How Do I Protect My Business with Non-Disclosure Agreements in South Africa?

    Reading Time: 16min

    12 November 2025

You’re about to share sensitive business information with a potential investor, a new employee, a contractor, or a prospective business partner. You know this information could potentially damage your business if it fell into the wrong hands, but you need to share it to move forward. How do you protect yourself?

Enter the non-disclosure agreement (NDA), also called a confidentiality agreement. This seemingly simple document is one of the most powerful tools for protecting your business’s valuable information. But like any legal instrument, it only works if you understand how to use it properly. Let’s explore how NDAs protect South African businesses and how to implement them effectively.

What Is a Non-Disclosure Agreement?

A non-disclosure agreement is a legally binding contract where one or more parties agree not to disclose or use any confidential information shared between them, without the other’s express consent and in line with clear parameters. It creates a legal obligation to keep specific information confidential at all times and establishes consequences for breaching that obligation.

The Core Purpose

An NDA aims to serve several crucial functions:

1. Legal protection: Create enforceable obligations not to disclose sensitive information.

2. Define confidential information: Clearly establish what information is protected and what is not protected. The more comprehensive the definition is, the more protection it offers and alleviates any gaps for issues later on.

3. Set boundaries: Specify how information can and cannot be used.

4. Establish consequences: Define what happens if someone breaches any terms under the NDA.

5. Demonstrate seriousness: Show that you take confidentiality seriously, encouraging compliance.

6. Provide remedies: Give you legal recourse if confidentiality is breached.

Types of Non-Disclosure Agreements

NDAs come in different formats depending on who’s sharing information:

1. Unilateral (One-Way) NDAs

One party discloses information to another who agrees to keep it confidential on behalf of the discloser.

Common scenarios:

  • Employer and employee (employer shares business information);
  • Business and contractor (you share information about your operations);
  • Business and potential investor (you share financial information); and
  • During procurement (you share requirements with potential suppliers).

Structure: “Party A will share confidential information with Party B. Party B agrees not to disclose or misuse this information.”

2. Bilateral (Mutual or Reciprocal) NDAs

Both parties will share confidential information with each other, and both agree to protect it.

Common scenarios:

  • Business partnership discussions (both parties share information);
  • Joint venture negotiations;
  • Merger and acquisition discussions;
  • Strategic alliance negotiations; and
  • Collaborative development projects.

Structure: “Both parties will share confidential information. Both parties agree to protect each other’s confidential information.”

3. Multilateral NDAs

Three or more parties are involved, with various information-sharing arrangements.

Common scenarios:

  • Consortium projects;
  • Multiple-party joint ventures; and
  • Industry collaborations.

Structure: “All parties may share confidential information with each other and agree to protect all parties’ information.”

What Information Should You Protect with NDAs?

Not everything needs an NDA, but many types of business information deserve protection:

Trade Secrets

  • Formulas, recipes, processes;
  • Manufacturing methods;
  • Product designs and specifications;
  • Software source codes and sequences; and
  • Proprietary algorithms.

Example: Your unique recipe for a beverage, a special manufacturing process that gives you a competitive advantage, or software you’ve developed.

Business Information

  • Customer/client lists and databases;
  • concepts, materials, ideas;
  • Supplier and service provider information and pricing;
  • Business strategies and plans;
  • Marketing strategies and campaigns;
  • Pricing structures and methodologies; and
  • Financial information and projections.

Example: Your detailed customer database with contact information, purchase history, and preferences, valuable information competitors would love to have.

Technical Information

  • Research and development data;
  • Technical specifications;
  • Engineering drawings;
  • Test results and analyses; and
  • Prototypes and samples.

Example: Technical specifications for a new product you’re developing before patent applications are filed.

Commercial Information

  • Contract terms with customers, clients or suppliers;
  • Tender applications and information;
  • Negotiation strategies; and
  • Terms of deals being negotiated.

Example: The pricing and terms you’ve negotiated with a key supplier that give you a competitive advantage.

Strategic Information

  • Business expansion plans;
  • Investment or funding pitches and plans;
  • Acquisition targets;
  • Partnership opportunities; and
  • Market entry strategies.

Example: Your plans to enter a new market or acquire a competitor, information that could be exploited by others if disclosed prematurely.

