Confidentiality

A confidentiality clause obliges each party to keep the other’s non-public information secret and to use it only for the purposes of the contract.

What it does

Doing business means sharing things you would rather competitors did not see: pricing, customer lists, product roadmaps, financials, technical details. A confidentiality clause (or a standalone non-disclosure agreement) creates a contractual duty to protect that information.

The clause defines what counts as confidential, either everything disclosed under the contract or only information marked as confidential. It sets the obligations: no disclosure to third parties, use only for the agreed purpose, reasonable care, access limited to people who need to know. It lists the standard exclusions: information already public, already known to the recipient, independently developed, or legitimately received from someone else.

Most clauses allow disclosure where required by law, with advance notice where possible. A duration is set: a fixed number of years after the contract ends or, for trade secrets, for as long as the information stays secret.

Example wording

Each party shall keep the other party’s Confidential Information confidential, shall not disclose it to any third party except to its employees, advisers, and subcontractors who need to know it and are bound by equivalent obligations, and shall use it only for the purposes of this Agreement. These obligations do not apply to information that is or becomes public through no fault of the receiving party, was already lawfully known to the receiving party, is independently developed, or must be disclosed by law. This clause survives for five (5) years after termination of this Agreement.

Risks for SMBs

“Marked confidential” definitions. If only information stamped as confidential is protected, everything said in a meeting, sent in an unmarked email, or shown on a screen is unprotected. Most SMBs do not mark anything. Prefer a definition that covers information a reasonable person would understand to be confidential.

Duration that ends too soon. A confidentiality period of two years after termination may be fine for pricing, but source code, formulas, and customer data can matter for far longer. Carve out trade secrets so they stay protected indefinitely.

No practical way to enforce. The clause is only as good as your ability to prove a breach. If a counterparty leaks your pricing to a competitor, you may never find out, and proving the source is hard. Limit what you share, not just what the contract says.

One-way obligations. Supplier templates sometimes protect the supplier’s information only. If you will be sharing customer data, financials, or plans, insist on mutual obligations.

Subcontractors and affiliates. Information often flows onward to the counterparty’s group companies, consultants, and hosting providers. Make sure the clause binds them to the same standard, and makes the counterparty responsible for their breaches.

Confidentiality is not data protection. Personal data is governed by data protection law regardless of the confidentiality clause. The two need to work together. See data processing.

Common variants and negotiation points


This page is general information about a common contract clause. It is not legal advice and does not account for your jurisdiction, industry, or the specific contract in front of you. Talk to a qualified lawyer before relying on it.

Tracking renewal dates, notice periods, and other contract obligations is what Trackado does.