Controller Processor Agreement Template for Australia

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Controller Processor Agreement?

The Controller Processor Agreement is essential for organizations operating in Australia that outsource the processing of personal data to third parties. This document is required when one party (the controller) engages another party (the processor) to perform data processing activities on its behalf. The agreement ensures compliance with the Privacy Act 1988, Australian Privacy Principles, and related privacy regulations. It details the scope of processing activities, security measures, data breach protocols, and compliance requirements. The document is particularly crucial given Australia's strict privacy regime and the significant penalties for non-compliance. It should be used whenever an organization engages external parties to process personal data, whether for cloud services, analytics, payroll processing, or other data handling activities.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Australia

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Controller Processor Agreement

A Controller Processor Agreement is a critical legal document that governs the relationship between organizations that collect personal data (controllers) and third-party service providers that process that data (processors). Under Australian privacy law, this agreement is essential whenever you outsource data processing activities to external parties, ensuring both organizations understand their obligations and liabilities under the Privacy Act 1988.

When do you need this document?

You need a Controller Processor Agreement whenever your organization engages external service providers to handle personal data on your behalf. This includes cloud storage providers, software-as-a-service platforms, marketing agencies processing customer data, payroll service providers, IT support companies accessing employee information, and analytics firms processing user data. The agreement is also required when engaging sub-processors or when your service provider uses additional third parties. Australian organizations must have these agreements in place before any data processing begins to ensure compliance with the Australian Privacy Principles and avoid potential penalties for privacy breaches.

Key legal considerations

The agreement must clearly define the scope and purpose of data processing activities, specifying what personal information will be processed and for what legitimate business purposes. Security measures and data protection protocols must be detailed, including encryption requirements, access controls, and incident response procedures. The document should establish clear data retention and deletion schedules, outline procedures for handling data subject access requests, and specify notification requirements in case of data breaches. Liability allocation between controller and processor is crucial, particularly regarding compensation for privacy breaches and regulatory penalties. The agreement must also address cross-border data transfers if the processor stores or processes data outside Australia.

Legal requirements in Australia

Under the Privacy Act 1988 and Australian Privacy Principles, organizations must ensure that any third party processing personal data provides adequate protection equivalent to what the controller would provide. The agreement must comply with APP 8, which requires organizations to take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs. Data breach notification requirements under the Notifiable Data Breaches scheme must be clearly addressed, including timeframes for notification and responsibilities for reporting to the Office of the Australian Information Commissioner. The agreement should reference relevant state privacy laws where applicable and ensure the processor maintains appropriate records of processing activities as required under Australian privacy legislation.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it