ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Supplier Confidentiality Agreement

Supplier Confidentiality Agreement

1. Purpose

This Supplier Confidentiality Agreement establishes the confidentiality obligations of a supplier, vendor, service provider, consultant company, technology provider, outsourcing provider, or other external organization that receives or accesses non-public information belonging to the Company or its customers.

The objective is to ensure that confidential information is:

  • Accessed only for authorized business purposes
  • Protected against unauthorized disclosure
  • Shared only with authorized personnel
  • Protected throughout the supplier relationship
  • Properly handled when transferred
  • Returned or securely deleted when required
  • Protected after termination of the relationship

Core Principle

Identify → Authorize → Share Minimally → Protect → Monitor → Return/Delete → Maintain Confidentiality


2. Parties

This Agreement is entered into between:

Company: __________________________________________

Supplier: __________________________________________

Supplier Legal Entity: ______________________________

Supplier Address: ___________________________________

Contract/Supplier ID: _______________________________

Primary Service: ____________________________________

Agreement Effective Date: ___________________________

Contract Expiry Date: _______________________________

The Company and Supplier are collectively referred to as the “Parties.”


3. Purpose of the Supplier Relationship

The Supplier is providing the following services:

The Supplier may receive or access Company Confidential Information solely to perform the agreed services.

The Supplier must not use Confidential Information for any other purpose unless expressly authorized in writing.


4. Definition of Confidential Information

Confidential Information means any non-public information disclosed to, accessed by, created for, or otherwise made available to the Supplier by or on behalf of the Company.

Confidential Information may be provided verbally, electronically, physically, visually, through systems, through APIs, or by any other means.

Confidential Information includes, but is not limited to:

Business Information

  • Business plans
  • Strategy
  • Financial information
  • Pricing
  • Forecasts
  • Commercial information
  • Contracts
  • Supplier information
  • Customer relationships
  • Product roadmaps
  • Marketing information
  • Internal reports
  • Operational information

Customer Information

  • Customer names and information
  • Customer contracts
  • Customer account information
  • Customer data
  • Customer systems
  • Customer configurations
  • Customer security information
  • Customer reports
  • Customer credentials
  • Customer technical information

Personal Information

  • Employee information
  • Customer personal data
  • Supplier contact information
  • Identification information
  • Financial information
  • Other personal information processed by the Supplier

Technical Information

  • Source code
  • Software architecture
  • APIs
  • Database structures
  • System designs
  • Infrastructure configurations
  • Technical documentation
  • Development information
  • Deployment configurations
  • Scripts
  • Automation
  • Algorithms

Information Security Information

  • Security architecture
  • Security configurations
  • Vulnerability information
  • Penetration-test results
  • Security findings
  • Risk assessments
  • Security incidents
  • Incident reports
  • Security monitoring information
  • Security procedures

Credentials and Secrets

  • Passwords
  • API keys
  • Access tokens
  • SSH keys
  • Cloud credentials
  • Database credentials
  • Encryption keys
  • Certificates
  • Service-account credentials
  • Recovery codes

Intellectual Property

  • Designs
  • Product concepts
  • Research
  • Technical developments
  • Proprietary methodologies
  • Trade secrets
  • Documentation
  • Software
  • Other intellectual property

5. Information Classification

The Supplier must comply with the Company’s information-classification requirements where applicable.

Information may be classified as:

ClassificationExample
PublicInformation approved for public release
InternalInternal business and operational information
ConfidentialCustomer, commercial, technical, and business information
RestrictedCredentials, sensitive personal data, critical security information

The Supplier must apply appropriate safeguards based on the classification and contractual requirements.


6. Confidentiality Obligations

The Supplier agrees to:

☐ Protect Confidential Information against unauthorized access, use, disclosure, copying, modification, or loss.

☐ Use Confidential Information only for the agreed business purpose.

☐ Limit access to authorized personnel.

☐ Apply appropriate security controls.

☐ Prevent unauthorized disclosure.

☐ Not sell, publish, or commercially exploit Confidential Information.

