1. Purpose
The Confidentiality and Non-Disclosure Policy establishes requirements for protecting confidential, sensitive, proprietary, personal, customer, security, and other non-public information from unauthorized access, disclosure, use, copying, transfer, or retention.
The policy defines how confidentiality obligations apply to employees, contractors, consultants, temporary workers, suppliers, partners, and other parties who may have access to organizational information.
Core Principle
Identify → Classify → Authorize → Protect → Share Carefully → Monitor → Return/Delete → Maintain Confidentiality
2. Scope
This policy applies to:
- Employees
- Contractors
- Consultants
- Interns
- Temporary workers
- Supplier personnel
- Business partners
- Service providers
- Advisors
- Auditors
- Other third parties
It applies to information in:
- Paper documents
- Chat and collaboration platforms
- Source-code repositories
- Databases
- Cloud platforms
- SaaS applications
- File-storage systems
- Customer environments
- Mobile devices
- Laptops and workstations
- Removable media
- Backups
- Logs
- Printed material
- Verbal communications
- Other information-storage or communication methods
3. Policy Objectives
The organization shall:
- Identify information requiring confidentiality protection.
- Define confidentiality responsibilities.
- Restrict information access to authorized individuals.
- Use appropriate contractual protections.
- Protect information during storage and transmission.
- Control information sharing with external parties.
- Prevent unauthorized copying and disclosure.
- Address confidentiality during onboarding, role changes, and offboarding.
- Protect customer and personal information.
- Manage confidentiality exceptions.
- Monitor and investigate suspected unauthorized disclosure.
- Maintain evidence of relevant confidentiality obligations.
4. Information Covered
Confidentiality requirements may apply to:
Business Information
- Business plans
- Financial information
- Pricing
- Strategy
- Contracts
- Commercial information
- Supplier information
- Customer information
- Sales information
- Product roadmaps
Technical Information
- Source code
- Architecture
- Infrastructure configuration
- Cloud configuration
- Database information
- API specifications
- CI/CD configuration
- Technical documentation
- System credentials
- Security configurations
Security Information
- Vulnerability information
- Penetration-test results
- Security assessments
- Incident information
- Security logs
- Threat information
- Security architecture
- Encryption information
- Security procedures
Personal and Customer Information
- Personal data
- Customer records
- Employee information
- Financial information
- Authentication information
- Support records
- Customer communications
5. Information Classification
Information shall be classified according to the organization’s approved information-classification scheme.
Example classifications:
| Classification | Description | Typical Protection |
|---|---|---|
| Public | Approved for public disclosure | Normal business controls |
| Internal | Intended for internal use | Authorized workforce access |
| Confidential | Unauthorized disclosure could cause harm | Restricted access and controlled sharing |
| Restricted | Highly sensitive or regulated information | Strict access, enhanced controls, monitoring |
The organization may use different classification names where defined by its information-classification policy.
6. Confidentiality Responsibilities
Individuals with access to confidential information shall:
- Use information only for authorized business purposes.
- Access only information required for their role.
- Protect information from unauthorized disclosure.
- Avoid unnecessary copying.
- Use approved communication and storage systems.
- Follow information-classification requirements.
- Follow secure-transfer requirements.
- Report suspected disclosure or loss.
- Return or delete information when instructed.
- Continue to protect information after their engagement ends where applicable.
7. Need-to-Know Principle
Access to confidential information shall be based on business need.
Individuals shall not access information simply because they technically can.
Access should be:
- Authorized
- Role-appropriate
- Limited to business requirements
- Reviewed periodically
- Removed when no longer required
Principle
Need to know, not merely ability to access.
8. Confidentiality Agreements
Where appropriate, the organization shall establish confidentiality obligations through:
- Employment agreements
- Confidentiality clauses
- Non-Disclosure Agreements (NDAs)
- Contractor agreements
- Supplier agreements
- Data Processing Agreements
- Customer agreements
- Partner agreements
- Security agreements
The appropriate agreement should be determined based on the relationship, information involved, legal requirements, and risk.
9. Employee Confidentiality
Employees shall be informed of their confidentiality responsibilities as part of onboarding.
