Mutual Non-Disclosure Agreement (NDA) Template
1. Purpose
This Mutual Non-Disclosure Agreement (NDA) establishes the requirements for protecting confidential information exchanged between two parties during discussions, evaluation, negotiation, implementation, service delivery, partnership, or other business activities.
Both parties may disclose confidential information to the other party. Each party agrees to protect information received from the other party and use it only for the agreed business purpose.
Core Principle
Disclose Only What Is Necessary → Protect It → Use Only for the Agreed Purpose → Restrict Access → Prevent Unauthorized Disclosure → Return/Delete When Required
2. Parties
This Agreement is entered into between:
Party A
Legal Name: __________________________________________
Address: _____________________________________________
Registration/Company ID: ______________________________
Authorized Representative: ____________________________
Title: _______________________________________________
Party B
Legal Name: __________________________________________
Address: _____________________________________________
Registration/Company ID: ______________________________
Authorized Representative: ____________________________
Title: _______________________________________________
Party A and Party B are individually referred to as a “Party” and collectively as the “Parties.”
3. Effective Date
Effective Date: ______________________
The obligations under this Agreement apply from the Effective Date unless otherwise specified.
4. Purpose of Information Exchange
The Parties may exchange information for the following purpose:
Examples may include:
- Business discussions
- Partnership evaluation
- Product evaluation
- Technology integration
- Security assessment
- Professional services
- Consulting
- Investment discussions
- Customer/vendor evaluation
- Joint development
- Commercial negotiations
- Due diligence
- Proof of concept
- Project delivery
Information received under this Agreement shall not be used for purposes unrelated to the agreed purpose without appropriate authorization.
5. Mutual Confidentiality
Each Party may act as both:
- Disclosing Party — the Party providing confidential information
- Receiving Party — the Party receiving confidential information
The Receiving Party shall protect the Disclosing Party’s Confidential Information in accordance with this Agreement.
The obligations apply equally to both Parties.
6. Definition of Confidential Information
“Confidential Information” means non-public information disclosed by one Party to the other Party that:
- Is identified as confidential;
- Is reasonably understood to be confidential based on its nature or the circumstances of disclosure; or
- Should reasonably be protected from unauthorized disclosure.
Confidential Information may exist in:
- Written form
- Electronic form
- Verbal form
- Visual form
- Demonstrations
- Presentations
- System access
- Screenshots
- Source code
- Documents
- Files
- Databases
- APIs
- Technical environments
- Meetings
- Emails
- Messages
- Reports
7. Examples of Confidential Information
Confidential Information may include:
Business Information
- Business plans
- Strategies
- Pricing
- Financial information
- Revenue information
- Forecasts
- Customer lists
- Supplier information
- Sales information
- Marketing plans
- Commercial terms
- Contracts
Technical Information
- Architecture
- Source code
- Software
- APIs
- System configurations
- Infrastructure information
- Cloud configurations
- Network information
- Database structures
- Technical documentation
- Development plans
Security Information
- Security architecture
- Vulnerability information
- Penetration-test results
- Security findings
- Incident information
- Security controls
- Credentials and authentication information
- Security procedures
- Monitoring information
- Security assessments
Customer and Personal Information
- Customer information
- Personal data
- Employee information
- User information
- Transaction information
- Account information
- Contact information
- Other protected information
Intellectual Property
- Designs
- Algorithms
- Product concepts
- Research
- Inventions
- Trade secrets
- Proprietary processes
- Technical know-how
- Documentation
- Product roadmaps
8. Information Classification
Where applicable, Confidential Information should be handled according to the applicable information classification.
Example:
| Classification | Example |
|---|---|
| Public | Information intentionally made public |
| Internal | Internal business information |
| Confidential | Sensitive business or customer information |
| Restricted | Highly sensitive information requiring enhanced protection |
The Disclosing Party may communicate the applicable classification when information is shared.
