ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Mutual NDA Template

Mutual NDA Template

Mutual Non-Disclosure Agreement (NDA) Template

1. Purpose

This Mutual Non-Disclosure Agreement (NDA) establishes the requirements for protecting confidential information exchanged between two parties during discussions, evaluation, negotiation, implementation, service delivery, partnership, or other business activities.

Both parties may disclose confidential information to the other party. Each party agrees to protect information received from the other party and use it only for the agreed business purpose.

Core Principle

Disclose Only What Is Necessary → Protect It → Use Only for the Agreed Purpose → Restrict Access → Prevent Unauthorized Disclosure → Return/Delete When Required


2. Parties

This Agreement is entered into between:

Party A

Legal Name: __________________________________________

Address: _____________________________________________

Registration/Company ID: ______________________________

Authorized Representative: ____________________________

Title: _______________________________________________

Party B

Legal Name: __________________________________________

Address: _____________________________________________

Registration/Company ID: ______________________________

Authorized Representative: ____________________________

Title: _______________________________________________

Party A and Party B are individually referred to as a “Party” and collectively as the “Parties.”


3. Effective Date

Effective Date: ______________________

The obligations under this Agreement apply from the Effective Date unless otherwise specified.


4. Purpose of Information Exchange

The Parties may exchange information for the following purpose:

Examples may include:

  • Business discussions
  • Partnership evaluation
  • Product evaluation
  • Technology integration
  • Security assessment
  • Professional services
  • Consulting
  • Investment discussions
  • Customer/vendor evaluation
  • Joint development
  • Commercial negotiations
  • Due diligence
  • Proof of concept
  • Project delivery

Information received under this Agreement shall not be used for purposes unrelated to the agreed purpose without appropriate authorization.


5. Mutual Confidentiality

Each Party may act as both:

  • Disclosing Party — the Party providing confidential information
  • Receiving Party — the Party receiving confidential information

The Receiving Party shall protect the Disclosing Party’s Confidential Information in accordance with this Agreement.

The obligations apply equally to both Parties.


6. Definition of Confidential Information

“Confidential Information” means non-public information disclosed by one Party to the other Party that:

  • Is identified as confidential;
  • Is reasonably understood to be confidential based on its nature or the circumstances of disclosure; or
  • Should reasonably be protected from unauthorized disclosure.

Confidential Information may exist in:

  • Written form
  • Electronic form
  • Verbal form
  • Visual form
  • Demonstrations
  • Presentations
  • System access
  • Screenshots
  • Source code
  • Documents
  • Files
  • Databases
  • APIs
  • Technical environments
  • Meetings
  • Emails
  • Messages
  • Reports

7. Examples of Confidential Information

Confidential Information may include:

Business Information

  • Business plans
  • Strategies
  • Pricing
  • Financial information
  • Revenue information
  • Forecasts
  • Customer lists
  • Supplier information
  • Sales information
  • Marketing plans
  • Commercial terms
  • Contracts

Technical Information

  • Architecture
  • Source code
  • Software
  • APIs
  • System configurations
  • Infrastructure information
  • Cloud configurations
  • Network information
  • Database structures
  • Technical documentation
  • Development plans

Security Information

  • Security architecture
  • Vulnerability information
  • Penetration-test results
  • Security findings
  • Incident information
  • Security controls
  • Credentials and authentication information
  • Security procedures
  • Monitoring information
  • Security assessments

Customer and Personal Information

  • Customer information
  • Personal data
  • Employee information
  • User information
  • Transaction information
  • Account information
  • Contact information
  • Other protected information

Intellectual Property

  • Designs
  • Algorithms
  • Product concepts
  • Research
  • Inventions
  • Trade secrets
  • Proprietary processes
  • Technical know-how
  • Documentation
  • Product roadmaps

8. Information Classification

Where applicable, Confidential Information should be handled according to the applicable information classification.

Example:

ClassificationExample
PublicInformation intentionally made public
InternalInternal business information
ConfidentialSensitive business or customer information
RestrictedHighly sensitive information requiring enhanced protection

The Disclosing Party may communicate the applicable classification when information is shared.


