- What a commercial-in-confidence disclaimer can and cannot do
- The confidentiality statement
- The stated purpose of disclosure
- Restrictions on use and disclosure
- Instructions if received in error
- Intellectual property ownership
- Reservation of rights and no waiver
- Exceptions and carve-outs
- Optional clauses worth considering
- How an Artificer Legal lawyer reviews your confidentiality protections
- The purpose clause is where a disclaimer earns its keep
You have just finished a proposal that contains your pricing, your margins and the way you would actually deliver the work. Before you send it, you add the words "Commercial in Confidence" to the footer, the same way you have on every quote, pitch deck and tender response you have sent this year. You are relying on that label to stop the document from being forwarded to a competitor.
The label can help, but only if you understand what it is. A commercial-in-confidence disclaimer is a one-way notice. It tells the recipient the information is confidential and limits what they may do with it, but it does not create a contract the way a signed non-disclosure agreement does, and it does not, on its own, make information confidential in the eyes of an Australian court. What it does is support your position later, by creating and recording the circumstances in which the information was handed over.
What a commercial-in-confidence disclaimer can and cannot do
In Australia, confidential information is protected through the equitable doctrine of breach of confidence. The elements of that doctrine were stated by Gummow J in Smith Kline & French Laboratories (Australia) Ltd v Secretary, Department of Community Services and Health (1990) 22 FCR 73, and they remain the framework courts apply today, as the Federal Court confirmed in Matthews v Clifton [2014] FCA 415.
For a claim to succeed, you must be able to:
- Identify the information specifically: you cannot protect "everything in the document" in global terms. You need to point to the particular pricing, methodology or customer data that was misused.
- Show the information had the necessary quality of confidence: it must not be common or public knowledge. Labelling public information as confidential does not make it so.
- Show it was received in circumstances importing an obligation of confidence: this is where the disclaimer does its work. A clear notice on the document is evidence that the recipient knew, or should have known, the information was provided in confidence.
- Show actual or threatened misuse: the recipient must have used or threatened to use the information without authority.
The courts also look at how the information was treated within your own business. In Del Casale v Artedomus (Aust) Pty Ltd [2007] NSWCA 172, the New South Wales Court of Appeal identified the factors that separate protectable confidential information from an employee's general skill and knowledge: how widely the information is known inside and outside the business, how valuable it is to competitors, how much effort went into developing it, and how hard it is to acquire or duplicate. A disclaimer is one layer of that picture. It does not replace the other layers.
That is why the drafting matters. A commercial-in-confidence disclaimer is a short document, but each of the clauses below has a job to do, and the way you draft each one affects whether the notice holds up when it counts.
The confidentiality statement
The opening clause states plainly that the document contains confidential information and is provided in confidence. This is the clause that does the work of the third element above, because it is what puts the recipient on notice.
Drafting minimums for this clause:
- Use plain words like "commercial in confidence", "confidential and proprietary" or "provided in confidence".
- Place the statement where the recipient will actually see it, on the document itself, not only in an email footer.
- Name the information it covers, or describe it by category, such as "pricing, margins and delivery methodology".
The trap is overreach. If the clause claims everything in the document is confidential, including material that is publicly available or that the recipient already knew, a court may treat the whole notice as self-serving and give it less weight. Scope the statement to what is genuinely yours.
The stated purpose of disclosure
This clause says why the information is being shared, for example "solely for the purpose of evaluating this proposal" or "to assess this tender response". It is the clause that most often makes the difference between a disclaimer that works and one that does not, because the obligation of confidence is an obligation about use.
Variants you will see:
- Broad purpose wording: for example, "for the purpose of your business dealings with us". This gives the recipient room to argue that almost any use fell within the purpose.
- No purpose at all: the recipient can then say they did not know what limits applied.
- A narrow, specific purpose: this is what you want. It defines the boundary of acceptable use, and a use outside that boundary is easier to characterise as a breach.
If you are comfortable allowing the recipient to share the document with their advisers, say so in this clause and require those advisers to keep it confidential too.
Restrictions on use and disclosure
This clause converts the purpose into concrete prohibitions. Typical restrictions include:
- Do not copy or forward the document or its attachments.
- Do not disclose it to third parties, except approved advisers.
- Do not use it for any purpose other than the stated purpose.
- Do not use it to compete with the disclosing business.
The drafting choice that matters most here is consistency with the permitted purpose. If the purpose clause says the recipient may share the document with their advisers, but the restriction clause says "no disclosure to anyone", the document contradicts itself and a court has to guess which instruction the recipient was meant to follow.
The trap is boilerplate that does not match how your business actually operates. If you routinely email the same quote to four prospects, an absolute "do not disclose" clause is unrealistic, and an opposing party can point to your own conduct to argue the information was not treated as confidential. Draft the restrictions you are prepared to live by, then live by them.
Instructions if received in error
This clause tells the recipient what to do if the document reaches them by mistake: notify the sender, delete the email and attachments, and do not copy, disclose or act on the information.
Practical drafting minimums:
- Give one clear action, such as "notify the sender immediately".
- Say what must happen to the material, such as "delete the email and any attachments".
- Say what the recipient must not do while they wait, such as "do not use or disclose the information".
