Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

Commercial Contracts and Terms of Sale6 min read

NDAs and confidentiality agreements: when and how to use them

The practical guide to deciding when to sign an NDA, what to include (definition, duration, exceptions, remedies) and how to enforce it in France and the EU.

An NDA (Non-Disclosure Agreement), or confidentiality agreement, secures sensitive exchanges with partners, investors, subcontractors or candidates. In France, it complements the pre-contractual confidentiality duty already provided by Article 1112-2 of the Civil Code (available on Legifrance — French legislation portal) and works alongside trade secret protection under Directive (EU) 2016/943 (EUR-Lex — EU law portal), implemented by Law no. 2018-670 of 30 July 2018.

An NDA is a contract under which one or more parties undertake not to disclose information identified as confidential and to use it only for a defined purpose. It particularly covers trade secrets (information with commercial value, reasonably protected and not generally known), a framework harmonised in Europe by Directive 2016/943 (EUR-Lex — EU law portal) and its French implementation (Legifrance — French legislation portal). INPI — French industrial property office provides practical guidance on key contractual precautions.

Note: since Law no. 2026-122 of 23 February 2026, legal advice from in-house counsel enjoys enhanced statutory confidentiality. An NDA nevertheless remains useful to cover other business information exchanged with external partners.

2) When should you use an NDA? 8 practical cases

  • Before a POC/technology partnership (specifications, roadmap, transfer prices).
  • Joint R&D development and exchanges of know-how (formulas, datasets, prototypes). See Regimbeau's practical R&D warning (analysis).
  • Investor teasers / due diligence and data rooms; the agreement governs access and use. Organise it alongside your legal data room.
  • M&A, transfer of a customer base (KPIs, customer contracts, margins, debts).
  • Tenders (methodologies, prices, cloud architecture).
  • Recruiting sensitive roles (C-level, R&D) before providing strategic information.
  • Services, managed IT and subcontracting (system/data access). Combine with a services contract and, where needed, a subcontracting agreement.
  • Private SaaS demonstrations involving technical secrets; remember alignment with your SaaS terms of sale and licences.

Good to know: many investors refuse NDAs at the very first contact. Share only non-sensitive information then, and defer critical details until after the term sheet, under an NDA.

3) Unilateral, bilateral or multilateral?

  • Unilateral: useful where only one party discloses (e.g. a pitch to an industrial company).
  • Bilateral: standard where both parties exchange information.
  • Multilateral: collaborative projects (consortia, calls for projects), to avoid chains of incompatible NDAs.

4) Essential clauses and negotiation points

4.1 Defining “Confidential Information”

  • Define precisely (technical, commercial, financial, legal, source code, AI training data) and exclude information that is public, already known without breach, independently developed or lawfully received from a third party.
  • Formalities: “Confidential” marking or a confirmation email within 5 to 10 days for oral exchanges. Good practice reiterated by INPI — French industrial property office.
  • Reverse engineering: Directive 2016/943 permits observation/study of a lawfully obtained product unless contractually prohibited (EUR-Lex — EU law portal). Include a prohibition if necessary.

4.2 Purpose and “need to know”

  • Limit use to a specific purpose (evaluating partnership X).
  • Allow sharing only with strictly necessary persons (employees, subcontractors, advisers), subject to an equivalent obligation.
  • In-house counsel's legal advice benefits from statutory confidentiality (Law 2026‑122, Legifrance — French legislation portal), without dispensing with an NDA for other exchanges.

4.3 Security obligations and standard of care

  • Reasonable measures: access control, encryption, DLP, logging. Trade secret protection requires “reasonable” protective measures (EUR-Lex — EU law portal).
  • The non-disclosure obligation is often treated as an obligation to achieve a result (obligation de résultat); facilitate proof through marking and traceability (R&D warning: Regimbeau — intellectual property advice).

4.4 Duration

4.5 Governing law, jurisdiction and interim proceedings

  • Choose governing law and a competent court suited to the place of performance/evidence. For more detail, see our guide to jurisdiction clauses.
  • In an emergency (leak), seek interim measures (référé) (injunction, coercive penalty payment) using emergency procedures described on Justice.fr — French justice portal.

