An NDA (Non-Disclosure Agreement), or confidentiality agreement, secures sensitive exchanges with partners, investors, subcontractors or candidates. In France, it complements the pre-contractual confidentiality duty already provided by Article 1112-2 of the Civil Code (available on Legifrance — French legislation portal) and works alongside trade secret protection under Directive (EU) 2016/943 (EUR-Lex — EU law portal), implemented by Law no. 2018-670 of 30 July 2018.
1) NDA: definition and useful legal framework
An NDA is a contract under which one or more parties undertake not to disclose information identified as confidential and to use it only for a defined purpose. It particularly covers trade secrets (information with commercial value, reasonably protected and not generally known), a framework harmonised in Europe by Directive 2016/943 (EUR-Lex — EU law portal) and its French implementation (Legifrance — French legislation portal). INPI — French industrial property office provides practical guidance on key contractual precautions.
Note: since Law no. 2026-122 of 23 February 2026, legal advice from in-house counsel enjoys enhanced statutory confidentiality. An NDA nevertheless remains useful to cover other business information exchanged with external partners.
2) When should you use an NDA? 8 practical cases
- Before a POC/technology partnership (specifications, roadmap, transfer prices).
- Joint R&D development and exchanges of know-how (formulas, datasets, prototypes). See Regimbeau's practical R&D warning (analysis).
- Investor teasers / due diligence and data rooms; the agreement governs access and use. Organise it alongside your legal data room.
- M&A, transfer of a customer base (KPIs, customer contracts, margins, debts).
- Tenders (methodologies, prices, cloud architecture).
- Recruiting sensitive roles (C-level, R&D) before providing strategic information.
- Services, managed IT and subcontracting (system/data access). Combine with a services contract and, where needed, a subcontracting agreement.
- Private SaaS demonstrations involving technical secrets; remember alignment with your SaaS terms of sale and licences.
Good to know: many investors refuse NDAs at the very first contact. Share only non-sensitive information then, and defer critical details until after the term sheet, under an NDA.
3) Unilateral, bilateral or multilateral?
- Unilateral: useful where only one party discloses (e.g. a pitch to an industrial company).
- Bilateral: standard where both parties exchange information.
- Multilateral: collaborative projects (consortia, calls for projects), to avoid chains of incompatible NDAs.
4) Essential clauses and negotiation points
4.1 Defining “Confidential Information”
- Define precisely (technical, commercial, financial, legal, source code, AI training data) and exclude information that is public, already known without breach, independently developed or lawfully received from a third party.
- Formalities: “Confidential” marking or a confirmation email within 5 to 10 days for oral exchanges. Good practice reiterated by INPI — French industrial property office.
- Reverse engineering: Directive 2016/943 permits observation/study of a lawfully obtained product unless contractually prohibited (EUR-Lex — EU law portal). Include a prohibition if necessary.
4.2 Purpose and “need to know”
- Limit use to a specific purpose (evaluating partnership X).
- Allow sharing only with strictly necessary persons (employees, subcontractors, advisers), subject to an equivalent obligation.
- In-house counsel's legal advice benefits from statutory confidentiality (Law 2026‑122, Legifrance — French legislation portal), without dispensing with an NDA for other exchanges.
4.3 Security obligations and standard of care
- Reasonable measures: access control, encryption, DLP, logging. Trade secret protection requires “reasonable” protective measures (EUR-Lex — EU law portal).
- The non-disclosure obligation is often treated as an obligation to achieve a result (obligation de résultat); facilitate proof through marking and traceability (R&D warning: Regimbeau — intellectual property advice).
4.4 Duration
- Common practice: 3 to 5 years after discussions end.
- For a technical secret, protection can last while the information remains a trade secret (proportionately). Useful guidance is available on Service Public Pro — business guidance and Economie.gouv.fr — French economy ministry.
4.5 Governing law, jurisdiction and interim proceedings
- Choose governing law and a competent court suited to the place of performance/evidence. For more detail, see our guide to jurisdiction clauses.
- In an emergency (leak), seek interim measures (référé) (injunction, coercive penalty payment) using emergency procedures described on Justice.fr — French justice portal.
