ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Employee NDA Template

Employee NDA Template

Employee Non-Disclosure Agreement (NDA)

1. Purpose

This Employee Non-Disclosure Agreement (NDA) establishes the obligations of an employee to protect confidential, proprietary, personal, customer, technical, security, and business information obtained during employment.

The agreement is intended to prevent unauthorized access, use, disclosure, copying, transfer, retention, or misuse of confidential information during and after employment.

Core Principle

Access only what is required → Use only for authorized business purposes → Protect it → Do not disclose it → Return/Delete it when required → Continue confidentiality after employment


2. Parties

This Agreement is entered into between:

Company: __________________________________________

Employee: __________________________________________

Employee ID: _______________________________________

Designation: ________________________________________

Department: ________________________________________

Effective Date: _____________________________________

The Company and Employee are collectively referred to as the “Parties.”


3. Purpose of the Agreement

The Employee may receive or have access to confidential information as part of their employment.

The Employee agrees to:

  • Protect confidential information
  • Use information only for authorized business purposes
  • Prevent unauthorized disclosure
  • Follow Company security requirements
  • Follow information classification requirements
  • Protect customer and personal information
  • Protect credentials and security information
  • Return or securely delete information when required
  • Continue protecting confidential information after employment ends

4. Definition of Confidential Information

For purposes of this Agreement, Confidential Information means non-public information belonging to or entrusted to the Company that the Employee accesses, receives, creates, develops, or becomes aware of through employment.

Confidential Information may include, but is not limited to:

Business Information

  • Business plans
  • Strategy
  • Financial information
  • Pricing
  • Revenue information
  • Forecasts
  • Budgets
  • Business processes
  • Internal reports
  • Management information
  • Commercial agreements
  • Supplier information
  • Customer relationships
  • Sales information
  • Marketing plans

Customer Information

  • Customer names and contact information
  • Customer account information
  • Customer contracts
  • Customer business information
  • Customer system information
  • Customer security information
  • Customer credentials
  • Customer data
  • Customer reports

Personal Information

  • Employee information
  • Customer personal data
  • Supplier personal data
  • Identification information
  • Contact information
  • Financial information
  • Other personal information processed by the Company

Technical Information

  • Source code
  • Software architecture
  • System designs
  • APIs
  • Database structures
  • Technical documentation
  • Infrastructure configurations
  • Development information
  • Deployment processes
  • Algorithms
  • Scripts
  • Automation
  • Technical specifications

Information Security Information

  • Security architecture
  • Vulnerability information
  • Penetration-test results
  • Security assessment results
  • Incident information
  • Security monitoring information
  • Security configurations
  • Security procedures
  • Security findings
  • Risk assessments
  • Security reports

Credentials and Secrets

  • Passwords
  • API keys
  • Access tokens
  • Encryption keys
  • SSH keys
  • Certificates
  • Cloud credentials
  • Database credentials
  • Service-account credentials
  • Recovery codes
  • Authentication information

Intellectual Property

  • Designs
  • Inventions
  • Concepts
  • Product ideas
  • Documentation
  • Software
  • Technical developments
  • Research
  • Trade secrets
  • Proprietary methodologies

5. Information Classification

The Employee must follow the Company’s information-classification requirements.

Where applicable, information may be classified as:

ClassificationExample
PublicApproved public website content
InternalInternal procedures and operational information
ConfidentialCustomer information, business plans, technical information
RestrictedCredentials, sensitive personal data, security findings, critical security information

The Employee must apply appropriate protection based on the classification of information.


6. Employee Confidentiality Obligations

The Employee agrees to:

☐ Keep Confidential Information confidential.

☐ Access Confidential Information only when authorized.

☐ Use Confidential Information only for legitimate business purposes.

☐ Not disclose Confidential Information to unauthorized persons.

☐ Not copy Confidential Information unnecessarily.

☐ Not transfer Confidential Information to unauthorized systems or services.

☐ Not use Confidential Information for personal purposes.

☐ Not use Company information for personal commercial benefit.

☐ Not share confidential information through unauthorized communication channels.

☐ Follow Company information-security policies and procedures.

☐ Immediately report suspected unauthorized disclosure or loss.


7. Need-to-Know Principle

The Employee must access Confidential Information only when required to perform their assigned responsibilities.

