Skip links

HOW MUCH SHOULD YOU TELL AN INVESTOR? THE NIGERIAN BUSINESS OWNER’S GUIDE TO TRANSPARENCY AND CONFIDENTIALITY

Opening your books to an investor is necessary. Handing over your trade secrets, customer lists, pricing strategy, and proprietary processes along with them is not. Nigerian law gives you a framework for drawing that line, but most businesses never use it.

 

A Nigerian fintech founder is in discussions with a venture capital firm. The investor wants to conduct due diligence before committing capital. They ask for financial records, reasonable. They ask for the cap table, reasonable. They ask for details of the company’s proprietary algorithm and customer acquisition model, the founder hesitates. The hesitation is correct, however, the response to it, in many cases, is not.

Too many Nigerian founders and business owners respond to investor requests by providing either everything or nothing. The founder who shares everything; every customer list, every operational process, every internal projection, without any contractual protection hands a sophisticated counterparty a complete picture of the business with no legal recourse if that information is later misused. The founder who shares nothing frustrates the due diligence process, signals that something is being hidden, and loses the investment.

The right answer is neither. It is a structured, deliberate approach to information disclosure that distinguishes between what must be shared, what can legitimately be withheld, and what can be shared, but only under contractual protection. That distinction is not just good commercial practice. Under Nigerian law, it determines whether your confidential business information is legally protected or merely aspirationally secret.

Designed by Freepik

What Business Transparency Actually Means

Transparency is not the same as total disclosure. It is the provision of relevant, accurate, and sufficient information to persons who have a legitimate reason to receive it and nothing more than that.

The test every business owner should apply when deciding what to share is this: does this person need this specific information to make the decision or perform the function for which access is being granted? If the answer is yes, the information should generally be provided. If the answer is no, it does not belong in the disclosure.

An investor considering an equity stake needs to understand the company’s financial position, ownership structure, material contracts, assets, liabilities, and anything that could materially affect the value or risk of the investment. That is the scope of legitimate due diligence. It does not automatically extend to every customer password, every supplier negotiation, every internal communication, or every aspect of the proprietary process that gives the business its competitive edge.

The question is not whether to be transparent. It is about being transparent with precision, disclosing what is necessary and protecting what is not.

The Three-Category Framework: A Practical Tool for Every Business

The most useful way to approach information disclosure is to sort your business information into three distinct categories before any investor conversation, partnership discussion, or commercial negotiation begins. This classification should happen in advance, not in the room.

Category One: Information You Must or Should Disclose

Certain information must be disclosed regardless of your commercial preferences, because the law requires it. Under the Companies and Allied Matters Act 2020 (CAMA), companies have statutory obligations relating to corporate records, directors’ interests, shareholder registers, and annual returns. These obligations attach to specific persons and circumstances; regulators, courts, shareholders, and tax authorities and a private confidentiality policy cannot override them.

Beyond statutory requirements, certain information should be disclosed because withholding it would defeat the purpose of the transaction. An investor conducting due diligence is entitled to financial statements, information about debts and liabilities, ownership and control structure, material contracts, and anything that could affect their assessment of the business’s value or risk profile. Deliberately concealing material information from an investor can expose the business and its principals to claims of misrepresentation or fraud if the investment proceeds and the concealed information later surfaces.

The principle here is proportionality: disclose what is material to the decision being made, in the context in which it is being made, to the person who legitimately needs it.

Category Two: Information You Can Legitimately Withhold

Not everything an investor asks for is something they genuinely need, and not every request is made in good faith. Nigerian businesses have legitimate commercial reasons for protecting certain categories of information, particularly from counterparties who may be connected to competitors or who have not yet made a binding commitment to the transaction.

The information that falls into this category typically includes: proprietary business processes and methodologies; pricing strategies and margin structures; unpublished marketing strategies; supplier negotiations and supplier identities; detailed customer lists and customer acquisition data; software source code and technical architecture; internal product roadmaps and unreleased offerings; internal risk assessments; and business expansion strategies. The common thread is that disclosure of this information would damage the business’s competitive position without advancing any legitimate decision the counterparty needs to make.

Withholding this information is not deceptive, it is prudent. The legal question is whether the information qualifies for protection as a trade secret or confidential information, which has specific requirements under Nigerian jurisprudence.

