Controller Processor Agreement Template for Ireland
Generate a bespoke document
What is a Controller Processor Agreement?
The Controller Processor Agreement is essential when an organization (the controller) engages another party (the processor) to process personal data on its behalf. This document is required under Article 28 of the GDPR and must comply with Irish law, including the Data Protection Act 2018. It sets out the processor's obligations regarding data security, confidentiality, sub-processing, and assistance with data subject requests. The agreement includes specific provisions required by Irish regulators and the Irish Data Protection Commission, making it suitable for organizations operating under Irish jurisdiction. It typically contains detailed schedules outlining the nature of processing activities, security measures, and approved sub-processors, ensuring comprehensive coverage of all GDPR compliance requirements.
Trusted by high-performance teams
About the Controller Processor Agreement
When your organization outsources data processing activities to third-party service providers in Ireland, a Controller Processor Agreement becomes legally mandatory under the General Data Protection Regulation (GDPR). This essential contract establishes clear responsibilities between data controllers and processors, ensuring compliance with Irish data protection laws while protecting both parties from regulatory penalties and privacy breaches.
When do you need this document?
You need a Controller Processor Agreement whenever you engage external service providers to handle personal data on your behalf. Common scenarios include hiring cloud storage providers, payroll companies, marketing agencies, IT support services, or customer service outsourcing firms. Under Article 28 of the GDPR and the Irish Data Protection Act 2018, this agreement is mandatory before any processing begins. The Irish Data Protection Commission actively enforces these requirements, making proper documentation critical for compliance audits and regulatory inspections.
Key legal considerations
Your Controller Processor Agreement must include specific GDPR-mandated clauses covering the processor's obligations, data security measures, sub-processor arrangements, and data subject rights assistance. The contract should clearly define the scope and purpose of processing, specify technical and organizational security measures, and establish procedures for data breaches, deletion requests, and regulatory cooperation. You must ensure the processor provides sufficient guarantees of GDPR compliance and agrees to process data only on your documented instructions. The agreement should also address liability allocation, indemnification provisions, and termination procedures, including secure data return or destruction requirements.
Legal requirements in Ireland
Under Irish law, your Controller Processor Agreement must comply with both the GDPR and the Data Protection Act 2018, which provides specific national implementation requirements. The Irish Data Protection Commission requires detailed documentation of processing activities, including data categories, processing purposes, retention periods, and international transfer safeguards. Your agreement must specify the processor's location, any cross-border data transfers, and compliance with Irish ePrivacy Regulations where applicable. The contract should include provisions for Irish Data Protection Commission inspections and must be available in English for regulatory review. Additionally, you must maintain records demonstrating the processor's compliance with Irish security standards and data protection principles, with specific attention to children's data if applicable under Irish national provisions.
GOVERNING LAW
Applicable law
This Controller Processor Agreement is drafted to comply with Ireland law. Key legislation includes:
Data Protection Act 2018 (Ireland): The main Irish legislation that supplements GDPR and provides for national implementation of data protection requirements in Ireland.
Irish Contract Law: General principles of Irish contract law that govern the formation and enforcement of contracts in Ireland.
ePrivacy Regulations 2011 (S.I. No. 336/2011): Irish regulations implementing the EU ePrivacy Directive, relevant for electronic communications and data processing.
Law Enforcement Directive (LED): EU Directive 2016/680 as implemented in Ireland, relevant if the processing involves law enforcement purposes.
Irish Data Protection Commission Guidelines: While not legislation, these are authoritative guidelines from the Irish DPC that provide practical guidance on compliance with data protection laws.
European Data Protection Board Guidelines: Guidelines and recommendations from the EDPB that provide authoritative interpretation of GDPR requirements for controller-processor relationships.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

