N.2.01 Confidentiality obligation in employment contracts
Control Overview
This control mandates that the organization formally legally binds all personnel—including full-time employees, temporary workers, and contractors—to strict confidentiality obligations from their first day of engagement. The primary objective is to mitigate insider risk and prevent the unauthorized disclosure or mishandling of sensitive data caused by negligence or malice. Compliance requires that information security responsibilities are explicitly articulated in employment agreements, reinforced by behavioral codes of conduct, and routinely reviewed to align with modern privacy and data protection standards.
Applicability Note: This control is fully applicable to the anDREa platform and is universally enforced across all personnel contracts and third-party contractor engagements.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement incorporates legal protections directly into our human resources lifecycle, driving alignment with our ISO/IEC 27001-based ISMS.
At anDREa, confidentiality is not treated as a passive checkbox, but as a foundational, contractually binding requirement. Security obligations are integrated directly into core Employee Contracts and are augmented by specialized, standalone Non-Disclosure Agreements (NDAs) where operational exposure dictates higher risk. To ensure these legal clauses translate into daily compliance, management pairs contract signing with a mandatory onboarding track. This process systematically details our ISMS policies, behavioral expectations, and clear disciplinary procedures for policy violations.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.06.02 - Terms and conditions of employment | Mandates that contractual agreements with employees and contractors state their responsibilities for information security. |
| ISO/IEC 27001 | A.06.06 - Confidentiality or non-disclosure agreements | Requires confidentiality or non-disclosure agreements reflecting the organization's needs for data protection to be maintained and reviewed. |
| Legal Agreements | Employee Contracts | The primary legal instrument containing explicit, mandatory confidentiality clauses for all internal staff. |
| Third-Party Governance | Contractor Non-Disclosure Agreements (NDAs) | Legally binding security and confidentiality annexes executed with external consultants, partners, and temporary hires. |
| Onboarding Lifecycle | Onboarding & Offboarding Process | Audit records verifying that new hires have completed policy briefings, acknowledged disciplinary frameworks, and formally accepted the ISMS guidelines. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Legal confidentiality obligations, contextual NDAs, and mandatory onboarding validation tracks are completely institutionalized and auditable.