germany nda geheimhaltungsvereinbarung dsgvo qes

German NDA Template 2026: BGB, DSGVO and QES Rules

Draft a German NDA in 2026 with BGB contract basics, GeschGehG safeguards, DSGVO duties, QES guidance, and key German B2B confidentiality clauses for startups.

MinjiLee MinjiLee · Product Lead September 8, 2026 11 min read

German NDA Template 2026: BGB, DSGVO and QES Rules

A Stuttgart hardware startup is about to share an unreleased product roadmap with a German manufacturing partner. The founders want a short German NDA, the supplier wants to begin work tomorrow, and the procurement team asks whether the agreement needs a Qualified Electronic Signature.

The short answer is usually no for a standard B2B confidentiality agreement. A German NDA, or Geheimhaltungsvereinbarung, is generally a contract built on ordinary German contract principles. A simple or advanced electronic signature can often show agreement when the parties are comfortable with the process. A Qualified Electronic Signature becomes important when a statutory written-form requirement applies or the parties need the legal effect associated with a handwritten signature.

The document still needs careful drafting. Under German law, confidentiality protection depends not only on a promise in the NDA but also on the company’s practical measures to identify and protect trade secrets. If the NDA covers personal data, the DSGVO, or GDPR, adds a separate privacy and security layer.

What a German NDA is meant to protect

A good NDA defines the business information that one party will disclose and limits how the recipient may use or share it. The information may include:

  • Product designs, source code, algorithms, and technical specifications
  • Pricing, margins, forecasts, and customer lists
  • Business plans, fundraising materials, and investor information
  • Manufacturing methods, test results, and quality data
  • Security architecture, credentials, and incident information
  • Personal data accessed while providing a service

The contract should distinguish genuinely confidential information from information that is already public or independently developed. Overly broad language can make a document difficult to apply and can create disputes about what the recipient was actually expected to protect.

A German B2B NDA usually works best when it explains the commercial project that requires disclosure. The purpose gives the recipient a clear boundary: use the information to evaluate or perform the project, not to develop a competing product or share it with unrelated teams.

Confidentiality is not the same as ownership. The NDA should say whether disclosures transfer no IP rights, whether a limited evaluation license is granted, and who owns work product created during the project.

BGB contract basics for confidentiality

The Bürgerliches Gesetzbuch, or BGB, provides the general foundation for German contract law. An NDA should therefore be drafted as a clear exchange of obligations: one party discloses defined information, and the other party promises to use it only for the agreed purpose, protect it, and disclose it only to permitted recipients.

German contract drafting should be attentive to:

  • Clear offer, acceptance, and authority to sign
  • Good-faith performance and reasonable cooperation
  • The scope of the recipient’s duties
  • Proportionality of contractual remedies
  • The relationship between the NDA and later project contracts
  • General terms and conditions rules if the NDA is used repeatedly

A template used across many counterparties may be treated as standard terms. Clauses that are surprising, internally inconsistent, or unreasonably one-sided can face scrutiny. The answer is not to remove protections; it is to describe the legitimate business purpose, use precise language, and avoid imposing obligations that go far beyond the information and project at issue.

The NDA should also address whether confidentiality obligations survive termination. A fixed period may be appropriate for ordinary commercial information, while information that remains a trade secret should be protected for as long as it retains that status, subject to the contract and applicable law.

GeschGehG and the need for reasonable protection measures

Germany’s Act on the Protection of Trade Secrets, known as the GeschGehG, protects business secrets against unlawful acquisition, use, and disclosure. The definition of a trade secret is important because it includes not only economic value and secrecy, but also reasonable confidentiality measures taken by the lawful holder.

That last point changes how an NDA should be used. Signing a confidentiality agreement is helpful evidence, but it is not the entire protection program.

A company should also consider:

  • Marking sensitive documents as confidential where practical
  • Restricting access to people who need the information
  • Using role-based permissions and strong authentication
  • Separating production data from evaluation materials
  • Training employees and contractors on handling rules
  • Keeping an access and disclosure record
  • Returning or securely deleting information when the project ends
  • Using confidentiality clauses in employment and supplier agreements

The NDA should match those controls. If a company sends an unmarked spreadsheet to a broad mailing list, a clause calling every piece of information a secret may be harder to defend than a focused classification and access process.

Include a process for suspected misuse, prompt notice of a security incident, cooperation in containment, and preservation of evidence. Avoid promising absolute security; require reasonable technical and organizational safeguards appropriate to the sensitivity of the information.

DSGVO duties when an NDA contains personal data

An NDA may itself contain names and contact details, but the harder issue is when the disclosed material includes personal data. Examples include customer records, employee files, user research, support tickets, identity documents, or pseudonymized datasets that can still be linked to individuals.

