NDA, or confidentiality agreement, is the first contract any business owner signs before disclosing or receiving sensitive information in a corporate transaction. If you are about to launch the sale of your company, raise a funding round, enter into a joint venture or engage a strategic advisor, that seemingly routine document is what separates a protected negotiation from an irreparable information leak.

In the Spanish middle market it is one of the costliest mistakes a small or mid-sized company can make: accepting the buyer’s template without reading it, or downloading a generic form off the internet, on the assumption that “an NDA is an NDA.” It is not. A poorly drafted agreement leaves the seller without real protection precisely when it is needed most.

This guide explains, with legal analysis updated to 2026, exactly what an NDA is, which clauses cannot be omitted, what types exist, what its legal validity is in Spain, and why it is the first signature in any M&A process.

What is an NDA or Confidentiality Agreement

An NDA (Non-Disclosure Agreement) is a contract under which one or more parties undertake to keep secret the confidential information they receive during a negotiation or business relationship, and not to use it for purposes other than those agreed. It is legally binding and enforceable before the courts.

The terms NDA, confidentiality agreement, non-disclosure agreement and secrecy agreement are fully equivalent: they all designate the same legal instrument. The only difference is one of language or style. The abbreviations “Confidentiality Agreement (CA)” or “confidentiality undertaking” are also used.

From a legal standpoint, the NDA is an atypical contract (contrato atípico): it has no specific regulation of its own in the Spanish Civil Code, but is grounded in the principle of freedom of contract (autonomía de la voluntad) under Article 1255 of the Civil Code, whereby contracting parties may establish such terms, clauses and conditions as they see fit, provided they are not contrary to law, morality or public policy (BOE: Civil Code). Legal scholarship characterises it as a continuing-performance contract with a negative obligation: for a set term, the receiving party undertakes not to do something—not to disclose, not to use beyond the agreed purpose, not to copy.

It is signed by natural or legal persons and arises whenever sensitive information is to be exchanged: company sales, funding rounds, alliances, technology licensing, or the engagement of suppliers or advisors with access to internal data. It must be signed before any information is handed over: disclosure made prior to signature is treated as voluntary disclosure, and the recipient can rarely be pursued afterwards.

NDA vs. Confidentiality Agreement vs. Confidentiality Clause: Are they the same?

It is worth distinguishing three concepts that are frequently confused:

  1. NDA, confidentiality contract or confidentiality agreement. A standalone, self-contained document focused exclusively on protecting information. It is signed as a step preliminary to a negotiation.
  2. Embedded confidentiality clause. A provision within a broader contract (employment, services, distribution, shareholders’ agreement, LOI). It is not a separate document but a clause integrated into another principal agreement.
  3. When each is appropriate. A standalone NDA is preferable where confidentiality is the principal object of the phase (typically in M&A, where the NDA is signed first and information is disclosed only afterwards). An embedded clause is sufficient where confidentiality is ancillary to an already-formalised contractual relationship.

Aspect

Standalone NDA Embedded confidentiality clause
When to use Before starting a negotiation or exchange of information (M&A, investment, due diligence)

Where a principal contract already exists (employment, services, distribution) and confidentiality is ancillary

Scope

Broad and detailed: definition of information, exclusions, terms, return of materials, consequences Limited to what the framework contract allows; usually shorter
Risks If missing or signed too late, the information disclosed is left unprotected

Risk of being diluted or of not surviving termination of the principal contract unless survival is expressly agreed

Types of NDA and when to use each

Unilateral NDA (one-way)

Only one party discloses confidential information and the other undertakes to protect it. This is the standard format in a classic sale process: the seller provides information and the buyer (or private equity fund) receives it and undertakes not to use it. It is also typical when engaging a supplier or consultant who accesses internal information without contributing any of their own.

Bilateral or Mutual NDA

Both parties exchange confidential information and assume reciprocal obligations. This is the appropriate format where two companies are exploring a merger of equals, a joint venture or a strategic alliance, and both “lift the hood” to show each other their numbers and processes. A common error is signing a unilateral NDA when, in fact, both parties exchange information: the result is that only one of them is protected.

