An NDA under Dutch law, a geheimhoudingsovereenkomst, is an ordinary contract in which one or both parties undertake not to disclose defined information and to use it only for an agreed purpose. Dutch law imposes no form requirement, so an NDA can in principle be concluded orally, but the party invoking it carries the burden of proving what was agreed, which makes a written agreement the only sensible option. Its enforceability turns on four things: a defined purpose, a workable definition of the confidential information, exceptions that respect the law, and remedies that a court will actually grant.
This guide sets out how NDAs work in the Netherlands: when they bind, how to define confidential information without overreaching, how long protection can last, which disclosures must always remain permitted, how an NDA supports a claim under the Trade Secrets Protection Act, how it interacts with the GDPR, and what a penalty clause can and cannot do, including the different rules that apply in an employment contract. It closes with enforcement, cross-border points and the questions clients ask most.
What an NDA is under Dutch law
An NDA is a contract, and it comes into being in the ordinary way through offer and acceptance. There is no requirement of writing, no notarial form and no consideration in the English-law sense. What matters is that the obligations are sufficiently determinable: which information, for which purpose, for how long, and with what consequence if the obligation is breached.
NDAs come in two shapes. A one-way agreement binds only the party receiving the information, which suits a situation where one side has a prototype, a client list or a set of figures and the other has nothing comparable to share. A mutual agreement binds both, which is usual in merger talks, joint development and most commercial negotiations, and which tends to produce a more balanced text because each side has to live under it.
In practice the NDA is the first of the commercial agreements to be signed, before the term sheet and well before the main contract, and it usually has to survive the failure of the negotiation it was written for. That is the point most often missed: an NDA is not an accessory to the deal, it is the instrument that governs what happens when the deal does not go ahead and the other party keeps everything you showed them.
A well-drafted NDA also does a second job. Under the Dutch Trade Secrets Protection Act, information only qualifies as a trade secret if reasonable steps have been taken to keep it secret. The NDA, together with access controls and a record of who received what, is the most visible of those steps, which means it functions as evidence in a later dispute even where nobody sues on the contract itself.
When a Dutch NDA is enforceable
Dutch courts enforce confidentiality obligations that look like real obligations. Vagueness is what defeats them. An NDA that defines confidential information as everything ever exchanged, imposes no purpose limitation, runs indefinitely against all information regardless of value and attaches an arbitrary penalty is not automatically void, but each of those features gives a court a reason to read the clause narrowly, to moderate the penalty, or to find that the information in question fell outside it.
Five features make the difference. The purpose has to be stated, because it is what limits use and what makes an ordinary commercial exchange distinguishable from a general gag. The definition of confidential information has to be capable of application by the people who handle the information day to day. Access has to be limited to those who need it, with the same obligations imposed on employees, advisers and subcontractors before anything is passed on. The exclusions have to be there, covering information that is already public, that the recipient already lawfully held, that it developed independently or that it obtained lawfully from a third party, and the agreement should say who bears the burden of proving that an exclusion applies, which is normally the recipient. And the remedies have to be proportionate, because a penalty that bears no relation to the interest protected invites the court to reduce it.
Enforceability also has an outer limit that no drafting can move. A clause that would prevent a party from reporting a criminal offence, from complying with a court order or a statutory duty, from giving truthful evidence when compelled or from making a protected disclosure under the Whistleblowers Protection Act cannot be enforced to that extent. Building those exceptions in does not weaken the agreement; leaving them out weakens it, because it invites an argument that the whole clause is contrary to public policy.
Defining confidential information without overreach
The definition is the clause that decides most disputes, and the instinct to make it as wide as possible is counterproductive. A definition that covers everything gives the recipient no way to comply and gives a court every reason to read it down. A definition that works describes categories tied to the purpose of the disclosure: technical know-how and source code, designs and prototypes, pricing and margins, customer and supplier data, business plans and, in the context of a transaction, the existence and content of the negotiations themselves. In an agreement about private matters the categories are different but the technique is the same.
Do not make the marking of documents the only route into protection. In real life information is disclosed in meetings, demonstrations and calls, and a rule that only stamped documents are confidential will exclude most of what actually matters. The workable standard is that information is confidential if it is marked as such or if the recipient knew or should reasonably have known that it was confidential given its nature and the circumstances of the disclosure. Where oral disclosure needs to be confirmed in writing, set a period that people can realistically meet and do not make a missed confirmation fatal.
