NDA Clause Explainer
Disclaimer: This skill provides general legal literacy and educational information to help you understand legal concepts and processes. It does NOT constitute legal advice, represent you in any legal matter, or create an attorney-client relationship. Laws vary by jurisdiction and change over time. Always consult a qualified attorney licensed in your jurisdiction for advice on specific legal matters affecting you.
When to Use
Use this skill when:
- The user has received a complete or partial NDA text and wants a plain-language explanation of what each clause means and what obligations it creates
- The user wants to understand the structural difference between a mutual NDA (both parties disclose and protect) and a unilateral NDA (one party discloses, the other protects) and what that difference means for their leverage and risk
- The user wants to identify red flags, aggressive provisions, or missing standard carve-outs before handing the document to an attorney for negotiation
- The user is preparing specific questions for a legal consultation and wants to use attorney time efficiently by understanding the document first
- The user wants to understand why a specific clause is phrased the way it is -- for example, why a disclosing party prefers a broad definition of confidential information while a receiving party prefers a narrow one
- The user is a first-time founder, freelancer, or employee encountering an NDA for the first time and needs to build baseline legal literacy about confidentiality agreements
- The user has received an NDA in a specific business context (pre-acquisition due diligence, vendor onboarding, investor pitch, employment pre-hire, accelerator application, joint venture discussion, freelance engagement) and wants to know whether the NDA's terms are standard for that context
Do NOT use when:
- The user wants to draft NDA language or generate a new NDA from scratch -- this requires a licensed attorney and falls outside educational explanation (use a legal drafting professional)
- The user wants a direct recommendation on whether to sign a specific NDA -- this skill explains what clauses mean and flags concerns, but the signing decision is legal advice requiring an attorney
- The user is reviewing a general commercial contract that includes a confidentiality section but is primarily about something else (services, licensing, employment) -- use
contract-basics-explainer for multi-topic contracts
- The user is reviewing the confidentiality provisions of an employment agreement as part of the broader employment contract review -- use
employment-contract-reader for employment-specific confidentiality, non-compete, and IP assignment clauses
- The user believes an NDA has already been violated and wants to understand their legal exposure or remedies -- this requires a litigation attorney, not educational explanation
- The user needs the NDA interpreted under a specific state's case law to determine enforceability -- jurisdiction-specific legal conclusions require local counsel
- The user wants to compare NDA terms across multiple active contracts to determine which governs a particular disclosure -- this is legal analysis requiring an attorney
Process
Step 1: Establish Context Before Analysis
Before analyzing any clause, gather the following context because NDA norms differ significantly by use case:
- NDA type: Is this mutual (both parties disclose) or unilateral (one party discloses)? If the NDA is labeled "mutual" but structured so that one party has broader obligations, flag that immediately.
- Business context: What is the relationship? Pre-acquisition due diligence, vendor selection, investor pitch, freelance project scoping, pre-employment interview, joint venture discussion, accelerator application, technology licensing negotiation, or research collaboration each has different market norms for NDA terms.
- Counterparty profile: Is this a large corporation with a legal department (their NDA template will be one-sided by design), a startup (may have a poorly drafted or copy-pasted NDA), an individual, or a government entity (government NDAs have additional complexity around FOIA and public records)?
- User's role: Is the user the disclosing party, the receiving party, or both in a mutual structure? Their concerns differ fundamentally -- disclosers worry about scope being too narrow; receivers worry about scope being too broad.
- Governing law: Which state or country's law governs? This matters because NDA enforceability varies significantly. California, for example, renders non-compete provisions in NDAs effectively unenforceable. New York courts strictly enforce choice-of-law clauses. Delaware is heavily preferred for M&A NDAs because Delaware courts have extensive NDA precedent.
- Specific concerns: Ask whether the user has already spotted something that bothers them, or whether they want a full systematic walkthrough.
Step 2: Analyze the Parties, Purpose, and Structure Clause
The opening recitals and definitions of parties establish who is bound and for what purpose -- this shapes every other clause.
- Disclosing Party / Receiving Party definitions: Confirm whether the NDA defines these as individual entities or whether they include "affiliates," "subsidiaries," and "representatives." A definition that includes affiliates extends the obligation (and the permitted disclosure set) across an entire corporate family -- this has significant implications for large companies.
- Purpose clause: The stated purpose limits how confidential information can be used. A narrow purpose like "evaluating a potential acquisition of Company X" means the receiving party cannot use disclosed information for any other purpose -- not to compete, not to approach customers, not to inform other deals. A vague purpose like "exploring a potential business relationship" gives the receiving party more flexibility but also provides less protection to the discloser.
- Unilateral vs. mutual structure: Unilateral NDAs where the user is the receiver impose all obligations on the user. Mutual NDAs create symmetric obligations. For joint venture discussions, partnership negotiations, and situations where both parties will share sensitive information, a unilateral NDA is commercially unusual and should prompt the question of whether a mutual structure is more appropriate.
- Representatives and permitted recipients: Many NDAs extend the Receiving Party's obligations to their "Representatives" -- typically defined to include directors, officers, employees, attorneys, accountants, and financial advisors. If "Representatives" is defined narrowly (employees only), the receiving party may be unable to have their own counsel review the disclosed information without technically breaching the NDA. Verify that at minimum attorneys and professional advisors are included.
Step 3: Dissect the Definition of Confidential Information
This is the single most consequential clause in any NDA. Its scope determines the universe of the receiving party's obligations.
- Three structural approaches and their implications:
- Omnibus / broad definition ("all information disclosed..."): Maximum protection for the discloser; maximum burden for the receiver. The receiver may not know at any given moment whether information received orally over lunch is covered. This is common in large-company standard templates and is aggressive when used for early-stage discussions where most shared information is non-sensitive.
- Marked/designated definition ("only information marked CONFIDENTIAL in writing, or if disclosed orally, confirmed in writing within 10 days..."): Clear but operationally demanding. The discloser must be disciplined about marking. If the discloser fails to mark information and later claims it was confidential, courts often enforce the marking requirement strictly. 10-30 days is the typical window for oral disclosure confirmation.
- Category-based definition ("including but not limited to: trade secrets, financial projections, customer lists, source code, manufacturing processes..."): The cleanest approach. The receiving party knows exactly what is covered. However, "including but not limited to" turns the list into examples rather than an exhaustive definition, which can reintroduce breadth.
- "Should reasonably know is confidential" language: This subjective standard is the most problematic. It asks the receiving party to speculate about the discloser's intent. Flag this phrase whenever it appears.
- Residuals clauses: Some technology-industry NDAs include a "residuals" provision allowing the receiving party to use information retained in the unaided memory of their representatives -- without any notes. This benefits the receiving party significantly and is strongly resisted by disclosers. Flag it when present because it substantially limits the NDA's protective value.
- Trade secret overlap: Confidential information definitions often overlap with statutory trade secret protection under the Defend Trade Secrets Act (DTSA, federal) and the Uniform Trade Secrets Act (UTSA, adopted by 48 states). Information that qualifies as a trade secret gets indefinite protection under statute regardless of NDA duration -- this is why some NDAs carve out trade secrets for indefinite protection while setting shorter terms for general confidential information.
Step 4: Evaluate the Standard Exclusions
Every well-drafted NDA should contain all five standard exclusions. Missing even one is a red flag that increases risk for the receiving party. Document which exclusions are present and which are absent.
- Public domain exclusion: Information that is or becomes publicly available through no fault of the receiving party is excluded. The key phrase is "through no fault" -- if the receiving party caused the disclosure, this exclusion does not apply.
- Prior knowledge exclusion: Information the receiving party already possessed before the NDA's effective date is excluded. Red flag: some NDAs require the receiving party to prove prior possession with documentation predating the NDA. Verify whether this burden exists.
- Independent development exclusion: Information independently developed by the receiving party without use of the disclosed information is excluded. This is essential for companies in the same general industry -- without this exclusion, the receiving party could be accused of violating the NDA for developing a product that happens to be similar to what was disclosed.
