Board confidentiality is the legal and ethical obligation every director has to keep internal discussions, documents, and deliberations private, releasing information only when the organization authorizes it or the law compels it. The duty attaches the moment someone joins a board and reaches everything they see and hear in that role. Violating it can trigger removal, civil lawsuits, and for directors of public companies, federal securities enforcement.
What Directors Have to Keep Private
As a practical matter, everything discussed in a board meeting or shared in board materials is confidential until the organization decides otherwise. The obvious categories include unreleased financial results, plans for mergers or acquisitions, litigation strategy, and proprietary business methods like trade secrets or product development timelines.
Personnel matters sit squarely in this zone and get particular sensitivity because individual privacy is layered on top of the organization’s interests. Executive compensation, performance reviews, hiring decisions, and terminations all qualify.
Less obvious but equally protected are the dynamics of the discussion itself. How individual directors voted, who argued for or against a proposal, and what concerns were raised in debate are all restricted. A director who tells a reporter “the board was split 5-4 on the deal” has disclosed confidential information even without revealing the substance of the deal.
The line between confidential and public shifts only when the board formally authorizes disclosure. Once the organization issues a press release, files a public document with a regulator, or otherwise puts information into the marketplace, that specific data is no longer restricted. Timing matters. Sharing earnings data two days before a public filing is just as much a breach as sharing it two months before.
Nonprofit directors face one nuance worth flagging. Federal law requires tax-exempt organizations to make their three most recent Form 990 returns, their exemption application, and related supporting documents available for public inspection, and to fulfill written requests for copies within 30 days.1Office of the Law Revision Counsel. 26 USC 6104 – Publicity of Information Required From Certain Exempt Organizations and Certain Trusts Information already in those filings isn’t secret; the duty still protects the deliberations that produced it.
Why the Duty Exists: Loyalty to the Organization
The obligation to keep board information private flows from the duty of loyalty, one of the core fiduciary duties every director owes. Loyalty requires directors to put the organization’s interests ahead of their own, which includes keeping confidential the information they receive in their role.2Cornell Law Institute. Duty of Loyalty Taking advantage of inside information for personal gain, diverting business opportunities, or leaking sensitive data to outsiders all violate this duty.
Courts have long treated this loyalty standard as absolute. The foundational case Guth v. Loft, Inc. described the required “undivided and unselfish loyalty to the corporation” and stated that there “shall be no conflict between duty and self-interest.”3Open Casebook. Corporations – Guth v Loft A director doesn’t need to have profited personally for a breach to matter. The question is whether they prioritized the organization’s interests when they handled the information.
The practical reason for the rule is simple. If directors worried that their candid assessments of risk, personnel, or strategy would become public, they would hedge every statement, and real deliberation would stop. Privacy is what makes honest boardroom conversation possible.
Executive Sessions
Executive sessions are the tool boards use for their most sensitive topics. These are closed portions of a meeting limited to independent directors and sometimes a small number of invited participants such as the general counsel. The CEO is often excluded, particularly when the discussion involves their compensation, performance, or potential termination.
Topics handled in executive session typically include succession planning, pending litigation, regulatory investigations, and disputes between board members. Restricting attendance reinforces confidentiality because fewer people in the room means fewer potential sources of a leak. Many boards schedule a short executive session at the end of every regular meeting so that calling one doesn’t signal a crisis. If the CEO was excluded, the board chair communicates any relevant decisions back afterward. Written records of executive sessions carry the same confidentiality protections as any other board document.
When the Duty Yields: Legal Compulsion and Whistleblowing
Board confidentiality has limits, and knowing where they fall is as important as knowing the rule itself. Two situations override the duty entirely.
