1. Definition of Confidential Information
This is the most important clause in any NDA — it defines exactly what information you're prohibited from sharing. A well-drafted definition is specific: it lists categories of protected information (e.g., 'customer lists, financial data, source code, business plans') and requires confidential information to be marked or identified as 'Confidential' in writing.
A problematic definition uses vague, catch-all language like 'any and all information disclosed, whether oral or written, relating to the Company's business.' That effectively covers everything the other party ever tells you — including information that's publicly available or that you already knew.
What's fair: information marked 'Confidential' in writing, or oral information confirmed as confidential within 30 days. What's a red flag: 'any and all information' with no marking requirement and no carve-outs.
💡 Tip: If you're the Receiving Party, push for a definition that requires confidential information to be clearly marked. If you're the Disclosing Party, oral disclosures should be confirmed in writing within a reasonable window (typically 30 days).
2. Exclusions from Confidential Information
The exclusions clause lists what is NOT protected by the NDA. This is your safety valve — without it, you could be liable for 'disclosing' information that was already public. A standard exclusions clause should cover four categories:
- Public domain: information already available to the public through no fault of yours.
- Prior knowledge: information you already possessed before the NDA was signed (ideally demonstrable by written records).
- Third-party disclosure: information you receive from a third party who has the right to disclose it.
- Independent development: information you independently develop without using the confidential information.
If any of these four are missing, push back. A missing 'independent development' exclusion is especially dangerous for software companies — it means if your engineers build something similar without ever seeing the confidential info, you could still be accused of breach.
3. Obligations of the Receiving Party
This clause spells out what you, as the Receiving Party, must do to protect the confidential information. The standard is usually 'reasonable care' — the same degree of care you use to protect your own confidential information, but no less than a reasonable standard of care.
Some NDAs demand a higher standard (e.g., 'best efforts' or 'utmost care'), which can be problematic — what does 'utmost care' mean in practice, and could a minor slip-up be treated as a breach?
This clause also typically limits who can access the information — usually only employees and contractors who 'need to know' and who are bound by similar confidentiality obligations. It may also restrict use of the information to a specific purpose (e.g., 'solely for evaluating a potential business relationship').
💡 Tip: Watch for NDAs that require you to ensure third parties (like your contractors) comply — make sure the standard is 'substantially similar' obligations, not 'identical,' since you may not control their standard agreements.
4. Term and Duration
The term clause specifies how long the NDA's obligations last. There are actually two durations to check:
- The agreement term: how long the NDA itself is in effect (e.g., 'this Agreement shall remain in effect for 3 years from the Effective Date'). After this, you can no longer share new confidential information under this NDA.
- The confidentiality obligation period: how long you must keep information confidential after the agreement ends. This typically runs 2-5 years for general business information, but may be perpetual for trade secrets.
A perpetual obligation for all information (not just trade secrets) is a major red flag. In fast-moving industries like tech, 5-year-old information is rarely still sensitive. Push for 2-3 years for general business information, with trade secrets protected indefinitely.
5. Governing Law and Jurisdiction
This clause determines which state or country's laws will interpret the NDA and where any lawsuits must be filed. For example, 'This Agreement shall be governed by the laws of the State of New York, and the parties submit to the exclusive jurisdiction of the federal and state courts located in New York County, New York.'
If the governing law is in a jurisdiction far from where you live or do business, disputes become significantly more expensive and inconvenient. A California startup shouldn't agree to New York governing law without a good reason — try to negotiate for your home state, Delaware (neutral for commercial contracts), or at minimum remove the 'exclusive' jurisdiction so either party can file where they are.
For international NDAs, the governing law choice is even more critical. Common law jurisdictions (US, UK, Australia, Singapore) and civil law jurisdictions (EU countries, China, Japan) treat NDAs quite differently — particularly around what constitutes 'confidential information' and what remedies are available for breach. For more on how force majeure and other clauses interact with jurisdiction, see our guide on the force majeure clause explained.
6. Remedies for Breach
The remedies clause explains what happens if someone violates the NDA. It almost always includes the right to seek 'injunctive relief' — a court order to stop the breach immediately. This is standard because money damages alone can't undo the disclosure of a trade secret.
Beyond injunctions, the clause may include: monetary damages (actual damages caused by the breach), liquidated damages (a preset dollar amount per violation — a red flag if excessive), and attorneys' fees (the losing party pays the winner's legal costs — can be one-sided or mutual).
Watch for one-sided attorneys' fees provisions (only you pay if you lose, but they don't pay if they lose). Also watch for liquidated damages — $1,000+ per violation with no cap is a red flag. Damages should be tied to actual harm, not preset as a penalty.
💡 Tip: If the NDA includes a liquidated damages clause, negotiate a reasonable cap (e.g., the total value of the underlying transaction) or remove it entirely in favor of actual damages.
