← Back to blog
Business & Legal

NDA Breaches and the Evidence Problem: Proving What Was Disclosed Under an NDA

By Provlyn·18 July 2026

When an NDA is breached, the injured party must prove what confidential information was disclosed, that the disclosure caused loss, and quantify that loss in financial terms. The first of those three elements — proving what was disclosed, in what form, and when — is where most NDA enforcement actions are evidentially weakest. Provlyn provides the independent record of disclosed material that standard file exchange cannot produce.

NDA Breaches and the UK Legal Framework

Non-disclosure agreements are among the most widely used commercial instruments in UK business, deployed to protect confidential information shared during negotiations, joint ventures, investment discussions, and employment relationships. Their use has grown significantly as UK trade secret protection has strengthened, giving businesses stronger legal tools to pursue misappropriation of confidential information alongside existing contractual remedies.

IlliquidX Ltd v Altana Wealth Ltd & others illustrates the point directly. The case concerned alleged breaches of a non-disclosure agreement, breaches of confidence, and breaches of the Trade Secrets (Enforcement, etc.) Regulations 2018 arising from information shared during the early stages of a failed joint venture — one of the most common factual patterns in UK trade secret litigation. At first instance ([2025] EWHC 299 (Ch)), Rajah J found the breach of confidence and trade secrets claims made out against the corporate defendants. The Court of Appeal ([2026] EWCA Civ 874, Arnold LJ, Zacaroli and Miles LJJ agreeing) dismissed the appeal on 10 July 2026. In a separate costs judgment ([2025] EWHC 1566 (Ch)), Rajah J noted that the proceedings had been “bedevilled by IX’s inability or refusal to specify with clarity and precision what its case was as to the confidential information that it says was misused.” IlliquidX won on liability but recovered only 50 per cent of its costs — reflecting a 10 per cent deduction conceded for failed claims, together with reductions for litigation conduct including inflated disclosure costs and unclear pleadings. IlliquidX proved its case. What it could not do was specify, with the precision the court expected, exactly what confidential information had been disclosed and when — and it paid for that in costs. The Trade Secrets (Enforcement, etc.) Regulations 2018 implemented the EU Trade Secrets Directive into UK law, providing a standalone civil remedy for misappropriation alongside contractual NDA rights. The National Security Act 2023 went further still, introducing criminal liability for trade secret theft in cases involving foreign powers and carrying a maximum sentence of 14 years’ imprisonment — a measure that reflects the growing legislative recognition of confidential information as commercially critical.

Provlyn was built for exactly that gap. An NDA creates the obligation. The vault deposit creates an independently anchored record of what was disclosed under it — made at the moment of disclosure, in a form neither party can alter after the fact.

The Three Things You Must Prove to Enforce an NDA Breach

When an NDA is breached and the injured party pursues a claim, UK courts require proof of three things. First, that confidential information was disclosed in breach of the agreement. Second, that the disclosure caused the claimant a loss. Third, what that loss amounts to in pounds. Speculative losses — what the claimant might have made if a competitor had not learned of their idea — are difficult to recover. The court is trying to put the claimant back in the position they would have been in if the breach had not happened, and that requires evidence of what was shared and what commercial value it carried.

In practice, the first element is where most enforcement actions are weakest. The claimant knows something was disclosed. The respondent may deny it, or deny that what was shared amounted to confidential information within the scope of the NDA, or dispute the form in which it was shared. Without an independent record of what was sent, when, and in what form, the claimant is relying on their own version of events — which courts treat as partisan rather than independent.

The consequences of failing to establish what was disclosed are significant. An injunction, which is the most immediate remedy available and the one most likely to limit ongoing damage, requires the court to be satisfied that confidential information was disclosed. Damages, similarly, require the claimant to identify and quantify the specific information that was shared. Without an independently anchored record of that disclosure, both remedies are harder to obtain and cheaper for the respondent to resist.

Why Standard File Exchange Cannot Prove What Was Disclosed Under an NDA

When confidential information is shared under an NDA, it is typically sent as an email attachment, a shared cloud storage link, or a file transfer. The sender has a copy in their sent folder. The recipient has a copy in their inbox. Both parties may have subsequent versions of the same document. None of the original exchange records is independent.

