Joint Controller Data Processing Agreement Template for Hong Kong

Generate a bespoke document

What is a Joint Controller Data Processing Agreement?

This Joint Controller Data Processing Agreement is essential when two or more organizations jointly determine how and why personal data is processed in Hong Kong. It's specifically required when multiple parties share decision-making authority over data processing activities and must comply with Hong Kong's Personal Data (Privacy) Ordinance (PDPO). The agreement should be used when organizations collaborate on projects involving shared data responsibilities, such as joint ventures, shared services arrangements, or collaborative research projects. It details the allocation of responsibilities, compliance obligations, security requirements, and liability arrangements between the joint controllers. The document ensures clear accountability and transparency in data protection practices while meeting Hong Kong's regulatory requirements and international data protection standards.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Hong Kong

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Joint Controller Data Processing Agreement

When your organization collaborates with other entities to process personal data in Hong Kong, you need a Joint Controller Data Processing Agreement to ensure compliance with the Personal Data (Privacy) Ordinance (PDPO). This legal document establishes the framework for shared data processing responsibilities and protects all parties from regulatory violations while maintaining transparent data protection practices.

When do you need this document?

You require this agreement whenever two or more organizations jointly determine how and why personal data is processed. Common scenarios include joint ventures where partners share customer databases, collaborative research projects involving participant data, shared services arrangements between affiliated companies, and marketing partnerships that involve data exchange. The agreement is also essential when organizations co-develop products or services that require shared access to personal data, or when multiple entities provide integrated services to the same data subjects. Without this agreement, you risk unclear accountability, regulatory non-compliance, and potential disputes over data protection responsibilities.

Key legal considerations

Your agreement must clearly define each controller's specific roles, responsibilities, and decision-making authority over the shared data processing activities. Include detailed provisions for data security measures, breach notification procedures, and individual rights fulfillment processes. Address liability allocation between joint controllers, ensuring fair distribution of potential penalties or compensation obligations. The document should establish clear communication protocols for regulatory interactions and specify which controller will serve as the primary contact point with Hong Kong's Privacy Commissioner. Additionally, include termination clauses that address data deletion, return, or continued processing rights when the joint controller relationship ends.

Legal requirements in Hong Kong

Under the PDPO, your agreement must ensure compliance with all six Data Protection Principles, particularly regarding lawful and fair collection, accuracy, and security safeguards. The document must address cross-border data transfer requirements if either controller operates outside Hong Kong, incorporating appropriate safeguards as outlined in PCPD guidance. Include provisions for data subject rights fulfillment, specifying how individuals can access, correct, or request deletion of their personal data from either controller. The agreement should also establish data breach handling procedures that comply with PCPD guidelines, including notification timelines and responsibility allocation. Ensure your document addresses data retention periods, processing limitations, and consent management where applicable under Hong Kong law.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

Ready to agree with confidence?
See Genie in action.