How to define what an NDA actually covers

Almost every confidentiality clause is written the same way, and it is squeezed from both sides. Define the protected material too widely and a court may decline to enforce it. Define it too narrowly and the thing that mattered was never covered. The drafter is guessing, before anyone knows what will be shared.

There is a way out that does not involve better adjectives. Define the scope by reference to the documents themselves, using their cryptographic fingerprints, so the agreement points at identified files rather than describing them.

Four ways to write the clause, and what each costs

ApproachThe difficultyWhere it fails
Everything disclosed is confidentialMay be treated as unreasonable or impractical to comply withHard to enforce, and gives no help identifying what a claim actually relies on
Only material marked confidentialDepends entirely on marking discipline under time pressureAnything shared unmarked falls outside the agreement
A written list of categoriesWritten before anyone knows what will be sharedMaterial that mattered was never in a listed category
A schedule of certificate referencesRequires depositing each document before it is sharedCovers only what was recorded, so the discipline has to hold

The last row has a cost of its own, stated plainly: it only covers what was recorded. If a document is shared without being deposited, the schedule does not reach it. That is a process discipline, not a technology, and it is worth knowing before adopting the approach.

What the courts are looking for

The requirement is particularity. A party asserting confidential information has to identify it with enough specificity that a court can tell what is protected and frame a remedy around it. That requirement does not sit in one numbered provision. In the EU it follows from the definition of a trade secret in Article 2(1) of Directive (EU) 2016/943 read with national rules of procedure, the same applies in the UK under the regulations implementing the Directive, and under the US Defend Trade Secrets Act a claimant must identify the secret with reasonable particularity.

English proceedings show what that means in practice. In IlliquidX Ltd v Altana Wealth Ltd and others [2024] EWHC 2191 (Ch), an application to amend particulars of claim, the court restated that claims for breach of confidence and misuse of trade secrets must be properly particularised both as to the information relied on and as to the misuse alleged, and refused some of the proposed amendments. IlliquidX went on to win at trial and to hold that win on appeal, so this is not a story about a claim failing. Our post on what standard disclosure cannot prove follows the case through to the costs judgment, where the lack of precision still cost the winning party.

The point holds whichever way a case goes. The material has to be identifiable before the dispute, in terms specific enough to survive being read back by an opponent.

Defining scope by fingerprint

A confidentiality clause describes the protected material because the material cannot go in the agreement itself. That is the whole difficulty: the description has to be broad enough to cover what will be shared and precise enough to be enforced, and those pull in opposite directions.

A fingerprint is neither broad nor narrow. Each document is deposited before it is shared, which produces a certificate carrying the file name, the SHA-256 fingerprint, a timestamp from an accredited trust service provider and a blockchain anchor. The certificate reference goes into a schedule to the agreement. The obligation then attaches to identified documents, and the schedule reveals nothing about their contents, because a hash cannot be reversed.

When documents change during a negotiation, each version gets its own deposit and reference. Whether that is worth doing, and how the clause should read, is a question for the lawyer drafting the agreement. This is a drafting approach rather than a legal rule, and nothing here is advice on your agreement.

The other half of the question

Defining what an agreement covers and proving what was actually sent are two different problems, and certificate services address only the first. In a dispute the second is usually where the argument lands: not whether the category was covered, but whether this document reached that person on that date.

A sent folder is held by the party relying on it. A recipient download log is held by the opposing party. Neither is independent, and a court will treat both accordingly. Provlyn shares from a vault instead: each recipient opens the material through a controlled link, each view is logged against a timestamp, and access can be withdrawn. Each recipient can be issued an individually watermarked copy, so a document that surfaces where it should not identifies who received it.

Where the material also qualifies as a trade secret, those access records do double duty, since keeping information access-restricted is one of the reasonable steps a holder has to evidence.

What an NDA cannot do

A page about making confidentiality agreements work should say where they stop. In the UK an NDA cannot be enforced against someone who is, or reasonably believes they are, a victim of crime, to prevent disclosure to the police or other bodies investigating or prosecuting crime, to a qualified lawyer for advice about it, or to a regulated professional for support. An agreement that purports to do so is unenforceable to that extent.

Confidentiality provisions also cannot be used to conceal unlawful behaviour, and the law in this area has been moving. None of it affects the ordinary commercial use of an NDA between businesses, which is what this page is about. It matters because a confidentiality regime built on the belief that an NDA silences everything is built on a false premise, and no amount of evidential infrastructure fixes that.

How the record is made

One automated sequence, each step taking the output of the one before it. The document is hashed with SHA-256. That hash is timestamped under RFC 3161 by an accredited trust service provider. The timestamped hash is anchored to the Bitcoin blockchain through OpenTimestamps. Only the hash travels, so the document stays where it is and the schedule can be shared with the other side without disclosing anything.

eIDAS qualification is a separate option on top of that sequence. With it, the timestamp carries the presumption under Article 41(2) that the date and time are accurate and the data intact, which shifts the burden to the party disputing it. A blockchain anchor on its own does not carry that presumption, a distinction set out in blockchain timestamps compared with qualified timestamps.

