Skip to content
All posts

What an NDA Cannot Stop Someone Doing

On this page
  1. It does not stop someone remembering
  2. It does not stop independent development
  3. It does not override a legal disclosure obligation
  4. It does not prevent a leak, only gives you a remedy afterwards
  5. What actually prevents a leak
  6. Putting the two jobs together properly
  7. Frequently asked questions
  8. Protect what an NDA alone cannot
  9. Sources

An NDA cannot stop someone remembering what they learned and applying it elsewhere, cannot stop them independently building something similar without using your specific information, cannot override a genuine legal obligation to disclose, and cannot physically prevent a leak before it happens. It only gives you a remedy afterwards, and only if you can prove what happened. This article sets out the honest limits of a document that is often oversold as a shield, so you can protect yourself in the ways that actually work rather than relying on paper that was never designed to stop the things people most fear.

> Quick answer: An NDA is a contract that creates a legal remedy for misuse of confidential information, not a technical or physical barrier that prevents disclosure from happening. It cannot stop someone remembering and using general knowledge and skill gained during a relationship, cannot stop genuinely independent development of something similar, cannot override a legal duty to disclose to a regulator or in court, and cannot prevent a determined leak before it occurs. It also does nothing about intellectual property ownership. What it does is deter, and give you something to point to afterwards if things go wrong. Prevention comes from access control, not paperwork.

It does not stop someone remembering

A confidentiality agreement protects information, not the general skill, know-how and experience a person accumulates by doing the work. Courts have long drawn a line between genuinely confidential, specific information and what is sometimes called the recipient's own stock of knowledge and expertise, the accumulated professional judgment that comes from having worked in a field or on a project, which they are entitled to carry with them to the next engagement. An advisor who worked with you for a year cannot suddenly forget how to advise generally, and an NDA was never designed to make them try. What it can restrain is their use of your specific confidential material, your customer list, your pricing, your unreleased product, not the general competence they built up while working with you. This distinction matters most when a former contractor, employee-adjacent worker or advisor moves to a competitor, and it is exactly where an NDA's protection turns out to be narrower than people expect, a point our companion guide on advisor equity touches from a different angle.

It does not stop independent development

If a competitor arrives at something similar to your product or idea through their own separate work, without ever having seen or used your confidential information, an NDA gives you no claim against them. Independent development is a standard, recognised carve-out in nearly every properly drafted confidentiality clause, and for good reason: the law protects specific confidential information, not the underlying idea in the abstract, and it does not grant anyone a monopoly over a category of product or business model. This trips people up constantly, particularly founders who assume an NDA means nobody else can build anything resembling what they are working on. It does not. If two teams independently reach a similar destination without one copying the other's confidential material, the NDA has nothing to say about it, and rightly so.

Every properly drafted NDA carves out disclosure required by law, regulation, or a court or regulator's order. A recipient compelled to hand over information in litigation, to a financial regulator, or under a statutory duty is not in breach of the NDA for complying, and no confidentiality agreement can lawfully require someone to break the law or defy a court order to keep a secret. Well-drafted NDAs usually require the recipient to notify the discloser before complying where they can, so the discloser has a chance to object or seek protective measures, but the underlying obligation to comply with a genuine legal requirement is not something an NDA can contract around. If you are relying on an NDA to keep something hidden from a regulator or a court, it will not do that job, and no template exists that could make it do so.

It does not prevent a leak, only gives you a remedy afterwards

This is the limit that catches people out most often. An NDA is a promise, backed by the threat of legal consequences, not a technical barrier. It does not stop a signed recipient from forwarding a document, taking a screenshot, or simply talking to the wrong person over coffee. If that happens, the NDA gives you grounds to seek an injunction, damages, or delivery up of material, covered in detail in our companion piece on whether an NDA is actually enforceable, but none of those remedies undoes the disclosure itself. Once sensitive information is out, it is out, and a subsequent court order stopping further use does not put the toothpaste back in the tube if the information has already reached a competitor or become public.

This is precisely why deterrence and prevention are two different jobs, and why relying on the NDA alone to do both is a mistake. Deterrence is the NDA's job: it makes clear that misuse carries real legal and reputational consequences, and most people and businesses genuinely do not want that exposure. Prevention is a different job entirely, and it belongs to how you actually control access to the material in the first place, not to the words in the contract.

