1. What an NDA actually does, and the moment it fails
  2. Five fixes before you share anything else
    1. 1. Reconstruct what was shared, when and how
    2. 2. Define the information the NDA actually protects
    3. 3. State the purpose of the disclosure
    4. 4. Make the obligations realistic and the enforcement practical
    5. 5. Behave as though the information is confidential
  3. When to bring a lawyer in
  4. The signature was never the protection

You had a potential partner sign your NDA before the pitch meeting. Six months later they launch a product that looks suspiciously like the one you described, priced the way you price. You pull out the NDA and actually read it for the first time. It is a template: "all information disclosed shall be confidential." There is no purpose stated, no carve-outs, and you shared your pricing model over coffee before anyone signed anything. You are suddenly not sure the document protects you at all.

The uncomfortable part is that you are probably right to be unsure. In Australian law, an NDA does not protect information in the abstract. It protects confidential information that meets a specific test, shared in circumstances that import an obligation of confidence, and then misused. Miss any of those elements and the claim fails, no matter how stern the document sounds.

What is at stake is not really the paperwork. It is the information itself, which for many small businesses is the main asset: customer lists, pricing models, product specifications, strategy. Two features of confidentiality law make this risk sharp. First, it is irreversible: once information is out in the world it cannot be made secret again, no matter what the NDA says. Second, it is evidentiary: a court will look at what you actually did around the information, not just what the document promised. If you treated it casually, you have made the other side's argument for them.

What an NDA actually does, and the moment it fails

An NDA works by creating a legal obligation: the recipient may only use the information for the agreed purpose and may not disclose it to anyone else. It does two jobs at once. It sets expectations, so the other side knows the information is not casual. And it creates consequences, so if they misuse it you can seek an injunction to stop further disclosure or claim damages for the loss.

It is just as important to be clear about what an NDA cannot do, because relying on it for those things is how false confidence builds. It cannot make public information secret again. It cannot undo a disclosure that has already happened. It cannot replace proper commercial terms, such as who owns intellectual property developed during the relationship. And it cannot make enforcement cheap if the agreement sends you to a court on the other side of the world.

The test Australian courts apply traces back to the English decision in Coco v AN Clark (Engineers) Ltd (1968) 1A IPR 587 and was restated by the NSW Court of Appeal in Filby v TEG Live Pty Ltd [2023] NSWCA 320. Three things must be shown: the information had the necessary quality of confidence; it was communicated in circumstances importing an obligation of confidence; and there was an unauthorised use of it, meaning some abuse of the information or unfair advantage taken of it.

Two consequences flow from that test that most people never think about. First, an obligation of confidence can arise from the circumstances of a conversation even with no document at all. Equity protects confidential information whether or not a piece of paper was signed. The document's real job is to make the obligation explicit, defined and provable. Second, a vague idea is not protected. In Filby, a promoter pitched a "general and inchoate" idea for an additional concert and lost his claim because the information was not specific enough to have the necessary quality of confidence. An NDA cannot turn a half-formed idea into a protectable asset.

This is where most NDAs quietly fail. They are written to sound tough rather than to be enforceable: "everything is confidential, forever, in all circumstances." That sounds protective and is in fact meaningless, because nobody can apply it day to day, and it gives both sides room to disagree at exactly the moment you need certainty. The gap between what is written and what is real is where the protection leaks away.

Five fixes before you share anything else

If you are reading this because you are about to sign or send an NDA, or because you suspect the one you already signed will not hold, here is the sequence that actually helps. Work through it before you disclose anything further.

1. Reconstruct what was shared, when and how

Start with the facts, not the document. Rebuild the record of every disclosure: what information went out, to whom, on what date, and whether it happened before or after the NDA was signed. Courts decide confidentiality cases on this record. Gather:

  • The signed NDA: every version you sent or received, including drafts and the final executed copy.
  • The communications: emails, messages and meeting notes covering or scheduling the disclosure.
  • The materials: documents you shared, with any markings or labels indicating confidentiality.
  • The access list: who saw the information, and whether access was limited or open.

Information shared before the NDA was signed, or shared casually with no record, may fall outside even a well-drafted document. Knowing what the record actually shows tells you how much protection you have and what needs fixing.

