A Non-Disclosure Agreement (NDA) is a legally binding contract in which one or both parties agree to keep specified information confidential. It is also called a confidentiality agreement, and the two terms mean the same thing. A workable NDA answers four questions: what is confidential, who may see it, for how long, and what happens if it leaks.
One-way or mutual?
This is the practical decision, and it follows from who is actually sharing. Getting it wrong is the most common reason an NDA has to be renegotiated halfway through a conversation.
| Type | Use it when |
|---|---|
| One-way (unilateral) | Only you disclose. Typical when you brief a contractor, a candidate or an agency on your systems. |
| Mutual (bilateral) | Both sides disclose. The default for supplier evaluations, partnerships and due diligence, because you will both see things. |
If you are being asked to sign a one-way NDA but expect to reveal anything of your own, ask for a mutual one. It is a routine request and refusing it tells you something.
The clauses that decide whether it is usable
Most NDAs look alike. The differences that matter in practice sit in five places, and they are worth reading before signing rather than after an incident.
| Clause | What to look for |
|---|---|
| Definition of confidential information | Broad enough to cover what you will actually share, and not dependent on stamping every document "confidential". |
| Permitted recipients | Whether subcontractors and group companies are included, and whether they are bound on the same terms. |
| Duration | How long the obligation runs after the relationship ends. Perpetual for trade secrets, a fixed term for commercial detail. |
| Return and deletion | What happens to the information at the end, including copies in backups, and whether you get confirmation. |
| Carve-outs | The standard exceptions: already public, independently developed, or required by law. Check that a legal demand triggers notice to you where notice is allowed. |
An NDA is not a technical control
This is the point worth taking away. An NDA gives you a remedy after information has already left. It deters, but it does not prevent: it cannot stop a copy being made.
Treat it as the legal layer on top of the technical one. If the data matters, pair it with access limits, a defined transfer method and a supplier assessment. Auditors look for exactly that pairing, because an NDA on its own shows intent rather than control.
Where ISO 27001 requires one
Annex A 6.6 covers confidentiality and non-disclosure agreements directly, and expects them to be identified, documented, regularly reviewed and signed by personnel and external parties. A.5.20 then covers what your supplier agreements have to say about security, which is where an NDA usually sits in a supplier file.
In practice the finding is rarely a missing NDA. It is that nobody can say which suppliers have signed one, or the version on file predates the current service. Keep them with the supplier record and review them on the same cycle.