Non-Disclosure Agreements In Hiring

Explore top LinkedIn content from expert professionals.

  • View profile for Gee Mann

    Inventor of the Travel Memory Layer | Founder, Travlr ID | Travel, AI & Data Infrastructure

    11,185 followers

    I am curious… Last week, our team spent time in a workshop with a potential partner. During the session, someone used ChatGPT to summarise our ideas in real time and make suggestions for improvement. It sparked great discussion, but it also raised an awkward question. For the AI to generate meaningful suggestions, it needed the context we had just shared, including technical details, strategic direction, and confidential roadmap items. Later, in a conversation with a legal advisor, we realised our NDAs did not explicitly cover this. They were written for a time when “sharing” meant emailing a document or handing over a printout, not pasting confidential information into a model you do not control. We ended up updating our docs to include an AI-specific clause: No Confidential Information may be uploaded to, processed by, or disclosed to any publicly available AI/ML system, model, or dataset without prior written consent. Apparently, this is starting to appear in some contracts as legal teams and AI law specialists are recommending clauses that: - Ban feeding confidential data into public models without written consent. - Require proof that approved tools will not train on the data. - Bind contractors and sub processors to the same rules. Some even provide model language allowing AI use only with “commercially reasonable assurances” the model will not train on the information and is isolated from other customers. Has anyone else encountered this or started updating their own NDAs and agreements? #AIGovernance #DataPrivacy #LegalTech #AICompliance #Contracts

  • View profile for Stuti G.

    Data Privacy, AI Governance @M&G | CIPP/E | EY

    3,402 followers

    Incorporating Data Privacy Clauses in NDAs 🔐 As someone deeply involved in data protection, I have seen firsthand how critical it is to protect sensitive information in our collaborations. In today’s landscape, integrating robust data privacy clauses into Non-Disclosure Agreements (NDAs) is no longer optional—it's essential. Why This Matters: 1. Regulatory Compliance: With regulations like GDPR and CCPA shaping our practices, we must ensure our NDAs reflect these legal requirements. I've witnessed the repercussions of non-compliance, and it's not something any organization can afford. 2. Data Classification: Clearly defining what sensitive data looks like is crucial. For example, specifying categories like PII or financial data helps everyone understand what’s at stake. 3. Access Controls: Establishing who can access sensitive information—and under what conditions—helps uphold the principle of least privilege. I’ve found that clarity here builds trust among all parties involved. 4. Breach Notification: It’s vital to have a breach notification protocol outlined in the NDA. Knowing how to respond swiftly can make all the difference in minimizing damage. 5. Data Transfer: In our globalized world, addressing cross-border data transfers in NDAs ensures we remain compliant with international standards. By embedding these technical aspects into our NDAs, we reinforce our commitment to data integrity and privacy. It’s not just about legal compliance; it’s about cultivating trust in every partnership. Let’s prioritize data privacy in our agreements and foster a culture of accountability in our industry. #DataPrivacy #NDA #LegalCompliance #DataSecurity #RiskManagement #cybersecurity #dataprotection

  • View profile for Andreas W.

    NED l Cyber & Risk expert l Advisor l Investor

    7,964 followers

    Companies are now adapting #NDAs to confront a defining risk of our time: confidential data leaking into AI systems. The reality is clear—traditional NDA clauses were not written for generative AI. Today, any party can upload sensitive information into a public large language model, intentionally or by accident, resulting in loss of control and sometimes even public disclosure. We’re seeing a surge in updated NDA language: “Receiving Party shall not (directly or indirectly) submit, upload, input, or otherwise disclose any Confidential Information… to any artificial intelligence system, machine learning model, large language model, or similar technology… that allows third parties to access, view, or enables any party involved in managing or developing the AI Systems to use such information to train the AI System…” For many, this is now essential—clear guardrails for an unpredictable risk surface. For others, it raises questions: how far should we go in restricting workflows? Is this protection, or overkill? Has your organization updated NDA templates to address AI-enabled data sharing? If so, what language works, and are you seeing new challenges from partners, vendors, or regulators? This isn’t about legal compliance—it’s about proactively defending what sets your company apart. In the age of generative tech, is your NDA future-proof? #AI #Cybersecurity #LegalInnovation #BusinessRisk #NDA #DataProtection

  • View profile for Gvantsa Baidoshvili

    Business & IP Law. Legal Engineering. Fluent in Common and Civil Law systems.

    18,273 followers

    Too many tech NDAs still include a “Residuals” carve-out: “Recipient may use information retained in unaided memory.” Here’s the concrete risk: If you permit memory-based reuse, you’ve signaled that the info isn’t tightly controlled. That undercuts the “reasonable measures” test for trade-secret protection. It also creates audit gaps. You can’t log or prove what someone “remembered,” so enforcement collapses on evidence. Worse, “residuals” language is vague. Engineers don’t know where “general know-how” ends and “client secrets” begin. That ambiguity shows up later - as infringement, leakage, or failed injunctions. Delete residuals entirely, or fence them in with hard exclusions: Residuals shall not include source code, models/weights, algorithms, datasets, prompts, strategic or financial plans, customer lists, technical specifications, security architecture, or any information that would identify the disclosing party or its counterparties. Reinforce secrecy standards: Nothing in this Agreement reduces protection under Applicable Trade Secret Law. Recipient shall implement and document reasonable measures to maintain secrecy, including access controls, need-to-know limits, and note-taking bans during access. Ban willful ‘memory capture’: Recipient shall not attempt to memorize Confidential Information or train personnel or tools to reconstruct it from memory. Tie to purpose and audits: Use is limited to the Purpose only. Recipient will keep access logs and certify deletions on request. Equitable relief available for threatened misuse. Add AI-specific guardrails: No ingestion of Confidential Information (in whole or part) into any AI system, model, or dataset; no fine-tuning, evaluation, or prompt-based reconstruction. __ Hello, I’m Gvantsa, Partner at GBPLO. I help entrepreneurs and high-growth companies close complex cross-border deals, secure IP, ensure enforceability across jurisdictions, and transform legal operations into profit-protecting, efficiency-driven systems. This post is for educational purposes only and does not constitute legal advice.

Explore categories