Confidentiality Clauses in Employment Contracts in India

Confidentiality clauses survive in India when non-competes fail. What HR should draft post the Varun Tyagi ruling and DPDP Act, with clause-by-clause fixes.
Confidentiality Clauses in Employment Contracts in India
Kumari Shreya
Thursday September 24, 2026
12 min Read

Share

A confidentiality clause is the one restrictive covenant in an Indian employment contract that reliably holds up in court. Non-competes mostly collapse. Broad post-employment restraints get struck down. But a well-drafted obligation to protect trade secrets and proprietary information survives, both during employment and after it ends.

That gap between what employers write and what courts enforce is where most HR teams lose. A clause copied from an old template, stretched to double as a non-compete, or silent on employee data protection creates a false sense of security rather than real protection.

Indian courts have spent over a century narrowing what an employer can restrict once a person walks out. The Delhi High Court reinforced that line again in 2025, and the Digital Personal Data Protection Act has added a layer that most clauses drafted before 2024 never accounted for. HR owns the contract, the onboarding, and the exit process where all of this plays out, so the drafting choices sit squarely on the people function.

Why Confidentiality Clauses Hold Up When Non-Competes Don’t

The core of Indian confidentiality law lives in one sentence. Section 27 of the Indian Contract Act, 1872 states that any agreement restraining a person from exercising a lawful profession, trade, or business is void to that extent, and Indian courts read it strictly. Unlike England or the United States, Section 27 offers no reasonableness test that can rescue an otherwise void restraint. A post-employment non-compete is void whether it runs six months or three years, one city or the whole country.

Confidentiality is treated differently, and the reason matters for how HR drafts it. A clause protecting trade secrets and proprietary information isn’t seen as a restraint on trade at all. It restricts what a former employee may use and disclose, not where they may work. Bombay High Court precedent has held that a restraint on the use of trade secrets during or after employment does not amount to a restraint of trade under Section 27, which is why this covenant survives when a non-compete sitting next to it in the same contract does not.

The distinction that carries the most weight is timing.

During Employment Versus After It Ends

Restrictions that operate while a person is still on the payroll get wide latitude. In Niranjan Shankar Golikari v. Century Spinning & Manufacturing Co., the Supreme Court recognised that a negative covenant requiring an employee to serve one employer exclusively during the contract term ordinarily does not amount to a restraint of trade. An employer can lawfully stop a current employee from moonlighting for a competitor or sharing internal documents. That’s a live contractual relationship, and courts respect it.

Everything changes at exit. A covenant that operated cleanly during employment becomes a potential control over a person’s future livelihood the moment they leave, and that’s what triggers Section 27. The same words can be enforceable on Monday and void on Friday, depending only on whether the employment still exists. HR teams that draft a single blanket “confidentiality and non-compete” clause covering both periods usually end up with something that fails after the person joins a rival.

The Confidentiality-as-Non-Compete Trap

The most common drafting error is dressing up a non-compete as a confidentiality obligation and hoping a court won’t notice. Courts notice. In American Express Bank Ltd. v. Ms. Priya Malik, the Delhi High Court held that an employee’s right to seek better employment cannot be curbed merely because the employee holds confidential data. The judgment was blunt that confidentiality cannot be used as a garb to perpetuate forced employment, and a restriction of that kind is hit by Section 27.

What this means in practice: a clause saying a departing employee “shall not join any competitor because they possess confidential information” is not a confidentiality clause. It’s a non-compete wearing a costume, and it’s void. A genuine confidentiality clause restricts the disclosure and misuse of specific protected information. It never restricts employment itself.

What the Varun Tyagi Ruling Changed for HR

The clearest recent signal came from the Delhi High Court in June 2025. In Varun Tyagi v. Daffodil Software Private Limited, the court quashed an injunction that had stopped a former employee from joining Digital India Corporation, a business associate of his old employer. Daffodil had leaned on a clause barring Tyagi from engaging with any business associate for three years after leaving. The court held the post-employment restraint void under Section 27 and found no proprietary information belonging to Daffodil that actually needed protecting.

The judgment reaffirmed that the extent or duration of a post-employment restraint is irrelevant to its validity, so even a narrow or short restriction is void under Section 27 of the Indian Contract Act unless it fits the goodwill exception. It also confirmed that negative covenants survive after termination only to the degree they protect genuine confidential information or restrain the soliciting of clients the employee personally dealt with.

