← Back to AI Legal Lab
Insight
Contract Review

NDA review basics

Hello, this is Legal Agent.

An NDA gets signed quickly and treated as a light formality before real negotiations begin, which is precisely why it deserves more attention than it usually gets: information shared before any deal is even decided cannot be un-shared once it is out, no matter what the contract later says about remedies.

One-way or mutual, and what actually counts as confidential

A one-way NDA fits a startup disclosing technical material to a larger counterparty, or an M&A seller sharing financials with a prospective buyer; a mutual NDA fits joint development or reciprocal due diligence, where both sides disclose. Review should start by confirming which structure the deal actually needs and which side is disclosing more sensitive information. An oral explanation, something seen during a site visit, or even the existence of the discussion itself can all fall inside "confidential information" depending on how the definition is drafted, while information already public, already held, or properly received from a third party is normally carved out.

Setting the definition and its exceptions

A receiving party should check that the definition is not so broad that it captures ordinary business conversation; a disclosing party should check that the carve-outs are not so wide that protection is effectively hollowed out. Purpose language narrows or widens what the recipient may actually do with the information: "for evaluating the transaction" reads differently from "for evaluating and implementing the transaction." It should match how long the NDA actually needs to stay useful, not just the negotiation period.

Disclosure, return and remedies

Who the information may be shared with (officers and employees, affiliates, outside counsel, investors) needs to match how the deal is actually being run; M&A and fundraising in particular often require sharing with an investment committee or outside advisers that a narrowly drafted NDA does not anticipate. Return-or-destroy obligations should account for the reality that complete deletion across email, backups and cloud storage is not always achievable, and a carve-out for records a company must retain for legal or audit purposes is common. Because a damages claim rarely undoes a leak, a disclosing party typically wants an injunction available as well, while a receiving party should check that the damages language is not phrased as covering "any and all loss." The confidentiality survival period, separately from the term of the NDA itself, commonly runs three to five years after termination.

Where the risk actually sits

A disclosing party's risk concentrates in a definition that is too narrow, or protection that is too weak once a leak happens; a receiving party's risk concentrates in a definition too broad to operate day to day, or return obligations too strict to actually meet. In a mutual NDA, both risks can coexist, since the two sides are often disclosing different kinds of information under the same clause, so language that looks even-handed is not always even-handed in effect.

Keywords
NDA & confidentiality
Browse all keywords

Related articles

Articles connected to this topic.

Insight / 2026.07.23 Game Payments and Gacha: Reviewing Japan's Payment Services Act and Premiums Rules Together Insight / 2026.07.22 Entertainment and Creator Contracts Should Define Ownership and Secondary Uses First Insight / 2026.07.20 Drone Businesses Should Design Aviation-Law Compliance and Field Operations Together
View AI Legal Lab articles