- Definition of confidential information
- Exclusions
- Permitted use
- Non-disclosure and security obligations
- Permitted disclosures
- Duration
- Return and destruction
- Remedies for breach
- Ownership and no licence
- Optional and situational clauses
- How Artificer Legal can help
- The definition of confidential information
Someone has handed you a non-disclosure agreement. Maybe a prospective investor wants to review your financials. Maybe a contractor is about to work on your product. Maybe a potential acquirer is conducting due diligence, and their lawyers have sent across a document for you to sign before any files change hands.
A confidentiality agreement — also called a non-disclosure agreement or NDA — is a contract that restricts how the receiving party may use and disclose the information you share. It sits at the front end of a relationship, before the main deal is done, and it fills the gap your other contracts leave open: the period where sensitive information is moving but nothing permanent has been agreed. It operates independently from (and supplements) later documents such as a service agreement, employment contract, or shareholders agreement — none of those automatically protect what you disclose at the exploratory stage.
What follows dissects the clauses you will encounter in a typical Australian NDA, what each one actually does, and the traps worth knowing before you sign or send.
Definition of confidential information
This is the clause that determines the scope of everything else. If information falls outside the definition, the agreement does not protect it — no matter how sensitive it is.
Most Australian NDAs use one of two approaches, or combine them:
- Category-based: lists types of information (financial data, customer lists, product specifications, source code, pricing structures, business plans) without naming specific documents.
- Marking-based: confines protection to materials marked or described as "Confidential" at the time of disclosure.
The drafting choice that matters most is breadth versus administrability. Category-based definitions offer broader coverage but can be challenged on the ground that the information was already public or that the category was unclear. Marking-based definitions are administratively clean but leave oral disclosures and unmarked documents unprotected by default.
The variant the other side often pushes for is a narrower definition — limiting protection to written materials or excluding whole categories that happen to overlap with their existing activities.
Traps to watch:
- Defining confidential information so broadly that it is commercially unworkable (e.g., "any information disclosed in any form") without a carve-out for information already known to the recipient.
- Leaving oral disclosures unprotected — add a clause requiring verbal disclosures to be confirmed in writing within a short period, or expressly include them in the definition.
- Not tailoring the definition to the deal — a software development NDA should name source code and specifications explicitly; a commercial partnership NDA should name financial models and customer data.
Exclusions
The exclusions clause defines what is not confidential information, even if it would otherwise fall within the definition. Without sensible exclusions, a well-drafted NDA becomes unenforceable in practice because it purports to protect information the recipient can demonstrate they already had.
Standard exclusions cover information that:
- is or becomes publicly available other than through a breach of the agreement;
- was already known to the recipient before disclosure (evidenced by written records);
- is independently developed by the recipient without reference to the disclosed information; or
- is received from a third party who is not under any obligation of confidence to the discloser.
The drafting trap here is a recipient-side push to broaden "publicly available" to cover any information that can be assembled from public sources — even if assembly itself required skill and effort. Resist this: compiled know-how, customer lists derived from public data, and financial models built on public figures are often genuinely confidential even if the raw inputs are not.
Permitted use
This clause limits what the recipient can do with the information, not just who they can share it with. It is one of the most commercially significant clauses in the document.
State the permitted purpose precisely — "solely for the purpose of evaluating a potential acquisition of the Discloser's business" rather than "for business evaluation purposes." The narrower the purpose, the harder it is for a recipient to argue that using your pricing data to inform their own market strategy was within scope.
The other side will often seek a broader permitted use clause — push back, and document your narrower position in writing before disclosure begins.
Non-disclosure and security obligations
This clause imposes the core duty: keep the information secret and apply reasonable safeguards. A workable clause should:
- prohibit disclosure to any person other than authorised personnel who need the information for the permitted purpose;
- require the recipient to apply security measures at least equivalent to those they use for their own confidential information (and no less than reasonable care);
- limit copying, extraction, and storage to what is necessary for the permitted purpose; and
- require authorised personnel to be bound by confidentiality obligations at least as stringent as those in the NDA.
If personal information (within the meaning of the Privacy Act 1988 (Cth)) will be shared, this clause should also require the recipient to handle that information consistently with the Australian Privacy Principles. Note that the Privacy Act's mandatory compliance regime applies to APP entities — broadly, organisations with an annual turnover above $3 million and certain others such as health service providers — but even smaller businesses that handle personal information as a commercial matter would be prudent to impose equivalent obligations contractually.
The drafting trap: vague security standards such as "reasonable precautions" with no further guidance. For sensitive deals, specify minimum controls — encrypted storage, restricted access lists, prohibition on cloud storage in certain jurisdictions.
Permitted disclosures
This clause creates a limited carve-out for situations where the recipient is legally compelled to disclose, or where professional advisers (lawyers, accountants, auditors) need access to give advice on the transaction.
A well-drafted permitted disclosures clause:
- permits disclosure to professional advisers who are themselves bound by confidentiality (contractually or by professional obligation);
- requires the recipient to notify the discloser promptly if a legal or regulatory demand to disclose is received, and to cooperate in seeking any available protection order or confidentiality undertaking; and
- limits any compelled disclosure to the minimum required by law.
The variant advisers often push for is a broad "as required by any law or regulation" carve-out with no notice requirement. That framing is too wide — require prior notice wherever legally permissible.
Duration
This clause sets how long the confidentiality obligations last. Duration questions produce real commercial disagreement.