- Third-party disclosure exclusion: Information received from a third party without restriction on disclosure is excluded. This protects the receiving party when they later receive the same information from a non-confidential source.
- Compelled disclosure exclusion: Information disclosed pursuant to a court order, law, or government requirement is excluded -- but usually requires advance notice to the discloser so they can seek a protective order. The notice provision is important: if there is no notice requirement, the discloser loses the opportunity to protect their information through a court proceeding.
- Additional non-standard exclusions to consider: Some receiving parties seek an exclusion for information developed by personnel who had no access to the discloser's information (common in large companies that firewall teams). This is commercially reasonable but disclosers often resist it.
Step 5: Analyze Obligations, Standard of Care, and Use Restrictions
The obligations clause defines what the receiving party must actively do (and refrain from doing) to comply with the NDA.
- Confidentiality obligation vs. use restriction: These are two distinct obligations that appear in the same clause. The confidentiality obligation prohibits disclosure to third parties. The use restriction prohibits using the information for any purpose other than the stated purpose -- even without disclosing it to anyone. A receiving party can violate an NDA's use restriction by using disclosed information internally for a purpose other than the stated one, even if they never tell anyone outside the company.
- Standard of care comparison:
- "Reasonable efforts" or "reasonable measures" -- the most common, most balanced standard. Courts interpret this as what a reasonable company in that situation would do.
- "Same care as own confidential information, but no less than reasonable care" -- slightly stricter. Introduces an internal reference point that can raise the bar if the receiving party has robust internal data protection.
- "Best efforts" or "highest degree of care" -- the most onerous. Courts interpret "best efforts" as requiring extraordinary measures. This standard is unusual and should be negotiated down.
- Need-to-know distribution: The NDA should limit internal access to employees and representatives who genuinely need the information to accomplish the stated purpose. Verify whether the NDA requires the receiving party to bind those representatives to equivalent confidentiality obligations -- this is a standard and reasonable requirement.
- Sub-disclosure to professional advisors: The receiving party's attorneys, accountants, and financial advisors will often need to review disclosed information. If the NDA does not explicitly permit disclosure to professional advisors who are themselves bound by professional confidentiality obligations, the receiving party may technically breach the NDA by having their own lawyer read the disclosed materials.
- Security requirements: Some NDAs, particularly in technology and healthcare contexts, specify technical security requirements (encryption at rest and in transit, access logging, specific SOC 2 compliance). If the receiving party cannot meet specified technical requirements, this must be negotiated before signing.
Step 6: Examine Term, Duration, and Survival Provisions
Duration provisions contain two distinct and commonly confused time periods.
- Agreement term: How long the NDA governs new disclosures. After this period, the discloser cannot disclose new information and expect NDA protection. Common ranges by context:
- Pre-acquisition due diligence: 1-2 years (deal-focused; expected to close or terminate quickly)
- Vendor/supplier relationships: 2-3 years with renewal provisions
- Technology partnerships: 3-5 years
- General business discussions: 1-3 years
- Survival/confidentiality obligation period: How long the receiving party's confidentiality obligations last after the agreement expires or terminates. This is where receiving parties frequently fail to read carefully. A 2-year NDA term with a 5-year survival period means the confidentiality obligations actually last 7 years from execution.
- Trade secret carve-out: Best practice in well-drafted NDAs is to apply the standard term to general confidential information while requiring confidentiality of trade secrets for as long as they maintain their trade secret status (indefinitely in practice). This is reasonable and commercially standard. An NDA that applies an indefinite confidentiality obligation to ALL information -- not just trade secrets -- imposes an unreasonable lifetime burden.
- Evergreen provisions: Some NDAs automatically renew unless terminated with written notice. Flag automatic renewal provisions because receiving parties may not realize they have a contractual obligation to send timely termination notices.
- Termination triggers: Understand what triggers termination. Some NDAs terminate only by mutual written agreement; others terminate automatically upon completion of the stated purpose; others include either-party termination rights with notice periods of 30-90 days. A receiving party should prefer a termination right -- being locked into an NDA indefinitely with no exit mechanism is problematic.
Step 7: Review Remedies, Injunctive Relief, and Enforcement Provisions
The remedies clause determines the consequences of a breach and establishes the enforcement mechanisms available to the discloser.
- Injunctive relief acknowledgment: Most NDAs include language stating that the receiving party acknowledges that breach would cause "irreparable harm" for which "monetary damages would be inadequate," and that the discloser is therefore entitled to seek injunctive relief without posting a bond. This language is strategically placed to remove two barriers to emergency court orders: (1) proving irreparable harm and (2) posting a security bond. Courts are not always bound by this contractual acknowledgment, but it helps the discloser. Flag it because the receiving party is pre-consenting to the discloser's ability to obtain an emergency restraining order.
- Liquidated damages clauses: Pre-specified damage amounts triggered by breach. These can be reasonable (representing a genuine pre-estimate of harm) or punitive (far exceeding likely actual harm). The enforceability of liquidated damages varies by state -- some states void them if they constitute a penalty; others enforce them liberally. Flag any liquidated damages clause with the specific amount so the user can evaluate whether it is proportionate to the information being protected.
- Attorneys' fees: One-way attorneys' fee provisions (only the prevailing discloser recovers fees) are aggressive. Mutual fee-shifting (prevailing party recovers fees regardless of who wins) is more balanced and standard.
- Indemnification scope: Indemnification provisions in NDAs can be broad or narrow. Broad versions require the breaching party to indemnify for all losses, claims, damages, and expenses (including third-party claims resulting from the breach). Narrow versions limit indemnification to direct damages. Flag indemnification provisions that extend to third-party claims.
- DTSA whistleblower immunity: The Defend Trade Secrets Act (18 U.S.C. § 1833) grants immunity to individuals who disclose trade secrets to government officials or attorneys in the course of reporting suspected violations of law, or in a court filing made under seal. This right cannot be contractually waived -- NDAs that purport to prohibit all disclosure without exception may be partially unenforceable under DTSA in the context of lawful whistleblowing. Note this protection to users even if the NDA does not mention it.
- DTSA notice requirement: For employers seeking DTSA's enhanced damages (exemplary damages up to 2x actual damages and attorneys' fees) in a trade secret misappropriation case, the DTSA requires that the employment agreement or NDA include a reference to the whistleblower immunity provision. Employer-issued NDAs that lack this notice clause may affect the employer's remedy options under federal law.
Step 8: Flag Non-Solicitation, Non-Compete, and Other Riders
NDAs frequently include provisions that have nothing to do with confidentiality -- these riders materially expand the agreement's scope and must be explicitly identified.
- Non-solicitation of employees: Prohibits the receiving party from recruiting or hiring the discloser's employees, typically for 1-2 years after the NDA's term. This is common in M&A due diligence NDAs (the acquirer gains access to information about key employees and could poach them). In early-stage business discussions, a non-solicitation in an NDA presented as "just a standard confidentiality agreement" is a significant scope expansion.
- Non-solicitation of customers: Prohibits the receiving party from soliciting the discloser's customers, often based on customer information disclosed under the NDA. This can be commercially devastating for a receiving party in a competitive industry.
- Non-compete provisions: Prohibits the receiving party from competing in the discloser's business area for a defined period. These are the most aggressive NDA riders. In California, non-competes are effectively unenforceable (Business and Professions Code § 16600). In other states, enforceability depends on reasonableness of scope, duration, and geography. Flag any non-compete provision in an NDA regardless of jurisdiction and recommend attorney review.
- Standstill provisions (M&A context): Prohibit the receiving party from acquiring shares of the discloser or making an unsolicited takeover bid for a defined period (typically 12-24 months). Standard in public company M&A due diligence NDAs. Unusual and aggressive in any other context.
- No-hire provisions: Distinct from non-solicitation -- a no-hire provision prohibits hiring specific individuals regardless of whether the receiving party solicited them. Courts increasingly scrutinize these as anti-competitive.
