Custom development is virtually impossible without transferring confidential information (CI) to the developer. Otherwise, how can it be considered custom?
The larger the client, the more complicated it is to agree on the terms of the confidentiality agreement. A standard contract is likely to be excessive with almost 100% certainty.
As a result, along with the minimum amount of information necessary for work, one might end up with a heap of obligations – to store and protect it as if it were one’s own, for many years, even after the expiration of the agreement. To keep records, organize storage, compensate for losses. To allow the disclosing party the opportunity for audit. To pay multimillion-dollar fines for the mere act of disclosure. Who knows what else. It’s a standard form, approved by the chairman of the board; changes cannot be made.
To be able to do one’s job without worries, one needs to have the clearest possible scope of obligations. This simple truth can be realized through a few conditions.
- Indicating that the NDA applies to a specific project. The temptation to extend it to all existing and future projects is strong; why sign something extra? But the smaller the scope, the fewer resources are required for its storage, fewer people can access it, and the risks of disclosure are lower.
- Confidential information – only written, marked as ‘confidential’. Allowing for a clear understanding of whether the confidentiality regime applies to specific information or not. In this case, labeling the information is the client’s responsibility. Avoid formulations like ‘any information’.
- Not all sensitive information can be returned or destroyed. The "residual" clause is used in standard NDAs of companies like Microsoft. It establishes the right to data that remains as a result of access to sensitive information, existing outside of material carriers (for example, in the memory of the person who had access to the sensitive information), including ideas, principles, and methods. Neither party has the right to restrict or prohibit the use of "residual" information by such individuals, nor can they charge for its use. This provision does not apply to patent and copyright objects that legally belong to the disclosing party.
- Personal data – don't forget to include the obligation for the disclosing party to obtain the subject's consent for the transfer of their personal data to the receiving party, and to provide this consent upon the receiving party's request (for example, in the case of an audit). It’s also important to notify the subject that their data has been transferred to a third party (especially relevant for European citizens).
- The right to return sensitive information early. If we receive something unnecessary (for example, excess or irrelevant to the project), we should not hesitate to return the sensitive information to its owner (the material carrier) or notify them of its destruction (if there is nothing to return).
- There is no double or triple liability for the same violation. An accidental data leak cannot be used as a means of enrichment for one of the parties. We limit ourselves to direct documented damages (not losses, which would imply damages + lost profits) within 30-70% of the project cost.
Each of these conditions is logical and also protects the client – the less sensitive information is disclosed, the lower the risk of leaks. There is no redundancy, just a clear scope of obligations. Protect yourself and your confidential information.
Source: habr.com
