NDA Meaning: A Plain Guide to Non-Disclosure Agreements
Summary
An NDA, or non-disclosure agreement, is a legal contract that requires one or both parties to keep defined information confidential for a set period. NDAs come in three forms: unilateral, mutual, and multilateral. Key clauses to read carefully include the definition of confidential information, the survival period after termination, and permitted disclosure exceptions. This guide explains what each section means in practice and what to verify before you sign.
The NDA meaning is straightforward: a Non-Disclosure Agreement is a contract that legally binds one or both parties to keep specific information confidential and to restrict how it can be used. NDAs appear in business negotiations, employment agreements, vendor relationships, and M&A preliminary discussions. Before signing, the critical question is not whether the document looks "standard" but whether the definition of confidential information, the duration of obligations, and any additional restrictions are proportionate to the actual relationship.
What NDA Stands For and What It Actually Does
NDA stands for Non-Disclosure Agreement. The same contract often travels under other names depending on the context and the jurisdiction: Confidentiality Agreement, Proprietary Information Agreement, or Secrecy Agreement. Whatever the header says, the mechanism is the same.
One party, or both, agrees to keep specific information private and not to use it for any purpose outside what the document permits. Signing creates a legally enforceable obligation. A breach, including an inadvertent one, can expose the receiving party to a claim for damages.
The first time I had to sign one, I assumed it was a formality. A vendor handed me a two-page document before a demo call, and a colleague said: just sign it, everyone does. I signed it. What I had not noticed was that the confidentiality period was five years, with no carve-out for information I might independently develop from public sources later. Nothing catastrophic followed, but the point is I had no idea what I had agreed to.
That experience is more common than most people admit. NDAs look routine. Most of the time they are. The details matter, though, and knowing what to look for takes less time than you think.
The Three Types of NDA You Are Most Likely to Encounter
Not all NDAs create the same obligations. In practice, you will encounter three configurations.
Unilateral NDA. One party discloses confidential information; the other agrees to protect it. This is the most common form in employment situations, where an employee agrees not to share proprietary processes, and in vendor relationships, where a supplier is shown client data before a contract is signed. The disclosing party carries no obligation. Only the receiving party is bound.
Mutual NDA. Both parties share and protect each other's information. This is standard in partnership negotiations, joint ventures, and preliminary M&A discussions, where each side needs to evaluate the other before committing. If you are entering a negotiation where both parties will share sensitive data, a mutual NDA is appropriate. Push for it if the other side presents a unilateral version.
Multilateral NDA. Three or more parties, one document. Used in complex transactions or consortium arrangements. Less common in day-to-day operations, but worth recognising when it appears.
The type determines who carries risk. In a unilateral NDA, the risk of breach sits entirely with the receiving party. In a mutual NDA, both parties are exposed. This distinction matters when deciding whether to negotiate a clause or accept the draft as written.
The Clauses That Matter Most
Reading an NDA from the first clause to the last is not necessarily the most efficient approach. There are four sections I check first, because they define the real scope of what is being agreed.
Definition of confidential information. This clause tells you what is protected. Vague language, such as "any information disclosed by either party," is problematic: it can inadvertently capture information that is already public, or information you develop independently. A well-drafted definition includes specific categories, such as technical data, client lists, or pricing structures, and explicit exclusions: information already in the public domain, information you knew before the relationship began, and information received from a third party without restriction.
Duration and survival. Two separate timeframes often appear in the same section and are easy to confuse. The term refers to how long the NDA is active as an agreement. The survival clause specifies how long the confidentiality obligation continues after the agreement ends. A two-year NDA with a five-year survival means that five years after termination, you are still bound to protect what you received. That is not unreasonable in many contexts, but you need to know it before signing.
Permitted disclosures. Every NDA allows the receiving party to share information with certain people: employees who need it to do their job, legal advisors, accountants. The clause should specify who qualifies and under what conditions, usually on a need-to-know basis and subject to equivalent confidentiality obligations. If this clause is missing or vague, the scope of your obligation becomes unclear.
Return or destruction. When the relationship ends, what happens to the information you received? A properly drafted NDA specifies whether documents must be returned, deleted, or destroyed, and how that destruction must be confirmed.

What an NDA Cannot Do: The Limits You Should Know
An NDA is a contract, not a lock. Understanding what it cannot protect is as important as understanding what it can.
Public domain information is never protectable. If information is already publicly available, published in a patent application, or disclosed at an industry conference, an NDA clause cannot retroactively classify it as confidential. Any clause attempting this is unenforceable.
