Contents
  1. What is an NDA Agreement
  2. When an NDA is really needed
  3. Negotiations with potential investors
  4. Sale of a company or business share
  5. Employees and external collaborators
  6. Development of software and technological products
  7. Cooperation with suppliers, distributors and agencies
  8. What an NDA Agreement Can Protect
  9. An example of a too broad and more precise definition
  10. NDA agreement and trade secret protection
  11. What an NDA does not automatically protect
  12. The most important provisions of a good NDA agreement
  13. When an NDA is required by employees and associates
  14. NDA Agreement and Personal Data
  15. The most common mistakes when drafting an NDA agreement
  16. What to do when an NDA is violated
  17. Is an NDA agreement sufficient to protect a trade secret?
  18. Checklist before signing an NDA agreement
  19. Frequently asked questions
  20. Conclusion

NDAs in Business: When They Are Needed and What They Actually Protect

Does signing an NDA mean that your business idea, customer base, financial data and any documents you send to the other party are automatically legally protected?

Not necessarily.

A confidentiality agreement can be an important mechanism for protecting business interests, but its name alone does not provide security. When a dispute arises, it can be shown that the contract does not define clearly enough what is confidential, for what purpose the information may be used, who can access it and how to prove that the obligation has been breached.

Universal patterns that are used without adapting to the specific relationship represent a particular problem. Such a document may seem strict, but in practice it does not correspond to the information that is actually exchanged, nor to the risks for which it was concluded.

Legal protection therefore does not depend only on signatures. It depends on the content of the contract, the nature of the information, the manner in which it was communicated and the measures taken by its holder to preserve its secrecy.

What is an NDA Agreement

The abbreviation NDA comes from the English term Non-Disclosure Agreement. In domestic business practice, the terms confidentiality agreement, non-disclosure agreement or trade secret agreement are most often used.

An NDA can be concluded as a stand-alone contract, but a confidentiality obligation can also be arranged as a clause in:

  • contract on business cooperation
  • employment contract
  • consulting contract
  • distribution agreement
  • software development contract
  • investment contract
  • license agreement
  • agreement on the purchase and sale of shares
  • pre-contract or other document regulating business negotiations

The contract can be unilateral, when only one party discloses confidential information, or mutual, when both parties exchange information that they want to protect.

In the law of the Republic of Serbia, there is no mandatory universal form of NDA contract. The contracting parties, within the limits of compulsory regulations, public order and good customs, regulate the content of their rights and obligations according to the specific business relationship.

That is why the content of the document is more important than its title. A document may be marked “NDA” and still not provide adequate protection. Conversely, a precise confidentiality clause in a broader business agreement may be sufficient if it properly governs the relevant risks.

When an NDA is really needed

An NDA agreement is not necessary in every business communication. Its routine signing with every client, employee or supplier can create additional administration for no real benefit.

A confidentiality agreement makes sense when one party must disclose to the other information whose unauthorized use or disclosure could cause it harm or deprive it of a business advantage.

Negotiations with potential investors

A company or startup seeking investment may disclose to the investor information about revenues, costs, development strategy, users, technology or future products.

The risk is not limited to public disclosure. The information can be used to evaluate another project, contact business partners or develop a competitive solution.

However, investors are often reluctant to sign an NDA at the earliest stage of discussions. This in itself does not necessarily indicate bad intent. Professional investors analyze a large number of similar projects and can avoid vague or overly broad obligations to each founder who presents them with an idea.

Risk can then be reduced by gradually disclosing information. In the initial phase, the market, the problem that the product solves and the basic business model can be presented, while technical details, sensitive financial data and key contracts are submitted only when the negotiations become more serious.

Sale of a company or business share

During the legal, financial and tax analysis, a potential buyer can gain access to contracts, balance sheets, disputes, employee, customer and supplier data.

If the transaction is not realized, the interested buyer may remain in possession of information that has great business value. Therefore, the obligation of confidentiality should be arranged before opening the data room system and before submitting the most sensitive documentation. Before delivering the documentation to the buyer, it is necessary to arrange confidentiality, but also to understand what due diligence in Serbia includes and what information the potential buyer will check.

Employees and external collaborators

Employees, developers, designers, consultants, accountants, marketing agencies and other collaborators often have immediate access to internal data.

A confidentiality obligation may be part of the underlying contract. A separate NDA agreement makes sense when the scope or importance of the information is such that it is necessary to regulate access, method of use, storage of documentation and obligations after the termination of cooperation in more detail.

Development of software and technological products

When hiring an external IT company, the customer can reveal the product’s business logic, technical documentation, system architecture, user data and development plan.

In this relationship, an NDA is not sufficient on its own. It is necessary to regulate separately who has the rights to the source code, documentation, design and other work results. The NDA regulates confidentiality, but the ownership and rights of the development results must be regulated separately, especially when it comes to the protection of software, code and digital products.

The duty of confidentiality and the transfer of intellectual property rights are different legal issues.

Cooperation with suppliers, distributors and agencies

A supplier, distributor or agency may gain access to prices, margins, sales plans, sales territories, customer contacts, campaign results and other commercial data.

A verbal expectation that a business partner will act discreetly is difficult to prove. A written contract makes it possible to determine in advance the permitted purpose of using information, the circle of authorized persons and the consequences of a violation.

What an NDA Agreement Can Protect

The subject of contractual protection can be various business, financial, technical and organizational information, such as:

  • business plans
  • financial data and projections
  • purchase and sale prices
  • rebates and margins
  • client lists
  • supplier data
  • technical documentation
  • source code
  • algorithms
  • production processes
  • formulas and recipes
  • marketing strategies
  • new product plans
  • internal research
  • work procedures
  • negotiating positions
  • commercial conditions
  • business models
  • specific know-how

However, it is not enough for the contract to simply declare “everything that one party learns” confidential.

Such a definition can be too broad and difficult to apply. In the event of a dispute, it will not always be clear whether certain information was actually disclosed, when it was disclosed, whether the recipient already possessed the information, and whether he could reasonably have known that it was considered confidential.

A good NDA therefore defines the categories of protected information, the manner in which it is communicated and the circumstances under which it is considered confidential.

An example of a too broad and more precise definition

The wording according to which “all information about the business of any contracting party” is confidential leaves too much room for different interpretations.

It would be more precise to specify that, for example, unpublished financial data, individually negotiated price terms, technical documentation, source code, customer data and product development plans that are provided to the other party for the purpose of evaluating or implementing a specific project are considered confidential.

There is no one formulation that fits every job. The definition must follow the information that will actually be exchanged in the concrete relationship.

NDA agreement and trade secret protection

An NDA agreement and a trade secret are not the same.

Under the Trade Secret Protection Act, legal protection applies to information that is secret, has commercial value because it is secret, and in respect of which reasonable measures have been taken to preserve its secrecy.

Signing an NDA can be one such measure. However, it cannot, by itself, turn commonly known, publicly available or commercially insignificant information into a trade secret.

For example, a firm may mark a publicly published price list as confidential in the contract. The mark alone will not change the fact that the document is available to the public.

On the other hand, the internal price formation model, the structure of discounts for individual customers and the plan for future price changes may represent confidential business information.

Trade secret protection is not limited to situations where there is an NDA. Illegal acquisition, use or disclosure of a trade secret can also exist outside the contractual relationship. NDA is one of the legal and organizational protection mechanisms, but it is not its only basis.

What an NDA does not automatically protect

A well-drafted contract usually excludes information that:

  • are already publicly available
  • were known to the recipient before their disclosure
  • are legally obtained from a third party
  • the recipient develops independently, without using confidential data
  • become public without breach of contract
  • must be disclosed based on the law or the decision of the competent authority

An NDA agreement does not automatically protect a business idea as such either.

An idea for an application, service, product or marketing campaign is therefore not the subject of an exclusive right. A contract may prohibit the other party from using specific, sufficiently specified and disclosed elements for purposes other than the agreed upon purpose, but does not automatically create a patent, copyright, trademark or ownership of an abstract idea.

Several mechanisms need to be distinguished.

The obligation of confidentiality means that the information must not be disclosed without authorization.

Prohibition of use means that the recipient may not use the information for their own or others’ purposes outside of the agreed purpose.

The transfer of intellectual property rights governs who has the rights to code, designs, photos, texts, technical solutions or other work results.

The prohibition of competition restricts the performance of certain competitive activities under legal and contractual conditions.

The prohibition of recruitment represents a special contractual obligation that can regulate the active recruitment of employees, associates or clients.

A single broad clause labeled an NDA cannot reliably replace all of these provisions.

The most important provisions of a good NDA agreement

The protective value of an NDA depends mostly on the precision of its key provisions.

  • Definition of confidential information

The contract should specify what is considered confidential information.

The definition may include information communicated:

  • in written form
  • electronically
  • orally
  • visually
  • by inspecting the documentation
  • access to the information system or business premises

In the case of orally communicated information, it can be foreseen that the disclosing party confirms it in writing within a certain period.

This does not mean that every piece of information must be listed individually. However, the categories must be clear enough for the recipient to understand what they are required to protect.

  • Permitted purpose of use

It is not enough to write that the recipient must not publish the data. It is necessary to clearly determine why he received them and for what purpose he may use them.

If a company has received technical documentation to assess the feasibility of a joint project, it should not use it to develop its own competitive product, even if the documentation has not been passed on to third parties.

Unauthorized use can be just as harmful as unauthorized disclosure.

  • Circle of persons who can gain access

In business, information is rarely kept only with the person who signed the contract. They can be accessed by employees, board members, lawyers, accountants, tax advisors, consultants and subcontractors.

The NDA agreement should therefore specify:

  • to which persons the information may be made available
  • under what conditions
  • whether these persons must have a corresponding obligation of confidentiality
  • who is responsible for their actions

It is common for access to be granted only to persons who really need the information for the realization of a specific job, i.e. according to the need to know principle.

  • Protection measures and standard of care

It is not enough to simply prohibit disclosure. The way in which the recipient must store the data should also be arranged.

Possible measures include:

  • limiting access to documentation
  • protection of user accounts and passwords
  • ban on sending data to private e-mail addresses
  • data storage in a controlled system
  • access records
  • prohibition of unauthorized copying
  • obligation to report a security incident
  • timely termination of access to former employees and associates

The contract may require that the recipient of the confidential information preserves the confidential information with at least as much care as it protects its own data of the same importance, but not below the standard reasonably expected in the appropriate type of business relationship.

  • Exceptions to the obligation of confidentiality

Standard exceptions do not weaken the contract. They make its boundaries clearer and more applicable.

The contract should regulate the situation in which the court, public prosecution, regulator or other competent authority requires the provision of data.

It can be envisaged that the recipient, when permitted by law, will notify the party that provided the information in advance and disclose only the amount of data that is necessary to fulfill the legal obligation.

  • Duration of confidentiality obligation

There is no one term that fits all information.

The commercial plan for the following year may lose its significance after the expiry of that period. A production formula, source code or specific know-how can have value for much longer.

Therefore, it is necessary to distinguish between:

  • duration of business cooperation
  • the period in which information is exchanged
  • the duration of the obligation of confidentiality after the termination of the relationship

In the case of information that represents a trade secret, it is possible to tie the duration of the obligation to the period during which the information retains the legal and factual features of secrecy. For other categories of confidential data, a reasonable time limit that corresponds to their nature and expected business importance can be agreed upon.

A permanent obligation should not be contracted mechanically for all data, without distinguishing between transient commercial information and long-term know-how.

  • Data recovery and destruction

Upon completion of negotiations or cooperation, it should be clearly stated whether the recipient must:

  • return the physical documentation
  • delete electronic copies
  • destroy working notes
  • remove data from device
  • terminate access to systems
  • confirm that deletion or destruction has taken place

It is necessary to take into account backup copies, legal obligations to keep documentation and data that cannot be immediately removed from automatic backups due to the technical characteristics of the system.

  • Liability for breach of contract

The contract may provide for the right to request:

  • termination of injury
  • return or destruction of documentation
  • compensation for damages
  • payment of the contractual penalty
  • application of other contractual and legal means of protection

According to the rules of the Law on Contracts and Torts, a contractual penalty can be provided for the violation of a non-monetary obligation, while the court under legal conditions can reduce its disproportionately high amount. Its clause must clearly determine for which violation the penalty is payable and how it is calculated.

The excessively high contracted amount does not mean that it will necessarily be collected in full, because the court can reduce the disproportionately high contractual penalty under legal conditions.

The relationship between the contractual penalty and compensation for damages should also be regulated, especially when the actual damages are higher than the contracted amount.

In practice, proving damage is a special problem. If a business strategy has been passed on to a competitor, it is not always easy to determine how much loss was caused by that procedure.

Therefore, the contract and business procedures should enable proving:

  • what information was submitted
  • when it was submitted
  • to whom access was allowed
  • for what purpose it was given
  • what obligations were assumed
  • Governing law and jurisdiction

In international business relations, it is important to determine which law applies and which court or arbitration will resolve any dispute.

A foreign form should not be automatically accepted just because it was submitted by an investor, supplier or business partner. Such a contract may contain institutes, remedies and wording that are not adapted to the domestic legal system or the interests of the domestic contracting party.

