Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Business Manager

previous version on gdrive

N.2.04 Continuing responsibilities after departure or change in the employment relationship

Control Overview

This control mandates that information security duties—specifically confidentiality and non-disclosure obligations—remain legally binding and enforceable after an individual leaves the organization or changes their internal role. To prevent post-employment data leaks or the unauthorized sharing of proprietary knowledge, the organization must explicitly define these surviving obligations in its contracts. Furthermore, these ongoing duties must be actively communicated to departing or transferring personnel during structured exit procedures and backed by written confirmation.

note

Applicability Note: This control is fully applicable to the anDREa platform, governing all post-employment lifecycles for internal staff, contractors, and third-party personnel.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, transforming standard HR offboarding into an active legal and operational security boundary.

At anDREa, we ensure that confidentiality obligations are not limited by the duration of active employment. Our core employment contracts and contractor NDAs feature explicit "survival clauses" stating that data protection requirements remain fully active post-departure. Operationally, our Onboarding & Offboarding Process bridges the gap between contract law and daily operations. During the mandatory exit interview, a formal review of these enduring responsibilities is conducted, and compliance is recorded within our standardized offboarding templates to establish a verifiable, audit-ready tracking trail.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.06.05 - Responsibilities after termination or change of employmentMandates that information security responsibilities and duties that remain valid after termination or change of employment are defined, communicated, and enforced.
Legal ArchitectureEmployee Contracts (templates)Core contract language establishing that confidentiality and data secrecy covenants legally persist indefinitely after contract expiration.
HR OperationsOnboarding & Offboarding ProcessThe documented record of the exit interview where ongoing non-disclosure expectations are explicitly reviewed with the departing worker.
Process GovernanceOnboarding & Offboarding ProcessThe operational master checklist ensuring every offboarding file receives formal tracking and confirmation of post-employment duties.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Surviving legal clauses, structured exit interview steps, and formalized offboarding templates are fully operationalized and traceably logged.