ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Third-Party Information Sharing Agreement

Third-Party Information Sharing Agreement

Template: This document should be reviewed by Legal/Privacy before execution. It is intended as a practical information-security template and should be adapted to the applicable contract, jurisdiction, data type, and business relationship.


1. Agreement Information

FieldDetails
Agreement ID[AGR-XXX]
Agreement TitleThird-Party Information Sharing Agreement
Effective Date[DD-MMM-YYYY]
Expiry/Review Date[DD-MMM-YYYY]
Organization[Organization Name]
Third Party[Third-Party Legal Name]
Business Purpose[Purpose]
Primary Contact[Name / Role]
Information Owner[Name / Role]
Agreement StatusDraft / Active / Expired / Terminated

2. Parties

This Information Sharing Agreement (“Agreement”) is between:

[Organization Legal Name], having its registered office at [Address], referred to as the “Organization”; and

[Third-Party Legal Name], having its registered office at [Address], referred to as the “Third Party”.

The Organization and Third Party are individually a “Party” and collectively the “Parties.”


3. Purpose

The purpose of this Agreement is to establish the requirements governing the sharing, access, use, protection, storage, transmission, retention, return, and deletion of information exchanged between the Parties.

Information shall be shared only for the agreed business purpose described in this Agreement.


4. Business Purpose

The information will be shared for:

[Describe the specific business purpose]

Examples:

  • Customer implementation
  • IT or security services
  • Audit or certification activities
  • Technical support
  • Business-process outsourcing
  • Professional consulting
  • Data processing
  • System integration
  • Regulatory or contractual requirements

The Third Party shall not use the information for unrelated purposes without prior written authorization from the Organization.


5. Scope of Information

The information covered by this Agreement includes only the information necessary for the agreed purpose.

Information TypeDescriptionClassificationPersonal DataCustomer Data
[Data Type][Description][Classification]Yes/NoYes/No
[Data Type][Description][Classification]Yes/NoYes/No

Information not identified in the agreed scope shall not be accessed, collected, copied, or processed unless separately authorized.


6. Information Classification

The Parties shall identify and apply appropriate protection based on information sensitivity.

Example classifications:

  • Public
  • Internal
  • Confidential
  • Restricted

Confidential and Restricted information shall receive enhanced protection.

The Organization may specify additional handling requirements for particular information.


7. Data Minimization

The Parties shall limit information shared to the minimum information reasonably necessary for the agreed business purpose.

Where practical, the Organization may use:

  • Data masking
  • Redaction
  • Pseudonymization
  • Anonymization
  • Aggregation
  • Filtering

The Third Party shall not request or retain additional information merely because it may be useful in the future unless such collection is authorized.


8. Permitted Use

The Third Party shall:

  1. Use the information only for the agreed purpose.
  2. Follow documented instructions from the Organization where applicable.
  3. Restrict access to authorized personnel.
  4. Protect the information against unauthorized access, disclosure, alteration, loss, or destruction.
  5. Comply with applicable contractual requirements.
  6. Notify the Organization of relevant security or privacy incidents.
  7. Return or securely delete information when required.

9. Prohibited Use

Unless expressly authorized, the Third Party shall not:

  • Sell the information.
  • Use the information for advertising or unrelated marketing.
  • Use the information for unrelated analytics.
  • Share the information with unauthorized parties.
  • Copy information unnecessarily.
  • Transfer information to personal accounts.
  • Upload information to unauthorized AI services.
  • Use information for its own unrelated purposes.
  • Attempt to bypass security controls.
  • Retain information beyond the agreed period.

10. Access Control

The Third Party shall apply appropriate access controls, including:

  • Unique user accounts.
  • Least privilege.
  • Need-to-know access.
  • Strong authentication.
  • MFA where appropriate.
  • Privileged-access controls.
  • Access reviews.
  • Timely removal of access.

Third-party personnel shall only receive access necessary for their assigned responsibilities.


11. Third-Party Personnel

The Third Party shall ensure that personnel with access to Organization information:

  • Have a legitimate business need.
  • Are appropriately authorized.
  • Receive relevant security awareness.
  • Are subject to confidentiality obligations.
  • Follow applicable security requirements.
  • Have access removed when no longer required.

12. Confidentiality

The Third Party shall maintain the confidentiality of information received from the Organization.

Confidentiality obligations shall apply to information accessed through:

  • Documents
  • Systems
  • Applications
  • APIs
  • Cloud platforms
  • Meetings
  • Emails
  • Reports
  • Customer systems
  • Audit activities

These obligations shall survive termination of the business relationship where required by the applicable agreement or law.


