Third Party Access Agreement Template for England and Wales
Generate a bespoke document
What is a Third Party Access Agreement?
A third-party access agreement is a document used in England and Wales to formally authorise a person or organisation that is not a party to the main property or system arrangement to enter, use, or interact with it for a defined purpose. It clarifies the scope of access, allocates liability between the parties, and sets out any conditions or restrictions. It is used in property, construction, IT, and commercial contexts to manage risk and ensure clarity about authorised access.
About the Third Party Access Agreement
A Third Party Access Agreement is a legally binding contract that governs when and how external organizations or individuals can access your company's systems, data, or physical facilities. Under United States federal law, these agreements are essential for maintaining compliance with cybersecurity regulations and protecting your business from unauthorized access risks. You need this document whenever granting access to vendors, contractors, partners, or service providers who require entry to your protected resources.
When do you need this document?
You need a Third Party Access Agreement whenever external parties require access to your organization's sensitive systems or data. Common scenarios include hiring IT consultants who need network access, partnering with cloud service providers for data processing, allowing vendors to access customer information for support purposes, or permitting auditors to review financial systems. Healthcare organizations must use these agreements when sharing patient data with third-party processors, while financial institutions need them for any external access to customer financial information. The agreement is also crucial when allowing remote workers from partner companies to access your systems or when engaging with cybersecurity firms for penetration testing.
Key legal considerations
Your agreement must clearly define the scope of access, specifying exactly which systems, data types, or facilities the third party can access and for what duration. Security requirements are critical and should mandate encryption, access controls, monitoring protocols, and incident response procedures that align with your organization's security standards. Confidentiality obligations must be comprehensive, covering how the third party handles, stores, and ultimately destroys or returns your data. Include specific liability provisions that address data breaches, unauthorized access, and violations of the agreement terms. The contract should also establish audit rights, allowing you to monitor the third party's compliance with security requirements and access restrictions.
Legal requirements in United States
Under United States federal law, your Third Party Access Agreement must comply with the Computer Fraud and Abuse Act (CFAA), which prohibits unauthorized computer access and requires explicit authorization for all system access. If your organization handles healthcare data, the agreement must include HIPAA-compliant Business Associate provisions that govern how protected health information is accessed, used, and safeguarded. Financial institutions must ensure compliance with the Gramm-Leach-Bliley Act (GLBA) when granting access to customer financial data, including specific privacy and security safeguards. The Electronic Communications Privacy Act (ECPA) governs monitoring and interception of electronic communications, so your agreement must address any monitoring of third-party access. Additionally, organizations subject to FISMA requirements must ensure third-party access agreements meet federal information security management standards, including proper risk assessments and security controls.
GOVERNING LAW
Applicable law
This Third Party Access Agreement is drafted to comply with England and Wales law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it