Intercompany Data Processing Agreement Template for Australia

Generate a bespoke document

What is a Intercompany Data Processing Agreement?

The Intercompany Data Processing Agreement is utilized when companies within the same corporate group need to establish formal arrangements for processing personal data in Australia. This document is essential for compliance with the Privacy Act 1988 and Australian Privacy Principles, particularly when one group entity acts as a data controller and another as a data processor. The agreement becomes necessary when group companies share customer data, employee information, or other personal data for various business purposes. It outlines specific obligations regarding data security, confidentiality, breach notification, and data subject rights, while also addressing the unique aspects of related party transactions. The document is particularly important for Australian businesses with complex corporate structures or those operating across multiple jurisdictions while maintaining an Australian nexus.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Australia

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Intercompany Data Processing Agreement

An Intercompany Data Processing Agreement is a specialised contract that governs how personal data is handled between related companies within the same corporate group. Under Australian law, this agreement ensures your group entities comply with the Privacy Act 1988 and Australian Privacy Principles when sharing or processing personal information across different companies in your corporate structure.

When do you need this document?

You need this agreement when your parent company collects customer data but your subsidiary processes it for marketing campaigns, or when your holding company manages employee records that operating companies need to access for payroll and HR functions. It's essential when your Australian head office shares client information with regional subsidiaries for service delivery, or when group companies collaborate on joint projects requiring personal data exchange. The agreement becomes critical during corporate restructures where data processing responsibilities shift between entities, and when implementing shared IT systems across multiple group companies. You also need this document if your group operates across state boundaries, as different Australian jurisdictions may have varying privacy requirements.

Key legal considerations

Your agreement must clearly define which entity acts as the data controller and which serves as the data processor under Australian privacy law. The data controller retains primary responsibility for compliance with Australian Privacy Principles, while the processor must follow specific instructions and maintain appropriate security measures. You need robust data security clauses that meet Australian standards, including encryption requirements, access controls, and staff training obligations. The agreement should include comprehensive breach notification procedures that comply with the Notifiable Data Breaches scheme under the Privacy Act. Data retention and deletion clauses must align with Australian legal requirements and your privacy policy commitments. Cross-border data transfer provisions are crucial if any group entity is located outside Australia, requiring adequate protection measures or relevant exceptions under Australian privacy law.

Legal requirements in Australia

Under the Privacy Act 1988, your agreement must ensure both entities understand their obligations regarding the Australian Privacy Principles, particularly around collection, use, disclosure, and security of personal information. The agreement needs to address the Notifiable Data Breaches scheme requirements, including 30-day notification timeframes to the Office of the Australian Information Commissioner and affected individuals. State-specific privacy laws may apply depending on your entities' locations, such as the Privacy and Personal Information Protection Act 1998 in New South Wales. The Corporations Act 2001 imposes additional requirements for related party transactions, requiring proper corporate authorisation and potential disclosure obligations. Your agreement should comply with the Electronic Transactions Act 1999 if using digital signatures or electronic document execution. The Spam Act 2003 may be relevant if your data processing includes electronic marketing activities between group entities.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it