M&A NDA: Key Clauses, Timing, and Best Practices for 2026

Updated: Sep 29 ‘26 Published: Sep 29 ‘26 31 min read

No time to read? Get a quick AI summary

Before a seller shares revenue figures, customer lists, product roadmaps, or other sensitive deal materials, a single document must be signed. This is true whether one company purchases another, two companies combine, or investment bankers manage a competitive buyer process. 

The M&A NDA (non-disclosure agreement) is the first binding contract in nearly every deal. Without it, a seller lacks contractual protection once discussions become substantive.

  • For public company targets, an inadequately drafted NDA creates securities-law exposure and may create securities-law and MNPI control issues if confidential discussions affect trading activity. 
  • For private companies, a weak agreement can hand a rival buyer a roadmap to the customer base, employees, pricing, and market position, with no contractual remedy if things go wrong.

This guide covers what deal professionals need to know about the M&A non-disclosure agreement: what it is, when to sign it, which clauses matter most, how buyers and sellers negotiate it differently, and how the virtual data room operationalizes enforcement in practice.

Key takeaways

  • The M&A NDA is the first signed document in nearly every deal and must be in place before the CIM is shared.
  • “NDA” and “confidentiality agreement” are functionally identical in M&A. The label matters less than the clauses and how well they protect the seller’s information.
  • One-way NDAs are standard in sell-side auctions; mutual NDAs are appropriate when two firms exchange sensitive information.
  • The residuals clause is the most dangerous provision for sellers, often buried in boilerplate. Sellers should resist it or explicitly exclude trade secrets.
  • Standstill provisions are essential for public company targets because they help prevent a buyer from using confidential information to support an unsolicited bid or hostile takeover.
  • The virtual data room enforces NDA obligations through clickwrap acceptance, phased access, audit trails, watermarking, and download restrictions. These are crucial operational controls.
  • NDA protections should reflect the transaction context, especially when an acquisition occurs in the same industry, the buyer operates competing business models, or sensitive materials will later support post-merger integration.
  • AI/LLM training prohibitions are increasingly standard in sophisticated NDA negotiations and should be included by default for deals involving proprietary technology or data.

What is an M&A NDA?

An M&A NDA (non-disclosure agreement) is a legally binding contract requiring the recipient of confidential business information, typically a prospective buyer or investor, to keep that information confidential, use it only to evaluate the potential transaction, and return or destroy it if the deal does not proceed. It defines what counts as confidential, who may access it, and what remedies apply if information is misused.

In practice, the NDA protects the seller while the parties assess whether the transaction makes commercial and legal sense. It may apply when two businesses explore a merger, when an acquisition would transfer ownership of the acquired firm, or when the buyer needs access to sensitive information before the parties agree on final deal terms.

The NDA also helps control disclosure of financial records, customer data, working capital details, market share information, and other materials that could affect valuation or negotiation leverage. 

Additionally, M&A NDAs are sometimes referred to as confidentiality agreements (CAs) – the terms are functionally identical in deal contexts. Some practitioners use “CA” for longer, bilaterally negotiated forms and “NDA” for shorter, unilateral documents, but courts treat them the same. 

In life sciences and pharma, “Confidential Disclosure Agreement” (CDA) is the more common label, though the legal structure is identical.

Why the Merger and Acquisition NDA Matters

The NDA is the legal foundation that enables structured disclosure. Proceeding without one or with a weak one leaves sellers exposed on several fronts:

  • Trade secret exposure. The Defend Trade Secrets Act requires owners to take “reasonable measures” to protect the status of trade secrets. Disclosing without an NDA can undermine trade secret protection.
  • Competitor intelligence. A strategic acquirer can extract significant competitive intelligence from the CIM and data room, then walk away from the deal with the information intact.
  • Employee and customer poaching. Without a non-solicitation clause, a buyer who learns which employees drive revenue or which customers represent 80% of ARR may face no contractual restriction on approaching them directly.
  • Securities law risk. Public companies must control material non-public information (MNPI). A standstill provision preventing the buyer from acquiring shares or making unsolicited bids is often an important control.

When Do You Sign an NDA in the M&A Process?

