1. Purpose
The Employee Confidentiality Acknowledgement records an employee’s understanding and acceptance of the organization’s confidentiality and information-protection responsibilities.
It confirms that the employee understands that information accessed during employment may be confidential, sensitive, proprietary, personal, customer-related, or security-sensitive and must be handled appropriately.
Core Principle
Access Only What You Need → Use Only for Business → Protect It → Do Not Disclose Without Authorization → Return/Delete When Required → Continue Confidentiality After Exit
2. Employee Information
| Field | Details |
|---|---|
| Employee Name | |
| Employee ID | |
| Job Title | |
| Department | |
| Manager | |
| Joining Date | |
| Work Location | |
| Employment Type | Employee / Intern / Other |
| Acknowledgement Date |
3. Confidentiality Responsibilities
I acknowledge that during my employment I may have access to information belonging to the organization, its customers, employees, suppliers, partners, or other third parties.
I understand that such information may include:
- Business information
- Financial information
- Customer information
- Personal data
- Employee information
- Source code
- Product information
- Intellectual property
- Security information
- Vulnerability information
- System architecture
- Cloud infrastructure information
- Internal procedures
- Contracts
- Pricing
- Business plans
- Product roadmaps
- Credentials and secrets
- Audit and compliance information
I agree to protect such information in accordance with applicable organizational policies, procedures, agreements, and security requirements.
4. Information Classification
I understand that information may have different classifications, such as:
☐ Public
☐ Internal
☐ Confidential
☐ Restricted
I acknowledge that the classification of information determines the level of protection and handling requirements that apply.
I will not assume that information is public merely because it has not been explicitly marked confidential.
5. Need-to-Know Access
I understand that access to Confidential and Restricted information is provided based on legitimate business need.
I agree to:
☐ Access only information required for my role.
☐ Not attempt to bypass access controls.
☐ Not access information out of curiosity.
☐ Not access another employee’s information without authorization.
☐ Not share my account with another person.
☐ Not use another person’s credentials.
☐ Report inappropriate or unexpected access.
6. Acceptable Use
I will use organizational information only for authorized business purposes.
I will not:
- Use confidential information for personal benefit;
- Use information for an unrelated purpose;
- Copy information unnecessarily;
- Download information unnecessarily;
- Transfer information to unauthorized locations;
- Disclose information to unauthorized individuals;
- Sell or commercially exploit confidential information;
- Use confidential information to benefit a competitor;
- Use organizational information for unauthorized external work.
7. Customer Information
Where I have access to customer information, I acknowledge that:
☐ Customer information must be protected.
☐ Access must be limited to legitimate business requirements.
☐ Customer information must not be copied unnecessarily.
☐ Customer information must not be shared with unauthorized persons.
☐ Customer information must not be used for personal purposes.
☐ Customer information must be handled according to contractual and organizational requirements.
8. Personal Data
Where I have access to personal data, I understand that I must:
☐ Use it only for authorized purposes.
☐ Access only the information required for my role.
☐ Avoid unnecessary copying.
☐ Avoid unauthorized disclosure.
☐ Follow applicable privacy and security requirements.
☐ Report suspected personal-data incidents.
☐ Follow retention and deletion requirements.
9. Credentials and Security Secrets
I understand that passwords, API keys, tokens, encryption keys, certificates, cloud credentials, SSH keys, and similar information are highly sensitive.
I agree to:
☐ Keep credentials confidential.
☐ Never share passwords unnecessarily.
☐ Never publish credentials.
☐ Never store secrets in public repositories.
☐ Never include secrets in source code where prohibited.
☐ Use approved secrets-management mechanisms.
☐ Report suspected credential compromise immediately.
10. Source Code and Intellectual Property
Where I have access to source code or intellectual property, I agree to:
☐ Protect it from unauthorized access.
☐ Use it only for authorized business activities.
☐ Not copy it unnecessarily.
☐ Not upload it to unauthorized repositories.
☐ Not share it externally without authorization.
☐ Not disclose proprietary technical information.
☐ Follow source-code access and repository-security requirements.
11. AI and Generative AI
I understand that confidential information must not be entered into unauthorized AI or external services.
Unless explicitly authorized, I will not submit the following to public or unapproved AI tools:
- Customer data
- Personal data
- Confidential documents
- Restricted information
- Private source code
- Security findings
- Credentials
- API keys
- Internal architecture
- Incident information
- Proprietary business information
I will use only organization-approved AI tools and services for confidential information.
12. Email and Communication
I understand that confidential information can be accidentally disclosed through email, messaging, collaboration platforms, or other communication channels.
I will:
☐ Verify recipients before sending sensitive information.
