What Is an NDA?
A non-disclosure agreement (NDA) — also called a confidentiality agreement — is a contract that creates a legal obligation to keep certain information private. It prevents the receiving party from disclosing or misusing information shared by the disclosing party.
NDAs are commonly used in the following situations:
- Sharing business plans, financial data, or trade secrets with potential investors or partners
- Onboarding employees or contractors who will access proprietary information
- Entering merger, acquisition, or due diligence discussions
- Engaging vendors or service providers who handle sensitive data
- Licensing technology or intellectual property
An NDA creates a legal duty to protect confidential information. It can apply to employees, vendors, customers, contractors, or business partners. Without one, the disclosing party may have limited legal recourse if sensitive information is shared without permission.
What Should an NDA Include?
Most NDAs include the following core elements:
- Identification of the parties
- Definition of confidential information
- Permitted purpose and use restrictions
- Exclusions from confidentiality
- Confidentiality obligations of the receiving party
- Term and duration
- Survival period after termination
- Return or destruction of confidential information
- Remedies for breach
- Governing law and dispute resolution
Each element plays a specific role in making the agreement enforceable and practical. Missing or vague clauses are a common source of disputes. For a shorter reference point, see Five Things to Look for in an NDA.
10 Essential NDA Clauses
1. Identification of the Parties
What it does: Names every party bound by the agreement.
Why it matters: If a party is not named, they are not legally bound. Ambiguity about affiliates, subsidiaries, or related entities can create enforcement gaps.
What to check: Confirm full legal names and entity types. Clarify whether the agreement extends to affiliates, parent companies, or third-party subcontractors. This is also a core contract drafting issue covered in broader business agreement guidance such as 6 Tips to effectively write business contract agreements.
2. Definition of Confidential Information
What it does: Identifies what information the NDA protects.
Why it matters: If the definition is too vague, it may be unenforceable. If it is too broad, it may capture information that should not be restricted.
What to check: Look for specific examples of protected information. Confirm that standard carve-outs exist for information that is already public, previously known, independently developed, or disclosed under legal compulsion. For more on drafting this section carefully, see Five Things to Look for in an NDA.
3. Permitted Purpose
What it does: Limits how the receiving party may use the confidential information.
Why it matters: Without a defined purpose, the receiving party may argue they were entitled to use the information in ways the disclosing party never intended.
What to check: The permitted purpose should be narrow and specific. Broad language like "internal business purposes" without further definition is a common weakness. This distinction also matters when deciding between an NDA and a confidentiality agreement.
4. Exclusions from Confidentiality
What it does: Lists the types of information that are not subject to the confidentiality obligation.
Why it matters: Standard exclusions protect the receiving party from obligations that would be unreasonable or unenforceable.
What to check: Most NDAs include exclusions for information that is:
- Already in the public domain at the time of disclosure
- Already known to the receiving party before disclosure
- Independently developed by the receiving party without use of the disclosed information
- Disclosed under a court order or legal requirement (with notice to the disclosing party where permitted)
For a clause-level breakdown of these carve-outs, see What is a Unilateral NDA? + Free Template.
5. Confidentiality Obligations
What it does: Describes what the receiving party must do to protect the information.
Why it matters: Vague obligations are difficult to enforce. Specific duties create a clear standard of care.
What to check: Look for requirements to use at least the same level of care as the party uses for its own confidential information, and no less than a reasonable standard of care. Confirm whether the receiving party can share information with employees or advisors, and under what conditions. Related contract confidentiality standards are also discussed in The Complete List Of Standard Clauses To Check Before Signing A Contract.
6. Term of the Agreement
What it does: Sets the start and end date of the NDA.
Why it matters: An agreement with no end date may be unenforceable in some jurisdictions. An agreement with too short a term may not protect information long enough to matter.
What to check: Confirm the agreement has a clear start date and a defined end date. Note whether the term refers to the duration of the relationship or the period of confidentiality obligations.
7. Survival Period
What it does: Specifies how long confidentiality obligations continue after the agreement ends or the relationship terminates.
Why it matters: Many NDAs end before the information loses its sensitivity. A survival clause extends protection beyond the formal agreement term.
What to check: Confirm that the survival period is explicitly stated. For trade secrets, some agreements include indefinite protection as long as the information qualifies as a trade secret under applicable law. Additional guidance on confidentiality periods appears in Five Things to Look for in an NDA.
8. Return or Destruction of Confidential Information
What it does: Requires the receiving party to return or destroy confidential information when the agreement ends or upon request.
Why it matters: Without this clause, the receiving party may retain sensitive information indefinitely after the relationship ends.
What to check: Look for a clear process, a defined timeline, and a certification requirement confirming that destruction has occurred. Consider whether cloud storage, backups, and derivative works are addressed. Broader data handling considerations are also relevant in In-House Legal Guide to Safeguarding Company Data.
9. Remedies for Breach
What it does: Describes the legal remedies available if the NDA is violated.
Why it matters: Without a remedies clause, the non-breaching party must rely entirely on general contract law, which may not provide fast or adequate relief.