☐ Not use Confidential Information for the Supplier’s independent commercial purposes.

☐ Not disclose Confidential Information to competitors or other unauthorized parties.

☐ Notify the Company of suspected unauthorized disclosure.

☐ Maintain confidentiality after termination of the relationship.


7. Need-to-Know Principle

The Supplier must restrict access to Confidential Information to personnel who:

  1. Require access to perform the contracted services;
  2. Are authorized to access the information; and
  3. Are subject to appropriate confidentiality obligations.

The Supplier must apply the principle:

Need-to-Know + Minimum Necessary Access

Technical availability of information does not constitute authorization.


8. Supplier Personnel

The Supplier must ensure that personnel with access to Company Confidential Information:

  • Are appropriately authorized
  • Understand their confidentiality responsibilities
  • Follow applicable security requirements
  • Receive appropriate security awareness where required
  • Use individual accounts where technically feasible
  • Protect credentials
  • Report security incidents
  • Do not disclose Confidential Information without authorization

The Supplier remains responsible for its personnel’s compliance with applicable confidentiality obligations.


9. Supplier Subcontractors and Subprocessors

The Supplier must not disclose Confidential Information to subcontractors, subprocessors, affiliates, or other third parties unless permitted under the applicable contract.

Where approval is required, the Supplier must:

☐ Identify the subcontractor/subprocessor

☐ Identify the service provided

☐ Identify the information accessed

☐ Identify the processing/storage location

☐ Apply appropriate confidentiality requirements

☐ Apply applicable security requirements

☐ Maintain appropriate oversight

☐ Notify the Company of material changes where required

The Supplier must ensure that approved subcontractors and subprocessors are subject to confidentiality obligations that are no less protective than those applicable to the Supplier.


10. Customer Information

Where the Supplier receives or accesses Company customer information, the Supplier must:

  • Use the information only for authorized services
  • Protect the information against unauthorized access
  • Apply applicable contractual security requirements
  • Restrict access to authorized personnel
  • Avoid unnecessary copying
  • Avoid unauthorized downloads
  • Follow applicable retention requirements
  • Return or delete information when required

The Supplier must not use customer information for its own marketing, analytics, product development, or other independent purposes unless expressly authorized.


11. Personal Data

Where the Supplier processes personal data on behalf of the Company, the Supplier must comply with applicable privacy and data-protection requirements and the applicable Data Processing Agreement, where one exists.

The Supplier must appropriately address:

  • Processing purpose
  • Data categories
  • Data subjects
  • Processing locations
  • Access
  • Retention
  • Deletion
  • Subprocessors
  • International transfers
  • Security
  • Incident notification
  • Data-subject requirements where applicable

This Agreement does not replace a required Data Processing Agreement.


12. Information Security

The Supplier must maintain appropriate administrative, technical, and physical safeguards to protect Confidential Information.

Depending on the risk and services provided, controls may include:

☐ Access control

☐ MFA

☐ Encryption

☐ Network security

☐ Endpoint security

☐ Vulnerability management

☐ Security monitoring

☐ Logging

☐ Backup

☐ Incident response

☐ Secure development

☐ Security awareness

☐ Physical security

☐ Business continuity

The specific security requirements should be defined in the applicable Supplier Security Requirements or contract.


13. Credentials and Secrets

Where the Supplier receives or manages Company credentials or secrets, the Supplier must:

  • Restrict access
  • Protect credentials securely
  • Avoid unnecessary copying
  • Prevent credential sharing
  • Use secure storage
  • Rotate credentials where required
  • Revoke credentials when no longer required
  • Report suspected compromise immediately

The Supplier must not store Company credentials in:

  • Public repositories
  • Source code
  • Unapproved cloud storage
  • Personal systems
  • Unapproved collaboration tools
  • Unsecured documents

14. Source Code and Intellectual Property

Where applicable, the Supplier must protect:

  • Source code
  • Software designs
  • Architecture
  • Algorithms
  • Development repositories
  • Infrastructure-as-code
  • CI/CD configurations
  • Technical documentation
  • Product designs

The Supplier must not copy, publish, reuse, sell, or disclose Company source code or proprietary technical information except as authorized.

