Skip to content
Singahi

Compliance · guide

ISO 27001 A.6.6: Confidentiality or Non-Disclosure Agreements

67 min read

Share
On this page

Quick Reference (60 Seconds)

AttributeDetail
Control IDA.6.6
TitleConfidentiality or Non-Disclosure Agreements
ObjectiveProtect information through legally binding confidentiality agreements
DomainPeople
ISO 27001:2022 ClauseAnnex A.6.6
What You Must DoHave NDAs in place for all personnel with information access; define scope; enforce them
OwnerLegal / CISO / HR
Maturity Level 1No NDA; verbal confidentiality only
Maturity Level 2Basic NDA in offer letter; no standalone agreement; no enforcement
Maturity Level 3Complete standalone NDA; defined scope; all employees signed; annual reminder; enforcement framework
Maturity Level 4Role-based NDAs; automated NDA management; digital signatures; third-party NDAs; regular training; breach monitoring; legal enforcement
Maturity Level 5AI-driven NDA analytics; predictive breach detection; automated contract lifecycle; blockchain evidence; zero-defect NDA compliance; industry leadership
ISO 27002 attributesControl type: Preventive · Properties: Confidentiality · Concepts: Protect · Capabilities: Human resource security, Information protection, Supplier relationships security · Domains: Governance and ecosystem

What the Control Asks For

Do you need this control?

A.6.6 is not mandatory in itself: under clause 6.1.3 you include it if your risk assessment calls for it, and record the decision in your Statement of Applicability. Most organisations include it, because staff, contractors and suppliers see confidential information. You can adapt it with tiered agreements (employee, contractor, supplier, visitor) rather than one template.

The Control in Brief

Annex A 6.6 asks for confidentiality or non-disclosure agreements that reflect the organization's needs for protecting information to be identified, documented, regularly reviewed and signed by personnel and other relevant interested parties.

Implementation Guidance (ISO 27002:2022, paraphrased)

Terms should reflect the type, classification, use and permitted access of the information, and consider:

  • (a) a definition of the information to be protected (for example confidential information)
  • (b) the expected duration, including cases where confidentiality must last indefinitely or until the information becomes public
  • (c) the required actions when the agreement ends
  • (d) the responsibilities and actions of signatories to avoid unauthorised disclosure
  • (e) ownership of information, trade secrets and intellectual property
  • (f) the permitted use of confidential information and the signatory's rights to use it
  • (g) the right to audit and monitor activities involving confidential information, for highly sensitive cases
  • (h) the process for notifying and reporting unauthorised disclosure or leakage
  • (i) return or destruction of information when the agreement ends
  • (j) expected actions on non-compliance

Consider the legal requirements of the jurisdictions involved (A.5.31–A.5.34), and review the requirements periodically and when circumstances change. Confidentiality terms inside an employment contract satisfy A.6.6 if they cover these points; a separate NDA is common but not required.

"Shall" vs "Should" Analysis

  • Shall (once you have selected this control): agreements are identified, documented, reviewed regularly and signed
  • Should: Specific NDA terms, scope, and enforcement mechanisms are flexible based on context

Common Misinterpretations

MisinterpretationReality
"NDA is just one paragraph in the offer letter"One vague paragraph rarely covers 27002's points; a standalone NDA or a full confidentiality section in the contract, with specific scope, duration and enforcement, is far stronger
"NDAs are unenforceable in India"NDAs are enforceable for trade secrets and confidential information; courts enforce reasonable restrictions
"Only employees need NDAs"Contractors, vendors, partners, visitors, and interns also need NDAs
"NDA scope is everything the company has"Scope must be specific and reasonable; overly broad NDAs may be challenged
"Once signed, we never need to review the NDA"Review NDA requirements periodically and when circumstances change (many organisations do it annually)
"NDA is just for post-employment"NDA obligations apply during AND after employment
"We can't enforce NDA against ex-employees"Courts in India enforce NDA breaches with injunctions, damages, and criminal action

Why NDAs Matter

The Business Risk Narrative

NDAs are the primary legal mechanism for protecting confidential information:

  • A 2013 Symantec and Ponemon Institute survey found that about half of employees who left their jobs kept confidential corporate data
  • A written NDA makes legal action far easier; without one you must rely on the equitable duty of confidence, which Indian courts recognise (for example John Richard Brady v Chemical Process Equipments, Delhi HC 1987) but which is harder to prove
  • DPDP Act 2023: NDA obligations reinforce data protection compliance

Regulatory Landscape in India

RegulationNDA RelevanceConsequence
Indian Contract Act 1872NDAs are enforced as contracts (damages under s.73–74; injunctions under the Specific Relief Act); s.27 voids restraints of trade, so an NDA drafted so broadly that it works as a non-compete can failDamages, injunctions
Equitable duty of confidence (case law)Protects confidential information even without a contract, but is harder to proveInjunctions, damages
Copyright Act 1957, s.17–19Employer owns works made in the course of employment; contractors own what they author unless there is a written assignment (s.18–19)Ownership disputes
DPDP Act 2023Processors must be engaged under a valid contract (s.8(2)); staff handling personal data must keep it confidential as part of reasonable safeguards (s.8(5))Up to ₹250 crore for failing to take reasonable safeguards
IT Act 2000, s.72ADisclosing personal information in breach of a lawful contract is an offenceImprisonment up to 3 years, fine up to ₹5 lakh, or both
Patents Act 1970 and Designs Act 2000Disclosure before filing can destroy noveltyLoss of patent or design rights
SEBI (Prohibition of Insider Trading) Regulations 2015Unpublished price-sensitive information must be protected; informant mechanism protects whistle-blowersSEBI penalties
Stamp duty (state Stamp Acts)Agreements must be stamped (e-stamped); an unstamped NDA is inadmissible until duty and penalty are paid (curable, per the Supreme Court in 2023)Delay in enforcement

Industry-Specific Consequences

IndustryNDA Failure Scenario
BFSIEmployee shares customer financial data with competitor; no NDA, so the bank must rely on the harder-to-prove duty of confidence; data breach; customer lawsuit
SaaS / B2BDeveloper takes source code to competitor; no NDA; no IP protection; product cloned; revenue loss; DPDP penalty
HealthtechDoctor shares patient database with competitor; no NDA; personal data breach under the DPDP Act; patient lawsuit
E-commerceCategory manager shares vendor pricing with competitor; no NDA; pricing undercut; margin erosion; vendor disputes
ManufacturingEngineer takes proprietary designs to competitor; no NDA; OEM contract loss; patent dispute; revenue loss
PharmaScientist takes drug formula to competitor; no NDA; patent dispute; clinical trial failure; regulatory action
ConsultingConsultant shares client deliverables with competitor; no NDA; client breach; professional liability; reputation loss
GovernmentOfficer leaks classified data; no NDA; Official Secrets Act prosecution; national security breach
TelecomEngineer shares network architecture with competitor; no NDA; competitive intelligence loss; DOT action
EducationProfessor shares research data with competitor institution; no NDA; IP dispute; funding loss

Scope and Applicability

What the Control Covers

  • NDA identification: Defining what NDAs are needed based on information protection needs
  • NDA documentation: Creating formal, legally binding NDA agreements
  • NDA review: Regular review of NDAs for adequacy and relevance
  • NDA signing: Ensuring all relevant parties sign NDAs before information access
  • NDA scope: Defining what information is covered by the NDA
  • NDA duration: During employment and post-employment obligations
  • NDA enforcement: Legal framework for breach detection and action
  • NDA storage: Secure storage and accessibility for legal action
  • NDA communication: Ensuring signatories understand their obligations
  • NDA training: Educating employees on confidentiality obligations
  • NDA reminder: Periodic reminders of obligations during employment
  • NDA exit reminder: Reminding departing employees of continuing obligations
  • Third-party NDAs: NDAs for vendors, contractors, partners, visitors, interns
  • Role-based NDAs: Different NDA scopes for different roles (general, technical, executive)
  • NDA lifecycle: Creation, signing, review, renewal, enforcement, termination

Who It Applies To

RoleResponsibility
LegalNDA drafting, legal review, enforceability assessment, litigation, breach action, contract law compliance
CISODefining information protection needs, NDA scope, technical confidentiality requirements, breach investigation
HRNDA onboarding, signature collection, NDA storage, employee communication, exit reminder, training coordination
Line ManagerEnsuring team members sign NDAs, reminding team of obligations, reporting suspected breaches
EmployeeSigning NDA, understanding obligations, complying with confidentiality, reporting breaches
ProcurementVendor NDAs, contractor NDAs, third-party NDA management, contract terms
ComplianceNDA compliance audit, regulatory alignment, evidence preparation, DPDP compliance
Board / ManagementNDA policy approval, breach escalation, risk acceptance, strategic IP protection
Vendor / ContractorSigning NDA, understanding obligations, complying with confidentiality, returning data at exit
Visitor / InternSigning short-term NDA, understanding limited obligations, returning access at exit

What It Does NOT Cover

  • General employment terms (covered by employment contract)
  • Non-compete clauses (limited enforceability in India; covered by contract law)
  • IP assignment (covered by IP assignment agreement, though related)
  • Non-solicitation (covered by non-solicitation agreement, though related)
  • General data protection (covered by DPDP policy, though NDA reinforces)
  • Physical security (covered by physical security controls)
  • Technical security controls (covered by technical controls)

Size-Based Applicability

Organization SizeApproach
Startups (< 50)Simple NDA (1-2 pages); all employees and contractors sign; basic scope; digital signature
SMB (50-500)Complete NDA (3-4 pages); role-based scope; third-party NDAs; annual review; digital signature
Mid-market (500-5000)Detailed NDA (5-6 pages); role-based NDAs; third-party NDAs; automated lifecycle; quarterly review; legal enforcement framework
Enterprise (5000+)Enterprise NDA framework; multiple NDA types; automated contract management; predictive analytics; global consistency; legal enforcement