The practical takeaway is uncomfortable but useful. If a contract’s post-exit protection rests on a non-compete, the protection is fiction. Real protection comes from a tightly drafted confidentiality clause, an IP assignment clause, and a narrow non-solicitation covenant. Those do the work employers wrongly expect a non-compete to do, the same reasoning TPB has covered on whether non-compete clauses are valid in India.

The Anatomy of a Confidentiality Clause That Survives

A confidentiality clause earns its keep through precision, not length. Vague clauses that call everything confidential tend to protect nothing, because a court can’t tell what the employer genuinely needed to guard. Each component below carries its own drafting risk, and skipping any one of them weakens the whole clause.

ElementWhat It Should SpecifyCommon Failure
Definition of confidential informationNamed categories: source code, client lists, pricing models, unpublished financials, algorithms“All information” catch-alls that courts read down
Scope of obligationNon-use and non-disclosure, during and after employmentSilence on the post-employment period
Carve-outsPublic-domain information, prior knowledge, information disclosed by lawNo exceptions, making the clause look punitive
Return and deletionObligation to return or delete on exit, across devices and cloudIgnoring personal devices and shadow copies
Survival periodA defined term the obligation continues after exitPerpetual obligations that invite challenge
Permitted disclosureDisclosure required by court order, regulator, or statuteBlocking lawful whistleblowing or statutory reporting

One nuance worth flagging. A confidentiality obligation that blocks an employee from making a disclosure they’re legally required to make to a court, a regulator, or under a statute like the POSH Act, 2013, is unenforceable to that extent and can expose the employer. Build the carve-out in rather than papering over it.

Confidential Information Is Not the Same as General Skill

Courts draw a hard line between an employer’s protectable secrets and the general knowledge and skill an employee acquires on the job. A software engineer at Infosys or a product manager at Razorpay carries away expertise, judgment, and a professional network of their own. A confidentiality clause cannot reach that. It reaches specific, identifiable proprietary information: the client contract terms, the unreleased pricing model, the proprietary codebase.

This is why over-broad clauses backfire. When an employer tries to classify an employee’s entire accumulated capability as confidential, a court reads the clause as a disguised restraint on the person’s livelihood and declines to enforce it. Narrow drafting protects more.

Confidentiality Clauses Now Sit Alongside the DPDP Act

Confidentiality drafting can no longer stop at trade secrets, and this is the shift most pre-2024 templates missed. When employees handle customer or colleague personal data, a second body of law applies. The Digital Personal Data Protection Act, 2023, with its rules notified by MeitY on 13 November 2025, makes the employer a Data Fiduciary and every employee a Data Principal, on a phased timeline with substantive obligations landing by May 2027.

The Act actually helps employers on the trade-secret front. It recognises the maintenance of confidentiality of trade secrets, intellectual property, and classified information, along with the prevention of corporate espionage, as a legitimate use for which employee consent isn’t separately required. So an employer can process employee data to protect its own secrets without treating that as a fresh consent event.

The harder part is the other direction. A clause that only protects the company’s secrets, and says nothing about how the employee must handle personal data they touch, leaves a compliance gap. The employer stays liable as Data Fiduciary regardless of what an individual employee does, and any contract term trying to shunt that statutory liability onto the employee doesn’t hold. The penalties give this teeth: breaches can draw up to ₹250 crore, with failure to notify carrying up to ₹200 crore per incident.

What HR Should Add to Data-Handling Clauses

The confidentiality section and the data-protection obligations increasingly need to be read together, though they protect different things. One guards the company’s proprietary information. The other governs personal data the company is accountable for under statute. A modern employment contract should carry both, clearly separated, with a few practical additions:

  • A data-handling obligation requiring employees to process personal data only for defined work purposes, mirroring the purpose-limitation principle the DPDP framework runs on.
  • A breach-reporting duty requiring employees to flag any suspected personal-data breach internally without delay, so the employer can meet its notification timeline to the Data Protection Board.
  • A return-and-deletion obligation covering personal data as well as proprietary files, across company and personal devices at exit.
  • A cross-reference to the organisation’s DPDP policy so the contract and the standing policy don’t drift apart.

Teams building this out will find TPB’s guide on what every HR leader should know about the DPDP Act a useful companion, since the clause and the wider compliance programme have to move together.

