You've got a meeting in three days with a manufacturer who could take your product from prototype to shelves. To move forward, they need to see the thing that makes it work — the mechanism, the supplier list, the pricing model you spent a year figuring out. And the moment you email that deck, the only thing standing between "trusted partner" and "future competitor" is a piece of paper you haven't written yet. That paper is a non-disclosure agreement, and if you get it wrong, it protects nothing.
The good news is that a solid NDA is one of the more approachable legal documents to write. It has a predictable skeleton, a handful of clauses that carry all the weight, and a few well-known traps that trip up first-timers. You don't need Latin or a law degree to produce one that a court would actually enforce — you need to understand what each part is doing and why.
This guide walks through how to write an NDA from the ground up: what it is, the clauses that matter, the language that quietly weakens it, and how to go from blank page to signature without leaving holes.
TL;DR: To write an NDA that holds up, define "Confidential Information" precisely, spell out exactly what the receiving party may and may not do with it, set a reasonable time limit, and add the standard carve-outs (public info, independently developed info) so the agreement stays enforceable. Decide up front whether it's one-way or mutual, and don't overreach — courts trim NDAs that are too broad. The fastest way to start is from a proven structure: browse LegesGPT legal document templates and adapt one to your deal rather than drafting from a blank page.
What an NDA actually does
A non-disclosure agreement (also called a confidentiality agreement) is a contract in which one or more parties agree to keep specified information secret and to use it only for an agreed purpose. It creates a legal obligation where none existed before. Without it, someone you share sensitive information with generally has no duty to protect it — and once a trade secret is public, you usually can't claw it back.
There are two basic shapes:
- Unilateral (one-way): Only one side discloses confidential information. Common when a founder pitches an investor, or a company hands specs to a contractor.
- Mutual (bilateral): Both sides expect to share sensitive information — typical in partnerships, joint ventures, or merger talks.
Picking the right shape is the first drafting decision. If both parties will realistically exchange secrets, a mutual NDA is fairer and faster to sign, because neither side is asking the other to accept a one-sided obligation.
The clauses that carry the weight
An NDA can look intimidating, but its protective force lives in a small number of clauses. Get these right and the rest is scaffolding.
1. Definition of Confidential Information
This is the heart of the document. If the definition is vague, everything downstream is vague. You have two competing instincts to balance: define it broadly enough to cover what matters, but not so broadly that a court sees it as unreasonable.
A workable definition usually does two things at once — it gives a general standard and concrete examples. For instance: "Confidential Information means any non-public business, technical, or financial information disclosed by the Disclosing Party, including but not limited to product designs, source code, customer lists, pricing, and business plans, whether or not marked 'confidential.'"
Decide whether disclosures must be marked confidential to qualify. Requiring a "Confidential" stamp is cleaner but risks leaving unmarked-but-sensitive information exposed — especially anything shared verbally in a meeting.
2. Obligations of the receiving party
Defining the information is only half the job; you also have to say what the recipient can and can't do with it. Strong NDAs spell out affirmative duties: keep it secret, use it only for the stated purpose, limit access to people who need it, and protect it with reasonable care. Name the permitted purpose explicitly ("to evaluate a potential supply relationship") so the information can't be repurposed for anything else.
3. Exclusions (the carve-outs)
Counterintuitively, the clauses that limit an NDA are what make it enforceable. Courts won't uphold an agreement that tries to lock down information the recipient couldn't possibly control. Standard exclusions state that Confidential Information does not include information that:
- was already public, or becomes public through no fault of the recipient;
- the recipient already knew before disclosure;
- the recipient independently developed without using your information; or
- a third party lawfully provided without a confidentiality duty.
Leave these out and you hand the other side an argument that the whole agreement is overreaching.
4. Term and duration
How long do the obligations last? Two clocks matter: how long the agreement is active (the period during which new disclosures are covered) and how long the duty of confidentiality survives after that. Many NDAs set confidentiality obligations to last two to five years. Trade secrets are the exception — for genuine trade secrets, it's common and reasonable to keep the obligation running for as long as the information stays secret. Indefinite blanket terms on ordinary business information, by contrast, are more likely to be viewed as unreasonable.
5. Return or destruction of information
Say what happens when the relationship ends: the recipient returns or destroys the confidential materials (and copies) on request, and optionally certifies in writing that they did. This closes the loop so old data doesn't linger indefinitely.
6. Remedies and boilerplate
Because leaked secrets often can't be undone with money alone, NDAs commonly state that a breach may cause "irreparable harm" and that the disclosing party may seek injunctive relief. Round it out with the usual boilerplate: governing law, jurisdiction, no automatic license to any IP, no obligation to proceed with a deal, and a severability clause so one bad sentence doesn't sink the whole contract. If you want a fuller tour of these standard provisions and why they earn their place, our guide on what to include in a contract covers the general clause set that applies across agreements.
A practical drafting walkthrough
Here's the order of operations for actually writing one:
- Name the parties precisely. Use full legal names and entity types (LLC, Inc.), plus who is disclosing and who is receiving. In a mutual NDA, both are both.
- State the purpose. One sentence describing why information is being shared. This anchors the "use only for" restriction later.
- Define Confidential Information. General standard plus examples, and your rule on marking.
- Set the obligations. Secrecy, limited use, need-to-know access, reasonable care.
- Add the exclusions. The four standard carve-outs above, plus a clause allowing disclosure if legally compelled (with notice to you where possible).
- Set the term. Agreement period and survival period; longer or indefinite for true trade secrets.
- Add return/destruction, remedies, and boilerplate.
- Signature blocks with names, titles, and dates.
If you've never assembled a contract before, it helps to see the mechanics of the whole process end to end; the walkthrough in how to draft a contract shows how the pieces fit together beyond just NDAs.
Common mistakes that gut an NDA
- Defining "Confidential Information" too broadly. "Any and all information" invites a court to strike it as unreasonable. Anchor it to your actual business.
- No time limit at all. An eternal duty on ordinary information reads as overreach. Reserve indefinite terms for genuine trade secrets.
- Forgetting the carve-outs. Without exclusions, the recipient can argue the agreement is unenforceable.
- Mismatched purpose and use. If the purpose clause and the use restriction don't line up, there's a gap to exploit.
- Skipping the "compelled disclosure" clause. A recipient hit with a subpoena needs a lawful way to comply without breaching — and you want the right to notice so you can contest it.
- Signing the wrong shape. Accepting a one-way NDA when you'll also be disclosing leaves your own secrets unprotected.
Overreaching is the quiet killer here. An NDA that tries to control too much is weaker, not stronger, because a court may narrow it or refuse to enforce it. Reasonableness is what makes it stick.
Starting from a template (the smart shortcut)
Very few well-drafted NDAs are written from a truly blank page — and yours doesn't need to be either. Starting from a vetted structure means the load-bearing clauses are already present and in the right order; your job becomes tailoring the definition, purpose, term, and parties to your specific deal. That's faster and far less error-prone than reinventing standard language.
A good starting point gives you the skeleton so you can focus on the details that make your NDA yours. LegesGPT's legal document templates include confidentiality agreements you can adapt clause by clause, and its drafting tools can help you adjust the language for a one-way versus mutual deal, tighten a definition, or sanity-check that you haven't left out a standard carve-out. Whatever you use, read every clause before you sign — a template is a head start, not a substitute for understanding what you're agreeing to.
The bottom line
Writing an NDA that holds up isn't about dense legalese. It's about being precise where precision matters — defining the information, stating the permitted use, adding the carve-outs, and setting a reasonable term — and being disciplined enough not to overreach. Decide one-way or mutual first, build from a solid structure, and tailor each clause to the actual deal in front of you. Do that, and the piece of paper standing between "trusted partner" and "future competitor" will actually do its job.
This article is general information, not legal advice. Laws and enforceability vary by state and jurisdiction; consult a licensed attorney for your specific situation.