Multilateral NDA

Three or more parties are involved and at least one shares information the others must protect. It replaces multiple bilateral agreements with a single contract, and is common in research consortia, club deals or projects involving several investors. Its complexity increases because access levels must be defined among all participants.

Enhanced NDA with non-solicitation and non-use clauses

In serious transactions, the NDA is usually reinforced with two additional clauses:

  • Non-use: restricts the use of the information strictly to evaluating the potential transaction, prohibiting its use to develop competing products, register patents or compete.
  • Non-solicitation: prevents the counterparty, leveraging access gained during due diligence, from poaching key employees, clients or suppliers. In Spain, their validity requires the restriction to be reasonable in duration and scope; typical periods range from one to two years. Where the restriction affects employees through an employment contract, Article 21.2 of the Workers’ Statute sets strict limits (financial compensation and a maximum duration of two years for technical staff, six months for others).

Essential clauses of a well-drafted NDA

Definition of Confidential Information

This is the heart of the agreement. It must be broad but specific: financial, commercial, operational and technical information, employee and client data, and even the very existence of the transaction. Commercial case law (particularly the Barcelona courts) rejects generic formulas such as “all commercial information.” It is advisable to enumerate categories and to include an identification mechanism (labelling or notification). In parallel, the exclusions must be detailed: information already in the public domain, information the recipient already lawfully knew, information lawfully received from a third party with no duty of secrecy, or information independently developed.

Term and Duration

This is where one of the most common pitfalls lies. Two distinct periods must be distinguished:

  • The term of the agreement for the exchange of information (while the negotiation lasts).
  • The survival period or survival of the duty of secrecy (how long the confidentiality obligation persists once the relationship ends).

In M&A, the standard duration of the obligation ranges from two to five years. For especially sensitive information—industrial secrets, formulas, source code, client lists—the obligation may be indefinite or very long, in line with trade-secret protection. Beware of two extremes: short terms of 6 to 12 months are clearly insufficient in a corporate transaction (the information remains sensitive long afterwards), while blanket “perpetual” clauses may be declared void as unduly restrictive. Best practice recommends three to five years for ordinary information and indefinite duration only for substantiated trade secrets.

Obligations of the receiving party

A duty of non-disclosure, use limited to the agreed purpose, a prohibition on copying save with authorisation, safekeeping with the same diligence applied to the party’s own information, and a duty to report any unauthorised access or loss. The duty must extend to the recipient’s employees, advisors and external suppliers, who must assume equivalent obligations in writing; otherwise, every link without an NDA is a leakage point.

Permitted disclosure exceptions

There are situations in which information may be disclosed WITHOUT breaching the NDA: where it is already in the public domain (through no fault of the recipient), where the recipient knew it beforehand, where it is lawfully obtained from a third party with no duty of secrecy, or where a legal, judicial or regulatory obligation requires disclosure. Defining these exceptions well does not weaken the NDA: it makes it more robust and reduces disputes.

Consequences of breach

An NDA without clear consequences is a dead letter. The usual tools are:

  • Damages under Article 1101 of the Civil Code, which requires those acting with wilful misconduct, negligence or default to indemnify the injured party. Its drawback: the actual harm, the causal link and the amount must be proven, which is notoriously difficult in an information leak.
  • Liquidated damages clause (cláusula penal) (Articles 1152 to 1155 of the Civil Code), setting a pre-agreed indemnity enforceable without proving the specific harm. It is the most effective tool: Article 1152 provides that the penalty replaces damages unless otherwise agreed, and the parties may expressly agree to combine it with the Article 1101 indemnity. A court may only mitigate it (Article 1154) in cases of partial or irregular performance.
  • Interim injunctive relief to halt the use or disclosure immediately.
  • Reimbursement of legal costs, if agreed.
  • Potential criminal consequences. Here it is worth correcting a widespread error: trade secrets are NOT protected by Article 197 of the Criminal Code (which protects the privacy and personal data of individuals), but by Articles 278, 279 and 280 of the Criminal Code, within the offences against the market and consumers. Article 278 punishes the seizure of data or media to discover a trade secret (industrial espionage), with an aggravated penalty if the secrets are disseminated; Article 279 sanctions the dissemination, disclosure or transfer of the secret by a person who was contractually or legally bound to keep it confidential; and Article 280 punishes anyone who, knowing of its unlawful origin and without having taken part in its discovery, uses or discloses the secret.