Access must be based on:

Business Need + Authorization + Minimum Required Access

The Employee must not attempt to access information merely because technical access is available.


8. Credentials and Authentication Information

The Employee must protect all credentials and authentication information.

The Employee must not:

  • Share passwords
  • Share MFA codes
  • Share API keys
  • Share access tokens
  • Share private keys
  • Store secrets in unauthorized locations
  • Commit credentials to source code
  • Send credentials through unsecured channels
  • Use another person’s account
  • Circumvent authentication controls

Credentials must be managed according to the Company’s access-management and credential-management requirements.


9. Customer and Personal Data

Where the Employee has access to customer or personal information, the Employee must:

  • Use the information only for authorized purposes
  • Access only the minimum information required
  • Follow applicable privacy requirements
  • Follow Company data-protection procedures
  • Prevent unauthorized disclosure
  • Avoid unnecessary copying
  • Avoid unauthorized downloads
  • Avoid unauthorized local storage
  • Report suspected data breaches promptly

The Employee must not use customer or personal information for personal purposes.


10. Source Code and Intellectual Property

Where applicable, the Employee must protect:

  • Source code
  • Software designs
  • Development repositories
  • Architecture
  • Algorithms
  • Technical documentation
  • Build and deployment configurations
  • Product designs
  • Internal development tools

The Employee must not copy, publish, transfer, sell, or disclose such information without authorization.


11. Use of External Services and AI Tools

The Employee must not upload Confidential Information to:

  • Personal cloud storage
  • Personal email accounts
  • Unauthorized file-sharing platforms
  • Public repositories
  • Unapproved SaaS applications
  • Public AI services
  • Generative AI tools
  • External development platforms

unless explicitly authorized by the Company.

Particular care must be taken before submitting:

  • Customer data
  • Personal data
  • Source code
  • Credentials
  • Security findings
  • Vulnerability information
  • Confidential documents
  • Internal business information

to external or AI-powered services.


12. Remote Working

When working remotely, the Employee must take reasonable measures to prevent unauthorized disclosure.

This includes:

☐ Securing Company devices

☐ Preventing unauthorized persons from viewing confidential information

☐ Using approved communication tools

☐ Using approved storage locations

☐ Protecting printed documents

☐ Avoiding confidential discussions in public locations

☐ Using secure networks as required

☐ Following Company remote-working requirements


13. Physical Documents

The Employee must appropriately protect confidential physical documents.

The Employee must not:

  • Leave confidential documents unattended
  • Dispose of confidential documents in ordinary waste
  • Photograph confidential documents without authorization
  • Remove documents from Company premises without authorization
  • Leave confidential documents visible to unauthorized persons

Confidential documents must be securely disposed of when no longer required.


14. Electronic Information

Confidential electronic information must be stored and transferred using Company-approved systems.

The Employee must not:

  • Use unauthorized storage
  • Forward confidential email to personal accounts
  • Upload information to unauthorized websites
  • Store sensitive information on unauthorized devices
  • Use unauthorized removable media
  • Transfer information through unapproved applications

15. Disclosure to Third Parties

The Employee must not disclose Confidential Information to:

  • Friends
  • Family members
  • Former employees
  • Competitors
  • Customers without authorization
  • Suppliers without authorization
  • Consultants without authorization
  • Other employees without a legitimate need-to-know

Disclosure to authorized third parties must follow Company procedures and applicable contractual requirements.


16. Public Disclosure and Social Media

The Employee must not disclose Confidential Information through:

  • Social media
  • Blogs
  • Forums
  • Public repositories
  • Presentations
  • Interviews
  • Articles
  • Videos
  • Conferences
  • Public messaging channels

unless the disclosure has been appropriately authorized.

The Employee must not represent personal opinions as Company-approved statements.


17. Security Incidents and Unauthorized Disclosure

The Employee must immediately report suspected:

  • Information leakage
  • Unauthorized disclosure
  • Lost documents
  • Lost devices
  • Misdelivered emails
  • Accidental sharing
  • Unauthorized access
  • Credential exposure
  • Data breach
  • Source-code exposure
  • Security incident

The Employee must cooperate with investigation and remediation activities.