9. Confidentiality Obligations

The Receiving Party shall:

☐ Protect Confidential Information from unauthorized access, use, disclosure, copying, modification, or loss.

☐ Use Confidential Information only for the agreed Purpose.

☐ Limit access to authorized individuals.

☐ Apply reasonable security safeguards.

☐ Prevent unauthorized disclosure.

☐ Not sell, publish, distribute, or commercially exploit Confidential Information without authorization.

☐ Not use Confidential Information for its own unrelated commercial benefit.

☐ Promptly notify the Disclosing Party of suspected unauthorized access or disclosure.


10. Need-to-Know Principle

Access to Confidential Information shall be limited to personnel who:

  • Require the information for the Purpose;
  • Are authorized to access it; and
  • Are subject to confidentiality obligations.

The Receiving Party should avoid providing broad access where a more limited access scope is practical.

Access should be based on business need, not convenience.


11. Protection of Confidential Information

Each Party shall use reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information.

Controls may include:

  • Access control
  • MFA where appropriate
  • Encryption
  • Secure file transfer
  • Endpoint security
  • Secure storage
  • Logging
  • Monitoring
  • Password protection
  • Secure disposal
  • Network security
  • Personnel confidentiality requirements

The required level of protection should be proportionate to the sensitivity and risk of the information.


12. Personnel and Representatives

A Receiving Party may disclose Confidential Information to its:

  • Employees
  • Officers
  • Directors
  • Contractors
  • Consultants
  • Professional advisers
  • Auditors
  • Legal advisers
  • Authorized representatives

only where access is necessary for the Purpose.

The Receiving Party remains responsible for ensuring that such persons are subject to appropriate confidentiality obligations.


13. Contractors and Subcontractors

Where a Party uses contractors or subcontractors who require access to Confidential Information:

☐ Access shall be limited to what is necessary.

☐ Appropriate confidentiality obligations shall apply.

☐ Security requirements shall be communicated where relevant.

☐ The Party shall remain responsible for unauthorized disclosure caused by its representatives to the extent permitted by applicable law and contract.


14. Customer and Personal Data

Where Confidential Information contains personal data or customer information, the Receiving Party shall:

  • Use the information only for the authorized Purpose;
  • Limit access to authorized personnel;
  • Apply appropriate security safeguards;
  • Avoid unnecessary copying;
  • Avoid unauthorized disclosure;
  • Follow applicable privacy requirements;
  • Return or delete information when required.

Where legally required, the Parties shall execute a separate Data Processing Agreement (DPA) or equivalent privacy agreement.


15. Credentials and Security Secrets

Confidential Information may include:

  • Passwords
  • API keys
  • Access tokens
  • SSH keys
  • Cloud credentials
  • Encryption keys
  • Certificates
  • Security configurations

Such information must receive appropriate protection.

Credentials shall not be:

  • Shared unnecessarily;
  • Stored in unsecured locations;
  • Published;
  • Committed to source-code repositories;
  • Included in public documentation;
  • Transmitted through insecure channels.

16. Source Code and Technical Information

Where source code or technical information is exchanged:

☐ Access shall be limited to authorized individuals.

☐ Source code shall not be copied unnecessarily.

☐ Source code shall not be disclosed to unauthorized third parties.

☐ Repository access shall be controlled.

☐ Credentials shall not be embedded in source code.

☐ Technical information shall be returned or deleted when required.

☐ Access shall be revoked when no longer required.


17. AI and External Services

A Receiving Party shall not submit Confidential Information to:

  • Public AI tools;
  • Generative AI services;
  • External data-processing services;
  • Public repositories;
  • Unapproved SaaS platforms;
  • External analytics platforms;

where doing so would result in unauthorized disclosure or use.

Confidential Information may be processed through an external service only where:

  • Authorized by the Disclosing Party where required;
  • Contractually permitted;
  • Appropriate security controls exist; and
  • Applicable privacy and confidentiality requirements are satisfied.

