One email containing confidential information, uploading source code to a personal laptop, or sharing sensitive information with a competitor can cost an IT company millions of dollars. That's why NDAs have become a standard safeguard for technology businesses.
A Non-Disclosure Agreement (NDA) is an agreement that specifies what information must remain confidential, who it may be shared with, and what happens if those obligations are breached. Companies routinely sign NDAs with employees, contractors, clients, business partners, and investors.
For IT companies, an NDA helps protect source code, product architecture, business processes, customer databases, AI developments, and other commercially valuable information.
This article explains how to draft an NDA that is more likely to be enforceable in practice. It covers the key provisions every technology company should consider, common drafting mistakes, and recent court decisions shaping the enforcement of confidentiality obligations.

What is a Non Disclosure Agreement, and why is it needed?
A non-disclosure agreement is a document that protects a business against disclosure of confidential information by team members, contractors, and clients. Signing the NDA is a crucial part of employment. For example, an employee may accept a competitor's job offer, and without an NDA, there would be a risk of disclosing trade secrets. Tesla faced such a problem when a former employee handed over logistics documents to a new employer, Zoox, and breached their NDA. The litigation ended with a settlement agreement, where the parties agreed that Zoox would pay compensation to Tesla.
Cases on NDA violation rarely reach court, more often the document plays a preventive role and serves as a warning to the employee against disclosing trade secrets. These agreements help shape corporate culture and attitudes toward confidential information.
Is it better to add an NDA as a contract clause or sign a separate agreement?
The NDA may be a part of a contract or a separate agreement. We advise including a particular clause in the main contract that will protect your privacy and set out detailed aspects in a separate agreement.
Let's take a look at an example. A company signs a software development contract with IT specialists, who are independent contractors. The software development contract will contain clauses requiring independent contractors to observe the general confidentiality rules, while more specific details such as the list of confidential information, methods of transfer and storage, and tools for proving violations will be described in a separate NDA.
The practice of American courts clearly shows that, next to NDA restrictions, there are often other restrictions including non-competition agreements (NCA) and non-solicitation agreements (NSA). All of these can be united in a single document, or executed separately.
How to Write an NDA: What to Include
The effectiveness of an NDA depends on how clearly it regulates the handling of confidential information. An effective NDA typically addresses the following issues:
- a definition of confidential information and the types of information covered by the agreement;
- information that is excluded from confidentiality obligations;
- circumstances in which disclosure is permitted;
- procedures for sharing and storing confidential information (e.g., corporate email, messaging platforms, cloud storage, code repositories, and project management tools);
- the duration of confidentiality obligations;
- procedures for returning or securely destroying confidential information after the relationship ends;
- liability for breach of the agreement;
- methods of proving a breach;
- governing law and dispute resolution provisions.
Let's look at each of these provisions in more detail.
What Information Should Be Considered Confidential?
Confidential information is any information that is not publicly available, provides a competitive or commercial advantage to a business, and could cause harm if disclosed. The scope of confidential information should be defined on a case-by-case basis, taking into account the company's business, its projects, and the individuals who have access to that information.
In most cases, confidential information includes:
- source code, software architecture, technical documentation, and specifications;
- business plans, financial data, and budgets;
- personal data, customer databases and information about partners and vendors;
- marketing strategies and commercial proposals;
- internal documentation, correspondence, and methodologies;
- drawings, templates, formulas, presentations, and other intellectual property.
There is no one-size-fits-all definition of confidential information. The list should reflect the specific information a company uses and the type of access each employee, contractor, or other team member has.
Stalirov&Co prepared an NDA for the international software development company Artkai. For its development team, the agreement identified the following categories of confidential information, among others:
- business development plans and market expansion strategies;
- the company's marketing strategy;
- customer databases and information about partners, vendors, and contractors;
- project budgets and compensation information;
- internal correspondence;
- source code, technical specifications, software documentation, and development materials;
- drawings, templates, formulas, and proprietary methodologies;
- presentations, diagrams, and other internal work product.
In practice, generic NDA templates rarely reflect a company's internal workflows, information flows or differing levels of access across teams. Documents downloaded from the internet rarely reflect the realities of a particular business, its internal processes, or the different levels of access within a team.
It's also important not to limit the agreement to a fixed list of known items. A well-drafted NDA should expressly state that the list of confidential information is not intended to be exhaustive. This helps ensure that other information meeting the agreed confidentiality criteria remains protected, even if it is not specifically identified in the agreement.