Subpoenas, Court Orders, and Regulatory Demands
A director who receives a valid subpoena or court order must comply, whatever the organization’s confidentiality expectations. Subpoenas can require testimony or the production of documents, and ignoring them can lead to contempt of court, which carries fines and possible jail time. Regulatory agencies have independent authority to demand records; the SEC, for example, requires regulated entities to maintain records specifically so examiners can review them.4U.S. Securities and Exchange Commission. Books and Records Requirements for Brokers and Dealers Under the Securities Exchange Act of 1934
The critical distinction is between a voluntary leak and a compelled disclosure. Sharing confidential information because a court ordered it is not a breach of fiduciary duty. Sharing the same information because a journalist asked nicely is. Any director who receives a legal demand should immediately contact the organization’s general counsel, who can evaluate the scope of the demand, assert any applicable privileges, and coordinate the response.
Reporting Wrongdoing
A confidentiality policy or agreement cannot legally prevent someone from reporting securities violations, financial fraud, or tax misconduct to the appropriate authorities. Federal regulations explicitly prohibit any person from taking action to impede an individual from communicating with SEC staff about a possible securities law violation, including enforcing or threatening to enforce a confidentiality agreement to block such communications.5eCFR. 17 CFR 240.21F-17 – Staff Communications With Individuals Reporting Possible Securities Law Violations The SEC has fined companies for using confidentiality agreements that lacked an explicit regulatory-reporting carve-out, even when no one was actually deterred from reporting.
The Dodd-Frank Act adds anti-retaliation protection. An employer cannot discharge, demote, suspend, threaten, or otherwise discriminate against someone for providing information to the SEC about a securities violation, and a whistleblower who suffers retaliation can sue for reinstatement, double back pay, and attorney’s fees.6Office of the Law Revision Counsel. 15 USC 78u-6 – Securities Whistleblower Incentives and Protection When an SEC action results in monetary sanctions exceeding $1 million, the whistleblower may receive an award of 10 to 30 percent of the amount collected.
Sarbanes-Oxley adds further protection for public-company reporting. It prohibits covered companies from retaliating against an employee who reports conduct they reasonably believe involves securities fraud, wire fraud, bank fraud, or a violation of SEC rules; protected reports can go to a federal agency, a member of Congress, or a supervisor within the organization.7Office of the Law Revision Counsel. 18 USC 1514A – Civil Action to Protect Against Retaliation in Fraud Cases The statute refers specifically to employees, and its application to directors in their capacity as directors is a more nuanced question; the broader Dodd-Frank protections use the term “individual” and are not limited to employees.
Nonprofit board members who suspect financial mismanagement or non-compliance with tax-exempt rules can file a complaint with the IRS using Form 13909. The IRS keeps the complainant’s identity confidential and will not disclose the status of any resulting investigation, citing taxpayer confidentiality rules under Section 6103 of the Internal Revenue Code.8Internal Revenue Service. IRS Complaint Process – Tax-Exempt Organizations
Insider Trading Risk for Public-Company Directors
For directors of publicly traded companies, breaching confidentiality is not only a fiduciary problem. It can be a federal crime. Section 10(b) of the Securities Exchange Act prohibits any “manipulative or deceptive device” in connection with the purchase or sale of securities.9Office of the Law Revision Counsel. 15 USC 78j – Manipulative and Deceptive Devices The SEC’s implementing rule treats trading “on the basis of material nonpublic information” in breach of a duty of trust or confidence to the issuer as a prohibited act.10eCFR. 17 CFR 240.10b5-1 – Trading on the Basis of Material Nonpublic Information
A board member who learns during a meeting that the company is about to be acquired and then buys shares, or who tips off a friend who buys shares, has committed insider trading. Criminal penalties reach up to 20 years in prison and fines of up to $5 million for individuals. The SEC can also pursue civil penalties of up to three times the profit gained or loss avoided. In fiscal year 2024, the SEC imposed an $83 million civil penalty and roughly $166 million in disgorgement against Morgan Stanley in connection with unauthorized disclosure of confidential information about large stock sales.11U.S. Securities and Exchange Commission. SEC Announces Enforcement Results for Fiscal Year 2024
The risk extends beyond personal trading. A director who shares material nonpublic information with someone else, even without trading themselves, can be liable as a “tipper,” and the person who receives the information and trades on it faces liability too. Casually mentioning a pending deal at a dinner party is all it takes.
