Aug 12, 2026 18 mins

How to Draft and Negotiate an NDA: What Actually Matters

Legal Reviewer
How to Draft and Negotiate an NDA: What Actually Matters

To draft and negotiate an NDA properly, you decide four things before you touch a template: whether disclosure runs one way or both, how you define confidential information, how long the obligations last, and what happens when someone breaches. Get those right and the rest of the document is largely boilerplate. Get them wrong and you have a signed agreement that protects nothing you actually care about.

An AI drafting tool speeds this up, but the value is not the speed. It is that a good tool holds a consistent position across every NDA you sign, flags the clauses that are genuinely negotiated, and stops the quiet drafting errors that make confidentiality obligations unenforceable or pointless. Below is how the document works in practice, which clauses buyers and sellers actually fight over, and the mistakes that turn a signed NDA into decoration.

One-way or mutual: decide this first

Every NDA is either one-way (unilateral) or mutual (bilateral). This single choice shapes the whole document, and people get it wrong constantly by reaching for whatever template is nearest.

  • One-way (unilateral): only one party discloses confidential information, and only the receiving party takes on obligations. Use it when the flow of sensitive information is genuinely in one direction, for example a company sharing its financials with a potential buyer, or an employer sharing methods with a contractor.
  • Mutual (bilateral): both parties disclose and both are bound. Use it when both sides will reveal something worth protecting, for example two businesses exploring a joint venture, a supply arrangement, or a technology integration where each shares roadmaps and data.

The practical trap is signing a one-way NDA drafted by the other side that treats you as the receiving party only, when in fact you will also be disclosing. You then carry all the obligations and none of the protections. If you expect to share anything sensitive back, push for mutual. It is usually an easy ask because it is symmetrical and fair, and a counterparty who refuses to make a one-way NDA mutual is often telling you something about how they intend to behave with your information.

A second, subtler point: a mutual NDA is not automatically the safer choice for you. If you are the primary discloser and the other side has little to share, a mutual NDA can water down your protections by forcing symmetrical, lowest-common-denominator terms. Match the structure to the actual information flow, not to a reflex about fairness.

FactorOne-way NDAMutual NDA
Who disclosesOne partyBoth parties
Who is boundReceiving party onlyBoth parties
Typical useInvestor review, hiring, one-sided data sharingJV, partnership, integration, M&A discussions
Negotiation lengthUsually shorterUsually longer, terms must work both ways
Risk if mismatchedYou disclose without protectionYour strong protections diluted to be symmetrical

The five clauses that are actually negotiated

Most of an NDA is standard. Notices, governing law, entire agreement, no assignment, severability: these rarely move and rarely matter to the commercial outcome. The negotiation, when there is one, concentrates on five clauses. If you know these cold, you can handle almost any NDA that lands on your desk.

1. Definition of confidential information

This is the most important clause in the document and the one most people skim. Everything else in the NDA operates on whatever this definition captures. If the definition is too narrow, obligations you thought you had simply do not exist. If it is too broad, it becomes unworkable and, in some jurisdictions, harder to enforce.

Two drafting styles exist:

  1. Broad catch-all: "all information disclosed by the disclosing party, whether or not marked confidential." Favours the discloser. Easy to breach accidentally because everything is covered, including things the receiving party genuinely did not treat as secret.
  2. Marking or designation requirement: only information marked "confidential" (or confirmed in writing within a set number of days if disclosed orally) is protected. Favours the receiving party. Cleaner, but places a real administrative burden on the discloser, who must actually mark things.

The practical middle ground most experienced negotiators accept: a broad definition, plus a carve-out for the standard exclusions (below), plus a common-sense rider that information a reasonable person would understand to be confidential from its nature or the circumstances of disclosure is covered even if unmarked. That protects the discloser without demanding perfect marking discipline that nobody maintains in practice.

2. Permitted purpose

The NDA should state the specific reason the information is being shared, often called the "Purpose" or "Permitted Purpose". This clause does quiet but heavy lifting. The receiving party may only use the information for that purpose, so a tight Purpose limits misuse even where the confidentiality obligation itself is broad.

  • Too vague: "for business purposes" gives the receiving party enormous latitude.
  • Too narrow: "to evaluate the proposed supply of widgets in Q3" may stop legitimate follow-on discussions.
  • Right: "to evaluate and, if agreed, to progress a potential commercial relationship between the parties in relation to [subject]." Specific enough to bite, wide enough to be usable.

