What Is NDA (Non-Disclosure Agreement)?

Also called: Nondisclosure agreement, Confidentiality agreement

Related problems: Vendor wants our network diagrams and security details before quoting; Need to share sensitive information during an RFP without it leaking; Provider sent its own NDA and we don't know if it's one-sided; Want vendors to keep our pricing and architecture confidential

A non-disclosure agreement (NDA) is a contract in which one or both parties agree to keep information they receive confidential and to use it only for a stated purpose, such as evaluating a possible deal. In IT and telecom buying, NDAs are commonly signed before a request for proposal, a network or security assessment, or a merger discussion, so that the buyer can share diagrams, configurations, pricing and plans with vendors. Many master agreements also contain a confidentiality section that does the same job once the parties are under contract. How an NDA is interpreted and enforced depends on its wording and on the governing law.

At a glance

  • It restricts disclosure and use of confidential information to an agreed purpose.
  • NDAs can be one-way or mutual; vendor evaluations often call for mutual terms.
  • Standard exceptions cover information that is public, already known, independently developed or legally required to be disclosed.
  • NDAs usually aren’t a substitute for data protection agreements when regulated personal data is involved.
  • Enforceability depends on the wording and governing law. This is general information, not legal advice.

What problem it solves

Getting accurate proposals for network, security or cloud services means telling vendors how your environment really works: where sites are, which systems are exposed, what you pay today, where you’re weak. That information is valuable to competitors and dangerous in the hands of attackers. An NDA sets the ground rules before you share it, and gives you a contractual remedy if it is misused.

Vendors use NDAs too, to protect roadmaps, pricing models and security documentation such as audit reports that they share only under confidentiality.

How it works

Definition of confidential information. NDAs define what is protected. Some cover everything disclosed; others cover only information marked confidential, which can catch out buyers who share material informally. Many include information that a reasonable person would understand to be confidential.

Permitted use and disclosure. The receiving party may use the information only for the stated purpose and share it only with people who need it, such as employees, advisors or subcontractors bound by similar duties.

Exceptions. Common exceptions cover information that is or becomes public through no fault of the recipient, was already known to it, is independently developed, or is received from a third party without restriction. Disclosure required by law or court order is usually permitted, often with notice to the disclosing party.

Duration. The agreement sets how long it lasts and how long the confidentiality duty continues, sometimes with longer protection for trade secrets.

Return or destruction. On request or at the end, the recipient typically must return or destroy the information, often with exceptions for backups and records it must keep.

Remedies. Many NDAs state that a breach may cause irreparable harm and allow the disclosing party to seek an injunction. A breach may also be a material breach of a broader agreement. The governing law and venue clause decides where and under which law disputes are heard.

Enforceability and interpretation depend on the governing law, the jurisdiction and the exact wording. This is general information, not legal advice; have counsel review the contract.

Running a structured sourcing process with NDAs in place is part of telecom expense management engagements; our managed network services page covers what providers typically need to see before quoting.

When it matters for buyers

Questions to ask vendors

  • Will you sign our mutual NDA, or what changes do you need to yours?
  • Does your NDA protect information we share, not only yours?
  • Does confidentiality depend on marking documents, and how are verbal disclosures handled?
  • Which subcontractors or partners will see our information, and are they bound by similar terms?
  • How will you return or destroy our information if we don’t proceed?
  • Will the confidentiality terms in the main contract replace this NDA, and how will earlier disclosures be covered?

How it differs from a data processing agreement

An NDA is about keeping business information secret and limiting its use. A data processing agreement (DPA) governs how a provider processes personal data on the customer’s behalf, often with terms required by privacy laws, such as processing only on instructions, security measures, subprocessors and breach notification. A provider handling personal data will often need both: the NDA or confidentiality clause for business information, and the DPA for personal data.

Frequently Asked Questions

Do we need an NDA before an RFP?
Often, if you will share network diagrams, security details, pricing or business plans. Many buyers sign a mutual NDA with each shortlisted vendor before sharing detailed requirements, and keep general information out of scope so the process can start without one.
What is the difference between a mutual and a one-way NDA?
A one-way NDA protects information disclosed by one party only. A mutual NDA protects information both parties disclose. In vendor evaluations both sides usually share something, so a mutual NDA is common; check that a vendor's form doesn't protect only its own information.
How long do NDA obligations last?
The NDA sets it. Many set a fixed confidentiality period after disclosure or after the agreement ends, and some protect trade secrets for as long as they remain trade secrets. Whether an indefinite obligation is enforceable can depend on the governing law. This is general information, not legal advice; have counsel review the contract.
Does an NDA cover personal data we share with a provider?
An NDA can require confidentiality, but it usually isn't enough on its own for regulated personal or health data. Privacy laws may require specific terms, typically in a data processing agreement or, for US health data, a business associate agreement, once a provider will process that data.
Once we sign the main contract, does the NDA still apply?
It depends on the documents. Many master agreements include their own confidentiality section that replaces the NDA for information shared after signing. Check whether the new contract supersedes the NDA and how information shared before signing is treated.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.