NDA Before a Deal: Protecting Trade Secrets in Business Negotiations

Vassilev & Chisuse Law Firm ยท 2025-12-26

Sensitive information is often disclosed long before a final transaction agreement is signed. Pricing models, customer portfolios, financial parameters, software code, technological know-how and project documentation may be shared by email, through a virtual data room or during meetings at the due diligence or preliminary negotiation stage. For this reason, the lack of a properly drafted NDA often occurs to be the most expensive year-end mistake.

Bulgarian law provides several parallel mechanisms for protecting such information. The principal frameworks include the Bulgarian Trade Secret Protection Act, contractual protection under the Obligations and Contracts Act, the duty to negotiate in good faith and the unfair competition rules under the Protection of Competition Act. The Trade Secret Protection Act expressly allows civil trade secret protection to coexist with enforcement under competition law. 

A Non-Disclosure Agreement (NDA) is not a statutory prerequisite for every item of information to qualify as a trade secret. It is nevertheless an important contractual and evidential measure because it defines the protected information, its Permitted Purpose, the persons who may access it and the consequences of a breach. 

Why Should an NDA Be Signed Before Material Disclosure? 

Risk arises as soon as sensitive information leaves the controlled environment of its holder. In corporate transactions, investment negotiations, technology projects and distribution arrangements, documents may reach employees, group companies, financial advisers, auditors, lawyers and technical experts before the parties agree the final transaction terms. 

Executing an NDA before the first material disclosure allows the parties to define the permissible use of the information in advance. Where information has already been disclosed without a contractual framework, statutory protection is not automatically lost, but proving the restrictions applicable to the recipient may become more difficult. 

An NDA signed after negotiations have begun may expressly define previously disclosed material as Confidential Information and regulate its future use and disclosure. Such wording should not automatically be treated as creating a contractual breach retrospectively for conduct that occurred before the contractual obligation came into existence. 

When Does Information Qualify as a Trade Secret? 

Not all non-public business information is automatically a trade secret. Article 3 of the Bulgarian Trade Secret Protection Act requires three cumulative elements. The information must not be generally known or readily accessible to persons who normally deal with that type of information, it must have commercial value because it is secret, and measures must have been taken by the person controlling it to keep it secret. 

Directive (EU) 2016/943, which underlies the Bulgarian framework, expresses the final requirement as reasonable steps under the circumstances to keep the information secret. 

An NDA may form an important part of those measures, but a signed agreement alone does not guarantee trade secret status. Clear classification of protected information, restricted access, confidentiality markings, technical controls, restrictions on copying and downloading and access logs may also be relevant. 

A generic statement that all business information is confidential is therefore not sufficient in itself. The particular information relied upon in a dispute must actually satisfy the statutory trade secret criteria and have been subject to genuine protective measures. 

What Remedies Apply to Unlawful Use or Disclosure? 

Under the Trade Secret Protection Act, use or disclosure without the holder's consent is unlawful where the recipient acquired the trade secret unlawfully, breached a confidentiality agreement or another duty not to disclose it, or breached an obligation restricting its use. 

A trade secret holder may seek a judicial finding of infringement, cessation or prohibition of use or disclosure, destruction or delivery of documents and other media containing the secret, and compensation for loss and lost profits. Interim protective measures may also be requested before or during proceedings. 

Claims under the Trade Secret Protection Act are subject to a five-year limitation period running from the infringement. The Act also provides specific confidentiality measures within court proceedings so that enforcement itself does not unnecessarily expose the protected information. 

In parallel, Article 37 of the Bulgarian Protection of Competition Act prohibits the acquisition, use or disclosure of production or trade secrets contrary to honest commercial practices. Article 29 establishes the general prohibition on unfair competition, while Article 36 addresses unfair solicitation of customers. 

Article 12 of the Bulgarian Obligations and Contracts Act also requires parties to act in good faith during negotiations and contract formation. Depending on the circumstances, misuse of information provided exclusively for negotiations may therefore also be relevant to pre-contractual liability. 

Why Is a Contractual Penalty Important in an NDA? 

A contractual penalty enables the parties to determine in advance the financial consequence of a particular contractual breach. Under Article 92 of the Bulgarian Obligations and Contracts Act, the penalty serves as compensation for non-performance without requiring the creditor to prove the loss or its precise amount. If the actual loss exceeds the agreed penalty, compensation for the excess may also be sought. 

This is particularly relevant to confidentiality breaches because the financial effect of disclosing pricing policies, customer information, algorithms or technical solutions can be difficult to quantify. The Bulgarian Supreme Court of Cassation has confirmed that lost profits cannot be presumed and must be based on a proven prospect of a certain increase in assets rather than a hypothetical expectation. 

A penalty clause should clearly identify the breaches to which it applies and must be validly agreed. Where an NDA forms part of a commercial transaction between merchants, Article 309 of the Bulgarian Commerce Act should also be considered. It provides that a contractual penalty due under a commercial transaction between merchants cannot be reduced solely because it is excessive. This does not remove the general requirements governing the validity of contractual clauses. 

What Should an Effective NDA Contain? 

An effective NDA should define Confidential Information with sufficient precision. It may cover financial models, pricing terms, margins, customer information, agreements, business plans, know-how, technical documentation, source code and information disclosed orally, in writing or electronically. In sensitive transactions, the existence of the negotiations themselves may also be confidential. 

