Data Protection Addendum Template for England and Wales

Generate a bespoke document

What is a Data Protection Addendum?

The Data Protection Addendum is essential when organizations engage in activities involving the processing of personal data in the United Kingdom. This document supplements existing commercial agreements to ensure compliance with UK data protection laws, particularly the UK GDPR and Data Protection Act 2018. It defines roles, responsibilities, and obligations regarding data processing activities, security measures, and breach management. The Data Protection Addendum is particularly crucial when one party processes personal data on behalf of another, establishing clear guidelines for data handling and protection.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Protection Addendum

A Data Protection Addendum is a crucial legal document that establishes binding obligations between organizations when personal data is processed in England and Wales. This addendum supplements your existing commercial agreements to ensure full compliance with UK data protection legislation, including the UK GDPR and Data Protection Act 2018. It clearly defines the roles and responsibilities of data controllers and processors, establishing a framework for lawful data handling.

When do you need this document?

You need a Data Protection Addendum whenever you engage a third party to process personal data on your behalf, or when you process personal data for another organization. This includes cloud service providers handling customer data, marketing agencies processing contact lists, payroll companies managing employee information, or IT support firms accessing user accounts. The document is also essential when establishing data sharing arrangements between organizations, implementing new software systems that handle personal data, or engaging international service providers that may transfer data outside the UK.

Key legal considerations

The addendum must clearly define whether each party acts as a data controller, processor, or joint controller under UK GDPR. You should specify the categories of personal data being processed, the purposes of processing, and the duration of the arrangement. Security measures are critical and must include appropriate technical and organizational safeguards to protect personal data. The document should address data subject rights, including how requests for access, deletion, or rectification will be handled. Breach notification procedures must be established, requiring processors to notify controllers within 72 hours of becoming aware of a breach. If data transfers occur internationally, you must include appropriate transfer mechanisms such as adequacy decisions or Standard Contractual Clauses.

Legal requirements in England and Wales

Under UK GDPR and the Data Protection Act 2018, data processing agreements must meet specific statutory requirements. The addendum must ensure lawful bases for processing are clearly identified and documented. For special category data, additional safeguards and explicit consent mechanisms may be required. The document must comply with Privacy and Electronic Communications Regulations (PECR) if electronic communications are involved. Data controllers remain fully liable for compliance even when using processors, making clear contractual obligations essential. The Information Commissioner's Office (ICO) expects detailed records of processing activities, and your addendum should facilitate this requirement. Penalties for non-compliance can reach £17.5 million or 4% of annual global turnover, making proper documentation crucial for regulatory protection.

GOVERNING LAW

Applicable law

This Data Protection Addendum is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: The UK General Data Protection Regulation - the primary data protection legislation in the UK post-Brexit, governing how personal data must be processed, stored and protected

DPA 2018: The Data Protection Act 2018 - the UK's implementation of data protection legislation that works alongside and supplements the UK GDPR

PECR: Privacy and Electronic Communications Regulations 2003 - specific rules governing electronic communications, including marketing, cookies, and privacy in telecommunications

EU GDPR: European Union General Data Protection Regulation - relevant for any data transfers between UK and EU, or when dealing with EU data subjects

International Transfer Mechanisms: Frameworks for transferring data internationally, including adequacy decisions, Standard Contractual Clauses (SCCs), and Binding Corporate Rules (BCRs)

NIS Regulations: Network and Information Systems Regulations 2018 - focusing on network and information systems security, particularly for essential services and digital service providers

Freedom of Information Act: Freedom of Information Act 2000 - relevant when dealing with public sector organizations and their data processing obligations

ICO Guidelines: Information Commissioner's Office guidelines and codes of practice - authoritative guidance on interpreting and implementing UK data protection laws

EDPB Guidelines: European Data Protection Board guidelines - relevant for understanding EU data protection requirements and best practices, particularly for cross-border processing

Industry-Specific Regulations: Sector-specific data protection requirements, including financial services regulations, healthcare data protection requirements, and marketing regulations

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

Ready to agree with confidence?
See Genie in action.