Table of Contents of Read These Twelve (12) Legal Principles Before Signing/Creating an Employer-Employee NDA

Table of Contents: Read These Twelve (12) Legal Principles Before Signing/Creating an Employer-Employee NDA

Read These Twelve (12) Legal Principles Before Signing/Creating an Employer-Employee NDA

An employer–employee NDA should protect legitimate business and personal-data interests without becoming so broad that it restricts lawful conduct or penalizes an employee for a good-faith legal claim.

1. Define “confidential information” with reasonable precision

The NDA should identify the categories of information covered, such as trade secrets, customer information, business plans, financial data, employee information, processes, source code, and internal reports.

It should exclude information that is:

  • publicly available without breach;
  • already lawfully known to the employee;
  • independently developed; or
  • lawfully received from a third party.

Avoid a blanket clause covering “all information relating to the employer.” In Yonzon v. Coca-Cola Bottlers Philippines, Inc. (2021), the Supreme Court said…

“For this very reason, Rule 3, Section 31 of the Red Book is unfair and unreasonable. It suffers from vagueness.”

“Giving of, supplying, and disclosing to the unauthorized person or the competitors, classified trade secrets, and other confidential materials, information, data or documents relating to the [Coca Cola’s] operations, programs formulae, processes, market studies, surveys, and other Company classified/restricted/confidential information, or other data, documents information similar to those enumerated herein.”

“Similarly, here, Coca-Cola did not give any examples or standards on how an information may be considered as confidential/classified/restricted leaving the same subject to the company’s whims and caprices.

Therefore, a company must establish specific standards or examples of what constitutes confidential information.

Whether a particular item is legally confidential depends on the employer’s treatment of the information, its commercial value, the access given to employees, and the measures taken to protect it.

Category of Confidential Information
(must clearly cover each information before prohibition against disclosure to unauthorized persons/competitors)
DescriptionExamples
1. Trade SecretNot merely based on the label. Courts consider factors such as (a) that such matter is publicly known as confidential; (b) the measures take to protect it; (c) its value to the employer and the competitors; (d) the effort or expense used to develop it; (e) how readily it can be obtained independently.1. A secret beverage formula or chemical composition.

2. A proprietary algorithm for detecting fraud or predicting customer demand.

3. A confidential pricing model that gives the employer an advantage over competitors.
2. Customer InformationInformation related to the customer’s personal information or activity. If it contains personal information, the employer must comply with the Data Privacy Act and its implementing rules. Employees who access these information must be (a) authorized by the employer; and (b) supported by reasonable organizational, physical, and technical measures.1. Customer names, contact numbers, email addresses, and delivery addresses.

2. Customer purchase history, preferences, complaints, and account records.

3. Customer credit information, transaction history, or negotiated pricing.
3. Business PlansContemplated future actions or strategy related to the conduct of the business of the employer.1. A plan to launch a new product or enter a new geographic market

2. A proposed merger, acquisition, restructuring, or expansion.

3. A strategy for responding to a competitor’s product or pricing campaign.
4. Financial DataAny quantitative information related to the employer/company that tracks how the money moves, what the latter owes, and its overall economic health.1. Non-public sales figures, revenue forecasts, and profit margins.

2. Departmental budgets, cash-flow projections, and cost structures.

3. Employee compensation data, payroll records, and proposed salary adjustments. (In the Coca-Cola case, the Court held that the employer did not clearly classify employee compensation as confidential information. Such classification cannot be subjected to their whims and caprices).
5. Employee InformationData relating to employees, including salary and employment records.1. Employee home address, telephone numbers, and emergency contacts;

2. Medical records, leave records, disability information, and health-insurance details.

3. Performance evaluations, disciplinary records, complaints and investigation files.
6. ProcessesOrganized methods or procedures by which business activities and services are performed.1. The step-by-step procedure for manufacturing, assembling, or testing a product.

2. An internal workflow for approving loans, refunds, or customer complaints.

3. A quality-control, logistics, or data processing procedure not disclosed to the public.
7. Source CodeHuman-readable instructions that direct a computer’s operation.

An NDA should cover the code itself, revisions, technical documentation, credentials, repositories, and derivative materials. It should also state that access to source code does not transfer ownership or grant the employee a license beyond what is necessary to perform assigned duties.
1. Source code for the employer’s mobile app, software app, or website.