- Defined term: obligations expire after a fixed period (commonly two to five years). Appropriate for time-sensitive commercial information that will become less sensitive as the market moves on.
- Trade secrets: obligations for true trade secrets — formulas, algorithms, source code — are often drafted to survive indefinitely, or for as long as the information remains confidential.
- Post-term survival: even where a defined term applies to general confidential information, specifically identified trade secrets should be carved out with no expiry.
The trap: accepting a short uniform term for all categories without carving out your most valuable information. Two years is commercially standard for many deals, but it may be entirely inadequate for a technical trade secret.
Return and destruction
At the end of the engagement or on request, the recipient must return or securely destroy all confidential materials, including copies and notes. This clause should:
- specify what happens to digital copies, backups, and extracts — not just physical documents;
- require written certification of destruction; and
- permit the recipient to retain one archival copy solely for the purpose of establishing compliance, subject to ongoing confidentiality obligations.
The other side will often seek to carve out materials retained in IT backup systems that are not easily accessible. Accept this only with a clear obligation that the backup data remains subject to the confidentiality obligations and will be deleted when the backup cycle expires.
Remedies for breach
This clause makes clear that a breach of the NDA entitles the discloser to seek urgent relief from a court — notably an injunction to prevent or stop ongoing unauthorised disclosure — and to claim damages.
Australian courts have consistently recognised that confidential information is difficult to value, that damages may be an inadequate remedy for an ongoing breach, and that injunctive relief is appropriate where the balance of convenience favours restraint. This clause reinforces that position contractually and signals to the recipient that enforcement is realistic.
Traps:
- Relying on damages alone without preserving the right to seek equitable relief — include express language preserving injunctive and other equitable remedies.
- Omitting an acknowledgement that a breach would cause irreparable harm — this acknowledgement assists an urgent injunction application, though courts will still apply their own assessment.
Ownership and no licence
Disclosing information does not transfer ownership of it, and it does not grant the recipient any right to use it beyond the permitted purpose. This clause makes that explicit.
It should state clearly that all intellectual property in the confidential information remains with the discloser, and that nothing in the NDA grants any licence — express or implied — to use the information for any other purpose.
This clause matters particularly where the information is or could be the subject of a patent application. Under s 18 of the Patents Act 1990 (Cth), a patentable invention must be novel — assessed against the prior art base as it existed before the priority date. If an invention is publicly disclosed before a patent application is filed, that disclosure may form part of the prior art base and defeat novelty. A robust NDA, signed before disclosure, is a standard mechanism for sharing pre-filing information without creating a prior art problem.
Optional and situational clauses
Some clauses are worth including depending on the nature of the deal:
- Mutual confidentiality: where both parties will share sensitive information (joint ventures, partnership negotiations, M&A), a mutual NDA imposes equivalent obligations on each side — make sure the definition of confidential information and the permitted use apply symmetrically.
- Non-solicitation: in some commercial relationships — particularly those involving access to customer lists or key personnel — a limited non-solicitation restriction, appropriately scoped, reinforces the confidentiality protections.
- Standstill or non-use for competitive purposes: in a competitive landscape, prohibit the recipient from using the information to inform a competing product or service, even if they do not technically "disclose" it to a third party.
- Data processing obligations: where the disclosed information includes personal information that the recipient will process on behalf of the discloser, a separate data processing agreement or schedule may be needed to satisfy the Australian Privacy Principles and any applicable state or territory health privacy legislation.
- Dispute resolution: a tiered clause requiring escalation to senior management before litigation can reduce cost and preserve commercial relationships where the breach is inadvertent.
How Artificer Legal can help
The clauses in a confidentiality agreement interact. A narrow definition of confidential information undermines a well-drafted remedies clause. A broad permitted use clause can hollow out the most precise non-disclosure obligation. A short duration term can undo months of careful protection.
When we review or draft an NDA for a client, we focus on the clauses that are most likely to be contested or misunderstood given the specific deal. For a founder sharing a product roadmap with a prospective investor, we would push for a broad category-based definition, an indefinite term for technical know-how, and an express acknowledgement of irreparable harm. For a business receiving an NDA from a large counterparty, we would examine whether the permitted use is genuinely limited to the stated purpose or whether it creates a back door for competitive intelligence gathering.
We would also check that any personal information protections in the agreement are consistent with the organisation's Privacy Policy and that the NDA does not inadvertently represent a data sharing arrangement that requires separate documentation.
If you have an NDA in front of you and you are not sure whether it protects what you intend — or gives up more than you realise — reach out to Artificer Legal for a review.
The definition of confidential information
If a dispute reaches court, the clause most often in question is not the one the parties spent the most time negotiating — it is the definition of confidential information. Courts cannot enforce an obligation over information the agreement has not clearly captured. An agreement that protects "confidential information generally" without specifying categories or marking requirements, and without a clear prior-knowledge exclusion, produces exactly the ambiguity that allows a recipient to argue that the most important information was not covered.
The most skipped element in NDA drafting is the tailoring step: adjusting the definition, the permitted use, and the duration to the specific information being shared rather than accepting a generic template. Templates are a starting point. The protection you actually need comes from matching the document to the deal.
In summary: a well-structured confidentiality agreement should define what it covers precisely, restrict use to a clearly stated purpose, require active security measures, carve out trade secrets from any time limit, and preserve equitable remedies in case of breach. Each clause depends on the others — the document works as a system, not a checklist.