4.6 Remedies and evidence
- Include a penalty clause (clause pénale) (fixed damages adjustable by the judge, art. 1231‑5 C. civ., Legifrance — French legislation portal), without excluding additional compensation where justified.
- Add a right to injunctive relief and return/destruction of materials, accompanied by a certificate.
- Organise evidence: marking, access registers, acknowledgments of receipt, watermarks.
5) GDPR: what an NDA does not cover
An NDA does not replace a data processing agreement (DPA) under the GDPR. If personal data is shared, define roles (controller/processor), purposes and security measures according to CNIL guidance. Minimise data, favour anonymisation, restrict access and set clear retention periods.
6) Operational process: the checklist before any sharing
- Choose the right format (unilateral/bilateral) and sign before sending anything.
- Version your template; plan annex management and the list of authorised persons.
- Limit access to “need to know”; use a data room with granular permissions and traceability; coordinate with your licence/access terms.
- Mark all documents “Confidential” and confirm oral exchanges in writing.
- Pass down the obligation to subcontractors and advisers; reflect it in your services contract and subcontracting agreements.
- Plan the exit (return/destruction, limited audit) and a credible penalty clause.
- Train teams in sharing rules and handling sensitive information (practical references on Economie.gouv.fr — French economy ministry and Service Public Pro — business guidance).
7) Sample clauses (adapt before use)
- Definition: “Confidential Information” means any non-public information, in any medium, relating in particular to products, services, know-how, technical and commercial data, marked “Confidential” or whose nature requires confidentiality.
- Permitted use: The Receiving Party shall use Confidential Information solely to evaluate [the Project] and disclose it only to persons who need to know it and are subject to an equivalent obligation.
- Prohibitions: Except as required by mandatory law, the Receiving Party shall refrain from reverse engineering, decompilation, testing or analysis outside the authorised framework.
- Duration: Confidentiality obligations apply for [X] years after discussions cease; for trade secrets, for as long as they retain that status.
- Remedies: Any breach shall attract a fixed penalty of [amount] € (art. 1231‑5 C. civ.), without prejudice to the right to obtain any injunctive relief and full compensation for the loss.
8) Common mistakes to avoid
- An overly vague definition or “everything exchanged” without exceptions: risk of unenforceability.
- Forgetting statutory exceptions (public information, already known, independently developed, court order).
- No flow-down to subcontractors/advisers: a gap in contractual protection.
- Unrealistic duration for short-lived commercial information; adjust to its nature.
- Mixing an NDA with exclusivity, non-compete or non-solicitation without a specific discussion.
- Omitting governing law/jurisdiction, creating procedural uncertainty; see our focus on jurisdiction clauses.
Quick FAQ
What duration should you choose? 3 to 5 years for most information; potentially longer for technical secrets while they remain reasonably protected.
Does an NDA cover personal data? No. A separate GDPR framework is needed (DPA, security, legal basis), according to CNIL — French data protection authority.
Is an NDA enough for an R&D project? It is necessary but must be precise (scope, use, reverse engineering). See the R&D analysis from Regimbeau — intellectual property advice.
What should you do after a leak? Activate emergency clauses (injunction, cessation), use interim proceedings (see Justice.fr — French justice portal), quantify loss and invoke the penalty clause.
What about an investor who refuses the NDA? Disclose only non-sensitive information and defer details until after the term sheet under an NDA; organise a restricted-access data room.
To secure negotiations and avoid liability blind spots, also see our analyses of limitation-of-liability clauses and services contracts.
Further reading
Related resources
Frequently asked questions
FAQ
What is an NDA's purpose?
To prevent disclosure and limit sensitive information use to a defined purpose, while facilitating evidence and remedies if information leaks.
How long should a confidentiality agreement last?
In practice, 3 to 5 years for commercial information. For a technical secret, protection can last while the information remains a trade secret.
Does an NDA replace a GDPR agreement?
No. An NDA is not a DPA. If personal data is exchanged, a specific GDPR framework is required (roles, security, retention periods).
Can reverse engineering be prohibited?
Yes, by contract, subject to statutory exceptions under Directive 2016/943 and applicable local law.
How should you respond to a breach?
Seek injunctive relief and invoke the penalty clause, secure evidence (access logs) and apply for interim court measures to stop the leak.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.