Output Format
Deliver the NDA analysis in this structured format. Populate every field with specific information from the NDA text provided. Do not leave fields blank -- if a provision is absent, explicitly note "Not present" and flag it.
## NDA Analysis: [Specific Business Context -- e.g., "Pre-Acquisition Due Diligence NDA, TechCorp → User"]
> This analysis provides educational explanations of NDA provisions. It does not constitute legal advice.
> Concern levels: None | Low | Medium | High | Critical
---
### NDA Overview
| Field | Detail |
|--------------------------|----------------------------------------------------------------|
| NDA Type | [Mutual / Unilateral -- specify who discloses, who protects] |
| Disclosing Party | [Entity name and how "affiliates" are defined, if applicable] |
| Receiving Party | [Entity name and definition of "Representatives"] |
| Stated Purpose | [Exact or paraphrased purpose from the agreement] |
| Agreement Term | [Duration of NDA for new disclosures, e.g., 2 years] |
| Survival Period | [Duration of confidentiality obligations after expiration] |
| Total Obligation Window | [Term + Survival -- the actual duration of user's obligations]|
| Trade Secret Treatment | [Indefinite / Same as general CI / Not specified] |
| Governing Law | [State / Country] |
| Dispute Resolution | [Courts / Arbitration / Jurisdiction specified] |
| Automatic Renewal | [Yes / No / Not specified] |
| Termination Rights | [Either party / Mutual only / Completion of purpose] |
---
### Clause-by-Clause Analysis
#### 1. Definition of Confidential Information
- **Structure:** [Omnibus / Marked-designation / Category-based / Hybrid]
- **Exact language (or summary):** "[Quote or close paraphrase]"
- **What this means in practice:** [Plain-language explanation of what is covered]
- **Market standard for this context:** [What is typical for this type of NDA]
- **Concern Level:** [None / Low / Medium / High / Critical]
- **Notes:** [Specific concerns about overbreadth, subjectivity, or vagueness]
#### 2. Exclusions from Confidential Information
| Exclusion | Present? | Concern If Missing |
|------------------------------------|----------|------------------------------------------------------------------|
| Already publicly available | [Yes/No] | User may be bound by info anyone can find in a Google search |
| Becomes public through no fault | [Yes/No] | User may be liable for third-party leaks they didn't cause |
| Prior knowledge of receiving party | [Yes/No] | User's pre-existing knowledge may become restricted |
| Received from third party | [Yes/No] | User may be bound after receiving same info from public source |
| Independently developed | [Yes/No] | User's own R&D may be treated as derived from disclosed info |
| Compelled by law / court order | [Yes/No] | User may lack ability to comply with legal obligations legally |
- **Burden of proof:** [Who must prove an exclusion applies, and what documentation is required]
- **Overall Exclusions Concern Level:** [None / Low / Medium / High / Critical]
#### 3. Receiving Party Obligations and Use Restrictions
- **Confidentiality obligation:** [Summarize the non-disclosure duty]
- **Use restriction:** [Summarize limitations on internal use beyond disclosure]
- **Standard of care:** [Reasonable efforts / Same as own CI / Best efforts / Highest degree]
- **Need-to-know requirement:** [Yes/No -- who internally can access]
- **Obligation to bind Representatives:** [Yes/No]
- **Professional advisor sub-disclosure permitted:** [Yes/No/Conditional]
- **Concern Level:** [None / Low / Medium / High / Critical]
#### 4. Term and Duration
- **Agreement term:** [X years from effective date / completion of purpose / other]
- **Survival period:** [X years after expiration / indefinite / not specified]
- **Total obligation window:** [Combined calculation]
- **Trade secret treatment:** [Indefinite / same as general / not specified]
- **Automatic renewal:** [Yes -- X-day notice required / No]
- **Concern Level:** [None / Low / Medium / High / Critical]
#### 5. Compelled Disclosure (Legal Process)
- **Permitted:** [Yes / No / Not addressed]
- **Notice to discloser required:** [Yes -- advance notice / Yes -- prompt notice / No]
- **Cooperation in protective order:** [Required / Not required]
- **DTSA whistleblower protection:** [Referenced in agreement / Not referenced]
- **Concern Level:** [None / Low / Medium / High / Critical]
#### 6. Return and Destruction of Information
- **Obligation:** [Return / Destroy / Either at discloser's election]
- **Trigger:** [On request / On termination / On expiration]
- **Certification required:** [Yes / No]
- **Electronic data acknowledgment:** [Addressed / Not addressed]
- **Concern Level:** [None / Low / Medium / High / Critical]
#### 7. Remedies and Enforcement
- **Injunctive relief pre-acknowledgment:** [Yes / No -- explain implications if yes]
- **Liquidated damages:** [Present -- specify amount / Not present]
- **Attorneys' fees:** [Prevailing party / One-way / Not specified]
- **Indemnification scope:** [Direct damages only / Third-party claims included / Not specified]
- **Concern Level:** [None / Low / Medium / High / Critical]
#### 8. Riders and Additional Restrictions
- **Non-solicitation (employees):** [Present -- X-year duration / Not present]
- **Non-solicitation (customers):** [Present -- X-year duration / Not present]
- **Non-compete:** [Present -- scope, duration, geography / Not present]
- **Standstill:** [Present -- X-month duration / Not present]
- **Other riders:** [List any additional restrictions beyond confidentiality]
- **Overall Riders Concern Level:** [None / Low / Medium / High / Critical]
---
### Red Flags Summary
| Priority | Clause | Issue | Practical Impact on User |
|----------|-------------------------|-----------------------------------------------|---------------------------------------------------|
| Critical | [Clause name] | [Specific problem] | [What this means for the user's obligations] |
| High | [Clause name] | [Specific problem] | [What this means for the user's obligations] |
| Medium | [Clause name] | [Specific problem] | [What this means for the user's obligations] |
| Low | [Clause name] | [Specific problem] | [What this means for the user's obligations] |
---
### Missing Standard Provisions Checklist
- [ ] [Missing provision] -- [Why it matters and what risk its absence creates]
- [ ] [Missing provision] -- [Why it matters and what risk its absence creates]
---
### Market Context Assessment
**For [this type of NDA], the market standard is:**
[2-4 sentences describing what is typical for this specific NDA context -- pre-acquisition due diligence, employment, investor pitch, vendor relationship, etc. -- and how this NDA compares to that standard.]
---
### Questions to Raise with Your Attorney
**About scope and definitions:**
1. [Specific, targeted question tied to a clause concern]
2. [Specific, targeted question tied to a clause concern]
**About obligations and compliance:**
3. [Specific, targeted question about how to comply with a specific provision]
4. [Specific, targeted question about a provision the user may not be able to meet]
**About negotiation:**
5. [Specific, targeted question about whether a particular term is negotiable]
6. [Specific, targeted question about alternative language to propose]
**About jurisdiction and enforceability:**
7. [Specific question about how the governing state's courts interpret a particular provision]
---
### Jurisdiction Note
This NDA designates [State] law as governing. Key considerations:
- [State]-specific rule 1 relevant to this NDA
- [State]-specific rule 2 relevant to this NDA
- How [State] courts have historically treated [the most concerning provision]
- Whether the user's home state differs from the governing law state, and what that means practically
Recommend confirming all of the above with an attorney licensed in [State].
Rules
Always present the disclaimer first and do not bury it. Place the disclaimer at the top of every response. Do not allow enthusiasm for helping the user to push the disclaimer below the fold.
Never advise the user to sign or not sign. This is the clearest line between legal education and legal advice. Present the analysis, flag concerns at appropriate severity levels, and always close with a recommendation for attorney review of any High or Critical concern. Saying "this clause is aggressive and you should ask your attorney whether to push back" is appropriate; saying "you should not sign this" is not.
Never draft NDA language or propose specific substitute clause text. Explaining what a clause means and why it is concerning is within scope. Writing alternative language for the user to propose is drafting -- it creates legal risk for the user if the language has unintended consequences. Direct the user to their attorney for specific language changes.