Personal Information

  • Employee personal information;
  • Customer/client personal data (subject to POPIA); and
  • Sensitive information about individuals.

Note: Protection of Personal Information Act (POPIA) imposes additional obligations for personal information beyond NDAs.

Key Elements of an Effective NDA

A strong NDA should include these essential components:

1. Clear Definition of Confidential Information

Precisely define what information is protected. This can be done through:

Specific identification: “Confidential Information means the business plan dated [date], the customer database provided on [date], and the product specifications marked ‘Confidential’.”

Category description: “Confidential Information includes all technical, commercial, financial, and strategic information relating to the Disclosing Party’s business, operations, customers, suppliers, and products.”

Marking requirement: “Confidential Information means any information marked as ‘Confidential,’ ‘Proprietary,’ or similar designation.”

Best practice: Combine approaches, define categories broadly, but require marking for physical documents and explicit designation for verbal disclosures.

2. Exclusions from Confidential Information

Specify information that does not form part of the confidentiality terms and definitions to avoid potential disputes. Standard exclusions:

Information that:

  • Was already public knowledge before disclosure;
  • Becomes public knowledge through no fault of the receiving party;
  • Was already known to the receiving party before disclosure;
  • Is independently developed by the receiving party without using confidential information;
  • Is rightfully received from a third party without confidentiality obligations; and
  • Must be disclosed by law or court order.

Example clause: “Confidential Information does not include information that: (a) is or becomes publicly available through no breach of this agreement; (b) was rightfully in the Recipient’s possession before disclosure; (c) is independently developed by the Recipient; or (d) is received from a third party without confidentiality obligations.”

3. Obligations of the Receiving Party

Clearly state what the recipient must (and must not) do:

Must:

  • Keep information confidential;
  • Use reasonable security measures to protect it;
  • Limit access to those with a need to know;
  • Return or destroy information when requested; and
  • Notify the disclosing party of any unauthorised disclosure.

Must not:

  • Disclose information to third parties without permission;
  • Use information for any purpose other than the agreed purpose;
  • Copy or reproduce information beyond what’s necessary; and
  • Reverse engineer products or processes (if applicable).

Example clause: “The Recipient shall: (a) maintain the Confidential Information in strict confidence; (b) not disclose it to any third party without prior written consent; (c) use it only for the Purpose; (d) protect it with the same degree of care used for its own confidential information, but not less than reasonable care; and (e) limit access to employees, contractors, or advisors who need to know and who are bound by similar confidentiality obligations.”

4. Permitted Uses

Specify the purpose for which information can be used:

Example: “The Recipient may use the Confidential Information solely to evaluate a potential business partnership with the Disclosing Party and for no other purpose.”

Be specific about permitted uses to prevent misuse under the guise of a legitimate purpose.

5. Duration of Confidentiality

How long must information remain confidential?

Common durations:

  • 2-3 years: Standard for general business information;
  • 5 years: Longer protection for more sensitive information;
  • Indefinitely: For true trade secrets that remain valuable; or
  • Until public: Protection continues until information becomes public through legitimate means.

Example clause: “The confidentiality obligations shall continue for a period of three years from the date of disclosure, except for information that constitutes a trade secret, which shall remain confidential indefinitely or until it becomes public through no fault of the Recipient.”

Practical consideration: Longer isn’t always better. Courts may view indefinite terms suspiciously for ordinary business information. Match duration to the legitimate lifespan of the information’s value.

6. Return or Destruction of Information

What happens to confidential materials when the relationship ends?

Example clause: “Upon termination of this agreement or upon request by the Disclosing Party, the Recipient shall promptly return or destroy all Confidential Information and certify in writing that it has done so, except for one copy which may be retained for legal compliance purposes.”

7. Remedies for Breach

Specify consequences for breaching confidentiality:

Injunctive relief: The right to get a court order stopping further disclosure.

Damages: Monetary compensation for losses caused by breach.

Specific remedies: Any other agreed consequences.

Example clause: “The Recipient acknowledges that breach of this agreement would cause irreparable harm to the Disclosing Party for which damages alone would be an inadequate remedy. Accordingly, the Disclosing Party shall be entitled to seek injunctive relief in addition to any other remedies available at law or in equity.”

