Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Confidentiality Obligations
Cyber Security

Confidentiality Obligations

← Back to Glossary
By NHI Mgmt Group Updated September 17, 2026 Domain: Cyber Security

Confidentiality obligations are the duties an employee has to protect sensitive company information during and after employment. They usually come from contracts, policy, or law, and they matter at offboarding because they reinforce that trade secrets, customer data, and internal records must not be taken or disclosed.

What confidentiality obligations actually cover

Confidentiality obligations do more than restate “keep secrets.” They define which information is protected, who may see it, when disclosure is permitted, and how long the duty continues after the working relationship ends.

For practitioners, the practical test is whether the obligation is specific enough to survive a real offboarding event. A useful clause or policy should clearly distinguish confidential business information from material that is already public, independently known, or lawfully required to be disclosed.

Where confidentiality obligations come from

These duties usually arise from three sources: employment or contractor agreements, internal policy, and law. The legal source matters because some information, such as trade secrets or regulated customer data, may remain protected even when a contract is silent.

That mix of sources is why organisations should not treat confidentiality as a single document problem. A contract may set the promise, policy may define the handling rules, and law may create the outer boundary for disclosure, retention, and evidence preservation.

Confidentiality obligations often overlap with Cloud Compliance Pulse 2025 where auditability, confidentiality control, and third-party handling expectations shape how sensitive information is managed across vendors and platforms.

Why offboarding is the highest-friction moment

Offboarding is where confidentiality duties become operational. At that point, access should end, company information should stay with the organisation, and any continuing obligations should be made unmistakable to the departing employee or contractor.

This is also where weak process creates avoidable exposure: documents can be retained on personal devices, files can be forwarded before access is revoked, and knowledge of internal systems can be reused in a competing role. The obligation matters because the risk persists after employment ends, not just during it.

NHIMG’s NHI Lifecycle Management Guide is useful here because it treats offboarding as a lifecycle control problem, not just a people process, which is the same operational mindset needed when sensitive information must be returned, revoked, or destroyed.

How organisations usually enforce the duty

Most enforcement is practical rather than dramatic: limiting access to need-to-know information, logging and reviewing sensitive document access, requiring return or deletion of company material, and preserving records of acknowledgements, exit conversations, and policy sign-off.

Clear definitions help. If an organisation cannot explain what counts as confidential, who owns it, and what must happen at exit, the obligation becomes hard to enforce and easy to dispute. That is especially true when customer data, internal records, product plans, or security information are involved.

The broader lifecycle and visibility angle is captured well in Top 10 NHI Issues, which highlights how unmanaged access, visibility gaps, and entitlement sprawl create exposure when identities or records are not properly controlled.

Risk and Threat Considerations

Confidentiality obligations fail when organisations rely on memory, informal handoffs, or unenforced policy language. The main exposure is not only accidental disclosure, but also intentional misuse of information after access should have ended, especially where a departing person still has copies, screenshots, exports, or retained credentials.

Failure mechanism: The duty is weakened when offboarding does not promptly revoke access, recover material, and document continuing restrictions, leaving sensitive information available for reuse or disclosure.

Impact: Organisations can lose trade secret protection, expose customer or employee data, undermine litigation or regulatory posture, and create avoidable competitive or reputational harm.

A useful indicator of scale is that only 20% of organisations have formal processes for offboarding and revoking API keys, showing how often post-exit control gaps persist in practice. NHIMG’s Ultimate Guide to NHIs reports that figure in the context of lifecycle control failures, which is relevant because confidentiality breaks often follow the same pattern of delayed revocation and poor visibility.

Practitioner Guidance: Treat confidentiality obligations as an exit control, not just a legal clause. The obligation should be easy to explain, easy to evidence, and hard to misunderstand at the moment when access, memory, and incentives are all changing at once.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementConfidentiality obligations depend on limiting and revoking access to sensitive information.
3 — Data ProtectionThe term concerns protecting sensitive company data from disclosure during and after employment.
Recommendation — Enforce least privilege and remove access promptly when employment ends. Classify sensitive data and apply protections that prevent unauthorized disclosure.
NIST CSF 2.0PR.AC — Identity Management, Authentication and Access ControlExit-time confidentiality depends on removing access to protected information and systems.
PR.DS — Data SecurityConfidentiality obligations are about preserving data confidentiality across storage and handling.
PR.IP — Information Protection Processes and ProceduresThe term depends on documented handling, retention, and offboarding procedures.
Recommendation — Revoke access paths quickly and verify that remaining access is justified. Protect sensitive information through handling rules, storage controls, and disclosure limits. Document confidentiality handling and exit procedures so they are consistently followed.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org