Template: This document should be reviewed by Legal/Privacy before execution. It is intended as a practical information-security template and should be adapted to the applicable contract, jurisdiction, data type, and business relationship.
1. Agreement Information
| Field | Details |
|---|---|
| Agreement ID | [AGR-XXX] |
| Agreement Title | Third-Party Information Sharing Agreement |
| Effective Date | [DD-MMM-YYYY] |
| Expiry/Review Date | [DD-MMM-YYYY] |
| Organization | [Organization Name] |
| Third Party | [Third-Party Legal Name] |
| Business Purpose | [Purpose] |
| Primary Contact | [Name / Role] |
| Information Owner | [Name / Role] |
| Agreement Status | Draft / Active / Expired / Terminated |
2. Parties
This Information Sharing Agreement (“Agreement”) is between:
[Organization Legal Name], having its registered office at [Address], referred to as the “Organization”; and
[Third-Party Legal Name], having its registered office at [Address], referred to as the “Third Party”.
The Organization and Third Party are individually a “Party” and collectively the “Parties.”
3. Purpose
The purpose of this Agreement is to establish the requirements governing the sharing, access, use, protection, storage, transmission, retention, return, and deletion of information exchanged between the Parties.
Information shall be shared only for the agreed business purpose described in this Agreement.
4. Business Purpose
The information will be shared for:
[Describe the specific business purpose]
Examples:
- Customer implementation
- IT or security services
- Audit or certification activities
- Technical support
- Business-process outsourcing
- Professional consulting
- Data processing
- System integration
- Regulatory or contractual requirements
The Third Party shall not use the information for unrelated purposes without prior written authorization from the Organization.
5. Scope of Information
The information covered by this Agreement includes only the information necessary for the agreed purpose.
| Information Type | Description | Classification | Personal Data | Customer Data |
|---|---|---|---|---|
| [Data Type] | [Description] | [Classification] | Yes/No | Yes/No |
| [Data Type] | [Description] | [Classification] | Yes/No | Yes/No |
Information not identified in the agreed scope shall not be accessed, collected, copied, or processed unless separately authorized.
6. Information Classification
The Parties shall identify and apply appropriate protection based on information sensitivity.
Example classifications:
- Public
- Internal
- Confidential
- Restricted
Confidential and Restricted information shall receive enhanced protection.
The Organization may specify additional handling requirements for particular information.
7. Data Minimization
The Parties shall limit information shared to the minimum information reasonably necessary for the agreed business purpose.
Where practical, the Organization may use:
- Data masking
- Redaction
- Pseudonymization
- Anonymization
- Aggregation
- Filtering
The Third Party shall not request or retain additional information merely because it may be useful in the future unless such collection is authorized.
8. Permitted Use
The Third Party shall:
- Use the information only for the agreed purpose.
- Follow documented instructions from the Organization where applicable.
- Restrict access to authorized personnel.
- Protect the information against unauthorized access, disclosure, alteration, loss, or destruction.
- Comply with applicable contractual requirements.
- Notify the Organization of relevant security or privacy incidents.
- Return or securely delete information when required.
9. Prohibited Use
Unless expressly authorized, the Third Party shall not:
- Sell the information.
- Use the information for advertising or unrelated marketing.
- Use the information for unrelated analytics.
- Share the information with unauthorized parties.
- Copy information unnecessarily.
- Transfer information to personal accounts.
- Upload information to unauthorized AI services.
- Use information for its own unrelated purposes.
- Attempt to bypass security controls.
- Retain information beyond the agreed period.
10. Access Control
The Third Party shall apply appropriate access controls, including:
- Unique user accounts.
- Least privilege.
- Need-to-know access.
- Strong authentication.
- MFA where appropriate.
- Privileged-access controls.
- Access reviews.
- Timely removal of access.
Third-party personnel shall only receive access necessary for their assigned responsibilities.
11. Third-Party Personnel
The Third Party shall ensure that personnel with access to Organization information:
- Have a legitimate business need.
- Are appropriately authorized.
- Receive relevant security awareness.
- Are subject to confidentiality obligations.
- Follow applicable security requirements.
- Have access removed when no longer required.
12. Confidentiality
The Third Party shall maintain the confidentiality of information received from the Organization.
Confidentiality obligations shall apply to information accessed through:
- Documents
- Systems
- Applications
- APIs
- Cloud platforms
- Meetings
- Emails
- Reports
- Customer systems
- Audit activities
These obligations shall survive termination of the business relationship where required by the applicable agreement or law.
13. Information Transfer
Information shall be transferred only through approved and appropriately secured channels.
