1. Why mutual rather than one-way?
  2. The essential clauses
    1. What counts as confidential information
    2. Permitted purpose
    3. Who can access it
    4. The confidentiality obligations themselves
    5. How long confidentiality lasts
    6. Return or destruction of information
    7. Remedies and injunctive relief
    8. What the NDA does not do
  3. Optional and situational clauses
  4. Where Artificer Legal can help
  5. The confidential information definition

Someone sends you a draft NDA before a partnership discussion gets serious. Or your counterparty wants you to sign theirs before they'll show you their pricing, supplier terms, or technical process. Or you're the one drafting and you're not sure whether a template you found online actually protects you.

A mutual confidentiality agreement — commonly called a mutual NDA — is the document that sits between "we're talking" and "we've agreed". Unlike a one-way NDA (where only one party is disclosing sensitive information and only the other promises to keep it quiet), a mutual NDA binds both sides. Each party discloses something worth protecting, and each party takes on obligations. That symmetry changes both the commercial dynamic and several of the drafting choices that matter most.

Why mutual rather than one-way?

The distinction is practical, not just semantic. If you're sharing your business model, financials, or customer acquisition strategy while the other party is sharing their supplier arrangements, technical process, or distribution network, a one-way NDA protects only one side — and the other party has no obligation at all to keep your information confidential unless they voluntarily agree to additional terms.

Common situations where a mutual NDA is the right tool:

  • Partnership and co-marketing discussions — where both sides are pitching their approach and neither wants the other using the information to go direct
  • Joint ventures — especially where both parties are contributing IP, know-how, or operational methodology
  • Supplier or manufacturer negotiations — where you're sharing product specifications, volumes, or commercial sensitivities and the supplier is sharing its pricing structures or production capacity
  • M&A and investment conversations — where detailed financials and business information flow in both directions during diligence
  • Technology builds — where you're briefing a developer or agency on your requirements while they're sharing their proprietary methodology or toolset

If only your business is sharing something genuinely sensitive, a one-way NDA may be simpler and give you cleaner enforcement. But if information flows both ways — as it usually does in serious commercial discussions — a mutual NDA is the more honest reflection of the arrangement.

The essential clauses

What counts as confidential information

The definition clause is the foundation of the whole document, and it commonly has two layers: a broad catch-all covering information disclosed in writing, verbally, visually, electronically, or by any other means; and a set of carve-outs for information that falls outside protection regardless.

Standard carve-outs include:

  • information already in the public domain (not through a breach of the NDA)
  • information the receiving party already knew before disclosure
  • information independently developed by the receiving party without reference to what was disclosed
  • information received from a third party who was lawfully free to disclose it

The drafting choice that matters most here is whether information must be marked "confidential" to be protected. A labelling requirement gives certainty, but it can leave gaps — fast-moving conversations, verbal briefings, and informal data shares often go unlabelled. For most business negotiations, a broad definition without a labelling requirement is more practical, provided the carve-outs are clearly worded.

Watch for:

  • Definitions so broad they capture information that was never actually sensitive, which creates compliance problems for both sides
  • Definitions so narrow they exclude the information that really matters (e.g. a definition that covers "written documents" but not verbally disclosed pricing)
  • Asymmetric definitions — where the draft purports to be mutual but the definition of one party's confidential information is materially narrower

Permitted purpose

The NDA should state precisely why the information is being shared. For example: "to evaluate a potential distribution partnership" or "to assess the commercial viability of a proposed joint development arrangement".

This clause does two things. It limits what the receiving party can do with the information — they cannot use it for any purpose beyond the one stated. And it gives the disclosing party a clearer basis to show misuse if things go wrong. Without a defined purpose, the receiving party has a wider argument that any business use was within the scope of the arrangement.

Who can access it

Most businesses need to share information internally. The representative clause handles this by defining who counts as a "representative" — typically employees, directors, legal and financial advisers, and sometimes potential financiers — and imposing two conditions:

  • access is limited to those who genuinely need it for the permitted purpose (a need-to-know standard), and
  • the party who shares the information remains responsible for its representatives' compliance.

Watch for drafts that permit disclosure to a loosely defined group (such as "affiliates" or "group companies") without any corresponding need-to-know restriction. In a mutual NDA, this works both ways — it is as important that your counterparty's access is constrained as it is that yours is.

The confidentiality obligations themselves

The core clause: keep the information confidential, use it only for the permitted purpose, protect it using reasonable security measures, and do not disclose it except as the agreement allows.

What "reasonable security" looks like in a modern business context includes:

  • limiting document access to named individuals rather than shared drives open to a whole team
  • using secure file-sharing platforms rather than forwarded email chains
  • not downloading or copying documents beyond what is necessary
  • notifying the other party if a breach occurs or is suspected

In a mutual NDA, both parties carry these obligations equally. A draft that imposes strict security obligations on the receiving party but says nothing about the disclosing party's own handling of shared information is asymmetric in practice, even if it looks mutual on the page.

How long confidentiality lasts

A common misconception is that an NDA lasts forever. Most do not — and the term clause is worth reading carefully.

