Confidential Information Definition in an NDA (Plain English + Examples)
The definition of “Confidential Information” determines how risky an NDA is. Here is how to spot overly broad definitions, fix them, and protect your own IP.

Shahzaib Khan is the founder of Clauze and building the product, from the underlying platform to the content library. He writes Clauze's blog drawing on hands-on experience building the tool's clause-detection logic and reviewing hundreds of real contracts during development.
In most non-disclosure agreements (NDAs), the single most important paragraph is the definition of "Confidential Information." This section sets the boundaries of what you are legally required to keep secret and what you are allowed to treat as public knowledge.
If the definition is too broad, you could inadvertently breach the contract by discussing a common industry trend. If it is too narrow, the other party might not be protected at all. For freelancers and startups, getting this right is essential to avoiding legal "compliance traps" where you are sued for sharing information you didn't even know was supposed to be secret.
Why the Definition is the Foundation of Every NDA
An NDA is essentially a lock on a door. The definition of Confidential Information is the list of everything that is supposed to be inside that room. If the list includes things that are actually outside in the hallway (like public info), the lock is useless—or worse, it becomes a trap for the person holding the key.
Without a clear definition, you are essentially signing a blank check for the other party's legal team. They can claim that any conversation, any email, or any idea shared was "confidential," even if it was common knowledge.
What a Fair Definition Looks Like
A fair definition is specific, practical, and limited to things that actually need protection. It focuses on non-public business, technical, or financial information that has real value. It also places a reasonable burden on the person sharing the info to identify what they want to keep secret.
**Example Clause:** *"Confidential Information means non-public business, technical, or financial information disclosed in writing by the Disclosing Party that is clearly marked 'Confidential' at the time of disclosure."*
**How Clauze flags this:** Clauze identifies this as a "Standard Protective" definition. The tool will note that the marking requirement is a major safety feature for the recipient, as it removes ambiguity about what is and isn't secret. Clauze recommends this structure for anyone receiving information, as it provides a clear audit trail.
Red Flag: The "Catch-all" Phrasing
The most dangerous definitions use "including but not limited to" or "all information relating to the business" without any limits. These phrases can turn ordinary conversations, public website data, and general industry knowledge into "confidential" information.
**Example Clause:** *"Confidential Information includes, but is not limited to, all information of any kind disclosed by the Disclosing Party, whether or not marked as confidential, relating to its business, products, customers, and operations, including all notes, summaries, and analyses derived therefrom."*
**How Clauze flags this:** Clauze flags this as a "Broad Scope Risk." It points out that "relating to its business" is so vague that it could cover almost anything. Clauze recommends narrowing this to "specifically identified trade secrets or proprietary data." Clauze also warns that the "derived therefrom" language can make your own notes and thoughts confidential, which is a major red flag for independent contractors.
Red Flag: Oral Disclosures without Follow-up
Sometimes NDAs treat oral information (things said in a meeting) as confidential automatically. This is a nightmare for compliance because nobody can remember every word spoken in a two-hour pitch or a casual coffee meeting.
**Example Clause:** *"Confidential Information shall include information disclosed orally, visually, or in any other form, whether or not such information is reduced to writing or marked as confidential."*
**How Clauze flags this:** Clauze identifies this as an "Unverifiable Obligation." It suggests a "Written Confirmation" requirement: oral disclosures should only be confidential if the disclosing party summarizes them in an email within 15 to 30 days. Clauze notes that without this, you are effectively agreeing to a "perfect memory" standard that is impossible to meet in a professional setting.
The Marking Requirement: Practical vs. Impossible
A "Marking Clause" requires the discloser to stamp documents as "Confidential." This is the gold standard for recipients. However, some NDAs try to skip this by using the "Reasonable Person" standard, which says anything that "reasonably should be understood" as confidential counts.
**Example Clause:** *"Confidential Information includes any information that, given the nature of the information or the circumstances of disclosure, a reasonable person would understand to be confidential, regardless of whether it is marked as such."*
**How Clauze flags this:** Clauze flags the "Reasonable Person Standard" as a medium risk. While it sounds fair, it is entirely subjective. What is "obviously" confidential to a CEO might not be to a developer. Clauze recommends insisting on a marking requirement for written documents to provide a clear objective standard. You can read more about why this matters in our guide to mutual NDA red flags.
