Think the topic of this post may apply to your business?

Contact me to discuss.

NDA Essentials, Part 2: What Counts as Confidential (and the Step Everyone Skips)

You said it out loud in a conference room, not in an email. Nobody stamped a document, nobody sent a follow-up memo, and eight months later the relationship went sideways. If your NDA requires written confirmation of anything disclosed orally, that unrecorded conversation may never have been protected at all.

Part 1 of this series covered nine provisions and gave the definition of confidential information a single paragraph. That undersold it. Everything else in the agreement, the standard of care, the remedies, is arguing about a term the parties often never pinned down. This post covers what actually counts as confidential, why the two standard ways of defining it each fail in their own ways, and the follow-up step almost nobody performs.

What Actually Gets Called Confidential

Every definition of confidential information, however it’s worded, is reaching for the same handful of categories:

  • Technical data: source code, architecture documents, product specifications, engineering drawings, algorithms, and features that haven’t shipped yet.
  • Business operations: financials, pricing models, cost structures, strategic plans, and internal processes.
  • Client insights: customer lists, contact information, usage data, and anything that reveals who a company’s customers are or how they use its product.
  • Intellectual property that isn’t yet protected by a patent, copyright registration, or trademark: inventions still in progress, unpatented designs, and plain know-how.

None of that is where the fight happens. The fight is over how the definition decides whether something you actually said or sent falls into one of these buckets in the first place.

Two Competing Definitions, and Why Both Fail Alone

Most NDAs pick one of two approaches to defining confidential information, and each fails in its own way.

The Marking-Based Definition

This approach protects only what’s labeled confidential in writing at the time of disclosure, or reduced to a written summary within a set number of days if it wasn’t written to begin with. Clean to apply, and it fails the moment someone forgets, which is often, since nobody marks a Slack message, a shared screen, or a photo of a whiteboard.

The Catch-All Definition

This approach instead covers anything a reasonable person would understand to be confidential given the nature of the information and the circumstances of its disclosure. That protects the discloser against exactly the human error above, and it leaves the recipient guessing, in real time, about what it can and can’t use. I’d rather negotiate a longer marking deadline than fight later over what a reasonable person would understand, because that phrase means whatever a judge wants it to.

Most NDA forms split the difference: marking required for anything written or tangible, a written follow-up required for anything oral or visual. That hybrid is certainly the right idea. But it also creates an obligation almost nobody actually performs.

The Oral-Disclosure Follow-Up (The One Nobody Performs)

Here’s the obligation. If your NDA uses the hybrid approach above and you disclose something in a meeting, a demo, or a phone call instead of a document, the agreement typically gives you a window (e.g. 10, 20, sometimes 30 days) to send the other side a written summary identifying what was disclosed and confirming it’s confidential. Miss that window, and under the plain language of most NDA forms, what you talked about in that room was never covered as confidential information.

This can be more than a mere technicality. It cost a company its trade secret protections in at least one case. In Convolve, Inc. v. Compaq Computer Corp., 527 F. App’x 910 (Fed. Cir. 2013), the NDA required that information disclosed orally or visually be identified as confidential at the time of disclosure and confirmed in a writing delivered within twenty days of the disclosure. Convolve disclosed trade secret information about hard disk drive technology at a meeting and never sent the follow-up confidentiality memo. The Federal Circuit court held the NDA’s language was clear, and rejected Convolve’s argument that both sides understood the information was confidential anyway. A written contract, the court said, supplants whatever informal understanding the parties may have shared. Therefore, what was said in that meeting received no protection under the NDA because its specific provisions were not followed.

The lesson isn’t that talking is dangerous. It’s that a specific, calendarable obligation is probably sitting in your NDA form right now, and it doesn’t enforce itself. If your form works this way, the fix costs about five minutes after any meeting where you say more than you type; a short email listing what was covered and stating that it’s confidential information under the agreement. Send it before the deadline in your NDA runs.

The Catch-All Trap

A definition reading “any and all information disclosed by either party, in any form” looks like maximum protection. It’s closer to the opposite. Courts have pushed back on definitions this broad, especially once they start looking like they restrain a recipient’s ordinary business rather than protect a specific disclosure, and an agreement nobody can actually comply with tends to get read narrowly by a judge deciding what it was reasonable to expect the recipient to do. There’s a practical cost too, not just a legal one. A recipient covering “everything” either ignores the restriction in practice, since no team treats every internal document that touched a vendor conversation as under lock and key, or it locks down so hard that ordinary work grinds to a halt. Either way, the breadth on paper and the reality of how the company actually operates come apart, and that gap is exactly what gets argued over once there’s a dispute.

The better draft names the categories, technical data, business operations, client insights, unregistered intellectual property, and pairs that with a reasonable marking or written-confirmation mechanism instead of either extreme. It tells your own team what actually needs protecting instead of asking them to guess.

Which Side of the Table You’re On

The right structure for this clause depends on which side of the table you’re sitting on more often.

If You’re Mostly Disclosing

That’s often still true even when you’re also receiving, in a bidirectional NDA. You want the definition broad enough to cover the ways you actually share information, and you want the marking or follow-up deadline generous enough that your own team can hit it. Thirty days beats ten.

If You’re Mostly Receiving

You want the opposite: real categories instead of a catch-all, and a marking or written-confirmation requirement with actual teeth, because that’s what tells you, in the moment, what you’re restricted from doing with what just landed in your inbox or your head. In a mutual NDA you’re negotiating both roles at once, so know which one describes more of your actual dealings with this counterparty before deciding which way to push.

Before You Sign the Next One

Pull your current NDA form and check it against this list before the next one lands in your inbox with a signature deadline attached.

  • Match the definition’s categories, technical data, business operations, client insights, intellectual property, to what you’ll actually disclose or receive, not a generic list copied out of a form.
  • If your NDA has a marking requirement, build the habit of stamping documents before they leave the building, not after someone asks.
  • If your NDA allows oral or visual disclosure with a written follow-up window, find that window today and put a five-minute recurring task on your calendar for the day after any substantive meeting with a counterparty.
  • Keep dated records for anything you might need to prove later as prior knowledge or independent development. A file’s modification date is worth more than someone’s memory of who thought of what first.
  • Don’t let a catch-all “everything is confidential” clause substitute for the habits above. Broad language protects you on paper and does nothing for you in a conversation nobody can point back to.
  • Read your current NDA form against this list and note which of these your team is actually equipped to do, not just which ones are already in the document.

Part 3 of this series turns to the permitted purpose clause: the one line that decides whether your own ordinary use of what you received counts as a breach.

This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact Ken McConkey to discuss your company’s specific confidentiality agreements.