3. Term and survival

Two different clocks run in an NDA and people confuse them constantly:

  • The term of the agreement: how long the NDA is in force, i.e. how long you can keep disclosing information under it. Often one to two years, sometimes tied to the life of the underlying discussion or contract.
  • The survival period of the confidentiality obligation: how long the duty to protect already-disclosed information continues after the agreement ends. This is the number that actually matters.

A common structure is a two-year term with confidentiality obligations surviving for three or five years after each disclosure or after termination. For genuine trade secrets, some disclosers want obligations to continue indefinitely for as long as the information remains secret. That is defensible for source code, formulations or algorithms; it is overreach for a pricing sheet that will be stale in six months.

Watch for the receiving party trying to collapse everything into a short flat term, and the disclosing party trying to make everything perpetual. The right answer usually splits the difference by information type: a finite period for ordinary commercial information and a longer or indefinite period for defined trade secrets.

4. Carve-outs (standard exclusions)

Every well-drafted NDA excludes certain information from the confidentiality obligation. These carve-outs are near-universal, and a receiving party should insist on all of them. Information is not confidential to the extent it:

  1. was already publicly available, or later becomes public through no fault of the receiving party;
  2. was already lawfully in the receiving party's possession before disclosure, without an obligation of confidence;
  3. was lawfully received from a third party who was free to disclose it;
  4. was independently developed by the receiving party without using the confidential information; or
  5. is required to be disclosed by law, court order or a regulator (usually with a duty to notify the disclosing party first, where lawful, so they can seek protection).

These are rarely contentious in themselves. Where negotiation happens is around the evidential standard, for example whether "independently developed" must be shown by written records. A disclosing party will want proof; a receiving party will resist an impossible burden. Land somewhere reasonable and move on.

5. Remedies

An NDA without a meaningful remedy is a promise with no consequence. The realistic problem with confidentiality breaches is that the damage is hard to quantify in money: once information is out, it is out. So two remedy points get negotiated.

  • Injunctive relief: a clause acknowledging that damages alone may be inadequate and that the disclosing party may seek an injunction to stop or prevent a breach. This is standard and worth having, though a court will decide on the facts regardless of what the clause says.
  • Liquidated damages or a stated cap: a pre-agreed sum payable on breach. Attractive because it avoids proving loss, but risky. In England and Wales and many other jurisdictions, a liquidated damages figure that is a penalty rather than a genuine pre-estimate of loss can be struck out. Use these carefully and get them right, because a badly drafted penalty clause gives you nothing.

The residuals clause: the one people miss

Residuals deserve their own section because it is the clause that quietly guts an NDA and most non-lawyers have never heard of it. A residuals clause says, in effect: the receiving party is free to use information retained in the unaided memory of its personnel, even if that information is confidential.

The logic offered is reasonable on its face. You cannot un-know something, and technology and consulting businesses do not want their people barred from working in a field just because they once saw a confidential deck. But a broad residuals clause can swallow the entire agreement. If your engineers can use anything they "remember", the practical protection over ideas, approaches and know-how evaporates.

How to handle residuals depending on which side you are on:

  • If you are disclosing sensitive know-how: resist a residuals clause, or narrow it heavily. Exclude trade secrets from it, exclude anything deliberately memorised, and make clear it does not grant a licence to your intellectual property.
  • If you are receiving: you may reasonably want some residuals protection so your people are not contaminated. Keep it tied to genuine unaided memory, not to retained documents.

If the other side pushes a residuals clause hard and you are the discloser, treat it as a signal about what they intend to do with your information. Whether to accept it is a commercial risk decision, not a legal formality, and it should be made consciously rather than nodded through.

Seven mistakes that make an NDA unenforceable or pointless

An NDA can be perfectly signed and still worthless. These are the recurring failures, roughly in order of how often they cause real damage.

  1. The wrong party signs, or an entity is misnamed. If the NDA names "Acme Ltd" but the person disclosing sits in "Acme Holdings Ltd", or the counterparty signs through an entity with no assets, you may have no one to enforce against. Confirm the exact legal name and that the signatory has authority.
  2. No definition, or a self-defeating definition, of confidential information. If the definition requires marking and nobody ever marks anything, nothing is protected. If it excludes information "known to the receiving party" without qualification, a counterparty can claim they already knew almost anything.
  3. Obligations that only bind one party by accident. A one-way template used for a two-way situation. You disclose, but the drafting only obliges the "receiving party", which is defined as the other side. Your disclosures are unprotected.
  4. A term so long or a scope so broad it becomes an unreasonable restraint. A perpetual obligation over all information, coupled with restrictions that operate like a non-compete, can be challenged as unenforceable in some jurisdictions. Keep obligations proportionate to what you are actually protecting.
  5. Missing the regulator or court carve-out. Without it, the receiving party is technically in breach the moment they comply with a subpoena or a regulator's request, which is both unfair and a red flag that the drafting was careless.
  6. Confusing the term with the survival period. A two-year term with no survival clause means confidentiality obligations end when the agreement ends, even for information disclosed on day one. Always check what survives.
  7. No governing law or jurisdiction, or a mismatched one. If your counterparty is overseas and the NDA is silent, enforcing it becomes slow and expensive. Specify governing law and where disputes are heard, and make sure it is somewhere you can practically enforce.