Distinguish confidentiality obligations from use restrictions in every analysis. These are different duties with different compliance implications. A receiving party can breach a use restriction without telling anyone outside the company. Always explain both dimensions when analyzing the obligations clause.
Flag every missing standard exclusion explicitly, by name. Do not summarize missing exclusions as "the exclusions are incomplete." Enumerate which of the five standard exclusions are absent and explain the specific risk each absence creates for the receiving party.
Always flag non-compete, non-solicitation, standstill, and no-hire provisions as scope expansions, regardless of how routine the counterparty claims they are. These provisions materially expand an NDA beyond confidentiality. The phrase "just a standard NDA" from a counterparty should heighten attention to riders, not reduce it.
Always note DTSA whistleblower immunity, even if the NDA does not reference it. Users -- particularly employees -- have a federal right to disclose trade secrets to government officials in the context of reporting suspected legal violations. This right cannot be waived by contract. Noting it ensures the user knows a right they may not know they have.
Calculate and state the total obligation window explicitly. Users routinely misread a "2-year NDA" as meaning their obligations last 2 years. If the agreement has a 2-year term plus a 3-year survival period, state clearly that the user's actual obligations last 5 years from signing.
Assess every NDA against the norms for its specific context. A provision that is aggressive in a freelance project NDA may be completely standard in a public-company M&A due diligence NDA. Calibrate severity levels against market norms for the specific context, not against an abstract "standard NDA."
When the NDA is governed by a state other than the user's home state, flag this as a jurisdiction concern. Non-compete enforceability, interpretation of broad definitions, and the implied covenant of good faith differ substantially by state. California, New York, Delaware, and Texas each have materially different NDA jurisprudence. Note the governing state's known tendencies and recommend local counsel review.
When the user provides only a partial NDA or describes clauses from memory, explicitly note the limitations of the analysis. Analysis of a paraphrased or incomplete NDA is less reliable than analysis of the actual text. Recommend the user share the full document and note that missing provisions may affect the analysis.
Do not present concern levels as binary (fine vs. problematic). Use a five-tier scale -- None, Low, Medium, High, Critical -- and explain what each level means in context. A provision can be "Medium" concern -- not a deal-breaker but worth understanding and potentially negotiating.
Edge Cases
Pre-Interview NDA (Employment Context)
Pre-interview NDAs are increasingly common in technology, finance, and executive recruitment. They are appropriate when the candidate will hear genuinely confidential information during the interview process (unannounced product plans, M&A targets, financial results). They become problematic when they are so broad that the candidate is restricted from discussing their own pre-existing knowledge or career trajectory.
What to look for:
- Scope should be limited to information disclosed during the interview process, not the candidate's pre-existing knowledge about the industry
- Duration of 1-2 years is reasonable; 5-year pre-interview NDAs are disproportionate
- No non-compete provisions -- the candidate has not been hired and should not be restricted from employment elsewhere based on an interview
- No non-solicitation provisions -- pre-hire NDAs should not restrict who the candidate can work with in the future
- The purpose clause should reference the hiring evaluation specifically, not broadly "exploring a business relationship"
Flag any pre-interview NDA that includes non-compete provisions regardless of their scope. Flag duration over 2 years. Flag definitions so broad they cover information the candidate learned independently before the interview.
Investor Pitch NDA (Startup Context)
Many venture capital firms and sophisticated angel investors decline to sign NDAs before hearing pitches. This is a market norm, not bad faith -- investors hear hundreds of pitches in similar categories and signing NDAs creates legal complexity. When a startup is asked to sign an NDA before presenting to an investor or accelerator, the concern reverses: the investor may be trying to restrict the startup from discussing its own ideas.
What to look for:
- The purpose clause must be specific to the pitch/evaluation process, not broadly stated
- The startup is often the disclosing party -- verify that the NDA actually protects the startup's information, not only the investor's
- Watch for unilateral NDAs where the startup is the receiver -- this is unusual in pitch contexts and may be an attempt to restrict the startup's use of information it independently developed
- Accelerator application NDAs should not restrict the applicant from discussing their business concept with co-founders, advisors, or other investors outside the application process
- Look for "no-shop" or standstill provisions that could prevent the startup from pitching to other investors during the evaluation period
Extremely Short NDA (One Page or Fewer)
A one-paragraph or one-page NDA is not inherently weaker than a long one -- brevity can actually create broader obligations because the standard carve-outs that protect receiving parties are absent.
What to look for:
- Verify all five standard exclusions. One-page NDAs frequently omit the prior knowledge, independent development, and third-party source exclusions
- Check whether there is any term limit. NDAs without an explicit term may create obligations that are indefinite by default
- Check whether there is a compelled disclosure provision. Without it, the receiving party may be unable to comply with a subpoena without breaching the NDA
- Check whether permitted recipients (employees, advisors) are defined. Without this, any internal distribution could technically breach the NDA
- A one-page NDA with no exclusions, no term, and no compelled disclosure provision may create more onerous obligations than a 10-page NDA with all standard provisions present
Mutual NDA with Asymmetric Obligations
Some NDAs are titled "Mutual Confidentiality Agreement" but impose meaningfully different obligations on each party. This asymmetry can arise from:
- Different definitions of confidential information for each party (Party A's CI is defined broadly; Party B's is defined by a marked-designation requirement)
- Different survival periods (Party A's obligations survive for 5 years; Party B's survive for 2 years)
- Different standards of care (Party A must use "best efforts"; Party B must use "reasonable efforts")
- Remedies available only to one party (Party A can seek injunctive relief; Party B cannot)
- Non-solicitation provisions that run only one direction
When analyzing a mutual NDA, explicitly compare the obligations of both parties side-by-side in the analysis. If the NDA is labeled mutual but the obligations are materially asymmetric, flag this prominently. The asymmetry may be intentional (the party with the more sensitive information negotiated stronger protections) or inadvertent (template language was not properly adapted for a mutual structure).
M&A Due Diligence NDA (Acquisition Context)
NDAs for pre-acquisition due diligence have specific market-standard features that differ from general business NDAs. Understanding these norms prevents treating standard M&A provisions as red flags or vice versa.
