NDA Processing Workflow Checklist Template

NDAs represent 30% of legal teams’ daily work, take an average of 5 days to execute, and are consistently under-managed after signature — with expiry dates missed, survival periods ignored, and a third-party NDA that no one can find when a dispute arises two years later.

Non-disclosure agreements are the contracts that legal teams process most frequently — and the ones most commonly treated as low-stakes administrative tasks rather than enforceable legal obligations. The routine NDA that was executed on an outdated template. The third-party NDA with a definition of “confidential information” that excludes most of the information actually being shared. The mutual NDA where one party wanted unilateral and no one noticed the mismatch. The NDA filed somewhere that no one can find when a breach is suspected eighteen months later. Research from Ironclad shows that 90% of NDAs are initiated on company paper, but legal involvement is still needed 30% of the time. A structured NDA processing workflow routes every NDA through the right template selection, the right clause checks, the right approval level, consistent e-signature execution, and a centralised archive with expiry and survival period tracking. This free checklist gives legal teams, business users, and legal operations professionals a structured framework for the full NDA processing workflow.

This checklist describes a process framework. It does not constitute legal advice. NDA requirements vary by jurisdiction and context. Consult qualified legal counsel for advice specific to your circumstances.
Use This Template Free See Live Example
No Credit Card Required

Mutual, Unilateral, and Employee NDAs — How the NDA Type Determines the Entire Process

Mutual / Bilateral NDA

When: Both parties intend to share and receive confidential information — two parties in a potential commercial relationship, joint venture discussions, or M&A due diligence where both sides share materials.

Key structural point: Obligations are symmetric — both parties owe the same confidentiality duties to the other. Appropriate where the information flow is genuinely bilateral.

Risk of wrong type: Using a mutual NDA when only one party is actually disclosing gives the counterparty unnecessary protections for information it is not providing.

Unilateral / One-Way NDA

When: Only one party is disclosing confidential information to the other — typically in a commercial evaluation where the discloser is sharing proprietary information and the recipient is evaluating it.

Key structural point: Only the receiving party owes confidentiality obligations. The disclosing party has no obligations.

Risk of wrong type: Using a unilateral NDA when both parties are sharing information leaves one party’s disclosures unprotected.

Employee NDA / Confidentiality Agreement

When: An employee is being given access to confidential business information, trade secrets, or sensitive data as part of their employment.

Key structural point: Typically part of the employment agreement or a standalone document; governed by employment law as well as contract law; enforceability of post-employment confidentiality obligations varies significantly by jurisdiction.

Risk of wrong type: Using a commercial NDA template for an employee without reviewing for employment law compliance in the relevant jurisdiction.

The NDA Processing Workflow Checklist

Six phases covering the full NDA lifecycle — from request intake and routing through template selection, legal review, execution, filing, and breach management.

Phase 1

NDA Request Intake & Routing

NDA intake is where most NDA processing inefficiency is created. An NDA request received via an informal channel without structured information produces a back-and-forth of clarification questions that extends the 5-day average to 10 or more.

  • Receive the NDA request through the defined intake channel — legal intake form, legal portal, or defined email address; not informally by direct message to an individual attorney
  • Collect required intake information — counterparty legal name, NDA type (mutual or unilateral), purpose of the information exchange, requesting business unit and internal sponsor, expected signing timeline, and whether the counterparty has sent their own NDA template
  • Confirm whether company paper or counterparty paper — company paper: issue the standard template; counterparty paper: route for legal review
  • Conduct a rapid conflict check — is the counterparty adverse to the company on any current matter?
  • Route to the correct track — standard template (company paper, low complexity): business user can execute with standard guidance; legal review track (third-party paper, unusual purpose, or non-standard scope)
Phase 2

Template Selection & Customisation

  • Select the correct template — mutual or unilateral; confirm the template is the current approved version; do not use an old version from a previous deal
  • Confirm the effective date — the date from which the NDA obligations run; typically the date of signing
  • Confirm the duration of the NDA — the term during which the parties are permitted to share confidential information; typically 2–5 years
  • Confirm the survival period — how long confidentiality obligations continue AFTER the NDA expires; this is often perpetual for trade secrets or a defined number of years; must be explicitly stated
  • Customise the purpose — the specific purpose for which confidential information may be used; broader purpose = more risk; narrower purpose = better control
  • Confirm governing law and jurisdiction — appropriate for the parties’ locations; the standard template may need adjustment for international counterparties
Phase 3

Legal Review of Counterparty NDA

This phase applies when reviewing a third-party NDA submitted on counterparty paper.