Where applicable, employees shall acknowledge:
☐ Confidentiality obligations
☐ Information-classification requirements
☐ Acceptable-use requirements
☐ Data-protection responsibilities
☐ Security responsibilities
☐ Reporting obligations
Confidentiality obligations may continue after employment ends where required by applicable agreements, law, or organizational requirements.
10. Contractor Confidentiality
Contractors and consultants shall be subject to appropriate confidentiality requirements before receiving access to confidential information.
Where applicable:
☐ NDA executed
☐ Contractual confidentiality clause included
☐ Information-access scope defined
☐ Customer confidentiality requirements addressed
☐ Data-protection requirements addressed
☐ Access limited to business need
☐ Exit requirements defined
Contractors shall not retain confidential organizational information after their engagement ends unless specifically authorized.
11. Supplier and Third-Party Confidentiality
Before sharing confidential information with suppliers or other third parties, the organization shall determine whether appropriate contractual protections are required.
Consider:
- NDA
- Confidentiality clause
- Supplier security agreement
- Data Processing Agreement
- Customer contractual requirements
- Data-location requirements
- Subprocessor requirements
Confidential information shall only be shared with authorized third parties for approved purposes.
12. Customer Information
Customer information shall be treated according to:
- Contractual requirements
- Information classification
- Privacy requirements
- Security requirements
- Applicable laws and regulations
Employees, contractors, and suppliers shall not disclose customer information outside authorized business purposes.
Customer information shall not be used for personal purposes, unauthorized testing, marketing, training, demonstrations, or other activities without appropriate authorization.
13. Personal Data
Personal data shall be handled according to applicable privacy requirements and the organization’s privacy and information-security procedures.
Individuals shall:
- Access only required personal data.
- Avoid unnecessary copying.
- Use approved storage systems.
- Use approved transfer mechanisms.
- Prevent unauthorized disclosure.
- Report suspected personal-data incidents.
Additional contractual or regulatory requirements may apply depending on the nature and location of the data.
14. Source Code Confidentiality
Source code shall be treated according to its classification and business sensitivity.
Employees and contractors shall:
☐ Use approved repositories
☐ Use authorized accounts
☐ Avoid unauthorized copies
☐ Avoid uploading source code to personal repositories
☐ Avoid sharing source code through unauthorized channels
☐ Protect repository credentials
☐ Follow open-source requirements
☐ Follow customer contractual restrictions
Source code shall not be disclosed to external parties without authorization.
15. Security and Vulnerability Information
Security-sensitive information shall receive appropriate protection.
Examples include:
- Vulnerability reports
- Penetration-test results
- Security weaknesses
- Incident reports
- Security architecture
- Security configurations
- Credentials
- Encryption details
- Threat intelligence
- Security monitoring information
Such information shall not be shared publicly or with unauthorized parties.
16. Credentials and Secrets
Credentials and secrets shall receive enhanced protection.
Examples include:
- Passwords
- API keys
- Access tokens
- SSH keys
- Cloud credentials
- Encryption keys
- Certificates
- Recovery codes
- Service-account credentials
Individuals shall:
- Never disclose credentials unnecessarily.
- Never share personal credentials.
- Use approved secret-management systems.
- Avoid storing secrets in source code.
- Avoid sending secrets through unsecured channels.
- Report suspected credential disclosure immediately.
Actual credentials shall never be included in confidentiality records or audit evidence.
17. Verbal Confidentiality
Confidential information may also be disclosed verbally.
Individuals shall take appropriate precautions during:
- Meetings
- Phone calls
- Video conferences
- Customer discussions
- Public events
- Conferences
- Travel
- Shared workspaces
Confidential discussions should not be conducted where unauthorized individuals can reasonably overhear them.
18. Email and Messaging
Confidential information sent through email or messaging systems shall use approved organizational channels.
Before sending confidential information, the sender should verify:
- Recipient identity
- Recipient authorization
- Correct email address
- Required attachments
- Information classification
- Need-to-know
- Appropriate encryption or secure-transfer mechanism where required
Avoid sending confidential information to personal email accounts unless explicitly authorized.
19. File Sharing
Confidential information shall be shared using approved systems.
Examples:
- Approved cloud storage
- Secure file-transfer systems
- Approved collaboration platforms
- Customer-approved portals
- Controlled document repositories
Public or unrestricted file-sharing links shall not be used for confidential or restricted information unless specifically approved and appropriately controlled.
