Avoiding the Traps in Non-Disclosure Agreements


Non-disclosure agreements are common wherever sensitive information is disclosed by one party to another, whether only one side is divulging information, such as between a client and a professional, or both parties are exchanging information mutually, such as in a business partnership. This guide walks through the clauses that matter most for the discloser, the recipient, or both, so information stays properly protected without unfairly constraining the recipient's activities.

Avoiding the traps in non-disclosure agreements

This guide is for legal, procurement and commercial teams who want to

tick icon

Develop a clear, even-handed definition of what counts as "confidential information" under an NDA.

tick icon

Limit a recipient's use and disclosure of information through express confidentiality obligations.

tick icon

Build in audit and enforcement rights so breaches can be identified and addressed.

tick icon

Ensure confidentiality obligations survive termination, including requiring return or destruction of information.

tick icon

Allocate liability for breaches committed by a recipient's employees and agents, and require appropriate data security controls.

tick icon

Apply balanced exclusions and carveouts, for pre-existing knowledge, independent development, and legally required disclosure, and qualify compliance obligations appropriately.

Published 15 July 2025  ·  Updated 6 August 2026

Non-disclosure agreements (NDAs) are common where sensitive information is disclosed by one party to the other. They might be used when only one party divulges information to the other, such as in the case of a client and a professional. Or, there may be a mutual exchange of information, such as in the case of a business partnership. In either case, the discloser of information will need to be certain that their information is properly protected. Similarly, the recipient should insist on appropriate carveouts to ensure that their activities are not unfairly constrained. This whitepaper flags considerations which are important for the discloser, the recipient, or both.

What counts as confidential information in an NDA?

Developing an even-handed and clear definition of which information is confidential is critical for both parties to understand their rights and obligations under the agreement. This definition will depend to some extent on the nature of the agreement. Commonly, confidential information is defined as information which is disclosed in connection with the agreement and is either confidential in nature, designated as confidential by the discloser, or known to be confidential by the recipient.

Tip for both parties: be as specific as you can when describing the confidential information.

Key points:

  • Use a definition that is even-handed rather than one-sided.
  • Cover information disclosed in connection with the agreement that is confidential in nature, designated confidential, or known to be confidential.
  • Be as specific as possible when describing the categories of information covered.

What can the recipient do with information shared under an NDA?

The obligations of the recipient set out the fundamental constraints on using the disclosed information. The discloser will typically seek to limit the use of the information in the following three ways:

  • First, by including an express obligation of confidence. Breach of an obligation of confidence entitles the discloser to a broader array of remedies beyond the damages owed for breach of contract, including injunctions to prevent the recipient from acting.
  • Secondly, by limiting the identity of the persons or entities to whom the information may be disclosed. Often this will have the effect of limiting the recipients to the officers or employees of a company who (a) need to know the information, (b) are subject to the provisions of the agreement, (c) have been notified that the information is confidential.
  • Thirdly, by limiting the purpose for which the information may be used. This may mean limiting use of the information to the commercial purposes contemplated by the agreement or for the purposes of giving effect to a particular transaction.
Tip for the discloser: define the permitted purpose of disclosure as tightly as possible.

Key points:

  • Impose an express obligation of confidence to unlock remedies such as injunctions.
  • Restrict who within the recipient's organisation may access the information.
  • Limit use of the information to the purpose the agreement is intended to serve.

How do you enforce an NDA if you think it's been breached?

While establishing the recipient's obligations is critical, the discloser should also have powers of audit and enforcement for cases when breaches are suspected to have occurred or when permitted disclosures are made. These include obligations on the recipient to notify the discloser of a breach and to assist with the enforcement of the agreement by providing information about the nature of the wrongful disclosure. Further, the discloser may also wish to have a power to verify the recipient's compliance with the agreement on its own accord. This will require a right to inspect the recipient's premises and consult its records.

Tip for the discloser: include an obligation to notify of disclosures made in breach of the agreement or which were made as being required by law.

Key points:

  • Require the recipient to notify the discloser of suspected or actual breaches.
  • Require the recipient to assist with enforcement by providing information about a wrongful disclosure.
  • Reserve a right to inspect premises and records to verify compliance.
The 10 critical NDA clauses
The 10 clauses covered in this guide, from definition of confidential information through to warranties of lawful disclosure.

