Consumer

I Signed an NDA and Might Have Broken It — What Actually Happens Now

Adv. Urvashi Goswami
Adv. Urvashi Goswami
|Updated on: 29 July 2026|10 min read
ShareLinkedInXWhatsAppFacebook
I Signed an NDA and Might Have Broken It — What Actually Happens Now

Key Highlights

  • NDA breach is a civil contract issue first — criminal exposure only kicks in under specific conditions like Section 72A of the IT Act
  • The company suing you needs to prove actual loss under Section 73 of the Indian Contract Act — suspicion or a slip of the tongue isn't enough on its own
  • What you disclosed matters more than that you disclosed something — a passing comment and a client database are treated very differently
  • Most companies send a cease-and-desist and try to negotiate before they sue, because Indian commercial litigation is slow and expensive relative to what small breaches are worth
  • You have a real window — usually the NDA's notice or cure clause — to fix this before it escalates
  • Publicly available information, protected whistleblowing, and disclosures made under a court order don't count as breaches, even if the NDA doesn't say so explicitly
  • Document what you said, to whom, and when — before you talk to anyone else about it, including a lawyer

It's 11 p.m. and you're re-reading a WhatsApp message you sent to a friend three days ago. You mentioned a client name. Maybe a number. Maybe you just said "we're about to close a deal with X" at a dinner where someone from a rival firm happened to be sitting two seats away. You signed an NDA — non-disclosure agreement, the contract that says you won't share certain information — when you joined this project, and now you're doing the math on how much trouble you're in. (You've probably already typed "NDA breach lawsuit India" into Google once tonight — no judgment, everyone does.)

Here's the actual answer, not the anxious 2 a.m. version. Usually, nothing happens. If something does happen, it starts with a letter, not a lawsuit. Indian companies rarely sue over an NDA breach unless they can point to a real, provable loss — because Section 73 of the Indian Contract Act, 1872 requires them to prove actual damage, not just the fact that you talked. Add to that the practical reality that contract disputes worth more than ₹3 lakh have to go through a Commercial Court, where cases commonly run two to five years even on the fast track — and most companies simply won't start that clock unless the number at stake justifies it. A stray comment with no financial consequence is legally very different from handing a competitor your former employer's client list. That distinction — what you disclosed, not just that you disclosed it — is the single biggest factor in what happens to you next.

What Actually Counts as "Breaking" an NDA

An NDA breach isn't a single, obvious act. It's any disclosure of information the agreement defines as confidential, to a person or in a manner the agreement doesn't permit — and that's a broader net than most people realise, because it also catches things that don't feel like betrayal.

Telling your spouse the salary structure of your last employer can technically be a breach if the NDA's definition of "confidential information" is broad enough. So can leaving a laptop open with a client deck visible, or mentioning a deal is "in progress" at a networking event. Intent matters for how a company reacts, but it doesn't erase the breach itself — an accidental slip and a deliberate leak to a competitor are both breaches, they just carry very different consequences.

What matters more than intent is scope: did the information actually reach someone who could use it against the company, and can that use be traced back to you? A comment overheard by nobody who matters is functionally different from a comment overheard by the one person who mattered.


The Fork in the Road: What Kind of Information Was It?

This is the question that decides almost everything downstream. Everything else follows from this.

Low-stakes disclosures — a general mention that a deal exists, an offhand comment about company size or culture, something that was going to become public within weeks anyway — rarely trigger any formal action. There's no financial loss to point to, so there's nothing to sue over even if someone wanted to.

Mid-stakes disclosures — specific deal terms, unreleased product features, internal strategy, salary bands — are where you start seeing cease-and-desist letters and, occasionally, negotiated settlements or forced resignations if you're an employee. The company has to weigh the cost of pursuing you against the actual damage done, and for most mid-stakes leaks, that math doesn't favour litigation.

High-stakes disclosures — client databases, source code, trade secrets, anything handed directly to a competitor with clear intent — are where injunctions and real litigation happen. The Delhi High Court's 1995 ruling in Burlington Home Shopping Pvt. Ltd. v. Rajnish Chibber is instructive here: a former employee took a compiled customer database to start a competing business, and the court granted an injunction because the database represented years of deliberate, provable investment. That's the kind of disclosure companies actually go to court over.

Notice what's missing from that middle category, though — general knowledge, skills, and relationships you built while working somewhere don't count as confidential information just because an NDA exists. The Delhi High Court made this explicit in American Express Bank Ltd. v. Priya Puri (2006), ruling against the bank when it tried to stop a former wealth management employee from serving clients at her new firm. Customer names, phone numbers, and the personal rapport she'd built with them were not trade secrets — they were public-domain information and her own professional relationships, and Section 27 of the Contract Act protects an employee's right to change jobs and use general know-how gained on the way. If what you disclosed falls into that category — general experience, not a proprietary system or dataset — you're on much firmer ground than you might think.


So What Are the Realistic Odds You Actually Get Sued?

Lower than the NDA's dramatic language suggests, for a simple reason: litigation in India is slow and expensive relative to what most breaches are worth. Courts move slowly. Companies know it, and they price that in.