Intellectual-property ownership is governed by the applicable commercial agreement and is not established solely by this confidentiality agreement unless expressly stated.


15. AI and External Services

The Supplier must not submit Company or customer Confidential Information to unauthorized:

  • Generative AI services
  • Public AI platforms
  • SaaS applications
  • Cloud services
  • File-sharing platforms
  • Development platforms
  • Analytics services
  • External processing services

unless expressly authorized.

Particular care must be taken with:

  • Customer data
  • Personal data
  • Source code
  • Security findings
  • Vulnerability information
  • Credentials
  • Architecture
  • Confidential documents

Where AI services are authorized, applicable contractual and security requirements must be followed.


16. Information Transfer

Confidential Information must be transferred using approved and appropriately secured methods.

Examples include:

  • Encrypted file transfer
  • Approved corporate email
  • Secure APIs
  • Approved collaboration platforms
  • Secure file-sharing systems
  • Other Company-approved mechanisms

The Supplier must not use unauthorized channels to transfer Confidential Information.


17. Data Location

The Supplier must not store, process, or transfer Confidential Information to locations that are not authorized under the applicable agreement.

Where relevant, the Supplier must identify:

LocationActivityInformationRequirement

Applicable contractual, privacy, regulatory, customer, and security requirements must be considered.


18. Physical Protection

Where the Supplier stores or handles physical Confidential Information, appropriate safeguards must be maintained.

These may include:

  • Physical access controls
  • Secure storage
  • Visitor controls
  • Secure areas
  • Document protection
  • Media protection
  • Secure disposal
  • Environmental controls

19. Security Incidents and Breaches

The Supplier must promptly notify the Company of any actual or suspected:

  • Data breach
  • Security incident
  • Unauthorized access
  • Unauthorized disclosure
  • Loss of Confidential Information
  • Credential compromise
  • Malware incident
  • Source-code exposure
  • Security vulnerability materially affecting Company information
  • Customer information exposure

Company Security Contact

Name/Team: ________________________________________

Email: ____________________________________________

Phone: ____________________________________________

The notification process and notification timeframe should be defined in the applicable contract or Supplier Security Requirements.


20. Incident Cooperation

Following a security incident, the Supplier must, where applicable:

  • Cooperate with investigation
  • Preserve relevant evidence
  • Identify affected information
  • Identify affected systems
  • Identify affected individuals or customers where appropriate
  • Support containment
  • Support remediation
  • Provide relevant incident information
  • Implement corrective actions

The Supplier must not intentionally destroy relevant evidence.


21. Security Assessments and Assurance

Where required by the contract and appropriate to the risk, the Supplier may be required to provide reasonable evidence of security controls.

Examples include:

  • ISO/IEC 27001 certificate
  • SOC report
  • Security assessment
  • Penetration-test summary
  • Security questionnaire
  • Business continuity evidence
  • Data-protection documentation
  • Relevant policies
  • Independent assurance reports

The Company should evaluate the scope and relevance of such evidence rather than relying solely on the existence of a certification.


22. Audit and Review Rights

Where agreed in the applicable contract, the Company may request reasonable information necessary to assess the Supplier’s compliance with applicable confidentiality and security requirements.

The review may include:

  • Security questionnaires
  • Evidence review
  • Meetings
  • Control assessments
  • Independent assurance reports
  • Relevant audit reports

Any audit or assessment rights should be exercised proportionately and subject to applicable contractual and legal requirements.


23. Supplier Personnel Access

The Supplier must maintain appropriate records of personnel authorized to access Company information where required.

The Supplier must promptly remove access when personnel:

  • Leave the Supplier
  • Change roles
  • No longer require access
  • Lose authorization
  • Are removed from the engagement

Where Company-managed accounts are used, the Company may directly manage access revocation.


24. Information Retention

The Supplier must retain Confidential Information only for as long as:

  • Required to perform the services;
  • Required by contract;
  • Required by applicable law; or
  • Otherwise authorized by the Company.