Key Definitions and Terminology

TermDefinitionSource
Non-Disclosure Agreement (NDA)A legally binding contract that establishes a confidential relationship between partiesContract Law
Confidential InformationInformation that is not public and is protected from disclosure under the NDANDA
Trade SecretInformation that derives economic value from being kept secret and is subject to reasonable efforts to maintain its secrecyTrade Secret Law
Proprietary InformationInformation owned by the organization that is protected from disclosureIP Law
DisclosureThe act of revealing confidential information to unauthorized partiesNDA
Permitted DisclosureDisclosure allowed under the NDA (e.g., to employees with need-to-know, to legal advisors)NDA
Return of InformationObligation to return or destroy confidential information upon termination or requestNDA
Survival ClauseClause specifying that NDA obligations continue after termination of employment or agreementNDA
BreachViolation of NDA obligations by unauthorized disclosure or useNDA
RemediesLegal actions available for NDA breach (injunction, damages, specific performance)NDA
InjunctionCourt order preventing a party from doing something (e.g., disclosing trade secrets)Legal
DamagesMonetary compensation for NDA breachLegal
Liquidated DamagesPre-agreed amount of damages for breach (must be reasonable, not penalty)Contract Law
Governing LawLaw that governs the NDA (Indian law for Indian organizations)NDA
JurisdictionCourts that have authority to hear disputes under the NDANDA
CounterpartsMultiple copies of the NDA, each of which is an originalNDA
Electronic SignatureDigital signature that is legally valid under the IT Act 2000IT Act
Third-Party NDANDA signed by external parties (vendors, contractors, partners)NDA
Mutual NDANDA where both parties agree to protect each other's confidential informationNDA
Unilateral NDANDA where only one party agrees to protect the other's confidential informationNDA
Role-Based NDANDA with scope tailored to specific job rolesNDA
NDA LifecycleProcess of creating, signing, reviewing, renewing, and enforcing NDAsContract Management
Contract Management SystemSoftware for managing contracts including NDAsLegal Tech
CLM (Contract Lifecycle Management)Software for managing contract lifecycleLegal Tech

Relationship to Other Controls

Upstream Controls (Prerequisites)

Control IDRelationshipWhy It Matters
A.5.1Policies for Information SecuritySecurity policy must define confidentiality requirements before NDA can be drafted
A.6.1ScreeningScreened employees must sign NDA before access is granted
A.6.2Terms and Conditions of EmploymentEmployment terms should reference NDA obligations
A.6.3Information Security AwarenessEmployees must understand NDA obligations
A.6.4Disciplinary ProcessNDA breach is a disciplinary matter
A.6.5Responsibilities after TerminationNDA obligations continue after termination; must be reminded at exit
A.5.32Intellectual Property RightsIP protection is closely related to NDA; often combined in agreements
A.5.34Privacy and Protection of PIIDPDP obligations are reinforced by NDA

Downstream Controls (Enabled By)

Control IDRelationshipWhy It Matters
A.6.5Responsibilities after TerminationNDA is a primary post-employment obligation
A.8.12Data Leakage PreventionDLP detects NDA breaches (data exfiltration)
A.8.15LoggingLogs provide evidence of NDA breaches
A.8.16Monitoring ActivitiesMonitoring detects NDA breaches
A.8.10Information DeletionNDA requires deletion of confidential information at the end of the agreement
A.5.20Addressing Security within Supplier AgreementsSupplier NDAs sit inside supplier agreements
A.5.12Classification of InformationNDA terms follow the classification of the information shared
A.5.19Information Security in Supplier RelationshipsVendor NDAs enable control over third-party confidentiality
A.5.22Monitoring and ReviewReviews include NDA compliance and adequacy

Parallel Controls (Work Alongside)

Control IDRelationshipWhy It Matters
A.5.32Intellectual Property RightsIP assignment and NDA are often combined in a single agreement
A.5.34Privacy and Protection of PIIDPDP obligations and NDA reinforce each other
A.6.7Remote WorkingRemote workers need NDAs with data protection obligations
A.8.10Information DeletionNDA requires deletion of confidential information
A.8.24Use of CryptographyEncryption supports NDA by protecting confidential data
A.8.20Networks SecurityNetwork security supports NDA by preventing unauthorized disclosure
A.8.30Outsourced DevelopmentDeveloper NDAs are critical for source code protection
A.5.19Information Security in Supplier RelationshipsSupplier NDAs protect shared information

Implementation Roadmap (Week-by-Week)

Phase 1: Discovery & Assessment (Weeks 1-2)

Week 1: Current NDA Assessment

  • Deliverable: Current NDA maturity assessment
  • Owner: Legal + CISO + HR
  • Activities:
    1. Review existing NDAs (if any): offer letter clauses, standalone agreements, third-party agreements
    2. Assess NDA coverage: what percentage of employees have signed NDAs
    3. Assess NDA scope: what information is covered; is it specific or vague
    4. Assess NDA duration: during employment only or post-employment too
    5. Assess NDA enforceability: are terms reasonable under Indian law
    6. Identify gaps: who has not signed, what information is not covered, what third parties lack NDAs
    7. Assess NDA storage: where are signed NDAs stored; are they accessible for legal action
    8. Assess NDA review cycle: when were NDAs last reviewed
    9. Interview managers about NDA awareness and enforcement
    10. Benchmark against industry practices and ISO 27001 requirements

Week 2: Risk and Gap Analysis

  • Deliverable: NDA gap analysis report
  • Owner: Legal + CISO + HR + Compliance
  • Activities:
    1. Map information assets to NDA coverage (what information is protected)
    2. Identify high-risk roles without adequate NDAs (technical, executive, customer-facing)
    3. Identify third-party gaps (vendors, contractors, partners without NDAs)
    4. Assess legal enforceability gaps (overly broad, vague, missing clauses)
    5. Assess NDA lifecycle gaps (no review, no renewal, no enforcement)
    6. Map regulatory requirements for NDAs (DPDP, RBI, SEBI, industry-specific)
    7. Identify trade secrets not covered by NDA
    8. Define target state for NDA maturity
    9. Create gap closure plan

Phase 2: Design & Planning (Weeks 3-4)

Week 3: NDA Design

  • Deliverable: Draft NDA Templates (Employee, Contractor, Vendor, Visitor, Intern)
  • Owner: Legal + CISO + HR
  • Activities:
    1. Draft complete Employee NDA template
    2. Draft Contractor/Third-Party NDA template
    3. Draft Vendor/Partner NDA template
    4. Draft Visitor/Intern Short-Term NDA template
    5. Define role-based NDA scopes (general, technical, executive, customer-facing)
    6. Define confidential information categories (trade secrets, customer data, business plans, source code, etc.)
    7. Define permitted disclosures (employees with need-to-know, legal advisors, regulators)
    8. Define post-employment obligations (duration, scope, return of information)
    9. Define breach consequences (injunction, damages, legal action)
    10. Define governing law (Indian law) and jurisdiction (Indian courts)
    11. Include electronic signature validity clause (IT Act 2000)
    12. Include DPDP compliance reference
    13. Legal review for enforceability under Indian law
    14. Review against Section 27 of Indian Contract Act (restraint of trade)

Week 4: NDA Lifecycle and Management Design

  • Deliverable: NDA Management Framework + CLM Setup Plan + Enforcement Framework
  • Owner: Legal + HR + CISO + IT
  • Activities:
    1. Design NDA onboarding workflow (sign before access, no exceptions)
    2. Design NDA storage and management system (contract repository, digital signatures)
    3. Design NDA review cycle (annual review, trigger-based review)
    4. Design NDA renewal process (for third-party NDAs with expiration dates)
    5. Design NDA training program (employee awareness, manager training)
    6. Design NDA reminder process (annual email reminder, exit reminder)
    7. Design NDA breach detection framework (DLP, monitoring, whistleblower)
    8. Design NDA enforcement framework (breach notice, injunction, litigation, damages)
    9. Design NDA metrics and reporting framework
    10. Select contract management system (CLM) or simple repository
    11. Design integration with HRIS (NDA status in employee record)

Phase 3: Implementation (Weeks 5-8)

Week 5: NDA Rollout to Existing Employees

  • Deliverable: 100% of existing employees have signed NDA
  • Owner: HR + Legal
  • Activities:
    1. Communicate NDA requirement to all employees (why, what, when, consequences)
    2. Distribute NDA for signature (digital or physical)
    3. Track completion rate (target: 100%)
    4. Follow up with non-responsive employees
    5. For employees who refuse: escalate to management; consider access restriction
    6. Store signed NDAs securely (contract repository, access-controlled)
    7. Update HRIS with NDA status for each employee
    8. Create NDA dashboard (signed, pending, refused, expired)

Week 6: Third-Party NDA Rollout

  • Deliverable: All third parties with information access have signed NDA
  • Owner: Legal + Procurement + CISO
  • Activities:
    1. Identify all third parties with access to confidential information (vendors, contractors, partners, consultants)
    2. Send NDA to all third parties without existing NDA
    3. Review existing third-party contracts for NDA clauses
    4. Update procurement process to require NDA before information sharing
    5. Track third-party NDA completion
    6. Store third-party NDAs in contract repository
    7. Create third-party NDA dashboard

Week 7: NDA Training and Communication

  • Deliverable: All employees trained on NDA obligations
  • Owner: HR + CISO + Legal + Training Team
  • Activities:
    1. Create NDA training module (what is confidential, what can't be shared, examples, consequences)
    2. Train all employees on NDA obligations (30-minute session or e-learning)
    3. Train managers on NDA enforcement and breach reporting
    4. Create NDA awareness materials (posters, videos, intranet)
    5. Create employee FAQ on NDA (20 questions)
    6. Create quick reference card for employees
    7. Conduct NDA awareness campaign (monthly reminder)

