A confidentiality agreement in business is a contract in which one or more parties promise not to disclose specified information, and not to use it outside an agreed purpose. In the Netherlands such an agreement sits on top of the Wet bescherming bedrijfsgeheimen (Trade Secrets Act), which has protected genuine trade secrets since 23 October 2018 even where nothing was signed. The contract earns its place by answering the questions the statute leaves open: what exactly counts as confidential, for how long, who may see it, and what a breach costs.
This article approaches confidentiality from the angle of the business relationship rather than the document. It sets out where a duty of secrecy comes from under Dutch law, what the Trade Secrets Act does and does not reach, and how confidentiality is managed in the situations where information actually leaks: negotiations, due diligence, supply chains and staff turnover. For the anatomy of the document itself, clause by clause, see our complete guide to the non-disclosure agreement.
Where confidentiality obligations come from in a Dutch business relationship
Dutch law recognises four separate sources of a duty of confidentiality, and they operate independently of one another. Knowing which one you are relying on determines what you have to prove and what you can demand.
The first source is the contract. A confidentiality agreement in business, or a confidentiality clause inside a wider contract, creates an obligation that binds the parties on its own terms. Its great advantage is that you define the subject matter yourself: you do not have to show that the information was economically valuable or that you guarded it well, only that it falls within the definition you agreed and that the other party disclosed or used it.
The second source is the Wet bescherming bedrijfsgeheimen. It gives the holder of a trade secret a set of remedies against anyone who acquires, uses or discloses that secret unlawfully, whether or not a contract exists between them. This is the layer that reaches the competitor who hired your former employee, or the party who never signed anything.
The third source is the general requirement of reasonableness and fairness that governs every obligation and every contract under articles 6:2 and 6:248 of the Burgerlijk Wetboek (Dutch Civil Code). Parties who negotiate with each other, or who work together under a contract that says nothing about secrecy, are not free to do whatever they like with what they learn. A duty of discretion can follow from the nature of the relationship, from the way the information was handed over, or from an express statement that a document was shared in confidence. Outside any relationship, a party who deliberately exploits the confidential information of another business can be liable in tort under article 6:162 BW.
The fourth source is the employment relationship. An employee owes a duty to behave as a good employee under article 7:611 BW, and that duty includes discretion about the affairs of the employer. Article 7:678 BW treats the disclosure of particulars of the employer household or business, where the employee was obliged to keep them secret, as an urgent cause capable of justifying ontslag op staande voet (summary dismissal). Professional advisers, works council members and financial institutions carry further statutory duties of their own.
What the Wet bescherming bedrijfsgeheimen protects without a contract
The Trade Secrets Act implements Directive (EU) 2016/943 and applies three cumulative conditions. Information is a bedrijfsgeheim (trade secret) only if it is secret, in the sense that it is not generally known or readily accessible to people who normally deal with that kind of information; if it has commercial value precisely because it is secret; and if the holder has taken reasonable measures, in the circumstances, to keep it secret. All three must be satisfied at the same time. Fail one and the statutory route closes.
In practice it is the third condition that decides cases. Reasonable measures are what turn a claim of secrecy into a provable fact: access restrictions on the network, a documented need-to-know policy, marking documents, logging who opened a data room, and, of course, signed confidentiality agreements. A business that circulates its pricing model as an unrestricted spreadsheet attachment has an uphill task convincing a court that the same model was a protected secret.
The Act then describes when acquisition, use or disclosure is unlawful: unauthorised access to or copying of documents, files or materials that contain the secret; any other conduct contrary to honest commercial practices; and use or disclosure by someone who breached a confidentiality obligation or a restriction on use. Liability extends to a third party who knew, or ought to have known in the circumstances, that the secret reached them through the unlawful act of someone else. That last rule is what allows a claim against the new employer as well as the departing employee.
Equally important is what the Act allows. Independent discovery of the same information is lawful. So is reverse engineering of a product that is publicly available or that you lawfully possess, unless a contract validly restricts it. Information rights of employees and their representatives are protected, and so is any other practice consistent with honest commercial practices. The Act also requires a court to reject a claim where the disclosure served freedom of expression, exposed misconduct or unlawful activity in the general public interest, or was made in the exercise of employee representation. A confidentiality agreement cannot contract those defences away.