20. External Disclosure
Confidential information shall not be disclosed externally without appropriate authorization.
Examples of external disclosure include:
- Customers
- Suppliers
- Partners
- Investors
- Consultants
- Media
- Public websites
- Social media
- Conferences
- Public repositories
- Online forums
- AI tools or external services
The individual shall confirm that the recipient is authorized to receive the information before disclosure.
21. Public Disclosure
Confidential or restricted information shall not be published through:
- Websites
- Social media
- Blogs
- Public repositories
- Public forums
- Presentations
- Marketing materials
- Press releases
- Public documents
unless it has gone through the organization’s approved disclosure process.
22. Use of AI and External Services
Employees and contractors shall not submit confidential, restricted, customer, personal, source-code, security, or proprietary information to external AI tools or other third-party services unless the service and use case have been approved.
Before using an external AI service, consider:
☐ Information classification
☐ Customer restrictions
☐ Privacy requirements
☐ Contractual restrictions
☐ Data retention
☐ Provider use of submitted information
☐ Security controls
☐ Organizational approval
Principle
Do not assume that an AI or online service is approved merely because it is publicly available.
23. Remote Working
Confidential information accessed remotely shall be protected against unauthorized disclosure.
Individuals shall:
- Use approved devices where required.
- Protect screens from unauthorized viewing.
- Use secure networks.
- Avoid discussing confidential matters in public places.
- Use approved collaboration tools.
- Secure physical documents.
- Protect devices from unauthorized access.
24. Physical Documents
Confidential documents shall be appropriately protected.
Individuals shall:
☐ Avoid leaving confidential documents unattended
☐ Store documents securely
☐ Limit printing
☐ Collect printed documents promptly
☐ Dispose of documents securely
☐ Prevent unauthorized viewing
☐ Follow clean-desk requirements where applicable
25. Removable Media
Confidential information should not be copied to removable media unless authorized and necessary.
Where removable media is approved:
- Use organization-approved devices.
- Apply encryption where required.
- Restrict access.
- Track sensitive transfers where appropriate.
- Securely erase or dispose of media when no longer required.
26. Information Transfer
Before transferring confidential information externally, verify:
☐ Business purpose
☐ Recipient authorization
☐ Information classification
☐ Data minimization
☐ Approved transfer method
☐ Encryption where required
☐ Contractual requirements
☐ Privacy requirements
☐ Transfer records where appropriate
Refer to the organization’s Information Transfer Procedure where applicable.
27. Third-Party Disclosure
When confidential information is shared with a third party:
- Confirm business need.
- Confirm authorization.
- Confirm confidentiality obligations.
- Identify the information being shared.
- Confirm classification.
- Use approved transfer mechanisms.
- Limit the information to what is necessary.
- Record the disclosure where required.
28. Subprocessors and Subcontractors
Where a supplier uses subprocessors or subcontractors that may access confidential information:
☐ Subprocessor identified
☐ Business purpose identified
☐ Information accessed identified
☐ Confidentiality obligations assessed
☐ Contractual requirements addressed
☐ Security requirements addressed
☐ Approval obtained where required
29. Information Retention
Confidential information shall not be retained longer than necessary unless retention is required by:
- Law
- Regulation
- Contract
- Legal hold
- Business requirement
- Security requirement
- Approved records-retention schedule
When information is no longer required, it should be securely deleted, destroyed, or returned according to applicable requirements.
30. Information Return
When requested or when a relationship ends, individuals and third parties shall return organizational information where required.
Examples include:
- Documents
- Source code
- Customer records
- Reports
- Security information
- Business records
- Portable media
- Physical documents
Return requirements should be documented where appropriate.
31. Secure Deletion
Where deletion is required:
☐ Data identified
☐ Deletion authorized
☐ Appropriate deletion method selected
☐ Backups considered
☐ Copies considered
☐ Third-party copies considered
☐ Deletion evidence obtained where appropriate
Information shall not be destroyed where it is subject to a legitimate legal, regulatory, contractual, or investigation-related preservation requirement.
32. Employee and Contractor Exit
Confidentiality obligations shall be addressed during offboarding.
The organization should:
☐ Revoke access
☐ Recover assets
☐ Address organizational information
☐ Address customer information
☐ Address source code
☐ Address credentials
☐ Confirm confidentiality obligations
☐ Address return/deletion requirements
☐ Obtain exit acknowledgement where appropriate
Individuals shall not retain confidential organizational information after their authorization ends unless specifically permitted.
