Skip to content

NDA checklist

UK NDA Checklist: 12 Clauses Every Confidentiality Agreement Should Cover

Before you sign or send an NDA, use this UK-specific checklist to confirm the agreement covers the 12 essential clauses: definition of confidential information, permitted purpose, statutory carve-outs, term, remedies, governing law and more.

By Richard Wood, Founder8 min readUpdated 31 August 2026Last reviewed 31 August 2026NDA basicsUK lawenforceabilitytemplates

Not all NDAs are equal. A poorly drafted confidentiality agreement can be unenforceable, can leave gaps a court will not fill, or can include clauses that are void under UK law. Whether you are reviewing an NDA someone else has sent you or adapting a template, this checklist helps you verify that the document covers 12 essential elements before you sign or send.

This is general information, not legal advice

NDASafe is a document preparation service, not a law firm. Our templates are legally reviewed against applicable UK law at the point of release, but every situation is different. Where significant value, unusual risk or a cross-border element is involved, take independent legal advice before you sign.

1. Definition of confidential information

This is the most important clause in the NDA. It defines what the agreement actually protects. A definition can work in three ways: (a) a category approach — “all technical, financial, and commercial information relating to the Disclosing Party’s business”; (b) a marking approach — “information marked CONFIDENTIAL”; or (c) a combination.

Check that the definition captures what you actually need to protect. A definition covering only “written information marked confidential” will not protect a verbal discussion unless the NDA also requires verbal disclosures to be confirmed in writing within a set period. NDASafe templates use a combination approach to close this gap.

2. Standard exclusions

Check that the NDA contains the four standard exclusions, which protect the recipient from being bound to keep secret information they legitimately have or acquire:

  • Information already in the public domain at the date of disclosure (through no fault of the recipient).
  • Information the recipient can show it already knew before the NDA was signed.
  • Information the recipient develops independently, without reference to the confidential information.
  • Information received from a third party who is free to disclose it without restriction.

3. Permitted purpose

The NDA should state why the information is being shared. “For the purpose of evaluating a potential acquisition” or “for the purpose of providing software development services”. A clear purpose clause restricts the recipient from using what they learn for unrelated purposes.

4. Statutory carve-outs (mandatory for employee NDAs)

Any NDA applying to an employee must include the following preserved rights, whether the NDA says so or not. A good NDA states them explicitly:

  • Protected disclosures (whistleblowing): the right to report wrongdoing to a regulator or in the public interest under ERA 1996, as amended by ERA 2025. A clause that purports to prevent this is void.
  • Sexual harassment disclosures: under ERA 2025, an NDA cannot prevent a worker disclosing sexual harassment within the meaning of the Equality Act 2010.
  • Victims of crime: under the Victims and Prisoners Act 2024, an NDA cannot prevent a victim of a criminal offence from disclosing to the police or a prosecutor.
  • Co-operating with regulators: the NDA cannot prevent disclosure to the FCA, HMRC, the ICO, or other regulators in the exercise of their statutory functions.

5. Duration (term)

The NDA should state how long the obligations last. Typical commercial NDA terms are 2 to 5 years. NDAs may provide that obligations continue indefinitely for information qualifying as a trade secret under the Trade Secrets (Enforcement, etc.) Regulations 2018. Courts will generally enforce a reasonable term; an excessively long term for ordinary commercial information with a limited commercial life may be challenged.

6. Governing law and jurisdiction

The NDA should specify English and Welsh law (or Scots law for Scotland-based parties) as the governing law and the courts of England and Wales as the jurisdiction. A US-law governing clause is a red flag in a UK NDA template: it creates uncertainty about which carve-out obligations apply and how a breach would be handled in UK proceedings.

7. Remedies: injunction acknowledgement

A damages award after a breach may be inadequate: once confidential information is disclosed, money does not unring the bell. The NDA should acknowledge that the parties recognise money damages may be an inadequate remedy, and that the innocent party is entitled to seek injunctive relief. An express clause makes any injunction application more straightforward.

8. Permitted sub-disclosure to employees and advisers

The receiving party will inevitably share the information internally. The NDA should expressly permit sub-disclosure to employees, board members, legal advisers and accountants who need to know, on the condition that those sub-recipients are bound by equivalent confidentiality obligations and the receiving party remains liable for their compliance.

9. Return or destruction of materials on termination

Check that the NDA requires the receiving party to return or destroy all confidential materials — including digital copies and extracts — on termination or at the disclosing party’s written request. For digital information, the clause should address materials held in email archives, cloud storage, and backup systems.

10. No licence implied

The NDA should state that sharing confidential information does not grant the recipient any licence, right, or interest in the information or any intellectual property associated with it. Without this clause, a court might infer an implied licence from the fact that the information was shared for a business purpose.

