1. Purpose
This Supplier Confidentiality Agreement establishes the confidentiality obligations of a supplier, vendor, service provider, consultant company, technology provider, outsourcing provider, or other external organization that receives or accesses non-public information belonging to the Company or its customers.
The objective is to ensure that confidential information is:
- Accessed only for authorized business purposes
- Protected against unauthorized disclosure
- Shared only with authorized personnel
- Protected throughout the supplier relationship
- Properly handled when transferred
- Returned or securely deleted when required
- Protected after termination of the relationship
Core Principle
Identify → Authorize → Share Minimally → Protect → Monitor → Return/Delete → Maintain Confidentiality
2. Parties
This Agreement is entered into between:
Company: __________________________________________
Supplier: __________________________________________
Supplier Legal Entity: ______________________________
Supplier Address: ___________________________________
Contract/Supplier ID: _______________________________
Primary Service: ____________________________________
Agreement Effective Date: ___________________________
Contract Expiry Date: _______________________________
The Company and Supplier are collectively referred to as the “Parties.”
3. Purpose of the Supplier Relationship
The Supplier is providing the following services:
The Supplier may receive or access Company Confidential Information solely to perform the agreed services.
The Supplier must not use Confidential Information for any other purpose unless expressly authorized in writing.
4. Definition of Confidential Information
Confidential Information means any non-public information disclosed to, accessed by, created for, or otherwise made available to the Supplier by or on behalf of the Company.
Confidential Information may be provided verbally, electronically, physically, visually, through systems, through APIs, or by any other means.
Confidential Information includes, but is not limited to:
Business Information
- Business plans
- Strategy
- Financial information
- Pricing
- Forecasts
- Commercial information
- Contracts
- Supplier information
- Customer relationships
- Product roadmaps
- Marketing information
- Internal reports
- Operational information
Customer Information
- Customer names and information
- Customer contracts
- Customer account information
- Customer data
- Customer systems
- Customer configurations
- Customer security information
- Customer reports
- Customer credentials
- Customer technical information
Personal Information
- Employee information
- Customer personal data
- Supplier contact information
- Identification information
- Financial information
- Other personal information processed by the Supplier
Technical Information
- Source code
- Software architecture
- APIs
- Database structures
- System designs
- Infrastructure configurations
- Technical documentation
- Development information
- Deployment configurations
- Scripts
- Automation
- Algorithms
Information Security Information
- Security architecture
- Security configurations
- Vulnerability information
- Penetration-test results
- Security findings
- Risk assessments
- Security incidents
- Incident reports
- Security monitoring information
- Security procedures
Credentials and Secrets
- Passwords
- API keys
- Access tokens
- SSH keys
- Cloud credentials
- Database credentials
- Encryption keys
- Certificates
- Service-account credentials
- Recovery codes
Intellectual Property
- Designs
- Product concepts
- Research
- Technical developments
- Proprietary methodologies
- Trade secrets
- Documentation
- Software
- Other intellectual property
5. Information Classification
The Supplier must comply with the Company’s information-classification requirements where applicable.
Information may be classified as:
| Classification | Example |
|---|---|
| Public | Information approved for public release |
| Internal | Internal business and operational information |
| Confidential | Customer, commercial, technical, and business information |
| Restricted | Credentials, sensitive personal data, critical security information |
The Supplier must apply appropriate safeguards based on the classification and contractual requirements.
6. Confidentiality Obligations
The Supplier agrees to:
☐ Protect Confidential Information against unauthorized access, use, disclosure, copying, modification, or loss.
☐ Use Confidential Information only for the agreed business purpose.
☐ Limit access to authorized personnel.
☐ Apply appropriate security controls.
☐ Prevent unauthorized disclosure.
☐ Not sell, publish, or commercially exploit Confidential Information.
☐ Not use Confidential Information for the Supplier’s independent commercial purposes.
☐ Not disclose Confidential Information to competitors or other unauthorized parties.
