ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Confidentiality Agreement Template

Confidentiality Agreement Template

Important: This is a general template for information-security and confidentiality purposes and is not legal advice. The organization should have the final agreement reviewed and adapted by qualified legal counsel for the applicable jurisdiction, employment relationship, data-protection requirements, intellectual-property provisions, and commercial terms.


1. Purpose

This Confidentiality Agreement establishes requirements for protecting confidential and proprietary information disclosed or made available between the parties.

The objective is to prevent unauthorized:

  • Access
  • Use
  • Disclosure
  • Copying
  • Modification
  • Distribution
  • Retention

of confidential information.

Core Principle

Identify → Classify → Access → Use → Protect → Share Only When Authorized → Return/Delete → Maintain Confidentiality


2. Parties

This Confidentiality Agreement (“Agreement”) is entered into between:

Disclosing Party:
Name: __________________________________________
Address: ________________________________________

and

Receiving Party:
Name: __________________________________________
Address: ________________________________________

Effective Date: _______________________________

The parties may be referred to individually as a “Party” and collectively as the “Parties.”


3. Purpose of Disclosure

Confidential Information may be disclosed solely for the following purpose:

The Receiving Party shall not use Confidential Information for purposes outside the agreed purpose unless authorized in writing.


4. Definition of Confidential Information

“Confidential Information” means non-public information disclosed or made available by the Disclosing Party, whether provided:

  • Orally
  • In writing
  • Electronically
  • Visually
  • Through system access
  • Through demonstrations
  • Through documents
  • Through source code
  • Through databases
  • Through application or cloud access
  • Through discussions or meetings

Confidential Information may include:

  • Business information
  • Customer information
  • Personal data
  • Financial information
  • Product information
  • Technical information
  • Source code
  • Software architecture
  • System configurations
  • Security information
  • Vulnerability information
  • Penetration-testing results
  • Credentials and secrets
  • API keys and tokens
  • Intellectual property
  • Trade secrets
  • Business strategies
  • Pricing information
  • Contracts
  • Internal policies and procedures
  • Employee information
  • Supplier information
  • Non-public reports
  • Documentation
  • Research and development information

5. Information Security Information

Where applicable, Confidential Information includes security-sensitive information such as:

  • Security architecture
  • Network diagrams
  • Cloud configurations
  • IAM configurations
  • Security controls
  • Vulnerability information
  • Penetration-test reports
  • Incident information
  • Incident investigation records
  • Security logs
  • Security monitoring information
  • Encryption information
  • Security assessments
  • Audit reports
  • Disaster-recovery information
  • Business-continuity information
  • Security credentials and secrets

Such information shall be protected from unauthorized disclosure or use.


6. Personal Data

Where Confidential Information contains personal data, the Receiving Party shall process such information only:

  • For an authorized purpose
  • In accordance with applicable instructions
  • In accordance with applicable privacy/data-protection requirements
  • Using appropriate security safeguards

The Receiving Party shall not use personal data for unrelated purposes.

Where required, the Parties shall enter into a separate Data Processing Agreement or other appropriate privacy arrangement.


7. Exclusions

Confidential Information does not include information that the Receiving Party can demonstrate:

  1. Was publicly available without breach of this Agreement;
  2. Was lawfully known by the Receiving Party before disclosure;
  3. Was independently developed without use of the Confidential Information;
  4. Was lawfully received from a third party without a confidentiality obligation; or
  5. Was authorized for public disclosure by the Disclosing Party.

The Receiving Party shall have appropriate evidence supporting any claimed exclusion where reasonably required.


8. Standard of Protection

The Receiving Party shall protect Confidential Information using reasonable and appropriate administrative, technical, and physical safeguards.

The Receiving Party shall apply a level of protection appropriate to:

  • Sensitivity
  • Business impact
  • Information classification
  • Security risk
  • Applicable legal requirements
  • Contractual requirements

9. Authorized Access

Access to Confidential Information shall be limited to persons who:

  • Have a legitimate business need
  • Are authorized to access the information
  • Are subject to appropriate confidentiality obligations
  • Have received appropriate security requirements where applicable

The Receiving Party shall not provide access to unauthorized individuals.