Standard in M&A NDAs that may appear aggressive in other contexts:
- Standstill provisions (12-18 months) preventing the acquirer from making unsolicited offers or acquiring shares -- completely standard
- Non-solicitation of employees for 18-24 months -- completely standard because the acquirer gains deep visibility into key personnel
- "Big boy" letters excluding personal injury claims from the limitation of liability -- common in sophisticated transactions
- Specific carve-outs allowing the target to provide information to potential acquisition financing sources under separate confidentiality agreements
What is still unusual even in M&A NDAs:
- Indefinite confidentiality obligations on ALL information (not just trade secrets)
- Non-compete provisions against the acquiring company's entire business (beyond the target's specific area)
- Liquidated damages provisions -- M&A NDAs rarely specify pre-set damage amounts because actual harm from breach is highly fact-specific
NDA That Includes Conflicting Choice-of-Law and Forum Selection Clauses
Occasionally an NDA designates one state's law as governing (e.g., "This Agreement shall be governed by the laws of Delaware") but designates courts in a different state as the mandatory forum (e.g., "Any dispute shall be resolved in the courts of New York"). This creates potential conflict because the New York court would apply Delaware law -- which it can do, but which may r
…(truncated)
1---2name: nda-clause-explainer3description: Provides a clause-by-clause breakdown of non-disclosure agreements (NDAs), explaining what each provision means, common variations, red flags, and questions to ask before signing. Covers mutual vs. unilateral NDAs, definition of confidential information, exclusions, term, remedies, and non-solicitation riders. Use when the user has an NDA to review, wants to understand NDA terminology, or needs to prepare questions for an attorney about a confidentiality agreement. Do NOT use for drafting NDAs, advising whether to sign, or reviewing other contract types (use contract-basics-explainer for general contracts).4license: Apache-2.05---6# NDA Clause Explainer78> **Disclaimer:** This skill provides general legal literacy and educational information to help you understand legal concepts and processes. It does NOT constitute legal advice, represent you in any legal matter, or create an attorney-client relationship. Laws vary by jurisdiction and change over time. Always consult a qualified attorney licensed in your jurisdiction for advice on specific legal matters affecting you.910---1112## When to Use1314**Use this skill when:**15- The user has received a complete or partial NDA text and wants a plain-language explanation of what each clause means and what obligations it creates16- The user wants to understand the structural difference between a mutual NDA (both parties disclose and protect) and a unilateral NDA (one party discloses, the other protects) and what that difference means for their leverage and risk17- The user wants to identify red flags, aggressive provisions, or missing standard carve-outs before handing the document to an attorney for negotiation18- The user is preparing specific questions for a legal consultation and wants to use attorney time efficiently by understanding the document first19- The user wants to understand why a specific clause is phrased the way it is -- for example, why a disclosing party prefers a broad definition of confidential information while a receiving party prefers a narrow one20- The user is a first-time founder, freelancer, or employee encountering an NDA for the first time and needs to build baseline legal literacy about confidentiality agreements21- The user has received an NDA in a specific business context (pre-acquisition due diligence, vendor onboarding, investor pitch, employment pre-hire, accelerator application, joint venture discussion, freelance engagement) and wants to know whether the NDA's terms are standard for that context2223**Do NOT use when:**24- The user wants to draft NDA language or generate a new NDA from scratch -- this requires a licensed attorney and falls outside educational explanation (use a legal drafting professional)25- The user wants a direct recommendation on whether to sign a specific NDA -- this skill explains what clauses mean and flags concerns, but the signing decision is legal advice requiring an attorney26- The user is reviewing a general commercial contract that includes a confidentiality section but is primarily about something else (services, licensing, employment) -- use `contract-basics-explainer` for multi-topic contracts27- The user is reviewing the confidentiality provisions of an employment agreement as part of the broader employment contract review -- use `employment-contract-reader` for employment-specific confidentiality, non-compete, and IP assignment clauses28- The user believes an NDA has already been violated and wants to understand their legal exposure or remedies -- this requires a litigation attorney, not educational explanation29- The user needs the NDA interpreted under a specific state's case law to determine enforceability -- jurisdiction-specific legal conclusions require local counsel30- The user wants to compare NDA terms across multiple active contracts to determine which governs a particular disclosure -- this is legal analysis requiring an attorney3132---3334## Process3536### Step 1: Establish Context Before Analysis3738Before analyzing any clause, gather the following context because NDA norms differ significantly by use case:3940- **NDA type:** Is this mutual (both parties disclose) or unilateral (one party discloses)? If the NDA is labeled "mutual" but structured so that one party has broader obligations, flag that immediately.41- **Business context:** What is the relationship? Pre-acquisition due diligence, vendor selection, investor pitch, freelance project scoping, pre-employment interview, joint venture discussion, accelerator application, technology licensing negotiation, or research collaboration each has different market norms for NDA terms.42- **Counterparty profile:** Is this a large corporation with a legal department (their NDA template will be one-sided by design), a startup (may have a poorly drafted or copy-pasted NDA), an individual, or a government entity (government NDAs have additional complexity around FOIA and public records)?43- **User's role:** Is the user the disclosing party, the receiving party, or both in a mutual structure? Their concerns differ fundamentally -- disclosers worry about scope being too narrow; receivers worry about scope being too broad.44- **Governing law:** Which state or country's law governs? This matters because NDA enforceability varies significantly. California, for example, renders non-compete provisions in NDAs effectively unenforceable. New York courts strictly enforce choice-of-law clauses. Delaware is heavily preferred for M&A NDAs because Delaware courts have extensive NDA precedent.45- **Specific concerns:** Ask whether the user has already spotted something that bothers them, or whether they want a full systematic walkthrough.4647### Step 2: Analyze the Parties, Purpose, and Structure Clause4849The opening recitals and definitions of parties establish who is bound and for what purpose -- this shapes every other clause.5051- **Disclosing Party / Receiving Party definitions:** Confirm whether the NDA defines these as individual entities or whether they include "affiliates," "subsidiaries," and "representatives." A definition that includes affiliates extends the obligation (and the permitted disclosure set) across an entire corporate family -- this has significant implications for large companies.52- **Purpose clause:** The stated purpose limits how confidential information can be used. A narrow purpose like "evaluating a potential acquisition of Company X" means the receiving party cannot use disclosed information for any other purpose -- not to compete, not to approach customers, not to inform other deals. A vague purpose like "exploring a potential business relationship" gives the receiving party more flexibility but also provides less protection to the discloser.53- **Unilateral vs. mutual structure:** Unilateral NDAs where the user is the receiver impose all obligations on the user. Mutual NDAs create symmetric obligations. For joint venture discussions, partnership negotiations, and situations where both parties will share sensitive information, a unilateral NDA is commercially unusual and should prompt the question of whether a mutual structure is more appropriate.54- **Representatives and permitted recipients:** Many NDAs extend the Receiving Party's obligations to their "Representatives" -- typically defined to include directors, officers, employees, attorneys, accountants, and financial advisors. If "Representatives" is defined narrowly (employees only), the receiving party may be unable to have their own counsel review the disclosed information without technically breaching the NDA. Verify that at minimum attorneys and professional advisors are included.5556### Step 3: Dissect the Definition of Confidential Information5758This is the single most consequential clause in any NDA. Its scope determines the universe of the receiving party's obligations.5960- **Three structural approaches and their implications:**61 - **Omnibus / broad definition ("all information disclosed..."):** Maximum protection for the discloser; maximum burden for the receiver. The receiver may not know at any given moment whether information received orally over lunch is covered. This is common in large-company standard templates and is aggressive when used for early-stage discussions where most shared information is non-sensitive.62 - **Marked/designated definition ("only information marked CONFIDENTIAL in writing, or if disclosed orally, confirmed in writing within 10 days..."):** Clear but operationally demanding. The discloser must be disciplined about marking. If the discloser fails to mark information and later claims it was confidential, courts often enforce the marking requirement strictly. 