1. What the law protects before you sign anything
  2. The clauses that matter in a confidentiality agreement
    1. What counts as confidential information
    2. What the information can be used for
    3. Who is allowed to see it
    4. How long the confidentiality obligation lasts
    5. What happens to the information at the end
    6. What is not confidential
    7. What happens if someone breaches
    8. Who owns what is created during the relationship
  3. Optional clauses worth adding
  4. How an Artificer Legal lawyer helps with confidentiality agreements
  5. The definition of confidential information

A confidentiality agreement is often the first legal document a startup signs. The moment usually looks the same: you have built something with real value in it, a pricing model, a product roadmap, source code, a customer list, and a developer, investor, or supplier wants to see it before they will work with you. Someone emails you their non-disclosure agreement (NDA), or a template arrives from a document service, and you are being asked to sign it before the call ends.

The document is a contract in which one party, or both, promises to keep specified information confidential and to use it only for an agreed purpose. It is usually structured as an agreement or as a deed; a one-way NDA is often made as a deed because a deed is binding without consideration, which avoids arguments about what the recipient gave in exchange for the promise. What the document does not do is transfer ownership of anything. It sits alongside your employment contracts, contractor agreements and IP assignments, and it protects you best when those documents do not contradict it.

What the law protects before you sign anything

Even with no document at all, Australian law gives some protection through the equitable action for breach of confidence. In Filby v TEG Live Pty Ltd [2023] NSWCA 320, the NSW Court of Appeal applied the long-standing test from Coco v A.N. Clark (Engineers) Ltd: the information must have the necessary quality of confidence, it must be imparted in circumstances importing an obligation of confidence, and there must be unauthorised use or disclosure of it. In that case, the court found that an idea pitched in a meeting for a free concert was too general and inchoate to have the necessary quality of confidence.

The problem with relying on equity alone is that you have to prove each element in court, and the boundaries are uncertain. A written confidentiality agreement does the job more precisely. It can define exactly what is confidential, state the permitted purpose, and bind the other party to those terms as a matter of contract, protecting information that equity might not treat as confidential at all. It also gives you a document you can point to when someone asks what they were allowed to do with what you shared.

The clauses that matter in a confidentiality agreement

Not all confidentiality agreements are created equal. A short template can help, but if it is missing key protections, or does not match how your business actually operates, it may not give you much comfort when you need it most. These are the clauses to look at first when you are drafting or reviewing one for a startup.

What counts as confidential information

This definition matters more than people expect. If it is too narrow, you can accidentally leave key information unprotected. If it is too broad, the other side may push back, or the agreement becomes unmanageable in practice.

A common approach is to define confidential information broadly, then carve out the exceptions. Typical drafting defines it as all information disclosed in connection with a stated purpose, followed by a list that includes:

  • Business plans: budgets, pricing strategies, margins and financial information
  • Customer material: customer lists, lead lists and marketing strategies
  • Supplier arrangements: supplier terms, manufacturing processes and distribution arrangements
  • Technical material: software code, technical documentation, product specifications, prototypes and designs
  • Internal material: systems, processes, know-how and the terms of commercial negotiations

A trap to watch for in the other party's NDA is a definition that captures your information but not theirs, or one that protects only information "marked confidential". If protection depends on marking, the pricing sheet you send as an email attachment is not covered, and neither is anything said in a meeting.

What the information can be used for

Confidentiality is not just about not disclosing. It is also about not using the information for the wrong purpose, and a purpose limitation clause is what makes that stick. For example, you might allow a developer to use your confidential information only to build your app, not to build a competing product or to reuse your commercial insights for another client.

The variants the other side pushes for are worth knowing:

  • "For the purpose of evaluating the proposed transaction" is the standard, sensible formulation
  • "For any purpose related to the parties' discussions" is looser than it looks and should be resisted
  • "For the recipient's own business purposes" effectively guts the agreement and should never be accepted

If the agreement has no purpose clause at all, the recipient can argue that any use is permitted, because nothing was prohibited beyond disclosure.

Who is allowed to see it

Most businesses do not want confidential information shared widely, so the agreement should restrict access to people who genuinely need to know, such as:

  • employees of the receiving party who need it for the permitted purpose
  • professional advisers such as lawyers and accountants
  • approved subcontractors

The receiving party should remain responsible for breaches by those people, including its employees, even after they leave. A trap is a definition of "representatives" so wide that it includes the recipient's other clients, related entities, or anyone they choose to engage, with no requirement to notify you before sharing.

How long the confidentiality obligation lasts

Some agreements impose obligations for a fixed period of two to five years. Others require confidentiality to continue for as long as the information remains genuinely confidential and commercially valuable, which is often the right approach for trade secrets and source code.

What makes sense depends on what you are sharing. A time-limited obligation can be fine for short-lived commercial negotiations, but less suitable for information that stays valuable for a long time. Two drafting choices matter here. First, whether the obligation survives the end of the main agreement, such as a services contract, so there is no gap after termination. Second, whether the term runs from the date of the agreement or from the date each item of information is disclosed.