☐ Notify the Company of suspected unauthorized disclosure.
☐ Maintain confidentiality after termination of the relationship.
7. Need-to-Know Principle
The Supplier must restrict access to Confidential Information to personnel who:
- Require access to perform the contracted services;
- Are authorized to access the information; and
- Are subject to appropriate confidentiality obligations.
The Supplier must apply the principle:
Need-to-Know + Minimum Necessary Access
Technical availability of information does not constitute authorization.
8. Supplier Personnel
The Supplier must ensure that personnel with access to Company Confidential Information:
- Are appropriately authorized
- Understand their confidentiality responsibilities
- Follow applicable security requirements
- Receive appropriate security awareness where required
- Use individual accounts where technically feasible
- Protect credentials
- Report security incidents
- Do not disclose Confidential Information without authorization
The Supplier remains responsible for its personnel’s compliance with applicable confidentiality obligations.
9. Supplier Subcontractors and Subprocessors
The Supplier must not disclose Confidential Information to subcontractors, subprocessors, affiliates, or other third parties unless permitted under the applicable contract.
Where approval is required, the Supplier must:
☐ Identify the subcontractor/subprocessor
☐ Identify the service provided
☐ Identify the information accessed
☐ Identify the processing/storage location
☐ Apply appropriate confidentiality requirements
☐ Apply applicable security requirements
☐ Maintain appropriate oversight
☐ Notify the Company of material changes where required
The Supplier must ensure that approved subcontractors and subprocessors are subject to confidentiality obligations that are no less protective than those applicable to the Supplier.
10. Customer Information
Where the Supplier receives or accesses Company customer information, the Supplier must:
- Use the information only for authorized services
- Protect the information against unauthorized access
- Apply applicable contractual security requirements
- Restrict access to authorized personnel
- Avoid unnecessary copying
- Avoid unauthorized downloads
- Follow applicable retention requirements
- Return or delete information when required
The Supplier must not use customer information for its own marketing, analytics, product development, or other independent purposes unless expressly authorized.
11. Personal Data
Where the Supplier processes personal data on behalf of the Company, the Supplier must comply with applicable privacy and data-protection requirements and the applicable Data Processing Agreement, where one exists.
The Supplier must appropriately address:
- Processing purpose
- Data categories
- Data subjects
- Processing locations
- Access
- Retention
- Deletion
- Subprocessors
- International transfers
- Security
- Incident notification
- Data-subject requirements where applicable
This Agreement does not replace a required Data Processing Agreement.
12. Information Security
The Supplier must maintain appropriate administrative, technical, and physical safeguards to protect Confidential Information.
Depending on the risk and services provided, controls may include:
☐ Access control
☐ MFA
☐ Encryption
☐ Network security
☐ Endpoint security
☐ Vulnerability management
☐ Security monitoring
☐ Logging
☐ Backup
☐ Incident response
☐ Secure development
☐ Security awareness
☐ Physical security
☐ Business continuity
The specific security requirements should be defined in the applicable Supplier Security Requirements or contract.
13. Credentials and Secrets
Where the Supplier receives or manages Company credentials or secrets, the Supplier must:
- Restrict access
- Protect credentials securely
- Avoid unnecessary copying
- Prevent credential sharing
- Use secure storage
- Rotate credentials where required
- Revoke credentials when no longer required
- Report suspected compromise immediately
The Supplier must not store Company credentials in:
- Public repositories
- Source code
- Unapproved cloud storage
- Personal systems
- Unapproved collaboration tools
- Unsecured documents
14. Source Code and Intellectual Property
Where applicable, the Supplier must protect:
- Source code
- Software designs
- Architecture
- Algorithms
- Development repositories
- Infrastructure-as-code
- CI/CD configurations
- Technical documentation
- Product designs
The Supplier must not copy, publish, reuse, sell, or disclose Company source code or proprietary technical information except as authorized.
