A Seattle founder is preparing to share a product roadmap, pricing model, and technical architecture with a potential strategic partner. Someone downloads a free NDA, changes the names, and sends it for signature. Months later, the partnership collapses, a former contractor joins a competitor, and the founder discovers that the agreement never clearly identified the information at issue, never addressed permitted uses, and offered no practical answer for data entered into an AI tool.
That scenario is common because an NDA often looks complete long before it becomes useful. A court won't evaluate whether the document felt reasonable during a business meeting. It will examine the parties, the language, the disclosures, the restrictions, the evidence, and the legal limits that apply when enforcement matters.
Why a Borrowed NDA Template Is a Litigation Risk
The founder in that scenario didn't make an irrational choice. A template seemed efficient, the prospective partner wanted a quick signature, and nobody expected a dispute. The problem emerged later, when the partner argued that the roadmap was merely general business information, the pricing discussion had been independently developed, and the contractor's later work reflected general industry knowledge rather than protected material.
A borrowed form often uses phrases such as "all proprietary information" or "any business information disclosed." Those phrases sound protective, but they may leave a judge asking what information was confidential, how it was identified, and whether the recipient had notice of the restriction. A document that treats every conversation as secret can also look overreaching, particularly when it doesn't distinguish trade secrets from ordinary business material.

The clauses that quietly transfer risk
A template creates litigation risk when it leaves important questions unanswered:
- Scope: Does the agreement identify product designs, source code, customer data, pricing, or only use a vague catchall?
- Purpose: Can the recipient use the information only to evaluate a partnership, or can it use the information for internal planning?
- Exceptions: What happens when information is already public, independently developed, lawfully received from another source, or required by law?
- Duration: Does the obligation expire before the information loses its commercial value?
- Evidence: Does the business label documents, maintain access records, or follow the agreement's designation process?
An NDA is an ordinary contract, but enforcement can fail when statutory rules or public policy intervene. The Cornell Legal Information Institute's explanation of NDAs) reflects that baseline. A signed document isn't a substitute for a defensible scope and disciplined handling practices.
Practical rule: Every important category of confidential information should be identifiable before a dispute begins, not reconstructed after a former partner has taken it.
A founder comparing an NDA with an investment document should also keep the documents separate. An investment agreement template addresses a different transaction and shouldn't be used as a shortcut for confidentiality analysis. The right question isn't whether a form looks professional. It's whether the form explains what was protected, why it was shared, and what the recipient could lawfully do with it.
Choosing Between a Unilateral and a Mutual NDA
The structure should follow the actual flow of information. A unilateral NDA protects disclosures moving primarily from one party to the other. A mutual NDA creates confidentiality obligations in both directions, so each party can be a discloser and a recipient.
A startup pitching a venture fund may need to protect a detailed product architecture while sharing little, if anything, from the fund. A one-way form can fit that discussion, although many investors won't sign broad NDAs for initial pitches. Two companies exploring a co-marketing partnership present a different problem. Each may disclose customer information, launch plans, pricing assumptions, and technical details, making mutual protection more logical.
An employment or contractor relationship requires closer attention. A company may disclose trade secrets, while the worker may also provide pre-existing tools, methods, or personal information that shouldn't become the company's confidential property. A mutual form can protect both sides, but it must still separate confidentiality from ownership and future work restrictions.
| Feature | Unilateral NDA | Mutual NDA |
|---|---|---|
| Protected disclosures | Information disclosed by one identified party | Information disclosed by either party |
| Permitted use | Recipient uses information for the stated business purpose | Each party uses the other's information only for the stated purpose |
| Breach analysis | Focuses on recipient's handling of the discloser's information | Requires analysis of each party's disclosures, duties, and defenses |
| Representatives | Recipient may share with approved personnel under defined conditions | Each party may share with its representatives under matching conditions |
| Residual information | May affect the recipient's future use of retained knowledge | Can create reciprocal, but still potentially broad, future-use rights |
Why the wrong format creates exposure
A one-way NDA used in a two-way deal can leave the second party's disclosures outside the defined protection. A mutual NDA used without careful limits can impose obligations on both sides that nobody intended, especially if the document treats every exchanged communication as confidential.
Residual knowledge clauses deserve particular caution. They may allow a recipient to use information remembered without written notes, but an expansive version can swallow the non-use obligation. If a software company shares an algorithm and the recipient later claims that the algorithm was merely “retained knowledge,” the clause may become the center of the dispute.
A useful explanation of the basic distinction appears in this guide to mutual NDAs. The document should state who discloses, who receives, what purpose controls, and which representatives may access the material. Those details matter more than the label on the first page.
Drafting the Core Clauses With Sample Language
A workable NDA should be drafted in a sequence that exposes gaps early. GOV.UK guidance distinguishes a one-way NDA, used when only one party discloses information, from a mutual NDA, used when both parties do. Its practical NDA guidance also supports narrowing the agreement to the actual disclosure.