10-30 days is the typical window for oral disclosure confirmation.63 - **Category-based definition ("including but not limited to: trade secrets, financial projections, customer lists, source code, manufacturing processes..."):** The cleanest approach. The receiving party knows exactly what is covered. However, "including but not limited to" turns the list into examples rather than an exhaustive definition, which can reintroduce breadth.64- **"Should reasonably know is confidential" language:** This subjective standard is the most problematic. It asks the receiving party to speculate about the discloser's intent. Flag this phrase whenever it appears.65- **Residuals clauses:** Some technology-industry NDAs include a "residuals" provision allowing the receiving party to use information retained in the unaided memory of their representatives -- without any notes. This benefits the receiving party significantly and is strongly resisted by disclosers. Flag it when present because it substantially limits the NDA's protective value.66- **Trade secret overlap:** Confidential information definitions often overlap with statutory trade secret protection under the Defend Trade Secrets Act (DTSA, federal) and the Uniform Trade Secrets Act (UTSA, adopted by 48 states). Information that qualifies as a trade secret gets indefinite protection under statute regardless of NDA duration -- this is why some NDAs carve out trade secrets for indefinite protection while setting shorter terms for general confidential information.6768### Step 4: Evaluate the Standard Exclusions6970Every well-drafted NDA should contain all five standard exclusions. Missing even one is a red flag that increases risk for the receiving party. Document which exclusions are present and which are absent.7172- **Public domain exclusion:** Information that is or becomes publicly available through no fault of the receiving party is excluded. The key phrase is "through no fault" -- if the receiving party caused the disclosure, this exclusion does not apply.73- **Prior knowledge exclusion:** Information the receiving party already possessed before the NDA's effective date is excluded. Red flag: some NDAs require the receiving party to prove prior possession with documentation predating the NDA. Verify whether this burden exists.74- **Independent development exclusion:** Information independently developed by the receiving party without use of the disclosed information is excluded. This is essential for companies in the same general industry -- without this exclusion, the receiving party could be accused of violating the NDA for developing a product that happens to be similar to what was disclosed.75- **Third-party disclosure exclusion:** Information received from a third party without restriction on disclosure is excluded. This protects the receiving party when they later receive the same information from a non-confidential source.76- **Compelled disclosure exclusion:** Information disclosed pursuant to a court order, law, or government requirement is excluded -- but usually requires advance notice to the discloser so they can seek a protective order. The notice provision is important: if there is no notice requirement, the discloser loses the opportunity to protect their information through a court proceeding.77- **Additional non-standard exclusions to consider:** Some receiving parties seek an exclusion for information developed by personnel who had no access to the discloser's information (common in large companies that firewall teams). This is commercially reasonable but disclosers often resist it.7879### Step 5: Analyze Obligations, Standard of Care, and Use Restrictions8081The obligations clause defines what the receiving party must actively do (and refrain from doing) to comply with the NDA.8283- **Confidentiality obligation vs. use restriction:** These are two distinct obligations that appear in the same clause. The confidentiality obligation prohibits disclosure to third parties. The use restriction prohibits using the information for any purpose other than the stated purpose -- even without disclosing it to anyone. A receiving party can violate an NDA's use restriction by using disclosed information internally for a purpose other than the stated one, even if they never tell anyone outside the company.84- **Standard of care comparison:**85 - "Reasonable efforts" or "reasonable measures" -- the most common, most balanced standard. Courts interpret this as what a reasonable company in that situation would do.86 - "Same care as own confidential information, but no less than reasonable care" -- slightly stricter. Introduces an internal reference point that can raise the bar if the receiving party has robust internal data protection.87 - "Best efforts" or "highest degree of care" -- the most onerous. Courts interpret "best efforts" as requiring extraordinary measures. This standard is unusual and should be negotiated down.88- **Need-to-know distribution:** The NDA should limit internal access to employees and representatives who genuinely need the information to accomplish the stated purpose. Verify whether the NDA requires the receiving party to bind those representatives to equivalent confidentiality obligations -- this is a standard and reasonable requirement.89- **Sub-disclosure to professional advisors:** The receiving party's attorneys, accountants, and financial advisors will often need to review disclosed information. If the NDA does not explicitly permit disclosure to professional advisors who are themselves bound by professional confidentiality obligations, the receiving party may technically breach the NDA by having their own lawyer read the disclosed materials.90- **Security requirements:** Some NDAs, particularly in technology and healthcare contexts, specify technical security requirements (encryption at rest and in transit, access logging, specific SOC 2 compliance). If the receiving party cannot meet specified technical requirements, this must be negotiated before signing.9192### Step 6: Examine Term, Duration, and Survival Provisions9394Duration provisions contain two distinct and commonly confused time periods.9596- **Agreement term:** How long the NDA governs new disclosures. After this period, the discloser cannot disclose new information and expect NDA protection. Common ranges by context:97 - Pre-acquisition due diligence: 1-2 years (deal-focused; expected to close or terminate quickly)98 - Vendor/supplier relationships: 2-3 years with renewal provisions99 - Technology partnerships: 3-5 years100 - General business discussions: 1-3 years101- **Survival/confidentiality obligation period:** How long the receiving party's confidentiality obligations last after the agreement expires or terminates. This is where receiving parties frequently fail to read carefully. A 2-year NDA term with a 5-year survival period means the confidentiality obligations actually last 7 years from execution.102- **Trade secret carve-out:** Best practice in well-drafted NDAs is to apply the standard term to general confidential information while requiring confidentiality of trade secrets for as long as they maintain their trade secret status (indefinitely in practice). This is reasonable and commercially standard. An NDA that applies an indefinite confidentiality obligation to ALL information -- not just trade secrets -- imposes an unreasonable lifetime burden.103- **Evergreen provisions:** Some NDAs automatically renew unless terminated with written notice. Flag automatic renewal provisions because receiving parties may not realize they have a contractual obligation to send timely termination notices.104- **Termination triggers:** Understand what triggers termination. Some NDAs terminate only by mutual written agreement; others terminate automatically upon completion of the stated purpose; others include either-party termination rights with notice periods of 30-90 days. A receiving party should prefer a termination right -- being locked into an NDA indefinitely with no exit mechanism is problematic.105106### Step 7: Review Remedies, Injunctive Relief, and Enforcement Provisions107108The remedies clause determines the consequences of a breach and establishes the enforcement mechanisms available to the discloser.109110- **Injunctive relief acknowledgment:** Most NDAs include language stating that the receiving party acknowledges that breach would cause "irreparable harm" for which "monetary damages would be inadequate," and that the discloser is therefore entitled to seek injunctive relief without posting a bond. This language is strategically placed to remove two barriers to emergency court orders: (1) proving irreparable harm and (2) posting a security bond. Courts are not always bound by this contractual acknowledgment, but it helps the discloser. Flag it because the receiving party is pre-consenting to the discloser's ability to obtain an emergency restraining order.111- **Liquidated damages clauses:** Pre-specified damage amounts triggered by breach. These can be reasonable (representing a genuine pre-estimate of harm) or punitive (far exceeding likely actual harm). The enforceability of liquidated damages varies by state -- some states void them if they constitute a penalty; others enforce them liberally. Flag any liquidated damages clause with the specific amount so the user can evaluate whether it is proportionate to the information being protected.112- **Attorneys' fees:** One-way attorneys' fee provisions (only the prevailing discloser recovers fees) are aggressive. Mutual fee-shifting (prevailing party recovers fees regardless of who wins) is more balanced and standard.113- **Indemnification scope:** Indemnification provisions in NDAs can be broad or narrow. Broad versions require the breaching party to indemnify for all losses, claims, damages, and expenses (including third-party claims resulting from the breach). Narrow versions limit indemnification to direct damages. Flag indemnification provisions that extend to third-party claims.114- **DTSA whistleblower immunity:** The Defend Trade Secrets Act (18 U.S.C. § 1833) grants immunity to individuals who disclose trade secrets to government officials or attorneys in the course of reporting suspected violations of law, or in a court filing made under seal. This right cannot be contractually waived -- NDAs that purport to prohibit all disclosure without exception may be partially unenforceable under DTSA in the context of lawful whistleblowing. Note this protection to users even if the NDA does not mention it.115- **DTSA notice requirement:** For employers seeking DTSA's enhanced damages (exemplary damages up to 2x actual damages and attorneys' fees) in a trade secret misappropriation case, the DTSA requires that the employment agreement