Where Confidentiality Fits in the Contract Lifecycle

A confidentiality clause is only as strong as the process around it, and HR controls that process end to end. A perfectly drafted clause signed once and never revisited protects far less than a modest clause reinforced at onboarding, during employment, and at exit. Enforcement almost always turns on evidence that the employee knew what was confidential and had access to it, which is an HR-record question as much as a legal one.

At onboarding, the obligation should be signed alongside the main contract, with the categories of protected information spelt out for that role rather than left generic. A backend engineer and a finance analyst hold different secrets, and the paperwork should reflect that.

During employment, access logs and document-classification labels build the evidentiary trail an employer needs if a dispute arises. At exit, the return-and-deletion obligation gets activated in the offboarding checklist, ideally tied to the process that manages handover and the notice period clauses in the employment contract.

The Wipro case is a caution on the exit end. In 2025, the Delhi High Court awarded ₹2 lakh in damages against Wipro over a termination letter it found defamatory, a reminder that how an employer handles exit paperwork carries its own legal weight.

In the End…

Most confidentiality clauses fail one of the same checks. A clause either protects information by naming specific categories or waves at “all confidential information” and hopes. It either steers clear of restricting where a person can work after leaving or drifts toward Section 27 and void status. And it either addresses how employees handle personal data under the DPDP framework or stops at trade secrets as if the last two years didn’t happen.

A clause that names its categories, stays clear of employment restraints, builds in lawful-disclosure carve-outs, and carries a data-handling obligation is doing real work. One that fails any of those needs a rewrite before the next hire signs it, not after a dispute forces the issue.

The other move worth making this quarter: separate the confidentiality clause, the IP assignment clause, and the non-solicitation clause into three distinct provisions instead of one tangled paragraph. Courts enforce clean, specific covenants and strike down blurry catch-alls, so the drafting discipline is the protection. Book an hour with legal counsel, bring the template, and fix the clause everyone copies but nobody has checked.


FAQs


Are confidentiality clauses enforceable in India?

Yes. Unlike post-employment non-competes, which Section 27 of the Indian Contract Act, 1872 renders void, a confidentiality clause restricts what a former employee may use or disclose rather than where they may work. Because it isn’t treated as a restraint of trade, it can survive both during employment and after it ends when drafted to protect specific proprietary information.

What’s the difference between a confidentiality clause and a non-compete in India?

A confidentiality clause limits the disclosure and misuse of specific protected information. A non-compete restricts where a person can work after leaving, which triggers Section 27 and is void regardless of duration or geography. A clause barring an employee from joining a competitor because they hold confidential data is a disguised non-compete, and it’s unenforceable.

What did the Varun Tyagi v. Daffodil Software ruling decide?

In June 2025 the Delhi High Court quashed an injunction stopping Varun Tyagi from joining Digital India Corporation, a business associate of his former employer. It held the post-employment restraint void under Section 27, confirmed that the duration or extent of such a restraint is irrelevant to its validity, and found no genuine confidential information that needed protecting.

How does the DPDP Act affect confidentiality clauses in employment contracts?

The Digital Personal Data Protection Act, 2023 makes the employer a Data Fiduciary and each employee a Data Principal. Confidentiality drafting can no longer stop at trade secrets; contracts should add data-handling, breach-reporting, and return-and-deletion obligations for personal data. Statutory liability stays with the employer, and breaches can draw penalties up to ₹250 crore.

Can a confidentiality clause stop an employee from joining a competitor?

No. In American Express Bank Ltd. v. Ms. Priya Malik, the Delhi High Court held that an employee’s right to seek better employment can’t be curbed merely because they hold confidential data, and that confidentiality can’t be used as a garb to perpetuate forced employment. Such a restriction is hit by Section 27.

Author
//
Kumari Shreya
Content Specialist Shreya delights in conveying her ideas and thoughts through her words. She enjoys exploring the different sides of the HR world and how the industry’s impact on the Indian population is increasing by the day. When not immersed in writing or researching for her writing, you can find her passionately discussing her favorite stories and learning more about the history of the world.
Show More
latest news

trending

Subscribe To Our Newsletter

Never miss a story

By submitting your information, you will receive newsletters and promotional content and agree to our Terms of Use and Privacy Policy. You may unsubscribe at any time.

More of this topic

Subscribe To Our Newsletter

Never miss a story

By submitting your information, you will receive newsletters and promotional content and agree to our Terms of Use and Privacy Policy. You may unsubscribe at any time.