Nigeria does not have a specific trade secrets statute. Protection of confidential business information is therefore primarily achieved through the common law action for breach of confidence, which Nigerian courts have recognised and applied. For a breach of confidence claim to succeed, the information must: have the necessary quality of confidence (it cannot be generally known or freely available); have been communicated in circumstances that import an obligation of confidence; and have been used in an unauthorised manner to the detriment of the party who communicated it.

At the international level, Article 39 of the TRIPS Agreement, to which Nigeria is bound as a WTO member, requires protection of undisclosed information that is secret, has commercial value because of its secrecy, and has been subject to reasonable steps to keep it confidential. The ‘reasonable steps’ requirement is critical: calling information confidential without actually taking steps to protect it weakens and may defeat any claim for its protection.

Category Three: Information That Can Be Disclosed — But Only Under Contract

The third category is where most of the practical complexity sits. There is information that a business genuinely needs to share in order to advance a transaction; detailed financial projections, business plans, customer data, technical documentation, proprietary processes, but that carries significant competitive risk if it leaves the protected environment of the negotiation.

The solution is neither to share it freely nor to refuse it entirely. It is to share it under a properly drafted Non-Disclosure Agreement that creates legally enforceable confidentiality obligations around the information being disclosed. The NDA converts the counterparty’s use of your confidential information from an act of discretion into a contractual obligation and makes the consequences of breach legally enforceable.

 

sample of non-disclosure agreement
source: www.freepik.com

NON-DISCLOSURE AGREEMENTS: WHAT MAKES THEM WORK IN NIGERIA

The perception among some Nigerian businesses that NDAs are difficult to enforce reflects poor drafting more than any inherent weakness in the law. When properly structured, an NDA creates enforceable contractual obligations and establishes the foundation for a breach of confidence claim if the obligations are violated. The combination provides overlapping protection suited to different breach scenarios.

A well-drafted NDA does more than state that ‘all information is confidential.’ An agreement drafted at that level of generality is difficult to enforce precisely because its scope is undefined. What information? Shared in what circumstances? For what purpose? Used how? The answers to these questions are what distinguish an enforceable NDA from a piece of paper that gives the recipient the impression of an obligation without creating one.

Definition of Confidential Information

The definition clause is the foundation of the entire agreement. It must clearly identify what information is protected; business plans, financial records, customer lists, technical data, intellectual property, operational strategies, pricing models, and must specify whether oral disclosures are covered (and if so, the mechanism by which they are confirmed in writing). An NDA that defines ‘confidential information’ as ‘all information shared between the parties’ is almost certainly too broad to enforce and too vague to be practically useful.

Purpose of Disclosure

The agreement must state why the information is being shared. Is it for an investment assessment? A potential joint venture? A commercial partnership? An acquisition? Specifying the purpose does two things: it restricts the recipient from using the information for unrelated purposes, a counterparty who uses your business plan to launch a competing product has breached the NDA even if they never disclosed the information to a third party and it limits the scope of what you are obligated to disclose under the agreement.

Restrictions on Use and Disclosure

This clause defines what the recipient can and cannot do with the information. They should be restricted from disclosing it to third parties without prior written consent, from using it for any purpose other than the stated purpose, and from copying or reproducing it beyond what the stated purpose requires. Where the recipient’s own employees, advisers, or representatives need access to the information in order to complete the evaluation, the NDA should extend its confidentiality obligations to those persons explicitly.

Exceptions to Confidentiality

A well-drafted NDA must identify the standard exceptions; information that was already publicly available when disclosed, information the recipient lawfully knew before disclosure, information independently developed by the recipient without reference to the disclosing party’s information, and information required to be disclosed by law or court order. These exceptions are not concessions; they are the legally recognised limits of what confidentiality protection can cover. An NDA that purports to extend protection to genuinely public information will not be enforced in those terms.

Duration

Confidentiality obligations must have a defined term. The appropriate duration depends on the nature of the information: trade secrets may warrant protection for as long as they remain confidential, which could be indefinitely; commercially sensitive business information that will be superseded by events; a financial projection, a marketing plan, may warrant a shorter period of two to five years. Obligations that are expressed to last forever in respect of ordinary commercial information are more likely to be challenged as unreasonable. Obligations tied to the information’s continued sensitivity are more robust.

Consequences of Breach and Remedies

This is the element most frequently omitted from Nigerian NDAs, and its absence significantly weakens enforcement. The agreement should specify what happens if the recipient breaches their obligations: the disclosing party’s right to seek an injunction to prevent continued disclosure; the right to claim damages for losses caused by the breach; and whether the agreement provides for liquidated damages, a pre-agreed sum that becomes payable on breach, which simplifies enforcement by removing the need to prove specific loss.

