Data Processing Agreement Addendum Template for Ireland
Generate a bespoke document
What is a Data Processing Agreement Addendum?
A Data Processing Agreement Addendum is essential when one organization (the processor) processes personal data on behalf of another organization (the controller) under Irish jurisdiction. This document supplements existing service agreements to ensure GDPR compliance and adherence to Irish data protection laws. It becomes necessary when the main service agreement doesn't adequately address data protection requirements or when circumstances change, such as new processing activities or regulatory updates. The addendum typically includes detailed provisions on processing scope, security measures, data breach procedures, and cross-border data transfers. It's particularly crucial for Irish-based companies or those processing data through Ireland, given its status as a key technology hub and its role in EU data protection enforcement.
About the Data Processing Agreement Addendum
A Data Processing Agreement Addendum is a critical legal document that governs how personal data is handled between organizations in Ireland. When you engage a service provider to process personal data on your behalf, this addendum ensures both parties comply with GDPR and Irish data protection laws. It supplements your main service contract by establishing clear responsibilities, security requirements, and procedures for lawful data processing.
When do you need this document?
You need this addendum whenever your organization acts as a data controller and engages another company to process personal data on your behalf. Common scenarios include hiring cloud service providers, payroll processors, marketing agencies, or IT support companies that will access employee or customer data. The addendum is also essential when expanding existing services to include new data processing activities, when transferring data outside the EEA, or when regulatory changes require updated compliance measures. Irish businesses particularly need this document when working with international service providers or when their processing activities involve sensitive personal data categories.
Key legal considerations
Your addendum must clearly define the scope and purpose of data processing, specifying exactly what data will be processed and for which legitimate purposes. Security measures are paramount - you must outline technical and organizational safeguards, including encryption, access controls, and staff training requirements. The document should establish clear procedures for data breach notification, ensuring compliance with GDPR's 72-hour reporting requirement. You'll also need provisions for data subject rights, allowing individuals to access, correct, or delete their personal data. When engaging sub-processors, the addendum must include approval mechanisms and ensure they meet the same protection standards. International data transfer clauses are crucial if data leaves the EEA, requiring Standard Contractual Clauses or adequacy decisions.
Legal requirements in Ireland
Under Irish law, your Data Processing Agreement Addendum must comply with both GDPR and the Data Protection Act 2018. The Irish Data Protection Commission requires specific provisions for controller-processor relationships, including clear allocation of responsibilities and liability. You must ensure your addendum addresses Ireland's national requirements for processing special categories of data, particularly for employment and health records. The document should reference appropriate legal bases for processing under Irish law and include provisions for cooperation with the Data Protection Commission during investigations. For electronic communications data, you must also comply with Irish e-Privacy regulations. Irish courts recognize these addenda as binding contracts, so ensure all terms are clearly defined and enforceable under Irish contract law.
GOVERNING LAW
Applicable law
This Data Processing Agreement Addendum is drafted to comply with Ireland law. Key legislation includes:
Data Protection Act 2018: Irish national law that implements GDPR and provides additional national requirements for data processing in Ireland
European Union (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011: Irish regulations implementing the EU e-Privacy Directive, relevant for electronic communications data processing
EU Standard Contractual Clauses (SCCs): Commission Implementing Decision (EU) 2021/914 - Required for international data transfers outside the EEA
European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011: Regulations governing privacy in electronic communications, relevant for data processing involving electronic communications
Criminal Justice (Mutual Assistance) Act 2008: Relevant for data processing agreements involving law enforcement cooperation and data sharing with foreign authorities
Data Protection Act 1988 and 2003: While largely superseded by GDPR and DPA 2018, these acts may still be relevant for historical context and certain continuing provisions
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it