---
title: "Trade Secrets and NDAs for Indian Startups Explained"
description: "India has no Trade Secret Act. Startups protect know-how via contracts (Section 27 Contract Act), IT Act Sections 43A and 72, BNS breach of trust, NDAs."
url: "https://advaslam.com/writing/trade-secrets-nda-protection-startups-india/"
image: "https://advaslam.com/og/writing/trade-secrets-nda-protection-startups-india.png"
---

[Business, banking & IPR](https://advaslam.com/practice/business-banking-ipr/)

# Trade Secrets and NDAs for Indian Startups: Protecting What You Don't Publish

By [**Adv. K J Muhammed Aslam**](https://advaslam.com/profile/) · Advocate, Ernakulam (Bar Council of Kerala)

Published 1 September 2026

India has **no standalone Trade Secret Act**, so the protection a Kerala startup has for its undisclosed know-how — pricing models, customer lists, training datasets, process know-how, source code that is not published — depends not on registration but on whether the business creates confidentiality by **contract** under the [Indian Contract Act, 1872](https://indiacode.gov.in/handle/123456789/496413) and by **conduct** through access controls, with statutory support from [Section 43A and Section 72 of the IT Act, 2000](https://indiacode.gov.in/handle/123456789/496511) and — where entrustment and misappropriation are made out — [Section 316 of the Bharatiya Nyaya Sanhita, 2023](https://indiacode.gov.in/handle/123456789/496548). An NDA signed after disclosure, or a non-compete so broad it is void under [Section 27 Contract Act](https://indiacode.gov.in/handle/123456789/496413), is not protection — it is paperwork that fails when tested.

## How is a trade secret defined when there is no Trade Secret Act?

No statute supplies a definition, so courts and commentators apply the classic three-part test drawn from TRIPS Article 39 and Indian breach-of-confidence jurisprudence:

| Element | What the business must show |
| --- | --- |
| **Secrecy** | The information is not generally known or readily accessible to persons who normally deal with that kind of information |
| **Commercial value because it is secret** | The information has economic value precisely because it is not public — a customer list, a trained model’s weights, a process yield — and disclosure would erode that value |
| **Reasonable steps to keep it secret** | The holder took measures that a reasonable business would take to preserve confidentiality — NDAs, need-to-know access, marking, technical controls, exit procedures |

A business that cannot show the third element — reasonable steps — fails even where the first two are made out. A pitch deck emailed without an NDA, a codebase accessible to every intern, and a customer database downloadable to personal devices are not trade secrets in practice, because no reasonable steps were taken to keep them secret. The DPDP Act reinforces this logic from the data side: [Rule 6 DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) requires encryption or masking, access controls and logging — the same controls that support a trade-secret claim.

## What laws actually protect trade secrets in India?

| Source | What it does | Limit |
| --- | --- | --- |
| **Contract — Sections 27, 73, 74 Contract Act, 1872** | Enforces NDAs, confidentiality clauses, non-solicitation and — where reasonable — limited post-contract restraints; damages for breach under Sections 73 and 74 | Section 27 voids agreements in **restraint of trade** — a blanket non-compete preventing a former employee from working in the same field anywhere is typically void; non-disclosure is distinct and generally enforceable |
| **Equity — breach of confidence** | Injunction and damages where confidential information was imparted in circumstances importing confidence and was misused — available even without a written NDA where the circumstances show confidence | Requires proof of the confidential character and the circumstances of disclosure |
| **IT Act — Section 43A** | Compensation for negligent failure to implement reasonable security practices where wrongful loss or gain results from handling of sensitive personal data — relevant where the trade secret includes personal data | Civil compensation; complements DPDP Section 8(5) safeguards (up to two hundred and fifty crore rupees for safeguard failure) |
| **IT Act — Section 72** | Penalty for breach of confidentiality and privacy by a person who has secured access to electronic records under the IT Act — penalty up to five lakh rupees (substituted for imprisonment and fine by the Jan Vishwas (Amendment of Provisions) Act, 2023) | Applies where access was obtained under IT Act powers or duties; narrower than Section 72A’s contractual disclosure route |
| **IT Act — Section 72A** | Penalty for disclosure of personal information in breach of a lawful contract, intending or knowing wrongful loss or gain — penalty up to twenty-five lakh rupees (substituted for imprisonment and fine by the Jan Vishwas (Amendment of Provisions) Act, 2023) | Requires a lawful contract and the mental element of wrongful loss or gain |
| **BNS — Section 316 (criminal breach of trust)** | Punishment where property is entrusted and dishonestly misappropriated or converted — invoked where an employee or partner entrusted with data or materials misappropriates them | Requires entrustment and dishonest misappropriation — not every NDA breach qualifies |
| **BNS — Section 336 (forgery), Section 353 (statements conducing to public mischief)** | Where misuse involves fabrication of records or misrepresentation | Fact-specific |