Include the standard exclusions and say where the burden lies. Equally, exclude the recipient’s general skills and experience. A clause that purports to stop someone from using what they have learned as a professional is unenforceable in substance and is often the reason a court approaches the rest of the agreement with suspicion. Confidentiality protects information, not competence, and if you want to restrain competition you have to say so separately and accept the stricter rules that apply to non-competition clauses.
Finally, state that no intellectual property is transferred or licensed by the disclosure, and that the recipient will not apply for rights in the disclosed material. Where a licence is in fact intended, it belongs in a licence agreement, not in a confidentiality clause.
Duration and purpose limitation
Duration and purpose are the two levers that keep an NDA proportionate. On purpose, the rule is simple: use is permitted for the stated purpose and for nothing else, and a new purpose requires written consent. Without that limitation, an NDA restricts disclosure but permits the recipient to use your information itself, which is usually the outcome you were trying to prevent.
On duration, distinguish between the term of the agreement and the term of the obligation. The agreement may end when the negotiation ends; the confidentiality obligation should survive it. For information that loses value quickly, a defined period of a few years after the end of the cooperation is proportionate and easier to enforce. For genuine trade secrets there is no reason to set an end date at all, because the statutory protection lasts as long as the information remains secret, and a contractual cut-off can be read as an admission that the parties did not regard it as a trade secret after that date.
Two provisions complete the picture. The obligation should end in respect of information that becomes public through no fault of the recipient, since protecting what everyone can read serves no purpose and makes the clause look oppressive. And there should be a clean exit: on completion of the purpose, or on request, the recipient returns or securely deletes the material and confirms in writing that it has done so, with a sensible carve-out for copies retained in backups and for material that must be kept under a statutory retention duty. That confirmation is worth having for its own sake, and it is exactly the kind of document that later demonstrates the reasonable steps the Trade Secrets Protection Act requires.
Permitted disclosures and the limits public policy sets
Every NDA needs defined exits, and the parties are better off writing them than leaving them to be argued about later. Six belong in almost every agreement.
The first is disclosure to professional advisers who are themselves bound by a duty of confidence: lawyers, accountants, auditors and, in a private context, doctors and therapists. The second is disclosure required by law or by a court, regulator or tax authority, coupled with an obligation to notify the disclosing party in advance where that is lawful and to limit the disclosure to what is required. The third is truthful evidence given under compulsion. The fourth is reporting suspected criminal conduct or an imminent danger to the police or a competent authority. The fifth is protected reporting under the Whistleblowers Protection Act, which has applied since February 2023 and prohibits any detriment as a consequence of a report; a contractual clause that stands in the way of such a report cannot be enforced against the reporting person. The sixth is internal disclosure on a need-to-know basis to people who have accepted equivalent obligations.
These are not concessions. An agreement that tries to close these routes risks being read as an attempt to obstruct supervision or prosecution, and a court confronted with such a clause will be less inclined to enforce the parts of the agreement that are legitimate.
How an NDA supports the Trade Secrets Protection Act
The Dutch Trade Secrets Protection Act (Wet bescherming bedrijfsgeheimen) implements the EU Trade Secrets Directive and protects information that meets three cumulative conditions: it is secret, in the sense that it is not generally known or readily accessible to people who normally deal with that kind of information; it has commercial value because it is secret; and it has been subject to reasonable steps, in the circumstances, to keep it secret. The third condition is the one that fails in practice, and it fails because nothing was documented.
The Act gives the holder of a trade secret remedies against unlawful acquisition, use or disclosure, including an injunction, the recall or destruction of infringing goods, and damages, and Dutch procedural law allows the court to restrict access to the confidential material in the proceedings themselves so that enforcement does not destroy the secret. Where the information was obtained by an employee or former employee in breach of an imposed duty of secrecy, the deliberate disclosure of business particulars can also be a criminal offence under article 273 of the Criminal Code.
The NDA supports all of this in a specific way. It identifies the categories treated as secret; it limits use to a purpose; it restricts access to identified people who have accepted the same duties; it imposes handling and security requirements; and it produces a paper trail of who received what and when it was returned or deleted. Keep that trail. A recipient log, a dated deposit or sealed specification describing the scope of the secret without disclosing it, and the deletion confirmations at the end of a project, are what turn an assertion into evidence. Our pages on Dutch law on the protection of trade secrets and on how to protect your trade secrets set out the wider set of measures.
