DPA Agreement Template for Australia
Generate a bespoke document
What is a DPA Agreement?
The Data Processing Agreement (DPA) is essential for organizations operating in Australia that engage third parties to process personal information on their behalf. This document is required to comply with the Privacy Act 1988 and Australian Privacy Principles, particularly APP 8 and APP 11, which address cross-border disclosure of personal information and security of personal information. The DPA Agreement establishes the rights, obligations, and responsibilities of both data controllers and processors, including requirements for data security, breach notification, audit rights, and data subject rights. It is particularly crucial when personal information is processed by external vendors, cloud service providers, or international organizations, and must address specific Australian regulatory requirements including the Notifiable Data Breaches scheme.
About the DPA Agreement
A Data Processing Agreement (DPA) is a legally binding contract that governs how third parties process personal information on behalf of your organization in Australia. Under the Privacy Act 1988 and Australian Privacy Principles (APPs), you must have proper safeguards in place when engaging external processors to handle personal data. This agreement establishes clear responsibilities, security requirements, and compliance obligations for both parties.
When do you need this document?
You need a DPA whenever you engage third-party service providers to process personal information on your behalf. This includes cloud storage providers, customer relationship management platforms, payroll processors, marketing automation tools, or any international vendor handling Australian personal data. The agreement is particularly crucial when data crosses borders, as APP 8 requires reasonable steps to ensure overseas recipients handle personal information consistently with the APPs. You'll also need this document if your organization operates in critical infrastructure sectors covered by the Security of Critical Infrastructure Act 2018, which imposes additional security obligations.
Key legal considerations
Your DPA must clearly define the scope of processing activities, data categories, and retention periods to comply with APP 3 (collection of solicited personal information). Include specific security measures that align with APP 11's requirement for reasonable steps to protect personal information from misuse, interference, loss, and unauthorized access. The agreement should address data subject rights under the Privacy Act, including access and correction requests. Include comprehensive breach notification procedures that meet the Notifiable Data Breaches scheme requirements, which mandate notification to the Office of the Australian Information Commissioner (OAIC) and affected individuals within specific timeframes when serious harm is likely. Ensure audit rights are included to verify compliance, and specify data deletion or return procedures upon contract termination.
Legal requirements in Australia
Under Australian law, your DPA must address several specific requirements. The Privacy Act 1988 requires that personal information collected for a specific purpose not be used or disclosed for secondary purposes without consent, unless an exception applies. Your agreement must specify lawful processing purposes and ensure data minimization principles are followed. If processing involves cross-border disclosure, you must comply with APP 8 by taking reasonable steps to ensure overseas recipients handle information consistently with the APPs. For organizations handling health information, additional requirements under state privacy laws may apply. The agreement should also address the processor's obligations to assist with privacy impact assessments and compliance audits. Include provisions for regular security reviews and updates to processing procedures as required by evolving privacy regulations and industry standards.
GOVERNING LAW
Applicable law
This DPA Agreement is drafted to comply with Australia law. Key legislation includes:
Notifiable Data Breaches (NDB) scheme: Part IIIC of the Privacy Act 1988, requiring organizations to notify affected individuals and the OAIC when a data breach is likely to result in serious harm
Security of Critical Infrastructure Act 2018: Relevant if the data processing involves critical infrastructure sectors, imposing additional security obligations
State Privacy Laws: Various state-specific privacy laws that might apply depending on the location of data processing (e.g., NSW Privacy and Personal Information Protection Act 1998)
Consumer Data Right (CDR): Legislation governing data portability and sharing, particularly relevant if the DPA involves handling of consumer data in regulated sectors
Spam Act 2003: Relevant if the data processing activities involve electronic communications or marketing activities
Cross-Border Privacy Rules (CBPR): International data transfer requirements that might affect Australian organizations transferring data overseas
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it