This clause is most valuable in email footers, where misdirected messages are common. It will not repair a deliberate leak, but it gives you a documented basis to act quickly when a mistake happens, and it is cheap insurance compared with the cost of chasing information that has already circulated.
Intellectual property ownership
If the document contains your templates, designs, written content, software specifications or product plans, this clause states that you retain ownership and that no rights are granted by the disclosure.
Two legal points sit behind this clause. First, copyright in original works subsists automatically under s 32 of the Copyright Act 1968 (Cth), so you do not need to register anything to own the copyright in your proposal. Second, the clause is really an anti-licence: it makes clear that handing over the document does not give the recipient permission to use your intellectual property.
The trap is treating this clause as a substitute for a real IP assignment. If you are creating work for a client, ownership of the deliverables should be dealt with in the contract, not in a footer. The disclaimer protects your material from misuse; it does not transfer rights, and it cannot fix a contract that is silent on who owns the finished work.
Reservation of rights and no waiver
This clause says you reserve all of your legal rights and that the disclosure does not waive any of them. It is short, but it serves a real purpose: it counters any argument that silence or delay, after you learn of a leak, should be treated as consent or as acceptance of the situation.
A drafting point worth noting: this clause only helps if your conduct is consistent with it. If you discover a breach and do nothing for months, a reservation of rights clause will not stop a court from drawing inferences from your inaction. Act promptly, and the clause supports you; act slowly, and it reads as boilerplate.
Exceptions and carve-outs
A credible disclaimer accepts that some disclosures are unavoidable. Common carve-outs permit disclosure:
- To professional advisers who are themselves bound by confidentiality.
- If required by law or a court order, often with a requirement to notify you first where possible.
- Where the information becomes public through no fault of the recipient.
The drafting choice is how wide to draw the carve-outs. Advisers' carve-outs are routine and make the document workable in practice. A "required by law" carve-out is sensible because no notice can override a statutory or court-ordered disclosure obligation. The trap is a public-domain carve-out drafted so broadly that it swallows the protection, for example "once the information is published anywhere, this notice ceases to apply". Keep the carve-out tied to disclosure through no fault of the recipient.
Optional clauses worth considering
Depending on the situation, you may add:
- Return or destruction of materials: ask the recipient to return or destroy the document at the end of the evaluation, useful in tenders and pitch processes.
- Duration of the obligation: state how long the confidentiality obligation lasts, which matters where information remains sensitive long after the deal.
- Notification of unauthorised disclosure: require the recipient to tell you if they become aware of a leak, which helps you respond quickly.
- Mutual confidentiality: include this where both sides are sharing information, so the notice protects you and records the recipient's own disclosures.
- Governing law and jurisdiction: worth adding where the recipient is based in another state or overseas.
How an Artificer Legal lawyer reviews your confidentiality protections
The first thing a lawyer at Artificer Legal would do is ask what the disclaimer is protecting and who it is being sent to, because that determines whether a notice is enough at all. For a quote sent to a prospect you have never met, a well-drafted disclaimer may be a sensible first layer. For a pitch to a potential investor, or for detailed technical information shared during due diligence, the answer is usually that you need a signed non-disclosure agreement or a confidentiality clause in the contract before the information goes out.
Where you already have a disclaimer, we would review it clause by clause against the elements of breach of confidence: whether the information is identified specifically enough, whether the purpose is stated narrowly, and whether the restrictions match the way you actually operate. We would also check the boundaries, because a disclaimer cannot protect public information, cannot override an obligation to disclose required by law, and cannot deal with personal information. If the document contains customer data or employee records, the Privacy Act 1988 (Cth) applies separately, and many small businesses fall within the small business exemption in s 6D of that Act (an annual turnover of $3 million or less), but if the Act does apply to you, a "commercial in confidence" label does not displace your obligations under the Australian Privacy Principles, which include maintaining a privacy policy under APP 1.
Finally, we would look at where the real protection should sit. For most businesses, the confidentiality clause inside your services agreement, contractor agreement or non-disclosure agreement is worth more than any footer, because it binds the other party by contract and gives you clear remedies. The disclaimer then plays its proper role: a visible, consistent marker on every document that leaves your business.
The purpose clause is where a disclaimer earns its keep
Every clause in this article has a role, but if one drafting choice decides whether a commercial-in-confidence disclaimer holds up, it is the stated purpose of disclosure. The equitable obligation of confidence is an obligation about use, and the purpose clause is what defines the boundary of acceptable use. A disclaimer that says "this is confidential" without saying what it may be used for leaves the most important question unanswered, and courts are left to infer the limits from conduct that may be ambiguous. A disclaimer that names a narrow, specific purpose gives you a clear line to point to when information is used outside it.
In short, a commercial-in-confidence disclaimer is a notice, not a contract. Use it to put recipients on notice, state a specific purpose, restrict use in terms you will actually enforce, and mark your documents consistently. Keep it realistic about advisers, legal obligations and public information, and remember that personal information is regulated separately under the Privacy Act. For anything genuinely valuable, pair the disclaimer with a signed agreement, and if you are unsure whether the label is doing enough, have a lawyer review it before you rely on it.