NDAs and the GDPR
An NDA does not displace data protection law. Where the confidential information includes personal data, the GDPR applies on its own terms and a confidentiality clause is not a legal basis for processing. The two instruments have to be aligned.
Start with the roles. If one party processes personal data on the other’s instructions, a processing agreement is compulsory and the NDA does not replace it. If both parties determine purposes and means, they are joint controllers and must record who performs which obligation. Then apply the principles inside the confidentiality arrangement itself: share only the personal data the purpose requires, prohibit reuse for unrelated purposes, restrict access to named roles, impose appropriate technical and organisational measures, set a concrete retention period rather than an open-ended one, and require return or secure deletion with written confirmation at the end.
Two further points matter with sensitive material. Cooperation on data subject requests should be addressed, and no clause may restrict a person’s exercise of their rights or their ability to complain to the supervisory authority. And where a breach occurs, the controller must assess it and, where required, notify the Dutch Data Protection Authority without undue delay and, where feasible, within seventy-two hours; the NDA should therefore oblige the other party to inform you immediately rather than after its own internal investigation. If personal data is involved at any scale, take specialist privacy advice before signing.
Penalty clauses: boetebeding, dwangsom and moderation
A confidentiality obligation without a credible consequence is difficult to enforce, because the loss caused by a leak is notoriously hard to quantify. Dutch law offers two instruments and they are frequently confused.
The contractual penalty, the boetebeding, is agreed by the parties and is payable on breach without proof of loss. Under article 6:92 of the Civil Code the penalty takes the place of statutory damages unless the contract provides otherwise, so an agreement that is silent leaves you with the penalty and nothing more. Say expressly that the penalty is without prejudice to the right to claim full damages and injunctive relief. Article 6:94 of the Civil Code allows the court to reduce a penalty where its application would be manifestly unfair, and disproportionate figures invite exactly that, so anchor the amount to a plausible view of the harm and consider a per-breach amount for discrete disclosures, a per-day amount for a continuing breach, and a cap on the total.
The dwangsom is different. It is a coercive payment imposed by the court to compel compliance with an order, under article 611a of the Code of Civil Procedure. It cannot be created by contract; it is requested together with an injunction. In practice the two work in parallel: the penalty compensates and deters, and the coercive payment forces the breach to stop.
A model formulation, adapted to the case, is that for each breach the recipient owes a penalty of a stated amount, increased by a stated amount for each day the breach continues, and that the penalty is without prejudice to the right to claim full damages, performance and injunctive relief.
NDAs with employees and contractors
Confidentiality in an employment relationship follows different rules, and this is where standard clauses copied from commercial contracts go wrong.
An employee already owes a duty of confidentiality as part of the obligation to behave as a good employee, but a written clause is worth having because it defines the scope and survives the end of the employment. The penalty, however, is regulated. Under article 7:650 of the Civil Code a penalty clause in an employment contract must be in writing, must specify the breach and the amount, must state precisely where the money goes, and may not benefit the employer directly or indirectly; the combined penalties imposed in one week may not exceed half a day’s wages. Parties may depart from the destination, the amount and the weekly maximum only in writing and only where the employee earns more than the statutory minimum wage, and even then the court may reduce a penalty it considers excessive. And under article 7:651 of the Civil Code the employer cannot both impose the penalty and claim damages for the same act; any clause that says otherwise is void. The commercial drafting instinct to make penalties cumulative with damages is therefore wrong in an employment contract.
Keep confidentiality separate from restrictive covenants. A non-competition or non-solicitation clause has its own requirements, including the written form and, in a fixed-term contract, a written statement of the compelling business interests that justify it. Hiding a restraint of trade inside a confidentiality clause does not make it enforceable; it makes the confidentiality clause suspect.
With contractors and agencies, the issue is different. There is no statutory transfer of intellectual property to the client, so the services agreement must deal expressly with assignment, and the confidentiality obligation must flow down to sub-consultants before any disclosure is made. Manage the practical side as well: least-privilege access on entry, and on exit the return of devices and credentials, the withdrawal of access and a written confirmation of deletion. An NDA that is not matched by the way the organisation actually handles the information proves very little.
Confidentiality agreements in private relationships
Confidentiality agreements are also used outside business, to protect identities, messages, images or the existence of a relationship. Dutch law does not treat them as a separate category: they are contracts, and the same requirements of clarity, purpose and proportionality apply. What changes is that the limits of public policy come into view much faster.