Examples include:
- Secure file-sharing platforms
- Customer portals
- SFTP
- Approved cloud storage
- Authenticated APIs
- Approved collaboration platforms
- Approved source-code repositories
- Secure physical delivery
Personal email, unauthorized cloud storage, public file-sharing links, or other unapproved channels shall not be used for Confidential or Restricted information.
14. Encryption
The Parties shall apply encryption appropriate to the sensitivity of information.
Where required:
- Information shall be encrypted during transmission.
- Sensitive information shall be encrypted while stored.
- Encryption keys shall be appropriately protected.
- Credentials and cryptographic keys shall not be transmitted through insecure channels.
Specific encryption requirements may be documented in Schedule A – Security Requirements.
15. Information Storage
The Third Party shall store Organization information only in approved locations and systems.
Where applicable, the Third Party shall document:
- Storage platform.
- Geographic location.
- Data center/cloud provider.
- Access controls.
- Encryption.
- Backup arrangements.
- Retention period.
The Third Party shall not move information to another storage location without authorization where such movement could affect contractual, privacy, regulatory, or security requirements.
16. Cloud and SaaS Services
Where the Third Party uses cloud or SaaS services to process Organization information, it shall maintain appropriate security controls.
The Third Party shall identify relevant:
- Cloud provider.
- Processing location.
- Subprocessors.
- Security controls.
- Access controls.
- Backup arrangements.
- Incident response arrangements.
Material changes to the processing environment may require notification or approval.
17. Subcontractors and Subprocessors
The Third Party shall not provide Organization information to subcontractors or subprocessors unless:
- Such use is authorized under the applicable agreement; and
- The subcontractor/subprocessor is subject to appropriate confidentiality and security obligations.
The Third Party remains responsible for information handled by its authorized subcontractors/subprocessors to the extent provided by the applicable contract.
Where required, the Third Party shall maintain a current list of relevant subprocessors.
18. Personal Data
Where personal data is shared, the Parties shall comply with applicable privacy and data-protection requirements.
The Parties should establish, where applicable:
- Purpose of processing.
- Categories of personal data.
- Categories of data subjects.
- Processing activities.
- Retention period.
- Security requirements.
- Data-subject requirements.
- Breach notification responsibilities.
- International transfer requirements.
- Subprocessor requirements.
Where required, this Agreement should be supplemented by a separate Data Processing Agreement (DPA).
19. Customer Information
Where customer information is shared, the Third Party shall comply with applicable:
- Customer contractual requirements.
- Security requirements.
- Confidentiality requirements.
- Data-processing restrictions.
- Data-location requirements.
- Incident-notification requirements.
Customer information shall not be reused for unrelated purposes without authorization.
20. Security Incident Notification
The Third Party shall promptly notify the Organization when it becomes aware of a security incident that affects, or may affect, Organization information.
The notification should include, where known:
- Date/time discovered.
- Nature of incident.
- Systems affected.
- Information affected.
- Potential impact.
- Containment actions.
- Investigation status.
- Contact person.
- Corrective actions.
The Parties should define specific notification timelines in the applicable contract based on business, regulatory, and customer requirements.
21. Data Breach Cooperation
Where a suspected or confirmed personal-data breach occurs, the Third Party shall reasonably cooperate with the Organization in:
- Investigation.
- Containment.
- Impact assessment.
- Evidence preservation.
- Regulatory assessment.
- Customer communication.
- Remediation.
- Corrective actions.
Notification to affected individuals or authorities shall be handled according to applicable law and contractual responsibilities.
22. Security Vulnerabilities
The Third Party shall maintain processes for identifying and addressing security vulnerabilities relevant to the services provided.
Where a vulnerability could materially affect Organization information or services, the Third Party shall:
- Assess the vulnerability.
- Apply appropriate remediation.
- Communicate material risks where required.
- Support investigation where necessary.
23. Security Monitoring and Logging
Where appropriate, the Third Party shall maintain logs relating to:
- User authentication.
- Access to sensitive information.
- Administrative activity.
- Security events.
- Data transfers.
- Significant system changes.
Logs should be protected against unauthorized modification and retained according to applicable requirements.
24. Business Continuity and Recovery
Where the Third Party provides a critical service, it should maintain appropriate:
- Backup arrangements.
- Recovery procedures.
- Business continuity measures.
- Disaster recovery capabilities.
- Recovery testing.
Requirements should be proportionate to the criticality of the service and information.
25. Information Retention
The Third Party shall retain Organization information only for:
- The agreed business purpose;
- The agreed contractual period;
- Applicable legal/regulatory requirements; or
- Another explicitly authorized purpose.