Intellectual-property ownership is governed by the applicable commercial agreement and is not established solely by this confidentiality agreement unless expressly stated.
15. AI and External Services
The Supplier must not submit Company or customer Confidential Information to unauthorized:
- Generative AI services
- Public AI platforms
- SaaS applications
- Cloud services
- File-sharing platforms
- Development platforms
- Analytics services
- External processing services
unless expressly authorized.
Particular care must be taken with:
- Customer data
- Personal data
- Source code
- Security findings
- Vulnerability information
- Credentials
- Architecture
- Confidential documents
Where AI services are authorized, applicable contractual and security requirements must be followed.
16. Information Transfer
Confidential Information must be transferred using approved and appropriately secured methods.
Examples include:
- Encrypted file transfer
- Approved corporate email
- Secure APIs
- Approved collaboration platforms
- Secure file-sharing systems
- Other Company-approved mechanisms
The Supplier must not use unauthorized channels to transfer Confidential Information.
17. Data Location
The Supplier must not store, process, or transfer Confidential Information to locations that are not authorized under the applicable agreement.
Where relevant, the Supplier must identify:
| Location | Activity | Information | Requirement |
|---|---|---|---|
Applicable contractual, privacy, regulatory, customer, and security requirements must be considered.
18. Physical Protection
Where the Supplier stores or handles physical Confidential Information, appropriate safeguards must be maintained.
These may include:
- Physical access controls
- Secure storage
- Visitor controls
- Secure areas
- Document protection
- Media protection
- Secure disposal
- Environmental controls
19. Security Incidents and Breaches
The Supplier must promptly notify the Company of any actual or suspected:
- Data breach
- Security incident
- Unauthorized access
- Unauthorized disclosure
- Loss of Confidential Information
- Credential compromise
- Malware incident
- Source-code exposure
- Security vulnerability materially affecting Company information
- Customer information exposure
Company Security Contact
Name/Team: ________________________________________
Email: ____________________________________________
Phone: ____________________________________________
The notification process and notification timeframe should be defined in the applicable contract or Supplier Security Requirements.
20. Incident Cooperation
Following a security incident, the Supplier must, where applicable:
- Cooperate with investigation
- Preserve relevant evidence
- Identify affected information
- Identify affected systems
- Identify affected individuals or customers where appropriate
- Support containment
- Support remediation
- Provide relevant incident information
- Implement corrective actions
The Supplier must not intentionally destroy relevant evidence.
21. Security Assessments and Assurance
Where required by the contract and appropriate to the risk, the Supplier may be required to provide reasonable evidence of security controls.
Examples include:
- ISO/IEC 27001 certificate
- SOC report
- Security assessment
- Penetration-test summary
- Security questionnaire
- Business continuity evidence
- Data-protection documentation
- Relevant policies
- Independent assurance reports
The Company should evaluate the scope and relevance of such evidence rather than relying solely on the existence of a certification.
22. Audit and Review Rights
Where agreed in the applicable contract, the Company may request reasonable information necessary to assess the Supplier’s compliance with applicable confidentiality and security requirements.
The review may include:
- Security questionnaires
- Evidence review
- Meetings
- Control assessments
- Independent assurance reports
- Relevant audit reports
Any audit or assessment rights should be exercised proportionately and subject to applicable contractual and legal requirements.
23. Supplier Personnel Access
The Supplier must maintain appropriate records of personnel authorized to access Company information where required.
The Supplier must promptly remove access when personnel:
- Leave the Supplier
- Change roles
- No longer require access
- Lose authorization
- Are removed from the engagement
Where Company-managed accounts are used, the Company may directly manage access revocation.
24. Information Retention
The Supplier must retain Confidential Information only for as long as:
- Required to perform the services;
- Required by contract;
- Required by applicable law; or
- Otherwise authorized by the Company.
The Supplier must not retain Confidential Information indefinitely for convenience.
25. Return and Deletion of Information
Upon Company request or termination of the relevant services, the Supplier must return or securely delete Confidential Information as required by the applicable agreement.