The Supplier must not retain Confidential Information indefinitely for convenience.


25. Return and Deletion of Information

Upon Company request or termination of the relevant services, the Supplier must return or securely delete Confidential Information as required by the applicable agreement.

This may include:

☐ Electronic files

☐ Physical documents

☐ Customer information

☐ Personal data

☐ Source code

☐ Security reports

☐ Credentials

☐ Configuration information

☐ Backups where applicable

☐ Removable media

☐ Other Company information

The Supplier may retain information where legally required, provided that the retained information remains protected and is not used for unauthorized purposes.


26. Verification of Deletion

Where required, the Company may request reasonable confirmation that Confidential Information has been returned or securely deleted.

Such confirmation may be provided through:

  • Written certification
  • Supplier deletion statement
  • System evidence
  • Data-disposal record
  • Other appropriate evidence

Deletion requirements should account for legitimate backup, legal-retention, and investigation requirements.


27. Business Continuity

Where the Supplier provides a critical service, the Supplier must maintain appropriate arrangements to protect the availability and continued delivery of the service.

Where applicable, the Company may assess:

  • Business continuity
  • Disaster recovery
  • Backup
  • Recovery capability
  • Recovery testing
  • RTO
  • RPO
  • Alternative arrangements

28. Publicity and Marketing

The Supplier must not use the Company’s:

  • Name
  • Logo
  • Customer names
  • Project details
  • Case studies
  • Screenshots
  • Confidential information

for marketing, publicity, presentations, websites, social media, or other public communications without prior authorization.


29. Legal and Regulatory Disclosure

Nothing in this Agreement prevents disclosure required by applicable law, court order, or valid regulatory requirement.

Where legally permitted, the Supplier should notify the Company before making such disclosure and cooperate with reasonable protective measures.


30. Exceptions to Confidential Information

Confidential Information does not generally include information that the Supplier can demonstrate:

  1. Was publicly available without breach of this Agreement;
  2. Was lawfully known to the Supplier before disclosure;
  3. Was lawfully received from an authorized third party without confidentiality restrictions; or
  4. Was independently developed without unauthorized use of Company Confidential Information.

The Supplier should consult the Company before relying on an exception.


31. Supplier Responsibility

The Supplier is responsible for ensuring that its personnel and approved subcontractors comply with applicable confidentiality obligations.

The Supplier must maintain appropriate internal processes to:

  • Identify authorized personnel
  • Control access
  • Communicate confidentiality obligations
  • Protect information
  • Report incidents
  • Remove access
  • Return/delete information

32. No Unauthorized Use

The Supplier must not use Confidential Information to:

  • Develop competing products
  • Build unrelated products
  • Conduct unauthorized analytics
  • Train unauthorized AI models
  • Market services
  • Contact customers for unauthorized commercial purposes
  • Sell information
  • Benefit another customer
  • Benefit the Supplier independently

unless expressly authorized.


33. No License or Transfer of Rights

Disclosure of Confidential Information does not grant the Supplier any ownership, license, intellectual-property right, or other right except the limited right to use the information for the authorized business purpose.


34. Relationship With Commercial Agreement

This Agreement should be read together with the applicable:

  • Master Services Agreement
  • Purchase Agreement
  • Statement of Work
  • Supplier Security Addendum
  • Data Processing Agreement
  • Service Level Agreement
  • Supplier Security Requirements
  • Other applicable contractual documents

If another agreement establishes stricter confidentiality or security requirements, the stricter applicable requirement should apply to the extent permitted by the contractual framework.


35. Confidentiality After Termination

The Supplier’s confidentiality obligations continue after termination or expiry of the business relationship for as long as the information remains confidential or as otherwise required by applicable law or contract.

Termination does not authorize the Supplier to retain, use, disclose, or exploit Confidential Information.


36. Security Exceptions

Any exception to agreed confidentiality or security requirements must be formally documented and approved where required.

ExceptionReasonRiskCompensating ControlApprovalExpiry

Temporary exceptions should include an expiry date.