Such an agreement can lawfully protect private information. It cannot be used to conceal a criminal offence, to prevent a report to the police or another authority, to prevent someone from seeking help from a lawyer, a doctor or a therapist, or to prevent truthful evidence being given when compelled. Those carve-outs must be written into the text. Nor may the obligation be tied to sexual conduct as its consideration; an agreement constructed in that way is contrary to public morality and will not be enforced.
Two practical points follow. Keep the scope narrow and the categories concrete, because a broad gag over an entire relationship is both unenforceable and evidence of the imbalance a court will look for. And where intimate images or other personal data are involved, apply the same data hygiene as in a commercial setting: limit what is shared, restrict access, and require deletion on request or when the purpose ends. The unlawful publication of sexual images is a criminal offence in its own right, and the civil remedies available to the victim, including an urgent injunction, exist regardless of what any agreement says.
Cross-border NDAs
Where the parties are in different countries, four choices decide whether the agreement is usable. The first is the governing law. Within the EU the Rome I Regulation respects the parties’ choice, subject to the overriding mandatory rules of the forum and to the rule that a choice cannot displace the mandatory law of the only country connected with the situation. Dutch law is the natural choice where most of the performance, and most of the information, sits here.
The second is the forum. A choice of court within the EU is upheld under the Brussels I bis Regulation and judgments circulate without an exequatur. Arbitration is the alternative and has two attractions in this context: the proceedings are confidential, which matters when the subject of the dispute is a secret, and awards are enforceable in a very large number of countries under the New York Convention. Its drawback is cost and the absence of an appeal. Whichever route you choose, keep an express carve-out allowing either party to seek urgent injunctive relief from a national court, because interim protection is what stops a leak while the merits are pending.
The third is language. State which language version prevails, and be careful with English legal terms in an agreement governed by Dutch law: expressions such as best efforts or consequential loss will be interpreted as a Dutch court interprets them, not as an English one would. The fourth is execution. Allow signature in counterparts and by electronic means; the legal weight of a digital signature depends on the type used, and a qualified electronic signature is equated with a handwritten one. Where the information concerns controlled technology, check the export control and sanctions rules before it is sent abroad; an NDA does not authorise a transfer that export law prohibits.
Red flags before you sign, and what to negotiate
Read the draft for the features that make an NDA either unenforceable or unworkable. A catch-all definition that covers everything ever exchanged, including information that is already public, and that leaves out the standard exclusions. The absence of any purpose limitation, which permits unrestricted reuse. Missing carve-outs for advisers, court orders, authorities and protected reports. A penalty with no rational basis, or one that is silent on whether damages remain claimable. No return or deletion obligation, which is a problem both under the GDPR and for the evidence of reasonable steps under the Trade Secrets Protection Act. A hidden assignment of intellectual property, or a clause that purports to restrict the recipient’s general skills. A restraint of trade smuggled in under the heading of confidentiality. Permission to share with unnamed affiliates and advisers without equivalent obligations. And a foreign governing law and forum with no carve-out for urgent relief in the Netherlands.
The corresponding negotiating points are modest and usually accepted. Fix the purpose and add that no licence of intellectual property is implied. Tighten the definition to categories and add the exclusions with the burden on the recipient. Make the obligations mutual where information genuinely flows both ways. Limit access to named roles and require equivalent obligations before onward disclosure. Add the public policy carve-outs. Set a retention and deletion regime with written confirmation. Size the penalty to the interest protected and state that damages and injunctive relief remain available, remembering that in an employment contract the statutory rules override that instinct. And settle the dispute mechanics: governing law, forum or arbitration, the prevailing language, and the emergency carve-out. Our note on contract negotiation strategies sets out how to run that discussion without losing the deal, and our guide to signing a contract without hidden legal issues covers the wider checks before signature.
What to do when an NDA is breached
Speed decides the outcome, because the value of confidential information disappears as it spreads. Work in a fixed order.
Secure the evidence first. Take dated screenshots with the URL visible, preserve the original emails and messages with their headers, export the access logs, and record who saw what and when. Do not edit anything. Then contain: withdraw credentials, close shared folders, restrict access to the smallest possible group, and instruct any supplier or subcontractor involved to stop onward disclosure immediately.