Week 8: NDA System and Automation

  • Deliverable: NDA management system operational
  • Owner: IT + Legal + HR
  • Activities:
    1. Implement contract management system (CLM) or repository
    2. Upload all signed NDAs to repository
    3. Configure alerts for NDA review, renewal, and expiration
    4. Integrate NDA status with HRIS (employee record shows NDA signed)
    5. Configure automated NDA reminder emails (annual, exit)
    6. Create NDA reporting dashboard (compliance, gaps, breaches)
    7. Test system with mock scenarios

Phase 4: Testing & Validation (Weeks 9-10)

Week 9: Process Testing

  • Deliverable: Process validation report
  • Owner: Legal + Internal Audit + CISO + HR
  • Activities:
    1. Test new hire onboarding with NDA (sign before access)
    2. Test contractor onboarding with NDA
    3. Test vendor NDA process (before information sharing)
    4. Test NDA review process (annual review simulation)
    5. Test NDA breach detection (DLP alert simulation)
    6. Test NDA enforcement process (breach notice template)
    7. Test exit NDA reminder process
    8. Test NDA storage and retrieval (legal action simulation)
    9. Verify 100% employee NDA coverage
    10. Verify 100% third-party NDA coverage

Week 10: Compliance and Audit Validation

  • Deliverable: Compliance validation report
  • Owner: Legal + Compliance Manager + HR
  • Activities:
    1. Validate NDA enforceability under Indian law (Legal review)
    2. Verify DPDP compliance for NDA (personal data in NDA, consent)
    3. Verify electronic signature validity (IT Act compliance)
    4. Verify NDA coverage for all employees (HRIS check)
    5. Verify NDA coverage for all third parties (contract repository check)
    6. Verify NDA review cycle documentation
    7. Verify NDA training completion
    8. Verify NDA storage security and accessibility
    9. Prepare compliance evidence package
    10. Conduct internal audit of NDA program

Phase 5: Documentation & Certification Prep (Weeks 11-12)

Week 11: Documentation

  • Deliverable: Complete NDA documentation
  • Owner: Legal + Compliance Manager
  • Activities:
    1. Document all NDA policies, procedures, and templates
    2. Create illustrative scenarios and examples (anonymized)
    3. Create training materials and videos
    4. Create FAQ and quick reference guides
    5. Create metrics dashboard and reporting templates
    6. Create evidence repository for audits
    7. Document NDA system configuration and workflows

Week 12: Certification Readiness

  • Deliverable: Audit-ready evidence package
  • Owner: CISO + Compliance Manager
  • Activities:
    1. Conduct internal audit of NDA program
    2. Prepare evidence for external ISO 27001 auditor
    3. Remediate any gaps found
    4. Conduct management review
    5. Present program to certification body

Detailed Implementation Guidance

Step-by-Step Implementation

Step 1: Identify NDA Needs

Information CategoryNDA ScopeWho Needs NDANDA Type
Trade SecretsProprietary algorithms, formulas, processes, methodologiesAll employees with accessEmployee NDA (Enhanced)
Customer DataCustomer personal data, financial data, contact informationAll employees with customer accessEmployee NDA (Standard)
Business PlansStrategy, financial projections, M&A plans, investment plansSenior management, finance, strategyEmployee NDA (Executive)
Source CodeSoftware code, API documentation, architectureDevelopers, DevOps, QAEmployee NDA (Technical)
Product RoadmapFuture product plans, feature lists, release schedulesProduct, engineering, marketingEmployee NDA (Standard)
Vendor/Partner DataVendor pricing, contracts, terms, partner informationProcurement, sales, partnershipsEmployee NDA (Standard)
Employee DataHR records, salary data, performance dataHR, managementEmployee NDA (HR)
Regulatory DataRBI reports, SEBI filings, audit reportsCompliance, finance, legalEmployee NDA (Compliance)
Intellectual PropertyPatents, trademarks, designs, copyrightsR&D, legal, productEmployee NDA + IP Assignment
Third-Party Shared DataCustomer data shared with vendors, partner dataVendors, contractors, partnersThird-Party NDA
Visitor Access DataAny information seen during facility visitVisitors, interns, auditorsVisitor/Intern NDA

Step 2: Draft NDA Templates

Employee NDA Template (Key Sections):

Template

Third-Party NDA Template (Key Differences):

  • Mutual or unilateral depending on information flow
  • Specific scope of information being shared
  • Purpose limitation (only for specific project or engagement)
  • Return or destruction of information upon termination
  • IP assignment required for any deliverables (India has no work-for-hire rule for contractors: under Copyright Act s.17 the contractor owns what it authors unless there is a written assignment under ss.18–19)
  • No post-employment obligations (engagement-based)
  • Audit rights for compliance verification
  • Data protection obligations (DPDP compliance)
  • Subcontractor NDA requirements

Visitor/Intern NDA Template (Key Differences):

  • Short-term (duration of visit/internship)
  • Limited scope (only information seen during visit)
  • No IP assignment
  • No post-employment obligations (engagement-based)
  • Immediate return of information and access upon departure
  • Supervision requirement
  • No digital access (physical observation only, if possible)

Step 3: Implement Role-Based NDAs

RoleNDA EnhancementsAdditional Clauses
General EmployeeStandard NDABasic confidentiality, return of information, post-employment obligations
Developer / EngineerTechnical NDASource code protection, IP assignment, open source restrictions, no side projects clause
Sales / Customer-FacingCustomer Data NDACustomer data protection, non-solicitation, no side business with customers
Senior ExecutiveExecutive NDABusiness strategy, M&A, board discussions, enhanced post-employment confidentiality, garden leave during notice (no post-employment non-compete: void under s.27)
HRHR Data NDAEmployee data protection, GDPR/DPDP compliance, no disclosure of sensitive HR information
FinanceFinancial Data NDAFinancial data protection, audit confidentiality, no trading on non-public information
Compliance / LegalRegulatory NDARegulatory data protection, attorney-client privilege, no disclosure of legal strategy
Contractor / ConsultantThird-Party NDAProject-specific scope, written IP assignment for all deliverables, stating the rights, worldwide territory and full term (otherwise s.19(5) limits it to 5 years and s.19(6) to India), data return, audit rights
Vendor / PartnerMutual NDAMutual confidentiality, data protection, subcontractor obligations, audit rights
InternShort-Term NDALimited scope, supervision, no digital access, immediate return
VisitorVisitor NDANo photography, no recording, no disclosure of anything seen, escort requirement

Step 4: Implement NDA Onboarding Workflow

  1. Job Offer Stage: NDA is attached to offer letter; candidate must sign NDA before accepting offer
  2. Pre-Joining Stage: NDA signed and returned before first working day; stored in contract repository
  3. First Day: HR verifies NDA is signed; provides copy to employee; explains obligations
  4. Access Granting: No system access until NDA is confirmed signed in HRIS
  5. Training: NDA training within first week of employment (part of security awareness)
  6. Annual Reminder: Annual email reminding employee of NDA obligations and any updates
  7. Exit: Exit interview includes NDA reminder; signed acknowledgment of continuing obligations
  8. Post-Employment: Monitoring for NDA violations; legal action if breach detected

Step 5: Implement NDA Storage and Management

  • Store all NDAs in secure, access-controlled contract repository
  • Maintain digital copies with electronic signatures (legally valid under IT Act 2000)
  • Maintain version control (NDA v1.0, v2.0, etc.)
  • Link NDA to employee record in HRIS (NDA signed: yes/no, date, version)
  • Link NDA to vendor record in procurement system
  • Ensure legal team has immediate access to NDAs for enforcement
  • Backup NDAs securely (encrypted, off-site)
  • Retain NDAs for duration of employment + post-employment obligation period + 7 years (for legal action)

Step 6: Implement NDA Review Cycle

  • Annual Review: Legal reviews all NDA templates for adequacy, relevance, and legal compliance
  • Trigger-Based Review: Review NDAs when:
    • New information types are created (new product, new data category)
    • Regulatory changes (DPDP Act, new RBI circular)
    • Legal precedents change (court decisions on NDA enforceability)
    • Breach occurs (lessons learned from breach)
    • New role is created (new NDA scope needed)
    • Third-party relationship changes (new vendor, new partnership)
  • Version Control: When NDA is updated, all new hires sign new version; existing employees may need to sign addendum
  • Communication: When NDA is updated, communicate changes to all employees

Step 7: Implement NDA Training and Communication

Employee Training:

  • What is confidential information (specific examples for their role)
  • What they can and cannot share (social media, personal email, public forums)
  • How to handle confidential information (encryption, secure storage, no personal devices)
  • Consequences of breach (disciplinary, legal, criminal)
  • How to report suspected breaches (whistleblower mechanism)
  • Real-world examples of NDA breaches and consequences

Manager Training:

  • How to identify NDA breaches in their team
  • How to report suspected breaches
  • How to enforce NDA obligations
  • How to handle employee questions about confidentiality
  • How to ensure new hires sign NDAs before access

Communication Materials:

  • Posters: "Your NDA: Protect What Matters"
  • Videos: 5-minute NDA explainer video
  • Intranet: NDA FAQ, examples, contact for questions
  • Email: Annual NDA reminder
  • Exit: NDA reminder and continuing obligations

Step 8: Implement NDA Breach Detection

  • DLP Monitoring: Detect data exfiltration (email, cloud, USB, printing)
  • Log Review: Review access logs for unauthorized access or suspicious activity
  • Whistleblower Hotline: Anonymous reporting of suspected NDA breaches
  • Social Media Monitoring: Monitor for confidential information shared on social media (LinkedIn, Twitter, etc.)
  • Competitive Intelligence: Monitor competitor products for signs of trade secret misappropriation
  • Employee Reporting: Encourage employees to report suspected breaches
  • Exit Monitoring: Monitor departing employees for data exfiltration in 30-90 days before exit
  • Third-Party Audit: Audit vendors and contractors for NDA compliance

