Protecting Secrets Without an NDA: Practical Alternatives

Alex Solo
byAlex Solo12 min read

Not every sensitive business conversation in New Zealand starts with an NDA, and in real life, many do not. Founders often share pricing models, product ideas, supplier details or customer insights too early, assume a casual verbal understanding is enough, or send documents marked “confidential” without any real legal backup. That is where problems start. Once information is out, it can be hard to pull it back, especially if the other party says there was no clear agreement about secrecy.

The good news is that protecting secrets without an NDA is often possible, but it depends on what you share, who you share it with, and what other legal and practical protections you put in place. In some situations, contract terms, workplace policies, intellectual property ownership clauses, privacy compliance and smart information controls can do much of the heavy lifting. The key is knowing which tool fits which risk before you sign a contract, accept a provider’s standard terms, or rely on a verbal promise.

Overview

You do not always need a standalone non-disclosure agreement to protect confidential information. New Zealand businesses can often rely on a mix of contract clauses, employment obligations, equitable duties of confidence, privacy processes and practical access controls, but those protections work best when they are put in place early and drafted clearly.

  • Identify exactly what information is sensitive, and whether it is confidential information, personal information, intellectual property, or all three.
  • Use confidentiality clauses in service agreements, supply contracts, employment agreements, contractor terms and term sheets where a full NDA is not practical.
  • Limit access on a need-to-know basis, keep records of what was shared, and avoid over-sharing before you sign.
  • Check who owns improvements, work product, data and know-how created during discussions or a project.
  • Make sure your privacy practices, including any privacy notice, cover any personal information you share under the Privacy Act 2020.
  • Do not assume a document label or a verbal understanding will be enough if a dispute comes up later.

When New Zealand Businesses Use NDAs

NDAs are common because they create a clear written rule about secrecy, but they are not the only way to protect business information.

In New Zealand, businesses often use NDAs before investor discussions, software demos, manufacturing conversations, due diligence, agency pitches, joint venture talks and contractor engagements. They can be useful when a business needs to share genuinely sensitive information before a broader contract is signed.

Still, there are plenty of situations where a separate NDA is skipped. Sometimes the parties move fast and include confidentiality clauses in a main agreement instead. Sometimes the relationship is already governed by an employment agreement, consultancy agreement or supplier contract. In other cases, the information is only partly confidential, and the business is better protected through operational controls rather than a formal NDA.

When a standalone NDA may not be necessary

A separate NDA may be unnecessary if the main contract already deals properly with confidentiality. That can work well where the parties are ready to commit to the commercial arrangement and the confidentiality obligation is only one part of the relationship.

Common examples include:

  • a software development agreement that includes confidentiality, intellectual property ownership and data security clauses
  • a contractor agreement that restricts use of internal methods, customer information and pricing data
  • an employment agreement that covers confidential information, post-employment obligations and return of company property
  • a heads of agreement or term sheet that includes a binding confidentiality clause even though the broader deal is still being negotiated

When alternative protections matter most

Alternative protections become especially important when you cannot get the other side to sign an NDA before initial discussions. That happens often with larger customers, corporate procurement teams, investors and some marketplaces or platforms that insist on their own standard terms.

In those moments, the practical question is not “NDA or nothing?”. The better question is what layers of protection you can still create before you share commercially valuable information.

What counts as a secret worth protecting?

Not all information gets the same legal treatment. A rough idea with no supporting detail is harder to protect than a documented process, customer list, recipe, source code base or pricing model that is clearly treated as confidential.

For many SMEs, the information most worth protecting includes:

  • supplier terms and manufacturing specifications
  • product roadmaps and technical documentation
  • software code, designs and internal tools
  • customer lists, sales pipelines and pricing strategies
  • marketing plans and campaign data
  • financial models and margin analysis
  • unreleased commercial proposals

The more specific and commercially valuable the information is, the more important it is to show that you treated it like confidential material in the first place.

If you are protecting secrets without an NDA, the real protection usually sits in the surrounding legal documents and business processes.

That means the best time to sort this out is before you sign a contract, before you accept the provider’s standard terms, and before you send over a data room, product demo or pricing file. Here are the main legal issues to check.

