How to Sign an NDA with an Employee
What is an employee NDA?
An NDA is a non-disclosure agreement. An employer signs it with an employee to protect the company’s client database, commercial offers, prices, CRM data, internal documents, business model, logins, passwords, and other important information.
In simple terms, an NDA means that the employee may receive access to company information, but may not disclose it, copy it, transfer it to third parties, or use it for personal purposes.
An NDA is especially important for sales managers, administrators, accountants, lawyers, marketers, SMM specialists, IT specialists, HR employees, department heads, and anyone who works with clients or internal company data.
Why does a company need an NDA?
An NDA helps the employer prove that certain information was confidential and that the employee knew they were not allowed to use or disclose it.
Without an NDA, the company may face difficulties if an employee:
- copies the client database;
- transfers client contacts to a competitor;
- starts poaching clients;
- uses the company’s commercial offers;
- takes document templates;
- discloses prices and discounts;
- keeps access to CRM or email;
- uses internal materials after termination.
An NDA does not eliminate every risk, but it significantly strengthens the company’s legal position.
Is an NDA a separate agreement or part of an employment contract?
An NDA may be a separate agreement or an appendix to the employment contract. In practice, it is better to use several documents together:
- include a general confidentiality clause in the employment contract;
- sign a separate NDA with detailed terms;
- adopt an internal trade secret policy;
- have the employee confirm they reviewed that policy.
This set of documents works better than one general confidentiality sentence in the employment contract.
Which employees should sign an NDA?
An NDA should be signed with employees who have access to important company information.
For example:
- sales managers;
- call-center operators;
- administrators;
- lawyers;
- accountants;
- marketers;
- SMM specialists;
- IT specialists;
- HR specialists;
- department heads;
- measurement specialists;
- employees working with CRM;
- employees with access to the client database;
- employees working with contracts and financial information.
If an employee has no access to important information, an NDA may be less relevant. But for businesses where clients and data are key assets, NDAs should be implemented systematically.
What should be considered confidential information?
The NDA should clearly define confidential information. A vague phrase such as “all company information” may not be enough.
Confidential information may include:
- client database;
- client names, phone numbers, addresses, and requests;
- negotiation history;
- CRM data;
- prices and discounts;
- commercial offers;
- contracts;
- suppliers and partners;
- sales scripts;
- marketing plans;
- advertising account data;
- financial indicators;
- business plans;
- internal regulations;
- training materials;
- logins and passwords;
- access to website, email, CRM, WhatsApp Business, Instagram;
- document templates, presentations, texts, and instructions.
The more specific the list, the easier it is to prove a breach.
What obligations should the NDA include?
The NDA should state that the employee must:
- not disclose confidential information;
- not transfer it to third parties;
- not use it for personal purposes;
- not copy the client database;
- not save documents on personal devices;
- not transfer information to competitors;
- not disclose logins and passwords;
- not use company materials after termination;
- return all documents and access credentials when leaving;
- delete copies of confidential information;
- maintain confidentiality after employment ends.
It is important to prohibit not only disclosure, but also unauthorized use.
How to protect the client database through an NDA?
The client database should be specifically mentioned in the NDA because it is often one of the most valuable company assets.
The NDA may state that:
- the client database belongs to the employer;
- the employee may use it only to perform job duties;
- copying, exporting, or transferring the database is prohibited;
- clients may not be used for personal purposes;
- the employee may not work with company clients behind the employer’s back;
- the employee may not poach clients after termination, if such restriction is agreed;
- the obligation continues after termination of employment.
If a manager starts contacting clients after leaving, this section becomes very important.
Can a penalty be included in the NDA?
Yes, the NDA may include a penalty for breach of confidentiality. However, the penalty should be specific and reasonable.
A penalty may be provided for:
- copying the client database;
- transferring information to third parties;
- disclosing trade secrets;
- transferring data to a competitor;
- poaching clients;
- failure to return documents;
- keeping copies after termination;
- using information in a personal business.