What a confidentiality agreement adds to the statutory protection
The statutory regime protects trade secrets. A great deal of commercially sensitive information is not a trade secret, and that gap is the reason contracts are still signed. The price you quoted in one tender, the identity of a prospective buyer, the existence of the negotiations themselves, a draft term sheet, the fact that a key customer is leaving: none of this necessarily has independent commercial value because it is secret, yet all of it can do damage in the wrong hands. A confidentiality agreement in business covers it because you defined it as covered.
The agreement does four further things the statute does not. It limits the purpose for which the information may be used, so that a recipient who was allowed to assess a target company may not use the same figures to compete. It regulates onward disclosure, naming the categories of advisers, group companies and subcontractors who may receive the information and requiring them to accept the same duty. It fixes the moment at which materials must be returned or destroyed, and lets you ask for written confirmation that this has happened. And it settles which law applies and which court or arbitral tribunal decides, which matters enormously once the recipient sits abroad.
There is a fifth, quieter benefit. Signing and enforcing confidentiality agreements is itself evidence of the reasonable measures that the Trade Secrets Act requires. A business with a consistent contracting practice is in a better position under the statute than one without, even in disputes with parties who never signed anything. The contract and the statute reinforce each other rather than competing.
Confidentiality clauses also appear inside other agreements, and the interaction needs watching. Where a separate confidentiality agreement is followed by a share purchase agreement, a services agreement or a shareholders agreement, the later contract often contains its own confidentiality provision and an entire agreement clause. Unless you say otherwise, the earlier agreement may be superseded on less favourable terms. Our overview of the types of commercial agreements under Dutch law explains how these documents fit together.
Confidentiality during negotiations and due diligence
The riskiest phase is the one before any main contract exists. Negotiating parties are already governed by reasonableness and fairness, but that duty is open-textured and hard to enforce quickly, which is why a confidentiality agreement should be signed before the first substantive meeting rather than at the point where a deal starts to look real. By then the sensitive information has usually already been shared.
In an acquisition or an investment round the confidentiality agreement carries additional weight because the buyer is, by definition, someone with an interest in the same market. Sensible practice is to disclose in stages: an anonymised profile first, then identified but aggregated financial information, then, only after a letter of intent, the customer contracts, margins and personnel data. A data room with individual logins produces a record of who looked at what, which is the single most useful piece of evidence if information later surfaces elsewhere. For a fuller picture of that process, see our article on due diligence in Dutch mergers and acquisitions.
Two further points regularly cause trouble. First, a non-solicitation undertaking, preventing the other side from approaching your staff or customers during and after the talks, belongs in the same document. Confidentiality alone does not stop a party from using what it saw to make an offer to your commercial director. Second, the agreement should survive the end of the negotiations. If talks break down, the duty of secrecy has to keep running; that is precisely the moment when the temptation to use the information is greatest. The rules on breaking off negotiations in the Netherlands deal with the other half of that problem.
Confidentiality in the supply chain and with subcontractors
Information rarely stops with the party you contracted. Manufacturers share drawings with tooling suppliers, software vendors use offshore developers, and service providers subcontract parts of the work. If your confidentiality agreement stops at your direct counterparty, the protection stops there too.
The remedy is a flow-down obligation: the counterparty may involve subcontractors only if it imposes confidentiality terms at least as strict as its own, and it remains liable to you for their conduct as if the breach were its own. Without that second half the clause is decorative, because you would otherwise have to sue a subcontractor with whom you have no contract, on the harder statutory footing. It is also worth naming the countries or entities to which information may be transferred; a supplier that quietly moves your production files to an affiliate elsewhere creates both a commercial and a regulatory problem.
