Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Decision guide·ESRS · Disclosure guides

ESRS Omissions and Confidential Information: Commercial Prejudice, Trade Secrets and Privacy

How to distinguish aggregation, redaction, permitted omission, legal restriction and missing data while preserving a fair and balanced sustainability statement

Who this is for A 13-minute read for reporting teams working through Information materiality: which disclosures and datapoints you report, and for reviewers testing whether the evidence behind it holds.

Short answer

The answer, before the reasoning

ESRS permits omission only for defined categories and conditions: exceptional serious commercial prejudice; qualifying trade secrets; classified information; or information protected by Union or national law or needed to safeguard the privacy or security of a person or legal entity. Before omitting, test whether aggregation, anonymisation or limited redaction can meet the disclosure objective.

For each omitted datapoint, disclose that the exemption was used and reassess the decision at every reporting date. Missing or uncertain data are different: they require an estimate, partial-scope treatment or transparent data-gap explanation rather than a confidentiality exemption.

Technical status note. The omission architecture described here appears in Directive (EU) 2026/470 and the revised ESRS annex adopted as C(2026) 5010 final on 3 July 2026. The final Official Journal text and applicable national law remain mandatory update checks.

Use note. A confidentiality concern does not automatically create a permitted ESRS omission. The undertaking should use the least restrictive treatment that protects the legitimate interest and still meets the disclosure objective. Legal, privacy, competition, security and assurance advice may be required.

Why five different information problems are often called “confidential”

During drafting, teams often place any uncomfortable item in a single “confidential” column. That column can contain genuinely protected trade secrets, customer names, personal grievance information, unapproved forecasts, incomplete calculations and poor performance. These are not the same problem and do not lead to the same reporting treatment.

The first control is classification. Ask whether the issue is:

a commercial-prejudice concern;

a legally qualifying trade secret or classified item;

a statutory privacy, confidentiality or security restriction;

ordinary contractual confidentiality that may be managed through aggregation or redaction; or

missing, uncertain or unapproved information.

Only the first three groups may support a permitted omission under the specified ESRS categories, and each still requires conditions, disclosure of the exemption and annual reassessment. Ordinary confidentiality should normally be handled through careful presentation. Missing data are governed by estimate and relief provisions, not omission rules.

Quick orientation

Figure 1. Apply the least restrictive treatment that preserves both the legitimate protection and the disclosure objective.

In practice

Field Practical orientation
First question Can the disclosure objective be met at an aggregated, anonymised or otherwise less sensitive level?
Permitted categories Exceptional serious commercial prejudice; qualifying trade secret; classified information; other legally protected information; privacy or security protection
Required public signal For each omitted datapoint, disclose that the exemption has been used
Reassessment Reconsider at every reporting date whether the information can still be omitted
Overarching safeguard Make every reasonable effort to ensure the overall relevance of the disclosure is not impaired
Common confusion “Confidential”, “not public”, “not final” and “data unavailable” are treated as equivalent legal grounds

The five reporting treatments

1. Full disclosure

Use full disclosure where the information is material, no legal restriction applies and the potential disadvantage is ordinary transparency rather than serious prejudice. Poor performance, an missed target, a material incident or a difficult dependency is not confidential merely because management would prefer not to highlight it.

2. Aggregation

Aggregation is usually the first protective technique. It can group information by geography, business line, relationship category, period or risk type so that the disclosure remains useful without revealing a counterparty, unit price, facility vulnerability or identifiable person.

Aggregation must not obscure material differences. ESRS 1 requires the level of aggregation and disaggregation to reflect significant variations and avoid hiding material information. A global figure that conceals a severe site-specific impact may not meet the objective even if it protects the site name. The solution may be a regional or category-level disclosure with a clear explanation of context.

3. Redaction or anonymisation

Redaction removes a limited protected element while retaining the surrounding information. Anonymisation is particularly relevant to grievance cases, workforce data, affected communities and consumers. It should prevent re-identification, including through combinations of location, job role, incident date and small population.

A disclosure can describe the nature, severity, response and status of an incident without identifying the complainant, supplier, technology or customer. The evidence file can remain more detailed under controlled access than the public report.

