A non-disclosure agreement in the Netherlands, also called a geheimhoudingsovereenkomst or NDA, is a contract in which one or both parties undertake not to disclose or use specified confidential information. Dutch law imposes no formal requirements on such an agreement: it is a normal contract, enforceable under the general rules of the Dutch Civil Code, and it stands alongside the statutory protection of trade secrets in the Wet bescherming bedrijfsgeheimen. Its practical value lies in what it defines, how long it lasts and what happens when it is breached.
What an NDA does that the law does not do by itself
Since 23 October 2018 the Netherlands has had a statute dedicated to confidential business information: the Wet bescherming bedrijfsgeheimen (Trade Secrets Protection Act), which implements EU Directive 2016/943. It protects information that satisfies three cumulative conditions. The information must be secret, in the sense that it is not generally known or readily accessible to people who normally deal with that kind of information. It must have commercial value precisely because it is secret. And the person lawfully in control of it must have taken reasonable steps, in the circumstances, to keep it secret.
That third condition is where the NDA earns its place. An organisation that hands out its designs, price calculations or source code without a confidentiality agreement will struggle to persuade a court that it took reasonable steps to keep them secret, and may therefore lose the statutory protection altogether. A signed NDA, together with access restrictions and marking of documents, is the ordinary evidence that the condition is met.
The agreement also does things the statute does not. It can cover information that is confidential but has no independent commercial value, such as the mere fact that negotiations are taking place. It can prohibit conduct the law permits, notably reverse engineering of a product that has been lawfully acquired, which the Directive and the Act treat as a legitimate way of obtaining information unless the parties have agreed otherwise. And it can attach an agreed financial consequence to a breach, which removes the hardest part of any confidentiality claim: proving loss.
Unilateral, mutual and multi-party confidentiality agreements
A unilateral NDA obliges one party only. It fits situations in which information flows in one direction: an inventor approaching a manufacturer, a company briefing a consultant, an employer engaging staff who will see customer data. A mutual or bilateral NDA obliges both sides and is the standard instrument in merger and acquisition talks, joint development and any negotiation in which both parties open their books.
Multi-party agreements are used in consortia and research collaborations, where several organisations both disclose and receive. They are harder to draft because the permitted purpose differs per participant and because a leak may be traceable to more than one recipient. In those arrangements it is worth agreeing in advance who may share what with which affiliate, and recording it in an annex that can be updated without renegotiating the whole agreement.
Whichever form is used, the NDA governs disclosure. It is not a substitute for the contract that governs the collaboration itself, and it does not settle who owns the results. A confidentiality agreement signed before a joint development project should therefore say expressly that nothing in it transfers intellectual property or grants a licence, so that ownership remains to be dealt with in the development contract.
The clauses that decide whether the agreement is worth anything
Start with the definition of confidential information. A definition that covers everything covers nothing in practice, because a court asked to enforce it has no way of telling what was actually protected. The workable approach names categories and, where possible, requires disclosures to be marked or confirmed in writing within a short period after an oral disclosure. Standard carve-outs belong here too: information that is already public, that the recipient already lawfully held, that it develops independently, or that it receives from a third party without breach of a duty of confidence.
Next comes the permitted purpose. The recipient should be allowed to use the information for one defined purpose and nothing else, because the real damage in most cases is not publication but use. Then the circle of permitted recipients: named employees, group companies, professional advisers, in each case on the condition that they are bound by equivalent obligations, with the disclosing recipient remaining liable for them.
Duration deserves more thought than it usually gets. An obligation that expires after a fixed term is easy to administer but leaves genuine trade secrets unprotected the day it lapses. An obligation that lasts as long as the information remains secret matches the commercial reality but requires the carve-outs to be watertight. Many agreements combine the two: a fixed term for ordinary confidential information and an unlimited term for information that qualifies as a trade secret. Finally, deal with the end: return or destruction of materials, retention of one copy for compliance purposes, and the survival of the confidentiality obligation after termination.
Penalty clauses: powerful, and easy to get wrong
A contractual penalty (boetebeding) is the most effective enforcement tool in a Dutch NDA, because it releases the claimant from having to prove and quantify loss. Under article 6:92 of the Dutch Civil Code the agreed penalty replaces statutory damages unless the contract provides otherwise, so an agreement that intends the penalty to be payable in addition to full compensation must say so expressly. Article 6:94 allows the court to reduce a penalty where the outcome would otherwise be manifestly unacceptable, and it can also increase the compensation where the penalty is manifestly insufficient. Courts apply the power to reduce with restraint between commercial parties, but a penalty that bears no relation to any conceivable loss invites it.
