A confidential information acknowledgement is a short signed declaration in which an employee confirms they understand what the company treats as confidential and how they must handle, protect and return it, during and after employment. HR collects it at joining, on moving to a sensitive role, and again at exit.
I understand that confidential information includes any non-public information I receive or create in the course of my work at [Company Name], in any form, including but not limited to:
Customer, vendor and employee data, including contact and financial details
Pricing, margins, budgets, financial results and business plans
Product designs, formulations, source code, processes and know-how
Client project information shared with the company in confidence
Salary, appraisal and HR records
Passwords, system configurations and security information
2. How I Will Handle It
I will access confidential information only as needed for my work.
I will store it only in approved company systems and devices.
I will not send it to personal email, personal cloud storage or chat groups.
I will not discuss it in public places or on social media.
I will lock away or shred printed confidential documents.
I will report any accidental disclosure to my manager and IT security immediately.
3. Return and Continuing Duty
On leaving the company, or earlier if asked, I will return or delete all confidential information in my possession and confirm this in writing. I understand that my duty to keep this information confidential continues after my employment ends, as set out in my appointment letter / NDA dated [DD/MM/YYYY].
4. At Exit Only
I have returned all documents, files and storage media containing confidential information
I have deleted company information from personal devices and accounts
I have handed over passwords and access details to my manager / IT
Declaration
I have read and understood this acknowledgement and agree to abide by it.
Employee [Employee Name] Date: [Date]
For [Company Name] [HR Name] Human Resources Date: [Date]
Post in 5 minutesDescribe the role in one line — we write the job description.
Verified applicantsEvery applicant has a verified mobile number.
Resume databaseSearch experienced candidates by skill, city and experience.
Frequently asked questions
Is a confidential information acknowledgement the same as an NDA?+
Not exactly. An NDA is a detailed agreement. The acknowledgement is a shorter declaration confirming the employee understands and accepts their confidentiality duties, often referring to the NDA.
Does confidentiality continue after an employee leaves?+
Usually the duty to protect confidential information continues after exit as per the appointment letter or NDA, subject to applicable law.
What is not confidential information?+
Information already public through no fault of the employee, and the employee's general skills and experience, are typically not treated as confidential.
Passwords: I will use strong, unique passwords for company accounts, keep MFA enabled and never share passwords or OTPs with anyone, including IT staff.
Phishing: I will not click links or open attachments in unexpected emails or messages, and will report suspicious messages to [Email ID].
Devices: I will lock my screen when away, keep company devices updated, and not disable antivirus or encryption.
Removable media: I will not use USB drives or external storage unless approved by IT.
Software: I will install only approved software and will not use unapproved cloud tools or AI tools to process company or client data.
Data: I will handle data according to its classification, share confidential data only with authorised persons, and not send company data to personal email or chat accounts.
Remote work: I will use the company VPN and avoid unsecured public Wi-Fi for company work.
Physical security: I will wear my ID card, prevent tailgating and keep confidential papers locked.
Incidents: I will report any lost device, suspected breach or virus to IT immediately at [Mobile Number].
Monitoring and Consequences
I understand that company systems, email, internet usage and devices may be monitored for security purposes as described in the policy. Violation of the policy may lead to withdrawal of access and disciplinary action in accordance with company rules, after due process.
I declare that I have read the following information security policies of [Company Name]: [Information Security Policy], [Access Control Policy], [Data Classification Policy] and [Incident Management Procedure].
Data Classification and Handling
Classification
Examples
Handling Rule
Public
Website content, brochures
May be shared freely
Internal
Internal circulars, org charts
Share only within the company
Confidential
Client data, contracts, salaries
Need-to-know access; encrypted when sent outside
Restricted
Source code, personal data, credentials
Named access only; never stored on personal devices
I Declare That
I will handle information according to its classification.
I will process personal data only for authorised purposes and in line with the data privacy policy.
I will follow client security requirements on the projects I work on.
I will not try to access information or systems I am not authorised to use.
I will report any actual or suspected security incident to [Security Contact] without delay.