Taking the NDA lightly leads to financial loss and disappointment, as happened in the series “The Billion Dollar Code” by Netflix, which is based on a real court case. It is a story about two geniuses, Carsten Schlüter and Juri Müller. The case shows how important it is to enter into an NDA and describe the scope of confidential information. Carsten and Juri developed Terra Vision, software for a virtual rendering of the world using satellite imagery and architectural data. To attract investment, the developers turned to Google. They disclosed features, algorithms, and business plans and showed a product prototype. But instead of financing, Google stole the idea and introduced a similar software to the world - Google Earth. Today this product is called Google Maps.
It would have been possible to avoid this situation if the developers had signed the NDA before sharing information with Google representatives. The list of confidential data should have included information about free navigation through the data warehouse, a quadtree as a map layout, a floating coordinate system, and an address in memory. But the developers didn’t sign the NDA, so they lost the rights to the technology and the opportunity to earn millions of dollars a year.
What information is not considered confidential?
Not all information shared during a business relationship is automatically considered confidential. To avoid disputes later on, an NDA should clearly identify the types of information that are excluded from confidentiality obligations. These typically include:
- information that is already publicly available or becomes public through no fault of the receiving party;
- information that the receiving party lawfully possessed before entering into the NDA;
- information lawfully obtained from a third party without any obligation of confidentiality;
- information that must be disclosed by law, court order, or a government authority (provided that the disclosing party is notified in advance whenever legally permitted).
What kind of disclosure is considered legal?
Although the information is confidential, there are situations when it can be disclosed. For example:
- Disclosure of data that is not directly indicated and not listed in the agreement.
- To provide additional services and transfer information to accountants, auditors, lawyers and other consultants.
- With the written consent of the confidential information owners.
- At the government authorities' request. It is worth adding to the NDA about the disclosure procedure in case of a request from a government agency. In that instance a party to an agreement receives a request, it notifies the other party and does so before it sends a response.
Another common situation where confidential information may be disclosed lawfully is the use of project information in a company's portfolio.
To avoid potential disputes, the NDA may include a separate provision governing the publication of case studies. For example, the parties may agree that the company is entitled to use information about the project in its portfolio only after obtaining the client's consent for the specific publication.
How Should Confidential Information Be Exchanged?
The agreement should include a provision specifying the methods for exchanging confidential information, including:
- email;
- messaging platforms: WhatsApp, Telegram, Slack;
- cloud storage services;
- web-based platforms for hosting and collaborative development of IT projects (e.g., GitHub, GitLab, Bitbucket);
- video conferencing platforms: Zoom, Google Meet, Microsoft Teams;
- project management tools: Trello, Asana, Jira;
- granting access to databases, repositories, libraries, and other information systems.
How should liability for breach of an NDA be defined?
The fine must be commensurate with the damage and the amount of the fine must be justified. The Stalirov&Co team often encounters agreements that set unreasonable fines and sanctions. However, there must be a logical connection between the violation and the fine, so that in every case the amount of the fine is logically connected to the damage.
In SIS v. Stoneridge Software, the NDA provided that, in the event of a breach, the disclosing party would be entitled to recover all compensation or benefits the breaching party had received, directly or indirectly, as a result of the unauthorized disclosure of confidential information. The court held that this provision was not an enforceable liquidated damages clause because it was based on the breaching party’s gain rather than a reasonable estimate of the losses the non-breaching party was likely to suffer.
This case illustrates that overly broad or poorly drafted penalty provisions may not be enforceable in practice. When drafting an NDA, it is therefore important to ensure that any liquidated damages or penalty clauses are reasonable and proportionate to the potential harm caused by a breach.
How can you prove violations and calculate damages?
Damages may be supported by the following evidence:
- Financial auditor's reports.
- Conclusions by experts which help to establish evidence of copyright infringement and intellectual property theft.
- Conclusions by independent IT specialists. For example, a game developer was hired by a competing company. An IT specialist concluded that a competitor's game uses a feature developed by your company when the developer was working on your project. Such a conclusion will help prove that the development was stolen.
- Witnesses testimonies on disclosure.
- Written evidence: non-disclosure agreement; digital platforms that generate and transmit confidential information, such as Jira, Asana, Confluence.
- Audio and video recordings that show unauthorized disclosure.
- Electronic evidence, for example business correspondence via email or messengers; voice messages; screenshots; publications in social networks; information from websites or mobile applications, cloud storage and others.