The Employee must not attempt to conceal an accidental or suspected disclosure.


18. Incident Investigation

Where a security or confidentiality incident occurs, the Employee may be required to:

  • Provide relevant information
  • Preserve evidence
  • Identify affected information
  • Identify recipients
  • Support investigation
  • Follow containment instructions
  • Cooperate with corrective actions

The Employee must not intentionally delete, modify, or destroy relevant evidence after becoming aware of an investigation unless instructed through an authorized process.


19. Company Property and Information

All Company information, documents, systems, credentials, records, source code, intellectual property, and other materials provided for employment remain subject to Company ownership and applicable contractual arrangements.

The Employee must not treat Company information as personal property merely because they created, accessed, or stored it during employment.


20. Information Created During Employment

Where applicable under the Employee’s employment agreement and applicable law, work products created in the course of employment may belong to the Company.

Examples may include:

  • Software
  • Documentation
  • Designs
  • Reports
  • Processes
  • Research
  • Technical materials
  • Business materials
  • Security assessments
  • Internal tools
  • Automation scripts

Ownership provisions should be aligned with the Employee’s employment agreement and applicable law.


21. Information Retention

The Employee must retain Confidential Information only for as long as authorized or required for legitimate business purposes.

The Employee must not retain Company information indefinitely for personal reference.

Information must be handled according to applicable:

  • Retention requirements
  • Legal requirements
  • Contractual requirements
  • Privacy requirements
  • Company policies

22. Return and Deletion of Information

Upon request or when employment ends, the Employee must return or securely delete Company information as instructed.

This may include:

☐ Documents

☐ Files

☐ Source code

☐ Customer information

☐ Security information

☐ Company devices

☐ Removable media

☐ Credentials

☐ Company records

☐ Printed documents

☐ Local copies

☐ Backup copies under the Employee’s control

The Employee must not retain unauthorized copies.

Deletion must not occur where information must be preserved for legal, regulatory, investigation, or other authorized purposes.


23. Personal Devices

Where Company information is accessed from a personal device under an approved BYOD arrangement, the Employee must follow applicable Company security requirements.

The Employee must not intentionally retain Company Confidential Information on personal devices after access is no longer authorized.

Where permitted by Company policy and applicable law, the Company may require removal of Company information from approved personal devices.


24. Confidentiality After Employment

The Employee’s confidentiality obligations continue after employment ends for as long as the information remains confidential or as otherwise required by applicable law or contract.

Termination of employment does not automatically authorize the Employee to:

  • Use Company Confidential Information
  • Disclose Company Confidential Information
  • Retain Company information
  • Access Company systems
  • Contact customers using confidential information
  • Use proprietary technical information

25. Exceptions

Confidential Information does not generally include information that the Employee can demonstrate:

  1. Was publicly available without breach of this Agreement;
  2. Was lawfully known to the Employee before disclosure by the Company;
  3. Was lawfully received from an authorized third party without confidentiality restrictions; or
  4. Was independently developed without unauthorized use of Company Confidential Information.

The Employee should seek guidance from the Company before relying on an exception.


26. Legally Required Disclosure

Nothing in this Agreement prevents the Employee from making a disclosure that is required by applicable law or a valid legal or regulatory requirement.

Where legally permitted, the Employee should notify the Company before making such disclosure so that the Company can determine whether appropriate protective measures are available.


27. Whistleblowing and Protected Reporting

Nothing in this Agreement is intended to prevent lawful reporting of:

  • Illegal activity
  • Regulatory violations
  • Security concerns
  • Workplace misconduct
  • Fraud
  • Other matters protected by applicable law

Any such reporting should be made through appropriate lawful channels.


28. Employee Responsibilities

The Employee is responsible for:

☐ Protecting Confidential Information

☐ Following Company security policies

☐ Following information-classification requirements

☐ Protecting credentials

☐ Following access-control requirements

☐ Protecting customer information

☐ Protecting personal information

☐ Reporting security incidents

☐ Reporting suspected confidentiality breaches

☐ Returning Company information when required

☐ Cooperating with investigations

☐ Continuing confidentiality after employment


29. Company Responsibilities

The Company should, where appropriate:

  • Define information-security requirements
  • Provide relevant policies and procedures
  • Provide appropriate security training
  • Establish access controls
  • Provide approved systems for handling information
  • Communicate confidentiality requirements
  • Provide appropriate reporting channels
  • Manage employee access
  • Revoke access when employment ends

30. Security Awareness

The Employee may be required to complete security and confidentiality training.