Next, send a formal demand, the sommatiebrief, citing the clauses breached and requiring, by a stated deadline, that the disclosure stop, that the material be taken down, that the recipients be identified, and that the material be returned or deleted with written confirmation. Many breaches end here, particularly where the recipient did not appreciate the position.
If it does not, apply for interim relief in summary proceedings. The preliminary relief judge can grant an injunction, order return or verified destruction and impose a coercive payment for each breach, usually within weeks. Claim the contractual penalty and reserve damages and costs at the same time. Where arbitration is agreed, file the merits there and use the court only for the emergency measures the arbitration clause allows.
Two more steps are easy to forget. If personal data leaked, run the breach assessment and make any notification the GDPR requires, and coordinate any public statement so that the response does not disclose more than the breach did. And afterwards, look at how it happened: in most cases the failure was in access management rather than in the drafting. Where a negotiated ending makes more sense than a judgment, a settlement agreement with reinforced undertakings and a deletion certificate is often the better outcome, particularly where litigation would draw attention to the very information you are trying to protect.
Template or tailored agreement
A template is a starting point, not a protection. It is adequate where the exchange is mutual and low-risk, the evaluation is short, no genuine trade secrets or meaningful personal data are involved, both parties are Dutch, and the penalty is modest or absent. In that situation the marginal value of bespoke drafting is small and the delay costs more than the risk.
Tailoring earns its cost in five situations. Where you will rely on the Trade Secrets Protection Act, because the agreement then has to be built as evidence of reasonable steps. Where meaningful personal data is shared, because the roles, the processing agreement and the retention regime have to be right. Where contractors, sub-processors or group companies will handle the information, because the flow-down obligations decide whether the chain holds. Where the relationship crosses a border, because the law, the forum, the language and the route to urgent relief have to work together. And where the amounts at stake justify a penalty large enough to be worth arguing about, because sizing it and keeping damages available takes drafting. Whether it is worth taking advice at all is a question we address more generally in our note on when legal advice is necessary in the Netherlands.
Frequently asked questions
Does an NDA have to be in writing
No. Dutch law imposes no form requirement, so a confidentiality obligation can be agreed orally or follow from the circumstances. But the party invoking it has to prove what was agreed, and that is close to impossible without a document. Put it in writing.
Can an NDA last indefinitely
Yes, and for genuine trade secrets that is the right approach, because statutory protection lasts as long as the information stays secret. For information that loses value quickly, a defined period after the end of the cooperation is more proportionate and easier to enforce.
Does everything have to be marked confidential
Marking helps but should not be the only route into protection, because much information is shared orally or in demonstrations. Combine marking with a standard that also covers information the recipient knew or should reasonably have known was confidential.
Can an NDA prevent someone from reporting a crime
No. Confidentiality cannot be enforced to prevent a report to the police or a supervisory authority, compliance with a court order or statutory duty, truthful evidence given under compulsion, or a protected disclosure under the Whistleblowers Protection Act. Write those exceptions into the text.
Can I claim the contractual penalty and damages as well
In a commercial contract, only if the agreement says so: under article 6:92 of the Civil Code the penalty replaces statutory damages unless the parties provide otherwise, and the court may reduce a penalty whose application would be manifestly unfair. In an employment contract you cannot: article 7:651 of the Civil Code prohibits imposing the penalty and claiming damages for the same act.
How quickly can I stop a leak
Summary proceedings before the preliminary relief judge normally produce a decision within weeks, and in genuinely urgent cases considerably faster. The judge can order the disclosure to stop, order return or verified deletion, and attach a coercive payment to the order.
Can an employer put a non-competition clause inside an NDA
It should not. A restraint on competing activity has its own statutory requirements and is assessed separately; concealing one inside a confidentiality clause does not make it enforceable and casts doubt on the rest of the agreement.
Getting the NDA right before you need it
An NDA works when the document matches how the information is actually handled: a stated purpose, a definition people can apply, access limited to those who need it, exceptions that respect the law, a retention and deletion regime, and remedies a court will grant. Drafted that way it also serves as evidence of the reasonable steps that the Trade Secrets Protection Act requires, which is often worth more than the contractual claim itself.
Law and More drafts and reviews confidentiality agreements for Dutch and international clients, aligns them with trade secret and data protection obligations, and acts in summary proceedings when a leak has to be stopped quickly. If you need an agreement before a negotiation starts, or you are dealing with a breach of one, contact our office.


