Home › HRMS › HR policies › Confidentiality policy
HR policy template

Confidentiality policy template

A confidentiality policy tells employees which information they must protect, how to handle it day to day and what happens when they leave. It covers price lists, formulas and designs, customer databases, tender documents, financial results, source code and salary records, whether on paper, on screen or in conversation. It gives practical rules to the confidentiality or non-disclosure clause in the appointment letter.

When to use it: Issue it at joining along with the confidentiality or non-disclosure clause in the appointment letter, and repeat the key points at exit. A lawyer or senior adviser should review it before the managing director approves it. Brief staff in sales, R&D, accounts and HR separately, as well as anyone with access to customer databases or tender documents.

Confidentiality policy template

Copy the text below and replace everything in square brackets with your company details.

1. Purpose

This policy protects the confidential information of [Company Name], its customers, suppliers and employees by setting clear rules for how employees use, share, store and return it.

2. Scope

It applies to all employees, trainees, interns and consultants, to information in any form, paper, electronic or spoken, and to the period of employment as well as the time after it ends.

3. Definitions

  • Confidential information: any non-public information about [Company Name], its customers, suppliers or employees, including prices, costings, margins, formulas, designs, drawings, source code, business plans, tender and bid documents, customer and vendor lists, contracts, unpublished financial results, and employees' salary and personal records.
  • Public: information the Company has published. Internal: routine information for employees only. Confidential: information limited to the teams that need it. Restricted: highly sensitive information shared only with named people.

4. Policy

  • Use confidential information only for your work, and share it only with colleagues who need it.
  • Do not disclose it to anyone outside the Company, including family, friends and former colleagues, unless you are authorised and a non-disclosure agreement is in place.
  • Mark documents with their classification. Restricted documents are shared by name and never forwarded.
  • Lock away papers and devices at the end of the day, lock your screen when you step away, and collect print-outs immediately.
  • Do not discuss confidential matters in cabs, trains, lifts, restaurants or on speaker phone in an open office.
  • Salary and personal records of colleagues are seen only by those whose role requires it, and HR and payroll staff do not share them, even informally.
  • Information that customers or partners give us is protected according to the terms of our agreements with them.

5. Procedure

  • Report any suspected leak, or any lost document, laptop, phone or pen drive, to [Designation] within [24] hours.
  • Before your last working day, return all documents, devices and copies, delete Company data from personal devices and accounts, and sign the exit confidentiality declaration.
  • Breaches are handled under the Disciplinary Action Policy, and the Company may also take legal action to protect its information.
  • Your duty of confidentiality continues after your employment ends, as stated in your appointment letter.

Exit confidentiality declaration: I confirm that I have returned all documents, devices and data belonging to [Company Name], that I have kept no copies in any form, and that I will continue to keep its confidential information confidential.
[Employee Name], [Employee ID], [Date]

6. Responsibilities

  • Employees: protect information in daily work and report losses at once.
  • Managers: decide who in the team needs access, and remove access when roles change.
  • IT and admin: control access to systems, files and storage rooms.
  • HR: explain the policy at joining and collect declarations at exit.

7. Exceptions

Disclosure is permitted when required by law, a court or a regulator, after informing [Legal Contact] where this is allowed, and when made in good faith under the Whistleblower Policy.

8. Review

[HR Head Designation] and [IT Head Designation] review this policy every [24] months, and after any leak, to check whether the classification and handling rules still fit how the Company works.

What to include

Examples from your business

List the information that matters to you: formulas for a pharma unit, drawings for an engineering firm, patient records for a clinic, source code for a software company. Examples make the definition usable.

A classification people can apply

Three or four levels with one-line meanings are enough. Complex schemes are ignored, and nothing gets marked at all.

Everyday habits

Include printers, screens, cab conversations and speaker phones. Most leaks come from ordinary habits rather than deliberate theft.

Colleagues' salary records

Say who may see payroll data and that HR and payroll staff must not share it informally. Leaked salary sheets cause lasting damage to trust.

Duties after exit

Link the policy to the confidentiality clause in the appointment letter and take a signed declaration at exit, with all devices and documents returned.

Lawful disclosures

Allow disclosures required by law and good-faith whistleblowing. A policy that seems to forbid reporting wrongdoing undermines trust in the whole document.

Common mistakes to avoid

Run it in ZeniaHR

Access Control limits who sees employee information: roles carry eight actions per module, data scope can be all, branch, department, reporting hierarchy or self, and salary, bank and contact fields can be masked by role. Employee Documents are held in secure storage and opened through time-limited download links. At exit, work through the offboarding exit checklist and store the signed confidentiality declaration in the employee's documents.

See it on your own data

A 30-minute demo on a video call. We set up your departments, shifts and leave rules and show attendance, leave and payroll running for your team. Free for your first 50 employees.

Book a free demoSee pricing

Frequently asked questions

What is a confidentiality policy for employees?

A confidentiality policy is a set of rules on how employees handle non-public information: what counts as confidential, how it is classified, who may see it, how it is stored and shared, what to do if it is lost, and what must be returned at exit. It supports the confidentiality clause in the appointment letter.

Does confidentiality continue after an employee leaves?

Yes, where the appointment letter or non-disclosure agreement provides for it, and a good policy repeats this. A former employee must not use or disclose the company's trade secrets, customer data or other confidential information after leaving. Collect all documents and devices before exit and take a signed declaration that no copies were kept.

Is salary information confidential?

Company salary records, such as payroll sheets and the pay of named colleagues, are confidential and should be seen only by HR, payroll and managers who need them. The policy should protect records held by the company rather than stop employees from discussing their own pay, which many companies accept.

What is a clean desk rule?

A clean desk rule asks employees to clear confidential papers from their desks, lock drawers and cupboards, lock screens when they step away and collect print-outs straight away. It prevents casual leaks to visitors and other staff, and can be checked with a quick walk-round at the end of the day.