10 NDA Red Flags That Could Cost You Millions (And Fixes)
Ten NDA red flags founders miss — IP assignment traps, perpetual survival, residuals, uncapped indemnification, and more. Pattern library with fixes and Burn Score triage.
Quick answer: what are the worst NDA red flags?
The ten highest-risk NDA patterns are: (1) unbounded confidentiality definitions, (2) IP assignment traps, (3) perpetual or excessive survival, (4) one-sided jurisdiction, (5) missing independent development exclusions, (6) hidden non-compete or non-solicit language, (7) strict liability for any disclosure, (8) residuals clauses, (9) uncapped indemnification, and (10) impractical return/destruction obligations. Flag any of these before signing.
*Updated July 2026 — expanded cross-links to the clause glossary hub, survival periods guide, Burn Score triage, and step-by-step risky clause workflow.*
Most NDAs look harmless. Two to five pages, standard boilerplate language, a signature block at the end. The problem is not what the NDA says on the surface — it is what the standard boilerplate actually means.
Here are ten red flags that show up in NDAs every day. Each one has cost real companies real money. For definitions, see the full glossary or the business-owner clause hub.
Red flag 1: "Any and all information" — the unbounded definition
What it says: "Confidential Information means any and all information, materials, or data disclosed by either party in connection with this Agreement."
What it means: Every conversation. Every email. Every whiteboard sketch. Every offhand comment at dinner. It is all confidential.
Why it is dangerous: When everything is confidential, nothing is safe. Your normal business operations — talking to customers, hiring employees, developing products — become potential breaches because you cannot know what counts as "Confidential Information."
The classic example: A startup shares market research with a potential partner under an unlimited-definition NDA. Two years later, the partner sues claiming the startup's entire product line was derived from that research. Even if the claim is meritless, the defence costs alone can be crippling.
How to fix it: Limit confidential information to specific categories identified in writing at the time of disclosure, plus information that would reasonably be considered confidential given the context. Add a materiality threshold — trivial information does not count. See the confidentiality definition glossary entry and how definition breadth compounds with survival periods.
Red flag 2: Perpetual confidentiality obligation
What it says: "The obligations of confidentiality shall survive indefinitely."
What it means: You must protect this information forever.
Why it is dangerous: Forever is a long time in business. Information that is commercially sensitive today may be irrelevant in three years — but under a perpetual NDA, you remain liable. Employee training, data handling procedures, and record-keeping must account for obligations that never expire.
Trade secrets are a legitimate exception — most legal systems protect them indefinitely. But ordinary business information should not carry the same burden.
How to fix it: 2-3 years for standard confidential information. Trade secrets remain protected until they enter the public domain. For negotiation anchors and redlines, see NDA survival periods: 5 durations that trap founders and termination clauses.
Red flag 3: IP assignment of improvements
What it says: "Any improvements, modifications, or derivative works based on Confidential Information shall be the exclusive property of the Disclosing Party."
What it means: If you use their information to build something better, they own it.
Why it is dangerous: This is the most expensive clause in a standard NDA. In technology companies especially, this clause can transfer ownership of your core product.
The scenario: Your startup shares code samples or architecture diagrams during a technical evaluation. The potential partner suggests an improvement. Under this clause, that improvement belongs to them — even if it ends up as a core feature of your product.
How to fix it: Each party retains all rights to its own IP. No licence or assignment is granted except by a separate written agreement with consideration. If the other party insists on some IP protection, limit it to specific deliverables created under a separate SOW. Deep dive: IP clauses in NDAs.
Red flag 4: Missing independent development exclusion
What it says: Nothing. The clause is simply absent.
What it means: If your product happens to resemble something you learned about during NDA discussions, you cannot prove independent development.
Why it is dangerous: Without an independent development exclusion, any similarity between your product and information shared under the NDA creates legal exposure. You are forced to prove a negative — that you did not use their information — which is nearly impossible without meticulous records.
How to fix it: Add a standard exclusion: "Confidential Information does not include information that the Receiving Party can demonstrate was independently developed without use of or reference to Confidential Information."
Red flag 5: Jurisdiction far from home
What it says: "This Agreement shall be governed by the laws of the State of Delaware. The parties submit to the exclusive jurisdiction of the courts located in Wilmington, Delaware."
What it means: If there is a dispute, you are going to Delaware.
Why it is dangerous: Litigation costs scale with distance. A Delaware lawyer charges Delaware rates. Travel costs, document handling, local counsel — all add up. For a small or medium business, the cost of defending even a weak claim in a foreign jurisdiction can force settlement regardless of merit.
How to fix it: Your home jurisdiction, or a neutral venue with arbitration. For smaller deals, mutual jurisdiction (either party can sue in the other's home court) is a reasonable compromise. See governing law in the glossary.