That regulatory problem deserves its own sentence, because it is the most common mistake we see. A confidentiality agreement is not a verwerkersovereenkomst (data processing agreement). Where the information you share includes personal data and the other party processes it on your instructions, the General Data Protection Regulation requires a separate agreement with the specific content set out in article 28 GDPR: subject matter, duration, nature and purpose, categories of data subject, security measures, sub-processing, assistance and deletion. Signing an NDA and assuming the point is covered leaves you exposed to the Autoriteit Persoonsgegevens as well as to your counterparty. Our article on the data processing agreement in the Netherlands sets out what that document must contain.
Confidentiality and your own staff
Most leaks are internal, and the employment relationship therefore deserves separate treatment. A confidentiality clause in an employment contract is valid without any of the formalities that surround a non-compete clause, and it may in principle continue after the employment ends. That is its strength. Its weakness is that a confidentiality clause on its own does not stop the employee from going to work for a competitor and applying everything that has become part of their general professional skill and experience.
Dutch law draws that line deliberately. Knowledge that an employee has absorbed as ordinary professional competence belongs to the employee; concrete, identifiable, protected information belongs to the employer. If you need to keep someone out of the market altogether, you need a non-concurrentiebeding (non-compete clause) or a relatiebeding (non-solicitation clause) meeting the requirements of article 7:653 BW, including the written form and, in a fixed-term contract, a written motivation of the compelling business interest. Our article on non-compete clauses under Dutch employment law covers where that boundary currently sits.
A penalty attached to an employee confidentiality clause is subject to its own rules. Article 7:650 BW requires the clause to be agreed in writing, to identify the rules whose breach is penalised, to state the amount, and to state precisely the destination of the penalty, which may not benefit the employer directly or indirectly. Parties may depart from part of that regime in writing for employees earning more than the statutory minimum wage, which is what most employment contracts do; the requirement of a written, specific clause remains. The employer must also choose: for one and the same breach it can claim the agreed penalty or full damages, not both.
Practical measures matter as much as clauses. Confidentiality obligations should be restated at the exit interview, company devices and accounts should be recovered and access revoked on the last working day, and mailbox and file-transfer logs should be preserved before the account is closed. Where an employee forwards company documents to a private address shortly before resigning, those logs are usually the whole case.
Penalty clauses and what a Dutch court does with them
A boetebeding (penalty clause) is the reason most confidentiality agreements have any deterrent effect at all. Without one you must prove your loss, and proving the financial consequences of a leak is genuinely difficult: the customer who did not come back, the tender you did not win, the licence you could no longer sell. A penalty clause replaces that exercise with a fixed sum.
Three rules of the Civil Code govern it. Under article 6:92 BW the penalty takes the place of statutory damages, so if you want to claim your actual loss on top of the penalty the agreement must say so expressly. Under article 6:93 BW the penalty only becomes payable after a notice of default in the same cases where a damages claim would require one, which means the popular belief that a penalty is due automatically and immediately is wrong more often than not; a well-drafted clause makes the penalty payable without notice and without proof of damage. And under article 6:94 BW the court may reduce an agreed penalty if fairness manifestly so requires. The Hoge Raad applies that power with restraint, but a clause that produces a wholly disproportionate result in the concrete case is a realistic target for moderation.
The design of the clause therefore matters more than the size of the number. A single lump sum for any breach invites moderation, because it treats a careless email to the wrong recipient the same as the wholesale transfer of a customer database. A tiered clause, with a fixed amount per breach and a per-day amount for a continuing breach, subject to an overall cap and expressly without prejudice to the right to claim further damages and an injunction, is both more credible and more likely to survive judicial scrutiny.
What to do when confidential information leaks
Speed and evidence decide these cases. The first step is to secure the record before it disappears: access logs, download and print histories, email traffic, the data room audit trail, and copies of the documents in the form in which they left the business. Do this before confronting anyone, and take care that the collection itself is lawful, particularly where it touches the personal communications of an employee.
The second step is a written notice setting out the obligation, the facts, the demand to cease and to return or destroy the material, and a deadline. That notice does double duty: it stops the breach in a fair number of cases, and it establishes the default that article 6:93 BW may require before the penalty falls due.
