Data Transfer Addendum Template for Germany
Generate a bespoke document
What is a Data Transfer Addendum?
The Data Transfer Addendum is essential for organizations transferring personal data under German jurisdiction, whether between group companies, to service providers, or across borders. It supplements existing service or commercial agreements by specifically addressing data protection requirements under German and EU law. This document becomes necessary when personal data is shared between separate legal entities or across jurisdictions, particularly when one party acts as a data controller and another as a data processor. The addendum ensures compliance with the German Federal Data Protection Act (BDSG), GDPR, and includes provisions for international transfers through Standard Contractual Clauses where required. It should be implemented whenever there is systematic sharing of personal data, especially in cross-border scenarios or when engaging new service providers who will process personal data.
Trusted by high-performance teams
About the Data Transfer Addendum
When your organization needs to transfer personal data in Germany, a Data Transfer Addendum provides the essential legal framework to ensure compliance with strict German and EU data protection requirements. This specialized document supplements your existing commercial agreements by addressing the specific obligations and safeguards required under the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
When do you need this document?
You need a Data Transfer Addendum whenever personal data crosses organizational boundaries within your business operations. This includes transferring customer data to cloud service providers, sharing employee information with payroll processors, or sending marketing data to advertising agencies. The document becomes particularly critical for international transfers outside the European Economic Area, where additional safeguards like Standard Contractual Clauses must be implemented. German companies engaging sub-processors, establishing data sharing arrangements with subsidiaries, or partnering with third-party service providers all require this addendum to maintain legal compliance.
Key legal considerations
Your Data Transfer Addendum must clearly define the roles of data controller and processor, specify the categories and purposes of data processing, and establish comprehensive security measures. The document should include detailed provisions for data subject rights, breach notification procedures, and audit rights for the data exporter. Critical clauses must address data retention periods, return or deletion obligations upon contract termination, and restrictions on further transfers to sub-processors. You should also include liability allocation between parties, indemnification provisions, and specific procedures for handling data protection authority inquiries or enforcement actions.
Legal requirements in Germany
German law requires your Data Transfer Addendum to comply with both GDPR Article 28 requirements and additional BDSG provisions that supplement EU regulations. The document must be written in clear, understandable language and include all mandatory information specified in GDPR Article 28(3). For international transfers, you must incorporate appropriate transfer mechanisms such as EU Standard Contractual Clauses, adequacy decisions, or approved codes of conduct. German federal state data protection laws may impose additional requirements depending on your processing location. The addendum must also address specific German legal concepts like joint controllership arrangements and provide mechanisms for cooperation with German data protection authorities, including the federal commissioner and state-level supervisory authorities.
GOVERNING LAW
Applicable law
This Data Transfer Addendum is drafted to comply with Germany law. Key legislation includes:
BDSG (Bundesdatenschutzgesetz): German Federal Data Protection Act that implements and supplements GDPR at the national level
BGB (Bürgerliches Gesetzbuch): German Civil Code providing the fundamental rules for contracts and legal relationships between parties
EU Standard Contractual Clauses: EU Commission's approved mechanism for international data transfers to third countries under GDPR Article 46
State Data Protection Laws (Landesdatenschutzgesetze): Specific data protection regulations of German federal states that may apply depending on the location of data processing
EU-US Data Privacy Framework: Framework for transatlantic data flows if transfers to the US are involved
HGB (Handelsgesetzbuch): German Commercial Code relevant for business-to-business contracts and commercial relationships
TMG (Telemediengesetz): German Telemedia Act governing digital services and online data processing
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

