01

When should an NDA be signed, and is a separate agreement always required?

An NDA is particularly useful before:

The Polish Civil Code protects information supplied during negotiations where it was made available subject to a confidentiality reservation. The recipient should not disclose it, supply it to others or use it for its own purposes. A breach may give rise to damages or an obligation to surrender benefits. A separate NDA remains useful because it can specify the information, purpose, authorised persons, protection period, return of materials, governing law and contractual remedies.

An NDA may be unilateral or mutual. A unilateral document fits a process in which only one party provides sensitive information. A mutual NDA is appropriate where both parties exchange their own confidential material. Using a mutual template automatically may impose unnecessary obligations on a party that does not in fact receive anything confidential.

  • commercial or investment negotiations;
  • disclosure of documents in due diligence;
  • a technology presentation, source-code review, prototype or pre-launch product demonstration;
  • sharing price structures, margins, customer lists or sales strategy;
  • onboarding a consultant, software house or subcontractor;
  • discussions about a joint venture or distribution partnership.
02

When does information qualify as a trade secret in Poland?

Under the Polish Act on Combating Unfair Competition, a trade secret includes technical, technological, organisational or other information with commercial value that, as a whole or in its particular combination, is not generally known or readily accessible to persons who normally deal with that type of information, provided that the person entitled to use or control it has taken steps, with due care, to keep it confidential.

This creates three practical conditions:

A signed NDA is important evidence of the third condition, but it should rarely be the only measure. If sensitive files are placed in an unrestricted folder, every employee can access all project documents and no recipient records are kept, it becomes harder to demonstrate consistent confidentiality measures.

Not every internal fact automatically qualifies as a trade secret. A public price list, register data or general industry knowledge does not acquire statutory status merely because the contract calls it confidential. The parties may nevertheless contractually protect a broader category of information, provided the obligation is sufficiently clear and lawful.

  • the information has actual or potential commercial value;
  • it is not generally known or readily accessible in the relevant field;
  • the business genuinely protects it.
03

How should confidential information and the permitted purpose be defined?

The definition should reflect the categories used in the relationship, for example:

The definition may cover oral, visual, electronic and written disclosures. Oral information can be subject to a later confirmation process. In an intensive due diligence exercise, requiring every file to be individually stamped “confidential” may be impractical. Conversely, a definition with no objective boundaries makes it difficult for the recipient to identify protected material.

Typical exclusions concern information that the recipient:

Purpose limitation is equally important. The recipient should use the information only to assess a defined transaction, perform the project or prepare a proposal. A clause that prohibits only “disclosure” leaves a gap if the recipient keeps the information private but uses it to build a competing solution or approach the discloser’s customer.

  • pricing models, margins and forecasts;
  • customer lists and terms of customer contracts;
  • source code, architecture, technical documentation and vulnerabilities;
  • product roadmaps, research results and prototypes;
  • negotiation strategy and transaction documents;
  • internal processes and know-how.
  • lawfully possessed before disclosure;
  • lawfully receives from a third party without a confidentiality duty;
  • develops independently without using the discloser’s information;
  • can demonstrate is publicly available without breach;
  • must disclose under applicable law, a final court order or a competent authority’s requirement.
04

Who may receive information and how should the confidentiality chain work?

The NDA should identify permitted recipients, such as employees with a need to know, board members, group companies, financing sources and external advisers. Access should follow the need-to-know principle.

The parties should determine whether those recipients are already bound by professional or statutory secrecy or need equivalent contractual obligations. The receiving party will normally be responsible for people to whom it discloses the materials within the permitted group.

In transaction negotiations, the parties may also require prior consent before contacting the discloser’s employees, customers or suppliers. This is not simply a confidentiality term, but it may protect the process from disruption or premature disclosure of a proposed deal. The restriction should be proportionate and linked to the transaction.

05

How long should confidentiality last?

There is no single period suitable for every category. Information about a short campaign or an outdated price list may lose sensitivity quickly; source code, a formula, an algorithm or long-term strategy may need protection for much longer.

The parties may combine:

An indefinite obligation covering every piece of information can be difficult to administer and may be disproportionate. A more workable structure differentiates categories and states which duties expire after a set period and which depend on continued secrecy.

Return or destruction provisions should cover documents, copies and working notes, with realistic exceptions for automatic backups, legal archives and materials that must be retained by law. Those exceptions should not permit continued operational use.