The picture changes completely once the other party is an employee. Article 7:650 of the Dutch Civil Code sets strict conditions for a penalty clause in an employment contract. The contract must state which rules carry a penalty and the amount of the penalty, and the clause must be agreed in writing. It must state precisely what the penalty money is used for, and that destination may not be the personal benefit of the employer. Each penalty must be a fixed amount in the currency of the wage, and the total penalties imposed in a week may not exceed half a day of wages.
Any clause conflicting with those provisions is void. There is one route around them: for employees whose wage exceeds the applicable minimum wage, the parties may deviate in writing from the rules on destination, fixed amount and the weekly ceiling. They may not deviate from the requirement that the contract identifies the rules and the amount, nor from the requirement of writing. This is precisely where employer confidentiality clauses fail: a clause promising an unspecified penalty, or one that keeps the money for the employer without a written deviation for an above-minimum-wage employee, cannot be enforced at all. Our employment lawyers see the consequence regularly, usually after the breach rather than before it.
A penalty clause is not the only remedy. Even without one, a breach of an NDA is a failure to perform under article 6:74 of the Dutch Civil Code and gives rise to damages, and unlawful acquisition, use or disclosure of a trade secret gives the holder the remedies of the Trade Secrets Protection Act.
Confidentiality in employment: what the clause can and cannot reach
An employee owes a duty to behave as a good employee under article 7:611 of the Dutch Civil Code, and that duty already implies a measure of confidentiality during the employment. It is thin comfort after the employment has ended, which is why a separate confidentiality clause, drafted to survive termination, belongs in every contract involving sensitive information.
A confidentiality clause is not a non-compete clause and should not be used as one. A non-compete clause (concurrentiebeding) is governed by article 7:653 of the Dutch Civil Code: it must be in writing, may not be agreed with a minor, and in a fixed-term contract is valid only if the employer sets out in writing the compelling business interests that make it necessary. A confidentiality clause carries none of those requirements because it restricts disclosure rather than employment. Courts notice when a clause labelled confidentiality in fact prevents someone from working in their field, and treat it accordingly.
There are limits no clause can cross. A confidentiality obligation cannot prevent an employee from reporting a suspected wrongdoing under Dutch whistleblower legislation; contractual provisions that restrict that right have no effect. It cannot prevent someone from reporting a criminal offence, from giving evidence when required to do so, or from providing information to a supervisory authority that is entitled to it. Nor does it override a statutory duty of the employer to hand over information. An NDA that purports to buy silence about unlawful conduct is not merely unenforceable, it is a liability in itself.
Personal data: an NDA is not a data processing agreement
Confidential information very often contains personal data, and at that point the General Data Protection Regulation applies in parallel with the contract. Where the recipient processes personal data on the instructions of the discloser, article 28 of the GDPR requires a separate data processing agreement (verwerkersovereenkomst) with a prescribed minimum content: subject matter and duration, the nature and purpose of the processing, the categories of data subject, security measures, rules on sub-processors, assistance with data subject rights and the fate of the data at the end.
A confidentiality clause does not satisfy those requirements and cannot be made to. The two documents serve different purposes: the NDA protects the commercial interest of the discloser, the processing agreement protects the individuals whose data is involved and allocates responsibility towards the Dutch Data Protection Authority. Where personal data crosses a border outside the European Economic Area, the transfer also needs its own legal basis under Chapter V of the GDPR. Treating one document as covering both is a common and expensive shortcut; our privacy lawyers deal with the aftermath more often than the drafting.
Enforcing an NDA when information leaks
Speed matters more than anything else, because the value of a secret disappears the moment it becomes public and no court order can restore it. The first step is evidence: secure log files, e-mail traffic, device images and download records before they are overwritten, and record what was disclosed to whom and when. Dutch procedure offers a specific instrument here, the evidentiary attachment (bewijsbeslag) combined with a claim for inspection of documents under article 843a of the Dutch Code of Civil Procedure, which allows a party with a legitimate interest to demand copies of specified documents relating to a legal relationship it is party to.
The usual route to a fast order is summary proceedings before the interim relief judge (kort geding voor de voorzieningenrechter). Typical claims are an order to stop the use or disclosure, an order to return or destroy materials, an order to name the recipients, and payment of the contractual penalty on pain of a further periodic penalty payment (dwangsom). The Trade Secrets Protection Act adds measures aimed at goods that infringe a trade secret, including recall from the market and destruction, and gives the court the power to protect the confidentiality of the secret during the proceedings themselves, which is essential because litigating about a secret otherwise risks disclosing it.
Damages are claimed in ordinary proceedings on the merits. Where the parties have agreed a penalty, the claim is simply for the penalty, which is why the clause is worth so much. Where they have not, the claimant must prove its loss, and lost profit from information that a competitor now also has is notoriously difficult to quantify. Serious breaches can additionally be a criminal offence: the Dutch Criminal Code makes it punishable to intentionally disclose a business secret which one is under a duty to keep.
