Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Personal Data Collection Agreement
"I need a Personal Data Collection Agreement for my healthcare technology startup in Mumbai that will collect patient health data through our mobile app, with special emphasis on medical data protection and parental consent for minor patients."
1. Parties: Identification of the Data Controller/Fiduciary (collecting entity) and the Data Subject (individual whose data is being collected)
2. Background: Context of the data collection relationship and purpose of the agreement
3. Definitions: Key terms used in the agreement, including types of personal data, processing activities, and technical terms
4. Purpose of Data Collection: Specific purposes for which personal data will be collected and processed
5. Types of Personal Data: Detailed categorization of personal data to be collected, including sensitive personal data if applicable
6. Consent and Authorization: Express consent clauses and authorization for data collection and processing
7. Data Processing Activities: Description of how the collected data will be processed, stored, and used
8. Data Subject Rights: Rights of the data subject including access, correction, deletion, and data portability
9. Data Security Measures: Security protocols and measures implemented to protect personal data
10. Data Retention Period: Duration for which data will be stored and criteria for determination
11. Data Sharing and Transfer: Conditions under which data may be shared with third parties or transferred internationally
12. Breach Notification: Procedures for handling and notifying data breaches
13. Termination: Conditions for termination and consequences for collected data
14. Governing Law and Jurisdiction: Applicable laws and jurisdiction for dispute resolution
1. International Data Transfers: Required when personal data may be transferred outside India, specifying compliance with cross-border data transfer requirements
2. Special Categories of Data: Required when collecting sensitive personal data such as health information, biometric data, or financial information
3. Children's Data Protection: Required when collecting data from minors, including parental consent requirements
4. Automated Decision Making: Required when using automated processing or profiling systems
5. Data Protection Impact Assessment: Required for high-risk processing activities
6. Grievance Resolution: Detailed procedure for handling data subject complaints and disputes
7. Insurance and Indemnification: Required when specific insurance coverage or indemnification for data incidents is needed
1. Schedule A - Categories of Personal Data: Detailed list of all personal data categories to be collected
2. Schedule B - Technical and Organizational Security Measures: Specific security measures and protocols implemented for data protection
3. Schedule C - Data Processing Activities: Detailed description of all processing activities and purposes
4. Schedule D - Authorized Third-Party Processors: List of approved third-party data processors and their roles
5. Appendix 1 - Consent Forms: Standard consent forms and opt-in/opt-out mechanisms
6. Appendix 2 - Data Subject Rights Request Forms: Templates for various data subject rights requests
7. Appendix 3 - Data Breach Response Plan: Detailed procedures for handling data breaches and incident response
8. Appendix 4 - Privacy Notices: Detailed privacy notices and information to be provided to data subjects
Authors
Biometric Data
Consent
Cross-border Transfer
Data Breach
Data Controller
Data Fiduciary
Data Principal
Data Processor
Data Protection Officer
Data Subject
Encrypted Data
Financial Data
Grievance Officer
Health Data
Information Technology Rules
Notice
Personal Data
Processing
Profiling
Pseudonymisation
Reasonable Security Practices
Sensitive Personal Data
Special Categories of Data
Storage
Technical Measures
Third Party
Third Party Processor
Transfer
Unauthorized Access
Valid Consent
Child
Guardian
Privacy Notice
Data Protection Impact Assessment
Organizational Measures
Data Retention Period
Data Subject Rights
Supervisory Authority
Applicable Law
Consent
Data Collection
Data Processing
Data Security
Confidentiality
Data Subject Rights
Cross-border Transfer
Third Party Processing
Breach Notification
Liability
Indemnification
Termination
Force Majeure
Severability
Entire Agreement
Amendment
Assignment
Notice
Governing Law
Jurisdiction
Dispute Resolution
Representation and Warranties
Compliance
Audit Rights
Data Retention
Data Deletion
Security Measures
Privacy Notice
Children's Data Protection
Automated Processing
Data Protection Impact Assessment
Record Keeping
Insurance
Remedies
Healthcare
Financial Services
Technology
E-commerce
Education
Telecommunications
Insurance
Retail
Professional Services
Human Resources
Marketing and Advertising
Travel and Hospitality
Real Estate
Manufacturing
Government and Public Sector
Legal
Compliance
Information Technology
Information Security
Privacy
Risk Management
Human Resources
Marketing
Customer Service
Operations
Data Analytics
Systems Administration
Internal Audit
Corporate Governance
Data Protection Officer
Privacy Officer
Legal Counsel
Compliance Manager
Information Security Manager
Risk Manager
IT Director
Chief Technology Officer
Chief Information Officer
Chief Privacy Officer
General Counsel
Operations Manager
HR Manager
Marketing Manager
Customer Service Manager
Data Analytics Manager
Systems Administrator
Database Administrator
Privacy Analyst
Compliance Officer
Find the exact document you need
Third Party Processing Agreement
An Indian law-governed agreement establishing terms for third-party processing of personal and sensitive data, ensuring compliance with IT Act and Rules.
