Protects confidential information
NDA in 60 seconds
A non-disclosure agreement (NDA), also called a confidentiality agreement, is a legally binding contract in which one or both parties agree not to disclose information covered by the agreement to third parties. NDAs protect trade secrets, business plans, customer lists, financial data, and other confidential information shared during business discussions, employment, or partnerships. In most jurisdictions, an NDA signed with an electronic signature is just as valid and enforceable as one signed with a wet-ink signature.
Mutual or one-way obligations
Electronically signable & enforceable
Typical term: 2-5 years
How an NDA works
An NDA creates a legal obligation of confidentiality between the parties. The core mechanism is simple: the receiving party agrees to keep specified information secret and to use it only for an agreed purpose.
One party (the disclosing party) shares confidential information with the other (the receiving party). The information may be marked confidential, or its confidential nature may be implied by the context and the relationship between the parties.
The receiving party agrees to use the information only for the stated purpose (e.g., evaluating a partnership, an acquisition, or an employment role) and not to disclose it to anyone outside the agreement, except permitted representatives bound by the same duty.
If the receiving party breaches the duty, the disclosing party can seek remedies such as injunctions, damages, and termination of the relationship. Courts routinely enforce NDAs when the scope is clear and the information qualifies as confidential.
Types of NDAs
NDAs come in three common forms, distinguished by who owes the duty of confidentiality.
One-way (unilateral) NDA
Only one party discloses information and the other party receives it. The receiving party owes the confidentiality duty. This is common when a company shares its business plan with a potential investor or a supplier.
Mutual (bilateral) NDA
Both parties disclose confidential information to each other and both owe confidentiality duties. This is standard in joint ventures, mergers and acquisitions, and co-development agreements where each side shares sensitive data.
Employee / interview NDA
A specialised NDA used when a job candidate or employee will be exposed to trade secrets. It defines what information is confidential, how long the duty lasts, and can include non-solicitation and non-compete clauses in some jurisdictions (subject to local law).
What an NDA must contain
For an NDA to be enforceable, it should clearly define the parties, the protected information, and the scope of the obligation. A well-drafted NDA typically includes these elements.
Parties
Precisely who is disclosing and who is receiving. Ambiguous party definitions are a common reason NDAs fail in court.
Definition of confidential information
A definition of confidential information. The best NDAs describe categories of information (financial data, technical specifications, customer lists) rather than relying only on a 'confidential' marking requirement.
Term, purpose and exclusions
The duration of the confidentiality duty (often 2-5 years, or indefinitely for trade secrets), the permitted purpose of use, exclusions (public information, independently developed information), and the governing law and dispute resolution mechanism.
Execution and evidence
Signature blocks that capture who signed, when, and in what capacity. Electronic signature platforms record this automatically with an audit trail, which strengthens enforceability.
Key NDA clauses, explained line by line
Most NDA disputes turn on how a handful of clauses were drafted. Here is what each core clause does, and the drafting traps that weaken it.
Definition of confidential information
The definition drives everything: information is only protected if it falls inside this clause. Weak drafting says 'all information disclosed orally' with no written confirmation mechanism. Strong drafting lists categories (financial, technical, customer, strategic) plus a catch-all for information 'marked confidential or reasonably identifiable as confidential', and requires oral disclosures to be confirmed in writing within 30 days.
Permitted use and need-to-know
The duty must state what the recipient may do with the information (evaluate the transaction, perform the engagement) and who may access it (named employees, advisers bound by equivalent duty). A common failure is omitting a 'need to know' limit, which lets a recipient argue the duty was open-ended.
Term and survival
The term is usually 2-5 years for ordinary business information, but trade secrets should survive the agreement (indefinitely, in effect). The expiry clause must distinguish 'information' from 'trade secrets'; if it does not, a court may treat the whole duty as time-limited and strip trade-secret protection.
Exclusions and their proof burden
The most-litigated carve-outs are: publicly known information (must be 'through no breach of this agreement'), independently developed information (requires the recipient to prove independent development with records), and information already known to the recipient (best evidenced in writing before disclosure).
Remedies, governing law and dispute resolution
A remedy clause should preserve injunctive relief because damages are often inadequate for leaked trade secrets, and should state the governing law and forum. Cross-border NDAs should add an arbitration clause (e.g., SIAC, HKIAC, ICC) to avoid multi-jurisdiction litigation.
