Information Security Agreement Template for England and Wales

Generate a bespoke document

What is a Information Security Agreement?

This Information Security Agreement is designed for use when organizations need to establish formal security protocols for handling sensitive information. It is particularly relevant in situations involving data sharing, third-party processing, or service provider relationships where confidential information needs protection. Governed by English and Welsh law, it incorporates requirements from UK data protection legislation, including UK GDPR and the Data Protection Act 2018, and establishes clear obligations for maintaining information security, managing incidents, and ensuring compliance with relevant standards.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Information Security Agreement

You need an Information Security Agreement when your organization handles sensitive data and requires formal security protocols with third parties. This legally binding contract establishes comprehensive security obligations, data protection compliance measures, and incident management procedures under England and Wales law. The agreement ensures all parties understand their responsibilities for protecting confidential information in accordance with UK data protection legislation.

When do you need this document?

You require this agreement when engaging service providers who will access your organization's sensitive data, such as cloud computing services, IT support contractors, or outsourced business processes. It's essential for data sharing partnerships between organizations, joint ventures involving confidential information exchange, and vendor relationships where third parties process personal data on your behalf. The agreement is particularly crucial for organizations subject to regulatory compliance requirements, including financial services, healthcare providers, and public sector entities. You also need this document when establishing formal security protocols with subsidiaries or affiliated companies that handle your data.

Key legal considerations

Your agreement must clearly define the scope of information covered, including personal data, commercially sensitive information, and intellectual property. Security obligations should specify technical and organizational measures required under UK GDPR, including encryption standards, access controls, and data retention policies. The contract must address roles and responsibilities for data controller and processor relationships, ensuring compliance with lawful processing requirements. Include detailed incident response procedures covering breach notification timelines, investigation responsibilities, and regulatory reporting obligations. Consider liability allocation for security failures, indemnification clauses, and termination procedures that ensure secure data return or destruction.

Legal requirements in England and Wales

Under UK GDPR and the Data Protection Act 2018, your agreement must include specific provisions for personal data processing, including lawful basis documentation and data subject rights procedures. The Privacy and Electronic Communications Regulations 2003 require additional safeguards for electronic communications and marketing data. Network and Information Systems Regulations 2018 impose cybersecurity requirements on essential service providers and digital service providers. Your contract should reference Computer Misuse Act 1990 protections against unauthorized access and specify compliance with sector-specific regulations such as PCI DSS for payment data. Include provisions for regulatory inspections, audit rights, and cooperation with Information Commissioner's Office investigations to ensure full legal compliance.

GOVERNING LAW

Applicable law

This Information Security Agreement is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: The UK General Data Protection Regulation - Primary legislation governing personal data processing and protection in the UK post-Brexit

Data Protection Act 2018: The UK's implementation of data protection legislation, working alongside UK GDPR to regulate personal data processing

PECR 2003: Privacy and Electronic Communications Regulations - Specific rules for electronic communications, marketing, and cookies

NIS Regulations 2018: Network and Information Systems Regulations - Framework for cybersecurity requirements for essential services and digital providers

Computer Misuse Act 1990: Legislation criminalizing unauthorized access to computer systems and data interference

RIPA 2000: Regulation of Investigatory Powers Act - Governs the interception of communications and use of surveillance

Trade Secrets Regulations 2018: Regulations providing legal framework for protection of trade secrets and confidential business information

Common Law Confidentiality: Common law principles protecting confidential information and trade secrets

UK Data Transfer Regulations: Regulations governing international data transfers and adequacy decisions post-Brexit

Employment Rights Act 1996: Legislation covering employee rights including aspects of data handling in employment context

Equality Act 2010: Legislation protecting against discrimination, including in data processing contexts

Consumer Rights Act 2015: Framework for consumer protection including digital content and services

E-Commerce Regulations 2002: Electronic Commerce Regulations governing online business activities and information security requirements

ISO 27001: International standard for information security management systems

PCI DSS: Payment Card Industry Data Security Standard - Requirements for organizations handling credit card information

Cyber Essentials: UK government-backed scheme providing baseline cybersecurity standards and certification

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it