Controller To Controller Agreement
An Indian law-governed agreement establishing terms for personal data sharing between independent data controllers, ensuring compliance with DPDP Act 2023.
Product Development Non Disclosure Agreement
An Indian law-compliant Non-Disclosure Agreement for protecting confidential information during product development activities and collaborations.
Joint Controller Data Processing Agreement
An Indian law-compliant agreement establishing roles and responsibilities between joint controllers for personal data processing activities.
Standard Data Processing Agreement
Indian-law compliant Data Processing Agreement governing the processing of personal data between controllers and processors, aligned with IT Act and DPDP Act requirements.
Dpia Agreement
An Indian law-governed agreement documenting the systematic assessment of data processing risks and protection measures under the Digital Personal Data Protection Act 2023.
Data Agreement
An Indian law-governed Data Agreement establishing terms for data sharing and processing, compliant with Indian data protection regulations.
Data Addendum
An Indian law-governed document that sets out data processing terms and compliance requirements under Indian data protection legislation.
Controller Processor Contract
An Indian law-compliant agreement governing the processing of personal data between a controller and processor under the Digital Personal Data Protection Act 2023.
DPA Contract
An Indian law-governed Data Processing Agreement establishing terms for personal data processing between controller and processor, ensuring compliance with Indian data protection regulations.
Third Party Processor Agreement
An Indian law-governed agreement establishing terms for third-party processing of personal data, ensuring compliance with Indian data protection regulations.
Personal Data Collection Agreement
An India-compliant Personal Data Collection Agreement governing the collection and processing of personal data under Indian data protection laws.
International Data Protection Agreement
An Indian law-governed agreement regulating international personal data transfers and processing, ensuring compliance with India's data protection regulations.
Processor To Processor DPA
An Indian law-compliant Data Processing Agreement between two processors, governing personal data processing activities and security measures under the Digital Personal Data Protection Act 2023.
Master Data Protection Agreement
An Indian law-governed agreement establishing data processing obligations between controller and processor under DPDP Act 2023.
Intra Group Data Transfer Agreement
A comprehensive agreement governing intra-group data transfers in India, ensuring compliance with Indian data protection laws and establishing data handling protocols between group entities.
Data Management Agreement
An Indian law-governed agreement establishing terms for data management and processing between organizations, ensuring compliance with Indian data protection regulations.
Data Controller To Data Controller Agreement
An Indian law-governed agreement establishing terms for personal data sharing between two independent data controllers, ensuring compliance with Indian data protection regulations.
Commissioned Data Processing Agreement
An Indian law-governed agreement establishing terms for commissioned data processing, ensuring compliance with Indian data protection regulations.
Intercompany Data Processing Agreement
An Indian law-governed agreement regulating intra-group personal data processing activities, ensuring compliance with Indian data protection regulations.
DPA Agreement
An Indian law-compliant agreement governing the processing of personal data between a controller and processor, ensuring compliance with the Digital Personal Data Protection Act, 2023.
Third Party Data Processing Agreement
An Indian law-governed agreement regulating third-party personal data processing activities, ensuring compliance with India's data protection regulations.
Data Transfer Addendum
A legal addendum governing data transfers under Indian law, ensuring compliance with the DPDP Act 2023 and establishing data protection requirements between parties.
Supplier Data Processing Agreement
An India-compliant data processing agreement governing the processing of personal data by suppliers, aligned with the DPDP Act 2023 and related regulations.
Personal Data Transfer Agreement
A legally binding agreement for personal data transfer between organizations, compliant with Indian data protection laws and regulations.
Personal Data Protection Agreement
Indian law-compliant Personal Data Protection Agreement governing the processing of personal data between parties under DPDP Act 2023.
Order Processing Agreement
An Indian law-governed agreement establishing terms for order processing services between a service provider and business client.
Data Protection Agreement For Employees
An India-compliant agreement governing the protection and processing of employee personal data under Indian data protection laws.
Affiliate Addendum
An India-compliant addendum governing affiliate marketing relationships, specifying commission structures and regulatory compliance requirements under Indian law.
Data Privacy Addendum
An Indian law-compliant addendum governing personal data processing and protection obligations between contracting parties.
Sub Processing Agreement
An Indian law-compliant agreement governing data handling between a processor and sub-processor, ensuring adherence to Indian data protection regulations.
International Data Transfer Agreement
An Indian law-governed agreement for secure and compliant international transfer of personal data, ensuring adherence to the Digital Personal Data Protection Act, 2023.
Data Protection Addendum
A legal document under Indian law that sets out data protection obligations and requirements between parties handling personal data, ensuring compliance with the DPDP Act 2023.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.