ISO 27001 Control A.6.6: Confidentiality or Non-Disclosure Agreements
Control A.6.6 is the legal backbone of confidentiality. A great deal of the information an organization needs to protect is not secured by a technical control but by a promise not to disclose it - and that promise is only worth something if it is written down, signed, and kept current. A.6.6 requires confidentiality or non-disclosure agreements (NDAs) that reflect the organization’s real protection needs, and that are identified, documented, regularly reviewed, and signed by the people who handle the information. It is the enforceable partner to the terms and conditions you set at hiring. This is the sixth control in our walk through Annex A.
What the control requires
Annex A control 6.6 of ISO 27001:2022 states that confidentiality or non-disclosure agreements reflecting the organization’s needs for the protection of information shall be identified, documented, regularly reviewed and signed by personnel and other relevant interested parties.
Four active verbs define the obligation:
- Identified - you know where confidentiality agreements are needed (employees, contractors, suppliers, partners, sometimes prospects)
- Documented - the agreements exist in a defined, retrievable form
- Regularly reviewed - they are kept current as needs, law, and relationships change, not signed once and forgotten
- Signed - by the relevant personnel and third parties, so the obligation is actually binding
A.6.6 is a preventive control. Annex A states it; ISO 27002 provides the guidance, and your Statement of Applicability records how you apply it.
How to implement confidentiality agreements
Cover both employees and third parties
Confidentiality obligations arise in two directions. Internally, they are usually built into the employment agreement or a standalone employee NDA. Externally, they take the form of NDAs with suppliers, contractors, partners, and prospects before sensitive information is shared. Map where each is needed - this is the “identified” part - so nobody handling confidential data is doing so without a binding agreement.
Make the agreement say something useful
A confidentiality agreement should reflect your actual needs, not be boilerplate. A strong one covers:
- A clear definition of confidential information (and what is excluded, such as public information)
- The permitted use and the obligation not to disclose
- How long the obligation lasts, including after the relationship ends
- Return or destruction of information on termination
- Consequences of breach, and the governing law
Keep them current with regular review
The word “regularly” is in the control for a reason. Agreements drift out of date as regulations change, as your data changes, and as templates improve. Set a review cycle - annually, or on significant change - for your standard templates, and re-paper long-running relationships when the template materially changes. Record when each template was last reviewed.
Track signatures - an unsigned NDA protects nothing
The control requires agreements to be signed. That means you need a record of who has signed what. For employees, fold NDA acknowledgement into onboarding. For third parties, track executed NDAs in a register or contract system so you can answer, quickly, “is there a signed NDA with this supplier?” An NDA sitting unsigned in a drafts folder gives you no protection.
Store and retain them properly
Signed agreements are records. Keep them retrievable for the life of the relationship and for any period afterward that the obligation or the law requires, under your documented information controls.
Related controls and clauses
A.6.2 connection. Terms and conditions of employment reference confidentiality; A.6.6 is where the detailed, signed obligation lives.
A.6.5 connection. Responsibilities after termination or change of employment rely on the NDA to keep confidentiality binding after someone leaves or moves role.
A.5.19 and A.5.20 connection. Supplier relationship controls require confidentiality terms in supplier agreements - the third-party side of A.6.6.
A.5.14 connection. Information transfer controls often require an NDA to be in place before information is shared externally.
Clause 7.5.3 connection. Signed agreements are controlled documented information - they must be retrievable and retained.
What auditors check
Agreements exist where needed. Auditors check that employees and relevant third parties are covered by confidentiality agreements, and that you can identify where they are required.
They are signed. They sample and look for actual signatures or acknowledgements - executed agreements, not templates. Unsigned NDAs are a common finding.
They are reviewed. Auditors look for evidence the templates are reviewed on a cycle, not frozen for years.
Third-party coverage. They probe whether suppliers and partners with access to confidential information have signed NDAs, often cross-checking with the supplier controls.
They are retrievable. Auditors expect you to produce a specific signed agreement reasonably quickly - a sign the records are actually managed.
Common mistakes to avoid
Unsigned agreements. A confidentiality agreement that was never signed is the most common failure - it provides neither protection nor evidence.
Boilerplate that fits nothing. A generic NDA that does not reflect your actual information or needs is weak. The control specifically requires agreements that reflect your protection needs.
Set and forget. Never reviewing templates leaves them out of step with current law and data. “Regularly reviewed” is an explicit requirement.
Employees covered, third parties not. Handing confidential data to a supplier with no signed NDA is a frequent and serious gap.
No central record. If you cannot tell who has signed what, you cannot demonstrate the control or act on a breach.
Losing post-termination coverage. An NDA that goes silent the moment employment ends leaves your information exposed exactly when the risk rises.
How 27kay can help
We help organizations put confidentiality on a firm legal footing - the right agreements, signed by the right people, reviewed on a sensible cycle, and retrievable when it matters. As part of ISO 27001 implementation, we map where NDAs are needed, align them with your employment, supplier, and information-transfer controls, and set up the signature tracking auditors expect. For the full picture, see our ISO 27001 knowledge hub.
Not sure every supplier with access to your data has a signed NDA? Get in touch - we will review your confidentiality agreements and close the gaps.