1. The essential clauses of a confidentiality policy
    1. What counts as confidential information
    2. What is not confidential
    3. Who has to follow it
    4. How information must be handled
    5. What happens when someone leaves
    6. What happens on a breach
  2. Optional clauses worth considering
  3. When to have a lawyer review your confidentiality policy
  4. The clause that decides whether your policy ever works

You have a confidentiality policy to draft because someone is about to get access to information that would hurt your business if it leaked: a new employee, a developer contractor, or an investor carrying out due diligence. The template sitting in front of you probably looks like a formality, but the choices made in each clause decide whether the document is ever enforced, and against whom.

A confidentiality policy is an internal document, not a contract. It states what your business treats as confidential, who must protect it, how it must be handled in the day to day, and what happens when those rules are broken. On its own it does not bind anyone outside your organisation. It works by supporting the obligations in your employment contracts, contractor agreements and non-disclosure agreements, and by recording what you regarded as confidential and how you expected it to be treated if a dispute ever reaches a court.

The essential clauses of a confidentiality policy

What counts as confidential information

The definition clause is the clause everything else hangs off. If it is too vague, staff cannot tell what is protected. If it is unrealistically broad, it gets ignored, and a court will not treat it as a serious record of what the business actually protects. The most workable drafting combines a short general description with a list of examples, such as:

  • Customer information: customer lists, contact details, buying patterns and support history.
  • Pricing and margins: quotes, discounting rules, wholesale rates and deal terms.
  • Business strategy: budgets, fundraising plans, growth targets and board papers.
  • Product and technical information: source code, designs, prototypes, roadmaps and test data.
  • Marketing plans: campaign calendars, influencer lists and advertising account insights.
  • Operations and processes: supplier terms, onboarding checklists and internal workflows.
  • Employee information: where relevant, and handled in line with privacy obligations.

The examples should also be tailored to your industry, because confidential looks different for a trades business, an eCommerce store and a software company, and a generic list is the first thing staff stop reading.

The policy records what you treat as confidential, but it does not make information confidential by itself. To succeed in an action for breach of confidence, the information must have the necessary quality of confidence, must have been disclosed in circumstances importing an obligation of confidence, and must have been misused. That is the test applied by the New South Wales Court of Appeal in Filby v TEG Live Pty Ltd [2023] NSWCA 320, where a claim failed partly because the idea in question was inherently unspecific. A policy with concrete examples is your evidence that information was specific, valuable and treated as confidential from the start.

What is not confidential

The carve-outs are the clauses that make the policy look reasonable and enforceable. Without them, the document claims everything is protected, which invites arguments at exactly the moment you need the policy to hold up. Standard exclusions cover information that:

  • Already public: information that is already public and did not become public through a breach by the recipient;
  • Independently developed: information independently developed by the recipient without using your information;
  • Required by law: information that must be disclosed by law, for example to a regulator, a court or under a valid subpoena;
  • Approved for release: information approved for release in writing by the business.

One drafting trap: make clear that a leak by your own people does not put information into the public domain for the recipient's benefit. The carve-out protects information that is already public through no fault of anyone bound by the policy, not information a recipient hopes to free up through a breach.

Who has to follow it

A scope clause names the people the policy applies to. It should cover everyone who can realistically touch your information:

  • Employees: full-time, part-time and casual;
  • Contractors and consultants: including developers, agencies and freelancers;
  • Interns and volunteers: anyone who works with the business, paid or unpaid;
  • Directors and founders: bound by the policy like everyone else with access;
  • Anyone else granted access: to your systems, documents or premises.

The important drafting point is what the policy cannot do on its own. It can state that contractors must comply as a condition of access, but that obligation only bites if their contract incorporates the policy or mirrors it in a non-disclosure agreement. The same goes for intellectual property. Under s 35(6) of the Copyright Act 1968 (Cth), your business owns copyright in works an employee creates in the course of employment under a contract of service. That rule does not extend to contractors, so if a contractor builds your software or writes your content, you need an express assignment of intellectual property in their agreement, not just a line in a policy.

How information must be handled

The handling rules are the practical heart of the policy and the section most people actually read. Keep them concrete and aligned with how work really happens:

  • Need-to-know access: confidential information is only accessed where required for the person's duties.
  • No shared logins: passwords are individual, not shared, and multi-factor authentication is used where available.
  • Approved tools only: business documents go through approved systems, not personal email or personal cloud accounts.
  • No unauthorised downloads: sensitive data is not copied onto personal devices unless authorised.
  • Secure storage: password managers, encryption and locked cabinets for physical records.
  • Clear desk and screen lock: especially in shared or co-working spaces.

If your business holds personal information, this section does double duty. APP 11 of the Privacy Act 1988 (Cth) requires an APP entity to take such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those steps include technical and organisational measures. A confidentiality policy that staff actually follow is an organisational measure that supports that obligation. A policy that sits in a folder, unread and unenforced, is far weaker evidence of reasonable steps.

