Data Controller To Data Controller Agreement Template for England and Wales

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Controller To Data Controller Agreement?

The Data Controller to Data Controller Agreement is essential when two organizations need to share personal data while maintaining independent control over their respective data processing activities. This agreement, governed by English and Welsh law, establishes clear protocols for data sharing, ensuring compliance with UK data protection legislation. It should be used whenever organizations plan to regularly share personal data, defining each party's obligations, security requirements, and procedures for handling data subject requests and breaches. The agreement is particularly crucial following Brexit, as it incorporates UK GDPR requirements and ICO guidance.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Controller To Data Controller Agreement

When your organization needs to share personal data with another company while both parties maintain independent control over their data processing activities, you need a Data Controller To Data Controller Agreement. This specialized contract ensures compliance with UK data protection laws while establishing clear boundaries and responsibilities for each organization involved in the data sharing arrangement.

When do you need this document?

You should use this agreement whenever your organization plans to regularly share personal data with another independent data controller. This includes situations such as joint marketing initiatives between companies, sharing customer information for enhanced services, business partnerships requiring customer data exchange, or collaborative research projects involving personal information. The agreement is also essential when outsourcing specific functions while retaining joint control over certain data processing activities, or when establishing data sharing relationships with suppliers, distributors, or other business partners who will process shared data for their own purposes.

Key legal considerations

The agreement must clearly define the purpose and scope of data sharing, ensuring both parties have a lawful basis for processing under UK GDPR. You need to specify which data protection principles apply, including data minimization, accuracy, storage limitation, and accountability requirements. Security measures are crucial – the document should outline technical and organizational safeguards that both parties must implement to protect shared personal data. The agreement must address how data subject rights will be handled, including access requests, rectification, erasure, and portability rights. Breach notification procedures are essential, defining how quickly and through what channels each party must inform the other of security incidents. You should also include clear data retention periods, deletion procedures, and termination clauses that specify what happens to shared data when the agreement ends.

Legal requirements in England and Wales

Under English and Welsh law, this agreement must comply with UK GDPR requirements, which diverged from EU GDPR following Brexit. The Data Protection Act 2018 provides additional context for UK-specific obligations that may not be covered in the EU framework. Both parties must ensure they have appropriate lawful bases for processing, which may include legitimate interests, contract performance, or consent depending on the data sharing purpose. The agreement should reference ICO guidance and codes of practice, particularly those relating to data sharing and joint controllers. You must consider the territorial scope of UK GDPR and ensure appropriate safeguards are in place if data will be transferred outside the UK. The document should also address compliance with PECR 2003 if electronic communications or marketing activities are involved. Regular reviews and updates may be necessary to maintain compliance with evolving UK data protection requirements and ICO guidance.

GOVERNING LAW

Applicable law

This Data Controller To Data Controller Agreement is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: Primary legislation governing data protection in the UK post-Brexit, setting out fundamental principles, rights, and obligations for data processing

Data Protection Act 2018: UK's implementation of data protection laws, complementing and supplementing the UK GDPR with specific national requirements

PECR 2003: Privacy and Electronic Communications Regulations governing electronic communications, including rules on cookies, marketing, and communication privacy

ICO Guidance: Official guidance and codes of practice from the Information Commissioner's Office, providing practical interpretation of data protection requirements

EDPB Guidelines: European Data Protection Board guidelines which, while not binding post-Brexit, remain influential in UK data protection practice

UK Case Law: Relevant judicial decisions from UK courts that interpret and apply data protection legislation

Article 5 Principles: Core data protection principles including lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality

Article 6 Processing Bases: Legal bases for processing personal data including consent, contract, legal obligation, vital interests, public task, and legitimate interests

Article 9 Special Categories: Requirements for processing special category data such as health, biometric, racial, or religious information

International Transfers: Rules and requirements for transferring personal data outside the UK, including adequacy decisions and appropriate safeguards

Data Subject Rights: Individual rights including access, rectification, erasure, portability, and objection to processing

Security Requirements: Technical and organizational measures required to ensure appropriate security of personal data

Breach Notifications: Requirements and timeframes for notifying authorities and affected individuals of personal data breaches

Joint Controller Provisions: Specific requirements for situations where two or more controllers jointly determine the purposes and means of processing

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it