37. Supplier Acknowledgement

The Supplier confirms that:

☐ The confidentiality requirements have been reviewed.

☐ The Supplier understands the permitted use of Confidential Information.

☐ Access will be restricted to authorized personnel.

☐ Appropriate security safeguards will be maintained.

☐ Subcontractors will be controlled as required.

☐ Security incidents will be reported.

☐ Confidential Information will not be used for unauthorized purposes.

☐ Information will be returned or deleted when required.

☐ Confidentiality obligations will continue after termination.


38. Supplier Declaration

The Supplier acknowledges that it may receive or access confidential, proprietary, customer, personal, technical, security, and other non-public information in connection with its services.

The Supplier agrees to protect such information and use it only for authorized business purposes.

The Supplier agrees to maintain appropriate confidentiality and security safeguards and to comply with applicable contractual requirements.

Supplier

Legal Name: _______________________________________

Authorized Representative: __________________________

Designation: _______________________________________

Signature: _________________________________________

Date: _____________________________________________


39. Company Representative

Name: __________________________________________

Designation: _____________________________________

Signature: _______________________________________

Date: ____________________________________________


40. Witness — Where Required

Name: __________________________________________

Designation: _____________________________________

Signature: _______________________________________

Date: ____________________________________________


41. Document Control

FieldDetails
Document NameSupplier Confidentiality Agreement
Document ID
Version
Effective Date
Owner
Approved By
Review FrequencyAnnual / As Required
ClassificationConfidential
Related PolicyConfidentiality and Non-Disclosure Policy
Related DocumentsSupplier Security Requirements / DPA / Contract
RetentionAccording to Legal and Contractual Requirements

42. Supplier Onboarding Checklist

Before sharing sensitive information:

☐ Supplier identity verified

☐ Supplier due diligence completed

☐ Supplier risk assessment completed

☐ Contract/SOW completed

☐ Confidentiality Agreement signed

☐ Security requirements agreed

☐ DPA completed where applicable

☐ Information classification identified

☐ Information-sharing method approved

☐ Access requirements identified

☐ Customer requirements reviewed

☐ Subprocessors assessed

☐ Data locations assessed

☐ Incident notification requirements agreed

☐ Security contacts recorded

☐ Supplier approved


43. Supplier Offboarding Checklist

At the end of the relationship:

☐ Contract termination/completion confirmed

☐ Supplier access inventory reviewed

☐ Company accounts disabled

☐ Cloud access removed

☐ Source-code access removed

☐ Production access removed

☐ Customer access removed

☐ Credentials/tokens addressed

☐ Confidential information returned

☐ Confidential information deleted where required

☐ Subprocessor access addressed

☐ Assets returned

☐ Deletion evidence obtained where required

☐ Supplier Register updated

☐ Confidentiality obligations communicated

☐ Offboarding evidence retained


44. AWS SaaS Startup Example

A SaaS startup engages an external managed service provider to support its AWS infrastructure.

The supplier may have access to:

  • AWS infrastructure
  • Monitoring systems
  • Cloud configurations
  • Infrastructure-as-code
  • Security logs
  • Incident information
  • Limited customer information

Before Access

Supplier Due Diligence → Risk Assessment → Contract → Confidentiality Agreement → Security Requirements → Access Approval

During the Relationship

The supplier must:

  • Access only authorized AWS resources.
  • Use named accounts where practical.
  • Use MFA.
  • Protect credentials and secrets.
  • Restrict personnel access.
  • Protect customer information.
  • Report security incidents.
  • Control subcontractors.

At Exit

Terminate Service → Revoke Access → Rotate Relevant Credentials → Return/Delete Information → Verify → Record

The confidentiality agreement establishes the supplier’s contractual obligation while the supplier security controls and access-management processes provide operational protection.


