How to draft a non-disclosure agreement (NDA) that protects your business
According to official data, 95% of civil agreements include an NDA. However, most companies rely on standard templates without adapting them to the specific deal or jurisdiction. Businesses often overlook crucial aspects such as evidence, enforcement mechanisms, and governing law. As a result, breaches of confidentiality frequently go unpunished. This is especially risky in international projects, where every clause must be carefully tailored. In this article, we will explore how to draft an NDA that truly protects your sensitive information, ensures enforceability across jurisdictions, and strengthens your legal position in case of a dispute.
Why do most NDAs fail in practice?
Many companies rely on standard non-disclosure agreement (NDA) templates without considering the legal intricacies. As a result, these agreements often fail to protect business interests in cases of conflict or data breaches.
Here are the most common mistakes companies make when drafting NDAs:
- Overly vague definitions of "confidential information". Without a precise list or concrete examples, courts may not recognize the data as protected.
- No sanctions for breaches. If no penalties or consequences are specified, a party disclosing confidential data may face no real loss.
- No mechanism for proving the breach. Without internal logging systems, access control protocols, and signed transfer records, it is nearly impossible to prove that a disclosure occurred.
- Using templates without jurisdictional consideration. A universal template may be invalid in a specific country or unenforceable in the desired jurisdiction.
According to research by the European Union Intellectual Property Office (EUIPO), more than 33% of companies in the EU have experienced a breach of confidential information, and in half of those cases, the NDA failed to uphold the company’s interests in court.
Key elements of NDAs that work
To ensure that an NDA serves its function — legally protecting confidential information and business interests — it must include specific and well-tested provisions.
What is confidential information?
A clear definition of what is being protected is the foundation of any NDA. Vague wording makes the agreement vulnerable in court. According to common law standards, confidential information is information that is not publicly available, has commercial value, and is disclosed under conditions of confidentiality. Under Article 2 of Directive (EU) 2016/943 on the protection of trade secrets, information must be secret, have commercial value, and be subject to reasonable steps to keep it confidential. This may include:
- Technical documentation and drawings
- Source code and software
- Business plans, strategies, and financial models
- Correspondence with clients or partners
- Know-how and methods not disclosed publicly
- Any other specific items or materials, which are considered by the Company as confidential according to its business activities and which it wishes to protect.
Excluded: information already published or known to third parties, as well as data required to be disclosed by law (e.g., by court order or regulatory request).
Important: include a sample list of confidential information in the NDA body or annex — this increases enforceability.
Rights and obligations of the parties
Clear obligations help avoid ambiguity and make the NDA legally sound.
- Who discloses and who receives. The NDA must clearly define the disclosing party and the receiving party, specifying their roles.
- Purpose of disclosure. The NDA should clearly state the purpose for which the information is shared — e.g., due diligence, contract negotiations, or audits.
- Restrictions on use. The receiving party must agree not to use the information for other purposes, not to disclose it to third parties, and to store it securely.
- Term and destruction of information. The NDA should set a term of validity (typically 2 to 5 years) and include an obligation to destroy or return the information after the cooperation ends.
Protection mechanisms and sanctions
Without clear consequences, an NDA loses its power as a preventive instrument. The agreement may include a fixed compensation amount or a formula for calculating damages, which simplifies legal protection in court. It is important that the amount is reasonable — otherwise it may be declared unenforceable. The NDA may also provide for the right to request an injunction to stop further use of the information in case of breach.
In case of NDA violation, additional measures may include revocation of IP usage rights (if they were granted), automatic termination of the main agreement, and an obligation to reimburse legal expenses.
How to sign NDAs with counterparties from different countries?
Companies often face challenges proving breaches, selecting an appropriate jurisdiction, and adapting provisions to local laws.
What qualifies as confidential information in one country may not be recognized as such in another. For example, in the U.S., the “reasonable steps to maintain secrecy” doctrine applies, while in EU countries, there are stricter requirements to formalize the list of protected information.
Even with a signed NDA, one party may challenge its enforceability by referring to its own national legal system. This is particularly relevant when the applicable law is not clearly stated in the agreement.
Practical solutions
- Multilateral NDA. In projects involving multiple parties (e.g., a startup, investor, and contractor), it is advisable to use a single NDA with a clearly defined applicable law and information disclosure rules.
- Tailored disclosure provisions. For investors — limit the use of disclosed information strictly to due diligence purposes. For developers — prohibit copying or reusing source code. For outsourcing teams — include a mandatory obligation to destroy all data after project completion.
- Use of neutral jurisdictions. If the parties cannot agree on using their national law, it is reasonable to select a neutral jurisdiction — for example, English law or Singaporean law. This helps balance interests, exclude the potential conflict of laws and simplify future dispute resolution.