9. Confidentiality Obligations
The Receiving Party shall:
☐ Protect Confidential Information from unauthorized access, use, disclosure, copying, modification, or loss.
☐ Use Confidential Information only for the agreed Purpose.
☐ Limit access to authorized individuals.
☐ Apply reasonable security safeguards.
☐ Prevent unauthorized disclosure.
☐ Not sell, publish, distribute, or commercially exploit Confidential Information without authorization.
☐ Not use Confidential Information for its own unrelated commercial benefit.
☐ Promptly notify the Disclosing Party of suspected unauthorized access or disclosure.
10. Need-to-Know Principle
Access to Confidential Information shall be limited to personnel who:
- Require the information for the Purpose;
- Are authorized to access it; and
- Are subject to confidentiality obligations.
The Receiving Party should avoid providing broad access where a more limited access scope is practical.
Access should be based on business need, not convenience.
11. Protection of Confidential Information
Each Party shall use reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information.
Controls may include:
- Access control
- MFA where appropriate
- Encryption
- Secure file transfer
- Endpoint security
- Secure storage
- Logging
- Monitoring
- Password protection
- Secure disposal
- Network security
- Personnel confidentiality requirements
The required level of protection should be proportionate to the sensitivity and risk of the information.
12. Personnel and Representatives
A Receiving Party may disclose Confidential Information to its:
- Employees
- Officers
- Directors
- Contractors
- Consultants
- Professional advisers
- Auditors
- Legal advisers
- Authorized representatives
only where access is necessary for the Purpose.
The Receiving Party remains responsible for ensuring that such persons are subject to appropriate confidentiality obligations.
13. Contractors and Subcontractors
Where a Party uses contractors or subcontractors who require access to Confidential Information:
☐ Access shall be limited to what is necessary.
☐ Appropriate confidentiality obligations shall apply.
☐ Security requirements shall be communicated where relevant.
☐ The Party shall remain responsible for unauthorized disclosure caused by its representatives to the extent permitted by applicable law and contract.
14. Customer and Personal Data
Where Confidential Information contains personal data or customer information, the Receiving Party shall:
- Use the information only for the authorized Purpose;
- Limit access to authorized personnel;
- Apply appropriate security safeguards;
- Avoid unnecessary copying;
- Avoid unauthorized disclosure;
- Follow applicable privacy requirements;
- Return or delete information when required.
Where legally required, the Parties shall execute a separate Data Processing Agreement (DPA) or equivalent privacy agreement.
15. Credentials and Security Secrets
Confidential Information may include:
- Passwords
- API keys
- Access tokens
- SSH keys
- Cloud credentials
- Encryption keys
- Certificates
- Security configurations
Such information must receive appropriate protection.
Credentials shall not be:
- Shared unnecessarily;
- Stored in unsecured locations;
- Published;
- Committed to source-code repositories;
- Included in public documentation;
- Transmitted through insecure channels.
16. Source Code and Technical Information
Where source code or technical information is exchanged:
☐ Access shall be limited to authorized individuals.
☐ Source code shall not be copied unnecessarily.
☐ Source code shall not be disclosed to unauthorized third parties.
☐ Repository access shall be controlled.
☐ Credentials shall not be embedded in source code.
☐ Technical information shall be returned or deleted when required.
☐ Access shall be revoked when no longer required.
17. AI and External Services
A Receiving Party shall not submit Confidential Information to:
- Public AI tools;
- Generative AI services;
- External data-processing services;
- Public repositories;
- Unapproved SaaS platforms;
- External analytics platforms;
where doing so would result in unauthorized disclosure or use.
Confidential Information may be processed through an external service only where:
- Authorized by the Disclosing Party where required;
- Contractually permitted;
- Appropriate security controls exist; and
- Applicable privacy and confidentiality requirements are satisfied.
18. Information Transfer
Confidential Information should be exchanged using appropriate secure methods.
