Alex is Sprintlaw's co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
What Should You Include In A Confidentiality Agreement (Or Clause)?
- 1. A Clear Definition Of “Confidential Information”
- 2. The Purpose (Permitted Use)
- 3. Disclosure Restrictions And “Need-To-Know” Access
- 4. Security Requirements (Practical Obligations)
- 5. Return Or Destruction Of Information
- 6. Term (How Long Does Confidentiality Last?)
- 7. What Happens If There’s A Breach?
- Key Takeaways
If you’re building a startup or running a small business, chances are you’ve already shared something valuable with someone else - a pitch deck, a pricing model, a customer list, a product roadmap, or even just a “rough idea” you’re excited about.
Most of the time, sharing information is a normal part of growing: you need to talk to developers, manufacturers, investors, contractors, employees, and potential partners. But there’s a key risk that often gets missed in the early stages: disclosing confidential information.
In plain terms, disclosure of confidential information is when someone shares (on purpose or by accident) information that should have stayed private. For a business owner, the problem isn’t just the disclosure itself - it’s what happens next: loss of competitive advantage, loss of trust, reputational damage, and sometimes real financial loss.
Below, we’ll walk you through what counts as confidential information in Australia, how it’s usually protected, what to do if it’s disclosed, and what legal documents and practical steps can help you reduce risk from day one.
What Counts As “Confidential Information” In A Small Business?
Confidential information is generally information that:
- is not publicly available,
- has value (commercially or strategically) because it’s private, and
- you’ve taken steps to keep it private.
For startups and small businesses, confidential information often includes more than you might expect. It’s not just “secret formulas” or big enterprise trade secrets.
Common Examples Of Confidential Information
- Customer and lead lists (including contact details, purchase history, deal values, renewal dates)
- Pricing information (including margins, discounting rules, quotes and rate cards)
- Product and technical info (source code, algorithms, prototypes, designs, product roadmap)
- Business strategy (market expansion plans, competitor analysis, pitch decks)
- Supplier/manufacturer information (supply terms, costs, processes, logistics)
- Internal processes (SOPs, workflows, unique methodologies)
- Financial info (budgets, forecasts, bank statements, cap table details)
- Employee or contractor data (salary data, performance info, HR files)
Something can be confidential even if it’s shared with a limited group - for example, information shared with a contractor “just to get the job done” can still be confidential.
What Is Not Confidential?
Information is less likely to be protected as confidential if it’s:
- already public (for example, published on your website or in marketing materials),
- generally known in your industry,
- independently developed by someone else without using your information, or
- shared widely without any expectation of privacy.
This is why the practical steps you take (like marking documents “confidential” and restricting access) can be just as important as what’s in your contracts.
Why Disclosure Of Confidential Information Is A Bigger Risk For Startups
Startups and smaller businesses often have fewer layers of protection. You’re moving quickly, wearing multiple hats, and working with external people more often - contractors, agencies, freelance developers, outsourced sales, virtual assistants, and manufacturers.
At the same time, your competitive edge is often tied to a handful of core assets:
- your idea and execution roadmap,
- your IP and know-how,
- your customer relationships, and
- your ability to attract funding and talent.
When confidential information is disclosed, the impact can be disproportionate. A larger business might absorb the loss. A smaller business can lose its momentum (or its market) overnight.
Typical Situations Where Disclosure Happens
- Pitching to investors and sharing decks or financials too early
- Hiring contractors without proper confidentiality terms
- Co-founder fallouts where someone walks away with key materials
- Employees leaving and taking customer lists or internal playbooks
- Supplier relationships where your product details are shared down the chain
- Accidental leaks (misdirected emails, shared drives, lost devices)
The good news is you can reduce most of these risks with a clear approach: identify what’s confidential, limit who can access it, and have the right documents in place before you share it.
How Do You Legally Protect Confidential Information In Australia?
In Australia, confidential information can be protected through a combination of:
- contractual protections (like NDAs and confidentiality clauses), and
- general legal principles (for example, obligations that can arise where information is given in confidence).
For most small businesses, the practical starting point is contracts - because they clarify expectations, define what “confidential” means for your business, and give you stronger enforcement options if something goes wrong.