Red flag 6: Non-compete or non-solicit in disguise
What it says: "The Receiving Party agrees not to engage in any business that competes with the Disclosing Party for a period of 12 months following disclosure."
What it means: You cannot do business in their space for a year.
Why it is dangerous: NDAs protect information. Non-competes restrict competition. When a non-compete is buried in an NDA with no separate consideration, it may be unenforceable — but that does not stop the other party from threatening litigation.
The same applies to non-solicitation clauses that prevent you from hiring the other party's employees.
How to fix it: Remove these clauses entirely. If the other party insists on post-employment restrictions, they belong in a separate agreement with clear limits and appropriate consideration. Compare scope in non-compete vs non-disclosure.
Red flag 7: Strict liability for any disclosure
What it says: "The Receiving Party shall be liable for any disclosure of Confidential Information, whether authorised or not."
What it means: You bear 100% of the risk, even if your systems are secure and the breach was beyond your control.
Why it is dangerous: No security system is perfect. Employees make mistakes. Cyber attacks happen. Strict liability means you pay for any breach regardless of fault — making you an insurer for the disclosing party's information.
How to fix it: Standard of care should be "reasonable care" — the same degree of care you use for your own confidential information. Add a carve-out for disclosures required by law or court order. Pair with capped indemnification — see red flag 9 below.
Red flag 8: Residuals clause — the memory loophole
What it says: "The Receiving Party may use Residuals — information retained in the unaided memory of its personnel who have had access to Confidential Information."
What it means: Anything your engineers or designers "remember" without looking at documents may fall outside confidentiality — including architecture, workflows, and trade craft.
Why it is dangerous: For technical and creative work, your competitive edge often lives in methodology, not literal files. A broad residuals clause lets the counterparty reuse concepts you disclosed under the NDA while still binding you to strict confidentiality.
How to fix it: Remove residuals entirely when the relationship involves technical or creative work. If the counterparty insists, narrow to truly generic skills — not project-specific insights. Residuals plus a broad confidentiality definition is one of the highest Burn Score combinations.
Red flag 9: Uncapped indemnification
What it says: "The Receiving Party shall indemnify, defend, and hold harmless the Disclosing Party from any and all claims, damages, and expenses arising from any breach of this Agreement."
What it means: You pay their legal bills and losses — with no dollar cap and sometimes no fault requirement.
Why it is dangerous: Indemnification turns a confidentiality agreement into unlimited financial exposure. A single employee mistake, a phishing attack, or a disputed "breach" can trigger defence costs that dwarf the deal value. See NDA indemnification clauses for market norms.
How to fix it: Cap indemnity at a fixed amount or the fees paid under the deal. Require the indemnified party to mitigate damages. Exclude consequential damages. Never accept uncapped indemnity on a standard mutual NDA.
Red flag 10: Impractical return and destruction
What it says: "Upon request, the Receiving Party shall immediately return or destroy all Confidential Information and certify destruction within 48 hours."
What it means: You must purge emails, Slack threads, Figma files, and backup systems on the counterparty's timeline — often without backup carve-outs.
Why it is dangerous: Return obligations are operational, not theoretical. "Immediately" on demand is unrealistic for distributed teams. Missing backup carve-outs force you to choose between breach and disaster-recovery compliance. See return & destruction and the return policies guide.
How to fix it: 10–15 business days to return or destroy after termination or written request. Add a backup retention carve-out (90 days) with continued confidentiality. Mutual duties in mutual NDAs.
How to handle these red flags
Not every NDA needs to be perfect. The key is prioritising based on context:
High priority — must fix:
- IP assignment clauses
- Missing independent development exclusion
- Uncapped indemnification
- Unreasonable jurisdiction
Medium priority — should fix:
- Overbroad confidentiality definition
- Residuals clauses on technical work
- Strict liability standard
Low priority — nice to fix:
- Perpetual term for non-trade-secret information
- Non-solicit clauses (if unenforceable in your jurisdiction)
- Impractical return timelines (unless combined with broad definitions)
For a repeatable workflow after pattern-matching, follow how to identify risky NDA clauses step by step. For full clause-by-clause review, see the complete NDA review guide.
The 60-second triage
Before you spend time negotiating, run the NDA through NDAShield. You will get a Burn Score that tells you exactly how risky the document is, with specific clause-level flags for each of these ten red flags — plus any others hiding in the fine print.
An NDA is a tool for collaboration. When you know what to look for, you can keep it that way.
Related resources
Want a fast risk estimate before you commit to a full review? Take the NDA Burn Score quiz. Compare purpose-built review against general AI in NDAShield vs ChatGPT and NDAShield vs Claude, or browse all NDA analysis tools. For redline quality across vendors, see comparing NDA review services.