This may include:
☐ Electronic files
☐ Physical documents
☐ Customer information
☐ Personal data
☐ Source code
☐ Security reports
☐ Credentials
☐ Configuration information
☐ Backups where applicable
☐ Removable media
☐ Other Company information
The Supplier may retain information where legally required, provided that the retained information remains protected and is not used for unauthorized purposes.
26. Verification of Deletion
Where required, the Company may request reasonable confirmation that Confidential Information has been returned or securely deleted.
Such confirmation may be provided through:
- Written certification
- Supplier deletion statement
- System evidence
- Data-disposal record
- Other appropriate evidence
Deletion requirements should account for legitimate backup, legal-retention, and investigation requirements.
27. Business Continuity
Where the Supplier provides a critical service, the Supplier must maintain appropriate arrangements to protect the availability and continued delivery of the service.
Where applicable, the Company may assess:
- Business continuity
- Disaster recovery
- Backup
- Recovery capability
- Recovery testing
- RTO
- RPO
- Alternative arrangements
28. Publicity and Marketing
The Supplier must not use the Company’s:
- Name
- Logo
- Customer names
- Project details
- Case studies
- Screenshots
- Confidential information
for marketing, publicity, presentations, websites, social media, or other public communications without prior authorization.
29. Legal and Regulatory Disclosure
Nothing in this Agreement prevents disclosure required by applicable law, court order, or valid regulatory requirement.
Where legally permitted, the Supplier should notify the Company before making such disclosure and cooperate with reasonable protective measures.
30. Exceptions to Confidential Information
Confidential Information does not generally include information that the Supplier can demonstrate:
- Was publicly available without breach of this Agreement;
- Was lawfully known to the Supplier before disclosure;
- Was lawfully received from an authorized third party without confidentiality restrictions; or
- Was independently developed without unauthorized use of Company Confidential Information.
The Supplier should consult the Company before relying on an exception.
31. Supplier Responsibility
The Supplier is responsible for ensuring that its personnel and approved subcontractors comply with applicable confidentiality obligations.
The Supplier must maintain appropriate internal processes to:
- Identify authorized personnel
- Control access
- Communicate confidentiality obligations
- Protect information
- Report incidents
- Remove access
- Return/delete information
32. No Unauthorized Use
The Supplier must not use Confidential Information to:
- Develop competing products
- Build unrelated products
- Conduct unauthorized analytics
- Train unauthorized AI models
- Market services
- Contact customers for unauthorized commercial purposes
- Sell information
- Benefit another customer
- Benefit the Supplier independently
unless expressly authorized.
33. No License or Transfer of Rights
Disclosure of Confidential Information does not grant the Supplier any ownership, license, intellectual-property right, or other right except the limited right to use the information for the authorized business purpose.
34. Relationship With Commercial Agreement
This Agreement should be read together with the applicable:
- Master Services Agreement
- Purchase Agreement
- Statement of Work
- Supplier Security Addendum
- Data Processing Agreement
- Service Level Agreement
- Supplier Security Requirements
- Other applicable contractual documents
If another agreement establishes stricter confidentiality or security requirements, the stricter applicable requirement should apply to the extent permitted by the contractual framework.
35. Confidentiality After Termination
The Supplier’s confidentiality obligations continue after termination or expiry of the business relationship for as long as the information remains confidential or as otherwise required by applicable law or contract.
Termination does not authorize the Supplier to retain, use, disclose, or exploit Confidential Information.
36. Security Exceptions
Any exception to agreed confidentiality or security requirements must be formally documented and approved where required.
| Exception | Reason | Risk | Compensating Control | Approval | Expiry |
|---|---|---|---|---|---|
Temporary exceptions should include an expiry date.
37. Supplier Acknowledgement
The Supplier confirms that:
☐ The confidentiality requirements have been reviewed.
☐ The Supplier understands the permitted use of Confidential Information.
