Email Confidentiality Notice: 10 Templates and What It Does

Ten confidentiality notice templates for business email, placement and length rules, and the court decisions that show what a notice does and does not protect.

Related guides: email disclaimer examples by industry and how to add a legal disclaimer to all outgoing emails.

The confidentiality notice is the paragraph under almost every business signature that begins "This email and any attachments are confidential." Most people copied it from someone else's footer and have never asked what it does. This guide gives you ten versions to copy, tells you where to put them and how long they should be, and then explains, with the court decisions, what a confidentiality notice can and cannot do for you.

What an email confidentiality notice is, and is not

An email confidentiality notice is a short statement, placed below the signature, that tells the reader the message is intended only for the named recipient and says what to do if it arrived by mistake: do not read on, do not forward, tell the sender, delete it. It is sometimes called a confidentiality disclaimer, a confidentiality statement, or a confidential email footer. They are the same thing.

It is not a contract. The recipient never agreed to it, so it cannot bind a stranger to secrecy. It is not encryption, and it does not make an insecure channel secure. And it is not required by law anywhere we have checked; what several countries do require on business email is the company's registration details, which is a different line. What the notice does is record your intent and your instructions, which turns out to matter in privilege disputes, trade-secret claims, and data protection investigations.

Ten email confidentiality notice templates

Replace the bracketed parts. Every template is written in plain English, which reads better and is no weaker in law than the Victorian version.

1. Short form (under 30 words)

This email and any attachments are confidential and intended solely for the addressee. If you received it in error, please notify [contact email] and delete it.

2. Standard form

This email and any attachments are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you are not the intended recipient, you must not read, copy, distribute, or rely on this message or its attachments. If you have received this email in error, please notify [contact email] immediately and delete it from your system.

3. With misdirected-mail instructions spelled out

This message is confidential and may be legally protected. If you are not the person it was addressed to, you have received it in error: please reply to tell the sender, do not open any attachments, do not forward or print it, and delete all copies, including from your deleted items folder.

4. Internal-only material

INTERNAL. This message contains information intended for [Company] staff only. Do not forward it outside the company without the author's permission.

5. Privileged and confidential (law firms and legal departments)

PRIVILEGED AND CONFIDENTIAL. This message may contain information protected by the attorney-client privilege or the work-product doctrine. Receipt by anyone other than the intended recipient is not a waiver of any privilege. If you are not the intended recipient, notify [contact email] and delete all copies.

Privilege has its own rules, which are covered in privileged and confidential email disclaimer: what it does for attorney-client privilege.

6. Protected health information (healthcare)

CONFIDENTIALITY NOTICE. This email may contain protected health information (PHI) that is confidential under HIPAA and other law. It is intended only for the named recipient. If you are not the intended recipient, any review, use, disclosure, or distribution is prohibited. If you received this message in error, notify [contact email] immediately and permanently delete it.

7. With a monitoring line (regulated and archiving firms)

This email is confidential and intended solely for the addressee. Email sent to or from [Company] may be monitored and retained in accordance with our policies and applicable law. If you received this message in error, please notify [contact email] and delete it.

8. With company registration details (UK example)

This email and any attachments are confidential and intended solely for the addressee. If you received it in error, please notify [contact email] and delete it. [Company] Ltd is a company registered in England and Wales with company number [number]. Registered office: [address].

The registration line is the part UK law actually requires; the statute and the equivalents for 20 other jurisdictions are in the generator's requirements by country table.

9. Confidentiality plus no contract by email (sales and procurement)

This email is confidential and intended solely for the addressee. Nothing in it creates a binding agreement on behalf of [Company] unless expressly stated and confirmed in a signed contract. If you received this message in error, please notify [contact email] and delete it.

10. Concise mobile version

Confidential. If this reached you in error, please tell the sender and delete it.

Where the notice goes and how long it should be

  • Below the signature, separated by a rule or a blank line, in smaller muted text. The signature identifies the sender; the notice sets the terms. Never above the signature, never in the body.
  • Under 100 words. Templates 1, 3, and 10 are the ones most companies should use. Regulated firms can justify up to 200 words; beyond that it is not read.
  • Once per message. If your server appends it to every reply, long threads end with a stack of identical notices. The fix depends on your platform and is in how to add a legal disclaimer to all outgoing emails.
  • Plain text, legible color. Gray is fine; near-white on white is not. If a court is asked whether a reader could have seen the notice, hidden text answers the question for them.

