A.6.6 Confidentiality or Non-Disclosure Agreements
Control Objective
Confidentiality or non-disclosure agreements reflecting the organisation’s needs for the protection of information shall be identified, documented, regularly reviewed and signed by personnel and other relevant interested parties.
Policy Statement
anDREa enforces comprehensive confidentiality and data protection obligations across all organizational relationships. Every employee, customer, supplier, and third-party contractor must execute legally binding Non-Disclosure Agreements (NDAs) and Data Processing Agreements (DPAs) before accessing any anDREa assets or platform environments.
Execution of Confidentiality Mechanisms
Confidentiality clauses and privacy mandates are embedded across three distinct layers of our ecosystem:
- Personnel Safeguards: Strict confidentiality obligations and non-disclosure covenants are written into standard employment contracts, binding all internal personnel to lifelong data protection standards Employee Contracts (templates).
- Customer Protection: Commercial agreements explicitly incorporate mutual confidentiality clauses alongside a formal Data Processing Agreement (DPA). These frameworks govern the secure processing and privacy of client data on the myDRE platform.
- Supplier Governance: Contracts with ICT and infrastructure vendors must incorporate formalized security clauses, NDAs, and DPAs to prevent data exposure and ensure supply chain alignment (see A.05.19 and A.05.21).