Last updated on August 8th, 2026 at 01:25 pm
TL;DR: A non-disclosure agreement (NDA) is a legally binding contract that obligates one or more parties to keep specified information secret. It is the standard first document signed before sharing anything sensitive, business plans, source code, financials, customer data, trade secrets, or strategic roadmaps. There are three main structures: unilateral (one party discloses), mutual (both disclose), and multilateral (three or more parties). An NDA works by defining what counts as confidential, who is bound, what they can and cannot do with the information, how long the obligation lasts, and what the consequences of breach are. It is enforceable as a contract under Indian law and in most jurisdictions globally. The clauses that decide whether an NDA actually holds up in practice, specifically the definition of confidential information, the carve-outs, and the remedies, are where most agreements fail. This guide covers all of it: the law, the clauses, the global picture, and what to do when someone breaks one.
Quick Answer: What Is a Non-Disclosure Agreement?
A non-disclosure agreement (NDA), also called a confidentiality agreement (CA), is a contract in which one or more parties agree to keep defined information confidential and not to use or disclose it beyond the permitted purpose. It converts an informal expectation of privacy into a legally enforceable obligation. Without an NDA, there is no contract, and no reliable legal remedy, if the other party walks away with your secrets.
NDAs are used in every commercial context: investor pitches, employment and contractor onboarding, mergers and acquisitions, vendor relationships, partnership negotiations, product development, and licensing discussions. The reason the NDA is almost always the first document signed is simple: once information is out, it cannot be taken back. The NDA is signed before the information changes hands, not after.
Why Most NDAs Fail, and Why It Matters Before Anything Else
Before diving into types and clauses, there is one finding worth putting at the centre of this guide, because it is the single most common reason NDAs do not hold up when tested.
The definition of confidential information is either too broad or too vague, and courts use it to invalidate the agreement.
In practice, this looks like one of two failure modes. The first: the definition says something like “all information exchanged between the parties.” Courts in the US, UK, India, Singapore, and most other jurisdictions treat this as overreaching. If everything is confidential, the concept loses meaning, and judges have routinely refused to enforce blanket definitions on the basis that they are unreasonable. The second: the definition is so narrow or specifically enumerated that information the disclosing party assumed was protected turns out to fall outside it.
A well-drafted definition of confidential information specifies the categories of information covered (technical, financial, commercial, strategic, operational), identifies the specific subject matter of the disclosure (for example, “information relating to the development of “Product Name”), may require marking or identification of confidential materials in writing, and sits alongside a clear list of carve-outs for information that is excluded.
Everything else in the NDA depends on getting this right. If you take one thing from this guide, it is this: the definition clause and the carve-outs are where enforceable NDAs are won or lost. The NDA drafting service at MyLegalPal ensures this clause is airtight before anything else.
The Three Types of NDA, and How to Choose the Right One
Unilateral (One-Way) NDA
One party (the disclosing party) shares confidential information with another (the receiving party). Only the receiving party is bound by the confidentiality obligation. The disclosing party has no restriction.
When to use it: investor pitches, sharing a business plan with a potential partner, employee and contractor onboarding where the company discloses proprietary information, vendor relationships where you are giving a supplier access to your processes or IP.
The structural risk: if the relationship ends up being genuinely two-way, if the other party also starts sharing confidential information, the unilateral NDA leaves the disclosing party unprotected. This is a common oversight in early-stage startup relationships where founders share information with advisors and advisors share strategic frameworks that they also want protected.
Mutual (Bilateral, Two-Way) NDA
Both parties disclose confidential information to each other. Both are bound.
When to use it: M&A discussions, joint venture negotiations, technology partnerships, co-development arrangements, any situation where both sides will share sensitive material during the relationship.
The structural point: a mutual NDA is not just two unilateral NDAs in one document. The obligations are usually symmetrical, but the confidential information of each party is separately defined. Getting the definitions right on both sides is essential.
Multilateral NDA
Three or more parties are involved. One or more parties disclose; all receiving parties are bound. A single multilateral NDA replaces the web of bilateral NDAs that would otherwise be needed between each pair of parties.
When to use it: consortium arrangements, multi-party joint ventures, complex technology deals with multiple subcontractors, any transaction where more than two parties need to share and protect information simultaneously.
The practical advantage is efficiency, one document, one signature round. The drafting complexity is higher because the definition of confidential information and the obligations must work correctly for each combination of disclosing and receiving parties.
The Definition of Confidential Information: The Clause That Decides Everything
This section exists because the definition of confidential information deserves far more attention than most NDA guides give it. It is not a formality. It is the clause that will determine, in any enforcement action, whether your NDA is worth the paper it is printed on.
