- Third Party Confidential Information
- Non-public information received from an outside organization β such as a client, vendor, or partner β that is designated as confidential under an agreement or by its nature.
- Need-to-Know Basis
- Access control principle limiting disclosure of confidential information only to individuals whose role requires them to use it.
- Data Classification
- A system for categorizing information by sensitivity level β for example, public, internal, confidential, and restricted β to determine handling requirements.
- Authorized Recipient
- An employee, contractor, or team member formally permitted to access specific third party confidential information for a defined business purpose.
- Breach of Confidentiality
- Any unauthorized disclosure, use, copying, or transmission of confidential information that violates the policy or an underlying agreement.
- Retention Period
- The defined duration for which confidential information must be kept before it is securely destroyed or returned to the originating party.
- Secure Disposal
- Destruction of confidential information in a manner that prevents reconstruction β shredding physical documents, permanently deleting electronic files, or degaussing storage media.
- Non-Disclosure Agreement (NDA)
- A binding legal contract between two parties establishing the terms under which confidential information may be shared and restricting further disclosure.
- Marking Convention
- A standardized label β such as 'Confidential,' 'Proprietary,' or 'Restricted' β applied to documents or files to signal their classification level and required handling.
- Incident Response
- The structured process an organization follows when a data breach or confidentiality violation is detected, including containment, notification, and remediation steps.