Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
Many New Zealand founders know they should “get an NDA signed”, but the real issue is knowing when an NDA actually helps, when it is overkill, and what mistakes make it useless. A common problem is sharing sensitive plans too early, relying on a template that does not match the deal, or assuming an NDA will automatically stop someone from using your ideas. Another frequent mistake is signing the other side’s confidentiality agreement without checking whether it is one sided, too broad, or hard to comply with in practice.
Using NDAs wisely means treating them as one tool in a bigger risk management plan, not a magic fix. The right agreement can protect pricing models, product roadmaps, customer lists, technical know how and deal discussions. The wrong agreement can slow a deal down, create false confidence, or leave obvious gaps. This guide explains when New Zealand businesses should use confidentiality agreements, what to check before you sign, and the mistakes that often catch founders before they realise where the risk really sits.
Overview
An NDA, or non-disclosure agreement, is a contract that sets rules for how confidential information can be used and shared. It can be very useful before due diligence, supplier discussions, pilot projects, contractor engagements and strategic talks, but it works best when the information is genuinely confidential and the agreement is tailored to the situation.
The strongest NDA is usually clear, practical and backed up by sensible internal processes. If your team cannot identify what is confidential, who can access it, and what happens when the project ends, the document alone will not do much heavy lifting.
- Check exactly what information is covered and whether the definition is too vague or too wide.
- Confirm who can receive the information, including employees, contractors, advisers and related companies.
- Look at the permitted purpose, so the recipient cannot use the information for side purposes.
- Review how long confidentiality obligations last and whether the period makes commercial sense.
- Check the exceptions, especially for information already known, public information, or material required to be disclosed by law.
- Make sure return or destruction obligations are realistic, especially if documents are stored in backups or shared systems.
- Consider whether the NDA needs extra protections, such as intellectual property clauses, non-solicitation terms, or restraint wording.
- Check what happens if there is a breach, including injunction wording, indemnities and dispute resolution clauses.
When New Zealand Businesses Use NDAs
New Zealand businesses usually use NDAs when they need to share genuinely sensitive information before trust has fully formed and before the main contract is signed. The key question is not whether an NDA sounds formal, it is whether the disclosure creates a real commercial risk if the information is misused.
Investor and capital raising discussions
Founders often assume every investor meeting should begin with an NDA. In reality, many professional investors will not sign one at an early stage, especially if they see many similar pitches and want to avoid later disputes about overlapping ideas.
That does not mean confidentiality is irrelevant. It means founders should be selective about what they disclose early. High level pitch information may be enough at first, while deeper commercial, financial or technical details can wait until discussions become serious.
If you are entering a detailed due diligence process, especially with a strategic investor or buyer, an NDA becomes much more useful. At that point, you may be sharing information such as:
- financial models and forecasts
- customer concentration data
- supplier terms and margins
- product development plans
- source code access or technical architecture
- proposed deal terms
Supplier, manufacturer and outsourcing negotiations
An NDA is often sensible before you share product specifications, manufacturing methods, formulas, pricing frameworks or planned market strategy with a supplier. This is especially true where the supplier could use your information to compete with you, approach your customers, or repackage the idea for another client.
This is where founders often get caught. They send detailed design packs or confidential costings before they sign anything, then discover the supplier has broad rights under its own standard terms or no clear confidentiality obligations at all.
Before you accept the provider's standard terms, check whether confidentiality is already covered. Sometimes a broader services agreement or manufacturing agreement includes enough protection. Sometimes it does not.
Contractor and consultant engagements
Freelancers, developers, designers, marketing agencies and specialist consultants regularly receive sensitive business information. An NDA can be helpful, but it should usually sit alongside a broader services contract.
That broader contract often needs to cover more than secrecy. It may need to deal with intellectual property ownership, deliverables, payment terms, privacy obligations, subcontracting and termination rights. If you only use an NDA, you may protect the information but still leave ownership of the work product unclear.
Potential sale of a business or assets
Confidentiality agreements are standard in sale discussions because buyers may ask for deeply sensitive information well before any sale is guaranteed. This can include customer lists, employee structures, software documentation, margins, lease details and key commercial contracts.
A well drafted NDA can restrict use of that information to evaluating the transaction, stop the buyer from contacting staff or customers without consent, and require information to be returned if the deal falls over. Those points matter because the buyer may also be a competitor.
