ISO 27001 Annex A 6.6 Confidentiality or non-disclosure agreements requires clear legal terms to protect company information. Signed agreements stop data leaks and bind employees, contractors, and third parties to confidentiality rules.
Table of contents
Key Takeaways
- Define confidentiality requirements: Set clear non-disclosure terms based on company data sensitivity and risk levels.
- Store agreements centrally: Keep signed non-disclosure agreements in a central document repository to prove compliance during audits.
- Sign before sharing data: Ensure all staff, contractors, and suppliers sign agreements before receiving confidential information.
- Enforce lasting obligations: Make sure confidentiality duties continue after employment or supplier contracts end.
- Clarify permitted data use: State exactly how third parties can handle, share, and protect your business information.
- Maintain active registers: Keep a central tracking list of all signed non-disclosure agreements and expiry dates.
- Review terms regularly: Update confidentiality clauses when business needs, legal rules, or risks change.
- Enforce clear breach penalties: Detail the legal consequences and actions taken if someone breaks confidentiality terms.
How to Implement ISO 27001 Annex A 6.6
- Draft standard agreements: Create approved non-disclosure templates for staff, contractors, and business partners.
- Identify sensitive data types: List the specific files, business plans, code, and customer records covered by confidentiality terms.
- Integrate with onboarding: Require all new employees and contractors to sign confidentiality clauses on their first day.
- Execute vendor agreements: Put mutual or one-way non-disclosure agreements in place before starting supplier discussions.
- Maintain a central register: Log all signed confidentiality documents, active dates, and contact owners in a central system.
- Define data return terms: Include clear rules that require third parties to return or destroy sensitive data once projects end.
- Train staff on terms: Educate workers on what counts as confidential data and how non-disclosure rules apply in daily work.
- Review clauses annually: Check your confidentiality templates each year to ensure they match current privacy laws and ISO standards.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 6.6
- Review non-disclosure templates: Check standard agreement templates to confirm they contain clear data protection duties and breach terms.
- Sample employee contracts: Inspect a random selection of staff files to verify signed confidentiality clauses are present.
- Audit supplier agreements: Check third-party records to confirm signed non-disclosure agreements were in place before data sharing began.
- Check the central NDA register: Review the agreement inventory to ensure all records, signatory names, and renewal dates remain current.
- Verify ongoing post-exit terms: Confirm confidentiality clauses remain legally binding after staff leave or supplier contracts finish.
- Inspect non-standard terms: Check that legal or compliance teams formally reviewed and approved any custom partner agreements.
- Audit training records: Confirm staff completed annual training explaining their duty to protect sensitive company files.
- Review breach incident logs: Check past incident reports to verify proper follow-up on any reported confidentiality violations.
Audit Evidence Checklist
- Standard NDA templates: Maintain approved, up-to-date confidentiality templates in your central document repository.
- Signed staff agreements: Supply countersigned employment contracts containing active confidentiality clauses.
- Signed supplier agreements: Produce valid non-disclosure contracts for all third-party vendors with system access.
- Central NDA register: Keep an active log of all executed confidentiality agreements and their key terms.
- Legal review records: Provide sign-off evidence for any non-standard agreements requested by external clients.
- Offboarding reminders: Supply exit forms showing departing workers received reminders about lasting confidentiality duties.
- Staff training logs: Show sign-off sheets proving workers finished training on confidential data protection.
What to Teach Employees
- Understand confidential data: Teach workers to identify private customer details, trade secrets, source code, and internal plans.
- Get NDAs signed early: Instruct staff never to share company information with third parties without an active, signed agreement.
- Avoid public disclosures: Remind workers never to discuss company projects or client names in public spaces or on social media.
- Respect partner information: Train staff to protect third-party information with the same high level of care as internal assets.
- Use standard templates: Tell workers to use approved agreement templates and avoid altering legal terms without permission.
- Report leaks immediately: Ensure employees know how to report accidental disclosures or broken agreements right away.
- Remember lasting duties: Remind staff that confidentiality rules continue to apply even after they leave the business.
Common Implementation Challenges
- Sharing data before signing: Teams disclose project details before completing paperwork. Require signed agreements before opening discussions.
- Missing central records: Agreements stay in individual email inboxes. Store every executed contract in a single central repository.
- Outdated contract terms: Old agreements fail to cover modern cloud workflows. Review and update legal templates on a set schedule.
- Unmonitored expiry dates: Fixed-term agreements expire while projects continue. Track renewal dates within a central contract log.
- Unapproved custom clauses: Sales teams accept vendor contracts with weak protection. Enforce formal legal reviews for custom terms.
- Vague data definitions: Agreements do not state what information is private. Clearly list all protected data types in the contract.
- Weak exit reminders: Departing workers forget their post-exit duties. Issue written reminders of lasting obligations during offboarding.
How to Measure Effectiveness (KPIs)
- NDA completion rate: Measure the percentage of active vendors and staff with countersigned agreements on file.
- On-time signing rate: Track the proportion of agreements signed before the initial disclosure of confidential data.
- Register accuracy rate: Measure how many physical and digital contracts match central tracking records during audits.
- Confidentiality breach count: Track the total number of unauthorized data disclosures reported each year.
- Expiring agreement review rate: Track the percentage of fixed-term NDAs renewed or closed before their expiry date.
- Staff training completion rate: Measure the percentage of workers who complete annual confidentiality awareness training.
- Audit finding count: Monitor the number of compliance gaps flagged during internal reviews of confidentiality agreements.
Related ISO 27001 Controls
ISO 27001 Control A 6.6 connects to several other ISO 27001 requirements:
Related ISO 27001 Controls
- ISO 27001 Clause 4.2: Understanding needs of interested parties.
- ISO 27001 Annex A 5.31: Legal and contractual requirements.
- ISO 27001 Annex A 6.2: Terms and conditions of employment.

