Commissioned Data Processing Agreement Template for Canada
Generate a bespoke document
What is a Commissioned Data Processing Agreement?
The Commissioned Data Processing Agreement is a crucial document required whenever an organization (Data Controller) engages a service provider (Data Processor) to process personal information on its behalf in Canada. This agreement is essential for compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws, which require organizations to ensure appropriate safeguards when transferring personal information to third parties for processing. The agreement must address specific requirements under Canadian privacy law, including security measures, confidentiality obligations, cross-border transfer restrictions, and breach notification procedures. It is particularly important given the increasing outsourcing of data processing activities and the need to maintain control over personal information throughout its lifecycle.
Trusted by high-performance teams
About the Commissioned Data Processing Agreement
A Commissioned Data Processing Agreement is a legally binding contract that governs the relationship between an organization (data controller) and a third-party service provider (data processor) when personal information is processed on behalf of the controller. Under Canadian privacy law, this agreement is essential for maintaining compliance with federal and provincial privacy legislation while ensuring appropriate protection of personal data throughout the processing lifecycle.
When do you need this document?
You need this agreement whenever your organization engages external service providers to handle personal information on your behalf. This includes cloud storage providers, payroll processing companies, customer relationship management services, marketing agencies handling customer data, IT support companies accessing employee information, or any vendor that processes personal data as part of their services. The agreement is particularly critical when processing involves sensitive information such as health records, financial data, or employee personal details. Canadian privacy law requires organizations to maintain responsibility for personal information even when processing is outsourced, making this agreement a legal necessity rather than an option.
Key legal considerations
The agreement must clearly define the scope and purpose of data processing activities, specify security measures that meet Canadian privacy standards, and establish protocols for handling data breaches. Key clauses should address data retention periods, deletion procedures upon contract termination, restrictions on sub-processor engagement, and prohibition of unauthorized data use. The contract must include provisions for regular security audits, incident reporting procedures, and compliance monitoring. Cross-border data transfer restrictions are particularly important, as Canadian privacy law limits transfers to jurisdictions without adequate privacy protections. The agreement should also specify liability allocation, indemnification provisions, and termination procedures that ensure secure data return or destruction.
Legal requirements in Canada
Under PIPEDA and provincial privacy laws like Alberta's PIPA, British Columbia's PIPA, and Quebec's Law 25, organizations must implement appropriate safeguards when engaging data processors. The agreement must demonstrate that processors will provide comparable protection to what the controller would provide directly. With Bill C-27 proposing significant privacy law reforms, agreements should be drafted to accommodate stricter consent requirements, enhanced individual rights, and mandatory breach notification timelines. Provincial Electronic Commerce Acts govern digital contract execution, requiring proper authentication for electronic signatures. The Privacy Commissioner of Canada and provincial commissioners have enforcement authority, making compliance documentation critical. Recent regulatory guidance emphasizes the need for explicit contractual provisions addressing algorithmic processing, automated decision-making, and artificial intelligence applications in data processing activities.
GOVERNING LAW
Applicable law
This Commissioned Data Processing Agreement is drafted to comply with Canada law. Key legislation includes:
Provincial Privacy Laws (PIPA Alberta, PIPA BC, Quebec's Law 25): Provincial privacy laws that may apply depending on the jurisdiction of the parties and where the data processing takes place
Digital Charter Implementation Act (Bill C-27): Proposed federal legislation that would reform PIPEDA and introduce more stringent data protection requirements, including specific provisions for automated decision systems
Electronic Commerce Act: Provincial legislation governing electronic transactions and digital signatures, relevant for the execution of the agreement
Contract Law (Common Law/Civil Code): Basic principles of contract law that govern the formation and enforcement of the agreement, varying between common law provinces and Quebec (Civil Code)
Consumer Protection Act: May be relevant if the data processing involves consumer data or if one party is considered a consumer under applicable law
Canada's Anti-Spam Legislation (CASL): Relevant if the data processing involves electronic communications or commercial electronic messages
Personal Health Information Protection Act (PHIPA): Applies if the data processing involves personal health information in Ontario or similar provincial health privacy laws
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