Legally mandated disclosures override NDAs. If a court orders disclosure, if a regulator requires it, or if whistleblower protection applies, the receiving party is generally permitted, or required, to disclose information despite the NDA. Most NDAs include an explicit carve-out for this. If yours does not, the legal obligation still applies regardless.
Overly broad language weakens enforceability. Courts have shown consistent reluctance to enforce NDA clauses that are too vague or too wide in scope. In EU and Swiss jurisdictions, courts apply a proportionality standard. An NDA that attempts to restrict an entire field of knowledge rather than specific identified information is unlikely to hold.
NDAs are not non-compete agreements. The two are sometimes confused, or deliberately conflated. A non-compete restricts where you can work after a relationship ends. An NDA restricts what you can say. Some NDAs include non-compete language as a separate clause. This requires specific attention, particularly in EU and Swiss contexts where non-compete provisions are subject to strict requirements and limited enforceability.
How Long Does an NDA Last and What Happens When It Expires
This question produces more confusion in practice than most others, usually because the person who signed the NDA assumed it had "run out" and no longer applied.
Two things expire: the agreement itself and the obligations it creates. When the term of the NDA ends, no new disclosures are being exchanged. But the survival clause, which specifies how long the confidentiality obligations persist, often extends well beyond the term. It is not unusual to see a survival period of three to five years after termination. For particularly sensitive information in M&A contexts, longer survival clauses do exist and are sometimes enforceable.
Once the survival period ends, the information that was protected is no longer covered by the agreement. You are free to disclose it, subject to any other applicable legal obligations. Trade secrets legislation, for example, operates independently of any NDA and does not expire automatically when the agreement does.
One practical note: the effective date matters. An NDA that was signed but never formally triggered may not bind you for information you received before the agreement came into effect. Check the start date, not just the signature date.
Red Flags in an NDA Worth Slowing Down For
Not every deviation from a typical NDA is a red flag. But certain provisions consistently signal that closer attention is warranted.
No expiration date on the confidentiality obligation. A perpetual NDA, one where the obligation to maintain confidentiality never ends, is unusual outside of trade secrets contexts and should be questioned. In most commercial relationships, three to five years after termination is a reasonable survival period. Perpetual obligations create permanent legal exposure that most parties do not need.
A definition of confidential information that captures derivatives. Some NDAs extend protection to information derived from the original disclosure. This increasingly includes outputs generated by AI tools that processed the confidential information. If you use an internal AI assistant to analyse materials received under an NDA and the agreement includes a broad derivatives clause, you may be in breach, even unintentionally. This is a point worth verifying with your counsel before using any third-party tool on materials received under a confidentiality obligation.
Non-compete language embedded in the confidentiality section. These are different obligations. Conflating them in a short document is either a drafting error or a deliberate attempt to extend restrictive covenants beyond what is being explicitly agreed. The two should appear as separate clauses and should be reviewed independently.
Jurisdiction in a court far from where you operate. If the other party insists on exclusive jurisdiction in a court that would be expensive or impractical for you to reach, the practical cost of enforcing your rights, or defending against a claim, increases substantially. This is worth flagging, even if you ultimately accept it.

When to Sign, When to Negotiate, and When to Ask Your Counsel
Most NDAs you receive in a professional context are reasonable, and signing makes sense most of the time. The calculus changes in a few situations.
Sign without detailed review when the NDA is clearly unilateral, the obligations are specific and time-limited, and the context is low-risk: a vendor demo, a preliminary sales call, a contractor who needs to see a system before quoting. In these cases, spending an hour on review creates friction without materially reducing your exposure.
Negotiate specific clauses when the definition of confidential information is too broad, the survival period exceeds what the relationship warrants, or the agreement includes non-compete provisions you did not expect. Most parties will accept reasonable adjustments on these points if you frame them as technical corrections rather than challenges to the fundamental terms.
Ask your counsel to review when the NDA covers information material to your business operations, when you are sharing, not just receiving, sensitive data, when the survival period is perpetual, or when the agreement is part of a transaction with significant financial stakes. I am not a lawyer, and this is not legal advice: it is the conclusion I reached after reviewing enough documents to know the limits of what I can assess on my own.
In practice, the question "is this NDA standard?" is less useful than "does this NDA say what I think it says?" The two are not always the same.
Before signing any confidentiality agreement, check three things: the scope of what is defined as confidential, how long your obligations last after the relationship ends, and whether there are provisions beyond confidentiality, such as non-compete or jurisdiction clauses, that extend the reach of what you are agreeing to. Five minutes spent on those sections prevents most of the problems.