NDA for software development

An NDA for a software development project, protecting the client's requirements, data and code and the developer's own tools and libraries, reviewed or drafted, for a fixed fee of £495 in three working days.

Share

NDA for software development

A non-disclosure agreement for a business engaging a developer or development agency, or for a developer receiving a client's requirements, reviewed or drafted, covering source code, architecture and data, the specification and the idea, the developer's own libraries and tools, open source, ownership of the code, access to systems, and the position after the project. £495, in three working days.

Buy now, £495

A software development project exposes the client's requirements, its data, its existing systems and, once the work starts, the source code, to a developer that builds similar systems for others; and it exposes the developer's own libraries, tools and methods to a client that may take the project elsewhere. A non-disclosure agreement signed before the requirements are shared protects both, and it has to deal with the questions an NDA alone does not answer: who owns the code, what open source components carry, and what access the developer has to the client's systems. I review the NDA one side has proposed, or draft one for the party instructing me, for a fixed fee of £495 in three working days.

Who this is for

Businesses in England and Wales commissioning software, an app, a platform or an integration from a development agency, a freelance developer or an offshore team, and developers and agencies receiving a client's requirements before a development agreement is signed. Both parties are businesses.

What matters in an NDA for software development

Source code, architecture, data and the specification

The NDA should define the confidential information to include the client's requirements and specification, its business processes, its data and database structures, its existing code and architecture, its API keys and credentials, and the code and documentation produced during the project. Source code is a literary work protected under section 3 of the Copyright, Designs and Patents Act 1988, and the NDA should record that access to it under the NDA grants no licence to use it beyond the project.

The developer's own libraries, tools and methods

A developer brings frameworks, libraries, components and methods that it uses across projects, and the NDA should protect them as the developer's confidential information where they are not public, state that they remain the developer's property, and distinguish them from the client-specific code. The review drafts the distinction so that both sides can identify what belongs to whom, which then carries into the development agreement's intellectual property clause.

Ownership of the code: what the NDA does and does not do

An NDA protects information; it does not transfer ownership of the code. Under section 11 of the Copyright, Designs and Patents Act 1988 the developer owns what it writes unless it assigns it in writing under section 90, and copyright in code not yet written can be assigned in advance under section 91. The review advises that the assignment belongs in the development agreement, adds an interim provision to the NDA so that code written before the agreement is signed is dealt with, and checks that the NDA does not accidentally assign the developer's libraries.

Open source components and their licences

Code the developer incorporates under an open source licence is not confidential and carries obligations of its own, and a copyleft licence can require the client's own code to be released if the two are combined and distributed. The NDA should carve open source components out of the confidential information and require the developer to disclose the components and licences it uses, so that the client knows what it is receiving before the development agreement fixes the position.

Access to systems, credentials and personal data

A developer given access to the client's systems and data for the project needs authority to access them, since access beyond what is authorised is an offence under section 1 of the Computer Misuse Act 1990, and where the systems contain personal data the developer processes it as the client's processor, which requires the terms in Article 28 of the UK GDPR and the Data Protection Act 2018. The NDA should define the access granted, require the developer to use only the credentials issued and to return them, and either contain the processor terms or state that they will be in the development agreement before any personal data is accessed.

After the project, remedies and the developer's other clients

The NDA should prohibit the developer using the client's requirements or code for other clients, and the client using the developer's libraries for other developers, for as long as the information remains confidential, the standard the Trade Secrets (Enforcement, etc.) Regulations 2018 apply to trade secrets, with return or deletion of code, data and credentials when the project ends or the NDA is terminated. It should acknowledge that damages may be an inadequate remedy, carve out disclosures required by law, and be governed by English law with jurisdiction in England and Wales, with the review considering enforceability where the developer is offshore.

What it costs

NDA review or drafting, £495. Three working days.

Buying online forms the engagement on payment. The scope is what the contract review page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • Your own contract returned with my amendments as tracked changes, plus a clean version with every change accepted, ready to send to the other side
  • Comments in the document where a point needs explaining
  • A written explanation of what I have changed and why, by email or as an attachment if it is lengthy, marking the points I would hold firm on and the ones that are negotiable
  • A view on what is normal market practice and what is the other side pushing their luck
  • One round of follow-up questions by email, included

What is not included

  • Negotiating directly with the other side, which I quote separately once I know who is on the other side. Where the other side is willing to share a live document, I can work in that document directly
  • Drafting a replacement contract from scratch
  • Advice on the law of any jurisdiction other than England and Wales
  • Tax, accounting or regulatory advice
  • Disputes about a contract that is already signed

Questions I am often asked

Does the NDA mean we own the code the developer writes?

An NDA does not transfer ownership: copyright stays with the developer unless it assigns the code in writing. The review adds an interim provision for code written before the development agreement is signed and advises on the assignment clause the agreement needs.

We are a development agency. Can the client's NDA take our framework?

It can if it is drafted widely, and clients' forms are. The review marks up the NDA so that your libraries, tools and methods remain yours and are protected as your confidential information, with only the client-specific code treated as the client's.

The developer is offshore. Is an English-law NDA enforceable against them?

It gives you a claim in England and Wales, but a judgment may not be enforceable where the developer is. The review considers an arbitration clause whose award would be enforced there, and advises on the practical protections: staged disclosure, code held in your own repository and credentials you control.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.