When an NDA is required by employees and associates

The employee’s obligation to keep real trade secrets should be distinguished from attempts to prohibit him from using general knowledge, experience and professional skills after the termination of the employment relationship.

An employer can protect:

  • internal price lists
  • client base
  • business and development plans
  • source code
  • technical documentation
  • internal procedures
  • supplier data
  • other specific confidential information

An NDA should not be used to make it virtually impossible for an employee to continue working in their profession.

In particular, confidentiality should be distinguished from the prohibition of competition. The prohibition of competition after the termination of the employment relationship can be agreed only under legal conditions, for a maximum of two years, with the obligation of the employer to pay the employee the agreed compensation.

The duty of confidentiality has a different function. It does not prohibit the employee from working for another employer, but from unauthorized disclosure or use of specific protected information.

Such an obligation may exist even after the termination of the employment relationship, as long as the specific information justifiably retains its confidential nature. It cannot, however, be extended to general professional knowledge, work experience and skills acquired by the employee during professional development.

A universal NDA for all employees is therefore not the best solution. A person who does not have access to sensitive data does not have to assume the same responsibilities as a director, developer or sales manager.

NDA Agreement and Personal Data

Certain information can be confidential business information and personal information at the same time.

A customer database, for example, may contain names, telephone numbers, e-mail addresses, purchase history and other data relating to specific or identifiable natural persons.

An NDA is not enough then.

The processing and exchange of data must have an appropriate legal basis and comply with the rules of personal data protection. Two companies cannot base the legality of exchanging personal data solely on the fact that they have concluded a confidentiality agreement.

The most common mistakes when drafting an NDA agreement

  • All information is declared confidential

Too broad a definition makes it difficult to apply and prove. Confidentiality should be tied to certain categories of data, the circumstances of their disclosure, or a reasonable expectation of secrecy.

  • Only disclosure, but not use, is prohibited

A contract may prohibit publication without saying that the data may not be used for one’s own project. This leaves a serious legal gap.

  • The purpose of delivery is not specified

Without a clearly defined purpose, it is difficult to determine when a permitted use has turned into abuse.

  • The contract is signed too late

Information has already been sent, a presentation has been held or access to the system has already been enabled.

A subsequently concluded NDA may also include previously provided information only if it is clearly agreed upon and if it can be proven what information was previously disclosed.

  • The foreign form is used without customization

Governing law, jurisdiction, contractual penalty and legal remedies may be inconsistent with domestic law and the specific business.

  • The contractual penalty is unrealistic or unclear

An extremely high amount may act as a deterrent, but it does not mean that you will be charged automatically.

The problem also exists when it is not clear whether the penalty is paid for each individual violation, for each disclosed information, for each day of the violation or only once.

  • The NDA is confused with the transfer of copyright

The fact that the developer is obliged to keep the code confidential does not automatically mean that the client has acquired all property rights to that code.

The transfer or assignment of rights must be regulated separately and with sufficient precision.

  • The obligation is not transferred to employees and subcontractors

The contracting party gets the right to hire subcontractors, but the contract does not regulate whether they must also keep information or who is responsible for their violation.

  • The company does not implement real security measures

Documents are sent without control, all employees have access, data is not classified, and accounts of former associates remain active.

In such a situation, the NDA remains a stand-alone document that is not supported by actual business practice.

What to do when an NDA is violated

First, it is necessary to determine what happened and protect the available evidence.

Important steps may include:

  • identifying information disclosed or used
  • determining who had access to it
  • storage of electronic communications
  • keeping records of access and downloads
  • providing copies of disputed documents or publications
  • sending a formal request to stop the violation
  • request for return or destruction of documentation
  • termination of access to systems
  • reference to the contractual penalty, if properly contracted
  • claim for damages
  • use of trade secret protection mechanisms
  • initiation of appropriate judicial or other proceedings

In these disputes, it is often not the most difficult thing to prove that a contract exists. It is more difficult to prove that specific information was protected, that the other party obtained it precisely within that relationship and that it used or disclosed it without authorization.

The speed of response can be important, especially when there is a risk that the information will be further distributed, published or used in the market.

Is an NDA agreement sufficient to protect a trade secret?

It’s not.

The NDA should be part of a broader classified information management system.

Such a system may include:

  • limiting access according to workplace and responsibilities
  • marking confidential documents
  • internal policies and procedures
  • technical access control
  • record of downloading and sending documents
  • employee training
  • control of external collaborators
  • regulated contracts on work and business cooperation
  • protection of intellectual property rights
  • procedures for termination of employment or cooperation
  • returning equipment and terminating user accounts
  • security incident response plan

An NDA is not a substitute for actual management of confidential information. A company that does not recognize, classify and store its confidential data will have a hard time protecting it with just one contract.

Checklist before signing an NDA agreement

Before signing, check:

Is confidential information sufficiently clearly defined?

Is the permitted purpose of use specified?

Does the contract prohibit both disclosure and unauthorized use?

Are reasonable exceptions arranged?

Is it clear who can access the data?

Is the recipient liable for employees and subcontractors?

Is the duration of the obligation appropriate to the nature of the information?

Are data recovery, deletion and destruction regulated?

Are the consequences of the injury legal and realistically applicable?

Is the contract aligned with the basic business contract?

Is it necessary to regulate intellectual property rights separately?

Is personal data shared?

Does the company really implement safeguards?

Are applicable law and jurisdiction clearly defined?

Was the contract signed before the disclosure of sensitive information?

Frequently asked questions

Does the NDA contract have to be notarized?

A notary certification is not prescribed for the conclusion of a normal NDA contract.

The written form is nevertheless very important in order to prove the identity of the contracting parties, the content of the assumed obligations, the date of conclusion and the scope of protection.

Can an NDA be concluded with an employee?

It can.

The obligation of confidentiality may be regulated by an employment contract, an annex, a separate NDA agreement or a corresponding internal document with which the employee is properly familiar.

The provisions must be sufficiently precise and should not be used as a veiled, unlimited prohibition of competition.

How long can the confidentiality obligation last?

The duration depends on the nature of the information.

For certain commercial data, a few years may be enough, while specific know-how may require protection as long as it retains the character of a secret and the business value based on that secrecy.

Does an NDA protect a business idea?

It can protect specific, sufficiently specified and confidentially communicated elements of an idea from unauthorized disclosure or use.

It does not automatically create an exclusive right to an abstract idea and does not supersede patent, copyright, trademark or other appropriate protection.

Can a fine be negotiated for breaching an NDA?

A contractual penalty may be agreed upon for breach of the non-monetary duty of confidentiality.

The clause should clearly define what conduct constitutes a breach and when the obligation to pay arises. A disproportionately high amount may be subject to a judicial reduction, and the ratio of contractual penalty and damages should be regulated separately.

Does the NDA apply if the document is not marked as confidential?

It may apply if it is clear from the contractual definition and circumstances that the information is confidential.

However, document marking, controlled delivery and a record of who received them make it much easier to prove.

Is the foreign NDA form applicable in Serbia?

It can serve as a starting point, but should not be used without legal verification.

It is necessary to check the applicable law, jurisdiction, definitions, duration of the obligation, contractual penalty, available remedies and relationship with other contracts.

What if confidential information became public?

If the information legally became publicly available, and this did not happen through a breach of contract, there is usually no longer a reason to treat that party as confidential.

If the information became public precisely because of the violation of the NDA agreement, the responsibility of the person who committed the violation does not end with the mere publication of the information.

Conclusion

An NDA agreement can be an important instrument to protect business interests, but only when it fits the specific relationship and the information that is actually exchanged.

A good contract should clearly specify:

  • what information is being protected
  • why the information is provided
  • who can access them
  • how they may be used
  • how long the commitment lasts
  • what happens after the cooperation ends
  • what are the consequences of the injury

The biggest mistake is believing that a signed form automatically solves the problem. Legal protection also depends on how the company manages data, restricts access and documents its delivery.

Before you open a data room to a potential investor, provide technical documentation to an external developer, or provide a business partner with access to a client base, you need to check whether the existing NDA really fits the relationship.

The JP Law law office provides legal support in drafting NDA contracts adapted to specific business, checking existing forms and their alignment with employment contracts, business cooperation, investment, software development and transfer of intellectual property rights.

Legal support can be significant even when a breach of confidentiality has already occurred, especially for the purpose of timely provision of evidence, assessment of legal options and selection of an appropriate protection mechanism.

Need legal assistance in Serbia?

Contact our team for advice on corporate, tax, immigration, employment and dispute resolution matters in Serbia.

Contact us
JP
Prepared by

Jusufović & Partners legal team

A Belgrade-based law firm advising clients on corporate, tax, immigration, employment, dispute resolution and investment matters in Serbia.