11. No representation as to accuracy

A short clause confirming that the disclosing party makes no representation as to the accuracy or completeness of the confidential information protects the discloser from liability if the recipient relies on the information and it later turns out to be wrong. Particularly important when sharing financial projections, forecasts, or technical specifications in an investment or acquisition context.

12. Proper execution by authorised signatories

An NDA is only as good as the signatures on it. Check that the person signing has authority to bind the organisation. For a company, the Companies Act 2006 requires execution either by two authorised signatories (directors or company secretary), or by a single director whose signature is witnessed. A signature from an employee without authority may not bind the company.

Keep the signed copy. You will need it to demonstrate the existence and terms of the NDA if you ever need to enforce it.

NDASafe templates cover all 12 checklist items by design

Each NDASafe template is drafted to include the definition, exclusions, purpose limit, statutory carve-outs, term, governing law, remedy clause, and execution block appropriate to that NDA type. One-time purchase from £29, editable Word document, 14-day money-back guarantee.

Step by step

  1. 1
    Define confidential information clearly

    The NDA should specify what counts as confidential: named categories (financial data, client lists, source code, designs), information marked confidential, or both. Overly broad definitions can be unenforceable; overly narrow ones leave gaps.

  2. 2
    State the permitted purpose

    The NDA should say why the information is being shared: 'to evaluate a potential commercial collaboration' or 'to provide software development services'. A purpose limit stops the recipient using what they learn for an unrelated purpose.

  3. 3
    Name the parties correctly

    Identify the disclosing party and the receiving party by full legal name. For a company, use the registered company name and number, not just the trading name.

  4. 4
    Check the standard exclusions are present

    Every NDA should exclude: information already in the public domain, information the recipient already knew, information independently developed by the recipient, and information received from a third party without restriction.

  5. 5
    Include the mandatory statutory carve-outs (employee NDAs)

    For any NDA signed by an employee, check that it explicitly preserves the right to make a protected disclosure under ERA 1996/ERA 2025, to disclose sexual harassment under the Equality Act 2010 (ERA 2025), and to report a crime to the police or a regulator.

  6. 6
    Check the duration is reasonable

    A reasonable NDA term for commercial information is 2 to 5 years. Perpetual NDAs are enforceable for genuine trade secrets, but can be challenged for ordinary commercial information with a limited commercial life.

  7. 7
    Confirm the remedy clause

    The NDA should acknowledge that damages may not be an adequate remedy for breach, and that the innocent party is entitled to seek an injunction. This makes injunctive relief applications easier in practice.

  8. 8
    Check governing law and jurisdiction

    The NDA should specify English and Welsh law (or Scots law if both parties are in Scotland) as the governing law, and the courts of England and Wales as the jurisdiction. A US-law governing clause in a UK NDA creates enforcement uncertainty.

  9. 9
    Check permitted sub-disclosure

    The NDA should say whether the recipient can share the information with their employees, contractors, or advisers, and if so, on what terms. Without this, the recipient may technically breach the NDA every time they brief a colleague.

  10. 10
    Confirm return or destruction of materials

    On termination or at the disclosing party's request, the recipient should be required to return or destroy all confidential materials including digital copies held in email archives and backup systems.

  11. 11
    Check for a no-licence implied clause

    The NDA should state that sharing confidential information does not grant the recipient any licence, right, or interest in the information or any associated intellectual property.

  12. 12
    Verify the signature block covers all parties with authority

    Both parties must sign. For a company, execution must be by an authorised person in accordance with the Companies Act 2006. Check that the signatory has authority to bind the organisation.

Frequently asked questions

How many clauses should an NDA have?

There is no fixed number, but a properly drafted UK NDA typically runs to 8–14 clauses. Very short NDAs often miss critical provisions; very long ones can be over-engineered for routine use. NDASafe templates are calibrated for the specific use case: the mutual NDA runs to 11 core clauses; the employee NDA adds the statutory carve-outs required by UK law.

What makes an NDA unenforceable in the UK?

Common reasons include: the definition of confidential information is so broad it covers public information; there are no standard exclusions; the duration is unreasonably long; the NDA tries to prevent an employee making a protected disclosure (void by statute); or one party signed without authority to bind the organisation.

Does an NDA need to be witnessed or notarised in the UK?

No. Notarisation is not required for a standard NDA contract under English law. Witnessing is required if the document is executed as a deed. Most commercial NDAs are simple contracts, not deeds, and require only the signatures of authorised parties. NDASafe templates are simple contracts.

Can I use the same checklist for a mutual NDA and a one-way NDA?

Most items apply to both. The key difference is that a mutual NDA must reflect both parties as disclosing and receiving (symmetric obligations), whereas a one-way NDA has an asymmetric structure. The statutory employee carve-outs apply only where one party is an individual employee.

Templates mentioned in this guide