Controller To Controller Dpa Template for England and Wales
Generate a bespoke document
What is a Controller To Controller Dpa?
The Controller to Controller DPA is essential when two organizations, acting as independent data controllers, need to share personal data while maintaining compliance with UK data protection laws. This agreement is specifically designed for use in England and Wales, addressing requirements under the UK GDPR and Data Protection Act 2018. It outlines the responsibilities of each controller, including data security measures, breach notification procedures, and management of data subject rights. The document is particularly crucial for organizations regularly sharing personal data as part of their business operations or collaborative projects.
Trusted by high-performance teams
About the Controller To Controller Dpa
When your organization needs to share personal data with another independent data controller, a Controller To Controller Data Protection Agreement (DPA) provides the essential legal framework to ensure compliance with UK data protection laws. This specialized agreement establishes clear responsibilities between two separate data controllers operating in England and Wales, ensuring both parties meet their obligations under the UK GDPR and Data Protection Act 2018.
When do you need this document?
You need a Controller To Controller DPA whenever two independent organizations share personal data for their own purposes. This commonly occurs when businesses collaborate on joint projects, share customer information for marketing purposes, or exchange employee data during acquisitions. Healthcare providers sharing patient information with specialists, educational institutions exchanging student records, or financial services companies sharing client data for compliance purposes all require this agreement. The document is also essential when organizations merge databases, participate in industry consortiums, or engage in research partnerships involving personal data.
Key legal considerations
The agreement must clearly define each controller's specific purposes for processing shared data and establish valid legal bases under the UK GDPR. Both parties need to implement appropriate technical and organizational security measures proportionate to the risk level of the data being shared. The document should specify breach notification procedures, ensuring both controllers can meet the 72-hour reporting requirement to the Information Commissioner's Office. Data retention periods must be clearly defined, with provisions for secure deletion when the data is no longer needed. The agreement should also address how each controller will handle data subject rights requests, including access, rectification, erasure, and portability rights.
Legal requirements in England and Wales
Under UK GDPR and the Data Protection Act 2018, both controllers must have lawful bases for processing and sharing personal data. The agreement must comply with the principle of data minimization, ensuring only necessary data is shared for specified purposes. Both parties need to conduct Data Protection Impact Assessments where high-risk processing is involved. The document should address requirements under the Privacy and Electronic Communications Regulations (PECR) if electronic marketing is involved. Controllers must also consider common law duties of confidentiality when sharing sensitive commercial or personal information. The Information Commissioner's Office guidance on data sharing must be followed, particularly regarding transparency requirements and the need to update privacy notices to inform data subjects about the sharing arrangement.
GOVERNING LAW
Applicable law
This Controller To Controller Dpa is drafted to comply with England and Wales law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

