A "Go-Dark" clause is a data-protection provision that requires one or both parties to permanently delete, destroy, or render inaccessible all confidential information, personal data, and business records upon termination of the contract or at a specified trigger event. This clause typically obligates the receiving party to certify in writing that all data has been securely destroyed and cannot be recovered. The clause exists to protect sensitive information from being retained, misused, or falling into unauthorized hands after the business relationship ends. It's particularly important in industries handling personal data, trade secrets, or regulated information (healthcare, finance, technology), where data retention can create legal liability, compliance violations, or competitive disadvantages.
The practical significance of a Go-Dark clause is substantial: it shifts the burden and cost of secure data destruction to the party holding the information, and it creates an enforceable obligation with potential breach consequences. However, Go-Dark clauses can conflict with legal hold requirements, tax/accounting retention obligations, or legitimate business needs to retain certain records. A poorly drafted clause may be impossible to comply with or may create unrealistic timelines for destruction of large data volumes.
Before signing, clarify the scope of data subject to destruction—distinguish between confidential business information, personal data, backup copies, and archived records. Negotiate reasonable timelines (typically 30-90 days post-termination) and carve out exceptions for data required by law, court order, or legitimate business records retention. Specify the destruction method (secure deletion, physical destruction, encryption) and whether certification by a third party is required. If you're the party retaining data, push back on overly broad destruction obligations and ensure the clause doesn't conflict with your legal compliance requirements or backup/disaster recovery practices. Consider whether "anonymization" of data is acceptable as an alternative to destruction.
Frequently Asked Questions
What does this clause mean in simple terms?
A "Go-Dark" clause is a data-protection provision that requires one or both parties to permanently delete, destroy, or render inaccessible all confidential information, personal data, and business records upon termination of the contract or at a specified trigger event.
Why should I care about this clause?
This clause typically obligates the receiving party to certify in writing that all data has been securely destroyed and cannot be recovered.
What are my options?
The clause exists to protect sensitive information from being retained, misused, or falling into unauthorized hands after the business relationship ends.
How does this affect small businesses?
It's particularly important in industries handling personal data, trade secrets, or regulated information (healthcare, finance, technology), where data retention can create legal liability, compliance violations, or competitive disadvantages.
