The ultimate how to implement guide to ISO 27001 Annex A 6.6 Confidentiality or Non-disclosure Agreements.
Table of contents
- 1. Differentiate NDAs by Role and Risk
- 2. Enforce Pre-Disclosure Signing
- 3. Define ‘Confidential Information’ Explicitly
- 4. Align NDAs with Data Protection Laws
- 5. Set Clear Durations and Expiry Terms
- 6. Mandate Return or Destruction of Data
- 7. Digitise and Index Signed Agreements
- 8. Review and Update Templates Annually
- 9. Educate Staff on NDA Triggers
- 10. Conduct Regular Compliance Audits
1. Differentiate NDAs by Role and Risk
Control Requirement: Identify the requirement for confidentiality or non-disclosure agreements reflecting the organisation’s needs.
Required Implementation Step: Do not use a single generic NDA for everyone. Create three distinct templates: ‘Standard Staff’ (low risk), ‘Privileged Admin/Exec’ (high IP/financial risk), and ‘External Partner/Vendor’ (commercial liability). Review these with legal counsel to ensure they specifically cover the types of data (e.g., PII, source code, trade secrets) exposed to each group.
Minimum Requirement: Three distinct, legally reviewed NDA templates stored in a central repository.
2. Enforce Pre-Disclosure Signing
Control Requirement: Ensure agreements are signed before information is disclosed.
Required Implementation Step: Implement a ‘No NDA, No Meeting’ protocol for external parties. Instruct reception and meeting organisers that external guests cannot enter sensitive areas or join Teams calls where confidential data is discussed without a verified, countersigned NDA on file.
Minimum Requirement: A workflow rule (e.g., in the Visitor Management System) blocking entry until NDA status is green.
3. Define ‘Confidential Information’ Explicitly
Control Requirement: Clearly define what information is to be protected.
Required Implementation Step: Avoid vague definitions like “everything we discuss.” Update the NDA schedule to explicitly list categories: “Client Databases,” “Pricing Algorithms,” “Unreleased Product Designs,” and “Network Schematics.” If the definition is too broad, it may be unenforceable in court; if too narrow, you leak data legally.
Minimum Requirement: An NDA definition clause that maps directly to your Information Classification Policy levels.
DO IT YOURSELF
ISO 27001
All the templates, tools, support and knowledge you need to do it yourself.
4. Align NDAs with Data Protection Laws
Control Requirement: Ensure compliance with relevant legislation (e.g., GDPR, DPA 2018).
Required Implementation Step: Review NDA clauses to ensure they do not accidentally attempt to override statutory rights (like whistleblowing) or data subject rights. Ensure the NDA explicitly mentions responsibilities regarding the processing of Personally Identifiable Information (PII) if the counterparty is a processor.
Minimum Requirement: A ‘Data Protection’ clause within the NDA referencing the specific applicable privacy legislation.
5. Set Clear Durations and Expiry Terms
Control Requirement: Define the duration of the agreement.
Required Implementation Step: Specify how long the confidentiality obligation lasts. For trade secrets, this should be “indefinite” or “perpetual.” For commercial discussions, a term of 3-5 years post-engagement is standard. Ensure the contract states that confidentiality obligations survive the termination of the business relationship.
Minimum Requirement: A specific ‘Survival’ clause in the contract extending confidentiality obligations beyond the end date.
6. Mandate Return or Destruction of Data
Control Requirement: Specify actions upon termination of the agreement.
Required Implementation Step: Include a mandatory clause requiring the other party to return or cryptographically destroy all confidential data upon request or contract termination. Require them to provide a written ‘Certificate of Destruction’ signed by a director, verifying that no copies exist on backups or personal devices.
Minimum Requirement: A clause granting the right to audit the counterparty’s deletion of your data.
7. Digitise and Index Signed Agreements
Control Requirement: Maintain records of signed agreements.
Required Implementation Step: Stop storing paper NDAs in filing cabinets. Use a digital signature platform (DocuSign/Adobe Sign) to capture agreements and automatically route the final PDF to a secure, searchable legal repository (e.g., SharePoint ‘Legal’ site). Tag files with the counterparty name and expiry date.
Minimum Requirement: A searchable digital registry of all active NDAs, accessible to the Legal and Procurement teams.
8. Review and Update Templates Annually
Control Requirement: Ensure agreements remain valid and enforceable.
Required Implementation Step: Schedule an annual review of the NDA templates with qualified legal counsel. Laws change (e.g., restriction of non-competes), and technology changes (e.g., impact of AI on IP ownership). An NDA written in 2018 may be useless against a data leak involving Generative AI in 2026.
Minimum Requirement: Documented evidence of an annual legal review of all standard NDA templates.
9. Educate Staff on NDA Triggers
Control Requirement: Ensure staff know when an NDA is required.
Required Implementation Step: Train Sales, Procurement, and HR staff on the specific triggers for issuing an NDA. They need to know that an “informal chat” about a potential partnership requires an NDA if pricing or product roadmaps are shown.
Minimum Requirement: Internal guidance documents or intranet pages explaining ‘When to use an NDA’.
10. Conduct Regular Compliance Audits
Control Requirement: Verify that NDAs are actually being signed and stored.
Required Implementation Step: Sample 10 recent vendor contracts and 10 new employee files. Check if a valid, signed NDA exists for each. If you find vendors working without a contract, raise a Non-Conformity immediately. This is a common failure point in ISO 27001 audits.
Minimum Requirement: An internal audit report sampling NDA compliance across HR and Procurement.