What Happens If a Director Breaches
The consequences for unauthorized disclosure range from embarrassing to career-ending, depending on what was disclosed and the harm caused.
Removal From the Board
The most immediate organizational response is removal. In many corporations, shareholders can remove a director with or without cause by a majority vote. When the board is classified into staggered terms, removal typically requires cause. The organization’s bylaws lay out the specific procedures, including notice requirements and voting thresholds. Some bylaws also allow the remaining directors to initiate removal without waiting for a shareholder vote.
Injunctions and Civil Liability
The organization can ask a court for an injunction to stop further disclosures. If a breach caused financial harm, the organization can sue for breach of fiduciary duty. Courts have wide flexibility in fashioning remedies for loyalty breaches, including requiring the director to compensate the organization for losses and to disgorge any personal profits gained from the leaked information. Courts have also noted that when a breach of the duty of loyalty is proven, the usual strict requirements of proving causation and damages may be relaxed in favor of equity and deterrence.
Legal costs to pursue these claims can be substantial, and courts have ordered breaching directors to cover them. Actual dollar amounts depend entirely on what was disclosed and the resulting damage. A leak that torpedoes a billion-dollar merger produces a very different damages calculation than one that embarrasses a board member at a cocktail party.
Federal Securities Enforcement
For public-company directors, unauthorized disclosure of material nonpublic information can trigger SEC enforcement carrying civil penalties, disgorgement of profits, and bars from serving as an officer or director of a public company.11U.S. Securities and Exchange Commission. SEC Announces Enforcement Results for Fiscal Year 2024 If the disclosure involved insider trading or tipping, criminal prosecution is on the table. These federal consequences exist independently of any lawsuit the organization brings, so a director can face both a civil suit from the company and a federal enforcement action at the same time.
Gaps in D&O Insurance
Directors and Officers insurance offers some protection for claims arising from board service, but coverage for confidentiality breaches is unreliable. Most D&O policies exclude intentional misconduct and fraud, and many contain specific exclusions for trade secret misappropriation or intellectual property violations. A deliberate leak will almost certainly trigger one of those exclusions, leaving the director personally responsible for defense costs and any judgment. Even where coverage is theoretically available, insurers routinely contest it in unauthorized-disclosure cases.
The Duty Continues After You Leave
The confidentiality obligation does not expire when a term ends, a director resigns, or one is removed. The fiduciary duty that created the obligation covered information received during service, and that information doesn’t become less sensitive because the person who learned it is no longer on the board. You cannot resign on Tuesday and start sharing the board’s secrets on Wednesday.
The scope of the continuing duty depends on the circumstances. A former director generally cannot use information from their service to compete with the organization or to poach business opportunities the organization was actively pursuing. How long these restrictions last depends on how sensitive the information is and how quickly it goes stale. Strategic plans discussed two weeks before resignation carry more weight than a budget projection from five years ago. Written agreements often specify a defined period to reduce ambiguity.
Written Confidentiality Policies and Agreements
Most boards don’t rely on the fiduciary duty alone. They put confidentiality in writing. A formal policy adopted as part of the governance framework sets clear expectations that every director acknowledges in writing when they join. Many organizations also require each director to sign a standalone confidentiality agreement.
These agreements typically define what information is covered, specify the standard of care the director must exercise (often the same degree the organization uses for its own proprietary information), and spell out what happens in the event of a breach. Well-drafted agreements include exceptions for legally compelled disclosures and, critically, a carve-out preserving the right to report potential legal violations to government regulators. The SEC has made clear that agreements without this carve-out violate federal rules, regardless of whether anyone was actually prevented from reporting.5eCFR. 17 CFR 240.21F-17 – Staff Communications With Individuals Reporting Possible Securities Law Violations
Information already in the public domain or learned independently from a source outside the organization is typically excluded from these agreements. That carve-out prevents the absurd result of a director being bound to secrecy about something everyone already knows. Be cautious about assuming information is truly public, though. Hearing a rumor about your company in the press is not the same as the board formally authorizing disclosure.