How to Write a Confidentiality Agreement: Information, Use, Exceptions and Signatures
Learn how to write a confidentiality agreement for consulting work, with confidential information, permitted use, exceptions, legal review and signatures.

A confidentiality agreement is easy to start and easy to make too vague. "Keep everything confidential" does not tell a consultant what information is covered, who may see it, what the information may be used for, or what happens when the engagement ends.
This guide uses a consulting scenario: a strategy review for a regional distributor. The client will share pricing notes, customer information, sales performance summaries and organization charts. The consulting firm will use one subcontractor for analysis. The sample wording is illustrative only and is not legal advice.
Identify the Parties, Purpose and Information
Start with the parties and the purpose for sharing information. The purpose controls the rest of the agreement. Without it, the permitted use clause has nothing to point to.
Draft language:
Purpose. The parties are sharing information solely so [Consultant] can perform the strategy review described in [statement of work reference].
Confidential Information. Confidential Information means non-public information disclosed by or on behalf of [Client] to [Consultant] in connection with the Purpose, whether oral, written, electronic or visual, that is marked confidential or that a reasonable person would understand to be confidential from its nature or the circumstances of disclosure. Examples include sales performance summaries, draft pricing, customer lists, organization charts and interview notes.
Be careful with examples. If the list is meant to be illustrative, say so. If it is meant to be exhaustive, that is a legal decision and should be reviewed.
The US Defend Trade Secrets Act defines a trade secret in terms that include reasonable measures to keep information secret and independent economic value from not being generally known (18 U.S.C. 1839). Do not assume every confidential item is a trade secret. The point is narrower: the agreement should show deliberate handling of information, and counsel should decide how trade secret language applies.
Limit Permitted Use and Disclosure
Permitted use says what the recipient may do with the information. For a consulting engagement, the clause should cover project work, team members, advisers and subcontractors.
Draft language:
[Consultant] may use Confidential Information only for the Purpose. [Consultant] may disclose Confidential Information only to its employees, professional advisers and approved subcontractors who need the information for the Purpose and who are bound by written confidentiality obligations at least as protective as this agreement.
Add handling expectations only if the parties can meet them:
[Consultant] will store Confidential Information in the approved project workspace and will not copy it into files used for other clients.
Do not promise security controls you do not operate. If the client requires a particular system, encryption method, deletion process or access log, confirm that it is available before signing.
For subcontractors, be concrete:
The subcontractor listed in Schedule A may access the purchasing-volume input file and analysis-output folder only. Interview notes, pricing strategy drafts and personnel information may not be shared with the subcontractor unless [Client] approves in writing.
Include Exceptions and Required Disclosures
Exceptions prevent the agreement from overreaching. Common exceptions address information the recipient already knew, public information, information lawfully received from someone else and independently developed information.
Draft language:
Confidential Information does not include information the receiving party can show was lawfully known to it before disclosure, is or becomes public other than through breach of this agreement, is lawfully received from a third party without a duty of confidence, or is independently developed without use of the Confidential Information.
Required disclosure language should address courts, regulators and law:
The receiving party may disclose Confidential Information to the extent required by law, court order or regulator, provided that where legally permitted it gives prompt notice so the disclosing party may seek protective treatment.
In the United States, confidentiality wording should not block protected reporting. The SEC states that Rule 21F-17(a) prohibits taking action to impede an individual from communicating directly with SEC staff about a possible securities law violation, including by enforcing or threatening to enforce a confidentiality agreement for such communications (SEC). Other regulators and countries have their own rules.
The Defend Trade Secrets Act also contains immunity provisions for certain confidential disclosures to government officials or attorneys to report or investigate suspected legal violations, and includes notice provisions for contracts with employees, including contractors and consultants (18 U.S.C. 1833). Have a lawyer decide whether and how to include notices and carve-outs.
Address Duration, Return and Deletion
Duration should match the information and law that applies. Some information may need protection for a fixed period. Some trade secret obligations may be drafted differently. Do not copy a duration without review.
Draft language:
The obligations continue for [period] after the last disclosure, except that trade secrets are protected for as long as they remain trade secrets under applicable law.
Return and deletion wording should be realistic:
Within [number] days after the Purpose ends or after written request, [Consultant] will return or securely delete Confidential Information, except for copies retained in routine backups, legal records or professional files that [Consultant] is required or permitted to keep. Retained copies remain subject to confidentiality obligations.
That exception matters. Many firms cannot truthfully promise instant deletion from every backup. Counsel should tailor the wording to the parties' systems and duties.
For consulting work, align this clause with the engagement documents. A statement of work may require the consultant to keep project records for a set period, while the confidentiality agreement may ask for deletion on request. If both are true, the agreement should explain which retained records may remain and under what continuing restrictions.
Draft coordination note:
The parties will reconcile this clause with any record-retention obligations in the statement of work or service agreement before signature. Where retained copies are permitted, they remain confidential and may be used only for the limited retention purpose.
This is not just legal tidiness. It prevents the project team from promising deletion that conflicts with its own professional or contractual records process.
Legal Review and Signatures
Before signature, review:
- Are the correct legal names used?
- Does the purpose match the statement of work?
- Are subcontractors and advisers handled?
- Are exceptions and lawful reporting carve-outs included?
- Does the duration match the information?
- Are return, deletion and retained-copy terms realistic?
- Is governing law addressed by counsel?
- Are signers authorized?
- Are tracked changes and comments removed from the signing copy?
Signature block:
Signed for [Client]: Name, title, date.
Signed for [Consultant]: Name, title, date.
Version signed: [file name and version number].
Store the signed agreement where the project team can verify it before information is shared. A confidentiality agreement that sits in someone's inbox is easy to miss when a subcontractor joins later or when a new team member asks for access.
Use an Editable Agreement Draft
The consulting confidentiality agreement template is an editable Word document with sections for parties, purpose and information, permitted use and disclosure, exceptions, duration and return, review and execution. It is a drafting structure, not a guarantee that the agreement is enforceable or compliant.
The practical goal is clarity: what information is protected, why it is shared, who may use it, what is excluded and who approved the final wording.
Last updated: September 26, 2026
Frequently Asked Questions
Related Articles
Audit Checklist Best Practices
Best practices for audit checklists, including scope, evidence, findings, actions, closure review, failure modes and sample wording.
Audit Checklist Checklist: Review Your Audit Form Before You Use It
A practical audit checklist checklist with decision gates for scope, evidence, findings, actions and closure review.
Audit Checklist Examples: Scope, Evidence, Findings and Closure
Audit checklist examples for consulting work, covering audit scope, evidence to inspect, findings and actions, closure review and practical draft wording.
Business Continuity Plan Best Practices for Consulting Teams
Business continuity plan best practices for consulting teams, including critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Checklist for Consulting Teams
A practical business continuity plan checklist for consulting work, covering critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Examples: Consulting Scenarios and Recovery Priorities
Business continuity plan examples for consulting teams, with critical services, recovery priorities, communications, exercises and review criteria.