13. Information Transfer

Information shall be transferred only through approved and appropriately secured channels.

Examples include:

  • Secure file-sharing platforms
  • Customer portals
  • SFTP
  • Approved cloud storage
  • Authenticated APIs
  • Approved collaboration platforms
  • Approved source-code repositories
  • Secure physical delivery

Personal email, unauthorized cloud storage, public file-sharing links, or other unapproved channels shall not be used for Confidential or Restricted information.


14. Encryption

The Parties shall apply encryption appropriate to the sensitivity of information.

Where required:

  • Information shall be encrypted during transmission.
  • Sensitive information shall be encrypted while stored.
  • Encryption keys shall be appropriately protected.
  • Credentials and cryptographic keys shall not be transmitted through insecure channels.

Specific encryption requirements may be documented in Schedule A – Security Requirements.


15. Information Storage

The Third Party shall store Organization information only in approved locations and systems.

Where applicable, the Third Party shall document:

  • Storage platform.
  • Geographic location.
  • Data center/cloud provider.
  • Access controls.
  • Encryption.
  • Backup arrangements.
  • Retention period.

The Third Party shall not move information to another storage location without authorization where such movement could affect contractual, privacy, regulatory, or security requirements.


16. Cloud and SaaS Services

Where the Third Party uses cloud or SaaS services to process Organization information, it shall maintain appropriate security controls.

The Third Party shall identify relevant:

  • Cloud provider.
  • Processing location.
  • Subprocessors.
  • Security controls.
  • Access controls.
  • Backup arrangements.
  • Incident response arrangements.

Material changes to the processing environment may require notification or approval.


17. Subcontractors and Subprocessors

The Third Party shall not provide Organization information to subcontractors or subprocessors unless:

  • Such use is authorized under the applicable agreement; and
  • The subcontractor/subprocessor is subject to appropriate confidentiality and security obligations.

The Third Party remains responsible for information handled by its authorized subcontractors/subprocessors to the extent provided by the applicable contract.

Where required, the Third Party shall maintain a current list of relevant subprocessors.


18. Personal Data

Where personal data is shared, the Parties shall comply with applicable privacy and data-protection requirements.

The Parties should establish, where applicable:

  • Purpose of processing.
  • Categories of personal data.
  • Categories of data subjects.
  • Processing activities.
  • Retention period.
  • Security requirements.
  • Data-subject requirements.
  • Breach notification responsibilities.
  • International transfer requirements.
  • Subprocessor requirements.

Where required, this Agreement should be supplemented by a separate Data Processing Agreement (DPA).


19. Customer Information

Where customer information is shared, the Third Party shall comply with applicable:

  • Customer contractual requirements.
  • Security requirements.
  • Confidentiality requirements.
  • Data-processing restrictions.
  • Data-location requirements.
  • Incident-notification requirements.

Customer information shall not be reused for unrelated purposes without authorization.


20. Security Incident Notification

The Third Party shall promptly notify the Organization when it becomes aware of a security incident that affects, or may affect, Organization information.

The notification should include, where known:

  • Date/time discovered.
  • Nature of incident.
  • Systems affected.
  • Information affected.
  • Potential impact.
  • Containment actions.
  • Investigation status.
  • Contact person.
  • Corrective actions.

The Parties should define specific notification timelines in the applicable contract based on business, regulatory, and customer requirements.


21. Data Breach Cooperation

Where a suspected or confirmed personal-data breach occurs, the Third Party shall reasonably cooperate with the Organization in:

  • Investigation.
  • Containment.
  • Impact assessment.
  • Evidence preservation.
  • Regulatory assessment.
  • Customer communication.
  • Remediation.
  • Corrective actions.

Notification to affected individuals or authorities shall be handled according to applicable law and contractual responsibilities.


22. Security Vulnerabilities

The Third Party shall maintain processes for identifying and addressing security vulnerabilities relevant to the services provided.

Where a vulnerability could materially affect Organization information or services, the Third Party shall:

  • Assess the vulnerability.
  • Apply appropriate remediation.
  • Communicate material risks where required.
  • Support investigation where necessary.

23. Security Monitoring and Logging

Where appropriate, the Third Party shall maintain logs relating to:

  • User authentication.
  • Access to sensitive information.
  • Administrative activity.
  • Security events.
  • Data transfers.
  • Significant system changes.

Logs should be protected against unauthorized modification and retained according to applicable requirements.


24. Business Continuity and Recovery

Where the Third Party provides a critical service, it should maintain appropriate:

  • Backup arrangements.
  • Recovery procedures.
  • Business continuity measures.
  • Disaster recovery capabilities.
  • Recovery testing.

Requirements should be proportionate to the criticality of the service and information.