The NDA for M&A is signed before any sensitive information changes hands — typically after an initial teaser but before the CIM is released. Here is the standard deal sequence:

  • Initial outreach/teaser. High-level, anonymized summary shared with no NDA required.
  • NDA signed. The gate before any confidential information is disclosed.
  • CIM shared. Detailed financials, customer data, and strategy released to signed bidders only.
  • Indications of interest (IOIs) / first-round bids. Non-binding bids submitted based on the CIM.
  • Phase 1 data room. Curated access for shortlisted bidders; sensitive items remain restricted.
  • LOI signed. The preferred buyer signs the letter of intent; the exclusivity period begins.
  • Confirmatory due diligence (full data room). The complete data room opens to the preferred buyer.
  • Definitive agreement/close: Purchase agreement executed; transaction closes.
  • Pro tip: A common mistake is treating the NDA as a post-LOI step. It must be in place at Step 2 before the CIM is shared. Releasing the CIM without a signed NDA is one of the most avoidable confidentiality failures in M&A.

One-Way vs. Mutual M&A NDAs

The first structural question in any M&A NDA is directionality: is only the buyer bound, or are both parties?

One-Way (Unilateral)Mutual (Bilateral)
Who is boundBuyer only.Both buyer and seller.
Typical useSell-side auction, asset/stock sale.Merger, stock-for-stock deal, bilateral negotiation.
When to useWhen the seller shares confidential information with bidders evaluating the target firm.When both sides exchange sensitive materials, such as financial projections, integration plans, debt financing details, or strategic rationale. 
Main purposeProtects seller information while bidders assess risk and deal value.Protects both sides when the companies involved are sharing commercially sensitive information.
Common deal contextCompetitive auction with several bidders; simpler and faster to sign.A strategic transaction where two or more companies may form a combined company or new entity.

In auction processes, a one-way NDA is standard: the seller sends a form, and bidders sign before receiving the CIM or accessing the data room. This works well when only the seller is disclosing sensitive information.

In mergers or strategic combinations, a mutual NDA is usually more appropriate. If both sides share financial projections, customer data, technology plans, or integration assumptions, each party needs protection before discussions move into detailed negotiation.

M&A NDA Key Clauses

The following clauses appear in virtually every M&A non-disclosure agreement. Knowing what each does and where the negotiating tension lies separates a functional NDA from one that fails under pressure. 

1. Definition of Confidential Information

The most consequential clause. A broad definition covers all non-public information shared in connection with the transaction, written, oral, electronic, or visual, including “existence of discussions” protection. 

A narrow definition limited to marked documents creates gaps, particularly for oral disclosures in management presentations. Sellers should push for broad; buyers typically prefer a marking requirement.

2. Exclusions from Confidentiality

Standard carve-outs protect buyers from liability for information that was not truly confidential:

  • Information already publicly known
  • Information the buyer possessed before signing
  • Information was independently developed without using the seller’s confidential information
  • Information received from a third party that is not bound by a confidentiality obligation. 

Sellers should accept these exclusions but ensure “publicly known” means generally available, not merely discoverable with significant research.

3. Permitted Use and Permitted Disclosures

The permitted use clause restricts the buyer to using confidential information solely to evaluate the transaction. Permitted disclosures define who the buyer can share information with: financial advisors, legal counsel, lenders, and internal deal teams. 

For private equity buyers, sellers should limit affiliate disclosure to those actively participating in the evaluation. PE sponsors sharing CIM data with competing portfolio companies is a real exposure.

4. Term and Duration

The standard term is two years from signing, or from termination of discussions, whichever is later. The range across deals runs from one to five years; trade secrets are typically carved out with indefinite protection. 

Sellers prefer a term of three to five years with no fixed end date for trade secrets. Buyers prefer one to two years with a clear expiration.

5. Non-Solicitation

Prevents the buyer from approaching the seller’s employees, customers, or suppliers for 12 to 24 months. Sellers should resist narrow drafting that covers only employees; customers and key suppliers disclosed during due diligence are equally exposed. 

Also, general solicitations, such as job postings, are typically carved out.

6. Standstill Provision

This clause is standard for public-company targets but rare in private deals. A standstill prevents the buyer from acquiring shares, making unsolicited bids, or taking other market actions, typically for 12 to 24 months. 

It is often a legal necessity for public targets managing MNPI obligations. “Don’t ask, don’t waive” provisions may be included, but have faced enforceability limits in Delaware courts.

7. Residuals Clause

One of the most dangerous provisions for sellers and one of the least understood. A residual clause permits a buyer’s representatives to retain and use, in their unaided memory, information disclosed during the deal, even after the NDA term ends. 

As Venable LLP and Dentons have noted, this can effectively nullify trade secret protection for information absorbed during data room review and management presentations. Sellers should resist any residual clause. However, if a buyer insists, limit it explicitly to exclude trade secrets.

8. Return or Destruction; Injunctive Relief; Governing Law

The return or destruction of information upon deal termination establishes the obligation, even if literal enforcement is difficult in the digital era. 

The irreparable harm and injunctive relief clause, which states that a breach cannot be compensated solely by monetary damages, makes emergency court relief significantly easier to obtain. 

Delaware and New York are common governing law choices for U.S. M&A NDAs. Yet, the enforceability of specific clauses varies by state, so consult local counsel.

9. AI and LLM Training Prohibition (2025–2026)

An emerging clause now appearing in NDAs negotiated by sophisticated counsel explicitly prohibits the use of disclosed confidential information to train or fine-tune artificial intelligence or large language model (LLM) systems. 

As AI tools become standard in due diligence workflows, the risk that confidential data enters a training pipeline is no longer hypothetical. Sellers should request this prohibition as a default, and buyers using third-party AI document review tools should disclose this during negotiation.

Buyer vs. Seller: Negotiating Priorities

In most M&A NDAs, the negotiation comes down to a simple trade-off: sellers want broad control over disclosure, while buyers want enough flexibility to evaluate the deal efficiently. 

Seller prioritiesBuyer priorities
Broad definition of Confidential Information, including oral disclosuresNarrow definition with marking requirement
Long term, 3–5 years; indefinite for trade secretsShort term, 1–2 years, fixed expiration
No residuals clause, or trade secret exclusionBroad residuals clause covering unaided memory
Non-solicit covering employees, customers, and suppliersNarrow non-solicit; carve-out for general solicitations
Standstill, if public target; 12–24 monthsNo standstill, or short, limited standstill
PE affiliate disclosure restricted to the active deal teamBroad permitted disclosures to affiliates and LPs
AI training prohibition; return/destruction obligationNo AI restriction; lighter destruction obligation

Most NDA negotiations are resolved within a few business days. The terms that generate the most friction – residuals, standstill, non-solicit scope, and affiliate disclosure – are worth mapping out before the first redline arrives.

The FTC Non-Compete Rule and M&A NDAs

The FTC issued its final Non-Compete Rule in April 2024, but the rule is not currently in effect or enforceable. A federal court set it aside in August 2024, and on September 5, 2025, the FTC filed to seek vacatur of the rule and to dismiss its appeal. 

As a result, M&A teams should not treat the rule as an active federal ban, but they should still review non-compete language carefully under applicable state law.

For M&A transactions, confidentiality obligations, non-solicitation clauses, and sale-related restrictive covenants serve different purposes. 

  • An NDA protects confidential information during the deal review. 
  • A non-solicit restricts approaches to employees, customers, or suppliers. 
  • A sale-related non-compete, where enforceable, may protect the new owner after closing by limiting the seller’s ability to use deal knowledge, customer relationships, or operational insight against the business.

This matters because restrictive covenants can become sensitive key terms in many deals, especially where the seller’s know-how, customer relationships, or competitive advantages are central to value. 

That’s why, before including non-compete language in an NDA or related deal document, counsel should review enforceability, scope, duration, geography, and whether the restriction is tied to a legitimate business sale.

Common M&A NDA Mistakes to Avoid

Most M&A NDA mistakes stem from weak templates, premature disclosure, and missing controls throughout the process. 

  • Using a generic NDA template. A standard commercial NDA lacks standstill, M&A-specific non-solicit, and phased-access provisions.
  • Releasing the CIM before signing. There is no functional reason to share the CIM without a signed NDA. This is the most avoidable confidentiality failure before a thorough investigation begins.
  • Accepting an unrestricted residuals clause. It can effectively nullify trade secret protection for information absorbed by the buyer’s deal team.
  • Omitting a standstill for public targets. Exposes the company to a buyer using MNPI to acquire shares or mount a hostile approach.
  • Non-solicit covering only employees. Customers and suppliers across the value chain need equal protection when disclosed as part of due diligence.
  • Unlimited affiliate disclosure for PE buyers. PE sponsors with competing portfolio companies or assets in different markets create real exposure if affiliates are broadly permitted.
  • No AI/LLM training prohibition. As AI-assisted due diligence becomes standard, omitting this clause creates material risk.

The M&A NDA and the Virtual Data Room

The NDA establishes the legal obligation, and the virtual data room operationalizes it. Most legal analysis of M&A NDAs stops at the contract, missing the layer where the agreement is actually enforced. 

Read more: For a full overview of virtual data room security in M&A, see our recent guide.

Clickwrap NDAs and Data Room Access

Many auction processes use clickwrap NDAs – electronic agreements presented at data room login that require an affirmative click to accept. 

Under ESIGN and UETA, clickwrap agreements are generally more enforceable when users receive clear notice of the terms and take an affirmative action to accept them. VDRs log the user’s name, acceptance timestamp, and IP address, creating evidence that may support enforcement of the contractual agreement. 

