eSign.AIeSign.AI

Glossary

What Are NDAs? A Complete Guide to Non-Disclosure Agreements

A non-disclosure agreement (NDA) is a legally binding contract that protects confidential information. Here is how NDAs work, when you need one, and how to sign them electronically.

eSign.AI Digital Trust Research Team8 min read

NDA in 60 seconds

A non-disclosure agreement (NDA), also called a confidentiality agreement, is a legally binding contract in which one or both parties agree not to disclose information covered by the agreement to third parties. NDAs protect trade secrets, business plans, customer lists, financial data, and other confidential information shared during business discussions, employment, or partnerships. In most jurisdictions, an NDA signed with an electronic signature is just as valid and enforceable as one signed with a wet-ink signature.

Purpose

Protects confidential information

Types

Mutual or one-way obligations

E-signature

Electronically signable & enforceable

Duration

Typical term: 2-5 years

How an NDA works

An NDA creates a legal obligation of confidentiality between the parties. The core mechanism is simple: the receiving party agrees to keep specified information secret and to use it only for an agreed purpose.

01

One party (the disclosing party) shares confidential information with the other (the receiving party). The information may be marked confidential, or its confidential nature may be implied by the context and the relationship between the parties.

02

The receiving party agrees to use the information only for the stated purpose (e.g., evaluating a partnership, an acquisition, or an employment role) and not to disclose it to anyone outside the agreement, except permitted representatives bound by the same duty.

03

If the receiving party breaches the duty, the disclosing party can seek remedies such as injunctions, damages, and termination of the relationship. Courts routinely enforce NDAs when the scope is clear and the information qualifies as confidential.

Types of NDAs

NDAs come in three common forms, distinguished by who owes the duty of confidentiality.

One-way (unilateral) NDA

Only one party discloses information and the other party receives it. The receiving party owes the confidentiality duty. This is common when a company shares its business plan with a potential investor or a supplier.

Mutual (bilateral) NDA

Both parties disclose confidential information to each other and both owe confidentiality duties. This is standard in joint ventures, mergers and acquisitions, and co-development agreements where each side shares sensitive data.

Employee / interview NDA

A specialised NDA used when a job candidate or employee will be exposed to trade secrets. It defines what information is confidential, how long the duty lasts, and can include non-solicitation and non-compete clauses in some jurisdictions (subject to local law).

What an NDA must contain

For an NDA to be enforceable, it should clearly define the parties, the protected information, and the scope of the obligation. A well-drafted NDA typically includes these elements.

Parties

Precisely who is disclosing and who is receiving. Ambiguous party definitions are a common reason NDAs fail in court.

Definition of confidential information

A definition of confidential information. The best NDAs describe categories of information (financial data, technical specifications, customer lists) rather than relying only on a 'confidential' marking requirement.

Term, purpose and exclusions

The duration of the confidentiality duty (often 2-5 years, or indefinitely for trade secrets), the permitted purpose of use, exclusions (public information, independently developed information), and the governing law and dispute resolution mechanism.

Execution and evidence

Signature blocks that capture who signed, when, and in what capacity. Electronic signature platforms record this automatically with an audit trail, which strengthens enforceability.

Key NDA clauses, explained line by line

Most NDA disputes turn on how a handful of clauses were drafted. Here is what each core clause does, and the drafting traps that weaken it.

Definition of confidential information

The definition drives everything: information is only protected if it falls inside this clause. Weak drafting says 'all information disclosed orally' with no written confirmation mechanism. Strong drafting lists categories (financial, technical, customer, strategic) plus a catch-all for information 'marked confidential or reasonably identifiable as confidential', and requires oral disclosures to be confirmed in writing within 30 days.

Permitted use and need-to-know

The duty must state what the recipient may do with the information (evaluate the transaction, perform the engagement) and who may access it (named employees, advisers bound by equivalent duty). A common failure is omitting a 'need to know' limit, which lets a recipient argue the duty was open-ended.