What courts have said about confidentiality notices

Three decisions cover most of what a business needs to know.

A notice cannot create privilege or secrecy on its own. In Scott v. Beth Israel Medical Center (N.Y. Sup. Ct. 2007), a doctor exchanged emails with his lawyers over his employer's email system, and the lawyers' messages carried a confidentiality and privilege footer. The court held the messages were not privileged: the employer's published policy said company email could be monitored, and a pro forma notice at the bottom of each message was not a reasonable precaution against that. The channel decided the outcome, not the footer.

The absence of a notice can count against you. In B&F Systems v. LeBlanc (M.D. Ga. 2011), a company claiming its customer information was a protected trade secret had sent it by email with no confidentiality marking at all. The court treated that absence as evidence the material was not intended to be confidential. This is the strongest practical argument for a notice: it is cheap proof that you treated the information as confidential.

A notice does not undo what the email says. In Baillie Estates v Du Pont (UK) Ltd [2009] CSOH 95, a Scottish court found that two short emails ("Go ahead" and "It's on the way") formed a contract. The sender's standard footer said emails were not contractual offers or acceptances, but it referred only to the email, not to the attached proposal that carried the terms, and the court said it would have made no difference anyway given what the messages plainly meant.

The practical reading: a confidentiality notice is evidence of intent and a set of instructions for a stranger, not a shield. Keep it because it costs nothing and helps when you need to show you took reasonable steps. Do not rely on it in place of access controls, encryption, or a signed agreement.

When to use one, and when not to

  • Use it on external business email from anyone who handles client, patient, financial, or personal information. That is most companies.
  • Use a specific version for a specific job. Privileged for lawyers, PHI for clinicians, monitoring for firms that archive, no-contract for people who negotiate. The generic notice does none of those jobs.
  • Skip it on internal mail unless policy requires template 4. Colleagues do not need to be told to delete the lunch order.
  • Do not put it on marketing email. Bulk messages are governed by CAN-SPAM, CASL, and the ePrivacy rules, which care about identification and unsubscribe links, not confidentiality. A confidentiality notice on a newsletter reads as a mistake.

How to get the same notice on every employee's email

Pasting a template into your own Gmail or Outlook settings takes a minute: copy the text from the email disclaimer generator, open the signature editor, paste it under your contact details. The hard part is the other 80 people. Emailing the template around produces 80 slightly different notices within a month, and nobody knows which version is live when legal changes it.

The reliable approach is to hold the notice in a signature template and deploy the template to every mailbox from one place, with variants per team or country where needed. The three ways to do that on Google Workspace and Microsoft 365, and why server-side footers stack in reply threads, are compared in how to add a legal disclaimer to all outgoing emails.

Frequently asked questions

Is an email confidentiality notice legally binding?

Not on the recipient. A unilateral notice cannot impose a duty on someone who never agreed to it, and courts in the US and UK have said so. It does serve as evidence that you intended the information to stay confidential, which matters in privilege and trade-secret disputes.

Is a confidentiality notice required by law?

No. No statute we have found requires one. The lines that company law does require on business email in the UK, EU member states, India, Singapore, Hong Kong, and elsewhere are company registration details, not confidentiality wording. HIPAA requires safeguards, not a notice, although a PHI notice is a widely used safeguard.

What should a confidentiality notice include?

Who the message is for, what a wrong recipient should not do (read, copy, forward, rely on it), what they should do (tell the sender, delete it), and a contact address for doing so. Everything else is optional.

Should the notice go above or below the signature?

Below. The signature identifies the sender; the notice defines the terms of the message. Putting it above the signature buries the contact details and signals that the sender does not expect to be read.

Do I need a confidentiality notice on internal emails?

Usually not. If your policy classifies some internal material, use a short internal-only line on those messages rather than a full notice on everything.

How do I add a confidentiality notice in Gmail or Outlook?

In Gmail: Settings, See all settings, Signature, paste the notice under your details. In Outlook: Settings, Mail, Compose and reply. For a whole company, deploy it through a signature template; the steps are in how to add a disclaimer to your email signature.

Share this post

Loading...