What to check: Most NDAs include the right to seek an injunction — a court order requiring the receiving party to stop disclosing information — in addition to monetary damages. Confirm whether the agreement includes liquidated damages (a pre-agreed sum for breach) and whether those amounts are reasonable and likely enforceable. For related guidance, see What Happens if you Break an NDA? and How to Handle and Resolve Breach of Contracts.
10. Governing Law and Dispute Resolution
What it does: Specifies which jurisdiction's law applies and how disputes will be resolved.
Why it matters: Governing law determines which rules apply to interpretation and enforcement. Dispute resolution terms determine whether parties go to court, arbitration, or mediation.
What to check: Confirm the governing law is stated clearly. Note whether disputes must go to arbitration (which is private and typically faster) or litigation (which is public and can be slower). Check whether the jurisdiction is convenient and reasonable for both parties. For more context, see 4 Basic Contract Terms & Conditions And How To Write Them and How to Resolve Contract Disputes.
Mutual vs. Unilateral vs. Multilateral NDAs
Not all NDAs work the same way. The structure depends on how many parties are sharing information.
Key consideration: A mutual NDA is appropriate when both parties will share sensitive information. Using a unilateral NDA when both parties are disclosing creates an imbalance and may leave one party unprotected.
If you need deeper guidance on choosing structure, see What is Mutual NDA? Everything you need to know and What is a Unilateral NDA? + Free Template.
11 Questions to Ask Before Signing an NDA
1. Who are the parties, and are affiliates included?
Short answer: Confirm full legal names and whether the agreement binds or protects related entities.
Why it matters: Undefined affiliate coverage can create gaps in protection or unexpected obligations.
Red flag: Broad affiliate inclusion on one side only, with no reciprocal coverage.
2. What exactly qualifies as confidential information?
Short answer: The definition should be specific, with examples, not a catch-all.
Why it matters: Vague definitions are difficult to enforce and may cover information that should be freely usable.
Red flag: "All information disclosed" with no carve-outs or examples.
3. What is the permitted purpose?
Short answer: The NDA should state exactly why the information is being shared and how it may be used.
Why it matters: Without a defined purpose, the receiving party has limited guidance and the disclosing party has limited protection.
Red flag: No use restriction, or a purpose so broad it is effectively unlimited.
4. Are the standard exclusions present?
Short answer: Confirm that information already public, previously known, independently developed, or legally compelled to disclose is excluded.
Why it matters: Without exclusions, the receiving party may be bound to protect information it already knew or that is publicly available.
Red flag: No exclusions at all, or exclusions that require the receiving party to prove the exception in writing before it applies.
5. How long does the agreement last?
Short answer: Check for a defined start date, end date, and survival period.
Why it matters: Indefinite NDAs may be unenforceable in some jurisdictions. Agreements that are too short may not protect information long enough.
Red flag: No end date, or a survival period that does not match the sensitivity of the information.
6. What are the return or destruction obligations?
Short answer: Confirm what must be returned or deleted, when, and how compliance must be confirmed.
Why it matters: Retaining confidential information after the relationship ends creates ongoing risk for both parties.
Red flag: No return or destruction clause, or requirements that are technically impossible to fulfill (for example, requiring deletion of all backup copies with no reasonable carve-out).
7. What remedies apply if the NDA is breached?
Short answer: Check whether the agreement allows injunctive relief and damages, and whether any liquidated damages amounts are reasonable.
Why it matters: Disproportionate penalties may be unenforceable. Weak remedies may not deter or compensate for a breach.
Red flag: Extreme one-sided penalties, or no remedy clause at all.
8. Which law governs the agreement?
Short answer: Confirm the governing law and whether it is reasonable for both parties.
Why it matters: Governing law affects interpretation, enforceability, and available remedies.
Red flag: Governing law of a jurisdiction with no connection to either party, or a jurisdiction that provides significantly weaker protection for one side.
9. Where must disputes be resolved?
Short answer: Confirm whether disputes go to court, arbitration, or mediation, and in which location.
Why it matters: A dispute resolution clause that requires one party to litigate in a distant jurisdiction creates practical and financial barriers to enforcement.
Red flag: Mandatory arbitration in a location that is unreasonably inconvenient for one party, or no dispute resolution clause at all.
10. Does the NDA include a non-compete or non-solicit clause?
Short answer: Check carefully for restrictions on hiring, competing, or soliciting customers that go beyond confidentiality.
Why it matters: Non-compete and non-solicit clauses are subject to different enforceability standards and are heavily restricted or unenforceable in some jurisdictions.
Red flag: Non-compete language embedded in a document presented as a simple NDA, without clear disclosure.
11. Is the agreement mutual or one-sided?
Short answer: Confirm whether both parties have the same obligations, or whether only one party bears the burden.
Why it matters: If both parties are sharing sensitive information, a unilateral NDA leaves one party unprotected.
Red flag: Obligations that apply only to one party in a situation where both parties are disclosing.
For a practical pre-signing walkthrough, also see How to Sign an NDA? (Best Practices + Tools).
For a broader clause-risk lens, review The Complete List Of Standard Clauses To Check Before Signing A Contract.
NDA Review Checklist
Use this checklist when reviewing any NDA before signing or sending for signature.

