Controller To Controller Data Processing Agreement Template for New Zealand
Generate a bespoke document
What is a Controller To Controller Data Processing Agreement?
The Controller to Controller Data Processing Agreement is essential when two organizations, each acting as independent data controllers, need to share personal data while maintaining compliance with New Zealand's privacy laws. This document becomes necessary when both parties independently determine the purposes and means of processing personal data and need to establish clear guidelines for data sharing, protection, and mutual responsibilities. The agreement is particularly relevant in scenarios involving regular data exchanges, joint projects, or integrated services where both parties maintain separate control over the data processing activities. It must comply with the New Zealand Privacy Act 2020 and includes provisions for data security, breach notification, cross-border transfers, and data subject rights. The document helps organizations maintain transparency, establish clear accountability, and ensure proper data protection measures are in place.
About the Controller To Controller Data Processing Agreement
When your organization needs to share personal data with another entity that also acts as a data controller, you need a Controller to Controller Data Processing Agreement. This legal document establishes the framework for data sharing between two independent organizations while ensuring compliance with New Zealand's privacy laws and protecting the rights of data subjects.
When do you need this document?
You need this agreement when two organizations that both independently determine how and why personal data is processed want to share information. Common scenarios include financial institutions sharing customer data for joint product offerings, healthcare providers exchanging patient information for coordinated care, government agencies collaborating on public services, or educational institutions sharing student data for research purposes. The agreement is also essential when technology companies integrate services requiring data exchange, telecommunications providers share customer information for network services, or research organizations collaborate on studies involving personal data.
Key legal considerations
The agreement must clearly define each party's role as independent data controllers and establish their respective responsibilities for data protection. Key clauses should address data security measures, including technical and organizational safeguards to protect personal information from unauthorized access or breaches. The document must include provisions for data breach notification procedures, specifying timeframes for notifying the other party and relevant authorities. Cross-border data transfer requirements need careful attention, particularly if data will be shared internationally, requiring adequate protection measures or approved transfer mechanisms. The agreement should also address data subject rights, including how individuals can access, correct, or request deletion of their personal information, and establish procedures for handling such requests between the controllers.
Legal requirements in New Zealand
Under the Privacy Act 2020, your agreement must comply with the thirteen Privacy Principles, particularly those relating to data collection, use, disclosure, and security. The agreement must specify the lawful basis for data sharing and ensure that personal information is only used for the purposes outlined in the document. You must include provisions for data retention and disposal, ensuring information is not kept longer than necessary for the specified purposes. If your data sharing involves overseas transfer of personal information, the agreement must address the requirements under Privacy Principle 12, including ensuring the recipient country has adequate privacy protections or implementing additional safeguards. The Contract and Commercial Law Act 2017 governs the formation and enforceability of the agreement, while the Fair Trading Act 1986 requires transparent and accurate representation of data handling practices to avoid misleading conduct.
GOVERNING LAW
Applicable law
This Controller To Controller Data Processing Agreement is drafted to comply with New Zealand law. Key legislation includes:
Contract and Commercial Law Act 2017: Governs the formation and enforcement of commercial contracts in New Zealand, including electronic transactions and digital signatures
Fair Trading Act 1986: Ensures fair business practices and prohibits misleading conduct, which is relevant for transparency in data handling practices
Consumer Guarantees Act 1993: Although primarily for consumer protection, its principles may be relevant if the data processing involves consumer data
Electronic Identity Verification Act 2012: Relevant for verification of identity and authentication requirements in data processing
Unsolicited Electronic Messages Act 2007: Important if the data processing involves electronic marketing or communications
Public Records Act 2005: May be relevant if one of the controllers is a public sector organization or handles public records
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it