Training may include:

  • Information classification
  • Password security
  • MFA
  • Phishing
  • Data protection
  • Confidentiality
  • Secure communication
  • Remote working
  • Incident reporting
  • Acceptable use
  • AI and external service usage

31. Violations

Violation of this Agreement or applicable Company security requirements may result in appropriate action in accordance with:

  • Employment terms
  • Company disciplinary procedures
  • Applicable law
  • Contractual obligations

Serious violations may include unauthorized disclosure, intentional data theft, credential sharing, unauthorized system access, or deliberate misuse of Confidential Information.


32. Security Exceptions

Any exception to the requirements of this Agreement must be formally authorized where required.

ExceptionBusiness ReasonRiskApprovalExpiry

Informal verbal approval should not be treated as a permanent exception.


33. Relationship With Company Policies

This Agreement should be read together with applicable Company policies and procedures, including:

  • Information Security Policy
  • Confidentiality and Non-Disclosure Policy
  • Acceptable Use Policy
  • Access Management Policy
  • Information Classification Policy
  • Data Protection/Privacy Policy
  • Remote Working Policy
  • Mobile Device Policy
  • Employee Security Policy
  • Incident Management Procedure
  • Employee Offboarding Procedure

Where applicable, the Employee must comply with the latest approved versions of these requirements.


34. Agreement Acknowledgement

The Employee confirms that they:

☐ Have read this Agreement

☐ Understand the confidentiality requirements

☐ Understand their information-security responsibilities

☐ Understand the need-to-know principle

☐ Understand the requirements for protecting customer and personal data

☐ Understand that confidentiality continues after employment

☐ Understand the requirement to return/delete Company information when instructed

☐ Understand the requirement to report suspected security or confidentiality incidents

☐ Agree to comply with applicable Company security policies


35. Employee Declaration

I acknowledge that during my employment I may have access to Confidential Information belonging to the Company, its customers, suppliers, employees, business partners, or other parties.

I agree to protect such information, use it only for authorized purposes, and not disclose or misuse it without appropriate authorization.

I understand that my confidentiality obligations may continue after my employment ends.

I agree to comply with applicable Company information-security, privacy, access-control, acceptable-use, and confidentiality requirements.

Employee

Name: __________________________________________

Employee ID: _____________________________________

Designation: _____________________________________

Signature: _______________________________________

Date: ____________________________________________


36. Company Representative

Name: __________________________________________

Designation: _____________________________________

Signature: _______________________________________

Date: ____________________________________________


37. Witness — Where Required

Name: __________________________________________

Designation: _____________________________________

Signature: _______________________________________

Date: ____________________________________________


38. Document Control

FieldDetails
Document NameEmployee Non-Disclosure Agreement
Document ID
Version
Effective Date
Owner
Approved By
Review FrequencyAnnual / As Required
ClassificationInternal / Confidential
Related PolicyConfidentiality and Non-Disclosure Policy
RetentionAccording to HR/Legal retention requirements

39. Implementation Checklist

Before the employee receives access to sensitive information:

☐ NDA reviewed

☐ NDA signed

☐ Employment agreement completed

☐ Confidentiality requirements communicated

☐ Security policies communicated

☐ Security awareness training completed or scheduled

☐ Information classification explained

☐ Access requirements identified

☐ Access approved

☐ MFA configured where required

☐ Appropriate access provisioned

☐ Employee acknowledgement retained


40. Exit Verification

At employee exit:

☐ Confidentiality obligations communicated

☐ Access revoked

☐ Company assets returned

☐ Company information returned/deleted where applicable

☐ Local copies addressed

☐ Credentials/secrets addressed where required

☐ Exit Security Acknowledgement completed

☐ Investigation/legal hold requirements considered

☐ Exit evidence retained


41. AWS SaaS Startup Example

A startup hires a DevOps engineer who receives access to:

  • AWS production
  • GitHub repositories
  • CI/CD pipelines
  • Production databases
  • Monitoring systems
  • Customer environments
  • Security documentation

The employee signs the NDA before receiving access.