Cross-border NDAs and the choice of law
Confidentiality agreements are frequently signed between parties in different countries, and the templates that circulate are usually American. That matters. Concepts such as punitive damages, liquidated damages doctrine and injunctive relief as of right do not translate into Dutch law, and a clause drafted around them can lose its effect entirely when Dutch law applies. Under the Rome I Regulation commercial parties are free to choose the governing law, and the choice should be made deliberately rather than inherited from a template.
Add a matching forum clause. A choice of the Dutch courts allows the interim relief judge to be approached quickly, and a judgment obtained in a Member State circulates within the European Union without further formality. Where the counterparty holds all its assets outside Europe, arbitration is often the more enforceable option. The practical test for any confidentiality clause is the same: if the information leaked tomorrow, which court could be asked for an order by the end of the week, and could that order be enforced where the recipient actually is.
Mistakes that come up most often
Signing too late is the first. An NDA agreed after the pitch meeting protects nothing that was said at the meeting, and a recipient who already holds the information can point to the carve-out for information it lawfully knew beforehand. The second is the boundless definition, which fails at the moment of enforcement. The third is the missing permitted purpose, which leaves a recipient free to use the information as long as it keeps it confidential, which is often exactly the harm the discloser feared.
The fourth is a penalty clause in an employment contract that ignores article 7:650 of the Dutch Civil Code and is therefore void. The fifth is relying on the agreement alone: the statutory protection of trade secrets requires reasonable technical and organisational measures, so access rights, document classification, exit interviews and the recovery of devices are part of the legal position, not merely good housekeeping. The sixth is signature by someone without authority to bind the counterparty, which is worth checking in the trade register before the information goes out.
Making the agreement work in day-to-day practice
A signed NDA that nobody applies is evidence of nothing. Because the statutory protection of trade secrets depends on reasonable measures, the way an organisation actually handles information is part of its legal position. That starts with knowing what the secrets are. Very few businesses can list them, yet a short inventory of the information whose disclosure would genuinely damage the company, and of where it is stored and who can reach it, is the foundation for every other measure and for any later claim.
Access should follow need. Restricting rights in the file system and in the customer relationship management software, using a data room with per-document permissions and download logging during a transaction, and marking documents as confidential when they leave the building all produce two benefits at once: fewer leaks, and a documented trail if one occurs. Where a supplier or contractor is involved, confidentiality obligations should be passed down the chain in writing rather than assumed.
Departures deserve their own procedure. Withdraw access on the last working day rather than a fortnight later, recover laptops, telephones and physical files, and remind the departing employee in writing of the obligations that continue after the employment has ended. Where a large volume of data was downloaded shortly before the resignation, act at once: the logs are the evidence, and they are usually overwritten on a fixed rotation. Reviewing the confidentiality position at that moment costs little; reconstructing it after the information has surfaced at a competitor costs a great deal more. The wider commercial framework is set out in our corporate law guides.
Frequently asked questions about non-disclosure agreements
Is an NDA legally binding in the Netherlands? Yes. It is an ordinary contract and requires no particular form, although a written agreement is essential in practice for proving what was agreed. There is no registration requirement and no notarial deed.
How long should a confidentiality obligation last? For as long as the information has value in being secret. A fixed term of a few years is common for commercial information exchanged in a transaction, while genuine trade secrets are better protected by an obligation that runs for as long as the information remains secret.
Can the same NDA be used for employees and suppliers? No. A confidentiality clause in an employment contract is subject to employment law, in particular the rules on penalty clauses in article 7:650 of the Dutch Civil Code, and it interacts with the non-compete and non-solicitation clauses in the same contract. A supplier NDA is a purely commercial document and should be drafted as one.
What can I do if confidential information has already been disclosed? Secure the evidence immediately, then consider summary proceedings for an order to stop the use and disclosure, backed by a periodic penalty payment. Whether the disclosure can still be contained determines everything else, so the assessment should be made within days.
Does an NDA stop a former employee from working for a competitor? No. Confidentiality restricts the use and disclosure of information, not the choice of employer. Restricting employment requires a valid non-compete or non-solicitation clause meeting the requirements of article 7:653 of the Dutch Civil Code.
Advice on non-disclosure agreements
Law & More drafts and reviews confidentiality agreements for businesses in the Netherlands, from a one-page NDA before a first meeting to the confidentiality architecture around a transaction or a research collaboration, and acts in summary proceedings when information has been misused. The agreement is worth reviewing before it is needed rather than after. Contact one of our contract lawyers to discuss the protection of your confidential information.


