How to Write an NDA (Non-Disclosure Agreement)

Janis Hiestand
7/30/2026
An NDA protects confidential information when two parties need to share sensitive material. It is one of the most common business documents, and also one of the most frequently botched. The usual failure mode is not a missing clause but an overly aggressive one: definitions so broad they cover everything, terms so long they feel punitive, restrictions so vague neither party knows what compliance looks like.
A good NDA is specific, reasonable, and short enough that the other party actually reads it.
When You Need an NDA
Not every business conversation requires one. NDAs make sense when you are about to share something that has real value if kept secret: a client list, proprietary pricing, unreleased product plans, source code, or trade secrets. If the conversation is about publicly available information or general industry knowledge, an NDA adds friction without adding protection.
The trigger is usually a specific event: a potential partnership, a contractor engagement, a merger discussion, or a vendor evaluation where your internal data will be exposed.
Mutual vs. One-Way
A mutual NDA protects both sides. Use it when both parties will share confidential information, which is the case in most partnership and collaboration discussions.
A one-way NDA protects only the disclosing party. Use it when one side is sharing sensitive material and the other is not, such as when you hire a contractor who will access your systems or client data.
Choosing the wrong type is a common mistake. Sending a one-way NDA to a potential partner who will also be sharing proprietary information signals that you see the relationship as one-sided. Sending a mutual NDA to a freelancer who will not be disclosing anything of their own creates unnecessary complexity.
Define Confidential Information Precisely
The definition clause does the most work in an NDA. It determines what is actually protected, and by extension, what the receiving party has to worry about.
Be specific. "All information shared between the parties" is too broad to enforce meaningfully and too broad for the other party to comply with confidently. Instead, name the categories: customer data, financial projections, product roadmaps, proprietary algorithms, pricing structures.
A well-scoped definition protects what matters without creating a compliance burden that makes the other party hesitant to sign.
Include Standard Exclusions
Every enforceable NDA carves out information that should not be treated as confidential:
- Information already in the public domain
- Information the receiving party independently developed
- Information the receiving party already possessed before disclosure
- Information received from a third party without restriction
These exclusions are standard, expected, and necessary. Omitting them makes the NDA look one-sided and can weaken enforceability.
Set a Reasonable Term
The confidentiality period should match how long the information stays sensitive. Two to five years is the standard range for most business relationships. Trade secrets may justify longer or even indefinite terms, but perpetual obligations on general business information tend to be unenforceable and signal inexperience.
If the NDA covers a specific project, tie the term to the project timeline plus a reasonable tail period.
Specify What Happens on Breach
State the remedies available if the agreement is violated. Most NDAs include a clause acknowledging that monetary damages may be inadequate and that the disclosing party may seek injunctive relief. This is standard language, but its presence matters because it establishes expectations before a dispute arises.
Also specify the obligation to return or destroy confidential materials when the relationship ends or the NDA expires. This is particularly important when the receiving party has been given access to files, systems, or physical documents.
Permitted Disclosures
The receiving party will often need to share confidential information with their own employees, contractors, or legal advisors to fulfill the purpose of the NDA. A clause permitting this, provided those individuals are bound by equivalent obligations, prevents the agreement from being impractical while maintaining protection.
Common Mistakes
Overreach on scope. An NDA that tries to protect everything protects nothing effectively. Courts are less sympathetic to broad, vague definitions.
Missing the purpose clause. Without a stated purpose, the NDA lacks context for what disclosures are expected and why. This matters in enforcement.
Forgetting the governing law. Specify which jurisdiction's law governs the agreement. This avoids an expensive threshold question if a dispute arises.
Using the wrong type. A mutual NDA for a one-way relationship, or vice versa, creates confusion about obligations and signals carelessness.
Start From a Template
The mutual NDA template and one-way NDA template on InkDraft include the standard clause structure: parties, purpose, definition, exclusions, term, permitted disclosures, remedies, and return obligations. Start from the one that matches your situation, adjust the definition of confidential information to your specific context, and the rest of the structure will hold.
More from the blog
Client Onboarding After Signing: A Step-by-Step Process
What to do after a client signs the contract. A step-by-step onboarding process that sets expectations, collects what you need, and prevents the most common early-engagement failures.
How to Follow Up on a Proposal (Without Being Annoying)
When to follow up on a proposal, what to say, and how to read the silence. A step-by-step follow-up sequence that keeps deals moving without damaging the relationship.
How to Write a Scope of Work
A scope of work defines what will be delivered, when, and under what conditions. How to write one that prevents scope creep, protects both sides, and keeps the project on track.