Joint ventures, collaborations and pilot projects
Businesses often share know how before signing a full collaboration agreement. An NDA can buy time while the parties work out whether the project is viable.
Still, an NDA does not answer every ownership question. If both sides will contribute ideas, data, methods or prototypes, you may need separate clauses dealing with:
- who owns pre existing intellectual property
- who owns improvements and new material created during the project
- whether either side can use the output outside the project
- whether exclusivity applies in a particular market or sector
Employment and senior hire situations
Employment agreements in New Zealand often include confidentiality obligations already. For senior hires, founders sometimes use a standalone NDA during recruitment, especially if strategic plans or commercially sensitive information will be shared before the person joins.
The main point is consistency. Your NDA should not contradict the employment agreement, contractor agreement or shareholder arrangements that follow. Otherwise, you create confusion about which terms apply.
Legal Issues To Check Before You Sign
Before you sign a confidentiality agreement, make sure it matches the real flow of information and the real risk in the deal. The legal wording matters, but the practical detail matters just as much.
What counts as confidential information
The definition of confidential information is one of the most negotiated parts of an NDA. If it is too narrow, important material may fall outside the agreement. If it is too broad, the receiving party may be unable to comply or may push back hard.
A good definition often covers information disclosed in writing, verbally, visually or electronically, as long as it is reasonably identifiable as confidential. Some businesses want every disclosure marked confidential, but that can fail in fast moving discussions where sensitive information is shared in calls or meetings.
Before you sign, think about whether the agreement should cover:
- business plans and strategy
- pricing, margins and forecasts
- customer and supplier information
- software, code, algorithms or technical methods
- research, prototypes and product specifications
- the existence and status of the discussions themselves
Permitted purpose
The agreement should say exactly why the recipient can use the information. Without a clear permitted purpose, the recipient may argue they can use the material more broadly than you expected.
For example, if the purpose is to evaluate a proposed supply arrangement, the NDA should not let the recipient use your technical information to improve its own offering or pitch to another client. This sounds obvious, but vague wording often creates room for argument later.
Who can access the information
Most businesses need to share confidential material internally with key staff and external advisers. The NDA should allow that, but only on a need to know basis and with suitable controls.
Check whether the recipient can share the information with:
- employees
- contractors
- related companies
- lawyers and accountants
- potential funders or subcontractors
If the list is too wide, your information can travel far beyond the people you expected. If the list is too narrow, the deal may become unworkable.
Time period and survival
Not every NDA should last forever. Some information loses value quickly. Other information, such as formulas, source code or strategic pricing methods, may justify a longer confidentiality period.
In many commercial situations, a period of two to five years is common, but the right period depends on the nature of the information and the industry. Trade secrets and enduring proprietary know how may need stronger, longer protection.
Exceptions to confidentiality
Reasonable exceptions stop an NDA from becoming unfair or impossible to comply with. Common exceptions cover information that:
- is already lawfully known by the recipient
- becomes public through no breach of the agreement
- is received lawfully from another source
- must be disclosed by law, court order, stock exchange rules or a regulator
These exceptions should be drafted carefully. A broad exception can hollow out the whole agreement.
Return, destruction and practical control
Many NDAs say all confidential information must be returned or destroyed on request or when discussions end. That sounds simple, but cloud storage, email trails, backups and collaborative tools make it harder in practice.
The clause should be realistic about what can be deleted, what may remain in secure backups, and who must certify destruction. If you are the recipient, avoid promises your systems cannot actually meet.
Intellectual property and ownership boundaries
An NDA protects secrecy, but it does not automatically transfer ownership of ideas, inventions or work product. Businesses often miss this point.
If the project involves development work, shared designs or technical input, check whether you also need written terms dealing with intellectual property ownership, licences, improvements and moral rights consents. Otherwise, you may preserve confidentiality while still arguing later about who owns what.
Enforcement and dispute risk
If a breach would cause serious harm, the agreement should support practical enforcement. That may include wording that recognises the right to seek urgent court orders to stop disclosure.
Still, enforcement is not only about legal remedies. Keep records of what was shared, when it was shared, and who received it. If you ever need a contract review to assess misuse or gaps, those records matter.
Common NDA Mistakes
The most common NDA mistakes happen before you rely on a verbal promise and before you sign the other side’s template without reading the details. A confidentiality agreement only works well when the document, the disclosure process and the commercial reality all line up.
