Controller To Controller Dpa Template for England and Wales

Generate a bespoke document

What is a Controller To Controller Dpa?

The Controller to Controller DPA is essential when two organizations, acting as independent data controllers, need to share personal data while maintaining compliance with UK data protection laws. This agreement is specifically designed for use in England and Wales, addressing requirements under the UK GDPR and Data Protection Act 2018. It outlines the responsibilities of each controller, including data security measures, breach notification procedures, and management of data subject rights. The document is particularly crucial for organizations regularly sharing personal data as part of their business operations or collaborative projects.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Controller To Controller Dpa

When your organization needs to share personal data with another independent data controller, a Controller To Controller Data Protection Agreement (DPA) provides the essential legal framework to ensure compliance with UK data protection laws. This specialized agreement establishes clear responsibilities between two separate data controllers operating in England and Wales, ensuring both parties meet their obligations under the UK GDPR and Data Protection Act 2018.

When do you need this document?

You need a Controller To Controller DPA whenever two independent organizations share personal data for their own purposes. This commonly occurs when businesses collaborate on joint projects, share customer information for marketing purposes, or exchange employee data during acquisitions. Healthcare providers sharing patient information with specialists, educational institutions exchanging student records, or financial services companies sharing client data for compliance purposes all require this agreement. The document is also essential when organizations merge databases, participate in industry consortiums, or engage in research partnerships involving personal data.

Key legal considerations

The agreement must clearly define each controller's specific purposes for processing shared data and establish valid legal bases under the UK GDPR. Both parties need to implement appropriate technical and organizational security measures proportionate to the risk level of the data being shared. The document should specify breach notification procedures, ensuring both controllers can meet the 72-hour reporting requirement to the Information Commissioner's Office. Data retention periods must be clearly defined, with provisions for secure deletion when the data is no longer needed. The agreement should also address how each controller will handle data subject rights requests, including access, rectification, erasure, and portability rights.

Legal requirements in England and Wales

Under UK GDPR and the Data Protection Act 2018, both controllers must have lawful bases for processing and sharing personal data. The agreement must comply with the principle of data minimization, ensuring only necessary data is shared for specified purposes. Both parties need to conduct Data Protection Impact Assessments where high-risk processing is involved. The document should address requirements under the Privacy and Electronic Communications Regulations (PECR) if electronic marketing is involved. Controllers must also consider common law duties of confidentiality when sharing sensitive commercial or personal information. The Information Commissioner's Office guidance on data sharing must be followed, particularly regarding transparency requirements and the need to update privacy notices to inform data subjects about the sharing arrangement.

GOVERNING LAW

Applicable law

This Controller To Controller Dpa is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: The United Kingdom General Data Protection Regulation - the primary data protection legislation in the UK post-Brexit, setting out the key principles, rights and obligations for processing personal data

Data Protection Act 2018: The UK's implementation of data protection legislation that works alongside and supplements the UK GDPR, providing additional local requirements and derogations

PECR: Privacy and Electronic Communications Regulations 2003 - Specific rules for electronic communications, including electronic marketing and cookies

Common Law Duty of Confidentiality: Legal obligation under English common law to keep certain information confidential, particularly relevant when it has been shared in circumstances implying confidentiality

EU GDPR: European Union General Data Protection Regulation - relevant for cross-border data transfers and when dealing with EU-based parties or data subjects

UK Adequacy Regulations: Regulations determining which countries or territories outside the UK are deemed to provide an adequate level of data protection, facilitating international data transfers

IDTA: International Data Transfer Agreement - The UK's mechanism for ensuring appropriate safeguards for international data transfers to countries without adequacy decisions

UK Addendum to EU SCCs: UK-specific addendum that can be used alongside the EU Standard Contractual Clauses for international data transfers

ICO Controller-Processor Guidance: Official guidance from the Information Commissioner's Office on controller and processor relationships and responsibilities

ICO Data Sharing Code: Statutory code of practice from the ICO providing practical guidance on data sharing between controllers

ICO International Transfer Guidance: ICO guidance on how to legally transfer personal data internationally, including requirements and available mechanisms

ICO Accountability Framework: ICO guidance framework helping organizations implement appropriate measures to ensure and demonstrate compliance with data protection requirements

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

Ready to agree with confidence?
See Genie in action.