What I outlined above is why your BD acting in bad faith is illegal under the securities law. It's not even a grey area.
Put your security research hat on for a moment. The "other side" of the trade wants to get the info subject to BD confidentiality (pt 2) and the exploit them (pt 3,4). When your BD does this it is expressly illegal. This has a name but mentioning it here would just confuse the issue. The question is this: what tools are available to this "other side" that would put the NPI in the hands of the "other side" but not divulge it more broadly? Would a bad-faith offer to do a ("sweet") biz deal be good enough bait to social engineer selective disclosure? Unless you can rule this out technologically, you have to rule it in for consideration.
It's best not to get sidetracked on whether the divulged info is legally NPI or PI (just yet) and look at it purely from a pragmatic perspective like a security credential. The BD either has it under control or not. And is it physically possible in terms of bits to have selective disclosure? And if it is does the pretext matter?
Make no mistake: the BD cannot hide if he abuses the information directly. He's like an authorized user. The issue is what level of authorization you give the counter-party and how to protect its abuse. The technical details and legality of pretexting security credentials is something I'm sure you could speak authoritatively to. I'm only using it as an example here for illustrative purposes.