> **Practical observation:** Most startup trade-secret disputes are won or lost on contract and on evidence of reasonable steps, not on the criminal provisions. The criminal track is fact-heavy and is not a substitute for a well-drafted NDA and an access-control programme.

## What makes an NDA enforceable — and what makes it fail under Section 27?

Section 27 Contract Act — every agreement by which anyone is restrained from exercising a lawful profession, trade or business of any kind is to that extent void — is the provision founders fear and counterparties invoke. The fear is partly misplaced because courts distinguish:

-   **Non-disclosure — generally enforceable.** An obligation not to disclose specific confidential information is a restraint on **disclosure**, not on the ability to carry on a trade. It is not the restraint Section 27 targets.
-   **Non-compete — closely scrutinised and often void post-employment.** A clause that says a former employee cannot work for any competitor anywhere for two years is a restraint on trade and is typically void under Section 27. A narrowly drawn restraint — for example, not to solicit the employer’s customers with whom the employee actually dealt, for six months, within a defined territory where the employer operates — has a better chance, but remains difficult. During employment, reasonable exclusivity and non-compete terms are more readily enforced; post-employment, the bar is higher.
-   **Non-solicitation — more readily enforced where reasonable.** Not to solicit employees or customers of the former employer, limited in time, scope and geography, tied to genuine confidential relationships.

An NDA that fails usually fails for one of these reasons:

1.  **Signed after disclosure.** The information was already shared before the NDA existed — there was no confidential basis at the time of sharing.
2.  **No definition of confidential information.** A clause that says everything is confidential is not credible; a schedule of categories with exclusions (publicly available information, independently developed information, information rightfully received from a third party without breach) is.
3.  **Unreasonable duration or geography.** Perpetual confidentiality for every casual disclosure is harder to enforce than a defined period tied to the sensitivity of the information and the commercial context.
4.  **No return-or-delete obligation.** The NDA allows the recipient to retain copies indefinitely, which undermines the secrecy claim.
5.  **No injunctive-relief acknowledgement.** The agreement does not acknowledge that breach would cause irreparable harm for which damages are inadequate — the language that supports an interim injunction.

## What should a Kerala startup’s NDA and confidentiality programme actually contain?

### The NDA — clauses that matter

1.  **Definition and exclusions.** Define confidential information by categories relevant to the startup — code, datasets, models, customer lists, financials, roadmaps — and list exclusions (public domain through no breach, independently developed, rightfully received from a third party).
2.  **Purpose limitation.** State the specific purpose of disclosure (evaluation of a partnership, employment, investment diligence) and prohibit use beyond that purpose.
3.  **Standard of care.** Require at least the same care the recipient uses for its own confidential information, and in any event reasonable care — including technical safeguards where the information is electronic.
4.  **No licence or assignment.** Clarify that disclosure does not transfer ownership — copyright stays with the author or employer under Sections 17 to 19 of the Copyright Act (see the [software copyright guide](https://advaslam.com/writing/software-copyright-startup-kerala-guide/)), and patent rights are not licensed by the NDA.
5.  **Duration.** A confidentiality period appropriate to the information — often two to five years for general commercial information, longer or indefinite for true trade secrets where the parties genuinely intend perpetual secrecy and the information qualifies.
6.  **Return or certified deletion.** On termination or on demand, return or certify deletion of confidential information and copies, including from backups where technically feasible, with a written certificate of deletion.
7.  **Residual knowledge.** Address whether general skills and knowledge retained in unaided memory are excluded — a point that matters for employee mobility and that should be addressed explicitly rather than left to argument.
8.  **Personal-data handling.** Where confidential information includes personal data, require compliance with the DPDP Act — lawful basis, purpose limitation, Rule 6 security safeguards, Rule 7 breach notification — so the NDA and the DPDP processor obligations reinforce each other (see the [DPDP countdown guide](https://advaslam.com/writing/dpdp-act-deadline-businesses/) and the [cross-border transfer guide](https://advaslam.com/writing/dpdp-cross-border-data-transfer-section-16/)).
9.  **Remedies.** Acknowledge irreparable harm and the availability of injunctive relief in addition to damages under Sections 73 and 74 Contract Act, and provide for governing law and dispute resolution (arbitration in Kochi is common for startups).
10.  **Reasonable post-employment restraints.** If sought, draw non-compete and non-solicitation narrowly — limited customers, limited geography, short duration — so they have a chance of surviving Section 27 scrutiny, and consider garden-leave or notice-period mechanisms during employment where appropriate.