  • a defined term for the NDA;
  • a longer confidentiality period following the end of discussions;
  • protection for statutory trade secrets for as long as they retain that status.
06

Which remedies and contractual penalties should be considered?

A breach of an NDA may create contractual liability. If the information also meets the statutory trade-secret test, the Polish Act on Combating Unfair Competition may support claims including cessation of the infringement, removal of its effects, damages and surrender of unjustified benefits.

Quantifying loss after disclosure of know-how can be difficult. Parties therefore often use a contractual penalty for breach of the non-monetary confidentiality obligation. The clause should determine:

An excessive penalty may be reduced by a court, while an unclear mechanism creates a dispute over calculation. Its design should reflect the importance of the information, project scale and realistic harm. The issue is examined further in Contractual penalties in Polish B2B agreements.

A contractual penalty does not replace other remedies. If the misuse continues, swift action to stop disclosure or use and preserve evidence may be more important than a later damages calculation.

  • which conduct triggers the penalty;
  • whether it applies per breach, per item or per event;
  • whether a continuing breach produces periodic accrual;
  • the aggregate cap, if any;
  • whether damages exceeding the penalty remain recoverable.
07

How should the NDA be implemented in practice?

Confidentiality should be visible in day-to-day operations. Depending on the risk and scale, a business may:

For a company sale, the parties may use a virtual data room, staged access and redaction of the most sensitive information until discussions are advanced. The preparation process is covered in How to prepare a Polish company for legal due diligence.

  • grant access only to people who need the information;
  • use named accounts, multi-factor authentication and access logs;
  • separate materials by sensitivity;
  • mark key documents and retain a disclosure index;
  • use a controlled repository rather than an open link;
  • train the team on disclosure rules;
  • bind advisers and subcontractors to appropriate duties;
  • close access and confirm return or deletion at the end of the process.
PRACTICE

How the issue appears in practice

Example

Hypothetical example: product documentation shared through an open link

A software producer discusses a distribution partnership. The parties sign a generic NDA covering “all information concerning the business”, but it does not define the purpose or authorised recipients. The producer sends an open folder link containing the product roadmap, architecture, key-customer pricing and a vulnerability report. The link is forwarded to a technical adviser who is not subject to an equivalent duty. The producer keeps no access logs and does not revoke access when negotiations end. Several months later, a competing feature similar to the roadmap appears on the market. The producer has an NDA, but it is difficult to establish who downloaded the document, which information was genuinely protected and whether the counterparty used it beyond the permitted purpose. The proper process would have used a tailored definition, a purpose limited to evaluating the partnership, named repository access, equivalent adviser obligations, download records and access closure at the end. The most sensitive information should have been disclosed in stages once a genuine need was confirmed.

Working checklist

Matters to determine or verify before proceeding

  • Which specific information has commercial value and needs protection?
  • Will the NDA be signed before the first disclosure?
  • Should the obligation be unilateral or mutual?
  • For which precise purpose may the recipient use the information?
  • Which employees, group entities, financing sources and advisers may receive access?
  • Which confidentiality exclusions are required and who must prove that they apply?
  • How long should each category remain protected?
  • How will the business document access, return or deletion and any breach?

Key issues at a glance

IssueKey information
Contractual confidential informationIts scope derives from the NDA and may be broader than the statutory trade-secret definition.
Statutory trade secretRequires commercial value, lack of general availability and genuine measures designed to preserve confidentiality.
Public informationDoes not become a trade secret merely because an NDA labels it confidential.
Permitted purposeShould restrict both disclosure and use of the information.
Further recipientsShould receive access only where needed and be subject to equivalent duties.
Contractual penaltyMay facilitate a claim but requires a clear trigger, calculation method and relationship with additional damages.
LEGAL BASIS

Legal basis

  • Polish Civil Code of 23 April 1964, in particular Articles 72¹, 353¹, 471 and 483–484.
  • Polish Act of 16 April 1993 on Combating Unfair Competition, in particular Articles 11 and 18.
  • Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 on the protection of undisclosed know-how and business information against their unlawful acquisition, use and disclosure.
Explore this areaBusiness in Poland

This article provides general information and does not constitute legal advice for a specific matter. The appropriate solution depends on the facts, documents and business objective.

Summary

An effective NDA combines tailored drafting, genuine organisational safeguards and evidence of what was disclosed and who had access. A broad definition cannot repair an uncontrolled document flow, while technical controls alone do not define the permitted use. The contractual and operational levels should be designed together.