If that does not work, the ordinary route is a kort geding (summary proceedings) before the voorzieningenrechter (preliminary relief judge), who can order the other party to stop using or disclosing the information, to hand over or destroy copies, and to identify everyone who received it. The Trade Secrets Act gives that judge an explicit power to impose such measures, and a separate rule allows the court, on request, to keep the allegedly secret information out of the public part of the proceedings, so that litigating does not itself publish what you are trying to protect. Where evidence is at risk of being destroyed, a bewijsbeslag (evidentiary seizure) can be sought before the other side is aware of the claim.
On the merits the court can order cessation, recall and destruction of infringing goods, award damages taking account of the value of the secret and the conduct of the infringer, and in some circumstances award compensation calculated as a reasonable licence fee instead of a prohibition. Publication of the judgment at the expense of the infringer is also available. Intentional disclosure of business secrets by someone under a duty to keep them can in addition be a criminal offence under article 273 of the Wetboek van Strafrecht, although in commercial practice the civil route is faster and more useful.
Mistakes that cost businesses their protection
The most damaging mistake is signing too late. Once the information has been shared, an agreement concluded afterwards does not restore the position, and the recipient will argue that what they already knew fell outside it.
A close second is the definition that is either boundless or bare. A clause covering all information disclosed by the discloser gives a court nothing to work with and is often read narrowly; a clause listing only technical drawings leaves the commercial information unprotected. The workable middle is a description of categories with concrete examples drawn from the actual relationship, combined with a marking or confirmation procedure for anything shared orally.
Then there is the term. Contrary to a persistent myth, Dutch law contains no fixed maximum, and a period of two to five years is a convention rather than a rule. Match the term to the commercial life of the information: a bid price is worthless to a competitor after the tender closes, whereas a manufacturing process may stay valuable for a decade. Where the information also qualifies as a trade secret, the statutory protection continues for as long as it remains secret, whatever the contract says.
Finally, the agreement that is never used. Confidentiality obligations that no one monitors, that are not passed down to subcontractors, and that are quietly ignored after every breach do not merely fail on their own terms; they undermine the argument that you took reasonable measures at all. Our article on protecting trade secrets sets out the organisational side of that discipline.
Frequently asked questions about confidentiality agreements
The questions below come up most often when businesses put a confidentiality agreement in place or discover that one has been breached.
How long does an NDA typically last?
In the Netherlands, the duration of an NDA needs to be both reasonable and justifiable. Most agreements you’ll see last for 2 to 5 years, a timeframe that Dutch courts generally consider enforceable. The real key is to tie the duration directly to the commercial lifespan of the information you’re protecting.
Dutch law sets no fixed maximum, so a perpetual term is not automatically void, but the further you move from the moment the information had real commercial value, the harder the obligation is to enforce. For that reason, it’s always best to specify a clear end date that reflects how long the information will realistically remain sensitive and commercially valuable.
What if someone refuses to sign?
A refusal to sign an NDA should be treated as a major red flag. It could signal a lack of seriousness about the business relationship, but more worrisomely, it might hint at a future intention to misuse your confidential information.
The safest and wisest course of action is to halt all discussions. Don’t share any more sensitive details until you have a signed agreement in place. It’s almost always better to walk away from a potential deal than to risk your valuable intellectual property.
Is an NDA still valid after employment ends?
Yes, absolutely. A core feature of any well-drafted NDA is that the duty of confidentiality is designed to outlive the termination of employment or any other business relationship. This is a standard and critical part of the agreement.
To avoid any doubt, the contract should state explicitly that the duty to protect confidential information continues for the entire term specified in the NDA, regardless of the individual’s employment status. This ensures your company’s secrets stay protected long after an employee or partner has moved on.
Law & More advises businesses in the Netherlands on confidentiality agreements, trade secret protection and the disputes that follow a leak. We draft and negotiate confidentiality agreements for negotiations, acquisitions and supply relationships, review the confidentiality and penalty clauses already in your contracts, and act in summary proceedings where information has to be recovered quickly. If you would like to discuss your situation, please contact our lawyers.