☐ Use approved communication channels.
☐ Avoid unnecessary distribution lists.
☐ Use secure transfer mechanisms where required.
☐ Avoid forwarding confidential information unnecessarily.
☐ Report accidental disclosure promptly.
13. File Sharing and Cloud Storage
I agree to use only approved storage and file-sharing services for organizational information.
I will not:
- Upload confidential information to personal cloud storage;
- Use unauthorized file-sharing services;
- Create public links for confidential information;
- Store Restricted information in unapproved locations;
- Share files with unauthorized recipients.
14. Remote Work
When working remotely, I will protect organizational information from unauthorized access.
I agree to:
☐ Use authorized devices.
☐ Use appropriate authentication.
☐ Use MFA where required.
☐ Protect my screen from unauthorized viewing.
☐ Avoid leaving confidential documents unattended.
☐ Avoid using shared/public computers for sensitive work unless authorized.
☐ Secure physical documents.
☐ Report lost or stolen devices.
15. Physical Documents
I understand that confidentiality requirements also apply to printed and physical information.
I will:
☐ Store sensitive documents securely.
☐ Avoid leaving confidential documents unattended.
☐ Use secure disposal methods.
☐ Protect documents during travel.
☐ Prevent unauthorized persons from viewing sensitive information.
16. External Disclosure
I will not disclose organizational Confidential or Restricted information to:
- Friends or family;
- Former employees;
- Competitors;
- Customers without authorization;
- Suppliers without authorization;
- Media;
- Public forums;
- Social media;
- Public repositories;
- External consultants;
- Other third parties;
unless disclosure is authorized and permitted.
17. Social Media and Public Communication
I understand that I must not publicly disclose confidential organizational information through:
- X/Twitter
- Blogs
- Forums
- Public presentations
- Public repositories
- Personal websites
- Other public channels
I will not publish internal screenshots, customer information, source code, security findings, internal documents, or other confidential information without authorization.
18. Security Information
I understand that security information can be particularly sensitive.
This may include:
- Vulnerabilities
- VAPT results
- Penetration-test reports
- Security incidents
- Security architecture
- Security configurations
- Monitoring information
- Security alerts
- Incident investigation evidence
- Unpatched vulnerabilities
I will restrict access to such information and disclose it only to authorized persons.
19. Supplier and Third-Party Information
I understand that information received from customers, suppliers, partners, consultants, and other third parties may also be confidential.
I agree to protect third-party information in accordance with:
- Contractual requirements;
- NDAs;
- Security requirements;
- Privacy requirements;
- Organizational policies.
20. Confidentiality Agreements
I acknowledge that I may be required to sign:
- Employee NDA;
- Confidentiality agreement;
- Customer confidentiality requirements;
- Supplier/third-party confidentiality requirements;
- Project-specific confidentiality agreements.
Where multiple confidentiality obligations apply, I will follow the applicable requirements.
21. Security Incidents and Accidental Disclosure
I will promptly report suspected or actual:
☐ Unauthorized disclosure
☐ Wrong-recipient email
☐ Lost confidential document
☐ Lost or stolen device
☐ Unauthorized access
☐ Public exposure of confidential information
☐ Credential compromise
☐ Source-code exposure
☐ Customer-data exposure
☐ Personal-data incident
☐ Unauthorized AI disclosure
☐ Other security incident
Reporting Channel
Security Contact: ___________________________________
Email: _____________________________________________
Incident Reporting System: ___________________________
I understand that early reporting is important and that I should not delay reporting an incident because I am uncertain whether it is serious.
22. Investigation and Evidence
I understand that the organization may need to investigate suspected confidentiality or security incidents.
Where required, I agree to reasonably cooperate with authorized investigations and preserve relevant information or evidence.
I will not:
- Delete evidence intentionally;
- Modify relevant records to conceal an incident;
- Destroy potentially relevant information after an incident is identified;
- Conduct unauthorized investigations.
23. Use of Personal Devices
Where personal devices are permitted for work, I understand that organizational information remains subject to organizational security requirements.
I agree to:
☐ Follow BYOD requirements.
☐ Use approved applications.
☐ Protect organizational information.
☐ Avoid unauthorized local storage.
☐ Report loss or theft.
☐ Follow organizational data-removal requirements.
24. Use of Removable Media
I will not copy Confidential or Restricted information to removable media unless authorized.
Where removable media is approved:
☐ Approved media shall be used.
☐ Encryption shall be used where required.
☐ Information shall be transferred securely.
☐ Media shall be protected from loss.
☐ Information shall be securely deleted when no longer required.
25. Information Retention
I understand that confidential information should not be retained longer than necessary.
I will:
☐ Follow applicable retention requirements.