Step 9: Implement NDA Enforcement

Enforcement Framework:

  1. Breach Detection: Identify a suspected NDA breach through monitoring, a report or other evidence
  2. Incident first: If personal or customer data is involved, handle it as a security incident (A.5.24–A.5.26) and decide notifications at once (CERT-In within 6 hours for reportable incidents; DPDP Board and affected people without delay once the Rules' breach duties apply; sector regulators and customers as required)
  3. Investigation: Gather evidence of breach (logs, documents, witness statements) under A.5.28
  4. Breach Notice: Send formal breach notice to violating party (cease and desist, return of information, damages)
  5. Settlement Negotiation: Attempt to resolve without litigation (return of information, damages, commitment)
  6. Injunction: If urgent, seek court injunction to stop further disclosure or use (ex-parte injunction if necessary)
  7. Civil Litigation: File civil suit for breach of contract, breach of confidence, or copyright infringement
  8. Criminal Action: For theft, criminal breach of trust or cheating (BNS), or IT Act s.72A, file a police complaint
  9. Disciplinary Action: For employees, initiate disciplinary process (A.6.4)
  10. Contract Termination: For third parties, terminate contract and seek damages

Step 10: Implement NDA Metrics and Reporting

  • Track NDA coverage: (Employees with signed NDA / Total employees) × 100
  • Track third-party NDA coverage: (Third parties with NDA / Total third parties with access) × 100
  • Track NDA signing time: Average days from offer to signed NDA
  • Track NDA review cycle: Last review date, next review date
  • Track NDA breach incidents: Number, type, severity, resolution
  • Track NDA enforcement actions: Breach notices, injunctions, litigation
  • Track NDA training completion: (Trained employees / Total employees) × 100
  • Track NDA annual reminder completion: (Reminders sent / Total employees) × 100
  • Report quarterly to management and board
  • Benchmark against industry data

Step 11: Continuous Improvement

  • Annual review of NDA templates and program
  • Quarterly metrics review
  • Post-breach review (lessons learned, NDA improvements)
  • Industry benchmarking (best practices, legal trends)
  • Regulatory updates (DPDP, labor law, industry-specific)
  • Employee feedback on NDA clarity and fairness
  • Legal trend analysis (court decisions on NDA enforceability)
  • Technology updates (new tools for NDA management, detection, enforcement)
  • Union/CBA alignment (if applicable)

Tools, Technologies, and Solutions

Complete Tool Comparison

ToolCategoryBest ForPricing modelKey FeaturesIntegration
DocuSignE-SignatureDigital NDA signingCommercialE-signatures, workflow, templates, audit trail, mobileHRIS, CRM, CLM
Adobe SignE-SignatureEnterprise contract signingCommercialE-signatures, workflow, templates, compliance, analyticsAdobe, HRIS, CRM
HelloSign (Dropbox)E-SignatureSMB e-signaturesCommercialSimple e-signatures, templates, basic workflowDropbox, Google
Zoho SignE-SignatureIndian SMBCommercialE-signatures, Indian compliance, templates, workflowZoho ecosystem
IroncladCLMEnterprise contract lifecycleCommercialContract creation, workflow, repository, analytics, NDA automationSalesforce, HRIS
DocuSign CLMCLMContract lifecycleCommercialContract lifecycle, e-signature, repository, workflowDocuSign, Salesforce
IcertisCLMEnterprise CLMCommercialContract lifecycle, AI, analytics, compliance, globalERP, CRM, HRIS
AgiloftCLMCustomizable CLMCommercialCustomizable workflows, repository, reporting, automationMulti-platform
ContractWorksCLMSimple contract managementCommercialContract repository, alerts, reporting, simple workflowLimited
PandaDocDocumentDocument creation and e-signCommercialDocument templates, e-signature, workflow, CRM integrationCRM, HRIS
Microsoft SharePointRepositoryDocument storageCommercialDocument storage, access control, version control, searchMicrosoft 365
Google DriveRepositoryCloud document storageCommercialDocument storage, access control, version control, searchGoogle Workspace
ServiceNowITSMEnterprise workflowCommercialWorkflow automation, case management, integration, reportingFull enterprise
BambooHRHRISEmployee NDA trackingCommercialEmployee records, document storage, onboarding workflow, reporting100+ integrations
WorkdayHRISEnterprise HRCommercialEmployee records, document management, onboarding, complianceFull enterprise
SAP SuccessFactorsHRISEnterprise HRCommercialEmployee records, document management, onboarding, analyticsSAP ecosystem
Symantec DLPDLPData exfiltration detectionCommercialEndpoint, network, cloud DLP, breach detection, monitoringEnterprise
Forcepoint DLPDLPEnterprise DLPCommercialEndpoint, network, cloud DLP, behavioral analytics, monitoringEnterprise
Microsoft PurviewDLPMicrosoft ecosystemCommercialDLP, eDiscovery, compliance, monitoring, insider riskMicrosoft 365
ProofpointDLPEmail and cloud DLPCommercialEmail DLP, cloud DLP, CASB, insider threat detectionEnterprise
SplunkSIEMLog analysis and monitoringCommercialLog analysis, security monitoring, breach detection, forensicsEnterprise
Elastic SecuritySIEMOpen-source SIEMFree / +Log analysis, security monitoring, breach detectionOpen-source
TeramindMonitoringUser activity monitoringCommercialUser activity monitoring, DLP, behavioral analytics, breach detectionSecurity
ConvercentEthicsWhistleblower hotlineCommercialAnonymous hotline, case management, investigation, complianceHRIS, legal
Navex GlobalEthicsEnterprise ethicsCommercialHotline, case management, investigation, policy, trainingEnterprise
EthicsPointHotlineAnonymous reportingCommercialAnonymous hotline, case management, investigation workflowHRIS, legal
Contract ManagementLegalContract repositoryVariesSecure storage, access control, version control, audit trailLegal, HRIS
SalesforceCRMCustomer data managementCommercialCustomer data, contract management, NDA tracking, reportingCRM ecosystem
HubSpotCRMSMB CRMCommercialCustomer data, document management, basic NDA trackingCRM ecosystem
Zoho CRMCRMIndian SMBCommercialCustomer data, document management, Indian complianceZoho ecosystem
SAP AribaProcurementVendor contract managementCommercialProcurement, vendor contracts, NDAs, complianceSAP ecosystem
CoupaProcurementProcurement and contractsCommercialProcurement, vendor management, contract lifecycle, NDAsERP, CRM
IvaluaProcurementProcurement platformCommercialProcurement, vendor management, contracts, complianceEnterprise

Recommendations by Organization Size

SizeE-SignatureCLMRepositoryDLPHRISMonitoring
Startup (<50)Zoho Sign or HelloSignPandaDoc or ContractWorksGoogle Drive or SharePointMicrosoft PurviewBambooHR or ZohoMicrosoft Purview
SMB (50-500)DocuSign or Zoho SignContractWorks or AgiloftSharePoint or Google DriveMicrosoft Purview or ForcepointBambooHR or GreytHRMicrosoft Purview or Splunk
Mid-market (500-5000)DocuSign or Adobe SignIronclad or DocuSign CLMSharePoint + ServiceNowSymantec or ForcepointWorkday or SAPSplunk or Elastic
Enterprise (5000+)DocuSign + Adobe SignIcertis or IroncladSharePoint + ServiceNow + Legal HoldSymantec + ForcepointWorkday or SAPSplunk + Teramind + Varonis

Policy and Procedure Templates

NDA Policy (Key Sections)

Template

NDA Procedure

Template


Risk Assessment and Treatment

Key Risks Addressed by This Control

Risk IDRisk DescriptionLikelihoodImpactRisk LevelTreatment
R-001Employee discloses confidential information to competitorMediumHighHighMitigate, Complete NDA, training, DLP, monitoring, enforcement
R-002Third party shares confidential information with unauthorized partiesMediumHighHighMitigate, Third-party NDA, audit, data protection, contract terms
R-003NDA is unenforceable due to poor draftingMediumHighMediumMitigate, Legal review, reasonable scope, Indian law compliance
R-004Employee does not understand NDA obligationsMediumMediumLowMitigate, Training, communication, FAQ, examples, annual reminder
R-005NDA not signed before access grantedMediumHighMediumMitigate, Onboarding workflow, HRIS gate, no access without NDA
R-006NDA not reviewed for regulatory changesLowMediumLowMitigate, Annual review, trigger-based review, legal oversight
R-007NDA breach not detectedMediumHighMediumMitigate, DLP, monitoring, whistleblower, social media, competitive intelligence
R-008NDA breach not enforcedMediumMediumLowMitigate, Enforcement framework, legal action, disciplinary process, breach notice
R-009NDA not stored securelyLowMediumLowMitigate, Secure repository, access controls, encryption, backup
R-010Visitor/intern accesses confidential information without NDAMediumMediumLowMitigate, Visitor NDA, escort, limited access, no digital access
R-011NDA scope is overly broad and unenforceableLowHighMediumMitigate, Specific scope, reasonable terms, legal review, role-based
R-012Post-employment NDA obligations not remindedMediumMediumLowMitigate, Exit reminder, signed acknowledgment, monitoring, enforcement
R-013Third-party subcontractors not bound by NDAMediumHighMediumMitigate, Subcontractor NDA clause, audit, flow-down obligations
R-014NDA not integrated with DPDP complianceLowMediumLowMitigate, DPDP reference in NDA, data protection obligations, consent
R-015Electronic signature not legally validLowMediumLowMitigate, IT Act compliance, e-signature platform, audit trail