Consider adding: Pre-agreed damages or penalties for breach (as discussed in our penalty vs liquidated damages guide), though these must be reasonable to be enforceable.

8. Governing Law and Jurisdiction

Specify which law applies and which courts have jurisdiction:

Example clause: “This agreement shall be governed by the laws of South Africa. The parties submit to the non-exclusive jurisdiction of the High Court of South Africa.”

When to Use NDAs: Common Business Scenarios

1. Hiring Employees

Timing: Before sharing sensitive information during recruitment, and as part of employment contracts.

What to protect: Business operations, customer lists, product information, strategic plans.

Considerations: Employment contracts should include comprehensive confidentiality and non-disclosure clauses. Standalone NDAs may be useful during recruitment before formal employment begins and before any interviews are conducted with potential employees.

2. Engaging Contractors and Service Providers

Timing: Before contractors start work and access sensitive information.

What to protect: Business processes, customer information, proprietary methods, any information they’ll access.

Considerations: Contractors often work for multiple clients and may inadvertently share information. NDAs are crucial before you share anything with them or start any project or job with them.

Example: IT contractors accessing your systems, marketing consultants seeing your strategies, accountants reviewing financial information.

3. Investor Discussions

Timing: Before sharing financial information, business plans or pitches, or strategic details with potential investors.

What to protect: Financial performance, projections, business strategies, intellectual property, customer information.

Considerations: Investors often evaluate multiple opportunities. Your NDA should prevent them from sharing your information with your competitors or using it to compete with you instead.

4. Business Partnership or Joint Venture Discussions

Timing: At the start of discussions, before detailed information is shared.

What to protect: All strategic, technical, and commercial information that both parties will share.

Considerations: Use mutual NDAs since both parties will likely share sensitive information with each other.

5. Merger and Acquisition Negotiations

Timing: Immediately, before any due diligence begins.

What to protect: Comprehensive business information, financial records, customer contracts, and employee information.

Considerations: M&A discussions involve extensive information sharing and investigations. Detailed NDAs are essential, often with specific provisions for deal-related disclosures.

6. Customer and Supplier Relationships

Timing: When sharing information beyond standard commercial details.

What to protect: Pricing structures, special terms, proprietary processes, collaborative development information.

Considerations: Many businesses overlook NDAs with customers and suppliers, but they can be important when sharing sensitive information.

7. Product Development Collaborations

Timing: Before discussing technical details or sharing specifications.

What to protect: Technical specifications, designs, development information, and intellectual property.

Considerations: Mutual NDAs are typical. Address ownership of concepts, strategies, ideas, and developments arising from the collaboration.

Drafting Tips: Making Your NDA Enforceable

1. Be Specific But Not Overly Broad

Too broad: “All information disclosed by either party”.

Better: “Technical specifications, customer data, and pricing information relating to [specific project/product]”.

Why it matters: Overly broad NDAs may be unenforceable or difficult to enforce. Courts want to see that you’ve genuinely identified confidential information, not just cast a net over everything.

2. Use Clear, Plain Language

Avoid unnecessary legal jargon. Modern contracts should be understandable to the people who must comply with them.

Legal jargon: “The recipient undertakes and covenants to maintain in strictest confidence and not divulge, disseminate, or otherwise communicate…”

Plain language: “The recipient agrees to keep confidential and not disclose…”

3. Tailor to Your Situation

Don’t use generic templates without customisation. Consider:

  • What specific information are you protecting?
  • Who are you sharing it with, and what’s their relationship to you?
  • What’s the purpose of sharing the confidential information?
  • What are the realistic restrictions and duration that should apply in the NDA?

4. Address Subcontractors and Employees

If the recipient may need to share information with their employees or subcontractors:

Example clause: “The Recipient may disclose Confidential Information to its employees, contractors, and professional advisors who have a legitimate need to know, provided that such persons are bound by confidentiality obligations at least as stringent as those in this agreement, and the Recipient remains responsible for their compliance.”

5. Include a Severability Clause

Ensure that if one provision is unenforceable, the rest remains valid:

Example: “If any provision of this agreement is found to be unenforceable, the remaining provisions shall continue in full force and effect.”

