Joint Data Controller Agreement Template for Australia
Generate a bespoke document
What is a Joint Data Controller Agreement?
The Joint Data Controller Agreement is essential when two or more organizations jointly determine the purposes and means of processing personal data in Australia. This document is required to comply with the Privacy Act 1988 and Australian Privacy Principles, particularly when organizations share data processing responsibilities and need to establish clear protocols for data handling, security, and compliance. The agreement becomes necessary in scenarios such as joint ventures, partnerships, or collaborative projects where multiple entities process personal data together. It addresses critical aspects including but not limited to data protection compliance, security measures, breach notification procedures, liability allocation, and data subject rights management. The document should be implemented before commencing joint processing activities and updated as regulatory requirements or processing activities change.
Trusted by high-performance teams
About the Joint Data Controller Agreement
A Joint Data Controller Agreement is a critical legal document that defines the relationship and responsibilities when two or more organizations collaborate in processing personal data in Australia. Under the Privacy Act 1988 and the Australian Privacy Principles (APPs), this agreement ensures that all parties understand their obligations and maintain compliance when jointly determining how personal information is collected, used, and disclosed.
When do you need this document?
You need this agreement whenever your organization shares data processing responsibilities with another entity. Common scenarios include joint ventures where partners combine customer databases, collaborative research projects involving multiple institutions sharing participant data, shared technology platforms where different companies access the same personal information, and business partnerships that require coordinated marketing efforts using customer data. The agreement is also essential when outsourcing specific data processing functions while maintaining joint control over the processing purposes and means.
Key legal considerations
The agreement must clearly allocate responsibilities for compliance with the thirteen Australian Privacy Principles, particularly regarding collection notices, data quality, security safeguards, and individual access rights. It should establish procedures for handling data subject requests, including access, correction, and deletion requests, ensuring seamless coordination between controllers. Breach notification obligations under the Notifiable Data Breaches scheme must be clearly defined, including timeframes for internal reporting and coordination of notifications to the Office of the Australian Information Commissioner and affected individuals. The document should address liability allocation, indemnification provisions, and dispute resolution mechanisms. Cross-border data transfer obligations must be addressed if any controller operates outside Australia, ensuring compliance with APP 8 requirements.
Legal requirements in Australia
Under Australian law, joint controllers must ensure their agreement complies with the Privacy Act 1988 and all relevant Australian Privacy Principles. The agreement must establish clear governance structures for data protection compliance and designate specific contact points for privacy-related inquiries and requests. Controllers must implement appropriate technical and organizational security measures as required by APP 11, with clearly defined responsibilities for each party. The document must address data retention periods and disposal procedures in accordance with APP 11.2. If the agreement involves organizations subject to different regulatory frameworks, such as credit reporting or telecommunications-specific privacy requirements, these additional obligations must be incorporated. The agreement should also consider implications under the Competition and Consumer Act 2010, particularly regarding unfair contract terms if dealing with small business entities.
GOVERNING LAW
Applicable law
This Joint Data Controller Agreement is drafted to comply with Australia law. Key legislation includes:
Notifiable Data Breaches (NDB) scheme: Part of the Privacy Act that establishes requirements for entities to notify individuals and the Commissioner about data breaches that are likely to result in serious harm
Competition and Consumer Act 2010: Includes provisions relating to unfair contract terms and consumer rights, which may be relevant to data handling practices and agreements between controllers
Electronic Transactions Act 1999: Provides the legal framework for electronic transactions and may be relevant for digital aspects of data processing and transfer between joint controllers
State and Territory Privacy Laws: Various state-specific privacy laws that may apply depending on the location of operations (e.g., Victorian Privacy and Data Protection Act 2014, NSW Privacy and Personal Information Protection Act 1998)
Privacy Regulation 2013: Supplements the Privacy Act with specific requirements for privacy impact assessments and other privacy-related obligations
Spam Act 2003: Relevant if the joint controllers will be engaging in electronic marketing or communications using personal data
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

