The General Data Protection Regulation (GDPR) doesn't just require companies to secure IT systems or document processes cleanly — the human factor is just as decisive. Data protection doesn't start at the firewall; it starts with employees. As soon as someone in a company works with personal data — such as customer data, employee information, or health data — that person must be bound to confidentiality. In concrete terms, this means: they must confirm in writing that they have been informed of their data protection obligations and commit to not disclosing or using personal data without authorization.
What Is a Confidentiality Agreement?
The confidentiality agreement — often also called a non-disclosure agreement (NDA) or “commitment to data secrecy” — is a central building block of data protection practice in companies. It's a document through which employees or external parties bindingly commit to keeping confidential all personal data they access as part of their work.
Everyday example:
A customer service employee sees addresses, e-mails, and complaints from customers every day. Without a confidentiality agreement, there's a high risk that such information — intentionally or accidentally — could leak out. That's exactly what the agreement is meant to prevent.
Unlike general loyalty clauses in an employment contract, the confidentiality agreement targets data protection requirements specifically — particularly the GDPR and national data protection laws. It therefore serves not only to protect trade secrets, but also to ensure that companies fulfill their legal responsibility to protect personal data.
Is a Confidentiality Agreement Mandatory Under the GDPR?
Yes — in many cases, it's even legally required.
The GDPR requires companies to take appropriate technical and organizational measures to protect personal data from unauthorized access or misuse (Art. 5(1)(f) and Art. 32 GDPR). This includes binding everyone who works with this data to confidentiality.
The German Federal Data Protection Act (BDSG) also spells out this obligation. Section 53 BDSG states:
“Persons involved in data processing may not process or disclose personal data without authorization. This obligation also continues after their activity has ended.”
Important: The commitment must be made actively, documented, and on an individual basis — blanket provisions in a standard employment contract are not sufficient.
Who Needs to Sign a Confidentiality Agreement?
In principle, everyone who has access to personal data as part of their work:
Who does this affect specifically?
- All internal employees, e.g., in HR, IT, marketing, or sales
- External service providers (e.g., IT support, marketing agencies, accounting services)
- Freelancers and consultants
- Interns and working students
- Volunteers and temporary staff
- Where applicable, processors (in addition to the DPA required under Art. 28 GDPR)
What Needs to Be Included in the Confidentiality Agreement?
A GDPR-compliant confidentiality agreement should include at least the following points:
- A reference to Art. 5 and Art. 32 GDPR as well as Section 53 BDSG
- A definition of what personal data is (e.g., names, contact details, IP addresses, health information)
- The obligation to maintain confidentiality during and after employment
- A note on the employment-law or civil-law consequences of violations
- Date, signature, and, where applicable, information about training or the data protection officer
Important for companies:
The signed confidentiality agreement isn't just an organizational step — it's also an important part of the accountability obligation under Art. 5(2) GDPR (“accountability principle”). Companies must be able to demonstrate that they've taken appropriate measures to protect personal data — including proof that everyone involved has been bound to confidentiality.
Practical tip: Keep the signed agreements traceable, whether digitally or on paper — ideally with a note on training or induction. That way, you can prove during a data protection audit that your company has met its obligations.
Common Mistakes With Confidentiality Agreements
- No individual commitment — just a clause in the employment contract
- Missing references to the GDPR or Section 53 BDSG
- No updates when requirements change or roles shift
- No training or documentation of the handover
Tip: A one-time signature isn't enough — regular refreshers (e.g., during onboarding, job changes, or when new tools are introduced) increase both security and liability coverage.
The Role of the Data Protection Officer
The GDPR doesn't just hold companies as a whole accountable — the data protection officer (DPO) also plays a decisive role in ensuring internal data protection compliance.
According to Article 39 GDPR, it's a core task of the data protection officer to
“monitor compliance with this Regulation” and “inform and advise the controller, the processor, and the employees who carry out processing [...].”
In concrete terms, this means:
Employees must be informed about their obligations when handling personal data.
This is ideally done as part of data protection training or onboarding processes.
The confidentiality agreement then serves not only as a legal safeguard, but also as documented proof that the person in question was informed accordingly.
Tip: The task of informing employees shouldn't be treated as a one-off formality. Data protection is an ongoing process — regular reminders and refresher training are worthwhile, and in many industries, even necessary.
Conclusion: No Commitment, No Data Protection
Even the best data protection software is of little use if people aren't on board. A GDPR-compliant confidentiality agreement gives you legal protection, sharpens awareness across the team, and shows that data protection is taken seriously within your company.
FAQ
Do I have to obligate each employee individually?
Do I have to obligate each employee individually?
Yes — blanket clauses in the employment contract aren't enough.
Does the duty of confidentiality continue after leaving the company?
Does the duty of confidentiality continue after leaving the company?
Yes, under Section 53 of the German Federal Data Protection Act (BDSG), the obligation continues even after the employment relationship ends.
Do I also need a declaration for service providers?
Do I also need a declaration for service providers?
Absolutely — either in the DPA or separately. For freelancers, a separate declaration is recommended.