4. Permitted omission

Paragraph 100 allows omission for the defined categories. The commercial-prejudice category is especially demanding. It is available only in exceptional cases where disclosure would seriously prejudice the commercial position, the omission does not prevent a fair and balanced understanding, and the undertaking has determined that it is impossible to meet the disclosure objective through another presentation such as aggregation.

Trade-secret treatment depends on the legal definition in Directive (EU) 2016/943. Not every confidential business fact is a trade secret. The undertaking should have evidence that the information is secret, has commercial value because it is secret and is subject to reasonable steps to keep it secret.

Classified information and other legal, privacy or security restrictions require a documented legal basis. The reporting team should not create an informal “security” category without specialist review.

5. Missing-data treatment

Unavailable, incomplete, unverified or unapproved data are not automatically omitted under paragraph 100. The undertaking should assess estimates, proxies, partial scope, quantitative reliefs, qualitative information, error correction or post-reporting-period updates. The public explanation should identify the limitation and improvement plan rather than imply that disclosure is legally prohibited.

Commercial prejudice: the four-part test

A commercial-prejudice omission should pass all four tests:

Serious prejudice. The likely harm is material and credible, not ordinary competitive discomfort or embarrassment.

Fair and balanced understanding. The omission does not prevent users from understanding the undertaking’s development, performance, position or material risks and impacts.

No less restrictive presentation. Aggregation, ranges, delayed granularity, category-level description or other presentation cannot meet the disclosure objective without causing the serious prejudice.

Datapoint notice and annual reassessment. The undertaking states that the exemption was used for each omitted datapoint and reassesses at every reporting date.

Examples that may require analysis include sensitive acquisition or disposal plans, negotiations, proprietary transition technologies, unannounced product exits and financially material commercial assumptions. The analysis should distinguish information already reflected in recognised financial amounts from strategic detail whose premature disclosure creates specific harm.

Trade secrets, intellectual capital and innovation

The revised omission provision covers information corresponding to intellectual capital, intellectual property, know-how, technological information or innovation results that qualify as a trade secret. A useful legal file includes:

description of the information and its owner;

why it is not generally known or readily accessible;

the commercial value derived from secrecy;

access controls, NDAs, technical protections and other reasonable steps;

the exact datapoint and disclosure objective affected;

alternative presentation considered;

approval and reassessment date.

The exemption should not be used to remove all information about a transition plan, product impact or innovation programme. The undertaking may often disclose the objective, governance, resources, expected effect, dependency and uncertainty without exposing the protected formula or technical design.

Privacy and security

Privacy restrictions are particularly important where the public report could identify a natural person through small groups or incident details. Data protection principles support minimisation and anonymisation, but they do not automatically justify omitting all workforce or grievance information. The public disclosure should be designed around the information need: prevalence, nature, severity, access to remedy, corrective action and trend.

Security can concern individuals, facilities, critical infrastructure, defence capabilities, cyber vulnerabilities and commercial security of legal persons. The file should identify the applicable legal or security basis and avoid revealing the sensitive detail in the public explanation of the exemption.

Omission register

The accompanying Excel workbook contains an OMISSION REGISTER. A complete record should include:

Figure 2. Different information problems require different public explanations and evidence controls.

In practice

Field Control question
Omission ID and datapoint What precise requirement is affected?
Proposed public information What would otherwise be disclosed?
Information category Commercial prejudice, trade secret, classified, legal restriction, privacy, security, ordinary confidentiality or missing data
Legal basis Which ESRS paragraph, law, regulation or legal definition applies?
Harm or protected interest What specific prejudice, right or security interest is at risk?
Fair-and-balanced test What essential understanding remains after the treatment?
Alternatives considered Aggregation, range, anonymisation, redaction, cross-reference or delayed detail
Reason alternatives fail Why can they not meet the objective without the protected harm?
Public notice How will use of the exemption be disclosed for the datapoint?
Evidence access Where is the underlying evidence retained and who may review it?
Approvers Reporting owner, legal, privacy/security specialist and governance body
Reassessment date When will the conclusion be retested?
Related statements Which narrative, metric, target or financial-effect disclosures must remain consistent?

Hypothetical example: one report, four different treatments

Context. Horizon Mobility is preparing climate, workforce and consumer disclosures. Four issues are escalated as “confidential”.