18. Information Transfer

Confidential Information should be exchanged using appropriate secure methods.

Examples include:

  • Encrypted file transfer
  • Approved secure file-sharing platforms
  • Secure APIs
  • Encrypted email where appropriate
  • Password-protected files with separate password transmission

The Parties should avoid sending highly sensitive information through unsecured channels.


19. Physical Information

Where Confidential Information exists in physical form:

☐ Documents shall be securely stored.

☐ Unauthorized persons shall not be permitted access.

☐ Documents shall not be unnecessarily copied.

☐ Sensitive documents shall be securely destroyed when no longer required.

☐ Physical media shall be protected against loss or theft.


20. Information Stored on Devices

Confidential Information stored on laptops, desktops, mobile devices, removable media, or other devices shall be appropriately protected.

Where appropriate:

  • Device encryption should be enabled;
  • Strong authentication should be used;
  • Security updates should be maintained;
  • Access should be restricted;
  • Lost or stolen devices should be reported promptly.

21. Remote Work

Where Confidential Information is accessed remotely:

  • Access shall use authorized systems;
  • Appropriate authentication shall be used;
  • Information shall not be exposed to unauthorized individuals;
  • Public/shared computers should not be used for sensitive information unless specifically authorized;
  • Confidential documents should not be left unattended;
  • Information should not be transferred to unauthorized personal storage.

22. Prohibited Activities

Unless explicitly authorized, the Receiving Party shall not:

  • Publish Confidential Information;
  • Sell Confidential Information;
  • Distribute Confidential Information;
  • Use Confidential Information for unrelated purposes;
  • Reverse engineer protected information where prohibited;
  • Copy source code unnecessarily;
  • Upload Confidential Information to public repositories;
  • Provide Confidential Information to competitors;
  • Use Confidential Information for personal benefit;
  • Use Confidential Information to develop competing products where prohibited by the agreed Purpose or applicable law.

23. Security Incident Notification

If a Party becomes aware of:

  • Unauthorized access;
  • Unauthorized disclosure;
  • Loss of Confidential Information;
  • Theft;
  • Accidental disclosure;
  • Cybersecurity incident;
  • Data breach;
  • Compromise of credentials;

involving the other Party’s Confidential Information, it shall notify the affected Party without undue delay, subject to applicable law and contractual requirements.

Security Contact

Party A Contact: ______________________________

Party B Contact: ______________________________

Notification Method: ___________________________


24. Incident Cooperation

Where a confidentiality or security incident occurs, the affected Parties shall reasonably cooperate in:

  • Investigation;
  • Evidence preservation;
  • Containment;
  • Risk assessment;
  • Remediation;
  • Required notifications;
  • Recovery;
  • Corrective actions.

The Parties should preserve relevant evidence where an investigation is required.


25. Legal and Regulatory Disclosure

Confidential Information may be disclosed where disclosure is required by:

  • Law;
  • Court order;
  • Regulatory authority;
  • Government authority;
  • Legal process.

Where legally permitted, the Receiving Party should:

  1. Notify the Disclosing Party before disclosure;
  2. Provide reasonable information about the request;
  3. Disclose only the information legally required;
  4. Cooperate with reasonable efforts to protect confidentiality.

26. Information That Is Not Confidential

Confidentiality obligations do not apply to information that the Receiving Party can demonstrate:

  • Was publicly available when disclosed;
  • Becomes publicly available without breach of this Agreement;
  • Was already lawfully known before disclosure;
  • Was independently developed without use of Confidential Information;
  • Was lawfully obtained from a third party without confidentiality restrictions;
  • Is expressly released from confidentiality by the Disclosing Party.

The Receiving Party should maintain appropriate evidence where relying on an exception.


27. No License or Ownership Transfer

Disclosure of Confidential Information does not transfer ownership of:

  • Intellectual property;
  • Source code;
  • Trademarks;
  • Patents;
  • Copyright;
  • Trade secrets;
  • Designs;
  • Technology;
  • Other proprietary rights.