Sample wording:
“In case of copying, transferring to third parties, or using the client database for personal purposes, the employee shall pay the employer a penalty of 1,000,000 tenge and compensate the losses caused.”
If the penalty is excessive, a court may reduce it. Therefore, the amount should be reasonable.
Can damages be claimed in addition to the penalty?
Yes, if this is expressly stated in the NDA.
For example:
“Payment of the penalty does not release the employee from the obligation to compensate the employer for damages in full.”
This is important because the actual damage from a client database leak may exceed the penalty amount.
Does the NDA remain valid after termination?
Yes, if the agreement says so. The NDA should state that confidentiality obligations survive termination of employment.
For example:
“The employee’s obligation not to disclose or use confidential information shall remain in force for 5 years after termination of employment.”
The NDA may set a specific period or state that the obligation remains until the information loses its confidential nature.
How should the NDA be signed?
For an NDA to work properly, the signing process should be documented.
The employer should:
- provide the employee with the NDA text;
- explain what information is confidential;
- obtain the employee’s signature;
- keep the signed copy;
- familiarize the employee with the trade secret policy;
- document access to CRM, email, and other systems;
- keep records of who has access to what information.
If the employee never signed the NDA, proving confidentiality obligations may be harder.
What should be done when the employee leaves?
When the employee leaves, the company should close information risks, not just issue a termination order.
The employer should:
- block CRM access;
- disable corporate email;
- change passwords;
- remove access to WhatsApp Business, Instagram, and the website;
- return documents and equipment;
- sign an access return act;
- require deletion of copies;
- remind the employee in writing that the NDA remains in force.
Many data leaks happen at the moment of termination, so this stage should not be ignored.
What if the employee breaches the NDA?
If an employee breaches the NDA, the employer should act quickly:
- Record the breach.
- Save correspondence, screenshots, and CRM logs.
- Block access.
- Prepare an internal incident report.
- Request an explanation from the employee.
- Send a written demand.
- Demand that the employee stop using the information.
- Demand deletion or return of data.
- Calculate the penalty and damages.
- Go to court or contact the police if necessary.
For court, the key evidence includes the contract, NDA, access to information, fact of breach, and calculation of the claim.
Common NDA mistakes
Common employer mistakes include:
- no specific list of confidential information;
- the client database is not mentioned separately;
- no penalty clause;
- no damages clause;
- no post-employment obligation;
- the employee did not sign the agreement;
- no internal trade secret policy;
- access rights were not documented;
- no return procedure for documents;
- the NDA is downloaded from the internet and not adapted to the business.
An NDA should match the company’s real business processes.
NDA and trade secrets
An NDA works best together with a trade secret regime. The company should adopt an internal policy, define the list of trade secrets, restrict access, mark important documents, and inform employees of the rules.
If the company does not take measures to protect information, it may be harder to prove that the information was truly confidential.
Conclusion
To properly sign an NDA with an employee, the company should clearly define confidential information, client database protection, employee obligations, term of confidentiality, liability, penalty, damages, and post-employment duties.
A good NDA protects real business assets: clients, data, business processes, prices, scripts, CRM, and internal materials.
An NDA is not just a formality. It is a legal lock on the door where the company keeps its business information.
FAQ
Should an employee sign an NDA?
Yes, if the employee has access to the client database, prices, CRM, internal documents, commercial offers, or other important information.
Should the NDA be separate or part of the employment contract?
It is better to sign a separate NDA and also include a confidentiality clause in the employment contract.
What should be defined as confidential information?
Client database, CRM data, prices, discounts, commercial offers, contracts, business plans, logins, passwords, and internal documents.
Can a penalty be recovered for NDA breach?
Yes, if the penalty is stated in the NDA and the breach is proven.
Does the NDA remain valid after termination?
Yes, if the agreement states that confidentiality obligations continue after termination.
What if the employee takes the client database?
The employer should block access, preserve evidence, send a written demand, require deletion of data, and consider court action.
Is a trade secret policy needed?
Yes, preferably. An NDA combined with an internal trade secret policy gives the company stronger protection.