Separate statutory duties can also outlast the contract. Under s 183 of the Corporations Act 2001 (Cth), an officer or employee of a corporation must not improperly use information obtained through their position to gain an advantage or cause detriment, and that duty continues after they stop being an officer or employee.

What happens to the information at the end

If the relationship ends or the deal does not proceed, it is common to require the other party to return or destroy confidential material, including copies. In reality, full deletion is complicated by backups and email archives, so a well-drafted clause handles this realistically while still protecting your interests. Look for:

  • return or destruction of documents and deletion of electronic copies within a set period
  • a written confirmation or certificate of destruction
  • a carve-out allowing the recipient to keep copies required by law or for ongoing obligations, which remain subject to confidentiality

A trap is silence on this point, which effectively lets the recipient keep everything after the relationship ends.

What is not confidential

Most confidentiality agreements include sensible exclusions, such as information that:

  • is already public and was not made public through a breach
  • was already known to the receiving party legitimately before disclosure
  • is independently developed without using your confidential information
  • must be disclosed by law, such as under a court order

Watch for exclusions drafted too widely. A common one is "information that the recipient obtains from a third party", which lets the recipient bypass the agreement by routing information through someone else. A better formulation is information obtained from a third party who was not under a confidentiality obligation to you.

What happens if someone breaches

If someone breaches confidentiality, your loss can be hard to quantify, so the agreement should set out the remedies available. These typically include:

  • an injunction or court orders to stop further use or disclosure
  • damages for loss suffered
  • an account of profits where the recipient has profited from the misuse

Courts can also order delivery up or destruction of material. Many agreements include an acknowledgment from both sides that damages may not be an adequate remedy and that injunctive relief may be appropriate. The pushback to expect from the other side is a liability cap, or a carve-out for accidental disclosure where the recipient promptly takes steps to limit the damage. Neither is unreasonable in the right circumstances, but each should be negotiated rather than accepted by default.

Who owns what is created during the relationship

A confidentiality agreement is about secrecy, not ownership. It is worth including a clause confirming that the recipient gets no rights in your intellectual property and that nothing in the agreement grants a licence. But if the recipient creates things for you, such as code, branding, designs or content, confidentiality does not give you ownership of what they create.

Copyright generally protects the particular expression of an idea, not the idea itself, and ownership of work created by a contractor or employee depends on the contract, not on secrecy. That is why an IP assignment clause, or a clear IP ownership term in the services or employment agreement, is often just as important as the confidentiality clause itself.

Optional clauses worth adding

A basic NDA covers the clauses above. Depending on the relationship, these additional clauses are worth considering:

  • Mutual obligations: include them when both sides will be sharing sensitive information, which is common in partnerships and joint ventures, so the agreement does not look one-sided
  • Non-solicitation and non-compete restraints: worth considering when a contractor or early employee will see your customers and staff, though restraints are only enforceable to the extent they are reasonable and protect a legitimate business interest
  • Breach notification: a requirement that the recipient tells you promptly if they discover a leak or unauthorised use, which matters when the information is high-value and the relationship is ongoing
  • Irreparable harm acknowledgment: a statement that damages may not be an adequate remedy, which helps if you need to move quickly to stop misuse
  • Governing law and jurisdiction: a clause specifying Australian law and Australian courts, particularly important when the counterparty is overseas or sends you their own NDA with a foreign governing law clause

An Artificer Legal practitioner would start by asking what you are actually sharing and with whom, because the right structure follows from that. If only you are disclosing, a one-way deed may be the cleanest option. If both sides are sharing, a mutual NDA avoids negotiation about fairness. If you are already engaging someone to do work, confidentiality obligations usually belong in the main services or employment contract rather than a standalone NDA, so they sit alongside payment terms, IP ownership and termination.

When reviewing an NDA the other side has sent, we would push back on one-sided definitions of confidential information, broad rights to share with "representatives" or related entities, and foreign governing law clauses. We would insist on a purpose limitation, a need-to-know restriction, survival of confidentiality for trade secrets, and a realistic return or destruction mechanism. We would also check the agreement against your other documents, because a confidentiality clause that contradicts your employment contracts, contractor agreements, or IP assignments creates exactly the uncertainty you want to avoid in a dispute.

The definition of confidential information

If you remember one clause, make it the definition of confidential information. It is the most misdrafted clause in the document, and it is usually the one that decides who wins. A definition that only covers information "marked confidential" leaves your pricing sheet unprotected. A definition so broad it covers everything the recipient already knows will be rewritten at the first pushback, or ignored as unenforceable. The definition, the exclusions, and the purpose limitation work as one unit: the definition says what is protected, the exclusions say what is not, and the purpose clause says what the recipient may actually do with it. Get that unit right and the rest of the agreement has something to enforce. Get it wrong, and the other clauses are protecting nothing in particular.

Confidentiality agreements help startups share what they need to share while reducing the risk of misuse. A strong one covers the definition of confidential information, the permitted purpose, who can access the information, how long the obligation lasts, and what happens at the end of the relationship. It is strongest when paired with practical habits, such as sharing information in stages and restricting access to sensitive files, and when it is consistent with your employment contracts, contractor agreements and IP ownership documents.