Controller To Controller Agreement Template for Germany
Generate a bespoke document
What is a Controller To Controller Agreement?
The Controller to Controller Agreement is essential when two or more organizations jointly determine the purposes and means of processing personal data in Germany. This document is particularly crucial for businesses engaged in collaborative projects, shared services, or joint ventures where personal data processing is involved. It must comply with both the GDPR and the German Federal Data Protection Act (BDSG), addressing specific German regulatory requirements and enforcement practices. The agreement outlines each party's obligations regarding data subject rights, transparency requirements, and security measures, while establishing clear lines of responsibility and liability allocation. It's particularly important in the German context due to the strict regulatory environment and the active role of German data protection authorities in enforcement.
About the Controller To Controller Agreement
A Controller To Controller Agreement is a legally binding document that governs the relationship between two or more organizations that jointly determine the purposes and means of processing personal data. Under German data protection law, this agreement is mandatory when organizations engage in joint processing activities, ensuring compliance with both the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz).
When do you need this document?
You need this agreement when your organization collaborates with other entities in ways that involve shared personal data processing. Common scenarios include joint marketing campaigns where customer databases are combined, shared research projects involving participant data, collaborative service platforms where multiple companies access the same user information, and business partnerships where customer or employee data is exchanged. German companies must also establish these agreements when working with international partners who process data of German residents, particularly given Germany's active enforcement of data protection regulations.
Key legal considerations
The agreement must clearly define each controller's specific responsibilities under GDPR Article 26, including who handles data subject requests, breach notifications, and regulatory communications. You must establish transparent arrangements for data subjects regarding their rights and how to exercise them. The document should specify data security measures, retention periods, and deletion procedures that both parties will implement. Liability allocation is crucial – you need to determine how responsibility is shared for potential data protection violations and associated penalties. The agreement must also address data transfer mechanisms if one controller is outside the EU, potentially requiring Standard Contractual Clauses or adequacy decisions.
Legal requirements in Germany
German law requires additional considerations beyond standard GDPR compliance. The Bundesdatenschutzgesetz (BDSG) provides specific national requirements that may affect your agreement, particularly regarding employee data processing and special categories of personal data. You must consider state-level data protection laws (Landesdatenschutzgesetze) that may apply depending on your operational locations within Germany. The agreement should address reporting obligations to German supervisory authorities, including the Federal Commissioner for Data Protection and Freedom of Information (BfDI) and relevant state authorities. German courts apply strict contractual interpretation under the Bürgerliches Gesetzbuch (BGB), so precise language and clear obligations are essential. Regular review and updates of the agreement are recommended to maintain compliance with evolving German data protection guidance and enforcement practices.
GOVERNING LAW
Applicable law
This Controller To Controller Agreement is drafted to comply with Germany law. Key legislation includes:
Bundesdatenschutzgesetz (BDSG): German Federal Data Protection Act - implements and supplements GDPR in Germany, providing specific national requirements
Bürgerliches Gesetzbuch (BGB): German Civil Code - provides the legal framework for contract formation and validity under German law
Landesdatenschutzgesetze: State Data Protection Laws - may apply depending on the specific German state (Bundesland) where the controllers operate
EU Standard Contractual Clauses (SCCs): If any international data transfers are involved, these would need to be considered and potentially incorporated
BfDI Guidelines: Guidelines from the German Federal Commissioner for Data Protection and Freedom of Information, providing practical interpretation of data protection requirements
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it