If your team works remotely or on a hybrid pattern, the handling rules deserve extra attention, because the boundary between work and personal devices blurs quickly. Many businesses pair the confidentiality policy with a separate information security policy so that expectations about access controls, storage and incident response are consistent rather than scattered across documents.

What happens when someone leaves

Confidentiality obligations have two lifetimes. While a person works for you, employees owe an implied duty of fidelity to their employer, recognised by the High Court in Concut Pty Ltd v Worrell [2000] HCA 64. The policy should restate that expectation. After the relationship ends, confidentiality survives through the express terms of the contract and through the equitable duty of confidence, and the policy should say so plainly. It should also require the return or deletion of business information on exit. The policy can go one step further and name what offboarding should include: prompt revocation of system access, recovery of keys, cards and passwords, and a written reminder of the ongoing obligations.

This clause is where policies get stretched into de facto restraints. General skills, knowledge and experience that a person takes with them cannot be locked up, and a restriction that goes beyond protecting genuinely confidential information risks being treated as a restraint of trade. Keep the post-employment obligation about the information, not about what the person can do for a competitor, and leave any genuine non-compete to a properly drafted restraint clause.

What happens on a breach

The final essential clause sets out the reporting and consequence pathway:

  • Who to notify: typically a founder, manager or operations lead;
  • How quickly: usually immediately or within a stated period;
  • What happens next: including investigation, containment of the leak and a disciplinary process;
  • Possible consequences: which can include disciplinary action, termination and, for serious cases, legal action.

Be realistic about what this clause promises. The policy itself does not create a cause of action against a third party who was never bound by it. The legal teeth come from the contract, or from an action for breach of confidence where the three elements are made out. What the policy adds is a documented standard that makes it easier to show what was agreed, what was shared and how it was meant to be treated. Keeping a simple record of how breaches were reported and handled is worth doing too: it shows the policy is real rather than decorative, and it gives you material if a later dispute turns on whether the business took its own rules seriously.

Optional clauses worth considering

Not every business needs every clause below, but each becomes worth including when a particular situation appears:

  • Return of information and devices: worth including if staff work on company laptops or phones; it turns offboarding into a checklist of what must come back or be deleted.
  • Personal device rules: worth including once staff work remotely or bring their own devices; specify what may be stored on them and how it must be secured.
  • Generative AI use: worth including as soon as anyone inputs business information into an AI tool; state that confidential information must not be entered into tools outside approved systems.
  • External disclosure authorisation: worth including if staff deal with investors, media, partners or industry events; any disclosure outside the business requires prior approval.
  • Data retention and destruction: worth including when you hold personal information, because APP 11 of the Privacy Act 1988 (Cth) also requires reasonable steps to destroy or de-identify personal information you no longer need.

When to have a lawyer review your confidentiality policy

A confidentiality policy is one of the cheapest documents to get right and one of the most expensive to get wrong, because its value only appears in a dispute. An Artificer Legal practitioner would review your policy in a specific order: the definition of confidential information against how your business actually operates; the carve-outs, to make sure they are standard rather than self-defeating; the scope, to check it covers contractors and anyone else with access; the alignment between the policy and your actual employment contracts, contractor agreements and NDAs, because a policy that contradicts a signed agreement creates an argument rather than resolving one; the post-employment clause, to make sure it protects information without overreaching into restraint of trade; and the handling rules, to check they line up with your obligations under APP 11 and with any information security policy you already have. For a business that has none of these documents yet, we would typically draft the employment contract and contractor agreement first and the policy second, so that the policy mirrors signed terms rather than the other way around.

We would also push back on the common drafting failures: an "everything is confidential" definition, consequences that promise more than the law can deliver, carve-outs that accidentally free up your own information, and a policy that was never acknowledged by the people it applies to. Having each staff member sign or acknowledge the policy, and keeping a record of it, is cheap and routinely decides whether a policy can be relied on later.

The clause that decides whether your policy ever works

The definition of confidential information is the clause that most often makes the difference, and it is the one most often misdrafted. Too vague and nobody knows what is protected, and a court may find the information was never specific enough to protect, as in Filby v TEG Live Pty Ltd [2023] NSWCA 320. Too broad and the policy is ignored in practice and treated as window dressing in a dispute. The businesses that get value from a confidentiality policy write the definition around the information that would actually hurt them if it leaked, name it in plain words, and keep every other clause consistent with it.

To summarise: a confidentiality policy records what your business treats as confidential, who must protect it and how; it supports rather than replaces your contracts and NDAs; the definition clause and the carve-outs decide whether the document is workable; the handling rules are where privacy obligations under APP 11 and day-to-day behaviour meet; post-employment obligations must protect information without drifting into restraint of trade; and enforcement ultimately rests on the contract and on the equitable action for breach of confidence.