6. Consider POPIA Compliance

If the information includes personal data, ensure your NDA and information handling comply with the Protection of Personal Information Act:

Example clause: “To the extent that Confidential Information includes Personal Information as defined in the Protection of Personal Information Act, both parties shall process such information in compliance with POPIA and shall implement appropriate technical and organisational measures to protect it.”

7. Digital Information Considerations

Modern information is predominantly digital. Address:

  • Electronic storage and transmission security;
  • Encryption requirements;
  • Access controls;
  • Backup and deletion procedures; and
  • Cloud storage restrictions.

Implementing NDAs Effectively

Having an NDA is one thing; using it effectively is another.

Best Practices for Using NDAs

1. Use them early: Get NDAs signed before sharing confidential information, not after. Once information is disclosed, it may be too late to protect your sensitive and confidential information.

2. Keep a register: Maintain a log of who has signed NDAs, what information was shared, and when NDAs expire (if applicable).

3. Mark documents clearly: Label confidential documents as “Confidential” or “Proprietary.” This supports your claim that information was treated as confidential.

4. Limit access: Only share information with people who genuinely need it and who have signed NDAs.

5. Use secure transmission: Email encryption, password-protected files, secure file-sharing platforms for digital information.

6. Train your team: Ensure employees understand confidentiality obligations and procedures for handling sensitive information.

7. Monitor compliance: Periodically review whether confidential information is being properly protected.

8. Follow your own procedures: If your NDA specifies certain security measures, actually implement them. Failure to follow your own procedures weakens enforcement.

What to Do If Your NDA Is Breached

If someone violates your NDA:

Step 1: Document the breach

  • How was confidentiality breached?
  • What information was disclosed as part of the breach?
  • To whom was it disclosed, and how much of the confidential information was disclosed?
  • What evidence exists of the breach?

Step 2: Send a cease and desist letter

  • Identify the breach clearly.
  • Demand immediate cessation of disclosure.
  • Require return or destruction of information.
  • State you’ll pursue legal action if necessary.

Step 3: Assess damages

  • What harm has the breach caused?
  • Has competitive advantage been lost?
  • Have customer relationships been damaged?
  • Are there quantifiable financial losses?

Step 4: Consider legal action

  • Apply for an urgent interdict to stop further disclosure.
  • Claim damages for losses suffered.
  • Seek an order for return/destruction of information.

Step 5: Review and improve

  • How did the breach occur?
  • Are stronger security measures needed?
  • Should NDA provisions be tightened?
  • Do procedures need updating?

Common NDA Mistakes to Avoid

Mistake 1: Using NDAs When Not Necessary

Not every conversation needs an NDA. Overusing them can:

  • Slow down business relationships
  • Create unnecessary bureaucracy
  • Make you appear paranoid or difficult
  • Dilute the significance when NDAs are genuinely needed

Solution: Reserve NDAs for situations involving truly confidential information.

Mistake 2: Disclosing Information Before NDA Is Signed

The single most common mistake, sharing sensitive information during preliminary discussions before getting an NDA signed.

Solution: Have standard NDA templates ready. Get signatures before substantive discussions begin.

Mistake 3: Overly Broad Definitions

Trying to protect all information, even public or trivial information.

Solution: Be specific about what’s confidential. Focus on genuinely sensitive information.

Mistake 4: Unrealistic Restrictions

Prohibiting recipients from using general knowledge or skills gained during the relationship.

Solution: Distinguish between specific confidential information (protectable) and general skills/experience (not protectable).

Mistake 5: Excessive Duration

Requiring indefinite confidentiality for ordinary business information.

Solution: Match duration to the realistic lifespan of the information’s value. Trade secrets can be indefinite; standard business information typically lasts around 2-5 years.

Mistake 6: Not Updating NDAs

Using decade-old templates that don’t address modern issues (digital information, cloud storage, POPIA, etc.).

Solution: Review and update NDA templates regularly, at least annually.

Mistake 7: No Consequences for Breach

NDAs that don’t specify remedies or include unenforceable penalty provisions.

Solution: Include clear remedies (injunctive relief, damages) and consider reasonable pre-agreed damages before sharing any information.

Mistake 8: Not Following Your Own Security Requirements

Requiring recipients to use “reasonable security measures” while you email confidential documents unencrypted.