Does confidentiality still apply after an NDA ends?

It is also critical for the discloser to consider the implications of terminating the agreement on the security of the disclosed information. If all of the recipient's obligations end when the agreement terminates then the recipient might lawfully divulge the confidential information while it remains sensitive. There are two methods to avoid losing the protections of an NDA upon termination.

  • First, stipulate that the confidentiality obligations of the recipient survive termination of the agreement for a certain period or perpetually. The recipient will then remain bound to confidence even if the relationship breaks down and the agreement is terminated.
  • Secondly, include an obligation to return or destroy confidential information in the possession of the recipient before termination. This takes the information out of the recipient's hands before they are released from their obligations of confidence.
Tip for the discloser: require the recipient to give formal notice that it has destroyed all copies of the information, including in any backup memory storage media.

Key points:

  • Have confidentiality obligations survive termination for a defined period or perpetually.
  • Require return or destruction of confidential information before termination takes effect.
  • Require formal notice of destruction, including of backup copies.

Is a company liable if its employees leak confidential information?

While disclosers often limit the transfer of confidential information on a need-to-know basis, that information may nonetheless pass in front of many pairs of eyes during its use by the recipient. The discloser should be alive to the possibility that the employees and agents of the recipient could commit a breach of confidence. Therefore, the discloser should include a clause which expressly states that the recipient bears liability for the acts of its employees and agents. This will avoid a future dispute about whether the recipient is liable where its employees have committed a breach of confidence and it is unclear whether they are acting within the scope of their employment.

Tip for discloser: where the information is extremely sensitive, consider requiring the recipient to have its employees sign individual confidentiality undertakings directly in favour of the discloser.

Key points:

  • Make the recipient expressly liable for breaches by its employees and agents.
  • Avoid disputes over whether an employee acted within the scope of their employment.
  • Consider individual employee confidentiality undertakings for highly sensitive information.

What data security obligations should be in an NDA?

The discloser should not only consider intentional wrongful disclosures. As recent events have shown, it is increasingly likely that information might be leaked or disclosed as the result of a cyber-attack. The discloser can protect against this possibility by imposing an obligation on the recipient to keep the confidential information secure. This will force the recipient to take steps to prevent unauthorised access to the confidential information. It may wish, either alternatively or additionally, to include a warranty stating that the recipient has appropriate security controls to safeguard the confidential information.

Tip for the discloser: specify the security controls that the recipient must have in place to protect the information.

Key points:

  • Impose an obligation on the recipient to keep confidential information secure.
  • Consider a warranty that the recipient has appropriate security controls in place.
  • Specify the security controls expected, rather than leaving them undefined.
  • See our related guide to data sovereignty and AI contract review tools for how this plays out when a supplier is offshore.

What information isn't covered by an NDA?

The recipient should ensure that the scope of information which is classified as confidential under the agreement is appropriate. This may require certain classes of information to be excluded from the application of the confidentiality obligations. Typical exclusions include:

  • Information which the discloser consents to being used at the time of disclosure. This may seem obvious, however, the recipient should ensure that a specific carveout exists.
  • Information which was already in the possession of the recipient, was disclosed by a third party, or was already in the public domain. The recipient should not be liable under the agreement for information which is not conveyed as part of the agreement but rather was already known to the recipient or acquired by other means.
  • Works which are the same as the confidential information but are developed by the recipient independently. Again, so long as the recipient can establish that it developed the works independently and not on account of information conveyed under the agreement then those works should not be subject to the recipient's confidentiality obligations.
Tip for discloser: in order to take advantage of the exception for information which was already in its possession, require the recipient having documentary proof that the relevant information was already in possession.

Key points:

  • Exclude information the discloser consents to using at the time of disclosure.
  • Exclude information already known to the recipient, disclosed by a third party, or already public.
  • Exclude works the recipient develops independently of the confidential information.

Can you be forced by law to disclose confidential information?

Another important carveout from the recipient's confidentiality obligations is the right to retain information and perform acts when legally required to do so. This will avoid a situation where the recipient is forced to choose between complying with the agreement or complying other laws and regulations to which it is subject.