### The programme — conduct that proves reasonable steps

An NDA without a programme is a contract without evidence. The reasonable-steps file a court or an investor looks for:

-   **Marking.** Confidential documents and repositories marked as such — not every email, but every genuinely sensitive disclosure.
-   **Need-to-know access.** Role-based access, least privilege, and logging of who accessed what — the same controls Rule 6 DPDP requires for personal data, applied to trade secrets.
-   **Onboarding and exit.** Confidentiality acknowledgements at joining, periodic reminders, and a structured exit process that revokes access, collects devices, and reminds the departing person of surviving obligations in writing.
-   **Vendor handling.** Every contractor, agency and cloud provider signs confidentiality and data-processing terms before access — not after — with sub-processing controls where personal data is involved.
-   **Logging for proof.** Access logs retained for at least the periods the business has chosen (the DPDP Rule 6 minimum is one year for personal-data logs; the CERT-In Directions require 180 days for ICT logs) so that misuse can be reconstructed and proved under [Section 63 BSA](https://advaslam.com/writing/electronic-evidence-bsa-section-63-certificate-guide/) if needed.

## How do trade secret, copyright, patent and DPDP fit together?

For a typical Kerala SaaS or healthtech startup, the portfolio is:

-   **Trade secret** — for undisclosed know-how, pricing, customer insights, and model weights that must stay confidential and that derive value from secrecy.
-   **Copyright** — for code expression and documentation automatically under Section 2(o) Copyright Act, strengthened by Form XIV registration and the Section 48 certificate.
-   **Patent** — for the inventive technical solution where the [Section 3(k) and CRI Guidelines 2025](https://advaslam.com/writing/patent-computer-related-inventions-cri-guidelines-2025/) technical-effect test is met, accepting that publication in the specification ends secrecy for that invention.
-   **Trademark** — for the brand (see the [online trademark infringement guide](https://advaslam.com/writing/trademark-infringement-online-domain-phishing-indrp/)).
-   **DPDP compliance** — for personal data within the know-how (customer data, user data) under the DPDP Act and Rules, with the same technical controls serving both trade-secret and data-protection purposes.

## Primary sources

-   [Indian Contract Act, 1872 — India Code](https://indiacode.gov.in/handle/123456789/496413) (Sections 27, 73, 74)
-   [Information Technology Act, 2000 — India Code](https://indiacode.gov.in/handle/123456789/496511) (Sections 43A, 72, 72A)
-   [Bharatiya Nyaya Sanhita, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496548) (Sections 316, 336)
-   [Copyright Act, 1957 — India Code](https://indiacode.gov.in/handle/123456789/496733) (Sections 2(o), 17, 18, 19, 48)
-   [Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (Section 8(5), Rule 6)
-   [Bharatiya Sakshya Adhiniyam, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496549) (Section 63 — proving electronic logs)

FAQ

## Common questions

**Is there a Trade Secret Act in India?**

No. India has no codified Trade Secret Act. Trade secrets are protected through a combination of contract law (the Indian Contract Act, 1872 — especially Section 27 on agreements in restraint of trade), equitable breach of confidence, Section 43A and Section 72 of the IT Act, 2000 on data handling and confidentiality, and — where entrustment and dishonest misappropriation are made out — criminal breach of trust under Section 316 of the Bharatiya Nyaya Sanhita, 2023. Protection therefore depends on how well the business creates confidentiality by contract and by conduct.

**Are NDAs enforceable in India?**

Yes, where they are reasonable. A non-disclosure obligation — not to disclose confidential information — is generally enforceable as a restraint on disclosure, distinct from a restraint on trade or employment. What courts scrutinise under Section 27 of the Contract Act is a restraint on carrying on a lawful profession or trade: a blanket non-compete that prevents a former employee from working in the same field anywhere is typically void under Section 27, while a narrowly drawn non-disclosure and non-solicitation that protects genuine confidential information is enforceable. Reasonableness of time, geography and scope decides the outcome.

