Non-Disclosure Agreements in the IT Sector

Share
Non-Disclosure Agreements in the IT Sector

By: Tijana Žunić Marić, Partner | Updated by: Sofija Udicki, Attorney | Updated: May 2026 | Next review: November 2026

Signing a Non-Disclosure Agreement — commonly known by the abbreviations NDA (Non-Disclosure Agreement) or CDA (Confidential Disclosure Agreement) — is a step that should come before concluding a legal transaction, such as a business cooperation agreement or a software development agreement, and even before negotiations between the parties begin. The purpose of this agreement is to protect what is most valuable in your business, and because it can be the difference between your company's success and failure, its importance can hardly be overstated.

So how is it possible that, in practice, this agreement gets so little attention?

Many serious negotiations in the IT industry are often accompanied by a generic NDA “downloaded” from the internet with no professional customization, or one drafted under the laws of a different country (for example, by a U.S. attorney) even though it is meant to apply in Serbia.

It is also common to see a specific NDA template that was originally drafted for a different project or a different set of contracting parties, later reused for a transaction it was never designed for.

Such practices often mean that the agreement cannot be enforced exactly when it is needed most, or that court protection becomes unavailable once confidential information has already ended up in the wrong hands. Unfortunately, these are consequences that may only surface years after signing — by which point it is already too late.

Would you really give away, so easily, something you spent years building, or invested so much in?

Since none of us want that outcome, this article lists some of the most common “traps” we have identified while working with clients from the IT sector, without going into more complex legal issues or their solutions.

9typical NDA traps

9 Typical NDA Traps

In short: The nine typical NDA traps include not knowing who your contracting party is, uncertainty about whether disclosure is one-way or two-way, a definition of confidential information that is either too broad or too narrow, and the lack of proper confidentiality protection procedures.

You Don't Know Who Your Contracting Party Is

Although it may look trivial at first glance, it is remarkable how often, in practice, we come across mistakes involving the identification of the contracting parties.

If you think this trap couldn't apply to you, ask yourself the following:

Before signing the NDA, did you request an excerpt from the Business Entities Registry from the other party, or at least check its electronic records yourself? Beyond that, did you reliably confirm that the person about to sign the NDA is actually authorized to sign on that company's behalf, and that their signature alone is sufficient?

If the answer is no, there is a good chance you have fallen into this trap. Typical examples include:

The NDA Is Not Signed by a Person Authorized to Represent the Company

For an NDA to be legally effective, it must be signed by a person (or persons) authorized to represent the company under the law, its founding act, or a corporate resolution. In other words, the fact that you have been negotiating with someone holding the title of CTO does not mean that person has the authority to sign the agreement.

To confirm whether someone is authorized to sign, you should review an excerpt from the relevant registry and/or the company's founding act and statute, or any other document proving the right of representation; the exact requirement depends on the country where your counterpart has its seat. [1]

In the IT sector, it is not unusual to find a website presenting the services of what looks like a single company, when in fact a group of independent freelancers with no jointly registered business stands behind it. In such cases, the NDA cannot be enforced, because there is no legal entity with which it was actually concluded. So while using such providers might save money earmarked for the project, the legal exposure this creates can be considerable — the effect is the same as if no NDA had ever been signed at all. In this situation, you need to sign a separate NDA with each individual you are negotiating with, or who is to take part in the project.

A very similar mistake occurs when a company does exist, but its trade name differs from the business name actually registered with the Business Entities Registry, and the agreement lists only one of the two instead of at least the full registered business name from the registry.

The Contracting Parties Are Not Adequately Identified

In practice, parties often fail to include every detail needed to properly identify one another — for example, they omit the exact registered address, or fail to state the number under which the company is recorded with the business entities register of its home country.

An example of properly identifying the contracting parties:

Example:

This Non-Disclosure Agreement (hereinafter: the “Agreement”) is signed on 10 October 2017 and enters into force on that date (hereinafter: the “Effective Date”), between

COMPANY A, established under the laws of the Netherlands, with its registered seat at Rembrandt Tower, 10th floor, Amstelplein, 1096 HA Amsterdam, the Netherlands, registration number: 34534534 (hereinafter: the “Disclosing Party”), represented by its legal representative Ms. Jane Smith,

and

COMPANY B, established under the laws of the Republic of Serbia, with its registered seat at Milentija Popovića no. 3, 11000 Belgrade, Serbia, registration number: 1231231 (hereinafter: the “Receiving Party”), represented by its legal representative Mr. John Doe.