2. Proprietary scripts for automation, data analysis, or system integration.

3. Internal libraries, APIs, database schemas, or software architecture documents.
8. Internal ReportsInformation generated within an organization for its operational, monitoring, or decision-making purposes.1. Internal audit reports and compliance-risk assessments;

2. Incident reports involving cybersecurity, workplace safety, or operational failures.

3. Management reports concerning sales performance, employee discipline, investigations, or regulatory exposure.

2. State the permitted purpose and prohibit unauthorized use

The NDA should specify that confidential information may be accessed and used only for the employee’s assigned functions.

An NDA should prohibit:

  • personal or unauthorized commercial use of confidential information;
  • disclosure to competitors or outsiders;
  • copying or downloading beyond business necessity;
  • use after reassignment or termination; and
  • use to solicit customers, employees, or business opportunities, unless separately and lawfully justified.

The restriction should be tied to the employer’s legitimate business interests and should not unnecessarily restrain the employee’s lawful work or legal rights.

Examples of Unauthorized Use/Disclosure of Confidential Information

  • 1. Disclosing the salary information of other employees without authorization (although the disclosure was later justified because the company rule was vague and the disclosure was used before a Labor Tribunal). – Yonzon vs. Coca-Cola
  • 2. A lending company is sending the personal information of its borrowers to the borrowers’ contacts to shame them into paying. The NPC characterized these acts as unauthorized processing and malicious disclosure of personal information. – Trimillos vs. FCash Global Lending (2025)
  • 3. Individuals unlawfully accessing and extracting election-related personal data – In Re: COMELEC, Smartmatic, RVA, WS and Other John Does and Jane Does. (2022)

3. Distinguish confidentiality from personal-data protection

If the information includes employee, customer, applicant, health, payroll, identification, or other personal data, the NDA should expressly state that the employee must comply with the Data Privacy Act of 2012 and its implementing rules.

A confidentiality clause does not, by itself, establish lawful authority to process personal data. Processing must observe transparency, legitimate purpose, and proportionality. Personal data must be adequate, relevant, limited to what is necessary, protected by appropriate safeguards, and not retained longer than necessary. These requirements are stated in the IRR of Republic Act No. 10173.

4. Limit employee access on a need-to-know basis

The employer should implement access controls so that employees receive only the data necessary for their functions. The NDA should require the employee to:

  • access information only through authorized systems;
  • avoid sharing credentials;
  • disclose information only to authorized persons;
  • secure physical and electronic records; and
  • immediately report suspected loss, unauthorized access, or disclosure.

The IRR specifically requires organizations to select and supervise personnel with access to personal data and requires those personnel to hold non-public personal data under strict confidentiality. That obligation continues even after the employee leaves employment or the contractual relationship ends. IRR of Republic Act No. 10173

5. Include lawful-disclosure exceptions

The NDA should not prohibit disclosure when it is:

  • required by law, subpoena, court order, or lawful government directive;
  • made to a regulator or public authority for a legitimate official purpose;
  • necessary to establish, exercise, or defend a legal claim; or
  • made to a lawyer or other professional adviser subject to confidentiality duties.

For sensitive personal information, the Data Privacy Act permits processing where it is necessary for the protection of lawful rights and interests in court proceedings, the establishment, exercise, or defense of legal claims, or when provided to a government or public authority. Yonzon v. Coca-Cola Bottlers Philippines, Inc. (2021)

The employee should, where legally permitted, give the employer prior notice of compelled disclosure and disclose only the portion legally required. The NDA should not be used to suppress whistleblowing, cooperation with lawful investigations, or the pursuit of labor and other legal remedies.

6. State clearly what happens upon termination

The agreement should require the employee, upon resignation, termination, reassignment, or demand, to:

  1. return company documents and devices;
  2. delete or surrender unauthorized copies;
  3. stop accessing company systems;
  4. preserve information subject to a litigation hold or legal-retention duty; and
  5. certify compliance when appropriate.

Confidentiality obligations may continue after employment, especially for information that remains non-public or legally protected. For personal data, the IRR expressly provides that the employee’s confidentiality obligation continues after leaving public service, transferring positions, or terminating employment or contractual relations. IRR of Republic Act No. 10173

7. Use a reasonable duration

The NDA should distinguish between:

  • ordinary business-confidential information, which may be protected for a defined reasonable period; and
  • trade secrets or personal data, which should remain protected for as long as they remain confidential or legally subject to protection.