**Can I protect my startup idea as a trade secret?**

An idea alone, without more, is hard to protect — trade secret protection attaches to information that is secret, has commercial value because it is secret, and is subject to reasonable steps to keep it secret. A bare idea disclosed without a confidentiality arrangement, without markers of secrecy and without access controls, rarely meets that test. An idea embodied in a plan, model, codebase, dataset or process that is shared only under a signed NDA and with need-to-know access can be.

**What should a startup NDA include to be effective?**

A clear definition of confidential information and exclusions, the purpose of disclosure, the standard of care and permitted uses, the duration of confidentiality, return or certified deletion on termination, the treatment of residual knowledge, the handling of personal data where relevant, and — where post-employment restraints are sought — narrowly drawn non-compete and non-solicitation clauses that are reasonable in time, scope and geography so they can survive Section 27 scrutiny. The NDA should be signed before disclosure, not after.

**What is the difference between trade secret and patent for a startup?**

A patent — if granted — gives a 20-year monopoly in exchange for public disclosure of the invention in the specification. A trade secret lasts as long as secrecy is maintained, but gives no monopoly against independent invention or reverse engineering. Choose patent where the advantage is in the inventive solution and disclosure is acceptable (see the CRI Guidelines guide for software and AI); choose trade secret where the advantage depends on non-disclosure and the information can be kept confidential in practice.

**A note on this article.** It is general legal information, not legal advice. The law may have changed since the date shown; before acting on anything here, take advice on your specific situation from an advocate of your choice.

## Related guides

-   [NDAs and confidentiality clauses — drafting and review](https://advaslam.com/practice/drafting/matters/agreements/#phrase-non-disclosure-agreement-nda-format-india-enforceability)
-   [Trade secrets and confidentiality — injunctions](https://advaslam.com/practice/business-banking-ipr/matters/trademark-copyright-design-secrets/#nda-sec-27-trade-secret-suit-protection-pack)

[All procedure guides →](https://advaslam.com/guides/)

Keep reading

Business, banking & IPR

### Can You Patent Software and AI in India? Section 3(k) and the CRI Guidelines 2025 Explained

Section 3(k) Patents Act excludes computer programmes per se, not all software. The technical effect and contribution test under the CRI Guidelines 2025.

1 Sept 2026

[Can You Patent Software and AI in India? Section 3(k) and the CRI Guidelines 2025 Explained](https://advaslam.com/writing/patent-computer-related-inventions-cri-guidelines-2025/)

Business, banking & IPR

### Software Copyright for Kerala Startups: How Your Code Is Protected and How Founders Lose It

Software is a literary work under Section 2(o) Copyright Act, 1957. What is protected, Section 48 registration, source code deposit and assignment mistakes.

1 Sept 2026

[Software Copyright for Kerala Startups: How Your Code Is Protected and How Founders Lose It](https://advaslam.com/writing/software-copyright-startup-kerala-guide/)

Contact

[WhatsApp](https://wa.me/919497240215?text=Hello%2C%20I%20found%20advaslam.com%20and%20would%20like%20to%20discuss%20a%20matter.) [contact@advaslam.com](mailto:contact@advaslam.com) [+91 94972 40215](tel:+919497240215)

