Controller To Controller Data Processing Agreement Template for Australia
Generate a bespoke document
What is a Controller To Controller Data Processing Agreement?
A Controller To Controller Data Processing Agreement is essential when two organizations need to share personal data while maintaining independent control over their respective data processing activities. This document is particularly relevant in the Australian legal context, where organizations must comply with the Privacy Act 1988 (Cth) and Australian Privacy Principles. The agreement is necessary when both parties act as data controllers and need to establish clear frameworks for data sharing, security measures, breach notification procedures, and compliance responsibilities. It's commonly used in scenarios such as partnerships, joint ventures, data sharing initiatives, or when organizations need to exchange customer or employee data for legitimate business purposes. The agreement includes comprehensive provisions for data protection, cross-border transfers, and regulatory compliance, while clearly defining each party's obligations and liabilities.
About the Controller To Controller Data Processing Agreement
When your organization needs to share personal data with another company while both parties maintain control over the processing activities, you need a Controller To Controller Data Processing Agreement. This legal document is crucial under Australian privacy law, ensuring both organizations comply with their obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) while protecting individuals' privacy rights.
When do you need this document?
You require this agreement when entering into business relationships that involve mutual data sharing. Common scenarios include strategic partnerships where customer databases are shared for joint marketing campaigns, merger and acquisition due diligence processes, joint research projects between universities and corporations, and collaborative ventures between healthcare providers sharing patient information. The agreement is also essential when outsourcing specific business functions where both parties will process personal data independently, such as shared customer service operations or co-branded loyalty programs.
Key legal considerations
The agreement must clearly define each party's role as a data controller and specify the types of personal information being shared, including sensitive information categories under APP 3. You need to establish robust security measures that comply with APP 11, including encryption standards, access controls, and regular security assessments. Data breach notification procedures must align with the Notifiable Data Breaches scheme, specifying timeframes and responsibilities for notifying the Office of the Australian Information Commissioner and affected individuals. The document should address data retention periods, deletion obligations, and audit rights to ensure ongoing compliance. Cross-border data transfer provisions are critical if either party operates internationally, requiring adequate protection mechanisms under APP 8.
Legal requirements in Australia
Under Australian law, both controllers must ensure the agreement complies with all 13 Australian Privacy Principles, particularly APP 6 regarding use and disclosure of personal information. The agreement must specify lawful bases for data sharing and processing activities, ensuring transparency requirements under APP 5 are met through appropriate privacy notices. You must establish mechanisms for handling data subject access requests under APP 12, including procedures for coordinating responses between controllers. The document should address liability and indemnification provisions, considering potential penalties under the Privacy Act which can reach $2.22 million for serious breaches. Regular compliance reviews and dispute resolution mechanisms should be included to maintain ongoing legal compliance and address any regulatory changes affecting the data sharing arrangement.
GOVERNING LAW
Applicable law
This Controller To Controller Data Processing Agreement is drafted to comply with Australia law. Key legislation includes:
Australian Privacy Principles (APPs): 13 privacy principles under the Privacy Act that set out standards for the collection, use, disclosure and management of personal information
Notifiable Data Breaches (NDB) scheme: Part of the Privacy Act that requires organizations to notify affected individuals and the OAIC when a data breach is likely to result in serious harm
Competition and Consumer Act 2010: Includes provisions relevant to fair trading and consumer protection that may impact data sharing agreements between businesses
Electronic Transactions Act 1999: Provides the legal framework for electronic transactions and digital signatures in Australia
State and Territory Privacy Laws: Various state-specific privacy legislation that may apply depending on the location of the parties and data subjects
Spam Act 2003: Relevant if the agreement involves the sharing of contact information that might be used for electronic marketing
Cross-border Privacy Rules (CBPR): APEC privacy framework that Australia has joined, relevant for international data transfers
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it