Hereinafter jointly referred to as the “Parties”,

WHEREAS, subject to the terms and conditions set out herein, and in order to prevent the unauthorized disclosure of confidential information as defined below, the Parties wish to enter into a confidential relationship in connection with the disclosure of certain proprietary and confidential information;

NOW, THEREFORE, in consideration of the mutual undertakings contained herein, the Parties agree as follows:

You Don't Know Whether Disclosure Is One-Way or Two-Way

Before entering into negotiations to sign an NDA, you need to determine whether confidential information will flow in only one direction, or whether both parties will be disclosing confidential information to one another. This means distinguishing between two types of NDAs: unilateral and bilateral (mutual).

One-way and two-way non-disclosure agreement (NDA)

In a standard outsourcing agreement, for instance, a unilateral NDA is usually the right fit, while a bilateral NDA tends to be used for joint ventures. Still, before the other party hands you its own NDA (which, as a rule, will be unilateral), consider whether certain aspects of your own business — the ones you will be disclosing over the course of the project — should also be treated as confidential.

With NDAs, “Everything Is Confidential” Is a Trap of Its Own

Once it is clear who will act as the Disclosing Party and who will be the Receiving Party of confidential information, you reach the most important part of the NDA: defining exactly what qualifies as confidential information.

In the broadest sense, any business information that provides a competitive advantage, and especially anything that qualifies as a trade secret, can be treated as confidential information. Typical examples include product formulas, client lists, marketing strategy, algorithms, processes embedded in computer programs (or the programs themselves), and financial information. Unauthorized use of such information may amount to unfair competition and/or a breach of trade secrecy.

The source code of a program is another good example of confidential information. Although source code is protected by copyright, [3] this protection is fairly limited, since it weakens with every technical modification to the code. An NDA is what protects you from a scenario where the Receiving Party, after reviewing your code, builds a program serving the same purpose and based on the same idea — just with somewhat different code — and ends up creating a product that benefits them instead of you.

What counts as confidential information in a particular case depends on the project itself and the underlying business relationship. Naturally, if you are the Disclosing Party (say, the client in an outsourcing arrangement), you will want the definition to be as broad as possible. If you are the Receiving Party (say, the contractor), you should negotiate for a definition that is as narrow as possible.

Either way, the outcome of the negotiation needs to strike the right balance — not so broad that it effectively amounts to “everything is confidential” (a catch-all clause), yet broad enough to cover every aspect of the business that genuinely deserves protection.

One mistake we have often come across in practice is defining confidential information so broadly that it raises a fair question: what, exactly, is not confidential?

The risk with such agreements is that they may end up unenforceable, meaning that a court could refuse to grant the Disclosing Party any protection in the event of a dispute. [4] So don't let yourself fall into this trap.

You should also specify how confidential information may be transferred — it is best to state explicitly that it can be disclosed in written, oral, or electronic form, and to cover information embodied in physical items, software, and materials, depending on what the confidential information relates to.

You Have No Confidentiality Protection Procedures in Place

In short: Signing an NDA is not enough — the Disclosing Party must also introduce and actually follow procedures for keeping confidential information secret (labeling documents, restricting access), or risk the agreement being unenforceable.

If you are the Disclosing Party and you have secured a signed NDA, you might assume you are fully covered. If so, unfortunately, you have just walked into another trap.

For the Disclosing Party to be able to enforce an NDA, it must introduce, and genuinely follow, procedures for keeping confidential information secret.

What Does That Mean in Practice?

For example, if the Disclosing Party sends written documentation containing confidential information to the Receiving Party, that documentation should carry the label “Confidential” or “Strictly Confidential.” If confidential information is shared verbally, its confidential nature should be pointed out at the time as well. There are other methods too, but the underlying principle is the same: confidential information cannot be treated the same way as everything else.

Another important procedure is keeping confidential information, within company premises, in files or locations that are not accessible to every employee — only to those specifically authorized. The same applies to access to electronic databases or cloud storage. Likewise, if material containing confidential information needs to be copied, only a person specifically authorized to access that information should be allowed to do so.

What Happens If You Don't?

In court proceedings, the Receiving Party may argue that it had no way of knowing that certain disclosed or used information was meant to be treated as confidential — an argument made easier by the Disclosing Party's own careless handling of that information. Under such circumstances, disclosure that runs against the Disclosing Party's interests may well go unpunished.

You Never Addressed Permitted Use

An NDA should spell out the permitted ways in which confidential information may be used.