☐ Delete unnecessary copies.
☐ Avoid storing information in personal locations.
☐ Follow secure disposal requirements.
☐ Preserve information where a legal hold or investigation requires retention.
26. Employee Transfer or Role Change
If my role changes, I understand that access to information may be:
- Removed;
- Modified;
- Restricted;
- Re-approved;
- Transferred to another owner.
I will not retain information or access that is no longer required for my new role.
27. Employee Exit
When my employment ends, or when access is otherwise withdrawn, I agree to:
☐ Return organizational information.
☐ Return organizational devices and media.
☐ Stop accessing organizational systems.
☐ Not retain unauthorized copies.
☐ Delete organizational information from permitted personal devices where required.
☐ Return confidential physical documents.
☐ Maintain confidentiality after leaving the organization.
☐ Cooperate with authorized exit procedures.
I understand that confidentiality obligations may continue after my employment ends.
28. Intellectual Property
I understand that organizational intellectual property must be protected.
This may include:
- Source code;
- Designs;
- Documentation;
- Algorithms;
- Product concepts;
- Research;
- Business methods;
- Technical information;
- Trade secrets.
I will not disclose or use organizational intellectual property outside authorized business purposes.
29. Continuing Confidentiality
I acknowledge that confidentiality obligations may continue after:
- Employment termination;
- Resignation;
- Retirement;
- Role change;
- Transfer;
- Contract completion;
- Access removal.
I will continue to protect information that remains confidential or legally protected.
30. Policy Compliance
I acknowledge that I am responsible for complying with applicable organizational requirements, including:
☐ Information Security Policy
☐ Confidentiality and NDA Policy
☐ Information Classification Policy
☐ Acceptable Use Policy
☐ Access Management Procedure
☐ Data Protection/Privacy Policy
☐ Remote Working Policy
☐ Incident Management Procedure
☐ Secure Disposal Procedure
☐ Other applicable security policies
31. Training and Awareness
I acknowledge that I may be required to complete information-security and confidentiality training.
Training Completed: ☐ Yes ☐ No
Training Date: ______________________________
Training/Module: ____________________________
32. Employee Declaration
I confirm that:
- I understand my confidentiality responsibilities.
- I will protect organizational and third-party information.
- I will access information only when authorized and required for my role.
- I will not disclose Confidential or Restricted information without authorization.
- I will follow applicable information-security and privacy requirements.
- I will protect credentials and security-sensitive information.
- I will report suspected confidentiality or security incidents promptly.
- I will return or securely delete organizational information when required.
- I understand that confidentiality obligations may continue after employment ends.
- I understand that violations may result in disciplinary, contractual, legal, or other appropriate action.
33. Employee Acknowledgement
Employee Name: _____________________________________
Employee ID: ________________________________________
Job Title: ___________________________________________
Department: _________________________________________
I confirm that I have read and understood this Employee Confidentiality Acknowledgement and agree to comply with the applicable confidentiality and information-security requirements.
Employee Signature: __________________________________
Date: ______________________________________________
34. Manager/HR Confirmation
I confirm that the employee has been informed of the applicable confidentiality and information-security responsibilities.
Manager/HR Name: ___________________________________
Role: _______________________________________________
Signature: __________________________________________
Date: ______________________________________________
35. Security/Compliance Confirmation
Where required:
Reviewer: ___________________________________________
Role: _______________________________________________
Review Date: ________________________________________
Comments:
Signature: __________________________________________
36. Exceptions
If an employee requires an exception to a confidentiality or information-security requirement:
☐ Business justification documented
☐ Risk assessed
☐ Compensating controls identified
☐ Appropriate approval obtained
☐ Expiry/review date defined
Exception Reference
Exception ID: ________________________________________
Approval: ____________________________________________
Expiry/Review Date: __________________________________
37. Evidence and Record Retention
The organization should retain appropriate evidence such as:
- Signed acknowledgement;
- Electronic acknowledgement;
- Employee NDA;
- Training record;
- Policy acknowledgement;
- Exception approvals;
- Relevant disciplinary/investigation records where applicable;
- Exit acknowledgement.
The organization should not retain unnecessary passwords, credentials, or other secrets as evidence.
38. Document Control
| Field | Details |
|---|---|
| Document Name | Employee Confidentiality Acknowledgement |
| Document Owner | |
| Version | |
| Effective Date | |
| Review Frequency | |
| Approved By | |
| Classification | Internal |
| Next Review Date | |
| Status | Draft / Approved / Retired |
39. AWS SaaS Startup Example
A DevOps engineer at an AWS SaaS startup has access to:
- AWS production accounts;
- GitHub repositories;
- CI/CD pipelines;
- Database systems;
- Monitoring systems;
- Customer information;
- Security findings.
