Personal Data Agreement Template for Ireland
Generate a bespoke document
What is a Personal Data Agreement?
The Personal Data Agreement is essential for organizations operating under Irish jurisdiction that process personal data, either as controllers or processors. This document is required under Article 28 of the GDPR and the Irish Data Protection Act 2018 whenever one organization processes personal data on behalf of another. It sets out specific obligations regarding data security, confidentiality, sub-processing, and international transfers, while ensuring compliance with Irish and EU data protection requirements. The agreement is particularly crucial following the Schrems II decision and updated requirements for international data transfers. It should be implemented before any data processing activities commence and must reflect specific technical and organizational measures appropriate to the processing activities involved.
Trusted by high-performance teams
Frequently Asked Questions
Is a Personal Data Agreement legally required in Ireland under GDPR?
Yes, Personal Data Agreements are legally mandatory in Ireland under Article 28 of the GDPR and the Irish Data Protection Act 2018. Any organization that processes personal data on behalf of another entity (as a data processor) must have a written contract in place. Failure to have this agreement can result in significant fines up to 4% of annual turnover or €20 million.
Can the Data Protection Commission fine me for not having a Personal Data Agreement?
Yes, the Irish Data Protection Commission can impose substantial fines for operating without a proper Personal Data Agreement. Under GDPR Article 28, this is considered a serious compliance violation that can result in administrative fines up to €20 million or 4% of global annual turnover, whichever is higher. The DPC has actively pursued enforcement actions for missing or inadequate data processing agreements.
Does my Personal Data Agreement need to specify Irish law as governing law?
While GDPR applies directly across all EU member states, it's common practice to specify Irish law as the governing law in Personal Data Agreements when either party is based in Ireland. This provides clarity for dispute resolution and ensures compliance with the Irish Data Protection Act 2018. The agreement must also specify jurisdiction for resolving disputes, typically Irish courts.
How is a Personal Data Agreement different from a Data Sharing Agreement in Ireland?
A Personal Data Agreement is used when one party processes data on behalf of another (controller-processor relationship), while a Data Sharing Agreement is for when both parties act as independent data controllers. Personal Data Agreements have stricter requirements under GDPR Article 28, including specific processor obligations, data security measures, and deletion requirements that don't apply to data sharing between controllers.
How long does it typically take to finalize a Personal Data Agreement in Ireland?
A straightforward Personal Data Agreement typically takes 1-3 weeks to finalize, depending on the complexity of data processing activities and negotiation between parties. More complex agreements involving sensitive data, multiple sub-processors, or international transfers can take 4-8 weeks. Legal review and approval processes can add additional time to ensure full GDPR compliance.
Can I process personal data while my Personal Data Agreement is still being negotiated?
No, you cannot legally process personal data without a signed Personal Data Agreement in place under Irish and EU law. GDPR Article 28 requires the written contract to be executed before any processing begins. Starting data processing without this agreement exposes both parties to regulatory penalties from the Data Protection Commission and potential data subject complaints.
Why do most Personal Data Agreements in Ireland fail DPC compliance audits?
Common failures include missing mandatory GDPR clauses like data subject rights procedures, inadequate security measures specifications, unclear sub-processor approval processes, and missing data breach notification requirements. Many agreements also fail to specify data retention periods, cross-border transfer safeguards, or proper audit rights for data controllers, all of which are required under Irish data protection law.
About the Personal Data Agreement
A Personal Data Agreement is a legally binding contract that governs how organizations handle personal data when one party processes data on behalf of another. Under Irish law, this agreement is mandatory whenever you engage a service provider to process personal data, ensuring compliance with both the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
When do you need this document?
You need a Personal Data Agreement whenever your organization acts as a data controller and engages external service providers to process personal data on your behalf. This includes situations such as hiring cloud storage providers, outsourcing payroll services, using customer relationship management systems, or engaging marketing agencies that handle customer data. The agreement is also required when establishing joint controller relationships where multiple organizations share responsibility for data processing decisions. You must have this contract in place before any data processing begins, as operating without it constitutes a breach of GDPR requirements that can result in significant fines from the Irish Data Protection Commission.
Key legal considerations
Your Personal Data Agreement must include specific mandatory clauses required under Article 28 of the GDPR. These include detailed descriptions of the subject matter, duration, nature and purpose of processing, categories of personal data, and categories of data subjects. The agreement must specify your processor's obligations regarding data security measures, confidentiality requirements, and procedures for handling data subject requests. You must also address sub-processor arrangements, including requirements for prior written authorization and ensuring sub-processors meet the same data protection standards. The contract should establish clear procedures for data breach notification, with processors required to notify you without undue delay upon discovering any breach. Additionally, you must include provisions for returning or deleting personal data upon termination of the agreement and allow for audits to demonstrate compliance.
Legal requirements in Ireland
Under Irish law, your Personal Data Agreement must comply with both GDPR requirements and specific provisions in the Irish Data Protection Act 2018. The contract must address international data transfers if your processor operates outside the European Economic Area, ensuring adequate safeguards are in place following the Schrems II decision. You must specify the technical and organizational measures that processors will implement, which should be appropriate to the risk level of your processing activities. Irish law requires that processors only act on documented instructions from controllers, and your agreement must clearly define these instruction mechanisms. The contract should also designate contact points for data protection matters and specify the applicable Irish law for dispute resolution. Remember that the Irish Data Protection Commission has enforcement powers and can impose administrative fines up to €20 million or 4% of annual global turnover for non-compliance.
GOVERNING LAW
Applicable law
This Personal Data Agreement is drafted to comply with Ireland law. Key legislation includes:
Irish Data Protection Act 2018: The national legislation that supplements GDPR in Ireland, providing specific requirements and derogations allowed under GDPR, including rules on processing special categories of personal data.
European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011: Irish implementation of the ePrivacy Directive, governing electronic communications privacy, including rules on cookies and direct marketing.
Irish Contract Law: Common law principles governing contract formation, validity, and enforcement in Ireland, ensuring the agreement meets basic contractual requirements.
EU Standard Contractual Clauses (SCCs): European Commission's approved mechanisms for international data transfers, which may be relevant if the agreement involves data transfers outside the EEA.
Irish Data Protection Commission (DPC) Guidance: Regulatory guidance and decisions from the Irish Data Protection Commission, providing practical interpretation of data protection requirements.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

