Introduction
In my years of practice as a Company Secretary and legal advisor, one pattern I see repeatedly is this: a founder walks into a meeting with a potential investor, a consultant, or a prospective partner — shares the details of their business model, their pricing strategy, their customer list — and walks out having signed nothing. Weeks later, the deal falls through. And the information is out there.
This scenario plays out far more often than it should, and almost always because the parties skipped what should have been the very first document exchanged: a Non-Disclosure Agreement (NDA).
In this post, I want to break down what an NDA actually does, when you need one, what you must look out for before signing one, and — importantly — what can go wrong if you do not have one in place. My aim is to give you a practitioner's view, not just a textbook definition.
What Is a Non-Disclosure Agreement?
A Non-Disclosure Agreement (also called a Confidentiality Agreement) is a legally binding contract between two or more parties under which one party (or both) agrees to keep certain information shared between them strictly confidential and not to disclose it to any third party without authorisation.
Under Indian law, an NDA draws its enforceability primarily from the Indian Contract Act, 1872 — it is a valid contract provided it satisfies the essentials of a contract: offer, acceptance, consideration, free consent, lawful object, and competency of parties. Breach of an NDA can give rise to a claim for damages and, in appropriate cases, injunctive relief before a court.
The NDA is typically the first legal document that should be executed before any substantive business discussions begin — before you share your pitch deck, before you bring in a consultant, before you sit down with a potential joint venture partner.
When Do You Need an NDA?
Here are the most common situations where an NDA is not optional — it is essential:
1. Before presenting your business to an investor or venture capitalist When you share your financial projections, product roadmap, or customer acquisition strategy with a potential investor, you are placing enormous trust in that person. An NDA ensures that information cannot be used against you — for example, shared with a competing investee company.
2. When hiring a consultant or external agency Consultants, marketing agencies, IT vendors, and auditors routinely gain access to sensitive business information as part of their engagement. An NDA executed before the engagement begins is your first line of protection.
Example from practice: A mid-sized manufacturing company engaged a consultancy firm to identify inefficiencies in their production process. In the course of this engagement, the consultants were given access to the company's cost structures, supplier contracts, and profit margins. Without an NDA, there would have been nothing to prevent that firm from sharing those details — deliberately or inadvertently — with a competitor. An NDA executed at the outset ensured the information remained protected, with contractual remedies available in the event of breach.
3. During joint venture negotiations If you are exploring a joint venture, both parties are simultaneously sharing sensitive information with each other. This calls for a mutual NDA — one where both sides are equally bound. If the other side sends you a one-sided NDA, pause and review carefully (more on this below).
4. When onboarding key employees Employees in senior, technical, or client-facing roles often have access to trade secrets, client databases, pricing models, and business strategies. Non-disclosure obligations should form part of their employment agreements or a separate NDA executed at the time of joining.
5. During mergers and acquisitions due diligence In an M&A transaction, the target company discloses extensive confidential financial, legal, and operational information to the acquirer. An NDA (often called a Confidentiality Agreement in this context) is invariably the first document signed in any M&A process.
Who Does an NDA Bind?
This is a question clients often ask me, and the answer is broader than most people expect.
An NDA binds not just the party that signs it, but typically extends to that party's employees, officers, directors, consultants, advisors, and any other person to whom the receiving party discloses the confidential information for the purposes of evaluating the transaction.
This is why well-drafted NDAs require the receiving party to ensure that any internal personnel who receive the confidential information are themselves bound by confidentiality obligations no less strict than those in the NDA. In practice, this means the receiving party should obtain further NDAs (or internal undertakings) from every person within their organisation who handles the disclosed information — and should keep a record of these.
Key Clauses to Examine Before You Sign an NDA
Over the years, I have reviewed and negotiated hundreds of NDAs on behalf of clients. Here are the provisions that matter most:
1. Examine the Full Scope of Your Obligations
Many clients assume that because a document is titled "Non-Disclosure Agreement," the only obligation it imposes is the duty of confidentiality. This is often not the case.
NDAs frequently bundle in other obligations such as non-compete clauses (restricting you from entering a competing business for a specified period) and non-solicit clauses (preventing you from approaching the other party's employees or clients). If you sign without reading carefully, you may find yourself bound by restrictions that go well beyond keeping information confidential.
Always read the entire document. If any clause is too broad or commercially impractical, negotiate to have it modified or deleted before signing.
2. The Definition and Scope of Confidential Information
This is almost always the most negotiated clause in an NDA.
The disclosing party (the one sharing the information) will naturally want the definition of "Confidential Information" to be as broad as possible — covering all information disclosed in any form. The receiving party will want a narrow, specific definition — covering only information that is expressly marked "Confidential" or specifically identified in writing.
From a practical standpoint, if you are the disclosing party sharing sensitive business information, push for a broad definition. If you are the receiving party, a narrow definition protects you from inadvertently breaching the NDA by discussing something that was not truly sensitive.
Important note: Some NDAs go further and state that not only the content of the discussions but the very existence of the transaction is itself confidential. This is common in M&A situations. For example, where an acquisition is being contemplated, the mere fact that discussions are taking place may be price-sensitive. In such cases, both parties must be extremely careful not to let any information — even the fact that they are talking — reach the public domain.
3. Remedies Available for Breach
Money cannot always compensate for the harm caused by disclosure of confidential information. If your client database is leaked to a competitor, the damage to your business relationships and competitive position may be irreversible — no amount of damages can undo it.
This is why well-drafted NDAs invariably include a provision for injunctive relief — the right to approach a court for an urgent order requiring the breaching party to immediately stop any further disclosure and, where possible, return or destroy the information already disclosed. Under Indian law, such relief may be sought under Order XXXIX of the Civil Procedure Code, 1908.