Information should not be retained indefinitely merely because storage is technically available.
26. Return and Deletion
Upon completion or termination of the business purpose, the Organization may require the Third Party to:
- Return information.
- Securely delete information.
- Remove access.
- Delete temporary copies.
- Remove credentials.
- Remove integration access.
- Delete information from applicable systems.
Where required, the Third Party shall provide written confirmation of deletion.
Backup copies may be retained temporarily where technically necessary, provided they remain protected and are deleted according to the applicable retention cycle.
27. Data Location and Cross-Border Transfers
Where relevant, the Third Party shall identify countries or regions where Organization information is:
- Stored.
- Processed.
- Accessed.
- Transferred.
Cross-border transfers shall comply with applicable legal, regulatory, contractual, and customer requirements.
28. Audit and Assurance
Depending on the risk and contractual requirements, the Organization may request reasonable evidence of the Third Party’s security controls.
Evidence may include:
- ISO 27001 certification.
- SOC reports.
- Independent assessment reports.
- Penetration-test summaries.
- Security questionnaires.
- Policies.
- Security-control evidence.
- Incident-management information.
Audit or assurance rights should be defined in the applicable commercial agreement.
29. Security Assessment
Before sharing high-risk information, the Organization may perform a Third-Party Security Assessment.
Assessment areas may include:
| Area | Assessment |
|---|---|
| Governance | Security policies and responsibilities |
| Access Control | Authentication, authorization, MFA |
| Data Protection | Encryption and classification |
| Infrastructure | Network/cloud security |
| Application Security | Secure development/testing |
| Incident Management | Detection and response |
| Privacy | Personal-data protection |
| Business Continuity | Backup and recovery |
| Supplier Management | Subcontractor controls |
| Physical Security | Facilities protection |
30. Security Requirements Schedule
The following requirements may be attached to this Agreement.
| Requirement | Applicable | Requirement/Control |
|---|---|---|
| MFA | Yes/No | [Requirement] |
| Encryption in Transit | Yes/No | [Requirement] |
| Encryption at Rest | Yes/No | [Requirement] |
| Access Review | Yes/No | [Frequency] |
| Security Logging | Yes/No | [Requirement] |
| Vulnerability Management | Yes/No | [Requirement] |
| Security Testing | Yes/No | [Requirement] |
| Incident Notification | Yes/No | [Requirement] |
| Data Location | Yes/No | [Requirement] |
| Subprocessors | Yes/No | [Requirement] |
| Data Deletion | Yes/No | [Requirement] |
| Business Continuity | Yes/No | [Requirement] |
31. Information Sharing Register
The Organization should maintain a record of significant information-sharing activities.
| Field | Details |
|---|---|
| Sharing ID | [EXT-001] |
| Third Party | [Name] |
| Information | [Description] |
| Classification | [Classification] |
| Purpose | [Purpose] |
| Data Type | [Customer/Personal/etc.] |
| Approval | [Approver] |
| Transfer Method | [Channel] |
| Contract Reference | [Reference] |
| Access Period | [Start–End] |
| Deletion/Return Date | [Date] |
| Status | Active/Completed/Closed |
32. Confidentiality and Restricted Information
For Restricted information, additional controls may include:
- Explicit authorization.
- Named-user access.
- MFA.
- Encryption.
- Restricted repository.
- Access logging.
- Download restrictions.
- Time-limited access.
- Secure deletion.
- Additional monitoring.
Examples include:
- Production credentials.
- API keys.
- Private keys.
- Sensitive security configurations.
- Detailed vulnerability information.
- Critical incident investigation information.
- Highly sensitive customer information.
33. Artificial Intelligence Services
The Third Party shall not submit Organization information to AI systems for unrelated purposes.
Where AI services are used to process Organization information, the Third Party should disclose, where applicable:
- AI service/provider.
- Purpose.
- Data processed.
- Whether data is retained.
- Whether data is used for model training.
- Processing location.
- Subprocessors.
- Security controls.
Additional contractual approval may be required for Confidential or Restricted information.
34. Information Classification and Handling
The Third Party shall follow the Organization’s documented information-handling requirements where contractually agreed.
| Classification | Minimum Expectation |
|---|---|
| Public | Protect against unauthorized modification |
| Internal | Authorized access |
| Confidential | Need-to-know + secure transfer/storage |
| Restricted | Explicit authorization + enhanced security controls |
35. Security Responsibilities
Organization
The Organization shall:
- Identify information to be shared.
- Define the business purpose.
- Determine applicable requirements.
- Define security requirements.
- Authorize appropriate sharing.