What a Strong Definition Contains
A strong definition of confidential information works on three levels.
First, it defines by category. It specifies the types of information that are covered: technical information (source code, algorithms, engineering specifications, formulas, processes, prototypes, test results), business information (financial data, pricing, customer and supplier lists, business strategies, market research, forecasts), and operational information (internal procedures, personnel information, contractual arrangements). Category-based definitions are preferable to exhaustive lists because they capture information in the relevant domain without needing to enumerate every possible document.
Second, it defines by subject matter. The best NDAs tie the definition to the specific subject matter of the disclosure. “Information relating to the disclosing party’s development of [Product X] and its commercial launch plans” is much more enforceable than “all business information.” Courts understand what the parties were trying to protect.
Third, it may require marking or identification. Some NDAs require confidential information to be labelled “Confidential” at the time of disclosure, or if orally disclosed, to be identified as confidential within a specified number of days. This is not always practical in relationships where information flows continuously, but for discrete disclosures, a specific presentation, a document set, a data room, it adds clarity.
What a Strong Definition Excludes (The Carve-Outs)
Carve-outs are not concessions. They are essential elements of a reasonable NDA. Without them, the agreement is over-broad, courts may not enforce it, and parties waste time disputing information that has no business being protected.
Standard carve-outs include:
Information that is or becomes publicly available through no act or omission of the receiving party. The key qualifier is “through no act or omission.” If the disclosing party themselves publish the information, the receiving party is no longer bound. If the receiving party leaks it and it becomes public as a result, the carve-out does not apply.
Information that was already known to the receiving party before the disclosure. This must be demonstrably pre-existing, ideally documented with timestamps, prior communications, or existing files. A receiving party who claims prior knowledge without documentation rarely succeeds.
Information independently developed by the receiving party without using the confidential information. This is important for technology companies and any party with active R&D. If a receiving party arrives at the same result through parallel research without using the disclosing party’s information, they should not be bound.
Information lawfully received from a third party who is not under a confidentiality obligation to the disclosing party. If a competitor independently discloses the same information to the receiving party legitimately, the receiving party is not in breach for knowing it.
Information required to be disclosed by law, regulation, or court order. This carve-out must be carefully drafted. Standard practice is to require the receiving party to give the disclosing party notice and an opportunity to seek a protective order before complying with any compelled disclosure, to the extent legally permitted.
The Key Clauses in Every NDA: What They Must Say
Permitted Use and Obligations
The NDA must state the single permitted purpose for which the receiving party may use the confidential information. “For the purpose of evaluating a potential commercial transaction between the parties” is a typical permitted purpose in a pre-deal context. “For the purpose of providing software development services under the Services Agreement dated [date]” is a typical permitted purpose in a vendor context.
The receiving party’s obligations to protect the information should be stated explicitly: limit access to personnel with a need to know, require those personnel to be bound by equivalent obligations, apply no less than the same standard of care as they apply to their own confidential information of similar sensitivity (and in any event not less than reasonable care), not copy or reproduce the information beyond what is necessary for the permitted purpose.
Term and Duration
The term of an NDA has two components. The first is the term of the relationship, meaning how long the NDA is active. The second is the duration of the confidentiality obligation, meaning how long the receiving party must maintain secrecy after the relationship ends or the NDA expires.
These are not the same thing and must be addressed separately.
An NDA might be active for the duration of merger discussions. The confidentiality obligation might survive the end of those discussions for three years. For trade secrets (information that retains commercial value precisely because it is not public), the confidentiality obligation can and often should be indefinite, lasting for as long as the information remains a trade secret.
A common drafting failure is to tie the duration of the confidentiality obligation to the term of the NDA, so that when the NDA expires after two years, all protection expires. If the parties’ relationship ended after six months and the confidential information is still commercially sensitive, this approach provides no protection at all. Confidentiality obligations should survive termination of the agreement, not expire with it.
In terms of specific durations: for general commercial NDAs, two to five years is standard. For employment and contractor NDAs involving trade secrets or client relationships, longer periods or indefinite duration for specific categories are appropriate and generally enforceable when limited to genuinely sensitive categories.
Return or Destruction of Information
When the NDA ends or the receiving party’s purpose is complete, the disclosing party typically has the right to require the return or certified destruction of all confidential information, including copies. This clause must address digital copies, backups, notes, and derivative works, not just physical documents. A certificate of destruction from the receiving party is standard practice.
Note that some jurisdictions permit the receiving party to retain archival copies for regulatory compliance purposes, and legal hold obligations may require retention of documents relevant to litigation even after an NDA requires destruction. The clause should account for these situations.
Injunctive Relief
This is one of the most important clauses in any NDA and one that is frequently omitted from template or poorly drafted agreements.