Start with a usable definition
The definition should identify categories and connect them to the transaction. A practical formulation might read:
“Confidential Information means non-public technical, commercial, financial, and business information disclosed by or on behalf of Discloser to Recipient in connection with evaluating the proposed partnership, including the materials identified in Exhibit A.”
An exhibit can list a roadmap, architecture diagrams, pricing analysis, customer research, and test results. The definition can cover oral information, but the agreement should explain how oral disclosures will be confirmed or identified afterward.
Limit use and state exclusions
The recipient should have a clear permission, not merely a prohibition:
“Recipient may use Confidential Information solely to evaluate and negotiate the proposed partnership and for no other purpose.”
The exclusions should include information that is publicly available without breach, already lawfully known, independently developed without use of the confidential material, or lawfully received from a third party. A compelled-disclosure provision should require prompt notice where legally permitted and disclosure of only the required portion.
Set duration, return obligations, and remedies
A basic term provision might say:
“The confidentiality obligations apply to disclosures made during the Evaluation Period and continue for the period stated in Section __, except that trade-secret obligations continue while the information qualifies for trade-secret protection under applicable law.”
Return and destruction language should address practical limits:
“Upon written request or termination of discussions, Recipient will return or destroy Confidential Information, except for archival copies retained under routine backup procedures, which remain subject to this Agreement.”
Remedies language should avoid promising automatic relief. It can acknowledge that unauthorized use may cause harm and permit the discloser to seek available equitable relief, damages, and other remedies allowed by law. The document should also address representatives, security measures, notice of unauthorized access, governing law, venue, and authority to sign.
A state-focused review can expose issues a generic form misses. For example, 2026 Texas NDA tips offers another jurisdiction-specific perspective, but Washington companies shouldn't import Texas provisions without reviewing governing law and local limits.
Setting Scope, Duration, and Survival the Right Way
Duration decisions should reflect the commercial lifecycle of the information being protected. A 2024 contract benchmark found that 74% of NDAs used a fixed confidentiality term and 26% were unlimited, with two years appearing in 56% of NDAs. Those figures show market practice, not a legal default. A common term can still fail for a product roadmap, formula, customer dataset, or security design. The 2024 contract benchmark provides that comparison.
Match the term to the information
A short-lived marketing plan may need less protection than source code or a manufacturing process. Define the scope narrowly enough to remain credible, while covering the information that creates competitive value. A definition that captures every fact exchanged can weaken the agreement in a dispute because it does not distinguish sensitive material from routine discussion.
Draft the scope around the information's expected usefulness and the way the recipient will handle it. If employees, contractors, or approved tools may access the material, the agreement should make those paths clear. Vague coverage creates room for arguments over whether a particular file, conversation, prompt, or derived record fell within the NDA.
Don't let the agreement defeat its own protections
A company can lose practical protection by ignoring its own designation procedure. If the NDA requires confidential documents to be marked and the company never marks them, the recipient may argue that the contractual condition was not satisfied. Courts have treated failures to follow confidentiality-designation or handling requirements as barriers to later trade-secret remedies. Holland & Knight's discussion of NDA and trade-secret issues addresses that risk.
Drafting position: Use a fixed period for ordinary confidential information when the business can justify it. For information that qualifies as a trade secret, preserve the protection while it remains secret and valuable under applicable law. This trade-secret duration guide explains why a fixed contractual period should not automatically end that protection.
The survival language must also fit the agreement's operational duties. Coordinate it with return and destruction obligations, backup exceptions, legal-retention requirements, and evidence preservation. If confidentiality ends while destruction duties continue, the provisions may conflict. Give each obligation a defined endpoint or a clear reason for continuing.
Writing AI and Generative Tool Provisions Into the NDA
A standard NDA often assumes that confidential information moves between people, email accounts, and controlled systems. That assumption no longer covers a company using ChatGPT, Microsoft Copilot, Claude, an internal large language model, or an AI coding assistant. The agreement should address whether a recipient can submit protected material to a generative tool, whether the provider may retain or use it, and whether the output contains or reconstructs the original information.
An AI clause should be specific enough for a security team to implement. It shouldn't merely say that the recipient must “use reasonable security,” because that phrase doesn't answer whether an employee can paste source code into an unapproved prompt window.
Cover the full AI data path
A practical provision can address four stages:
- Input restriction: “Recipient will not submit Confidential Information to a generative AI system or other machine-learning tool unless Discloser has approved that tool in writing.”
- Training restriction: “Recipient will not use Confidential Information to train, fine-tune, evaluate, or improve a model, whether directly or through a service provider.”
- Derived data: “Recipient will treat prompts, outputs, logs, embeddings, vector representations, model weights, and related records that contain or reflect Confidential Information as Confidential Information.”
- Incident notice: “Recipient will promptly notify Discloser after discovering unauthorized submission, retention, disclosure, or access involving Confidential Information in an AI system.”
The clause should also require deletion or isolation of prompts and logs where the approved tool supports those controls. If a vendor's terms permit retention or model improvement, the recipient should either obtain a contractual restriction or prohibit the tool entirely for protected data.
