LinkedInInstagramXTikTok

Non-Disclosure Agreements (NDAs): What They Must Contain to Hold

Why the NDA is often the first thing put to the test

In almost every significant deal, you share information you would not want a competitor to see. It might be a pricing model ahead of a tender, source code ahead of a partnership, a customer list ahead of a sale of the business, or an idea ahead of an investor meeting. The non-disclosure agreement, or NDA, is the document meant to keep that information in place.

The trouble is that many NDAs are written to look reassuring rather than to work. They are either so broad that they become hard to enforce, or so vague that it is later unclear what was even covered. When a counterparty does abuse the trust placed in them, it turns out the agreement does not provide the protection you believed it did.

This article walks through what a non-disclosure agreement actually needs to contain in order to hold, the difference between one-way and mutual agreements, how it relates to the protection of trade secrets, and the limits an NDA can never cross.

What an NDA is and how it works

A non-disclosure agreement is a contract in which one or more parties undertake not to disclose or use certain information outside an agreed purpose. It creates a contractual duty of confidentiality between parties who would otherwise have had no such obligation toward one another.

The agreement rests on general principles of contract law. That means the parties are largely free to decide its content, but also that it only binds those who have signed it. An employee of your counterparty, for example, is not automatically bound by an agreement the company has entered into, unless the agreement is constructed so that it also reaches staff and subcontractors.

One-way or mutual

A one-way NDA means that only one party discloses information and only the receiving party takes on a duty of confidentiality. It suits situations where information flows in a single direction, for instance when you engage a consultant who will be given insight into your operations but does not share anything sensitive in return.

A mutual agreement means that both parties disclose and receive confidential information, and therefore carry the same obligations toward each other. This is the norm in negotiations between parties of equal standing, such as ahead of a collaboration, a merger, or joint product development. Many choose a mutual agreement even when only one party initially shares information, because it is often easier to negotiate and feels more balanced.

What counts as confidential information

The heart of an NDA is the definition of what is actually protected. This is where many go wrong by being either too narrow or too broad. An overly narrow definition leaves gaps, while an overly broad one, such as “all information exchanged”, risks not being taken seriously and becomes hard to apply when it matters.

A well-considered definition describes the categories of information covered, for example business plans, pricing models, technical documentation, customer data, and source code, and ideally states that information shared in writing should be marked as confidential. Equally important is specifying what is not covered: information that is already public, that the recipient already had, or that the recipient independently developed without access to the protected information.

Permitted use and permitted recipients

A good agreement states not only that the information must be kept secret, but also the single purpose for which it may be used. Information disclosed ahead of a possible deal should be used to evaluate that deal, and nothing else. The agreement should also govern who may access the information internally, typically employees and advisers who need it for the agreed purpose and who are themselves bound by a corresponding duty of confidentiality.

Permitted disclosures

No NDA can or should prevent the disclosure of information when the law requires it. The agreement should therefore expressly allow a party to disclose information to an authority or a court when there is a legal obligation to do so. A common and sensible construction is that the party forced to disclose should, where possible and lawful, first notify the other party so that it can protect its interests.

How an NDA relates to the protection of trade secrets

A non-disclosure agreement does not stand alone. Alongside the contract sits a statutory protection for trade secrets. In Sweden this is governed by the Trade Secrets Act, which is built on the EU Trade Secrets Directive and therefore follows a shared European baseline.

Statutory protection generally requires that the information is in fact kept secret and that the holder has taken reasonable measures to protect it. The NDA plays a double role here. On one hand it grants an independent contractual right to claim liability for a breach. On the other hand, the very existence of an NDA is clear evidence that you have treated the information as secret, which strengthens your position under the statutory protection as well. The agreement and the law reinforce one another.

It is wise to describe this at the level of principle rather than to rely on precise statutory provisions. The key takeaway is that a well-drafted NDA not only provides contractual protection, but also makes it easier to invoke the stronger protection the law affords to those who actively guard their secrets.

Duration of confidentiality and penalties

Two questions are often handled carelessly: how long the confidentiality should last, and what happens if the agreement is breached.

On duration, there is no single right answer. For much business information it is reasonable for the duty of confidentiality to apply for a set period after the collaboration ends, often a few years. For certain types of information, such as genuine trade secrets or source code, longer or indefinite confidentiality may be justified for as long as the information actually remains secret. A perpetual and unlimited duty of confidentiality covering all information, by contrast, is rarely appropriate and can be hard to enforce.

On penalties, the agreement should take a position on liquidated damages, known in Swedish practice as vite. An agreed penalty means that the party who breaches the agreement must pay a fixed sum, without the injured party having to prove exactly what loss occurred. This is often a significant advantage, because in practice it can be very difficult to prove and quantify the financial harm caused by a breach of confidentiality. The alternative, relying on ordinary damages, requires you to show both that harm occurred and how large it was. A well-balanced penalty, neither so low that it fails to deter nor so high that it appears unreasonable, makes the agreement considerably sharper.

A practical example: when the NDA is missing at the wrong moment

Imagine a SaaS company negotiating with a larger player about a possible partnership. During the first meetings the company openly shares its product roadmap, its pricing model, and how its technical integration is built, in order to show how well a collaboration would work. The NDA, they say, will be signed “once we get to something concrete”.

The collaboration fizzles out. A few months later the larger player launches its own feature that is strikingly similar to what the company presented. Because the information was shared before any NDA was in place, and without being marked as confidential, the company is in a very weak position. There is no agreed penalty to invoke and it is difficult to show after the fact that the information was treated as secret.

With an NDA signed before the first meeting, the situation would have looked different. The information would have been defined as confidential, its use limited to evaluating that specific partnership, and an agreed penalty would have given the company a concrete consequence to rely on. The lesson is simple: the agreement should be in place before the first sensitive information leaves the room, not afterward.

