Confidentiality policy template
Copy the text below and replace everything in square brackets with your company details.
1. Purpose
This policy protects the confidential information of [Company Name], its customers, suppliers and employees by setting clear rules for how employees use, share, store and return it.
2. Scope
It applies to all employees, trainees, interns and consultants, to information in any form, paper, electronic or spoken, and to the period of employment as well as the time after it ends.
3. Definitions
- Confidential information: any non-public information about [Company Name], its customers, suppliers or employees, including prices, costings, margins, formulas, designs, drawings, source code, business plans, tender and bid documents, customer and vendor lists, contracts, unpublished financial results, and employees' salary and personal records.
- Public: information the Company has published. Internal: routine information for employees only. Confidential: information limited to the teams that need it. Restricted: highly sensitive information shared only with named people.
4. Policy
- Use confidential information only for your work, and share it only with colleagues who need it.
- Do not disclose it to anyone outside the Company, including family, friends and former colleagues, unless you are authorised and a non-disclosure agreement is in place.
- Mark documents with their classification. Restricted documents are shared by name and never forwarded.
- Lock away papers and devices at the end of the day, lock your screen when you step away, and collect print-outs immediately.
- Do not discuss confidential matters in cabs, trains, lifts, restaurants or on speaker phone in an open office.
- Salary and personal records of colleagues are seen only by those whose role requires it, and HR and payroll staff do not share them, even informally.
- Information that customers or partners give us is protected according to the terms of our agreements with them.
5. Procedure
- Report any suspected leak, or any lost document, laptop, phone or pen drive, to [Designation] within [24] hours.
- Before your last working day, return all documents, devices and copies, delete Company data from personal devices and accounts, and sign the exit confidentiality declaration.
- Breaches are handled under the Disciplinary Action Policy, and the Company may also take legal action to protect its information.
- Your duty of confidentiality continues after your employment ends, as stated in your appointment letter.
Exit confidentiality declaration: I confirm that I have returned all documents, devices and data belonging to [Company Name], that I have kept no copies in any form, and that I will continue to keep its confidential information confidential.
[Employee Name], [Employee ID], [Date]
6. Responsibilities
- Employees: protect information in daily work and report losses at once.
- Managers: decide who in the team needs access, and remove access when roles change.
- IT and admin: control access to systems, files and storage rooms.
- HR: explain the policy at joining and collect declarations at exit.
7. Exceptions
Disclosure is permitted when required by law, a court or a regulator, after informing [Legal Contact] where this is allowed, and when made in good faith under the Whistleblower Policy.
8. Review
[HR Head Designation] and [IT Head Designation] review this policy every [24] months, and after any leak, to check whether the classification and handling rules still fit how the Company works.
What to include
Examples from your business
List the information that matters to you: formulas for a pharma unit, drawings for an engineering firm, patient records for a clinic, source code for a software company. Examples make the definition usable.
A classification people can apply
Three or four levels with one-line meanings are enough. Complex schemes are ignored, and nothing gets marked at all.
Everyday habits
Include printers, screens, cab conversations and speaker phones. Most leaks come from ordinary habits rather than deliberate theft.
Colleagues' salary records
Say who may see payroll data and that HR and payroll staff must not share it informally. Leaked salary sheets cause lasting damage to trust.
Duties after exit
Link the policy to the confidentiality clause in the appointment letter and take a signed declaration at exit, with all devices and documents returned.
Lawful disclosures
Allow disclosures required by law and good-faith whistleblowing. A policy that seems to forbid reporting wrongdoing undermines trust in the whole document.
Common mistakes to avoid
- Defining confidential information so broadly that everything is covered and nothing is prioritised.
- Not collecting laptops, pen drives and printed files before the last working day.
- Keeping salary sheets on a shared drive that the whole accounts team can open.
- Relying on a signed NDA alone without teaching people the daily habits.
- Forgetting that interns, consultants and temporary staff also see confidential information.
Run it in ZeniaHR
Access Control limits who sees employee information: roles carry eight actions per module, data scope can be all, branch, department, reporting hierarchy or self, and salary, bank and contact fields can be masked by role. Employee Documents are held in secure storage and opened through time-limited download links. At exit, work through the offboarding exit checklist and store the signed confidentiality declaration in the employee's documents.
See it on your own data
A 30-minute demo on a video call. We set up your departments, shifts and leave rules and show attendance, leave and payroll running for your team. Free for your first 50 employees.
Book a free demoSee pricingFrequently asked questions
What is a confidentiality policy for employees?
A confidentiality policy is a set of rules on how employees handle non-public information: what counts as confidential, how it is classified, who may see it, how it is stored and shared, what to do if it is lost, and what must be returned at exit. It supports the confidentiality clause in the appointment letter.
Does confidentiality continue after an employee leaves?
Yes, where the appointment letter or non-disclosure agreement provides for it, and a good policy repeats this. A former employee must not use or disclose the company's trade secrets, customer data or other confidential information after leaving. Collect all documents and devices before exit and take a signed declaration that no copies were kept.
Is salary information confidential?
Company salary records, such as payroll sheets and the pay of named colleagues, are confidential and should be seen only by HR, payroll and managers who need them. The policy should protect records held by the company rather than stop employees from discussing their own pay, which many companies accept.
What is a clean desk rule?
A clean desk rule asks employees to clear confidential papers from their desks, lock drawers and cupboards, lock screens when they step away and collect print-outs straight away. It prevents casual leaks to visitors and other staff, and can be checked with a quick walk-round at the end of the day.