ISO 27001 Confidentiality or Non-disclosure Agreements Explained – Control 6.6

ISO 27001 Confidentiality or Non-disclosure Agreements Explained – Control 6.6

Confidential information only stays confidential if expectations are clear and legally enforceable. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations rely on informal trust, handshakes, or generic, copy-pasted templates when sharing high-value IP, customer databases, or trade secrets with staff, contractors, and vendors. Trust is a wonderful human trait, but in security, it is not a control. Annex A 6.6 is about formalising trust and making sure your confidentiality protections hold up in the real world.

ISO 27001:2022 includes Annex A 6.6 to ensure your business uses legally enforceable Non-Disclosure Agreements (NDAs) and confidentiality clauses. This control replaces former 2013 requirements (13.2.4) and aligns confidentiality obligations directly with your data classification framework, third-party vendor risk management, and post-employment protections.

Quick Summary: What ISO 27001 Annex A 6.6 Requires

At a practical level, Annex A 6.6 is about establishing clear legal boundaries before granting access to sensitive assets. It does not mean forcing every casual visitor to sign a 20-page legal document just to enter reception; it expects risk-proportionate, enforceable terms. Here is what you need to do in plain English:

  • Identify Confidentiality Triggers: Determine which roles, relationships, and third-party vendor engagements require formal NDAs before data access is granted.
  • Define Covered Information Clearly: Explicitly specify what constitutes confidential data, connecting terms to your Information Classification Policy (Annex A 5.12).
  • Set Permitted Use Limits: State precisely how shared data may be processed, who may view it, and restrict copying or distribution.
  • Enforce Surviving (Post-Termination) Terms: Ensure confidentiality obligations remain legally binding long after employment or vendor contracts end.
  • Incorporate Breach Reporting Requirements: Require signatories to report accidental disclosures or security events immediately (Annex A 6.8).
  • Review Legal Enforceability Periodically: Audit agreements to ensure compliance with local employment laws, privacy regulations (e.g., GDPR), and jurisdictional changes.

Why Informal Trust Is a Major Security Hazard

Without legally enforceable confidentiality agreements, your organisation lacks formal recourse if sensitive information is leaked, stolen, or shared with competitors. Informal assumptions leave intellectual property, trade secrets, and customer records wide open to exploitation.

Ignoring confidentiality agreement controls exposes your business to severe hazards:

  • Unprotected Post-Employment Exfiltration: Departing staff taking client lists, product source code, or pricing models to a direct competitor without legal restriction.
  • Third-Party Vendor Exposure: External suppliers, SaaS vendors, or contractors sharing internal architectural diagrams or security audit findings without consent (Annex A 8.30).
  • Inability to Seek Legal Remedies: Courts refusing to grant injunctions or damages following a breach because the business failed to define data as “confidential.”
  • Regulatory Privacy Violations: Disclosing client PII or sensitive personal records to partners without contractual data protection obligations (Annex A 8.10).

My 8 Step Plan to Implement Annex A 6.6 Fast

You do not need a massive legal team on retainer to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready confidentiality framework.

1. Identify Where Confidentiality Agreements Are Mandatory

Audit your organizational touchpoints to determine where confidential information leaves your direct control:

  • All full-time, part-time, and temporary employment contracts (Annex A 6.2).
  • External contractors, freelancers, and independent technical consultants.
  • Third-party suppliers, managed service providers (MSPs), and software vendors (Annex A 8.30).
  • M&A partners, prospective investors, and strategic commercial alliances.

2. Explicitly Scope Covered Information and Exclusions

Vague NDAs that claim “everything is secret” often fail in court. Define covered data precisely:

  • Reference your formal Information Classification scheme (e.g., “Confidential,” “Restricted”) (Annex A 5.12).
  • Specify data formats covered (written documentation, electronic files, source code, oral disclosures, visual demos).
  • State explicit legal exclusions (e.g., information already in the public domain, data lawfully received from a third party, or disclosures required by law).