10. Least Privilege

Where systems or repositories containing Confidential Information are accessed, the Receiving Party shall use the minimum access necessary to perform the agreed purpose.

Access shall not be broader than reasonably required.


11. Credential Protection

Where access credentials are provided, the Receiving Party shall:

  • Protect credentials
  • Not share passwords
  • Not share MFA codes
  • Protect API keys
  • Protect access tokens
  • Protect private keys
  • Follow applicable authentication requirements
  • Report suspected credential compromise promptly

Credentials shall not be included in documents or communications unnecessarily.


12. Use Restrictions

The Receiving Party shall not, without authorization:

  • Copy Confidential Information unnecessarily
  • Modify Confidential Information
  • Publish Confidential Information
  • Sell Confidential Information
  • Distribute Confidential Information
  • Use Confidential Information for personal benefit
  • Use Confidential Information for a competing purpose
  • Upload Confidential Information to unauthorized services
  • Disclose Confidential Information to unauthorized third parties

13. Source Code

Where source code is disclosed, the Receiving Party shall:

  • Protect source code from unauthorized access
  • Use approved repositories where applicable
  • Not copy source code unnecessarily
  • Not disclose source code to unauthorized persons
  • Not publish source code
  • Protect repository credentials
  • Protect embedded secrets
  • Follow applicable intellectual-property requirements

Additional software/IP terms may be included where required.


14. Customer Information

Where customer information is provided, the Receiving Party shall:

  • Use it only for the agreed purpose
  • Follow customer-specific restrictions
  • Protect it from unauthorized disclosure
  • Limit access to authorized personnel
  • Follow applicable retention requirements
  • Return or delete it when required

15. Information Sharing

Before sharing Confidential Information with another party, the Receiving Party shall verify that:

  • Sharing is necessary
  • The recipient is authorized
  • The recipient has appropriate confidentiality obligations
  • Applicable contractual requirements are satisfied
  • Appropriate security controls are in place

16. Third-Party Disclosure

The Receiving Party shall not disclose Confidential Information to subcontractors, consultants, suppliers, or other third parties without appropriate authorization.

Where third-party disclosure is authorized, the Receiving Party shall ensure appropriate confidentiality and security obligations are established.


17. Government or Legal Disclosure

If the Receiving Party is legally required to disclose Confidential Information, it may make the required disclosure to the extent legally permitted.

Where legally permitted, the Receiving Party shall:

  • Notify the Disclosing Party promptly
  • Provide reasonable cooperation
  • Limit disclosure to the information legally required
  • Take reasonable steps to protect the confidentiality of the disclosed information

18. Security Incident Notification

The Receiving Party shall promptly notify the Disclosing Party of any actual or suspected:

  • Unauthorized access
  • Unauthorized disclosure
  • Loss
  • Theft
  • Accidental disclosure
  • Credential compromise
  • Data breach
  • Security incident affecting Confidential Information

Notification Contact

Name/Team: _______________________________

Email: ____________________________________

Phone: ____________________________________

The Agreement may specify a more precise contractual notification period where required.


19. Security Incident Cooperation

Following a security incident involving Confidential Information, the Receiving Party shall reasonably cooperate with the Disclosing Party in:

  • Investigation
  • Evidence preservation
  • Impact assessment
  • Containment
  • Remediation
  • Regulatory assessment
  • Customer notification where applicable
  • Corrective action

The parties shall coordinate responsibilities according to applicable agreements and law.


20. Security Controls

Where appropriate to the nature of the relationship, the Receiving Party shall maintain safeguards such as:

☐ Access control
☐ MFA
☐ Encryption
☐ Endpoint protection
☐ Secure storage
☐ Secure transmission
☐ Logging and monitoring
☐ Vulnerability management
☐ Security awareness
☐ Backup protection
☐ Incident response
☐ Secure disposal

Specific security requirements may be established through a separate Security Addendum or contract.