Except where separately agreed in writing, each Party retains ownership of its Confidential Information.


28. Intellectual Property

Nothing in this Agreement grants either Party ownership of the other Party’s intellectual property.

Any intellectual-property rights created during a joint project should be addressed through a separate written agreement where required.


29. No Obligation to Proceed

Unless separately agreed, this Agreement does not require either Party to:

  • Enter into a commercial relationship;
  • Purchase services;
  • Provide services;
  • Complete a transaction;
  • Enter into another agreement.

Either Party may discontinue discussions subject to applicable contractual obligations.


30. Return or Destruction of Confidential Information

Upon written request or termination of the applicable business relationship, the Receiving Party shall, subject to applicable law and legitimate retention requirements:

☐ Return Confidential Information;

☐ Delete electronic copies;

☐ Destroy physical copies;

☐ Remove access;

☐ Return devices or media containing information;

☐ Delete information from approved systems where technically and legally practical.

Exceptions

A Party may retain information where required by:

  • Law;
  • Regulation;
  • Legal hold;
  • Professional obligations;
  • Legitimate backup or archival processes.

Retained information shall remain subject to applicable confidentiality obligations.


31. Confirmation of Deletion

Where appropriate, the Disclosing Party may request reasonable confirmation that Confidential Information has been returned or deleted.

Deletion/Return Confirmation Required: ☐ Yes ☐ No

Confirmation Method: _______________________________


32. Data Location

Where sensitive information is exchanged, the Parties should understand where it will be:

  • Stored;
  • Processed;
  • Backed up;
  • Transferred.

Where geographic or regulatory restrictions apply, the Parties shall address those requirements through appropriate contractual arrangements.


33. Confidentiality After Termination

Termination of the business relationship does not automatically terminate confidentiality obligations.

Confidentiality obligations shall continue for:

Period: __________________________________________

or, where applicable, for as long as the information remains confidential or legally protected.

Trade Secrets

Trade secrets and information that remains legally protected shall continue to receive protection for the period required by applicable law.


34. Publicity and Marketing

Neither Party shall publicly announce the relationship or use the other Party’s:

  • Name;
  • Logo;
  • Trademark;
  • Customer reference;
  • Case study;
  • Project details;

without appropriate authorization, unless otherwise agreed in writing.


35. Audit and Security Review

Where justified by the nature and risk of the relationship, the Parties may agree to:

  • Security questionnaires;
  • Security assessments;
  • Independent assurance reports;
  • Compliance evidence;
  • Security reviews;
  • Audit rights.

Any such rights should be defined in the applicable commercial agreement or security addendum where appropriate.


36. Compliance With Security Requirements

Where the Parties exchange information through a controlled business relationship, each Party shall comply with applicable agreed security requirements.

These may include:

  • Access control;
  • Information classification;
  • Secure transfer;
  • Incident notification;
  • Data protection;
  • Confidentiality;
  • Secure disposal;
  • Security testing;
  • Business continuity requirements.

37. Exceptions

Any exception to this Agreement should be:

  • Documented;
  • Approved by authorized representatives;
  • Time-bound where appropriate;
  • Risk-assessed where appropriate;
  • Reviewed periodically.

Exception

Approved By: _______________________________________

Date: ______________________________________________


38. No Waiver

Failure to enforce a provision of this Agreement does not automatically constitute a waiver of that provision or any other provision.


39. Governing Law

This Agreement shall be governed by the laws of:

Jurisdiction: ________________________________________

The courts/authorities having jurisdiction shall be:

Jurisdiction/Venue: __________________________________

The Parties should obtain appropriate legal advice before finalizing this clause.


40. Term

This Agreement begins on the Effective Date and remains effective until:

Termination Date: ___________________________________

or until terminated according to the applicable terms.

Confidentiality obligations shall survive termination as specified in this Agreement.


41. Amendments

Any amendment to this Agreement should be:

  • In writing;
  • Approved by authorized representatives of both Parties;
  • Maintained as part of the contractual record.