Contract disputes above ₹3 lakh in value can go to a Commercial Court under the Commercial Courts Act, 2015 — a system built specifically to move faster than ordinary civil courts, with mandatory pre-institution mediation and stricter timelines. Even so, commercial contract suits commonly run somewhere in the range of two to five years from filing to resolution, and that's the optimistic end; broader civil litigation in India averages considerably longer. For a company to commit two-plus years and real legal spend, the loss has to be worth chasing — and under Section 73, they have to actually prove that loss occurred, not just that a breach happened. A hypothetical or reputational "what if they'd used it" argument generally doesn't clear that bar on its own.

This is why the more common playbook — Indian or otherwise — looks like this: internal investigation, then a cease-and-desist letter, then a negotiation (a settlement, a quiet resignation, an agreement that you won't repeat the disclosure), and only then, if at all, a lawsuit. Litigation is usually the last resort a company reaches for, not the first, because pursuing you costs more time and money than most disclosures actually cost them.

None of this means you're safe if what you disclosed was genuinely high-stakes — client databases, trade secrets, source code. In that bracket, companies do sue, and they sue fast, often seeking an injunction (a court order stopping further use or disclosure) within days rather than waiting years for a full trial. The Burlington case above is exactly that scenario. The odds shift sharply once the disclosure is provably valuable to a competitor.


When an NDA Breach Becomes a Criminal Matter

Most NDA breaches are civil matters — contract disputes, not crimes. But there's one specific criminal provision worth knowing about if personal or customer data was involved: Section 72A of the Information Technology Act, 2000, punishes disclosure of personal information obtained under a lawful contract, done with intent to cause wrongful loss or gain, with imprisonment up to three years, a fine up to ₹5 lakh, or both.

This isn't a catch-all for any NDA breach — it applies specifically to personal information (customer data, employee records, that kind of material) disclosed in breach of a contract, and it requires intent or knowledge that the disclosure would cause harm. A general business-strategy leak doesn't fall under it. But if what left your hands was a spreadsheet of customer phone numbers or health records, this is the provision that changes the conversation from "will I get a letter from a lawyer" to "should I be worried about a criminal complaint" — not every leak carries that weight, and the distinction matters for how seriously you treat the next 24 hours.


What to Do in the Next 24 Hours

If you're reading this because it already happened, here's the practical sequence, in order.

Write down exactly what you disclosed, to whom, and when. Do this before you talk to anyone else about it, including friends or colleagues. Your own accurate memory, recorded now, is worth more than a reconstructed version six weeks from now when a lawyer asks you for details.

Check if it's retractable. A message you can delete before it's screenshotted, a comment you can walk back in the same conversation, information that hadn't actually reached anyone who could act on it — these change your position meaningfully.

Pull out the actual NDA and find the notice or cure clause. Many NDAs — especially employment and vendor agreements — include a clause requiring the other party to notify you and give you a chance to fix or stop the issue before pursuing any remedy. If yours has one, that's your real window, and it's often longer than the panic makes it feel.

Decide whether proactive disclosure makes sense. This isn't always the right move, and it depends heavily on what was disclosed and to whom. For low-stakes slips, staying quiet and simply not repeating the mistake is often the more sensible path. For anything that could plausibly cause traceable, provable harm, getting ahead of it — informing the counterparty before they find out independently — can meaningfully change how they respond, since companies generally treat voluntary disclosure more favourably than discovery.

Get a lawyer's letter before you sign anything. If the company sends a cease-and-desist or asks you to sign an acknowledgment, don't respond alone. Even a short consultation with an advocate before you reply can prevent you from admitting more than the facts actually support.


Exceptions That Mean You Might Not Be Liable at All

Not every disclosure of "confidential" information is a breach, regardless of what the NDA's language implies. Three situations generally void liability even under a strictly worded agreement:

The information was already public. If it was in a press release, a public filing, or reasonably discoverable through legitimate means before you disclosed it, most NDAs (and courts) won't treat repeating it as a breach — the confidentiality obligation attaches to secrecy, not to the words themselves.

You were legally required to disclose it. Responding to a subpoena, a court order, or a statutory regulator's demand overrides an NDA's confidentiality terms. Companies cannot contract their way out of your legal obligation to comply with a lawful order, though good practice is usually to notify them before you comply, not after.

Whistleblower protection applies. Disclosures made in good faith to report illegal conduct — fraud, safety violations, regulatory breaches — carry statutory protection in specific contexts (the Companies Act's whistle blower mechanisms, sectoral regulations) that an NDA cannot override, though the scope of this protection depends heavily on the specific law and forum involved, and isn't a blanket shield for any disclosure framed as a public interest concern.


So What Does All This Actually Mean for You?

If what you disclosed was minor and the other side hasn't contacted you yet, the realistic odds are that nothing further happens — most breaches never generate a formal response, because pursuing them isn't worth it. Got a cease-and-desist? That's the company signalling it wants this resolved without litigation; respond through an advocate, calmly and promptly, and it usually closes there. If what left your hands was genuinely valuable — a client database, proprietary code, trade secrets handed to a competitor — you're in different territory, and legal advice now beats legal advice after a lawsuit lands.

Courts do take different views depending on how an NDA defines "confidential information" and how directly the disclosure caused harm, so don't treat this as settled everywhere. Read your specific NDA's notice clause, be honest about which bracket your disclosure falls into, and act inside the window the contract actually gives you.

Frequently Asked Questions

Common questions about Consumer

Adv. Urvashi Goswami

About the Author

Adv. Urvashi Goswami

Verified advocate on LegalKonnect.

All articles are reviewed for legal accuracy before publication.

Meet the author

Related Articles