21. Remote Access

Where Confidential Information is accessed remotely, the Receiving Party shall:

  • Use approved access methods
  • Protect authentication credentials
  • Use MFA where required
  • Protect devices
  • Prevent unauthorized viewing
  • Use secure communication channels
  • Follow applicable remote-access requirements

22. Cloud and SaaS Services

Confidential Information shall not be uploaded to external cloud or SaaS services unless:

  • The service is authorized;
  • The use is necessary;
  • Appropriate security controls exist; and
  • Applicable contractual/privacy requirements are satisfied.

23. Artificial Intelligence and Generative AI

The Receiving Party shall not submit Confidential Information to public or unauthorized AI/generative-AI services unless expressly authorized.

This includes:

  • Source code
  • Customer information
  • Personal data
  • Security findings
  • Credentials
  • Internal documentation
  • Trade secrets
  • Restricted business information

Where AI services are authorized, their applicable security, privacy, retention, and data-use requirements shall be assessed.


24. Physical Protection

Where Confidential Information exists in physical form, the Receiving Party shall protect it against:

  • Unauthorized access
  • Loss
  • Theft
  • Unauthorized copying
  • Unauthorized photography
  • Unauthorized disposal

Physical documents shall be stored and disposed of appropriately.


25. Information Transmission

When transmitting Confidential Information, the Receiving Party shall use appropriate secure methods.

Where appropriate:

  • Encryption shall be used.
  • Recipient identity shall be verified.
  • Access restrictions shall be applied.
  • Unnecessary information shall not be transmitted.
  • Transmission records shall be maintained where required.

26. Return of Information

Upon request by the Disclosing Party, or upon completion or termination of the relevant relationship, the Receiving Party shall, as applicable:

  • Return Confidential Information;
  • Delete or securely destroy Confidential Information;
  • Remove unauthorized copies;
  • Return storage media;
  • Return Company/customer assets;
  • Confirm completion where reasonably required.

27. Backup Copies

Where Confidential Information exists in routine system backups, deletion may occur according to the applicable backup-retention cycle where immediate deletion is technically impractical.

Such information shall remain protected and shall not be restored or used except for legitimate recovery or other authorized purposes.


28. Evidence of Return or Destruction

Where required, the Receiving Party may provide reasonable confirmation that Confidential Information has been returned or securely destroyed.

Confirmation Method: ________________________

Date: _______________________________________

Authorized Person: ___________________________


29. Intellectual Property

Nothing in this Agreement shall be interpreted as transferring ownership of intellectual property unless expressly stated in a separate written agreement.

Confidentiality does not by itself grant the Receiving Party ownership or unrestricted rights to use the Disclosing Party’s intellectual property.


30. No License

Disclosure of Confidential Information does not grant the Receiving Party any license or other intellectual-property right except the limited right to use the information for the agreed purpose.


31. Ownership

All Confidential Information remains the property of the Disclosing Party or its applicable owner, subject to applicable contractual arrangements.


32. Confidentiality of the Relationship

Where appropriate, the existence and nature of the business relationship may itself be treated as Confidential Information.

☐ Applicable

☐ Not Applicable


33. Duration of Confidentiality

The confidentiality obligations shall apply:

Commencement Date: __________________________

Confidentiality Period: _______________________

The applicable duration should be determined based on the nature of the information and applicable law.

For trade secrets or information requiring continuing protection, confidentiality may continue for as long as the information remains legally protected or confidential, subject to applicable law.


34. Obligations After Termination

Termination of the relationship shall not automatically terminate confidentiality obligations that are intended to continue after termination.

The Receiving Party shall continue to protect Confidential Information according to the applicable survival provisions of this Agreement.


35. Employee and Personnel Access

The Receiving Party shall ensure that personnel who require access to Confidential Information:

  • Have a legitimate business need;
  • Are appropriately authorized;
  • Are subject to confidentiality obligations;
  • Understand relevant security requirements.

36. Subcontractors

Where subcontractors are permitted, the Receiving Party shall ensure that applicable subcontractors are subject to confidentiality and security obligations that appropriately protect the Confidential Information.

The Receiving Party remains responsible for its contractual obligations concerning such information, subject to the applicable agreement.


