Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

Commercial Contracts and Terms of Sale6 min read

Differences between NDAs, confidentiality agreements and DPAs: a practical guide for startups

Understand the differences between NDAs, confidentiality agreements and DPAs: when to use each document, key clauses, mistakes to avoid and startup checklists.

Confusing NDAs, confidentiality agreements and DPAs exposes startups to information leaks, failed deals and GDPR penalties. This practical guide clarifies their uses, essential clauses and mistakes to avoid.

NDAs, confidentiality agreements and confidentiality clauses: making the distinction

NDA (Non-Disclosure Agreement): a standalone contract

An NDA is a specific contract under which one or more parties undertake not to disclose certain information. It may be unilateral (one-way) or bilateral (mutual). Under French law, confidentiality during negotiations is also protected by statute: Article 1112‑2 of the Code civil. A contractual NDA provides protection beyond negotiations and specifies the scope, duration, exceptions and penalties.

In French practice, “NDA” and “confidentiality agreement” are often synonymous. Professional literature also notes this equivalence in terminology (see an accessible overview of the differences in terminology).

Confidentiality agreement: a generic term

“Confidentiality agreement” means either a standalone NDA or a simple confidentiality clause included in another contract (services, licence, terms of sale or employment). A standalone agreement is recommended when information is exchanged before, or independently of, the main contract (investor pitches, due diligence, POCs).

An integrated confidentiality clause

An integrated clause also protects secrecy, but is often more concise. If properly drafted, it can be as robust as a standalone NDA. It should systematically be included in a services agreement or B2B terms of sale to cover all information exchanged during performance.

DPA (Data Processing Agreement): a separate GDPR contract

A DPA governs the processing of personal data by a processor on behalf of a controller. It is a legal requirement under Article 28 of the GDPR. It is independent of an NDA: an NDA protects confidential information (technical or commercial information and know-how), whereas a DPA governs GDPR compliance for personal-data processing.

The key elements of a DPA are specified in the legislation and CNIL recommendations: documented instructions, confidentiality of authorised persons, security (Art. 32), subprocessors, assistance to the controller, handling data when the contract ends, and audits. For further practical guidance, see our DPA guide for SaaS startups.

What should you use, and when? Practical startup scenarios

  • Investor pitch, POC with a major account or technical audit of a partner: a standalone NDA (unilateral if only you disclose information; bilateral if disclosure is mutual).
  • Signing a B2B sales agreement or a services agreement: an integrated confidentiality clause plus a separate DPA if personal data is processed for the customer.
  • Using a hosting/cloud provider, marketing tool or call centre that processes personal data on your behalf: a DPA is mandatory (Art. 28 GDPR), in addition to any confidentiality clauses.
  • Sharing an algorithm, product roadmap or non-public pricing: an NDA. For strategic information qualifying as a trade secret, protection may last as long as secrecy is maintained (see INPI guidance on trade secrets and économie.gouv.fr).

Drafting checklists

NDA / standalone confidentiality agreement

  • A precise definition of “Confidential Information” (including oral/visual media and specifying whether “derived” information is included), plus the usual exceptions (public, already known, legitimately received from a third party, independently developed).
  • Scope of authorised recipients (employees, officers, advisers, auditors, potential investors), subject to a need-to-know requirement and equivalent confidentiality obligations.
  • Strictly defined permitted use (assessing the partnership, carrying out the POC, due diligence, etc.).
  • Separate periods for disclosure and the confidentiality obligation (often 3–5 years; for trade secrets, until the information becomes public).
  • Reasonable protection measures (access controls, encryption, compartmentalisation).
  • Return/destruction upon first request or at the end of the relationship, with statutory exceptions (archives, regulatory requirements).
  • Penalties and remedies: a penalty clause or damages, and the ability to seek urgent relief (an injunction). Check compatibility with your liability caps: it is common to exclude confidentiality breaches from the damages cap.
  • Chosen governing law and jurisdiction, prevailing language, severability, assignment and notices.

Good practice: centralise your NDAs and automate expiry reminders in your Legal Ops processes. Avoid copying and pasting unsuitable templates: an investor NDA does not serve the same purpose as a supplier NDA.

Confidentiality clause integrated into a contract

  • Ensure it covers all information exchanged during performance, including customer and third-party information.
  • Align the confidentiality period with the sensitivity of the data (often longer than the contract term).
  • Ensure compatibility with other clauses (caps, penalties, termination). Examples appear in our resource on key issues in services agreements.

DPA (Art. 28 GDPR): mandatory clauses

  • Subject matter, duration, nature and purposes of processing, categories of data subjects and data, and the controller’s obligations and rights (Article 28 GDPR).
  • Processing in accordance with documented instructions, plus confidentiality of authorised persons.
  • Appropriate security (Art. 32), logging, testing and vulnerability management.
  • Conditional use of subprocessors (prior specific or general authorisation, identical contractual obligations).
  • Assistance: exercising rights, breach notifications (Art. 33‑34), impact assessments and audits.
  • End of contract: deletion or return of data, erasure of copies and evidence of completion.

CNIL publishes useful guidance on the processor’s role and DPA content (cnil.fr). Practical reminders are also available on Service Public Pro.

Common mistakes and risks

  • Thinking an NDA replaces a DPA: incorrect. An NDA protects secrecy; a DPA provides the legal framework for personal-data processing.
  • Failing to include actual recipients (freelancers, consultancies, investors) among authorised recipients: a source of “indirect” breaches.
  • Defining confidential information too broadly or vaguely: a risk of unenforceability.
  • Omitting standard exceptions: you obstruct statutory obligations (inspections, audits) or necessary exchanges with your advisers.
  • Unrealistic terms (“perpetual” confidentiality without specifying trade secrets) or, conversely, periods too short for know-how.
  • Ignoring processors’ GDPR compliance: the absence of a DPA can expose you to administrative fines of up to 4% of worldwide turnover (Article 83 of the GDPR), as CNIL points out.

Implementation for startups

  • Map your information flows: what confidential information? What personal data? Who has access?
  • Standardise your templates: at least one unilateral NDA, one bilateral NDA, a standard confidentiality clause and a DPA compatible with your offerings.
  • Train your teams: sales, product and engineering must know when to send an NDA, when to require a DPA and which points to negotiate.
  • Align your documents with your internal policies: security, access management and privacy policy (see how to draft a GDPR privacy policy).

Further reading

Related resources

Frequently asked questions

FAQ

What is the difference between an NDA and a confidentiality agreement?

In practice, there is no substantive difference: NDA is the English-language name for a standalone confidentiality agreement. This should be distinguished from a simple confidentiality clause integrated into another contract.

When is a DPA mandatory?

Whenever a provider processes personal data on your behalf. Article 28 of the GDPR requires it, and CNIL oversees compliance.

How long should an NDA last?

3 to 5 years is common. For a trade secret, protection may last as long as the information remains secret.

Does an NDA replace a DPA?

No. An NDA protects confidential information generally; a DPA provides the legal framework for personal-data processing.

Should confidentiality breaches be excluded from the liability cap?

Yes, this is common practice to prevent damages arising from a leak being limited by a general damages cap.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles