1. Definition of Confidential Information
The definition of 'Confidential Information' is the most important clause in any NDA. It determines what you're legally obligated to protect.
- ☐ Is the definition specific ('information marked Confidential in writing') or overly broad ('any and all information disclosed, whether orally or in writing')?
- ☐ If oral disclosures are covered, does the NDA require written confirmation within a reasonable time (typically 30 days)?
- ☐ Are you comfortable with everything that falls under the definition? If it covers 'all business discussions,' that could include casual conversations.
- ☐ Is the definition mutual? If not, only one party's information is protected.
💡 Tip: Overly broad definitions are the #1 NDA red flag. A definition that covers 'any and all information' gives the other party unlimited power to claim breach. Push for specificity — 'information marked Confidential.'
2. Exclusions from Confidentiality
Standard NDAs exclude certain categories of information from protection. Make sure these exclusions are present and reasonable:
- ☐ Public domain information — already publicly available through no fault of yours.
- ☐ Prior knowledge — information you already knew before signing the NDA.
- ☐ Third-party disclosure — information you receive from someone else who isn't bound by the NDA.
- ☐ Independent development — information you develop on your own without using the confidential information.
- ☐ Are the exclusions clearly stated, or are they missing entirely? Missing exclusions = red flag.
3. Term and Duration
- ☐ How long does the NDA last? 2-5 years is standard for general business information.
- ☐ Are trade secrets protected indefinitely? This is standard and acceptable.
- ☐ Is there a perpetual (forever) obligation for non-trade-secret information? That's a red flag — push for a defined term.
- ☐ Does the NDA survive termination of the underlying agreement? It should, but for a reasonable period, not forever.
- ☐ Is the term different for each party? It should be the same.
4. Receiving Party Obligations
- ☐ Are you required to use the same degree of care you use for your own confidential information ('reasonable care') — or a higher standard?
- ☐ Are you allowed to share information with employees/contractors who need to know it — and are they also bound by confidentiality?
- ☐ Are you required to notify the disclosing party of any unauthorized disclosure? This is standard.
- ☐ Is there any obligation to actively monitor or audit compliance? That's unusual — push back.
5. Hidden Non-Compete Clauses
- ☐ Does the NDA contain non-solicitation language (can't hire their employees) — and if so, is that acceptable to you?
- ☐ Does the NDA contain non-compete language (can't compete with their business)? NDAs should be about confidentiality, not competition.
- ☐ Are there any restrictions on who you can do business with in the future? If so, those belong in a separate agreement, not hidden in an NDA.
- ☐ If you're an individual (not a company), do the restrictions unreasonably limit your ability to work in your field?
💡 Tip: NDAs sometimes sneak in non-compete or non-solicitation clauses. Read carefully — a confidentiality agreement should protect information, not restrict your career.
6. Return of Information
- ☐ When the NDA ends, are you required to return or destroy all confidential materials? This is standard.
- ☐ Is there a certification requirement — do you need to certify in writing that you've destroyed everything? This is common but can be burdensome.
- ☐ Are there carve-outs for automated backups, legal retention requirements, or one copy for compliance? Check for these.
- ☐ Can you realistically comply with the return/destruction requirements? If they require deleting all emails — can you actually do that?
7. Indemnification
- ☐ Does the NDA require you to indemnify (cover legal costs for) the other party? This is unusual in a standalone NDA.
- ☐ If indemnification is included, is it mutual — or one-sided against you?
- ☐ Are there any financial penalties for breach beyond actual damages? Liquidated damages clauses in NDAs are uncommon and should be questioned.
8. Governing Law
- ☐ Which state or country's law governs the NDA? Is it a jurisdiction you're comfortable with?
- ☐ If the governing law is in another state or country, would you have to hire a lawyer there to defend yourself?
- ☐ Is there a venue clause requiring disputes to be heard in a specific court — and is that court convenient for you?
9. Remedies for Breach
- ☐ Does the NDA allow for injunctive relief (court order to stop the breach) — this is standard and expected.
- ☐ Are monetary damages specified, and are they capped or unlimited?
- ☐ Is there an attorneys' fees clause — does the losing party pay the winning party's legal fees? This can be one-sided or mutual.
- ☐ Is there a jury trial waiver? This is common but understand what you're giving up.
How to Use This Checklist
Go through each item in order. For any item where the NDA falls short, decide whether it's a dealbreaker or a negotiating point. Not every NDA needs to be perfect — but you should understand every risk before you sign.
For a faster approach, upload your NDA to our free AI NDA checker. It runs through a similar checklist automatically, flagging red flags like overly broad definitions, perpetual terms, and hidden non-competes in under 30 seconds.
Review My NDA Now →