37. Audit or Assurance

Where appropriate and contractually agreed, the Disclosing Party may request reasonable information or evidence demonstrating compliance with applicable confidentiality and security requirements.

Such activities shall be proportionate to the relationship and applicable contractual requirements.


38. Non-Compliance

Suspected material breaches of this Agreement shall be promptly escalated through the appropriate business, security, HR, or legal channels.

Corrective actions may include:

  • Access restriction
  • Credential revocation
  • Information recovery
  • Investigation
  • Remediation
  • Contractual action
  • Other remedies available under the applicable agreement and law

39. Security Exceptions

No employee, contractor, or representative may independently waive confidentiality or security requirements.

Exceptions shall require appropriate authorization and shall be documented where applicable.


40. Compliance With Law

The Parties shall comply with applicable laws and regulations relevant to Confidential Information.

Where personal data is involved, applicable privacy and data-protection requirements shall be addressed separately where necessary.


41. Governing Law

Governing Law: _______________________________

Jurisdiction: _________________________________

Dispute Resolution: ___________________________

These provisions should be finalized by qualified legal counsel.


42. Notices

Formal notices under this Agreement shall be provided to:

Disclosing Party

Name: ______________________________________

Email: ______________________________________

Address: ____________________________________

Receiving Party

Name: ______________________________________

Email: ______________________________________

Address: ____________________________________


43. Entire Agreement

This Agreement represents the Parties’ understanding concerning confidentiality for the agreed purpose, subject to any applicable master agreement, employment agreement, data-processing agreement, security addendum, or other contractual documents.

Where documents conflict, the applicable contractual precedence provisions shall apply.


44. Amendment

Any amendment to this Agreement shall be made in accordance with the agreed contractual process.


45. Severability

If any provision of this Agreement is determined to be invalid or unenforceable, the remaining provisions shall continue to apply to the extent permitted by applicable law.


46. Signatures

Disclosing Party

Legal Name: __________________________________

Authorized Representative: ____________________

Title: ________________________________________

Signature: ____________________________________

Date: ________________________________________


Receiving Party

Legal Name: __________________________________

Authorized Representative: ____________________

Title: ________________________________________

Signature: ____________________________________

Date: ________________________________________


47. Employee NDA Variant

For employees, the following additional statement may be incorporated:

Employee Confidentiality Responsibility

During employment, the Employee may receive access to confidential, proprietary, customer, personal, technical, security, financial, or business information. The Employee shall use such information only for authorized business purposes, protect it against unauthorized access or disclosure, and comply with the Company’s information-security and data-protection requirements.

The Employee shall not intentionally disclose, copy, transfer, publish, or use confidential information outside authorized business purposes.

These responsibilities may continue after termination of employment to the extent provided by applicable agreements and law.


48. Contractor / Consultant Variant

For contractors and consultants:

The Contractor/Consultant shall access Confidential Information only to the extent necessary to perform the agreed services and shall protect such information in accordance with this Agreement and applicable security requirements.

The Contractor/Consultant shall not disclose Confidential Information to any third party without appropriate authorization and shall ensure that approved personnel are subject to appropriate confidentiality obligations.

Upon completion or termination of the engagement, the Contractor/Consultant shall return or securely delete Confidential Information and Company assets as required.


49. AWS SaaS Startup Example

For an AWS-based SaaS startup, a confidentiality agreement with a VAPT provider may cover:

  • Application architecture
  • AWS architecture
  • Security configurations
  • Test credentials
  • Vulnerability findings
  • Penetration-test results
  • Source-code information
  • Customer-data exposure
  • Security reports
  • Incident information

Additional requirements may include:

NDA → Authorized Scope → Named Testers → MFA → Limited Access → Secure Testing → Secure Report Delivery → Incident Notification → Access Revocation → Information Return/Deletion

Test credentials should be temporary and should not be included unnecessarily in the NDA itself.


