Joint Controller Agreement Template for Australia

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Joint Controller Agreement?

This Joint Controller Agreement is essential when two or more organizations jointly determine how personal data will be processed in Australia. It is required for compliance with the Privacy Act 1988 and Australian Privacy Principles (APPs), particularly when organizations share decision-making authority over data processing activities. The agreement should be used when parties collaborate on projects involving shared data processing, joint ventures, or integrated services where both parties influence how personal data is handled. It establishes clear lines of responsibility, ensures transparent communication to data subjects, and sets out procedures for managing data protection obligations, including breach notification and subject access requests. The document is crucial for demonstrating compliance with Australian privacy laws and establishing clear accountability between joint controllers.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Australia

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Joint Controller Agreement

When your organization shares data processing decisions with another entity in Australia, you need a Joint Controller Agreement to comply with privacy law. This legally binding document establishes clear responsibilities between organizations that jointly determine the purposes and means of processing personal data under the Privacy Act 1988.

When do you need this document?

You need a Joint Controller Agreement whenever two or more organizations make shared decisions about how personal data is collected, used, or disclosed. This typically occurs in business partnerships, joint ventures, shared marketing campaigns, or integrated service delivery where both parties influence data processing activities. For example, if your company partners with another business to deliver services requiring customer data sharing, or when multiple entities collaborate on research projects involving personal information, this agreement becomes essential. The document is also required when organizations share databases, conduct joint customer relationship management, or engage in co-marketing activities where both parties determine data processing purposes.

Key legal considerations

Your Joint Controller Agreement must clearly allocate responsibilities between parties to avoid regulatory gaps and potential liability. Key clauses should define each controller's specific obligations under the Australian Privacy Principles, establish procedures for handling data subject requests, and outline breach notification responsibilities. The agreement must address data sharing protocols, security measures, and retention periods that comply with APP requirements. Consider including provisions for regular compliance audits, staff training obligations, and procedures for managing third-party processors. Cross-border data transfer clauses are crucial if either party operates internationally, ensuring compliance with APP 8. The agreement should also establish clear communication channels for privacy-related matters and define how each party will respond to regulatory inquiries from the Office of the Australian Information Commissioner.

Legal requirements in Australia

Under Australian privacy law, joint controllers must ensure their agreement complies with all 13 Australian Privacy Principles established by the Privacy Act 1988. You must clearly identify each party's role in data collection, use, and disclosure activities, ensuring transparency in your privacy policies and collection notices. The agreement must address notification obligations under the Notifiable Data Breaches scheme, including which party is responsible for reporting breaches to the OAIC and affected individuals. Each controller remains jointly liable for privacy compliance, so your agreement should establish indemnification clauses and dispute resolution procedures. State privacy laws may impose additional requirements, particularly in New South Wales under the Privacy and Personal Information Protection Act 1998. Ensure your agreement includes provisions for regular review and updates to maintain ongoing compliance with evolving privacy regulations and enforcement guidance from the OAIC.

GOVERNING LAW

Applicable law

This Joint Controller Agreement is drafted to comply with Australia law. Key legislation includes:

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it