An indefinite clause covering information that has already become public or is no longer commercially sensitive is unnecessarily broad. The agreement should also identify the event that starts the confidentiality period and the circumstances that end it.

Ordinary Confidential InformationTrade Secret
Information kept confidential because disclosure may harm the business.Information involving a commercially valuable secret
Examples: Internal reports, business information, supplier information (depending on the circumstance), employee data.Supplier information (depending on the circumstance), technical process, formula, proprietary system, or any information in which disclosure can impair the owner’s competitiveness.
Protected for a defined reasonable periodProtected for as long as they remain confidential

8. Require reasonable security measures

The employee’s obligations should include practical safeguards, such as:

  • using company-approved devices and applications;
  • encrypting or securely transmitting sensitive files;
  • preventing unauthorized viewing or downloading;
  • maintaining secure passwords and authentication;
  • not using personal email or unapproved cloud storage; and
  • securely disposing of printed and electronic records.

The employer remains responsible for implementing appropriate organizational, physical, and technical measures. An NDA should therefore complement, not replace, the employer’s privacy and information-security policies. IRR of Republic Act No. 10173

9. Provide a breach-reporting procedure

The NDA should require immediate reporting of any actual or suspected:

  • lost device or document;
  • misdirected email;
  • unauthorized access;
  • accidental disclosure;
  • compromised account; or
  • improper downloading or copying.

An accidental disclosure may still constitute a personal-data breach. In NPC Case No. 18-K-200 (2020), the NPC held that an employee’s lack of intent or malice did not remove the organization’s obligations arising from an unauthorized disclosure.

Where a qualifying personal-data breach is involved, the employer may have to notify the NPC and affected data subjects within the applicable 72-hour period under NPC Circular 16-03. The NDA should require prompt internal reporting—preferably immediately or within a specified number of hours—so the employer can assess and comply with that deadline.

10. Avoid treating every breach as automatic grounds for dismissal

The NDA may identify serious violations and disciplinary consequences, but it should not state that any technical or inadvertent disclosure automatically justifies dismissal. The employer should consider:

  • the employee’s position and level of responsibility;
  • the nature and sensitivity of the information;
  • whether the employee was authorized to access it;
  • intent, negligence, or good faith;
  • actual or probable harm;
  • the employee’s compliance with reporting duties; and
  • the employer’s applicable disciplinary rules.

Under Yonzon v. Coca-Cola Bottlers Philippines, Inc. (2021), dismissal based on loss of trust and confidence requires that the employee occupy a position of trust and that there be a clearly established act justifying the loss of trust. A vague confidentiality provision is not sufficient by itself.

11. Coordinate the NDA with company policies

The NDA should be consistent with the employer’s:

  • employee handbook;
  • acceptable-use policy;
  • data-privacy notice;
  • information-security policy;
  • records-retention policy; and
  • disciplinary rules.

The agreement should identify which document prevails in case of inconsistency. Employees should receive adequate orientation and training, particularly when they handle personal data. The IRR requires capacity-building, orientation, or training for personnel who process personal data. IRR of Republic Act No. 10173

12. Include ownership and no-license provisions

The NDA should clarify that:

  • confidential information remains the employer’s property;
  • disclosure does not transfer ownership;
  • no intellectual-property license is granted except the limited right to perform assigned work; and
  • work product and company records must be returned or preserved as required.

The NDA should not, however, claim ownership over an employee’s general knowledge, skills, experience, or independently developed work unless a separate and legally supportable agreement governs those matters.

Practical standard

A sound employer–employee NDA should be:

  1. specific about the information protected;
  2. limited to legitimate business and privacy purposes;
  3. clear about authorized access and use;
  4. qualified by lawful-disclosure and legal-claim exceptions;
  5. continuing where the information remains confidential or legally protected;
  6. supported by actual security measures and employee training; and
  7. proportionate in its disciplinary and remedial consequences.

The most important drafting risk is an overbroad definition of confidential information. The NDA should protect genuine secrets and personal data, but should not be used to prevent an employee from reporting wrongdoing, cooperating with lawful authorities, or asserting a legitimate legal claim.