☐ Access will be restricted to authorized personnel.
☐ Appropriate security safeguards will be maintained.
☐ Subcontractors will be controlled as required.
☐ Security incidents will be reported.
☐ Confidential Information will not be used for unauthorized purposes.
☐ Information will be returned or deleted when required.
☐ Confidentiality obligations will continue after termination.
38. Supplier Declaration
The Supplier acknowledges that it may receive or access confidential, proprietary, customer, personal, technical, security, and other non-public information in connection with its services.
The Supplier agrees to protect such information and use it only for authorized business purposes.
The Supplier agrees to maintain appropriate confidentiality and security safeguards and to comply with applicable contractual requirements.
Supplier
Legal Name: _______________________________________
Authorized Representative: __________________________
Designation: _______________________________________
Signature: _________________________________________
Date: _____________________________________________
39. Company Representative
Name: __________________________________________
Designation: _____________________________________
Signature: _______________________________________
Date: ____________________________________________
40. Witness — Where Required
Name: __________________________________________
Designation: _____________________________________
Signature: _______________________________________
Date: ____________________________________________
41. Document Control
| Field | Details |
|---|---|
| Document Name | Supplier Confidentiality Agreement |
| Document ID | |
| Version | |
| Effective Date | |
| Owner | |
| Approved By | |
| Review Frequency | Annual / As Required |
| Classification | Confidential |
| Related Policy | Confidentiality and Non-Disclosure Policy |
| Related Documents | Supplier Security Requirements / DPA / Contract |
| Retention | According to Legal and Contractual Requirements |
42. Supplier Onboarding Checklist
Before sharing sensitive information:
☐ Supplier identity verified
☐ Supplier due diligence completed
☐ Supplier risk assessment completed
☐ Contract/SOW completed
☐ Confidentiality Agreement signed
☐ Security requirements agreed
☐ DPA completed where applicable
☐ Information classification identified
☐ Information-sharing method approved
☐ Access requirements identified
☐ Customer requirements reviewed
☐ Subprocessors assessed
☐ Data locations assessed
☐ Incident notification requirements agreed
☐ Security contacts recorded
☐ Supplier approved
43. Supplier Offboarding Checklist
At the end of the relationship:
☐ Contract termination/completion confirmed
☐ Supplier access inventory reviewed
☐ Company accounts disabled
☐ Cloud access removed
☐ Source-code access removed
☐ Production access removed
☐ Customer access removed
☐ Credentials/tokens addressed
☐ Confidential information returned
☐ Confidential information deleted where required
☐ Subprocessor access addressed
☐ Assets returned
☐ Deletion evidence obtained where required
☐ Supplier Register updated
☐ Confidentiality obligations communicated
☐ Offboarding evidence retained
44. AWS SaaS Startup Example
A SaaS startup engages an external managed service provider to support its AWS infrastructure.
The supplier may have access to:
- AWS infrastructure
- Monitoring systems
- Cloud configurations
- Infrastructure-as-code
- Security logs
- Incident information
- Limited customer information
Before Access
Supplier Due Diligence → Risk Assessment → Contract → Confidentiality Agreement → Security Requirements → Access Approval
During the Relationship
The supplier must:
- Access only authorized AWS resources.
- Use named accounts where practical.
- Use MFA.
- Protect credentials and secrets.
- Restrict personnel access.
- Protect customer information.
- Report security incidents.
- Control subcontractors.
At Exit
Terminate Service → Revoke Access → Rotate Relevant Credentials → Return/Delete Information → Verify → Record
The confidentiality agreement establishes the supplier’s contractual obligation while the supplier security controls and access-management processes provide operational protection.
45. Startup-Friendly Model
For a low-risk supplier:
Supplier Verification → Contract → Confidentiality → Basic Security Requirements → Approval
For a medium-risk supplier:
Due Diligence → Risk Assessment → NDA/Confidentiality → Security Assessment → Contract → Approval → Monitoring
For a high/critical supplier:
Enhanced Due Diligence → Security Assessment → Data/Access Review → DPA → Security Addendum → Assurance Evidence → Contract → Approval → Continuous Monitoring → Exit Planning
The level of due diligence should be proportionate to the supplier’s risk.
46. Common Mistakes
Avoid:
- Signing a confidentiality agreement without identifying the information being shared.
- Treating an NDA as a substitute for supplier security controls.
- Sharing customer data before appropriate contractual arrangements are completed.
- Ignoring subcontractors and subprocessors.
- Failing to define incident notification requirements.
- Allowing suppliers unnecessary production access.
- Allowing suppliers to use confidential information for AI training without authorization.
- Failing to define data retention and deletion.
- Ignoring geographic data-location requirements.
- Failing to revoke supplier access at termination.
- Failing to obtain deletion/return evidence where required.
- Allowing supplier personnel to retain information for future projects.
47. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Confidentiality and Non-Disclosure Policy | Defines organizational confidentiality requirements |
| Supplier Confidentiality Agreement | Establishes supplier confidentiality obligations |
| Supplier Security Requirements | Defines required supplier security controls |
| Supplier Security Addendum | Adds detailed contractual security requirements |
| Supplier Risk Assessment | Determines supplier risk |
| Third-Party Due Diligence Checklist | Establishes broader supplier due diligence |
| Supplier Security Questionnaire | Collects supplier security information |
| Supplier Security Review | Evaluates supplier controls |
| Data Processing Agreement | Addresses personal-data processing |
| Supplier Monitoring Procedure | Monitors supplier security performance |
| Supplier Offboarding Checklist | Controls supplier exit |
| Contract Review Checklist | Verifies contractual security requirements |
48. ISO 27001 / SOC 2 Connection
A Supplier Confidentiality Agreement supports the organization’s supplier-security framework by establishing contractual confidentiality requirements for external organizations that access organizational or customer information.
The agreement should be supported by appropriate controls such as:
- Supplier due diligence
- Supplier risk assessment
- Supplier security requirements
- Access control
- Information classification
- Subprocessor management
- Security monitoring
- Incident management
- Business continuity
- Data protection
- Contract review
- Supplier offboarding
For ISO 27001, the applicable controls and documented information should be determined through the organization’s ISMS risk assessment and applicable legal, regulatory, contractual, and customer requirements.
49. Quick Audit Checklist
☐ Supplier identified
☐ Business purpose documented
☐ Information being shared identified
☐ Information classification identified
☐ Supplier risk assessed
☐ Confidentiality agreement approved
☐ Agreement signed
☐ Need-to-know requirement established
☐ Supplier personnel controlled
☐ Subcontractors/subprocessors assessed
☐ Security requirements agreed
☐ Customer requirements considered
☐ Personal-data requirements considered
☐ Data locations considered
☐ Incident notification requirements defined
☐ Security assurance reviewed where appropriate
☐ Return/deletion requirements defined
☐ Exit requirements defined
☐ Supplier approved
☐ Evidence retained
50. Final Audit Trail
For every significant supplier relationship, the organization should be able to demonstrate:
Who is the supplier?
What service do they provide?
What confidential information is shared?
Why does the supplier need it?
What classification applies?
Who is authorized to access it?
Are subcontractors involved?
What security requirements apply?
What happens if the supplier has a security incident?
How long can the supplier retain the information?
How will information be returned or deleted?
Who approved the relationship?
What happens when the relationship ends?
Final Principle
A Supplier Confidentiality Agreement establishes the contractual obligation to protect information; effective supplier security requires that obligation to be connected to due diligence, risk assessment, access control, security requirements, monitoring, incident management, and verified supplier exit.
Legal note: This is a practical information-security template and should be reviewed by qualified legal counsel and aligned with the applicable jurisdiction, master services agreement, supplier contract, DPA, customer requirements, and regulatory obligations before execution.