Oral arguments alone are not enough to prove disclosure of confidential information. It is crucial to substantiate that the agreement has been violated, through the collection of evidence, and that the amount you want to recover is commensurate with the damage.
What is considered an NDA violation?
An NDA should clearly define what constitutes a breach of the agreement. Depending on the circumstances, this may include failing to comply with the company's internal policies on handling confidential information, copying confidential data to personal devices, disclosing it to third parties or competitors, publishing confidential materials, or using the information to develop competing products or technologies.
A good example is Ferm RFID Solutions B.V. v. ADE/ADC (Netherlands, 2024). The parties entered into an NDA as part of a joint RFID technology development project. After receiving confidential technical information, one party shared it with another company within its corporate group. That information was subsequently used to prepare and file patent applications. The court found that disclosing the confidential information to a third party without the owner's consent breached the NDA, prohibited any further use or disclosure of the information, and ordered the defendants to compensate the claimant for its losses.
Another example is Tesla, Inc. v. Alexander Yatskov. In May 2022, Tesla sued a former engineer, alleging that before leaving the company he copied confidential files related to the Dojo project onto his personal devices, used his personal email account to access and work with those files, and failed to return all confidential information after his employment ended. The dispute was settled in April 2023, with the former employee agreeing to pay compensation under the terms of the settlement.
When Can the Use of AI Tools Violate an NDA?
Employees increasingly use ChatGPT, Claude, Gemini and similar AI tools to review contracts, debug code and summarise documents. Where those materials contain confidential information, such use may conflict with the terms of an NDA.
For example, in Bodea v. JPMorgan Chase, a U.S. federal court approved a Protective Order providing that uploading confidential materials to public generative AI tools constitutes disclosure to an unauthorized third party.
Businesses are taking a similar approach. After employees uploaded confidential source code and internal documents to ChatGPT, Samsung restricted the use of public generative AI services when handling corporate information.
The international law firm Morgan Lewis prohibits the use of client information and personal data in public generative AI tools and has implemented internal safeguards to enforce that policy.
Against this backdrop, companies should review not only their internal AI policies but also their NDA templates. Where confidential information may be used in connection with generative AI, the agreement should expressly address that risk. In particular, companies should consider including provisions that:
- restrict or prohibit the upload of confidential information to public AI services;
- identify the categories of information that may not be processed using generative AI;
- require the use of company-approved or enterprise AI solutions when handling confidential information; and
- establish liability for violations of these requirements.
Where will the dispute be adjudicated and why do you need to determine jurisdiction before you draft an NDA?
When entering into an NDA, the parties should determine in advance which country's laws will govern the agreement and whether any disputes will be resolved by a court or through arbitration. These decisions can significantly affect the time and cost of resolving a dispute, as well as the ability to recover damages from the breaching party.
The choice of governing law and dispute resolution forum should take into account where the parties are incorporated, where their assets are located, and in which jurisdiction a judgment or arbitral award may ultimately need to be enforced. When working with international business partners, it is important to consider not only where a dispute can be resolved most efficiently, but also whether any resulting judgment or arbitral award can be effectively enforced in the relevant jurisdiction.
Practical NDA Preparation Checklist from the IT Lawyers at Stalirov&Co
When drafting an NDA, keep the following practical considerations in mind:
- Clearly define what constitutes confidential information. The definition should reflect the nature of your business and cover not only source code, but also business processes, technical documentation, product architecture, commercial terms, financial information, and other valuable business data.
- Specify what constitutes a breach of the NDA. For example, copying confidential information to personal devices, disclosing it to third parties, using it for personal projects, or developing a competing product.
- Distinguish the confidentiality period from the term of the agreement. This ensures that confidentiality obligations remain in force even after the contractual relationship has ended.
- Include enforcement provisions that are legally sustainable. If the NDA is entered into with a foreign counterparty, ensure that any liquidated damages or penalty clauses are enforceable under the governing law.
- Avoid relying on generic NDA templates. The enforceability of NDA provisions varies significantly across jurisdictions, particularly in the context of employment relationships.
- Address the use of the client's name or project in marketing materials. If either party intends to refer to the relationship in a portfolio, on a website, or in promotional materials, this should be expressly agreed in advance.
- Ensure that the NDA applies to everyone with access to confidential information. This includes not only employees, but also contractors, consultants, freelancers, and any other individuals involved in the project.