- Inclusion of an arbitration clause. If a dispute does arise, the presence of an ICC, LCIA, or SIAC arbitration clause helps avoid prolonged litigation and increases the enforceability of the decision.
How to prove a breach of NDA?
Even a perfectly written NDA will not work without proof of a breach. In the event of a confidentiality leak, the availability and quality of evidence determine whether the company can obtain compensation or an injunction against further use of the disclosed data.
What is typically accepted as evidence:
- Log files and digital footprints. Metadata, system logs, and document access history on cloud platforms (e.g., Google Drive, Dropbox, SharePoint) can all serve as evidence of data leakage.
- Electronic correspondence. Emails and messages exchanged via platforms such as Telegram, WhatsApp, or Slack that explicitly or implicitly disclose or transmit confidential information.
- Access to internal systems. Records of IP addresses, user actions, timestamps, and verification through access control systems (such as SSO, Active Directory, etc.) can be critical.
- Technical audits and expert reports. In complex cases, companies often engage cybersecurity or digital forensics experts to analyze the leak channels and trace unauthorized disclosures.
- Witness statements. In some jurisdictions, it is admissible to rely on testimony from colleagues, employees, or even business partners to confirm that confidential information was disclosed to third parties.
According to DLA Piper, in the absence of digital evidence, more than half of NDA violation cases fail to reach a court ruling.
Often overlooked but crucial NDA clauses
Even well-drafted NDAs often omit certain critical clauses, which weakens their protective effect. These provisions can play a decisive role in legal disputes or unexpected changes in cooperation terms.
Survival clause
This clause specifies which obligations remain in force after the NDA expires. For instance, even if the agreement has ended, the duty not to disclose certain information may continue for 2–5 years or indefinitely.
Without such a clause, a court may interpret the obligations as no longer valid. This is particularly important in investment projects or R&D contexts, where data remains sensitive for years.
Non-circumvention clause
This provision prohibits a party from using the received information to establish direct contact with third parties, bypassing the disclosing party. It is commonly used in venture deals, international trade, and M&A transactions. For example, a partner may not bypass an intermediary and approach the end client after receiving their contact details under the NDA.
Penalty clause with a damage calculation formula
This clause stipulates a specific amount of compensation (or a formula to calculate it) in the event of a breach of NDA obligations. It may be expressed as a fixed amount (e.g., €100,000) or linked to the scale of damage (such as a percentage of the deal value or lost profits). This clause disciplines the parties and lowers the threshold for initiating litigation—there is no need to prove the exact loss amount.
Practical advice from Key2Law specialists
A reliable NDA is not just a formal document but a real legal protection tool. To make it work effectively, it’s crucial not only to draft it correctly but also to properly integrate it into your business processes.
- Use tailored NDAs for different counterparties. Universal templates don’t reflect the purpose of disclosure, the recipient’s status, or the specifics of the deal. An investor, a contractor, and a co-founder all come with different risks and require different terms.
- Specify the exact types of information. Instead of vague terms like “any confidential information,” list clear categories: technical documentation, source code, client databases, deal terms, and business plans.
- Appoint a person responsible for NDA enforcement. This can be an in-house lawyer, CFO, or project manager who monitors the NDA’s term, the data transfer process, and the existence of confirmation records.
- Store evidence of data transfers. Ideally, use neutral platforms with access logging (e.g., DocSend, Google Drive with role-based access). This significantly simplifies proof in case of a breach.
- Update the NDA when conditions or team composition change. New employees, a change in jurisdiction, or a shift in your company’s role (e.g., from contractor to partner)—all of these are valid reasons to revise the agreement.
Our experience shows: more than half of NDA-related disputes could have been avoided with a precise definition of confidential information and a functioning enforcement mechanism.
How can Key2Law help you create an NDA?
The Key2Law team specializes in drafting legally sound and internationally enforceable NDAs that can stand up in court and protect your business in case of a dispute. We know which provisions work across jurisdictions, and we help you avoid the common pitfalls.
We offer:
- Audit and revision of existing NDAs. We identify weak spots, eliminate risks of invalidity, and tailor the agreement to your corporate structure.
- Drafting NDAs for specific deals or counterparties. Whether it's an investor, contractor, developer, or co-founder, we consider the purpose of data sharing and the possible consequences of a leak.
- Preparation of bilingual or multilingual NDAs. We ensure compliance accuracy across languages and legal systems.
- Implementation of additional protection mechanisms. Arbitration clauses, penalty provisions, injunctions, and non-circumvention clauses—everything needed to make your NDA work in practice.
- Litigation support in case of NDA breaches. We collect the evidence, file claims, and ensure enforcement in the appropriate jurisdiction.
Do you want to be confident that your sensitive information is protected, not just written on paper? Contact Key2Law — we will turn your NDA into a true shield for your business.