33. Privileged Users
Additional confidentiality controls may apply to privileged users who have access to:
- Production systems
- Security systems
- Cloud administration
- Databases
- Source code
- Encryption keys
- Security monitoring
- Customer environments
Privileged-user offboarding shall follow the organization’s Privileged User Offboarding Checklist.
34. Security Incident and Confidentiality Breach
A suspected unauthorized disclosure shall be treated as a security event and assessed according to the organization’s incident-management process.
Examples include:
- Email sent to the wrong recipient
- Lost confidential document
- Accidental public disclosure
- Source code uploaded to a public repository
- Customer data sent to an unauthorized party
- Confidential information shared with an unapproved AI service
- Lost laptop containing confidential information
- Unauthorized copying
- Deliberate disclosure
Individuals shall report suspected confidentiality breaches immediately through the designated security reporting process.
35. Confidentiality Breach Response
Where a confidentiality incident occurs, the organization may:
- Identify the information involved.
- Determine the affected individuals or systems.
- Assess the classification and sensitivity.
- Contain the disclosure.
- Revoke access where required.
- Recover or delete information where possible.
- Assess privacy and contractual impact.
- Preserve evidence.
- Notify affected parties where required.
- Perform root-cause analysis.
- Implement corrective actions.
- Record lessons learned.
36. Monitoring
The organization may monitor appropriate systems and activities to protect confidential information, subject to applicable law and organizational requirements.
Monitoring may include:
- Access logs
- File-sharing activity
- Data-transfer activity
- Repository activity
- Administrative activity
- Security alerts
- DLP controls where implemented
- Cloud activity
- Email-security controls
- Endpoint-security controls
Monitoring shall be performed according to applicable policies and legal requirements.
37. Confidentiality Exceptions
Exceptions to this policy require appropriate authorization.
Examples may include:
- Legal disclosure
- Regulatory disclosure
- Law-enforcement request
- Customer-approved disclosure
- Contractually required disclosure
- Approved public disclosure
- Security testing
- Approved research
Exception Record
| Exception | Information | Reason | Approver | Expiry | Status |
|---|---|---|---|---|---|
38. Roles and Responsibilities
Management
Management shall:
- Support confidentiality requirements.
- Define appropriate information-classification requirements.
- Ensure contractual protections are used where appropriate.
- Support enforcement of confidentiality requirements.
Information Security
Information Security shall:
- Define security requirements.
- Support confidentiality risk assessment.
- Monitor relevant security controls.
- Investigate suspected confidentiality breaches.
- Maintain related security procedures.
HR/People Team
HR/People shall:
- Include confidentiality requirements in applicable employment processes.
- Coordinate confidentiality acknowledgements.
- Support employee offboarding.
- Maintain applicable personnel records.
Procurement/Supplier Management
Procurement/Supplier Management shall:
- Identify supplier confidentiality requirements.
- Ensure appropriate contractual protections.
- Coordinate supplier confidentiality obligations.
Managers
Managers shall:
- Approve appropriate access.
- Ensure employees understand confidentiality requirements.
- Limit information access to business need.
- Support offboarding and information return.
Employees and Contractors
Individuals shall:
- Protect confidential information.
- Follow classification requirements.
- Use approved systems.
- Report suspected disclosure.
- Follow return and deletion instructions.
- Maintain confidentiality after exit where applicable.
39. Training and Awareness
Personnel with access to confidential information shall receive appropriate security awareness and confidentiality training.
Training may cover:
- Information classification
- Secure information handling
- Phishing
- Email security
- Data protection
- Secure file sharing
- AI and external service usage
- Clean desk
- Remote working
- Incident reporting
- Confidentiality obligations
Training shall be appropriate to the individual’s role and risk.
40. Enforcement
Failure to comply with this policy may result in:
- Access restriction
- Corrective action
- Additional training
- Investigation
- Disciplinary action
- Contractual action
- Supplier corrective action
- Termination of access
- Termination of employment or contract where appropriate
- Legal action where applicable
Actions shall be consistent with applicable law, contracts, and organizational procedures.
41. Policy Exceptions
Any exception to this policy shall:
- Have a documented business justification.
