Skip to main content
Free guides and templates

The NDA Red-Flag Guide

Non-disclosure agreements are the most-signed and least-read contracts in business. They arrive looking standard, get waved through, and then bind a party for years on terms nobody scrutinised. This guide is the opposite of waving them through: a field manual to the clauses that turn a routine NDA into a trap.

Read it before you sign the next one. Every red flag below is something a counterparty inserts because it benefits them — and that you can usually negotiate out in a single email.

First, get the direction right

Before reading a word of substance, identify the structure:

  • One-way (unilateral) — only one party discloses. Fine if you are purely the recipient of information. Dangerous if you are signing the discloser's one-way template but actually plan to share your own confidential material, which will then be unprotected.
  • Mutual — both parties disclose and both are bound. The right default for any real two-way conversation.

A one-way NDA presented for a genuinely two-way discussion is the first red flag. Ask for mutual.

Red flag 1: an overbroad definition of confidential information

The worst NDAs define confidential information as "all information disclosed, in any form, whether or not marked confidential." That makes everything confidential, including things you already knew, which is impossible to comply with and unenforceable in many courts — but you do not want to be the test case.

What good looks like. Confidential information is information that is either marked confidential, or that a reasonable person would understand to be confidential from the circumstances. Pair it with a clear exclusions list (below).

Red flag 2: missing or gutted exclusions

A fair NDA always carves out information that is:

  • already public, or becomes public through no fault of the recipient;
  • already known to the recipient before disclosure;
  • independently developed by the recipient without using the disclosed information;
  • lawfully received from a third party with no duty of confidence.

If these exclusions are missing, narrowed, or subject to a "burden of proof on the recipient with contemporaneous written evidence" standard, that is a red flag. You can be held in breach for using information you had every right to use.

Red flag 3: a perpetual or excessively long term

Watch two separate clocks: the disclosure period (how long you can keep exchanging information) and the confidentiality period (how long the duty to protect lasts after disclosure).

A confidentiality period of "in perpetuity" for ordinary commercial information is a red flag — it is an unmanageable, indefinite liability. A defensible structure is: a fixed term (commonly two to five years) for general confidential information, with an indefinite term reserved only for genuine trade secrets, which the law protects for as long as they remain secret anyway.

Red flag 4: a one-sided or punitive remedies clause

Be wary of:

  • Liquidated damages — a fixed sum payable per breach. If the number bears no relation to likely loss, it may be an unenforceable penalty, but it is leverage against you regardless.
  • Indemnities inside an NDA — unusual and usually overreaching. An NDA should give rise to ordinary damages and injunctive relief, not an indemnity.
  • One-way injunctive relief that lets only the discloser seek an injunction. Make it mutual.

Red flag 5: residual-knowledge clauses (cutting both ways)

A "residuals" clause lets the recipient freely use information retained in the unaided memory of its personnel. If you are the recipient, you want one — it protects your people from being accused of breach for what they simply remember. If you are the discloser, a broad residuals clause can gut your protection entirely. Know which side you are on before you accept or reject it.

Red flag 6: hidden non-compete and non-solicit terms

Some NDAs smuggle in restrictive covenants — a promise not to compete, not to solicit employees, or not to approach the same customers. These are substantive commitments that have no business in a confidentiality agreement and may be unenforceable depending on jurisdiction and scope. If you see them, strike them and negotiate them separately if they are genuinely needed.

Red flag 7: assignment, governing law and forum

  • Assignment — can the NDA be assigned to a third party, including a competitor, without your consent? It should not be, at least not without consent.
  • Governing law and forum — an NDA governed by, and litigated in, a far-off jurisdiction can make enforcement so expensive that the protection is theoretical. Push for a forum you can actually use.

The 60-second NDA triage

When an NDA lands and you need a decision fast:

  1. Is it mutual when it should be? If not, ask.
  2. Are the four standard exclusions present and unqualified?
  3. Is the confidentiality term fixed for ordinary information (not perpetual)?
  4. Are there liquidated damages, indemnities, or hidden non-competes? Strike them.
  5. Is the governing law and forum somewhere you can enforce?

Clear all five and the NDA is almost certainly safe to sign.

Stop reading NDAs line by line

NDAs are high-volume, low-variation, and perfect for automation — which is exactly why they consume so much senior time that should go elsewhere. Attorly reviews every incoming NDA against this red-flag list and your own standard, flags the overbroad definitions, missing exclusions, perpetual terms and smuggled-in covenants, and drafts the redline back to a fair position, with legal context for 13 jurisdictions across Europe, the Nordics, the UK and the US.

Triage your next NDA at attorly.ai (7-day trial, card required).