The indemnity clause in a non-disclosure agreement (NDA) under the United Kingdom law

Indemnity clauses in UK NDAs: scope, legal basis, negotiation strategy, and how English law limits indemnity liability for breach of confidentiality.

Standard position

Indemnity clauses in English NDAs are relatively uncommon compared to other contract types, but when included, they typically require one party to compensate the other for losses arising from breach of confidentiality obligations or misuse of disclosed information. In the UK market, indemnity is often restricted to breaches by the receiving party's employees, agents, or contractors, rather than covering all third-party breaches. Many NDAs omit standalone indemnity provisions altogether, relying instead on general damages remedies and specific performance. When present, indemnity typically covers legal costs, regulatory fines, and direct financial losses directly caused by unauthorized disclosure or use.

Legal basis

English law does not require indemnity clauses in NDAs; they are contractual constructs. The legal framework rests on breach of contract principles under common law, supplemented by the equitable doctrine of confidence (established in Coco v A N Clark (Engineers) Ltd and later cases). Indemnity is an express allocation of risk: it requires the indemnifying party to put the indemnified party in the position it would have been in had the breach not occurred. English law distinguishes between indemnity (a complete reimbursement) and a guarantee (a secondary liability). Courts construe indemnity clauses strictly: ambiguity is resolved against the party seeking to rely on the indemnity. Indemnity does not typically cover losses arising from the indemnified party's own negligence unless expressly stated, reflecting the contra proferentem rule and public policy limitations on excluding liability for negligence.

Drafting and negotiation

Key negotiation points include the scope of triggering events (breach only, or also third-party breaches beyond the receiving party's control?), the definition of "losses" (direct damages only, or consequential loss, reputational harm, and regulatory penalties?), and causation thresholds (direct causation required, or any connection to the breach). Receiving parties should resist open-ended indemnity covering unknown future claims; instead, negotiate caps tied to contract value or a fixed sum, a time limit (e.g. 12 months from discovery), and a materiality threshold (e.g. claims above GBP 10,000 only). Disclosing parties should clarify whether indemnity applies only to their own disclosures or extends to information the receiving party already possessed. Consider whether indemnity applies only to breaches caused by the receiving party's gross negligence or willful default, excluding ordinary negligence. Insurance-backed indemnity (with proof of coverage) is rarely negotiated in NDAs but may be relevant for high-value transactions. Mitigation clauses should obligate the indemnified party to take reasonable steps to minimize losses.

Common pitfalls

Drafters often fail to define the baseline "non-breached" state: what losses would have occurred anyway? Vagueness about whether the indemnifying party covers only direct employee breaches or also subcontractors creates disputes. Broad consequential loss language (including lost profits, business opportunity, and reputational damage) exposes the indemnifying party to uncertain, uninsurable liability; these should be excluded unless transaction value justifies it. Failure to include a cap, basket, or time limit can lead to claims years after disclosure ends. Another pitfall is silent treatment of force majeure: does indemnity apply if disclosure results from a cyber breach or court order? Using indemnity as a substitute for clear breach remedies (e.g., injunction) is inefficient; indemnity should complement, not replace, equitable relief. Finally, forgetting to require notice and opportunity to defend (standard practice in English contract law) may waive the right to control settlement and allocate defence costs.

Sample language

The Receiving Party shall indemnify and hold harmless the Disclosing Party from and against all reasonable costs and losses (including legal fees and regulatory fines) directly arising from the Receiving Party's material breach of its confidentiality obligations, provided that the Receiving Party was either directly responsible for the breach or failed to exercise reasonable care in preventing breach by its employees or agents. This indemnity shall not apply to breaches beyond the Receiving Party's reasonable control, to the extent the Disclosing Party fails to mitigate loss, or to any losses occurring more than 12 months after the Disclosing Party discovers the breach.

This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.

Frequently asked questions

Is an indemnity clause mandatory in a UK NDA?
No. English law does not require indemnity in NDAs. Most standard NDAs rely on damages remedies and injunctive relief only. Indemnity is optional and used mainly in high-value or sensitive transactions where the disclosing party wants guaranteed compensation for breach.
Does indemnity in an NDA cover losses the receiving party did not cause?
Generally no, unless the clause explicitly states otherwise. English law interprets indemnity clauses strictly: the indemnifying party is typically liable only for breaches caused by its own acts, omissions, or failure to control its agents and employees. Force majeure, court orders, and third-party cyber theft are usually excluded unless specifically included.
What losses can be claimed under an NDA indemnity clause?
English law permits claims for direct losses directly caused by breach, including legal costs, regulatory fines, and quantifiable financial harm. Consequential loss, lost profits, and reputational damage are excluded by default and must be expressly stated in the clause. Caps and baskets are strongly advised to limit exposure.
What is the difference between indemnity and liability exclusion in an NDA?
Indemnity is a positive obligation to compensate the other party for specific losses arising from breach. Liability exclusion (or limitation) restricts the amount or type of damages available. English law treats these separately: liability caps do not necessarily bar indemnity claims unless the clause is drafted to merge them. Indemnity also carries stricter causation and control requirements.

Related in the library

Adira drafts and reviews contracts under the law of the jurisdiction they work in.

See Adira