  • Verify the parties — correct legal names of both parties; check the signing entity is the correct legal entity
  • Review the definition of confidential information — is it broad enough to cover all information that will actually be shared? Too narrow a definition leaves important information unprotected
  • Review permitted purpose — is the stated purpose consistent with the actual intended use? Too broad a purpose permits the counterparty to use information beyond the intended context
  • Review the exceptions to confidentiality — typically: information already known to the recipient; publicly available information; information received from a third party without restriction; required disclosure by law; confirm these are appropriately scoped
  • Review the obligations on the receiving party — how confidential information must be handled; disclosure to employees and advisers on a need-to-know basis; security measures required
  • Review the duration and survival period — confirm these are appropriate for the nature of the information being shared
  • Review return/destruction of information — what happens to confidential information when the NDA expires; return or certified destruction; carve-outs for required regulatory retention
  • Flag any non-standard or unusual provisions — injunctive relief clauses, exclusivity provisions, or other unusual terms for business owner awareness
Phase 4

Approval & Execution

  • Obtain legal approval — for company paper: legal sign-off that the template is issued correctly; for counterparty paper: legal sign-off on the reviewed draft
  • Obtain business owner approval — the internal sponsor confirms the purpose, counterparty, and key terms are correct
  • Issue for signature — via e-signature (preferred for speed and audit trail); to the correct authorised signatory at both parties
  • Confirm signature authority — the person signing on behalf of both parties has authority to bind their respective organisation to the NDA
  • Confirm both parties have executed — fully executed (signed by both parties) before treating the NDA as binding
Phase 5

Filing, Tracking & Expiry Management

  • File the executed NDA — in the central contract repository; searchable by counterparty name, date, and expiry date
  • Update the NDA register — counterparty, NDA type, effective date, expiry date, survival period end date, purpose, and internal owner
  • Set expiry reminders — at least 30 days before expiry: is the relationship still active? Should the NDA be renewed or formally allowed to lapse?
  • Set survival period reminders — when the survival period ends is distinct from when the NDA expires; both must be tracked
  • Brief the internal sponsor — on key terms, obligations under the NDA, and the information that is and is not covered
Phase 6

Breach Identification & Response

  • Define the breach indicators — what behaviours might indicate a breach; confirm the internal process for reporting a suspected breach
  • Confirm the NDA is still in force — the breach must have occurred during the confidentiality period, which may include the survival period
  • Collect evidence — how was the breach identified? What information was disclosed? To whom?
  • Engage legal counsel — to assess the breach, available remedies (injunction, damages, liquidated damages if specified), and appropriate next steps
  • Issue a cease and desist letter — if appropriate; drafted by qualified counsel
  • Document everything — all evidence of the breach, all communications, and all steps taken; required for any legal action

This checklist is available as a free, runnable template in CheckFlow — routing company-paper NDAs to business users and third-party NDAs to legal review, with expiry and survival period tracking set at the filing stage for every executed NDA.

Use This Template Free

The Survival Period — the Most Important NDA Clause Most NDAs Get Wrong

An NDA has two distinct time periods that are frequently confused. The term is the period during which the parties are permitted to share confidential information under the agreement — typically two to five years. The survival period is the period after the NDA expires during which confidentiality obligations continue. If the NDA expires after two years but has no survival provision, the receiving party is free to use or disclose the information the day after expiry.

For genuinely sensitive information — trade secrets, proprietary technology, strategic plans — the survival period should be perpetual (confidentiality obligations never expire) or at minimum very long (five to ten years). A survival period that is shorter than the commercially relevant life of the information provides only partial protection. Every NDA should explicitly state both the term and the survival period — and the two should be separately reviewed to ensure they are appropriate for the nature of the information being shared.

Why Run Your NDA Workflow in CheckFlow?

