Financial services guide

NDA for Financial Services UK: Protecting Confidential Information in FCA-Regulated Businesses

How UK financial services firms — banks, wealth managers, fintech companies, financial advisers and insurance firms — use NDAs to protect proprietary strategies, client data, regulatory intelligence, and technology partnerships.

By Richard Wood, Founder8 min readUpdated 11 June 2026Last reviewed 11 June 2026financial servicesUK lawNDA basicstemplates

Financial services firms deal in commercially sensitive information as a matter of course: trading strategies, client portfolios, proprietary models, regulatory intelligence, and financial technology that took years and significant capital to build. NDAs play a specific role in this sector — supplementing the implied regulatory and common-law duties that already apply to FCA-regulated firms, and providing a clear contractual framework for commercial partnerships where those duties do not naturally extend.

This is general information, not legal advice

NDASafe is a document preparation service, not a law firm. Our templates are legally reviewed against applicable UK law at the point of release, but every situation is different. Where significant value, unusual risk or a cross-border element is involved, take independent legal advice before you sign.

The existing confidentiality framework in financial services

Before an NDA is signed, several confidentiality obligations may already exist. UK banks and authorised deposit-takers owe a common-law duty of confidence to their customers (Tournier v National Provincial and Union Bank of England [1924] 1 KB 461). FCA-regulated firms are subject to data-handling requirements under SYSC, client confidentiality obligations under COBS, and data protection obligations under the Data Protection Act 2018 and UK GDPR.

An NDA operates alongside these obligations, not as a substitute. In a commercial relationship between two financial services firms — or between a financial firm and a technology supplier — an NDA provides a clear contractual definition of what is confidential, an agreed permitted purpose, a contractual remedy (injunction, damages) if the obligation is breached, and a duration that outlasts the underlying commercial relationship.

Common financial services NDA scenarios

ScenarioInformation sharedNDA type
Fintech partnership or API integrationProprietary technology, API architecture, client insight, commercial termsMutual NDA — both parties disclose
Bank technology vendor assessmentBank's technical architecture, security requirements, operational dataOne-Way NDA (bank as disclosing party) or Mutual if vendor also discloses technology
Wealth manager engaging an external consultantClient segmentation data, investment philosophy, fee modelsOne-Way NDA (wealth manager as disclosing party) or Freelancer NDA
Financial services M&ARegulatory permissions, client book, P&L, capital structureMutual NDA — both sides disclose in deal process
Insurance firm and data analytics providerActuarial models, claims data, pricing algorithmsOne-Way or Mutual depending on information flow
Asset manager and distribution partnerProprietary fund strategies, performance data, investor profilesMutual NDA

Fintech partnerships: the mutual NDA standard

Open banking, embedded finance, and payments partnerships are the most common NDA context in UK financial services today. When a bank or e-money institution engages a fintech to provide technology, data analytics, or a customer-facing product, both parties share commercially sensitive information from the outset: the fintech's proprietary code and methodology; the bank's client architecture, API specifications, and regulatory strategy.

The FCA's third-party risk management requirements (SYSC 8 and its operational resilience policy) require regulated firms to maintain appropriate governance over their technology suppliers. An NDA is part of that governance framework — but the regulated firm will also need a formal supplier due-diligence process and, for critical infrastructure relationships, compliance with applicable regulatory guidance.

The NDASafe Mutual NDA is appropriate for most fintech partnership conversations. Where the fintech is also building bespoke software under contract, the Freelancer NDA — which includes IP assignment provisions — provides a cleaner foundation, because it handles ownership of deliverables that a standard NDA leaves open.

FCA and third-party oversight

The FCA and PRA have powers under FSMA 2000 to designate 'critical third parties' — technology or service providers systemic to UK financial services — and subject them to direct oversight. If your supplier relationship involves a designated provider, your NDA exists within a broader regulatory governance framework. Seek independent legal advice on how the regulatory regime interacts with your commercial confidentiality arrangements.

Trading strategies and proprietary models

A proprietary trading strategy — whether a quantitative model, a systematic approach, or a discretionary methodology — represents years of research, testing and refinement. The NDA definition of confidential information must explicitly include:

  • Quantitative models and algorithms — the logic, parameters and source code of any systematic strategy.
  • Backtesting and performance data — historical performance records that reveal how the strategy works.
  • Risk management frameworks — position limits, drawdown controls, and exposure rules specific to the strategy.
  • Research reports and analytical outputs — pre-publication research that informs the strategy.
  • Technology architecture — the execution infrastructure, data feeds and latency optimisation that underpin performance.

