Skip to main content

Confidential Information Definition in Contracts

By Waleed Hamada 11 min read
Confidential Information Definition in Contracts

Understanding Confidential Information Definitions in Contracts

The confidential information definition is the most consequential single provision in any NDA — because it determines what is actually protected. Too broad and courts refuse enforcement. Too narrow and everything you share falls outside it entirely.

Key Takeaways
The confidential information definition determines what is actually protected under an NDA — US courts will not enforce confidentiality for information that falls outside the definition.
Four drafting approaches exist: blanket (“all information”), category-based, mark-as-confidential, and hybrid. The category-based or hybrid approach is market standard.
Four standard carve-outs must appear in every definition: public domain information, independently developed information, third-party received information, and legally required disclosures.
Trade secrets are a legally distinct subset of confidential information — protectable indefinitely under the Defend Trade Secrets Act; general confidential information is typically protected for 2–5 years under contract.
Legal Chain generates correctly scoped confidential information definitions — calibrated for the specific document type and US jurisdiction — in every NDA it drafts.
Quick Answer

The confidential information definition in a contract specifies exactly what information the receiving party must keep secret. It is the foundation of any NDA — because courts will not enforce confidentiality obligations for information outside the definition, regardless of intent. Too broad and enforcement fails. Too narrow and information is unprotected. The market-standard approach is a category-based definition with four standard carve-outs. Legal Chain drafts correctly scoped definitions for all 50 US states — free at legalcha.in/beta.

A business professional reviewing the confidential information definition in an NDA contract to ensure the definition covers the right categories of information including financial data technical specifications customer lists business plans and product roadmaps while including the four standard carve-outs for public domain independently developed third-party received and legally required disclosures under US contract law

Every NDA contains a confidential information definition. Whether that definition actually protects the information you share depends on its scope, its specificity, and whether it includes the standard carve-outs that courts expect to see. Photo: Unsplash / Helloquence

Why the Confidential Information Definition Is the NDA’s Most Important Provision

Most NDA drafting attention focuses on the length of the confidentiality obligation, the survival period, and the remedies for breach. These matter — but none of them matter if the information in question does not fall within the definition of confidential information in the first place.

US courts apply a strict threshold: the receiving party owes a confidentiality obligation only for information that falls within the contract’s definition. Information disclosed during the relationship but outside the definition creates no obligation. If a vendor shares its proprietary pricing model with a customer under an NDA and the pricing model does not fall within the NDA’s definition — perhaps because it is not in writing and the definition requires written designation — the customer may disclose it without any contractual liability.

The definition is the foundation of the entire agreement. Everything else depends on it working correctly.

The Four Approaches to Defining Confidential Information

01
Blanket definition — “all information shared”
⚠ Overbreadth risk
Defines confidential information as all information disclosed by one party to the other, in any form, through any channel. Simple to draft, impossible to practically administer. Courts in California, New York, and several other US states have refused to enforce blanket definitions as overbroad — because they impose obligations that are practically unworkable (treating every casual conversation as legally protected) and that may cover information the disclosing party has no legitimate interest in protecting. Highest enforcement risk; not recommended for commercial NDAs.
02
Category-based definition
✓ Market standard
Lists specific categories of protected information — financial data, technical specifications, customer and prospect lists, business plans, product roadmaps, employee information, trade secrets, and other named categories — and defines confidential information as information falling within those categories. Provides specific notice to the receiving party of what is protected. Courts respond well to category-based definitions because they are administrable and targeted. The risk is that information not fitting a named category is unprotected — requiring careful selection of categories that match the actual information likely to be shared.
03
Mark-as-confidential definition
Limited scope
Defines confidential information as only that information specifically marked or designated as confidential in writing at the time of disclosure — or confirmed as confidential in writing within a specified period after oral disclosure. Provides maximum certainty about what is protected, but creates operational risk: information shared without marking may be unprotected, and parties often fail to mark consistently in practice. Most appropriate for technical and IP-heavy relationships where the disclosing party can reliably identify and mark what it considers confidential at the time of disclosure.
04
Hybrid definition — categories plus catch-all
✓ Market standard
Combines category-based protection (named categories are protected without marking) with a catch-all for information designated as confidential in writing at the time of disclosure. The category-based component covers the most important information automatically. The catch-all allows protection of additional information that falls outside the named categories, provided the disclosing party marks it. This approach provides both certainty (for important categories) and flexibility (for edge cases) — and is the most defensible definition format in most US jurisdictions.