A party’s own sent folder is produced and held by the party with an interest in the outcome. Email metadata is editable. File system timestamps reflect activity on a specific device and can be changed. The recipient’s copy, if they deny receiving a particular version, cannot be independently verified against what was sent. In a dispute about what was disclosed, both parties’ records are subject to the same challenge: they were produced by a party with a stake in the outcome, and courts treat them accordingly.

The position is further complicated where information has been shared in multiple iterations — a business plan updated three times during negotiations, a financial model revised after each investor meeting, a technical specification updated before final disclosure. Each version may carry different commercial sensitivity. Without an independently anchored record of each version at the moment it was shared, the question of which iteration was disclosed when, and what it contained at that moment, becomes a contest of competing assertions.

How Provlyn Lets You Prove What Was Disclosed Under an NDA

A Provlyn vault deposit made before confidential material is shared produces an independent, cryptographically anchored record of exactly what was disclosed, at the moment of disclosure. The deposit works as follows:

  1. SHA-256 hash generated — a unique cryptographic fingerprint of the exact file at that moment. A single change anywhere in the document produces an entirely different fingerprint. The fingerprint cannot be reverse-engineered to reveal the document’s contents, which remain private to the disclosing party.
  2. RFC 3161 timestamp applied — the fingerprint is timestamped by an accredited Trust Service Provider, creating a cryptographically signed record of the exact moment that version of the document existed.
  3. eIDAS Article 41 qualification — the timestamp is qualified by an accredited Qualified Trust Service Provider (QTSP), giving the vault certificate a legal presumption of accuracy in EU member states and strong electronic evidence status under UK law.
  4. Bitcoin blockchain anchoring — the fingerprint is anchored on the Bitcoin blockchain through the OpenTimestamps protocol, creating a permanent public record that does not depend on Provlyn’s continued operation to remain verifiable.
  5. Vault certificate issued — a downloadable PDF recording the file name, the SHA-256 fingerprint, the qualified eIDAS timestamp, and the blockchain anchor. Independently verifiable by any court, regulator, or counterparty.

Provlyn’s versioning capability extends this across an entire disclosure sequence. Each iteration of a document shared under an NDA can be deposited independently, building an anchored record of what was disclosed at each stage of a negotiation or joint venture. A fuller technical walkthrough is at www.provlyn.com/how-it-works.

What the Record Changes Before and After an NDA Breach

The value of an independently anchored disclosure record is not limited to enforcement. It changes the position of both parties from the moment the NDA is executed.

A recipient who knows that the confidential material they received is independently fingerprinted and timestamped — in a form that cannot be altered — operates differently from one who received a file with no independent record attached. The record does not prevent misuse. What it does is make misuse immediately traceable to the specific version of the specific document that was shared, at the specific moment it was received. That changes the risk calculation for any recipient who considers using information outside the terms of the agreement.

When a breach does occur, the claimant’s position changes in kind. The question of what was disclosed is no longer a contest of competing assertions. The vault certificate answers it: this specific version of this specific document was in the disclosing party’s hands at this specific moment, before it was shared. The evidential foundation for an injunction, a damages claim, or a negotiated settlement is established before the dispute begins.

The asymmetry is the same as it is for any other form of prior proof. The cost of establishing a Provlyn disclosure record is a seven-day free trial. The cost of pursuing an NDA enforcement action without one — or of settling for less because the evidence of what was disclosed is contestable — is of a different order entirely.

Establish a cryptographic record of what you disclose under an NDA

Provlyn provides cryptographic prior proof of ownership for any digital artefact. Each deposit is hashed with SHA-256, timestamped by an accredited Trust Service Provider under RFC 3161, qualified under eIDAS Article 41, and anchored on the Bitcoin blockchain. The vault certificate carries a legal presumption of accuracy under the EU eIDAS Regulation, is admissible evidence in UK and EU jurisdictions, and remains valid permanently, independently of Provlyn’s continued operation. Start your free seven-day trial at www.provlyn.com. No credit card required.

This post provides general information about the role of cryptographic evidence. It is not legal advice. For advice on a specific matter, consult a qualified lawyer in your jurisdiction.

Related Reading

Developments in UK Trade Secret Litigation for 2025 — IPWatchdog

Trade Secrets 2025: United Kingdom — Chambers and Partners

CPR 32.19: What UK Courts Require to Prove a Document Is Authentic

Protect your work with Provlyn

Blockchain-anchored timestamps and court-admissible certificates. Prove it. Permanently.

Get started free