Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Intercompany Data Processing Agreement
"I need an Intercompany Data Processing Agreement under Austrian law for our financial services group, where our Vienna headquarters will process customer data for our German subsidiary, including international data transfers and sub-processing rights."
1. Parties: Identification of the group companies involved - controller entity and processor entity
2. Background: Context of the intercompany relationship and purpose of the data processing agreement
3. Definitions: Key terms used in the agreement, including GDPR-specific terminology and company group-specific terms
4. Scope and Purpose of Processing: Detailed description of the data processing activities, categories of data, and processing purposes
5. Duration of Processing: Term of the agreement and processing activities
6. Obligations of the Processor: Processor's duties under GDPR Article 28, including processing only on documented instructions
7. Obligations of the Controller: Controller's responsibilities and requirements for lawful instructions
8. Confidentiality: Confidentiality obligations for the processing of personal data and business information
9. Technical and Organizational Measures: Security measures implemented to ensure appropriate level of data protection
10. Sub-processing: Conditions and requirements for engaging sub-processors within or outside the company group
11. Data Subject Rights: Procedures for handling data subject requests and processor's assistance obligations
12. Personal Data Breach: Notification requirements and procedures in case of data breaches
13. Audit Rights: Controller's audit rights and processor's cooperation obligations
14. Return or Deletion of Data: Obligations regarding personal data at the end of processing activities
15. Liability and Indemnification: Allocation of liability between group companies and indemnification provisions
16. Governing Law and Jurisdiction: Austrian law as governing law and jurisdiction provisions
1. International Data Transfers: Required when personal data will be transferred outside the EEA within the company group
2. Group-Wide Data Protection Standards: Include when referencing binding corporate rules or group-wide data protection policies
3. Cost Allocation: Include when there are specific intercompany charging arrangements for processing activities
4. Insurance: Include when specific insurance requirements need to be specified between group entities
5. Works Council Requirements: Include when processing involves employee data requiring works council involvement
6. Emergency Protocols: Include for critical processing activities requiring specific emergency procedures
7. Group-wide Audit Procedures: Include when establishing specific audit procedures aligned with group compliance programs
1. Schedule 1 - Processing Activities: Detailed description of processing activities, including data categories, purposes, and duration
2. Schedule 2 - Technical and Organizational Measures: Detailed description of security measures implemented by the processor
3. Schedule 3 - Approved Sub-processors: List of pre-approved sub-processors within the group or third parties
4. Schedule 4 - Transfer Mechanisms: Details of transfer mechanisms used for international data transfers
5. Schedule 5 - Security Breach Response Plan: Detailed procedures for handling and reporting data breaches
6. Appendix A - Standard Forms: Standard forms for data subject requests, breach notifications, and audit requests
7. Appendix B - Contact Points: List of key contacts for data protection matters in both controller and processor entities
Authors
Affiliated Company
Applicable Data Protection Laws
Austrian Data Protection Act
Authorized Personnel
Binding Corporate Rules
Controller
Data Protection Impact Assessment
Data Protection Officer
Data Subject
Data Subject Rights
EEA
EU Standard Contractual Clauses
GDPR
Group Company
Information Security Incident
International Data Transfer
Parent Company
Personal Data
Personal Data Breach
Processing
Processor
Restricted Transfer
Security Measures
Services
Special Categories of Personal Data
Sub-processor
Supervisory Authority
Technical and Organizational Measures
Term
Third Country
Transfer Mechanisms
Written Instructions
Scope of Processing
Duration
Processing Instructions
Confidentiality
Security Measures
Sub-processing
Data Subject Rights
Data Protection Impact Assessment
Data Breach Notification
Data Transfer
Audit Rights
Technical and Organizational Measures
Return or Deletion of Data
Liability
Indemnification
Force Majeure
Termination
Governing Law
Jurisdiction
Assignment
Severability
Entire Agreement
Notices
Amendments
Compliance with Laws
Personnel Obligations
Documentation
Cooperation
Insurance
Cost Allocation
Dispute Resolution
Financial Services
Manufacturing
Technology
Healthcare
Retail
Professional Services
Insurance
Telecommunications
Energy
Transportation and Logistics
Pharmaceuticals
Real Estate
Media and Entertainment
Consumer Goods
Education
Legal
Compliance
Data Protection
Information Security
IT
Risk Management
Corporate Governance
Information Governance
Operations
Privacy Office
Regulatory Affairs
Internal Audit
Technology Governance
Data Protection Officer
Privacy Manager
Legal Counsel
Compliance Officer
IT Security Manager
Chief Information Security Officer
Group Privacy Director
Corporate Counsel
Risk Manager
Information Governance Manager
Chief Legal Officer
Head of Compliance
Privacy Counsel
Group Data Protection Manager
Chief Technology Officer
Head of IT
Operations Director
Group Security Officer
Find the exact document you need
Agreement On The Processing Of Personal Data
An Austrian law-governed agreement establishing terms for personal data processing between controller and processor, ensuring GDPR and DSG compliance.
Data Processing Contract
Austrian law-governed Data Processing Contract ensuring GDPR compliance for controller-processor relationships.
Joint Controller Agreement
An Austrian law-governed agreement defining responsibilities and obligations between parties jointly controlling personal data processing under GDPR Article 26.
Standard Data Processing Agreement
An Austrian law-governed Data Processing Agreement establishing GDPR-compliant terms between data controller and processor.
Order Data Processing Agreement
An Austrian law-governed Data Processing Agreement establishing terms for personal data processing under GDPR and national requirements.
Data Addendum
An Austrian law-governed data processing addendum ensuring GDPR and DSG compliance for controller-processor relationships.
Data Processing Addendum DPA
An Austrian law-governed Data Processing Addendum that establishes GDPR-compliant terms for personal data processing between controllers and processors.
Controller To Controller Data Processing Agreement
An Austrian law-governed agreement establishing data sharing arrangements between two independent data controllers, ensuring GDPR and DSG compliance.
Intercompany Data Processing Agreement
Austrian law-governed Intercompany Data Processing Agreement for GDPR-compliant data processing between group companies.
Controller To Controller DPA
An Austrian law-governed Data Processing Agreement between two independent data controllers, compliant with GDPR and DSG requirements.
Data Transfer Addendum
An Austrian law-governed addendum establishing terms for compliant personal data transfers between organizations, ensuring adherence to GDPR and Austrian data protection requirements.
Controller Processor Agreement
An Austrian law-governed agreement between a data controller and processor establishing GDPR-compliant terms for personal data processing.
Order Processing Agreement
Austrian law-governed Order Processing Agreement establishing GDPR-compliant terms for personal data processing between controller and processor.
Data Protection Agreement For Employees
An Austrian-law governed employee data protection agreement ensuring GDPR and DSG compliance in the employment relationship.
Affiliate Addendum
An Austrian law-governed addendum establishing terms and conditions for affiliate marketing relationships, including commission structures and compliance requirements.
Sub Processing Agreement
An Austrian law-governed agreement establishing terms for delegating personal data processing activities to a sub-processor, ensuring GDPR compliance.
International Data Transfer Agreement
An Austrian law-governed agreement for lawful transfer of personal data from EU/EEA to non-EU/EEA countries, ensuring GDPR compliance and appropriate data protection safeguards.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.