7. Return or Destruction of Information
When the NDA ends or the Disclosing Party asks, you must return or destroy all confidential materials. Most clauses require you to certify in writing that you've done so. This is standard and generally reasonable.
However, some NDAs demand overly burdensome destruction: certifying 'under penalty of perjury' that you've deleted everything including automated backups, archived emails, and disaster recovery copies. If your backup system retains data for 90 days and can't be selectively purged, you can't comply with this.
Negotiate for: (1) 'commercially reasonable efforts' instead of absolute destruction, (2) an exclusion for automated backup systems (with a commitment not to restore the data for business use), and (3) an exclusion for copies required by law or regulation. One copy may also be retained for compliance/legal hold purposes.
8. Non-Solicitation and Non-Compete
Some NDAs go beyond confidentiality and include restrictions on hiring the other party's employees (non-solicitation) or competing with their business (non-compete). These are NOT standard NDA clauses — they are separate restrictions that fundamentally affect your ability to do business.
A non-solicitation clause might say: 'Receiving Party shall not solicit or hire any employee of Disclosing Party for 12 months after the NDA terminates.' This is common enough to be negotiable, but ensure it's mutual and limited to employees you interacted with during the engagement (not the entire company).
A hidden non-compete might say: 'Receiving Party shall not use Confidential Information to develop any product or service that competes with Disclosing Party.' This sounds like a use restriction but can function as a non-compete — especially if 'Confidential Information' is broadly defined. Flag it.
For a deeper dive on spotting unfair terms, see our NDA red flags guide and learn how to review a contract yourself.
9. Residuals Clause
A residuals clause allows the Receiving Party to use information retained in the 'unaided memory' of its employees who had access to the confidential information. In theory, this acknowledges that people can't un-learn general knowledge and ideas. In practice, it can be a loophole — especially for software companies where seeing a demo could give a competitor ideas that end up in their product.
If you're the Disclosing Party (sharing your secrets), push to remove the residuals clause entirely, or limit it so it doesn't apply to software code, algorithms, or technical designs. If you're the Receiving Party, the clause gives your team breathing room — but don't rely on it as a defense for deliberate copying.
The residuals clause is one of the most negotiated provisions in tech NDAs. It's worth understanding both sides' positions before you sit down at the table.
10. Miscellaneous (Integration, Severability, Amendment)
The 'miscellaneous' or 'general provisions' section at the end of an NDA contains standard legal boilerplate that's mostly non-controversial — but not entirely. Key provisions to check:
- Integration / Entire Agreement: says the NDA is the complete agreement between the parties and supersedes any prior discussions. Standard — ensures side conversations don't become binding.
- Severability: if one clause is found unenforceable by a court, the rest of the NDA survives. Standard and mutually beneficial.
- Amendment: how the NDA can be changed — almost always 'in writing signed by both parties.' Standard.
- Waiver: if one party doesn't enforce a right once, they haven't waived it forever. Standard but should be explicit — a 'non-waiver' clause.
- Assignment: whether you can transfer the NDA to another party. Most NDAs prohibit assignment without consent, which is standard. If you're a startup that might be acquired, negotiate for assignment rights in connection with a merger or sale.
- Counterparts: allows the NDA to be signed in separate copies (e.g., one party signs via DocuSign, the other via email). Standard and convenient.
NDA Clause Checklist: What's Fair vs. Red Flag
Here's a quick reference for what's standard (green flag) vs. what should make you pause (red flag) in each NDA clause:
- ✓ Confidential Info: marked 'Confidential' → ✗ 'Any and all information disclosed' with no marking requirement
- ✓ Exclusions: all 4 standard carve-outs (public domain, prior knowledge, third-party, independent development) → ✗ Missing independent development or prior knowledge exclusion
- ✓ Obligations: 'reasonable care' standard → ✗ 'Best efforts' or 'utmost care' with no definition
- ✓ Term: 2-5 years for general business info, perpetual for trade secrets only → ✗ Perpetual for ALL information including non-trade-secret
- ✓ Governing Law: your home state or Delaware → ✗ Distant forum with 'exclusive' jurisdiction
- ✓ Remedies: injunctive relief + actual damages → ✗ Liquidated damages with no cap, one-sided attorneys' fees
- ✓ Return of Info: 'commercially reasonable efforts' + backup exclusion → ✗ 'Under penalty of perjury' with no backup exclusion
- ✓ Non-Solicit: mutual, limited to employees you interacted with → ✗ One-sided, covers all employees of a large company
- ✓ Residuals: explicitly limited, excludes source code/designs → ✗ Unlimited residuals clause in a tech NDA
💡 Tip: The fastest way to check all of these at once: upload your NDA to our [NDA clause checker](/nda-clause-checker). It scans every clause, flags risky language, and gives you suggested fixes — in about 30 seconds.