Issue A — unannounced plant-conversion plan

The transition plan includes a facility conversion under active commercial negotiation. Disclosing the site, timing and contract price could undermine the negotiation. Horizon tests regional aggregation, a capex range and narrative description. It concludes that a regional description and range meet the disclosure objective without serious prejudice. Treatment: aggregation, not omission.

Issue B — proprietary battery chemistry

A climate action depends on a new chemistry protected through controlled know-how. The exact formula qualifies as a trade secret. Horizon discloses the action, governance, expected production effect, capital dependency and uncertainty but omits the formula. It states that the trade-secret exemption was used for the relevant technical datapoint. Treatment: permitted omission of the protected detail.

Issue C — harassment investigation in a five-person team

Publishing location, role, date and outcome would make the complainant identifiable. Horizon aggregates the incident with a broader population and describes investigation, remedy and control improvement. Underlying details remain in a restricted evidence file. Treatment: anonymisation and aggregation.

Issue D — missing supplier incident data

The company has incomplete information from indirect suppliers. There is no confidentiality or legal restriction. Horizon uses a risk-based estimate, explains coverage and uncertainty, and sets an improvement plan. Treatment: estimate and data-gap disclosure, not omission.

The case demonstrates why a single confidentiality label is inadequate. Three issues are reported through alternative presentation; only the protected technical detail uses the omission exemption.

Illustrative omission disclosure

Why it works. It identifies the exemption, limits its scope, preserves surrounding decision-useful information, records alternatives and governance, and commits to annual reassessment.

What must be adapted. The legal classification, exact datapoint, alternative methods, approver and remaining disclosed information must match the entity’s facts.

Hypothetical scenario

Illustrative wording — adapt to facts and legal advice

“The undertaking has omitted one technical datapoint concerning proprietary process know-how because the information qualifies as a trade secret under the applicable legal definition. The exemption has been applied only to the protected technical detail. The related action, governance, resources, expected operational effect, dependencies and material uncertainty are disclosed in this section. The undertaking considered aggregated and range-based presentation but concluded that those methods would still reveal the protected know-how. The basis for the conclusion was approved by the Disclosure Committee following legal review and will be reassessed at the next reporting date.”

Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.

In practice

Weak versus stronger handling

Weak treatment Stronger controlled treatment
“Information omitted for confidentiality” Defined category, legal basis, datapoint notice, alternative-presentation test and annual reassessment
Entire transition-plan section removed because one technology is sensitive Protected technical detail omitted; strategy, action, resources, dependencies and effects retained
Supplier name removed but the remaining facts identify it Re-identification risk assessed and data aggregated at a safe level
Missing figure labelled confidential Estimate or data-gap treatment applied with method and improvement plan
Legal approves a blanket list once Each datapoint and reporting date reassessed with current facts
Public report says nothing about use of exemptions Required use of exemption stated without disclosing the protected content

Governance workflow

Step 1. Identify the exact datapoint and disclosure objective

Do not review a whole section in the abstract. Mark the precise text, number, assumption or evidence whose disclosure is challenged.

Step 2. Classify the concern

Use the five-treatment taxonomy. If the issue is ordinary confidentiality or missing data, route it to aggregation/redaction or estimate controls rather than the omission register.

Step 3. Test less restrictive alternatives

Prepare at least one alternative disclosure: category-level wording, range, non-monetary quantity, delayed granularity, anonymised case, cross-reference or partial redaction. Assess whether it still produces a fair and balanced understanding.

Step 4. Obtain specialist review

Commercial prejudice requires commercial and legal evidence. Trade-secret claims require legal classification. Privacy and security require the relevant specialists. Reporting owners should not make these determinations alone.

Step 5. Approve at governance level

Material omissions should be visible to the Disclosure Committee and, where significant to the approval of the sustainability statement, the relevant management or supervisory body. The approval record should state what remains disclosed.

Step 6. Control public notice and connected information

Ensure the datapoint notice is included. Check that cross-references, targets, financial effects, risk descriptions and the compliance statement do not contradict the omission.

Step 7. Reassess annually and on trigger events

Reassess if negotiations end, information becomes public, legal classification changes, a security risk is resolved, a population becomes large enough for safe aggregation or new reporting guidance is issued.