None of these are exotic. They are ordinary drafting slips, and they happen because NDAs are treated as low-value paperwork that gets copied, pasted and signed under time pressure. That is exactly why a consistent process matters more than any single clever clause.

How the negotiation actually plays out

Most NDA negotiations are short, and the moves are predictable. Here is the usual choreography so you can recognise where you are.

  1. Someone sends their standard form. Whoever sends first is anchoring on their preferred position. If they are the receiving party, expect a narrow definition and short survival. If they are the discloser, expect a broad definition and long or perpetual survival.
  2. You mark up the five clauses that matter. Definition, purpose, term and survival, carve-outs, remedies, plus residuals if it appears. Leave the boilerplate alone unless it is genuinely wrong.
  3. They accept most of it. Reasonable counterparties concede the standard carve-outs and the regulator exception immediately, because refusing looks unreasonable.
  4. You resolve one or two real points. Usually survival length, the residuals clause, or whether the definition requires marking. This is a commercial trade, not a legal one.
  5. You sign. With the right entities named and the right signatories.

The discipline that separates a business that manages this risk well from one that does not is consistency. If every NDA you sign starts from the same considered positions, you know your exposure. If each one is negotiated from scratch by whoever happens to be free, your risk is scattered across dozens of documents nobody can find.

Where AI genuinely helps, and where it does not

AI is well suited to NDAs precisely because they are high-volume, repetitive and pattern-heavy, which is where consistency pays off and where human attention drifts. Used properly, an AI contract tool does three things that reduce risk on this document type.

  • It drafts from your agreed position, not a random template. Instead of copying the last NDA you can find, you generate from a house standard that already encodes the term, carve-outs and residuals stance you have decided on. GenieAI supports this kind of standardised first-draft generation so the starting point is the position you actually want to hold.
  • It reviews an inbound NDA against your playbook. When a counterparty sends their form, the tool flags where their definition is too narrow, where survival is missing, where a residuals clause has crept in, and where the entity names look wrong. Many teams use GenieAI for review and negotiation alone, treating it as a consistent second pair of eyes on every document rather than as a drafting engine.
  • It keeps the work where the work happens. Most NDAs live in Word and email. A tool that works inside Word means people do not have to change how they work to get the check done, which is the difference between a policy that is followed and one that is ignored.

What AI does not do is make the commercial call for you. Whether to accept a residuals clause, whether a five-year survival is worth pushing for, whether a counterparty's entity is worth contracting with at all: these are judgements. The tool surfaces the issue and shows you the options. You decide. And for anything genuinely high-stakes, an unusual structure, a very large exposure, an unfamiliar jurisdiction, involve a qualified lawyer. A good AI tool makes that involvement more focused, because the routine cleanup is already done before the lawyer looks.

For teams that handle a steady flow of NDAs across sales, procurement and operations, the security of the platform itself matters, because these documents contain the sensitive information the NDA exists to protect. GenieAI holds ISO/IEC 27001:2022 certification, which is the baseline you should expect from any system that touches this material.

Sector notes: NDAs are not one-size-fits-all

The five clauses are universal, but the emphasis shifts by industry. A few examples of where the pressure lands:

  • Technology: residuals and IP ownership dominate. Engineers move between projects, and a broad residuals clause can undermine the whole agreement. Definitions of confidential information need to capture source code, architecture and roadmaps specifically. This matters across technology businesses handling frequent partner and integration discussions.
  • Energy and mining: NDAs often cover geological data, reserve estimates, project economics and pricing that stay sensitive for years, so long survival periods and tight definitions matter. Teams in energy and mining frequently disclose highly valuable technical data during joint venture and offtake talks.
  • Construction and real estate: NDAs sit at the front of bids, developments and transactions, and the volume is high. Consistency across many counterparties matters more than any single clever clause, which is where a standardised process helps construction and real estate teams most.