What Kind of Cases Are We Talking About?

There can be several, depending on the specifics of the deal, but two typical examples stand out.

For instance, the Receiving Party must be allowed to disclose confidential information to its own employees, but only to the extent necessary for them to carry out their duties, and only on condition that the Receiving Party has bound those employees to an NDA that is at least as strict as its own.

There is another detail worth watching here. If this clause is drafted narrowly and covers only the term “employee,” you have limited it to people in a formal employment relationship. Given how common it is in Serbia's IT sector to engage developers who are actually entrepreneurs rather than employees under the Labor Law, an imprecisely worded clause like this leaves an entire category of people free to misuse the information. The same risk arises when volunteers or interns are given access to confidential information.

Another standard exception to the confidentiality obligation covers information that was already available to the public at the time it was disclosed to the Receiving Party.

What Does That Actually Mean?

For example, if you have 10 contractors and have signed an NDA with 9 of them, but missed the tenth, and that contractor later discloses confidential information to the public, you will not be able to enforce the other nine NDAs with respect to what that one contractor made public.

It is also worth keeping in mind that, in certain situations, disclosure is simply unavoidable — for example, when the Receiving Party is ordered by a court or another authority to disclose the information, in whole or in part. Such situations should be regulated so that disclosure only follows the necessary notification of the Disclosing Party, and only to the extent strictly required.

You Didn't Realize That Timing Is Everything

The duration of an NDA matters for three separate reasons:

Don't Sign the NDA Too Late

Don't wait for “negotiations to get serious” before signing — conclude the NDA right when they begin. Waiting any longer creates room for someone to “borrow” your idea, concept, or business model for their own benefit, leaving you with little or nothing you can do about it. So no matter how informal the conversation feels, always consider the nature of the information you are about to share, and whether it is appropriate to share it before an NDA has been signed.

Don't Forget to Set a Timeframe for Disclosure

A well-drafted NDA always specifies the period during which confidential information is expected to be disclosed, whether the parties agree on a specific window (for example, at the start of the project) or on the entire duration of the work on the project.

Don't Get the Duration of Protection Wrong

For certain confidential information, it is entirely natural for protection to last indefinitely — the standard example being Coca-Cola's secret formula, successfully kept secret for a hundred years. [5] However, if the subject of your NDA is something like a client list or a marketing strategy rather than anything in that league, it is usually acceptable to limit the agreement's duration to a few years, after which the information will most likely lose its value simply through obsolescence. The key is to set a timeframe that is reasonable given the nature of the confidential information. [6]

That said, NDAs with no time limit at all are not unusual in practice. With this type of agreement, it is fair to ask whether it would actually be enforceable in court. So think carefully about whether the information you are protecting as a trade secret will hold its commercial value forever, or whether it will eventually become obsolete.

You Skipped the Penalty Clause

NDAs often include a clause requiring the Receiving Party to compensate the Disclosing Party for damages in the event of a breach of confidentiality. If you think that clause alone protects you well, think twice.

In practice, proving such damages is extremely difficult, and the burden of proof in court proceedings falls on the Disclosing Party. That is why it is usually better for the Disclosing Party to negotiate a penalty clause that eases this burden of proof — one that can even be drafted to exceed the actual damage that might occur in a given case.

That said, this kind of clause can meet resistance from the other party during negotiations, since it is considerably stricter than a plain damages clause. If that resistance is the reason the other party is unwilling to sign, it is up to the Disclosing Party to assess whether the counterpart is conscientious enough to be an adequate business partner, keeping in mind that penalty clauses only ever apply once confidential information has actually been disclosed.

You Left Out Dispute Resolution and the Governing Law

A solid NDA must include a clause specifying how disputes will be resolved. This matters even more with a foreign business partner, since the question of which country's courts have jurisdiction arises whenever the Disclosing and Receiving Parties are seated in different countries. This deserves careful thought — arbitration is often a better fit for both sides than litigation. You can read more about the benefits of arbitration on our blog.

Alongside jurisdiction, it is equally important to agree on the governing law. You might be wondering what “governing law” actually means: it is the law that governs the agreement itself, and the one that fills any gap the agreement does not address.

We have seen a large number of NDAs that address dispute resolution but say nothing about governing law, even though the two clauses carry equal weight.

If you fail to specify the governing law, you risk not knowing which rules to apply in order to resolve a dispute over the agreement's interpretation.

