Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Joint Controller Agreement
I need a Joint Controller Agreement for a partnership between a medical research institute and a university in Ireland, with special attention to handling sensitive health data and research findings, to be implemented by March 2025.
1. Parties: Identification of the joint controllers entering into the agreement
2. Background: Context of the relationship and purpose of the joint processing activities
3. Definitions: Key terms used in the agreement, including GDPR-specific terminology
4. Scope of Joint Processing: Detailed description of the personal data processing activities covered by the agreement
5. Allocation of Responsibilities: Clear division of data protection obligations between the joint controllers
6. Data Subject Rights: Procedures for handling data subject requests and designated points of contact
7. Transparency Requirements: Obligations regarding privacy notices and communication with data subjects
8. Security Measures: Technical and organizational measures required for data protection
9. Data Breach Notification: Procedures for handling and reporting personal data breaches
10. Liability and Indemnification: Distribution of liability between parties and indemnification provisions
11. Term and Termination: Duration of the agreement and termination provisions
12. General Provisions: Standard contractual clauses including governing law, jurisdiction, and amendments
1. International Data Transfers: Required if personal data will be transferred outside the EEA
2. Special Categories of Data: Required if processing sensitive personal data under Article 9 GDPR
3. Sub-processing: Required if either controller will engage sub-processors
4. Joint Marketing Activities: Required if controllers collaborate on marketing initiatives
5. Industry-Specific Compliance: Required for regulated industries (e.g., healthcare, financial services)
6. Data Protection Impact Assessment: Required for high-risk processing activities
7. Audit Rights: Optional section detailing mutual audit rights and procedures
1. Schedule 1 - Processing Activities: Detailed description of joint processing activities, including categories of data and purposes
2. Schedule 2 - Technical and Organizational Measures: Specific security measures implemented by each controller
3. Schedule 3 - Data Subject Rights Procedure: Detailed procedures for handling data subject requests
4. Schedule 4 - Data Breach Response Plan: Step-by-step protocol for managing data breaches
5. Schedule 5 - Contact Details: Key contacts for each controller, including DPO details if applicable
6. Appendix A - Privacy Notice Template: Template for joint privacy notice to data subjects
7. Appendix B - Data Transfer Mechanisms: Details of any international transfer mechanisms if applicable
Authors
Applicable Data Protection Law
Authorised Recipients
Business Day
Confidential Information
Controller
Data Protection Impact Assessment
Data Protection Officer
Data Subject
Data Subject Rights
DPC
EEA
Effective Date
EU
GDPR
Group Company
Irish Data Protection Act
Joint Controllers
Joint Processing Activities
Material Breach
Personal Data
Personal Data Breach
Processing
Processor
Professional Advisers
Relevant Personnel
Representatives
Security Measures
Special Categories of Personal Data
Sub-processor
Supervisory Authority
Technical and Organisational Measures
Term
Third Party
Transfer Mechanisms
Scope
Joint Controller Obligations
Data Protection
Data Subject Rights
Security
Confidentiality
Audit Rights
Data Breach
Liability
Indemnification
International Transfer
Sub-processing
Term and Termination
Force Majeure
Assignment
Notices
Severability
Entire Agreement
Governing Law
Dispute Resolution
Variation
Cooperation
Costs
Third Party Rights
Records and Audit
Transparency
Risk Assessment
Insurance
Exit Management
Financial Services
Healthcare
Technology
E-commerce
Education
Marketing and Advertising
Research and Development
Insurance
Telecommunications
Professional Services
Real Estate
Retail
Travel and Hospitality
Legal
Compliance
Information Security
Data Protection
Risk Management
Information Technology
Operations
Privacy
Governance
Commercial
Data Governance
Data Protection Officer
Privacy Manager
Legal Counsel
Compliance Officer
Information Security Manager
Risk Manager
Chief Privacy Officer
Chief Information Security Officer
Chief Technology Officer
Chief Legal Officer
Operations Director
Project Manager
Commercial Director
Head of Compliance
Head of Data Governance
Find the exact document you need
Gdpr Intercompany Agreement
Irish law-governed GDPR Intercompany Agreement for regulating personal data transfers and processing between group companies under Irish and EU data protection requirements.
Sub Processor Agreement
An Irish law-governed agreement establishing terms for delegated data processing activities between a processor and sub-processor, ensuring GDPR compliance.
Data Processing Agreement Addendum
An Irish law-governed addendum establishing GDPR-compliant terms for data processing activities between controllers and processors.
Third Party Processing Agreement
An Irish law-governed agreement establishing terms for third-party processing of personal data in compliance with GDPR and local data protection requirements.
Data Processing Contract
An Irish law-governed agreement establishing terms for personal data processing activities between a Data Controller and Data Processor, ensuring GDPR compliance.
Joint Controller Agreement
An Irish law-governed agreement establishing responsibilities between joint controllers under GDPR and Irish data protection law.
Data Processing Addendum
An Irish law-governed Data Processing Addendum that establishes GDPR-compliant terms for personal data processing between controllers and processors.
Data Addendum
An Irish law-governed Data Addendum establishing GDPR-compliant data processing terms between controllers and processors.
Controller To Controller Agreement GDPR
Irish law Controller to Controller Agreement establishing GDPR-compliant data sharing framework between independent data controllers.
Data Sharing Agreement Controller To Processor
An Irish law-governed agreement establishing terms for personal data processing between a Controller and Processor, ensuring GDPR compliance.
Third Party Data Processing Agreement
An Irish law-governed Data Processing Agreement establishing GDPR-compliant terms between a data controller and processor.
Data Transfer Addendum
An Irish law-governed addendum that establishes compliant mechanisms for international personal data transfers under GDPR and Irish data protection laws.
Controller Processor Agreement
An Irish law-governed agreement establishing terms for processing personal data under GDPR, between a data controller and processor.
Order Processing Agreement
An Irish law-governed agreement establishing terms for order processing services, ensuring GDPR compliance and data protection requirements.
Data Protection Agreement For Employees
An Irish law-governed agreement establishing data protection protocols between employer and employee, ensuring GDPR compliance and proper handling of employee personal data.
Sub Processing Agreement
An Irish law-governed agreement between a data processor and sub-processor establishing terms for personal data processing in compliance with GDPR and Irish data protection legislation.
International Data Transfer Agreement
Irish law-governed agreement for compliant transfer of personal data from Ireland/EU to non-EEA countries, ensuring GDPR and local law compliance.
Data Transfer Agreement
An Irish law-governed agreement establishing terms for compliant transfer of personal data between organizations under GDPR and Irish data protection legislation.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.