The problem with relying on damages alone after a confidentiality breach is that the harm is often impossible to quantify. If a former employee takes your customer list to a competitor, what are the precise financial damages? If a potential investor shares your product roadmap with a rival, how do you prove how much of your competitive advantage was lost? Courts struggle with these calculations, and the resulting damages awards are often inadequate.
Injunctive relief is a court order requiring the breaching party to stop the disclosure or use immediately. It does not require proof of specific financial loss, it requires proof of breach and a showing that damages would be inadequate. For most confidentiality breaches, the argument that damages are inadequate is straightforward.
A well-drafted NDA expressly acknowledges that breach would cause irreparable harm for which damages are inadequate, and that the disclosing party is entitled to seek injunctive and other equitable relief in addition to any other remedy. This language matters because some courts look for explicit contractual acknowledgment before granting expedited injunctive relief.
Governing Law and Jurisdiction
The choice of governing law shapes everything: the enforceability of the confidentiality obligation, the duration of protections, and the remedies available. This matters more in cross-border NDAs than in domestic ones, but even domestic NDAs in federal systems (US, India, Australia) should specify the state or jurisdiction.
For cross-border NDAs, arbitration is generally preferable to court litigation. An arbitral award is enforceable in over 160 countries under the New York Convention, whereas a court judgment from one country can be very difficult to enforce in another. The arbitration clause should specify the seat (not just the venue), the arbitral rules, the number of arbitrators, and the language.
NDA vs Confidentiality Clause vs Non-Compete vs IP Assignment: The Confused Set
These four documents are frequently confused with each other, combined incorrectly, or used as substitutes for each other when they serve fundamentally different purposes.
NDA vs Confidentiality Clause
A standalone NDA is a separate contract whose entire purpose is confidentiality. It is used at the beginning of a relationship, before a larger contract exists, or where confidentiality is the primary concern and there is nothing else to document. It is also used between parties who are not yet in a formal commercial relationship.
A confidentiality clause is a provision within a larger contract, an employment agreement, a services agreement, an M&A share purchase agreement, but it does the same job as one clause within a larger agreement. The advantage is consolidation: if there is already a contract governing the relationship, a confidentiality clause inside it is cleaner than a separate NDA running in parallel.
The practical rule: if you are at the start of a conversation and no other contract exists, use a standalone NDA. Once the commercial contract is in place, the confidentiality clause in that contract generally takes over and the standalone NDA becomes secondary or superseded.
NDA vs Non-Compete
An NDA restricts what the receiving party can do with specific information. A non-compete restricts what a person can do professionally: which clients they can work with, which companies they can join, and which business activities they can engage in.
These are fundamentally different in their legal treatment. Non-compete clauses are far more legally controversial and restricted than confidentiality obligations in almost every jurisdiction.
In India, Section 27 of the Indian Contract Act, 1872 voids agreements in restraint of trade. Post-termination non-competes in employment contracts are routinely struck down by Indian courts. A confidentiality obligation, by contrast, is a legitimate and enforceable protection of business interests, not a restraint of trade.
The mistake that causes significant legal problems is conflating the two: drafting an NDA that effectively functions as a non-compete by defining confidential information so broadly that it covers all knowledge the receiving party has gained in an industry, or by building in obligations that prevent the person from working in their field. Courts see through this. The NDA gets challenged on Section 27 grounds even though it is labelled a confidentiality agreement.
Keep them separate. If you need both a confidentiality obligation and a non-compete, draft them as distinct provisions and ensure the non-compete is carefully calibrated for enforceability. NDA vs IP Assignment Agreement
An NDA protects information by restricting what the receiving party can disclose or do with it. An IP assignment agreement transfers ownership of intellectual property from one party to another.
These are complementary, not interchangeable. An NDA during a product development project keeps the project details confidential. But the NDA does not determine who owns the code, the design, or the invention that results from the project. That requires an IP assignment agreement.
For startups and technology companies in particular, this distinction is critical. The IP due diligence that investors conduct before funding will check both: are the company’s secrets protected by NDAs, and does the company actually own the IP it has created? An NDA with contractors who built your product does not make the company the IP owner, that requires a properly drafted assignment clause or a separate IP assignment agreement.
The broader picture of why startups lose ownership of their own product is directly connected to the confusion between these two documents.
NDAs in India: The Full Legal Picture
Enforceability Under the Indian Contract Act, 1872
NDAs are enforceable in India as contracts under the Indian Contract Act, 1872, subject to the usual requirements for a valid contract: free consent, lawful consideration, competent parties, and a lawful object.
