ISO/IEC 27001:2022 Annex A · Control 6.6
Confidentiality or Non-Disclosure Agreements: A Practical Implementation Guide
Use clear confidentiality agreements that match the information, relationship and jurisdiction.
This control concerns identifying, documenting, reviewing and signing confidentiality or non-disclosure agreements that protect organizational information.
What should the control achieve?
- Relationships requiring confidentiality terms are identified.
- Agreements define protected information and permitted use.
- Terms are signed before disclosure.
- Agreements are reviewed when risk or law changes.
Step-by-step implementation
Identify use cases
Cover employees, contractors, suppliers, partners, candidates and transaction parties.
Define protected scope
Describe confidential information, exclusions, purpose and authorized recipients.
Set handling duties
Address protection, onward disclosure, incident reporting, return, deletion and compelled disclosure.
Define duration and remedies
Match survival periods and consequences to information and law.
Execute before access
Track signatures, entities and effective dates.
Review and enforce
Update templates, investigate breaches and retain agreement evidence.
What this could look like in practice
A product company uses employment confidentiality clauses, supplier NDAs and a transaction-specific NDA for acquisition discussions. The latter restricts purpose, named advisers, secure transfer and deletion if negotiations end.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Employee | Confidentiality terms accompany employment agreement. | Signed terms |
| Supplier | NDA precedes sharing architecture details. | Executed NDA |
| Project | Purpose-specific agreement limits recipients and retention. | Project agreement |
| Termination | Return/deletion and continuing duties are confirmed. | Closure record |
Implementation evidence
- NDA policy
- Approved templates
- Legal review
- Signed agreements
- Agreement register
- Disclosure approvals
- Return/deletion evidence
- Breach records
Useful metrics
- Required NDAs signed before disclosure
- Expired or missing agreements
- Template review completion
- Confidentiality breaches
Common mistakes
- Using one template in every country.
- Defining confidential information impossibly broadly.
- Signing after disclosure.
- Failing to bind subcontractors or advisers.
- Keeping agreements without knowing what was shared.
Questions an auditor may ask
- When is an NDA required?
- How are templates selected and reviewed?
- Show proof the agreement preceded disclosure.
- How are return and deletion handled?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.