Understanding Confidentiality
Last Updated: March 31, 2026
Disclaimer: This guide provides a framework for analysis and is not legal advice. For specific ambiguities or high-stakes situations, refer to the Risk Assessment Guide or consult qualified legal counsel.
“Confidentiality” rules in agreements protect certain types of information. How can you identify what type of information is protected, and what type of information can be freely shared??
The answer lies in shifting your mindset. Start by asking the basic question: “What can I share?” — this will help you identify what information is actually considered “confidential.”
Quick Start
Use this framework to analyze potential confidentiality obligations. (Often you’ll find that you aren’t as limited as you think!)
- Determine Your Obligations: Confirm whether, and how, you’re legally bound to silence.
- Analyze the Contract: Locate the definition of “Confidential Information,” any language inferring confidentiality, and any exceptions.
- Categorize the Data: Use the steps outlined in this guide to filter the specific information you want to share.
- Move to Next Steps: Know when to ask for help or how to assess risk.
Step 1: Determine Your Obligations
Before analyzing what you can say, first confirm whether you have any obligation to keep information confidential.
You Might Have a Legal Obligation of Confidentiality If:
- You Signed Something: Someone at your organization signed a Non-Disclosure Agreement (“NDA”) or other agreement.
- You Clicked Something: Someone at your organization accepted a clickthrough “Terms of Service” or “EULA” before accessing software or a platform. NOTE: If your organization is using software, it’s highly likely that someone agreed to that software’s terms.
You Likely Do NOT Have an Obligation If:
- You Received Unilateral Notice: You only received an email footer or verbal warning mentioning confidentiality, but never signed or agreed to anything.
- There’s No Contract: Your organization has been in discussions with another party about business ideas or received a pitch, but hasn’t signed any documents or started using that party’s software or service.
Step 2: Analyze the Contract: What’s Off-Limits?
Confidentiality obligations can exist in multiple places in a document, so read through the language carefully!
A. Where to Find the Language
Scan your agreement for these clauses. They may create confidentiality obligations in specific ways:
- Confidentiality: Typically outlines the scope of your obligations based on the definition of “Confidential Information”.
- Payment & Pricing: Might restrict you from sharing rates, royalties, or fee structures.
- Term & Termination: Often describes how long any confidentiality obligations will last. Look for “survival” language here, which can extend the confidentiality term beyond the end of the rest of the contract.
- Publicity / Marketing: Might limit what you can say publicly about the relationship.
- Grant of Rights: Might restrict how you describe the licensed material, but might only restrict what you can use it for.
- Deliverables / Work Product: Some work product might be considered “confidential” until it’s publicly released (like a newly-developed game), but some or all aspects of that confidentiality might expire upon release. For example, the existence of the work product would be publicly known, but the details of funding or development might still be confidential.
B. Keywords
If you don’t see a “Confidentiality” header or language in the clauses above, Ctrl+F for:
- Proprietary
- Trade Secret
- Restricted
- Shall not disclose
- Confidential
C. The Analysis Checklist
Use this mental model to extract the rules from your document:
- The Definition: Confidentiality obligations only apply to information that everyone agrees is confidential. Is “Confidential Information” defined broadly (“this contract and its terms”) or narrowly (“only items marked Confidential”)?
- The Exclusions: Does it explicitly exclude information that is Public, Already Known, Independently Developed, or Required by Law to be shared?
- The Duration: Is the obligation fixed (e.g., “3 years from disclosure”) or indefinite?
Step 3: Categorize Your Data: Use the Decision Framework
Follow this Framework and use these Decision Points to evaluate and categorize the information you have. You can also use the appended Decision Flowchart to help filter that information; the logic below mirrors the decision points in the graphic.
First Decision Point: Is the Information Publicly Known?
- The Test: Is the information already available through an authorized public channel (e.g., the vendor’s website, official press releases, or government records)? NOTE: even information that is widely discussed in a community isn’t necessarily “publicly known.”
- Yes: STOP. This is low risk. You are likely free to share.
- No / Unsure: Proceed to Decision Point 2.
Second Decision Point: Is the Information Considered “Confidential” Under Your Contract?
- The Test: Check your contract, Terms of Service, or End User License Agreement (”EULA”) language.
- Does the definition of “Confidential Information” include the category of information you want to share?
- Does any other clause in your contract concern the type of information you want to share, and if so, does that clause limit sharing?
- No: (e.g., the language only limits sharing user metrics, and you want to discuss your payment terms). STOP. This is low risk, and you are likely free to share, but exercise professional courtesy before you do!
- Yes: Proceed to Decision Point 3.
Third Decision Point: Is There an Applicable Exception?
- The Test: Check the “Exclusions” or “Exceptions” clause.
- Did you already know this information before entering into an agreement?
- Did you develop this information independently (e.g., your own metrics)?
- Are you required by law (FOIA/court order) to disclose it?
- Yes: STOP. Low risk. You may share, but check for notification requirements (e.g., “prompt notice” to the third party).
- No: STOP. This is likely restricted information, so proceed to risk assessment.
Step 4: Move to Next Steps
If you reach the end of the Framework and you are unsure about whether your information really is confidential, you have two paths:
Path A: Consult Legal Counsel
Use these specific questions to get direct, high-value answers:
- Before Entering an Agreement: “Is the definition of ‘Confidential Information’ too broad? It seems to cover our own data.”
- Existing Agreement: “I want to share [X], which I think is public knowledge. Does this fall under a standard exception, or any exceptions in Clause [Y]?”
- Known Risk: “We received a FOIA request for this contract. The terms say that the entire agreement is ‘Confidential.’ What do we need to do?”
Path B: Risk Assessment (No Counsel Available)
If you do not have immediate access to legal counsel, refer to the Risk Assessment Guide to evaluate the potential consequences of sharing the information.
Conclusion
Confidentiality obligations might appear tricky and onerous, but you can navigate them by following the steps above and referencing the flowchart in the appendix. When in doubt, assess your (and your organization’s) risk in sharing the information you want to share (or consult qualified counsel!) before you proceed to share.