Confidentiality Agreement Examples: Sample Wording for Scope, Use, Exceptions and Signatures
Confidentiality agreement examples for a consulting engagement, with sample wording for confidential information, permitted use, exceptions, and legal review and signatures, plus a US-focused review checklist.

A confidentiality agreement looks simple until you have to write one. The hard questions are practical. What exactly is confidential? Who may see it? What happens when the engagement ends? Examples help because they show how the wording of each clause answers those questions in a real situation.
This guide uses one fictional consulting scenario and walks through four parts of a mutual or one-way agreement: confidential information, permitted use, exceptions, and legal review and signatures. The wording is illustrative drafting language, not legal advice, and no clause here is guaranteed to be enforceable or suitable for your circumstances. Names, dates and terms are placeholders.
The scenario used throughout
A small consulting team has been asked by a regional distributor to run a six-week strategy review. Before interviews begin, the client wants to share sales performance notes, draft pricing, a customer list and internal organization charts. The consultants also plan to bring in one subcontractor for analysis and will hold interview notes that reveal how staff talk about management.
That means information flows in both directions and beyond the two named parties. A one-line promise to "keep everything confidential" would not tell anyone what to protect, who may see it or when to delete it. Each of the four sections below fixes one of those gaps.
Part 1: Confidential information
The definition is the core of the agreement, and vague definitions cause the most disputes. A useful definition does three things: it says what is covered, it says how the recipient will know it is covered, and it links the information to the reason for sharing it.
Sample wording:
Purpose. The parties are sharing information solely to allow [Consultant] to carry out the strategy review described in [statement of work reference] (the "Purpose").
Confidential Information means non-public information disclosed by or on behalf of [Client] to [Consultant] in connection with the Purpose, in any form, that is marked confidential or that a reasonable person would understand to be confidential from its nature or the circumstances of disclosure. It includes, for example, [sales performance data, draft pricing, customer lists, organization charts and interview notes].
Two drafting choices are worth noticing. The list of examples is introduced with "for example" so that it illustrates rather than limits the definition. And the definition combines "marked confidential" with "a reasonable person would understand", which avoids the situation where important information goes unprotected because someone forgot a label. Whether to rely on marking at all is a decision for your lawyer.
The US Defend Trade Secrets Act gives a sense of why precision and care matter. Its definition of a trade secret requires that the owner has taken reasonable measures to keep the information secret and that the information derives independent economic value from not being generally known. A confidentiality agreement is one of the ordinary steps an organization may take, but it is only one part of protecting information, and whether any particular information qualifies is a legal question.
Definition check: Could a junior analyst read the definition and know whether a given sales summary, interview note or org chart is covered?
Part 2: Permitted use and disclosure
This section limits what the recipient may do with the information. Good drafting is specific about purpose, people and handling.
Sample wording:
Permitted use. [Consultant] may use Confidential Information only for the Purpose and for no other purpose.
Authorized recipients. [Consultant] may share Confidential Information only with its employees and any subcontractors listed in [Schedule A] who need it for the Purpose and who are bound by written confidentiality obligations no less protective than these.
Handling. [Consultant] will keep Confidential Information in [the approved document store], will restrict access to the persons above, and will not copy it into files or systems used for other clients.
Incident notice. [Consultant] will tell [Client contact] in writing within [number] days after becoming aware that Confidential Information has been used or disclosed in a way this agreement does not permit.
Notice how each clause is tied to something the consultants can actually do. Promise only handling measures you can carry out; an agreement that promises controls the team does not have creates its own breach risk.
If a person outside the two signatories, such as the subcontractor, will see the information, name them or describe the class of person, and say what they must sign first.
Use check: Does every person who will handle the information appear in the agreement or a schedule, and can the team really follow the handling rules?
Part 3: Exceptions, required disclosures and duration
Exceptions say what the agreement does not restrict. They should be short, specific and drafted with a lawyer, because each one narrows the protection.
Sample wording:
Exclusions. Confidential Information does not include information that the receiving party can show (a) is or becomes public other than through its breach of this agreement, (b) was lawfully known to it before disclosure, (c) was lawfully received from a third party without a duty of confidence, or (d) it developed independently without using the Confidential Information.
Required disclosure. The receiving party may disclose Confidential Information to the extent required by law or a court or regulator, provided that, where the law allows, it gives [Client] prompt written notice so that [Client] may seek protective treatment.
Term and return. The obligations in this agreement continue for [duration] from the date of the last disclosure. Within [number] days after a written request or the end of the Purpose, [Consultant] will return or securely delete Confidential Information, except that it may keep [copies required by law or contract, and routine backups] subject to continuing confidentiality.
The retention exception matters because deleting everything is often not possible. Backups and legal or professional record-keeping duties may require copies to remain for a time. Say so plainly instead of promising deletion that cannot happen.