A well-drafted NDA with a precise definition of confidential information, clear obligations, and a defined term is enforceable. Indian courts have consistently upheld confidentiality obligations as legitimate protections of business interests. Remedies available include:
Injunction: a court order restraining the breaching party from continuing the disclosure or misuse. Available under Order 39 of the Code of Civil Procedure, 1908, and under Section 37 of the Specific Relief Act, 1963. Urgency applications can be heard ex parte (without the other side present) in genuine emergencies.
Damages: compensation under Section 73 of the Indian Contract Act for loss that naturally arose from the breach.
Account of profits: where the breaching party has profited from the confidential information, the disclosing party may seek disgorgement of those profits.
The Section 27 Line
Section 27 of the Indian Contract Act voids agreements in restraint of trade. A pure confidentiality obligation that says you cannot disclose specific information is not a restraint of trade and is enforceable. An obligation that in substance prevents a person from working in their professional field by making all their industry knowledge “confidential” is a restraint of trade and is vulnerable.
The rule for Indian NDAs: define confidential information specifically, not as a proxy for general professional knowledge. If a software engineer works on your platform for two years, their obligation not to disclose your source code and architecture is legitimate. An obligation that purports to make everything they learnt about software engineering while working with you “confidential” would face serious enforceability challenges under Section 27.
Data Protection: The DPDP Act, 2023 Layer
Where the confidential information includes personal data of customers, employees, or other individuals, the NDA now sits alongside the Digital Personal Data Protection Act, 2023. The DPDP Act imposes obligations on the handling of personal data regardless of what the NDA says, data minimisation, purpose limitation, security safeguards, breach notification obligations, and obligations to assist data principals in exercising their rights.
For any NDA in India involving the sharing of personal data, the data protection obligations must be addressed either within the NDA itself or in a separate Data Processing Agreement (DPA). Our DPA template covers these obligations.
Stamping
Under the applicable State Stamp Acts, an NDA should be adequately stamped to be admissible as evidence in Indian courts. The stamp duty varies by state and depends on the value of the consideration and the nature of the document. Failing to stamp does not render the agreement void, but an unstamped document may be inadmissible until stamp duty plus penalty is paid.
Where NDAs Matter Most in Indian Startup Practice
NDAs are a foundational document in three specific Indian startup contexts.
The first is investor relations. Before any pitch, term sheet discussion, or due diligence process, a mutual NDA between the startup and the investor protects both the startup’s proprietary information and any investment strategy or portfolio information the investor shares. For the startup, the NDA is protection against an investor sharing the pitch with competitors or passing the technology details to portfolio companies.
The second is contractor and vendor relationships. Indian startups rely heavily on freelancers, development agencies, and outsourced service providers. The difference between an employee and an independent contractor has major implications for IP ownership and confidentiality obligations. A contractor NDA is essential before sharing any proprietary technical or business information.
The third is co-founder and founding team arrangements. Before the formal founding documents are in place, and during the period of early exploration and product development, NDAs between co-founders and early team members protect the idea and the work while the relationship is being formalised. The founders’ agreement eventually supersedes or incorporates these protections.
For employment contexts, our guide on employment contracts in India covers how to structure these correctly.
NDAs Globally: The Jurisdiction-by-Jurisdiction Picture
NDAs are enforceable across most of the world’s major commercial jurisdictions, but the specifics (what can be protected, for how long, and by what remedies) differ in ways that matter for cross-border deals.
United States
NDAs are heavily used and robustly enforced in the US. Trade secret protection is reinforced federally by the Defend Trade Secrets Act (DTSA) 2016, which creates a federal civil cause of action for trade secret misappropriation and allows for the seizure of misappropriated trade secrets in extraordinary circumstances. State trade secret laws (most based on the Uniform Trade Secrets Act) provide additional protection.
Key US points: courts scrutinise duration, geographic scope, and the reasonableness of the confidentiality definition, particularly in employment contexts. California has specific restrictions on NDAs used to silence employees from reporting illegal conduct. Recent legislation under AB 2088 and its successors limits the use of NDAs in settlement agreements involving sexual harassment, discrimination, and workplace safety violations. NDAs that prevent employees from reporting violations to regulatory agencies are unenforceable.
Our contract lawyers in the USA advise on US-law NDAs across all states.
United Kingdom
NDAs (commonly called confidentiality agreements in UK practice) are enforceable and governed by general contract law, with trade secrets protected by the Trade Secrets (Enforcement, etc.) Regulations 2018 (implementing the EU Trade Secrets Directive, retained post-Brexit).
The UK has seen significant legislative and regulatory scrutiny of NDAs following their use to silence victims of harassment and discrimination in employment contexts. The Economic Crime and Corporate Transparency Act 2023 and Parliamentary debates have signalled tightening of restrictions. UK courts will not enforce NDA provisions that prevent disclosure of criminal conduct, protected disclosures under whistleblowing legislation, or co-operation with regulatory investigations. Duration must be reasonable.
