Controller To Controller Data Processing Agreement Template for Hong Kong
Generate a bespoke document
What is a Controller To Controller Data Processing Agreement?
The Controller To Controller Data Processing Agreement is essential when two organizations, both acting as data controllers under Hong Kong's Personal Data (Privacy) Ordinance, need to share personal data for specific business purposes. This document is particularly crucial in situations where regular data sharing occurs between independent organizations, each maintaining separate control over the processing of personal data. The agreement ensures compliance with Hong Kong's data protection requirements, including the six data protection principles under the PDPO and guidelines issued by the Privacy Commissioner for Personal Data. It establishes clear protocols for data security, breach notification, data subject rights, and liability allocation. The document should be used whenever two controllers engage in systematic or regular sharing of personal data, regardless of whether the sharing is reciprocal or one-way.
About the Controller To Controller Data Processing Agreement
When two organizations in Hong Kong both act as data controllers and need to share personal data, a Controller To Controller Data Processing Agreement becomes legally essential under the Personal Data (Privacy) Ordinance. This specialized agreement differs from standard data processing contracts because both parties maintain independent control over personal data, requiring careful coordination to ensure PDPO compliance while protecting data subject rights.
When do you need this document?
You need this agreement when your organization regularly shares personal data with another company where both entities act as independent data controllers. Common scenarios include joint marketing initiatives between retailers, data sharing between affiliated companies for customer service purposes, or collaborative research projects involving personal information. The agreement is particularly crucial when establishing ongoing business relationships that involve systematic data exchange, such as referral programs between professional services firms or data sharing arrangements between financial institutions for compliance purposes. Any situation where both organizations make independent decisions about data processing purposes and methods requires this specialized controller-to-controller framework.
Key legal considerations
Your agreement must clearly define each controller's responsibilities under the PDPO's six data protection principles, particularly regarding data accuracy, security safeguards, and purpose limitation. Include specific provisions for data subject access requests, ensuring both controllers can respond appropriately when individuals exercise their rights. Address cross-border data transfer requirements if either party processes data outside Hong Kong, incorporating adequate safeguards as outlined in PCPD guidance. Establish clear protocols for data breach notification, including timelines for informing the other controller and affected data subjects. Define liability allocation carefully, as both controllers remain independently responsible for PDPO compliance. Include termination clauses specifying data return or destruction procedures when the relationship ends.
Legal requirements in Hong Kong
Under Hong Kong's Personal Data (Privacy) Ordinance, both controllers must ensure the agreement complies with all six data protection principles, including lawful collection, accuracy requirements, and appropriate security measures. The Privacy Commissioner's guidance on data processor contracts provides specific requirements that apply to controller relationships, particularly regarding transparency and accountability measures. Your agreement must address the mandatory data protection impact assessment requirements for high-risk processing activities and ensure compliance with the PCPD's guidance on cross-border data transfers if applicable. Include provisions for regular compliance auditing and establish clear procedures for handling data subject complaints or regulatory inquiries. The agreement should also incorporate Hong Kong contract law principles to ensure enforceability and include dispute resolution mechanisms suitable for the local jurisdiction.
GOVERNING LAW
Applicable law
This Controller To Controller Data Processing Agreement is drafted to comply with Hong Kong law. Key legislation includes:
PCPD Guidance on Data Processor Contracts: Guidelines issued by the Privacy Commissioner providing specific requirements for contracts involving personal data transfers and processing
PCPD Guidance on Cross-border Data Transfers: Guidelines on the handling of personal data transfers outside of Hong Kong, including recommended contractual safeguards
Hong Kong Contract Law: General principles of contract law in Hong Kong that govern the formation and enforcement of contractual agreements
PCPD Data Protection Principles: Six key principles under the PDPO that must be adhered to when handling personal data, including purpose limitation, accuracy, retention, security, transparency, and access/correction rights
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it