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

```json
{"@context":"https://schema.org","@graph":[{"@type":"WebSite","@id":"https://advaslam.com/#website","url":"https://advaslam.com","name":"Adv. K J Muhammed Aslam","alternateName":"advaslam.com","publisher":{"@id":"https://advaslam.com/#person"},"inLanguage":"en-IN"},{"@type":"Person","@id":"https://advaslam.com/#person","name":"K J Muhammed Aslam","alternateName":["Adv. K J Muhammed Aslam","Advocate K J Muhammed Aslam","Muhammed Aslam K J","Adv. Aslam"],"honorificPrefix":"Adv.","jobTitle":"Advocate","description":"Advocate enrolled with the Bar Council of Kerala, practising from High Court Junction, Ernakulam: cyber and technology law, data protection (DPDP), business, banking and IPR, and litigation before the High Court of Kerala and the courts at Ernakulam.","url":"https://advaslam.com/profile/","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"alumniOf":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"memberOf":[{"@type":"Organization","name":"Bar Council of Kerala","url":"https://barcouncilkerala.org/lawyer-registry-list"},{"@type":"Organization","name":"Kerala High Court Advocates' Association","url":"https://khcaa.com/"}],"identifier":[{"@type":"PropertyValue","propertyID":"Bar Council of Kerala Enrolment No.","value":"K/001823/2026"},{"@type":"PropertyValue","propertyID":"KHCAA Membership No.","value":"OAJ 358"}],"knowsAbout":["Information Technology Act 2000","Cyber crime law","Technology law and technology contracts","Digital Personal Data Protection Act 2023","DPDP compliance","Data protection and privacy law","Business and commercial law","Contract drafting and negotiation","Banking and finance law","Negotiable Instruments Act cheque dishonour","SARFAESI Act","Intellectual property law","Copyright and trademark law","Patent infringement","GST and income-tax law","Blockchain and cryptocurrency technology","Web3 wallets and NFTs","Drone regulation and DigitalSky framework","Writ petitions under Article 226","Criminal law","Civil and consumer litigation","Family and succession law","Service and labour law","Legal drafting","Mediation and dispute resolution"],"knowsLanguage":["en","ml"],"workLocation":{"@id":"https://advaslam.com/#practice"},"hasCredential":[{"@type":"EducationalOccupationalCredential","credentialCategory":"Enrolment as an advocate","identifier":"K/001823/2026","recognizedBy":{"@type":"Organization","name":"Bar Council of Kerala"},"description":"Enrolled as an advocate with the Bar Council of Kerala (K/001823/2026), 2026"},{"@type":"EducationalOccupationalCredential","credentialCategory":"degree","educationalLevel":"Bachelor","recognizedBy":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"description":"BBA LLB (Hons.), Bharata Mata School of Legal Studies (2025)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"Remote Pilot Certificate","recognizedBy":{"@type":"Organization","name":"Directorate General of Civil Aviation, India"},"description":"DGCA Remote Pilot Certificate, issued 2022"}],"subjectOf":[{"@type":"CreativeWork","name":"Govind Babu v. State of Kerala (Crl.M.C. No. 5640 of 2026, 2026:KER:69496)","url":"https://indiankanoon.org/doc/151180872/","datePublished":"2026-09-10","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Viji Sagar v. State of Kerala (Crl.M.C. No. 1603 of 2026, 2026:KER:20803)","url":"https://indiankanoon.org/doc/193042273/","datePublished":"2026-03-09","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Anjana v. Manoharan A.P. (C.R.P. No. 442 of 2025, 2026:KER:10054)","url":"https://indiankanoon.org/doc/68585852/","datePublished":"2026-02-05","publisher":{"@type":"Organization","name":"High Court of Kerala"}}],"sameAs":["https://www.linkedin.com/in/azlubro","https://portal.khcaa.com/advocate?id=10480","https://lexosys.com"]},{"@type":"LegalService","@id":"https://advaslam.com/#practice","name":"Adv. K J Muhammed Aslam — Advocate, Ernakulam","url":"https://advaslam.com","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"geo":{"@type":"GeoCoordinates","latitude":9.9889,"longitude":76.2748},"hasMap":"https://www.google.com/maps/search/?api=1&query=Lalan+Towers+High+Court+Junction+Ernakulam","areaServed":[{"@type":"City","name":"Ernakulam"},{"@type":"City","name":"Kochi"},{"@type":"State","name":"Kerala"},{"@type":"Country","name":"India"}],"openingHoursSpecification":{"@type":"OpeningHoursSpecification","dayOfWeek":["Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"opens":"10:00","closes":"18:30"},"founder":{"@id":"https://advaslam.com/#person"},"knowsAbout":["Cyber crime and IT Act matters","Data protection and DPDP Act compliance","Business, banking, intellectual property and tax","Legal drafting","Criminal law: bail, quash and appeals","Writ petitions before the High Court of Kerala","Civil, property and consumer matters","Family and succession matters","Service and labour matters"]},{"@type":"BlogPosting","@id":"https://advaslam.com/writing/trade-secrets-nda-protection-startups-india/#article","isPartOf":{"@id":"https://advaslam.com/#website"},"headline":"Trade