Data Sharing Agreement Controller To Processor Template for England and Wales

Generate a bespoke document

What is a Data Sharing Agreement Controller To Processor?

This Data Sharing Agreement Controller To Processor is designed for use when an organization (the controller) needs to engage another organization (the processor) to process personal data on its behalf. The agreement is essential for compliance with UK data protection laws, particularly the UK GDPR and Data Protection Act 2018. It should be used whenever there is a controller-processor relationship involving personal data processing in England and Wales. The document covers essential elements including security measures, data breach procedures, processor obligations, and data handling requirements.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Sharing Agreement Controller To Processor

When your organization needs to engage a third-party service provider to handle personal data on your behalf, you need a Data Sharing Agreement Controller To Processor. This legal document establishes the framework for lawful data processing relationships under England and Wales law, ensuring compliance with UK data protection regulations while protecting both parties' interests.

When do you need this document?

You need this agreement whenever you engage external organizations to process personal data as part of your business operations. This includes situations where you hire cloud storage providers to store customer information, engage marketing agencies to process customer databases, or contract IT support companies to maintain systems containing personal data. The agreement is also essential when outsourcing payroll processing, customer service operations, or any function involving access to personal information. Under UK GDPR, any controller-processor relationship requires a written contract that meets specific legal requirements.

Key legal considerations

The agreement must address critical obligations under Article 28 of UK GDPR, including ensuring the processor only processes data on documented instructions from you as the controller. You need robust security measures clauses that comply with Article 32 requirements, covering both technical and organizational safeguards. The document should clearly define data breach notification procedures, establishing timeframes for the processor to inform you of any security incidents. Include provisions for data subject rights, ensuring the processor assists you in responding to access requests, deletion demands, and other individual rights. The agreement must also address international data transfers if the processor operates outside the UK, ensuring adequate safeguards are in place. Consider including audit rights, allowing you to assess the processor's compliance with data protection obligations.

Legal requirements in England and Wales

Under England and Wales law, your agreement must comply with UK GDPR and the Data Protection Act 2018, which govern all aspects of the controller-processor relationship. The processor must implement appropriate technical and organizational measures to ensure data security, as required by Article 32 of UK GDPR. You must ensure the agreement covers processing of special category data if applicable, following Schedule 1 of the Data Protection Act 2018. The document should address retention periods and data deletion requirements, ensuring compliance with data minimization principles. If electronic communications are involved, consider Privacy and Electronic Communications Regulations 2003 requirements. The agreement must also respect common law duties of confidentiality that apply under English and Welsh legal principles. Ensure the contract allows for regulatory cooperation with the Information Commissioner's Office and includes provisions for handling regulatory investigations or enforcement actions.

GOVERNING LAW

Applicable law

This Data Sharing Agreement Controller To Processor is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: UK General Data Protection Regulation - Primary legislation governing data protection in the UK post-Brexit, setting out fundamental principles for data processing, including specific requirements for controller-processor relationships under Article 28 and security measures under Article 32

DPA 2018: Data Protection Act 2018 - The UK's implementation of data protection legislation, including specific provisions for special category data processing under Schedule 1

PECR: Privacy and Electronic Communications Regulations 2003 - Specific rules for privacy and electronic communications, complementing general data protection laws

Common Law Duty of Confidentiality: Legal principle under English and Welsh common law requiring maintenance of confidentiality where information is shared in circumstances implying an obligation of confidence

English and Welsh Contract Law: General principles of contract law that govern the formation and enforcement of agreements under the jurisdiction of England and Wales

Freedom of Information Act 2000: Legislation governing public access to information held by public authorities, relevant when public sector bodies are involved in data sharing

ICO Controller-Processor Guidance: Regulatory guidance from the Information Commissioner's Office specifically addressing requirements and best practices for controller-processor relationships

ICO Data Sharing Guidance: Regulatory guidance from the Information Commissioner's Office on best practices and requirements for data sharing agreements

EDPB Guidelines: European Data Protection Board guidelines which, while not binding post-Brexit, remain influential in UK data protection practice and interpretation

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

Ready to agree with confidence?
See Genie in action.