1

Consistent routing for every NDA — company paper or third-party paper

The most consequential NDA processing decision is whether a third-party NDA is routed for legal review or processed as company paper by a business user. CheckFlow’s NDA intake checklist captures whether the NDA is on company or counterparty paper at intake and routes accordingly — ensuring third-party NDAs receive legal review and company-paper NDAs move through the efficient business-user track without waiting in the legal queue.

Auto-Routing
2

Expiry and survival period tracking built into the filing step

The most common post-execution NDA failure is that expiry dates are not tracked and NDAs lapse without review or renewal. CheckFlow’s NDA workflow assigns expiry reminders and survival period end-date tracking as required steps in the filing phase — so every executed NDA has its expiry and survival period tracked from day one, regardless of who handled the processing.

Recurring Checklists
3

A searchable, centralised NDA archive

When a suspected NDA breach occurs, the first question is: “Is the NDA still in force and does it cover this information?” Answering that question requires a searchable archive that can retrieve the right NDA by counterparty name, purpose, and date. Every NDA processed through CheckFlow is filed with consistent metadata — counterparty, type, effective date, expiry, survival period — making it immediately retrievable.

SOP Software

NDAs are a sub-category of contract management. CheckFlow’s Contract Review & Approval Checklist covers the full contract review process for commercial agreements beyond the NDA. See the Contract Review & Approval Checklist →

NDA expiry tracking is part of the broader contract renewal management function. CheckFlow’s Contract Renewal Reminder Checklist covers the structured renewal management process. See the Contract Renewal Reminder Checklist →

Frequently Asked Questions

What should an NDA processing workflow include?

+

An NDA processing workflow covers six phases: request intake (structured intake through a defined channel, identifying NDA type, confirming company or counterparty paper, and routing accordingly), template selection and customisation (correct template, effective date, duration, survival period, purpose, and governing law), legal review of counterparty NDAs (party verification, definition of confidential information, permitted purpose, exceptions, obligations, duration, and unusual provisions), approval and execution (legal and business approval, e-signature execution, signatory authority confirmation), filing and tracking (central repository, NDA register, expiry reminders, and survival period tracking), and breach management (evidence collection, legal counsel engagement, and remedies).

What is the difference between a mutual and a unilateral NDA?

+

A mutual (bilateral) NDA imposes confidentiality obligations on both parties — each party both discloses and receives confidential information, and both owe duties of confidentiality to the other. A unilateral (one-way) NDA imposes confidentiality obligations only on the receiving party — one party discloses information and the other party agrees to keep it confidential. Mutual NDAs are appropriate when both parties are genuinely sharing information with each other (M&A due diligence, joint venture exploration, commercial partnerships). Unilateral NDAs are appropriate when only one party is disclosing (a company showing its proprietary technology to a potential customer; a business sharing its strategy with an adviser). Using a mutual NDA when a unilateral NDA is appropriate gives the counterparty confidentiality protections for information it is not providing.

What is the survival period in an NDA and why is it important?

+

The survival period is the period after the NDA formally expires during which confidentiality obligations continue. Without a survival provision, a receiving party may be free to disclose the confidential information the day after the NDA expires — even if the information is commercially sensitive. For trade secrets and proprietary technology, the survival period should typically be perpetual or very long. For less sensitive commercial information, three to five years post-expiry is common. The survival period must be explicitly stated in the NDA — a court will generally not read in a survival period that is not specified.

Is an e-signature on an NDA legally binding?

+

In the US, e-signatures are legally binding for NDAs under the Electronic Signatures in Global and National Commerce Act (E-SIGN Act) and the Uniform Electronic Transactions Act (UETA), which have been adopted by all US states. In the UK and EU, e-signatures are recognised under the Electronic Communications Act 2000 and the eIDAS Regulation respectively. The key requirements are that the e-signature clearly identifies the signatory, that the signatory intended to sign, and that the signed document is preserved with evidence of the signature process. The most common e-signature platforms (DocuSign, Adobe Sign, HelloSign) produce audit trails that satisfy these requirements. For NDAs involving particularly sensitive information or parties in jurisdictions with specific requirements, verify applicable e-signature law with counsel.

Is CheckFlow free for this template?

+

You can start a free 14-day trial with no credit card required, giving you full access to all features including this template. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Process Every NDA Consistently, Compliantly, and With an Archive That Works When You Need It

Free trial — no credit card required.