Common mistakes companies make

The most common mistake is sharing information before the agreement is in place. An NDA does not protect information that has already been disclosed. The natural rule is to sign the agreement before the first meeting where anything sensitive might come up.

A second mistake is an overly broad or vague definition of confidential information. When everything is claimed to be secret, it becomes hard in practice to argue that anything in particular was. A clear boundary is stronger than a sweeping phrase.

A third mistake is perpetual, unlimited obligations covering every conceivable piece of information without any time limit. Such clauses look powerful but may, in the worst case, appear unreasonable and thereby weaken the agreement.

A fourth mistake is forgetting to bind those who actually handle the information. If the counterparty’s employees and subcontractors are not captured by the agreement, the protection can be hollow at precisely the points where the information moves.

A fifth mistake is using the same template for entirely different situations. An NDA for an acquisition, one for a hire, and one for a vendor relationship have different needs, and a template that fits all of them usually fits none of them well.

Legal risks of a weak NDA

The most tangible risk is an agreement that cannot be enforced in practice. An agreement with a vague definition, no penalty, and no clear purpose may well be signed and feel reassuring, yet deliver very little when it is finally tested.

Another risk is an agreement that reaches too far. Clauses that in practice prevent a counterparty from operating in the same industry at all, or that impose an unreasonably burdensome duty of confidentiality on an individual, risk being adjusted or set aside entirely. An agreement a court considers unreasonable protects you less than a balanced one.

A third risk is relying on the NDA alone and neglecting practical measures. If you otherwise handle the information carelessly, spread it internally without control, or leave it openly accessible, you undermine both the contractual and the statutory protection. Protection of trade secrets presupposes that you actually treat the information as secret.

What an NDA can never do

There is a limit to what a non-disclosure agreement may govern, and that limit is important to know. An NDA can never be used to silence the reporting of misconduct or illegal acts.

An employee or a counterparty cannot contract away the right to raise the alarm about serious wrongdoing. There is a specific protection for whistleblowers, and companies of a certain size are required to have internal reporting channels. An NDA that attempts to prevent someone from reporting suspected crimes or serious misconduct conflicts with this protection and has no effect in that respect.

In the same way, an NDA cannot prevent anyone from providing information to an authority or a court when there is a legal obligation to do so, nor can it be used to conceal criminal activity. An agreement drafted as if it could do these things not only undermines its own credibility but may, in the worst case, appear to be an attempt to circumvent mandatory rules. A professionally drafted NDA is therefore explicit that the duty of confidentiality yields to the right to report misconduct and to statutory disclosure obligations.

Recommended actions

First decide whether the agreement should be one-way or mutual, based on how the information will actually flow. Sign the agreement before you share anything sensitive, not once the deal starts to firm up.

Define confidential information precisely enough for the protection to be meaningful, and expressly state what is not covered as well as the single purpose for which the information may be used. Govern which recipients may access the information internally and ensure that employees and subcontractors are covered too.

Set a considered duration rather than a sweeping perpetual obligation, and include a balanced agreed penalty so you avoid having to prove exact loss in the event of a breach. Make sure the agreement expressly leaves room for statutory disclosure obligations and for the right to report misconduct, so that it does not become ineffective in those respects.

Finally, complement the agreement with practical measures. Limit internal distribution, mark sensitive documents, and keep track of who has been given access to what. It is this combination of contract and actual conduct that produces protection that holds.

Frequently asked questions about NDAs

What is the difference between a one-way and a mutual NDA?

In a one-way agreement only one party discloses information and only the receiving party has a duty of confidentiality. In a mutual agreement both parties disclose and protect information and carry the same obligations. Mutual agreements are common in negotiations between parties of equal standing.

Does an NDA have to be in writing?

An oral undertaking can in theory be binding, but in practice a written agreement is essential. Without written form it becomes very difficult to show what was agreed and what information was covered, which leaves the protection almost worthless.

How long should confidentiality last?

It depends on the information. For much business data a set period after the collaboration ends is reasonable, while genuine trade secrets may justify longer protection for as long as the information remains secret. Unlimited confidentiality over all information, by contrast, is rarely appropriate.

Can an NDA stop an employee from reporting misconduct?

No. A non-disclosure agreement cannot contract away the right to report serious wrongdoing or illegal acts. Whistleblower protection and statutory disclosure obligations take precedence, and a clause that attempts to prevent such reporting has no effect in that respect.

Is an agreed penalty better than damages?

A penalty makes liability easier to enforce, because you avoid having to prove exactly what loss occurred. Ordinary damages require you to show both that harm took place and how large it was, which is often difficult in confidentiality breaches. A balanced penalty therefore makes the agreement more effective.

When do we need an NDA?

Typical situations include ahead of an acquisition, when hiring key people, in collaborations with vendors and consultants, and ahead of investor meetings. The rule of thumb is that an NDA should be in place every time you share information you would not want a competitor to see.

Conclusion

A non-disclosure agreement is one of the most widely used and, at the same time, most underestimated documents in business. The difference between an agreement that looks good and one that actually holds lies in the details: a precise definition, a clear purpose, a considered duration, a balanced penalty, and correct handling of the limits the law sets. Timing matters just as much, having the agreement in place before the first sensitive information leaves the room.

Lawgent helps companies design NDAs that genuinely protect your trade secrets while staying within the limits the law sets. We combine experienced business-law advice with AI-driven efficiency, so that you get an agreement tailored to your specific situation, faster and more cost-effectively than at a traditional firm. Are you facing a negotiation, a hire, or a collaboration where sensitive information will be shared? Contact Lawgent for a review of your non-disclosure agreements.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop