The confidentiality clause in a non-disclosure agreement (NDA) under India law
Confidentiality clause in Indian NDAs: obligations, exceptions, duration, and care standards under the Indian Contract Act, 1872.
Standard Position
In Indian NDAs, the confidentiality clause is the core operative provision that defines what information qualifies as confidential, who is bound, and what obligations attach. Under Indian law, a confidentiality clause must clearly identify the subject matter (Confidential Information), specify the recipient's duties, and outline permitted uses. The standard market position in India mirrors global practice but reflects the Indian Contract Act, 1872 (ICA) principles: the clause should impose a duty of care on the receiving party, restrict disclosure to need-to-know personnel, and permit limited exceptions.
Indian courts interpret confidentiality clauses strictly according to Section 10 of the ICA (offer and acceptance) and the principle of consensus ad idem (meeting of minds). A confidentiality clause creates a contractual obligation enforceable under Section 73 (damages for breach) and Section 74 (limitation of damages) of the ICA. The clause must be sufficiently certain to be enforceable; vague or overbroad confidentiality language risks being struck down as unreasonable restraint under Section 27 of the ICA or as opposed to public policy.
Legal Basis
Section 10 of the ICA requires agreement on essential terms; the definition of Confidential Information must be clear enough to satisfy this. Section 27 restricts agreements that restrain a person from earning a livelihood; overboard confidentiality periods (e.g., perpetual restrictions on general knowledge) may infringe this. Section 73 allows damages for breach, but the receiving party may invoke Section 72 if they received the information from a third party without breach of duty.
The Information Technology Act, 2000, and the Data Protection regulatory framework (now transitioning to the Digital Personal Data Protection Act, 2023) may intersect if the Confidential Information includes personal data. This creates an additional layer: NDAs must not conflict with data protection duties.
Drafting and Negotiation
A robust confidentiality clause in an Indian NDA should:
-
Define Confidential Information precisely: specify that it includes technical data, business plans, financial information, and customer lists, but expressly exclude information that is (a) publicly available (not through breach), (b) independently developed, (c) lawfully received from a third party without confidentiality obligation, or (d) required to be disclosed by law or court order (with notice and mitigation obligations).
-
Specify the standard of care: require the recipient to protect the information with the same care they apply to their own confidential information (reasonable-care standard), or with a higher standard if negotiated (e.g., industry-standard security).
-
Limit duration: Indian courts prefer finite terms. A common negotiated position is 3-5 years from disclosure; perpetual restrictions on general knowledge are disfavored.
-
Clarify permitted uses: narrow the permitted use to the stated purpose (e.g., evaluation, negotiation). Any derivative use or broader commercial application must be separately permitted.
-
Address compelled disclosure: require the recipient to notify the discloser if compelled by law, court, or regulatory authority to disclose, allowing the discloser to seek protective orders.
Common negotiation points: receivers typically resist indefinite confidentiality terms and seek broad exceptions for information developed independently. Disclosers push for stricter care standards and longer terms. A balanced position: 5-7 year confidentiality for business information, indefinite for trade secrets (as defined under the Trade Secrets Act, 2000, a part of the Design Act framework).
Common Pitfalls
- Overly broad definitions of Confidential Information that sweep in public domain knowledge create unenforceability risk under Section 27.
- Failure to address statutory disclosure (e.g., under GST, Companies Act, or Labour law) creates ambiguity; always include a "compelled disclosure" carve-out.
- Vague care standards (e.g., "best efforts") are harder to enforce; "reasonable care" is more enforceable in Indian courts.
- Perpetual restrictions on the recipient's use of general skills or knowledge acquired incidentally may be deemed restraint under Section 27.
- Omitting details on return/destruction of information can lead to disputes; always specify timelines and certification requirements.
Sample language
The Receiving Party shall maintain the Confidential Information in strict confidence and protect it with the same degree of care it applies to its own confidential information, but not less than reasonable care, for a period of five (5) years from the date of disclosure or until the information enters the public domain through no breach by the Receiving Party, whichever is earlier. The Confidential Information shall not include information that (a) is publicly available, (b) was independently developed without access to the Confidential Information, (c) is lawfully received from a third party without confidentiality restrictions, or (d) is required to be disclosed by law, provided the Receiving Party gives prompt written notice to the Discloser to permit a protective order.
This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.
Frequently asked questions
- How long should a confidentiality obligation last under Indian law?
- Indian courts disfavor perpetual restrictions, especially if they restrain earning a livelihood (Section 27, ICA). Standard practice is 3-7 years from disclosure for business information. Trade secrets, if defined narrowly under applicable law, may support indefinite confidentiality. Always tie the duration to the nature of information and align with the statutory requirement of certainty.
- What is the standard of care required in an Indian NDA confidentiality clause?
- "Reasonable care" is the default and most enforceable in Indian courts. Higher standards (e.g., "strict confidentiality" or industry-specific standards like ISO 27001) are negotiable but may be harder to prove breach. Avoid vague terms like "best efforts." Align the care standard to the sensitivity of information and the parties' sophistication.
- Must an Indian NDA confidentiality clause include a compelled disclosure exception?
- Yes, strongly recommended. Indian law does not automatically excuse breach due to legal compulsion. A clause requiring notice to the Discloser when disclosure is compelled by law or court order allows the Discloser to seek protective measures and avoids disputes. Omitting this creates enforceability risks and practical conflict with statutory obligations (GST, RBI, etc.).
- Can a confidentiality clause in an Indian NDA restrict an employee's use of general knowledge?
- No. Section 27 of the ICA voids restrictions that prevent a person from earning a livelihood. Confidentiality clauses that restrict use of general skills or knowledge acquired incidentally (beyond the specific Confidential Information) are unenforceable. Define Confidential Information narrowly to avoid this trap.
Related in the library
- The confidentiality clause in a SaaS agreement under India law
- The confidentiality clause in a SaaS agreement under the United States law
- The confidentiality clause in a non-disclosure agreement (NDA) under the United States law
- The limitation of liability clause in a consultancy agreement under India law
- The governing law clause in a SaaS agreement under India law
- The dispute resolution clause in a non-disclosure agreement (NDA) under India law
Adira drafts and reviews contracts under the law of the jurisdiction they work in.
See Adira