Non-Disclosure Agreements (NDAs)
An NDA (also called a confidentiality agreement) is a contract that sets rules around how the other party can use and disclose your confidential information.
You’ll often use an NDA when you’re sharing information before a deeper commercial agreement is signed - for example, during early discussions with:
- potential partners,
- manufacturers,
- developers and agencies,
- consultants,
- prospective buyers of your business, or
- investors (though in practice, many investors prefer not to sign NDAs - so you need a “share smart” strategy).
Confidentiality Clauses Inside Other Contracts
Sometimes the best protection isn’t a standalone NDA - it’s a well-drafted confidentiality clause built into the contract that governs the relationship, such as:
- a contractor agreement,
- an employment contract,
- a supplier agreement, or
- a service agreement with a client.
This can be especially useful because it keeps everything in one place (commercial terms + confidentiality + IP + dispute processes), which is often easier to manage as you grow.
For example, if you’re hiring staff, a tailored Employment Contract can include confidentiality obligations alongside duties, pay, and termination terms.
Keep Confidentiality And IP Protection Working Together
Confidential information protection and intellectual property (IP) protection often overlap - but they’re not the same thing.
- Confidentiality is about keeping information private.
- IP ownership is about who owns creations like code, designs, brand assets, and written materials.
One common mistake is relying on confidentiality alone when what you really need is clear IP ownership terms (especially with contractors). If someone creates IP for you, you’ll often want written terms that clearly deal with ownership (for example, an assignment or a licence), depending on the arrangement.
What Should You Include In A Confidentiality Agreement (Or Clause)?
Not all confidentiality wording is created equal. A “template NDA” might look fine, but if it doesn’t fit what you’re actually sharing (or how your business operates), it can leave gaps when you need it most.
Here are the provisions small businesses should pay close attention to when dealing with disclosure of confidential information.
1. A Clear Definition Of “Confidential Information”
This should cover the categories that matter to your business (for example: client lists, pricing, code, financials, product plans), and ideally cover information shared in different ways - written, verbal, visual, electronic, etc.
You can also include exclusions (like information that becomes public through no fault of the recipient).
2. The Purpose (Permitted Use)
A strong agreement limits the other party to using the information only for a specific purpose - for example, “evaluating a potential partnership” or “performing services under the contract”.
This matters because many disputes aren’t about whether someone shared the info - they’re about whether they used it to compete, solicit customers, or build a rival product.
3. Disclosure Restrictions And “Need-To-Know” Access
Your agreement should usually say the recipient can only share confidential information with people who:
- need it to fulfil the purpose, and
- are bound by confidentiality obligations (for example, their employees or subcontractors).
4. Security Requirements (Practical Obligations)
It’s one thing to say “keep it confidential”. It’s another to require reasonable security steps - such as secure storage, access controls, not using personal devices, and notifying you if there’s a suspected data breach.
This can be particularly relevant if the information includes personal information, because privacy obligations may also apply depending on your business and the data you handle. If your business collects and handles personal data, having a properly drafted Privacy Policy is often part of your broader risk management.
5. Return Or Destruction Of Information
When the relationship ends (or if the deal doesn’t go ahead), you generally want the other party to return or destroy your confidential information - including copies, notes, and summaries.
6. Term (How Long Does Confidentiality Last?)
Some confidentiality obligations last for a set period (for example, 2–5 years). Others may last indefinitely, particularly for information that remains valuable as long as it stays secret.
The right approach depends on what you’re sharing and the commercial context. A “one-size-fits-all” timeframe can be risky.
7. What Happens If There’s A Breach?
A good agreement should outline what happens if confidentiality is breached, including:
- your right to seek urgent court orders (injunctions) to stop further disclosure,
- your ability to pursue losses (damages), and
- steps the recipient must take to limit the damage (like notifying you and cooperating).
This is where clarity matters. When there’s a disclosure of confidential information, speed is everything - you want a contract that supports fast action.
Practical Steps To Prevent Disclosure Of Confidential Information (Before It Happens)
Contracts are essential, but they work best alongside simple operational habits. If you ever need to enforce your rights, it also helps to show you treated the information as confidential in practice.
Limit Access Internally
- Only give confidential files to team members who genuinely need them.
