Contract clause

Return of confidential information clause

A return of materials clause says what must be handed back or destroyed when a contract or a discussion ends, by when, and how that is proved. It covers documents, samples and data, and it usually carves out copies held in routine backups that nobody can extract on request.

This is the clause most often drafted as a promise nobody can keep. Asking a business to delete every copy including backups is asking an IT team to do something its systems were built to prevent.

· Co-founder

4 min read · Published

Sample clause

the end of a due diligence process between Fernhill Consulting and Marlow Logistics, a fictional freight business in Brisbane

1. Return or Destruction. Within 14 days after receiving a written request, or within 14 days after this agreement ends, the Receiving Party must return or destroy all Confidential Information in its possession or control, including all copies, notes and analyses derived from it. 1.1 Physical samples and original documents must be returned rather than destroyed. 2. Backups. Clause 1 does not require deletion of a copy held in a routine system backup that cannot reasonably be isolated. Any such copy remains subject to clause 8 until it is deleted in the ordinary course of the Receiving Party's backup cycle, and must not be restored for any purpose other than disaster recovery. 3. Retained Copies. The Receiving Party may retain one copy of the Confidential Information where it is required to do so by law, by a regulator, or by its professional insurer, and must tell the Disclosing Party what it has kept and why. 4. Certificate. Within 5 business days of complying with clause 1, the Receiving Party must give the Disclosing Party a certificate signed by an officer confirming what was returned and what was destroyed.

Sample wording, not legal advice.

Variants

Return only

Physical material such as prototypes, samples, artwork or original signed documents, where destruction is not an acceptable outcome.

Within 10 business days after this agreement ends, the Receiving Party must return to the Disclosing Party every document, sample, prototype and item of equipment supplied to it, in the condition in which it was supplied, fair wear and tear excepted. The Receiving Party must not destroy any such item without the Disclosing Party's prior written instruction. Delivery is at the Receiving Party's cost to the address in Item 3 of the Schedule, and risk in each item passes on delivery.

Destroy with a certificate

Information shared electronically, where returning files achieves nothing because the sender already has them.

Within 14 days after this agreement ends the Receiving Party must destroy all Confidential Information in its possession or control, including all copies, extracts and derived materials, and must permanently delete it from its systems other than routine backups. Within 5 business days of doing so the Receiving Party must provide a certificate signed by one of its officers, identifying what was destroyed, the date of destruction and the method used, and confirming that no copy has been retained except as permitted by clause 3.

Retain one archival copy

Advisers, auditors and regulated businesses that are required to keep engagement records for a fixed period.

The Receiving Party may retain one copy of the Confidential Information in its archives to the extent required by law, by a regulator with jurisdiction over it, or by its professional indemnity insurer. Any retained copy must be kept in a restricted archive, must not be accessed except for the purpose that justified retaining it, and remains subject to the confidentiality obligations in clause 8 for as long as it is held, notwithstanding any earlier expiry of those obligations.

What to negotiate

The risk of leaving it out

Without the clause there is no deadline, no method and no proof, so material stays on laptops and shared drives indefinitely with nobody responsible for it. When a leak happens years later, the disclosing party finds that the other side was never obliged to return anything, and that the confidentiality obligation it relied on may have already expired.

Deletion promises that cannot be kept

A clause requiring deletion of every copy is common and rarely achievable. Backups run on cycles, disaster recovery systems replicate across sites, and email archives are retained under separate policies, often because a regulator requires it. Signing up to delete everything means signing up to a breach, which helps nobody. The honest version carves out routine backups, keeps them under the confidentiality obligation until they age out, and bars restoring them for any purpose other than disaster recovery. That gives the disclosing party a real protection instead of an unenforceable promise, and it gives the receiving party something its own technology team can actually implement.

Lawful retention and personal information

Advisers, auditors and regulated businesses often must keep engagement records for a fixed period, and insurers frequently require the same. A clause with no retention exception forces those parties either to breach the contract or to breach their own obligations. Where the material includes personal information, the Privacy Act 1988 and the Australian Privacy Principles also apply, and they include an obligation to destroy or de identify personal information that is no longer needed for a permitted purpose, subject to other legal requirements. A return of materials clause that ignores privacy leaves the receiving party balancing two sets of rules with no guidance.

Where it sits in a generated document

The document generator writes an agreement as numbered content, so the return obligation usually appears as a sub clause under confidentiality, with the backup carve out and the certificate as further sub clauses. The generated text is written from the description it is given and it never prints citations, so any deadline or statutory reference in a draft has to be checked before the document is used. Describing the backup carve out in the prompt is worth doing, because a plain request produces the unachievable version.

Documents that carry this clause

Questions people ask

Should confidential information be returned or destroyed?

Destruction is the practical default for anything shared electronically, because returning files gives the sender nothing it does not already have. Physical items such as prototypes, samples and original signed documents should be returned instead. Many clauses let the disclosing party choose in its request, which covers both situations without needing two clauses.

What about copies held in backups?

They should be carved out expressly. No standard backup system allows one counterparty's files to be pulled from a nightly snapshot, so a promise to delete everything is a promise to breach. The workable approach keeps backup copies under the confidentiality obligation until they age out, and bars restoring them for anything other than disaster recovery.

What is a destruction certificate?

A short document signed by an officer of the receiving party confirming what was destroyed, when, and by what method. It turns an unverifiable promise into something a person has put their name to, which changes how the task is handled internally. Five business days after completing the destruction is a common deadline for providing it.

Can a party keep an archival copy?

Usually yes, where the law, a regulator or a professional insurer requires it. Advisers and auditors often must keep engagement records for years. The retained copy should sit in a restricted archive, stay subject to the confidentiality obligation for as long as it is held, and be disclosed to the other party so nobody is surprised later.

Does the clause cover notes and analyses?

It should say so. Models, summaries and internal analyses built from the information are often more valuable than the source files, and a clause limited to documents supplied can miss them entirely. Receiving parties commonly ask to exclude board papers and legal advice, which is reasonable if those documents remain confidential.

How does privacy law interact with this clause?

Where the material includes personal information, the Privacy Act 1988 and the Australian Privacy Principles apply alongside the contract, including an obligation to destroy or de identify personal information no longer needed for a permitted purpose, subject to other legal requirements. A clause that ignores this leaves the receiving party reconciling two sets of rules.

Put the clause in a finished document

The button opens the document generator with a starting description already filled in. Change it to match your own agreement before you run it.

Create a document with OneCraft

Related clauses

For everything the document generator can do, see the document maker.

Step by step in the builder: Create a document with AI, then Document builder components.

Sources

Written and checked by the OneCraft team. Last checked .