Common structures:

  • A fixed period from signing (often two to five years), during which all disclosed information remains protected
  • A term tied to the duration of the discussions plus a tail period after they end
  • Separate treatment of different categories — general commercial information protected for a fixed period, trade secrets protected indefinitely (or for as long as they remain secret)

If the term is too short, confidentiality may expire while the information is still commercially sensitive. If it is too long or undifferentiated, the other party may resist signing or push for carve-outs that erode the protection you actually need. The right answer depends on what you are sharing — a customer list may need longer protection than a proposed pricing structure.

Return or destruction of information

If discussions end without a deal, what happens to the information that was exchanged? A return-or-destroy clause requires each party to either return the materials they received or confirm that those materials have been deleted.

In practice, a carve-out is usually needed for documents that have been archived in automated systems or retained for regulatory or legal purposes — but the clause should make clear that retained copies remain subject to the confidentiality obligations and cannot be accessed or used.

Watch for drafts that omit this clause entirely, leaving no mechanism to recover or confirm destruction of sensitive materials after a deal falls through.

Remedies and injunctive relief

A breach of a mutual NDA can cause harm that is difficult to quantify in damages — once confidential information has been shared with the wrong people, money alone cannot undo it. Well-drafted NDAs include express acknowledgment that breach may cause irreparable harm, and that the affected party may seek urgent court relief (including injunctive relief) to prevent further disclosure.

Under Australian law, courts have a general equitable jurisdiction to grant injunctions to restrain actual or threatened misuse of confidential information. An express clause acknowledging this does not guarantee any outcome, but it can strengthen your position when you need to act quickly — particularly if the other party argues that damages are an adequate remedy and no urgent orders are needed.

What the NDA does not do

This clause — often called a "no partnership" or "no obligation to proceed" clause — is worth including explicitly, because small business owners sometimes assume the NDA does more than it does.

A mutual NDA does not:

  • create a partnership, joint venture, or agency relationship between the parties
  • obligate either party to proceed with a transaction or continue discussions
  • transfer ownership of intellectual property — information you share remains yours, but the NDA does not make IP created during discussions automatically belong to either party

If IP ownership is genuinely in play — for example, where both parties are developing something together — that needs to be addressed in a separate agreement. An NDA will not resolve it.

Optional and situational clauses

Some provisions come up only in particular circumstances:

  • Non-solicitation clause — prevents either party from approaching the other's staff or contractors during and after discussions. Worth including when you are sharing detailed information about your team or operations.
  • Standstill clause — common in M&A discussions, prevents the receiving party from acquiring shares or assets during the diligence period. Usually proposed by the target business.
  • Permitted disclosure to regulators — a carve-out allowing disclosure of confidential information where required by law or a regulatory authority, without triggering a breach. Usually uncontroversial but important to have.
  • Privacy Act overlay — if confidential information includes personal information (customer lists, employee data, contact details), consider whether either party's disclosure is consistent with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. An NDA does not authorise disclosure that is otherwise unlawful.
  • Governing law and dispute resolution — for cross-border discussions or counterparties in a different state, specifying Australian law (and ideally the relevant jurisdiction) avoids later arguments about which law applies.

A mutual NDA looks simple until it isn't. The clauses practitioners push back on most often are the confidential information definition (usually too vague or, in template form, too narrow), the representatives clause (often too permissive on the other side), and the term (frequently mismatched to the actual sensitivity of what is being shared).

When reviewing a mutual NDA that a counterparty has sent, the questions worth working through are: Is the definition of confidential information genuinely symmetric? Is the permitted purpose specific enough to matter? Who, on the other side, can access what you are sharing — and is there any real constraint? Is the term appropriate for what you are disclosing?

When drafting your own, the priority is getting the purpose, definition, and representatives clauses right before you worry about anything else — those three determine most of the practical risk.

If you are negotiating a mutual NDA before a significant business discussion — an M&A conversation, a joint venture, a technology build, or a relationship where both sides have genuinely valuable information — it is worth having a practitioner review or draft the document rather than relying on a generic template. Artificer Legal works with Australian businesses on commercial contract matters including confidentiality agreements. Contact us to discuss your situation.

The confidential information definition

The confidential information definition is the clause that determines whether you win or lose if something goes wrong. Every other clause in the NDA depends on it — if the information that was misused does not fall within the definition, none of the protections apply, and none of the remedies are available.

A mutual NDA is also often misunderstood as a single-purpose document. It is better understood as the formal start of a structured commercial conversation: it defines what can be shared, for what purpose, with whom, and for how long — and it creates legal consequences if those boundaries are crossed. Getting it right before discussions become substantive is far simpler than trying to address a breach after the fact.

Key points:

  • A mutual NDA binds both parties to confidentiality obligations, making it appropriate where information flows in both directions — unlike a one-way NDA where only one party discloses.
  • The most important clauses are the definition of confidential information, the permitted purpose, the representatives clause, and the confidentiality term.
  • An NDA does not create a partnership, transfer IP, or obligate either party to proceed — separate agreements are needed for those purposes.
  • If confidential information includes personal information, compliance with the Privacy Act 1988 (Cth) is a separate consideration that an NDA does not resolve.
  • Common mistakes include signing too late, using a template that does not reflect the actual deal, and not checking which legal entity is binding itself.