In practice

Common mistakes and corrections

Mistake Risk Correction
Using “commercially sensitive” as a substitute for serious prejudice Overbroad omission and unbalanced report Document specific credible harm and exceptional circumstances
Skipping aggregation because management wants no disclosure Fails the alternative-presentation condition Prepare and challenge less restrictive wording
Treating an NDA as an ESRS exemption by itself Contractual confidentiality may not meet paragraph 100 Analyse legal category and disclosure objective
Omitting poor performance Creates greenwashing and fair-presentation risk Disclose performance; protect only genuinely restricted detail
Combining privacy and missing-data rationales Obscures the actual limitation Separate anonymisation from estimation
Omitting without datapoint-level notice Fails an explicit condition Add controlled exemption notice
Reusing last year’s legal memo Circumstances and public availability may have changed Annual reassessment and trigger review
Providing the public report’s vague wording as the only evidence Assurance cannot evaluate the conditions Retain restricted detailed evidence and approvals

Myth

“If management or a counterparty considers information confidential, ESRS allows it to be left out.”

Reality

ESRS omission categories are specific and conditional. Ordinary confidentiality often calls for aggregation, anonymisation or limited redaction. Commercial-prejudice omission is exceptional and requires serious harm, a fair-and-balanced result, proof that less restrictive presentation cannot meet the objective, datapoint notice and annual reassessment. Missing or inconvenient information must be handled under data-gap and estimate rules.

Readiness

Omission review checklist

  • The exact datapoint and disclosure objective are identified.
  • The issue is classified separately from ordinary confidentiality and missing data.
  • The applicable ESRS and legal basis are documented.
  • The specific harm, right or security interest is evidenced.
  • Aggregation, anonymisation, range and redaction have been tested.
  • The remaining disclosure provides a fair and balanced understanding.
  • The omission is limited to the minimum protected information.
  • Use of the exemption is disclosed for the datapoint.
  • Connected narratives, metrics, targets and financial effects remain consistent.
  • Underlying evidence is retained under controlled access.
  • Legal and specialist reviewers have approved the classification.
  • Governance approval is recorded.
  • Annual and trigger-based reassessment is scheduled.

Frequently asked questions

Can customer or supplier names be omitted?

Often a useful disclosure can be provided at category, geography or concentration level without names. Whether a name must or may be withheld depends on materiality, contractual and legal restrictions, commercial harm and the disclosure objective. Removing a name does not justify removing the underlying impact or risk.

Is an NDA enough to use the ESRS omission exemption?

Not automatically. An NDA may be relevant evidence of confidentiality, but the undertaking still needs a paragraph 100 category and its conditions, or it should use aggregation/redaction that meets the disclosure objective.

Can anticipated financial effects be omitted for commercial prejudice?

The ESRS application guidance states that the omission provisions apply to anticipated financial effects. The undertaking must still meet the relevant omission conditions and preserve decision-useful surrounding information.

How should the use of an exemption be disclosed without revealing the secret?

State that the exemption was used for the relevant datapoint and, where safe, identify the category and scope. Do not describe the protected information so precisely that the notice defeats the protection.

Is “not approved by the board” a ground for omission?

No. Draft status may affect whether information is reliable or constitutes a plan, but it is not itself a confidentiality exemption. The undertaking should assess materiality, estimate status, governance and the applicable disclosure requirement.

Questions

Questions people ask

Can names be omitted?

Often a useful disclosure can be provided at category, geography or concentration level without names. Whether a name must or may be withheld depends on materiality, contractual and legal restrictions, commercial harm and the disclosure objective. Removing a name does not justify removing the underlying impact or risk.

Is an NDA enough?

Not automatically. An NDA may be relevant evidence of confidentiality, but the undertaking still needs a paragraph 100 category and its conditions, or it should use aggregation/redaction that meets the disclosure objective.

Can financial effects be withheld?

The ESRS application guidance states that the omission provisions apply to anticipated financial effects. The undertaking must still meet the relevant omission conditions and preserve decision-useful surrounding information.

How is an exemption disclosed?

State that the exemption was used for the relevant datapoint and, where safe, identify the category and scope. Do not describe the protected information so precisely that the notice defeats the protection.

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · ESRS

ESRS and CSRD training

Double materiality, datapoints and the sustainability statement, with a mentor on your own report.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See course formats
/en/knowledge-hub/disclosure-guides/esrs/esrs-information-materiality/esrs-omissions-and-confidential-information-commercial-prejudice-trade/