What a workable NDA looks like
An NDA should define what is confidential, why it may be used, who may receive it, how long duties last, and what happens when disclosure is required or the relationship ends. A red flag for the discloser may be a necessary protection for the recipient, so review every clause from both positions.
Confidentiality agreements are often signed before the commercial relationship is fully defined. That makes them easy to treat as routine and easy to get wrong.
The discloser wants useful information protected. The recipient needs a workable boundary that does not capture what it already knew, developed independently, received lawfully or must disclose.
NDA red-flags table: both sides
| Clause | Discloser concern | Recipient concern |
|---|---|---|
| Definition | important oral, technical or business information falls outside scope | everything connected to the relationship is confidential, even if public or trivial |
| Purpose | use is broad enough to enable competition or product development | purpose is too narrow for diligence, testing, advisers or implementation |
| Recipients | affiliates, contractors or AI providers receive data without equivalent controls | the recipient cannot share with staff, advisers or suppliers needed for the evaluation |
| Term | protection ends before the information loses sensitivity | every category is protected indefinitely, regardless of its nature |
| Remedies | the agreement offers no practical response to misuse | automatic penalties, indemnities or injunction language is disproportionate or one-sided |
1. The definition is too broad or too narrow
A definition limited to documents marked “confidential” may miss demonstrations, conversations, access credentials and observations. A definition covering all information “related to” a party may be impossible to administer.
Check whether the agreement distinguishes trade secrets, other confidential information and information that needs a marking or later confirmation.
2. The exclusions do not work in practice
Common exclusions cover information already known, independently developed, lawfully received from another source or publicly available without breach. Red flags include impossible proof standards, no allowance for partial knowledge, and exclusions that can be used only with records the recipient could not reasonably have kept.
3. “Permitted use” hides a non-compete
A restriction on using information for anything beyond the stated purpose is normal. It becomes risky when the purpose or related restrictions prevent lawful independent work, hiring, investment, customer relationships or product development unrelated to the disclosed information.
4. Residuals and memory clauses rewrite the protection
A residuals clause may let personnel use information retained in unaided memory. For a discloser, that can hollow out confidentiality around product, pricing or strategy. For a recipient, deleting the clause may create concern that ordinary skills and experience are restricted. Define the boundary instead of treating “residuals” as boilerplate.
5. Compelled disclosure arrives without a process
The NDA should address disclosure required by law, court or authority: notice where legally permitted, cooperation, disclosure limited to what is required, and efforts to preserve confidential treatment. Absolute advance-notice duties can be impossible where the law prohibits notice.
6. Return and deletion promises exceed system reality
Check backups, security logs, legal holds, email archives, disaster recovery, regulator duties and systems managed by subprocessors. A workable clause can preserve limited inaccessible copies subject to continuing confidentiality instead of promising technically impossible deletion.
7. AI use is silent
If confidential information may be entered into an AI service, identify the provider, access model, retention, logging, training or secondary use, location, subprocessors and deletion controls. “We use an enterprise plan” is not a substitute for the relevant contract and configuration.
8. Ownership or licence language goes beyond confidentiality
An NDA normally protects information; it should not quietly assign IP, grant a production licence, transfer feedback rights or authorise broad derivative use unless the parties intentionally negotiated that outcome.
9. The term treats every secret the same
Commercial information can lose sensitivity while source code, algorithms or manufacturing know-how may remain valuable for much longer. Review the disclosure period and the confidentiality period separately and consider whether trade secrets need different treatment.
10. Governing law and remedies surprise one side
Check law, forum, interim relief, damages, indemnities, contractual penalties and cost recovery. Do not assume a clause guarantees a remedy or will be applied exactly as written in every jurisdiction.
Primary sources checked
- Directive (EU) 2016/943 on trade secrets — Official Journal 15 June 2016; checked 31 July 2026; locator: Articles 2–5.
- Portuguese Industrial Property Code, trade-secret protection — consolidated page checked 31 July 2026; locator: Articles 313–315.
- Portuguese Civil Code — consolidated page last amended 23 June 2026; checked 31 July 2026; locator: Article 405 on contractual freedom.
Review the actual NDA, not only the checklist. See what needs attention in Contract Review and prepare the issues that may require a lawyer.
This guide is for general information only and is not legal advice. It was prepared by Outlex using public legal sources and product context. For advice on your specific situation, speak with a qualified lawyer.