The 4 Standard Carve-outs (The "Must-Haves")
Every fair NDA must include exceptions. These ensure you aren't sued for knowing things that everyone else knows. These are the "safety valves" of an NDA.
**Example Clause:** *"Confidential Information does not include information that: (a) is or becomes public through no fault of Recipient; (b) was already in Recipient's possession prior to disclosure; (c) is received from a third party without restriction; or (d) is independently developed without use of the Confidential Information."*
**How Clauze flags this:** Clauze checks for the "Big Four Carve-outs." If any are missing, it flags a "High Protection Gap." These exceptions are non-negotiable. Clauze particularly focuses on the "Independent Development" carve-out, as it protects your right to work on similar projects in the future. For more on these, see our deep dive into permitted disclosures and carve-outs.
Third-Party Information Traps
If you are working with a client who uses third-party tools or data, they might try to make you responsible for those third-party secrets too. This can lead to you unknowingly breaching contracts you've never even seen.
**Example Clause:** *"Confidential Information includes all information disclosed to the Disclosing Party by third parties which the Disclosing Party is under an obligation to keep confidential, and Recipient agrees to be bound by all such third-party obligations."*
**How Clauze flags this:** Clauze identifies "Third-Party Expansion" as a high risk. It notes that you are being asked to follow rules you haven't even seen. Clauze suggests limiting this to information specifically identified to you as third-party confidential data. It warns that "blindly" accepting third-party obligations is a recipe for legal disaster.
Trade Secrets vs. Confidential Information
Trade secrets (like algorithms or customer lists) often have longer protection periods than general confidential information (like a draft marketing plan). It's important to distinguish between the two so you aren't on the hook for general data forever.
**Example Clause:** *"The obligations for general Confidential Information expire in 3 years, but obligations for Trade Secrets shall continue for as long as such information remains a trade secret under applicable law."*
**How Clauze flags this:** Clauze identifies "Indefinite Trade Secret Protection" as a standard but high-burden clause. It will remind you that while this is common, you must ensure you have a process for identifying which specific items are trade secrets. Clauze suggests adding a requirement that trade secrets must be explicitly designated as such at the time of disclosure.
The "Residuals" Clause: A Secret License?
A residuals clause allows the other party to use ideas they "remember" without it being a breach. We cover this in detail in our Mutual NDA Red Flags post, but it's relevant here too because it effectively limits the definition of what is actually protected.
**Example Clause:** *"Notwithstanding anything to the contrary, Recipient may use for any purpose the residuals resulting from access to the Confidential Information, provided that Recipient does not disclose the Confidential Information."*
**How Clauze flags this:** Clauze flags "Residuals Rights" as a major risk for the disclosing party. It explains that this clause allows the recipient to use your ideas as long as they don't take a physical copy. Clauze recommends deleting this if you are the one sharing sensitive intellectual property.
How to Narrow a Broad Definition
If you are presented with a broad definition, use these simple negotiation steps to protect yourself:
- **Add a Marking Requirement:** Insist on "In writing and marked 'Confidential'."
- **Add a Confirmation Period:** Ensure oral info is confirmed in writing within 15 days.
- **Verify the Carve-outs:** Ensure all four standard exceptions are present and robust.
- **Limit the Scope:** Change "relating to the business" to "specifically related to [Project Name]."
- **Add a Time Limit:** Ensure the confidentiality obligation has a clear end date (e.g., 2-3 years).
For more on NDA structures, see our post on mutual NDA red flags or our guide on permitted disclosures and carve-outs. If you are just starting, read our overview of what an NDA actually means. You should also be aware of how limitation of liability caps can protect you if a breach does occur.
Quick Answers (AEO)
What does "confidential information" mean in an NDA?
It is the specific set of data, ideas, or documents you agree not to share. The definition sets the legal boundaries of your silence and determines your liability.
Should confidential information be marked?
Yes. A marking requirement ("Confidential") is the best way to prevent accidental breaches and ensure you know exactly what is protected and what isn't.
Is oral information confidential?
Only if the contract says so. The best practice is to require oral information to be confirmed in writing within a few weeks to remain protected under the NDA.
Ready to run your own contract review?
Paste any contract and get a plain English breakdown, risk badges, and practical next steps.
Analyse a contract