NDA Review Checklist: Everything to Look For
Updated July 2026 · 7 min read
Non-disclosure agreements (NDAs) are among the most frequently reviewed contracts in legal practice. They're often treated as "simple" or "standard" — but the details matter enormously. A poorly drafted NDA can expose your client to significant risk, or fail to protect them when it matters most.
This checklist covers every clause you should examine when reviewing an NDA, with specific red flags to watch for at each step.
The Complete NDA Review Checklist
☐Definition of Confidential Information — Is the definition broad enough to cover all types of information your client might share? Does it include oral disclosures, not just written? Are there reasonable carve-outs (publicly available info, independently developed, rightfully received from third parties)?
☐Mutual vs. One-Way — Is the NDA mutual (both parties disclose and receive) or one-way (only one party's information is protected)? If one-way, is that the correct direction for your client?
☐Obligations of Receiving Party — Does the receiving party agree to: (a) maintain confidentiality, (b) not disclose to third parties, (c) use only for the stated purpose, (d) protect with at least reasonable care, (e) return or destroy upon request or termination?
☐Permitted Disclosures — Are there carve-outs for: (a) employees and agents with a need to know, (b) professional advisors under their own confidentiality obligations, (c) legal/regulatory requirements? Are the carve-outs properly scoped?
☐Duration/Term — How long do the confidentiality obligations last? 2-5 years is standard. Indefinite obligations for trade secrets are acceptable. Watch for terms shorter than the useful life of the information.
☐Indemnification — Is there an indemnification clause? Is it mutual or one-sided? Is there a cap? An uncapped, one-sided indemnification obligation is a significant risk.
☐Limitation of Liability — Are the liability caps equal for both parties? Are there carve-outs that nullify the cap (e.g., for gross negligence, willful misconduct)? Watch for disproportionate caps.
☐Return or Destruction of Information — Is there a clear requirement to return or destroy confidential information upon request or termination? Is there a timeline? Are backup copies addressed?
☐Non-Use / Non-Circumvention — Does the NDA prevent the receiving party from using the information to circumvent the disclosing party in business dealings? Is there a non-solicitation clause for employees or customers?
☐Governing Law and Jurisdiction — Which jurisdiction's laws govern? Is dispute resolution through litigation or arbitration? Is the venue convenient for your client? Are class action waivers included?
☐Assignment — Can either party assign the NDA without consent? If your client is the disclosing party, they should control whether their confidential information can be transferred to a new entity.
☐Amendment — Can the NDA be amended unilaterally? All amendments should require mutual written consent.
☐Termination — Can the NDA be terminated for convenience? What happens to confidentiality obligations after termination? (They should survive for the stated duration.)
☐Residual Knowledge — Is there a residual knowledge clause allowing the receiving party to use general knowledge retained "in unaided memory"? These clauses significantly weaken protection.
☐Injunctive Relief — Does the NDA acknowledge that monetary damages alone may be inadequate and allow for injunctive relief? This is important for enforcement.
Common NDA Red Flags
One-Sided Indemnification
The most common NDA red flag: one party must indemnify the other for any breach, but the obligation isn't mutual. If your client is the one giving the indemnification, they bear all the risk with no reciprocal protection.
Disproportionate Liability Caps
Watch for liability caps that differ significantly between parties — for example, $100 for one party and $50,000 for the other. This creates a situation where one party has meaningful exposure while the other has almost none.
Unilateral Assignment Rights
If one party can assign the NDA without consent, they can transfer your client's confidential information to a new entity — potentially a competitor. Assignment should require mutual consent.
Overly Broad Non-Compete
Some NDAs include non-compete restrictions that are unreasonably broad — worldwide, multi-year, covering all competitors. These may be unenforceable but still create chilling effects and litigation risk.
Missing Termination Clause
An NDA without a termination-for-convenience clause locks both parties in indefinitely. Make sure there's a way out with reasonable notice.
Unilateral Amendment
If one party can amend the NDA terms without the other's consent, the agreement can change at any time. This is a serious risk — all amendments should require mutual written consent.
How AI Helps with NDA Review
Manually checking all 15 items on this checklist for every NDA is time-consuming and error-prone. AI contract review tools like ContractPeer automate the first pass:
- Upload the NDA (PDF, DOCX, or TXT)
- AI analyzes every clause against 15+ risk categories — including all the items on this checklist
- Get a structured report with severity ratings, the exact clause text, plain-language explanations, and recommended actions
- Review and validate the AI findings, then communicate risks to your client
This cuts NDA review time from hours to minutes while ensuring consistent, comprehensive coverage.
Note: This checklist is for informational purposes only and does not constitute legal advice. Always have a qualified attorney review NDAs before signing.