Non-Disclosure Agreements (NDAs) are among the most frequently used legal documents in commerce. They are typically entered into before the parties have agreed to do business together and often before any value has been exchanged. Their purpose is straightforward: to facilitate the sharing of confidential information while preserving its confidentiality.

Yet NDAs present a curious contradiction.

Many organisations that spend considerable time negotiating liability caps, exclusions of indirect loss and carefully balanced risk allocation in their principal commercial agreements will sign an NDA containing none of those protections. In some cases, the same organisation that insists upon a liability cap in a multimillion-pound services agreement will accept uncapped liability under a three-page NDA signed merely to enable preliminary discussions.

This raises an important question: have businesses collectively concluded that such risk is justified, or has the market simply accepted a drafting convention without subjecting it to sufficient scrutiny?

 

Why Do Businesses Accept So Much Risk in NDAs?

One of the most striking aspects of many NDAs is the absence of any meaningful limitation of liability regime.

In a typical supply, services or technology agreement, it is considered entirely normal for the parties to negotiate financial liability caps and exclusions for indirect or consequential losses. Those provisions form the foundation of commercial risk allocation. Businesses generally seek certainty as to their maximum exposure and are reluctant to accept liabilities that are disproportionate to the value of the transaction.

NDAs are often treated differently.

Many NDAs contain no cap on liability whatsoever. Equally, they frequently omit any exclusion of indirect or consequential losses. The result is that a receiving party may be exposed to potentially unlimited liability arising from a single breach of confidentiality, notwithstanding that the NDA itself may have no associated contract value and may ultimately lead to no commercial relationship at all.

The conventional justification is that confidential information is inherently valuable and that the disclosing party should be entitled to recover all losses arising from its misuse. There is some force in this argument. A disclosure of trade secrets, strategic plans or acquisition-related information could undoubtedly cause significant damage.

However, that reasoning is not entirely persuasive.

The same justification could be advanced in relation to intellectual property infringement, professional negligence, cyber incidents or business interruption losses. Yet parties routinely agree to financial limitations and carefully calibrated remedies in those circumstances. Indeed, many risks that are objectively more likely to occur than a confidentiality breach are nevertheless subject to extensive contractual limitation.

The question therefore arises as to whether the absence of liability caps in NDAs is truly a conscious commercial decision or merely the result of market inertia. In many cases, it appears to be the latter. NDAs are often viewed as administrative gateway documents rather than contracts requiring substantive negotiation. As a consequence, provisions that would be heavily negotiated elsewhere are simply overlooked.

 

The Enforcement Challenge

The theoretical exposure created by an NDA is only one side of the equation. The other is whether the disclosing party can actually enforce its rights in practice.

The answer is frequently more complicated than many assume.

Where confidential information enters the public domain or appears to have been misused, there is often an immediate assumption regarding responsibility. If Company A discloses information to Company B and that information later emerges in the market, Company B may become the obvious suspect.

Suspicion, however, is not evidence.

To establish liability, a claimant will generally need to demonstrate not only that the information was confidential and that obligations of confidence existed, but also that the receiving party was responsible for the relevant disclosure or misuse. In many cases, proving that causal link can be extraordinarily difficult.

Modern businesses operate within complex information environments. Confidential information may be accessed by employees, directors, consultants, professional advisers, subcontractors and affiliated entities. Information may be stored across multiple systems and locations. A leak may occur through negligence, malicious conduct, inadequate security controls or a completely unrelated third party.

The fact that confidential information has escaped does not necessarily establish how, when or by whom that occurred.

This presents a significant practical challenge. Many NDA disputes are not determined by the quality of the drafting but by the availability of evidence. Without evidence establishing responsibility for a disclosure, the existence of a broad confidentiality obligation may offer limited practical protection.

This inevitably leads to a more uncomfortable question: if proving a breach is often so difficult, what is the real value of an NDA?

The answer may be that NDAs derive much of their value from deterrence rather than enforcement. They establish clear expectations, create contractual obligations and discourage misconduct. Most commercial actors comply with NDAs not because they anticipate litigation, but because the existence of the obligation influences behaviour.