25. Information Retention

The Third Party shall retain Organization information only for:

  • The agreed business purpose;
  • The agreed contractual period;
  • Applicable legal/regulatory requirements; or
  • Another explicitly authorized purpose.

Information should not be retained indefinitely merely because storage is technically available.


26. Return and Deletion

Upon completion or termination of the business purpose, the Organization may require the Third Party to:

  • Return information.
  • Securely delete information.
  • Remove access.
  • Delete temporary copies.
  • Remove credentials.
  • Remove integration access.
  • Delete information from applicable systems.

Where required, the Third Party shall provide written confirmation of deletion.

Backup copies may be retained temporarily where technically necessary, provided they remain protected and are deleted according to the applicable retention cycle.


27. Data Location and Cross-Border Transfers

Where relevant, the Third Party shall identify countries or regions where Organization information is:

  • Stored.
  • Processed.
  • Accessed.
  • Transferred.

Cross-border transfers shall comply with applicable legal, regulatory, contractual, and customer requirements.


28. Audit and Assurance

Depending on the risk and contractual requirements, the Organization may request reasonable evidence of the Third Party’s security controls.

Evidence may include:

  • ISO 27001 certification.
  • SOC reports.
  • Independent assessment reports.
  • Penetration-test summaries.
  • Security questionnaires.
  • Policies.
  • Security-control evidence.
  • Incident-management information.

Audit or assurance rights should be defined in the applicable commercial agreement.


29. Security Assessment

Before sharing high-risk information, the Organization may perform a Third-Party Security Assessment.

Assessment areas may include:

AreaAssessment
GovernanceSecurity policies and responsibilities
Access ControlAuthentication, authorization, MFA
Data ProtectionEncryption and classification
InfrastructureNetwork/cloud security
Application SecuritySecure development/testing
Incident ManagementDetection and response
PrivacyPersonal-data protection
Business ContinuityBackup and recovery
Supplier ManagementSubcontractor controls
Physical SecurityFacilities protection

30. Security Requirements Schedule

The following requirements may be attached to this Agreement.

RequirementApplicableRequirement/Control
MFAYes/No[Requirement]
Encryption in TransitYes/No[Requirement]
Encryption at RestYes/No[Requirement]
Access ReviewYes/No[Frequency]
Security LoggingYes/No[Requirement]
Vulnerability ManagementYes/No[Requirement]
Security TestingYes/No[Requirement]
Incident NotificationYes/No[Requirement]
Data LocationYes/No[Requirement]
SubprocessorsYes/No[Requirement]
Data DeletionYes/No[Requirement]
Business ContinuityYes/No[Requirement]

31. Information Sharing Register

The Organization should maintain a record of significant information-sharing activities.

FieldDetails
Sharing ID[EXT-001]
Third Party[Name]
Information[Description]
Classification[Classification]
Purpose[Purpose]
Data Type[Customer/Personal/etc.]
Approval[Approver]
Transfer Method[Channel]
Contract Reference[Reference]
Access Period[Start–End]
Deletion/Return Date[Date]
StatusActive/Completed/Closed

32. Confidentiality and Restricted Information

For Restricted information, additional controls may include:

  • Explicit authorization.
  • Named-user access.
  • MFA.
  • Encryption.
  • Restricted repository.
  • Access logging.
  • Download restrictions.
  • Time-limited access.
  • Secure deletion.
  • Additional monitoring.

Examples include:

  • Production credentials.
  • API keys.
  • Private keys.
  • Sensitive security configurations.
  • Detailed vulnerability information.
  • Critical incident investigation information.
  • Highly sensitive customer information.

33. Artificial Intelligence Services

The Third Party shall not submit Organization information to AI systems for unrelated purposes.

Where AI services are used to process Organization information, the Third Party should disclose, where applicable:

  • AI service/provider.
  • Purpose.
  • Data processed.
  • Whether data is retained.
  • Whether data is used for model training.
  • Processing location.
  • Subprocessors.
  • Security controls.

Additional contractual approval may be required for Confidential or Restricted information.


34. Information Classification and Handling

The Third Party shall follow the Organization’s documented information-handling requirements where contractually agreed.

ClassificationMinimum Expectation
PublicProtect against unauthorized modification
InternalAuthorized access
ConfidentialNeed-to-know + secure transfer/storage
RestrictedExplicit authorization + enhanced security controls

35. Security Responsibilities

Organization

The Organization shall:

  • Identify information to be shared.
  • Define the business purpose.
  • Determine applicable requirements.
  • Define security requirements.
  • Authorize appropriate sharing.
  • Communicate relevant restrictions.

