct associated with the early operation of UberX. The court nevertheless found that the elements of the conspiracy tort were not made out. In particular, statutory unlawfulness is not automatically “unlawful means” for a private conspiracy action. Whether it qualifies depends on the legislation and the remedies Parliament intended.

The breach-of-confidence finding is therefore important. It shows why an organisation should assess the provenance and use of each dataset, rather than assuming that success against a broad allegation resolves every narrower issue. Confidential information can create exposure even where another theory of liability fails.

This article provides governance and investigative guidance, not legal advice. The legal effect of competitor-data collection depends on the facts, jurisdiction, access controls, contracts, privacy obligations, representations made during collection and the nature of the information.

Was Surfcam Really Spyware?

The label should be used carefully. Contemporary reports and the parties’ arguments described Surfcam as spyware, and the term became central to the public story. That reporting can be described accurately as an allegation or characterisation. It should not be converted into an unqualified technical finding.

Authoritative cyber-security glossaries generally use “spyware” to mean software installed on a system or device to collect information without the user’s knowledge or consent. The public material reviewed for this article does not establish that Surfcam was installed on GoCatch systems or devices as malware. Reporting instead described a purpose-built tool that obtained or analysed information made available through competitor services or customer-facing interfaces.

That distinction does not decide whether the collection was lawful, fair or commercially acceptable. Automated scraping, querying or extraction can still engage confidentiality, privacy, contract, access-control and computer-offence issues. It simply means that “spyware”, “scraping”, “unauthorised access” and “breach of confidence” are not interchangeable descriptions.

The same discipline applies to the word “hacking”. Section 478.1 of the Criminal Code Act 1995 (Cth), for example, addresses intentional and knowing unauthorised access to or modification of restricted data, with “restricted data” defined by reference to an access-control system. It does not follow that every automated collection from an online service satisfies those elements. The access path and the collector’s authority have to be established.

The Provenance Test for Competitive Intelligence

Before competitor information is collected, purchased, enriched, shared or used, the commissioning organisation should be able to answer five linked questions.

1. What Is the Source?

“Online”, “open source” and “provided by a consultant” are not sufficient provenance. The record should identify the original platform, document, person, database or observation and the date on which the information was obtained.

Public visibility is relevant, but it is not universal permission. The Office of the Australian Information Commissioner states that publicly available personal information must still be collected consistently with the Australian Privacy Principles where they apply. APP 3 requires collection to be reasonably necessary, lawful and fair; the OAIC also emphasises data minimisation.

2. What Authority Permitted Collection?

Authority may arise from genuine public access, an appropriate licence, contractual permission, consent or another valid legal basis. It should not be inferred from technical possibility alone. A system accepting a request does not necessarily mean the requester is entitled to make it.

The commissioning brief should expressly prohibit credential misuse, impersonation, deception, evasion of access controls and collection beyond the approved purpose. If a supplier proposes a method that relies on “everyone does it”, secrecy from the client’s legal team or the absence of an express technical block, the work should pause for review.

3. How Was the Information Obtained?

The method determines much of the risk. Manual review of a public tariff differs from automated collection at scale. A licensed dataset differs from a file supplied by an employee of a competitor. Information visible to a normal customer differs from data extracted by manipulating a private interface or using credentials not issued for that purpose.

Organisations should document the tools, accounts, queries, rate, time period and transformations used. That record allows legal, privacy, security and audit teams to test the method rather than relying on a reassuring label.

4. What Use Is Permitted?

Lawful acquisition does not make every secondary use permissible. A dataset obtained for market analysis may contain personal information, commercially sensitive material or fields irrelevant to the approved question. APP 6, where applicable, limits use or disclosure of personal information outside its primary purpose unless an exception applies.

Purpose limitation should be operational: allow only the people, fields, duration and outputs required for the approved decision. Suppress or delete information that is not needed. A competitor’s employees or contractors should not become recruitment targets merely because their details appear in a broader dataset.

5. What Record Supports the Account?

A programme is difficult to defend if its authority exists only in memory. Retain the written brief, legal and privacy review, source register, supplier due diligence, approved method, access logs, collection dates, quality checks, permitted outputs and deletion decision.

The purpose of this record is not to manufacture legitimacy after the event. It is to ensure that decision-makers can test the collection before it begins and reconstruct it if challenged.

Governance question Evidence of a controlled practice Escalation trigger
Source Named original source, acquisition date and owner “Open source” or “consultant data” with no traceable origin
Authority Licence, consent, public-access rationale or documented legal basis Method depends on borrowed credentials, false identity or ignored restrictions
Method Approved tool, account, query, scale and collection window Access-control testing, interface manipulation or unexplained automation
Personal information Necessity, fairness, minimisation and privacy review recorded Bulk contact details unrelated to the approved intelligence question
Use Defined purpose, users, outputs and retention period Recruitment, targeting or disclosure beyond the commissioned purpose
External provider Capability, method, subcontractor and data-handling checks Provider will not reveal sources or document collection steps
Accountability Review decision, logs and disposal record retained Instructions move to private channels or records are intentionally avoided

 

Red Flags That the Boundary Is Being Crossed

A single indicator does not determine liability, but the following conditions warrant immediate review:

  1. A team is asked not to involve legal, privacy, compliance or information-security personnel.
  2. The proposed method depends on concealing identity, affiliation or the purpose of access.
  3. A tool is described by outcome only, with no explanation of its data source or collection path.
  4. The supplier refuses to identify subcontractors or original sources.
  5. Credentials, tokens, test accounts or accounts belonging to another person are used outside their authorised purpose.
  6. Collection continues after a platform owner restricts access, revokes permission or raises an objection.
  7. Personal contact information is captured when the approved question concerns pricing, coverage or market position.
  8. Messages celebrate the method’s deniability or recommend avoiding formal records.
  9. Data is moved to personal devices, unapproved cloud services or disappearing-message channels.
  10. Executives receive conclusions without source confidence, collection limitations or an audit trail.

These are governance warnings because they affect both the conduct and the organisation’s ability to understand it. A board cannot exercise oversight over a programme whose true collection method is hidden behind a vendor or internal nickname.

If Improper Collection Is Suspected

The first response should preserve options. Do not ask employees to delete tools, “clean up” messages or recreate missing approvals. Do not contact a suspected competitor, provider or individual before legal and investigative leads have considered evidence preservation, privilege, notification duties and the risk of tipping off relevant parties.

A proportionate initial response may include:

  1. Establish governance. Appoint an authorised decision-maker and obtain legal advice on privilege, employment issues, regulatory obligations and the permitted investigation scope.
  2. Stabilise the activity. Suspend the disputed collection without destroying data, code, accounts or logs. Restrict further use and disclosure of the information.
  3. Preserve relevant evidence. Identify source code, scripts, repositories, cloud and application logs, access tokens, device artefacts, emails, chat records, approvals, contracts, invoices, data exports and deletion settings. Preservation should be targeted and documented.
  4. Map the data flow. Determine what was collected, from where, by whom, using which identity or account, where it was stored, who received it and how it informed business decisions.
  5. Test competing explanations. Distinguish public collection, licensed access, employee disclosure, vendor activity, configuration error, credential misuse and deliberate access-control evasion. Do not force the evidence into a preferred narrative.
  6. Assess continuing exposure. Consider whether personal information, confidential information, contractual restrictions, regulator engagement, litigation holds or third-party notification are involved.
  7. Record limitations. State what evidence was unavailable, overwritten, outside jurisdiction or beyond the commissioned period. An investigation should not turn an incomplete record into a definitive attribution.

The Australian Signals Directorate recommends that incident-response plans be tailored to an organisation’s environment, priorities, resources and obligations. It also emphasises event logging and forensic visibility. Those controls matter here because a competitor-intelligence dispute may begin as a legal or conduct concern and develop into a digital-forensics question.

Scope the Investigation Around the Collection Path

The appropriate response is rarely a generic “spyware check”. The investigation should follow the credible pathways by which the information could have been obtained and used.

Corporate investigators can examine decision-making, relationships, authorisation, vendor activity and witness accounts. Digital-forensics specialists can preserve and analyse relevant devices, accounts, code, logs and data transfers within an agreed lawful scope. Legal counsel should direct legal issues and determine how privilege is managed.

A technical surveillance countermeasures survey may be relevant if there are specific indicators of physical eavesdropping, covert devices or compromised meeting environments. It is not a substitute for reviewing software, access records and data provenance. NSI Global’s separate analysis of the Woolworths espionage allegation addresses meeting access and explains this distinction. Matters spanning several disciplines should be commissioned according to the risk pathways, as outlined in Beyond the Scope of a Private Investigator.