45. Startup-Friendly Model

For a low-risk supplier:

Supplier Verification → Contract → Confidentiality → Basic Security Requirements → Approval

For a medium-risk supplier:

Due Diligence → Risk Assessment → NDA/Confidentiality → Security Assessment → Contract → Approval → Monitoring

For a high/critical supplier:

Enhanced Due Diligence → Security Assessment → Data/Access Review → DPA → Security Addendum → Assurance Evidence → Contract → Approval → Continuous Monitoring → Exit Planning

The level of due diligence should be proportionate to the supplier’s risk.


46. Common Mistakes

Avoid:

  • Signing a confidentiality agreement without identifying the information being shared.
  • Treating an NDA as a substitute for supplier security controls.
  • Sharing customer data before appropriate contractual arrangements are completed.
  • Ignoring subcontractors and subprocessors.
  • Failing to define incident notification requirements.
  • Allowing suppliers unnecessary production access.
  • Allowing suppliers to use confidential information for AI training without authorization.
  • Failing to define data retention and deletion.
  • Ignoring geographic data-location requirements.
  • Failing to revoke supplier access at termination.
  • Failing to obtain deletion/return evidence where required.
  • Allowing supplier personnel to retain information for future projects.

47. Relationship With Other ISMS Documents

DocumentRelationship
Confidentiality and Non-Disclosure PolicyDefines organizational confidentiality requirements
Supplier Confidentiality AgreementEstablishes supplier confidentiality obligations
Supplier Security RequirementsDefines required supplier security controls
Supplier Security AddendumAdds detailed contractual security requirements
Supplier Risk AssessmentDetermines supplier risk
Third-Party Due Diligence ChecklistEstablishes broader supplier due diligence
Supplier Security QuestionnaireCollects supplier security information
Supplier Security ReviewEvaluates supplier controls
Data Processing AgreementAddresses personal-data processing
Supplier Monitoring ProcedureMonitors supplier security performance
Supplier Offboarding ChecklistControls supplier exit
Contract Review ChecklistVerifies contractual security requirements

48. ISO 27001 / SOC 2 Connection

A Supplier Confidentiality Agreement supports the organization’s supplier-security framework by establishing contractual confidentiality requirements for external organizations that access organizational or customer information.

The agreement should be supported by appropriate controls such as:

  • Supplier due diligence
  • Supplier risk assessment
  • Supplier security requirements
  • Access control
  • Information classification
  • Subprocessor management
  • Security monitoring
  • Incident management
  • Business continuity
  • Data protection
  • Contract review
  • Supplier offboarding

For ISO 27001, the applicable controls and documented information should be determined through the organization’s ISMS risk assessment and applicable legal, regulatory, contractual, and customer requirements.


49. Quick Audit Checklist

☐ Supplier identified

☐ Business purpose documented

☐ Information being shared identified

☐ Information classification identified

☐ Supplier risk assessed

☐ Confidentiality agreement approved

☐ Agreement signed

☐ Need-to-know requirement established

☐ Supplier personnel controlled

☐ Subcontractors/subprocessors assessed

☐ Security requirements agreed

☐ Customer requirements considered

☐ Personal-data requirements considered

☐ Data locations considered

☐ Incident notification requirements defined

☐ Security assurance reviewed where appropriate

☐ Return/deletion requirements defined

☐ Exit requirements defined

☐ Supplier approved

☐ Evidence retained


50. Final Audit Trail

For every significant supplier relationship, the organization should be able to demonstrate:

Who is the supplier?
What service do they provide?
What confidential information is shared?
Why does the supplier need it?
What classification applies?
Who is authorized to access it?
Are subcontractors involved?
What security requirements apply?
What happens if the supplier has a security incident?
How long can the supplier retain the information?
How will information be returned or deleted?
Who approved the relationship?
What happens when the relationship ends?

Final Principle

A Supplier Confidentiality Agreement establishes the contractual obligation to protect information; effective supplier security requires that obligation to be connected to due diligence, risk assessment, access control, security requirements, monitoring, incident management, and verified supplier exit.

Legal note: This is a practical information-security template and should be reviewed by qualified legal counsel and aligned with the applicable jurisdiction, master services agreement, supplier contract, DPA, customer requirements, and regulatory obligations before execution.