42. Entire Agreement

This Agreement represents the understanding between the Parties regarding confidentiality for the Purpose described above, unless supplemented or replaced by a subsequent written agreement.

Where another agreement contains more specific confidentiality or security requirements, the Parties should clearly establish which terms take precedence.


43. Notices

Party A

Name: _____________________________________________

Email: _____________________________________________

Address: ___________________________________________

Party B

Name: _____________________________________________

Email: _____________________________________________

Address: ___________________________________________


44. Signatures

Party A

Legal Name: ________________________________________

Authorized Representative: ___________________________

Title: ______________________________________________

Signature: __________________________________________

Date: ______________________________________________


Party B

Legal Name: ________________________________________

Authorized Representative: ___________________________

Title: ______________________________________________

Signature: __________________________________________

Date: ______________________________________________


45. Mutual NDA Information Exchange Record

For audit and governance purposes, the Parties may maintain a record of significant information exchanges.

DateDisclosing PartyInformationClassificationPurposeRecipientMethod

This record should not itself contain unnecessary sensitive information.


46. Mutual NDA Onboarding Checklist

Before exchanging sensitive information:

☐ Parties verified

☐ Authorized representatives identified

☐ Business purpose documented

☐ Confidentiality agreement executed

☐ Information classification identified

☐ Sensitive information identified

☐ Personal data requirements assessed

☐ Security requirements identified

☐ Access requirements defined

☐ Information transfer method approved

☐ Security contacts identified

☐ AI/external-service restrictions understood

☐ Subcontractor requirements considered

☐ Retention requirements considered

☐ Return/deletion requirements defined


47. Mutual NDA Offboarding Checklist

When discussions or the relationship end:

☐ Information exchange stopped where appropriate

☐ Access revoked

☐ Shared accounts reviewed

☐ Credentials/tokens addressed where necessary

☐ Confidential documents returned/deleted

☐ Physical documents recovered

☐ Devices/media addressed

☐ Third-party access reviewed

☐ Deletion/return evidence retained where required

☐ Continuing confidentiality obligations communicated

☐ NDA records retained


48. AWS SaaS Startup Example

An AWS-based SaaS startup is evaluating another technology company for a potential integration.

During the evaluation, the startup shares:

  • AWS architecture diagrams;
  • API documentation;
  • Product roadmap;
  • Security architecture;
  • VAPT findings;
  • Sample customer data;
  • Integration credentials;
  • Technical documentation.

The technology company may also share:

  • Proprietary APIs;
  • Product architecture;
  • Source-code samples;
  • Pricing;
  • Security documentation;
  • Product roadmap.

Mutual NDA Controls

Before the exchange:

Business Purpose: Technology integration evaluation.

Information Classification: Confidential/Restricted.

Access: Named personnel only.

Transfer: Approved secure file-sharing platform.

Credentials: Temporary test credentials with limited permissions.

Customer Data: Prefer synthetic/test data.

AI: No Confidential Information submitted to unapproved public AI services.

Retention: Information returned/deleted when evaluation ends.

Security Incident: Prompt notification of unauthorized disclosure.

Audit Trail

Business Purpose → Mutual NDA → Information Classification → Secure Exchange → Controlled Access → Evaluation → Return/Delete → Access Revocation → Evidence


49. Startup-Friendly Mutual NDA Model

For a startup, the NDA process should be strong without creating unnecessary administrative overhead.

Low-Risk Discussions

Use:

  • Standard mutual NDA;
  • Basic confidentiality obligations;
  • Limited information exchange.

Medium-Risk Discussions

Add:

  • Information classification;
  • Secure file sharing;
  • Access restrictions;
  • Personal-data requirements;
  • Security incident notification.

High-Risk Discussions

Add enhanced controls for:

  • Source code;
  • Production access;
  • Customer data;
  • Personal data;
  • Security findings;
  • Cloud architecture;
  • Credentials;
  • Privileged access;
  • Highly sensitive intellectual property.