Every certificate can be checked without us, using SHA-256, OpenSSL, the European Commission's trusted lists and any OpenTimestamps client. Our timestamp validator is open source and checks any provider's timestamp, not only ours.

Record your first deposit →

Questions

How should an NDA define confidential information?

Specifically enough that a court can tell what was covered, without setting out the content in a document the other side keeps. Drafters are caught between two failures: a definition covering everything disclosed may be treated as unreasonable and difficult to enforce, while a narrow list may leave out the material that actually mattered. One way through is to define the scope by reference to the documents themselves. Each document is hashed, the hash is timestamped, and the resulting certificate reference is listed in a schedule to the agreement. The schedule names a fingerprint rather than describing content, so the scope is exact and the material stays private.

Can an NDA be too broad to enforce?

It can be. Courts have been reluctant to enforce confidentiality definitions so wide that compliance becomes impractical or the restriction reaches beyond a legitimate business interest. Separately from enforceability, the breadth of a definition creates a pleading problem: a party bringing a claim has to particularise the information it actually relies on, and a clause covering everything gives no help with that. In IlliquidX Ltd v Altana Wealth Ltd and others [2024] EWHC 2191 (Ch), an application to amend particulars of claim, the court restated that claims for breach of confidence and misuse of trade secrets must be properly particularised as to both the information relied on and the misuse alleged, and refused some of the proposed amendments. IlliquidX went on to win at trial and on appeal, so this is not a story about a claim failing. It is about what the pleading has to contain first.

How does a certificate reference work in an NDA?

Each document is deposited before it is shared, which produces a certificate carrying the file name, its SHA-256 fingerprint, a timestamp from an accredited trust service provider and a blockchain anchor. The certificate has its own reference. That reference goes into a schedule to the agreement, so the confidentiality obligation attaches to identified documents rather than to a description of them. If the parties later disagree about whether a particular file was covered, the fingerprint answers it: the file either produces the listed fingerprint or it does not. This is a drafting approach rather than a legal rule, so the wording should be settled with the lawyer drafting the agreement.

What happens when the documents change during negotiation?

Each version gets its own deposit and its own certificate reference, and the schedule is updated or extended as the negotiation proceeds. This is the situation static drafting handles worst, since a business plan revised three times or a model recalculated after every meeting leaves the parties arguing about which iteration was covered. A sequence of dated certificates removes that argument without requiring the agreement to be renegotiated each time.

How do I prove what was actually sent to the other side?

Defining the scope and proving the disclosure are two separate problems, and a certificate answers only the first. A sent folder is held by the party relying on it, and a recipient download log is held by the opposing party, so neither carries weight on its own. Sharing from an access-controlled vault records each recipient and each view against a timestamp, and issuing individually watermarked copies means a leaked document identifies who received it. A scope definition without a disclosure record leaves half the question open.

What can an NDA not prevent?

More than many drafters assume, and this is worth knowing before relying on one. In the UK an NDA cannot be enforced to stop someone who is, or reasonably believes they are, a victim of crime from disclosing to the police or other bodies investigating or prosecuting crime, to a qualified lawyer for legal advice about it, or to a regulated professional for support. Agreements that attempt it are unenforceable to that extent. Confidentiality provisions also cannot be used to conceal unlawful behaviour, and the law here has been moving. None of that affects the ordinary commercial use of an NDA, but a confidentiality regime built on the assumption that an NDA silences everything is built wrong.

Does this apply to contracts other than NDAs?

The same reasoning applies wherever an agreement refers to material held outside it. Licence agreements referring to licensed technology, development agreements referring to a specification, supply agreements referring to a bill of materials, employment contracts referring to defined confidential material. In each case the agreement describes something in prose while the actual subject sits in a separate file. Recording those files and referring to them by fingerprint closes the gap between what the contract says and what it points at.

What does a dated record not do?

It does not make an unenforceable agreement enforceable, and it does not decide whether particular information qualifies as confidential. Those are questions of contract law and fact for a court. What it establishes is that a specific document existed in a specific form on a specific date and has not changed since, which is the foundation the other arguments are built on rather than a replacement for them. Drafting remains a job for a lawyer.

Where to go next. Read what standard disclosure cannot prove, or the contract approval evidence gap. See trade secrets, check pricing, or read how to verify a record without us.

This page gives general information about confidentiality agreements and evidence. It is not legal advice, and nothing here is a recommendation on the drafting of your agreement. For a specific matter, consult a qualified lawyer in the relevant jurisdiction.