Confidentiality clauses in the main contract

A well-drafted confidentiality clause can do much of the work of an NDA. It should say what information is protected, how it can be used, who can access it, when disclosure is allowed and what happens when the relationship ends.

At a minimum, check whether the clause covers:

  • information disclosed in writing, verbally and visually
  • use of the information only for a defined purpose
  • disclosure only to staff, advisers or subcontractors who genuinely need access
  • security obligations, including reasonable steps to prevent unauthorised disclosure
  • return or deletion of information at the end of the arrangement
  • exceptions, such as material already in the public domain or required disclosures by law

This is where founders often get caught. A short generic confidentiality clause may look fine, but still leave gaps around subcontractors, data storage, product testing or future use of know-how.

Equitable obligations of confidence

New Zealand law can sometimes protect confidential information even without a signed NDA. If information was clearly confidential, shared in circumstances importing confidence, and misused, the business that shared it may have a legal basis to complain.

That said, this route is less certain than having clear written terms. It usually depends on facts, conduct and evidence. If the recipient says the information was vague, already known, or not obviously confidential, the argument becomes much harder.

For business owners, the practical lesson is simple. Do not rely on implied duties where you could create express written terms instead.

Employment agreements and workplace policies

Your own team is often the biggest confidentiality risk, not because staff mean harm, but because access is broad and habits can be loose. Employees may forward documents to personal email accounts, re-use templates, or take know-how into a new role without thinking through the legal consequences.

Employment agreements should clearly deal with confidential information and intellectual property created in the course of employment. Internal policies should also explain what staff can and cannot do with company information.

Useful protections often include:

  • clear definitions of confidential information
  • ownership of work created by employees as part of their role
  • restrictions on unauthorised use or disclosure during employment and after employment ends
  • rules for storing, sharing and deleting files
  • return of devices, access cards, records and documents when employment ends

Post-employment restraints require separate care and must be reasonable to be enforceable, so they should not be used as a substitute for properly drafted confidentiality terms.

Contractor and supplier terms

Independent contractors and external suppliers are a common weak point. Businesses often bring in developers, designers, marketers or manufacturers before proper paperwork is in place, then assume confidentiality is implied.

That is risky. Contractors are not employees, and ownership of work product does not automatically pass to your business just because you paid for it. If a contractor will see internal systems, customer information, plans or prototypes, their agreement should deal with confidentiality, IP ownership, data handling and return of materials.

Before you rely on a freelancer’s template or a supplier’s standard terms, check who can use your information and whether they can subcontract work or retain copies for internal purposes. In many cases, a short contract review can identify gaps before sensitive information is shared.

Intellectual property ownership

Confidentiality and intellectual property often overlap, but they are not the same thing. A secret process may be confidential, while a logo, software code or design asset may also raise copyright or trade mark issues.

If someone helps develop an idea, build a prototype, refine a process or create documents around your concept, ownership should be dealt with directly. Otherwise, you may protect secrecy but still end up in a dispute over who owns the outcome.

Check whether your agreements clearly cover:

  • pre-existing materials each party brings to the project
  • new intellectual property created during the relationship
  • licences to use background tools or templates
  • restrictions on re-using confidential methods or proprietary materials for other clients

Trade mark registration may also be relevant if the “secret” sits partly in brand positioning or a new product identity, but registration does not replace confidentiality.

Privacy Act 2020 obligations

If the information includes personal information, confidentiality alone is not enough. The Privacy Act 2020 may apply to how you collect, use, store and disclose that data.

This matters in founder conversations more often than people expect. A customer list can include personal information. So can employee files, user analytics tied to identifiable people, and due diligence materials with contact details or performance information.

Before you share personal information, think about:

  • whether you have a proper reason to disclose it
  • whether individuals have been told how their information will be used
  • whether you can de-identify or minimise the data first
  • whether the recipient will store it securely, including if information is sent overseas

A confidentiality promise does not override privacy law. You need both angles covered, including broader data protection steps.

Good legal drafting helps, but evidence of careful handling matters too. If a dispute arises, one of the first questions will be whether you actually treated the material as sensitive.

Simple controls can strengthen your position:

  • share only the portion of information needed for the immediate discussion
  • use staged disclosure, with more detail released only after commercial terms are agreed
  • mark documents confidential where appropriate
  • keep a record of what was shared, when and with whom
  • restrict folder access and remove access promptly when talks end
  • avoid sending full customer or pricing databases where a summary will do

These steps are not a legal substitute for written terms, but they often make the difference between a weak claim and a credible one.

