Define: Keep Confidential

In a contract, to "keep confidential" means to protect disclosed information from unauthorized access or disclosure. The obligated party must limit sharing to those with a genuine need to know, obtain consent before further disclosure, and apply reasonable safeguards, ensuring sensitive business, technical, or personal information remains protected throughout and often after the agreement's term.

Legal accuracy standard set & glossary spot-checked by Imad Mohammed Nazar , Skadden-trained M&A lawyer, Legal Engineer at GenieAI

What Keep Confidential Means in a Contract

The phrase "keep confidential" is a contractual obligation imposed on a party who receives sensitive information from another party. It requires that recipient to prevent unauthorized disclosure, whether accidental or deliberate, and to treat the information with a defined standard of care. This obligation typically applies to trade secrets, financial data, business plans, personal data, and other proprietary materials shared during a business relationship.

The obligation is not merely a moral commitment but a legally enforceable term. Breaching it can expose the disclosing party to competitive harm, regulatory scrutiny, or reputational damage, and can give rise to claims for damages or injunctive relief under the law governing the contract. Because of this, the phrase is rarely left to stand alone; it is almost always paired with definitions, exceptions, and procedural requirements that clarify what counts as confidential and how it must be handled.

In practice, keeping information confidential also means restricting internal access. Even within the recipient's own organization, only employees, contractors, or advisers with a legitimate need to know should be permitted to view the material, and further disclosure to third parties usually requires the discloser's explicit consent.

How Keep Confidential Is Defined or Measured

Most agreements measure compliance with a "keep confidential" obligation against a defined standard of care, often phrased as the same degree of care the recipient uses to protect its own confidential information, but never less than a reasonable standard. This dual test balances practicality with a baseline of diligence that protects the discloser even if the recipient's internal practices are lax.

Definitions matter enormously here. A contract will typically specify what qualifies as confidential information (marked documents, orally disclosed information later confirmed in writing, or anything a reasonable person would understand to be sensitive) and what falls outside the obligation, such as information already public, independently developed, or rightfully obtained from a third party without restriction.

  • Marking requirements: some contracts require confidential material to be labeled as such to trigger protection.
  • Access logs and controls: technical measures, sometimes referenced through an Information Security Policy, can serve as evidence of compliance.
  • Duration: obligations may survive termination for a fixed period or indefinitely for trade secrets.

Where Keep Confidential Appears in Agreements

The obligation to keep information confidential is the core promise found in a Non-Disclosure Agreement, but it also appears as a standalone clause embedded within broader commercial contracts, employment agreements, licensing deals, and joint venture arrangements. It frequently sits alongside consent mechanisms, since disclosure to a third party is often permitted only with prior written approval, documented through instruments like a Consent Letter.

Confidentiality clauses also intersect with disclosure processes during transactions. A Disclosure Agreement or disclosure schedule may carve out specific exceptions to what must be kept confidential, particularly during due diligence when sensitive information is shared with prospective buyers or investors.

Industries handling sensitive data, such as healthcare, finance, and technology, rely heavily on these clauses to satisfy regulatory expectations and client trust. Access restrictions are often reinforced by internal policy documents, and organizations sometimes pair confidentiality terms with an Access Control Policy to operationalize the legal promise.

Why the Exact Wording Matters

Vague confidentiality language creates uncertainty about what must be protected and for how long. If a contract simply states that a party must "keep confidential" without defining scope, exceptions, or duration, disputes can arise over whether specific information was ever intended to be covered, or whether disclosure to an affiliate, adviser, or regulator was permitted.

Precise wording also determines remedies. Contracts that specify injunctive relief as an available remedy, in addition to damages, give the disclosing party a faster route to stop ongoing unauthorized disclosure. Similarly, clear survival clauses ensure the obligation does not simply evaporate once the underlying agreement ends, which is critical for trade secrets that retain value indefinitely.

Ambiguity around consent requirements is another common pitfall. If the contract does not specify whether consent must be written, and from whom, parties may disagree later about whether a disclosure was authorized.

Drafting Considerations

Drafters should define confidential information with enough specificity to be enforceable while remaining broad enough to cover the realistic scope of what will be shared. Standard exclusions, such as publicly available information, should be included to avoid overreach. The standard of care, whether reasonable care or a higher contractual standard, should be explicitly stated rather than assumed.

It is also wise to address the mechanics of consent and access restriction directly, specifying who within the recipient's organization may access the information and what approval process applies before any third-party disclosure. Referencing supporting instruments, such as a disclosure schedule, can help manage exceptions transparently.

Finally, consider the practical enforcement of the obligation. Clauses should specify the duration of confidentiality, whether it survives termination, and what remedies apply on breach, ensuring the obligation to keep information confidential is not just aspirational but genuinely actionable.

Relevant Circumstances

  • When sharing sensitive information with another party
  • In consulting projects where confidential business information is involved
  • During projects that require the sharing of proprietary technology or knowledge
  • When submitting a patent application which involves the disclosure of technical knowledge

Looking for a quick legal answer?

Draft, review and negotiate legal documents empowered by the market-leading contracting AI.

No credit card required - 30-second signup