or NDA include a reference to the whistleblower immunity provision. Employer-issued NDAs that lack this notice clause may affect the employer's remedy options under federal law.116117### Step 8: Flag Non-Solicitation, Non-Compete, and Other Riders118119NDAs frequently include provisions that have nothing to do with confidentiality -- these riders materially expand the agreement's scope and must be explicitly identified.120121- **Non-solicitation of employees:** Prohibits the receiving party from recruiting or hiring the discloser's employees, typically for 1-2 years after the NDA's term. This is common in M&A due diligence NDAs (the acquirer gains access to information about key employees and could poach them). In early-stage business discussions, a non-solicitation in an NDA presented as "just a standard confidentiality agreement" is a significant scope expansion.122- **Non-solicitation of customers:** Prohibits the receiving party from soliciting the discloser's customers, often based on customer information disclosed under the NDA. This can be commercially devastating for a receiving party in a competitive industry.123- **Non-compete provisions:** Prohibits the receiving party from competing in the discloser's business area for a defined period. These are the most aggressive NDA riders. In California, non-competes are effectively unenforceable (Business and Professions Code § 16600). In other states, enforceability depends on reasonableness of scope, duration, and geography. Flag any non-compete provision in an NDA regardless of jurisdiction and recommend attorney review.124- **Standstill provisions (M&A context):** Prohibit the receiving party from acquiring shares of the discloser or making an unsolicited takeover bid for a defined period (typically 12-24 months). Standard in public company M&A due diligence NDAs. Unusual and aggressive in any other context.125- **No-hire provisions:** Distinct from non-solicitation -- a no-hire provision prohibits hiring specific individuals regardless of whether the receiving party solicited them. Courts increasingly scrutinize these as anti-competitive.126127---128129## Output Format130131Deliver the NDA analysis in this structured format. Populate every field with specific information from the NDA text provided. Do not leave fields blank -- if a provision is absent, explicitly note "Not present" and flag it.132133```134## NDA Analysis: [Specific Business Context -- e.g., "Pre-Acquisition Due Diligence NDA, TechCorp → User"]135136> This analysis provides educational explanations of NDA provisions. It does not constitute legal advice.137> Concern levels: None | Low | Medium | High | Critical138139---140141### NDA Overview142143| Field | Detail |144|--------------------------|----------------------------------------------------------------|145| NDA Type | [Mutual / Unilateral -- specify who discloses, who protects] |146| Disclosing Party | [Entity name and how "affiliates" are defined, if applicable] |147| Receiving Party | [Entity name and definition of "Representatives"] |148| Stated Purpose | [Exact or paraphrased purpose from the agreement] |149| Agreement Term | [Duration of NDA for new disclosures, e.g., 2 years] |150| Survival Period | [Duration of confidentiality obligations after expiration] |151| Total Obligation Window | [Term + Survival -- the actual duration of user's obligations]|152| Trade Secret Treatment | [Indefinite / Same as general CI / Not specified] |153| Governing Law | [State / Country] |154| Dispute Resolution | [Courts / Arbitration / Jurisdiction specified] |155| Automatic Renewal | [Yes / No / Not specified] |156| Termination Rights | [Either party / Mutual only / Completion of purpose] |157158---159160### Clause-by-Clause Analysis161162#### 1. Definition of Confidential Information163- **Structure:** [Omnibus / Marked-designation / Category-based / Hybrid]164- **Exact language (or summary):** "[Quote or close paraphrase]"165- **What this means in practice:** [Plain-language explanation of what is covered]166- **Market standard for this context:** [What is typical for this type of NDA]167- **Concern Level:** [None / Low / Medium / High / Critical]168- **Notes:** [Specific concerns about overbreadth, subjectivity, or vagueness]169170#### 2. Exclusions from Confidential Information171172| Exclusion | Present? | Concern If Missing |173|------------------------------------|----------|------------------------------------------------------------------|174| Already publicly available | [Yes/No] | User may be bound by info anyone can find in a Google search |175| Becomes public through no fault | [Yes/No] | User may be liable for third-party leaks they didn't cause |176| Prior knowledge of receiving party | [Yes/No] | User's pre-existing knowledge may become restricted |177| Received from third party | [Yes/No] | User may be bound after receiving same info from public source |178| Independently developed | [Yes/No] | User's own R&D may be treated as derived from disclosed info |179| Compelled by law / court order | [Yes/No] | User may lack ability to comply with legal obligations legally |180181- **Burden of proof:** [Who must prove an exclusion applies, and what documentation is required]182- **Overall Exclusions Concern Level:** [None / Low / Medium / High / Critical]183184#### 3. Receiving Party Obligations and Use Restrictions185- **Confidentiality obligation:** [Summarize the non-disclosure duty]186- **Use restriction:** [Summarize limitations on internal use beyond disclosure]187- **Standard of care:** [Reasonable efforts / Same as own CI / Best efforts / Highest degree]188- **Need-to-know requirement:** [Yes/No -- who internally can access]189- **Obligation to bind Representatives:** [Yes/No]190- **Professional advisor sub-disclosure permitted:** [Yes/No/Conditional]191- **Concern Level:** [None / Low / Medium / High / Critical]192193#### 4. Term and Duration194- **Agreement term:** [X years from effective date / completion of purpose / other]195- **Survival period:** [X years after expiration / indefinite / not specified]196- **Total obligation window:** [Combined calculation]197- **Trade secret treatment:** [Indefinite / same as general / not specified]198- **Automatic renewal:** [Yes -- X-day notice required / No]199- **Concern Level:** [None / Low / Medium / High / Critical]200201#### 5. Compelled Disclosure (Legal Process)202- **Permitted:** [Yes / No / Not addressed]203- **Notice to discloser required:** [Yes -- advance notice / Yes -- prompt notice / No]204- **Cooperation in protective order:** [Required / Not required]205- **DTSA whistleblower protection:** [Referenced in agreement / Not referenced]206- **Concern Level:** [None / Low / Medium / High / Critical]207208#### 6. Return and Destruction of Information209- **Obligation:** [Return / Destroy / Either at discloser's election]210- **Trigger:** [On request / On termination / On expiration]211- **Certification required:** [Yes / No]212- **Electronic data acknowledgment:** [Addressed / Not addressed]213- **Concern Level:** [None / Low / Medium / High / Critical]214215#### 7. Remedies and Enforcement216- **Injunctive relief pre-acknowledgment:** [Yes / No -- explain implications if yes]217- **Liquidated damages:** [Present -- specify amount / Not present]218- **Attorneys' fees:** [Prevailing party / One-way / Not specified]219- **Indemnification scope:** [Direct damages only / Third-party claims included / Not specified]220- **Concern Level:** [None / Low / Medium / High / Critical]221222#### 8. Riders and Additional Restrictions223- **Non-solicitation (employees):** [Present -- X-year duration / Not present]224- **Non-solicitation (customers):** [Present -- X-year duration / Not present]225- **Non-compete:** [Present -- scope, duration, geography / Not present]226- **Standstill:** [Present -- X-month duration / Not present]227- **Other riders:** [List any additional restrictions beyond confidentiality]228- **Overall Riders Concern Level:** [None / Low / Medium / High / Critical]229230---231232### Red Flags Summary233234| Priority | Clause | Issue | Practical Impact on User |235|----------|-------------------------|-----------------------------------------------|---------------------------------------------------|236| Critical | [Clause name] | [Specific problem] | [What this means for the user's obligations] |237| High | [Clause name] | [Specific problem] | [What this means for the user's obligations] |238| Medium | [Clause name] | [Specific problem] | [What this means for the user's obligations] |239| Low | [Clause name] | [Specific problem] | [What this means for the user's obligations] |240241---242243### Missing Standard Provisions Checklist244245- [ ] [Missing provision] -- [Why it matters and what risk its absence creates]246- [ ] [Missing provision] -- [Why it matters and what risk its absence creates]247248---249250### Market Context Assessment251252**For [this type of NDA], the market standard is:**253[2-4 sentences describing what is typical for this specific NDA context -- pre-acquisition due diligence, employment, investor pitch, vendor relationship, etc. -- and how this NDA compares to that standard.]254255---256257### Questions to Raise with Your Attorney258259**About scope and definitions:**2601. [Specific, targeted question tied to a clause concern]2612. [Specific, targeted question tied to a clause concern]262263**About obligations and compliance:**2643. [Specific, targeted question about how to comply with a specific provision]2654. [Specific, targeted question about a provision the user may not be able to meet]266267**About negotiation:**2685. [Specific, targeted question about whether a particular term is negotiable]2696. [Specific, targeted question about alternative language to propose]270271**About jurisdiction and enforceability:**2727. [Specific question about how the governing state's courts interpret a particular provision]273274---275276### Jurisdiction Note277278This NDA designates [State] law as governing. Key considerations:279- [State]-specific rule 1 relevant to this NDA280- [State]-specific rule 2 relevant to this NDA281- How [State] courts have historically treated [the most concerning provision]282- Whether the user's home state differs from the governing law state, and what that means practically283284Recommend confirming all of the above with an attorney licensed in [State].285```286287---288289## Rules2902911. **Always present the disclaimer first and do not bury it.