Audit and Compliance Checklist

Audit Questions (25 Questions)

#Audit QuestionExpected EvidenceRed Flags
1Is there a formal NDA policy?Approved policyNo policy, ad-hoc NDAs
2Are NDA templates documented?NDA templatesNo templates, inconsistent NDAs
3Do all employees have signed NDAs?NDA repository, HRIS recordsMissing NDAs, gaps in coverage
4Are NDAs signed before access is granted?Onboarding records, access logsAccess granted before NDA signed
5Do third parties have signed NDAs?Vendor NDA recordsThird parties without NDAs
6Is NDA scope specific and reasonable?NDA templatesOverly broad or vague scope
7Do NDAs include post-employment obligations?NDA templatesOnly during employment
8Are NDAs reviewed regularly?Review records, version historyNo review, outdated NDAs
9Is NDA training provided?Training records, LMSNo training, employees unaware
10Are NDAs stored securely?Repository, access controlsNo secure storage, lost NDAs
11Is there NDA breach detection?DLP, monitoring, whistleblowerNo detection, breaches undetected
12Is there NDA enforcement framework?Legal framework, breach noticesNo enforcement, breaches ignored
13Are electronic signatures used?E-signature platform, audit trailNo e-signature, manual only
14Are NDAs role-based?Role-based NDA templatesOne-size-fits-all NDA
15Are visitor/intern NDAs in place?Visitor NDA recordsVisitors without NDAs
16Are NDA annual reminders sent?Communication recordsNo reminders, forgotten obligations
17Is NDA exit reminder conducted?Exit interview recordsNo exit reminder
18Are NDA metrics tracked?Metrics dashboardNo metrics, no improvement
19Are subcontractor NDAs required?Third-party NDA termsNo subcontractor obligations
20Is NDA enforceable under Indian law?Legal review recordsUnenforceable terms, legal risk
21Are trade secrets covered by NDA?NDA scopeTrade secrets not covered
22Is DPDP compliance referenced in NDA?NDA templateNo DPDP reference
23Are NDA versions controlled?Version historyNo version control
24Is NDA linked to HRIS/procurement?System integrationNo integration, manual tracking
25Are NDA breaches investigated?Investigation recordsNo investigation, no action

Metrics and KPIs

Figure · Measures

The measures that show A.6.6 is working

  • NDA Coverage100%Monthly
  • NDA Coverage100%Monthly
  • NDA Signing Time<3 daysMonthly
  • NDA Review Cycle Compliance100%Annual
  • NDA Training Completion100%Annual
Targets and reporting cadence as defined in the table below, where the formula for each is given.

Key Metrics Dashboard

KPIFormulaTargetFrequency
NDA Coverage (Employees)(Employees with signed NDA / Total employees) × 100100%Monthly
NDA Coverage (Third Parties)(Third parties with NDA / Total third parties with access) × 100100%Monthly
NDA Signing TimeAverage days from offer to signed NDA<3 daysMonthly
NDA Review Cycle Compliance(NDAs reviewed on schedule / Total NDA templates) × 100100%Annual
NDA Training Completion(Employees completing NDA training / Total employees) × 100100%Annual
NDA Annual Reminder Completion(Reminders sent / Total employees) × 100100%Annual
NDA Breach IncidentsNumber of confirmed NDA breach incidentsTrending downMonthly
NDA Breach Detection Rate(Detected breaches / Estimated breaches) × 100>80%Quarterly
NDA Enforcement ActionsNumber of enforcement actions (notices, injunctions, litigation)Trending upQuarterly
NDA Enforcement Success Rate(Successful enforcements / Total enforcement actions) × 100>70%Quarterly
NDA Exit Reminder Rate(Exit reminders sent / Total exits) × 100100%Per exit
NDA Repository SecuritySecurity audit score for NDA repository>95%Quarterly
NDA Version Control Compliance(NDAs with version control / Total NDAs) × 100100%Monthly
NDA E-Signature Rate(NDAs signed electronically / Total NDAs) × 100>90%Monthly
Visitor NDA Coverage(Visitors with NDA / Total visitors with information access) × 100100%Monthly
Contractor NDA Coverage(Contractors with NDA / Total contractors with access) × 100100%Monthly
NDA Addendum Completion(Employees signing updated NDA / Total affected employees) × 100100%Per update
Third-Party NDA Audit Compliance(Third parties passing NDA audit / Total audited) × 100>95%Annual
NDA Onboarding SLA(NDAs signed within SLA / Total new hires) × 100>98%Monthly
NDA Storage Accessibility(NDAs retrievable within 1 hour / Total test retrievals) × 100100%Quarterly
NDA Breach CostAverage cost of NDA breach (damages, legal, remediation)Trending downAnnual
NDA Program ROI(Value of prevented breaches / NDA program cost)>50xAnnual
NDA Legal Review Compliance(NDAs reviewed by Legal / Total NDA templates) × 100100%Annual
NDA Employee Understanding(Employees who understand NDA / Total) × 100>90%Annual

Common Pitfalls and How to Avoid Them

#PitfallWhy It HappensHow to Avoid
1No NDA at allSmall company, informal culture, trust-basedCreate NDA immediately; even 1-page NDA is better than nothing
2NDA only in offer letterConvenience, lack of legal expertiseCreate standalone NDA with specific scope, duration, enforcement
3NDA scope is overly broadFear of missing something, copying foreign templatesSpecific scope, reasonable terms, role-based, legal review for Indian law
4NDA not signed before accessHR process gap, urgent need for access, no gateOnboarding workflow: no access until NDA verified in HRIS
5No third-party NDAsAssumption that vendors are trusted, procurement gapProcurement process: no contract without NDA; vendor NDA requirement
6NDA not reviewedSet and forget, no process, no legal oversightAnnual review, trigger-based review, version control, legal involvement
7No NDA trainingAssumption that employees know, no training budgetMandatory NDA training as part of security awareness, examples, FAQ
8NDA not stored securelyConvenience, no repository, lost documentsSecure contract repository, access controls, backup, version control
9No enforcementCost, effort, assumption of futilityEnforcement framework, breach notice template, legal action budget
10No post-employment reminderExit process gap, no exit interview, assumptionExit reminder, signed acknowledgment, monitoring, enforcement
11Visitor access without NDAConvenience, short visit, assumption of low riskVisitor NDA for any facility access; escort; limited access
12Electronic signature not validUsing non-compliant platform, no IT Act referenceE-signature platform compliant with IT Act 2000; validity clause in NDA
13No role-based NDAsOne-size-fits-all approach, no analysisRole-based NDA scopes (general, technical, executive, customer-facing)
14Subcontractors not coveredAssumption that vendor handles it, no flow-downSubcontractor NDA clause in vendor contracts; audit; verification
15No DPDP compliance in NDAUnawareness, no DPDP programInclude DPDP data protection obligations in NDA; consent; deletion
16NDA not linked to HRISManual process, no system integrationHRIS integration: NDA status in employee record; automated gate
17No breach detectionNo DLP, no monitoring, no whistleblowerDLP, monitoring, whistleblower, social media, competitive intelligence
18Trade secrets not coveredVague scope, no trade secret identificationSpecific trade secret definition, indefinite protection, enhanced security
19NDA not integrated with exit processSiloed processes, no coordinationExit interview NDA reminder, signed acknowledgment, monitoring
20No metrics or improvementInformal approach, no trackingMetrics dashboard, quarterly review, benchmarking, continuous improvement
21Copying foreign NDA templatesNo local legal expertise, online templatesIndian law review, Section 27 compliance, reasonable restrictions
22No NDA for internsShort-term, assumption of low risk, no processIntern NDA (short-term, limited scope, supervision, no digital access)
23No competitive intelligence monitoringNo resources, no awareness, no toolsCompetitive intelligence program, product monitoring, patent monitoring
24No whistleblower protectionFear of misuse, no policy, no cultureAnonymous hotline, non-retaliation policy, protection for reporters
25No NDA for departing employeesExit process gap, no exit interviewExit NDA reminder, signed acknowledgment, continuing obligations

Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian SaaS Company, DataFlow Analytics

Company Profile:

  • Size: 95 employees
  • Industry: B2B SaaS, Data Analytics Platform
  • Location: Bengaluru, India
  • Customers: 150 enterprise clients globally
  • Regulatory Scope: DPDP Act 2023, SOC 2 Type II, ISO 27001, GDPR

Challenge: DataFlow had minimal NDA protection:

  • Employment offer letters had a vague 2-sentence "confidentiality" clause: "You agree to maintain confidentiality of company information"
  • No standalone NDA; no specific scope; no definition of confidential information
  • No post-employment obligations; no trade secret protection
  • No third-party NDAs for 12 vendors with access to customer data
  • No visitor NDA; investors and potential customers toured the office freely
  • A senior data scientist left and joined a competitor; he took the entire machine learning model architecture and training data
  • DataFlow discovered the competitor's product used the same unique ML approach
  • DataFlow's case was weak because the offer letter clause was too vague, leaving only the harder-to-prove duty of confidence
  • Legal counsel advised that the "confidentiality" clause was unenforceable for trade secrets because it lacked specificity
  • The competitor launched the product and won 3 of DataFlow's customers
  • Revenue decline: 20% in 6 months; valuation drop in next funding round
  • The company had no NDA training; employees did not understand what was confidential
  • No one had ever been reminded of confidentiality obligations
  • No exit interview included NDA reminder

Solution:

  1. Week 1-2: Emergency NDA Creation

    • Engaged an external security consultant for emergency NDA program design
    • Created complete standalone Employee NDA (4 pages) with specific scope:
      • Trade secrets: ML models, algorithms, training data, feature engineering
      • Customer data: all customer data, analytics, reports, dashboards
      • Business information: pricing, strategy, financials, roadmaps
      • Technical information: source code, architecture, API documentation
    • Created post-employment obligations: 3 years for general, indefinite for trade secrets
    • Created IP assignment clause (all work product owned by company)
    • Created breach remedies: injunction and damages (liquidated-damages clauses are limited to a reasonable amount under Section 74 of the Contract Act)
    • Legal review for enforceability under Indian law (Section 27 of Contract Act)
  2. Week 3-4: NDA Rollout

    • Obtained signed NDA from all 95 existing employees (100% compliance)
    • Created digital signature process using DocuSign (legally valid under IT Act)
    • Created NDA repository in Google Drive (secure, access-controlled)
    • Updated HRIS with NDA status for all employees
    • Created third-party NDA template for vendors
    • Sent NDAs to all 12 vendors with customer data access; 11 signed immediately, 1 required negotiation
    • Created visitor NDA for office tours and meetings
    • Created intern NDA for summer interns
  3. Week 5-6: NDA Training and Communication

    • Created NDA training module (30 minutes, e-learning)
    • Training covered: what is confidential, real examples, what can't be shared, consequences
    • All 95 employees completed training (100%)
    • Created NDA FAQ (20 questions) on intranet
    • Created quick reference card for employees
    • Created annual NDA reminder email template
    • Sent first annual reminder to all employees
  4. Week 7-8: NDA Integration and Enforcement

    • Integrated NDA with onboarding workflow: no access until NDA signed
    • Created exit interview NDA reminder (10 questions, signed acknowledgment)
    • Created breach detection framework (DLP, monitoring, whistleblower)
    • Created enforcement framework (breach notice, injunction, litigation)
    • Created NDA metrics dashboard (coverage, breaches, enforcement)
    • Set up Microsoft Purview DLP for data exfiltration detection
    • Set up anonymous whistleblower hotline through EthicsPoint
  5. Week 9-12: Legal Action and Recovery

    • Legal team investigated the ex-data scientist's breach
    • Gathered evidence: code similarity, LinkedIn posts, competitive product analysis
    • Sent breach notice to ex-employee and competitor (cease and desist, damages)
    • Filed for injunction to stop competitor product launch
    • Negotiated settlement: ex-employee returned code, paid damages, and gave a written undertaking not to use the code
    • Competitor removed the infringing feature
    • Won back 2 of the 3 lost customers after demonstrating improved security
    • Created illustrative scenario for sales team on NDA importance

Results:

  • NDA coverage: 100% of employees and 100% of vendors (from 0% and 0%)
  • Training completion: 100% of employees
  • Breach detection: DLP detected 2 data exfiltration attempts in first 6 months (prevented)
  • Legal enforcement: 1 breach notice, 1 injunction, 1 settlement ( recovered)
  • Revenue recovery: Stabilized after initial decline; won back 2 customers
  • Customer trust: Restored after demonstrating NDA program
  • Funding: Next round closed successfully with NDA program as security differentiator
  • Culture: Confidentiality became part of organizational culture

Illustrative Scenario 2: Large Manufacturing, Indian Pharma Ltd. (IPL)

Company Profile:

  • Size: 3,200 employees, 2,800 factory workers
  • Industry: Pharmaceutical Manufacturing (Generic Drugs)
  • Location: Hyderabad and Ahmedabad, India
  • Products: 150+ generic drugs; 8 manufacturing facilities
  • Regulatory Scope: CDSCO, USFDA, EMA, WHO-GMP, DPDP Act 2023, ISO 27001
  • IP: 12 patents, 45+ trade secrets (formulations, processes)
  • Union: Factory workers union; CBA every 3 years

Challenge: IPL had a critical IP protection problem:

  • Only 200 of 3,200 employees had signed NDAs (6% coverage); mostly senior management
  • Factory workers, technicians, and QA staff had no NDAs despite access to proprietary formulations
  • NDA was a 1-page document from 2005 with vague language: "You will not disclose company secrets"
  • No definition of trade secrets; no specific scope; no post-employment obligations
  • No third-party NDAs for 45+ contract manufacturers, API suppliers, and CROs
  • No visitor NDA; consultants and customer auditors toured facilities freely (regulatory inspectors are bound by statute and do not sign company NDAs)
  • A senior formulation scientist left and joined a competitor in Gujarat
  • He took the proprietary formulation for a high-value oncology drug
  • The competitor filed a patent on the same formulation (using IPL's trade secret)
  • IPL had no NDA with the scientist; the vague 2005 document was unenforceable for trade secrets
  • IPL attempted legal action but the court ruled that the NDA was too vague to protect the specific formulation
  • The competitor launched the drug at 30% lower price; IPL lost 40% market share in 12 months
  • Significant revenue loss in the first year; patent dispute ongoing
  • The company had no NDA training; scientists did not understand what constituted a trade secret
  • No exit interview included NDA reminder or IP return verification
  • The union resisted NDAs, fearing "surveillance" and "unfair restrictions on workers"

Solution:

  1. Months 1-2: Union Engagement and NDA Design

    • Engaged an external security consultant for union-compliant NDA program design
    • Established Joint IP Protection Committee (3 management + 3 union representatives)
    • Conducted 6 workshops with union leaders on IP risks and job protection
    • Presented data: IP theft could lead to factory closure, affecting 2,800 jobs
    • Shared industry examples of IP theft and its effect on jobs
    • Union agreed to NDA terms if:
      • NDA is reasonable and not overly broad
      • NDA does not restrict workers from finding new employment (no non-compete)
      • NDA training is paid work time
      • NDA is in local language (Telugu and Gujarati) for factory workers
      • Union representative on IP committee
      • No surveillance or monitoring of personal activity
  2. Months 3-4: Complete NDA Rollout

    • Created complete NDA for all 3,200 employees:
      • Specific definition of trade secrets (formulations, processes, manufacturing methods)
      • Specific definition of confidential information (customer data, pricing, regulatory data)
      • Post-employment obligations: 5 years for formulations, 3 years for general
      • No non-compete (union requirement); focused on non-disclosure and non-use
      • IP assignment clause (all inventions during employment owned by company)
      • Breach remedies: injunction, damages, criminal action (if applicable)
      • In local language (Telugu and Gujarati) for factory workers
    • Created third-party NDA for 45+ vendors and contract manufacturers
    • Created visitor NDA for USFDA, EMA, auditors, consultants
    • Created intern NDA for research interns
    • Created role-based NDA variations (scientist, technician, QA, management, factory worker)
    • Obtained signed NDA from 3,150 employees (98% compliance; 50 refused initially, later convinced)
    • Obtained signed NDA from 43 of 45 vendors (2 required negotiation, later signed)
  3. Months 5-6: NDA Training and Communication

    • Created NDA training in English, Telugu, and Gujarati
    • Training covered: what is trade secret, real examples, what can't be shared, consequences
    • All 3,200 employees completed training (paid work time, as per union agreement)
    • Created visual posters on factory floor: "Your Formulation = Your Job Protection"
    • Created NDA FAQ in 3 languages (30 questions)
    • Created quick reference card for factory workers
    • Trained 200 supervisors on NDA enforcement and breach reporting
    • Annual NDA reminder system established
  4. Months 7-9: NDA Integration and Enforcement

    • Integrated NDA with onboarding workflow: no facility access without NDA
    • Created exit NDA reminder and IP return verification for all exits
    • Implemented DLP across all R&D and manufacturing systems
    • Created competitive intelligence program to monitor competitor patents and products
    • Created whistleblower hotline (anonymous, with union representative oversight)
    • Created legal enforcement framework (breach notice, injunction, litigation, criminal)
    • Created IP committee review of all competitive intelligence findings
    • USFDA audit: zero findings on IP protection; commendation for NDA program
  5. Months 10-12: Legal Action and Recovery

    • Legal team investigated the ex-scientist's breach
    • Gathered evidence: formulation similarity, patent filing analysis, email forensics
    • Sent breach notice to ex-scientist and competitor (cease and desist, damages)
    • Filed for patent invalidation (based on prior use/public knowledge)
    • Filed civil suit for trade secret misappropriation
    • Negotiated settlement: ex-scientist admitted breach, competitor paid damages, patent transferred to IPL
    • Won back 30% market share after competitor withdrew infringing product
    • Created industry illustrative scenario on IP protection in pharmaceutical manufacturing

Results:

  • NDA coverage: 98% of employees (from 6%); 100% of vendors (from 0%)
  • Training completion: 100% of 3,200 employees
  • Union relations: NDA terms agreed with the union
  • Breach detection: DLP detected 5 data exfiltration attempts in first year (prevented)
  • Legal enforcement: 1 breach notice; a patent challenge on the ground that the invention was wrongfully obtained (Patents Act s.25 opposition and s.64 revocation); 1 settlement
  • Market share: Recovered 30% after initial 40% loss
  • Revenue: Stabilized after the initial loss
  • Patent protection: 12 patents protected; 1 recovered through settlement

Multi-Framework Mapping

The references below genuinely overlap with A.6.6. Use them when one set of evidence must satisfy several frameworks.

