Joint Controller Data Processing Agreement Template for Hong Kong
Generate a bespoke document
What is a Joint Controller Data Processing Agreement?
This Joint Controller Data Processing Agreement is essential when two or more organizations jointly determine how and why personal data is processed in Hong Kong. It's specifically required when multiple parties share decision-making authority over data processing activities and must comply with Hong Kong's Personal Data (Privacy) Ordinance (PDPO). The agreement should be used when organizations collaborate on projects involving shared data responsibilities, such as joint ventures, shared services arrangements, or collaborative research projects. It details the allocation of responsibilities, compliance obligations, security requirements, and liability arrangements between the joint controllers. The document ensures clear accountability and transparency in data protection practices while meeting Hong Kong's regulatory requirements and international data protection standards.
Trusted by high-performance teams
About the Joint Controller Data Processing Agreement
When your organization collaborates with other entities to process personal data in Hong Kong, you need a Joint Controller Data Processing Agreement to ensure compliance with the Personal Data (Privacy) Ordinance (PDPO). This legal document establishes the framework for shared data processing responsibilities and protects all parties from regulatory violations while maintaining transparent data protection practices.
When do you need this document?
You require this agreement whenever two or more organizations jointly determine how and why personal data is processed. Common scenarios include joint ventures where partners share customer databases, collaborative research projects involving participant data, shared services arrangements between affiliated companies, and marketing partnerships that involve data exchange. The agreement is also essential when organizations co-develop products or services that require shared access to personal data, or when multiple entities provide integrated services to the same data subjects. Without this agreement, you risk unclear accountability, regulatory non-compliance, and potential disputes over data protection responsibilities.
Key legal considerations
Your agreement must clearly define each controller's specific roles, responsibilities, and decision-making authority over the shared data processing activities. Include detailed provisions for data security measures, breach notification procedures, and individual rights fulfillment processes. Address liability allocation between joint controllers, ensuring fair distribution of potential penalties or compensation obligations. The document should establish clear communication protocols for regulatory interactions and specify which controller will serve as the primary contact point with Hong Kong's Privacy Commissioner. Additionally, include termination clauses that address data deletion, return, or continued processing rights when the joint controller relationship ends.
Legal requirements in Hong Kong
Under the PDPO, your agreement must ensure compliance with all six Data Protection Principles, particularly regarding lawful and fair collection, accuracy, and security safeguards. The document must address cross-border data transfer requirements if either controller operates outside Hong Kong, incorporating appropriate safeguards as outlined in PCPD guidance. Include provisions for data subject rights fulfillment, specifying how individuals can access, correct, or request deletion of their personal data from either controller. The agreement should also establish data breach handling procedures that comply with PCPD guidelines, including notification timelines and responsibility allocation. Ensure your document addresses data retention periods, processing limitations, and consent management where applicable under Hong Kong law.
GOVERNING LAW
Applicable law
This Joint Controller Data Processing Agreement is drafted to comply with Hong Kong law. Key legislation includes:
PCPD Guidance on Data Processor Contracts: Guidelines issued by Hong Kong's Privacy Commissioner providing specific requirements for contracts with data processors
Data Protection Principles (DPPs) under PDPO: Six fundamental principles under the PDPO that govern the collection, handling, and use of personal data in Hong Kong
PCPD Guidance on Cross-border Data Transfers: Guidelines regarding international data transfers, relevant if the joint controllers operate across different jurisdictions
PCPD Guidance on Data Breach Handling: Guidelines on handling and reporting data breaches, essential for defining responsibilities between joint controllers
Electronic Transactions Ordinance (Cap. 553): Relevant for electronic execution and record-keeping requirements if the agreement is executed electronically
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