- Identify the information and risk involved.
- Identify compensating controls where appropriate.
- Have an accountable owner.
- Have an approved expiration date.
- Be reviewed periodically.
Exceptions should be recorded in the organization’s Information Security Exception Register.
42. Records and Evidence
The organization may retain evidence such as:
☐ Signed NDAs
☐ Employment confidentiality clauses
☐ Contractor agreements
☐ Supplier agreements
☐ Security acknowledgements
☐ Training records
☐ Information-transfer records
☐ Confidentiality exceptions
☐ Incident records
☐ Information-return records
☐ Secure-deletion evidence
☐ Offboarding records
☐ Access-revocation evidence
Records shall be protected according to their classification.
43. Policy Review
This policy shall be reviewed periodically and when significant changes occur, including:
- Major organizational changes
- New regulatory requirements
- New customer requirements
- Significant security incidents
- Major technology changes
- Changes to information-classification requirements
- Changes to contractual obligations
- Changes to business operations
Review Frequency
At least: Annually, unless a shorter period is required by the organization’s risk or compliance requirements.
44. Policy Approval
Policy Owner: ______________________________
Information Security Owner: __________________
Approved By: _______________________________
Version: ___________________________________
Effective Date: _____________________________
Review Date: _______________________________
Approval Date: ______________________________
45. Quick Audit Checklist
☐ Confidentiality policy approved
☐ Information classification defined
☐ Need-to-know principle implemented
☐ Employee confidentiality obligations defined
☐ Contractor confidentiality obligations defined
☐ Supplier confidentiality requirements defined
☐ NDA process defined
☐ Customer information protected
☐ Personal data requirements addressed
☐ Source-code confidentiality addressed
☐ Security information protected
☐ Credentials/secrets protected
☐ External disclosure controlled
☐ AI/external service use addressed
☐ Information transfer controlled
☐ Information retention defined
☐ Return/deletion requirements defined
☐ Offboarding confidentiality addressed
☐ Confidentiality incident reporting defined
☐ Exceptions controlled
☐ Training provided
☐ Records retained
☐ Policy reviewed periodically
46. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Classification Policy | Defines information classification |
| Information Handling Procedure | Defines secure information handling |
| Information Transfer Procedure | Controls information transfers |
| Acceptable Use Policy | Defines acceptable use of organizational resources |
| Data Protection/Privacy Policy | Addresses personal-data protection |
| Employee Security Responsibilities | Defines personnel responsibilities |
| Employee Offboarding Policy | Addresses employee exit |
| Contractor Offboarding Procedure | Addresses contractor exit |
| Exit Security Acknowledgement | Records continuing security obligations |
| Supplier Security Requirements | Defines third-party security requirements |
| Supplier Security Agreement | Establishes contractual security obligations |
| Access Management Procedure | Controls access to information |
| Incident Response Procedure | Handles confidentiality incidents |
| Information Security Exception Register | Records approved exceptions |
| Security Awareness Policy | Supports confidentiality awareness |
47. ISO 27001 / SOC 2 Connection
This policy supports the organization’s protection of information through confidentiality requirements, access control, information handling, personnel security, supplier relationships, information transfer, incident management, and contractual controls.
For ISO 27001, the specific controls and evidence applicable to the organization should be determined through the organization’s risk assessment and Statement of Applicability.
For SOC 2, the policy can provide supporting evidence that confidentiality responsibilities are formally defined and communicated to personnel and relevant third parties.
The policy should operate together with the organization’s information-classification, access-control, supplier-management, privacy, incident-management, and offboarding processes.
48. Final Audit Trail
For confidential information, the organization should be able to demonstrate:
What information requires confidentiality protection?
How is the information classified?
Who is authorized to access it?
Why does the person need access?
What contractual confidentiality obligations apply?
How is information protected during storage and transfer?
How are external disclosures controlled?
How are customer and personal information protected?
How are source code, security information, and credentials protected?
What happens when an employee or contractor leaves?
How are confidentiality breaches reported and investigated?
How are exceptions approved?
What evidence demonstrates that confidentiality requirements are operating?
Final Principle
Confidentiality is not only an NDA. It is a lifecycle control covering classification, access, handling, sharing, storage, transfer, monitoring, incident response, and exit.