Examples include:
- Encrypted file transfer
- Approved secure file-sharing platforms
- Secure APIs
- Encrypted email where appropriate
- Password-protected files with separate password transmission
The Parties should avoid sending highly sensitive information through unsecured channels.
19. Physical Information
Where Confidential Information exists in physical form:
☐ Documents shall be securely stored.
☐ Unauthorized persons shall not be permitted access.
☐ Documents shall not be unnecessarily copied.
☐ Sensitive documents shall be securely destroyed when no longer required.
☐ Physical media shall be protected against loss or theft.
20. Information Stored on Devices
Confidential Information stored on laptops, desktops, mobile devices, removable media, or other devices shall be appropriately protected.
Where appropriate:
- Device encryption should be enabled;
- Strong authentication should be used;
- Security updates should be maintained;
- Access should be restricted;
- Lost or stolen devices should be reported promptly.
21. Remote Work
Where Confidential Information is accessed remotely:
- Access shall use authorized systems;
- Appropriate authentication shall be used;
- Information shall not be exposed to unauthorized individuals;
- Public/shared computers should not be used for sensitive information unless specifically authorized;
- Confidential documents should not be left unattended;
- Information should not be transferred to unauthorized personal storage.
22. Prohibited Activities
Unless explicitly authorized, the Receiving Party shall not:
- Publish Confidential Information;
- Sell Confidential Information;
- Distribute Confidential Information;
- Use Confidential Information for unrelated purposes;
- Reverse engineer protected information where prohibited;
- Copy source code unnecessarily;
- Upload Confidential Information to public repositories;
- Provide Confidential Information to competitors;
- Use Confidential Information for personal benefit;
- Use Confidential Information to develop competing products where prohibited by the agreed Purpose or applicable law.
23. Security Incident Notification
If a Party becomes aware of:
- Unauthorized access;
- Unauthorized disclosure;
- Loss of Confidential Information;
- Theft;
- Accidental disclosure;
- Cybersecurity incident;
- Data breach;
- Compromise of credentials;
involving the other Party’s Confidential Information, it shall notify the affected Party without undue delay, subject to applicable law and contractual requirements.
Security Contact
Party A Contact: ______________________________
Party B Contact: ______________________________
Notification Method: ___________________________
24. Incident Cooperation
Where a confidentiality or security incident occurs, the affected Parties shall reasonably cooperate in:
- Investigation;
- Evidence preservation;
- Containment;
- Risk assessment;
- Remediation;
- Required notifications;
- Recovery;
- Corrective actions.
The Parties should preserve relevant evidence where an investigation is required.
25. Legal and Regulatory Disclosure
Confidential Information may be disclosed where disclosure is required by:
- Law;
- Court order;
- Regulatory authority;
- Government authority;
- Legal process.
Where legally permitted, the Receiving Party should:
- Notify the Disclosing Party before disclosure;
- Provide reasonable information about the request;
- Disclose only the information legally required;
- Cooperate with reasonable efforts to protect confidentiality.
26. Information That Is Not Confidential
Confidentiality obligations do not apply to information that the Receiving Party can demonstrate:
- Was publicly available when disclosed;
- Becomes publicly available without breach of this Agreement;
- Was already lawfully known before disclosure;
- Was independently developed without use of Confidential Information;
- Was lawfully obtained from a third party without confidentiality restrictions;
- Is expressly released from confidentiality by the Disclosing Party.
The Receiving Party should maintain appropriate evidence where relying on an exception.
27. No License or Ownership Transfer
Disclosure of Confidential Information does not transfer ownership of:
- Intellectual property;
- Source code;
- Trademarks;
- Patents;
- Copyright;
- Trade secrets;
- Designs;
- Technology;
- Other proprietary rights.
Except where separately agreed in writing, each Party retains ownership of its Confidential Information.
28. Intellectual Property
Nothing in this Agreement grants either Party ownership of the other Party’s intellectual property.
Any intellectual-property rights created during a joint project should be addressed through a separate written agreement where required.
29. No Obligation to Proceed
Unless separately agreed, this Agreement does not require either Party to:
- Enter into a commercial relationship;
- Purchase services;
- Provide services;
- Complete a transaction;
- Enter into another agreement.
Either Party may discontinue discussions subject to applicable contractual obligations.
30. Return or Destruction of Confidential Information
Upon written request or termination of the applicable business relationship, the Receiving Party shall, subject to applicable law and legitimate retention requirements:
☐ Return Confidential Information;
☐ Delete electronic copies;
☐ Destroy physical copies;
☐ Remove access;
☐ Return devices or media containing information;
☐ Delete information from approved systems where technically and legally practical.
Exceptions
A Party may retain information where required by:
- Law;
- Regulation;
- Legal hold;
- Professional obligations;
- Legitimate backup or archival processes.
Retained information shall remain subject to applicable confidentiality obligations.
31. Confirmation of Deletion
Where appropriate, the Disclosing Party may request reasonable confirmation that Confidential Information has been returned or deleted.
Deletion/Return Confirmation Required: ☐ Yes ☐ No
Confirmation Method: _______________________________
32. Data Location
Where sensitive information is exchanged, the Parties should understand where it will be:
- Stored;
- Processed;
- Backed up;
- Transferred.
Where geographic or regulatory restrictions apply, the Parties shall address those requirements through appropriate contractual arrangements.
33. Confidentiality After Termination
Termination of the business relationship does not automatically terminate confidentiality obligations.
Confidentiality obligations shall continue for:
Period: __________________________________________
or, where applicable, for as long as the information remains confidential or legally protected.
Trade Secrets
Trade secrets and information that remains legally protected shall continue to receive protection for the period required by applicable law.
34. Publicity and Marketing
Neither Party shall publicly announce the relationship or use the other Party’s:
- Name;
- Logo;
- Trademark;
- Customer reference;
- Case study;
- Project details;
without appropriate authorization, unless otherwise agreed in writing.
35. Audit and Security Review
Where justified by the nature and risk of the relationship, the Parties may agree to:
- Security questionnaires;
- Security assessments;
- Independent assurance reports;
- Compliance evidence;
- Security reviews;
- Audit rights.
Any such rights should be defined in the applicable commercial agreement or security addendum where appropriate.
36. Compliance With Security Requirements
Where the Parties exchange information through a controlled business relationship, each Party shall comply with applicable agreed security requirements.
These may include:
- Access control;
- Information classification;
- Secure transfer;
- Incident notification;
- Data protection;
- Confidentiality;
- Secure disposal;
- Security testing;
- Business continuity requirements.
37. Exceptions
Any exception to this Agreement should be:
- Documented;
- Approved by authorized representatives;
- Time-bound where appropriate;
- Risk-assessed where appropriate;
- Reviewed periodically.
Exception
Approved By: _______________________________________
Date: ______________________________________________
38. No Waiver
Failure to enforce a provision of this Agreement does not automatically constitute a waiver of that provision or any other provision.
39. Governing Law
This Agreement shall be governed by the laws of:
Jurisdiction: ________________________________________
The courts/authorities having jurisdiction shall be:
Jurisdiction/Venue: __________________________________
The Parties should obtain appropriate legal advice before finalizing this clause.
40. Term
This Agreement begins on the Effective Date and remains effective until:
Termination Date: ___________________________________
or until terminated according to the applicable terms.
Confidentiality obligations shall survive termination as specified in this Agreement.
41. Amendments
Any amendment to this Agreement should be:
- In writing;
- Approved by authorized representatives of both Parties;
- Maintained as part of the contractual record.
42. Entire Agreement
This Agreement represents the understanding between the Parties regarding confidentiality for the Purpose described above, unless supplemented or replaced by a subsequent written agreement.