Example: Category-Based Confidential Information Definition

Category-based definition — market-standard example

“Confidential Information” means any and all non-public information disclosed by one party (the “Disclosing Party”) to the other party (the “Receiving Party”), whether disclosed orally, in writing, electronically, or by any other means, that relates to: (a) financial information, including revenues, costs, projections, and pricing; (b) technical information, including source code, algorithms, product specifications, and system architecture; (c) business information, including customer lists, prospect lists, business plans, marketing strategies, and partnership arrangements; (d) personnel information, including employee compensation and performance data; and (e) any other information that the Disclosing Party designates as confidential in writing at the time of disclosure. Confidential Information does not include information that: (i) is or becomes publicly known through no act or omission of the Receiving Party; (ii) was rightfully known by the Receiving Party prior to disclosure without any obligation of confidentiality; (iii) is rightfully received by the Receiving Party from a third party without restriction on disclosure; or (iv) is required to be disclosed by applicable law or court order, provided that the Receiving Party provides prompt written notice to the Disclosing Party and cooperates with the Disclosing Party’s efforts to seek a protective order.

A startup founder working with their legal team to review and refine the confidential information definition in their company NDA ensuring it uses a category-based approach listing financial data technical specifications customer lists business plans and product roadmaps with a catch-all for information designated in writing and the four standard carve-outs for public domain independently developed third-party received and legally required disclosures

The example definition above is a hybrid approach: five named categories of information protected automatically, plus a catch-all for information marked in writing. The four carve-outs follow immediately, narrowing the definition to information the disclosing party actually has a legitimate interest in protecting. Legal Chain generates definitions in this structure, calibrated for the specific US jurisdiction and document type. Photo: Unsplash / Mimi Thian

The Four Standard Carve-Outs Every Definition Must Include

01
Public domain — information already publicly known

Information that is publicly available at the time of disclosure, or that enters the public domain after disclosure through no act or omission of the receiving party, is not confidential. This carve-out prevents the definition from imposing obligations on information anyone could find — and from creating liability when information becomes public through third parties or through the disclosing party’s own actions. The “through no act or omission” qualifier is essential: if the receiving party causes the information to become public, the carve-out does not apply.

02
Independent development — information developed without reference to the disclosure

Information independently developed by the receiving party without reference to or use of the disclosing party’s confidential information is not subject to the confidentiality obligation. This carve-out protects the receiving party’s right to develop its own information — including information that may resemble what the disclosing party shared, provided it was developed independently. The receiving party typically bears the burden of demonstrating independence of development, which is why internal records of development timelines and sources are valuable in a dispute.

03
Third-party disclosure — information received without confidentiality restrictions

Information rightfully received by the receiving party from a third party who is not bound by any confidentiality obligation with respect to that information is not confidential under the agreement. This carve-out prevents the definition from imposing obligations on information the receiving party legitimately acquired from another source — provided the third-party source was entitled to disclose it. If the third party received the information from the disclosing party under a confidentiality obligation, this carve-out does not apply.

04
Legally required disclosure — law, court order, or government authority

Information required to be disclosed by applicable law, valid court order, or government authority is excepted from the confidentiality obligation — provided the receiving party gives prompt written notice to the disclosing party before disclosure (where legally permitted) and cooperates with the disclosing party’s efforts to seek a protective order. The notice requirement is essential: it gives the disclosing party the opportunity to challenge the compelled disclosure before it occurs, rather than learning about it after the fact.

