TL;DR
- A non-disclosure agreement is a contract that creates a legal obligation to keep specific information private, and it needs 10 core elements to be enforceable and practical.
- A standard NDA follows a predictable structure: parties, defined confidential information, permitted purpose, exclusions, obligations, term, survival period, return or destruction terms, remedies, and governing law.
- NDAs come in three structures, unilateral, mutual, and multilateral, depending on how many parties are actually sharing information.
- Common red flags include an overly broad definition of confidential information, no exclusions, no end date, hidden non-compete language, and one-sided remedies.
- Managing NDAs at scale needs standard templates, a defined approval workflow, and a searchable repository, not ad hoc handling for every new request.
A non-disclosure agreement (NDA), also called a confidentiality agreement, is a contract that creates a legal obligation to keep certain information private. It prevents the receiving party from disclosing or misusing information shared by the disclosing party.
An NDA creates a legal duty to protect confidential information. It can apply to employees, vendors, customers, contractors, or business partners. Without one, the disclosing party may have limited legal recourse if sensitive information is shared without permission.
What Does a Standard NDA Look Like?
Most NDAs follow the same basic structure, regardless of industry or purpose. If you've never drafted or reviewed one before, here's roughly what you're looking at:
- A preamble, naming the parties and the date
- A definition of confidential information, spelling out what's actually protected
- A permitted purpose clause, limiting how the receiving party can use what's shared
- Exclusions, carving out information that shouldn't need protecting
- Obligations, describing the standard of care the receiving party owes
- Term and survival period, how long the agreement runs and how long confidentiality lasts after it ends
- Return or destruction terms, what happens to the information when it's over
- Remedies, what the disclosing party can do if it's breached
- Governing law and, and signature blocks for every party
A well-drafted NDA rarely runs longer than two or three pages for a straightforward business relationship. If a draft you're reviewing runs much longer than that without a clear reason, like a highly technical scope of work attached as an exhibit, it's worth asking why.
10 Essential NDA Clauses
1. Identification of the Parties
What it does: Names every party bound by the agreement.
Why it matters: If a party is not named, they are not legally bound. Ambiguity about affiliates, subsidiaries, or related entities can create enforcement gaps.
What to check: Confirm full legal names and entity types. Clarify whether the agreement extends to affiliates, parent companies, or third-party subcontractors. This is also a core contract drafting issue covered in broader business agreement guidance such as 6 tips to effectively write business contract agreements.
2. Definition of Confidential Information
What it does: Identifies what information the NDA protects.
Why it matters: If the definition is too vague, it may be unenforceable. If it is too broad, it may capture information that should not be restricted.
What to check: Look for specific examples of protected information. Confirm that standard carve-outs exist for information that is already public, previously known, independently developed, or disclosed under legal compulsion.
3. Permitted Purpose
What it does: Limits how the receiving party may use the confidential information.
Why it matters: Without a defined purpose, the receiving party may argue they were entitled to use the information in ways the disclosing party never intended.
What to check: The permitted purpose should be narrow and specific. Broad language like "internal business purposes" without further definition is a common weakness. This distinction also matters when deciding between an NDA and a confidentiality agreement.
4. Exclusions from Confidentiality
What it does: Lists the types of information that are not subject to the confidentiality obligation.
Why it matters: Standard exclusions protect the receiving party from obligations that would be unreasonable or unenforceable.
What to check: Most NDAs include exclusions for information that is already in the public domain at the time of disclosure, already known to the receiving party before disclosure, independently developed without use of the disclosed information, or disclosed under a court order or legal requirement.
5. Confidentiality Obligations
What it does: Describes what the receiving party must do to protect the information.
Why it matters: Vague obligations are difficult to enforce. Specific duties create a clear standard of care.
What to check: Look for requirements to use at least the same level of care as the party uses for its own confidential information, and no less than a reasonable standard of care. Confirm whether the receiving party can share information with employees or advisors, and under what conditions. Related contract confidentiality standards are also discussed in the complete list of standard clauses to check before signing a contract.
6. Term of the Agreement
What it does: Sets the start and end date of the NDA.
Why it matters: An agreement with no end date may be unenforceable in some jurisdictions. An agreement with too short a term may not protect information long enough to matter.