The employee acknowledges that:
- Production access is limited to business need;
- AWS credentials must remain confidential;
- MFA is required;
- Source code cannot be copied to personal repositories;
- Customer information cannot be downloaded unnecessarily;
- Security findings cannot be publicly disclosed;
- Confidential information cannot be entered into unapproved AI tools;
- Access will be removed when the employee changes role or leaves;
- Confidentiality obligations continue after employment ends.
Evidence
Signed Acknowledgement → Security Training → Access Approval → Periodic Review → Role Change/Offboarding → Access Revocation → Exit Confirmation
40. Startup-Friendly Model
For a startup, this acknowledgement can be incorporated into the employee onboarding workflow.
Before Access
☐ Employment agreement completed
☐ NDA/confidentiality agreement completed
☐ Confidentiality acknowledgement completed
☐ Security training completed
☐ Required policies acknowledged
☐ Access approved
During Employment
☐ Annual security training
☐ Periodic policy acknowledgement where required
☐ Access reviews
☐ Incident reporting
☐ Role-change review
At Exit
☐ Access revoked
☐ Assets returned
☐ Information returned/deleted where required
☐ Exit acknowledgement completed
☐ Continuing confidentiality communicated
41. Common Mistakes
Avoid:
- Treating the acknowledgement as a replacement for an NDA where an NDA is required.
- Giving employees access before required confidentiality commitments are completed.
- Using the same requirements regardless of information sensitivity.
- Failing to explain what employees should actually protect.
- Ignoring customer and third-party information.
- Allowing confidential information to be entered into unapproved AI tools.
- Failing to include confidentiality obligations after termination.
- Not connecting confidentiality requirements with access management.
- Not collecting evidence of acknowledgement.
- Keeping sensitive credentials as acknowledgement evidence.
42. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Confidentiality and NDA Policy | Defines confidentiality requirements |
| Employee NDA | Establishes contractual confidentiality obligations |
| Confidentiality Requirements Matrix | Defines handling requirements by classification |
| Information Classification Policy | Defines information classification |
| Access Management Procedure | Controls employee access |
| Security Awareness Policy | Defines security awareness requirements |
| Security Training Procedure | Supports employee training |
| Employee Onboarding Checklist | Ensures confidentiality requirements are completed |
| Employee Role Change Checklist | Updates access after role changes |
| Employee Offboarding Policy | Protects information when employment ends |
| Access Revocation Checklist | Removes access |
| Incident Response Procedure | Handles confidentiality incidents |
| Asset Return Checklist | Recovers organizational assets |
43. ISO 27001 / SOC 2 Connection
The Employee Confidentiality Acknowledgement supports the organization’s personnel-security and information-protection framework.
It provides evidence that employees:
- Understand confidentiality responsibilities;
- Are informed about information-security requirements;
- Understand acceptable handling of sensitive information;
- Understand incident-reporting responsibilities;
- Understand access limitations;
- Understand post-employment confidentiality obligations.
The acknowledgement itself does not establish ISO 27001 or SOC 2 compliance. It should operate together with appropriate policies, contracts, training, access controls, monitoring, incident management, and offboarding processes.
44. Quick Audit Checklist
☐ Employee identified
☐ Employee ID recorded
☐ Role and department recorded
☐ Confidentiality responsibilities communicated
☐ Information classification explained
☐ Need-to-know explained
☐ Customer information requirements explained
☐ Personal-data requirements explained
☐ Credential protection explained
☐ Source-code protection explained
☐ AI/external-service restrictions explained
☐ Remote-work requirements explained
☐ Incident reporting explained
☐ Exit confidentiality explained
☐ Applicable policies identified
☐ Security training completed
☐ NDA completed where required
☐ Employee acknowledgement signed
☐ HR/manager confirmation completed
☐ Evidence retained
☐ Exceptions documented where applicable
45. Final Audit Trail
For each employee with access to Confidential or Restricted information, the organization should be able to demonstrate:
Who is the employee?
What information can they access?
Why do they need access?
Were confidentiality requirements communicated?
Was an NDA required?
Did the employee acknowledge the requirements?
Was security training completed?
Are access controls in place?
Do they understand customer and personal-data requirements?
Do they understand AI and external-service restrictions?
Do they know how to report an incident?
What happens when their role changes?
What happens when they leave?
Is evidence of the acknowledgement retained?
Final Principle
Confidentiality is not achieved merely by signing an NDA. Employees must understand what information they are protecting, how they are expected to handle it, what they must never disclose, how to report mistakes, and what obligations continue when their employment ends.