You Never Thought About Termination

NDAs typically require the Receiving Party to return, destroy, and/or delete confidential information once the business relationship between the parties ends, and to provide the Disclosing Party with proof of having done so.

That said, if you are the Receiving Party, you should negotiate the right to keep certain confidential information in your own archive. The reason is simple: in the event of a court dispute, you will want to be able to prove exactly what was disclosed to you, i.e., what was actually treated as confidential, so that you are not left at a disadvantage compared with the Disclosing Party.

If the NDA is signed alongside a business cooperation agreement or a software development agreement (or any similar contract), the termination of the confidentiality obligation should be tied to the end of that underlying relationship. For example, the agreement might provide that the obligation continues for three years following the end of the cooperation.

Finally, if you are confident that you have not fallen into any of these nine traps — congratulations! You belong to a small minority. Still, keep in mind that this article lists only the typical mistakes we have observed while working with clients from the IT sector; NDAs can raise far more complex legal questions that deserve dedicated attention of their own. So the next time you sign an NDA, give the protection of the most valuable part of your business the attention it deserves.

Legal Notes and Sources

[1] If your counterpart is a foreign company, you can request a copy of a “Certificate of Incumbency,” a “Register of Directors,” or an equivalent document proving that a person or persons are authorized to sign the agreement.

[2] A trade name is the name a company uses for marketing and sales purposes and by which it presents itself to the public; it does not have to be identical to the business name registered with the Business Entities Registry.

[3] The legal protection of software remains a matter of debate among a large number of intellectual-property lawyers. Opinions differ on whether software should also enjoy patent protection, or whether copyright protection alone should apply.

[5] Learn more about the world's longest-held trade secret: jbipl.pubpub.org.

[4] This is exactly what happened in the well-known case of Lasership, Inc. v. Watson, where a Virginia court found that the NDA could not be enforced, because the clause barring the employee from sharing information about the employer had been drafted too broadly — covering information that could not reasonably be considered confidential — and because of the clause purporting to last for the rest of the employee's life. A similar outcome occurred in Trailer Leasing Co. v. Associates Commercial Corp., where an Illinois court declined to enforce the NDA because the definition of confidential information was too broad and included no geographic limitation.

[6] For example, in Augusta Medical Complex, Inc. v. Blue Cross of Kansas, Inc., a Kansas court took a clear stance against NDAs with an indefinite duration.

Frequently Asked Questions about NDAs

When should an NDA be signed?

An NDA should be signed right when negotiations begin — not once they “get serious.” The longer you wait, the greater the risk that someone uses your idea, concept, or business model, leaving you with little or nothing you can do about it.

Who has to sign an NDA for it to be legally valid?

An NDA must be signed by the person or persons authorized to represent the company under the law, its statute, or a corporate resolution. Negotiating with someone in a senior role, such as a CTO, does not by itself mean that person is authorized to sign the agreement on the company's behalf.

Can confidential information be shared with the Receiving Party's employees?

Yes, within limits. The Receiving Party may disclose the information to its employees only to the extent necessary for them to perform their duties, and only on condition that the Receiving Party has bound those employees to an NDA that is no less strict than its own.

Does an NDA need to last forever?

Not always. An indefinite duration is only natural for rare, exceptionally valuable information, such as Coca-Cola's secret formula. For most business information, such as client lists or marketing strategy, it is acceptable to set the duration of protection at a few years, depending on the nature of the information.

What happens if the NDA does not specify governing law?

If governing law has not been agreed, a dispute over how to interpret the agreement may leave the parties unsure which legal rules to apply in order to resolve it, even where a court or arbitration forum has been specified.

Tijana Žunić Marić, Partner | Zunic Law
Tijana Žunić Marić is a partner at Zunic Law, specializing in IT law, data protection, and NDAs. She advises domestic and international clients from the IT sector on trade secret protection, the drafting and negotiation of NDAs, and compliance with data protection regulations.

Updated by: Sofija Udicki, Attorney | Zunic Law
Sofija Udicki is an attorney at Zunic Law whose day-to-day work focuses on corporate, tax, and labor law. She provides comprehensive legal support to clients from the technology sector, with a particular focus on intellectual property law.

Reviewed by: Nemanja Žunić, Partner · View profile

Updated by: Sofija Udicki, Senior Associate · View profile

Related people


Zunic Law

Law firm

Add Zunic Law as a preferred source on Google
Newsletter

Learn legal updates, and what to do about them

Legal developments in Serbia and the EU, each with the step it asks of your business.

Sign up

Two emails a month. Unsubscribe any time.