The non-disclosure agreement (“NDA”) is the contract most companies sign fastest and read least. It shows up early, it is short, someone calls it standard, and it gets signed so the real negotiation can start. Then, unless you have overriding confidentiality provisions in a later definitive agreement, it governs your business’s confidential information for the next three to five years.
The takeaway: an NDA is a real contract with real teeth, and about nine provisions in it do all of the work. This discussion covers those nine common provisions at a high level, and each one gets its own post later in this series.
NDAs come in one of two formats, unidirectional or bidirectional. While it is not unusual to have a vendor or customer provide you with their unidirectional NDA template, I recommend against using such a one-direction NDA unless your business will be disclosing absolutely no confidential information. NDAs in technology and SaaS deals tend to be mutual (bidirectional), as both sides disclose and both sides receive. Every position you take against the other side’s confidential information gets taken against yours, which is why you must stay aware of what restrictions and obligations you are placing on the other party as they are also being placed upon you.
1. What Counts as Confidential Information
Two drafting approaches, failing in opposite directions. A marking requirement protects only what is marked as confidential, which is clean on paper and problematic in practice, because people forget to mark a Slack message, a screen share, or a whiteboard photo as confidential. Conversely, a catch-all definition covers anything a reasonable person would understand to be confidential from its nature and the circumstances of disclosure, which protects the discloser and leaves the recipient with no reliable way to know what is restricted.
2. The Exclusions
Four carve-outs are standard: information already publicly available through no fault of the recipient, information the recipient already knew free of any duty, information from a third party free of any duty, and information independently developed without use of or reference to what was disclosed. The negotiation is rarely about whether these are present in the NDA. It is about which party carries the burden of proving one of the exclusions, and whether the words “or reference to” survive in the independent-development carve-out.
Compelled disclosure is where I part company with a lot of forms. A subpoena or regulatory demand often gets drafted as a fifth exclusion, which strips the information of protection the moment a court asks for it. This topic belongs in its own provision as a permitted disclosure: prompt notice where notice is lawful, cooperation in seeking protective treatment, and no more disclosed than the law requires.
3. The Permitted Purpose
“Solely to evaluate a potential business relationship between the parties” is one line, and the entire use restriction hangs on it. Draft it too narrowly and your ordinary operations breach the agreement. Draft it too broadly and it’s near unenforceable and useless.
This clause could matter more than the definition of confidential information and gets a fraction of the attention. The part that is missed by many people is that if the evaluation succeeds and the parties sign an MSA, an NDA limited to evaluating a potential relationship no longer authorizes use of that information to perform the contract. Either the MSA’s confidentiality provision takes over cleanly, or the NDA’s purpose has to cover performance under the later definitive agreement. You must understand the NDA does not exist in a vacuum. It must work with your other agreements. You don’t want conflicting provisions or gaps in coverage.
4. Who Is Allowed to See Confidential Information
A need-to-know standard applied to a defined group: employees, affiliates, officers, directors, advisors, contractors, sometimes financing sources. There are two common points of contention; whether affiliates are included and whether those recipients must be bound by written obligations at least as protective as the NDA.
The provision that makes the rest enforceable is the one making the receiving party responsible for any breach by any party it has communicated your confidential information to, as if it had breached itself. Without it, your remedy could run against an individual contractor instead of the company that handed them the file.
5. The Standard of Care
The common standard is reasonable care, and in no event less than the care the recipient uses for its own confidential information of like importance. Both halves matter, because a company with weak internal security has a very low bar for its own information.
There is a reason to care beyond the contract. State law tends to define trade secrets by the methods used to protect them from public disclosure. For example, information qualifies as a trade secret under the Oklahoma Uniform Trade Secrets Act only if it is “the subject of efforts that are reasonable under the circumstances to maintain its secrecy,” 78 Oklahoma Statutes § 86(4)(b). Your NDAs, and your actual practice under them, are much of what proves that element later. A confidentiality program that exists only in your contract file is not evidence of much.
6. Two Time Components: Term and Duration
These are different time components, and confusing them is one of the most common errors in short-form NDAs. The “term” dictates how long new disclosures are covered. The “duration” controls how long the recipient has to protect what was already disclosed. A two-year term with a three-to-five-year survival period is common.
What commonly gets left out is the trade secret carve-out: obligations as to trade secrets continue for as long as the information remains a trade secret under applicable law. Without a specific trade secret carve-out, a fixed expiration date in your NDA reads as your own agreement that trade secret protection ends on a date certain, an awkward position to hold while arguing you made reasonable efforts to maintain secrecy.
8. Remedies and Injunctive Relief
Nearly every NDA states that breach will cause irreparable harm for which money damages are inadequate, and that the disclosing party may obtain injunctive relief without posting a bond. Keep the clause. But do not rely on it as some courts have ruled that where parties have contractually agreed that any breach would constitute irreparable harm, that stipulation without more is insufficient to support an irreparable harm finding.
The damages disclaimer is also worth your consideration. If your NDA waives indirect, incidental, and consequential damages, look hard at what is left, because loss from disclosure of confidential information is very often exactly the category just waived. Accept a broad waiver, lose your injunction, and you are holding an agreement with no effective remedy in it.
9. The Residual Memory Clause
Most common in enterprise and SaaS forms, and the provision people are most likely to sign without reading. A residuals clause lets the receiving party use information retained in the unaided memory of individuals who had authorized access. In a technical evaluation, that covers a great deal.
It is not automatically unacceptable, and it is sometimes necessary, since you cannot ask an engineer to forget an architecture. If you accept one, narrow it: unaided memory only, no intentional memorization, no license under any patent or copyright, no use to develop a competing product, and customer data, pricing, and source code excluded outright.
Also Worth Thinking About
- No license, no warranty as to accuracy or completeness, and no obligation to proceed with any transaction. Three sentences that keep an evaluation from turning into an implied deal.
- The Defend Trade Secrets Act notice, 18 U.S.C. § 1833(b)(3), when the agreement is with an employee or an individual contractor. Omit it and you cannot recover exemplary damages or attorney fees under the DTSA against that person.
- Governing law and venue, which decide how much the nine provisions above are actually worth to you.
The Fastest Way to Get This Wrong
Sign the counterparty’s form because it is only four pages. Length has nothing to do with risk here. Four pages that give away your permitted purpose, your remedies, and your residuals will cost you more than forty pages of a well-built MSA. Read your own template against these nine provisions and find out which side of each one you are on.
Part 2 of this series will discuss the definition of confidential information: marking requirements, catch-all standards, the oral-disclosure follow-up nobody actually performs, and how to write a definition your own team can follow.
This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact Ken McConkey, Esquire to discuss your company’s specific confidentiality agreements.