Do not let the agreement silence reporting to regulators
Two US rules illustrate why exceptions cannot be written only from the client's point of view.
First, the Defend Trade Secrets Act provides that an individual is not criminally or civilly liable under federal or state trade secret law for disclosing a trade secret in confidence to a government official or an attorney solely to report or investigate a suspected violation of law, or in a sealed court filing. It also says an employer must give notice of that immunity in any contract or agreement with an employee that governs the use of a trade secret or other confidential information, and that "employee" includes an individual working as a contractor or consultant. If an employer does not give that notice, it may not be awarded exemplary damages or attorney fees in an action against an employee who was not notified.
Second, the SEC's whistleblower protections page quotes Rule 21F-17(a): no person may take any action to impede an individual from communicating directly with Commission staff about a possible securities law violation, including enforcing or threatening to enforce a confidentiality agreement with respect to such communications. The SEC's first enforcement action under this rule involved confidentiality statements that warned witnesses in internal investigations of discipline if they discussed the matter with outside parties without approval from the company's legal department.
Both are US rules, and the extent to which they apply to your agreement depends on who the parties are and what information is involved. Other countries and regulators have their own requirements. The practical lesson for drafting is to include a short carve-out for lawful reporting and to have counsel decide the exact wording:
Protected reporting. Nothing in this agreement prohibits any person from reporting a possible violation of law to a government agency or from making other disclosures protected by law, and no approval or notice to [Client] is required to do so. [Insert any statutory notice your counsel advises for your jurisdiction.]
Exceptions check: Are the exclusions specific, is there a lawful reporting carve-out, and is the return or deletion promise something the team can actually do?
Part 4: Legal review and signatures
The final section turns a draft into a record everyone agrees to. Drafting mistakes made here are easy to avoid.
- Review. Have a qualified lawyer check governing law, remedies, the term, ownership of materials and any statutory notices. A template or an example cannot decide these for you.
- Same version. Confirm both parties sign the same version, with no tracked changes or comments left in the file.
- Authority. Record each signer's name and title and confirm they are authorized to bind the organization.
- Storage. Keep the executed copy and disclosure records in the approved location.
A simple signature block might read:
Signed for [Client]: Name [ ] Title [ ] Date [ ] Signed for [Consultant]: Name [ ] Title [ ] Date [ ] Version signed: [file name and version number] Reviewed by: [legal reviewer, date]
Do not treat silence or continued work as acceptance. Say in the agreement how it becomes effective, and record who approved it and when.
Review the draft before you send it
Use these prompts on a read-through by someone who did not write the draft:
- Purpose and definition: Does the agreement say why information is shared, and what is and is not confidential?
- People: Are subcontractors and advisers named or clearly described?
- Handling: Can the receiving team actually do everything the agreement says?
- Exceptions: Are exclusions and required disclosures specific and reviewed by counsel?
- Reporting: Does the wording avoid impeding lawful reports to regulators, and has counsel checked any required notice?
- Term: Are duration and return or deletion arrangements realistic?
- Consistency: Do the terms match the other documents in the engagement?
- Execution: Are signers authorized, and is the signed version stored?
Adapt the examples in an editable Word draft
If you would rather not rebuild these sections for each engagement, the consulting confidentiality agreement template is an editable Word file with sections for parties, purpose and information, permitted use and disclosure, exceptions, duration and return, and review and execution. It is a starting draft, not a guarantee that any agreement is complete, compliant or enforceable.
Confidentiality terms usually sit alongside other engagement documents. Check that they line up with your consulting statement of work and engagement letter, and have the whole set reviewed by a qualified legal professional before anyone signs.
Sources: 18 U.S.C. § 1833, Cornell Legal Information Institute, 18 U.S.C. § 1839, Cornell Legal Information Institute, Whistleblower Protections, SEC
Last updated: September 26, 2026
Frequently Asked Questions
Related Articles
Audit Checklist Best Practices
Best practices for audit checklists, including scope, evidence, findings, actions, closure review, failure modes and sample wording.
Audit Checklist Checklist: Review Your Audit Form Before You Use It
A practical audit checklist checklist with decision gates for scope, evidence, findings, actions and closure review.
Audit Checklist Examples: Scope, Evidence, Findings and Closure
Audit checklist examples for consulting work, covering audit scope, evidence to inspect, findings and actions, closure review and practical draft wording.
Business Continuity Plan Best Practices for Consulting Teams
Business continuity plan best practices for consulting teams, including critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Checklist for Consulting Teams
A practical business continuity plan checklist for consulting work, covering critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Examples: Consulting Scenarios and Recovery Priorities
Business continuity plan examples for consulting teams, with critical services, recovery priorities, communications, exercises and review criteria.