Nevertheless, the evidential challenge should not be ignored. As information governance and cybersecurity become increasingly sophisticated, it may be appropriate for parties to consider mechanisms that improve traceability. Audit rights, record-keeping obligations and information access logs may become increasingly important, particularly where highly sensitive information is being disclosed.

 

The Problem with Confidentiality Indemnities

If uncapped liability under an NDA warrants scrutiny, confidentiality indemnities warrant even greater scrutiny.

Many NDA precedents contain indemnity provisions requiring the receiving party to indemnify the disclosing party for losses arising from breaches of confidentiality obligations. Such clauses are often included as standard language and receive little attention during negotiations.

That is surprising given their potential impact.

A conventional damages claim generally requires the claimant to prove breach, causation and loss. An indemnity can alter that dynamic significantly. Depending upon its drafting, an indemnity may provide a contractual entitlement to recover specified losses without many of the limitations and arguments that would ordinarily apply to a damages claim.

From a practical perspective, this shifts the balance of power in favour of the disclosing party.

The receiving party may find itself responding not merely to an allegation of breach but also to a demand for payment supported by the indemnity. The legal and commercial burden then moves to the receiving party to challenge the application of the indemnity and the quantification of the claimed losses.

This is particularly significant when combined with uncapped liability. Together, the two provisions can create a risk profile that is materially broader than that contained in the parties’ principal commercial agreements.

It is therefore reasonable to ask why confidentiality indemnities have become so commonplace.

The answer is unlikely to be that every disclosing party has consciously determined that an indemnity is necessary. More often, such provisions appear to have become embedded within market precedents and are reproduced without any detailed consideration of whether they remain appropriate for the particular circumstances.

 

The Search for a Practical Balance

The natural response to these concerns is to improve the drafting.

One could introduce liability caps, exclude indirect and consequential losses, impose detailed evidential requirements, include audit provisions, prescribe cybersecurity standards and carefully regulate indemnity rights.

From a legal perspective, that approach has considerable merit.

From a commercial perspective, however, it creates a different problem.

The more sophisticated the protection, the longer and more complex the NDA becomes.

The purpose of an NDA is typically to facilitate discussions, not to become a significant negotiation exercise in its own right. If parties are required to negotiate a ten-page risk allocation regime simply to commence exploratory commercial discussions, the document may cease to serve its intended purpose.

For that reason, the appropriate solution is unlikely to be found in maximum drafting. It is more likely to be found in proportionate drafting.

Routine commercial discussions may justify a relatively simple NDA containing sensible limitations of liability and no indemnity provisions. By contrast, disclosures involving highly sensitive trade secrets, acquisition activity, strategic information or proprietary technology may warrant more extensive protections, including enhanced security measures, stronger audit rights and bespoke remedies.

The level of contractual protection should correspond to the significance of the information being disclosed.

 

Conclusion

The market’s treatment of NDAs presents an interesting anomaly. Businesses that would rarely accept unlimited liability in their core commercial arrangements frequently do so in NDAs. Equally, confidentiality indemnities are often accepted with little consideration of the substantial shift in risk and leverage that they create.

At the same time, the practical enforcement of confidentiality obligations can be considerably more challenging than is often acknowledged. The existence of a broad contractual obligation does not eliminate the evidential difficulties associated with proving responsibility for a leak or misuse of information.

The result is a striking paradox: NDAs often create extensive theoretical liability while simultaneously presenting significant practical enforcement challenges.

Perhaps the most important question is not whether NDAs remain necessary – they undoubtedly do. Rather, it is whether businesses and their advisers should be more willing to challenge long-standing assumptions regarding risk allocation within those documents.

For contracts designed merely to enable conversations, many NDAs impose surprisingly significant legal exposure. The fact that this continues to be accepted as standard market practice may be one of the more curious features of modern commercial contracting.

If you would like us to review your NDA, please get in touch with our Commercial Team at enquiries@ellisons.com

Explore Commercial Law Services