Sub Processing Agreement Template for Australia
Generate a bespoke document
What is a Sub Processing Agreement?
The Sub Processing Agreement is essential in modern data processing arrangements where organizations need to delegate data processing activities to additional service providers. This document is particularly relevant in Australia, where the Privacy Act 1988 and Australian Privacy Principles create specific obligations for entities handling personal information. The agreement is typically used when a data processor (who processes data on behalf of a data controller) needs to engage another party (sub-processor) to assist with processing activities. It establishes clear chains of responsibility, ensures compliance with privacy laws, and sets out specific technical and organizational measures for data protection. The Sub Processing Agreement becomes crucial when organizations are handling sensitive data, operating in regulated industries, or engaging in cross-border data transfers, as it helps maintain compliance and manage risk throughout the data processing chain.
Trusted by high-performance teams
About the Sub Processing Agreement
When your organization needs to engage additional service providers to assist with data processing activities, a Sub Processing Agreement ensures you maintain compliance with Australia's strict privacy laws. This document creates a legally binding framework between data processors and sub-processors, establishing clear responsibilities and obligations under the Privacy Act 1988 and Australian Privacy Principles.
When do you need this document?
You need a Sub Processing Agreement whenever your business acts as a data processor and must engage another party to help process personal information. This commonly occurs when cloud service providers subcontract storage or analytics functions, when payroll companies use third-party software providers, or when marketing agencies engage specialized data analysis firms. The agreement is also essential for international arrangements where Australian personal information is processed overseas, ensuring compliance with cross-border data transfer requirements under the Privacy Act.
Key legal considerations
The agreement must clearly define the scope of permitted processing activities and establish that the sub-processor will only process data according to documented instructions. Critical clauses include data security obligations, breach notification procedures, and rights of audit or inspection. You must ensure the sub-processor provides sufficient guarantees regarding technical and organizational measures for data protection. The agreement should address data retention periods, deletion procedures, and the return of data upon termination. Risk allocation clauses are crucial, particularly regarding liability for data breaches or privacy violations that could result in regulatory action or compensation claims.
Legal requirements in Australia
Under the Privacy Act 1988, the primary data processor remains responsible for compliance with Australian Privacy Principles even when using sub-processors. The agreement must ensure the sub-processor meets equivalent data protection standards and implements appropriate security measures as required under APP 11. If the sub-processing involves overseas data transfers, you must comply with APP 8 requirements, including ensuring the overseas recipient is subject to substantially similar privacy protections or obtaining individual consent. The Security of Critical Infrastructure Act 2018 may impose additional requirements if the data processing involves critical infrastructure sectors. Documentation requirements under the Privacy Act mean you must maintain records of all sub-processing arrangements and be able to demonstrate compliance with privacy obligations throughout the processing chain.
GOVERNING LAW
Applicable law
This Sub Processing Agreement is drafted to comply with Australia law. Key legislation includes:
Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010): Provides consumer protections that may apply to data processing services and contractual relationships
Contracts Review Act 1980: Governs the formation and enforcement of contracts in Australia, relevant for the agreement's validity
Electronic Transactions Act 1999: Regulates electronic communications and transactions, relevant for digital data processing activities
Security of Critical Infrastructure Act 2018: May apply if the data processing involves critical infrastructure sectors or sensitive data
Notifiable Data Breaches Scheme: Part of the Privacy Act requiring organizations to notify individuals and the OAIC about data breaches likely to cause serious harm
State-specific Privacy Laws: Various state-level privacy regulations that might apply depending on the location of data processing activities
Cross-border Disclosure Requirements under APP 8: Specific requirements for sending personal information to overseas recipients
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