Ensure your NDA expressly states that the parties acknowledge that a breach would cause irreparable harm and that injunctive relief shall be available without the need to prove actual monetary damage.
4. Whether Information Must Be Marked "Confidential"
Some NDAs require that for information to be protected, it must be physically marked "CONFIDENTIAL" at the time of disclosure. While this may be workable when exchanging written documents, it becomes impractical in real-world settings — for example, when confidential information is shared orally during a meeting, or when the receiving party has access to an entire shared server.
If you are the disclosing party, try to exclude or broaden this requirement so that all information disclosed in the context of the relationship is protected, regardless of whether it is specifically marked. If you are the receiving party, a marking requirement gives you greater certainty about what is and is not covered.
5. Permitted Exceptions to Confidentiality
Every well-drafted NDA must contain a set of standard exceptions — situations where the receiving party is permitted to disclose the confidential information without it constituting a breach. These typically include:
- Information that was already in the public domain at the time of disclosure (through no fault of the receiving party);
- Information that the receiving party can demonstrate was already known to it independently before disclosure;
- Information received from a third party who was entitled to disclose it; and
- Information that is required to be disclosed pursuant to a court order, statutory requirement, or direction from a regulatory authority.
The last exception is particularly important in the Indian context, given that regulators such as SEBI, the RBI, the Income Tax Department, or the MCA may require disclosure of information in the course of their investigations or proceedings. An NDA cannot and should not prevent compliance with lawful regulatory requirements — and a clause providing for this exception protects the receiving party from being caught between conflicting obligations.
6. Return or Destruction of Confidential Information
Most NDAs require that upon the conclusion of the discussions (or the termination of the agreement), the receiving party must return all confidential information — documents, files, copies — to the disclosing party, or certify that all such information has been destroyed.
This works well for physical copies (hard copy plans, printed documents, USB drives, and so on). Electronic information is trickier — emails, downloaded files, and server-stored data are harder to "return." Modern NDAs therefore typically require the receiving party to delete all electronic copies and certify this in writing, while permitting retention of copies solely for legal record-keeping or compliance purposes.
Note for consultants and advisors: If you are a consultant who has received confidential information in the course of an engagement, you may wish to negotiate the right to retain copies of your own work product — analysis, recommendations, presentations you prepared — after the engagement ends. Retaining such work can be valuable in demonstrating your expertise to future clients, once the confidentiality period expires.
7. Duration of Confidentiality Obligations
How long must the receiving party keep the information confidential? This depends on:
- The nature of the business and the information concerned; and
- Whether the NDA is standalone or embedded within a larger contract.
For fast-evolving sectors such as technology, fintech, or software, confidential information (particularly product specifications or technical know-how) may become commercially irrelevant within a year or two as the technology changes. A shorter confidentiality period (1–2 years) may therefore be appropriate.
For slow-changing information — such as a client database, a supplier network, a business model, or financial data — the information retains its value much longer. Confidentiality periods of 3–5 years, or even indefinite obligations for trade secrets, are common and defensible.
Where an NDA is embedded within a services agreement or employment contract, confidentiality obligations often survive the termination of the main contract for a specified post-termination period.
One-Sided vs. Mutual NDAs — Know the Difference
A one-sided (unilateral) NDA imposes confidentiality obligations only on the receiving party. This is appropriate when only one party is disclosing sensitive information — for example, a company sharing its pitch deck with a potential investor.
A mutual (bilateral) NDA imposes obligations on both parties. This is the right structure for joint venture negotiations, strategic partnerships, or M&A discussions where both sides are disclosing sensitive information to each other.
If you receive a one-sided NDA from the other party in a situation where you are also sharing sensitive information, you should insist that it be converted into a mutual NDA before signing.
Common Mistakes I See in Practice
Based on my experience advising clients across corporate, startup, and MSME sectors, here are the most frequent NDA-related mistakes:
Signing without reading — The most common mistake. Clients sign because "it's just an NDA" without realising the document contains non-compete or non-solicit obligations.
Not having an NDA at all — Many informal business discussions proceed on the basis of trust alone. Trust is valuable, but a signed document is enforceable.
Overly broad or vague definitions — NDAs that define "Confidential Information" as "everything we discuss" without any parameters can be difficult to enforce and create uncertainty for the receiving party.
No carve-out for compelled disclosure — Failing to include an exception for court orders or regulatory requirements puts the receiving party in an impossible position.
No survival clause — Without a clause stating that confidentiality obligations survive the termination of the agreement, the obligations may technically end when the contract does.
Conclusion
An NDA is not a formality. It is your first and most fundamental act of legal protection when entering into any business relationship that involves sharing sensitive information. Whether you are a startup founder pitching to investors, an MSME engaging a vendor, or a company entering into an acquisition — the NDA is the document that should be on the table before anything else.
At AVA Synergy, we assist clients in drafting, reviewing, and negotiating NDAs tailored to their specific business context — ensuring that the language is precise, the obligations are balanced, and your confidential information is genuinely protected.
If you would like us to review an NDA you have received, draft one for your business, or advise you on any aspect of contract drafting, do reach out to us.
Amrita Kumari Founder, AVA Synergy Company Secretary | Law Graduate Gurugram, Haryana, India 📧 info@avasynergy.com 🌐 www.avasynergy.com
AVA Synergy provides corporate compliance, legal advisory, and business outsourcing solutions. Our team comprises Company Secretaries, Chartered Accountants, and Advocates serving clients across India and in cross-border structuring matters.
Disclaimer: This blog post is for general informational and educational purposes only and does not constitute legal advice. Readers should consult a qualified legal professional before taking any action based on the contents of this post.