Our contract lawyers in London advise on UK-law NDAs.
European Union
NDAs are enforceable across EU member states, reinforced by the EU Trade Secrets Directive 2016/943, implemented into national law across all member states. The Directive provides a harmonised definition of trade secrets (information that is secret, has commercial value because it is secret, and has been subject to reasonable steps to keep it secret) and minimum standards for protection and remedies.
GDPR applies wherever confidential information includes personal data of EU data subjects, regardless of where the NDA parties are located. Data Processing Agreements are required where a receiving party processes personal data on behalf of a disclosing party.
Our contract lawyers in the EU advise on EU-law NDAs.
Singapore
Singapore is a major hub for cross-border NDAs in the Asia-Pacific region, particularly in technology, investment, and commercial transactions. NDAs are fully enforceable under the general law of contract and the common law of confidentiality. Singapore’s courts are sophisticated, commercially oriented, and generally willing to grant injunctive relief promptly.
For cross-border NDAs in the region, Singapore is frequently chosen as the governing law and arbitral seat (under SIAC rules) because of its enforceability, neutrality, and the international enforcement of SIAC awards under the New York Convention.
Our contract lawyers in Singapore advise on Singapore-law NDAs.
UAE and Dubai
NDAs are increasingly important in the UAE context as Dubai and Abu Dhabi have grown as hubs for technology, finance, and investment. NDAs are enforceable in the UAE, with the Dubai International Financial Centre (DIFC) courts offering a particularly sophisticated and internationally recognised enforcement mechanism for those operating within the DIFC free zone.
Federal Decree Law No. 26 of 2020 on Commercial Transactions and the DIFC Contract Law provide the framework. Confidentiality obligations in employment agreements are enforceable but must be reasonable in scope.
Our contract lawyers in Dubai advise on UAE-law NDAs.
Canada
Canada operates under both common law (for most provinces) and civil law (Quebec), with NDAs enforceable under contract law principles in all jurisdictions. Trade secret protection operates through tort law (breach of confidence) at common law and, increasingly, through statutory provisions. Recent legislative discussions around a federal trade secrets statute have not yet resulted in enacted legislation.
Our contract lawyers in Canada advise on Canadian NDAs.
The Common Thread Across Jurisdictions
NDAs are enforceable almost everywhere that commerce happens. The points of variation are: the duration considered reasonable, the treatment of NDAs in employment contexts (where courts and legislatures in most jurisdictions impose greater scrutiny than in commercial B2B contexts), the statutory reinforcement of trade secret protection, and the specific rules around NDAs used to suppress disclosure of unlawful conduct. A cross-border NDA should specify its governing law, and that governing law should be reviewed against it.
How to Enforce a Breached NDA: The Practical Playbook
Discovering that the other party has breached your NDA is not the end. The response matters, and the speed of that response matters enormously.
Step 1: Preserve Evidence Immediately
Before doing anything else, document the breach. Screenshot the disclosure, save the emails or messages, capture the online post, preserve the document that was shared without authorisation. Digital evidence is volatile. It can be deleted, edited, or hidden. A screenshot with a timestamp, combined with a notarised declaration of what it shows, creates admissible evidence.
If the breach involves digital assets, a file emailed to a competitor, code shared in a repository, or customer data that was extracted, you should preserve server logs, access logs, and email metadata. Your IT team or a digital forensics specialist can assist. In India, the Information Technology Act, 2000 provides for the admissibility of electronic records as evidence.
Step 2: Send a Written Demand Immediately
As soon as the breach is confirmed, send a written legal notice to the breaching party: a formal cease and desist letter demanding that they immediately stop the disclosure or use of the confidential information, confirm in writing within a specified period (typically 72 hours to seven days) that they have stopped, return or certify the destruction of all confidential materials, and identify all third parties to whom the information has already been disclosed.
The letter should be sent by email (with read receipt) and by registered post simultaneously. In India, a legal notice under Section 80 of the Code of Civil Procedure can be sent before civil litigation. Our legal notice for breach of contract service provides advocate-drafted notices from ₹2,999.
The legal notice serves several purposes. It creates a formal record that you acted promptly on discovering the breach. It gives the other party a final opportunity to comply without litigation. And in the context of an injunction application, it demonstrates to the court that you demanded cessation and were refused. That strengthens the case for urgent relief.
