What "Confidential Information" Actually Means
The confidential information definition is the most-litigated clause in any NDA. It determines what you can and cannot share — and more importantly, what happens if you get it wrong. A poorly drafted definition either protects nothing (too narrow) or protects everything including publicly available information (too broad — and often unenforceable).
At its core, confidential information is any non-public information that gives a business competitive advantage and that the Disclosing Party takes reasonable steps to protect. This includes trade secrets, but it also covers a broader category of business-sensitive information that falls short of trade secret status.
The definition typically appears in Section 1 of an NDA and sets the boundaries for the entire agreement. Every other clause — the term, the exclusions, the remedies — operates within the scope established here. If information doesn't fall within the definition, it isn't protected. If the definition is too vague, a court may refuse to enforce it.
Broad vs. Narrow Definitions: The Trade-off
A broad definition ('any and all information disclosed by the Disclosing Party, regardless of form or marking') is great for the Disclosing Party — everything is covered automatically. But it creates two problems. First, the Receiving Party can't easily tell what's confidential and what's not, leading to accidental breaches. Second, courts are skeptical of catch-all definitions and may refuse to enforce them.
A narrow definition ('information marked CONFIDENTIAL in writing and delivered by registered mail or hand delivery only') is precise but impractical. Oral conversations aren't covered. Emails aren't covered unless each one is marked. Information shared in a meeting isn't covered unless followed by written confirmation. This protects the Receiving Party but leaves the Disclosing Party exposed.
The middle ground — and what most well-drafted NDAs use — is a definition that includes: (1) information marked or identified as confidential at the time of disclosure, and (2) information that a reasonable person would understand to be confidential given the circumstances. This captures both formal written disclosures and informal oral ones, without being a catch-all.
💡 Tip: The best definition for most situations: 'Confidential Information means information disclosed by the Disclosing Party that is either (a) marked or identified as confidential at the time of disclosure, or (b) of a nature that a reasonable person would understand to be confidential given the circumstances of disclosure, including but not limited to [list of categories].'
Common Categories of Protected Information
Most NDAs list specific categories to eliminate ambiguity. A well-drafted definition typically includes:
- Trade secrets and know-how — formulas, processes, methods, techniques
- Customer and supplier lists, including contact details and purchasing history
- Financial information — revenue, margins, pricing, projections, cap tables
- Business plans and strategic roadmaps, whether in writing or discussed orally
- Product designs, prototypes, specifications, and source code
- Marketing strategies, campaign performance data, and customer acquisition metrics
- Employee and contractor information, including compensation and performance data
- Third-party confidential information that the Disclosing Party is obligated to protect
- Intellectual property filings before publication — patent applications, trademark filings in progress
- Legal and regulatory matters — pending litigation, regulatory investigations, settlement terms
💡 Tip: If you're the Disclosing Party, list categories that cover your specific business. A software company needs 'source code and algorithms.' A manufacturer needs 'manufacturing processes and quality control data.' Generic categories are better than nothing, but specific ones are harder to dispute.
Marking Requirements: Written vs. Oral Disclosures
Many NDAs require information to be 'marked Confidential' for protection to apply — but this creates a gap for oral disclosures (meetings, calls, presentations). There are three common approaches:
- Strict marking: Only written information marked 'CONFIDENTIAL' is protected. Oral disclosures are not covered unless followed by written confirmation within 30 days. Safest for the Receiving Party; riskiest for the Disclosing Party.
- Reasonable identification: Both marked written information and oral information identified as confidential at the time of disclosure are protected. This is the most common commercial standard.
- No marking required: All information disclosed during the relationship is confidential. This is the broadest approach — and the most dangerous for the Receiving Party. Avoid this unless you have a very good reason.
If you're the Disclosing Party and the NDA requires marking, get in the habit of stamping every slide deck, spreadsheet, and document with 'CONFIDENTIAL.' For meetings, start with a verbal statement: 'Everything we discuss today is confidential under our NDA dated [date].' Follow up with an email summarizing the topics discussed without revealing the confidential details.
What Is NOT Confidential (Standard Exclusions)
Every enforceable NDA must list what is excluded from protection. The standard four exclusions are universal across practically every NDA. If any of these is missing, it's a red flag:
- Information already in the public domain — if it's on Wikipedia, in a newspaper, or in a public filing, it's not confidential, regardless of what the NDA says.
- Information you already possessed before receiving it from the Disclosing Party — you can't be forced to 'un-know' something you already knew.
- Information you receive from a third party who is not under a confidentiality obligation — if an unrelated third party gives you the same information without restriction, you're free to use it.
- Information you independently develop without using or referencing the confidential information — your own R&D team's parallel innovation is yours, even if it overlaps with what the Disclosing Party shared.
💡 Tip: Watch for NDAs that remove or weaken these exclusions. A clause that says 'information in the public domain is excluded only if it entered the public domain through no fault of the Receiving Party' is fine. A clause that says 'all information disclosed is deemed confidential regardless of public availability' is not enforceable and is a sign the Disclosing Party doesn't understand how NDAs work — or worse, they're intentionally overreaching.
Trade Secrets vs. General Confidential Information
Not all confidential information is a trade secret, but all trade secrets are confidential information. The distinction matters because trade secrets get stronger legal protection — including potential criminal penalties for theft under the Defend Trade Secrets Act.
A trade secret requires three things: (1) the information is not generally known to the public, (2) it derives economic value from being secret, and (3) the owner takes reasonable measures to keep it secret. The Coca-Cola formula is a trade secret. Your Q3 revenue projections are confidential information but probably not a trade secret.
Why the distinction matters in an NDA: trade secrets often receive perpetual protection — the obligation to protect them doesn't end when the NDA expires. General confidential information, on the other hand, is typically protected only for the term of the NDA (2-5 years). If your NDA doesn't distinguish between the two, you may end up with perpetual obligations for non-trade-secret information you received — which is unreasonable and potentially unenforceable.
Red Flags in Confidential Information Definitions
Before signing, check the definition for these warning signs:
- 'Any and all information' without categories or marking requirements — too vague to be enforceable, too broad to comply with.
- Missing standard exclusions — if public domain, prior knowledge, third-party, and independent development aren't excluded, push back.
- Oral information automatically covered without any identification requirement — you could breach the NDA by remembering something said offhand at lunch.
- Definition includes information you created before the NDA existed — your pre-existing IP should never be swept into a new NDA's definition.
- Information remains confidential 'indefinitely' or 'in perpetuity' — reasonable for trade secrets, unreasonable for general business information.
The confidential information definition is the foundation of the entire NDA. If it's wrong, nothing else in the agreement works correctly. Use ContractRev's NDA clause checker to analyze this clause specifically — it flags overbroad definitions, missing exclusions, and unreasonable marking requirements in seconds.
Review My NDA Now →