50. Startup-Friendly Confidentiality Model

A startup can maintain a simple confidentiality lifecycle:

Before Access

  • Identify information
  • Classify sensitivity
  • Establish confidentiality obligations
  • Approve access

During Access

  • Least privilege
  • Secure authentication
  • Approved systems
  • Secure transfer
  • No unauthorized sharing

When Sharing

  • Verify recipient
  • Confirm business need
  • Confirm authorization
  • Use approved transfer mechanism

When Relationship Ends

  • Revoke access
  • Return/delete information
  • Address credentials and tokens
  • Confirm completion where required
  • Retain appropriate evidence

Identify → Protect → Share Carefully → Return/Delete → Evidence


51. Common Mistakes

Avoid:

  • Using one generic NDA without considering the relationship.
  • Failing to define the purpose of disclosure.
  • Failing to identify customer or personal data.
  • Allowing unrestricted access to confidential information.
  • Sharing credentials through the NDA process.
  • Treating an NDA as a substitute for security controls.
  • Ignoring subcontractors.
  • Ignoring cloud/SaaS services.
  • Ignoring AI/generative-AI use.
  • Failing to define incident notification.
  • Failing to address return/deletion.
  • Failing to address confidentiality after termination.
  • Storing unnecessary copies of confidential information.
  • Assuming signing an NDA automatically prevents a security incident.

52. Relationship With Other ISMS Documents

DocumentRelationship
Human Resources Security PolicyDefines personnel-security requirements
Employee Security ResponsibilitiesDefines employee security duties
Employment Security Clause TemplateEstablishes employment security terms
Employee Screening PolicyDefines screening requirements
Access Management ProcedureControls access to information
Information Classification PolicyDefines information sensitivity
Information Transfer ProcedureControls information sharing
Data Protection PolicyAddresses personal-data protection
Data Processing AgreementDefines applicable processing requirements
Supplier Security AddendumDefines supplier security requirements
Supplier Security RequirementsEstablishes supplier expectations
Incident Response ProcedureHandles confidentiality/security incidents
Asset Return ProcedureControls return of organizational assets
Employee Offboarding ProcedureControls termination
Security Policy Acknowledgement RegisterRecords acknowledgement

53. ISO/IEC 27001 Connection

A confidentiality agreement supports the organization’s protection of information through appropriate confidentiality obligations for personnel and relevant external parties.

It may support areas concerning:

  • Confidentiality
  • Information protection
  • Personnel responsibilities
  • Access control
  • Supplier relationships
  • Information transfer
  • Privacy
  • Intellectual-property protection
  • Secure termination/offboarding

The Confidentiality Agreement is not itself a universally prescribed ISO/IEC 27001 document or mandatory template. The organization should determine when confidentiality agreements or equivalent contractual provisions are required based on its risk assessment, information sensitivity, personnel relationships, supplier relationships, legal requirements, and contractual obligations.


54. Audit Evidence Checklist

The organization should be able to demonstrate, where applicable:

☐ Approved NDA template
☐ Signed confidentiality agreements
☐ Employee confidentiality clauses
☐ Contractor confidentiality agreements
☐ Supplier confidentiality agreements
☐ Customer confidentiality agreements
☐ Confidentiality requirements communicated
☐ Information classification
☐ Authorized access
☐ Access approvals
☐ Incident notifications
☐ Information return/deletion records
☐ Offboarding records
☐ Subcontractor confidentiality requirements
☐ Security exceptions
☐ Agreement review records

Sensitive credentials and secrets should not be retained as NDA evidence.


55. Final Confidentiality Audit Trail

For significant confidential-information relationships, the organization should be able to demonstrate:

What confidential information is being shared?
Why is it being shared?
Who is authorized to access it?
Are appropriate confidentiality obligations established?
Are security requirements defined?
Is access limited to the required scope?
How is the information protected?
How are incidents reported?
Are subcontractors controlled?
What happens when the relationship ends?
Is information returned or deleted where required?
Is appropriate evidence retained?

Final Principle

An NDA establishes a legal confidentiality obligation, but confidentiality is not achieved by the signature alone. Effective protection requires the agreement to be supported by appropriate access control, information classification, secure handling, security awareness, incident reporting, technical safeguards, and controlled return or deletion of information.