Data Processing Addendum Template for Ireland
Generate a bespoke document
What is a Data Processing Addendum?
A Data Processing Addendum is essential whenever an organization (the controller) engages another party (the processor) to process personal data on its behalf. This document, governed by Irish law, serves as a critical compliance tool for ensuring adherence to both EU GDPR and Irish data protection requirements. It should be used as an addendum to main service agreements where personal data processing is involved, whether for cloud services, outsourcing, or any other data processing activities. The DPA includes mandatory provisions required by Article 28 GDPR, Irish-specific requirements, and practical operational procedures for managing the data processing relationship. It covers crucial aspects such as security measures, breach notification procedures, audit rights, and data transfer mechanisms, while incorporating specific requirements from the Irish Data Protection Commission's guidance and the Data Protection Act 2018.
About the Data Processing Addendum
A Data Processing Addendum (DPA) is a legally binding contract that governs how personal data is processed when you engage a third-party service provider. Under Irish law and GDPR, this document is mandatory whenever you act as a data controller and engage another organization as a data processor to handle personal data on your behalf.
When do you need this document?
You need a Data Processing Addendum whenever you outsource any activity involving personal data processing. This includes engaging cloud service providers, IT support companies, payroll processors, marketing agencies, or any vendor that will access, store, or process personal data for your organization. The document is also required when sub-processors are involved in the data processing chain. Irish businesses must ensure all data processing relationships are governed by compliant DPAs before any personal data is shared or processed by external parties.
Key legal considerations
Your DPA must comply with Article 28 GDPR requirements, including specific mandatory clauses covering processing instructions, security measures, and data subject rights. The agreement must clearly define the scope of processing activities, categories of personal data involved, and retention periods. Critical provisions include technical and organizational security measures, breach notification procedures within 72 hours, audit rights, and deletion obligations upon contract termination. You must ensure the processor provides sufficient guarantees regarding security measures and only processes data according to your documented instructions. The DPA should also address liability allocation, insurance requirements, and dispute resolution mechanisms under Irish jurisdiction.
Legal requirements in Ireland
Under the Irish Data Protection Act 2018 and European Union (General Data Protection Regulation) Regulations 2018, your DPA must incorporate specific Irish regulatory requirements. The document must reference the Irish Data Protection Commission as the lead supervisory authority and include provisions for regulatory cooperation. For international data transfers, you must incorporate EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) and conduct transfer impact assessments. Irish-specific considerations include provisions for processing special categories of personal data, criminal conviction data, and compliance with sectoral regulations. The DPA must also address data localization requirements where applicable and ensure compatibility with Irish employment law when processing employee data. Regular review and updates are essential to maintain compliance with evolving Irish DPC guidance and regulatory interpretations.
GOVERNING LAW
Applicable law
This Data Processing Addendum is drafted to comply with Ireland law. Key legislation includes:
Data Protection Act 2018: Irish national law that implements GDPR and provides additional data protection requirements specific to Ireland, including rules for processing special categories of personal data
European Union (General Data Protection Regulation) Regulations 2018: Irish statutory instrument (S.I. No. 174/2018) providing additional rules and procedures for implementing GDPR in Ireland
EU Standard Contractual Clauses (SCCs): Commission Implementing Decision (EU) 2021/914 - Required for international data transfers outside the EEA, must be incorporated if the DPA involves cross-border data flows
ePrivacy Regulations 2011: Irish regulations (S.I. No. 336/2011) implementing the EU ePrivacy Directive, relevant for electronic communications data and cookies
Data Protection Act (Section 36(2)) (Health Research) Regulations 2018: Specific regulations governing data processing in health research contexts, relevant if the DPA involves health data processing
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it