The DSGVO, or GDPR, may require the parties to determine:

  • Who is the controller for each processing activity
  • Whether the recipient acts as a processor or an independent controller
  • What legal basis supports the disclosure and use
  • Whether a data-processing agreement is required
  • Which categories of data subjects and data are involved
  • How long the information will be kept
  • How access, deletion, and incident requests will be handled
  • What technical and organizational measures protect the data

An NDA does not replace a GDPR data-processing agreement. If a supplier processes personal data on the startup’s behalf, the parties may need a separate Article 28 processing arrangement with required details. The NDA can still set confidentiality, security, permitted-use, and disclosure rules, but it should point to the privacy agreement rather than pretending to cover every GDPR duty.

Use data minimization. If a supplier only needs aggregated performance information, do not send identifiable customer records. If personal data must be shared, use a controlled folder, limit access, define deletion, and document the purpose.

QES versus simple and advanced electronic signatures

The eIDAS Regulation recognizes electronic signatures at different levels. A simple electronic signature can be a name, symbol, or process associated with a person’s intention to sign. An advanced electronic signature provides stronger identity and integrity connections. A Qualified Electronic Signature is created through a qualified trust-service framework and has the equivalent legal effect of a handwritten signature under eIDAS.

For an ordinary German NDA, German law does not generally require a QES merely because the document is confidential. If the parties agree on the terms, the signer has authority, and the signing method reliably shows identity and intent, a simple or advanced signature is often sufficient for the agreement.

QES becomes the safer or necessary choice when:

  • A statute requires written form and electronic form is being used instead of paper
  • The document is a formal instrument with a handwritten-signature equivalent requirement
  • A customer, procurement policy, bank, or regulated counterparty mandates QES
  • The parties want the strongest standardized identity and integrity evidence
  • The agreement is part of a broader transaction with formal execution rules

A QES does not make bad drafting good, and a simple signature does not automatically make a contract invalid. Choose the signature level based on the legal form, risk, counterparty, and evidence needed.

For most startup NDAs, the better investment is a complete final document, a verified signer, a controlled invitation, and a preserved audit record. Upgrade to QES when the document or counterparty requires it.

Key clauses for a German B2B NDA

A useful German NDA template should cover the following.

Purpose and parties: Identify the disclosing party, recipient, affiliates, project, and authorized signatories. State whether the NDA is mutual or one-way.

Definition of confidential information: Include oral, written, visual, electronic, and derived information, but exclude information that is public, already known without restriction, independently developed, or lawfully received from a third party.

Permitted purpose: Limit use to a named evaluation, transaction, service, or project. Prohibit use for competitive development or any unrelated commercial purpose.

Need-to-know disclosures: Allow disclosure to employees, professional advisers, affiliates, and subcontractors only when necessary and subject to confidentiality duties at least as protective as the NDA.

Security and incident notice: Require reasonable safeguards, access controls, and prompt notice of unauthorized access, loss, or disclosure.

Compelled disclosure and protected reporting: Allow legally required disclosure to the extent necessary, with prior notice where legally permitted. Preserve rights that cannot lawfully be waived, including protected reporting and employee representation rights.

Return or deletion: Set a process for returning or deleting information, with a narrow exception for legally required archives or secure backup systems.

Term and survival: State the contract term and how long obligations survive. Consider continuing protection for information that remains a trade secret.

No license and no warranty: Clarify ownership, no implied IP license, and the limits of any information provided for evaluation.

Remedies and liability: Draft proportionate injunctive-relief, damages, and liability language that fits German law and the commercial relationship.

Law, forum, and language: Choose governing law, venue, and the controlling language for bilingual documents. Check whether the chosen court clause is effective for the parties and transaction.

A practical signing and evidence workflow

Before disclosure, label the information, confirm the purpose, approve the recipient list, and select the right contract version. If personal data is involved, complete the privacy assessment and any required data-processing agreement before uploading files.

At signing, verify the legal entity and signer authority. Use a signing method that creates a clear link between the signer and the final NDA. For an ordinary B2B NDA, a simple or advanced electronic signature may be enough; for a formal written-form situation, use QES or follow the required wet-ink and notarization process.

After signing, keep:

  • The final NDA and every schedule
  • The signing invitation and identity evidence
  • The time and completion record
  • The document version and integrity record
  • Any later amendments or renewals
  • The disclosure register for particularly sensitive materials
  • Deletion or return confirmations at the end of the project

AiDocX can help a legal or operations team generate a first NDA draft, review it for missing purpose and disclosure clauses, and send it for tracked e-signature. It should sit inside a broader German legal and privacy review, especially where trade secrets or personal data are involved.

This is general information, not legal advice. A German lawyer and, where relevant, a data-protection professional should review a specific NDA, processing arrangement, or formal signature requirement.

A well-drafted Geheimhaltungsvereinbarung is not meant to slow down a partnership. It creates a clear boundary for sharing information, supports the protection measures required in practice, and gives both sides a record of what they agreed. If your team needs a manageable starting point, use an approved AiDocX template, tailor the purpose and data terms, and obtain local review before sending sensitive material.

Ready to automate your documents with AI?

Start free with AiDocX — AI contract drafting, meeting minutes, consultation notes, e-signatures, and more in one platform.

Get Started Free