Data Entry and Confidentiality Agreements: Protecting Your Business Information

Alex Solo
byAlex Solo12 min read

If your business uses a freelancer, offshore contractor, admin agency, or temporary staff member to handle customer records, invoices, supplier details, or internal spreadsheets, a verbal promise to “keep things private” is not enough. New Zealand businesses often make the same avoidable mistakes: relying on a basic template that does not match the work, failing to define what information is actually confidential, and accepting a provider’s standard terms without checking who owns the cleaned or processed data.

That is where the risk starts. A data entry provider might access personal information, pricing models, internal processes, and commercially sensitive material long before a problem becomes visible. If the agreement is vague, you may have trouble controlling subcontracting, setting security expectations, or requiring information to be returned or deleted when the work ends.

This guide explains what data entry and confidentiality agreements do, what New Zealand businesses should check before signing, where founders often get caught, and how to reduce the legal and practical risk before you hand over business information.

Overview

Data entry and confidentiality agreements help set the rules for how another person or business may access, use, store, process, and protect your information. For New Zealand SMEs, the key issues usually sit across contract terms, privacy compliance, ownership of work product, security expectations, and what happens at the end of the engagement.

  • Define exactly what services the data entry provider will perform, including accuracy standards, turnaround times, and quality control.
  • State what information is confidential, who can access it, and what uses are permitted.
  • Deal expressly with personal information and Privacy Act 2020 obligations, especially if customer or employee data is involved.
  • Confirm whether subcontracting, offshore access, or cloud storage is allowed and on what conditions.
  • Set out who owns the entered, corrected, formatted, or enriched data and any templates or outputs created.
  • Include security, breach notification, return, deletion, and audit-style obligations where appropriate.
  • Check liability clauses, indemnities, limits on claims, and dispute resolution before you accept the provider's standard terms.

What Data Entry and Confidentiality Agreements Means For New Zealand Businesses

A data entry and confidentiality agreement is a practical risk-control document. It is usually used where one party gives another access to business records or datasets so that information can be entered, updated, cleaned, migrated, sorted, tagged, or processed.

For a small or growing business, this often happens in ordinary founder moments. You might engage a virtual assistant to update your CRM, use a contractor to digitise paper forms, outsource invoice processing, or bring in temporary admin support during a busy period. Each of those tasks can involve commercially sensitive information or personal information protected under New Zealand privacy law.

Why this agreement matters

The main risk is not just “someone leaks a file”. The bigger issue is uncontrolled use of information. A provider may duplicate records, use customer data to train internal systems, leave documents in a shared drive, or continue retaining spreadsheets after the job ends. If your contract is silent, you may be left arguing about expectations rather than enforcing clear obligations.

A well-drafted agreement helps you manage:

  • confidentiality obligations for business information, trade secrets, pricing, supplier arrangements, product plans, and internal procedures
  • privacy obligations where personal information about customers, staff, contractors, or leads is involved
  • service expectations, including quality, formatting rules, correction processes, and deadlines
  • ownership of outputs, including edited databases, categorised records, and migrated files
  • security requirements, such as password controls, restricted access, device protections, and secure storage
  • end-of-contract steps, including return, deletion, certification of destruction, and ongoing confidentiality

Confidential information is broader than many founders expect

Founders often think confidentiality clauses only cover trade secrets. In practice, your confidential information may include customer lists, margins, supplier contacts, software access credentials, draft budgets, business plans, standard operating procedures, staff information, and any non-public dataset you hand over.

The agreement should not leave this to guesswork. It should define confidential information clearly enough that both sides know what is covered, while still being broad enough to catch information shared in spreadsheets, emails, dashboards, attachments, and verbal instructions.

Privacy Act issues can sit inside a simple admin job

If the provider will handle personal information, your contract should reflect that. The Privacy Act 2020 applies to agencies in New Zealand and can affect how personal information is collected, stored, used, disclosed, and secured. Even if the outsourced task looks basic, such as entering customer names and order details into a system, privacy obligations may still apply.

This is where founders often get caught. A business may focus on confidentiality but forget to address:

  • whether the provider may use the information only for your instructions
  • how long the provider may retain the information
  • whether the information can be accessed outside New Zealand
  • what technical and organisational safeguards are expected
  • how quickly the provider must notify you of a privacy or security incident

If a provider is handling personal information on your behalf, your business still needs to think carefully about oversight and contractual controls. You cannot assume the outsourcing itself removes your risk.