Electronic signing of NDAs: legal validity
NDAs are routinely signed electronically. The legal basis is well established in most major jurisdictions.
United States (ESIGN / UETA)
The ESIGN Act and UETA provide that electronic signatures and records have the same legal effect as their paper equivalents for most contracts, including NDAs, provided the parties consent to electronic transactions.
European Union (eIDAS)
The eIDAS Regulation gives electronic signatures legal effect across the EU, with higher evidential weight for advanced (AES) and qualified (QES) signatures. An NDA signed with a simple electronic signature (SES) is generally valid; AES/QES strengthen the evidence chain.
Singapore & Hong Kong (ETA / ETO)
The Electronic Transactions Act and the Electronic Transactions Ordinance (Cap. 553) recognise electronic signatures for most commercial documents, with certain exclusions for deeds and court documents.
China (Electronic Signature Law)
The Electronic Signatures Law (2005) and the Civil Code recognise electronic signatures for commercial contracts. China also has specific rules for electronic contracts in e-commerce (E-Commerce Law 2019), and courts have upheld e-signed NDAs in trade secret disputes.
Cross-border NDAs: governing law and enforcement
When the disclosing party and recipient sit in different jurisdictions, three questions decide whether the NDA is worth the paper it is signed on.
Choice of law and forum
If the NDA is silent, a dispute can turn into a fight over which court hears the case before the merits are ever discussed. Choose the governing law and forum explicitly: the disclosing party's jurisdiction is the usual choice, because the law that protects the trade secret is the one the disclosing party knows. Some jurisdictions (e.g., EU member states) may override contractual choice of law with mandatory rules protecting employees and consumers.
Arbitration vs litigation
For multi-country deals, arbitration (SIAC, HKIAC, ICC, LCIA) is often more enforceable than court judgments because the New York Convention (172+ states) recognises arbitral awards nearly everywhere. Court judgments still require local recognition proceedings in many countries.
Data transfer compliance
Sharing personal data across borders (customer lists, HR data) triggers data-transfer rules: GDPR adequacy decisions or SCCs in the EU, PIPL cross-border transfer rules in China, and PDPA restrictions in Singapore and Malaysia. An NDA cannot override these; pair the NDA with a data-processing agreement where needed.
Trade secret regimes by region
Trade secret protection is not automatic everywhere. In the EU, the Trade Secrets Directive (2016/943) harmonises protection; in China, the Anti-Unfair Competition Law protects trade secrets but requires the holder to have taken confidentiality measures - which is exactly what a signed NDA evidences. In the US, the Defend Trade Secrets Act (2016) provides a federal cause of action, but state law varies.
Common NDA mistakes and how to avoid them
Most NDA disputes come down to drafting and process failures, not the signature method. These are the mistakes to avoid.
Vague or overbroad definition
Defining confidential information so narrowly that routine disclosures fall outside protection, or so broadly that a court finds the clause unreasonable. Use defined categories plus a 'marked or reasonably identifiable' catch-all.
Missing or unrealistic term
No expiry or an unrealistic perpetual term. Trade secrets may need indefinite protection, but non-trade-secret information should have a defined term. Courts dislike indefinite duties for ordinary business information.
No remedies or enforcement path
An NDA that covers confidentiality but not what happens on breach, or that lacks an exclusive-remedy clause. Include injunctive relief, damages, and attorney-fee provisions where appropriate.
Poor execution evidence
Sending an unsigned NDA, losing the signed copy, or failing to capture identity verification. An e-signature platform with an audit trail solves this: the signed PDF, timestamp, and signer identity records become the evidence package.
Common questions about NDAs
NDA stands for non-disclosure agreement, also known as a confidentiality agreement. It is a contract in which parties agree to keep specified information confidential.
How eSign.AI applies this in practice
eSign.AI lets you send an NDA for electronic signature in minutes, with signer identity verification, tamper-evident PDFs, trusted timestamps, and a complete evidence package. Every signature is recorded with the identity, time and consent data you need to enforce the agreement.
Legal review checklist
Use this page as a starting point, not as a legal conclusion. Confirm the jurisdiction, effective date, document type, signature method, identity step and evidence requirements with current primary sources before relying on it.
Jurisdiction
Country, state or sector and the transaction entities involved.
Source control
Primary source, effective date and reviewer.
Workflow proof
Completed test and retained evidence package for the target process.