Tip for the discloser: require the recipient to give advance notice (where possible) before making a disclosure that is required by law; that could give the discloser time to take action that protects the information even after the disclosure is made.

Key points:

  • Allow the recipient to retain information and act where legally required to do so.
  • Require advance notice of a legally required disclosure wherever possible.

Can you be liable for a breach that wasn't your fault?

The recipient should also ensure that its obligation to ensure compliance with the terms of the agreement is not absolute. An absolute obligation may have the effect of making the recipient strictly liable for any breaches of confidence. However, in some cases, such as where the confidential information is stolen notwithstanding that the recipient's control protocols were adequate, the recipient should not be liable for a disclosure.

Tip for recipient: qualify the obligation to ensure compliance with the language of "reasonable endeavours".

Key points:

  • Avoid an absolute compliance obligation, which can create strict liability.
  • Qualify compliance obligations with "reasonable endeavours" language.

How can someone who gets information under an NDA know it was lawfully obtained?

The recipient may wish to establish that the confidential information has been divulged lawfully. A warranty stating that the discloser has the right to disclose the confidential information and authorise the recipient to use that information should be used for this purpose. This will protect the discloser in the event that it is subsequently discovered that the information was wrongfully obtained and can no longer be used by the recipient.

Tip for the recipient: refer expressly to the recipient's proposed use of the information and link the warranty to that use.

Key points:

  • Obtain a warranty that the discloser has the right to disclose the information lawfully.
  • Link the warranty expressly to the recipient's proposed use of the information.

Frequently asked questions

What should a definition of confidential information in an NDA cover?

The definition should be even-handed and specific enough for both parties to understand their rights and obligations. Commonly, confidential information is defined as information disclosed in connection with the agreement that is either confidential in nature, designated as confidential by the discloser, or known to be confidential by the recipient. Both parties benefit from being as specific as possible when describing what falls within that definition.

How can a discloser limit how a recipient uses confidential information?

A discloser typically limits use of information in three ways: by imposing an express obligation of confidence, by restricting which persons or entities may receive the information, and by limiting the purpose for which it can be used. An express obligation of confidence is particularly valuable because breaching it can entitle the discloser to remedies beyond damages, including injunctions.

Why do confidentiality obligations need to survive termination of an NDA?

If a recipient's obligations end automatically when the agreement terminates, the recipient could lawfully divulge information that remains sensitive. NDAs typically address this by stipulating that confidentiality obligations survive termination for a set period, or perpetually, and by requiring the recipient to return or destroy confidential information before termination, including confirming destruction of any backup copies.

Who is liable if an employee of the recipient breaches confidentiality?

Because confidential information often passes in front of many employees during use, a discloser should include a clause making the recipient expressly liable for breaches committed by its employees and agents. This avoids later disputes about whether an employee was acting within the scope of their employment. Where information is extremely sensitive, a discloser can also require individual confidentiality undertakings signed directly by employees.

What information should be excluded from the definition of confidential information?

Typical exclusions cover information the discloser consents to being used at the time of disclosure, information already in the recipient's possession or the public domain, and works the recipient develops independently without reference to the confidential information. A recipient should require documentary proof that information was already in its possession to rely on that exclusion.

Should a recipient's obligation to ensure compliance be absolute?

No. An absolute compliance obligation can make the recipient strictly liable even where a breach occurs despite adequate controls, such as when information is stolen. Recipients should instead qualify the obligation with language such as "reasonable endeavours" so they are not automatically liable for disclosures they could not reasonably have prevented.

About the author

Michael Pattison is a Lawyer and the Founder of ContractProbe, an Australian AI-powered contract review platform built for legal and commercial teams.

This article is general information only and does not constitute legal advice. Organisations should obtain advice for their specific circumstances.

Get the full white paper

tick icon

All 10 critical NDA clauses, from definition of confidential information through to warranties of lawful disclosure.

tick icon

Practical, party-specific tips for both disclosers and recipients under each clause.

tick icon

Guidance on carveouts and exclusions to keep confidentiality obligations balanced and enforceable.

Download the white paper