What actually prevents a leak

Real prevention comes from limiting who can see something and what they can do with it once they have it, mechanisms that operate before a breach rather than after one. A gated link requiring a verified email and one-time code, with NDA acceptance built in before anything opens, controls who gets in at all. Page-by-page analytics tell you whether the material was actually opened and by whom, which is at least early warning if something looks unusual, a document opened repeatedly from unfamiliar locations, for instance. On the Business tier, per-viewer watermarking stamps each copy with the specific viewer's identity, so a leaked screenshot or forwarded PDF is traceable back to whoever it came from, which changes the incentive to leak in the first place even though it does not physically stop someone taking a photo of their screen. And where a relationship ends or turns sour, one-click revocation cuts off access immediately, even to a document someone has already opened, rather than leaving a live link circulating indefinitely.

None of this makes a leak impossible. Nothing does, short of never sharing anything sensitive with anyone, which defeats the purpose of most business relationships. What it does is narrow the opportunity, create a paper trail if something goes wrong, and make misuse considerably harder to get away with, which is a more honest goal than pretending a signed document alone can prevent a breach from ever happening.

Putting the two jobs together properly

The right approach treats the NDA and the access controls as two halves of the same job, not substitutes for each other. Work out which document actually fits the relationship, our guide on choosing between a one-way and a mutual NDA covers that decision, then draft a properly scoped mutual or one-way NDA, assembled from vetted clauses rather than invented ones as our piece on drafting a one-way NDA with AI explains, so the legal deterrent and remedy exist, along with the distinction that keeps assembled wording different from invented wording. Then gate, watermark and track the actual document so you have both a practical barrier to casual leaking and hard evidence if something goes wrong anyway. Relying on either one alone leaves a genuine gap: paperwork with no access control is easy to breach quietly, and access control with no signed agreement leaves you with no contractual remedy if someone determined gets through anyway.

This article addresses England and Wales law on confidentiality and disclosure. If you are dealing with a counterpart elsewhere, the specific legal carve-outs will differ by jurisdiction, but the underlying limits described here, memory, independent development, legal compulsion, and the gap between deterrence and prevention, hold true regardless of which country's law governs the document.

Frequently asked questions

Can an NDA stop a former contractor working for a competitor?

Not generally, and most NDAs are not drafted to try. An NDA restricts use of specific confidential information, not someone's ability to work in the same field or industry again. Restricting future employment or engagements is a separate kind of clause, typically found in a restrictive covenant, not a standard confidentiality agreement.

Does an NDA stop someone building something similar?

Not if they built it independently, without using your confidential information. Independent development is a standard carve-out in properly drafted NDAs, and the law protects specific confidential information rather than granting ownership over an idea or business model in the abstract.

Can an NDA prevent a regulator or court from getting information?

No. A properly drafted NDA carves out disclosure required by law, regulation, or a court order, and no confidentiality agreement can lawfully require someone to defy a legal requirement to keep information secret.

If someone leaks information covered by an NDA, can I get it back?

Not in the sense of undoing the disclosure. You can seek an injunction to stop further use, damages, or delivery up of remaining copies, covered in our guide on NDA enforceability, but none of that reverses information that has already spread. Prevention through access control matters more than remedy after the fact.

What actually stops a leak, if not the NDA itself?

Access controls do the preventive work: a gated link requiring verification, per-viewer watermarking that traces a leaked copy to its source, and one-click revocation that cuts off access immediately. The NDA supplies the legal deterrent and remedy; these controls supply the practical barrier.

Protect what an NDA alone cannot

Pair a properly drafted one-way or mutual NDA with real access control: gated links, per-viewer watermarking and page-by-page analytics, so you have both deterrence and evidence rather than paperwork alone. The free tier gives three rooms and twenty-five active links, forever, with no card required; the AI drafter and e-signature start on Pro at £19 a month. Start for free and stop treating the signed document as the whole answer.

This article is general information, not legal advice. What a specific NDA covers, and what remedies are available if it is breached, depends on its drafting and the facts of your situation, and is worth checking with a qualified adviser where real value is at risk.

Sources

Keep reading