Business Law

NDAs: How to Use Non-Disclosure Agreements to Protect Your Business

March 3, 2026

What Is a Non-Disclosure Agreement?

A non-disclosure agreement (NDA) — also called a confidentiality agreement — is a contract in which one or both parties agree to keep certain information confidential and not to use it for purposes other than those specified in the agreement. NDAs are used across virtually every industry and at every stage of business, from early-stage startup conversations to multi-billion-dollar M&A transactions.

Despite their ubiquity, NDAs are frequently drafted poorly, negotiated carelessly, or deployed in situations where they provide little practical protection. Understanding how NDAs actually work — what they can and cannot protect, how to draft them effectively, and when they're worth the paper they're printed on — is important for every business owner.

When to Use an NDA

NDAs are appropriate whenever you're sharing sensitive proprietary information with someone who doesn't already have a legal obligation to keep it confidential. Common situations include:

  • Conversations with potential investors, partners, or acquirers about your business model, technology, or financials
  • Early discussions with potential employees or contractors before an employment or services agreement is in place
  • Vendor or supplier relationships involving access to proprietary processes, formulas, or customer data
  • Licensing negotiations involving trade secrets or proprietary technology
  • Any situation where you're sharing information you wouldn't want a competitor to have

Note what's not on this list: NDAs are generally not useful (and often counterproductive) in fundraising conversations with professional venture capitalists. Most VCs will refuse to sign NDAs before early-stage pitch meetings — it's simply not the norm, and asking signals naivety about how fundraising works. VCs see hundreds of pitches; they're not going to sign an NDA to hear your pitch, and making this a condition effectively disqualifies you from many conversations. The practical protection in early fundraising conversations comes from not sharing genuinely sensitive technical details until there's more mutual commitment.

Key Provisions in a Well-Drafted NDA

1. Definition of Confidential Information

The definition of what constitutes "confidential information" is the most important substantive provision in an NDA. It should be broad enough to capture all the sensitive information you want protected, but precise enough to be enforced. Standard approaches include: (1) designating disclosed information as confidential at the time of disclosure (either orally or in writing); (2) defining categories of information that are automatically confidential (e.g., financial information, technical data, customer lists); or (3) a combination of both.

The definition should also address exclusions — categories of information that are not confidential even if they meet the general definition. Standard exclusions include: information that is publicly available through no fault of the recipient; information the recipient already knew before receiving it from the disclosing party; information independently developed by the recipient without use of confidential information; and information received from a third party without restriction.

2. Permitted Uses

The NDA should specify the purpose for which confidential information can be used. In a typical bilateral NDA for exploring a business partnership, the permitted use is evaluating the potential transaction. A contractor NDA might permit use only for performing services under the engagement. The tighter the permitted use restriction, the stronger the protection.

3. Duration

NDA obligations should have a specified duration. Two to five years is common for commercial NDAs. Trade secret protection obligations should ideally survive for as long as the information remains a trade secret (potentially indefinitely). When evaluating NDAs presented by other parties, be cautious of confidentiality obligations that last indefinitely for all disclosed information — they can create practical compliance burdens for routine business operations.

4. Standard of Care

The NDA should specify the standard of care the recipient must use to protect the confidential information — typically the same care used to protect the recipient's own confidential information, but not less than a reasonable standard. This provision determines how the recipient's conduct is evaluated if a breach is alleged.

5. Injunctive Relief

Because a breach of confidentiality — once it happens — is extremely difficult to remedy with money damages alone (the information is already disclosed), well-drafted NDAs typically include a provision acknowledging that breach would cause irreparable harm and agreeing that the disclosing party is entitled to seek injunctive relief without posting a bond. This provision can be critical in getting a court to act quickly to prevent ongoing harm.

Unilateral vs. Mutual NDAs

A unilateral NDA protects information flowing from one party to the other — only the recipient has confidentiality obligations. A mutual (or bilateral) NDA imposes confidentiality obligations on both parties. Mutual NDAs are appropriate when both parties will be sharing sensitive information. Unilateral NDAs are more appropriate when information primarily flows one direction (e.g., a vendor receiving access to customer data).

The Limits of NDAs

NDAs protect against intentional disclosure by the contracting party — they don't protect against independent discovery, reverse engineering, public disclosure by a third party, or a sophisticated adversary who is determined to use information while technically avoiding what can be proven as a breach. Trade secret protection requires not just an NDA but a comprehensive program of confidentiality protocols, access controls, and employee education. NDAs are one important component of that program, not the whole program.