Confidential Information vs Trade Secret: The Practical Difference

Dimension Confidential information (contract) Trade secret (DTSA + state law)
Source of protection Contract (NDA or confidentiality agreement) Statute — Defend Trade Secrets Act (federal) + state trade secret laws
Threshold for protection Falls within the contractual definition — no independent legal standard required Must derive economic value from secrecy; owner must take reasonable steps to maintain secrecy
Duration of protection Typically 2–5 years post-termination for general information under market-standard NDAs Indefinite — for as long as the information remains secret and the owner maintains reasonable security
Remedies for misappropriation Contract remedies — damages, injunction (if the NDA includes injunctive relief provision) DTSA remedies — injunction, damages (including unjust enrichment), exemplary damages for willful misappropriation, attorney’s fees
Requirement for prior disclosure Protection is triggered by disclosure under the NDA — prior disclosure to the receiving party under the agreement No contractual relationship required — trade secret protection arises from the information’s nature and the owner’s security measures
Interaction Best practice: NDA definitions should explicitly include trade secrets within the category-based definition, ensuring contractual and statutory protection overlap for the highest-value information

“The confidential information definition does not just determine what is protected — it determines whether the NDA has any practical value at all. An NDA with a blanket definition that courts will not enforce, or a category-based definition that excludes the information actually shared, is a document that creates the appearance of protection without providing it.”

Frequently Asked Questions

What is a confidential information definition in a contract?+
The provision in an NDA or confidentiality agreement specifying exactly what information the receiving party must keep secret. Courts enforce confidentiality obligations only for information within the definition — information outside it creates no obligation. The definition is the foundation of the entire NDA. Four drafting approaches exist: blanket (“all information” — overbreadth risk), category-based (named categories — market standard), mark-as-confidential (written designation required — limited scope), and hybrid (categories plus catch-all — market standard).
What are the standard exceptions to a confidential information definition?+
Four carve-outs must appear in every definition: public domain information (available before or becoming available after disclosure through no fault of the receiving party); independently developed information (developed without reference to the disclosing party’s information); third-party received information (from a source not bound by confidentiality); and legally required disclosures (by law or court order, with advance notice to the disclosing party where permitted). Without these carve-outs, courts may refuse enforcement as overbroad.
Should a confidential information definition be broad or specific?+
Category-based or hybrid — not blanket broad. A blanket definition covering “all information shared” faces overbreadth challenges in California, New York, and other jurisdictions. A definition that is too specific may leave actually-shared information unprotected. Market standard is a category-based definition listing the specific types of information likely to be shared (financial, technical, customer, personnel) combined with a catch-all for information designated in writing. Legal Chain generates definitions in this structure for any US jurisdiction — free at legalcha.in/beta.
What is the difference between confidential information and a trade secret?+
Trade secrets are a legally distinct subset of confidential information — protectable under the Defend Trade Secrets Act (DTSA) and state statutes, without a contract, indefinitely, provided the information derives economic value from secrecy and the owner takes reasonable security measures. General confidential information under a contract is broader: any information within the NDA’s definition is protected, regardless of whether it meets the trade secret threshold — but only for the contract’s survival period (typically 2–5 years). Best practice: include trade secrets explicitly in the NDA’s category-based definition for overlapping protection.

Generate correctly scoped confidential information definitions. Free.

Category-based or hybrid approach. Four standard carve-outs included. Trade secret protection language applied. Jurisdiction-calibrated for all 50 US states. Any NDA type — mutual or unilateral. No credit card required.

Try Legal Chain Today

Disclaimer
This article is published for general informational purposes only and does not constitute legal advice. Confidential information definition scope and enforceability vary by US jurisdiction and specific facts. Legal Chain is a technology platform and is not a law firm. Use of Legal Chain does not create an attorney-client relationship. For NDAs involving trade secrets, employee matters, or significant business relationships, consult a licensed attorney. Legal Chain currently supports US jurisdictions only.

5 1 vote
Article Rating

Leave a Reply

0 Comments
Oldest
Newest Most Voted

Discover more from Legal Chain

Subscribe to get the latest posts sent to your email.

Ready to get started?

Try Legal Chain Free Today

Draft, analyze, and protect your contracts with AI. No credit card required.

View pricing Legal Chain is a technology platform. Not legal advice.

0
Would love your thoughts, please comment.x
()
x