Governing law, jurisdiction and arbitration

The NDA should be expressly governed by Spanish law and should designate the forum. For disputes between companies, jurisdiction is usually conferred on the Commercial Courts (Juzgados de lo Mercantil) of the secret holder’s domicile. In M&A transactions, arbitration is generally preferable to ordinary jurisdiction for a decisive reason: confidentiality and procedural privacy. Whereas court judgments are public, arbitral proceedings allow both the terms of the contract and the very existence of the dispute to be kept secret—particularly valuable where the matter at stake is precisely confidential information. Arbitration also offers technical specialisation and shorter timelines.

Return or destruction of information

The NDA must provide for what happens to the information when the process closes (or is abandoned): the obligation to return or destroy all documentation received, including copies, with certified destruction. Without this clause, documents remain in circulation beyond control and exposure is prolonged indefinitely.

The NDA in M&A: Why it is the first signature in the process

When the NDA is signed in a sale process

In an orderly sale, the sequence is clear. The seller’s advisor first circulates a Teaser or blind profile: a brief, anonymous document that presents the opportunity without revealing the company’s identity. At this stage no NDA is yet required, because the party behind it is not disclosed. Only when a buyer expresses interest is it asked to sign the NDA; once signed, the name is revealed and full information is provided. Later, if the buyer progresses, the Letter of Intent (LOI) is negotiated, reiterating and reinforcing confidentiality. The sequence is therefore: Teaser/Blind Profile → NDA → LOI → due diligence.

What the NDA protects at each phase

The NDA covers an escalating scale of sensitivity. First, the Information Memorandum (Infomemo) or sale book, a detailed document (20–50 pages) with accounts, clients, team and market positioning. Next, the financial projections and business plan. Finally, the Data Room in the due diligence phase, where the most sensitive contractual, employment, tax and legal documentation is uploaded. Each level requires a reinforced protection framework, which is why the initial NDA is usually supplemented with specific schedules governing data-room access.

Information that should never be disclosed until an advanced phase

Some information should not be disclosed even with a signed NDA, especially where the prospective buyer is a direct competitor: per-client pricing, margins, individual contracts, industrial secrets or granular commercial strategy. For these cases a Clean Room is used: a restricted environment accessible only to a Clean Team—a small group of external advisors with no role in the buyer’s commercial decisions—that analyses the sensitive information and provides the client only with aggregated, anonymised conclusions. It is the standard tool for reconciling due diligence with competition law.

The paradigmatic case is Altice/PT Portugal: in April 2018 the European Commission fined Altice EUR 124.5 million for gun-jumping, finding that certain confidential commercial information had already been exchanged from the signing of the SPA; the fine was upheld by the General Court and by the Court of Justice of the EU in November 2023, which adjusted one of the fines to EUR 52,912,500.

Common NDA mistakes in M&A that destroy value

The most frequent in the lower and middle market:

  • Accepting the buyer’s NDA without reviewing it. Funds and corporates have their own template, drafted to protect them. It must be negotiated, not signed as is.
  • Failing to include a non-solicitation clause, leaving the buyer free to identify and hire key employees.
  • Defining confidential information too narrowly, excluding anything not marked as confidential.
  • Terms that are too short (one year is insufficient in M&A).
  • Failing to bind the buyer’s external advisors (lawyers, auditors, consultants).
  • Signing the NDA only with a resourceless subsidiary instead of with the group’s parent. Where the buyer operates through a holding structure, the obligor should be the parent company or the parent should guarantee performance; otherwise, any eventual claim may run up against an empty shell.