- Use role-based access in your systems (CRM, cloud storage, code repositories).
- Remove access promptly when someone leaves.
Label And Organise Confidential Documents
- Mark key documents as “Confidential” (including decks, manuals, pricing sheets).
- Keep confidential docs in dedicated folders with restricted access.
- Avoid sharing sensitive documents via open links with no expiry.
Train Your Team (Especially Early)
Startups often assume “everyone knows not to share secrets”. In practice, people make mistakes when they’re busy.
Even a short onboarding checklist and a clear policy can reduce accidental leaks significantly - especially if you’re hiring quickly or using contractors.
Use The Right Contracts For The Right Relationships
If you’re bringing on co-founders or early investors, clarity on ownership and control is crucial. A well-drafted Shareholders Agreement can help set expectations around confidentiality, decision-making, and what happens if someone exits.
If you’re formalising company governance, documents like a Company Constitution can also form part of your broader “structure and control” framework (which can matter as you scale and bring more stakeholders into the business).
Be Strategic When Sharing With Investors Or Potential Partners
Sometimes you’ll be asked to share sensitive information early. You don’t always have leverage to insist on an NDA, particularly with larger counterparties.
In those cases, a practical approach can be:
- share high-level information first,
- only share sensitive details once there’s real momentum (or a term sheet / heads of agreement),
- use data rooms with tracking and access logs, and
- keep a record of what you shared, with whom, and when.
What To Do If Confidential Information Has Been Disclosed
Even with the right precautions, disclosure can still happen - and you’ll often find out after the fact (for example, a customer tells you they were contacted, or you notice your materials being used elsewhere).
When it happens, it’s easy to feel stuck. But there are practical steps you can take early that can make a big difference.
1. Act Quickly And Contain The Damage
- Identify what was disclosed and how.
- Work out who received it (and whether it has been shared further).
- Secure your systems (change passwords, revoke access, audit downloads).
2. Gather Evidence (Before It Disappears)
Keep copies of:
- emails and messages,
- contracts and NDAs,
- file access logs (where available),
- screenshots of any public disclosures, and
- notes of relevant conversations (including dates and attendees).
This isn’t about escalating unnecessarily - it’s about making sure you can properly assess your position and options.
3. Check What Contracts Apply
Look at whether you have:
- an NDA,
- a confidentiality clause in a contractor/customer agreement,
- employment contract obligations, or
- policies that apply.
If you don’t have anything in writing, you may still have options, but your position is usually stronger if expectations were clearly documented.
4. Consider A Written Demand Or Cease And Desist
Often, the first step is a formal written notice demanding the recipient:
- stop using and disclosing the information,
- return or destroy copies, and
- confirm in writing what they’ve done with the information.
In some situations, a properly drafted cease and desist letter can be a practical way to draw a clear line and start resolving the issue quickly.
5. Get Legal Advice Early If The Risk Is Material
If the disclosure involves core IP, key customers, major financial data, or anything that could materially harm your business, getting advice early can help you:
- work out whether urgent court action is needed,
- protect evidence and your commercial position,
- avoid making admissions in communications, and
- choose a strategy that’s proportionate to the risk.
In a startup, the goal is usually to protect your business without getting distracted from building. Early advice can help you move fast and keep the issue contained.
Key Takeaways
- Disclosure of confidential information can seriously affect your startup’s value, momentum, and competitive edge - especially when you’re relying on a small set of core assets.
- Confidential information often includes customer lists, pricing, supplier details, product roadmaps, code, internal processes, and financials - not just “trade secrets”.
- The most practical protection for small businesses is usually a combination of strong contracts (NDAs and confidentiality clauses) and sensible internal controls (limited access, secure storage, clear onboarding).
- Confidentiality terms should clearly define what’s confidential, restrict use to a specific purpose, limit who it can be shared with, and set expectations for return/destruction and breach consequences.
- If confidential information is disclosed, acting quickly, gathering evidence, and checking what contractual protections apply can put you in the best position to limit damage.
- Getting your key documents in place early - like an Employment Contract, Shareholders Agreement, Company Constitution and Privacy Policy - can significantly reduce confidentiality risk as you grow.
If you’d like help protecting your business from disclosure of confidential information, you can reach us at 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.






