Glossary

Non-Disclosure Agreement (NDA)

Confidentiality agreement protecting confidential information in collaboration with external parties.

A

B

C

D

E

F

G

H

I

J

K

L

M

N

A Non-Disclosure Agreement (NDA) is a legally binding contract that establishes a confidential relationship between parties, obligating them to protect sensitive information shared during a business relationship. NDAs specify what constitutes confidential information, the obligations of the receiving party, the duration of the confidentiality obligation, and the consequences of a breach, providing a legal framework for secure information exchange.

In a compliance and security context, NDAs are essential when engaging with third parties such as consultants, managed service providers, or potential business partners who may access sensitive data. Frameworks like ISO 27001 specifically require organisations to identify and document confidentiality requirements with external parties, making NDAs a fundamental control in third-party risk management programmes.

O

P

Q

R

S

T

U

V

W

Z

Frequently asked questions

What is a non-disclosure agreement (NDA)?
A non-disclosure agreement (NDA) is a legally binding contract in which one or more parties agree not to disclose specified confidential information that is shared with them.
What does NDA stand for?
NDA stands for Non-Disclosure Agreement. It is also commonly called a confidentiality agreement.
What is the difference between a unilateral and a mutual NDA?
In a unilateral NDA only one party discloses confidential information, while in a mutual (bilateral) NDA both parties share information and are bound to protect it.
Why do NDAs matter for compliance?
Frameworks such as ISO 27001 and SOC 2 expect organisations to protect confidential information shared with third parties, and an NDA is a standard control used to enforce that obligation.