Controller Processor Agreement Template for Australia
Generate a bespoke document
What is a Controller Processor Agreement?
The Controller Processor Agreement is essential for organizations operating in Australia that outsource the processing of personal data to third parties. This document is required when one party (the controller) engages another party (the processor) to perform data processing activities on its behalf. The agreement ensures compliance with the Privacy Act 1988, Australian Privacy Principles, and related privacy regulations. It details the scope of processing activities, security measures, data breach protocols, and compliance requirements. The document is particularly crucial given Australia's strict privacy regime and the significant penalties for non-compliance. It should be used whenever an organization engages external parties to process personal data, whether for cloud services, analytics, payroll processing, or other data handling activities.
About the Controller Processor Agreement
A Controller Processor Agreement is a critical legal document that governs the relationship between organizations that collect personal data (controllers) and third-party service providers that process that data (processors). Under Australian privacy law, this agreement is essential whenever you outsource data processing activities to external parties, ensuring both organizations understand their obligations and liabilities under the Privacy Act 1988.
When do you need this document?
You need a Controller Processor Agreement whenever your organization engages external service providers to handle personal data on your behalf. This includes cloud storage providers, software-as-a-service platforms, marketing agencies processing customer data, payroll service providers, IT support companies accessing employee information, and analytics firms processing user data. The agreement is also required when engaging sub-processors or when your service provider uses additional third parties. Australian organizations must have these agreements in place before any data processing begins to ensure compliance with the Australian Privacy Principles and avoid potential penalties for privacy breaches.
Key legal considerations
The agreement must clearly define the scope and purpose of data processing activities, specifying what personal information will be processed and for what legitimate business purposes. Security measures and data protection protocols must be detailed, including encryption requirements, access controls, and incident response procedures. The document should establish clear data retention and deletion schedules, outline procedures for handling data subject access requests, and specify notification requirements in case of data breaches. Liability allocation between controller and processor is crucial, particularly regarding compensation for privacy breaches and regulatory penalties. The agreement must also address cross-border data transfers if the processor stores or processes data outside Australia.
Legal requirements in Australia
Under the Privacy Act 1988 and Australian Privacy Principles, organizations must ensure that any third party processing personal data provides adequate protection equivalent to what the controller would provide. The agreement must comply with APP 8, which requires organizations to take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs. Data breach notification requirements under the Notifiable Data Breaches scheme must be clearly addressed, including timeframes for notification and responsibilities for reporting to the Office of the Australian Information Commissioner. The agreement should reference relevant state privacy laws where applicable and ensure the processor maintains appropriate records of processing activities as required under Australian privacy legislation.
GOVERNING LAW
Applicable law
This Controller Processor Agreement is drafted to comply with Australia law. Key legislation includes:
Privacy Amendment (Notifiable Data Breaches) Act 2017: Establishes mandatory data breach notification requirements for entities regulated by the Privacy Act
Australian Privacy Principles (APPs): 13 principles outlined in Schedule 1 of the Privacy Act that regulate the handling of personal information by Australian government agencies and organizations
Privacy Amendment (Enhancing Privacy Protection) Act 2012: Significant reform to the Privacy Act that introduced the APPs and enhanced privacy protections
State Privacy Laws: Various state-specific privacy laws that may apply depending on the jurisdiction (e.g., Victorian Data Sharing Act 2017, NSW Privacy and Personal Information Protection Act 1998)
Security of Critical Infrastructure Act 2018: May be relevant if the data processing involves critical infrastructure sectors or systems
Competition and Consumer Act 2010: Includes provisions related to unfair contract terms and consumer protection that may affect data handling agreements
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it