2. Define the information the NDA actually protects

The most common failure is a definition that protects everything and therefore protects nothing. "All information disclosed is confidential" leaves both sides guessing about what they can and cannot use. Replace it with a definition that names the categories that matter to your business: pricing, customer lists, product specifications, source code, financials, strategy. Then add the carve-outs, the things the NDA does not cover:

  • Public information: anything already in the public domain, because the law will not make public information secret again.
  • Known information: what the recipient already knew before you shared it.
  • Independent development: what the recipient develops on their own, without using your information.
  • Required disclosures: disclosures compelled by law, such as to ASIC, the ATO or a court.

Carve-outs are not concessions. They are what make the definition credible and enforceable. An NDA that tries to lock up the whole world is the one a court will strain against, and the one the other side will test.

3. State the purpose of the disclosure

An NDA that only says "do not disclose" is missing half its job. The other half is "use this only for this purpose." A purpose clause such as "the recipient may use the information only to evaluate a potential commercial partnership" turns a vague promise into a measurable one.

Purpose is what makes misuse provable. Legitimate use is use within the purpose. Anything else is misuse, and you can point to the clause when it happens. It also does quiet work on the other side: their advisers will tell them what they can and cannot do with the information, and a clear purpose shrinks the grey zone they might otherwise wander into.

4. Make the obligations realistic and the enforcement practical

"Confidential forever" feels safe and is usually commercially unrealistic. Courts do not rewrite unreasonable bargains, and a term that demands the impossible is the one the other side will argue about when it matters. Structure the obligations sensibly instead:

  • Timeframes: perpetual protection for genuinely sensitive material such as trade secrets, and reasonable periods for ordinary business information.
  • Security: achievable obligations, such as reasonable care and access limited to people who need to know, rather than perfect security.
  • Parties: name the actual entities involved, not a trading name or an unregistered business.
  • One-way or mutual: a one-way NDA when only one side is disclosing, a mutual NDA when both are. Taking on obligations you do not need complicates an otherwise simple conversation.
  • Governing law and jurisdiction: choose a forum you would realistically use. If the other party is overseas, an Australian NDA may be difficult to enforce, and you should think now about where you would have to sue.

5. Behave as though the information is confidential

The last fix is not in the document at all. Courts weigh behaviour: if you shared the information casually, with no controls, no limited access and no marking, you have made it harder to argue it was truly sensitive. Protection is built by habit:

  • Stage the disclosure: share only what each conversation actually needs, and hold the rest back.
  • Mark it: label documents as confidential and control access to them.
  • Limit the circle: give the information only to people with a need to know.
  • Keep records: note what was shared, with whom and when.
  • Sign first: never share the sensitive material before the NDA is signed.

There is also a backstop that operates even where an NDA is missing or weak. Under s 183 of the Corporations Act 2001 (Cth), directors, officers and employees of a company must not improperly use information obtained because of their position, and the duty continues after they leave. If the person on the other side of the table obtained your information through their role, that statutory duty applies regardless of what the document says.

When to bring a lawyer in

If misuse may have already happened, or you are about to share information that is genuinely central to your business, this is the point at which professional help earns its keep. The assessment a lawyer would run is concrete: review the NDA and the disclosure record against the three elements of breach of confidence, form a view on whether the information had the necessary quality of confidence and whether the circumstances imported an obligation of confidence, and identify what evidence of misuse exists.

If misuse has occurred, speed matters. A lawyer can move quickly for an interlocutory injunction to stop further disclosure before the information spreads, and can advise on the remedies realistically available, which may include damages or an account of profits. Much of that work is practical rather than theoretical: preserving the evidence trail, sending a carefully worded letter that puts the other side on notice, and forming a view on whether an urgent court application is warranted before the information travels any further. If the NDA itself is the problem, a lawyer will redraft it or negotiate amendments so that the definition, the purpose, the carve-outs, the timeframes and the jurisdiction all match the relationship you are actually in. If you are unsure whether the situation justifies that step, the review itself is usually quick, and the answer is worth having before you share anything more.

The signature was never the protection

The thing to remember is this: what protects you is not the signature on the NDA. It is the specificity of the information and your conduct around it. A document cannot rescue information that was already public, already shared, or too vague to identify. The businesses that stay protected are the ones that define what is confidential, state why it is being shared, and then behave as though it matters, from the first conversation to the last.

If your current NDA is a template, or you have been using the same one for every relationship, review it before you need it to hold. Rebuild the record of what has been shared, tighten the definition and the purpose, make the obligations realistic, and treat the information as confidential in practice. None of that is glamorous. It is what makes the difference between a document that sits in a drawer and one that actually holds up.