Where another agreement contains more specific confidentiality or security requirements, the Parties should clearly establish which terms take precedence.
43. Notices
Party A
Name: _____________________________________________
Email: _____________________________________________
Address: ___________________________________________
Party B
Name: _____________________________________________
Email: _____________________________________________
Address: ___________________________________________
44. Signatures
Party A
Legal Name: ________________________________________
Authorized Representative: ___________________________
Title: ______________________________________________
Signature: __________________________________________
Date: ______________________________________________
Party B
Legal Name: ________________________________________
Authorized Representative: ___________________________
Title: ______________________________________________
Signature: __________________________________________
Date: ______________________________________________
45. Mutual NDA Information Exchange Record
For audit and governance purposes, the Parties may maintain a record of significant information exchanges.
| Date | Disclosing Party | Information | Classification | Purpose | Recipient | Method |
|---|---|---|---|---|---|---|
This record should not itself contain unnecessary sensitive information.
46. Mutual NDA Onboarding Checklist
Before exchanging sensitive information:
☐ Parties verified
☐ Authorized representatives identified
☐ Business purpose documented
☐ Confidentiality agreement executed
☐ Information classification identified
☐ Sensitive information identified
☐ Personal data requirements assessed
☐ Security requirements identified
☐ Access requirements defined
☐ Information transfer method approved
☐ Security contacts identified
☐ AI/external-service restrictions understood
☐ Subcontractor requirements considered
☐ Retention requirements considered
☐ Return/deletion requirements defined
47. Mutual NDA Offboarding Checklist
When discussions or the relationship end:
☐ Information exchange stopped where appropriate
☐ Access revoked
☐ Shared accounts reviewed
☐ Credentials/tokens addressed where necessary
☐ Confidential documents returned/deleted
☐ Physical documents recovered
☐ Devices/media addressed
☐ Third-party access reviewed
☐ Deletion/return evidence retained where required
☐ Continuing confidentiality obligations communicated
☐ NDA records retained
48. AWS SaaS Startup Example
An AWS-based SaaS startup is evaluating another technology company for a potential integration.
During the evaluation, the startup shares:
- AWS architecture diagrams;
- API documentation;
- Product roadmap;
- Security architecture;
- VAPT findings;
- Sample customer data;
- Integration credentials;
- Technical documentation.
The technology company may also share:
- Proprietary APIs;
- Product architecture;
- Source-code samples;
- Pricing;
- Security documentation;
- Product roadmap.
Mutual NDA Controls
Before the exchange:
Business Purpose: Technology integration evaluation.
Information Classification: Confidential/Restricted.
Access: Named personnel only.
Transfer: Approved secure file-sharing platform.
Credentials: Temporary test credentials with limited permissions.
Customer Data: Prefer synthetic/test data.
AI: No Confidential Information submitted to unapproved public AI services.
Retention: Information returned/deleted when evaluation ends.
Security Incident: Prompt notification of unauthorized disclosure.
Audit Trail
Business Purpose → Mutual NDA → Information Classification → Secure Exchange → Controlled Access → Evaluation → Return/Delete → Access Revocation → Evidence
49. Startup-Friendly Mutual NDA Model
For a startup, the NDA process should be strong without creating unnecessary administrative overhead.
Low-Risk Discussions
Use:
- Standard mutual NDA;
- Basic confidentiality obligations;
- Limited information exchange.
Medium-Risk Discussions
Add:
- Information classification;
- Secure file sharing;
- Access restrictions;
- Personal-data requirements;
- Security incident notification.
High-Risk Discussions
Add enhanced controls for:
- Source code;
- Production access;
- Customer data;
- Personal data;
- Security findings;
- Cloud architecture;
- Credentials;
- Privileged access;
- Highly sensitive intellectual property.
50. Common Mistakes
Avoid:
- Using a one-sided NDA when both parties disclose sensitive information.