- Communicate relevant restrictions.
Third Party
The Third Party shall:
- Protect received information.
- Restrict access.
- Follow agreed security requirements.
- Prevent unauthorized disclosure.
- Report relevant incidents.
- Manage subcontractors appropriately.
- Return/delete information as required.
36. Exceptions
Any exception to agreed security requirements should:
- Be documented.
- Have a business justification.
- Be risk assessed.
- Identify compensating controls.
- Have an owner.
- Have an expiry date.
- Be approved by the appropriate authority.
37. Termination
Upon termination of the relationship or information-sharing arrangement:
- Information-sharing access shall be terminated.
- Accounts and credentials shall be revoked.
- Organization information shall be returned or securely deleted as required.
- Subcontractor access shall be reviewed.
- Temporary access shall be removed.
- Relevant evidence shall be retained.
- Continuing confidentiality obligations shall remain applicable where required.
38. Records and Evidence
The Parties should retain appropriate evidence such as:
- Executed agreement.
- NDA/DPA.
- Information-sharing register.
- Security assessment.
- Risk assessment.
- Approvals.
- Access records.
- Transfer records.
- Security incident records.
- Deletion/return confirmation.
- Audit/assurance reports.
- Subprocessor records.
- Periodic reviews.
39. Review
This Agreement should be reviewed:
- Before significant changes to information sharing.
- When the business purpose changes.
- When new data types are introduced.
- When new subprocessors are introduced.
- After significant security incidents.
- When applicable legal/regulatory requirements change.
- During periodic supplier reviews.
- Before renewal where appropriate.
40. Document Control
| Field | Details |
|---|---|
| Document Owner | [Name/Role] |
| Business Owner | [Name/Role] |
| Security Owner | [Name/Role] |
| Version | [Version] |
| Effective Date | [Date] |
| Review Date | [Date] |
| Classification | Confidential |
| Status | Draft/Approved/Active/Expired |
| Approved By | [Name/Role] |
41. Approval and Sign-Off
For [Organization Name]
Name: __________________________
Title: __________________________
Signature: ______________________
Date: __________________________
For [Third-Party Legal Name]
Name: __________________________
Title: __________________________
Signature: ______________________
Date: __________________________
42. Practical Approval Checklist
Before executing the Agreement:
- Third Party identified.
- Business purpose documented.
- Information identified.
- Information classified.
- Data minimization considered.
- Personal data identified.
- Customer data identified.
- Legal/regulatory requirements assessed.
- NDA requirement assessed.
- DPA requirement assessed.
- Security requirements defined.
- Transfer channel approved.
- Third-party security assessment completed where required.
- Subprocessors assessed.
- Retention period defined.
- Return/deletion requirements defined.
- Incident notification requirements defined.
- Access requirements defined.
- Agreement approved.
- Agreement signed.
- Information-sharing register updated.
43. ISO 27001 Connection
This Agreement supports applicable requirements relating to:
- Information transfer.
- Supplier relationships.
- Supplier agreements.
- Information classification.
- Access control.
- Data protection.
- Cloud services.
- Incident management.
- Information deletion.
- Security monitoring.
- Protection of information shared with external parties.
The exact applicable controls should be determined through the organization’s risk assessment and Statement of Applicability (SoA).
44. Relationship With Other ISMS Documents
This Agreement should operate together with:
Third-Party Security Assessment
→ evaluates the third party.
Risk Assessment
→ identifies and evaluates risks.
Supplier Security Requirements
→ defines required security controls.
External Data Sharing Procedure
→ defines when and how information may be shared.
Information Transfer Policy
→ establishes information-transfer principles.
Secure Information Transfer Procedure
→ defines secure operational transfer steps.
Data Processing Agreement
→ addresses applicable personal-data processing obligations.
Information Classification Policy
→ determines information sensitivity.
Access Control Policy
→ controls third-party access.
Incident Response Procedure
→ handles security incidents.
Data Breach Response Procedure
→ handles applicable personal-data breaches.
45. Final Control Chain
Third Party Identified
→ Business Purpose Defined
→ Information Identified
→ Classification Determined
→ Risk Assessed
→ Legal/Privacy Requirements Checked
→ Security Requirements Defined
→ Agreement Executed
→ Access Authorized
→ Information Shared Securely
→ Monitoring
→ Periodic Review
→ Access Revoked
→ Information Returned/Deleted
→ Evidence Retained
Final Principle
Do not share information with a third party simply because there is a business relationship. Define what is being shared, why it is required, who can access it, how it will be protected, how long it will be retained, and what happens when the relationship or business purpose ends.