3. Define Permitted Use and Access Boundaries

Limit how the recipient can use disclosed information once access is granted:

  • State the specific purpose for which the information is being shared (the “Permitted Purpose”).
  • Restrict internal distribution strictly to personnel with a verified need-to-know who have signed equivalent terms.
  • Prohibit copying, modifying, reverse-engineering, or exporting sensitive files outside approved environments.

4. Enforce Surviving Post-Termination Duration

Confidentiality risks do not end when an employment contract or vendor agreement terminates:

  • Specify the exact time horizon for confidentiality obligations (e.g., 3–5 years post-termination, or indefinitely for core trade secrets and source code).
  • Mandate the immediate return or verifiable destruction (crypto-shredding/sanitisation) of all confidential media upon relationship termination (Annex A 7.14).
  • Include post-employment restrictive covenants where permitted by local employment law.

5. Embed Immediate Incident and Breach Notification Terms

Ensure that signatories are contractually bound to assist during security incidents:

  • Mandate immediate notification (e.g., within 24 hours) if a signatory suspects or discovers an unauthorized disclosure.
  • Require full cooperation during incident investigations, forensic triage, and containment efforts (Annex A 5.26).
  • Incorporate duty-to-mitigate clauses forcing the recipient to take immediate steps to halt further exposure.

6. Specify Remedies and Consequences of Breach

Agreements must carry clear weight to act as an effective deterrent against misuse:

  • Outline contractual consequences, including immediate termination of engagement and access rights.
  • Explicitly preserve your right to seek court injunctions, financial damages, and legal cost recovery.
  • For employees, link confidentiality breaches directly to formal disciplinary policies up to and including dismissal.

7. Integrate NDAs into Onboarding and Vendor Workflows

Automate confidentiality execution so data access is never granted prior to signature:

  • Embed confidentiality terms directly into standard employment contracts signed during onboarding.
  • Require signed NDAs before issuing system credentials, physical badges (Annex A 7.2), or access to staging environments.
  • Store signed agreements in a central, searchable contract repository maintained by HR or legal.

8. Review and Update Agreements Periodically

Confidentiality terms degrade over time as laws, technologies, and business models evolve:

  • Review NDA templates annually to ensure alignment with updated data privacy legislation (e.g., GDPR, CCPA).
  • Re-execute agreements when an employee transitions to a higher-risk role or when vendor project scopes expand significantly.
  • Ensure governing law and jurisdiction clauses remain valid across international working arrangements.

Common Implementation Pitfalls and How to Fix Them

When preparing clients for ISO 27001 audits, I frequently spot the same confidentiality agreement mistakes. Here are the main traps and how to solve them:

  • Problem: Relying on a Generic, Single-Page NDA Downloaded from the Internet
    Ninja Solution: Tailor agreement terms to your specific data classification levels, technical environments, and operational risks.
  • Problem: Granting System Credentials to Contractors Before an NDA Is Executed
    Ninja Solution: Block IT account provisioning until HR or Procurement attaches a verified, signed NDA to the onboarding ticket.
  • Problem: Confidentiality Obligations Expiring Immediately When a Contract Ends
    Ninja Solution: Include explicit “Survives Termination” language maintaining confidentiality for 3–5 years or indefinitely for trade secrets.
  • Problem: No Record of Where Signed Vendor NDAs Are Stored
    Ninja Solution: Centralize all vendor and employee NDAs inside a secure digital contract archive linked to your vendor register (Annex A 8.30).

The ISO 27001 Ninja Bottom Line

ISO 27001 Annex A 6.6 is about replacing informal expectations with clear, legally enforceable commitments. Confidential information should never rely on goodwill alone; structure and legal clarity preserve your business assets.

By identifying confidentiality triggers, scoping covered data explicitly, defining permitted use limits, enforcing surviving post-termination terms, embedding breach notification rules, automating execution during onboarding, and maintaining a central contract repository, you protect your intellectual property, mitigate third-party exposure, and satisfy your ISO 27001 auditor with complete confidence.