1. Overly Broad Confidential Information Definition
The confidentiality definition determines what you're prohibited from sharing. Some NDAs define confidential information so broadly that essentially everything the other party tells you — including information already publicly available — is covered. Before signing, use our NDA risk analysis to check if your agreement has reasonable scope. Look for carve-outs that exclude information you already know, information that's publicly available through no fault of yours, and information you independently develop.
💡 Tip: A fair NDA should explicitly exclude: (a) information already in the public domain, (b) information you already possessed before receiving it, (c) information you receive from a third party without restriction, and (d) information you independently develop.
2. Perpetual Confidentiality Obligations
Some NDAs state that confidentiality obligations last forever. In practice, this is rarely enforceable, but it creates unnecessary risk and legal ambiguity. Most standard NDAs set a reasonable term — typically 2-5 years. For trade secrets specifically, perpetual protection is standard and acceptable.
3. One-Sided Obligations
A mutual NDA protects both parties' confidential information equally. A one-sided NDA only protects the disclosing party. If both parties are sharing sensitive information (which is common in partnerships, joint ventures, and M&A discussions), insist on a mutual NDA. Red flag: the NDA defines 'Disclosing Party' and 'Receiving Party' in a way that only goes one direction.
4. Residuals Clause
Watch for a 'residuals clause' that allows the receiving party to use information retained in the unaided memory of its employees. While this sounds innocuous, it can effectively gut the NDA's protections — especially for software companies, where general knowledge gained from a demo could be used to build a competing product.
5. Hidden Non-Compete Clauses
Some NDAs sneak in non-compete or non-solicitation restrictions alongside confidentiality obligations. If the NDA prevents you from competing with the other party or soliciting their employees/customers for a period of time, that goes far beyond confidentiality and needs separate consideration. Flag any restriction that affects your ability to do business beyond simply keeping information secret.
6. Unreasonable Return or Destruction Requirements
Most NDAs require you to return or destroy confidential information upon request or when the relationship ends. This is reasonable. However, some require you to certify in writing under penalty of perjury that you've destroyed everything — including automated backups and archived emails. If you can't realistically comply, negotiate for 'commercially reasonable efforts' instead of an absolute obligation.
7. Excessive Liquidated Damages
Some NDAs specify a dollar amount per breach. A liquidated damages clause of thousands of dollars per violation is a red flag. Damages for NDA breaches should be based on actual harm, not a punitive preset amount. If you see liquidated damages, ask to remove them or cap them at a reasonable level.
8. Unfavorable Governing Law and Venue
If the NDA specifies a governing law in a jurisdiction far from where you live or do business, disputes become significantly more expensive. A California startup shouldn't agree to New York governing law without a good reason. Try to negotiate for your home state or a neutral jurisdiction.
What a Fair NDA Looks Like
A fair NDA is mutual, has a reasonable term (2-5 years for non-trade-secret information), includes standard carve-outs (public domain, prior knowledge, independent development, third-party disclosure), and doesn't include hidden non-competes or unreasonable return obligations. Before signing any NDA, run it through ContractRev to flag problematic language in seconds.
Review My NDA Now →NDA red flags are just one piece of the puzzle. For a broader view of what can go wrong in any contract — from service agreements to leases — see our guide to common contract mistakes to avoid.