What to check: Confirm the agreement has a clear start date and a defined end date. Note whether the term refers to the duration of the relationship or the period of confidentiality obligations.
7. Survival Period
What it does: Specifies how long confidentiality obligations continue after the agreement ends or the relationship terminates.
Why it matters: Many NDAs end before the information loses its sensitivity. A survival clause extends protection beyond the formal agreement term.
What to check: Confirm that the survival period is explicitly stated. For trade secrets, some agreements include indefinite protection as long as the information qualifies as a trade secret under applicable law.
8. Return or Destruction of Confidential Information
What it does: Requires the receiving party to return or destroy confidential information when the agreement ends or upon request.
Why it matters: Without this clause, the receiving party may retain sensitive information indefinitely after the relationship ends.
What to check: Look for a clear process, a defined timeline, and a certification requirement confirming that destruction has occurred. Consider whether cloud storage, backups, and derivative works are addressed. Broader data handling considerations are also relevant in our guide to safeguarding company data.
9. Remedies for Breach
What it does: Describes the legal remedies available if the NDA is violated.
Why it matters: Without a remedies clause, the non-breaching party must rely entirely on general contract law, which may not provide fast or adequate relief.
What to check: Most NDAs include the right to seek an injunction, a court order requiring the receiving party to stop disclosing information, in addition to monetary damages. Confirm whether the agreement includes liquidated damages and whether those amounts are reasonable and likely enforceable. For related guidance, see what happens if you break an NDA and how to resolve contract disputes.
10. Governing Law and Dispute Resolution
What it does: Specifies which jurisdiction's law applies and how disputes will be resolved.
Why it matters: Governing law determines which rules apply to interpretation and enforcement. Dispute resolution terms determine whether parties go to court, arbitration, or mediation.
What to check: Confirm the governing law is stated clearly. Note whether disputes must go to arbitration or litigation and whether the jurisdiction is reasonable for both parties. For more context, see 4 basic contract terms and conditions and how to write them.
Each element plays a specific role in making the agreement enforceable and practical. Missing or vague clauses are a common source of disputes. For a shorter reference point, see five things to look for in an NDA.
NDA Review Checklist
Use this checklist when reviewing any NDA before signing or sending for signature.
For related general review guidance, see how to review different types of contracts.
How to Manage NDAs Efficiently
Organizations that regularly send, receive, and negotiate NDAs benefit from a structured management approach. Ad hoc handling increases risk and creates unnecessary delays.
Use standard templates. Maintain approved NDA templates for common scenarios, employee onboarding, vendor engagement, partnership discussions, and investor meetings.
Build an approval workflow. Define who can approve NDAs at different risk levels. Low-risk, standard NDAs may not require legal review.
Redline and negotiate efficiently. Contract redlining tools track changes, compare versions, and communicate proposed edits clearly.
Manage signatures digitally. Electronic signature workflows eliminate printing and manual filing while creating a clear audit trail.
Store NDAs in a searchable repository. Centralized contract storage lets teams find active NDAs quickly, track expiry dates, and monitor survival periods.
Set renewal and expiry reminders. Automated reminders let teams review, renew, or formally terminate agreements before they lapse.
Conclusion
A well-drafted NDA does more than label information as confidential. It identifies the parties, defines what is protected, limits how information may be used, includes clear exclusions, sets realistic confidentiality and survival periods, addresses return or destruction obligations, and provides proportionate remedies if a breach occurs.
Before signing any NDA, review the scope of the confidentiality obligation, the duration and survival period, the remedies and dispute resolution terms, and any additional restrictions such as non-compete or non-solicit language that may be embedded in the agreement.
For teams managing NDAs at scale, standard templates, structured approval workflows, digital redlining, electronic signatures, and searchable contract repositories reduce review time, improve consistency, and lower the risk of agreements lapsing unnoticed.
SpotDraft brings NDA templates, review, signatures, and storage into one platform. Book a demo to see it work.
Frequently Asked Questions
What is an NDA?
What types of information are protected by an NDA?
Who needs to sign an NDA?
When do NDAs expire?
What's the difference between an NDA and a confidentiality agreement?
What makes an NDA unenforceable?
What is the difference between a confidentiality clause and a non-compete clause?
Related content