Address privacy and oversight
AI restrictions also intersect with data protection. Personal information, customer records, employee data, and regulated material may create obligations that an NDA cannot waive. A recent trade-secret analysis recommends explicit training prohibitions, approved-tool controls, audit rights, and breach-notification triggers, while trade-secret commentary also warns that AI use must comply with rules such as GDPR. This AI risk assessment template for U.S. businesses can help identify operational questions that belong beside the NDA review.
The agreement should identify who may approve a tool, how approval is documented, and whether the recipient must provide evidence of compliance. A company that bans AI in the contract but allows unrestricted use in practice may create a credibility problem during enforcement.
Enforceability, Public Policy, and Washington-Specific Limits
An NDA generally operates as a contract, but a court can refuse to enforce a clause when a statute or public policy controls. The document must protect legitimate confidential information without functioning as a disguised non-compete, a ban on lawful reporting, or an assignment of rights unrelated to secrecy.
The federal trade-secret arena makes careful drafting more important. The Defend Trade Secrets Act became law on May 11, 2016, creating a federal civil cause of action for trade-secret misappropriation. Researchers identified 486 federal cases involving a DTSA claim between May 11, 2016 and May 10, 2017, showing how quickly confidentiality drafting became connected to federal litigation practice. The Senate Judiciary Committee report on the DTSA is the source for that milestone and case count.
Update the whistleblower notice
Post-2016 agreements often need a notice describing immunity for certain confidential disclosures to government officials or attorneys for reporting or investigating suspected legal violations. Omitting the notice can affect the employer's ability to recover some forms of relief under the DTSA. The provision shouldn't claim that a worker has waived whistleblower rights, because that kind of waiver creates a direct public-policy problem.
Trade-secret litigation has also become costlier to ignore. Federal filings reached an all-time high in 2025, with more than 1,500 cases and roughly a 20% year-over-year increase. The first half of 2025 also saw more than $485 million in damages awarded. CRA International's trade-secret litigation watch reports those figures.
Washington review points
Washington businesses should examine whether a confidentiality restriction limits ordinary employment mobility. A clause that prevents a worker from serving customers, working in an industry, or using general skills may be treated as a non-compete in substance, even if the document calls it an NDA. Washington-specific rules and public policy can affect non-compete provisions, employee movement, non-solicitation language, and the remedies available to an employer.
Red flags include:
- Undefined secrecy: The agreement covers all information without categories, examples, or a workable designation process.
- Hidden restraint: The non-use clause prevents lawful work rather than misuse of confidential information.
- Rights waiver: The document restricts whistleblower reporting or legally protected communications.
- No consideration: The recipient receives no clear contractual benefit or agreed exchange where one is required.
- Impossible compliance: The agreement requires deletion of systems or backups the recipient cannot control.
For Washington companies evaluating the consequences of a threatened breach, business litigation guidance can provide useful context. The NDA should be reviewed alongside employment, privacy, trade-secret, and dispute-resolution provisions, not in isolation.
Negotiation Checklist, Red Flags, and When to Engage Counsel
Negotiation should separate terms that improve clarity from terms that change the business relationship. A limited definition, a purpose tied to the transaction, reasonable survival, and reciprocal duties are usually easier to defend than a document that attempts to control every future use of knowledge.
A residual knowledge clause deserves a narrow definition. It may address unaided memory, but it shouldn't authorize use of source code, customer lists, pricing files, or identifiable trade-secret material. Non-solicitation language also needs a specific business rationale and should not become a broad restriction on employment or customer choice.
Green lights and red flags
Green lights include:
- Defined scope: The agreement identifies the information and its business context.
- Purpose limitation: The recipient can use the information only for the stated transaction.
- Operational controls: The document explains representatives, security, AI tools, return, and destruction.
- Balanced remedies: The parties preserve available relief without promising automatic injunctions.
Red flags include:
- Perpetual non-compete language: The NDA prevents future work rather than protecting secrets.
- Overbroad residual knowledge: The recipient receives an unrestricted license to remembered information.
- One-sided non-solicit: The clause reaches employees, customers, or relationships unrelated to the disclosure.
- Blanket improvement assignment: The NDA claims ownership of everything created during the relationship.
- Whistleblower waiver: The document attempts to silence protected reporting.
Outside counsel becomes particularly valuable when the disclosure involves source code, regulated data, trade secrets with long commercial lives, generative AI, contractors, employment mobility, or cross-border data flows. A lawyer should also review the document when the other party insists on unfamiliar governing law, arbitration, unusual fee shifting, or an aggressive remedies clause.
A founder can start with a template, but a template should be treated as a drafting aid, not as evidence that the NDA fits Washington law or the transaction. Before signing, the business should identify the assets being shared, document the disclosure process, and have counsel test the agreement against the dispute that would cause the greatest harm.
By Design Law Firm & Legal Consultancy, PLLC offers NDA drafting and review for startups and growing companies, including trade-secret, AI-use, privacy, and Washington enforceability issues. Businesses can visit By Design Law Firm & Legal Consultancy, PLLC to discuss a practical confidentiality agreement before sensitive information is shared.