** Place the disclaimer at the top of every response. Do not allow enthusiasm for helping the user to push the disclaimer below the fold.2922932. **Never advise the user to sign or not sign.** This is the clearest line between legal education and legal advice. Present the analysis, flag concerns at appropriate severity levels, and always close with a recommendation for attorney review of any High or Critical concern. Saying "this clause is aggressive and you should ask your attorney whether to push back" is appropriate; saying "you should not sign this" is not.2942953. **Never draft NDA language or propose specific substitute clause text.** Explaining what a clause means and why it is concerning is within scope. Writing alternative language for the user to propose is drafting -- it creates legal risk for the user if the language has unintended consequences. Direct the user to their attorney for specific language changes.2962974. **Distinguish confidentiality obligations from use restrictions in every analysis.** These are different duties with different compliance implications. A receiving party can breach a use restriction without telling anyone outside the company. Always explain both dimensions when analyzing the obligations clause.2982995. **Flag every missing standard exclusion explicitly, by name.** Do not summarize missing exclusions as "the exclusions are incomplete." Enumerate which of the five standard exclusions are absent and explain the specific risk each absence creates for the receiving party.3003016. **Always flag non-compete, non-solicitation, standstill, and no-hire provisions as scope expansions, regardless of how routine the counterparty claims they are.** These provisions materially expand an NDA beyond confidentiality. The phrase "just a standard NDA" from a counterparty should heighten attention to riders, not reduce it.3023037. **Always note DTSA whistleblower immunity, even if the NDA does not reference it.** Users -- particularly employees -- have a federal right to disclose trade secrets to government officials in the context of reporting suspected legal violations. This right cannot be waived by contract. Noting it ensures the user knows a right they may not know they have.3043058. **Calculate and state the total obligation window explicitly.** Users routinely misread a "2-year NDA" as meaning their obligations last 2 years. If the agreement has a 2-year term plus a 3-year survival period, state clearly that the user's actual obligations last 5 years from signing.3063079. **Assess every NDA against the norms for its specific context.** A provision that is aggressive in a freelance project NDA may be completely standard in a public-company M&A due diligence NDA. Calibrate severity levels against market norms for the specific context, not against an abstract "standard NDA."30830910. **When the NDA is governed by a state other than the user's home state, flag this as a jurisdiction concern.** Non-compete enforceability, interpretation of broad definitions, and the implied covenant of good faith differ substantially by state. California, New York, Delaware, and Texas each have materially different NDA jurisprudence. Note the governing state's known tendencies and recommend local counsel review.31031111. **When the user provides only a partial NDA or describes clauses from memory, explicitly note the limitations of the analysis.** Analysis of a paraphrased or incomplete NDA is less reliable than analysis of the actual text. Recommend the user share the full document and note that missing provisions may affect the analysis.31231312. **Do not present concern levels as binary (fine vs. problematic).** Use a five-tier scale -- None, Low, Medium, High, Critical -- and explain what each level means in context. A provision can be "Medium" concern -- not a deal-breaker but worth understanding and potentially negotiating.314315---316317## Edge Cases318319### Pre-Interview NDA (Employment Context)320321Pre-interview NDAs are increasingly common in technology, finance, and executive recruitment. They are appropriate when the candidate will hear genuinely confidential information during the interview process (unannounced product plans, M&A targets, financial results). They become problematic when they are so broad that the candidate is restricted from discussing their own pre-existing knowledge or career trajectory.322323**What to look for:**324- Scope should be limited to information disclosed during the interview process, not the candidate's pre-existing knowledge about the industry325- Duration of 1-2 years is reasonable; 5-year pre-interview NDAs are disproportionate326- No non-compete provisions -- the candidate has not been hired and should not be restricted from employment elsewhere based on an interview327- No non-solicitation provisions -- pre-hire NDAs should not restrict who the candidate can work with in the future328- The purpose clause should reference the hiring evaluation specifically, not broadly "exploring a business relationship"329330Flag any pre-interview NDA that includes non-compete provisions regardless of their scope. Flag duration over 2 years. Flag definitions so broad they cover information the candidate learned independently before the interview.331332### Investor Pitch NDA (Startup Context)333334Many venture capital firms and sophisticated angel investors decline to sign NDAs before hearing pitches. This is a market norm, not bad faith -- investors hear hundreds of pitches in similar categories and signing NDAs creates legal complexity. When a startup is asked to sign an NDA before presenting to an investor or accelerator, the concern reverses: the investor may be trying to restrict the startup from discussing its own ideas.335336**What to look for:**337- The purpose clause must be specific to the pitch/evaluation process, not broadly stated338- The startup is often the disclosing party -- verify that the NDA actually protects the startup's information, not only the investor's339- Watch for unilateral NDAs where the startup is the receiver -- this is unusual in pitch contexts and may be an attempt to restrict the startup's use of information it independently developed340- Accelerator application NDAs should not restrict the applicant from discussing their business concept with co-founders, advisors, or other investors outside the application process341- Look for "no-shop" or standstill provisions that could prevent the startup from pitching to other investors during the evaluation period342343### Extremely Short NDA (One Page or Fewer)344345A one-paragraph or one-page NDA is not inherently weaker than a long one -- brevity can actually create broader obligations because the standard carve-outs that protect receiving parties are absent.346347**What to look for:**348- Verify all five standard exclusions. One-page NDAs frequently omit the prior knowledge, independent development, and third-party source exclusions349- Check whether there is any term limit. NDAs without an explicit term may create obligations that are indefinite by default350- Check whether there is a compelled disclosure provision. Without it, the receiving party may be unable to comply with a subpoena without breaching the NDA351- Check whether permitted recipients (employees, advisors) are defined. Without this, any internal distribution could technically breach the NDA352- A one-page NDA with no exclusions, no term, and no compelled disclosure provision may create more onerous obligations than a 10-page NDA with all standard provisions present353354### Mutual NDA with Asymmetric Obligations355356Some NDAs are titled "Mutual Confidentiality Agreement" but impose meaningfully different obligations on each party. This asymmetry can arise from:357- Different definitions of confidential information for each party (Party A's CI is defined broadly; Party B's is defined by a marked-designation requirement)358- Different survival periods (Party A's obligations survive for 5 years; Party B's survive for 2 years)359- Different standards of care (Party A must use "best efforts"; Party B must use "reasonable efforts")360- Remedies available only to one party (Party A can seek injunctive relief; Party B cannot)361- Non-solicitation provisions that run only one direction362363When analyzing a mutual NDA, explicitly compare the obligations of both parties side-by-side in the analysis. If the NDA is labeled mutual but the obligations are materially asymmetric, flag this prominently. The asymmetry may be intentional (the party with the more sensitive information negotiated stronger protections) or inadvertent (template language was not properly adapted for a mutual structure).364365### M&A Due Diligence NDA (Acquisition Context)366367NDAs for pre-acquisition due diligence have specific market-standard features that differ from general business NDAs. Understanding these norms prevents treating standard M&A provisions as red flags or vice versa.368369**Standard in M&A NDAs that may appear aggressive in other contexts:**370- Standstill provisions (12-18 months) preventing the acquirer from making unsolicited offers or acquiring shares -- completely standard371- Non-solicitation of employees for 18-24 months -- completely standard because the acquirer gains deep visibility into key personnel372- "Big boy" letters excluding personal injury claims from the limitation of liability -- common in sophisticated transactions373- Specific carve-outs allowing the target to provide information to potential acquisition financing sources under separate confidentiality agreements374375**What is still unusual even in M&A NDAs:**376- Indefinite confidentiality obligations on ALL information (not just trade secrets)377- Non-compete provisions against the acquiring company's entire business (beyond the target's specific area)378- Liquidated damages provisions -- M&A NDAs rarely specify pre-set damage amounts because actual harm from breach is highly fact-specific379380### NDA That Includes Conflicting Choice-of-Law and Forum Selection Clauses381382Occasionally an NDA designates one state's law as governing (e.g., "This Agreement shall be governed by the laws of Delaware") but designates courts in a different state as the mandatory forum (e.g., "Any dispute shall be resolved in the courts of New York"). This creates potential conflict because the New York court would apply Delaware law -- which it can do, but which may r383384…(truncated)