Information Security Agreement Template for England and Wales
Generate a bespoke document
What is a Information Security Agreement?
This Information Security Agreement is designed for use when organizations need to establish formal security protocols for handling sensitive information. It is particularly relevant in situations involving data sharing, third-party processing, or service provider relationships where confidential information needs protection. Governed by English and Welsh law, it incorporates requirements from UK data protection legislation, including UK GDPR and the Data Protection Act 2018, and establishes clear obligations for maintaining information security, managing incidents, and ensuring compliance with relevant standards.
Trusted by high-performance teams
About the Information Security Agreement
You need an Information Security Agreement when your organization handles sensitive data and requires formal security protocols with third parties. This legally binding contract establishes comprehensive security obligations, data protection compliance measures, and incident management procedures under England and Wales law. The agreement ensures all parties understand their responsibilities for protecting confidential information in accordance with UK data protection legislation.
When do you need this document?
You require this agreement when engaging service providers who will access your organization's sensitive data, such as cloud computing services, IT support contractors, or outsourced business processes. It's essential for data sharing partnerships between organizations, joint ventures involving confidential information exchange, and vendor relationships where third parties process personal data on your behalf. The agreement is particularly crucial for organizations subject to regulatory compliance requirements, including financial services, healthcare providers, and public sector entities. You also need this document when establishing formal security protocols with subsidiaries or affiliated companies that handle your data.
Key legal considerations
Your agreement must clearly define the scope of information covered, including personal data, commercially sensitive information, and intellectual property. Security obligations should specify technical and organizational measures required under UK GDPR, including encryption standards, access controls, and data retention policies. The contract must address roles and responsibilities for data controller and processor relationships, ensuring compliance with lawful processing requirements. Include detailed incident response procedures covering breach notification timelines, investigation responsibilities, and regulatory reporting obligations. Consider liability allocation for security failures, indemnification clauses, and termination procedures that ensure secure data return or destruction.
Legal requirements in England and Wales
Under UK GDPR and the Data Protection Act 2018, your agreement must include specific provisions for personal data processing, including lawful basis documentation and data subject rights procedures. The Privacy and Electronic Communications Regulations 2003 require additional safeguards for electronic communications and marketing data. Network and Information Systems Regulations 2018 impose cybersecurity requirements on essential service providers and digital service providers. Your contract should reference Computer Misuse Act 1990 protections against unauthorized access and specify compliance with sector-specific regulations such as PCI DSS for payment data. Include provisions for regulatory inspections, audit rights, and cooperation with Information Commissioner's Office investigations to ensure full legal compliance.
GOVERNING LAW
Applicable law
This Information Security Agreement is drafted to comply with England and Wales law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

