A non-disclosure agreement — NDA, also called a confidentiality agreement — is the most commonly signed business contract in the United States. Employees sign them at hiring. Vendors sign them before pitching. Merger targets sign them before due diligence. Startups sign them before investor meetings. The volume of NDAs is so high that most parties give them cursory review and sign — and most of the time, nothing goes wrong.
But when an NDA dispute does arise, the specific language of the clauses becomes determinative. This article walks through the clauses that most affect NDA enforceability and practical outcome. It is general guidance, not legal advice. Cornell's LII entry on NDAs is a useful starting reference, and the US Patent and Trademark Office's trade-secret overview addresses the related trade-secret framework.[¹][³]
The two NDA archetypes
NDAs come in two main structures:
- One-way (unilateral) NDA. One party (the disclosing party) shares confidential information with another (the receiving party). The receiving party owes confidentiality obligations; the disclosing party owes none.
- Mutual (two-way) NDA. Both parties share confidential information and owe reciprocal confidentiality obligations.
One-way NDAs are common in employer-employee, vendor-customer, and investor-startup relationships. Mutual NDAs are common in strategic partnerships, joint ventures, and early-stage acquisition discussions where both parties share sensitive information. In transactional settings the NDA often gets rolled into a broader preliminary document — see our piece on contracts versus memoranda of understanding for how the confidentiality language then interacts with binding-vs-non-binding framing.
The practical difference: a one-way NDA favors the disclosing party. A mutual NDA is more balanced. Converting an offered one-way NDA to a mutual one is often possible in negotiation and usually beneficial for the party being asked to sign.
Defining "Confidential Information"
The definition of confidential information is the most important clause in any NDA. It sets the scope of what is protected — and what is not.
Common definition patterns:
- Broad inclusive. All information disclosed by one party to the other is confidential, subject to listed exclusions. Favors the disclosing party.
- Marked-only. Only information specifically marked "confidential" (in writing) or identified as confidential at the time of oral disclosure is protected. Favors the receiving party but requires diligent marking by the disclosing party.
- Category list. Only information within listed categories (financial data, product roadmap, customer lists, source code) is protected. Favors certainty but risks under-coverage.
- Hybrid. Broad inclusive language with a follow-up acknowledgment requirement — information disclosed orally becomes confidential only if followed up in writing within a stated period.
The marked-only approach is often preferred by receiving parties because it requires the disclosing party to actively identify what they consider confidential. A disclosing party who fails to mark may find the information unprotected. But marked-only clauses require real discipline from the disclosing party.
Standard exclusions
Almost every NDA excludes four categories of information from confidentiality obligations:
- Information that was already in the public domain before disclosure.
- Information that becomes public through no fault of the receiving party.
- Information the receiving party already knew before disclosure, demonstrable by prior written records.
- Information independently developed by the receiving party without reference to the confidential information.
A fifth exclusion often added:
- Information received from a third party who had the right to disclose it without confidentiality obligations.
These exclusions are foundational and generally enforceable. An NDA that does not include them may be unenforceable to that extent — the underlying rationale is that information the public already has access to isn't capable of being treated as confidential or secret in the first place, the same reasoning that governs when trade-secret protection lapses.[²]
Permitted use clause
A well-drafted NDA limits the receiving party's use of the confidential information — not just disclosure but use. A common structure:
- The receiving party may use the confidential information only for a stated purpose (the "Purpose" — typically evaluating a transaction, performing services under a contract, developing a product).
- Use for any other purpose is a breach.
- Use by the receiving party's employees, contractors, and advisors is permitted only to those who have a need to know and who are subject to confidentiality obligations at least as strict as those in the NDA.
The Purpose definition matters. A Purpose defined as "evaluating a potential acquisition" is narrower than "evaluating a potential business relationship" — and a receiving party who uses the information for a different relationship or transaction (a joint venture instead of the contemplated acquisition, say) may be in breach even without public disclosure.
Term and survival
NDAs have two related duration concepts:
- Term. The period during which confidentiality obligations apply to new disclosures.
- Survival. The period during which confidentiality obligations continue after the term ends.
Common structures:
- Term of 1-3 years, survival 2-5 years. Relatively short coverage; appropriate for transactional or short-project relationships.
- Term of the relationship, survival perpetual. Employment NDAs and trade-secret NDAs often structure this way. Survival perpetual is legally defensible for genuine trade secrets; may be unenforceable for ordinary confidential information in some states that disfavour indefinite obligations.
- Survival tied to trade-secret status. The confidentiality obligation survives for as long as the information remains a trade secret (defined to lose protection once public).