Third Party

The Third Party shall:

  • Protect received information.
  • Restrict access.
  • Follow agreed security requirements.
  • Prevent unauthorized disclosure.
  • Report relevant incidents.
  • Manage subcontractors appropriately.
  • Return/delete information as required.

36. Exceptions

Any exception to agreed security requirements should:

  • Be documented.
  • Have a business justification.
  • Be risk assessed.
  • Identify compensating controls.
  • Have an owner.
  • Have an expiry date.
  • Be approved by the appropriate authority.

37. Termination

Upon termination of the relationship or information-sharing arrangement:

  • Information-sharing access shall be terminated.
  • Accounts and credentials shall be revoked.
  • Organization information shall be returned or securely deleted as required.
  • Subcontractor access shall be reviewed.
  • Temporary access shall be removed.
  • Relevant evidence shall be retained.
  • Continuing confidentiality obligations shall remain applicable where required.

38. Records and Evidence

The Parties should retain appropriate evidence such as:

  • Executed agreement.
  • NDA/DPA.
  • Information-sharing register.
  • Security assessment.
  • Risk assessment.
  • Approvals.
  • Access records.
  • Transfer records.
  • Security incident records.
  • Deletion/return confirmation.
  • Audit/assurance reports.
  • Subprocessor records.
  • Periodic reviews.

39. Review

This Agreement should be reviewed:

  • Before significant changes to information sharing.
  • When the business purpose changes.
  • When new data types are introduced.
  • When new subprocessors are introduced.
  • After significant security incidents.
  • When applicable legal/regulatory requirements change.
  • During periodic supplier reviews.
  • Before renewal where appropriate.

40. Document Control

FieldDetails
Document Owner[Name/Role]
Business Owner[Name/Role]
Security Owner[Name/Role]
Version[Version]
Effective Date[Date]
Review Date[Date]
ClassificationConfidential
StatusDraft/Approved/Active/Expired
Approved By[Name/Role]

41. Approval and Sign-Off

For [Organization Name]

Name: __________________________

Title: __________________________

Signature: ______________________

Date: __________________________

For [Third-Party Legal Name]

Name: __________________________

Title: __________________________

Signature: ______________________

Date: __________________________


42. Practical Approval Checklist

Before executing the Agreement:

  • Third Party identified.
  • Business purpose documented.
  • Information identified.
  • Information classified.
  • Data minimization considered.
  • Personal data identified.
  • Customer data identified.
  • Legal/regulatory requirements assessed.
  • NDA requirement assessed.
  • DPA requirement assessed.
  • Security requirements defined.
  • Transfer channel approved.
  • Third-party security assessment completed where required.
  • Subprocessors assessed.
  • Retention period defined.
  • Return/deletion requirements defined.
  • Incident notification requirements defined.
  • Access requirements defined.
  • Agreement approved.
  • Agreement signed.
  • Information-sharing register updated.

43. ISO 27001 Connection

This Agreement supports applicable requirements relating to:

  • Information transfer.
  • Supplier relationships.
  • Supplier agreements.
  • Information classification.
  • Access control.
  • Data protection.
  • Cloud services.
  • Incident management.
  • Information deletion.
  • Security monitoring.
  • Protection of information shared with external parties.

The exact applicable controls should be determined through the organization’s risk assessment and Statement of Applicability (SoA).


44. Relationship With Other ISMS Documents

This Agreement should operate together with:

Third-Party Security Assessment
→ evaluates the third party.

Risk Assessment
→ identifies and evaluates risks.

Supplier Security Requirements
→ defines required security controls.

External Data Sharing Procedure
→ defines when and how information may be shared.

Information Transfer Policy
→ establishes information-transfer principles.

Secure Information Transfer Procedure
→ defines secure operational transfer steps.

Data Processing Agreement
→ addresses applicable personal-data processing obligations.

Information Classification Policy
→ determines information sensitivity.

Access Control Policy
→ controls third-party access.

Incident Response Procedure
→ handles security incidents.

Data Breach Response Procedure
→ handles applicable personal-data breaches.


45. Final Control Chain

Third Party Identified

→ Business Purpose Defined

→ Information Identified

→ Classification Determined

→ Risk Assessed

→ Legal/Privacy Requirements Checked

→ Security Requirements Defined

→ Agreement Executed

→ Access Authorized

→ Information Shared Securely

→ Monitoring

→ Periodic Review

→ Access Revoked

→ Information Returned/Deleted

→ Evidence Retained

Final Principle

Do not share information with a third party simply because there is a business relationship. Define what is being shared, why it is required, who can access it, how it will be protected, how long it will be retained, and what happens when the relationship or business purpose ends.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *