The confidentiality clause in a SaaS agreement under the United States law

US SaaS confidentiality clause: mutual protection, UTSA trade secret law, carve-outs, legal disclosure, duration, and negotiation strategy.

Standard Position

In US SaaS agreements, confidentiality clauses protect both the vendor and customer from unauthorized disclosure of sensitive information. The standard market position is mutual protection: the vendor protects customer data and business information, while the customer protects the vendor's trade secrets, source code, and proprietary methodologies. Most SaaS vendors carve out exceptions for information that is publicly available, independently developed, or required to be disclosed by law. A typical confidentiality obligation lasts for the term of the agreement plus 2 to 5 years post-termination, though this varies by industry and data sensitivity.

Legal Basis

US law provides multiple foundations for confidentiality protection. Under common law, parties can create binding confidentiality obligations through contract, enforceable via breach of contract claims. The Uniform Trade Secrets Act (UTSA), adopted in all 50 states with minor variations, protects "trade secrets" (information that derives economic value from not being generally known and is subject to reasonable efforts to maintain secrecy). Federal law adds layers: the Computer Fraud and Abuse Act (CFAA) criminalizes unauthorized computer access, while the Economic Espionage Act (18 U.S.C. §1836) imposes criminal penalties for trade secret theft. For customer data, state privacy laws (California Consumer Privacy Act, Virginia Consumer Data Protection Act, etc.) and the Health Insurance Portability and Accountability Act (HIPAA, if applicable) impose statutory confidentiality duties independent of contract.

Drafting and Negotiation

Key negotiation points include: (1) Definition scope. Overly broad definitions (e.g., "any information disclosed") create unreasonable obligations; courts will enforce reasonable limitations under UTSA principles. Use tiered definitions distinguishing customer data, trade secrets, and business information, each with tailored protection levels. (2) Standard of care. Vendors typically accept a "reasonable care" or "industry-standard" standard, not absolute liability. Customers frequently push for "same care as own information" language; this is negotiable but commits vendors to internal security parity. (3) Permitted disclosures. Always include exceptions for legally required disclosures (court orders, regulatory requests, subpoenas), but include notice and cooperation language allowing the receiving party to seek protective orders. (4) Regulatory compliance. If personal data is involved, explicitly state that compliance with privacy laws (CCPA, GDPR for international flows, HIPAA, etc.) takes precedence and permits necessary disclosures. (5) Return or destruction. Specify post-termination obligations: must information be returned, destroyed, or may reasonable archival copies be retained for compliance? (6) Duration asymmetry. Trade secrets merit indefinite protection under UTSA principles; non-confidential business information typically receives 3 to 5 years. Customers often propose indefinite customer data protection, which is increasingly standard.

Common Pitfalls

First, failing to align confidentiality scope with actual data flows. If a vendor uses subprocessors, the confidentiality clause must address downstream obligations; the customer's information cannot receive greater protection from the vendor than from its service providers. Second, creating impossibly broad carve-outs (e.g., all aggregate data or any information used to improve services without explicit consent). This can render the clause unenforceable or trigger regulatory violations. Third, omitting operational detail: vendors should specify the persons with access, audit rights, and data localization commitments to avoid disputes about "reasonable care." Fourth, conflating confidentiality with liability caps. Confidentiality breaches often trigger statutory damages under privacy laws; excluding those via general liability caps may be unenforceable. Finally, failing to address incident response: if a breach occurs, what are notification timelines, remediation obligations, and the customer's right to audit or investigate?

Sample language

Each party shall protect the other's Confidential Information using reasonable care and industry-standard security practices, and shall not disclose it to third parties except as permitted by this Agreement or required by law. Confidential Information excludes information that is publicly available, independently developed without reference to the disclosing party's information, or rightfully received from a third party without confidentiality restrictions. Either party may disclose Confidential Information when legally compelled, provided it gives prompt notice and reasonable cooperation to seek protective orders. Confidentiality obligations survive termination for five years for business information and indefinitely for trade secrets.

This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.

Frequently asked questions

What is a trade secret under US law and does confidentiality clause duration differ from other confidential information?
Under the Uniform Trade Secrets Act, a trade secret is information that derives independent economic value from not being generally known and is subject to reasonable efforts to maintain secrecy. Trade secrets receive indefinite protection under UTSA principles, while general business information typically receives 3 to 5 years post-termination. Most SaaS agreements use this tiered approach.
Can a vendor disclose customer data if legally required, and what must the clause say?
Yes. All US SaaS confidentiality clauses should permit disclosure when legally required (court orders, regulatory requests, subpoenas). Best practice is to require the vendor to notify the customer promptly and cooperate with efforts to seek protective orders, ensuring the customer can challenge disclosure before it occurs.
What standard of care should the vendor accept for protecting confidential information?
The market standard is "reasonable care" or "industry-standard" security practices, not absolute liability. Some customers negotiate "same care as the vendor uses for its own information," which is reasonable but should exclude data the vendor does not store or process. Avoid undefined standards that invite post-breach disputes.
Does confidentiality survive termination of the SaaS agreement?
Yes, but duration varies by information type. Trade secrets and customer data typically survive indefinitely (or for the data retention period); other confidential business information usually survives 2 to 5 years. The clause must specify post-termination return or destruction obligations and any allowed archival for compliance purposes.

Related in the library

Adira drafts and reviews contracts under the law of the jurisdiction they work in.

See Adira