Survival perpetual for a genuine trade secret has no inherent end date under trade-secret law: protection lasts as long as the information keeps its value from not being generally known and the owner keeps taking reasonable steps to protect it.[²] Survival perpetual for information that isn't a genuine trade secret rests on ordinary contract enforceability instead, and an indefinite confidentiality obligation not tied to protectable trade-secret status may draw more scrutiny from a court in some states than one that is.
Residuals clause
Some NDAs include a "residuals" clause that allows the receiving party to use ideas, concepts, or know-how retained in employees' memories (without reference to notes or records) for their ordinary business purposes. Technology-industry NDAs frequently include residuals clauses.
Residuals clauses are favored by receiving parties and disfavored by disclosing parties. A disclosing party asked to accept a residuals clause should understand that it significantly narrows the enforceability of the NDA — the receiving party can effectively use most concepts in ordinary course after reasonable time passes.
Carve-outs for legal process
Virtually every modern NDA includes a carve-out allowing the receiving party to disclose confidential information when legally required — subpoena, court order, government investigation, securities disclosure obligation. A well-drafted carve-out:
- Requires prompt notice to the disclosing party.
- Allows the disclosing party an opportunity to seek a protective order.
- Limits the disclosure to what is actually required by the legal process.
- Treats disclosure pursuant to the carve-out as not a breach.
A carve-out that allows the receiving party to disclose without notice to the disclosing party is unusual and favors the receiving party.
Whistleblower protections
Federal and state laws protect whistleblower disclosures regardless of what the NDA says. The Defend Trade Secrets Act (DTSA), 18 USC section 1833(b), provides immunity for whistleblowers who disclose trade secrets to government officials or in court filings for whistleblower purposes.[⁴] Several states have parallel or broader protections.
NDAs that do not include the DTSA whistleblower-notice language may render the employer ineligible for exemplary damages and attorney fees in a trade-secret case. Most modern employee NDAs include this notice explicitly.
Return or destruction at termination
A typical NDA requires the receiving party to return or destroy the disclosing party's confidential information at termination or on request. The clause should specify:
- Whether return or destruction is at the disclosing party's option.
- The deadline for return or destruction.
- Whether electronic copies on archival backup must be destroyed (typically impractical and carved out).
- Whether the receiving party's legal counsel may retain a copy for compliance purposes.
Modern NDAs often accept that complete destruction of electronic backups is impractical and exempt archival backups as long as they are not accessed.
Remedies
NDAs typically specify several remedies for breach:
- Injunctive relief. A court order stopping the breach. Often described as the "appropriate" remedy because monetary damages are inadequate for confidentiality breaches (you cannot undisclose information).
- Damages. Actual damages from the breach, often specified as including consequential damages and sometimes liquidated damages.
- Attorney's fees. Awarded to the prevailing party (if the clause so provides).
- Specific performance. Required return of the information.
A damages clause that attempts liquidated damages for an unlimited amount is often unenforceable as a penalty. A clause that acknowledges that monetary damages are inadequate and specifies injunctive relief as available is usually enforceable.
Common NDA mistakes
Short list of frequent errors:
- Accepting a one-way NDA when mutual coverage is appropriate.
- Accepting a broad definition of confidential information without exclusions.
- Accepting a perpetual term for ordinary business information.
- Accepting a Purpose definition narrower than the actual intended use.
- Failing to negotiate residuals carve-out expectations.
- Missing the DTSA whistleblower-notice language in employee NDAs.
- Ignoring the return-or-destruction clause's technical impossibility.
Where DocAssessment fits
DocAssessment does not have an NDA-specific extractor. NDA phrases are scored inside the generic contract bucket by the same keyword-based detector used for every document type, so a qualifying NDA is classified as a contract document. It gets the same contract extractor as any other agreement: parties, scope of work, payment terms and schedule, liability and termination clauses, termination notice, governing law, jurisdiction, and effective and expiration dates, before any AI model sees the document. The methodology page describes the seven-step pipeline. The contract schema has no field for an NDA's one-way-versus-mutual structure, its survival period, a residuals carve-out, or DTSA whistleblower-notice language. The heuristic risk engine can flag a handful of whole-clause categories it already recognizes, such as arbitration, liability, and termination-penalty language, when the surrounding text matches its patterns. It does not itemize gaps specific to NDAs.
For specific NDA negotiations — especially in M&A, strategic partnerships, or employee matters — a transactional attorney typically is the right next step before signing.
References
- Cornell Legal Information Institute: Nondisclosure Agreement — accessed April 2026.
- Cornell Legal Information Institute: Trade Secret — accessed August 2026.
- US Patent and Trademark Office: Trade Secrets Basics — accessed April 2026.
- 18 USC Chapter 90 — Protection of Trade Secrets — accessed April 2026.