Secrets and NDAs for Indian Startups: Protecting What You Don't Publish","description":"India has no Trade Secret Act. Startups protect know-how via contracts (Section 27 Contract Act), IT Act Sections 43A and 72, BNS breach of trust, NDAs.","url":"https://advaslam.com/writing/trade-secrets-nda-protection-startups-india/","mainEntityOfPage":"https://advaslam.com/writing/trade-secrets-nda-protection-startups-india/","datePublished":"2026-09-01T00:00:00.000Z","dateModified":"2026-09-01T00:00:00.000Z","keywords":"trade secret India law, NDA India enforceability, Section 27 Contract Act NDA, trade secret protection startup India, IT Act 43A 72 confidentiality, non-compete India enforceability","inLanguage":"en-IN","author":{"@id":"https://advaslam.com/#person"},"publisher":{"@id":"https://advaslam.com/#person"},"image":"https://advaslam.com/og/writing/trade-secrets-nda-protection-startups-india.png","about":{"@type":"Service","@id":"https://advaslam.com/practice/business-banking-ipr/#service","name":"Business, banking & IPR","url":"https://advaslam.com/practice/business-banking-ipr/","provider":{"@id":"https://advaslam.com/#practice"}}},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://advaslam.com/"},{"@type":"ListItem","position":2,"name":"Articles","item":"https://advaslam.com/writing/"},{"@type":"ListItem","position":3,"name":"Trade Secrets and NDAs for Indian Startups: Protecting What You Don't Publish","item":"https://advaslam.com/writing/trade-secrets-nda-protection-startups-india/"}]},{"@type":"FAQPage","mainEntity":[{"@type":"Question","name":"Is there a Trade Secret Act in India?","acceptedAnswer":{"@type":"Answer","text":"No. India has no codified Trade Secret Act. Trade secrets are protected through a combination of contract law (the Indian Contract Act, 1872 — especially Section 27 on agreements in restraint of trade), equitable breach of confidence, Section 43A and Section 72 of the IT Act, 2000 on data handling and confidentiality, and — where entrustment and dishonest misappropriation are made out — criminal breach of trust under Section 316 of the Bharatiya Nyaya Sanhita, 2023. Protection therefore depends on how well the business creates confidentiality by contract and by conduct."}},{"@type":"Question","name":"Are NDAs enforceable in India?","acceptedAnswer":{"@type":"Answer","text":"Yes, where they are reasonable. A non-disclosure obligation — not to disclose confidential information — is generally enforceable as a restraint on disclosure, distinct from a restraint on trade or employment. What courts scrutinise under Section 27 of the Contract Act is a restraint on carrying on a lawful profession or trade: a blanket non-compete that prevents a former employee from working in the same field anywhere is typically void under Section 27, while a narrowly drawn non-disclosure and non-solicitation that protects genuine confidential information is enforceable. Reasonableness of time, geography and scope decides the outcome."}},{"@type":"Question","name":"Can I protect my startup idea as a trade secret?","acceptedAnswer":{"@type":"Answer","text":"An idea alone, without more, is hard to protect — trade secret protection attaches to information that is secret, has commercial value because it is secret, and is subject to reasonable steps to keep it secret. A bare idea disclosed without a confidentiality arrangement, without markers of secrecy and without access controls, rarely meets that test. An idea embodied in a plan, model, codebase, dataset or process that is shared only under a signed NDA and with need-to-know access can be."}},{"@type":"Question","name":"What should a startup NDA include to be effective?","acceptedAnswer":{"@type":"Answer","text":"A clear definition of confidential information and exclusions, the purpose of disclosure, the standard of care and permitted uses, the duration of confidentiality, return or certified deletion on termination, the treatment of residual knowledge, the handling of personal data where relevant, and — where post-employment restraints are sought — narrowly drawn non-compete and non-solicitation clauses that are reasonable in time, scope and geography so they can survive Section 27 scrutiny. The NDA should be signed before disclosure, not after."}},{"@type":"Question","name":"What is the difference between trade secret and patent for a startup?","acceptedAnswer":{"@type":"Answer","text":"A patent — if granted — gives a 20-year monopoly in exchange for public disclosure of the invention in the specification. A trade secret lasts as long as secrecy is maintained, but gives no monopoly against independent invention or reverse engineering. Choose patent where the advantage is in the inventive solution and disclosure is acceptable (see the CRI Guidelines guide for software and AI); choose trade secret where the advantage depends on non-disclosure and the information can be kept confidential in practice."}}]}]}
```