Step 3: Apply for an Injunction
If the breach is ongoing or the demand goes unanswered, file for injunctive relief promptly. In India, an application for an interim injunction under Order 39, Rules 1 and 2 of the Code of Civil Procedure can be filed alongside the main civil suit. Courts can hear injunction applications on an urgent basis, and in clear cases of ongoing breach can grant ex parte relief (without hearing the other side first) to stop the disclosure immediately.
The three factors a court considers for an interim injunction are: prima facie case (the applicant has a plausible legal case), balance of convenience (the harm from refusing the injunction is greater than the harm from granting it), and irreparable harm (damages would not adequately compensate the applicant). In NDA breach cases involving genuine trade secrets, all three factors typically favour the applicant.
Speed is critical. Delay in applying for an injunction is itself an argument against granting it, if you waited, a court may infer the harm is not as irreparable as claimed.
Step 4: Pursue Damages and Account of Profits
Alongside or following the injunction application, pursue damages for the loss caused by the breach. In cases where quantifying specific financial loss is difficult (which it often is in confidentiality breaches), courts may apply a broader assessment of compensatory damages or order an account of profits, requiring the breaching party to disgorge the profit they made from using the confidential information.
Where the NDA contains a liquidated damages clause specifying a pre-agreed amount for breach, that clause is relevant to the damages claim, though Indian courts retain discretion to reduce unreasonable liquidated damages under Section 74 of the Indian Contract Act.
Step 5: Consider Criminal Remedies Where Applicable
In India, certain NDA breaches overlap with criminal law. If confidential information constitutes a trade secret and the breach involves the misappropriation of electronic data, the Information Technology Act, 2000 may provide criminal remedies. Where the breach involves fraud or breach of trust, the Indian Penal Code provisions on criminal breach of trust (Section 405) and cheating (Section 420) may apply. Criminal remedies are not always appropriate or available, but they are worth assessing with your lawyer where the breach is wilful and egregious.
If the breach involves publicly disclosing or threatening to disclose confidential information to extract money or advantages, extortion provisions under the IPC may be relevant.
NDAs in Employment: What Employers and Employees Both Need to Know
Employment NDAs are among the most commonly signed and most frequently misunderstood contracts in commerce. A few points that affect both sides.
For Employers
An employment NDA should be signed at the start of employment, ideally as part of the employment contract or on the first day. An NDA signed mid-employment may face consideration challenges (what did the employee receive in exchange for the new restriction after they were already employed?).
The NDA should clearly distinguish between confidential information (what the employee cannot disclose) and IP ownership (who owns what the employee creates during employment). These are separate legal questions that are often combined in a single document without adequate separation. For the IP ownership piece, our guide on employment contracts in India covers what must be in the employment contract to ensure the employer owns employee-created work.
Post-termination confidentiality obligations in employment NDAs are enforceable in India for specific, defined categories of confidential information. Non-compete restrictions post-termination face Section 27 challenges. Keep these separate and carefully calibrated.
For Employees and Contractors
Before signing an employment NDA or contractor confidentiality agreement, read the definition of confidential information carefully. If it is so broad that it would cover everything you have ever learnt in your professional career, it may be unenforceable, but litigating that point is expensive and time-consuming. Better to negotiate a narrower definition upfront.
Understand what the permitted use clause says. Some NDAs say you can use the confidential information only for the specific project you are engaged on. If you move to a different project at the same company, the earlier NDA technically does not cover the new work. This is occasionally used as a gap in IP ownership arguments.
If you are a contractor (not an employee), remember that the NDA does not resolve the IP ownership question. As discussed above, a contractor NDA and an IP assignment agreement are different documents that both need to be in place for the commissioning party to have complete protection. Our guide on work for hire vs independent contractor agreements is essential reading if you are on either side of this.
NDAs for Startups: The Three Situations That Require Specific Attention
1. Pitching to Investors Without an NDA
Many investors refuse to sign NDAs before hearing an initial pitch. This is standard practice, especially at the early pitch stage, for two reasons: the investor may be seeing dozens of pitches on similar ideas, and signing NDAs for each would create impossible conflicts. Asking a venture fund to sign an NDA before a first pitch meeting will often result in the meeting being declined.
The practical response: do not share your most sensitive technical details (source code, specific algorithms, unreleased proprietary data) in the initial pitch. Share enough to demonstrate the opportunity. Save the deep technical disclosure for due diligence, at which point an NDA is entirely appropriate and expected. Most reputable investors will sign an NDA at the due diligence stage.
Where the startup’s core value is in a genuinely novel technical method, a provisional patent application filed before any disclosure provides protection that does not depend on NDA compliance.
2. NDAs with Co-Founders and Early Team
Before the company is formally incorporated and shareholder agreements and employment contracts are in place, the people building the startup are sharing sensitive information with each other on the basis of mutual trust and a shared vision. If the relationship breaks down, and co-founder breakdowns are not uncommon, who owns what can become severely contested.
