What Should an NDA Actually Cover? A Practical Guide for Australian Businesses
Non-disclosure agreements, or NDAs, are commonly used when businesses need to share commercially sensitive information before entering into a transaction, partnership or other commercial arrangement.
They are often treated as relatively simple documents. In many cases, however, the effectiveness of an NDA depends less on whether it contains a general obligation to keep information confidential and more on whether the agreement properly reflects the information being disclosed, the reason it is being disclosed and the way the parties will actually use it.
This is particularly important for technology, SaaS and other businesses that may be sharing commercially valuable information about their products, customers, pricing, systems, intellectual property or future plans.
A well-drafted NDA should therefore do more than simply state that information must remain confidential. It should clearly define what information is protected, how that information may be used, who may receive it and what happens to the information once the commercial discussions come to an end. These are all matters addressed in the confidentiality deed materials provided.
What information should an NDA protect?
One of the most important parts of an NDA is the definition of confidential information.
The definition needs to be broad enough to capture the information that is likely to be disclosed, while still being clear enough for the parties to understand what is protected.
Depending on the transaction, confidential information may include financial information, pricing, business plans, budgets, forecasts, customer and supplier information, contracts, market research, technical information, software, databases, know-how and other commercially sensitive material.
For a technology business, the information may also include details about software architecture, product roadmaps, integrations, security controls, development plans, APIs or proprietary processes.
It is also worth considering how information will actually be exchanged. Businesses rarely share confidential information only through documents clearly marked “confidential”. Sensitive information may also be disclosed during meetings, demonstrations, calls, workshops and negotiations.
An NDA should therefore be drafted with the commercial relationship in mind rather than assuming that every piece of confidential information will be formally labelled before it is disclosed.
Not all information should remain confidential
A well-drafted NDA will usually exclude certain categories of information from the confidentiality obligations.
For example, information may not need to be treated as confidential if it is already publicly available, was already lawfully known by the recipient, was independently developed without using the confidential information or was lawfully obtained from another source.
These exclusions are important because an NDA should protect genuinely confidential information without attempting to restrict information that the recipient already has a legitimate right to use.
The purpose for which the information can be used matters
An NDA should not only restrict disclosure. It should also regulate how the recipient can use the information.
This is usually dealt with through a defined “Permitted Purpose”.
For example, a company may provide financial information and technical materials to another business so that the other business can assess a proposed acquisition, partnership or technology integration. The recipient should generally be able to use that information for the purpose of assessing and negotiating that transaction, but not for unrelated commercial purposes.
This distinction can be particularly important where the parties operate in the same industry or where the information being shared could provide a competitive advantage.
Preventing someone from publicly disclosing confidential information is only part of the protection. In many cases, it is equally important to prevent the information from being used for a purpose that the disclosing party never intended.
Who can receive the confidential information?
In practice, the company signing the NDA will often need to share the information internally or with professional advisers.
The agreement may therefore permit disclosure to certain approved people, such as directors, employees, lawyers, accountants, consultants, financiers or related companies.
The important issue is not simply who may receive the information, but what obligations apply once the information has been shared.
A business disclosing sensitive information will generally want to ensure that the people receiving it have a genuine need to know the information and are subject to appropriate confidentiality obligations. The NDA may also make the recipient responsible for breaches caused by employees, advisers or other approved recipients.
This is an important part of the risk allocation under the agreement. An obligation imposed on the company itself may provide limited practical protection if the information can then be passed to a broad group of people without appropriate safeguards.
Security obligations should reflect the information being shared
Confidentiality can be lost through poor information security as well as deliberate disclosure.
An NDA may therefore require the recipient to take reasonable or appropriate security measures to protect confidential information against unauthorised access, disclosure, misuse or loss.
The appropriate standard will depend on the nature of the information.
A company sharing a general business proposal may not require the same level of security as a company providing access to highly sensitive technical documents, proprietary datasets or other valuable commercial information.
For some transactions, a general obligation to take reasonable security measures may be sufficient. For others, more specific security or handling requirements may be appropriate.
What happens when negotiations end?
Businesses should also consider what happens to confidential information if the proposed transaction or commercial relationship does not proceed.
An NDA will often give the disclosing party the right to require confidential information to be returned, destroyed or deleted.
However, these obligations should also be commercially workable.
Information may be retained in automated backups, email archives, legal files, board papers or records that need to be kept for regulatory, insurance or professional purposes.
It may therefore be more realistic to allow certain information to be retained in limited circumstances while requiring that the retained information continues to be treated as confidential.
An absolute obligation to remove every copy of information from every system may sound protective but can be difficult, or sometimes impossible, to comply with in practice.
How long should confidentiality obligations continue?
There is no single confidentiality period that will be appropriate for every NDA.
The right period depends on the nature of the information being protected.
Some information loses its commercial value relatively quickly. Pricing, budgets and financial forecasts may become outdated within a few years.
Other information may remain commercially sensitive for a much longer period. This can include trade secrets, proprietary technology, source code, internal processes and valuable know-how.
For that reason, a confidentiality period should not simply be selected because two years, three years or five years appears in a template.
The more useful question is how long the particular information being disclosed is likely to remain commercially sensitive.
Should the NDA be mutual?
An NDA may be one-way or mutual.
A one-way NDA can be appropriate where only one party is expected to disclose confidential information. A mutual NDA may be more appropriate where both parties will exchange sensitive information.
For example, mutual confidentiality obligations are common in discussions involving strategic partnerships, technology integrations, joint ventures or other transactions where both businesses will be sharing information.
A mutual NDA is not automatically better simply because the obligations apply equally to both parties. The structure should reflect the actual flow of information between the parties.
Be careful when an NDA contains non-solicitation provisions
Some NDAs contain provisions that go beyond confidentiality.
One example is a non-solicitation clause that restricts a party from approaching or recruiting the other party's employees, customers, suppliers or other business relationships.
Other NDAs may include restrictions preventing a party from speaking with competing bidders or pursuing another transaction.
These clauses can sometimes be appropriate, particularly in certain transaction contexts, but they should not automatically be treated as standard confidentiality provisions.
They impose separate commercial restrictions on the parties and should be considered on their own terms.
If an NDA contains non-solicitation, no-shop or similar restrictions, it is worth considering whether those provisions are genuinely necessary for the proposed transaction and whether their scope and duration are reasonable.
An NDA should reflect the actual commercial arrangement
NDAs are often regarded as relatively low-risk documents, particularly when they are short.
The length of the document is not necessarily a good indication of the legal or commercial risk involved.
The important question is whether the NDA properly protects the information being disclosed and reflects the way the parties intend to use that information.
Before signing or sending an NDA, businesses should consider the information being shared, the purpose of the disclosure, the people who may receive the information, the security requirements, the duration of the confidentiality obligations and any additional provisions dealing with matters such as non-solicitation or indemnities.
For technology and SaaS businesses in particular, confidential information can include some of the most valuable information held by the business.
An NDA should therefore be more than a document that allows discussions to begin. It should provide a practical framework for protecting the information while those discussions take place.
Need help with an NDA?
Pixel Legal advises technology companies, SaaS businesses and other Australian businesses on NDAs, technology contracts and commercial agreements.
If you are preparing to share commercially sensitive information, have received an NDA from another business or want to understand the risks in an agreement before signing it, we can assist with preparing, reviewing and negotiating the document.
Disclaimer
This article provides general information only and is not legal advice. The appropriate terms of an NDA will depend on the parties, the information being disclosed and the particular transaction. You should obtain legal advice about your circumstances before entering into an NDA.