NDA Templates: Why a downloadable form does not protect you in serious deals

Searching for a free “NDA template Word” or “NDA sample” is tempting for speed, but dangerous in a corporate transaction. What do these generic templates contain? A basic structure: the parties, a cursory definition of confidential information, a term, and little else.

What is systematically missing? Adaptation to the specific transaction: a definition of information calibrated to the business, well-constructed exclusions, the distinction between term and survival period, non-use and non-solicitation clauses, a proportionate liquidated-damages clause, rules governing advisor and data-room access, and the choice of forum and governing law.

The real risk is threefold: templates from foreign jurisdictions citing laws inapplicable in Spain (which may render the contract void); residual data from other companies through reuse (the “Frankenstein effect”); and the absence of the data-protection clauses now mandatory. A poorly conceived NDA creates a false sense of security that is only discovered once the damage is done.

How should a template be used correctly? As a starting point to understand the structure, never as the final document. In a serious transaction, the NDA should be reviewed or drafted by a professional who understands the business and the mechanics of the deal. That is why, rather than offering a template, at Maraz we prefer to support the drafting and negotiation of the agreement appropriate to each transaction.

How Maraz Corporate Finance supports the signing of M&A NDAs

At Maraz Corporate Finance we integrate the NDA into the overall transaction strategy, not as an isolated formality:

  • Review of buyers’ NDAs, identifying clauses skewed in favour of the other side before our client signs.
  • Bespoke drafting of the agreement where the seller is the proposing party, calibrated to each counterparty’s profile.
  • Staged information-disclosure strategy: teaser → infomemo → data room → clean room, so that each level of information is released only when the buyer’s commitment warrants it.
  • Coordination with specialist corporate lawyers on the client’s side, contributing the financial and process perspective that complements the legal one.
  • Experience in the Spanish middle market, where we know the usual practices of funds and industrial buyers.

If you are considering selling, raising investment or exploring a corporate transaction, our M&A transaction advisory team can help you protect your information from the very first conversation.

NDA FAQs

What exactly is an NDA?

An NDA (Non-Disclosure Agreement) is a contract under which one or more parties undertake to keep secret the confidential information they receive and not to use it beyond the agreed purpose. It is legally binding and known in Spanish as an acuerdo de confidencialidad.

Is an NDA the same as a confidentiality agreement?

Yes. NDA, confidentiality agreement, confidentiality contract and non-disclosure agreement are equivalent names for the same legal instrument. The difference is purely one of language or style.

Is an NDA legally valid in Spain?

Yes, fully. It is grounded in Article 1255 of the Civil Code, reinforced by Law 1/2019 on Trade Secrets and Law 3/1991 on Unfair Competition, and enforceable before the courts as a signed private document, with no notary required.

How long does an NDA typically last?

In M&A, the usual confidentiality obligation runs between two and five years. For highly sensitive information it may be indefinite. It is important to distinguish the term of the agreement for exchanging information from the survival period of the duty of secrecy. One-year terms are insufficient in a corporate transaction.

What happens if someone breaches an NDA?

The holder can claim the agreed liquidated-damages clause (enforceable without proving the harm), additional damages (Article 1101 of the Civil Code), interim injunctive relief, and the actions under Law 1/2019. In serious cases, the disclosure of trade secrets may constitute a criminal offence under Articles 278 to 280 of the Criminal Code.

Is it mandatory to sign an NDA before due diligence?

It is not a legal obligation, but it is essential in practice. No prudent seller opens its data room without a signed NDA: doing so would amount to voluntary disclosure that would leave the information unprotected if the deal does not close.

Can I use an NDA template downloaded from the internet?

As a starting point to understand the structure, yes; as the final document in a serious transaction, no. Generic templates tend to omit critical clauses, cite inapplicable legislation or carry over data from other contracts. In an M&A transaction, the NDA should be reviewed or tailored by a professional.

Javier de Rojas Roca de Togores

Partner – Maraz Corporate Finance