4.6 Remedies and evidence

  • Include a penalty clause (clause pénale) (fixed damages adjustable by the judge, art. 1231‑5 C. civ., Legifrance — French legislation portal), without excluding additional compensation where justified.
  • Add a right to injunctive relief and return/destruction of materials, accompanied by a certificate.
  • Organise evidence: marking, access registers, acknowledgments of receipt, watermarks.

5) GDPR: what an NDA does not cover

An NDA does not replace a data processing agreement (DPA) under the GDPR. If personal data is shared, define roles (controller/processor), purposes and security measures according to CNIL guidance. Minimise data, favour anonymisation, restrict access and set clear retention periods.

6) Operational process: the checklist before any sharing

  • Choose the right format (unilateral/bilateral) and sign before sending anything.
  • Version your template; plan annex management and the list of authorised persons.
  • Limit access to “need to know”; use a data room with granular permissions and traceability; coordinate with your licence/access terms.
  • Mark all documents “Confidential” and confirm oral exchanges in writing.
  • Pass down the obligation to subcontractors and advisers; reflect it in your services contract and subcontracting agreements.
  • Plan the exit (return/destruction, limited audit) and a credible penalty clause.
  • Train teams in sharing rules and handling sensitive information (practical references on Economie.gouv.fr — French economy ministry and Service Public Pro — business guidance).

7) Sample clauses (adapt before use)

  • Definition: “Confidential Information” means any non-public information, in any medium, relating in particular to products, services, know-how, technical and commercial data, marked “Confidential” or whose nature requires confidentiality.
  • Permitted use: The Receiving Party shall use Confidential Information solely to evaluate [the Project] and disclose it only to persons who need to know it and are subject to an equivalent obligation.
  • Prohibitions: Except as required by mandatory law, the Receiving Party shall refrain from reverse engineering, decompilation, testing or analysis outside the authorised framework.
  • Duration: Confidentiality obligations apply for [X] years after discussions cease; for trade secrets, for as long as they retain that status.
  • Remedies: Any breach shall attract a fixed penalty of [amount] € (art. 1231‑5 C. civ.), without prejudice to the right to obtain any injunctive relief and full compensation for the loss.

8) Common mistakes to avoid

  • An overly vague definition or “everything exchanged” without exceptions: risk of unenforceability.
  • Forgetting statutory exceptions (public information, already known, independently developed, court order).
  • No flow-down to subcontractors/advisers: a gap in contractual protection.
  • Unrealistic duration for short-lived commercial information; adjust to its nature.
  • Mixing an NDA with exclusivity, non-compete or non-solicitation without a specific discussion.
  • Omitting governing law/jurisdiction, creating procedural uncertainty; see our focus on jurisdiction clauses.

Quick FAQ

What duration should you choose? 3 to 5 years for most information; potentially longer for technical secrets while they remain reasonably protected.

Does an NDA cover personal data? No. A separate GDPR framework is needed (DPA, security, legal basis), according to CNIL — French data protection authority.

Is an NDA enough for an R&D project? It is necessary but must be precise (scope, use, reverse engineering). See the R&D analysis from Regimbeau — intellectual property advice.

What should you do after a leak? Activate emergency clauses (injunction, cessation), use interim proceedings (see Justice.fr — French justice portal), quantify loss and invoke the penalty clause.

What about an investor who refuses the NDA? Disclose only non-sensitive information and defer details until after the term sheet under an NDA; organise a restricted-access data room.

To secure negotiations and avoid liability blind spots, also see our analyses of limitation-of-liability clauses and services contracts.

Further reading

Related resources

Frequently asked questions

FAQ

What is an NDA's purpose?

To prevent disclosure and limit sensitive information use to a defined purpose, while facilitating evidence and remedies if information leaks.

How long should a confidentiality agreement last?

In practice, 3 to 5 years for commercial information. For a technical secret, protection can last while the information remains a trade secret.

Does an NDA replace a GDPR agreement?

No. An NDA is not a DPA. If personal data is exchanged, a specific GDPR framework is required (roles, security, retention periods).

Can reverse engineering be prohibited?

Yes, by contract, subject to statutory exceptions under Directive 2016/943 and applicable local law.

How should you respond to a breach?

Seek injunctive relief and invoke the penalty clause, secure evidence (access logs) and apply for interim court measures to stop the leak.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles