Alex is Sprintlaw's co-founder and a legal technology leader. He holds law and media degrees from the University of Sydney and has been recognized by Australasian Lawyer, Lawyers Weekly and the Sydney Young Entrepreneur Awards for his work building Sprintlaw and improving access to business legal support.
For US founders, startups, and small business operators, sharing confidential information is often necessary to build partnerships, attract investors, or hire talent. Non-disclosure agreements (NDAs) are the standard tool to protect this sensitive information. However, many businesses make mistakes when drafting, negotiating, or relying on NDAs, which can create contract risk and leave your trade secrets, business plans, or customer data exposed. This guide explains the most common NDA mistakes, why they project, and how to avoid them. We cover practical examples, state law caveats, and actionable checklists to help you use NDAs effectively and reduce risk.
What Is a Non-Disclosure Agreement?
A non-disclosure agreement (NDA) is a contract that requires one or both parties to keep certain information confidential and not use it for unauthorized purposes. NDAs are used in many business settings, including:
- Pitching new products or business ideas to investors or potential partners
- Hiring employees or contractors who will access proprietary data
- Exploring mergers, acquisitions, or joint ventures
- Collaborating with vendors, suppliers, or consultants
- Licensing technology or intellectual property
NDAs can be one-way (only one party discloses information) or mutual (both parties share and protect information). The purpose is to create a legal obligation for the recipient to keep the information secret and use it only for a specified purpose.
There is no single federal law governing all NDAs. Instead, enforceability is determined by state contract law, which can vary significantly. Some states, such as California and New York, have specific rules about what can be protected and for how long. Federal law may also apply in certain industries (such as healthcare or defense) or when trade secrets are involved under the Defend Trade Secrets Act (DTSA). Always consider which state law applies to your NDA and whether your terms align with local requirements.
Common Non-Disclosure Agreement Mistakes
Even experienced founders and operators can make mistakes that weaken or invalidate their NDAs. Here are the most common errors, with practical examples and state law caveats:
- Vague or overly broad definitions of confidential information: If your NDA says "all information" is confidential, a court may find it too vague to enforce. For example, a startup in Texas tried to protect "all business information" in an NDA with a contractor. When the contractor leaked pricing details, the court refused to enforce the NDA because it was not specific enough. Tip: List exactly what is confidential, such as "customer lists, source code, pricing models, and marketing strategies."
- Unrealistic or unenforceable time periods: Some NDAs try to impose confidentiality obligations "forever." Many states, including California, will only enforce NDAs for a reasonable period, especially for information that loses value over time. For example, a New York court refused to enforce a perpetual NDA for sales data, finding that the information was no longer sensitive after three years. Tip: Use a reasonable term (often 2-5 years for business information, longer for true trade secrets).
- No carve-outs for public information or legal disclosures: NDAs should clarify that information already known to the public, or required to be disclosed by law, is not protected. In Florida, a business tried to enforce an NDA against a former employee who shared information that was already public. The court ruled the NDA was unenforceable because it failed to include this carve-out. Tip: Always include exclusions for public, previously known, or independently developed information, and for disclosures required by law or court order.
- Failing to specify permitted uses: If the NDA does not say how the recipient can use the information, it may be too vague to enforce. For example, a California startup shared a prototype with a manufacturer under an NDA that did not limit use to evaluation purposes. The manufacturer used the design for its own product, and the NDA was not enforceable. Tip: State the purpose of disclosure (e.g., "solely to evaluate a business proposal").
- Missing signatures or unclear parties: An NDA is only binding if it is properly signed by the right parties. In Illinois, a company lost a trade secret case because the NDA was signed by an individual, not the company that actually received the information. Tip: Clearly name all parties and ensure authorized representatives sign the NDA.
- Ignoring state law differences: Using a generic template without checking local law can create problems. For example, California law restricts NDAs that limit employee mobility or whistleblowing. In Massachusetts, NDAs in employment settings must meet specific requirements to be enforceable. Tip: Always tailor your NDA to the relevant state law.
- Not updating NDAs for remote work or digital sharing: With more business conducted online, NDAs should address electronic communications, cloud storage, and remote access. In a recent Georgia case, an NDA failed to cover cloud-based file sharing, so leaked documents were not protected. Tip: Update your NDA to cover all forms of digital and remote information sharing.
These mistakes can result in an NDA that is partially or entirely unenforceable, leaving your business exposed to the risk of information leaks, lost competitive advantage, or costly litigation.
Key NDA Terms and How to Get Them Right
To reduce contract risk, pay careful attention to the following NDA terms. Here is a practical checklist, with examples and caveats:
- Definition of Confidential Information: Be specific. For example, "Confidential Information includes business plans, customer lists, pricing data, source code, and marketing strategies disclosed in writing or orally and marked as confidential." Avoid blanket terms like "all information." In states like California, overly broad definitions may be struck down.
- Purpose of Disclosure: State why the information is being shared (e.g., "to evaluate a potential partnership"). This limits how the recipient can use the information and helps courts enforce the NDA.
- Obligations of the Recipient: Spell out what the recipient must do to protect the information (e.g., "use reasonable care," "limit access to employees with a need to know"). In New York, courts look for clear obligations in the NDA text.
- Exclusions: List what is not confidential, such as information that is public, already known, or independently developed. Include a carve-out for disclosures required by law or court order. This is especially important in regulated industries.
- Term and Duration: Specify how long confidentiality obligations last. For most business information, 2-5 years is common. For trade secrets, longer periods may be justified, but "perpetual" NDAs are often challenged. In Texas, courts generally enforce reasonable durations tied to the value of the information.
- Remedies for Breach: Include language about injunctive relief or damages if the NDA is violated. For example, "The disclosing party may seek injunctive relief and damages in the event of a breach." This signals the seriousness of the obligation and may help in court.
- Governing Law and Jurisdiction: Choose which state's law applies and where disputes will be resolved. This is especially important for businesses operating in multiple states. For example, if your company is based in Delaware but discloses information to a California partner, consider which state's law is more favorable and specify it in the NDA.
- Digital and Remote Sharing: Address how information can be shared electronically, who can access it remotely, and how it must be protected. For example, "Confidential Information may be shared via secure cloud storage and accessed only by authorized personnel."
Here is a practical NDA review checklist:
- Are the parties clearly identified and authorized to sign?
- Is confidential information specifically defined?
- Is the purpose of disclosure clear and limited?
- Are exclusions and carve-outs included?
- Is the duration reasonable and enforceable under state law?
- Are remedies for breach stated?
- Does the NDA address digital and remote sharing?
- Is the governing law appropriate for your business?
Taking the time to get these terms right can make the difference between an NDA that protects your business and one that creates risk.
State Law Differences and Industry Rules
NDAs are governed by state contract law, which means enforceability can vary depending on where you and the other party are located. Here are some important state-specific considerations and industry rules:
- California: California law restricts NDAs that limit employee mobility or whistleblowing. NDAs cannot prevent employees from reporting illegal activity or moving to a competitor. California courts are also skeptical of NDAs with overly broad definitions or indefinite durations. If your business is based in or works with California parties, review your NDA for compliance with local law.
- New York: New York generally enforces NDAs but will not uphold terms that are unreasonably broad or against public policy. Recent laws limit NDAs in settlement agreements involving harassment or discrimination claims. If your NDA is part of a settlement, check for compliance with New York's specific requirements.
- Texas and Florida: These states are more likely to enforce NDAs, but courts will still scrutinize the scope and duration for reasonableness. In Texas, courts look for a clear connection between the NDA's duration and the value of the information.
- Massachusetts: NDAs with employees must meet specific statutory requirements, including notice and consideration. If you use NDAs with Massachusetts employees, review the Massachusetts Noncompetition Agreement Act for compliance.
Industry-specific rules may also apply. For example:
- Healthcare: NDAs covering patient information must comply with HIPAA and related federal regulations.
- Finance: Financial institutions may be subject to additional confidentiality requirements under federal and state law.
- Defense: Contractors in the defense industry may need to comply with federal security and confidentiality rules.
When working with parties in different states or industries, specify which state's law will govern the NDA and check for any industry-specific requirements. If you are unsure, consult an attorney familiar with the relevant jurisdictions and sector.
Practical NDA Scenarios and Common Mistakes
To illustrate how NDA mistakes can arise, here are some real-world scenarios and lessons learned:
- Startup pitching to investors: A founder emails a pitch deck to a potential investor without first getting an NDA signed. The investor later shares the idea with a competitor. Without a signed NDA, the founder has little legal recourse. Lesson: Always get NDAs signed before sharing sensitive information, even with trusted contacts.
- Hiring a remote contractor: A business hires a developer in another state and uses a generic NDA template. The NDA does not address digital file sharing or specify which state law applies. When the developer leaks code, it is unclear which court has jurisdiction or how to enforce the contract. Lesson: Customize your NDA for the specific deal, parties, and state law. Address digital and remote sharing.
- Employee onboarding: An employee signs an NDA with a perpetual confidentiality term. When the employee leaves and joins a competitor, they challenge the NDA in court. The court finds the term unreasonable and refuses to enforce it. Lesson: Use reasonable, time-limited confidentiality periods, especially for employees.
- Joint venture negotiations: Two companies enter into a mutual NDA but fail to define what information is confidential. Later, one party claims the other breached the NDA, but the vague definition makes enforcement difficult. Lesson: Clearly define confidential information and document what is disclosed.
- Vendor collaboration: A company shares sensitive pricing data with a vendor under an NDA but does not specify that the vendor's subcontractors are also bound. The subcontractor leaks the information. Lesson: Extend NDA obligations to affiliates, employees, and subcontractors where appropriate.
To avoid these mistakes, use the following practical steps:
- Always get NDAs signed before sharing confidential information.
- Customize your NDA for the specific deal, parties, and applicable state law.
- Keep clear records of what was disclosed, when, and to whom.
- Review and update NDAs regularly, especially for remote work and digital sharing.
- Extend NDA obligations to affiliates, employees, and subcontractors as needed.
- Seek legal review for high-value deals or complex arrangements.
These steps help ensure your NDA is enforceable and provides real protection for your business.
When to Seek Attorney Review for Your NDA
While many NDAs are straightforward, certain situations call for attorney review. Consider getting legal advice if:
- You are dealing with high-value intellectual property or trade secrets
- The other party is in a different state or country
- The NDA will be used in a regulated industry (healthcare, finance, defense, etc.)
- You need to enforce or challenge an NDA in court
- The NDA involves employees, contractors, or partners with access to critical business data
- The NDA will be used as part of a settlement agreement or employment contract
An attorney can help you:
- Draft clear, enforceable NDA terms tailored to your business and industry
- Identify and address state law differences and compliance issues
- Advise on digital and remote work confidentiality challenges
- Negotiate fair terms with investors, partners, or vendors
- Respond to NDA breaches or disputes, including litigation support
Legal review is especially important if you are using an NDA template from the internet. Templates may not be up to date, may not fit your business, or may not comply with state law. Investing in a tailored NDA can save significant time and cost if a dispute arises.
For example, a SaaS founder in Colorado used a free NDA template that did not address remote access or specify Colorado law. When a remote contractor in another state leaked customer data, the founder faced an uphill battle enforcing the NDA. A tailored NDA could have clarified jurisdiction, obligations, and remedies, making enforcement easier.
FAQs
Are NDAs enforceable in every US state?
NDAs are generally enforceable in most US states, but the rules vary. Some states, like California, limit how NDAs can restrict employee mobility or whistleblowing. Courts in every state will review NDAs for reasonableness, clarity, and compliance with public policy. Always check which state law applies to your NDA and whether your terms are enforceable in that jurisdiction.
How long should an NDA last?
The duration of an NDA should be reasonable based on the type of information protected. For most business information, 2-5 years is typical. Trade secrets may justify longer periods, but perpetual NDAs are often challenged in court. State law may also set limits on enforceability. For example, Massachusetts and California courts are unlikely to enforce perpetual confidentiality for ordinary business data.
What happens if someone breaches an NDA?
If an NDA is breached, the non-breaching party can seek remedies such as damages, injunctions, or specific performance. The exact remedies depend on the contract terms and state law. In practice, enforcing an NDA may require legal action in court, which can be costly and time-consuming. Having clear remedies in your NDA can help speed up the process and improve your chances of success.
Can I use a template NDA for my business?
Template NDAs can be a starting point, but they often miss key details like state law differences, digital sharing, or industry-specific requirements. It is best to customize your NDA for each deal and have it reviewed by a legal professional, especially for high-value or complex arrangements. A tailored NDA reduces risk and increases enforceability.
Do NDAs protect ideas?
NDAs can protect confidential information, but they do not protect general ideas that are not specifically defined or documented. To maximize protection, clearly describe what information is confidential and keep records of what was disclosed. If you need to protect inventions or creative works, consider using patents, copyrights, or trademarks in addition to NDAs.
Key Takeaways
- Non-disclosure agreements are essential for protecting confidential business information, but common mistakes can create contract risk.
- State law, industry rules, and contract terms all affect NDA enforceability.
- Be specific about what is confidential, how it can be used, and for how long.
- Review and update NDAs for remote work, digital sharing, and changing business needs.
- Consider attorney review for high-value, complex, or multi-state deals.
- Keep clear records of what was disclosed and to whom.
If you need help drafting, reviewing, or negotiating a non-disclosure agreement, our team can support your project through the Sprintlaw platform. Contact us at (888) 449-8437 or team@sprintlaw.com to discuss your needs. Where legal services are required, they are delivered by licensed lawyers at trusted US law firms through the Sprintlaw platform.