Nigerian courts will enforce a properly structured NDA. The courts have awarded injunctions restraining breach of confidence and ordered damages where confidential information was misused. The key requirement is that the agreement is sufficiently precise to establish what was agreed, what was breached, and what loss resulted.

Illustration by Freepik

Practical Steps Every Nigerian Business Should Take

  1. Classify your information before any negotiation begins: The three-category framework above should be applied to your business’s information assets before you enter any investor conversation, partnership discussion, or commercial negotiation. Decide in advance what is freely disclosable, what is conditionally disclosable, and what is not disclosable at all. This classification prevents decisions being made under pressure in the middle of a conversation.

 

  1. Require an NDA before disclosing Category Three information: Any information that carries competitive risk should only be shared after the NDA is signed, not before, and not during. The sequence matters. An NDA signed after the information has been shared protects nothing. Make it a condition of access, not an afterthought.

 

  1. Take active steps to protect the information you claim is confidential: Nigerian courts and the TRIPS framework both require that trade secrets be subject to ‘reasonable steps’ to maintain their secrecy. This means access controls, password protection for digital assets, physical security for hard copies, clear marking of documents as confidential, and confidentiality obligations in employment and contractor agreements. Information that is freely accessible within your organisation, shared with every employee, stored in an unsecured folder, circulated without restriction,  is difficult to protect as a trade secret regardless of what your NDA says.

 

  1. Include confidentiality provisions in all relevant commercial agreements: An NDA is appropriate for discrete disclosure events, investor due diligence, partnership discussions, joint venture negotiations. For ongoing commercial relationships; employment, contractor engagements, supplier agreements, distribution arrangements, confidentiality should be embedded directly in the relevant agreement rather than managed through a separate standalone NDA.

 

  1. Disclose in stages, not all at once: In investor due diligence processes, consider structuring disclosure in tranches tied to the progression of the transaction. General company information and financial summaries can be shared at the initial stage. Detailed operational data, customer information, and proprietary processes should be reserved until the investor has made a binding indication of interest and the NDA is in place. This approach protects your most sensitive information for the stage of the process where commitment is highest.

 

  1. Get legal advice before, not after, a disclosure dispute: The businesses that find their NDAs unenforceable are almost always the ones who drafted them without legal advice, or who signed whatever the counterparty provided without having it reviewed. An NDA drafted by the recipient’s lawyers is structured to protect the recipient. A properly drafted NDA protects the disclosing party. The distinction matters enormously if the relationship breaks down and the information is misused.

 

The Principle Is Simple, However, the Execution Requires Care.

Opening your books to an investor is not the same as handing over the keys to the business. The information that allows an investor to assess a company and the information that would allow a competitor to replicate it are not the same set of documents. The distinction between them is the foundation of a commercially intelligent approach to transparency.

Nigerian law supports that distinction. The common law of breach of confidence protects genuinely confidential information. Properly drafted NDAs create enforceable contractual obligations. CAMA defines the scope of what must be disclosed to regulated persons. The framework exists. What most businesses lack is the structured approach to applying it.

Disclose what is necessary, protect what is sensitive, draw the line deliberately, in writing, before the conversation begins, not in response to a dispute after it ends.

Written by: Otitoju Olaide
Junior Associate
Starr Attorneys

 

Need Help Structuring an NDA or a Due Diligence Process?

Starr Attorneys advises Nigerian businesses, founders, and investors on confidentiality agreements, investor due diligence frameworks, trade secret protection, and commercial contract structuring. Whether you are preparing for an investment round, entering a partnership, or protecting your business’s proprietary information, we provide the legal structure to do it properly.

+234 704 545 9409   |   info@starrattorneys.co   |   starrattorneys.co

 

The information that makes your business valuable is often the same information your competitors would most like to have. Protecting it is not paranoia, it is the basic discipline of running a business that is worth protecting.

Related Reading from Starr Attorneys

What if the work you did last year was still paying you till today?

A Patent You Don’t Renew Is a Patent You Don’t Own

Mergers in Nigeria: What Every Business Needs to Know Before the Deal

What Every Nigerian Business Must Know About Taxes

 

Starr Attorneys  |  Business Law Firm  |  Abuja  |  Lagos  |  Port Harcourt  |  Onitsha  |  Kano  |  starrattorneys.co

Leave a comment