As a result, clickwrap suits broad bidder pools. Separately negotiated NDAs remain preferable for bilateral transactions, cross-border mergers, or deals involving highly sensitive commercial data.

Phased Access Tied to NDA Scope

A well-designed VDR mirrors the NDA’s permitted use through phased access:

  1. Phase 1 (post-NDA, pre-LOI). High-level financials, redacted contracts, anonymized customer data, and selected growth strategy materials. Identifying information is withheld. 
  2. Phase 2 (post-LOI, confirmatory DD). Unredacted financials, customer-level data, source code, and key employee agreements. Access is limited to the preferred buyer and approved representatives.

Read more: The NDA alone does not prevent unauthorized disclosure, but VDR permissions provide operational control. See the full data room checklist for structuring access by deal phase.

For transactions involving competitors, sensitive folders may also require clean-team access. This helps reduce exposure when shared documents could raise antitrust concerns or reveal plans for forward or backward integration, or entry into adjacent markets.  

Audit Trails, Watermarking, and Reasonable Measures

Every VDR action is logged: who accessed which document, when, from where, for how long, and whether it was downloaded. 

This audit trail is critical evidence in an NDA breach claim, especially when confidential data could affect a discounted cash flow analysis, cost-saving assumptions, or post-deal value creation.

Modern VDRs also operationalize the NDA’s reasonable measures standard through: 

  • Dynamic watermarking (documents stamped with the viewer’s name and timestamp)
  • View-only and no-download restrictions
  • Screen capture deterrence
  • In-platform redaction. 

For deals involving a competitor buyer, restricting sensitive folders to outside counsel only, not the buyer’s commercial team, adds a layer of protection. This is especially important when the buyer is evaluating market power, new markets, or other sensitive competitive information. 

Read more: Seek additional guidance on how due diligence works in these structures. Check our recent guide.

M&A NDA Templates and Resources

Rather than competing on template SEO, we point to the authoritative free resources that deal teams actually use:

  1. oneNDA M&A. A Creative Commons (CC BY-ND) short-form template available at onenda.org is designed to be signed in minutes, ideal for broad bidder pools.
  2. Stanford Law School Mutual NDA. A longer bilateral template developed for nonprofit M&A is a useful baseline for for-profit bilateral structures.
  3. Law firm analyses. Faegre Drinker, Latham & Watkins, and Kutak Rock have each published substantive clause-level analyses with model language – useful benchmarks for evaluating specific provisions.

Templates are starting points, not substitutes for counsel review. A template designed for a bilateral merger may not be suitable for a PE-sponsored public company auction. For organizing the full transaction file, see the M&A document management checklist.

FAQ

An M&A NDA is a confidentiality agreement used in mergers and acquisitions to protect sensitive information shared between the seller and a prospective buyer. It usually restricts the acquiring company from using financial, commercial, operational, or strategic information for any purpose other than evaluating the transaction.
An NDA is not always required by law, but it is standard in any professionally managed M&A process. Before the due diligence phase begins, the seller needs a signed agreement to protect customer data, financial records, employee information, intellectual property, and other confidential materials.
An NDA is typically signed after the initial teaser and before the Confidential Information Memorandum, or CIM, is shared. This timing matters because the buyer may use early diligence findings to assess risk, valuation, and the potential purchase price before submitting a bid.
Most M&A NDAs last one to five years, with two years being common in many private transactions. Trade secrets often receive longer or indefinite protection because their value may continue well after the deal closes.
A standstill provision prevents a buyer from acquiring shares, launching a tender offer, or making an unsolicited approach after receiving confidential information. It is especially important when the seller is publicly listed, because confidential deal discussions may affect the company’s stock price and require careful control by the target company's board
If an M&A NDA is breached, the seller may seek injunctive relief, monetary damages, or both, depending on the agreement and governing law. In practice, breach claims often depend on strong evidence, so audit trails, access logs, and download records help resolve key legal matters.
Yes. In a well-run M&A process, data room access should only be granted after the parties sign an NDA or accept a clickwrap confidentiality agreement. This protects the seller while allowing approved users to review documents in a controlled environment.

The DataRooms.org content team

The DataRooms.org content team is a group of experienced professionals dedicated to delivering insightful, well-researched, and up-to-date information on virtual data rooms.

Our team conducts in-depth market research, develops strategic content plans, and delivers data-driven insights to help businesses make informed decisions.

We are committed to helping businesses make informed decisions when selecting virtual data room solutions.

To make sure you have the best possible experience on our site, we use cookies. By continuing to use this website, you consent to the use of cookies.
Learn more
To top