Solution: Practice what you preach. Implement the security measures you require of others.

NDAs vs Other Protective Measures

NDAs are important, but shouldn’t be your only protection:

Complementary Protections

1. Restrictive covenants in employment contracts

  • Non-compete clauses
  • Non-solicitation provisions
  • Intellectual property assignment clauses

2. Physical security measures

  • Secure storage of documents
  • Access controls to facilities
  • Visitor management
  • Secure disposal of sensitive documents

3. Digital security

  • Encryption
  • Password protection
  • Access controls and user permissions
  • Regular security audits
  • Secure backup and disaster recovery

4. Intellectual property protection

  • Patent applications for inventions
  • Trademark registration for brands
  • Copyright registration for original works
  • Trade secret management programmes

5. Internal policies and procedures

  • Information classification systems
  • Document handling procedures
  • Employee confidentiality training
  • Incident response plans

6. Insurance

  • Cyber insurance covering data breaches
  • Business interruption insurance
  • Professional indemnity for certain disclosures

The Layered Approach

The most effective protection comes from layering multiple measures:

  • Legal protections (NDAs, restrictive covenants)
  • Technical controls (encryption, access controls)
  • Physical security (locks, access restrictions)
  • Administrative controls (policies, training)
  • Cultural elements (confidentiality awareness)

Special Considerations for South African Businesses

POPIA Compliance

The Protection of Personal Information Act creates obligations beyond NDAs for personal data:

Key requirements:

  • Lawful processing of personal information
  • Purpose specification and limitation
  • Data minimisation
  • Accuracy and retention limits
  • Security safeguards
  • Data subject rights (access, correction, deletion)

How it affects NDAs: When confidential information includes personal data, your NDA should address POPIA compliance, but the NDA alone doesn’t satisfy all POPIA requirements.

Electronic Communications and Transactions Act

The ECTA recognises electronic NDAs and e-signatures as valid, but ensures that:

  • Electronic signatures meet legal requirements;
  • Parties intend to be bound by electronic acceptance; and
  • Reliable methods verify identity and intent.

Competition Law Considerations

Be cautious about information sharing in certain contexts:

  • Competitor information exchanges during industry associations;
  • Joint venture discussions between competitors; and
  • Information sharing that might facilitate collusion.

NDAs don’t protect anti-competitive conduct and behaviour. Consult competition law specialists for sensitive scenarios.

Labour Law Intersection

For employee NDAs, consider:

  • Can’t restrict employees from using general skills and experience;
  • Post-employment confidentiality obligations;
  • Relationship with the restraint of trade provisions; and
  • Fair dismissal procedures for breaches.

Final Thoughts on Protecting Your Business with NDAs

Non-disclosure agreements are essential tools for protecting your business’s valuable information in today’s competitive environment. When properly drafted and implemented, they create legal obligations, demonstrate the seriousness of confidentiality, and provide remedies when breaches occur.

Key principles for effective NDA protection:

  • Use NDAs proactively before sharing sensitive information
  • Tailor them to your specific situation rather than using generic templates
  • Be clear about what’s confidential and what’s not
  • Make obligations reasonable and proportionate
  • Implement supporting security measures to reinforce confidentiality
  • Monitor compliance and act quickly if breaches occur
  • Keep them updated to address modern challenges and legal developments
  • Layer protections – NDAs work best as part of comprehensive information security

Remember: An NDA is only as good as your ability and willingness to enforce it. Don’t sign NDAs you can’t realistically enforce and maintain, and don’t ask others to sign NDAs you won’t enforce. The goal is to create genuine, enforceable confidentiality obligations that protects your business and confidential information while enabling necessary information sharing for growth and collaboration.

Well-crafted NDAs, properly implemented and backed by strong information security practices, give you legal recourse and practical protection for your business’s most valuable asset – its information. In South Africa’s increasingly knowledge-based economy, effective confidentiality protection through NDAs isn’t optional; it’s essential for business success.

Need help drafting customised non-disclosure agreements or developing comprehensive information protection strategies? Consult with one of our qualified commercial law attorneys who can create NDAs tailored to your specific business needs and ensure they provide maximum protection while remaining practical and enforceable.