Using an NDA where a fuller contract is needed
Founders sometimes use an NDA as a shortcut when the relationship really calls for a services agreement, development agreement or heads of terms. The NDA may cover secrecy, but not payment, ownership, timelines, acceptance criteria, liability or exit rights.
The main risk is false confidence. You think the deal is covered because a document is signed, but the key business terms are still missing.
Disclosing too much before the NDA is signed
This sounds basic, but it happens all the time. A founder wants to move quickly, sends the deck, the product roadmap, the costing sheet and the customer pipeline, then asks for the NDA afterwards.
Once the information is already out, the NDA cannot always fix the problem. Share in stages where possible. Start with enough information to advance the discussion, then increase the detail once the paperwork is in place.
Assuming an NDA protects ideas in the abstract
New ideas alone are hard to protect through an NDA if they are expressed at a high level and could be independently developed by someone else. Confidentiality agreements work best for specific information that is not public and has been shared in confidence.
If the real value lies in branding, software, designs, content or inventions, you may need additional protection such as trade mark registration, copyright ownership clauses, or other intellectual property arrangements. The NDA is only one piece of the picture.
Accepting one sided or unworkable terms
Some NDAs are drafted heavily in favour of the disclosing party. That may be acceptable if only one side is sharing information, but not always. If the obligations are impossible to comply with, the document creates risk rather than managing it.
Watch for clauses that:
- make you responsible for every act of every affiliate, adviser or contractor without limit
- require deletion of all backup data where your systems cannot do that
- ban any use of residual know how retained in employees' memory
- impose very long confidentiality periods for information with short commercial life
- include broad indemnities that are out of proportion to the deal
Forgetting privacy and data handling issues
Some confidential information is also personal information. If customer, employee or user data is being shared, the Privacy Act 2020 may also be relevant. An NDA does not replace privacy compliance or a proper privacy notice where one is required.
Before you sign, check whether personal information will be disclosed, why it is necessary, and whether the sharing is permitted. In some cases, anonymising or aggregating data is safer than sharing raw datasets.
Not aligning the NDA with other deal documents
If the NDA says one thing and the later supply agreement, SaaS agreement, employment agreement or term sheet says another, the parties may argue over which document governs. This is common where confidentiality clauses are copied from old templates.
Make sure the documents fit together on issues such as ownership, permitted use, term, return of information and dispute process. Small inconsistencies can create expensive confusion.
Ignoring internal processes
Even a well drafted NDA will not help much if your team forwards sensitive documents freely or stores them in open folders. Businesses often focus on the paper and forget the workflow.
Simple internal controls can reduce risk significantly, such as:
- marking key documents confidential
- limiting access to need to know staff
- keeping disclosure logs during due diligence
- using secure data rooms for larger transactions
- having a clear sign off process before sensitive material is shared
FAQs
Do all business discussions need an NDA?
No. An NDA is most useful where you need to share genuinely sensitive information and there is a real risk of misuse. Early conversations can often proceed with limited disclosure instead.
Is a one way or mutual NDA better?
It depends on who is sharing information. A one way NDA suits situations where only one party is disclosing confidential material. A mutual NDA is more appropriate where both sides will exchange sensitive information.
Can an NDA protect my business idea?
Sometimes, but only to a point. An NDA protects confidential information shared in confidence. It does not automatically give you ownership rights over broad concepts or stop independent development.
How long should an NDA last in New Zealand?
There is no single required period. Many commercial NDAs use a term of two to five years, but the right duration depends on the type of information, how long it stays valuable, and whether trade secret style protection is needed.
What if the other side refuses to sign an NDA?
You can still manage risk by limiting what you disclose, staging the discussion, withholding the most sensitive details until later, and using a fuller contract once the relationship becomes more concrete. In some situations, that is a normal commercial outcome rather than a red flag.
Key Takeaways
- Using NDAs wisely means using them where there is real confidentiality risk, not as a reflex in every conversation.
- A useful NDA clearly defines the confidential information, permitted purpose, recipients, exceptions, duration and return or destruction process.
- An NDA does not replace other legal documents where you also need terms about intellectual property, services, payment, liability or privacy.
- Founders often get caught by disclosing too much too early, relying on generic templates, or signing one sided terms without checking how they work in practice.
- Good internal controls matter just as much as the wording, especially during due diligence, supplier negotiations and contractor engagements.
- If you are reviewing or negotiating using ndas wisely and want help with confidentiality agreements, intellectual property clauses, privacy issues, or supplier and contractor contract terms, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.







