Non-disclosure agreements are common wherever sensitive information is disclosed by one party to another, whether only one side is divulging information, such as between a client and a professional, or both parties are exchanging information mutually, such as in a business partnership. This guide walks through the clauses that matter most for the discloser, the recipient, or both, so information stays properly protected without unfairly constraining the recipient's activities.
Develop a clear, even-handed definition of what counts as "confidential information" under an NDA.
Limit a recipient's use and disclosure of information through express confidentiality obligations.
Build in audit and enforcement rights so breaches can be identified and addressed.
Ensure confidentiality obligations survive termination, including requiring return or destruction of information.
Allocate liability for breaches committed by a recipient's employees and agents, and require appropriate data security controls.
Apply balanced exclusions and carveouts, for pre-existing knowledge, independent development, and legally required disclosure, and qualify compliance obligations appropriately.
By Michael Pattison, Lawyer & Founder, ContractProbe
Published 15 July 2025 · Updated 6 August 2026
Non-disclosure agreements (NDAs) are common where sensitive information is disclosed by one party to the other. They might be used when only one party divulges information to the other, such as in the case of a client and a professional. Or, there may be a mutual exchange of information, such as in the case of a business partnership. In either case, the discloser of information will need to be certain that their information is properly protected. Similarly, the recipient should insist on appropriate carveouts to ensure that their activities are not unfairly constrained. This whitepaper flags considerations which are important for the discloser, the recipient, or both.
Developing an even-handed and clear definition of which information is confidential is critical for both parties to understand their rights and obligations under the agreement. This definition will depend to some extent on the nature of the agreement. Commonly, confidential information is defined as information which is disclosed in connection with the agreement and is either confidential in nature, designated as confidential by the discloser, or known to be confidential by the recipient.
The obligations of the recipient set out the fundamental constraints on using the disclosed information. The discloser will typically seek to limit the use of the information in the following three ways:
While establishing the recipient's obligations is critical, the discloser should also have powers of audit and enforcement for cases when breaches are suspected to have occurred or when permitted disclosures are made. These include obligations on the recipient to notify the discloser of a breach and to assist with the enforcement of the agreement by providing information about the nature of the wrongful disclosure. Further, the discloser may also wish to have a power to verify the recipient's compliance with the agreement on its own accord. This will require a right to inspect the recipient's premises and consult its records.
It is also critical for the discloser to consider the implications of terminating the agreement on the security of the disclosed information. If all of the recipient's obligations end when the agreement terminates then the recipient might lawfully divulge the confidential information while it remains sensitive. There are two methods to avoid losing the protections of an NDA upon termination.
While disclosers often limit the transfer of confidential information on a need-to-know basis, that information may nonetheless pass in front of many pairs of eyes during its use by the recipient. The discloser should be alive to the possibility that the employees and agents of the recipient could commit a breach of confidence. Therefore, the discloser should include a clause which expressly states that the recipient bears liability for the acts of its employees and agents. This will avoid a future dispute about whether the recipient is liable where its employees have committed a breach of confidence and it is unclear whether they are acting within the scope of their employment.
The discloser should not only consider intentional wrongful disclosures. As recent events have shown, it is increasingly likely that information might be leaked or disclosed as the result of a cyber-attack. The discloser can protect against this possibility by imposing an obligation on the recipient to keep the confidential information secure. This will force the recipient to take steps to prevent unauthorised access to the confidential information. It may wish, either alternatively or additionally, to include a warranty stating that the recipient has appropriate security controls to safeguard the confidential information.
The recipient should ensure that the scope of information which is classified as confidential under the agreement is appropriate. This may require certain classes of information to be excluded from the application of the confidentiality obligations. Typical exclusions include:
Another important carveout from the recipient's confidentiality obligations is the right to retain information and perform acts when legally required to do so. This will avoid a situation where the recipient is forced to choose between complying with the agreement or complying other laws and regulations to which it is subject.
The recipient should also ensure that its obligation to ensure compliance with the terms of the agreement is not absolute. An absolute obligation may have the effect of making the recipient strictly liable for any breaches of confidence. However, in some cases, such as where the confidential information is stolen notwithstanding that the recipient's control protocols were adequate, the recipient should not be liable for a disclosure.
The recipient may wish to establish that the confidential information has been divulged lawfully. A warranty stating that the discloser has the right to disclose the confidential information and authorise the recipient to use that information should be used for this purpose. This will protect the discloser in the event that it is subsequently discovered that the information was wrongfully obtained and can no longer be used by the recipient.
The definition should be even-handed and specific enough for both parties to understand their rights and obligations. Commonly, confidential information is defined as information disclosed in connection with the agreement that is either confidential in nature, designated as confidential by the discloser, or known to be confidential by the recipient. Both parties benefit from being as specific as possible when describing what falls within that definition.
A discloser typically limits use of information in three ways: by imposing an express obligation of confidence, by restricting which persons or entities may receive the information, and by limiting the purpose for which it can be used. An express obligation of confidence is particularly valuable because breaching it can entitle the discloser to remedies beyond damages, including injunctions.
If a recipient's obligations end automatically when the agreement terminates, the recipient could lawfully divulge information that remains sensitive. NDAs typically address this by stipulating that confidentiality obligations survive termination for a set period, or perpetually, and by requiring the recipient to return or destroy confidential information before termination, including confirming destruction of any backup copies.
Because confidential information often passes in front of many employees during use, a discloser should include a clause making the recipient expressly liable for breaches committed by its employees and agents. This avoids later disputes about whether an employee was acting within the scope of their employment. Where information is extremely sensitive, a discloser can also require individual confidentiality undertakings signed directly by employees.
Typical exclusions cover information the discloser consents to being used at the time of disclosure, information already in the recipient's possession or the public domain, and works the recipient develops independently without reference to the confidential information. A recipient should require documentary proof that information was already in its possession to rely on that exclusion.
No. An absolute compliance obligation can make the recipient strictly liable even where a breach occurs despite adequate controls, such as when information is stolen. Recipients should instead qualify the obligation with language such as "reasonable endeavours" so they are not automatically liable for disclosures they could not reasonably have prevented.
Michael Pattison is a Lawyer and the Founder of ContractProbe, an Australian AI-powered contract review platform built for legal and commercial teams.
This article is general information only and does not constitute legal advice. Organisations should obtain advice for their specific circumstances.
All 10 critical NDA clauses, from definition of confidential information through to warranties of lawful disclosure.
Practical, party-specific tips for both disclosers and recipients under each clause.
Guidance on carveouts and exclusions to keep confidentiality obligations balanced and enforceable.