During employment:

Need-to-Know → Authorized Access → Secure Use → No Unauthorized Disclosure

When the employee leaves:

Notify → Revoke AWS/GitHub/Production Access → Recover Assets → Address Secrets → Return/Delete Information → Verify → Record

The NDA provides the contractual confidentiality obligation, while access-management and offboarding procedures provide the operational controls.


42. Startup-Friendly Model

A startup does not need a complicated NDA to establish effective confidentiality protection.

At minimum:

Before Access

NDA → Security Responsibilities → Training → Access Approval

During Employment

Need-to-Know → Secure Handling → Authorized Use → Incident Reporting

At Exit

Access Revocation → Information Return/Delete → Asset Return → Exit Acknowledgement

The important objective is to ensure that the NDA is connected to actual security controls rather than being treated as a standalone document.


43. Common Mistakes

Avoid:

  • Using an NDA without access controls.
  • Giving employees access before required agreements are completed.
  • Treating every employee as having unrestricted access.
  • Allowing credentials to be shared.
  • Ignoring customer confidentiality requirements.
  • Allowing confidential information to be uploaded to unauthorized AI tools.
  • Allowing source code to be copied to personal repositories.
  • Forgetting confidentiality obligations after termination.
  • Failing to revoke access when employees leave.
  • Failing to recover Company information.
  • Retaining unnecessary copies of signed NDAs.
  • Using an NDA as a substitute for information-security policies.

44. Relationship With Other ISMS Documents

DocumentRelationship
Confidentiality and Non-Disclosure PolicyDefines organizational confidentiality requirements
Employee NDAEstablishes individual contractual confidentiality obligations
Employment AgreementDefines employment terms and related obligations
Information Classification PolicyDefines information protection requirements
Access Management ProcedureControls employee access
Employee Onboarding ChecklistEnsures NDA and security requirements are completed
Employee Offboarding PolicyControls confidentiality and security during exit
Exit Security AcknowledgementRecords continuing obligations at exit
Incident Response ProcedureHandles confidentiality/security incidents
Data Protection PolicyAddresses personal-data protection
Acceptable Use PolicyDefines permitted use of Company resources

45. ISO 27001 / SOC 2 Connection

An Employee NDA supports the organization’s broader information-security and personnel-security framework.

It helps demonstrate that employees understand and accept confidentiality responsibilities and that contractual obligations exist for protecting information.

The NDA should not be considered sufficient by itself. Effective protection should also include:

  • Access control
  • Information classification
  • Security awareness
  • Confidentiality requirements
  • Monitoring where appropriate
  • Incident reporting
  • Employee offboarding
  • Access revocation
  • Asset return
  • Information return/deletion

For ISO 27001, the specific controls and documented information required should be determined through the organization’s ISMS risk assessment and applicable requirements.


46. Quick Audit Checklist

☐ NDA template approved

☐ NDA signed before sensitive access where required

☐ Employee identity verified

☐ Confidentiality requirements communicated

☐ Information classification communicated

☐ Need-to-know principle established

☐ Security policies acknowledged

☐ Security training completed

☐ Customer/personal data requirements communicated

☐ AI/external-service restrictions communicated

☐ Access appropriately approved

☐ NDA record retained

☐ Exit confidentiality requirements communicated

☐ Access revoked at exit

☐ Company information returned/deleted where applicable

☐ Exit acknowledgement completed


47. Final Audit Trail

For an employee handling sensitive information, the organization should be able to demonstrate:

Who is the employee?
What confidential information can they access?
Why do they need access?
Was confidentiality formally agreed?
Were security responsibilities communicated?
Was security training completed?
Was access appropriately authorized?
How is confidential information protected during employment?
How are incidents reported?
What happens when employment ends?
Was access revoked?
Was Company information returned/deleted where required?
Are confidentiality obligations continuing after exit?

Final Principle

An NDA creates the confidentiality obligation; the ISMS must make that obligation operational through access control, secure information handling, awareness, incident reporting, and secure employee exit.

Legal note: This is a practical information-security template and should be reviewed by the organization’s legal counsel and adapted to the applicable employment laws, jurisdiction, employment agreement, and business requirements before use.