Term and survival

The term is usually 2-5 years for ordinary business information, but trade secrets should survive the agreement (indefinitely, in effect). The expiry clause must distinguish 'information' from 'trade secrets'; if it does not, a court may treat the whole duty as time-limited and strip trade-secret protection.

Exclusions and their proof burden

The most-litigated carve-outs are: publicly known information (must be 'through no breach of this agreement'), independently developed information (requires the recipient to prove independent development with records), and information already known to the recipient (best evidenced in writing before disclosure).

Remedies, governing law and dispute resolution

A remedy clause should preserve injunctive relief because damages are often inadequate for leaked trade secrets, and should state the governing law and forum. Cross-border NDAs should add an arbitration clause (e.g., SIAC, HKIAC, ICC) to avoid multi-jurisdiction litigation.

Cross-border NDAs: governing law and enforcement

When the disclosing party and recipient sit in different jurisdictions, three questions decide whether the NDA is worth the paper it is signed on.

Choice of law and forum

If the NDA is silent, a dispute can turn into a fight over which court hears the case before the merits are ever discussed. Choose the governing law and forum explicitly: the disclosing party's jurisdiction is the usual choice, because the law that protects the trade secret is the one the disclosing party knows. Some jurisdictions (e.g., EU member states) may override contractual choice of law with mandatory rules protecting employees and consumers.

Arbitration vs litigation

For multi-country deals, arbitration (SIAC, HKIAC, ICC, LCIA) is often more enforceable than court judgments because the New York Convention (172+ states) recognises arbitral awards nearly everywhere. Court judgments still require local recognition proceedings in many countries.

Data transfer compliance

Sharing personal data across borders (customer lists, HR data) triggers data-transfer rules: GDPR adequacy decisions or SCCs in the EU, PIPL cross-border transfer rules in China, and PDPA restrictions in Singapore and Malaysia. An NDA cannot override these; pair the NDA with a data-processing agreement where needed.

Trade secret regimes by region

Trade secret protection is not automatic everywhere. In the EU, the Trade Secrets Directive (2016/943) harmonises protection; in China, the Anti-Unfair Competition Law protects trade secrets but requires the holder to have taken confidentiality measures - which is exactly what a signed NDA evidences. In the US, the Defend Trade Secrets Act (2016) provides a federal cause of action, but state law varies.

Common NDA mistakes and how to avoid them

Most NDA disputes come down to drafting and process failures, not the signature method. These are the mistakes to avoid.

Vague or overbroad definition

Defining confidential information so narrowly that routine disclosures fall outside protection, or so broadly that a court finds the clause unreasonable. Use defined categories plus a 'marked or reasonably identifiable' catch-all.

Missing or unrealistic term

No expiry or an unrealistic perpetual term. Trade secrets may need indefinite protection, but non-trade-secret information should have a defined term. Courts dislike indefinite duties for ordinary business information.

No remedies or enforcement path

An NDA that covers confidentiality but not what happens on breach, or that lacks an exclusive-remedy clause. Include injunctive relief, damages, and attorney-fee provisions where appropriate.

Poor execution evidence

Sending an unsigned NDA, losing the signed copy, or failing to capture identity verification. An e-signature platform with an audit trail solves this: the signed PDF, timestamp, and signer identity records become the evidence package.

Common questions about NDAs

NDA stands for non-disclosure agreement, also known as a confidentiality agreement. It is a contract in which parties agree to keep specified information confidential.

How eSign.AI applies this in practice

eSign.AI lets you send an NDA for electronic signature in minutes, with signer identity verification, tamper-evident PDFs, trusted timestamps, and a complete evidence package. Every signature is recorded with the identity, time and consent data you need to enforce the agreement.

Legal review checklist

Use this page as a starting point, not as a legal conclusion. Confirm the jurisdiction, effective date, document type, signature method, identity step and evidence requirements with current primary sources before relying on it.

Jurisdiction

Country, state or sector and the transaction entities involved.

Source control

Primary source, effective date and reviewer.

Workflow proof

Completed test and retained evidence package for the target process.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.