FrameworkReferenceHow it relates
NIST SP 800-53 Rev 5PS-6 Access agreementsSigned agreements before access, reviewed when needs change
PCI DSS v4.0.112.8.2Written agreements with third-party service providers that handle account data
SOC 2 (2017 TSC)C1.1 (confidential information identified and protected); CC9.2 (vendor and partner risk)Confidentiality commitments with staff and partners
COBIT 2019APO07 Managed human resources; APO10 Managed vendorsAgreements for employees and suppliers
DPDP Act 2023s.8(2) processors engaged under a valid contract; s.8(5) safeguardsConfidentiality terms for anyone processing personal data on your behalf
Indian lawContract Act 1872 s.27 (restraint of trade), ss.73–74 (damages); Copyright Act 1957 ss.17–19 (ownership and assignment)Enforceability of NDA and IP terms

Regulatory and Industry Context

India Regulatory Framework

RegulationNDA RelevanceConsequence
Indian Contract Act 1872NDAs are enforced as contracts (damages under s.73–74; injunctions under the Specific Relief Act); s.27 voids restraints of trade, so an NDA drafted so broadly that it works as a non-compete can failDamages, injunctions
Equitable duty of confidence (case law)Protects confidential information even without a contract, but is harder to proveInjunctions, damages
Copyright Act 1957, s.17–19Employer owns works made in the course of employment; contractors own what they author unless there is a written assignment (s.18–19)Ownership disputes
DPDP Act 2023Processors must be engaged under a valid contract (s.8(2)); staff handling personal data must keep it confidential as part of reasonable safeguards (s.8(5))Up to ₹250 crore for failing to take reasonable safeguards
IT Act 2000, s.72ADisclosing personal information in breach of a lawful contract is an offenceImprisonment up to 3 years, fine up to ₹5 lakh, or both
Patents Act 1970 and Designs Act 2000Disclosure before filing can destroy noveltyLoss of patent or design rights
SEBI (Prohibition of Insider Trading) Regulations 2015Unpublished price-sensitive information must be protected; informant mechanism protects whistle-blowersSEBI penalties
Stamp duty (state Stamp Acts)Agreements must be stamped (e-stamped); an unstamped NDA is inadmissible until duty and penalty are paid (curable, per the Supreme Court in 2023)Delay in enforcement

International Regulations

RegulationNDA Requirement
GDPR (EU)Article 32, security measures; Article 28, processor obligations; Article 5, confidentiality
HIPAA (US)§164.308(a)(4), Information access management; confidentiality obligations
SOX (US)Internal controls including confidentiality and information protection
UK Employment Rights Act 1996Confidentiality obligations; trade secret protection
EU Trade Secret DirectiveTrade secret protection; NDA enforceability; legal remedies
Defend Trade Secrets Act (US)Federal trade secret protection; civil and criminal remedies
Uniform Trade Secrets Act (US)State-level trade secret protection
ILO ConventionWorker rights and fair treatment; confidentiality obligations
WIPOInternational IP protection; trade secret harmonization
UNCITRALInternational contract law; electronic signatures

Sector-Specific Requirements

SectorNDA-Specific Requirements
BFSIRBI-mandated confidentiality; customer data protection; SEBI dealer confidentiality; fraud response; integrity committee; garden leave NDAs
HealthcareClinical staff confidentiality; patient data protection; CDSCO compliance; HIPAA-style confidentiality; clinical trial data protection
TelecomDOT security clearance; subscriber data confidentiality; network architecture protection; lawful interception confidentiality
ManufacturingOT system confidentiality; process protection; IP protection; standing orders; union CBA confidentiality terms; design protection
GovernmentService rules confidentiality; classified data; Official Secrets Act; CVC guidelines; conduct rules; security clearance
DefenceSecurity clearance; classified data; Official Secrets Act; export control; foreign contact confidentiality; defence secrets
AviationDGCA security; airside access confidentiality; safety data protection; substance testing confidentiality; security-critical role NDAs
EducationTeacher confidentiality; student data protection; FERPA/GDPR compliance; research data; IP protection; child safety
SaaS / B2BSource code protection; customer data confidentiality; SOC 2 compliance; developer code of conduct; API protection; cloud data NDAs
E-commerceCustomer data confidentiality; payment data protection; vendor pricing; warehouse data; delivery personnel NDAs
PharmaDrug formula protection; clinical trial data; CDSCO compliance; patent confidentiality; regulatory data; USFDA compliance
ConsultingClient deliverables confidentiality; non-solicitation; professional liability; client relationship protection; proprietary methodology NDAs

Roles and Responsibilities (RACI)

ActivityAccountableResponsibleConsultedInformed
NDA PolicyCISOLegalHRBoard
NDA Template DraftingLegalLegal TeamCISOManagement
NDA Legal ReviewLegalLegal TeamCISOHR
NDA Onboarding (Employee)HRHR ManagerLegalEmployee
NDA Onboarding (Third Party)ProcurementProcurement ManagerLegal, CISOVendor
NDA StorageLegalHR AdminITCISO
NDA ReviewLegalLegal TeamCISO, HRBoard
NDA TrainingCISOTraining TeamHR, LegalAll Employees
NDA CommunicationHRHR ManagerCISOAll Employees
NDA Breach DetectionCISOSecurity TeamLegalHR
NDA Breach InvestigationCISOSecurity TeamLegalHR
NDA EnforcementLegalLegal TeamCISOBoard
NDA MetricsCISOHR AnalystLegalBoard
NDA AuditInternal AuditHR, CISOLegalBoard
NDA Exit ReminderHRHR ManagerCISOEmployee
Third-Party NDA AuditCISOSecurity TeamProcurementLegal
Visitor NDAHRHR AdminCISOFacilities
Intern NDAHRHR ManagerCISOIntern
NDA System ManagementITIT AdminLegalCISO
NDA Union LiaisonLegalHR HeadCISOUnion
NDA Policy ReviewCISOLegalHRBoard
NDA Breach NoticeLegalLegal TeamCISOHR
NDA LitigationLegalLegal TeamCISOBoard
NDA Criminal ActionLegalLegal TeamCISOBoard
NDA Regulatory ReportingComplianceCompliance ManagerCISO, LegalRegulator

Documentation and Evidence Requirements

Required Documents

DocumentOwnerRetention PeriodFormat
NDA PolicyCISO7 yearsPDF + Word
NDA ProcedureHR7 yearsPDF + Word
Employee NDA TemplateLegal7 yearsWord
Third-Party NDA TemplateLegal7 yearsWord
Visitor/Intern NDA TemplateLegal7 yearsWord
Role-Based NDA TemplatesLegal7 yearsWord
Signed Employee NDAsHREmployment + 7 yearsPDF (signed)
Signed Third-Party NDAsProcurementEngagement + 7 yearsPDF (signed)
Signed Visitor/Intern NDAsHRVisit + 3 yearsPDF (signed)
NDA RepositoryLegal7 yearsDigital repository
NDA Version ControlLegal7 yearsVersion history
NDA Review RecordsLegal7 yearsReview records
NDA Training RecordsHR5 yearsLMS records
NDA Communication RecordsHR3 yearsEmail, intranet records
NDA Annual Reminder RecordsHR3 yearsEmail records
NDA Exit Reminder RecordsHR7 yearsExit records
NDA Breach RecordsCISO7 yearsIncident records
NDA Enforcement RecordsLegal7 yearsLegal records
NDA Breach Notice RecordsLegal7 yearsNotices
NDA Litigation RecordsLegal7 yearsCase files
NDA Criminal Action RecordsLegal7 yearsCase files
NDA Metrics and ReportsCISO3 yearsDashboard, reports
NDA Audit EvidenceInternal Audit5 yearsAudit reports
NDA Onboarding RecordsHR7 yearsOnboarding records
NDA E-Signature Audit TrailIT7 yearsE-signature platform records
NDA DPDP Compliance RecordsLegal7 yearsDPDP records
NDA Union Negotiation RecordsLegal7 yearsMeeting minutes
NDA Competitive IntelligenceCISO3 yearsIntelligence reports
NDA Whistleblower RecordsCISO3 yearsHotline records
NDA System ConfigurationIT3 yearsConfiguration records
NDA Lessons LearnedCISO3 yearsDocumentation
NDA Improvement RecordsCISO3 yearsImprovements
NDA Quick Reference CardHR3 yearsCard
NDA Employee FAQHR3 yearsFAQ document
NDA Tool ComparisonCISO3 yearsComparison
NDA Vendor GuideProcurement3 yearsGuide
NDA Assessment GuideCISO3 yearsGuide
NDA Documentation TemplateHR3 yearsTemplate
NDA KPI TrackerCISO3 yearsTracker
NDA Incident Response GuideCISO3 yearsGuide
NDA Training PlanHR3 yearsPlan
NDA Communication TemplateHR3 yearsTemplate
NDA Vendor Management GuideProcurement3 yearsGuide
NDA Risk Assessment TemplateCISO3 yearsTemplate
NDA Compliance ChecklistCompliance3 yearsChecklist
NDA Procedure TemplateHR3 yearsTemplate
NDA Policy TemplateCISO3 yearsTemplate
NDA Audit ChecklistInternal Audit3 yearsChecklist
NDA RACI MatrixCISO3 yearsMatrix
NDA Maturity ModelCISO3 yearsModel
NDA value AnalysisFinance3 yearsAnalysis
NDA Quick Reference CardHR3 yearsCard

Continuous Improvement

Figure · Tiers

Maturity levels for confidentiality or non-disclosure agreements

Maturity levels for ISO 27001 A.6.6, confidentiality or non-disclosure agreements, from most to least mature: Optimizing, ai-driven nda analytics; Quantitatively Managed, automated nda management; Defined, complete standalone nda; Managed, basic nda in offer letter; Initial, no nda; verbal confidentiality only.
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Maturity Model (Level 1-5)

LevelNameDescription
1InitialNo NDA; verbal confidentiality only; no enforcement; no records
2ManagedBasic NDA in offer letter; some employees signed; no standalone agreement; no enforcement; no training
3DefinedComplete standalone NDA; all employees signed; role-based NDAs; third-party NDAs; annual review; training; enforcement framework; exit reminder; metrics
4Quantitatively ManagedAutomated NDA management; digital signatures; CLM system; DLP monitoring; legal enforcement; competitive intelligence; quarterly metrics; breach detection; union compliance
5OptimizingAI-driven NDA analytics; predictive breach detection; automated contract lifecycle; blockchain evidence; zero-defect NDA compliance; continuous legal trend analysis; industry leadership; integrated IP protection

Improvement Cycle

  • Plan: Annual review of NDA templates; quarterly metrics; industry benchmarking; regulatory updates; employee feedback; legal trend analysis; competitive intelligence
  • Do: Deploy new tools; update NDA templates; train employees; enhance detection; improve enforcement; update contracts; refine DLP; competitive monitoring
  • Check: Measure coverage; audit enforceability; benchmark; gather feedback; review breaches; analyze legal trends; competitive intelligence review
  • Act: Standardize; communicate; update procedures; report to management; share best practices; union collaboration; legal framework refinement; patent monitoring
  • AI Contract Analysis: AI analyzing NDAs for gaps, risks, and enforceability
  • Predictive Breach Analytics: AI predicting which employees or third parties are at risk of NDA breach
  • Automated NDA Lifecycle: End-to-end automation from creation to enforcement
  • Blockchain Evidence: Blockchain for immutable evidence of NDA signing and breach
  • Real-Time Breach Detection: Continuous monitoring with AI-driven anomaly detection
  • Smart Contracts: Self-executing NDA enforcement through blockchain smart contracts
  • Digital Contract Assistants: AI chatbots guiding employees through NDA questions and obligations
  • Competitive Intelligence AI: AI monitoring competitor products and patents for NDA breach indicators
  • Integrated CLM+HRIS: Single platform managing employee lifecycle and NDA compliance
  • Cross-Border NDA Management: Automated NDA management for global organizations with multi-jurisdiction compliance

FAQ

Frequently Asked Questions (20 Questions)

Q1: Is an NDA required for ISO 27001 certification? A: Not automatically. No Annex A control is mandatory. Under clause 6.1.3 you choose the controls your risk assessment calls for, then record A.6.6 in your Statement of Applicability as included (and how) or excluded (and why). Most organisations include it, because staff, contractors and suppliers routinely see confidential information. If you include it, auditors will check that the agreements reflect your actual protection needs, are signed and are reviewed periodically.

Q2: Are NDAs enforceable in India? A: Yes, NDAs are enforceable in India for trade secrets and confidential information. However, Section 27 of the Indian Contract Act prohibits agreements in restraint of trade (which may limit non-compete clauses). Courts enforce reasonable confidentiality restrictions. The key is specificity: vague NDAs may be unenforceable.

Q3: What makes an NDA enforceable in India? A: Specificity of scope (what is confidential), reasonable duration, reasonable restrictions, written agreement, signed by both parties, lawful purpose, and consideration. Trade secrets are protected indefinitely as long as they remain secret. General confidential information is typically protected for 2-5 years post-employment.

Q4: Can we include a non-compete clause in the NDA? A: Post-employment non-compete clauses are generally void under Section 27 of the Indian Contract Act (restraint of trade). However, non-compete during employment is valid. For post-employment, focus on non-disclosure, non-use, and non-solicitation instead. Garden leave (paid notice period without work) is a valid alternative.

Q5: Do contractors and vendors need NDAs? A: Yes. Any third party with access to confidential information must sign an NDA. This includes contractors, vendors, partners, consultants, and even visitors who may see confidential information. Third-party NDAs should include data protection obligations (DPDP compliance).

Q6: What is the difference between an NDA and an IP assignment agreement? A: NDA protects confidential information from disclosure. IP assignment agreement transfers ownership of intellectual property (inventions, code, designs) to the employer. They are often combined in a single agreement but serve different purposes. Both are essential for IP protection.

Q7: How long should post-employment NDA obligations last? A: Trade secrets: indefinitely (as long as information remains secret). General confidential information: 2-5 years is reasonable. Business strategy and customer data: 2-3 years. Technical information: 3-5 years. Duration should be reasonable and justifiable; overly long periods may be challenged.

Q8: Are electronic signatures valid for NDAs in India? A: Yes, under the Information Technology Act 2000, electronic signatures are legally valid. Use a compliant e-signature platform (DocuSign, Adobe Sign, Zoho Sign) that provides audit trails. Include an electronic signature validity clause in the NDA.

Q9: What should we do if an employee refuses to sign the NDA? A: Explain the importance and legal requirement. If the employee still refuses, escalate to management. Do not grant access to confidential information until the NDA is signed. If the employee continues to refuse, employment may not proceed (or access is severely restricted). Consult Legal before terminating for NDA refusal.

Q10: What is the scope of confidential information in an NDA? A: The scope should be specific and reasonable. Include: trade secrets, customer data, business plans, financial data, source code, technical documentation, product roadmaps, vendor information, employee data, regulatory data, and any information marked as confidential. Exclude publicly available information and information known before employment.

Q11: Do we need different NDAs for different roles? A: Yes, role-based NDAs are recommended. Developers need source code protection. Sales need customer data protection. Executives need business strategy protection. Factory workers need process protection. Role-based NDAs are more enforceable because they are specific and reasonable.

Q12: How do we enforce an NDA against an ex-employee? A: (1) Gather evidence of breach, (2) Send breach notice (cease and desist), (3) Attempt settlement, (4) Seek injunction if urgent, (5) File civil suit for damages, (6) Consider criminal action if applicable, (7) Notify regulator if required. The NDA provides the legal basis for all these actions.

Q13: What is the difference between a unilateral and mutual NDA? A: Unilateral NDA: one party agrees to protect the other's confidential information (employee-employer). Mutual NDA: both parties agree to protect each other's confidential information (vendor partnerships, joint ventures). Use mutual NDAs when information flows both ways.

Q14: Do interns and visitors need NDAs? A: Yes, if they have access to confidential information. Intern NDAs should be short-term, limited scope, and supervised. Visitor NDAs should cover what they see during the visit, require escort, and prohibit photography/recording. For short facility tours with no confidential access, a simple visitor acknowledgment may suffice.

Q15: How do we handle NDA for remote workers? A: Remote workers should sign the same NDA as on-site employees, with additional clauses: data protection on home devices, secure home office requirements, no co-working space confidentiality, VPN usage, and remote device return obligations. Include BYOD/MDM requirements if applicable.

Q16: What is a "trade secret" and how is it different from "confidential information"? A: Trade secret: information that derives economic value from being kept secret and is subject to reasonable efforts to maintain secrecy (e.g., proprietary algorithms, drug formulas). Confidential information: broader category including any non-public information (e.g., customer lists, business plans). Trade secrets are protected indefinitely; confidential information for a defined period.

Q17: How do we integrate NDA with DPDP Act 2023? A: Include obligations to protect the personal data the employee handles: protect it, use it only for work, not disclose it, and delete it on exit. Keep this separate from the organisation's own processing of the employee's data, which rests on DPDP s.7(i) and a separate notice, not on the NDA. Ensure NDA scope covers personal data as confidential information. Include DPDP consent and grievance mechanisms.

Q18: What should we do if we suspect an NDA breach but have no evidence? A: Investigate discreetly. Gather evidence through DLP logs, access logs, monitoring, competitive intelligence, and witness interviews. Do not accuse without evidence. If evidence is insufficient, increase monitoring and strengthen controls. Document the suspicion and investigation. Consult Legal before sending breach notice.

Q19: Can we combine NDA, IP assignment, and non-solicitation in one agreement? A: Yes, many organizations combine these into a single "Employee Confidentiality and IP Agreement" or "Proprietary Information and Inventions Agreement" (PIIA). This is efficient and ensures all obligations are covered. However, ensure each clause is specific and enforceable. Legal review is essential.

Q20: What will an ISO 27001 auditor look for in A.6.6? A: The auditor will verify: (1) NDAs are identified based on information protection needs, (2) NDAs are documented in formal agreements, (3) NDAs are regularly reviewed, (4) NDAs are signed by all personnel with information access, (5) third-party NDAs are in place, (6) NDA scope is adequate, (7) NDA duration is defined, (8) there is evidence of NDA signing, (9) NDA storage is secure, (10) there is evidence of NDA training and communication, and (11) there is evidence of NDA enforcement capability.


References and Further Reading

ISO Standards

  • ISO 27001:2022: Information Security Management Systems
  • ISO 27002:2022: Information Security Controls
  • ISO/IEC 27701:2025: Privacy information management systems

Indian Law

  • Indian Contract Act 1872: Section 27 (restraint of trade)
  • DPDP Act 2023
  • IT Act 2000: Section 10A (contracts formed electronically); Section 3A and the Second Schedule (electronic signatures, including Aadhaar eSign and DSC). Use Aadhaar eSign or a DSC for enforcement-critical NDAs, and pay stamp duty
  • Copyright Act 1957
  • Patents Act 1970
  • Designs Act 2000
  • Trademarks Act 1999
  • Companies Act 2013
  • Official Secrets Act 1923
  • POSH Act 2013
  • Industrial Relations Code 2020 (standing orders; replaced the Industrial Employment (Standing Orders) Act 1946)
  • Industrial Relations Code 2020 (replaced the Industrial Disputes Act 1947)

International

  • GDPR (EU): Articles 5, 28, 32
  • HIPAA (US): §164.308(a)(4)**
  • SOX (US): Internal controls
  • UK Employment Rights Act 1996
  • EU Trade Secret Directive
  • Defend Trade Secrets Act (US)
  • Uniform Trade Secrets Act (US)
  • ILO Convention
  • WIPO: International IP protection
  • UNCITRAL: International contract law

Industry

  • RBI Cyber Security Framework: Confidentiality obligations
  • SEBI CSCRF (2024): Market data confidentiality
  • IRDAI Guidelines: Insurance data confidentiality
  • NASSCOM: IT industry employment practices
  • ISACA: Security and governance guidance
  • Data Security Council of India: Data protection best practices
  • Verizon DBIR: Data breach investigations
  • Symantec: Insider threat reports
  • Kaspersky: Employee data theft statistics
  • OPPI: Pharmaceutical industry best practices

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.