Non-Disclosure Agreement (NDA)

Confidentiality agreement protecting confidential information in collaboration with external parties.

A Non-Disclosure Agreement (NDA) is a legally binding contract in which one or both parties agree to keep specified information confidential. It is also called a confidentiality agreement, and the two terms mean the same thing. A workable NDA answers four questions: what is confidential, who may see it, for how long, and what happens if it leaks.

One-way or mutual?

This is the practical decision, and it follows from who is actually sharing. Getting it wrong is the most common reason an NDA has to be renegotiated halfway through a conversation.

TypeUse it when
One-way (unilateral)Only you disclose. Typical when you brief a contractor, a candidate or an agency on your systems.
Mutual (bilateral)Both sides disclose. The default for supplier evaluations, partnerships and due diligence, because you will both see things.

If you are being asked to sign a one-way NDA but expect to reveal anything of your own, ask for a mutual one. It is a routine request and refusing it tells you something.

The clauses that decide whether it is usable

Most NDAs look alike. The differences that matter in practice sit in five places, and they are worth reading before signing rather than after an incident.

ClauseWhat to look for
Definition of confidential informationBroad enough to cover what you will actually share, and not dependent on stamping every document "confidential".
Permitted recipientsWhether subcontractors and group companies are included, and whether they are bound on the same terms.
DurationHow long the obligation runs after the relationship ends. Perpetual for trade secrets, a fixed term for commercial detail.
Return and deletionWhat happens to the information at the end, including copies in backups, and whether you get confirmation.
Carve-outsThe standard exceptions: already public, independently developed, or required by law. Check that a legal demand triggers notice to you where notice is allowed.

An NDA is not a technical control

This is the point worth taking away. An NDA gives you a remedy after information has already left. It deters, but it does not prevent: it cannot stop a copy being made.

Treat it as the legal layer on top of the technical one. If the data matters, pair it with access limits, a defined transfer method and a supplier assessment. Auditors look for exactly that pairing, because an NDA on its own shows intent rather than control.

Where ISO 27001 requires one

Annex A 6.6 covers confidentiality and non-disclosure agreements directly, and expects them to be identified, documented, regularly reviewed and signed by personnel and external parties. A.5.20 then covers what your supplier agreements have to say about security, which is where an NDA usually sits in a supplier file.

In practice the finding is rarely a missing NDA. It is that nobody can say which suppliers have signed one, or the version on file predates the current service. Keep them with the supplier record and review them on the same cycle.

Frequently asked questions

What is a non-disclosure agreement (NDA)?
A non-disclosure agreement (NDA) is a legally binding contract in which one or more parties agree not to disclose specified confidential information that is shared with them.
What does NDA stand for?
NDA stands for Non-Disclosure Agreement. It is also commonly called a confidentiality agreement.
What is the difference between a unilateral and a mutual NDA?
In a unilateral NDA only one party discloses confidential information, while in a mutual (bilateral) NDA both parties share information and are bound to protect it.
Why do NDAs matter for compliance?
Frameworks such as ISO 27001 and SOC 2 expect organisations to protect confidential information shared with third parties, and an NDA is a standard control used to enforce that obligation.