Different structures suit different jobs

Not every business needs the same document. Sometimes a stand-alone non-disclosure agreement is enough before a trial task or tender discussion. In other cases, the confidentiality and privacy terms should sit inside a broader services agreement that also covers scope, fees, service levels, liability, termination rights, and termination.

That choice matters because confidentiality alone does not answer operational issues like rework, delivery dates, access rights, acceptance testing, or who pays if data must be corrected after errors are found.

Before you sign a contract for data entry services, make sure the agreement matches the real flow of information in your business. The legal document should reflect who gets access, what systems are used, what type of data is involved, and what happens if something goes wrong.

1. Scope of services and standards

The agreement should describe the work in plain language. “Data entry services” is too vague on its own. You want enough detail to avoid later disputes about whether the provider was meant to validate information, remove duplicates, standardise formats, classify records, or simply transcribe what they received.

Useful service points to spell out include:

  • what source documents or datasets will be used
  • what systems or software the provider will access
  • expected turnaround times
  • accuracy thresholds or QA checks
  • who reviews completed work
  • how corrections and rework will be handled

2. Definition of confidential information

A confidentiality clause should say what is covered, how the provider can use the information, and what they must do to protect it. It should also address standard carve-outs, such as information already public or lawfully known to the provider before disclosure.

Before you rely on a verbal promise, check whether the agreement also covers:

  • information shared orally during calls or meetings
  • copies, extracts, summaries, notes, and screenshots
  • metadata and system-generated exports
  • access credentials and passwords
  • confidential information received from your customers, suppliers, or other third parties

3. Privacy and personal information handling

If names, phone numbers, addresses, employment details, account information, or other personal information are involved, the contract should deal with privacy expressly. This is not just a good practice point. It is often central to the risk profile of the arrangement.

Key privacy-related questions include:

  • is the provider restricted to acting only on your instructions
  • what security measures are required
  • can the provider copy or download datasets to local devices
  • can information be transferred offshore or accessed by overseas personnel
  • how and when must incidents be reported
  • what assistance must the provider give if an access request, correction request, or complaint arises

Cross-border arrangements need extra care. If the provider, their team, or their cloud storage sits outside New Zealand, you should understand where information is going and whether your contract addresses that reality with appropriate data protection controls.

4. Subcontracting and offshore processing

Many data entry businesses do not perform all work in-house. They may use subcontractors, remote assistants, or overseas affiliates. If that matters to your business, the contract should not stay silent.

You may want:

  • a prohibition on subcontracting without written consent
  • a requirement that any subcontractor signs equivalent confidentiality and privacy obligations
  • clear responsibility on the main provider for all acts and omissions of subcontractors
  • notice of where data will be accessed or stored

This point is especially important where client contracts, procurement terms, or internal policies limit offshore handling of information.

5. Ownership and permitted use

The agreement should say who owns the original data, the updated dataset, and any outputs created through the service. In most business arrangements, the customer expects to retain ownership of its source information and receive ownership or unrestricted use rights in the completed work product.

The provider should usually be restricted from using your information for unrelated purposes. That includes internal analytics, training datasets, benchmarking, marketing examples, or future work for other clients unless you have expressly agreed otherwise.

6. Security obligations and incident response

Security clauses should be practical, not decorative. If the work involves sensitive records, think about device controls, multi-factor authentication, restricted permissions, secure transmission methods, and whether physical documents are stored or scanned securely.

The contract can also require prompt notice of actual or suspected incidents, cooperation with investigation steps, and compliance with your reasonable directions for containment and remediation under a clear incident response process.

7. Return, deletion, and retention

When the engagement ends, your information should not remain scattered across inboxes, laptops, external drives, and shared folders. The agreement should say whether information must be returned, deleted, or both, and whether the provider must confirm that in writing.

Retention exceptions can be legitimate, for example where records must be kept by law, but those exceptions should be narrow and clearly described.

8. Liability, indemnities, and dispute terms

This is often where standard form agreements become one-sided. A provider may try to cap liability at a very low amount, exclude indirect loss broadly, or avoid meaningful responsibility for subcontractors or data incidents.

Before you accept the provider's standard terms, check:

  • whether liability caps are realistic in light of the value and sensitivity of the information
  • whether confidentiality and privacy breaches are carved out from liability limits
  • whether indemnities are fair and specific rather than open-ended
  • how disputes must be notified and resolved
  • whether you can terminate quickly if misuse, unauthorised disclosure, or serious non-compliance occurs

Common Mistakes With Data Entry and Confidentiality Agreements

Most problems with these agreements come from treating the work as “just admin”. Once a provider handles sensitive records, the contract needs to deal with data use and control in real operational terms.