An NDA between founding members, executed at the beginning of the relationship, protects proprietary information during the formation phase. It should be replaced or supplemented by the founders’ agreement once the company is incorporated. Our guide on what every co-founder must legally settle before day one covers the full picture.
3. SaaS Platforms: NDAs in Customer and Vendor Relationships
For a SaaS company, confidentiality flows in multiple directions simultaneously. The company receives confidential data from customers (which may be personal data requiring DPDP or GDPR compliance). The company shares its proprietary technology with vendors and integration partners. And the company discloses its technical architecture to potential enterprise customers during the sales and security review process.
The legal documents every SaaS startup needs includes a full analysis of where NDAs fit alongside terms of service, data processing agreements, and acceptable use policies. The SaaS Agreement drafting service provides the complete commercial contract that incorporates or supersedes the NDA once a customer relationship is formalised.
Common NDA Mistakes to Avoid
Defining confidential information too broadly. The most common reason NDAs are not enforced. If the definition is overreaching, courts invalidate it or refuse to enforce it. Specific is enforceable. Broad is fragile.
Omitting the standard carve-outs. Makes the obligation over-broad and unreasonable. Courts expect carve-outs. Their absence signals poor drafting and can be used to challenge the entire definition.
No defined duration for the confidentiality obligation. A common drafting failure. Without a term, the obligation’s duration is uncertain and subject to a reasonableness challenge. Specify the duration. For trade secrets, an indefinite obligation limited to the period the information remains a trade secret is both appropriate and enforceable.
Tying confidentiality duration to the NDA term. If the NDA expires in two years, and the confidentiality obligation expires with it, you have no protection for information that remains sensitive after year two. Confidentiality obligations should survive termination of the agreement.
Forgetting injunctive relief. Without an express provision allowing the disclosing party to seek injunctive relief, the damages-only remedy is often inadequate. Every NDA should contain an express acknowledgment of the right to seek injunctive and equitable relief.
Using a one-way NDA when the relationship is two-way. If both parties are sharing, use a mutual NDA. A unilateral NDA leaves one side exposed.
Signing an NDA after the information has already been shared. The NDA creates prospective obligations. It does not retroactively protect information already disclosed without one. Sign before sharing.
Using a generic international template for an India-governed NDA without localisation. Stamp duty requirements, the Section 27 constraint, the DPDP Act data protection overlay, and Indian remedial procedure all require India-specific provisions that a generic global template will not contain.
Conflating the NDA with the non-compete. As discussed above, blending these two concepts in a single document is legally hazardous in India. Draft them as separate, distinct provisions.
Free NDA Template
Our free NDA template provides a fill-in-the-blanks starting point covering the definition of confidential information, carve-outs, permitted use, term and duration, return of information, injunctive relief, and governing law. It is designed to give you the structure and the standard language.
The template is a reference, not a substitute for professional drafting in any situation of significance. The right NDA depends on whether it is one-way or mutual, the sensitivity of the information, the parties’ jurisdictions, the relationship type, and the specific purpose of the disclosure. Use the template to understand what should be there, and have it professionally tailored or reviewed where the stakes are meaningful.
For a professionally drafted NDA, not a template, our NDA drafting service is prepared by qualified lawyers.
Frequently Asked Questions
What is a non-disclosure agreement (NDA)?
A non-disclosure agreement (NDA) is a legally binding contract in which one or more parties agree to keep specified information confidential and not to disclose or misuse it. It is used whenever sensitive information, business plans, financials, source code, trade secrets, customer data, must be shared with someone, while the disclosing party still needs to control how that information is used. An NDA defines what information is confidential, who is bound, what they may do with it, how long the obligation lasts, and what remedies apply on breach.
What are the types of NDA?
There are three main types. A unilateral (one-way) NDA binds only the receiving party, used when one side shares information. A mutual (two-way) NDA binds both parties, used when both sides share sensitive information. A multilateral NDA involves three or more parties and governs confidentiality between all of them in a single document, avoiding the need for multiple bilateral agreements.
Are NDAs enforceable in India?
Yes. NDAs are enforceable in India as contracts under the Indian Contract Act, 1872. Courts can award damages for breach and grant injunctions to restrain ongoing disclosure. The definition of confidential information must be specific enough to be reasonable. Care is required under Section 27 of the Contract Act to ensure the NDA does not cross into a de facto restraint of trade. The NDA should be adequately stamped for admissibility as evidence.
What should an NDA include?
A strong NDA contains: a precise definition of confidential information (by category and subject matter), standard carve-outs (publicly available information, prior knowledge, independent development, third-party disclosure, legally compelled disclosure), the permitted use of the information, the protection obligations, a defined term and confidentiality duration that survives the agreement’s term, obligations to return or destroy information, an express right to seek injunctive relief, and a governing law and jurisdiction clause.
How long does an NDA last?
NDAs typically set a confidentiality obligation of two to five years for general commercial information. For genuine trade secrets (information whose value depends on it remaining secret), an indefinite obligation (lasting as long as the information remains secret) is both appropriate and generally enforceable. The confidentiality obligation should be specified to survive the termination or expiry of the NDA itself, not expire with it.
What happens if someone breaches an NDA?
The disclosing party can pursue: an injunction to stop ongoing disclosure or misuse, damages for the financial loss caused by the breach, an account of profits where the breaching party profited from the confidential information, and in appropriate cases, criminal remedies under Indian law for breach of trust or misappropriation of electronic data. Speed matters, a prompt demand letter and an urgent injunction application are always more effective than delayed action. See our guide on what to do if someone breaches a contract for the broader framework.
What is the difference between an NDA and a confidentiality clause?
An NDA is a standalone contract whose sole purpose is confidentiality. A confidentiality clause is a provision within a larger contract (employment agreement, services agreement, M&A agreement) that achieves the same purpose as one clause among many. Use a standalone NDA at the beginning of a relationship before other contracts exist. A confidentiality clause inside the main commercial contract is cleaner once that contract is in place.
Can an employer make an employee sign an NDA?
Yes. NDAs are standard in employment relationships and routinely signed at the start of employment as part of the employment contract or as a separate document. Post-termination confidentiality obligations (restricting what the employee can disclose after leaving) are enforceable for specific categories of confidential information in India. Post-termination non-compete restrictions are a separate matter and face Section 27 challenges. The two should be drafted as distinct provisions.
Do investors always refuse to sign NDAs?
At the initial pitch stage, many investors decline to sign NDAs because they see many similar pitches and signing creates potential conflicts. This is standard practice and does not signal bad faith. At the due diligence stage, when detailed technical, financial, and strategic information is shared, an NDA is appropriate and most investors will sign one. The practical response is to share high-level information at the pitch stage and reserve the most sensitive technical disclosures for due diligence.
Is a verbal NDA enforceable in India?
An oral confidentiality agreement can theoretically be enforceable in India as a contract, but it is extremely difficult to prove in practice. The existence of the obligation, its specific terms, and the breach all become matters of disputed testimony rather than documentary evidence. NDAs should always be in writing. An oral assurance of confidentiality is not a substitute.
Other Articles on My Legal Pal
- IP Assignment Agreement: The Complete Guide, what comes after the NDA when IP ownership needs to be formally transferred
- What Is Breach of Contract?, the full framework for what constitutes a breach and what remedies are available
- Employment Contracts in India, how confidentiality and IP provisions work inside an employment agreement
- Legal Documents Every SaaS Startup Needs, where the NDA fits in the full SaaS legal document stack
- IP Due Diligence for Startups, what investors check before funding, including how NDAs and trade secret protection are evaluated
- Indemnity Clause Explained, how indemnity provisions work alongside NDA remedies
- Why Startups Lose Ownership of Their Own Product, the connection between NDA failures and IP ownership gaps
- Work for Hire vs Independent Contractor Agreements, the IP ownership complement to the contractor NDA
- Essential Contracts Every AI Startup Must Have, the specific confidentiality challenges in AI development contexts
Get Your NDA Drafted or Reviewed by a Lawyer
A poorly worded NDA is not legal protection. It is a false sense of security. If the definition of confidential information is too vague, or the carve-outs are missing, or there is no injunctive relief provision, the agreement will not hold up when you actually need it to.
Our NDA drafting service provides lawyer-prepared non-disclosure agreements tailored to your transaction, jurisdiction, and the type of information you need to protect. We draft unilateral, mutual, employment, startup, and cross-border NDAs. Starting from Rs. 2,999.
If you already have an NDA and want to know whether it will hold up, our contract review service covers that.
If you want to start with a template, our free NDA template gives you the full structure and standard language as a starting point.
For questions about your specific situation, ask a lawyer or speak to our contract lawyers in India.
Authored and reviewed by Prakhar Rai, Advocate, founder of My Legal Pal. Prakhar is enrolled with the Bar Council of India and has over ten years of experience advising businesses and founders on confidentiality, IP, and commercial contracts across India and cross-border. He is an alumnus of the National Law School of India University, Bangalore.
This article is general information, not legal advice. NDA law and enforceability vary by jurisdiction and by the facts. For advice on your specific NDA, speak to a qualified lawyer.