50. Common Mistakes

Avoid:

  • Using a one-sided NDA when both parties disclose sensitive information.
  • Defining Confidential Information too narrowly.
  • Allowing unrestricted access to Confidential Information.
  • Sending sensitive information through insecure channels.
  • Sharing real customer data unnecessarily.
  • Sharing production credentials during evaluation.
  • Uploading Confidential Information to public AI tools.
  • Failing to control subcontractor access.
  • Failing to define return/deletion requirements.
  • Forgetting confidentiality obligations after termination.
  • Allowing employees or contractors to use information for unrelated purposes.
  • Treating an NDA as a replacement for technical security controls.
  • Assuming an NDA alone satisfies privacy or regulatory requirements.

51. Relationship With Other ISMS Documents

DocumentRelationship
Information Classification PolicyDefines how information is classified
Confidentiality and NDA PolicyEstablishes confidentiality requirements
Employee NDAProtects information accessed by employees
Contractor NDAProtects information accessed by contractors
Supplier Confidentiality AgreementProtects information shared with suppliers
Data Processing AgreementAddresses personal-data processing
Information Transfer ProcedureControls information exchange
Access Management ProcedureControls access to systems/information
Supplier Security RequirementsDefines third-party security expectations
Incident Response ProcedureHandles confidentiality/security incidents
Asset Return ChecklistSupports return of information/assets
Employee Offboarding PolicySupports confidentiality after employee exit
Supplier OffboardingSupports secure termination of supplier relationships
Legal & Regulatory Requirements RegisterTracks applicable obligations

52. ISO 27001 / SOC 2 Connection

A Mutual NDA can support the organization’s broader information-security and confidentiality framework.

It can provide evidence that:

  • Confidentiality obligations are formally established;
  • Information shared with external parties is appropriately protected;
  • Access is restricted;
  • Third-party disclosures are controlled;
  • Information return/deletion is addressed;
  • Security incidents involving confidential information are considered;
  • Contractual security expectations are documented.

However, an NDA does not by itself demonstrate compliance with ISO 27001 or SOC 2.

Technical, organizational, access-control, monitoring, incident-management, privacy, and other applicable controls must also be implemented based on the organization’s risks and requirements.


53. Quick Audit Checklist

☐ Mutual NDA executed

☐ Both Parties identified

☐ Business purpose documented

☐ Confidential Information defined

☐ Information classification considered

☐ Need-to-know access defined

☐ Personnel confidentiality addressed

☐ Contractor/subcontractor access addressed

☐ Customer data assessed

☐ Personal data assessed

☐ Security requirements defined

☐ Secure transfer method defined

☐ Credentials protected

☐ AI/external-service restrictions defined

☐ Incident notification addressed

☐ Legal disclosure addressed

☐ Return/deletion requirements defined

☐ Post-termination confidentiality defined

☐ Intellectual property ownership addressed

☐ Publicity restrictions addressed

☐ Governing law defined

☐ Authorized signatures obtained

☐ NDA record retained


54. Final Audit Trail

For every significant mutual confidentiality relationship, the organization should be able to demonstrate:

Who are the Parties?
Why are they exchanging information?
What information is being exchanged?
How sensitive is the information?
Who can access it?
How is it protected?
How is it transferred?
Are customer or personal data involved?
Are contractors or subcontractors involved?
Can the information be processed by AI or external services?
What happens if information is accidentally disclosed?
When will the information be returned or deleted?
How long do confidentiality obligations continue?
Who approved and signed the agreement?

Final Principle

A Mutual NDA should not simply say “keep information confidential.” It should establish a clear, mutual framework for what information is protected, why it is shared, who may access it, how it must be protected, what happens after disclosure, and what happens when the relationship ends.


Legal Note

This template is a practical information-security and business template and is not legal advice. The Parties should have the final agreement reviewed by qualified legal counsel, particularly for governing law, jurisdiction, intellectual-property rights, trade secrets, privacy requirements, regulatory obligations, international data transfers, non-solicitation/non-compete provisions, and enforceability.