Common NDA Mistakes

The biggest mistake is thinking that “no NDA” means “no protection”, or worse, acting as though informal trust is enough.

Businesses usually run into trouble because they share information too early, use the wrong contract, or fail to distinguish between confidentiality, IP ownership and privacy compliance. Here are the mistakes that come up most often.

Sharing too much before terms are agreed

Founders sometimes reveal the key commercial value of a deal in the first conversation. That might be the exact supplier, the margin structure, the algorithm logic or the customer acquisition method.

A better approach is staged disclosure. Share enough to test interest, then release more detail once the purpose, recipient and legal terms are clear.

Assuming “confidential” labels solve the issue

Labelling a file confidential can help show your intention, but it is not magic. If there is no clear legal obligation, no restricted purpose and no evidence of careful handling, the label on its own may not achieve much.

Use labels as one part of a wider system, not as the entire protection plan.

Using a generic clause that does not fit the deal

Not all confidentiality clauses are equal. A clause drafted for a simple supply arrangement may be too light for software development, commercial due diligence or data sharing.

This is especially risky where the recipient can:

  • subcontract work
  • store data with third-party providers
  • use anonymised or aggregated information
  • retain materials for legal or compliance reasons
  • develop similar products for other clients

If the clause does not deal with those real-world points, the business may assume it has more protection than it actually does.

Forgetting to deal with contractors and advisers

Many leaks happen through adjacent parties, not the main counterparty. Accountants, consultants, agencies, offshore developers and manufacturers may all touch sensitive information.

If your contract only binds the main company but says nothing about its staff, subcontractors or advisers, there may be a gap. The same issue comes up internally when businesses rely on informal expectations instead of written employee obligations and policies.

Ignoring ownership of outcomes

Sometimes the most valuable risk is not disclosure, but re-use. You may share methods or ideas in a collaboration, then find the other party has not copied your documents, but has built a similar process using what they learned.

This is why confidentiality should be reviewed alongside intellectual property clauses, licence terms, exclusivity where relevant, and termination rights or restraints on use of materials for purposes outside the relationship.

Overestimating verbal promises

A verbal assurance can help explain the context, but it is much weaker than a clear written clause. Memory differs, personnel change and commercial pressure builds. If the secret matters to your business, get the key terms recorded before you rely on a handshake understanding.

FAQs

Can confidential information be protected without an NDA in New Zealand?

Yes, sometimes. Protection can come from confidentiality clauses in other contracts, employment obligations, contractor terms, privacy processes and equitable duties of confidence. A standalone NDA is often helpful, but it is not the only option.

Is a confidentiality clause in a service agreement enough?

It can be, if it is drafted properly for the actual risks. The clause should define the information, limit use, control access, address return or deletion, and work alongside IP and privacy terms where relevant.

What if I already shared the information before anything was signed?

Your position may still not be lost, especially if the circumstances clearly showed the information was confidential. But enforcement is harder without written terms. You should document what was shared, who received it, what was said at the time, and get legal advice quickly if misuse is a concern.

Do employee agreements cover business secrets automatically?

Not always in a way that is clear enough. Employment agreements should expressly deal with confidential information and IP ownership, and those terms should be backed up by practical policies and access controls.

Does privacy law apply if the “secret” is customer data?

Yes, potentially. If the information identifies individuals, the Privacy Act 2020 may apply to disclosure, use, storage and security. A confidentiality promise does not replace your privacy obligations.

Key Takeaways

  • Protecting secrets without an NDA is possible, but it usually depends on having the right clauses in your main contracts and sensible internal controls.
  • Confidentiality, intellectual property ownership and privacy compliance are related but separate issues, and all three may need attention before you sign.
  • Employment agreements, contractor terms, supplier contracts and term sheets can all help protect sensitive business information if drafted carefully.
  • Practical steps matter, including staged disclosure, limited access, records of what was shared and prompt return or deletion of materials.
  • The main risk is over-sharing too early or relying on a verbal promise when the information is genuinely valuable to your business.

If you want help with confidentiality clauses, contractor terms, intellectual property ownership, privacy obligations, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.