- Defining Confidential Information too narrowly.
- Allowing unrestricted access to Confidential Information.
- Sending sensitive information through insecure channels.
- Sharing real customer data unnecessarily.
- Sharing production credentials during evaluation.
- Uploading Confidential Information to public AI tools.
- Failing to control subcontractor access.
- Failing to define return/deletion requirements.
- Forgetting confidentiality obligations after termination.
- Allowing employees or contractors to use information for unrelated purposes.
- Treating an NDA as a replacement for technical security controls.
- Assuming an NDA alone satisfies privacy or regulatory requirements.
51. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Classification Policy | Defines how information is classified |
| Confidentiality and NDA Policy | Establishes confidentiality requirements |
| Employee NDA | Protects information accessed by employees |
| Contractor NDA | Protects information accessed by contractors |
| Supplier Confidentiality Agreement | Protects information shared with suppliers |
| Data Processing Agreement | Addresses personal-data processing |
| Information Transfer Procedure | Controls information exchange |
| Access Management Procedure | Controls access to systems/information |
| Supplier Security Requirements | Defines third-party security expectations |
| Incident Response Procedure | Handles confidentiality/security incidents |
| Asset Return Checklist | Supports return of information/assets |
| Employee Offboarding Policy | Supports confidentiality after employee exit |
| Supplier Offboarding | Supports secure termination of supplier relationships |
| Legal & Regulatory Requirements Register | Tracks applicable obligations |
52. ISO 27001 / SOC 2 Connection
A Mutual NDA can support the organization’s broader information-security and confidentiality framework.
It can provide evidence that:
- Confidentiality obligations are formally established;
- Information shared with external parties is appropriately protected;
- Access is restricted;
- Third-party disclosures are controlled;
- Information return/deletion is addressed;
- Security incidents involving confidential information are considered;
- Contractual security expectations are documented.
However, an NDA does not by itself demonstrate compliance with ISO 27001 or SOC 2.
Technical, organizational, access-control, monitoring, incident-management, privacy, and other applicable controls must also be implemented based on the organization’s risks and requirements.
53. Quick Audit Checklist
☐ Mutual NDA executed
☐ Both Parties identified
☐ Business purpose documented
☐ Confidential Information defined
☐ Information classification considered
☐ Need-to-know access defined
☐ Personnel confidentiality addressed
☐ Contractor/subcontractor access addressed
☐ Customer data assessed
☐ Personal data assessed
☐ Security requirements defined
☐ Secure transfer method defined
☐ Credentials protected
☐ AI/external-service restrictions defined
☐ Incident notification addressed
☐ Legal disclosure addressed
☐ Return/deletion requirements defined
☐ Post-termination confidentiality defined
☐ Intellectual property ownership addressed
☐ Publicity restrictions addressed
☐ Governing law defined
☐ Authorized signatures obtained
☐ NDA record retained
54. Final Audit Trail
For every significant mutual confidentiality relationship, the organization should be able to demonstrate:
Who are the Parties?
Why are they exchanging information?
What information is being exchanged?
How sensitive is the information?
Who can access it?
How is it protected?
How is it transferred?
Are customer or personal data involved?
Are contractors or subcontractors involved?
Can the information be processed by AI or external services?
What happens if information is accidentally disclosed?
When will the information be returned or deleted?
How long do confidentiality obligations continue?
Who approved and signed the agreement?
Final Principle
A Mutual NDA should not simply say “keep information confidential.” It should establish a clear, mutual framework for what information is protected, why it is shared, who may access it, how it must be protected, what happens after disclosure, and what happens when the relationship ends.
Legal Note
This template is a practical information-security and business template and is not legal advice. The Parties should have the final agreement reviewed by qualified legal counsel, particularly for governing law, jurisdiction, intellectual-property rights, trade secrets, privacy requirements, regulatory obligations, international data transfers, non-solicitation/non-compete provisions, and enforceability.