Using a generic NDA instead of a service contract

A short confidentiality deed may help before preliminary discussions, but it usually does not cover service levels, correction obligations, access permissions, subcontracting, or return and deletion steps. If the provider is actually performing work, not just receiving a proposal, a broader agreement is often the better fit.

Leaving confidential information too vague

If the clause simply says “all information shared is confidential” without context, arguments can arise later about whether customer data exports, formulas, internal notes, or verbal instructions were included. Specific drafting reduces room for dispute.

It can also help to distinguish between:

  • general confidential business information
  • personal information
  • access credentials and security information
  • third-party confidential material that you are permitted to share only for limited purposes

Ignoring privacy because the provider is trustworthy

Trust matters, but it is not a substitute for a clear contract. Even a reliable contractor can make mistakes with storage, transmission, retention, or subcontracting. If personal information is involved, privacy settings, instructions, and reporting obligations should be written down.

Allowing unrestricted subcontracting

Founders often assume the person they hired will do the work personally. Later they find the dataset was shared with a wider team or an offshore assistant. If that is unacceptable, say so before you sign. If it is acceptable, attach conditions and keep responsibility with the main provider.

Forgetting to deal with access after the project ends

This is a common practical gap. A contractor may still have login access, synced folders, exported files, or archived messages after the engagement finishes. Your agreement should support an offboarding process that removes access and deals with data copies.

Accepting unrealistic liability limits

Cheap service arrangements can carry high information risk. If the contract limits all liability to one month of fees, that may leave your business exposed if sensitive records are misused or lost. The right approach depends on the work, but the clause should be read carefully, not skipped.

Assuming ownership is obvious

It may feel obvious that your business owns customer data and corrected files, but contracts can say otherwise. Some templates give the provider rights to use de-identified material, methods, or derived datasets. Those provisions should be checked against your operational and reputational risk.

Relying on policy documents that are not contractually binding

A provider may send a privacy policy, security overview, or onboarding note and treat that as enough. Those documents can be useful, but your core obligations should sit in the contract itself, or the contract should clearly incorporate them in a binding way.

Missing industry or client-specific restrictions

Some businesses handle information under separate commitments to customers, enterprise clients, or regulators. If your business works in sectors such as health, finance, education, recruitment, or professional services, your own client-facing contracts may already restrict who can access information and where it can be stored.

That means your data entry agreement should line up with those commitments. If it does not, your outsourcing arrangement can create a breach elsewhere in your business.

FAQs

Do I need a written agreement for a small data entry job?

Usually yes, if the provider will access confidential or personal information. Even a short-term project can expose customer records, internal pricing, or login details. A written agreement makes expectations clear and gives you a better basis to act if something goes wrong.

Is a confidentiality clause enough on its own?

Not always. If the provider is performing actual services, you often also need terms covering scope, quality standards, privacy handling, subcontracting, ownership, liability, and what happens when the work ends.

What if the provider is overseas?

Extra care is needed. You should check where data will be accessed and stored, whether subcontractors are involved, and how the contract deals with privacy, security, and breach reporting. Cross-border handling can materially change your risk.

Who owns the entered or cleaned data after the work is done?

That should be stated in the contract. Many businesses expect to own both the source data and the completed output, but you should not assume the position is automatic, especially if the provider uses its own templates, tools, or processing methods.

Can I use the provider's standard terms if they look reasonable?

Possibly, but read them closely before you sign. The main problem areas are usually confidentiality definitions, privacy obligations, subcontracting rights, data use permissions, return and deletion obligations, and low liability caps.

Key Takeaways

  • Data entry and confidentiality agreements are not just admin paperwork, they control how another party may access, use, store, and protect your business information.
  • New Zealand businesses should check both confidentiality and privacy issues, especially where customer or employee data is involved.
  • The contract should clearly cover scope of work, quality standards, subcontracting, offshore access, security controls, ownership, and end-of-project deletion or return.
  • A generic NDA is often not enough where the provider is actually performing ongoing services.
  • Founders commonly get caught by vague definitions, hidden subcontracting, weak liability terms, and assumptions that ownership or deletion is “obvious”.
  • Before you accept the provider's standard terms, make sure the agreement reflects how your data will really move through the engagement.

If you want help with confidentiality clauses, privacy terms, subcontracting controls, liability limits, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.