If your NDAs feed directly into a sales pipeline, the same discipline applies to the contracts that follow them. Managing NDAs, MSAs and order forms as one consistent flow is where contract support for sales teams reduces the risk of terms drifting apart between the confidentiality stage and the deal itself.

A short checklist before you sign

Run every NDA through this, whether you drafted it or received it:

  1. Is the structure right, one-way or mutual, for the actual information flow?
  2. Are the correct legal entities named, and does the signatory have authority?
  3. Does the definition of confidential information capture what you care about without being self-defeating?
  4. Is the Purpose specific enough to limit misuse but wide enough to be usable?
  5. Do you understand both the term and the survival period, and are they proportionate?
  6. Are all five standard carve-outs present, including the regulator and court exception?
  7. Is there a residuals clause, and if so, have you consciously accepted the risk?
  8. Are the remedies meaningful, and does any liquidated damages figure risk being an unenforceable penalty?
  9. Is governing law and jurisdiction specified, and can you practically enforce there?

If you can answer all nine, you have done more than most people who sign these documents. An NDA is only as good as the thinking behind it, and the thinking takes minutes once you know what you are looking for.

Frequently asked questions

What is the difference between a one-way and a mutual NDA?

In a one-way (unilateral) NDA, only one party discloses confidential information and only the receiving party takes on obligations. In a mutual (bilateral) NDA, both parties disclose and both are bound. Choose based on the actual flow of information: use one-way when only one side is sharing something sensitive, and mutual when both sides will reveal information worth protecting, such as in a joint venture or integration discussion.

How long should an NDA last?

Two clocks matter. The term of the agreement, how long you can keep disclosing under it, is often one to two years. The survival period, how long the duty to protect already-disclosed information continues, is the number that counts and is commonly three to five years after disclosure or termination. For genuine trade secrets such as source code or formulations, obligations may last as long as the information stays secret. Ordinary commercial information does not justify a perpetual term.

What makes an NDA unenforceable?

Common causes include naming the wrong legal entity or having someone sign without authority, a definition of confidential information that is self-defeating (for example requiring marking that never happens), obligations so broad or long they amount to an unreasonable restraint, a liquidated damages figure that a court treats as a penalty, and missing governing law where the counterparty is overseas. Individually these look minor, but any one can leave you with a signed document that protects nothing.

What is a residuals clause and should I accept it?

A residuals clause lets the receiving party use confidential information retained in the unaided memory of its personnel. It sounds reasonable but can quietly gut the whole agreement, because it frees people to use ideas and know-how they remember. If you are disclosing sensitive material, resist it or narrow it heavily, excluding trade secrets and anything deliberately memorised. If you are receiving, keep any residuals right tied to genuine memory, not to retained documents. Accepting one is a conscious commercial risk decision, not a formality.

Can AI draft and negotiate an NDA?

Yes. NDAs are high-volume and pattern-heavy, which suits AI well. A good tool drafts from your agreed house position rather than a random template, reviews an inbound NDA against your playbook to flag weak definitions, missing survival periods and stray residuals clauses, and works inside Word where the negotiation happens. GenieAI does both drafting and review, and many teams use it for review alone. The tool surfaces the issues and options; the commercial judgements and any genuinely high-stakes matters still need a person, and sometimes a qualified lawyer.

What are the standard carve-outs in an NDA?

Information is typically excluded from the confidentiality obligation to the extent it was already public or later becomes public through no fault of the receiving party, was already lawfully held before disclosure, was received from a third party free to disclose it, was independently developed without using the confidential information, or must be disclosed by law, court order or a regulator. A receiving party should insist on all five, and the regulator and court exception usually carries a duty to notify the disclosing party first where lawful.

Do I need a lawyer to sign an NDA?

Not for a routine NDA, if you understand the five clauses that matter: the definition of confidential information, the purpose, the term and survival, the carve-outs, and the remedies, plus any residuals clause. For unusual structures, very large exposures, unfamiliar jurisdictions, or NDAs tied to a significant transaction, involve a qualified lawyer. Using a consistent process or an AI review tool for the routine work makes any lawyer's involvement more focused and less expensive, because the standard cleanup is already done.

What is the most important clause in an NDA?

The definition of confidential information. Every other obligation in the NDA operates on whatever this clause captures, so if it is too narrow you have protections that do not exist, and if it is unworkably broad it can be harder to enforce. The practical middle ground is a broad definition, plus the standard carve-outs, plus a rider that information a reasonable person would understand to be confidential is covered even if unmarked.

Legal Reviewer

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Interested in joining our team? Explore career opportunities with us and be a part of the future of Legal AI.

Ready to agree with confidence?
See Genie in action.