BUSINESS & TECHNOLOGY CONTRACTING

Cross-Border NDAs: Why Enforceability is Never Guaranteed

Non-Disclosure Agreements (NDAs) are often treated as the “easy” part of cross-border deals-short, standardized, and signed quickly to unlock negotiations.
But here’s the uncomfortable truth: once your NDA crosses jurisdictions, enforceability is never guaranteed.

In international transactions, NDA failure is one of the most common early-stage causes of IP leakage. The risk is structural, not theoretical.

Common-law jurisdictions (US, UK) treat NDAs as straightforward contracts with predictable remedies.
Civil-law jurisdictions (Germany, France) often rely on statutory duties-good faith, unfair competition, proportionality-rather than contract language alone.

The same clause can be interpreted entirely differently depending on where it lands.

Example:
A US-style NDA requiring indefinite confidentiality may be enforceable in New York but struck down in France, where courts expect confidentiality periods to be proportionate and tied to legitimate commercial interests.

Courts routinely refuse to enforce NDA provisions that conflict with local public policy. Overly broad restrictions on employee mobility or knowledge sharing may be invalid in Europe even if acceptable in the US.

Public-policy overrides are one of the most common reasons NDAs fail internationally.

Parties often specify governing law but forget that enforcement depends on the court that hears the dispute.

A South African company may choose English law, but if the dispute arises in Germany, German judges will apply their own procedural rules-and may not honor the NDA as drafted.

Scenario:
You choose English law. Your counterparty leaks information in Munich. You sue. The German court acknowledges the English governing law clause-but applies German procedural rules and German public-policy limits. Your carefully drafted NDA suddenly becomes a suggestion, not a shield.

Modern confidentiality obligations don’t exist in a vacuum. GDPR, POPIA, and similar regimes impose mandatory rules on data handling, retention, and disclosure-rules that override any conflicting NDA clause.

This means an NDA cannot:

  • Authorize transfers that violate local data-export restrictions
  • Permit retention periods longer than statutory limits
  • Override mandatory breach-notification duties

In cross-border deals, data-transfer compliance is often more determinative than the NDA itself.

Even when an NDA is technically enforceable, cross-border litigation or arbitration is slow, expensive, and uncertain.
By the time you secure a judgment, the confidential information may already have lost its value.

This is why experienced negotiators treat NDAs as deterrents, not remedies.

NDAs are not useless. They work best when:

  • The parties operate in the same legal tradition
  • The information disclosed is low-sensitivity
  • The relationship is ongoing and commercially valuable
  • The counterparty is reputationally constrained

In these contexts, NDAs function as behavioural anchors-signals of professionalism and intent-rather than litigation tools.

Avoid one-size-fits-all templates.
Tailor clauses to reflect the legal sensitivities of each jurisdiction involved.

Release low-sensitivity information first. Escalate only once trust and compliance are demonstrated.

Technical safeguards-data-access controls, staged disclosures, IP registrations-often protect confidential information more effectively than paper promises.

A 30-minute consult can save a multi-million-rand leak.

Arbitration offers neutrality, but enforcement still depends on local courts.
Check whether the New York Convention applies in all relevant jurisdictions.

Liquidated damages, escrowed penalties, or accelerated injunctive relief can create real deterrence.

Confidentiality should sit inside licensing terms, performance guarantees, and compliance mechanisms-not rely solely on a standalone NDA.

Cross-border NDAs are not worthless, but they are not bulletproof either.
They signal intent and professionalism, not guaranteed protection.

Smart negotiators treat NDAs as one layer in a multi-layered protection strategy.

Assume your NDA will fail. Then design your information-protection strategy accordingly.
The real question is not whether your NDA is enforceable, but:
What practical steps are you taking to protect your information if the NDA fails?

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2025 Centre For Innovative Commerce CC
Privacy Policy Terms and Conditions Sitemap