Duration matters more here than in most commercial NDAs. The commercial life of a successful proprietary model may be a decade or more. Trade-secret survival provisions — protecting the strategy for as long as it remains secret — are more appropriate than a fixed two-year general term.

Financial services M&A

Acquisitions of FCA-regulated businesses carry additional confidentiality sensitivity. The target's FCA permission set — the breadth of regulated activities it can conduct — is commercially valuable and may not be publicly announced until the deal is closed. Senior manager profiles under the SM&CR, client book composition, and any ongoing FCA supervisory engagement are similarly sensitive.

An M&A NDA for a financial services deal should expressly cover FCA and PRA permissions and correspondence, SM&CR senior manager profiles, client book composition and AUM breakdown, regulatory capital position, and ongoing supervisory matters.

The standard guidance from the M&A NDA guide applies in full — mutual NDA, non-solicitation, non-circumvention, process existence as confidential — with additional categories of information specific to the regulated context.

Employees in financial services

Financial services employees — particularly relationship managers, fund managers, proprietary traders, and compliance officers — have access to commercially sensitive and legally protected information as a core part of their role. An employee NDA for financial services should cover: client lists and AUM data, trading strategies, risk models, compliance intelligence, and regulatory submissions.

Non-compete and non-solicitation clauses are standard in financial services employment, though they face the same reasonableness test as in other sectors (Tillman v Egon Zehnder [2019] UKSC 32). FCA-regulated individuals who are approved persons or senior managers should be aware that certain post-employment obligations may be imposed by the regulatory regime independently of any contractual restriction.

FCA regulatory disclosure cannot be blocked by an NDA

Any NDA used by or with an FCA-regulated firm must include an express carve-out permitting disclosure to the FCA, PRA, Financial Ombudsman, FSCS, and any other competent regulatory authority as required by law or regulation. A clause that purports to prevent a regulated firm from making required regulatory disclosures is void and potentially in breach of FCA Principle 11 (relations with regulators).

Financial services NDA templates for UK regulated firms

NDASafe Mutual, One-Way, Freelancer and Employee NDA templates include the standard regulatory and whistleblowing carve-outs required for FCA-regulated contexts. £29 each or £79 for all eight — editable Word documents, delivered instantly.

Frequently asked questions

Do banks in the UK have a duty of confidentiality?

Yes. Separate from any NDA, banks owe a duty of confidentiality to their customers at common law, established in Tournier v National Provincial and Union Bank of England [1924] 1 KB 461. That duty covers information acquired in the course of the banking relationship. An NDA supplements that implied duty in a commercial context — such as a fintech partnership, an acquisition discussion, or a technology vendor assessment — providing a clear contractual framework and defined remedies.

Does a financial services NDA need to comply with FCA rules?

FCA-regulated firms are subject to data governance, third-party risk management, and operational resilience requirements under the FCA Handbook (SYSC 8, SYSC 13). An NDA is part of a regulated firm's third-party risk framework — not a substitute for it. Importantly, any NDA used by or with an FCA-regulated firm must include an express carve-out for regulatory reporting: a clause that prevents disclosure to the FCA or PRA when required would be contrary to regulatory obligations and void.

What NDA do I need for a fintech partnership?

A mutual NDA is appropriate for most fintech partnerships because both parties typically share confidential information — the fintech shares its technology and business model; the bank or financial institution shares its API architecture, customer insight and regulatory strategy. Where the fintech is also building bespoke software, a Freelancer NDA with IP assignment provisions may be more appropriate, as it handles the ownership question that a standard NDA leaves open.

Can an NDA protect a trading strategy or investment algorithm?

Yes. A proprietary trading strategy, quantitative model, or investment algorithm qualifies as confidential information. The definition in the agreement should expressly name trading strategies, quantitative models, backtesting data and performance metrics as protected categories. For genuinely proprietary core IP, trade-secret survival provisions — protecting the strategy indefinitely — are more appropriate than a fixed two or three-year term.

Do financial advisers need NDAs?

Financial advisers and wealth managers who share proprietary financial planning methodologies, fee structures, client segmentation approaches, or technology with a third party should use an NDA to protect that information. The FCA's conduct rules under COBS apply to client-facing relationships; the NDA applies to B2B commercial relationships. Both may be relevant simultaneously.

Templates mentioned in this guide