The aim is a decision-useful factual record: what happened, what can be supported, what remains uncertain and which controls should change. No investigation can guarantee complete recovery, definitive attribution or a litigation outcome.

Questions for Boards and Executives

  1. Can management identify every source used in current competitor-intelligence reporting?
  2. Who approves automated collection, and what legal, privacy and security review occurs first?
  3. Do external providers disclose their original sources, tools, subcontractors and collection methods?
  4. Which controls prevent the use of another person’s credentials, tokens or accounts?
  5. How is personal information excluded when it is not necessary to the intelligence question?
  6. Can the organisation stop collection quickly without destroying evidence?
  7. Are source records and access logs retained long enough to investigate a complaint?
  8. Who decides whether a concern requires legal review, corporate investigation or digital forensics?
  9. Does reporting distinguish verified facts, analyst inference and untested allegation?

If leadership cannot answer these questions, the weakness is not merely documentary. It means the organisation may be accepting competitor information without knowing whether it was collected within its authority or whether it can be defended under scrutiny.

Frequently Asked Questions

Is Competitive Intelligence Legal in Australia?

Competitive intelligence can involve lawful activities such as analysing public announcements, published prices, corporate records, market data and properly licensed sources. Legality depends on the information, method, authority and use. The term does not excuse deception, breach of confidence, privacy non-compliance, contractual breach or unauthorised system access.

Is Publicly Available Data Free to Use for Any Purpose?

No. Public availability is one consideration, not blanket permission. Privacy obligations may still apply to personal information, and contractual, confidentiality, intellectual-property or platform restrictions may also be relevant. Collect only what is necessary for a defined and reviewed purpose.

Is Web Scraping Illegal?

There is no universal answer. Risk depends on what is collected, whether access controls or credentials are involved, the representations made, applicable terms, scale, privacy obligations and the intended use. Organisations should obtain legal advice on the proposed method rather than treating technical accessibility as authority.

Why Should Surfcam Not Automatically Be Called Spyware?

The term usually describes code placed on a device or information system so it can gather activity or other information covertly. Public reporting characterised Surfcam as spyware, but the material reviewed for this article does not establish that technical installation. A precise account should identify the reported collection method without turning a contested label into a forensic conclusion.

What Should an Organisation Do If It Suspects Improper Competitor Monitoring?

Stop further collection in a way that preserves evidence, restrict use of the information, obtain legal advice and define a targeted investigation. Relevant records may include approvals, source registers, code, cloud and application logs, messages, contracts, access tokens and data exports. Avoid premature attribution or broad internal searches without an authorised scope.

How NSI Global Can Assist

NSI Global supports organisations that need to determine how sensitive competitor information was obtained, whether an internal or external provider acted outside authority, and what evidence remains available. An engagement can combine corporate investigation and digital forensics where the facts justify both workstreams, with scope, limitations and reporting designed around the client’s legal, operational and reputational risk.

Contact NSI Global to discuss a confidential, appropriately scoped assessment. The initial objective is to identify the relevant collection pathways and preserve decision options—not to assume that a tool, employee, supplier or competitor is responsible before the evidence has been examined.

Sources and Further Reading

Supreme Court of Victoria judgment: Taxi Apps v Uber — 2025 VSC 514, 25 August 2025.

Robinson Gill analysis of the Taxi Apps–Uber conspiracy decision, reviewed 31 August 2026.

Conspiracy claim rejected after Uber flattened rival, Insurance News, 4 September 2025.

Uber ‘tech bros’ sought to destroy Australian taxi app using corporate espionage, court hears, Australian Associated Press via The Guardian, 2 April 2024.

Australian Privacy Principles and APP 3 collection guidance, Office of the Australian Information Commissioner, APP 3 guidance updated May 2026.

APP 6 use or disclosure guidance, Office of the Australian Information Commissioner.

Criminal Code Act 1995 (Cth), Part 10.7, Federal Register of Legislation, current version reviewed 31 August 2026.

Spyware definition, National Institute of Standards and Technology; and ASD cyber-security glossary, Australian Signals Directorate.

Cyber security incident response planning: practitioner guidance and best practices for event logging and threat detection, Australian Signals Directorate.

Secure your peace of mind