The agreement should define the Permitted Purpose. In a due diligence process, for example, information may be provided solely for evaluating and negotiating the proposed transaction and may be prohibited from use for an independent competitive, manufacturing or commercial purpose. 

The authorised recipient group should also be clearly defined. A Need-to-Know structure can limit access to employees, directors and professional advisers who genuinely require the information and are subject to appropriate confidentiality obligations. 

The NDA should address legally compelled disclosure. Where permitted by law, it may require advance notice to the disclosing party and limit disclosure to the information strictly required by a court, regulator or other competent authority. 

Return, deletion or destruction provisions are also important. For electronic archives, backup systems and legally required retention, the clause should recognise genuine technical and regulatory constraints rather than impose an immediate deletion obligation that cannot in practice be performed. 

What Confidentiality Exceptions Should Be Included? 

An NDA should normally exclude information that becomes publicly available without breach, that the recipient can demonstrate it lawfully possessed before disclosure, that is lawfully received from an independent source without a confidentiality obligation, or that is independently developed without use of the protected information. 

These exceptions should be drafted carefully. The fact that an individual component is publicly available does not necessarily mean that a particular combination, structure or compilation cannot qualify as a trade secret. 

The Trade Secret Protection Act also recognises statutory cases in which acquisition, use or disclosure is lawful, including the exercise of freedom of expression, disclosure of wrongdoing in the public interest and other interests recognised under EU or Bulgarian law. An NDA cannot validly eliminate mandatory statutory exceptions. 

Can an NDA Prohibit Reverse Engineering? 

Under the Trade Secret Protection Act, observation, study, disassembly or testing of a product or object that is publicly available or lawfully possessed may constitute lawful acquisition of information where the recipient is not subject to a legally valid duty restricting such acquisition. 

This makes NDA drafting particularly important when prototypes, test devices, software demonstrations or technical specifications are shared. The parties may contractually restrict reverse engineering, decompilation, disassembly or technical analysis to the extent permitted by applicable law. Directive (EU) 2016/943 expressly recognises that reverse engineering may be restricted through a legally valid contractual obligation. 

Does an NDA Replace GDPR Compliance? 

An NDA does not replace compliance with the General Data Protection Regulation (GDPR). Where customer, employee or other personal data are disclosed during due diligence or negotiations, the parties must separately determine their data protection roles, legal basis, data minimisation requirements and appropriate safeguards. 

An Article 28 GDPR data processing agreement is required where the recipient processes personal data on behalf of a controller and therefore acts as a processor. Article 28 does not automatically apply to every disclosure of personal data between two companies. Where each party independently determines the purposes and means of processing, the relationship must be assessed according to the parties' actual GDPR roles. 

How Long Should Confidentiality Obligations Last? 

There is no universal statutory duration suitable for every NDA. The appropriate period depends on the nature and commercial life of the protected information. 

Information with a limited economic life, such as certain pricing terms or parameters of a particular transaction, may be protected for a defined period after negotiations end. For technological know-how, algorithms, production formulas or other genuine trade secrets, the agreement may link the confidentiality obligation to the period during which the information continues to satisfy the statutory criteria for trade secret protection. 

A broad perpetual obligation applying indiscriminately to every category of information is not automatically stronger protection. A more precise approach aligns the duration with the nature of the information and the legitimate interest being protected. 

What Matters in a Cross-Border NDA? 

A cross-border NDA should address both governing law and dispute resolution. Under Regulation (EC) No. 593/2008, Rome I, parties can generally expressly choose the law governing their contract. 

Where the parties select a court of an EU Member State, international jurisdiction should be considered under Regulation (EU) No. 1215/2012, Brussels I bis, including Article 25 on jurisdiction agreements. Arbitration is expressly excluded from the scope of Brussels I bis. Where arbitration is preferred, the arbitration clause must therefore be structured under the applicable arbitration framework rather than treated as a Brussels I bis jurisdiction clause. 

In international transactions, governing law, jurisdiction or arbitration, contractual penalties and available remedies should be designed as a coherent system rather than copied mechanically from an NDA prepared for another jurisdiction. 

How Can Businesses Reduce Risk Before Disclosure? 

Effective protection begins before the first material disclosure. An NDA should form part of a broader confidential information management framework rather than operate as the sole protective measure. 

Documents may be classified and marked as confidential, access may be granted on a Need-to-Know basis, and sensitive materials may be shared through controlled Virtual Data Rooms with individual access rights and system logs. In transaction processes, disclosure can also be staged according to the progress of due diligence and the recipient's genuine need for the information. 

This approach strengthens contractual protection and helps demonstrate that the company actually treated the information as confidential and took measures to preserve its secrecy. 

Legal Assistance with NDAs and Trade Secret Protection 

Vassilev & Chisuse Law Firm provides legal assistance in corporate and investment negotiations, acquisition transactions, protection of trade secrets and know-how, and the drafting and negotiation of confidentiality agreements. Assistance may include pre-contractual risk analysis, structuring Permitted Purpose and contractual penalty provisions, and representation in disputes concerning unlawful use or disclosure of confidential business information. 

This material is provided for general informational purposes only. It does not constitute individual legal, tax or financial advice. The scope of protection in any particular case depends on the nature of the information, the measures taken to protect it, the contractual relationship between the parties and the manner in which the information was acquired, used or disclosed. 

Related legal services

Related articles